citetrail
Citetrail
ローカルで動作し、出典情報を保持するブラウザ閲覧メモリ — すべての呼び出し結果には、取得元のURL、タイトル、タイムスタンプが付随します。
Citetrailは、あなたが実際に読んだページをキャプチャし、自分のマシンに保存して、検索可能にします — あなた自身にとっても、MCP経由のAIエージェントにとっても。エージェントがそこで見つけた情報を使用する際、正確な出典を引用できます。
ステータス: プレリリース。インストール前にプロジェクトのステータスを参照してください。
ライセンス: Apache-2.0
デフォルトでローカル動作。 アカウント不要、サーバー不要、アップロードなし。ブロックされたページはフェイルクローズドになります。
Citetrailが解決する問題
6つのタブを読んで閉じた後、コーディングエージェントが4番目のタブの内容を必要とするとします。現在の選択肢は、再度貼り付けるか、エージェントにオープンウェブを再検索させて同じページにたどり着くことを祈るか、出典のない回答を受け入れるかです。
ブラウザ履歴は、あなたがURLを訪問したことを知っています。しかし、ページに何が書かれていたかは知らず、エージェントに伝えることもできません。Citetrailはそのギャップを埋めます:
ブラウザ履歴 | Citetrail |
URLのリスト | 実際に読んだコンテンツをキャプチャ |
タイトルによる大まかな検索 | ページの内容による検索 |
ツールからは見えない | MCP経由でエージェントがクエリ可能 |
「なぜここにあるのか」という概念がない | すべてのエントリが出典情報を保持 |
無差別にすべて | 許可されたページのみ。ブロックリストはフェイルクローズド |
Related MCP server: qsearch
「出典情報を保持する」の意味
保存されたすべてのフラグメントは限定された参照を保持します: ソースURL、ページタイトル、キャプチャタイムスタンプ、ページ内の位置。呼び出しはフラグメントとその参照を一緒に返します — これらは分離できません。Citetrailから回答するエージェントは、常に情報の取得元を明示でき、あなたも常に元のページを開くことができます。
ソースが消えた場合、Citetrailはソースが消えたと明示します。あたかもまだ存在するかのようにフラグメントを静かに提供することはありません。
クイックスタート
git clone https://github.com/anonb3ll/citetrail
cd citetrail
python3 -m venv .venv
.venv/bin/pip install -e .
.venv/bin/citetrail init
# 2. Search the local store
.venv/bin/citetrail search "retry backoff"
# Optional: block a sensitive hostname before it can be stored
.venv/bin/citetrail block bank.example.test
# 3. Point an agent at the same local store over MCP
.venv/bin/citetrail mcp --stdioデフォルトのストアは~/.local/share/citetrailです。別のローカルディレクトリを使用するには、CITETRAIL_STOREを設定するか、--store PATHを渡してください。展開済みのChromiumアダプタを読み込むにはdocs/extension.mdを参照してください。
ドキュメント
ガイド | 説明 |
ドキュメントの索引 | |
CLIコマンドとストアのレイアウト | |
MCPツールのスキーマと登録 | |
Chromium拡張機能のセットアップ | |
ブロックリストとフェイルクローズドの動作 | |
オプションのRunroom統合 |
よくある質問
AIエージェントにブラウジング履歴を検索させるにはどうすればよいですか?
ローカルのMCPサーバーを実行し、エージェントに登録します。エージェントは他のMCPツールと同様にCitetrailをクエリし、出典が付いたフラグメントを受け取ります。ブラウザやプロファイルへの生のアクセス権は決して付与されません。
データはどこに保存され、何かがアップロードされることはありますか?
自分のマシン上のローカルデータベースに保存され、いつでも削除できます。Citetrailにはサーバーがなく、アップロードも行われません。docs/privacy.mdを参照してください。
銀行、メール、社内イントラネットのキャプチャを停止するにはどうすればよいですか?
ブロックリストを使用します。キャプチャ前にチェックされ、フェイルクローズドで動作します — ページに対してルールを評価できない場合、そのページはキャプチャされません。citetrail block bank.example.testでホストを追加します。許可リストのみのキャプチャは将来の予定です。
エージェントは実際に読んでいないソースを引用できますか?
Citetrailからはできません。参照はフラグメントと一緒に移動します。出典情報なしでテキストを返すAPIは存在しません。
オフラインの場合、またはページが消えた場合はどうなりますか?
呼び出しは、すでにキャプチャした内容に対してオフラインで動作します。元のURLに到達できない場合、結果はその旨がマークされ、現在のものとして黙って提示されることはありません。利用不可やプライバシーによるブロックの状態は、隠されることなく正直に報告されます。
これはノートアプリやセカンドブレインですか?
いいえ。Citetrailはキャプチャと呼び出しを行います。思考の整理、ナレッジグラフの構築、何かのメンテナンスを求めることはありません。あなたが読んだものを知る必要があるツールのための基盤です。
どのブラウザでも動作しますか?
拡張機能はまずChromiumベースのブラウザを対象としています。拡張機能とローカルサービス間のネイティブブリッジには実際の制限があります — docs/limitations.mdを参照してください。
Citetrailではないもの
ホスト型サービスでも同期サービスでもありません。1台のマシン、1つのストアです。
PKMやノートシステムではありません。
臨床、ウェルビーイング、注意力追跡ツールではありません。あなたの認知について何ら主張するものではありません。
スクレイパーではありません。自分のルールの下で、自分が訪問したページをキャプチャします。
モバイルアプリではありません。
docs/limitations.mdとdocs/private-exclusions.mdを参照してください。
関連プロジェクト
Runroomは、レビューゲートと監査証跡を備えたAIエージェントと人間の間の引き継ぎを調整します。2つのプロジェクトは独立しており、互いを必要としません。オプションの統合により、Citetrailの参照が管理されたRunroomタスクに供給される様子を示します。
コントリビューション
CONTRIBUTING.mdとCODE_OF_CONDUCT.mdをお読みください。脆弱性は非公開で報告してください — SECURITY.mdを参照してください。
プロジェクトのステータス
プレリリース、1.0以前です。インターフェースは変更される予定です。Citetrailは、他の人々がこれを必要としているかを知るために公開されています — 試した場合は、何を呼び出そうとしていたか、そしてそれができたかを教えてください。
ライセンス
Apache License 2.0。Copyright 2026 The Citetrail Contributors。
Available Tools
1 toolcitetrail_searchC
Search local captures with inseparable provenance.
| Name | Required | Description | Default |
|---|---|---|---|
| query | Yes | ||
| source_state | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure. 'Search' implies a read-only operation, but the description does not clarify what 'inseparable provenance' means, how results are returned, whether source_state affects behavior, or what happens when captures are unavailable or privacy-blocked. This is a minimal signal rather than transparent behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single short sentence with no filler or repetition. The core action and resource are front-loaded. It is appropriately concise, though the cryptic 'inseparable provenance' could have been replaced with more useful information without harming length.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is relatively simple with only two parameters, but there is no output schema, no annotations, and no parameter-level documentation. The description leaves critical details undefined: what 'local captures' are, what 'inseparable provenance' means, how query matching works, and what the response shape is. This is not enough for an agent to reliably invoke the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0%, and the description provides no information about either parameter. 'query' and 'source_state' are completely undocumented, and the meaning of the source_state enum values is left entirely to inference. The description fails to compensate for the schema's lack of parameter descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states a search operation over 'local captures,' which identifies the tool's verb and resource. The phrase 'with inseparable provenance' adds a distinguishing quality, though it is jargon-heavy and not fully explained. With no sibling tools to differentiate from, this is clear enough for basic selection.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the tool should be used when searching local captures, giving some usage context. However, it provides no explicit guidance on when to prefer this tool over alternatives, no prerequisites, and no exclusions. The usage signal is only implicit.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v0.1.0- First observed
citetrail_search
TDQS
Scored across 1 tool
With only one tool, there is no possibility of confusion or overlap. The purpose of citetrail_search is singular and unambiguous.
The single tool name 'citetrail_search' follows a clear object-action pattern, and with only one tool there is no inconsistency to evaluate.
A single search tool feels insufficient for a server named 'citetrail', which implies a broader capture management lifecycle. One tool is too thin for the apparent scope of the domain.
The server only exposes search; there are no create, retrieve, update, delete, or list operations for captures. This leaves agents unable to ingest or manage captures, creating significant gaps and dead ends.
Maintenance
Related MCP Connectors
Scrape, crawl and search the web for AI agents via MCP.
- KogniteOAuthdev.kognite
Hosted agent memory: store, search, and recall facts across sessions from any MCP client.
Agentic search over your Dewey document collections from any MCP-compatible client.
Personal knowledge MCP: capture bookmarks, notes & todos by chat; archive pages; search memory.
Related MCP Servers
- AlicenseNot gradedqualityBmaintenanceEnables AI tools to query a user's private, locally stored memories (notes, documents) with source citations, using the MCP protocol.12 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to perform web searches with full content retrieval and multi-engine provenance, including trust scoring and local corpus persistence, via MCP integration.1 npm2Apache 2.0
- AlicenseNot gradedqualityCmaintenanceEnables LLM agents to perform web search, scraping, and summarization outside their context window, receiving compact cited briefs via MCP while full pages are cached and viewable in a local web UI.MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to perform web research over MCP: search with a real browser, fetch JS-rendered pages, download PDFs and convert them to Markdown, then search and page through large documents using bounded previews so the context window isn't flooded.BSD Zero Clause