๐Ÿงช Closed beta โ€“ testers wanted
Agent Fettle by Nobukz Code

Check, repair and keep Windows' own defences.
A tray-resident tool that keeps Windows' built-in protection configured, repairs a broken developer environment and backs up your folders.

๐Ÿšซ What it is not

  • An antivirus (it neither detects nor removes malware)
  • An AI agent (AI output never changes a setting)
  • A tool that shouts "N problems found!" and pushes you to pay
  • Something that sits in your network path (no network driver)

โœ… What it is

  • A tool that makes sure Windows' own defences are on, and stay on
  • A repair tool for broken PATH entries, startup items and network configuration โ€“ always reversible
  • Versioned folder backups and a cleaner that deletes by kind, never your documents
  • Findings and settings never leave your PC

๐Ÿ”— How it works

๐ŸชŸ

Windows' own defences

Defender / firewall / UAC / ...

Windows does the protecting. Agent Fettle brings no engine of its own.

โ†’read-only

Agent Fettle (tray)

Checks 19 items every hour

Quietly tells you only when an item drifts from the recommendation. One notification per item per day.

โ†’your click
๐Ÿง‘โ€๐Ÿ’ป

You

Read the plan, decide to apply

Every change needs your confirmation; admin prompts are batched into one UAC.

Nothing is changed automatically. "Not verified" (could not be read) is not counted as a fault, and there is no score or threat level.

๐Ÿ›ก The 19 items it checks

Much of what commercial security suites sell as "extra layers" is already in Windows. But PUA blocking, controlled folder access, network protection and ASR rules are not enforced by default, and Windows Home has no Group Policy editor to turn them on. Agent Fettle enables them in two clicks and tells you if they get turned off again.

Antivirus
Active antivirusDefinition status
Microsoft Defender
Real-time protectionSignature ageTamper protectionPUA protectionControlled folder accessNetwork protectionASR rulesExclusions
Firewall
All three profiles
OS protections
Secure BootMemory integrity (HVCI)Smart App ControlUACSmartScreenBitLocker
Browser
Chrome Safe Browsing
Credentials
Password manager
As recommended
nothing to do
Differs
a plan is offered
Not verified
could not be read
Not applicable
this PC lacks it

๐Ÿ”ง How a repair works (only ever reversible)

  1. 1๐Ÿ”

    Detect

    Read-only. No admin rights needed.

  2. 2๐Ÿ“‹

    Show the plan

    What will change and how. Nothing is touched yet.

  3. 3๐Ÿ–ฑ

    Apply

    Your click. One UAC prompt if needed.

  4. 4๐Ÿ’พ

    Back up

    Previous values are saved first; if that fails, it stops.

  5. 5โœ…

    Change & verify

    The same check runs again to confirm the fix.

Disable or rename rather than delete. Where deletion is the only option (the cleaner), the list of files is written to disk first. If there is no result file, the outcome is reported as "unknown", never as success.

๐Ÿ“ฆ Features

๐Ÿ›ก Defence posture, kept

Records the 19 items hourly and notifies only on regressions. The four Defender features that are off by default (PUA, controlled folder access, network protection, ASR) can be enabled from the app; ASR starts in audit mode before you promote it to block.

๐Ÿ”ง Developer environment repair

33 checks: PATH entries that no longer exist, Scripts folders whose interpreter is gone, startup items and services without a binary, ghost network profiles, disabled adapter bindings. Repairs follow the flow above.

๐Ÿ’พ Folder backups

Differential ZIPs plus a monthly full, with generations. Destinations: local, NAS (UNC), or the Google Drive / OneDrive desktop folders. Nothing at the destination is ever deleted or overwritten. Comes with a developer preset (AI tool chat history, editor settings, shell profiles).

๐Ÿšซ Blocklist

Blocks malvertising and unwanted domains through the Chrome / Edge URLBlocklist policy โ€“ no extension, nothing in the network path. Exports for uBlock Origin too.

๐Ÿงน Cleaner

Recycle Bin, temp files, crash dumps, browser caches, Windows Update leftovers and dev-tool caches, deleted by kind after you tick them. Documents, Downloads and Desktop are never counted.

๐Ÿค– Local LLM (optional)

A model running on your PC (Qwen2.5 1.5B / 7B) explains findings, verifies repair results and helps triage symptoms. Nothing is sent out, AI output never changes a setting, and a validation layer rejects made-up item IDs.

๐Ÿ”’ What leaves your PC โ€“ and what doesn't

Never

Findings, settings, backup contents

Everything stays in %LOCALAPPDATA%\AgentFettle

Never

Usage data / telemetry

There is no code path to send it. No local port is opened either.

Only if you choose

The download request for an LLM model

Fetched from Hugging Face and verified by SHA-256. Nothing about your PC is sent.

โœ… Requirements

  • Windows 10 22H2 (build 19041+) / Windows 11, 64-bit
  • WebView2 runtime (the app tells you if it is missing)
  • One resident process, 55โ€“80 MB. Admin rights only when applying a repair
  • Local LLM: a few GB of disk; a GPU helps but is not required
  • Cannot start on PCs where Smart App Control is ON (the app is unsigned)
  • UI in English and Japanese (follows the Windows display language; switchable)

๐Ÿ’ณ Licence (planned)

One-time payments, no auto-renewal. 14-day free trial after install.

Monthlyยฅ300 / 30 days
Annualยฅ2,800 / year
Permanentยฅ6,000 / one-off
Apply as a beta tester

Beta testers get a one-year licence for free. Purchase opens with the public release.

โš ๏ธ Please note

  • No code-signing certificate is used. SmartScreen warns on first run ("More info" โ†’ "Run anyway"). The SHA-256 of every build is published so you can verify the download.
  • Malware detection and removal are done by Microsoft Defender. Agent Fettle is a tool for checking and keeping its configuration.
  • Repairs change settings, PATH and the registry. Always read the plan before applying; previous values are saved and can be restored.