gavel
Code quality platform for Bazel monorepos — static analyzers as aspects, SARIF, quality gates
Install / Use
claude mcp add gavelcode -- npx -y github:gavelcode/gavelIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of gavel
gavel scores 80/100 on our quality scale, 3574th of 4,594 Development & Engineering skills we index.
Its MCP Server is 7.0 KB long, well organised into 14 sections with 5 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated today, so gavel is actively maintained.
- Our last check on 2026-09-25 found the source still online.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (1 minor note below). An AI review of the same text found nothing harmful.
- noteInstalls by piping a downloaded script into a shellline 34
curl -fsSL https://raw.githubusercontent.com/gavelcode/gavel/main/install.sh | sh
AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
gavel compared with similar skills
All 4 of these similar skills score higher than gavel; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| gavel (this skill)by gavelcode | 80 | 10 | today | MCP Server |
| Agent-Reachby Panniantong | 100 | 92.4k | 21d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 45.1k | 1d ago | CLAUDE.md |
Frequently asked questions
- How do I install gavel?
- Run
claude mcp add gavelcode -- npx -y github:gavelcode/gavel. The install tabs above show the steps for each supported agent. - Which AI agents does gavel work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is gavel safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands (1 minor note below). An AI review of the same text found nothing harmful. It is Apache-2.0-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is gavel still maintained?
- The repository was last updated today, so gavel is actively maintained.
Skill content
View source on GitHubGavel
Bazel builds your monorepo. Gavel judges it. Order in the codebase!
The quality gate for Bazel monorepos — build-graph-native, local, agent-ready.
Your monorepo builds green. That's not the same as innocent. Gavel gathers the
evidence as Bazel aspects, holds every change to the law you set in gavel.yaml,
and returns a verdict: the regression you just introduced stands charged, while a
decade of existing debt is not on trial. One verdict, handed to your CI, your
terminal, and your coding agent alike.
gavel init # open the case
gavel judge # hear it

Install
# Homebrew — macOS & Linux
brew install gavelcode/tap/gavel
# or the install script — Linux, CI, Docker
curl -fsSL https://raw.githubusercontent.com/gavelcode/gavel/main/install.sh | sh
Prebuilt binaries for every platform are on the releases page.
Gavel needs a Bazel 8.0+ (bzlmod) workspace; verify with gavel --version.
bazel build //apps/cli/cmd/gavel
# binary at bazel-bin/apps/cli/cmd/gavel/gavel_/gavel
</details>
How it works
Every change gets its day in court.
1. The evidence comes from the build graph
Analyzers — golangci-lint, PMD, CPD, SpotBugs, Error Prone, Ruff, Bandit,
ESLint, Clippy — run as Bazel aspects. They see the exact source tree,
dependency graph, and toolchains Bazel already resolves; no separate scanner, no
second config to drift. SonarQube re-scans the world; Gavel looks only at the
targets the graph says changed (--affected), so a run stays fast as the
monorepo grows. Every tool, every language, normalized to one format: SARIF.
2. You're only tried for what you changed
gavel.yaml is the quality gate — code, reviewed and versioned with the
repo, not clicked into a web UI. It evaluates only what you just added against a
committed baseline: new findings, coverage regressions, new architecture
violations. Adopt Gavel on ten years of debt and it blocks on today's diff,
never on the backlog.
projects:
- name: payments
pattern: "//payments/..."
tooling:
go: [golangci-lint, archtest]
quality_gate:
findings: { max_error: 0 }
coverage: { min: 80 }
architecture_violations: { max: 0 }
Every run saves a fingerprint snapshot; the next shows the delta — new, fixed, existing — plus the coverage trend. No server required.
payments/api/handler.go:42 error null check missing golangci-lint:nilerr NEW
⚖ VERDICT: FAIL — code_quality
1 new · 8 fixed · 31 existing coverage 73.5% (↑5.0%) architecture PASS
3. A verdict your coding agent can request
Coding agents write code they can't see the consequences of — a lint regression,
a coverage drop, a layering violation land three commits later in CI. gavel mcp
starts a Model Context Protocol server that
exposes judge, lint_file, findings, coverage, and arch as tools. Point
Claude Code, Cursor, or Zed at it and the agent checks its own work against the
same Bazel-aware gate as it writes — a quality conscience, inline.
For editors and dashboards, gavel watch re-analyzes on every save and emits a
JSONL event stream. Both run fully local — no server, no network.
Gavel vs SonarQube: the case
| | SonarQube | Gavel |
|---|---|---|
| Build-graph awareness | None | Bazel aspects understand target dependencies |
| Monorepo model | One project, or a branch per project | Hierarchical: per-package, per-project, whole repo |
| Analysis scope | Full scan or file diff | Bazel-aware: changed files + affected targets |
| Local workflow | Server round-trip | Fully local, zero network |
| Coding-agent / editor loop | — | MCP server + watch event stream |
| Quality gate | Web-UI config | Code (gavel.yaml), versioned with the repo |
| Progress tracking | Server-backed | Local fingerprint snapshots, no infrastructure |
| Footprint | Java server + database + scanner | One static Go binary, runs inside Bazel |
SonarQube is a mature platform with fifteen years of rules behind it, and Gavel isn't trying to replace it. Gavel answers a question SonarQube structurally can't: which packages of my Bazel monorepo are healthy, and did this change make one of them worse — where the build graph is the unit of analysis and the inner loop is where quality is actually won.
Already running aspect's rules_lint? Keep it. Gavel reads the SARIF it drops in
bazel-bin/(gavel judge --findings-source=rules_lint) and turns those reports into a gate — baseline delta, coverage, architecture, verdict — the layer rules_lint deliberately leaves to you.
Status
Alpha — v0.1.0. Under active development; APIs and config formats may change. Gavel gates its own repository on every commit — it is its own first user.
Working today:
gavel init— scaffold config + Bazel integrationgavel judge— analyze, evaluate the gate, show findings and the deltagavel judge --project <name>·--quick·--summary·--affected— scope and shape the rungavel judge --absolute— evaluate all findings (release gates, nightly)gavel judge --json·--output-sarif report.sarif— structured output for CI, IDEs, GitHub Code Scanninggavel judge --server URL --token TOKEN— shared team baseline: fetch and submitgavel watch— re-analyze on change, emitting a JSONL event streamgavel mcp— Model Context Protocol server for editor / agent integrationgavel validate— check Bazel integration health- Baseline mode (default): fingerprint-based new/fixed/existing classification, committed to git for the team
- Analyzers: golangci-lint, PMD, CPD, SpotBugs, Error Prone, Ruff, Bandit, ESLint, Clippy
- Server (optional): web dashboard, centralized history, team baselines, API-token auth
Documentation
- Quickstart — from zero to a first verdict in five minutes
- Configuration —
gavel.yamlandarchitecture.yml, field by field - Baseline & delta — how new / fixed / existing is decided
- Server deployment — running
gavel-server - Full documentation index
Contributing
Issues and pull requests are welcome — see CONTRIBUTING.md and our Code of Conduct. Security reports go through SECURITY.md.
License
Related Skills
Agent-Reach
92.4kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
ai-job-search
45.1kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
