Skip to content
| Marketplace
Sign in
Visual Studio Code>Testing>FactoryLineNew to Visual Studio Code? Get it now.
FactoryLine

FactoryLine

Code Factory

|
2 installs
| (0) | Free
Trace AI changes from intent through six audits to reviewable proof and a human-owned release decision.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

FactoryLine for VS Code

You used an AI agent to change the app. The tests are green. Before you merge, you need one answer: could the test actually fail when the behavior is wrong?

FactoryLine starts with that question. Run a bounded local command, inspect the receipt beside the diff, and decide what needs a person—not another confident agent message. It never uploads your workspace, code, or receipts.

The proof path, in three moves

  1. Start with First Proof. Run factory first-proof --root . to challenge a test in a disposable sandbox. A test that still passes after its behavior is removed is a review signal, not a release signal.
  2. Make the handoff inspectable. If Junie, Copilot, CodeRabbit, Devin, Eve, Grok Build, or another agent supplied work, Agent Proof Bridge records the local before/after artifacts, sealed scope, checkpoints, and Oracle Contract binding in Graph Ops. It does not start agents, inherit their authority, or turn their claims into proof.
  3. Keep app-release work visible. AppForge Mission Control turns a confirmed app story into a storyboard, review queue, and evidence dossier. It can surface avoidable App Store policy and prior-rejection gaps before TestFlight; final submission stays with the human and Apple remains the decision-maker.

Your choice remains explicit throughout: inspect the evidence, approve the next boundary, or stop and repair. A green check is useful only when you can see what it actually proves.

Catch AI-generated tests that could never fail — before review. Keep the receipts and proof path next to the code, then open Graph Ops to see what is evidenced, blocked, or next. First run factory first-proof --root . to see a hollow negative control caught in a disposable sandbox, then open FactoryLine: Open Local Factory Studio or run factory mvp "Build an approval tracker" --root .. The extension never calls a starter production-ready by itself.

1.0.1 release preview: the editor surfaces typed intent-to-proof handoffs, route traces, current checkpoints, and proof-delta retry stops beside the existing First Proof and AppForge paths. Searchable audit rules and exact-hash receipt reuse make evidence easier to locate without loading the whole rule set. This is a release preview; marketplace publication requires its own verified provider read-back.

New First Lap control: factory first-lap init creates plain-language MISSION.md, END-TO-END.md, and verifier-only holdout scenarios. Critical verifiers must pass approved/defective/wrong-candidate calibration and one human-observed intake-to-handoff lap before supervised autonomy is considered. Incidents can be promoted into permanent regression gates, and only typed transient provider failures are retryable. See First Lap.

New in 0.9.4: the Oracle Firewall blocks same-ID rewrites of a blocking or release obligation's meaning, source binding, provenance, criticality, effect, or gate semantics. AppForge Oracle dossier receipts now retain a matching, hash-valid evidence path for review.

Also in 0.9.1: the Agent Proof Bridge makes an Eve, Junie, Grok Build, or generic handoff inspectable in Graph Ops. It verifies the typed DAG, sealed scope, source preconditions, real before/after artifacts, declared checkpoint continuity, and current Oracle Contract binding. It never starts or resumes an agent, posts a worklog, or inherits agent authority.

AppForge Mission Control turns a confirmed app story into a visible review path and checks 30 exact-build Apple policy and prior rejection classes before submission. Credential references—not raw secrets—can be handed to a supervised agent for evidence preparation; final TestFlight/App Review submission stays human-authorized. The workflow is designed to save avoidable rework/waiting time and minimize rejection risk, not guarantee Apple approval.

Unified Graph Ops also shows SaaS Reality receipts: whether OAuth/OIDC identity, tenant authorization, checkout, verified webhook, entitlement, feature access, and revocation agree. The core works across standards-compliant providers, keeps unknowns blocked, rejects raw credentials, and never contacts or mutates the provider.

The Open VSX extension and local proof core remain free. Every capability shipped before the transition is free through December 14, 2026. Beginning December 15, Founding Proof Pro may remain $5.95/month or $60/year for early adopters; standard Proof Pro is planned at $9/month or $90/year, AppForge Builder at $24/month or $240/year, and Team Assurance at $20 per active contributor/month annually or $24 monthly. Hosted execution is metered separately; downloading the extension and using local CLI, MCP, Studio, Graph Ops, receipts, and proof gates remain free. See the Open VSX service plan.

Commands

  • FactoryLine: Run Spec-to-Ship Assembly runs factory assemble <feature> --root <workspace>.
  • FactoryLine: Continue Assembly to Next Boundary runs the state-aware factory continue [feature] --root <workspace> workflow.
  • FactoryLine: Verify Feature Receipts runs factory verify <feature> --root <workspace>.
  • FactoryLine: Open Local Meter reads factory meter --root <workspace> --json after workspace confirmation.
  • FactoryLine: Open Latest Receipt finds JSON under .factory/ and receipts/, then renders a local receipt panel.
  • FactoryLine: Open Local Factory Studio opens the confirmed loopback target compiler.
  • FactoryLine: Open Product Missions opens Studio in deterministic PRD-to-mission mode.
  • FactoryLine: Open Unified Graph Ops opens the bounded, read-only local evidence map.
  • Verifier Plane (terminal workflow) runs factory verifier session|verify|progress to bind independent worker/verifier evidence, deterministic checks, and hard budgets. It validates supplied receipts; it does not execute or sandbox a runner.
  • PRD Grill (terminal workflow) runs factory prd grill PRD.md --root <workspace> to create a capped, source-bound clarification sheet before PRD optimization or compilation. It never rewrites the PRD or starts a build.
  • Requirement IDs such as REQ-*, FR-*, and NFR-* receive a read-only CodeLens that opens matching local proof in .factory, receipts, coverage, tests, or specs.

Each command requires a trusted VS Code workspace. FactoryLine accepts only a feature name containing letters, digits, hyphens, and underscores; it does not pass arbitrary shell fragments to your terminal.

For a GitHub pull request, the optional factory github proof-review workflow can publish the same deterministic proof facts beside CodeRabbit or another AI reviewer. It does not require their account, import their comments as proof, auto-approve, merge, or modify source.

For a team-operated agent change, run the CLI’s factory plan verify in the trusted workspace and attach the optional local JSON/Markdown/Mermaid packet to the review. It makes approved scope alignment and Proof Debt visible; it does not add an autonomous extension action, execute tests, approve, merge, or modify source. See the Teams and Enterprise Operations Manual for role boundaries and rollout.

For UI-scoped work, add the optional Prestige Design Review to the same local evidence path. It supplies a purpose-led design brief and review artifacts for hierarchy, responsive behavior, affordances, consistency, and design tokens. The extension does not apply a design change or treat a visual score as production readiness.

Expected outcomes

Code Factory was built first for the creator's own AI-assisted workflow. A 60-day local Codex metadata slice observed 25 related tasks, 133 completed turns, 2,710 command runs, 785 MCP or app calls, and 555 file-change events. A separate, transparent counterfactual model estimates 30–110 gross manual-equivalent hours over the period after a 50% overlap haircut, or 15–55 hours per month. At an illustrative loaded rate of $75–$150/hour, that is $2,250–$16,500 of modeled gross capacity value.

This is one user's case—not a benchmark, guaranteed ROI, or verified cash saving. Net savings must subtract tool cost and human oversight. For vibe coders, the practical target is less context reconstruction and fewer false "done" states. For engineers, it is reviewable proof beside the diff. For teams and enterprises, it is repeatable evidence with explicit human authority.

Code Factory 60-day personal case study

Install

Install the Code Factory CLI first:

pip install factoryline-code-factory
factory first-proof --root .

Build a local VSIX from this directory, then install it in VS Code:

npm ci
npm run package
code --install-extension factoryline-vscode-1.0.1.vsix

Set factoryline.command if the factory executable is not on VS Code's PATH. Product Missions create only supervised, approval-required local packets and do not grant execute, merge, deploy, publish, connector, credential, or messaging authority. Requirement CodeLens navigation reads bounded local text artifacts only; it does not run FactoryLine or change approval state.

If this free, local-first workflow helps, use the post-success Star Code Factory action or visit the GitHub repository. That action is optional, opens only GitHub when selected, and sends no workspace data.

Code Factory 0.20 also includes an optional hosted GitHub PR-assurance adapter, durable mission graphs, and secret-free BYOK policies. VS Code workspaces use those controls through the local factory CLI or loopback Studio; the extension never stores provider keys. It is deployed separately from this local editor extension; see Hosted PR assurance.

Scope

This is the VS Code adapter. The separate JetBrains Platform adapter and its compatibility boundary are documented in docs/INTELLIJ.md.

Verifier Plane

factory verifier separates a worker's candidate receipt from a distinct verifier's evidence. It rejects self-verification, drift, path escape, false passing checks, and declared budget overrun. Graph Ops renders a bound session as runtime-unattested until independently supplied evidence is verified; this adapter does not claim to execute or enforce a sandbox.

Contradiction gate

factory cdte scan detects architecturally incompatible NFR pairs before any code is generated, by deterministic lookup over a decision table. No model is called. Analysis is tiered measured / modeled / structural, and a modeled analysis whose inputs are absent is withheld rather than estimated. Critical and high severity conflicts engage the fail-closed boundary and pause the line at nfr_conflict.

Habituation gate

factory habituation status calibrates the human approval signal against each reviewer's own baseline and escalates: surface, second approver, fail closed. Blocking is refused until blind-spot re-review outcomes correct the proxy. Public exports carry distributions only, never per-reviewer rows.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft