MemoraBLOCK
Give your AI agents persistent, collective memory — with deduplicating absorb, supersession lineage, semantic search, and a graph UI. Speaks MCP.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Memora
"You never truly know the value of a moment until it becomes a memory."
Give your AI agents persistent collective memory An MCP memory layer for agents: structured storage, semantic retrieval, graph relations, and source-backed cross-session context.
Absorb agent work into durable graph memory, then use memory_digest(topic) to retrieve relevant memories, TODOs/issues, related edges, and source IDs.
Features · Preview · Install · Usage · Config · Multi-DB · Containers · Live Graph · Cloud Graph · Chat · Semantic Search · Documents · LLM Dedup · Linking · Neovim
Features
Core Storage
- 💾 **
51d480142fbcOBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add memora-graph --env CF_API_TOKEN=${CF_API_TOKEN} --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env MEMORA_HEALTH_TOKEN=${MEMORA_HEALTH_TOKEN} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"memora-graph": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CF_API_TOKEN": "${CF_API_TOKEN}",
"CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
"MEMORA_HEALTH_TOKEN": "${MEMORA_HEALTH_TOKEN}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (48)
27 read · 13 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_memory | write | Create a new memory in the knowledge base. Use when the user asks to save, create, add, or remember something. |
delete_memory | destructive | Delete a memory by ID. Use when the user asks to remove or delete a specific memory. |
memory_absorb | read | Intelligently absorb facts into memory with dedup and consolidation. |
memory_backfill_tags | read | Re-tag existing memories with project-prefixed tags. |
memory_boost | read | Boost a memory |
memory_clusters | read | Detect clusters of related memories. |
memory_create | write | Create a new memory entry. |
memory_create_batch | write | Create multiple memories in one call. |
memory_create_issue | write | Create a new issue/bug memory. |
memory_create_section | write | Create a new section/subsection header memory. |
memory_create_todo | write | Create a new TODO/task memory. |
memory_delete | destructive | Delete a memory by id. |
memory_delete_batch | destructive | Delete multiple memories by id. |
memory_delete_document | destructive | Delete a stored document and all its fragments. |
memory_detect_supersessions | write | Detect memories that supersede (update/replace) other memories. |
memory_digest | read | Return a deterministic digest of memories related to a topic. |
memory_events_clear | destructive | Mark events as consumed. |
memory_events_poll | read | Poll for memory events (e.g., shared-cache notifications). |
memory_export | write | Export all memories to JSON format for backup or transfer. Rate limited: 60s cooldown. |
memory_export_graph | read | Export memories as interactive HTML knowledge graph. |
memory_find_duplicates | read | Find potential duplicate memory pairs with optional LLM-powered comparison. |
memory_get | read | Retrieve a single memory by id (full content by default). |
memory_get_document | read | Retrieve a stored document and its fragments by document key. |
memory_hierarchy | read | Return memories organised into a hierarchy derived from their metadata. |
memory_hybrid_search | read | Perform a hybrid search combining keyword (FTS) and semantic (vector) search. |
memory_import | write | Import memories from JSON format. Rate limited: 60s cooldown. |
memory_import_sweep | destructive | Admin: finish or remove rows an interrupted import left behind. |
memory_insights | read | Analyze stored memories and produce actionable insights. |
memory_link | write | Create an explicit typed link between two memories. |
memory_list | read | List memories, optionally filtering by substring query or metadata. |
memory_list_compact | read | [Deprecated] List memories in compact format (id, preview, tags only). |
memory_merge | destructive | Merge source memory into target, then delete source. |
memory_migrate_images | read | Migrate existing base64 images to R2 storage. |
memory_rebuild_crossrefs | read | Recompute cross-reference links for all memories. Rate limited: 300s cooldown. |
memory_rebuild_embeddings | read | Recompute embeddings for all memories. Rate limited: 300s cooldown. |
memory_related | read | Return cross-referenced memories for a given entry. |
memory_semantic_search | read | Perform a semantic search using vector embeddings. |
memory_stats | read | Get statistics and analytics about stored memories. |
memory_store_document | read | Store a structured document as a root memory + searchable fragments. |
memory_tag_hierarchy | read | Return stored tags organised as a namespace hierarchy. |
memory_tags | read | Return the allowlisted tags. |
memory_unlink | destructive | Remove a link between two memories. |
memory_update | write | Update an existing memory. |
memory_upload_image | write | Upload an image file directly to R2 storage. |
memory_validate_tags | read | Validate stored tags against the allowlist and report invalid entries. |
memory_verify_integrity | read | Read-only embedding integrity doctor with bounded offending ids. |
ping | read | return |
update_memory | write | Update an existing memory by ID. Use when the user asks to modify, edit, or change a specific memory. |
Trust audit
BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
" - AWS credentials file: ~/.aws/credentials\n"
_BLOCKED_PATTERNS = [".ssh", ".gnupg", ".aws", ".config/gcloud", "id_rsa", "id_ed25519", ".env"]
.claude/skills/memora
memora-graph/public/_graph_limit.mjs
TOKEN = "memora-api-v1-test-token"
delete_memory, memory_delete, memory_delete_batch, memory_delete_document, memory_events_clear, memory_import_sweep, memory_merge, memory_unlink
memora-graph/public/index.html
const indexBannerVisible = await page.$eval(
const rect = (sel) => page.$eval(sel, (n) => {const state = await page.$eval(sel, (n) => {const fgBannerVisible = await page.$eval(
const fgBannerStill = await page.$eval(
return hashlib.md5("|".join(key_parts).encode()).hexdigest()[:16]uniq = hashlib.sha1(content.encode()).hexdigest()[:12]
join(dirname(fileURLToPath(import.meta.url)), "../../tests/fixtures/graph_limit_conformance.json"),
} from "../../memora/graph/_graph_limit.mjs";
join(dirname(fileURLToPath(import.meta.url)), "../../tests/fixtures/tag_policy_conformance.json"),
The printed workspace URL is always `http://127.0.0.1:<PORT>/mcp` (the registry default). For a non-default store, append `/<name>` yourself — a bare `/mcp` on a registry silently binds `MEMORA_DEFAUL
{"mcpServers": {"memora": {"type": "http", "url": "http://127.0.0.1:<PORT>/mcp/<store>"}}}"url": "http://127.0.0.1:8000/mcp/ob1"
`http://127.0.0.1:8910/mcp/ob1`. See [Container Deployment](#container-deployment).
{"mcpServers": {"memora": {"type": "http", "url": "http://127.0.0.1:8910/mcp/ob1"}}}"query": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
<link rel="icon" type="image/png" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABUAAAAgCAMAAADKfsO6AAACdlBMVEUSFSISFSERFSMSFiIRFSIRFiETFSISFiEUGCUUGCQTFyMQFCETFyQTFSMRFSEHCRQIChYQEyASFiMRFCELDh
image_bytes = base64.b64decode(b64_data)
Gates applied: no_behavioural_pass.
51d480142fbcfull audit observations/trust-audit/mcp-server/agentic-box__memora-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 51d480142fbc | BLOCK | D | 68 | first audit |
Questions
What is the Memora MCP server?
Give your AI agents persistent, collective memory — with deduplicating absorb, supersession lineage, semantic search, and a graph UI. Speaks MCP.
What tools does Memora expose?
48 in total: 27 read-only, 13 that write, and 8 that can delete or overwrite (delete_memory, memory_delete, memory_delete_batch, memory_delete_document, memory_events_clear). Every one is listed on this page with its risk.
Is Memora safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (68/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Memora need?
It reads CF_API_TOKEN, CLOUDFLARE_API_TOKEN, MEMORA_HEALTH_TOKEN and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Memora run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as memora-graph at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (51d480142fbc), read on 2026-09-30. The repository is watched and re-audited when it changes.