MemClawBLOCK
Caura (formerly MemClaw) — governed shared memory for AI agent fleets. Multi-agent, multi-tenant, MCP-native. Trust tiers, keystone policies, audit trails, knowledge graph, self-improving retrieval. Apache 2.0.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Caura — Shared governed memory for AI agents
Fleet memory for AI agents — governed, shared, self-improving.
MemClaw is now Caura — same product, one name. Existing memclaw* tool calls and supported MEMCLAW environment aliases continue to work; use caura_ names and current Caura URLs for new configuration. The PyPI name memclaw-client is kept only as a redirect shell (0.5.1) that installs caura-client; it provides no memclaw_client import and no MemClaw class. The npm package @caura/memclaw-client was never published.
Quick Start · Features · Performance · MCP · API Reference · Plugin Docs ·
c2e413b09d28OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add plugin --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ATLASCLOUD_API_KEY=${ATLASCLOUD_API_KEY} --env CAURA_API_KEY=${CAURA_API_KEY} --env CAURA_KEYSTONES_ENABLED=${CAURA_KEYSTONES_ENABLED} -- npx -y @caura/[email protected]{
"mcpServers": {
"plugin": {
"command": "npx",
"args": [
"-y",
"@caura/[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"ATLASCLOUD_API_KEY": "${ATLASCLOUD_API_KEY}",
"CAURA_API_KEY": "${CAURA_API_KEY}",
"CAURA_KEYSTONES_ENABLED": "${CAURA_KEYSTONES_ENABLED}"
}
}
}
}Exposed tools (17)
15 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Caura | read | Central persistent memory for OpenClaw agents with cross-fleet, multi-agent shared recall |
Direct | read | agent-authored |
Forged | read | forged |
Legacy | read | legacy |
bad-skill | read | nope |
caura_doc | read | return f |
caura_write | write | raise RuntimeError( |
deploy-runbook | write | deploy steps |
git-rebase-safety | read | rebase steps |
good | read | ok |
good-skill | read | ok |
incident-triage | read | triage steps |
should-be-ignored | read | should-be-ignored |
skill-a | read | alpha |
skill-b | read | bravo — newly shared |
valid-slug | read | ok |
x | read | exploit |
Trust audit
BLOCKgrade F · trust 31/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
payload.py
_CLOUD_METADATA_IPS = frozenset({"169.254.169.254", "fd00:ec2::254"})return getattr(importlib.import_module(module_name), attr)
package = importlib.import_module(package_name)
importlib.import_module(f"{package_name}.{name}")print(f"token : {token}")print(f"token : {token}")print(f"token : {token}")"key sk-ant-api03-AbCdEf123456GhIjKl789 rotated"
"api_key = 'hijklmnopqrstuvwx1234'",
assert PIICategory.SECRET in _cats('api_key = "Aa1Bb2Cc3Dd4Ee5Ff6Gg7Hh8"')secret = "aB3xK9mP2qR7sT1vW5yZ8nQ4" # 24 chars, high entropy → trips the gate
text = "-----BEGIN RSA PRIVATE KEY-----\n" + ("A" * 200_000)pem = "-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA\n-----END RSA PRIVATE KEY-----"
assert PIICategory.SECRET in _cats("-----BEGIN RSA PRIVATE KEY-----")"xoxb-1234567890-abcdefghij",
.env.test
.pre-commit-config.yaml
.release-please-manifest.json
restored = pickle.loads(pickle.dumps(exc.value))
restored = pickle.loads(pickle.dumps(exc.value))
model = getattr(importlib.import_module(module), name)
module = importlib.import_module(module_name)
exec(
_MACHINE_ID_SHORT = hashlib.sha1(
Gates applied: no_behavioural_pass.
c2e413b09d28full audit observations/trust-audit/mcp-server/caura-ai__memclaw.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | c2e413b09d28 | BLOCK | F | 31 | first audit |
Questions
What is the MemClaw MCP server?
Caura (formerly MemClaw) — governed shared memory for AI agent fleets. Multi-agent, multi-tenant, MCP-native. Trust tiers, keystone policies, audit trails, knowledge graph, self-improving retrieval. Apache 2.0.
What tools does MemClaw expose?
17 in total: 15 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MemClaw safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (31/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does MemClaw need?
It reads ANTHROPIC_API_KEY, ATLASCLOUD_API_KEY, CAURA_API_KEY, CAURA_KEYSTONES_ENABLED, CAURA_KEYSTONES_TOKEN_CAP, CORE_STORAGE_SHARED_SECRET, GEMINI_API_KEY, GOOGLE_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, PLATFORM_EMBEDDING_API_KEY and PLATFORM_LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MemClaw run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @caura/plugin at 2.23.3.
How current is this page?
The grade is for one exact copy of the source (c2e413b09d28), read on 2026-10-01. The repository is watched and re-audited when it changes.