Atlas / MCP servers / delorenj / Qdrant Memory

Qdrant MemoryBLOCK

mcp/delorenj/qdrant-memory

MCP server providing a knowledge graph implementation with semantic search capabilities powered by Qdrant vector database

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
8 2r · 3w · 3d
Transport
stdio
License
—
Stars
24
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@delorenj/mcp-qdrant-memory)

This MCP server provides a knowledge graph implementation with semantic search capabilities powered by Qdrant vector database.

Features

  • Graph-based knowledge representation with entities and relations
  • File-based persistence (memory.json)
  • Semantic search using Qdrant vector database
  • OpenAI embeddings for semantic similarity
  • HTTPS support with reverse proxy compatibility
  • Docker support for easy deployment

Environment Variables

The following environment variables are required:

# OpenAI API key for generating embeddings
OPENAI_API_KEY=your-openai-api-key

# Qdrant server URL (supports both HTTP and HTTPS)
QDRANT_URL=https://your-qdrant-server

# Qdrant API key (if authentication is enabled)
QDRANT_API_KEY=your-qdrant-api-key

# Name of the Qdrant collection to use
QDRANT_COLLECTION_NAME=your-collection-name

Setup

Local Setup

  1. Install dependencies:
npm install
  1. Build the server:
npm run build

Docker Setup

  1. Build the Docker image:
docker build -t mcp-qdrant-memory .
  1. Run the Docker container with required environment variables:
docker run -d \
-e OPENAI_API_KEY=your-openai-api-key \
-e QDRANT_URL=http://your-qdrant-server:6333 \
-e QDRANT_COLLECTION_NAME=your-collection-name \
-e QDRANT_API_KEY=your-qdrant-api-key \
--name mcp-qdrant-memory \
mcp-qdrant-memory

Add to MCP settings:

{
"mcpServers": {
"memory": {
"command": "/bin/zsh",
"args": ["-c", "cd /path/to/server && node dist/index.js"],
"env": {
"OPENAI_API_KEY": "your-openai-api-key",
"QDRANT_API_KEY": "your-qdrant-api-key",
"QDRANT_URL": "http://your-qdrant-server:6333",
"QDRANT_COLLECTION_NAME": "your-collection-name"
},
"alwaysAllow": [
Read from source at commit fc91f8320358OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-qdrant-memory --env OPENAI_API_KEY=${OPENAI_API_KEY} --env QDRANT_API_KEY=${QDRANT_API_KEY} -- npx -y @delorenj/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-qdrant-memory": {
      "command": "npx",
      "args": [
        "-y",
        "@delorenj/[email protected]"
      ],
      "env": {
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "QDRANT_API_KEY": "${QDRANT_API_KEY}"
      }
    }
  }
}
03

Exposed tools (8)

2 read · 3 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_observationswriteAdd new observations to existing entities
create_entitieswriteCreate multiple new entities in the knowledge graph
create_relationswriteCreate multiple new relations between entities
delete_entitiesdestructiveDelete multiple entities and their relations
delete_observationsdestructiveDelete specific observations from entities
delete_relationsdestructiveDelete multiple relations
read_graphreadRead the entire knowledge graph
search_similarreadSearch for similar entities and relations using semantic search
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (7)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
persistence/qdrant.ts:33
rejectUnauthorized: false,
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
test-auth.mjs:24
rejectUnauthorized: false
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
test-direct.mjs:13
rejectUnauthorized: false
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/persistence/qdrant.ts:20
apiKey: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhY2Nlc3MiOiJtIn0.x6NrWBMMtPqcep5dNxOqjXT42sQhATAMdxEqVFDJKew',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_entities, delete_observations, delete_relations
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @qdrant/js-client-rest, axios, dotenv, openai, @types/dotenv, @types/node, shx
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-09 · audit v0.4.1 · source sha fc91f8320358full audit observations/trust-audit/mcp-server/delorenj__qdrant-memory.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09fc91f8320358BLOCKD69first audit
06

Questions

What is the Qdrant Memory MCP server?

MCP server providing a knowledge graph implementation with semantic search capabilities powered by Qdrant vector database

What tools does Qdrant Memory expose?

8 in total: 2 read-only, 3 that write, and 3 that can delete or overwrite (delete_entities, delete_observations, delete_relations). Every one is listed on this page with its risk.

Is Qdrant Memory safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Qdrant Memory need?

It reads OPENAI_API_KEY and QDRANT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Qdrant Memory run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @delorenj/mcp-qdrant-memory at 0.2.4.

How current is this page?

The grade is for one exact copy of the source (fc91f8320358), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement