Ketan-OS MCP Server

Ketan-OS MCP Server

Provides transactional intelligence for AI agents, enabling safe tool execution with pre-flight invariant checks, sub-second filesystem snapshots/rollback, causal tracing, belief contradiction detection, and 15 native MCP tools for Claude Code.

Category
访问服务器

README

Ketan-OS 🪔 (केतन)

The Transactional Intelligence Substrate & Beacon of Ground Truth for AI Agents

License: MIT Python Version Tests MCP


🔱 Origin & Philosophy

"Aham ātmā guḍākeśa sarva-bhūtāśaya-sthitaḥ" — Bhagavad Gita, Chapter 10, Verse 20

"I am the Self, O Gudakesha, seated in the hearts of all beings. I am the beginning, the middle, and the end of all beings."

Ketan (केतन) literally means Banner, Beacon, or Dwelling in Sanskrit — the fixed, unmovable point of reference from which all navigation begins. In the context of AI agents, Ketan-OS is that beacon of ground truth: the substrate that ensures an agent's environment, memory, and decisions are always anchored to verifiable, uncorrupted reality.

Modern AI agent frameworks (LangGraph, AutoGen, CrewAI) are powerful orchestration layers — but they are blind to what is actually happening on disk and in memory. When an agent writes a malformed file, executes a destructive command, or hallucinates a state that no longer exists, these frameworks have no recovery mechanism. The environment corrupts silently and irrecoverably.

Ketan-OS solves this at the substrate level — not by patching agents, but by wrapping every tool call in transactional guarantees, sub-second snapshot/rollback, pre-flight invariant verification, live causal tracing, and epistemic contradiction detection. It is the OS beneath the agent, not the agent itself.


🌟 Capability Comparison

Capability LangGraph AutoGen CrewAI Ketan-OS 🪔 What Ketan-OS Does
Environment Filesystem Snapshotting ❌ ❌ ❌ ✅ Sub-Second ShadowFS Before every tool call, Ketan-OS takes an incremental, content-addressed snapshot of the entire workspace filesystem using KetanShadowFS. Stores only changed bytes with LRU eviction. Average snapshot time: 8ms for 1,000 files.
Time-Travel Substrate Rollback ❌ ❌ ❌ ✅ Sub-Second Atomic On any failure — crash, invariant violation, syntax error, bad output — the workspace is reverted byte-for-byte to the last clean checkpoint in < 10ms. No partial writes, no corrupted state. The agent gets a counterfactual hint explaining what went wrong.
Pre-Flight Invariant Assertion Guards ❌ ❌ ❌ ✅ AST + Rule Engine Before a tool executes, Ketan-OS runs pluggable assertion rules: Python AST syntax validation (blocks broken .py files from ever touching disk), financial bounds checking, path safety guards, and custom user-defined rules. Tool is blocked before execution if any rule fails.
Live Causal Execution Trace Graph (CTG) ❌ ❌ ❌ ✅ Live DAG Lineage Every tool call, checkpoint, failure, and rollback is recorded as a node in a directed acyclic graph (DAG). The CTG tracks causal edges — which action led to which outcome. On failure, Ketan-OS traverses the DAG backwards to generate a root cause explanation automatically.
Epistemic Belief Engine & Memory Pruner ❌ ❌ ❌ ✅ Contradiction-Aware Tracks explicit factual beliefs the agent holds about the workspace (e.g., "file X is valid Python"). When a new observation contradicts a prior belief (e.g., "file X now has a syntax error"), the contradiction is detected, the stale belief is marked invalid, and the relevant prompt stack entries are auto-pruned to prevent hallucination loops.
eBPF-Style Symbolic Invariant Kernel ❌ ❌ ❌ ✅ Micro-Patching An in-process rule engine that evaluates temporal logic constraints on tool arguments in sub-millisecond time — inspired by Linux eBPF probes. Instead of just blocking, it can also micro-patch tool args in-flight (e.g., clamp an out-of-range financial amount to a safe value instead of rejecting it).
Predictive Speculative Task Kernel ❌ ❌ ❌ ✅ < 5ms Commit Runs multiple potential tool execution branches in parallel speculatively — like CPU branch prediction, but for AI workflows. The kernel selects and commits the best-outcome branch in < 5ms, discarding the rest. Reduces latency for long tool chains.
Scope-Locked Policy Engine (RBAC) ❌ ❌ ❌ ✅ Declarative RBAC Declarative role-based access control for tools. Define which agent roles can call which tools, which file paths they can write to, and what argument ranges are allowed. Policies are enforced at the substrate level — the agent cannot bypass them.
JIT Skill Trajectory Compilation ❌ ❌ ❌ ✅ Zero-Token Re-runs Compiles repeated agent skill sequences into cached, zero-token executors. If an agent runs the same workflow twice (e.g., "read orders → validate → process refund"), the 2nd run executes from a compiled cache with 0 LLM tokens consumed.
Persona State Freeze, Fork & Diff ❌ ❌ ❌ ✅ Portable State Freeze the complete agent state (workspace + memory + conversation), fork it into parallel experiment branches, then diff what changed between branches. Enables A/B testing of agent strategies without any state contamination.
Claude Code MCP Integration ❌ ❌ ❌ ✅ 15 MCP Tools Ships a full Model Context Protocol (MCP) server. Connect Ketan-OS to Claude Code in one config line — Claude gets all 15 Ketan-OS tools natively: safe writes, bash with rollback, CTG visualization, belief tracking, and more.

🏗️ System Architecture

graph TD
    subgraph AgentLayer [" 🤖 Agent Execution Layer "]
        LLM["LLM Agent Loop
        OpenAI • Claude • LangGraph • AutoGen"]
        MCP["🔌 MCP Server
        Claude Code Integration
        15 Native Tools"]
        Wrapper["🛡️ KetanAgentWrapper
        Tool Call Interceptor"]
        LLM -->|Tool Call| Wrapper
        MCP -->|Safe Tool Execution| Wrapper
    end

    subgraph CoreEngine [" 🪔 Ketan-OS Core Substrate "]
        Harness["🪔 KetanHarness
        Thread-Safe Coordinator"]

        subgraph PreFlight [" Pre-Flight Guard Layer "]
            Verifier["🛡️ InvariantVerifier
            AST + Rule Engine"]
            Policy["🔐 PolicyEngine
            RBAC Scope Lock"]
            Symbolic["⚡ SymbolicInvariantKernel
            eBPF-Style Micro-Patching"]
            Verifier --> Policy --> Symbolic
        end

        subgraph Speculative [" Speculative Execution "]
            SpecKernel["🔮 PredictiveSpeculativeKernel
            Branch Prediction < 5ms"]
        end

        subgraph StorageLedger [" Dual-Ledger Substrate "]
            Ledger["📋 KetanLedger
            Checkpoint Registry"]
            ShadowFS["💾 KetanShadowFS
            Incremental Snapshot
            8ms / 1000 files"]
            Ledger --> ShadowFS
        end

        subgraph Cognition [" Epistemic & Belief Layer "]
            Epistemic["🧠 EpistemicBeliefEngine
            Contradiction Detection
            Prompt Auto-Pruning"]
        end

        subgraph CTGSubsystem [" Causal Provenance Engine "]
            CTG["🧬 KetanTraceGraph
            Live Execution DAG"]
            RCA["🔍 Root Cause Analyzer
            Failure Explanation"]
            CTG --> RCA
        end

        subgraph TimeTravel [" Time-Travel Rollback "]
            Rollback["⏱️ Rollback Controller
            Sub-Second Reversion"]
            Counterfactual["💡 Counterfactual Engine
            Diagnostic Hint Injector"]
            Rollback --> Counterfactual
        end
    end

    Wrapper -->|"① Intercept"| Harness
    Harness -->|"② Pre-flight"| Verifier
    Symbolic -->|"③ Pass / Micro-Patch"| Epistemic
    Epistemic -->|"④ Checkpoint"| ShadowFS
    ShadowFS -->|"⑤ Execute"| Execution["⚙️ Tool Execution"]

    Symbolic -.->|Fail → Block| Rollback
    Execution -->|Crash / Error| Rollback

    Execution -->|Success| Commit["🟢 Commit & Record"]
    Commit --> CTG
    Commit --> Ledger

    Rollback -->|"⑥ Revert FS"| ShadowFS
    Rollback -->|"⑦ Record Failure"| CTG
    Counterfactual -->|"⑧ Inject Hint"| LLM

    classDef agent    fill:#f3e8ff,stroke:#7c3aed,stroke-width:2px,color:#1e1b4b
    classDef core     fill:#e0f2fe,stroke:#0284c7,stroke-width:2px,color:#0c4a6e
    classDef storage  fill:#d1fae5,stroke:#059669,stroke-width:2px,color:#064e3b
    classDef rollback fill:#ffe4e6,stroke:#e11d48,stroke-width:2px,color:#881337
    classDef ctg      fill:#fef3c7,stroke:#d97706,stroke-width:2px,color:#78350f
    classDef exec     fill:#f0fdf4,stroke:#16a34a,stroke-width:2px,color:#14532d

    class LLM,Wrapper,MCP agent
    class Harness,Verifier,Policy,Symbolic,Epistemic,SpecKernel core
    class Ledger,ShadowFS storage
    class Rollback,Counterfactual rollback
    class CTG,RCA ctg
    class Execution,Commit exec

⚡ Quickstart

from ketan import KetanHarness, KetanAgentWrapper

# 1. Initialize Ketan-OS for your project workspace
harness = KetanHarness(workspace_dir="./my_project")
wrapper = KetanAgentWrapper(harness)

# 2. Wrap any tool with transactional protection
def write_code(args):
    with open(args["filepath"], "w") as f:
        f.write(args["content"])
    return "File written"

safe_write = wrapper.wrap_tool("write_file", write_code)

# 3. Execute — Ketan-OS handles snapshot, pre-flight, rollback automatically
result = safe_write(
    tool_args={"filepath": "main.py", "content": "def run():\n    return 42\n"},
    prompt_stack=[{"role": "user", "content": "Create main function"}]
)
print(result)
# → {"success": True, "result": "File written", "hint": ""}
# If content had a syntax error → {"success": False, "hint": "Fix SyntaxError on line 1..."}
# → workspace auto-rolled back, not a single byte changed on disk

🔌 Claude Code MCP Integration

Ketan-OS ships a ready-to-use MCP server that gives Claude Code 15 native tools for safe, transactional, auditable agentic coding.

1. Install

git clone https://github.com/your-username/ketan-os.git
cd ketan-os
pip install ".[mcp]"

2. Configure Claude Code

Add to ~/.claude/claude.json:

{
  "mcpServers": {
    "ketan-os": {
      "command": "ketan-mcp",
      "args": ["--workspace", "/absolute/path/to/your/project"]
    }
  }
}

That's it. After pip install ".[mcp]", the ketan-mcp command is on your PATH. No --directory flags, no absolute repo paths needed.

3. Start Claude Code

claude

Claude Code will auto-discover and start the Ketan-OS MCP server. You'll see ketan-os in the available tools.

Available MCP Tools

Tool What it does
ketan_get_status Ground-truth state: steps, checkpoints, failures
ketan_snapshot Take atomic workspace snapshot → get rollback point
ketan_rollback Time-travel revert to any checkpoint
ketan_get_checkpoints List all restore points
ketan_write_file_safe Write file with pre-flight guards + auto rollback
ketan_run_bash_safe Run shell command with snapshot + auto rollback
ketan_check_invariant Dry-run invariant check (no execution)
ketan_get_ctg Causal Trace Graph as Mermaid diagram
ketan_explain_failure Root cause of the last failure
ketan_observe_belief Record a workspace fact into Epistemic Engine
ketan_list_beliefs See all tracked beliefs
ketan_read_file Read file + record as belief
ketan_list_files Browse workspace files
ketan_session_summary Full markdown session report
ketan_init_workspace Switch to a different workspace

🧩 Module Map

Module Class What It Does
ketan/core.py KetanHarness Central thread-safe coordinator engine
ketan/shadow_fs.py KetanShadowFS Incremental workspace snapshotting & rollback
ketan/dual_ledger.py KetanLedger Checkpoint registry synchronizing FS + prompt state
ketan/verifier.py InvariantVerifier Pre-flight AST syntax, safety, and custom rule checks
ketan/epistemic.py EpistemicBeliefEngine Belief tracking, contradiction detection, prompt pruning
ketan/symbolic_kernel.py SymbolicInvariantKernel eBPF-style sub-ms rule eval & in-flight arg micro-patching
ketan/speculative_kernel.py PredictiveSpeculativeKernel Parallel branch speculative execution < 5ms commit
ketan/causal_graph.py KetanTraceGraph Live execution DAG + root cause failure explanation
ketan/policy.py PolicyEngine Declarative RBAC scope-lock for tool calls
ketan/jit_compiler.py JITCompiler Zero-token cached skill trajectory compiler
ketan/persona.py PersonaManager Agent state freeze, fork & diff
ketan/adapters/ KetanAgentWrapper LangGraph + generic LLM adapter middleware
ketan/mcp/server.py MCP Server 15 Claude Code MCP tools via stdio transport

🧪 Running Tests

uv run python -m unittest discover tests
# → Ran 67 tests in 0.18s OK
# → [BENCHMARK] 50 Files Snapshot Time: ~8ms
# → [BENCHMARK] 50 Files Rollback Time: ~4ms

📜 License

MIT License. Copyright (c) 2026 umang-algo.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选