MCP servers that give assistants persistent memory, knowledge graphs and structured reasoning. Each entry is scanned with the deterministic Capability-Flow Trust Model — grades are computed, never self-reported.
Security scan results for the Session Manager MCP server.
The official structured-reasoning server: break problems into revisable thought sequences.
The official knowledge-graph memory server: persistent entities, relations and observations.
Security scan results for the Apps MCP server.
Security scan results for the Bitbucket MCP server.
Security scan results for the Serper Search Scrape MCP server.
Security scan results for the Genkit Ai MCP server.
Memory server that stores knowledge in a Neo4j graph database backend.
Security scan results for the Velixar MCP server.
Security scan results for the Mcpscraper Memory Db MCP server.
Local memory service for coding copilot agents.
Security scan results for the Ua MCP server.
Security scan results for the Teams MCP server.
Security scan results for the Mikrotik MCP server.
Security scan results for the Powerautomate MCP server.
Security scan results for the Mentedb MCP server.
Security scan results for the Paput MCP server.
Lightweight sequential-thinking scratchpad with optional validation of planned tool usage.
Security scan results for the Code Graph MCP server.
Local memory server backed by markdown and JSON files, synced via git.
Security scan results for the Genudo Mcp Client MCP server.
Security scan results for the Subgraph Registry MCP server.
Security scan results for the Memory Bank MCP server.
Security scan results for the Agent402 MCP server.
Servers in this category extend an AI assistant with state that outlives a single chat. Instead of forgetting everything when the session ends, the assistant writes to and reads from an external store through the Model Context Protocol. Typical backends include vector databases such as Chroma or Qdrant, graph stores like Neo4j, embedded SQLite, plain JSON or Markdown files on disk, and hosted memory layers such as Mem0 or Zep. A second group adds no storage at all: structured-reasoning servers give the model a scratchpad for step-by-step thinking, branching and revision. The full MCP Trust Registry lets you compare them side by side.
Memory pairs naturally with servers from the Databases and Productivity & Workflow categories, where the recalled context drives real queries and actions.
A memory store is a write path into every future conversation. If a malicious or compromised MCP server — or untrusted content the assistant summarizes into memory — plants a poisoned entry, that entry is replayed as trusted context indefinitely: persistent prompt injection. Memory files also accumulate exactly what attackers want, from internal plans to credentials mentioned in passing, and a server that combines memory with broad file or network access could quietly exfiltrate that entire history.
That is why each listing here carries a Trust Score: a deterministic engine reads the published npm or PyPI package, maps its capability blast radius and reports individual findings with evidence. The A-F grade is reproducible, involves no AI judgment and cannot be bought — the scoring model is documented in full.
It can be, when the memory MCP server has a narrow blast radius — local storage, no unnecessary network egress — and a strong Trust Score. Prefer servers whose stored data you can inspect and wipe. Treat everything written into memory as future prompt input, because that is exactly what it becomes.