MemorySAFE
MCP Memory Server with PostgreSQL and pgvector for long-term memory capabilities
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This server implements long-term memory capabilities for AI assistants using mem0 principles, powered by PostgreSQL with pgvector for efficient vector similarity search.
Features
- PostgreSQL with pgvector for vector similarity search
- Automatic embedding generation using BERT
- RESTful API for memory operations
- Semantic search capabilities
- Support for different types of memories (learnings, experiences, etc.)
- Tag-based memory retrieval
- Confidence scoring for memories
- Server-Sent Events (SSE) for real-time updates
- Cursor MCP protocol compatible
Prerequisites
- PostgreSQL 14+ with pgvector extension installed:
# In your PostgreSQL instance: CREATE EXTENSION vector;
- Node.js 16+
Setup
- Install dependencies:
npm install
- Configure environment variables:
Copy .env.sample to .env and adjust the values:
cp .env.sample .env
Example .env configurations:
# With username/password DATABASE_URL="postgresql://username:password@localhost:5432/mcp_memory" PORT=3333 # Local development with peer authentication DATABASE_URL="postgresql:///mcp_memory" PORT=3333
- Initialize the database:
npm run prisma:migrate
- Start the server:
npm start
For development with auto-reload:
npm run dev
Using with Cursor
Adding the MCP Server in Cursor
To add the memory server to Cursor, you need to modify your MCP configuration file located at ~/.cursor/mcp.json. Add the following configuration to the mcpServers object:
{
"mcpServers": {
"memory": {
"command": "node",
"args": [
"/path/to/your/memory/src/server.js"
]
}
}
}Replace /path/to/your/memory with the actual path to your memory server installation.
For example, if you cloned the repository to /Users/username/workspace/memory, your configuration would look like:
{
"mcpServers": {
"memory": {
"command":5c557ac97df1OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-memory -- npx -y [email protected]
{
"mcpServers": {
"mcp-memory": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (3)
2 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
memory.create | write | Create a new memory entry |
memory.list | read | List all memories |
memory.search | read | Search for memories using semantic similarity |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
.env.sample
dotenv, @xenova/transformers, pg, nodemon
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
Gates applied: no_behavioural_pass, no_license.
5c557ac97df1full audit observations/trust-audit/mcp-server/sdimitrov__memory-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 5c557ac97df1 | SAFE | B | 89 | first audit |
Questions
What is the Memory MCP server?
MCP Memory Server with PostgreSQL and pgvector for long-term memory capabilities
What tools does Memory expose?
3 in total: 2 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Memory safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Memory need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (5c557ac97df1), read on 2026-10-07. The repository is watched and re-audited when it changes.