Neo4j Agent MemoryCAUTION
Memory management MCP server for AI agents using Neo4j knowledge graphs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://coderabbit.ai)
Reverie is KnowAll AI's Neo4j knowledge-graph memory for AI agents, served over MCP. It is published on npm as `@knowall-ai/reverie` (successor to the legacy package @knowall-ai/mcp-neo4j-agent-memory). The GitHub repository is now knowall-ai/mcp-reverie, and old URLs redirect.
Reverie turns an agent's memory from a pile of facts into a map of the entities in its world and how they relate, and keeps that map healthy. It is an MCP server, so any agent that speaks the Model Context Protocol (Claude Desktop, OpenClaw, Azure AI Foundry, Cursor...) gets the same graph; a Hermes Agent memory-provider flavour lives in hermes-reverie.
Why Reverie
- A typed entity graph, not a fact store. People, organisations, projects, places, concepts, meetings and decisions are nodes with typed relationships. "Who at the Irish FA have we talked to about Winnie?" is a graph walk, not a similarity search.
- Search that finds "Ben" when you say "Benjamin". Hybrid keyword + semantic search, with local embeddings by default (no API key) and OpenAI, Azure OpenAI, Ollama or Voyage a config switch away.
- It dreams. A
dreamtool merges duplicates safely, canonicalises labels, re-embeds, counts orphans and flags nodes that have become property dumps, so a nightly job can keep the graph clean. - One graph, any agent. KnowAll runs Sallie (OpenClaw) and Poppie (Hermes) against the same conventions; Reverie is how they share what they know.
- LLM-driven, transparent tools. Simple atomic operations; the model does the entity recognition
b717c0b16810OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add reverie --env NEO4J_PASSWORD=${NEO4J_PASSWORD} -- npx -y @knowall-ai/[email protected]Exposed tools (12)
4 read · 6 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
create_connection | write | Create a connection between two memories (its good to have connected memories) |
create_memory | write | Create a new memory in the knowledge graph. Consider that the memory might already exist, so Search → Create → Connect (its important to try and connect memories) |
delete_connection | destructive | Delete a specific connection between two memories (use with caution - this permanently removes the relationship) |
delete_memory | destructive | Delete a memory and all its connections (use with caution - this permanently removes the memory and all its connections) |
dream | write | Deterministically relabel, merge duplicates, and refresh embeddings, with an optional dry run report. |
get_guidance | read | Get help on using the memory tools effectively |
list_memory_labels | read | List all unique memory labels currently in use with their counts (useful for getting an overview of the knowledge graph) |
memory_stats | read | Summarize node, relationship, label, embedding, and orphan counts for the graph. |
query_memories | write | Run a read-only Cypher query and return up to 200 scrubbed rows. |
search_memories | read | Hybrid keyword + semantic search across the knowledge graph. |
update_connection | write | Update properties of an existing connection between memories |
update_memory | write | Update properties of an existing memory such as adding more detail or make a change when you find out something new |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
const host = secureEndpoint(env.OLLAMA_HOST?.trim() || 'http://127.0.0.1:11434', 'OLLAMA_HOST');
delete_connection, delete_memory
assert.ok(readOnlyViolation("CALL /* hi */ apoc.load.json('http://169.254.169.254/') YIELD value RETURN value"));# Reverie HTTP server listening on http://127.0.0.1:8643
url: `http://127.0.0.1:${port}`,assert.ok(readOnlyViolation("CALL /* hi */ apoc.load.json('http://169.254.169.254/') YIELD value RETURN value"));@huggingface/transformers, @modelcontextprotocol/sdk, dotenv, neo4j-driver, uuid, zod, @types/node, c8
unauthorised access to the Neo4j credentials, and findings from automated scanners with no
.smithery/index.cjs
docs/brand/backdrop-clean.png
images/reverie-banner.png
images/reverie-icon.png
Gates applied: no_behavioural_pass.
b717c0b16810full audit observations/trust-audit/mcp-server/knowall-ai__neo4j-agent-memory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b717c0b16810 | CAUTION | B | 89 | first audit |
Questions
What is the Neo4j Agent Memory MCP server?
Memory management MCP server for AI agents using Neo4j knowledge graphs
What tools does Neo4j Agent Memory expose?
12 in total: 4 read-only, 6 that write, and 2 that can delete or overwrite (delete_connection, delete_memory). Every one is listed on this page with its risk.
Is Neo4j Agent Memory safe to connect to an agent?
With care. The audit graded it B (89/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Neo4j Agent Memory need?
It reads NEO4J_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Neo4j Agent Memory run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @knowall-ai/reverie at 0.5.3.
How current is this page?
The grade is for one exact copy of the source (b717c0b16810), read on 2026-10-07. The repository is watched and re-audited when it changes.