SuperLocalMemoryBLOCK
Open-source governed, local-first memory control plane for AI agents and teams. arXiv:2608.08253
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Claude Code, Codex, Cursor and other MCP clients forget what they learned when a session ends. SuperLocalMemory (SLM) gives them one long-term memory that lives on your machine: it learns from use, enforces who may read and erase what, coordinates many agents, and says "I don't have that" instead of guessing.
Every recall is checked before your agent uses it. A judge decides whether the memories found actually answer the question: Laya runs fully on your Mac, and Jev runs online on Windows, Linux and macOS. When they don't answer it, SLM says so instead of handing over a confident wrong answer: a hallucination guard for retrieval (answer check).
In Mode A, core remember and recall make no model-provider call. Anything that sends data out is a choice you make, and the docs say exactly what goes.
[](https://pypi.org/project/superlocalmemory/) [](https://www.npmjs.com/package/superlocalmemory) [](https://pepy.tech/project/superlocalmemory) [](https://www.npmjs.com/package/superlocalmemory) [](https://github.com/qualixar/superlocalmemory/stargazers) [](pyproject.toml) [](LICENSE) [![An
350455328ddaOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add superlocalmemory --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env API_KEY=${API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"superlocalmemory": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"API_KEY": "${API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
}
}
}
}Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
echo | read | Echo a string — used by the e2e client call. |
ping | read | Health ping. |
recall | read | Return a deliberately non-trivial response without a live database. |
Trust audit
BLOCKgrade F · trust 47/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
"exec(", "eval(", "compile(", "os.system", "os.popen", "os.spawn","/.ssh/", ".install_token", ".aws/credentials", ".netrc",
"169.254.169.254",
"metadata.google.internal",
m = __import__(mod)
__import__(mod)
__import__(mod)
importlib.import_module(name)
_mod_v341 = __import__(f"superlocalmemory.server.routes.{_module_name_v341}", fromlist=["router"])print(f" Key: {'configured' if api_key else 'none (keyless)'}")print(f" {secret}\n")"without consent", "exfiltrat",
"topics": [{"name": "secret=AKIAABCDEFGHIJKLMNOP", "strength": 0.9}],assert "AKIAABCDEFGHIJKLMNOP" not in dumped
("AWS AKIAABCDEFGHIJKLMNOP", "AKIAABCDEFGH"),"entities": ["AKIAABCDEFGHIJKLMNOP", "Qualixar"],
assert "AKIAABCDEFGHIJKLMNOP" not in dumped
"DATABASE_URL=postgres://admin:[email protected]:5432/app",
("URL password containing @", "mysql://root:p@ssw0rdFAKE@localhost/db", "p@ssw0rdFAKE"),assert out == f"postgres://admin:{REDACTED_MARKER}@db1.corp.internal:5432/app"api_key="sk-test-EXISTING-do-not-wipe",
secret = "AKIAsecretthatmustnotleak12345"
TOKEN = "install-token-for-this-test-0123456789abcdef"
token = "global-scope-opt-in-token-991"
secret = b"ghp_PLANTEDcredential0123456789abcdef"
Gates applied: no_behavioural_pass.
350455328ddafull audit observations/trust-audit/mcp-server/qualixar__superlocalmemory-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 350455328dda | BLOCK | F | 47 | first audit |
Questions
What is the SuperLocalMemory MCP server?
Open-source governed, local-first memory control plane for AI agents and teams. arXiv:2608.08253
What tools does SuperLocalMemory expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SuperLocalMemory safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (47/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does SuperLocalMemory need?
It reads ANTHROPIC_API_KEY, API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, SLM_DOGFOOD_API_KEY, SLM_INJECTION_EXACT_TOKENS, SLM_MESH_SHARED_SECRET, SLM_REQUIRE_CREDENTIALS, SLM_SIGNER_KEY and TOKENIZERS_PARALLELISM from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SuperLocalMemory run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as superlocalmemory at 4.1.21.
How current is this page?
The grade is for one exact copy of the source (350455328dda), read on 2026-10-06. The repository is watched and re-audited when it changes.