Observed Signal · Jun 28, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Neutral
Infrawise: CI Checks to Block AI-Generated Infra Mistakes
The article introduces infrawise check, a CI build-step that analyzes a codebase alongside live infrastructure (DynamoDB schemas, PostgreSQL indexes, Lambda usage) and fails the build when AI-generated or other code would introduce infrastructure anti-patterns such as full table scans or missing indexes. infrawise provides blocking findings with table- and caller-specific details, a severity gating flag (--fail-on high|medium|low) for CI integration (example shown for GitHub Actions), and an infrawise.yaml configuration that supports environment-variable substitution and scoped table analysis. The tool requires read-only AWS permissions (e.g., dynamodb:ListTables, dynamodb:DescribeTable) and is intended to catch regressions that static analysis, tests, and code review cannot detect because they lack live infrastructure context.
Practical developer tooling that can prevent infrastructure regressions caused by AI-generated code; useful for software reliability but not industry-shifting for AdTech/MarTech.
Track npm Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- infrawise check is a CI step that reads live infrastructure metadata (DynamoDB schemas, PostgreSQL indexes, Lambda usage) and fails the build on blocking findings.
- The tool reports blocking findings with specific table names and caller functions (example: HIGH full table scan on DynamoDB table "Orders").
- CI integration supports a severity gate via --fail-on with values high (default), medium, and low to control which severities block the build.
- infrawise.yaml supports environment-variable substitution (e.g., ${DB_PASSWORD}) and scoped includeTables to limit analysis.
- For AWS access infrawise operates read-only and needs minimal IAM permissions such as dynamodb:ListTables and dynamodb:DescribeTable.
Connected Companies & Entities
3 Entities mapped“GitHub · npm...”
“Claude Code wrote it; nobody caught it because nobody — not the reviewer, not the tests, not the linter — had any way to know that Orders ha...”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Zapier Launches AI Guardrails for Inline Workflow Safety
Zapier announced AI Guardrails, a new set of inline safety checks that run inside automated workflows to detect PII, prompt injection attempts, jailbreaking, toxic content, and sentiment issues before AI outputs reach downstream systems. The feature can scan for more than 30 PII types (credit cards, SSNs, emails, addresses), block or redact detected data, and return structured results that teams can route, block, or escalate using Zapier paths and filters without code. AI Guardrails integrates across Zapier Zaps, Agents, and MCP-connected tools and can be called by AI clients such as Cursor and Claude. Zapier positions the capability as an enforcement layer to operationalize AI safety policies directly within production workflows to reduce incidents and increase trust in automated AI-driven processes.
Contract Checks Prevent AI's Plausible-But-Wrong Code
A developer ran an experiment building a Cloudflare SvelteKit booking app using an AI-assisted scaffold (npm create microservices-app) and then deliberately introduced a typical AI-agent mistake: inlining a database write in a route and bypassing a verified booking use-case that enforced slot-conflict protection. The project ships executable contracts (README.agent.md, docs/api-boundary.md and microservices.check.mjs). Running the provided microservices check flagged the exact file and contract violation, forcing restoration of the verified delegation. The post recommends a three-move pattern for agent-driven development: push dangerous logic behind named boundaries, write machine-readable contract checks that assert the boundary held, and run those checks in the agent loop. The author cites Veracode (2025) statistics about developer AI usage and vulnerabilities to underscore risk.
Architecture Fitness Tests Prevent AI Code Breakages
A developer describes building an AI-agent and IoT production boilerplate (FastAPI, asyncpg, LangGraph, MQTT, pgvector) and encountering architectural violations when using Claude Code and Cursor to refactor code. To prevent silent architectural drift, the author created 18 static "architecture fitness" tests that parse Python source with the stdlib ast module (no external dependencies) and run in ~0.4 seconds as a pre-commit gate. The tests enforce boundaries (forbidden imports, async/sync constraints, Redis key conventions, migration rules, trace-id contracts, etc.). Combined with a CLAUDE.md repository contract file (correct vs wrong examples), the approach caught 12+ violations before the tests and zero afterward, enabling AI-assisted refactoring without breaking critical hot-path performance characteristics.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
