Local-first architecture guardrails and project context for JS/TS AI coding agents.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
@codapult/guard is a local-first, model-agnostic architecture guard for JavaScript and
TypeScript projects.
It learns what already exists, records the project’s architectural memory, and can protect future changes from introducing regressions covered by the project’s approved policy.
Suppose a SaaS project has an established boundary:
An AI agent can still produce code that is valid TypeScript but crosses that boundary:
After the project has explicitly approved a matching import rule or deterministic contract, Guard checks the changed files and reports matching violations deterministically:
The file path, rule ID, message, and counts depend on the project. This is the actual CLI output
shape: Guard does not infer that every Client → Database edge is forbidden, and it does not
activate proposals silently. The team approves the relevant policy first; then existing findings
can be baselined while newly matching violations fail the gate and give the agent bounded evidence
to repair.
Guard does not tell every project to use the same architecture. It discovers the architecture that is already there, then lets the team decide what becomes policy.
The core is universal. The strongest first-class scenarios are Next.js SaaS and AI-assisted development, including server/client boundaries, routes, persistence, authentication, billing, background jobs, environment configuration, and AI integrations.
Guard is an independent open-source project from Codapult. It does not require Codapult and can be installed in any JavaScript or TypeScript repository.
The relationship is complementary:
| Project | Role |
|---|---|
@codapult/guard | Universal architecture guardrails, project memory, contracts, MCP, and AI-agent context. |
@codapult/cli | Codapult SaaS project CLI that includes Guard through a thin adapter. |
| Codapult | Full-source Next.js SaaS foundation with conventions Guard can discover and protect. |
Use standalone Guard for any compatible project. Use the Codapult CLI when working on a Codapult SaaS project and you want project management, database, plugins, deployment, MCP, and Guard in one CLI.
AI agents can produce syntactically valid code that still violates the architecture of a real project: a client component imports server-only code, a new action bypasses the established auth boundary, a route writes to the database directly, or a change duplicates a service that already exists.
Existing tools remain essential, but they solve different problems:
| Tool category | Primary question | Guard’s relationship |
|---|---|---|
| TypeScript | Is the code type-correct? | Uses the project’s typecheck as an optional gate. |
| ESLint / Biome | Does code follow language and style rules? | Does not duplicate their lint rules. |
| Tests | Does behavior match executable expectations? | Runs configured checks when enabled; does not replace tests. |
| SAST / dependency scanners | Is there a known security or dependency risk? | Can connect adapters; focuses on architecture and change impact. |
| PR review services | What semantic concerns should a reviewer consider? | Produces a bounded, redacted review packet for the selected AI host. |
| Guard | Is the project becoming architecturally worse? | Maintains project-specific architectural memory and regression gates. |
Requirements: Node.js >=20.19 and a JavaScript or TypeScript project.
The package exposes the codapult-guard binary:
The npm package is scoped as @codapult/guard; the executable intentionally remains
codapult-guard for discoverability and consistency with the standalone product name.
Run from the project root:
init is protected and refuses to overwrite an existing baseline. Use init --force only when
deliberately replacing the project memory. Use analyze to refresh discovered facts without
resetting the baseline.
Guard separates facts, policy, verification, and decision:
| Layer | Contains | How it is produced |
|---|---|---|
| Facts | AST, files, imports, dependencies, routes, calls, capabilities, graph, Git history | Deterministic local discovery |
| Policy | Rules, contracts, conventions, baseline | Observed proposals plus explicit team approval |
| Verification | Changed-file checks, impact analysis, contracts, project checks, review packet | Local CLI, MCP, CI, and existing project tools |
| Decision | Pass, fail, warning, needs-review, not-configured | Developer or AI host using Guard evidence |
Guard does not assume a fixed UI → actions → services → repositories → database architecture.
It can discover that shape when the project exhibits it, but observed patterns become enforceable
only after explicit approval.
Policy paths are validated as project-relative paths. Guard rejects traversal, absolute paths, and symlinks escaping the project root; import-boundary checks include imports, re-exports, and literal dynamic imports.
The model is framework-aware without being framework-dependent:
| Area | Examples of discovered evidence |
|---|---|
| JavaScript / TypeScript | AST modules, declarations, calls, directives, aliases, re-exports, dynamic imports |
| Next.js / React | App Router routes, route methods, Server Actions, client/server boundaries |
| API boundaries | Route handlers, API modules, entrypoints, impact paths |
| Data | ORM packages, schemas, migrations, repositories, persistence boundaries |
| Capabilities | Auth, payments, email, AI/RAG, queues, storage, cache, search, analytics, content |
| Operations | Environment references, configs, deployment, observability, webhooks |
| Repository shape | Workspaces, package scripts, dependencies, cycles, import hotspots, Git history |
| Testing | Test files, test scripts, workspace checks, changed files |
Capabilities are evidence, not requirements. A Vite app, Express service, Hono project, Node package, monorepo, or Next.js SaaS can all use the same Guard core.
Guard is an architecture control plane for AI-assisted development. It protects project-specific boundaries and change impact using local facts, approved policy, and deterministic verification.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/guard)<a href="https://allmcps.com/mcp/guard"><img src="https://allmcps.com/api/badge/guard?style=directory" alt="Guard on AllMCPs" /></a>