ai-core
AI 代理安全与规划的核心护栏
插件: boundary-arch-hardening complexity-loc-budgets deadcode-orphan-api paranoid-tool-policy plan-diff-scope spec-adr-gate surface-contract-guard
直接使用已签名的注册表(无需克隆仓库)。
ai-dx-mcp plugins install --registry https://github.com/AmirTlinov/compas-plugin-registry/releases/latest/download/registry.manifest.v1.json --admin-lane --plugins <plugin-id> --repo-root /path/to/your/projectai-dx-mcp plugins install --registry https://github.com/AmirTlinov/compas-plugin-registry/releases/latest/download/registry.manifest.v1.json --admin-lane --packs <pack-id> --repo-root /path/to/your/projectAI 代理安全与规划的核心护栏
插件: boundary-arch-hardening complexity-loc-budgets deadcode-orphan-api paranoid-tool-policy plan-diff-scope spec-adr-gate surface-contract-guard
Entropy-control rails for long-lived typed AI-first repos; scans typed change memory, not legacy exec-plan or review JSON truth.
插件: context-budget docs-graph golden-principles-enforcer quality-summary-report stale-artifact-scanner
Flagship typed-change proof rails for AI-first repos, without legacy truth-surface shims.
插件: boundary-arch-hardening change-contract complexity-loc-budgets deadcode-orphan-api docs-graph lease-lock merge-truth-contract paranoid-tool-policy projection-integrity review-matrix structured-report-ingestion surface-contract-guard
Quality-first non-authoring rails for code repositories; compas provides objective feedback without materializing repo truth surfaces.
插件: boundary-arch-hardening complexity-loc-budgets coverage-nonregression deadcode-orphan-api lint-unified-gate paranoid-tool-policy perf-regression-budget quality-summary-report reuse-report-gate surface-contract-guard tests-junit-gate worktree-isolation-guard
Experimental runtime, observability, and UI harness rails for bootable AI-first repos.
插件: app-lifecycle-harness lease-lock observability-agent-gate ui-validation-gate worktree-isolation-guard
安装全部已注册插件(包括可选与高级检查)
插件: app-lifecycle-harness boundary-arch-hardening change-contract complexity-loc-budgets context-budget coverage-nonregression deadcode-orphan-api docs-graph docs-no-drift exceptions-ttl-guard golden-principles-enforcer lease-lock lint-unified-gate log-pii-guard merge-truth-contract observability-agent-gate paranoid-tool-policy perf-regression-budget plan-diff-scope projection-integrity provenance-attestation quality-summary-report release-readiness-gate reuse-report-gate review-matrix sast-semgrep-gate sbom-gate secrets-leak-guard spec-adr-gate stale-artifact-scanner structured-report-ingestion supply-chain-hygiene surface-contract-guard tests-junit-gate ui-validation-gate worktree-isolation-guard
质量、测试、文档与非回退检查
插件: coverage-nonregression docs-no-drift exceptions-ttl-guard lint-unified-gate perf-regression-budget quality-summary-report release-readiness-gate reuse-report-gate structured-report-ingestion tests-junit-gate
安全、密钥泄露与供应链安全 gates
插件: log-pii-guard provenance-attestation sast-semgrep-gate sbom-gate secrets-leak-guard supply-chain-hygiene
推荐安全默认:仅社区稳定检查;不包含 experimental/deprecated 插件
插件: boundary-arch-hardening complexity-loc-budgets coverage-nonregression deadcode-orphan-api docs-no-drift exceptions-ttl-guard lint-unified-gate log-pii-guard paranoid-tool-policy plan-diff-scope provenance-attestation reuse-report-gate sast-semgrep-gate sbom-gate secrets-leak-guard spec-adr-gate supply-chain-hygiene surface-contract-guard tests-junit-gate
显示 38 共 38.
没有符合筛选条件的插件。
Run a repo-declared start-readiness-smoke-teardown runtime harness
面向多语言项目的架构分层与边界策略加固(反“意大利面”)
Validate typed change capsule frontmatter, required sections, and lease declarations
为多语言仓库设置复杂度与代码行数(LOC)预算,防止 AI 生成“单体”
Validate typed context-budget limits across active change capsules and projection manifests
覆盖率非回退保护(防止 coverage 下降)
检测多语言 runtime 源码中的死私有符号与“孤儿”公共 API
Validate docs-router, change-capsule graph files, and stale capsule freshness windows
文档同步的 no‑drift 检查:架构与文档契约一致性
用于社区上手的参考最小插件
P16:对 allowlist 例外强制 TTL/过期/预算规则
Validate a compact PHILOSOPHY.md golden-principles contract for AI-first repositories
Validate typed lease policy and detect conflicting active change leases
P19:为 Rust/Python/JS/TS 质量检查接入统一 lint gate
防止日志中泄露 PII 与密钥
Assemble canonical merge-readiness proof from existing compas witness state and repo-local review truth
Validate repo-local observability reports, logs, metrics, and traces
严格工具执行的“偏执”工具策略护栏
性能回退预算 gate:用于 AI 修改与 runtime 影响检查
P03:强制检查“计划 ↔ diff”的范围一致性
Validate typed projection manifest integrity for change-capsule projections
Provenance/attestation gate:用于发布产物完整性与信任
Check and refresh the machine-readable quality summary witness from canonical compas gate outputs
CI/CD 发布就绪检查:确保确定性的发布
P05:带 reuse-report 工具的 gate 扩展(反复制粘贴)
Validate legacy JSON review artifacts and witness references for compatibility-mode merge lanes
Validate review-matrix policy and change-capsule lens requirements by risk tier
P12:将 Semgrep 安全扫描接入 gate 流程
SBOM gate:用于依赖清单与 lockfile 可追踪性
密钥泄露防护:阻止 secret 暴露
Spec/ADR gate:在实现前强制目标/非目标/验收标准/边界情况/回滚方案
Scan for stale plans, review artifacts, and orphaned evidence files
在 gates 中验证并强制结构化报告产物(SARIF/JUnit/JSON)
供应链 gate:要求确定性的依赖 lockfile 与稳定版本
通过显式 baselines 防止公共 API surface 膨胀与契约破坏
P14:在 gate 中强制 JUnit 规范化的测试执行
Validate repo-produced UI smoke reports, screenshots, and DOM assertions
Validate deterministic per-worktree state, log, temp, and port isolation config