
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@tenetvault/mcp-server
Advanced tools
Local-first memory and rules layer for AI coding agents — MCP server and CLI.
Local-first memory and rules layer for AI coding agents — via Model Context Protocol.
npx -y @tenetvault/mcp-server@latest setup cursor
This initializes the vault and configures Cursor MCP in one step. Replace cursor with claude, codex, or all.
Verify with:
npx -y @tenetvault/mcp-server@latest doctor
mcp_write_enabled (default off) guards all write operationstenetvault setup <ide> # Auto-configure MCP (cursor|claude|codex|all)
tenetvault doctor [ide] # Diagnose activation issues (--json for CI)
tenetvault init # Initialize an encrypted vault at ~/.tenetvault/
# Non-interactive: tenetvault init --passphrase-file <private-0600-file>
tenetvault capture --title <t> --content <c> # Save a candidate growth memory
pbpaste | tenetvault capture --title <t> --kind lesson
tenetvault review today --approve 1,3 --reject 2 --complete
tenetvault start # Start daemon (Local API + vault runtime) + Web UI
tenetvault open # Start if needed and open the dashboard
tenetvault vault unlock # Unlock interactively in this terminal
tenetvault vault quick-unlock enable # macOS opt-in; stores a device key, never your passphrase
tenetvault vault quick-unlock # User-triggered system authentication after a restart
tenetvault vault quick-unlock status # Inspect non-sensitive configuration state
tenetvault vault quick-unlock forget # Remove this Mac's device slot and Keychain item
tenetvault vault quick-unlock downgrade # Verify both recovery paths, remove device slots, return to v2
tenetvault vault rotate-key --confirm # Rekey SQLCipher and every active key slot
tenetvault version # Show version
tenetvault flags list # List feature flags
tenetvault flags set <key> <on|off> # Toggle a feature flag
The daemon can be healthy while the encrypted Vault is locked. Agents cannot read protected data in that state. Unlock from the local dashboard or a trusted local terminal; agents never receive or submit your passphrase. Quick Unlock is an explicit macOS convenience feature and never runs automatically. It is available only in releases whose app-like Keychain helper is formally signed and provisioned; the current release retains the code but ships it disabled and fail-closed until those Apple release materials are available. Manual passphrase and recovery unlock remain supported.
Full documentation is included in the source repository. The GitHub link is usable only when that repository is publicly available or the reader has access: github.com/tenetvault/tenetvault.
MIT
FAQs
Local-first memory and rules layer for AI coding agents — MCP server and CLI.
The npm package @tenetvault/mcp-server receives a total of 45 weekly downloads. As such, @tenetvault/mcp-server popularity was classified as not popular.
We found that @tenetvault/mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.