agentseed
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@agentseedverify my recent changes for hallucinated APIs before marking done"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
π‘οΈ AgentSeed
Anti-hallucination guardrails for AI coding agents.
A hybrid Agent Plugins plugin (Skill + MCP Server) that forces spec-driven development and verifies code before it is marked done β so "Done, all tests pass" becomes an observed fact, not a claim.
English Β· δΈζ Β· ζ₯ζ¬θͺ
β Like this project? Consider giving it a star β it helps developers find guardrails before they ship hallucinated code.
Why AgentSeed
LLMs hallucinate β in code, that means invented APIs, undefined identifiers, fake test passes, and confident overclaims. The numbers:
15.1% of code hallucinations are knowledge-conflicting: calling APIs that don't exist or were never imported (arXiv:2404.00971).
<10% of hallucinated code fails tests β most slips through CI (arXiv:2404.00971).
60%+ of model-output errors are unverifiable β no way to tell fact from fiction (FAVA, cited in SoK).
Prompt-only guardrails are soft: a model can agree to verify and then skip it. AgentSeed binds the instruction to a hard MCP gate β the evidence comes from running code, not from the model's self-report.
It also fills two gaps the 1.0.0 spec deliberately leaves open:
Gap in Agent Plugins 1.0.0 | What AgentSeed does |
No enforcement mechanism (skills are optional to follow) |
|
No official conformance linter |
|
Related MCP server: Metsuke
What it does
Six MCP tools β zero required dependencies, enhanced by optional extras:
Tool | Catches | Technique |
| Invented APIs / undefined symbols | Python AST + TS/JS lexical pass |
| Placeholder code, overclaims, fabricated content | 28+ signals in 3 groups |
| Non-conformant plugin packaging | Strict 1.0.0 linter |
| "Tests pass" without running anything | Deterministic execution channel |
| Invalid structured output | JSON Schema validation |
| No persistent evidence trail | Appends a JSONL audit entry under |
Measured on a seeded synthetic corpus (5 defect classes): precision 1.0, recall 1.0 (tp=100, fp=0, fn=0) with the regression test locking it in β methodology and honest scope in docs/BENCHMARK.md.
Live demo
$ verify_code(source="def f():\n return magic_unknown()\n", language="python")
{
"language": "python",
"suspects": ["magic_unknown"] # β hallucinated API caught
}
$ scan_hallucination(source="The feature is production ready, all tests pass. Trust me.")
{
"hits": [
{"word": "all tests pass", "group": "oversold", "line": 1},
{"word": "production ready", "group": "oversold", "line": 1},
{"word": "trust me", "group": "oversold", "line": 1}
],
"clean": false # β overclaim caught
}
$ check_plugin(path="/path/to/AgentSeed")
{ "ok": true, "errors": [], "warnings": [] } # β strict 1.0.0 conformanceQuick start
Option A β download a release (no git needed):
# grab the latest asset from https://gitcode.com/badhope/AgentSeed/releases
# or use the installer, which drops it into a client of your choice:
bash install.sh --client auto # macOS / Linux
./install.ps1 -Client auto # Windows PowerShell
# --client: claude | opencode | cursor | manualOption B β clone:
git clone https://gitcode.com/badhope/AgentSeed.git
# or: https://gitcode.com/badhope/AgentSeed Β· https://gitee.com/badhope/AgentSeedDrop the
AgentSeed/directory into any client that supports Agent Plugins (Cursor, VS Code, Claude Code, Copilotβ¦). No build, no install; zero required dependencies (optional extras below).The client auto-discovers the
verify-before-codeskill and theagentseedMCP server fromplugin.json+mcp.json.That's it. The skill now gates every coding task: contract β implement β verify β evidence.
Run it standalone for a self-check:
python3 server/guard_engine.py # self-check: demo verify_code + scan_hallucination
python3 -m unittest discover -s server # 90+ unit tests (also: `pytest` in CI)Gate a human PR with the same rules (CI mode):
python3 server/guard_cli.py gate --root . # composite hard gate: conformance
# + symbols + baseline scan, exit 1 on any failure
python3 server/guard_cli.py check . --ci # plugin conformance only, exit 1 on errors
python3 server/guard_cli.py scan src/ --strict # hallucination scan, blocking severities onlyWindows note:
mcp.jsonlaunches the server viapython3. On many Windows installs that alias is a Microsoft Store stub; if the server fails to start, changecommandto["python", "server/guard_server.py"]or point it at your interpreter's absolute path.
Optional dependencies
AgentSeed runs on the Python standard library alone. Installing the extras upgrades two tools to industry-standard engines (auto-detected, graceful fallback either way):
pip install -r server/requirements.txtExtra | Upgrades | Without it |
|
| built-in subset validator |
|
| built-in AST walk |
| SKILL.md frontmatter parsing β full YAML | built-in lite parser |
Use an absolute path to
guard_server.py; the server resolves everything else from its own location, so no special cwd is required.
Compatibility & graceful degradation
AgentSeed adapts to whatever the host supports, degrading one level at a time β never silently skipping verification:
Host capability | What you get | Setup |
Full Agent Plugins | drop-in: skill + MCP auto-discovered, | copy the plugin directory |
MCP-capable client | all 6 tools via registration | exact snippets above |
Skills-only client | skill workflow; verification degrades to | copy |
Plain terminal / CI / no agent at all | CLI gates with exit codes |
|
The skill itself carries the degradation path: when the MCP tools are absent,
it instructs the agent to run guard_cli.py verify/scan through the shell and
apply the same blocking rules to exit codes.
Platform support
Client | Agent Plugins 1.0.0 | Status | Notes |
Claude Code | skills + MCP config | verified | skills via |
opencode | skills + MCP config | verified |
|
Cursor | skills + mcp.json | untested* | copy into project; no stable plugin dir yet |
VS Code (+Copilot) | MCP support rolling out | untested* | use mcp.json fields as-is |
Cline / Windsurf | MCP config compatible | untested* | stdio server entry maps directly |
* honest states: the formats are spec-compatible and expected to work, but we have not run AgentSeed in these clients ourselves. Verified = actually exercised by the maintainers. If you verify one, open a PR updating this table.
Clients honoring the full spec also set ${PLUGIN_DATA}; AgentSeed reads
agentseed.config.json from there.
Configuration reference (agentseed.config.json)
Key | Type | Effect |
|
| scan exclusions (replaces built-in test-idiom list) |
|
| per-group severity override |
|
| default |
|
| extend the hallucination word pool at runtime |
|
| names |
|
| allowlist of executables |
|
| child environment policy: |
Unknown keys are warned about on stderr β a typo'd key is never silently ignored.
Language coverage (honest scope)
Language |
|
Python | full AST scope walk (+ pyflakes when installed), line numbers |
TypeScript / JavaScript | lexical regex pass (documented false-positive classes) |
Go / Java / Rust / C/C++ / others | not analyzed yet β returns an empty result |
β οΈ Security note:
sandbox_runexecutes real processes with your user's permissions. Clients must gate it behind user approval; setsandbox_allowed_prefixesin shared/CI environments. When an allowlist is configured, commands resolve throughPATHto their absolute path before execution β a hostile working directory cannot shadow an allowlisted basename with a planted executable, and unmatched/unresolvable commands are refused (exit -10) without running.
Client setup β exact configuration
AgentSeed has two halves; both are needed for the full gate:
Skill (
skills/verify-before-code/) β teaches the agent the workflow.MCP server (
server/guard_server.py) β provides the 6 tools.
The installers wire step 1 and print step 2 for your client. Manual setup:
Claude Code
# skill: copy it flat so SKILL.md sits directly in the folder
cp -R skills/verify-before-code ~/.claude/skills/verify-before-code
# MCP server:
claude mcp add agentseed -- python /path/to/AgentSeed/server/guard_server.pyopencode β copy skills/verify-before-code/ to
~/.config/opencode/skill/verify-before-code, then add to opencode.json:
{
"mcp": {
"agentseed": {
"type": "local",
"command": ["python", "/path/to/AgentSeed/server/guard_server.py"],
"enabled": true
}
}
}Cursor / other MCP clients β register a stdio server with
command: python, args: ["/path/to/AgentSeed/server/guard_server.py"],
and copy the skill folder per your client's skills location.
Use an absolute path to
guard_server.py; the server resolves everything else from its own location, so no special cwd is required.
Changelog
See CHANGELOG.md.
Built-in guardrail library (EN / δΈζ / ζ₯ζ¬θͺ)
Resource | Contents |
| 20+ copy-paste guardrail prompts: completion evidence, verify-before-claim, uncertainty, API verification, citation rules⦠|
| Failure-mode catalog: 5-class code taxonomy + SoK findings + real legal/chat cases |
| Executable end-of-task checklist: risk class β contract β evidence β language audit |
| The contract every coding task must satisfy |
| Adoption map of vendor techniques (Anthropic, OpenAI, AWS, NVIDIA, IBM, Guardrails AI, Vectara) |
How the gate works
Before coding β load the SDD contract, state it in one sentence.
Implement β real code only: no placeholders, no invented APIs.
Before "done" β call
verify_code+scan_hallucination; prove runtime claims withsandbox_run; validate structure withschema_validate.Language audit β completion reports attach evidence; overclaim vocabulary is banned.
Only when all checks pass may the task be marked complete.
The enforced norms (how the AI is constrained)
The skill does not just suggest behavior β each norm maps to a gate that observes compliance:
Norm | Enforced by |
Contract before code (goal / interface / non-goals / verification) | Gate 1 of |
No invented APIs β never call an undefined symbol |
|
Real implementations only β no stubs/placeholders/fakes |
|
Verification before completion claims β run it, then say it | Gate 3 + |
Evidence-backed reports β file:line you read, output you saw | Gate 4 audit + |
Smallest diff, no drive-by refactors; surface ambiguity, ask once | contract non-goals + CI |
These synthesize what strong agent operators converged on publicly β the
AGENTS.md open standard, Anthropic's Claude Code best
practices, and community
disciplines like
FerroxLabs/agents-md (senior-
engineer stance, anti-sycophancy, forced verification loops). The difference:
there they are prose; here every norm has an enforcing tool or exit code.
Full table with rationale:
skills/verify-before-code/references/DEFAULT-NORMS.md.
Works alongside your agent config files
AgentSeed complements β not replaces β the context files your team already
maintains for AI coding agents (CLAUDE.md, AGENTS.md, .cursor/rules/,
.github/copilot-instructions.md, CONTRIBUTING.md conventions):
Those files carry project facts: stack, commands, layout, style. They are prose β persuasive but soft.
AgentSeed carries the behavior contract and the enforcement: hallucination detection, verification gates, evidence trails β hard MCP tools plus CI exit codes that cannot be quietly deprioritized.
Keep one source of truth per concern: point your
AGENTS.mdat this skill's norms instead of copying them; the plugin updates and the norm stays binding.
Why AgentSeed vs. alternatives
Prompt-only guardrail skills (e.g. superpowers) | Static import linters (MCP) | AgentSeed | |
Touches code | β prompt only | β import-graph analysis | β AST + lexical analysis |
Runs verification tools | β | lint gates | β 6 MCP tools incl. sandboxed execution |
Hallucination-language scan | β | β | β stub / oversold / fabricated signals (EN + CJK) |
Enforcement | soft (skill text) | CI gate | hard gate: skill + MCP + CLI exit codes |
Agent Plugins 1.0.0 conformance linter | β | β | β first |
Roadmap
Hybrid Skill + MCP guardrail, 6 tools β first strict 1.0.0 linter
Prompt pool + pattern library + grouped signals + vendor techniques
verify_codefor TypeScript / JavaScript (zero-dependency lexical pass)verify_codefor GoGrammar-constrained decoding for structured outputs
Optional remote fact-checker (HHEM-style) MCP server
FAQ
Does it need a specific LLM? No β it's client-agnostic and model-agnostic. The gate is enforced by the skill + MCP server, not by any model.
Zero dependencies? Yes. The entire MCP server is pure Python standard library.
Conformant? check_plugin validates the plugin against the spec (Β§5/Β§6/Β§7) β and AgentSeed passes its own linter (ok: true).
Contributing
Issues, PRs and ideas welcome. See the roadmap for directions β or open an issue for a hallucination pattern we haven't catalogued yet.
License
Apache-2.0 Β© AgentSeed. See LICENSE.
β If AgentSeed saved you from shipping hallucinated code, star the repo β it's the best signal that guardrails matter.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseDqualityDmaintenanceSpec-driven development tool for AI coding assistants that generates specs, validates code compliance, and provides actionable feedback.1129MIT
- AlicenseNot gradedqualityBmaintenanceProvides SDLC compliance verification as tools that AI agents can invoke, continuously monitoring and evaluating development processes.MIT

corbatofficial
AlicenseAqualityBmaintenancePolicy and quality engine for AI coding agents that enforces team coding standards and provides validation gates for agent-assisted software delivery.7624MIT
Rigour MCPofficial
AlicenseNot gradedqualityBmaintenanceEnables AI agents to self-govern by scanning code for hardcoded secrets, structural violations, and AI drift in real-time, providing fix packets for automatic remediation.26MIT
Related MCP Connectors
33 tools that make AI write, implement, and verify intent against explicit, testable constraints.
Lints + auto-fixes how AI coding agents discover any new product. 24 rules, 6 tools, score 0-100.
See, price, and control every tool call your AI agents make: policy checks, cost, and audit tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Morningstar202604/AgentSeed'
If you have feedback or need assistance with the MCP directory API, please join our Discord server