Store memory in the hierarchical memory system (local SQLite)
AI agents use th0th_remember to create or update resources in Th0th — usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Th0th environment.
This tool writes data to a local SQLite database. It creates/modifies persistent records, which is reversible (data can be deleted later). No code execution, financial operations, or irreversible destruction is implied. Severity is medium because an AI agent could store misleading or sensitive information persistently across sessions.
From the tool's definition Store memory in the hierarchical memory system (local SQLite)
Documented attack patterns abuse exactly the kind of access th0th_remember gives an agent:
PolicyLayer is an MCP gateway — it sits between your AI agents and Th0th, and nothing reaches the server without passing your rules. This is the rule we recommend for th0th_remember:
{
"version": "1",
"default": "deny",
"tools": {
"th0th_remember": {
"limits": [
{
"counter": "th0th_remember_rate",
"window": "minute",
"max": 30,
"scope": "grant"
}
]
}
}
} th0th_remember stays usable, but capped — an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
Free to start. No card required.
Store memory in the hierarchical memory system (local SQLite). It is categorised as a Write tool in the Th0th MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Th0th MCP server in PolicyLayer and add a rule for th0th_remember: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Th0th. Nothing to install.
th0th_remember is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the th0th_remember rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for th0th_remember. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
th0th_remember is provided by the Th0th MCP server (s1lv4/th0th). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
Deterministic rules across all 21 Th0th tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.
Free to start. No card required.
21 Th0th tools catalogued and risk-classified — across an index of 42,500+ MCP servers.