
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
turbo-quant-memory
Advanced tools
Local-first MCP memory server for AI coding agents with compact retrieval and project/global scopes.
Your agent stops re-reading files and re-deriving the same conclusions.
Your notes, code and secrets never leave your machine.
A long session accumulates hard-won detail about why the code is the way it is. Then the context compacts and it is gone. Next session the agent re-reads the same files, re-derives the same conclusions, and bills you for the same tokens again.
CLAUDE.md does not scale past a few dozen lines, and it cannot answer "what did we decide about X, and why?".
Turbo Quant Memory is an MCP server that gives the agent a persistent, searchable store it writes to while it works — decisions, lessons, patterns, session handoffs — plus a compact index of your Markdown. Retrieval returns ~220-character result cards rather than whole documents; the agent loads full content only when a card is not enough.
| Turbo Quant Memory | mem0 / OpenMemory | MCP memory server | |
|---|---|---|---|
| Where your data lives | your disk, always | vendor cloud or self-host | your disk |
| Your data leaves the host | never | yes, unless self-hosted | never |
| Retrieval | hybrid BM25 + dense vector, RRF-fused | dense vector | exact graph lookup |
| What a search returns | compact cards, hydrate on demand | full memories | full nodes |
| Knowledge graph | yes — with lifecycle + linting | no | yes |
| Non-English content | Cyrillic exact-match out of the box | varies | n/a |
| Measures its own savings | yes — server_info() | no | no |
| Price | free, MIT | paid tiers | free |
No HTTP client, no telemetry, no phone-home. Verify it yourself — this returns nothing:
grep -rnE '^[[:space:]]*(import|from)[[:space:]]+(requests|httpx|aiohttp|urllib3)\b' src/
To be precise about the one exception: on first run fastembed downloads the embedding model (~0.22 GB) from Hugging Face. After that the server runs fully offline. Your notes, code and secrets are never transmitted anywhere — there is nothing in the package that could send them.
Paste this into Claude Code, Codex, Gemini CLI, Cursor or Antigravity:
Install and configure the Turbo Quant Memory MCP server for this workspace from https://github.com/Lexus2016/turbo_quant_memory — follow the README, register the
tqmemoryserver, runturbo-memory-mcp skill install, run the health check, and index this project.
skill install copies an operating manual into every agent skill directory on the machine, so every future session already knows how to use the memory without being told.
uv tool install turbo-quant-memory
Upgrading from 0.27.x or earlier? The distribution was renamed in 0.28.0, so
uv tool upgrade turbo-memory-mcp no longer resolves — run
uv tool install --force turbo-quant-memory once, and uv tool upgrade turbo-quant-memory afterwards. The turbo-memory-mcp command itself is
unchanged, so client configs keep working.
Then register the server with your client:
claude mcp add --scope project tqmemory -- turbo-memory-mcp serve # Claude Code
codex mcp add tqmemory -- turbo-memory-mcp serve # Codex
gemini mcp add tqmemory turbo-memory-mcp serve # Gemini CLI
Cursor, OpenCode, Antigravity and other clients → CLIENT_INTEGRATIONS.md. Hermes runs MCP through a systemd gateway → docs/hermes.md.
Turbo Quant Memory doesn't just claim to save tokens — every install keeps a running tally you can read anytime with server_info() (field usage_stats.headline). The savings are yours to verify, not ours to promise.
Live snapshot from a real developer instance (v0.28.2):
| What the memory did | Number |
|---|---|
| 🔢 Input tokens saved (cumulative) | ≈ 2,640,000 and counting |
| 🔁 Retrievals served | 2,280 searches + 280 deep hydrations |
| 📉 Average saved per retrieval | ≈ 1,200 tokens |
| 📚 Knowledge under management | 237 active notes + 763 indexed code blocks |
| 🛡️ Integrity | 0 corrupted records · 0 pending migrations |
These are one machine's cumulative numbers, not a synthetic benchmark — your own counter starts at zero and grows as your agent works. Run
server_info()on your install to see your real figure.
decision, lesson, pattern, handoff — each stored with tags, provenance and a knowledge-graph link to the file or issue it is about.durable (decisions, patterns) and reference (indexed docs) are searched by default; episodic (session handoffs) stays out of the way until you ask for it, so yesterday's noise never buries an architectural decision.human-explicit and ranks above the agent's own observations at equal relevance.Full technical detail → docs/features.md
| Group | Tools |
|---|---|
| Write | remember_note · deprecate_note · promote_note · index_paths |
| Read | semantic_search · hydrate · recent_context · list_scopes |
| Graph | link_entities · unlink_entities · get_related_entities |
| Hygiene | lint_knowledge_base · health · self_test · server_info |
| Vault | set_secret · get_secret · list_secrets · delete_secret |
| MEMORY_STRATEGY.md | How to actually use the memory day to day |
| CLIENT_INTEGRATIONS.md | Per-client setup: Cursor, OpenCode, Antigravity, … |
| TECHNICAL_SPEC.md | Architecture and storage format |
| docs/features.md | Retrieval, graph, tiers, embedder, FTS language |
| docs/secrets-vault.md | Vault setup, threat model, FAQ |
| docs/hermes.md | Hermes gateway setup and troubleshooting |
| CHANGELOG.md | Release history |
MIT. Copy it, modify it, fork it, ship it inside a closed-source product, sell it. Attribution is the only condition.
🇺🇸 English · 🇺🇦 Українська · 🇷🇺 Русский
FAQs
Local-first MCP memory server for AI coding agents with compact retrieval and project/global scopes.
We found that turbo-quant-memory demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.