
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
cortex-brain
Advanced tools
Give your AI agents a company brain. MCP server over a markdown knowledge base: cited articles, freshness tracking, open questions, and a safe inbox write path.
Give your AI agents a company brain.
An MCP server over a plain-markdown knowledge base — cited articles, freshness tracking, open questions, and a safe write path. Your agents stop re-asking the same questions and start consulting (and growing) a shared, auditable memory of how your company actually works.
npx cortex-brain init my-brain # scaffold a brain (12-domain taxonomy + conventions)
npx cortex-brain my-brain # serve it to agents over MCP
"AI agents need a living map of how a company works — knowledge extracted from scattered sources into executable form, so agents can actually do the work safely and consistently." — the "Company Brain" thesis (YC RFS)
Generic memory stores remember strings. A brain is structured: who said it, when, how fresh it is, what's still disputed. cortex-brain implements the cortex conventions — proven in production as an internal team wiki pattern — as five MCP tools any agent can use.
| Tool | What it does |
|---|---|
brain_search | Keyword search across all articles. Hits carry freshness (current/aging/stale/historical) so agents can judge reliability. |
brain_get_article | Full article: markdown + frontmatter — title, domain, tags, sources (who/when/where), linked open questions. |
brain_file | The single sanctioned write path: drops knowledge into inbox/ with a metadata header. A curator (human or agent) summarizes it into the wiki later — agents never mutate articles directly. |
brain_list_questions | Unresolved conflicts and code/wiki mismatches (q-NNN). Agents that learn an answer file it back. |
brain_status | Health report: coverage by domain, freshness distribution, stale articles, empty domains, pending inbox drops. |
{
"mcpServers": {
"company-brain": {
"command": "npx",
"args": ["-y", "cortex-brain", "/path/to/your/brain"]
}
}
}
Works on any cortex-style markdown knowledge base — including ones you already have. No database, no embeddings, no API keys: the markdown is the store, git is the history, humans can read every byte.
The brain stays trustworthy because of five rules (enforced/encouraged by the tools):
[sN], resolving to a frontmatter
sources: entry (who, when, type, ref).current (≤60d) → aging (≤6mo) → stale;
historical is deliberate and never auto-promoted. Computed live from
frontmatter dates.state: local | staged | merged | deployed | n/a. Proposed work is never written up as shipped.inbox/; a curator owns the wiki.
Conflicts become open questions, never silent overwrites.q-NNN), tracked to
resolution.---
title: Auth and Permissions
domain: products/atlas
last_updated: 2026-06-01
freshness: current
tags: [auth, rbac]
sources:
- id: s1
who: dana
when: 2026-06-01
type: meeting
ref: resource-bin/products/atlas/2026-06-01-auth-sync.md
open_questions: [q-002]
---
# Auth and Permissions
Access tokens expire after 15 minutes. [s1]
cortex-brain init <dir> [--name <SystemName>] Scaffold a new brain
cortex-brain <brain-path> Serve as MCP (stdio)
cortex-brain <brain-path> --status Print health report, exit
import { scanBrain, buildIndex, searchBrain, brainStatus } from "cortex-brain";
const articles = await scanBrain("./my-brain");
const hits = searchBrain(buildIndex(articles), articles, "deployment process");
npm install
npm test # vitest, 80%+ coverage enforced
npm run build
node scripts/smoke.mjs # E2E: real MCP client over stdio, all five tools
MIT
FAQs
Give your AI agents a company brain. MCP server over a markdown knowledge base: cited articles, freshness tracking, open questions, and a safe inbox write path.
The npm package cortex-brain receives a total of 6 weekly downloads. As such, cortex-brain popularity was classified as not popular.
We found that cortex-brain demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.