
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
hive - context compiler and shared-memory MCP server for Claude Code and its sub-agents
A shared brain for Claude Code and its sub-agents (MCP server + CLI).
Agents share state, not conversations: a fresh agent boots with a ~350-token compiled working set instead of re-reading 30k tokens of files and transcripts. Decisions survive across sessions and days, sub-agents inherit each other's results (never their chat logs), and 50 parallel agents can write without clobbering each other.
Golden rule: never make an agent pay tokens to read information it doesn't need — or pay twice for the same information.
Full design: docs/PLAN.md.
npm install -g hive-mcp
Or from source:
git clone https://github.com/HusseinTaha/hive-mcp.git && cd hive-mcp
npm install && npm run build
npm install -g .
Now hive works from anywhere. Data lives in one file: ~/.hive/ctx.db (an existing
~/.sharedctx/ctx.db from older versions is adopted automatically).
cd your-project
hive init
This does three things:
.mcp.json — registers the hive MCP server, giving every agent five tools (below)..claude/settings.json — wires three hooks:
SessionStart → injects a <800-token bootstrap, so every session starts already knowing the projectSubagentStop → commits each sub-agent's final report to shared memory automaticallyPreCompact → snapshots state before Claude Code compacts, so nothing is lost mid-sessionCLAUDE.md — adds the one-line norm: bootstrap with ctx_get, save results with ctx_commit.Restart Claude Code afterwards so it picks up the config.
You mostly don't do anything — that's the point. The hooks bootstrap every session and capture every sub-agent's results. Your part is telling Claude things worth remembering, in plain language:
And when you come back tomorrow, a new session already knows all of it.
| Tool | What it does |
|---|---|
ctx_get | The working set: objective, current tasks, blockers, hot decisions, recent changes, topic index — compiled to a budget (~350–800 tok). Pass since=<last CURSOR> on later calls to get only changes (~15–100 tok). topic=auth drills into one topic. |
ctx_search | BM25 search over everything ever stored, ~40 tok/hit with [e<id>] provenance refs. Zero local hits → labeled results from your other projects ([proj-a/e12] …). |
ctx_commit | Save results: what changed, decisions (key/value/reason), facts, open questions, task updates. Hard size caps — a commit is a telegram, not a memoir. |
ctx_task | Lease-based task board: claim / release / complete. Two agents can never hold the same task; stale leases (30 min) are reclaimable; complete requires evidence. |
ctx_compile | A bespoke context pack for one task description — relevance-ranked, so cold facts matching the task resurface and hot-but-unrelated ones drop. |
== acme-api @ a3f9c21 · CURSOR: 412 ==
OBJECTIVE: Ship v1 auth
NOW: refresh-token rotation (task#12, owner: backend-2)
BLOCKED: none
DECISIONS: db=PostgreSQL(relational+tx) | auth=JWT(15m access) | api=REST
CHANGED: login endpoint impl (backend-1, 2h ago, ev: tests/auth ✓)
OPEN: rate-limit login?
⚠ VERIFY: 'api routes complete' written @ b2e11f0 (HEAD moved)
TOPICS: auth(9k) db(6k) api-contracts(7k)
MORE: d:cors · q:session-invalidation — pull via topic= or ctx_search
~350 tokens replacing a 30k-token history dump. Superseded decisions never appear here, but stay searchable forever — that's what stops agent #7 from re-proposing MongoDB.
hive init wire up .mcp.json + hooks + CLAUDE.md in cwd, seed DB
hive status [--project P] [--role R] [--budget N] [--topic T] [--since N]
print the compiled working set (what agents see)
hive stats [--project P] context-spend telemetry per tool + est. savings
hive distill [--project P] heat decay + working-set pressure valve (also runs
automatically every ~25 events)
hive compress [--project P] [--model M] [--dry-run]
model-assisted fact compression via the claude CLI;
originals kept in supersede chains
hive dump [--project P] raw append-only event log as JSON lines
hive bootstrap alias of status (used by the SessionStart hook)
Environment: HIVE_DB overrides the DB path; HIVE_PROJECT overrides the project key
(default: git-root basename). Legacy SHAREDCTX_* names still work.
| Naive shared-history | hive | |
|---|---|---|
| Tool schemas | ~2,000 (10 verbose tools) | ~840 (5 terse tools, CI-guarded) |
| Bootstrap | 20k–80k transcript / file re-reads | ~350–800 (hook-injected) |
| Refresh checks | full re-dump each time | ~15–100 (cursor deltas) |
| Handoff | poisons the next agent | ~200-tok structured commit |
Under the hood: append-only SQLite event log (WAL — 50 parallel writers, zero conflicts),
facts with supersede-chains (nothing is ever deleted), provenance + git-drift ⚠ VERIFY
flags on volatile facts, evidence-gated completion, and a distiller that keeps the hot
working set ≤ ~1,500 tokens no matter how much knowledge accumulates.
npm test # 39 tests: behavior, eval harness (50k-token seeded project),
# multi-process stress (20 writers / 12-way lease race), schema-token guard
npm run build # tsc → dist/
npm install -g . # reinstall the global CLI after changes
Roadmap M0–M4 from docs/PLAN.md is complete. Remaining work is field
tuning: use it on real projects and let hive stats + the eval harness drive ranking changes.
FAQs
hive - context compiler and shared-memory MCP server for Claude Code and its sub-agents
The npm package hive-mcp receives a total of 8 weekly downloads. As such, hive-mcp popularity was classified as not popular.
We found that hive-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.