From a blank repo to an enforced, human-approved spec.
Four moments, one command each. You are not configuring a tool; you are watching who controls what: your AI reads the contract, and only humans change it. Everything below is free.
uv tool install linebreak-gate # or: pip install linebreak-gate
- 01
Agree on WHAT gets built, before the AI runs
The AI builds at full speed... whatever it understood. The agreement about what it SHOULD build lives in a doc nobody re-reads.
linebreak-gate spec new
You get a draft of acceptance criteria (.linebreak/spec-draft.yml). Ask your AI to fill it from the PRD you already have: Notion, Jira, a doc. It's a draft, not a contract yet.
- 02
Your signature turns it into a contract
Today, “approved” is a thumbs-up in Slack. Nobody can reconstruct later who said yes, and to what exactly.
linebreak-gate spec approve .linebreak/spec-draft.yml \ --approver "Ana Lopez <ana@example.com>"
The approval is on the record inside the repo (who, when, exactly what) and travels with git. See it: linebreak-gate spec list.
- 03
Your AI builds READING the contract, and can't change it
Copy-pasting specs into a chat, and “someone” adjusting a criterion mid-week without you noticing.
linebreak-gate mcp install --editor claude-code # or: cursor · codex
Restart your editor and ask the agent for the next story: it reads it from the contract. Then ask it to CHANGE a criterion: it can't. The bridge is read-only by design.
- 04
CI says “no” for you
You are the review bottleneck, and whatever slips past you, ships.
linebreak-gate check
Machine checks really run; a `manual` criterion BLOCKS until a human signs it off (linebreak-gate signoff). Last test: hand-edit an approved criterion: on the free tier only git catches it. Making that edit fail CI by itself is exactly what the signed Record adds.
The whole loop, one take

Draft the criteria, a named human approves, the check blocks until the manual criterion carries a sign-off, then it passes. Real terminal, no mock.
That was the whole product.
You just saw what's free (the gate, the bridge, the unsigned record) and what's paid (cryptographic signatures that make tampering fail CI on its own). Next step: protect a real repo.