Stop your coding agents from taking shortcuts and drifting.
Workspine is a CLI tool that runs coding agents in disciplined steps: subagents audit plans before execution, wait for your approval in PLAN.md, write code in clean context batches, and verify the live app in headless Playwright. No cloud lock-in: everything is saved to your repo as Markdown in .work/.
How It Works (In 3 Steps)
Click a step to see the real files and output:The agent hid the button in React (display: none). Unit tests passed, but /api/invites had 0 server auth and leaked admin access to anyone with curl.
Plan-checker subagent audits the plan in a fresh context, flags the security flaw, and locks server middleware into PLAN.md before you approve it.
// ✖ REJECTED BY PLAN-CHECKER:
- Shortcut: Hide UI button in components/InviteModal.tsx
- Flaw: Backend route /api/invites is still vulnerable to raw cURL
// ✓ LOCKED IN PLAN.md:
+ Task 1: Add token verification to src/middleware/authGateway.ts
+ Task 2: Assert HTTP 403 Forbidden with Playwright
→ Awaiting Owner Approval in .work/phases/01-PLAN.mdThe 3 Commands You Run
Single-wave, zero ceremony. Targets one file, writes proof, and closes.
Spawns subagents to plan dependencies, audit shortcuts, and wait for your approval.
Freezes state into .work/.continue-here.md. Resume tomorrow with zero prompt rot.
Workspine does not store your code or state in proprietary databases. Every plan, decision, and proof is committed to .work/ right next to your code.
Why Unsupervised Coding Agents Fail
When an AI agent is given free rein, it optimizes for declaring the task complete as quickly as possible.
- ✕Lazy UI Shortcuts: Hides buttons in CSS with
display:noneinstead of adding backend authentication. - ✕Mocked Test Illusion: Modifies test mocks so tests turn green without verifying real runtime behavior.
- ✕Context Rot: 100k+ token sessions cause hallucinated imports and deleted functions.
- ✓Pre-Execution Audit: Plan-checker rejects client-only patches and enforces server middleware before code executes.
- ✓Live Browser Proof: Headless Playwright tests actual DOM rendering and network HTTP status codes.
- ✓Isolated Wave Context: Fresh context per task wave eliminates memory drift and prompt rot.