Whetstone

CAT. WST‑050
MIT · NODE ≥ 22
REV. 2026‑08
An isometric pixel-art sharpening stone

Your definition of correct, enforced.

Whetstone captures what correct means in your repo as plain files in git, then enforces it with a deterministic engine that calls a model only where judgment is irreducible.

It gates your changes, whoever wrote them.

Output · the exit code is the enforcement

CodeOutcomeWhat it means about your change
0PassedEvery check that applied ran, and none of them failed.
0UncoveredNo check matched these paths. It says so rather than implying a pass, and lets you through: blocking here is what teaches people --no-verify.
1BlockedA check ran and failed. The only outcome that is a verdict on your change.
2IncompleteA check that could have blocked never ran. The gate is broken, not your change, and the two never share a message.

Four outcomes where most gates have two. Splitting failed from could not run is the difference between a gate you trust and one you learn to route around.

Operation

01wst initInterviews your repo. Reads what it declares, and asks about what it cannot know, like where a bug is expensive.
02wst gateClassifies the change, selects the checks that apply, skips whatever a receipt proves unchanged, runs the rest.
03wst signalYou record the friction the run hit. A human types this one.
04wst retroClusters the signals and proposes rule changes. It never applies them.

In a terminal, wst with no arguments opens a launcher over these commands. One row each, saying what it reads, what it writes and what its exit code means; the rows this repo cannot run yet say what they are waiting for. It runs the one you pick and comes back. Off a terminal it prints the help, because a menu waiting for a keypress in a CI job hangs where nobody can see it.

The product is three commands. wst init writes what a repo needs to verify itself, wst ready answers whether the current work is ready without being told what changed, and wst status says what is here and what is missing. wst triage and wst check remain as diagnostics.

What lands in your repository

.wst/
  constitution.md      what your project holds non-negotiable
  triage.yaml          which paths earn which discipline
  checks/              one file per check, with what earned it
  skills/              rules that travel with the repo
  memory/              decisions, signals, retro log
.githooks/pre-push   where the exit code actually stops a push
AGENTS.md            rendered from the above, never the source

Plain text, all of it. Delete the directory and the tool is gone; nothing else knows you installed it. Three runtime dependencies, no services, nothing to host.

A check Whetstone brings itself arrives switched off, with the friction that earned it recorded in the file. Its logic ships with the binary, so it runs as wst check run <id> and not as a script nobody wrote in your repo.

npm i -g @juanmzz/whetstone GitHub · npm

A judgment check earns the right to block by measurement, not by assertion: severity: block on an llm check fails to load without a calibration receipt whose hashes still recompute. This project's own review lens measured 100 of 100 correct across ten fixtures before it earned that, and the receipt binds the prompt, the fixtures, the model and the runtime, so changing any one of them drops the authority rather than carrying it over.