Guardrails and tooling for AI-assisted software development.
Local-first tools that let teams move fast with autonomous coding agents while keeping structure, review, and safety in human hands.
noctcore is home to a small family of developer tools built around one idea: autonomy is only useful when it is governed. Agents can write most of the code, but structure, review gates, and safety stay under your control. Everything we ship runs on your machine, keeps your data local, and stays legible so you always know what a tool did and why.
| Project | What it is | Status | Get it |
|---|---|---|---|
| Nightcore | A local-first, autonomous Claude dev studio: a Rust and Tauri core over a Bun provider sidecar, with governed agents that plan, build, and verify work under a policy you set. | In active development | Download the latest release (macOS, Windows) |
| Nysia | A terminal-first agentic development environment (Tauri v2 + Rust). Every tab is an agent or shell session over a headless nysiad daemon that owns the terminals and orchestration state, so the UI can close or crash without interrupting a running agent. Tasks come from GitHub Issues and start in branch-keyed worktrees. |
In active development (v0.3) | Build from source |
| Harness | A zero-dependency CLI that enforces a repository's structure lock in that repo's own CI. No account, no server, no Nightcore install: a teammate clones the repo and npx @noctcore/harness check fails the build on any violation. |
Shipped, on npm | npx @noctcore/harness check |
| ESLint plugins | Eleven focused plugins, a shared utils package, and a catalog of whole-repo lint-meta rules. They catch architecture, contract, data-integrity, and safety problems that generic linters can't see. | Shipped, on npm | Docs · Where to start |
| SDK | A typed toolkit for building on top of the studio and its provider layer. | Planned |
Everything below is published on npm with provenance through npm trusted publishing. Each name links to its source; the docs links go to the rule reference.
| Package | npm | What it does | Docs |
|---|---|---|---|
@noctcore/harness |
Runs a repo's structure-lock checks (.nightcore/harness.json) in its own CI, plus a lint-meta subcommand for whole-repo rules from a committed registry. |
||
@noctcore/eslint-plugin-code-quality |
Guard clauses, comment and test hygiene, deterministic time, no stray process.exit. |
docs | |
@noctcore/eslint-plugin-async-safety |
Fetch timeouts, AbortSignal forwarding, async races and shared mutable state. |
docs | |
@noctcore/eslint-plugin-contracts |
IO boundaries (checked fetch, parsed boundary data), error cause and taxonomy, zod schema and wire naming, env access, decimal money, translation keys. | docs | |
@noctcore/eslint-plugin-security |
Shell injection, path traversal, SSRF, open redirect, unsanitized HTML (XSS), timing-unsafe comparison, server actions that bypass their action client. | docs | |
@noctcore/eslint-plugin-observability |
Structured logging: context objects over interpolation, no sensitive fields in logs, no lost error detail, declared PII in audit payloads. | docs | |
@noctcore/eslint-plugin-react |
React architecture and correctness (prop drilling, state colocation, memoized context, effect safety, guarded web storage). | docs | |
@noctcore/eslint-plugin-rsc |
React Server Components and App Router correctness (navigation errors that must not be swallowed). | docs | |
@noctcore/eslint-plugin-llm |
LLM output treated as untrusted input before it reaches a sink. | docs | |
@noctcore/eslint-plugin-prisma |
Prisma tenancy, soft-delete and transaction guardrails (tenant-scope escape hatches, raw SQL, request-body writes, single-writer models, audit placement). | docs | |
@noctcore/eslint-plugin-architecture |
Module and folder shape (folder-per-component, barrels, feature boundaries, import depth, colocated tests). | docs | |
@noctcore/eslint-plugin-monorepo |
Workspace package boundaries (barrel-only and exports-map-aware imports); needs your workspace scope. | docs | |
@noctcore/lint-meta-rules |
Whole-repo rules ESLint can't reach (package naming, declared workspace deps, file-size ratchets), run by harness lint-meta. |
docs | |
@noctcore/eslint-utils |
Shared rule-creator and AST helpers the plugins are built on. |
Nothing to install; run it straight from any repo's CI:
npx @noctcore/harness check
npx @noctcore/harness lint-meta # whole-repo lint-meta rules, opt-in by presenceFlat config only (ESLint 9+), each plugin versioned on its own. Every rule, its options, and the presets are documented at noctcore.github.io/eslint-plugins.
npm i -D @noctcore/eslint-plugin-code-quality @typescript-eslint/parser # or bun add -D / pnpm add -D// eslint.config.js (flat config). The presets set no `files` and no parser, so give them both.
import tsParser from '@typescript-eslint/parser';
import codeQuality from '@noctcore/eslint-plugin-code-quality';
export default [
{
...codeQuality.configs.recommended,
files: ['**/*.{ts,tsx}'],
languageOptions: { parser: tsParser },
},
];New here? Start with code-quality, async-safety and contracts, then add the plugins for your stack. The Where to start guide has a combined config.
- Local-first. Your code and your data stay on your machine. No hosted anything, no phone-home.
- Governed autonomy. Agents move fast inside guardrails you define, not around them.
- Legible by default. Every action a tool takes is visible and reviewable, never a black box.
- Downstream-owned. What we generate, you own. Edit it, extend it, or throw it away.
- npm: npmjs.com/org/noctcore
- ESLint plugin docs: noctcore.github.io/eslint-plugins
- Nightcore releases: github.com/noctcore/nightcore/releases
- Web: shirone.dev
- Contact: support@shirone.dev
Built with care by noctcore. Ship fast, stay in control.