Deja VuBLOCK
The most accurate, cheapest and fastest memory for coding agents: searchable session history from Claude Code, Codex, Cursor and 32 more agents, already on your disk. No LLM, one Go binary.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The one memory your coding agents share, built from the history already on your disk.
Your agent is about to re-debug something you fixed in March — in a different agent. deja starts full: it indexes what Claude Code, Codex, Cursor and 32 more agents already wrote to disk, and hands it back in whichever agent asks.
English | 简体中文 | 繁體中文 | 日本語 | 한국어 | Español | Português | Français | Deutsch | Русский | Türkçe | हिन्दी
Nobody searched anything — the agent called deja itself. Two real runs against a synthetic corpus: nobody's history is published.
curl -fsSL https://raw.githubusercontent.com/vshulcz/deja-vu/main/install.sh | sh deja install --auto
macOS and Linux; ten seconds to install, about ten to index · Windows, Homebrew, npm and the rest
6b970f959f81OBSERVED · 2026-09-29Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add deja-vu -- npx -y @vshulcz/[email protected] mcp
Exposed tools (8)
7 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
deja | read | Search your own past coding sessions |
deja-vu | read | Memory from the coding sessions already on this machine |
deja_blame | read | The past sessions that discussed a file, so you know why it is shaped the way it is before editing, refactoring or deleting it. Session history, not git authorship. |
deja_fix | read | What this machine ran after that same error before, in the sessions where the error did not come back. Paste the failing output verbatim rather than a paraphrase — the match is on the error |
deja_how | write | The real invocation this machine uses for a build, test, deploy or script, with the flags it actually ran, ordered by how many sessions ran it. A guessed command is plausible and fails on this setup. |
deja_recall | read | Search this machine |
deja_remember | read | Store one durable decision once it is settled, as a single self-contained fact that will make sense months later. Not transcripts, not a summary of the conversation, and not anything already obvious from the code. |
deja_session | read | A full digest of the single best-matching past session — what was tried, what was decided, what it cost. Use after deja_recall when the reasoning behind an earlier decision matters, not just that it happened. |
Trust audit
BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
case '', '', '', '', '', // embeddings and overrides
'', '', '', '', // isolates
carrySplitRE = regexp.MustCompile(`([.!?]\**)\s+([A-ZА-ЯЁ«"*#\[])`)
"grok-title": "sk-ant-api03-titlesecret0123456789",
"sk-ant-api03-abcdefghijklmnopqrstuvwxyz012345",
in := `api_key=sk-ant-abcdefghijklmnopqrstuvwxyz0123456789`
`{"type":"user","sessionId":"sec","timestamp":"` + ts + `","message":{"role":"user","content":"the key was AKIAABCDABCDABCDABCD in the config"}}`,"claude-text": "AKIAIOSFODNN7EXAMPL1",
body := `{"type":"user","sessionId":"leaky-1","cwd":"/w/s","timestamp":"2026-07-02T10:00:00Z","message":{"role":"user","content":"staging is down, here is the dsn: postgres://svc:[email protected]`{"type":"user","sessionId":"s3","timestamp":"2026-03-06T10:00:00Z","message":{"role":"user","content":"psql postgres://svc:[email protected]:5432/app"}}`,`{"type":"user","sessionId":"s3","timestamp":"2026-03-06T10:02:00Z","message":{"role":"user","content":"still failing: postgres://svc:[email protected]:5432/app"}}`,"postgres://user:pass1234567890@localhost/db",
"postgres://app:[email protected]:5432/prod",
const secret = "8f14e45fceea167a5a36dedd4bea2543"
const token = "ghp_abcdefghijklmnopqrstuvwxyz0123456789"
const secret = "credential-that-must-not-appear"
const secret = "ghp_abcdefghijklmnop0123456789QRSTUV"
const secret = "ghp_abcdefghijklmnop0123456789QRSTUV"
raw := "continue the work\u202ereversed\u200b here: ghp_0123456789abcdefghijklmnopqrstuvwxyzAB"
if strings.Contains(got, "ghp_0123456789abcdefghijklmnopqrstuvwxyzAB") {argv, ok := handoffArgv("claude", "work\u202ereversed here ghp_0123456789abcdefghijklmnopqrstuvwxyzAB")if strings.Contains(joined, "\u202e") || strings.Contains(joined, "ghp_0123456789abcdefghijklmnopqrstuvwxyzAB") {const token = "ghp_abcdefghijklmnopqrstuvwxyz0123456789"
{"a private key", "-----BEGIN PRIVATE KEY-----", "MIIBVgIBADANBgkqhkiG9w0\n-----END PRIVATE KEY-----\nand the rest of the note survives", "MIIBVgIBADANBgkqhkiG9w0"},"-----BEGIN RSA PRIVATE KEY-----\nMIIEpAIBAAKCAQEAfakefakefakefakefake\n-----END RSA PRIVATE KEY-----",
Gates applied: no_behavioural_pass.
6b970f959f81full audit observations/trust-audit/mcp-server/vshulcz__deja-vu.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-29 | 6b970f959f81 | BLOCK | F | 38 | first audit |
Questions
What is the Deja Vu MCP server?
The most accurate, cheapest and fastest memory for coding agents: searchable session history from Claude Code, Codex, Cursor and 32 more agents, already on your disk. No LLM, one Go binary.
What tools does Deja Vu expose?
8 in total: 7 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Deja Vu safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (38/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Deja Vu need?
It reads KEYWORDS and MY_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Deja Vu run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as dsh-deja at 0.21.3.
How current is this page?
The grade is for one exact copy of the source (6b970f959f81), read on 2026-09-29. The repository is watched and re-audited when it changes.