Atlas / MCP servers / avids2 / Memorix

MemorixBLOCK

mcp/avids2/memorix

Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Windsurf, Gemini CLI, Antigravity, OpenClaw, Hermes Agent, Oh-my-Pi, Pi, Copilot, Kiro, OpenCode, and Trae.

Verdict
BLOCK
Grade
F
Trust score
39 /100
Exposed tools
193 148r · 34w · 11d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
809
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Memorix

Local-first shared memory layer for AI coding agents. One project memory system for Claude Code, Codex, CodeBuddy Code, Cursor, Windsurf, Copilot, Gemini CLI, OpenCode, Grok Build, OpenClaw, Hermes Agent, Oh-my-Pi, Pi, Kiro, Antigravity, Trae, DeepSeek Harness, WorkBuddy, and any MCP-capable agent.

Listed in the official MCP Registry

Shared Project Memory | MCP | Git Memory | Reasoning Memory | Plugins | Orchestration

Read from source at commit 0ddb6f2c10e1OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add memorix -- npx -y [email protected] serve
03

Exposed tools (193)

148 read · 34 write · 11 destructive. Blast radius: 11 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_observationswrite
arg-testreadtest
askreadAsk Memorix a question (single-shot chat). Pipe: echo
auditreadInspect Memorix audit trail and project attribution health
backgroundreadManage the Memorix Control Plane as a background service
bswriteShortcut: background start
calculatereadEvaluate mathematical expressions
calculatorreadPerform basic arithmetic operations
changelogreadShow changelog entries
checkpointreadInspect and manage native compact continuity checkpoints
cleanupdestructiveRemove low-quality auto-generated observations
cleardestructiveClear all messages
clonereadDuplicate the current session at the current position
codegraphreadInspect and refresh CodeGraph Memory for the current project
commandsreadShow available slash commands
commitwriteIngest a git commit as memory
compactreadManually compact the session context
configreadInspect Memorix TOML configuration
contextreadShow the Memory Autopilot brief for the current project
continuityreadTrack task requirements, decisions, verification, risks, and outcomes
copyreadCopy last agent message to clipboard
create_entitieswrite
create_relationswrite
custom-skillreadA custom skill
dashboardreadLaunch a standalone read-mostly project dashboard
deletedestructiveDelete the last message
delete_entitiesdestructive
delete_memorydestructiveDelete/archive a memory observation by marking it as resolved. Use this when the user wants to remove outdated or incorrect memories.
delete_observationsdestructive
delete_relationsdestructive
deploywriteDeploy the application
deterministic_probereadMandatory benchmark tool. Call exactly once with the turn and marker from the user prompt.
doctorreadDiagnose Memorix health — project identity, embedding, data, conflicts
double_numberreadDoubles a number and returns the result
dummyreadDummy tool
duplicate-toolreadFirst
echoreadEcho back text
echo_valuereadEcho a string value
editwriteEdit a file.
evidencereadInspect project-scoped evidence cards and provenance
examplereadExample
explainreadExplain where Memorix project context comes from
exportreadExport session (HTML default, or specify path: .html/.jsonl)
feedbackreadRecord and audit memory feedback
findreadFind files by pattern
forkwriteCreate a new fork from a previous user message
formationreadInspect Memory Formation Pipeline runtime metrics
generated-skillreadA generated skill
getreadRead a resolved Memorix config value
get_circlereadReturns a circle image for visualization
get_circle_with_descriptionreadReturns a circle image with a text description
get_current_timereadGet the current date and time
get_memory_detailreadRetrieve the full narrative and facts of a specific memory observation by its ID. Use this after search_memories when you need more context about a specific result.
git-hook-installwriteInstall git post-commit hook for automatic memory capture
git-hook-uninstalldestructiveRemove memorix git post-commit hook
grepreadSearch a file
handoffwriteCreate structured handoff artifacts between agents
helpreadShow help
hiddenreadHidden
hidden-skillreadA hidden skill.
hookreadHandle agent hook event (called by agent hook configs)
hooksreadManage automatic memory hooks for agents
hotkeysreadShow all keyboard shortcuts
identityreadSelect the explicit CLI actor used for private or team-scoped operations
imagereadAnalyze an image and store the result as memory
importwriteImport and resume a session from a JSONL file
ingestreadIngest engineering knowledge from Git and images
initreadInitialize Memorix TOML configuration
injectedreadInjected skill
inspectreadInspect things
inspect_schemareadInspect the schema
installwriteInstall Memorix hooks for IDEs (interactive)
integratereadGenerate integration files for a specific IDE or agent
knowledgereadInitialize, review, and lint the Memorix Knowledge Workspace
linkreadTarget
linkedin_skillreadGet LinkedIn comments
listreadList a directory
list_recent_memoriesreadList recent memory observations for the project. Use this when the user wants to see what has been stored recently or browse the knowledge base.
load-skillsreadLoad skills
lockreadAcquire, release, and inspect advisory team file locks
logreadBatch ingest recent git commits as memories
loginreadConfigure provider authentication
logoutdestructiveRemove provider authentication
lookupreadLook up a value
math_operationreadPerform basic arithmetic operations
mediawriteImport, attach, inspect, and clean controlled local media assets
memcodereadEnter memcode TUI — native coding agent with memory
memorixreadShared workspace memory for Claude Code and other AI coding agents.
memorix-localreadLocal marketplace for the Memorix Claude Code plugin.
memorix_audit_projectread
memorix_codegraph_statusread
memorix_compaction_checkpointread
memorix_consolidateread
memorix_context_packread
memorix_continuityread
memorix_dashboardread
memorix_deduplicateread
memorix_detailread
memorix_evidenceread
memorix_feedbackread
memorix_formation_metricsread
memorix_graph_contextread
memorix_handoffread
memorix_ingest_imageread
memorix_knowledgeread
memorix_mediaread
memorix_pollread
memorix_project_contextread
memorix_promoteread
memorix_resolveread
memorix_retentionread
memorix_rules_syncwrite
memorix_searchread
memorix_search_reasoningread
memorix_session_contextread
memorix_session_endread
memorix_session_startwrite
memorix_skillsread
memorix_storeread
memorix_store_reasoningread
memorix_suggest_topic_keyread
memorix_timelineread
memorix_transferwrite
memorix_workspace_syncwrite
memoryreadShow Memorix memory commands
messagewriteSend, broadcast, and read team messages from the CLI
migratewriteWrite a TOML config from existing compatibility config
modelreadSelect model (opens selector UI)
my-skillreadCustom project instructions
my_custom_toolreadA custom tool
namewriteSet session display name
newwriteStart a new session
onereadOne template
open_nodesread
orchestratewriteRun structured multi-agent coordination loop
pathreadShow Memorix TOML config paths
pingreadPing tool
pollreadGet a full project coordination snapshot for an agent
pr-reviewreadReview and address PR comments
previewreadPreview files to be created by hooks installation
promptreadprompt
purgedestructiveRetire memories from retrieval (current project by default, --all for every project)
quitreadQuit ${APP_NAME}
readreadRead a file
read_graphread
reasoningreadStore and search decision rationale from the operator CLI
receiptreadGenerate a privacy-safe memory handoff receipt
recentreadShortcut for
reloadreadReload keybindings, extensions, skills, prompts, and themes
rememberreadShortcut for
repairreadRepair Memorix-owned agent integration files
resumereadResume a different session
retentionreadInspect retention state and archive expired memories
reviewreadReview template
scoped-modelswriteEnable/disable models for Ctrl+P cycling
searchreadShortcut for
search_memoriesreadSearch the project memory knowledge base for relevant decisions, bugs, architecture notes, gotchas, or other engineering context. Use this when the user asks about project history, design rationale, known issues, or technical details.
search_nodesread
secondreadSecond skill
servewriteStart Memorix MCP Server on stdio transport
serve-httpwriteStart the shared Memorix MCP control plane over HTTP
sessionreadShow session info and stats
settingsreadOpen settings menu
setupwriteInstall the best Memorix integration package for an agent
sharereadShare session as a secret GitHub gist
skill-onereadFirst skill.
skill-tworeadSecond skill.
skillsreadDiscover, generate, and inspect project skills from the CLI
statusreadShow hook installation status for all agents
store_memoryreadStore a new memory observation to the project knowledge base. Use this when the user wants to save a decision, gotcha, bug fix, architecture note, or any engineering context worth remembering.
syncwriteInteractive cross-agent synchronization plus explicit rules/workspace subcommands
sync-storewriteReplicate the local observation store across your devices (opt-in, provider-agnostic)
targetreadTarget
taskwriteCreate, claim, complete, and inspect team tasks
teamreadManage project-scoped orchestration coordination state
team_file_lockread
team_manageread
team_messageread
team_taskread
testreadtest tool
test-skillreadA test skill.
test_toolreadA test tool
todowritewriteWrite a todo item
transferwriteExport or import project memory snapshots
treereadNavigate session tree (switch branches)
trustwriteSave project trust decision for future sessions
tworeadFirst line description
uninstalldestructiveRemove automatic memory hooks for agents
update_memorywriteUpdate an existing memory observation by its ID. Use this when the user wants to modify or add to an existing memory. Provide the ID and the fields to update.
visiblereadUse <this> & that
visible-skillreadA visible skill.
workbenchreadOpen the interactive terminal memory control plane
writewriteWrite a file
04

Trust audit

BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (6 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHInventory / provenance · inv.suspicious_name · CWE-1104
src/multimodal/image-payload.ts
image-payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/agent-core/src/harness/types.ts:323
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/memcode/src/core/export-html/vendor/highlight.min.js:133
}),!0),this.lastIndex=0}exec(e){this.matcherRe.lastIndex=this.lastIndex
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/memcode/src/core/export-html/vendor/highlight.min.js:143
this.rules.push([e,n]),"begin"===n.type&&this.count++}exec(e){
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/tui/native/darwin/prebuilds/darwin-arm64/darwin-modifiers.node
darwin-modifiers.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/tui/native/darwin/prebuilds/darwin-x64/darwin-modifiers.node
darwin-modifiers.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/tui/native/win32/prebuilds/win32-arm64/win32-console-mode.node
win32-console-mode.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
packages/tui/native/win32/prebuilds/win32-x64/win32-console-mode.node
win32-console-mode.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
packages/ai/src/providers/faux.ts:249
const tokenSize = minTokenSize + Math.floor(Math.random() * (maxTokenSize - minTokenSize + 1));
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:63
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=5 CMD ["node", "-e", "fetch('http://127.0.0.1:3211/health').then(r => process.exit(r.ok ? 0 : 1)).catch(() => process.exit(1))"]
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/memcode/src/modes/interactive/components/daxnuts.ts:12
"bbbab8b9b9b6b9b8b5bcbbb8b8b7b4b7b5b2b6b5b2b8b7b4b7b6b3b6b4b1bdbcb8bab8b6bbb8b5b8b5b1bbb8b4c2bebbc1bebac0bdbabfbcb9c1bebabfbebbc0bfbcc0bdbabbb8b5c1bfbcbfbcb8bbb9b6bfbcb8c2bfbcc1bfbcbfbbb8bdb9b6b8b7b5b
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/cli/workbench.ts:1
/**
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/ai/test/github-copilot-anthropic.test.ts:61
const s = streamAnthropic(model, context, { apiKey: "tid_copilot_session_test_token" });
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/ai/test/github-copilot-anthropic.test.ts:97
apiKey: "tid_copilot_session_test_token",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/ai/test/google-vertex-api-key-resolution.test.ts:94
apiKey: "gcp-vertex-credentials",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/cli/config-command.test.ts:265
expect(content).toContain('api_key = "embedding-test-secret"');
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/media/asset-store.test.ts:248
const secret = 'sk-abcdefghijklmnopqrstuvwxyz1234';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/memory/secret-filter.test.ts:34
expect(containsCredential('ghp_abcdefghijklmnopqrstuvwxyz123456789012')).toBe(true);
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/memory/secret-filter.test.ts:87
const token = 'ghp_abcdefghijklmnopqrstuvwxyz123456789012';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/workspace/sanitizer.test.ts:13
const input = '"token": "ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789"';
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
cleanup, clear, delete, delete_entities, delete_memory, delete_observations, delete_relations, git-hook-uninstall, logout, purge, uninstall
Why it matters. 11 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
packages/memcode/examples/extensions/doom-overlay/doom/build/doom.wasm
doom.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/ai/test/bedrock-thinking-payload.test.ts
bedrock-thinking-payload.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.suspicious_name · CWE-1104
packages/memcode/examples/extensions/provider-payload.ts
provider-payload.ts
Why it matters. member named after an attack tool
Fix. remove or justify

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 0ddb6f2c10e1full audit observations/trust-audit/mcp-server/avids2__memorix.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-280ddb6f2c10e1BLOCKF39first audit
06

Questions

What is the Memorix MCP server?

Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Windsurf, Gemini CLI, Antigravity, OpenClaw, Hermes Agent, Oh-my-Pi, Pi, Copilot, Kiro, OpenCode, and Trae.

What tools does Memorix expose?

193 in total: 148 read-only, 34 that write, and 11 that can delete or overwrite (cleanup, clear, delete, delete_entities, delete_memory). Every one is listed on this page with its risk.

Is Memorix safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (39/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 11 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Memorix need?

It reads AI_GATEWAY_API_KEY, ALIYUN_API_KEY, ANTHROPIC_API_KEY, ANTHROPIC_OAUTH_TOKEN, ANT_LING_API_KEY, ATLASCLOUD_API_KEY, AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_BEARER_TOKEN_BEDROCK, AWS_BEDROCK_SKIP_AUTH, AWS_CONTAINER_CREDENTIALS_FULL_URI and AWS_CONTAINER_CREDENTIALS_RELATIVE_URI from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Memorix run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as memorix-pi-package at 1.9.6.

How current is this page?

The grade is for one exact copy of the source (0ddb6f2c10e1), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement