Claude Mem LiteBLOCK
Persistent long-term memory for Claude Code via MCP — captures coding decisions, bugfixes, and context across sessions. Hybrid FTS5 + TF-IDF search with episode batching. Single SQLite DB, no external services. Alternative to claude-mem with 600x lower cost.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
claude-mem-lite is a persistent memory (also called long-term memory or cross-session context) system for [Claude Code](https://docs.anthropic.com/en/docs/claude-code) — Anthropic's CLI coding agent. It runs as an [MCP](https://modelcontextprotocol.io/) server plus a set of Claude Code hooks, automatically capturing coding observations, decisions, and bug fixes during sessions, then providing full-text search with query expansion to recall them later.
Compared to general-purpose LLM memory frameworks like `mem0` or the MCP reference `memory` server, claude-mem-lite is purpose-built for Claude Code's hook lifecycle: episode batching cuts LLM calls 7–10× vs the original claude-mem (an estimated ~600× lower total cost — see the cost model below; this is an architecture estimate, not a measured benchmark), while the FTS5 retriever benchmarks at 0.90 Recall@10 / 0.85 Precision@10 (see Search Quality for the reproduction command).
中文简介:claude-mem-lite 是 Claude Code 的轻量级持久化记忆 / 长期记忆 / 跨会话上下文插件,基于 MCP 协议 + 钩子机制,自动捕获编码会话中的决策、修复和上下文,并通过 FTS5 全文检索召回。详见 中文 README。
Zero external services. Single SQLite database. Minimal overhead.
Why claude-mem-lite?
A ground-up redesign of claude-mem, replacing its heavyweight architecture with a smarter, leaner approach.
Architecture comparison
577bc31bc584OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add claude-mem-lite --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CLAUDE_MEM_FILE_INTEL_MIN_TOKENS=${CLAUDE_MEM_FILE_INTEL_MIN_TOKENS} --env CLAUDE_MEM_REREAD_MIN_TOKENS=${CLAUDE_MEM_REREAD_MIN_TOKENS} --env CLAUDE_MEM_UPS_IDENTIFIER_BYPASS=${CLAUDE_MEM_UPS_IDENTIFIER_BYPASS} -- npx -y [email protected]{
"mcpServers": {
"claude-mem-lite": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"CLAUDE_MEM_FILE_INTEL_MIN_TOKENS": "${CLAUDE_MEM_FILE_INTEL_MIN_TOKENS}",
"CLAUDE_MEM_REREAD_MIN_TOKENS": "${CLAUDE_MEM_REREAD_MIN_TOKENS}",
"CLAUDE_MEM_UPS_IDENTIFIER_BYPASS": "${CLAUDE_MEM_UPS_IDENTIFIER_BYPASS}"
}
}
}
}Exposed tools (19)
15 read · 2 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
mem_browse | read | |
mem_compress | read | |
mem_defer | read | |
mem_defer_drop | destructive | |
mem_defer_list | read | |
mem_delete | destructive | |
mem_export | read | |
mem_fts_check | read | |
mem_get | read | |
mem_maintain | read | |
mem_optimize | read | |
mem_recall | read | |
mem_recent | read | |
mem_save | write | |
mem_search | read | |
mem_search_feedback | read | |
mem_stats | read | |
mem_timeline | read | |
mem_update | write |
Trust audit
BLOCKgrade F · trust 41/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(NATIVE_BINDING_REBUILD_CMD, { cwd: installDir, stdio: 'pipe' });: () => exec(NATIVE_BINDING_SOURCE_BUILD_CMD, { cwd: installDir, stdio: 'pipe' }));"Done: x" adf8748 x | 1f5cb94 x | 540a5ef -
8. BOM settings.json refused with an invisible char in the message ("Unexpected token ''"); empty and whitespace-only settings.json also refused (nothing to lose there).header: 'Authorization: Bearer sk-ant-api03-XYZ123456789abcdef',
expect(parsed.ctx).not.toContain('sk-ant-api03-XYZ123456789abcdef');const secret = 'Authorization: Bearer sk-ant-api03-XYZ123456789abcdef';
expect(line).not.toContain('sk-ant-api03-XYZ123456789abcdef');const SECRET_CMD = 'curl -H "Authorization: Bearer sk-ant-api03-abcdefghijklmnop" https://x';
| 28 | db connection URL | `postgres://user:passwordvalue@host/db/notes.mjs` | `\b(postgres(?:ql)?\|mysql\|...)...` |
body: 'connect with postgres://user:[email protected]:5432/app and api_key=sk-abcdefghij1234567890',
'postgres://u:p@h:5432/db',
const SECRET = 'sk-ant-api03-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA';
stored title : rotate ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789ab before release
stored files : ["/home/u/ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789/app.mjs"]
title: 'repro: export GH_TOKEN=ghp_abcdefghijklmnopqrstuvwxyz0123456789',
const GH_TOKEN = 'ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789ab';
const pat = 'ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789';
MATCH idx=19 probe="-----BEGIN RSA PRIVATE KEY-----***-----END RSA PRIVATE KEY-----"
`Here is the key: -----BEGIN RSA PRIVATE KEY----- MIIJKAIBAAKCAgEA...` (about 70 chars of the key body), even
NEW: "$ head -c 120 id_rsa\n-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEAu1SU1LfVLPHCozMxH2Mo4lgOEePzNm0tRgeLezV6ffAt0gunVTLw7onLRnrq0\n$ cat id_rsa\n***PEM_KEY***"
NEW: "-----BEGIN OPENSSH PRIVATE KEY-----\nMIIEow...rq0\n-----BEGIN CERTIFICATE-----...***PEM_KEY***" K1 leaked NEW: true OLD: false
PUBLIC KEY, now erases all the text between them: `Keys start with -----BEGIN RSA PRIVATE KEY----- and certs ... with -----BEGIN CERTIFICATE----- ok` →
expect(scrubSecrets('xoxb-123456789-abcdefghij')).toBe('***');expect(scrubSecrets('xoxp-token-value-here')).toBe('***');Gates applied: no_behavioural_pass.
577bc31bc584full audit observations/trust-audit/mcp-server/sdsrss__claude-mem-lite.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 577bc31bc584 | BLOCK | F | 41 | first audit |
Questions
What is the Claude Mem Lite MCP server?
Persistent long-term memory for Claude Code via MCP — captures coding decisions, bugfixes, and context across sessions. Hybrid FTS5 + TF-IDF search with episode batching. Single SQLite DB, no external services. Alternative to claude-mem with 600x lower cost.
What tools does Claude Mem Lite expose?
19 in total: 15 read-only, 2 that write, and 2 that can delete or overwrite (mem_defer_drop, mem_delete). Every one is listed on this page with its risk.
Is Claude Mem Lite safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (41/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Claude Mem Lite need?
It reads ANTHROPIC_API_KEY, CLAUDE_MEM_FILE_INTEL_MIN_TOKENS, CLAUDE_MEM_REREAD_MIN_TOKENS, CLAUDE_MEM_UPS_IDENTIFIER_BYPASS, MEM_OR_FALLBACK_MAX_TOKENS, OPENROUTER_API_KEY and RELEASE_SIGNING_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Claude Mem Lite run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-mem-lite at 6.25.0.
How current is this page?
The grade is for one exact copy of the source (577bc31bc584), read on 2026-10-08. The repository is watched and re-audited when it changes.