Atlas / MCP servers / guymanndude / Mnemo Cortex

Mnemo CortexCAUTION

mcp/guymanndude/mnemo-cortex

Open-source cognitive coprocessor with active memory for AI agents — persistent recall, semantic search, overnight dreaming, verified facts, encrypted USB sync. MCP server; works with Claude, ChatGPT, and any local LLM. Built by one maker and his agents.

Verdict
CAUTION
Grade
D
Trust score
60 /100
Exposed tools
31 27r · 4w · 0d
Transport
stdio
License
MIT
Stars
157
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://glama.ai/mcp/servers/GuyMannDude/mnemo-cortex)

🌐 Home: [projectsparks.ai](https://projectsparks.ai) — the story, the docs, and how the project is funded.

The Project Sparks ecosystem — everything is free; the whole thing runs on donations. Satisfaction guaranteed, or your no money back. 🎨 Free Art Gallery · 🧒 Kids Seek-&-Find Gallery · 🎁 Mnemo Swag · 🌐 projectsparks.ai · ❤️ PayPal / GitHub Sponsors / Ko-fi

Why this exists

The big AI-memory systems run on millions in venture capital. Mnemo Cortex was built by one 73-year-old maker — on Social Security, a $20-a-month Claude subscription, and a stubborn belief that his AI partners should remember him.

It is not a demo. It is the production memory of a working five-agent fleet on two machines, every day since March 2026:

  • *~10,000 memories
Read from source at commit 152a95a52300OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mnemo-cortex-mcp-bridge --env API_KEY=${API_KEY} --env DISCORD_TOKEN_FILE=${DISCORD_TOKEN_FILE} --env MNEMO_AUTH_TOKEN=${MNEMO_AUTH_TOKEN} --env MNEMO_DREAM_FACT_MAX_TOKENS=${MNEMO_DREAM_FACT_MAX_TOKENS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mnemo-cortex-mcp-bridge": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "DISCORD_TOKEN_FILE": "${DISCORD_TOKEN_FILE}",
        "MNEMO_AUTH_TOKEN": "${MNEMO_AUTH_TOKEN}",
        "MNEMO_DREAM_FACT_MAX_TOKENS": "${MNEMO_DREAM_FACT_MAX_TOKENS}"
      }
    }
  }
}
03

Exposed tools (31)

27 read · 4 write · 0 destructive.

ToolRiskDescription
agent_startupread
list_brain_filesread
mnemo_capture_pauseread
mnemo_capture_resumeread
mnemo_fact_authorityread
mnemo_fact_demoteread
mnemo_fact_getread
mnemo_fact_proposalsread
mnemo_fact_queryread
mnemo_fact_savewrite
mnemo_memory_demoteread
mnemo_recallread
mnemo_recall_trajectoryread
mnemo_savewrite
mnemo_save_trajectorywrite
mnemo_searchread
mnemo_shareread
mnemo_transcriptread
opie_startupread
passport_forget_or_overrideread
passport_get_user_contextread
passport_list_pending_observationsread
passport_observe_behaviorread
passport_promote_observationread
read_brain_fileread
session_checkpointread
session_endread
wiki_indexread
wiki_readread
wiki_searchread
write_brain_filewrite
04

Trust audit

CAUTIONgrade D · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (11 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
integrations/openclaw-mcp/package.json
integrations/openclaw-mcp/package.json
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
integrations/openclaw-mcp/server.js
integrations/openclaw-mcp/server.js
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tools/seed-facts.py:145
print(f"Auth:      {'X-API-KEY (token set)' if auth_headers() else 'none (loopback)'}")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
agentb/cli.py:160
cors_list = '["http://127.0.0.1", "http://localhost"]'
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_m_group_storage.py:134
'postgres://mnemo:[email protected]:5432/cortex',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_m_group_storage.py:135
'redis://user:[email protected]',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_m_group_storage.py:151
text = "DISCORD_TOKEN=abcdef1234567890XYZ and postgres://u:p4ssw0rd@h/db"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/test_redact.py:145
"actions": [{"command": "export GH=ghp_AbCdEfGhIjKlMnOpQrStUvWxYz0123456789", "n": 3}],
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/passport/test_detectors.py:41
("secret_private_key_pem", "-----BEGIN RSA PRIVATE KEY-----\nMIIE..."),
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
tests/passport/test_detectors.py:40
("secret_slack_token", "xoxb-123456789012-abcdefABCDEF"),
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/wheel-smoke-test.sh:49
importlib.import_module(mod)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_chat.py:37
vec[int(hashlib.md5(word.encode()).hexdigest(), 16) % 768] += 1.0
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_c1_c2.py:58
"../../../tmp/pwn",       # relative traversal
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_c1_c2.py:97
body = {"agent_id": "../../../tmp/mnemo_pwn", "summary": "escape",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_c1_c2.py:114
r = client.post("/context", json={"agent_id": "../../etc", "prompt": "hi"},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_c1_c2.py:150
"../../../etc/passwd", "/etc/passwd", "a/b", "a.b", "", "A" * 129, "x\ny",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_security_c1_c2.py:166
sm.get_session_transcript("../../secret")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CHANGELOG.md:3753
(`MNEMO_URL` default `http://127.0.0.1:50001`); optional `MNEMO_AUTH_TOKEN`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/install-chatgpt.md:107
curl -s -o /dev/null -w "%{http_code}\n" -X POST http://127.0.0.1:50002/recall
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/install-chatgpt.md:188
curl -s -X POST http://127.0.0.1:50001/context \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/install-chatgpt.md:218
Check the server: `curl http://127.0.0.1:50001/health` on the gate machine,
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
agentb/stick.py:186
passphrase.encode(), salt=bytes.fromhex(kdf["salt"]),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
agentb/stick.py:225
return bytes.fromhex(p.read_text(encoding="utf-8").strip())
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
integrations/mcp-bridge/package.json
@modelcontextprotocol/sdk, zod
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:1971
- **Boot: the SIMILARITY MATCHES section is CUT — removed outright, replaced with nothing** (`integrations/mcp-bridge/server.js`; its 2,000-unit budget retired from `boot-budget.js`). Problem this fix
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 152a95a52300full audit observations/trust-audit/mcp-server/guymanndude__mnemo-cortex.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07152a95a52300CAUTIOND60first audit
06

Questions

What is the Mnemo Cortex MCP server?

Open-source cognitive coprocessor with active memory for AI agents — persistent recall, semantic search, overnight dreaming, verified facts, encrypted USB sync. MCP server; works with Claude, ChatGPT, and any local LLM. Built by one maker and his agents.

What tools does Mnemo Cortex expose?

31 in total: 27 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Mnemo Cortex safe to connect to an agent?

With care. The audit graded it D (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Mnemo Cortex need?

It reads API_KEY, DISCORD_TOKEN_FILE, MNEMO_AUTH_TOKEN, MNEMO_DREAM_FACT_MAX_TOKENS, MNEMO_DREAM_STRATEGY_MAX_TOKENS, MNEMO_GATE_TOKEN_FILE, MNEMO_GATE_UPSTREAM_TOKEN_FILE, MNEMO_JEV_KEY_FILE, MNEMO_PASSPORT_DIR, OPENROUTER_API_KEY, TEST_AGENTB_KEY and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mnemo Cortex run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mnemo-cortex-mcp-bridge at 2.34.0.

How current is this page?

The grade is for one exact copy of the source (152a95a52300), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement