Guardrails for agent-written SvelteKit code
Client work: a large SvelteKit monorepo
SvelteKitSvelte 5TypeScriptCoding agents
- Problem
- Most of the code on a client platform was being written with coding agents, and more developers were about to join. Once an agent copies a shortcut, the next session treats it as the way the app works.
- What I did
- Put the rules in code rather than in agent instructions: a boundary checker that parses the source, a lint plugin that wants a comment justifying every $effect, a route data audit and a module ownership check. All of them run in pnpm check before a deploy.
- Outcome
- The custom checks stopped 8 of 38 failed UAT deploys, and nobody switched one off to get a deploy through
- Exceptions down from 43 to 16, which the team later took to 12
- The checks went with the code at handover and still gate UAT and production deploys