Candidate
Generated automatically when an automated verification test fails repeatedly. Quarantined until confirmed.
Enforce pre-edit research, protect against legacy gotchas, analyze blast radius across monorepo packages, and prevent code regressions — in 3 coarse-grained MCP tools.
Kuma is an autonomous safety-first context & orchestration engine that runs as a zero-native-build MCP server alongside AI coding agents. Its job is simple: make sure agents understand what they are about to change before they change it.
Instead of scattering 30+ micro-tools that confuse agents, Kuma exposes exactly 3 coarse-grained tools: kuma_context, kuma_memory, and kuma_safety. Each tool executes deterministic multi-step internal pipelines backed by a pure WASM SQLite knowledge store.
Auto-detects your workspace platforms (Claude, Cursor, Windsurf, Antigravity, OpenCode) and configures rules, hooks, and MCP servers automatically:
curl -fsSL https://raw.githubusercontent.com/plumpslabs/kuma/main/install.sh | bash
Install directly from Claude Code terminal:
/plugin marketplace add plumpslabs/kuma
/plugin install kuma@plumpslabs-kuma
Add as a native Antigravity plugin:
agy plugin add https://github.com/plumpslabs/kuma
# Auto-detect your editors & agents
npx @plumpslabs/kuma init
# Or install for all 13 supported agent formats
npx @plumpslabs/kuma init --all
{
"mcpServers": {
"kuma": {
"command": "npx",
"args": ["-y", "@plumpslabs/kuma"]
}
}
}
📖 Read INSTALL.md for complete setup guides for Cursor, Windsurf, OpenCode, Zed, Cline, and Copilot.
5 seconds slower but safe beats lightning-fast regression. Every modification has a verified safety net.
Mandatory research pipeline before editing unfamiliar code. Blast radius and consumers are evaluated first.
Coarse-grained pipelines. Exactly 3 MCP tools instead of 30+ granular tools that distract agent attention.
Gotchas, decisions, and domain flows persist across agent restarts, git branch switches, and subagent forks.
SQLite knowledge graph, package dependency graph, and AST analysis execute locally without flaky LLM calls.
Fresh gotchas injected only when relevant; stale gotchas auto-deprecated when files are deleted or refactored.
Kuma keeps your agent's MCP tool palette lean and focused. All capabilities are grouped into 3 deterministic tools with high-signal actions:
| Action | Purpose | Pipeline Flow |
|---|---|---|
init | Project brief & session restore | Loads git branch, workspace package summary, and top-5 budgeted fresh gotchas. |
research | 5-step research pipeline | Checks cache, scans codebase, executes graph queries, assesses blast radius risk. |
history | Cross-session provenance | Answers "why is this file written this way" — change log, decisions, resolved quirks. |
map | Repository workspace topology | Monorepo package map, internal package dependencies, and affected packages. |
impact | Blast radius & consumers | Identifies downstream consumers, related test files, and architectural risk scoring. |
flow | Domain sequence flow | Reads sequence flows connecting entry points to middleware, handlers, and databases. |
| Action | Purpose | Details |
|---|---|---|
gotcha | Record or resolve quirks | Supports full lifecycle: candidate, active, verified, resolved, deprecated. |
arch_flow | Record execution sequence | Domain execution flow (e.g. route.ts → controller.ts → service.ts → db.ts). |
decision | ADR decision recording | Records architectural decision rationale, options evaluated, and chosen outcomes. |
research_save | Save research findings | Stores structured research findings into .kuma/research/ and SQLite cache. |
search | Hybrid knowledge search | FTS5 full-text + graph traversal + session memory search. |
| Action | Purpose | Details |
|---|---|---|
guard | Anti-regression & architecture check | Blocks circular dependencies, private package imports, and dangerous shell commands. |
verify | Scoped monorepo verification | Auto-detects test runners (pnpm, npm, cargo, pytest, go) and runs tests on affected packages only. |
checkpoint | Atomic snapshot | Creates a point-in-time file snapshot before major refactors. |
rollback_label | Deterministic rollback | Restores files cleanly to a labeled snapshot if refactoring fails. |
Modern software projects are rarely single-folder apps. Kuma automatically maps monorepo topologies (pnpm workspaces, npm/yarn workspaces, Cargo, Go) and performs deterministic blast radius analysis:
Identifies package boundaries, cross-package dependencies, and package ownership without requiring manual configuration.
When modifying a core package or shared utility, Kuma instantly computes which downstream packages and test files are affected.
Prevents circular package imports and blocks deep private imports (e.g. importing from package/src/internal instead of the package root).
Gotchas are fragile legacy quirks and framework pitfalls. To prevent advice decay, Kuma tracks gotchas through a rigorous lifecycle:
Generated automatically when an automated verification test fails repeatedly. Quarantined until confirmed.
Confirmed gotchas injected right before an agent touches the fragile file. Budgeted strictly to top-5 to prevent context token bloat.
Marked fixed when verification passes after code modification, or when an agent resolves it via kuma_memory({ action: "gotcha", status: "resolved" }).
When files are deleted or renamed, Kuma's self-healing engine automatically retires obsolete gotchas so they never distract future sessions.
Parallel background subagents (auditors, researchers, coding subagents) frequently read and write to the knowledge store concurrently:
Database flushes and session memory writes use atomic file replacement (.tmp.pid.timestamp → renameSync), ensuring zero corruptions under high concurrency.
Tracks current git branches via git rev-parse. Detects branch switches and informs agents immediately so context remains aligned.
Runs everywhere Node.js runs using WebAssembly SQLite (sql.js) — zero node-gyp or C++ compiler toolchain headaches.
Kuma is engineered to provide complete peace of mind whether running standalone or paired with agent governance frameworks:
| Scenario | How Kuma Operates | Benefits |
|---|---|---|
| Standalone MCP | Injected via kuma init into Claude Code, Cursor, OpenCode, Antigravity, Windsurf, Roo, etc. |
Enforces the research pipeline, gotcha pre-edit shield, and auto-verification on every turn. |
| With Matcha | Pairs harmoniously with Matcha's cognitive governors (planning gate, reviewer, auditor, cleaner). | Kuma's .kuma/ state is exempted from gates, providing persistent knowledge to Matcha's 6 specialized subagents. |
| In CI / CD | Runs automated verification, drift detection, and garbage collection in headless scripts. | Ensures that repository documentation and knowledge graphs stay perfectly synced with code changes. |