Atlas / MCP servers / yoloshii / ClawMem

ClawMemBLOCK

mcp/yoloshii/clawmem

On-device memory layer for AI agents. Claude Code, OpenClaw and Hermes. Hooks + MCP server + hybrid RAG search.

Verdict
BLOCK
Grade
F
Trust score
59 /100
Exposed tools
34 31r · 3w · 0d
Transport
stdio
License
MIT
Stars
211
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

On-device memory for Claude Code, OpenClaw, Hermes, and AI agents. Retrieval-augmented search, hooks, and an MCP server in a single local system. No API keys, no cloud dependencies.

ClawMem fuses recent research into a retrieval-augmented memory layer that agents actually use. The hybrid architecture combines QMD-derived multi-signal retrieval (BM25 + vector search + reciprocal rank fusion + query expansion + cross-encoder reranking), SAME-inspired composite scoring (recency decay, confidence, content-type half-lives, co-activation reinforcement), MAGMA-style intent classification with multi-graph traversal (semantic, temporal, and causal beam search), and A-MEM self-evolving memory notes that enrich documents with keywords, tags, and causal links between entries. Pattern extraction from Engram adds deduplication windows, frequency-based durability scoring, and temporal navigation.

Integrates via Claude Code hooks, an MCP server (works with any MCP-compatible client), a native OpenClaw plugin, or a Hermes Agent MemoryProvider plugin. All paths write to the same local SQLite vault. A decision captured during a Claude Code session shows up immediately when an OpenClaw or Hermes agent picks up the same project.

TypeScript on Bun. MIT License.

What It Does

ClawMem turns your markdown notes, project docs, and research dumps into persistent memory for AI coding agents. It automatically:

  • Surfaces relevant context on every prompt (context-surfacing hook)
  • Bootstraps sessions with your profile, latest handoff, recent decisions, and stale notes
  • **Captures decisions, preferences, milesto
Read from source at commit 445497ed7af3OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add clawmem-openclaw-plugin --env CLAWMEM_API_TOKEN=${CLAWMEM_API_TOKEN} --env CLAWMEM_DISABLE_FTS_BYPASS=${CLAWMEM_DISABLE_FTS_BYPASS} --env CLAWMEM_EMBED_API_KEY=${CLAWMEM_EMBED_API_KEY} --env CLAWMEM_LLM_API_KEY=${CLAWMEM_LLM_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "clawmem-openclaw-plugin": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CLAWMEM_API_TOKEN": "${CLAWMEM_API_TOKEN}",
        "CLAWMEM_DISABLE_FTS_BYPASS": "${CLAWMEM_DISABLE_FTS_BYPASS}",
        "CLAWMEM_EMBED_API_KEY": "${CLAWMEM_EMBED_API_KEY}",
        "CLAWMEM_LLM_API_KEY": "${CLAWMEM_LLM_API_KEY}"
      }
    }
  }
}
03

Exposed tools (34)

31 read · 3 write · 0 destructive.

ToolRiskDescription
ClawMemreadOn-device hybrid memory layer for OpenClaw — composite scoring, graph traversal, lifecycle management, and pre-emptive compaction state extraction
__IMPORTANTread
beads_syncwrite
build_graphsread
diary_readread
diary_writewrite
find_causal_linksread
find_similarread
getread
index_statsread
intent_searchread
kg_queryread
lifecycle_restoreread
lifecycle_statusread
lifecycle_sweepread
list_vaultsread
memory_evolution_statusread
memory_forgetread
memory_pinread
memory_rankread
memory_retrieveread
memory_snoozeread
memory_statsread
multi_getread
profileread
queryread
query_planread
reindexread
searchread
session_logread
statusread
timelineread
vault_syncwrite
vsearchread
04

Trust audit

BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (9 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SKILL.md:246
- **Stop-hook ranges keep coming back as `model unavailable` while the LLM server is up** → v0.41.0's observer prompt could pass the 4,096-token context the docs prescribe for the observer model, and 
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clawmem.ts:2411
console.log(token
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/clawmem.ts:3412
console.log(`precompact state via ${c.cyan}before_prompt_build${c.reset} when token usage approaches the`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/hermes/__init__.py:231
logger.debug("ClawMem REST %s %s failed: %s", method, path, _redact(str(e), token))
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/hermes/__init__.py:247
logger.debug("ClawMem REST %s %s failed: %s", method, path, _redact(str(e), token))
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/openclaw/index.ts:274
svcCtx.logger.warn(`clawmem: REST API not started: \`clawmem serve-token\` failed: ${got.problem}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/hermes/__init__.py:220
url = f"http://127.0.0.1:{port}{path}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/hermes/__init__.py:237
resp = client.get(f"http://127.0.0.1:{port}{path}", headers=headers)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/hermes/__init__.py:240
f"http://127.0.0.1:{port}{path}",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/openclaw/tools.ts:44
const url = `http://127.0.0.1:${cfg.servePort}${path}`;
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/eval-bypass-ab.ts:485
if (N.mrrA - N.mrrB < GATES.epsN) gateViolations.push(`N ΔMRR ${(N.mrrA - N.mrrB).toFixed(3)} < ${GATES.epsN}`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/eval-bypass-ab.ts:489
if (X.mrrA - X.mrrB < GATES.epsX) gateViolations.push(`X ΔMRR ${(X.mrrA - X.mrrB).toFixed(3)} < ${GATES.epsX}`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/eval-keyword-acceptance.ts:467
console.log(`  ΔMRR (B−A) combined = ${(mrrB - mrrA).toFixed(3)} (switch needs ≥ ${E5.switchMargin}) → ${cond.margin}`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
scripts/eval-keyword-acceptance.ts:542
console.log(`  G1 ΔMRR(P−B) eligible-combined = ${(mrr(elig, "rankP") - mrr(elig, "rankB")).toFixed(3)} (ship needs ≥ ${S516.g1MarginMrr}) → ${s516Cond.g1_marginMrr}`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/mcp.ts:1820
if (b.pinBoost !== 0) parts.push(`pinΔ ${round3(b.pinBoost)}`);
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/hooks/eval-vector-daemon.integration.test.ts:154
describe("daemon-backed hook replay-eval (codex t76)", () => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/recall-buffer.ts:26
return createHash("sha1")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
eval-bundles/judge-override-2026-08-01/tooling/capability-eval.ts:21
} from "../../../src/judge.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
eval-bundles/judge-override-2026-08-01/tooling/capability-eval.ts:25
} from "../../../src/hooks/decision-extractor.ts";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/eval/hook-run.ts:2731
const pkg = await import("../../package.json", { with: { type: "json" } }) as { default?: { version?: string } };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/eval/run.ts:83
const pkg = JSON.parse(readFileSync(new URL("../../package.json", import.meta.url), "utf8")) as { version?: string };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/openclaw/shell.ts:200
resolve(__dirname, "../../bin/clawmem"),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/guides/openclaw-plugin.md:192
openclaw config set plugins.entries.clawmem.config.gpuLlm http://127.0.0.1:8000
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, gray-matter, node-llama-cpp, sqlite-vec, yaml, zod, @types/bun, sqlite-vec-darwin-arm64
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:1041
- [Thoth](https://github.com/siddsachar/Thoth) — anti-contamination deductive synthesis, contradiction-aware + name-aware merge gates, post-import conversation fact extraction, quiet-window heavy main
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-06 · audit v0.4.1 · source sha 445497ed7af3full audit observations/trust-audit/mcp-server/yoloshii__clawmem.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06445497ed7af3BLOCKF59first audit
06

Questions

What is the ClawMem MCP server?

On-device memory layer for AI agents. Claude Code, OpenClaw and Hermes. Hooks + MCP server + hybrid RAG search.

What tools does ClawMem expose?

34 in total: 31 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ClawMem safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (59/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does ClawMem need?

It reads CLAWMEM_API_TOKEN, CLAWMEM_DISABLE_FTS_BYPASS, CLAWMEM_EMBED_API_KEY, CLAWMEM_LLM_API_KEY, CLAWMEM_LLM_CONTEXT_TOKENS and CLAWMEM_RERANK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ClawMem run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as clawmem-openclaw-plugin at 0.10.2.

How current is this page?

The grade is for one exact copy of the source (445497ed7af3), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement