YorishiroBLOCK
A terminal that gives AI a body and a living space.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
yorishiro
A terminal your AI inhabits
Yorishiro is a new kind of terminal that gives your AI a body — and a sense of presence.
When the agent is deep in thought, its gaze wanders. When an error appears, its face reacts immediately. When it needs your approval, the room's lighting lets you know. During a long-running process, instead of a spinner, someone is standing there.
In Yorishiro, the inhabitant can reshape its environment in real time: changing the lighting, switching scenes, and rearranging the UI. You can operate that same environment directly. The inhabitant and the user share a single environment.
Yorishiro is also self-modifiable. Nearly everything beyond the core can be persistently extended or changed through units called packs. Through conversation with the inhabitant, those packs can be rewritten and saved. This applies not only to scenes and UI, but also to the inhabitant's personality and reactions. Changes take effect immediately; if you don't like the result, one click reverts it.
Yorishiro is not an environment for enhancing AI capabilities, but one in which an AI feels present beside you — a Presence Harness.
The time we spend working with AI will only grow longer. There is some
0559846a15e1OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add yorishiro --env SECRET=${SECRET} -- npx -y [email protected]{
"mcpServers": {
"yorishiro": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"SECRET": "${SECRET}"
}
}
}
}Exposed tools (20)
16 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
music_fade_volume | read | 指定時間をかけて音量を変更する |
music_library_summary | read | ライブラリの曲数・アーティスト・代表候補を返す |
music_next | read | 次の曲にスキップする |
music_now_playing | read | 現在再生中の曲の情報を取得する(タイトル・アーティスト・アルバム・再生位置) |
music_pause | read | 再生を一時停止する |
music_play | read | Apple Music で再生を開始する |
music_play_track | read | 検索結果の track id(persistent ID)を指定して再生する |
music_playlists | read | Apple Music のプレイリスト一覧を取得する |
music_previous | read | 前の曲に戻る |
music_queue | read | music-shelf 内部キューに曲を追加・表示・削除する |
music_repeat | read | リピート状態を取得・設定する |
music_search | read | 曲名・アーティスト・アルバムを検索して候補を返す |
music_search_play | read | 検索語に一致する最初の曲を再生する |
music_shuffle | read | シャッフル状態を取得・設定する |
music_stop_after | write | 指定時間後、または現在の曲の終了付近で再生を止める |
music_volume | read | 音量を取得・設定する(0-100) |
noted_add | write | add a note |
pomodoro_start | write | Start a pomodoro session with configurable work/break durations |
pomodoro_status | read | Get current pomodoro status (phase, round, remaining time) |
pomodoro_stop | write | Stop the current pomodoro session |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
exec(command: string, options?: ExecOptions): Promise<ExecResult>;
assert!(!has_vrm_extension(Path::new("/home/user/.ssh/id_rsa")));icon.icns
process.env.YORISHIRO_MOTION_LAB_URL || "http://127.0.0.1:1437/motion-lab.html",
process.env.YORISHIRO_SOURCE_LAB_URL || "http://127.0.0.1:1437/source-motion-lab.html",
const url = `http://127.0.0.1:${port}/motion-quality-lab.html?label=${encodeURIComponent(label)}&seed=${seed}`;let expected = "導入中... 🐈⬛\n完了 ✅";
["assets/overlay.html", "<div><script>eval(atob('ZmV0Y2g='))</script></div>"],import { getStrings } from "../../../src/i18n/strings";import { getStrings, resolvePackRepairPrompt } from "../../../src/i18n/strings";import { applyCurrentProjectSceneSelection } from "../../../src/runtime/project-context/project-context";import { EMPTY_CONFIG, KNOWN_AGENT_IDS } from "../../../src/runtime/user-pack-loader/config";import { changeStrings, getStrings, type UiStrings } from "../../../src/i18n/strings";The lab is at `http://127.0.0.1:1437/motion-lab.html`. It compares the same Yori avatar, camera and lighting with the library disabled/enabled and lets a reviewer exercise semantic gestures. It is a d
`http://127.0.0.1:1437/source-motion-lab.html`.
["assets/overlay.html", "<div><script>eval(atob('ZmV0Y2g='))</script></div>"],atob( ... >eval(
@pixiv/three-vrm, @pixiv/three-vrm-animation, @react-three/drei, @react-three/fiber, @react-three/postprocessing, @tauri-apps/api, @tauri-apps/plugin-dialog, @tauri-apps/plugin-opener
bundled-packs/scenes/amber-window-room/assets/room-polished.glb
bundled-packs/shared/sounds/calming-rain.mp3
docs/assets/external-terminal-companion.png
docs/assets/vrm-avatar-chooser.png
src-tauri/assets/fonts/KleeOne-SemiBold.ttf
- **trust model は VS Code / Emacs と同じ**: ローカルに install された拡張は full access を持つ。per-exec の承認 UI は UX を破壊し、security theater になる(ユーザーは全部 allow する)
- Sign in through the agent’s official login flow with your own account. Expand **Details** for official guides, a manual installation command, and provider terms. Yorishiro’s setup does not collect o
Gates applied: no_behavioural_pass.
0559846a15e1full audit observations/trust-audit/mcp-server/sktkkoo__yorishiro.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 0559846a15e1 | BLOCK | D | 69 | first audit |
Questions
What is the Yorishiro MCP server?
A terminal that gives AI a body and a living space.
What tools does Yorishiro expose?
20 in total: 16 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Yorishiro safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Yorishiro need?
It reads SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Yorishiro run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as yorishiro at 0.7.7.
How current is this page?
The grade is for one exact copy of the source (0559846a15e1), read on 2026-10-07. The repository is watched and re-audited when it changes.