MegaMemorySAFE
Persistent project knowledge graph for coding agents. MCP server with semantic search, in-process embeddings, and web explorer.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MegaMemory
Persistent project knowledge graph for coding agents.
An MCP server that lets your coding agent build and query a graph of concepts, architecture, and decisions — so it remembers across sessions.
The LLM is the indexer. No AST parsing. No static analysis. Your agent reads code, writes concepts in its own words, and queries them before future tasks. The graph stores concepts — features, modules, patterns, decisions — not code symbols.
The Loop
understand → work → update
- Session start — agent calls
list_rootsto orient itself - Before a task — agent calls
understandwith a natural language query (orget_conceptfor exact ID lookup) - After a task — agent calls
create_conceptorupdate_conceptto record what it built
Everything persists in a per-project SQLite database at .megamemory/knowledge.db.
Installation
npm install -g megamemory
[!NOTE] Requires Node.js >= 18. The embedding model (~23MB) downlo
88c57800cf54OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add megamemory -- npx -y [email protected]
{
"mcpServers": {
"megamemory": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
3 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_concept | write | Add a new concept to the knowledge graph. Call this after completing a task to record new features, components, patterns, or decisions you built. Include specific details: parameter names, defaults, file locations, and rationale. |
get_concept | read | Look up a concept by its exact ID. Returns the concept with its full context including children, edges, incoming edges, and parent. Unlike |
link | write | Create a relationship between two existing concepts. |
list_conflicts | write | List all unresolved merge conflicts in the knowledge graph, grouped by merge_group. Each group contains competing versions with full data. Call this when the user runs /merge to begin AI-assisted conflict resolution. |
list_roots | read | List all top-level concepts in the knowledge graph with their direct children. Call this at the start of a session to get a high-level project overview. |
remove_concept | destructive | Soft-delete a concept from the knowledge graph. The concept and its removal reason are preserved in history. |
resolve_conflict | write | Resolve a merge conflict by providing the correct resolved content. Read both conflict versions, verify against the current codebase, then provide the accurate resolved summary. Do NOT just pick a side — write the truth. |
understand | read | Query the project knowledge graph. Call this before starting any task to load relevant context about concepts, features, and architecture. Returns matched concepts with their children, edges, and parent context. |
update_concept | write | Update an existing concept in the knowledge graph. Call this after completing a task that changed existing features or components. Only include fields that changed. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
remove_concept
import { KnowledgeDB } from "../../db.js";@modelcontextprotocol/sdk, @xenova/transformers, libsql, picocolors, zod, @types/node, @vitest/coverage-v8, tsx
Gates applied: no_behavioural_pass.
88c57800cf54full audit observations/trust-audit/mcp-server/0xk3vin__megamemory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | 88c57800cf54 | SAFE | B | 89 | first audit |
Questions
What is the MegaMemory MCP server?
Persistent project knowledge graph for coding agents. MCP server with semantic search, in-process embeddings, and web explorer.
What tools does MegaMemory expose?
9 in total: 3 read-only, 5 that write, and 1 that can delete or overwrite (remove_concept). Every one is listed on this page with its risk.
Is MegaMemory safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does MegaMemory need?
No credential environment variables were found in its source, so it appears to need none.
How does MegaMemory run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as megamemory at 1.6.2.
How current is this page?
The grade is for one exact copy of the source (88c57800cf54), read on 2026-10-03. The repository is watched and re-audited when it changes.