MemexBLOCK
Zettelkasten-based persistent memory for AI coding agents. Works with Claude Code, Cursor, VS Code Copilot, Codex, Windsurf & any MCP client. No vector DB — just markdown + git sync.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/iamtouchskyer-memex)
Persistent memory for AI coding agents. Your agent remembers what it learned across sessions.
English | 中文 | 日本語 | 한국어 | Español
English
Every time your AI agent finishes a task, it saves insights as atomic knowledge cards with [[bidirectional links]]. Next session, it recalls relevant cards before starting work — building on what it already knows instead of starting from scratch.
No vector database, no embeddings — just markdown files your agent (and you) can read.
Supported platforms
All platforms share the same ~/.memex/cards/ directory. A card written in Claude Code is instantly available in Cursor, Codex, or any other client.
Prerequisites
- VS Code / Copilot: No prerequisites — the extension bundles everything
- Claude Code: No prerequisites — the plugin handles everything
- Pi: Requires Node.js 18+ and
npm install -g @touchskyer/memex - All other platforms (Cursor, Codex, Windsurf, etc.): Requires Node.js 18+
Install
Step 1: Add memex to your editor
2a690b1dd8f6OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add memex -- npx -y @touchskyer/[email protected]
Exposed tools (12)
8 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
flomo_import_parse | write | |
flomo_push | write | |
memex_archive | read | |
memex_links | read | |
memex_organize | read | |
memex_pull | read | |
memex_push | write | |
memex_read | read | |
memex_recall | read | |
memex_retro | read | |
memex_search | read | |
memex_write | write |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (21)
`\n 2. If no key exists: ssh-keygen -t ed25519 && ssh-add ~/.ssh/id_ed25519` +
memex-mcp-0.1.8.vsix
memex-mcp-0.1.9.vsix
"remote https://user:[email protected]/org/repo and token ghp_abcdefghijklmnopqrstuvwxyz1234567890",
const key = "-----BEGIN RSA PRIVATE KEY-----\nabc123\n-----END RSA PRIVATE KEY-----";
.windsurfrules
.vscodeignore
for (const path of ["~/.netrc", "~/.npmrc", "~/.docker/config.json", "~/.kube/config"]) {import { archiveCommand } from "../../src/commands/archive.js";import { CardStore } from "../../src/lib/store.js";import { backlinksCommand } from "../../src/commands/backlinks.js";import { CardStore } from "../../src/lib/store.js";import { MemexConfig } from "../../src/lib/config.js";JSON.stringify({ flomoWebhookUrl: "https://evil.com/exfil" }),endpoint: `http://127.0.0.1:${address.port}/openai/v1/`,@modelcontextprotocol/sdk, commander, gray-matter, zod, @types/node, esbuild, happy-dom, marked
@touchskyer/memex, @types/vscode, @vscode/vsce, typescript
dist/cli.js
dist/cli.js.map
vscode-extension/memex-mcp-0.1.10.vsix
vscode-extension/memex-mcp-0.1.16.vsix
Gates applied: no_behavioural_pass.
2a690b1dd8f6full audit observations/trust-audit/mcp-server/iamtouchskyer__memex-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 2a690b1dd8f6 | BLOCK | D | 69 | first audit |
Questions
What is the Memex MCP server?
Zettelkasten-based persistent memory for AI coding agents. Works with Claude Code, Cursor, VS Code Copilot, Codex, Windsurf & any MCP client. No vector DB — just markdown + git sync.
What tools does Memex expose?
12 in total: 8 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Memex safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Memex need?
It reads AZURE_OPENAI_API_KEY, AZURE_OPENAI_API_KEY_FILE, MEMEX_AZURE_OPENAI_API_KEY, MEMEX_AZURE_OPENAI_API_KEY_FILE and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Memex run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as memex-mcp at 0.1.22.
How current is this page?
The grade is for one exact copy of the source (2a690b1dd8f6), read on 2026-10-07. The repository is watched and re-audited when it changes.