Atlas / MCP servers / sandst1 / Remind

RemindCAUTION

mcp/sandst1/remind

A memory layer for AI Agents

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
20 15r · 3w · 2d
Transport
—
License
Apache-2.0
Stars
84
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/remind-mcp/) [](https://www.python.org/downloads/) [](LICENSE)

Agent-driven memory layer for LLMs. Remind is a deterministic memory substrate with temporal facts, semantic retrieval, and structured curation — the calling agent is the only intelligence.

[Documentation](https://sandst1.github.io/remind/) · [Examples](https://sandst1.github.io/remind/examples/) · [Changelog](https://sandst1.github.io/remind/reference/changelog)

Quick start

pip install remind-mcp

No configuration required — Remind uses local embeddings by default (fastembed, no API key).

remind remember "This project uses React with TypeScript"
remind remember "Chose PostgreSQL for the database" -t decision
remind remember "Cache TTL is 600 seconds" -t fact -e concept:caching
remind recall "What tech stack are we using?"

How it works

Remind stores episodes (raw experiences) and concepts (generalized knowledge). You capture and curate memories explicitly using CLI commands or MCP tools.

For facts (-t fact), Remind automatically:

  1. Creates a Fact row with validity tracking
  2. Assigns it to a cluster based on entity overlap (Jaccard similarity)
  3. Detects potential collisions with existing facts — same-cluster collisions and cross-cluster related facts are returned with ready-to-paste apply commands

For any remember call, the output also surfaces the top-5 nearest episodes and concepts semantically, so you can catch contradictions before they go unnoticed.

For patterns and concepts, you use remind apply to create them from episodes:

remind apply << 'EOF'
concept from=ep:11,ep:12 title="Retry-with-backoff for resilience" "Exponential 
Read from source at commit e2996848dbd7OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add remind-docs --env AZURE_OPENAI_API_KEY=${AZURE_OPENAI_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env REMIND_HYBRID_KEYWORD_WEIGHT=${REMIND_HYBRID_KEYWORD_WEIGHT} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "remind-docs": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AZURE_OPENAI_API_KEY": "${AZURE_OPENAI_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "REMIND_HYBRID_KEYWORD_WEIGHT": "${REMIND_HYBRID_KEYWORD_WEIGHT}"
      }
    }
  }
}
03

Exposed tools (20)

15 read · 3 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
applywriteApply a batch changeset to memory.
delete_conceptdestructiveSoft delete a concept from memory.
delete_episodedestructiveSoft delete an episode from memory.
dismiss_conflictreadDismiss a conflict: both claims are valid (e.g. different contexts).
entitiesreadList entities (files, functions, people, etc.) in memory.
episode_typesreadList configured episode types.
eventsreadRead the append-only change feed of writes.
inspectreadInspect concepts or episodes in memory.
inspect_entityreadInspect an entity and its relationships.
list_conflictsreadList detected memory conflicts (contradictions) awaiting triage.
list_deletedreadList soft-deleted episodes and concepts.
recallreadRetrieve relevant memories for a query.
rememberreadStore an experience or observation in memory (fast, no LLM calls).
resolve_conflictreadResolve a conflict by declaring which fact is correct.
restore_conceptreadRestore a previously deleted concept.
restore_episodereadRestore a previously deleted episode.
snapshotreadRead a snapshot of memory state as JSON.
statsreadGet memory statistics.
update_conceptwriteUpdate an existing concept.
update_episodewriteUpdate an existing episode in memory.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMInventory / provenance · inv.binary · CWE-1104
memory.db
memory.db
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_concept, delete_episode
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/remind/background.py:30
return hashlib.md5(db_url.encode()).hexdigest()[:12]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/remind/background.py:35
return hashlib.md5(raw.encode()).hexdigest()[:16]
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:161
"url": "http://127.0.0.1:8765/sse?db=my-project"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:169
Web UI at `http://127.0.0.1:8765/ui/`, REST API at `/api/v1/`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
website/guide/mcp.md:36
"url": "http://127.0.0.1:8765/sse?db=my-project"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
web/package.json
d3, lucide-svelte, @sveltejs/vite-plugin-svelte, @tsconfig/svelte, svelte, svelte-check, typescript, vite
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
website/package.json
vitepress
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
.remind/remind.db
.remind/remind.db
Why it matters. 3592192 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/architecture.png
docs/architecture.png
Why it matters. 6249288 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/architecture_original.png
docs/architecture_original.png
Why it matters. 5826556 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
website/public/architecture.png
website/public/architecture.png
Why it matters. 6249288 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha e2996848dbd7full audit observations/trust-audit/mcp-server/sandst1__remind.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07e2996848dbd7CAUTIONB89first audit
06

Questions

What is the Remind MCP server?

A memory layer for AI Agents

What tools does Remind expose?

20 in total: 15 read-only, 3 that write, and 2 that can delete or overwrite (delete_concept, delete_episode). Every one is listed on this page with its risk.

Is Remind safe to connect to an agent?

With care. The audit graded it B (89/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Remind need?

It reads AZURE_OPENAI_API_KEY, OPENAI_API_KEY and REMIND_HYBRID_KEYWORD_WEIGHT from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (e2996848dbd7), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement