SugarBLOCK
Persistent memory for AI coding agents. Local-first, cross-session context, global knowledge, and optional autonomous task execution.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Persistent memory for AI coding agents.
Your AI agent starts every session with amnesia. The architecture decisions, conventions, and gotchas you explained last week are gone. Sugar is the local-first memory layer that remembers them for you - per project, across projects, on your machine.
Your memory. Your machine. Your data.
What Sugar Does
Sugar is a memory layer your AI coding agent can read and write directly:
- Project memory - Decisions, preferences, error patterns, and research stored per-project
- Global memory - Standards and guidelines shared across every project you work on
- Semantic search - Retrieve relevant context by meaning, not just keywords
- MCP integration - Your AI agent reads and writes memory directly during sessions
- Local-first - SQLite on your disk, no API keys, fully offline-capable
- Task queue - Optional autonomous execution, powered by the same memory layer
Quick Start
# Install once, use in any project pipx install sugarai # Initialize in your project cd ~/dev/my-app sugar init # Store what you know sugar remember "We use async/await everywhere, never callbacks" --type preference sugar remember "JWT tokens use RS256, expire in 15 min - see auth/tokens.py" --type decision sugar remember "When tests fail with import errors, check __init__.py exports first" --type error_pattern # Retrieve it later sugar recall "authentication" sugar recall "how do we handle async"
Your AI agent can also read and write memory directly - no copy-pasting required.
MCP Integration
Connect Sugar's memory to your AI agent so it can access project context automatically.
Claude Code - Memory server (primary):
claude mcp add sugar -- sugar mcp memory
Claude Code - Task server (optional):
claude mcp add sugar-tasks -- sugar mcp tasks
Once connected, Claude can call store_learning to save context mid-session and `sea
b2bbbcc515e1OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sugarai -- None sugarai==3.10.2 mcp memory
claude mcp add sugarai -- None sugarai==3.10.2 mcp serve
Exposed tools (33)
23 read · 7 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_issue | read | Analyze a GitHub issue and return insights |
createTask | write | Create a new Sugar task for autonomous development |
find_similar_issues | read | Find issues similar to a given issue |
generate_response | read | Generate a response for a GitHub issue |
getStatus | read | Get Sugar system status and task queue metrics |
get_project_context | read | |
initSugar | read | Initialize Sugar in the current project directory |
listTasks | read | List Sugar tasks with optional filtering |
list_recent_memories | read | |
recall | read | |
removeTask | destructive | Remove a task from the queue |
runOnce | write | Execute one autonomous development cycle (picks up highest priority task) |
search_codebase | read | Search the codebase for relevant code |
search_memory | read | |
store_learning | read | |
sugar_add | write | Add a new task to Sugar |
sugar_add_task | write | |
sugar_list | read | List Sugar tasks with optional filtering by status, type, or priority |
sugar_list_tasks | read | |
sugar_priority | read | Change the priority of a task. Higher priority tasks are executed first. |
sugar_recall | read | Search Sugar |
sugar_remove | destructive | Remove a task from the work queue (cannot be undone) |
sugar_remove_task | destructive | |
sugar_run | write | Execute one autonomous development cycle. Sugar will pick the highest priority pending task and execute it. Use --dry-run to simulate without making changes. |
sugar_status | read | Get Sugar system status including task queue metrics and worker status |
sugar_task_status | read | |
sugar_update_task | write | |
sugar_view | read | View detailed information about a specific task including history and context |
sugar_view_task | read | |
suggest_labels | read | Suggest labels for an issue based on its content |
updateTask | write | Update an existing Sugar task |
validate_response | read | Validate a response before posting |
viewTask | read | View detailed information about a specific task |
Trust audit
BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (21)
"blocked_commands": ["sudo", "rm -rf /"],
"blocked_commands": ["sudo", "rm -rf /", "chmod 777"],
{"command": "sudo rm -rf /"},"blocked_commands": ["sudo"],
'/usr/local/bin/sugar',
"/usr/local/bin/sugar",
"/usr/local/bin/claude",
removeTask, sugar_remove, sugar_remove_task
.pre-commit-config.yaml
mock_find_claude.return_value = "/usr/local/bin/claude"
assert config["sugar"]["claude"]["command"] == "/usr/local/bin/claude"
eslint
@modelcontextprotocol/sdk, zod, @types/node, typescript
@types/bun, typescript, zod
aiosqlite, pyyaml, watchdog, gitpython, structlog, click, python-dotenv, claude-agent-sdk
@app.post("/session/{session_id}/prompt")- Never run Sugar with elevated privileges unless absolutely necessary
Add Sugar as an MCP server to give Claude Code full access to your memory:
# Add to ~/.bashrc or ~/.zshrc
- Add to your PATH, or
system use found in code, not declared in the description
Gates applied: no_behavioural_pass.
b2bbbcc515e1full audit observations/trust-audit/mcp-server/cdnsteve__sugar.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | b2bbbcc515e1 | BLOCK | F | 59 | first audit |
Questions
What is the Sugar MCP server?
Persistent memory for AI coding agents. Local-first, cross-session context, global knowledge, and optional autonomous task execution.
What tools does Sugar expose?
33 in total: 23 read-only, 7 that write, and 3 that can delete or overwrite (removeTask, sugar_remove, sugar_remove_task). Every one is listed on this page with its risk.
Is Sugar safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (59/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Sugar need?
It reads ANTHROPIC_API_KEY, GITHUB_TOKEN and OPENCODE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Sugar run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @anthropic/sugar-opencode at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (b2bbbcc515e1), read on 2026-10-09. The repository is watched and re-audited when it changes.