Atlas / MCP servers / diaaaj / A-MEM

A-MEMSAFE

mcp/diaaaj/a-mem-3

Self-evolving memory system for coding agents

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 5r · 2w · 1d
Transport
stdio
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

mcp-name: io.github.DiaaAj/a-mem-mcp

A-MEM is a self-evolving memory system for coding agents. Unlike simple vector stores, A-MEM automatically organizes knowledge into a Zettelkasten-style graph with dynamic relationships. Memories don't just get stored—they evolve and connect over time.

Currently tested with Claude Code. Support for other MCP-compatible agents is planned.

Quick Start

Install

pip install a-mem

Add to Claude Code

claude mcp add a-mem -s user -- a-mem-mcp \
-e LLM_BACKEND=openai \
-e LLM_MODEL=gpt-4o-mini \
-e OPENAI_API_KEY=sk-...

That's it! A session-start hook installs automatically to remind Claude to use memory.

Note: Memory is stored per-project in ./chroma_db. For global memory across all projects, see Memory Scope.

Uninstall

a-mem-uninstall-hook   # Remove hooks first
pip uninstall a-mem

How It Works

t=0              t=1                t=2

◉───◉             ◉───◉
◉               │                 ╱ │ ╲
◉                ◉──┼──◉
│
◉

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━▶
self-evolving memory
  1. Add a memory → A-MEM extracts keywords, context, and tags via LLM
  2. Find neighbors → Searches for semantically similar existing memories
  3. Evolve → Decides whether to link, strengthen connections, or update re
Read from source at commit 45988a1f1369OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add a-mem --env OPENAI_API_KEY=${OPENAI_API_KEY} -- None a-mem==0.2.4
03

Exposed tools (8)

5 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_memory_notewrite
check_task_statusread
delete_memory_notedestructive
read_memory_noteread
search_memoriesread
search_memories_agenticread
search_memories_by_timeread
update_memory_notewrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_memory_note
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_llm_backends.py:206
sglang_host="http://192.168.1.100",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_llm_backends.py:209
self.assertEqual(controller.llm.base_url, "http://192.168.1.100:8080")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_llm_backends.py:247
sglang_host="http://10.0.0.1",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_llm_backends.py:251
self.assertEqual(memory_system.llm_controller.llm.sglang_host, "http://10.0.0.1")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_llm_backends.py:253
self.assertEqual(memory_system.llm_controller.llm.base_url, "http://10.0.0.1:9999")
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
sentence-transformers, chromadb, rank_bm25, nltk, transformers, litellm, numpy, scikit-learn
Why it matters. 9 requirement(s) not pinned with ==
Fix. pin exact versions
INFOInventory / provenance · inv.oversize · CWE-1104
Figure/demo.gif
Figure/demo.gif
Why it matters. 7681834 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
INSTALL.md:97
1. Load configuration from `.env` file (or environment variables)
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SETUP.md:165
cat .env | grep OPENAI_API_KEY
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 45988a1f1369full audit observations/trust-audit/mcp-server/diaaaj__a-mem-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0845988a1f1369SAFEB89first audit
06

Questions

What is the A-MEM MCP server?

Self-evolving memory system for coding agents

What tools does A-MEM expose?

8 in total: 5 read-only, 2 that write, and 1 that can delete or overwrite (delete_memory_note). Every one is listed on this page with its risk.

Is A-MEM safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does A-MEM need?

It reads OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does A-MEM run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as a-mem.

How current is this page?

The grade is for one exact copy of the source (45988a1f1369), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement