SmartStudy AgentBLOCK
The AI study agent that learns how you learn — RL picks the action, FSRS picks the timing, the LLM only writes the quizzes. Chrome extension · Anki export · MCP server · runs on Ollama
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The AI study agent that learns how you learn — a reinforcement-learning policy decides what you study next, an FSRS memory model decides when you review it, and an LLM generates the quizzes in between. In your browser, in your terminal, or inside Claude via MCP.
[](https://www.python.org/downloads/) [](https://www.anthropic.com/) [](https://streamlit.io/) -4A90E2.svg) [](https://github.com/open-spaced-repetition/py-fsrs) [](ankiexport.py) [](mcpserver.py) [](LICENSE) [](https://huggingface.co/spaces/HumphreySun98/smart-study-agent)
English · 中文简介 · 📚 Technical Deep Dive — the POMDP framing, the math behind both policies, and the experiments (including the ones the heuristic won)
🌐 Live — Two Ways to Use It
22c79c280350OBSERVED · 2026-10-07Exposed tools (8)
7 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
export_anki_deck | read | Export the student |
generate_quiz | read | Generate n multiple-choice questions on a topic using the configured |
get_student_profile | read | Get a student |
list_students | read | List all students known to SmartStudy. |
next_action | read | Ask the RL policy what to do next for this student+topic: |
record_quiz_result | read | Record a quiz result (0.0-1.0). Updates the belief state, trains the |
review_queue | read | Topics due for review right now (FSRS memory model), plus the full |
save_quiz_to_bank | write | Save generated questions to the student |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
atob( ... new Function(
digest = hashlib.md5(student_name.encode()).hexdigest()
anthropic, python-dotenv, numpy, openai, huggingface_hub, pypdf, rich, streamlit
chrome-extension/lib/pdfjs/pdf.worker.mjs
chrome-extension/screenshots/youtube.png
Gates applied: critical_finding, no_behavioural_pass.
22c79c280350full audit observations/trust-audit/mcp-server/humphreysun98__smartstudy-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 22c79c280350 | BLOCK | D | 69 | first audit |
Questions
What is the SmartStudy Agent MCP server?
The AI study agent that learns how you learn — RL picks the action, FSRS picks the timing, the LLM only writes the quizzes. Chrome extension · Anki export · MCP server · runs on Ollama
What tools does SmartStudy Agent expose?
8 in total: 7 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SmartStudy Agent safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does SmartStudy Agent need?
It reads ANTHROPIC_API_KEY, HF_TOKEN and SMARTSTUDY_LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (22c79c280350), read on 2026-10-07. The repository is watched and re-audited when it changes.