Skip to main content

Local-first MCP memory backend and governance console for coding agents

Project description

MemoryGuard governance console showing organized shared memory, a supersede chain, and a rollback history

MemoryGuard

Shared memory for coding agents, without shared-memory chaos.
A local-first MCP memory layer that organizes writes automatically and keeps every governance decision reversible.

PyPI version Python 3.10 or newer MIT license 中文文档

Your agents can write freely. MemoryGuard classifies, deduplicates, supersedes, quarantines, and compresses shared memory on every write - then lets you inspect, correct, or roll back the result afterward.

No account. No server. No telemetry. Your memory stays local.

Install in 60 seconds · See the governance loop · What it is and isn't

Why MemoryGuard

Persistent memory solves only half the problem. When several coding agents write into the same context, memory can become duplicated, stale, contradictory, or unsafe to reuse.

MemoryGuard is the local control layer between your coding agents and their shared memory:

Instead of MemoryGuard gives you
A growing pile of unreviewed notes Write-time classification, deduplication, superseding, conflict detection, quarantine, derivation, and compression
Approving every agent write by hand Automatic writes; human review only when you need it
Treating an overwrite as permanent History, evidence, supersede chains, and rollback
Sending project context to another service A local MCP stdio server with local SQLite storage

See the governance loop

A MemoryGuard demo: an agent writes a duplicate memory, MemoryGuard supersedes the stale version, then the operator restores a previous version

Agent writes memory
  -> MemoryGuard MCP write
  -> auto-organize
      classify · deduplicate · supersede · detect conflict · quarantine · compress
  -> active shared memory
  -> governance console
      inspect · correct · merge · lock · restore · roll back

The console is not an approval queue. Agents keep moving; you govern the outcome with evidence when it matters.

Install in 60 seconds

pip install agent-memguard

Choose the coding agent you use. Each command adds MemoryGuard as an MCP server and writes its instruction file.

# Claude Code
memoryguard source add . && python -m memoryguard.provider_adapters install claude

# Codex
memoryguard source add . && python -m memoryguard.provider_adapters install codex

# Cursor
memoryguard source add . && python -m memoryguard.provider_adapters install cursor

Then restart your agent and verify the environment:

memoryguard doctor
memoryguard mcp-status

Need a desktop window for the governance console?

pip install "agent-memguard[gui]"

For explicit configuration and provider-specific behavior, see the Claude Code, Codex, and Cursor guides.

What you can govern

MemoryGuard evidence views for a conflict, a quarantined secret, a supersede chain, and version history

Signal What you can do
Duplicate or stale memory See the supersede chain and restore the prior version if needed
Conflicting memories Surface the conflict and resolve it deliberately
Secrets, tokens, or credentials Quarantine them instead of leaving them in active shared memory
A wrong governance decision Inspect its history and roll the shared memory back to a version snapshot
Multiple coding agents Bind agents to a governed shared-memory group

What MemoryGuard is - and isn't

MemoryGuard is a local MCP memory backend and governance console for coding agents. It provides a shared source of truth and organizes writes as they arrive.

It is not a cloud service, an account system, or a human gate that blocks every memory write. It also does not pretend every agent's native memory can be disabled: provider support is reported as redirected, observed, or unsupported where appropriate.

Architecture

Layer Responsibility
Evidence layer Agent-native memory, files, documents, and external MCP descriptors; raw inputs, not governance truth
Memory layer MemoryGuard's local MCP shared-memory backend; the governed shared source of truth
Governance layer GUI and CLI for observation, evidence, corrections, and reversible changes

Core surfaces

Surface Use it for
MCP memory backend Read, search, write, update, delete, and inspect shared-memory status
Auto-organizer Classify, deduplicate, supersede, detect conflicts, quarantine, derive, and compress on write
Governance console Review raw writes, conflicts, quarantine, supersede chains, and versions
Provider adapters Set up Claude Code, Codex, or Cursor from one command
CLI Audit local sources, manage authorized inputs, inspect reports, and manage memory builds/releases

The complete MCP tool reference and CLI command reference are below for evaluation and integration work.

CLI commands
Command Description
audit [path] Read-only scan; generate a report
open [path] Open the latest report in a window
explain <finding_id> Explain a finding's evidence and risk
plan <finding_ids...> Generate a minimal fix plan without writing
apply <plan_id> Apply a plan: backup, patch, and rescan
verify Rescan and compare before/after
undo <change_id> Restore from backup and re-verify
source <action> Manage authorized sources
scan Read-only scan and coverage ledger
import <action> <bundle> Preview or create an offline import bundle
memory <action> Memory build, verify, and release rollback workflows
doctor Diagnose installation and environment
mcp-status Inspect MCP shared-memory status
MCP tools
Group Tools
Memory backend memoryguard_memory_read, memoryguard_memory_search, memoryguard_memory_write, memoryguard_memory_update, memoryguard_memory_delete, memoryguard_memory_status
Audit and scan memoryguard_audit, memoryguard_explain, memoryguard_list_sources, memoryguard_scan_summary, memoryguard_neuron_graph, memoryguard_import_preview, memoryguard_build_plan
Agent binding memoryguard_binding_create, memoryguard_binding_list
External MCP memoryguard_external_mcp_list, memoryguard_external_mcp_import
Document extraction memoryguard_extract_memories, memoryguard_accept_candidates
Semantic and provider memoryguard_semantic_check, memoryguard_provider_install

Privacy and safety boundaries

  • MemoryGuard runs as a local MCP stdio server; it requires no account, remote server, or telemetry.
  • Shared memory is stored locally in SQLite under .memoryguard/.
  • Source scanning is read-only by default. Changes use explicit plans, backups, rescans, and undo paths.
  • A quarantined memory is deliberately kept out of active shared memory until you decide what to do with it.

Roadmap

  • Now: local MCP backend, auto-organization, governance console, provider adapters, and rollback.
  • Later: enhanced governance signals such as decay, derivation, and governance reports. No committed date.
  • Later: team and enterprise capabilities after proven demand. No committed date.

Contributing

Issues and pull requests are welcome. Read CONTRIBUTING.md; by submitting a pull request, you agree to the CLA.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent_memguard-0.1.1.tar.gz (197.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agent_memguard-0.1.1-py3-none-any.whl (207.8 kB view details)

Uploaded Python 3

File details

Details for the file agent_memguard-0.1.1.tar.gz.

File metadata

  • Download URL: agent_memguard-0.1.1.tar.gz
  • Upload date:
  • Size: 197.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.4

File hashes

Hashes for agent_memguard-0.1.1.tar.gz
Algorithm Hash digest
SHA256 cbb8c51124d4285211a0b2f821e54542f22107c4015d9573f35a73b1010c3140
MD5 7e27e650e93f238e72781ecbab9597c7
BLAKE2b-256 f103de30af040d8baaa0e19ebbe598cff76ac6b8747d76604981922e4f93728b

See more details on using hashes here.

File details

Details for the file agent_memguard-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: agent_memguard-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 207.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.14.4

File hashes

Hashes for agent_memguard-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 4ff91824dd1589b4e4418b1fd79307e93ec93f94baae6bb053061aa096779b1e
MD5 593f3028b5158aeb275f1a007d293882
BLAKE2b-256 f69b440ae00a5302794a0cc5aec3c1060a68c6256cc27474a100d7c8d8f9a38a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page