01
@supabase/supabase-js ^2.0.0Dependency
New manifest entries, requested versions, added import or load sites, and possible repository matches.
Tibo documentation · 10 minute read
This is the complete practical guide to Tibo. Start with the quick scan, learn how to read evidence, then add the review skill to Codex or Claude so every agent task leaves a clear decision trail.
01 · Quick start
Tibo is a CLI. It does not need an account, API key, hosted workspace, or model call. It reads tracked and untracked working-tree changes locally.
# From your changed repository
npx --yes @goankan/tibo@0.1.1 scan
# Ask for stable JSON instead
npx --yes @goankan/tibo@0.1.1 scan --jsonInput
Git diff plus untracked files
Output
Evidence-backed findings
State
A local decision ledger
02 · Mental model
The core is deliberately boring and explainable. A Git change goes through narrow structural detectors. Each detector returns evidence, confidence, and a limitation. You decide. The ledger gives the next session the answer.
agent changes files
↓
Git working tree
↓
diff and line normalizer
↓
structural detectors
↓
evidence-backed findings
↓
you choose keep / reject / later
↓
.tibo/decisions.json + decisions.md
↓
next session runs npx --yes @goankan/tibo@0.1.1 summaryThe host agent can explain returned evidence and make an explicitly approved repair. Tibo itself never edits source files and never silently approves a finding.
03 · Supported changes
The first release focuses on TypeScript and JavaScript repositories. The output is intentionally smaller than a generic linter.
01
@supabase/supabase-js ^2.0.0New manifest entries, requested versions, added import or load sites, and possible repository matches.
02
NEXT_PUBLIC_SUPABASE_URLNew process.env reads using dot or bracket notation, with the file that reads the value.
03
DROP COLUMN emailSQL and migration changes, including a high-severity marker for potentially destructive operations.
04
export type Session = ...New or changed exported functions, classes, constants, types, and interfaces.
05
src/utils/mail.tsPossible overlap for a newly added file using bounded filename and symbol evidence.
Possible matches are lexical evidence, not proof that two packages or modules are equivalent. Tibo says what it found and what it cannot know from a diff.
04 · Read a finding
Every finding answers four questions: what changed, where it changed, why Tibo raised it, and what remains unknown.
{
"id": "8a2a693714dd",
"kind": "dependency",
"summary": "dependency added @supabase/supabase-js ^2.0.0",
"evidence": [
{
"path": "package.json",
"detail": "Added manifest entry: @supabase/supabase-js"
},
{
"path": "src/lib/supabase.ts",
"line": 2,
"detail": "Added import"
}
],
"confidence": "high",
"limitation": "Presence in a manifest does not prove necessity or safety.",
"decision": "unreviewed"
}Evidence
Paths and lines you can open and verify.
Limitation
The boundary between a signal and a conclusion.
05 · Before and after
A package name alone creates suspicion. Evidence gives an engineer something concrete to approve, reject, or defer.
Before · vague review
“The agent added Supabase. Is that okay?”
After · Tibo review
“@supabase/supabase-js ^2.0.0 was added to package.json and imported in src/lib/supabase.ts:2. Keep, reject, or later?”
06 · Everyday workflow
Install and scan
npx --yes @goankan/tibo@0.1.1 scanRun from the repository the agent changed.
Machine output
npx --yes @goankan/tibo@0.1.1 scan --jsonGive stable findings to an agent, script, or CI job.
Record a decision
npx --yes @goankan/tibo@0.1.1 decide <id> keep|reject|laterStore only the human's explicit choice.
Show project memory
npx --yes @goankan/tibo@0.1.1 summary --jsonGive the next agent the ledger and unresolved findings.
If you are working from a checkout instead of npm, build with npm run build and use node dist/index.js in place of npx --yes @goankan/tibo@0.1.1.
07 · Decisions and ledger
Keep means you accepted the decision. Reject means you do not want to approve it. Later leaves the question visible. None of these commands edits the repository.
npx --yes @goankan/tibo@0.1.1 decide 8a2a693714dd reject
npx --yes @goankan/tibo@0.1.1 summary --json# Tibo decisions
## 8a2a693714dd · dependency
- decision: keep
- subject: @supabase/supabase-js ^2.0.0
- evidence: package.json:12, src/lib/supabase.ts:2
- decided: 2026-09-22The JSON ledger is stored at .tibo/decisions.json. The Markdown view at .tibo/decisions.md is for humans and future agent sessions. Stable finding IDs stop the same decision from being asked again without a meaningful change.
08 · Codex and Claude
Tibo includes a portable skill at skills/tibo-review/SKILL.md. Copy it into Codex or Claude Code. The host agent explains returned evidence and asks for your decision; Tibo remains the source of truth.
Codex
mkdir -p ~/.codex/skills/tibo-review
cp -R skills/tibo-review/* \
~/.codex/skills/tibo-review/Claude Code
mkdir -p .claude/skills/tibo-review
cp -R skills/tibo-review/* \
.claude/skills/tibo-review/The host-agent contract
npx --yes @goankan/tibo@0.1.1 scan --json after the agent changes files.npx --yes @goankan/tibo@0.1.1 decide.09 · Best practices
Scan when an agent says a task is complete and before you commit. The context is fresh and the diff is still easy to understand.
Open the referenced file and line. A finding tells you where to look; it does not replace engineering judgment.
If you need product context, defer the finding. Do not accept a choice just to clear the inbox.
Record the reason in the surrounding project context when a choice matters. Reset an entry intentionally instead of deleting history casually.
10 · Boundaries
11 · Roadmap
The roadmap is intentionally staged. Next are richer route, event, serialized-field, module-graph, and rollback detectors; real Codex and Claude validation; team review surfaces; and an optional evidence-only explanation provider.
FAQ
No. Detection is local and deterministic. The Codex or Claude skill can explain the returned evidence, but Tibo does not require a model call.
No. Reject only records your decision. A host agent can make a repair only after you separately approve that repair plan.
Yes. Tibo includes untracked files in the local scan so a newly created file can be reviewed before it is staged.
The first release focuses on TypeScript and JavaScript repositories and their common manifests, environment reads, migrations, and exports.
In .tibo/decisions.json and .tibo/decisions.md inside the repository. There is no hosted account or required dashboard.