# Workrail

> Step-by-step workflow enforcement for AI agents via MCP

## Facts
- Page: https://tashan.sh/capability/pkg-exaudeus-workrail
- tashan id: pkg:@exaudeus/workrail
- Source: https://github.com/EtienneBBeaulac/workrail
- npm: https://www.npmjs.com/package/@exaudeus/workrail
- Type: npm
- Category: security
- tashan score: 60.0 / 100
- Adoption: 36.0
- Upkeep: 70.0
- Freshness: 90.0
- Evidence coverage: 100% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- npm downloads: 366/week
- License: MIT
- Official: no

## Install

```sh
claude mcp add exaudeus-workrail -- npx -y @exaudeus/workrail
```

## Security audit
- Known advisories: 0
- Install-time script: `node -e "const v=parseInt(process.versions.node.split('.')[0],10); if(v<20){console.error('WorkRail requires Node.js >=20. Current: '+process.versions.node+'\nPlease upgrade: https://nodejs.org/'); process.exit(1);}"`
- Build provenance: attested
- Declared permission surface: credentials

Permissions are read from DECLARED dependencies only. Nothing is executed, so an empty result means "nothing declared", never "nothing possible".

---
Measured 2026-08-21 by tashan (https://tashan.sh) from public evidence. Scorer s5.
