π΅ matcha β Simple. Efficient. Deliberate. Never twice.
Matcha operates strictly as a Developer-Side / Pre-Flight Governance Layer for AI coding agents.
AI Coding Agent Workspace (Matcha pre-flight governance)
β
βΌ (Passes Planning Gate + Safety Shield + Post-Write Scan)
Pull Request (GitHub / GitLab / Bitbucket)
β
βΌ (Mandatory Branch Protection)
Human Code Review (Senior Engineer Approval)
β
βΌ (CI/CD Pipeline)
CI Verification: Unit/Integration Tests + SAST/DAST + Secret Scanner + Dependency Audit
β
βΌ
Production Deployment
Important
Matcha is NOT a replacement for CI/CD, branch protection, or human review. It is an upstream, shift-left policy engine designed to prevent agents from creating messy diffs, destructive command executions, and accidental leaks before code reaches version control.
- Destructive Command Execution:
- Blocks catastrophic shell commands (
rm -rf /,rm -rf ~,mkfs, disk device overwrites viadd,git reset --hard, unleased force pushes).
- Blocks catastrophic shell commands (
- Hardcoded Secrets & Credential Leaks:
- Scans file write buffers for exposed API keys, private keys, access tokens, and passwords via
patterns.jsonregex registry.
- Scans file write buffers for exposed API keys, private keys, access tokens, and passwords via
- Agent Scope Sprawl & Unbounded Hallucinations:
- Enforces the Planning Gate (
.agents/plan/current.md), halting writes until a structured problem, goals, and bounded execution plan are recorded.
- Enforces the Planning Gate (
- "Theater of Compliance" (Anti-Rubber-Stamping):
- Captures machine-readable test execution evidence (
.agents/state/evidence.json) with process exit codes, preventing agents from hallucinating "all tests passed".
- Captures machine-readable test execution evidence (
- Silent Overrides & Bypass Tracking:
- Every bypass or override (
MATCHA_SHIELD_OFF,matcha off) is logged with an ISO timestamp, actor, and rationale to.agents/audit.log.
- Every bypass or override (
- Deep Business Logic Exploits:
- Matcha cannot prove the absence of IDOR (Broken Object Level Authorization), complex state machine bugs, or distributed race conditions.
- Zero-Day Vulnerabilities in Dependencies:
- Dependency vulnerability auditing requires dedicated SCA tools (e.g., Snyk, Dependabot, Trivy) in your CI pipeline.
- Bypassed Execution:
- If commands are executed directly in an external shell without AI agent hooks, Matcha's runtime hooks are not triggered.
Matcha supports both frictionless prototyping and enterprise compliance:
- Toggle Off:
matcha offor/matcha:offallows free exploration, but logs the action to.agents/audit.log. - Environment Override:
MATCHA_SHIELD_OFF=truedisables shield blocking, appending an audit record for compliance inspection. - Audit Review: Run
matcha auditat any time to inspect recent override events.
If you discover a security vulnerability in Matcha (such as a bypass vector in matcha-shield.js or command injection in hook arguments), please report it responsibly:
- Email:
security@plumpslabs.dev - GitHub: Submit a Private Vulnerability Report via GitHub Security Advisories.
- Acknowledgement: Within 48 hours.
- Triage & Assessment: Within 3 business days.
- Patch Release: Within 7 business days for high/critical severity issues.
Please do NOT open public GitHub issues for undisclosed security vulnerabilities.