Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

com.runmemento/memento

NPM · @PSRAGHUVEER/MEMENTO · SCANNED AUG 3

Local-first, LLM-agnostic memory layer for AI assistants.

+16 this week 34 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security65
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known high-severity CVE affects @hono/node-server 1.13.7, a direct dependency. A fixed version is available. View diagnostics → Fail
  • Runs a script at install time (postinstall) that we could not recognise. It may be perfectly ordinary, but we do not read the published tarball, so we cannot say what it does. View diagnostics → Partial
  • Only part of the dependency tree could be resolved (224 of 235), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency71
  • Repository check failed: the declared repository URL redirects; it must resolve directly. See how to fix → View diagnostics → Fail
  • Cryptographically verified build provenance (signed, bound to veerps57/memento). View diagnostics → Pass
  • Clear OSI-approved license (Apache-2.0).Pass
  • Actively maintained (last published 77 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability0
  • Schema quality not yet verified: our sandbox run of this package did not complete, so we have no schema to assess.Unverified
Stability & Change Management0
  • Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.Unverified
Tool Coverage0
  • Tool coverage not yet verified: our sandbox run of this package did not complete, so we have no tool definitions to assess.Unverified
Capabilities0
  • Protocol version not yet verified: our sandbox run of this package did not complete, so we never saw its MCP handshake.Unverified

Unverified: 4 categories

Categories scored 0 because our sandbox run of this package has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @psraghuveer/memento

# add to Claude Code
claude mcp add com-runmemento-memento -- npx -y @psraghuveer/memento
# add to Codex CLI
codex mcp add com-runmemento-memento -- npx -y @psraghuveer/memento
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-runmemento-memento": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@psraghuveer/memento"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-runmemento-memento --command npx --arg -y --arg @psraghuveer/memento
# ~/.hermes/config.yaml
mcp_servers:
  com-runmemento-memento:
    command: "npx"
    args: ["-y", "@psraghuveer/memento"]
// mcp.json
{
  "mcpServers": {
    "com-runmemento-memento": {
      "command": "npx",
      "args": [
        "-y",
        "@psraghuveer/memento"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 0
    • CVE-2025-62610 affects this package: high security
    • GHSA-f88m-g3jw-g9cj affects this package: high security
    • CVE-2026-47675 affects this package: high security
    • CVE-2026-47673 affects this package: high security
    • CVE-2026-59895 affects this package: high security
    • CVE-2025-71381 affects this package: high security
    • CVE-2026-29087 affects this package: high security
    • CVE-2026-59897 affects this package: high security
    • CVE-2026-24473 affects this package: high security
    • CVE-2026-47676 affects this package: high security
    • CVE-2026-24472 affects this package: high security
    • CVE-2026-22818 affects this package: high security
    • CVE-2026-33532 affects this package: high security
    • CVE-2026-56764 affects this package: high security
    • CVE-2026-56763 affects this package: high security
    • CVE-2026-44459 affects this package: high security
    • CVE-2026-24771 affects this package: high security
    • CVE-2026-29086 affects this package: high security
    • CVE-2026-29045 affects this package: high security
    • CVE-2026-39406 affects this package: high security
    • CVE-2026-24398 affects this package: high security
    • CVE-2026-39407 affects this package: high security
    • CVE-2025-59139 affects this package: high security
    • CVE-2026-54286 affects this package: high security
    • CVE-2026-47674 affects this package: high security
    • CVE-2026-39410 affects this package: high security
    • CVE-2026-54287 affects this package: high security
    • CVE-2026-56762 affects this package: high security
    • CVE-2026-29085 affects this package: high security
    • CVE-2026-44458 affects this package: high security
    • CVE-2026-54288 affects this package: high security
    • CVE-2026-44456 affects this package: high security
    • CVE-2026-39408 affects this package: high security
    • CVE-2026-54290 affects this package: high security
    • CVE-2026-44455 affects this package: high security
    • CVE-2026-44457 affects this package: high security
    • CVE-2026-44635 affects this package: high security
    • CVE-2026-22817 affects this package: high security
    • CVE-2026-56761 affects this package: high security
    • CVE-2026-39409 affects this package: high security
    • CVE-2026-54289 affects this package: high security
    • GHSA-frvp-7c67-39w9 affects this package: high security
  • 2 Aug 26 +34
    • CVE-2026-33532 affects this package: high security
    • CVE-2026-22818 affects this package: high security
    • GHSA-f88m-g3jw-g9cj affects this package: high security
    • CVE-2026-39407 affects this package: high security
    • CVE-2026-56764 affects this package: high security
    • CVE-2026-56763 affects this package: high security
    • CVE-2026-44459 affects this package: high security
    • CVE-2026-24771 affects this package: high security
    • CVE-2026-29086 affects this package: high security
    • CVE-2026-29045 affects this package: high security
    • CVE-2026-39406 affects this package: high security
    • CVE-2026-24398 affects this package: high security
    • CVE-2025-59139 affects this package: high security
    • CVE-2026-54286 affects this package: high security
    • CVE-2026-47674 affects this package: high security
    • CVE-2026-39410 affects this package: high security
    • CVE-2026-54287 affects this package: high security
    • CVE-2026-56762 affects this package: high security
    • CVE-2026-29085 affects this package: high security
    • CVE-2026-44458 affects this package: high security
    • CVE-2026-54288 affects this package: high security
    • CVE-2026-44456 affects this package: high security
    • CVE-2026-39408 affects this package: high security
    • CVE-2026-54290 affects this package: high security
    • CVE-2026-44455 affects this package: high security
    • CVE-2026-44457 affects this package: high security
    • CVE-2026-44635 affects this package: high security
    • CVE-2026-22817 affects this package: high security
    • CVE-2026-56761 affects this package: high security
    • CVE-2026-39409 affects this package: high security
    • CVE-2026-54289 affects this package: high security
    • GHSA-frvp-7c67-39w9 affects this package: high security
    • CVE-2026-47675 affects this package: high security
    • CVE-2026-24472 affects this package: high security
    • CVE-2026-47676 affects this package: high security
    • CVE-2026-24473 affects this package: high security
    • CVE-2026-59897 affects this package: high security
    • CVE-2026-29087 affects this package: high security
    • CVE-2025-71381 affects this package: high security
    • CVE-2026-59895 affects this package: high security
    • CVE-2026-47673 affects this package: high security
    • CVE-2025-62610 affects this package: high security
    • Known CVEs: unverified → fail security
    • Provenance: unverified → pass security
    • Install scripts: unverified → partial security
    • Malware scan: unverified → pass security
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • The scripts that run when this package is installed changed: postinstall security
    • The attested source repository moved: veerps57/memento security
    • License: unverified → pass functional
    • Maintenance: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
    • Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
    • Licence: Apache-2.0 functional
  • 1 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 −18
    • Malware scan: pass → unverified security
    • Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. functional
    • Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet. functional
  • 27 Jul 26 18

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/@psraghuveer/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
veerps57/memento
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/veerps57/memento/.github/workflows/release.yml@refs/heads/main
Rekor log index:
1561214721
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:09e8e19d253e280679123f2d9e590a962b0494dcd9274c2140dbe64b132137aed0036f9ea0b79fca617a102c0a7876f7ad7ddf944964dfd1377df458b
Discovery method:
attestation_endpoint
Install scripts 1 script
Hook Tier Command
postinstall unreviewed node ./scripts/postinstall.mjs
Vulnerabilities 42 findings
ID CVE Severity Vector Fix available
GHSA-92pp-h63x-v22m CVE-2026-39406 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-frvp-7c67-39w9 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-wc8c-qw6v-h7f6 CVE-2026-29087 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-26pp-8wgv-hjvm CVE-2026-56762 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-2gcr-mfcq-wcc3 CVE-2026-47676 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-3hrh-pfw6-9m5x CVE-2026-47675 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N yes
GHSA-3vhc-576x-3qv4 CVE-2026-22818 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N yes
GHSA-458j-xx4x-4375 CVE-2026-56761 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N yes
GHSA-5pq2-9x2x-5p6w CVE-2026-29086 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N yes
GHSA-69xw-7hcm-h432 CVE-2026-44455 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N yes
GHSA-6wqw-2p9w-4vw4 CVE-2026-24472 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-88fw-hqm2-52qc CVE-2026-54290 high CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N yes
GHSA-92vj-g62v-jqhh CVE-2025-59139 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-9r54-q6cx-xmh5 CVE-2026-24771 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N yes
GHSA-9vqf-7f2p-gf9v CVE-2026-44456 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-f577-qrjj-4474 CVE-2026-47673 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-f67f-6cw9-8mq4 CVE-2026-22817 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N yes
GHSA-gq3j-xvxp-8hrf CVE-2026-56764 low CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-hm8q-7f3q-5f36 CVE-2026-44459 low CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N yes
GHSA-j6c9-x7qj-28xf CVE-2026-54287 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N yes
GHSA-m732-5p4w-x69g CVE-2025-62610 high CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N yes
GHSA-p6xx-57qc-3wxr CVE-2026-29085 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-p77w-8qqv-26rm CVE-2026-44457 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-q5qw-h33p-qvwr CVE-2026-29045 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-q7jf-gf43-6x6p CVE-2025-71381 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N yes
GHSA-qp7p-654g-cw7p CVE-2026-44458 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N yes
GHSA-r354-f388-2fhh CVE-2026-24398 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-r5rp-j6wh-rvv4 CVE-2026-39410 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-rv63-4mwf-qqc2 CVE-2026-54288 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-v8w9-8mx6-g223 CVE-2026-56763 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-w332-q679-j88p CVE-2026-24473 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-w62v-xxxg-mg59 CVE-2026-59895 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N yes
GHSA-wgpf-jwqj-8h8p CVE-2026-54289 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-wmmm-f939-6g9c CVE-2026-39407 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-wwfh-h76j-fc44 CVE-2026-54286 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-xf4j-xp2r-rqqx CVE-2026-39408 medium yes
GHSA-xgm2-5f3f-mvvc CVE-2026-59897 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-xpcf-pg52-r92g CVE-2026-39409 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-xrhx-7g5j-rcj5 CVE-2026-47674 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N yes
GHSA-pv5w-4p9q-p3v2 CVE-2026-44635 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-f88m-g3jw-g9cj high yes
GHSA-48c2-rrv3-qjmp CVE-2026-33532 medium CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L yes
Dependencies 224 packages

224 packages in the resolved dependency tree · 218 deprecated · 74 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tools for package channels are captured by running the package in an isolated sandbox. The most recent sandbox run could not capture a tool list from this package.