Pod

Available as Markdown and JSON. Pod is also available over MCP.

Reported issues for Gemdex

Pod holds 8 of 8 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to Gemdex.

Most discussed

spec: report_outcome tool + trust-weighted recall ranking (outcome feedback loop)

Full implementation spec for proposal 1 in #107. Companion spec: save-time conflict detection (proposal 3).

Summary

Add an outcome feedback loop to the memory layer: a new report_outcome MCP tool records whether a recalled memory worked, failed, or was stale; recall transparently counts how often each memory is surfaced; recall output shows each hit's track record; and an opt-in trust-weighted re-ranking boosts proven memories and demotes ones that burned the agent.…

Read the thread · 2026-07-21 · closed · 1 comment

Desktop app: support UI-approved first-launch sidecar dependency bootstrap

Goal

The packaged Gemdex desktop app should support full first-run onboarding from the UI. A user who installs and launches the app should not need to manually run sidecar commands or install Gemdex runtime dependencies outside the app.

Current gap

The desktop shell starts the sidecar with npx -y gemdex-mcp serve --port 0 (or GEMDEX_SERVE_CMD in development). If the required runtime path is unavailable or the sidecar cannot be started, the frontend can only show sidecar…

Read the thread · 2026-06-05 · closed · 1 comment

[GAP-02] Load memory-list thumbnails through authenticated attachment fetches

Metadata

Problem

Memory-list thumbnails assign the sidecar attachment route directly to img.src. Desktop sidecar requests require X-Gemdex-Token, which an image element cannot add, so thumbnail requests receive 401 responses. The editor already uses an authenticated…

Read the thread · 2026-06-05 · closed · 1 comment

[GAP-01] Add recovery UI when the active remote is unreachable at boot

Metadata

Problem

A configured remote causes /config to pass the setup gate, but if the remote is unreachable during initial memory loading the app only surfaces an error status. The setup screen remains hidden and there is no actionable route to…

Read the thread · 2026-06-05 · closed · 1 comment

Add desktop app remote mode settings

Expose BYOI remote mode in the desktop manager without moving auth secrets into frontend code.

Scope:

Acceptance criteria:

Read the thread · 2026-06-05 · closed · 1 comment

Add CLI commands for remote configuration and migration

Add user-facing commands for configuring and moving between local and BYOI remote mode.

Scope:

Acceptance criteria:

Read the thread · 2026-06-05 · closed · 1 comment

Wire gemdex-mcp to local and remote backend modes

Allow the MCP stdio server to use the local backend by default or a configured remote Gemdex Server when requested.

Scope:

Acceptance criteria:

Read the thread · 2026-06-05 · closed · 1 comment

Security: lock down gemdex serve CORS (currently Access-Control-Allow-Origin: *) + add an app auth/CSRF token

Problem

The localhost sidecar (gemdex serve, packages/mcp/src/serve.ts) responds with Access-Control-Allow-Origin: * (plus Allow-Methods: GET, POST, PUT, DELETE, OPTIONS) on all routes. The routes are unauthenticated, so any website the user visits can issue cross-origin requests to http://127.0.0.1:<port> and read /memories, /export, and (since #11) raw attachment bytes, or mutate state via POST/PUT/DELETE. Binding to 127.0.0.1 does not mitigate this (a browser on…

Read the thread · 2026-06-03 · closed · 0 comments

Most recent

The remaining reports are on the project's issue tracker.