Atlas / MCP servers / sdsrss / Claude Mem Lite

Claude Mem LiteBLOCK

mcp/sdsrss/claude-mem-lite

Persistent long-term memory for Claude Code via MCP — captures coding decisions, bugfixes, and context across sessions. Hybrid FTS5 + TF-IDF search with episode batching. Single SQLite DB, no external services. Alternative to claude-mem with 600x lower cost.

Verdict
BLOCK
Grade
F
Trust score
41 /100
Exposed tools
19 15r · 2w · 2d
Transport
stdio
License
MIT
Stars
66
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

claude-mem-lite is a persistent memory (also called long-term memory or cross-session context) system for [Claude Code](https://docs.anthropic.com/en/docs/claude-code) — Anthropic's CLI coding agent. It runs as an [MCP](https://modelcontextprotocol.io/) server plus a set of Claude Code hooks, automatically capturing coding observations, decisions, and bug fixes during sessions, then providing full-text search with query expansion to recall them later.

Compared to general-purpose LLM memory frameworks like `mem0` or the MCP reference `memory` server, claude-mem-lite is purpose-built for Claude Code's hook lifecycle: episode batching cuts LLM calls 7–10× vs the original claude-mem (an estimated ~600× lower total cost — see the cost model below; this is an architecture estimate, not a measured benchmark), while the FTS5 retriever benchmarks at 0.90 Recall@10 / 0.85 Precision@10 (see Search Quality for the reproduction command).

中文简介:claude-mem-lite 是 Claude Code 的轻量级持久化记忆 / 长期记忆 / 跨会话上下文插件,基于 MCP 协议 + 钩子机制,自动捕获编码会话中的决策、修复和上下文,并通过 FTS5 全文检索召回。详见 中文 README。

Zero external services. Single SQLite database. Minimal overhead.

Why claude-mem-lite?

A ground-up redesign of claude-mem, replacing its heavyweight architecture with a smarter, leaner approach.

Architecture comparison

Read from source at commit 577bc31bc584OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add claude-mem-lite --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CLAUDE_MEM_FILE_INTEL_MIN_TOKENS=${CLAUDE_MEM_FILE_INTEL_MIN_TOKENS} --env CLAUDE_MEM_REREAD_MIN_TOKENS=${CLAUDE_MEM_REREAD_MIN_TOKENS} --env CLAUDE_MEM_UPS_IDENTIFIER_BYPASS=${CLAUDE_MEM_UPS_IDENTIFIER_BYPASS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claude-mem-lite": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "CLAUDE_MEM_FILE_INTEL_MIN_TOKENS": "${CLAUDE_MEM_FILE_INTEL_MIN_TOKENS}",
        "CLAUDE_MEM_REREAD_MIN_TOKENS": "${CLAUDE_MEM_REREAD_MIN_TOKENS}",
        "CLAUDE_MEM_UPS_IDENTIFIER_BYPASS": "${CLAUDE_MEM_UPS_IDENTIFIER_BYPASS}"
      }
    }
  }
}
03

Exposed tools (19)

15 read · 2 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
mem_browseread
mem_compressread
mem_deferread
mem_defer_dropdestructive
mem_defer_listread
mem_deletedestructive
mem_exportread
mem_fts_checkread
mem_getread
mem_maintainread
mem_optimizeread
mem_recallread
mem_recentread
mem_savewrite
mem_searchread
mem_search_feedbackread
mem_statsread
mem_timelineread
mem_updatewrite
04

Trust audit

BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (6 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
lib/binding-probe.mjs:300
exec(NATIVE_BINDING_REBUILD_CMD, { cwd: installDir, stdio: 'pipe' });
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
lib/binding-probe.mjs:346
: () => exec(NATIVE_BINDING_SOURCE_BUILD_CMD, { cwd: installDir, stdio: 'pipe' }));
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/audits/20260926-v6.15.0-round3-review.md:46
"Done: x"              adf8748 x | 1f5cb94 x | 540a5ef -
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/audits/20260929-e2e-install-report.md:114
8. BOM settings.json refused with an invisible char in the message ("Unexpected token ''"); empty and whitespace-only settings.json also refused (nothing to lose there).
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/hook-telemetry.test.mjs:225
header: 'Authorization: Bearer sk-ant-api03-XYZ123456789abcdef',
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/hook-telemetry.test.mjs:228
expect(parsed.ctx).not.toContain('sk-ant-api03-XYZ123456789abcdef');
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/hook-telemetry.test.mjs:268
const secret = 'Authorization: Bearer sk-ant-api03-XYZ123456789abcdef';
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/hook-telemetry.test.mjs:293
expect(line).not.toContain('sk-ant-api03-XYZ123456789abcdef');
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/import-jsonl-dedup-scrub.test.mjs:35
const SECRET_CMD = 'curl -H "Authorization: Bearer sk-ant-api03-abcdefghijklmnop" https://x';
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/audits/20260921-preship-claims-v6.10.1.md:96
| 28 | db connection URL | `postgres://user:passwordvalue@host/db/notes.mjs` | `\b(postgres(?:ql)?\|mysql\|...)...` |
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/activity.test.mjs:38
body: 'connect with postgres://user:[email protected]:5432/app and api_key=sk-abcdefghij1234567890',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/handoff-working-on-scrub-order.test.mjs:300
'postgres://u:p@h:5432/db',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/secret-scrub-coverage.test.mjs:13
const SECRET = 'sk-ant-api03-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
docs/audits/20260906-173816.md:127
stored title : rotate ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789ab before release
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
docs/audits/20260913-v6.8.2-claims-review.md:50
stored files                     : ["/home/u/ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789/app.mjs"]
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/activity.test.mjs:37
title: 'repro: export GH_TOKEN=ghp_abcdefghijklmnopqrstuvwxyz0123456789',
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/audit-r10-secret-gaps.test.mjs:21
const GH_TOKEN = 'ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789ab';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/hook-telemetry.test.mjs:251
const pat = 'ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789';
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/audits/20260922-preship-claims-v6.11.0-r1.md:96
MATCH idx=19 probe="-----BEGIN RSA PRIVATE KEY-----***-----END RSA PRIVATE KEY-----"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/audits/20260927-v6.18.0-pretag-security-recheck.md:26
`Here is the key: -----BEGIN RSA PRIVATE KEY----- MIIJKAIBAAKCAgEA...` (about 70 chars of the key body), even
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/audits/20260927-v6.19.0-pretag-defect.md:31
NEW: "$ head -c 120 id_rsa\n-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEAu1SU1LfVLPHCozMxH2Mo4lgOEePzNm0tRgeLezV6ffAt0gunVTLw7onLRnrq0\n$ cat id_rsa\n***PEM_KEY***"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/audits/20260927-v6.19.0-pretag-defect.md:34
NEW: "-----BEGIN OPENSSH PRIVATE KEY-----\nMIIEow...rq0\n-----BEGIN CERTIFICATE-----...***PEM_KEY***"   K1 leaked NEW: true OLD: false
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/audits/20260927-v6.19.0-pretag-delta.md:54
PUBLIC KEY, now erases all the text between them: `Keys start with -----BEGIN RSA PRIVATE KEY----- and certs ... with -----BEGIN CERTIFICATE----- ok` →
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
tests/utils.test.mjs:1613
expect(scrubSecrets('xoxb-123456789-abcdefghij')).toBe('***');
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
tests/utils.test.mjs:1614
expect(scrubSecrets('xoxp-token-value-here')).toBe('***');

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 577bc31bc584full audit observations/trust-audit/mcp-server/sdsrss__claude-mem-lite.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08577bc31bc584BLOCKF41first audit
06

Questions

What is the Claude Mem Lite MCP server?

Persistent long-term memory for Claude Code via MCP — captures coding decisions, bugfixes, and context across sessions. Hybrid FTS5 + TF-IDF search with episode batching. Single SQLite DB, no external services. Alternative to claude-mem with 600x lower cost.

What tools does Claude Mem Lite expose?

19 in total: 15 read-only, 2 that write, and 2 that can delete or overwrite (mem_defer_drop, mem_delete). Every one is listed on this page with its risk.

Is Claude Mem Lite safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (41/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Claude Mem Lite need?

It reads ANTHROPIC_API_KEY, CLAUDE_MEM_FILE_INTEL_MIN_TOKENS, CLAUDE_MEM_REREAD_MIN_TOKENS, CLAUDE_MEM_UPS_IDENTIFIER_BYPASS, MEM_OR_FALLBACK_MAX_TOKENS, OPENROUTER_API_KEY and RELEASE_SIGNING_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Mem Lite run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-mem-lite at 6.25.0.

How current is this page?

The grade is for one exact copy of the source (577bc31bc584), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement