IJFWBLOCK
IJFW — It Just F*cking Works. Ferrox Labs' local-first infrastructure for AI coding agents: shared memory, smart routing, multi-AI cross-audits, disciplined workflow.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
<img src="docs/guide/assets/ferrox-hero.png" alt="Ferrox Labs' IJFW (It Just F*cking Works): local-first infrastructure for AI coding agents, shown as eight engines: shared memory (cross-session recall), workflow discipline (plan, gate, execute), cross-audit (multi-model review), specialist bench (skills on demand), token savings (smarter routing), observability (local dashboard), learns you (adapts from edits), and design contract (one design system). Runs under Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, OpenCode, Qwen, Kimi, OpenClaw, Aider, and more." width="100%"/>
Your AI tools are brilliant, forgetful, undisciplined, and alone. One install fixes all four.
IJFW is one shared brain, and a full operating layer, for every AI coding tool you use. Install it once and your tools remember across sessions, plan before they build, check each other's work for hallucinations, pull in the right specialist for the job, and quietly cut your token bill. All on your machine. All yours.
npm install -g @ijfw/install && ijfw-install
08fb41baee56OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add express-api-server --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} --env FIGMA_TOKEN=${FIGMA_TOKEN} --env IJFW_AUTOLINK_API_KEY=${IJFW_AUTOLINK_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"express-api-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}",
"FIGMA_TOKEN": "${FIGMA_TOKEN}",
"IJFW_AUTOLINK_API_KEY": "${IJFW_AUTOLINK_API_KEY}"
}
}
}
}Exposed tools (9)
7 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ijfw_brain | read | IJFW Brain — query, links, wiki, conflict-resolve in one combined tool. verb= |
ijfw_cross_project_search | read | BM25-ranked search across every IJFW project ever opened on this machine. Results tagged [project:<basename>] with line numbers + snippets. Use when you need to recall how a similar problem was solved in another project. Reads ~/.ijfw/registry.md as the source of truth. |
ijfw_memory_facts | read | Query the bi-temporal facts table (subject/predicate/object timeline with valid_from / valid_to). Default: current-valid rows only. Pass history=true for full timeline; pass valid_at=<ISO-8601> for point-in-time. Subject + predicate are required. |
ijfw_memory_prelude | write | CALL THIS AT SESSION START. Returns all relevant project memory in one pass -- knowledge base, handoff state, recent activity. Eliminates the need to grep/search/recall separately. Call once at the start of a session before answering the user. |
ijfw_memory_search | read | Keyword search across memory sources. Up to 20 results. Scope defaults to current project; pass scope: |
ijfw_memory_store | read | Persist a decision, observation, or session state so it survives context resets. For decisions and patterns, add summary/why/how_to_apply for a richer knowledge-base entry. Returns isError on storage failure. |
ijfw_metrics | read | See tokens/spend, model routing mix, and session totals -- the receipts behind your IJFW sessions. Aggregates from .ijfw/metrics/sessions.jsonl. Tolerates mixed v1/v2 lines. |
ijfw_prompt_check | read | Call on the first turn when the user prompt is short (<30 tokens) or likely vague. Returns whether the prompt is under-specified and a sharpening suggestion. Deterministic regex detector -- no LLM call. Use for Codex/Cursor/Windsurf/Copilot/Gemini where pre-prompt hooks are not available. |
ijfw_update_check | write | Check if an IJFW update is available. Issues a confirmation token; the user must run |
Trust audit
BLOCKgrade F · trust 33/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (15 observation(s))
- Network
- declared (13 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const out = redactSecrets('claude sk-ant-api03-ABCDEFGHIJKLMNOPQRSTUVWXYZ');const out = redactSecrets('GH ghp_abcdefghijklmnopqrstuvwxyz0123456789');const out = redactSecrets('token: github_pat_11ABCDEFGHIJKLMNO_abcdefghijklmn');const pem = '-----BEGIN PRIVATE KEY-----\nMIIEvQIBADANBgkqhkiG9w0BAQEFAASC...\n-----END PRIVATE KEY-----';
const out = redactSecrets('slack=xoxb-1234567890-abcdefghij');'src/auth/login.js loaded; sk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZ123456 ' + // gitleaks:allow -- synthetic redactor fixture
const stripe = classify('sk_live_ABCDEFGHIJKLMNOPQRSTUVWXYZ123456'); // gitleaks:allow -- synthetic redactor fixtureconst STRIPE_LIVE = 'sk_live_TESTABC123DEFGHIJKLMNOPQRSTUVWXYZ';
const SECRET = 'sk_live_TESTABC123DEFGHIJKLMNOPQRSTUVWXYZ'; // gitleaks:allow -- synthetic fixture proving the scrub gate
const r = classifyAnchored('sk_live_abcdefghijklmnopqrstuvwxyz123456');5. **V155-017 (v1.5.5):** `ijfw_update_apply` was retired from the MCP tool surface — it was redundant given that `ijfw_update_check` already writes the sentinel + issues the token in one step. If an
const f = Function('return 1+1');const env = Function('return process.env')();note: 'Different training lineage; fast on review tasks. The - flag reads prompt from stdin. --skip-git-repo-check bypasses the trusted-directory gate added in codex-cli 0.118.0. --sandbox read-only b
'.npmrc', '.pypirc', '.netrc', '.gitconfig', '.gitconfig.local',
{ name: 'fake-ssh-id_rsa', body: 'CANARY-SSH-PRIVATE-KEY-DO-NOT-USE' },{ name: '~/.ssh subpath', path: join(home, '.ssh') },{ name: '~/.aws subpath', path: join(home, '.aws') },assert.equal(archives.length, 0, 'no in-tree gz archive of the exfiltrated bytes');
await writeFile(targetFile, JSON.stringify({ verdict: 'FAIL', affected_artifacts: [{ type: 'EXFIL' }] }), 'utf8');assert.ok(!types.includes('EXFIL'), 'symlinked target body must not leak into results');const url = 'http://127.0.0.1:' + port;
console.log('[ijfw] Dashboard running at http://127.0.0.1:' + port);const res = await fetch(`http://127.0.0.1:${port}${path}`);const base = `http://127.0.0.1:${port}`;Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
08fb41baee56full audit observations/trust-audit/mcp-server/therealseandonahoe__ijfw.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 08fb41baee56 | BLOCK | F | 33 | first audit |
Questions
What is the IJFW MCP server?
IJFW — It Just F*cking Works. Ferrox Labs' local-first infrastructure for AI coding agents: shared memory, smart routing, multi-AI cross-audits, disciplined workflow.
What tools does IJFW expose?
9 in total: 7 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is IJFW safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (33/100) and found 18 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does IJFW need?
It reads ANTHROPIC_API_KEY, AWS_SECRET_ACCESS_KEY, FIGMA_TOKEN, IJFW_AUTOLINK_API_KEY, IJFW_CTX_WINDOW_TOKENS, IJFW_STATE_GATE_BYPASS, JWT_SECRET, SSH_AUTH_SOCK and TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (08fb41baee56), read on 2026-10-06. The repository is watched and re-audited when it changes.