CurionCAUTION
Curion is a project-local memory layer for AI coding agents, published as an MCP server for Claude Code, Codex, OpenCode, and other MCP clients.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@geanatz/curion) [](https://github.com/geanatz/curion/actions/workflows/ci.yml) [](https://docs.npmjs.com/generating-provenance-statements) [](https://github.com/geanatz/curion/blob/main/LICENSE)
Project-local memory layer for AI agents, exposed as a [Model Context Protocol](https://modelcontextprotocol.io) (MCP) stdio server.
Curion gives your AI agent a persistent memory of the project it is working in. Across sessions it can remember design decisions, architecture choices, team conventions, and anything else you choose to store — and recall the relevant pieces when you ask.
It runs as a local MCP stdio server that any compatible client can spawn. Each project has its own private store at .curion/; memories are never sent to a shared backend.
The public MCP API (the two tools, their strict input schemas, and the public text / structuredContent surfaces) is stable and frozen.
Table of contents
- Why Curion
- Quick start
- Other MCP clients
- Example prompts
- Key features
- Privacy & storage
- Configuration essentials
- Troubleshooting
- Documentation
- Support, security, and contributing
Why Curion
- Persistent, project-local memory. Design decisions, conventions, and
"things to remember" survive across sessions inside .curion/.
- Two tools, one surface.
remember(text)stores a piece of project
memory; recall(text) re
2ca2f3963870OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add curion -- npx -y @geanatz/[email protected]
Exposed tools (11)
11 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
false-premise-like | read | No-answer queries that mention a missing tool (a labeled false-premise case). |
negation-like | read | Queries the negation detector flagged (contain |
no-answer-easy | read | No-answer queries that are NOT hard-negatives (the |
no-answer-hard | read | No-answer queries that ARE hard-negatives (the |
ood-entity-like | read | Queries the OOD-entity detector flagged (mention a tool the corpus does not have, and share tokens with a legacy record). |
paraphrase-trap | read | Paraphrase-family queries (the known-bad lexical baseline case). |
recall | read | |
remember | read | |
temporal-current | read | Queries the temporal-current detector flagged (contain |
temporal-divergent | read | Temporal queries whose |
temporal-non-divergent | read | Temporal queries whose |
Trust audit
CAUTIONgrade F · trust 55/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
re: /\b(?:tell|instruct|program|configure|set\s+up)\s+(?:the\s+)?(?:next|future|coming|subsequent|downstream|any)\s+(?:agent|assistant|model|llm|ai)\s+to\s+(?:bypass|skip|disable|turn\s+off|switch\s+o
re: /\b(?:reveal|show|leak|exfiltrate|send|email|post|publish|export|dump)\s+(?:the\s+|all\s+)?(?:system\s+prompt|stored\s+(?:memories?|data|secrets?)|persisted\s+(?:memories?|data|secrets?)|saved\s+(
label: "exfiltrate-stored",
label: "exfiltrate-stored",
re: /\b(?:reveal|show|leak|exfiltrate|send|email|post|publish|export|dump)\b[^.!?\n]{0,80}\b(?:secrets?|tokens?|api[_ -]?keys?|passwords?|credentials?|private[_ -]?keys?)\b[^.!?\n]{0,40}\b(?:out|away|const ANTHROPIC_KEY = "sk-ant-test-not-real-1234567890abcdef";
const SECRET = "glpat-abcdefghijklmnopqrstuvwxyz0123456789";
const secret = "glpat-abcdefghijklmnopqrst";
const secret = "glpat-abcdefghijklmnopqrst";
apiKey: "sk-aaaaaaaaaaaaaaaaaaaaaaaaaa",
apiKey: "sk-aaaaaaaaaaaaaaaaaaaaaaaaaa",
"GitHub token: ghp_abcdefghijklmnopqrstuvwxyz0123456789",
"-----BEGIN RSA PRIVATE KEY-----\nMIIEog==\n-----END RSA PRIVATE KEY-----",
private_key: "-----BEGIN PRIVATE KEY-----",
"Slack: xoxb-12345-67890-abcdefghijkl",
.c8rc.json
import { tokenize } from "../../retrieval/lexical.js";} from "../../retrieval/lexical.js";
import { tokenize } from "../../retrieval/lexical.js";} from "../../retrieval/lexical.js";
} from "../../retrieval/lexical.js";
" policy held-out TNR% posAbst% hit5Ret% rank1Ret% curT1Ret% P R F1 | TNRΔ posAbstΔ hit5Δ rank1Δ curT1Δ PΔ RΔ F1Δ"
" family total hybrid(rank1) best(rank1) Δhybrid " +
"hybrid(hit5) ΔvsLexical bestSources"
" family total hybrid(rank1) best(rank1) Δhybrid " +
Gates applied: no_behavioural_pass.
2ca2f3963870full audit observations/trust-audit/mcp-server/geanatz__curion.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2ca2f3963870 | CAUTION | F | 55 | first audit |
Questions
What is the Curion MCP server?
Curion is a project-local memory layer for AI coding agents, published as an MCP server for Claude Code, Codex, OpenCode, and other MCP clients.
What tools does Curion expose?
11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Curion safe to connect to an agent?
With care. The audit graded it F (55/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Curion need?
It reads CURION_FALLBACK_API_KEY, CURION_PRIMARY_API_KEY, CURION_PROVIDER_FALLBACK_KEY, CURION_PROVIDER_PRIMARY_KEY, GROQ_API_KEY, MINIMAX_API_KEY and NVIDIA_NIM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Curion run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @geanatz/curion at 0.3.7.
How current is this page?
The grade is for one exact copy of the source (2ca2f3963870), read on 2026-10-08. The repository is watched and re-audited when it changes.