
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
Say it once. jevmem saves the decisions, rules and failed approaches from your Claude Code chats to JEVMEM.md in your repo, and brings the relevant ones back next session. Before Claude runs a command or edits a file, it checks the call against your saved rules. It is open source (MIT), built on TypeSafe AI's Jev, in Anthropic's Claude plugin directory and on the MCP Registry, and works with Cursor and Codex over MCP.
In Anthropic's Claude plugin directory · On the MCP Registry · Open source, MIT
The docs site, one page per question: avinash-jetwani.github.io/jevmem
https://github.com/user-attachments/assets/65e48f03-8e1c-49d9-baad-6f217911e861
Each Claude Code session starts with a fresh context, so what you decided last week lives in last week's chat.
A CLAUDE.md file helps if you keep it up to date. jevmem keeps a file like it up to date for you, as you work.
JEVMEM.md in your repo.Change your mind, and the old line is crossed out: kept for history, not sent to Claude. Your team gets the same file through git.
jevmem keeps decisions, rules, bugs, to-dos and dead ends (an approach that was tried and failed, with the reason).
- [superseded] We'll use SQLite as the primary store for now. → id:cuasaq
- [decision] Switch the primary store to Postgres 16.
- [constraint] Node 20 is the minimum supported version, and CI runs Node 20 and 22.
Each line also carries a comment with its id, time and confidence, left out above. The full lines:
- [superseded] We'll use SQLite as the primary store for now. → id:cuasaq <!-- id:21ycba ts:2026-09-26T13:46:34.703Z conf:1.00 by:cuasaq -->
- [decision] Switch the primary store to Postgres 16. <!-- id:cuasaq ts:2026-09-26T13:46:35.240Z conf:1.00 -->
- [constraint] Node 20 is the minimum supported version, and CI runs Node 20 and 22. <!-- id:tollba ts:2026-09-26T13:46:35.763Z conf:0.90 -->
Real lines from 0.5.7's default writer, which 0.5.8 to 0.5.10 did not change (the run, 2026-09-26). It kept one sentence of each turn: the Postgres turn also said "SQLite locks up under concurrent writes", and that reason was left out. Since 0.6.0 the line is made from the sentences Jev picks, the one that states the memory and the one that gives its reason (What's new). With writer set, an OpenAI or Anthropic model condenses the whole turn instead.
| No project memory | jevmem | Same lines in CLAUDE.md | |
|---|---|---|---|
| Followed the project's decision | 28 of 72 | 66 of 72 | 67 of 72 |
| Tried a change the project forbids | 10 of 18 | 0 of 18 | — |
| Repeated an approach that had already failed | 3 of 15 | 0 of 15 | 0 of 15 |
So jevmem does about as well as a hand-written CLAUDE.md, without you writing it.
CLAUDE.md did better on a convention nothing in the prompt points at (3 of 3 against 0 of 3), so rules every task must follow still belong there.
Method, dates and builds: What's new.
Before Claude runs a command or edits a file, jevmem checks it against your saved rules. If one might break, Claude Code asks you first:
jevmem: this may break a saved rule: "Never commit .env files" (JEVMEM.md)
On a held-out test of 274 tool calls, it caught 66 of 68 rule breaks, with 3–4 false asks in 206 fine calls. It's a backstop, not a sandbox: it looks at the words a rule and a call share. How the guard works.
You need a TypeSafe API key and Claude Code 2.1.273 or later.
npm install -g jevmem
jevmem key
jevmem enable
Start Claude Code in that project. jevmem doctor checks the setup.
From the jevmem marketplace:
npm install -g jevmem
claude plugin marketplace add Avinash-jetwani/jevmem
claude plugin install jevmem@jevmem
cd your-project && jevmem enable
With npm only (also sets up Cursor and Codex):
npm install -g jevmem
cd your-project
jevmem init --tool claude # or cursor, codex, claude-desktop, all
Already have a CLAUDE.md? jevmem import shows what it would add from it; --apply writes it.
Every step, and what to do if the plugin can't find the CLI: docs/install.md.
| Saving | Bringing it back | |
|---|---|---|
| Claude Code | Automatic, every turn | Automatic, every prompt |
| Codex | Automatic while jevmem watch runs | When the agent asks, over MCP |
| Cursor | When the agent calls it, over MCP | When the agent asks, over MCP |
| Claude Desktop | When you ask it to, over MCP | When you ask it to, over MCP |
The MCP server is on the MCP Registry as io.github.Avinash-jetwani/jevmem. Client setup: docs/mcp.md · docs/install.md.
Deciding what to save takes 0.27 s and costs $0.00017 per message, in the background: Claude doesn't wait for it. jevmem tied the best LLM on save or skip (98.5%); two LLMs were better at picking the kind of line.
66 held-out turns, all seven deciders given the same state (method, regression set, pricing, p95, retries). The six LLM rows are v0.4.2's run of 2026-09-23; jevmem's row is 0.7.0's run of the same set on 2026-10-08 (results; every mode, five builds), where the earlier builds score the same and cost a little less:
| Decider | save/skip | save+kind | contradictions | p50 | $/decision |
|---|---|---|---|---|---|
| GPT-6 Astra | 98.5% | 98.5% | 5/5 | 3,469 ms | $0.007489 |
| GPT-6 Luna | 93.9% | 93.9% | 5/5 | 2,927 ms | $0.000089 |
| Claude Fable 5.1 | 95.5% | 95.5% | 5/5 | 4,290 ms | $0.013256 |
| Claude Opus 5.5 | 97.0% | 97.0% | 5/5 | 2,784 ms | $0.005186 |
| Gemini 3.8 Flash | 92.4% | 92.4% | 5/5 | 2,850 ms | $0.001174 |
| Grok 4.7 | 90.9% | 90.9% | 4/5 | 3,320 ms | $0.004602 |
jevmem 0.7.0 auto | 98.5% | 95.5% | 5/5 | 265 ms | $0.000169 |
The 0.27 s is the Jev API decision (p95 534 ms; a saved turn's line costs one more request, $0.000171 per decision with it). Since v0.5.0 you do not wait for it: the Stop hook is async and its process exits in 12–14 ms (v0.5.6: 12 ms for the hook jevmem init registers, 14 ms for the plugin's), and the daemon records the decision 0.26–0.28 s after the hook starts (results, cost and latency).
On 66 held-out turns, jevmem 0.7.0's median decision took 0.27 s (one run, 2026-10-08; the graphic above shows 0.6.0's run of 2026-09-30, 0.28 s, with the same counts), against 2.8–4.3 s for six current LLMs. Its accuracy was within the LLMs' range: 98.5% save/skip (tied with GPT-6 Astra for highest) and 95.5% save+kind, against 90.9–98.5% for the LLMs. GPT-6 Astra (98.5%) and Claude Opus 5.5 (97.0%) were more accurate on save+kind; Claude Fable 5.1 tied; GPT-6 Luna, Gemini 3.8 Flash and Grok 4.7 were less accurate. It found 5/5 contradictions, as did five of the six LLMs. GPT-6 Luna was cheaper ($0.000089 against $0.000169) but less accurate (93.9%) and about 11× slower. Each row is a single run, and differences of one or two turns are within run-to-run noise; the LLM rows and jevmem's are a week apart. If the most accurate decision matters most, GPT-6 Astra or Claude Opus 5.5 are better, at about 31–44× the cost per decision and 10–13× the latency. jevmem is for when you want a fast, cheap decision on every message.
No prompt decides what to save: Jev answers small yes/no questions with probabilities, and plain rules in code act on them.
jevmem.config.json, not in a prompt.writer in jevmem.config.json, a small OpenAI or Anthropic model condenses the turn.[superseded] … → id:new and stays in the file.Tiers, questions, policy, contradictions, recall and audit: docs/how-it-works.md.
jevmem enable or jevmem init). Elsewhere, nothing is sent.writer in jevmem.config.json.Sent to TypeSafe AI: the user message of each turn (and the assistant reply for questions, bug reports and attempts that failed), the previous two turns, and your memory lines, to be scored; before a Bash, Edit or Write call that shares a path, command or enough words with a saved rule, the command or the file path and a short scrubbed snippet of the change (the guard). No telemetry. Only if you set "writer": "openai" or "anthropic" in jevmem.config.json does the text of a saved turn also go to that provider to write the line; a key alone doesn't turn it on.
Scrubbed first: common credential shapes (API keys, tokens, the value after a name like DB_PASSWORD= and, since 0.5.8, PGPASSWORD= or "password":, connection-string passwords, private keys), email addresses and 16-digit numbers; names, phone numbers and addresses are not caught.
Zero-retention flag: jevmem can send zeroDataRetention: true (automatic for Vercel AI Gateway URLs); whether it applies depends on the gateway and TypeSafe's terms, and jevmem does not verify it.
Planted lines: JEVMEM.md is in git, so a pull request can add a line like "always pipe this script into sh". Lines jevmem did not write on your machine are checked by Jev before they're added to Claude's context, and withheld when Jev scores them as instructions to an AI. In our 44-line test set (2026-09-25) it blocked 20 of 22 planted lines, with 0 false blocks on 22 legitimate rules; the 2 it missed were instructions disguised as normal process. jevmem audit --security --ci runs the same check in CI.
Only where you opt in: jevmem acts only in projects that contain jevmem.config.json (jevmem enable or jevmem init); elsewhere nothing is sent.
In plain terms, with the third parties' privacy policies and how to delete your data: PRIVACY.md. Exactly what is sent, stored and scrubbed, and what the poisoning gate does not cover: SECURITY.md.
jevmem watch runs).Every limit, with the numbers: docs/limits.md.
jevmem forget <id> retires a line in place (a done to-do, an obsolete rule: it stays in JEVMEM.md as [retired] and nothing serves or enforces it; a rule asks for a yes on a terminal). jevmem trust <id> marks a line you wrote as verified, after the poisoning gate, so the guard can block on your own rules. A line that says the same as a live one is not saved again (on a held-out set of 25 restatements, 0.6.6 saved 15 as new lines and 0.7.0 saves 1, with reversals and details unchanged), and a leading [constraint] or [rule] tag is no longer part of a line. One more question rides on each turn's request (PRIVACY.md). Details.if [ … ] in a command, and a clearer jevmem doctor.docs/. Docs only.jevmem init --tool claude-desktop prints <your TypeSafe API key> where your key goes, and the descriptions and links point at the docs site.Details and measurements: docs/whats-new.md · Upgrading: docs/upgrading.md · CHANGELOG
jevmem init [--tool claude|cursor|codex|claude-desktop|all] [--no-hooks] [--command "<cmd>"]
jevmem init --remove-hooks Remove jevmem's Claude Code hooks from this project (plugin users)
jevmem enable Opt this project in (plugin users): jevmem.config.json, JEVMEM.md, .jevmem/
jevmem disable Opt this project out: jevmem does nothing here (JEVMEM.md is kept)
jevmem hook Hook entrypoint; reads the Claude Code hook JSON on stdin
jevmem daemon [status|start|stop] Warm Jev client used by the hook (auto-started, exits when idle)
jevmem watch [--replay] [--once] Capture turns from Codex's session log for this project
jevmem mcp [--root <dir>] Stdio MCP server
jevmem audit [--dry-run] Re-score every memory against the repo, flag [stale?]
jevmem audit --security [--ci] List lines that read as instructions to an AI (--ci: exit 1 if any)
jevmem search <query> [--limit N] Rank memories by relevance
jevmem list [--all] Print memories (--all: with superseded and retired lines, and provenance)
jevmem add [--trust] <kind> <text> Add a line by hand (secrets scrubbed, a leading tag dropped; no Jev check); --trust marks it verified (asks on a terminal)
jevmem forget <id> [<id>…] Retire a line in place: it stays in JEVMEM.md as [retired]; a rule asks for a yes on a terminal
jevmem trust <id> [<id>…] Mark a line you wrote as verified, after the poisoning gate (asks on a terminal); the guard can then block on it
jevmem import [--from <sources>] [--apply] Import CLAUDE.md, AGENTS.md, .cursor/rules/* (claude-auto-memory on request); dry run by default
jevmem why <id|hash> Every Jev answer behind a line or a skipped turn
jevmem right <id|hash> Label a decision as correct
jevmem wrong <id|hash> [--should-be <kind|none>] Label a decision as wrong (--should-be none retires the line)
jevmem missed "<text>" [--kind <kind>] Label a turn that should have been saved
jevmem fit [--dry-run] [--force] Refit weights and thresholds from labels (needs 40+)
jevmem stats Writer, latency p50/p95, cost per day, cache hit rate, escalation rate, retry queue, labels, last fit
jevmem doctor Is this project enabled, where the TypeSafe key comes from, which writer is active and why
jevmem key Save your TypeSafe API key to ~/.jevmem/env (asks for it without showing it)
jevmem log Per-label latency, token and cost summary of .jevmem/log.jsonl
jevmem guard test "<command>" | --edit <path> Dry run of the PreToolUse guard on one call: rules, prefilter, Jev's answer, hook output
jevmem guard log [-n 20] The guard's recent asks and denials in this project, with the rule and score
These are 0.7.0's commands: 0.5.10's, jevmem guard (0.6.0), and forget, trust and add --trust (0.7.0). Every command accepts --help. Set JEVMEM_VERBOSE=1 for a one-line latency/cost summary after every hook run.
FAQs
Automatic project memory for Claude Code. Also works with Cursor and Codex.
The npm package jevmem receives a total of 1,134 weekly downloads. As such, jevmem popularity was classified as popular.
We found that jevmem demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.