Atlas / MCP servers / plateerlab / Synaptic Memory

Synaptic MemoryCAUTION

mcp/plateerlab/synaptic-memory

Knowledge graph + MCP tool server for LLM agents with hybrid retrieval, live DB sync, Korean FTS, and memory feedback.

Verdict
CAUTION
Grade
D
Trust score
61 /100
Exposed tools
43 29r · 11w · 3d
Transport
—
License
NOASSERTION
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Default path: zero API calls at index time. Zero infra. Zero lock-in. A knowledge graph + MCP tool server for LLM agents, with hybrid retrieval, CDC-based live database sync, and Korean FTS built in.

[](https://pypi.org/project/synaptic-memory/) [](https://pypi.org/project/synaptic-memory/) [](LICENSE)

한국어 README

5-minute start

pip install "synaptic-memory[sqlite,korean,vector]"
synaptic-quickstart --db quickstart.db

That command builds a tiny SQLite-backed graph and runs three searches — all without calling any LLM at indexing time. Omit --db for an in-memory, zero-dependency smoke test. Full source for the expanded example: examples/quickstart.py.

Why not just RAG?

Plain RAG usually answers from independent chunks. Synaptic builds a graph first, so an agent can search, follow relations, inspect structured rows, and remember which evidence helped.

It is not a vector database replacement. It is the graph and tool layer around your existing documents, SQL data, embedding endpoint, and agent runtime.

Build and search

import asyncio
from synaptic import SynapticGraph

async def main():
# Any data → knowledge graph (CSV, JSONL, directory)
graph = await SynapticGraph.from_data("./my_data/", preset="rag")
try:
result = await graph.search("my question")
print(result.nodes[0].
Read from source at commit a42a99ee2960OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add synaptic-memory --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx synaptic-memory
claude-desktop
{
  "mcpServers": {
    "synaptic-memory": {
      "command": "uvx",
      "args": [
        "synaptic-memory"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (43)

29 read · 11 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
agent_aggregate_nodesreadAggregate nodes by property — GROUP BY + COUNT/SUM/AVG.
agent_compare_searchreadCompare search — decompose multi-topic query and search in parallel.
agent_countreadCount how many nodes match a filter without fetching them.
agent_deep_searchreadDeep search — search + expand + read documents in ONE call.
agent_expandreadWalk one graph hop out from a specific node.
agent_explore_contextreadExplore the knowledge graph around a specific node, following semantic relationships.
agent_filter_nodesreadFilter nodes by property value — for structured/tabular data.
agent_find_similarreadSearch knowledge with agent-aware intent for smarter results.
agent_followreadWalk a specific edge type from a starting node.
agent_get_documentreadFetch a document with smart context control.
agent_get_reasoning_chainreadGet the full reasoning chain for a decision: decision → outcome → lessons learned.
agent_join_relatedreadFollow a foreign key to find related records.
agent_list_categoriesreadList all top-level categories in the knowledge graph.
agent_log_actionreadLog a tool call or action within an agent session.
agent_record_decisionreadRecord a decision made by the agent with rationale and considered alternatives.
agent_record_outcomereadRecord the outcome of a previous decision. Triggers Hebbian learning.
agent_searchreadMulti-turn search — finds evidence for a natural-language query.
agent_search_exactreadLiteral substring match for codes, IDs, or exact strings.
agent_session_inforeadInspect the current state of an agent session.
agent_start_sessionwriteStart an agent work session. All subsequent actions can be linked to this session.
agent_top_nodesreadReturn the top-N rows of ``table`` ordered by ``sort_by``.
knowledge_addwriteAdd a new knowledge node to the graph.
knowledge_add_chunkswriteIngest pre-chunked content (BYO-chunker workflow).
knowledge_add_documentwriteAdd a long document to the graph with automatic chunking.
knowledge_add_tablewriteIngest a structured table into the graph.
knowledge_askreadAnswer a question end-to-end with honest routing — cheap path first, agent only when needed.
knowledge_backfillreadRepair existing nodes that are missing embeddings or phrase hubs.
knowledge_consolidatewriteRun memory consolidation — expire old L0 nodes, promote accessed ones.
knowledge_exportreadExport the knowledge graph.
knowledge_ingest_pathreadIngest a file from the local filesystem into the *current* graph.
knowledge_linkwriteCreate a link between two knowledge nodes.
knowledge_merge_nodesdestructiveMerge ``drop_id`` into ``keep_id`` and delete ``drop_id``.
knowledge_reinforcereadReinforce knowledge nodes after use (Hebbian learning).
knowledge_removedestructiveDelete a single node and cascade-remove its edges.
knowledge_searchreadSearch the knowledge graph for lessons, decisions, patterns, and past outcomes.
knowledge_snapshotreadGenerate a markdown snapshot of the graph — for agent priming.
knowledge_statsreadGet knowledge graph statistics — node counts by kind and level, cache stats.
knowledge_sync_from_databasewriteIncrementally sync the graph with a live database (CDC).
knowledge_unlinkdestructiveDelete edges from ``source_id`` to ``target_id``.
knowledge_updatewriteUpdate fields of an existing knowledge node.
knowledge_update_edgewriteChange weight and/or kind of existing edge(s) between two nodes.
ontology_define_typewriteDefine or update a custom node/edge type in the ontology.
ontology_query_schemareadQuery the ontology schema. Returns type definitions including inherited properties.
04

Trust audit

CAUTIONgrade D · trust 61/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

MEDIUMInventory / provenance · inv.binary · CWE-1104
eval/data/gt_datasets.xlsx
gt_datasets.xlsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/synaptic/backends/__pycache__/__init__.cpython-312.pyc
__init__.cpython-312.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/synaptic/backends/__pycache__/memory.cpython-312.pyc
memory.cpython-312.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/synaptic/extensions/__pycache__/__init__.cpython-312.pyc
__init__.cpython-312.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
src/synaptic/extensions/__pycache__/classifier_rules.cpython-312.pyc
classifier_rules.cpython-312.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/synaptic/__init__.py:290
mod = importlib.import_module(_LAZY_V012[name])
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
eval/scripts/ingest_krra.py:96
help="Embedding API base URL (e.g. http://14.6.220.78:11434/v1)",
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
eval/scripts/kuzu_parity.py:213
print(f"✓ PARITY: |ΔMRR| = {abs(mrr_delta):.4f} < 0.05 — Kuzu matches Memory.")
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
CLAUDE.md:244
synaptic-mcp --db knowledge.db --source-dsn postgresql://user:pw@host/db
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_cdc_ids.py:120
a = deterministic_row_id("postgres://u:pw1@h/d", "products", "P001")
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_cdc_ids.py:121
b = deterministic_row_id("postgres://u:pw2@h/d", "products", "P001")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
knowledge_merge_nodes, knowledge_remove, knowledge_unlink
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
eval/run_all.py:1897
return hashlib.md5(f.read()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
eval/scripts/parse_krra.py:73
return hashlib.md5(path.encode()).hexdigest()[:16]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/synaptic/extensions/document_ingester.py:738
return hashlib.md5(text.encode("utf-8")).hexdigest()[:16]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/synaptic/extensions/entity_ids.py:32
h = hashlib.md5(f"{type_key}\x00{normalized}".encode()).hexdigest()[:16]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/synaptic/extensions/entity_ids.py:44
h = hashlib.md5(combined.encode()).hexdigest()[:16]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
eval/baselines/README.md:10
--embed-url http://14.6.220.78:11434/v1 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
eval/baselines/README.md:11
--reranker-url http://14.6.220.78:8180
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
eval/baselines/README.md:15
--embed-url http://14.6.220.78:11434/v1 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
examples/ablation/diagnostics/agent_loop_20260702_180201.md:8
- LLM base URL: http://127.0.0.1:18134/v1
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/benchmark/test_ablation.py:462
f"{'nDCG@K':>7} | {'P@K':>6} | {'R@K':>6} | {'Avg ms':>7} | {'ΔMRR':>7}"
INFOInventory / provenance · inv.oversize · CWE-1104
eval/data/finreg/raw.jsonl
eval/data/finreg/raw.jsonl
Why it matters. 6950732 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
tests/benchmark/data/autorag_retrieval.json
tests/benchmark/data/autorag_retrieval.json
Why it matters. 1409438 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
tests/benchmark/data/hotpotqa.json
tests/benchmark/data/hotpotqa.json
Why it matters. 1317589 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a42a99ee2960full audit observations/trust-audit/mcp-server/plateerlab__synaptic-memory.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a42a99ee2960CAUTIOND61first audit
06

Questions

What is the Synaptic Memory MCP server?

Knowledge graph + MCP tool server for LLM agents with hybrid retrieval, live DB sync, Korean FTS, and memory feedback.

What tools does Synaptic Memory expose?

43 in total: 29 read-only, 11 that write, and 3 that can delete or overwrite (knowledge_merge_nodes, knowledge_remove, knowledge_unlink). Every one is listed on this page with its risk.

Is Synaptic Memory safe to connect to an agent?

With care. The audit graded it D (61/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Synaptic Memory need?

It reads ANTHROPIC_API_KEY, DEEPSEEK_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (a42a99ee2960), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement