Press enter or click to view image in full size
VEKTOR v1.9.5 is here, and it moves the platform from a fast-moving memory add-on into an agentic orchestration tool for solo devs and medium-sized teams who value local install and privacy with a choice of over 600 LLMs across 9 providers with all the latest models updated.
Some models via Groq, Openrouter, Gemini are also partially free to use with API keys or use Ollama locally for complete privacy. Local open source models have improved over the last 6 months to the stage that they are acceptable in coding and tooling requests.
None of your data is stored by us, no ads, no telemetry, no embedding costs, no data overages, no data limits or weekly caps from us, no on-selling or using your data in training.
This release touches security, coordination, and daily usability in equal measure. Faraday now scans a skill package before it ever runs, catching dangerous code, known vulnerabilities, and hidden binaries that used to slip past every text-based check.
The multi-agent Collab system no longer trusts a model’s opinion of its own work; it verifies against real compiler output, and when a task keeps failing, it can now rewrite its own approach or restructure the plan entirely instead of retrying blindly.
Press enter or click to view image in full size
VEKTOR v1.9.5 — What’s New
Every fix below was found, reproduced, and verified against live data before it shipped.
Security
- Built a full pre-install skill scanner. It checks a skill package before you ever run it, not after.
- Real Python AST analysis catches dangerous calls: exec, eval, subprocess with shell=True, pickle.loads.
- Live CVE lookups against OSV.dev, so known-vulnerable dependencies get flagged with real advisory IDs.
- Malware pattern detection for webshells, cryptominers, and reverse shell one-liners.
- Supply chain checks: unpinned dependencies, malicious postinstall hooks, typosquat package names.
- New binary and executable detection. A compiled
.exe,.dll, or.sofile used to slip through every text-based scanner untouched. Now it gets flagged, even if someone renames the file to hide it, because the check reads the actual file header, not just the extension. - SARIF and JSON output modes, plus proper exit codes, so this plugs into any CI pipeline.
- MITRE ATT&CK technique tags now show up directly in the live event feed, not just buried in a status JSON blob.
- The event graph endpoint had a hard cap of 300 events. Now it is adjustable, so a busy history doesn’t get silently truncated.
Press enter or click to view image in full size
Model Selection
- Improved where the “Newest” and “Oldest” sort buttons did nothing for OpenAI, Groq, Cerebras, and most other providers. Only OpenRouter had real release dates before this. Every one of these providers actually returns a real creation date in their own API, it just wasn’t being read. Now it is.
- Verified live against a real account: 116 OpenAI models, all sorting correctly by true release date.
- Live, right now (via the app’s real-time model discovery), across the 9 providers with an Active Model tab: 642 models — driven almost entirely by OpenRouter (454) and OpenAI (116) refreshing live from their real APIs; Claude, Gemini, Groq, Mistral, xAI, Cerebras fill out the rest.
- Static catalog baseline (every provider VEKTOR knows how to talk to, including ones without a live discovery feed — DeepSeek, Together, Cohere, MiniMax, NVIDIA, Perplexity, LM Studio, LiteLLM): 101 models, across 17 providers total.
Voice and Speech
- Added language and emotion/style controls to the voice preferences panel. Previously the server could accept these settings, but nothing in the interface sent them.
- MiniMax and ElevenLabs both get real per-provider tuning now: language boost, emotion tags, and a style intensity slider.
- Speech-to-text shipped with three real tiers: free browser recognition, cloud (Groq or OpenAI Whisper), and fully offline local recognition, so nobody is locked into one approach.
Multi-Agent Collaboration (Collab)
- Replaced pure LLM opinion with real ground truth verification. A failed build or a broken downstream file now gets caught by an actual compiler check, not just another model’s guess.
- Added Conductor re-planning. If a task fails repeatedly with the same approach, the system can now rewrite the approach itself instead of just retrying the same thing forever.
- Full topology re-planning for the hardest failures: new nodes get added to route around a dead end in the task graph.
- Real coordination primitives between agents working the same task: signal, listen, and challenge, so one agent can flag a concern about another’s output before final judgment.
- Upgraded from a text convention to genuine tool calling across every configured provider, Claude included.
- Full trajectory recording and replay, so a past run can be re-run and compared side by side.
Desk Interface.
- Fixed the profile page jumping the scroll position every time new information was added.
- Fully built out the Preferences panel: answer font, keyboard shortcut style, response language, response length, autosuggest, notifications, and the full voice settings above.
- Model picker now has real search and sort, with capability badges for vision, voice, video, tool use, and mixture of experts.
Upgrading
Drop-in from any prior version, same as always. Your memory database stays untouched.
npm install -g ./vektor-slipstream-1.9.5.tgzFull changelog with everything not covered here is at vektormemory.com/docs/changelog. Questions or feedback, the forum’s the fastest way to reach us.
VEKTOR Memory builds local-first persistent memory infrastructure for AI agents. Documentation and downloads at vektormemory.com.