Govern AI coding agents with evidence your auditor can file.
Every repository’s agent instructions and MCP servers, inventoried and tested against 8 controls, cross-referenced to SOC 2, ISO/IEC 27001:2022, ISO/IEC 42001:2023, NIST AI RMF 1.0. Generated on your machine; nothing is uploaded.
Inventory
Which repositories instruct which agents, every instruction file, and every MCP server agents can call, with transport and source.
Controls
Secrets, hidden characters, remote-code instructions, bypassed checks, unpinned tools, ownership and accuracy, each tested across the fleet.
Evidence pack
Print-ready HTML with scope, method, results, framework cross-reference and sign-off, plus CSVs and a SHA-256 tying it to the raw data.
What is tested, and where it maps.
Each control is tested with the rules listed beside it: reproducible code, no AI. False-positive rates are published with their sample size wherever enough real findings exist to measure them. Framework references show where the evidence is commonly relevant.
| Control | Tested by | Framework references |
|---|---|---|
| TC-01 AI coding agents and their tools are inventoried The organisation knows which repositories give instructions to which AI coding agents, and which MCP servers those agents can call. | The audit itself (inventory) | SOC 2 CC6.1 — Logical access: inventory of information assets ISO/IEC 27001:2022 A.5.9 — Inventory of information and other associated assets ISO/IEC 42001:2023 A.4.4 — Tooling resources NIST AI RMF 1.0 GOVERN 1.6 — Mechanisms are in place to inventory AI systems |
| TC-02 Secrets are kept out of agent instructions and tool configuration No credential, token or key is written into a file that AI agents read or into an MCP server configuration. | CTX-X005 | SOC 2 CC6.1 — Logical access: protection of credentials ISO/IEC 27001:2022 A.5.17 — Authentication information ISO/IEC 27001:2022 A.8.12 — Data leakage prevention NIST AI RMF 1.0 MEASURE 2.7 — AI system security and resilience are evaluated |
| TC-03 Agent instructions are free of hidden or injected content Instruction files contain no invisible or bidirectional characters, encoded payloads, or instructions to download and run remote code. | CTX-X001CTX-X002CTX-X003 | SOC 2 CC6.8 — Prevent or detect unauthorised or malicious software ISO/IEC 27001:2022 A.8.7 — Protection against malware ISO/IEC 27001:2022 A.8.28 — Secure coding NIST AI RMF 1.0 MEASURE 2.7 — AI system security and resilience are evaluated |
| TC-04 Agents are not told to bypass quality and security checks No instruction tells an agent to skip tests, disable linters or checks, or hide changes from review. | CTX-X004 | SOC 2 CC8.1 — Change management: changes are tested before implementation ISO/IEC 27001:2022 A.8.29 — Security testing in development and acceptance ISO/IEC 42001:2023 A.6.2.4 — AI system verification and validation |
| TC-05 Third-party agent tools are pinned and authenticated MCP servers, skills and rule packs are pinned to a version or hash, and remote servers use TLS and authentication. | CTX-X006CTX-X007CTX-X009 | SOC 2 CC9.2 — Risks from vendors and business partners are assessed and managed ISO/IEC 27001:2022 A.5.21 — Managing information security in the ICT supply chain ISO/IEC 42001:2023 A.10.3 — Suppliers NIST AI RMF 1.0 GOVERN 6.1 — Policies address risks from third-party entities |
| TC-06 Agent instructions have owners and reviewed changes Every instruction file is covered by CODEOWNERS, and generated files are changed only at their source. | CTX-G001CTX-G002CTX-G003 | SOC 2 CC8.1 — Change management: changes are authorised and approved ISO/IEC 27001:2022 A.8.32 — Change management ISO/IEC 27001:2022 A.8.4 — Access to source code NIST AI RMF 1.0 GOVERN 2.1 — Roles and responsibilities are documented |
| TC-07 Agent instructions are accurate and consistent Instructions match the repository (paths, scripts, package manager, versions) and do not contradict each other across files and tools. | CTX-S003CTX-S004CTX-D001CTX-D002CTX-D003CTX-D005CTX-C001CTX-C002CTX-C003 | SOC 2 CC2.1 — Relevant, quality information supports internal control ISO/IEC 27001:2022 A.8.9 — Configuration management ISO/IEC 42001:2023 A.6.2.7 — AI system technical documentation NIST AI RMF 1.0 MAP 2.2 — Knowledge limits and how outputs are used are documented |
| TC-08 Agent context is monitored over time The audit is repeated and compared with the previous run, so regressions are found and followed up. | Comparison with the previous audit | SOC 2 CC4.1 — Ongoing and separate evaluations SOC 2 CC7.1 — Detection of configuration changes and vulnerabilities ISO/IEC 27001:2022 A.8.16 — Monitoring activities NIST AI RMF 1.0 MANAGE 4.1 — Post-deployment monitoring plans are implemented |
Scope of the evidence. threadctx produces evidence about AI coding agent configuration. It is not an attestation, certification or audit opinion. Framework references show where the evidence is commonly relevant; your auditor decides whether it is sufficient for a control.
One command, on your machine.
The audit lists your organisation’s repositories with your own GitHub token, reads only agent context files and the manifests they cite, and writes the reports locally. Run it before an audit window, or on a schedule with Team for continuous evidence.
- evidence.html — cover, summary, method, controls, cross-reference, inventory, sign-off. Save as PDF.
- controls.csv — one row per control and framework reference.
- inventory.csv — every agent instruction file and MCP server.
- audit.json — the raw data; its SHA-256 is printed in the pack.
Open a real sample, generated from our own GitHub organisation.
Agent context audit: acme Fleet grade C (74/100 average) 48 repositories scanned · 31 with agent context 6 blockers · 41 warnings AI governance controls (SOC 2, ISO 27001, ISO 42001, NIST AI RMF): 5/8 met · 2 need attention · 1 gap Full report written: threadctx-audit-acme/report.html threadctx-audit-acme/evidence.html threadctx-audit-acme/controls.csv threadctx-audit-acme/inventory.csv threadctx-audit-acme/audit.json
Built so there is nothing to breach.
threadctx analyses your repositories where they already are. We never receive your code, your instruction files or your findings.
| Component | Where it runs | What it reads | What leaves |
|---|---|---|---|
| CLI, Action, MCP server | Your machine or CI runner | Local files | Nothing. No telemetry. |
| Org audit | Your machine | Agent context files via the GitHub API, with your token | Requests to GitHub only. Reports are written locally. |
| Licence check | Your machine | The licence key (Ed25519 signature) | Nothing. Verified offline. |
| Web grader | threadctx.dev | Public files of public repositories | Grade cached for an hour. Security findings never shown. |
| Checkout | Stripe | Email, organisation name, payment | We keep the order reference to issue your licence. |
Supply chain
- Single-file CLI with zero runtime dependencies
- Third-party licences shipped with every release
- GitHub Action and its steps pinned by commit SHA
- Apache-2.0 licensed; the npm package ships readable, unminified JavaScript
Subprocessors
- Stripe — payments and billing portal
- Vercel — hosting of threadctx.dev
- Cloudflare — DNS and email routing
None of them receive your code or findings.
Vulnerability disclosure
Report privately to security@threadctx.dev. We acknowledge within 3 working days and aim to fix within 30. security.txt
Vendor questionnaires
threadctx does not hold a SOC 2 report of its own. Because our servers never process your code or findings, most vendor-security questions do not apply; we are glad to complete your questionnaire. Send it to us.
Walk into your next audit with the answer.
Start with the free summary, then unlock the evidence pack with a $299 snapshot.