89
/ 100
1 month ago
glama

memorix

Cross-agent memory bridge for AI coding assistants. Persistent knowledge graph shared across 10 IDEs (Cursor, Windsurf, Claude Code, Codex, Copilot, Kiro, Antigravity, OpenCode, Trae, Gemini CLI) via MCP. 22 tools including team collaboration, auto-cleanup, mini-skills, session management, and workspace sync. 100% local, zero API keys required.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 2 critical
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 7 credentials: ANTHROPIC_API_KEY, MEMORIX_AGENT_LLM_API_KEY, MEMORIX_API_KEY, MEMORIX_EMBEDDING_API_KEY, MEMORIX_LLM_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 critical2 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@3.0.0GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@3.0.0GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

lowdiff@7.0.0GHSA-73rr-hh4g-fpgx

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

lowjs-yaml@3.13.1GHSA-mh29-5h37-fv8m

js-yaml has prototype pollution in merge (<<)

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretANTHROPIC_API_KEY
configINIT_CWD
🔐 secretMEMORIX_AGENT_LLM_API_KEY
configMEMORIX_AGENT_LLM_BASE_URL
configMEMORIX_AGENT_LLM_MODEL
configMEMORIX_AGENT_LLM_PROVIDER
🔐 secretMEMORIX_API_KEY
configMEMORIX_AUDIT_FILE
configMEMORIX_AUTO_UPDATESafer Update Checks: Auto-update now defaults to notify-only; background install is explicit opt-in via =install.
configMEMORIX_AUTO_UPDATE_TIMEOUT_MS
configMEMORIX_DATA_DIR
configMEMORIX_EMBEDDING
🔐 secretMEMORIX_EMBEDDING_API_KEY
configMEMORIX_EMBEDDING_BASE_URL
configMEMORIX_EMBEDDING_DIMENSIONS
configMEMORIX_EMBEDDING_MODEL
configMEMORIX_FORMATION_HOOKS_SAMPLING_RATE
configMEMORIX_FORMATION_MODE
🔐 secretMEMORIX_LLM_API_KEY
configMEMORIX_LLM_BASE_URL
configMEMORIX_LLM_MODEL
configMEMORIX_LLM_PROVIDER
configMEMORIX_LLM_TIMEOUT_MS
configMEMORIX_MODE
configMEMORIX_PERF
configMEMORIX_PROJECT_ROOT
configMEMORIX_SESSION_TIMEOUT_MS86400000 memorix background start # 24h
🔐 secretOPENAI_API_KEY
🔐 secretOPENROUTER_API_KEY
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/avids2-memorix-sq9xn1)](https://m8ven.ai/mcp/avids2-memorix-sq9xn1)
commit: fd133ecd09e4c6f4306809bf13f2925907684d34
code hash: a50cbc3c918107f977e3daf65fb82945508722c737dd2a31b78e059c68c70138
verified: 6/12/2026, 10:56:04 AM
view raw JSON →