Agent skill

Codebase Memory MCP

by vincentkoc in vincentkoc/dotskills

Resolve canonical Git checkouts, index and verify codebase-memory-mcp graphs through the guarded CLI, and safely audit duplicate worktree caches.

MITAuto-check passedDevelopment

Install Codebase Memory MCP

skills CLI
$ npx skills add vincentkoc/dotskills --skill codebase-memory-mcp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vincentkoc/dotskills codebase-memory-mcp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vincentkoc/dotskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codebase-memory-mcp .claude/skills/codebase-memory-mcp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codebase-memory-mcp
GitHub stars
107
Token cost
~3k tokens
SKILL.md length
1,244 words
Files
6 (incl. scripts, assets)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Resolve canonical Git checkouts, index and verify codebase-memory-mcp graphs through the guarded CLI, and safely audit duplicate worktree caches.

  • Works in 8 steps: Verify the repository and binary. → Resolve the canonical owning checkout. → Prefer exposed MCP graph tools for… → …
  • A user mentions codebase memory MCP
  • SKILL.md covers Purpose, When to use, Workflow and Inputs, plus 2 more sections
  • Runs Shell and Python scripts from its folder; calls git

What it does

Codebase Memory MCP is an agent skill from vincentkoc/dotskills. Resolve canonical Git checkouts, index and verify codebase-memory-mcp graphs through the guarded CLI, and safely audit duplicate worktree caches. Use when a user mentions codebase memory MCP, searchgraph, tracepath, indexrepository, worktree indexes, or oversized graph caches.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and assets (for example `agents/openai.yaml`, `scripts/codebase-memory-graph.sh` and `scripts/codebase_memory_cache.py`).

It sits in Development, covering Git worktrees and MCP servers. It works with Model Context Protocol and Git. The repository describes itself as: 🐙 A curated set of Codex and OpenClaw skills for workflow automation, technical debugging, and agent-assisted development patterns. The licence is MIT.

When your agent uses it

  • A user mentions codebase memory MCP
  • Indexrepository
  • Worktree indexes
  • Oversized graph caches

Example prompts

  • “/codebase-memory-mcp”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Verify the repository and binary.
  2. Resolve the canonical owning checkout.
  3. Prefer exposed MCP graph tools for discovery.
  4. Use the helper for CLI indexing.
  5. Verify the graph.
  6. Treat the UI as unavailable.
  7. Audit cache cleanup before applying it.
  8. Report exact proof.

What it can do on your machine

Read from SKILL.md and the folder at commit b83ca13. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codebase Memory MCP loads about 3k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from vincentkoc/dotskills at commit b83ca13, republished under its MIT licence (© vincentkoc). 1,244 words, ~2,964 tokens.

Download SKILL.mdSave it as .claude/skills/codebase-memory-mcp/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
codebase-memory-mcp
description
Resolve canonical Git checkouts, index and verify codebase-memory-mcp graphs through the guarded CLI, and safely audit duplicate worktree caches. Use when a user mentions codebase memory MCP, search_graph, trace_path, index_repository, worktree indexes, or oversized graph caches.
license
MIT
metadata.source
https://github.com/vincentkoc/dotskills

Codebase Memory MCP

Purpose

Bring up codebase-memory-mcp for the owning Git checkout and prove the graph is usable before relying on it for code discovery. Keep linked worktrees on the owner's graph instead of creating one graph per branch.

When to use

  • Initialize, re-index, refresh, or troubleshoot a repository graph.
  • Use search_graph, trace_path, get_code_snippet, or query_graph.
  • Verify that a repository is indexed before graph-backed exploration.
  • Audit or prune duplicate linked-worktree indexes without deleting cache files directly.

Workflow

  1. Verify the repository and binary.
    • git rev-parse --show-toplevel
    • git status -sb
    • command -v codebase-memory-mcp
    • codebase-memory-mcp --version
  2. Resolve the canonical owning checkout.
    • scripts/codebase-memory-graph.sh canonical --repo "$(git rev-parse --show-toplevel)"
    • Linked worktrees resolve through their absolute Git common directory to the one checkout that owns it.
    • Separate clones remain separate projects.
    • Independent roots under ~/.codex/worktrees, ~/GIT/_Worktrees, any .worktrees component, /tmp, or /private/tmp are never indexed. Linked worktrees under those paths may only rewrite to one existing nonreserved owner.
    • Never independently index ~/GIT/_Synthetic or repositories marked by .git/gwt-synthetic.json. This indexing rule grants no cleanup authority.
    • Missing, invalid, bare, ambiguous, ownerless, reserved-owner, or NUL-containing repositories fail closed.
  3. Prefer exposed MCP graph tools for discovery.
    • If the tool is absent, the service times out/closes its transport, or no usable project exists, report that surface once and continue ordinary code work with bounded rg and direct reads. Do not retry without changed service evidence. Graph availability is not a prerequisite for ordinary inspection or repair.
    • Installer or client configuration must separately disable the MCP index_repository tool because it cannot enforce the canonical indexing boundary. For Codex installs, render the private disabled_tools configuration accordingly.
    • When indexing is requested and the graph is missing, run scripts/codebase-memory-graph.sh index --repo "$(git rev-parse --show-toplevel)" --mode full. Do not start indexing or daemon repair as an incidental prerequisite to another task.
    • Use search_graph, trace_path, and get_code_snippet before broad text scans.
  4. Use the helper for CLI indexing.
    • scripts/codebase-memory-graph.sh init --repo "$(git rev-parse --show-toplevel)" --mode full
    • The helper always sends the canonical owning checkout to index_repository.
    • Use --mode fast for a smoke index.
    • Installer integrations render scripts/codebase-memory-gateway.py.tmpl with an approved pinned backend path. Replace @@PYTHON_PATH_SHEBANG@@ with the raw absolute interpreter path and replace @@PYTHON_PATH_JSON@@, @@BACKEND_PATH_JSON@@, and @@RESOLVER_PATH_JSON@@ with JSON string literals containing the exact absolute interpreter, backend, and codebase_memory_cache.py paths. The rendered gateway has no upgrade logic and uses execve for pass-through.
    • The gateway guards raw CLI calls only. Zero-argument MCP stdio startup intentionally passes through to the approved backend, so the gateway is not an MCP tool-filtering proxy and does not replace the separate disabled_tools control.
    • The public CLI accepts a tool name and at most one JSON object. It normalizes --json and --progress before checking index_repository; index calls always require an explicit JSON repo_path. File, stdin, worker, prefixed-command, and vendor-installer forms fail closed. Default output and explicit --json output keep their upstream formats.
    • Before activating a daemon-capable backend, verify auto_index=false, auto_watch=false, and UI disabled. Ordinary MCP clients can share one session-managed daemon. The gateway denies daemon start because version 0.10.8 enables the UI on a cold start; it permits only daemon status.
  5. Verify the graph.
    • codebase-memory-mcp cli list_projects
    • scripts/codebase-memory-graph.sh schema --repo "$(git rev-parse --show-toplevel)"
    • Run one focused graph query before declaring success.
  6. Treat the UI as unavailable.
    • start-ui and keepalive fail closed before configuration or process mutation.
    • UI startup remains disabled until upstream /api/index canonicalization can enforce the same boundary. status may report an already-running grandfathered listener.
  7. Audit cache cleanup before applying it.
    • Freeze a host-specific manifest: scripts/codebase-memory-graph.sh cache-audit --manifest /secure/path/cbm-cache.json
    • Built-in reserved roots are ~/.codex/worktrees, ~/GIT/_Worktrees, /tmp, /private/tmp, and any exact .worktrees path component. The audit records normalized lexical and resolved boundary evidence; .worktrees component matching is case-insensitive on Darwin.
    • Missing roots under a reserved boundary are reserved_missing_root candidates. Live valid graphs whose physical canonical root and Git common directory remain reserved are reserved_live_root candidates, including shallow, promisor, and partial clones. Dangling symlinks, bare repositories, non-Git roots, and invalid reserved mappings block as live_root_unmapped.
    • Other missing roots are protected unless the audit names an explicit narrow --ephemeral-prefix.
    • Reserved aliases or linked worktrees that resolve to a nonreserved owner retain duplicate cleanup rules. They require a mapped, registered, final-protected healthy full canonical graph; candidate graphs, reserved graphs, shallow/promisor/partial owners, missing alternate graphs, and ambiguous owners cannot preserve them.
    • When legacy home symlinks name the same physical checkout, preserve the exact canonical graph and treat only the symlink-named graph as a duplicate. Preserve a sole symlink-named graph.
    • Review the manifest, then dry-run it: scripts/codebase-memory-graph.sh cache-prune --manifest /secure/path/cbm-cache.json
    • Manifests with host blockers fail closed by default. After reviewing every relationship, explicitly add --allow-blocked-manifest to preflight and prune only independent candidates while preserving all protected and blocked projects.
    • To retain an exact manifest candidate at runtime, repeat --protect-candidate NAME on cache-prune. Each named candidate must still exist in the unchanged snapshot and pass its root, prefix, classification, canonical mapping, and clone-health rules. It remains in the expected snapshot but is excluded from cache inventory, holder sweeps, DB integrity preflight, final holder probes, and deletion.
    • Runtime candidate protection does not bypass host blockers; add --allow-blocked-manifest independently when blockers were reviewed. Unknown, duplicate, or non-candidate names fail before preflight.
    • Apply only the unchanged manifest: scripts/codebase-memory-graph.sh cache-prune --manifest /secure/path/cbm-cache.json --apply
    • Dry-run and apply freeze regular DB/WAL/SHM fingerprints for every eligible candidate in manifest order, rejecting a missing or size-mismatched DB, nonregular files, and nonzero WAL. Existing absolute paths are swept with /usr/sbin/lsof -nP -F0pfn -f -- in deterministic, NUL-parsed batches before any SQLite open and again after every exact mode=ro&immutable=1 quick_check; global fingerprint equality is required between phases. An absent or zero-byte WAL and a stable regular SHM are allowed. Use prune-only --lsof-timeout-seconds SECONDS to override the 300-second holder timeout within the guarded 30-900 range.
    • Batch holder sweeps are point-in-time checks: they do not prevent a legacy index or server surface from reopening a graph after the check. Unprivileged lsof may not see root-owned or other-user holders, so pruning trusts the point-in-time visibility available to the cache owner; running as root provides stronger holder visibility. Apply processes eligible candidates in manifest order, at most eight per deletion batch and within the same 128 KiB path budget. Each batch revalidates the snapshot and live fingerprints, performs one holder sweep, proves post-sweep fingerprint equality, then revalidates every remaining candidate relationship immediately before the first delete child. The batch launches only codebase-memory-mcp cli delete_project children and verifies registrations plus DB/WAL/SHM absence before continuing; spawn errors, timeouts, nonzero exits, retained registrations, residue, drift, or ambiguous state stop future batches and report launched, verified-deleted, failed, and ambiguous names and bytes.
    • Before applying any manifest containing reserved_live_root, deploy the reserved-root indexing prevention and quiesce every legacy index/server surface outside this helper. The helper reports this operational precondition but does not probe or kill processes.
    • Deletion uses codebase-memory-mcp cli delete_project only. Never remove project databases directly.
  8. Report exact proof.
    • Indexed project name.
    • Node and edge counts when available.
    • Any grandfathered UI listener reported by status.
    • For cleanup: manifest path and digest, manifest/eligible/preflighted candidate totals, runtime protected names/reasons/bytes, required operational preconditions, before/after project and byte totals, deleted project names, and any stop condition.
    • Missing binaries, unavailable MCP tools, or incomplete proof.
Show full SKILL.md (56 more words)Show less

Inputs

  • Repository path.
  • Index mode: fast, moderate, full, or cross-repo-intelligence.
  • Optional status listener port; default 9749.
  • For cache maintenance: a host-local manifest path, optional explicit ephemeral prefixes, and optional exact runtime protected candidate names.

Outputs

  • Indexed and queryable repository graph.
  • A dry-run cache manifest or guarded CLI-only deletion report.
  • Exact status, schema, and proof summary.

Flow

mermaid
stateDiagram-v2
    [*] --> ResolveCanonicalOwner
    ResolveCanonicalOwner --> ReportBlocked: missing, ambiguous, or reserved owner
    ResolveCanonicalOwner --> SelectTask: valid owning checkout
    state SelectTask <<choice>>
    SelectTask --> QueryGraph: discovery
    SelectTask --> GuardedIndex: indexing explicitly requested
    SelectTask --> AuditManifest: cache maintenance
    SelectTask --> ReportBlocked: UI startup requested
    GuardedIndex --> QueryGraph: index succeeds
    GuardedIndex --> ReportBlocked: index fails
    QueryGraph --> ReportProof: schema and focused query pass
    QueryGraph --> BoundedSourceSearch: graph unavailable during code work
    BoundedSourceSearch --> ReportProof: direct source findings with graph limitation
    QueryGraph --> ReportBlocked: requested graph repair remains unverified
    AuditManifest --> ReviewAndDryRun
    ReviewAndDryRun --> ReportProof: audit or dry-run only
    ReviewAndDryRun --> ApplyThroughCLI: apply requested and every precondition passes
    ReviewAndDryRun --> ReportBlocked: blockers or drift
    ApplyThroughCLI --> VerifyDeletion
    VerifyDeletion --> ReportProof: registration and files absent
    VerifyDeletion --> ReportBlocked: failure, residue, or ambiguity
    ReportProof --> [*]
    ReportBlocked --> [*]

© vincentkoc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, assets) in skills/codebase-memory-mcp of vincentkoc/dotskills.

  • SKILL.md
  • agents/openai.yaml
  • assets/icon.jpg
  • scripts/codebase-memory-gateway.py.tmpl
  • scripts/codebase-memory-graph.sh
  • scripts/codebase_memory_cache.py

Open the folder on GitHubat commit b83ca13

Compare with similar skills

Codebase Memory MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codebase Memory MCP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codebase Memory MCP this skillvincentkoc/dotskills107—~3kAutomated safety check: PassMIT
Devcontainer Devstacklok/toolhive-studio170—~3.8kAutomated safety check: NotesApache-2.0
Agent Deckasheshgoplani/agent-deck1k—~1.7kAutomated safety check: PassMIT
Puppetmaster Agent Orchestrationprofessorpalmer/Puppetmaster467—~3.2kAutomated safety check: PassMIT
Vibe Kanbanaiskillstore/marketplace430—~4.4kAutomated safety check: NotesNone
Lanes Sessionslanes-sh/app273—~4.3kAutomated safety check: PassNone

Similar skills

  • Devcontainer Dev

    stacklok/toolhive-studio

    Spin up and interact with ToolHive Studio's containerized dev environment (Xvfb + noVNC + DinD).

    170 GitHub stars~3.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Agent Deck

    asheshgoplani/agent-deck

    agent-deck, the terminal session manager for AI coding agents.

    1k GitHub stars~1.7k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Puppetmaster Agent Orchestration

    professorpalmer/Puppetmaster

    Operates and supervises Puppetmaster, a multi-agent orchestrator, through its MCP tools or CLI, picking the right verb for edits, reviews, audits and long-running jobs.

    467 GitHub stars~3.2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Vibe Kanban

    aiskillstore/marketplace

    Manage AI coding agents on a visual Kanban board. An agent skill from aiskillstore/marketplace.

    430 GitHub stars~4.4k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Lanes Sessions

    lanes-sh/app

    A skill your agent uses when managing Lanes issues or driving Claude Code sessions through the lanes MCP tools — creating issues, starting/stopping/inspecting sessions, batch-launching work across…

    273 GitHub stars~4.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Memtrace Decision Memory

    syncable-dev/memtrace-public

    Use Cortex decision memory through the normal Memtrace MCP tools.

    486 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from vincentkoc/dotskills

All 19 skills in this repo
  • Openclaw PR Batch Sweep

    vincentkoc/dotskills

    Select, review, repair, validate, and land batches of up to 20 low-risk OpenClaw contributor pull requests using Vincent's maintainer preferences and bounded sub-agent lanes.

    107 GitHub stars~4.1k tokensUpdated 5 days ago
    Auto-check passed
  • Tmux Agent Lane Orchestrator

    vincentkoc/dotskills

    Monitor and coordinate one tmux agent lane, reconstruct worker state from panes and recent Codex logs, classify progress and blockers, and produce concise manager summaries.

    107 GitHub stars~967 tokensUpdated 5 days ago
    Auto-check passed
  • Org Branch Cleanup

    vincentkoc/dotskills

    Audit and safely prune stale branches across a GitHub organization with immutable snapshots, conservative merged-PR classification, live SHA/protection/open-PR revalidation, resumable deletion…

    107 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check passed
  • Session Done

    vincentkoc/dotskills

    Prepare a concise session handoff when the user asks to wrap up, capture continuation context, or use /done.

    107 GitHub stars~833 tokensUpdated 5 days ago
    Auto-check passed
  • Codex Goal Mining

    vincentkoc/dotskills

    Mine structured Codex /goal history locally or across a configured machine fleet, measure active goal time and resumed thread spans, identify unfinished and recurring semantic runs, and turn them…

    107 GitHub stars~1.2k tokensUpdated 5 days ago
    Auto-check passed
  • Semantic Slicing

    vincentkoc/dotskills

    Build local semantic review slices by combining clawpatch feature maps, deepsec threat candidates, visual review maps, and optional gitcrawl/discrawl evidence for repos such as openclaw/openclaw.

    107 GitHub stars~2k tokensUpdated 5 days ago
    Auto-check passed

Questions about Codebase Memory MCP

What does Codebase Memory MCP do?

Resolve canonical Git checkouts, index and verify codebase-memory-mcp graphs through the guarded CLI, and safely audit duplicate worktree caches. Codebase Memory MCP is an agent skill from vincentkoc/dotskills. Resolve canonical Git checkouts, index and verify codebase-memory-mcp graphs through the guarded CLI, and safely audit duplicate worktree caches.

When should I use Codebase Memory MCP?

Codebase Memory MCP fits situations like: A user mentions codebase memory MCP; indexrepository; worktree indexes; oversized graph caches.

How do I install Codebase Memory MCP in Claude Code?

Run `npx skills add vincentkoc/dotskills --skill codebase-memory-mcp -a claude-code`. Or copy the skill folder (skills/codebase-memory-mcp in vincentkoc/dotskills) into .claude/skills/codebase-memory-mcp in your project. Claude Code loads it when a task matches its description.

How do I install Codebase Memory MCP in Codex?

Run `npx skills add vincentkoc/dotskills --skill codebase-memory-mcp -a codex`. Or copy the skill folder (skills/codebase-memory-mcp in vincentkoc/dotskills) into .agents/skills/codebase-memory-mcp in your project. Codex loads it when a task matches its description.

Can I use Codebase Memory MCP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vincentkoc/dotskills --skill codebase-memory-mcp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codebase-memory-mcp, .gemini/skills/codebase-memory-mcp, .github/skills/codebase-memory-mcp and .opencode/skills/codebase-memory-mcp in your project.

What does Codebase Memory MCP need to run?

Going by SKILL.md and its folder, Codebase Memory MCP needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: Python 3; A Bash shell.

Does Codebase Memory MCP access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codebase Memory MCP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Codebase Memory MCP use?

Codebase Memory MCP is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codebase Memory MCP use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codebase Memory MCP?

Skills that share tags, products or a category with Codebase Memory MCP: Devcontainer Dev (stacklok/toolhive-studio, 170 stars), Agent Deck (asheshgoplani/agent-deck, 1k stars), Puppetmaster Agent Orchestration (professorpalmer/Puppetmaster, 467 stars) and Vibe Kanban (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codebase Memory MCP?

vincentkoc (a GitHub user) maintains it in vincentkoc/dotskills, which has 107 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 2, 2026.

Source: vincentkoc/dotskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.