MnemoCAUTION
Persistent memory for Claude Code. Your AI never starts from scratch again.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Persistent memory for Claude Code. Your AI never starts from scratch again.
[](https://github.com/omermaksutii/mnemo/actions) [](https://www.npmjs.com/package/@mnemo-mcp/cli) [](https://www.npmjs.com/package/@mnemo-mcp/server) [](https://www.npmjs.com/package/@mnemo-mcp/core) [](LICENSE)
Mnemo gives Claude Code a brain that survives across sessions. It captures decisions, conventions, and preferences — and recalls them by meaning, on demand, with sub-100ms semantic search.
Install
# install the CLI npm install -g @mnemo-mcp/cli # install Mnemo into Claude Code (skill + MCP server) mnemo init # (optional) also wire auto-capture hooks mnemo init --with-hooks # verify mnemo doctor
After mnemo init, restart Claude Code. The /mnemo skill and the mnemo_* MCP tools are now available — Claude will use them automatically when relevant.
Use it from the terminal too
mnemo remember "our API auth uses OAuth2 with refresh tokens every 30min" mnemo remember --global "I prefer pnpm over npm" mnemo recall "what's our auth pattern?" mnemo recall "auth" --explain # show the ranking breakdown per hit mnemo list mnemo stats mnemo forget mnemo backup # timestamped snapshot mnemo restore mnemo-backups/.json mnemo migrate # rebuild the index after an embedder change mnemo serve # localhost web dashboard mnemo watch docs/ # auto-capture matching files as they chan
c49d6265c2f7OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sync-server --env MNEMO_ENCRYPTION_KEY=${MNEMO_ENCRYPTION_KEY} --env MNEMO_SYNC_TOKEN=${MNEMO_SYNC_TOKEN} -- npx -y @mnemo-mcp/[email protected]{
"mcpServers": {
"sync-server": {
"command": "npx",
"args": [
"-y",
"@mnemo-mcp/[email protected]"
],
"env": {
"MNEMO_ENCRYPTION_KEY": "${MNEMO_ENCRYPTION_KEY}",
"MNEMO_SYNC_TOKEN": "${MNEMO_SYNC_TOKEN}"
}
}
}
}Exposed tools (15)
12 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
AuthService | read | handles login |
a | read | d |
add-endpoint | write | Add a new REST API endpoint |
b | read | d |
mnemo_entity_context | read | Everything known about an entity (a named service/module/concept): its memories and directly-related entities |
mnemo_forget | destructive | Delete a memory by id (full or 8-char prefix) |
mnemo_list | read | List recent memories |
mnemo_procedure_run | write | Retrieve a named procedure as a checklist (use before executing the workflow) |
mnemo_procedure_suggest | read | Find a procedural workflow that matches a task description, if one exists |
mnemo_recall | read | Semantic recall of stored memories |
mnemo_remember | read | Capture a memory |
mnemo_stats | read | Show memory engine stats |
mnemo_what_depends_on | read | Graph traversal: which entities transitively require or use the named entity |
p | read | d |
p1 | read | d |
Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (16)
if (skipped.length) console.log(chalk.yellow(` skipped ${skipped.length} (secret content)`));console.log(` auth: ${token ? 'bearer token required' : 'OPEN (no token — dev only)'}`);expect(hasSecrets('here is my token ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj')).toBe(true);const matches = detectSecrets('ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj');m.capture({ content: 'secret: ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj', scope: 'global' }),content: 'this contains ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj',
mnemo_forget
crypto.test.ts
process.env.MNEMO_SYNC_URL = `http://127.0.0.1:${h.port}`;base = `http://127.0.0.1:${h.port}`;@types/node, typescript, vitest, tsx
commander, chalk
@huggingface/transformers, hnswlib-node, sql.js, @types/sql.js
@modelcontextprotocol/sdk, zod
- **`@mnemo-mcp/sync-server`** — a new, self-hostable, dependency-light blob backend (`mnemo-sync-server`). Stores one opaque ciphertext blob per namespace; bearer-token auth; `/v1/health` + `/v1/blob
demo.gif
Gates applied: no_behavioural_pass.
c49d6265c2f7full audit observations/trust-audit/mcp-server/omermaksutii__mnemo-8.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | c49d6265c2f7 | CAUTION | C | 75 | first audit |
Questions
What is the Mnemo MCP server?
Persistent memory for Claude Code. Your AI never starts from scratch again.
What tools does Mnemo expose?
15 in total: 12 read-only, 2 that write, and 1 that can delete or overwrite (mnemo_forget). Every one is listed on this page with its risk.
Is Mnemo safe to connect to an agent?
With care. The audit graded it C (75/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Mnemo need?
It reads MNEMO_ENCRYPTION_KEY and MNEMO_SYNC_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mnemo run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mnemo-mcp/sync-server at 2.6.0.
How current is this page?
The grade is for one exact copy of the source (c49d6265c2f7), read on 2026-10-08. The repository is watched and re-audited when it changes.