cerefox · MCP server
Cerefox — user-owned shared memory for AI agents. CLI + stdio MCP server + web UI + ingestion for a knowledge base on your own Supabase project (or fully self-hosted with Cerefox Local).
Not claimed by its maker. Is this yours? Prove it and answer the findings
The registry now serves 1.17.4. Everything measured on this page describes 1.14.5.
Findings, provenance and the install command are records of the scanned version, not the one npm would give you today. Treat them as history until this listing is rescanned. Registry checked 2026-10-06.
Published because it was found. A finding is information about where the limits are, not a verdict that the software is unsafe.
Receipt history: every signed receipt for every version of this listing, and what changed between them.
Cerefox — user-owned shared memory for AI agents. CLI + stdio MCP server + web UI + ingestion for a knowledge base on your own Supabase project (or fully self-hosted with Cerefox Local).
Static scanned
Paste this into your client's MCP configuration.
{
"mcpServers": {
"cerefox": {
"command": "npx",
"args": [
"-y",
"@cerefox/memory@1.14.5"
]
}
}
}Or run it directly.
npx -y @cerefox/memory@1.14.5Pinned to 1.14.5, which is the version the findings above were found in. Drop the version to take whatever is newest, and the report on this page stops describing what you installed.
3,539 installs last month (via ecosyste.ms) · build provenance signed · no published advisories · checked 2026-10-06
Built from source, attested
npm publishes a signed statement that this exact package was built from the repository below, at this commit. It is verifiable without taking our word for it.
It renders the current rung (static scanned) and links back here, where what that does and does not establish is one click away. It updates itself as the evidence deepens.
[](https://ooruby.com/market/cerefox-memory)Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.
MCP server for enabling memory for Claude through a knowledge graph
Maintenance
MaintainedA release on 14 Sep 2026 (1.14.5), 9 days before this check on 23 Sep 2026. Anything later would only be more recent.
Read from the npm registry, read by the weekly version refresh.
Release activity only: it says nothing about quality or safety, and a finished small package can be fine without releases. How it is measured