Atlas / MCP servers / xuanlinai / Overmind

OvermindCAUTION

mcp/xuanlinai/overmind

玄霖超脑 · 无量网络 v4 重构版— 66 模块6通道 AI 认知神经系统 · 装一次,你所有的 AI 工具从此共享一个永远不失忆的大脑。跨会话记忆 · 多 Agent 互通 · 自动代码审查 · 零配置

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
5 3r · 2w · 0d
Transport
—
License
MIT
Stars
85
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

66 模块 AI 认知神经系统 · 6 通道架构 · 知识图谱推理 · 红队审查 · 自进化

🇨🇳 中文 | English

不是记忆,是推理。不是工具,是神经系统。不是插件,是认知引擎。

🥇 6 通道架构 — 串并联管道 + z2 中枢 + n2 终端 🥈 零配置自适应安装 — 探针 + 自修复 + 诚实降级 🥉 零进程触发 — 根治 Windows 窗口闪烁 🔮 舰队模式 — 多 CC 自发现 + 跨 CC 技能 boosting + 冲突检测 🧠 66 模块实时互连 — 知识图谱 4500+ 节点 · 10 种关系 · 被动推理

🇨🇳 中文

这是什么

玄霖超脑 v4(无量网络)是 Claude Code 的外挂认知引擎。66 个模块通过 6 条通道 + 事件总线实时互连,形成 AI 界首个认知神经系统。

它在你不在的时候仍在思考。你写的每行代码先被红队分身攻击才到你面前。你做的每个决策都有"选了另一个会怎样"的阴影追踪。你开的每个 CC 实例都能看到彼此在做什么。

重构版 vs 初版 v4

版本演进

性能

Read from source at commit e96699a841e8OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add xuanlin-overmind --env ANTHROPIC_AUTH_TOKEN=${ANTHROPIC_AUTH_TOKEN} --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OVERMIND_API_KEY=${OVERMIND_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "xuanlin-overmind": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_AUTH_TOKEN": "${ANTHROPIC_AUTH_TOKEN}",
        "DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "OVERMIND_API_KEY": "${OVERMIND_API_KEY}"
      }
    }
  }
}
03

Exposed tools (5)

3 read · 2 write · 0 destructive.

ToolRiskDescription
create_skillwrite创建新 SKILL.md 文件
list_skillsread列出匹配查询的技能
memory_statsread记忆统计
save_memorywrite手动保存一条语义记忆
search_memoryread混合检索记忆(BM25 + 向量),返回 top-K 相关记忆
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (9 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

HIGHPrompt injection · review.misleading_scope · CWE-94, CWE-1427
<listing:description>
Augment AI agents with an external cognitive engine providing persistent five-layer memory
Why it matters. The listing describes a memory system, but the package actually installs a daemon, modifies CLAUDE.md, injects content into every conversation, scans all sessions, and runs persistent background processes.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
daemon.py:646
h = hashlib.md5((mem[2] or '')[:50].encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
wiring.js:421
const hash = require('crypto').createHash('md5').update(JSON.stringify(fleetData)).digest('hex')
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
better-sqlite3
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWObfuscation / stealth · review.concealment · CWE-506, CWE-94
README.md
零进程触发 — 根治 Windows 窗口闪烁
Why it matters. The package explicitly designs hidden background triggers using temp file rename to avoid user detection of daemon activity.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
LOWPrompt injection · review.data_transfer · CWE-94, CWE-1427
README.md
Every CC instance you open can see what the others are doing.
Why it matters. Fleet mode scans all Claude Code sessions, extracts Q/A pairs, and broadcasts them across instances, sharing user conversation data across processes.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
LOWPrompt injection · review.data_transfer · CWE-94, CWE-1427
README.md
AI 筛选:flash 模型过滤注入文档,94% 压缩率
Why it matters. The n2 terminal sends filtered conversation data to an external 'flash model' for processing, transferring user data off-machine.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
INFOInventory / provenance · inv.oversize · CWE-1104
launcher.exe
launcher.exe
Why it matters. 1184555 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
video/demo_cn.mp4
video/demo_cn.mp4
Why it matters. 6880915 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
video/demo_en.mp4
video/demo_en.mp4
Why it matters. 8943970 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha e96699a841e8full audit observations/trust-audit/mcp-server/xuanlinai__overmind.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07e96699a841e8CAUTIONB87first audit
06

Questions

What is the Overmind MCP server?

玄霖超脑 · 无量网络 v4 重构版— 66 模块6通道 AI 认知神经系统 · 装一次,你所有的 AI 工具从此共享一个永远不失忆的大脑。跨会话记忆 · 多 Agent 互通 · 自动代码审查 · 零配置

What tools does Overmind expose?

5 in total: 3 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Overmind safe to connect to an agent?

With care. The audit graded it B (87/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Overmind need?

It reads ANTHROPIC_AUTH_TOKEN, DEEPSEEK_API_KEY, OPENAI_API_KEY and OVERMIND_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (e96699a841e8), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement