
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
Your agent wrote 40 markdown files last week. How many of them are lies?
DocGov is the adult in the room for AI-written docs. It decides where files go, notices when two documents contradict each other, and tells you what went stale the moment you change code.
It's a Claude Code plugin and a standalone CLI. Node 20+, zero dependencies, nothing leaves your machine.
You point it at a repo that's been vibe-coded for a few months:
$ docgov review
DocGov review
─────────────
5 documents inventoried · 0 machine contracts · stack: none detected
Finding Count
----------------------------- -----
unclassified 3
low-confidence classification 1
moves proposed 1
frontmatter to add 5
suspected duplicates 0
missing documents 2
Plan written to .docgov/fix-plan.md — nothing has changed.
4 of 11 actions need a judgement call.
Read the plan, delete anything you disagree with, then: docgov fix --dry-run
Nothing moved. It wrote you a plan. You read it, delete the parts you disagree with, and run
docgov fix — which works on a branch and reverts itself if anything fails to verify.
claude plugin marketplace add ZeeshanSultan/DocGov
claude plugin install docgov
That gets you the hooks, which are the good part: your agent gets handed the rules before it edits governed code, and gets stopped before it writes a doc in the wrong place.
Not using Claude Code? The CLI works on its own, and it's the same binary CI runs:
npx docgov-cli setup
(The package is docgov-cli because npm won't hand out docgov. The command you type is
still docgov.)
Your first five minutes:
docgov setup # turn it on. infers your project's shape, writes .docgov/config.yaml
docgov review # look at the docs you already have. writes a plan, changes nothing
docgov fix # run the plan, on a branch, reverting itself if verification fails
Then, day to day:
docgov check # did I just break a rule?
docgov stale # which docs did the code move out from under?
docgov affected # I changed this — what do I need to update?
docgov health # how bad is it, out of 100?
Every command takes --json. Full list: docs/reference/commands.md.
| Knows what a document is | 57 document classes. Each one has a place it belongs, sections it must have, and a size past which it stops being that kind of document. Point it at a file and it'll tell you what you wrote. |
| Knows which docs outrank which | Your spec beats the tutorial that paraphrases it. A README can't quietly contradict an ADR. When two documents disagree, there's a defined answer for which one is wrong. |
| Hands your agent the rules | Write INV-LIC-001 A license belongs to exactly one organization. in a spec, map it to the code it governs, and every agent that touches that code gets the rule before it writes a line. Cheapest useful thing in here. |
| Notices when docs go stale | Code moved and the doc didn't. Spec moved and the code didn't. Your OpenAPI file is ahead of the page describing it. Scored by what changed around a document, not by how old it is. |
| Tells you what to update | You changed this file — here are the docs that need to change with it, split into required and optional, as a checklist your agent can work through and CI can check. |
| Packs context for agents | docgov brief billing returns the minimum authoritative context for an area and nothing else. It's the only documentation your agent pays tokens for. |
| Won't let you leak | Before anything goes public it flags what would leak and writes rewrite briefs. An external doc is a different artifact, not a redacted copy. Nothing publishes automatically. |
Two halves, and the split is the whole design:
Software decides what blocks. Is this id a duplicate? Is this file in the right place? Did code change that a spec claims to describe? Same answer in your editor and in CI, and it can always show its working.
A model decides what's subjective. Do these two documents actually contradict each other? Should this be split? Is this prose still true? Reported for review, never enforced.
An LLM never decides whether
docgov.idis duplicated. Software never decides whether your prose is clear.
A governance tool that blocks a README typo gets uninstalled, so enforcement ramps: adopting
DocGov on a repo that already has docs starts in warn-only, and setup tells you when to turn
that off.
fix needs git and a clean tree. "Without losing anything" is only a real promise if
every change is revertible.npm test runs 63 tests against real temporary git repos. DocGov governs its own repository,
so docgov check --all here is a real end-to-end test.
MIT.
FAQs
Your AI writes docs faster than anyone can check them. DocGov checks them.
The npm package docgov-cli receives a total of 6 weekly downloads. As such, docgov-cli popularity was classified as not popular.
We found that docgov-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.