RemindbBLOCK
An agentic memory database that cuts session tokens by 82–99%. One portable SQLite file — your agent's memory, anywhere.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
remindb
Agentic memory in a single SQLite file.
Stop letting your agent re-read the same notes every session.
Why I built this
Coding agents already have memory. CLAUDE.md, AGENTS.md, your notes folder, that growing pile of project READMEs. Stuff persists just fine.
The problem is how the agent consumes it. Every session starts by re-reading the whole pile from scratch — every Read, every Grep, scanning raw prose the agent has already processed dozens of times. Big context windows don't fix it. A 1M-token window is still paid per call, and still can't tell yesterday's stale note from today's relevant one.
Raw markdown is the wrong shape for memory. Not because it can't hold the words — it can — but because it forces the agent to pay full freight on every read.
remindb is a single SQLite file your agent treats as long-term memory. It parses your notes (Markdown, HTML, JSON, YAML, TOON) into a structured tree, hashes every node, encodes repetitive structures compactly when it saves tokens, and surfaces the whole thing through a tight MCP tool suite.
What you g
ed8e6075fed3OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add remindb-opencode -- npx -y @radimsem/[email protected]
{
"mcpServers": {
"remindb-opencode": {
"command": "npx",
"args": [
"-y",
"@radimsem/[email protected]"
]
}
}
}Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
remindb | write | Mounts the remindb MCP server so OpenClaw agents can query and update a compiled view of their workspace. |
Trust audit
BLOCKgrade F · trust 46/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
return fmt.Errorf("refusing to bind HTTP transport to non-loopback %s without authentication: set REMINDB_AUTH_TOKEN to enable bearer-token auth, or pass --insecure-public (REMINDB_INSECURE_PUBLIC=1)s.logger.Warn("serve: HTTP bound to non-loopback with --insecure-public; no authentication", "listen", addr)"DATABASE_URL_TEST": "postgres://test:test@localhost:5433/webshop_test"
result_backend: postgresql://airflow:[email protected]/airflow
"dataURL": "data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hsaW5rIiB2aWV3Qm94PSIwIDAgMjQwNiAyNDA2IiB3aWR0aD0iMjQwNiIgaG
"dataURL": "data:image/svg+xml;base64,PHN2ZyBmaWxsPSIjNDI4NWY0IiByb2xlPSJpbWciIHZpZXdCb3g9IjAgMCAyNCAyNCIgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB3aWR0aD0iMjQiIGhlaWdodD0iMjQiPjx0aXRsZT5Hb29nbG
"dataURL": "data:image/svg+xml;base64,PHN2ZyBmaWxsPSIjN2MzYWVkIiByb2xlPSJpbWciIHZpZXdCb3g9IjAgMCAyNCAyNCIgeG1sbnM9Imh0dHA6Ly93d3cudzMub3JnLzIwMDAvc3ZnIiB3aWR0aD0iMjQiIGhlaWdodD0iMjQiPjx0aXRsZT5PYnNpZG
"dataURL": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAgAAAAIACAYAAAD0eNT6AAEv9ElEQVR4Ae3AA6AkWZbG8f937o3IzKdyS2Oubdu2bdu2bdu2bWmMnpZKr54yMyLu+Xa3anqmhztr1S+46qqrrrrqqqv+vyG46qqrrrrqqqv+vyG46qqrrr
"dataURL": "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAoAAAAKACAYAAAAMzckjAACxfklEQVR4Ae3AA6AkWZbG8f937o3IzKdyS2Oubdu2bdu2bdu2bWmMnpZKr54yMyLu+Xa3anqmhztr1a9y1VX/S/mz36F/8rK8AfgtwO/BZXo68ETJf5uKu4
"akia0123456789abcdef", // lowercase near-miss
{"aws_lowercase", "akia0123456789abcdef"},"postgres://alice:[email protected]:5432/app",
input: "DSN postgres://alice:[email protected]:5432/app end",
const secret = "TOP-SECRET-NODE-BODY-9f3c"
const secret = "TOP-SECRET-NODE-BODY-r3s0urce"
const secret = "TOP-SECRET-NODE-BODY"
"ghp_aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"-----BEGIN RSA PRIVATE KEY-----\ndata\n-----END RSA PRIVATE KEY-----",
"-----BEGIN RSA PRIVATE KEY-----\nhalf", // half-formed PEM
-----BEGIN RSA PRIVATE KEY-----
{"pem_half_block", "-----BEGIN RSA PRIVATE KEY-----\ndata\n"},"-----BEGIN RSA PRIVATE KEY-----\ndata\n-----END RSA PRIVATE KEY-----",
"xoxb-abcdefghij1234567890",
input: "tok xoxb-abcdefghij1234567890 end",
"xoxb-abcdefghij1234567890",
Gates applied: no_behavioural_pass.
ed8e6075fed3full audit observations/trust-audit/mcp-server/radimsem__remindb.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ed8e6075fed3 | BLOCK | F | 46 | first audit |
Questions
What is the Remindb MCP server?
An agentic memory database that cuts session tokens by 82–99%. One portable SQLite file — your agent's memory, anywhere.
What tools does Remindb expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Remindb safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (46/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Remindb need?
No credential environment variables were found in its source, so it appears to need none.
How does Remindb run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @radimsem/remindb-opencode at 0.3.12.
How current is this page?
The grade is for one exact copy of the source (ed8e6075fed3), read on 2026-10-07. The repository is watched and re-audited when it changes.