On-device memory layer with retrieval-augmented search, hooks, and MCP server for AI agents to persist and recall context across sessions without cloud dependencies.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
yaml is vulnerable to Stack Overflow via deeply nested YAML collections
process.env. You'll be asked to provide them before it can run.CLAUDE_SESSION_IDCLAWMEM_API_TOKEN— secret ./bin/clawmem serve # with bearer token authCLAWMEM_CONFIG_DIRCLAWMEM_CONTRADICTION_POLICY— link v0.7.1. Merge-time contradiction gate policy. link inserts a new row + contradicts edge (default). supersede marks the old row status='inactive'.CLAWMEM_EMBED_API_KEY— jina_your-key-hereCLAWMEM_EMBED_DIMENSIONS— OpenAI https://api.openai.com text-embedding-3-small 1536 8K context, Matryoshka dimensions viaCLAWMEM_EMBED_MAX_CHARS— Note: Cloud providers handle their own context window limits — ClawMem skips client-side truncation when an API key is set. Local llama-server truncates at (default: 6000 chars).CLAWMEM_EMBED_MODEL— jina-embeddings-v5-text-smallCLAWMEM_EMBED_TPM_LIMIT— 100000 Tokens-per-minute limit for cloud embedding pacing. Match to your provider tier.CLAWMEM_EMBED_URL— export =http://gpu-host:8088CLAWMEM_ENABLE_AMEM— enabled A-MEM note construction + link generation during indexingCLAWMEM_FOCUS_ROOTCLAWMEM_HOOK_DEDUP_WINDOW_SECCLAWMEM_LLM_MODEL— export =qwen3CLAWMEM_LLM_NO_THINK— true Append /no_think to remote LLM prompts. Set to false for standard OpenAI models and other endpoints that reject or treat the Qwen-style suffix as literal prompt text.CLAWMEM_LLM_REASONING_EFFORTCLAWMEM_LLM_URL— export =http://gpu-host:8089CLAWMEM_MERGE_GUARD_DRY_RUN— false v0.7.1. When true, Phase 2 merge-safety rejections are logged but not enforced — use for calibration before enabling the gate.CLAWMEM_MERGE_SCORE_NORMAL— 0.93 v0.7.1. Phase 2 consolidation merge-safety threshold when candidate and existing anchors align. Merges above this normalized 3-gram cosine score are allowed.CLAWMEM_NO_LOCAL_MODELS— To prevent fallback and fail fast instead, set =true.CLAWMEM_NUDGE_INTERVALCLAWMEM_PRECOMPACT_PROXIMITY_RATIOCLAWMEM_PROFILE— balanced # speed balanced deepCLAWMEM_SESSION_FOCUSCLAWMEM_SESSION_IDCLAWMEM_STDIO_MODECLAWMEM_VAULTS— export ='{"work":"~/.cache/clawmem/work.sqlite","personal":"~/.cache/clawmem/personal.sqlite"}'INDEX_PATHNO_COLOR[](https://m8ven.ai/mcp/yoloshii-clawmem-1rj1jc)