
gutsy
io.github.kouhxpv0.1.1Updated Oct 7, 2026
Local gut check before risky agent actions: calibrated safe/intended probabilities, no API calls.
Overview
A local gut check that returns calibrated safe/intended probabilities and a proceed, confirm or block recommendation before risky agent actions.
- What it does
- Exposes a gut_check tool that takes an action description plus optional context and user request, and returns probabilities that the action is intended and reversible, a reject score, and a recommendation of proceed, confirm or block. It runs a small local model on the CPU with no API calls, so code and context stay on the machine. An optional Claude Code hook can run the same check on risky Bash commands, where it can only ask or deny, never auto-approve.
- When to use it
- Worth adding when a coding agent may delete files, rewrite git history, force-push, touch databases, deploy, publish or send things, and you want a fast second opinion that adds friction before those steps. It is a speed bump, not a security boundary, so keep normal permission settings in place.
- Requirements
- A local Python runtime; the package is run with uvx. A local gutsy-inference server is needed, either started separately or launched by the MCP server when GUTSY_INFERENCE_DIR points at a directory containing models.json. Optional settings include GUTSY_URL, GUTSY_MODEL, GUTSY_PROCEED_MIN, GUTSY_BLOCK_MIN and GUTSY_API_KEY. Desktop only.
Installation
In SourceWeft
- Open gutsy in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
gutsy-mcp
A local gut check for coding agents. Before Claude Code, Codex, Cursor or Copilot runs
rm -rf, force-pushes, deploys or sends something, it calls gut_check and gets back
calibrated probabilities that the action is intended and safe, plus a recommendation:
proceed, confirm (ask the user first) or block.
Runs on your CPU with gutsy (0.8B, 775 MB GGUF). No API calls, no per-call cost, deterministic, and your code never leaves the machine.
What it is and isn't
It's a fast second opinion that adds friction where it's warranted. It is not a security boundary: the agent decides whether to call it and writes the context it sees, and a 0.8B model is weak at ambiguity and multi-step rules (see the model card). Keep your normal permission settings on. Default thresholds aren't tuned for your workflow; log the probabilities and adjust them.
1. Start the gutsy runtime
Or set GUTSY_INFERENCE_DIR=/path/to/gutsy/gutsy-inference and gutsy-mcp starts it on
first use.
2. Add the MCP server
Claude Code:
Cursor (.cursor/mcp.json) / Claude Desktop:
VS Code (.vscode/mcp.json):
Codex (~/.codex/config.toml):
Then tell the agent when to use it (CLAUDE.md, AGENTS.md, .cursor/rules):
Before deleting files, rewriting git history, force-pushing, touching databases, deploying, publishing or sending anything, call
gut_check. If it doesn't returnproceed, stop and ask me.
3. Optional: enforce it with a Claude Code hook
An MCP tool only runs if the agent remembers to call it. The hook runs on every risky-looking Bash command regardless. It can only ask or deny, never auto-approve.
.claude/settings.json:
block becomes a confirmation prompt by default; set GUTSY_HOOK_ALLOW_DENY=1 to deny outright.
Tool
gut_check(action, context="", user_request="") returns:
License: Apache 2.0.
Source: README.md at commit 75a820d
Tools
0Version history
1- v0.1.1LatestOct 7, 2026


