Atlas / MCP servers / richschefren / Atlas

AtlasCAUTION

mcp/richschefren/atlas-7

Open-source local-first cognitive memory. AGM-compliant belief revision (49/49 postulates). When a fact changes, downstream beliefs are automatically re-evaluated, not just flagged.

Verdict
CAUTION
Grade
C
Trust score
75 /100
Exposed tools
3 2r · 0w · 1d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
85
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Open-source local-first cognitive memory — alpha. Implements AGM-compliant belief revision on a property graph. Adds a propagation engine — Ripple — that recomputes downstream beliefs when an upstream fact changes. Runs entirely on your laptop.

[](https://opensource.org/licenses/Apache-2.0) [](https://github.com/RichSchefren/atlas/actions/workflows/test.yml) [](docs/AGM_COMPLIANCE.md) []()

[](https://livememory.pages.dev)

↑ 3× preview — [watch the narrated 90-second version with sound](https://livememory.pages.dev). The story behind it is [on X](https://x.com/richschefren/status/2065318023007814017) — reply with the stale belief that bit you.

Alpha: the propagation loop works end-to-end (./demo.sh proves it in 12 seconds). Ingestion and entity resolution on truly unstructured text are still maturing — see atlas_core/ingestion/ for the prompts we're iterating on.

See it work in 12 seconds

git clone https://github.com/RichSchefren/atlas && cd atlas
docker compose up -d
python3 -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"
./demo.sh

The ./demo.sh command runs the entire loop end-to-end, visibly:

  1. Plants a tiny graph (3 nodes, 2 Depends_On edges)
  2. Changes a fact (Origins coffee price: $89 → $129)
  3. Calls RippleEngine.propagate() — the real orchestrator
  4. Shows reassessment proposals, contradictions, and routing decisions
  5. Resolves one through adjudication.resolve() (real AGM revise)
  6. Verifies the SHA-256 hash chain

Every line is real Neo4j + real l

Read from source at commit 82985821158cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add atlas-memory-obsidian --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ATLAS_COGNITIVE_TOKEN=${ATLAS_COGNITIVE_TOKEN} --env ATLAS_HTTP_TOKEN=${ATLAS_HTTP_TOKEN} --env ATLAS_NEO4J_PASSWORD=${ATLAS_NEO4J_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "atlas-memory-obsidian": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "ATLAS_COGNITIVE_TOKEN": "${ATLAS_COGNITIVE_TOKEN}",
        "ATLAS_HTTP_TOKEN": "${ATLAS_HTTP_TOKEN}",
        "ATLAS_NEO4J_PASSWORD": "${ATLAS_NEO4J_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (3)

2 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
memory.getreadFetch one Atlas memory by candidate ID. No graph required.
memory.listreadList retrievable non-denied Atlas memories newest first.
sharing.revokedestructiveRevoke a previously granted share.
04

Trust audit

CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (13 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (22)

MEDIUMInventory / provenance · inv.binary · CWE-1104
integrations/gbrain-atlas/atlas-memory-gbrain-0.1.0.tgz
atlas-memory-gbrain-0.1.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
integrations/openclaw-atlas/atlas-memory-openclaw-0.2.0.tgz
atlas-memory-openclaw-0.2.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
paper/arxiv/atlas-arxiv.tar.gz
atlas-arxiv.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
atlas_core/api/api_app.py:34
"app://obsidian.md,http://localhost:8765,http://127.0.0.1:8765",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
atlas_core/api/http_server.py:35
"http://127.0.0.1:8765",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
integrations/cognitive-service/clients/node-client.mjs:85
const baseUrl = argument("--base-url", "http://127.0.0.1:8741");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
integrations/cognitive-service/clients/python_client.py:102
parser.add_argument("--base-url", default="http://127.0.0.1:8741")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
integrations/hermes-atlas/atlas/cognitive_client.py:63
self.base_url = f"http://127.0.0.1:{state['port']}"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/hermes/test_native_hermes_plugin.py:725
token = "parent-watch-token-0123456789abcdef"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
sharing.revoke
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/unit/test_docs_install_modes.py:57
mod = importlib.import_module(module)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/gbrain-native.yml:51
mkdir -p ../../.contract/gbrain-package-committed ../../.contract/gbrain-package-rebuilt
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/gbrain-native.yml:52
cp atlas-memory-gbrain-0.1.0.tgz ../../.contract/atlas-memory-gbrain-committed.tgz
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/gbrain-native.yml:53
tar -xzf atlas-memory-gbrain-0.1.0.tgz -C ../../.contract/gbrain-package-committed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/gbrain-native.yml:55
tar -xzf atlas-memory-gbrain-0.1.0.tgz -C ../../.contract/gbrain-package-rebuilt
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
.github/workflows/gbrain-native.yml:56
diff -ru ../../.contract/gbrain-package-committed/package ../../.contract/gbrain-package-rebuilt/package
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
integrations/openclaw-atlas/package.json
@types/node, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
obsidian-plugin/package.json
@types/node, esbuild, obsidian, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:145
After running `./demo.sh`, open `http://localhost:7474` (default password `atlasdev`) and run any of these:
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
laptop-setup/README.md:96
op read "op://Developer/OpenAI API Key/credential" | head -c 10  # key reads
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
site/atlas-hero.gif
site/atlas-hero.gif
Why it matters. 1103526 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
site/atlas-launch.mp4
site/atlas-launch.mp4
Why it matters. 5846012 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 82985821158cfull audit observations/trust-audit/mcp-server/richschefren__atlas-7.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0782985821158cCAUTIONC75first audit
06

Questions

What is the Atlas MCP server?

Open-source local-first cognitive memory. AGM-compliant belief revision (49/49 postulates). When a fact changes, downstream beliefs are automatically re-evaluated, not just flagged.

What tools does Atlas expose?

3 in total: 2 read-only, 0 that write, and 1 that can delete or overwrite (sharing.revoke). Every one is listed on this page with its risk.

Is Atlas safe to connect to an agent?

With care. The audit graded it C (75/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Atlas need?

It reads ANTHROPIC_API_KEY, ATLAS_COGNITIVE_TOKEN, ATLAS_HTTP_TOKEN, ATLAS_NEO4J_PASSWORD, GBRAIN_MCP_TOKEN, MEMORI_API_KEY, NEO4J_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Atlas run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as atlas-memory-obsidian at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (82985821158c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement