
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Git-native project memory for AI coding agents. Deterministic local recall and evidence-governed evolution for Claude Code, Codex, Cursor, and Gemini CLI.
Open-source project memory for Claude Code, Codex, Cursor, Gemini CLI, and other AI coding agents — local, deterministic, reviewable, and safely self-improving.
Git-native · AI agent memory · local recall · evidence-governed · Apache-2.0
English · 简体中文 · 繁體中文 · 日本語 · 한국어 · Español · Français · Deutsch · Português (BR)
Most AI agent memory systems optimize for remembering more. OwnMem starts with a different question: who owns project knowledge, who may change it, and how can a bad memory be stopped before it changes a coding agent's actions?
| Advantage | What it means in practice |
|---|---|
| The repository owns memory | Readable Markdown in .ownmem/ travels through clone, review, and rollback with the code. |
| One memory serves many agents | Claude Code, Codex, Cursor, Gemini CLI, Grok CLI, and other hosts share one source of project truth. |
| Deterministic local recall | Default recall makes no model or network call; the same query, config, and snapshot produce the same ranking. |
| Evidence before authority | Content cannot declare itself trusted. Independent receipts and live evidence checks decide delivery. |
| Bounded growth | Schemas, quotas, duplicate gates, lifecycle rules, and audits keep memory from becoming a second abandoned wiki. |
| Low-risk automation, review for impact | Replay-proven R0 retrieval metadata can evolve unattended; prose, policy, and higher-risk changes cannot. |
OwnMem separates writing experience from delivering it to an agent:
The differentiator is not one ranking formula. OwnMem turns coding-agent memory into a verifiable retrieval and evolution protocol:
| Mechanism | How it is enforced |
|---|---|
| Evidence-carrying memory | Content hash, evidence root, lifecycle, applicability, risk, and predecessor receipts determine whether text may enter context. |
| Counterfactual promotion gate | Automation must prove baseline miss, candidate-only recovery, and zero regression on the previously passing corpus. |
| Risk from change surface | Risk is derived from what changed and what it can affect; an agent cannot downgrade its own proposal. |
| Content-addressed compensating rollback | Automatic edits carry a verified inverse operation; failures or harmful outcomes restore the exact previous bytes without erasing history. |
| Memory-poisoning quarantine | Candidates, content, authority, and evidence are separate trust domains; retrieval never grants permission to act. |
| Selective delivery | Insufficient evidence produces advisory, quarantine, or abstention instead of invented confidence. |
| Immutable compiled snapshots | Markdown, graph edges, ranking identity, and trust state become one reproducible runtime input. |
| Three anti-pollution ledgers | Retrieval correctness, user/host-confirmed outcomes, and agent self-attribution never impersonate one another. |
Read the detailed technical design and research mapping.
Requires Node.js 20.6 or newer. Run this inside the repository that should own the memory:
npm install --save-dev ownmem
npx ownmem init --locale auto --hosts claude,codex --layers dashboard --hook
Reopen the agent after initialization. OwnMem creates .ownmem/ and edits only managed marker regions in host files. Use --hosts claude, --hosts codex, --hosts cursor, or --hosts gemini when only one adapter is needed; preview changes with npx ownmem init --check.
After setup, keep working in plain language:
“Remember this: staging deployment timeouts come from the pool cap, not too few workers. Check both together next time.”
“Before changing this, check whether the project memory has seen the same failure.”
The host recalls before scoped work and schedules one locked, debounced evolution pass at the end of a turn. You normally do not need to chain promotion, trust, audit, or compile commands. Open the local console or inspect the coordinator when you want visibility:
npx ownmem dashboard --open
npx ownmem evolve status
npx ownmem evolve run --force
OwnMem automates the part it can prove, not the part that merely sounds plausible.
| Good fit | Choose another system when |
|---|---|
| A team wants project knowledge reviewed and migrated with code. | You need a cross-repository personal profile or global user memory. |
| Several coding agents rotate through one repository. | You need to capture every conversation automatically with no evidence or risk boundary. |
| Local, reproducible recall with no retrieval API bill matters. | You need large-scale cloud vector search or a real-time global knowledge graph. |
| Bad memory must be attributable, rejectable, and reversible. | Maximum recall volume matters more than governance. |
OwnMem does not claim these foundations as inventions. Its contribution is their composition into an executable protocol for repository memory:
These citations describe the research lineage; they do not imply that the papers implement OwnMem or that OwnMem reproduces their experiments.
| Document | Purpose |
|---|---|
| Architecture | Package boundaries, snapshots, trust, and evolution |
| Technical design | Mechanisms, threat model, and research mapping |
| Plugins | Optional host plugin installation |
| Updating | Safe repository updates and version migrations |
| Privacy | Local data and optional channel boundaries |
| Changelog | Version history |
| License | Apache-2.0 |
OwnMem is open source. Reproducible issues and pull requests are welcome.
FAQs
Git-native project memory for AI coding agents. Deterministic local recall for Claude Code, Codex, Cursor, and Gemini CLI.
The npm package ownmem receives a total of 218 weekly downloads. As such, ownmem popularity was classified as not popular.
We found that ownmem demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.