KageBLOCK
Persistent, verified memory for coding agents — so they stop re-explaining your codebase and never act on stale knowledge. Every memory is checked against your actual code; lives in your repo as plain files, shared via git. No account, no DB. Install: npx -y @kage-core/kage-graph-mcp install
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Kage manages your memory and agents
State an intent. Kage's orchestrator briefs a coding agent from your repo's own memory, runs it in an isolated git worktree — a single run or a multi-wave goal — and re-runs the checks itself rather than trusting the agent's report:
┌ VERIFIED 3/3 — checks run by Kage, not the agent · build-a-stale-memory-triage-surface-do-n-260818-ec2c │ "the stale-memory triage surface is built and wired into the review flow" │ ✓ tests ran npm test --prefix mcp → exit 0 evidence/tests.log │ ✓ diff-size inspected at most 800 changed lines evidence/diff-size.log │ ✓ citations inspected every formally cited path exists (directly, or as a unique suffix) in the worktree evidence/citations.log │ · touched 4 file(s), 212 line(s) └────────────────────────────────────────────────────────────────
A real receipt from this repo's own run history. Every row is a command Kage ran or a fact it inspected — never a claim the agent made about itself. kage merge only lands the code once the claim holds, and ratifies what the agent learned, so the next brief, yours or a teammate's, starts smarter.
That memory is the decisions behind your codebase, the runbook for a tricky deploy, the root cause of a gnarly bug — captured as your agents work and checked against the actual code, so what gets reused stays true. It's kept as plain Markdown files in your repo, conformant to the Google Open Knowledge Format (OKF) so there's no lock-in, and shared with your whole team through git. No account, no database, no API key.
npx -y @kage-core/kage-graph-mcp install
<
38b666fcde97OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add kage-graph-mcp -- npx -y @kage-core/[email protected]
Exposed tools (77)
56 read · 20 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
kage_audit | read | Audit whether repo memory and code intelligence are trustworthy: validation, memory inbox, structured context coverage, code graph precision, graph links, and concrete recommendations. |
kage_benchmark | write | Return Kage proof metrics, or set mode=memory_quality / memory_scale for synthetic memory retrieval benchmarks. |
kage_benchmark_compare | read | Compare the same task on the same repo with and without Kage. Reports estimated baseline discovery tokens/steps versus Kage recall/code-graph context, with evidence and caveats. |
kage_branch_overlay | write | Build and return branch overlay metadata: branch, head, merge-base, changed files, and pending packet IDs. |
kage_capabilities | read | Return an evidence-backed Kage memory-system capability audit across repo memory, collaboration/session proof, benchmarks, and dashboard/viewer readiness. |
kage_capture | write | Create a repo-local Kage memory packet immediately. Org/global promotion still requires explicit human review. Capture is rejected if every referenced path is missing from the repo; set allow_missing_paths to record anyway. |
kage_cleanup_candidates | read | Find conservative cleanup candidates from Kage |
kage_code_index | write | Write external code index artifacts consumed by the code graph. Prefers SCIP when scip-typescript and scip are installed, then falls back to the built-in LSP-compatible symbol index. |
kage_compact | read | Consolidate repo memory: prune dead citations, deprecate hard-stale packets, and surface near-duplicate clusters to merge (via kage_supersede). Defaults to a dry run; pass dry_run=false to apply pruning/deprecation. Duplicate merging stays an agent decision — no hosted LLM is used. |
kage_compile_brief | read | Compile a brief for an intent from repo memory and the code graph, without dispatching. Returns memories (with author and date), predicted touch set, derived checks, and a confidence band with its basis. |
kage_conflicts | read | List repo-local memory packet pairs that contradict each other (same cited path, same subject, opposing claim). Resolve each with kage_supersede, or keep both intentionally. On a repo with many contradictions, |
kage_context | read | Primary kage entry point. Validates memory health, recalls relevant packets, and queries both the code graph and knowledge graph — all in one call. Call this at the start of every task; it answers caller/usage questions from the code graph too, so you rarely need a separate graph tool. |
kage_context_slot_delete | destructive | Delete a repo-local context slot by label. |
kage_context_slot_set | write | Create or update a repo-local pinned context slot. Use for durable, high-signal repo guidance that should always be included without loading all memory. |
kage_context_slots | read | List repo-local pinned context slots. Pinned slots are small, reviewable facts that Kage includes in recall/context before task-specific memory. |
kage_contributors | read | Build local contributor profiles from git history: commits, recent activity, touched files, modules, ownership silos, hotspot ownership, and commit category mix. |
kage_decisions | read | Summarize the repo |
kage_dependency_path | read | Find how two files are connected in Kage |
kage_dispatch | read | Hire a coding agent to deliver an intent in an isolated worktree, then verify its claim by executing the checks. Pass your judgment (drop_memories, confidence, clarification) so it is recorded with the run — the kernel validates it: drops need a reason and confidence may only be lowered. |
kage_distill | read | Distill stored observations for one session into repo-local memory candidates. Org/global promotion still requires explicit human review. |
kage_docs_search | read | Search this repo |
kage_events_since | write | Run events since a cursor. Call at the start of each turn to catch up on work that finished while you were talking. Pass back next_cursor from the previous reply; it reports how many events it could not fit rather than truncating silently. |
kage_feedback | read | Record how useful a recalled repo-local memory packet was, which tunes Kage |
kage_fetch | read | Fetch the full content of a specific node from the kage knowledge graph. Use after kage_search to get the complete fix, pattern, or decision. |
kage_goal_create | write | Open a goal: the room |
kage_goal_finish | read | Abandon a goal before its runs finish, with a reason that is kept as part of its history. There is no tool to force a goal to |
kage_goal_status | read | Where a goal stands: its state, each wave |
kage_graph | read | Query the repo-local Kage knowledge graph. Returns typed, evidence-backed graph facts from entities, edges, and episodes. |
kage_graph_insights | read | Return deterministic code graph intelligence: central files, dependency cycles, import communities, and short entry flows. Use to orient agents before broad architectural edits. |
kage_graph_registry | read | Build a signed graph-registry manifest for generated memory graph, code graph, indexes, metrics, audit, inbox, source packet IDs, packet hashes, and repo git state. |
kage_graph_visual | read | Export the repo-local Kage knowledge graph as Mermaid flowchart text for visual inspection. |
kage_inbox | read | Return an actionable memory review inbox: pending packets, stale packets, duplicates, missing structured context, validation issues, and recommended actions. On a repo with many packets, |
kage_install_policy | write | Install or update the repo AGENTS.md policy that tells coding agents to use Kage automatically. |
kage_judgment | write | The recorded judgment for a run: which memories you kept or dropped and why, the confidence you set, the question you asked, and any moves the kernel refused. |
kage_learn | read | Capture a durable, reusable learning from the current session as a verified repo-local memory packet (committed under .agent_memory/, shared with the team via git). Use it the moment you discover something a future session should know: a decision and its rationale, a bug |
kage_learning_ledger | write | Return an agent-facing ledger that classifies observed session events into save, ignore, needs-evidence, or already-distilled memory decisions. |
kage_list_domains | read | List all domains in the kage knowledge graph with their node counts and top tags. Use to orient before searching. |
kage_memory_access | read | Report which repo-local memory packets have actually been recalled recently. This uses local ignored access telemetry and does not mutate shareable packet files. On a repo with many packets, |
kage_memory_audit | read | Return the repo-local audit trail for explicit memory mutations: capture, feedback, review, supersede, deprecate, and delete. |
kage_memory_handoff | read | Return a teammate/agent handoff queue by combining memory inbox, lifecycle, audit, timeline, and lineage into concrete next actions. |
kage_memory_lifecycle | read | Return a repo-local memory lifecycle report: healthy, hot, cold, stale, disputed, ungrounded, pending, generated, and concrete review actions. |
kage_memory_lineage | read | Return memory supersession chains so agents can use current replacement packets and keep retired memory as audit history. |
kage_memory_reconcile | read | Return agent-owned memory reconciliation work when source files linked to existing memory changed. Agents must update, supersede, or mark stale memory before final handoff. |
kage_memory_timeline | read | Return recent repo-memory activity for teammate handoff: added, updated, pending, and deprecated packets with review actions. On a repo with heavy recent memory churn, |
kage_merge_run | write | Accept a verified claim: merge its branch and ratify the learnings that rode with it into team memory. Only a run in state |
kage_metrics | read | Return concise Kage adoption and quality metrics: code graph counts, language/parser coverage, memory graph evidence coverage, pending/approved packets, validation state, and readiness score. |
kage_module_health | read | Return local module health scorecards from Kage |
kage_observe | read | Store an automatic local observation event from an agent session. Observations are privacy-scanned, deduplicated, and never published automatically. |
kage_pr_summarize | write | Create a PR/branch memory summary from local git diff metadata and write repo-local change memory. Use when a branch is ready to hand off. |
kage_profile | read | Return a compact project profile for agent orientation: repo totals, languages, top code+memory concepts, key files, memory focus, run commands, and next actions. |
kage_propose_from_diff | write | Create or update a branch review summary and repo-local change-memory packet from local git status and diff metadata. Org/global promotion still requires explicit human review. |
kage_quality | read | Return memory quality metrics: useful memory ratio, duplicate burden, stale/wrong feedback, evidence coverage, path grounding, and review queue size. On a repo with many packets, |
kage_recall | read | Recall repo-local Kage memory from .agent_memory packets. Returns an agent-ready context block plus ranked packet summaries. |
kage_registry_recommend | read | Recommend documentation packs, skills, and optional MCPs for this repo based on its package metadata. Recommendations never install anything automatically. |
kage_reject_run | write | Refuse a claim with a reason. The reason is captured as a negative_result memory so future briefs carry it. |
kage_report | read | The while-you-were-away digest: ready, blocked, halted, and the trust line. Observed numbers only. |
kage_review_artifact | write | Create a Markdown review artifact summarizing pending memory packets for PR or human review. |
kage_review_run | write | Record your review verdict on a run |
kage_reviewers | read | Suggest reviewers for target or changed files from local git authorship, recent edits, and code-graph co-change ownership. Does not contact GitHub or external services. |
kage_risk | read | Assess modification risk for files using Kage |
kage_room_state | write | Clock in: the compact state of every run, what needs the user, and the trust line. Call this FIRST in any session — the manager holds no memory of its own. |
kage_search | read | Search the kage community knowledge graph for gotchas, patterns, configs, and architectural decisions across auth, database, payments, deployment, frontend, testing, and more. Returns node summaries ranked by relevance. |
kage_session_replay | read | Return a privacy-preserving replay digest for observed agent sessions: timeline, touched paths, commands, durable candidates, and distill actions without raw transcript text. |
kage_sessions | read | Summarize local agent observation sessions, durable capture candidates, and next distillation actions without exposing raw transcript replay. |
kage_setup_agent | read | Generate MCP/setup instructions for Codex, Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Cline, Goose, Roo Code, Kilo Code, Claude Desktop, Aider, or generic MCP. |
kage_setup_doctor | read | Audit Kage setup across supported agents, including Claude Code ambient hook readiness when applicable. |
kage_skills | read | Codify durable, verified repo memory (runbooks, workflows, actionable decisions) into git-native SKILL.md files under .claude/skills/ that every teammate |
kage_stop | write | Halt a run now. State is preserved and the run is resumable. |
kage_structural_index | read | Build the complete cache-backed structural index for large repos. This covers all supported source/config/doc files and writes .agent_memory/structural artifacts separate from learned memory. |
kage_task | write | The full card for one run: state, claim, checks with verdicts, unsure notes, learnings. |
kage_tell | write | Answer or steer a run. A blocked or dropped agent is RESUMED in place with its context intact; a live one gets the message queued for its next boundary. The reply states which happened — never assume delivery. |
kage_validate | read | Validate repo-local Kage memory packets, pending packets, generated indexes, and sensitive-content checks. |
kage_verify_agent | read | Verify that Kage is truly active for the current agent: config, repo policy, indexes, recall, code graph, and this live MCP tool reachability. |
kage_verify_citations | read | Verify that a memory packet |
kage_workspace | read | Summarize a local multi-repo workspace: discovered git repos, Kage memory coverage, code graph counts, package dependencies, route contracts, topic/event contracts, and cross-repo co-change links between repos. Use when a task spans multiple sibling repos. |
kage_workspace_recall | read | Recall Kage memory across every indexed repo in a local workspace and rank the combined hits. Use for cross-repo teammate knowledge and shared context. |
kage_xray | read | Return a first-use Repo X-Ray: code structure layers for entry points, core files, risk, tests, memory overlay, and knowledge gaps. |
Trust audit
BLOCKgrade F · trust 58/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
if (args.includes("--no-strict")) patch.strict_verify = false;icon.icns
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
kage_context_slot_delete
.kageignore
assert.doesNotThrow(() => new Function(script), "the emitted client script must still parse");
assert.doesNotThrow(() => new Function(script));
assert.doesNotThrow(() => new Function(script));
assert.doesNotThrow(() => new Function(script), "the emitted script must still parse");
assert.doesNotThrow(() => new Function(script));
import { initProject, capture } from "../../mcp/dist/kernel.js";import { loadApprovedPackets } from "../../kernel.js";for (const id of ["nope", "../../../etc/passwd", "repo:x:decision:missing"]) {assert.equal(normalizeSessionKey("../../etc/passwd"), "etc-passwd");Verified by: Timed polling of http://127.0.0.1:3113/viewer/index.html after `touch .agent_memory/packets/*.md`; npm test 537 pass 0 fail exit 0
Verified by: npm test --prefix mcp; curl -I http://127.0.0.1:8767/viewer/index.html
{"schema_version":2,"id":"repo:https-github-com-kage-core-kage:bug_fix:local-viewer-responses-include-browser-security-headers-1779050518395","title":"Local viewer responses include browser security hEvidence: Fixed in mcp/daemon.ts. Headless Playwright click-through from http://127.0.0.1:8766/ across Overview, Graph, Memory, Risks, Review, Owners, and Artifacts preserved graph params, loaded the
Fixed in mcp/daemon.ts. Headless Playwright click-through from http://127.0.0.1:8766/ across Overview, Graph, Memory, Risks, Review, Owners, and Artifacts preserved graph params, loaded the real repo
@kage-core/kage-graph-mcp
@modelcontextprotocol/sdk, @xterm/addon-fit, @xterm/xterm, tree-sitter-wasms, typescript, web-tree-sitter, @types/node, node-pty
Gates applied: no_behavioural_pass.
38b666fcde97full audit observations/trust-audit/mcp-server/kage-core__kage.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 38b666fcde97 | BLOCK | F | 58 | first audit |
Questions
What is the Kage MCP server?
Persistent, verified memory for coding agents — so they stop re-explaining your codebase and never act on stale knowledge. Every memory is checked against your actual code; lives in your repo as plain files, shared via git. No account, no DB. Install: npx -y @kage-core/kage-graph-mcp install
What tools does Kage expose?
77 in total: 56 read-only, 20 that write, and 1 that can delete or overwrite (kage_context_slot_delete). Every one is listed on this page with its risk.
Is Kage safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (58/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Kage need?
It reads APPLE_APP_SPECIFIC_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Kage run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as kage-shell at 5.0.0.
How current is this page?
The grade is for one exact copy of the source (38b666fcde97), read on 2026-10-08. The repository is watched and re-audited when it changes.