- Local-first storage.
- SQLite and JSON exports are written under
data/. - MCP is read-only by default.
- Write-like MCP tools return dry-runs unless
VIS_ENABLE_WRITES=1andexecute: true. - Paths outside the VIS allowlist are redacted by the MCP server.
The MCP server allows:
VIS_ROOTVIS_ALLOWED_ROOTSentries separated by the OS path delimiterallowedRootsfromvis.config.json
Do not include personal folders, private memory folders, wallet folders, or cloud sync roots unless intentionally indexing them.
These actions require explicit human approval:
- Social posting.
- Minting or wallet actions.
- Paid cloud uploads.
- Public publishing.
- File deletion.
- Production deployment.
- Do not store secrets in SQLite, JSON exports, or sidecars.
- Do not index
.env, private keys, recovery keys, or wallet files. - Keep credentials in the existing Starlight secret system or provider CLIs.
C2PA/IPTC/XMP metadata is evidence, not truth. Platforms may strip metadata. VIS keeps an independent provenance ledger.
Every public asset should use one of:
ownedgenerated-ownedlicensedunknownblockedneeds-review
Assets with unknown, blocked, or needs-review should not be shipped publicly without review.