io.github.VonderVuflya/yggdrasil
PYPI · YGGDRASIL-MEMORY · SCANNED SEP 20
One shared, durable memory for your AI coding agents — local-first, zero-dependency.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security50
- Malware scan not yet available for this package.Unverified
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised native-build step with no shell scripting around it. View diagnostics → Pass
- No production dependencies, so there is no dependency health to assess. View diagnostics → Pass
Provenance & Transparency32
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- License check failed: the license (GNU Affero General Public License v3 or later (AGPLv3+)) isn't a recognized OSI-approved license. See how to fix → Fail
- Actively maintained (last published 45 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1102 tokens (~183/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities20
- Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.github.VonderVuflya/yggdrasil MCP server?
io.github.VonderVuflya/yggdrasil runs locally as a PyPI package, launched with uvx yggdrasil-memory. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · yggdrasil-memory
claude mcp add vondervuflya-yggdrasil -- uvx yggdrasil-memory
{
"mcpServers": {
"vondervuflya-yggdrasil": {
"command": "uvx",
"args": [
"yggdrasil-memory"
]
}
}
} {
"servers": {
"vondervuflya-yggdrasil": {
"command": "uvx",
"args": [
"yggdrasil-memory"
]
}
}
} codex mcp add vondervuflya-yggdrasil -- uvx yggdrasil-memory
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"vondervuflya-yggdrasil": {
"type": "local",
"command": [
"uvx",
"yggdrasil-memory"
],
"enabled": true
}
}
} openclaw mcp add vondervuflya-yggdrasil --command uvx --arg yggdrasil-memory
mcp_servers:
vondervuflya-yggdrasil:
command: "uvx"
args: ["yggdrasil-memory"] {
"McpServers": {
"vondervuflya-yggdrasil": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"yggdrasil-memory"
]
}
}
} assistant mcp add vondervuflya-yggdrasil -t stdio -c uvx -a yggdrasil-memory
{
"mcpServers": {
"vondervuflya-yggdrasil": {
"command": "uvx",
"args": [
"yggdrasil-memory"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 −3
- Stability: pass → 0.80 functional
- 19 Sept 26 0
- Stability: 0.97 → pass security
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 −3
- Stability: pass → 0.80 functional
- 12 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed pypi/yggdrasil-memory@0.15.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | pypi |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 0 packages
| Packages resolved | 0 |
|---|---|
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ygg_bootstrap Load one project's memory ~166
Load the top durable memories for ONE project — decisions, conventions, lessons, and open status — to prime work at the start of a task. Use when you already know the project; for cross-project discovery use ygg_recall, for a targeted in-project query use ygg_search. Results are project-scoped and ranked, most-used and pinned first.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Maximum number of memories to return (default 5). Raise for a fuller picture; lower to keep context small. |
| project | string | yes | Project to scope to — usually the git repository name, e.g. "checkout-api". |
| query | string | – | Optional focus to rank within the project, e.g. "payment retries". Leave empty for the project's most relevant memories overall. |
No output schema declared.
No examples provided.
ygg_health Check memory engine health ~70
Report the local Yggdrasil memory engine's health: running status, total stored-memory count, and whether semantic (dense-vector) search is available. Call this first when any other ygg_* tool fails unexpectedly, to confirm the engine is up before retrying. Returns a small JSON status object.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
ygg_materialize Export a memory to Markdown ~172
Write ONE stored memory to a human-readable Markdown note (Obsidian-compatible) on disk; the stored memory itself is unchanged. Use when the user wants to read, edit, or archive a specific memory as a file. Needs the memory id from a prior ygg_recall / ygg_search / ygg_bootstrap result plus its project; returns the written file path.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The memory id to export, as returned by a prior recall/search/bootstrap, e.g. "ygg_4a5c82a...". |
| output_dir | string | – | Directory to write the Markdown note into (default "vault/04-learnings"). Must stay inside the local vault root; paths escaping it are rejected. |
| project | string | yes | The project the memory belongs to. |
No output schema declared.
No examples provided.
ygg_recall Recall prior work across all projects ~178
Search durable memory ACROSS ALL projects for prior solutions, decisions, and lessons to reuse. Use BEFORE solving any non-trivial problem ("have I handled this before?"); for one known project use ygg_bootstrap to load its context or ygg_search for a targeted query instead. Ranks by relevance and past usage — lexical by default, semantic when embeddings are enabled.
| Name | Type | Req | Description |
|---|---|---|---|
| json | boolean | – | Return raw JSON instead of formatted text (default false). Set true to parse fields programmatically. |
| limit | integer | – | Maximum number of memories to return (default 5). |
| query | string | yes | Natural-language description of the problem or topic to find prior work for, e.g. "token refresh before opening socket". |
| type | string | – | Optional filter to one memory category. Omit to recall across all types. |
No output schema declared.
No examples provided.
ygg_remember Save a durable memory ~320
Persist ONE atomic, reusable fact (a decision, lesson, fix, convention, or status) to a project's durable memory for future sessions. Call right after you decide something, learn a lesson, or fix a non-obvious bug; store one idea per call, phrased to stand alone. Near-duplicates are merged automatically and obvious secrets (API keys, tokens) are refused. Returns the saved memory id.
| Name | Type | Req | Description |
|---|---|---|---|
| confidence | number | – | Optional confidence 0.0–1.0; higher ranks the memory more strongly in recall. Defaults to the engine's standard for tool writes. |
| content | string | yes | The single durable fact — one atomic idea, phrased so it stays useful with no surrounding context. |
| contradicts | string | – | Optional id of a memory this one CONTRADICTS — both stay active, the dispute is recorded for review. |
| project | string | yes | Project this fact belongs to — usually the git repo name, e.g. "checkout-api". |
| solves | string | – | Optional id of a memory this one SOLVES (e.g. this fix resolves that open follow_up) — links them in the relation graph. |
| source | string | – | Provenance tag for where this memory came from (default "ygg-mcp"). Usually leave as default. |
| supersedes | string | – | Optional id of a memory this one REPLACES — records a SUPERSEDES edge and archives the old memory (reversible). |
| type | string | yes | Memory category that best fits the fact. |
No output schema declared.
No examples provided.
ygg_search Search one project's memory ~196
Search ONE project's durable memory with a free-text query and optional type filter — the precise, in-project lookup. Use when you know the project and want specific matches (e.g. every 'fix' about auth); for cross-project discovery use ygg_recall, to load a project's whole context use ygg_bootstrap. Lexical BM25 plus semantic ranking when embeddings are enabled.
| Name | Type | Req | Description |
|---|---|---|---|
| json | boolean | – | Return raw JSON instead of formatted text (default false). Set true to parse fields programmatically. |
| limit | integer | – | Maximum results to return (default 5). |
| project | string | yes | Project to search within — typically the git repo name, e.g. "webdesk". |
| query | string | yes | Free-text query describing what you're looking for, e.g. "flaky e2e tests". |
| type | string | – | Optional filter to one memory category. Omit to search all types. |
No output schema declared.
No examples provided.
What is the io.github.VonderVuflya/yggdrasil MCP server?
io.github.VonderVuflya/yggdrasil is an MCP server listed in the public MCP registry as io.github.VonderVuflya/yggdrasil. One shared, durable memory for your AI coding agents, local-first, zero-dependency. This page covers its PyPI package (yggdrasil-memory).
Is the io.github.VonderVuflya/yggdrasil MCP server safe to use?
io.github.VonderVuflya/yggdrasil scores 60 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.VonderVuflya/yggdrasil MCP server expose?
io.github.VonderVuflya/yggdrasil exposes 6 tools: ygg_health, ygg_recall, ygg_bootstrap, ygg_search, ygg_remember, ygg_materialize. Their descriptions and schemas cost roughly 1,102 tokens of context every time the server is loaded.
Is the io.github.VonderVuflya/yggdrasil MCP server still maintained?
io.github.VonderVuflya/yggdrasil is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.