Atlas / MCP servers / omermaksutii / Mnemo

MnemoCAUTION

mcp/omermaksutii/mnemo-8

Persistent memory for Claude Code. Your AI never starts from scratch again.

Verdict
CAUTION
Grade
C
Trust score
75 /100
Exposed tools
15 12r · 2w · 1d
Transport
stdio
License
MIT
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Persistent memory for Claude Code. Your AI never starts from scratch again.

[](https://github.com/omermaksutii/mnemo/actions) [](https://www.npmjs.com/package/@mnemo-mcp/cli) [](https://www.npmjs.com/package/@mnemo-mcp/server) [](https://www.npmjs.com/package/@mnemo-mcp/core) [](LICENSE)

Mnemo gives Claude Code a brain that survives across sessions. It captures decisions, conventions, and preferences — and recalls them by meaning, on demand, with sub-100ms semantic search.

Install

# install the CLI
npm install -g @mnemo-mcp/cli

# install Mnemo into Claude Code (skill + MCP server)
mnemo init

# (optional) also wire auto-capture hooks
mnemo init --with-hooks

# verify
mnemo doctor

After mnemo init, restart Claude Code. The /mnemo skill and the mnemo_* MCP tools are now available — Claude will use them automatically when relevant.

Use it from the terminal too

mnemo remember "our API auth uses OAuth2 with refresh tokens every 30min"
mnemo remember --global "I prefer pnpm over npm"
mnemo recall "what's our auth pattern?"
mnemo recall "auth" --explain          # show the ranking breakdown per hit
mnemo list
mnemo stats
mnemo forget 
mnemo backup                            # timestamped snapshot
mnemo restore mnemo-backups/.json
mnemo migrate                           # rebuild the index after an embedder change
mnemo serve                             # localhost web dashboard
mnemo watch docs/                       # auto-capture matching files as they chan
Read from source at commit c49d6265c2f7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add sync-server --env MNEMO_ENCRYPTION_KEY=${MNEMO_ENCRYPTION_KEY} --env MNEMO_SYNC_TOKEN=${MNEMO_SYNC_TOKEN} -- npx -y @mnemo-mcp/[email protected]
claude-desktop
{
  "mcpServers": {
    "sync-server": {
      "command": "npx",
      "args": [
        "-y",
        "@mnemo-mcp/[email protected]"
      ],
      "env": {
        "MNEMO_ENCRYPTION_KEY": "${MNEMO_ENCRYPTION_KEY}",
        "MNEMO_SYNC_TOKEN": "${MNEMO_SYNC_TOKEN}"
      }
    }
  }
}
03

Exposed tools (15)

12 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AuthServicereadhandles login
areadd
add-endpointwriteAdd a new REST API endpoint
breadd
mnemo_entity_contextreadEverything known about an entity (a named service/module/concept): its memories and directly-related entities
mnemo_forgetdestructiveDelete a memory by id (full or 8-char prefix)
mnemo_listreadList recent memories
mnemo_procedure_runwriteRetrieve a named procedure as a checklist (use before executing the workflow)
mnemo_procedure_suggestreadFind a procedural workflow that matches a task description, if one exists
mnemo_recallreadSemantic recall of stored memories
mnemo_rememberreadCapture a memory
mnemo_statsreadShow memory engine stats
mnemo_what_depends_onreadGraph traversal: which entities transitively require or use the named entity
preadd
p1readd
04

Trust audit

CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (16)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/cli/src/commands/ingest.ts:63
if (skipped.length) console.log(chalk.yellow(`  skipped ${skipped.length} (secret content)`));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/sync-server/src/index.ts:21
console.log(`  auth:  ${token ? 'bearer token required' : 'OPEN (no token — dev only)'}`);
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/core/tests/v1.1-features.test.ts:61
expect(hasSecrets('here is my token ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj')).toBe(true);
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/core/tests/v1.1-features.test.ts:68
const matches = detectSecrets('ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj');
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/core/tests/v1.1-features.test.ts:76
m.capture({ content: 'secret: ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj', scope: 'global' }),
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
packages/core/tests/v1.1-features.test.ts:84
content: 'this contains ghp_AbCdEfGhIjKlMnOpQrStUvWxYzAbCdEfGhIj',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
mnemo_forget
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
packages/core/tests/crypto.test.ts
crypto.test.ts
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/cli/tests/sync.test.ts:24
process.env.MNEMO_SYNC_URL = `http://127.0.0.1:${h.port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/sync-server/tests/server.test.ts:15
base = `http://127.0.0.1:${h.port}`;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, typescript, vitest, tsx
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
commander, chalk
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/core/package.json
@huggingface/transformers, hnswlib-node, sql.js, @types/sql.js
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/mcp/package.json
@modelcontextprotocol/sdk, zod
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:8
- **`@mnemo-mcp/sync-server`** — a new, self-hostable, dependency-light blob backend (`mnemo-sync-server`). Stores one opaque ciphertext blob per namespace; bearer-token auth; `/v1/health` + `/v1/blob
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
demo.gif
demo.gif
Why it matters. 2034560 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c49d6265c2f7full audit observations/trust-audit/mcp-server/omermaksutii__mnemo-8.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c49d6265c2f7CAUTIONC75first audit
06

Questions

What is the Mnemo MCP server?

Persistent memory for Claude Code. Your AI never starts from scratch again.

What tools does Mnemo expose?

15 in total: 12 read-only, 2 that write, and 1 that can delete or overwrite (mnemo_forget). Every one is listed on this page with its risk.

Is Mnemo safe to connect to an agent?

With care. The audit graded it C (75/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mnemo need?

It reads MNEMO_ENCRYPTION_KEY and MNEMO_SYNC_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mnemo run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mnemo-mcp/sync-server at 2.6.0.

How current is this page?

The grade is for one exact copy of the source (c49d6265c2f7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement