Enables AI agents to maintain persistent, local memory with retrieval-augmented search, knowledge graphs, and context surfacing, without any cloud dependencies.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
process.env. You'll be asked to provide them before it can run.CLAUDE_SESSION_IDCLAWMEM_API_TOKEN— secret ./bin/clawmem serve # with bearer token authCLAWMEM_CONFIG_DIRCLAWMEM_CONTRADICTION_POLICY— link v0.7.1. Merge-time contradiction gate policy. link inserts a new row + contradicts edge (default). supersede marks the old row status='inactive'.CLAWMEM_EMBED_API_KEY— (none) API key for cloud embedding. Enables cloud mode: batch embedding, provider-specific params, TPM-aware pacing.CLAWMEM_EMBED_DIMENSIONS— (none) Output dimensions for OpenAI text-embedding-3- Matryoshka models (e.g. 512, 1024).CLAWMEM_EMBED_MAX_CHARSCLAWMEM_EMBED_MODEL— embedding Model name for embedding requests. Override for cloud providers (e.g. jina-embeddings-v5-text-small).CLAWMEM_EMBED_TPM_LIMIT— 100000 Tokens-per-minute limit for cloud embedding pacing. Match to your provider tier.CLAWMEM_EMBED_URLCLAWMEM_FOCUS_ROOTCLAWMEM_LLM_API_KEYCLAWMEM_LLM_MODEL— qwen3 Model name sent to the configured LLM endpoint. Override this for OpenAI-compatible proxies such as gpt-5.4-mini.CLAWMEM_LLM_NO_THINK— true Append /no_think to remote LLM prompts. Set to false for standard OpenAI models and other endpoints that reject or treat the Qwen-style suffix as literal prompt text.CLAWMEM_LLM_REASONING_EFFORTCLAWMEM_LLM_URLCLAWMEM_MERGE_GUARD_DRY_RUN— false v0.7.1. When true, Phase 2 merge-safety rejections are logged but not enforced — use for calibration before enabling the gate.CLAWMEM_NO_LOCAL_MODELS— false Block node-llama-cpp from auto-downloading GGUF models. Set true for remote-only setups where you want fail-fast on unreachable endpoints.CLAWMEM_NUDGE_INTERVALCLAWMEM_PRECOMPACT_PROXIMITY_RATIOCLAWMEM_PROFILE— balanced # speed balanced deepCLAWMEM_SESSION_FOCUSCLAWMEM_SESSION_IDCLAWMEM_STDIO_MODECLAWMEM_VAULTS— export ='{"work":"~/.cache/clawmem/work.sqlite","personal":"~/.cache/clawmem/personal.sqlite"}'NO_COLORZR_SRCZR_OUTZR_MAXLENZR_VERIFY_ONLYZR_TEMPZR_PORTCLAWMEM_BIN— /path/to/clawmem # Path to clawmem binary (or ensure it's on PATH)CLAWMEM_SERVE_PORT— 7438 # REST API port (default: 7438)CLAWMEM_SERVE_MODE— external # "external" (you run clawmem serve) or "managed" (plugin manages it)[](https://m8ven.ai/mcp/bflabsai-clawmem-bf-ln3oia)