Atlas / MCP servers / alibaizhanov / Mengram

MengramBLOCK

mcp/alibaizhanov/mengram

Human-like memory for AI agents — semantic, episodic & procedural. Experience-driven procedures that learn from failures. Free API, Python & JS SDKs, LangChain, CrewAI & OpenClaw integrations.

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
32 21r · 9w · 2d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
204
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<source media="(prefers-color-scheme: dark)" srcset="https://img.shields.io/badge/Mengram-a855f7?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAxMjAgMTIwIj48cGF0aCBkPSJNNjAgMTYgUTkyIDE2IDk2IDQ4IFExMDAgNzggNzIgODggUTUwIDk2IDM4IDc2IFEyNiA1OCA0NiA0NiBRNjIgMzggNzAgNTIgUTc2IDY0IDYyIDY4IiBmaWxsPSJub25lIiBzdHJva2U9IiNmZmYiIHN0cm9rZS13aWR0aD0iOCIgc3Ryb2tlLWxpbmVjYXA9InJvdW5kIi8+PGNpcmNsZSBjeD0iNjIiIGN5PSI2OCIgcj0iOCIgZmlsbD0iI2ZmZiIvPjwvc3ZnPg=="> <img alt="Mengram" src="https://img.shields.io/badge/Mengram-a855f7?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAxMjAgMTIwIj48cGF0aCBkPSJNNjAgMTYgUTkyIDE2IDk2IDQ4IFExMDAgNzggNzIgODggUTUwIDk2IDM4IDc2IFEyNiA1OCA0NiA0NiBRNjIgMzggNzAgNTIgUTc2IDY0IDYyIDY4IiBmaWxsPSJub25lIiBzdHJva2U9IiNmZmYiIHN0cm9rZS13aWR0aD0iOCIgc3Ryb2tlLWxpbmVjYXA9InJvdW5kIi8+PGNpcmNsZSBjeD0iNjIiIGN5PSI2OCIgcj0iOCIgZmlsbD0iI2ZmZiIvPjwvc3ZnPg==">

Give your AI agents memory that actually learns

[](https://github.com/alibaizhanov/mengram/stargazers) [](https://pypi.org/project/mengram-ai/) [](https://www.npmjs.com/package/mengram-ai) [](LICENSE) [](https://pypi.org/project/mengram-ai/) [](https://github.com/alibaizhanov/mengram/commits/main)

[Website](https://mengram.io) · [Get API Key](https://mengram.io/#signup) · [Docs](https://mengram.io/docs) · [Console](https://mengram.io/dashboard) · Examples

pip install mengram-ai   # 
Read from source at commit 68e66482cf91OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mengram --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env COHERE_API_KEY=${COHERE_API_KEY} --env GITHUB_CLIENT_SECRET=${GITHUB_CLIENT_SECRET} --env MENGRAM_API_KEY=${MENGRAM_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mengram": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "COHERE_API_KEY": "${COHERE_API_KEY}",
        "GITHUB_CLIENT_SECRET": "${GITHUB_CLIENT_SECRET}",
        "MENGRAM_API_KEY": "${MENGRAM_API_KEY}"
      }
    }
  }
}
03

Exposed tools (32)

21 read · 9 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
archive_factdestructiveArchive a specific fact on an entity — soft-delete without removing the entity. Use when a fact is outdated, wrong, or no longer relevant.
askreadGet a synthesized answer to a question, grounded in the user
checkpointwriteSave a session checkpoint — summarize key decisions, learnings, and outcomes from this conversation. Lighter than
context_forreadGet relevant memory context for a specific task. Returns a compact context pack: related entities, procedures, and past events. Use at the START of a new task to load relevant background. More focused than
dedupwriteFind and automatically merge duplicate entities. Scans all entities and merges near-duplicates (e.g.
delete_entitydestructiveDelete an entity and all its data (facts, relations, knowledge). Use when user explicitly asks to remove something from memory.
dismiss_triggerwriteDismiss a smart trigger without firing its webhook. Use when user wants to ignore or snooze a trigger notification.
fix_entity_typereadFix an entity
generate_rules_filereadGenerate a CLAUDE.md, .cursorrules, or .windsurfrules file from memory. Creates structured project rules, conventions, tech stack, workflows, and known issues — perfect for AI coding assistants. Output can be saved directly to a file.
get_entityreadGet details of a specific entity — facts, relations, knowledge. Use when user asks about a specific person, project, or concept by name.
get_feedreadGet activity feed — recent memory changes and events. Use when user asks
get_graphreadGet the knowledge graph — all entities and their relationships. Use when user asks
get_insightsreadGet AI-generated insights about the user — patterns, connections, reflections from memory analysis. Call this when user asks
get_reflectionsreadGet AI-generated reflections (insights and patterns found across memories). Optional scope filter:
get_triggersreadList smart triggers — reminders, contradictions detected, and patterns. Use when user asks
list_episodesreadList or search episodic memories (events, interactions, experiences). Use when user asks
list_memoriesreadList all stored memory entities with their types and fact counts. Use when user asks
list_proceduresreadList learned workflows/procedures from memory. Use when user asks
merge_entitieswriteMerge two entities into one — combines facts, relations, and knowledge. Use when there are duplicate entities (e.g.
procedure_feedbackreadRecord success or failure for a procedure. ALWAYS use this when the user reports that a workflow worked or failed. On failure with context, the system automatically evolves the procedure to a new improved version.
procedure_historyreadShow how a procedure evolved over time — all versions and what changed. Use when user asks
recallreadSemantic search through the user
recall_allreadRecall EVERYTHING from memory vault.
reflectwriteTrigger AI reflection on memories — analyzes facts to find patterns, insights, and connections. Use when user asks
rememberwriteSave knowledge from a conversation to memory — pass message pairs and the AI extracts entities, facts, relations, episodes, and procedures. Use after meaningful exchanges where the user shares personal info, preferences, decisions, or technical context worth remembering.
remember_textwriteSave plain text to memory — the AI extracts entities, facts, and relations automatically. Use when user shares a note, snippet, URL content, or any freeform text to remember.
run_agentswriteRun memory agents that analyze, clean, and find patterns in memory. Use
searchreadAdvanced structured search — returns entities with relevance scores, facts, and knowledge snippets. Use instead of
search_allreadUnified search across ALL memory types — semantic, episodic, and procedural. Best for broad queries that might match different memory types.
search_procedureswriteSearch procedures by name, trigger, or step content.
timelinereadSearch memory by time. Use when user asks
vault_statsreadGet memory vault statistics — total entities, facts, relations, knowledge items, and storage usage. Use when user asks
04

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (12 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
cloud/api.py:317
if hostname in ("localhost", "0.0.0.0", "metadata.google.internal") or hostname.endswith(".internal") or hostname.endswith(".local"):
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
cloud/store/_webhooks.py:182
if hostname in ("localhost", "0.0.0.0", "metadata.google.internal") or hostname.endswith(".internal") or hostname.endswith(".local"):
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docker-compose.yml:38
DATABASE_URL: postgresql://mengram:mengram@postgres:5432/mengram
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli.py:1886
print(f"API key: {api_key}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli.py:2261
print(f"  API key: {api_key[:10]}...{api_key[-4:]}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli.py:2329
print(f"  API key: {api_key}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli.py:2337
print(f'  export MENGRAM_API_KEY="{api_key}"')
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
cloud/api.py:6333
or f"http://127.0.0.1:{os.environ.get('PORT', '8000')}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
cloud/api.py:6397
or f"http://127.0.0.1:{os.environ.get('PORT', '8000')}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
cloud/api.py:6454
logger.info(f"   http://0.0.0.0:{port}")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
local/resume_page.py:87
url = f"http://127.0.0.1:{srv.server_port}/"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cloud/dashboard.html:4340
Paddle.Initialize({ token: 'live_45d33010340ea579d61b1e7233d' });
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
archive_fact, delete_entity
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
vscode-mengram/.vscodeignore
.vscodeignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
local/resume.py:103
return hashlib.sha1(base.encode("utf-8")).hexdigest()[:16]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
local/resume.py:228
return hashlib.sha1(raw.encode("utf-8")).hexdigest()[:12]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_cli.py:12
monkeypatch.setenv("MENGRAM_URL", "http://192.168.2.99:8420/")
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:4
<source media="(prefers-color-scheme: dark)" srcset="https://img.shields.io/badge/Mengram-a855f7?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmci
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:5
<img alt="Mengram" src="https://img.shields.io/badge/Mengram-a855f7?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAxMjAgMTIwI
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/customer-support-agent/requirements.txt
mengram-ai, python-dotenv
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/devops-agent/requirements.txt
mengram-ai, python-dotenv
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/personal-assistant/requirements.txt
mengram-ai, langchain-openai, python-dotenv
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/procedural-memory-demo/requirements.txt
mengram-ai
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
obsidian-plugin/package.json
@types/node, builtin-modules, obsidian
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
cloud/for-agents.html:87
<div class="card"><h3>Server-side extraction</h3><p>Send raw conversation turns — facts, events, and workflows are extracted, deduplicated, and contradiction-checked for you. No prompt engineering.</p
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 68e66482cf91full audit observations/trust-audit/mcp-server/alibaizhanov__mengram.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0668e66482cf91BLOCKD61first audit
06

Questions

What is the Mengram MCP server?

Human-like memory for AI agents — semantic, episodic & procedural. Experience-driven procedures that learn from failures. Free API, Python & JS SDKs, LangChain, CrewAI & OpenClaw integrations.

What tools does Mengram expose?

32 in total: 21 read-only, 9 that write, and 2 that can delete or overwrite (archive_fact, delete_entity). Every one is listed on this page with its risk.

Is Mengram safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mengram need?

It reads ANTHROPIC_API_KEY, COHERE_API_KEY, GITHUB_CLIENT_SECRET, MENGRAM_API_KEY, MOONSHOT_API_KEY, OAUTH_REDIRECT_ALLOWLIST, OPENAI_API_KEY, PADDLE_API_KEY, PADDLE_WEBHOOK_SECRET and RESEND_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mengram run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mengram at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (68e66482cf91), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement