Open-source governed, local-first memory control plane for AI agents and teams. arXiv:2608.08253
Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
qualixar
Source: github_code · also listed on Glama, github_topic
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
SLM_DATA_DIRSelf-bootstraps a Python venv, installs all deps in an isolatedSLM_HOMESL_MEMORY_PATHSLM_DISABLE_WARMUP_SIDE_EFFECTSSLM_MCP_EMBEDDEDSLM_SESSION_IDCLAUDE_SESSION_IDCLAUDE_PROJECT_DIRPROJECT_PATHSLM_AGENT_IDMulti-Agent Memory per-agent write activity and attribution; memories stamped by , agent write counts, and trust signalsCLAUDE_AGENT_TYPESLM_CLI_PATHSLM_HOOK_DAEMON_URLSLM_HOOK_DAEMON_TIMEOUTKMP_DUPLICATE_LIB_OKOMP_NUM_THREADSOPENBLAS_NUM_THREADSMKL_NUM_THREADSVECLIB_MAXIMUM_THREADSNUMEXPR_NUM_THREADSTOKENIZERS_PARALLELISMORT_DISABLE_COREMLSLM_SOURCE_ROOTSLM_BENCH_DIRSLM_BENCH_DBSLM_CACHE_DBSLM_DOGFOOD_API_KEYGITHUB_OUTPUTSLM_SKIP_DEP_CHECKSLM_DB_BUSY_TIMEOUT_MSSLM_SIGNER_KEYSLM_DAEMON_PORTSLM_NON_INTERACTIVESLM_MEMORY_DBSLM_USER_SESSIONSLM_TEST_ISOLATIONSLM_TEST_ALLOW_DAEMON_SPAWNSLM_AUTO_PROMOTE_DELAY_SSLM_AUTO_PROMOTE_MIN_EDGESCUDA_VISIBLE_DEVICESPYTORCH_MPS_HIGH_WATERMARK_RATIOPYTORCH_MPS_MEM_LIMITPYTORCH_ENABLE_MPS_FALLBACKTORCH_DEVICESLM_EMBED_WORKER_RSS_LIMIT_MBSLM_MAX_EMBEDDING_WORKERSSLM_EMBED_IDLE_TIMEOUTSLM_EMBED_RESPONSE_TIMEOUTSLM_EMBED_RECYCLE_AFTERSLM_MIN_AVAILABLE_MEMORY_GBSLM_STORE_FAST_EMBED_TIMEOUT_MSSLM_PII_REDACTIONTool annotations
62/96 tools have annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
96/96 tools missing one or more hints — session_init (missing: destructiveHint, idempotentHint, openWorldHint); observe (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); report_feedback (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +93 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
No eval / new Function
1 eval() or new Function() call — dynamic code execution
Replace eval / Function with explicit parsing or safer alternatives.
Readable source code
5 files appear obfuscated
Ship unminified, readable source.
No arbitrary install scripts
Has postinstall/preinstall script — runs arbitrary code on npm install
Remove postinstall/preinstall hooks unless they’re essential.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/qualixar-superlocalmemory-178op5)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check