Atlas / MCP servers / savantskie / Persistent AI Memory

Persistent AI MemoryBLOCK

mcp/savantskie/persistent-ai-memory

A persistent local memory for AI, LLMs, or Copilot in VS Code.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
38 28r · 9w · 1d
Transport
stdio
License
MIT
Stars
236
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://github.com/savantskie/persistent-ai-memory)

🌟 Community Call to Action: Have you made improvements or additions to this system? Submit a pull request! Every contributor will be properly credited in the final product.

GITHUB LINK - https://github.com/savantskie/persistent-ai-memory.git

What's New in v2.0.0 (September 20, 2026)

Full Feature Parity Release -- PAM is now fully in sync with the internal production system. Every feature from months of real-world use is now public.

  • Core Identity System -- Distills a complete profile of who the user is

across all conversations. Pulls from curated memories, the OpenWebUI memory table, and archived databases. Updates incrementally rather than starting from scratch each time.

  • Automated Memory Maintenance -- Background tasks reformat old memories,

detect contradictions and updates, and link orphaned memories to their source conversations. Includes a backlog processor that deduplicates entries, fills in missing metadata, and re-ranks memory importance using the LLM.

  • Task Coordinator -- Centralized scheduler replaces ad-hoc sleep loops.

Proper concurrency control with per-database locking and LLM call gating. Detects user activity and waits until idle to run heavy work.

  • Vision Support -- Precomputes image embeddings via a separate vision

server so the main LLM does not need mmproj loaded. Caches embeddings for cross-turn injection. Works with llama.cpp, LM Studio, and any OpenAI-compatible embedding provider.

  • Cross-System Deduplication -- When promoting short-term memories to

long-term storage, checks for exact and semantic duplica

Read from source at commit 9b1092369159OBSERVED · 2026-10-06
02

Exposed tools (38)

28 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
cancel_appointmentreadCancel a scheduled appointment
complete_appointmentreadMark an appointment as completed
complete_reminderreadMark a reminder as completed
create_appointmentwriteCreate an appointment, optionally recurring (e.g., weekly mental health appointments)
create_memorywriteCreate a curated memory entry
create_reminderwriteCreate a reminder or multiple recurring reminders
delete_reminderdestructivePermanently delete a reminder
export_all_tool_callsreadExport all tool calls from current and archived databases for LORA training dataset generation (web-only, not for models)
get_active_remindersreadGet active (not completed) reminders
get_ai_insightsreadGet recent AI self-reflection insights and patterns
get_appointmentsreadGet recent appointments, optionally filtered by date range
get_character_contextreadGet relevant context about characters from memory
get_completed_remindersreadGet recently completed reminders
get_conversation_contextreadRetrieve conversation context linked to a memory in three modes: snippet (4 msgs before/after), summary (count, date range, first/last msgs), or full (all messages)
get_current_timereadGet the current server time in ISO format (UTC and local)
get_project_continuityreadGet context to continue development work
get_recent_contextreadGet recent conversation context from the last N days
get_remindersreadGet recent reminders, optionally filtered by date range
get_system_healthreadGet comprehensive system health, statistics, and database status
get_tool_informationreadGet tool usage statistics OR tool documentation. Pass mode=
get_upcoming_appointmentsreadGet upcoming appointments (not cancelled)
get_weather_open_meteoreadOpen-Meteo forecast (no API key). Defaults to configured location and caches once per local day.
link_code_contextreadLink conversation to specific code context
list_available_memory_banksreadGet list of available memory banks with memory counts per bank
list_available_tagsreadGet list of available tags from registry with their canonical forms, variations, and usage counts
reflect_on_tool_usagereadAI self-reflection on tool usage patterns and effectiveness
reschedule_reminderwriteUpdate the due date of a reminder
save_development_sessionwriteSave VS Code development session context
search_memoriesreadSearch memories using semantic similarity with importance and type filtering, or direct ID lookup. Searches across long-term curated memories, short-term memories, conversations, and schedule. Either
search_project_historyreadSearch VS Code project development history
search_roleplay_historyreadSearch past roleplay interactions and character development
store_ai_reflectionwriteStore an AI self-reflection/insight record (manual write)
store_conversationreadStore conversation automatically
store_project_insightreadStore development insight or decision
store_roleplay_memoryreadStore important roleplay moments or character developments
trigger_database_maintenancewriteManually trigger database maintenance (archival, repairs, optimization) outside of the regular 6-hour schedule
update_memorywriteUpdate an existing curated memory
write_ai_insightswriteAlias of store_ai_reflection — write an AI self-reflection/insight record
03

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (21)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
ai_memory_short_term.py:692
embedding = pickle.loads(row[0])
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
<tool:get_weather_open_meteo>:1
Open-Meteo forecast (no API key). Defaults to configured location and caches once per local day.
Why it matters. asks the agent to read credentials
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_reminder
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_health_check.py:71
__import__(module_name)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
ai_memory_core.py:377
content_hash = hashlib.md5(f"{content}:{role}:{session_id}".encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
ai_memory_core.py:2357
content_hash = hashlib.md5(msg_content.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
ai_memory_core.py:2419
content_hash = hashlib.md5(msg_content.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
ai_memory_core.py:2472
content_hash = hashlib.md5(msg_content.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
ai_memory_core.py:2536
content_hash = hashlib.md5(msg_content.encode()).hexdigest()
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:214
"api_url": "http://127.0.0.1:11434",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:233
"api_url": "http://127.0.0.1:11434",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:270
"embedding_api_endpoint_url": "http://127.0.0.1:11434"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:285
"embedding_api_endpoint_url": "http://127.0.0.1:11434"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CONFIGURATION.md:395
"api_url": "http://127.0.0.1:11434",
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
TROUBLESHOOTING.md:264
# Or: Full permissions (less secure)
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
TROUBLESHOOTING.md:343
# Make permanent (add to ~/.bashrc or ~/.zshrc)
Why it matters. instructs the agent to persist itself in the user's environment
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CONFIGURATION.md:371
curl https://ollama.ai/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL.md:34
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALLATION_COMPLETE.md:10
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALLATION_COMPLETE.md:73
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
REDDIT_QUICKSTART.md:22
curl -sSL https://raw.githubusercontent.com/savantskie/persistent-ai-memory/main/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 9b1092369159full audit observations/trust-audit/mcp-server/savantskie__persistent-ai-memory.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-069b1092369159BLOCKD69first audit
05

Questions

What is the Persistent AI Memory MCP server?

A persistent local memory for AI, LLMs, or Copilot in VS Code.

What tools does Persistent AI Memory expose?

38 in total: 28 read-only, 9 that write, and 1 that can delete or overwrite (delete_reminder). Every one is listed on this page with its risk.

Is Persistent AI Memory safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Persistent AI Memory need?

No credential environment variables were found in its source, so it appears to need none.

How does Persistent AI Memory run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (9b1092369159), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement