Mnemo CortexCAUTION
Open-source cognitive coprocessor with active memory for AI agents — persistent recall, semantic search, overnight dreaming, verified facts, encrypted USB sync. MCP server; works with Claude, ChatGPT, and any local LLM. Built by one maker and his agents.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://glama.ai/mcp/servers/GuyMannDude/mnemo-cortex)
🌐 Home: [projectsparks.ai](https://projectsparks.ai) — the story, the docs, and how the project is funded.
The Project Sparks ecosystem — everything is free; the whole thing runs on donations. Satisfaction guaranteed, or your no money back. 🎨 Free Art Gallery · 🧒 Kids Seek-&-Find Gallery · 🎁 Mnemo Swag · 🌐 projectsparks.ai · ❤️ PayPal / GitHub Sponsors / Ko-fi
Why this exists
The big AI-memory systems run on millions in venture capital. Mnemo Cortex was built by one 73-year-old maker — on Social Security, a $20-a-month Claude subscription, and a stubborn belief that his AI partners should remember him.
It is not a demo. It is the production memory of a working five-agent fleet on two machines, every day since March 2026:
- *~10,000 memories
152a95a52300OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mnemo-cortex-mcp-bridge --env API_KEY=${API_KEY} --env DISCORD_TOKEN_FILE=${DISCORD_TOKEN_FILE} --env MNEMO_AUTH_TOKEN=${MNEMO_AUTH_TOKEN} --env MNEMO_DREAM_FACT_MAX_TOKENS=${MNEMO_DREAM_FACT_MAX_TOKENS} -- npx -y [email protected]{
"mcpServers": {
"mnemo-cortex-mcp-bridge": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"DISCORD_TOKEN_FILE": "${DISCORD_TOKEN_FILE}",
"MNEMO_AUTH_TOKEN": "${MNEMO_AUTH_TOKEN}",
"MNEMO_DREAM_FACT_MAX_TOKENS": "${MNEMO_DREAM_FACT_MAX_TOKENS}"
}
}
}
}Exposed tools (31)
27 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
agent_startup | read | |
list_brain_files | read | |
mnemo_capture_pause | read | |
mnemo_capture_resume | read | |
mnemo_fact_authority | read | |
mnemo_fact_demote | read | |
mnemo_fact_get | read | |
mnemo_fact_proposals | read | |
mnemo_fact_query | read | |
mnemo_fact_save | write | |
mnemo_memory_demote | read | |
mnemo_recall | read | |
mnemo_recall_trajectory | read | |
mnemo_save | write | |
mnemo_save_trajectory | write | |
mnemo_search | read | |
mnemo_share | read | |
mnemo_transcript | read | |
opie_startup | read | |
passport_forget_or_override | read | |
passport_get_user_context | read | |
passport_list_pending_observations | read | |
passport_observe_behavior | read | |
passport_promote_observation | read | |
read_brain_file | read | |
session_checkpoint | read | |
session_end | read | |
wiki_index | read | |
wiki_read | read | |
wiki_search | read | |
write_brain_file | write |
Trust audit
CAUTIONgrade D · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (11 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
integrations/openclaw-mcp/package.json
integrations/openclaw-mcp/server.js
print(f"Auth: {'X-API-KEY (token set)' if auth_headers() else 'none (loopback)'}")cors_list = '["http://127.0.0.1", "http://localhost"]'
'postgres://mnemo:[email protected]:5432/cortex',
'redis://user:[email protected]',
text = "DISCORD_TOKEN=abcdef1234567890XYZ and postgres://u:p4ssw0rd@h/db"
"actions": [{"command": "export GH=ghp_AbCdEfGhIjKlMnOpQrStUvWxYz0123456789", "n": 3}],("secret_private_key_pem", "-----BEGIN RSA PRIVATE KEY-----\nMIIE..."),("secret_slack_token", "xoxb-123456789012-abcdefABCDEF"),importlib.import_module(mod)
vec[int(hashlib.md5(word.encode()).hexdigest(), 16) % 768] += 1.0
"../../../tmp/pwn", # relative traversal
body = {"agent_id": "../../../tmp/mnemo_pwn", "summary": "escape",r = client.post("/context", json={"agent_id": "../../etc", "prompt": "hi"},"../../../etc/passwd", "/etc/passwd", "a/b", "a.b", "", "A" * 129, "x\ny",
sm.get_session_transcript("../../secret")(`MNEMO_URL` default `http://127.0.0.1:50001`); optional `MNEMO_AUTH_TOKEN`
curl -s -o /dev/null -w "%{http_code}\n" -X POST http://127.0.0.1:50002/recallcurl -s -X POST http://127.0.0.1:50001/context \
Check the server: `curl http://127.0.0.1:50001/health` on the gate machine,
passphrase.encode(), salt=bytes.fromhex(kdf["salt"]),
return bytes.fromhex(p.read_text(encoding="utf-8").strip())
@modelcontextprotocol/sdk, zod
- **Boot: the SIMILARITY MATCHES section is CUT — removed outright, replaced with nothing** (`integrations/mcp-bridge/server.js`; its 2,000-unit budget retired from `boot-budget.js`). Problem this fix
Gates applied: no_behavioural_pass.
152a95a52300full audit observations/trust-audit/mcp-server/guymanndude__mnemo-cortex.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 152a95a52300 | CAUTION | D | 60 | first audit |
Questions
What is the Mnemo Cortex MCP server?
Open-source cognitive coprocessor with active memory for AI agents — persistent recall, semantic search, overnight dreaming, verified facts, encrypted USB sync. MCP server; works with Claude, ChatGPT, and any local LLM. Built by one maker and his agents.
What tools does Mnemo Cortex expose?
31 in total: 27 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Mnemo Cortex safe to connect to an agent?
With care. The audit graded it D (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Mnemo Cortex need?
It reads API_KEY, DISCORD_TOKEN_FILE, MNEMO_AUTH_TOKEN, MNEMO_DREAM_FACT_MAX_TOKENS, MNEMO_DREAM_STRATEGY_MAX_TOKENS, MNEMO_GATE_TOKEN_FILE, MNEMO_GATE_UPSTREAM_TOKEN_FILE, MNEMO_JEV_KEY_FILE, MNEMO_PASSPORT_DIR, OPENROUTER_API_KEY, TEST_AGENTB_KEY and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mnemo Cortex run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mnemo-cortex-mcp-bridge at 2.34.0.
How current is this page?
The grade is for one exact copy of the source (152a95a52300), read on 2026-10-07. The repository is watched and re-audited when it changes.