ccdwyer/proof-decay

A Claude Code mod that tracks which test, typecheck, lint and build results are still true after later edits, and stops commit messages that claim checks which are stale.
ccdwyer/proof-decay

Proof Decay records every test, typecheck, lint and build run the agent makes, then marks the result stale as soon as a later edit touches what it covered. It shows a proof board above the prompt, fingerprints the working tree at the end of each turn and before commits, and uses Oathkeeper to refuse commits whose messages claim passing checks that are actually stale, failed or missing. Recognised commands include npm/yarn/pnpm/bun test/lint/typecheck/build, jest, vitest, mocha, playwright, pytest, tsc, vue-tsc, mypy, pyright, eslint, ruff, biome, go test/vet/build, cargo test/check/clippy/build, swift test/build, xcodebuild test/build, gradle test/build and make test/lint. Install via /plugin marketplace add ccdwyer/claude-mods and /plugin install proof-decay@ccdwyer-mods. It runs entirely locally, sends nothing over the network, and collects no telemetry.
Check the author's README for the marketplace and plugin name first. Commands may change as the repository evolves.
claude plugin marketplace add ccdwyer/proof-decay claude plugin install proof-decay

Tests and tsc pass, so the board reads ✓ tests fresh · ✓ types fresh. One edit later both go ⚠ stale (1 edit), and a commit claiming "All tests pass" is refused by Oathkeeper. MP4
| Fresh | Stale | Refused |
|---|---|---|
|
|
|
|
A Claude Code mod that tracks which verification results are still true.
"Tests passed" stops meaning anything once the code changes. Proof Decay records every test, typecheck, lint and build run the agent makes, then marks the result stale as soon as a later edit touches what it covered.
✓ tests fresh · ⚠ types stale (3 edits) · ✗ lint failed. It shows the repo you're in.&& chain that succeeded, or the last command of a newline/; script is recorded, because those are the only cases where the one exit status the call has can be pinned to the check. npm test; true, npm test || …, pipes, subshells and $(…) never produce a pass, and anything inside quotes is never treated as a command. A check whose outcome can't be read (npm test || true, $(npm test), a failed chain) casts doubt on the earlier pass instead. Interrupted or backgrounded runs are skipped.npm test, pytest, go test ./..., tsc -p tsconfig.json) counts as a project result. Some runs are scoped or filtered instead. That includes runs from below the repo root (or from a nested package.json), runs that name files or a directory, script variants (test:unit), workspace or package flags, plain cargo test at a workspace root, and name filters (-t, -kfoo, --lib, -only-testing). They still show on the board, but they never back a claim. A failed scoped run also casts doubt on the project pass.-m, heredocs and -F files, and git -C is supported. If it claims checks passed ("all tests pass", "typecheck is clean", "CI is green"), but the matching whole-project run in that repo is stale, failed or missing, the commit is refused. Hedged lines ("should pass", "tests pass when…", "not all tests pass") are ignored. A claimed commit has to run as its own command, not chained after other commands. git add before it in the same call is fine. It's also refused if it would commit less than what was tested: unstaged changes, untracked files the tests saw (even with -a), or pathspec, --only and --patch commits. bash -c '…' wrappers are looked inside. After popd, cd ~ or cd -, the target repo can't be pinned, so claims are refused. If a message can't be read in advance (a $VAR, an editor, --amend --no-edit when history can't be read), the commit only goes through while every check in the repo is fresh. Every other commit goes through, with a note to the model listing what wasn't re-verified./proofs lists every recorded run with its age, scope, repo and any reason for doubt. /proofs clear forgets them all. Results last for the whole session, across prompts.Recognised commands include npm/yarn/pnpm/bun test/lint/typecheck/build scripts, jest, vitest, mocha, playwright test, pytest, tsc, vue-tsc, mypy, pyright, eslint, ruff, biome, go test/vet/build, cargo test/check/clippy/build, swift test/build, xcodebuild test/build, gradle test/build, and make test/make lint.
/plugin marketplace add ccdwyer/claude-mods
/plugin install proof-decay@ccdwyer-mods
/reload-plugins
claude plugin validate .
claude plugin test .
Events this mod hooks, as claude plugin validate reads the module:
session.startcommand.run{command=proofs}tool.call{tool=Bash}tool.callturn.completeui.render{component=AbovePrompt}Engine calls it makes: $.clock.now, $.command.register, $.fs.read (via demote, judgeCommit), $.fs.stat (via exists), $.process.run (via fingerprint, judgeCommit, rootOf), $.session.cwd, $.state.get, $.state.set, $.ui.resolve.
A tool.call hook sits in the middle of every tool call: it can see the call, refuse it, or add context to its result. This mod uses that only for the behaviour described above.
It runs entirely on your machine. It sends nothing over the network. It runs git locally to fingerprint the working tree.
The mod collects no analytics or telemetry, and its author receives no data from it.
Full policy: PRIVACY.md.
MIT