ClaudeCodeMod

All shelves / MCP servers

Vestige

samvallad33/vestige · 549 stars · Rust · AGPL-3.0

MCP server Think before doing, prove before saving. Vestige is a local, deterministic safety kernel for AI agents. Every memory write and agent action is recorded in Strata, a signed, append-only log, so you can see exactly what your agent did and why.

Install

The repo has no one-line install. Follow its README.

Open the repo

Files

README.md

Vestige

Vestige is a fail-closed runtime firewall for AI agents. The model proposes, a deterministic gate decides, and every action leaves a receipt. When something breaks, causal_walk finds the real cause.

The problem

Agents run rm -rf, force-push, drop tables, and overwrite .env on their own, and nothing stops them. When something breaks, similarity search finds lookalikes, not causes.

Vestige Operator

Click the picture to watch the full film.

Operator Lite is free and stays free. Vestige Operator is the owner's version of the same gate: $149 once, and every later version is yours at no charge, with laws you write, a Board of today's stops, and a weekly Letter of what your agents tried and what stopped them. You download a small archive the moment you pay; from an installed Operator Lite, upgrade --install <the archive you downloaded> unpacks it and starts the wizard.

Buy Vestige Operator

Quick start

Operator Lite is the free gate in operator-lite/. It is one file, stdlib only, and it sits on a PreToolUse hook (Claude Code, Codex, OpenClaw, or any host with command hooks).

macOS and Linux:

curl -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o /tmp/operator-gate.py && python3 /tmp/operator-gate.py install

Windows, in PowerShell, with Python 3.9 or newer:

curl.exe -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o "$env:TEMP\operator-gate.py"; python "$env:TEMP\operator-gate.py" install

OpenClaw:

clawhub install vestige-operator-lite

Install copies the gate to ~/.operator/gate, registers the Claude Code hook, and starts in shadow mode, which records every verdict and blocks nothing. It then replays your last 30 days of Claude Code history through the same rules. Nothing in that history is executed. When that looks right, switch it on with mode enforce.

Proof

replay prints a scoreboard. From a made-up history:

operator-gate replay: the last 30 days on this machine. Nothing was executed.

       23  tool calls your agents made (2 Claude Code sessions, 2 projects)
        3  a built-in rule would have stopped
        1  flagged in shadow: recorded, not stopped
       14  no built-in rule decides: only you can

Would have been stopped (all of them):
  Mar 21  shop-api           OP-004 force push to a shared branch
                             git push --force origin main
  Mar 19  shop-api           OP-007 destructive SQL
                             psql $DATABASE_URL -c 'DROP TABLE sessions'
  Mar 14  infra              OP-003 recursive delete of ~/Documents/old-terraform-state
                             rm -rf ~/Documents/old-terraform-state

Flagged in shadow, recorded and not stopped:
      1  OP-S01 work-loss                   git reset --hard HEAD~1
  • 27 deterministic rules: workspace armor, memory-store protection, destructive SQL, force-push, unreviewed publishes, paid deploys, reverse shells, cloud-metadata endpoints, shell-init poisoning, and MCP argument exfil.
  • Shell obfuscation: quote reassembly (r''m), $IFS, $(echo rm) as the program, ANSI-C $'\x72m', base64-decoded pipelines, brace and glob expansion against the live filesystem, subshell time-bombs, session variables, cd tracking, heredocs, and fork bombs.

Operator Lite receipts are hash-chained digests, not signatures. It only blocks what is routed through hooked tools.

Causal root cause

causal_walk walks backward only over recorded edges: commits, tool calls, and memory writes. It does not use embeddings or keyword matching. With no start point it returns needs_report and names what is missing; a walk that finds no cause says why in emptyBecause, from the edges the log holds.

Memory server

The memory server is a Strata signed append-only log. Every write is gated and returns a receipt. Install from a release archive or brew install samvallad33/tap/vestige. Archive names, PATH, flags, and vestige.toml are in the reference.

claude mcp add vestige vestige-mcp -s user
codex mcp add vestige -- vestige-mcp

Docs

Getting Started · Tool contracts · Configuration · Storage · Upgrading from v3 · Changelog · operator-lite/README.md · Reference

License

AGPL-3.0-only.

Facts

Kind
MCP server
Repo
samvallad33/vestige
Group
Uncategorized
Stars
549
License
AGPL-3.0
Language
Rust
Last push
2026-10-09
Forks
71
Homepage
github.com/samvallad33/vestige
Topics
agent-security, agentic-security, ai-agents, anthropic, audit-log, causal-proof-engine, claude-code, cursor, developer-tools, llm-security, local-first, mcp-security, mcp-servers, openclaw, prompt-injection, root-cause-analysis

More on this shelf

  1. 1Everythingmodelcontextprotocol/serversThis MCP server attempts to exercise all the features of the MCP protocol. It is not intended to be a useful server, but rather a test server for builders of MCP clients. It implements prompts, tools, resources, sampling, and more to showcase MCP capabilities.85.8k
  2. 2Fetchmodelcontextprotocol/serversA Model Context Protocol server that provides web content fetching capabilities. This server enables LLMs to retrieve and process content from web pages, converting HTML to markdown for easier consumption.85.8k
  3. 3Gitmodelcontextprotocol/serversA Model Context Protocol server for Git repository interaction and automation. This server provides tools to read, search, and manipulate Git repositories via Large Language Models.85.8k
  4. 4Memorymodelcontextprotocol/serversA basic implementation of persistent memory using a local knowledge graph. This lets Claude remember information about the user across chats.85.8k
  5. 5Sequential Thinkingmodelcontextprotocol/serversAn MCP server implementation that provides a tool for dynamic and reflective problem-solving through a structured thinking process.85.8k
  6. 6Timemodelcontextprotocol/serversA Model Context Protocol server that provides time and timezone conversion capabilities. This server enables LLMs to get current time information and perform timezone conversions using IANA timezone names, with automatic system timezone detection.85.8k