Memento — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Memento (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
Aggregate score unchanged between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
<div align="center"> <img src="assets/memento-logo.svg" alt="Memento Logo" width="100%">
<h1>Memento</h1> <p><strong>The Autonomous Nervous System for AI Agents</strong></p>
Memento is a local-first, open-source MCP middleware that gives your AI agents (Cursor, Claude Desktop, Trae, etc.) persistent memory, proactive goal enforcement, and autonomous intelligence — all running on a zero-cost SQLite temporal graph with Reciprocal Rank Fusion (RRF) retrieval.
No cloud databases. No API calls for storage. Everything stays on your machine.
Built on SQLite FTS5 (full-text search) and cosine similarity (vector embeddings). Fuses keyword matches and semantic meaning via Reciprocal Rank Fusion. WAL-mode enabled for concurrency.
Keep your AI aligned with project objectives at three escalation levels:
Deterministic regex/tree-sitter rules that block anti-patterns at commit time and in the IDE. 100% deterministic — zero LLM hallucination risk during enforcement.
Background cognitive loop with four levels:
Each project gets its own .memento/ directory with an isolated SQLite database. No context bleeding between projects. Configure via MEMENTO_DIR or per-project .cursor/mcp.json.
Semantic entity-relationship graph on top of the Knowledge Graph. Track files, components, decisions, and their dependencies. Impact analysis shows what breaks when you change something.
Memento exposes 14 action-based tools via MCP. Each tool uses an action parameter instead of separate tools per operation:
| Tool | Actions | Purpose |
|---|---|---|
memento | (main router) | Primary proactive memory interface |
memento_project | set_state, get_state, delete_state, set_goals, list_goals, summary | Vision, milestones, blockers, goals |
memento_session | begin, resume, handoff, status, list | Session lifecycle and handoff |
memento_graph | add_entity, add_relation, query, impact, summary | Project Memory Graph |
memento_search | basic, advanced, explain | FTS, vNext pipeline, routing trace |
memento_remember | add, consolidate, share, evaluate, hit | Memory write operations |
memento_configure | enforcement, coercion, daemon, autonomy, consolidation_scheduler, kg_scheduler, dependency_tracker, superpowers, access | All configuration |
memento_cognitive | dream, align, warnings, tasks | Cognitive engine operations |
memento_health | status, health, memory, kg, quality, relevance, cache, explain | Diagnostics |
memento_coercion | list_presets, apply_preset, list_rules, add_rule, remove_rule, install_hooks | Active Coercion management |
memento_kg | extract, health, cross_workspace_stats | Knowledge Graph operations |
memento_notifications | configure, list, dismiss | Proactive notifications |
memento_audit_dependencies | (standalone) | Dependency audit |
memento_migrate_workspace_memories | (standalone) | Workspace memory migration |
pip install memento-mcpOr run without installing:
uvx memento-mcpAdd to your global mcp.json (e.g. ~/.cursor/mcp.json):
{
"mcpServers": {
"memento": {
"command": "memento-mcp",
"env": {
"OPENAI_API_KEY": "your-api-key",
"OPENAI_BASE_URL": "https://api.openai.com/v1",
"MEM0_MODEL": "openai/gpt-4o-mini"
}
}
}
}For per-project workspace isolation, add to .cursor/mcp.json in your project root:
{
"mcpServers": {
"memento": {
"command": "memento-mcp",
"env": {
"OPENAI_API_KEY": "your-api-key",
"OPENAI_BASE_URL": "https://api.openai.com/v1",
"MEM0_MODEL": "openai/gpt-4o-mini",
"MEMENTO_DIR": "${workspaceFolder}"
}
}
}
}Add .cursor/ to your .gitignore to avoid committing API keys.
memento-mcp --help
memento --help<details> <summary>Running without OpenAI (offline / testing)</summary>
Set MEMENTO_EMBEDDING_BACKEND=none to disable embeddings. Memento falls back to FTS5-only search — no API key needed.
MEMENTO_EMBEDDING_BACKEND=none memento-mcp</details>
| Variable | Default | Description |
|---|---|---|
OPENAI_API_KEY | — | Required for OpenAI embeddings and cognitive features |
OPENAI_BASE_URL | https://api.openai.com/v1 | OpenAI-compatible endpoint (e.g. OpenRouter) |
MEM0_MODEL | openai/gpt-4o-mini | LLM model for cognitive features |
MEM0_EMBEDDING_MODEL | text-embedding-3-small | Embeddings model |
MEMENTO_EMBEDDING_BACKEND | auto-detect | local (fastembed), openai, or none |
MEMENTO_DIR | cwd | Workspace root for .memento/ state |
MEMENTO_UI | 0 | Enable local web UI (1/true) |
MEMENTO_UI_PORT | 8089 | Local UI port |
MEMENTO_UI_AUTH_TOKEN | — | Auth token for local web UI |
MEMENTO_RULE_CONFIRMATION | true | Require confirmation before applying coercion rules |
MEMENTO_PROACTIVE_INJECT | 1 | Inject relevant memories on every tool call (0 to disable) |
MEMENTO_PROACTIVE_TOP_K | 3 | Number of memories to inject proactively |
MEMENTO_DECAY_SEMANTIC | 0.005 | Decay λ for semantic memories (~200d half-life) |
MEMENTO_DECAY_EPISODIC | 0.02 | Decay λ for episodic memories (~50d half-life) |
MEMENTO_DECAY_WORKING | 0.05 | Decay λ for working memories (~14d half-life) |
MEMENTO_WRITE_SEARCH_TRACE | 0 | Write last_search.json trace on every search (1 to enable) |
MEMENTO_HANDOFF_AUTO_CHECKPOINT_EVERY_N_EVENTS | 25 | Auto-checkpoint frequency |
MEMENTO_SHARED_KG_PATH | — | Path to a shared KG SQLite file (federation — multiple workspaces share one graph) |
MEMENTO_FEDERATION_SOCKET | — | Unix socket path for push notifications between agents (replaces 30s WAL polling) |
Memento works from the terminal too:
# Auto-capture git context as a memory
memento capture --auto
# Save a free-form note
memento capture --text "Resolved auth timeout by increasing JWT expiry"
# Search memories
memento search "how did I fix the promise bug"
# Show workspace status
memento statusMemento operates at two levels:
memento_configure)Example activation sequence:
memento_project(action="set_goals", goals=["Implement auth flow", "Refactor DB layer"])
memento_configure(action="enforcement", level="level2", enabled=true)
memento_configure(action="consolidation_scheduler", enabled=true, interval_minutes=30)
memento_configure(action="autonomy", level="active")Memento is released under the GNU Affero General Public License v3.0 (AGPL-3.0). If you modify Memento and offer it as a network service, you must release your modified source code under the same license.
See LICENSE for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.