Atlas / MCP servers / aayoawoyemi / Ori Mnemos

Ori MnemosCAUTION

mcp/aayoawoyemi/ori-mnemos

Local-first persistent agentic memory powered by Recursive Memory Harness (RMH). Open source must win.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
16 11r · 3w · 2d
Transport
stdio
License
Apache-2.0
Stars
328
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Open-source persistent memory infrastructure for AI agents.

Ori implements human cognition as mathematical models on a knowledge graph. Activation decay from ACT-R. Spreading activation along wiki-link edges. Hebbian co-occurrence from retrieval patterns. Reinforcement learning on retrieval itself. Recursive graph traversal with sub-question decomposition. The system learns what matters, forgets what doesn't, and optimizes its own retrieval pipeline.

Persistent memory across sessions, clients, and machines. Zero-infrastructure retrieval that matches and in several cases strongly outperforms incumbents on benchmarks — and you own every byte of your data. Markdown on disk. Wiki-links as graph edges. Git as version control. No database lock-in, no cloud dependency, no vendor capture.

v0.7.0 · npm · Paper · Apache-2.0

Use

Ori is three surfaces over one index. The markdown is the truth; the index is derived. The learned half — Q-values, LinUCB arms, retrieval history — is not, so export it before deleting anything (see When to rebuild).

CLI

npx ori init          # scaffold a vault
npx ori index build   # derive the index
npx ori explore "..."   # navigated retrieval
npx ori sql "..."       # read-only SQL over the index

MCP server — ori serve, registered in a client config. This is how an agent uses it.

Library — recall is the same wired entry the CLI and the MCP ori_recall tool both go through, so the programmatic path and the agent path cannot drift.

import { recall } from "ori-memory";

const res = await recall("./vault", "what did we decide about caching?", { limit: 5 });
for (const hit of res.data.results) console.log(hit.title, hit.score);

searchComposite is also exported for callers that have already assembled vectors, graph metrics and a config; recall does that assembly fo

Read from source at commit c0586336ff88OBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add ori-memory -- npx -y [email protected]
03

Exposed tools (16)

11 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
memory_sqlreadRead-only SQL over your memory index (SQLite). Use for questions the ranking tools
ori_addwriteCreate a note in inbox. Always pass description and project: you know them now, and a note
ori_explorereadDeep memory exploration via PPR graph traversal. Propagates through wiki-links
ori_healthreadFull diagnostic
ori_index_builddestructiveBuild or update the embedding index. Only re-embeds changed notes unless force=true.
ori_learning_resetdestructiveRecord the user
ori_promotereadPromote an inbox note to notes/ with classification, linking, and area assignment.
ori_prunereadAnalyze activation topology and identify archive candidates.
ori_query_rankedreadFull ranked retrieval with Q-value reranking, co-occurrence PPR, and stage meta-learning.
ori_query_similarreadComposite vector search only (semantic + metadata, no keyword/graph). Faster but single-signal. Excludes archived notes by default.
ori_updatewriteUpdate agent files: identity, goals, methodology (self/), or daily, reminders (ops/).
ori_update_decisionwriteRecord the user
ori_validatereadValidate a note against schema
ori_wakereadSession boot: constant-size briefing, budget-capped. Call this first in a session.
ori_warmthreadAssociative warmth field for the current context. Returns low-token note titles, scores, and sources showing what memory is resonating before and alongside retrieval.
ori_whats_newreadRelease notes for an Ori version (default: the installed one). Use when the user asks what changed,
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/falsification/findings-safety.md:355
| `\u200bDROP TABLE note` (ZWSP prefix) | `... got "DROP TABLE note"` |
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
ori_index_build, ori_learning_reset
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
scaffold/.ori
.ori
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/add-description-project.test.ts:9
import { runInit } from "../../src/cli/init.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/add-description-project.test.ts:10
import { runAdd } from "../../src/cli/add.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/add-description-project.test.ts:11
import { runPromote } from "../../src/cli/promote.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/add-description-project.test.ts:12
import { runValidate } from "../../src/cli/validate.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/cli/add-description-project.test.ts:13
import { parseFrontmatter } from "../../src/core/frontmatter.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@clack/prompts, @huggingface/transformers, @modelcontextprotocol/sdk, better-sqlite3, chalk, commander, figlet, graphology
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha c0586336ff88full audit observations/trust-audit/mcp-server/aayoawoyemi__ori-mnemos.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-03c0586336ff88CAUTIONB89first audit
06

Questions

What is the Ori Mnemos MCP server?

Local-first persistent agentic memory powered by Recursive Memory Harness (RMH). Open source must win.

What tools does Ori Mnemos expose?

16 in total: 11 read-only, 3 that write, and 2 that can delete or overwrite (ori_index_build, ori_learning_reset). Every one is listed on this page with its risk.

Is Ori Mnemos safe to connect to an agent?

With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Ori Mnemos need?

It reads OPENAI_API_KEY and ORI_TEST_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Ori Mnemos run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as ori-memory at 0.8.1.

How current is this page?

The grade is for one exact copy of the source (c0586336ff88), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement