This tutorial covers how to add the [Knowledge Graph Memory MCP Server](https://github.com/modelcontextprotocol/servers/tree/main/src/memory) as a Goose extension. This enables Goose to analyze relationships, detect patterns, and gain a deeper understanding of your data. The knowledge graph builds on the [memory extension](/docs/tutorials/memory-mcp) by mapping complex relationships between concepts and providing persistent memory across Goose sessions.
1. [Launch the installer](goose://extension?cmd=npx&arg=-y&arg=%40modelcontextprotocol%2Fserver-memory&id=knowledge_graph_memory&name=Knowledge%20Graph%20Memory&description=Graph-based%20memory%20system%20for%20persistent%20knowledge%20storage)
2. Press `Yes` to confirm the installation
3. Scroll to the top and click `Exit` from the upper left corner
In this example, I'll show you how Goose can become an intelligent security reviewer by using connected knowledge patterns to detect and analyze vulnerabilities. Goose will be able to understand the relationship between security issues, their impacts, and mitigations.
This means Goose doesn't just spot issues - it understands how vulnerabilities connect to real world impacts and can suggest comprehensive solutions.
### Step 1: Teach Goose About Security Patterns
#### Goose Prompt #1
```
goose, learn these security vulnerability patterns and their relationships:
1. SQL Injection relates to:
- Unvalidated database inputs
- Data theft risks
- Parameterized query solutions
2. XSS Vulnerabilities connect to:
- Unescaped user output
- Session hijacking risks
- Content sanitization fixes
3.Authentication Weaknesses link to:
- Session management
- Account compromise
- JWT-based solutions
```
#### Goose Output
```
I'll store this security knowledge in the Knowledge Graph Memory with proper entities and relationships
[.... Create Entities .....]
Now, let's create the relationships between these security concepts:
[.... Create Relations .....]
Let me verify what's been stored:
[... Read Graph ...]
I've now stored your security knowledge in the graph with:
1. Vulnerability Entities:
- SQL Injection (with observations about unvalidated inputs and data theft)
- XSS Vulnerabilities (with observations about unescaped output and session risks)
- Authentication Weaknesses (with observations about session management)
2. Solution Entities:
- Parameterized Queries
- Content Sanitization
- JWT Authentication
3. Connected Relationships:
- Vulnerabilities → their potential impacts
- Solutions → the vulnerabilities they mitigate
The knowledge is now structured in a way that I can:
- Trace vulnerability impact chains
- Identify appropriate solutions for each vulnerability
- Understand how different security issues are related
```
### Step 2: Use Connected Knowledge for Code Review
#### Goose Prompt # 2
```
Review this API endpoint for security issues:
```
```js
app.post('/api/login', (req, res) => {
const { username, password } = req.body;
const query = `SELECT * FROM users WHERE username = '${username}'`;
db.query(query, (err, result) => {
if (err) throw err;
if (result.length > 0) {
res.cookie('user', username);
res.json({ success: true });
}
});
});
```
#### Goose Output
```
I'll analyze this code using our connected knowledge graph to trace security vulnerabilities and their implications:
[.... Search Nodes ... Open Nodes ...]
Based on our knowledge graph analysis, I've found multiple critical security issues:
1. SQL Injection Vulnerability:
- Issue: Using string concatenation in query WHERE username = '${username}'
- Impact Chain: SQL Injection → Data Theft
- Risk Level: Critical
- Solution (from parameterized_queries): Use parameterized queries instead
2. Authentication Weakness:
- Issue: Using basic cookie-based session res.cookie('user', username)