
gutsy
io.github.kouhxpv0.1.1更新于 Oct 7, 2026
Local gut check before risky agent actions: calibrated safe/intended probabilities, no API calls.
概览
在代理执行高风险操作前提供本地“直觉检查”,返回经过校准的安全/意图概率以及 proceed、confirm 或 block 建议。
- 功能
- 提供 gut_check 工具,输入操作描述以及可选的上下文和用户请求,返回该操作是否有意图、是否可逆的概率、拒绝分数,以及 proceed、confirm 或 block 建议。它在 CPU 上运行一个小型本地模型,不调用 API,因此代码和上下文不会离开本机。可选的 Claude Code 钩子可对高风险 Bash 命令执行同样的检查,且只能询问或拒绝,不能自动批准。
- 适用场景
- 当编码代理可能删除文件、重写 git 历史、强制推送、操作数据库、部署、发布或发送内容时,适合加入,以便在这些步骤前获得快速第二意见并增加阻力。它只是减速带,不是安全边界,因此应保留常规权限设置。
- 运行要求
- 需要本地 Python 运行环境,包通过 uvx 运行。需要本地 gutsy-inference 服务器,可单独启动,也可在 GUTSY_INFERENCE_DIR 指向包含 models.json 的目录时由 MCP 服务器启动。可选设置包括 GUTSY_URL、GUTSY_MODEL、GUTSY_PROCEED_MIN、GUTSY_BLOCK_MIN 和 GUTSY_API_KEY。仅支持桌面端。
安装
在 SourceWeft 中
- 打开 控制台中的 gutsy,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
gutsy-mcp
A local gut check for coding agents. Before Claude Code, Codex, Cursor or Copilot runs
rm -rf, force-pushes, deploys or sends something, it calls gut_check and gets back
calibrated probabilities that the action is intended and safe, plus a recommendation:
proceed, confirm (ask the user first) or block.
Runs on your CPU with gutsy (0.8B, 775 MB GGUF). No API calls, no per-call cost, deterministic, and your code never leaves the machine.
What it is and isn't
It's a fast second opinion that adds friction where it's warranted. It is not a security boundary: the agent decides whether to call it and writes the context it sees, and a 0.8B model is weak at ambiguity and multi-step rules (see the model card). Keep your normal permission settings on. Default thresholds aren't tuned for your workflow; log the probabilities and adjust them.
1. Start the gutsy runtime
Or set GUTSY_INFERENCE_DIR=/path/to/gutsy/gutsy-inference and gutsy-mcp starts it on
first use.
2. Add the MCP server
Claude Code:
Cursor (.cursor/mcp.json) / Claude Desktop:
VS Code (.vscode/mcp.json):
Codex (~/.codex/config.toml):
Then tell the agent when to use it (CLAUDE.md, AGENTS.md, .cursor/rules):
Before deleting files, rewriting git history, force-pushing, touching databases, deploying, publishing or sending anything, call
gut_check. If it doesn't returnproceed, stop and ask me.
3. Optional: enforce it with a Claude Code hook
An MCP tool only runs if the agent remembers to call it. The hook runs on every risky-looking Bash command regardless. It can only ask or deny, never auto-approve.
.claude/settings.json:
block becomes a confirmation prompt by default; set GUTSY_HOOK_ALLOW_DENY=1 to deny outright.
Tool
gut_check(action, context="", user_request="") returns:
License: Apache 2.0.
来源:README.md,提交 75a820d
工具
0版本历史
1- v0.1.1最新Oct 7, 2026


