Repository navigation
13.0.3 — MCP Registry, security policy, honest metadata
Nothing in the runtime changed. This release exists so the package carries
the metadata the wider ecosystem reads.
Added
server.jsonand anmcp-namemarker in the README, so the package can be
published to the official MCP Registry.
The registry verifies PyPI ownership by matching that marker against the
package description, which is why it needs a release rather than a commit.SECURITY.md— supported versions, private reporting through GitHub
Security Advisories, and a threat model that says plainly what is in scope
for a local-first server and what is not.CONTRIBUTING.md— development setup, thememory_core/ai_layerimport
rule thattests/test_v11_layer_separation.pyenforces, and the two rules
learned the hard way: tests must skip on absent gitignored corpora, and
benchmark runners must passrecord_usage=False.
Fixed
- The PyPI description advertised 46 tools; the server exposes 74. The
repository description on GitHub still quoted LongMemEval R@5 97.45%,
a number 13.0.0 retired when the runner stopped measuring its own
self-contained retrieval stack. Both now match the README: 74 tools,
95.1% R@5.