Plugins

Plugins for Cursor, ChatGPT and Codex

One portable plugin. Your agent audits your code and adds the boundary, entirely locally.

What is inside

PartNameWhat it does
Skillfail-closed-governanceAdds a deterministic boundary to an existing project
Skillgovernance-reviewAudits for fail-open paths and bypasses
Skillsecure-agent-toolWraps one function, tool or MCP operation
Rulefail-closed.mdcKeeps agents from granting themselves authority
Command/governance-reviewTraces proposal → authorization → effect for every path
Command/protect-toolWraps the selected function and adds tests

What a review reports

For each consequential side effect it lists every path that can reach it and classifies each as one of:

It ends with the residual risk that remains even after fixes.

What the agent can do for you

Review a repository, identify consequential side effects and fail-open paths, propose a patch, install Core, wrap functions and tools, generate policy configuration, generate and run tests, and explain what is still risky. No account, no network calls, and no commercial service required.

Install

The plugin lives in the plugin/ folder of the repository, with a Cursor manifest, a Codex compatibility manifest and a portable Agent Plugin manifest. Marketplace listings are being prepared; until then, copy the folder into your agent's plugins location.