Atlas / MCP servers / ryjoxtechnologies / Octopoda

OctopodaBLOCK

mcp/ryjoxtechnologies/octopoda

The open-source memory and observability layer for AI agents — persistent memory, loop detection, hash-chained audit trails, and a live dashboard, automatic on pip install.

Verdict
BLOCK
Grade
F
Trust score
42 /100
Exposed tools
30 24r · 5w · 1d
Transport
stdio
License
NOASSERTION
Stars
487
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🐙 Octopoda

The open-source memory and observability layer for AI agents. Persistent memory, loop detection, audit trails, and a live dashboard — automatic on pip install.

Website · Docs · Dashboard · Quick start · MCP server

Read from source at commit b692ff63e99cOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add octopoda --env AGENT_API_KEY=${AGENT_API_KEY} --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env JOE_KEY=${JOE_KEY} --env KEY_JOE=${KEY_JOE} -- uvx octopoda
claude-desktop
{
  "mcpServers": {
    "octopoda": {
      "command": "uvx",
      "args": [
        "octopoda"
      ],
      "env": {
        "AGENT_API_KEY": "${AGENT_API_KEY}",
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "JOE_KEY": "${JOE_KEY}",
        "KEY_JOE": "${KEY_JOE}"
      }
    }
  }
}
03

Exposed tools (30)

24 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
OctopodareadAI agent memory infrastructure with built-in loop detection across 10 stuck-pattern classifiers, shared memory between agents, and per-agent cost analysis.
octopoda_agent_statsreadGet performance statistics and analytics for an agent.
octopoda_broadcastreadBroadcast a message to all agents. Any agent can read broadcasts.
octopoda_consolidatewriteFind and optionally merge duplicate memories. Duplicates degrade
octopoda_forgetdestructiveExplicitly forget (delete) a specific memory. Use when a memory is
octopoda_forget_stalereadForget old memories to keep the agent
octopoda_get_contextreadGet relevant context from memory before generating a response.
octopoda_get_goalreadGet the current goal and progress for an agent.
octopoda_list_agentsreadList all registered agents in your Octopoda account.
octopoda_log_decisionreadLog an agent decision with full audit trail.
octopoda_loop_historyreadGet loop detection alert history for pattern analysis. Shows how
octopoda_loop_statusreadGet comprehensive loop detection status for an agent. Combines 5
octopoda_memory_healthreadCheck the health of an agent
octopoda_process_conversationreadProcess a conversation turn — automatically extracts and stores memories.
octopoda_read_messagesreadRead messages from an agent
octopoda_read_sharedreadRead from shared memory written by any agent.
octopoda_recallreadRetrieve a stored memory by key.
octopoda_recall_historyreadGet the full timeline of how a memory changed over time.
octopoda_recall_similarreadSearch an agent
octopoda_relatedreadQuery the knowledge graph for an entity and its connections.
octopoda_rememberreadStore a persistent memory for an AI agent. Memory is stored in the cloud and persists across sessions.
octopoda_restorereadRestore agent memory from a snapshot. Reverts to the saved state.
octopoda_searchreadSearch an agent
octopoda_search_filteredreadSearch memories with combined filters. All filters are AND-combined.
octopoda_send_messagewriteSend a message from one agent to another. Creates an inbox/outbox
octopoda_set_goalwriteSet a goal for an agent with optional milestones. Goals are tracked
octopoda_sharewriteWrite to shared memory that other agents can read.
octopoda_snapshotreadTake a snapshot (checkpoint) of all agent memory. Use before risky operations.
octopoda_statusreadOne-call diagnostic: is Octopoda actually working?
octopoda_update_progresswriteUpdate progress on an agent
04

Trust audit

BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (10 observation(s))
Shell
declared (9 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
octopoda_zf/active/sandbox.py:80
exec(code, self._safe_globals(), ns)  # noqa: S102 - sandboxed; see docstring
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
synrix_runtime/dashboard/static/assets/courseModules-COM931Z8.js:937
A calculator is the simplest possible tool that still demonstrates real agent behaviour. The LLM can't reliably do maths on its own. Ask GPT-4 to compute \`(47 * 83) + (156 / 12)\` and it might get it
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
synrix_runtime/dashboard/static/assets/courseModules-COM931Z8.js:962
result = eval(expression, {"__builtins__": {}}, allowed_names)\r
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
synrix_runtime/dashboard/static/assets/courseModules-COM931Z8.js:968
We're restricting \`eval()\` to a safe subset of functions. In production, you'd use a proper expression parser. For learning, this does the job.\r
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
synrix_runtime/dashboard/static/assets/courseModules-COM931Z8.js:1110
result = eval(expression, {"__builtins__": {}}, allowed_names)\r
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
synrix_runtime/dashboard/static/assets/anthropic-pentagon-DBbgekQy.avif
anthropic-pentagon-DBbgekQy.avif
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
octopoda/__init__.py:170
return getattr(importlib.import_module(mod), name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
octopoda_zf/active/sandbox.py:60
return __import__(name, *args, **kwargs)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
octopoda_zf/instrument/autogen_hook.py:88
mod = __import__(path, fromlist=["BaseGroupChat"])
MEDIUMInsecure crypto · crypto.weak_random · CWE-327, CWE-338
synrix_runtime/dashboard/static/assets/index-RsFqQstg.js:70
*/function ca(){return ca=Object.assign?Object.assign.bind():function(e){for(var t=1;t<arguments.length;t++){var n=arguments[t];for(var r in n)Object.prototype.hasOwnProperty.call(n,r)&&(e[r]=n[r])}re
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
synrix_runtime/auth_flow.py:257
print(f"  Login failed: {data.get('detail', 'Invalid email or password')}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
synrix_runtime/demo/openai_agents_demo.py:355
print(f"  [OK] OpenAI API key: {api_key[:8]}...{api_key[-4:]}")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
synrix_runtime/dashboard/static/assets/courseModules-COM931Z8.js:13544
Your agent has access to tools: database queries, API calls, file system operations, email sending. An attacker who can influence the agent's reasoning can redirect those tools. Instead of querying cu
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
synrix_runtime/dashboard/static/assets/courseModules-COM931Z8.js:14132
The key constraints here are: no network access (prevents data exfiltration), read-only filesystem (prevents persistent changes), memory and CPU limits (prevents resource exhaustion), and a timeout (p
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/integration/dashboard_smoke.py:152
urllib.request.urlopen(f"http://127.0.0.1:{LOCAL_PORT}/health", timeout=1).read()
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/integration/dashboard_smoke.py:157
results.append(run_target("local (pip install)", f"http://127.0.0.1:{LOCAL_PORT}"))
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/integration/local_dashboard_smoke.py:85
code, body, _ = fetch(f"http://127.0.0.1:{DASH_PORT}/")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/integration/local_dashboard_smoke.py:108
code, html, _ = fetch(f"http://127.0.0.1:{DASH_PORT}/")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/integration/local_dashboard_smoke.py:136
url = f"http://127.0.0.1:{DASH_PORT}{ref}"
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
synrix/direct_client.py:136
time.sleep(0.0001)  # 100μs
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
synrix/direct_client.py:164
time.sleep(0.00001)  # 10μs after initial busy-wait
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
synrix_runtime/dashboard/static/assets/NewLanding-Bf-4IBxi.js:290
<div style="display:grid;grid-template-columns:110px 1fr 90px;gap:12px;align-items:center"><span style="color:oklch(0.8 0.14 55)">Write p50</span><div style="height:6px;border-radius:3px;background:rg
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
synrix_runtime/dashboard/static/assets/NewLanding-Bf-4IBxi.js:291
<div style="display:grid;grid-template-columns:110px 1fr 90px;gap:12px;align-items:center"><span style="color:oklch(0.8 0.14 55)">Read p50</span><div style="height:6px;border-radius:3px;background:rgb
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
synrix_runtime/dashboard/static/assets/Resources-9PNgzvs2.js:1
import{aN as e,aU as m}from"./index-RsFqQstg.js";import{N as h,F as p}from"./Footer-Bckgcb7L.js";import{m as s}from"./proxy-DETd9jo6.js";import{R as l}from"./ResponsiveContainer-DQ_nfUjb.js";import{B 
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
synrix_runtime/dashboard/static/assets/courseModules-COM931Z8.js:3408
api_key="your-octopoda-api-key",\r

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha b692ff63e99cfull audit observations/trust-audit/mcp-server/ryjoxtechnologies__octopoda.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-30b692ff63e99cBLOCKF42first audit
06

Questions

What is the Octopoda MCP server?

The open-source memory and observability layer for AI agents — persistent memory, loop detection, hash-chained audit trails, and a live dashboard, automatic on pip install.

What tools does Octopoda expose?

30 in total: 24 read-only, 5 that write, and 1 that can delete or overwrite (octopoda_forget). Every one is listed on this page with its risk.

Is Octopoda safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (42/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Octopoda need?

It reads AGENT_API_KEY, ANTHROPIC_API_KEY, JOE_KEY, KEY_JOE, KEY_NEW, OCTOPODA_ADMIN_KEY, OCTOPODA_ANTHROPIC_API_KEY, OCTOPODA_API_KEY, OCTOPODA_ENCRYPTION_KEY, OCTOPODA_LICENSE_KEY, OCTOPODA_OPENAI_API_KEY and OCTOPODA_PLATFORM_OPENAI_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Octopoda run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as octopoda.

How current is this page?

The grade is for one exact copy of the source (b692ff63e99c), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement