
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@memstack/cli
Advanced tools
CLI for MemStack — shell-based agent memory. Use from bash scripts, opencode/Claude Code shell tools, CI pipelines, or any subprocess-capable agent.
npm install -g @memstack/cli
# or
npx @memstack/cli [command]
All via environment variables. Same scheme as @memstack/mcp.
| Variable | Purpose | Default |
|---|---|---|
MEMSTACK_STORAGE | Storage backend | memory |
MEMSTACK_DIR | Directory for markdown/disk | ./memories |
DATABASE_URL | Postgres connection | — |
SQLITE_PATH | SQLite database path | ./memstack.db |
REDIS_URL | Redis connection | redis://localhost:6379 |
OPENAI_API_KEY | OpenAI LLM + embeddings | — |
ANTHROPIC_API_KEY | Anthropic LLM (summarization) | — |
MEMSTACK_OPENAI_BASE_URL | Custom API endpoint (DeepSeek, etc.) | https://api.openai.com/v1 |
MEMSTACK_LLM_MODEL | Model override | gpt-4o-mini |
MEMSTACK_EMBED_ON_STORE | Auto-embed on store | true |
All output is JSON to stdout. Errors go to stderr.
memstack store --actor "agent-1" --content "User reported login bug" --type interaction --importance 0.8 --tags "bug,login"
# {"id":"mem_...","actorId":"agent-1","content":"User reported login bug",...}
memstack retrieve --actor "agent-1" --query "login" --strategy hybrid --limit 5
memstack retrieve --actor "agent-1" --created-after "2026-01-01T00:00:00Z" --created-before "2026-06-01T00:00:00Z"
memstack context --actor "agent-1" --max-tokens 2000
# {"systemPrompt":"## Important Memories\n- ...", "tokenEstimate": 280, ...}
memstack summarize --actor "agent-1" --older-than 7d
# {"summary": {...}, "deletedCount": 47}
memstack prune --actor "agent-1" --type byAge --max-age 30d
memstack prune --actor "agent-1" --type byImportance --min-importance 0.3
memstack prune --actor "agent-1" --type byCount --max-count 500
memstack prune --actor "agent-1" --type byAge --max-age 7d --dry-run # preview only
memstack purge --actor "agent-1"
# 42 (number of deleted memories)
memstack merge --ids "mem_abc,mem_def,mem_ghi"
# {merged memory object}
memstack stats --actor "agent-1"
# {"total":1500,"expired":3,"oldest":"...","newest":"...","avgImportance":0.6,...}
memstack delete --id "mem_abc123"
# {"deleted":true}
memstack health
# {"storage":true,"llm":true,"embedding":true}
memstack export --actor "agent-1"
memstack export --actor "agent-1" --out ./backup.json
# {"saved":"./backup.json","count":1500}
memstack import --actor "agent-1" --file ./backup.json
# {"imported":1500}
Each memory's original createdAt is preserved on import (round-trips exactly with export). Importing a snapshot with zero memories fails cleanly with a non-zero exit.
The CLI normalizes and validates input before storing:
--importance is clamped to the 0.0–1.0 range (e.g. --importance 5 stores as 1, --importance=-1 stores as 0).--actor is trimmed of leading/trailing whitespace (--actor " a " and --actor a are the same actor).--tags drops empty entries from trailing/double commas (--tags "a,,b," → ["a","b"]).prune --type rejects unknown strategies with a non-zero exit instead of silently doing nothing. Valid: byAge, byImportance, byCount, byType, custom, compose.prune --actor is scoped to that actor only — it never touches other actors' memories.#!/bin/bash
AGENT_ID="support-bot"
# Before each turn: inject memory context
CONTEXT=$(memstack context --actor "$AGENT_ID" --max-tokens 1500)
SYSTEM_PROMPT=$(echo "$CONTEXT" | jq -r '.systemPrompt')
# After each turn: store what happened
memstack store --actor "$AGENT_ID" --content "$TURN_SUMMARY" --type interaction
# Periodic maintenance
memstack prune --actor "$AGENT_ID" --type byAge --max-age 30d
cd packages/cli
pnpm build && pnpm check && pnpm test
npm publish --access public
After publishing, users install with:
npm install -g @memstack/cli
MIT
FAQs
CLI for MemStack — shell-based agent memory
We found that @memstack/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.