Agents RememberBLOCK
A branch-aware, dual-revision epistemic ledger and control plane for AI coding agents. From requirements and isolated work to validated changes and durable, queryable project truth.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Agents Remember
Git-verified records for what your coding agents know. A control plane for what they do.
📖 Current docs: https://foxfire1st.github.io/agents-remember/ 🤖 Machine-readable summary: https://foxfire1st.github.io/agents-remember/llms.txt Note: caches and search snippets may serve an outdated copy of this README — the docs site above is canonical and always current.
##
Table of Contents
- Why It Exists
- Core Features
- What It Looks Like In Practice
- Live Demo
- Requirements
- Quickstart
- Run The Dashboard
- Documentation
- Repository Layout
- Status
- Stability
- Contributing
Why It Exists
Modern coding agents can make clean, plausible edits while missing the project-specific rules that make those edits safe. A top-level instruction file can help, but it does not naturally reappear when the agent is deep in a file and deciding what to change.
Agents Remember fixes that: the matching note is reachable at the moment of the edit — most often by the very path the agent is already working in — so project rules surface exactly when a change is being made, not buried in a top-level file.
Core Features
**Agents Remember gives coding agents project memory they can v
ee438f56b6a9OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add repository-profile-node-fixture --env AR_DAGGER_RUNTIME_AUTHORITY_DIGEST=${AR_DAGGER_RUNTIME_AUTHORITY_DIGEST} -- npx -y [email protected]{
"mcpServers": {
"repository-profile-node-fixture": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AR_DAGGER_RUNTIME_AUTHORITY_DIGEST": "${AR_DAGGER_RUNTIME_AUTHORITY_DIGEST}"
}
}
}
}Exposed tools (64)
44 read · 20 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Model | read | Model used by this harness session |
cgc_callees | read | List what a function calls (its callees) from the CodeGraphContext graph. Read-only; |
cgc_callers | read | List the callers of a function from the CodeGraphContext graph. Read-only; needs the cgc |
cgc_complexity | read | Report complexity metrics from the CodeGraphContext graph (whole repo, or one function |
cgc_dependencies | read | Report a module |
cgc_symbol_search | read | Find a symbol in the CodeGraphContext code graph. Read-only; needs the |
cgc_visualize | read | Produce a CodeGraphContext graph visualization (serves a browser view on `port`). Needs |
citation_fix | read | Regenerate anchored citation ranges inside one leaf memory worktree. The enclosure |
closeout_queue | read | Inspect or idempotently rebuild one sprint |
codex_benchmark_prepare | read | Prepare resettable benchmark case workspaces (clones repos, materializes coordination). |
codex_benchmark_run | write | Run a Codex benchmark case (executes Codex agents in a sandbox). Refused unless the MCP |
context_packet | read | Bundle a repository |
curator_coherence | write | Author, publish, inspect, or validate one leaf |
direct_landing | write | Verify one series code commit and durably serialize its memory + ledger writes. |
dispatch_agent | write | Create and durably brief one child seat on a canonical task document plus role. |
drift_check | write | Task-start gate: classify how far onboarding has drifted from the code since it was last |
gate_decide | read | Decide the one open gate matching an authorized child document and kind. |
gate_list | read | List folded gates in the caller |
grepai_search | read | Semantic search over memory/onboarding via the grepai provider. Read-only; needs the |
grepai_trace | read | Trace relationships in the grepai semantic graph for a symbol. trace_action is |
lifecycle_end | read | End the active lifecycle. outcome is |
lifecycle_finalize_task | read | Finalize one parent-child task lifecycle edge. The task |
lifecycle_gate | read | Raise a gate on the caller |
lifecycle_phase | write | Move the active lifecycle along its phase axis (orthogonal to state): one of |
lifecycle_resume | read | Resume the active lifecycle from blocked back to running once the gate or question |
lifecycle_start | write | Begin a new session lifecycle and become its running owner. Guarded: rejected |
lifecycle_turn_end_notification | write | Notify the developer the turn is complete and stop -- no wait, no gate; the next AR |
memory_baseline_adopt | write | Create the first attributed memory baseline for an external memory repo. Mutating: commits |
memory_baseline_status | read | Report drift and Git attribution state to decide whether an external-memory baseline can be |
memory_carryover_apply | write | Apply an approved plan inside the exact ordinary recovery leaf, committing attributed memory |
memory_carryover_plan | read | Plan (non-mutating) carrying richer onboarding from a source branch into the exact open |
memory_init | read | Initialize or repair a repository |
memory_quality_check | read | Prepare memory before certification admission using drift-integrity and style checks. |
message_child | read | Persist and deliver one whole message to an authorized direct child seat. |
message_parent | read | Persist and deliver one whole message to this seat |
ping | read | Liveness check. Returns server name, version, and transport. Read-only; no side effects. |
provider_diagnostics | read | Raw provider-native diagnostic detail (container states, ports, backend/embedder health, |
provider_status | read | Compact provider readiness summary (per-provider state ready/degraded/stopped, watcher |
provider_watchers | read | Control provider watchers. action: |
read_ar_files | read | Read-only batch read of up to 5 repo-relative paths inside an AR-managed repo, |
rename_child | write | Change the display label of the current occupant of a direct child seat. |
rename_self | write | Change this hosted seat |
resolve_context | read | Resolve a repository |
retire_child | read | Retire the current occupant of one authorized direct child seat. |
route_index_refresh | read | Regenerate the overview.index.json route indexes so they match the current onboarding |
runtime_install | write | Install/refresh the packaged coordinator runtime into the coordination root. Safe to |
server_info | read | Report the resolved configuration: coordination/workspace/transcript roots, allowed |
skills_install | write | Copy the packaged skills into the harness skill root (e.g. .claude/skills) so the harness |
switch_lifecycle | read | Leave the current lifecycle and begin a fresh one. A persistent lifecycle is paused; |
task_doc | read | return task_doc_payload( |
task_reopen | read | Reopen a COMPLETED leaf under its exact same leaf id (no -rN suffix). A state |
worktree_abandon | read | Abandon a worktree-backed task WITHOUT integrating it. First prove that the enclosure |
worktree_attach | read | Re-attach to an existing task contract without mutating git, resuming its lifecycle |
worktree_checkpoint_landing | write | Partially PUBLISH an UNFINISHED atomic master: land its accumulated line into its super |
worktree_cleanup | read | Archive and read back one terminal generation |
worktree_closeout_apply | write | Start or observe an approved task-bound worktree closeout. A mutating call |
worktree_closeout_preview | read | Non-mutating preview of the bounded closeout Git transaction. |
worktree_integrate | write | Start or observe task-bound landing onto its source branch (strategy |
worktree_operation_control | read | Retry, recover, resume, cancel, retire, or supersede one task generation. |
worktree_pause | write | PAUSE an atomic master: stop it and hand control back to the developer. Publishes |
worktree_record_landing | read | Record that this task |
worktree_start | write | Create or load a task contract plus code (and external-memory) git worktrees. Publishes |
worktree_status | read | Resolve the exact independent locator and enclosure-root manifest/journal, then report a |
worktree_sync | write | Pull the moved official line into a live worktree (issue #54). Mutating: fetches |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (12 observation(s))
- Network
- declared (14 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
return f"postgres://{user}:{password}@{host}:{port}/{database}?sslmode=disable"reducer.ts
useFilesTree.ts
return Language(getattr(importlib.import_module(module_name), attribute)())
const baseUrl = `http://127.0.0.1:${port}`;baseURL: process.env.AR_CHATS_E2E_BASE_URL ?? "http://127.0.0.1:8781",
baseURL: "http://127.0.0.1:5173",
url: "http://127.0.0.1:5173",
_ZWJ = ""
const TOKEN = "0123456789abcdef0123456789abcdef";
.git-blame-ignore-revs
.prettierignore
.prettierrc.json
return importlib.import_module(DAGGER_MODULE_ID)
return hashlib.sha1(framed, usedforsecurity=False).hexdigest()
digest = hashlib.sha1(VENDORED_VOCABULARY_URL.encode()).hexdigest()
digest = hashlib.sha1(
const dashboardDir = resolve(fileURLToPath(new URL("../../", import.meta.url)));const repoRoot = new URL("../../", import.meta.url);import { css, cva, cx } from "../../styled-system/css";import type { TaskDocumentRef } from "../../types/terminalCatalog";import { libraryConversationKey } from "../../test/fixtures/conversationWire";const base = process.argv[2] ?? "http://127.0.0.1:5173";
<div class="data"><div class="main-wrapper" role="main"><div class="main-content"><noscript><div class="h2"><span id="challenge-error-text">Enable JavaScript and cookies to continue</span></div></nosc
<div class="data"><div class="main-wrapper" role="main"><div class="main-content"><noscript><div class="h2"><span id="challenge-error-text">Enable JavaScript and cookies to continue</span></div></nosc
Gates applied: no_behavioural_pass.
ee438f56b6a9full audit observations/trust-audit/mcp-server/foxfire1st__agents-remember-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | ee438f56b6a9 | BLOCK | F | 56 | first audit |
Questions
What is the Agents Remember MCP server?
A branch-aware, dual-revision epistemic ledger and control plane for AI coding agents. From requirements and isolated work to validated changes and durable, queryable project truth.
What tools does Agents Remember expose?
64 in total: 44 read-only, 20 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Agents Remember safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Agents Remember need?
It reads AR_DAGGER_RUNTIME_AUTHORITY_DIGEST from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (ee438f56b6a9), read on 2026-10-08. The repository is watched and re-audited when it changes.