agi-memory command protection
Reviews agi-memory commands that rewrite the canonical memory vault, permanently delete a memory across every synced machine, attach a remot
Reviews agi-memory commands that rewrite the canonical memory vault, permanently delete a memory across every synced machine, attach a remote that will receive the whole store, bulk-seed it from git history, or change the invariants injected into later sessions. Reads such as recall, log, inspect, blocks and sync status stay unreviewed.
command.agi-memory · v1.0.0 · Other extensions
- Protection rules
- 6
- Permission checks
- 6
- Mapped commands
- 6
Overview
What this coverage does
Reviews agi-memory commands that rewrite the canonical memory vault, permanently delete a memory across every synced machine, attach a remote that will receive the whole store, bulk-seed it from git history, or change the invariants injected into later sessions. Reads such as recall, log, inspect, blocks and sync status stay unreviewed.
Key facts
- Catalog ID
command.agi-memory- Version
- v1.0.0
- Kind
- Command coverage
- Category
- Other extensions
- Protection rules
- 6
- Permission checks
- 6
- Mapped commands
- 6
- Maintainer
- Community contributor(community, provenance recorded)
- Source commit
- 85c5e82
- Protection model
- External · opt-in
External coverage. It must be enabled through Guard controls; this page does not activate it.
Stated limits
- Coverage is limited to the reviewed operations and the surrounding Guard policy.
- A maintainer profile is not a security certification or an official upstream endorsement.
Command mapping
Every command this extension recognizes, with the catalog default floor Guard applies before workspace policy. Search the table, then open an operation for safe variants and the permission ID.
6 operations · 6 reviewed by default These are catalog defaults, not your workspace policy.
Showing 6 of 6 operations
- Reviewed Guard intercepts the command for review before it runs.Critical
agi-memory delete 3 --hard
agi-memory permanent memory deletion
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `agi-memory delete <id> --hard`, which permanently removes an observation rather than marking it superseded. The delete cascades into the long-term facts promoted from that observation and appends a vault tombstone, so the removal propagates to every other machine sharing the vault on the next sync. Delete invocations carrying unresolved shell expansions are still reviewed through Guar…
- Documented safe variants
agi-memory command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.agi-memory.permission.delete-hard
- Reviewed Guard intercepts the command for review before it runs.Critical
agi-memory sync dedupe
agi-memory vault deduplication
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `agi-memory sync dedupe`, which rewrites the canonical append-only memory vault in place. It is the only agi-memory operation that rewrites rather than appends, it prunes records it judges redundant, and a similarity key that merges two distinct memories destroys the loser with no undo. Sync invocations carrying unresolved shell expansions are still reviewed through Guard's floor becau…
- Documented safe variants
agi-memory command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.agi-memory.permission.sync-dedupe
- Reviewed Guard intercepts the command for review before it runs.High
agi-memory sync init
agi-memory vault remote initialisation
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `agi-memory sync init`, which turns the local memory vault into a git repository and attaches a remote. Every memory already in the vault is then pushed to that remote on the next sync, so pointing it at the wrong repository publishes the whole store. With --create-private it also creates a new GitHub repository through the gh CLI.
- Documented safe variants
agi-memory command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.agi-memory.permission.sync-init
- Reviewed Guard intercepts the command for review before it runs.Medium
agi-memory bootstrap
agi-memory cold-start memory seeding
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `agi-memory bootstrap` and the standalone `agi-bootstrap` script, which parse git history and README.md and bulk-write the result into the memory store. Run against a store that is not empty, or against the wrong repository, this mixes generated memories into curated ones with no marker separating them afterwards.
- Documented safe variants
agi-memory command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.agi-memory.permission.bootstrap
- Reviewed Guard intercepts the command for review before it runs.Medium
agi-memory pin tls-rule 'TLS v1.3 only'
agi-memory core memory pin
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `agi-memory pin`, which writes a core-memory block that is injected into the context of every later session for the project. Pinning under an existing key overwrites that block, replacing an invariant later sessions were relying on.
- Documented safe variants
agi-memory command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.agi-memory.permission.pin
- Reviewed Guard intercepts the command for review before it runs.Medium
agi-memory unpin tls-rule
agi-memory core memory unpin
- Default floor
- Reviewed by default. Guard intercepts the command for review before it runs.
- Detector mode
- review
- What it matches
- Identifies `agi-memory unpin`, which removes a core-memory block. Later sessions stop receiving the invariant it held, and nothing in a later session reveals that it was ever there.
- Documented safe variants
agi-memory command helpskip this operation when they are the documented preview or help form.- Permission ID
- command.agi-memory.permission.unpin
Tool state mapping
No per-tool overrides are declared. Command defaults above resolve through the workspace Guard policy unless a later policy layer changes them.
Runtime identity
- Catalog ID
- command.agi-memory
- Guard enforcement ID
- command.agi-memory
- Source path
- contributions/extensions/command.agi-memory.json
- Contribution digest
sha256…8e19c5
Action classes
agi-memory vault rewrite commandagi-memory permanent memory deletion commandagi-memory vault remote initialisation commandagi-memory cold-start seeding commandagi-memory core memory pin commandagi-memory core memory unpin commandTechnical profile
No independent profile published
This extension has no current independent technical profile. Catalog facts and any legacy launch remain separate and are not presented as profile evidence.
FAQ
Frequently asked questions
Reviews agi-memory commands that rewrite the canonical memory vault, permanently delete a memory across every synced machine, attach a remote that will receive the whole store, bulk-seed it from git history, or change the invariants injected into later sessions. Reads such as recall, log, inspect, blocks and sync status stay unreviewed. The listing declares 6 rules and 6 permission checks. 6 operations · 6 reviewed by default. Coverage is limited to these reviewed operations and the surrounding Guard policy.
External · opt-in: External coverage. It must be enabled through Guard controls; this page does not activate it. Enabling state is always controlled through Guard policy, never from this directory.
This listing entered the catalog as a community contribution through a public pull request with recorded provenance. Credit is attribution only. A verified publisher profile and the claim flow verify authority separately; neither is an upstream endorsement or a HOL safety certification.
No. Every listing documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. Review the stated limitations and the exact source tree before relying on any single control.
6 operations · 6 reviewed by default. Examples: agi-memory delete 3 --hard (reviewed by default); agi-memory sync dedupe (reviewed by default); agi-memory sync init (reviewed by default); agi-memory bootstrap (reviewed by default); agi-memory pin tls-rule 'TLS v1.3 only' (reviewed by default); agi-memory unpin tls-rule (reviewed by default). These are catalog defaults, not your workspace policy.
External coverage. It must be enabled through Guard controls; this page does not activate it. Enablement is managed through your workspace's Guard policy and controls — never from this directory. Open the install guidance for the setup flow, then adjust the command coverage for command.agi-memory in Guard's policy surface.
The matching action is stopped at Guard's pre-action boundary before it executes, and the decision is recorded with evidence your workspace can review. Exact behavior follows your Guard policy combined with this entry's 6 rules and 6 permission checks.
No. Guard is local-first: interception, decisions, and evidence stay on your machine unless your workspace explicitly configures cloud features. This page is documentation only — it never executes a command or changes protection state.
Guard runs locally alongside the major AI coding agents and MCP-capable harnesses, so this coverage applies wherever Guard intercepts actions. See the supported harness guides at https://hol.org/guard/harnesses for per-tool approval behavior and limitations.
Guard has a free local tier that includes command interception, evidence, and the policy controls this listing documents. Team plans add shared policy, review queues, and audit surfaces. Current plans: https://hol.org/guard/pricing
Open an issue or pull request against the hol-guard repository, where the canonical catalog lives: https://github.com/hashgraph-online/hol-guard Listings are corrected through the same public review process that adds them.
Yes. Community extensions are merged through public pull requests with recorded provenance, and you can claim the publisher page for a contribution you maintain through the Publisher Studio.
The command mapping table is the audit trail for covered commands and catalog default floors. Pair it with the reviewed rule and permission counts, the per-tool state mapping, and the exact source tree linked from View exact source at the reviewed commit. Guard records enforcement decisions with evidence locally, so what ships matches what you reviewed.