
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
slowave
Advanced tools
Living memory layer across your coding agents and AI tools.
Supports: Claude Code, Codex, OpenCode, Cursor, Cline, Windsurf/Devin Desktop, Claude Desktop
AI agents have large context windows, but that context ends with your current session. Open a new session, switch from Claude Code to Codex, and you have to restate the same decisions, constraints, and failed attempts.
Slowave gives your agents one local, shared memory, without requiring a separate LLM for memory maintenance.
Slowave is an adaptive memory layer that approaches agent memory from a specific angle:
Reasoning and memory form a continuous feedback loop.
graph LR
LLM["Reasoning<br/>(Claude, Codex, etc.)"]
MEM["Memory<br/>(Slowave)"]
LLM -->|Feedback| MEM
MEM -->|Retrieve| LLM
MEM -->|Adapt| MEM
Slowave retains what helps agents achieve their goals, weakens what does not, and continuously adapts based on use. It does this through a continuous feedback loop between your agent and its memory:
remember → recall → use → feedback → reinforce / weaken → decay
Over time, your agent’s feedback shapes what Slowave returns, and your memories become reusable context for your agent to achieve its goals.
Memory is continuously reshaped by use rather than a static collection of facts waiting to be retrieved.
The first useful payoff is simply not having to repeat the same constraint in the next task.
Over time, the way you work becomes reusable context for your agent.
See platform coverage and manual steps.
pipx install slowave
slowave setup --dry-run
slowave setup
The quick start configures every detected client. To configure just one client at a time, see the installation reference.
[!IMPORTANT] No LLM API key required.
To remove Slowave, see the removal guide.
Slowave is transparent to your work. You keep working with your agent as usual.
Slowave is strictly connected to your agent in both directions:
What you will see while working with your agent:
Optionally you will see:
Slowave does not decide whether a claim is true or important. Your agent makes that judgment and reports whether retrieved memory helped, was irrelevant, or became stale. Slowave maintains the resulting local memory.
Start the local dashboard with:
slowave dashboard
In the dashboard, inspect:
Track memory health and retrieval effectiveness with:
Client coverage is actively expanding. Suggest more integrations or report broken ones with setup details.
✅ = manually verified · ⬜ = pending verification
| Client | macOS | Linux | Windows | Setup |
|---|---|---|---|---|
| Claude Code | ✅ | ✅ | ✅ | slowave setup --client claude-code |
| Cline | ✅ | ✅ | ✅ | slowave setup --client cline |
| Cursor | ✅ | ✅ | ✅ | slowave setup --client cursor ¹ |
| Windsurf | ✅ | ✅ | ✅ | slowave setup --client windsurf |
| Claude Desktop | ✅ | ✅ | ✅ | slowave setup --client claude-desktop ¹ |
| OpenCode | ✅ | ✅ | ✅ | slowave setup --client opencode |
| Codex | ✅ | ✅ | ✅ | slowave setup --client codex |
| All the above | slowave setup |
¹ requires one manual paste after setup
[!IMPORTANT] The default embedding model downloads from Hugging Face on first use (~45 MB, cached locally). Subsequent runs work offline.
Memory is stored in plaintext in the current OS user's application-data directory. Slowave does not send it to a hosted memory service. See runtime data location.
Slowave works through 5 simple MCP tools:
Activate: start a task and load relevant memory.Remember: save a fact, decision, preference, or instruction.Recall: search memory during a task.Feedback: mark retrieved memory as useful, irrelevant, or stale.Commit: save the task outcome and any reusable procedure.A background worker consolidates relevant memories and procedures.
flowchart LR
A[Agent task] --> B[1. <i>activate</i><br/>start session]
B --> C[Scoped retrieval<br/>and session]
C --> D[Agent reasoning]
D --> E[2. <i>remember</i><br/>durable claims]
D --> F[3. <i>recall</i><br/>mid-task lookup]
C --> G[4. <i>feedback</i><br/>target assessments]
F --> G
E --> H[5. <i>commit</i><br/>outcome and verification]
G --> H
H --> I[(Local SQLite<br/>raw events and evidence)]
I --> J[Offline consolidation]
J --> K[(Episodes, prototypes,<br/>schemas, relations)]
K --> C
See architecture.md and design.md for details.
[!IMPORTANT] Slowave is public beta software. APIs, configuration, and storage schema may change, and migrations are not guaranteed before stable release.
The current evaluation notes report preliminary retrieval-evidence results, methodology, limitations, and commands for running new evaluations. They do not claim end-to-end agent accuracy or a comparison against other memory systems. See benchmarks.md before treating any result as a production-quality claim.
Slowave is open source under the AGPL-3.0-or-later license.
Contributions are welcome, especially in:
See CONTRIBUTING.md before submitting a pull request.
Slowave is open source under the GNU AGPL-3.0-or-later license.
FAQs
Brain-inspired long-term memory for AI agents — zero LLM during ingest or retrieval
The pypi package slowave receives a total of 234 weekly downloads. As such, slowave popularity was classified as not popular.
We found that slowave demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.