YourMemoryBLOCK
Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
YourMemory
Your AI has the memory of a goldfish. Not anymore.
Persistent, self-improving memory for AI agents — built on the science of how humans remember.
[](https://pypi.org/project/yourmemory/) [](https://pypi.org/project/yourmemory/) [](https://pypi.org/project/yourmemory/) [](https://creativecommons.org/licenses/by-nc/4.0/) [](https://github.com/sachitrafa/YourMemory)
[](BENCHMARKS.md) [](BENCHMARKS.md) [](BENCHMARKS.md) [](https://modelcontextprotocol.io)
[▶ Try the live interactive demo](https://sachitrafa.github.io/YourMemory/marketing/interactive.html) · [Website](https://yourmemoryai.xyz) · Benchmarks
The problem
Every morning your AI agent treats you like a stranger. Same context re-explained. Same preferences forgotten. Every session starts from zero.
Most "memory" tools bolt a vector database onto an agent and call it done — but that's just storage. It hoards every near-duplicate until retrieval drowns in noise. A goldfish with a bigger bowl.
YourMemory is different: memory that works like a brain, not a database.
e891ac2a767dOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add yourmemory -- None yourmemory==1.4.25
Trust audit
BLOCKgrade D · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (24)
return pickle.load(f)
G = pickle.load(open(graph_path, "rb"))
const fn = new Function(
new Function("React", "module", "exports", "require", code)(const fn = new Function(
# Docker: postgresql://postgres:postgres@localhost:5432/yourmemory
DATABASE_URL: postgresql://postgres:postgres@db:5432/yourmemory
DATABASE_URL=postgresql://postgres:postgres@localhost:5432/yourmemory
print(f" Dashboard → http://127.0.0.1:{port}/ui", file=sys.stderr)SERVER_URL = f"http://127.0.0.1:{DASHBOARD_PORT}"- ZEP_STORE_POSTGRES_DSN=postgres://zep:zep@zep-db:5432/zep
print(f"\n── Retrieval eval ({len(cases)} cases) ──")print(f"\n── Session eval ({sum(len(c['turns']) for c in session_cases)} turns) ──")key = hashlib.md5(text.encode()).hexdigest()
LOCOMO_PATH = os.path.join(os.path.dirname(__file__), "../../locomo/data/locomo10.json")
header = f" {'Question Type':<36} {'Base':>{col}} {'+ Boost':>{col}} {'Δpp':>6}"@cloudflare/workers-types, typescript, wrangler
fastapi, uvicorn, psycopg2-binary, pgvector, python-dotenv, httpx, apscheduler, spacy
| Agent/programmatic access | Valid `ym_` API key, validated on every call |
e.g. unauthorized memory access, leaked API key or secret, cross-user data exposure,
**Get your token:** visit **[yourmemoryai.xyz](https://yourmemoryai.xyz/)** → enter your email → verify with a 6-digit code → copy your token.
demo.gif
demo_gifs/temporal_boost.gif
Gates applied: no_behavioural_pass.
e891ac2a767dfull audit observations/trust-audit/mcp-server/sachitrafa__yourmemory-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | e891ac2a767d | BLOCK | D | 60 | first audit |
Questions
What is the YourMemory MCP server?
Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.
Is YourMemory safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (60/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does YourMemory need?
It reads ANTHROPIC_API_KEY, MEM0_API_KEY, NEO4J_PASSWORD, SUPERMEMORY_API_KEY, YOURMEMORY_AUTH and ZEP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does YourMemory run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as yourmemory-backend at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (e891ac2a767d), read on 2026-10-06. The repository is watched and re-audited when it changes.