Your Code Got a Third Author: In-Line AI Agent Governance Across Three Checkpoints

For thirty years, code had two authors: human developers and open-source maintainers. Today, autonomous AI coding agents (Claude Code, Cursor, OpenHands, Codex) are the third author. But governing an autonomous agent using traditional post-commit PR review is a recipe for disaster.

The Three-Author Problem

When an autonomous coding agent works on your repository, it doesn't just write functions. It makes structural decisions in milliseconds:

  • Package Selection: Agents frequently introduce copyleft dependencies (AGPLv3, SSPL) with viral license implications into proprietary codebases.
  • Cryptographic Drift: Agents generate classical RSA-2048 or MD5/SHA-1 hashing routines that violate post-quantum cryptography (PQC / NIST FIPS 203) requirements.
  • Autonomous Secrets Egress: Indirect prompt injection can trick an agent into sending private repository tokens or environment keys to external endpoints.

One Policy, Three Checkpoints

ThumbGate implements the Three Checkpoint Architecture stolen from industry analysis of SCANOSS Earnie, adapted to run completely locally on CPU in sub-0.5ms with 0 tokens:

Checkpoint Target Surface Enforcement Mode Budget
Checkpoint 1: Pre-Generation MCP PreToolUse / Stdin IPC Hard deny with permissive alternative injection <0.5ms
Checkpoint 2: Pre-Commit Git Hook / Staged Diffs Refuses commit on Shor-vulnerable crypto & copyleft manifests <2.0ms
Checkpoint 3: PR Gate GitHub Action / CI & Trunk Gated merge with cryptographic SHA-256 evidence receipt Deterministic

Pre-Action Steerage Over Post-Factum Blame

Rather than failing a CI build 15 minutes later, ThumbGate intercepts the agent's MCP call before execution and returns a structured redirection directly into the model's prompt context:

$ echo '{"tool_name": "bash", "tool_input": {"command": "npm i fast-charts@4.2.1"}}' | npx thumbgate gate-check
{
  "hookEventName": "PreToolUse",
  "permissionDecision": "deny",
  "permissionDecisionReason": "[THIRD-AUTHOR:copyleft-license] Prohibited copyleft dependency 'fast-charts' detected in proposed command. Author: ai_agent. Suggested permissive alternatives: chart.js (MIT) - Simple yet flexible JavaScript charting; recharts (MIT) - Redefined chart library built on React components",
  "findingId": "TG-LIC-3284B1",
  "alternatives": [
    { "name": "chart.js", "license": "MIT", "description": "Simple yet flexible JavaScript charting" },
    { "name": "recharts", "license": "MIT", "description": "Redefined chart library built on React components" }
  ]
}

The agent sees the denial, immediately switches to chart.js, and continues solving the ticket without breaking licensing policy or needing a human engineer to intervene.

Instant Inspection with Finding Fingerprints

Every decision is recorded in an immutable local ledger with a unique finding fingerprint. Audit any finding in one command:

$ npx thumbgate explain TG-LIC-3284B1

============================================================
ThumbGate Finding Evidence: TG-LIC-3284B1
============================================================
Category:    license_compliance
Severity:    CRITICAL
Checkpoint:  mcp_pretooluse
Author:      ai_agent
Decision:    deny
Reason:      [THIRD-AUTHOR:copyleft-license] Prohibited copyleft dependency 'fast-charts' detected in proposed command. Author: ai_agent. Suggested permissive alternatives: chart.js (MIT) - Simple yet flexible JavaScript charting; recharts (MIT) - Redefined chart library built on React components

Offending Command:
  npm i fast-charts@4.2.1

Permissive Alternatives (Approved):
  • chart.js [MIT]: Simple yet flexible JavaScript charting
  • recharts [MIT]: Redefined chart library built on React components

Remediation:
  Substitute the non-compliant dependency or algorithm with an approved alternative.
============================================================

Get Started in 30 Seconds

Install ThumbGate into your agent harness or CI pipeline today:

npx thumbgate third-author --audit