2
/ 100
1 month ago
npm

kunickiaj/codemem

codemem MCP server

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Hardcoded credentials detected
28 live-looking API keys in source: 24 GitHub PAT (classic), 1 OpenAI API key, 1 OpenAI project key
🔐
You'll be asked for 1 credential: CODEMEM_SYNC_COORDINATOR_ADMIN_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCODEMEM_CLAUDE_HOOK_CONTEXT_DIR
configCODEMEM_CLAUDE_HOOK_FLUSH
configCODEMEM_CLAUDE_HOOK_FLUSH_ON_STOP
configCODEMEM_CLAUDE_HOOK_LOCK_DIR
configCODEMEM_CLAUDE_HOOK_SPOOL_DIR
configCODEMEM_CODEX_HOOK_HTTP_TIMEOUT_MS
configCODEMEM_CODEX_HOOK_LOCK_DIR
configCODEMEM_CODEX_HOOK_SPOOL_DIR
configCODEMEM_CONFIG1. explicit
configCODEMEM_DBSQLite database path
configCODEMEM_DEVICE_ID
configCODEMEM_EMBEDDING_DISABLED
configCODEMEM_EMBEDDING_MODEL
configCODEMEM_FILE_CONTEXT
configCODEMEM_FILE_CONTEXT_MIN_BYTES
configCODEMEM_INJECT_CONTEXT0 to disable automatic context injection
configCODEMEM_INJECT_HTTP_FALLBACK
configCODEMEM_INJECT_HTTP_MAX_TIME_S
configCODEMEM_INJECT_LIMIT
configCODEMEM_INJECT_MAX_CHARS
configCODEMEM_INJECT_TOKEN_BUDGET
configCODEMEM_KEYS_DIR
configCODEMEM_PLUGIN_IGNORE
configCODEMEM_PLUGIN_LOG
configCODEMEM_PLUGIN_LOG_PATH
configCODEMEM_PROJECT
🔐 secretCODEMEM_SYNC_COORDINATOR_ADMIN_SECRET
configCODEMEM_SYNC_MDNS
configCODEMEM_SYNC_OPS_LIMIT
configCODEMEM_VIEWER_HOST, CODEMEM_VIEWER_PORT Host/port the plugin-managed viewer should start, probe, and restart
configCODEMEM_VIEWER_PORTCODEMEM_VIEWER_HOST, Host/port the plugin-managed viewer should start, probe, and restart
configCODEX_HOME
configSHELL
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 2 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/codemem-mcp-1vcsqb)](https://m8ven.ai/mcp/codemem-mcp-1vcsqb)
commit: ca0006d5d7e195a74ff7e9c4e11f6ebb43b100a9
code hash: 0ca2ca9ef4a29139b738694ee5746f40eaaac6c3dc24f5f6d2de35aa78130055
verified: 6/16/2026, 12:54:37 PM
view raw JSON →