HookTripwire
Map statically provable local hook references from configuration to scripts and findings before anything executes.
Local-first developer tools
Six focused open-source tools for AI-agent security, observability, and code intelligence. Each turns a difficult question into inspectable evidence without uploading analyzed code, logs, traces, or API contracts to a hosted backend.
npx --yes github:mockingbird777/hooktripwire#v0.3.0 .claude .cursor .github/workflows --map-hooks
Audit surface
Audit coding-agent hooks before execution, then trace statically provable local references from configuration to scripts and findings with HookGraph—without running scanned code.
Choose a job. This tiny guide runs entirely in your browser and points to the smallest useful tool.
No signup, upload, or background request—just a local recommendation.
Map statically provable local hook references from configuration to scripts and findings before anything executes.
Every project has a documented quick-start path, realistic examples, documented trade-offs, tests, and a public roadmap.
HookGraph maps hook configuration to local scripts and security findings—statically, with explicit unknowns.
Recovery Ledger records high-confidence retry recovery evidence with failed attempts, timing, tokens, and local cost estimates.
Trace reverse change impact with deterministic shortest witnesses and explicit output safety limits.
Surface candidate failure precursors from redacted service-local event sequences, with support, lift, and timing.
Detect declared API access broadening: anonymous alternatives, removed OAuth scopes, and weaker security choices.
Compose complementary capabilities by marginal lexical coverage and disclose exactly what remains uncovered.
Analyzed code, logs, traces, and API contracts are not uploaded to a hosted backend.
Stable structured output, meaningful exit codes, and CI-friendly workflows.
MIT licensed, with public roadmaps and contribution paths in every repository.