In MemoriaSAFE
Persistent Intelligence Infrastructure for AI Agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/in-memoria) [](https://www.npmjs.com/package/in-memoria) [](https://opensource.org/licenses/MIT) [](https://discord.gg/6mGsM4qkYm)
Giving AI coding assistants a memory that actually persists.
Quick Demo
[](https://asciinema.org/a/ZyD2bAZs1cURnqoFc3VHXemJx)
Watch In Memoria in action: learning a codebase, providing instant context, and routing features to files.
The Problem: Session Amnesia
You know the drill. You fire up Claude, Copilot, or Cursor to help with your codebase. You explain your architecture. You describe your patterns. You outline your conventions. The AI gets it, helps you out, and everything's great.
Then you close the window.
Next session? Complete amnesia. You're explaining the same architectural decisions again. The same naming conventions. The same "no, we don't use classes here, we use functional composition" for the fifteenth time.
Every AI coding session starts from scratch.
This isn't just annoying, it's inefficient. These tools re-analyze your codebase on every interaction, burning tokens and time. They give generic suggestions that don't match your style. They have no memory of what worked last time, what you rejected, or why.
The Solution: Persistent Intelligence
In Memoria is an MCP server that learns from your actual codebase and remembers across sessions. It builds persistent intelligence about your code (patterns, architecture, conventions, decisions) that AI assistants can query through the Model Context Protocol.
Think of it as giving your AI pair programmer a notepad that doesn't get
0aa2a05f98ccOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add in-memoria --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]Exposed tools (12)
10 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
analyze_codebase | read | One-time analysis of a specific file or directory. Returns AST structure, complexity metrics, and detected patterns for that path only. For project-wide understanding, use get_project_blueprint instead (faster, uses learned intelligence). Use this for deep-dive analysis of a specific file you\ |
auto_learn_if_needed | read | Automatically learn from codebase if intelligence data is missing or stale. Call this first before using other In-Memoria tools - it\ |
get_developer_profile | read | Get patterns and conventions learned from this codebase\ |
get_intelligence_metrics | read | Get detailed metrics about the intelligence database and learning state |
get_pattern_recommendations | read | Get coding pattern recommendations learned from this codebase. Use this when implementing new features to follow existing patterns (e.g., |
get_performance_status | read | Get performance metrics including database size, query times, and resource usage |
get_project_blueprint | write | Get instant project blueprint - eliminates cold start exploration by providing tech stack, entry points, key directories, and architecture overview |
get_semantic_insights | read | Search for code-level symbols (variables, functions, classes) by name and see their relationships, usage patterns, and evolution. Use this to find where a specific function/class is defined, how it\ |
get_system_status | read | Get comprehensive system status including intelligence data, performance metrics, and health indicators |
health_check | read | Verify In-Memoria setup and configuration for a project. Checks database accessibility, project structure, and API keys. |
predict_coding_approach | write | Find which files to modify for a task using intelligent file routing. Use this when the user asks |
search_codebase | read | Search for code by text matching or patterns. Use |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- none-observed
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
console.log(`OpenAI API Key: ${apiKey ? '✅ Available' : '❌ Not set'}`);import { SemanticEngine } from '../../engines/semantic-engine.js';import { PatternEngine } from '../../engines/pattern-engine.js';import { SQLiteDatabase } from '../../storage/sqlite-db.js';import { ProgressTracker } from '../../utils/progress-tracker.js';import { ConsoleProgressRenderer } from '../../utils/console-progress.js';@modelcontextprotocol/sdk, @surrealdb/node, @xenova/transformers, better-sqlite3, chokidar, eventemitter3, glob, nanoid
@napi-rs/cli
Gates applied: no_behavioural_pass.
0aa2a05f98ccfull audit observations/trust-audit/mcp-server/pi22by7__in-memoria.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 0aa2a05f98cc | SAFE | B | 89 | first audit |
Questions
What is the In Memoria MCP server?
Persistent Intelligence Infrastructure for AI Agents
What tools does In Memoria expose?
12 in total: 10 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is In Memoria safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does In Memoria need?
It reads OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does In Memoria run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as in-memoria-core at 0.6.0.
How current is this page?
The grade is for one exact copy of the source (0aa2a05f98cc), read on 2026-10-06. The repository is watched and re-audited when it changes.