
gutsy
io.github.kouhxpv0.1.1更新於 Oct 7, 2026
Local gut check before risky agent actions: calibrated safe/intended probabilities, no API calls.
概覽
在代理執行高風險動作前提供本機「直覺檢查」,回傳校準過的安全/意圖機率以及 proceed、confirm 或 block 建議。
- 功能
- 提供 gut_check 工具,輸入動作描述以及選用的上下文與使用者請求,回傳該動作是否有意圖、是否可逆的機率、拒絕分數,以及 proceed、confirm 或 block 建議。它在 CPU 上執行小型本機模型,不呼叫 API,因此程式碼與上下文不會離開本機。選用的 Claude Code 鉤子可對高風險 Bash 指令執行相同檢查,且只能詢問或拒絕,不能自動核准。
- 適用情境
- 當編碼代理可能刪除檔案、改寫 git 歷史、強制推送、操作資料庫、部署、發佈或傳送內容時,適合加入,以便在這些步驟前取得快速第二意見並增加阻力。它只是減速帶,不是安全邊界,因此應保留一般權限設定。
- 執行需求
- 需要本機 Python 執行環境,套件透過 uvx 執行。需要本機 gutsy-inference 伺服器,可單獨啟動,也可在 GUTSY_INFERENCE_DIR 指向包含 models.json 的目錄時由 MCP 伺服器啟動。選用設定包括 GUTSY_URL、GUTSY_MODEL、GUTSY_PROCEED_MIN、GUTSY_BLOCK_MIN 和 GUTSY_API_KEY。僅支援桌面端。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 gutsy,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
gutsy-mcp
A local gut check for coding agents. Before Claude Code, Codex, Cursor or Copilot runs
rm -rf, force-pushes, deploys or sends something, it calls gut_check and gets back
calibrated probabilities that the action is intended and safe, plus a recommendation:
proceed, confirm (ask the user first) or block.
Runs on your CPU with gutsy (0.8B, 775 MB GGUF). No API calls, no per-call cost, deterministic, and your code never leaves the machine.
What it is and isn't
It's a fast second opinion that adds friction where it's warranted. It is not a security boundary: the agent decides whether to call it and writes the context it sees, and a 0.8B model is weak at ambiguity and multi-step rules (see the model card). Keep your normal permission settings on. Default thresholds aren't tuned for your workflow; log the probabilities and adjust them.
1. Start the gutsy runtime
Or set GUTSY_INFERENCE_DIR=/path/to/gutsy/gutsy-inference and gutsy-mcp starts it on
first use.
2. Add the MCP server
Claude Code:
Cursor (.cursor/mcp.json) / Claude Desktop:
VS Code (.vscode/mcp.json):
Codex (~/.codex/config.toml):
Then tell the agent when to use it (CLAUDE.md, AGENTS.md, .cursor/rules):
Before deleting files, rewriting git history, force-pushing, touching databases, deploying, publishing or sending anything, call
gut_check. If it doesn't returnproceed, stop and ask me.
3. Optional: enforce it with a Claude Code hook
An MCP tool only runs if the agent remembers to call it. The hook runs on every risky-looking Bash command regardless. It can only ask or deny, never auto-approve.
.claude/settings.json:
block becomes a confirmation prompt by default; set GUTSY_HOOK_ALLOW_DENY=1 to deny outright.
Tool
gut_check(action, context="", user_request="") returns:
License: Apache 2.0.
來源:README.md,提交 75a820d
工具
0版本歷史
1- v0.1.1最新Oct 7, 2026


