Claude Total MemoryBLOCK
Persistent local memory for AI coding agents — Claude Code, Codex CLI, Cursor, any MCP client. Temporal knowledge graph, procedural memory, AST codebase ingest, cross-project analogy. LongMemEval R@5 95.1%, LoCoMo 0.607, BEAM 1M 0.448. 74 MCP tools, 9 IDEs, 100% local.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Persistent, local memory for AI coding agents: Claude Code, Codex CLI, Cursor and any MCP client.
[](https://pypi.org/project/total-agent-memory/) [](https://pypi.org/project/total-agent-memory/) [](https://www.npmjs.com/package/total-agent-memory) [](https://github.com/vbcherepanov/total-agent-memory/pkgs/container/total-agent-memory) [](https://modelcontextprotocol.io) [](LICENSE)
total-agent-memory (TAM) is an open-source memory server for AI coding agents. Coding agents start every session without memory of earlier ones, so decisions, fixes and project conventions have to be explained again. TAM stores decisions, solutions, facts, errors and session summaries on your machine and returns them through the Model Context Protocol (MCP), so any MCP client can use it without code changes.
Each store is one directory built around a SQLite database. Recall combines full-text BM25, dense embeddings computed locally, fuzzy matching and a knowledge graph, and fuses the ranked lists with reciprocal rank fusion; an optional cross-encoder can rerank the result. The default profile makes no LLM call on write or search, so r
b48b774bace1OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add total-agent-memory -- None total-agent-memory==14.7.0
Exposed tools (76)
51 read · 22 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analogize | write | Find past solutions/lessons from OTHER projects whose feature set |
benchmark | write | Run the eval harness: recall_at_k, prevention_rate, latency percentiles. |
classify_task | read | v8.0: classify task into L1-L4 complexity + suggested phases. |
file_context | read | BEFORE editing a file, call this to surface past errors, lessons, |
ingest_codebase | read | Parse a file or directory into semantic AST chunks |
kg_add_fact | write | Record a temporal fact assertion (subject, predicate, object). |
kg_at | read | Point-in-time query: return fact assertions valid at `timestamp` |
kg_invalidate_fact | read | Close a currently-valid fact assertion. History is retained. |
kg_timeline | read | Full chronological history of assertions for a subject. |
learn_error | read | Structured error capture: file, error, root_cause, fix, pattern. |
list_intents | read | List recent user prompts from the intents table, newest first. |
memory_answer | read | Generate and verify a cited answer using the configured reasoning LLM. |
memory_associate | read | Associative recall — brain-like spreading activation through knowledge graph. |
memory_concepts | read | List or search concepts in the knowledge graph. |
memory_consolidate | write | Find and merge duplicate/similar knowledge records. Keeps the longest version, |
memory_consolidate_status | write | v11.0 W2-G: report the consolidation daemon state — per-project last-run, |
memory_context_build | read | Build optimal context for a query. Combines: spreading activation + knowledge graph |
memory_delete | destructive | Delete a knowledge record. By default a soft delete: the record leaves search results |
memory_entity_resolve | read | v11.0 W1-F: resolve a mention to its canonical entity within a project+type. |
memory_episode_recall | read | Find past episodes (experiences). Search by concepts, outcome, project, or impact. |
memory_episode_save | write | Save an episode — narrative of WHAT HAPPENED and HOW. |
memory_eval_contradictions | read | v11.0 Phase 8: runs contradiction_detector against a labelled |
memory_eval_entity_consistency | read | v11.0 Phase 8: verifies entity_dedup canonicalization is stable |
memory_eval_locomo | write | v11.0 Phase 8: run the LongMemEval-style recall+prevention |
memory_eval_long_context | read | v11.0 Phase 8: large-context recall scenario. Saves N records |
memory_eval_recall | read | v11.0 Phase 8: generic recall benchmark on a dataset path or a |
memory_eval_temporal | read | v11.0 Phase 8: temporal recall using temporal_kg + temporal_filter. |
memory_explain_search | read | v11.0: same as memory_search_fast but returns a per-tier breakdown |
memory_export | read | Export all knowledge as JSON for backup or migration. |
memory_extract_session | read | Get pending session transcripts for knowledge extraction. |
memory_forget | write | Apply retention policy: archive stale records (>180d, never recalled, low confidence), |
memory_get | read | Batched fetch by ID — complement to memory_recall(mode= |
memory_graph | read | Query the unified knowledge graph. Returns neighborhood of a node: |
memory_graph_index | read | Reindex CLAUDE.md rules and skills into the knowledge graph. |
memory_graph_stats | read | Knowledge graph statistics: nodes, edges, communities, top concepts, health metrics. |
memory_history | read | View version history for a knowledge record. Shows the chain of superseded versions |
memory_index_passages | read | Build local passage indexes before evidence searches. Repeat using next_after_id until remaining=0. |
memory_observe | write | Save a lightweight observation (auto-capture). No dedup, no ChromaDB — fast and cheap. |
memory_perf_report | read | v11.0: dump in-process telemetry counters (search_total_ms, embed_ms, |
memory_rebuild_embeddings | read | v11.0: re-encode every record (or every record in a given embedding |
memory_rebuild_fts | destructive | v11.0: drop and rebuild the SQLite FTS5 virtual table from `knowledge` |
memory_recall | read | Search ALL memory: decisions, solutions, facts, lessons from ALL past sessions. |
memory_recall_iterative | read | v11.0 W1-B: IRCoT-style iterative retrieval. Decomposes the query into |
memory_reflect_now | write | Run reflection (the |
memory_relate | write | Create a typed relation between two knowledge records. Enriches graph expansion in Tier 4 search. |
memory_save | write | Save knowledge explicitly. Types: decision (MUST include WHY in context), |
memory_save_fast | write | v11.0: same as memory_save but routes through the fast hot path |
memory_search_by_tag | read | Search knowledge by tag. Returns all active records with matching tag (partial match). |
memory_search_fast | read | v11.0: like memory_recall but with rerank=False, diverse=False forced. |
memory_self_assess | read | Self-assessment: how competent am I in given domains? Shows level, confidence, blind spots. |
memory_skill_get | write | Find skills matching a trigger. Skills are learned procedures — HOW to do things. |
memory_skill_update | write | Record skill usage or refine a skill. Updates success rate and metrics. |
memory_stats | read | Memory statistics with health metrics: sessions, knowledge by type/project, |
memory_temporal_query | read | v11.0 W1-C: deterministic temporal reasoning — Allen interval relations, |
memory_timeline | read | Browse session history. sessions_ago=N for |
memory_update | write | Update existing knowledge. Replaces the record `id`, or the best match for `find` |
memory_warmup | read | v11.0: pre-load FastEmbed model and open the vector store, so the |
memory_wiki_generate | read | v10 — Render the per-project wiki digest (top decisions, |
phase_transition | read | v8.0: advance a task to the next phase. |
rule_set_phase | destructive | Attach or remove a phase scope on a rule (v8.0 lazy rule loading). |
save_decision | write | v8.0: save a structured architectural decision (options + criteria matrix + |
save_intent | write | Persist one user prompt into the `intents` table (same source as the |
search_intents | read | Substring search over user prompts (LIKE). Returns newest match first. |
self_error_log | read | Log an error/failure for pattern analysis. Call AUTOMATICALLY when: |
self_insight | read | Manage insights from error patterns (ExpeL-style). Actions: |
self_patterns | read | Analyze error patterns and self-improvement stats. Views: |
self_reflect | write | Save a verbal self-reflection (Reflexion pattern). |
self_rules | read | Manage behavioral rules (SOUL). Rules are promoted insights that shape agent behavior. |
self_rules_context | read | Get active behavioral rules for current session. |
session_end | read | End-of-session capture: summary + highlights + pitfalls + next_steps |
session_init | write | At session start: return the most recent unconsumed end-of-session |
task_create | write | v8.0: start a task in `van` phase (auto-classifies level if missing). |
task_phases_list | write | v8.0: list all phases of a task in chronological order. |
workflow_learn | read | Record a learned workflow (named sequence of steps) for future reuse. |
workflow_predict | read | Predict outcome (success probability, avg duration) for a workflow |
workflow_track | read | Record a workflow execution outcome. Outcome ∈ |
Trust audit
BLOCKgrade F · trust 36/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (8 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
!function(g,t){"object"==typeof exports&&"undefined"!=typeof module?t(exports):"function"==typeof define&&define.amd?define(["exports"],t):t((g="undefined"!=typeof globalThis?globalThis:g||self).vis=g".env" ... urllib.request
".env" ... urllib.request
".env" ... urllib.request
".env" ... urllib.request
importlib.import_module(mod)
mod = importlib.import_module(module_path)
(r"\b(?:send|upload|post|exfiltrate|forward)\b[^.\n]{0,60}\b(?:ssh key|private key|id_rsa|api key|password|"CMD curl -fsS http://127.0.0.1:37737/healthz >/dev/null \
&& curl -fsS http://127.0.0.1:3737/healthz >/dev/null \
f"[tune] {model_id} -> τc={winner.p_contradict_threshold} "f"τe={winner.p_entail_threshold} margin={winner.p_contradict_margin} "r"(?<=[.!?])\s+(?=[A-ZА-ЯЁ])"
words = re.findall(r"[a-zA-Zа-яА-ЯёЁ0-9][\w-]{1,}", text.lower())names = re.findall(r'\b[A-ZА-Я][a-zа-я]+(?:[ -][A-ZА-Я][a-zа-я]+)*\b', subject)
KEY = 'sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789'
KEY = "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789"
KEY = "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789"
"anthropic": "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789",
ANTHROPIC = "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789"
TAM_TEST_PG_URL: postgresql://tam_ci:[email protected]:5432/postgres?sslmode=disable
export TAM_BENCH_PG_ADMIN_URL=postgresql://postgres:[email protected]:5433/postgres?sslmode=disable
`<data dir>/database.json` (mode 0600) holds the DSN encrypted with the master key, the installation id and the generation. Precedence: the dashboard's setting (`database.json`) > `TAM_TEAM_DATABASE_U
MASK = 'postgresql://tam:••••@db.internal:5433/tam_prod?sslmode=require'
admin_url = f"postgresql://{PG_TEST_USER}:{password}@127.0.0.1:{port}/postgres?sslmode=disable"Gates applied: no_behavioural_pass.
b48b774bace1full audit observations/trust-audit/mcp-server/vbcherepanov__claude-total-memory-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b48b774bace1 | BLOCK | F | 36 | first audit |
Questions
What is the Claude Total Memory MCP server?
Persistent local memory for AI coding agents — Claude Code, Codex CLI, Cursor, any MCP client. Temporal knowledge graph, procedural memory, AST codebase ingest, cross-project analogy. LongMemEval R@5 95.1%, LoCoMo 0.607, BEAM 1M 0.448. 74 MCP tools, 9 IDEs, 100% local.
What tools does Claude Total Memory expose?
76 in total: 51 read-only, 22 that write, and 3 that can delete or overwrite (memory_delete, memory_rebuild_fts, rule_set_phase). Every one is listed on this page with its risk.
Is Claude Total Memory safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (36/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Claude Total Memory need?
It reads ANTHROPIC_API_KEY, COHERE_API_KEY, GITHUB_TOKEN, MEMORY_EMBED_API_KEY, MEMORY_LLM_API_KEY, MEMORY_PASSAGE_INDEX_ENABLED, MEMORY_QUALITY_BYPASS_TYPES, OPENAI_API_KEY, TAM_REMOTE_TOKEN_FILE and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Claude Total Memory run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as total-agent-memory.
How current is this page?
The grade is for one exact copy of the source (b48b774bace1), read on 2026-10-07. The repository is watched and re-audited when it changes.