RepoGuard MCP Server

Zero-dependency Clean Architecture linter and context generator MCP server for Claude Desktop, Claude Code, and Cursor.

Documentation

๐Ÿ›ก๏ธ RepoGuard

RepoGuard Banner

The Architecture Guardian for AI-Assisted Codebases.
Stop AI from turning your repository into architectural spaghetti across TypeScript, Python, and Golang in ~12ms.

RepoGuard on Product Hunt

GitHub Stars CI & Architecture Guard npm version downloads RepoGuard MCP server Listed on mcpservers.org Marketplace License Live Playground

๐ŸŽฎ Try it in your browser: RepoGuard Interactive Playground โ€” Audit code snippets in real-time with zero install.


โšก The Problem

AI coding assistants (Cursor, GitHub Copilot, Claude Code, Windsurf) write 300 lines of code in seconds. However, without strict repository guardrails, they frequently introduce AI Code Rot:

  1. Bypass Architectural Layers: Run raw database queries (Prisma, Drizzle, SQLAlchemy, GORM) directly inside UI components or HTTP handlers.
  2. Reinvent Existing Helpers: Write duplicate date/string utilities instead of importing from /utils or shared packages.
  3. Escape Type Safety & Error Handling: Scatter : any in TypeScript or discard errors with _ = err in Go to pass quick compilation.
  4. Leak Sensitive Secrets: Hardcode mock API keys or prefix private secrets with NEXT_PUBLIC_, bundling them into client-side JS.

RepoGuard acts as an automated architecture supervisor: it generates strict, customized .cursorrules, CLAUDE.md, and .windsurfrules context files, verifies pre-commit diffs in ~12ms, runs an MCP server for live agent consultation, and performs inline audits on every Pull Request.


๐Ÿš€ Quickstart

Run directly in any repository (zero installation required):

npx repoguard-rules init

Or install globally:

npm install -g repoguard-rules
repoguard init

What happens in 2 seconds:

  • ๐Ÿ” Auto-detects your tech stack (Next.js, NestJS, Express, FastAPI, Django, Gin, Fiber, Prisma, GORM, etc.).
  • ๐Ÿ“ Generates tailored .cursorrules (for Cursor AI).
  • ๐Ÿค– Generates a comprehensive CLAUDE.md (for Claude Code).
  • ๐ŸŒŠ Generates .windsurfrules (for Windsurf IDE).
  • ๐Ÿ›ก๏ธ Generates .github/copilot-instructions.md (for GitHub Copilot).
  • โš™๏ธ Configures pre-commit guard hooks & CI workflow.

๐Ÿค– Native MCP Server (Model Context Protocol)

RepoGuard v1.6.1 features a zero-dependency, JSON-RPC 2.0 stdio MCP Server. Connect it to Cursor, Claude Desktop, or any MCP-compatible coding client so your AI agent can audit code and verify guardrails autonomously:

1. Cursor Configuration (~/.cursor/mcp.json or .cursor/mcp.json):

{
  "mcpServers": {
    "repoguard": {
      "command": "npx",
      "args": ["-y", "repoguard-rules@1.6.1", "mcp"]
    }
  }
}

2. Claude Desktop Configuration (claude_desktop_config.json):

{
  "mcpServers": {
    "repoguard": {
      "command": "npx",
      "args": ["-y", "repoguard-rules@1.6.1", "mcp"]
    }
  }
}

Available MCP Tools:

  • repoguard_audit: Performs a comprehensive architectural audit of the project root and returns health metrics and grade (A+ to F).
  • repoguard_get_rules: Retrieves all built-in guardrails for TypeScript, Python, and Go for LLM prompt context injection.
  • repoguard_analyze_diff: Analyzes a code diff or snippet before writing to disk, catching violations before they happen.

๐Ÿ› ๏ธ CLI Commands & Formats

CommandDescription
npx repoguard-rules initScans codebase and generates tailored AI context files.
npx repoguard-rules auditEvaluates entire codebase and returns an Architectural Health Score (A+ to F).
npx repoguard-rules mcpStarts the Model Context Protocol stdio server for Claude & Cursor.
npx repoguard-rules fixInteractively inspects violations and outputs refactoring plans.
npx repoguard-rules audit --format=sarifGenerates standard OASIS SARIF v2.1.0 for GitHub Code Scanning integration.
npx repoguard-rules audit --format=jsonOutputs machine-readable JSON for custom CI/CD pipelines.
npx repoguard-rules diffAudits uncommitted git diffs against architectural rules in real-time.
npx repoguard-rules hook installConfigures local .git/hooks/pre-commit to prevent rule breaches.
npx repoguard-rules rulesDisplays all 12 built-in architectural rules and descriptions.

Ignoring Files & Folders (.repoguardignore)

Add a .repoguardignore file to your root directory to skip specific files or directories:

# .repoguardignore
legacy/
migrations/
test/fixtures/

๐Ÿ›ก๏ธ Built-in Architectural Rules

Rule IDCategorySeverityGuardrail Enforced
RULE-01ArchitectureErrorProhibits raw ORM/DB queries in UI components and Controllers (TS/JS).
RULE-PY-01ArchitectureWarning / CriticalEnforces FastAPI layer separation; forbids direct DB queries and raw commits (db.commit()) inside route handlers.
RULE-GO-01ArchitectureWarning / CriticalEnforces Clean Architecture in Go; prohibits raw database/GORM operations inside Gin, Fiber, or Echo HTTP handlers.
RULE-GO-02Error HandlingWarningFlags unchecked errors silenced via blank identifier (_ = err) in Go.
RULE-02SecurityCriticalFlags hardcoded secrets, private keys, and API tokens.
RULE-09SecurityCriticalFlags private secrets exposed via public prefixes (NEXT_PUBLIC_*SECRET*, VITE_*SECRET*).
RULE-03Type SafetyWarningForbids lazy : any and as any escape hatches in TypeScript.
RULE-04Code QualityInfoEnforces structured logging instead of raw console.log.
RULE-05Next.js / SSRErrorPrevents hydration mismatch from browser globals (window/localStorage).
RULE-06SecurityCriticalDetects SQL injection hazards in raw query string interpolations.
RULE-07API DesignWarningEnforces schema validation (Zod/Pydantic) on incoming request payloads.
RULE-08DRY PrincipleInfoPrevents AI assistants from duplicating existing common utility helpers.

๐Ÿค– GitHub Action & Security Integration

RepoGuard dogfoods its own architecture on every push. You can add continuous architectural enforcement to your CI/CD pipeline using the official Action:

# .github/workflows/ci.yml
name: CI & Architecture Guard

on:
  push:
    branches: [ main ]
  pull_request:
    branches: [ main ]

jobs:
  audit:
    name: Unit Tests & Dogfood Audit
    runs-on: ubuntu-latest
    steps:
      - name: Checkout Code
        uses: actions/checkout@v4

      - name: Setup Node.js
        uses: actions/setup-node@v4
        with:
          node-version: 20

      - name: Run Architecture & Stack Tests
        run: npm test

      - name: Dogfood Audit (RepoGuard on RepoGuard)
        run: node bin/repoguard.js audit --strict

GitHub Code Scanning (SARIF v2.1.0):

      - run: npx repoguard-rules audit --format=sarif > repoguard.sarif
      - uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: repoguard.sarif

๐Ÿ’Ž Plans & Enterprise Upgrades

RepoGuard is 100% free and open-source for public repositories and local development. For automated CI/CD PR enforcement, private teams, and custom architectural rule engines:

TierPriceIdeal ForWhat's Included
Open Source$0 (Free Forever)Solo builders & public reposUnlimited local CLI scans, .cursorrules, CLAUDE.md, MCP Server, pre-commit hooks, all 12 built-in rules
Developer Pro$12 / monthIndependent engineers & contractorsUnlimited private repositories, automated PR Review Bot, custom rules engine, secret leak detector
Engineering Team$39 / monthStartups & engineering orgsUp to 5 devs, GitHub Org-wide CI/CD merge blocker, SOC2 architecture audit logs, Slack/Discord alerts

๐Ÿ‘‰ Subscribe to Developer Pro ($12/mo) โ€ข Upgrade Team ($39/mo) โ€ข ๐Ÿ‡ง๐Ÿ‡ท Pagar no PIX (R$ 67 ร  vista)


๐Ÿ“ˆ Star History

Star History Chart


๐Ÿ‘ฅ Contributors & Community

Special thanks to the open source engineers contributing to RepoGuard:

๐ŸŒŸ Support & Community

If RepoGuard helps keep your AI coding clean, consider giving this repository a โญ Star!