Atlas / MCP servers / iroha924 / sphica

sphicaBLOCK

mcp/iroha924/sphica

Local memory of past decisions for Claude Code and Codex. Records sessions and decisions in a local SQLite file and recalls them over MCP.

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
18 16r · 2w · 0d
Transport
stdio
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/iroha924/sphica/blob/main/LICENSE) [](https://github.com/iroha924/sphica/actions/workflows/check.yml) [](https://scorecard.dev/viewer/?uri=github.com/iroha924/sphica) [](https://www.bestpractices.dev/projects/14787) [](https://www.npmjs.com/package/sphica#provenance) [](https://github.com/iroha924/sphica/blob/main/.github/dependabot.yml)

What the badges cover: CI runs the checks in Contributing, and how each release is built and published is in Security. A passing badge does not mean the code is free of bugs or vulnerabilities.

English | 日本語

Local memory of past implementation and decisions for Claude Code and Codex. Sphica records your coding sessions, and keeps what was decided, rejected, deferred, and built, each record quoting the words it came from. Your agent finds those records when it searches, and sees the relevant ones on its own when it reads or edits a file they apply to (in Codex, before a shell command that names the file and before apply_patch). The database is a single SQLite file on your machine.

Features

  • Automatic recording. Sphica keeps your prompts, the agent's final reply for each turn, and the paths of the files a turn changed (by the edit tools, or seen in git status at the turn's end).
  • Records with their sources. /sphica:trace turns a session into
Read from source at commit 6c77b2e39584OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add sphica-server --env API_KEY=${API_KEY} --env TOKEN=${TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "sphica-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "TOKEN": "${TOKEN}"
      }
    }
  }
}
03

Exposed tools (18)

16 read · 2 write · 0 destructive.

ToolRiskDescription
exportread
fieldsread
forget_applywrite
forget_previewread
glean_beginread
glean_fetchread
harvest_beginread
overviewread
readread
record_checkread
record_contextread
record_savewrite
review_checkread
review_selectread
searchread
statusread
trace_beginread
trace_pendingread
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
none-observed
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/src/github.ts:65
const { stdout } = await exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
server/evals/cloud/claude-run.ts:20
export const DENY_FILES = [".npmrc", ".netrc"].map((p) => path.join(os.homedir(), p));
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/knowledge-schema
.claude/skills/knowledge-schema
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/plugin-agent-authoring
.claude/skills/plugin-agent-authoring
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/plugin-release
.claude/skills/plugin-release
Why it matters. link not followed
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
server/test/capture.test.ts:173
['password: "correcthorsebatterystaple"', "correcthorse"],
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
server/test/capture.test.ts:135
["gh: ghp_abcdefghijklmnopqrstuvwxyz0123456789", "ghp_abc"],
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
server/test/capture.test.ts:188
["-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA\n-----END RSA PRIVATE KEY-----", "MIIEowIB"],
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
server/test/capture.test.ts:281
"-----BEGIN RSA PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
server/test/record.test.ts:413
"-----BEGIN PRIVATE KEY-----\nkeyBody\n-----END PRIVATE KEY-----\n",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
server/test/text.test.ts:46
const keys = "-----BEGIN PRIVATE KEY-----\nx\n-----END PRIVATE KEY-----\n".repeat(20_000);
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
server/test/text.test.ts:55
const key = "-----BEGIN PRIVATE KEY-----\nMIIEvQ\n-----END PRIVATE KEY-----";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint-cli2.jsonc
.markdownlint-cli2.jsonc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/test/record.test.ts:1950
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/test/record.test.ts:1958
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/test/record.test.ts:1968
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
server/test/record.test.ts:1976
exec(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
server/evals/acceptance/driver.ts:1447
const fakeSha = (label: string): string => crypto.createHash("sha1").update(label).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
server/evals/acceptance/driver.ts:1457
const sha = (s) => crypto.createHash("sha1").update(s).digest("hex");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/check-ai-config.mjs:470
if (/dist\/cli\.js/.test(source) && !source.includes("../../dist/cli.js")) {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/check-ai-config.mjs:471
fail(`${relative}: calls the sphica CLI but has no ../../dist/cli.js for Codex`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/evals/acceptance/driver.ts:11
import { checkAnchor } from "../../src/anchors.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/evals/acceptance/driver.ts:12
import { askedBefore, askedText } from "../../src/asked.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/evals/acceptance/driver.ts:13
import { callerOf } from "../../src/caller.ts";
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
server/test/codex-trust.test.ts:58
'{"event_name":"user_prompt_submit","hooks":[{"async":false,"command":"powershell.exe -NoProfile -NonInteractive -EncodedCommand JgAgAG4AbwBkAGUAIAAiACQAZQBuAHYAOgBQAEwAVQBHAEkATgBfAFIATwBPAFQALwBkAGk

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6c77b2e39584full audit observations/trust-audit/mcp-server/iroha924__sphica.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076c77b2e39584BLOCKF54first audit
06

Questions

What is the sphica MCP server?

Local memory of past decisions for Claude Code and Codex. Records sessions and decisions in a local SQLite file and recalls them over MCP.

What tools does sphica expose?

18 in total: 16 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is sphica safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does sphica need?

It reads API_KEY and TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does sphica run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as sphica-server at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (6c77b2e39584), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement