No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by vouchdev · MCP Server · ★ 112
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is vouch safe to install? View the security audit →
vouch Git-native, review-gated knowledge base for LLM agents. MCP server + JSONL tool server + CLI. Agents should not start every session with amnesia — but they shouldn't get to write whatever they want either. is a knowledge base for LLM agents with an explicit review gate: agents propose writes; humans approve them with . Approved artifacts are plain files on disk — YAML for claims, markdown for pages — so the KB lives in your repo, is reviewed in PRs, diffs cleanly, and can be exported as a portable bundle. It also captures your Claude Code sessions automatically — each session's work is harvested and rolled up into a summary. But where the persistent-memory tools compress with an LLM an
| Stars | 112 |
| Forks | 65 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 67.8105602155907/100 |
| Open Issues | 43 |
| Last Updated | 2026-08-02 |
| Created | 2026-05-17 |
| Platforms | claude-code, cli, mcp, python |
| Est. Tokens | ~19k |
These tools work well together with vouch for enhanced workflows:
Looking for a vouch alternative? If you're comparing vouch with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Local-first AI PKM for coding conversations: import Claude Code/Cursor/Codex, distill notes, semantic search,
Open-source infrastructure for agents that learn from experience. Capture production traces and turn lessons i
Structural code intelligence for AI agents — semantic search, knowledge graphs, and a built-in MCP server in o
Daymon puts your favorite AI to work 24/7. It schedules, remembers, and orchestrates your own virtual team. Fr
GRACE (Graph-RAG Anchored Code Engineering): open Agent Skills for contract-driven AI code generation with sem
A collection of AI agent skills for Clawdbot, Claude Code, Codex
Explore other popular mcp server tools:
vouch is A git-native, review-gated knowledge base for AI agents: they propose writes, you approve them. Every claim cites a source, every change is a diff in your repo. MCP + CLI.. It is categorized as a MCP Server with 112 GitHub stars.
vouch is primarily written in Python. It covers topics such as agent-skills, ai, ai-brain.
You can find installation instructions and usage details in the vouch GitHub repository at github.com/vouchdev/vouch. The project has 112 stars and 65 forks, indicating an active community.
vouch is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to vouch on Agent Skills Hub include ChatCrystal, stash, octocode. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: