io.github.basicmachines-co/basic-memory
Reviewed MCP Trust live-scan corpus candidate. Public meaning remains limited to controlled first-pass scan evidence and receipt caveats.
Automated danger grade: this page reports detected or inferred risk from a scan. It is not an endorsement, certification, or claim that the server is malicious.
Grade history
4 scans on record between 2026-07-03 and 2026-07-04. The grade has not changed across them.
| Scanned (UTC) | Grade | Engine | Attributed cause |
|---|---|---|---|
| 2026-07-03 13:58 | B | mcpaudit 2.4.0 | First scan on record |
| 2026-07-03 14:13 | B | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:17 | B | mcpaudit 2.4.0 | No change |
| 2026-07-04 08:17 | B | mcpaudit 2.4.0 | No change |
History as recorded by this registry's own scans. The cause is an attribution from the inputs the registry records — the scanner engine identity and the declared tool surface — not proof of what changed on the server. Generated 2026-08-02.
How to read this grade
- What was scanned: basic-memory, as distributed.
- When: 2026-07-04 08:17:59.
- By what: mcpaudit 2.4.0, applied to the published danger rubric (weights, bands, and the critical cap are all public).
- What the grade means: this registry's opinion, computed by the disclosed automated methodology against the artifact version above, on the scan date above. It measures conformance to the rubric at scan time.
- What it does not claim: it is not a statement that the product is malicious, insecure in your deployment, or unfit for use, and it is not an endorsement or certification.
- Disagree? Grades are re-checkable against the same package version, and corrections are welcome: open a dispute — see the dispute & correction policy.
Spec-shift exposure
BREAKS against MCP 2026-07-28-rc · confidence high · ruled 2026-07-18
| Dimension | Area | Verdict |
|---|---|---|
| D1 | Stateless-core compatibility | BREAKS |
| D2 | Deprecated-capability reliance | READY |
| D3 | Authorization posture | N_A |
| D4 | Schema and wire conformance | READY |
| D5 | Extensions readiness | NOTE |
What to change
- D1 [trivial] Pass stateless=True through to the stdio transport at src/basic_memory/cli/commands/mcp.py:118-120, i.e. mcp_server.run(transport=transport, stateless=True). FastMCP already forwards the kwarg to the SDK's ServerSession, and the server keeps its state in SQLite and the filesystem rather than in the protocol session, so nothing depends on the handshake. Separately retire the 'sse' transport option at mcp.py:28,121 per RC-D1-c.
This is a point-in-time ruling against a release candidate, not the published specification, and it is independent of the danger grade above. Neither figure constrains the other.
Provenance & dispute
- Listing basis: operator-listed from a public catalog. This entry was not submitted by its vendor.
- Scan target: the published pypi artifact
basic-memory, installed and scanned locally using sandbox imagemcp-trust-batch4:20260703. The public record stores the sandbox image, but not the network mode, so this page does not claim network isolation for that run. - Credentials: none declared, none used.
- Dispute: vendor or maintainer of this server? Dispute this grade — first response within 14 days.
Add this badge to your README
Copy the Markdown below only if you want to link readers to the latest danger grade and scan caveats:
[](https://mcp-trust.vercel.app/ui/servers/io-github-basicmachines-co-basic-memory-0-22-1)
Findings
| Severity | Rule | Title | Category | Detail |
|---|---|---|---|---|
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=true |
| high | MCP001 | File read capability | file_read | path; directory |
| high | MCP002 | File write capability | file_write | delete |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=true |
| medium | MCP001 | File read capability | file_read | directory |
| high | MCP002 | File write capability | file_write | write; overwrite; create |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| medium | MCP001 | File read capability | file_read | directory |
| medium | MCP002 | File write capability | file_write | create |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| medium | MCP002 | File write capability | file_write | append |
| high | MCP001 | File read capability | file_read | path; directory; folder |
| medium | MCP002 | File write capability | file_write | destination |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| high | MCP001 | File read capability | file_read | path; directory |
| high | MCP002 | File write capability | file_write | create; set |
| low | MCP005 | Destructive operation capability | destructive | destructiveHint=true |
| high | MCP002 | File write capability | file_write | delete |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
| low | MCP001 | File read capability | file_read | readOnlyHint=true |
Score breakdown
| Dimension | Raw (0–10) | Weight | Weighted |
|---|---|---|---|
| File access | 1.8 | ×1.2 | 2.16 |
| Network access | 0.0 | ×1.0 | 0.00 |
| Shell execution | 0.0 | ×2.0 | 0.00 |
| Destructive | 2.0 | ×0.3 | 0.60 |
| Exfiltration | 0.0 | ×0.4 | 0.00 |