Add fak to your agent over MCP
Reader: an MCP builder wiring the fak kernel into a client they already run.
Lifecycle: current · Generation: the stdio transport and the fak_* adjudication
verbs are release-independent; tools/list on your build is the authoritative tool inventory.
Authority: integration index · APIs, wires & MCP.
Proof / next action: python3 examples/mcp/verify.py (seconds; deterministic; exit 0/1; no model, key, or GPU).
Start here: which MCP job is yours? This page serves the first row — completing setup here never requires reading kernel implementation history. The other rows route to their own pages.
| You want to… | Read |
|---|---|
| Wire fak into your MCP client (Claude Code, Cursor, any MCP client) | this page |
| Put fak in front of another MCP server you already run | harden-any-mcp.md |
| Front your agent’s model instead — a base-URL proxy, no per-call asking | README.md; for Claude Code, claude.md |
| Read the wire contract or kernel internals (contributor) | the deeper layers below |
What you are wiring
fak serve --stdio is a Model Context Protocol server: newline-delimited JSON-RPC 2.0
over stdin/stdout — no listener, no auth surface, no network. It exposes the kernel’s
adjudication verbs as MCP tools, so your agent can ask for a verdict before running
a call (fak_adjudicate), run a tool through the kernel (fak_syscall), or screen
a result it already executed (fak_admit). Every call is adjudicated against a
reviewable capability floor that lives in git as a JSON manifest.
Setup: Claude Code (one paste)
- Get the binary onto your
PATH—go build -o fak ./cmd/fakfrom a clone (the Go module is the repo root), or a release binary. -
Copy
examples/mcp/.mcp.jsonto your project root:{ "mcpServers": { "fak": { "command": "fak", "args": ["serve", "--stdio", "--policy", "examples/dev-agent-policy.json"], "env": {} } } } - Open Claude Code in that project — it discovers a project-level
.mcp.json, offers to enable the server, andfakappears under/mcpwith thefak_*tools available.
The shipped entry wires the example
dev-agent floor.
Point --policy at your own reviewed floor
(POLICY.md), or drop the
flag to run the raw fail-closed kernel (default-deny: every tool refused until you
allow it).
Setup: other clients
| Client | How |
|---|---|
| Claude Code (without the paste) | claude mcp add fak -- fak serve --stdio |
| Cursor | the same mcpServers block in .cursor/mcp.json (project) or ~/.cursor/mcp.json (global) — see cursor.md |
| Any MCP client, stdio | run fak serve --stdio as the server command |
| Any MCP client, HTTP | fak serve --addr 127.0.0.1:8080, then POST /mcp |
Check it worked (the one next action)
From a clone root (the script and the example policy live in the repo, so this one
check needs the clone even if your own project only carries .mcp.json):
python3 examples/mcp/verify.py # -> PASS / FAIL, exit 0 / 1
The script drives the real stdio transport — the exact path .mcp.json wires — and
is deterministic: the same four checks return the same verdicts on every run, with no
model, no key, no GPU, no network. PASS (exit 0) means all four held:
- the JSON-RPC handshake names the server (
fak-gateway); tools/listdiscovery lists thefak_*adjudication tools;- a shared-history mutation (
git_push) is refused DENY / POLICY_BLOCK; - a read (
git_status) is allowed — the floor is live, not a blanket deny.
A captured run with the raw JSON-RPC frames is in
examples/mcp/EXAMPLE-OUTPUT.md.
The tools your agent gets
The core verbs are fak_adjudicate (verdict only, before your client runs a tool),
fak_syscall (adjudicate and execute through the kernel), fak_admit (screen a result
you already ran, before it enters context), fak_read (kernel-cached file reads),
and fak_changes / fak_revoke (the cross-agent coherence feed). The per-tool table —
what each does and when your agent calls it — is in
examples/mcp/README.md;
the full input schemas come from tools/list on your build, which is authoritative.
Scope, honestly: the verify script exercises the call-side capability gate over MCP
stdio. The result-side stack (context-MMU quarantine, IFC taint ledger) is reached via
fak_admit / fak_syscall; its claim-by-claim scope is
CLAIMS.md.
Where the deeper layers live
Setup does not require these; they are the contributor and maintainer layers behind it.
- Worked example with captured frames — the runnable proof directory this page’s setup and next action come from.
- MCP tool-result envelope — the
SyscallResponsewire shape and the closed refusal vocabulary (contributor). - MCP tool-schema floor baseline — the measured always-sent schema token budget (contributor).
- Publishing fak to the Official MCP Registry — how the server is listed for discovery (maintainer).