Knowledge Graph MemorySAFE
MCP server enabling persistent memory for Claude through a local knowledge graph - fork focused on local development
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Persistent memory for AI models through a local knowledge graph.
Store and retrieve information across conversations using entities, relations, and observations. Works with Claude Code/Desktop and any MCP-compatible AI platform.
Why ".aim" and "aim_" prefixes?
AIM stands for AI Memory - the core concept of this system. The three AIM elements provide clear organization and safety:
- `.aim` directories: Keep AI memory files organized and easily identifiable
- `aim_` tool prefixes: Group related memory functions together in multi-tool setups
- `_aim` safety markers: Each memory file starts with
{"type":"_aim","source":"mcp-knowledge-graph"}to prevent accidental overwrites of unrelated JSONL files
This consistent AIM naming makes it obvious which directories, tools, and files belong to the AI memory system.
CRITICAL: Understanding .aim dir vs _aim file marker
Two different things with similar names:
.aim= Project-local directory name (MUST be named exactly.aimfor project detection to work)_aim= File safety marker (appears inside JSONL files:{"type":"_aim","source":"mcp-knowledge-graph"})
For project-local storage:
- Directory MUST be named
.aimin your project root - Example:
my-project/.aim/memory.jsonl - The system specifically looks for this exact name
For global storage (--memory-path):
- Can be ANY directory you want
- Examples:
~/yourusername/.aim/,~/memories/,~/Dropbox/ai-memory/,~/Documents/ai-data/ - Complete flexibility - choose whatever location works for you
Storage Logic
File Location Priority:
- Project with `.aim` - Uses
.aim/memory.jsonl(project-local) - No project/no .aim - Uses configured global directory
- Contexts - Adds suffix:
memory-work.jsonl,memory-personal.jsonl
Safety System:
- Every memory file starts with
{"type":"_aim","source":"mcp-knowledge-graph"} - System refuses to write to fi
8c532b6a1e5fOBSERVED · 2026-09-26Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-knowledge-graph -- npx -y [email protected]
{
"mcpServers": {
"mcp-knowledge-graph": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
7 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
aim_memory_forget | read | Forget memories. Removes memories and their associated links. DATABASE SELECTION: Entities are deleted from the specified database |
aim_memory_get | read | Retrieve specific memories by exact name. Use this when you know exactly what you |
aim_memory_link | read | Link two memories together with a relationship. Use this to connect related information. RELATION STRUCTURE: Each link has |
aim_memory_list_stores | read | List all available memory databases and show current storage location. DATABASE TYPES: - |
aim_memory_read_all | read | Read all memories in a database. Returns every stored memory and their links. FORMAT OPTIONS: - |
aim_memory_remove_facts | destructive | Remove specific facts from a memory. Keeps the memory but removes selected observations. DATABASE SELECTION: Observations are deleted from entities within the specified database |
aim_memory_search | read | Search memories by keyword. Use this when you don |
aim_memory_store | read | Store new memories. Use this to remember people, projects, concepts, or any information worth persisting. AIM (AI Memory) provides persistent memory for AI assistants. The |
aim_memory_unlink | destructive | Remove links between memories. Keeps the memories but removes their connections. DATABASE SELECTION: Relations are deleted from the specified database |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
aim_memory_remove_facts, aim_memory_unlink
for (const bad of ['a/b', 'a\\b', 'work/../../etc']) {assert.throws(() => assertContextSafe('../../../../tmp/pwned'), /path separators/);minimist, @types/minimist, @types/node, shx, typescript
Gates applied: no_behavioural_pass.
8c532b6a1e5ffull audit observations/trust-audit/mcp-server/shaneholloman__knowledge-graph-memory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | 8c532b6a1e5f | SAFE | B | 89 | first audit |
Questions
What is the Knowledge Graph Memory MCP server?
MCP server enabling persistent memory for Claude through a local knowledge graph - fork focused on local development
What tools does Knowledge Graph Memory expose?
9 in total: 7 read-only, 0 that write, and 2 that can delete or overwrite (aim_memory_remove_facts, aim_memory_unlink). Every one is listed on this page with its risk.
Is Knowledge Graph Memory safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Knowledge Graph Memory need?
No credential environment variables were found in its source, so it appears to need none.
How does Knowledge Graph Memory run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-knowledge-graph at 1.4.0.
How current is this page?
The grade is for one exact copy of the source (8c532b6a1e5f), read on 2026-09-26. The repository is watched and re-audited when it changes.