
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
cp-memory-mcp
Advanced tools
Local-first, governable memory for AI coding agents.
Remember project rules across sessions, recall only what matters, and correct bad memory without hiding history.
简体中文 | English
For reproducible package, protocol and recall checks, see verification evidence and limits.
~/.cp-memory/memory.db by default.
With Python 3.10+ and uv installed, any stdio MCP client can start CP Memory with:
uvx cp-memory-mcp
The public package passed a clean-cache MCP handshake with all 40 tools and a write/search/correct flow. See MCP client setup for Codex, Claude Code, Cursor, VS Code, and Gemini CLI examples.
For the enhanced Codex integration with lifecycle Hooks and Skills, install the plugin:
codex plugin marketplace add CJhuochai/cp-memory
codex plugin add cp-memory@cp-memory
Restart Codex after installation and approve the lifecycle Hooks if prompted.
CP Memory is a local-first memory plugin for Codex. It stores facts, preferences, ongoing work, episodes, decisions, and conversation checkpoints in a local SQLite database, then restores relevant context through MCP tools and lifecycle hooks.
The goal is not to remember as much as possible. The goal is memory that remains trustworthy after long-term use: explainable, reviewable, correctable, and governable.
repo:, project:, and workspace: scopes.You tell Codex:
Remember this: releases for this project must start on a branch, run tests, and merge through a PR.
In a later session, you ask:
What are the release rules for this plugin?
CP Memory restores the relevant memory from the local primary store first, and Codex follows that rule. If the memory is wrong, you can mark it wrong, mark it stale, or write a corrected version.
See more anonymized examples in docs/examples.md.
For a GIF, short video, or launch post, use the sanitized 30-second demo script.
For any stdio MCP client, use the verified public package:
uvx cp-memory-mcp
Client-specific commands and JSON files are in docs/mcp-clients.md.
For Windows, the recommended path is GitHub Marketplace installation:
codex plugin marketplace add CJhuochai/cp-memory
codex plugin add cp-memory@cp-memory
Restart Codex after installation. If Codex asks you to trust hooks, approve the CP Memory lifecycle hooks in the hooks view.
For macOS/Linux, use the source installer. It creates a private Python runtime for the plugin and installs the MCP dependency:
git clone https://github.com/CJhuochai/cp-memory.git
cd cp-memory
sh ./install.sh
Restart Codex when it finishes. Do not treat GitHub Marketplace installation on macOS/Linux as an equivalently verified path: Marketplace does not run install.sh, so it does not create that private runtime.
| Platform | Recommended installation | Verified coverage |
|---|---|---|
| Windows | GitHub Marketplace; install.ps1 for local development | Unit tests, isolated installation validation, and GitHub Actions CI passed |
| macOS | Source installer: sh ./install.sh | GitHub Actions macOS CI passed unit tests and isolated install/MCP startup validation |
| Linux | Source installer: sh ./install.sh | GitHub Actions Ubuntu CI passed unit tests and isolated install/MCP startup validation |
Manual smoke testing of real Codex desktop Hook injection on macOS/Linux is still pending access to physical devices. This release is accepted through three-platform CI; the boundary does not affect the installer and MCP-startup checks already covered, but it is not a substitute for full desktop manual acceptance.
memory.db, logs, private summaries, or environment files.If you have seen other memory projects, start with docs/comparison.md. CP Memory's main difference is Codex lifecycle integration plus memory governance, not just storage and search.
See docs/roadmap.md for future directions. The roadmap prioritizes local-first behavior, explainability, correctability, and privacy safety.
See CHANGELOG.md for version history.
Windows users normally do not need to run install.ps1. It is mainly for local development, refreshing the personal marketplace cache, and migrating old global hook wiring from earlier versions.
For local macOS/Linux development, run:
sh ./install.sh
sh ./scripts/test-install.sh
Python 3 with python3 on PATH is required. The installer creates a private virtual environment in the plugin directory and installs runtime dependencies; this is the currently verified installation path for macOS/Linux.
Run the test suite:
python -m unittest discover -s tests -p test_cp_memory.py
Validate the installer in an isolated temporary profile without touching your real Codex configuration:
powershell -ExecutionPolicy Bypass -File .\scripts\test-install.ps1
MIT
FAQs
Local-first, governable memory for AI coding agents
The pypi package cp-memory-mcp receives a total of 65 weekly downloads. As such, cp-memory-mcp popularity was classified as not popular.
We found that cp-memory-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.