Docs menu
Start
- Quick start
- Access tokens: GitHub, Gitea, GitLab
- Run your AI agent through it
- Choose what gets checked
- Let your agent ask the gate (MCP)
Setup in depth
Policy and frames
- Choosing what the gate checks
- Frames and kits
- Groups and whitelist
- Excluding paths from scans
- Writing your own frames
Operate
- Day-to-day operations
- Notifications and Auto-PR
- Multiple agents
- Audit log analyzer and agent comparison
- Agent stats API
Server
Security
Extend
Help
Frame reference
Docs / Frame reference
Frame reference
Every check nimblegate ships (57 frames): what each one catches in a push, its severity, and how to fix a finding.
BLOCK rejects the push
WARN lets it through, records the finding
INFO records only
Security14
- WARN Cloudflare Pages _headers must set the baseline security headers cf-pages-headers-baseline When a CF Pages headers file is present, surface a WARN for each missing baseline security header
- BLOCK No Unicode bidirectional override no-bidi-override Reject files containing Unicode bidirectional override characters. These reverse the visual rendering of code so the human eye sees one control-flow path...
- WARN No database dump in repo no-database-dump-in-repo Detect machine-generated database dumps committed to the repository. A dump is a snapshot of real data - customer records, hashed credentials, tokens - and...
- BLOCK No environment file in repo no-env-file-in-repo Detect live environment files (.env, .env.production, .env.staging, ...) committed to the repository. The values in an environment file are credentials by...
- BLOCK No hardcoded credentials no-hardcoded-credentials Detect committed secrets - API keys, access tokens, OAuth tokens - by matching well-known issuer prefixes. The intent: once a credential is pushed to a...
- WARN No homoglyph (Latin-confusable) characters in source no-homoglyph-identifiers Warn when source files contain Cyrillic or Greek letters that look identical to Latin letters in most fonts. Attack shape: a function or variable named...
- WARN No innerHTML for user input no-innerHTML-user-input Detect element.innerHTML = <expression patterns in JavaScript / TypeScript / HTML files. innerHTML assignment of untrusted input is the most common XSS...
- BLOCK No invisible Unicode tag characters no-invisible-tag-chars Reject files containing characters in the Unicode tag block (U+E0000–U+E007F). These render as zero pixels in every editor and terminal yet carry full...
- BLOCK No kubeconfig in repo no-kubeconfig-in-repo Detect Kubernetes client credentials committed to the repository. A kubeconfig with client-key-data is cluster access in one file - the base64 payload is a...
- WARN No http:// resources on HTTPS pages no-mixed-content-urls Reject HTML / Svelte / Astro pages that reference http:// resources via src= or href= attributes. On HTTPS pages, browsers block these as mixed content -...
- WARN No PII in source no-pii-in-source Detect real-looking personal data committed to the repository - payment card numbers, bank account numbers (IBAN), and national IDs in fixtures, seed data,...
- BLOCK No private keys in repo no-private-keys-in-repo Detect private cryptographic keys committed to the repository. Two detection paths run in parallel
- BLOCK No Terraform state in repo no-terraform-state-in-repo Detect Terraform state committed to the repository. State files hold every provider credential, connection string, and resource attribute in plaintext -...
- BLOCK No zero-width characters in source files no-zero-width-in-source Reject source files containing zero-width Unicode characters
Git safety5
- WARN Folder-to-branch lock folder-branch-lock Multi-folder repos with one branch per folder (orphan-branch pattern) are trivially easy to commit/push from the wrong folder. This frame verifies the...
- BLOCK No amend on pushed commits no-amend-pushed-commits Block git commit --amend when the commit being amended has already been pushed to a remote. Amending a pushed commit rewrites the SHA, which means every...
- BLOCK Commits must not skip hooks with --no-verify no-bypass-pre-commit Reject git commit --no-verify (and the short form -n). --no-verify is git's built-in mechanism to skip the pre-commit hook - which is exactly how nimblegate...
- BLOCK No force-push to main no-force-push-main Block git push --force (or -f) against protected branches (main, master, trunk, release/). This is the most common irreversible destruction of public history.
- BLOCK No .lfsconfig changes no-lfsconfig-changes Block any add / modify / delete of .lfsconfig. The file controls where Git LFS uploads go; a one-line change can silently redirect every future LFS upload...
App correctness12
- WARN Cloudflare GraphQL date ranges must fit the dataset's retention cf-graphql-dataset-by-window Catch Cloudflare Analytics GraphQL queries whose datetimegeq / dategeq range exceeds the queried dataset's Free-tier retention cap. CF rejects these...
- WARN Cloudflare GraphQL queries must select fields the dataset exposes cf-graphql-schema-match Reject CF GraphQL queries that select fields the dataset doesn't expose. The two failure modes are symmetric
- WARN SvelteKit dynamic public env vars must be declared dynamic-env-declared Reject SvelteKit components / TypeScript / JavaScript that read env.PUBLICX via $env/dynamic/public when PUBLICX isn't declared in wrangler.toml [vars] or...
- WARN Linters must not be switched off wholesale no-blanket-lint-disable Flags linters and type checkers turned off for a whole file or crate
- WARN The test command must run tests no-noop-test-script Flags a test command that runs nothing
- WARN Tests must be able to fail no-placeholder-tests Flags tests in test files that cannot fail
- WARN Production code must not detect test runs no-test-special-casing Flags code outside test files that checks whether it is running under test
- WARN Skipped and focused tests must be marked as intended no-unmarked-test-skips Flags tests that are switched off or that switch the rest of the suite off
- WARN CI must not be told to ignore failures no-weakened-ci Flags CI settings that let a failing step or job pass
- INFO Prefer static over dynamic public env vars in SvelteKit prefer-static-public Surface INFO-level findings on any $env/dynamic/public import. For build-time-known values, $env/static/public is safer: inlined at build, undefined imports...
- INFO Env-reading components imported at the top of a SvelteKit page top-of-page-import-safety Surface an INFO-level finding when a SvelteKit +page.svelte or +layout.svelte imports a component whose module body uses $env/dynamic/public. Components...
- WARN Column names in code must exist in the schema schema-vs-code-drift Reject code that references a column name in an UPPERSNAKECASECOLS array when that column doesn't exist in any committed schema.sql or migrations/.sql....
Command safety6
- WARN Approved registries only approved-registries-only Flag dependency-source declarations that route around the organisation's approved registry. Teams that run an internal registry mirror gate every dependency...
- BLOCK apt purge - require simulate first apt-purge-preview apt purge X can cascade through transitive dependencies and remove core platform packages. Block uninspected purges; require the user to first run apt purge...
- BLOCK No curl | sh curl-pipe-shell Block committed shell scripts (and Dockerfiles) that pipe a remote fetch directly into an interpreter. The pattern is convenient and ubiquitous - curl...
- BLOCK Migration scripts must name the target environment migration-script-explicit-env Reject bash scripts that invoke a multi-env CLI (wrangler, gcloud, kubectl, vercel, flyctl, supabase, firebase, heroku) without an explicit env-scope flag -...
- BLOCK Migration scripts must verify the change after applying it migration-verification-step Reject apply--migration wrapper scripts that DDL-apply but never query the target afterwards to confirm the change is visible. Silent failures on the apply...
- BLOCK Destructive SQLite migrations need an idempotent wrapper sqlite-migration-idempotent-wrapper Reject .sql migration files containing destructive / non-idempotent DDL (ALTER TABLE ADD/DROP/RENAME COLUMN, RENAME TABLE) unless either
Filesystem safety1
Network safety2
- WARN CIDR ranges must not have host bits set cidr-host-bits-zero Reject IPv4 CIDR strings with host bits set (e.g. 142.132.208.101/24). Cloudflare, AWS Security Groups, GCP firewall, UFW, and Kubernetes NetworkPolicy all...
- WARN Reverse proxies must not point at localhost no-localhost-in-proxy-config Reject reverse-proxy config files that name localhost as the upstream target. Modern Go-based proxies (cloudflared, anything using the Go net resolver) try...
Encoding8
- BLOCK Consistent line endings consistent-line-endings Block two specific line-ending hazards
- BLOCK No UTF-8 byte-order mark no-bom Reject text files that begin with the UTF-8 byte-order mark (EF BB BF, U+FEFF). The BOM is unnecessary for UTF-8 and silently breaks shell scripts...
- BLOCK No en/em-dash adjacent to command flags no-en-dash-in-commands Block en-dash (U+2013, –) and em-dash (U+2014, -) when they appear immediately adjacent to an alphabetic character. This catches the classic AI-paste /...
- BLOCK No mixed tab + space indentation no-mixed-indent Block lines whose leading whitespace contains both tabs and spaces. The two render identically in many editors but bind differently to whatever consumes the...
- WARN No non-printable control characters no-non-printable Warn on C0 control characters (U+0000–U+001F, excluding tab / LF / CR) and C1 control characters (U+0080–U+009F). These typically arrive from raw paste of...
- BLOCK No smart / curly quotes in config no-smart-quotes-in-config Reject config files containing typographic ("smart") quotes: U+2018-U+201F. These render like ASCII " and ' but parsers reject them - silently in some YAML...
- WARN No zero-width characters in docs / prose no-zero-width-in-content Warn on zero-width Unicode runes (U+200B/U+200C/U+200D/U+FEFF) in documentation and prose files. These render invisibly, but
- BLOCK No tabs in YAML indentation yaml-no-tabs YAML does not permit tab characters in indentation. Most parsers fail on the first tab with expected <block end, but found '<tab' or a similarly cryptic...
Conventions9
- WARN Cross-branch ID consistency cross-branch-id-consistency When a project uses canonical ID tables (analytics website IDs, API token tags, external service identifiers), files in different folders/branches must...
- WARN Naked TODOs must carry a date, owner, or issue link dated-todo Scans staged files for TODO, FIXME, HACK, and XXX markers that don't include at least one of
- WARN Documentation must move with the code doc-touches-with-code A commit that changes source files declared in code-doc-map.toml must also include a staged change to the mapped documentation file. The intent is to keep...
- WARN Markdown internal link check markdown-link-check-internal Scans Markdown files for inline text and links that look like project-relative paths and verifies each target exists. External links (http://, https://,...
- WARN Every image needs an alt attribute html-img-alt Every <img tag must have an alt attribute. The empty form alt="" is intentional in HTML5 and explicitly satisfies this check - it signals "decorative image,...
- WARN HTML markup must be valid html-markup-valid HTML markup validation pass - the class of problems Vite, the HTML5 spec, and downstream tooling (RSS readers, AMP validators, social-card scrapers)...
- WARN No placeholder text in shipped pages html-placeholder-content Surface a WARN when shipping HTML / Svelte / Astro / Markdown content contains placeholder patterns that escape into production embarrassingly often
- WARN Every HTML page needs the required meta tags html-required-meta Every shipping HTML page (plain .html, SvelteKit +page.svelte / +layout.svelte, Astro .astro) must declare
- WARN HTML pages should carry SEO and social meta tags html-seo-meta Surface a WARN when HTML pages are missing the standard SEO + social meta set