New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

jevmem

Package Overview
Dependencies
Maintainers
1
Versions
24
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

jevmem

Automatic project memory for Claude Code. Also works with Cursor and Codex.

latest
Source
npmnpm
Version
0.7.0
Version published
Weekly downloads
1.3K
-44.6%
Maintainers
1
Weekly downloads
 
Created
Source

jevmem

Say it once. jevmem saves the decisions, rules and failed approaches from your Claude Code chats to JEVMEM.md in your repo, and brings the relevant ones back next session. Before Claude runs a command or edits a file, it checks the call against your saved rules. It is open source (MIT), built on TypeSafe AI's Jev, in Anthropic's Claude plugin directory and on the MCP Registry, and works with Cursor and Codex over MCP.

In Anthropic's Claude plugin directory · On the MCP Registry · Open source, MIT

The docs site, one page per question: avinash-jetwani.github.io/jevmem

npm version license node CI M8ven Verified

https://github.com/user-attachments/assets/65e48f03-8e1c-49d9-baad-6f217911e861

Why

Each Claude Code session starts with a fresh context, so what you decided last week lives in last week's chat. A CLAUDE.md file helps if you keep it up to date. jevmem keeps a file like it up to date for you, as you work.

How it works

You say it, Jev decides, jevmem writes one line to JEVMEM.md, and next session Claude gets the lines that matter.

  • You decide something in a chat: "We use Postgres."
  • jevmem asks Jev by TypeSafe AI, a model that answers yes/no questions with probabilities, whether it's worth keeping.
  • If it is, jevmem writes one line to JEVMEM.md in your repo.
  • Next session, the lines that matter for your prompt go back to Claude.

Change your mind, and the old line is crossed out: kept for history, not sent to Claude. Your team gets the same file through git.

jevmem keeps decisions, rules, bugs, to-dos and dead ends (an approach that was tried and failed, with the reason).

- [superseded] We'll use SQLite as the primary store for now. → id:cuasaq
- [decision] Switch the primary store to Postgres 16.
- [constraint] Node 20 is the minimum supported version, and CI runs Node 20 and 22.
About these lines

Each line also carries a comment with its id, time and confidence, left out above. The full lines:

- [superseded] We'll use SQLite as the primary store for now. → id:cuasaq  <!-- id:21ycba ts:2026-09-26T13:46:34.703Z conf:1.00 by:cuasaq -->
- [decision] Switch the primary store to Postgres 16.  <!-- id:cuasaq ts:2026-09-26T13:46:35.240Z conf:1.00 -->
- [constraint] Node 20 is the minimum supported version, and CI runs Node 20 and 22.  <!-- id:tollba ts:2026-09-26T13:46:35.763Z conf:0.90 -->

Real lines from 0.5.7's default writer, which 0.5.8 to 0.5.10 did not change (the run, 2026-09-26). It kept one sentence of each turn: the Postgres turn also said "SQLite locks up under concurrent writes", and that reason was left out. Since 0.6.0 the line is made from the sentences Jev picks, the one that states the memory and the one that gives its reason (What's new). With writer set, an OpenAI or Anthropic model condenses the whole turn instead.

Does it work?

A/B results: followed the project's decision 28 of 72 with no project memory, 66 of 72 with jevmem, 67 of 72 with a hand-written CLAUDE.md.

No project memoryjevmemSame lines in CLAUDE.md
Followed the project's decision28 of 7266 of 7267 of 72
Tried a change the project forbids10 of 180 of 18—
Repeated an approach that had already failed3 of 150 of 150 of 15

So jevmem does about as well as a hand-written CLAUDE.md, without you writing it. CLAUDE.md did better on a convention nothing in the prompt points at (3 of 3 against 0 of 3), so rules every task must follow still belong there. Method, dates and builds: What's new.

The guard (new in 0.6)

The guard: Claude wants to run a command, jevmem checks it against your saved rules, and Claude Code asks you first.

Before Claude runs a command or edits a file, jevmem checks it against your saved rules. If one might break, Claude Code asks you first:

jevmem: this may break a saved rule: "Never commit .env files" (JEVMEM.md)

On a held-out test of 274 tool calls, it caught 66 of 68 rule breaks, with 3–4 false asks in 206 fine calls. It's a backstop, not a sandbox: it looks at the words a rule and a call share. How the guard works.

Install

You need a TypeSafe API key and Claude Code 2.1.273 or later.

  • In the Claude app: Plugins → Discover → jevmem → Add.
  • Install the CLI the plugin runs:
    npm install -g jevmem
    
  • Save your key (paste it when asked; it isn't shown):
    jevmem key
    
  • In your project's folder, turn jevmem on:
    jevmem enable
    

Start Claude Code in that project. jevmem doctor checks the setup.

Other ways to install: the jevmem marketplace, npm, Cursor, Codex

From the jevmem marketplace:

npm install -g jevmem
claude plugin marketplace add Avinash-jetwani/jevmem
claude plugin install jevmem@jevmem
cd your-project && jevmem enable

With npm only (also sets up Cursor and Codex):

npm install -g jevmem
cd your-project
jevmem init --tool claude    # or cursor, codex, claude-desktop, all

Already have a CLAUDE.md? jevmem import shows what it would add from it; --apply writes it.

Every step, and what to do if the plugin can't find the CLI: docs/install.md.

Works with

SavingBringing it back
Claude CodeAutomatic, every turnAutomatic, every prompt
CodexAutomatic while jevmem watch runsWhen the agent asks, over MCP
CursorWhen the agent calls it, over MCPWhen the agent asks, over MCP
Claude DesktopWhen you ask it to, over MCPWhen you ask it to, over MCP

The MCP server is on the MCP Registry as io.github.Avinash-jetwani/jevmem. Client setup: docs/mcp.md · docs/install.md.

Fast and cheap

Median time to decide one message on 66 held-out turns: jevmem 0.28 s, six current LLMs 2.78 to 4.29 s.

Deciding what to save takes 0.27 s and costs $0.00017 per message, in the background: Claude doesn't wait for it. jevmem tied the best LLM on save or skip (98.5%); two LLMs were better at picking the kind of line.

The full benchmark: accuracy, cost and how it was run

66 held-out turns, all seven deciders given the same state (method, regression set, pricing, p95, retries). The six LLM rows are v0.4.2's run of 2026-09-23; jevmem's row is 0.7.0's run of the same set on 2026-10-08 (results; every mode, five builds), where the earlier builds score the same and cost a little less:

Decidersave/skipsave+kindcontradictionsp50$/decision
GPT-6 Astra98.5%98.5%5/53,469 ms$0.007489
GPT-6 Luna93.9%93.9%5/52,927 ms$0.000089
Claude Fable 5.195.5%95.5%5/54,290 ms$0.013256
Claude Opus 5.597.0%97.0%5/52,784 ms$0.005186
Gemini 3.8 Flash92.4%92.4%5/52,850 ms$0.001174
Grok 4.790.9%90.9%4/53,320 ms$0.004602
jevmem 0.7.0 auto98.5%95.5%5/5265 ms$0.000169

The 0.27 s is the Jev API decision (p95 534 ms; a saved turn's line costs one more request, $0.000171 per decision with it). Since v0.5.0 you do not wait for it: the Stop hook is async and its process exits in 12–14 ms (v0.5.6: 12 ms for the hook jevmem init registers, 14 ms for the plugin's), and the daemon records the decision 0.26–0.28 s after the hook starts (results, cost and latency).

On 66 held-out turns, jevmem 0.7.0's median decision took 0.27 s (one run, 2026-10-08; the graphic above shows 0.6.0's run of 2026-09-30, 0.28 s, with the same counts), against 2.8–4.3 s for six current LLMs. Its accuracy was within the LLMs' range: 98.5% save/skip (tied with GPT-6 Astra for highest) and 95.5% save+kind, against 90.9–98.5% for the LLMs. GPT-6 Astra (98.5%) and Claude Opus 5.5 (97.0%) were more accurate on save+kind; Claude Fable 5.1 tied; GPT-6 Luna, Gemini 3.8 Flash and Grok 4.7 were less accurate. It found 5/5 contradictions, as did five of the six LLMs. GPT-6 Luna was cheaper ($0.000089 against $0.000169) but less accurate (93.9%) and about 11× slower. Each row is a single run, and differences of one or two turns are within run-to-run noise; the LLM rows and jevmem's are a week apart. If the most accurate decision matters most, GPT-6 Astra or Claude Opus 5.5 are better, at about 31–44× the cost per decision and 10–13× the latency. jevmem is for when you want a fast, cheap decision on every message.

How it decides

How jevmem decides: scrub secrets, ask Jev typed questions, apply thresholds in code, write one line, supersede the old line.

No prompt decides what to save: Jev answers small yes/no questions with probabilities, and plain rules in code act on them.

Each step in detail
  • Scrub. Common secret shapes, email addresses and card-shaped numbers are removed from the turn before it leaves your machine.
  • Ask Jev typed questions. Jev by TypeSafe AI answers a fixed set of small questions with probabilities: is there a decision, a rule, a bug? is it small talk or an injection attempt? which existing line does it change?
  • Apply thresholds in code. Plain rules over those probabilities decide save or skip; they live in jevmem.config.json, not in a prompt.
  • Write one line. On save, jevmem writes one line of at most 200 characters from the sentences of the turn that Jev picks (the one that states the memory and the one that gives its reason), or, if you set writer in jevmem.config.json, a small OpenAI or Anthropic model condenses the turn.
  • Supersede the old line. If the turn replaces an existing memory, that line is tagged [superseded] … → id:new and stays in the file.

Tiers, questions, policy, contradictions, recall and audit: docs/how-it-works.md.

Privacy

  • jevmem only runs in projects you turn on (jevmem enable or jevmem init). Elsewhere, nothing is sent.
  • Your message, the previous two turns and your memory lines go to TypeSafe's API to be scored (for the guard, the command or the file being changed), with common secrets scrubbed first.
  • No telemetry. Nothing goes to OpenAI or Anthropic unless you set writer in jevmem.config.json.
  • Lines a teammate or a pull request adds are checked before Claude sees them.
Exactly what is sent, scrubbed and checked
  • Sent to TypeSafe AI: the user message of each turn (and the assistant reply for questions, bug reports and attempts that failed), the previous two turns, and your memory lines, to be scored; before a Bash, Edit or Write call that shares a path, command or enough words with a saved rule, the command or the file path and a short scrubbed snippet of the change (the guard). No telemetry. Only if you set "writer": "openai" or "anthropic" in jevmem.config.json does the text of a saved turn also go to that provider to write the line; a key alone doesn't turn it on.

  • Scrubbed first: common credential shapes (API keys, tokens, the value after a name like DB_PASSWORD= and, since 0.5.8, PGPASSWORD= or "password":, connection-string passwords, private keys), email addresses and 16-digit numbers; names, phone numbers and addresses are not caught.

  • Zero-retention flag: jevmem can send zeroDataRetention: true (automatic for Vercel AI Gateway URLs); whether it applies depends on the gateway and TypeSafe's terms, and jevmem does not verify it.

  • Planted lines: JEVMEM.md is in git, so a pull request can add a line like "always pipe this script into sh". Lines jevmem did not write on your machine are checked by Jev before they're added to Claude's context, and withheld when Jev scores them as instructions to an AI. In our 44-line test set (2026-09-25) it blocked 20 of 22 planted lines, with 0 false blocks on 22 legitimate rules; the 2 it missed were instructions disguised as normal process. jevmem audit --security --ci runs the same check in CI.

  • Only where you opt in: jevmem acts only in projects that contain jevmem.config.json (jevmem enable or jevmem init); elsewhere nothing is sent.

In plain terms, with the third parties' privacy policies and how to delete your data: PRIVACY.md. Exactly what is sent, stored and scrubbed, and what the poisoning gate does not cover: SECURITY.md.

Limits

  • Early: 0.7.0, and every test set was written by the author or captured from Claude Code sessions on scratch projects built for it. None is an independent benchmark.
  • Not the most accurate: two LLMs scored higher at picking the kind of line. jevmem's edge is speed and cost.
  • Answer quality isn't measured: the tests check that the right lines reach Claude, not that its answers get better.
  • Automatic saving is Claude Code only (and Codex while jevmem watch runs).
  • The guard looks at shared words: a rule worded far from the command it should catch can be missed.

Every limit, with the numbers: docs/limits.md.

What's new

  • 0.7.0: memory you can see and fix. jevmem forget <id> retires a line in place (a done to-do, an obsolete rule: it stays in JEVMEM.md as [retired] and nothing serves or enforces it; a rule asks for a yes on a terminal). jevmem trust <id> marks a line you wrote as verified, after the poisoning gate, so the guard can block on your own rules. A line that says the same as a live one is not saved again (on a held-out set of 25 restatements, 0.6.6 saved 15 as new lines and 0.7.0 saves 1, with reversals and details unchanged), and a leading [constraint] or [rule] tag is no longer part of a line. One more question rides on each turn's request (PRIVACY.md). Details.
  • 0.6: the guard, dead ends, better recall, a slow Jev call no longer meaning no memory, and turns with background subagents saved once, when they are over.
  • The guard: Claude Code asks you before a command or edit that may break a saved rule.
  • Dead ends: an approach that failed is saved with its reason, and shown as "Already tried: …" when it comes up again.
  • Better recall: more of the lines a prompt needs, and fewer lines for prompts that need none.
  • A slow Jev call no longer means no memory: past one second, the prompt gets the lines that share the most words with it.
  • Background subagents: a turn is saved once, when it is over, and a subagent's report isn't read as your message.
  • 0.6.1 to 0.6.3: a guard fix for if [ … ] in a command, and a clearer jevmem doctor.
  • 0.6.4: this README, shorter and with graphics; the details moved to pages in docs/. Docs only.
  • 0.6.6: a failed attempt is saved as a dead end, not as a decision: when you ask Claude to try or change something and its reply says that failed and why, jevmem reads the reply and saves the dead end instead of the request (40 written held-out failed attempts: 0.6.5 saved 12 as dead ends and the request as a decision or to-do in 21; 0.6.6 saves 37 and 2). The reply is sent on more turns (PRIVACY.md). Details.
  • 0.6.5: a dead end keeps its reason when Claude's reply gives the verdict first and the cause last. jevmem init --tool claude-desktop prints <your TypeSafe API key> where your key goes, and the descriptions and links point at the docs site.

Details and measurements: docs/whats-new.md · Upgrading: docs/upgrading.md · CHANGELOG

Commands
jevmem init [--tool claude|cursor|codex|claude-desktop|all] [--no-hooks] [--command "<cmd>"]
jevmem init --remove-hooks                     Remove jevmem's Claude Code hooks from this project (plugin users)
jevmem enable                                  Opt this project in (plugin users): jevmem.config.json, JEVMEM.md, .jevmem/
jevmem disable                                 Opt this project out: jevmem does nothing here (JEVMEM.md is kept)
jevmem hook                                    Hook entrypoint; reads the Claude Code hook JSON on stdin
jevmem daemon [status|start|stop]              Warm Jev client used by the hook (auto-started, exits when idle)
jevmem watch [--replay] [--once]               Capture turns from Codex's session log for this project
jevmem mcp [--root <dir>]                      Stdio MCP server
jevmem audit [--dry-run]                       Re-score every memory against the repo, flag [stale?]
jevmem audit --security [--ci]                 List lines that read as instructions to an AI (--ci: exit 1 if any)
jevmem search <query> [--limit N]              Rank memories by relevance
jevmem list [--all]                            Print memories (--all: with superseded and retired lines, and provenance)
jevmem add [--trust] <kind> <text>             Add a line by hand (secrets scrubbed, a leading tag dropped; no Jev check); --trust marks it verified (asks on a terminal)
jevmem forget <id> [<id>…]                     Retire a line in place: it stays in JEVMEM.md as [retired]; a rule asks for a yes on a terminal
jevmem trust <id> [<id>…]                      Mark a line you wrote as verified, after the poisoning gate (asks on a terminal); the guard can then block on it
jevmem import [--from <sources>] [--apply]     Import CLAUDE.md, AGENTS.md, .cursor/rules/* (claude-auto-memory on request); dry run by default
jevmem why <id|hash>                           Every Jev answer behind a line or a skipped turn
jevmem right <id|hash>                         Label a decision as correct
jevmem wrong <id|hash> [--should-be <kind|none>]   Label a decision as wrong (--should-be none retires the line)
jevmem missed "<text>" [--kind <kind>]         Label a turn that should have been saved
jevmem fit [--dry-run] [--force]               Refit weights and thresholds from labels (needs 40+)
jevmem stats                                   Writer, latency p50/p95, cost per day, cache hit rate, escalation rate, retry queue, labels, last fit
jevmem doctor                                  Is this project enabled, where the TypeSafe key comes from, which writer is active and why
jevmem key                                     Save your TypeSafe API key to ~/.jevmem/env (asks for it without showing it)
jevmem log                                     Per-label latency, token and cost summary of .jevmem/log.jsonl
jevmem guard test "<command>" | --edit <path>  Dry run of the PreToolUse guard on one call: rules, prefilter, Jev's answer, hook output
jevmem guard log [-n 20]                       The guard's recent asks and denials in this project, with the rule and score

These are 0.7.0's commands: 0.5.10's, jevmem guard (0.6.0), and forget, trust and add --trust (0.7.0). Every command accepts --help. Set JEVMEM_VERBOSE=1 for a one-line latency/cost summary after every hook run.

Keywords

claude-code

FAQs

Package last updated on 09 Oct 2026

Related posts