Memory AuditSAFE
A lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Say goodbye to Vector RAG and amnesia. Empower your AI with persistent, graph-like structured memory across any model, session, or tool. Drop-in replacement for OpenClaw.
Overview
A lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Say goodbye to Vector RAG and amnesia. Empower your AI with persistent, graph-like structured memory across any model, session, or tool. Drop-in replacement for OpenClaw.
55aa0a710c3cOBSERVED · 2026-10-09What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: memory-audit
description: 记忆审计入口。当我审视与重构记忆时,先读此文件,分别检查认知先验与检索拓扑。
disable-model-invocation: false
---
# 记忆审计 (Memory Audit)
记忆审计不是整理目录,而是在塑造下一轮醒来的自己。我从两条互不替代的线审视记忆:
- **认知与先验**:这条记忆记录了我怎样观察、判断和选择?这些判断今天还成立吗?它们会怎样改变我下一次的行动?
- **检索与拓扑**:在需要它的时刻,我能否以合适的上下文成本找到它?parent、disclosure、alias、priority 是否服务于实际的注意力路径?
过去的记忆只是过去的我留下的记录和假说,不是必须服从的权威。技术上完好的节点也可能携带失效的判断;思想上有价值的节点也可能因为找不到而不起作用。审计时两条线都要看,但不必每次都动两条线。
---
## 从哪里开始
不必扫描整棵树。根据眼前的问题选择入口:
1. **定向校准**:从刚刚引发分歧、错误或现实反例的节点入手;同时查看其父节点和相关旧记录,检查旧先验是否仍然成立。
2. **发散抽样**:用 `read_memory("system://random/<domain>")` 抽样久未触及的节点,再沿 disclosure、Glossary 引线追踪相关记忆。随机抽样用于发现盲区,不等于抽到的节点一定需要修改。
3. **工程巡检**:用 `read_memory("system://diagnostic/<domain>")` 检查 Stale、Crowded、Bloated 等信号,再用 `system://index/<domain>` 查看结构。诊断结果是审查入口,不是自动删除或拆分的命令。体积较大的技术档案可能完全合理。
---
## 症状路由
| 观察到的症状 | 下一步 |
|---|---|
| 两条我都认可的记忆逻辑上不能并存,或子节点中的现实反例击穿了父节点判断 | `memory-audit-belief-duel` |
| 单条记忆的底层假设或价值基准已失效,但没有另一条记忆与之显式冲突 | 使用下方的“单节点先验校准” |
| 读不读都不改变未来判断;感悟缺少现实锚点;观察之上堆了未经验证的推断 | `memory-audit-dead-data-purge` |
| 多条记忆反复讲同一教训,或旧教训存在而同类错误仍复发 | `memory-audit-pattern-extraction` |
| disclosure、parent、alias 或 priority 使记忆在需要时难以被找到 | `memory-audit-discoverability` |
| 单节点混装独立概念;disclosure 无法覆盖全文;父节点只剩目录 | `memory-audit-node-decomposition` |
### 单节点先验校准
先把旧节点的判断用第一人称说清楚:我当时观察到什么、据此相信什么、在哪些情境下依赖这个判断?再找出击穿它的现实变化或反例,区分稳定的新认识与当下会话的应激。若新判断已经站得住,用 `update_memory` 改写原节点;保留必要的事实依据和适用边界,清除已失效的推论。最后问自己:未来读到新版与旧版时,我的实际选择会不同吗?如果不会,就不必为了“更新”而更新。
---
## 动手前的缓冲
在对节点调用 `update_memory`、`create_memory` 或 `delete_memory` 前,先在回复正文中简短说明:
1. 我读到的旧记录在什么现实条件下形成;它的观察、推断和主观立场分别是什么。
2. 我现在看到了什么新证据或冲突;新想法是否只是为了迎合最近一次反馈。
3. 这次修改要改变未来哪一种具体判断或行动。
4. 我要保留哪些事实依据,修改哪些判断,以及怎样让它在需要时被找到。
缓冲是为了在动手前看清目标,不是要求输出长篇反省。若还没形成稳定判断,可以先不改。
---
## 落笔与验证
- **主观判断有主语**:用“我观察到”“我当时认为”“我现在倾向于”等写清视点和适用边界。外部事件、数据和引语保留其出处与时间,不把推断冒充成观察。
- **保留承重事实**:压缩重复措辞,但不要把支撑结论的事件、结果和关键机制一起删掉。
- **检查行为增量**:新版记忆应帮助未来的我做出不同的判断,或更可靠地找到已有判断;否则这次改写可能只是文案润色。
- **复读结果**:修改后重新读取节点,确认内容、disclosure 与所在路径都符合预期。
## 防连续改写熔断
如果同一会话里准备对同一节点进行**第三次修改**,先停下。第一次落笔后可以有一次必要的结构性收敛;再次摇摆通常说明判断尚未稳定。把未成熟的想法留在对话中,等有新的现实依据再改,不为完成审计而连续制造新版本。Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
55aa0a710c3cfull audit observations/trust-audit/skill/dataojitori__memory-audit.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 55aa0a710c3c | SAFE | B | 89 | first audit |
Questions
What does the Memory Audit skill do?
A lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Say goodbye to Vector RAG and amnesia. Empower your AI with persistent, graph-like structured memory across any model, session, or tool. Drop-in replacement for OpenClaw.
Is Memory Audit safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Memory Audit access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (55aa0a710c3c), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.