EionBLOCK
Shared Memory Storage for Multi-Agent Systems
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Eion
Connecting AI agents through shared memory and collaborative intelligence.
[](https://www.gnu.org/licenses/agpl-3.0)
[](https://discord.gg/mMNckGYVbq)
Eion is a shared memory storage that provides unified knowledge graph capabilities for multi-agent systems, adapting to different AI deployment scenarios from single LLM applications to complex multi-agency systems.
1. LLM Application
User ↔ LLM Application → Eion (context storage)
2. AI Agent Application
Business Logic ↔ AI Agent → Eion (memory + knowledge graph)
3. Agency (Multi-Agent) Systems
3a. Sequential Agency
Agent A → context → Agent B → context → Agent C ↓ ↓ ↓ Eion ← shared memory & knowledge → Eion
3b. Concurrent Live Agency (WIP)
Agent A ──┐ ├── shared live context ← Eion (live sync + notifications) Agent B ──┤ │ Agent C ──┘
4. External Guest Agent Access
Internal Agency: Agent A ↔ Agent B → Eion ← External Agent C (guest) ↑ (controlled access)
Quick Start
Prerequisites
- Docker & Docker Compose: For PostgreSQL and Neo4j
- Go 1.21+: For the Eion server
- Python 3.13+: For knowledge extraction services
1. Clone and Setup
96836e112a44OBSERVED · 2026-10-06Exposed tools (8)
3 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_memory | write | Store new memory in an Eion session |
create_knowledge | write | Store new knowledge in an Eion session |
delete_knowledge | destructive | Delete all knowledge from an Eion session |
delete_memory | destructive | Delete specific memories from an Eion session |
get_memory | read | Retrieve recent memories from an Eion session |
search_knowledge | read | Search for knowledge in an Eion session using semantic query |
search_memory | read | Search for memories in an Eion session using text query |
update_knowledge | write | Update existing knowledge in an Eion session |
Trust audit
BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (17)
Exec(ctx)
Exec(ctx)
Exec(ctx)
Exec(ctx)
Exec(ctx)
echo " PostgreSQL: postgresql://eion:eion_pass@localhost:5432/eion"
# password: "your-secure-password"
delete_knowledge, delete_memory
hash_obj = hashlib.md5()
anthropic, requests, python-dotenv, ../
mcp, httpx, pydantic, asyncio, uvloop
pydantic, requests, python-dotenv, networkx, numpy, neo4j, jinja2, orjson
assets/eion-cream.png
assets/eion-demo.gif
assets/eion-navy.png
- **Resource Management**: Agent-owned resources with complex delegation, agents validate/approve each other's changes, elevated permission request chains
<option value="crud">Full Access (crud)</option>
Gates applied: no_behavioural_pass.
96836e112a44full audit observations/trust-audit/mcp-server/eiondb__eion.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 96836e112a44 | BLOCK | D | 64 | first audit |
Questions
What is the Eion MCP server?
Shared Memory Storage for Multi-Agent Systems
What tools does Eion expose?
8 in total: 3 read-only, 3 that write, and 2 that can delete or overwrite (delete_knowledge, delete_memory). Every one is listed on this page with its risk.
Is Eion safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (64/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Eion need?
It reads ALPHA_VANTAGE_API_KEY, ANTHROPIC_API_KEY, DB_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Eion run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (96836e112a44), read on 2026-10-06. The repository is watched and re-audited when it changes.