Piia-EngramBLOCK
Local-first AI memory you can see, edit, and override — portable across Claude Code, Codex, Cursor, Windsurf, and other MCP coding tools.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Local-first AI work identity you can see, edit, and override — portable across your MCP coding tools.
Tell AI once who you are, how you work, and what "good" means. Claude Code, Codex, Cursor, Windsurf, and other MCP-compatible tools can start from the same AI work identity layer — local files you own, no cloud account, no hidden memory you cannot inspect.
Install · See It in Action · Supported Tools · MCP Tools · FAQ
ENGLISH | 中文
[](https://pypi.org/project/piia-engram/) [](https://pypi.org/project/piia-engram/) [](https://python.org) [](https://modelcontextprotocol.io) [](LICENSE) [](https://github.com/Patdolitse/piia-engram/actions/workflows/ci.yml) [](https://github.com/Patdolitse/piia-engram/actions/workflows/guard-strategic-files.yml)
Listed in: [](https://registry.modelcontextprotocol.io) [](https://github.com/punkpeye/awesome-mcp-servers) [](https://glama.ai
3a9f40de3e9bOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add piia-engram -- uvx piia-engram==4.21.2 stdio
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (10 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"ghp_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA1234",
"ghp_BBBBBBBBBBBBBBBBBBBBBBBBBBBBBB5678",
"ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789",
"ghp_0123456789abcdefghij0123456789",
"gho_0123456789abcdefghij0123456789",
"xoxb-1234567890-abcdefghijkl",
"sk_live_abcdefghij1234567890",
"metadata.google.internal",
print(f"usage error: {token} requires a value", file=sys.stderr)print(f"usage error: unknown capabilities option: {token}", file=sys.stderr)"Project Beacon uses public API v1 via add_decision"
expected_origin = f"http://127.0.0.1:{port}"return f"http://127.0.0.1:{port}/auth#t={token}""postgres://admin:[email protected]:5432/prod",
_assistant_line(f"connection postgres://admin:[email protected]/prod worked"),
secret = "ZZ_CONTINUITY_SECRET_BODY"
secret = "ZZ_RECALL_SIGNAL_SECRET"
secret = "ZZ_CORE_MANAGEMENT_SECRET"
secret = "ZZ_DELETE_RECEIPT_SECRET"
secret = "DOCK_STATUS_BODY_SECRET"
FAKE_PEM = "-----BEGIN RSA PRIVATE KEY-----"
"-----BEGIN RSA PRIVATE KEY-----",
f.write_text("-----BEGIN RSA PRIVATE KEY-----\n", encoding="utf-8")"-----BEGIN RSA PRIVATE KEY-----", # PEM block
{"sensitivity": "public", "comment": "-----BEGIN OPENSSH PRIVATE KEY-----"},Gates applied: critical_finding, no_behavioural_pass.
3a9f40de3e9bfull audit observations/trust-audit/mcp-server/patdolitse__piia-engram.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 3a9f40de3e9b | BLOCK | F | 46 | first audit |
Questions
What is the Piia-Engram MCP server?
Local-first AI memory you can see, edit, and override — portable across Claude Code, Codex, Cursor, Windsurf, and other MCP coding tools.
Is Piia-Engram safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Piia-Engram need?
It reads ENGRAM_AUTH_TOKEN and ENGRAM_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Piia-Engram run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as onboard-golden-fixture at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (3a9f40de3e9b), read on 2026-10-06. The repository is watched and re-audited when it changes.