perch
Perch is a semantic code linter that turns your team's review rules into committed, executable policy checks powered by Jev.
Perch is the rare linter that lets your review comments become committed, executable policy — write the guarantee in English, point it at a path, and it runs in CI with a confidence score attached. The agent-skill workflow is the actual product insight: `/perch` takes a correction, adds the rule, checks the broken code (1 broken, 93% confidence, exit 3), then checks the fix (nothing to report, exit 0). For teams reviewing code written by Claude Code, Codex, or Cursor, that loop is worth trying. Compare with Semgrep if you want a mature rule ecosystem and don't care about natural-language intent; compare with CodeRabbit or Greptile if you'd rather have AI review comments than committed
Verified 3d ago · liveness 65/100 · cite: rightaichoice.com/tools/perch
- Small engineering teams wanting repository-level policy enforcement with committed, readable rules
- Developers reviewing or gating code produced by AI coding agents in Claude Code, Codex, or Cursor
- Teams whose review friction is project-specific behavior (logging secrets, discount caps, ownership checks), not style
- Python and TypeScript codebases needing semantic checks rather than syntax-only pattern matching
- Teams that need a hosted dashboard, multi-user policy management, or org-wide analytics across repositories
- Projects requiring a documented REST API or SDK to trigger scans programmatically
- Users who want zero-config drop-in linting — the value depends on writing your own perch.yaml rules
We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.
- Honest verdict, not marketing
- Real pros & cons from real users
- Attributed quotes with receipts
3 free scans · no card needed
Skip Perch if you don't want to write and maintain your own `perch.yaml` rules — without them you're mostly getting generic defect and weak-crypto scans a free linter already does.
Every `perch scan` sends relevant source to TypeSafe for Jev analysis and bills per run; the demo shows an estimated $0.0017 for one 18-finding scan, so costs scale with scan frequency rather than seats.
Perch is free to install and to commit rules with — the CLI itself is MIT licensed by Verglas LLC, so the only recurring cost is the per-scan Jev analysis from TypeSafe AI, shown as roughly $0.0017 for one 18-finding scan. That puts it far below seat-priced per-developer code-review tools and static-analysis platforms, and it means the spend scales with how often you scan rather than how many engineers you have. For a team of two to ten on a Python or TypeScript repo, the cost profile is closer
In short
perch — Perch is a semantic code linter that turns your team's review rules into committed, executable policy checks powered by Jev. Best for Small engineering teams wanting repository-level policy enforcement with committed, readable rules, Developers reviewing or gating code produced by AI coding agents in Claude Code, Codex, or Cursor, Teams whose review friction is project-specific behavior (logging secrets, discount caps, ownership checks), not style. Free to use.
What's new in perch
Checked 3 days agoAcross the latest 1 update: 1 feature update.
What people actually say about perch — is it worth it?
We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.
7 mentions across 6 sources (Reddit, Hacker News, YouTube, Product Hunt, GitHub, Lemmy), 63 more we could not attribute · researched Sep 26, 2026.
Weighted by the 70 posts each of 6 sources contributed.
- +Free and globally installed via npm as @lakeday/perch — zero cost to try.
- +Natural-language rules in perch.yaml let you encode team conventions as reviewable code.
- +Findings include rule ID, file:line, severity, confidence percentage, and enclosing method.
- +Per-finding confidence scoring avoids binary pass/fail and reduces false-positive fatigue.
- +Rules can target non-code files, like enforcing sentence case in Markdown docs.
- −Almost no independent user reviews or testimonials exist for the actual linter.
- −Open language-filtering bug means shipped scans may flag irrelevant vulnerability classes.
- −No listed integrations with CI/CD, editors, or Slack — everything is manual CLI wiring.
- −Name collision with Google Perch and a board game makes community support hard to find.
- −Unclear how the Jev engine performs at scale or on large monorepos.
- • No monetary hidden costs since the tool is free, but the time cost of writing and maintaining perch.yaml rules is real
- • If Perch Cloud launches, it may introduce paid tiers for cloud features not currently available
- • Manual CI/CD integration effort if you want to run perch scan outside your local machine
Viability Score
How well maintained and how widely used is perch? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this
Last calculated: September 2026
How we score →Key Features
- Run semantic scans across a source tree with `perch scan` for defects and security issues
- Author custom lints in perch.yaml with plain-language guarantees via `--ensure`
- Scope rules by unit with `--each method` or `--each file`
- Limit rules to path globs with `--where "src/**/*.ts"`
- Report each finding with rule ID, file:line, severity, confidence percentage, and method name
- Filter a scan to one rule with `perch scan --filter rule=<name>`
- Test a rule against a specific symbol with `perch check <file>::<method> --rules <name>`
- Detect off-by-one loop errors, weak cryptography (MD5-hashed tokens), and unhandled nulls
- Score findings probabilistically (e.g. 91%, 93%, 72%) rather than pass/fail
- Scan only changed files with surrounding context using `perch scan --since origin/main`
- Fail CI jobs on breaking findings with exit code 3
- Store findings locally in the .perch directory
- Apply rules to non-code files such as Markdown documentation with `--each file`
- Install the Perch skill for Claude Code, Codex, or Cursor so agents check their own fixes
- Report scan summaries with finding count, methods touched, and estimated cost
About perch
Perch is a semantic linter for codebases where the rules live in your repository, not in a vendor's rule pack. Install it globally with `npm install -g @lakeday/perch`, then run `perch scan` to look for defects and security issues across your source tree — a demo scan returned 18 findings across 14 methods. Each finding comes back with a rule ID, file and line, severity, a confidence percentage, and the enclosing method, so you get probabilistic judgments (91%, 93%, 72%) rather than binary pass/fail gates. The part that separates it from a conventional linter is `perch.yaml`. You define a rule with `perch rules add`, pick a target with `--each method` or `--each file`, scope it with `--where "src/**/*.ts"`, and describe the behavior in plain language using `--ensure`. Documented examples include keeping passwords and access tokens out of logs, capping discounts at 20%, rolling back transactions on failed writes, checking record ownership before updates, and requiring sentence case in Markdown headings. The rule is committed next to the code, so project policy is version-controlled and reviewed like everything else. Built-in scans handle generic problems — off-by-one loop errors, MD5-hashed tokens, unhandled nulls on empty collections — and run alongside your custom rules. `--filter rule=<name>` isolates a single rule, and `perch check <file>::<method> --rules <name>` tests a rule against a specific symbol. That last workflow is what Perch pushes for AI coding agents: install the Perch skill for Claude Code, Codex, or Cursor, turn a correction into a rule, verify it fails on the broken code (exit 3), then verify it passes on the fix (exit 0). The mechanics run on Jev from TypeSafe AI, and scans upload relevant source to TypeSafe for analysis while findings are saved locally in `.perch`. CI is a first-class path: `perch scan --since origin/main` scans changed files with surrounding context, and failing findings exit with code 3 so the job breaks. Perch is distributed as an MIT-licensed npm CLI by Verglas LLC, and it fits small teams and solo developers who want repository-level policy enforcement without assembling a static-analysis platform.
Behind the Verdict
The problem Perch picks is real and boring: a linter passes everything because the thing that mattered was project-specific — a password in a log line, a 150% discount, an update that never checks record ownership. Perch's answer is to let you write those as rules in `perch.yaml` in plain English via `--ensure`, scoped with `--each method` or `--each file` and `--where`, and commit them next to the code. The CLI is consistent about this: `perch rules add`, `perch scan --filter rule=`, and `perch check <file>::<method> --rules <name>` all work the same way on code and on Markdown documentation. Where it earns its keep is the agent loop. The Perch skill for Claude Code, Codex, or Cursor changes the shape of a fix: the agent turns a correction into a rule, checks it against the original broken method (1 check, 1 broken, 93% confidence, exit 3), applies the fix (`percent = min(Decimal(percent), Decimal("20"))`), then checks again (1 check, nothing to report, exit 0, 5 discount test cases passed). The rule stays in `perch.yaml` and re-runs on later edits, which is materially more durable than a conversation with an agent that forgets by the next session. The built-in scans matter too as a floor: off-by-one loop errors, weak cryptography (MD5-hashed tokens), and unhandled nulls on empty collections come back with confidence percentages (90%, 78%, 88%) rather than hard gates, which is the right posture for heuristic detection — you inspect the 91% finding rather than fighting a red build. Be clear-eyed about the tradeoffs. Custom rules are the entire value proposition, so a team that won't write `perch.yaml` gets little that a conventional linter doesn't already offer. Scans send relevant source to TypeSafe for Jev analysis and store findings locally in `.perch`, so anyone with source-residency constraints needs to think about that. The documented CI path is GitHub Actions, and there is no documented REST API or SDK for triggering scans from other systems. The CLI is MIT licensed by Verglas LLC, which makes it cheap to try and impossible to be locked into — a real advantage at a team size where a static-analysis platform contract can't be justified. For a small Python or TypeScript codebase gating AI-generated pull requests, this is the cleanest expression of "our policy, written down, run on every change" currently available.
Researching perch? Get your full AI stack in 60 seconds.
Free, no signup — tell us your goal and get tools matched to your budget & existing stack.
Real-world workflow fit
Concrete scenarios for the personas perch actually fits — and what changes day-one when you adopt it.
Your agent writes a discount function that applies 150%. You type `/perch` with the correction "Discounts can be no larger than 20%.", the agent runs `perch rules add discount-limit --where cart.py --each method --ensure "Discounts can be no larger than 20%."`, then `perch check cart.py::apply_discount --rules discount-limit` on the original code and gets 1 broken at 93% confidence with exit 3.
Outcome: The agent edits `percent = min(Decimal(percent), Decimal("20"))`, re-runs the check (nothing to report, exit 0, 5 discount test cases passed), and `discount-limit` stays in perch.yaml so the same regression is caught on every later edit.
You add a GitHub Actions step that runs `perch scan --since origin/main`, which uploads changed files with surrounding context to TypeSafe for Jev analysis and exits with code 3 when findings fail, breaking the job.
Outcome: Agent-authored PRs that log access tokens or hash user IDs with MD5 can't merge silently, and findings land in the local `.perch` directory for the reviewer to inspect with their confidence scores.
You commit `docs-headings-name-things`, `docs-no-anthropomorphism`, and `docs-show-output` against `docs/**/*.md`, then run `perch check docs/install.md --rules docs-headings-name-things,docs-no-anthropomorphism,docs-show-output` after each documentation edit.
Outcome: Vague headings like "One issue, opened up" and prose like "the first pass speaks for the method's shape" come back as findings, and a fenced command block with no output fails the rule — all before the agent finishes the task.
Use Cases
- Add a `private-logs` rule scoping `src/**/*.ts` methods so passwords and access tokens never reach log statements.
- Enforce a `discount-limit` business invariant on `cart.py` so discount methods never exceed 20%.
- Lint Markdown documentation for sentence-case headings by targeting `docs/**/*.md` files.
- Require `atomic-writes` in Python methods so transactions roll back when any write fails.
- Gate AI-generated pull requests by scanning agent-authored code for defects and weak cryptography before merge.
- Enforce `record-ownership` checks in `api/**/*.py` update methods to prevent unauthorized record modification.
- Catch vague narrative headings and filler prose in docs with `docs-headings-name-things` and `docs-no-anthropomorphism`.
- Require that every fenced command block in your docs shows its real output via the `docs-show-output` rule.
Limitations
- Perch is distributed as an MIT-licensed npm CLI; the scraped pages show no hosted service, dashboard, or public API, so programmatic or multi-user workflows are unverified.
- Scans run against the Jev engine from TypeSafe AI, which costs money per analysis — the site shows an estimated $0.0017 for one 18-finding scan — and the exact billing model is not documented in the scraped material.
- Rule authoring requires writing `perch.yaml` entries with glob scopes and `--ensure` text, so the tool's value scales with the effort you put into custom policy.
- Findings are stored locally in `.perch`, and GitHub Actions is the documented CI path.
- Because findings carry confidence percentages rather than hard verdicts, nothing stops a reviewer from ignoring a 72% finding.
as of 2026-09-26
12-month cost
Project the real annual outlay, including the implied monthly cost when only an annual tier is published.
Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.
Plans compared
For each published perch tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.
CLI (MIT license)
Free (MIT license); per-scan Jev analysis billed separately
Ideal for
Solo developers and small Python or TypeScript teams who want committed, readable policy rules and are comfortable paying the per-scan Jev analysis cost from TypeSafe AI.
What this tier adds
Starting tier and the only published option: MIT-licensed CLI plus per-run Jev analysis, with rules you author and commit yourself.
Where the pricing makes sense
The company stage and team size where perch's pricing actually pencils out — and where peers do it cheaper.
Perch is free to install and to commit rules with — the CLI itself is MIT licensed by Verglas LLC, so the only recurring cost is the per-scan Jev analysis from TypeSafe AI, shown as roughly $0.0017 for one 18-finding scan. That puts it far below seat-priced per-developer code-review tools and static-analysis platforms, and it means the spend scales with how often you scan rather than how many engineers you have. For a team of two to ten on a Python or TypeScript repo, the cost profile is closer
Setup time & first value
How long it actually takes to get something useful out of perch — broken out by persona, not the marketing-page minute.
Solo developer: about five minutes — `npm install -g @lakeday/perch`, run one `perch scan`, read the confidence-scored findings. Small team: fifteen to thirty minutes to add your first `perch.yaml` rule with `perch rules add` and verify it with `perch check` before and after a fix. CI: add one GitHub Actions step running `perch scan --since origin/main` and let exit code 3 break the job. Teams
Switching to or from perch
How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.
- →From ESLint or a style-only linter: keep your existing config for formatting, add Perch rules for behavior — logging secrets, ownership checks, discount caps — that a syntax linter can't express.
- →From Semgrep: rewrite the handful of rules that encode project-specific policy in `perch.yaml` with `--ensure` plain-language text, scoping them with `--each method` and `--where`.
- →From manual review comments: take your recurring PR feedback and run `perch rules add <name> --each method --where <glob> --ensure "<the rule in English>"`, then commit the generated perch.yaml entry.
- →From no linter at all: install the CLI, run `perch scan` once to see the built-in defect, weak-crypto, and unhandled-null findings, and only then start writing custom rules.
- ↗To Semgrep or another rule-pack static analyzer: port your `perch.yaml` rules back into concrete pattern rules, accepting that the natural-language `--ensure` intent has to be re-expressed as syntax.
- ↗To a hosted AI code-review tool like CodeRabbit or Greptile: keep Perch as the pre-merge policy gate locally, and let the hosted reviewer handle commentary on the diff instead.
- ↗To a full static-analysis platform: export the findings stored under `.perch` and hand the project-specific rules to whoever administers org-wide policy, since Perch has no shared dashboard.
- ↗To plain CI failure: replace the `perch scan --since origin/main` step with your remaining linters' exit codes, accepting that confidence-scored semantic findings disappear.
Integrations
Resources & Guides
Tutorials & Learning
YouTube returned 6 videos for “perch”, and we withheld 6: 6 could not be judged, because “perch” is a single word that other videos use for other things. We are showing none, because we could not prove any of them are about perch.
Official links
Tools that pair well with perch
Common stack mates teams adopt alongside perch, with the specific reason each pairing earns its keep.
Moderne
Moderne sequences your repos into a Lossless Semantic Tree for deterministic code change at scale.
Codacy AI
Codacy AI enforces code review, security scans, and AI governance guardrails inside your IDE and on every pull request.
Wiz
Wiz connects code, cloud, and runtime into one security graph so teams can fix the risks attackers can actually reach.
Featured Head-to-Head Comparisons
Perch vs Endor Labs
These aren't really competitors, so treat it as a 'what problem are you buying for' question rather than a bake-off. Endor Labs is for security and DevSecOps teams that need reachability-verified vulnerability prioritization plus governance over AI coding agents, MCP servers, and skills — with FedRAMP 2026's reachability mandate (Aug 2026 news) pushing that capability from nice-to-have to requirement. Perch is for a small Python/TypeScript team that wants its own repo-committed natural-language rules — logging secrets, discount caps, ownership checks — enforced in CI for free. If you have a dedicated security function and compliance obligations, pick Endor Labs; if your review friction is project-specific behavior and you'll write the rules yourself, pick Perch.
Perch vs Amazon Codewhisperer
These aren't competitors — they're different layers of the stack. If you want an AI assistant that writes and modernizes code inside your IDE with AWS-native security scanning and agentic tasks, pick Amazon Q Developer (the current name for CodeWhisperer since April 2024). If you want a lightweight, free CLI that enforces your team's own rules — logging secrets, discount caps, ownership checks — across AI-generated code from Cursor, Codex, or Claude Code, pick Perch. The realistic answer for a team running AI coding agents: use both. Q Developer generates, Perch gates.
Perch vs Mindgard
These two do not compete for the same budget, so there is no head-to-head winner. If your problem is adversarial risk in production AI agents — shadow AI, guardrail bypasses, exploit-backed findings your GRC team can audit — Mindgard is built for exactly that, and you will pay a contact-sales enterprise price for it. If your problem is code-level policy enforcement inside a repo (off-by-one loops, MD5-hashed tokens, unhandled nulls, or catching what Claude Code/Codex/Cursor wrote), Perch is free, runs from your terminal or GitHub Actions, and expects you to write your own perch.yaml rules. Pick by problem, not by category: agent attack surface vs source-tree defects.
Perch vs Bito
These are two different line items on the same engineering budget, and most teams adopting agents will eventually want both. Bito is the one that pays for itself only at scale — it needs multi-repo agent traffic already burning tokens, and it comes with a scoping call instead of a published rate. Perch is free and installs in minutes, so its real cost is the time you spend writing perch.yaml rules; it earns its place the moment your review friction is project-specific behavior rather than style. If you can only pick one right now: pick Perch to stop bad agent-generated code from merging, and pick Bito once your agent bill is big enough that a routing and grounding layer has something to save.
Perch vs Snyk Deepcode Ai
These are different purchases despite both being code security tools. Snyk DeepCode AI is a platform commitment: you get hybrid symbolic+ML detection, Agent Fix autofixes, context-aware prioritization, and a security dashboard — but enterprise-grade features like Evo AI pentesting and coding-agent security sit behind an Enterprise Platform Subscription with credit-based pricing that scales by active contributors. Perch costs nothing and does one job well: it enforces your team's own semantic rules with probabilistic confidence scores, and it fits teams gating AI-agent output in Claude Code, Codex, or Cursor. If nobody on the team will write perch.yaml, Snyk is the safer pick. If budget is zero and the real problem is project-specific behavior — logging secrets, discount caps, ownership checks — Perch wins on cost and on rules that live in your repo.
Perch vs Coro
These two will never appear on the same shortlist. If you're a lean IT team or an MSP trying to collapse endpoint, email, cloud, identity, network and data security into one agent and one console, Coro is built for exactly that — but budget for a partner-issued quote and accept it isn't aimed at a dedicated SOC doing deep threat hunting. If you write Python or TypeScript and your review friction is project-specific behavior rather than style, Perch is free and worth an afternoon: install it, write one perch.yaml rule, and see whether probabilistic findings with confidence scores beat your current linter. Don't evaluate them against each other; evaluate each against its own alternative.
Alternatives to perch
View allFrequently Asked Questions
Used perch? Help shape our editorial sentiment research.