Atlas / MCP servers / gannonh / Memento

MementoSAFE

mcp/gannonh/memento

Memento MCP: A Knowledge Graph Memory System for LLMs

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
20 12r · 4w · 4d
Transport
stdio
License
MIT
Stars
425
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Scalable, high performance knowledge graph memory system with semantic retrieval, contextual recall, and temporal awareness. Provides any LLM client that supports the model context protocol (e.g., Claude Desktop, Cursor, Github Copilot) with resilient, adaptive, and persistent long-term ontological memory.

[](https://github.com/gannonh/memento-mcp/actions/workflows/memento-mcp.yml) [](https://smithery.ai/server/@gannonh/memento-mcp)

Core Concepts

Entities

Entities are the primary nodes in the knowledge graph. Each entity has:

  • A unique name (identifier)
  • An entity type (e.g., "person", "organization", "event")
  • A list of observations
  • Vector embeddings (for semantic search)
  • Complete version history

Example:

{
"name": "John_Smith",
"entityType": "person",
"observations": ["Speaks fluent Spanish"]
}

Relations

Relations define directed connections between entities with enhanced properties:

  • Strength indicators (0.0-1.0)
  • Confidence levels (0.0-1.0)
  • Rich metadata (source, timestamps, tags)
  • Temporal awareness with version history
  • Time-based confidence decay

Example:

{
"from": "John_Smith",
"to": "Anthropic",
"relationType": "works_at",
"strength": 0.9,
"confidence": 0.95,
"metadata": {
"source": "linkedin_profile",
"last_verified": "2025-03-21"
}
}

Storage Backend

Memento MCP uses Neo4j as its storage backend, providing a unified solution for both graph storage and vector search capabilities.

Why Neo4j?

  • Unified Storage: Consolidates both graph and vector storage into a single database
  • Native Graph Operations: Built specifically for graph traversal and queries
  • Integrated Vector Search
Read from source at commit 941b81c1fa57OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add memento-mcp --env EMBEDDING_RATE_LIMIT_TOKENS=${EMBEDDING_RATE_LIMIT_TOKENS} --env NEO4J_PASSWORD=${NEO4J_PASSWORD} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y @gannonh/[email protected]
claude-desktop
{
  "mcpServers": {
    "memento-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@gannonh/[email protected]"
      ],
      "env": {
        "EMBEDDING_RATE_LIMIT_TOKENS": "${EMBEDDING_RATE_LIMIT_TOKENS}",
        "NEO4J_PASSWORD": "${NEO4J_PASSWORD}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (20)

12 read · 4 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_observationswriteAdd new observations to existing entities in your Memento MCP knowledge graph memory
create_entitieswriteCreate multiple new entities in your Memento MCP knowledge graph memory system
create_relationswriteCreate multiple new relations between entities in your Memento MCP knowledge graph memory. Relations should be in active voice
debug_embedding_configreadDebug tool to check embedding configuration and status of your Memento MCP knowledge graph memory system
delete_entitiesdestructiveDelete multiple entities and their associated relations from your Memento MCP knowledge graph memory
delete_observationsdestructiveDelete specific observations from entities in your Memento MCP knowledge graph memory
delete_relationsdestructiveDelete multiple relations from your Memento MCP knowledge graph memory
diagnose_vector_searchreadDiagnostic tool to directly query Neo4j database for entity embeddings, bypassing application abstractions
force_generate_embeddingdestructiveForcibly generate and store an embedding for an entity in your Memento MCP knowledge graph memory
get_decayed_graphreadGet your Memento MCP knowledge graph memory with confidence values decayed based on time
get_entity_embeddingreadGet the vector embedding for a specific entity from your Memento MCP knowledge graph memory
get_entity_historyreadGet the version history of an entity from your Memento MCP knowledge graph memory
get_graph_at_timereadGet your Memento MCP knowledge graph memory as it existed at a specific point in time
get_relationreadGet a specific relation with its enhanced properties from your Memento MCP knowledge graph memory
get_relation_historyreadGet the version history of a relation from your Memento MCP knowledge graph memory
open_nodesreadOpen specific nodes in your Memento MCP knowledge graph memory by their names
read_graphreadRead the entire Memento MCP knowledge graph memory system
search_nodesreadSearch for nodes in your Memento MCP knowledge graph memory based on a query
semantic_searchreadSearch for entities semantically using vector embeddings and similarity in your Memento MCP knowledge graph memory
update_relationwriteUpdate an existing relation with enhanced properties in your Memento MCP knowledge graph memory
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_entities, delete_observations, delete_relations, force_generate_embedding
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/embeddings/EmbeddingJobManager.ts:713
return crypto.createHash('md5').update(text).digest('hex');
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/embeddings/__vitest__/EmbeddingServiceIntegration.test.ts:23
console.log(`API key available: ${apiKey ? 'true' : 'false'}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__vitest__/KnowledgeGraphManagerSearch.test.ts:10
const testFilePath = path.join(__dirname, '../../test-output/test-memory.json');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/__vitest__/neo4j-cli.test.ts:2
import { Neo4jConfig } from '../../storage/neo4j/Neo4jConfig';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/__vitest__/storage.test.ts:24
vi.mock('../../storage/StorageProviderFactory');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/__vitest__/storage.test.ts:25
vi.mock('../../storage/VectorStoreFactory.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/__vitest__/storage.test.ts:33
import { StorageProviderFactory } from '../../storage/StorageProviderFactory.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:87
- **HTTP**: `http://127.0.0.1:7474` (for Neo4j Browser UI)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:108
- **HTTP**: `http://127.0.0.1:7474` (for Neo4j Browser UI)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, dotenv, lru-cache, neo4j-driver, openai, ts-node, uuid, @types/lru-cache
Why it matters. 25 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 941b81c1fa57full audit observations/trust-audit/mcp-server/gannonh__memento.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01941b81c1fa57SAFEB89first audit
06

Questions

What is the Memento MCP server?

Memento MCP: A Knowledge Graph Memory System for LLMs

What tools does Memento expose?

20 in total: 12 read-only, 4 that write, and 4 that can delete or overwrite (delete_entities, delete_observations, delete_relations, force_generate_embedding). Every one is listed on this page with its risk.

Is Memento safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Memento need?

It reads EMBEDDING_RATE_LIMIT_TOKENS, NEO4J_PASSWORD and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Memento run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @gannonh/memento-mcp at 0.3.9.

How current is this page?

The grade is for one exact copy of the source (941b81c1fa57), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement