AtlasCAUTION
Open-source local-first cognitive memory. AGM-compliant belief revision (49/49 postulates). When a fact changes, downstream beliefs are automatically re-evaluated, not just flagged.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Open-source local-first cognitive memory — alpha. Implements AGM-compliant belief revision on a property graph. Adds a propagation engine — Ripple — that recomputes downstream beliefs when an upstream fact changes. Runs entirely on your laptop.
[](https://opensource.org/licenses/Apache-2.0) [](https://github.com/RichSchefren/atlas/actions/workflows/test.yml) [](docs/AGM_COMPLIANCE.md) []()
[](https://livememory.pages.dev)
↑ 3× preview — [watch the narrated 90-second version with sound](https://livememory.pages.dev). The story behind it is [on X](https://x.com/richschefren/status/2065318023007814017) — reply with the stale belief that bit you.
Alpha: the propagation loop works end-to-end (./demo.shproves it in 12 seconds). Ingestion and entity resolution on truly unstructured text are still maturing — seeatlas_core/ingestion/for the prompts we're iterating on.
See it work in 12 seconds
git clone https://github.com/RichSchefren/atlas && cd atlas docker compose up -d python3 -m venv .venv && source .venv/bin/activate pip install -e ".[dev]" ./demo.sh
The ./demo.sh command runs the entire loop end-to-end, visibly:
- Plants a tiny graph (3 nodes, 2
Depends_Onedges) - Changes a fact (Origins coffee price: $89 → $129)
- Calls
RippleEngine.propagate()— the real orchestrator - Shows reassessment proposals, contradictions, and routing decisions
- Resolves one through
adjudication.resolve()(real AGM revise) - Verifies the SHA-256 hash chain
Every line is real Neo4j + real l
82985821158cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add atlas-memory-obsidian --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ATLAS_COGNITIVE_TOKEN=${ATLAS_COGNITIVE_TOKEN} --env ATLAS_HTTP_TOKEN=${ATLAS_HTTP_TOKEN} --env ATLAS_NEO4J_PASSWORD=${ATLAS_NEO4J_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"atlas-memory-obsidian": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"ATLAS_COGNITIVE_TOKEN": "${ATLAS_COGNITIVE_TOKEN}",
"ATLAS_HTTP_TOKEN": "${ATLAS_HTTP_TOKEN}",
"ATLAS_NEO4J_PASSWORD": "${ATLAS_NEO4J_PASSWORD}"
}
}
}
}Exposed tools (3)
2 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
memory.get | read | Fetch one Atlas memory by candidate ID. No graph required. |
memory.list | read | List retrievable non-denied Atlas memories newest first. |
sharing.revoke | destructive | Revoke a previously granted share. |
Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (13 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
atlas-memory-gbrain-0.1.0.tgz
atlas-memory-openclaw-0.2.0.tgz
atlas-arxiv.tar.gz
"app://obsidian.md,http://localhost:8765,http://127.0.0.1:8765",
"http://127.0.0.1:8765",
const baseUrl = argument("--base-url", "http://127.0.0.1:8741");parser.add_argument("--base-url", default="http://127.0.0.1:8741")self.base_url = f"http://127.0.0.1:{state['port']}"token = "parent-watch-token-0123456789abcdef"
sharing.revoke
mod = importlib.import_module(module)
mkdir -p ../../.contract/gbrain-package-committed ../../.contract/gbrain-package-rebuilt
cp atlas-memory-gbrain-0.1.0.tgz ../../.contract/atlas-memory-gbrain-committed.tgz
tar -xzf atlas-memory-gbrain-0.1.0.tgz -C ../../.contract/gbrain-package-committed
tar -xzf atlas-memory-gbrain-0.1.0.tgz -C ../../.contract/gbrain-package-rebuilt
diff -ru ../../.contract/gbrain-package-committed/package ../../.contract/gbrain-package-rebuilt/package
@types/node, typescript
@types/node, esbuild, obsidian, typescript
After running `./demo.sh`, open `http://localhost:7474` (default password `atlasdev`) and run any of these:
op read "op://Developer/OpenAI API Key/credential" | head -c 10 # key reads
site/atlas-hero.gif
site/atlas-launch.mp4
Gates applied: no_behavioural_pass.
82985821158cfull audit observations/trust-audit/mcp-server/richschefren__atlas-7.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 82985821158c | CAUTION | C | 75 | first audit |
Questions
What is the Atlas MCP server?
Open-source local-first cognitive memory. AGM-compliant belief revision (49/49 postulates). When a fact changes, downstream beliefs are automatically re-evaluated, not just flagged.
What tools does Atlas expose?
3 in total: 2 read-only, 0 that write, and 1 that can delete or overwrite (sharing.revoke). Every one is listed on this page with its risk.
Is Atlas safe to connect to an agent?
With care. The audit graded it C (75/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Atlas need?
It reads ANTHROPIC_API_KEY, ATLAS_COGNITIVE_TOKEN, ATLAS_HTTP_TOKEN, ATLAS_NEO4J_PASSWORD, GBRAIN_MCP_TOKEN, MEMORI_API_KEY, NEO4J_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Atlas run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as atlas-memory-obsidian at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (82985821158c), read on 2026-10-07. The repository is watched and re-audited when it changes.