Back to Discover

GateTest

connector

crclabs-hq

120-module QA gate. Give Claude eyes (screenshots), ears (Sentry errors), and hands (verify fixes).

View on GitHub
0 starsSynced Aug 2, 2026

Install to Claude Code

/plugin marketplace add crclabs-hq/GateTest

README

GateTest

One gate. 121 modules. Self-healing CI.

AI-powered code quality. Pay per scan via Stripe.

GateTest npm CI License: MIT Modules Tests Node


The 30-second pitch

GateTest is a single CLI plus a composite GitHub Action that runs 120 static-analysis modules against any codebase, then uses Claude to repair the findings it can. It replaces SonarQube, Snyk, ESLint, Cypress, Lighthouse, axe, pa11y, and twenty-plus other tools with one config, one gate decision, and one report.

It is different because the cost trends to zero. Deterministic AST and rule-based layers run first — these are free and ship the fix in milliseconds. Claude only runs on patterns nothing else has seen. Every Claude win is distilled into a reusable recipe, so the next time the same pattern appears anywhere in the network it is handled for free. The longer you run GateTest, the less of it is paid work.

What you get depends on the tier. A pull request with the fixes, regression tests pinned to each fix, an architecture-shape critique, a cross-finding attack-chain analysis, and a CTO-readable executive summary — in whichever combination the tier you bought includes. One-time payment per scan via Stripe at checkout. No subscription, no auto-renew.


Install & Usage — 30 seconds

GitHub Action — recommended for most users

Drop this in .github/workflows/gatetest.yml:

name: GateTest Quality Gate
on: [push, pull_request]
jobs:
  gate:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: crclabs-hq/GateTest@v1.1.1
        with:
          suite: full
          auto-fix: ${{ github.event_name == 'pull_request' }}
        env:
          ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}

The action is a composite — no Docker pull, no container build. It installs GateTest, runs the gate, and if auto-fix: true and ANTHROPIC_API_KEY is set, runs the AI repair loop on a blocking gate. See action.yml for every input.

CLI — local development

# Install from npm:
npm install -g @gatetest/cli
gatetest --suite quick

# Or run against the current directory with no install:
npx github:crclabs-hq/GateTest --suite quick

# Or clone and run from source:
git clone https://github.com/crclabs-hq/GateTest
cd gatetest && npm install
node bin/gatetest.js --suite quick

Pre-push sweep

Run the full pre-merge sweep locally in one command:

npm run sweep          # ~30-60s — tests + build + gate + secrets + self-scan

This runs the same seven checks that block a merge in CI. Verdict is green or red. Exit code is 0 or 1, matching CI exactly.

Fast path during iteration:

npm run sweep -- --fast    # skip tests + build, gate-only, ~3-5s

See gatetest sweep --help for every flag.

Silencing a false positive — 10 seconds

Every scanner gets it wrong sometimes. When GateTest flags something you've judged safe, add one line to a .gatetestignore file at your repo root:

# Silence one rule from one module:
secrets:generic-api-key

# Silence a whole module:
deadCode

# Silence a rule everywhere it fires:
*:trailing-whitespace

# Scope a suppression to a path:
secrets:generic-api-key@tests/fixtures/**

# Skip a path entirely:
vendor/**

Suppressed findings are excluded from the gate decision and every failure count, but stay visible in a suppressedChecks list — nothing is silently hidden. Two more controls:

  • gatetest --noise — ranks your noisiest modules and prints the exact ignore line to copy.
  • Auto-softening — a module you chronically dismiss stops blocking the gate on its own (never on thin evidence: it takes repeated dismissals at a high fire-rate).

Project-wide options live in .gatetest.json (suites, per-module config, severity overrides) — run gatetest --init to scaffold one.

Onboarding a mature repo — baseline mode

Turning a scanner on against a large existing codebase usually means drowning in a backlog you didn't write. GateTest's baseline mode grandfathers everything that exists today so the gate only ever fails on new findings — "clean as you code."

# Snapshot every current finding into .gatetest/baseline.json — commit it:
gatetest --baseline

# From now on, normal runs pass on the pre-existing findings and only
# block on NEW ones. Baselined findings stay visible, never hidden.
gatetest --suite full

Fix a baselined finding and it's gone for good; the count is tracked per file, so adding a second secret to a file that already had one baselined re-blocks the gate (you can't sneak a new problem in behind an old one). Refresh the snapshot after paying down debt with gatetest --baseline; delete .gatetest/baseline.json to see everything again.

Testing pages behind a login — authenticated crawl

The live crawler can carry a session so it reaches authed areas (/dashboard/*, account pages) instead of bouncing off the login redirect:

# A header (repeatable), a cookie, or an exported browser session —
# values support ${ENV_VAR} so secrets stay out of committed config:
gatetest --crawl https://app.example.com --crawl-header "Authorization: Bearer ${TOKEN}"
gatetest --crawl https://app.example.com --crawl-cookie "session=${SESSION}"
gatetest --crawl https://app.example.com --crawl-storage-state state.json

Session material is only ever sent to the target's own origin — never to third-party links, assets, or cross-origin redirects. Without a session, a crawl that hits a login wall tells you exactly which flag to add rather than silently skipping the protected pages. The hosted scanner at gatetest.io accepts the same session auth.

Claude Code / MCP — give Claude eyes, ears & hands

Connect GateTest directly to Claude Code (or any MCP-compatible AI) in one command:

claude mcp add gatetest -- npx -y @gatetest/mcp-server

24 tools across five families:

FamilyToolsWhat it gives Claude
Enginescan_local, run_module, fix_issue, verify_fix, …Scan + fix local code
👁 Eyescapture_screenshot, get_visual_diffSee the rendered page as a real image
👂 Earsget_production_errors, run_live_checksHear Sentry/Datadog/Rollbar errors + localhost runtime failures
🤝 Handsverify_fixHard ✅/❌ — prove the fix actually worked
🔬 Root Causeresolve_stack_trace, blame_regressionResolve a minified stack trace to original file:line via source maps; find the git commit that introduced a specific line. Same engines are also CLI subcommands (gatetest trace, gatetest blame) — one implementation, both entry points

Works with Claude Code, Cursor, Windsurf, Continue, and Cline. See packages/mcp-server/ for the full tool reference and example prompts.

Website — no install at all

Visit gatetest.io/web and paste any URL. You get a free preview and a paid full report. For WordPress sites use gatetest.io/wp.

Wire it into CI — GitHub, GitLab, or CircleCI

Don't hand-write the pipeline. One command scaffolds a complete, conventional config:

gatetest --ci-init github     # .github/workflows/gatetest.yml
gatetest --ci-init gitlab     # .gitlab-ci.yml
gatetest --ci-init circleci   # .circleci/config.yml

Each generated config gates the right thing at the right time rather than running everything everywhere: a quick, diff-scoped scan on merge requests and pull requests, a full scan on the main branch, and a separate security stage. JUnit and SARIF are emitted to .gatetest/reports/ and wired into the platform's native test-reporting and artifact storage, so failures show up in the UI instead of only in the log.

On any other CI — Jenkins, Buildkite, Bitbucket, Drone — the CLI is the whole integration:

npx @gatetest/cli --suite full --junit --sarif

Onboarding an existing codebase? Pair this with baseline mode above so the gate only fails on new findings.

Replay a failing CI run locally

Reproduce any failing GitHub Actions run on your laptop in seconds:

gatetest replay https://github.com/owner/repo/actions/runs/12345

This fetches the run, identifies which steps failed, and runs them locally against your current working tree. Output tells you whether the failure reproduces, doesn't reproduce (flaky CI), or hits a different error.

Authentication is optional — if you have a GITHUB_TOKEN set or gh CLI installed, replay can read private repo runs. Otherwise it uses the unauthenticated rate limit (60 req/hour, fine for a few replays).

Root-cause a bug from the CLI

# Resolve a minified stack trace back to original file:line:column
cat error.log | gatetest trace -

# Find which commit introduced a specific line (read-only — never
# checks out or mutates the working tree)
gatetest blame src/app.js --line 42

Both subcommands share the exact same engine as the MCP resolve_stack_trace and blame_regression tools — run them by hand or let Claude call them mid-fix-loop; the answer is identical either way. Run gatetest trace --help or gatetest blame --help for the full option list.


The flywheel — why GateTest gets cheaper over time

                ┌──────────────────────────┐
   CI BREAKS    │  Failed workflow run     │
       ──>      └────────────┬─────────────┘
                             │
                ┌────────────▼─────────────┐
                │  AI CI-fixer reads logs  │
                │  + failing files         │
                └────────────┬─────────────┘
                             │
              ┌──────────────┼──────────────┐
              │              │              │
              ▼              ▼              ▼
         ┌────────┐    ┌────────┐    ┌────────┐
         │  AST   │ →  │  Rule  │ →  │ Recipe │   ─── ALL FREE ───
         └────┬───┘    └────┬───┘    └────┬───┘
              │             │             │   (none matched?)
              └─────────────┴─────────────┘
                             │
                             ▼
                ┌──────────────────────────┐
                │ Claude — paid, one shot  │
                │ Result distilled into a  │
                │ recipe for next time     │
                └────────────┬─────────────┘
                             │
                             ▼
                ┌──────────────────────────┐
                │  PR opens with the fix   │
                │  + regression test       │
                └──────────────────────────┘

First time we see a pattern: Claude. Every time after: free. The longer you run GateTest, the cheaper it gets.


What it replaces

One config, one bill, one gate decision. Twelve-plus tools dissolve into single CLI flags.

Their toolGateTest module
Snyk Code, Dependabot, npm auditsecurity, dependencies
SonarQubecodeQuality + every other module
ESLint, Stylelintlint
Cypress, BrowserStack, Sauce Labse2e
Lighthouseperformance
axe, pa11yaccessibility
Percy, Chromaticvisual
git-secrets, TruffleHogsecrets, secretRotation
hadolint, dockledockerfile
actionlint, zizmor, StepSecurityciSecurity
tfsec, Checkov, Terrascanterraform
kube-score, kubeaudit, Polariskubernetes
Stryker, Pitestmutation
broken-link-checkerlinks
(none — fragmented across ESLint rules)errorSwallow, nPlusOne, flakyTests
(none — no static tool exists)redos, moneyFloat, logPii, tlsSecurity
(none — runtime profilers only)resourceLeak, raceCondition, retryHygiene

Twelve-plus tools. One config. One bill. Full module catalogue: run node bin/gatetest.js --list or read it on gatetest.io.


Tiers and pricing

Scan tiers are one-time payments via Stripe at checkout — no auto-renew. Continuous and MCP are monthly subscriptions; manage or cancel them yourself at gatetest.io/billing (enter your checkout email, get a secure Stripe portal link by email — update your card, view invoices, change plan, or cancel). Refunds only at our discretion for scans that failed to start or crashed mid-way without producing a report (contact hello@gatetest.ai).

TierPriceWhat you get
Quick Scan$294 modules — syntax, linting, secrets, code quality. Fastest path to a first signal. Scan-only — no auto-fix.
Full Scan$99The full engine suite (88 modules; mutation + chaos run via the GitHub Action instead — they need a CI runner). SARIF + JUnit reports via the CLI / GitHub Action. Scan-only — auto-fix ships at the Scan + Fix tier.
Scan + Fix$199Everything in Full, plus a second-Claude pair-review critique on every fix and an architecture-shape design-observations report.
Forensic Scan$399Everything in Scan + Fix, plus real Claude diagnosis on every finding, cross-finding attack-chain correlation, board-ready CISO report (OWASP / SOC2 / CIS v8 / 30-60-90), and a CTO-readable executive summary. Mutation testing and chaos / fuzz pass are also available via the GitHub Action (mutation: true / chaos: true) — they need a CI runner to execute your test suite and a headless browser, so they ship with the Action rather than the website-only scan.
Continuous$49/moScan every push via the GitHub App. Unlimited deterministic push scans plus a monthly Claude AI-review allowance. Fix PRs are a per-scan upsell.
MCP$29/moThe hosted remote MCP endpoint — use GateTest from claude.ai web/mobile or locked-down machines, plus hosted scan history (gtmcp_ key delivered by email after checkout). The local MCP server (npx @gatetest/mcp-server) is 100% free — every tool runs on your machine with your keys.

Live prices and Stripe checkout at gatetest.io.


Honest limits

GateTest is not magic. The things it does not yet do, said out loud:

  • Headless-browser modules (liveCrawler, runtimeErrors, explorer, chaos) degrade gracefully on Vercel serverless. Chromium cannot launch inside the function. The modules emit an info-level skip and the rest of the scan continues — full power requires the CLI, a worker, or local dev.
  • Hosted website scans read up to 50 source files per scan (prioritised by relevance). Most small-to-mid repos fit; a large monorepo gets a representative slice. The CLI and GitHub Action scan everything with no cap.

The full Known Issues table (with severity and status) lives in CLAUDE.md — that file is the project's source of truth.


Architecture

Static engine. 121 modules, every one extending BaseModule. Each module is a self-contained scanner that emits checks at three severity levels (error blocks the gate, warning reports, info is informational). The runner is EventEmitter-based, supports parallel execution, diff-mode (--diff scans only git-changed files), watch mode, and five output formats (Console, JSON, HTML, SARIF for the GitHub Security tab, JUnit XML for any CI). The gate has four small runtime dependencies (acorn, pngjs, pixelmatch, and the MCP SDK) — node bin/gatetest.js --list runs anywhere Node 20+ runs.

Website and payments. gatetest.io is Next.js 16 with the App Router, Tailwind 4, and Stripe in per-scan upfront-charge mode. One-time payment per scan at checkout — no subscription, no auto-renew, no hold-then-capture flow. All scan state is persisted in Stripe metadata so the serverless functions stay stateless across requests — there is no shared in-memory state and no webhook is required for the critical user flow. The scan executes inside the function response and reports back directly.

AI layer. Claude (Anthropic). On the GitHub Action the customer brings their own ANTHROPIC_API_KEY and pays Anthropic directly. On the website the key is managed and the cost is folded into the tier price. Every Claude success is distilled into a recipe by the flywheel orchestrator (see lib/ and the AI CI-fixer at scripts/ai-ci-fixer.js) so subsequent runs on the same pattern are deterministic and free.

The codebase ships under MIT, the gate runs locally with no external calls, and every architectural decision is documented inline in CLAUDE.md.


Real-repo proofs

GateTest is dogfooded against itself on every push, and the team runs the full Forensic pipeline against external production codebases before shipping changes that touch the deeper tiers. The reports below are reproducible artifacts in this repo:


Develop and contribute

git clone https://github.com/crclabs-hq/GateTest
cd gatetest
npm install
(cd website && npm install)
node --test tests/*.test.js
node bin/gatetest.js --list

The Bible — CLAUDE.md — is required reading for contributors. It defines the architecture, the quality bar, the forbidden list, the protected platforms, and the authorization rules that apply to anything touching money, user data, or public-facing communication.

Bug reports and feature requests are welcome via GitHub Issues. Small PRs that fix one thing and add a test are merged fastest. The pre-commit and pre-push hooks under src/hooks/ run the gate locally — running them before pushing keeps CI green.


License

MIT — see LICENSE.


GateTest is built and maintained at gatetest.io. Talk to the team via the chat on the site. File bugs at GitHub Issues.

Rendered live from crclabs-hq/GateTest's GitHub README — not stored, always reflects the source repo.

0 Install Methods

No plugins listed in this repo's manifest.

0 Comments

Login required
Log in to post a comment or update on this repo.

No comments yet — be the first to share an update.