RoampalBLOCK
Memory that learns what works.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://roampal.ai) [](https://www.python.org/downloads/) [](https://tauri.app/) [](https://roampal.ai) [](LICENSE)
Memory that learns what works. So you can do more of it.
Say it worked. Say it didn't. The AI remembers.
Stop re-explaining yourself every conversation. Roampal remembers outcomes, learns from feedback, and gets smarter over time—all 100% private and local.
85.8% non-adversarial on LoCoMo (1,986 questions). +23 pts over raw ingestion. Absorbs 1,135 poison memories losing only 4 pts. (Paper)
Benchmark Results
LoCoMo dataset (1,986 questions, 5 categories, corrected ground truths). Evaluated with [roampal-labs](https://github.com/roampal-ai/roampal-labs). Dual-graded by local 20B + MiniMax M2.7.
- System learns through natural conversation, not t
ba9a724a4cc0OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add roampal-ui --env ROAMPAL_API_KEY=${ROAMPAL_API_KEY} --env ROAMPAL_REQUIRE_AUTH=${ROAMPAL_REQUIRE_AUTH} -- npx -y [email protected]{
"mcpServers": {
"roampal-ui": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ROAMPAL_API_KEY": "${ROAMPAL_API_KEY}",
"ROAMPAL_REQUIRE_AUTH": "${ROAMPAL_REQUIRE_AUTH}"
}
}
}
}Exposed tools (11)
8 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_to_memory_bank | write | |
archive_memory | read | Archive outdated/irrelevant memories from memory_bank. |
clear | destructive | Clear conversation |
export | read | Export chat history |
gemma4 | read | Gemma 4 8B — native tools, lower VRAM |
get_context_insights | read | |
help | read | Show all commands |
record_response | read | |
score_memories | read | |
search_memory | read | |
update_memory | write | Update existing memory when information changes or needs correction. |
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (6 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const parsed = yaml.load(yamlContent);
- Prompt injection sanitization: Removes malicious patterns ([IGNORE], [SYSTEM], <|im_start|>, etc.)
icon.icns
shutil.rmtree(chromadb_dest)
shutil.rmtree(temp_dir)
shutil.rmtree(metadata_dir)
shutil.rmtree(uploads_dir)
shutil.rmtree(repo_dir)
text = 'api_key="sk_live_abcdefghij1234567890"'
text = '''-----BEGIN RSA PRIVATE KEY-----
text = 'api_key="sk_live_abcdefghij1234567890"'
assert "sk_live_abcdefghij1234567890" not in result
API Key: api_key=sk_live_1234567890abcdef1234
clear
__import__(pkg)
cache_key = hashlib.md5(text.encode('utf-8')).hexdigest()"sessions/../../../etc/passwd",
"sessions/../../malicious.txt",
"../../secret2.txt",
"data/../../../secret3.txt",
zf.writestr("../../../tmp/pwned.txt", "attacker controlled content")+ "csp": "default-src 'self'; img-src 'self' data: blob: http://localhost:8765 http://127.0.0.1:8765; connect-src 'self' http://localhost:8765 ...
| `ui-implementation/src-tauri/tauri.conf.json` | Added `img-src 'self' data: blob: http://localhost:8765 http://127.0.0.1:8765` |
await apiFetch('http://127.0.0.1:8765/api/test')_JPEG_DATA_URL = "data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAYEBQYFBAYGBQYHBwYIChAKCgkJChQODwwQFxQYGBcUFhYaHSUfGhsjHBYWICwgIyYnKSopGR8tMC0oMCUoKSj/2wBDAQcHBwoIChMKChMoGhYaKCgoKCgoKCgoKCg
Gates applied: no_behavioural_pass.
ba9a724a4cc0full audit observations/trust-audit/mcp-server/roampal-ai__roampal-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ba9a724a4cc0 | BLOCK | F | 46 | first audit |
Questions
What is the Roampal MCP server?
Memory that learns what works.
What tools does Roampal expose?
11 in total: 8 read-only, 2 that write, and 1 that can delete or overwrite (clear). Every one is listed on this page with its risk.
Is Roampal safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Roampal need?
It reads ROAMPAL_API_KEY and ROAMPAL_REQUIRE_AUTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Roampal run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as roampal-ui at 0.3.3.
How current is this page?
The grade is for one exact copy of the source (ba9a724a4cc0), read on 2026-10-07. The repository is watched and re-audited when it changes.