Fable Mode is an open-source control plane for AI coding agents.
It makes an agent deliberate, produce evidence, and survive adversarial review
before it earns permission to write to your workspace. The gates are
mechanical, not prompt advice: no timer, no proof, no write access.
Demo
KERR // ORRERY
One self-contained HTML file. Raw WebGL, zero libraries, zero external assets,
and zero build step.
https://github.com/user-attachments/assets/8287bbfe-e3ee-4dcf-ba0f-f9ff22ae79bd
7 renders rejected before final · 2 bugs caught · 10/10 red-team probes passed
Fable Mode overview
https://github.com/user-attachments/assets/27f4f8a2-b1bb-4398-a08c-bc9fd93d69d7
Quick start
A session starts locked. Confidence does not unlock it.
- Install the MCP server using one of the options below.
- Add the optional Agent Skill if you want the full workflow.
- Ask your agent to use Fable Mode for a concrete coding task and choose a time budget.
A new session starts with execution locked:
{
"action": "create_session",
"session_name": "demo-refactor",
"objective": "Refactor the parser without changing public behavior",
"time_budget_minutes": 2
}
The agent then records evidence and an invariant. An early unlock_execution
request is rejected until the authority timer and proof prerequisites pass.
Use get_status at any point to see the active phase, remaining time, evidence
counts, and lock state.
The same gates guard every phase: evidence receipts for claims, a five-vector
red-team swarm for code, and a sealed record of what was verified.
One package, two agent environments
Fable ships as one PyPI package. The same package contains the runtime, stdio
MCP server, and complete Agent Skill. Setup is explicit so installing an MCP
server never silently activates workspace instructions.
Run setup from the project the agent will work in:
uvx --from fable-engine==1.3.9 fable-mode setup --yes
This resolves the pinned package in an isolated uv environment and copies the
bundled skill to .agents/skills/fable-mode. Use --dry-run to preview or
--target <dir> for another skill directory. For a persistent install, use:
python -m pip install fable-engine
fable-mode setup --yes
Then choose only the invocation that matches the agent environment.
Native MCP client
Run fable-engine as the stdio server. For example:
// Claude Code: claude mcp add fable-engine -- uvx --from fable-engine==1.3.9 fable-engine
// Cursor or another JSON-configured client:
{
"mcpServers": {
"fable-engine": {
"command": "uvx",
"args": ["--from", "fable-engine==1.3.9", "fable-engine"]
}
}
}

Shell sandbox with internet, no MCP host
The same package exposes a direct JSON transport. Pipe one fable_session
argument object to fable-mode call:
printf '%s\n' '{"action":"create_session","session_name":"demo","objective":"Verify this change","time_budget_minutes":2}' \
| uvx --from fable-engine==1.3.9 fable-mode call
The command uses JSON Lines: one fable_session argument object per input line
and one JSON result per output line. Keep that process open for a full workflow so
the authority timer and session stay in the same trusted runtime. A one-line pipe
is useful for a single inspection call. Each uvx command can resolve an
isolated environment; pip install is better when the sandbox keeps a Python
environment between calls. Session data persists outside that environment in
Fable's data directory (FABLE_DATA_DIR can override it).
Python 3.10+, zero runtime dependencies. Published on PyPI as fable-engine.
Skill activation remains explicit
setup is the unified path. The older install-skill command remains as a
compatible alias for skill-only installation. Neither fable-engine nor
pip install fable-engine writes instructions into a workspace on its own.
How it works
- Think — Time-locked deliberation. The agent cannot write until the timer ends.
- Prove — Claims need real evidence (tool receipts, hashes, invariants).
- Attack — A red-team swarm tries to break the code.
- Write — Only then is the workspace unlocked.
Optional: AI evidence adjudicator
The evidence in a session is written by an AI agent, so Fable can optionally
ask an external reviewer model to audit that evidence before the workspace
unlocks. Stdlib-only, one bounded HTTPS call, no local model, no extra RAM to
speak of. Off by default; fail-closed when enforcing. It raises the cost of
fabricated proof - it cannot guarantee deception is impossible, and the
mechanical gates stay the primary authority. Setup and honest limits:
AI evidence adjudicator.
What it is not
- Not a claim of flawless code. It is a checkable workflow, not a guarantee.
- Not a bigger prompt. The locks are enforced by the engine, not by wording.
- Not a framework lock-in. It speaks MCP and runs beside your current agent.
Docs
Contributing
Issues and pull requests are welcome. See CONTRIBUTING.md.
MIT License · Built by REX