# cuemap-mcp

Local memory and context retrieval for AI agents through CueMap.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.7.4
- **Author:** io.github.cuemap-dev
- **License:** Unknown
- **npm:** cuemap-mcp
- **Source:** https://github.com/cuemap-dev/cuemap-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 14 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-21T17:00:52.951Z
- **Version scanned:** 0.7.4
- **CVEs:** none found by OSV at scan time

## Tools

31 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `cuemap_init_preview` — Preview supported repository files without ingesting content. Call this before first-time repository initialization, present the grouped paths to the user, and 
- `cuemap_init` — Apply a user-confirmed repository ingestion scope and start CueMap's incremental filesystem watcher. Always call cuemap_init_preview first for a new repository 
- `cuemap_add` — Store a natural-language memory in CueMap. Uses the repository-scoped default project unless one is supplied, creates it when needed, and applies deterministic 
- `cuemap_intent_classify` — Classify text with CueMap's local intent model and return recall/memory eligibility signals. Scores are ranking signals, not calibrated probabilities.
- `cuemap_status` — Check CueMap background ingestion progress for a project. After cuemap_init, poll this tool until verified_complete is true. An initial idle status with 0/0 wri
- `cuemap_projects` — List CueMap projects, summary metadata, and whether each project is currently loaded in RAM.
- `cuemap_project_save` — Persist the current state of a CueMap project without unloading it. Package operations save automatically; use this only when an explicit durable checkpoint is 
- `cuemap_project_load` — Load a persisted CueMap project into RAM before a latency-sensitive operation. Normal project requests load automatically, so use this for explicit warm-up.
- `cuemap_project_unload` — Persist and unload a CueMap project from RAM to reduce memory use. Use only when the user explicitly asks to unload or free inactive project memory; active proj
- `cuemap_project_pack` — Write a ready-to-query .cuemap package for one project to a local file. The package contains sensitive project content; use only after the user explicitly appro
- `cuemap_project_package_load` — Install and warm a local .cuemap package. Use only after the user explicitly approves the exact package path; existing projects are never overwritten.
- `cuemap_project_push` — Pack and upload a CueMap project with the engine host's configured AWS CLI. Use only after explicit approval of the exact S3 destination; an existing object at 
- `cuemap_project_pull` — Download, install, and warm a .cuemap package with the engine host's configured AWS CLI. Use only after explicit approval of the exact S3 source; existing proje
- `cuemap_project_sync` — Fast-forward a project through immutable history at an S3 sync root. Pushes local-only changes, pulls remote-only changes, and refuses divergent histories or st
- `cuemap_stats` — Read CueMap statistics for the repository-scoped project or globally across the engine.
- `cuemap_memory_get` — Get one stored memory as readable text with source metadata. Pass the memory_id and owning project_id from recall as memory_id and project. Does not expand neig
- `cuemap_memory_reinforce` — Reinforce one CueMap memory, optionally along specific cue pathways.
- `cuemap_memory_delete` — Permanently delete one CueMap memory. Set confirmed=true only after explicit user confirmation.
- `cuemap_ingest_url` — Explicitly ingest content from a URL, optionally crawling same-domain links. Use only when the user asks to ingest that URL.
- `cuemap_ingest_content` — Explicitly ingest supplied raw content into CueMap. Use only when the user asks to persist that content.
- `cuemap_ingest_file` — Explicitly ingest one local file into CueMap. Use only for a file the user has placed in scope and asked to ingest.
- `cuemap_project_export` — Export a cursor-paginated page of memories from a CueMap project.
- `cuemap_project_artifacts` — Inspect CueBridge artifact metadata for a CueMap project without reloading or mutating it.
- `cuemap_alias_list` — List manual cue aliases associated with one cue.
- `cuemap_alias_add` — Add a manual weighted mapping from one cue to another.
- `cuemap_alias_merge` — Merge multiple cues into one canonical cue. Set confirmed=true only after explicit user confirmation.
- `cuemap_lexicon_inspect` — Inspect one cue and its Lexicon relationships.
- `cuemap_lexicon_graph` — Read the current Lexicon graph for a project.
- `cuemap_lexicon_wire` — Manually wire a token to a canonical Lexicon cue.
- `cuemap_lexicon_delete` — Permanently delete one Lexicon entry. Set confirmed=true only after explicit user confirmation.
- `cuemap_recall` — Recall evidence for a focused question; follow up with narrower queries as needed. Returns engine JSON with project_id and memory_id handles, source metadata, a

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"cuemap\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"cuemap-mcp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on your machine.
- Floor 37, ceiling 61 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/cuemap-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/cuemap-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/cuemap-mcp
- HTML page: https://forgeregistry.com/registry/cuemap-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
