Sugar — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Sugar (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
Score rose 26 points between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
Autonomous issue resolution for AI-assisted development.
<!-- mcp-name: io.github.cdnsteve/sugar -->
Security scanners find vulnerabilities. Dependabot opens issues. Copilot flags problems. Sugar reads the issue, writes the fix, runs the tests, and opens the PR.
No issue left sitting in a backlog waiting for someone to have time.
Most AI dev tools stop at the discovery layer:
GitHub Copilot CLI -> scan -> open issues
Snyk -> scan -> open issues
Dependabot -> scan -> open issuesSugar is the resolution layer:
Labeled issue appears on GitHub
-> Sugar picks it up (label filter: "security", "dependabot", "bug")
-> AI agent reads the issue, analyzes the affected code
-> Fix implemented, tests run locally
-> PR opened - you review and mergeConfigure which labels Sugar watches, point it at your repo, and run sugar run.
See workflow examples for security auto-fix, bug triage, test coverage, and more.
Sugar combines persistent memory with autonomous task execution:
# Install once, use in any project
pipx install sugarai
# Initialize in your project
cd ~/dev/my-app
sugar init
# Store what you know
sugar remember "We use async/await everywhere, never callbacks" --type preference
sugar remember "JWT tokens use RS256, expire in 15 min - see auth/tokens.py" --type decision
sugar remember "When tests fail with import errors, check __init__.py exports first" --type error_pattern
# Retrieve it later
sugar recall "authentication"
sugar recall "how do we handle async"Your AI agent can also read and write memory directly - no copy-pasting required.
Connect Sugar's memory to your AI agent so it can access project context automatically.
Claude Code - Memory server (primary):
claude mcp add sugar -- sugar mcp memoryClaude Code - Task server (optional):
claude mcp add sugar-tasks -- sugar mcp tasksOnce connected, Claude can call store_learning to save context mid-session and search_memories to pull relevant knowledge before starting work. The memory server works from any directory - global memory is always available even outside a Sugar project.
Other MCP clients (Goose, Claude Desktop):
# Goose
goose configure
# Select "Add Extension" -> "Command-line Extension"
# Name: sugar
# Command: sugar mcp memory
# OpenCode - one command setup
sugar opencode setupSome knowledge belongs to you, not just one project. Coding standards, preferred patterns, security practices - these should follow you everywhere.
# Store a guideline that applies to all your projects
sugar remember "Always validate and sanitize user input before any DB query" \
--type guideline --global
sugar remember "Use conventional commits: feat/fix/chore/docs/test" \
--type guideline --global
# View your global guidelines
sugar recall "security" --global
sugar memories --global
# Search works project-first, but guidelines always surface
sugar recall "database queries"
# Returns: project-specific memories + relevant global guidelinesGlobal memory lives at ~/.sugar/memory.db. Project memory lives at .sugar/memory.db. When you search, project context wins - but guideline type memories from global always appear in results so your standards stay visible.
Via MCP, pass scope: "global" to store_learning to save cross-project knowledge directly from your AI session.
Memory types: decision, preference, file_context, error_pattern, research, outcome, guideline
Full docs: Memory System Guide
Sugar uses two SQLite databases and a tiered search strategy.
Two stores:
.sugar/memory.db) - context specific to one project~/.sugar/memory.db) - knowledge that applies everywhereSeven memory types, each with different retrieval behavior:
| Type | Purpose | TTL |
|---|---|---|
decision | Architecture and implementation choices | Never |
preference | How you like things done | Never |
file_context | What files and modules do | Never |
error_pattern | Bugs and their fixes | 90 days |
research | API docs, library findings | 60 days |
outcome | What worked, what didn't | 30 days |
guideline | Cross-project standards and best practices | Never |
Search strategy - project-first with reserved guideline slots:
This means a mature project's local context dominates results. A new project with no local memory gets global knowledge automatically. And your guidelines are always visible regardless.
Search engine: Semantic search via sentence-transformers (all-MiniLM-L6-v2, 384-dim vectors) with sqlite-vec. Falls back to SQLite FTS5 keyword search, then LIKE queries. No external API calls - everything runs locally.
# Install with semantic search (recommended)
pipx install 'sugarai[memory]'
# Works without it too - just uses keyword matching
pipx install sugaraiMCP tools available to your AI agent:
| Tool | What it does |
|---|---|
search_memory | Search both stores, returns results with scope labels |
store_learning | Save a memory (pass scope: "global" for cross-project) |
recall | Get formatted markdown context for a topic |
get_project_context | Full project summary including global guidelines |
list_recent_memories | Browse recent memories by type |
MCP resources:
sugar://project/context - project summarysugar://preferences - coding preferencessugar://global/guidelines - cross-project standardsThe task queue lets you hand off work and let it run autonomously. It reads from the same memory store, so Sugar already knows your preferences and patterns before it starts.
# Add tasks
sugar add "Fix authentication timeout" --type bug_fix --urgent
sugar add "Add user profile settings" --type feature
# Start the autonomous loop
sugar runSugar picks up tasks, executes them with your configured AI agent, runs tests, commits working code, and moves to the next task. It runs until the queue is empty or you stop it.
Delegate from Claude Code mid-session:
/sugar-task "Fix login timeout" --type bug_fix --urgentAdvanced task options:
# Orchestrated execution (research -> plan -> implement -> review)
sugar add "Add OAuth authentication" --type feature --orchestrate
# Iterative mode - loops until tests pass
sugar add "Implement rate limiting" --ralph --max-iterations 10
# Check queue status
sugar list
sugar statusFull docs: Task Orchestration
Works with any CLI-based AI coding agent:
| Agent | Memory MCP | Task MCP | Notes |
|---|---|---|---|
| Claude Code | Yes | Yes | Full support |
| OpenCode | Yes | Yes | sugar opencode setup |
| Goose | Yes | Yes | Via MCP |
| Aider | Via CLI | Via CLI | Manual recall |
Recommended: pipx - installs once, available everywhere, no venv conflicts:
pipx install sugaraiUpgrade / Uninstall:
pipx upgrade sugarai
pipx uninstall sugarai<details> <summary>Other installation methods</summary>
pip (requires venv activation each session)
pip install sugaraiuv
uv pip install sugaraiWith semantic search (recommended for memory):
pipx install 'sugarai[memory]'With GitHub integration:
pipx install 'sugarai[github]'All features:
pipx install 'sugarai[all]'</details>
Sugar is project-local by default. Each project gets its own .sugar/ folder with its own database and config. Global memory lives at ~/.sugar/. Like git - one installation, per-project state.
~/.sugar/
└── memory.db # Global memory (guidelines, cross-project knowledge)
~/dev/my-app/
├── .sugar/
│ ├── sugar.db # Project memory + task queue
│ ├── config.yaml # Project settings
│ └── prompts/ # Custom agent prompts
└── src/Recommended .gitignore:
.sugar/sugar.db
.sugar/sugar.log
.sugar/*.db-*Commit .sugar/config.yaml and .sugar/prompts/ to share settings with your team.
.sugar/config.yaml is created on sugar init:
sugar:
dry_run: false
loop_interval: 300
max_concurrent_work: 3
claude:
enable_agents: true
discovery:
github:
enabled: true
repo: "user/repository"Contributions welcome. See CONTRIBUTING.md.
git clone https://github.com/roboticforce/sugar.git
cd sugar
uv pip install -e ".[dev,test,github]"
pytest tests/ -vDual License: AGPL-3.0 + Commercial
Sugar is provided "AS IS" without warranty. Review all AI-generated code before use.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.