Atlas / MCP servers / juyterman1000 / Entroly

EntrolyBLOCK

mcp/juyterman1000/entroly

Cut AI context cost without trusting the compressor. Every reduction is reversible, byte-exact recoverable, and carries an auditable receipt. Local-first, works through proxy, MCP, SDK, or agent wrapper.

Verdict
BLOCK
Grade
F
Trust score
41 /100
Exposed tools
114 89r · 22w · 3d
Transport
sse · stdio
License
Apache-2.0
Stars
471
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Entroly — Select AI context with auditable recovery.

Receipt-backed selection records: what was kept, what was omitted, and the handle that recovers the exact original bytes. Compression you can undo, on your own repository, in one command — without replacing your model or agent architecture.

code --install-extension entroly.entroly-vscode · pip install -U entroly && entroly go · npx entroly

Entroly is an open-source, local-first AI token-efficiency and Context Assurance layer: budgeted evidence selection, recoverable context compression, content-addressed evidence recovery, and auditable receipts. Works through VS Code, Claude Code, Cursor, Codex, OpenClaw, GitHub Copilot, Aider, and OpenAI/Anthropic-compatible apps.

Read from source at commit 946959a19d7fOBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add entroly -- uvx entroly==1.0.85
claude-code (npm)
claude mcp add entroly-mcp -- npx -y [email protected]
03

Exposed tools (114)

89 read · 22 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
advance_proof_guided_contextreadVerify one model round and return exact evidence or a final answer.
allowedreadreturn value + 1
analyze_codebase_healthreadAnalyze codebase health (grade A-F).
blast_radiusreadAnalyze the blast radius of file changes on existing beliefs. Returns affected beliefs, risk level, and recommendations.
checkpoint_statewriteSave current state for crash recovery.
compile_beliefsreadCompile source code into belief artifacts (Truth → Belief pipeline). Scans directory for source files, extracts entities, resolves dependencies, writes beliefs.
compile_docsreadCompile markdown documentation files into belief artifacts with confidence 0.80 (human-authored > machine-inferred).
compress_imagereadCompress an image for vision model input, with optional OCR text extraction.
compress_shellreadCompress CLI output (git, npm, cargo, pytest, etc.) preserving errors and key info.
coverage_gapsreadFind source files with no corresponding belief in the vault. Identifies blind spots before running compile_beliefs.
create_context_receiptwriteCreate a Context Receipt from supplied documents.
create_context_receipt_from_pathwriteCreate a Context Receipt from a local document file or directory.
create_skillwriteCreate a new skill from a capability gap (Evolution layer). Generates SKILL.md, tool.py, metrics.json, and test cases.
deniedreadreturn
eicv_suppress_hallucinationsreadVerify an LLM response and optionally rewrite hallucinated claims.
eicv_verify_claimreadVerify a single claim against evidence using the EICV pipeline.
entroly-contextwriteShow Entroly context savings or run
entroly_dashboardreadShow live value metrics: money saved, performance, bloat prevention, quality.
entroly_retrievereadRetrieve exact source content omitted by compressed context.
epistemic_routereadRoute a query through the CogOps Epistemic Ingress Controller. Inspects 4 signals (intent, belief coverage, freshness, risk) and selects one of 5 canonical flows.
execute_flowwriteExecute a full canonical epistemic flow end-to-end. Routes query through the Ingress Controller then chains the appropriate pipeline.
explain_contextreadExplain why each fragment was included/excluded in last optimization.
explain_receipt_omissionreadExplain why a chunk was omitted from a Context Receipt.
export_training_datareadExport vault beliefs as JSONL training data for LLM finetuning. Filters out stale and low-confidence beliefs.
get_statsreadGet comprehensive session statistics.
ingest_diagramreadIngest an image/diagram into context memory (requires PIL/OCR — not available in WASM runtime, use pip install entroly).
ingest_diffwriteIngest a code diff/patch into context memory. Converts unified diff into structured change summary with intent classification.
ingest_voicereadIngest audio into context memory (requires whisper — not available in WASM runtime, use pip install entroly).
inspect_proof_guided_contextreadInspect the last durable proof-guided response without advancing it.
learn_from_failureswriteMine failure patterns from PRISM, vault, and evolution data. Optionally apply corrections.
list_compression_receiptsreadList only receipts visible to this workspace/session scope.
locate_evidencereadLocate exact source spans without generating an answer.
manage_skillsreadManage CogOps skill lifecycle (Evolution layer). Actions: list, benchmark, promote.
optimize_contextreadSelect the optimal context subset for a token budget. Uses IOS + PRISM RL + Channel Coding.
prefetch_relatedreadPredict which files the LLM will need next based on co-access patterns and dependency graph.
prepare_proof_guided_contextreadPrepare a durable proof-guided model request from local documents.
prepare_task_dreamreadPrepare an expiring, receipt-backed task skill before agent work.
process_changereadProcess a code change through the Change-Driven pipeline (Flow 4). Diff → ChangeSet → Review → Blast Radius → Vault.
recall_relevantreadSemantic recall of most relevant stored fragments.
record_command_exitreadRecord the exit code of a command that was generated and executed.
record_edit_outcomewriteRecord whether the user accepted, reverted, or retried an AI edit.
record_outcomereadRecord whether selected fragments led to success/failure (RL feedback).
record_test_resultreadRecord that tests RAN and either passed or failed for a request.
recover_receipt_omissionreadRecover the full text of context a Context Receipt omitted.
recover_shellreadRecover full CLI output from a compression handle.
refresh_beliefsreadMark beliefs as stale after file changes so the next verify pass will flag them for re-compilation.
refresh_repository_indexreadAtomically rebuild the fixed repository snapshot.
remember_fragmentreadStore a context fragment with automatic dedup and entropy scoring.
render_context_receiptreadRender a Context Receipt JSON artifact as a Markdown audit report.
repo_file_mapreadReturn the canonical Entroly file map across Python, Rust core, and WASM repos with ownership roles.
repository_architecturereadReturn verified layers, communities, cycles, routes, and hotspots.
repository_architecture_diffreadCompare two committed architecture receipts and report structural drift.
repository_change_impactreadReturn reverse file/call impact for known workspace-relative paths.
repository_code_healthreadAudit verified complexity, cycles, coupling, and navigability risk.
repository_file_move_applywriteApply a blocker-free module move after commitment and risk checks.
repository_file_move_previewwritePreview a headless Python module move with exact import rewrites.
repository_git_architecture_diffwriteCompare a local Git commit with the verified worktree without checkout.
repository_graph_queryreadQuery verified typed neighbors, paths, relatedness, or impact.
repository_graph_snapshotreadExport the complete bounded graph as a portable committed snapshot.
repository_graph_snapshot_checkreadVerify a shared snapshot and prove whether it matches current sources.
repository_http_routesreadDiscover verified HTTP routes, mounted prefixes, handlers, and collisions.
repository_interprocedural_flowreadTrace source-verified arguments, parameters, returns, and consumers.
repository_lsp_rename_previewwriteRun the operator-configured LSP and return a committed no-write plan.
repository_mapreadRank a receipt-backed structural map across the fixed repository.
repository_program_graphreadReturn verified Python control flow and reaching definitions.
repository_program_slicereadBuild a proof-carrying partial code slice from verified facts.
repository_rename_applywriteApply a previewed rename after plan-hash and risk acknowledgement.
repository_rename_previewwritePreview exact rename edits; performs no writes and reports incompleteness.
repository_runtime_overlayreadBind value-free runtime events to fresh source and symbol evidence.
repository_safe_delete_applydestructiveApply a blocker-free delete after plan-hash and risk acknowledgement.
repository_safe_delete_previewdestructivePreview a headless delete; any known or lexical reference blocks it.
repository_semantic_overlayreadVerify external LSP/compiler ranges before trusting semantic edges.
repository_summaryreadReturn bounded counts and the deterministic repository-index digest.
repository_symbol_graphreadTrace freshness-checked static calls without guessing symbol identity.
repository_tests_for_changesreadRank tests related to known changed paths without executing them.
repository_verified_contextreadReturn a partial code graph scoped to one task with a receipt.
resume_statereadResume from the latest checkpoint.
retrieve_compressed_spanreadRetrieve one in-scope span and debit returned tokens from savings.
scan_for_vulnerabilitiesreadScan code for security vulnerabilities (SAST).
search_compressed_spansreadSearch in-scope spans and return bounded exact excerpts.
security_reportreadSession-wide security audit across all ingested fragments.
security_scanreadScan content for prompt injection attacks and security threats.
shared_memory_forgetdestructiveRemove a shared memory entry by ID.
shared_memory_listreadList shared memory entries, optionally filtered by agent or tag.
shared_memory_searchreadSearch cross-agent shared memory by relevance. Returns entries from all agents.
shared_memory_statsreadGet cross-agent shared memory statistics.
shared_memory_writewriteWrite to cross-agent shared memory. Deduplicates near-identical entries via SimHash.
smart_readreadRead a file at an automatic or caller-chosen resolution.
start_workspace_listenerwriteStart a background workspace listener that continuously feeds repo changes into CogOps belief CI.
steer_outputreadClassify query effort and return output steering directives + max_tokens budget.
sync_workspace_changeswriteSynchronize workspace file changes into the belief and verification layers. Detects new/modified/deleted files, marks beliefs stale, recompiles.
vault_hygiene_scanreadScan vault beliefs against each other for knowledge decay.
vault_queryreadQuery the CogOps Knowledge Vault for existing beliefs. Supports lookup by entity name or listing all.
vault_searchreadFull-text search across all belief artifacts in the vault. Uses keyword matching with entity-name boosting.
vault_statusreadShow the current state of the CogOps Knowledge Vault: total beliefs, verification status, confidence distribution, and routing statistics.
vault_time_travelreadQuery the vault
vault_write_actionwriteWrite a task output or report to the CogOps Knowledge Vault (actions/).
vault_write_beliefwriteWrite a belief artifact to the CogOps Knowledge Vault with machine-auditable frontmatter.
verify_and_repairreadVerify LLM-generated code and suggest repairs for hallucinations.
verify_beliefswriteRun a full verification pass on all beliefs. Checks staleness, contradictions, confidence divergence, low confidence scores.
verify_provenancereadVerify that LLM-generated code is grounded in the provided context.
verify_responsereadVerify an AI-generated response for hallucination. Computes entity coverage gap, hedging curvature, and entropy consistency. Returns fused_risk [0.0=safe, 1.0=hallucinated], verdict (pass/warn/flag), and flagged claims. All local — zero LLM calls.
work_acknowledge_recoveryreadAccept responsibility for recovered work state so acting is allowed.
work_claimreadRecord explicit agent work plus a bounded advisory scope lease.
work_compile_contextreadCompile verified code context and record its Work Graph receipt.
work_context_faultreadFault exact omitted code from a context token or verified context object.
work_handoffwriteCreate a graph-bound handoff receipt and complete continuation proof.
work_modificationsreadModifications recorded between observations by the workspace watcher.
work_record_contextreadAttach a canonical ContextReceipt to its exact WorkScope.
work_record_executionreadAtomically record route, observable execution and exact-head verification.
work_record_memoryreadAttach provenance-bearing memory without trusting raw model prose.
work_resumereadRecover unfinished work and optionally seal a no-handoff proof.
work_session_statusreadReport the automatic takeover performed when this server started.
work_statereadInspect persisted shared work state without appending a polling event.
04

Trust audit

BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (8 observation(s))
Shell
declared (18 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
entroly-engine/src/guardrails.rs:244
if lower.contains("-----begin private key-----")
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
entroly-engine/src/guardrails.rs:245
|| lower.contains("-----begin rsa private key-----")
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
entroly-engine/src/guardrails.rs:575
assert!(has_safety_signal("-----BEGIN PRIVATE KEY-----\nabc"));
CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
entroly-engine/src/guardrails.rs:576
assert!(has_safety_signal("-----BEGIN RSA PRIVATE KEY-----\nabc"));
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:462
pattern: "pickle.loads(",
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:465
description: "pickle.loads() on untrusted data executes arbitrary code during deserialization.",
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:473
pattern: "pickle.load(",
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:476
description: "pickle.load() from a file or stream — RCE if file is attacker-controlled.",
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:484
pattern: "yaml.load(",
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
entroly-engine/src/query_persona.rs:122
pub fn eval(&self, x: &[f32], y: &[f32]) -> f32 {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:348
pattern: "exec(",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:351
description: "exec() with request-derived content — arbitrary code execution.",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
entroly-engine/src/sast.rs:352
fix: "Never exec() user-supplied content. If dynamic dispatch is needed, use a whitelist of safe operations.",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
entroly/work_graph_path_policy.py:69
"id_rsa*", "id_dsa*", "id_ecdsa*", "id_ed25519*",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
entroly/work_graph_path_policy.py:72
".npmrc", ".pypirc", ".netrc", "_netrc", ".htpasswd",
Why it matters. touches a credential store
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
entroly/proxy_transport_safe.py:52
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
entroly-engine/src/sast.rs:598
pattern: "verify=false",
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
entroly-engine/src/sast.rs:602
fix: "Remove verify=False. If using self-signed certs in dev, configure a custom CA bundle instead.",
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInventory / provenance · inv.binary · CWE-1104
entroly.mcpb
entroly.mcpb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
extensions/jetbrains/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
entroly/cli.py:2373
return importlib.import_module(mod_name).loads(raw)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
entroly/verifiers/symbol_resolution.py:247
mod = importlib.import_module(mod_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
external_adapter/__init__.py:25
module = importlib.import_module(module_name)
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
entroly/autotune.py:319
param = random.choice(list(TUNABLE_PARAMS.keys()))
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
entroly-wasm/js/cli.js:366
console.log(`    ${C.CYAN}demo${C.RESET}       Before/after demo showing token savings`);

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 946959a19d7ffull audit observations/trust-audit/mcp-server/juyterman1000__entroly.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01946959a19d7fBLOCKF41first audit
06

Questions

What is the Entroly MCP server?

Cut AI context cost without trusting the compressor. Every reduction is reversible, byte-exact recoverable, and carries an auditable receipt. Local-first, works through proxy, MCP, SDK, or agent wrapper.

What tools does Entroly expose?

114 in total: 89 read-only, 22 that write, and 3 that can delete or overwrite (repository_safe_delete_apply, repository_safe_delete_preview, shared_memory_forget). Every one is listed on this page with its risk.

Is Entroly safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (41/100) and found 18 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Entroly need?

It reads ANTHROPIC_API_KEY, API_KEY, ENTROLY_BYPASS, ENTROLY_CONTROL_TOKEN, ENTROLY_ELC_BUDGET_TOKENS, ENTROLY_GITHUB_TOKEN, ENTROLY_MAX_CONTEXT_TOKENS, ENTROLY_MCP_PASSIVE, ENTROLY_OPENCLAW_RECEIPT_KEY_FILE, ENTROLY_PASSIVE_FEEDBACK, ENTROLY_PROXY_ACCESS_TOKEN and ENTROLY_ROUTING_AUTHORITY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Entroly run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as entroly-openclaw at 1.0.85.

How current is this page?

The grade is for one exact copy of the source (946959a19d7f), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement