Plugins for Cursor, ChatGPT and Codex
One portable plugin. Your agent audits your code and adds the boundary, entirely locally.
What is inside
| Part | Name | What it does |
|---|---|---|
| Skill | fail-closed-governance | Adds a deterministic boundary to an existing project |
| Skill | governance-review | Audits for fail-open paths and bypasses |
| Skill | secure-agent-tool | Wraps one function, tool or MCP operation |
| Rule | fail-closed.mdc | Keeps agents from granting themselves authority |
| Command | /governance-review | Traces proposal → authorization → effect for every path |
| Command | /protect-tool | Wraps the selected function and adds tests |
What a review reports
For each consequential side effect it lists every path that can reach it and classifies each as one of:
FAIL_OPEN: an error, timeout or missing config grants permissionBYPASS: a path reaches the effect without the checkSELF_AUTH: the agent can grant itself authority or approvalSTALE_AUTH: authority is cached, unexpired-forever, or not re-checkedUNBOUND_EFFECT: approval applies to free text or something that can change afterwardsMISSING_RECEIPT: the action can happen with no recordPOLICY_ERROR: malformed, ambiguous or silently-defaulting policyAPPROVAL_BYPASS: high-risk action proceeds without independent approvalOK
It ends with the residual risk that remains even after fixes.
What the agent can do for you
Review a repository, identify consequential side effects and fail-open paths, propose a patch, install Core, wrap functions and tools, generate policy configuration, generate and run tests, and explain what is still risky. No account, no network calls, and no commercial service required.
Install
The plugin lives in the plugin/ folder of the repository, with a Cursor manifest, a Codex compatibility manifest and a portable Agent Plugin manifest. Marketplace listings are being prepared; until then, copy the folder into your agent's plugins location.