legitAgent
MCP, CLI, GitHub Action, and a Cursor plugin: scan HTML/JSX/TSX/Vue/Svelte/Astro and a live page for typical 152-FZ, 38-FZ, and consumer-law risks.
Challenge
Agents and developers add personal-data forms, analytics, and cookie banners without a check. A lawyer is not sitting in every PR, and typical holes — no consent, a pre-checked checkbox, Metrika without opt-in, “Ads” without an erid, a storefront without an offer — ship to production easily.
Solution
One engine, @legit-agent/core, plus a Playwright live scanner. In the IDE — MCP tools (scan, review, scan_url, list_rules, explain_rule, generate_policy, get_law) and slashes /check /fix /scan /scan-url. In the terminal — npx @legit-agent/cli. In CI — a GitHub Action with SARIF, a PR comment, and an issue on high. Live scan-url waits for SPA hydration, clicks “reject”, and inspects cookies before and after. A second review pass marks confirm / reject / ask_human; CI still uses the raw findings. init-policy prints a policy draft. The rule catalog includes article excerpts; a rule without an excerpt does not enter the catalog.
Outcome
A public product: the site, npm packages @legit-agent/*, the repository, and a demo with a broken site. It connects in Cursor with one button. Used on Alba projects, including this site, as an always-on check before committing forms, trackers, or cookies. This is a heuristic, not a legal opinion.
Stack
Gallery








