Point K9X Inspector at your GitHub repositories. On every push, or on a schedule, it reads each solution — never running it — and reports where the code departs from the framework: contracts, layering, the governed model path, Shield and Guardian, Zero Trust, secrets and the framework version. Every finding comes with the file, the line and the fix.
28 rules in eight areas. The rules are part of the framework itself (k9_aif_abb.k9_inspect), so
the command line, CI and this service apply exactly the same checks.
Agents extend BaseAgent or another agent ABB, so governance wraps them; loop agents keep their loop.
Router → Orchestrators → Squads → Agents; each layer knows only the one below.
Every model call goes through llm_invoke() — where governance, retries and the call trace live.
Shield enabled with checks, Guardian on and failing closed, production mode, no agent opting out, orchestrators screening input.
Enabled at the orchestrator, with signed identity rather than roles claimed in the payload.
Only routers and orchestrators publish; agents and squads raise RequiresHIL instead.
No secrets in YAML, no committed .env, no private IP addresses; squad and agent YAML well formed.
The k9-aif version each solution declares, against the latest release — and whether it predates governance by construction.
Inspection is static and deterministic: Python is read as syntax trees and YAML as data; nothing from the inspected repository is imported or run, and no model is involved, so the same commit always gives the same report.
List the applications to watch — any number, each a GitHub repository, branch and optional subfolder.
A GitHub push (signed webhook), a schedule that skips unchanged branches, or Inspect now for any public repository.
A shallow, size-limited clone is read against every registered rule.
Verdict, rule pass rate and ranked findings, plus a remediation guide — stored per commit.
orchestrators/claims_orchestrator.py:14orchestrator imports agent classes — register them in the entry pointagents/fraud_scoring_agent.py:38llm_invoke() not inside try/exceptrequirements.txt:2requires k9-aif>=1.4.0 — raise to the latestVerdict (compliant / with warnings / non-compliant), share of rules passing, findings ranked critical → violation → warning → recommendation, each with file, line, the offending line and the fix. Markdown and JSON.
A remediation plan in priority order: why each rule exists in the framework, every place it is broken, and ready-to-use Shield, Guardian and Zero Trust configuration for the governance findings.
Every inspection is kept with its trigger and commit, so you can see when a solution drifted and when it came back into line.
k9aif inspect <folder> --fail-on violation fails a build on the
same findings this service reports.
K9X Inspector is itself a solution on the framework: it installs k9-aif and runs the framework's inspection
ABB (K9Inspector, BaseInspectionRule, InspectionRuleRegistry).
Triggers queue inspections; one worker fetches the repository, the framework's inspector applies the rules, and the report and guidelines are stored for the UI.
K9-AIF is an architecture-first framework for governed multi-agent systems: ABB contracts, three-layer decoupling, governance by construction with k9x Shield and Granite Guardian, Zero Trust and human-in-the-loop review. Inspector is how a team knows its solutions still follow it.