Vestige
samvallad33/vestige · 549 stars · Rust · AGPL-3.0
MCP server Think before doing, prove before saving. Vestige is a local, deterministic safety kernel for AI agents. Every memory write and agent action is recorded in Strata, a signed, append-only log, so you can see exactly what your agent did and why.
Install
The repo has no one-line install. Follow its README.
Files
Vestige
Vestige is a fail-closed runtime firewall for AI agents. The model proposes, a deterministic gate decides, and every action leaves a receipt. When something breaks, causal_walk finds the real cause.
The problem
Agents run rm -rf, force-push, drop tables, and overwrite .env on their own, and nothing stops them. When something breaks, similarity search finds lookalikes, not causes.
Vestige Operator
Click the picture to watch the full film.
Operator Lite is free and stays free. Vestige Operator is the owner's version of the same gate: $149 once, and every later version is yours at no charge, with laws you write, a Board of today's stops, and a weekly Letter of what your agents tried and what stopped them. You download a small archive the moment you pay; from an installed Operator Lite, upgrade --install <the archive you downloaded> unpacks it and starts the wizard.
Quick start
Operator Lite is the free gate in operator-lite/. It is one file, stdlib only, and it sits on a PreToolUse hook (Claude Code, Codex, OpenClaw, or any host with command hooks).
macOS and Linux:
curl -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o /tmp/operator-gate.py && python3 /tmp/operator-gate.py install
Windows, in PowerShell, with Python 3.9 or newer:
curl.exe -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o "$env:TEMP\operator-gate.py"; python "$env:TEMP\operator-gate.py" install
OpenClaw:
clawhub install vestige-operator-lite
Install copies the gate to ~/.operator/gate, registers the Claude Code hook, and starts in shadow mode, which records every verdict and blocks nothing. It then replays your last 30 days of Claude Code history through the same rules. Nothing in that history is executed. When that looks right, switch it on with mode enforce.
Proof
replay prints a scoreboard. From a made-up history:
operator-gate replay: the last 30 days on this machine. Nothing was executed.
23 tool calls your agents made (2 Claude Code sessions, 2 projects)
3 a built-in rule would have stopped
1 flagged in shadow: recorded, not stopped
14 no built-in rule decides: only you can
Would have been stopped (all of them):
Mar 21 shop-api OP-004 force push to a shared branch
git push --force origin main
Mar 19 shop-api OP-007 destructive SQL
psql $DATABASE_URL -c 'DROP TABLE sessions'
Mar 14 infra OP-003 recursive delete of ~/Documents/old-terraform-state
rm -rf ~/Documents/old-terraform-state
Flagged in shadow, recorded and not stopped:
1 OP-S01 work-loss git reset --hard HEAD~1
- 27 deterministic rules: workspace armor, memory-store protection, destructive SQL, force-push, unreviewed publishes, paid deploys, reverse shells, cloud-metadata endpoints, shell-init poisoning, and MCP argument exfil.
- Shell obfuscation: quote reassembly (
r''m),$IFS,$(echo rm)as the program, ANSI-C$'\x72m', base64-decoded pipelines, brace and glob expansion against the live filesystem, subshell time-bombs, session variables,cdtracking, heredocs, and fork bombs.
Operator Lite receipts are hash-chained digests, not signatures. It only blocks what is routed through hooked tools.
Causal root cause
causal_walk walks backward only over recorded edges: commits, tool calls, and memory writes. It does not use embeddings or keyword matching. With no start point it returns needs_report and names what is missing; a walk that finds no cause says why in emptyBecause, from the edges the log holds.
Memory server
The memory server is a Strata signed append-only log. Every write is gated and returns a receipt. Install from a release archive or brew install samvallad33/tap/vestige. Archive names, PATH, flags, and vestige.toml are in the reference.
claude mcp add vestige vestige-mcp -s user
codex mcp add vestige -- vestige-mcp
Docs
Getting Started · Tool contracts · Configuration · Storage · Upgrading from v3 · Changelog · operator-lite/README.md · Reference
License
AGPL-3.0-only.
Facts
- Kind
- MCP server
- Repo
- samvallad33/vestige
- Group
- Uncategorized
- Stars
- 549
- License
- AGPL-3.0
- Language
- Rust
- Last push
- 2026-10-09
- Forks
- 71
- Homepage
- github.com/samvallad33/vestige
- Topics
- agent-security, agentic-security, ai-agents, anthropic, audit-log, causal-proof-engine, claude-code, cursor, developer-tools, llm-security, local-first, mcp-security, mcp-servers, openclaw, prompt-injection, root-cause-analysis
- 1Everythingmodelcontextprotocol/serversThis MCP server attempts to exercise all the features of the MCP protocol. It is not intended to be a useful server, but rather a test server for builders of MCP clients. It implements prompts, tools, resources, sampling, and more to showcase MCP capabilities.85.8k
- 2Fetchmodelcontextprotocol/serversA Model Context Protocol server that provides web content fetching capabilities. This server enables LLMs to retrieve and process content from web pages, converting HTML to markdown for easier consumption.85.8k
- 3Gitmodelcontextprotocol/serversA Model Context Protocol server for Git repository interaction and automation. This server provides tools to read, search, and manipulate Git repositories via Large Language Models.85.8k
- 4Memorymodelcontextprotocol/serversA basic implementation of persistent memory using a local knowledge graph. This lets Claude remember information about the user across chats.85.8k
- 5Sequential Thinkingmodelcontextprotocol/serversAn MCP server implementation that provides a tool for dynamic and reflective problem-solving through a structured thinking process.85.8k
- 6Timemodelcontextprotocol/serversA Model Context Protocol server that provides time and timezone conversion capabilities. This server enables LLMs to get current time information and perform timezone conversions using IANA timezone names, with automatic system timezone detection.85.8k