What we've built.
Vodou is an AI operating system with persistent local memory, MCP tool orchestration and autonomous agents. Each entry below is one capability that shipped: what it does, what it cost to get there, and the part that transfers to whatever you're building. The engine internals stay closed; the lessons don't.
Themes: architecture (30) · ai-agents (30) · observability (24) · memory (13) · mcp (12) · llm (11) · retrieval (4) · security (3)
-
Your old frontend's service worker will outlive your redesign
Moving a redesigned agent console to '/' broke two things no diff showed: a cached service worker, and stream cursors that outlived a server restart.
-
Our memory ceiling logged ABORT while the file kept growing
A size ceiling enforced in one of three writers logged ABORT every cycle while the file grew. Five memory bugs where the guard lived in the wrong place.
-
Chrome refuses an iframe silently, and onload still fires
A shipped panel proxied to an opt-in process, then went blank behind frame-ancestors. Two failure classes, one five-minute check you can run on your own stack.
-
A 'new' badge is a lie unless something records when you looked
A sidebar of scheduled agents needs a per-viewer watermark, written when the list is actually on screen. Plus the surrogate-pair bug that ate an emoji title.
-
A trust pin with no undo is an outage you shipped on purpose
An extension-ID pin hardened our browser bridge and could refuse every other browser on the machine, permanently. What that lockout taught me about auto-trust.
Feature guide: Vodou Bridge, the AI memory extension
-
A parked human-in-the-loop prompt needs a clock, or a restart is your only exit
A workflow menu waited three days for a digit until a gateway restart freed it. Parked asks need a lazy TTL, a mismatch counter, and control words everywhere.
Feature guide: Agent skills
-
Your MCP audit table probably has no producer
The audit table existed since migration 046 and held zero rows for its whole life. What I found instrumenting both MCP client stacks, and three checks for yours.
Feature guide: MCP gateway
-
Nine agents in one worktree and each one knew only the branch name
How a daemon tells a coding session when a peer touched the same files: keyed on the transcript not the pid, silent unless the sets intersect.
Feature guide: Claude Code memory
-
The trust label your registry declares never reaches the model
Two memory searches per turn with no shared id, a THIS BLOCK WINS block that a budget could evict, and a trust field only a commit guard read. What fixing all three took.
Feature guide: AI harness
-
The runs panel said 'No runs recorded yet'. The ledger had every run.
A scheduler wrote a run ledger nobody served, a skill prompt dropped the user's words, and a spawnSync stalled the gateway 9.6 s. Three checks for your own stack.
Feature guide: AI agent automation
-
A console leaked one CSS class and hid 11 days of receipts
Two ways an agent console lied during a redesign: a view's opt-out class nothing removed, and a receipt table no page read. With a five-minute check for each.
-
Your first-run path is the only code that runs with defaults off
A liveness ping answered by the transport, and a demo riding a toggle that ships off. Two failures in one first-run path, plus the check to run on yours.
-
Two writers, one judge: how a review queue became 90% noise
A memory-conflict queue hit 1,377 rows on a vault with 33 real conflicts. One producer had an LLM judge and dismissed 97% of its own work. The other had none.
Feature guide: Persistent AI memory
-
Your message table is storing your UI, not your transcript
Four producers wrote into one turn and two baked HTML into storage. What it took to make the turn receipt a real event, and the SQL to check your own store.
Feature guide: Local AI agent
-
A skill that finishes into a tab nobody has open did not finish
Console-mode skills completed into a workbench nobody was looking at. How results got routed to the surface the user is on, and the sibling-tree trap that cost two days.
-
The renderer existed. Nothing on that surface ever called it.
A side panel drew agent plans perfectly and could not run one. Four presses found four bugs a green suite could not see, plus the delivery check that catches them.
-
66,570 characters reached the model and nothing logged them
I built a per-turn event log that rebuilds the exact request we sent, then measured the bytes it could not account for. The first number was 66,570.
-
Prompt injection defense that survives to turn 40
Page text an agent reads can outlive the turn as a stored memory and come back as trusted context. Two invariants: separate fields, and a turn-scoped approval gate.
-
Your agent's tool manifest is a comment until something reads it
A scheduled agent declared six MCP tools, called none of them, and reported ok. Enforcing that declaration at fire time cut selection from 1-of-942 to 1-of-6.
Feature guide: Agent harness
-
Your MCP allowlist controls tool names, not what they return
A read-only MCP profile still returned my cwd and MEMORY.md, because the disclosure was in the result envelope, not the tool list. How to check yours.
Feature guide: MCP gateway
-
A rule at byte 37,367 is not a rule if the cap is 32 KiB
Five AI coding hosts read five rules files in one repo. Mine had drifted for months, and the rule that mattered most sat past Codex's 32 KiB context cap.
-
Two tables both called 'skill', and nothing knew which was which
Vodou had 160 file skills and 15 console skills sharing one word. Every feature picked a table and called it the truth. Here is the seam and how to find yours.
Feature guide: Agent skills
-
Your MEMORY.md is a file nobody writes to. Render it instead.
An always-injected memory file got one bullet in four months while the store grew to 42k chunks. Rendering it per session from the DB, and what valid_at fixed.
Feature guide: Claude Code memory
-
A 400-byte cap crashed my memory daemon on one emoji
Two memory bugs with the same shape: a truncation that counted bytes, and a fact verifier whose 'approved everything' looked identical to 'never ran'. With a five-minute check for your own stack.
Feature guide: Persistent AI memory
-
Your document chunker is a memory chunker, and it quadruples your store
One 15,869-char file became 181 chunks. Fixing that exposed a scoring floor applied to two incomparable scales. Two invariants, one SQL check, for any RAG stack.
Feature guide: Persistent AI memory
-
Per-site memory off switches only work if every reader asks the same authority
Governing an agent's page memory took three enforcement points, a soft delete with a dry run, and a live test that found four defects the unit suites missed.
Feature guide: Vodou Bridge, the AI memory extension
-
Your Agent's Memory Has No Idea Where It Was
Agent memory stores what was said and drops where it happened. Adding a page axis to a memory store took four live-only defects and a per-site permission model.
Feature guide: Vodou Bridge, the AI memory extension
-
Your agent's approval gate is probably just a warning label
We shipped plan cards, real parallel tool calls and an approval gate for an MCP agent. The gate was decoration for two days, and the fan was never parallel.
Feature guide: AI orchestration
-
A silent failure looks exactly like a feature you never built
Shipping an agent surface into 22 chat sites we don't own: the Chrome gesture that doesn't survive an await, and three builds all claiming one version number.
Feature guide: Vodou Bridge, the AI memory extension
-
Every copy of the rule agreed. That was the bug.
Four surfaces minted the same token four different ways, and all four agreed. How we found the drift, why the tests couldn't see it, and the guard that now can.