OPEN DEMONSTRATION
K9X ecosystem · continuous conformance

Solutions built on K9-AIF keep its architecture.
Inspector checks it on every push.

Point K9X Inspector at your GitHub repositories. On every push, or on a schedule, it reads each solution — never running it — and reports where the code departs from the framework: contracts, layering, the governed model path, Shield and Guardian, Zero Trust, secrets and the framework version. Every finding comes with the file, the line and the fix.

Sign in

What it checks

28 rules in eight areas. The rules are part of the framework itself (k9_aif_abb.k9_inspect), so the command line, CI and this service apply exactly the same checks.

Contracts

Agents extend BaseAgent or another agent ABB, so governance wraps them; loop agents keep their loop.

K9-CON-001 · 002

Three-layer decoupling

Router → Orchestrators → Squads → Agents; each layer knows only the one below.

K9-DEC-001

One model path

Every model call goes through llm_invoke() — where governance, retries and the call trace live.

K9-LLM-001 · 002 · 003

Governance

Shield enabled with checks, Guardian on and failing closed, production mode, no agent opting out, orchestrators screening input.

K9-GOV-001 … 010

Zero Trust

Enabled at the orchestrator, with signed identity rather than roles claimed in the payload.

K9-GOV-011

Kafka ownership

Only routers and orchestrators publish; agents and squads raise RequiresHIL instead.

K9-KAF-001

Secrets & configuration

No secrets in YAML, no committed .env, no private IP addresses; squad and agent YAML well formed.

K9-CFG-001 … 004 · K9-YAML-001 · 002

Framework version

The k9-aif version each solution declares, against the latest release — and whether it predates governance by construction.

K9-DEP-001 · 002

How it works

Inspection is static and deterministic: Python is read as syntax trees and YAML as data; nothing from the inspected repository is imported or run, and no model is involved, so the same commit always gives the same report.

1Track

List the applications to watch — any number, each a GitHub repository, branch and optional subfolder.

2Trigger

A GitHub push (signed webhook), a schedule that skips unchanged branches, or Inspect now for any public repository.

3Inspect

A shallow, size-limited clone is read against every registered rule.

4Report & guide

Verdict, rule pass rate and ranked findings, plus a remediation guide — stored per commit.

What you get

Sample inspection acme/claims-solution · main NON-COMPLIANT · 75%
0critical
4violations
21warnings
3advice
VIOL
orchestrators/claims_orchestrator.py:14orchestrator imports agent classes — register them in the entry point
WARN
agents/fraud_scoring_agent.py:38llm_invoke() not inside try/except
ADV
requirements.txt:2requires k9-aif>=1.4.0 — raise to the latest

Compliance report

Verdict (compliant / with warnings / non-compliant), share of rules passing, findings ranked critical → violation → warning → recommendation, each with file, line, the offending line and the fix. Markdown and JSON.

Guidelines document

A remediation plan in priority order: why each rule exists in the framework, every place it is broken, and ready-to-use Shield, Guardian and Zero Trust configuration for the governance findings.

History per application

Every inspection is kept with its trigger and commit, so you can see when a solution drifted and when it came back into line.

Same rules in CI

k9aif inspect <folder> --fail-on violation fails a build on the same findings this service reports.

Architecture

K9X Inspector is itself a solution on the framework: it installs k9-aif and runs the framework's inspection ABB (K9Inspector, BaseInspectionRule, InspectionRuleRegistry).

K9X Inspector architecture

Triggers queue inspections; one worker fetches the repository, the framework's inspector applies the rules, and the report and guidelines are stored for the UI.

Built on the K9-AIF framework

K9-AIF is an architecture-first framework for governed multi-agent systems: ABB contracts, three-layer decoupling, governance by construction with k9x Shield and Granite Guardian, Zero Trust and human-in-the-loop review. Inspector is how a team knows its solutions still follow it.

K9X StudioDesign and build solutions on the framework
K9X InspectorInspects solutions built on K9-AIF
K9X SentinelKeeps the framework current with new threats
K9X SatanSecurity analysis: red-team attacks
K9X RepositoryEnterprise architecture repository
K9X HILHuman-in-the-loop review

Scope

  • Static inspection shows that the structure governance relies on is in place — not that a running deployment behaves correctly. Runtime containment is what K9X Satan tests; human decisions are recorded in K9X HIL.
  • Public GitHub repositories, or private ones with a read-only token on the server.
  • This is an open public demonstration with sample data; do not enter real information.