Developer-first AI safety checks. Secret scanning + prompt-policy lint in one zero-dep Python CLI.
Four capabilities in one lightweight package — catch secrets and policy violations before they reach your main branch.
Detects leaked API keys, tokens, private keys, and common credential formats in tracked files.
Catches deny-listed patterns in AI-facing text assets — system prompts, configs, and instruction files.
stdlib only. pip install is instant, works in any sandbox, no supply chain risk.
Ships as CLI, GitHub Action, Claude Code skill, and Cursor rule — fits wherever you already work.
Scans your repo for two classes of issues before a PR lands. Choose baseline (CI-friendly) or strict (release audits) profile.
Pick the channel that fits your workflow. All four run the same scan engine.
wrg-devguard ships the same scan engine across every distribution surface. Whether you run it locally, in CI, or let your AI agent invoke it — same rules, same output, same exit codes.
Install from PyPI. Add to CI. Let your agent run it. Zero config, zero deps.