SageBLOCK
(S)AGE - (Sovereign) Agent Governed Experience
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Stop re-explaining your project.
SAGE gives AI agents a persistent memory of project decisions, failed approaches and useful lessons. Connect your tools to the same local node so authorized agents can record experience and recall relevant context in later sessions. Inspect what they keep in CEREBRUM, SAGE's local dashboard.
Works with Claude Code, Codex, Cursor and other MCP-capable clients. Developers can integrate through the Python SDK or signed REST API. Recall depends on what is recorded, your configuration and the agent's use of its tools.
Download SAGE · Get started · Connect your AI · Developer quickstart
Why SAGE · Quick Start · For Developers · Architecture · Capabilities · Dashboard · Release history · Documentation
Why SAGE
Use SAGE when your agents return to ongoing work: a design decision worth keeping, an approach that failed, or a lesson the next session should use. RAG retrieves source material; SAGE uses retrieval too, with a governed record of agent experience around it.
- Trace the origin. Agent-signed writes attribute memories to their recorded author.
- Review admission. Memories pass through a validation lifecycle before they enter normal recall.
- Control access. Enrollment, domain permissions and classification determine which agents can use a mem
439b312a5259OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sage:11.23.15 -- docker run -i --rm ghcr.io/l33tdawg/sage:11.23.15:None
Exposed tools (11)
11 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
sage_domains | read | Page this signed caller |
sage_forget | read | Deprecate a memory by ID. |
sage_inception | read | Initialize your persistent memory session. Call on first interaction with SAGE. |
sage_list | read | Browse memories with filters. |
sage_recall | read | Search memories by semantic similarity. |
sage_reflect | read | End-of-task reflection. Store dos and don |
sage_reinstate | read | Withdraw or resolve an open two-phase challenge and return the memory to committed. |
sage_remember | read | Store a memory in SAGE. |
sage_status | read | Get this signed caller |
sage_timeline | read | Get memories in a time range. |
sage_turn | read | Per-turn memory cycle. Recalls relevant memories AND stores an observation atomically. |
Trust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
func (defaultExecer) Exec(argv0 string, argv []string, envv []string) error {func (defaultExecer) Exec(argv0 string, argv []string, envv []string) error {Exec(argv0 string, argv []string, envv []string) error
Dockerfile.node
Dockerfile.node
AppIcon.icns
<FEFF00540068006500200043006C006F0073006500640020004C006F006F0070003A002000410049002000440065007300690067006E0073002C002000410049002000480061007200640065006E0073002C00200041004900200053006F006C0076006
<FEFF004500780070006500720069006D0065006E007400200043003A0020004D006F00640065006C002000530077006100700070006100620069006C0069007400790020007700690074006800200045006E0072006900630068006500640020004B006
<</Type/FontDescriptor/FontName/NMKOEA+LMRoman10-Bold/Flags 4/FontBBox[-486 -295 1607 1133]/Ascent 699/CapHeight 699/Descent -194/ItalicAngle 0/StemV 114/XHeight 444/CharSet(/A/B/C/D/E/F/G/H/I/J/K/L/M
<</Type/FontDescriptor/FontName/KEYQJQ+LMRoman10-Regular/Flags 4/FontBBox[-430 -290 1417 1127]/Ascent 0/CapHeight 0/Descent 0/ItalicAngle 0/StemV 69/XHeight 431/CharSet(/A/B/C/D/E/F/G/H/I/J/K/L/M/N/O/
| `POSTGRES_URL` | `postgres://sage:sage_dev_password@postgres:5432/sage?sslmode=disable` | PostgreSQL connection string |
return "postgres://sage:sage_dev_password@localhost:5432/sage?sslmode=disable"
const token = "sqlite-concurrent-claim-token"
const token = "sqlite-expired-claim-token"
const token = "sqlite-malformed-expiry-token"
token = "pre-v23-root-fallback-bearer"
const token = "protected-route-session"
"ca_key": "-----BEGIN EC PRIVATE KEY-----\nplaintext\n-----END EC PRIVATE KEY-----",
"-----BEGIN EC PRIVATE KEY-----\nfake\n-----END EC PRIVATE KEY-----",
require.NoError(t, os.WriteFile(certPath, []byte("-----BEGIN PRIVATE KEY-----\nFAKE\n-----END PRIVATE KEY-----\n"), 0o600)).golangci.yml
.goreleaser.yaml
func (s *stubExecer) Exec(argv0 string, argv []string, envv []string) error {func (r *recordingExecer) Exec(argv0 string, argv []string, _ []string) error {bucket = hashlib.md5(row.item.id.encode()).digest()[0] & 1
Gates applied: no_behavioural_pass.
439b312a5259full audit observations/trust-audit/mcp-server/l33tdawg__sage-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 439b312a5259 | BLOCK | F | 43 | first audit |
Questions
What is the Sage MCP server?
(S)AGE - (Sovereign) Agent Governed Experience
What tools does Sage expose?
11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Sage safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Sage need?
It reads GH_TOKEN, GITHUB_TOKEN, MACMINI_KEY_PATH, OPENAI_API_KEY and SAGE_AGENT_KEY_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Sage run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as sage at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (439b312a5259), read on 2026-10-06. The repository is watched and re-audited when it changes.