@smallironman/mcp-memory-keeper
npm
v0.13.2-fork1
Source verified
Published by smallironman666 — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.
MCP server for persistent context management in AI coding assistants
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 0 = 100. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
✓ No adoption-risk deductions — minimal blast radius, verified enough, and fully inspected.
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In a packaging/dev/install script (shipped, but not the server runtime) (`dist/__tests__/e2e/issue33-reproduce.test.js:37`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: "@jest/globals"); const child_process_1 = require("child_process"); const fs = __importStar(require("fs")); const path =
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/__tests__/e2e/issue33-reproduce.test.js
In a packaging/dev/install script (shipped, but not the server runtime) (`dist/__tests__/e2e/server-e2e.test.js:37`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: "@jest/globals"); const child_process_1 = require("child_process"); const fs = __importStar(require("fs")); const path =
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/__tests__/e2e/server-e2e.test.js
In a packaging/dev/install script (shipped, but not the server runtime) (`dist/__tests__/integration/server-initialization.test.js:37`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: "@jest/globals"); const child_process_1 = require("child_process"); const fs = __importStar(require("fs")); const path =
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server dist/__tests__/integration/server-initialization.test.js
Each tool and what it can reach — statically extracted from the published source.
context_analyzeno sensitive capabilitycontext_batch_deleteno sensitive capabilitycontext_batch_saveno sensitive capabilitycontext_batch_updateno sensitive capabilitycontext_branch_sessionno sensitive capabilitycontext_cache_fileno sensitive capabilitycontext_channel_statsno sensitive capabilitycontext_checkpointno sensitive capabilitycontext_compressno sensitive capabilitycontext_delegateno sensitive capabilitycontext_diffno sensitive capabilitycontext_exportno sensitive capabilitycontext_file_changedno sensitive capabilitycontext_find_relatedno sensitive capabilitycontext_getno sensitive capabilitycontext_get_relatedno sensitive capabilitycontext_get_sharedno sensitive capabilitycontext_git_commitno sensitive capabilitycontext_hybrid_searchno sensitive capabilitycontext_importno sensitive capabilitycontext_integrate_toolno sensitive capabilitycontext_journal_entryno sensitive capabilitycontext_linkno sensitive capabilitycontext_list_channelsno sensitive capabilitycontext_merge_sessionsno sensitive capabilitycontext_prepare_compactionno sensitive capabilitycontext_reassign_channelno sensitive capabilitycontext_restore_checkpointno sensitive capabilitycontext_saveno sensitive capabilitycontext_searchno sensitive capabilitycontext_search_allno sensitive capabilitycontext_semantic_searchno sensitive capabilitycontext_session_listno sensitive capabilitycontext_session_startno sensitive capabilitycontext_set_project_dirno sensitive capabilitycontext_shareno sensitive capabilitycontext_statusno sensitive capabilitycontext_summarizeno sensitive capabilitycontext_timelineno sensitive capabilitycontext_visualizeno sensitive capabilitycontext_watchno sensitive capabilityDebug Loggingno sensitive capabilityDefault Sessionno sensitive capabilityEmergency Recovery Sessionno sensitive capabilityRecovery Sessionno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v0.13.2-fork1 latest |
A 100/100 | 3 | 1.13.0 | 2026-09-07 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @smallironman/mcp-memory-keeper --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 2 side by side →
FDA device & vehicle recall risk for AI agents: recall history, MAUDE trend, risk score.
Open-source MCP server exposing Agent402.Tools' catalog — 500+ strong: 400+ self-hostable tools + 100 multi-tool skill packs (security-audit, trend-analysis, structured-scrape, decode-blob, forecasting-bake-off) for AI agents — browser, web search & answe
Zero-dependency MCP server that gives AI agents a self-updating project memory in AGENTS.md. Returns merge instructions instead of mutating state, so every change is a reviewable diff.
MCP Apps UI resources and server helpers for n8n
MCP server providing comprehensive access to BookStack knowledge management system
MCP server for tracking achievements with STAR methodology