Plugins
Scruple plugins package named, tested rules. They can check common engineering problems or standards your team repeats in review. Register each factory under the namespace used by its rule IDs, then enable individual rules in rules.
Rules start from bounded parser targets. They can use the configured provider to classify ambiguous possible candidates, then send selected candidates for the final rule decision. A finding appears only when the provider chooses the finding label and its final answer clears the rule's probability and confidence thresholds.
Every threshold option is an object with warning and error probabilities. The numeric form is not accepted, and warning cannot exceed error. Scores from warning up to error produce non-blocking warnings. Scores at or above error produce blocking errors. The rule must also meet minConfidence. Configuring a rule as "warn" caps output at warning; "error" allows either tier.
| Plugin | Choose it for |
|---|---|
| API Contracts | Function contracts and explicit Fastify or Express route behavior |
| Async | Concurrency, sequencing, cancellation, and async lifetime |
| Comments | Comment usefulness, accuracy, suppressions, and deprecations |
| Errors | Swallowed, wrapped, and message-dispatched exceptions |
| Observability | Safe, actionable, stable, and non-duplicated telemetry |
| Relational Databases | Joins, loop queries, transaction scope, and pagination order |
| Resources | Cleanup, ownership, retry limits, backoff, jitter, and deadlines |
| Security | Authorization, exposure, and direct request-to-sensitive-sink flows |
| Tests | Meaningful oracles, specific failures, and reliable synchronization |
Rule configuration follows the ESLint/Oxlint shape: use a severity alone, or [severity, options]. Plugin factories themselves take no arguments.
plugins: { comments: comments() },
rules: {
"comments/no-misleading-comments": [
"warn",
{ threshold: { warning: 0.9, error: 0.97 } },
],
},Rule registry
Find the check you need.
49 semantic rules across 9 plugins.
49 rules
api-contracts/no-ambiguous-failure-contractsDisallow overlapping public failure channels.
api-contracts/no-ignored-significant-resultsDo not discard meaningful call results.
api-contracts/no-misleading-function-namesDisallow names that contradict visible behavior.
api-contracts/no-misleading-http-statusDisallow statuses that contradict visible outcomes.
api-contracts/no-side-effects-in-safe-http-methodsDisallow requested mutation through safe HTTP methods.
api-contracts/require-input-validationRequire validation of untrusted boundary input.
async/no-async-initializationDisallow async work hidden in initialization.
async/no-serial-independent-workDo not run independent awaits in series.
async/no-unbounded-concurrencyDisallow potentially unbounded promise fan-out.
async/no-unobserved-async-workDo not leave started async work unobserved.
async/require-abort-listener-cleanupRequire cleanup of abort listeners.
async/require-cancellation-propagationRequire accepted cancellation to be forwarded.
async/require-race-loser-cleanupRequire cleanup of locally owned race losers.
comments/no-change-history-commentsDisallow obsolete change narration.
comments/no-commented-out-codeDisallow disabled executable implementation.
comments/no-misleading-commentsDisallow claims contradicted by visible code.
comments/no-useless-commentsDisallow comments with no maintenance value.
comments/prefer-concise-commentsPrefer useful but concise comment prose.
comments/require-actionable-deprecationsRequire migration guidance in deprecations.
comments/require-actionable-todosRequire actionable TODO, FIXME, and HACK markers.
comments/require-justified-suppressionsRequire explanations for tool suppressions.
errors/no-lossy-error-wrappingDisallow replacement errors that lose the original cause.
errors/no-message-based-error-dispatchDisallow control flow coupled to exception prose.
errors/no-swallowed-errorsDisallow silently suppressed unexpected failures.
errors/no-useless-catch-boundariesDisallow catch handlers that add no behavior.
observability/no-duplicate-error-reportingDo not report the same caught failure twice.
observability/no-sensitive-logsDisallow sensitive values emitted without redaction.
observability/no-unactionable-errorsRequire operation and failure evidence in error events.
observability/require-operation-contextRequire a stable operation identity in events.
observability/require-stable-telemetry-namesRequire stable event, span, and metric names.
relational-databases/no-query-in-loopDisallow per-item relational queries.
relational-databases/prefer-database-joinPrefer joining related query results in the database.
relational-databases/require-deterministic-pagination-orderRequire visible ordering for pagination.
relational-databases/require-transaction-scoped-clientRequire transaction-scoped database clients.
resources/no-leaked-resourcesDisallow owned resources left unreleased.
resources/require-bounded-retriesRequire a finite bound on retry behavior.
resources/require-cleanup-on-failureRequire cleanup that is safe on failure.
resources/require-complete-resource-cleanupRequire complete cleanup of multiple resources.
resources/require-retry-backoff-with-jitterRequire retry backoff with jitter.
resources/require-retry-time-budgetRequire an overall deadline for retry work.
security/no-sensitive-data-exposureDisallow sensitive data sent through output sinks.
security/no-unsafe-redirectDisallow request-controlled redirect targets.
security/no-untrusted-command-executionDisallow request data reaching command or code execution.
security/no-untrusted-mass-assignmentDisallow wholesale persistence of request objects.
security/no-user-controlled-authorizationDisallow authorization based on attacker-controlled claims.
tests/no-fixed-delay-synchronizationDisallow sleeps used to synchronize tests.
tests/no-nondeterministic-testsDisallow uncontrolled inputs that make tests flaky.
tests/no-vacuous-testsDisallow tests with no effective behavior verification.
tests/require-specific-error-assertionsRequire assertions that identify the expected failure.
Does your team repeat a code-review standard that is not listed here?
Write a plugin that selects the relevant code, defines the allowed answers and thresholds, and supplies the warning.