‹ The Index

Speclock

npm

Stop AI from breaking code you told it not to touch. Enforces .cursorrules, CLAUDE.md, and AGENTS.md — not just suggests. Zero-config: npx speclock protect reads your existing AI rule files, extracts constraints, installs pre-commit hooks, and makes your

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code (installable)
installable: each client documents how to load an MCP server of this type — that is the client's promise, not a claim verified against this capability

Work: Knowledge management

Who it is for: Operations · Researcher

Install (Claude Code):

claude mcp add speclock -- npx -y speclock

Security audit

scanned 2026-08-09

Every finding is shown in full — which advisory, the version that fixes it, and the exact command run at install time. Nothing in this audit is behind a licence.

No known advisoriesclearchecked against OSV for 5.7.0
Reads and writes filesfrom declared dependencies
No build provenanceno attestation — the published artifact cannot be traced to its source

npm ↗  ·  source ↗  ·  pkg:speclock

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›

Measured 2026-08-09  ·  scorer s5  ·  how  ·  something wrong here?