Atlas / MCP servers / varun29ankus / Shodh-Memory

Shodh-MemoryBLOCK

mcp/varun29ankus/shodh-memory

Local, LLM-free memory for AI agents. A single offline Rust binary — deterministic and auditable — that learns from use, forgets the irrelevant, and strengthens what matters. No cloud, no API keys.

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
67 47r · 12w · 8d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
301
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Shodh-Memory

Persistent cognitive memory for AI agents and robots — with no LLM in the loop. Remembers what matters, forgets what doesn't, gets smarter with use.

Read from source at commit fda2ad7f58a3OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add memory-mcp --env SHODH_API_KEY=${SHODH_API_KEY} -- npx -y @shodh/[email protected]
03

Exposed tools (67)

47 read · 12 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_causal_linkwriteRecord an explicit causal edge between two memories. from_memory_id is the cause/origin (the earlier event), to_memory_id is the effect (the later one); the relation reads from→to, e.g. relation=Caused means
add_projectwriteCreate a new project to group todos. Use parent to create a sub-project under another project.
add_todowriteAdd a task to your todo list. Supports GTD workflow with projects, contexts (@computer, @phone), priorities, due dates, and subtasks (via parent_id).
add_todo_commentwriteAdd a comment to a todo. Use to track progress, notes, or resolution details.
archive_projectreadArchive a project. Archived projects are hidden by default but can be restored.
backup_createwriteCreate a backup of all memories. Returns backup metadata including ID, size, and checksum. Backups are stored locally and can be restored later.
backup_listreadList all available backups for this user. Returns backup history with IDs, timestamps, and sizes.
backup_purgedestructivePurge old backups, keeping only the most recent N. Useful for managing disk space.
backup_restorereadRestore a previously created backup by ID. Destructive: replaces this user
backup_verifyreadVerify backup integrity using SHA-256 checksum. Use to check if a backup is corrupted before restoring.
complete_todoreadMark a todo as complete. For recurring tasks, automatically creates the next occurrence.
consolidation_reportreadGet a report of what the memory system has been learning. Shows memory strengthening/decay events, edge formation, fact extraction, and maintenance cycles. Use this to understand how your memories are evolving.
context_summaryreadGet a condensed summary of recent learnings, decisions, and context. Use this at the start of a session to quickly understand what you
countreadNumber of memories (default: 10)
delete_projectdestructivePermanently delete a project. Use delete_todos=true to also delete all todos in the project.
delete_tododestructiveDelete a todo permanently.
delete_todo_commentdestructiveDelete a comment from a todo.
dismiss_reminderreadDismiss/acknowledge a triggered reminder. Call this after you
fact_narrativesreadGet synthesized narratives from accumulated facts, clustered by topic with confidence levels and causal chains. Shows what the system has learned, organized into coherent themes.
forgetdestructiveDelete a specific memory by ID
list_anomaliesreadRank recent memories by statistical deviation from this user
list_documentswriteList the documents in the corpus, with sizes. Start here: it tells you what is available
list_entitiesreadList the entities in the knowledge graph, ranked by salience (learned importance), with their types and mention counts. Use to discover what people, systems, places, and concepts the graph tracks — or to find the exact name to pass to explore_entity. For memory contents use recall; this is the graph
list_memoriesreadList all stored memories
list_projectsreadList all projects with todo counts and status breakdown.
list_remindersreadList all pending reminders. Use to check what reminders are scheduled.
list_subtaskswriteList subtasks of a parent todo. Use add_todo with parent_id to create subtasks.
list_todo_commentsreadList all comments and activity history for a specific todo.
list_todosreadList or search todos. Supports semantic search via query parameter, or GTD-style filtering. Returns Linear-style formatted output grouped by status.
memory_healthreadCheck memory system status and statistics
memory_statsreadGet statistics about stored memories
pending_workreadShow todos and incomplete tasks
proactive_contextreadREQUIRED: Call this tool with EVERY user message to surface relevant memories and build conversation history. Pass the user
purge_factsdestructiveDelete facts matching a content pattern. Use dry_run=true to preview before deleting. Useful for cleaning up garbage facts (e.g.,
queryreadWhat to search for in memories
quick_recallreadSearch your memories for relevant context
read_documentreadRead one text document from the corpus. Returns the head of very large files with a note
read_memoryreadRead the FULL content of a specific memory by ID. Use this when you need to see the complete text of a memory that was truncated in search results.
recallreadSearch memories AND todos using semantic similarity. Returns both relevant memories and matching todos. Use this to find past experiences, decisions, context, or pending work. Modes:
recall_by_tagsreadFind memories by tags. Returns memories matching ANY of the provided tags. Useful for finding memories by category (e.g.,
recent_memoriesreadShow recently created memories
reinforce_memoriesreadGive Hebbian feedback on memories after using them: outcome
rememberreadStore a memory for future recall. Use this to remember important information, decisions, user preferences, project context, or anything you want to recall later.
reorder_todowriteMove a todo up or down within its status group. Use to prioritize tasks manually.
repair_indexreadRepair vector index by re-indexing orphaned memories. Use this when verify_index shows unhealthy status. Returns count of repaired memories.
reset_token_sessiondestructiveReset the token counter for a new session. Call this when starting a new conversation or after context has been compressed/summarized.
search_documentsreadFind which documents contain a string, with the matching lines. Use before read_document
session_digestreadGet a consolidated digest of the current session: timestamps, token usage, memories created/recalled, tools used with counts, entities extracted, topic changes, and consolidation events. Use after context compression or at session milestones.
session_historyreadShow what you worked on across recent sessions. Returns session summaries with entities, memory stats, and timestamps. Use group_by_project to detect cross-session project continuity via entity overlap.
session_summaryreadGet a summary of recent learnings, decisions, and context
set_reminderwriteSet a reminder for the future. Triggers on time (at specific time or after duration) or context match (when keywords appear in conversation). Reminders will surface automatically when conditions are met.
shodh_add_todowriteCreate a task/todo with optional project, priority, contexts, and due date. Follows GTD methodology.
shodh_complete_todoreadMark a task as complete. For recurring tasks, automatically creates the next occurrence.
shodh_context_summaryreadGet a condensed summary of recent decisions, learnings, and project context from memory.
shodh_forgetdestructiveDelete a specific memory by its ID. Use when information is outdated or incorrect.
shodh_list_todosreadList tasks/todos filtered by status and project. Returns tasks with IDs, priorities, and status.
shodh_proactive_contextreadSurface memories relevant to the current conversation context. Uses entity matching and semantic similarity.
shodh_recallreadSearch persistent memory using natural language. Returns semantically similar memories ranked by relevance.
shodh_rememberreadStore a memory that persists across sessions. Use for important facts, decisions, user preferences, or learnings.
todo_statsreadGet statistics about your todos - counts by status, overdue items, etc.
token_statusreadGet MCP pipeline token throughput for this session. Tracks tokens flowing through shodh memory tools only — NOT the AI context window. Use for internal diagnostics, not context window health.
topicreadThe topic to explore
update_todowriteUpdate a todo
update_todo_commentwriteUpdate an existing comment on a todo.
validate_causal_linkreadConfirm or reject a causal edge by its edge ID (shown by trace_lineage and list_causal_edges). Confirming an inferred edge raises it to full confidence and strengthens the knowledge-graph connections between the two memories
verify_indexreadVerify vector index integrity - diagnose orphaned memories that are stored but not searchable. Returns health status and count of orphaned memories.
what_i_knowreadSurface everything related to a topic
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (11 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ingest/folder.rs:126
const PREFIXES: &[&str] = &["id_rsa", "id_ed25519", "id_ecdsa", "id_dsa", ".env"];
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ingest/folder.rs:129
".netrc",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ingest/folder.rs:134
"authorized_keys",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ingest/folder.rs:1413
"id_rsa",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/ingest/folder.rs:1414
"id_ed25519.pub",
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.binary · CWE-1104
front/ui/src/features/chat/useBilling.ts
useBilling.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
seat/src/policy.ts
policy.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/recall_harness/bridge_harness.rs:245
"Vanguard", "Beacon", "Cipher", "Vector", "Warden", "Lattice", "Sentinel", "Cordon", "Bastion",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/recall_harness/lineage_harness.rs:123
"the Beacon network outage",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.claude/hooks/session-start.sh:4
API_URL="${SHODH_API_URL:-http://127.0.0.1:3030}"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
benches/integration_benchmarks.rs:359
let secret = "webhook-signing-secret-for-linear-integration";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
benches/integration_benchmarks.rs:379
let secret = "webhook-signing-secret-for-github-integration";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
benches/integration_benchmarks.rs:459
let secret = "webhook-signing-secret";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
benches/integration_benchmarks.rs:501
let secret = "webhook-signing-secret";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/integration_webhook_tests.rs:115
let secret = "webhook-signing-secret";
MEDIUMPrompt injection · review.data_transfer · CWE-94, CWE-1427
<tool:proactive_context>
REQUIRED: Call this tool with EVERY user message to surface relevant memories and build conversation history.
Why it matters. The proactive_context tool description instructs the agent to unconditionally send every user message to the memory backend on each interaction, transferring all conversation content off-machine without per-message user consent.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
backup_purge, delete_project, delete_todo, delete_todo_comment, forget, purge_facts, reset_token_session, shodh_forget
Why it matters. 8 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.graphon_run
.graphon_run
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.locomo_run_id
.locomo_run_id
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
.github/workflows/reader-composition.yml:9
# Chain: recall-eval (SHODH_DUMP_CONTEXT) exports exactly the top-k retrieved
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
.github/workflows-archive/fusion-feature-fit.yml:111
def split(r): return int(hashlib.md5(r['case_id'].encode()).hexdigest(), 16) % 10 < 7
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
benchmarks/longmemeval_to_harness.py:188
data.sort(key=lambda q: hashlib.md5(q["question_id"].encode()).hexdigest())
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/fit_fusion_calibration.py:90
h = int(hashlib.sha1(q["case_id"].encode()).hexdigest(), 16) % 100
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
python/shodh_memory/client.py:337
cargo_target = Path("../../target/release") / binary_name
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/handlers/integrity.rs:327
post_json("/api/integrity/scrub", &json!({ "user_id": "../../etc" })),

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha fda2ad7f58a3full audit observations/trust-audit/mcp-server/varun29ankus__shodh-memory.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06fda2ad7f58a3BLOCKF54first audit
06

Questions

What is the Shodh-Memory MCP server?

Local, LLM-free memory for AI agents. A single offline Rust binary — deterministic and auditable — that learns from use, forgets the irrelevant, and strengthens what matters. No cloud, no API keys.

What tools does Shodh-Memory expose?

67 in total: 47 read-only, 12 that write, and 8 that can delete or overwrite (backup_purge, delete_project, delete_todo, delete_todo_comment, forget). Every one is listed on this page with its risk.

Is Shodh-Memory safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Shodh-Memory need?

It reads ANTHROPIC_API_KEY, API_KEY, BASETEN_API_KEY, OPENAI_API_KEY, SHODH_API_KEY, SHODH_API_KEYS, SHODH_DEV_API_KEY, SHODH_JUDGE_MAX_TOKENS, SHODH_SEAT_TOKEN and SHODH_TOKEN_BUDGET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Shodh-Memory run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @shodh/seat-harness at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (fda2ad7f58a3), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement