MCP Hub
Back to servers

agence

Validated

AI governance MCP server — policy enforcement, skills, memory, multi-LLM consensus

Registry
Stars
2
Tools
10
Updated
May 3, 2026
Validated
May 5, 2026
Validation Details

Duration: 9.2s

Server: agence v1.0.0

Quick Install

npx -y @l-agence/mcp-server-agence

l'Agence — Agentic Engineering Co-Environments

Author: Stephane Korning · 2026 · MIT + Commons Clause
Version: v1.0.0 · May 2026

The governance layer for AI coding agents.
Every agent action classified, gated, and cryptographically logged — regardless of which LLM or tool runs it.


The Problem

Your AI coding agents can write code. They can commit, push, delete, refactor.

But who's watching them?

Claude Code has no audit trail. Aider trusts the user. Codex sandboxes everything and hopes for the best. LangChain gives you building blocks but no guardrails.

Agence exists because advisory guardrails aren't guardrails at all. It's the layer that sits between any AI agent and your filesystem and says "not without approval."


What Agence Does

Agence is an agent-agnostic governance stack for software engineering. It doesn't replace your coding agent — it governs, orchestrates, and audits all of them from a single control plane.

Command Gating — Every shell command is classified before execution:

TierGateExample
T0Auto-executegit status, ls, cat
T1Loggedgit add, git commit
T2Human approval requiredgit push, git reset
T3Blockedrm -rf, chmod 777, kill

Unknown commands default to T2. Not T0. Fail-closed. The guard runs as a separate process — agents cannot bypass their own policy.

Cryptographic Audit — Every agent decision is logged to a Merkle-chained, append-only ledger. Each entry links to the previous via SHA-256. Tamper with one entry and the chain breaks. Verify with: agence ^ledger verify.

Multi-Agent Orchestration — 18 agents across 4 types (persona, tool, loop, ensemble). Route with @agent syntax. Override models with dot-notation: @ralph.gpt4o. Dispatch to Aider, Claude Code, Copilot, or your own tools — all governed by the same policy.

Peer Consensus — Route any question to 3 independent LLMs and get weighted consensus. Your architecture review shouldn't depend on one model's blind spots.

Session Persistence — Save, resume, and hand off sessions between agents. Full context survives restarts. Automatic tmux capture of stdout/stdin/stderr — no 16KB buffer limits.

Git-Native — No database. No server. State lives in git worktrees and flat files. Knowledge is sharded, gated, and selectively routed — you decide what gets shared.


By the Numbers

30,701Lines of production code (23.9K TypeScript + 6.8K bash)
751Tests with 1,768 assertions across 21 files
279Security-specific tests (guard + hardening + SEC regressions)
9Red-team cycles completed (SEC-008 through SEC-019)
33+Orchestration skills (^fix, ^review, ^hack, ^peers, ^vault...)
18Registered agents (10 persona, 5 tool, 1 loop, 2 ensemble)
12LLM providers (Anthropic, OpenAI, Azure, Google, Mistral, Groq, Ollama...)
10MCP tools + 3 MCP resources (Model Context Protocol server)
3Dependencies total (MCP SDK, Bun, Zod)
0Databases required

Who This Is For

  • Teams using multiple AI coding agents who need one policy governing all of them
  • Enterprises requiring audit trails for AI-generated code changes
  • Security-conscious developers who want fail-closed gating, not fail-open trust
  • Anyone who's had an AI agent break something and wished there was a layer between the agent and rm -rf

Who This Is NOT For

  • If you want an AI pair programmer → use Aider
  • If you want IDE autocomplete → use Continue or Copilot
  • If you want to build any kind of agent → use LangChain/LangGraph
  • If you want cloud-hosted async tasks → use OpenAI Codex

Agence governs all of the above.


Install

As a git submodule (recommended)

git submodule add https://github.com/l-agence/agence .agence
git submodule update --init --recursive
bash .agence/bin/agence ^init
export PATH="$PWD/.agence/bin:$PATH"

Or: clone directly

git clone https://github.com/l-agence/agence .agence
cd .agence && bun install
./bin/agence ^init
export PATH="$PWD/.agence/bin:$PATH"

Prerequisites

ToolRequiredInstall
bash 4+YesBuilt-in on Linux/macOS/WSL
git 2.30+Yessudo apt install git
bun 1.3+Yesbun.sh
tmuxFor swarmsudo apt install tmux
jqFor ledger queriessudo apt install jq

Windows: Use WSL (Ubuntu recommended).


Quick Start

# Chat with an agent
agence "How should I structure this feature?"

# Route to a specific agent
agence @sonya "Review this auth module"

# Launch an agent shell
agence !ralph                    # Persona: autonomous iteration
agence !claude                   # Tool: Claude Code CLI
agence !aider                    # Tool: aider (code patches)

# Save session (resume later or hand off to another agent)
agence ^save "OAuth2: done token validation, next: refresh flow"
agence ^resume
agence ^handoff @sonya

# Audit trail
agence ^ledger verify            # Verify Merkle chain integrity
agence ^audit trail              # View full decision history

# Peer consensus (3 independent LLMs)
agence @peers "Should we use Redis or Postgres for session storage?"

# See all commands
agence --help

Architecture

YOUR REPO/
└── .agence/                     ← lives here (submodule or clone)
    ├── bin/                     # CLI: agence, aibash, ibash, aido, agentd
    ├── codex/                   # Governance: AIPOLICY.yaml, Laws, Principles, agents/
    ├── nexus/                   # Local state: .ailedger, sessions, faults (gitignored)
    ├── knowledge/               # Team knowledge: docs, lessons, plans (committed)
    │   └── private/             # Private knowledge (gitignored, never shared)
    ├── organic/                 # Swarm coordination: tasks, jobs, workflows
    └── lib/                     # Core: guard.ts, signal.ts, skill.ts, memory.ts, peers.ts

COGNOS — Four pillars:

PillarPurposeLocation
CODEXImmutable governance — Laws, Principles, Rules, AIPOLICYcodex/
KNOWLEDGETeam-shared docs, lessons, plans — selectively routed via @ symlinksknowledge/
NEXUSLocal operational state — sessions, ledger, signalsnexus/ (gitignored)
ORGANICSwarm orchestration — tasks, workflows, matrix schedulingorganic/

Runtime: Bun + bash. No Python. No pip. No npm install of untrusted packages in the critical path.

MCP: Agence exposes itself as an MCP server (10 tools, 3 resources) so any MCP-compatible client can use agence's governance layer. Agence also acts as an MCP client — consuming tools from external MCP servers. See MCP.md for integration guide.


Command Reference

PrefixModeExampleUse When
(none)Chatagence "explain this error"Advice, explanation, Q&A
^Knowledgeagence ^save, agence ^lessonShared state, knowledge ops
~Privateagence ~note "idea"Private notes (never committed)
+Autonomousagence +refactor-authAgent plans & executes a task
/Validatedagence /git-statusPre-approved safe commands
!Systemagence !ralph, agence !claudeLaunch agents or tools
@Routeagence @sonya "review this"Send to specific agent

Agent Roster

AgentTypeBest For
@ralphLoopAutonomous iteration with backpressure
@sonyaPersonaArchitecture, code review
@claudiaPersonaDeep reasoning, critical decisions
@chadPersonaDevOps, infra, CI/CD
@alephPersonaRed team, security analysis
@claudeToolClaude Code CLI (headless spawn)
@aiderToolCode patches, git diffs
@pilotToolGitHub Copilot CLI
@peersEnsemble3-LLM weighted consensus
@pairEnsemble2-LLM lightweight consensus

Override models with dot-notation: @ralph.gpt4o, @sonya.opus, @ralph.aider


Governance

Agence uses a 5-tier command policy. The guard runs as a separate process — agents cannot bypass their own policy.

TierGateExample
T0Auto-executegit status, ls, cat
T1Loggedgit add, git commit
T2Human approvalgit push, git reset
T3Blockedrm -rf, chmod 777
T4NeverForce push main, drop DB

Unknown commands default to T2. Fail-closed. 120+ rules across git, GitHub CLI, AWS, Terraform, and shell.

All decisions logged to nexus/.ailedger — append-only, Merkle-chained, HMAC-signed.

See SECURITY.md for full security architecture, red-team findings, and disclosure timeline.


Swarm (agentd)

agentd start ralph claude aider   # Launch 3 agents in tmux
agentd tangent create fix-auth    # Isolated worktree + container
agentd inject fix-auth "run tests"  # Send command via socat socket
agentd status                     # View all agents + tangents

Each tangent gets: isolated git worktree, optional Docker container (--cap-drop ALL, --read-only, --no-new-privileges), socat socket for IPC, tmux pane for observability.


Tests

bun test                          # Full suite

751 tests, 1,768 assertions, 0 failures across 21 files:

SuiteTestsCoverage
guard.test.ts132Command gate, tier escalation, eval safety
security-hardening.test.ts134HMAC, signal forgery, injection prevention, SEC-010→019 regressions
memory.test.ts62COGNOS 3-store: retain/recall/cache/forget/promote/distill
peers-dispatch.test.ts53Peer consensus, mixed routing
queue.test.ts42Work queue, dashboard, GitHub Issues bridge
runs.test.ts35SWE run lifecycle, aggregation, outcomes
vault.test.ts20Hermetic vault init/sync/push/pull + SEC-019 security
setup.test.ts10Interactive wizard, escaping, validation
mcp-client.test.ts10MCP client guard-gating, env sanitization
mcp.test.ts10MCP tool/resource surface verification
sequent.test.ts12Tournament tangents, CLI dispatch

Documentation

DocWhat it covers
ArchitectureEnd-to-end system design
Swarmagentd, tangents, tmux model
CommandsComplete CLI reference
SecurityTCB, red-team findings, disclosure timeline
TutorialGetting started walkthrough
SetupDetailed installation guide

License

MIT + Commons Clause — free to use, modify, and self-host.
Commercial redistribution requires a separate agreement.
See LICENSE.md.


Built by Stephane Korning. Hardened by 5 red-team cycles. Governed by its own CODEX.

Reviews

No reviews yet

Sign in to write a review