UniDeX-Agent-HarnessBLOCK
UniDeX Agent Harness: a second brain and supervised Chief of Staff for Claude Code and Codex CLI, with persistent memory, recall and session capture, plus proposals you approve before anything changes. Lives in a plain-Markdown vault, with the UniDeX macOS app as its live dashboard.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A second brain for Claude Code and Codex CLI, and a macOS app that renders it. Persistent memory · recall · session capture · a named Chief of Staff · a live monitor of it all.
Quick start · Prerequisites · Installation · Screenshots · First session · Chief of Staff · Commands · How it works · Docs
Claude Code and Codex CLI forget everything between sessions. UniDeX gives them a vault they can read from on every prompt and write back to at the end of every session, then puts a dashboard on to
5fa102102840OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add agenticos-workbench --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env APPLE_KEYCHAIN_PROFILE=${APPLE_KEYCHAIN_PROFILE} -- npx -y [email protected]{
"mcpServers": {
"agenticos-workbench": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"APPLE_KEYCHAIN_PROFILE": "${APPLE_KEYCHAIN_PROFILE}"
}
}
}
}Exposed tools (44)
42 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Default | read | Claude Code |
Explore | read | Find the status bar code |
Fable | read | The latest Fable |
GPT-Astra | read | Frontier intelligence. |
GPT-Luna | read | Fast and affordable. |
GPT-Old | read | Older. |
GPT-Sol | read | Workhorse. |
GPT-Tide-2 | read | The previous generation. |
GPT-Tide-3 | read | The newest tide model. |
Haiku | read | The latest Haiku |
Opus | read | The latest Opus |
Sonnet | read | The latest Sonnet |
a | read | first line second line |
brief_read | read | |
code-review | read | Review the current diff |
compact | read | Compact the conversation |
deploy | write | Ship the app |
docs_researcher | read | Checks APIs |
docx | read | Word documents |
explorer | read | Explores |
feedback_rules | read | |
graph_neighbors | read | |
graph_overview | read | |
graph_path | read | |
graph_query | read | |
imagegen | read | Images |
memory_list | read | |
memory_read | read | |
memory_search | read | |
my-model | read | Custom model id |
pattern_list | read | |
planner | read | Plans |
pr_explorer | read | Maps code paths |
recall | read | |
review | read | Review the open changes |
reviewer | read | Reviews diffs |
routine_list | read | |
session_list | read | |
session_recall | read | |
snapshot_read | read | |
tide-report | write | Write the tide report |
triage | read | Triage issues |
wrap | read | Session end |
wrap_session | read |
Trust audit
BLOCKgrade F · trust 25/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | FAIL |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (13 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
2. **In-session extraction.** Use the `wrap` skill: review this conversation and call the `wrap_session` tool of the `agenticos` MCP server (`mcp__agenticos__wrap_session`) exactly once with `facts`,
2. **In-session extraction.** Use the `wrap` skill: review this conversation and call the `wrap_session` tool of the `agenticos` MCP server (`mcp__plugin_agenticos_agenticos__wrap_session`) exactly on
make-payload.mjs
payload.ts
out = exec(sqlite3, ['-readonly', '-json', db, CODEX_SQL], { encoding: 'utf8', timeout: 5000, stdio: ['ignore', 'pipe', 'pipe'] });exec(bin, ['login', 'status'], { timeout: opts.timeoutMs || 10000, env: headlessEnv(), encoding: 'utf8' }, (err, stdout, stderr) => {const r = bin ? exec(bin, ['--version'], { encoding: 'utf8' }) || {} : { error: new Error('AOS_PYTHON_BIN is empty') };const r = exec(bin, ['--version'], { encoding: 'utf8', timeout: 30000, stdio: ['ignore', 'pipe', 'pipe'] });const r = exec(uv, args, {const browser = await until(() => chromium.connectOverCDP(`http://127.0.0.1:${port}`, { timeout: 2_000 }), 30_000, 500);const b2 = await until(() => chromium.connectOverCDP(`http://127.0.0.1:${port2}`, { timeout: 2_000 }), 30_000, 500);export const OLLAMA_URL = "http://127.0.0.1:11434";
process.stdout.write(` ${r.ts} real $${r.realUsd} Δreal $${r.realDelta ?? '—'} Δanalyzer $${r.tgRawDelta ?? '—'} derived ${r.derivedCalibration ?? '—'}\n`);2. Otherwise — or whenever the user says "refresh sitrep" — run the Rebuild below.
2. Otherwise — or whenever the user says "refresh sitrep" — run the Rebuild below.
.gitleaks.toml
.keep
.graphifyignore
return crypto.createHash('sha1').update(JSON.stringify(stable)).digest('hex').slice(0, 16);const hash = crypto.createHash('sha1').update(raw).digest('hex');const VAULT_KEY = crypto.createHash('sha1').update(PATHS.VAULT).digest('hex').slice(0, 8);const gitCacheFile = (dir, tmp) => path.join(tmp, `aos-sl-git-${crypto.createHash('sha1').update(dir).digest('hex').slice(0, 16)}.json`);return hashlib.sha1(joined.encode("utf-8")).hexdigest()for (const p of ["/etc/passwd", `${HOME}/.ssh/config`, `${HOME}/Documents/x.md`, `${VAULT}-other/x.md`, `${VAULT}/../x`, "relative/x", "", `${VAULT}/a\0b`,for (const p of [`${HOME}/.codex/auth.json`, `${HOME}/.claude/.credentials.json`, `${VAULT}/workspaces/app/.env`, `${VAULT}/.env.local`, `${VAULT}/certs/server.pem`, `${VAULT}/id_ed25519`])Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
5fa102102840full audit observations/trust-audit/mcp-server/zzoretich__unidex-agent-harness.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 5fa102102840 | BLOCK | F | 25 | first audit |
Questions
What is the UniDeX-Agent-Harness MCP server?
UniDeX Agent Harness: a second brain and supervised Chief of Staff for Claude Code and Codex CLI, with persistent memory, recall and session capture, plus proposals you approve before anything changes. Lives in a plain-Markdown vault, with the UniDeX macOS app as its live dashboard.
What tools does UniDeX-Agent-Harness expose?
44 in total: 42 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is UniDeX-Agent-Harness safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (25/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does UniDeX-Agent-Harness need?
It reads ANTHROPIC_API_KEY and APPLE_KEYCHAIN_PROFILE from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does UniDeX-Agent-Harness run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as agenticos-workbench at 1.4.0.
How current is this page?
The grade is for one exact copy of the source (5fa102102840), read on 2026-10-08. The repository is watched and re-audited when it changes.