MementoSAFE
Memento MCP: A Knowledge Graph Memory System for LLMs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Scalable, high performance knowledge graph memory system with semantic retrieval, contextual recall, and temporal awareness. Provides any LLM client that supports the model context protocol (e.g., Claude Desktop, Cursor, Github Copilot) with resilient, adaptive, and persistent long-term ontological memory.
[](https://github.com/gannonh/memento-mcp/actions/workflows/memento-mcp.yml) [](https://smithery.ai/server/@gannonh/memento-mcp)
Core Concepts
Entities
Entities are the primary nodes in the knowledge graph. Each entity has:
- A unique name (identifier)
- An entity type (e.g., "person", "organization", "event")
- A list of observations
- Vector embeddings (for semantic search)
- Complete version history
Example:
{
"name": "John_Smith",
"entityType": "person",
"observations": ["Speaks fluent Spanish"]
}Relations
Relations define directed connections between entities with enhanced properties:
- Strength indicators (0.0-1.0)
- Confidence levels (0.0-1.0)
- Rich metadata (source, timestamps, tags)
- Temporal awareness with version history
- Time-based confidence decay
Example:
{
"from": "John_Smith",
"to": "Anthropic",
"relationType": "works_at",
"strength": 0.9,
"confidence": 0.95,
"metadata": {
"source": "linkedin_profile",
"last_verified": "2025-03-21"
}
}Storage Backend
Memento MCP uses Neo4j as its storage backend, providing a unified solution for both graph storage and vector search capabilities.
Why Neo4j?
- Unified Storage: Consolidates both graph and vector storage into a single database
- Native Graph Operations: Built specifically for graph traversal and queries
- Integrated Vector Search
941b81c1fa57OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add memento-mcp --env EMBEDDING_RATE_LIMIT_TOKENS=${EMBEDDING_RATE_LIMIT_TOKENS} --env NEO4J_PASSWORD=${NEO4J_PASSWORD} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @gannonh/[email protected]{
"mcpServers": {
"memento-mcp": {
"command": "npx",
"args": [
"-y",
"@gannonh/[email protected]"
],
"env": {
"EMBEDDING_RATE_LIMIT_TOKENS": "${EMBEDDING_RATE_LIMIT_TOKENS}",
"NEO4J_PASSWORD": "${NEO4J_PASSWORD}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (20)
12 read · 4 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_observations | write | Add new observations to existing entities in your Memento MCP knowledge graph memory |
create_entities | write | Create multiple new entities in your Memento MCP knowledge graph memory system |
create_relations | write | Create multiple new relations between entities in your Memento MCP knowledge graph memory. Relations should be in active voice |
debug_embedding_config | read | Debug tool to check embedding configuration and status of your Memento MCP knowledge graph memory system |
delete_entities | destructive | Delete multiple entities and their associated relations from your Memento MCP knowledge graph memory |
delete_observations | destructive | Delete specific observations from entities in your Memento MCP knowledge graph memory |
delete_relations | destructive | Delete multiple relations from your Memento MCP knowledge graph memory |
diagnose_vector_search | read | Diagnostic tool to directly query Neo4j database for entity embeddings, bypassing application abstractions |
force_generate_embedding | destructive | Forcibly generate and store an embedding for an entity in your Memento MCP knowledge graph memory |
get_decayed_graph | read | Get your Memento MCP knowledge graph memory with confidence values decayed based on time |
get_entity_embedding | read | Get the vector embedding for a specific entity from your Memento MCP knowledge graph memory |
get_entity_history | read | Get the version history of an entity from your Memento MCP knowledge graph memory |
get_graph_at_time | read | Get your Memento MCP knowledge graph memory as it existed at a specific point in time |
get_relation | read | Get a specific relation with its enhanced properties from your Memento MCP knowledge graph memory |
get_relation_history | read | Get the version history of a relation from your Memento MCP knowledge graph memory |
open_nodes | read | Open specific nodes in your Memento MCP knowledge graph memory by their names |
read_graph | read | Read the entire Memento MCP knowledge graph memory system |
search_nodes | read | Search for nodes in your Memento MCP knowledge graph memory based on a query |
semantic_search | read | Search for entities semantically using vector embeddings and similarity in your Memento MCP knowledge graph memory |
update_relation | write | Update an existing relation with enhanced properties in your Memento MCP knowledge graph memory |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
delete_entities, delete_observations, delete_relations, force_generate_embedding
.gitmodules
return crypto.createHash('md5').update(text).digest('hex');console.log(`API key available: ${apiKey ? 'true' : 'false'}`);const testFilePath = path.join(__dirname, '../../test-output/test-memory.json');
import { Neo4jConfig } from '../../storage/neo4j/Neo4jConfig';vi.mock('../../storage/StorageProviderFactory');vi.mock('../../storage/VectorStoreFactory.js');import { StorageProviderFactory } from '../../storage/StorageProviderFactory.js';- **HTTP**: `http://127.0.0.1:7474` (for Neo4j Browser UI)
- **HTTP**: `http://127.0.0.1:7474` (for Neo4j Browser UI)
axios, dotenv, lru-cache, neo4j-driver, openai, ts-node, uuid, @types/lru-cache
Gates applied: no_behavioural_pass.
941b81c1fa57full audit observations/trust-audit/mcp-server/gannonh__memento.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | 941b81c1fa57 | SAFE | B | 89 | first audit |
Questions
What is the Memento MCP server?
Memento MCP: A Knowledge Graph Memory System for LLMs
What tools does Memento expose?
20 in total: 12 read-only, 4 that write, and 4 that can delete or overwrite (delete_entities, delete_observations, delete_relations, force_generate_embedding). Every one is listed on this page with its risk.
Is Memento safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Memento need?
It reads EMBEDDING_RATE_LIMIT_TOKENS, NEO4J_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Memento run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @gannonh/memento-mcp at 0.3.9.
How current is this page?
The grade is for one exact copy of the source (941b81c1fa57), read on 2026-10-01. The repository is watched and re-audited when it changes.