claudeers.
// MCP Servers

agentseed-mcp

Anti-hallucination gate for AI coding agents — 8 MCP tools catch invented APIs (17 languages), fake "all tests pass" claims, and slopsquatting packages befor…

Repository unavailable
0/100
last commit 30 days ago
last release 30 days ago
releases 12
open issues 0

Install with your AI

This project is repository unavailable — not recommended for automated install, so we don't generate an auto-install prompt for it. Read the repo and decide for yourself.

// compatibility

Platformscli, api
Operating systems—
AI compatibilityclaude
LicenseApache-2.0
Pricingopen-source
LanguagePython

Get your FREE $2.50 API credits to access TickAtlas financial data ↗
AgentSeed logo

AgentSeed

The anti-hallucination gate for AI coding agents.

AI agents invent APIs. They claim "all tests pass" without running anything. They ship confident, fabricated code. AgentSeed is the gate that stops it — a zero-dependency plugin that verifies code before it is marked done, so "done" means observed fact, not self-report.

English · 中文 · 日本語

⭐ Like this project? Star it — it helps developers find guardrails before they ship hallucinated code.


Why you need this

LLMs hallucinate — and in code that means invented APIs, undefined identifiers, fake test passes, and confident overclaims:

  • 15.1% of code hallucinations call APIs that don't exist or were never imported (arXiv:2404.00971).
  • <10% of hallucinated code fails tests — ~90% slips past CI (arXiv:2404.00971).
  • 60%+ of model-output errors are unverifiable on their face (FAVA, SoK).

Prompt-only guardrails are soft: a model can agree to verify and then skip it. AgentSeed binds the instruction to a hard gate — the evidence comes from running code, not from the model's own word.

What AgentSeed is — in 30 seconds

A drop-in Agent Plugins 1.0.0 plugin (Skill + MCP server + optional client hook + CI gate) that makes three promises:

PromiseHow it's kept
🚫 No invented APIsverify_code parses your code in 17 languages and flags any symbol that is called but never defined or imported
🚫 No fake "done"scan_hallucination catches stubs, overclaims, and fabricated claims in English and CJK; sandbox_run proves runtime claims by actually running them
🚫 No skipped verificationthe Skill gates the workflow, the client hook blocks Write/Edit on files that don't pass, and guard_cli gate enforces the same rules in CI with exit codes

It also fills the two gaps the 1.0.0 spec deliberately leaves open:

Gap in Agent Plugins 1.0.0AgentSeed's answer
No enforcement mechanism (skills are optional to follow)verify-before-code skill + optional client-enforced hook make verification non-skippable
No official conformance lintercheck_plugin is the first strict 1.0.0 linter — and AgentSeed passes its own linter (ok: true)

See it catch a hallucination

# Your coding agent just "finished" this — it calls magic_unknown(),
# an API that doesn't exist and was never imported:

def f():
    return magic_unknown()      # ← hallucinated API

# AgentSeed, before the task can be marked done:
$ verify_code(source=..., language="python")
{
  "language": "python",
  "suspects": ["magic_unknown"]       # ← caught, blocking
}
# And the agent's completion claim doesn't survive either:
"The feature is production ready, all tests pass. Trust me."

$ scan_hallucination(source=...)
{
  "hits": [
    {"word": "all tests pass",   "group": "oversold",  "line": 1},
    {"word": "production ready", "group": "oversold",  "line": 1},
    {"word": "trust me",         "group": "oversold",  "line": 1}
  ],
  "clean": false                        # ← caught, blocking
}

The verdict is measured, not promised: on a seeded synthetic corpus (5 defect classes, 100 defective + 40 clean modules) AgentSeed scores precision 1.0 · recall 1.0 (tp=100, fp=0, fn=0) — locked in by a regression test. Methodology and honest limits: docs/BENCHMARK.md.

How the gate works

  1. Before coding — load the SDD contract and state it in one sentence.
  2. Implement — real code only: no placeholders, no invented APIs.
  3. Before "done" — run verify_code + scan_hallucination; prove runtime claims with sandbox_run; validate structure with schema_validate.
  4. Language audit — completion reports attach evidence; overclaim vocabulary is banned.
  5. Only when all checks pass may the task be marked complete.

Quick start

Option A — download a release (no git needed):

# grab the latest asset from https://github.com/Morningstar202604/agentseed-mcp/releases
# or use the installer, which wires it into your client:
bash install.sh --client auto --hooks        # macOS / Linux
./install.ps1 -Client auto -Hooks            # Windows PowerShell
# --client: claude | opencode | cursor | manual
# --hooks / -Hooks: also register the Claude Code enforcement hook

Option B — clone:

git clone https://github.com/Morningstar202604/agentseed-mcp.git
# mirrors: https://gitee.com/badhope/agentseed-mcp · https://gitcode.com/badhope/agentseed-mcp
  1. Drop the cloned agentseed-mcp/ directory into any Agent Plugins–capable client (Cursor, VS Code, Claude Code, Copilot…). No build, no install.
  2. The client auto-discovers the verify-before-code skill and the agentseed MCP server from plugin.json + mcp.json.
  3. That's it. Every coding task is now gated: contract → implement → verify → evidence.

Run it standalone or gate a human PR with the same rules:

python3 server/guard_engine.py                       # self-check demo
python3 -m unittest discover -s server               # full unit-test suite
python3 server/guard_cli.py gate --root .            # CI-equivalent hard gate
python3 server/guard_cli.py check . --ci             # plugin conformance only
python3 server/guard_cli.py verify src/app.go        # language inferred from the suffix
python3 server/guard_cli.py scan src/app.py --strict # inline or file, hallucination signals
python3 server/guard_cli.py scan . --baseline baseline-scan.json  # tree sweep, new signals only

Windows note: mcp.json may only name one literal interpreter, and it ships python3 (right for macOS/Linux/WSL). On Windows run ./install.ps1, which rewrites command to python in the installed copy, or edit it by hand as "command": "python" with "args": ["server/guard_server.py"] — command is a string, the array belongs to args. npx agentseed-mcp needs no editing at all: the npm shim picks the interpreter per platform.

The 8 MCP tools

Zero required dependencies — pure Python standard library; optional extras upgrade two tools to industry-standard engines (see below).

ToolCatchesTechnique
verify_codeInvented APIs / undefined symbolsPython AST + config-driven lexical passes (17 languages)
check_contractCode violates a written specrequires/prohibits contract check
check_importsHallucinated packages (slopsquatting)stdlib + known-packages allowlist check
scan_hallucinationPlaceholder code, overclaims, fabricated content28+ signals in 3 groups, EN + CJK
check_pluginNon-conformant plugin packagingStrict 1.0.0 linter
sandbox_run"Tests pass" without running anythingDeterministic execution channel (bounded-memory output)
schema_validateInvalid structured outputJSON Schema validation
record_verificationNo persistent evidence trailJSONL audit trail under PLUGIN_DATA

Language coverage (honest scope)

Languageverify_code analysis
Pythonfull AST scope walk (+ pyflakes when installed), line numbers
TypeScript / JavaScriptlexical regex pass (documented false-positive classes)
Go · Rust · Java · C · C++ · C# · PHP · Ruby · Kotlin · Swiftconfig-driven generic lexical pass
Dart · Lua · R · Zigconfig-driven generic lexical pass
any other languageadd a LangSpec registry entry — no engine change

Honest limits: attribute calls (obj.m()), macros, and cross-file symbols are not analyzed; Ruby's paren-less calls are supported.

Honest limits: attribute calls (obj.m()), macros, and cross-file symbols are not analyzed; Ruby's paren-less calls are supported.

It really catches other languages — live-tested

The same rule applies to every registered language: a bare call to a symbol that is never defined is a hallucination, whatever the syntax:

# Go       detect_undefined_symbols("func main() { process_data() }", "go")  -> ["process_data"]
# Rust     fn main() { let x = load_config() }        -> ["load_config"]
# Java     class A { void m() { connect_db() } }      -> ["connect_db"]
# C        int main() { ghost(); return 0; }          -> ["ghost"]
# Kotlin   fun main() { fetch_users() }               -> ["fetch_users"]
# Swift    func run() { connect() }                   -> ["connect"]
# Ruby     def run; authenticate; end                 -> ["authenticate"]
# TypeScript function run() { connectDb() }           -> ["connectDb"]

Verified across Go · Rust · Java · C · C++ · C# · PHP · Ruby · Kotlin · Swift · TypeScript · Dart · Lua · R · Zig — every language flags its invented call, and clean code in each language reports zero false positives.

Client-enforced hook mode

Skills persuade; hooks enforce at the client boundary. Register AgentSeed as a Claude Code hook and every Write/Edit/MultiEdit is scanned automatically — no prompt can skip it:

python3 server/guard_hook.py register --client claude   # idempotent, merges settings
python3 server/guard_hook.py --file path/to/source.py   # scan any file directly
  • PreToolUse inspects the incoming content before it lands on disk; a blocking finding exits 2, and the agent must fix the flagged lines.
  • PostToolUse re-checks saved files on write paths without inline content.
  • Failure policy (honest): infrastructure problems (bad stdin, unreadable files) never block work — fail-open; only positive scan findings block.

Platform support

ClientStatusNotes
Claude Code✅ verifiedskills + MCP + optional enforcement hook
opencode✅ verified~/.config/opencode/opencode.json
Cursor⚪ spec-compatible*copy into project; no stable plugin dir yet
VS Code (+Copilot)⚪ spec-compatible*MCP support rolling out
Cline / Windsurf⚪ spec-compatible*stdio server entry maps directly

* honest states: formats are spec-compatible and expected to work, but not yet exercised by the maintainers. If you verify one, open a PR updating this table.

Optional dependencies

pip install -r server/requirements.txt
ExtraUpgradesWithout it
jsonschemaschema_validate → full Draft 2020-12built-in subset validator
pyflakesverify_code → pyflakes F821 analysisbuilt-in AST walk
pyyamlSKILL.md frontmatter → full YAMLbuilt-in lite parser

Configuration (agentseed.config.json)

KeyEffect
allowlistscan exclusions (replaces built-in test-idiom list)
severitiesper-group severity override (error | warning | info)
timeoutdefault sandbox_run timeout, seconds (1–120)
extra_tokensextend the hallucination word pool at runtime
suppress_symbolsnames verify_code never flags (reported in suppressed)
known_packagespackages check_imports treats as known (stdlib + common + this list)
sandbox_allowed_prefixesallowlist of executables sandbox_run may launch; PATH-resolved, separator-boundary enforced (absent = unrestricted)
sandbox_env"inherit" | "scrub" — scrub drops credential-looking env vars

Unknown keys are warned on stderr — a typo is never silently ignored.

⚠️ Security note: sandbox_run executes real processes with your user's permissions. Gate it behind user approval; set sandbox_allowed_prefixes in shared/CI environments. Commands resolve through PATH to absolute paths before execution, so a hostile cwd cannot shadow an allowlisted binary; unmatched commands are refused (exit -10) without running.

Compatibility & graceful degradation

Host capabilityWhat you get
Full Agent Pluginsdrop-in: skill + MCP auto-discovered, ${PLUGIN_DATA} config honored
MCP-capable clientall 8 tools via registration
Skills-only clientskill workflow; verification degrades to guard_cli.py via shell
Plain terminal / CICLI gates with exit codes

Built-in guardrail library (EN / 中文 / 日本語)

PROMPT-POOL (copy-paste guardrail prompts) · HALLUCINATION-PATTERNS (failure-mode catalog) · VERIFICATION-CHECKLIST (executable end-of-task checklist) · SDD-CONTRACT (the contract every task must satisfy) · DEFAULT-NORMS (senior-engineer operating norms, mapped to the gate that enforces each; English only) · VENDOR-SOLUTIONS (adoption map of vendor techniques). Every library lives under skills/verify-before-code/references/, and the SKILL files list them.

Why AgentSeed vs. alternatives

Prompt-only guardrail skillsStatic import linters (MCP)AgentSeed
Touches code❌ prompt only✅ import graphs✅ AST + lexical (registry-wide)
Runs verification tools❌lint gates✅ 8 MCP tools incl. sandbox
Hallucination-language scan❌❌✅ stub/oversold/fabricated, EN + CJK
Enforcementsoft (skill text)CI gatehard: skill + MCP + hook + CLI exit codes
1.0.0 conformance linter❌❌✅ first

FAQ

Does it need a specific LLM? No — client-agnostic and model-agnostic; the gate is enforced by skill + MCP + hooks + CI, not by any model.

Zero dependencies? Yes. The MCP server is pure Python standard library.

Does it work with our existing AGENTS.md / CLAUDE.md? Yes — it complements them. Those files carry project facts (prose, persuasive); AgentSeed carries the behavior contract and the hard enforcement.

How do I extend it to another language? Add a LangSpec registry entry in server/engine/symbols.py — one config, no engine change.

Contributing

Issues, PRs and ideas welcome — or open an issue for a hallucination pattern we haven't catalogued yet. See CONTRIBUTING.md.

License

Apache-2.0 © AgentSeed. See LICENSE.


⭐ If AgentSeed saved you from shipping hallucinated code, star the repo — it's the best signal that guardrails matter.

// faq

What is agentseed-mcp?

Anti-hallucination gate for AI coding agents — 8 MCP tools catch invented APIs (17 languages), fake "all tests pass" claims, and slopsquatting packages before they ship. Zero-dependency Agent Plugins 1.0.0 plugin (Skill + MCP server + CLI + CI gate) for Claude Code, Cursor, VS Code, Copilot.. It is open-source on GitHub.

Is agentseed-mcp free to use?

agentseed-mcp is open-source under the Apache-2.0 license, so it is free to use.

What category does agentseed-mcp belong to?

agentseed-mcp is listed under mcp-servers in the Claudeers registry of Claude-compatible tools.

5 views
★ 8 stars
unclaimed
updated about 1 month ago

// embed badge

agentseed-mcp on Claudeers
[![Claudeers](https://claudeers.com/api/badge/agentseed-mcp.svg)](https://claudeers.com/agentseed-mcp)

// retro hit counter

agentseed-mcp hit counter
[![Hits](https://claudeers.com/api/counter/agentseed-mcp.svg)](https://claudeers.com/agentseed-mcp)

// reviews

// guestbook

0/500

// related in MCP Servers

🔓

f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete…

// mcp-serversf/⟨HTML⟩★ 171,127◷ NOASSERTION[ claude ]
🔓

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Gemini CLI & Hermes Agent. Only official website: ccswitch.io

// mcp-serversfarion1231/⟨Rust⟩★ 136,484◷ MIT[ claude ]
🔓

🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman

// mcp-serversJuliusBrussee/⟨JavaScript⟩★ 107,719◷ MIT[ claude ]
🔓

An open-source AI agent that brings the power of Gemini directly into your terminal.

// mcp-serversgoogle-gemini/⟨TypeScript⟩★ 107,167◷ Apache-2.0[ claude ]
→ see how agentseed-mcp connects across the ecosystem