Memory
Individual Mnemosyne bank for every Forgejo identity.
Private agent infrastructure
Connect agents to tenant-isolated memory, private search, safe browser automation, live documentation, semantic code intelligence and Forgejo — without exposing your infrastructure.
Operational catalog
One bearer token and one compact tool bridge. Discover exact schemas on demand instead of loading every integration into context.
Individual Mnemosyne bank for every Forgejo identity.
Self-hosted metasearch through SearXNG.
Network-isolated Playwright automation with SSRF controls.
Version-aware library documentation through Context7.
Semantic navigation and targeted edits with Serena.
Approved remote repository packing with Repomix.
Repositories, issues and pull requests under user OAuth.
Policies, approvals, async jobs and privacy-safe audit.
Safe template-bound Remotion renders and temporary files.
Scoped Forgejo Actions status, dispatch and cancellation.
Signed webhooks and ntfy lifecycle events.
Live client configuration, skills and service guidance.
Security model
OAuth identity follows every request. The gateway enforces tenant ownership, scope, policy, confirmation and outbound network controls before a tool executes.
Forgejo OAuth with PKCE creates a short-lived account token. Every token maps to one identity and one memory bank.
Server policy evaluates tool risk, scopes and target metadata. Destructive operations bind approvals to exact arguments.
Calls emit privacy-safe audit metadata. Layered monitors verify gateway, response, dependency and authenticated behavior.
Quick connect
Download a verified bundle, choose initial MCP connections, then let the agent discover only the service and schema it needs.
# Linux / macOS
curl -fsSL https://git.barem.atractio.lol/rethinger/atractio-tool/raw/branch/main/install.sh | sh
# Windows PowerShell
irm https://git.barem.atractio.lol/rethinger/atractio-tool/raw/branch/main/install.ps1 | iex
# Store the token and choose compact or direct MCP
atractio-tool setup