OctopodaBLOCK
The open-source memory and observability layer for AI agents — persistent memory, loop detection, hash-chained audit trails, and a live dashboard, automatic on pip install.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
🐙 Octopoda
The open-source memory and observability layer for AI agents. Persistent memory, loop detection, audit trails, and a live dashboard — automatic on pip install.
Website · Docs · Dashboard · Quick start · MCP server
b692ff63e99cOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add octopoda --env AGENT_API_KEY=${AGENT_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env JOE_KEY=${JOE_KEY} --env KEY_JOE=${KEY_JOE} -- uvx octopoda{
"mcpServers": {
"octopoda": {
"command": "uvx",
"args": [
"octopoda"
],
"env": {
"AGENT_API_KEY": "${AGENT_API_KEY}",
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"JOE_KEY": "${JOE_KEY}",
"KEY_JOE": "${KEY_JOE}"
}
}
}
}Exposed tools (30)
24 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Octopoda | read | AI agent memory infrastructure with built-in loop detection across 10 stuck-pattern classifiers, shared memory between agents, and per-agent cost analysis. |
octopoda_agent_stats | read | Get performance statistics and analytics for an agent. |
octopoda_broadcast | read | Broadcast a message to all agents. Any agent can read broadcasts. |
octopoda_consolidate | write | Find and optionally merge duplicate memories. Duplicates degrade |
octopoda_forget | destructive | Explicitly forget (delete) a specific memory. Use when a memory is |
octopoda_forget_stale | read | Forget old memories to keep the agent |
octopoda_get_context | read | Get relevant context from memory before generating a response. |
octopoda_get_goal | read | Get the current goal and progress for an agent. |
octopoda_list_agents | read | List all registered agents in your Octopoda account. |
octopoda_log_decision | read | Log an agent decision with full audit trail. |
octopoda_loop_history | read | Get loop detection alert history for pattern analysis. Shows how |
octopoda_loop_status | read | Get comprehensive loop detection status for an agent. Combines 5 |
octopoda_memory_health | read | Check the health of an agent |
octopoda_process_conversation | read | Process a conversation turn — automatically extracts and stores memories. |
octopoda_read_messages | read | Read messages from an agent |
octopoda_read_shared | read | Read from shared memory written by any agent. |
octopoda_recall | read | Retrieve a stored memory by key. |
octopoda_recall_history | read | Get the full timeline of how a memory changed over time. |
octopoda_recall_similar | read | Search an agent |
octopoda_related | read | Query the knowledge graph for an entity and its connections. |
octopoda_remember | read | Store a persistent memory for an AI agent. Memory is stored in the cloud and persists across sessions. |
octopoda_restore | read | Restore agent memory from a snapshot. Reverts to the saved state. |
octopoda_search | read | Search an agent |
octopoda_search_filtered | read | Search memories with combined filters. All filters are AND-combined. |
octopoda_send_message | write | Send a message from one agent to another. Creates an inbox/outbox |
octopoda_set_goal | write | Set a goal for an agent with optional milestones. Goals are tracked |
octopoda_share | write | Write to shared memory that other agents can read. |
octopoda_snapshot | read | Take a snapshot (checkpoint) of all agent memory. Use before risky operations. |
octopoda_status | read | One-call diagnostic: is Octopoda actually working? |
octopoda_update_progress | write | Update progress on an agent |
Trust audit
BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (9 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
exec(code, self._safe_globals(), ns) # noqa: S102 - sandboxed; see docstring
A calculator is the simplest possible tool that still demonstrates real agent behaviour. The LLM can't reliably do maths on its own. Ask GPT-4 to compute \`(47 * 83) + (156 / 12)\` and it might get it
result = eval(expression, {"__builtins__": {}}, allowed_names)\rWe're restricting \`eval()\` to a safe subset of functions. In production, you'd use a proper expression parser. For learning, this does the job.\r
result = eval(expression, {"__builtins__": {}}, allowed_names)\ranthropic-pentagon-DBbgekQy.avif
return getattr(importlib.import_module(mod), name)
return __import__(name, *args, **kwargs)
mod = __import__(path, fromlist=["BaseGroupChat"])
*/function ca(){return ca=Object.assign?Object.assign.bind():function(e){for(var t=1;t<arguments.length;t++){var n=arguments[t];for(var r in n)Object.prototype.hasOwnProperty.call(n,r)&&(e[r]=n[r])}reprint(f" Login failed: {data.get('detail', 'Invalid email or password')}")print(f" [OK] OpenAI API key: {api_key[:8]}...{api_key[-4:]}")Your agent has access to tools: database queries, API calls, file system operations, email sending. An attacker who can influence the agent's reasoning can redirect those tools. Instead of querying cu
The key constraints here are: no network access (prevents data exfiltration), read-only filesystem (prevents persistent changes), memory and CPU limits (prevents resource exhaustion), and a timeout (p
urllib.request.urlopen(f"http://127.0.0.1:{LOCAL_PORT}/health", timeout=1).read()results.append(run_target("local (pip install)", f"http://127.0.0.1:{LOCAL_PORT}"))code, body, _ = fetch(f"http://127.0.0.1:{DASH_PORT}/")code, html, _ = fetch(f"http://127.0.0.1:{DASH_PORT}/")url = f"http://127.0.0.1:{DASH_PORT}{ref}"time.sleep(0.0001) # 100μs
time.sleep(0.00001) # 10μs after initial busy-wait
<div style="display:grid;grid-template-columns:110px 1fr 90px;gap:12px;align-items:center"><span style="color:oklch(0.8 0.14 55)">Write p50</span><div style="height:6px;border-radius:3px;background:rg
<div style="display:grid;grid-template-columns:110px 1fr 90px;gap:12px;align-items:center"><span style="color:oklch(0.8 0.14 55)">Read p50</span><div style="height:6px;border-radius:3px;background:rgb
import{aN as e,aU as m}from"./index-RsFqQstg.js";import{N as h,F as p}from"./Footer-Bckgcb7L.js";import{m as s}from"./proxy-DETd9jo6.js";import{R as l}from"./ResponsiveContainer-DQ_nfUjb.js";import{B api_key="your-octopoda-api-key",\r
Gates applied: no_behavioural_pass.
b692ff63e99cfull audit observations/trust-audit/mcp-server/ryjoxtechnologies__octopoda.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | b692ff63e99c | BLOCK | F | 42 | first audit |
Questions
What is the Octopoda MCP server?
The open-source memory and observability layer for AI agents — persistent memory, loop detection, hash-chained audit trails, and a live dashboard, automatic on pip install.
What tools does Octopoda expose?
30 in total: 24 read-only, 5 that write, and 1 that can delete or overwrite (octopoda_forget). Every one is listed on this page with its risk.
Is Octopoda safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (42/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Octopoda need?
It reads AGENT_API_KEY, ANTHROPIC_API_KEY, JOE_KEY, KEY_JOE, KEY_NEW, OCTOPODA_ADMIN_KEY, OCTOPODA_ANTHROPIC_API_KEY, OCTOPODA_API_KEY, OCTOPODA_ENCRYPTION_KEY, OCTOPODA_LICENSE_KEY, OCTOPODA_OPENAI_API_KEY and OCTOPODA_PLATFORM_OPENAI_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Octopoda run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as octopoda.
How current is this page?
The grade is for one exact copy of the source (b692ff63e99c), read on 2026-09-30. The repository is watched and re-audited when it changes.