
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@putervision/state-memory-mcp
Advanced tools
Deterministic, persistent graph server for tracking workflow state, decisions, and blockers.
@putervision/state-memory-mcp is a zero-infrastructure, deterministic Model Context Protocol (MCP) server that provides AI coding assistants (such as Cursor, Claude Code, Gemini, or Copilot) with a structured, persistent SQLite graph for tracking workflow state—tasks, decisions, artifacts, plans, blockers, and their semantic relationships.
🌐 Official Documentation & Website: statememorymcp.com
Prerequisites: Node.js >= 18.18.0
# 1. Install globally
npm install -g @putervision/state-memory-mcp
# 2. Navigate to your project directory
cd your-project
# 3. Initialize state-memory-mcp
# Creates .state-memory-mcp/, updates .gitignore, registers project,
# and scaffolds IDE instructions and MCP configs for Cursor, Claude, VS Code, Windsurf, etc.
state-memory-mcp init
# Done! Restart your IDE or Agent Manager to activate.
# Run directly via binary (after global install)
state-memory-mcp run
# Re-initialize across all registered workspace projects
state-memory-mcp init-global
state-memory-mcp view).@putervision/vision-memory-mcp for visual state caching, perceptual hashing, and cryptographic multimodal evidence packs..state-memory-mcp/ in your workspace.@putervision/state-memory-mcp provides 13 production-grade consolidated MCP tools organized across 5 core workflow domains:
manage_nodes (node CRUD, FTS5/TF-IDF vector search, atomic batch mutations, observation notes), manage_edges (typed DAG links, multimodal visual state linking).manage_tasks (topological dependency queue, blocker detection, task completion with artifacts, auto-prune), manage_sessions (agent attribution, turn tracking, context bootstrap).manage_specs (PRD/RFC parsing, requirement-to-task decomposition, live acceptance criteria verification, compliance scoring).get_analytics (velocity, burndown, token ROI, cognitive load, critical path), get_events (SHA-256 tamper-evident event ledger), run_diagnostics (DAG validation, health checks, AST reference integrity).manage_snapshots (checkpoints, time-travel undo), manage_database (backups, checksum audits, VCS branch merge), manage_data (bulk import/export, ML trajectories), query_graph (subgraphs, dependency tracing, raw SQL), use_blackboard (multi-agent asynchronous topic board).👉 For complete parameter specifications, return schemas, and example payloads, see the Tools Reference Guide and Formal API Reference.
AI Agent Prompt / Task
│
▼
┌─────────────────────────────────┐
│ Agent Session Attribution │ ──▶ manage_sessions(action: "start")
└────────────────┬────────────────┘
│
▼
┌─────────────────────────────────┐
│ Context & Task Prioritization │ ──▶ get_analytics(action: "summary")
│ │ ──▶ manage_tasks(action: "next")
└────────────────┬────────────────┘
│
▼
┌─────────────────────────────────┐
│ Deterministic Graph Mutation │ ──▶ manage_nodes(action: "create"|"update")
│ (Tasks, Decisions, Blockers) │ ──▶ manage_edges(action: "add"|"link_visual")
└────────────────┬────────────────┘
│
▼
┌─────────────────────────────────┐
│ Spec & Integrity Verification │ ──▶ manage_specs(action: "compliance"|"verify")
│ │ ──▶ run_diagnostics(action: "validate")
└────────────────┬────────────────┘
│
▼
┌─────────────────────────────────┐
│ Persistent SQLite Storage │ ──▶ .state-memory-mcp/graph.db (WAL mode)
│ Append-Only Event Ledger │ ──▶ SHA-256 Cryptographic Audit Chain
└─────────────────────────────────┘
Explore dedicated guides and deep dives in the docs/ directory:
| Guide | Description |
|---|---|
| 🏗️ Architecture & Codebase Distillation | High-signal architectural overview, module inventory, data flows, and design decisions. |
| 🚀 v0.10 → v1.0 Migration Guide | Step-by-step migration guide, legacy tool mapping table, and STATE_MEMORY_COMPAT mode. |
| 💡 Value Proposition & Theory | Cognitive Externalization, FSM Formalism, First-Hop Determinism & Benchmark metrics. |
| 📋 State Memory Concepts | Node Types (task, decision, blocker...), Status Values, Typed Edges & Seeding Guidelines. |
| ⚙️ Configuration & IDE Setup | Auto-Initialization details, Environment Variables table, and Editor Configs (Cursor, VS Code, Claude, Antigravity, Windsurf). |
| 🛠️ CLI Command Reference | CLI flags (init, run, view, inspect, metrics, audit, doctor, backup, restore, merge) & Git Scanner. |
| ⏱️ Sessions, Snapshots & SDD | Session Lifecycle, Event Audit Trail, Snapshots, Trajectories, Sub-directory support & Spec-Driven Development. |
| 🧰 Tools, Resources & Prompts | Complete reference for all 13 Consolidated MCP Tools, read-only state-memory:/// Resources, and Prompt templates. |
| 📘 Formal API Reference | Formal parameters, return schemas, and code signatures for all MCP endpoints. |
| 🎨 3D Visualizer Guide | Viewing and exporting the interactive WebGL 3D Force-Directed Graph visualizer. |
| 🗄️ Database Schema | SQLite tables, columns, indexes, and schema migration history. |
When an autonomous AI agent enters a repository with state-memory-mcp:
1. Orient & Bootstrap ──▶ manage_sessions(action: "start") + get_analytics(action: "summary")
2. Task Selection ──▶ manage_tasks(action: "next") + manage_tasks(action: "find_blockers")
3. Trace Context ──▶ query_graph(action: "trace") + manage_specs(action: "compliance")
4. Execute & Record ──▶ manage_nodes(action: "create", type: "decision") + manage_edges(action: "link_visual")
5. Validate & Close ──▶ run_diagnostics(action: "validate") + manage_tasks(action: "complete") + manage_sessions(action: "end")
# Run full unit, integration, and performance benchmark test suite across all 113 test files (418 tests)
npm run test
Developed and maintained by PuterVision. Released under the MIT License.
FAQs
Deterministic, persistent graph server for tracking workflow state, decisions, and blockers.
We found that @putervision/state-memory-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.