Atlas / MCP servers / mkreyman / Memory Keeper

Memory KeeperSAFE

mcp/mkreyman/memory-keeper

MCP server for persistent context management in AI coding assistants

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
48 29r · 18w · 1d
Transport
stdio
License
MIT
Stars
136
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mcp-memory-keeper) [](https://www.npmjs.com/package/mcp-memory-keeper) [](https://github.com/mkreyman/mcp-memory-keeper/actions/workflows/ci.yml) [](https://codecov.io/gh/mkreyman/mcp-memory-keeper) [](https://opensource.org/licenses/MIT)

A Model Context Protocol (MCP) server that provides persistent context management for Claude AI coding assistants. Never lose context during compaction again! This MCP server helps Claude Code maintain context across sessions, preserving your work history, decisions, and progress.

🚀 Quick Start

Get started in under 30 seconds:

# Add memory-keeper to Claude
claude mcp add memory-keeper npx mcp-memory-keeper

# Start a new Claude session and use it!
# Try: Analyze the current repo and save your analysis in memory-keeper

That's it! Memory Keeper is now available in all your Claude sessions. Your context is stored in ~/mcp-data/memory-keeper/ and persists across sessions.

🚀 Practical Memory Keeper Workflow Example

Custom Command + CLAUDE.md = Automatic Context Management

CLAUDE.md (condensed example)

# Project Configuration

## Development Rules

- Always use memory-keeper to track progress
- Save architectural decisions and test results
- Create checkpoints before context limits

## Quality Standards

- All tests must pass before marking complete
- Document actual vs claimed results

Custom Command Example: `/my-dev-workflow`

# My Development Workflow

When working on the provided project:

- Use
Read from source at commit 313987d3fa66OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-memory-keeper --env MCP_CHARS_PER_TOKEN=${MCP_CHARS_PER_TOKEN} --env MCP_MAX_TOKENS=${MCP_MAX_TOKENS} --env MCP_TOKEN_SAFETY_BUFFER=${MCP_TOKEN_SAFETY_BUFFER} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-memory-keeper": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "MCP_CHARS_PER_TOKEN": "${MCP_CHARS_PER_TOKEN}",
        "MCP_MAX_TOKENS": "${MCP_MAX_TOKENS}",
        "MCP_TOKEN_SAFETY_BUFFER": "${MCP_TOKEN_SAFETY_BUFFER}"
      }
    }
  }
}
03

Exposed tools (48)

29 read · 18 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
context_analyzereadAnalyze context to extract entities and relationships
context_batch_deletedestructiveDelete multiple context items by keys or pattern in a single atomic operation
context_batch_savewriteSave multiple context items in a single atomic operation
context_batch_updatewriteUpdate multiple context items with partial updates in a single atomic operation
context_branch_sessionwriteCreate a branch from current session for exploring alternatives
context_cache_filereadCache file content with hash for change detection
context_channel_statsreadGet detailed statistics for a specific channel or all channels
context_checkpointwriteCreate a named checkpoint of current context
context_compresswriteIntelligently compress old context to save space
context_delegatereadDelegate complex analysis tasks to specialized agents
context_diffreadGet changes to context items since a specific point in time (timestamp, checkpoint, or relative time)
context_exportreadExport session data (context items, cached files, and checkpoints with their
context_file_changedreadCheck if a file has changed since it was cached
context_find_relatedreadFind entities related to a key or entity
context_getreadRetrieve saved context by key, category, or session with enhanced filtering. Returns all accessible items (public items + own private items)
context_get_relatedreadGet items related to a given context item
context_get_sharedreadGet shared context items from other sessions
context_git_commitwriteCreate git commit with automatic context save
context_importwriteImport previously exported session data. For security, imports are confined to the
context_integrate_toolreadTrack events from other MCP tools
context_journal_entrywriteAdd a timestamped journal entry with optional tags and mood
context_linkwriteCreate a relationship between two context items
context_list_channelsreadList all channels with metadata (counts, activity, categories)
context_merge_sessionswriteMerge another session into the current one
context_prepare_compactionwriteAutomatically save critical context before compaction
context_reassign_channelwriteMove context items between channels based on keys, patterns, or entire channel
context_restore_checkpointreadRestore context from a checkpoint
context_savewriteSave a context item with optional category, priority, and privacy setting
context_searchreadSearch through saved context items with advanced filtering
context_search_allreadSearch across multiple or all sessions with pagination support
context_semantic_searchreadSearch context using natural language queries
context_session_listreadList recent sessions
context_session_startwriteStart a new context session with optional project directory for git tracking
context_set_project_dirwriteSet the project directory for git tracking in the current session
context_sharereadShare a context item with other sessions for cross-session collaboration
context_statusreadGet current context status and statistics
context_summarizereadGet AI-friendly summary of session context
context_timelinereadGet timeline of activities with optional grouping
context_visualizereadGenerate visualization data for the knowledge graph
context_watchwriteCreate and manage watchers for real-time context change monitoring
cp-roundtripreadround trip checkpoint
generate_recommendationsreadGenerate actionable recommendations
merge_insightswriteMerge insights from multiple agents
pattern_detectionreadDetect patterns in saved context
relationship_extractionreadExtract relationships between entities
summarizationwriteCreate summaries from multiple context items
test_capabilityreadTest capability
trend_analysisreadAnalyze trends over time
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (12)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
context_batch_delete
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.lintstagedrc.json
.lintstagedrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/utils/vector-store.ts:67
const hash = crypto.createHash('md5').update(ngram).digest();
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/__tests__/integration/issue24-final-fix.test.ts:161
console.log(`Items token estimate: ${estimatedTokens}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/e2e/checkpoint-round-trip.test.ts:26
const SERVER_ENTRY = path.join(__dirname, '../../../dist/index.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/e2e/import-path-confinement.test.ts:107
serverProcess = spawn('node', [path.join(__dirname, '../../../dist/index.js')], {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/e2e/import-path-confinement.test.ts:158
const pkgVersion = require('../../../package.json').version;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/e2e/import-path-confinement.test.ts:205
filePath: '../../../../../../etc/hostname',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/e2e/issue33-reproduce.test.ts:87
const proc = spawn('node', [path.join(__dirname, '../../../dist/index.js')], {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, better-sqlite3, simple-git, uuid, @eslint/js, @jest/globals, @types/better-sqlite3, @types/jest
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 313987d3fa66full audit observations/trust-audit/mcp-server/mkreyman__memory-keeper.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07313987d3fa66SAFEB89first audit
06

Questions

What is the Memory Keeper MCP server?

MCP server for persistent context management in AI coding assistants

What tools does Memory Keeper expose?

48 in total: 29 read-only, 18 that write, and 1 that can delete or overwrite (context_batch_delete). Every one is listed on this page with its risk.

Is Memory Keeper safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Memory Keeper need?

It reads MCP_CHARS_PER_TOKEN, MCP_MAX_TOKENS and MCP_TOKEN_SAFETY_BUFFER from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Memory Keeper run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-memory-keeper at 0.14.1.

How current is this page?

The grade is for one exact copy of the source (313987d3fa66), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement