Skip to content

Releases: hifzabuildsai/fourgate

Release list

Fourgate v0.3.0

Choose a tag to compare

@hifzabuildsai hifzabuildsai released this 01 Oct 23:32
f8a03f9

Fourgate v0.3.0

Fourgate gives independent outcome verification for consequential AI-agent actions. After an MCP tool reports success, Fourgate reads the system of record back and records PASS, FAIL or UNKNOWN. No LLM makes that decision.

Install: pip install fourgate

New commands

  • fourgate guard: runs a local stdio MCP server behind the runtime Outcome Guard in shadow (default) or enforce mode.
  • fourgate doctor: checks a guard setup without side effects before you wrap a real server.
  • fourgate demo: a local, zero-credential demo of five real MCP sessions, then a summary page.
  • fourgate init: writes readback.json, runtime.json and scan.json for one write tool from flags.
  • fourgate --version

Guard: fail closed at startup, fail open per call

  • At startup, guard validates the contracts and exits 2 without starting the server if any are invalid. It also refuses to start if the outcome log can't be written.
  • Per call, a verifier crash, timeout, malformed output, missing selector or internal fault is recorded as UNKNOWN (never PASS). The connector's response is passed through unchanged; the call is never blocked on uncertainty.

Doctor: zero-write guarantees and limits

  • doctor never sends tools/call, never runs a verifier, makes no network request, and never creates or modifies a file. If a server command is given, the server is started only for initialize and tools/list, then stopped.
  • It cannot verify that the read credential is valid or read-only, or that the read-back endpoint is reachable. Anything the server does on its own at start-up is outside Fourgate's control.

Demo is simulated. The demo connector is a local simulation, and a local file stands in for the system of record. It needs no API keys and makes no network requests.

Supported

  • Local stdio MCP servers (scan and runtime)
  • HTTP and GitHub read-back via GET
  • Python 3.10–3.13
  • Linux and Windows

Fixes

  • Windows: server commands are now resolved against PATH inside virtual environments (#41)

Known limits

  • No remote MCP transport.
  • Outcome contracts are reviewed and approved by a human; they are not generated.
  • The verifier budget is 2000 ms per call. Anything slower is UNKNOWN (fail open).