seamlessCAUTION
Local-first shared memory and task coordination for AI coding agents. One Go binary, MCP server, markdown files you own. Hooks for Claude Code and Codex CLI (and their desktop apps).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pkg.go.dev/github.com/arctop/seamless) [](https://github.com/arctop/seamless/releases/latest) [](LICENSE) [](https://thereisnospoon.org/docs/reference/mcp/)
An AI coding agent rediscovers the same constraint every session, because nothing it learns survives the context window. Run two agents against the same backlog and they pick the same step and build it twice. And the products that promise to fix this keep your project's memory in someone else's database.
Seamless is a local-first memory and coordination substrate for AI coding agents. Works with Claude Code, Codex CLI, and any MCP client. It also works from chats in the Claude desktop app, for long-running work that isn't code: see Seamless in the Claude app.
It gives a fleet of agents a shared, durable memory and a way to divide work without colliding: memories with a supersession lifecycle, hybrid recall, a dependency-aware task queue with lease-based claiming, captured plans, and research trials. Durable knowledge is stored as markdown files on disk; the seamlessd daemon indexes it, serves it over MCP, and renders a web console, while the companion seam CLI gives headless agents a direct interface.
Full documentation: [thereisnospoon.org/docs/](https://thereisnospoon.org/docs/) · Website: thereisnospoon.org (source in docs/)
Developed and published by Arctop. MIT licensed.
Design principles
- Built for a fleet, not a lone agent. Real coordination primitives: a
dependency-aware ready-queue, atomic lease-based task claiming, and plans composed of notes and steps, so agents divide lab
fa87b1725ad9OBSERVED · 2026-10-09Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
list_agent_resources | read | The machine-readable endpoints this site publishes for agents: llms.txt, |
read_page | read | Read any page of this site as markdown. Takes a path (/docs/quickstart/) |
search_docs | read | Full-text search over the Seamless documentation at |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (23)
"Set the session and refresh cookies with HttpOnly, Secure, and SameSite=Lax. Do not return the tokens in the response body and do not let any client script read them: an XSS bug then can't exfiltrate
"Set the session and refresh cookies with HttpOnly, Secure, and SameSite=Lax. Do not return the tokens in the response body and do not let any client script read them: an XSS bug then can't exfiltrate
` api_key: "test-key-not-a-real-one"`,
cfg.MCP.APIKey = "test-key-that-must-not-reach-codex"
.golangci.yml
.goreleaser.yaml
.nojekyll
deep, err := renderMarkdown(src, "../../", "../../../")
require.Contains(t, string(deep.HTML), `href="../../concepts/memory/"`)
require.Contains(t, string(deep.HTML), `href="../../reference/mcp/tasks/#tasks_claim"`)
require.Contains(t, string(deep.HTML), `src="../../static/shot.png"`)
require.Contains(t, string(deep.HTML), `href="../../../scenarios/task-collision/"`,
{"private middle", []string{"8.8.8.8", "169.254.169.254", "1.1.1.1"}},then open http://127.0.0.1:8899/.
--hide-scrollbars 'http://127.0.0.1:8899/static/og-source.html'
SEAMLESS_SHOT_BASE=http://127.0.0.1:8090 SEAMLESS_MCP_API_KEY=<same key> \
`http://127.0.0.1:8081/api/mcp` (streamable HTTP) and A2A at
`http://127.0.0.1:8081/api/a2a` (JSON-RPC), with the live agent card at
curl -fsSL https://thereisnospoon.org/install | sh
nothing did -- the `curl | sh` installer shipped with the README and every docs
- The installer (`curl -fsSL https://thereisnospoon.org/install | sh`)
- feat(install): one-command curl | sh installer for macOS and Linux
curl -fsSL https://thereisnospoon.org/install | sh # macOS, Linux
Gates applied: no_behavioural_pass.
fa87b1725ad9full audit observations/trust-audit/mcp-server/arctop__seamless.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | fa87b1725ad9 | CAUTION | B | 81 | first audit |
Questions
What is the seamless MCP server?
Local-first shared memory and task coordination for AI coding agents. One Go binary, MCP server, markdown files you own. Hooks for Claude Code and Codex CLI (and their desktop apps).
What tools does seamless expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is seamless safe to connect to an agent?
With care. The audit graded it B (81/100) and found 23 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does seamless need?
It reads SEAMLESS_MCP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does seamless run?
It speaks streamable-http, so it runs as a service you connect to over the network.
How current is this page?
The grade is for one exact copy of the source (fa87b1725ad9), read on 2026-10-09. The repository is watched and re-audited when it changes.