Pass, advisory, or block. The same answer every time.
A quality gate for code written by people and by agents. It checks a change in under a second once the index is built, with no model in the loop. TypeScript and JavaScript, plus PHP and Python behind a one-line opt-in. Free and MIT licensed. No account.
$ npm i -D locrin- BLOCKsecret-exposedadmin.ts:4
- PASSkey moved to server envre-check
Blocked before it moved on. No model in the loop, so the same change gets the same answer.
01 / How it works
Install and run init
Add it with npm, pip, Homebrew, or cargo. locrin init writes the config and the hooks, and locrin check answers pass, advisory, or block.
Today's findings are baselined
Every finding the repo has today goes into a baseline, so you are gated on what you do next, not on your history.
Your agent hears it first
A blocking finding reaches Claude Code before it moves on. If it tries to stop with a block outstanding, Locrin sends it back, up to three times.
CI checks the pull request
The GitHub Action posts the verdict on the pull request, uploads SARIF to code scanning, and fails the job on a block. It can gate deploys too.
02 / What makes it different
find_existing, one of five tools in the MCP server, searches the symbols your repo already has.secret-exposed is locked on: no config setting can turn it off.Install. Init. Check.
Free, MIT licensed, no account. Pick your package manager, then run init and check in your repo.
$ npm i -D locrin$ npx locrin init$ npx locrin checkNo account. --offline turns off the only network call.
Rolling it out across a team? [email protected]