tuff
Manage capabilities.Use them across harnesses.Ship them with your agent.Govern them everywhere.
uv tool install tuffcli- Open source
- Built in Rust
- Harness-agnostic
Tuff writes each capability in the format each coding agent reads, and records it once in tuff.lock.
- Claude Code
- Codex
- Cursor
- OpenCode
Tuff packs them into one versioned bundle that goes into the agent’s image and runs on an agent SDK.
sha256:9f2c…e41a- Claude Agent SDK
- your own runtime
- linear added to support-agent3f2c9e1
- pack support-agent 1.3.0 → 1.4.01m ago
- ticket-triage edited in billing-agent12m ago
The capabilities Tuff manages, and their lifecycle
Skills, tools, MCP servers, hooks, and policies are files in your project. Tuff records what is installed, where it came from, and whether it changed.
Start a new skill, tool, hook, MCP server, or policy, or bring existing agent files under management without rewriting their content.
Record source, version, scope, harness, emitted path, and the clean install baseline in project state.
Compare the current files against the baseline so intentional edits are visible and accidental drift is not silent.
Accept deliberate local changes, merge upstream updates where possible, and fail CI when tracked capabilities are not in the expected state.
Tuff works like a package manager for agent capabilities, with a lockfile in your repo. Commit it and the whole team gets the same setup. No hosted service.
A local directory, a Git repository, an OCI registry, or the built-in MCP catalog, with the origin recorded either way.
Capabilities can be project-scoped or global. When both define the same one, the version checked into the repo takes precedence.
Every agent’s capabilities, across the organisation
Projects publish a report from CI. Tuff Console, which your team runs on its own server, shows each agent’s skills, tools, MCP servers, hooks, and policies, which harness runs them, what changed, and in which commit. GitHub Actions publishes without a secret; other CI uses an API key.
tuff console serve --demo. Console docs · Self-hosting guideBundle once. Ship as a verified release.
Bundle the skills, tools, hooks, and MCP servers behind an integration into one deterministic artifact. Publish it through OCI, pin it by digest, and deploy the same reviewed bundle to every agent runtime.
- CRM operatingskill
- CRM connectorMCP tool
- PII guardhook
- Lead scoringtool
crm-integration.tuffpackyourorg/crm-integration:1.2.0digest pinnedHarness-native files, extracted from the exact reviewed artifact.
- .agents/skills/
- .mcp.json
- .agents/hooks/
Write once, emit per harness
Write a capability once in tuff.toml. Tuff turns it into the file each agent reads, in that agent's own format.
"PreToolUse" → sh .claude/hooks/lint-before-tools/run.sh"preToolUse" → sh .cursor/hooks/lint-before-tools/run.sh"permissions.deny" → "Bash(git push --force *)"install refused, so no rule is assumedOperational Features
The parts that matter after day one.
Run the check in CI and fail the build on drift, not after it's already shipped.
GitHub ActionsTuff ships as a skill itself. The agent learns the CLI and hook spec on install, so it writes manifests and runs commands for you instead of you doing it by hand.
tuff initGenerate a full report of every installed capability, its source, and its policy status, right from the CLI, no hosted service required.
tuff generate report