
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
chainmemory-mcp
Advanced tools
Cross-model, cryptographically verifiable memory for Claude, ChatGPT, and any AI agent — own your AI's memory and carry it across every model. MCP server, 24 tools: remember, semantic recall, selective inject, Project Brain (verifiable project state), rol
Cross-model, cryptographically verifiable memory for Claude, ChatGPT, and any AI agent — own your AI's memory and carry it across every model.
ChainMemory MCP exposes the ChainMemory protocol to any AI agent that speaks the Model Context Protocol. Memories are encrypted at rest (AES-256-GCM, per-user), verifiable with Merkle proofs, and portable across ChatGPT, Claude, Gemini, Perplexity, and any other LLM. No vendor lock-in, ever.
get_project_state consolidates your atomic memories into a structured, versioned, verifiable project state (decisions, risks, constraints, metrics), and delivers active role contracts with it in a single callget_role_contract (read the contract), assume_role (open an audited Role Session), release_role (close with a summary)Visit https://faucet.chainmemory.ai. You receive an API key (aic_...) and a starter balance of AIC. ChainMemory collects no personal data — your key is your identity.
Edit your Claude Desktop config (~/Library/Application Support/Claude/claude_desktop_config.json on macOS, %APPDATA%\Claude\claude_desktop_config.json on Windows):
{
"mcpServers": {
"chainmemory": {
"command": "npx",
"args": ["-y", "chainmemory-mcp"],
"env": {
"CHAINMEMORY_API_KEY": "aic_your_key_here"
}
}
}
}
Restart Claude Desktop. The 24 tools are now available.
chainmemory_recallchainmemory_rememberget_project_state (Brain + active role contracts)assume_role (audited Role Session)| Tool | Description |
|---|---|
chainmemory_remember | Write a permanent encrypted memory. Auto-tagged by content. |
chainmemory_recall | Recall the user's recent memories (most recent first) |
list_memories_filtered | Filter by project tag and archived status |
update_memory_tags | Change tags on an existing memory |
archive_memory | Hide a memory from recall (reversible) |
unarchive_memory | Restore an archived memory |
| Tool | Description |
|---|---|
get_project_state | Consolidated, verifiable project state + active role contracts (state_hash, anchored on-chain) |
update_project_state | Propose structured ops (22-op grammar); server validates, builds, hashes, persists |
| Tool | Description |
|---|---|
get_role_contract | Read a role's contract: purpose, rules with checks and severity, working protocol |
assume_role | Open an audited Role Session under an active contract (pins contract + Brain hashes) |
release_role | Close a Role Session with a summary of work done and pending |
| Tool | Description |
|---|---|
list_projects | List the user's projects |
create_project | Create a custom project tag with optional auto-tag keywords |
delete_project | Delete a project tag |
list_project_templates | List built-in templates |
add_project_from_template | Instantiate a built-in template |
| Tool | Description |
|---|---|
chainmemory_stats | Network stats (AIs, memories, blocks, AIC supply) |
chainmemory_register | Register a new AI identity on-chain |
chainmemory_profile | Get an AI's profile and trust score |
chainmemory_seal | Seal a memory permanently (requires AICHAIN_KEY) |
| Tool | Description |
|---|---|
get_my_context | Portable verified context across all platforms |
| Tool | Description |
|---|---|
get_inject_balance | Check AIC balance |
inject_memories | Inject 1-50 memories into current chat context (0.001 AIC, optimistic) |
get_inject_history | History of inject operations |
| Var | Required | Description |
|---|---|---|
CHAINMEMORY_API_KEY | Yes | Your API key from the faucet |
CHAINMEMORY_API_BASE | No | Default https://api.chainmemory.ai |
AICHAIN_KEY | No | Wallet private key — only required by chainmemory_seal |
AICHAIN_RPC | No | Default https://rpc.chainmemory.ai — only for chainmemory_seal |
For most users only CHAINMEMORY_API_KEY is needed.
inject_memories with a list of IDsget_inject_history shows confirmation status┌─────────────────────────────────────────────────────────────┐
│ AI Agent (Claude Desktop, ChatGPT, any MCP client) │
└──────────────────┬──────────────────────────────────────────┘
│ MCP stdio
↓
┌─────────────────────────────────────────────────────────────┐
│ chainmemory-mcp v2.5 (this package) │
└──────────────────┬──────────────────────────────────────────┘
│ HTTPS + x-api-key
↓
┌─────────────────────────────────────────────────────────────┐
│ api.chainmemory.ai │
│ - per-user encryption at rest (AES-256-GCM) │
│ - Project Brain (deterministic builder + state_hash) │
│ - Role contracts + audited Role Sessions │
│ - SQLite + Merkle proofs │
└──────────────────┬──────────────────────────────────────────┘
│ JSON-RPC
↓
┌─────────────────────────────────────────────────────────────┐
│ ChainMemory L1 — Chain ID 202604 │
│ - Geth PoA Clique, 3 validators │
│ - Memory contract + daily checkpoint anchoring │
│ - Project State anchoring (public verification) │
└─────────────────────────────────────────────────────────────┘
MIT
FAQs
Cross-model, cryptographically verifiable memory for Claude, ChatGPT, and any AI agent — own your AI's memory and carry it across every model. MCP server, 36 tools: remember, semantic search, on-chain verification proofs, forensic audit, selective inject,
The npm package chainmemory-mcp receives a total of 489 weekly downloads. As such, chainmemory-mcp popularity was classified as not popular.
We found that chainmemory-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.