CortexBLOCK
Memory for AI agents that never leaves your device. Local-first, end-to-end-encrypted, zero-telemetry memory engine (Rust, MCP) — gives Claude & any MCP client persistent cross-session memory.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/gambletan/cortex/stargazers) [](https://opensource.org/licenses/MIT)
[🧠 Try Cortex in your browser](https://gambletan.github.io/cortex/) — zero install, 124KB WASM, runs entirely client-side. If Cortex helps your AI remember, [give it a ⭐](https://github.com/gambletan/cortex/stargazers) — it takes 1 second and helps others discover the project.
中文 | 日本語 | 한국어
Local memory for personal AI agents.
Private. Free. Local. — a memory engine for personal AI agents.
Your AI's memory archive lives on your device. Pure Rust. 3.8MB binary. The local engine needs no hosted service and collects zero telemetry. Optional encrypted sync uses your own cloud storage; optional Muse sharing sends only the excerpts you approve to Cortex Cloud and Meta. (On-device semantic search downloads a ~30MB model once on first use, then runs fully offline — or go 100% offline with CORTEX_NO_EMBEDDINGS=1. See Security & Privacy.)
What you get
- 🔒 Private by default — memories live in a local SQLite file; sync and Muse sharing require explicit opt-in. Zero telemetry (CI-enforced).
- 🧠 Real memory, not a text file — 4 tiers, multi-signal retrieval, self-correcting Bayesian beliefs, a cross-channel people graph.
- ⚡ Sub-millisecond — 156μs ingest, 568μs search. ~528× faster than cloud memory APIs, with no network round-trip.
- 🔌 Drop-in for any agent — one MCP server gives Claude Code / Claude Desktop (or any MCP client) persistent cross-session memory.
- 🤝 Connect Meta Muse to chosen excerpts — your archive stays local. The optional service at
https://cortex.alvinsclub.aiserves only your approved e
3bc7bcf5a959OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cortex-http:2.4.0 -- docker run -i --rm ghcr.io/gambletan/cortex/cortex-http:2.4.0:None
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (24)
SSH_KEY="${SSH_KEY:-$HOME/.ssh/id_ed25519_usa}"$TMPDB4
$TMPDB4-shm
$TMPDB4-wal
(["Carmen leads the Beacon coalition.",
"The Beacon coalition lobbies the Granite assembly.",
assert!(check_transport("http://127.0.0.1:8080").is_ok());assert!(check_transport("http://127.0.0.1.evil.example").is_err());let _ = s.write_all(b"HTTP/1.1 307 Temporary Redirect\r\nLocation: http://127.0.0.1:1/x\r\nContent-Length: 0\r\n\r\n");
let dev = Device::new(Device::generate_secret(), Some("AAAAAAAAAAAAAAAAAAAAAA".into()), format!("http://127.0.0.1:{port}"));cortex_wasm_bg.wasm
"the beacon memory travels",
.retrieve_with_namespace("beacon memory", 5, None, None, None, None).retrieve_with_namespace("beacon memory", 5, None, None, None, None)format!("http://127.0.0.1:{}", self.port)esbuild, typescript
@types/node, typescript
Run: curl -fsSL https://raw.githubusercontent.com/gambletan/cortex/main/install.sh | bash -s -- --ide claude
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
curl -fsSL https://raw.githubusercontent.com/gambletan/cortex/main/install.sh | bash
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
curl -fsSL https://raw.githubusercontent.com/gambletan/cortex/main/install.sh | bash
bench/data/locomo10.json
Gates applied: no_behavioural_pass.
3bc7bcf5a959full audit observations/trust-audit/mcp-server/gambletan__cortex-9.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3bc7bcf5a959 | BLOCK | D | 69 | first audit |
Questions
What is the Cortex MCP server?
Memory for AI agents that never leaves your device. Local-first, end-to-end-encrypted, zero-telemetry memory engine (Rust, MCP) — gives Claude & any MCP client persistent cross-session memory.
Is Cortex safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Cortex need?
It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Cortex run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @cortex-ai-memory/cortex-memory at 2.4.0.
How current is this page?
The grade is for one exact copy of the source (3bc7bcf5a959), read on 2026-10-08. The repository is watched and re-audited when it changes.