Atlas / MCP servers / geanatz / Curion

CurionCAUTION

mcp/geanatz/curion

Curion is a project-local memory layer for AI coding agents, published as an MCP server for Claude Code, Codex, OpenCode, and other MCP clients.

Verdict
CAUTION
Grade
F
Trust score
55 /100
Exposed tools
11 11r · 0w · 0d
Transport
stdio
License
Apache-2.0
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@geanatz/curion) [](https://github.com/geanatz/curion/actions/workflows/ci.yml) [](https://docs.npmjs.com/generating-provenance-statements) [](https://github.com/geanatz/curion/blob/main/LICENSE)

Project-local memory layer for AI agents, exposed as a [Model Context Protocol](https://modelcontextprotocol.io) (MCP) stdio server.

Curion gives your AI agent a persistent memory of the project it is working in. Across sessions it can remember design decisions, architecture choices, team conventions, and anything else you choose to store — and recall the relevant pieces when you ask.

It runs as a local MCP stdio server that any compatible client can spawn. Each project has its own private store at .curion/; memories are never sent to a shared backend.

The public MCP API (the two tools, their strict input schemas, and the public text / structuredContent surfaces) is stable and frozen.

Table of contents

  • Why Curion
  • Quick start
  • Other MCP clients
  • Example prompts
  • Key features
  • Privacy & storage
  • Configuration essentials
  • Troubleshooting
  • Documentation
  • Support, security, and contributing

Why Curion

  • Persistent, project-local memory. Design decisions, conventions, and

"things to remember" survive across sessions inside .curion/.

  • Two tools, one surface. remember(text) stores a piece of project

memory; recall(text) re

Read from source at commit 2ca2f3963870OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add curion -- npx -y @geanatz/[email protected]
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
false-premise-likereadNo-answer queries that mention a missing tool (a labeled false-premise case).
negation-likereadQueries the negation detector flagged (contain
no-answer-easyreadNo-answer queries that are NOT hard-negatives (the
no-answer-hardreadNo-answer queries that ARE hard-negatives (the
ood-entity-likereadQueries the OOD-entity detector flagged (mention a tool the corpus does not have, and share tokens with a legacy record).
paraphrase-trapreadParaphrase-family queries (the known-bad lexical baseline case).
recallread
rememberread
temporal-currentreadQueries the temporal-current detector flagged (contain
temporal-divergentreadTemporal queries whose
temporal-non-divergentreadTemporal queries whose
04

Trust audit

CAUTIONgrade F · trust 55/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/safety/precheck.ts:234
re: /\b(?:tell|instruct|program|configure|set\s+up)\s+(?:the\s+)?(?:next|future|coming|subsequent|downstream|any)\s+(?:agent|assistant|model|llm|ai)\s+to\s+(?:bypass|skip|disable|turn\s+off|switch\s+o
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/safety/precheck.ts:304
re: /\b(?:reveal|show|leak|exfiltrate|send|email|post|publish|export|dump)\s+(?:the\s+|all\s+)?(?:system\s+prompt|stored\s+(?:memories?|data|secrets?)|persisted\s+(?:memories?|data|secrets?)|saved\s+(
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/safety/precheck.ts:305
label: "exfiltrate-stored",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/safety/precheck.ts:310
label: "exfiltrate-stored",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/safety/precheck.ts:326
re: /\b(?:reveal|show|leak|exfiltrate|send|email|post|publish|export|dump)\b[^.!?\n]{0,80}\b(?:secrets?|tokens?|api[_ -]?keys?|passwords?|credentials?|private[_ -]?keys?)\b[^.!?\n]{0,40}\b(?:out|away|
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/anthropic-provider.test.ts:29
const ANTHROPIC_KEY = "sk-ant-test-not-real-1234567890abcdef";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/mcp-stdio-e2e.test.ts:974
const SECRET = "glpat-abcdefghijklmnopqrstuvwxyz0123456789";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/remember-safety.test.ts:394
const secret = "glpat-abcdefghijklmnopqrst";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/remember-safety.test.ts:638
const secret = "glpat-abcdefghijklmnopqrst";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/trace-tool-boundary.test.ts:684
apiKey: "sk-aaaaaaaaaaaaaaaaaaaaaaaaaa",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/trace.test.ts:370
apiKey: "sk-aaaaaaaaaaaaaaaaaaaaaaaaaa",
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/remember-mvp.test.ts:766
"GitHub token: ghp_abcdefghijklmnopqrstuvwxyz0123456789",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/remember-mvp.test.ts:772
"-----BEGIN RSA PRIVATE KEY-----\nMIIEog==\n-----END RSA PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/trace.test.ts:382
private_key: "-----BEGIN PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
tests/remember-mvp.test.ts:769
"Slack: xoxb-12345-67890-abcdefghijkl",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.c8rc.json
.c8rc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/benchmark/variants/dense-vector.ts:65
import { tokenize } from "../../retrieval/lexical.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/benchmark/variants/dense-vector.ts:70
} from "../../retrieval/lexical.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/benchmark/variants/fts5.ts:53
import { tokenize } from "../../retrieval/lexical.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/benchmark/variants/fts5.ts:58
} from "../../retrieval/lexical.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/benchmark/variants/hybrid.ts:101
} from "../../retrieval/lexical.js";
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/benchmark/held-out-validation.ts:904
"  policy                       held-out TNR%  posAbst%  hit5Ret%  rank1Ret%  curT1Ret%  P     R     F1   |  TNRΔ  posAbstΔ  hit5Δ  rank1Δ  curT1Δ  PΔ   RΔ   F1Δ"
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/benchmark/retrieval-runner.ts:2685
"  family         total  hybrid(rank1)  best(rank1)  Δhybrid  " +
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/benchmark/retrieval-runner.ts:2686
"hybrid(hit5)  ΔvsLexical  bestSources"
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/benchmark/retrieval-runner.ts:2787
"  family         total  hybrid(rank1)  best(rank1)  Δhybrid  " +

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2ca2f3963870full audit observations/trust-audit/mcp-server/geanatz__curion.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-082ca2f3963870CAUTIONF55first audit
06

Questions

What is the Curion MCP server?

Curion is a project-local memory layer for AI coding agents, published as an MCP server for Claude Code, Codex, OpenCode, and other MCP clients.

What tools does Curion expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Curion safe to connect to an agent?

With care. The audit graded it F (55/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Curion need?

It reads CURION_FALLBACK_API_KEY, CURION_PRIMARY_API_KEY, CURION_PROVIDER_FALLBACK_KEY, CURION_PROVIDER_PRIMARY_KEY, GROQ_API_KEY, MINIMAX_API_KEY and NVIDIA_NIM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Curion run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @geanatz/curion at 0.3.7.

How current is this page?

The grade is for one exact copy of the source (2ca2f3963870), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement