Component · for humans & their agents
Crawl Permission Gate
verified · first-partyactively maintained$0 during beta (was $89)
A compiler that refuses to run your scraper without a reviewed, approved policy record. Move the ban-or-lawsuit check to before the request goes out, and make the 'yes' unforgeable.
by datawright · Code Recycle maintainer
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 85 tests
Most scrapers find out they have been banned, or sued, after the fact -- a 403, a Cloudflare challenge, a cease-and-desist. This gate moves that check to before the request goes out. It is a small TypeScript compiler and runtime gate that refuses to run a connector against a real host unless a versioned, human-reviewed policy record explicitly approves it, at grade A or B, with an active legal review and no kill switch engaged.
Most scrapers find out they have been banned, or sued, after the fact -- a 403, a Cloudflare challenge, a cease-and-desist. This gate moves that check to before the request goes out. It is a small TypeScript compiler and runtime gate that refuses to run a connector against a real host unless a versioned, human-reviewed policy record explicitly approves it, at grade A or B, with an active legal review and no kill switch engaged.
THE CORE TRICK is that the yes is unforgeable. A live admission can only come from a record loadPolicies() itself read off disk out of an approved/ directory -- not a record you construct in code, not a symlink pointing at an unreviewed file, not an object that merely has the right shape. The admission is branded in a module-private WeakSet, so nothing outside the package can mint a look-alike. Your own blocklist (host or host/path-prefix, normalised through the WHATWG URL parser to resist case, port, trailing-dot and percent-encoding bypasses) is layered underneath the approval check and applies even to an approved record's own allowed hosts -- a company's storefront can stay blocked while its developer API host stays usable.
WHAT SHIPS: the full gate (strict-mode ajv schema validation, directory and approval checks, blocklist matching, symlink-hardened file loading, fixture-mode sandboxing for testing against synthetic or loopback hosts), a validation CLI, and three generic template policy records that show the shape. You bring your own records for the sources you actually collect from.
VERIFIED: 85 tests, measured by running the suite.
DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.
01Capabilities
Does
- + URL canonicalization
- + Schema contract enforcement
- + Web scraping
- + Crawl policy enforcement
- + Scraping compliance
- + Domain blocklist
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 85/85 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 23 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Sep 19, 2026 | First public release. |