sphicaBLOCK
Local memory of past decisions for Claude Code and Codex. Records sessions and decisions in a local SQLite file and recalls them over MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/iroha924/sphica/blob/main/LICENSE) [](https://github.com/iroha924/sphica/actions/workflows/check.yml) [](https://scorecard.dev/viewer/?uri=github.com/iroha924/sphica) [](https://www.bestpractices.dev/projects/14787) [](https://www.npmjs.com/package/sphica#provenance) [](https://github.com/iroha924/sphica/blob/main/.github/dependabot.yml)
What the badges cover: CI runs the checks in Contributing, and how each release is built and published is in Security. A passing badge does not mean the code is free of bugs or vulnerabilities.
English | 日本語
Local memory of past implementation and decisions for Claude Code and Codex. Sphica records your coding sessions, and keeps what was decided, rejected, deferred, and built, each record quoting the words it came from. Your agent finds those records when it searches, and sees the relevant ones on its own when it reads or edits a file they apply to (in Codex, before a shell command that names the file and before apply_patch). The database is a single SQLite file on your machine.
Features
- Automatic recording. Sphica keeps your prompts, the agent's final reply for each turn, and the paths of the files a turn changed (by the edit tools, or seen in
git statusat the turn's end). - Records with their sources.
/sphica:traceturns a session into
6c77b2e39584OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sphica-server --env API_KEY=${API_KEY} --env TOKEN=${TOKEN} -- npx -y [email protected]{
"mcpServers": {
"sphica-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"TOKEN": "${TOKEN}"
}
}
}
}Exposed tools (18)
16 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
export | read | |
fields | read | |
forget_apply | write | |
forget_preview | read | |
glean_begin | read | |
glean_fetch | read | |
harvest_begin | read | |
overview | read | |
read | read | |
record_check | read | |
record_context | read | |
record_save | write | |
review_check | read | |
review_select | read | |
search | read | |
status | read | |
trace_begin | read | |
trace_pending | read |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- none-observed
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const { stdout } = await exec(export const DENY_FILES = [".npmrc", ".netrc"].map((p) => path.join(os.homedir(), p));
.claude/skills/knowledge-schema
.claude/skills/plugin-agent-authoring
.claude/skills/plugin-release
['password: "correcthorsebatterystaple"', "correcthorse"],
["gh: ghp_abcdefghijklmnopqrstuvwxyz0123456789", "ghp_abc"],
["-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA\n-----END RSA PRIVATE KEY-----", "MIIEowIB"],
"-----BEGIN RSA PRIVATE KEY-----",
"-----BEGIN PRIVATE KEY-----\nkeyBody\n-----END PRIVATE KEY-----\n",
const keys = "-----BEGIN PRIVATE KEY-----\nx\n-----END PRIVATE KEY-----\n".repeat(20_000);
const key = "-----BEGIN PRIVATE KEY-----\nMIIEvQ\n-----END PRIVATE KEY-----";
.markdownlint-cli2.jsonc
exec(
exec(
exec(
exec(
const fakeSha = (label: string): string => crypto.createHash("sha1").update(label).digest("hex");const sha = (s) => crypto.createHash("sha1").update(s).digest("hex");if (/dist\/cli\.js/.test(source) && !source.includes("../../dist/cli.js")) {fail(`${relative}: calls the sphica CLI but has no ../../dist/cli.js for Codex`);import { checkAnchor } from "../../src/anchors.ts";import { askedBefore, askedText } from "../../src/asked.ts";import { callerOf } from "../../src/caller.ts";'{"event_name":"user_prompt_submit","hooks":[{"async":false,"command":"powershell.exe -NoProfile -NonInteractive -EncodedCommand JgAgAG4AbwBkAGUAIAAiACQAZQBuAHYAOgBQAEwAVQBHAEkATgBfAFIATwBPAFQALwBkAGkGates applied: no_behavioural_pass.
6c77b2e39584full audit observations/trust-audit/mcp-server/iroha924__sphica.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6c77b2e39584 | BLOCK | F | 54 | first audit |
Questions
What is the sphica MCP server?
Local memory of past decisions for Claude Code and Codex. Records sessions and decisions in a local SQLite file and recalls them over MCP.
What tools does sphica expose?
18 in total: 16 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is sphica safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does sphica need?
It reads API_KEY and TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does sphica run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as sphica-server at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (6c77b2e39584), read on 2026-10-07. The repository is watched and re-audited when it changes.