Agent context integrity

Your coding agents follow instructions nobody reviews.

Claude Code, Cursor, Copilot, Gemini and Codex each read different files. threadctx shows what every agent is actually told, finds stale paths, copies that never see your shared file, and risky MCP config, fixes them in one pull request, and hands security the evidence.

Runs locally, nothing uploadedZero dependenciesApache-2.0 licensedOffline-verified licences
Example repository, lightly shortened. These are the problems our benchmark found most often: stale paths, tool files that never see AGENTS.md, and rules that apply to nothing. See a real pull request check.

Reads the instructions of every major coding agent

AGENTS.mdClaude CodeCursorGitHub CopilotGemini CLIOpenAI CodexMCP serversClaude skills
The problem

Agent instructions rot quietly, and every agent obeys them.

They are written once, copied between tools, and rarely tested. When a path moves or a script is renamed, agents keep following the old text. We benchmarked 210 public repositories; 184 of them have agent instruction files.

48%

of the 184 with instruction files keep them in two or more tools’ formats, so copies can drift apart.

23%

of the 184 have tool-specific files that never see the shared AGENTS.md.

16%

of the 184 repeat the same directive word for word in files an agent loads together.

Every finding reviewed by hand. Most repositories still score an A (88%): the problems cluster, and they multiply across an organisation. Read the report · Methodology

What it finds

35 deterministic rules, with their accuracy in the open.

No AI guessing: every rule is a reproducible check. Each rule page shows its false-positive rate with the sample size behind it. Today 3 rules have 30+ hand-reviewed real-world findings; the rest say “not yet established” until they do, and any rule over 5% is demoted automatically.

Drift

Paths that no longer exist, scripts that are not defined, the wrong package manager, outdated versions.

Conflicts

CLAUDE.md says npm, AGENTS.md says pnpm. Different agents, different builds.

Duplication

Instructions copied across files that load together, and generic text that costs tokens in every session.

Injection risks

Hidden Unicode, curl-pipe-to-shell, secrets in context, and MCP servers that run whatever was published last.

Browse all rules →

How it works

Scan, fix, and keep it fixed.

Scan in seconds

Grades every agent’s view of the repository, A to F, and shows exactly which files each agent loads.

npx threadctx scan

Fix in one pull request

Safe, mechanical fixes land as a reviewable pull request. Nothing is rewritten by a model.

npx threadctx fix --pr

Guard every pull request

The GitHub Action comments with the grade change and blocks only problems a change introduces.

npx threadctx init --pr
Who it is for

One source of truth for everyone who touches agent context.

Developers

Know what your agent was told before it touches your code. Free, local, in your terminal, CI and Claude Code.

  • Grade and badge for your repo
  • See each agent’s effective context
  • One-command fix pull requests

Platform leads & architects

Every repository in the organisation, graded together, with where they disagree and a ranked fix plan.

  • Org-wide audit across all repos
  • Conventions that drifted between teams
  • Trends from audit to audit

Security & compliance

An inventory of AI agents and MCP servers, and evidence mapped to the frameworks you are audited against.

  • SOC 2 · ISO 27001 · ISO 42001 · NIST AI RMF
  • Secrets, injection and supply-chain checks
  • Print-ready evidence pack with integrity hash
Security & compliance

Answer “how do we govern AI coding agents?” with evidence, not a policy PDF.

The org audit produces an evidence pack your auditor can file: 8 controls tested across every repository, cross-referenced to SOC 2, ISO/IEC 27001, ISO/IEC 42001 and NIST AI RMF, plus a full inventory of agent instruction files and MCP servers.

  • Generated on your machine. Repository contents are never sent to us.
  • Tamper-evident. The pack carries the SHA-256 of its raw data.
  • GRC-ready. Controls and inventory as CSV, ready to attach in your GRC tool or a spreadsheet.
ControlStatus
TC-01 AI coding agents and their tools are inventoried
SOC 2 CC6.1 · ISO/IEC 27001:2022 A.5.9
Met
TC-02 Secrets are kept out of agent instructions and tool configuration
SOC 2 CC6.1 · ISO/IEC 27001:2022 A.5.17
Gap
TC-03 Agent instructions are free of hidden or injected content
SOC 2 CC6.8 · ISO/IEC 27001:2022 A.8.7
Met
TC-04 Agents are not told to bypass quality and security checks
SOC 2 CC8.1 · ISO/IEC 27001:2022 A.8.29
Met
TC-05 Third-party agent tools are pinned and authenticated
SOC 2 CC9.2 · ISO/IEC 27001:2022 A.5.21
Attention
TC-06 Agent instructions have owners and reviewed changes
SOC 2 CC8.1 · ISO/IEC 27001:2022 A.8.32
Met
Try it now

Grade any public repository.

We read its public agent instruction files and grade them. Security findings are never shown publicly.

Everywhere you work

Terminal, CI, and inside your agent.

CLI

npx threadctx scan. SARIF for GitHub code scanning, exit codes for any CI.

GitHub Action

A grade-change comment on every pull request. Only new problems block. See it on a real PR

Claude Code plugin

Slash commands, a skill and a read-only MCP server. Install

MCP server

npx threadctx mcp lets any agent check its own instructions before it acts.

Pricing

Free for every repository. Pay for the organisation view.

Everything that runs on one repository is free, forever. Paid plans add the org-wide audit, trends and the compliance evidence pack.

Free

$0 forever
  • Scan, explain, diff, fix and badge any repository
  • Fix pull requests, GitHub Action, MCP server
  • Org audit summary in your terminal

How paid plans are priced

By agent repositories: repositories with at least one agent instruction or MCP config file. The free audit summary tells you how many you have. Annual plans match the yearly audit cycle; the snapshot is for evidence once.

Not sure which fits? Ask us.

Snapshot audit

$299 one-off
  • One organisation, up to 100 agent repositories
  • Full report: every repo graded, where teams disagree, ranked fix plan
  • Compliance evidence pack (SOC 2, ISO 27001, ISO 42001, NIST AI RMF)
  • 14 days to fix and re-run
  • Credited in full toward an annual plan started within 30 days

Team

$99 / month, billed yearly

$1,188 per year

  • One organisation, up to 50 agent repositories
  • Unlimited audits and evidence packs all year
  • Trends: what improved or regressed since the last audit
  • Ongoing-monitoring control (TC-08) evidenced

On the roadmap: Scheduled weekly audits in your own GitHub, with regression issues.

Business

$299 / month, billed yearly

$3,588 per year

  • One organisation, up to 500 agent repositories
  • Everything in Team
  • Priority email support

On the roadmap: Org-wide fix pull requests; Developer-machine MCP inventory; Policy baseline for every repository.

Agency

$2,990 per year
  • Up to 10 client organisations
  • Full reports and evidence packs for each
  • Trends for every organisation
  • More organisations: $249 a year each, by email

You list your client organisations at checkout.

Enterprise from $12,000 per year

Unlimited agent repositories and organisations · Invoicing, procurement and security questionnaires · Custom rule packs for your policies · Priority support and rollout help.

Talk to us

Secure checkout by Stripe · Manage or cancel from the licence page · Licences are verified offline · Prices in USD, taxes may apply · Terms

Questions

What leaves my machine?

Nothing by default. The scanner reads files locally and makes no network calls. The org audit reads repositories through the GitHub API with your own token and analyses them on your machine. Licences are verified offline.

Is the evidence pack a SOC 2 report?

No. It is evidence about how your AI coding agents are configured, mapped to the controls it is commonly relevant to. Your auditor decides whether it is sufficient. threadctx does not certify or attest anything.

Does it rewrite my instructions with an AI?

No. Fixes are deterministic edits you review in a pull request. Research on repository context files found that bloated, generic context raises cost without improving task success, so threadctx mostly points at what to delete.

How accurate is it?

Every rule’s false-positive rate is measured on a hand-labelled public corpus and shown on its page. A rule over 5% is demoted automatically. See the rules.

Does it show what the agent actually loaded?

It shows what a correctly behaving tool loads according to its documentation, with the date each adapter was verified. The Claude Code adapter is also checked against the real tool. See the agents.

Can I cancel?

Yes, any time from the licence page through Stripe’s billing portal. Licences keep working until the end of the paid period.

Find out what your agents are told.

Thirty seconds, no sign-up, nothing uploaded.

npx threadctx scan