gutsy

io.github.kouhxpv0.1.1Updated Oct 7, 2026

Local gut check before risky agent actions: calibrated safe/intended probabilities, no API calls.

VerifiedSTDIODesktop onlyDeveloper ToolsSecurity & Monitoring

Overview

AI-generated overview

A local gut check that returns calibrated safe/intended probabilities and a proceed, confirm or block recommendation before risky agent actions.

What it does
Exposes a gut_check tool that takes an action description plus optional context and user request, and returns probabilities that the action is intended and reversible, a reject score, and a recommendation of proceed, confirm or block. It runs a small local model on the CPU with no API calls, so code and context stay on the machine. An optional Claude Code hook can run the same check on risky Bash commands, where it can only ask or deny, never auto-approve.
When to use it
Worth adding when a coding agent may delete files, rewrite git history, force-push, touch databases, deploy, publish or send things, and you want a fast second opinion that adds friction before those steps. It is a speed bump, not a security boundary, so keep normal permission settings in place.
Requirements
A local Python runtime; the package is run with uvx. A local gutsy-inference server is needed, either started separately or launched by the MCP server when GUTSY_INFERENCE_DIR points at a directory containing models.json. Optional settings include GUTSY_URL, GUTSY_MODEL, GUTSY_PROCEED_MIN, GUTSY_BLOCK_MIN and GUTSY_API_KEY. Desktop only.
Before you install
The agent decides whether to call the tool and writes the context it sees, and a 0.8B model is weak at ambiguity and multi-step rules, so it is not a security boundary. Default thresholds are not tuned for a given workflow; log probabilities and adjust them. GUTSY_API_KEY may be needed if the runtime is started with an API key. The optional hook can deny commands outright when GUTSY_HOOK_ALLOW_DENY is set.

Installation

In SourceWeft

  1. Open gutsy in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

gutsy-mcp

A local gut check for coding agents. Before Claude Code, Codex, Cursor or Copilot runs rm -rf, force-pushes, deploys or sends something, it calls gut_check and gets back calibrated probabilities that the action is intended and safe, plus a recommendation: proceed, confirm (ask the user first) or block.

Runs on your CPU with gutsy (0.8B, 775 MB GGUF). No API calls, no per-call cost, deterministic, and your code never leaves the machine.

What it is and isn't

It's a fast second opinion that adds friction where it's warranted. It is not a security boundary: the agent decides whether to call it and writes the context it sees, and a 0.8B model is weak at ambiguity and multi-step rules (see the model card). Keep your normal permission settings on. Default thresholds aren't tuned for your workflow; log the probabilities and adjust them.

1. Start the gutsy runtime

bash
git clone https://github.com/kouhxp/gutsypip install -e gutsy/gutsy-inferencehf download kouhxp/gutsy --include "gutsy-0.8b-v04*" --local-dir gutsy/gutsy-inference/modelscd gutsy/gutsy-inference && cp models.example.json models.jsongutsy-inference check && gutsy-inference serve     # http://127.0.0.1:8765

Or set GUTSY_INFERENCE_DIR=/path/to/gutsy/gutsy-inference and gutsy-mcp starts it on first use.

2. Add the MCP server

Claude Code:

bash
claude mcp add gutsy -- uvx gutsy-mcp

Cursor (.cursor/mcp.json) / Claude Desktop:

json
{ "mcpServers": { "gutsy": { "command": "uvx", "args": ["gutsy-mcp"] } } }

VS Code (.vscode/mcp.json):

json
{ "servers": { "gutsy": { "type": "stdio", "command": "uvx", "args": ["gutsy-mcp"] } } }

Codex (~/.codex/config.toml):

toml
[mcp_servers.gutsy]command = "uvx"args = ["gutsy-mcp"]

Then tell the agent when to use it (CLAUDE.md, AGENTS.md, .cursor/rules):

Before deleting files, rewriting git history, force-pushing, touching databases, deploying, publishing or sending anything, call gut_check. If it doesn't return proceed, stop and ask me.

3. Optional: enforce it with a Claude Code hook

An MCP tool only runs if the agent remembers to call it. The hook runs on every risky-looking Bash command regardless. It can only ask or deny, never auto-approve.

bash
uv tool install gutsy-mcp      # puts gutsy-hook on PATH

.claude/settings.json:

json
{  "hooks": {    "PreToolUse": [      { "matcher": "Bash", "hooks": [{ "type": "command", "command": "gutsy-hook", "timeout": 60 }] }    ]  }}

block becomes a confirmation prompt by default; set GUTSY_HOOK_ALLOW_DENY=1 to deny outright.

Tool

gut_check(action, context="", user_request="") returns:

json
{  "recommendation": "confirm",  "reason": "Not confident enough to proceed without the user.",  "p_intended": 0.41,  "p_reversible": 0.08,  "verdict_probabilities": {"proceed": 0.22, "confirm": 0.61, "block": 0.17},  "reject": 0.04,  "confidence": 0.42}
env vardefault
GUTSY_URLhttp://127.0.0.1:8765runtime URL
GUTSY_INFERENCE_DIRlets gutsy-mcp start the runtime
GUTSY_MODELruntime defaultmodel name from models.json
GUTSY_PROCEED_MIN0.85
GUTSY_BLOCK_MIN0.50
GUTSY_API_KEYif you run serve --api-key-env

License: Apache 2.0.

Source: README.md at commit 75a820d

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.1LatestOct 7, 2026