mirror of
https://github.com/samvallad33/vestige.git
synced 2026-07-02 22:01:01 +02:00
Second swarm pass (complete every-line sweep), verified against real code (38/101 confirmed real; 63 false positives excluded). This commit lands the main-compatible subset: - redmine SSRF guard: rewrite host check to use host_str()+std::net::IpAddr instead of the `url` crate (url is not a direct dep of vestige-core on main; the previous form only compiled on the feature branch). Same protection: blocks localhost + loopback/private/link-local/unspecified IPs. - bin/restore: guard wrapper[0] index (empty backup array would panic) - bin/cli: char-boundary-safe node.id truncation (2 byte-slice panics); XML-escape the model/home strings before launchd plist substitution - prospective_memory: Duration::try_hours/try_days (panic on out-of-range user config); case-insensitive " at " split now uses the lowercased index so the contains() check and the split agree core 477/0, mcp builds, clippy clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
Vestige MCP Server
Local cognitive memory for MCP-compatible AI agents.
This crate provides the vestige-mcp stdio MCP server plus the vestige CLI.
The cognitive engine lives in vestige-core; this crate owns protocol handling,
tool dispatch, optional dashboard serving, backups, restore, update, and
portable import/export commands.
Install
For normal users, prefer the release package:
npm install -g vestige-mcp-server
For local development:
cargo build --release -p vestige-mcp
Register With An MCP Client
Use the command vestige-mcp in any stdio MCP client:
{
"mcpServers": {
"vestige": {
"command": "vestige-mcp"
}
}
}
Examples:
claude mcp add vestige vestige-mcp -s user
codex mcp add vestige -- vestige-mcp
Transports
- Default: JSON-RPC 2.0 over stdio.
- Optional: MCP-over-HTTP on
/mcp, enabled only with--http,--http-port, orVESTIGE_HTTP_ENABLED=1. - Dashboard:
vestige dashboardorVESTIGE_DASHBOARD_ENABLED=1.
HTTP and dashboard bearer tokens are generated locally; see
docs/CONFIGURATION.md.
Current Tool Surface
The server exposes the current unified MCP tools from
src/server.rs, including:
session_contextsearch,smart_ingest,memory,codebase,intentiondeep_reference,cross_reference,contradictionsdream,explore_connections,predictmemory_health,memory_graph,composed_graph,system_statusimportance_score,find_duplicatesconsolidate,memory_timeline,memory_changelogbackup,export,restore,gc,suppress
See the root README.md and
docs/AGENT-MEMORY-PROTOCOL.md for
agent instructions.
License
AGPL-3.0-only