mcp-memory-serviceBLOCK
Open-source persistent memory for AI agent pipelines (LangGraph, CrewAI, AutoGen) and Claude. REST API + knowledge graph + autonomous consolidation.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Persistent Shared Memory for AI Agent Pipelines
Open-source memory backend for AI agents — REST API, MCP, OAuth, CLI, dashboard. One self-hosted service, every transport. Agents store decisions, share causal knowledge graphs, and retrieve context in 5ms — without cloud lock-in or API costs.
Works with LangGraph · CrewAI · AutoGen · any HTTP client · Claude Desktop · OpenCode
[](https://mcpmemory.services) [](https://opensource.org/licenses/Apache-2.0) [](https://pypi.org/project/mcp-memory-service/) [](https://pypi.org/project/mcp-memory-service/) [](https://github.com/doobidoo/mcp-memory-service) [](https://github.com/doobidoo/mcp-memory-service/blob/main/docs/remote-mcp-setup.md) [](https://github.com/doobidoo/mcp-memory-service/blob/main/docs/oauth-setup.md) [](https://deepwiki.com/doobidoo/mcp-memory-service)
e72d39873669OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-memory-video --env CLOUDFLARE_API_TOKEN=${CLOUDFLARE_API_TOKEN} --env ELEVENLABS_API_KEY=${ELEVENLABS_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GROQ_API_KEY=${GROQ_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-memory-video": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CLOUDFLARE_API_TOKEN": "${CLOUDFLARE_API_TOKEN}",
"ELEVENLABS_API_KEY": "${ELEVENLABS_API_KEY}",
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"GROQ_API_KEY": "${GROQ_API_KEY}"
}
}
}
}Exposed tools (5)
4 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
check_database_health | read | Check the health of the memory database |
delete_memory | destructive | Delete a memory by content hash |
retrieve_memory | read | Retrieve memories based on a query |
search_by_tag | read | Search memories by tags |
store_memory | read | Store a memory with content and optional metadata |
Trust audit
BLOCKgrade F · trust 40/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (12 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const resultsArray = eval(resultsMatch[1]);
return eval(resultsMatch[1]) || [];
tags = eval(row["tags"])
exec(compile(f.read(), new_script, 'exec'), global_vars)
Write-Host ' & "C:/Windows/System32/OpenSSH/ssh-add.exe" "$env:USERPROFILE\.ssh\id_ed25519"' -ForegroundColor Yellow
S.verify = False # ponytail: self-signed cert on localhost
verify = False if url.startswith("https") else Trueverify = False if API_URL.startswith("https") else Trueverify = False if url.startswith("https") else True__import__(module)
__import__(package)
module = importlib.import_module(module_name)
module = importlib.import_module(_lazy_map[name], __name__)
print(f' "MCP_API_KEY": "{api_key}",')print(f"\n🔑 Generated API key: {api_key}")print(f" API Key: {config.get('api_key', 'Not set')}")print(f"\n🔑 Generated API key: {api_key}")print(f" API Key: {config.get('api_key', 'Not set')}")config.API_KEY = "test-secret-key-12345"
secret = "leaked-from-registration"
key.write_text("-----BEGIN PRIVATE KEY-----\n")delete_memory
.coveragerc
.mlc-config.json
.nojekyll
Gates applied: no_behavioural_pass.
e72d39873669full audit observations/trust-audit/mcp-server/doobidoo__mcp-memory-service.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e72d39873669 | BLOCK | F | 40 | first audit |
Questions
What is the mcp-memory-service MCP server?
Open-source persistent memory for AI agent pipelines (LangGraph, CrewAI, AutoGen) and Claude. REST API + knowledge graph + autonomous consolidation.
What tools does mcp-memory-service expose?
5 in total: 4 read-only, 0 that write, and 1 that can delete or overwrite (delete_memory). Every one is listed on this page with its risk.
Is mcp-memory-service safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (40/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does mcp-memory-service need?
It reads CLOUDFLARE_API_TOKEN, ELEVENLABS_API_KEY, GEMINI_API_KEY, GROQ_API_KEY, HARVEST_LLM_GROQ_API_KEY, LLAMAPARSE_API_KEY, LLM_API_KEY, MCP_API_KEY, MCP_BOOTSTRAP_MAX_TOKENS, MCP_DCR_REGISTRATION_KEY, MCP_EXTERNAL_EMBEDDING_API_KEY and MCP_HYBRID_KEYWORD_WEIGHT from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does mcp-memory-service run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-memory-video at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (e72d39873669), read on 2026-10-08. The repository is watched and re-audited when it changes.