
BoteX is an agent-agnostic, MCP-native execution harness for autonomous code-editing subagents. Any MCP-compatible client (IDE agents, desktop assistants, orchestrators) can delegate multi-step coding tasks to it.
BoteX is an execution harness for AI coding agents. It is a guardrail harness designed specifically for autonomous code-editing agents, sitting between an MCP client and a codebase to enforce deterministic safeguards before code touches disk. It exposes a focused set of MCP tools for task execution, workspace memory, diagnostics, and utility operations. BoteX wraps agent actions in safety gates. These include outline-first inspection, a read-before-write gate, pre-write syntax validation, multi-tier fuzzy patching, automatic snapshot rollback, hard budget and pricing caps, and strict privacy and Zero Data Retention enforcement. Every delegated task follows a contract-driven lifecycle, and a task returns ok: true only when completion is verified on disk. Permissions follow the principle of least privilege through modes such as readonly, edit, destructive, and full. Command execution is disabled by default and guarded by a binary allowlist, deny rules, an isolated environment, and timeouts. Model fallbacks can switch to alternative models if a model refuses a task, burns its token limit without output, or hits provider rate limits.