0
/ 100
1 month ago
glama

MCP Memory Service - TypeScript

A cloud-based vector memory service that provides AI assistants with persistent storage, semantic search, and entity management via the Model Context Protocol. It features multi-tenant isolation and bidirectional synchronization with macOS and Google contacts and calendars.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 3 critical, 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 9 credentials: CLERK_PUBLISHABLE_KEY, CLERK_SECRET_KEY, CLERK_TOKEN, CLERK_WEBHOOK_SECRET, DATABASE_AUTH_TOKEN, GOOGLE_CLIENT_SECRET, OPENAI_API_KEY, TEST_TOKEN, TURSO_AUTH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 critical3 high3 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

critical@clerk/nextjs@6.33.1GHSA-vqx2-fgx2-5wq9

Official Clerk JavaScript SDKs: Middleware-based route protection bypass

criticalvitest@2.0.0GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

criticalvitest@2.0.0GHSA-9crc-q9x8-hgqq

Vitest allows Remote Code Execution when accessing a malicious website while Vitest API server is listening

high@clerk/backend@2.17.0GHSA-w24r-5266-9c3c

Clerk has an authorization bypass when combining organization, billing, or reverification checks

high@clerk/nextjs@6.33.1GHSA-w24r-5266-9c3c

Clerk has an authorization bypass when combining organization, billing, or reverification checks

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOW_DEV_AUTH
configAPI_URL
🔐 secretCLERK_PUBLISHABLE_KEY
🔐 secretCLERK_SECRET_KEYyour-clerk-secret-key
🔐 secretCLERK_TOKEN
🔐 secretCLERK_WEBHOOK_SECRET
configCORS_ORIGIN
🔐 secretDATABASE_AUTH_TOKEN
configDATABASE_URL
configDEFAULT_USER_EMAILuser@example.com
configEMBEDDING_MONITOR_INTERVAL60000 # Check every 60 seconds
configENABLE_EMBEDDING_MONITORtrue # Enable background monitoring
configGOOGLE_CLIENT_IDyour-google-client-id
🔐 secretGOOGLE_CLIENT_SECRETyour-google-client-secret
configGOOGLE_REDIRECT_URI
configHOST
configLOG_LEVEL📝 Smart Logging: -aware logging with state tracking (v1.7.1+)
configMCP_DEBUG0 # Set to 1 for detailed MCP protocol debugging
configMCP_DEFAULT_USER_EMAIL
configNEXT_PUBLIC_APP_URL
🔐 secretOPENAI_API_KEYyour-openai-api-key
configPORT
configRATE_LIMIT_REQUESTS_PER_MINUTE
configRATE_LIMIT_WINDOW_MS
configREMOTE_MCP_HOST
configREMOTE_MCP_PORT
configREMOTE_MCP_URL
🔐 secretTEST_TOKEN
🔐 secretTURSO_AUTH_TOKENyour-auth-token
configTURSO_SYNC_URL
configTURSO_URLlibsql://your-database.turso.io
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/bobmatnyc-mcp-memory-ts-yrdbu5)](https://m8ven.ai/mcp/bobmatnyc-mcp-memory-ts-yrdbu5)
commit: a04ead577ae9ed3342163e5d8266043205beccb5
code hash: 41fb120ea4146e412ec34a394845a2ffc2307f41efde9b0c1a6b419d42544103
verified: 6/13/2026, 10:34:20 AM
view raw JSON →