Atlas / MCP servers / codeabra / iai Personal Memory Engine

iai Personal Memory EngineCAUTION

mcp/codeabra/iai-personal-memory-engine

A cyber brain for your AI. It never forgets a detail, remembers exactly what you said, and learns how you work over time. Free, local, works with Cursor, Claude Code, Codex, OpenClaw, Hermes and more. MIT.

Verdict
CAUTION
Grade
F
Trust score
59 /100
Exposed tools
15 13r · 2w · 0d
Transport
stdio
License
MIT
Stars
896
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

Keeps every conversation word-for-word and gives your AI agent the right context on every turn.

Quick start · How it works · Benchmarks ·

Read from source at commit 41cdcb1304b9OBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add iai-mcp-wrapper --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env IAI_DAEMON_TOKEN_PATH=${IAI_DAEMON_TOKEN_PATH} --env IAI_MCP_CRYPTO_PASSPHRASE=${IAI_MCP_CRYPTO_PASSPHRASE} --env IAI_MCP_EXACT_AUTHORITY_OFF=${IAI_MCP_EXACT_AUTHORITY_OFF} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "iai-mcp-wrapper": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "IAI_DAEMON_TOKEN_PATH": "${IAI_DAEMON_TOKEN_PATH}",
        "IAI_MCP_CRYPTO_PASSPHRASE": "${IAI_MCP_CRYPTO_PASSPHRASE}",
        "IAI_MCP_EXACT_AUTHORITY_OFF": "${IAI_MCP_EXACT_AUTHORITY_OFF}"
      }
    }
  }
}
03

Exposed tools (15)

13 read · 2 write · 0 destructive.

ToolRiskDescription
claim_checkreadCheck a claim (e.g.
curiosity_pendingreadList pending curiosity questions queued by the sleep daemon. Read-only. Filter by session_id.
episodes_recentreadReturns the N most-recent user-turn records, time-desc.
events_queryreadQuery user-visible events (kind whitelist). Read-only. Optional since (ISO-8601), severity, limit.
memory_capturereadCapture a verbatim turn (auto-dedups near-duplicates).
memory_consolidatewriteTrigger sleep-cycle consolidation: schema induction, FSRS decay, Hebbian pruning. Mutates store; idempotent in one sleep window.
memory_contradictreadMark a record contradicted; new fact stored as a NEW record (old NEVER deleted). Mutates store.
memory_recallreadRecall verbatim memories by cue — decisions, preferences, prior
memory_recall_structuralreadStructural recall via TEM role->filler bindings (BSC hypervectors). Read-only. Prefer over memory_recall for role-filler queries.
memory_reinforcereadBoost Hebbian edges among co-retrieved record ids. Mutates edge weights. Use when two records co-answered.
memory_searchreadUse for code/doc search; returns hints to verify — never replaces
memory_temporal_recallreadTime-travel recall: as_of bounds records, changed_since filters events. Read-only.
profile_get_setwriteRead or write a profile knob (10 sealed: 9 AUTIST + wake_depth). operation get|set; returns knob value.
schema_listreadList induced schemas (Tier-0 + Tier-1) from sleep consolidation. Read-only. Filter by domain and confidence_min.
topologyreadSnapshot of memory-graph topology: N, C, L, sigma, community_count, regime. Read-only diagnostic; sigma never toggles retrieval.
04

Trust audit

CAUTIONgrade F · trust 59/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (13 observation(s))
Network
declared (11 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
bench/embedder_baseline/vectors.npy
vectors.npy
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
desktop/src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/iai_mcp/iai_cli.py:767
print(f"unknown directive id: {token}", file=sys.stderr)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/iai_mcp/iai_cli.py:770
print(f"directive already retired: {token}", file=sys.stderr)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/iai_mcp/iai_cli.py:773
print(f"ambiguous directive id prefix: {token}", file=sys.stderr)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/iai_mcp/core/__init__.py:585
except Exception:  # noqa: BLE001 -- the beacon is advisory
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/iai_mcp/socket_server.py:201
except Exception:  # noqa: BLE001 -- beacon is advisory
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/iai_mcp/socket_server.py:212
except Exception:  # noqa: BLE001 -- beacon is advisory
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/src-tauri/src/main.rs:213
if let Ok(url) = format!("http://127.0.0.1:{port}/").parse() {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/iai_mcp/brainview.py:1925
url = f"http://127.0.0.1:{server.server_address[1]}/"
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
bench/contradiction_longitudinal_claude.py:854
"| N slice | ΔMRR mean | stdev | min | max | robust? |",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
bench/contradiction_longitudinal_claude.py:866
"B-class ΔMRR (CI) | B-contract hint% / anti-hits% | "
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
bench/contradiction_longitudinal_claude.py:896
"- **Metric B-classical (rank current above cosine)** tests an expectation the system does not promise: it uses dual-route + inhibitory edges + hints, not rerank. Expect ΔMRR ≈ 0; this is a feature, n
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/iai_mcp/capture.py:439
("ru-net-pravilno", re.compile(r"\bнет,\s*правильно\b", re.IGNORECASE)),
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/iai_mcp/capture.py:440
("ru-vspomni-pravilnyi", re.compile(r"\bвспомни(?:ть)?\s+правильн\w*\b", re.IGNORECASE)),
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/iai_mcp/_deploy/hooks/iai-mcp-auto-scan-antigravity.ps1:1
$ErrorActionPreference = "SilentlyContinue"
LOWInventory / provenance · inv.binary · CWE-1104
fixtures/golden/_rails/round_trip.bin
round_trip.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
fixtures/golden/hdc/bsc_bundle_10000.bin
bsc_bundle_10000.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
fixtures/golden/hdc/bsc_fillers_sample.bin
bsc_fillers_sample.bin
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/test_native_submodule_names.py:59
restored = pickle.loads(pickle.dumps(cls))
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_native_submodule_names.py:18
return importlib.import_module(f"iai_mcp_native.{name}")
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_native_submodule_names.py:34
mod = importlib.import_module(f"iai_mcp_native.{sub}")
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_prime_cache_boundary.py:38
mod = importlib.import_module(name)
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/test_per_turn_recall_safety.py:436
exec(compile(ast.Module(body=definitions, type_ignores=[]),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
bench/contradiction_longitudinal_claude.py:376
digest = hashlib.md5(str(cue).encode("utf-8")).digest()

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 41cdcb1304b9full audit observations/trust-audit/mcp-server/codeabra__iai-personal-memory-engine.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-3041cdcb1304b9CAUTIONF59first audit
06

Questions

What is the iai Personal Memory Engine MCP server?

A cyber brain for your AI. It never forgets a detail, remembers exactly what you said, and learns how you work over time. Free, local, works with Cursor, Claude Code, Codex, OpenClaw, Hermes and more. MIT.

What tools does iai Personal Memory Engine expose?

15 in total: 13 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is iai Personal Memory Engine safe to connect to an agent?

With care. The audit graded it F (59/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does iai Personal Memory Engine need?

It reads ANTHROPIC_API_KEY, IAI_DAEMON_TOKEN_PATH, IAI_MCP_CRYPTO_PASSPHRASE, IAI_MCP_EXACT_AUTHORITY_OFF, IAI_MCP_SCHEMA_BYPASS_COS_THRESHOLD and PYTHON_KEYRING_BACKEND from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does iai Personal Memory Engine run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as iai-mcp-wrapper at 3.2.3.

How current is this page?

The grade is for one exact copy of the source (41cdcb1304b9), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement