Verifiable Memory — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Verifiable Memory (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<!-- mcp-name: io.github.Mars-proj/verifiable-memory -->
Memory for AI agents that cannot hallucinate. It answers only from stored facts — with the source cited — or it honestly says "I don't know." Every guarantee below is cryptographic or true by construction, not a prompt trick.
An MCP server + Python SDK. Plug it into any agent (Claude Desktop/Code, LangChain, custom). The LLM phrases; this layer guarantees the facts.
LLMs store knowledge in weights. So they hallucinate, can't cite, can't be edited, can't forget, can't be audited. That blocks agents from any high-stakes use — legal, finance, healthcare, compliance, autonomous workflows.
source.python3 benchmark.py)Stress-tested to 1,000,000 facts on a 7 GB CPU box, no GPU:
| Metric | verifiable-memory |
|---|---|
| Hallucination on adversarial traps | 0.0% |
| Accuracy when answered / citations | 100% / 100% |
| Query latency (p50 / p99) | 4.4 µs / 14 µs |
| Throughput | 137,000 q/s (16 threads) |
| Memory | ~1.2 GB for 1M facts (~1 KB/fact) |
| Provable forget | ✅ root reverts |
vs a naive "always answer" baseline: 0% vs 100% fabrication on the same traps.
pip install verifiable-memory-mcp
verifiable-memory # MCP server over stdio
# from source:
git clone https://github.com/Mars-proj/verifiable-memory && cd verifiable-memory
python3 -m vmem.server{
"mcpServers": {
"verifiable-memory": {
"command": "verifiable-memory",
"args": [],
"env": { "VMEM_STATE": "~/.verifiable_memory" }
}
}
}Then your agent can learn_fact, recall (cited or abstains), forget (provably), prove_fact, contradictions, multihop, and more — 13 tools.
Facts are stored as data (subject, relation, object + source), indexed for O(1) exact recall; answers are exact-match-or-abstain; the knowledge state commits to a Merkle root. No vectors needed for the verifiable path → 0 fabrication by construction.
This is a memory / trust layer, not a reasoning engine and not a better chatbot. It wins on verifiability (cite-or-abstain, forget, determinism, audit), not on open-ended fluency. Pair it with your LLM: LLM = language, this = ground truth.
Need a hosted API, on-prem deployment, or help integrating verifiable memory into your agent (legal / fintech / healthcare / agent platforms)? → Pilot & enterprise: Sergey · [email protected]
MIT licensed. PRs welcome.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.