VestigeBLOCK
Cognitive deterministic memory transaction security kernel for agents, that traces backwards to find the root cause and not the lookalike
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Local cognitive memory for MCP agents.
It keeps the decisions a project already made, and it can reach backward from a failure to earlier memories that share its entities. With tracing on, a retrieval leaves a receipt. The store is SQLite on your machine.
[](https://github.com/samvallad33/vestige/releases/latest) [](https://github.com/samvallad33/vestige/actions) [](https://github.com/samvallad33/vestige/releases/latest) [](LICENSE)
Install · Why not RAG · The Live Gate · Continuity · Benchmark · Science · Docs
The cause never looks like the bug
Agents re-learn the same lessons. They recommend a change you already tested and rejected, re-derive a fix that was already written down, and treat every session as if the last one never happened. Vestige is the local memory an MCP client calls while you work: smart_ingest stores, recall retrieves. Near-identical writes merge, disagreements can be listed, unused memories fade under FSRS-6, and a failure can be walked backward to earlier memories that share its entities.
27040ba25ac8OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vestige-mcp-server -- npx -y [email protected]
Trust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
("-----BEGIN PRIVATE KEY-----", "-----END PRIVATE KEY-----"),"-----BEGIN RSA PRIVATE KEY-----",
"-----BEGIN EC PRIVATE KEY-----",
"-----BEGIN OPENSSH PRIVATE KEY-----",
let first = scan_secrets("-----BEGIN PRIVATE KEY-----\nAAAA\n-----END PRIVATE KEY-----");let slack = format!("xoxb-123456-654321-{}", "a".repeat(24));0.BZytbIA4.css.br
0.BZytbIA4.css.gz
1.DTkU2GWb.css.br
1.DTkU2GWb.css.gz
10.DfJ43uDZ.css.br
\r\f\xA0\v`];function ta(e,t,n){var r=e==null?``:``+e;if(t&&(r=r?r+` `+t:t),n){for(var i of Object.keys(n))if(n[i])r=r?r+` `+i:i;else if(r.length)for(var a=i.length,o=0;(o=r.indexOf(i,o))>=0;){var s=o/// url = "postgres://vestige:secret@localhost:5432/vestige"
# url = "postgres://vestige:secret@localhost:5432/vestige"
url = "postgres://vestige:secret@localhost:5432/vestige"
export DATABASE_URL="postgresql://vestige:[email protected]:5432/vestige"
export DATABASE_URL="postgres://vestige:[email protected]:5432/vestige_dev"
.agentaudit-report.json
tar czf ../../../vestige-mcp-aarch64-linux-android.tar.gz vestige-mcp
tar czf ../../../vestige-mcp-${{ matrix.target }}.tar.gz vestige-mcp vestige vestige-restoretar czf ../../../vestige-mcp-x86_64-unknown-linux-gnu.tar.gz vestige-mcp vestige vestige-restore
tar czf ../../../vestige-mcp-aarch64-unknown-linux-gnu.tar.gz vestige-mcp vestige vestige-restore
tar -czf ../../../vestige-mcp-${{ matrix.target }}.tar.gz vestige-mcp vestige vestige-restore INSTALL-INTEL-MAC.mdVerify the CLI: `vestige dashboard`. It binds `http://127.0.0.1:3927` (override with `--port`) and `/` redirects to `/dashboard`. The first start of `vestige-mcp` downloads the Nomic embedding model (
The server binds **http://127.0.0.1:3927** and redirects `/` to **/dashboard**. The observatory steps a fixed 60fps clock, 720 frames, 12 seconds, and can export that loop as an mp4. Share artifacts a
Gates applied: critical_finding, no_behavioural_pass.
27040ba25ac8full audit observations/trust-audit/mcp-server/samvallad33__vestige.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 27040ba25ac8 | BLOCK | F | 43 | first audit |
Questions
What is the Vestige MCP server?
Cognitive deterministic memory transaction security kernel for agents, that traces backwards to find the root cause and not the lookalike
Is Vestige safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Vestige need?
It reads VESTIGE_ARENA_ALLOW_KEYWORD_ONLY, VESTIGE_E2E_AUTH_TOKEN and VESTIGE_SANHEDRIN_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Vestige run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as vestige-mcp-server at 3.1.1.
How current is this page?
The grade is for one exact copy of the source (27040ba25ac8), read on 2026-09-29. The repository is watched and re-audited when it changes.