ForgetSAFE
#1 Persistent memory for AI coding agents based on real-world benchmarks
Overview
#1 Persistent memory for AI coding agents based on real-world benchmarks
739684e68e2eOBSERVED · 2026-10-06What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: forget
description: Delete specific observations from agentmemory after showing them and getting explicit confirmation. Use when the user says "forget this", "delete memory", "remove that note", or wants to scrub specific data for privacy.
argument-hint: "[what to forget - session ID, file path, or search term]"
user-invocable: true
---
The user wants to remove data from agentmemory: $ARGUMENTS
## Quick start
```json
memory_smart_search { "query": "old api key in config", "limit": 20 }
```
Show the matches, get a yes, then:
```json
memory_governance_delete { "memoryIds": ["abc12345", "def67890"], "reason": "user privacy request" }
```
Expected output:
```text
Found 2 matching memories. Confirmed. Deleted 2 memories.
```
## Why
This is destructive and irreversible. Show exactly what will be deleted and get
an explicit yes before calling delete. Delete by memory ID, never a bare session.
## Workflow
1. Search with `memory_smart_search`, the user's text as `query`, `limit: 20`.
2. Show what matched: session ids, memory ids, titles. Ask for explicit
confirmation. Do not proceed on silence or a vague "sure, whatever".
3. On confirmation, call `memory_governance_delete` with `memoryIds` (array or
comma-separated string) and optional `reason` (default `plugin skill request`).
4. To drop a whole session, collect every memory id in that session from the
search results and pass them all. The MCP does not accept a bare `sessionId`.
5. Lessons are separate: delete one with `memory_lesson_delete` and its
`lessonId`; `memory_governance_delete` does not touch lessons.
6. Report the deletion count back. A count of 0 means the ids did not exist;
say so instead of claiming a delete.
## Anti-patterns
WRONG: search returns matches, you immediately call `memory_governance_delete`
without showing them or waiting for a yes.
RIGHT: list the matches, ask "Delete these 2? (yes/no)", and only delete after
an explicit yes.
## Checklist
- Matches were shown to the user before any delete.
- An explicit yes was received, not assumed.
- `memoryIds` holds real ids from the search, never a bare `sessionId`.
- Final message states the actual count deleted.
## See also
- `remember`: the write side; forget is its undo.
- `recall`: find the exact memory id before deleting.
## Troubleshooting
See ../_shared/TROUBLESHOOTING.md if `memory_smart_search` or `memory_governance_delete` is not available.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
description: Delete specific observations from agentmemory after showing them and getting explicit confirmation. Use when the user says "forget this", "delete memory", "remove that note", or wants to
Delete specific observations or sessions from agentmemory. Use when user says "forget this", "delete memory", or wants to remove specific data for privacy.
Gates applied: no_behavioural_pass.
739684e68e2efull audit observations/trust-audit/skill/rohitg00__forget.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 739684e68e2e | SAFE | B | 89 | first audit |
Questions
What does the Forget skill do?
#1 Persistent memory for AI coding agents based on real-world benchmarks
Is Forget safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Forget access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (739684e68e2e), read on 2026-10-06. The repository is watched, and a new audit runs when it changes — this is the first audit.