Atlas / MCP servers / ferroxlabs / IJFW

IJFWBLOCK

mcp/ferroxlabs/ijfw-1

IJFW — It Just F*cking Works. Ferrox Labs' local-first infrastructure for AI coding agents: shared memory, smart routing, multi-AI cross-audits, disciplined workflow.

Verdict
BLOCK
Grade
F
Trust score
36 /100
Exposed tools
9 7r · 2w · 0d
Transport
—
License
MIT
Stars
212
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<img src="docs/guide/assets/ferrox-hero.png" alt="Ferrox Labs' IJFW (It Just F*cking Works): local-first infrastructure for AI coding agents, shown as eight engines: shared memory (cross-session recall), workflow discipline (plan, gate, execute), cross-audit (multi-model review), specialist bench (skills on demand), token savings (smarter routing), observability (local dashboard), learns you (adapts from edits), and design contract (one design system). Runs under Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, OpenCode, Qwen, Kimi, OpenClaw, Aider, and more." width="100%"/>

Your AI tools are brilliant, forgetful, undisciplined, and alone. One install fixes all four.

IJFW is one shared brain, and a full operating layer, for every AI coding tool you use. Install it once and your tools remember across sessions, plan before they build, check each other's work for hallucinations, pull in the right specialist for the job, and quietly cut your token bill. All on your machine. All yours.

npm install -g @ijfw/install && ijfw-install
Read from source at commit 08fb41baee56OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add express-api-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} --env FIGMA_TOKEN=${FIGMA_TOKEN} --env IJFW_AUTOLINK_API_KEY=${IJFW_AUTOLINK_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "express-api-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}",
        "FIGMA_TOKEN": "${FIGMA_TOKEN}",
        "IJFW_AUTOLINK_API_KEY": "${IJFW_AUTOLINK_API_KEY}"
      }
    }
  }
}
03

Exposed tools (9)

7 read · 2 write · 0 destructive.

ToolRiskDescription
ijfw_brainreadIJFW Brain — query, links, wiki, conflict-resolve in one combined tool. verb=
ijfw_cross_project_searchreadBM25-ranked search across every IJFW project ever opened on this machine. Results tagged [project:<basename>] with line numbers + snippets. Use when you need to recall how a similar problem was solved in another project. Reads ~/.ijfw/registry.md as the source of truth.
ijfw_memory_factsreadQuery the bi-temporal facts table (subject/predicate/object timeline with valid_from / valid_to). Default: current-valid rows only. Pass history=true for full timeline; pass valid_at=<ISO-8601> for point-in-time. Subject + predicate are required.
ijfw_memory_preludewriteCALL THIS AT SESSION START. Returns all relevant project memory in one pass -- knowledge base, handoff state, recent activity. Eliminates the need to grep/search/recall separately. Call once at the start of a session before answering the user.
ijfw_memory_searchreadKeyword search across memory sources. Up to 20 results. Scope defaults to current project; pass scope:
ijfw_memory_storereadPersist a decision, observation, or session state so it survives context resets. For decisions and patterns, add summary/why/how_to_apply for a richer knowledge-base entry. Returns isError on storage failure.
ijfw_metricsreadSee tokens/spend, model routing mix, and session totals -- the receipts behind your IJFW sessions. Aggregates from .ijfw/metrics/sessions.jsonl. Tolerates mixed v1/v2 lines.
ijfw_prompt_checkreadCall on the first turn when the user prompt is short (<30 tokens) or likely vague. Returns whether the prompt is under-specified and a sharpening suggestion. Deterministic regex detector -- no LLM call. Use for Codex/Cursor/Windsurf/Copilot/Gemini where pre-prompt hooks are not available.
ijfw_update_checkwriteCheck if an IJFW update is available. Issues a confirmation token; the user must run
04

Trust audit

BLOCKgrade F · trust 36/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (15 observation(s))
Network
declared (13 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.anthropic · CWE-798, CWE-321
mcp-server/test-redactor.js:22
const out = redactSecrets('claude sk-ant-api03-ABCDEFGHIJKLMNOPQRSTUVWXYZ');
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
mcp-server/test-redactor.js:27
const out = redactSecrets('GH ghp_abcdefghijklmnopqrstuvwxyz0123456789');
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
mcp-server/test-redactor.js:32
const out = redactSecrets('token: github_pat_11ABCDEFGHIJKLMNO_abcdefghijklmn');
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
mcp-server/test-redactor.js:77
const pem = '-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASC...\n-----END PRIVATE KEY-----';
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
mcp-server/test-redactor.js:47
const out = redactSecrets('slack=xoxb-1234567890-abcdefghij');
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
mcp-server/test-d2-symbol-graph.js:131
'src/auth/login.js loaded; sk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZ123456 ' + // gitleaks:allow -- synthetic redactor fixture
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
mcp-server/test-d2-symbol-graph.js:150
const stripe = classify('sk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZ123456'); // gitleaks:allow -- synthetic redactor fixture
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
mcp-server/test-ingest-redaction.js:52
const STRIPE_LIVE = 'sk_live_TESTABC123DEFGHIJKLMNOPQRSTUVWXYZ';
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
mcp-server/test-memory-engine-audit-fixes.js:99
const SECRET = 'sk_live_TESTABC123DEFGHIJKLMNOPQRSTUVWXYZ'; // gitleaks:allow -- synthetic fixture proving the scrub gate
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
mcp-server/test-redactor.js:335
const r = classifyAnchored('sk_live_abcdefghijklmnopqrstuvwxyz123456');
CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
claude/skills/ijfw-update/SKILL.md:38
5. **V155-017 (v1.5.5):** `ijfw_update_apply` was retired from the MCP tool surface — it was redundant given that `ijfw_update_check` already writes the sentinel + issues the token in one step. If an 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp-server/test-sandbox-vm-bans.js:56
const f = Function('return 1+1');
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp-server/test-sandbox-vm-bans.js:80
const env = Function('return process.env')();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
mcp-server/src/audit-roster.js:70
note: 'Different training lineage; fast on review tasks. The - flag reads prompt from stdin. --skip-git-repo-check bypasses the trusted-directory gate added in codex-cli 0.118.0. --sandbox read-only b
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
mcp-server/src/compute/sandbox-macos.js:62
'.npmrc', '.pypirc', '.netrc', '.gitconfig', '.gitconfig.local',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
mcp-server/test-sandbox-allowlist.js:67
{ name: 'fake-ssh-id_rsa', body: 'CANARY-SSH-PRIVATE-KEY-DO-NOT-USE' },
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
mcp-server/test-sandbox-allowlist.js:100
{ name: '~/.ssh subpath', path: join(home, '.ssh') },
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
mcp-server/test-sandbox-allowlist.js:102
{ name: '~/.aws subpath', path: join(home, '.aws') },
Why it matters. touches a credential store
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
mcp-server/test-blackboard.js:444
assert.equal(archives.length, 0, 'no in-tree gz archive of the exfiltrated bytes');
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
mcp-server/test-memory-feedback.js:143
await writeFile(targetFile, JSON.stringify({ verdict: 'FAIL', affected_artifacts: [{ type: 'EXFIL' }] }), 'utf8');
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
mcp-server/test-memory-feedback.js:159
assert.ok(!types.includes('EXFIL'), 'symlinked target body must not leak into results');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/bin/ijfw-dashboard:140
const url  = 'http://127.0.0.1:' + port;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/bin/ijfw-dashboard:144
console.log('[ijfw] Dashboard running at http://127.0.0.1:' + port);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/test-cost-endpoints.js:23
const res = await fetch(`http://127.0.0.1:${port}${path}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
mcp-server/test-dashboard-audit-fixes.js:53
const base = `http://127.0.0.1:${port}`;

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-06 · audit v0.4.1 · source sha 08fb41baee56full audit observations/trust-audit/mcp-server/ferroxlabs__ijfw-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0608fb41baee56BLOCKF36first audit
06

Questions

What is the IJFW MCP server?

IJFW — It Just F*cking Works. Ferrox Labs' local-first infrastructure for AI coding agents: shared memory, smart routing, multi-AI cross-audits, disciplined workflow.

What tools does IJFW expose?

9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is IJFW safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (36/100) and found 18 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does IJFW need?

It reads ANTHROPIC_API_KEY, AWS_SECRET_ACCESS_KEY, FIGMA_TOKEN, IJFW_AUTOLINK_API_KEY, IJFW_CTX_WINDOW_TOKENS, IJFW_STATE_GATE_BYPASS, JWT_SECRET, SSH_AUTH_SOCK and TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (08fb41baee56), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement