Atlas / MCP servers / qualixar / SuperLocalMemory

SuperLocalMemoryBLOCK

mcp/qualixar/superlocalmemory-1

Open-source governed, local-first memory control plane for AI agents and teams. arXiv:2608.08253

Verdict
BLOCK
Grade
F
Trust score
47 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio · streamable-http
License
AGPL-3.0
Stars
227
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Claude Code, Codex, Cursor and other MCP clients forget what they learned when a session ends. SuperLocalMemory (SLM) gives them one long-term memory that lives on your machine: it learns from use, enforces who may read and erase what, coordinates many agents, and says "I don't have that" instead of guessing.

Every recall is checked before your agent uses it. A judge decides whether the memories found actually answer the question: Laya runs fully on your Mac, and Jev runs online on Windows, Linux and macOS. When they don't answer it, SLM says so instead of handing over a confident wrong answer: a hallucination guard for retrieval (answer check).

In Mode A, core remember and recall make no model-provider call. Anything that sends data out is a choice you make, and the docs say exactly what goes.

[](https://pypi.org/project/superlocalmemory/) [](https://www.npmjs.com/package/superlocalmemory) [](https://pepy.tech/project/superlocalmemory) [](https://www.npmjs.com/package/superlocalmemory) [](https://github.com/qualixar/superlocalmemory/stargazers) [](pyproject.toml) [](LICENSE) [![An

Read from source at commit 350455328ddaOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add superlocalmemory --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "superlocalmemory": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "API_KEY": "${API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
      }
    }
  }
}
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
echoreadEcho a string — used by the e2e client call.
pingreadHealth ping.
recallreadReturn a deliberately non-trivial response without a live database.
04

Trust audit

BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (11 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/superlocalmemory/evolution/mutation_generator.py:102
"exec(", "eval(", "compile(", "os.system", "os.popen", "os.spawn",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/superlocalmemory/evolution/mutation_generator.py:117
"/.ssh/", ".install_token", ".aws/credentials", ".netrc",
Why it matters. touches a credential store
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/superlocalmemory/server/egress_policy.py:42
"169.254.169.254",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/superlocalmemory/server/egress_policy.py:43
"metadata.google.internal",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/superlocalmemory/cli/commands.py:3212
m = __import__(mod)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/superlocalmemory/cli/commands.py:3254
__import__(mod)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/superlocalmemory/cli/commands.py:3283
__import__(mod)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/superlocalmemory/core/scale_autopromote.py:81
importlib.import_module(name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/superlocalmemory/server/api.py:222
_mod_v341 = __import__(f"superlocalmemory.server.routes.{_module_name_v341}", fromlist=["router"])
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/superlocalmemory/cli/provider_custom_endpoint.py:99
print(f"  Key: {'configured' if api_key else 'none (keyless)'}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/superlocalmemory/cli/remote_commands.py:374
print(f"  {secret}\n")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/superlocalmemory/evolution/mutation_generator.py:120
"without consent", "exfiltrat",
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
tests/test_api/test_brain_endpoint.py:359
"topics":   [{"name": "secret=AKIAABCDEFGHIJKLMNOP", "strength": 0.9}],
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
tests/test_api/test_brain_endpoint.py:371
assert "AKIAABCDEFGHIJKLMNOP" not in dumped
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
tests/test_security/test_injection_uses_hosted_redaction.py:35
("AWS AKIAABCDEFGHIJKLMNOP", "AKIAABCDEFGH"),
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
tests/test_security/test_preference_redaction.py:72
"entities": ["AKIAABCDEFGHIJKLMNOP", "Qualixar"],
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
tests/test_security/test_preference_redaction.py:79
assert "AKIAABCDEFGHIJKLMNOP" not in dumped
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_retrieval/test_hosted_redaction_shapes.py:51
"DATABASE_URL=postgres://admin:[email protected]:5432/app",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_retrieval/test_hosted_redaction_shapes.py:53
("URL password containing @", "mysql://root:p@ssw0rdFAKE@localhost/db", "p@ssw0rdFAKE"),
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_retrieval/test_hosted_redaction_shapes.py:176
assert out == f"postgres://admin:{REDACTED_MARKER}@db1.corp.internal:5432/app"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_acceptance_core.py:146
api_key="sk-test-EXISTING-do-not-wipe",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_learning/test_signals_pipeline.py:93
secret = "AKIAsecretthatmustnotleak12345"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_server/test_answer_check_auth.py:30
TOKEN = "install-token-for-this-test-0123456789abcdef"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_server/test_profile_runtime_switch.py:532
token = "global-scope-opt-in-token-991"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/test_infra/test_backup_crypto_format.py:78
secret = b"ghp_PLANTEDcredential0123456789abcdef"

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 350455328ddafull audit observations/trust-audit/mcp-server/qualixar__superlocalmemory-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06350455328ddaBLOCKF47first audit
06

Questions

What is the SuperLocalMemory MCP server?

Open-source governed, local-first memory control plane for AI agents and teams. arXiv:2608.08253

What tools does SuperLocalMemory expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is SuperLocalMemory safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (47/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does SuperLocalMemory need?

It reads ANTHROPIC_API_KEY, API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, SLM_DOGFOOD_API_KEY, SLM_INJECTION_EXACT_TOKENS, SLM_MESH_SHARED_SECRET, SLM_REQUIRE_CREDENTIALS, SLM_SIGNER_KEY and TOKENIZERS_PARALLELISM from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does SuperLocalMemory run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as superlocalmemory at 4.1.21.

How current is this page?

The grade is for one exact copy of the source (350455328dda), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement