Speclock

SSE

by sgroy10

23 332 downloads Not rated yet MIT

About

AI constraint engine — persistent memory + active enforcement. Stops AI from breaking locked code. Semantic conflict detection, file-level guards, session continuity. 19 MCP tools.

Details

Transport
SSE
License
MIT

Explore

- Semantic conflict detection (100/100 score, 0% false positives)
- Hard enforcement mode that blocks AI from proceeding
- Pre‑commit hooks and MCP integration for all major AI tools
- Tamper‑proof audit trail with HMAC‑SHA256 chain
- SOC 2 / HIPAA compliance exports
- Encrypted storage (AES‑256‑GCM) and RBAC with API key auth
- Policy‑as‑Code DSL using YAML rules

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Speclock
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

npx speclock protect              # Install in your project (creates CLAUDE.md if missing)
speclock mcp install claude-code  # Wire up MCP for Claude Code (or cursor, windsurf, cline, codex)
speclock doctor                   # Verify everything is set up correctly

That's it. Your AI now has rules it can't ignore. Default mode is WARN (loud warnings, no blocks). Opt in to hard enforcement with speclock protect --strict.

1. Go to Settings → Connectors → New MCP server
2. Enter URL: https://speclock-mcp-production.up.railway.app/mcp
3. Paste project instructions into Knowledge

---

speclock_init

Initialize SpecLock in project

speclock_get_context

Full context pack (the key tool)

speclock_set_goal

Set project goal

speclock_add_lock

Add constraint + auto-guard files

speclock_remove_lock

Soft-delete a lock

speclock_add_decision

Record architectural decision

speclock_add_note

Add pinned note

speclock_set_deploy_facts

Record deploy config

speclock_check_conflict

Semantic conflict check against all locks

speclock_set_enforcement

Switch advisory/hard mode

speclock_override_lock

Override with reason (audit logged)

speclock_override_history

View override audit trail

speclock_semantic_audit

Analyze git diff against locks

speclock_detect_drift

Scan for constraint violations

speclock_audit

Audit staged files pre-commit

speclock_session_briefing

Start session + full briefing

speclock_session_summary

End session + record summary

speclock_log_change

Log a change with files

speclock_get_changes

Recent tracked changes

speclock_get_events

Full event log (filterable)

speclock_checkpoint

Git tag for rollback

speclock_repo_status

Branch, commit, diff summary

speclock_suggest_locks

AI-powered lock suggestions

speclock_health

Health score + multi-agent timeline

speclock_apply_template

Apply constraint template

speclock_report

Violation stats + most tested locks

speclock_verify_audit

Verify HMAC chain integrity

speclock_export_compliance

SOC 2 / HIPAA / CSV reports

speclock_policy_evaluate

Evaluate policy rules

speclock_policy_manage

CRUD for policy rules

speclock_telemetry

Opt-in usage analytics

speclock_add_typed_lock

Add typed constraint (numerical/range/state/temporal)

speclock_check_typed

Check proposed values against typed constraints

speclock_list_typed_locks

List all typed constraints

speclock_update_threshold

Update typed lock thresholds

speclock_compile_spec

Compile natural language into structured constraints

speclock_build_graph

Build/refresh code dependency graph

speclock_blast_radius

Calculate blast radius of file changes

speclock_map_locks

Map locks to actual code files

speclock_review_patch

ALLOW/WARN/BLOCK verdict for proposed changes

speclock_review_patch_diff

Diff-native review with signal scoring + unified verdict

speclock_parse_diff

Parse unified diff into structured changes (debug/inspect)

speclock_sync_rules

Sync constraints to Cursor, Claude, Copilot, Windsurf, Gemini, Aider, AGENTS.md

speclock_list_sync_formats

List all available sync formats

speclock_replay

Replay a session's activity — what AI tried and what was caught

speclock_list_sessions

List available sessions for replay

speclock_drift_score

0-100 project integrity metric — how much AI deviated from intent

speclock_coverage

Lock Coverage Audit — find unprotected code areas

speclock_strengthen

Grade locks and suggest stronger versions

<details>
<summary><b>Memory</b> — goal, locks, decisions, notes, deploy facts</summary>

| Tool | What it does |
|------|-------------|
| speclock_init | Initialize SpecLock in project |
| speclock_get_context | Full context pack (the key tool) |
| speclock_set_goal | Set project goal |
| speclock_add_lock | Add constraint + auto-guard files |
| speclock_remove_lock | Soft-delete a lock |
| speclock_add_decision | Record architectural decision |
| speclock_add_note | Add pinned note |
| speclock_set_deploy_facts | Record deploy config |

</details>

<details>
<summary><b>Enforcement</b> — conflict detection, hard blocking, overrides</summary>

| Tool | What it does |
|------|-------------|
| speclock_check_conflict | Semantic conflict check against all locks |
| speclock_set_enforcement | Switch advisory/hard mode |
| speclock_override_lock | Override with reason (audit logged) |
| speclock_override_history | View override audit trail |
| speclock_semantic_audit | Analyze git diff against locks |
| speclock_detect_drift | Scan for constraint violations |
| speclock_audit | Audit staged files pre-commit |

</details>

<details>
<summary><b>Tracking & Sessions</b> — changes, events, session continuity</summary>

| Tool | What it does |
|------|-------------|
| speclock_session_briefing | Start session + full briefing |
| speclock_session_summary | End session + record summary |
| speclock_log_change | Log a change with files |
| speclock_get_changes | Recent tracked changes |
| speclock_get_events | Full event log (filterable) |
| speclock_checkpoint | Git tag for rollback |
| speclock_repo_status | Branch, commit, diff summary |

</details>

<details>
<summary><b>Intelligence</b> — suggestions, health, templates, reports</summary>

| Tool | What it does |
|------|-------------|
| speclock_suggest_locks | AI-powered lock suggestions |
| speclock_health | Health score + multi-agent timeline |
| speclock_apply_template | Apply constraint template |
| speclock_report | Violation stats + most tested locks |

</details>

<details>
<summary><b>Enterprise</b> — audit, compliance, policy, telemetry</summary>

| Tool | What it does |
|------|-------------|
| speclock_verify_audit | Verify HMAC chain integrity |
| speclock_export_compliance | SOC 2 / HIPAA / CSV reports |
| speclock_policy_evaluate | Evaluate policy rules |
| speclock_policy_manage | CRUD for policy rules |
| speclock_telemetry | Opt-in usage analytics |

</details>

<details>
<summary><b>Typed Constraints</b> — numerical, range, state, temporal (v5.0)</summary>

| Tool | What it does |
|------|-------------|
| speclock_add_typed_lock | Add typed constraint (numerical/range/state/temporal) |
| speclock_check_typed | Check proposed values against typed constraints |
| speclock_list_typed_locks | List all typed constraints |
| speclock_update_threshold | Update typed lock thresholds |

</details>

<details>
<summary><b>Spec Compiler & Code Graph</b> — NL→constraints, dependency analysis (v5.0)</summary>

| Tool | What it does |
|------|-------------|
| speclock_compile_spec | Compile natural language into structured constraints |
| speclock_build_graph | Build/refresh code dependency graph |
| speclock_blast_radius | Calculate blast radius of file changes |
| speclock_map_locks | Map locks to actual code files |

</details>

<details>
<summary><b>Patch Gateway & AI Patch Firewall</b> — change review, diff analysis (v5.1/v5.2)</summary>

| Tool | What it does |
|------|-------------|
| speclock_review_patch | ALLOW/WARN/BLOCK verdict for proposed changes |
| speclock_review_patch_diff | Diff-native review with signal scoring + unified verdict |
| speclock_parse_diff | Parse unified diff into structured changes (debug/inspect) |

</details>

<details>
<summary><b>Universal Rules Sync & Incident Replay</b> — cross-tool sync, session replay (v5.3)</summary>

| Tool | What it does |
|------|-------------|
| speclock_sync_rules | Sync constraints to Cursor, Claude, Copilot, Windsurf, Gemini, Aider, AGENTS.md |
| speclock_list_sync_formats | List all available sync formats |
| speclock_replay | Replay a session's activity — what AI tried and what was caught |
| speclock_list_sessions | List available sessions for replay |
| speclock_drift_score | 0-100 project integrity metric — how much AI deviated from intent |
| speclock_coverage | Lock Coverage Audit — find unprotected code areas |
| speclock_strengthen | Grade locks and suggest stronger versions |

</details>

---

speclock sync --all # Sync to ALL tools
speclock sync --format cursor # Cursor only
speclock sync --format claude # Claude Code only
speclock sync --preview windsurf # Preview without writing

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "speclock": {
            "speclock": {
                "command": "npx",
                "args": [
                    "-y",
                    "speclock",
                    "serve"
                ]
            }
        }
    }
}

McpServers

{
    "speclock": {
        "command": "npx",
        "args": [
            "-y",
            "speclock",
            "serve"
        ]
    }
}

→ sk_speclock_a1b2c3... (shown once, stored as SHA-256 hash)


| Role | Read | Write Locks | Override | Admin |
|------|:---:|:---:|:---:|:---:|
| viewer | Yes | — | — | — |
| developer | Yes | — | With reason | — |
| architect | Yes | Yes | Yes | — |
| admin | Yes | Yes | Yes | Yes |

AES-256-GCM Encryption

bash
export SPECLOCK_ENCRYPTION_KEY="your-secret"
speclock encrypt # Encrypts brain.json + events.log at rest

PBKDF2 key derivation (100K iterations). Authenticated encryption. HIPAA 2026 compliant.

HMAC Audit Chain

Every event gets an HMAC-SHA256 hash chained to the previous event. Modify anything — the chain breaks.

bash
$ speclock audit-verify

✓ Audit chain VALID — 247 events, 0 broken links, no tampering detected.


Compliance Exports

bash
speclock export --format soc2 # SOC 2 Type II report (JSON)
speclock export --format hipaa # HIPAA PHI protection report
speclock export --format csv # All events for auditor spreadsheets

---

Policy-as-Code

Declarative YAML rules for organization-wide enforcement:

yaml

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.