iai Personal Memory EngineCAUTION
A cyber brain for your AI. It never forgets a detail, remembers exactly what you said, and learns how you work over time. Free, local, works with Cursor, Claude Code, Codex, OpenClaw, Hermes and more. MIT.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
Keeps every conversation word-for-word and gives your AI agent the right context on every turn.
Quick start · How it works · Benchmarks ·
41cdcb1304b9OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add iai-mcp-wrapper --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env IAI_DAEMON_TOKEN_PATH=${IAI_DAEMON_TOKEN_PATH} --env IAI_MCP_CRYPTO_PASSPHRASE=${IAI_MCP_CRYPTO_PASSPHRASE} --env IAI_MCP_EXACT_AUTHORITY_OFF=${IAI_MCP_EXACT_AUTHORITY_OFF} -- npx -y [email protected]{
"mcpServers": {
"iai-mcp-wrapper": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"IAI_DAEMON_TOKEN_PATH": "${IAI_DAEMON_TOKEN_PATH}",
"IAI_MCP_CRYPTO_PASSPHRASE": "${IAI_MCP_CRYPTO_PASSPHRASE}",
"IAI_MCP_EXACT_AUTHORITY_OFF": "${IAI_MCP_EXACT_AUTHORITY_OFF}"
}
}
}
}Exposed tools (15)
13 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
claim_check | read | Check a claim (e.g. |
curiosity_pending | read | List pending curiosity questions queued by the sleep daemon. Read-only. Filter by session_id. |
episodes_recent | read | Returns the N most-recent user-turn records, time-desc. |
events_query | read | Query user-visible events (kind whitelist). Read-only. Optional since (ISO-8601), severity, limit. |
memory_capture | read | Capture a verbatim turn (auto-dedups near-duplicates). |
memory_consolidate | write | Trigger sleep-cycle consolidation: schema induction, FSRS decay, Hebbian pruning. Mutates store; idempotent in one sleep window. |
memory_contradict | read | Mark a record contradicted; new fact stored as a NEW record (old NEVER deleted). Mutates store. |
memory_recall | read | Recall verbatim memories by cue — decisions, preferences, prior |
memory_recall_structural | read | Structural recall via TEM role->filler bindings (BSC hypervectors). Read-only. Prefer over memory_recall for role-filler queries. |
memory_reinforce | read | Boost Hebbian edges among co-retrieved record ids. Mutates edge weights. Use when two records co-answered. |
memory_search | read | Use for code/doc search; returns hints to verify — never replaces |
memory_temporal_recall | read | Time-travel recall: as_of bounds records, changed_since filters events. Read-only. |
profile_get_set | write | Read or write a profile knob (10 sealed: 9 AUTIST + wake_depth). operation get|set; returns knob value. |
schema_list | read | List induced schemas (Tier-0 + Tier-1) from sleep consolidation. Read-only. Filter by domain and confidence_min. |
topology | read | Snapshot of memory-graph topology: N, C, L, sigma, community_count, regime. Read-only diagnostic; sigma never toggles retrieval. |
Trust audit
CAUTIONgrade F · trust 59/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (13 observation(s))
- Network
- declared (11 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
vectors.npy
icon.icns
print(f"unknown directive id: {token}", file=sys.stderr)print(f"directive already retired: {token}", file=sys.stderr)print(f"ambiguous directive id prefix: {token}", file=sys.stderr)except Exception: # noqa: BLE001 -- the beacon is advisory
except Exception: # noqa: BLE001 -- beacon is advisory
except Exception: # noqa: BLE001 -- beacon is advisory
if let Ok(url) = format!("http://127.0.0.1:{port}/").parse() {url = f"http://127.0.0.1:{server.server_address[1]}/""| N slice | ΔMRR mean | stdev | min | max | robust? |",
"B-class ΔMRR (CI) | B-contract hint% / anti-hits% | "
"- **Metric B-classical (rank current above cosine)** tests an expectation the system does not promise: it uses dual-route + inhibitory edges + hints, not rerank. Expect ΔMRR ≈ 0; this is a feature, n
("ru-net-pravilno", re.compile(r"\bнет,\s*правильно\b", re.IGNORECASE)),("ru-vspomni-pravilnyi", re.compile(r"\bвспомни(?:ть)?\s+правильн\w*\b", re.IGNORECASE)),$ErrorActionPreference = "SilentlyContinue"
round_trip.bin
bsc_bundle_10000.bin
bsc_fillers_sample.bin
restored = pickle.loads(pickle.dumps(cls))
return importlib.import_module(f"iai_mcp_native.{name}")mod = importlib.import_module(f"iai_mcp_native.{sub}")mod = importlib.import_module(name)
exec(compile(ast.Module(body=definitions, type_ignores=[]),
digest = hashlib.md5(str(cue).encode("utf-8")).digest()Gates applied: no_behavioural_pass.
41cdcb1304b9full audit observations/trust-audit/mcp-server/codeabra__iai-personal-memory-engine.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 41cdcb1304b9 | CAUTION | F | 59 | first audit |
Questions
What is the iai Personal Memory Engine MCP server?
A cyber brain for your AI. It never forgets a detail, remembers exactly what you said, and learns how you work over time. Free, local, works with Cursor, Claude Code, Codex, OpenClaw, Hermes and more. MIT.
What tools does iai Personal Memory Engine expose?
15 in total: 13 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is iai Personal Memory Engine safe to connect to an agent?
With care. The audit graded it F (59/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does iai Personal Memory Engine need?
It reads ANTHROPIC_API_KEY, IAI_DAEMON_TOKEN_PATH, IAI_MCP_CRYPTO_PASSPHRASE, IAI_MCP_EXACT_AUTHORITY_OFF, IAI_MCP_SCHEMA_BYPASS_COS_THRESHOLD and PYTHON_KEYRING_BACKEND from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does iai Personal Memory Engine run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as iai-mcp-wrapper at 3.2.3.
How current is this page?
The grade is for one exact copy of the source (41cdcb1304b9), read on 2026-09-30. The repository is watched and re-audited when it changes.