Ori MnemosCAUTION
Local-first persistent agentic memory powered by Recursive Memory Harness (RMH). Open source must win.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Open-source persistent memory infrastructure for AI agents.
Ori implements human cognition as mathematical models on a knowledge graph. Activation decay from ACT-R. Spreading activation along wiki-link edges. Hebbian co-occurrence from retrieval patterns. Reinforcement learning on retrieval itself. Recursive graph traversal with sub-question decomposition. The system learns what matters, forgets what doesn't, and optimizes its own retrieval pipeline.
Persistent memory across sessions, clients, and machines. Zero-infrastructure retrieval that matches and in several cases strongly outperforms incumbents on benchmarks — and you own every byte of your data. Markdown on disk. Wiki-links as graph edges. Git as version control. No database lock-in, no cloud dependency, no vendor capture.
v0.7.0 · npm · Paper · Apache-2.0
Use
Ori is three surfaces over one index. The markdown is the truth; the index is derived. The learned half — Q-values, LinUCB arms, retrieval history — is not, so export it before deleting anything (see When to rebuild).
CLI
npx ori init # scaffold a vault npx ori index build # derive the index npx ori explore "..." # navigated retrieval npx ori sql "..." # read-only SQL over the index
MCP server — ori serve, registered in a client config. This is how an agent uses it.
Library — recall is the same wired entry the CLI and the MCP ori_recall tool both go through, so the programmatic path and the agent path cannot drift.
import { recall } from "ori-memory";
const res = await recall("./vault", "what did we decide about caching?", { limit: 5 });
for (const hit of res.data.results) console.log(hit.title, hit.score);searchComposite is also exported for callers that have already assembled vectors, graph metrics and a config; recall does that assembly fo
c0586336ff88OBSERVED · 2026-10-03Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add ori-memory -- npx -y [email protected]
Exposed tools (16)
11 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
memory_sql | read | Read-only SQL over your memory index (SQLite). Use for questions the ranking tools |
ori_add | write | Create a note in inbox. Always pass description and project: you know them now, and a note |
ori_explore | read | Deep memory exploration via PPR graph traversal. Propagates through wiki-links |
ori_health | read | Full diagnostic |
ori_index_build | destructive | Build or update the embedding index. Only re-embeds changed notes unless force=true. |
ori_learning_reset | destructive | Record the user |
ori_promote | read | Promote an inbox note to notes/ with classification, linking, and area assignment. |
ori_prune | read | Analyze activation topology and identify archive candidates. |
ori_query_ranked | read | Full ranked retrieval with Q-value reranking, co-occurrence PPR, and stage meta-learning. |
ori_query_similar | read | Composite vector search only (semantic + metadata, no keyword/graph). Faster but single-signal. Excludes archived notes by default. |
ori_update | write | Update agent files: identity, goals, methodology (self/), or daily, reminders (ops/). |
ori_update_decision | write | Record the user |
ori_validate | read | Validate a note against schema |
ori_wake | read | Session boot: constant-size briefing, budget-capped. Call this first in a session. |
ori_warmth | read | Associative warmth field for the current context. Returns low-token note titles, scores, and sources showing what memory is resonating before and alongside retrieval. |
ori_whats_new | read | Release notes for an Ori version (default: the installed one). Use when the user asks what changed, |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (9)
| `\u200bDROP TABLE note` (ZWSP prefix) | `... got "DROP TABLE note"` |
ori_index_build, ori_learning_reset
.ori
import { runInit } from "../../src/cli/init.js";import { runAdd } from "../../src/cli/add.js";import { runPromote } from "../../src/cli/promote.js";import { runValidate } from "../../src/cli/validate.js";import { parseFrontmatter } from "../../src/core/frontmatter.js";@clack/prompts, @huggingface/transformers, @modelcontextprotocol/sdk, better-sqlite3, chalk, commander, figlet, graphology
Gates applied: no_behavioural_pass.
c0586336ff88full audit observations/trust-audit/mcp-server/aayoawoyemi__ori-mnemos.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-03 | c0586336ff88 | CAUTION | B | 89 | first audit |
Questions
What is the Ori Mnemos MCP server?
Local-first persistent agentic memory powered by Recursive Memory Harness (RMH). Open source must win.
What tools does Ori Mnemos expose?
16 in total: 11 read-only, 3 that write, and 2 that can delete or overwrite (ori_index_build, ori_learning_reset). Every one is listed on this page with its risk.
Is Ori Mnemos safe to connect to an agent?
With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Ori Mnemos need?
It reads OPENAI_API_KEY and ORI_TEST_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Ori Mnemos run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as ori-memory at 0.8.1.
How current is this page?
The grade is for one exact copy of the source (c0586336ff88), read on 2026-10-03. The repository is watched and re-audited when it changes.