Shodh-MemoryBLOCK
Local, LLM-free memory for AI agents. A single offline Rust binary — deterministic and auditable — that learns from use, forgets the irrelevant, and strengthens what matters. No cloud, no API keys.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Shodh-Memory
Persistent cognitive memory for AI agents and robots — with no LLM in the loop. Remembers what matters, forgets what doesn't, gets smarter with use.
fda2ad7f58a3OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add memory-mcp --env SHODH_API_KEY=${SHODH_API_KEY} -- npx -y @shodh/[email protected]Exposed tools (67)
47 read · 12 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_causal_link | write | Record an explicit causal edge between two memories. from_memory_id is the cause/origin (the earlier event), to_memory_id is the effect (the later one); the relation reads from→to, e.g. relation=Caused means |
add_project | write | Create a new project to group todos. Use parent to create a sub-project under another project. |
add_todo | write | Add a task to your todo list. Supports GTD workflow with projects, contexts (@computer, @phone), priorities, due dates, and subtasks (via parent_id). |
add_todo_comment | write | Add a comment to a todo. Use to track progress, notes, or resolution details. |
archive_project | read | Archive a project. Archived projects are hidden by default but can be restored. |
backup_create | write | Create a backup of all memories. Returns backup metadata including ID, size, and checksum. Backups are stored locally and can be restored later. |
backup_list | read | List all available backups for this user. Returns backup history with IDs, timestamps, and sizes. |
backup_purge | destructive | Purge old backups, keeping only the most recent N. Useful for managing disk space. |
backup_restore | read | Restore a previously created backup by ID. Destructive: replaces this user |
backup_verify | read | Verify backup integrity using SHA-256 checksum. Use to check if a backup is corrupted before restoring. |
complete_todo | read | Mark a todo as complete. For recurring tasks, automatically creates the next occurrence. |
consolidation_report | read | Get a report of what the memory system has been learning. Shows memory strengthening/decay events, edge formation, fact extraction, and maintenance cycles. Use this to understand how your memories are evolving. |
context_summary | read | Get a condensed summary of recent learnings, decisions, and context. Use this at the start of a session to quickly understand what you |
count | read | Number of memories (default: 10) |
delete_project | destructive | Permanently delete a project. Use delete_todos=true to also delete all todos in the project. |
delete_todo | destructive | Delete a todo permanently. |
delete_todo_comment | destructive | Delete a comment from a todo. |
dismiss_reminder | read | Dismiss/acknowledge a triggered reminder. Call this after you |
fact_narratives | read | Get synthesized narratives from accumulated facts, clustered by topic with confidence levels and causal chains. Shows what the system has learned, organized into coherent themes. |
forget | destructive | Delete a specific memory by ID |
list_anomalies | read | Rank recent memories by statistical deviation from this user |
list_documents | write | List the documents in the corpus, with sizes. Start here: it tells you what is available |
list_entities | read | List the entities in the knowledge graph, ranked by salience (learned importance), with their types and mention counts. Use to discover what people, systems, places, and concepts the graph tracks — or to find the exact name to pass to explore_entity. For memory contents use recall; this is the graph |
list_memories | read | List all stored memories |
list_projects | read | List all projects with todo counts and status breakdown. |
list_reminders | read | List all pending reminders. Use to check what reminders are scheduled. |
list_subtasks | write | List subtasks of a parent todo. Use add_todo with parent_id to create subtasks. |
list_todo_comments | read | List all comments and activity history for a specific todo. |
list_todos | read | List or search todos. Supports semantic search via query parameter, or GTD-style filtering. Returns Linear-style formatted output grouped by status. |
memory_health | read | Check memory system status and statistics |
memory_stats | read | Get statistics about stored memories |
pending_work | read | Show todos and incomplete tasks |
proactive_context | read | REQUIRED: Call this tool with EVERY user message to surface relevant memories and build conversation history. Pass the user |
purge_facts | destructive | Delete facts matching a content pattern. Use dry_run=true to preview before deleting. Useful for cleaning up garbage facts (e.g., |
query | read | What to search for in memories |
quick_recall | read | Search your memories for relevant context |
read_document | read | Read one text document from the corpus. Returns the head of very large files with a note |
read_memory | read | Read the FULL content of a specific memory by ID. Use this when you need to see the complete text of a memory that was truncated in search results. |
recall | read | Search memories AND todos using semantic similarity. Returns both relevant memories and matching todos. Use this to find past experiences, decisions, context, or pending work. Modes: |
recall_by_tags | read | Find memories by tags. Returns memories matching ANY of the provided tags. Useful for finding memories by category (e.g., |
recent_memories | read | Show recently created memories |
reinforce_memories | read | Give Hebbian feedback on memories after using them: outcome |
remember | read | Store a memory for future recall. Use this to remember important information, decisions, user preferences, project context, or anything you want to recall later. |
reorder_todo | write | Move a todo up or down within its status group. Use to prioritize tasks manually. |
repair_index | read | Repair vector index by re-indexing orphaned memories. Use this when verify_index shows unhealthy status. Returns count of repaired memories. |
reset_token_session | destructive | Reset the token counter for a new session. Call this when starting a new conversation or after context has been compressed/summarized. |
search_documents | read | Find which documents contain a string, with the matching lines. Use before read_document |
session_digest | read | Get a consolidated digest of the current session: timestamps, token usage, memories created/recalled, tools used with counts, entities extracted, topic changes, and consolidation events. Use after context compression or at session milestones. |
session_history | read | Show what you worked on across recent sessions. Returns session summaries with entities, memory stats, and timestamps. Use group_by_project to detect cross-session project continuity via entity overlap. |
session_summary | read | Get a summary of recent learnings, decisions, and context |
set_reminder | write | Set a reminder for the future. Triggers on time (at specific time or after duration) or context match (when keywords appear in conversation). Reminders will surface automatically when conditions are met. |
shodh_add_todo | write | Create a task/todo with optional project, priority, contexts, and due date. Follows GTD methodology. |
shodh_complete_todo | read | Mark a task as complete. For recurring tasks, automatically creates the next occurrence. |
shodh_context_summary | read | Get a condensed summary of recent decisions, learnings, and project context from memory. |
shodh_forget | destructive | Delete a specific memory by its ID. Use when information is outdated or incorrect. |
shodh_list_todos | read | List tasks/todos filtered by status and project. Returns tasks with IDs, priorities, and status. |
shodh_proactive_context | read | Surface memories relevant to the current conversation context. Uses entity matching and semantic similarity. |
shodh_recall | read | Search persistent memory using natural language. Returns semantically similar memories ranked by relevance. |
shodh_remember | read | Store a memory that persists across sessions. Use for important facts, decisions, user preferences, or learnings. |
todo_stats | read | Get statistics about your todos - counts by status, overdue items, etc. |
token_status | read | Get MCP pipeline token throughput for this session. Tracks tokens flowing through shodh memory tools only — NOT the AI context window. Use for internal diagnostics, not context window health. |
topic | read | The topic to explore |
update_todo | write | Update a todo |
update_todo_comment | write | Update an existing comment on a todo. |
validate_causal_link | read | Confirm or reject a causal edge by its edge ID (shown by trace_lineage and list_causal_edges). Confirming an inferred edge raises it to full confidence and strengthens the knowledge-graph connections between the two memories |
verify_index | read | Verify vector index integrity - diagnose orphaned memories that are stored but not searchable. Returns health status and count of orphaned memories. |
what_i_know | read | Surface everything related to a topic |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const PREFIXES: &[&str] = &["id_rsa", "id_ed25519", "id_ecdsa", "id_dsa", ".env"];
".netrc",
"authorized_keys",
"id_rsa",
"id_ed25519.pub",
useBilling.ts
policy.ts
"Vanguard", "Beacon", "Cipher", "Vector", "Warden", "Lattice", "Sentinel", "Cordon", "Bastion",
"the Beacon network outage",
API_URL="${SHODH_API_URL:-http://127.0.0.1:3030}"let secret = "webhook-signing-secret-for-linear-integration";
let secret = "webhook-signing-secret-for-github-integration";
let secret = "webhook-signing-secret";
let secret = "webhook-signing-secret";
let secret = "webhook-signing-secret";
REQUIRED: Call this tool with EVERY user message to surface relevant memories and build conversation history.
backup_purge, delete_project, delete_todo, delete_todo_comment, forget, purge_facts, reset_token_session, shodh_forget
.graphon_run
.locomo_run_id
# Chain: recall-eval (SHODH_DUMP_CONTEXT) exports exactly the top-k retrieved
def split(r): return int(hashlib.md5(r['case_id'].encode()).hexdigest(), 16) % 10 < 7
data.sort(key=lambda q: hashlib.md5(q["question_id"].encode()).hexdigest())
h = int(hashlib.sha1(q["case_id"].encode()).hexdigest(), 16) % 100
cargo_target = Path("../../target/release") / binary_namepost_json("/api/integrity/scrub", &json!({ "user_id": "../../etc" })),Gates applied: no_behavioural_pass.
fda2ad7f58a3full audit observations/trust-audit/mcp-server/varun29ankus__shodh-memory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | fda2ad7f58a3 | BLOCK | F | 54 | first audit |
Questions
What is the Shodh-Memory MCP server?
Local, LLM-free memory for AI agents. A single offline Rust binary — deterministic and auditable — that learns from use, forgets the irrelevant, and strengthens what matters. No cloud, no API keys.
What tools does Shodh-Memory expose?
67 in total: 47 read-only, 12 that write, and 8 that can delete or overwrite (backup_purge, delete_project, delete_todo, delete_todo_comment, forget). Every one is listed on this page with its risk.
Is Shodh-Memory safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Shodh-Memory need?
It reads ANTHROPIC_API_KEY, API_KEY, BASETEN_API_KEY, OPENAI_API_KEY, SHODH_API_KEY, SHODH_API_KEYS, SHODH_DEV_API_KEY, SHODH_JUDGE_MAX_TOKENS, SHODH_SEAT_TOKEN and SHODH_TOKEN_BUDGET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Shodh-Memory run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @shodh/seat-harness at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (fda2ad7f58a3), read on 2026-10-06. The repository is watched and re-audited when it changes.