PRAE for GitHub Copilot’s agent, through MCP.

In part

In agent mode, GitHub Copilot can call tools from the MCP servers its editor is configured with. PRAE’s MCP server can be one of them, so file access routed through it is judged before contents return.

Serves: Developer agents →

  1. 01 · Where the agent operates

    GitHub Copilot

  2. 02 · What it can reach

    The repository in the editor, the terminal, and the MCP servers its editor is configured with.

  3. 03 · Where PRAE intervenes

    At PRAE’s MCP server: file reads routed through it are judged before contents return.

04 · What PRAE does: Evaluate → Enforce → Steer → Prove

  1. Evaluate

    Each file read the agent routes through PRAE’s MCP server is judged against your pack before it runs.

  2. Enforce

    A refused read returns nothing: the file’s contents never reach the model, and the agent is told why.

  3. Steer

    Not on this surface yet.

  4. Prove

    Every decision is sealed in the hash-chained, signed ledger, with the rule that produced it.

05 · What you get, and how it plugs in

  1. Register PRAE’s MCP server in the editor npx -p prae-cli prae mcp --root <workspace> --pack <policy.json> --ledger <decisions.jsonl>

File reads and listings routed through PRAE’s MCP server.

Copilot’s own built-in tools are not intercepted, and its instruction files are not read yet. Not yet validated end to end with Copilot.