PRAE for the agent in Windsurf.

In part

Windsurf’s agent works across the repository, the terminal and its MCP servers. Today PRAE governs the file access you route through its MCP server, and reads the .windsurfrules it follows as proposed policy.

Serves: Developer agents →

  1. 01 · Where the agent operates

    Windsurf

  2. 02 · What it can reach

    The repository and files on the developer’s machine, the terminal, and its configured MCP servers.

  3. 03 · Where PRAE intervenes

    At PRAE’s MCP server: file reads routed through it are judged before contents return.

04 · What PRAE does: Evaluate → Enforce → Steer → Prove

  1. Evaluate

    Each file read the agent routes through PRAE’s MCP server is judged against your pack before it runs. The .windsurfrules it follows is read and proposed as rules you review.

  2. Enforce

    A refused read returns nothing: the file’s contents never reach the model, and the agent is told why.

  3. Steer

    Not on this surface yet.

  4. Prove

    Every decision is sealed in the hash-chained, signed ledger, with the rule that produced it.

05 · What you get, and how it plugs in

  1. Register PRAE’s MCP server in Windsurf npx -p prae-cli prae mcp --root <workspace> --pack <policy.json> --ledger <decisions.jsonl>
  2. Read the rules it follows prae instructions . && prae propose .

File reads and listings routed through PRAE’s MCP server; .windsurfrules read and proposed as rules.

Windsurf’s own built-in tools are not intercepted yet; that is on the roadmap.