hollow-testsTests that test nothing
Tests with no assertion or only constant ones, swallowed errors and un-awaited promises — in Jest, Vitest, Mocha, node:test, pytest and unittest.
Fini Proof™ · proof-based code verification
Developers and AI coding agents now write code faster than anyone can review it. Fini Proof checks every change in your own CI and gives one verdict: PASS, FAIL or NOT_MEASURED. Every finding comes with a command that reproduces it, and every check must catch a planted bug before it may judge your code.
Configured trial: 7 days, 7 proof commands, 1 repository. The CLI starts its trial on the first proof command; account creation does not reset it.
Already using Fini Proof? Sign in to your Developer workspace$ npx fini-proof check --base origin/main engines hollow-tests secrets fail-open skip-ratchet tenant-filter migrations HIGH src/orders/order.service.ts:42 TENANT_FILTER_MISSING proof: fini-proof prove --engine tenant-filter --file src/orders/order.service.ts --line 42 HIGH test/refund.spec.ts:18 hollow-tests/NO_ASSERTION VERDICT: FAIL (exit 1) · evidence .fini-proof/runs/<run id>.json$ git commit -am "scope order lookup by tenant, assert refund"$ npx fini-proof check --base origin/mainVERDICT: PASS (exit 0)
The problem
A reviewer reads the diff and trusts the green tick. The expensive bugs sit where the tick is wrong.
An agent asked to “add tests” often writes tests with no real assertion. Coverage goes up, CI goes green, and nothing is protected.
In multi-tenant software, one query without a tenant filter is a data leak. In the diff it looks like any other line.
A step with “|| true”, a skipped suite, a “.only” left in by mistake: the pipeline reports success because nothing was checked.
How it works
A check that has never been seen to fail is not evidence. So before a check reads your code, it has to catch a defect we planted.
Each engine first runs on planted defects (negative controls) and clean look-alikes (positive controls). If it misses one, the result is NOT_MEASURED — never a pass.
On a pull request only the changed files are judged, so old debt does not block new work. Existing skipped tests and applied migrations are recorded once as a baseline.
Each finding names the file, line and rule, with a fix and a prove command that reproduces it. Every run writes an evidence file with a hash of every input, and SARIF for code scanning.
Every check ran, every control behaved, and nothing blocking remains.
At least one blocking finding, each with its file, line and proof command.
Something could not be checked — an unreadable file, a missing base branch, a check that missed its planted bug. “Could not check” is never turned into a pass.
Six built-in checks
Deterministic engines, not a language model’s opinion: the same input gives the same verdict, and every result can be reproduced offline.
hollow-testsTests with no assertion or only constant ones, swallowed errors and un-awaited promises — in Jest, Vitest, Mocha, node:test, pytest and unittest.
tenant-filterA query on a multi-tenant table with no tenant condition. It reads your schema to find which tables hold tenant data — raw SQL, TypeORM, Prisma, Knex, Django, SQLAlchemy and more.
migrationsDropped tables and columns, type rewrites, NOT NULL without a default, and migrations with no way back — plain SQL, Flyway, Prisma, TypeORM, Knex, Alembic, Django and more.
fail-openSteps and scripts that report success when they failed: “|| true”, “set +e”, continue-on-error, an empty catch, “except: pass”.
secretsCloud keys, private keys, API tokens and real values in .env files. If gitleaks is installed, Fini Proof runs it and holds it to the same planted-defect test.
skip-ratchetA focused “.only” is always caught. Existing skips are recorded once; after that the count can only go down unless someone writes down why.
Guardrails for AI coding agents
Coding agents are fast — and happy to report “all tests pass” about tests that assert nothing. Fini Proof sits between the agent and “done”.
A Stop hook keeps the agent from finishing while the verdict is FAIL and hands it the findings. A PostToolUse hook checks each file as it is written.
“fini-proof mcp” gives any MCP client three tools — check, explain_finding and list_rules — on the same licensed path and evidence as the CLI.
An AGENTS.md section plus a CI gate. The gate also fails a pull request that changes the checker’s own config or baseline without human approval.
Every evidence file records who made the change — a person or an agent — and which verifier checked it. A verifier cannot attest its own change.
You can tell an agent to make CI green. It cannot switch off the check that decides.
Works where you already work
- uses: actions/checkout@v4
with: { fetch-depth: 0 }
- run: npx --yes fini-proof check --base origin/${{ github.base_ref }} --sarif-out fini-proof.sarif
env: { FINI_PROOF_LICENCE: ${{ secrets.FINI_PROOF_LICENCE }} }Security and your data
Runs in your CI. The engines are deterministic and need no model call, so your source code is never uploaded.
Evidence, not code. Sending results to your Developer workspace is optional and sends the evidence file — hashes, rules and verdicts. An edited evidence file is refused.
Offline licence. An Ed25519-signed licence is checked on your machine with no network call, so it works on air-gapped runners too.
No lock-in. Results come out as JSON and SARIF, so you keep them if you ever leave.
Never trains on your code. Customer code is never used to train or fine-tune any model.
CLI, six checks, proof state, SARIF and JSON, CI templates, MCP server, Claude Code and Codex integration.
GitHub App with check runs and annotations. Results uploaded to your Developer workspace show as self-reported until the hosted verifier ships.
IDE extension. SOC 2 and ISO 27001: not certified today, and we do not claim to be.
Who it is for
CTO / VP Engineering
Let agents write more of the code while a check you control decides what counts as done.
Head of QA and release
Find the tests that pass whatever the code does, and stop skipped tests piling up without anyone deciding.
CISO and compliance
Each run records engine versions, input hashes, the verdict and who made the change — exported as JSON and SARIF.
IT services delivery head
Attach proof of verification to every client delivery, so acceptance is about evidence, not opinion.
Get started
Create a workspace account to keep evidence, or start locally with the CLI guide.
Configured trial: 7 days, 7 proof commands, 1 repository. Consult the CLI guide for the installed version’s enforced limits.
Create a workspace account$20 for 1 developer(s) per month, prepaid before applicable tax
See plans and pricingFAQ
Explore the trial guide and current prepaid plans on the developer page.