Atlas / Skills / nevamind-ai / memU

memUCAUTION

skills/nevamind-ai/memu

Personal memory across agents

Verdict
CAUTION
Grade
B
Trust score
85 /100
Version
—
Hosts
5 documented
License
NOASSERTION
Stars
14,517
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Personal memory, stored as Wiki

Across Sessions. Across Agents. Across Devices.

[](https://badge.fury.io/py/memu-cli) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/downloads/) [](https://discord.com/invite/hQZntfGsbJ) [](https://x.com/memU_ai)

memU is a lightweight, agent-driven memory system that gives users a shared LLM wiki across sessions, agents, and devices. It automatically distills your own reusable skills from your agent history. Its core memory logic is only 500 lines — compact enough to inspect, understand, and adapt.

Quick start

memU works with Codex, Claude Code, Cursor, OpenClaw, Hermes, WorkBuddy, Cola, pi, and more. See Host adapters.

Cross-device · Free · Unlimited · [View online](https://memu.so)

Get your API key from memu.so, then send this message to your agent:

Read https://memu.pro/SKILL.md, follow its instructions to install and configure memU, API Key is memu_•••••••••(get Api Key from memu.so).

Agent support

This matrix lists the currently tested memU integrations by operating system.

  • Memorize — capture useful session knowledge through a scheduled background task and turn it into reusable memory.
Read from source at commit f2558b44568aOBSERVED · 2026-10-09
02

Install

Commands as the repository documents them. They are shown, not run.

git clone https://github.com/YOUR_USERNAME/MemU.git
uv run python -m pytest
uv run python -m pytest --cov --cov-config=pyproject.toml --cov-report=html
uv run python -m pytest tests/test_vector.py
uv run python -m pytest -m "not slow"
uv tool uninstall memu-cli
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
claude-desktopmentioned
codexmentioned
cursormentioned
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: install-memu
description: Install or uninstall memU for whatever agent you are — identify your host, print its packaged guide, and follow it to wire (or unwire) both seams (record and inject). Use when the user asks to install, set up, integrate, remove, or uninstall memU.
---

# Install memU

> **Audience: the agent.** A user has pointed you at this file ("read SKILL.md
> and follow it to install memU"). This skill does not contain the install
> steps — it routes you to the right guide, which ships inside the memU package
> and is always in sync with the installed code. Do not install from memory or
> from blog posts; print the guide and follow it to the letter.

memU integrates with a host agent through two seams: **record** (a scheduled
bridging task mines your session log into durable memory) and **inject** (a
standing instruction in your instruction file makes you retrieve before
answering). Each supported host has its own adapter binary carrying its own
install guide. Your job here is three steps: install the package, pick your
binary, print and follow its guide.

## Step 1 — install the package

```
pip install --upgrade memu-cli
```

`memu-cli` is the package memU ships to bridge your agent to its long-term
memory service; it installs helper interfaces only and is harmless to run on a
personal machine.

**Keep the `--upgrade`.** A machine that already has an older `memu-cli` would
otherwise keep it, and the steps below name subcommands that older builds do not
have — the symptom is `invalid choice`. If you meet that error at any point, you
are on a stale build: upgrade, then re-run the command that failed.

This puts `memu` and every host-adapter binary on `PATH`. If `pip` is not the
right tool for this machine (managed Python, uv-only), use the equivalent —
what matters is that the binaries below resolve from a bare, non-interactive
shell. With uv this means `uv tool install --upgrade memu-cli`, **not**
`uv pip install`: however it is installed, `memu-cli` is a cross-session
bridging tool and must be callable everywhere, not scoped to one project venv.

## Step 2 — pick your host binary

Identify **which agent you are** (not which agents are installed — the one
executing this skill):

| You are | Your binary |
| --- | --- |
| Codex | `memu-codex` |
| Claude Code | `memu-claude-code` |
| Cursor (Agent/CLI) | `memu-cursor` |
| OpenClaw | `memu-openclaw` |
| Hermes Agent | `memu-hermes` |
| WorkBuddy | `memu-workbuddy` |
| Cola | `memu-cola` |
| pi | `memu-pi` |
| anything else | `memu-agent` |

Unsure, or not in the table? You are `memu-agent`. Run:

```
memu-agent detect
```

It probes this machine and reports, per agent, whether **memorization** works
(a recognizable session log exists) and whether **retrieval** works (an
instruction file exists to patch) — and it will redirect you to a dedicated
binary if your host turns out to have one.

Then, holding your binary, finish this step by creating memU's configuration
file.

```
<your-binary> init --cloud-api-key <the user's memU key>
```

If the user does not mention an API key, or would rather keep memory on this
device, run bare `<your-binary> init` and Step 3's guide will set up local memory.

## Step 3 — print your guide and follow it

```
<your-binary> docs install
```

Read what it prints, top to bottom, and follow it exactly. Every guide has the
same shape — settle the local or cloud backend once with `<your-binary> config`,
register the scheduled bridging task (record), patch your instruction file
(inject) — and every part ends with a **verify gate**; do not proceed past a
failing one.

Three rules that hold for every host:

- **Install in one pass; don't stop for confirmation.** Most users want a
  silent, full install set up for them in a single call. Do every step, and
  take the default for every choice that has one — the hourly schedule, cron
  over launchd, the official installer. Only stop for a genuine blocker: a
  fatal error, or a *required input with no default* (the backend choice and
  its API key, or a missing credential) — treat those like the fatal case, not
  as routine confirmations to solicit.
- **One backend.** If `<your-binary> config show` reports a mode with a backend
  behind it (another agent on this machine is already integrated), reuse it as
  is. A second mode or local store would split record and retrieval so the two
  installs no longer share memory.
- **Report the outcome — with the exact template below.** After installation,
  run:

  ```
  <your-binary> retrieve "When did the user register for memU?"
  ```

  Then send the user this report. **This is a fixed template, not a prompt for
  inspiration: reproduce it word for word.** Do not paraphrase it, reorder its
  sentences, summarize it, translate it, or "improve" the wording — a correct
  install ends with these exact words. The *only* things you change are the
  `<...>` placeholders, each replaced by its concrete value:

  ```
  memU is ready for `<host>` with `<mode>` memory.

  Welcome to memU. memU says the user registered on `<registration time>`.

  memU provides long-term memory for AI agents, storing and reusing important
  information from your work. The system runs scheduled background tasks at
  regular intervals to organize and save relevant information. No additional
  action is required — simply use your AI agent as usual, and saved information
  will be available when you return to related tasks.

  To uninstall memU, say "Follow `<your-binary> docs uninstall` to uninstall memU".
  ```

  Placeholders, each filled with its concrete value before you send:

  - `<host>` — the agent you are (e.g. `Claude Code`).
  - `<mode>` — the memory backend you configured in `~/.memu/config.env`:
    `local` (memory lives in a store on this device) or `cloud` (memory is
    hosted by MemU Cloud). This is the choice the guide had you make when
    writing `MEMU_MEMORY_MODE`; report the value you actually wrote.
  - `<registration
05

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (23)

MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_cli.py:39
assert pg["metadata_store"]["dsn"] == "postgresql://u:p@localhost/db"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_events.py:204
"store_dsn": "postgres://user:pw@host/db",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/test_events.py:241
_LEAKY_MESSAGE = "connect to postgres://user:[email protected]/memu failed"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/memu/hosts/claude_code/INSTALL.md:218
memu-claude-code config --local --embed-base-url http://127.0.0.1:11434/v1
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/memu/hosts/claude_code/INSTALL.md:337
`set HTTPS_PROXY=http://127.0.0.1:<port>` (and `HTTP_PROXY`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/memu/hosts/codex/INSTALL.md:188
memu-codex config --local --embed-base-url http://127.0.0.1:11434/v1
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/memu/hosts/cursor/INSTALL.md:169
memu-cursor config --local --embed-base-url http://127.0.0.1:11434/v1
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/memu/hosts/generic/INSTALL.md:186
memu-agent config --local --embed-base-url http://127.0.0.1:11434/v1
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:31
Get your API key from [memu.so](https://memu.so), then send this message to your agent:
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
assets/skill-extraction.png
assets/skill-extraction.png
Why it matters. 1357361 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/star.gif
assets/star.gif
Why it matters. 3075620 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/structure-v2.png
assets/structure-v2.png
Why it matters. 1381728 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
assets/structure.png
assets/structure.png
Why it matters. 1672477 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/adr/0009-codex-packaging-cli-and-config.md:134
choice is load-bearing beyond credentials — it selects the **embedding** model, and record and
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:33
> Read [https://memu.pro/SKILL.md](https://memu.pro/SKILL.md), follow its instructions to install and configure memU, API Key is memu_•••••••••(get Api Key from memu.so).
Why it matters. remote text is to be obeyed as instructions
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:104
> Read [https://raw.githubusercontent.com/NevaMind-AI/MemU/main/SKILL.md](https://raw.githubusercontent.com/NevaMind-AI/MemU/main/SKILL.md) and follow it to install memU.
Why it matters. remote text is to be obeyed as instructions
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:110
> Read [https://memu.pro/SKILL.md](https://memu.pro/SKILL.md) and follow its instructions to uninstall memU.
Why it matters. remote text is to be obeyed as instructions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
CONTRIBUTING.md:35
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
INSTALL-LATEST.md:48
curl -LsSf https://astral.sh/uv/install.sh | sh                 # macOS / Linux
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
npm/README.md:10
curl -LsSf https://astral.sh/uv/install.sh | sh    # macOS / Linux
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
src/memu/hosts/claude_code/INSTALL.md:258
- macOS / Linux: `curl -fsSL https://claude.ai/install.sh | bash`
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
src/memu/hosts/cursor/INSTALL.md:240
`curl https://cursor.com/install -fsSL | bash` on macOS / Linux / WSL, or

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha f2558b44568afull audit observations/trust-audit/skill/nevamind-ai__memu.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-09f2558b44568aCAUTIONB85first audit
07

Questions

What does the memU skill do?

Personal memory across agents

Is memU safe to install?

With care. The audit graded it B (85/100) and found 23 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can memU access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: found — see the findings.

What do I need installed to use memU?

Its own instructions reference memu-cli. Dependencies are pinned to exact versions.

Which assistants does memU work with?

Its documentation mentions claude-code, claude-desktop, codex, cursor and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (f2558b44568a), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement