Your coding agents follow instructions nobody reviews.
Claude Code, Cursor, Copilot, Gemini and Codex each read different files. threadctx shows what every agent is actually told, finds stale paths, copies that never see your shared file, and risky MCP config, fixes them in one pull request, and hands security the evidence.
.cursor/rules/api.mdc 3: warning `globs` (src/legacy/**/*.ts) matches no files, so this rule never applies. CTX-S004 .mcp.json 1: warning MCP server "files" runs a package with no version. Pin an exact version. CTX-X006 AGENTS.md 5: info `docs/architecture.md` does not exist. Agents will follow a dead pointer. CTX-D001 CLAUDE.md 1: warning Claude Code and Cursor have their own files and Claude Code does not read AGENTS.md. Their copies can drift apart. CTX-S002 Grade B (84/100) 0 blockers, 3 warnings, 1 info Always loaded: Claude Code ≈19 · Cursor ≈47 · Copilot ≈66 tokens
Reads the instructions of every major coding agent
Agent instructions rot quietly, and every agent obeys them.
They are written once, copied between tools, and rarely tested. When a path moves or a script is renamed, agents keep following the old text. We benchmarked 210 public repositories; 184 of them have agent instruction files.
of the 184 with instruction files keep them in two or more tools’ formats, so copies can drift apart.
of the 184 have tool-specific files that never see the shared AGENTS.md.
of the 184 repeat the same directive word for word in files an agent loads together.
Every finding reviewed by hand. Most repositories still score an A (88%): the problems cluster, and they multiply across an organisation. Read the report · Methodology
35 deterministic rules, with their accuracy in the open.
No AI guessing: every rule is a reproducible check. Each rule page shows its false-positive rate with the sample size behind it. Today 3 rules have 30+ hand-reviewed real-world findings; the rest say “not yet established” until they do, and any rule over 5% is demoted automatically.
Drift
Paths that no longer exist, scripts that are not defined, the wrong package manager, outdated versions.
Conflicts
CLAUDE.md says npm, AGENTS.md says pnpm. Different agents, different builds.
Duplication
Instructions copied across files that load together, and generic text that costs tokens in every session.
Injection risks
Hidden Unicode, curl-pipe-to-shell, secrets in context, and MCP servers that run whatever was published last.
Scan, fix, and keep it fixed.
Scan in seconds
Grades every agent’s view of the repository, A to F, and shows exactly which files each agent loads.
npx threadctx scanFix in one pull request
Safe, mechanical fixes land as a reviewable pull request. Nothing is rewritten by a model.
npx threadctx fix --prGuard every pull request
The GitHub Action comments with the grade change and blocks only problems a change introduces.
npx threadctx init --prOne source of truth for everyone who touches agent context.
Developers
Know what your agent was told before it touches your code. Free, local, in your terminal, CI and Claude Code.
- Grade and badge for your repo
- See each agent’s effective context
- One-command fix pull requests
Platform leads & architects
Every repository in the organisation, graded together, with where they disagree and a ranked fix plan.
- Org-wide audit across all repos
- Conventions that drifted between teams
- Trends from audit to audit
Security & compliance
An inventory of AI agents and MCP servers, and evidence mapped to the frameworks you are audited against.
- SOC 2 · ISO 27001 · ISO 42001 · NIST AI RMF
- Secrets, injection and supply-chain checks
- Print-ready evidence pack with integrity hash
Answer “how do we govern AI coding agents?” with evidence, not a policy PDF.
The org audit produces an evidence pack your auditor can file: 8 controls tested across every repository, cross-referenced to SOC 2, ISO/IEC 27001, ISO/IEC 42001 and NIST AI RMF, plus a full inventory of agent instruction files and MCP servers.
- Generated on your machine. Repository contents are never sent to us.
- Tamper-evident. The pack carries the SHA-256 of its raw data.
- GRC-ready. Controls and inventory as CSV, ready to attach in your GRC tool or a spreadsheet.
| Control | Status |
|---|---|
| TC-01 AI coding agents and their tools are inventoried SOC 2 CC6.1 · ISO/IEC 27001:2022 A.5.9 | Met |
| TC-02 Secrets are kept out of agent instructions and tool configuration SOC 2 CC6.1 · ISO/IEC 27001:2022 A.5.17 | Gap |
| TC-03 Agent instructions are free of hidden or injected content SOC 2 CC6.8 · ISO/IEC 27001:2022 A.8.7 | Met |
| TC-04 Agents are not told to bypass quality and security checks SOC 2 CC8.1 · ISO/IEC 27001:2022 A.8.29 | Met |
| TC-05 Third-party agent tools are pinned and authenticated SOC 2 CC9.2 · ISO/IEC 27001:2022 A.5.21 | Attention |
| TC-06 Agent instructions have owners and reviewed changes SOC 2 CC8.1 · ISO/IEC 27001:2022 A.8.32 | Met |
Grade any public repository.
We read its public agent instruction files and grade them. Security findings are never shown publicly.
Terminal, CI, and inside your agent.
CLI
npx threadctx scan. SARIF for GitHub code scanning, exit codes for any CI.
GitHub Action
A grade-change comment on every pull request. Only new problems block. See it on a real PR
Claude Code plugin
Slash commands, a skill and a read-only MCP server. Install
MCP server
npx threadctx mcp lets any agent check its own instructions before it acts.
Free for every repository. Pay for the organisation view.
Everything that runs on one repository is free, forever. Paid plans add the org-wide audit, trends and the compliance evidence pack.
Free
- Scan, explain, diff, fix and badge any repository
- Fix pull requests, GitHub Action, MCP server
- Org audit summary in your terminal
How paid plans are priced
By agent repositories: repositories with at least one agent instruction or MCP config file. The free audit summary tells you how many you have. Annual plans match the yearly audit cycle; the snapshot is for evidence once.
Not sure which fits? Ask us.
Snapshot audit
- One organisation, up to 100 agent repositories
- Full report: every repo graded, where teams disagree, ranked fix plan
- Compliance evidence pack (SOC 2, ISO 27001, ISO 42001, NIST AI RMF)
- 14 days to fix and re-run
- Credited in full toward an annual plan started within 30 days
Team
$1,188 per year
- One organisation, up to 50 agent repositories
- Unlimited audits and evidence packs all year
- Trends: what improved or regressed since the last audit
- Ongoing-monitoring control (TC-08) evidenced
On the roadmap: Scheduled weekly audits in your own GitHub, with regression issues.
Business
$3,588 per year
- One organisation, up to 500 agent repositories
- Everything in Team
- Priority email support
On the roadmap: Org-wide fix pull requests; Developer-machine MCP inventory; Policy baseline for every repository.
Agency
- Up to 10 client organisations
- Full reports and evidence packs for each
- Trends for every organisation
- More organisations: $249 a year each, by email
Enterprise from $12,000 per year
Unlimited agent repositories and organisations · Invoicing, procurement and security questionnaires · Custom rule packs for your policies · Priority support and rollout help.
Secure checkout by Stripe · Manage or cancel from the licence page · Licences are verified offline · Prices in USD, taxes may apply · Terms
Questions
What leaves my machine?
Nothing by default. The scanner reads files locally and makes no network calls. The org audit reads repositories through the GitHub API with your own token and analyses them on your machine. Licences are verified offline.
Is the evidence pack a SOC 2 report?
No. It is evidence about how your AI coding agents are configured, mapped to the controls it is commonly relevant to. Your auditor decides whether it is sufficient. threadctx does not certify or attest anything.
Does it rewrite my instructions with an AI?
No. Fixes are deterministic edits you review in a pull request. Research on repository context files found that bloated, generic context raises cost without improving task success, so threadctx mostly points at what to delete.
How accurate is it?
Every rule’s false-positive rate is measured on a hand-labelled public corpus and shown on its page. A rule over 5% is demoted automatically. See the rules.
Does it show what the agent actually loaded?
It shows what a correctly behaving tool loads according to its documentation, with the date each adapter was verified. The Claude Code adapter is also checked against the real tool. See the agents.
Can I cancel?
Yes, any time from the licence page through Stripe’s billing portal. Licences keep working until the end of the paid period.
Find out what your agents are told.
Thirty seconds, no sign-up, nothing uploaded.