LOCAL SCAN
Scan Workspace
Free. No API key. Full JS/TS coverage and a first pass for Python (poetry, uv, pinned requirements.txt). Writes COPPICE.md and a Cursor rule so the next agent extends what exists.
CODEBASE GOVERNANCE FOR CURSOR
Agents forget what the last session built. Coppice scans the repo, writes a short contract, and injects it into the next Cursor session. This site is history for your GitHub projects — not a second IDE.
Scans run in Cursor. This page is the public site — dashboard login needs the Coppice API.
01
Coppice asks GitHub for your identity and repo list. You land on the dashboard. No Cursor API key on this site.
02
Pick the GitHub repo you already vibe in. Coppice does not clone or scan GitHub as the product.
03
Run Scan Workspace (free) or Agent Scan. After sign-in, the extension can upload contract + findings here.
One structure, one pattern, one library per job. Keep src/app/ or frontend/ + backend/. Do not invent src/modules/.
Auth already exists? Extend it. Do not add a sibling login. Next app/api is a route, not a feature.
Unused files, exports, and packages get pruned. Config and CSS count. Toolchain peers stay.
CVE at the exact lockfile version via OSV. Bump the winner, or remove if unused. Never add a second library to “fix” it.
LOCAL SCAN
Free. No API key. Full JS/TS coverage and a first pass for Python (poetry, uv, pinned requirements.txt). Writes COPPICE.md and a Cursor rule so the next agent extends what exists.
AGENT SCAN
On-demand Cursor SDK for Laravel, Go, Rails, and deeper Python. Billed to your Cursor Models pool (Composer 2.5). Same finding JSON. Does not invent CVEs. Never asked on a JS/TS-only local scan.
After GitHub authorization, the dashboard lists linked repos and scan history (local engine vs Agent Scan). The gardener still lives in Cursor.