mirror of
https://github.com/samvallad33/vestige.git
synced 2026-07-24 23:41:01 +02:00
Add the firewall causal slice so a poisoned/injected memory is screened, quarantined, and proven held-out on the receipt (influence_allowed=false): - screen_write() detector (neuroscience/microglial_firewall.rs): deterministic prompt-injection / exfiltration / poisoning screen with NFKC + homoglyph folding and word-boundary matching to avoid false quarantines. - Receipt gains quarantined[] / influence_allowed / engram_phases (additive, serde-default, back-compatible with old receipts). - New trace events memory.quarantine + episode.boundary (mirror the TS union). - gate_writes() now screens every write and, on a quarantine verdict, suppresses the node (held out of retrieval) + records the quarantine receipt + events, so influence_allowed=false is ENFORCED, not cosmetic. Content capped at 16KB. - VestigeEvent::MemoryQuarantined live broadcast. Verified: cargo test vestige-core/vestige-mcp green, clippy -D warnings clean, integration test proves a screened injection is absent from the write's retrieval. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
Vestige MCP Server
Local cognitive memory for MCP-compatible AI agents.
This crate provides the vestige-mcp stdio MCP server plus the vestige CLI.
The cognitive engine lives in vestige-core; this crate owns protocol handling,
tool dispatch, optional dashboard serving, backups, restore, update, and
portable import/export commands.
Install
For normal users, prefer the release package:
npm install -g vestige-mcp-server
For local development:
cargo build --release -p vestige-mcp
Register With An MCP Client
Use the command vestige-mcp in any stdio MCP client:
{
"mcpServers": {
"vestige": {
"command": "vestige-mcp"
}
}
}
Examples:
claude mcp add vestige vestige-mcp -s user
codex mcp add vestige -- vestige-mcp
Transports
- Default: JSON-RPC 2.0 over stdio.
- Optional: MCP-over-HTTP on
/mcp, enabled only with--http,--http-port, orVESTIGE_HTTP_ENABLED=1. - Dashboard:
vestige dashboardorVESTIGE_DASHBOARD_ENABLED=1.
HTTP and dashboard bearer tokens are generated locally; see
docs/CONFIGURATION.md.
Current Tool Surface
The server exposes the current unified MCP tools from
src/server.rs, including:
session_contextsearch,smart_ingest,memory,codebase,intentiondeep_reference,cross_reference,contradictionsdream,explore_connections,predictmemory_health,memory_graph,composed_graph,system_statusimportance_score,find_duplicatesconsolidate,memory_timeline,memory_changelogbackup,export,restore,gc,suppress
See the root README.md and
docs/AGENT-MEMORY-PROTOCOL.md for
agent instructions.
License
AGPL-3.0-only