Atlas / MCP servers / kage-core / Kage

KageBLOCK

mcp/kage-core/kage

Persistent, verified memory for coding agents — so they stop re-explaining your codebase and never act on stale knowledge. Every memory is checked against your actual code; lives in your repo as plain files, shared via git. No account, no DB. Install: npx -y @kage-core/kage-graph-mcp install

Verdict
BLOCK
Grade
F
Trust score
58 /100
Exposed tools
77 56r · 20w · 1d
Transport
stdio
License
GPL-3.0
Stars
40
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Kage manages your memory and agents

State an intent. Kage's orchestrator briefs a coding agent from your repo's own memory, runs it in an isolated git worktree — a single run or a multi-wave goal — and re-runs the checks itself rather than trusting the agent's report:

┌ VERIFIED 3/3 — checks run by Kage, not the agent · build-a-stale-memory-triage-surface-do-n-260818-ec2c
│ "the stale-memory triage surface is built and wired into the review flow"
│ ✓ tests       ran       npm test --prefix mcp → exit 0   evidence/tests.log
│ ✓ diff-size   inspected at most 800 changed lines   evidence/diff-size.log
│ ✓ citations   inspected every formally cited path exists (directly, or as a unique suffix) in the worktree   evidence/citations.log
│ · touched     4 file(s), 212 line(s)
└────────────────────────────────────────────────────────────────

A real receipt from this repo's own run history. Every row is a command Kage ran or a fact it inspected — never a claim the agent made about itself. kage merge only lands the code once the claim holds, and ratifies what the agent learned, so the next brief, yours or a teammate's, starts smarter.

That memory is the decisions behind your codebase, the runbook for a tricky deploy, the root cause of a gnarly bug — captured as your agents work and checked against the actual code, so what gets reused stays true. It's kept as plain Markdown files in your repo, conformant to the Google Open Knowledge Format (OKF) so there's no lock-in, and shared with your whole team through git. No account, no database, no API key.

npx -y @kage-core/kage-graph-mcp install

<

Read from source at commit 38b666fcde97OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add kage-graph-mcp -- npx -y @kage-core/[email protected]
03

Exposed tools (77)

56 read · 20 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
kage_auditreadAudit whether repo memory and code intelligence are trustworthy: validation, memory inbox, structured context coverage, code graph precision, graph links, and concrete recommendations.
kage_benchmarkwriteReturn Kage proof metrics, or set mode=memory_quality / memory_scale for synthetic memory retrieval benchmarks.
kage_benchmark_comparereadCompare the same task on the same repo with and without Kage. Reports estimated baseline discovery tokens/steps versus Kage recall/code-graph context, with evidence and caveats.
kage_branch_overlaywriteBuild and return branch overlay metadata: branch, head, merge-base, changed files, and pending packet IDs.
kage_capabilitiesreadReturn an evidence-backed Kage memory-system capability audit across repo memory, collaboration/session proof, benchmarks, and dashboard/viewer readiness.
kage_capturewriteCreate a repo-local Kage memory packet immediately. Org/global promotion still requires explicit human review. Capture is rejected if every referenced path is missing from the repo; set allow_missing_paths to record anyway.
kage_cleanup_candidatesreadFind conservative cleanup candidates from Kage
kage_code_indexwriteWrite external code index artifacts consumed by the code graph. Prefers SCIP when scip-typescript and scip are installed, then falls back to the built-in LSP-compatible symbol index.
kage_compactreadConsolidate repo memory: prune dead citations, deprecate hard-stale packets, and surface near-duplicate clusters to merge (via kage_supersede). Defaults to a dry run; pass dry_run=false to apply pruning/deprecation. Duplicate merging stays an agent decision — no hosted LLM is used.
kage_compile_briefreadCompile a brief for an intent from repo memory and the code graph, without dispatching. Returns memories (with author and date), predicted touch set, derived checks, and a confidence band with its basis.
kage_conflictsreadList repo-local memory packet pairs that contradict each other (same cited path, same subject, opposing claim). Resolve each with kage_supersede, or keep both intentionally. On a repo with many contradictions,
kage_contextreadPrimary kage entry point. Validates memory health, recalls relevant packets, and queries both the code graph and knowledge graph — all in one call. Call this at the start of every task; it answers caller/usage questions from the code graph too, so you rarely need a separate graph tool.
kage_context_slot_deletedestructiveDelete a repo-local context slot by label.
kage_context_slot_setwriteCreate or update a repo-local pinned context slot. Use for durable, high-signal repo guidance that should always be included without loading all memory.
kage_context_slotsreadList repo-local pinned context slots. Pinned slots are small, reviewable facts that Kage includes in recall/context before task-specific memory.
kage_contributorsreadBuild local contributor profiles from git history: commits, recent activity, touched files, modules, ownership silos, hotspot ownership, and commit category mix.
kage_decisionsreadSummarize the repo
kage_dependency_pathreadFind how two files are connected in Kage
kage_dispatchreadHire a coding agent to deliver an intent in an isolated worktree, then verify its claim by executing the checks. Pass your judgment (drop_memories, confidence, clarification) so it is recorded with the run — the kernel validates it: drops need a reason and confidence may only be lowered.
kage_distillreadDistill stored observations for one session into repo-local memory candidates. Org/global promotion still requires explicit human review.
kage_docs_searchreadSearch this repo
kage_events_sincewriteRun events since a cursor. Call at the start of each turn to catch up on work that finished while you were talking. Pass back next_cursor from the previous reply; it reports how many events it could not fit rather than truncating silently.
kage_feedbackreadRecord how useful a recalled repo-local memory packet was, which tunes Kage
kage_fetchreadFetch the full content of a specific node from the kage knowledge graph. Use after kage_search to get the complete fix, pattern, or decision.
kage_goal_createwriteOpen a goal: the room
kage_goal_finishreadAbandon a goal before its runs finish, with a reason that is kept as part of its history. There is no tool to force a goal to
kage_goal_statusreadWhere a goal stands: its state, each wave
kage_graphreadQuery the repo-local Kage knowledge graph. Returns typed, evidence-backed graph facts from entities, edges, and episodes.
kage_graph_insightsreadReturn deterministic code graph intelligence: central files, dependency cycles, import communities, and short entry flows. Use to orient agents before broad architectural edits.
kage_graph_registryreadBuild a signed graph-registry manifest for generated memory graph, code graph, indexes, metrics, audit, inbox, source packet IDs, packet hashes, and repo git state.
kage_graph_visualreadExport the repo-local Kage knowledge graph as Mermaid flowchart text for visual inspection.
kage_inboxreadReturn an actionable memory review inbox: pending packets, stale packets, duplicates, missing structured context, validation issues, and recommended actions. On a repo with many packets,
kage_install_policywriteInstall or update the repo AGENTS.md policy that tells coding agents to use Kage automatically.
kage_judgmentwriteThe recorded judgment for a run: which memories you kept or dropped and why, the confidence you set, the question you asked, and any moves the kernel refused.
kage_learnreadCapture a durable, reusable learning from the current session as a verified repo-local memory packet (committed under .agent_memory/, shared with the team via git). Use it the moment you discover something a future session should know: a decision and its rationale, a bug
kage_learning_ledgerwriteReturn an agent-facing ledger that classifies observed session events into save, ignore, needs-evidence, or already-distilled memory decisions.
kage_list_domainsreadList all domains in the kage knowledge graph with their node counts and top tags. Use to orient before searching.
kage_memory_accessreadReport which repo-local memory packets have actually been recalled recently. This uses local ignored access telemetry and does not mutate shareable packet files. On a repo with many packets,
kage_memory_auditreadReturn the repo-local audit trail for explicit memory mutations: capture, feedback, review, supersede, deprecate, and delete.
kage_memory_handoffreadReturn a teammate/agent handoff queue by combining memory inbox, lifecycle, audit, timeline, and lineage into concrete next actions.
kage_memory_lifecyclereadReturn a repo-local memory lifecycle report: healthy, hot, cold, stale, disputed, ungrounded, pending, generated, and concrete review actions.
kage_memory_lineagereadReturn memory supersession chains so agents can use current replacement packets and keep retired memory as audit history.
kage_memory_reconcilereadReturn agent-owned memory reconciliation work when source files linked to existing memory changed. Agents must update, supersede, or mark stale memory before final handoff.
kage_memory_timelinereadReturn recent repo-memory activity for teammate handoff: added, updated, pending, and deprecated packets with review actions. On a repo with heavy recent memory churn,
kage_merge_runwriteAccept a verified claim: merge its branch and ratify the learnings that rode with it into team memory. Only a run in state
kage_metricsreadReturn concise Kage adoption and quality metrics: code graph counts, language/parser coverage, memory graph evidence coverage, pending/approved packets, validation state, and readiness score.
kage_module_healthreadReturn local module health scorecards from Kage
kage_observereadStore an automatic local observation event from an agent session. Observations are privacy-scanned, deduplicated, and never published automatically.
kage_pr_summarizewriteCreate a PR/branch memory summary from local git diff metadata and write repo-local change memory. Use when a branch is ready to hand off.
kage_profilereadReturn a compact project profile for agent orientation: repo totals, languages, top code+memory concepts, key files, memory focus, run commands, and next actions.
kage_propose_from_diffwriteCreate or update a branch review summary and repo-local change-memory packet from local git status and diff metadata. Org/global promotion still requires explicit human review.
kage_qualityreadReturn memory quality metrics: useful memory ratio, duplicate burden, stale/wrong feedback, evidence coverage, path grounding, and review queue size. On a repo with many packets,
kage_recallreadRecall repo-local Kage memory from .agent_memory packets. Returns an agent-ready context block plus ranked packet summaries.
kage_registry_recommendreadRecommend documentation packs, skills, and optional MCPs for this repo based on its package metadata. Recommendations never install anything automatically.
kage_reject_runwriteRefuse a claim with a reason. The reason is captured as a negative_result memory so future briefs carry it.
kage_reportreadThe while-you-were-away digest: ready, blocked, halted, and the trust line. Observed numbers only.
kage_review_artifactwriteCreate a Markdown review artifact summarizing pending memory packets for PR or human review.
kage_review_runwriteRecord your review verdict on a run
kage_reviewersreadSuggest reviewers for target or changed files from local git authorship, recent edits, and code-graph co-change ownership. Does not contact GitHub or external services.
kage_riskreadAssess modification risk for files using Kage
kage_room_statewriteClock in: the compact state of every run, what needs the user, and the trust line. Call this FIRST in any session — the manager holds no memory of its own.
kage_searchreadSearch the kage community knowledge graph for gotchas, patterns, configs, and architectural decisions across auth, database, payments, deployment, frontend, testing, and more. Returns node summaries ranked by relevance.
kage_session_replayreadReturn a privacy-preserving replay digest for observed agent sessions: timeline, touched paths, commands, durable candidates, and distill actions without raw transcript text.
kage_sessionsreadSummarize local agent observation sessions, durable capture candidates, and next distillation actions without exposing raw transcript replay.
kage_setup_agentreadGenerate MCP/setup instructions for Codex, Claude Code, Cursor, Windsurf, Gemini CLI, OpenCode, Cline, Goose, Roo Code, Kilo Code, Claude Desktop, Aider, or generic MCP.
kage_setup_doctorreadAudit Kage setup across supported agents, including Claude Code ambient hook readiness when applicable.
kage_skillsreadCodify durable, verified repo memory (runbooks, workflows, actionable decisions) into git-native SKILL.md files under .claude/skills/ that every teammate
kage_stopwriteHalt a run now. State is preserved and the run is resumable.
kage_structural_indexreadBuild the complete cache-backed structural index for large repos. This covers all supported source/config/doc files and writes .agent_memory/structural artifacts separate from learned memory.
kage_taskwriteThe full card for one run: state, claim, checks with verdicts, unsure notes, learnings.
kage_tellwriteAnswer or steer a run. A blocked or dropped agent is RESUMED in place with its context intact; a live one gets the message queued for its next boundary. The reply states which happened — never assume delivery.
kage_validatereadValidate repo-local Kage memory packets, pending packets, generated indexes, and sensitive-content checks.
kage_verify_agentreadVerify that Kage is truly active for the current agent: config, repo policy, indexes, recall, code graph, and this live MCP tool reachability.
kage_verify_citationsreadVerify that a memory packet
kage_workspacereadSummarize a local multi-repo workspace: discovered git repos, Kage memory coverage, code graph counts, package dependencies, route contracts, topic/event contracts, and cross-repo co-change links between repos. Use when a task spans multiple sibling repos.
kage_workspace_recallreadRecall Kage memory across every indexed repo in a local workspace and rank the combined hits. Use for cross-repo teammate knowledge and shared context.
kage_xrayreadReturn a first-use Repo X-Ray: code structure layers for entry points, core files, risk, tests, memory overlay, and knowledge gaps.
04

Trust audit

BLOCKgrade F · trust 58/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (2 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
mcp/cli.ts:3092
if (args.includes("--no-strict")) patch.strict_verify = false;
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInventory / provenance · inv.binary · CWE-1104
shell/build/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
mcp/dead-ends.test.ts:161
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
mcp/delegation-api.test.ts:59
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
mcp/goal-continuity.test.ts:96
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
mcp/render-calm.test.ts:423
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
mcp/sessions-api-gaps.test.ts:30
const TOKEN = "test-token-0123456789abcdef0123456789abcdef";
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
kage_context_slot_delete
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.kageignore
.kageignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp/add-project.test.ts:151
assert.doesNotThrow(() => new Function(script), "the emitted client script must still parse");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp/dead-ends.test.ts:537
assert.doesNotThrow(() => new Function(script));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp/delegation-api.test.ts:520
assert.doesNotThrow(() => new Function(script));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp/delegation-api.test.ts:1599
assert.doesNotThrow(() => new Function(script), "the emitted script must still parse");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp/sessions-api-gaps.test.ts:182
assert.doesNotThrow(() => new Function(script));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
evals/agent-trajectory/scenarios.mjs:5
import { initProject, capture } from "../../mcp/dist/kernel.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/delegation/tui/app.ts:6
import { loadApprovedPackets } from "../../kernel.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/memory-view.test.ts:122
for (const id of ["nope", "../../../etc/passwd", "repo:x:decision:missing"]) {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/room-sessions.test.ts:59
assert.equal(normalizeSessionKey("../../etc/passwd"), "etc-passwd");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.agent_memory/packets/bug_fix-expensive-synchronous-work-must-leave-the-process-not-just-move-after-listen-0f2c0341.md:30
Verified by: Timed polling of http://127.0.0.1:3113/viewer/index.html after `touch .agent_memory/packets/*.md`; npm test 537 pass 0 fail exit 0
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.agent_memory/packets/bug_fix-local-viewer-responses-include-browser-security-headers-4aac607c.md:24
Verified by: npm test --prefix mcp; curl -I http://127.0.0.1:8767/viewer/index.html
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.agent_memory/packets/bug_fix-local-viewer-responses-include-browser-security-headers-4aac607c.md:39
{"schema_version":2,"id":"repo:https-github-com-kage-core-kage:bug_fix:local-viewer-responses-include-browser-security-headers-1779050518395","title":"Local viewer responses include browser security h
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.agent_memory/packets/bug_fix-local-viewer-viewer-route-must-redirect-to-index-with-params-626de899.md:23
Evidence: Fixed in mcp/daemon.ts. Headless Playwright click-through from http://127.0.0.1:8766/ across Overview, Graph, Memory, Risks, Review, Owners, and Artifacts preserved graph params, loaded the
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.agent_memory/packets/bug_fix-local-viewer-viewer-route-must-redirect-to-index-with-params-626de899.md:28
Fixed in mcp/daemon.ts. Headless Playwright click-through from http://127.0.0.1:8766/ across Overview, Graph, Memory, Risks, Review, Owners, and Artifacts preserved graph params, loaded the real repo
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
alias/kage-graph-mcp/package.json
@kage-core/kage-graph-mcp
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp/package.json
@modelcontextprotocol/sdk, @xterm/addon-fit, @xterm/xterm, tree-sitter-wasms, typescript, web-tree-sitter, @types/node, node-pty
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 38b666fcde97full audit observations/trust-audit/mcp-server/kage-core__kage.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0838b666fcde97BLOCKF58first audit
06

Questions

What is the Kage MCP server?

Persistent, verified memory for coding agents — so they stop re-explaining your codebase and never act on stale knowledge. Every memory is checked against your actual code; lives in your repo as plain files, shared via git. No account, no DB. Install: npx -y @kage-core/kage-graph-mcp install

What tools does Kage expose?

77 in total: 56 read-only, 20 that write, and 1 that can delete or overwrite (kage_context_slot_delete). Every one is listed on this page with its risk.

Is Kage safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (58/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Kage need?

It reads APPLE_APP_SPECIFIC_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kage run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as kage-shell at 5.0.0.

How current is this page?

The grade is for one exact copy of the source (38b666fcde97), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement