@batalabs/virlow-mcp-core
v3.77.3
Published
Virlow MCP connector core: encrypted note and memory access, folder exposure, and the memories opt-in. Shared by the local virlow-mcp CLI and the hosted connector.
Readme
@batalabs/virlow-mcp-core
The connector core behind Virlow's MCP integration: encrypted note and memory access, folder exposure, and the memories opt-in.
Shared deliberately. The local virlow-mcp CLI and the hosted connector both
decide what an AI tool may read, and those rules — folders.mcpEnabled and the
account's memories setting — must have one implementation. Two copies of the
code that decides who can read what would drift, and drift there is a security
bug rather than an inconsistency.
What it does not contain: transports, the CLI, and the unlock user interface. Those differ between local and hosted and belong to their hosts.
Published from batalabs/virlow-app.
