Atlas / MCP servers / vbcherepanov / Claude Total Memory

Claude Total MemoryBLOCK

mcp/vbcherepanov/claude-total-memory-1

Persistent local memory for AI coding agents — Claude Code, Codex CLI, Cursor, any MCP client. Temporal knowledge graph, procedural memory, AST codebase ingest, cross-project analogy. LongMemEval R@5 95.1%, LoCoMo 0.607, BEAM 1M 0.448. 74 MCP tools, 9 IDEs, 100% local.

Verdict
BLOCK
Grade
F
Trust score
36 /100
Exposed tools
76 51r · 22w · 3d
Transport
stdio · streamable-http
License
MIT
Stars
71
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Persistent, local memory for AI coding agents: Claude Code, Codex CLI, Cursor and any MCP client.

[](https://pypi.org/project/total-agent-memory/) [](https://pypi.org/project/total-agent-memory/) [](https://www.npmjs.com/package/total-agent-memory) [](https://github.com/vbcherepanov/total-agent-memory/pkgs/container/total-agent-memory) [](https://modelcontextprotocol.io) [](LICENSE)

total-agent-memory (TAM) is an open-source memory server for AI coding agents. Coding agents start every session without memory of earlier ones, so decisions, fixes and project conventions have to be explained again. TAM stores decisions, solutions, facts, errors and session summaries on your machine and returns them through the Model Context Protocol (MCP), so any MCP client can use it without code changes.

Each store is one directory built around a SQLite database. Recall combines full-text BM25, dense embeddings computed locally, fuzzy matching and a knowledge graph, and fuses the ranked lists with reciprocal rank fusion; an optional cross-encoder can rerank the result. The default profile makes no LLM call on write or search, so r

Read from source at commit b48b774bace1OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add total-agent-memory -- None total-agent-memory==14.7.0
03

Exposed tools (76)

51 read · 22 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analogizewriteFind past solutions/lessons from OTHER projects whose feature set
benchmarkwriteRun the eval harness: recall_at_k, prevention_rate, latency percentiles.
classify_taskreadv8.0: classify task into L1-L4 complexity + suggested phases.
file_contextreadBEFORE editing a file, call this to surface past errors, lessons,
ingest_codebasereadParse a file or directory into semantic AST chunks
kg_add_factwriteRecord a temporal fact assertion (subject, predicate, object).
kg_atreadPoint-in-time query: return fact assertions valid at `timestamp`
kg_invalidate_factreadClose a currently-valid fact assertion. History is retained.
kg_timelinereadFull chronological history of assertions for a subject.
learn_errorreadStructured error capture: file, error, root_cause, fix, pattern.
list_intentsreadList recent user prompts from the intents table, newest first.
memory_answerreadGenerate and verify a cited answer using the configured reasoning LLM.
memory_associatereadAssociative recall — brain-like spreading activation through knowledge graph.
memory_conceptsreadList or search concepts in the knowledge graph.
memory_consolidatewriteFind and merge duplicate/similar knowledge records. Keeps the longest version,
memory_consolidate_statuswritev11.0 W2-G: report the consolidation daemon state — per-project last-run,
memory_context_buildreadBuild optimal context for a query. Combines: spreading activation + knowledge graph
memory_deletedestructiveDelete a knowledge record. By default a soft delete: the record leaves search results
memory_entity_resolvereadv11.0 W1-F: resolve a mention to its canonical entity within a project+type.
memory_episode_recallreadFind past episodes (experiences). Search by concepts, outcome, project, or impact.
memory_episode_savewriteSave an episode — narrative of WHAT HAPPENED and HOW.
memory_eval_contradictionsreadv11.0 Phase 8: runs contradiction_detector against a labelled
memory_eval_entity_consistencyreadv11.0 Phase 8: verifies entity_dedup canonicalization is stable
memory_eval_locomowritev11.0 Phase 8: run the LongMemEval-style recall+prevention
memory_eval_long_contextreadv11.0 Phase 8: large-context recall scenario. Saves N records
memory_eval_recallreadv11.0 Phase 8: generic recall benchmark on a dataset path or a
memory_eval_temporalreadv11.0 Phase 8: temporal recall using temporal_kg + temporal_filter.
memory_explain_searchreadv11.0: same as memory_search_fast but returns a per-tier breakdown
memory_exportreadExport all knowledge as JSON for backup or migration.
memory_extract_sessionreadGet pending session transcripts for knowledge extraction.
memory_forgetwriteApply retention policy: archive stale records (>180d, never recalled, low confidence),
memory_getreadBatched fetch by ID — complement to memory_recall(mode=
memory_graphreadQuery the unified knowledge graph. Returns neighborhood of a node:
memory_graph_indexreadReindex CLAUDE.md rules and skills into the knowledge graph.
memory_graph_statsreadKnowledge graph statistics: nodes, edges, communities, top concepts, health metrics.
memory_historyreadView version history for a knowledge record. Shows the chain of superseded versions
memory_index_passagesreadBuild local passage indexes before evidence searches. Repeat using next_after_id until remaining=0.
memory_observewriteSave a lightweight observation (auto-capture). No dedup, no ChromaDB — fast and cheap.
memory_perf_reportreadv11.0: dump in-process telemetry counters (search_total_ms, embed_ms,
memory_rebuild_embeddingsreadv11.0: re-encode every record (or every record in a given embedding
memory_rebuild_ftsdestructivev11.0: drop and rebuild the SQLite FTS5 virtual table from `knowledge`
memory_recallreadSearch ALL memory: decisions, solutions, facts, lessons from ALL past sessions.
memory_recall_iterativereadv11.0 W1-B: IRCoT-style iterative retrieval. Decomposes the query into
memory_reflect_nowwriteRun reflection (the
memory_relatewriteCreate a typed relation between two knowledge records. Enriches graph expansion in Tier 4 search.
memory_savewriteSave knowledge explicitly. Types: decision (MUST include WHY in context),
memory_save_fastwritev11.0: same as memory_save but routes through the fast hot path
memory_search_by_tagreadSearch knowledge by tag. Returns all active records with matching tag (partial match).
memory_search_fastreadv11.0: like memory_recall but with rerank=False, diverse=False forced.
memory_self_assessreadSelf-assessment: how competent am I in given domains? Shows level, confidence, blind spots.
memory_skill_getwriteFind skills matching a trigger. Skills are learned procedures — HOW to do things.
memory_skill_updatewriteRecord skill usage or refine a skill. Updates success rate and metrics.
memory_statsreadMemory statistics with health metrics: sessions, knowledge by type/project,
memory_temporal_queryreadv11.0 W1-C: deterministic temporal reasoning — Allen interval relations,
memory_timelinereadBrowse session history. sessions_ago=N for
memory_updatewriteUpdate existing knowledge. Replaces the record `id`, or the best match for `find`
memory_warmupreadv11.0: pre-load FastEmbed model and open the vector store, so the
memory_wiki_generatereadv10 — Render the per-project wiki digest (top decisions,
phase_transitionreadv8.0: advance a task to the next phase.
rule_set_phasedestructiveAttach or remove a phase scope on a rule (v8.0 lazy rule loading).
save_decisionwritev8.0: save a structured architectural decision (options + criteria matrix +
save_intentwritePersist one user prompt into the `intents` table (same source as the
search_intentsreadSubstring search over user prompts (LIKE). Returns newest match first.
self_error_logreadLog an error/failure for pattern analysis. Call AUTOMATICALLY when:
self_insightreadManage insights from error patterns (ExpeL-style). Actions:
self_patternsreadAnalyze error patterns and self-improvement stats. Views:
self_reflectwriteSave a verbal self-reflection (Reflexion pattern).
self_rulesreadManage behavioral rules (SOUL). Rules are promoted insights that shape agent behavior.
self_rules_contextreadGet active behavioral rules for current session.
session_endreadEnd-of-session capture: summary + highlights + pitfalls + next_steps
session_initwriteAt session start: return the most recent unconsumed end-of-session
task_createwritev8.0: start a task in `van` phase (auto-classifies level if missing).
task_phases_listwritev8.0: list all phases of a task in chronological order.
workflow_learnreadRecord a learned workflow (named sequence of steps) for future reuse.
workflow_predictreadPredict outcome (success probability, avg duration) for a workflow
workflow_trackreadRecord a workflow execution outcome. Outcome ∈
04

Trust audit

BLOCKgrade F · trust 36/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
declared (10 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/dashboard_static/vendor/vis-network-9.1.6/vis-network.min.js:26
!function(g,t){"object"==typeof exports&&"undefined"!=typeof module?t(exports):"function"==typeof define&&define.amd?define(["exports"],t):t((g="undefined"!=typeof globalThis?globalThis:g||self).vis=g
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
src/tools/brain_autonomy.py:34
".env" ... urllib.request
Why it matters. reads secrets in the same file that sends data out
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
src/tools/dependency_monitor.py:27
".env" ... urllib.request
Why it matters. reads secrets in the same file that sends data out
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
src/tools/llm_router.py:32
".env" ... urllib.request
Why it matters. reads secrets in the same file that sends data out
HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
src/tools/tech_radar.py:27
".env" ... urllib.request
Why it matters. reads secrets in the same file that sends data out
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/v9_cheap_full_run.sh:35
importlib.import_module(mod)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/reflection/scheduler.py:65
mod = importlib.import_module(module_path)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/recall_output.py:29
(r"\b(?:send|upload|post|exfiltrate|forward)\b[^.\n]{0,60}\b(?:ssh key|private key|id_rsa|api key|password|"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:101
CMD curl -fsS http://127.0.0.1:37737/healthz >/dev/null \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:102
&& curl -fsS http://127.0.0.1:3737/healthz >/dev/null \
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/calibrate_nli.py:1324
f"[tune] {model_id} -> τc={winner.p_contradict_threshold} "
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/calibrate_nli.py:1325
f"τe={winner.p_entail_threshold} margin={winner.p_contradict_margin} "
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/ingestion/chunker.py:40
r"(?<=[.!?])\s+(?=[A-ZА-ЯЁ])"
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/ingestion/extractor.py:409
words = re.findall(r"[a-zA-Zа-яА-ЯёЁ0-9][\w-]{1,}", text.lower())
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/memory_core/grounding.py:48
names = re.findall(r'\b[A-ZА-Я][a-zа-я]+(?:[ -][A-ZА-Я][a-zа-я]+)*\b', subject)
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/browser/test_local_settings_ui.py:16
KEY = 'sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789'
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/test_dashboard_settings.py:21
KEY = "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789"
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/test_local_settings.py:21
KEY = "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789"
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/test_secret_redaction.py:22
"anthropic": "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789",
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/test_stored_secrets.py:19
ANTHROPIC = "sk-ant-api03-AbCdEfGhIjKlMnOpQrStUvWxYz0123456789"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/postgres.yml:36
TAM_TEST_PG_URL: postgresql://tam_ci:[email protected]:5432/postgres?sslmode=disable
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
benchmarks/pg_parity_bench.py:18
export TAM_BENCH_PG_ADMIN_URL=postgresql://postgres:[email protected]:5433/postgres?sslmode=disable
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/TEAM_POSTGRES.md:109
`<data dir>/database.json` (mode 0600) holds the DSN encrypted with the master key, the installation id and the generation. Precedence: the dashboard's setting (`database.json`) > `TAM_TEAM_DATABASE_U
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/browser/test_team_database_ui.py:21
MASK = 'postgresql://tam:••••@db.internal:5433/tam_prod?sslmode=require'
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/pg_support.py:172
admin_url = f"postgresql://{PG_TEST_USER}:{password}@127.0.0.1:{port}/postgres?sslmode=disable"

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b48b774bace1full audit observations/trust-audit/mcp-server/vbcherepanov__claude-total-memory-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b48b774bace1BLOCKF36first audit
06

Questions

What is the Claude Total Memory MCP server?

Persistent local memory for AI coding agents — Claude Code, Codex CLI, Cursor, any MCP client. Temporal knowledge graph, procedural memory, AST codebase ingest, cross-project analogy. LongMemEval R@5 95.1%, LoCoMo 0.607, BEAM 1M 0.448. 74 MCP tools, 9 IDEs, 100% local.

What tools does Claude Total Memory expose?

76 in total: 51 read-only, 22 that write, and 3 that can delete or overwrite (memory_delete, memory_rebuild_fts, rule_set_phase). Every one is listed on this page with its risk.

Is Claude Total Memory safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (36/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Claude Total Memory need?

It reads ANTHROPIC_API_KEY, COHERE_API_KEY, GITHUB_TOKEN, MEMORY_EMBED_API_KEY, MEMORY_LLM_API_KEY, MEMORY_PASSAGE_INDEX_ENABLED, MEMORY_QUALITY_BYPASS_TYPES, OPENAI_API_KEY, TAM_REMOTE_TOKEN_FILE and TYPESAFE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Total Memory run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as total-agent-memory.

How current is this page?

The grade is for one exact copy of the source (b48b774bace1), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement