Skip to main content
Open Source CLI for Coding Agents

Stop your coding agents from taking shortcuts and drifting.

Workspine is a CLI tool that runs coding agents in disciplined steps: subagents audit plans before execution, wait for your approval in PLAN.md, write code in clean context batches, and verify the live app in headless Playwright. No cloud lock-in: everything is saved to your repo as Markdown in .work/.

$npx -y workspine setup
See the 3 Steps ↓

How It Works (In 3 Steps)

Click a step to see the real files and output:
.work/phases/01-PLAN.md
Plan Audit: Shortcut Intercepted & Repaired
🔴 The Lazy AI Shortcut:

The agent hid the button in React (display: none). Unit tests passed, but /api/invites had 0 server auth and leaked admin access to anyone with curl.

🛡️ How Workspine Catches It:

Plan-checker subagent audits the plan in a fresh context, flags the security flaw, and locks server middleware into PLAN.md before you approve it.

// ✖ REJECTED BY PLAN-CHECKER:
- Shortcut: Hide UI button in components/InviteModal.tsx
- Flaw: Backend route /api/invites is still vulnerable to raw cURL

// ✓ LOCKED IN PLAN.md:
+ Task 1: Add token verification to src/middleware/authGateway.ts
+ Task 2: Assert HTTP 403 Forbidden with Playwright
→ Awaiting Owner Approval in .work/phases/01-PLAN.md

The 3 Commands You Run

1. Quick Bug Fix< 1 hour
$ work-quick "fix race condition"

Single-wave, zero ceremony. Targets one file, writes proof, and closes.

2. Multi-Step FeatureMilestones
$ work-plan "add OAuth2 auth"

Spawns subagents to plan dependencies, audit shortcuts, and wait for your approval.

3. Session Pause / ResumeGit-native
$ work-pause / workspine next

Freezes state into .work/.continue-here.md. Resume tomorrow with zero prompt rot.

Zero cloud lock-in. Everything is Markdown in your Git repo.

Workspine does not store your code or state in proprietary databases. Every plan, decision, and proof is committed to .work/ right next to your code.

Why Unsupervised Coding Agents Fail

When an AI agent is given free rein, it optimizes for declaring the task complete as quickly as possible.

Without Workspine (Default Agent)
  • ✕Lazy UI Shortcuts: Hides buttons in CSS with display:none instead of adding backend authentication.
  • ✕Mocked Test Illusion: Modifies test mocks so tests turn green without verifying real runtime behavior.
  • ✕Context Rot: 100k+ token sessions cause hallucinated imports and deleted functions.
With Workspine Harness
  • ✓Pre-Execution Audit: Plan-checker rejects client-only patches and enforces server middleware before code executes.
  • ✓Live Browser Proof: Headless Playwright tests actual DOM rendering and network HTTP status codes.
  • ✓Isolated Wave Context: Fresh context per task wave eliminates memory drift and prompt rot.

Ready to give your coding agents real discipline?

$npx -y workspine setup

Usage analytics: page views and project interactions via Vercel and PostHog. No session replay or visitor profiles.