Atlas / MCP servers / kikeven / zerikai_memory

zerikai_memoryCAUTION

mcp/kikeven/zerikai-memory

A standalone local-only Python MCP server that gives any IDE persistent, workspace-isolated memory. works with any IDE supporting MCP servers

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
16 11r · 4w · 1d
Transport
stdio
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

zerikai_memory 🧠

⭐ Bookmark the project: If you use this tool, drop a star to save it to your GitHub profile and track new performance updates.

Never lose your AI context again. zerikai_memory provides persistent, workspace-isolated memory for every IDE that is local-first, cost-aware, and instant. It uses deterministic Tree-Sitter code parsing indexing to capture entities and deep code descriptions like functions, classes, and docstrings into a local ChromaDB vector store. Accessed via a local MCP interface to slash token costs while maintaining high-resolution codebase mapping, it retrieves hyper-relevant context on query through L2 and Lexical re-indexing with strict source verification (Entity, File, Line Number, and L2). Designed to pair perfectly with low-cost DeepSeek APIs, it injects structured, highly precise local context instead of dumping raw, massive files, maximizing KV cache hits to radically reduce your active token costs.

Read from source at commit 34267ca6dc04OBSERVED · 2026-10-08
02

Exposed tools (16)

11 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
debug_workspace_idreadMCP tool (FastMCP @mcp.tool()): show what workspace ID
get_briefreadMCP tool (FastMCP @mcp.tool()): retrieve the current project brief
get_cache_statsreadMCP tool (FastMCP @mcp.tool()): show DeepSeek cache hit/miss rates
get_cost_reportreadMCP tool (FastMCP @mcp.tool()): generate DeepSeek cost breakdown by
get_token_usagereadMCP tool (FastMCP @mcp.tool()): return DeepSeek API token usage and
init_workspacereadMCP tool (FastMCP @mcp.tool()): initialize a workspace via
list_memoryreadMCP tool (FastMCP @mcp.tool()): list raw ChromaDB memory entries.
list_workspacesreadMCP tool (FastMCP @mcp.tool()): list all known workspaces from
merge_workspaceswriteMCP tool (FastMCP @mcp.tool()): merge ChromaDB collections from
purge_usage_datadestructiveMCP tool (FastMCP @mcp.tool()): delete token tracking records from
query_memoryreadFastMCP @mcp.tool() tool: query ChromaDB memory with LLM synthesis.
resolve_workspacereadMCP tool (FastMCP @mcp.tool()): resolve a workspace identifier to
save_to_memorywriteMCP tool (FastMCP @mcp.tool()): save content to persistent vector
scan_statusreadMCP tool (FastMCP @mcp.tool()): return progress of a running or
scan_workspacewriteMCP tool (FastMCP @mcp.tool()): start a background workspace scan
update_briefwriteMCP tool (FastMCP @mcp.tool()): replace the project brief in
03

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (13)

MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
jev/questions.py:333
"focus": "Look for prompt injection, meta-instructions, requests to ignore prior instructions, credential exfiltration, or attempts to steer model behavior.",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
config.py:112
_host = os.getenv("OLLAMA_HOST", "http://127.0.0.1:11434")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
config.py:114
_host = "http://127.0.0.1:11434"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
purge_usage_data
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.memignore
.memignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.memignore.example
.memignore.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
main.py:1311
doc_id = hashlib.md5(
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
main.py:1482
doc_id = hashlib.md5(f"{workspace_id}:{source_id}".encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
main.py:2403
doc_id = hashlib.md5(
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
main.py:2466
doc_id = hashlib.md5(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
documentation/05-llm-backends.md:19
pulled. Verify: `http://127.0.0.1:11434` should respond in a browser.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
documentation/05-llm-backends.md:22
If issues persist, unset it or set it explicitly to `http://127.0.0.1:11434`.
INFOInventory / provenance · inv.oversize · CWE-1104
img/zerikai_memory.png
img/zerikai_memory.png
Why it matters. 1997880 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 34267ca6dc04full audit observations/trust-audit/mcp-server/kikeven__zerikai_memory.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0834267ca6dc04CAUTIONB86first audit
05

Questions

What is the zerikai_memory MCP server?

A standalone local-only Python MCP server that gives any IDE persistent, workspace-isolated memory. works with any IDE supporting MCP servers

What tools does zerikai_memory expose?

16 in total: 11 read-only, 4 that write, and 1 that can delete or overwrite (purge_usage_data). Every one is listed on this page with its risk.

Is zerikai_memory safe to connect to an agent?

With care. The audit graded it B (86/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does zerikai_memory need?

It reads DEEPSEEK_API_KEY, ENABLE_TOKEN_TRACKING, JEV_MAX_PASSAGES, JEV_REPORT_MAX_TOKENS and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does zerikai_memory run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (34267ca6dc04), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement