PondCAUTION
Lossless storage and search for AI agent sessions, across every agentic client.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/tenequm/pond/actions/workflows/ci.yml) [](https://crates.io/crates/pond-db) [](https://pond.locker/) [](LICENSE)
"I know we discussed that before. Why can't I find that damn conversation?"
Pond makes every AI agent session you've ever run - Claude Code, Codex, any tool, any machine - searchable in one place.
Your agent history is already on your disk: thousands of sessions full of decisions, fixes, and dead ends - scattered across tools that can't search them. Pond ingests them all automatically and losslessly into storage you own (a local dir or your own S3 bucket), makes the whole corpus searchable and SQL-queryable, and hands that recall back to your agents over MCP - so "how did we fix this before?" is a query, not an archaeology dig. Sessions stop being locked to the tool that created them: any session can be restored into any supported client and continued there.
brew install tenequm/tap/pond # macOS / Linux scoop bucket add tenequm https://github.com/tenequm/scoop-bucket # Windows scoop install tenequm/pond
Or prompt your agent: "Please install and set up pond (see github.com/tenequm/pond)" - the full, failure-proofed version of that prompt is in Connect your agents.
A live 12k-session corpus, then a thr
a6596d4c862aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add pi-pond -- npx -y [email protected]
{
"mcpServers": {
"pi-pond": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Pond | read | Durable, lossless recall over past agent sessions via read-only pond tools. |
Trust audit
CAUTIONgrade D · trust 69/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
{"cwd":"/Users/user/Projects/myproject-a","isSidechain":false,"message":{"content":[{"text":"# AGENTS.md instructions for /Users/user/Projects/myproject-a\n\n<INSTRUCTIONS>\n## Skills\nA skill is a selet plain = StorageUrl::parse("s3+http://127.0.0.1:9000/pond").unwrap();7337857a-125f-4db6-ab8e-9d70c9f1115f.db
85732767-bcd9-46ac-8e31-08d986363857.db
884ff681-7470-411c-a581-b5faa1f0fb57.db
conversation_summaries.db
07439cf3-11de-46cd-ae53-730229b38bac.db
.envrc
.audit-key
.claude.json
.last-cleanup
.claude.json.backup.1778766138995
payload-auto-yx1ua6.json
docs/site/public/spec.md
const run = exec(
exec: exec(
exec: exec(
exec: exec(
exec: exec(
import type { AgentToolResult } from "../../../../src/tools.js";{ "mode": "url", "url": "http://127.0.0.1:9797/mcp" }url: "http://127.0.0.1:9797/mcp",
expect(config).toMatchObject({ mode: "url", url: "http://127.0.0.1:9797/mcp" });const config = parsePondConfig({ mode: "url", url: "http://127.0.0.1:9797/mcp" });{"parentUuid":"431d1daf-06f5-4e2c-a01a-6b3fbf4568a3","isSidechain":false,"message":{"model":"claude-opus-4-7","id":"msg_01EBYs4jMCAhcSTs91xXwdaX","type":"message","role":"assistant","content":[{"type"Gates applied: no_behavioural_pass.
a6596d4c862afull audit observations/trust-audit/mcp-server/tenequm__pond.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | a6596d4c862a | CAUTION | D | 69 | first audit |
Questions
What is the Pond MCP server?
Lossless storage and search for AI agent sessions, across every agentic client.
What tools does Pond expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Pond safe to connect to an agent?
With care. The audit graded it D (69/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Pond need?
No credential environment variables were found in its source, so it appears to need none.
How does Pond run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as pi-pond at 0.3.0.
How current is this page?
The grade is for one exact copy of the source (a6596d4c862a), read on 2026-10-08. The repository is watched and re-audited when it changes.