Atlas / MCP servers / knowall-ai / Neo4j Agent Memory

Neo4j Agent MemoryCAUTION

mcp/knowall-ai/neo4j-agent-memory

Memory management MCP server for AI agents using Neo4j knowledge graphs

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
12 4r · 6w · 2d
Transport
stdio · streamable-http
License
MIT
Stars
69
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://coderabbit.ai)

Reverie is KnowAll AI's Neo4j knowledge-graph memory for AI agents, served over MCP. It is published on npm as `@knowall-ai/reverie` (successor to the legacy package @knowall-ai/mcp-neo4j-agent-memory). The GitHub repository is now knowall-ai/mcp-reverie, and old URLs redirect.

Reverie turns an agent's memory from a pile of facts into a map of the entities in its world and how they relate, and keeps that map healthy. It is an MCP server, so any agent that speaks the Model Context Protocol (Claude Desktop, OpenClaw, Azure AI Foundry, Cursor...) gets the same graph; a Hermes Agent memory-provider flavour lives in hermes-reverie.

Why Reverie

  • A typed entity graph, not a fact store. People, organisations, projects, places, concepts, meetings and decisions are nodes with typed relationships. "Who at the Irish FA have we talked to about Winnie?" is a graph walk, not a similarity search.
  • Search that finds "Ben" when you say "Benjamin". Hybrid keyword + semantic search, with local embeddings by default (no API key) and OpenAI, Azure OpenAI, Ollama or Voyage a config switch away.
  • It dreams. A dream tool merges duplicates safely, canonicalises labels, re-embeds, counts orphans and flags nodes that have become property dumps, so a nightly job can keep the graph clean.
  • One graph, any agent. KnowAll runs Sallie (OpenClaw) and Poppie (Hermes) against the same conventions; Reverie is how they share what they know.
  • LLM-driven, transparent tools. Simple atomic operations; the model does the entity recognition
Read from source at commit b717c0b16810OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add reverie --env NEO4J_PASSWORD=${NEO4J_PASSWORD} -- npx -y @knowall-ai/[email protected]
03

Exposed tools (12)

4 read · 6 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
create_connectionwriteCreate a connection between two memories (its good to have connected memories)
create_memorywriteCreate a new memory in the knowledge graph. Consider that the memory might already exist, so Search → Create → Connect (its important to try and connect memories)
delete_connectiondestructiveDelete a specific connection between two memories (use with caution - this permanently removes the relationship)
delete_memorydestructiveDelete a memory and all its connections (use with caution - this permanently removes the memory and all its connections)
dreamwriteDeterministically relabel, merge duplicates, and refresh embeddings, with an optional dry run report.
get_guidancereadGet help on using the memory tools effectively
list_memory_labelsreadList all unique memory labels currently in use with their counts (useful for getting an overview of the knowledge graph)
memory_statsreadSummarize node, relationship, label, embedding, and orphan counts for the graph.
query_memorieswriteRun a read-only Cypher query and return up to 200 scrubbed rows.
search_memoriesreadHybrid keyword + semantic search across the knowledge graph.
update_connectionwriteUpdate properties of an existing connection between memories
update_memorywriteUpdate properties of an existing memory such as adding more detail or make a change when you find out something new
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/embeddings.ts:251
const host = secureEndpoint(env.OLLAMA_HOST?.trim() || 'http://127.0.0.1:11434', 'OLLAMA_HOST');
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_connection, delete_memory
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit.test.mjs:140
assert.ok(readOnlyViolation("CALL /* hi */ apoc.load.json('http://169.254.169.254/') YIELD value RETURN value"));
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:541
# Reverie HTTP server listening on http://127.0.0.1:8643
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/helpers/http.mjs:25
url: `http://127.0.0.1:${port}`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit.test.mjs:140
assert.ok(readOnlyViolation("CALL /* hi */ apoc.load.json('http://169.254.169.254/') YIELD value RETURN value"));
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@huggingface/transformers, @modelcontextprotocol/sdk, dotenv, neo4j-driver, uuid, zod, @types/node, c8
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SECURITY.md:51
unauthorised access to the Neo4j credentials, and findings from automated scanners with no
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
.smithery/index.cjs
.smithery/index.cjs
Why it matters. 6784582 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/brand/backdrop-clean.png
docs/brand/backdrop-clean.png
Why it matters. 1734194 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
images/reverie-banner.png
images/reverie-banner.png
Why it matters. 1706332 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
images/reverie-icon.png
images/reverie-icon.png
Why it matters. 1260835 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b717c0b16810full audit observations/trust-audit/mcp-server/knowall-ai__neo4j-agent-memory.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b717c0b16810CAUTIONB89first audit
06

Questions

What is the Neo4j Agent Memory MCP server?

Memory management MCP server for AI agents using Neo4j knowledge graphs

What tools does Neo4j Agent Memory expose?

12 in total: 4 read-only, 6 that write, and 2 that can delete or overwrite (delete_connection, delete_memory). Every one is listed on this page with its risk.

Is Neo4j Agent Memory safe to connect to an agent?

With care. The audit graded it B (89/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Neo4j Agent Memory need?

It reads NEO4J_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Neo4j Agent Memory run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @knowall-ai/reverie at 0.5.3.

How current is this page?

The grade is for one exact copy of the source (b717c0b16810), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement