tuff

Manage capabilities.Use them across harnesses.Ship them with your agent.Govern them everywhere.

uv tool install tuffcli
brew, pip, cargo, and script installs
support-agentgithub.com/acme/agents · apps/support-agent
1 manageGather capabilities from your repo, git, the MCP catalog, and packs.
2 use across harnesses

Tuff writes each capability in the format each coding agent reads, and records it once in tuff.lock.

  • Claude Code
  • Codex
  • Cursor
  • OpenCode
tuff.lockone record for all of them
3 ship with your agent

Tuff packs them into one versioned bundle that goes into the agent’s image and runs on an agent SDK.

support-agent 1.4.0sha256:9f2c…e41a
  • Claude Agent SDK
  • your own runtime
tuff console publish
4 govern & observeSee what every project runs, what drifted, and which rules are not enforced.
12projects
86capabilities
2drifted
1policy gap
  • linear added to support-agent3f2c9e1
  • pack support-agent 1.3.0 → 1.4.01m ago
  • ticket-triage edited in billing-agent12m ago

The capabilities Tuff manages, and their lifecycle

Skills, tools, MCP servers, hooks, and policies are files in your project. Tuff records what is installed, where it came from, and whether it changed.

//capabilities
//lifecycle
01Create or add

Start a new skill, tool, hook, MCP server, or policy, or bring existing agent files under management without rewriting their content.

02Track

Record source, version, scope, harness, emitted path, and the clean install baseline in project state.

03Diff

Compare the current files against the baseline so intentional edits are visible and accidental drift is not silent.

04Update or check

Accept deliberate local changes, merge upstream updates where possible, and fail CI when tracked capabilities are not in the expected state.

//stateEverything lives in your repo

Tuff works like a package manager for agent capabilities, with a lockfile in your repo. Commit it and the whole team gets the same setup. No hosted service.

//sourcesInstall from sources you trust

A local directory, a Git repository, an OCI registry, or the built-in MCP catalog, with the origin recorded either way.

//scopesProject scope wins

Capabilities can be project-scoped or global. When both define the same one, the version checked into the repo takes precedence.

Every agent’s capabilities, across the organisation

Projects publish a report from CI. Tuff Console, which your team runs on its own server, shows each agent’s skills, tools, MCP servers, hooks, and policies, which harness runs them, what changed, and in which commit. GitHub Actions publishes without a secret; other CI uses an API key.

Tuff Console
A working preview with sample data. Open Projects, Capabilities, Policies, or Audit to look around. Run your own with tuff console serve --demo. Console docs · Self-hosting guide

Bundle once. Ship as a verified release.

Bundle the skills, tools, hooks, and MCP servers behind an integration into one deterministic artifact. Publish it through OCI, pin it by digest, and deploy the same reviewed bundle to every agent runtime.

CRM capabilities
  • CRM operatingskill
  • CRM connectorMCP tool
  • PII guardhook
  • Lead scoringtool
Tuff pack
yourorg/crm-integration:1.2.0crm-integration.tuffpack
sha25684a1c7e9…2f40
4 capabilities2 targetsverified ✓
OCI registry
yourorg/crm-integration:1.2.0digest pinned
signedattestedpolicy approved
Agent runtime
Runtime filesystem

Harness-native files, extracted from the exact reviewed artifact.

  • .agents/skills/
  • .mcp.json
  • .agents/hooks/
Explore Tuff Packs

Write once, emit per harness

Write a capability once in tuff.toml. Tuff turns it into the file each agent reads, in that agent's own format.

tuff.toml
id = "lint-before-tools"
type = "hook"
[hook]
event = "pre_tool_use"
command = "npm run lint"
tuff add
claude.claude/settings.json"PreToolUse" → sh .claude/hooks/lint-before-tools/run.sh
cursor.cursor/hooks.json"preToolUse" → sh .cursor/hooks/lint-before-tools/run.sh

Operational Features

The parts that matter after day one.

01CI Integration

Run the check in CI and fail the build on drift, not after it's already shipped.

GitHub Actions
02Tuff Skills

Tuff ships as a skill itself. The agent learns the CLI and hook spec on install, so it writes manifests and runs commands for you instead of you doing it by hand.

tuff init
03Audit Reports

Generate a full report of every installed capability, its source, and its policy status, right from the CLI, no hosted service required.

tuff generate report