Atlas / MCP servers / foxfire1st / Agents Remember

Agents RememberBLOCK

mcp/foxfire1st/agents-remember-1

A branch-aware, dual-revision epistemic ledger and control plane for AI coding agents. From requirements and isolated work to validated changes and durable, queryable project truth.

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
64 44r · 20w · 0d
Transport
—
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Agents Remember

Git-verified records for what your coding agents know. A control plane for what they do.

📖 Current docs: https://foxfire1st.github.io/agents-remember/ 🤖 Machine-readable summary: https://foxfire1st.github.io/agents-remember/llms.txt Note: caches and search snippets may serve an outdated copy of this README — the docs site above is canonical and always current.

##

Table of Contents

  1. Why It Exists
  2. Core Features
  3. What It Looks Like In Practice
  4. Live Demo
  5. Requirements
  6. Quickstart
  7. Run The Dashboard
  8. Documentation
  9. Repository Layout
  10. Status
  11. Stability
  12. Contributing

Why It Exists

Modern coding agents can make clean, plausible edits while missing the project-specific rules that make those edits safe. A top-level instruction file can help, but it does not naturally reappear when the agent is deep in a file and deciding what to change.

Agents Remember fixes that: the matching note is reachable at the moment of the edit — most often by the very path the agent is already working in — so project rules surface exactly when a change is being made, not buried in a top-level file.

Core Features

**Agents Remember gives coding agents project memory they can v

Read from source at commit ee438f56b6a9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add repository-profile-node-fixture --env AR_DAGGER_RUNTIME_AUTHORITY_DIGEST=${AR_DAGGER_RUNTIME_AUTHORITY_DIGEST} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "repository-profile-node-fixture": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AR_DAGGER_RUNTIME_AUTHORITY_DIGEST": "${AR_DAGGER_RUNTIME_AUTHORITY_DIGEST}"
      }
    }
  }
}
03

Exposed tools (64)

44 read · 20 write · 0 destructive.

ToolRiskDescription
ModelreadModel used by this harness session
cgc_calleesreadList what a function calls (its callees) from the CodeGraphContext graph. Read-only;
cgc_callersreadList the callers of a function from the CodeGraphContext graph. Read-only; needs the cgc
cgc_complexityreadReport complexity metrics from the CodeGraphContext graph (whole repo, or one function
cgc_dependenciesreadReport a module
cgc_symbol_searchreadFind a symbol in the CodeGraphContext code graph. Read-only; needs the
cgc_visualizereadProduce a CodeGraphContext graph visualization (serves a browser view on `port`). Needs
citation_fixreadRegenerate anchored citation ranges inside one leaf memory worktree. The enclosure
closeout_queuereadInspect or idempotently rebuild one sprint
codex_benchmark_preparereadPrepare resettable benchmark case workspaces (clones repos, materializes coordination).
codex_benchmark_runwriteRun a Codex benchmark case (executes Codex agents in a sandbox). Refused unless the MCP
context_packetreadBundle a repository
curator_coherencewriteAuthor, publish, inspect, or validate one leaf
direct_landingwriteVerify one series code commit and durably serialize its memory + ledger writes.
dispatch_agentwriteCreate and durably brief one child seat on a canonical task document plus role.
drift_checkwriteTask-start gate: classify how far onboarding has drifted from the code since it was last
gate_decidereadDecide the one open gate matching an authorized child document and kind.
gate_listreadList folded gates in the caller
grepai_searchreadSemantic search over memory/onboarding via the grepai provider. Read-only; needs the
grepai_tracereadTrace relationships in the grepai semantic graph for a symbol. trace_action is
lifecycle_endreadEnd the active lifecycle. outcome is
lifecycle_finalize_taskreadFinalize one parent-child task lifecycle edge. The task
lifecycle_gatereadRaise a gate on the caller
lifecycle_phasewriteMove the active lifecycle along its phase axis (orthogonal to state): one of
lifecycle_resumereadResume the active lifecycle from blocked back to running once the gate or question
lifecycle_startwriteBegin a new session lifecycle and become its running owner. Guarded: rejected
lifecycle_turn_end_notificationwriteNotify the developer the turn is complete and stop -- no wait, no gate; the next AR
memory_baseline_adoptwriteCreate the first attributed memory baseline for an external memory repo. Mutating: commits
memory_baseline_statusreadReport drift and Git attribution state to decide whether an external-memory baseline can be
memory_carryover_applywriteApply an approved plan inside the exact ordinary recovery leaf, committing attributed memory
memory_carryover_planreadPlan (non-mutating) carrying richer onboarding from a source branch into the exact open
memory_initreadInitialize or repair a repository
memory_quality_checkreadPrepare memory before certification admission using drift-integrity and style checks.
message_childreadPersist and deliver one whole message to an authorized direct child seat.
message_parentreadPersist and deliver one whole message to this seat
pingreadLiveness check. Returns server name, version, and transport. Read-only; no side effects.
provider_diagnosticsreadRaw provider-native diagnostic detail (container states, ports, backend/embedder health,
provider_statusreadCompact provider readiness summary (per-provider state ready/degraded/stopped, watcher
provider_watchersreadControl provider watchers. action:
read_ar_filesreadRead-only batch read of up to 5 repo-relative paths inside an AR-managed repo,
rename_childwriteChange the display label of the current occupant of a direct child seat.
rename_selfwriteChange this hosted seat
resolve_contextreadResolve a repository
retire_childreadRetire the current occupant of one authorized direct child seat.
route_index_refreshreadRegenerate the overview.index.json route indexes so they match the current onboarding
runtime_installwriteInstall/refresh the packaged coordinator runtime into the coordination root. Safe to
server_inforeadReport the resolved configuration: coordination/workspace/transcript roots, allowed
skills_installwriteCopy the packaged skills into the harness skill root (e.g. .claude/skills) so the harness
switch_lifecyclereadLeave the current lifecycle and begin a fresh one. A persistent lifecycle is paused;
task_docreadreturn task_doc_payload(
task_reopenreadReopen a COMPLETED leaf under its exact same leaf id (no -rN suffix). A state
worktree_abandonreadAbandon a worktree-backed task WITHOUT integrating it. First prove that the enclosure
worktree_attachreadRe-attach to an existing task contract without mutating git, resuming its lifecycle
worktree_checkpoint_landingwritePartially PUBLISH an UNFINISHED atomic master: land its accumulated line into its super
worktree_cleanupreadArchive and read back one terminal generation
worktree_closeout_applywriteStart or observe an approved task-bound worktree closeout. A mutating call
worktree_closeout_previewreadNon-mutating preview of the bounded closeout Git transaction.
worktree_integratewriteStart or observe task-bound landing onto its source branch (strategy
worktree_operation_controlreadRetry, recover, resume, cancel, retire, or supersede one task generation.
worktree_pausewritePAUSE an atomic master: stop it and hand control back to the developer. Publishes
worktree_record_landingreadRecord that this task
worktree_startwriteCreate or load a task contract plus code (and external-memory) git worktrees. Publishes
worktree_statusreadResolve the exact independent locator and enclosure-root manifest/journal, then report a
worktree_syncwritePull the moved official line into a live worktree (issue #54). Mutating: fetches
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (12 observation(s))
Network
declared (14 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
mcp/src/agents_remember/providers/grepai/lifecycle/core.py:408
return f"postgres://{user}:{password}@{host}:{port}/{database}?sslmode=disable"
MEDIUMInventory / provenance · inv.binary · CWE-1104
dashboard/src/data/conversation/reducer.ts
reducer.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
dashboard/src/panels/file-viewer/useFilesTree.ts
useFilesTree.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp/src/agents_remember/memory_quality/style/citations/grammars.py:221
return Language(getattr(importlib.import_module(module_name), attribute)())
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
dashboard/e2e-chats/support/daemon.ts:129
const baseUrl = `http://127.0.0.1:${port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
dashboard/playwright.chats-e2e.config.ts:34
baseURL: process.env.AR_CHATS_E2E_BASE_URL ?? "http://127.0.0.1:8781",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
dashboard/playwright.config.ts:15
baseURL: "http://127.0.0.1:5173",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
dashboard/playwright.config.ts:21
url: "http://127.0.0.1:5173",
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
mcp/src/agents_remember/serving/conversation/control/previews.py:26
_ZWJ = ""
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
dashboard/scripts/require-dagger-test-environment.test.mjs:7
const TOKEN = "0123456789abcdef0123456789abcdef";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.git-blame-ignore-revs
.git-blame-ignore-revs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
dashboard/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
dashboard/.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp/tests/test_agents_remember_quality.py:59
return importlib.import_module(DAGGER_MODULE_ID)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp/src/agents_remember/models/lifecycles/preparation.py:297
return hashlib.sha1(framed, usedforsecurity=False).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp/src/agents_remember/models/tokens.py:66
digest = hashlib.sha1(VENDORED_VOCABULARY_URL.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp/src/agents_remember/providers/current_state.py:79
digest = hashlib.sha1(
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/e2e-chats/support/daemon.ts:20
const dashboardDir = resolve(fileURLToPath(new URL("../../", import.meta.url)));
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/e2e-production/cockpit.production.spec.ts:31
const repoRoot = new URL("../../", import.meta.url);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/src/cockpit/Cockpit.tsx:12
import { css, cva, cx } from "../../styled-system/css";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/src/data/conversation-library/client.ts:8
import type { TaskDocumentRef } from "../../types/terminalCatalog";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
dashboard/src/data/conversation-library/store.test.ts:3
import { libraryConversationKey } from "../../test/fixtures/conversationWire";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
dashboard/e2e/ptyRenderBench.mjs:13
const base = process.argv[2] ?? "http://127.0.0.1:5173";
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
benchmarks/cases/tensorflow-check-numerics-xla/author-results/2026-05-19/with-onboarding/run-003.stderr:25
<div class="data"><div class="main-wrapper" role="main"><div class="main-content"><noscript><div class="h2"><span id="challenge-error-text">Enable JavaScript and cookies to continue</span></div></nosc
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
mcp/src/agents_remember/package_data/benchmarks/cases/tensorflow-check-numerics-xla/author-results/2026-05-19/with-onboarding/run-003.stderr:25
<div class="data"><div class="main-wrapper" role="main"><div class="main-content"><noscript><div class="h2"><span id="challenge-error-text">Enable JavaScript and cookies to continue</span></div></nosc

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha ee438f56b6a9full audit observations/trust-audit/mcp-server/foxfire1st__agents-remember-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08ee438f56b6a9BLOCKF56first audit
06

Questions

What is the Agents Remember MCP server?

A branch-aware, dual-revision epistemic ledger and control plane for AI coding agents. From requirements and isolated work to validated changes and durable, queryable project truth.

What tools does Agents Remember expose?

64 in total: 44 read-only, 20 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Agents Remember safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Agents Remember need?

It reads AR_DAGGER_RUNTIME_AUTHORITY_DIGEST from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (ee438f56b6a9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement