Neo4j Knowledge Graph MemorySAFE
MCP Memory Server with Neo4j backend for AI knowledge graph storage
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@izumisy/mcp-neo4j-memory-server) [](https://opensource.org/licenses/MIT) [](https://www.typescriptlang.org/) [](https://neo4j.com/)
简介
MCP Neo4j Knowledge Graph Memory Server是一个基于Neo4j图数据库的知识图谱记忆服务器,用于存储和检索AI助手与用户交互过程中的信息。该项目是官方Knowledge Graph Memory Server的增强版本,使用Neo4j作为后端存储引擎。
通过使用Neo4j作为存储后端,本项目提供了更强大的图查询能力、更好的性能和可扩展性,特别适合构建复杂的知识图谱应用。
功能特点
- 🚀 基于Neo4j的高性能图数据库存储
- 🔍 强大的模糊搜索和精确匹配能力
- 🔄 实体、关系和观察的完整CRUD操作
- 🌐 与MCP协议完全兼容
- 📊 支持复杂的图查询和遍历
- 🐳 Docker支持,便于部署
安装
前提条件
- Node.js >= 22.0.0
- Neo4j数据库(本地或远程)
通过npm安装
# 全局安装 npm install -g @jovanhsu/mcp-neo4j-memory-server # 或作为项目依赖安装 npm install @jovanhsu/mcp-neo4j-memory-server
使用Docker
# 使用docker-compose启动Neo4j和Memory Server git clone https://github.com/JovanHsu/mcp-neo4j-memory-server.git cd mcp-neo4j-memory-server docker-compose up -d
环境变量配置
服务器使用以下环境变量进行配置:
与Claude集成
在Claude Desktop中配置
在claude_desktop_config.json中添加以下配置:
{
"mcpServers": {
"graph-memory": {
"command": "npx",
"args": [
"-y",
"@izumisy/mcp-neo4j-memory-server"
],
"env": {
"NEO4J_URI": "neo4j://localhost:7687",
"NEO4J_USER": "neo4j",
"NEO4J_PASSWORD": "password",
"NEO4J_DATABASE": "memory"
}
}
}
}在Claude Web中使用MCP Inspector
- 安装[MCP Inspector](https://
f7e9fab61d16OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-neo4j-memory-server --env NEO4J_PASSWORD=${NEO4J_PASSWORD} -- npx -y @jovanhsu/[email protected]{
"mcpServers": {
"mcp-neo4j-memory-server": {
"command": "npx",
"args": [
"-y",
"@jovanhsu/[email protected]"
],
"env": {
"NEO4J_PASSWORD": "${NEO4J_PASSWORD}"
}
}
}
}Exposed tools (8)
2 read · 3 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_observations | write | Add new observations to existing entities in the knowledge graph |
create_entities | write | Create multiple new entities in the knowledge graph |
create_relations | write | Create multiple new relations between entities in the knowledge graph. Relations should be in active voice |
delete_entities | destructive | Delete multiple entities and their associated relations from the knowledge graph |
delete_observations | destructive | Delete specific observations from entities in the knowledge graph |
delete_relations | destructive | Delete multiple relations from the knowledge graph |
open_nodes | read | Open specific nodes in the knowledge graph by their names |
search_nodes | read | Search for nodes in the knowledge graph based on a query |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
delete_entities, delete_observations, delete_relations
@modelcontextprotocol/sdk, neo4j-driver, fuse.js, zod, @changesets/cli, @types/node, prettier, shx
You should assume that you are interacting with default_user
Always begin your chat by saying only "Remembering..."
Gates applied: no_behavioural_pass.
f7e9fab61d16full audit observations/trust-audit/mcp-server/jovanhsu__neo4j-knowledge-graph-memory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | f7e9fab61d16 | SAFE | B | 89 | first audit |
Questions
What is the Neo4j Knowledge Graph Memory MCP server?
MCP Memory Server with Neo4j backend for AI knowledge graph storage
What tools does Neo4j Knowledge Graph Memory expose?
8 in total: 2 read-only, 3 that write, and 3 that can delete or overwrite (delete_entities, delete_observations, delete_relations). Every one is listed on this page with its risk.
Is Neo4j Knowledge Graph Memory safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Neo4j Knowledge Graph Memory need?
It reads NEO4J_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Neo4j Knowledge Graph Memory run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @jovanhsu/mcp-neo4j-memory-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (f7e9fab61d16), read on 2026-10-09. The repository is watched and re-audited when it changes.