New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@easylabs/engram

Package Overview
Dependencies
Maintainers
1
Versions
29
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@easylabs/engram

Engram — persistent memory layers, knowledge graph, curator engine, policy gates, and provenance chain for AI agents.

Source
npmnpm
Version
3.3.0
Version published
Weekly downloads
16
433.33%
Maintainers
1
Weekly downloads
 
Created
Source

Engram

By Easy Labs

Persistent agent memory, mycelium-powered knowledge graph, safety hooks, code intelligence, provenance tracking, and video/audio ingestion. 10 MCP tools and 15 user-facing CLI commands for Claude Code and compatible agents.

Inspired by LACP by @0xNyk — the original local agent context protocol that showed agents could have persistent memory.

npm

MIT License OpenClaw >= 0.23.0 Node >= 22 Python >= 3.9

Overview

Engram brings persistent agent memory into your development workflow. It gives your agents session memory that survives across conversations, a knowledge graph backed by Obsidian, safety hooks that block dangerous operations before they execute, and a hash-chained provenance trail for every session.

The plugin implements a 5-layer memory system: per-project session memory with daily structure, an Obsidian-backed knowledge graph with QMD semantic search, an ingestion pipeline for external content (including video and audio via insanely-fast-whisper), AST-level code intelligence, and cryptographic provenance receipts. These layers work together so that every agent session starts with institutional context and ends with auditable evidence of what happened.

Engram is for teams and individuals who run agents on real codebases and need guardrails (blocking npm publish, git reset --hard, secrets access), persistent memory (facts that carry between sessions), and a clear audit trail. It is local-first by default -- all data stays on your machine.

Key capabilities:

  • Execution hooks (session context injection, pretool guard, quality gate, write validation)
  • Risk-based policy routing with three tiers (safe / review / critical) and cost ceilings
  • Per-project session memory with daily folder structure and per-agent session files
  • Session auto-capture hook (fires automatically on /new and /reset)
  • Obsidian-backed knowledge graph with QMD semantic search
  • Video and audio ingestion via ffmpeg + insanely-fast-whisper transcription
  • Vault doctor: scan orphans, fix frontmatter, add tags, rename hash files
  • Vault migration tool for restructuring existing vaults into Engram-compatible layout
  • 8-step curator maintenance cycle (inbox processing, consolidation, wikilinks, staleness, conflicts, schema, index, health)
  • Code intelligence via AST analysis, call graphs, and impact analysis
  • Cryptographic provenance tracking (SHA-256 hash-chained receipts)
  • Configurable safety profiles from autonomous to full-audit
  • 10 MCP tools for memory query, fact promotion, ingestion, guard status, vault management, graph indexing, brain resolution, memory KPIs, vault optimization, and session saving
  • 15 user-facing CLI commands organized into memory, guard, vault, brain, and ingest groups
  • Node.js interactive wizard with arrow-key navigation (powered by @clack/prompts)

Quick Start

Prerequisites

RequirementVersionNotes
OpenClaw>= 0.23.0Core runtime
Node.js>= 22CLI and wizard
Python>= 3.9Hook handlers and lib modules
Bash>= 4.0CLI tools are bash/python scripts
QMDrequiredSemantic search and memory backend — installed by wizard
Obsidian(optional)Knowledge graph vault (Layer 2)
ffmpeg(optional)Video/audio ingestion (Layer 3)
insanely-fast-whisper(optional)GPU-accelerated audio transcription

Install

Global install (recommended):

npm install -g @easylabs/engram

One-shot (no install):

npx @easylabs/engram

From the repo:

git clone https://github.com/itseasyco/engram
cd engram
bash INSTALL.sh

First-time Setup

engram wizard       # Interactive setup
engram doctor       # Verify installation

Uninstall

engram uninstall

This removes the plugin extension directory, managed hooks, and gateway config entries. Vault data and LACP memory files are preserved. Pass --yes to skip confirmation.

MCP Tools (10 tools)

Engram exposes 10 tools via the Model Context Protocol that agents can call directly during sessions.

ToolDescription
engram_memory_queryQuery session memory and LACP facts with semantic search (uses QMD when available)
engram_promote_factPromote a session observation to persistent scored fact
engram_ingestIngest transcripts, URLs, PDFs, files, video, and audio into the knowledge graph
engram_guard_statusCheck guard rule status, recent blocks, and allowlist entries
engram_vault_statusReport on Obsidian vault health, note counts, and index freshness
engram_graph_indexTrigger knowledge graph re-indexing with optional QMD semantic search
engram_brain_resolveResolve a query against contradictions/supersessions in knowledge notes
engram_memory_kpiReturn memory system KPIs: fact count, schema coverage, staleness, contradictions
engram_vault_optimizeApply memory-centric graph physics defaults (link distance, repel, node sizing, color groups)
engram_save_sessionSave session memory to daily folder structure with per-agent session files

CLI Reference

The engram command is the main entry point. Commands are organized into five groups: memory, guard, vault, brain, and ingest.

Top-level Commands

CommandDescription
engram wizardInteractive setup wizard (Node.js UI with arrow-key navigation)
engram wizard --section <name>Run a specific wizard section: vault, engine, profile, mode, guard, dependencies, all
engram statusSystem overview (mode, mutations, vault, tools)
engram doctorFull diagnostics across plugin, all 5 layers, MCP, and tests
engram uninstallRemove Engram (preserves vault data); pass --yes to skip confirmation
engram -v / engram --versionPrint version

Memory Commands

CommandDescription
engram memory query <topic>Search memory for facts matching a topic
engram memory promotePromote session facts to persistent memory
engram memory statusShow memory system status

Guard Commands

CommandDescription
engram guard rulesList all guard rules with their status
engram guard blocksView recent blocks from the audit log
engram guard toggle <rule-id>Enable or disable a specific rule
engram guard level <rule-id> <level>Set block level (block/warn/log) for a rule
engram guard allow "<cmd>"Add a command to the global allowlist
engram guard deny "<cmd>"Remove a command from all allowlists
engram guard configInteractive guard configuration
engram guard defaults --level <level>Set global default block level
engram guard resetReset to factory defaults

Vault Commands

CommandDescription
engram vault statusVault health and statistics
engram vault auditFull audit (broken links, orphans)
engram vault backupBackup vault
engram vault restoreRestore vault from backup
engram vault optimizeApply memory-centric graph physics defaults
engram vault kpiVault quality KPIs (fact count, schema coverage, staleness, contradictions)
engram vault healVault doctor: scan orphans, fix frontmatter, add tags, rename hash files
engram vault migrateStructure migration with wikilink preservation

Brain Commands

CommandDescription
engram brain expandRe-summarize, deduplicate, and compress memory layers
engram brain expand --consolidateRun mycelium consolidation pass
engram brain expand --curator-cycleRun full 8-step curator maintenance cycle
engram brain resolveResolve contradictions/supersessions in knowledge notes
engram brain codeAST analysis, symbol lookup, call graphs, impact analysis
engram brain graphInitialize, index, and query the knowledge graph

Ingest Command

CommandDescription
engram ingest <type> <source>Ingest content (transcript, url, pdf, file, video, video-batch, audio)

How the Memory System Works

Engram implements a continuous memory lifecycle across agent sessions.

The Five Layers

Layer 1: Session Memory     ~/.openclaw/projects/<slug>/memory/
Layer 2: Knowledge Graph    ~/obsidian/vault/ (Obsidian + QMD)
Layer 3: Ingestion Pipeline engram ingest (transcripts, URLs, PDFs, video, audio)
Layer 4: Code Intelligence  engram brain code (AST, call graphs, impact)
Layer 5: Provenance         ~/.openclaw/provenance/ (hash-chained receipts)

The Memory Lifecycle

  Agent works on a task
       |
       v
  Session memory accumulates (Layer 1)
  Per-project data in ~/.openclaw/projects/<slug>/memory/
       |
       v
  Facts get promoted to persistent memory (engram_promote_fact)
  Scored, categorized, deduplicated
       |
       v
  Knowledge gets indexed in vault/graph (Layer 2)
  Organized into projects / engineering / knowledge / inbox
       |
       v
  Session saved to daily structure (engram_save_session or auto-capture hook)
  vault/memory/YYYY-MM-DD/<agent-id>-<session>.md
       |
       v
  Next session starts
  session-start hook fires (Layer 1 + 2)
  Injects top relevant facts + git context into the agent's system message
       |
       v
  Agent has institutional memory from previous sessions

Session Memory

Every project gets its own memory directory at ~/.openclaw/projects/<slug>/memory/. The session-start hook reads the current git context (branch, recent commits, modified files) and injects it as a system message when a new session begins.

Session Auto-Capture

Engram includes a managed hook (engram-session-capture) that fires automatically when you issue /new or /reset in OpenClaw. It reads the session transcript, extracts key decisions and facts, writes a per-agent session file to vault/memory/YYYY-MM-DD/, and updates the daily index.

Knowledge Graph

The Obsidian vault is organized into the Engram taxonomy:

vault/
  home/           # Master index, vault overview
  memory/         # Daily session memory (YYYY-MM-DD folders)
  projects/       # Per-repo/per-project knowledge
  engineering/    # Architecture, decisions, active work
  knowledge/      # Concepts, learnings, agent knowledge
  inbox/          # Incoming notes awaiting curator processing
  reference/      # External docs, API references
  people/         # Team members, contacts
  archive/        # Archived/deprecated content
  _metadata/      # Vault config, taxonomy

Vault Doctor

The vault doctor scans every note in your vault and fixes what it can:

  • Find orphans (notes with zero backlinks)
  • Add/fix YAML frontmatter (title, category, tags, dates, status)
  • Auto-detect tags from content
  • Rename hash-named files to prose-style titles
  • Detect category and suggest/execute moves to correct folders
engram vault heal
engram vault heal --dry-run    # Preview changes without writing

Vault Migration

For existing vaults that need restructuring into the Engram-compatible layout:

engram vault migrate /path/to/vault --dry-run   # Preview
engram vault migrate /path/to/vault              # Execute

Lossless Context Integration

When contextEngine is set to lossless-claw, the plugin integrates with the LCM (Lossless Context Manager) backend. LCM's DAG compaction works alongside Engram's fact injection: LCM compresses conversational context while Engram injects curated facts at session start.

Safety Profiles

Seven profiles control which hooks fire and how they behave.

ProfileHooks EnabledBlock BehaviorUse Case
autonomoussession-start, pretool-guard, stop-quality-gate, write-validateAll hooks warn but never block; agent keeps workingDaily driver, autonomous agents, unattended operation
balancedsession-start, stop-quality-gateNo guard or write validationGeneral development, moderate-risk tasks (default)
context-onlysession-startNo safety gates at allLightest touch, just inject git context
guard-railpretool-guard, stop-quality-gateBlocks dangerous commands, catches incomplete workSafety without context injection overhead
minimal-stopstop-quality-gateOnly detects premature agent stopsLow-risk development and testing
hardened-execsession-start, pretool-guard, stop-quality-gate, write-validateAll hooks block; violations require explicit approvalProduction deploys, high-stakes work
full-auditsession-start, pretool-guard, stop-quality-gate, write-validateAll hooks block; verbose logging; full provenanceCompliance, audit trails, debugging hook behavior

Set the profile during install or change it later in ~/.openclaw/extensions/engram/config/.engram.env.

Guard System

The pretool-guard hook intercepts tool calls before execution and checks them against a configurable set of rules.

How It Works

  • The agent attempts to run a command (e.g., npm publish)
  • pretool-guard.py loads guard-rules.json (mtime-cached for performance)
  • The command is checked against allowlists first (global + repo-specific) -- if matched, it passes
  • Then checked against all enabled rules via regex patterns
  • For a matched rule, the block level is resolved: repo override > rule-specific > global default
  • Action is taken based on block level:
    • block -- command is rejected (exit 1)
    • warn -- warning is logged, command proceeds (exit 0)
    • log -- silently logged, command proceeds (exit 0)
  • Every match is written to guard-blocks.jsonl for audit

Built-in Rules (16 rules)

Rule IDPatternCategory
npm-publishnpm/yarn/pnpm/cargo publishdestructive
curl-pipe-interpretercurl | python, wget | node, etc.destructive
chmod-777chmod 777 (overly permissive)destructive
git-reset-hardgit reset --harddestructive
git-clean-forcegit clean -fdestructive
docker-privilegeddocker run --privilegeddestructive
fork-bombFork bomb patterndestructive
scp-rsync-rootscp/rsync to /rootdestructive
data-exfiltrationcurl --data @.env, @.ssh, etc.destructive
env-files.env file accessprotected-path
config-tomlconfig.toml accessprotected-path
secrets-directorysecrets/ directory accessprotected-path
claude-settings.claude/settings.jsonprotected-path
authorized-keysauthorized_keysprotected-path
pem-key-files.pem, .key filesprotected-path
gnupg-directory.gnupg/ directoryprotected-path

Per-Repo Overrides

{
  "repo_overrides": {
    "/path/to/my-repo": {
      "block_level": "warn",
      "rules_override": {
        "npm-publish": { "enabled": false },
        "git-reset-hard": { "block_level": "warn" }
      },
      "command_allowlist": [
        { "pattern": "docker run --privileged", "reason": "Needed for CI builds" }
      ]
    }
  }
}

Using engram guard

engram guard rules                                # List all rules
engram guard blocks                               # Recent blocks
engram guard toggle npm-publish                   # Toggle a rule
engram guard level git-reset-hard warn            # Set block level
engram guard allow "git reset --hard HEAD~1" --reason "Common dev workflow"
engram guard deny "git reset --hard HEAD~1"       # Remove from allowlist
engram guard config                               # Interactive configuration
engram guard defaults --level warn                # Set global default
engram guard reset                                # Factory defaults

Automation & Ingestion

Engram supports multiple patterns for getting external data into the knowledge graph, including text, documents, and video/audio media.

Video and Audio Ingestion

Engram can ingest video and audio files by extracting audio via ffmpeg and transcribing with Whisper.

# Ingest a video file
engram ingest video ~/obsidian/vault ./meeting-recording.mp4 \
  --speaker "Team Standup" --date "2026-03-23"

# Ingest audio
engram ingest audio ~/obsidian/vault ./voice-memo.mp3 \
  --title "Architecture Discussion"

# Batch-process a directory
engram ingest video-batch ~/obsidian/vault ./recordings/ \
  --date-from-filename --parallel 4

Manual Ingestion

engram ingest transcript ~/obsidian/vault ./call-notes.txt --speaker "Bob"
engram ingest url ~/obsidian/vault "https://example.com/article" --title "Overview"
engram ingest pdf ~/obsidian/vault ./whitepaper.pdf --title "System Design"
engram ingest file ~/obsidian/vault ./meeting-notes.md --title "Sprint Retro"

Curator Maintenance Cycle

The curator engine runs an 8-step maintenance cycle on your vault:

  • Process inbox (route queue-agent, queue-human, queue-cicd, queue-session)
  • Run mycelium consolidation (spreading activation, memory decay, path reinforcement)
  • Weave wikilinks (connect related notes)
  • Staleness scan (flag outdated content)
  • Conflict resolution (detect contradictions)
  • Schema enforcement (validate frontmatter)
  • Index update (rebuild graph index)
  • Health report (summary of vault state)
engram brain expand --curator-cycle

Configuration

Plugin Config

Location: ~/.openclaw/extensions/engram/config/.engram.env

Environment-style config for the plugin. Set during install by the wizard.

Guard Rules

Location: ~/.openclaw/extensions/engram/config/guard-rules.json

Controls all 16 guard rules, block levels, allowlists, and per-repo overrides. See Guard System for the full schema.

Key Config Properties

PropertyTypeDefaultDescription
enabledbooleantrueEnable/disable the plugin
profilestring"balanced"Safety profile
obsidianVaultstring~/obsidian/vaultPath to Obsidian knowledge vault
codeGraphEnabledbooleanfalseEnable AST analysis, call graphs, impact analysis
provenanceEnabledbooleantrueEnable hash-chained cryptographic receipts
contextEnginestring/nullnull"lossless-claw" for LCM integration, null for file-based
promotionThresholdnumber70Minimum score for auto-promotion (0-100)

Coming Soon

The following features exist in the codebase but are not fully wired or tested end-to-end:

  • Connected mode — engram connect / engram disconnect for joining shared vaults. The underlying sync_daemon.py, invites.py, and heartbeat.py modules are implemented but not tested in multi-user scenarios.
  • Connectors — engram connector for GitHub, Slack, Email, filesystem, webhooks, and cron-based fetching. Connector modules exist at plugin/lib/connectors/ but have not been tested against live external services.
  • File watcher — engram watch for auto-ingestion of files dropped into monitored directories.
  • Obsidian-headless sync — Multi-machine vault sync via ob CLI for connected/curator modes.
  • Pretool guard delivery — The before_tool_call hook depends on OpenClaw gateway lifecycle events not yet exposed in all runtimes. The guard code works; delivery depends on the gateway version.

Troubleshooting

"plugin not found"

Check that package.json exists in the plugin directory with "openclaw": { "extensions": ["./index.ts"] } and the gateway config has the plugin entry under plugins.installs.

"missing register/activate export"

The index.ts must export a default object with a register(api) method.

SDK not found

The installer should create a symlink at ~/.openclaw/extensions/engram/node_modules/openclaw. If missing:

ls ~/.openclaw/extensions/*/node_modules/openclaw
ln -s <detected_path> ~/.openclaw/extensions/engram/node_modules/openclaw

Hooks not showing in openclaw hooks list

Expected behavior. Engram registers hooks as lifecycle listeners via api.on(), which do not appear in openclaw hooks list. Verify by running engram doctor.

Run diagnostics

engram doctor       # Full diagnostics across all 5 layers
engram wizard       # Re-run wizard to fix configuration

Using Hooks with Claude Code

Two of the four hooks can be wired directly into Claude Code via its native hooks system in ~/.claude/settings.json:

{
  "hooks": {
    "session_initialization": [
      {
        "command": "python3 ~/.openclaw/extensions/engram/plugin/hooks/handlers/session-start.py",
        "timeout": 10000
      }
    ],
    "agent_stop": [
      {
        "command": "python3 ~/.openclaw/extensions/engram/plugin/hooks/handlers/stop-quality-gate.py",
        "timeout": 5000
      }
    ]
  }
}

Works with Claude Code today:

  • session-start — injects git context and LACP memory
  • stop-quality-gate — catches premature stops and rationalization patterns

Requires OpenClaw (not available in Claude Code):

  • pretool-guard — intercepts tool calls before execution
  • write-validate — validates file writes before they happen

Video / Audio Transcription

Engram ingests video and audio files via ffmpeg + insanely-fast-whisper:

# Install
pipx install insanely-fast-whisper==0.0.15 --force --pip-args="--ignore-requires-python"

# Use with Engram
engram ingest video /Volumes/Vault ~/recordings/meeting.mp4 --title "Q1 Planning"
Setup~Time for 1 hour of audioNotes
NVIDIA A100 / 4090~1 minBest performance
NVIDIA T4 / 3060~3-5 minUse --batch-size 12 if you hit OOM
Mac (Apple Silicon)~5-10 minAuto-sets --device-id mps --batch-size 4
CPU only~20-40 minUse openai-whisper instead

Contributing

Repo Structure

engram/
  package.json               # @easylabs/engram
  openclaw.plugin.json       # Plugin manifest (hooks, profiles, config schema, bins)
  INSTALL.sh                 # Install script (consumed by wizard output)
  bin/
    engram                   # Main CLI entry point (bash router)
    wizard.mjs               # Node.js interactive wizard (@clack/prompts)
  plugin/
    index.ts                 # Gateway entry point (hook + tool registration)
    bin/                     # CLI tools (engram-*)
    config/                  # Guard rules, example configs
    hooks/
      handlers/              # Python hook scripts
      managed/               # Auto-capture hook
      profiles/              # 7 safety profile JSONs
      tests/                 # Hook unit tests (pytest)
    lib/                     # Python modules
      mycelium.py            # Spreading activation, FSRS memory model
      curator.py             # 8-step curator maintenance cycle
      vault_doctor.py        # Orphan scan, frontmatter fix, tag detection
      vault_migrate.py       # Vault structure migration
      connectors/            # GitHub, Slack, Email, filesystem, webhook, cron
      tests/                 # Lib unit tests

Running Tests

cd plugin && python -m pytest -v               # Everything
cd plugin && python -m pytest hooks/tests/ -v   # Hook tests
cd plugin && python -m pytest lib/tests/ -v     # Lib tests

Dependencies

Required (installed automatically):

DependencyWhat it enables
QMDSemantic search, memory backend, context injection
poppler (pdftotext)PDF text extraction for ingestion

Optional (offered during setup):

DependencyWhat it enables
ffmpegVideo/audio processing for media ingestion
insanely-fast-whisperGPU-accelerated audio transcription
GitNexusMulti-language AST, call graphs, complexity analysis
lossless-clawNative LCM SQLite context engine
obsidian-headless (ob)Multi-machine vault sync for connected/curator modes

License

MIT

Keywords

engram

FAQs

Package last updated on 31 Mar 2026

Related posts