
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
Cursor installer and shared delivery assets for Boffin, routed architectural guardrails for AI coding agents
You asked for a small fix. Your AI agent came back with a renovation.
Boffin is the brilliant, fussy technical expert who reads the diff and refuses to let your coding agent knock out a load-bearing wall.
Boffin gives coding agents the relevant architectural constraints before they edit, then makes them verify the result. It is powered by ParselFire Core.
The public case studies record these guided refactors on real open-source code:
+17 / -17; 2,104 assertions
across 8 test files passed; distinct continuation and recovery paths were
preserved.+16 / -33; 49 tests passed;
no public API change.These are reproducible case studies, not a controlled A/B benchmark.
Boffin requires Node.js 18 or newer.
Run from your project:
npx boffinit cursor
Run these inside Claude Code:
/plugin marketplace add MicSm/boffin
/plugin install boffin@boffin
Run these from a terminal:
codex plugin marketplace add MicSm/boffin
codex plugin add boffin@boffin
Codex does not trust plugin hooks automatically. Run /hooks once inside Codex
to review and trust Boffin's hooks; until then the plugin's skills work but the
automatic per-session activation stays off.
Want the machinery? Read how ParselFire Core works.
Similar code is not always the same code. Boffin gives the agent a reason to stop before it merges a real special case, blurs a sync/async boundary, moves state away from its owner, or turns a focused task into a tour of the codebase.
The point is not to make the agent timid. It is to make the expensive details explicit before they become an interesting afternoon.
Portable adapters cover hosts that read AGENTS.md, CLAUDE.md, workspace
rules, or repository instructions. See
host delivery and adapters for
the technical map.
lite, full, and max change?They tune cleanup ambition, not correctness:
lite keeps cleanup pressure low and favors the smallest useful change.full is the balanced default.max applies the strongest cleanup pressure when the task justifies it.On plugin hosts, select a profile with /boffin lite, /boffin full, or
/boffin max. There is no off profile.
No. Every profile keeps the same early correctness stages and rejection rules, including trust-boundary validation, data-loss prevention, security, and accessibility requirements.
No. Boffin does not isolate processes, filter shell commands, or restrict filesystem or network access. It guides architectural decisions in generated code. Use command sandboxes and security controls for their own job; Boffin has a different job.
npx boffinit cursor uninstall
The uninstaller removes Boffin-managed files only and leaves unrelated Cursor rules and unknown project files alone.
No. It tells the agent which contracts deserve attention and requires external checks, but your repository's tests and review process remain authoritative.
Boffin is available under the MIT License. See credits.
FAQs
Boffin: staff-engineer layer for AI coding agents. Routes per-edit architectural constraints and requires verification. Not a static AGENTS.md. Install: npx boffinit cursor
The npm package boffinit receives a total of 14 weekly downloads. As such, boffinit popularity was classified as not popular.
We found that boffinit demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.