Clean
npm · 3 files analyzed
@modelcontextprotocol/server-memory
No risky behavior detected.
View source ↗Environment variables (config / keys) 1
AI review
This is an official Anthropic MCP server for persistent memory via a local knowledge graph. No prompt injection, hidden instructions, data exfiltration, or deceptive tool descriptions were found. The only environment variable access is for a local file path configuration, which is expected and safe.
Model: deepseek-chat
Static findings
Environment variables (config / keys) · Reads environment variables (config / API keys)
low
dist/index.js:12
if (process.env.MEMORY_FILE_PATH) {
Scanning every extension your team installs?
Pro & Team add monitoring, private scans, and a CI gate for unsafe extensions.
MCPVet is a heuristic aid, not a security guarantee. A clean grade does not prove an extension is safe; always review code and instructions you don't trust.