AgentDBBLOCK
Vector memory that gets smarter every time your agent uses it.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/agentdb) [](https://www.npmjs.com/package/agentdb) [](LICENSE) [](https://www.typescriptlang.org/)
[](https://github.com/ruvnet/ruvector) [](#-self-learning-loop) [](#-mcp-integration) [](https://github.com/ruvnet/agentdb)
Vector memory that gets smarter every time your agent uses it.
A single-file cognitive container — vectors, indexes, learning state, and a cryptographic audit trail in one .rvf. Self-learning search improves up to 36% from feedback alone, with no manual tuning. Runs in Node, the browser, edge runtimes, and offline.
Why AgentDB?
Most vector databases store embeddings and call it done. AgentDB watches which results your agent actually used, learns from that signal, and ranks the next query better. The bandit underneath also picks the right RL algorithm, the right compression tier, and the right pattern weighting on its own — so the database itself gets sharper while you focus on the agent.
The name: a database that thinks like an agent — episodic memory, skill library, causal r
85bed1bd0078OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add vite_react_shadcn_ts --env AGENTDB_DEV_BYPASS_SECRET=${AGENTDB_DEV_BYPASS_SECRET} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GOOGLE_GEMINI_API_KEY=${GOOGLE_GEMINI_API_KEY} --env HF_TOKEN=${HF_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"vite_react_shadcn_ts": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"AGENTDB_DEV_BYPASS_SECRET": "${AGENTDB_DEV_BYPASS_SECRET}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"GOOGLE_GEMINI_API_KEY": "${GOOGLE_GEMINI_API_KEY}",
"HF_TOKEN": "${HF_TOKEN}"
}
}
}
}Exposed tools (76)
62 read · 11 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
AgentDB | read | Ultra-fast vector database for AI agents with WebAssembly acceleration, adaptive learning, and 100% client-side operation. |
Basketball | read | Official size basketball for indoor/outdoor use |
advanced_auth | read | Advanced authentication with MFA |
agentdb_attention_benchmark | read | Benchmark attention mechanism performance |
agentdb_attention_compute | read | Compute attention mechanism for query-key-value triplets |
agentdb_attention_configure | read | Configure attention mechanism parameters |
agentdb_attention_metrics | read | Get attention mechanism usage metrics and statistics |
agentdb_clear_cache | destructive | Clear query cache to refresh statistics and search results |
agentdb_delete | destructive | Delete vector(s) from AgentDB by ID or filters. Supports single ID deletion or bulk deletion with conditions. |
agentdb_delete_batch | destructive | Delete many episode/pattern rows by ID list in a single transaction. Faster and safer than looping |
agentdb_init | read | Initialize AgentDB database with schema and optimizations. Creates all required tables for vector storage, causal memory, skills, and provenance tracking. |
agentdb_insert | write | Insert a single vector with metadata into AgentDB. Automatically generates embeddings for the provided text. |
agentdb_insert_batch | write | Batch insert multiple vectors efficiently using transactions and parallel embedding generation. Optimized for large datasets. |
agentdb_pattern_search | read | Search patterns with taskEmbedding, k, threshold, and filters |
agentdb_pattern_stats | read | Get pattern statistics including total patterns, success rates, and top task types |
agentdb_pattern_store | read | Store reasoning pattern with embedding, taskType, approach, and successRate |
agentdb_pattern_store_batch | read | Batch store multiple reasoning patterns efficiently using transactions and parallel embedding generation. 4x faster than sequential agentdb_pattern_store calls. 🔄 PARALLEL-SAFE: Can be used alongside other batch operations. |
agentdb_search | read | Semantic k-NN vector search using cosine similarity. Returns the most relevant results ranked by similarity score. |
agentdb_stats | read | Get comprehensive database statistics including table counts, storage usage, and performance metrics |
api_request | read | Make authenticated API requests |
auth_skill | read | Authentication implementation |
authentication | read | User authentication with JWT |
basic_auth | read | Basic authentication |
cache_manager | read | Redis-based caching with TTL |
caching-skill | read | Implement caching strategies |
causal_add_edge | write | Add a causal relationship between actions and outcomes |
causal_query | read | Query causal effects to understand what actions cause what outcomes |
causal_traverse | read | Walk the causal graph between two memories. Returns the chain of causal links (with confidence and uplift) up to max_depth hops. Use this to answer |
complex_skill | read | Complex skill with nested types |
data_validation | read | Input data validation |
database_query | write | Execute SQL queries safely |
database_query_optimizer | read | Optimize database queries with batch loading |
db_stats | read | Get database statistics showing record counts |
error_handler | read | Comprehensive error handling middleware |
experience_record | read | Record tool execution as experience for reinforcement learning and experience replay |
extracted-pattern | read | Pattern from learning |
fast-skill | read | Fast execution skill |
fibonacci | read | Calculate fibonacci numbers |
hash_password | read | Secure password hashing with bcrypt |
high-success | read | High success rate skill |
jwt_auth | read | JWT authentication with tokens |
jwt_authentication | read | Generate and verify JWT tokens |
learner_discover | read | Automatically discover causal patterns from episode history |
learning_end_session | write | End an active learning session and save the final trained policy to the database. |
learning_explain | read | Explain action recommendations with confidence scores and supporting evidence from past experiences |
learning_feedback | write | Submit feedback on action quality to train the RL policy. Feedback includes reward signal and outcome state. |
learning_metrics | read | Get learning performance metrics including success rates, rewards, and policy improvement |
learning_predict | read | Get AI-recommended action for a given state with confidence scores and alternative actions. |
learning_start_session | write | Start a new reinforcement learning session with specified algorithm and configuration. Supports 9 RL algorithms: q-learning, sarsa, dqn, policy-gradient, actor-critic, ppo, decision-transformer, mcts, model-based. |
learning_train | read | Train the RL policy using batch learning with collected experiences. Returns training metrics including loss, average reward, and convergence rate. |
learning_transfer | write | Transfer learning between sessions or tasks, enabling knowledge reuse across different contexts |
metadata_test | read | Test metadata persistence |
migration-skill | read | Test skill for migration |
no_description | read | |
oauth2_login | read | OAuth2 login flow with PKCE |
optimization-skill | read | Optimize database queries |
recall_with_certificate | read | Retrieve memories with causal utility scoring and provenance certificate |
reflexion_retrieve | read | Retrieve relevant past episodes for learning from experience |
reflexion_store | read | Store an episode with self-critique for reflexion-based learning |
reflexion_store_batch | read | Batch store multiple episodes efficiently using transactions and parallel embedding generation. 3.3x faster than sequential reflexion_store calls (152 → 500 ops/sec). 🔄 PARALLEL-SAFE: Can be used alongside other batch operations. |
reward_signal | read | Calculate reward signal for outcomes based on success, efficiency, and causal impact |
simple_skill | read | A simple test skill |
skill-1 | read | First skill |
skill-2 | read | Second skill |
skill_create | write | Create a reusable skill in the skill library |
skill_create_batch | write | Batch create multiple skills efficiently using transactions and parallel embedding generation. 3x faster than sequential skill_create calls (304 → 900 ops/sec). 🔄 PARALLEL-SAFE: Can be used alongside other batch operations. |
skill_search | read | Search for applicable skills by semantic similarity |
stats-skill | read | Skill for stats testing |
tagged-pattern | read | Pattern with tags |
test-pattern | read | Test pattern storage |
test-skill | read | Test skill |
test_skill | read | Test skill |
test_update | write | Test skill update |
type_test | read | Type compatibility test |
unique-pattern | read | First pattern |
validation_schema | read | Request validation with Zod schemas |
Trust audit
BLOCKgrade F · trust 26/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (8 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
- eval() removal
exec(sql: string): void;
exec(sql: string) {exec(sql: string) {exec(sql: string): void;
jailbreak, PII masking, input sanitization, unicode filtering, rate
agentdb-browser-examples.zip
bun.lockb
score = Math.random() > 0.9 ? dotProduct(query, key) : 0;
score = Math.random() > 0.9 ? dotProductMCP(query, key) : 0;
console.log(` Auth Token: ${colors.cyan}${authToken.substring(0, 8)}...${colors.reset}`);console.log(` Token Count: ${features.tokenCount}`);logTest('Prevent UNION-based exfiltration', false, 'Attack payload accepted!');logTest('Prevent UNION-based exfiltration', true);logTest('Prevent UNION-based exfiltration', false, `Wrong error: ${error}`);forwardPassTargetUs: 500, // Sub-millisecond target (500μs)
p50LatencyUs: 500, // 500μs median latency
const coherenceTimeMs = gateDepth * 0.001; // 1μs per gate (optimistic)
console.log(`✅ Using Beam-5 (94.8% recall) + Dynamic-k (71μs latency)\n`);
- **Beam Width**: 5 (94.8% recall@10, 112μs latency)
token: "verification_token_from_email"
token: "reset_token_from_email",
token: "verification_token_from_email"
<p style="color: var(--text-secondary); margin-bottom: 1rem; font-size: 0.875rem;">
<button class="btn btn-secondary btn-sm" onclick="bulkDeletePatterns()" id="bulk-delete-btn" style="display: none;">🗑️ Delete Selected</button>
Gates applied: instruction_override, no_behavioural_pass.
85bed1bd0078full audit observations/trust-audit/mcp-server/ruvnet__agentdb.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 85bed1bd0078 | BLOCK | F | 26 | first audit |
Questions
What is the AgentDB MCP server?
Vector memory that gets smarter every time your agent uses it.
What tools does AgentDB expose?
76 in total: 62 read-only, 11 that write, and 3 that can delete or overwrite (agentdb_clear_cache, agentdb_delete, agentdb_delete_batch). Every one is listed on this page with its risk.
Is AgentDB safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (26/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does AgentDB need?
It reads AGENTDB_DEV_BYPASS_SECRET, ANTHROPIC_API_KEY, GOOGLE_GEMINI_API_KEY, HF_TOKEN, HUGGINGFACE_API_KEY, JWT_SECRET, MCP_API_KEY, MCP_SECRET, OPENAI_API_KEY, OPENROUTER_API_KEY and REFRESH_TOKEN_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does AgentDB run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as vite_react_shadcn_ts at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (85bed1bd0078), read on 2026-10-07. The repository is watched and re-audited when it changes.