Atlas / MCP servers / verygoodplugins / AutoMem

AutoMemBLOCK

mcp/verygoodplugins/automem

MCP client for AutoMem — give Claude, Cursor, Codex, and other MCP tools durable graph+vector memory across conversations.

Verdict
BLOCK
Grade
D
Trust score
68 /100
Exposed tools
28 12r · 14w · 2d
Transport
sse · stdio · streamable-http
License
MIT
Stars
65
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

One command. Infinite memory. Perfect recall across all your AI tools.

npx @verygoodplugins/mcp-automem setup

Your AI assistant now remembers everything. Forever. Across every conversation.

https://github.com/user-attachments/assets/fd79112b-5158-4320-a054-8c18ab1ea314

The guided installer — npx @verygoodplugins/mcp-automem install walks you through local, hosted, or existing-endpoint setup.

Works with Claude Desktop, Cursor IDE, Claude Code, GitHub Copilot (coding agent), ChatGPT, ElevenLabs, OpenAI Codex, OpenClaw, Hermes, Grok Build, Google Antigravity - any MCP-compatible AI platform.

The Problem We Solve

Every AI conversation starts from zero. Claude forgets your coding style. Cursor can't learn your patterns. Your assistant doesn't remember yesterday's decisions.

Until now.

AutoMem MCP connects your AI to persistent memory powered by [AutoMem](https://github.com/verygoodplugins/automem) - a graph-vector memory service.

What You Get

🧠 Persistent Memory Across Sessions

  • AI remembers decisions, patterns, and context forever
  • Works across all MCP platforms
Read from source at commit 043ae5892870OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-automem -- npx -y @verygoodplugins/[email protected]
03

Exposed tools (28)

12 read · 14 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AutoMemreadPersistent AutoMem-backed graph memory for OpenClaw.
bad-token-401-abortswriteA 401 on the authed recall probe must abort before any write.
claude-existing-headlesswriteSibling client: headless existing-target install for Claude Code in settings mode (the scriptable alternative to the recommended plugin).
claude-plugin-autoinstallreadPlugin mode with
claude-plugin-fallbackreadPlugin mode with no
cloud-instapodsreadhosted cloud → InstaPods: provider select → no resolve paste → setup-page plan
cloud-otherreadhosted cloud → Other: provider select → paste URL + key up front
cloud-railwayreadhosted cloud → Railway (guided): provider select → no paste → provision plan
codex-existing-headlesswriteHeadless existing-target install for Codex against a healthy endpoint.
delete_memorydestructiveDelete a memory by ID (\
dry-run-no-writeswriteDry-run must produce a plan and change nothing.
endpoint-500-abortswriteA reachable-but-broken endpoint (500) must abort before any write.
existing-claude-pluginwriteexisting + Claude Code → plugin sub-prompt (manual step, no settings write)
existing-claude-settingsreadexisting + Claude Code → settings sub-prompt (writes settings.json)
existing-cursorreadexisting endpoint, full interactive: target select → URL → key → agents (cursor)
existing-grokreadexisting endpoint, full interactive: target -> URL -> key -> agents (grok, last in the list)
existing-nonereadzero-agent guard: empty multiselect -> explicit confirm -> review says no agents
grok-existing-headlesswriteHeadless existing-target install for Grok Build. Grok is deliberately absent from DEFAULT_AGENT_CLIENTS, so it is opt-in via --clients.
idempotent-reinstallwriteRunning the codex install twice must stay valid (no corruption on second pass).
localwritelocal docker: target → dir prompt → no agents (dry-run, no docker)
malformed-health-200-htmlreadEndpoint returns /health 200 with an HTML body (no JSON). Tests whether verify
no-agent-installwrite--no-agent-install writes only .env, no client integration files.
non-tty-no-yes-previewwriteNon-interactive without --yes/--dry-run must preview only and write nothing.
recall_memoryreadRecall memories from AutoMem in one of three modes. The mode is selected by which params you pass. **Mode 1 — ID fetch:** pass \
store_memorywriteStore memory in one of two modes — single-memory (set top-level \
uninstall-after-installdestructiveInstall codex via the real npx path, then
update_memorywriteUpdate an existing memory
website-bootstrap-install-shwriteThe real production entrypoint: website install.sh -> npx file:<tarball> install, headless.
04

Trust audit

BLOCKgrade D · trust 68/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (7 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/demo/hermes-demo-stack.override.yml:14
# Ports chosen to avoid the personal (:8001) and eval (:8031/:8041) stacks.
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/build-hermes-demos.mjs:334
console.log(`✓ Capture B sidecar verified (answer cites ${PROVABLE_FACT.token})`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/setup.ts:235
console.log(buildSummaryInstructions(endpoint, Boolean(apiKey)));
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/setup.ts:265
console.log(JSON.stringify(buildMcpConfigJson(endpoint, apiKey), null, 2));
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/cli/templates.ts:25
apiKey = 'your-auto-mem-api-key'
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_memory, uninstall-after-install
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.commitlintrc.cjs
.commitlintrc.cjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.git-blame-ignore-revs
.git-blame-ignore-revs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.json
.markdownlint.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/claude-code.ts:15
fileURLToPath(new URL('../../templates/claude-code', import.meta.url))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/codex.ts:20
fileURLToPath(new URL('../../templates/codex', import.meta.url))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/copilot.ts:71
fileURLToPath(new URL('../../templates/copilot', import.meta.url))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/copilot.ts:464
fileURLToPath(new URL('../../templates/COPILOT_INSTRUCTIONS_MEMORY_RULES.md', import.meta.url))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/cursor.ts:19
fileURLToPath(new URL('../../package.json', import.meta.url))
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
AGENTS.md:235
AUTOMEM_API_URL=http://127.0.0.1:8001
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
INSTALLATION.md:321
"AUTOMEM_API_URL": "http://127.0.0.1:8001"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
INSTALLATION.md:472
- **AutoMem API URL** — e.g. `http://127.0.0.1:8001` or your Railway URL. Leave empty to use `AUTOMEM_API_URL` from your environment; falls back to `http://127.0.0.1:8001`.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
INSTALLATION.md:500
"AUTOMEM_API_URL": "http://127.0.0.1:8001",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
INSTALLATION.md:677
"AUTOMEM_API_URL": "http://127.0.0.1:8001",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@inquirer/prompts, @modelcontextprotocol/sdk, dotenv, node-fetch, smol-toml, yaml, @commitlint/cli, @commitlint/config-conventional
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
tests/e2e/FINDINGS.md:119
>    relying on the bridge's `dotenv` to read `.env`. Avoids the secret, but is launch-cwd-fragile
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALLATION.md:1230
curl -fsSL https://openclaw.ai/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALLATION.md:1244
curl -fsSL https://automem.ai/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 043ae5892870full audit observations/trust-audit/mcp-server/verygoodplugins__automem.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07043ae5892870BLOCKD68first audit
06

Questions

What is the AutoMem MCP server?

MCP client for AutoMem — give Claude, Cursor, Codex, and other MCP tools durable graph+vector memory across conversations.

What tools does AutoMem expose?

28 in total: 12 read-only, 14 that write, and 2 that can delete or overwrite (delete_memory, uninstall-after-install). Every one is listed on this page with its risk.

Is AutoMem safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (68/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AutoMem need?

It reads AUTOMEM_API_KEY, AUTOMEM_API_TOKEN, AUTOMEM_RECALL_TOKEN_BUDGET, MOCK_EXPECT_TOKEN and RAILWAY_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AutoMem run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @verygoodplugins/mcp-automem at 0.16.0.

How current is this page?

The grade is for one exact copy of the source (043ae5892870), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement