Atlas / MCP servers / roboticforce / Sugar

SugarBLOCK

mcp/roboticforce/sugar-1

Persistent memory for AI coding agents. Local-first, cross-session context, global knowledge, and optional autonomous task execution.

Verdict
BLOCK
Grade
F
Trust score
59 /100
Exposed tools
33 23r · 7w · 3d
Transport
stdio
License
NOASSERTION
Stars
98
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Persistent memory for AI coding agents.

Your AI agent starts every session with amnesia. The architecture decisions, conventions, and gotchas you explained last week are gone. Sugar is the local-first memory layer that remembers them for you - per project, across projects, on your machine.

Your memory. Your machine. Your data.

What Sugar Does

Sugar is a memory layer your AI coding agent can read and write directly:

  • Project memory - Decisions, preferences, error patterns, and research stored per-project
  • Global memory - Standards and guidelines shared across every project you work on
  • Semantic search - Retrieve relevant context by meaning, not just keywords
  • MCP integration - Your AI agent reads and writes memory directly during sessions
  • Local-first - SQLite on your disk, no API keys, fully offline-capable
  • Task queue - Optional autonomous execution, powered by the same memory layer

Quick Start

# Install once, use in any project
pipx install sugarai

# Initialize in your project
cd ~/dev/my-app
sugar init

# Store what you know
sugar remember "We use async/await everywhere, never callbacks" --type preference
sugar remember "JWT tokens use RS256, expire in 15 min - see auth/tokens.py" --type decision
sugar remember "When tests fail with import errors, check __init__.py exports first" --type error_pattern

# Retrieve it later
sugar recall "authentication"
sugar recall "how do we handle async"

Your AI agent can also read and write memory directly - no copy-pasting required.

MCP Integration

Connect Sugar's memory to your AI agent so it can access project context automatically.

Claude Code - Memory server (primary):

claude mcp add sugar -- sugar mcp memory

Claude Code - Task server (optional):

claude mcp add sugar-tasks -- sugar mcp tasks

Once connected, Claude can call store_learning to save context mid-session and `sea

Read from source at commit b2bbbcc515e1OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add sugarai -- None sugarai==3.10.2 mcp memory
claude-code (pypi)
claude mcp add sugarai -- None sugarai==3.10.2 mcp serve
03

Exposed tools (33)

23 read · 7 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_issuereadAnalyze a GitHub issue and return insights
createTaskwriteCreate a new Sugar task for autonomous development
find_similar_issuesreadFind issues similar to a given issue
generate_responsereadGenerate a response for a GitHub issue
getStatusreadGet Sugar system status and task queue metrics
get_project_contextread
initSugarreadInitialize Sugar in the current project directory
listTasksreadList Sugar tasks with optional filtering
list_recent_memoriesread
recallread
removeTaskdestructiveRemove a task from the queue
runOncewriteExecute one autonomous development cycle (picks up highest priority task)
search_codebasereadSearch the codebase for relevant code
search_memoryread
store_learningread
sugar_addwriteAdd a new task to Sugar
sugar_add_taskwrite
sugar_listreadList Sugar tasks with optional filtering by status, type, or priority
sugar_list_tasksread
sugar_priorityreadChange the priority of a task. Higher priority tasks are executed first.
sugar_recallreadSearch Sugar
sugar_removedestructiveRemove a task from the work queue (cannot be undone)
sugar_remove_taskdestructive
sugar_runwriteExecute one autonomous development cycle. Sugar will pick the highest priority pending task and execute it. Use --dry-run to simulate without making changes.
sugar_statusreadGet Sugar system status including task queue metrics and worker status
sugar_task_statusread
sugar_update_taskwrite
sugar_viewreadView detailed information about a specific task including history and context
sugar_view_taskread
suggest_labelsreadSuggest labels for an issue based on its content
updateTaskwriteUpdate an existing Sugar task
validate_responsereadValidate a response before posting
viewTaskreadView detailed information about a specific task
04

Trust audit

BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (10 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (21)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
scripts/benchmark_v3.py:130
"blocked_commands": ["sudo", "rm -rf /"],
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
scripts/benchmark_v3.py:144
"blocked_commands": ["sudo", "rm -rf /", "chmod 777"],
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
scripts/benchmark_v3.py:153
{"command": "sudo rm -rf /"},
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
scripts/benchmark_v3.py:243
"blocked_commands": ["sudo"],
Why it matters. asks for elevated privileges
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
.claude-plugin/mcp-server/sugar-mcp.js:71
'/usr/local/bin/sugar',
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
packages/mcp-server/src/index.ts:81
"/usr/local/bin/sugar",
MEDIUMFilesystem / path · fs.system_paths · CWE-22, CWE-59
sugar/main.py:2341
"/usr/local/bin/claude",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
removeTask, sugar_remove, sugar_remove_task
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/test_cli.py:45
mock_find_claude.return_value = "/usr/local/bin/claude"
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/test_cli.py:56
assert config["sugar"]["claude"]["command"] == "/usr/local/bin/claude"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
.claude-plugin/mcp-server/package.json
eslint
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp-server/package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/opencode-plugin/package.json
@types/bun, typescript, zod
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
aiosqlite, pyyaml, watchdog, gitpython, structlog, click, python-dotenv, claude-agent-sdk
Why it matters. 9 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/phase3_sdk_integration.md:1726
@app.post("/session/{session_id}/prompt")
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
TERMS.md:52
- Never run Sugar with elevated privileges unless absolutely necessary
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/user/memory.md:307
Add Sugar as an MCP server to give Claude Code full access to your memory:
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/user/faq.md:45
# Add to ~/.bashrc or ~/.zshrc
Why it matters. instructs the agent to persist itself in the user's environment
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/user/installation-guide.md:28
- Add to your PATH, or
Why it matters. instructs the agent to persist itself in the user's environment
INFOPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b2bbbcc515e1full audit observations/trust-audit/mcp-server/roboticforce__sugar-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b2bbbcc515e1BLOCKF59first audit
06

Questions

What is the Sugar MCP server?

Persistent memory for AI coding agents. Local-first, cross-session context, global knowledge, and optional autonomous task execution.

What tools does Sugar expose?

33 in total: 23 read-only, 7 that write, and 3 that can delete or overwrite (removeTask, sugar_remove, sugar_remove_task). Every one is listed on this page with its risk.

Is Sugar safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (59/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Sugar need?

It reads ANTHROPIC_API_KEY, GITHUB_TOKEN and OPENCODE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Sugar run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @anthropic/sugar-opencode at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (b2bbbcc515e1), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement