Pre-commit code quality guardian. Detects semantic drift in AI-generated code.
HefestoAI Model Context Protocol (MCP) Server
The io.github.artvepa80/hefestoai MCP server is a pre-commit code quality guardian that detects semantic drift in AI-generated code. It checks whether a project’s declared items—such as dependencies, configurations, and install artifacts—match what the project actually does before changes ship.
🛠️ Key Features
Detects semantic drift in AI-generated code
Verifies declared deps, configs, and install artifacts against real outcomes
Provides 4 tools (toolCount: 4)
🚀 Use Cases
Pre-commit validation for repositories using AI-generated code
Ensuring declared project state matches installation and behavior
Catching mismatches before release
⚡ Developer Benefits
Adds a release- and shipping-time verification step for AI-authored changes
Helps prevent inconsistencies between project declarations and actual install artifacts
⚠️ Limitations
Scope described is centered on semantic drift and verification of declared vs. actual deps/configs/install artifacts
HefestoAI — release truth engine for AI-generated code
After your AI wrote the code, but before it ships. HefestoAI verifies that what your project declares — deps, configs, install artifacts — matches what it actually does.
HefestoAI's core contribution: detecting drift between what your project declares and what it does. These analyzers run automatically on every hefesto analyze and catch issues that linters and security scanners miss because they're not in any single file — they're in the inconsistency between files.
Analyzer
What it catches
Rule ID
Imports vs Deps
Python imports not declared in pyproject.toml or requirements.txt
OT-IMPORTS-001
Docs vs Entrypoints
CLI scripts in [project.scripts] missing from README
OT-DOCS-001
Packaging Parity
Version mismatch between pyproject.toml, CHANGELOG, and README badges
OT-PKG-001/002
Install Artifact Parity
action.yml inputs not consumed; Dockerfile COPY sources missing
OT-INSTALL-001/002
CI Config Drift
Python version or flake8 config mismatch between local and CI workflow
OT-CI-001/002/003
bash
# All operational truth findings appear in standard output
hefesto analyze . --severity MEDIUM
Quick Start
bash
pip install hefesto-ai
cd your-project
hefesto analyze . --fail-on critical
# PR review (new in v4.11.2) — analyze only changed code
hefesto pr-review
hefesto pr-review --strict # include file-level context
hefesto pr-review --post --pr 42 # post inline comments via gh CLI
Why Hefesto? The AI Code Problem
AI tools like Claude Code, GitHub Copilot, and Cursor generate code at machine speed. But who validates that code?
Analyze only the code changed in a pull request. Post inline comments on changed lines with deterministic dedup keys so reruns never create duplicate comments.
bash
# Generate review as JSON (default — no network, no token needed)
hefesto pr-review
# Post inline comments via gh CLI (convenience mode)
hefesto pr-review --post --pr 42 --repo owner/name
# Include file-level context findings (not just changed lines)
hefesto pr-review --strict
How it works:
Parses git diff between base and head (auto-detects origin/main or GITHUB_BASE_REF)
Runs the full analyzer suite on touched files only
Filters findings to changed lines (default) or full files (--strict)
Emits JSON with SHA256 dedup keys for each finding
¹ TreeSitter languages require the [multilang] extra:
pip install "hefesto-ai[multilang]". Without it, files in these
languages are skipped at parse time and Hefesto emits a stderr warning
pointing to the install command (also exposed via
report.meta.parser_failures in JSON output).
Fast lint/test gate — Black, isort, Flake8, and a minimal test suite
Note: Hooks are local to your machine and not committed to git. Run hefesto install-hooks after cloning or whenever scripts/git-hooks/pre-push is updated.
Hefesto OSS works standalone. If Hefesto PRO is installed, OSS can optionally enable:
Patch C API hardening for hefesto serve, scope gating (first-party by default), TS/JS
symbol discovery, and safe deterministic enrichment (schema-first, masked, bounded).
See docs/PRO_OPTIONAL_FEATURES.md.
REST API (PRO)
bash
# Start server (binds to 127.0.0.1 by default)
hefesto serve --port 8000
# Analyze code
curl -X POST http://localhost:8000/analyze \
-H "Content-Type: application/json" \
-H "X-API-Key: $HEFESTO_API_KEY" \
-d '{"code": "def test(): pass", "severity": "MEDIUM"}'
# Run IRIS Agent
python -m hefesto.omega.iris_agent --config iris_config.yaml
# Check status
hefesto omega status
IRIS Telemetry Contract (OMEGA)
IRIS labels deployments as GREEN/YELLOW/RED using post-deploy telemetry. The input format is an open contract — any observability stack can produce it:
# Validate your telemetry file
python scripts/validate_aggregates_jsonl.py aggregates.jsonl
# Feed to IRIS (OMEGA tier)export IRIS_TELEMETRY_SOURCE=file
export IRIS_TELEMETRY_FILE=aggregates.jsonl
iris label-outcomes --repo org/repo --commit abc123 --env production --window both --json
Enterprise collectors (Prometheus, Datadog, CloudWatch) and integration runbooks are available in the PRO distribution.
vs. Competition
Criterion
Hefesto
Semgrep
CodeRabbit
Qodo
Snyk
AI-generated code focus
✅ Primary use case
Generic
✅ Yes
✅ Yes
Generic
Declared-vs-real drift detection
✅ Core feature
❌
❌
❌
❌
Operational truth analyzers
✅ 5 analyzers
❌
❌
❌
❌
Languages supported
22 formats
Many
Many
Many
Many
Setup time
< 5 min, no config
Config-heavy
Cloud signup
Cloud signup
Cloud signup
Where it runs
Local CLI / GitHub Action / pre-commit / MCP
Local / cloud
Cloud only
Cloud only
Cloud / CLI
Pricing
Free OSS / $8 Pro / $19 OMEGA
Free OSS / Contact sales
$24/dev/mo
Free Dev / $30/dev/mo
$25/dev/mo*
*Snyk pricing is per product (Code, Open Source, Container, IaC); multi-product subscriptions cost more.
HefestoAI's niche: Detecting drift between what AI-generated code declares and what it does. Traditional tools validate code against language rules. HefestoAI validates code against the project's own declarations — its dependencies, its configs, its install artifacts.
Dogfooding (Honest Account)
We run HefestoAI's strict gate against HefestoAI's own code on every push to main. As of 2026-04-29, the gate is GREEN — but it took us 6 weeks of refactor to get there.
When we initially activated the gate in strict mode, it flagged 12 complexity findings in our own gate-internals code. We considered three responses: silence the findings (rejected — that's exactly the drift we critique), accept the override permanently (rejected — same reason), or refactor at root cause (chosen — took 1 PR, 4 commits, 2 days, plus a declared-vs-real drift discovery in our own positioning doc that we logged for fix).
The full audit and refactor history are tracked internally in our private repo. The override mechanics and reversion criteria are documented; the gate-internals refactor reduced two CRITICAL functions from cyclomatic complexity 33 → 1 and 25 → 6 respectively, all helpers under 10.
Changelog
v4.11.2 (2026-04-12)
Phase 4 — Narrow Semantic Analyzer: ATTRIBUTE_NAME_MISMATCH (typo detection via difflib) and SILENT_EXCEPTION_SWALLOW (broad except with trivially silent body)
Cross-repo schema contract test: pins 12-key PR review finding dict between OSS and Pro
code_snippet in PR review JSON: field was silently dropped, now included
Phase 3.1 — Enrichment rendering: PR comments render AI enrichment summary when present
Upgrade notice: shows when a newer version is available on PyPI
Fix: contextlib.suppress(ImportError) recognized as optional-import guard
PR Review: New hefesto pr-review command — diff-scoped analysis with inline GitHub PR comments and SHA256 dedup keys. Two workflow templates (simple + deduped) in examples/github-actions/
Operational Truth Analyzers: 5 project-level analyzers detect drift between imports/deps, docs/entrypoints, packaging versions, install artifacts, and CI config — all visible via hefesto analyze