PluginBench
MCP Server
Active
MIT

Fable Mode MCP Server

io.github.REX-codebase/fable-mode

Mechanical write gates and evidence receipts for AI coding agents—think, prove, attack, then write.

What is the Fable Mode MCP server?

Fable Mode is an open-source control plane for AI coding agents that enforces a deliberate workflow before granting write access to your workspace. It uses time-locked phases, evidence receipts, and adversarial red-team review to ensure agents think through changes before modifying code. The gates are mechanical, not prompt-based: no timer expiration, no proof, no write permission.

Fable Mode prevents AI coding agents from writing prematurely by enforcing a four-phase workflow: deliberation under a time lock, evidence collection for claims, adversarial red-team testing, and only then workspace write access. It's useful when you want verifiable confidence that an agent has thoroughly considered its changes before modifying your codebase.

How to install Fable Mode

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "fable-mode": {
      "command": "uvx",
      "args": [
        "fable-engine"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • create_session — Start a new locked session with an objective and time budget in minutes
  • get_status — Check the active phase, remaining time, evidence counts, and lock state
  • unlock_execution — Request workspace write access after meeting evidence and timer prerequisites
  • record_evidence — Submit evidence receipts and invariants to support claims
  • red_team_review — Run a five-vector adversarial swarm to test code before execution

Use cases

  • Refactor code with confidence that the agent has deliberated and tested changes
  • Verify that an agent's proposed modifications don't break public behavior
  • Catch bugs through mandatory adversarial review before code is written
  • Audit evidence and proof that an agent collected during its reasoning
  • Enforce a checkable workflow for high-stakes code changes in production systems

Fable Mode MCP server FAQ

What is Fable Mode?

Fable Mode is a control plane that makes AI coding agents deliberate, produce evidence, and survive adversarial review before earning permission to write to your workspace. It enforces mechanical gates (time locks, evidence receipts, red-team testing) rather than relying on prompts or confidence scores.

Is Fable Mode free?

Yes, Fable Mode is open-source under the MIT License and published on PyPI as `fable-engine` with zero runtime dependencies.

How do I install it in Cursor or Claude?

Install via `uvx --from fable-engine==1.3.9 fable-engine` as an MCP server, or use `fable-mode setup --yes` to add the optional Agent Skill. VS Code users can click the provided install badge.

Does Fable Mode require authentication?

No authentication is required. It runs locally with optional support for an external AI evidence adjudicator (off by default), which uses a single bounded HTTPS call if enabled.

What happens if the agent tries to write before the gates unlock?

The workspace remains locked. The agent cannot write until the time-lock timer expires, evidence prerequisites are met, and red-team review passes. Early `unlock_execution` requests are rejected.

Can I use Fable Mode without the Agent Skill?

Yes. The MCP server works standalone as a native client. The optional Agent Skill provides a full workflow; setup is explicit so installing the package never silently activates workspace instructions.

README (reference)

Source of truth, from the repository.

<div align="center"> <br/> <img src="./assets/logo-light-mode.svg" width="120" alt="Fable Mode"/>

Fable Mode

<!-- mcp-name: io.github.REX-codebase/fable-mode -->

Agents that think before they write.

<br/>

<a href="https://github.com/REX-codebase/fable-mode"><img src="https://img.shields.io/badge/python-3.10%2B-black" alt="Python 3.10+"/></a>   <a href="./LICENSE"><img src="https://img.shields.io/badge/license-MIT-black" alt="MIT"/></a>   <a href="https://modelcontextprotocol.io"><img src="https://img.shields.io/badge/protocol-MCP-black" alt="MCP"/></a>   <img src="https://img.shields.io/badge/dependencies-0-black" alt="Zero Dependencies"/>   <img src="https://img.shields.io/badge/tests-490%20passing-black" alt="490 tests passing"/>

<br/><br/>

</div>
<br/>

Fable Mode is an open-source control plane for AI coding agents.

It makes an agent deliberate, produce evidence, and survive adversarial review before it earns permission to write to your workspace. The gates are mechanical, not prompt advice: no timer, no proof, no write access.

<br/> <div align="center"> <img src="./assets/flow-simple.svg" width="720" alt="Think → Prove → Attack → Write"/> </div>

Demo

KERR // ORRERY

One self-contained HTML file. Raw WebGL, zero libraries, zero external assets, and zero build step.

https://github.com/user-attachments/assets/8287bbfe-e3ee-4dcf-ba0f-f9ff22ae79bd

<sub>7 renders rejected before final · 2 bugs caught · 10/10 red-team probes passed</sub>

<br/>

Fable Mode overview

https://github.com/user-attachments/assets/27f4f8a2-b1bb-4398-a08c-bc9fd93d69d7

<br/>

Quick start

A session starts locked. Confidence does not unlock it.

  1. Install the MCP server using one of the options below.
  2. Add the optional Agent Skill if you want the full workflow.
  3. Ask your agent to use Fable Mode for a concrete coding task and choose a time budget.

A new session starts with execution locked:

{
  "action": "create_session",
  "session_name": "demo-refactor",
  "objective": "Refactor the parser without changing public behavior",
  "time_budget_minutes": 2
}

The agent then records evidence and an invariant. An early unlock_execution request is rejected until the authority timer and proof prerequisites pass. Use get_status at any point to see the active phase, remaining time, evidence counts, and lock state.

The same gates guard every phase: evidence receipts for claims, a five-vector red-team swarm for code, and a sealed record of what was verified.

<br/>

One package, two agent environments

Fable ships as one PyPI package. The same package contains the runtime, stdio MCP server, and complete Agent Skill. Setup is explicit so installing an MCP server never silently activates workspace instructions.

Run setup from the project the agent will work in:

uvx --from fable-engine==1.3.9 fable-mode setup --yes

This resolves the pinned package in an isolated uv environment and copies the bundled skill to .agents/skills/fable-mode. Use --dry-run to preview or --target <dir> for another skill directory. For a persistent install, use:

python -m pip install fable-engine
fable-mode setup --yes

Then choose only the invocation that matches the agent environment.

Native MCP client

Run fable-engine as the stdio server. For example:

// Claude Code: claude mcp add fable-engine -- uvx --from fable-engine==1.3.9 fable-engine
// Cursor or another JSON-configured client:
{
  "mcpServers": {
    "fable-engine": {
      "command": "uvx",
      "args": ["--from", "fable-engine==1.3.9", "fable-engine"]
    }
  }
}

Install MCP server in VS Code

Shell sandbox with internet, no MCP host

The same package exposes a direct JSON transport. Pipe one fable_session argument object to fable-mode call:

printf '%s\n' '{"action":"create_session","session_name":"demo","objective":"Verify this change","time_budget_minutes":2}' \
  | uvx --from fable-engine==1.3.9 fable-mode call

The command uses JSON Lines: one fable_session argument object per input line and one JSON result per output line. Keep that process open for a full workflow so the authority timer and session stay in the same trusted runtime. A one-line pipe is useful for a single inspection call. Each uvx command can resolve an isolated environment; pip install is better when the sandbox keeps a Python environment between calls. Session data persists outside that environment in Fable's data directory (FABLE_DATA_DIR can override it).

Python 3.10+, zero runtime dependencies. Published on PyPI as fable-engine.

Skill activation remains explicit

setup is the unified path. The older install-skill command remains as a compatible alias for skill-only installation. Neither fable-engine nor pip install fable-engine writes instructions into a workspace on its own.

<br/>

How it works

  1. Think — Time-locked deliberation. The agent cannot write until the timer ends.
  2. Prove — Claims need real evidence (tool receipts, hashes, invariants).
  3. Attack — A red-team swarm tries to break the code.
  4. Write — Only then is the workspace unlocked.
<br/>

Optional: AI evidence adjudicator

The evidence in a session is written by an AI agent, so Fable can optionally ask an external reviewer model to audit that evidence before the workspace unlocks. Stdlib-only, one bounded HTTPS call, no local model, no extra RAM to speak of. Off by default; fail-closed when enforcing. It raises the cost of fabricated proof - it cannot guarantee deception is impossible, and the mechanical gates stay the primary authority. Setup and honest limits: AI evidence adjudicator.

<br/>

What it is not

  • Not a claim of flawless code. It is a checkable workflow, not a guarantee.
  • Not a bigger prompt. The locks are enforced by the engine, not by wording.
  • Not a framework lock-in. It speaks MCP and runs beside your current agent.
<br/>

Docs

<br/>

Contributing

Issues and pull requests are welcome. See CONTRIBUTING.md.

<br/>
<div align="center">

<sub>MIT License · Built by REX</sub>

</div>

Related MCP servers

Check if an ecommerce purchase meets buyer rules before payment. Returns PASS, FAIL, or REVIEW.

Integrate Google's Gemini 3 with Claude via 30+ tools: image/video generation, research, code execution, TTS, and web search.

212
TypeScript
MIT
View repository →

A complete color workflow over MCP: mix, convert, harmonize, measure, place, and remember palettes.

1
Python
MIT
View repository →

Rent GPUs, robots, drones, and construction gear on RIGShare; also onboards equipment owners.

0
JavaScript
MIT
View repository →
N8n8n MCP Server logo

n8n MCP Server

Maintained

The most complete MCP server for n8n — 43 tools for workflows, data tables, and more.

0
JavaScript
MIT
View repository →

Daily US banking regulation brief, weekly digest, archive and comment-deadline tracker. No key.

0
JavaScript
MIT
View repository →