arrowmem-mcp
Server Details
Free Ollama hardening checker, plus tools for privacy architecture and the Data Dignity Standard.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-06-18
- URL
TDQS
Score is being calculated.
Available Tools
14 toolscheck_exposed_servicesRead-onlyInspect
ArrowMem Guard's machine security sweep, given diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Checks whether a model server and common database, search and notebook services are reachable beyond loopback, plus firewall state, disk encryption, screen lock, and pending OS updates - each resolves to PASS, FAIL, or UNVERIFIABLE (never guessed on missing data). The report leads with the highest-severity unresolved finding and names one first action, then lists every result in full with a complete per-OS fix and verify step. States plainly that a service bound wide is not the same claim as internet-reachable (this tool can see local configuration, not your network path). Limits: no signature or malware detection, no behavioural analysis, no filesystem or traffic monitoring. Nothing you submit is stored, logged, or retained; each call is evaluated in isolation. Paid tool - requires a valid API key.
| Name | Required | Description | Default |
|---|---|---|---|
| platform | No | ||
| firewall_status_text | No | ||
| redis_listen_addresses | No | ||
| ollama_listen_addresses | No | ||
| screen_lock_status_text | No | ||
| jupyter_listen_addresses | No | ||
| mongodb_listen_addresses | No | ||
| pending_os_updates_count | No | ||
| postgres_listen_addresses | No | ||
| disk_encryption_status_text | No | ||
| elasticsearch_listen_addresses | No |
check_ollama_hardeningRead-onlyIdempotentInspect
Checks whether a self-hosted model server install still matches the hardening guide's defaults, given the diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Checks: host environment variable safety, loopback-only reachability on the model server and reverse proxy ports, the reverse proxy configuration's bind directive and credential enforcement, a unique (non-shared) credential, and disk encryption - each check resolves to PASS, FAIL, or UNVERIFIABLE (never guessed), the same three per-check states the doctor script uses. The OVERALL verdict differs from the script's own stricter rule, which collapses any UNVERIFIABLE into a failed run: this tool reports an UNVERIFIABLE-only result as UNVERIFIABLE, not an asserted failure it never measured. Nothing you submit is stored, logged, or retained; each call is evaluated in isolation and returns a per-check verdict. Cannot verify mesh-only reachability (no live network probe) and cannot detect drift after the moment you ran the diagnostics. Free tool, no API key required.
| Name | Required | Description | Default |
|---|---|---|---|
| platform | No | ||
| caddyfile_text | No | ||
| ollama_host_env | No | ||
| caddy_listen_addresses | No | ||
| ollama_listen_addresses | No | ||
| disk_encryption_status_text | No |
check_ollama_loopbackRead-onlyIdempotentInspect
Checks one thing: whether your self-hosted model server is reachable from outside the machine. Given the diagnostic output your own machine (or AI tool) already produced locally - this tool never reaches your machine or network, it only reasons over what you send it. Resolves to PASS, FAIL, or UNVERIFIABLE (never guessed). On FAIL, returns the complete fix. Nothing you submit is stored, logged, or retained.
| Name | Required | Description | Default |
|---|---|---|---|
| ollama_host_env | No | ||
| ollama_listen_addresses | No |
disable_alert_relayDestructiveIdempotentInspect
Ends this API key's ArrowMem Guard alert relay enrolment. No arguments. Your family link stops resolving, your old topic gets one fixed notice that the relay ended, and every relay attribute is removed from your key's row; it mints nothing, and calling it again is a no-op. Your key, usage, cap and subscription are untouched; call enrol_alert_relay afterward to enrol again. Paid tool - requires a valid API key. Spends one call.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
enrol_alert_relayDestructiveIdempotentInspect
Enrols this API key in the ArrowMem Guard alert relay (the watchdog page and the family 'Is It Really Me' check). Mints a relay token stored beside your key and returns an alert topic derived from it (subscribe to it once, in a push notification app, on your own phone), plus a one-time family link you share with the one person you want able to check on you if a call sounds like you and asks for money. No arguments. On an already-enrolled key it returns the SAME topic and no new family link (never re-shown once given). To replace the topic or the link use rotate_alert_relay; to end the enrolment use disable_alert_relay. Honest limit: ArrowMem can derive this topic from what it stores, so a topic is public-by-name the moment it exists - every page sent over it is a fixed, contentless sentence, never your real findings or any personal detail. The family check cannot be faked the same way; an answer comes back through the server, bound to a one-time token, and only proves someone holding the phone tapped Yes or No. Paid tool - requires a valid API key. Spends one call. A family member's own ask also spends one call from your plan, so you can see a leaked link being used.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
get_arrowbridge_infoRead-onlyIdempotentInspect
ArrowBridge, the local-first / own-hardware half of ArrowMem's privacy design - what it does today and what is still planned, not live.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
get_data_dignity_standardRead-onlyIdempotentInspect
The Data Dignity Standard (v0.5, draft for public comment): a free, open, testable standard for what happens to a person's data when an AI agent interacts with a site on their behalf, and how sites and agents are graded against it.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
get_hardening_guideRead-onlyIdempotentInspect
The full, live-tested procedure for hardening a self-hosted model server (mesh-only reachability, loopback-only bind, unique per-install credentials, disk encryption, a doctor script). Free tool, no API key required.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
get_org_infoRead-onlyIdempotentInspect
ArrowMem Inc. is a Canadian company that makes ArrowMem, a personal AI assistant. This tool returns the company's own published overview: what ArrowMem is, who operates it, and its official site.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
get_privacy_modelRead-onlyIdempotentInspect
ArrowMem's privacy and security architecture: zero retention, client-side encryption, processing-location disclosure, and how the business is funded without reading user content.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
get_verified_business_factsRead-onlyIdempotentInspect
Looks up hand-verified facts about a local business by name and city: legal name, locations, published prices (each with its source URL and the date it was verified), hours, an ownership statement, the audit date, and what is not yet verified. Every record was entered by hand from the business's own published sources, with the business's written consent to be published here. A business not found returns a plain NOT_FOUND result. Free tool, no API key required.
| Name | Required | Description | Default |
|---|---|---|---|
| city | Yes | ||
| business_name | Yes |
inventory_ai_agentsRead-onlyIdempotentInspect
Lists every AI tool configuration on this machine and every tool each one exposes at the config level, plus which agent hosts could not be checked and why. AI tools whose connectors live in your provider account, not a local file, so they are always reported UNVERIFIABLE by design with where to check instead - never silently omitted. Free and stateless: this call has no memory of a prior one, so it lists what is configured, it does not detect what changed since you last looked. Nothing you submit is stored, logged, or retained.
| Name | Required | Description | Default |
|---|---|---|---|
| cursor_global_tools_text | No | ||
| claude_desktop_tools_text | No | ||
| cursor_global_config_text | No | ||
| cursor_project_tools_text | No | ||
| claude_desktop_config_text | No | ||
| cursor_project_config_text | No | ||
| claude_code_user_tools_text | No | ||
| claude_code_user_config_text | No | ||
| claude_code_project_tools_text | No | ||
| claude_code_project_config_text | No |
list_packsRead-onlyIdempotentInspect
The specific government disability-claim packs that run inside ArrowMem, and how the optional cross-device sync tier works.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
rotate_alert_relayDestructiveInspect
Replaces part of this API key's ArrowMem Guard alert relay enrolment. Argument: {"scope": "topic"|"family"|"both"} (required). scope="topic" replaces the relay token only (the old topic gets one notice that it is changing, then stops being used) - your family link keeps working. scope="family" replaces the family link only (the old one stops working) and returns the new link - your topic is unchanged. scope="both" does both. Your key, usage, cap and subscription are untouched. Requires an existing enrolment (enrol_alert_relay). Paid tool - requires a valid API key. Spends one call.
| Name | Required | Description | Default |
|---|---|---|---|
| scope | Yes |
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
14 tool updates
- First observed
check_exposed_services - First observed
check_ollama_hardening - First observed
check_ollama_loopback - First observed
disable_alert_relay - First observed
enrol_alert_relay - First observed
get_arrowbridge_info - First observed
get_data_dignity_standard - First observed
get_hardening_guide - First observed
get_org_info - First observed
get_privacy_model - First observed
get_verified_business_facts - First observed
inventory_ai_agents - First observed
list_packs - First observed
rotate_alert_relay
Related MCP Connectors
7 free tools: MCP health scans, AI-readiness scores, llms.txt generator, glossary, indexes.
Free OpenAI-compatible inference with signed provenance receipts and 3 focused MCP tools.
Search vetted privacy tools, read guides & glossary, and run free privacy diagnostics.
Free tools: 2026 API shutdown scanner, small-business website auditor, photo resale estimator.
Related MCP Servers
- AlicenseAqualityBmaintenanceSelf-hosted governance layer between an AI assistant and your data: allow/deny policy, deterministic PII masking, row caps, and a hash-chained audit log with an Ed25519-signed receipt for every access, verifiable offline.4236 npm3MIT
- AlicenseNot gradedqualityBmaintenanceLocal-first AI compliance scanner via Model Context Protocol, scanning codebases for violations of DPDPA 2023, RBI FREE-AI, SEBI AI/ML, and the EU AI Act.18 PyPI1Apache 2.0
- AlicenseAqualityBmaintenanceEnables observability and governance for local LLMs via Ollama, including auditing model usage, scanning prompts for secrets/PII, and enforcing allow/deny policies.21MIT
- AlicenseAqualityBmaintenanceProvides anonymous, privacy-preserving tools for AI agents, including prompt-injection scanning, site file validation, endpoint liveness checks, attestation, and risk-pattern analysis.34MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.