# Reported issues for Gemdex

Pod holds 8 of 8 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [Gemdex](/mcp/gemdex).

## Most discussed

### spec: report_outcome tool + trust-weighted recall ranking (outcome feedback loop)

Full implementation spec for proposal **1** in #107. Companion spec: save-time conflict detection (proposal 3).

## Summary

Add an outcome feedback loop to the memory layer: a new `report_outcome` MCP tool records whether a recalled memory **worked**, **failed**, or was **stale**; `recall` transparently counts how often each memory is surfaced; recall output shows each hit's track record; and an **opt-in** trust-weighted re-ranking boosts proven memories and demotes ones that burned the agent.…

[Read the thread](https://github.com/nikships/gemdex/issues/108) · 2026-07-21 · closed · 1 comment

### Desktop app: support UI-approved first-launch sidecar dependency bootstrap

## Goal

The packaged Gemdex desktop app should support full first-run onboarding from the UI. A user who installs and launches the app should not need to manually run sidecar commands or install Gemdex runtime dependencies outside the app.

## Current gap

The desktop shell starts the sidecar with `npx -y gemdex-mcp serve --port 0` (or `GEMDEX_SERVE_CMD` in development). If the required runtime path is unavailable or the sidecar cannot be started, the frontend can only show sidecar…

[Read the thread](https://github.com/nikships/gemdex/issues/88) · 2026-06-05 · closed · 1 comment

### [GAP-02] Load memory-list thumbnails through authenticated attachment fetches

## Metadata

* Source: `remote_memory_gaps.html` / GAP-02
* Severity: Critical
* Component: Desktop memory list
* Layer: `packages/app/frontend/src/main.js` (`renderList()`, `fetchAttachmentObjectUrl()`)
* Reported effort: \~2 hours

## Problem

Memory-list thumbnails assign the sidecar attachment route directly to `img.src`. Desktop sidecar requests require `X-Gemdex-Token`, which an image element cannot add, so thumbnail requests receive 401 responses. The editor already uses an authenticated…

[Read the thread](https://github.com/nikships/gemdex/issues/59) · 2026-06-05 · closed · 1 comment

### [GAP-01] Add recovery UI when the active remote is unreachable at boot

## Metadata

* Source: `remote_memory_gaps.html` / GAP-01
* Severity: Critical
* Component: Desktop frontend boot/config gate
* Layer: `packages/app/frontend/src/main.js` (`syncConfigGate()`, `init()`, `loadMemories()`)
* Reported effort: \~3 hours

## Problem

A configured remote causes `/config` to pass the setup gate, but if the remote is unreachable during initial memory loading the app only surfaces an error status. The setup screen remains hidden and there is no actionable route to…

[Read the thread](https://github.com/nikships/gemdex/issues/58) · 2026-06-05 · closed · 1 comment

### Add desktop app remote mode settings

Expose BYOI remote mode in the desktop manager without moving auth secrets into frontend code.

Scope:

* Add storage mode settings: Local and Remote.
* Allow selecting/configuring a named remote through the local sidecar.
* Add connection test and auth-status display.
* Support import local memories to remote from the app.
* Keep long-lived tokens in the sidecar/config layer, not frontend JS state.

Acceptance criteria:

* Desktop app can browse/create/edit/delete/export/import against a…

[Read the thread](https://github.com/nikships/gemdex/issues/35) · 2026-06-05 · closed · 1 comment

### Add CLI commands for remote configuration and migration

Add user-facing commands for configuring and moving between local and BYOI remote mode.

Scope:

* Add gemdex remote add/list/remove/status commands.
* Add gemdex mode local and gemdex mode remote <name>.
* Add token configuration flow suitable for bearer-token deployments.
* Add import-local-to-remote migration command.

Acceptance criteria:

* Users can configure a remote without editing JSON by hand.
* Tokens are stored outside project repos and are not printed after entry.
* gemdex status…

[Read the thread](https://github.com/nikships/gemdex/issues/34) · 2026-06-05 · closed · 1 comment

### Wire gemdex-mcp to local and remote backend modes

Allow the MCP stdio server to use the local backend by default or a configured remote Gemdex Server when requested.

Scope:

* Select backend based on GEMDEX_MODE and configured remote name/env vars.
* Keep the public MCP tool list exactly save_memory, recall, update_memory.
* Keep attachment path resolution in MCP stdio handlers before remote upload.
* Provide clear startup/runtime errors when remote mode is misconfigured.

Acceptance criteria:

* Existing local MCP tests continue to pass.
*…

[Read the thread](https://github.com/nikships/gemdex/issues/33) · 2026-06-05 · closed · 1 comment

### Security: lock down `gemdex serve` CORS (currently `Access-Control-Allow-Origin: *`) + add an app auth/CSRF token

## Problem

The localhost sidecar (`gemdex serve`, `packages/mcp/src/serve.ts`) responds with `Access-Control-Allow-Origin: *` (plus `Allow-Methods: GET, POST, PUT, DELETE, OPTIONS`) on all routes. The routes are unauthenticated, so **any website the user visits can issue cross-origin requests** to `http://127.0.0.1:<port>` and read `/memories`, `/export`, and (since #11) raw attachment bytes, or mutate state via `POST`/`PUT`/`DELETE`. Binding to `127.0.0.1` does not mitigate this (a browser on…

[Read the thread](https://github.com/nikships/gemdex/issues/12) · 2026-06-03 · closed · 0 comments

## Most recent

The remaining reports are on [the project's issue tracker](https://github.com/nikships/gemdex/issues).
