Atlas / MCP servers / l33tdawg / Sage

SageBLOCK

mcp/l33tdawg/sage-3

(S)AGE - (Sovereign) Agent Governed Experience

Verdict
BLOCK
Grade
F
Trust score
43 /100
Exposed tools
11 11r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
254
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Stop re-explaining your project.

SAGE gives AI agents a persistent memory of project decisions, failed approaches and useful lessons. Connect your tools to the same local node so authorized agents can record experience and recall relevant context in later sessions. Inspect what they keep in CEREBRUM, SAGE's local dashboard.

Works with Claude Code, Codex, Cursor and other MCP-capable clients. Developers can integrate through the Python SDK or signed REST API. Recall depends on what is recorded, your configuration and the agent's use of its tools.

Download SAGE · Get started · Connect your AI · Developer quickstart

Why SAGE · Quick Start · For Developers · Architecture · Capabilities · Dashboard · Release history · Documentation

Why SAGE

Use SAGE when your agents return to ongoing work: a design decision worth keeping, an approach that failed, or a lesson the next session should use. RAG retrieves source material; SAGE uses retrieval too, with a governed record of agent experience around it.

  • Trace the origin. Agent-signed writes attribute memories to their recorded author.
  • Review admission. Memories pass through a validation lifecycle before they enter normal recall.
  • Control access. Enrollment, domain permissions and classification determine which agents can use a mem
Read from source at commit 439b312a5259OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add sage:11.23.15 -- docker run -i --rm ghcr.io/l33tdawg/sage:11.23.15:None
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
sage_domainsreadPage this signed caller
sage_forgetreadDeprecate a memory by ID.
sage_inceptionreadInitialize your persistent memory session. Call on first interaction with SAGE.
sage_listreadBrowse memories with filters.
sage_recallreadSearch memories by semantic similarity.
sage_reflectreadEnd-of-task reflection. Store dos and don
sage_reinstatereadWithdraw or resolve an open two-phase challenge and return the memory to committed.
sage_rememberreadStore a memory in SAGE.
sage_statusreadGet this signed caller
sage_timelinereadGet memories in a time range.
sage_turnreadPer-turn memory cycle. Recalls relevant memories AND stores an observation atomically.
04

Trust audit

BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (3 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/sage-launcher/exec_unix.go:14
func (defaultExecer) Exec(argv0 string, argv []string, envv []string) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/sage-launcher/exec_windows.go:18
func (defaultExecer) Exec(argv0 string, argv []string, envv []string) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/sage-launcher/rollback.go:58
Exec(argv0 string, argv []string, envv []string) error
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
deploy/Dockerfile.node
Dockerfile.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
deploy/federation-acceptance/Dockerfile.node
Dockerfile.node
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
installer/macos/AppIcon.icns
AppIcon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
papers/Paper3 - Institutional Memory as Organizational Knowledge - AI Agents That Learn Their Jobs from Experience Not Instructions.pdf:273
<FEFF00540068006500200043006C006F0073006500640020004C006F006F0070003A002000410049002000440065007300690067006E0073002C002000410049002000480061007200640065006E0073002C00200041004900200053006F006C0076006
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
papers/Paper3 - Institutional Memory as Organizational Knowledge - AI Agents That Learn Their Jobs from Experience Not Instructions.pdf:561
<FEFF004500780070006500720069006D0065006E007400200043003A0020004D006F00640065006C002000530077006100700070006100620069006C0069007400790020007700690074006800200045006E0072006900630068006500640020004B006
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
papers/Paper3 - Institutional Memory as Organizational Knowledge - AI Agents That Learn Their Jobs from Experience Not Instructions.pdf:2521
<</Type/FontDescriptor/FontName/NMKOEA+LMRoman10-Bold/Flags 4/FontBBox[-486 -295 1607 1133]/Ascent 699/CapHeight 699/Descent -194/ItalicAngle 0/StemV 114/XHeight 444/CharSet(/A/B/C/D/E/F/G/H/I/J/K/L/M
MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
papers/Paper3 - Institutional Memory as Organizational Knowledge - AI Agents That Learn Their Jobs from Experience Not Instructions.pdf:2799
<</Type/FontDescriptor/FontName/KEYQJQ+LMRoman10-Regular/Flags 4/FontBBox[-430 -290 1417 1127]/Ascent 0/CapHeight 0/Descent 0/ItalicAngle 0/StemV 69/XHeight 431/CharSet(/A/B/C/D/E/F/G/H/I/J/K/L/M/N/O/
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/ARCHITECTURE.md:228
| `POSTGRES_URL` | `postgres://sage:sage_dev_password@postgres:5432/sage?sslmode=disable` | PostgreSQL connection string |
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
internal/store/postgres_agents_test.go:33
return "postgres://sage:sage_dev_password@localhost:5432/sage?sslmode=disable"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/store/agent_claim_test.go:34
const token = "sqlite-concurrent-claim-token"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/store/agent_claim_test.go:71
const token = "sqlite-expired-claim-token"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/store/agent_claim_test.go:88
const token = "sqlite-malformed-expiry-token"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
internal/store/mcp_tokens_test.go:484
token   = "pre-v23-root-fallback-bearer"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
web/appv23_route_security_test.go:563
const token = "protected-route-session"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
cmd/sage-gui/quorum_test.go:18
"ca_key": "-----BEGIN EC PRIVATE KEY-----\nplaintext\n-----END EC PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
cmd/sage-gui/quorum_test.go:40
"-----BEGIN EC PRIVATE KEY-----\nfake\n-----END EC PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
web/wizard_chatgpt_test.go:179
require.NoError(t, os.WriteFile(certPath, []byte("-----BEGIN PRIVATE KEY-----\nFAKE\n-----END PRIVATE KEY-----\n"), 0o600))
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/sage-launcher/launcher_test.go:79
func (s *stubExecer) Exec(argv0 string, argv []string, envv []string) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cmd/sage-launcher/rollback_e2e_test.go:218
func (r *recordingExecer) Exec(argv0 string, argv []string, _ []string) error {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
bench/judge-qualify/qualify.py:419
bucket = hashlib.md5(row.item.id.encode()).digest()[0] & 1

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 439b312a5259full audit observations/trust-audit/mcp-server/l33tdawg__sage-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06439b312a5259BLOCKF43first audit
06

Questions

What is the Sage MCP server?

(S)AGE - (Sovereign) Agent Governed Experience

What tools does Sage expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Sage safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (43/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Sage need?

It reads GH_TOKEN, GITHUB_TOKEN, MACMINI_KEY_PATH, OPENAI_API_KEY and SAGE_AGENT_KEY_FILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Sage run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as sage at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (439b312a5259), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement