AgentMemorySAFE
Eliminate AI hallucinations. Zero config. Works instantly with Cline, RooCode, KiloCode, and more.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Hybrid Memory System for AI Coding Agents
Seamlessly integrate with KiloCode, Cline, and RooCode's built-in memory banks while providing powerful search, analytics, and automation.
[](https://marketplace.visualstudio.com/) [](https://marketplace.visualstudio.com/)
🚀 Now Available as an Antigravity Skill!
agentMemory is now fully compatible with Antigravity. Use it as a skill to give your agents persistent, searchable memory that syncs with your project documentation.
See SKILL.md for usage instructions.
🎯 What Makes agentMemory Different?
KiloCode, Cline, and RooCode already have memory banks - but they're manual and limited.
Their Built-In Memory Banks
.kilocode/rules/memory-bank/ ← Markdown files .clinerules/memory-bank/ ← Manually updated .roo/memory-bank/ ← No search capability
The Problem with Native Memory Banks:
- ❌ Manual Maintenance: Agents must manually rewrite files to update memory.
- ❌ No Search: Agents must read entire files to find specific information.
- ❌ No Analytics: No way to track memory growth or patterns over time.
- ❌ Isolated: Memories are locked to a single project.
✅ The Solution: agentMemory
agentMemory fixes these limitations by upgrading your memory bank with:
.agentMemory/ ← Our structured database ├── Bi-directional sync ← Keeps their markdown updated ├── Powerful search ← Query by type, tags, content ├── Visual dashboard ← See trends and analytics └── MCP tools ← Programmatic access for AI
Benefits:
- ✅ Automatic sync - No manual "update memory bank" needed
- ✅ Searchable - Find memories by query, ty
2a9252dab7a8OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add agentmemory -- npx -y [email protected]
{
"mcpServers": {
"agentmemory": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (7)
5 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
memory_list | read | List all memories of a specific type |
memory_read | read | Read memory by exact key |
memory_search | read | Search memories by keyword, tags, or type |
memory_stats | read | Get storage and cache statistics |
memory_update | write | Update existing memory |
memory_write | write | Store new memory in the memory bank |
project_init | read | Initialize project storage |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
.vscodeignore
@types/uuid, fastify, keyv, keyv-file, level, lru-cache, msgpack-lite, uuid
- `full` - Full access (read, write, update, delete)
Gates applied: no_behavioural_pass.
2a9252dab7a8full audit observations/trust-audit/mcp-server/webzler__agentmemory.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2a9252dab7a8 | SAFE | B | 89 | first audit |
Questions
What is the AgentMemory MCP server?
Eliminate AI hallucinations. Zero config. Works instantly with Cline, RooCode, KiloCode, and more.
What tools does AgentMemory expose?
7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is AgentMemory safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does AgentMemory need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (2a9252dab7a8), read on 2026-10-08. The repository is watched and re-audited when it changes.