EntrolyBLOCK
Cut AI context cost without trusting the compressor. Every reduction is reversible, byte-exact recoverable, and carries an auditable receipt. Local-first, works through proxy, MCP, SDK, or agent wrapper.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Entroly — Select AI context with auditable recovery.
Receipt-backed selection records: what was kept, what was omitted, and the handle that recovers the exact original bytes. Compression you can undo, on your own repository, in one command — without replacing your model or agent architecture.
code --install-extension entroly.entroly-vscode · pip install -U entroly && entroly go · npx entroly
Entroly is an open-source, local-first AI token-efficiency and Context Assurance layer: budgeted evidence selection, recoverable context compression, content-addressed evidence recovery, and auditable receipts. Works through VS Code, Claude Code, Cursor, Codex, OpenClaw, GitHub Copilot, Aider, and OpenAI/Anthropic-compatible apps.
946959a19d7fOBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add entroly -- uvx entroly==1.0.85
claude mcp add entroly-mcp -- npx -y [email protected]
Exposed tools (114)
89 read · 22 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
advance_proof_guided_context | read | Verify one model round and return exact evidence or a final answer. |
allowed | read | return value + 1 |
analyze_codebase_health | read | Analyze codebase health (grade A-F). |
blast_radius | read | Analyze the blast radius of file changes on existing beliefs. Returns affected beliefs, risk level, and recommendations. |
checkpoint_state | write | Save current state for crash recovery. |
compile_beliefs | read | Compile source code into belief artifacts (Truth → Belief pipeline). Scans directory for source files, extracts entities, resolves dependencies, writes beliefs. |
compile_docs | read | Compile markdown documentation files into belief artifacts with confidence 0.80 (human-authored > machine-inferred). |
compress_image | read | Compress an image for vision model input, with optional OCR text extraction. |
compress_shell | read | Compress CLI output (git, npm, cargo, pytest, etc.) preserving errors and key info. |
coverage_gaps | read | Find source files with no corresponding belief in the vault. Identifies blind spots before running compile_beliefs. |
create_context_receipt | write | Create a Context Receipt from supplied documents. |
create_context_receipt_from_path | write | Create a Context Receipt from a local document file or directory. |
create_skill | write | Create a new skill from a capability gap (Evolution layer). Generates SKILL.md, tool.py, metrics.json, and test cases. |
denied | read | return |
eicv_suppress_hallucinations | read | Verify an LLM response and optionally rewrite hallucinated claims. |
eicv_verify_claim | read | Verify a single claim against evidence using the EICV pipeline. |
entroly-context | write | Show Entroly context savings or run |
entroly_dashboard | read | Show live value metrics: money saved, performance, bloat prevention, quality. |
entroly_retrieve | read | Retrieve exact source content omitted by compressed context. |
epistemic_route | read | Route a query through the CogOps Epistemic Ingress Controller. Inspects 4 signals (intent, belief coverage, freshness, risk) and selects one of 5 canonical flows. |
execute_flow | write | Execute a full canonical epistemic flow end-to-end. Routes query through the Ingress Controller then chains the appropriate pipeline. |
explain_context | read | Explain why each fragment was included/excluded in last optimization. |
explain_receipt_omission | read | Explain why a chunk was omitted from a Context Receipt. |
export_training_data | read | Export vault beliefs as JSONL training data for LLM finetuning. Filters out stale and low-confidence beliefs. |
get_stats | read | Get comprehensive session statistics. |
ingest_diagram | read | Ingest an image/diagram into context memory (requires PIL/OCR — not available in WASM runtime, use pip install entroly). |
ingest_diff | write | Ingest a code diff/patch into context memory. Converts unified diff into structured change summary with intent classification. |
ingest_voice | read | Ingest audio into context memory (requires whisper — not available in WASM runtime, use pip install entroly). |
inspect_proof_guided_context | read | Inspect the last durable proof-guided response without advancing it. |
learn_from_failures | write | Mine failure patterns from PRISM, vault, and evolution data. Optionally apply corrections. |
list_compression_receipts | read | List only receipts visible to this workspace/session scope. |
locate_evidence | read | Locate exact source spans without generating an answer. |
manage_skills | read | Manage CogOps skill lifecycle (Evolution layer). Actions: list, benchmark, promote. |
optimize_context | read | Select the optimal context subset for a token budget. Uses IOS + PRISM RL + Channel Coding. |
prefetch_related | read | Predict which files the LLM will need next based on co-access patterns and dependency graph. |
prepare_proof_guided_context | read | Prepare a durable proof-guided model request from local documents. |
prepare_task_dream | read | Prepare an expiring, receipt-backed task skill before agent work. |
process_change | read | Process a code change through the Change-Driven pipeline (Flow 4). Diff → ChangeSet → Review → Blast Radius → Vault. |
recall_relevant | read | Semantic recall of most relevant stored fragments. |
record_command_exit | read | Record the exit code of a command that was generated and executed. |
record_edit_outcome | write | Record whether the user accepted, reverted, or retried an AI edit. |
record_outcome | read | Record whether selected fragments led to success/failure (RL feedback). |
record_test_result | read | Record that tests RAN and either passed or failed for a request. |
recover_receipt_omission | read | Recover the full text of context a Context Receipt omitted. |
recover_shell | read | Recover full CLI output from a compression handle. |
refresh_beliefs | read | Mark beliefs as stale after file changes so the next verify pass will flag them for re-compilation. |
refresh_repository_index | read | Atomically rebuild the fixed repository snapshot. |
remember_fragment | read | Store a context fragment with automatic dedup and entropy scoring. |
render_context_receipt | read | Render a Context Receipt JSON artifact as a Markdown audit report. |
repo_file_map | read | Return the canonical Entroly file map across Python, Rust core, and WASM repos with ownership roles. |
repository_architecture | read | Return verified layers, communities, cycles, routes, and hotspots. |
repository_architecture_diff | read | Compare two committed architecture receipts and report structural drift. |
repository_change_impact | read | Return reverse file/call impact for known workspace-relative paths. |
repository_code_health | read | Audit verified complexity, cycles, coupling, and navigability risk. |
repository_file_move_apply | write | Apply a blocker-free module move after commitment and risk checks. |
repository_file_move_preview | write | Preview a headless Python module move with exact import rewrites. |
repository_git_architecture_diff | write | Compare a local Git commit with the verified worktree without checkout. |
repository_graph_query | read | Query verified typed neighbors, paths, relatedness, or impact. |
repository_graph_snapshot | read | Export the complete bounded graph as a portable committed snapshot. |
repository_graph_snapshot_check | read | Verify a shared snapshot and prove whether it matches current sources. |
repository_http_routes | read | Discover verified HTTP routes, mounted prefixes, handlers, and collisions. |
repository_interprocedural_flow | read | Trace source-verified arguments, parameters, returns, and consumers. |
repository_lsp_rename_preview | write | Run the operator-configured LSP and return a committed no-write plan. |
repository_map | read | Rank a receipt-backed structural map across the fixed repository. |
repository_program_graph | read | Return verified Python control flow and reaching definitions. |
repository_program_slice | read | Build a proof-carrying partial code slice from verified facts. |
repository_rename_apply | write | Apply a previewed rename after plan-hash and risk acknowledgement. |
repository_rename_preview | write | Preview exact rename edits; performs no writes and reports incompleteness. |
repository_runtime_overlay | read | Bind value-free runtime events to fresh source and symbol evidence. |
repository_safe_delete_apply | destructive | Apply a blocker-free delete after plan-hash and risk acknowledgement. |
repository_safe_delete_preview | destructive | Preview a headless delete; any known or lexical reference blocks it. |
repository_semantic_overlay | read | Verify external LSP/compiler ranges before trusting semantic edges. |
repository_summary | read | Return bounded counts and the deterministic repository-index digest. |
repository_symbol_graph | read | Trace freshness-checked static calls without guessing symbol identity. |
repository_tests_for_changes | read | Rank tests related to known changed paths without executing them. |
repository_verified_context | read | Return a partial code graph scoped to one task with a receipt. |
resume_state | read | Resume from the latest checkpoint. |
retrieve_compressed_span | read | Retrieve one in-scope span and debit returned tokens from savings. |
scan_for_vulnerabilities | read | Scan code for security vulnerabilities (SAST). |
search_compressed_spans | read | Search in-scope spans and return bounded exact excerpts. |
security_report | read | Session-wide security audit across all ingested fragments. |
security_scan | read | Scan content for prompt injection attacks and security threats. |
shared_memory_forget | destructive | Remove a shared memory entry by ID. |
shared_memory_list | read | List shared memory entries, optionally filtered by agent or tag. |
shared_memory_search | read | Search cross-agent shared memory by relevance. Returns entries from all agents. |
shared_memory_stats | read | Get cross-agent shared memory statistics. |
shared_memory_write | write | Write to cross-agent shared memory. Deduplicates near-identical entries via SimHash. |
smart_read | read | Read a file at an automatic or caller-chosen resolution. |
start_workspace_listener | write | Start a background workspace listener that continuously feeds repo changes into CogOps belief CI. |
steer_output | read | Classify query effort and return output steering directives + max_tokens budget. |
sync_workspace_changes | write | Synchronize workspace file changes into the belief and verification layers. Detects new/modified/deleted files, marks beliefs stale, recompiles. |
vault_hygiene_scan | read | Scan vault beliefs against each other for knowledge decay. |
vault_query | read | Query the CogOps Knowledge Vault for existing beliefs. Supports lookup by entity name or listing all. |
vault_search | read | Full-text search across all belief artifacts in the vault. Uses keyword matching with entity-name boosting. |
vault_status | read | Show the current state of the CogOps Knowledge Vault: total beliefs, verification status, confidence distribution, and routing statistics. |
vault_time_travel | read | Query the vault |
vault_write_action | write | Write a task output or report to the CogOps Knowledge Vault (actions/). |
vault_write_belief | write | Write a belief artifact to the CogOps Knowledge Vault with machine-auditable frontmatter. |
verify_and_repair | read | Verify LLM-generated code and suggest repairs for hallucinations. |
verify_beliefs | write | Run a full verification pass on all beliefs. Checks staleness, contradictions, confidence divergence, low confidence scores. |
verify_provenance | read | Verify that LLM-generated code is grounded in the provided context. |
verify_response | read | Verify an AI-generated response for hallucination. Computes entity coverage gap, hedging curvature, and entropy consistency. Returns fused_risk [0.0=safe, 1.0=hallucinated], verdict (pass/warn/flag), and flagged claims. All local — zero LLM calls. |
work_acknowledge_recovery | read | Accept responsibility for recovered work state so acting is allowed. |
work_claim | read | Record explicit agent work plus a bounded advisory scope lease. |
work_compile_context | read | Compile verified code context and record its Work Graph receipt. |
work_context_fault | read | Fault exact omitted code from a context token or verified context object. |
work_handoff | write | Create a graph-bound handoff receipt and complete continuation proof. |
work_modifications | read | Modifications recorded between observations by the workspace watcher. |
work_record_context | read | Attach a canonical ContextReceipt to its exact WorkScope. |
work_record_execution | read | Atomically record route, observable execution and exact-head verification. |
work_record_memory | read | Attach provenance-bearing memory without trusting raw model prose. |
work_resume | read | Recover unfinished work and optionally seal a no-handoff proof. |
work_session_status | read | Report the automatic takeover performed when this server started. |
work_state | read | Inspect persisted shared work state without appending a polling event. |
Trust audit
BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (18 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
if lower.contains("-----begin private key-----")|| lower.contains("-----begin rsa private key-----")assert!(has_safety_signal("-----BEGIN PRIVATE KEY-----\nabc"));assert!(has_safety_signal("-----BEGIN RSA PRIVATE KEY-----\nabc"));pattern: "pickle.loads(",description: "pickle.loads() on untrusted data executes arbitrary code during deserialization.",
pattern: "pickle.load(",description: "pickle.load() from a file or stream — RCE if file is attacker-controlled.",
pattern: "yaml.load(",pub fn eval(&self, x: &[f32], y: &[f32]) -> f32 {pattern: "exec(",description: "exec() with request-derived content — arbitrary code execution.",
fix: "Never exec() user-supplied content. If dynamic dispatch is needed, use a whitelist of safe operations.",
"id_rsa*", "id_dsa*", "id_ecdsa*", "id_ed25519*",
".npmrc", ".pypirc", ".netrc", "_netrc", ".htpasswd",
"metadata.google.internal",
pattern: "verify=false",
fix: "Remove verify=False. If using self-signed certs in dev, configure a custom CA bundle instead.",
entroly.mcpb
gradle-wrapper.jar
return importlib.import_module(mod_name).loads(raw)
mod = importlib.import_module(mod_name)
module = importlib.import_module(module_name)
param = random.choice(list(TUNABLE_PARAMS.keys()))
console.log(` ${C.CYAN}demo${C.RESET} Before/after demo showing token savings`);Gates applied: critical_finding, no_behavioural_pass.
946959a19d7ffull audit observations/trust-audit/mcp-server/juyterman1000__entroly.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | 946959a19d7f | BLOCK | F | 41 | first audit |
Questions
What is the Entroly MCP server?
Cut AI context cost without trusting the compressor. Every reduction is reversible, byte-exact recoverable, and carries an auditable receipt. Local-first, works through proxy, MCP, SDK, or agent wrapper.
What tools does Entroly expose?
114 in total: 89 read-only, 22 that write, and 3 that can delete or overwrite (repository_safe_delete_apply, repository_safe_delete_preview, shared_memory_forget). Every one is listed on this page with its risk.
Is Entroly safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (41/100) and found 18 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Entroly need?
It reads ANTHROPIC_API_KEY, API_KEY, ENTROLY_BYPASS, ENTROLY_CONTROL_TOKEN, ENTROLY_ELC_BUDGET_TOKENS, ENTROLY_GITHUB_TOKEN, ENTROLY_MAX_CONTEXT_TOKENS, ENTROLY_MCP_PASSIVE, ENTROLY_OPENCLAW_RECEIPT_KEY_FILE, ENTROLY_PASSIVE_FEEDBACK, ENTROLY_PROXY_ACCESS_TOKEN and ENTROLY_ROUTING_AUTHORITY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Entroly run?
It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as entroly-openclaw at 1.0.85.
How current is this page?
The grade is for one exact copy of the source (946959a19d7f), read on 2026-10-01. The repository is watched and re-audited when it changes.