RecallSAFE
#1 Persistent memory for AI coding agents based on real-world benchmarks
Overview
#1 Persistent memory for AI coding agents based on real-world benchmarks
739684e68e2eOBSERVED · 2026-10-06What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: recall
description: Search agentmemory for past observations, sessions, and learnings about a topic using hybrid BM25 plus vector plus graph search. Use when the user says "recall", "what did we do about", "did we ever", "have we seen", or needs context from past sessions.
argument-hint: "[search query]"
user-invocable: true
---
The user wants to recall past context about: $ARGUMENTS
## Quick start
```json
memory_smart_search { "query": "jwt refresh token rotation", "limit": 10 }
```
Expected output:
```text
2 results across 2 sessions.
[importance 8] decision · "Rotate refresh tokens on every use" (session 7f3a9c21)
[importance 5] code · "limit.ts counts per-IP" (session b21d004e)
```
## Why
Only surface what the tool returned. Never fabricate an observation, a session
id, or an importance score. If nothing comes back, say so.
## Workflow
1. Call `memory_smart_search` with the user's text as `query` and `limit: 10`.
Pass `project` when the user scopes to a specific repo.
2. Group results by session. Records carry a provenance channel (`user`, `agent`,
`tool`, `import`, `shared`); when results conflict, prefer `user` over `agent`
inference, and flag `shared` records as another teammate's write.
3. For each observation show its type, title, and narrative.
4. Lead with the high-signal observations (importance >= 7).
5. If zero results, suggest 2-3 alternative search terms and stop. Do not guess.
## Anti-patterns
WRONG: results are empty, so you write "We probably discussed token expiry last
week" from assumption.
RIGHT: "No memories matched that query. Try `refresh token`, `session expiry`,
or `auth rotation`."
## Checklist
- Every observation shown came from the tool response.
- Results grouped by session, high-importance first.
- Empty results trigger alternative-term suggestions, not invention.
- No session id or score was paraphrased or rounded.
## See also
- `remember`: the write side; recall retrieves what it stores.
- `recap`, `handoff`, `session-history`: session-scoped views of the same data.
- `memory-discipline`: when to run this search unprompted.
## Troubleshooting
See ../_shared/TROUBLESHOOTING.md if `memory_smart_search` is not available.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
739684e68e2efull audit observations/trust-audit/skill/rohitg00__recall.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 739684e68e2e | SAFE | B | 89 | first audit |
Questions
What does the Recall skill do?
#1 Persistent memory for AI coding agents based on real-world benchmarks
Is Recall safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Recall access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (739684e68e2e), read on 2026-10-06. The repository is watched, and a new audit runs when it changes — this is the first audit.