Atlas / Skills / plastic-labs / Zo

ZoCAUTION

skills/plastic-labs/zo

Memory library for building stateful agents

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
0.1.0
Hosts
—
License
AGPL-3.0
Stars
7,495
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give your AI persistent memory across conversations using Honcho.

Features

  • Auto-Memory: Save user and assistant messages to Honcho with one call
  • Query Memory: Ask natural language questions about what Honcho remembers ("What are my hobbies?")
  • Context Injection: Retrieve conversation context formatted for direct LLM use
  • Multi-Workspace Support: Manage separate memory spaces via HONCHO_WORKSPACE_ID

Installation

pip install honcho-ai python-dotenv

Or with uv:

uv add honcho-ai python-dotenv

Environment Variables

Create a .env file:

HONCHO_API_KEY=your-api-key-here
HONCHO_WORKSPACE_ID=default

Get your API key at honcho.dev.

Quick Start

from tools.save_memory import save_memory
from tools.query_memory import query_memory
from tools.get_context import get_context

# Save a conversation turn
save_memory("alice", "I love hiking in the mountains", "user", "session-1")
save_memory("alice", "That sounds wonderful!", "assistant", "session-1")

# Query what Honcho remembers
answer = query_memory("alice", "What are my hobbies?", "session-1")
print(answer)  # "Alice enjoys hiking in the mountains."

# Get context ready for an LLM call
messages = get_context("alice", "session-1", "assistant", tokens=4000)
# messages is a list of {"role": ..., "content": ...} dicts

Tool Reference

save_memory(user_id, content, role, session_id, assistant_id="assistant")

Saves a message to Honcho memory.

Returns a confirmation string.

query_memory(user_id, query, session_id=None)

Quer

Read from source at commit 757fc5d02ea6OBSERVED · 2026-10-07
02

Install

Commands as the repository documents them. They are shown, not run.

pip install honcho-ai python-dotenv
uv add honcho-ai python-dotenv
uv run pytest tests/ -v
pip install honcho-ai python-dotenv
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: honcho-memory
description: Gives AI agents persistent memory across conversations using Honcho. Automatically saves and retrieves user context so the AI remembers preferences, history, and facts between sessions. Use when you need the AI to remember past conversations, recall what a user has told it, inject relevant context into prompts, or manage separate memory spaces for different topics.
license: AGPL-3.0
compatibility: Requires Python 3.9+, honcho-ai>=2.1.0, and a Honcho API key from honcho.dev. Set HONCHO_API_KEY and optionally HONCHO_WORKSPACE_ID in your environment.
metadata:
  author: plastic-labs
  version: "0.1.0"
  honcho-sdk: "2.1.0"
---

# Honcho Memory Skill

This skill provides three tools for storing and retrieving AI memory using [Honcho](https://honcho.dev).

## Setup

1. Get a Honcho API key at [honcho.dev](https://honcho.dev).
2. Set environment variables:

   ```
   HONCHO_API_KEY=your-api-key
   HONCHO_WORKSPACE_ID=default   # optional, defaults to "default"
   ```

3. Install dependencies:

   ```
   pip install honcho-ai python-dotenv
   ```

## Tools

### `save_memory`

Saves a conversation turn (user or assistant message) to Honcho.

**When to use:** After every message exchange to build up the user's memory.

```python
from tools.save_memory import save_memory

save_memory(
    user_id="alice",           # unique user identifier
    content="I love hiking",   # message text
    role="user",               # "user" or "assistant"
    session_id="chat-1",       # conversation session ID
    assistant_id="assistant"   # optional: assistant peer ID (default: "assistant")
)
```

### `query_memory`

Asks a natural language question against stored memory using Honcho's Dialectic API.

**When to use:** When the user asks "do you remember...?", or when you need to recall facts about the user before responding.

```python
from tools.query_memory import query_memory

answer = query_memory(
    user_id="alice",
    query="What are Alice's hobbies?",
    session_id="chat-1"   # optional: scope to a session
)
# Returns: "Alice enjoys hiking."
```

### `get_context`

Retrieves recent conversation history formatted for direct use in an LLM API call.

**When to use:** At the start of each LLM call to inject relevant context from past conversations.

```python
from tools.get_context import get_context

messages = get_context(
    user_id="alice",
    session_id="chat-1",
    assistant_id="assistant",
    tokens=4000              # max tokens to include
)
# Returns: [{"role": "user", "content": "..."}, ...]
```

## Concept Mapping

| Zo Computer | Honcho |
|---|---|
| Account | Workspace |
| User | Peer |
| Conversation | Session |
| Message | Message |

## Example: Full Conversation Flow

```python
from tools.save_memory import save_memory
from tools.query_memory import query_memory
from tools.get_context import get_context

user_id = "alice"
session_id = "session-1"

# 1. Save user message
save_memory(user_id, "I'm learning Rust and love rock climbing", "user", session_id)

# 2. Save assistant reply
save_memory(user_id, "That's great! Both require patience.", "assistant", session_id)

# 3. In a later session, recall what you know
print(query_memory(user_id, "What does Alice do in her free time?"))
# → "Alice is learning Rust and enjoys rock climbing."

# 4. Get context window for next LLM call
messages = get_context(user_id, session_id, "assistant", tokens=4000)
```
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills
.agents/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 757fc5d02ea6full audit observations/trust-audit/skill/plastic-labs__zo.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-07757fc5d02ea6CAUTIONB89first audit
06

Questions

What does the Zo skill do?

Memory library for building stateful agents

Is Zo safe to install?

With care. The audit graded it B (89/100) and found 2 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Zo access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (757fc5d02ea6), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement