Medium Risk

th0th_remember

Store memory in the hierarchical memory system (local SQLite)

How to control th0th_remember ↓

AI agents use th0th_remember to create or update resources in Th0th — usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Th0th environment.

Medium Risk

This tool writes data to a local SQLite database. It creates/modifies persistent records, which is reversible (data can be deleted later). No code execution, financial operations, or irreversible destruction is implied. Severity is medium because an AI agent could store misleading or sensitive information persistently across sessions.

From the tool's definition Store memory in the hierarchical memory system (local SQLite)

Documented attack patterns abuse exactly the kind of access th0th_remember gives an agent:

PolicyLayer is an MCP gateway — it sits between your AI agents and Th0th, and nothing reaches the server without passing your rules. This is the rule we recommend for th0th_remember:

policy.json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "th0th_remember": {
      "limits": [
        {
          "counter": "th0th_remember_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}

th0th_remember stays usable, but capped — an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.

  1. Create a free account and register Th0th — nothing to install.
  2. Add this policy — paste it, or build it visually.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
LIMIT THIS TOOL →

Free to start. No card required.

Go deeper

What does the th0th_remember tool do? +

Store memory in the hierarchical memory system (local SQLite). It is categorised as a Write tool in the Th0th MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.

How do I enforce a policy on th0th_remember? +

Register the Th0th MCP server in PolicyLayer and add a rule for th0th_remember: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Th0th. Nothing to install.

What risk level is th0th_remember? +

th0th_remember is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.

Can I rate-limit th0th_remember? +

Yes. Add a rate_limit block to the th0th_remember rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block th0th_remember completely? +

Set action: deny in the PolicyLayer policy for th0th_remember. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides th0th_remember? +

th0th_remember is provided by the Th0th MCP server (s1lv4/th0th). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Enforce policy on every Th0th tool call.

Deterministic rules across all 21 Th0th tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Free to start. No card required.

21 Th0th tools catalogued and risk-classified — across an index of 42,500+ MCP servers.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.