Atlas / MCP servers / iamtouchskyer / Memex

MemexBLOCK

mcp/iamtouchskyer/memex-3

Zettelkasten-based persistent memory for AI coding agents. Works with Claude Code, Cursor, VS Code Copilot, Codex, Windsurf & any MCP client. No vector DB — just markdown + git sync.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
12 8r · 4w · 0d
Transport
stdio
License
MIT
Stars
142
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/iamtouchskyer-memex)

Persistent memory for AI coding agents. Your agent remembers what it learned across sessions.

English | 中文 | 日本語 | 한국어 | Español

English

Every time your AI agent finishes a task, it saves insights as atomic knowledge cards with [[bidirectional links]]. Next session, it recalls relevant cards before starting work — building on what it already knows instead of starting from scratch.

No vector database, no embeddings — just markdown files your agent (and you) can read.

Supported platforms

All platforms share the same ~/.memex/cards/ directory. A card written in Claude Code is instantly available in Cursor, Codex, or any other client.

Prerequisites

  • VS Code / Copilot: No prerequisites — the extension bundles everything
  • Claude Code: No prerequisites — the plugin handles everything
  • Pi: Requires Node.js 18+ and npm install -g @touchskyer/memex
  • All other platforms (Cursor, Codex, Windsurf, etc.): Requires Node.js 18+

Install

Step 1: Add memex to your editor

Read from source at commit 2a690b1dd8f6OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add memex -- npx -y @touchskyer/[email protected]
03

Exposed tools (12)

8 read · 4 write · 0 destructive.

ToolRiskDescription
flomo_import_parsewrite
flomo_pushwrite
memex_archiveread
memex_linksread
memex_organizeread
memex_pullread
memex_pushwrite
memex_readread
memex_recallread
memex_retroread
memex_searchread
memex_writewrite
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (21)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/lib/sync.ts:107
`\n  2. If no key exists: ssh-keygen -t ed25519 && ssh-add ~/.ssh/id_ed25519` +
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.binary · CWE-1104
vscode-extension/memex-mcp-0.1.8.vsix
memex-mcp-0.1.8.vsix
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
vscode-extension/memex-mcp-0.1.9.vsix
memex-mcp-0.1.9.vsix
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/lib/sensitive-input.test.ts:70
"remote https://user:[email protected]/org/repo and token ghp_abcdefghijklmnopqrstuvwxyz1234567890",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/lib/sensitive-input.test.ts:31
const key = "-----BEGIN RSA PRIVATE KEY-----\nabc123\n-----END RSA PRIVATE KEY-----";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
vscode-extension/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/lib/sensitive-input.test.ts:104
for (const path of ["~/.netrc", "~/.npmrc", "~/.docker/config.json", "~/.kube/config"]) {
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/commands/archive.test.ts:5
import { archiveCommand } from "../../src/commands/archive.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/commands/archive.test.ts:6
import { CardStore } from "../../src/lib/store.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/commands/backlinks.test.ts:5
import { backlinksCommand } from "../../src/commands/backlinks.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/commands/backlinks.test.ts:6
import { CardStore } from "../../src/lib/store.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/commands/backlinks.test.ts:7
import { MemexConfig } from "../../src/lib/config.js";
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
tests/commands/flomo.test.ts:358
JSON.stringify({ flomoWebhookUrl: "https://evil.com/exfil" }),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/lib/azure-embeddings.test.ts:102
endpoint: `http://127.0.0.1:${address.port}/openai/v1/`,
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, commander, gray-matter, zod, @types/node, esbuild, happy-dom, marked
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
vscode-extension/package.json
@touchskyer/memex, @types/vscode, @vscode/vsce, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
dist/cli.js
dist/cli.js
Why it matters. 1610377 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
dist/cli.js.map
dist/cli.js.map
Why it matters. 2529572 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
vscode-extension/memex-mcp-0.1.10.vsix
vscode-extension/memex-mcp-0.1.10.vsix
Why it matters. 4741783 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
vscode-extension/memex-mcp-0.1.16.vsix
vscode-extension/memex-mcp-0.1.16.vsix
Why it matters. 4741788 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 2a690b1dd8f6full audit observations/trust-audit/mcp-server/iamtouchskyer__memex-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-072a690b1dd8f6BLOCKD69first audit
06

Questions

What is the Memex MCP server?

Zettelkasten-based persistent memory for AI coding agents. Works with Claude Code, Cursor, VS Code Copilot, Codex, Windsurf & any MCP client. No vector DB — just markdown + git sync.

What tools does Memex expose?

12 in total: 8 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Memex safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Memex need?

It reads AZURE_OPENAI_API_KEY, AZURE_OPENAI_API_KEY_FILE, MEMEX_AZURE_OPENAI_API_KEY, MEMEX_AZURE_OPENAI_API_KEY_FILE and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Memex run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as memex-mcp at 0.1.22.

How current is this page?

The grade is for one exact copy of the source (2a690b1dd8f6), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement