Atlas / MCP servers / samvallad33 / Vestige

VestigeBLOCK

mcp/samvallad33/vestige

Cognitive deterministic memory transaction security kernel for agents, that traces backwards to find the root cause and not the lookalike

Verdict
BLOCK
Grade
F
Trust score
43 /100
Exposed tools
—
Transport
stdio
License
AGPL-3.0
Stars
639
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Local cognitive memory for MCP agents.

It keeps the decisions a project already made, and it can reach backward from a failure to earlier memories that share its entities. With tracing on, a retrieval leaves a receipt. The store is SQLite on your machine.

[](https://github.com/samvallad33/vestige/releases/latest) [](https://github.com/samvallad33/vestige/actions) [](https://github.com/samvallad33/vestige/releases/latest) [](LICENSE)

Install · Why not RAG · The Live Gate · Continuity · Benchmark · Science · Docs

The cause never looks like the bug

Agents re-learn the same lessons. They recommend a change you already tested and rejected, re-derive a fix that was already written down, and treat every session as if the last one never happened. Vestige is the local memory an MCP client calls while you work: smart_ingest stores, recall retrieves. Near-identical writes merge, disagreements can be listed, unused memories fade under FSRS-6, and a failure can be walked backward to earlier memories that share its entities.

Read from source at commit 27040ba25ac8OBSERVED · 2026-09-29
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add vestige-mcp-server -- npx -y [email protected]
03

Trust audit

BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (7 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/vestige-core/src/security.rs:313
("-----BEGIN PRIVATE KEY-----", "-----END PRIVATE KEY-----"),
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/vestige-core/src/security.rs:315
"-----BEGIN RSA PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/vestige-core/src/security.rs:319
"-----BEGIN EC PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/vestige-core/src/security.rs:323
"-----BEGIN OPENSSH PRIVATE KEY-----",
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
crates/vestige-core/src/security.rs:548
let first = scan_secrets("-----BEGIN PRIVATE KEY-----\nAAAA\n-----END PRIVATE KEY-----");
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
crates/vestige-core/src/security.rs:521
let slack = format!("xoxb-123456-654321-{}", "a".repeat(24));
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/dashboard/build/_app/immutable/assets/0.BZytbIA4.css.br
0.BZytbIA4.css.br
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/dashboard/build/_app/immutable/assets/0.BZytbIA4.css.gz
0.BZytbIA4.css.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/dashboard/build/_app/immutable/assets/1.DTkU2GWb.css.br
1.DTkU2GWb.css.br
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/dashboard/build/_app/immutable/assets/1.DTkU2GWb.css.gz
1.DTkU2GWb.css.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
apps/dashboard/build/_app/immutable/assets/10.DfJ43uDZ.css.br
10.DfJ43uDZ.css.br
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
apps/dashboard/build/_app/immutable/chunks/Cmba2AGc.js:3
\r\f\xA0\v`];function ta(e,t,n){var r=e==null?``:``+e;if(t&&(r=r?r+` `+t:t),n){for(var i of Object.keys(n))if(n[i])r=r?r+` `+i:i;else if(r.length)for(var a=i.length,o=0;(o=r.indexOf(i,o))>=0;){var s=o
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/plans/0002b-pool-and-config.md:183
/// url = "postgres://vestige:secret@localhost:5432/vestige"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/plans/0002b-pool-and-config.md:676
# url                  = "postgres://vestige:secret@localhost:5432/vestige"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/plans/0002b-pool-and-config.md:755
url                  = "postgres://vestige:secret@localhost:5432/vestige"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/plans/0002c-migrations.md:848
export DATABASE_URL="postgresql://vestige:[email protected]:5432/vestige"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/plans/0002d-store-impl-bodies.md:1530
export DATABASE_URL="postgres://vestige:[email protected]:5432/vestige_dev"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agentaudit-report.json
.agentaudit-report.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/ci.yml:225
tar czf ../../../vestige-mcp-aarch64-linux-android.tar.gz vestige-mcp
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/ci.yml:288
tar czf ../../../vestige-mcp-${{ matrix.target }}.tar.gz vestige-mcp vestige vestige-restore
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/ci.yml:410
tar czf ../../../vestige-mcp-x86_64-unknown-linux-gnu.tar.gz vestige-mcp vestige vestige-restore
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/ci.yml:522
tar czf ../../../vestige-mcp-aarch64-unknown-linux-gnu.tar.gz vestige-mcp vestige vestige-restore
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/release.yml:161
tar -czf ../../../vestige-mcp-${{ matrix.target }}.tar.gz vestige-mcp vestige vestige-restore INSTALL-INTEL-MAC.md
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:74
Verify the CLI: `vestige dashboard`. It binds `http://127.0.0.1:3927` (override with `--port`) and `/` redirects to `/dashboard`. The first start of `vestige-mcp` downloads the Nomic embedding model (
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:198
The server binds **http://127.0.0.1:3927** and redirects `/` to **/dashboard**. The observatory steps a fixed 60fps clock, 720 frames, 12 seconds, and can export that loop as an mp4. Share artifacts a

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-09-29 · audit v0.4.1 · source sha 27040ba25ac8full audit observations/trust-audit/mcp-server/samvallad33__vestige.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2927040ba25ac8BLOCKF43first audit
05

Questions

What is the Vestige MCP server?

Cognitive deterministic memory transaction security kernel for agents, that traces backwards to find the root cause and not the lookalike

Is Vestige safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (43/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Vestige need?

It reads VESTIGE_ARENA_ALLOW_KEYWORD_ONLY, VESTIGE_E2E_AUTH_TOKEN and VESTIGE_SANHEDRIN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Vestige run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as vestige-mcp-server at 3.1.1.

How current is this page?

The grade is for one exact copy of the source (27040ba25ac8), read on 2026-09-29. The repository is watched and re-audited when it changes.

Advertisement