A-MEMSAFE
Self-evolving memory system for coding agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
mcp-name: io.github.DiaaAj/a-mem-mcp
A-MEM is a self-evolving memory system for coding agents. Unlike simple vector stores, A-MEM automatically organizes knowledge into a Zettelkasten-style graph with dynamic relationships. Memories don't just get stored—they evolve and connect over time.
Currently tested with Claude Code. Support for other MCP-compatible agents is planned.
Quick Start
Install
pip install a-mem
Add to Claude Code
claude mcp add a-mem -s user -- a-mem-mcp \ -e LLM_BACKEND=openai \ -e LLM_MODEL=gpt-4o-mini \ -e OPENAI_API_KEY=sk-...
That's it! A session-start hook installs automatically to remind Claude to use memory.
Note: Memory is stored per-project in ./chroma_db. For global memory across all projects, see Memory Scope.Uninstall
a-mem-uninstall-hook # Remove hooks first pip uninstall a-mem
How It Works
t=0 t=1 t=2 ◉───◉ ◉───◉ ◉ │ ╱ │ ╲ ◉ ◉──┼──◉ │ ◉ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━▶ self-evolving memory
- Add a memory → A-MEM extracts keywords, context, and tags via LLM
- Find neighbors → Searches for semantically similar existing memories
- Evolve → Decides whether to link, strengthen connections, or update re
45988a1f1369OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add a-mem --env OPENAI_API_KEY=${OPENAI_API_KEY} -- None a-mem==0.2.4Exposed tools (8)
5 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_memory_note | write | |
check_task_status | read | |
delete_memory_note | destructive | |
read_memory_note | read | |
search_memories | read | |
search_memories_agentic | read | |
search_memories_by_time | read | |
update_memory_note | write |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
delete_memory_note
sglang_host="http://192.168.1.100",
self.assertEqual(controller.llm.base_url, "http://192.168.1.100:8080")
sglang_host="http://10.0.0.1",
self.assertEqual(memory_system.llm_controller.llm.sglang_host, "http://10.0.0.1")
self.assertEqual(memory_system.llm_controller.llm.base_url, "http://10.0.0.1:9999")
sentence-transformers, chromadb, rank_bm25, nltk, transformers, litellm, numpy, scikit-learn
Figure/demo.gif
1. Load configuration from `.env` file (or environment variables)
cat .env | grep OPENAI_API_KEY
Gates applied: no_behavioural_pass.
45988a1f1369full audit observations/trust-audit/mcp-server/diaaaj__a-mem-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 45988a1f1369 | SAFE | B | 89 | first audit |
Questions
What is the A-MEM MCP server?
Self-evolving memory system for coding agents
What tools does A-MEM expose?
8 in total: 5 read-only, 2 that write, and 1 that can delete or overwrite (delete_memory_note). Every one is listed on this page with its risk.
Is A-MEM safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does A-MEM need?
It reads OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does A-MEM run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as a-mem.
How current is this page?
The grade is for one exact copy of the source (45988a1f1369), read on 2026-10-08. The repository is watched and re-audited when it changes.