Cruxible Core
About
Cruxible Core is a deterministic, typed state layer for AI agents and human teams to operate on verifiable, governed domain state. It models entity and relationship types, write rules, and recurring workflows in a Terraform-like config, and the runtime enforces them. The core…
Details
- License
- Apache-2.0
Explore
- Deterministic ingest: state enters row by row from pinned artifacts.
- Governed writes: proposal flow with declared evidence and human review.
- Executable model: declared workflows are previewable, replayable, and versioned.
- Reproducible reads: same query, same state, same result with a receipt.
- No LLM inside: core is a pure deterministic layer, works with any agent.
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Cruxible CoreCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
pip install cruxible already includes the Python client
(import cruxible_client); add the [mcp] extra for the cruxible-mcp
entrypoint. Nothing else is needed when the agent shares the daemon's
environment.
Mint each agent its own credential (as in Get Started) so every write is
attributed to a token, and for stronger isolation prefer a split
environment: the daemon runs in its own environment, and the agent's
environment installs only the slim client — no runtime, no direct
access to state files:
pip install cruxible-client # agent environment only; ~2 dependencies
- CRUXIBLE_REQUIRE_SERVER=1 keeps the agent on the daemon path.
- CRUXIBLE_SERVER_STATE_DIR lives outside the agent's writable workspace.
MCP example:
{
"mcpServers": {
"cruxible": {
"command": "cruxible-mcp",
"env": {
"CRUXIBLE_MODE": "governed_write",
"CRUXIBLE_SERVER_URL": "http://127.0.0.1:8100",
"CRUXIBLE_SERVER_BEARER_TOKEN": "<agent-token>"
}
}
}
}
CRUXIBLE_MODE selects one of four cumulative permission tiers —
read_only, governed_write, graph_write, admin — and denied calls name
the tier they need. Give an agent the lowest tier that does its job:
governed_write (above) can run workflows, propose, and record feedback,
but cannot mutate the raw graph or resolve proposals.
Local permission modes are a practical hardening layer, not full sandboxing. If
trust levels matter, keep the daemon state outside the agent workspace and
expose only the client, HTTP, or MCP surface. See
Isolated Deployment.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"cruxible core": {
"cruxible": {
"command": "cruxible-mcp",
"env": {
"CRUXIBLE_MODE": "admin"
}
}
}
}
}
McpServers
{
"cruxible": {
"command": "cruxible-mcp",
"env": {
"CRUXIBLE_MODE": "admin"
}
}
}
Cruxible is hard state for AI agents — a typed, verifiable state layer
that teams of agents and humans operate together. Work compounds into a
record of what you've determined to be true: every claim reviewed and linked
to its evidence. When the expensive question arrives (which assets are
exposed? what breaks downstream? is this authority still good law?), the
answer is computed over established truth, not guessed from a pile of
context.
You model your domain in a Terraform-like config: entity and relationship
types, deterministic workflows, write rules. The runtime enforces it.
<p align="center">
</p>
- State enters deterministically. Exports and tables from real systems
are pinned as artifacts and matched row by row into proposals; model
judgment is injected only where your pinned domain logic can't decide.
- Writes are governed. Governed relationships can only be written through
a proposal flow that requires declared evidence, auto-resolves only under
trust rules you set, and routes everything else to human review. Every
accepted claim is attributed and carries a receipt.
- The model is executable. Recurring procedures are declared workflows in
the same config: previewed before they apply, locked to the exact provider
code and artifacts they compile against, replayable from receipts. State
accumulates as the exhaust of governed work, and the model improves
iteratively: feedback and outcomes are recorded in state, and the config
evolves like code.
- Reads are reproducible. Same query, same state, same result, with a
receipt explaining how it was derived. Queries express structure that
retrieval can't: multi-hop traversals, review status, staleness against
cited sources.
- The core is deterministic. No LLM inside, no hidden API calls. It works
with any agent or harness, points at your existing systems, and mints into
state only the claims worth coordinating around.
Get Started
pip install cruxible
Model your own domain: hand your agent the authoring skills in
skills/
(prepare-data → create-state → review-state) with your exports
(wiki-to-state converts an existing CLAUDE.md pile or Obsidian vault), or
start from Modeling State
and the config template.
Or run the demo — a seeded supply-chain world, ~3 minutes, no tokens
(sandbox writes attribute to a built-in operator identity):
```bash
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



