Privacy-first developer intelligence — surfaces what matters from the noise
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
- !Licence file present but not machine-readable
claude mcp add 4da -- npx -y @4da/mcp-server{
"mcpServers": {
"4da": {
"command": "npx",
"args": ["-y", "@4da/mcp-server"]
}
}
}Resumen de MCP Servers
<div align="center">
<img src="assets/4da-hero.png" alt="4DA" width="360" />
<br />
[](https://github.com/4DA-Systems/4DA/actions/workflows/validate.yml)
[](LICENSE)
[](https://www.npmjs.com/package/@4da/mcp-server)
[](#download)
**All signal. No feed.**
</div>
---
**4DA reads the internet for developers — privately, locally. Your codebase decides what's relevant.**
It scans your codebase — `Cargo.toml`, `package.json`, `go.mod`, Git history — and scores every article, advisory, and release from 20+ sources against what you actually build. An item needs 2+ independent signals to survive. Everything else is rejected.
Benchmarked across 9 developer personas against a 245-item labeled corpus — 1,997 scored evaluations: **93% of content is rejected, and 98.9% of labeled noise is correctly rejected.** Those are measured numbers, and you can [reproduce them in one command](#benchmarks). Your real rejection rate — computed from your own data, not ours — is shown in the Signal tab.
Saves and dismissals build a preference profile you can inspect, pin, or forget — and teach the Brief what to stop showing you. Relevance scoring itself stays grounded in your actual stack. And when the engine improves, it re-judges everything it already holds: yesterday's noise becomes tomorrow's signal.
### The fastest way to try it
Already using Claude Code, Cursor, or Windsurf? One command:
```bash
npx @4da/mcp-server
```
This scans your project, detects your stack, and gives your AI assistant live vulnerability scanning, dependency health, upgrade planning, and ecosystem intelligence. No API keys. No accounts. Works standalone — no desktop app required. [Full MCP documentation.](mcp-4da-server/)
<p align="center">
<img src="site/screenshots/01-brief.png" alt="4DA Brief tab — top picks and live signal stream scored against your stack" width="800" />
</p>
---
## How It Works
### Scoring
5 independent signal axes. An item must pass **2 or more** to surface. Single-axis matches are hard-capped at 28% — no matter how strong one signal is, it cannot pass alone.
| Axis | What it measures |
|------|-----------------|
| **Context** | Semantic similarity to your active codebase |
| **Interest** | Alignment with your declared topics |
| **ACE** | Real-time signals from your Git commits and file edits |
| **Dependency** | Direct matches against your installed packages |
| **Learned** | Reserved — held out of scoring until it can be validated against your explicit feedback |
What passes the gate goes through 12 quality multipliers: content depth, novelty detection, competing tech penalties, title-body coherence, and intent scoring from recent work. Every constant is calibrated across 9 simulated developer personas with 245 labeled test items.
### LLM Verification
After keyword scoring, an LLM layer verifies the top items against your full developer context — stack, dependencies, recent commits, anti-technologies, and engagement history. Strict 1-5 rubric:
- **5 = MUST-READ**: Security alert for YOUR dependency, breaking change YOU must act on
- **3 = WORTH KNOWING**: Useful tool that fits YOUR exact stack
- **1 = NOISE**: Mentions your tech but isn't actionable
This is where the gold surfaces — articles the keyword pipeline misses because there's no keyword overlap, but the LLM understands the conceptual relevance to your specific project.
**You own the compute.** Use [Ollama](https://ollama.com/) for free local inference (fully private), or bring your own Anthropic/OpenAI key. 4DA never pays for your compute, never stores your keys remotely, never makes API calls you didn't configure.
### Anti-Gaming
Content creators who learn the scoring algorithm still can't game it:
- **Title-body coherence**: titles must deliver on what they promise. Claim "React + Rust + Tauri" but only discuss React? Penalty.
- **Keyword concentration**: repeating "Rust" four times in a title hurts your score.
- **Confirmation gate**: keyword-stuffing hits one axis. Without matching the user's codebase, installed packages, AND recent work — the gate rejects it.
- **Grounded scoring**: relevance keys on your actual dependency graph and stack — not popularity, not engagement. There is no behavioural signal to farm; content scores only when it matters to what you actually build.
No algorithm can be gamed when the scoring signal comes from your local filesystem. Your `Cargo.lock` doesn't lie.
---
## Privacy & Trust
4DA is local-first and direct-to-provider. There is no 4DA-operated server, no analytics, and no user account system. Your indexed content, scores, and intelligence live in a SQLite database on your machine.
**The only outbound traffic:**
| Category | Where | Why |
|----------|-------|-----|
| Source adapters | HN, GitHub, Reddit, arXiv, etc. | Fetching public content you configured |
| LLM providers | Anthropic / OpenAI / localhost Ollama | Only if YOU set up BYOK keys |
| License validation | Keygen | Only if you activated a paid license |
| Updater | GitHub Releases | Signed via minisign, once per session |
| Crash reports | **None** | 4DA sends no crash reports. Export a scrubbed diagnostic bundle locally, on demand. |
That's the whole list. There is no 4DA telemetry endpoint because there is no 4DA cloud.
Don't take our word for it:
| | |
|---|---|
| [**Network Transparency**](NETWORK.md) | Every outbound connection, with source code references |
| [**Trust Architecture**](docs/TRUST-ARCHITECTURE.md) | Why local-first means you don't need to trust us |
| [**Privacy (Plain Language)**](docs/PRIVACY-PLAIN-LANGUAGE.md) | One-page, no-legalese privacy summary |
| [**Security Audit Guide**](docs/SECURITY-AUDIT-GUIDE.md) | Map of trust-critical code paths for auditors |
| [**Build from Source**](docs/BUILD-FROM-SOURCE.md) | Compile it yourself and verify the binary |
---
## Download
> **Pre-built binaries** — no Rust toolchain required.
| Platform | Download | Auto-updates |
|----------|----------|:------------:|
| **Windows** | [`.exe` installer](https://github.com/4DA-Systems/4DA/releases/latest) | Yes |
| **macOS** | [`.dmg` (Apple Silicon & Intel)](https://github.com/4DA-Systems/4DA/releases/latest) | Yes |
| **Linux** | [`.AppImage` / `.deb`](https://github.com/4DA-Systems/4DA/releases/latest) | Yes |
Every release publishes `SHASUMS256.txt` and per-file `.sha256` sidecars. [Verification instructions.](docs/VERIFY-DOWNLOADS.md)
> **Windows users:** SmartScreen will prompt on first launch (new application, building reputation). Click **More info → Run anyway**. [Full details.](docs/launch/WINDOWS-INSTALL.md)
Or install the **MCP server** for Claude Code / Cursor / Windsurf:
```bash
npx @4da/mcp-server
```
### Build from Source
```bash
git clone https://github.com/4DA-Systems/4DA.git
cd 4DA
pnpm install
pnpm tauri dev # First build: 5-15 min. Dev server: localhost:4444.
```
**Prerequisites:** Rust (1.93.1 via `rust-toolchain.toml`), Node.js 20, pnpm 9.15. Platform-specific: [Windows](docs/BUILD-FROM-SOURCE.md) needs VS Build Tools 2022 with C++ workload. [Full build guide.](docs/BUILD-FROM-SOURCE.md)
**First-run setup** (API keys, context dirs, sources): [Getting Started.](docs/GETTING_STARTED.md)
---
## System Requirements
4DA runs on modest hardware. Private semantic search is built in — no GPU, no API key, and no first-run download required.
| | Baseline (free) | + Cloud AI (BYOK) | + Local AI (offline) |
|---|---|---|---|
| RAM | 4 GB | 4 GB | 16 GB (8B model); 32 GB for 12–14B |
| CPU | any 64-bit | any 64-bit | 6–8 cores |
| GPU | not needed | not needed | optional (recommended for speed) |
| Disk | ~500 MB | ~500 MB | + 5–9 GB per model |
| Network | install only | install + your AI provider | install + one model download (or none with Ollama) |
- OS: Windows 10 (1803+) / 11, macOS 10.15+, Ubuntu 22.04+ (WebKitGTK 4.1).
- One installer (~110 MB). The local embedding model ships inside it — no separate download, works fully offline on first run.
- Baseline = private on-device semantic search. Cloud AI adds AI-written briefings + deeper reranking via your own API key. Local AI runs everything offline (Ollama or a downloaded model).
---
## Architecture
```
Your Codebase External Sources
| |
v v
+-----------+ +--------------+
| ACE | | 20+ Source |
| Scanner + | | Adapters |
| Git Watch | | (background) |
+-----+-----+ +------+-------+
| |
v v
+------------------------------------------+
| 5-Axis Scoring Engine |
| |
| context --+ |
| interest --+- confirmation gate (2+/5) |
| ace -------+ |
| dependency-+ x quality x novelty |
| learned ---+ x domain x intent |
+------------------+-----------------------+
|
v
+-----------------+
| What survived |
+-----------------+
```
| Layer | Technology |
|-------|-----------|
| App Shell | Tauri 2.0 (Rust backend + WebView) |
| Frontend | React 19 + TypeScript + Tailwind CSS v4 |
| Database | SQLite 3.45+ with sqlite-vec (vector search) |
| Scoring | Custom pipeline → build-time Rust codegen |
| Embeddings | OpenAI text-embedding-3-small / Ollama |
| LLM | Anthropic Claude / OpenAI / Ollama (BYOK) |
---
## Pricing
**Free** — $0 forever. No credit card. No accouLo que la gente pregunta sobre 4DA
¿Qué es 4DA-Systems/4DA?
+
4DA-Systems/4DA es mcp servers para el ecosistema de Claude AI. Privacy-first developer intelligence — surfaces what matters from the noise Tiene 2 estrellas en GitHub y su última actualización registrada es del 2026-10-03.
¿Cómo se instala 4DA?
+
Puedes instalar 4DA clonando el repositorio (https://github.com/4DA-Systems/4DA) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar 4DA-Systems/4DA?
+
Nuestro agente de seguridad ha analizado 4DA-Systems/4DA y le ha asignado un Trust Score de 80/100 (tier: Trusted). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene 4DA-Systems/4DA?
+
4DA-Systems/4DA es mantenido por 4DA-Systems. La última actividad registrada en GitHub es del 2026-10-03, con 3 issues abiertos.
¿Hay alternativas a 4DA?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega 4DA en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/4da-systems-4da)<a href="https://claudewave.com/repo/4da-systems-4da"><img src="https://claudewave.com/api/badge/4da-systems-4da" alt="Featured on ClaudeWave: 4DA-Systems/4DA" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.