Install
$ agentstack add mcp-the-geek-freaks-neoth Open-source listing — not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Pipes remote content directly into a shell (remote code execution).
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
NEOTH
Your private AI buddy. Loyal to you. Useful everywhere.
One memory. Three brain paths. Five memory tiers + your vault. Local-first by default.
NEOTH is the personal AI system for people who want a real assistant, not a forgetful chatbot. It remembers what you approve, helps in daily life, codes seriously, connects to your tools, runs on your own machine, and leaves typed audit proof for its governed sensitive paths, with exceptions documented in the threat model.
Normal user? Open the GUI and talk — no YAML. · Pro? Every claim has a CLI command that proves it. · Skeptic? 15 minutes, proof on your own machine.
Install · Why NEOTH · Demos · DAUs + Pros · Privacy · Coding · Babel-Index · Comparison · Docs
Install
> The source tree is versioned for NEOTH 1.0.0, but no v1.0.0 release or > crates.io package exists yet. The current working install path is the source > checkout below. The bootstrap commands become valid only after the first > compatible signed release is published; cargo install neoth --locked --features release-desktop > becomes valid > only after the ordered SDK + core crates.io publication completes.
Current install (source checkout):
git clone https://github.com/The-Geek-Freaks/NEOTH
cd NEOTH
NEOTH_SRC_DIR="$PWD" bash scripts/install.sh
neoth gui
The all-components source installer needs Node.js 22.16+ to compile the Keet standalone. Signed desktop archives bundle it and need no Node.js.
After the first signed release, one-command install (Linux/macOS):
curl -fsSL https://raw.githubusercontent.com/The-Geek-Freaks/NEOTH/main/SRC/install.sh | bash
export PATH="$HOME/.local/bin:$PATH" # profile wiring applies automatically to new shells
neoth gui
The binary installer always verifies SHA-256 plus release authenticity. It uses an installed minisign with the [pinned public key](NEOTHRELEASEMINISIGN_PUBKEY.txt), an installed cosign, or downloads a temporary Cosign verifier whose platform SHA-256 is pinned to an immutable official Sigstore source commit. A clean machine therefore needs no preinstalled verifier. A downloaded verifier with the wrong digest is never executed; NEOTH_ALLOW_UNVERIFIED_RECOVERY=1 applies only when the verifier cannot be downloaded and the archive was authenticated out of band.
Desktop archives contain neoth, the neothd compatibility launcher, the separate neothd-gui binary consumed by neoth gui, neoth-migrate, and neoth-relay, plus the zero-dependency neoth-keet-bridge standalone. Only the explicitly headless musl server archive omits the GUI and the glibc-linked Keet companion. The future crates.io package installs only the neoth/neothd core package; use a release archive or source checkout for the companion executables.
After the first signed release, Windows users can download and double-click the signed NEOTH-1.0.0-x64-Setup.exe (or ARM64 variant) on the Releases page. The zero-prompt PowerShell alternative is:
irm https://raw.githubusercontent.com/The-Geek-Freaks/NEOTH/main/SRC/install.ps1 | iex
neoth gui
Then run the health check:
neoth doctor
neoth doctor --explain "freedom.yaml"
The wizard asks normal questions: who you are, what NEOTH may remember, whether you want local-only or cloud providers, which channels to connect, and how much autonomy NEOTH gets. YAML is optional. The happy path is a GUI path.
Demo Loops
| First run | Memory proof | | :-- | :-- | | | |
| Coding buddy | Privacy audit | | :-- | :-- | | | |
Why NEOTH
Most AI tools are brilliant strangers. They can answer one prompt, but they do not really know you, cannot prove what they remembered, and quietly move the trust boundary to someone else's backend.
NEOTH is built around a different promise:
> The AI should be loyal to the user, not to a platform.
That means:
| Principle | What it means in practice | | :-- | :-- | | Your memory | Profile facts, project context, decisions, and recall live in your NEOTH home. | | Your consent | Sensitive profile changes, provider routes, plugins, and external actions are inspectable. | | Your tools | CLI, GUI, chat channels, Obsidian, Paperless, CalDAV calendar, optional source-build IMAP email, n8n, local models, and private mesh. | | Your proof | WAL-backed audit, evidence-linked profile facts, plugin capability logs, and privacy commands. | | Your upgrade path | Starts simple, scales into a serious operator runtime without switching products. |
For Normal Users And Pros
NEOTH is deliberately not only for developers. The core product is a buddy that can be used by a normal person, while still staying deep enough for a senior operator.
| If you are a normal user | If you are a pro | | :-- | :-- | | Open the GUI and talk normally. | Use the CLI, local models, WAL, policies, plugins, and cluster commands. | | Say "remember this" and approve what matters. | Inspect exact evidence, confidence, provider destination, and redaction state. | | Connect Telegram, Slack, WhatsApp, Obsidian, Paperless, and CalDAV calendar; source builds can opt into IMAP triage. | Script workflows, bind n8n, define hooks, use MCP, and review plugin capabilities. | | Ask "what did we decide?" and get useful recall. | Run neoth recall, neoth verify, neoth privacy audit, neoth plugin ledger. | | Let NEOTH explain setup problems in plain language. | Pipe neoth doctor --output json into CI or fleet checks. |
What NEOTH Does
| Area | 1.0 target behavior | | :-- | :-- | | Buddy | Keeps a durable personal profile, remembers approved facts, adapts to your style, and asks before crossing trust boundaries. | | Brain | Routes work through role-bound brain paths for fast answers, deeper reasoning, and verification. | | Memory | Uses five durable memory tiers — episode, profile, ground truth, consolidated, long-term — plus your external vault (Obsidian/Paperless) ingested into them. | | Daily life | Ingests Paperless documents, CalDAV calendar, notes, files, images, audio, and video into reviewable memory; IMAP inbox triage is a source-build opt-in and has no SMTP/send path. | | Coding | Plans work, tracks tasks on a canvas/Kanban board, runs checks, learns repo context, and promotes reviewed decisions into memory. | | Self-diagnosis | Scores its own event stream for collapse risk (Babel-Index): seven variables per rolling window, pre-registered failure labels, early warning before the agent loop — not after. | | Self-reflection | Looks back on its own work — weekly topic recap plus opt-in daily and yearly summaries archived and written to Obsidian as daily notes / yearly summaries — runs an opt-in weekly Hacker News tech-currency scan that flags trending topics your skills don't cover, and proposes review-gated SkillOpt improvements to its own skills (never auto-applied). | | Self-evolution | Dreams nightly (neoth dream now): clusters the week's episodes into themes and writes them to Obsidian. Proposes, council-reviews, and applies upgrades to its own skills with rollback (neoth self-improve). Notices its own behavioral patterns and proposes changes you approve or decline (neoth self-dev). Distills tool sequences you repeat into candidate skills (neoth distill). | | Migration | Brings your history with you: neoth-migrate detect discovers complete OpenClaw, Hermes, OpenHuman, and Veronica homes; dry-run previews them and consent-gated atomic apply imports their local memory as reviewable candidates. neoth import session covers Claude Code / Codex / Gemini transcripts, and neoth transfer export moves whole memories between machines as X25519-encrypted, Ed25519-signed bundles. | | Autonomy | Four built-in levels (strict through full) plus custom: a Standard baseline with exhaustive per-action allow / confirm / deny overrides in freedom.yaml; neoth permissions show/check/set/clear exposes and edits the active policy atomically. Custom cannot weaken Full's hard safety floor, and unattended cron/auto-update stay fail-closed; one-word neoth sudomode; your own plain-YAML constitution is injected before every prompt (neoth moral-core). | | Gateway | OpenAI-compatible endpoint (/v1/chat/completions): point Cursor, Aider, or Continue at NEOTH and every call gets your provider routing, council, and audit trail. | | Loops | neoth loop run "" --until "" — bounded autonomous iteration with L1-L3 budget ladders, full history in neoth loop history. | | Recon | Authorized-engagement recon through gated uncover (exposed-host discovery) and tlsx (TLS/cert intel) shims — refused under Strict autonomy and audit-logged. | | Automation | Runs small local cron jobs and larger n8n workflows through a default-off, scoped localhost API with endpoint-specific consent and WAL auditing. | | Channels | One canonical GUI/CLI registry for Telegram, Slack, WhatsApp Business, repository-owned WhatsApp Web/Baileys, Discord, Signal, LINE, IRC, iMessage through BlueBubbles, Mattermost, Google Chat, Matrix, Twitch, Nostr, and the full-duplex Keet-identity Pear/Hyperswarm companion. Read-only live probes are shared by both surfaces, and hot credential rotation restarts only the affected adapter. The Keet companion creates private NEOTH topics; it does not claim access to existing Keet app rooms because no supported room/message API exists. | | Private mesh | Pairs nodes over LAN/mDNS, Tailscale, Hysteria, and consent-gated cluster discovery. | | Plugins | Loads skills and WASM plugins behind capability gates, signature checks, revocation, and hostcall audit. | | Doctor | Explains broken setup, missing keys, model cache problems, channel wiring, disk issues, plugin state, provider flapping, and cluster discovery. |
Privacy
NEOTH is local-first and fail-closed by design.
| Guarantee | How to verify | | :-- | :-- | | No silent profile extraction to cloud | neoth privacy audit --last 30d (recent provider calls + profile writes + channel egress) | | No silent provider fallback | neoth provider list and neoth wal show --type provider_fallback_attempted (every 429 failover is a durable audit frame) | | No ambient plugin power | neoth plugin ledger (capabilities used) and neoth wal show --type plugin_cap_denied (over-level calls refused at runtime) | | No invisible memory mutation | neoth profile pending and neoth profile show | | No unverifiable history | neoth verify | | No accidental channel writes | approval policy plus WAL events for outbound actions |
Local-only mode is a first-class path:
neoth preset activate fully-local
neoth preset apply fully-local
neoth doctor
neoth privacy audit --last 30d
Read the full privacy model in [docs/privacy.md](docs/privacy.md).
> Security-research skills ship enabled by default. NEOTH bundles three dual-use > registers — lowkey_base (authorised security research / defensive analysis), raskal > (authorised red-team / offensive-tooling), and archon (meta-reasoning orchestrator). > They are operator-authorisation-scoped — they refuse mass-harm, untargeted destruction, > and out-of-scope targets — and ship enabled so an authorised pentester gets working > tooling instead of refusals. Don't want them? Disable any subset in freedom.yaml: > > ``yaml > skills: > disabled: > - raskal > - archon > ` > > (Or suppress *all* skill injection for benchmark/eval runs with > skills.disabledforeval_sessions: true`.)
Why it holds up
The differentiators are mechanisms you can inspect, not slogans.
Governed sensitive paths emit typed events into an append-only, HMAC-chained WAL — and you get the commands to prove what was recorded: neoth verify (chain integrity), neoth wal show --type (every frame of one kind), neoth privacy audit --last 30d (recorded provider/channel/privacy activity). Audit coverage and explicit best-effort or log-only exceptions are listed in the [threat model](docs/security/threat-model.md); chain verification proves that recorded frames were not altered, not that every possible side effect emitted a frame.
A WASM plugin built against the versioned neoth-plugin-sdk guest ABI exports neoth_abi_version() -> i32 plus neoth_run() -> i32; the daemon checks ABI v1 before execution. It can only use the hostcalls its manifest declared and you approved at neoth plugin enable. That approval is bound to the exact permission, canonical manifest digest, and WASM digest: any later semantic manifest, capability, or binary change cannot load on the next daemon start until you explicitly re-enable it. The running daemon keeps only its already-validated immutable module, approval, and manifest-derived fuel/memory-limit snapshot. A call above the approved level is refused fail-closed at runtime and recorded as a 0xC7 PLUGIN_CAP_DENIED audit frame — visible in neoth wal show --type plugin_cap_denied, never silent.
Crossing a trust boundary — cloud call, profile-to-cloud extract, channel egress, plugin capability, autonomy raise — is denied by default until you grant it once, on purpose. Both the grant and the refusal are logged.
Any model id passes through the provider layer with no hardcoded whitelist; the managed CLIs (claude-cli / codex / antigravity) self-update and the model catalog is discovered at runtime — so a new model ships and NEOTH already routes to it, no source patch.
Coding Buddy
NEOTH is not a coding toy bolted onto a chat app. The coding path is designed for visible planning, reviewable execution, and memory that improves future work.
| Step | What NEOTH does | | :-- | :-- | | Plan | Turns a request into a scoped plan, risk list, and acceptance checks. | | Map | Reads repo context, prior decisions, docs, issue state, and coding memory. | | Track | Keeps backlog, todo, in-progress, review, done, blocked, and archived states visible. | | Execute | Runs local checks, cargo/test/lint loops, and targeted implementation flows. | | Review | Separates code generation from review, promotes only validated decisions into memory. | | Improve | Learns repo conventions and recurring fixes without swallowing secrets or unapproved facts. |
Operator commands:
neoth code "plan the auth refactor"
neoth kanban watch
neoth code check
neoth recall "why did we choose this storage layout?"
Brain And Memory
NEOTH uses role separation because a loyal assistant should not treat every task as one giant prompt.
| System | Job | | :-- | :-- | | Left path | Fast, pragmatic help, routing, daily buddy work, small tasks. | | Right path | Deeper reasoning, planning, alternatives, difficult code and architecture. | | Corpus callosum | Arbitration, evidence collection, contradiction handling, consensus, escalation. | | Five memory tiers + vault | Short recall, personal profile, ground truth anchors, consolidated facts, long-term knowledge — plus ingested external-vault context. |
The point is not mystical branding. The point is operational separation: fast tasks stay fast, serious tasks get more scrutiny, and durable memory gets evidence instead of vibes.
Each path binds to its own provider — Anthropic on the left, a local model on the right, OpenRouter as arbiter, any mix you want — and hard questions go to a council: the paths argue, dissent is recorded, and the runtime tracks which path wins which kind of argument over time and reweights routing accordingly.
neoth hemispheres set --role right --provider local_ouro
neoth council voices
neoth ecology winner-chain # who has been winning the arguments, and why
Facts you never want the model to overwrite live in a separate register: neoth groundtruth add pins them immu
…
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: The-Geek-Freaks
- Source: The-Geek-Freaks/NEOTH
- License: Apache-2.0
- Homepage: https://deepwiki.com/The-Geek-Freaks/NEOTH
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.