π‘οΈ AgentSeed
Anti-hallucination guardrails for AI coding agents.
A hybrid Agent Plugins 1.0.0 plugin (Skill + MCP Server) that forces spec-driven development and verifies code before it is marked done β so "Done, all tests pass" becomes an observed fact, not a claim.
English Β· δΈζ Β· ζ₯ζ¬θͺ
β Like this project? Consider giving it a star β it helps developers find guardrails before they ship hallucinated code.
Why AgentSeed
LLMs hallucinate β in code, that means invented APIs, undefined identifiers, fake test passes, and confident overclaims. The numbers:
- 15.1% of code hallucinations are knowledge-conflicting: calling APIs that don't exist or were never imported (arXiv:2404.00971).
- <10% of hallucinated code fails tests β most slips through CI (arXiv:2404.00971).
- 60%+ of model-output errors are unverifiable β no way to tell fact from fiction (FAVA, cited in SoK).
Prompt-only guardrails are soft: a model can agree to verify and then skip it. AgentSeed binds the instruction to a hard MCP gate β the evidence comes from running code, not from the model's self-report.
It also fills two gaps the 1.0.0 spec deliberately leaves open:
| Gap in Agent Plugins 1.0.0 | What AgentSeed does |
|---|---|
| No enforcement mechanism (skills are optional to follow) | verify-before-code skill makes verification non-skippable |
| No official conformance linter | check_plugin is the first strict 1.0.0 linter |
What it does
Five MCP tools β zero required dependencies, enhanced by optional extras:
| Tool | Catches | Technique |
|---|---|---|
verify_code |
Invented APIs / undefined symbols | Python AST + TS/JS lexical pass |
scan_hallucination |
Placeholder code, overclaims, fabricated content | 28+ signals in 3 groups |
check_plugin |
Non-conformant plugin packaging | Strict 1.0.0 linter |
sandbox_run |
"Tests pass" without running anything | Deterministic execution channel |
schema_validate |
Invalid structured output | JSON Schema validation |
Live demo
$ verify_code(source="def f():\n return magic_unknown()\n", language="python")
{
"language": "python",
"suspects": ["magic_unknown"] # β hallucinated API caught
}
$ scan_hallucination(source="The feature is production ready, all tests pass. Trust me.")
{
"hits": [
{"word": "all tests pass", "group": "oversold", "line": 1},
{"word": "production ready", "group": "oversold", "line": 1},
{"word": "trust me", "group": "oversold", "line": 1}
],
"clean": false # β overclaim caught
}
$ check_plugin(path="/path/to/AgentSeed")
{ "ok": true, "errors": [], "warnings": [] } # β strict 1.0.0 conformance
Quick start
Option A β download a release (no git needed):
# grab the latest asset from https://github.com/weed33834/AgentSeed/releases
# or use the installer, which drops it into a client of your choice:
bash install.sh --client auto # macOS / Linux
./install.ps1 -Client auto # Windows PowerShell
# --client: claude | opencode | cursor | manual
Option B β clone:
git clone https://github.com/weed33834/AgentSeed.git
# or: https://gitcode.com/badhope/AgentSeed Β· https://gitee.com/badhope/AgentSeed
- Drop the
AgentSeed/directory into any client that supports Agent Plugins 1.0.0 (Cursor, VS Code, Claude Code, Copilotβ¦). No build, no install; zero required dependencies (optional extras below). - The client auto-discovers the
verify-before-codeskill and theagentseedMCP server fromplugin.json+mcp.json. - That's it. The skill now gates every coding task: contract β implement β verify β evidence.
Run it standalone for a self-check:
python3 server/guard_engine.py # conformance + demos
python3 -m unittest discover -s server # 50+ unit tests
Gate a human PR with the same rules (CI mode):
python3 server/guard_cli.py check . --ci # plugin conformance, exit 1 on errors
python3 server/guard_cli.py scan src/ --strict # hallucination scan, blocking severities only
Windows note:
mcp.jsonlaunches the server viapython3. On manyWindows installs that alias is a Microsoft Store stub; if the server failsto start, changecommandto["python", "server/guard_server.py"]orpoint it at your interpreter's absolute path.
Optional dependencies
AgentSeed runs on the Python standard library alone. Installing the extrasupgrades two tools to industry-standard engines (auto-detected, gracefulfallback either way):
pip install -r server/requirements.txt
| Extra | Upgrades | Without it |
|---|---|---|
jsonschema |
schema_validate β full Draft 2020-12 validation |
built-in subset validator |
pyflakes |
verify_code β pyflakes F821 undefined-name analysis |
built-in AST walk |
pyyaml |
SKILL.md frontmatter parsing β full YAML | built-in lite parser |
Use an absolute path to
guard_server.py; the server resolves everythingelse from its own location, so no special cwd is required.
Compatibility & graceful degradation
AgentSeed adapts to whatever the host supports, degrading one level at a timeβ never silently skipping verification:
| Host capability | What you get | Setup |
|---|---|---|
| Full Agent Plugins 1.0.0 | drop-in: skill + MCP auto-discovered, ${PLUGIN_DATA} config honored |
copy the plugin directory |
| MCP-capable client | all 5 tools via registration | exact snippets above |
| Skills-only client | skill workflow; verification degrades to guard_cli.py via shell (the skill contains the fallback instructions) |
copy skills/verify-before-code flat |
| Plain terminal / CI / no agent at all | CLI gates with exit codes | python server/guard_cli.py check . --ci |
The skill itself carries the degradation path: when the MCP tools are absent,it instructs the agent to run guard_cli.py verify/scan through the shell andapply the same blocking rules to exit codes.
Platform support
| Client | Agent Plugins 1.0.0 | Status | Notes |
|---|---|---|---|
| Claude Code | skills + MCP config | verified | skills via ~/.claude/skills, server via claude mcp add |
| opencode | skills + MCP config | verified | ~/.config/opencode/opencode.json, see docs |
| Cursor | skills + mcp.json | untested* | copy into project; no stable plugin dir yet |
| VS Code (+Copilot) | MCP support rolling out | untested* | use mcp.json fields as-is |
| Cline / Windsurf | MCP config compatible | untested* | stdio server entry maps directly |
* honest states: the formats are spec-compatible and expected to work, but wehave not run AgentSeed in these clients ourselves. Verified = actually exercisedby the maintainers. If you verify one, open a PR updating this table.
Clients honoring the full spec also set ${PLUGIN_DATA}; AgentSeed readsagentseed.config.json from there (allowlist, severity map, sandbox timeout).
Client setup β exact configuration
AgentSeed has two halves; both are needed for the full gate:
- Skill (
skills/verify-before-code/) β teaches the agent the workflow. - MCP server (
server/guard_server.py) β provides the 5 tools.
The installers wire step 1 and print step 2 for your client. Manual setup:
Claude Code
# skill: copy it flat so SKILL.md sits directly in the folder
cp -R skills/verify-before-code ~/.claude/skills/verify-before-code
# MCP server:
claude mcp add agentseed -- python /path/to/AgentSeed/server/guard_server.py
opencode β copy skills/verify-before-code/ to~/.config/opencode/skill/verify-before-code, then add to opencode.json:
{
"mcp": {
"agentseed": {
"type": "local",
"command": ["python", "/path/to/AgentSeed/server/guard_server.py"],
"enabled": true
}
}
}
Cursor / other MCP clients β register a stdio server withcommand: python, args: ["/path/to/AgentSeed/server/guard_server.py"],and copy the skill folder per your client's skills location.
Use an absolute path to
guard_server.py; the server resolves everythingelse from its own location, so no special cwd is required.
Changelog
See CHANGELOG.md.
Built-in guardrail library (EN / δΈζ / ζ₯ζ¬θͺ)
| Resource | Contents |
|---|---|
PROMPT-POOL |
20+ copy-paste guardrail prompts: completion evidence, verify-before-claim, uncertainty, API verification, citation rules⦠|
HALLUCINATION-PATTERNS |
Failure-mode catalog: 5-class code taxonomy + SoK findings + real legal/chat cases |
VERIFICATION-CHECKLIST |
Executable end-of-task checklist: risk class β contract β evidence β language audit |
SDD-CONTRACT |
The contract every coding task must satisfy |
VENDOR-SOLUTIONS |
Adoption map of vendor techniques (Anthropic, OpenAI, AWS, NVIDIA, IBM, Guardrails AI, Vectara) |
How the gate works
- Before coding β load the SDD contract, state it in one sentence.
- Implement β real code only: no placeholders, no invented APIs.
- Before "done" β call
verify_code+scan_hallucination; prove runtime claims withsandbox_run; validate structure withschema_validate. - Language audit β completion reports attach evidence; overclaim vocabulary is banned.
- Only when all checks pass may the task be marked complete.
Why AgentSeed vs. alternatives
| Anti-Hallucinate (mcpmarket) | superpowers | AgentSeed | |
|---|---|---|---|
| Touches code | β chat-only | prompt-only | β AST analysis |
| Runs tools | β | β | β 5 MCP tools |
| Enforcement | soft | soft | hard gate |
| 1.0.0 conformance linter | β | β | β first |
Roadmap
- Hybrid Skill + MCP guardrail, 5 tools β first strict 1.0.0 linter
- Prompt pool + pattern library + grouped signals + vendor techniques
verify_codefor TypeScript / JavaScript (zero-dependency lexical pass)verify_codefor Go- Grammar-constrained decoding for structured outputs
- Optional remote fact-checker (HHEM-style) MCP server
FAQ
Does it need a specific LLM? No β it's client-agnostic and model-agnostic. The gate is enforced by the skill + MCP server, not by any model.
Zero dependencies? Yes. The entire MCP server is pure Python standard library.
Conformant? check_plugin validates the plugin against 1.0.0 Β§5/Β§6/Β§7 β and AgentSeed passes its own linter (ok: true).
Contributing
Issues, PRs and ideas welcome. See the roadmap for directions β or open an issue for a hallucination pattern we haven't catalogued yet.
License
MIT Β© AgentSeed. See LICENSE.
β If AgentSeed saved you from shipping hallucinated code, star the repo β it's the best signal that guardrails matter.