Persistent AI MemoryBLOCK
A persistent local memory for AI, LLMs, or Copilot in VS Code.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://github.com/savantskie/persistent-ai-memory)
🌟 Community Call to Action: Have you made improvements or additions to this system? Submit a pull request! Every contributor will be properly credited in the final product.
GITHUB LINK - https://github.com/savantskie/persistent-ai-memory.git
What's New in v2.0.0 (September 20, 2026)
Full Feature Parity Release -- PAM is now fully in sync with the internal production system. Every feature from months of real-world use is now public.
- Core Identity System -- Distills a complete profile of who the user is
across all conversations. Pulls from curated memories, the OpenWebUI memory table, and archived databases. Updates incrementally rather than starting from scratch each time.
- Automated Memory Maintenance -- Background tasks reformat old memories,
detect contradictions and updates, and link orphaned memories to their source conversations. Includes a backlog processor that deduplicates entries, fills in missing metadata, and re-ranks memory importance using the LLM.
- Task Coordinator -- Centralized scheduler replaces ad-hoc sleep loops.
Proper concurrency control with per-database locking and LLM call gating. Detects user activity and waits until idle to run heavy work.
- Vision Support -- Precomputes image embeddings via a separate vision
server so the main LLM does not need mmproj loaded. Caches embeddings for cross-turn injection. Works with llama.cpp, LM Studio, and any OpenAI-compatible embedding provider.
- Cross-System Deduplication -- When promoting short-term memories to
long-term storage, checks for exact and semantic duplica
9b1092369159OBSERVED · 2026-10-06Exposed tools (38)
28 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
cancel_appointment | read | Cancel a scheduled appointment |
complete_appointment | read | Mark an appointment as completed |
complete_reminder | read | Mark a reminder as completed |
create_appointment | write | Create an appointment, optionally recurring (e.g., weekly mental health appointments) |
create_memory | write | Create a curated memory entry |
create_reminder | write | Create a reminder or multiple recurring reminders |
delete_reminder | destructive | Permanently delete a reminder |
export_all_tool_calls | read | Export all tool calls from current and archived databases for LORA training dataset generation (web-only, not for models) |
get_active_reminders | read | Get active (not completed) reminders |
get_ai_insights | read | Get recent AI self-reflection insights and patterns |
get_appointments | read | Get recent appointments, optionally filtered by date range |
get_character_context | read | Get relevant context about characters from memory |
get_completed_reminders | read | Get recently completed reminders |
get_conversation_context | read | Retrieve conversation context linked to a memory in three modes: snippet (4 msgs before/after), summary (count, date range, first/last msgs), or full (all messages) |
get_current_time | read | Get the current server time in ISO format (UTC and local) |
get_project_continuity | read | Get context to continue development work |
get_recent_context | read | Get recent conversation context from the last N days |
get_reminders | read | Get recent reminders, optionally filtered by date range |
get_system_health | read | Get comprehensive system health, statistics, and database status |
get_tool_information | read | Get tool usage statistics OR tool documentation. Pass mode= |
get_upcoming_appointments | read | Get upcoming appointments (not cancelled) |
get_weather_open_meteo | read | Open-Meteo forecast (no API key). Defaults to configured location and caches once per local day. |
link_code_context | read | Link conversation to specific code context |
list_available_memory_banks | read | Get list of available memory banks with memory counts per bank |
list_available_tags | read | Get list of available tags from registry with their canonical forms, variations, and usage counts |
reflect_on_tool_usage | read | AI self-reflection on tool usage patterns and effectiveness |
reschedule_reminder | write | Update the due date of a reminder |
save_development_session | write | Save VS Code development session context |
search_memories | read | Search memories using semantic similarity with importance and type filtering, or direct ID lookup. Searches across long-term curated memories, short-term memories, conversations, and schedule. Either |
search_project_history | read | Search VS Code project development history |
search_roleplay_history | read | Search past roleplay interactions and character development |
store_ai_reflection | write | Store an AI self-reflection/insight record (manual write) |
store_conversation | read | Store conversation automatically |
store_project_insight | read | Store development insight or decision |
store_roleplay_memory | read | Store important roleplay moments or character developments |
trigger_database_maintenance | write | Manually trigger database maintenance (archival, repairs, optimization) outside of the regular 6-hour schedule |
update_memory | write | Update an existing curated memory |
write_ai_insights | write | Alias of store_ai_reflection — write an AI self-reflection/insight record |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (21)
embedding = pickle.loads(row[0])
Open-Meteo forecast (no API key). Defaults to configured location and caches once per local day.
delete_reminder
__import__(module_name)
content_hash = hashlib.md5(f"{content}:{role}:{session_id}".encode()).hexdigest()content_hash = hashlib.md5(msg_content.encode()).hexdigest()
content_hash = hashlib.md5(msg_content.encode()).hexdigest()
content_hash = hashlib.md5(msg_content.encode()).hexdigest()
content_hash = hashlib.md5(msg_content.encode()).hexdigest()
"api_url": "http://127.0.0.1:11434",
"api_url": "http://127.0.0.1:11434",
"embedding_api_endpoint_url": "http://127.0.0.1:11434"
"embedding_api_endpoint_url": "http://127.0.0.1:11434"
"api_url": "http://127.0.0.1:11434",
# Or: Full permissions (less secure)
# Make permanent (add to ~/.bashrc or ~/.zshrc)
curl https://ollama.ai/install.sh | sh
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash
Gates applied: no_behavioural_pass.
9b1092369159full audit observations/trust-audit/mcp-server/savantskie__persistent-ai-memory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 9b1092369159 | BLOCK | D | 69 | first audit |
Questions
What is the Persistent AI Memory MCP server?
A persistent local memory for AI, LLMs, or Copilot in VS Code.
What tools does Persistent AI Memory expose?
38 in total: 28 read-only, 9 that write, and 1 that can delete or overwrite (delete_reminder). Every one is listed on this page with its risk.
Is Persistent AI Memory safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Persistent AI Memory need?
No credential environment variables were found in its source, so it appears to need none.
How does Persistent AI Memory run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (9b1092369159), read on 2026-10-06. The repository is watched and re-audited when it changes.