Local-first developer tools

Safer AI automation.Clearer systems.

Six focused open-source tools for AI-agent security, observability, and code intelligence—designed to produce a useful answer quickly without sending analyzed code, logs, traces, or API contracts to a hosted backend.

  • runs locally
  • no hosted analysis
  • MIT licensed
hooktripwire · static audit
npx --yes github:mockingbird777/hooktripwire#v0.2.0 .claude .cursor .github/workflows

Audit surface

  • Coding-agent hooksSTATIC
  • Workflow permissionsOFFLINE
  • Shell-backed automationNO EXEC
  • Mutable dependenciesTRACEABLE
START HERE · AGENT SECURITY

HookTripwire

Audit coding-agent hooks and automation before execution. Catch dangerous commands, broad permissions, secret exfiltration, and mutable dependencies without running scanned code.

Works with
Claude Code, Cursor, VS Code, and GitHub Actions
Reports
Terminal, JSON, SARIF, or standalone HTML
Trust model
Static analysis only; scanned commands are never executed
Automation
Reusable GitHub Action and stable CI exit codes

Start with the question you need answered.

Choose a job. This tiny guide runs entirely in your browser and points to the smallest useful tool.

No signup, upload, or background request—just a local recommendation.

Recommended tool

HookTripwire

Statically audit agent hooks, workflows, permissions, and shell-backed automation before anything executes.

One focused tool for each hard question.

Every project has a documented quick-start path, realistic examples, documented trade-offs, tests, and a public roadmap.

01 AGENT SECURITY

HookTripwire v0.2.0

Audit agent hooks, workflow permissions, and shell automation before execution.

02 OBSERVABILITY

SpanGarden v0.1.1

Turn AI-agent traces into critical paths, retry signals, latency, token, and cost insight.

03 CODE INTELLIGENCE

ArchLens v0.2.0

Map repository dependencies, cycles, hotspots, and high-coupling files locally.

04 LOG ANALYSIS

LogLoom v0.2.0

Turn noisy logs into a redacted, clustered, shareable investigation report.

05 API SAFETY

SpecSentinel v0.2.0

Catch breaking and security-relevant OpenAPI changes locally or in CI.

06 CAPABILITY ROUTING

Task2Tool v0.2.0

Rank the smallest useful set of skills and tools for a natural-language task.

Local-first privacy

Your code, logs, traces, and API contracts stay on your machine.

Automation-ready

Stable structured output, meaningful exit codes, and CI-friendly workflows.

Open by default

MIT licensed, with public roadmaps and contribution paths in every repository.