# NEOTH

> Local-first personal AI daemon in Rust — five-tier memory, consent-gated tools, WASM plugin sandbox, multi-provider LLM routing, channels, GUI, signed audit logs, and Babel-Index collapse prediction on its own runtime.

- **Type:** MCP server
- **Install:** `agentstack add mcp-the-geek-freaks-neoth`
- **Verified:** Pending review
- **Seller:** [The-Geek-Freaks](https://agentstack.voostack.com/s/the-geek-freaks)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [The-Geek-Freaks](https://github.com/The-Geek-Freaks)
- **Source:** https://github.com/The-Geek-Freaks/NEOTH
- **Website:** https://deepwiki.com/The-Geek-Freaks/NEOTH

## Install

```sh
agentstack add mcp-the-geek-freaks-neoth
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

NEOTH

Your private AI buddy. Loyal to you. Useful everywhere.

  One memory. Three brain paths. Five memory tiers + your vault. Local-first by default.

  NEOTH is the personal AI system for people who want a real assistant, not a
  forgetful chatbot. It remembers what you approve, helps in daily life, codes
  seriously, connects to your tools, runs on your own machine, and leaves typed
  audit proof for its governed sensitive paths, with exceptions documented in
  the threat model.

  Normal user? Open the GUI and talk — no YAML.
  &nbsp;·&nbsp; Pro? Every claim has a CLI command that proves it.
  &nbsp;·&nbsp; Skeptic? 15 minutes, proof on your own machine.

  Install
  · Why NEOTH
  · Demos
  · DAUs + Pros
  · Privacy
  · Coding
  · Babel-Index
  · Comparison
  · Docs

  
    
  
  
    
  
  
    
  
  
    
  
  
    
  
  
    
  

## Install

> The source tree is versioned for **NEOTH 1.0.0**, but no `v1.0.0` release or
> crates.io package exists yet. The current working install path is the source
> checkout below. The bootstrap commands become valid only after the first
> compatible signed release is published; `cargo install neoth --locked --features release-desktop`
> becomes valid
> only after the ordered SDK + core crates.io publication completes.

Current install (source checkout):

```bash
git clone https://github.com/The-Geek-Freaks/NEOTH
cd NEOTH
NEOTH_SRC_DIR="$PWD" bash scripts/install.sh
neoth gui
```

The all-components source installer needs Node.js 22.16+ to compile the Keet
standalone. Signed desktop archives bundle it and need no Node.js.

After the first signed release, one-command install (Linux/macOS):

```bash
curl -fsSL https://raw.githubusercontent.com/The-Geek-Freaks/NEOTH/main/SRC/install.sh | bash
export PATH="$HOME/.local/bin:$PATH" # profile wiring applies automatically to new shells
neoth gui
```

The binary installer always verifies SHA-256 plus release authenticity. It uses
an installed `minisign` with the
[pinned public key](NEOTH_RELEASE_MINISIGN_PUBKEY.txt), an installed `cosign`, or
downloads a temporary Cosign verifier whose platform SHA-256 is pinned to an
immutable official Sigstore source commit. A clean machine therefore needs no
preinstalled verifier. A downloaded verifier with the wrong digest is never
executed; `NEOTH_ALLOW_UNVERIFIED_RECOVERY=1` applies only when the verifier
cannot be downloaded and the archive was authenticated out of band.

Desktop archives contain `neoth`, the `neothd` compatibility launcher, the
separate `neothd-gui` binary consumed by `neoth gui`, `neoth-migrate`, and
`neoth-relay`, plus the zero-dependency `neoth-keet-bridge` standalone. Only the
explicitly headless musl server archive omits the GUI and the glibc-linked Keet
companion.
The future crates.io package installs only the `neoth`/`neothd` core package;
use a release archive or source checkout for the companion executables.

After the first signed release, Windows users can download and double-click the
signed `NEOTH-1.0.0-x64-Setup.exe` (or ARM64 variant) on the Releases page. The
zero-prompt PowerShell alternative is:

```powershell
irm https://raw.githubusercontent.com/The-Geek-Freaks/NEOTH/main/SRC/install.ps1 | iex
neoth gui
```

Then run the health check:

```bash
neoth doctor
neoth doctor --explain "freedom.yaml"
```

The wizard asks normal questions: who you are, what NEOTH may remember, whether
you want local-only or cloud providers, which channels to connect, and how much
autonomy NEOTH gets. YAML is optional. The happy path is a GUI path.

## Demo Loops

| First run | Memory proof |
| :-- | :-- |
|  |  |

| Coding buddy | Privacy audit |
| :-- | :-- |
|  |  |

## Why NEOTH

Most AI tools are brilliant strangers. They can answer one prompt, but they do
not really know you, cannot prove what they remembered, and quietly move the
trust boundary to someone else's backend.

NEOTH is built around a different promise:

> The AI should be loyal to the user, not to a platform.

That means:

| Principle | What it means in practice |
| :-- | :-- |
| **Your memory** | Profile facts, project context, decisions, and recall live in your NEOTH home. |
| **Your consent** | Sensitive profile changes, provider routes, plugins, and external actions are inspectable. |
| **Your tools** | CLI, GUI, chat channels, Obsidian, Paperless, CalDAV calendar, optional source-build IMAP email, n8n, local models, and private mesh. |
| **Your proof** | WAL-backed audit, evidence-linked profile facts, plugin capability logs, and privacy commands. |
| **Your upgrade path** | Starts simple, scales into a serious operator runtime without switching products. |

## For Normal Users And Pros

NEOTH is deliberately not only for developers. The core product is a buddy that
can be used by a normal person, while still staying deep enough for a senior
operator.

| If you are a normal user | If you are a pro |
| :-- | :-- |
| Open the GUI and talk normally. | Use the CLI, local models, WAL, policies, plugins, and cluster commands. |
| Say "remember this" and approve what matters. | Inspect exact evidence, confidence, provider destination, and redaction state. |
| Connect Telegram, Slack, WhatsApp, Obsidian, Paperless, and CalDAV calendar; source builds can opt into IMAP triage. | Script workflows, bind n8n, define hooks, use MCP, and review plugin capabilities. |
| Ask "what did we decide?" and get useful recall. | Run `neoth recall`, `neoth verify`, `neoth privacy audit`, `neoth plugin ledger`. |
| Let NEOTH explain setup problems in plain language. | Pipe `neoth doctor --output json` into CI or fleet checks. |

## What NEOTH Does

| Area | 1.0 target behavior |
| :-- | :-- |
| **Buddy** | Keeps a durable personal profile, remembers approved facts, adapts to your style, and asks before crossing trust boundaries. |
| **Brain** | Routes work through role-bound brain paths for fast answers, deeper reasoning, and verification. |
| **Memory** | Uses five durable memory tiers — episode, profile, ground truth, consolidated, long-term — plus your external vault (Obsidian/Paperless) ingested into them. |
| **Daily life** | Ingests Paperless documents, CalDAV calendar, notes, files, images, audio, and video into reviewable memory; IMAP inbox triage is a source-build opt-in and has no SMTP/send path. |
| **Coding** | Plans work, tracks tasks on a canvas/Kanban board, runs checks, learns repo context, and promotes reviewed decisions into memory. |
| **Self-diagnosis** | Scores its own event stream for collapse risk (Babel-Index): seven variables per rolling window, pre-registered failure labels, early warning before the agent loop — not after. |
| **Self-reflection** | Looks back on its own work — weekly topic recap plus opt-in daily and yearly summaries archived and written to Obsidian as daily notes / yearly summaries — runs an opt-in weekly Hacker News tech-currency scan that flags trending topics your skills don't cover, and proposes review-gated SkillOpt improvements to its own skills (never auto-applied). |
| **Self-evolution** | Dreams nightly (`neoth dream now`): clusters the week's episodes into themes and writes them to Obsidian. Proposes, council-reviews, and applies upgrades to its own skills with rollback (`neoth self-improve`). Notices its own behavioral patterns and proposes changes you approve or decline (`neoth self-dev`). Distills tool sequences you repeat into candidate skills (`neoth distill`). |
| **Migration** | Brings your history with you: `neoth-migrate detect` discovers complete OpenClaw, Hermes, OpenHuman, and Veronica homes; dry-run previews them and consent-gated atomic apply imports their local memory as reviewable candidates. `neoth import session` covers Claude Code / Codex / Gemini transcripts, and `neoth transfer export` moves whole memories between machines as X25519-encrypted, Ed25519-signed bundles. |
| **Autonomy** | Four built-in levels (`strict` through `full`) plus `custom`: a Standard baseline with exhaustive per-action `allow` / `confirm` / `deny` overrides in `freedom.yaml`; `neoth permissions show/check/set/clear` exposes and edits the active policy atomically. Custom cannot weaken Full's hard safety floor, and unattended cron/auto-update stay fail-closed; one-word `neoth sudomode`; your own plain-YAML constitution is injected before every prompt (`neoth moral-core`). |
| **Gateway** | OpenAI-compatible endpoint (`/v1/chat/completions`): point Cursor, Aider, or Continue at NEOTH and every call gets your provider routing, council, and audit trail. |
| **Loops** | `neoth loop run "" --until ""` — bounded autonomous iteration with L1-L3 budget ladders, full history in `neoth loop history`. |
| **Recon** | Authorized-engagement recon through gated `uncover` (exposed-host discovery) and `tlsx` (TLS/cert intel) shims — refused under Strict autonomy and audit-logged. |
| **Automation** | Runs small local cron jobs and larger n8n workflows through a default-off, scoped localhost API with endpoint-specific consent and WAL auditing. |
| **Channels** | One canonical GUI/CLI registry for Telegram, Slack, WhatsApp Business, repository-owned WhatsApp Web/Baileys, Discord, Signal, LINE, IRC, iMessage through BlueBubbles, Mattermost, Google Chat, Matrix, Twitch, Nostr, and the full-duplex Keet-identity Pear/Hyperswarm companion. Read-only live probes are shared by both surfaces, and hot credential rotation restarts only the affected adapter. The Keet companion creates private NEOTH topics; it does not claim access to existing Keet app rooms because no supported room/message API exists. |
| **Private mesh** | Pairs nodes over LAN/mDNS, Tailscale, Hysteria, and consent-gated cluster discovery. |
| **Plugins** | Loads skills and WASM plugins behind capability gates, signature checks, revocation, and hostcall audit. |
| **Doctor** | Explains broken setup, missing keys, model cache problems, channel wiring, disk issues, plugin state, provider flapping, and cluster discovery. |

## Privacy

NEOTH is local-first and fail-closed by design.

| Guarantee | How to verify |
| :-- | :-- |
| **No silent profile extraction to cloud** | `neoth privacy audit --last 30d` (recent provider calls + profile writes + channel egress) |
| **No silent provider fallback** | `neoth provider list` and `neoth wal show --type provider_fallback_attempted` (every 429 failover is a durable audit frame) |
| **No ambient plugin power** | `neoth plugin ledger` (capabilities used) and `neoth wal show --type plugin_cap_denied` (over-level calls refused at runtime) |
| **No invisible memory mutation** | `neoth profile pending` and `neoth profile show` |
| **No unverifiable history** | `neoth verify` |
| **No accidental channel writes** | approval policy plus WAL events for outbound actions |

Local-only mode is a first-class path:

```bash
neoth preset activate fully-local
neoth preset apply fully-local
neoth doctor
neoth privacy audit --last 30d
```

Read the full privacy model in [docs/privacy.md](docs/privacy.md).

> **Security-research skills ship enabled by default.** NEOTH bundles three dual-use
> registers — `lowkey_base` (authorised security research / defensive analysis), `raskal`
> (authorised red-team / offensive-tooling), and `archon` (meta-reasoning orchestrator).
> They are operator-authorisation-scoped — they refuse mass-harm, untargeted destruction,
> and out-of-scope targets — and ship **enabled** so an authorised pentester gets working
> tooling instead of refusals. Don't want them? Disable any subset in `freedom.yaml`:
>
> ```yaml
> skills:
>   disabled:
>     - raskal
>     - archon
> ```
>
> (Or suppress *all* skill injection for benchmark/eval runs with
> `skills.disabled_for_eval_sessions: true`.)

## Why it holds up

The differentiators are mechanisms you can inspect, not slogans.

Governed sensitive paths emit typed events into an append-only, HMAC-chained
WAL — and you get the commands to prove what was recorded: `neoth verify`
(chain integrity),
`neoth wal show --type ` (every frame of one kind), `neoth privacy audit --last 30d`
(recorded provider/channel/privacy activity). Audit coverage and explicit
best-effort or log-only exceptions are listed in the
[threat model](docs/security/threat-model.md); chain verification proves that
recorded frames were not altered, not that every possible side effect emitted
a frame.

A WASM plugin built against the versioned `neoth-plugin-sdk` guest ABI exports
`neoth_abi_version() -> i32` plus `neoth_run() -> i32`; the daemon checks ABI v1
before execution. It can only use the hostcalls its manifest declared and you
approved at `neoth plugin enable`.
That approval is bound to the exact permission, canonical
manifest digest, and WASM digest: any later semantic manifest, capability, or binary
change cannot load on the next daemon start until you explicitly re-enable it. The
running daemon keeps only its already-validated immutable module, approval, and
manifest-derived fuel/memory-limit snapshot. A call
above the approved level is refused fail-closed at runtime and recorded as a
`0xC7 PLUGIN_CAP_DENIED` audit frame — visible in
`neoth wal show --type plugin_cap_denied`, never silent.

Crossing a trust boundary — cloud call, profile-to-cloud extract, channel egress,
plugin capability, autonomy raise — is denied by default until you grant it once,
on purpose. Both the grant and the refusal are logged.

Any model id passes through the provider layer with no hardcoded whitelist; the
managed CLIs (claude-cli / codex / antigravity) self-update and the model catalog is
discovered at runtime — so a new model ships and NEOTH already routes to it, no source
patch.

## Coding Buddy

NEOTH is not a coding toy bolted onto a chat app. The coding path is designed
for visible planning, reviewable execution, and memory that improves future
work.

| Step | What NEOTH does |
| :-- | :-- |
| **Plan** | Turns a request into a scoped plan, risk list, and acceptance checks. |
| **Map** | Reads repo context, prior decisions, docs, issue state, and coding memory. |
| **Track** | Keeps backlog, todo, in-progress, review, done, blocked, and archived states visible. |
| **Execute** | Runs local checks, cargo/test/lint loops, and targeted implementation flows. |
| **Review** | Separates code generation from review, promotes only validated decisions into memory. |
| **Improve** | Learns repo conventions and recurring fixes without swallowing secrets or unapproved facts. |

Operator commands:

```bash
neoth code "plan the auth refactor"
neoth kanban watch
neoth code check
neoth recall "why did we choose this storage layout?"
```

## Brain And Memory

NEOTH uses role separation because a loyal assistant should not treat every task
as one giant prompt.

| System | Job |
| :-- | :-- |
| **Left path** | Fast, pragmatic help, routing, daily buddy work, small tasks. |
| **Right path** | Deeper reasoning, planning, alternatives, difficult code and architecture. |
| **Corpus callosum** | Arbitration, evidence collection, contradiction handling, consensus, escalation. |
| **Five memory tiers + vault** | Short recall, personal profile, ground truth anchors, consolidated facts, long-term knowledge — plus ingested external-vault context. |

The point is not mystical branding. The point is operational separation: fast
tasks stay fast, serious tasks get more scrutiny, and durable memory gets
evidence instead of vibes.

Each path binds to its own provider — Anthropic on the left, a local model on
the right, OpenRouter as arbiter, any mix you want — and hard questions go to
a **council**: the paths argue, dissent is recorded, and the runtime tracks
which path wins which kind of argument over time and reweights routing
accordingly.

```bash
neoth hemispheres set --role right --provider local_ouro
neoth council voices
neoth ecology winner-chain   # who has been winning the arguments, and why
```

Facts you never want the model to overwrite live in a separate register:
`neoth groundtruth add` pins them immu

…

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [The-Geek-Freaks](https://github.com/The-Geek-Freaks)
- **Source:** [The-Geek-Freaks/NEOTH](https://github.com/The-Geek-Freaks/NEOTH)
- **License:** Apache-2.0
- **Homepage:** https://deepwiki.com/The-Geek-Freaks/NEOTH

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: flagged — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-the-geek-freaks-neoth
- Seller: https://agentstack.voostack.com/s/the-geek-freaks
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
