
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
engram-tools
Advanced tools
Shared memory for AI coding agents. Store, recall, and learn across tools, sessions, and teams.
Shared memory for AI coding agents. Engram lets MCP-compatible agents store what they learn, recall team knowledge, transfer lessons across repos, and report whether recalled memories actually helped.
engram-toolsengram_start for one-call session setup + smart context loadingengram_rehydrate for context-compaction recovery from the session journalengram_smarter for task-specific context loading when switching tasksengram_store, engram_recall, engram_report_outcome, engram_get_context, engram_skill, and engram_setupVOYAGE_API_KEY is configurednpx engram-tools --setup engram_your_api_key
For an agent-driven install, keep the credential out of the command arguments and preview the selected client first:
export ENGRAM_API_KEY=engram_your_api_key
npx -y engram-tools@latest --setup --client codex --dry-run
npx -y engram-tools@latest --setup --client codex
Supported selectors are claude, cursor, gemini, antigravity, windsurf, opencode, codex, copilot, cline, roo, kiro, amazonq, goose, continue, and all. Aliases such as roo-code and amazon-q are accepted. The agent may run the command when its host grants shell and file access; workspace authorization and payment remain human-controlled.
The setup command writes MCP config for Claude Code, Cursor, Gemini, Antigravity, Codex, OpenCode, VS Code/Copilot, Cline, Roo Code, Kiro, Amazon Q Developer, Goose, and Continue when possible. Existing JSON, TOML, and YAML settings are preserved. For Claude Code, it also writes optional slash-command aliases for convenience.
After setup, restart your AI tool or start a new session. Most MCP clients load servers only at session startup. Start every client the same way: call engram_start once with project, repo, stack, role, market, and task.
If the conversation was compacted, summarized, resumed, truncated, or the agent feels prior context is incomplete, call engram_rehydrate before continuing. It restores the session journal: where the agent left off, decisions, gotchas, open loops, and lessons since the last rehydrate. If the agent is mid-session and only needs focused task context, call engram_smarter.
Manual MCP config:
{
"mcpServers": {
"engram": {
"command": "npx",
"args": ["-y", "engram-tools", "mcp"],
"env": {
"ENGRAM_API_KEY": "engram_your_api_key",
"ENGRAM_API_URL": "https://api.engram.tools"
}
}
}
}
engram_start
Start a session in one call. This loads setup guidance, the Engram operating contract, and the most relevant memories. Use it at the beginning of a session, when entering a repo, or when task context changes. Use engram_rehydrate after compaction/resume. Skill guides are available on demand when the task needs a checklist.
{
"project": "HouseCompass",
"repo": "housecompass.uk",
"role": "frontend product engineer",
"market": "UK property",
"task": "build the listing detail page",
"stack": ["Next.js", "TypeScript", "PostgreSQL"]
}
engram_rehydrate
Restore working memory after context compaction, summary, resume, truncation, or agent confusion. This is the anti-context-compaction tool: it returns the latest checkpoint, decisions to preserve, gotchas to avoid, open loops, recent timeline, and the learning-path delta since the last rehydrate.
{
"project": "HouseCompass",
"repo": "housecompass.uk",
"task": "continue the listing detail page",
"reason": "conversation context was compacted",
"depth": "standard"
}
engram_smarter
Load task-specific memories in one call. Use this after engram_start, when switching tasks, or when recovering focused context mid-session. Set include_skills: true only for checklist-heavy work such as review, security, migration, deployment, testing, performance, accessibility, or localization.
{
"context": "Next.js 16 + Prisma signup bug, fixing API key setup",
"repo": "engram",
"include_skills": true
}
engram_cross_pollinate
Find reusable lessons from other repos in the same workspace.
{
"target_repo": "engram",
"context": "Stripe webhook tier updates and signup reliability"
}
engram_store
Save a convention, pattern, gotcha, solution, architecture note, or dependency quirk.
engram_recall
Search memories by semantic query, repo, type, or tags.
engram_report_outcome
Report whether a recalled memory helped. This updates confidence and improves future ranking.
Hosted API base:
https://api.engram.tools
Useful endpoints:
POST /api/v1/startPOST /api/v1/smarterPOST /api/v1/cross-pollinatePOST /api/v1/storePOST /api/v1/recallPOST /api/v1/reportPOST /api/v1/contextPOST /api/v1/skillPOST /api/v1/setupGET /api/v1/capabilitiesAll private endpoints require:
Authorization: Bearer <ENGRAM_API_KEY>
npm install
npm run db:setup
npm run dev:http
Environment:
DATABASE_URL=postgresql://...
ENGRAM_API_KEY=engram-dev-key-001
VOYAGE_API_KEY=optional
Run verification:
npm run typecheck
npm run build
npm run test:product
The product smoke test stores memories, calls /api/v1/smarter, and verifies /api/v1/cross-pollinate.
Engram is in beta. The core memory, smarter context, cross-repo transfer, outcome-learning, hosted limits, API metering, Stripe plan updates, and basic dashboard flows are implemented. Scale-plan items such as SSO/SAML, self-hosted packaging, and SLA terms are handled as custom rollout work.
MIT
FAQs
Memory for AI agent teams. Store, recall, and learn across tools, sessions, repositories, and teammates.
The npm package engram-tools receives a total of 63 weekly downloads. As such, engram-tools popularity was classified as not popular.
We found that engram-tools demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.