Back to Browse

Engrava MCP Server

Developer ToolsModerate5.7MCP RegistryLocal
Free

Server data from the Official MCP Registry

MindQL queries, hybrid search, and a thought graph - read/write memory for AI agents.

About

MindQL queries, hybrid search, and a thought graph - read/write memory for AI agents.

Security Report

5.7
Moderate5.7Moderate Risk

Engrava MCP is a well-engineered, security-conscious server that exposes an agent memory database over stdio. Authentication is handled through the underlying Engrava library's store configuration (API keys via environment variables); the server itself enforces proper scoping with read-only mode support and comprehensive input validation. Code quality is excellent with strict type checking, proper error handling, and no obvious malicious patterns. Minor findings relate to error message details and permission scope verification, but these do not meaningfully impact security posture. Supply chain analysis found 2 known vulnerabilities in dependencies (1 critical, 0 high severity). Package verification found 1 issue.

3 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

What You'll Need

Set these up before or after installing:

Absolute path to the SQLite database file. Created if missing; its directory must exist. Enough on its own: full-text search, the graph and MindQL work, but vector search needs ENGRAVA_MCP_CONFIG.Optional

Environment variable: ENGRAVA_DB_PATH

Absolute path to an engrava.yaml, for an embedding provider (vector search) and the thought/edge journal. When set, it takes precedence and ENGRAVA_DB_PATH is not read.Optional

Environment variable: ENGRAVA_MCP_CONFIG

Set to true to register no write tools.Optional

Environment variable: ENGRAVA_MCP_READ_ONLY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "ai-sovantica-engrava": {
      "env": {
        "ENGRAVA_DB_PATH": "your-engrava-db-path-here",
        "ENGRAVA_MCP_CONFIG": "your-engrava-mcp-config-here",
        "ENGRAVA_MCP_READ_ONLY": "your-engrava-mcp-read-only-here"
      },
      "args": [
        "engrava-mcp"
      ],
      "command": "uvx"
    }
  }
}

Reviews

No reviews yet

Be the first to review this server!