by samvallad33
Think before doing, prove before saving. Vestige is a local, deterministic safety kernel for AI agents. Every memory write and agent action is recorded in Strata, a signed, append-only log, so you can see exactly what your agent did and why.
# Add to your Claude Code skills
git clone https://github.com/samvallad33/vestigeLast scanned: 5/14/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-14T06:47:15.043Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how vestige compares with popular alternatives.
vestige is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by samvallad33. Think before doing, prove before saving. Vestige is a local, deterministic safety kernel for AI agents. Every memory write and agent action is recorded in Strata, a signed, append-only log, so you can see exactly what your agent did and why. It has 648 GitHub stars.
Yes. vestige passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/samvallad33/vestige" and add it to your Claude Code skills directory (see the Installation section above).
vestige is primarily written in Rust. It is open-source under samvallad33 on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh vestige against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Vestige is a fail-closed runtime firewall for AI agents. The model proposes, a deterministic gate decides, and every action leaves a receipt. When something breaks, causal_walk finds the real cause.
Agents run rm -rf, force-push, drop tables, and overwrite .env on their own, and nothing stops them. When something breaks, similarity search finds lookalikes, not causes.
Click the picture to watch the full film.
Operator Lite is free and stays free. Vestige Operator is the owner's version of the same gate: $149 once, and every later version is yours at no charge, with laws you write, a Board of today's stops, and a weekly Letter of what your agents tried and what stopped them. You download a small archive the moment you pay; from an installed Operator Lite, upgrade --install <the archive you downloaded> unpacks it and starts the wizard.
Operator Lite is the free gate in operator-lite/. It is one file, stdlib only, and it sits on a PreToolUse hook (Claude Code, Codex, OpenClaw, or any host with command hooks).
macOS and Linux:
curl -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o /tmp/operator-gate.py && python3 /tmp/operator-gate.py install
Windows, in PowerShell, with Python 3.9 or newer:
curl.exe -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o "$env:TEMP\operator-gate.py"; python "$env:TEMP\operator-gate.py" install
OpenClaw:
clawhub install vestige-operator-lite
Install copies the gate to ~/.operator/gate, registers the Claude Code hook, and starts in shadow mode, which records every verdict and blocks nothing. It then replays your last 30 days of Claude Code history through the same rules. Nothing in that history is executed. When that looks right, switch it on with mode enforce.
replay prints a scoreboard. From a made-up history:
operator-gate replay: the last 30 days on this machine. Nothing was executed.
23 tool calls your agents made (2 Claude Code sessions, 2 projects)
3 a built-in rule would have stopped
1 flagged in shadow: recorded, not stopped
14 no built-in rule decides: only you can
Would have been stopped (all of them):
Mar 21 shop-api OP-004 force push to a shared branch
git push --force origin main
Mar 19 shop-api OP-007 destructive SQL
psql $DATABASE_URL -c 'DROP TABLE sessions'
Mar 14 infra OP-003 recursive delete of ~/Documents/old-terraform-state
rm -rf ~/Documents/old-terraform-state
Flagged in shadow, recorded and not stopped:
1 OP-S01 work-loss git reset --hard HEAD~1
r''m), $IFS, $(echo rm) as the program, ANSI-C $'\x72m', base64-decoded pipelines, brace and glob expansion against the live filesystem, subshell time-bombs, session variables, cd tracking, heredocs, and fork bombs.Operator Lite receipts are hash-chained digests, not signatures. It only blocks what is routed through hooked tools.
causal_walk walks backward only over recorded edges: commits, tool calls, and memory writes. It does not use embeddings or keyword matching. With no start point it returns needs_report and names what is missing; a walk that finds no cause says why in emptyBecause, from the edges the log holds.
The memory server is a Strata signed append-only log. Every write is gated and returns a receipt. Install from a release archive or brew install samvallad33/tap/vestige. Archive names, PATH, flags, and vestige.toml are in the reference.
claude mcp add vestige vestige-mcp -s user
codex mcp add vestige -- vestige-mcp
Getting Started · Tool contracts · Configuration · Storage · Upgrading from v3 · Changelog · operator-lite/README.md · Reference
AGPL-3.0-only.