
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@mnemodb/mcp
Advanced tools
MnemoDB memory engine as an MCP server: memory_recall, memory_remember, memory_review, memory_compact over human-readable .mem.md stores.
The MnemoDB memory engine as an MCP server. Gives any MCP client — Claude Code,
Cursor, Windsurf, Claude Desktop — persistent memory stored in human-readable,
git-diffable .mem.md files.
claude mcp add mnemodb -- npx -y @mnemodb/mcp@latest
CLAUDE.md and Claude's memory tool
already give agents memory. MnemoDB isn't a replacement — it's the structure
they don't provide: typed entries with lifecycle (TTL, supersession, compaction),
provenance and a trust model (tool-sourced memories are flagged untrusted and
can't override human instructions), portability across tools, and auditable
Markdown files you can git diff. Worth it when the agent maintains memory
itself over many sessions, or you work across more than one tool. Full rationale:
https://github.com/mnemodb/mnemodb
Eleven memory-semantic operations — things a plain memory folder can't do:
memory_boot — always-loaded context (preambles + pinned entries); call at session startmemory_list — list the whole store (no query needed); browse everythingmemory_recall — ranked retrieval for a query, with provenance + untrusted flagmemory_show — one entry in full: body, all metadata, lifecycle statusmemory_history — an entry's supersession lineage (what it replaced / what replaced it)memory_stats — the store's self-report: counts by type/scope/provenance, budget, stalenessmemory_remember — store a typed entry (dedup, provenance stamping, supersession)memory_forget — auditable soft-delete to the archive (recoverable; trust-gated)memory_pin — set an entry's load tier (always/auto/cold); guards against pinning untrusted contentmemory_review — stale entries, contradictions, budget statusmemory_compact — the vacuum pass (dry-run by default)claude mcp add mnemodb -- npx -y @mnemodb/mcp@latest
Or in .mcp.json at your project root:
{
"mcpServers": {
"mnemodb": { "command": "npx", "args": ["-y", "@mnemodb/mcp@latest"] }
}
}
The store is discovered at ./.memory (create one with npx @mnemodb/cli init),
or set MNEMO_STORE=/path/to/store. Then add a short instruction to CLAUDE.md
telling the agent to call memory_recall / memory_remember — see
https://github.com/mnemodb/mnemodb/blob/main/docs/USAGE.md
Everything written through memory_remember is stamped src: agent.
Tool-derived content is data, never instructions (spec §10), flagged untrusted
on recall so consuming agents don't obey it.
FAQs
MnemoDB memory engine as an MCP server: memory_recall, memory_remember, memory_review, memory_compact over human-readable .mem.md stores.
The npm package @mnemodb/mcp receives a total of 109 weekly downloads. As such, @mnemodb/mcp popularity was classified as not popular.
We found that @mnemodb/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.