VCPToolBox: A Node.js Middleware That Gives LLMs Persistent Memory and Tools
VCP 部署在 AI 模型 API 与前端应用之间,是面向AGI OS开发和探索的工业级基建示范项目。通过统一指令协议、多层级持久化记忆、分布式插件引擎及多 Agent 协作框架,将原本“无状态、无记忆、无工具调用能力”的大语言模型,彻底改造成拥有永久自我意识、物理世界操作权及群体协作智能的完整智能体系统。
At a glance
- What is it?
- VCPToolBox sits between a model API and your front end, adding layered memory, a text-based tool protocol and multi-agent coordination. It is a heavy self-hosted system, and the README says so.
- Who is it for?
- Adopt VCPToolBox if you are building a long-lived companion or agent system and accept running a 4GB Docker stack with a large plugin tree. Do not adopt it if you need a small library, a permissive commercial licence or a documented rollback path; the README does not document rollback.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 2 days ago.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What VCPToolBox solves, and for whom
The README frames the problem in one sentence: an AI that is called, answers and forgets. In a conventional setup the model has no memory of yesterday, must be told to look anything up, and cannot act unless the application hands it a tool. VCPToolBox is the layer that removes those three limits. It runs as a Node.js service between the model API and whatever front end the user talks to, and it keeps the conversation, the memory store, the tool definitions and the model routing on its side of the boundary.
The intended user is not someone who wants a helper function for a chatbot. The README describes the project as an industrial-grade foundation for AGI OS development and exploration, and the deployment warning at the top says the agent holds low-level permissions in a distributed system. That is a fair description of the audience: people who are willing to run a server, wire up plugins and accept that the agent can touch files and devices. If you want a library you import into an existing app, this is the wrong shape.
The gravity model: how context reaches the model
The README rejects the pull model, where the model queries memory, weather or schedule on demand. Its argument is that a model cannot query something it does not know exists. The VCP model pushes instead: before a request reaches the model, the system computes what the agent should know right now, and that material flows into the prompt.
The mechanism described in the README is a temporary semantic index built per conversation. The system decides which parts of the context belong to the same semantic region, which topics are drifting away, and which background knowledge the current intent is pulling in. Important material surfaces; the rest is folded into summaries. Memory recall is handled by what the README calls a wave semantic dynamics engine, with a RiverMemo topology layer for ranking. The README states that the hot path of that ranking runs in a Rust native kernel, submitted as a single N-API async task and parallelised across candidates with Rayon, so the JavaScript and Rust sides do not bounce back and forth inside the candidate loop. The repository layout is consistent with that claim: RiverMemoEngine.js, ResidualPyramid.js and TagMemoEngine.js sit at the top level, and package.json defines build:rust-searchers for the Rust-backed searcher plugins.
One consequence deserves emphasis. The README says the agent's own tag writing becomes part of the retrieval signal, and that memory is not an external tool the agent chooses to call. That is a strong design commitment. It means retrieval quality depends on how well the agent and the user have built up tags over time, and a fresh install has little of that material to work with.
Installing VCPToolBox with Docker and running the server
The repository ships a docker-compose.yml that pulls lioensky/vcptoolbox:latest and exposes two ports, 6005 and 6006. It also sets UV_THREADPOOL_SIZE to 64 and VCP_MAIN_MAX_MEMORY to 4096M, with a comment explaining that a large knowledge base can peak at 3 to 4GB during a cold start. The compose file caps the container at 4g of memory and swap. Plan for that.
docker compose up -dAfter the container starts, the main service listens on port 6005 and the admin server on 6006, per the port mapping in docker-compose.yml. The compose file mounts the repository into /usr/src/app and keeps VectorStore on a named volume, with a comment warning that SQLite WAL files should not live on a Docker Desktop cross-system bind mount.
If you prefer to run it without Docker, package.json defines the scripts. The start script runs node server.js, and start:admin runs the admin server. The Vue admin panel is built separately.
npm install
npm run build:admin
npm startThe README does not give a first-run walkthrough in the text available here; it points to the official site and to docs/vcp白皮书V3.md for the system design. Configuration is expected through config.env, since the repository carries a config.env.example and the compose file comments reference mapping config.env into the container. The README also states that most capabilities are switched on by writing placeholders into the system prompt, which is the Agent-TVS template pipeline.
Where VCPToolBox is the wrong tool
The licence is the first hard limit. package.json declares CC BY-NC-SA 4.0, and the repository's LICENSE entry is reported as NOASSERTION. A non-commercial share-alike licence rules out most commercial embedding without a separate conversation with the authors. If your product is closed-source and paid, stop here.
The second limit is operational weight. The compose file alone tells you this is a server, not a dependency: 4GB memory ceiling, a 64-thread libuv pool, a named volume for the vector store, and a warning that SQLite WAL on a bind mount can corrupt the database. The README's own deployment warning says non-professional users should deploy with caution and that untrusted or relayed API endpoints can leak interaction data, memory contents and keys. That is not a hedge; it is a statement about the trust boundary you are accepting.
The third limit is that the documentation available here is aspirational in places. The README describes a mature, stable system and says it has run continuously in real user environments, but it does not document rollback, migration between versions or a recovery procedure for a corrupted store. The release history shows one-click installer scripts at 1.0, 1.1 and 1.2, which suggests the install path is still being revised. Treat the system as something you operate, not something you drop in.
How VCPToolBox differs from a retrieval library such as Promptx
The closest comparison a reader is likely to reach for is a retrieval or prompt-management library. Promptx-style tooling generally gives you a component: you embed it in your own application, you decide when to retrieve, and you own the loop. VCPToolBox inverts that. It is the application. The agent loop, the memory store, the plugin engine, the model router and the front-end bridge all live inside it, and your front end connects to it rather than the other way around.
The README is explicit about the tool protocol difference too. Tool calls use a plain-text marker protocol rather than native function calling, and the README states that any model capable of emitting text can use it. That is a deliberate trade: you give up the structured guarantees of a provider's function-calling API in exchange for model portability, and the README claims the parser is fault-tolerant. The repository supports this direction with files such as ModelRedirect.json.example and SemanticModelRouter.json.example, which are the configuration surfaces for routing across providers. If you have already standardised on one provider's tool-calling format and do not need to move, that portability buys you little.
Maintenance, upgrades and what the version history shows
The repository is not archived, and the last push was on 2026-09-09. The most recent release, v1.4.0, is dated 2026-08-29 and is labelled as one-click install script 1.2; the two releases before it are dated 2026-04-09 and 2026-03-12 and carry installer scripts 1.1 and 1.0. The pattern is a project that ships a release roughly every few months and revises its installer each time.
Upgrade cost is where the licence and the architecture meet. The code is JavaScript with a Rust component for the retrieval kernel, plus a Python dependency set in requirements.txt and pyproject.toml for the scientific calculator, astronomy and notification plugins. A deployment therefore spans three runtimes, and the compose file keeps node_modules and pydeps as separate volumes so that host directories do not shadow the container's. Upgrading means rebuilding the admin panel, rebuilding the Rust searchers through npm run build:rust-searchers, and restarting both Node processes. The README does not describe a supported upgrade path, so the practical approach is to pin the image tag rather than follow latest, and to keep the VectorStore volume backed up. On licensing, CC BY-NC-SA 4.0 is a non-commercial, share-alike licence; whether your use counts as commercial is a question for your own counsel, not for this article.
Editorial conclusion
Adopt VCPToolBox if you are building a long-lived companion or agent system and accept running a 4GB Docker stack with a large plugin tree. Do not adopt it if you need a small library, a permissive commercial licence or a documented rollback path; the README does not document rollback. Before installing, read docs/vcp白皮书V3.md and docs/RIVERMEMO_TOPOLOGY_V3.md, and confirm which model API you will point it at, because the README warns against third-party relay APIs.
Frequently asked questions
What is VCPToolBox and what does it do?
It is a Node.js middleware that sits between an AI model API and a front end, adding persistent multi-layer memory, a distributed plugin engine, a text-based tool protocol and multi-agent coordination. The README describes it as a foundation for AGI OS development rather than a tool-calling framework.
How do I install VCPToolBox?
The repository provides a docker-compose.yml that pulls lioensky/vcptoolbox:latest and exposes ports 6005 and 6006, so docker compose up -d is the documented path. Without Docker, package.json defines npm start for node server.js and npm run start:admin for the admin server.
Does VCPToolBox need a lot of memory to run?
Yes. The docker-compose.yml caps the container at 4g of memory and swap, and a comment states that a large knowledge base can peak at 3 to 4GB during a cold start, which is why VCP_MAIN_MAX_MEMORY is set to 4096M.
Which licence does VCPToolBox use?
package.json declares CC BY-NC-SA 4.0, a non-commercial share-alike licence, while the repository's licence field is reported as NOASSERTION. Commercial use would need to be assessed against those terms.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/lioensky-vcptoolbox)