gutsy

io.github.kouhxpv0.1.1更新于 Oct 7, 2026

Local gut check before risky agent actions: calibrated safe/intended probabilities, no API calls.

概览

AI 生成的概览

在代理执行高风险操作前提供本地“直觉检查”,返回经过校准的安全/意图概率以及 proceed、confirm 或 block 建议。

功能
提供 gut_check 工具,输入操作描述以及可选的上下文和用户请求,返回该操作是否有意图、是否可逆的概率、拒绝分数,以及 proceed、confirm 或 block 建议。它在 CPU 上运行一个小型本地模型,不调用 API,因此代码和上下文不会离开本机。可选的 Claude Code 钩子可对高风险 Bash 命令执行同样的检查,且只能询问或拒绝,不能自动批准。
适用场景
当编码代理可能删除文件、重写 git 历史、强制推送、操作数据库、部署、发布或发送内容时,适合加入,以便在这些步骤前获得快速第二意见并增加阻力。它只是减速带,不是安全边界,因此应保留常规权限设置。
运行要求
需要本地 Python 运行环境,包通过 uvx 运行。需要本地 gutsy-inference 服务器,可单独启动,也可在 GUTSY_INFERENCE_DIR 指向包含 models.json 的目录时由 MCP 服务器启动。可选设置包括 GUTSY_URL、GUTSY_MODEL、GUTSY_PROCEED_MIN、GUTSY_BLOCK_MIN 和 GUTSY_API_KEY。仅支持桌面端。
安装前请注意
由代理决定是否调用该工具并撰写其看到的上下文,且 0.8B 模型在歧义和多步规则上较弱,因此它不是安全边界。默认阈值未针对具体工作流调优;应记录概率并调整。若运行时以 API key 启动,可能需要 GUTSY_API_KEY。设置 GUTSY_HOOK_ALLOW_DENY 时,可选钩子可直接拒绝命令。

安装

在 SourceWeft 中

  1. 打开 控制台中的 gutsy,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

gutsy-mcp

A local gut check for coding agents. Before Claude Code, Codex, Cursor or Copilot runs rm -rf, force-pushes, deploys or sends something, it calls gut_check and gets back calibrated probabilities that the action is intended and safe, plus a recommendation: proceed, confirm (ask the user first) or block.

Runs on your CPU with gutsy (0.8B, 775 MB GGUF). No API calls, no per-call cost, deterministic, and your code never leaves the machine.

What it is and isn't

It's a fast second opinion that adds friction where it's warranted. It is not a security boundary: the agent decides whether to call it and writes the context it sees, and a 0.8B model is weak at ambiguity and multi-step rules (see the model card). Keep your normal permission settings on. Default thresholds aren't tuned for your workflow; log the probabilities and adjust them.

1. Start the gutsy runtime

bash
git clone https://github.com/kouhxp/gutsypip install -e gutsy/gutsy-inferencehf download kouhxp/gutsy --include "gutsy-0.8b-v04*" --local-dir gutsy/gutsy-inference/modelscd gutsy/gutsy-inference && cp models.example.json models.jsongutsy-inference check && gutsy-inference serve     # http://127.0.0.1:8765

Or set GUTSY_INFERENCE_DIR=/path/to/gutsy/gutsy-inference and gutsy-mcp starts it on first use.

2. Add the MCP server

Claude Code:

bash
claude mcp add gutsy -- uvx gutsy-mcp

Cursor (.cursor/mcp.json) / Claude Desktop:

json
{ "mcpServers": { "gutsy": { "command": "uvx", "args": ["gutsy-mcp"] } } }

VS Code (.vscode/mcp.json):

json
{ "servers": { "gutsy": { "type": "stdio", "command": "uvx", "args": ["gutsy-mcp"] } } }

Codex (~/.codex/config.toml):

toml
[mcp_servers.gutsy]command = "uvx"args = ["gutsy-mcp"]

Then tell the agent when to use it (CLAUDE.md, AGENTS.md, .cursor/rules):

Before deleting files, rewriting git history, force-pushing, touching databases, deploying, publishing or sending anything, call gut_check. If it doesn't return proceed, stop and ask me.

3. Optional: enforce it with a Claude Code hook

An MCP tool only runs if the agent remembers to call it. The hook runs on every risky-looking Bash command regardless. It can only ask or deny, never auto-approve.

bash
uv tool install gutsy-mcp      # puts gutsy-hook on PATH

.claude/settings.json:

json
{  "hooks": {    "PreToolUse": [      { "matcher": "Bash", "hooks": [{ "type": "command", "command": "gutsy-hook", "timeout": 60 }] }    ]  }}

block becomes a confirmation prompt by default; set GUTSY_HOOK_ALLOW_DENY=1 to deny outright.

Tool

gut_check(action, context="", user_request="") returns:

json
{  "recommendation": "confirm",  "reason": "Not confident enough to proceed without the user.",  "p_intended": 0.41,  "p_reversible": 0.08,  "verdict_probabilities": {"proceed": 0.22, "confirm": 0.61, "block": 0.17},  "reject": 0.04,  "confidence": 0.42}
env vardefault
GUTSY_URLhttp://127.0.0.1:8765runtime URL
GUTSY_INFERENCE_DIRlets gutsy-mcp start the runtime
GUTSY_MODELruntime defaultmodel name from models.json
GUTSY_PROCEED_MIN0.85
GUTSY_BLOCK_MIN0.50
GUTSY_API_KEYif you run serve --api-key-env

License: Apache 2.0.

来源:README.md,提交 75a820d

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.1最新Oct 7, 2026