Anti-poisoning memory store for agents: provenance, versioning, quarantine gate
- ✓Open-source license (MIT)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
git clone https://github.com/Icaro0310/devin-memory && cp devin-memory/*.md ~/.claude/agents/Resumen de Subagents
<div align="center">
<img src="assets/banner.svg" alt="devin-memory" width="100%"/>
<a href="https://github.com/Icaro0310/devin-memory/actions/workflows/ci.yml"><img src="https://github.com/Icaro0310/devin-memory/actions/workflows/ci.yml/badge.svg" alt="ci"/></a>
<a href="https://pypi.org/project/devin-memory/"><img src="https://img.shields.io/pypi/v/devin-memory" alt="PyPI"/></a>
<a href="https://scorecard.dev/viewer/?uri=github.com/Icaro0310/devin-memory"><img src="https://api.scorecard.dev/projects/github.com/Icaro0310/devin-memory/badge" alt="OpenSSF Scorecard"/></a>
<a href="https://m8ven.ai/mcp/icaro0310/devin-memory?s=readme"><img src="https://m8ven.ai/badge/mcp/icaro0310/devin-memory" alt="M8ven Score"/></a>
</div>
# devin-memory
> **Unofficial community project.** Not affiliated with, endorsed by, or
> sponsored by Cognition AI. "Devin" is a trademark of Cognition AI.
**[Português (BR)](README.pt-BR.md)** · English
An anti-poisoning memory store for Devin: durable facts with provenance,
versioning, and a quarantine gate — so agent memory can't be silently
corrupted by a bad session or injected content.
## The problem
Agent memory is a poisoning vector. Any tool that persists "facts" between
sessions can be corrupted by a single bad session — an injected instruction
or a pasted secret becomes a trusted belief in every future session, with no
review step and no way to answer *"where did this come from?"*.
## Prior art
- The **Devin memory MCP** (`retain`/`recall`/`reflect` over
`.devin/memory/memories.jsonl`) — append-only, no screening, no session
provenance. `devin-memory` exports to that exact line shape.
- **MemGPT / LangChain memory** — persistence layers that optimize for
recall, not for auditing or distrusting what was stored.
`devin-memory` adapts the memory-store idea; it adds the parts those tools
don't have: a quarantine gate and provenance back to real session rows.
## What makes it Devin-native
1. **Side-by-side:** every entry can carry `source_session_id` +
`source_rowid`, auditable against Devin's `sessions.db` via
`devin-internals`' read-only store — the memory MCP cannot verify that a
claimed source session (or a specific message row) ever existed. The
quarantine gate also screens every write for secret and injection shapes.
2. **No-Devin:** without `sessions.db` there is no session provenance to
audit — the extra disappears.
3. **One sentence:** *it's a memory store that remembers where each memory
came from — and quarantines suspicious ones until a human releases them.*
## Install
Python ≥ 3.10 and `pipx` are required. **Windows (PowerShell):** install `pipx` with `py -m pip install --user pipx`, run `py -m pipx ensurepath`, then reopen the terminal. **Linux (Debian/Ubuntu):** run `sudo apt install pipx python3-venv` and `pipx ensurepath`; reopen the terminal. Other Linux distributions should install `pipx` using their package manager.
```bash
pipx install "devin-memory @ git+https://github.com/Icaro0310/devin-memory.git"
```
For development:
```bash
pip install -e ".[dev]"
pytest
```
## Usage
```bash
# Store a fact (screened on write; suspect content lands in quarantine)
devin-memory retain "CI is green on Windows + Linux" --tags ci,status
devin-memory retain "..." --source-session <session-id> --source-rowid <n>
devin-memory retain "..." --workspace /path/to/project # scope to a workspace
# Keyword-ranked recall — returns active entries only
devin-memory recall "ci status" [--json] [--limit 5] [--tags a,b]
# Quarantine lane: list, mark an existing entry, or release one
devin-memory quarantine # list with reasons
devin-memory quarantine <id> [--reason manual:x] # mark entry as quarantined
devin-memory quarantine --release <id> # human override -> active
# Contradictions: a conflicting retain is linked, not overwritten
devin-memory conflicts [--json] # (newer, older) pairs; resolve with
# supersede / retract / quarantine <id>
# Mine a session for durable knowledge -> proposed entries (inactive
# until reviewed); extraction is heuristic — see "Limitations"
devin-memory extract <session-id> --sessions-db path/to/sessions.db
devin-memory extract --latest --sessions-db path/to/sessions.db [--auto-approve]
devin-memory list --status proposed # review queue
devin-memory approve <id> # proposed -> active
# Context block for a UserPromptSubmit hook — active entries only,
# filtered by workspace + machine profile, bounded by ~4 chars/token
devin-memory prime [--workspace PATH] [--max-tokens N]
# Versioning and housekeeping
devin-memory supersede <id> "corrected fact"
devin-memory retract <id>
devin-memory list [--status active|proposed|quarantined|retracted] [--json]
# Audit an entry's provenance against a real sessions.db (read-only)
devin-memory verify <id> --sessions-db path/to/sessions.db
# Export active memories to a memory-MCP-compatible JSONL
devin-memory export --out memories.jsonl
```
## MCP server
<!-- mcp-name: io.github.Icaro0310/devin-memory -->
`devin-memory` is also a real MCP server (stdio) — the same retain/recall
pipeline with the quarantine gate on every write, callable from Devin,
Claude Desktop, Cursor or any MCP client:
```bash
pipx install "devin-memory[mcp] @ git+https://github.com/Icaro0310/devin-memory.git"
```
Client config:
```json
{
"mcpServers": {
"devin-memory": {
"command": "devin-memory-mcp",
"args": ["--db", "/path/to/memory.db"]
}
}
}
```
Tools: `retain`, `recall`, `screen` (dry-run the gate, no write), `list`,
`retract`, `supersede`, `quarantine`, `release`, `approve`, `conflicts`,
`prime`, `verify`, `extract`. Every tool returns structured data or a
`{"error", "detail"}` object — nothing raises through the transport.
`DEVIN_MEMORY_DB` works as an alternative to `--db`.
## Learn from sessions with `devin-learning`
This companion CLI extracts candidate lessons from a `sessions.db` and writes
reviewable skill drafts. It does not install drafts into a workspace by default.
```bash
devin-learning extract --sessions-db path/to/sessions.db --out ./learning-drafts
devin-learning review --out ./learning-drafts
# After reviewing drafts, explicitly allow output to a live skill directory:
devin-learning extract --sessions-db path/to/sessions.db --out .devin/skills --apply
```
`review` is a dry-run unless `--apply` is given; `review --apply` moves rejected
drafts under `_rejected/`. The extractor reads session contents, so keep its
output private until reviewed.
## Memory states
`active` · `proposed` (extracted, awaiting `approve`) · `quarantined`
(screened or manually flagged, awaiting `release`) · `retracted` (withdrawn or
superseded). Only `active` entries surface in `recall`/`prime`/`export` —
quarantined content is never printed and never recalled.
## Conflicts, extraction and prime (heuristics)
- **Conflicts** — a `retain` that gives the opposite directive about the same
normalized subject as an existing active entry is stored alongside it with a
`conflicts_with` link (`devin-memory conflicts`). The heuristic compares a
stop-word-stripped "subject key" plus affirmative/prohibitive polarity — it
deliberately misses reworded contradictions rather than mislinking facts.
- **`extract`** scans one session's `message_nodes` (read-only via
devin-internals) for durable-knowledge signals — user corrections
("na verdade", "actually", "the right way"), preferences ("always", "never",
"sempre", "nunca"), discovered commands (backticked known tools) and paths.
Candidates are screened like any write: clean ones land `proposed`,
suspect ones `quarantined`. `--auto-approve` skips the review step.
- **`prime`** emits a compact `# devin-memory: recalled context (heuristic)`
block sized for a prompt hook. Entries scoped with `retain --workspace`
only prime inside that workspace; entries written under a different
machine profile never prime (the profile defaults to `corporate` —
fail-closed).
The store is `./memory.db` by default — override with `--db` or
`DEVIN_MEMORY_DB`. It is the only store this tool writes to; Devin's
`sessions.db`, `acp-messages/*.db` and `state.vscdb` are only ever read.
## Works with Devin alone (Devin-only mode)
devin-memory keeps a local memory store (JSONL) with provenance tracking and
a quarantine lane — no external memory service, no network calls. Both console
scripts (`devin-memory` and `devin-learning`) run on your machine only.
Honest caveat: write-time screening is a heuristic, not a guarantee — suspect
entries land in quarantine for **human review**, so keep that habit.
## Platform support
The memory store uses an explicit local SQLite path and the session database is
provided with `--sessions-db`; no platform-specific path is assumed. Windows
and Linux are supported and covered by CI.
## Limitations
- **Extraction is heuristic, and proposed by default.** `extract` lifts
keyword-shaped sentences from one session into a `proposed` review queue —
nothing becomes active without `approve` (or `--auto-approve`). For a
richer lesson pipeline see `devin-learning`.
- **The screen is a filter, not a guarantee.** Pattern-based secret detection
and injection heuristics have both false positives (→ quarantine, one
command to release) and false negatives. Run dedicated scanners
(gitleaks, `devin-redact`) too — this complements them.
- **Recall ranking is keyword-based**, deterministic and documented — no
embeddings or semantic search in M1.
- **Provenance is recorded, not self-verifying.** `retain` stores the
claimed `source_session_id`/`source_rowid`; `verify` audits it against a
real `sessions.db` afterwards. A bad actor can claim fake provenance —
the point is that it is *checkable*.
- **Quarantined supersessions still retire the old version.** If the
replacement quarantines, review the queue (`quarantine --release`).
- *Lo que la gente pregunta sobre devin-memory
¿Qué es Icaro0310/devin-memory?
+
Icaro0310/devin-memory es subagents para el ecosistema de Claude AI. Anti-poisoning memory store for agents: provenance, versioning, quarantine gate Tiene 1 estrellas en GitHub y su última actualización registrada es del 2026-10-04.
¿Cómo se instala devin-memory?
+
Puedes instalar devin-memory clonando el repositorio (https://github.com/Icaro0310/devin-memory) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar Icaro0310/devin-memory?
+
Nuestro agente de seguridad ha analizado Icaro0310/devin-memory y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene Icaro0310/devin-memory?
+
Icaro0310/devin-memory es mantenido por Icaro0310. La última actividad registrada en GitHub es del 2026-10-04, con 5 issues abiertos.
¿Hay alternativas a devin-memory?
+
Sí. En ClaudeWave puedes explorar subagents similares en /categories/agents, ordenados por popularidad o actividad reciente.
Despliega devin-memory en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/icaro0310-devin-memory)<a href="https://claudewave.com/repo/icaro0310-devin-memory"><img src="https://claudewave.com/api/badge/icaro0310-devin-memory" alt="Featured on ClaudeWave: Icaro0310/devin-memory" width="320" height="64" /></a>Más Subagents
The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
The agent that grows with you
Java 面试 & 后端通用面试指南,覆盖计算机基础、数据库、分布式、高并发、系统设计与 AI 应用开发
Build Agentic workflows, RAG pipelines, with rich AI model and tool support on one collaborative workspace. Deploy on cloud, VPC, or self-hosted, so teams move from prototype to production without rebuilding the stack.
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
The agent engineering platform.