Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

com.runmemento/memento

NPM · @PSRAGHUVEER/MEMENTO · SCANNED SEP 28

Local-first, LLM-agnostic memory layer for AI assistants.

0 this week 37 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security74
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known high-severity CVE affects @hono/node-server 1.13.7, a direct dependency. A fixed version is available. View diagnostics → Fail
  • Declares code that runs automatically (postinstall) and that we could not recognise. It may be perfectly ordinary, but we have not established what it does. View diagnostics → Partial
  • 76 of 223 dependencies flagged as unhealthy (2 deprecated). View diagnostics → Partial
Provenance & Transparency74
  • Repository check failed: the declared repository URL redirects; it must resolve directly. See how to fix → View diagnostics → Fail
  • Cryptographically verified build provenance (signed, bound to veerps57/memento). View diagnostics → Pass
  • Clear OSI-approved license (Apache-2.0).Pass
  • Actively maintained (last published 133 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability0
  • Schema quality not yet verified: this server's registry entry declares environment variables (an API key or similar), and its server did not start in our sandbox, so we have no schema to assess.Unverified
Stability & Change Management0
  • Stability not yet verified: this server's registry entry declares environment variables (an API key or similar), and its server did not start in our sandbox, so we have no schema to compare.Unverified
Tool Coverage0
  • Tool coverage not yet verified: this server's registry entry declares environment variables (an API key or similar), and its server did not start in our sandbox, so we have no tool definitions to assess.Unverified
Tool Safety0
  • Tool safety not yet verified: this server's registry entry declares environment variables (an API key or similar), and its server did not start in our sandbox, so we have no tool text to scan.Unverified
Capabilities0
  • Protocol version not yet verified: this server's registry entry declares environment variables (an API key or similar), and its server did not start in our sandbox, so we never saw its MCP handshake.Unverified

Unverified: 5 categories

Categories scored 0 because our sandbox has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →

Install

How do I install the com.runmemento/memento MCP server?

com.runmemento/memento runs locally as an npm package, launched with npx -y @psraghuveer/memento. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @psraghuveer/memento

# add to Claude Code
claude mcp add com-runmemento-memento -- npx -y @psraghuveer/memento
// .cursor/mcp.json
{
  "mcpServers": {
    "com-runmemento-memento": {
      "command": "npx",
      "args": [
        "-y",
        "@psraghuveer/memento"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-runmemento-memento": {
      "command": "npx",
      "args": [
        "-y",
        "@psraghuveer/memento"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add com-runmemento-memento -- npx -y @psraghuveer/memento
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-runmemento-memento": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@psraghuveer/memento"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-runmemento-memento --command npx --arg -y --arg @psraghuveer/memento
# ~/.hermes/config.yaml
mcp_servers:
  com-runmemento-memento:
    command: "npx"
    args: ["-y", "@psraghuveer/memento"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-runmemento-memento": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@psraghuveer/memento"
      ]
    }
  }
}
# add to Vellum
assistant mcp add com-runmemento-memento -t stdio -c npx -a -y @psraghuveer/memento
// mcp.json
{
  "mcpServers": {
    "com-runmemento-memento": {
      "command": "npx",
      "args": [
        "-y",
        "@psraghuveer/memento"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • CVE-2026-47675 affects this package: high ▼ security
    • GHSA-frvp-7c67-39w9 affects this package: high ▼ security
    • CVE-2026-54289 affects this package: high ▼ security
    • CVE-2026-39409 affects this package: high ▼ security
    • CVE-2026-56761 affects this package: high ▼ security
    • CVE-2026-84363 affects this package: high ▼ security
    • CVE-2026-84364 affects this package: high ▼ security
    • CVE-2026-22817 affects this package: high ▼ security
    • CVE-2026-44635 affects this package: high ▼ security
    • CVE-2026-44457 affects this package: high ▼ security
    • CVE-2026-44455 affects this package: high ▼ security
    • CVE-2026-54290 affects this package: high ▼ security
    • CVE-2026-39408 affects this package: high ▼ security
    • CVE-2026-44456 affects this package: high ▼ security
    • CVE-2026-47676 affects this package: high ▼ security
    • GHSA-rgj7-g3m4-5g8c affects this package: high ▼ security
    • CVE-2026-69207 affects this package: high ▼ security
    • CVE-2026-54288 affects this package: high ▼ security
    • CVE-2026-44458 affects this package: high ▼ security
    • CVE-2026-29085 affects this package: high ▼ security
    • CVE-2026-56762 affects this package: high ▼ security
    • CVE-2026-54287 affects this package: high ▼ security
    • CVE-2026-39410 affects this package: high ▼ security
    • CVE-2026-54286 affects this package: high ▼ security
    • CVE-2025-59139 affects this package: high ▼ security
    • CVE-2026-71850 affects this package: high ▼ security
    • CVE-2026-39407 affects this package: high ▼ security
    • CVE-2026-24398 affects this package: high ▼ security
    • CVE-2026-39406 affects this package: high ▼ security
    • CVE-2026-24473 affects this package: high ▼ security
    • CVE-2026-59897 affects this package: high ▼ security
    • CVE-2026-29087 affects this package: high ▼ security
    • CVE-2025-71381 affects this package: high ▼ security
    • CVE-2026-59895 affects this package: high ▼ security
    • CVE-2026-47673 affects this package: high ▼ security
    • GHSA-f88m-g3jw-g9cj affects this package: high ▼ security
    • CVE-2025-62610 affects this package: high ▼ security
    • CVE-2026-33532 affects this package: high ▼ security
    • CVE-2026-22818 affects this package: high ▼ security
    • CVE-2026-84365 affects this package: high ▼ security
    • CVE-2026-47674 affects this package: high ▼ security
    • CVE-2026-24472 affects this package: high ▼ security
    • CVE-2026-29045 affects this package: high ▼ security
    • CVE-2026-29086 affects this package: high ▼ security
    • CVE-2026-24771 affects this package: high ▼ security
    • CVE-2026-44459 affects this package: high ▼ security
    • CVE-2026-56763 affects this package: high ▼ security
    • CVE-2026-56764 affects this package: high ▼ security
  • 26 Sept 26 0
    • CVE-2026-47674 affects this package: high ▼ security
    • CVE-2026-84365 affects this package: high ▼ security
    • CVE-2026-22818 affects this package: high ▼ security
    • CVE-2026-33532 affects this package: high ▼ security
    • CVE-2025-62610 affects this package: high ▼ security
    • GHSA-f88m-g3jw-g9cj affects this package: high ▼ security
    • CVE-2026-47673 affects this package: high ▼ security
    • CVE-2026-59895 affects this package: high ▼ security
    • CVE-2025-71381 affects this package: high ▼ security
    • CVE-2026-29087 affects this package: high ▼ security
    • CVE-2026-59897 affects this package: high ▼ security
    • CVE-2026-24473 affects this package: high ▼ security
    • CVE-2026-47676 affects this package: high ▼ security
    • CVE-2026-24472 affects this package: high ▼ security
    • CVE-2026-47675 affects this package: high ▼ security
    • GHSA-frvp-7c67-39w9 affects this package: high ▼ security
    • CVE-2026-54289 affects this package: high ▼ security
    • CVE-2026-39409 affects this package: high ▼ security
    • CVE-2026-56761 affects this package: high ▼ security
    • CVE-2026-84363 affects this package: high ▼ security
    • CVE-2026-84364 affects this package: high ▼ security
    • CVE-2026-22817 affects this package: high ▼ security
    • CVE-2026-44635 affects this package: high ▼ security
    • CVE-2026-44457 affects this package: high ▼ security
    • CVE-2026-44455 affects this package: high ▼ security
    • CVE-2026-54290 affects this package: high ▼ security
    • CVE-2026-39408 affects this package: high ▼ security
    • CVE-2026-44456 affects this package: high ▼ security
    • GHSA-rgj7-g3m4-5g8c affects this package: high ▼ security
    • CVE-2026-69207 affects this package: high ▼ security
    • CVE-2026-54288 affects this package: high ▼ security
    • CVE-2026-44458 affects this package: high ▼ security
    • CVE-2026-29085 affects this package: high ▼ security
    • CVE-2026-56762 affects this package: high ▼ security
    • CVE-2026-54287 affects this package: high ▼ security
    • CVE-2026-39410 affects this package: high ▼ security
    • CVE-2026-56764 affects this package: high ▼ security
    • CVE-2026-54286 affects this package: high ▼ security
    • CVE-2025-59139 affects this package: high ▼ security
    • CVE-2026-71850 affects this package: high ▼ security
    • CVE-2026-39407 affects this package: high ▼ security
    • CVE-2026-24398 affects this package: high ▼ security
    • CVE-2026-56763 affects this package: high ▼ security
    • CVE-2026-39406 affects this package: high ▼ security
    • CVE-2026-29045 affects this package: high ▼ security
    • CVE-2026-29086 affects this package: high ▼ security
    • CVE-2026-24771 affects this package: high ▼ security
    • CVE-2026-44459 affects this package: high ▼ security
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • CVE-2026-24473 affects this package: high ▼ security
    • CVE-2026-84365 affects this package: high ▼ security
    • CVE-2026-22818 affects this package: high ▼ security
    • CVE-2026-33532 affects this package: high ▼ security
    • CVE-2025-62610 affects this package: high ▼ security
    • GHSA-f88m-g3jw-g9cj affects this package: high ▼ security
    • CVE-2026-47673 affects this package: high ▼ security
    • CVE-2026-59895 affects this package: high ▼ security
    • CVE-2025-71381 affects this package: high ▼ security
    • CVE-2026-29087 affects this package: high ▼ security
    • CVE-2026-59897 affects this package: high ▼ security
    • CVE-2026-47676 affects this package: high ▼ security
    • CVE-2026-24472 affects this package: high ▼ security
    • CVE-2026-47675 affects this package: high ▼ security
    • GHSA-frvp-7c67-39w9 affects this package: high ▼ security
    • CVE-2026-54289 affects this package: high ▼ security
    • CVE-2026-39409 affects this package: high ▼ security
    • CVE-2026-56761 affects this package: high ▼ security
    • CVE-2026-84363 affects this package: high ▼ security
    • CVE-2026-84364 affects this package: high ▼ security
    • CVE-2026-22817 affects this package: high ▼ security
    • CVE-2026-44635 affects this package: high ▼ security
    • CVE-2026-44457 affects this package: high ▼ security
    • CVE-2026-44455 affects this package: high ▼ security
    • CVE-2026-54290 affects this package: high ▼ security
    • CVE-2026-39408 affects this package: high ▼ security
    • CVE-2026-44456 affects this package: high ▼ security
    • GHSA-rgj7-g3m4-5g8c affects this package: high ▼ security
    • CVE-2026-69207 affects this package: high ▼ security
    • CVE-2026-54288 affects this package: high ▼ security
    • CVE-2026-44458 affects this package: high ▼ security
    • CVE-2026-29085 affects this package: high ▼ security
    • CVE-2026-56762 affects this package: high ▼ security
    • CVE-2026-54287 affects this package: high ▼ security
    • CVE-2026-39410 affects this package: high ▼ security
    • CVE-2026-47674 affects this package: high ▼ security
    • CVE-2026-54286 affects this package: high ▼ security
    • CVE-2025-59139 affects this package: high ▼ security
    • CVE-2026-71850 affects this package: high ▼ security
    • CVE-2026-39407 affects this package: high ▼ security
    • CVE-2026-24398 affects this package: high ▼ security
    • CVE-2026-39406 affects this package: high ▼ security
    • CVE-2026-29045 affects this package: high ▼ security
    • CVE-2026-29086 affects this package: high ▼ security
    • CVE-2026-24771 affects this package: high ▼ security
    • CVE-2026-44459 affects this package: high ▼ security
    • CVE-2026-56763 affects this package: high ▼ security
    • CVE-2026-56764 affects this package: high ▼ security
  • 23 Sept 26 0
    • CVE-2026-56764 affects this package: high ▼ security
    • CVE-2026-84365 affects this package: high ▼ security
    • CVE-2026-22818 affects this package: high ▼ security
    • CVE-2026-33532 affects this package: high ▼ security
    • CVE-2025-62610 affects this package: high ▼ security
    • GHSA-f88m-g3jw-g9cj affects this package: high ▼ security
    • CVE-2026-47673 affects this package: high ▼ security
    • CVE-2026-59895 affects this package: high ▼ security
    • CVE-2025-71381 affects this package: high ▼ security
    • CVE-2026-29087 affects this package: high ▼ security
    • CVE-2026-59897 affects this package: high ▼ security
    • CVE-2026-24473 affects this package: high ▼ security
    • CVE-2026-47676 affects this package: high ▼ security
    • CVE-2026-24472 affects this package: high ▼ security
    • CVE-2026-47675 affects this package: high ▼ security
    • GHSA-frvp-7c67-39w9 affects this package: high ▼ security
    • CVE-2026-54289 affects this package: high ▼ security
    • CVE-2026-39409 affects this package: high ▼ security
    • CVE-2026-56761 affects this package: high ▼ security
    • CVE-2026-84363 affects this package: high ▼ security
    • CVE-2026-84364 affects this package: high ▼ security
    • CVE-2026-22817 affects this package: high ▼ security
    • CVE-2026-44635 affects this package: high ▼ security
    • CVE-2026-44457 affects this package: high ▼ security
    • CVE-2026-44455 affects this package: high ▼ security
    • CVE-2026-54290 affects this package: high ▼ security
    • CVE-2026-39408 affects this package: high ▼ security
    • CVE-2026-44456 affects this package: high ▼ security
    • GHSA-rgj7-g3m4-5g8c affects this package: high ▼ security
    • CVE-2026-69207 affects this package: high ▼ security
    • CVE-2026-54288 affects this package: high ▼ security
    • CVE-2026-44458 affects this package: high ▼ security
    • CVE-2026-29085 affects this package: high ▼ security
    • CVE-2026-56762 affects this package: high ▼ security
    • CVE-2026-54287 affects this package: high ▼ security
    • CVE-2026-39410 affects this package: high ▼ security
    • CVE-2026-47674 affects this package: high ▼ security
    • CVE-2026-54286 affects this package: high ▼ security
    • CVE-2025-59139 affects this package: high ▼ security
    • CVE-2026-71850 affects this package: high ▼ security
    • CVE-2026-39407 affects this package: high ▼ security
    • CVE-2026-24398 affects this package: high ▼ security
    • CVE-2026-39406 affects this package: high ▼ security
    • CVE-2026-29045 affects this package: high ▼ security
    • CVE-2026-29086 affects this package: high ▼ security
    • CVE-2026-24771 affects this package: high ▼ security
    • CVE-2026-44459 affects this package: high ▼ security
    • CVE-2026-56763 affects this package: high ▼ security
  • 22 Sept 26 0

    We did not load change detail this far back for this component, so this day may have recorded more than is shown.

    • CVE-2026-39406 affects this package: high ▼ security
    • CVE-2026-84365 affects this package: high ▼ security
    • CVE-2026-22818 affects this package: high ▼ security
    • CVE-2026-33532 affects this package: high ▼ security
    • CVE-2025-62610 affects this package: high ▼ security
    • GHSA-f88m-g3jw-g9cj affects this package: high ▼ security
  • 16 Sept 26 +1

    We did not load change detail this far back for this component, so this day may have recorded more than is shown.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Analysed npm/@psraghuveer/memento@0.9.2

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem npm
Reason Verified
Discovered via Registry attestation endpoint
Source repo veerps57/memento
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/veerps57/memento/.github/workflows/release.yml@refs/heads/main
Rekor log index 1561214721
Predicate type SLSA build provenance https://slsa.dev/provenance/v1
Subject digest sha512:09e8e19d253e280679123f2d9e590a962b0494dcd9274c2140dbe64b132137aed0036f9ea0b79fca617a102c0a7876f7ad7ddf944964dfd1377df458b

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
postinstall unreviewed node ./scripts/postinstall.mjs

Background: Why install scripts are a supply-chain risk →

Vulnerabilities 48 findings
ID CVE Severity Vector Fix available
GHSA-92pp-h63x-v22m CVE-2026-39406 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-frvp-7c67-39w9 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-wc8c-qw6v-h7f6 CVE-2026-29087 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-26pp-8wgv-hjvm CVE-2026-56762 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-2gcr-mfcq-wcc3 CVE-2026-47676 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-3hrh-pfw6-9m5x CVE-2026-47675 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N yes
GHSA-3vhc-576x-3qv4 CVE-2026-22818 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N yes
GHSA-458j-xx4x-4375 CVE-2026-56761 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N yes
GHSA-5pq2-9x2x-5p6w CVE-2026-29086 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N yes
GHSA-69xw-7hcm-h432 CVE-2026-44455 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N yes
GHSA-6wqw-2p9w-4vw4 CVE-2026-24472 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-88fw-hqm2-52qc CVE-2026-54290 high CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N yes
GHSA-8j4g-w8fx-2239 CVE-2026-69207 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-92vj-g62v-jqhh CVE-2025-59139 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-9r54-q6cx-xmh5 CVE-2026-24771 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N yes
GHSA-9vqf-7f2p-gf9v CVE-2026-44456 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-crvj-82cr-hjcx CVE-2026-84363 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N yes
GHSA-f23p-vx2j-j53r CVE-2026-71850 medium CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N yes
GHSA-f577-qrjj-4474 CVE-2026-47673 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-f67f-6cw9-8mq4 CVE-2026-22817 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N yes
GHSA-g6gw-c38x-mqfc CVE-2026-84364 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-gq3j-xvxp-8hrf CVE-2026-56764 low CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-gqvv-2mrq-wpjv CVE-2026-84365 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N yes
GHSA-hm8q-7f3q-5f36 CVE-2026-44459 low CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N yes
GHSA-j6c9-x7qj-28xf CVE-2026-54287 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N yes
GHSA-m732-5p4w-x69g CVE-2025-62610 high CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N yes
GHSA-p6xx-57qc-3wxr CVE-2026-29085 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-p77w-8qqv-26rm CVE-2026-44457 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-q5qw-h33p-qvwr CVE-2026-29045 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-q7jf-gf43-6x6p CVE-2025-71381 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N yes
GHSA-qp7p-654g-cw7p CVE-2026-44458 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N yes
GHSA-r354-f388-2fhh CVE-2026-24398 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-r5rp-j6wh-rvv4 CVE-2026-39410 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-rv63-4mwf-qqc2 CVE-2026-54288 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-v8w9-8mx6-g223 CVE-2026-56763 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-w332-q679-j88p CVE-2026-24473 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-w62v-xxxg-mg59 CVE-2026-59895 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N yes
GHSA-wgpf-jwqj-8h8p CVE-2026-54289 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-wmmm-f939-6g9c CVE-2026-39407 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-wwfh-h76j-fc44 CVE-2026-54286 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-xf4j-xp2r-rqqx CVE-2026-39408 medium yes
GHSA-xgm2-5f3f-mvvc CVE-2026-59897 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-xpcf-pg52-r92g CVE-2026-39409 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N yes
GHSA-xrhx-7g5j-rcj5 CVE-2026-47674 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N yes
GHSA-pv5w-4p9q-p3v2 CVE-2026-44635 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N yes
GHSA-f88m-g3jw-g9cj high yes
GHSA-rgj7-g3m4-5g8c high yes
GHSA-48c2-rrv3-qjmp CVE-2026-33532 medium CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L yes

Background: What a vulnerability scan can and cannot prove →

Dependencies 223 packages
Packages resolved 223
Deprecated 2
Stale 75
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tools for package channels are captured by running the package in an isolated sandbox. The most recent sandbox run could not capture a tool list from this package.

Common questions

What is the com.runmemento/memento MCP server?

com.runmemento/memento is an MCP server listed in the public MCP registry as com.runmemento/memento. Local-first, LLM-agnostic memory layer for AI assistants. This page covers its npm package (@psraghuveer/memento).

Is the com.runmemento/memento MCP server safe to use?

com.runmemento/memento scores 37 out of 100 on VerifyMCP. We recorded 48 known advisories against it as of 28 September 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

Is the com.runmemento/memento MCP server still maintained?

com.runmemento/memento is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the com.runmemento/memento MCP server under?

com.runmemento/memento declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.