memsearch-mcp AGENTS.md

memsearch-mcp AGENTS.md is an instructions file for Codex, OpenCode from TadMSTR/memsearch-mcp. It costs 561 tokens per session, scanned A, original, MIT.

Project instructions for memsearch-mcp, a server that searches agent memory files using several search methods and Milvus, a database for vector search. They document its tools, structure, dependencies, and configuration.

In plain words
What is it for?
Use them when developing, configuring, testing, or operating the memory-search server.
Why use it?
They explain how memory search and re-indexing work, including the allowed paths and authentication settings.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: reads .claude/ paths.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/tadmstr/memsearch-mcp/agents-md
Clone the repo
git clone --depth 1 https://github.com/TadMSTR/memsearch-mcp

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for memsearch-mcp AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/tadmstr/memsearch-mcp/agents-md.svg)](https://agentmods.dev/instructions/tadmstr/memsearch-mcp/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/tadmstr/memsearch-mcp/agents-md"><img src="https://agentmods.dev/badge/instructions/tadmstr/memsearch-mcp/agents-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 561 This file is loaded in full into every session.
When invoked 561 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00561 $0.00561
Opus 5 $0.00280 $0.00280
Sonnet 5 $0.00112 $0.00112
Haiku 4.5 $0.00056 $0.00056

Measured 5d ago against content hash 5e1e02771b52, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

memsearch-mcp AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 60 lines

How it starts

The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.

memsearch-mcp

FastMCP server wrapping the memsearch Python library for hybrid vector+BM25+reranker semantic search over agent memory files.

What it does

Provides two tools for searching and re-indexing the forge agent memory store backed by Milvus.

Tools

  • search_memory(query, limit=10) — Hybrid search: vector (Milvus) + BM25 + reranker. Returns ranked MemoryResult objects with path, snippet, score, tier, and tags.
  • index_memory(path=None) — Trigger index refresh for a path. Path must be within _ALLOWED_INDEX_ROOTS.

Structure

src/memsearch_mcp/
  __init__.py
  server.py         FastMCP server — 2 tools, MemSearch init, HMAC auth middleware, path whitelist
  models.py         MemoryResult pydantic model
tests/              pytest tests (conftest.py stubs `memsearch` when the lib is absent)
ecosystem.config.js PM2 config
pyproject.toml

Dependencies

Package Role
fastmcp MCP server framework
memsearch Hybrid search library (Milvus + BM25)
pydantic Result model
structlog JSON structured logging

Configuration

Env var Purpose
MEMSEARCH_SECRET Optional HMAC secret for X-Memsearch-Token auth header
LOG_LEVEL Logging verbosity
MCP_PORT Server port

Milvus URI, collection name, embedding provider/model, and reranker model are sourced from the memsearch package's own config via memsearch.config.resolve_config() — not from this server's env vars.

Key architecture decisions

  • _ALLOWED_INDEX_ROOTS whitelistindex_memory only accepts paths under ~/.claude/memory or /opt/agents/memory. Uses Path.is_relative_to() for strict prefix matching after symlink resolution. This prevents agents from triggering indexing of arbitrary filesystem paths. Do not widen this without a security review (resolved from a 2026-05-28 audit finding).
  • HMAC auth middleware — optional Starlette middleware validates X-Memsearch-Token if MEMSEARCH_SECRET is set. Enable this when the server is exposed beyond localhost.

Read the full file on GitHub · 60 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 60 lines · 561 tokens per session scan A 5e1e02771b52

Subscribe to this mod's changes

memsearch-mcp AGENTS.md is an instructions file published in the GitHub repository TadMSTR/memsearch-mcp (0 stars, last pushed 1mo ago), licensed MIT. It adds 561 tokens to every session, about $0.0028 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.