KICKSTART, I-10/3 KORANG ROAD
← Back to case studies
Developer Tooling

Coppice — Codebase Governance for Cursor

Gardener for vibe-coded repos: architecture contract, no duplicate features, orphan hygiene, and lockfile CVEs—so the next agent extends what already exists

Overview

Coppice is TekReign’s codebase governance gardener for Cursor. Each agent run is stateless; Coppice is the memory. It scans the workspace on your machine, derives an architecture contract, scores findings, and writes COPPICE.md plus a Cursor rule so the next session extends the existing layout instead of inventing a sibling.

Project details

Client

TekReign Product

Duration

Ongoing product

Category

Developer Tooling

Live ProjectVisit Live Project

Key Results

Architecture Contract
Local Scan in Cursor
Lockfile CVE Hygiene

The Challenge

Vibe-coded repos drift: a second UI library, a second HTTP client, a second login, unused files, and known-bad package versions quietly accumulate. Agents do not remember the last session. Teams needed a contract that lives in the repo—not another cloud scanner and not a second implementation of the same feature.

Our Solution

We shipped Coppice as a Cursor gardener with a local-first scan model: • Architecture contract: one folder layout, one design pattern per job, one library per job • Duplicate features: extend the existing module; do not create a sibling • Orphan hygiene: unused files, exports, and packages get pruned instead of accumulating • Security: CVEs at the exact lockfile version, and secrets in the repo—fix by bumping the winner or removing an orphan, never by adding a second library • Local scan (free, no API key): full JS/TS coverage plus a first-pass Python read, on folder open and lockfile change • Agent Scan (on-demand, Cursor SDK): Python, Laravel, Go, Rails and others; billed to your Cursor plan; same finding JSON; never invents CVEs • Free plan: gardener in the editor, one linked GitHub repo and the latest scan • Premium: GitHub-linked history, billed on GitHub Marketplace—unlimited repos, explore board, ticket/PR overlay, local vs Agent Scan overlay • Scans never run in the cloud

The Results

Coppice keeps prompting honest without adding a second stack: • The next agent sees COPPICE.md and a Cursor rule before it writes • One architecture, no duplicate work, no dead code, no known-bad package versions • Free gardener in the editor; Premium GitHub history billed on GitHub, not a Coppice card • Agent Scan stays on your Cursor plan • Live product at coppice.tekreign.com

Technologies Used

Cursor extensionVS Code extensionCOPPICE.md contractCursor rulesLocal JS/TS scanCursor SDK Agent ScanGitHub Marketplace (Premium)Lockfile CVE matching
“Keep prompting. Coppice keeps the repo honest—one architecture, no sibling logins, and CVEs at the lockfile version, scanned on the machine instead of in the cloud.”

Engineering Lead

Coppice user