Atlas / MCP servers / pi22by7 / In Memoria

In MemoriaSAFE

mcp/pi22by7/in-memoria

Persistent Intelligence Infrastructure for AI Agents

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 10r · 2w · 0d
Transport
stdio
License
MIT
Stars
174
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/in-memoria) [](https://www.npmjs.com/package/in-memoria) [](https://opensource.org/licenses/MIT) [](https://discord.gg/6mGsM4qkYm)

Giving AI coding assistants a memory that actually persists.

Quick Demo

[](https://asciinema.org/a/ZyD2bAZs1cURnqoFc3VHXemJx)

Watch In Memoria in action: learning a codebase, providing instant context, and routing features to files.

The Problem: Session Amnesia

You know the drill. You fire up Claude, Copilot, or Cursor to help with your codebase. You explain your architecture. You describe your patterns. You outline your conventions. The AI gets it, helps you out, and everything's great.

Then you close the window.

Next session? Complete amnesia. You're explaining the same architectural decisions again. The same naming conventions. The same "no, we don't use classes here, we use functional composition" for the fifteenth time.

Every AI coding session starts from scratch.

This isn't just annoying, it's inefficient. These tools re-analyze your codebase on every interaction, burning tokens and time. They give generic suggestions that don't match your style. They have no memory of what worked last time, what you rejected, or why.

The Solution: Persistent Intelligence

In Memoria is an MCP server that learns from your actual codebase and remembers across sessions. It builds persistent intelligence about your code (patterns, architecture, conventions, decisions) that AI assistants can query through the Model Context Protocol.

Think of it as giving your AI pair programmer a notepad that doesn't get

Read from source at commit 0aa2a05f98ccOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add in-memoria --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
03

Exposed tools (12)

10 read · 2 write · 0 destructive.

ToolRiskDescription
analyze_codebasereadOne-time analysis of a specific file or directory. Returns AST structure, complexity metrics, and detected patterns for that path only. For project-wide understanding, use get_project_blueprint instead (faster, uses learned intelligence). Use this for deep-dive analysis of a specific file you\
auto_learn_if_neededreadAutomatically learn from codebase if intelligence data is missing or stale. Call this first before using other In-Memoria tools - it\
get_developer_profilereadGet patterns and conventions learned from this codebase\
get_intelligence_metricsreadGet detailed metrics about the intelligence database and learning state
get_pattern_recommendationsreadGet coding pattern recommendations learned from this codebase. Use this when implementing new features to follow existing patterns (e.g.,
get_performance_statusreadGet performance metrics including database size, query times, and resource usage
get_project_blueprintwriteGet instant project blueprint - eliminates cold start exploration by providing tech stack, entry points, key directories, and architecture overview
get_semantic_insightsreadSearch for code-level symbols (variables, functions, classes) by name and see their relationships, usage patterns, and evolution. Use this to find where a specific function/class is defined, how it\
get_system_statusreadGet comprehensive system status including intelligence data, performance metrics, and health indicators
health_checkreadVerify In-Memoria setup and configuration for a project. Checks database accessibility, project structure, and API keys.
predict_coding_approachwriteFind which files to modify for a task using intelligent file routing. Use this when the user asks
search_codebasereadSearch for code by text matching or patterns. Use
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
none-observed
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/test-vector-db.js:10
console.log(`OpenAI API Key: ${apiKey ? '✅ Available' : '❌ Not set'}`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/automation-tools.ts:2
import { SemanticEngine } from '../../engines/semantic-engine.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/automation-tools.ts:3
import { PatternEngine } from '../../engines/pattern-engine.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/automation-tools.ts:4
import { SQLiteDatabase } from '../../storage/sqlite-db.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/automation-tools.ts:5
import { ProgressTracker } from '../../utils/progress-tracker.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp-server/tools/automation-tools.ts:6
import { ConsoleProgressRenderer } from '../../utils/console-progress.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @surrealdb/node, @xenova/transformers, better-sqlite3, chokidar, eventemitter3, glob, nanoid
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
rust-core/package.json
@napi-rs/cli
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 0aa2a05f98ccfull audit observations/trust-audit/mcp-server/pi22by7__in-memoria.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-060aa2a05f98ccSAFEB89first audit
06

Questions

What is the In Memoria MCP server?

Persistent Intelligence Infrastructure for AI Agents

What tools does In Memoria expose?

12 in total: 10 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is In Memoria safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does In Memoria need?

It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does In Memoria run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as in-memoria-core at 0.6.0.

How current is this page?

The grade is for one exact copy of the source (0aa2a05f98cc), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement