MemorixBLOCK
Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Windsurf, Gemini CLI, Antigravity, OpenClaw, Hermes Agent, Oh-my-Pi, Pi, Copilot, Kiro, OpenCode, and Trae.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Memorix
Local-first shared memory layer for AI coding agents. One project memory system for Claude Code, Codex, CodeBuddy Code, Cursor, Windsurf, Copilot, Gemini CLI, OpenCode, Grok Build, OpenClaw, Hermes Agent, Oh-my-Pi, Pi, Kiro, Antigravity, Trae, DeepSeek Harness, WorkBuddy, and any MCP-capable agent.
Listed in the official MCP Registry
Shared Project Memory | MCP | Git Memory | Reasoning Memory | Plugins | Orchestration
0ddb6f2c10e1OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add memorix -- npx -y [email protected] serve
Exposed tools (193)
148 read · 34 write · 11 destructive. Blast radius: 11 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_observations | write | |
arg-test | read | test |
ask | read | Ask Memorix a question (single-shot chat). Pipe: echo |
audit | read | Inspect Memorix audit trail and project attribution health |
background | read | Manage the Memorix Control Plane as a background service |
bs | write | Shortcut: background start |
calculate | read | Evaluate mathematical expressions |
calculator | read | Perform basic arithmetic operations |
changelog | read | Show changelog entries |
checkpoint | read | Inspect and manage native compact continuity checkpoints |
cleanup | destructive | Remove low-quality auto-generated observations |
clear | destructive | Clear all messages |
clone | read | Duplicate the current session at the current position |
codegraph | read | Inspect and refresh CodeGraph Memory for the current project |
commands | read | Show available slash commands |
commit | write | Ingest a git commit as memory |
compact | read | Manually compact the session context |
config | read | Inspect Memorix TOML configuration |
context | read | Show the Memory Autopilot brief for the current project |
continuity | read | Track task requirements, decisions, verification, risks, and outcomes |
copy | read | Copy last agent message to clipboard |
create_entities | write | |
create_relations | write | |
custom-skill | read | A custom skill |
dashboard | read | Launch a standalone read-mostly project dashboard |
delete | destructive | Delete the last message |
delete_entities | destructive | |
delete_memory | destructive | Delete/archive a memory observation by marking it as resolved. Use this when the user wants to remove outdated or incorrect memories. |
delete_observations | destructive | |
delete_relations | destructive | |
deploy | write | Deploy the application |
deterministic_probe | read | Mandatory benchmark tool. Call exactly once with the turn and marker from the user prompt. |
doctor | read | Diagnose Memorix health — project identity, embedding, data, conflicts |
double_number | read | Doubles a number and returns the result |
dummy | read | Dummy tool |
duplicate-tool | read | First |
echo | read | Echo back text |
echo_value | read | Echo a string value |
edit | write | Edit a file. |
evidence | read | Inspect project-scoped evidence cards and provenance |
example | read | Example |
explain | read | Explain where Memorix project context comes from |
export | read | Export session (HTML default, or specify path: .html/.jsonl) |
feedback | read | Record and audit memory feedback |
find | read | Find files by pattern |
fork | write | Create a new fork from a previous user message |
formation | read | Inspect Memory Formation Pipeline runtime metrics |
generated-skill | read | A generated skill |
get | read | Read a resolved Memorix config value |
get_circle | read | Returns a circle image for visualization |
get_circle_with_description | read | Returns a circle image with a text description |
get_current_time | read | Get the current date and time |
get_memory_detail | read | Retrieve the full narrative and facts of a specific memory observation by its ID. Use this after search_memories when you need more context about a specific result. |
git-hook-install | write | Install git post-commit hook for automatic memory capture |
git-hook-uninstall | destructive | Remove memorix git post-commit hook |
grep | read | Search a file |
handoff | write | Create structured handoff artifacts between agents |
help | read | Show help |
hidden | read | Hidden |
hidden-skill | read | A hidden skill. |
hook | read | Handle agent hook event (called by agent hook configs) |
hooks | read | Manage automatic memory hooks for agents |
hotkeys | read | Show all keyboard shortcuts |
identity | read | Select the explicit CLI actor used for private or team-scoped operations |
image | read | Analyze an image and store the result as memory |
import | write | Import and resume a session from a JSONL file |
ingest | read | Ingest engineering knowledge from Git and images |
init | read | Initialize Memorix TOML configuration |
injected | read | Injected skill |
inspect | read | Inspect things |
inspect_schema | read | Inspect the schema |
install | write | Install Memorix hooks for IDEs (interactive) |
integrate | read | Generate integration files for a specific IDE or agent |
knowledge | read | Initialize, review, and lint the Memorix Knowledge Workspace |
link | read | Target |
linkedin_skill | read | Get LinkedIn comments |
list | read | List a directory |
list_recent_memories | read | List recent memory observations for the project. Use this when the user wants to see what has been stored recently or browse the knowledge base. |
load-skills | read | Load skills |
lock | read | Acquire, release, and inspect advisory team file locks |
log | read | Batch ingest recent git commits as memories |
login | read | Configure provider authentication |
logout | destructive | Remove provider authentication |
lookup | read | Look up a value |
math_operation | read | Perform basic arithmetic operations |
media | write | Import, attach, inspect, and clean controlled local media assets |
memcode | read | Enter memcode TUI — native coding agent with memory |
memorix | read | Shared workspace memory for Claude Code and other AI coding agents. |
memorix-local | read | Local marketplace for the Memorix Claude Code plugin. |
memorix_audit_project | read | |
memorix_codegraph_status | read | |
memorix_compaction_checkpoint | read | |
memorix_consolidate | read | |
memorix_context_pack | read | |
memorix_continuity | read | |
memorix_dashboard | read | |
memorix_deduplicate | read | |
memorix_detail | read | |
memorix_evidence | read | |
memorix_feedback | read | |
memorix_formation_metrics | read | |
memorix_graph_context | read | |
memorix_handoff | read | |
memorix_ingest_image | read | |
memorix_knowledge | read | |
memorix_media | read | |
memorix_poll | read | |
memorix_project_context | read | |
memorix_promote | read | |
memorix_resolve | read | |
memorix_retention | read | |
memorix_rules_sync | write | |
memorix_search | read | |
memorix_search_reasoning | read | |
memorix_session_context | read | |
memorix_session_end | read | |
memorix_session_start | write | |
memorix_skills | read | |
memorix_store | read | |
memorix_store_reasoning | read | |
memorix_suggest_topic_key | read | |
memorix_timeline | read | |
memorix_transfer | write | |
memorix_workspace_sync | write | |
memory | read | Show Memorix memory commands |
message | write | Send, broadcast, and read team messages from the CLI |
migrate | write | Write a TOML config from existing compatibility config |
model | read | Select model (opens selector UI) |
my-skill | read | Custom project instructions |
my_custom_tool | read | A custom tool |
name | write | Set session display name |
new | write | Start a new session |
one | read | One template |
open_nodes | read | |
orchestrate | write | Run structured multi-agent coordination loop |
path | read | Show Memorix TOML config paths |
ping | read | Ping tool |
poll | read | Get a full project coordination snapshot for an agent |
pr-review | read | Review and address PR comments |
preview | read | Preview files to be created by hooks installation |
prompt | read | prompt |
purge | destructive | Retire memories from retrieval (current project by default, --all for every project) |
quit | read | Quit ${APP_NAME} |
read | read | Read a file |
read_graph | read | |
reasoning | read | Store and search decision rationale from the operator CLI |
receipt | read | Generate a privacy-safe memory handoff receipt |
recent | read | Shortcut for |
reload | read | Reload keybindings, extensions, skills, prompts, and themes |
remember | read | Shortcut for |
repair | read | Repair Memorix-owned agent integration files |
resume | read | Resume a different session |
retention | read | Inspect retention state and archive expired memories |
review | read | Review template |
scoped-models | write | Enable/disable models for Ctrl+P cycling |
search | read | Shortcut for |
search_memories | read | Search the project memory knowledge base for relevant decisions, bugs, architecture notes, gotchas, or other engineering context. Use this when the user asks about project history, design rationale, known issues, or technical details. |
search_nodes | read | |
second | read | Second skill |
serve | write | Start Memorix MCP Server on stdio transport |
serve-http | write | Start the shared Memorix MCP control plane over HTTP |
session | read | Show session info and stats |
settings | read | Open settings menu |
setup | write | Install the best Memorix integration package for an agent |
share | read | Share session as a secret GitHub gist |
skill-one | read | First skill. |
skill-two | read | Second skill. |
skills | read | Discover, generate, and inspect project skills from the CLI |
status | read | Show hook installation status for all agents |
store_memory | read | Store a new memory observation to the project knowledge base. Use this when the user wants to save a decision, gotcha, bug fix, architecture note, or any engineering context worth remembering. |
sync | write | Interactive cross-agent synchronization plus explicit rules/workspace subcommands |
sync-store | write | Replicate the local observation store across your devices (opt-in, provider-agnostic) |
target | read | Target |
task | write | Create, claim, complete, and inspect team tasks |
team | read | Manage project-scoped orchestration coordination state |
team_file_lock | read | |
team_manage | read | |
team_message | read | |
team_task | read | |
test | read | test tool |
test-skill | read | A test skill. |
test_tool | read | A test tool |
todowrite | write | Write a todo item |
transfer | write | Export or import project memory snapshots |
tree | read | Navigate session tree (switch branches) |
trust | write | Save project trust decision for future sessions |
two | read | First line description |
uninstall | destructive | Remove automatic memory hooks for agents |
update_memory | write | Update an existing memory observation by its ID. Use this when the user wants to modify or add to an existing memory. Provide the ID and the fields to update. |
visible | read | Use <this> & that |
visible-skill | read | A visible skill. |
workbench | read | Open the interactive terminal memory control plane |
write | write | Write a file |
Trust audit
BLOCKgrade F · trust 39/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
image-payload.ts
exec(
}),!0),this.lastIndex=0}exec(e){this.matcherRe.lastIndex=this.lastIndexthis.rules.push([e,n]),"begin"===n.type&&this.count++}exec(e){darwin-modifiers.node
darwin-modifiers.node
win32-console-mode.node
win32-console-mode.node
const tokenSize = minTokenSize + Math.floor(Math.random() * (maxTokenSize - minTokenSize + 1));
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=5 CMD ["node", "-e", "fetch('http://127.0.0.1:3211/health').then(r => process.exit(r.ok ? 0 : 1)).catch(() => process.exit(1))"]"bbbab8b9b9b6b9b8b5bcbbb8b8b7b4b7b5b2b6b5b2b8b7b4b7b6b3b6b4b1bdbcb8bab8b6bbb8b5b8b5b1bbb8b4c2bebbc1bebac0bdbabfbcb9c1bebabfbebbc0bfbcc0bdbabbb8b5c1bfbcbfbcb8bbb9b6bfbcb8c2bfbcc1bfbcbfbbb8bdb9b6b8b7b5b
/**
const s = streamAnthropic(model, context, { apiKey: "tid_copilot_session_test_token" });apiKey: "tid_copilot_session_test_token",
apiKey: "gcp-vertex-credentials",
expect(content).toContain('api_key = "embedding-test-secret"');const secret = 'sk-abcdefghijklmnopqrstuvwxyz1234';
expect(containsCredential('ghp_abcdefghijklmnopqrstuvwxyz123456789012')).toBe(true);const token = 'ghp_abcdefghijklmnopqrstuvwxyz123456789012';
const input = '"token": "ghp_aBcDeFgHiJkLmNoPqRsTuVwXyZ0123456789"';
cleanup, clear, delete, delete_entities, delete_memory, delete_observations, delete_relations, git-hook-uninstall, logout, purge, uninstall
doom.wasm
.gitmodules
bedrock-thinking-payload.test.ts
provider-payload.ts
Gates applied: no_behavioural_pass.
0ddb6f2c10e1full audit observations/trust-audit/mcp-server/avids2__memorix.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 0ddb6f2c10e1 | BLOCK | F | 39 | first audit |
Questions
What is the Memorix MCP server?
Open-source cross-agent memory layer for coding agents via MCP. Compatible with Claude Code, Codex, Cursor, Windsurf, Gemini CLI, Antigravity, OpenClaw, Hermes Agent, Oh-my-Pi, Pi, Copilot, Kiro, OpenCode, and Trae.
What tools does Memorix expose?
193 in total: 148 read-only, 34 that write, and 11 that can delete or overwrite (cleanup, clear, delete, delete_entities, delete_memory). Every one is listed on this page with its risk.
Is Memorix safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (39/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 11 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Memorix need?
It reads AI_GATEWAY_API_KEY, ALIYUN_API_KEY, ANTHROPIC_API_KEY, ANTHROPIC_OAUTH_TOKEN, ANT_LING_API_KEY, ATLASCLOUD_API_KEY, AUTH_TOKEN, AWS_ACCESS_KEY_ID, AWS_BEARER_TOKEN_BEDROCK, AWS_BEDROCK_SKIP_AUTH, AWS_CONTAINER_CREDENTIALS_FULL_URI and AWS_CONTAINER_CREDENTIALS_RELATIVE_URI from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Memorix run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as memorix-pi-package at 1.9.6.
How current is this page?
The grade is for one exact copy of the source (0ddb6f2c10e1), read on 2026-09-28. The repository is watched and re-audited when it changes.