Shared, live team memory for Claude — a remote MCP server on Cloudflare Workers + D1
Memory MCP demonstrates solid tool design with clear naming conventions (memory_search, memory_get, memory_upsert, etc.), comprehensive parameter schemas using Zod validation, and thoughtful descriptions. All 7 tools follow verb_noun patterns. Input schemas are well-defined with type constraints, enums, and min/max bounds. However, output schemas are not formally documented, responses are JSON stringified without explicit field documentation. Error handling is present but minimal (e.g., 'not found: ${name}' lacks recovery guidance). Parameter descriptions are adequate but could be more prescriptive about constraints. The server correctly rejects secrets via looksLikeSecret() validation, showing security awareness.
Delete a memory (SOFT — reversible via memory_restore). The deletion is archived to history.
Fetch the full body of one memory by name.
Get a memory's version history (who changed/deleted what, when).
Get recently updated memories (what changed in the team mid-session). Lightweight list, no body.
Restore a soft-deleted memory by name.
Full-text search across the team's shared memory (accent/case-insensitive). Returns lightweight rows (name, description, type, status, author); use memory_get for the full body.
Output schemas not formally documented. Tools return JSON.stringify(results) without explicit field documentation. LLMs cannot reliably parse response structure or plan downstream calls.
Error messages lack recovery guidance. 'not found: ${name}' and 'deleted: ${name}' do not suggest next steps (e.g., 'Try memory_search() to find similar names').
Parameter descriptions lack explicit constraint documentation. E.g., 'Memory name (kebab-case)' should state 'Must match ^[a-z0-9-]+$ (lowercase letters, digits, hyphens only)' in the description text, not just the regex.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 71 | 2026-07-28+ | v2 |
Write/update a note in the team memory. One fact, short body. author is AUTOMATIC (from the token) — no parameter. DO NOT WRITE SECRETS — keys/tokens/passwords are rejected. The previous version is archived to history.
No pagination metadata returned. memory_search and memory_recent accept limit but do not return total_count or next_cursor, preventing agents from knowing if results are truncated.
Soft-delete and restore lack confirmation step. memory_delete is irreversible in practice (soft-delete can be overwritten). No dry-run or confirmation pattern to prevent accidental data loss.