MexBLOCK
Team memory for engineers and their AI agents. Lives in your repo. Shared through Git.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Shared project memory for engineers and their coding agents.
MEX keeps your team's architecture, decisions, requirements, and handoffs alongside the code. Engineers and their agents can build on shared context, review proposed changes, and carry work between sessions and teammates—with Git as the sharing layer.
English | 简体中文 | Español | Português (Brasil)
[](https://www.npmjs.com/package/mex-agent) [](https://www.npmjs.com/package/mex-agent) [](https://github.com/mex-memory/mex/stargazers) [](https://mexmemory.com) [](https://discord.gg/FEdNsQ4Qt4) [](https://github.com/mex-memory/mex/blob/v0.8.2/LICENSE) [](https://github.com/mex-memory/mex/actions/workflows/ci.yml) [](https://github.com/mex-memory/mex/blob/v0.8.2/package.json) [](https://github.com/mex-memory/mex/blob/v0.8.2/package.json) [](#agent-memory-mode) [](#mcp-server)
Team memory · A teammate-handoff example · Project Hub · Quick start ·
b0134ebdafffOBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mex-mcp -- npx -y [email protected]
{
"mcpServers": {
"mex-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (21)
19 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
architecture | read | How Harbour |
auth | read | Auth pattern |
conventions | read | How code is written in Harbour: naming, structure, errors and tests. |
data-model | read | The tables Harbour stores and how they relate to one another. |
decisions | read | The choices Harbour has made and the reasoning behind each one. |
glossary | read | Terms used throughout Harbour, defined once so they are not redefined. |
integrations | read | The third parties Harbour talks to and what each one is trusted for. |
mex_check | write | Run a drift check on the mex scaffold. Returns a DriftReport with a numeric score, issues list, and file count. |
mex_heartbeat | read | Check the mex scaffold heartbeat. Returns ok status, stale files with age in days, and memory cleanup status. |
mex_log | read | Append an agent event to the mex log, or read recent events. Valid kinds: ${EVENT_KINDS.join( |
mex_read_file | read | Read a file from the mex scaffold directory (.mex/). Path is relative to .mex/ (e.g. |
mex_timeline | read | Read historical project notes, optionally filtered by kind or time. Scans at most the latest 8 MiB / 10,000 non-empty log lines; older history may be absent. Recorded notes are historical context, not verified current knowledge. |
operations | read | Running Harbour: deploys, alerts, and what to do when something stops. |
pattern-index | read | Lookup table for Harbour |
performance | read | Where Harbour spends its time and which numbers are worth watching. |
risks | read | Known risks in Harbour, what triggers each one, and what would reduce it. |
router | read | Session bootstrap and navigation hub for the Harbour ticketing service. |
security | read | How Harbour handles credentials, access and customer data. |
setup | write | Preparing a machine to run and test Harbour locally. |
stack | read | The technologies Harbour runs on and the constraints on changing them. |
testing | read | How Harbour is tested and what each layer of the suite is for. |
Trust audit
BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(sql: string): void;
exec(sql: string): void {exec(sql: string): void;
<!-- mex:entity
tree-sitter-javascript.wasm
tree-sitter-python.wasm
tree-sitter-rust.wasm
import { AI_TOOLS, type AiTool } from "./types.js";const BOM = "";
member: () => ({ ...teamMember(), secret: "/Users/alice/private" }) as never,const secret = "PRIVATE_TOKEN_PATH_AND_PROMPT";
const secret = "PROPRIETARY-PROSE-THAT-MUST-NOT-BE-LOGGED";
.mex-managed.json
.mex-managed.json
.windsurfrules
.windsurfrules
import { parseStructuredAnswer } from "../../compare/lib/answer.mjs";import { BASH_GUARD_DENIAL } from "../../compare/lib/bash-guard.mjs";import { parseStructuredAnswer } from "../../compare/lib/answer.mjs";import { parseJsonLines } from "../../core/jsonl.mjs";import { round } from "../../core/stats.mjs";/.env" ... curl
expect(new URL(rawUrl, "http://127.0.0.1").pathname).toBe("/api/v1/overview");const url = new URL(rawUrl, "http://127.0.0.1");
const url = new URL(rawUrl, "http://127.0.0.1");
Gates applied: no_behavioural_pass.
b0134ebdaffffull audit observations/trust-audit/mcp-server/mex-memory__mex.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | b0134ebdafff | BLOCK | F | 41 | first audit |
Questions
What is the Mex MCP server?
Team memory for engineers and their AI agents. Lives in your repo. Shared through Git.
What tools does Mex expose?
21 in total: 19 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mex safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (41/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Mex need?
No credential environment variables were found in its source, so it appears to need none.
How does Mex run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mex-mcp at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (b0134ebdafff), read on 2026-09-24. The repository is watched and re-audited when it changes.