Spots

GitHub - Chaarangan/stepgate: Agents can't skip steps: an MCP server that runs…

Agents can't skip steps. Write an agent's procedure once, as a YAML stepfile, and run it from any MCP client, such as Claude Code, with the model that client already uses.

A stepfile declares its inputs, the remote APIs

A stepfile declares its inputs, the remote APIs and MCP servers it may call, and an ordered list of steps. Each step says what output it must produce and which gates check that output. The file names no model and no framework.

Stepgate runs stepfiles. It is an MCP server

Stepgate runs stepfiles. It is an MCP server that offers each stepfile as a tool. When a client's agent calls it, Stepgate shows the agent one step at a time, makes every API call the step needs, and moves on only when the step's gates pass. Make the procedure you already wrote enforceable

A skill or runbook written as markdown tells

A skill or runbook written as markdown tells an agent what to do, and the agent decides how much of it to follow. Here is one:

stepgate_outline turns it into a skeleton, and the

stepgate_outline turns it into a skeleton, and the finished stepfile makes both lines binding. Stepgate does the lookup itself, so the agent never fetches or copies a version. The agent only writes the notes, and a gate rejects any note whose version differs from what the registry returned, naming the rows that broke it:

When an agent is handed a plan as

When an agent is handed a plan as text, it decides how much of the plan to follow, a step counts as done when the agent says so, and nothing records afterwards what actually ran. A stepfile moves those decisions out of the model:

Steps run in order, one at a time

Steps run in order, one at a time. The agent is shown only the current step's instructions and operations, never a later step, so it cannot skip ahead. Earlier steps stay in its own conversation.

Gates decide, not the model. A step passes

Gates decide, not the model. A step passes only when its output satisfies JSON Schema, JSONLogic or an HTTP verifier, and gates can check that output against what the APIs actually returned, so a fabricated value fails. A failed gate's diagnosis goes back to the model for a bounded number of retries.

The model never holds a key. The server

The model never holds a key. The server makes every tool call and attaches credentials itself, and it refuses requests to hosts the stepfile does not declare.

Every run leaves a record. A hash-chained ledger

Every run leaves a record. A hash-chained ledger lists each step, tool call, gate verdict and retry, and editing it afterwards breaks the chain, which stepgate --verify detects.

News

GitHub - Chaarangan/stepgate: Agents can't skip steps: an MCP server that runs gated, API-only stepfiles on the client's own model.

Agents can't skip steps.

@spots #dev
Source: Show HN
See more like this