ai-core
Core AI-agent safety and planning rails
Plugins: boundary-arch-hardening complexity-loc-budgets deadcode-orphan-api paranoid-tool-policy plan-diff-scope spec-adr-gate surface-contract-guard
Works directly with the signed registry (no cloning).
ai-dx-mcp plugins install --registry https://github.com/AmirTlinov/compas-plugin-registry/releases/latest/download/registry.manifest.v1.json --admin-lane --plugins <plugin-id> --repo-root /path/to/your/projectai-dx-mcp plugins install --registry https://github.com/AmirTlinov/compas-plugin-registry/releases/latest/download/registry.manifest.v1.json --admin-lane --packs <pack-id> --repo-root /path/to/your/projectCore AI-agent safety and planning rails
Plugins: boundary-arch-hardening complexity-loc-budgets deadcode-orphan-api paranoid-tool-policy plan-diff-scope spec-adr-gate surface-contract-guard
Entropy-control rails for long-lived typed AI-first repos; scans typed change memory, not legacy exec-plan or review JSON truth.
Plugins: context-budget docs-graph golden-principles-enforcer quality-summary-report stale-artifact-scanner
Flagship typed-change proof rails for AI-first repos, without legacy truth-surface shims.
Plugins: boundary-arch-hardening change-contract complexity-loc-budgets deadcode-orphan-api docs-graph lease-lock merge-truth-contract paranoid-tool-policy projection-integrity review-matrix structured-report-ingestion surface-contract-guard
Quality-first non-authoring rails for code repositories; compas provides objective feedback without materializing repo truth surfaces.
Plugins: boundary-arch-hardening complexity-loc-budgets coverage-nonregression deadcode-orphan-api lint-unified-gate paranoid-tool-policy perf-regression-budget quality-summary-report reuse-report-gate surface-contract-guard tests-junit-gate worktree-isolation-guard
Experimental runtime, observability, and UI harness rails for bootable AI-first repos.
Plugins: app-lifecycle-harness lease-lock observability-agent-gate ui-validation-gate worktree-isolation-guard
Install all registered plugins, including optional and advanced checks.
Plugins: app-lifecycle-harness boundary-arch-hardening change-contract complexity-loc-budgets context-budget coverage-nonregression deadcode-orphan-api docs-graph docs-no-drift exceptions-ttl-guard golden-principles-enforcer lease-lock lint-unified-gate log-pii-guard merge-truth-contract observability-agent-gate paranoid-tool-policy perf-regression-budget plan-diff-scope projection-integrity provenance-attestation quality-summary-report release-readiness-gate reuse-report-gate review-matrix sast-semgrep-gate sbom-gate secrets-leak-guard spec-adr-gate stale-artifact-scanner structured-report-ingestion supply-chain-hygiene surface-contract-guard tests-junit-gate ui-validation-gate worktree-isolation-guard
Quality, test, docs, and non-regression checks
Plugins: coverage-nonregression docs-no-drift exceptions-ttl-guard lint-unified-gate perf-regression-budget quality-summary-report release-readiness-gate reuse-report-gate structured-report-ingestion tests-junit-gate
Security, secret-leak, and supply-chain safety gates
Plugins: log-pii-guard provenance-attestation sast-semgrep-gate sbom-gate secrets-leak-guard supply-chain-hygiene
Recommended safe defaults: community-stable checks only; no experimental/deprecated plugins.
Plugins: boundary-arch-hardening complexity-loc-budgets coverage-nonregression deadcode-orphan-api docs-no-drift exceptions-ttl-guard lint-unified-gate log-pii-guard paranoid-tool-policy plan-diff-scope provenance-attestation reuse-report-gate sast-semgrep-gate sbom-gate secrets-leak-guard spec-adr-gate supply-chain-hygiene surface-contract-guard tests-junit-gate
Showing 38 of 38.
No plugins match your filters.
Run a repo-declared start-readiness-smoke-teardown runtime harness
Architecture layers + boundary policy hardening (anti-spaghetti) for polyglot projects
Validate typed change capsule frontmatter, required sections, and lease declarations
Complexity and LOC budgets for polyglot repositories to prevent AI-generated monoliths
Validate typed context-budget limits across active change capsules and projection manifests
Coverage non-regression guard for quality posture
Detect dead private symbols and orphaned public API in polyglot runtime sources
Validate docs-router, change-capsule graph files, and stale capsule freshness windows
Docs sync no-drift checks for architecture and documentation contract health
Reference minimal plugin for community onboarding
P16 enforce TTL, expiry and budget rules for allowlist exceptions
Validate a compact PHILOSOPHY.md golden-principles contract for AI-first repositories
Validate typed lease policy and detect conflicting active change leases
P19 plugin wires a unified lint gate for rust, python, and js/ts quality checks
Prevent PII and secret leaks in logging output
Assemble canonical merge-readiness proof from existing compas witness state and repo-local review truth
Validate repo-local observability reports, logs, metrics, and traces
Paranoid Tool Policy guardrail for strict tool execution
Performance Regression Budget gate for AI edits and runtime-impact checks.
P03 plugin enforces plan-to-diff scope consistency checks
Validate typed projection manifest integrity for change-capsule projections
Provenance and attestation gate for release artifact integrity and trust.
Check and refresh the machine-readable quality summary witness from canonical compas gate outputs
CI/CD release-readiness enforcement for deterministic publishing
P05 gate extension with reuse-report tool
Validate legacy JSON review artifacts and witness references for compatibility-mode merge lanes
Validate review-matrix policy and change-capsule lens requirements by risk tier
P12 wiring: add Semgrep security scan into gate flow
SBOM gate plugin for dependency manifests and lockfile traceability
Secrets Leakage Guard plugin for blocking secret exposure checks.
Spec/ADR gate plugin: enforce goal, non-goals, acceptance, edge-cases and rollback before implementation
Scan for stale plans, review artifacts, and orphaned evidence files
Validate and enforce structured report artifacts (SARIF/JUnit/JSON) in gates
Supply-chain gate for deterministic dependency lockfiles and stable versions
Guard public API surface growth and contract breaks with explicit baselines
P14 enforces normalized JUnit-aware test execution in gate
Validate repo-produced UI smoke reports, screenshots, and DOM assertions
Validate deterministic per-worktree state, log, temp, and port isolation config