1. Select Your Agent Harness (16 Supported)
Choose your editor, terminal CLI, or app builder below to view the verified native MCP configuration and 1-click install command.
2. Live Prompt Security & Alternative Rewriter
Test how ThumbGate intercepts dangerous prompt patterns (OWASP API Top 10, LLM Top 10, MCP tool tampering) and proposes safe code patterns before any files are modified.
Click "Evaluate Security" to run the local policy engine.
3. The Architecture Reality: Advisory Context vs. Deterministic Firewall
Salt Code injects passive prompt rules from a remote cloud server. When an agent experiences residual stream distress, system prompts are ignored. ThumbGate operates at the execution layer.
| Architectural Pillar | Salt Code (Advisory Cloud MCP) | ThumbGate (Deterministic Local Firewall) |
|---|---|---|
| Enforcement Plane | Prompt context injection (MCP advisory prompt / .cursorrules) | Execution-time PreToolUse hook (deterministic fail-closed firewall) |
| Transport & Privacy | Remote cloud MCP server (requires work email, remote SaaS round-trip) | 100% local stdio / subshell diode (zero cloud egress, air-gap safe) |
| Cost & Latency | Bloats context window tokens + network round-trips to cloud | Zero LLM tokens for gate checks; <5ms deterministic AST/regex rail |
| Self-Improvement | Static vendor list of 40 rules | Ralph Loop + Thompson Sampling feedback-to-prevention rule synthesis |
| Runtime Defense | Advisory warning in text generation | Hard interdiction of BOLA, secret leaks, raw eval, and rogue git wipes |