arrowmem-mcp
Free Ollama hardening checker, plus tools for privacy architecture and the Data Dignity Standard.
我該用這個嗎
品質與安全性
根據工具定義與協定合規性的自動化分析。
上下文成本
這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。
安裝
一鍵安裝
將以下內容加入你的 `claude_desktop_config.json` 檔案:
{
"mcpServers": {
"arrowmem-mcp": {
"url": "https://mcp.arrowmem.ca/mcp"
}
}
}遠端端點
https://mcp.arrowmem.ca/mcpstreamable-http它能做什麼
工具清單
工具(14)
🟢check_exposed_services(platform, ollama_listen_addresses, postgres_listen_addresses, mongodb_listen_addresses, redis_listen_addresses, ...)
ArrowMem Guard's machine security sweep, given diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Checks whether a model server and common database, search and notebook services are reachable beyond loopback, plus firewall state, disk encryption, screen lock, and pending OS updates - each resolves to PASS, FAIL, or UNVERIFIABLE (never guessed on missing data). The report leads with the highest-severity unresolved finding and names one first action, then lists every result in full with a complete per-OS fix and verify step. States plainly that a service bound wide is not the same claim as internet-reachable (this tool can see local configuration, not your network path). Limits: no signature or malware detection, no behavioural analysis, no filesystem or traffic monitoring. Nothing you submit is stored, logged, or retained; each call is evaluated in isolation. Paid tool - requires a valid API key.
輸入結構描述
{
"type": "object",
"properties": {
"platform": {
"type": "string",
"enum": [
"windows",
"mac",
"linux"
]
},
"ollama_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"postgres_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"mongodb_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"redis_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"elasticsearch_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"jupyter_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"firewall_status_text": {
"type": "string",
"maxLength": 4000
},
"disk_encryption_status_text": {
"type": "string",
"maxLength": 4000
},
"screen_lock_status_text": {
"type": "string",
"maxLength": 4000
},
"pending_os_updates_count": {
"type": "integer",
"minimum": 0
}
},
"additionalProperties": false
}🟢check_ollama_hardening(platform, ollama_host_env, ollama_listen_addresses, caddy_listen_addresses, caddyfile_text, ...)
Checks whether a self-hosted model server install still matches the hardening guide's defaults, given the diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Checks: host environment variable safety, loopback-only reachability on the model server and reverse proxy ports, the reverse proxy configuration's bind directive and credential enforcement, a unique (non-shared) credential, and disk encryption - each check resolves to PASS, FAIL, or UNVERIFIABLE (never guessed), the same three per-check states the doctor script uses. The OVERALL verdict differs from the script's own stricter rule, which collapses any UNVERIFIABLE into a failed run: this tool reports an UNVERIFIABLE-only result as UNVERIFIABLE, not an asserted failure it never measured. Nothing you submit is stored, logged, or retained; each call is evaluated in isolation and returns a per-check verdict. Cannot verify mesh-only reachability (no live network probe) and cannot detect drift after the moment you ran the diagnostics. Free tool, no API key required.
輸入結構描述
{
"type": "object",
"properties": {
"platform": {
"type": "string",
"enum": [
"windows",
"mac",
"linux"
]
},
"ollama_host_env": {
"type": "string",
"maxLength": 300
},
"ollama_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"caddy_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
},
"caddyfile_text": {
"type": "string",
"maxLength": 20000
},
"disk_encryption_status_text": {
"type": "string",
"maxLength": 4000
}
},
"additionalProperties": false
}🟢check_ollama_loopback(ollama_host_env, ollama_listen_addresses)
Checks one thing: whether your self-hosted model server is reachable from outside the machine. Given the diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Resolves to PASS, FAIL, or UNVERIFIABLE (never guessed). On FAIL, returns the complete fix. Nothing you submit is stored, logged, or retained.
輸入結構描述
{
"type": "object",
"properties": {
"ollama_host_env": {
"type": "string",
"maxLength": 300
},
"ollama_listen_addresses": {
"type": "array",
"maxItems": 20,
"items": {
"type": "string",
"maxLength": 100
}
}
},
"additionalProperties": false
}🔴disable_alert_relay
Ends this API key's ArrowMem Guard alert relay enrolment. No arguments. Your family link stops resolving, your old topic gets one fixed notice that the relay ended, and every relay attribute is removed from your key's row; it mints nothing, and calling it again is a no-op. Your key, usage, cap and subscription are untouched; call enrol_alert_relay afterward to enrol again. Paid tool - requires a valid API key. Spends one call.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}🔴enrol_alert_relay
Enrols this API key in the ArrowMem Guard alert relay (the watchdog page and the family 'Is It Really Me' check). Mints a relay token stored beside your key and returns an alert topic derived from it (subscribe to it once, in a push notification app, on your own phone), plus a one-time family link you share with the one person you want able to check on you if a call sounds like you and asks for money. No arguments. On an already-enrolled key it returns the SAME topic and no new family link (never re-shown once given). To replace the topic or the link use rotate_alert_relay; to end the enrolment use disable_alert_relay. Honest limit: ArrowMem can derive this topic from what it stores, so a topic is public-by-name the moment it exists - every page sent over it is a fixed, contentless sentence, never your real findings or any personal detail. The family check cannot be faked the same way; an answer comes back through the server, bound to a one-time token, and only proves someone holding the phone tapped Yes or No. Paid tool - requires a valid API key. Spends one call. A family member's own ask also spends one call from your plan, so you can see a leaked link being used.
輸入結構描述
{
"type": "object",
"properties": {},
"additionalProperties": false
}🟢get_arrowbridge_info
ArrowBridge, the local-first / own-hardware half of ArrowMem's privacy design - what it does today and what is still planned, not live.
輸入結構描述
{
"type": "object",
"properties": {}
}🟢get_data_dignity_standard
The Data Dignity Standard (v0.5, draft for public comment): a free, open, testable standard for what happens to a person's data when an AI agent interacts with a site on their behalf, and how sites and agents are graded against it.
輸入結構描述
{
"type": "object",
"properties": {}
}🟢get_hardening_guide
The full, live-tested procedure for hardening a self-hosted model server (mesh-only reachability, loopback-only bind, unique per-install credentials, disk encryption, a doctor script). Free tool, no API key required.
輸入結構描述
{
"type": "object",
"properties": {}
}🟢get_org_info
ArrowMem Inc. is a Canadian company that makes ArrowMem, a personal AI assistant. This tool returns the company's own published overview: what ArrowMem is, who operates it, and its official site.
輸入結構描述
{
"type": "object",
"properties": {}
}🟢get_privacy_model
ArrowMem's privacy and security architecture: zero retention, client-side encryption, processing-location disclosure, and how the business is funded without reading user content.
輸入結構描述
{
"type": "object",
"properties": {}
}🟢get_verified_business_facts(business_name, city)
Looks up hand-verified facts about a local business by name and city: legal name, locations, published prices (each with its source URL and the date it was verified), hours, an ownership statement, the audit date, and what is not yet verified. Every record was entered by hand from the business's own published sources, with the business's written consent to be published here. A business not found returns a plain NOT_FOUND result. Free tool, no API key required.
輸入結構描述
{
"type": "object",
"properties": {
"business_name": {
"type": "string",
"maxLength": 200
},
"city": {
"type": "string",
"maxLength": 200
}
},
"required": [
"business_name",
"city"
],
"additionalProperties": false
}🟢inventory_ai_agents(claude_desktop_config_text, claude_code_user_config_text, claude_code_project_config_text, cursor_global_config_text, cursor_project_config_text, ...)
Lists every AI tool configuration on this machine and every tool each one exposes at the config level, plus which agent hosts could not be checked and why. AI tools whose connectors live in your provider account, not a local file, so they are always reported UNVERIFIABLE by design with where to check instead - never silently omitted. Free and stateless: this call has no memory of a prior one, so it lists what is configured, it does not detect what changed since you last looked. Nothing you submit is stored, logged, or retained.
輸入結構描述
{
"type": "object",
"properties": {
"claude_desktop_config_text": {
"type": "string",
"maxLength": 300000
},
"claude_code_user_config_text": {
"type": "string",
"maxLength": 300000
},
"claude_code_project_config_text": {
"type": "string",
"maxLength": 300000
},
"cursor_global_config_text": {
"type": "string",
"maxLength": 300000
},
"cursor_project_config_text": {
"type": "string",
"maxLength": 300000
},
"claude_desktop_tools_text": {
"type": "string",
"maxLength": 500000
},
"claude_code_user_tools_text": {
"type": "string",
"maxLength": 500000
},
"claude_code_project_tools_text": {
"type": "string",
"maxLength": 500000
},
"cursor_global_tools_text": {
"type": "string",
"maxLength": 500000
},
"cursor_project_tools_text": {
"type": "string",
"maxLength": 500000
}
},
"additionalProperties": false
}🟢list_packs
The specific government disability-claim packs that run inside ArrowMem, and how the optional cross-device sync tier works.
輸入結構描述
{
"type": "object",
"properties": {}
}🔴rotate_alert_relay(scope)
Replaces part of this API key's ArrowMem Guard alert relay enrolment. Argument: {"scope": "topic"|"family"|"both"} (required). scope="topic" replaces the relay token only (the old topic gets one notice that it is changing, then stops being used) - your family link keeps working. scope="family" replaces the family link only (the old one stops working) and returns the new link - your topic is unchanged. scope="both" does both. Your key, usage, cap and subscription are untouched. Requires an existing enrolment (enrol_alert_relay). Paid tool - requires a valid API key. Spends one call.
輸入結構描述
{
"type": "object",
"properties": {
"scope": {
"type": "string",
"enum": [
"topic",
"family",
"both"
]
}
},
"required": [
"scope"
],
"additionalProperties": false
}社群
證據