MemiBLOCK
The design layer for agentic AI — design context, interface checks, and verification for coding agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The design layer for agentic AI.
Give your coding agent an interface brief before it edits. Memi maps the UI already in your repository, surfaces file-anchored accessibility and design-system risks, and gives you a deterministic check to rerun before merge. Start with the CLI, then add the same gate to every pull request.
Memi Studio is available today; Memi Canvas is currently in development. No account, API key, Figma file, global install, or daemon is required for the first audit.
Start with your next interface · Get Memi Studio · Read the research
Quickstart: find your first interface issue
Run one non-destructive audit in any frontend repository. It needs no account, API key, Figma file, global install, or daemon.
npx -y @memi-design/cli@latest diagn
8d605e42202fOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cli -- npx -y @memi-design/[email protected] mcp start --no-figma
Exposed tools (73)
62 read · 10 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Accessibility | read | The interface works across keyboard, screen reader, contrast, motion, and touch needs. |
Clarity | read | Users can tell what matters, what each control does, and what to do next. |
Consistency | read | The product repeats tokens, components, copy patterns, and interaction rules. |
Control | read | Users can review, undo, cancel, and steer consequential actions. |
Evidence | read | Visible proof |
Feedback | read | The system acknowledges user actions, progress, loading, success, and failure. |
Navigation | read | Navigation evidence |
Secondary | read | Another |
Top_Name | read | Explicit |
Trust | read | Risk clarity |
analyze_design | read | |
audit-frontend-design | read | Evidence-backed frontend design review for accessibility, hierarchy, tokens, states, and responsive behavior. |
audit_interface_craft | read | |
audit_ux_tenets_traps | read | |
better-ui | read | Build and polish a general interface screen. |
cancel_probe | read | Cancellation probe |
capture_screenshot | read | Capture a screenshot of a Figma node (or the current page) as image data. Prereq: bridge + plugin connected (check_bridge_health); node IDs from get_selection or get_page_tree. Returns: { type: |
check_bridge_health | read | Check health of the Figma WebSocket bridge. Works with no plugin connected; never throws. Returns: { status: |
check_skill_compliance | read | |
compose | read | |
create_spec | destructive | Create or overwrite a spec in the registry (Zod-validated). Same-name specs are silently overwritten — check get_specs first. Returns: \ |
design_doc | read | |
design_systems_context | read | |
diagnose_app_quality | read | Diagnose local project source without network access, command execution, or report persistence. |
enforce-design-ci | read | Deterministic pull-request checks for accessibility, design tokens, component structure, responsive behavior, and UI states. |
generate_code | read | |
generate_health_report | read | |
get_ai_usage | read | |
get_page_tree | read | Get the hierarchical node tree of the current Figma file. Prereq: bridge + plugin connected. Returns: array of pages { id, name, type: |
get_registry_item | read | Return one shadcn registry-item.json-compatible item from the workspace. Returns: files, targets, dependencies, cssVars, and Atomic Design metadata. Errors: isError if the item is unknown (discover names via get_shadcn_registry). |
get_research | read | Load and return the project |
get_selection | read | |
get_shadcn_registry | read | Build a shadcn registry.json-compatible index from the workspace (component specs; tokens map to a registry:theme item when present). Returns: { $schema, name, homepage, items[] } with file targets, registryDependencies, cssVars. For a single item use get_registry_item. |
get_spec | read | Fetch the full body of one spec by name. Returns: full spec JSON — ComponentSpec: atomicLevel, props, variants, composesSpecs, codeConnect, WCAG fields; PageSpec: sections, meta; DataVizSpec: chartType, dataShape. Errors: isError if the name is not found (list names via get_specs). |
get_specs | read | List all saved specs (cheap summary operation). Returns: [{ name, type: |
get_tokens | read | Get design tokens from the local registry, optionally filtered. Prereq: none — local read; run pull_design_system if empty. Returns: [{ name, type: |
legacy-skill | read | Plain description |
local_extension | read | Audited local extension |
measure_text | read | |
mermaid_jam_export | write | Write Mermaid Jam-ready FigJam source artifacts from research or a simulation run. This is source + open friendly: it writes .mmd/.md files under .memoire/mermaid-jam and returns next steps. It does not attempt clipboard or direct paste automation. |
named | read | Named |
nested-skill | read | Heading |
network_extension | read | Test |
plan_ui_fixes | read | |
prepare_apple_design_brief | read | Prepare a local Apple design brief without running Xcode or writing files. |
prepare_design_agent_brief | read | Prepare a bounded local design brief without executing commands, integrations, or models. |
prepare_frontend_brief | read | Inspect existing components, props, tokens and stories before editing frontend code. Optionally resolve supplied Figma/Paper evidence; no network, model, config execution or writes. Unknown behavior remains unassessed. |
pull_design_system | read | Pull the full design system from Figma (tokens, components, styles) into the local registry. Prereq: Figma bridge running + plugin connected — verify with check_bridge_health; start via \ |
pull_design_system_rest | read | Pull the design system from Figma via REST API — no plugin or bridge required. Prereq: FIGMA_TOKEN and FIGMA_FILE_KEY env vars. Returns: { tokens, components, styles, lastSync }. Errors: missing env vars, or Figma API errors (403 = bad token, 404 = bad file key). Use in CI/headless; equivalent to \ |
remember-design-system | read | A repository-specific preflight brief for tokens, components, routes, conventions, and verification commands before interface work. |
research_design_package | read | |
research_generate_specs | read | |
run_audit | write | Run a deterministic design-system audit (WCAG contrast, token completeness, spec accessibility) and return structured findings. Prereq: none — token/spec level, no Figma, no AI. Returns: { success, results: issues[], score, level, summary }. focus= |
scaffold_agent_design_files | read | |
scaffold_swiftui_files | read | |
simulation_compare | read | Compare completed simulation runs by adoption, confidence, evidence coverage, risk, and cost. |
simulation_costs | write | Summarize token and cost usage for a simulation run. |
simulation_export_spec | read | Convert a simulation report into a product-spec impact artifact that agents can paste into specs or handoff docs. |
simulation_generate_agents | read | Generate a 20-60 agent model-swarm cohort from Memoire research evidence without starting a run. |
simulation_interview | read | Interview a simulated product stakeholder from a completed local or model-swarm run. |
simulation_list_runs | read | List persisted simulation runs with lightweight summaries. Use this to discover runIds for simulation_status, simulation_stream, simulation_transcript, simulation_costs, simulation_report, and simulation_compare. |
simulation_models | read | List Codex-first model profiles available to Memoire model-swarm simulations. Live model execution is opt-in; unavailable providers automatically fall back to deterministic clean-room simulation. |
simulation_plan | read | |
simulation_report | read | Export a simulation report with recommendations, risks, assumptions, events, interviews, and evidenceFindingIds. |
simulation_run | write | Run a prepared local or model-swarm product simulation scenario. Prerequisites: Call simulation_plan first and pass the returned scenario.id. Returns on success: SimulationRun with status, events, eventCount, and persisted run id. |
simulation_run_matrix | write | Plan and run multiple model-swarm hypotheses, then compare outcomes for product-spec decision work. |
simulation_status | write | Read a local simulation run status from .memoire/simulations/runs. |
simulation_stream | write | Read persisted simulation events in stream order. Paginated — use offset/limit to page through long runs instead of materializing the full event log. |
simulation_transcript | write | Read model-swarm transcript memory for a run. |
swiftui-design-engineering | read | Build and verify accessible SwiftUI screens and navigation. |
sync_design_tokens | write | |
top-name | read | Explicit |
update_token | write |
Trust audit
BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
/^(?:id_dsa|id_ecdsa|id_ed25519|id_rsa)$/i,
console.log(ui.dots("AI", payload.ai.apiKey ? ui.green("enabled") : ui.dim("heuristic")));console.log(ui.ok(`Token valid — connected as @${user.handle} (${user.email})`));console.log(ui.ok("Figma token found " + ui.dim(token.value.startsWith("figd_") ? "(figd_...)" : "(configured)")));console.log(ui.ok(`${diff.tokens.added.length} new token${diff.tokens.added.length > 1 ? "s" : ""}`));console.log(ui.warn(`${diff.tokens.removed.length} removed token${diff.tokens.removed.length > 1 ? "s" : ""}`));const token = "figd_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6";
const secret = "dualentry-trust-core-secret-canary";
const token = "preview-session-token";
create_spec
performance-trace.zip
accessibility-audit-2.0.0.tgz
agent-memory-profiles-0.1.0.tgz
agent-messaging-gateway-0.1.0.tgz
agent-session-checkpoints-0.1.0.tgz
exec(compile(code, f"{path}::cell-{cell_index}", "exec"), namespace)await exec(maestro, ["--udid", udid, "test", flow, "--format", "junit", "--output", trace], {const hierarchy = await exec(maestro, ["--udid", udid, "hierarchy"], {expect(pluginMain).not.toContain("eval(");{ name: "new Function()", code: "new Function('return 1');" },const actualSha1 = createHash("sha1").update(buffer).digest("hex");const actual = createHash("sha1").update(bytes).digest("hex");function args(bytes: Buffer) { return {bytes, integrity: `sha512-${createHash("sha512").update(bytes).digest("base64")}`, shasum: createHash("sha1").update(bytes).digest("hex"), expectedPhrase: phraseconst sha1 = createHash("sha1").update(bytes).digest("hex");return createHash("sha1").update(values.join("\n")).digest("hex").slice(0, 10);Gates applied: no_behavioural_pass.
8d605e42202ffull audit observations/trust-audit/mcp-server/memi-design__memi-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 8d605e42202f | BLOCK | F | 45 | first audit |
Questions
What is the Memi MCP server?
The design layer for agentic AI — design context, interface checks, and verification for coding agents.
What tools does Memi expose?
73 in total: 62 read-only, 10 that write, and 1 that can delete or overwrite (create_spec). Every one is listed on this page with its risk.
Is Memi safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (45/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Memi need?
It reads ANTHROPIC_API_KEY, CLAUDE_CODE_OAUTH_TOKEN, FIGMA_FILE_KEY, FIGMA_TOKEN, GEMINI_API_KEY, GITHUB_TOKEN, GOOGLE_API_KEY, MEMOIRE_PUBLISH_READY_SKIP_AUTH, OPENAI_API_KEY and PENPOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Memi run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @sarveshsea/memi-studio-types at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (8d605e42202f), read on 2026-10-08. The repository is watched and re-audited when it changes.