Locrin by RaxbiFree · MIT

Pass, advisory, or block. The same answer every time.

A quality gate for code written by people and by agents. It checks a change in under a second once the index is built, with no model in the loop. TypeScript and JavaScript, plus PHP and Python behind a one-line opt-in. Free and MIT licensed. No account.

More
$ npm i -D locrin
Locrin · hook
Gating
$ "Add an admin Supabase client"
→ agent edited src/lib/admin.ts
hook verdict237 ms
  • BLOCKsecret-exposedadmin.ts:4
  • PASSkey moved to server envre-check
BLOCK
1 → 0
ADVISORY
0
MODEL
none
Verdict · pass

Blocked before it moved on. No model in the loop, so the same change gets the same answer.

01 / How it works

1

Install and run init

Add it with npm, pip, Homebrew, or cargo. locrin init writes the config and the hooks, and locrin check answers pass, advisory, or block.

2

Today's findings are baselined

Every finding the repo has today goes into a baseline, so you are gated on what you do next, not on your history.

3

Your agent hears it first

A blocking finding reaches Claude Code before it moves on. If it tries to stop with a block outstanding, Locrin sends it back, up to three times.

4

CI checks the pull request

The GitHub Action posts the verdict on the pull request, uploads SARIF to code scanning, and fails the job on a block. It can gate deploys too.

02 / What makes it different

No model inside, no account needed: the same change gets the same verdict every time, and the hooks never touch the network.
An agent can look before it writes: find_existing, one of five tools in the MCP server, searches the symbols your repo already has.
21 rules, 10 of them for security, and precision is measured before a rule ships: three missed the bar, so they ship switched off.
Confidence, not severity, decides what blocks, and secret-exposed is locked on: no config setting can turn it off.
Measured on a 1,846-file TypeScript repo: a 4.71 s cold index, then 237 ms for the Claude Code hook and 362 ms for a warm 30-file check.
We use it ourselves: our FastLift app runs Locrin on its pull requests and in its Claude Code hooks.

Install. Init. Check.

Free, MIT licensed, no account. Pick your package manager, then run init and check in your repo.

$ npm i -D locrin$ npx locrin init$ npx locrin check

No account. --offline turns off the only network call.

Rolling it out across a team? hello@raxbi.com