Atlas / MCP servers / agentic-box / Memora

MemoraBLOCK

mcp/agentic-box/memora-1

Give your AI agents persistent, collective memory — with deduplicating absorb, supersession lineage, semantic search, and a graph UI. Speaks MCP.

Verdict
BLOCK
Grade
D
Trust score
68 /100
Exposed tools
48 27r · 13w · 8d
Transport
streamable-http
License
MIT
Stars
729
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Memora

"You never truly know the value of a moment until it becomes a memory."

Give your AI agents persistent collective memory An MCP memory layer for agents: structured storage, semantic retrieval, graph relations, and source-backed cross-session context.

Absorb agent work into durable graph memory, then use memory_digest(topic) to retrieve relevant memories, TODOs/issues, related edges, and source IDs.

Features · Preview · Install · Usage · Config · Multi-DB · Containers · Live Graph · Cloud Graph · Chat · Semantic Search · Documents · LLM Dedup · Linking · Neovim

Features

Core Storage

  • 💾 **
Read from source at commit 51d480142fbcOBSERVED · 2026-09-30
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add memora-graph --env CF_API_TOKEN=${CF_API_TOKEN} --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env MEMORA_HEALTH_TOKEN=${MEMORA_HEALTH_TOKEN} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "memora-graph": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CF_API_TOKEN": "${CF_API_TOKEN}",
        "CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
        "MEMORA_HEALTH_TOKEN": "${MEMORA_HEALTH_TOKEN}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (48)

27 read · 13 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_memorywriteCreate a new memory in the knowledge base. Use when the user asks to save, create, add, or remember something.
delete_memorydestructiveDelete a memory by ID. Use when the user asks to remove or delete a specific memory.
memory_absorbreadIntelligently absorb facts into memory with dedup and consolidation.
memory_backfill_tagsreadRe-tag existing memories with project-prefixed tags.
memory_boostreadBoost a memory
memory_clustersreadDetect clusters of related memories.
memory_createwriteCreate a new memory entry.
memory_create_batchwriteCreate multiple memories in one call.
memory_create_issuewriteCreate a new issue/bug memory.
memory_create_sectionwriteCreate a new section/subsection header memory.
memory_create_todowriteCreate a new TODO/task memory.
memory_deletedestructiveDelete a memory by id.
memory_delete_batchdestructiveDelete multiple memories by id.
memory_delete_documentdestructiveDelete a stored document and all its fragments.
memory_detect_supersessionswriteDetect memories that supersede (update/replace) other memories.
memory_digestreadReturn a deterministic digest of memories related to a topic.
memory_events_cleardestructiveMark events as consumed.
memory_events_pollreadPoll for memory events (e.g., shared-cache notifications).
memory_exportwriteExport all memories to JSON format for backup or transfer. Rate limited: 60s cooldown.
memory_export_graphreadExport memories as interactive HTML knowledge graph.
memory_find_duplicatesreadFind potential duplicate memory pairs with optional LLM-powered comparison.
memory_getreadRetrieve a single memory by id (full content by default).
memory_get_documentreadRetrieve a stored document and its fragments by document key.
memory_hierarchyreadReturn memories organised into a hierarchy derived from their metadata.
memory_hybrid_searchreadPerform a hybrid search combining keyword (FTS) and semantic (vector) search.
memory_importwriteImport memories from JSON format. Rate limited: 60s cooldown.
memory_import_sweepdestructiveAdmin: finish or remove rows an interrupted import left behind.
memory_insightsreadAnalyze stored memories and produce actionable insights.
memory_linkwriteCreate an explicit typed link between two memories.
memory_listreadList memories, optionally filtering by substring query or metadata.
memory_list_compactread[Deprecated] List memories in compact format (id, preview, tags only).
memory_mergedestructiveMerge source memory into target, then delete source.
memory_migrate_imagesreadMigrate existing base64 images to R2 storage.
memory_rebuild_crossrefsreadRecompute cross-reference links for all memories. Rate limited: 300s cooldown.
memory_rebuild_embeddingsreadRecompute embeddings for all memories. Rate limited: 300s cooldown.
memory_relatedreadReturn cross-referenced memories for a given entry.
memory_semantic_searchreadPerform a semantic search using vector embeddings.
memory_statsreadGet statistics and analytics about stored memories.
memory_store_documentreadStore a structured document as a root memory + searchable fragments.
memory_tag_hierarchyreadReturn stored tags organised as a namespace hierarchy.
memory_tagsreadReturn the allowlisted tags.
memory_unlinkdestructiveRemove a link between two memories.
memory_updatewriteUpdate an existing memory.
memory_upload_imagewriteUpload an image file directly to R2 storage.
memory_validate_tagsreadValidate stored tags against the allowlist and report invalid entries.
memory_verify_integrityreadRead-only embedding integrity doctor with bounded offending ids.
pingreadreturn
update_memorywriteUpdate an existing memory by ID. Use when the user asks to modify, edit, or change a specific memory.
04

Trust audit

BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
memora/backends.py:77
"  - AWS credentials file: ~/.aws/credentials\n"
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
memora/server.py:3038
_BLOCKED_PATTERNS = [".ssh", ".gnupg", ".aws", ".config/gcloud", "id_rsa", "id_ed25519", ".env"]
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/memora
.claude/skills/memora
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
memora-graph/public/_graph_limit.mjs
memora-graph/public/_graph_limit.mjs
Why it matters. link not followed
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_api_v1.py:21
TOKEN = "memora-api-v1-test-token"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_memory, memory_delete, memory_delete_batch, memory_delete_document, memory_events_clear, memory_import_sweep, memory_merge, memory_unlink
Why it matters. 8 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.symlink · CWE-1104
memora-graph/public/index.html
memora-graph/public/index.html
Why it matters. link not followed
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
memora-graph/scripts/test_ui.mjs:105
const indexBannerVisible = await page.$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
memora-graph/scripts/test_ui.mjs:205
const rect = (sel) => page.$eval(sel, (n) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
memora-graph/scripts/test_ui.mjs:209
const state = await page.$eval(sel, (n) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
memora-graph/scripts/test_ui.mjs:457
const fgBannerVisible = await page.$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
memora-graph/scripts/test_ui.mjs:488
const fgBannerStill = await page.$eval(
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
claude-plugin/hooks-handlers/post_tool_use.py:269
return hashlib.md5("|".join(key_parts).encode()).hexdigest()[:16]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/measure_absorb_roundtrips.py:88
uniq = hashlib.sha1(content.encode()).hexdigest()[:12]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
memora-graph/scripts/test_graph_limit.mjs:71
join(dirname(fileURLToPath(import.meta.url)), "../../tests/fixtures/graph_limit_conformance.json"),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
memora-graph/scripts/test_graph_limit_ui.mjs:14
} from "../../memora/graph/_graph_limit.mjs";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
memora-graph/scripts/test_tag_writes.mjs:27
join(dirname(fileURLToPath(import.meta.url)), "../../tests/fixtures/tag_policy_conformance.json"),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:148
The printed workspace URL is always `http://127.0.0.1:<PORT>/mcp` (the registry default). For a non-default store, append `/<name>` yourself — a bare `/mcp` on a registry silently binds `MEMORA_DEFAUL
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:151
{"mcpServers": {"memora": {"type": "http", "url": "http://127.0.0.1:<PORT>/mcp/<store>"}}}
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:394
"url": "http://127.0.0.1:8000/mcp/ob1"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:404
`http://127.0.0.1:8910/mcp/ob1`. See [Container Deployment](#container-deployment).
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:460
{"mcpServers": {"memora": {"type": "http", "url": "http://127.0.0.1:8910/mcp/ob1"}}}
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
contracts/memora-api/v1/fixtures/payload_too_large.json:12
"query": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
memora/graph/index.html:6
<link rel="icon" type="image/png" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABUAAAAgCAMAAADKfsO6AAACdlBMVEUSFSISFSERFSMSFiIRFSIRFiETFSISFiEUGCUUGCQTFyMQFCETFyQTFSMRFSEHCRQIChYQEyASFiMRFCELDh
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
memora/image_storage.py:297
image_bytes = base64.b64decode(b64_data)

Gates applied: no_behavioural_pass.

Audited 2026-09-30 · audit v0.4.1 · source sha 51d480142fbcfull audit observations/trust-audit/mcp-server/agentic-box__memora-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-3051d480142fbcBLOCKD68first audit
06

Questions

What is the Memora MCP server?

Give your AI agents persistent, collective memory — with deduplicating absorb, supersession lineage, semantic search, and a graph UI. Speaks MCP.

What tools does Memora expose?

48 in total: 27 read-only, 13 that write, and 8 that can delete or overwrite (delete_memory, memory_delete, memory_delete_batch, memory_delete_document, memory_events_clear). Every one is listed on this page with its risk.

Is Memora safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (68/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Memora need?

It reads CF_API_TOKEN, CLOUDFLARE_API_TOKEN, MEMORA_HEALTH_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Memora run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as memora-graph at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (51d480142fbc), read on 2026-09-30. The repository is watched and re-audited when it changes.

Advertisement