AI coding assistants like Cursor, GitHub Copilot, Claude Code, and Windsurf have completely revolutionized developer velocity. Being able to scaffold an entire feature in 10 seconds feels like having superpowers.
Until 3 months later, when your tech lead opens the repository and screams.
While AI models are brilliant at solving isolated algorithmic tasks, they lack holistic architectural discipline. Without strict repo-level boundaries, AI assistants quietly poison your codebase with architectural drift:
-
Layer Bypassing: The AI queries Prisma, Drizzle, or raw SQL directly inside React components or API route handlers, completely ignoring your
/servicesdomain logic. -
Re-inventing Existing Helpers: Instead of importing your existing
formatCurrencyhelper, the AI writes a fresh 20-line copy with zero reuse. -
The Lazy
: anyEscape Hatch: When TypeScript complains about complex interfaces, the AI sprinkles: anyoras anyeverywhere to force quick compilation. - Secret Leaks: Mock API keys and tokens accidentally hardcoded into files.
- PR Review Fatigue: Tech leads spend hours reviewing 800-line AI-generated PRs, hunting for subtle architectural breaches.
To solve this without manually writing hundreds of lines of rule files, we built RepoGuard: an open-source, zero-dependency CLI that scans your project stack, enforces 8 strict architectural guardrails, and grades your repository's architectural health from A+ to F.
🚀 Instant Quickstart (Zero Install Required)
RepoGuard is completely free and published on the official NPM registry. You can test it on any repository right now:
1. Check Your Architectural Health Score
Run this command in the root of any repository:
npx repoguard-rules audit
RepoGuard scans your entire codebase against 8 strict architectural rules and outputs an instant health report card:
====================================================
ARCHITECTURAL HEALTH DASHBOARD
====================================================
Files Audited: 42
Total Violations: 0
Health Score: 100/100 [Grade: A+]
====================================================
✨ Flawless architecture! Zero drift detected across all files.
If violations exist, it pinpoints the exact file, line number, violated rule, and suggests a clean architectural fix.
2. Auto-Generate Strict Guardrails for Cursor & Claude Code
Instead of writing rule files by hand, run:
npx repoguard-rules init
In 2 seconds, RepoGuard:
- 🔍 Detects your stack (Next.js, NestJS, Express, Python, Prisma, Tailwind, etc.).
- 📝 Generates tailored
.cursorrules(for Cursor AI). - 🤖 Generates a comprehensive
CLAUDE.md(for Claude Code). - 🌊 Generates
.windsurfrules(for Windsurf IDE). - 🛡️ Configures pre-commit hook triggers.
🛡️ The 8 Built-in Architectural Rules
| Rule ID | Category | Severity | Guardrail Enforced |
|---|---|---|---|
| RULE-01 | Architecture | Error | Blocks raw ORM/DB calls inside Controllers and UI components. |
| RULE-02 | Security | Critical | Flags hardcoded secrets, API tokens, and credentials in code. |
| RULE-03 | Type Safety | Warning | Forbids lazy : any and as any escape hatches. |
| RULE-04 | Code Quality | Info | Enforces structured logging instead of raw console.log. |
| RULE-05 | Next.js / SSR | Error | Prevents SSR hydration mismatch from browser globals (window/localStorage). |
| RULE-06 | Security | Critical | Detects dangerous SQL injection risks in raw query interpolations. |
| RULE-07 | API Design | Warning | Enforces Zod schema validation on incoming request body payloads. |
| RULE-08 | DRY Principle | Info | Prevents AI assistants from duplicating existing common utility helpers. |
🔬 Real-Time Git Diff Auditing
Before committing code generated by an AI assistant, you can audit your staged changes in real-time:
npx repoguard-rules check
Or physically block architectural drift before it ever leaves a developer's machine:
npx repoguard-rules install-hook
This installs a lightweight .git/hooks/pre-commit script that runs in milliseconds. If an AI assistant smuggled a raw DB call into a frontend component, the commit is safely rejected with actionable guidance on how to fix it.
🌟 Open Source & Getting Involved
RepoGuard is completely free and licensed under MIT:
- 📦 NPM Registry: https://www.npmjs.com/package/repoguard-rules
- ⭐ GitHub Repository: https://github.com/taylormatematica-beep/repoguard
- 🌐 Live Interactive Docs: https://taylormatematica-beep.github.io/repoguard/
If you find the tool useful or want to keep AI coding disciplined across your team, please consider starring the repository on GitHub ⭐!
Discussion:
What is the worst architectural mistake you've caught Cursor or Copilot making in your projects? Let's discuss in the comments below! 👇
Top comments (2)
Hey everyone! Creator of RepoGuard here. 👋
We built this after a 3-month Next.js + Prisma project where Cursor wrote hundreds of lines at lightning speed, but quietly bypassed our service layer and started calling the ORM directly inside UI components.
The CLI is completely free, zero-dependency, and open-source:
$ npx repoguard-rules audit
I'd love to hear from you:
Drop your thoughts below — I'll be actively answering and building requested rules! 🚀
Some comments may only be visible to logged-in visitors. Sign in to view all comments.