npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

repoguard-rules

v1.6.1

Published

The Architecture Guardian for AI-assisted codebases. Enforces clean layers, generates .cursorrules & CLAUDE.md for TypeScript, Python and Golang, and audits PRs in real-time.

Downloads

1,785

Readme

🛡️ RepoGuard


⚡ The Problem

AI coding assistants (Cursor, GitHub Copilot, Claude Code, Windsurf) write 300 lines of code in 5 seconds. However, without strict repository guardrails, they frequently:

  1. Bypass Architectural Layers: Run raw database queries (Prisma, Drizzle, SQLAlchemy, GORM) directly inside UI components or HTTP handlers.
  2. Reinvent Existing Helpers: Write duplicate date/string utilities instead of importing from /utils or shared packages.
  3. Escape Type Safety & Error Handling: Scatter : any in TypeScript or discard errors with _ = err in Go to pass quick compilation.
  4. Leak Sensitive Secrets: Hardcode mock API keys or prefix private secrets with NEXT_PUBLIC_, bundling them into client-side JS.

RepoGuard acts as an automated architecture supervisor: it generates strict, customized .cursorrules, CLAUDE.md, and .windsurfrules context files, verifies pre-commit diffs, and runs inline audits on every Pull Request.


🚀 Quickstart

Run directly in any repository (zero installation required):

npx repoguard-rules init

Or install globally:

npm install -g repoguard-rules
repoguard init

What happens in 2 seconds:

  • 🔍 Auto-detects your tech stack (Next.js, NestJS, Express, FastAPI, Django, Gin, Fiber, Prisma, GORM, etc.).
  • 📝 Generates tailored .cursorrules (for Cursor AI).
  • 🤖 Generates a comprehensive CLAUDE.md (for Claude Code).
  • 🌊 Generates .windsurfrules (for Windsurf IDE).
  • 🛡️ Generates .github/copilot-instructions.md (for GitHub Copilot).
  • ⚙️ Configures pre-commit guard hooks & CI workflow.

🛠️ CLI Commands & Formats

| Command | Description | | :--- | :--- | | npx repoguard-rules init | Scans codebase and generates tailored AI context files. | | npx repoguard-rules audit | Evaluates entire codebase and returns an Architectural Health Score (A+ to F). | | npx repoguard-rules audit --format=sarif | Generates standard OASIS SARIF v2.1.0 for GitHub Code Scanning integration. | | npx repoguard-rules audit --format=json | Outputs machine-readable JSON for custom CI/CD pipelines. | | npx repoguard-rules diff | Audits uncommitted git diffs against architectural rules in real-time. | | npx repoguard-rules hook install | Configures local .git/hooks/pre-commit to prevent rule breaches. | | npx repoguard-rules rules | Displays all 12 built-in architectural rules and descriptions. |

Ignoring Files & Folders (.repoguardignore)

Add a .repoguardignore file to your root directory to skip specific files or directories:

# .repoguardignore
legacy/
migrations/
test/fixtures/

🛡️ Built-in Architectural Rules

| Rule ID | Category | Severity | Guardrail Enforced | | :--- | :--- | :--- | :--- | | RULE-01 | Architecture | Error | Prohibits raw ORM/DB queries in UI components and Controllers (TS/JS). | | RULE-PY-01 | Architecture | Warning / Critical | Enforces FastAPI layer separation; forbids direct DB queries and raw commits (db.commit()) inside route handlers. | | RULE-GO-01 | Architecture | Warning / Critical | Enforces Clean Architecture in Go; prohibits raw database/GORM operations inside Gin, Fiber, or Echo HTTP handlers. | | RULE-GO-02 | Error Handling | Warning | Flags unchecked errors silenced via blank identifier (_ = err) in Go. | | RULE-02 | Security | Critical | Flags hardcoded secrets, private keys, and API tokens. | | RULE-09 | Security | Critical | Flags private secrets exposed via public prefixes (NEXT_PUBLIC_*SECRET*, VITE_*SECRET*). | | RULE-03 | Type Safety | Warning | Forbids lazy : any and as any escape hatches in TypeScript. | | RULE-04 | Code Quality | Info | Enforces structured logging instead of raw console.log. | | RULE-05 | Next.js / SSR | Error | Prevents hydration mismatch from browser globals (window/localStorage). | | RULE-06 | Security | Critical | Detects SQL injection hazards in raw query string interpolations. | | RULE-07 | API Design | Warning | Enforces schema validation (Zod/Pydantic) on incoming request payloads. | | RULE-08 | DRY Principle | Info | Prevents AI assistants from duplicating existing common utility helpers. |


🤖 GitHub Action & Security Integration

Add continuous architectural enforcement to your CI/CD pipeline:

# .github/workflows/repoguard.yml
name: RepoGuard Architecture Audit
on: [pull_request]

jobs:
  audit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with:
          node-version: 20
      - run: npx repoguard-rules audit --strict

GitHub Code Scanning (SARIF):

      - run: npx repoguard-rules audit --format=sarif > repoguard.sarif
      - uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: repoguard.sarif

💎 Plans & Enterprise Upgrades

RepoGuard is 100% free and open-source for public repositories and local development. For automated CI/CD PR enforcement, private teams, and custom architectural rule engines:

| Tier | Price | Ideal For | What's Included | | :--- | :--- | :--- | :--- | | Open Source | $0 (Free Forever) | Solo builders & public repos | Unlimited local CLI scans, .cursorrules, CLAUDE.md, pre-commit hooks, all 12 built-in rules | | Developer Pro | $12 / month | Independent engineers & contractors | Unlimited private repositories, automated PR Review Bot, custom rules engine, secret leak detector | | Engineering Team | $39 / month | Startups & engineering orgs | Up to 5 devs, GitHub Org-wide CI/CD merge blocker, SOC2 architecture audit logs, Slack/Discord alerts |

👉 Subscribe to Developer Pro ($12/mo) • Upgrade Team ($39/mo) • 🇧🇷 Pagar no PIX (R$ 67 à vista)


👥 Contributors & Community

Special thanks to the open source engineers contributing to RepoGuard:

🌟 Support & Community

If RepoGuard helps keep your AI coding clean, consider giving this repository a ⭐ Star!