Atlas / MCP servers / 0xk3vin / MegaMemory

MegaMemorySAFE

mcp/0xk3vin/megamemory

Persistent project knowledge graph for coding agents. MCP server with semantic search, in-process embeddings, and web explorer.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
9 3r · 5w · 1d
Transport
stdio
License
MIT
Stars
707
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MegaMemory

Persistent project knowledge graph for coding agents.

An MCP server that lets your coding agent build and query a graph of concepts, architecture, and decisions — so it remembers across sessions.

The LLM is the indexer. No AST parsing. No static analysis. Your agent reads code, writes concepts in its own words, and queries them before future tasks. The graph stores concepts — features, modules, patterns, decisions — not code symbols.

The Loop

understand → work → update

  1. Session start — agent calls list_roots to orient itself
  2. Before a task — agent calls understand with a natural language query (or get_concept for exact ID lookup)
  3. After a task — agent calls create_concept or update_concept to record what it built

Everything persists in a per-project SQLite database at .megamemory/knowledge.db.

Installation

npm install -g megamemory
[!NOTE] Requires Node.js >= 18. The embedding model (~23MB) downlo
Read from source at commit 88c57800cf54OBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add megamemory -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "megamemory": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (9)

3 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_conceptwriteAdd a new concept to the knowledge graph. Call this after completing a task to record new features, components, patterns, or decisions you built. Include specific details: parameter names, defaults, file locations, and rationale.
get_conceptreadLook up a concept by its exact ID. Returns the concept with its full context including children, edges, incoming edges, and parent. Unlike
linkwriteCreate a relationship between two existing concepts.
list_conflictswriteList all unresolved merge conflicts in the knowledge graph, grouped by merge_group. Each group contains competing versions with full data. Call this when the user runs /merge to begin AI-assisted conflict resolution.
list_rootsreadList all top-level concepts in the knowledge graph with their direct children. Call this at the start of a session to get a high-level project overview.
remove_conceptdestructiveSoft-delete a concept from the knowledge graph. The concept and its removal reason are preserved in history.
resolve_conflictwriteResolve a merge conflict by providing the correct resolved content. Read both conflict versions, verify against the current codebase, then provide the accurate resolved summary. Do NOT just pick a side — write the truth.
understandreadQuery the project knowledge graph. Call this before starting any task to load relevant context about concepts, features, and architecture. Returns matched concepts with their children, edges, and parent context.
update_conceptwriteUpdate an existing concept in the knowledge graph. Call this after completing a task that changed existing features or components. Only include fields that changed.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
remove_concept
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/helpers/db-worker.ts:2
import { KnowledgeDB } from "../../db.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @xenova/transformers, libsql, picocolors, zod, @types/node, @vitest/coverage-v8, tsx
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha 88c57800cf54full audit observations/trust-audit/mcp-server/0xk3vin__megamemory.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0388c57800cf54SAFEB89first audit
06

Questions

What is the MegaMemory MCP server?

Persistent project knowledge graph for coding agents. MCP server with semantic search, in-process embeddings, and web explorer.

What tools does MegaMemory expose?

9 in total: 3 read-only, 5 that write, and 1 that can delete or overwrite (remove_concept). Every one is listed on this page with its risk.

Is MegaMemory safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MegaMemory need?

No credential environment variables were found in its source, so it appears to need none.

How does MegaMemory run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as megamemory at 1.6.2.

How current is this page?

The grade is for one exact copy of the source (88c57800cf54), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement