Atlas / MCP servers / patdolitse / Piia-Engram

Piia-EngramBLOCK

mcp/patdolitse/piia-engram

Local-first AI memory you can see, edit, and override — portable across Claude Code, Codex, Cursor, Windsurf, and other MCP coding tools.

Verdict
BLOCK
Grade
F
Trust score
46 /100
Exposed tools
—
Transport
stdio
License
AGPL-3.0
Stars
162
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Local-first AI work identity you can see, edit, and override — portable across your MCP coding tools.

Tell AI once who you are, how you work, and what "good" means. Claude Code, Codex, Cursor, Windsurf, and other MCP-compatible tools can start from the same AI work identity layer — local files you own, no cloud account, no hidden memory you cannot inspect.

Install · See It in Action · Supported Tools · MCP Tools · FAQ

ENGLISH | 中文

[](https://pypi.org/project/piia-engram/) [](https://pypi.org/project/piia-engram/) [](https://python.org) [](https://modelcontextprotocol.io) [](LICENSE) [](https://github.com/Patdolitse/piia-engram/actions/workflows/ci.yml) [](https://github.com/Patdolitse/piia-engram/actions/workflows/guard-strategic-files.yml)

Listed in: [](https://registry.modelcontextprotocol.io) [](https://github.com/punkpeye/awesome-mcp-servers) [](https://glama.ai

Read from source at commit 3a9f40de3e9bOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add piia-engram -- uvx piia-engram==4.21.2 stdio
03

Trust audit

BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/release_sanitize_check.py:118
"ghp_AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA1234",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/release_sanitize_check.py:119
"ghp_BBBBBBBBBBBBBBBBBBBBBBBBBBBBBB5678",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/release_sanitize_check.py:120
"ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/release_sanitize_check.py:121
"ghp_0123456789abcdefghij0123456789",
CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
scripts/release_sanitize_check.py:122
"gho_0123456789abcdefghij0123456789",
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
scripts/release_sanitize_check.py:127
"xoxb-1234567890-abcdefghijkl",
CRITICALHard-coded secrets · secret.stripe · CWE-798, CWE-321
scripts/release_sanitize_check.py:128
"sk_live_abcdefghij1234567890",
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/piia_engram/reader.py:93
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/piia_engram/setup_wizard.py:3273
print(f"usage error: {token} requires a value", file=sys.stderr)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/piia_engram/setup_wizard.py:3292
print(f"usage error: unknown capabilities option: {token}", file=sys.stderr)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/piia_engram/continuity_contract.py:242
"Project Beacon uses public API v1 via add_decision"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/piia_engram/dock_ui/app.py:107
expected_origin = f"http://127.0.0.1:{port}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/piia_engram/dock_ui/server.py:23
return f"http://127.0.0.1:{port}/auth#t={token}"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_hook_content_digest.py:115
"postgres://admin:[email protected]:5432/prod",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_hook_content_digest.py:199
_assistant_line(f"connection postgres://admin:[email protected]/prod worked"),
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_continuity_report.py:17
secret = "ZZ_CONTINUITY_SECRET_BODY"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_continuity_report.py:177
secret = "ZZ_RECALL_SIGNAL_SECRET"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_core.py:5224
secret = "ZZ_CORE_MANAGEMENT_SECRET"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_core.py:5255
secret = "ZZ_DELETE_RECEIPT_SECRET"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_dock_resume.py:1258
secret = "DOCK_STATUS_BODY_SECRET"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_export_redaction.py:29
FAKE_PEM = "-----BEGIN RSA PRIVATE KEY-----"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_hook_content_digest.py:118
"-----BEGIN RSA PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_sanitize_check.py:95
f.write_text("-----BEGIN RSA PRIVATE KEY-----\n", encoding="utf-8")
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_sensitivity.py:440
"-----BEGIN RSA PRIVATE KEY-----",         # PEM block
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_sensitivity.py:488
{"sensitivity": "public", "comment": "-----BEGIN OPENSSH PRIVATE KEY-----"},

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 3a9f40de3e9bfull audit observations/trust-audit/mcp-server/patdolitse__piia-engram.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-063a9f40de3e9bBLOCKF46first audit
05

Questions

What is the Piia-Engram MCP server?

Local-first AI memory you can see, edit, and override — portable across Claude Code, Codex, Cursor, Windsurf, and other MCP coding tools.

Is Piia-Engram safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (46/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Piia-Engram need?

It reads ENGRAM_AUTH_TOKEN and ENGRAM_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Piia-Engram run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as onboard-golden-fixture at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (3a9f40de3e9b), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement