Atlas / MCP servers / kunwar-shah / Claudex

ClaudexCAUTION

mcp/kunwar-shah/claudex

MCP server with persistent memory + FTS5 search for Claude Code conversation history. Index your ~/.claude/projects/, expose 10 MCP tools, browse via web UI. MIT-licensed.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
10 8r · 1w · 1d
Transport
stdio
License
MIT
Stars
95
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Professional conversation viewer and analysis tool for Claude Code

Category: Development Tools · Conversation Analysis · Usage Monitoring

Claudex is a full-stack web application designed for developers, QA engineers, and researchers who need to inspect, search, and analyze Claude Code conversation histories. Built with React and Fastify, it provides enterprise-grade full-text search using SQLite FTS5, universal template support for all Claude Code versions, and comprehensive analytics dashboards.

[](https://github.com/kunwar-shah/claudex/releases) [](https://github.com/kunwar-shah/claudex/blob/main/LICENSE) [](https://kunwar-shah.github.io/claudex/) [](https://github.com/kunwar-shah/claudex/discussions) [](https://github.com/hesreallyhim/awesome-claude-code)

📚 [Documentation](https://kunwar-shah.github.io/claudex/) | 💬 [Discussions](https://github.com/kunwar-shah/claudex/discussions) | 🐛 [Issues](https://github.com/kunwar-shah/claudex/issues)

🆕 What's New

Version 1.3.0 (February 12, 2026) — MCP Server

  • 🧠 MCP Server: Model Context Protocol server gives Claude Code persistent memory across sessions
  • 🔧 10 MCP Tools: Project context, session search, conversation retrieval, structured memory CRUD
  • 💾 Structured Memory System: Store coding k
Read from source at commit c6dd077da0caOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add claudex -- npx -y @kunwarshah/[email protected]
03

Exposed tools (10)

8 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
delete_memorydestructiveDelete a specific memory by namespace, type, and key. Use when a memory is outdated or incorrect.
get_project_contextwriteGet a condensed context snapshot for the current project. Call this at the START of every session to load project memory: recent sessions, favorited sessions, and project stats. This is your primary memory tool — use it before doing any work.
get_sessionreadGet the full conversation from a session. Defaults to the current project. Use this when you need to read the actual messages from a past session — e.g., to recall implementation details, decisions made, or code that was written.
get_session_summaryreadGet a quick summary of a session — title, message count, dates, tags, favorites, and token stats. Defaults to the current project. Cheaper than get_session when you only need metadata, not full messages.
list_memoriesreadList all stored memories for the current project with stats. Shows namespace, type, key, priority. Useful for understanding what knowledge is stored.
list_projectsreadList all Claude Code projects on this machine. Shows which project is currently active.
list_sessionsreadList sessions for a project. Defaults to the current project. Pass projectId to target a different project. Use this when the user asks about previous conversations, or when you need to find a specific session.
recall_memoryreadRecall stored memories for the current project. Returns memories sorted by priority and recency. Use this to retrieve codebase knowledge, conventions, decisions, and context from previous sessions.
search_conversationsreadSearch conversations using full-text search. Defaults to the current project. Set allProjects=true to search across all projects, or pass a specific projectId. Use this when the user asks
store_memoryreadStore a structured memory for the current project. Use this when you discover important codebase patterns, conventions, decisions, or architecture details that should persist across sessions. Memories are stored in SQLite and survive restarts.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (10 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
client/src/components/SessionMetadataControls.jsx:122
<span className="text-xs text-slate-400" title="Hidden">👁️🗨️</span>
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
client/src/components/SessionMetadataControls.jsx:199
{metadata.isHidden ? '👁️🗨️ Hidden' : '👁️ Visible'}
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_memory
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clauderc
.clauderc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/mcp/index.js:27
const pkg = require(path.resolve(__dirname, '../../../package.json'))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/server.js:39
root: join(__dirname, '../../client/dist'),
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
client/package.json
@headlessui/react, @radix-ui/react-slot, @tailwindcss/forms, @tanstack/react-query, @tremor/react, axios, date-fns, lucide-react
Why it matters. 30 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
chalk, cross-spawn, concurrently, playwright
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
server/package.json
@fastify/cors, @fastify/static, @modelcontextprotocol/sdk, date-fns, dotenv, fastify, ndjson, sqlite3
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/screenshots/conversation-view.png
docs/screenshots/conversation-view.png
Why it matters. 1323500 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
screenshots/backup/conversation-view.png
screenshots/backup/conversation-view.png
Why it matters. 1323500 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
screenshots/hero.gif
screenshots/hero.gif
Why it matters. 2427291 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:528
cat server/.env | grep PROJECT_ROOT
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c6dd077da0cafull audit observations/trust-audit/mcp-server/kunwar-shah__claudex.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c6dd077da0caCAUTIONB89first audit
06

Questions

What is the Claudex MCP server?

MCP server with persistent memory + FTS5 search for Claude Code conversation history. Index your ~/.claude/projects/, expose 10 MCP tools, browse via web UI. MIT-licensed.

What tools does Claudex expose?

10 in total: 8 read-only, 1 that write, and 1 that can delete or overwrite (delete_memory). Every one is listed on this page with its risk.

Is Claudex safe to connect to an agent?

With care. The audit graded it B (89/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Claudex need?

No credential environment variables were found in its source, so it appears to need none.

How does Claudex run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-viewer-server at 1.1.0.

How current is this page?

The grade is for one exact copy of the source (c6dd077da0ca), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement