AgentStack
MCP verified MIT Self-run

Buckler

mcp-rethunk-ai-buckler · by Rethunk-AI

Agent gatehouse for AI coding harnesses (Cursor, Claude Code, …): declarative hook policies, harness-neutral core + adapters, YAML packs (polished Git pack by default). Cosign-signed releases; setup.sh for Linux, macOS, Windows (Git Bash).

No reviews yet
0 installs
0 views
view→install

Install

$ agentstack add mcp-rethunk-ai-buckler

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Buckler? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Buckler — Agent Gatehouse

> Protect your system from unauthorized agentic actions. Declarative, multi-harness policy engine that intercepts shell commands and tool calls from AI coding assistants—before they cause damage.

[](https://github.com/Rethunk-AI/buckler/actions/workflows/ci.yml) [](https://python.org) [](https://github.com/astral-sh/uv) [](https://github.com/astral-sh/ruff) [](https://mypy-lang.org/) [](LICENSE)


Summary

Buckler is a harness-neutral policy engine: declarative YAML rules evaluate normalized signals from any AI coding assistant and decide whether to allow, deny, ask, or nudge—independent of which harness fired the hook. The agent-git and agent-gh packs ship enabled by default, blocking uncontrolled git commits, force-pushes, remote destruction, and destructive gh commands out of the box.

Feature Highlights

  • Harness-neutral core — the evaluator knows nothing about Cursor's hooks.json; only thin adapters do
  • Declarative YAML packs — rules match on abstract trigger kinds, not harness-specific strings
  • agent-git + agent-gh packs — deny uncontrolled git commits / force-push / remote destruction; deny destructive gh subcommands; nudge toward MCP tools
  • Cosign-signed releases — every release tarball is verified before install
  • Cross-platform — Linux, macOS, Windows (Git Bash)

Documentation

| Audience | File | |----------|------| | Install, configure, bypass, troubleshoot | [HUMANS.md](HUMANS.md) | | LLM / dev internals, contract rules | [AGENTS.md](AGENTS.md) | | Architecture & adapter boundary | [ARCHITECTURE.md](ARCHITECTURE.md) | | Commit conventions, CI, dev setup | [CONTRIBUTING.md](CONTRIBUTING.md) | | Threat model, Cosign verification, disclosure | [SECURITY.md](SECURITY.md) | | Troubleshooting (hooks, policy, audit log) | [docs/troubleshooting.md](docs/troubleshooting.md) | | Rule YAML schema | [docs/rule-schema.md](docs/rule-schema.md) | | Default agent-git pack matrix | [docs/agent-git.md](docs/agent-git.md) | | Default agent-gh pack matrix | [docs/agent-gh.md](docs/agent-gh.md) | | Path resolution (XDG, Windows, env overrides) | [docs/paths.md](docs/paths.md) |

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.