Guardian agent for AI coding: four frontier models review risky diffs and commits before they ship.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
One command to connect your AI coding agents to TruVerifAI β multi-model review tools plus local pre-commit/pre-write review gates β on Claude Code, Codex CLI, Cursor (IDE + CLI), VS Code / GitHub Copilot, Gemini CLI, and Antigravity.
init shows a plan of everything it will write for your machine and asks
once before touching anything. To scope or preview it:
Agent names: claude, codex, copilot, vscode, cursor, gemini,
antigravity; hook is the git pre-commit gate and rules the agent-rules
blocks. Declining the prompt exits with nothing written. A flag init does
not recognize also exits with nothing written (it never falls through to an
install).
MIT-licensed. Zero runtime dependencies β this package is plain,
unminified JavaScript and Python; npm pack @truverifai/init and read every
line. There is no build step and no transitive supply chain.
node <launcher> <host> <gate>.py. No node, no gates, on any host.python3, or py on Windows) β the gate code itself.npx @truverifai/init doctor checks both and names the missing one, rather
than letting an absent runtime disable the gates silently.
The review gates block risky commits and edits. One command controls all of them:
(If you installed globally with npm i -g @truverifai/init, the same commands
are available as the shorter tvai gates off. Plain npx does not leave a
tvai binary on your PATH, so use the full form above unless you installed
globally.)
This writes enable_gates to ~/.truverifai/config.json, which every
delivery reads β the git pre-commit hook and the Codex, Cursor, Copilot,
VS Code, Gemini and Antigravity hooks alike. The MCP review tools stay
connected either way; only the automatic gating stops.
Two things worth knowing:
enable_gates was removed
from the plugin's settings panel (it could only ever reach Claude Code's own
hooks β the X8 split), so this command is the single switch. One exception:
a value stored in the panel before the removal may still be exported to
Claude Code's hooks until you clear it; gates status calls that out and
says how.TVAI_ENABLE_GATES overrides everything. If you have it exported,
gates on|off writes the file underneath it and has no effect until you
unset it. gates status says so.To remove the gates entirely rather than switch them off, see Removing it below.
init runs as you, interactively: it prints the plan first, writes only
after you confirm, and prints every file it touches. The complete list:
Its own home β ~/.truverifai/
config.json β your tvai_β¦ API key (minted via browser device-flow
login; this process never sees a password).gates/current/ β the review-gate code (Python + a Node launcher),
vendored from this package's vendor/ directory..nudge_state.json, gate_state/ β local rate-limit / state files.Per detected agent (user-level; only for agents found on your machine)
api_token option, and one permissions.allow
entry (mcp__plugin_panel-review_truverifai) in ~/.claude/settings.json
so Claude's auto-mode classifier permits the free gate-release calls.
Additive merges only β the file is backed up first, never created, and
never has anything removed.TRUVERIFAI markers) and
[features] hooks = true in ~/.codex/config.toml; ~/.codex/hooks.json.~/.cursor/hooks.json (gates) and ~/.cursor/mcp.json (tools).~/.copilot/mcp-config.json.mcp.json.~/.gemini/settings.json (tools entry).Per repository (written in the repo you run init from, with a prompt)
.github/hooks/truverifai-gate.json + truverifai-vscode.json
(Copilot CLI / VS Code gate hooks), .gemini/settings.json (Gemini
hooks), .agents/hooks.json (Antigravity hooks).TRUVERIFAI_RULES_STARTβ¦END) in
AGENTS.md / CLAUDE.md / GEMINI.md β you are asked first..git/hooks/pre-commit β the git gate, which catches commits made
outside any agent (and is the one layer --no-verify makes an
explicit, auditable act). Installed automatically when you run init
inside a git repo. It is the only repo-scoped gate, so add it to other
repos with cd <repo> && npx @truverifai/init hook. An existing
pre-commit hook you wrote is never overwritten β init reports it and
prints the line to add by hand.logout strips the API key from every config listed above. Nothing is
installed as a service, daemon, or startup item; the gates only run when
your agent host invokes its hooks.
truverif.ai mints your API key
in the browser.api.truverif.ai a hashed repo fingerprint (SHA-256 of your git remote
URL or repo path β the raw path/URL never leaves the machine),
content hashes of the changed hunks, and the local classifier's category
labels and scores. Not your source code, and not your file paths
(only coarse path-class tags like "test/docs").audit_coding etc.): send only what your agent
explicitly passes when it invokes a review β that is the product: the
diff/context you choose to submit is analyzed by multiple frontier
models.TVAI_PAYLOAD_LOG) are local-only and opt-in β nothing
is uploaded.The gates fail open by design: if our server is unreachable or anything errors, your commit/write proceeds and a visible notice says the change was not gated. This tool never blocks your work on its own failure.
The full source is public at
github.com/TruVerifAI/init β every
release is synced there. To verify a tarball by hand:
npm pack @truverifai/init, extract, and diff against the repo β
bin/tvai.js, lib/*.js, and vendor/gates/*.py are the entire runtime
surface, dependency-free. The gate code (vendor/gates/) is also
published at
github.com/TruVerifAI/claude-plugins
(plugins/panel-review/hooks/). Build provenance attestation (CI publish
with cryptographic linkage to this repo) is the planned next step.
A complete removal, in one command:
init wrote (Codex, Cursor, Copilot, VS Code,
Gemini, Antigravity, and the git pre-commit hook), the vendored gate code
under ~/.truverifai/, and the MCP server entries. Hook files you share
with other tools are edited, not deleted β only our own entries are taken
out, matched by marker..tvai-bak backups init made of shared config files β deleted
only after the live file is verified clean; if a live file still contains
our entries, its backup is kept and named as the restore source.Uninstall is honest about failure: anything it could not remove is listed at the end under "needs your attention", and the command exits nonzero when secret-bearing residue remains (CI scripts that assumed exit 0 should check this). Silence means clean.
Uninstall also tries the host CLIs to remove the plugins init installed
(claude plugin uninstall panel-review@truverifai,
codex plugin remove panel-review@truverifai), best-effort: each attempt
prints what happened, a failure never blocks the rest of the uninstall, and
where no runnable CLI exists (the Claude desktop app) it prints the in-app
step instead (+ button, then Plugins).
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/panel-review)<a href="https://allmcps.com/mcp/panel-review"><img src="https://allmcps.com/api/badge/panel-review?style=directory" alt="Panel Review on AllMCPs" /></a>