ClawMemBLOCK
On-device memory layer for AI agents. Claude Code, OpenClaw and Hermes. Hooks + MCP server + hybrid RAG search.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
On-device memory for Claude Code, OpenClaw, Hermes, and AI agents. Retrieval-augmented search, hooks, and an MCP server in a single local system. No API keys, no cloud dependencies.
ClawMem fuses recent research into a retrieval-augmented memory layer that agents actually use. The hybrid architecture combines QMD-derived multi-signal retrieval (BM25 + vector search + reciprocal rank fusion + query expansion + cross-encoder reranking), SAME-inspired composite scoring (recency decay, confidence, content-type half-lives, co-activation reinforcement), MAGMA-style intent classification with multi-graph traversal (semantic, temporal, and causal beam search), and A-MEM self-evolving memory notes that enrich documents with keywords, tags, and causal links between entries. Pattern extraction from Engram adds deduplication windows, frequency-based durability scoring, and temporal navigation.
Integrates via Claude Code hooks, an MCP server (works with any MCP-compatible client), a native OpenClaw plugin, or a Hermes Agent MemoryProvider plugin. All paths write to the same local SQLite vault. A decision captured during a Claude Code session shows up immediately when an OpenClaw or Hermes agent picks up the same project.
TypeScript on Bun. MIT License.
What It Does
ClawMem turns your markdown notes, project docs, and research dumps into persistent memory for AI coding agents. It automatically:
- Surfaces relevant context on every prompt (context-surfacing hook)
- Bootstraps sessions with your profile, latest handoff, recent decisions, and stale notes
- **Captures decisions, preferences, milesto
445497ed7af3OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add clawmem-openclaw-plugin --env CLAWMEM_API_TOKEN=${CLAWMEM_API_TOKEN} --env CLAWMEM_DISABLE_FTS_BYPASS=${CLAWMEM_DISABLE_FTS_BYPASS} --env CLAWMEM_EMBED_API_KEY=${CLAWMEM_EMBED_API_KEY} --env CLAWMEM_LLM_API_KEY=${CLAWMEM_LLM_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"clawmem-openclaw-plugin": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"CLAWMEM_API_TOKEN": "${CLAWMEM_API_TOKEN}",
"CLAWMEM_DISABLE_FTS_BYPASS": "${CLAWMEM_DISABLE_FTS_BYPASS}",
"CLAWMEM_EMBED_API_KEY": "${CLAWMEM_EMBED_API_KEY}",
"CLAWMEM_LLM_API_KEY": "${CLAWMEM_LLM_API_KEY}"
}
}
}
}Exposed tools (34)
31 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ClawMem | read | On-device hybrid memory layer for OpenClaw — composite scoring, graph traversal, lifecycle management, and pre-emptive compaction state extraction |
__IMPORTANT | read | |
beads_sync | write | |
build_graphs | read | |
diary_read | read | |
diary_write | write | |
find_causal_links | read | |
find_similar | read | |
get | read | |
index_stats | read | |
intent_search | read | |
kg_query | read | |
lifecycle_restore | read | |
lifecycle_status | read | |
lifecycle_sweep | read | |
list_vaults | read | |
memory_evolution_status | read | |
memory_forget | read | |
memory_pin | read | |
memory_rank | read | |
memory_retrieve | read | |
memory_snooze | read | |
memory_stats | read | |
multi_get | read | |
profile | read | |
query | read | |
query_plan | read | |
reindex | read | |
search | read | |
session_log | read | |
status | read | |
timeline | read | |
vault_sync | write | |
vsearch | read |
Trust audit
BLOCKgrade F · trust 59/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
- **Stop-hook ranges keep coming back as `model unavailable` while the LLM server is up** → v0.41.0's observer prompt could pass the 4,096-token context the docs prescribe for the observer model, and
console.log(token
console.log(`precompact state via ${c.cyan}before_prompt_build${c.reset} when token usage approaches the`);logger.debug("ClawMem REST %s %s failed: %s", method, path, _redact(str(e), token))logger.debug("ClawMem REST %s %s failed: %s", method, path, _redact(str(e), token))svcCtx.logger.warn(`clawmem: REST API not started: \`clawmem serve-token\` failed: ${got.problem}`);url = f"http://127.0.0.1:{port}{path}"resp = client.get(f"http://127.0.0.1:{port}{path}", headers=headers)f"http://127.0.0.1:{port}{path}",const url = `http://127.0.0.1:${cfg.servePort}${path}`;if (N.mrrA - N.mrrB < GATES.epsN) gateViolations.push(`N ΔMRR ${(N.mrrA - N.mrrB).toFixed(3)} < ${GATES.epsN}`);if (X.mrrA - X.mrrB < GATES.epsX) gateViolations.push(`X ΔMRR ${(X.mrrA - X.mrrB).toFixed(3)} < ${GATES.epsX}`);console.log(` ΔMRR (B−A) combined = ${(mrrB - mrrA).toFixed(3)} (switch needs ≥ ${E5.switchMargin}) → ${cond.margin}`);console.log(` G1 ΔMRR(P−B) eligible-combined = ${(mrr(elig, "rankP") - mrr(elig, "rankB")).toFixed(3)} (ship needs ≥ ${S516.g1MarginMrr}) → ${s516Cond.g1_marginMrr}`);if (b.pinBoost !== 0) parts.push(`pinΔ ${round3(b.pinBoost)}`);describe("daemon-backed hook replay-eval (codex t76)", () => {return createHash("sha1")} from "../../../src/judge.ts";
} from "../../../src/hooks/decision-extractor.ts";
const pkg = await import("../../package.json", { with: { type: "json" } }) as { default?: { version?: string } };const pkg = JSON.parse(readFileSync(new URL("../../package.json", import.meta.url), "utf8")) as { version?: string };resolve(__dirname, "../../bin/clawmem"),
openclaw config set plugins.entries.clawmem.config.gpuLlm http://127.0.0.1:8000
@modelcontextprotocol/sdk, gray-matter, node-llama-cpp, sqlite-vec, yaml, zod, @types/bun, sqlite-vec-darwin-arm64
- [Thoth](https://github.com/siddsachar/Thoth) — anti-contamination deductive synthesis, contradiction-aware + name-aware merge gates, post-import conversation fact extraction, quiet-window heavy main
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
445497ed7af3full audit observations/trust-audit/mcp-server/yoloshii__clawmem.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 445497ed7af3 | BLOCK | F | 59 | first audit |
Questions
What is the ClawMem MCP server?
On-device memory layer for AI agents. Claude Code, OpenClaw and Hermes. Hooks + MCP server + hybrid RAG search.
What tools does ClawMem expose?
34 in total: 31 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ClawMem safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (59/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does ClawMem need?
It reads CLAWMEM_API_TOKEN, CLAWMEM_DISABLE_FTS_BYPASS, CLAWMEM_EMBED_API_KEY, CLAWMEM_LLM_API_KEY, CLAWMEM_LLM_CONTEXT_TOKENS and CLAWMEM_RERANK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ClawMem run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as clawmem-openclaw-plugin at 0.10.2.
How current is this page?
The grade is for one exact copy of the source (445497ed7af3), read on 2026-10-06. The repository is watched and re-audited when it changes.