Inspiration

AI coding agents increase delivery speed, but can also change test files and CI configuration. A pipeline can appear green for the wrong reason. False-Green Firewall explores how to keep the evidence used to approve a change independent of the change itself.

What it does

The prototype separates an agent's proposed code change from verification. A deterministic Python gate denies missing, stale, mismatched, failed or weakened evidence. GitLab CI runs 55 regression tests and real local Git merge/reject rehearsals. A separate CI configuration was also tested against an intentional candidate-local CI tampering attempt.

How it uses GitLab

A public Work Item triggered a GitLab Duo Agent Platform workflow that produced an MR (!3). Separately, the public Showcase runs MR-specific pipelines for a GREEN candidate (!4, passed) and a RED candidate (!5, failed). Both examples are available in the public project and the code is MIT-licensed.

An isolated private GitLab sandbox demonstrated GREEN automatic merge and RED merge blocking, including an attack that changed a candidate-local .gitlab-ci.yml to an unconditional pass while an independent CI policy still rejected RED.

These are separate experiments. The live Duo-to-protected-CI-to-automatic-merge chain has NOT been demonstrated as a single end-to-end system.

How it was built

Python 3.12, GitLab Duo Agent Platform, GitLab Work Items, Merge Requests, GitLab CI/CD, a fail-closed evaluation gate, a read-only GitLab MR/pipeline API inspector and offline Git integration rehearsals. Current tests: 55 PASS.

Challenges and lessons

The hardest challenge was learning that a failed CI job does not automatically prove that GitLab will enforce a merge block. The hackathon Showcase grants my account Developer + AI Custom role, not Maintainer. Its project merge-check settings are not accessible, so this particular public merge-enforcement claim remains unproven. The stronger merge-block evidence comes from my separate private sandbox, not from the public Showcase.

Impact

This is a reproducible security pattern for teams using agent-generated changes. It shows why the system that writes the code should not be the sole authority for deciding whether that code is safe to promote.

What is next

Protect CI policy references from agent write access, bind evidence to cryptographic attestations, and demonstrate GitLab Duo through independent verification and merge in one environment.

Category

Path A — Start Fresh. Supervised autonomy. No production deployment is claimed.

Evidence

Public code and CI: https://gitlab.com/gitlab-ai-hackathon/transcend-october-2026/43125784/showcase/-/tree/submission-false-green-firewall-v5 Duo-generated MR: https://gitlab.com/gitlab-ai-hackathon/transcend-october-2026/43125784/showcase/-/merge_requests/3 GREEN MR: https://gitlab.com/gitlab-ai-hackathon/transcend-october-2026/43125784/showcase/-/merge_requests/4 RED MR: https://gitlab.com/gitlab-ai-hackathon/transcend-october-2026/43125784/showcase/-/merge_requests/5

Built With

  • git
  • gitlab
  • gitlab-ci/cd
  • gitlab-duo-agent-platform
  • gitlab-work-items
  • python
Share this project:

Updates

Submission history