Memory KeeperSAFE
MCP server for persistent context management in AI coding assistants
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/mcp-memory-keeper) [](https://www.npmjs.com/package/mcp-memory-keeper) [](https://github.com/mkreyman/mcp-memory-keeper/actions/workflows/ci.yml) [](https://codecov.io/gh/mkreyman/mcp-memory-keeper) [](https://opensource.org/licenses/MIT)
A Model Context Protocol (MCP) server that provides persistent context management for Claude AI coding assistants. Never lose context during compaction again! This MCP server helps Claude Code maintain context across sessions, preserving your work history, decisions, and progress.
🚀 Quick Start
Get started in under 30 seconds:
# Add memory-keeper to Claude claude mcp add memory-keeper npx mcp-memory-keeper # Start a new Claude session and use it! # Try: Analyze the current repo and save your analysis in memory-keeper
That's it! Memory Keeper is now available in all your Claude sessions. Your context is stored in ~/mcp-data/memory-keeper/ and persists across sessions.
🚀 Practical Memory Keeper Workflow Example
Custom Command + CLAUDE.md = Automatic Context Management
CLAUDE.md (condensed example)
# Project Configuration ## Development Rules - Always use memory-keeper to track progress - Save architectural decisions and test results - Create checkpoints before context limits ## Quality Standards - All tests must pass before marking complete - Document actual vs claimed results
Custom Command Example: `/my-dev-workflow`
# My Development Workflow When working on the provided project: - Use
313987d3fa66OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-memory-keeper --env MCP_CHARS_PER_TOKEN=${MCP_CHARS_PER_TOKEN} --env MCP_MAX_TOKENS=${MCP_MAX_TOKENS} --env MCP_TOKEN_SAFETY_BUFFER=${MCP_TOKEN_SAFETY_BUFFER} -- npx -y [email protected]{
"mcpServers": {
"mcp-memory-keeper": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MCP_CHARS_PER_TOKEN": "${MCP_CHARS_PER_TOKEN}",
"MCP_MAX_TOKENS": "${MCP_MAX_TOKENS}",
"MCP_TOKEN_SAFETY_BUFFER": "${MCP_TOKEN_SAFETY_BUFFER}"
}
}
}
}Exposed tools (48)
29 read · 18 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
context_analyze | read | Analyze context to extract entities and relationships |
context_batch_delete | destructive | Delete multiple context items by keys or pattern in a single atomic operation |
context_batch_save | write | Save multiple context items in a single atomic operation |
context_batch_update | write | Update multiple context items with partial updates in a single atomic operation |
context_branch_session | write | Create a branch from current session for exploring alternatives |
context_cache_file | read | Cache file content with hash for change detection |
context_channel_stats | read | Get detailed statistics for a specific channel or all channels |
context_checkpoint | write | Create a named checkpoint of current context |
context_compress | write | Intelligently compress old context to save space |
context_delegate | read | Delegate complex analysis tasks to specialized agents |
context_diff | read | Get changes to context items since a specific point in time (timestamp, checkpoint, or relative time) |
context_export | read | Export session data (context items, cached files, and checkpoints with their |
context_file_changed | read | Check if a file has changed since it was cached |
context_find_related | read | Find entities related to a key or entity |
context_get | read | Retrieve saved context by key, category, or session with enhanced filtering. Returns all accessible items (public items + own private items) |
context_get_related | read | Get items related to a given context item |
context_get_shared | read | Get shared context items from other sessions |
context_git_commit | write | Create git commit with automatic context save |
context_import | write | Import previously exported session data. For security, imports are confined to the |
context_integrate_tool | read | Track events from other MCP tools |
context_journal_entry | write | Add a timestamped journal entry with optional tags and mood |
context_link | write | Create a relationship between two context items |
context_list_channels | read | List all channels with metadata (counts, activity, categories) |
context_merge_sessions | write | Merge another session into the current one |
context_prepare_compaction | write | Automatically save critical context before compaction |
context_reassign_channel | write | Move context items between channels based on keys, patterns, or entire channel |
context_restore_checkpoint | read | Restore context from a checkpoint |
context_save | write | Save a context item with optional category, priority, and privacy setting |
context_search | read | Search through saved context items with advanced filtering |
context_search_all | read | Search across multiple or all sessions with pagination support |
context_semantic_search | read | Search context using natural language queries |
context_session_list | read | List recent sessions |
context_session_start | write | Start a new context session with optional project directory for git tracking |
context_set_project_dir | write | Set the project directory for git tracking in the current session |
context_share | read | Share a context item with other sessions for cross-session collaboration |
context_status | read | Get current context status and statistics |
context_summarize | read | Get AI-friendly summary of session context |
context_timeline | read | Get timeline of activities with optional grouping |
context_visualize | read | Generate visualization data for the knowledge graph |
context_watch | write | Create and manage watchers for real-time context change monitoring |
cp-roundtrip | read | round trip checkpoint |
generate_recommendations | read | Generate actionable recommendations |
merge_insights | write | Merge insights from multiple agents |
pattern_detection | read | Detect patterns in saved context |
relationship_extraction | read | Extract relationships between entities |
summarization | write | Create summaries from multiple context items |
test_capability | read | Test capability |
trend_analysis | read | Analyze trends over time |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
context_batch_delete
.lintstagedrc.json
.prettierignore
.prettierrc.json
const hash = crypto.createHash('md5').update(ngram).digest();console.log(`Items token estimate: ${estimatedTokens}`);const SERVER_ENTRY = path.join(__dirname, '../../../dist/index.js');
serverProcess = spawn('node', [path.join(__dirname, '../../../dist/index.js')], {const pkgVersion = require('../../../package.json').version;filePath: '../../../../../../etc/hostname',
const proc = spawn('node', [path.join(__dirname, '../../../dist/index.js')], {@modelcontextprotocol/sdk, better-sqlite3, simple-git, uuid, @eslint/js, @jest/globals, @types/better-sqlite3, @types/jest
Gates applied: no_behavioural_pass.
313987d3fa66full audit observations/trust-audit/mcp-server/mkreyman__memory-keeper.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 313987d3fa66 | SAFE | B | 89 | first audit |
Questions
What is the Memory Keeper MCP server?
MCP server for persistent context management in AI coding assistants
What tools does Memory Keeper expose?
48 in total: 29 read-only, 18 that write, and 1 that can delete or overwrite (context_batch_delete). Every one is listed on this page with its risk.
Is Memory Keeper safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Memory Keeper need?
It reads MCP_CHARS_PER_TOKEN, MCP_MAX_TOKENS and MCP_TOKEN_SAFETY_BUFFER from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Memory Keeper run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-memory-keeper at 0.14.1.
How current is this page?
The grade is for one exact copy of the source (313987d3fa66), read on 2026-10-07. The repository is watched and re-audited when it changes.