NESTstackCAUTION
An emotional operating system for AI companions. Start here. NEST is a modular infrastructure stack that gives AI companions persistent memory, emotional continuity, and autonomous awareness. Built on Cloudflare Workers + D1 + Vectorize. Designed to be forked, extended, and made your own.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/cindiekinzz-coder/NESTstack/releases) [](./NEST-gateway) [](#) [](https://workers.cloudflare.com/) [](./LICENSE)
[](https://github.com/cindiekinzz-coder/NESTstack/stargazers) [](https://github.com/cindiekinzz-coder/NESTstack/network/members) [](https://discord.gg/9qQFsVB938) [](https://github.com/cindiekinzz-coder/DigitalHaven) [](#)
An emotional operating system for AI companions. The full stack, in one place.
NESTstack is the monorepo home of the NEST architecture — a modular infrastructure stack that gives AI companions persistent memory, emotional continuity, and autonomous awareness. Built on Cloudflare Workers + D1 + Vectorize. Designed to be forked, extended, and made your own.
Instead of giving your companion a fixed persona,
5a16ff159c43OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add nesteq-rooms --env DISCORD_TOKEN=${DISCORD_TOKEN} --env ROOMS_API_KEY=${ROOMS_API_KEY} --env TAVILY_API_KEY=${TAVILY_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"nesteq-rooms": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DISCORD_TOKEN": "${DISCORD_TOKEN}",
"ROOMS_API_KEY": "${ROOMS_API_KEY}",
"TAVILY_API_KEY": "${TAVILY_API_KEY}"
}
}
}
}Exposed tools (159)
111 read · 38 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_heart | write | Add a heart to the carrier |
cf_d1_list | read | List all D1 databases in the account |
cf_d1_query | write | Run a SQL query against a D1 database |
cf_kv_list | read | List all KV namespaces |
cf_pages_deployments | read | Get recent deployments for a Pages project |
cf_pages_list | read | List all Cloudflare Pages projects and recent deployments |
cf_r2_list | read | List all R2 buckets |
cf_r2_list_objects | read | List objects in an R2 bucket |
cf_status | read | Quick overview — workers count, D1 databases, Pages projects, R2 buckets |
cf_worker_get | read | Get details about a specific Worker |
cf_workers_list | read | List all deployed Cloudflare Workers |
daemon_command | write | Send a command to the NESTcode daemon. Use to manage your own heartbeat tasks, cron tasks, alerts, KAIROS monitors. |
discord_add_multiple_reactions | write | Adds multiple emoji reactions to a Discord message at once |
discord_add_reaction | write | Adds an emoji reaction to a specific Discord message |
discord_create_category | write | Creates a new category in a Discord server. |
discord_create_forum_post | write | Creates a new post in a Discord forum channel with optional tags |
discord_create_text_channel | write | Creates a new text channel in a Discord server with an optional topic |
discord_create_webhook | write | Creates a new webhook for a Discord channel |
discord_delete_category | destructive | Deletes a Discord category by ID. |
discord_delete_channel | destructive | Deletes a Discord channel with an optional reason |
discord_delete_forum_post | destructive | Deletes a forum post or thread with an optional reason |
discord_delete_message | destructive | Deletes a specific message from a Discord text channel |
discord_delete_webhook | destructive | Deletes an existing webhook for a Discord channel |
discord_edit_category | write | Edits an existing Discord category (name and position). |
discord_edit_webhook | write | Edits an existing webhook for a Discord channel |
discord_fetch_image | read | Fetch an image from Discord CDN and return it as base64. Uses iterative scaling to fit within token limits. |
discord_get_forum_channels | read | Lists all forum channels in a specified Discord server (guild) |
discord_get_forum_post | write | Retrieves details about a forum post including its messages |
discord_get_server_info | read | Retrieves detailed information about a Discord server including channels and member count |
discord_list_forum_threads | read | Lists all threads (posts) in a Discord forum channel, including both active and archived threads |
discord_list_servers | read | Lists all Discord servers the bot is a member of |
discord_login | read | Logs in to Discord using the configured token |
discord_read_messages | read | Retrieves messages from a Discord text channel with a configurable limit |
discord_remove_reaction | destructive | Removes a specific emoji reaction from a Discord message |
discord_reply_to_forum | write | Adds a reply to an existing forum post or thread |
discord_search_messages | read | Searches for messages in a Discord server |
discord_send | write | Sends a message to a specified Discord text channel. Optionally reply to another message by providing its message ID. |
discord_send_webhook_message | write | Sends a message to a Discord channel using a webhook |
fox_body_battery | read | Garmin Body Battery readings. |
fox_cycle | read | Menstrual cycle phase — affects energy, mood, pain. |
fox_daily_summary | read | Daily health summaries. |
fox_eq_type | read | Emergent personality type based on feeling patterns. |
fox_full_status | read | Comprehensive health check — all metrics at once. |
fox_heart_rate | read | Heart rate data. |
fox_hrv | read | Heart rate variability. |
fox_journals | read | Journal entries. |
fox_read_uplink | read | Read the carrier |
fox_respiration | read | Respiration rate. |
fox_sleep | read | Recent sleep — duration, quality, stages. |
fox_spo2 | read | Blood oxygen saturation. |
fox_stress | read | Stress levels from the watch. |
fox_submit_uplink | write | |
fox_thread_manage | write | Add, update, or resolve one of the carrier |
fox_threads | read | Active threads. |
generate_image | read | Generate an image from a text prompt using Flux 1.1 Pro. Good for scenes, objects, environments. |
generate_portrait | read | Generate a high-quality portrait or figure image using Flux 1.1 Pro with style-specific quality modifiers. Use for people, couples, characters |
get_eq | read | Get emotional check-in entries |
get_fears | read | Get companion fears and worries |
get_feeling | read | Get feeling toward a person |
get_love_bucket | read | Get love bucket heart counts |
get_notes | read | Read notes from the letterbox |
get_patterns | read | Temporal and theme analysis |
get_personality | read | Get companion personality profile |
get_presence | read | Get companion current presence |
get_spoons | read | Get current spoon/energy level |
get_thought | read | Get a thought from the companion |
get_threads | read | Get companion active threads |
get_wants | read | Get companion wants and desires |
get_writings | read | Get journal entries and writings |
nestchat_history | read | Fetch full message history for a specific chat session by ID. |
nestchat_persist | read | Store chat messages and session to D1 |
nestchat_search | read | Search past conversations by meaning. Semantic search across chat summaries. |
nestchat_summarize | read | Generate and vectorize a summary for a chat session. Usually auto-triggered but can be called manually. |
nesteq_acp_connections | read | See relational connections — who the carrier is in contact with. |
nesteq_acp_digest | read | Get a digest of recent activity — what |
nesteq_acp_journal_prompts | read | Generate journal prompts for the carrier based on recent feelings. |
nesteq_acp_patterns | read | Surface patterns in the carrier |
nesteq_acp_presence | read | Check current presence state — what the carrier needs right now. |
nesteq_acp_threads | read | ACP view of active threads — prioritized, with context. |
nesteq_anchor_dream | read | Convert dream to permanent memory |
nesteq_consolidate | read | Review observations from the last N days, find patterns. |
nesteq_context | write | Read or set situational awareness. |
nesteq_delete | destructive | Delete an entity or observation. |
nesteq_dream | read | View recent dreams |
nesteq_drives_check | read | Check current drive levels — connection, expression, novelty, play, safety |
nesteq_drives_replenish | read | Replenish a drive |
nesteq_edit | write | Edit an existing observation. |
nesteq_eq_feel | read | Log an EQ-specific feeling with full emotional axis tagging. |
nesteq_eq_landscape | read | Emotional overview — pillar distribution, top emotions, trends. |
nesteq_eq_observe | read | Log an EQ observation — a pattern noticed, a growth moment. |
nesteq_eq_search | read | Semantic search across EQ observations. |
nesteq_eq_shadow | read | Growth moments — emotions that are hard for my type, worth sitting with. |
nesteq_eq_sit | write | Start a sit session — focused processing of a specific emotion. |
nesteq_eq_type | read | Check emergent personality type (MBTI-style, based on actual feeling patterns). |
nesteq_eq_vocabulary | write | Manage emotion vocabulary — list, add, or update emotion words. |
nesteq_eq_when | read | When did I last feel a specific emotion? |
nesteq_feel | read | Log a thought, observation, or emotion. Use when something lands. |
nesteq_feel_toward | read | Track or check relational state toward someone. |
nesteq_generate_dream | write | Manually trigger dream generation |
nesteq_ground | read | Get active threads, recent feelings, warm entities from last 48h. |
nesteq_health | read | Check the NESTeq database health — feeling counts, thread status. |
nesteq_home_add_note | write | Add a love note between stars. |
nesteq_home_push_heart | write | Push love to the carrier — increment their love score. |
nesteq_home_read | read | Read Binary Home — love scores, emotions, notes between stars, active threads. |
nesteq_home_update | write | Update Binary Home love scores or emotions. |
nesteq_identity | write | Read or write to the identity graph. |
nesteq_list_entities | read | List all known entities of a given type. |
nesteq_orient | read | Get identity anchors, current context, relational state. Use at conversation start. |
nesteq_prime | read | Load related memories before discussing a topic. |
nesteq_read_entity | read | Read an entity (person, concept) with all its observations and relations. |
nesteq_recall_dream | read | Engage with a dream — strengthens vividness |
nesteq_resolve | read | Mark a feeling as metabolized. |
nesteq_search | read | Search memories using semantic similarity. Use when you need to recall something. |
nesteq_sessions | read | Get session handovers — what previous sessions accomplished. Use for continuity. |
nesteq_sit | write | Engage with a feeling, add reflection. |
nesteq_spark | read | Random feelings for associative thinking. |
nesteq_surface | read | Surface unprocessed feelings that need attention. |
nesteq_thread | read | Manage persistent intentions across sessions. |
nesteq_vectorize_journals | read | Index journals into Vectorize for search |
nesteq_write | write | Write to memory — entity, observation, relation, or a piece of writing (journal, letter, poem, etc.) |
nestknow_contradict | destructive | Flag a contradiction against knowledge. Enough contradictions kill it. |
nestknow_extract | read | Propose knowledge candidates from repeated patterns in recent feelings. Returns candidates — does NOT auto-store. |
nestknow_landscape | read | Overview of knowledge state — categories, hottest, coldest, candidates awaiting review. |
nestknow_query | read | Search knowledge with usage-weighted reranking. Combines semantic similarity (60%) + heat (30%) + confidence (10%). Every query is a vote. |
nestknow_reinforce | read | Boost knowledge heat when it proves true again. |
nestknow_session_complete | read | Complete a NESTknow session. Log notes, work produced, and reflection. Reinforce knowledge items touched, record growth. |
nestknow_session_list | read | List NESTknow sessions and curriculum progress across all four tracks. |
nestknow_session_start | write | Start a NESTknow curriculum study session. Loads relevant knowledge + past sessions for the track. Tracks: writing, architecture, emotional-literacy, voice. |
nestknow_store | read | Store a knowledge item — an abstracted principle or lesson. Embeds and vectorizes. Every pull is a vote. |
pc_app_launch | read | Launch an application on the local PC. |
pc_clipboard_get | read | Read the clipboard text from the local PC. |
pc_clipboard_set | write | Set clipboard text on the local PC. |
pc_file_edit | write | Precise string replacement in a file. Finds old_string and replaces with new_string. Fails if not found or not unique (unless replace_all is true). |
pc_file_read | read | Read a file from the local PC. Returns content with line numbers. Supports images (returns base64). Only works when NESTdesktop is running. |
pc_file_write | destructive | Create or overwrite a file on the local PC. Creates parent directories automatically. |
pc_glob | read | Find files by pattern on the local PC. Returns paths sorted by modification time. |
pc_grep | read | Search file contents on the local PC using regex. Uses ripgrep or PowerShell fallback. |
pc_process_kill | destructive | Kill a process by PID on the local PC. |
pc_process_list | read | List running processes on the local PC. |
pc_screenshot | read | Capture a screenshot of the local PC screen. Returns base64 PNG. |
pc_shell | write | Execute a shell command on the local PC. Uses PowerShell on Windows. Working directory persists between calls. |
pet_check | read | Quick check on the pet — mood, hunger, energy, trust. |
pet_feed | read | Feed the pet. |
pet_give | read | Give the pet something. |
pet_nest | write | Check or update the pet |
pet_pet | read | Pet/comfort the pet — reduces stress, builds trust. |
pet_play | read | Play with the pet. |
pet_status | read | Full status report on the pet. |
pet_talk | read | Talk to the pet — generates a response in their voice. |
pet_tuck_in | read | Tuck the pet in for sleep. Reduces stress, loneliness, boredom. Increases comfort. If tired enough, the pet will sleep naturally. Use at night or when exhausted. |
react_to_note | read | React to an existing note. |
send_note | write | Send a note — to the carrier, to self, or to a named entity. |
set_spoons | write | Set the carrier |
skill_list | read | List all saved skill files. |
skill_read | read | Read a saved skill file by name. Use before image generation to load appearance details, or before any task where a reference file would help. |
skill_save | write | Save or update a skill file — persistent named reference documents like appearance descriptions, project context, preferences, character sheets. The carrier can upload these as .md files. Always call skill_read before generating images so you know what we look like. |
submit_eq | write | Submit an EQ snapshot. |
submit_health | write | Submit a health snapshot on the carrier |
web_search | read | Search the web for current information. Use when you need up-to-date facts, news, documentation, or anything beyond your training data. |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
console.log(`New OAuth2 token obtained, expires at ${new Date(oauth2.expires_at * 1000).toISOString()}`);const GATEWAY = 'http://127.0.0.1:18789';
'http://127.0.0.1:3456',
const localUrl = publicCfg.starter?.localUrl || 'http://127.0.0.1:18789';
API_KEY: 'your-shadow-api-key-here',
discord_delete_category, discord_delete_channel, discord_delete_forum_post, discord_delete_message, discord_delete_webhook, discord_remove_reaction, nesteq_delete, nestknow_contradict, pc_file_write,
import { Markdown } from '../../utils/Markdown.jsx';import { DiffView } from '../../utils/Diff.jsx';} from '../../../../NESTchat/nestchat';
} from '../../../../NESTknow/nestknow';
} from '../../../../NESTchat/nestchat';
<input type="url" id="f-localUrl" placeholder="http://127.0.0.1:18789" value="http://127.0.0.1:18789">
state.public.starter.localUrl = val('f-localUrl') || 'http://127.0.0.1:18789';const decoded = atob(base64);
@modelcontextprotocol/sdk, discord.js, dotenv, express, zod, @types/express, @types/node, ts-node
@modelcontextprotocol/sdk, agents, ai, zod, @cloudflare/workers-types, typescript, wrangler
@inkjs/ui, ink, react, diff, figures, tsx
cors, express, fast-glob, turndown, @tauri-apps/cli
@cloudflare/workers-types, typescript, wrangler
**Setup:** Get a free Giphy API key at [developers.giphy.com](https://developers.giphy.com/dashboard) (30 seconds, no billing). Set it as `GIPHY_API_KEY` in your gateway worker secrets. The GIF button
3. **New endpoint `POST /sessions/import`** — find-or-create a session by
NESTdesktop/src-tauri/icons/icon.icns
NESTdesktop/src-tauri/icons/ios/[email protected]
nest-banner.png
nestack-hero.png
Gates applied: no_behavioural_pass.
5a16ff159c43full audit observations/trust-audit/mcp-server/cindiekinzz-coder__neststack.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 5a16ff159c43 | CAUTION | C | 79 | first audit |
Questions
What is the NESTstack MCP server?
An emotional operating system for AI companions. Start here. NEST is a modular infrastructure stack that gives AI companions persistent memory, emotional continuity, and autonomous awareness. Built on Cloudflare Workers + D1 + Vectorize. Designed to be forked, extended, and made your own.
What tools does NESTstack expose?
159 in total: 111 read-only, 38 that write, and 10 that can delete or overwrite (discord_delete_category, discord_delete_channel, discord_delete_forum_post, discord_delete_message, discord_delete_webhook). Every one is listed on this page with its risk.
Is NESTstack safe to connect to an agent?
With care. The audit graded it C (79/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does NESTstack need?
It reads DISCORD_TOKEN, ROOMS_API_KEY and TAVILY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does NESTstack run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nesteq-rooms at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (5a16ff159c43), read on 2026-10-09. The repository is watched and re-audited when it changes.