Atlas / MCP servers / mex-memory / Mex

MexBLOCK

mcp/mex-memory/mex

Team memory for engineers and their AI agents. Lives in your repo. Shared through Git.

Verdict
BLOCK
Grade
F
Trust score
41 /100
Exposed tools
21 19r · 2w · 0d
Transport
stdio
License
MIT
Stars
1,703
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Shared project memory for engineers and their coding agents.

MEX keeps your team's architecture, decisions, requirements, and handoffs alongside the code. Engineers and their agents can build on shared context, review proposed changes, and carry work between sessions and teammates—with Git as the sharing layer.

English | 简体中文 | Español | Português (Brasil)

[](https://www.npmjs.com/package/mex-agent) [](https://www.npmjs.com/package/mex-agent) [](https://github.com/mex-memory/mex/stargazers) [](https://mexmemory.com) [](https://discord.gg/FEdNsQ4Qt4) [](https://github.com/mex-memory/mex/blob/v0.8.2/LICENSE) [](https://github.com/mex-memory/mex/actions/workflows/ci.yml) [](https://github.com/mex-memory/mex/blob/v0.8.2/package.json) [](https://github.com/mex-memory/mex/blob/v0.8.2/package.json) [](#agent-memory-mode) [](#mcp-server)

Team memory · A teammate-handoff example · Project Hub · Quick start ·

Read from source at commit b0134ebdafffOBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mex-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mex-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (21)

19 read · 2 write · 0 destructive.

ToolRiskDescription
architecturereadHow Harbour
authreadAuth pattern
conventionsreadHow code is written in Harbour: naming, structure, errors and tests.
data-modelreadThe tables Harbour stores and how they relate to one another.
decisionsreadThe choices Harbour has made and the reasoning behind each one.
glossaryreadTerms used throughout Harbour, defined once so they are not redefined.
integrationsreadThe third parties Harbour talks to and what each one is trusted for.
mex_checkwriteRun a drift check on the mex scaffold. Returns a DriftReport with a numeric score, issues list, and file count.
mex_heartbeatreadCheck the mex scaffold heartbeat. Returns ok status, stale files with age in days, and memory cleanup status.
mex_logreadAppend an agent event to the mex log, or read recent events. Valid kinds: ${EVENT_KINDS.join(
mex_read_filereadRead a file from the mex scaffold directory (.mex/). Path is relative to .mex/ (e.g.
mex_timelinereadRead historical project notes, optionally filtered by kind or time. Scans at most the latest 8 MiB / 10,000 non-empty log lines; older history may be absent. Recorded notes are historical context, not verified current knowledge.
operationsreadRunning Harbour: deploys, alerts, and what to do when something stops.
pattern-indexreadLookup table for Harbour
performancereadWhere Harbour spends its time and which numbers are worth watching.
risksreadKnown risks in Harbour, what triggers each one, and what would reduce it.
routerreadSession bootstrap and navigation hub for the Harbour ticketing service.
securityreadHow Harbour handles credentials, access and customer data.
setupwritePreparing a machine to run and test Harbour locally.
stackreadThe technologies Harbour runs on and the constraints on changing them.
testingreadHow Harbour is tested and what each layer of the suite is for.
04

Trust audit

BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (6 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/graph/db/sqlite.ts:48
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/graph/db/sqlite.ts:84
exec(sql: string): void {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/graph/fingerprint-store.ts:12
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
test/fixtures/wiki/adversarial/bom.md:1
<!-- mex:entity
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/graph/wasm/tree-sitter-javascript.wasm
tree-sitter-javascript.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/graph/wasm/tree-sitter-python.wasm
tree-sitter-python.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/graph/wasm/tree-sitter-rust.wasm
tree-sitter-rust.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/agent-command.ts:1
import { AI_TOOLS, type AiTool } from "./types.js";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/wiki/markdown/positions.ts:18
const BOM = "";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/hub/http/__tests__/app.test.ts:1417
member: () => ({ ...teamMember(), secret: "/Users/alice/private" }) as never,
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/setup/__tests__/headless-population.test.ts:304
const secret = "PRIVATE_TOKEN_PATH_AND_PROMPT";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/wiki/operations/__tests__/integrity.test.ts:389
const secret = "PROPRIETARY-PROSE-THAT-MUST-NOT-BE-LOGGED";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agents/skills/mex-inbox/.mex-managed.json
.mex-managed.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agents/skills/mex-relay/.mex-managed.json
.mex-managed.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mex/.tool-configs/.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
templates/.tool-configs/.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
evaluate/adapters/agents/claude.mjs:1
import { parseStructuredAnswer } from "../../compare/lib/answer.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
evaluate/adapters/agents/claude.mjs:2
import { BASH_GUARD_DENIAL } from "../../compare/lib/bash-guard.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
evaluate/adapters/agents/codex.mjs:1
import { parseStructuredAnswer } from "../../compare/lib/answer.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
evaluate/adapters/agents/shared.mjs:1
import { parseJsonLines } from "../../core/jsonl.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
evaluate/adapters/agents/shared.mjs:2
import { round } from "../../core/stats.mjs";
LOWNetwork egress · net.env_exfil · CWE-200, CWE-319
packages/hub-web/src/pages/SetupTranscript.test.tsx:92
/.env" ... curl
Why it matters. reads secrets in the same file that sends data out
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/hub-web/src/api/client.test.ts:219
expect(new URL(rawUrl, "http://127.0.0.1").pathname).toBe("/api/v1/overview");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/hub-web/src/api/client.test.ts:231
const url = new URL(rawUrl, "http://127.0.0.1");
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/hub-web/src/api/client.test.ts:244
const url = new URL(rawUrl, "http://127.0.0.1");

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha b0134ebdaffffull audit observations/trust-audit/mcp-server/mex-memory__mex.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-24b0134ebdafffBLOCKF41first audit
06

Questions

What is the Mex MCP server?

Team memory for engineers and their AI agents. Lives in your repo. Shared through Git.

What tools does Mex expose?

21 in total: 19 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mex safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (41/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Mex need?

No credential environment variables were found in its source, so it appears to need none.

How does Mex run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mex-mcp at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (b0134ebdafff), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement