memnox
Your agents can already do the work. Memnox makes it safe to let them do it without you. See what Claude Code, Codex and Cursor can actually do on your machine, and put the dangerous actions behind ask or deny. Local, deterministic, and no model ever decides.
Install / Use
claude mcp add Memnox -- npx -y github:Memnox/memnoxIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of memnox
memnox scores 76/100 on our quality scale, 1025th of 1,116 Security skills we index.
Its MCP Server is 30 KB long, well organised into 17 sections with 22 code examples: a thorough specification that gives an agent plenty to work with.
It has 10 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 2 days ago, so memnox is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 97/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
memnox compared with similar skills
All 4 of these similar skills score higher than memnox; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| memnox (this skill)by Memnox | 76 | 10 | 2d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 91.8k | 20d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.8k | 1d ago | MCP Server |
Frequently asked questions
- How do I install memnox?
- Run
claude mcp add Memnox -- npx -y github:Memnox/memnox. The install tabs above show the steps for each supported agent. - Which AI agents does memnox work with?
- It is written for Claude Code, Claude Desktop, Cursor and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
- Is memnox safe to use?
- It is Apache-2.0-licensed and scores 97/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is memnox still maintained?
- The repository was last updated 2 days ago, so memnox is actively maintained.
Skill content
View source on GitHubMemnox is an open source runtime that tells you what you can safely let your AI coding agent do next. It rules on every tool call Claude Code, Codex, Cursor, Gemini CLI or Windsurf makes, before the call runs, with one of three verdicts: allow, ask or deny. It runs on your machine, needs no account, and no model decides anything.
You already have agents that read your files, run your shell, push to your repositories
and call your MCP servers. Memnox sits inside each of their sessions: what is allowed goes
ahead, what is denied is refused with a way forward, and what needs a person asks you in
the prompt you are already looking at. Once you have said yes to the same thing often
enough, memnox next names it as something you could stop being asked about.
You do not learn a new tool to get that. You set it up once and keep working the way you work now.
Set up once
npm install -g memnox
memnox setup
That is the last Memnox command you need. setup finds the agents on this machine and
goes through them one at a time: what each can already reach, what you want to call it,
and whether to put it under Memnox. Nothing is changed for an agent you say no to.
Claude Code
claude-code
id agt_claude-code
config ~/.claude.json
mcp github
can use shell, filesystem, git, network, mcp
can reach ~/.aws/credentials, network
Call it something acme will recognise, or press Enter to keep "Claude Code" > Backend Coder
Put Backend Coder under Memnox now? [Y/n] y
For each agent you accept, it puts a hook in front of every tool call, gives the agent a
small MCP server (memnox-session) it can ask Memnox through, and adds a /fingerprint
command. Then you open Claude Code, Codex, Cursor, Gemini CLI or Windsurf the way you
always do. There is nothing to launch and nothing to remember.
Node 22 or newer, on macOS or Linux. On Windows, run it inside WSL, and ADR 0001 says why.
What you get, inside every session
| When | What Memnox does | What you typed | |---|---|---| | A session starts | The agent is told the boundary it works in, the rules in force, what your team has settled and how this repository is built, so it plans around them instead of walking into them | nothing | | The agent reaches for something your rules refuse | The call never runs. The agent is told why and what to use instead, so it finishes the task rather than stalling | nothing | | Something needs a person | You are asked in your agent's own permission prompt, or in the conversation, or in your Slack or Discord DM. Yes once, yes for the session, or no | a yes or a no | | The agent writes code that breaks how this repository is built | Refused before it lands, or sent straight back to be put right, even when the agent switches from its edit tool to the shell | nothing | | Your prompt touches something your team already decided | The decision is put in front of the agent, with who confirmed it and where | nothing | | Two agents go for the same file | The second is told who holds it and what they have been doing | nothing | | You want to know why, what happened, or to undo it | Ask the agent in plain words: "why was that refused?", "what have you done this session?", "undo what you did" | a sentence |
One session, start to finish
You open Claude Code in a repository and ask it to add order cancellation. Before it reads a file, it has been told where it stands:
Memnox: Memnox rules on this session in enforce mode: a rule that refuses stops the call, and one that asks puts the question to the person.
Project boundary: ~/work/shop. A write outside it asks first.
Your workspace has settled 1 decision(s), policies and owners. Before you change code, ask the memnox-session "brief" tool about the paths, or "memory" about the subject, and cite what it says.
This repository states how its code is written, in .memnox/code-fingerprint.yaml. Follow it; a write that breaks an enforced line is refused.
Your prompt mentions payment retries, which your team settled in Slack, so that decision is put in front of the agent too:
Your workspace settled this about payment retries: "Declined payments are never retried." (a decision, confirmed by ada@acme.com, on 2026-05-02, source https://acme.slack.com/archives/C01/p17).
In a hurry, the agent writes the update straight into the HTTP handler. The repository sends every database write through an Action, so the write never lands:
Memnox: This repository's code fingerprint: all database writes go through Actions, which own transactions and event persistence (rule fingerprint:writes-only-in-actions)
Instead: call actionFactory.create(XAction.class).run(params)
It writes the Action instead, and when the work is done it tries to force push:
verdict DENY
reason you chose to deny this: it rewrites history somebody else may already have pulled
instead push a branch and open a PR
So it pushes a branch and opens a PR. You typed one prompt. Every one of those answers came back inside the conversation, and each is in the record when you ask the agent "why was that refused?"
How it reaches each agent
Each agent's own hook asks Memnox before every tool call: a file read or write, a shell command, a web fetch, an MCP call. The answer comes back in the agent's own format, so the agent treats it like any other result.
When a rule refuses, the call never runs and the agent is told why and what to use instead, so it carries on with the task rather than retrying.
When a rule asks, Claude Code shows its own permission prompt with Memnox's reason
in it. Say yes once, or for the rest of the session; a second yes to the same thing
stops the asking for that session. An agent with no prompt of its own relays the
question in the conversation, and you reply yes, allow for this session or no.
Turn on memnox config set approvals both and it reaches your Slack or Discord DM too,
where the first answer wins.
When your prompt names something the workspace already settled, or just before the agent's first write to a file it covers, the decision is added to the conversation with who confirmed it and where.
Ask Memnox through the agent, in plain words. Every agent gets memnox-session,
with eight tools:
| You say | Tool |
|---|---|
| "Why was that refused?" | why |
| "Where does Memnox stand?" | status |
| "What have you done this session?" | replay |
| "Would git push --force be allowed here?" | decisions |
| "What did we decide about retries, and who said so?" | memory |
| "Brief me on src/payments before you start" | brief |
| "Record how this repository's code is written" | fingerprint |
| "Undo what you did this session" | rewind |
Every tool but rewind and fingerprint only reads. rewind waits for your yes before
it moves a file, and fingerprint writes a repository's first fingerprint and never
changes one that exists. None of them can allow, approve or change a rule, and an agent
that tries memnox allow, memnox mode off or an edit to a rule file from its shell is
refused before any rule is read, since an agent that could would approve itself.
| Agent | Checked before it runs | A question goes to | Told at session start |
|---|---|---|---|
| Claude Code | every tool | its own permission prompt | yes |
| Codex | every tool its hook reports | the conversation | yes |
| Gemini CLI | every tool | the conversation | yes |
| Cursor | commands, MCP calls, file reads and writes | its own prompt for commands and MCP calls | yes |
| Windsurf | commands, MCP calls, file reads and writes | memnox approve, the workspace or your DM | no, only what memnox-session says when it connects |
The five seams
Below the hooks, five seams sit in the path an agent's action already takes, so an agent does not have to cooperate for them to see it. Each turns what the agent tried into an action a rule matches, and each answers allow, ask or deny.
| Agent action | Seam | How it is put in the path | Action a rule matches | What it cannot see |
|---|---|---|---|---|
| Calls a tool on an MCP server | MCP proxy | memnox mcp wrap repoints every MCP config on the machine, keeping a backup | mcp.* | a tool that lies about its name in tools/list, which is classified by the lie |
| Runs git, docker, kubectl, gh, npm and the rest of the 19 classified binaries | PATH interceptors | memnox setup puts them on the agent's PATH, and offers your login PATH too | shell.execute, and per verb, such as git.push-force | a binary called by absolute path around the PATH |
| Sends an HTTP request | Egress proxy | memnox run starts it on loopback and points the agent at it | http.request | the body inside HTTPS, and a tool that ignores HTTPS_PROXY |
| Asks git for a credential before reaching a remote | Git credential helper | memnox-git-credential, which holds no secret and can hand none out | git.credential | a push over SSH, which never asks git for a credential |
| Opens chromium, chromedriver, geckodriver, google-chrome or msedgedriver | Browser driver | the PATH interceptors, which rule on the host rather than the script | browser.navigate | what the page does once the host is allowed |
A verdict of deny names what to use instead. A verdict of ask holds the call for a person, and for the browser that is once per host per session. The threat model states each limit in full.
A change to your rules reaches an open session on its next tool call. MCP servers the agent already started, and the note it read at the start, catch up when you restart the agent. Everything from inside the session has the whole story.
Holding agents to the way your code is written
Every repository has rules nobody wrote down where an agent would read them: writes go through one layer, time is always UTC, nothing returns null. An agent new to the code breaks them in the first hour, and a reviewer catches it days later if at all. Memnox turns them into a code fingerprint the first agent records and every agent after it is held to.
Why this is not another CLAUDE.md
CLAUDE.md, AGENTS.md, GEMINI.md and .cursor/rules tell an agent what it should do.
They are loaded into the model's context, and following them is the agent's job. Nothing
happens when it does not, until a reviewer notices.
CLAUDE.md, AGENTS.md, .cursor/rules
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
91.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
