# Chimera

> Updated 2026-09-27 · type: tool · category: mcp-agents · status: active · rev 1

Chimera is a local-first workspace where agents propose actions classified auto, confirm, or blocked, each logged to a tamper-evident audit chain.

- Open source: yes (Apache-2.0)
- Self-hostable: yes
- Pricing model: free
- Best for: A single operator running agents (Codex, Claude Code, Bedrock, OpenRouter) who wants bounded delegation — high-impact actions need explicit confirmation, everything stays auditable — plus a live view of the agent's browser tabs to take over mid-task, all local.
- Last verified: 2026-09-27

- **Canonical:** https://gtmstacker.com/registry/tool/chimera/
- **Source:** [rodkend78 · GitHub](https://github.com/rodkend78/chimera)
- **Tags:** mcp-agents, agent-security, human-in-the-loop, audit-log, self-hostable, typescript
- **Repository:** https://github.com/rodkend78/chimera

## Is Chimera open source?

Yes, Chimera is open source under the Apache-2.0 license.

## How much does Chimera cost?

Chimera is free to use.

## Can I self-host Chimera?

Yes, Chimera can be self-hosted (the source is available under the Apache-2.0 license).

## Alternatives & related

- [Provenance Gate](https://gtmstacker.com/registry/tool/provenance-gate/)
- [Agent Governance Toolkit](https://gtmstacker.com/registry/tool/agent-governance-toolkit/)


---

Chimera is a local-first workspace where AI agents propose actions classified auto, confirm, or blocked, with every decision written to a tamper-evident audit chain. Open source: yes (Apache-2.0); self-hostable; pricing free. It is model-independent (Codex, Claude Code, Bedrock, OpenRouter) and ships as a source beta.

## What it does

Chimera puts a human between an agent's intent and its consequences. Every action an agent wants to take is classified into one of three lanes — auto (proceed), confirm (wait for the operator), or blocked — so nothing high-impact happens without explicit say-so, and each decision is recorded in a tamper-evident audit chain you can replay to see exactly what happened and why. It is model-independent (bring your own: Codex, Claude Code, Bedrock, OpenRouter), runs fully local on macOS or Linux, and includes a Chromium workspace where you can watch the agent's tabs live and take over mid-task. The codebase is real — TypeScript with a React/Vite frontend, a Python worker, Playwright integration, and a test suite. Open source: yes (Apache-2.0); self-hostable; pricing free.

## Provenance

- Apache-2.0 per repo; 1 star; Node 22.19.0+, TypeScript + React/Vite + Python worker + Playwright; documented API and security models; actions classified auto/confirm/blocked into a tamper-evident audit chain; model-independent; runs fully local; self-described source beta, not production-ready (WebFetch 2026-09-27).
- Surfaced via arbitrage_x viral-post tracking (2026-09-27 pass, @rodkendrick), then verified at the primary repo.
- Part of a cluster of agent-guardrail drops this pass — see provenance-gate (deterministic tool-call gating) and browser-session-ctl (bounded live-browser control).
- Curated from the GTM Stacker signal registry (2026-09-27 pass); license/facts independently verified 2026-09-27.

## Why it matters for a GTM stack

As agents take on real GTM actions — updating records, sending outreach, changing spend — the governing question becomes "what is this agent allowed to do on its own, and can I prove what it did." Chimera answers both in one place: a per-action auto/confirm/blocked policy for bounded delegation, plus an audit chain for accountability, with a live Chromium view so you can intervene before a bad action lands. Open source: yes (Apache-2.0); self-hostable; pricing free. The honest read: it is a one-star source beta by the author's own description, so the policy engine and the tamper-evidence of the audit chain are design intentions to pilot and verify, not guarantees — but the shape (bounded delegation + auditability, local, model-agnostic) is exactly the control layer agent-driven GTM work is missing.
