Route architectural constraints to AI coding agents per file
Staff-engineer control layer for AI coding agents: routes only the architectural constraints relevant to the file being edited, then requires verification.
Why it matters
Prevent AI coding agents from turning small fixes into large rewrites by injecting file-specific architectural constraints before edits and requiring proportional verification afterward, ensuring agents respect boundaries like sync/async separation, trust boundaries, and scope limits.
Outcomes
What it gets done
Select and route only the architectural constraints relevant to the specific file being edited
Require verification checks proportional to the scope of the code change
Preserve critical boundaries like sync/async separation, API contracts, and state ownership during refactors
Deliver signed constraint packs to Cursor, Claude Code, Codex, and OpenCode from a single npm package
Install
Add it to your toolbox
Run in your project directory:
curl -fsSL https://spark.entire.vc/get/micsm-boffin | bash Overview
Boffin
An npm tool that acts as a staff-engineer control layer for AI coding agents: it routes only the architectural constraints relevant to the exact file being edited, rather than one static rules file for the whole repo, and requires a verification check proportional to the size of the change. Use it when an AI coding agent keeps turning small requested fixes into large, unreviewed rewrites, and a per-edit constraint routing and verification layer is needed on top of Cursor, Claude Code, Codex, or OpenCode.
What it does
Boffin, published on npm as boffinit, is a staff-engineer control layer for AI coding agents: instead of shipping one static instructions block for the whole repository the way an AGENTS.md file does, it selects and feeds the agent only the architectural constraints that apply to the specific file it is about to edit, then requires a verification check proportional to the size of the change. It is explicitly not a linter or CI gate, since it acts before and after the edit rather than only checking committed code, and it is not a command sandbox or security tool, since it does not isolate processes or restrict filesystem or network access. The routing and constraint-selection logic is powered by ParselFire Core.
When to use - and when NOT to
Use it when an AI coding agent repeatedly turns a small requested fix into a large, unreviewed rewrite, and the goal is to make it stop before merging a real special case, blurring a sync/async boundary, moving state away from its owner, or turning a focused task into a tour of the codebase. For a focused change it keeps scope small and asks for the narrowest check that proves the edit; for an open-ended refactor it requires a read-only audit first, followed by one verified finding at a time. It requires Node.js 18 or newer, and it does not replace tests or code review, your repository's existing checks stay authoritative; it also is not a security or sandboxing tool.
Inputs and outputs
npx boffinit cursor
That single command installs the Cursor integration; Claude Code installs via /plugin marketplace add MicSm/boffin followed by /plugin install boffin@boffin, Codex via codex plugin marketplace add MicSm/boffin and codex plugin add boffin@boffin, Codex additionally requires running /hooks once to trust the plugin's hooks, and OpenCode via npx boffinit opencode, which writes always-on guidance into .boffin/AGENTS.md through opencode.json. Each host can be removed independently with an uninstall flag, e.g. npx boffinit cursor uninstall, which removes only that host's managed files and leaves shared .boffin/packs and .boffin/VERSION in place if another host still uses them. Output is the agent's edit itself, now scoped by the routed constraints and accompanied by whatever verification the change required.
Integrations
Every constraint ships as readable, GPG-signed, versioned markdown under packs/ in the repository, nothing is hidden at install time. Three profiles, lite, full, and max, tune how much cleanup ambition is applied without changing the safety floor: every profile keeps the same early correctness stages, including trust-boundary validation, data-loss prevention, security, and accessibility rejection rules. Public case studies document guided refactors on real open-source repositories: a DuckDB C++ change landed at +17/-17 lines with 2,104 assertions across 8 test files passing, a FastAPI change at +16/-33 with 49 tests passing and no public API change, and a LangChain change that preserved its sync/async boundary across 4 passing tests. Portable adapters also cover other hosts that read AGENTS.md, CLAUDE.md, or workspace rules.
Who it's for
Teams and developers using AI coding agents in Cursor, Claude Code, Codex, or OpenCode who need the agent's edits kept scoped to the actual request and verified proportionally, instead of trusting a single static repo-wide instructions file. The project is MIT licensed.
Source README
Boffin
Boffin (npm: boffinit) is a staff-engineer control layer for AI coding
agents: it feeds the agent the architectural constraints for the exact file it
is editing and makes it verify the result -- DuckDB case study:
a guided refactor landed at +17 / -17 lines with 2,104 assertions passing.
You ask for a 15-line fix; the agent comes back with a 500-line renovation.
Boffin gives the agent the architectural constraints that apply to the file it
is about to touch, then makes it verify the result.
It is not another AGENTS.md and not a prompt pack. Those formats usually ship
one static instructions block for the whole repository; Boffin routes only the
constraints relevant to the current edit. Powered by ParselFire Core.
npx boffinit cursor
What Boffin is not
- Not a static repo-wide rules file (
AGENTS.md-style one block for everything) - Not a prompt pack or system-prompt trick
- Not a linter or CI gate -- it acts before and after the edit
- Not a speed tool -- the frame is review-safety
What Boffin does
- Selects the constraints relevant to the edit in front of the agent
- Requires verification proportional to the change
- Ships for Cursor, Claude Code, Codex, and OpenCode from one npm package
- Delivers signed portable packs powered by ParselFire Core
How it differs (honest comparison)
Static rules file (AGENTS.md) |
Boffin | |
|---|---|---|
| Delivery | Usually one static block for the whole repo | Constraints routed to the current edit |
| Verification | None required by the format | Required, proportional to the change |
| Evidence | Usually none | Recorded case studies with numbers |
Proof, not promises
The public case studies record these guided refactors on real open-source code:
- DuckDB:
+17 / -17; 2,104 assertions
across 8 test files passed; distinct continuation and recovery paths were
preserved. - FastAPI:
+16 / -33; 49 tests passed;
no public API change. - LangChain: the sync/async boundary was
preserved; 4 tests passed.
These are reproducible case studies, not a controlled A/B benchmark.
Install
Boffin requires Node.js 18 or newer.
Cursor
Run from your project:
npx boffinit cursor
Claude Code
Run these inside Claude Code:
/plugin marketplace add MicSm/boffin
/plugin install boffin@boffin
Codex
Run these from a terminal:
codex plugin marketplace add MicSm/boffin
codex plugin add boffin@boffin
Codex does not trust plugin hooks automatically. Run /hooks once inside Codex
to review and trust Boffin's hooks; until then the plugin's skills work but the
automatic per-session activation stays off.
OpenCode
Run from your project:
npx boffinit opencode
Then open the project in OpenCode. Always-on guidance lands viaopencode.json -> .boffin/AGENTS.md. On demand: /boffin,/boffin-review, or the boffin / boffin-review skills.
Install details, commands, and troubleshooting:
OpenCode delivery.
Want the machinery? Read how ParselFire Core works.
What Boffin is fussy about
Similar code is not always the same code. Boffin gives the agent a reason to
stop before it merges a real special case, blurs a sync/async boundary, moves
state away from its owner, or turns a focused task into a tour of the codebase.
- For a focused change, it keeps the requested scope small and asks for the
narrowest check that proves the edit. - For an open-ended refactor or review, it requires a read-only audit first,
followed by one verified finding at a time. - When cleanup conflicts with an earlier correctness rule, correctness wins.
The point is not to make the agent timid. It is to make the expensive details
explicit before they become an interesting afternoon.
FAQ
How is Boffin different from AGENTS.md?
AGENTS.md is usually one static instructions file for the whole repository.
Boffin routes only the architectural constraints relevant to the file the agent
is about to edit, then requires a check proportional to the change.
Where do the constraints come from?
Every rule ships in this repository as readable, versioned markdown underpacks/, and the packs are GPG-signed. Nothing is hidden at install
time: open any pack and read every rule before trusting it. At edit time Boffin
selects which of those rules apply to the file being touched. See
how ParselFire Core works for the routing map.
Why does my coding agent turn small fixes into huge rewrites?
You ask for a small fix; the agent comes back with a renovation. Boffin
injects the load-bearing constraints for the current file before the edit and
forces verification afterward.
What do lite, full, and max change?
They tune cleanup ambition, not correctness:
litekeeps cleanup pressure low and favors the smallest useful change.fullis the balanced default.maxapplies the strongest cleanup pressure when the task justifies it.
On plugin hosts, select a profile with /boffin lite, /boffin full, or/boffin max. There is no off profile.
Do profiles change the safety floor?
No. Every profile keeps the same early correctness stages and rejection rules,
including trust-boundary validation, data-loss prevention, security, and
accessibility requirements.
Is Boffin a command sandbox or security tool?
No. Boffin does not isolate processes, filter shell commands, or restrict
filesystem or network access. It guides architectural decisions in generated
code. Use command sandboxes and security controls for their own job; Boffin has
a different job.
How do I uninstall the Cursor or OpenCode integration?
npx boffinit cursor uninstall
npx boffinit opencode uninstall
Each uninstaller removes that host's managed files only. Shared.boffin/packs and .boffin/VERSION stay if the other host is still
installed. Unrelated project files are left alone.
Does Boffin replace tests or code review?
No. It tells the agent which contracts deserve attention and requires external
checks, but your repository's tests and review process remain authoritative.
Other hosts
Portable adapters cover hosts that read AGENTS.md, CLAUDE.md, workspace
rules, or repository instructions. See
host delivery and adapters for
the technical map.
Project
- Repository: https://github.com/MicSm/boffin
- Engine documentation: ParselFire Core
- Evidence: Python and
C++ - Contributions: CONTRIBUTING.md
Boffin is available under the MIT License. See credits.
npx boffinit cursor
FAQ
Common questions
Discussion
Questions & comments · 0
Sign In Sign in to leave a comment.