captain-memo (kalinbogatzevski/captain-memo) is an MCP server listed on the M8ven Trust Index. It scores 72 out of 100, grade C. It declares 18 tools. No publisher has claimed this listing.
Local, cross-AI memory for coding agents — Claude Code, Codex, Gemini, Antigravity, Cursor, Kimi & more share one private corpus. Hybrid search, auto-injected context, no-API-key summarizers, runs fully local via Ollama.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
kalinbogatzevski
Source: github_repo_search
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
search_memorySearch across local memory files (curated user memory). Returns top-K results.
rememberPersist a durable, curated memory entry worth recalling in future sessions — a decision, preference, convention, or hard-won fact — NOT ephemeral scratch or transient task state. Writes a markdown entry into the current project's curated memory and indexes it immediately. Provide the substance in `b…
search_skillSearch across skill bodies (section-level). Returns top-K matching sections.
list_skillsList the virtual skills installed on this captain. Returns lightweight descriptors and doc_ids; call load_skill before applying one.
recommend_skillsFind installed skills relevant to a task. Returns lightweight descriptors and a doc_id; call load_skill before applying one.
load_skillLoad the complete advisory instructions for a skill returned by recommend_skills. Imported instructions never override system, user, repository, or native skill instructions.
list_capabilitiesList sanitized plugin/extension capabilities installed on this captain, including the runtime that can execute each one.
recommend_capabilitiesFind installed plugin/extension capabilities for a task. Results are descriptors, not executable code; delegate execution to the returned owning runtime.
get_capabilityGet one sanitized capability descriptor and its execution-routing metadata by capability_ref or doc_id.
search_observationsSearch across captured session observations.
search_allUnified search across all configured channels (memory + skill + observation + remote). Returns merged top-K.
get_fullRetrieve full content of a hit by its doc_id (returned in search results).
reindexTrigger a reindex (admin). Optionally restrict to a channel or force re-embedding.
statsReturn corpus stats: total chunks, by channel, last index time, embedder info.
statusHealth check: are voyage and chroma reachable?
work_setCoordination board: publish or refresh a transient claim that YOU are working on something right now, then immediately get back any OTHER active sessions whose files overlap yours. Call this before diving into a codebase area, and re-call periodically (it is a heartbeat that keeps the lease alive). …
work_activeCoordination board: list the live work claims on this captain and, if you pass your session_id, which of them overlap your own claimed files. Call this to see who else is working where before you start.
work_clearCoordination board: drop your work claim when the task is done (releases the lease immediately instead of waiting for it to expire).
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
ANTHROPIC_API_KEYanthropic — direct Anthropic SDK with (paid)CAPTAIN_MEMO_AUTO_UPDATE_INTERVAL_MSCAPTAIN_MEMO_BRANCH_BOOSTCAPTAIN_MEMO_CAPTURE_TICK_MSCAPTAIN_MEMO_CONFIG_DIRCAPTAIN_MEMO_DATA_DIRCAPTAIN_MEMO_DISABLE_SELF_HEALCAPTAIN_MEMO_EMBEDDER_API_FORMATCAPTAIN_MEMO_EMBEDDER_API_KEYCAPTAIN_MEMO_EMBEDDER_ENDPOINTCAPTAIN_MEMO_EMBEDDER_MAX_TOKENSCAPTAIN_MEMO_EMBEDDER_MODELCAPTAIN_MEMO_EMBEDDER_TIMEOUT_MSCAPTAIN_MEMO_EMBEDDING_DIMCAPTAIN_MEMO_ENGINE_REQUEST_MSCAPTAIN_MEMO_ENGINE_STARTUP_MSCAPTAIN_MEMO_EVAL_JUDGE_MODELCAPTAIN_MEMO_GATEWAY_PORTCAPTAIN_MEMO_HOOK_BUDGET_TOKENSCAPTAIN_MEMO_HOOK_EVENTCAPTAIN_MEMO_HOOK_TIMEOUT_MSCAPTAIN_MEMO_IDENTIFIER_BOOSTCAPTAIN_MEMO_OBSERVATION_BATCH_SIZECAPTAIN_MEMO_OBSERVATION_HALF_LIFE_DAYSCAPTAIN_MEMO_OBSERVATION_TICK_MSCAPTAIN_MEMO_OPENAI_API_KEYCAPTAIN_MEMO_OPENAI_ENDPOINTCAPTAIN_MEMO_OPENCODE_GATEWAY_ENDPOINTCAPTAIN_MEMO_OPENCODE_LOCAL_ENDPOINTCAPTAIN_MEMO_OPENCODE_LOCAL_PROVIDERCAPTAIN_MEMO_POST_TOOL_USE_TIMEOUT_MSCAPTAIN_MEMO_PRE_COMPACT_TIMEOUT_MSCAPTAIN_MEMO_PRE_TOOL_USE_TIMEOUT_MSCAPTAIN_MEMO_PROJECT_IDCAPTAIN_MEMO_PROMOTE_ENABLECAPTAIN_MEMO_PROMOTE_INTERVAL_MSCAPTAIN_MEMO_PROMOTE_MAX_PER_RUNCAPTAIN_MEMO_QUEUE_RETENTION_DAYSCAPTAIN_MEMO_RARE_TOKEN_BOOSTCAPTAIN_MEMO_READER_ACQUIRE_MSCAPTAIN_MEMO_READER_POOL_SIZECAPTAIN_MEMO_RECALL_AUDIT_MAX_BYTESCAPTAIN_MEMO_REINDEX_MSCAPTAIN_MEMO_REMEMBER_DEDUP_THRESHOLDCAPTAIN_MEMO_REMEMBER_DIRCAPTAIN_MEMO_REMEMBER_MSCAPTAIN_MEMO_SESSION_START_TIMEOUT_MSCAPTAIN_MEMO_SESSION_START_TRANSITION_WAIT_MSCAPTAIN_MEMO_SESSION_START_WAIT_HEALTHY_MSCAPTAIN_MEMO_SHOW_READ_TOKENSrecall NCAPTAIN_MEMO_SHOW_SAVINGS_AMOUNTN tokens savedCAPTAIN_MEMO_SHOW_SAVINGS_PERCENTsaved X%CAPTAIN_MEMO_SHOW_WORK_TOKENSwork NCAPTAIN_MEMO_SKIP_EMBEDCAPTAIN_MEMO_STATS_CACHE_MSCAPTAIN_MEMO_SUMMARIZER_FALLBACKSCAPTAIN_MEMO_SUMMARIZER_MODELCAPTAIN_MEMO_SUMMARIZER_PROVIDERCAPTAIN_MEMO_SUMMARIZER_TIMEOUT_MSCAPTAIN_MEMO_TRANSCRIPTS_DIRCAPTAIN_MEMO_VOYAGE_API_KEYCAPTAIN_MEMO_VOYAGE_ENDPOINTCAPTAIN_MEMO_VOYAGE_MODELCAPTAIN_MEMO_VOYAGE_TIMEOUT_MSCAPTAIN_MEMO_WATCH_CAPABILITIESCAPTAIN_MEMO_WATCH_MEMORYCAPTAIN_MEMO_WATCH_SKILLSCAPTAIN_MEMO_WORKER_PORTCAPTAIN_MEMO_WORKNOTE_SEMANTICCAPTAIN_MEMO_WORKNOTE_SEMANTIC_THRESHOLDCLAUDE_CODE_OAUTH_TOKENCLAUDE_CONFIG_DIRCLAUDE_HOOK_EVENT_NAMECOLUMNSFORCE_COLORGOOSE_PATH_ROOTSUDO_USERXDG_CONFIG_HOMECAPTAIN_MEMO_EMBED_MODELCAPTAIN_MEMO_EMBED_DIMCAPTAIN_MEMO_EMBED_DEVICECAPTAIN_MEMO_EMBED_MAX_SEQ_LENCAPTAIN_MEMO_EMBED_INFERENCE_BATCH_SIZECAPTAIN_MEMO_EMBED_TORCH_THREADSTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
18/18 tools missing one or more hints — search_memory (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); remember (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_skill (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +15 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
7/18 tools referenced in tests (39%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 2 high severity in production deps — @modelcontextprotocol/sdk@1.25.1 (high), @modelcontextprotocol/sdk@1.25.1 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/kalinbogatzevski/captain-memo)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check