Atlas / MCP servers / eiondb / Eion

EionBLOCK

mcp/eiondb/eion

Shared Memory Storage for Multi-Agent Systems

Verdict
BLOCK
Grade
D
Trust score
64 /100
Exposed tools
8 3r · 3w · 2d
Transport
stdio
License
AGPL-3.0
Stars
159
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Eion

Connecting AI agents through shared memory and collaborative intelligence.

[](https://www.gnu.org/licenses/agpl-3.0)

[](https://discord.gg/mMNckGYVbq)

Eion is a shared memory storage that provides unified knowledge graph capabilities for multi-agent systems, adapting to different AI deployment scenarios from single LLM applications to complex multi-agency systems.

1. LLM Application

User ↔ LLM Application → Eion (context storage)

2. AI Agent Application

Business Logic ↔ AI Agent → Eion (memory + knowledge graph)

3. Agency (Multi-Agent) Systems

3a. Sequential Agency

Agent A → context → Agent B → context → Agent C
↓              ↓              ↓
Eion ← shared memory & knowledge → Eion

3b. Concurrent Live Agency (WIP)

Agent A ──┐
├── shared live context ← Eion (live sync + notifications)
Agent B ──┤
│
Agent C ──┘

4. External Guest Agent Access

Internal Agency: Agent A ↔ Agent B → Eion ← External Agent C (guest)
↑
(controlled access)

Quick Start

Prerequisites

  • Docker & Docker Compose: For PostgreSQL and Neo4j
  • Go 1.21+: For the Eion server
  • Python 3.13+: For knowledge extraction services

1. Clone and Setup

Read from source at commit 96836e112a44OBSERVED · 2026-10-06
02

Exposed tools (8)

3 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_memorywriteStore new memory in an Eion session
create_knowledgewriteStore new knowledge in an Eion session
delete_knowledgedestructiveDelete all knowledge from an Eion session
delete_memorydestructiveDelete specific memories from an Eion session
get_memoryreadRetrieve recent memories from an Eion session
search_knowledgereadSearch for knowledge in an Eion session using semantic query
search_memoryreadSearch for memories in an Eion session using text query
update_knowledgewriteUpdate existing knowledge in an Eion session
03

Trust audit

BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (17)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/knowledge/service.go:660
Exec(ctx)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/knowledge/service.go:691
Exec(ctx)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/memory/migrations.go:25
Exec(ctx)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/memory/service.go:616
Exec(ctx)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
internal/memory/service.go:831
Exec(ctx)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
setup.sh:108
echo "  PostgreSQL: postgresql://eion:eion_pass@localhost:5432/eion"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
eion.yaml.example:70
#   password: "your-secure-password"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_knowledge, delete_memory
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
internal/numa/python/numa_module.py:42
hash_obj = hashlib.md5()
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
demo/requirements.txt
anthropic, requests, python-dotenv, ../
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
internal/mcp/requirements.txt
mcp, httpx, pydantic, asyncio, uvloop
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
pydantic, requests, python-dotenv, networkx, numpy, neo4j, jinja2, orjson
Why it matters. 17 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
assets/eion-cream.png
assets/eion-cream.png
Why it matters. 1376721 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/eion-demo.gif
assets/eion-demo.gif
Why it matters. 3482336 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/eion-navy.png
assets/eion-navy.png
Why it matters. 1434167 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/IMPLEMANTATION_PLAN.md:59
- **Resource Management**: Agent-owned resources with complex delegation, agents validate/approve each other's changes, elevated permission request chains
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
internal/console/templates/console.html:55
<option value="crud">Full Access (crud)</option>

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 96836e112a44full audit observations/trust-audit/mcp-server/eiondb__eion.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0696836e112a44BLOCKD64first audit
05

Questions

What is the Eion MCP server?

Shared Memory Storage for Multi-Agent Systems

What tools does Eion expose?

8 in total: 3 read-only, 3 that write, and 2 that can delete or overwrite (delete_knowledge, delete_memory). Every one is listed on this page with its risk.

Is Eion safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (64/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Eion need?

It reads ALPHA_VANTAGE_API_KEY, ANTHROPIC_API_KEY, DB_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Eion run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (96836e112a44), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement