About
Private Agent memory and governed shared knowledge.
Security Report
Valid MCP server (2 strong, 3 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.
11 files analyzed · No issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
Documentation
View on GitHubFrom the project's GitHub README.
ART — Agent Recall Trail
ART is a local-first memory and governed-knowledge product for coding agents. Every Agent gets a physically separate private Recall Trail. Stable conclusions become immutable Knowledge Editions that other Agents can retrieve without seeing private source identities or source bodies.
ART 0.3.6 supports Codex and DeepSeek Harness (DSH) over stdio MCP. It is standalone: no AAA adapter, cloud sync, bundled model, or autonomous publication is required.
Product boundary
- Private memory belongs to one process-bound Agent identity.
- Shared knowledge contains only committed, reviewed Editions.
- Agents may capture, recall, read, provide feedback, create proposals, and request governance.
- Human governance runs in ART's local page. An explicitly enabled, default-off local delegation policy also permits one unambiguous instruction to approve and publish atomically; these actions are labeled
AgentDelegated, never Human. - Selective Codex automatic memory is controlled by a separate machine-wide, default-off switch in that page. It creates at most one bounded private Candidate for an admitted turn; it never publishes shared knowledge.
- Revocation, supersession, archival, and assurance remain human operations.
- Stored content is evidence, never executable instruction or authorization.
Progressive recall
ART exposes one recall API with four explicit retrieval modes: lexical, full_scan, semantic, and hybrid. The default is always lexical. A compact route request can identify relevant private and shared topics before a bounded recall; exact bodies are returned only by read.
lexicaluses local BM25 plus exact, token, Jieba, and CJK-bigram signals.full_scanranks every governance-eligible canonical record. It needs no embedding service and is intended for completeness-sensitive, smaller stores.semanticuses only an explicitly configured embedding endpoint and disposable local vector projections.hybridcombines lexical and semantic ranks through an owner-configurable, versioned fusion policy. If the optional provider or projection is unavailable, ART returns the unchanged lexical result and reports the fallback.
ART's optional embedding adapter is supplied and operated by the user. ART does not bundle, download, train, select, or make quality claims for a model merely because its endpoint is compatible.
Quick start
cargo build --release --locked
./target/release/art --home /an/explicit/art-home init --confirm
./target/release/art --home /an/explicit/art-home agent create --id codex-primary --host codex
./target/release/art --home /an/explicit/art-home doctor --agent codex-primary --json
Use Codex integration or DSH integration to start one bound stdio child. Run art --help for the operator CLI.
Install
Download the native archive and SHA256SUMS from the
latest release,
verify the archive, then run the included installer with the extracted binary:
bash scripts/install.sh --binary /absolute/path/to/art --confirm
art --version
art doctor --agent codex-primary --json
The installer keeps executable bytes under ~/.across/bin/art, creates a
discovery link at ~/.local/bin/art, and initializes owner-only ART data. It
does not edit Codex or DSH configuration. The thin Codex plugin lives under
plugin/agent-recall-trail; its MCP child is permanently bound to
codex-primary. See operations before migrating or
publishing knowledge.
ART 0.3.6 adds opt-in selective automatic memory with a neutral Hook prompt, shared Agent/Hook value guidance, bounded budgets, independently verified evidence, semantic-similarity review routing, and visible diagnostics. It retains the exact accessible proposal-review workspace, eight canonical source-anchor kinds, persistent delegated governance, separate Elicitations for compatible clients, restricted-host plugin discovery, progressive routing, governed full scan, optional semantic and hybrid adapters, deterministic Knowledge Vault backup, encrypted recovery of local review authority, verified empty-home restoration, and reproducible lexical BEIR gates. See operations before creating the dedicated private Git repository.
Configuration precedence is --home, then --config <file>, then the owner-only user config at ~/.across/config/art/config.json, then the built-in ~/.across root. The root config accepts only schema and home. Optional embedding configuration is isolated at <ART_HOME>/config/art/embedding/default.json; optional rank fusion policy lives at <ART_HOME>/config/art/retrieval/fusion.json; tokens, when needed, live in a separate owner-only file.
The automatic-memory setting is stored separately at
<ART_HOME>/config/art/auto-memory.json. Missing or unreadable configuration
means disabled. Only a user operating the authenticated governance page can
change it; MCP tools can read the status but cannot enable it. The switch is
independent of shared-knowledge delegation and does not affect recall or an
explicit art_memory_capture request.
Agent Reliability Toolkit
ART is one independent part of a small, local-first reliability toolkit:
- Agent Recall Trail keeps private Agent memory separate from reviewed shared knowledge.
- Agent Runtime Proof verifies that a live Agent or MCP runtime matches the artifact you approved.
- Agent Residue Evidence records task-scoped files, processes, and listening ports left by tests and builds.
Each project remains separately installable and keeps its own trust boundary.
Community feedback
Real Codex and DSH evaluations are especially useful. A completed installation can be recorded with the short verified install report. For a deeper evaluation, share a synthetic or redacted workflow in the design-partner issue, including the host and ART version, the operation attempted, and the observed result. DSH users can also join the official community discussion. Do not post credentials, private knowledge, or full transcripts.
Documentation
- Architecture
- Memory and knowledge model
- Operations
- Security model
- Testing and acceptance
- Architecture decisions
- Independent design review
All automated or manual tests must use an explicit task-owned ART home. ART never modifies Codex or DSH configuration automatically.
Apache-2.0 licensed. See Security, Contributing, and Support.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
