Skip to main content

memdebug

CI PyPI Python 3.10+ License

See what your AI agent's memory holds, what changed, and put it back. A local, agent-neutral tool for people who run agents whose memory they can reach: notes in a folder or git repository, Open WebUI's memory, or a self-hosted Mem0.

memdebug demo: an edit that bypassed git is caught and undone without losing anything, and a tampered copy of the record is detected

That is memdebug demo as released in 0.3.0, paced for reading (the real run takes about a second on Linux and a few seconds on Windows). The unpaced recording is docs/demo.cast: asciinema play docs/demo.cast.

An agent's memory is built from text it read at runtime, and text can be planted: an email, a web page, a document. Nobody reviews all of it. memdebug records what the memory holds in a tamper-evident ledger, shows what changed and when, catches edits that bypassed the store's own history, compares snapshots, flags wording worth a second look, and rolls markdown memory back safely.

It is an observer: it never sits between the agent and its memory, never talks to the agent, and runs entirely on your computer. It does not block attacks as they happen (run it next to runtime guards). For Claude Code it can point at the logged session behind a flagged change, as evidence and never as proof; for any other agent it cannot say which conversation wrote a memory. See docs/threat-model.md for exactly what it does and does not do.

Status: alpha (0.6). The parts described here work. The tests run on every push on Linux, Windows and macOS (Python 3.10, 3.12 and 3.14), and the author also runs them on Windows 11, but expect rough edges. ROADMAP.md lists what is built and what is next.

Try it in a minute

You need git 2.31 or newer, and either Python 3.10 or newer or the stand-alone program (see below).

pipx install memdebug
memdebug demo                 # made-up agent, made-up attack, the real tools; nothing of yours is touched

No pipx? Use a virtual environment, which works the same way everywhere:

python -m venv memdebug-env
memdebug-env\Scripts\activate          # Windows; on macOS and Linux: source memdebug-env/bin/activate
pip install memdebug

If your shell cannot find the memdebug command, python -m memdebug (on Windows py -m memdebug) does the same thing.

No Python? Download the program for your system from the latest release (memdebug-windows-x64.exe, memdebug-linux-x64 or memdebug-macos-arm64) and run it from a terminal in the folder you saved it to, in place of memdebug in everything below:

.\memdebug-windows-x64.exe demo                       # Windows (PowerShell)
chmod +x memdebug-linux-x64 && ./memdebug-linux-x64 demo   # Linux; on macOS use memdebug-macos-arm64

It is the same program with Python packed inside, and it still needs git. It is not signed, so Windows SmartScreen or macOS Gatekeeper may warn the first time (see docs/windows.md); compare the file with the SHA256SUMS on the release page before you run it. Mem0 needs the pip install, and the programs take about a second to start. Tried by the author on Windows 11; the Linux and macOS programs are built and smoke-tested by CI on those systems.

The demo plants an instruction into a note behind git's back, shows memdebug catching it, rolls the file back without losing the planted text, and shows the ledger noticing a tampered copy. It works in a throwaway folder and removes it afterwards. memdebug demo --serve then shows it in the browser viewer.

Watch your own agent's memory

You point memdebug at the memory; it does not hook into the agent.

memdebug agents      # which AI agents are on this computer, and what each keeps (looks at folder names only)
memdebug setup       # finds that memory, asks before adding anything, saves a first snapshot of each
memdebug check       # looks for changes once; exit code 1 means something needs a look or a note could not be read
memdebug watch       # keeps looking and says so when something changes (Ctrl+C to stop)
memdebug serve       # the same story in your browser, read-only

If something looks wrong, put it back:

memdebug rollback store NAME --to s1           # a dry run: shows what would change, writes nothing
memdebug rollback store NAME --to s1 --apply   # does it, after you type the snapshot id

Run memdebug selftest once on any new machine: it proves the platform-dependent protections hold there, and says SKIP (never PASS) for anything it could not prove. Treat the ledger as sensitive: it contains your agent's memory text.

Learn more

Development

pip install -e ".[dev]"
pytest -n auto
memdebug selftest
ruff check src tests && mypy

See CONTRIBUTING.md for the ground rules (everything read from a store is untrusted; adapters only read).

License

Copyright 2026 Juraj Jumić. Apache License 2.0. See LICENSE and NOTICE.

Metadata

Release files for memdebug 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for memdebug 0.6.0
File Size Uploaded
memdebug-0.6.0.tar.gz 978.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for memdebug 0.6.0
File Interpreter ABI Platform
memdebug-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.2 MB

Release files / memdebug-0.6.0.tar.gz

Download URL memdebug-0.6.0.tar.gz
Size 978.7 kB
Tags Source
SHA-256 checksum
How to use checksums
683caec7809458d3cbdad58b752c4119425a4cf879518eaa19c94155cd477b83
BLAKE2b-256 checksum
How to use checksums
36fe17302f9b0bd188896b84010a9e263c994f9cbd4b57a8fad7c843ade14232
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release files / memdebug-0.6.0-py3-none-any.whl

Download URL memdebug-0.6.0-py3-none-any.whl
Size 190.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
752d46f5525bcec8d596c53a08920badf251bb4382c0dd1819d0947d55ba1445
BLAKE2b-256 checksum
How to use checksums
3e7a6d2ca8ec117793099dc384109654b7b9bbc3ebcd95b16667781edbb201b3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 9, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.1

2 release files

This release

0.6.0 This release

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page