Local-first developer tools

Safer AI automation.Clearer systems.

Six focused open-source tools for AI-agent security, observability, and code intelligence. Each turns a difficult question into inspectable evidence without uploading analyzed code, logs, traces, or API contracts to a hosted backend.

  • runs locally
  • no hosted analysis
  • MIT licensed
hooktripwire · static audit
npx --yes github:mockingbird777/hooktripwire#v0.3.0 .claude .cursor .github/workflows --map-hooks

Audit surface

  • Hook config → local script graphSTATIC
  • Workflow permissionsOFFLINE
  • Shell-backed automationNO EXEC
  • Mutable dependenciesTRACEABLE
START HERE · AGENT SECURITY

HookTripwire

Audit coding-agent hooks before execution, then trace statically provable local references from configuration to scripts and findings with HookGraph—without running scanned code.

Works with
Claude Code, Cursor, VS Code, and GitHub Actions
Reports
Terminal, JSON, SARIF, standalone HTML, and bounded HookGraph evidence
Trust model
Static analysis only; scanned commands are never executed
Automation
Reusable GitHub Action and stable CI exit codes

Start with the question you need answered.

Choose a job. This tiny guide runs entirely in your browser and points to the smallest useful tool.

No signup, upload, or background request—just a local recommendation.

Recommended tool

HookTripwire

Map statically provable local hook references from configuration to scripts and findings before anything executes.

One focused tool for each hard question.

Every project has a documented quick-start path, realistic examples, documented trade-offs, tests, and a public roadmap.

01 AGENT SECURITY

HookTripwire v0.3.0

HookGraph maps hook configuration to local scripts and security findings—statically, with explicit unknowns.

02 OBSERVABILITY

SpanGarden v0.2.0

Recovery Ledger records high-confidence retry recovery evidence with failed attempts, timing, tokens, and local cost estimates.

03 CODE INTELLIGENCE

ArchLens v0.3.0

Trace reverse change impact with deterministic shortest witnesses and explicit output safety limits.

04 LOG ANALYSIS

LogLoom v0.3.0

Surface candidate failure precursors from redacted service-local event sequences, with support, lift, and timing.

05 API SAFETY

SpecSentinel v0.3.0

Detect declared API access broadening: anonymous alternatives, removed OAuth scopes, and weaker security choices.

06 CAPABILITY ROUTING

Task2Tool v0.3.0

Compose complementary capabilities by marginal lexical coverage and disclose exactly what remains uncovered.

Local-first privacy

Analyzed code, logs, traces, and API contracts are not uploaded to a hosted backend.

Automation-ready

Stable structured output, meaningful exit codes, and CI-friendly workflows.

Open by default

MIT licensed, with public roadmaps and contribution paths in every repository.