Atlas / MCP servers / ruvnet / AgentDB

AgentDBBLOCK

mcp/ruvnet/agentdb

Vector memory that gets smarter every time your agent uses it.

Verdict
BLOCK
Grade
F
Trust score
26 /100
Exposed tools
76 62r · 11w · 3d
Transport
stdio
License
MIT
Stars
89
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/agentdb) [](https://www.npmjs.com/package/agentdb) [](LICENSE) [](https://www.typescriptlang.org/)

[](https://github.com/ruvnet/ruvector) [](#-self-learning-loop) [](#-mcp-integration) [](https://github.com/ruvnet/agentdb)

Vector memory that gets smarter every time your agent uses it.

A single-file cognitive container — vectors, indexes, learning state, and a cryptographic audit trail in one .rvf. Self-learning search improves up to 36% from feedback alone, with no manual tuning. Runs in Node, the browser, edge runtimes, and offline.

Why AgentDB?

Most vector databases store embeddings and call it done. AgentDB watches which results your agent actually used, learns from that signal, and ranks the next query better. The bandit underneath also picks the right RL algorithm, the right compression tier, and the right pattern weighting on its own — so the database itself gets sharper while you focus on the agent.
The name: a database that thinks like an agent — episodic memory, skill library, causal r
Read from source at commit 85bed1bd0078OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add vite_react_shadcn_ts --env AGENTDB_DEV_BYPASS_SECRET=${AGENTDB_DEV_BYPASS_SECRET} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GOOGLE_GEMINI_API_KEY=${GOOGLE_GEMINI_API_KEY} --env HF_TOKEN=${HF_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "vite_react_shadcn_ts": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AGENTDB_DEV_BYPASS_SECRET": "${AGENTDB_DEV_BYPASS_SECRET}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "GOOGLE_GEMINI_API_KEY": "${GOOGLE_GEMINI_API_KEY}",
        "HF_TOKEN": "${HF_TOKEN}"
      }
    }
  }
}
03

Exposed tools (76)

62 read · 11 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AgentDBreadUltra-fast vector database for AI agents with WebAssembly acceleration, adaptive learning, and 100% client-side operation.
BasketballreadOfficial size basketball for indoor/outdoor use
advanced_authreadAdvanced authentication with MFA
agentdb_attention_benchmarkreadBenchmark attention mechanism performance
agentdb_attention_computereadCompute attention mechanism for query-key-value triplets
agentdb_attention_configurereadConfigure attention mechanism parameters
agentdb_attention_metricsreadGet attention mechanism usage metrics and statistics
agentdb_clear_cachedestructiveClear query cache to refresh statistics and search results
agentdb_deletedestructiveDelete vector(s) from AgentDB by ID or filters. Supports single ID deletion or bulk deletion with conditions.
agentdb_delete_batchdestructiveDelete many episode/pattern rows by ID list in a single transaction. Faster and safer than looping
agentdb_initreadInitialize AgentDB database with schema and optimizations. Creates all required tables for vector storage, causal memory, skills, and provenance tracking.
agentdb_insertwriteInsert a single vector with metadata into AgentDB. Automatically generates embeddings for the provided text.
agentdb_insert_batchwriteBatch insert multiple vectors efficiently using transactions and parallel embedding generation. Optimized for large datasets.
agentdb_pattern_searchreadSearch patterns with taskEmbedding, k, threshold, and filters
agentdb_pattern_statsreadGet pattern statistics including total patterns, success rates, and top task types
agentdb_pattern_storereadStore reasoning pattern with embedding, taskType, approach, and successRate
agentdb_pattern_store_batchreadBatch store multiple reasoning patterns efficiently using transactions and parallel embedding generation. 4x faster than sequential agentdb_pattern_store calls. 🔄 PARALLEL-SAFE: Can be used alongside other batch operations.
agentdb_searchreadSemantic k-NN vector search using cosine similarity. Returns the most relevant results ranked by similarity score.
agentdb_statsreadGet comprehensive database statistics including table counts, storage usage, and performance metrics
api_requestreadMake authenticated API requests
auth_skillreadAuthentication implementation
authenticationreadUser authentication with JWT
basic_authreadBasic authentication
cache_managerreadRedis-based caching with TTL
caching-skillreadImplement caching strategies
causal_add_edgewriteAdd a causal relationship between actions and outcomes
causal_queryreadQuery causal effects to understand what actions cause what outcomes
causal_traversereadWalk the causal graph between two memories. Returns the chain of causal links (with confidence and uplift) up to max_depth hops. Use this to answer
complex_skillreadComplex skill with nested types
data_validationreadInput data validation
database_querywriteExecute SQL queries safely
database_query_optimizerreadOptimize database queries with batch loading
db_statsreadGet database statistics showing record counts
error_handlerreadComprehensive error handling middleware
experience_recordreadRecord tool execution as experience for reinforcement learning and experience replay
extracted-patternreadPattern from learning
fast-skillreadFast execution skill
fibonaccireadCalculate fibonacci numbers
hash_passwordreadSecure password hashing with bcrypt
high-successreadHigh success rate skill
jwt_authreadJWT authentication with tokens
jwt_authenticationreadGenerate and verify JWT tokens
learner_discoverreadAutomatically discover causal patterns from episode history
learning_end_sessionwriteEnd an active learning session and save the final trained policy to the database.
learning_explainreadExplain action recommendations with confidence scores and supporting evidence from past experiences
learning_feedbackwriteSubmit feedback on action quality to train the RL policy. Feedback includes reward signal and outcome state.
learning_metricsreadGet learning performance metrics including success rates, rewards, and policy improvement
learning_predictreadGet AI-recommended action for a given state with confidence scores and alternative actions.
learning_start_sessionwriteStart a new reinforcement learning session with specified algorithm and configuration. Supports 9 RL algorithms: q-learning, sarsa, dqn, policy-gradient, actor-critic, ppo, decision-transformer, mcts, model-based.
learning_trainreadTrain the RL policy using batch learning with collected experiences. Returns training metrics including loss, average reward, and convergence rate.
learning_transferwriteTransfer learning between sessions or tasks, enabling knowledge reuse across different contexts
metadata_testreadTest metadata persistence
migration-skillreadTest skill for migration
no_descriptionread
oauth2_loginreadOAuth2 login flow with PKCE
optimization-skillreadOptimize database queries
recall_with_certificatereadRetrieve memories with causal utility scoring and provenance certificate
reflexion_retrievereadRetrieve relevant past episodes for learning from experience
reflexion_storereadStore an episode with self-critique for reflexion-based learning
reflexion_store_batchreadBatch store multiple episodes efficiently using transactions and parallel embedding generation. 3.3x faster than sequential reflexion_store calls (152 → 500 ops/sec). 🔄 PARALLEL-SAFE: Can be used alongside other batch operations.
reward_signalreadCalculate reward signal for outcomes based on success, efficiency, and causal impact
simple_skillreadA simple test skill
skill-1readFirst skill
skill-2readSecond skill
skill_createwriteCreate a reusable skill in the skill library
skill_create_batchwriteBatch create multiple skills efficiently using transactions and parallel embedding generation. 3x faster than sequential skill_create calls (304 → 900 ops/sec). 🔄 PARALLEL-SAFE: Can be used alongside other batch operations.
skill_searchreadSearch for applicable skills by semantic similarity
stats-skillreadSkill for stats testing
tagged-patternreadPattern with tags
test-patternreadTest pattern storage
test-skillreadTest skill
test_skillreadTest skill
test_updatewriteTest skill update
type_testreadType compatibility test
unique-patternreadFirst pattern
validation_schemareadRequest validation with Zod schemas
04

Trust audit

BLOCKgrade F · trust 26/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (7 observation(s))
Shell
declared (8 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/docker-validation.sh:153
- eval() removal
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/cli/commands/migrate.ts:92
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/db-fallback.ts:431
exec(sql: string) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/db-fallback.ts:629
exec(sql: string) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/types/database.types.ts:79
exec(sql: string): void;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/adrs/ADR-008-chat-ui-rvf-kernel-embedding.md:623
jailbreak, PII masking, input sanitization, unicode filtering, rate
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
MEDIUMInventory / provenance · inv.binary · CWE-1104
ui/agentdb-browser-examples.zip
agentdb-browser-examples.zip
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
ui/bun.lockb
bun.lockb
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
src/cli/commands/attention.ts:547
score = Math.random() > 0.9 ? dotProduct(query, key) : 0;
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
src/mcp/attention-tools-handlers.ts:374
score = Math.random() > 0.9 ? dotProductMCP(query, key) : 0;
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/agentdb-cli.ts:838
console.log(`  Auth Token: ${colors.cyan}${authToken.substring(0, 8)}...${colors.reset}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/route.ts:399
console.log(`  Token Count: ${features.tokenCount}`);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/validate-security-fixes.ts:305
logTest('Prevent UNION-based exfiltration', false, 'Attack payload accepted!');
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/validate-security-fixes.ts:308
logTest('Prevent UNION-based exfiltration', true);
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/validate-security-fixes.ts:310
logTest('Prevent UNION-based exfiltration', false, `Wrong error: ${error}`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
simulation/scenarios/domain-examples/trading-systems.ts:14
forwardPassTargetUs: 500,        // Sub-millisecond target (500μs)
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
simulation/scenarios/domain-examples/trading-systems.ts:78
p50LatencyUs: 500,               // 500μs median latency
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
simulation/scenarios/latent-space/quantum-hybrid.ts:246
const coherenceTimeMs = gateDepth * 0.001; // 1μs per gate (optimistic)
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
simulation/scenarios/latent-space/traversal-optimization.ts:233
console.log(`✅ Using Beam-5 (94.8% recall) + Dynamic-k (71μs latency)\n`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
simulation/scenarios/latent-space/traversal-optimization.ts:728
- **Beam Width**: 5 (94.8% recall@10, 112μs latency)
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
ui/.claude/commands/flow-nexus/user-tools.md:136
token: "verification_token_from_email"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
ui/.claude/skills/flow-nexus-platform/SKILL.md:69
token: "reset_token_from_email",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
ui/.claude/skills/flow-nexus-platform/SKILL.md:77
token: "verification_token_from_email"
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
ui/public/agentdb/examples/browser/management-ide/PATTERN_ENHANCEMENTS_INTEGRATION.md:38
<p style="color: var(--text-secondary); margin-bottom: 1rem; font-size: 0.875rem;">
MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
ui/public/agentdb/examples/browser/management-ide/PATTERN_ENHANCEMENTS_INTEGRATION.md:49
<button class="btn btn-secondary btn-sm" onclick="bulkDeletePatterns()" id="bulk-delete-btn" style="display: none;">🗑️ Delete Selected</button>

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 85bed1bd0078full audit observations/trust-audit/mcp-server/ruvnet__agentdb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0785bed1bd0078BLOCKF26first audit
06

Questions

What is the AgentDB MCP server?

Vector memory that gets smarter every time your agent uses it.

What tools does AgentDB expose?

76 in total: 62 read-only, 11 that write, and 3 that can delete or overwrite (agentdb_clear_cache, agentdb_delete, agentdb_delete_batch). Every one is listed on this page with its risk.

Is AgentDB safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (26/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AgentDB need?

It reads AGENTDB_DEV_BYPASS_SECRET, ANTHROPIC_API_KEY, GOOGLE_GEMINI_API_KEY, HF_TOKEN, HUGGINGFACE_API_KEY, JWT_SECRET, MCP_API_KEY, MCP_SECRET, OPENAI_API_KEY, OPENROUTER_API_KEY and REFRESH_TOKEN_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AgentDB run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as vite_react_shadcn_ts at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (85bed1bd0078), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement