Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add mcp/novasplace/csm/cross-session-memory-bridgegit clone --depth 1 https://github.com/NovasPlace/CSMWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/mcp/novasplace/csm/cross-session-memory-bridge)<a href="https://agentmods.dev/mcp/novasplace/csm/cross-session-memory-bridge"><img src="https://agentmods.dev/badge/mcp/novasplace/csm/cross-session-memory-bridge.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
cross-session-memory-bridge scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"cross-session-memory-bridge": {
"cwd": ".",
"command": "node",
"args": [
"./runtime/launch-mcp.mjs"
],
"env": {
"CSM_DATABASE_PROVIDER": "postgres",
"CSM_REQUIRE_EXPLICIT_DATABASE_URL": "true"
},
"env_vars": [
"CSM_DATABASE_URL",
"CSM_DB_TLS_MODE",
"CSM_EMBEDDING_PROVIDER",
"CSM_EMBEDDING_DIMENSIONS",
"OLLAMA_HOST",
"OPENAI_API_KEY"
]
}
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 21 lines scan A 61e939e105be
cross-session-memory-bridge is an MCP server published in the GitHub repository NovasPlace/CSM (42 stars, last pushed 2d ago), licensed MIT. Its token cost is not measured: an MCP server costs its tool schemas, not its config file. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other mcp servers, from other repositories
dark-memory-mcp
Persistent memory + vibe-loop engine for AI agents. Single Go binary, SQLite-backed, stdio MCP. Runs locally from the @opitacode/dark-memory-mcp npm package.
KIP
Knowledge Graphs to enable memory persistence, knowledge evolution, explainable interaction. Runs locally from the @ldclabs/kip-mcp-server npm package. Needs 2 environment variables to run.
knowl
Governed project memory for AI coding agents. Local-first, typed knowledge atoms over MCP, with stale decisions retired instead of accumulated. Runs locally from the @dat999zx/knowl npm package.
synapse-secure-memory
Persistent memory infrastructure for AI agents — AES-256-GCM encrypted at rest, semantic search, MCP-native. Runs locally from the synapse-layer Python package. Needs 4 environment variables to run.
synapse-layer
Persistent memory infrastructure for AI agents — AES-256-GCM encrypted at rest, semantic search, MCP-native. Runs locally from the synapse-layer Python package. Needs 3 environment variables to run.
adam-framework
MCP server that exposes Adam Framework vault memory as tools for Claude Desktop, Cursor, and any MCP-compatible client. Runs locally from the adam-mcp Python package. Needs 1 environment variable to run.