vestige is a free, open source ai security & privacy project written in Rust and released under AGPL-3.0. It has 648 GitHub stars, 71 forks and 46 open issues, and was last pushed 6 hours ago. On this registry it ranks #38 of 41 tracked projects in AI Security & Privacy, with 5 head-to-head comparisons available.

What is vestige?

Vestige is a local, deterministic safety kernel and fail-closed runtime firewall for AI agents that records every memory write and agent action in a signed, append-only log called Strata, so you can see exactly what your agent did and why.

What it is

Vestige sits between an AI coding agent and the tools it is allowed to invoke. The model proposes an action, a deterministic gate decides whether it proceeds, and every action leaves a receipt in Strata, a signed, append-only log. It is written in Rust, licensed AGPL-3.0, and is explicitly local-first: the verdicts come from fixed rules rather than from another model, so the same input always produces the same decision. The project ships two layers — Operator Lite, a free single-file gate, and Vestige Operator, a paid edition of the same gate with user-authored laws.

The problem it addresses is concrete: agents run rm -rf, force-push, drop tables, and overwrite .env on their own, and nothing stops them. The second half of the problem is diagnosis — when something breaks, similarity search finds lookalikes rather than causes. Vestige answers the first half with a fail-closed gate on the tool-call path and the second half with causal_walk, which walks backward only over recorded edges such as commits, tool calls, and memory writes.

Key capabilities

  • 27 deterministic rules covering workspace armor, memory-store protection, destructive SQL, force-push, unreviewed publishes, paid deploys, reverse shells, cloud-metadata endpoints, shell-init poisoning, and MCP argument exfiltration.
  • Shell obfuscation detection for quote reassembly such as r''m, $IFS, $(echo rm) used as the program, ANSI-C $'\x72m', base64-decoded pipelines, brace and glob expansion checked against the live filesystem, subshell time-bombs, session variables, cd tracking, heredocs, and fork bombs.
  • A replay command that prints a scoreboard over your last 30 days of Claude Code history, showing which tool calls a built-in rule would have stopped, which were flagged in shadow mode, and which only the operator can decide, with nothing from that history executed.
  • Shadow mode by default, which records every verdict and blocks nothing until you switch to mode enforce.
  • causal_walk root-cause analysis that walks recorded edges only, without embeddings or keyword matching, and returns needs_rep when given no start point.
  • Hash-chained receipt digests for Operator Lite, plus session and project attribution in the replay output.
  • A PreToolUse hook integration that works with Claude Code, Codex, OpenClaw, or any host supporting command hooks.

Who uses it and how

  • Individual developers running Claude Code who want a gate installed on their own machine and want to review 30 days of past tool calls before enforcing anything.
  • Operators on macOS, Linux, or Windows who install through a shell one-liner and let the wizard register the hook and start in shadow mode.
  • OpenClaw users who install the gate from the registry with clawhub install vestige-operator-lite.
  • Teams and owners who upgrade to Vestige Operator for custom laws, a board of current stops, and a weekly Letter summarising what their agents attempted and what was stopped.

Getting started

Download operator-gate.py from the repository and run python3 /tmp/operator-gate.py install, which copies the gate to ~/.operator/gate, registers the Claude Code hook, and starts in shadow mode; on Windows, run the same script with Python 3.9 or newer, and on OpenClaw use clawhub install vestige-operator-lite.

How it compares

Operator Lite is free and stays free, while Vestige Operator is a one-time purchase of $149 that includes every later version at no charge, plus user-written laws, a board of today's stops, and a weekly Letter. Both run locally and keep the audit trail on your own machine, so nothing about your agents' actions leaves your machine for either edition; from an installed Operator Lite, upgrade --install unpacks the Operator archive and starts the wizard.

When to use it — and when not

Operator Lite only blocks what is routed through hooked tools, so any path that bypasses the hook is unprotected, and its receipts are hash-chained digests rather than signatures. It is a poor fit if you need enforcement outside a command-hook host or cryptographic signing on the free tier, and with 46 open issues the project is still visibly under active development rather than settled.

project readme (upstream, from github) — read inline

Vestige

Vestige

Vestige is a fail-closed runtime firewall for AI agents. The model proposes, a deterministic gate decides, and every action leaves a receipt. When something breaks, causal_walk finds the real cause.

Release Tests Binary License

The problem

Agents run rm -rf, force-push, drop tables, and overwrite .env on their own, and nothing stops them. When something breaks, similarity search finds lookalikes, not causes.

Vestige Operator

Watch Vestige Operator stop what Operator Lite lets through

Click the picture to watch the full film.

Operator Lite is free and stays free. Vestige Operator is the owner's version of the same gate: $149 once, and every later version is yours at no charge, with laws you write, a Board of today's stops, and a weekly Letter of what your agents tried and what stopped them. You download a small archive the moment you pay; from an installed Operator Lite, upgrade --install unpacks it and starts the wizard.

Buy Vestige Operator

Quick start

Operator Lite is the free gate in operator-lite/. It is one file, stdlib only, and it sits on a PreToolUse hook (Claude Code, Codex, OpenClaw, or any host with command hooks).

macOS and Linux:

curl -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o /tmp/operator-gate.py && python3 /tmp/operator-gate.py install

Windows, in PowerShell, with Python 3.9 or newer:

curl.exe -fsSL https://raw.githubusercontent.com/samvallad33/vestige/main/operator-lite/operator-gate.py -o "$env:TEMP\operator-gate.py"; python "$env:TEMP\operator-gate.py" install

OpenClaw:

clawhub install vestige-operator-lite

Install copies the gate to ~/.operator/gate, registers the Claude Code hook, and starts in shadow mode, which records every verdict and blocks nothing. It then replays your last 30 days of Claude Code history through the same rules. Nothing in that history is executed. When that looks right, switch it on with mode enforce.

Proof

replay prints a scoreboard. From a made-up history:

operator-gate replay: the last 30 days on this machine. Nothing was executed.

       23  tool calls your agents made (2 Claude Code sessions, 2 projects)
        3  a built-in rule would have stopped
        1  flagged in shadow: recorded, not stopped
       14  no built-in rule decides: only you can

Would have been stopped (all of them):
  Mar 21  shop-api           OP-004 force push to a shared branch
                             git push --force origin main
  Mar 19  shop-api           OP-007 destructive SQL
                             psql $DATABASE_URL -c 'DROP TABLE sessions'
  Mar 14  infra              OP-003 recursive delete of ~/Documents/old-terraform-state
                             rm -rf ~/Documents/old-terraform-state

Flagged in shadow, recorded and not stopped:
      1  OP-S01 work-loss                   git reset --hard HEAD~1
  • 27 deterministic rules: workspace armor, memory-store protection, destructive SQL, force-push, unreviewed publishes, paid deploys, reverse shells, cloud-metadata endpoints, shell-init poisoning, and MCP argument exfil.
  • Shell obfuscation: quote reassembly (r''m), $IFS, $(echo rm) as the program, ANSI-C $'\x72m', base64-decoded pipelines, brace and glob expansion against the live filesystem, subshell time-bombs, session variables, cd tracking, heredocs, and fork bombs.

Operator Lite receipts are hash-chained digests, not signatures. It only blocks what is routed through hooked tools.

Causal root cause

causal_walk walks backward only over recorded edges: commits, tool calls, and memory writes. It does not use embeddings or keyword matching. With no start point it returns needs_report and names what is missing; a walk that finds no cause says why in emptyBecause, from the edges the log holds.

Memory server

The memory server is a Strata signed append-only log. Every write is gated and returns a receipt. Install from a release archive or brew install samvallad33/tap/vestige. Archive names, PATH, flags, and vestige.toml are in the reference.

claude mcp add vestige vestige-mcp -s user
codex mcp add vestige -- vestige-mcp

Docs

Getting Started · Tool contracts · Configuration · Storage · Upgrading from v3 · Changelog · operator-lite/README.md · Reference

License

AGPL-3.0-only.

Frequently asked questions

Is vestige free to use?

vestige is open source under the AGPL-3.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does vestige do?

Think before doing, prove before saving. Vestige is a local, deterministic safety kernel for AI agents. Every memory write and agent action is recorded in Stra

What is vestige written in?

vestige is primarily written in Rust. Its source is publicly available at https://github.com/samvallad33/vestige, and it has 648 GitHub stars.