Individual Reports
mem0langmemhonchoengrammempalaceswafrallm-wiki-memoryrainboxlettasupermemoryverelhindsightgraphitimastra-observational-memorymemosbasic-memoryagentmemorytencentdb-agent-memorycogneeclaude-mema-memholographichermes-agentopenvikingredis-agent-memory-serverbyteroveropenclawhipporagvoyagergenerative-agentsmagic-contextpimetaclawnanobotcowagentgenericagentopen-coworkgini-agentmoltismercury-agentllamaindexatomic-agentmateclawwaku-agentmemoraloongflowcore-memorymemantomemory-engineai-memoryctxoptmemmemvidmemoryosmemuopenworkerqwen-codeopencodenooa-memoryneo4j-agent-memoryelastic-atlasmirixmemobasememarymemoriremepowermemminecontextacontextsecond-metigrimosrnemoclawdaimonmemmachinebuzzlogseqopenhumanadk-pythonaukora-kernelautogengoodai-ltmeveroseccskalesnekosillytavernrisuaisoul-of-waifuz-waifvirtualwifehelmagnosimplemempydantic-ai-harnesscamelagent-frameworkcrewaigobiiagent-memory-supabaselivingfeedcosmonapsenpcpyjugglermagicoregitlordagent-afkcortexmnemopitokenmizerzerostacklethecsmgraphifylorekitclioagentswarmsempryodextoproject-golemopenyakmementomembasepalazzoauramemex-zero-ragagentrecall-xmemledgerterse-memoryagentic-context-enginedeer-flowean-agentosm-flowuniversal-memory-enginenova-aimemsemcambiumperseus-vaultprovemargosovereignmemoryops-aideepcodeprime-agentmnemosyneomikirocrewmnemoryengram-alphasesaopensresmythos-sreqwen-mm-pluginsremem-mcpwindie-sandboxplur1busomniintelligenceomniclaudehillockmemory-compileragent-memory-doctrineodsneurakeepopen-knowledge-formatomnimemtempomemdovsgopenmake-llmelaiargosreporecallthoughtdagopenmasqno-humankwipucraftholomemhumanspro-workflowteamai-clievox-genesismemcontinuumsage-memorypluropenzync-coresibyl-memoryauto-companyripwireengram-formatkhojanything-llmjoplinusememossilverbulletsiyuantriliumvistavelantrim-exocortex-crystalforgetfulhalofyorigintrail-dkgai-agent-bookdsh-mnemewidemem-aikaerualtk-evolveopen-braindistill-kurawagglekektordbclaude-mem-liteegcprojectmemstratagateagent-memory-mcpvelesdbdsh-mnemonyantrikdb-hermes-plugininite-braingoodmemorymemorixdense-memloreaimazemakermemtomemtracedecaytitenllm-memory-apidemarkuspeople-contextstate-memory-mcpthe-librarianakbjazagentrtinno-agentoh-my-hermesbitterbot-desktopyantrikdb-enginenodedbopenconchooxmaximem-synap-sdksykesivtreliot-memory-osneuralmindinspeximuspi-memorymandalorekannaka-memorychumplongterm-memory-mcpagent-memory-guarda-memorymemexyacmemolevhanda-dbtemporalstoremushroomdbflairtheurianyantrik-oshuiran-cerebrolight-membifrostmnemorachitta-fieldmnemonicnougenshardseddaosirisholo-invariantcodememtessellumneothhungry-hippacortanacortex-hypermnesiaengram-cognitiveclaudinio-brainre-callokf-agent-memoryloreweavetemveramindreaderverimemanatidmemhtmlbwmemhuqanontomemyantrik-mindmnesioulpiagaiusaidememocogzleteomemorywhalerememorafava-trailsleankghyphaai-maestrocontextstream-mcpmnesticcognee-rskipi-systembeevibeknowlkiwi-membeever-atlaspensyvekglitemeridianmemory-vaultopen-graph-memoryfunesdeusgastownbeadsmemorizeryantrikdb-mcppmbspectormempalace-coderesonant-mindengram-nickcirvemulosqlite-memory-mcpautomemmexm3-memoryruvectorogadcontext-engineeringgraftmind-mempapercliprrsiememagent-memory-distillationfarmembodied-lgrliving-mind-cortexopen-bridgevortx-ememshellbrainmemeshmamamnemosyne-nabzxautoharnessmegamemorykagura-memory-cloudprismer-cloudmemseekexomemrust-self-learning-memorymemhopcortexeswordcelloctop-memoryrecallnestmemoosezenbrainobelyth-cortexcortex-hubmindmemoslindahaviv-second-brainrexleimo-aiosdynamics-memorydsh-layered-memorycyrene-agentneo-agent-brainoctobrainkimetsulint-aiautobot-ainano-braindreamgraphflowlyglobal-agent-memoryrecollectrightmemorytidemindclaude-engramctx-openroampal-coreopencode-session-recallaoci-codemcp-context-servertree-ring-memoryengram-mcpdsh-continual-harnesscounterpartsclaude-engram-mlapeterorgtreesmritimainlinemintaagent-memory-enginealphaonedev-ai-memoryselvedgegmeow-ontologylocal-memory-mcparcheusmarvisattune-aisession-recallmgi-mindmnemocortexdbsynapse-layerfernmefluctlightdbosk-systempluribusihmt-memory
Repos Inspected
- mem0ai/mem0 at
c7ee362a…— read only at the second pin; eighteen dependency surfaces inside the cooldown, nothing installed or run. The memory package now fetches a remotely switchable notice config and classifies search queries as temporal, gated on telemetry that defaults on - langchain-ai/langmem
at
9d033b47…— read at the second pin and audited there on 2026-09-30, which is upstream HEAD, with the store read in langchain-ai/langgraph atcheckpoint==4.2.0andcheckpointpostgres==3.1.2; no auto-run surface and two build-time execution points, read rather than executed; nothing installed, built or run.scope_enforcedholds; no committed test asserts it. - plastic-labs/honcho at
210b56cf…— read only; four dependency files were inside the seven-day cooldown, so nothing was installed - Gentleman-Programming/engram
at
fa222a06… - MemPalace/mempalace at
8c4865f7… - Prateek816/7layermem
at
d3500bfd… - cognicore-dev/cognicore-env
at
08d91395… - RBKunnela/ALMA-memory
at
91a352f2… - deepractice/promptx at
93c1e535… - fuyuxiang/echo-agent
at
f612b74f… - kitfunso/hippo-memory
at
f774b2db… - kunal12203/swafra
at
669e7bdb… - ctxr-dev/llm-wiki-memory
at
4e7f98f3…— read only; one auto-run surface (AGENTS.md, addressed to a reading agent and recorded as data), fifty floating ranges behind a lockfile and one manifest inside the seven-day cooldown, so nothing was installed and no stage was run. The unread quality marker was established by sweeping every non-test reference to the metadata field, not by executing a recall - neoneye/RainBox at
e09dd4f6… - letta-ai/letta at
5bcdd177… - supermemoryai/supermemory
at
2415a5c7…— read only at the second pin; a dependency surface inside the cooldown, so nothing was installed or run. The web console was reduced to a redirect shell, andscope_enforcedwas re-tested against the exact-match container-tag predicate that moved intopackages/tools/src/claude-memory.ts - amitpatole/verel
at
a8cbba27…— read only; no auto-run surface, one build-time execution surface, one unpinned surface and one file inside the seven-day cooldown. Nothing was installed and nothing was run. The pin was checked for reachability fromHEADbefore reading, because an earlier pin for this repository turned out to be unreachable from any branch. The project ships a self-grader against this atlas's seven capabilities, so every mark is stated against a file read here rather than against that probe - vectorize-io/hindsight
at
16d4025f…— read only at the second pin; 51 dependency surfaces inside the cooldown, so nothing was installed or run.negative_evaladded on the tests that came with a fix for chunk ids colliding across banks - BatterWorks/Hatchdoor
at
c2b9861a…— read only; the screen found no auto-run surface and no build-time execution, one unpinned manifest (frontend/package.json, 39 floating ranges behind a lockfile) and both lockfiles unchanged for 14 days, so nothing was installed, nocargoornpmcommand was run and no container was started.AGENTS.mdis addressed to a reading agent and was recorded as data. The thirty-six committed eval runs were recomputed from their own per-query tables rather than quoted; the README's badges and Docker Hub image still name the pre-renameBattermanZ/Hatchdoor. AGPL-3.0 - getzep/graphiti at
c035afb7… - mastra-ai/mastra
at
2f05e3e8… - MemTensor/MemOS at
de806942… - basicmachines-co/basic-memory
at
3bf2d523… - rohitg00/agentmemory
at
e04ba888… - TencentCloud/tencentdb-agent-memory
at
8f2dc830… - topoteretes/cognee at
c0d18c80… - thedotmack/claude-mem
at
40be934a… - agiresearch/A-mem
at
ceffb860… - NousResearch/hermes-agent
at
8df0a037…— one commit carrying two reports: Hermes's own built-in memory, and theholographicHRR plugin shipped in the same tree. Read only; one auto-run surface, twenty-one build-time execution surfaces, five unpinned surfaces and twenty files inside the seven-day cooldown. Nothing was installed and no suite was run - volcengine/OpenViking
at
192b813e…— read only at the second pin; a dependency surface inside the cooldown, so nothing was installed or run.scope_enforcedre-located from the write-target isolation handler to the account predicate on the vector backend - redis/agent-memory-server
at
8683648f… - campfirein/byterover-cli
at
1052ac1a… - openclaw/openclaw
at
2e7e5ef6… - Trustedwear-Tech/citra-decision-system
at
6f200f29…— read only; eight build-time execution surfaces and eight dependency surfaces inside the seven-day cooldown, so nothing was installed and nothing was run - Arc-Computer/ATLAS at
c226386f…— examined, no report; see the boundary note below - OSU-NLP-Group/HippoRAG
at
1438aba3… - MineDojo/Voyager
at
55e45a88… - joonspk-research/generative_agents
at
fe05a71d… - cortexkit/magic-context
at
8805036a… - earendil-works/pi
at
f9bcd351… - aiming-lab/MetaClaw at
922caf3a… - HKUDS/nanobot at
1c3c6826…— read only at the second pin; nothing installed or run. Archiving restructured into aMemoryArchiverwith a raw-checkpoint fallback; no mark moved - zhayujie/CowAgent
at
3bf04290…— read only at the second pin; two dependency surfaces inside the cooldown, nothing installed or run. Scope re-tested across four retrieval arms including a new vector backend - lsdefine/GenericAgent
at
1b6442fe…— read only at the second pin; nothing installed or run. The memory policy gained one exclusion — project-specific facts belong in the project, not in L3 — and the L1/L2 files turn out to be untracked runtime artifacts - OpenCoworkAI/open-cowork
at
a1d0e4ab… - Open-Curiosity/gini-agent
at
6c5d85ed… - moltis-org/moltis
at
1f6d28ea…— audited at the third pin, where no memory path had moved; nothing installed, built or run. Session logs are written raw by a hook while the sanitizing exporter has no caller, and the agent-scope predicate sits on the memory tools and not on the per-turn prefetch - cosmicstack-labs/mercury-agent
at
781daac2…— read only at the second pin; two dependency surfaces inside the cooldown, so nothing was installed or run. The stack row was traced and promoted from seeded to reviewed, and ashareableflag gating an outward cloud fetch was read at its defaults - run-llama/llama_index
at
0f43c00b… - AtomicBot-ai/atomic-agent
at
f31ec05d… - mateaix/mateclaw
at
5c67af85… - ShenSeanChen/waku-agent
at
761c4201…— read only;pyproject.tomlchanged the day of the reading and two build-time execution points (Makefile,evals/conftest.py), so nothing was installed or run.waku/memory/did not move; the reading was the new gate-accuracy eval underevals/judge/, which closes a criticism the report had published in six places, and a producer re-test ofhuman_reviewfrom the dashboard fact rows toSqliteFactStore - agentic-box/memora at
4b91fa74…— read only; one auto-run surface that was not present at the previous pin (.claude-plugin/marketplace.json, read first), one build-time exec at pytest collection, two unpinned manifests and no dependency surface inside the cooldown; nothing was installed or executed - baidu-baige/LoongFlow
at
945c78bc… - JohnnyFiv3r/Core-Memory
at
b3857ff5… - moorcheh-ai/memanto at
ce38df50…— read only; one auto-run surface (.gitattributes), six build-time execution points, nothing installed or run - timescale/memory-engine
at
2ef90da9… - acdesigntech/memory-project
at
83b2ac97… - akitaonrails/ai-memory
at
74d2d31e… - ActiveMemory/ctx
at
955749b4… - VictorTaelin/OptMem at
1fb164cf…— no licence file - memvid/memvid at
e6bd9f7b… - BAI-LAB/MemoryOS
at
587ed775… - NevaMind-AI/memU
at
08e1ed4c… - andrewyng/openworker
at
5bc10d92…— read only; no auto-run surface, three build-time execution surfaces, two unpinned surfaces and one dependency file inside the seven-day cooldown. Nothing was installed and nothing was run. MIT - QwenLM/qwen-code
at
537311b8… - anomalyco/opencode at
e03db9bc… - NVIDIA-NeMo/labs-OO-Agents
at
362f8bd2… - neo4j-labs/agent-memory
at
f801acc6… - noamschwartz/atlas-memory-demo
at
d84f9235… - NVIDIA/NemoClaw at
be46805b… - chaitanyagiri/munder-difflin
at
c7c8921f…Re-pinned and re-screened on 2026-09-19 after three readings published a false absence claim: each said the repository contains no tests, and 110 sat in a top-leveltest/directory at every one of those pins. - imran31415/kube-coder
at
6707237f… - munch2u-a11y/Cognitive-Spatial-Memory
at
39df03a1… - esengine/DeepSeek-Reasonix
at
025bd17b…— read only, at the tip ofstudio, the default branch; the screen found one auto-run surface (committed.githooks/pre-push), one build-time execution path (Makefile), five unpinned manifests behind lockfiles and eleven dependency files inside the seven-day cooldown, so nothing was installed, built or run.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were read as data. MIT - Morephine/feltstate at
3a9f7f52… - yaminbkk/NexusMem
at
e1842964…— read only; one auto-run surface (server.json), two manifests inside the seven-day cooldown, nothing installed or run - Daily-Nerd/daimon
at
3e525689…— read only; three auto-run surfaces, three build-time execution paths, one unpinned surface and two files inside the seven-day cooldown. Nothing was built and nothing was run. Apache-2.0 - Mirix-AI/MIRIX at
8cb06a62… - memodb-io/memobase at
358c16bb… - kingjulio8238/Memary
at
b2331a2c… - MemoriLabs/Memori
at
10d65015… - agentscope-ai/ReMe at
bebad367… - oceanbase/powercontext
at
9d1b4844… - volcengine/MineContext
at
171c7a9e… - memodb-io/Acontext at
259d73bf… - mindverse/Second-Me at
d0e40251… - Sompote/TigrimOSR
at
e6056e80… - MemMachine/MemMachine
at
da7de4cb… - block/buzz at
7c789dee…— read only at the second pin; five dependency surfaces inside the cooldown, nothing installed or run. Scope recorded against the relay's engram read gate, which keeps an id-lookup exemption the newer result-gated kinds close - logseq/logseq at
8e15eeec…— read only from a shallow clone with a blobless clone for history; a pnpm lockfile and twenty-six manifests inside the seven-day cooldown, one build-time exec, nothing installed or run - tinyhumansai/openhuman
at
97eb9252… - google/adk-python
at
322e3bf0… - aumara-xyz/aukora-kernel
at
b441edc4… - microsoft/autogen
at
027ecf0a… - GoodAI/goodai-ltm
at
22ca10c2… - GoodAI/goodai-ltm-benchmark
at
188e7618…— the companion benchmark, described on the benchmarks page - EverMind-AI/EverOS at
5076683a… - affaan-m/ECC at
8321021c… - skalesapp/skales
at
ce47854a…— BSL 1.1, source-available; a v7.1.0 snapshot that upstream removed from every commit on 18 September 2026, read from the atlas archive; screened at this pin on 2026-09-17: no auto-run surface, one build-time execution surface (apostinstallrunning a nestednpm install), two unpinned surfaces; nothing installed, built or run - Project-N-E-K-O/N.E.K.O
at
bcdd5c2f… - netease-youdao/LobsterAI
at
2921c1e5…— not a report; cited in the OpenClaw analysis - SillyTavern/SillyTavern
at
06bde939… - kwaroran/RisuAI at
669b12ce… - jofizcd/Soul-of-Waifu
at
747048b3… - SugarcaneDefender/z-waif
at
aaf905c1… - yakami129/VirtualWife
at
c8afd6d3… - GOODMAN-PRO/helm
at
f453eaa9… - agno-agi/agno at
85b6d1d1… - aiming-lab/SimpleMem
at
db80b6a7… - pydantic/pydantic-ai
at
a205b282… - camel-ai/camel at
8c791b7b… - microsoft/agent-framework
at
c030fa35… - crewAIInc/crewAI
at
7b796623… - gobii-ai/gobii-platform
at
c9929bf8… - reescalder/agent-memory-supabase
at
b711e6d7… - showjihyun/livingfeed
at
732d8bed… - Cosmonapse/cosmonapse-core
at
47462600… - npc-worldwide/npcpy at
26fc78b5… - juggler-ai/juggler at
4908d8d0… - jihadkhawaja/magicore
at
ae8ba6bb…— formerly jihadkhawaja/mem0sharp; read only - yashneil75/gitlord at
8bfe0aa3…— read only; one commit past the first pin, a version bump with no source change; no auto-run surface, no build-time execution point, one unpinned manifest with no lockfile; nothing installed, built or run - griffinwork40/agent-afk
at
e0a607b1… - CortexPrism/cortex at
0c446572… - can1357/oh-my-pi
at
c5a8e0e0… - Shweta-Mishra-ai/tokenmizer
at
028fc8cc… - gi-dellav/zerostack at
16fadb3b… - deeplethe/lethe at
b6053b7b… - NovasPlace/CSM at
9c7cfb22…— read only, audited at an unchanged pin on 2026-09-28 from a full clone; three auto-run surfaces (.mcp.json,hooks/,hooks/hooks.json), eleven floating ranges behind a lockfile, and anAGENTS.mdread as data; the optionalCSM_LIVING_MIND_URLserver was read atf8bdb805…to match its route; nothing installed, built or run - Graphify-Labs/graphify
at
b9cd9570… - mthines/lorekit at
07d2ce84… - SyntheticAutonomicMind/CLIO
at
444398c5…— re-screened on 2026-09-28 from a full clone: one build-time exec path (Makefile) and anAGENTS.mdread as data, no auto-run surface; nothing installed, built or run. - AgentSwarms-fyi/agentswarms
at
cf179dd9…Re-pinned and re-screened on 2026-09-19 after the first reading published a false absence claim: its section 10 said no test file existed anywhere in the repository, and 395 did at that pin. - proxysoul/Empryo
at
64ea2ec8…— renamed fromproxysoul/soulforge - truffle-ai/dexto
at
ac56fbfc…— read only at the second pin; a dependency surface inside the cooldown, so nothing was installed or run. The memory packages did not change;human_reviewre-tested and recorded as delete-only, since pinning is an agent tool - Arvincreator/project-golem
at
210658a1… - openyak/openyak at
bd88bff8… - xD4O/memento at
f8e1dc14… - 12ziyad/universal-memory-engine
at
b17c5486… - unibaseio/membase
at
9e03b75a… - calibrae/palazzo
at
07a788ac… - youngbryan97/aura
at
cf84a733…— read only at the second pin; the previous pin is an ancestor, so the 5,339-commit drift is real rather than a rewrite; two manifests inside the seven-day cooldown, so nothing was installed and the audit-chain suite was read rather than run this time - JPeetz/MeMex-Zero-RAG
at
f955d993…— read only; the previous pin was fetched by sha after a history rewrite and the two trees compared; one auto-run surface (.mcp.json), one build-time execution point, nothing installed or run - Goldentrii/AgentRecall-X
at
5d3389d2… - riktar/memledger
at
27f67e43… - terse-lang/terse
at
637140a3…— the report coversapps/terse-memory/ - kayba-ai/agentic-context-engine
at
31f4e118… - bytedance/deer-flow at
34bbeb18…— read only at the second pin; nothing installed or run. Both marks re-tested; scope rests on the host always resolving a user, since the default backend's shared index filters conditionally - eanai-ro/ean-agentos
at
0c5e0ecf… - FlowElement-xinliuyuansu/m_flow
at
0d585cda…— audited at this pin on 2026-09-30, which is upstream HEAD; no auto-run surface, five build-time execution points and five unpinned surfaces, read rather than executed; nothing installed, built or run. The published benchmark totals were recomputed fromFlowElement-xinliuyuansu/mflow-benchmarksata04accf3… - Whooptie/NOVA_AI
at
802a3218…— read only; no auto-run surface, two build-time execution points, twelve unpinned requirements, nothing installed or run - WindSeries83/memsem at
8332a236…— read only; the repository moved fromWindSeries69/memsem; no auto-run surface, one build-time execution point, nothing installed or run - velantrian/velantrim-exocortex-crystal
at
3ed3a53e…— read only; no auto-run surface, one build-time execution point, two unpinned surfaces, nothing installed or run - KimGLee/Cambium at
6ed60b8c… - os-tack/ostk-recall at
4c75f920… - Perseus-Computing-LLC/perseus-vault
at
9c829207… - BernhardJackiewicz/provem
at
f6ce1b69… - derekhu0002/Argo
at
607a1c1d… - Renkasha/Sovereign at
86018d65… - patibandlavenkatamanideep/memoryops-ai
at
b357e90b…— read only at v2.5; two dependency surfaces inside the cooldown and fourconftest.pyfiles that execute on pytest collection, so the eval sets, the Mem0 comparison harness and the committed perf runs were read rather than executed - HKUDS/DeepCode at
4bb4fd9c…— read only at the second pin; three dependency surfaces inside the cooldown, so nothing was installed or run. The scope predicate cited by the first reading turned out to live in a repository method with no caller, and the mark now rests on the Python filter that the live listing path applies - PrimeIntellect-ai/prime-agent
at
66abc2a6…— read only; no auto-run surface, seven build-time execution surfaces, twenty-one unpinned surfaces and eight files inside the seven-day cooldown, plus a.husky/pre-commitpayload that stays inert until something pointscore.hooksPathat it. Nothing was installed and nothing was run. The repository is the artifact behind two papers — arXiv:2608.23552 for the harness and arXiv:2605.09998 for the memory design — whose figures are not reproducible from anything in the tree. MIT - mnemosyne-oss/mnemosyne
at
3bb08dd7… - BasedHardware/omi
at
b38c5457… - kirodotdev/KiroCrew at
a170442f… - fpytloun/mnemory
at
c67b9167… - techtheist/engram
at
cb7a3944… - munch2u-a11y/Helix-AGI
at
7ecefca0… - munch2u-a11y/AIMAOS at
0d8c58c2… - Cedrick-Coto/Aeris at
68a2bd6d… - MakerViking/mimir
at
ff5b3688…— read only; no auto-run surface, no build-time execution, no manifest inside the cooldown, nothing installed or run - fpytloun/cognis at
f475b8ae… - fpytloun/intaris
at
ba0fb257… - mindmuxai/brain.md at
8064f333… - scrypster/muninndb at
34b505f4…— read only at the second pin; nothing installed or run. Five marks re-tested and given evidence records; contradiction debt now surfaces at session start - CodeAbra/iai-personal-memory-engine
at
c400059a…— read only; the screen found one auto-run surface (.claude-plugin/marketplace.json, a Claude Code plugin manifest), four build-time execution paths (setup.py, the Tauribuild.rs, twoconftest.py) and two unpinned manifests, with every lockfile at least thirteen days old, so nothing was installed, built or run. The LongMemEval figures were read from the README and the harness; the seven committed contradiction-benchmark runs were read from their own Markdown and JSON. MIT - Zenghuang-Fu/SESA-Self-Evolving-Search-Agents
at
74de5d77… - Tracer-Cloud/opensre
at
730ebc1a…— read only at the second pin; nothing installed or run. 745 commits on, the memory subsystem moved by 99 lines, all three marks re-tested at the producer, and the rejected-value gap is unchanged - yoloshii/clawmem
at
ba09cb83… - agi-is-going-to-arrive/memory-palace
at
56c9bed3… - vornicx/Midas at
ee9953c1… - carsteneu/yesmem
at
d9e02873… - CortexReach/memory-lancedb-pro
at
93899f88…— MIT declared inpackage.json, no LICENSE file in the tree - 7xuanlu/wenlan at
47971618…— the product is named Wenlan - kage-core/kage at
e7cc0876…— GPL-3.0 - esaradev/icarus-memory-infra
at
6e348708… - omega-memory/omega-memory
at
4a3cfc69… - RyjoxTechnologies/Octopoda-OS
at
583ddf19…— MIT for the SDK only; the native engine is proprietary and not in the tree - samvallad33/vestige at
3c5b1987…— AGPL-3.0; the Silent Rotation benchmark is on a different branch - varun29ankuS/shodh-memory
at
e44fdce6…— re-pinned three commits on and read from the GitHub API rather than a clone; nothing was installed or run - Mibayy/token-savior at
73e9c7f5…— the tsbench harness is not published; the README says so at this commit - H-XX-D/recall-memory-substrate
at
b448f24e… - RedPlanetHQ/core
at
4a5b18d8…— AGPL-3.0 with a Commons Clause, source-available - yantrikos/yantrikdb-server
at
36dca9ac…— Apache-2.0 - haagndaazer/vibe-cognition
at
208e7d2e… - garrytan/gbrain at
d13aa742…— read only; a.claude-plugin/directory that runs on load and apostinstall, two manifests inside the seven-day cooldown, nothing installed or run - qualixar/superlocalmemory
at
5bfa47c9…— AGPL-3.0 - orneryd/NornicDB
at
e917408d…— MIT perLICENSE.md; no plainLICENSEfile - EmpiricaAI/empirica at
763859dc… - quixiai/hexis at
7423622a… - sweetsophia/noosphere
at
6406d867…— release 1.13.3; read only, twelve manifests inside the cooldown - prefrontal-systems/cortexgraph
at
81a2daa3…— AGPL-3.0 inLICENSE, MIT inCITATION.cff - virtual-context/virtual-context
at
f8319282…— AGPL-3.0 with a commercial-licence contact - SuanmoSuanyangTechnology/MemoryBear
at
e5087b10…— read only at the second pin; no auto-run surface and nothing inside the cooldown, and nothing was installed or run. The scheduled forgetting cycle is commented out at the Celery beat entry while the crontab built from its config is still constructed and unreferenced - jumbocontext/cli
at
30e7947a…— AGPL-3.0 - Modern-Prometheus-AI/Neuroca
at
b4d4198e…— read mid-refactor; the memory integration suites are skipped at module level - winstonkoh87/Athena-Public
at
f82e8f69… - mem9-ai/mem9 at
5af03a68…— read only at the second pin; nothing installed or run.scope_enforcedwithdrawn at unchanged code: the tenant boundary is a database per tenant, and inside it the identity columns are optional filters read from the request body - hamr0/aurora at
750a39da… - AIOSAI/AIPass at
f9c4d6e4…— read only; memory is one of nineteen subsystems in a monorepo; three auto-run surfaces under.claude/, thirty build-time execution points, one manifest inside the seven-day cooldown, nothing installed or run - vbcherepanov/total-agent-memory
at
42c70076…— renamed tototal-agent-memory; the old URL still redirects - OmniNode-ai/omnimemory
at
59874e5b…— the lifecycle dispatch handler is a documented no-op; retrieval defaults to in-memory stubs - christopherkarani/Wax
at
9f79b1a6…— Swift; read on macOS notes only, never built - buildingjoshbetter/TrueMemory
at
063e5b88…— AGPL-3.0; telemetry is opt-out and defaults on. Re-pinned after six commits, all Dependabot bumps touching no source file; both marks re-tested at the producer and unchanged - 9thLevelSoftware/Daem0n-MCP
at
00809c67… - Alby2007/PLTM-Claude-repost-
at
5146bfbf…— MIT declared inpyproject.toml; noLICENSEfile in the tree - zhangfengcdt/memoir at
b8b14fce…— read only at the second pin; nothing installed or run. Three marks re-tested and given evidence records - 24kchengYe/MemoMind at
d45a7a08…— vendors and patches Hindsight; its own Python is 1,411 lines - gitmem-dev/gitmem
at
d47a625f… - Harshitk-cp/engram at
4a3d2048…— the third distinct repository named Engram in this atlas - CompleteIdeas/agent-working-memory
at
6b04ba62… - rahilp/second-brain-cloudflare
at
7bd02dab… - JubaKitiashvili/context-mem
at
2a55af0a…— six benchmark harnesses with dated result JSONs committed - nhevers/moltbrain
at
1cb9a703…— AGPL-3.0; the companion Virtuals plugin is a separate repository and was not read - hermes-labs-ai/fidelis
at
318a5cbb…— mid-rename fromcogito-ergo; the store path and the benchmark writeup still use the old name - TeleAI-UAGI/telemem at
4f11e89e…— the tech report PDF and arXiv entry were not read; the repository's own files were - alibaizhanov/mengram
at
e90a8caa…— the repository's own spec describes the regression gate as unbuilt; it is implemented and wired in - tickernelz/opencode-mem
at
0c8ed7d5…— read only; no auto-run surface, one build-time execution surface, two unpinned surfaces and two files inside the seven-day cooldown.AGENTS.mdis addressed to a reading agent and was treated as data. Nothing was installed and no test was run.SECURITY_AUDIT.mdis scoped to a commit older than this pin. MIT - CaviraOSS/LongMemory
at
4da4986d…— formerly OpenMemory; read only, nothing installed or run. A rewrite at the same slug: every previously cited file is gone, the report was rewritten,negative_evalwithdrawn for want of any test, andbitemporal,trust_stateandaudit_logadded on the new engine - aayoawoyemi/ori-mnemos
at
db5d3224…—bench/results/is gitignored, so no benchmark run is committed - sachitrafa/yourmemory
at
0bda3e03… - fozikio/cortex-engine
at
a0925da1… - breferrari/obsidian-mind
at
af615d10…— read only at the second pin and audited there on 2026-09-30, which is upstream HEAD; three in-repo auto-run surfaces (plugin manifest, five settings hooks, one MCP server), read rather than executed. The first reading missed a 1,425-case test suite and with it three marks, all of which predate that pin; the audit kept the three marks and corrected the prose and records beside them - djolex999/vir at
d6347c69… - growth-kinetics/diffmem
at
48ecbb61…— read only; no auto-run surface, no build-time execution and three unpinned dependency surfaces; nothing was installed, built or run, and no command was executed against the router or its HTTP route. MIT declared by a README badge and apyproject.tomlclassifier; no licence file in the tree. Audited on 2026-09-30 at the same pin, which is upstream HEAD - zilliztech/memsearch
at
fc0ef776… - arhuman/mnemos at
6e7b14f4… - dataojitori/nocturne_memory
at
ffb5c709…— read only at the second pin; nothing installed or run. The web backend now runsnpm installat startup when the frontend is unbuilt, which the repository screen cannot see - gupsammy/claudest
at
9088bf8d…— theclaude-memoryplugin of the eight in the marketplace - jordanmccann/agentmemory
at
3aa3b838…— the dataset file the run log names is not committed and was not obtained - vstorm-co/memv at
21891376…— read at the second pin and audited there on 2026-09-30, which is upstream HEAD; two auto-run surfaces in.claude/and two build-time execution points, read rather than executed; nothing installed, built or run. The audit addednegative_evalon committed isolation and expiry cases that predate both pins - maydali28/memcp at
81c7177d… - eshaan-nair/arcrift at
5424ea14…— the browser extension's permissions and network behaviour were not examined - divagr18/memlayer
at
5e95f440… - alash3al/stash at
d34ed430… - rahulmranga/knowledge-worker
at
bbb46379… - rlabs-inc/memory-ts at
8fcadf6d… - GoogleCloudPlatform/open-knowledge-format
at
ad30107c… - richarvey/OmniMem
at
63685f8c… - wikieden/tempomem
at
92181fbb…— read only; nothing installed - BJHYZJ/DovSG at
b355987a…— read only; the six submodules were left uninitialised and the two committed shared objects were not inspected - openmake/openmake_llm
at
1a4089d7…— read only; nine manifests inside the seven-day cooldown, nothing installed or run - DITlieD/ELAI-archive
at
26bf2bc7…— read only; four build-time execution paths and six unpinned surfaces, nothing inside the cooldown, nothing installed - bobaba76/Argos at
755f652a…— read only;requirements.txtinside the seven-day cooldown, nothing installed or run. The repository has since been deleted or made private — it returns 404 with no redirect — and the pinned commit survives only in the atlas's fork,agent-memory-atlas-archive/bobaba76--Argos - jags111/reporecall at
0c0a9ff6…— read only; a committed.mcp.jsonauto-start and aprepublishOnlybuild, nothing installed; a copy of a project whose manifest repository no longer resolves - chenxiachan/thoughtdag
at
850b89d1…— read only; five dependency files inside the seven-day cooldown, nothing installed - benmaster82/Kwipu
at
01dd7d40…— read only; one unpinned manifest - drobins25/craft at
7006381d…— read only, from a depth-one clone; four auto-run surfaces read, one manifest inside the seven-day cooldown - polmanas1998-star/holomem
at
b09cb1b0…— read only; one unpinned requirement, two manifests inside the seven-day cooldown - munch2u-a11y/HUMANs at
a1c86c29…— read only; one manifest with no lockfile, one file inside the seven-day cooldown,AGENTS.mdtreated as data - rohitg00/pro-workflow
at
7f7209d7…— read only; three auto-run surfaces read, one unpinned manifest behind a 96-day-old lockfile, MIT asserted with no licence file - Tencent/teamai-cli at
c6367b96…— read only;package.jsoninside the seven-day cooldown,AGENTS.mdandCLAUDE.mdtreated as data - aquifer-labs/artesian
at
14e4f2d9…— read only; no auto-run surface, no build-time execution path, one unpinned dependency surface in the Python bindings,AGENTS.mdandCLAUDE.mdtreated as data - jarmstrong158/context-keeper
at
d08355a4…— read only; seven hook scripts and an MCP start command as auto-run surfaces, one build-time execution path intests/conftest.py,CLAUDE.mdtreated as data - smaramwbc/statewave at
8d4d1e26…— read only; no auto-run surface, three build-time execution paths in pytest conftest files, one manifest inside the seven-day cooldown,AGENTS.mdtreated as data - caura-ai/caura at
c4406e4c…— read only; three auto-run surfaces in the project's own harness configuration, twelve manifests inside the seven-day cooldown, four build-time execution paths, ten unpinned dependency surfaces - shisa-ai/shisad at
e4e33e59…— read only; one auto-run surface, four build-time execution paths, one unpinned dependency surface,AGENTS.mdandCLAUDE.mdtreated as data - doobidoo/mcp-memory-service
at
742f50b1…— read only; four auto-run surfaces, seven build-time execution paths, eight unpinned dependency surfaces, an uninstalledpre-commithook payload - zjunlp/LightMem at
8449d574…— read only; no auto-run surface, one build-time execution path, four unpinned dependency surfaces including arequirements.txtwith twenty-six unversioned entries - vshulcz/deja-vu at
6a33ce28…— read only; three auto-run surfaces, six manifests inside the seven-day cooldown, one build-time execution path, five unpinned dependency surfaces - grapeot/context-infrastructure
at
421df58b…— read only; no auto-run surface, no build-time execution path, one unpinned dependency surface,AGENTS.mdtreated as data; no licence file in the repository - Intelligent-Internet/CommonGround
at
10b50ddb…— read only, without submodules; one auto-run surface, one build-time execution path,uv.lockunchanged for 113 days,AGENTS.mdtreated as data. The CG-Cardbox payload store is a submodule and was not present - tenequm/pond at
3507b50a…— read only; one auto-run surface, two manifests inside the seven-day cooldown, two build-time execution paths, four unpinned dependency surfaces - JanYork/llm-wiki-cli
at
11e869f5…— read only; no auto-run surface, three manifests inside the seven-day cooldown, one build-time execution path, one unpinned dependency surface, and nothing was built or run - Haustorium12/continuity-v2
at
4e98d464…— read only; one auto-run surface in the four hook scripts, no manifest, no build-time execution path and no unpinned dependency surface, and nothing was installed or run - siimvene/memspec
at
7c0a47f3…— read only; one auto-run surface in the three Claude Code hooks, one build-time execution path, one unpinned dependency surface, three manifests dated inside the cooldown by the shallow clone's tip date, and nothing was installed, built or run - AlexisOlson/somnigraph
at
6dc4d349…— read only; no auto-run surface, no manifest inside the cooldown, no build-time execution path and no unpinned dependency surface, with a lockfile 161 days old and aCLAUDE.mdtreated as data; nothing was installed or run. Apache-2.0 under a Commons Clause, which is not an open-source licence - slowave-ai/slowave at
00b5a1d7…— read only; one auto-run surface, five build-time execution points, one unpinned dependency surface and one dependency file inside the seven-day cooldown, withuv.lockpresent. Nothing was installed, built or run and no benchmark was reproduced. AGPL-3.0-or-later, with a commercial licence offered separately - ultracontext/ultracontext
at
736b4711…— read only, onmain; three side branches were left unread, one build-time execution path in the JS SDK'spostinstall, eight unpinned dependency surfaces and a root lockfile 100 days old; nothing was installed, built or run - openmasq/openmasq
at
a8d9a9ee…— read only; a.githooks/directory not installed, nineteen dependency files inside the seven-day cooldown, nothing installed - no-human-ai/no_human
at
5f99b7af…— read only; twoconftest.pyfiles that execute on collection, six dependency files inside the seven-day cooldown, nothing installed or run - El-AI-Intelligence/engram-format
at
f1e92dad…— read only; both manifests inside the seven-day cooldown, nothing compiled or run - khoj-ai/khoj at
ae229ca8…— read only; a devcontainer and a VS Code settings file that execute on open, five unpinned surfaces, nothing installed or run - Mintplex-Labs/anything-llm
at
90108f98…— read only from a shallow clone; a devcontainer, a.gitmodulesand two VS Code files that run on open, thirteen manifests inside the seven-day cooldown, nothing installed or run - laurent22/joplin
at
981a03c5…— read only from a shallow clone; an.envrcand a VS Code settings file that run on open, over a hundred manifests inside the seven-day cooldown, nothing installed or run - usememos/memos at
14d3c689…— read only from a shallow clone; ago.sumand four manifests inside the seven-day cooldown, nothing installed or run - silverbulletmd/silverbullet
at
b7548912…— read only from a shallow clone; a VS Code settings file that runs on open, ten manifests inside the seven-day cooldown, threebuild.rsfiles and two Makefiles, nothing installed or run - siyuan-note/siyuan at
9f775e8a…— read only from a shallow clone; a pnpm lockfile with thirty-one floating ranges, nothing inside the seven-day cooldown, nothing installed or run - TriliumNext/Trilium at
d78999ff…— read only from a shallow clone; an.envrc, an.mcp.jsonand a VS Code settings file that run on open, twenty-seven manifests inside the seven-day cooldown, four build-time execution points, nothing installed or run - joshhhhhan/VISTA
at
900aa338…— read only; apyproject.tomlinside the seven-day cooldown with no lockfile beside it, nothing installed or run - marsmanleo/marsnme at
25b7d6c1…— the hosted service was not used - The-825/breadcrumbs at
bf0b6a2b…— the fleet architecture its docs describe is not in the tree - HamedMP/matrix-os
at
f155f1a1…— read only; two auto-run surfaces, two build-time execution surfaces, twenty-seven unpinned surfaces and fourteen files inside the seven-day freshness cooldown, ten of them changed the day it was read. Nothing was installed and nothing was run;AGENTS.mdandCLAUDE.mdwere read as data. AGPL-3.0 - veracium-ai/Veracium
at
1d33f019…— read only, from a full clone; four files scanned, one auto-run surface, one build-time execution point, one unpinned dependency surface and one dependency file inside the seven-day cooldown. Nothing was installed, built or run and no benchmark was reproduced. MIT - VectifyAI/OpenKB
at
ff54396e…— read only; one auto-run surface, one build-time execution surface, one unpinned surface, and both lockfiles unchanged for more than a month.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were treated as data. Nothing was installed and nothing was run. Apache-2.0 - munch2u-a11y/Habitus-AI
at
f93b770e…— read only; no auto-run surface, no build-time execution surface, one unpinned surface, and apyproject.tomlmodified the same day. Nothing was installed and nothing was run. Apache-2.0 - infiniflow/ragflow at
302ada2c…— read only; one auto-run surface (.github/copilot-instructions.md, a stale template still carrying(fill)placeholders and naming arequirements.txtabsent from the tree), thirty-six build-time execution surfaces, eight unpinned surfaces and nine files inside the seven-day cooldown,go.modandgo.sumamong them on the day of reading. Nothing was installed, no container was started and nouv,make,goor npm command was run.AGENTS.mdandCLAUDE.md, which is a symlink to it, are addressed to a reading agent and were recorded as data. Read for the Memory subsystem; the retrieval-augmented-generation half is a document index and out of scope. Apache-2.0 - openvurp/openvurp
at
fc68e643…— read only; the screen found no auto-run surface and no build-time execution, and two unpinned manifests both changed inside the seven-day cooldown (pyproject.tomlon the day of the pinned commit,channels/wa-bridge/package.jsonthe day before, neither with a lockfile), so nothing was installed and nopip,npmorpytestcommand was run. Test functions were counted withgrep; the CI workflow's own comment says 443 and the tree holds 594. MIT - railstracks/animus at
6d0e14fb…— read only; the screen found no auto-run surface and no build-time execution, one unpinned manifest (admin-ui/package.json, 12 floating ranges behind a lockfile) and both lockfiles unchanged for 50 days, so nothing was installed, nocmake,make,npmor Lua command was run, and no binary from the checkout was executed, including the committedtest_hkdfat the tree root.AGENTS.mdandAGENTS.orm.mdare both addressed to a reading agent and were recorded as data; one of their claims names a directory,include/animus_kernel/store/, that is not in the tree. Apache-2.0 - AreevAI/areev at
5b6b29f3…— read only, from a full clone; one auto-run surface, two build-time execution points, three unpinned dependency surfaces and thirty dependency files inside the seven-day cooldown.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run and no benchmark was reproduced. Dual MIT or Apache-2.0 - Taki7980/Ai-workflow
at
ae3d3851…— the screen scanned one file, there being no manifest, lockfile or hook in the tree; the execution surface is fourteen PowerShell scripts it does not parse, read by hand and not run.AGENTS.mdwas read as data. No licence file - ScPlaceholder/MOTH-agent-memory-template
at
d4b404c3…— the screen returnedNOTHING SCANNED, so the execution surface was read by hand: standard library only, writes confined totempfiledirectories inside--selftest, one local-Ollama call. On that basis the tools were run and their output is quoted in the report. Apache-2.0 - Lumen-Labs/brainapi2
at
b434f92a…— read only; no auto-run surface, three build-time execution surfaces, three unpinned surfaces, and four dependency manifests inside the seven-day freshness cooldown. Nothing was installed and nothing was run;AGENTS.mdandCLAUDE.mdwere read as data. BUSL-1.1, Additional Use Grant: None, Change Date 2030-08-13 - sebastianbrzustowicz/Agentic-GraphRAG-Blueprint
at
e33f5f69…— read only; no auto-run surface, two build-time execution surfaces, four unpinned surfaces, and every dependency manifest inside the seven-day freshness cooldown. Nothing was installed and nothing was run. MIT - FareedKhan-dev/all-agentic-architectures
at
cf9d620a…— thememory/package and the twelve architectures that import it; the other twenty-six were skimmed. Read only; two auto-run surfaces (a devcontainerpostCreateCommand, a committed.vscode/settings.json), one build-time execution surface, one unpinned surface and no lockfile. Nothing was installed and nothing was run. MIT - KhanCold/merchantbench
at
f44ce969…— read only; no auto-run surface, no build-time execution surface, four unpinned requirement files and no lockfile. Nothing was installed and nothing was run. Apache-2.0 - memseekai/membukkit at
ecd2cfe9…— read only; no auto-run surface, no build-time execution surface, one unpinned surface, and both lockfiles unchanged for fourteen days. Nothing was installed and nothing was run. Apache-2.0 - OpenHands/software-agent-sdk
at
97dbce5c…— read only; no auto-run surface, fourteen build-time execution surfaces, four unpinned surfaces and six files inside the seven-day cooldown.AGENTS.mdis addressed to a reading agent and was treated as data. Nothing was installed and nothing was run. MIT - NIMI-research/Tycho at
f68912a7…— read only; no auto-run surface, one execution surface (aMakefilewhose default target is worth checking before a baremake) and one unpinned surface. Nothing was installed and nothing was run. Apache-2.0 - ryanbbrown/Retrodict
at
71672e8e…— read only; no auto-run surface, no unpinned surface, and one execution surface intests/conftest.py, which runs on pytest collection before any test does.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were treated as data. Nothing was installed and nothing was run. - Mininglamp-AI/polyphony-arc-3
at
9bb384c2…— read only; no auto-run surface, no execution surface, one unpinned surface. Nothing was installed and nothing was run. MIT - github/gh-aw at
9259aea1…— the memory subsystem only; the compiler's other surfaces were not traced - mksglu/context-mode at
f889a053…— Elastic License 2.0; the sandbox executor was not exercised - ollama/ollama at
38fdb5dd…— theagent/package was read at the previous pin and is removed at this one; the inference engine was not read - oraios/serena at
18fa47bf…— the memory subsystem; the language-server tooling was skimmed, not traced - lucasrosati/claude-code-memory-setup
at
a89c275e…— the importer, its cron wrapper and the SessionEnd hook; Obsidian and Graphify are separate and Graphify has its own report - vllm-project/semantic-router
at
b4be720c…— the memory package and its end-to-end suite; the classification and routing halves were not traced - ruvnet/ruflo at
2602b642…— read only at the second pin; ten dependency surfaces inside the cooldown, nothing installed or run.negative_evaladded on a supersession test present at the first pin, on a store now documented as the live hierarchical-memory path - alexgreensh/token-optimizer
at
689cba8a…— PolyForm Noncommercial 1.0.0; the OpenClaw TypeScript half, not the 40,314-line Python core - dahshanlabs/klypix-mcp
at
43e7c5cf…— read only; the dependency surface was inside the seven-day cooldown, so nothing was installed and the committed benchmark was inspected rather than reproduced - cbalgeman/agent-mesh
at
a8187089…— read only; no third-party dependencies to install, and the two shipped examples were read rather than run - SmythOS/sre at
5c382a1e…— read only; theMemoryManagersubsystem, the fourMemory*components, the security decorator and the SDK chat store, not the LLM-provider or component libraries - QwenLM/Qwen-MM-Plugins
at
07736672…— thevideo-memoryandomni-memorycapabilities; the other thirteen are tool bundles. Read only at the third pin, withpyproject.tomlinside the cooldown; nothing installed, built or run. A node-type exclusion case earnsnegative_eval, andomni-memorystamps its superseded triples on a copy the written store never holds - tinhien11/remem-mcp at
7590cece…— read only at the third pin, 70 commits and four versions on; a manifest was inside the cooldown, so nothing was installed. All four marks re-tested at the producer; the v11 raw fallback dropstrust_statefrom its exclusions and is held off rejected rows by the soft-delete instead - buiilding/Windie-Sandbox
at
bd0dcd8f…— read only; the three declared submodules were left uninitialised and nothing undervendor/was inspected, and the dependency surface changed the same day so nothing was built - potpie-ai/potpie
at
7726221d…— read only; six manifests were inside the seven-day cooldown and aMakefileand fiveconftest.pyexecute on collection, so nothing was installed and the conformance and approval assertions were read rather than run - repowise-dev/repowise
at
04e1dc67…— read only; a.claude-plugin/directory and an MCPserver.jsondeclare start commands, five dependency surfaces were inside the seven-day cooldown, and a pytest tree of this size carries manyconftest.pyfiles that execute on collection, so nothing was installed and the published benchmark numbers were read rather than reproduced - zzet/gortex at
2b5480bf…— read only at the second pin; nothing installed or run. Marks hold; the trust record now names the speculative tier that is excluded by default - truefoundry/trueforge
at
4fad485a…— read only at the second pin; eight dependency surfaces inside the cooldown, nothing installed or run. The tenant now comes from the request context, real only under the TrueFoundry authenticator; turn reads still take a session id alone - NORTHTEKDevs/lossless-context-mcp
at
1ef5bf9e…— read only; two auto-run surfaces (thehooks/directory, which is the product, and an MCPserver.json), one build-timepackage.jsonlifecycle script and one unpinned range with a lockfile beside it; the benchmark numbers were read rather than reproduced, and the corpus behind them is the author's own transcript history and is not published - RAZZULLIX/KAISEN
at
b709ecc7…— read only; no auto-run surface, one dependency manifest inside the seven-day cooldown, one unpinned range, and atests/conftest.pythat executes on collection; nothing was installed and no test was run - vercel-labs/fx at
e45d7809…— read only; no auto-run surface, one dependency manifest inside the seven-day cooldown, two unpinned ranges in test packages, and anAGENTS.mdaddressed to a reading agent, recorded as data; the corrupt-file path in the memory tool was established by readingloadMemoriesand its caller rather than by executing them - Cyb3rb1ade/openclaw-plur1bus-memory
at
c381fd57…— read only; no auto-run surface, two manifests inside the seven-day cooldown, nothing installed or run - OmniNode-ai/omniintelligence
at
25ee01e7…— read only, on thedevdefault branch; its framework packages resolve from PyPI, andomnibase_corev0.47.24 andomnibase_infrav0.38.59, the tagsuv.locknames, were read for the evidence-tier ordering, the repository runtime and the view refresh;omnibase_spiandomnimarketwere not read beyond an organisation-wide code search - OmniNode-ai/omniclaude
at
6f062cd5…— read only, on thedevdefault branch; same private framework dependencies, and both dependency manifests were inside the seven-day cooldown at this pin, so nothing was installed. Audited on 2026-09-20 at the same pin: one sentence said two cohort-identity parameters are never passed anywhere in the repository, and the tests pass both at five call sites — the production call site passes neither, which is what the finding rests on. - roandejager/Hillock at
94e6ae1b…— read only; its benchmark needs a local Ollama model and its first launch fetches 822 MB of GloVe vectors, so the published numbers were read rather than reproduced, and the encoder and gate-geometry findings were checked by reimplementing the arithmetic in separate code - KTVSUN/memory-compiler
at
e79ee179…— read only, at the third commit of a repository created the same day;screen_repo.pyreported NOTHING SCANNED, so the eleven-file tree was enumerated and read by hand - MythologIQ-Labs-LLC/agent-memory
at
c80f0685…— read only; one auto-run surface (.github/copilot-instructions.md), three manifests inside the seven-day cooldown, nothing installed or run - Osmantic/ODS at
21f4b3a6…— read only; reviewed forods/memory-shepherd/, the only agent-memory mechanism in a tree that is otherwise a deployment system for a local AI stack - jbsalles/Selmem at
8da0e8d1…— read only; no auto-run surface, no build-time execution point and no manifest inside the cooldown; nothing installed, built or run - Tencent/WeKnora at
b82fd6c0…— read only; four dependency surfaces inside the cooldown and six build-time execution points, so nothing was installed or run; reviewed forinternal/**/memory*, the long-term memory subsystem added at v0.8.0, with the surrounding RAG and wiki framework as context - dominiclachance/neurakeep
at
57f1afa2…— read only; both manifests were inside the cooldown, so nothing was installed and the native SQLite module was never built. The local core is Apache-2.0; the product's hosted tier is commercial and was not inspected - alexisfox7/PRO-LONG at
9d2f2d46…— read only; the sync routine in section 9 of its report was re-derived over scratch files rather than run from the tree, and the 25 committed runs were compared byte for byte against their own sandbox copies. Audited on 2026-09-19 at the same pin, which is still the tip, after the report published two false absence claims — a missingLICENSEfile that is present, and no test file where one exists - jerber/arc-code at
6b33c1f7…— read only;tests/conftest.pyexecutes on collection and two dependency surfaces changed the day of the reading, so nothing was installed and no test was run - OmniNode-ai/knowledge-base
at
cb724907…— read only; nothing was installed and the counts come from reading the frontmatter of every artifact in the tree - faisalhussain-devs/MindCache
at
45b904a7…— read only; the manifest had changed four days earlier and carries no lockfile, so nothing was installed and no test was run - szara7678/OpenAkashic
at
6c916d9a…— read only; two MCP manifests declare start commands and two dependency surfaces are unpinned, so nothing was installed and nothing was run - TrianglLabs/otis
at
879397c8…— read only; the manifest changed the day before the reading and carries twenty-two floating ranges with no lockfile, so nothing was installed and no test was run - Q00/ouroboros at
79a423e8…— read only; two harness hooks fire on prompt submit and after every edit, and both dependency surfaces changed inside the cooldown, so nothing was installed and no test was run. The hooks were read first and reach neither the network nor anything outside the project and~/.ouroboros/data - camgitt/memoir at
8de61433…— read only; one auto-run surface (server.json), two manifests inside the seven-day cooldown, nothing installed or run - deepseek-ai/deepseek-harness
at
0d1f5000…— read only; the repository became public hours before the reading, so every one of its 244 dependency surfaces is inside the cooldown and 97 manifests are unpinned. Bothpostinstallscripts were read first and neither reaches the network; nothing was installed and nothing was executed - nutshellai-tech/mobius
at
0f74ca84…— read only; seven dependency surfaces changed inside the cooldown, so nothing was installed and no test was run. Source-available under a bespoke non-commercial licence rather than an OSI-approved one - itechmeat/open-second-brain
at
54bb28d9…— read only; two committed git hooks are activated by the packagepreparescript and were read first (fmt, lint, typecheck only, no network), and two dependency surfaces sit inside the cooldown, so nothing was installed and no test was run - getzep/zep at
495bf728…— read only; nothing was installed, built or run. The committed LoCoMo experiments were read from git rather than rerun, and Graphitiv0.3.21and thezep-cloud3.28.0 SDK were read at their tags for the engine and contract claims - zhongwanjun/MemoryBank-SiliconFriend
at
cf61c419…— read only; the screen returned NOTHING SCANNED, so the execution surface was read by hand. The forgetting curve's behaviour was established by evaluating the expression, not by running the repository - noahshinn/reflexion at
218cf0ef…— read only;.gitmodulespulls further trees on a recursive clone andhuman-eval/setup.pyexecutes at install time, so neither was done. The AlfWorld success trajectories were computed from the committed JSON - langchain-ai/langgraph
at
230927fb…— read only; 8 dependency surfaces sit inside the cooldown. The backend divergences reported were read from the SQL and from the absence of a pragma, not observed in a running store - langchain-ai/langchain
at
41d35728…— read only; 42 dependency surfaces sit inside the cooldown, and the monorepo is the rare fully lockfiled tree here, with zero unpinned surfaces - NirDiamant/Agent_Memory_Techniques
at
dacb760a…— read only; nineteen unpinned requirements and atests/conftest.pythat runs on pytest collection, so nothing was installed and no notebook was executed. The code was read by extracting the notebook cells as source - xai-org/grok-build at
37949780…— read only; 102 dependency surfaces sit inside the cooldown and sevenbuild.rsfiles execute at build time, so nothing was installed and the tree was never compiled. The deletion gap reported was established by reading the clear path against the index location, not by running a store - crlome/runar-forge at
68224879…— read only; the cleanest screen of anything read this round, with no auto-run surface, no build-time execution and no unpinned manifest, but four dependency surfaces inside the cooldown, so nothing was installed or built. The graduation cap reported was established by reading the caller against the list query's ORDER BY - martian56/redcell
at
cb557584…— read only; five unpinned manifests and eight dependency surfaces inside the cooldown, so nothing was installed or run. The scope call — findings in, the LangGraph checkpointer out — was made by tracing what the assistant reads back against what the checkpointer stores - kovartravis/neuron at
14872690…— read only; one auto-run surface (the.claude/settings.jsonhooks the system installs), two build-time execution points, nothing installed or run - cytostack/openwolf at
521fbc47…— read only, at release 2.1.0; no auto-run surface, one build-timeprepublishOnly, and bothpackage.jsonandpnpm-lock.yamlchanged the same day, inside the seven-day cooldown, so nothing was installed and nothing was run. The reflection cron's whole-file replacement ofcerebrum.mdwas established by readingrunAiTaskagainst the shipped cron manifest, not by executing it - juanceresa/sift-kg at
d786991c…— read only; no auto-run surface, atests/conftest.pythat executes on pytest collection and no lockfile besidepyproject.toml, so nothing was installed and no stage of the pipeline was run. The claim that a rebuild discards the review decisions was established by readingbuild's inputs against whereapply-mergeswrites - outworked/outworked at
89ed7b99…— read only, at v0.4.3; no auto-run surface, one build-time lifecycle script and one unpinned range behind a lockfile, so nothing was installed and the desktop app was never launched. The caller-supplied scope was established by reading the three tool definitions againsthandleMcpRequestand itsagentIdinjection, not by running two agents against one store - Corbell-AI/Corbell at
75c7b20a…— read only; no auto-run surface, atests/conftest.pythat executes on pytest collection, and an unpinnedpyproject.tomlwith no lockfile beside it, so nothing was installed and no command was run. The confirmation-gate finding was established by reading theauto_scandefault against the only assignment toCandidateDoc.confirmed - legoambarish/portable-handoff
at
ec5f203b…— read only, at version 0.1.0; screened on a full clone on 2026-09-26 at the same pin: one build-time execution point (tests/conftest.py) andpyproject.tomlwith no lockfile, so nothing was installed and no capsule was produced. The provenance cap and the fields it skips, the finalize merge, the budget's output and the load-time briefing were read frommodels.py,finalize.py,budgeting.py,cli.pyandload.pyagainst the committed tests - memorax-ai/memorax-code
at
1525c20f…— read only; no auto-run surface, three build-time execution points, nine dependency manifests inside the seven-day cooldown, andAGENTS.mdandCLAUDE.mdaddressed to a reading agent, recorded as data. Nothing was installed, no client was deployed and no request was made to the hosted service, so every claim is about the client half: the store behind/v1/memories/*was not exercised. The second reading read the scope key itself —baseUserId@repositoryName, with the collision-resistant key kept local — and found the task-status projection deleted - Lolaplex/agents-memory
at
a60babbb…— read only, at version 1.1.0 on a 103-commit history; no auto-run surface, no build-time execution, one dependency manifest inside the seven-day cooldown, andAGENTS.mdandCLAUDE.mdaddressed to a reading agent, recorded as data. Nothing was installed and no test was run; the line-numbered id and the revise-in-place return string were read fromstore.pyagainst the ABI it implements - ArihantDeva/heimdall
at
8c7fb780…— read only, re-screened at the re-pin; no auto-run surface, no build-time execution, three files inside the seven-day cooldown and two unpinned dependency surfaces (three floating ranges inpackage.jsonagainst a present lockfile, sixteen>=requirements invendor/graphify/requirements.txt). Nothing was installed, no Graft daemon was started, no reconciler was run and no search was issued, so the verdict ordering, the journal schema and the convergence loop were read frombin/kb_search_verify.pyandbin/lib/; Graft's vendored C source was read only for its licence and vendoring note - thefullnacho/hestia at
51ebf7b0…— read only; no auto-run surface, one build-time execution point, three unpinned surfaces. Nothing was installed, no local model was pulled and no service was started; the memory records are gitignored runtime data and were absent from the checkout, so every claim is about the code that writes them - nanocoai/nanoclaw
at
f5967d3c…— read only; two auto-run surfaces, one build-time execution point, two unpinned surfaces, and bothpackage.jsonandpnpm-lock.yamlchanged the same day. Nothing was installed, no container was built and no command from the tree was run - RuneLind/muninn at
b95d5044…— read only; one auto-run surface, no build-time execution, one unpinned surface, one dependency file inside the seven-day cooldown. Nothing was installed, no Postgres was started and no test was run - LinzeColin/AgentDatabase
at
85149238…— read only; one auto-run surface and a long tail of build-time execution points inside vendored skill reference material. Nothing was installed and no script was run. No licence file is present in the tree - AdultSwimmer/AuraOS at
81dffa9b…— read only; no auto-run surface, two build-time execution points in documentation Makefiles, three unpinned requirement files, nothing inside the seven-day cooldown. Nothing was installed, no model was pulled and no server was started; the two committed.pycfiles were disassembled with the standard library'sdisand not executed. No licence file is present in the tree; the README's License section says MIT - patham9/mettaclaw
at
7b30527b…— read only; the screen returned NOTHING SCANNED, because the repository carries no package manifest of any kind, so the dependency surface was read by hand rather than parsed. PeTTa was not cloned, nothing was installed and no agent was run - singnet/Omega at
78c6691a…— read only; build-time execution declared in sixconftest.pyfiles underAutotests/. Nothing was installed, no container was built and no test was run - NORTHTEKDevs/genome at
ea76cf92…— read only; two auto-run surfaces (mcp.jsonandserver.json, both MCP publication manifests declaring a start command), two build-time execution points (prepublishOnlyin the TypeScript SDK andtests/conftest.pyon pytest collection), two unpinned surfaces, and three files changed three days before the pin, inside the seven-day cooldown. Nothing was installed, no test or benchmark was run, andpython -m genome.verify— the repository's own air-gap receipt — was not invoked - nehloo-interactive/graphnosis-app
at
b79be25d…— read only; one auto-run surface, two build-time execution points, eight unpinned surfaces including a non-registry dependency pinned asgithub:nehloo-interactive/graphnosis-secure-sync#v0.4.1, and aCLAUDE.mdaddressed to a reading agent. Nothing was installed, nothing was built and no test was run. The graph store, its encryption and the op-log codec live in that pinned dependency and were not read; the report covers the sidecar around it and says where its claims stop - vmDeshpande/Arcon
at
f04a5e49…— read only; no auto-run surface, no build-time execution, ten unpinned surfaces and nine files inside the seven-day cooldown. Nothing was installed and no test was run. The README's licence badge points at aLICENSEfile the tree does not contain, so what a reader may do with it is not established by this repository - vmDeshpande/ai-agent-automation
at
86b6072d…— read only, at release v0.12.0; screened again on a full clone on 2026-09-26 at the same pin: one build-time execution point (the rootpreparescript running husky), three unpinned surfaces with lockfiles unchanged for 13 days, two inert husky hook payloads and anAGENTS.mdtreated as data. Nothing was installed and no test was run. The recall service, the store, the embedding adapter, theAgentschema and the one memory test file were read against each other - hellangleZ/Agent-MemoryForge
at
770b4eef…— read only; screened twice at this pin, on 2026-09-13 and on a full clone on 2026-09-26: twoconftest.pyfiles that execute on pytest collection, apyproject.tomlwith no lockfile, fifteen floating ranges inportal-uibehind a lockfile, and nothing inside the seven-day cooldown. Nothing was installed and no suite was run - aakarim/OpenLore
at
d1038017…— re-read at the v0.7.2 release;dashboard/package.jsonand its lockfile inside the 7-day cooldown and aMakefileexecution surface. Nothing was installed, built or run. The shellhistoryquery filters by plain prefix and skips the nested-docset carve-out the filesystem read path enforces - rekal-dev/rekal-cli at
4550e602…— read only; screened on 2026-09-13 and again on a full clone on 2026-09-26 at the same pin: two auto-run surfaces (a.claude-plugin/marketplace manifest and a configured LFS smudge filter over the packed embedding model),go.sumunchanged since 16 July 2026, and an uninstalledscripts/pre-pushhook. Nothing was installed and no suite was run - xerj-org/xerj at
2c31f968…— read only; screened again on a full clone on 2026-09-26: 9 dependency manifests inside the 7-day cooldown, twobuild.rsfiles cargo executes at build time, and two uninstalled git hooks. Nothing was installed, built or run. The boundary between namespaces is a reserved index per namespace behind an index-name authorizer, with no scope key on the document - linggen/linggen-memory
at
9e1c0326…— read only; one auto-run surface and two dependency manifests changed inside the seven-day cooldown. Nothing was installed and no test was run - JordyZomer/lemmalog at
b8e24dbd…— read only; screened on 2026-09-13 and again on a full clone on 2026-09-26, clean both times: no auto-run surface, no build-time execution point, and aCargo.locklast changed on 2 September 2026.scripts/install.shruns only when invoked.cargo testwas not run, so the claims about tests are claims about their committed source - GuyMannDude/mnemo-cortex
at
fec22efd…— read only; four dependency manifests underintegrations/changed the day of the pin, inside the cooldown, and a build-time execution point. Nothing was installed and the suite was not run - MaxFreedomPollard/Compartment
at
05c2816a…— read only; three auto-run surfaces (a.claude-plugin/marketplace manifest,mcp.jsonandserver.json), atests/conftest.pythat executes on collection, and apyproject.tomlchanged inside the seven-day cooldown. Nothing was installed, no harness was wired and the suite was not run - Dicklesworthstone/cass_memory_system
at
61561508…— read only; an npmpostinstallrunning a patch script, and three dependency files changed two days before the pin, inside the cooldown. Nothing was installed and the suite was not run - nambok/mentedb at
4ba993dc…— read only; screened on 2026-09-13 and again on a full clone on 2026-09-26 at the same pin: two cargobuild.rsbuild-time execution points, floating benchmark requirements and an agent-instructions file. Nothing was installed andcargo testwas not run, so the claims about tests are claims about their committed source - iamtouchskyer/memex at
453c0e33…— read only; screened on 2026-09-13 and again on a full clone on 2026-09-26: six auto-run surfaces — a.claude-plugin/marketplace manifest,.cursorrules,hooks/andhooks/hooks.jsonregistering SessionStart and Stop,server.jsonandsmithery.yaml— two build-time execution points, an npmpreparethat copiesscripts/pre-commitinto.git/hooksand aprepublishOnlybuild, plus a committeddist/, and nothing inside the seven-day cooldown on the second screen. Nothing was installed, no hook was registered and no test was run - framerslab/agentos at
1e992183…— read only, re-pinned one commit on; an npmpreparelifecycle that builds on install and aprepublishOnlychain, nothing inside the cooldown;pnpm-lock.yamllast changed on 20 July 2026. Nothing was installed and no test was run - grpcer/ownmem at
14f4edec…— read only; one auto-run surface and two dependency files changed within the seven-day cooldown, so nothing was installed and neither the self-tests nor the public benchmark was run - Coding-Dev-Tools/engraphis
at
ca790261…— read only; two auto-run surfaces (a.claude-plugin/marketplace manifest and committed.githooks/pre-commit), five build-time execution points, and seven dependency files changed the day of the pin, inside the cooldown. Nothing was installed, no hook was registered and no eval was run. Open-core: the README places hosted sync, analytics and team services outside this repository, and only the local engine was read - kiycoh/silica-core at
3fd11a00…— read only; four auto-run surfaces (a.claude-plugin/marketplace and plugin manifest, ahooks/hooks.jsonregistering SessionStart, PreCompact and Stop, and anmcp.json), three build-time execution points, and bothpyproject.tomlanduv.lockchanged the day of the pin. Nothing was installed, no hook was registered, no eval was run and no vault was opened. One flagged finding is a false positive worth recording:silica/router/states/setup.pymatched the install-time-execution heuristic on its filename and is an FSM state - NORTHTEKDevs/rck
at
440f6259…— read only; no auto-run surface, one build-time execution point (aMakefilein the paper directory), one unpinned surface, nothing inside the cooldown. Nothing was installed, no test was run and no benchmark was executed; the substrate comparison reported here is the project's own measurement, read from its paper and the JSON studies indata/ - aiming-lab/AutoResearchClaw
at
be4ba475…— read only; no auto-run surface, one build-time execution point (tests/conftest.pyon pytest collection), one unpinned surface, nothing inside the cooldown. Nothing was installed and no test was run - Sidharth-Singh10/weave
at
ff8a6afa…— read only; no auto-run surface, no build-time execution, one unpinned surface and three files inside the seven-day cooldown. Nothing was installed, no container was started and no test was run, so the findings come from the tree and its nine migrations. There is noLICENSEfile in the repository - RakuenSoftware/aimee
at
d7cb7915…— read only; one auto-run surface (.claude/hooks/), one build-time execution point, three unpinned surfaces, eleven manifests dated inside the seven-day cooldown by a depth-1 clone, nothing installed or built; the commit is ontesting, whichorigin/HEADdesignates as the default branch - Starksood/fireweed-mcp
at
b37747b0…— read only; one auto-run surface, one unpinned surface and one dependency file inside the seven-day cooldown, no build-time execution. Nothing was installed and no test was run, so the findings come from the tree. FSL-1.1-ALv2, source-available, converting to Apache 2.0 on 1 January 2028. The README cites recall figures and erasure canaries held in a repository not published at this pin; those are recorded as pointers and not as citations - zeenie-ai/OpenCompany
at
2d238ee6…— read only; no auto-run surface, eight build-time execution surfaces, four unpinned surfaces and two files inside the seven-day cooldown. Nothing was installed and no suite was run, so the findings come from the tree.CLAUDE.mdat the root is addressed to a reading agent and was treated as data. MIT - Open-Finance-Lab/AgenticTrading
at
8df40dbe…— read only; one auto-run surface, five build-time execution surfaces, seven unpinned surfaces and two dependency files changed inside the seven-day cooldown.CLAUDE.mdat the root is addressed to a reading agent and was treated as data. Nothing was installed and nothing was run. OpenMDW-1.0, a model-and-data licence rather than a software one - SenteLabsAI/OpenExecutive
at
c54d0e71…— read only; three auto-run surfaces, two build-time execution surfaces, one unpinned surface, and lockfiles unchanged for 56 and 75 days.CLAUDE.mdat the root is addressed to a reading agent and was treated as data. Nothing was installed and nothing was run. Twelve commits between 11 June and 3 July 2026, with nothing since. Apache-2.0 - buiilding/WindieOS at
da2deadc…— read only; one auto-run surface, one build-time execution point, eight unpinned manifests, lockfiles unchanged for 47–130 days so no cooldown exposure. Nothing installed or run. A distinct repository from the same author's Rust Windie Sandbox, sharing no git history; the embedding-space rebuild and delete gaps were read fromlocal_store.pyagainst the architecture doc and the delete-cleanup tests - Krilliac/Sonder-runtime
at
1a41a88d…— read only; no auto-run surface, no dependency surface inside the cooldown, two build-time execution points (conftest.py), two unpinned dev/train requirement ranges. Nothing installed or run; the quarantine base-rate and attribution guards, the outcome-provenance enforcement, and the newlesson_tombstonesrejected-value registry were read fromretriever.py,memory_store.py,reflection.pyandlesson_pruner.pyagainst the committed tests - Anchorstate-Lab/GMR at
7bee2a08…— read only, at release v0.6.6; dependency surfaces inside the seven-day cooldown and the ordinary Cargo build surfaces,Cargo.lockpresent, so nothing was installed or run. The content-addressed transition, theAttempt/ReasonClass/FailureCodetaxonomy, the append-only journal and the drift-surfacing semantics were read fromgmr-coreandgmr-runtimeand cross-checked against the committedgrounding.rsandoperations.rstests - parcadei/Continuous-Claude-v3
at
d07ff4b0…— read only; two.claude/auto-run surfaces (hooks/,settings.json), five floating npm ranges behind a committed lockfile, one floatingopc/pyproject.toml, so nothing was installed or run.opc/was established as the authoritative memory tree (the.claude/scripts/core/*.pycopy has nodb/layer); the daemon extraction, the broken default SQLite backend, the per-session dedup against global recall, the inert confidence and the unstamped embedding column were read fromopc/scripts/core/anddb/againstdocker/init-schema.sqland the compiled hooks - fellowgeek/mcp-memory
at
a50a8770…— read only; one build-time exec (the setup wizard) and one unpinned surface (fastmcp<=3,pyyaml>=6.0), nothing inside the cooldown, so nothing was installed or run. The upsert-and-mirror OKF store, the FTS5 read path, the namespace predicate on retrieve and delete and its optional form on search, thelog.mdchange log, and the write-only handling of OKF'sstatus/verified/stale_afterwere read from the five source files againsttest_memory.py - CloudLLM-ai/mentisdb
at
4c9b9504…— read only; no auto-run surface, one build-time exec, one unpinned surface, so nothing was installed or run. The SHA-256 hash chain and its refuse-to-load verification, the append-only supersession with default exclusion, the relation-hosted validity time, and the Ed25519-verified skill registry were read fromsrc/lib.rs,src/server.rsandsrc/skills.rsagainst the committedinvalidation_search_tests.rs; the two hash-excluded fields and the unverified thought signatures were confirmed against the whitepaper - team-monet/monet
at
9fa38c2d…— read only; FRESH manifests behind a committedpnpm-lock.yaml, so nothing was installed or run. The concept–observation store, the lexical stage/rule binding, the declare/ratify/resolve human loop, the circle scoping and the append-only event logs were read fromengine.ts,gates.ts,mcp-server.tsandresolution.tsagainst the Vitest suite; the "moments" and "corrections" claims were sized against the code - MemTensor/memmy-agent
at
65c1825d…— read only; FRESH manifests across the workspaces, so nothing was installed or run. TheMemory/package was confirmed as the authoritative local SQLite engine (distinct from the MemOS Python package and from the opt-in hosted OpenMem backend); the layered store, the evolution and negative-experience pipelines, the injected per-agent CLI skill and the unscoped main recall were read fromMemory/src/storage/,service/andcli/against the committed tests - GoogleCloudPlatform/generative-ai
(always-on-memory-agent) at
97597c46…— read only; a sample subdir (standalone originShubhamsaboo/always-on-memory-agent, MIT), build-time execution points and unpinned surfaces typical of a Python sample, so nothing was installed or run. The embedding-free SQLite store, the load-and-read query (read_all_memoriesatLIMIT 50, no search), the 30-minute consolidation daemon and the hard-delete correction were read fromagent.pyagainst the README - klairtech/one-agent-many-hats
at
a90396cf…— read only, at 36 commits over three days, under PolyForm Noncommercial 1.0.0; both manifests were inside the cooldown and the two declared dependencies are build-time, so nothing was installed or built. The five memory layers, the write-time lesson refusal, the canary slice and the feedback verdicts were read fromsrc/memory/againsttest/memory.test.ts; the committed working paper was read in its published form at sandeepkavety.com, because the PDF in the tree does not extract to legible text with the tools on this machine - bytechefhq/bytechef at
dc28f0b7…— read only; the knowledge base, the nine chat-memory components, the guardrail advisors and the tenant and environment contexts, not the workflow engine, the connector catalogue or the React client. A Gradle monolith needing Postgres, pgvector and a broker to test, so nothing was built or run and the Testcontainers suites were read rather than executed - codician-team/growmos
at
510deb2d…— read only, at 23 commits on a repository created the same day; three auto-run surfaces all invoking the project's own binary, one manifest changed that day and no lockfile, so nothing was installed and the twenty committed tests were read rather than run - kevin-hs-sohn/hipocampus
at
df88ca19…— read only; the screener reported zero auto-run surfaces becausehooks/hooks.jsonand.claude-plugin/are not on its fixed path list, so the three hooks it registers were found and read by hand. Nothing was installed or run, and the MemAware benchmark the README reports lives in a separate repository that was not read - KnowledgeXLab/MemHarness
at
31329e8e…— read only;agent_system/memory/and the Milvus store, not the vendoredverltrainer or the five environment packages. The stack needs conda, vLLM, flash-attn and a served embedding model, so nothing was installed and the published ALFWorld and WebShop figures were read rather than reproduced — no run artifacts are committed for them - scottrbk/forgetful at
35764a88…— read only; no auto-run surface, threeconftest.pycollection-time surfaces,pyproject.tomlanduv.lockinside the seven-day cooldown, three agent-instruction files read as data; nothing installed or run. - EMI-Group/genesis
at
1ab2e249…— read only; no auto-run surface, one build-time execution point in the Tauri crate, two Rust manifests inside the seven-day cooldown. The commit read on 2026-09-17 wasab8f6f6d, which the project's rebuilt merges left offmainthe same day; this pin is the commit onmaincarrying the identical root tree, so the reading and the pin describe the same bytes - krakozavr/MemContinuum
at
e21bfa06…— read only; one auto-run surface (fourteen hook scripts a plugin manifest can register), two dependency manifests inside the seven-day cooldown, nothing installed or run - l33tdawg/sage at
43dcd61e…— read only; two auto-run surfaces, five build-time execution points, five unpinned surfaces, six manifests inside the cooldown, nothing installed or run - plur-ai/plur at
e26901c1…— read only; three auto-run surfaces (two plugin manifests and a hooks directory), one build-time execution point, twelve unpinned surfaces, nothing installed or run - openzync/openzync-core
at
17cea04b…— read only; no auto-run surface, nine build-time execution points, two unpinned surfaces and two dependency files inside the seven-day cooldown; nothing installed, built or run - Sibyl-Labs/Sibyl-Memory
at
761bfc64…— read only; no auto-run surface, three build-time execution points, four manifests inside the seven-day cooldown, nothing installed or run - MaxMiksa/Auto-Company
at
e1dfce15…— read only; one auto-run surface (.claude/settings.json, which setsbypassPermissionsand allows Bash, Edit and Write), one build-time execution point, three unpinned dependency surfaces and one manifest inside the seven-day cooldown, so nothing was installed or run; still no licence file in the tree against an MIT badge in the README - redhat-et/ripwire
at
e54b688e…— read only; two auto-run surfaces and four unpinned dependency surfaces, none inside the seven-day cooldown.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run and no benchmark was reproduced. Apache-2.0 - swang1024/SAGE at
01466cd1…— read only, at the head ofmain; no auto-run surface, three build-time execution points, one unpinned requirements file, and apoetry.lockunchanged for 88 days so the tree is outside the seven-day cooldown. Nothing was installed and no suite was run; the published accuracy figures were recomputed offline from the committed per-question judge output rather than by re-running the benchmark - 0xranx/OpenContext at
0649e713…— read only, at the head ofmain; no auto-run surface, four build-time execution points, three unpinned manifests each with a lockfile beside it, three lockfiles between 222 and 253 days old, anAGENTS.mdaddressed to a reading agent read as data, and an inertscripts/pre-commitpayload read rather than run. Nothing was installed and no suite was run - bakka22/khabeer at
cd752621…— read only; no auto-run surface, three build-time execution paths all inside the bundled skill library (aconftest.py, asetup.pyand a LaTeXMakefile), the Termux half of the tree left unread, nothing built or installed - Nikeshchaudhary52494/memora
at
4c3d1aa9…— read only; no auto-run surface and no build-time execution path, four dependency manifests inside the seven-day cooldown and two unpinned surfaces; nothing installed or run, and the evaluation ranking was reproduced offline rather than by running the suite - Ste2027/ContextMeld at
77d0acbd…— read only; no auto-run surface, one build-time execution path insrc-tauri/build.rs, four manifests inside the seven-day cooldown and one unpinned surface; nothing installed, built or run - Tanglies/AgentOS
at
08a3af64…— read only, re-pinned 46 commits on; two editor-configuration findings in.vscode/, neither set to run on folder open, oneconftest.pythat executes at pytest collection, and three dependency surfaces changed the same day, all inside the seven-day cooldown. A.gitattributesnew since the previous pin was read before checkout — line-ending and binary markers, nofilter=. The folder was not opened in an editor and nothing was installed or run. - drephantom/memory-garden
at
d7fdb1c7…— read only; no auto-run surface, oneconftest.py, two manifests inside the seven-day cooldown and no unpinned surface; nothing installed or run - yestropcool/kept
at
8177f233…— read only; no auto-run surface and no build-time execution path, two manifests inside the seven-day cooldown and no unpinned surface; nothing built or run - causewayai/hivemind at
666bfa10…— read only; the previous pin was fetched from the archive fork after a history rewrite and the two trees compared; no auto-run surface, one build-time execution point (aMakefile), nothing inside the seven-day cooldown and no unpinned surface; nothing installed, built or run, and the embedding distances were computed by reimplementing the hash offline - stevefunng/Nuum at
51c9ec34…— read only; no auto-run or build-time surface, eight manifests and the pnpm lockfile inside the seven-day cooldown, floating ranges under one workspace lockfile,AGENTS.mdread as data; nothing built or run - 410979729/scope-recall-hermes
at
365e5784…— read only from a full clone; no auto-run surface, threeconftest.pyfiles that run at pytest collection,pyproject.tomlanduv.lockinside the seven-day cooldown, and anAGENTS.mdread as data; nothing installed, built or run - codecoradev/uteke
at
c0573a42…— read only; no auto-run surface and no build-time execution path, every manifest inside the cooldown only because the depth-1 clone dates each file to the pin, three unpinned surfaces in benchmark and docs tooling; nothing built or run, the LongMemEval headline recomputed from the committed raw output and the graph foreign-key failure reproduced against the DDL in Python's sqlite3 - zzjzzb/ai-memory
at
92082815…— read only; no auto-run surface, three build-time execution paths (twopreparescripts that run cargo at install, a napibuild.rs), five manifests inside the seven-day cooldown and no lockfile committed; nothing built or run, and the tokenizer and hash-embedding figures were computed by reimplementing them offline - Maple-Aikon/janus-graph
at
5a66516f…— read only; no auto-run surface, onetests/conftest.py,pyproject.tomlanduv.lockinside the seven-day cooldown and no unpinned surface; nothing built or run, and the graph schema, group-to-graph mapping and edge invalidation were read in graphiti-core at tagv0.29.3, the versionuv.lockpins - ramakay/claude-self-reflect
at
ca5655a8…— read only; three auto-run surfaces (a Claude Code plugin manifest whose postInstall installs hooks, a committed pre-commit hook, an empty MCP manifest), one build-time path (an npm postinstall that downloads a checksum-verified release binary and does not activate without an opt-in), eleven floating ranges in the docs-site manifest against a present lockfile, three lockfiles unchanged for 23 days; nothing installed, built or run, and the committed eval-kit artifacts were inspected rather than regenerated - deeplethe/utopia
at
e26d97aa…— read only; no auto-run surface and no build-time execution path, one floating version and seven manifests genuinely inside the cooldown on a full clone,web/package.jsonheld reproducible by its pnpm lockfile; nothing installed, built or run, and the linked BIRD Mini-Dev submission opened and read - activeloopai/hivemind
at
ce30de7c…— read only; one auto-run surface (a plugin marketplace manifest pointing at a pinned subdirectory of the same repository), two build-time execution paths (a postinstall running a tree-sitter native-build heal, a prepare running husky and the build), one unpinned manifest with 26 floating ranges against a present lockfile, none inside the cooldown from a full clone, a pre-commit payload not installed in a bare checkout; nothing installed, built or run - rush-db/rushdb at
67214ab6…— read only; one auto-run surface that turns out to hold no hooks, two build-timepreparescripts, six unpinned manifests with the root lockfile untouched for eleven days,CLAUDE.mdread as data; nothing installed, built or run, the conformance fixture's event id recomputed in Python from the committed JSON - Signet-AI/signetai at
11e4720c…— read only; one auto-run surface in a committed.githooks/that the rootpreparescript would activate, five build-time execution paths, 37 manifests inside the cooldown on a full clone, 31 unpinned surfaces in web, dashboard and template tooling,AGENTS.mdandCLAUDE.mdread as data; nothing installed, built or run, and the LongMemEval headline checked against the tree rather than recomputed, because no result artifact is committed - angelnicolasc/graymatter
at
d03c408e…— read only; three auto-run surfaces, all MCP manifests declaring the project's own server with no network fetch and no out-of-tree read, six dependency surfaces inside the cooldown and one unpinned manifest in the docs site; nothing built, installed or run, every benchmark figure read from a committed artifact or the test that pins it - BennettSchwartz/membrane
at
b3f1f091…— read only; screened twice at this pin, on 2026-09-12 and on a full clone on 2026-09-26: no auto-run surface, two build-time execution paths (the Makefile default target and a TypeScriptprepublishOnlychain), no dependency surface inside the seven-day cooldown on the full clone (the thirteen found on 2026-09-12 were depth-1 clone artifacts), nine unpinned surfaces across the SDKs, the harness and a scanning workspace; nothing installed, built or run, and the compounding decay trajectory recomputed from the committed constants in a scratch script - Lyellr88/marm-memory
at
f3d626cb…— read only; no auto-run surface, three build-time execution points (a pnpm-enforcingpreinstalland twoconftest.py), five unpinned dependency surfaces in the Python requirements and the console manifests, oneAGENTS.mdread as data, the console lockfile outside the cooldown at eight days; nothing installed, built or run, and the concept-graph predicate shadowing reproduced by re-implementing the trigger table and its matching loop in a scratch script - lobu-ai/lobu at
462df8b7…— read only; five auto-run surfaces read before anything else and all benign project-local guards, thirty-four manifests inside the cooldown and thirty-four unpinned surfaces, two build-time execution paths,AGENTS.mdandCLAUDE.mdtreated as data; nothing installed, built or run, one submodule left uninitialised, and the live table set recomputed from the 280 migrations in Python rather than read off the baseline dump - ChristopherKahler/base
at
566c7531…— read only; no auto-run surface, one build-time execution path (build.rs, which runsgit rev-parseto stamp the version), nothing inside the seven-day cooldown, two unpinned surfaces (a dashboard manifest above a present lockfile, and 29 unpinned Python requirements for the AST pass),Cargo.lockpresent; nothing installed, built or run, and the licence read as the Functional Source License 1.1 with an Apache-2.0 future licence rather than theNOASSERTIONthe API reports - dcostenco/prism-coder
at
5e509052…— read only; five auto-run surfaces read before anything else (a Claude Code plugin manifest, a.claude/settings.jsonhook pointing at a script absent from the tree, an empty.gitmodules, and MCP and Smithery manifests naming the published npm package), three build-time execution paths, four dependency surfaces inside the seven-day cooldown, 33 floating ranges above a present lockfile, one uninstalled git-hook payload,GEMINI.mdread as data; nothing installed, built or run - Facets-cloud/flow
at
99efdaef…— read only; no auto-run surface, one build-time execution path (theMakefiledefault target), nothing inside the seven-day cooldown (go.modandgo.sumlast changed 23 June 2026), no unpinned dependency surface, andAGENTS.mdread as data; nothing installed, built or run - mnemon-dev/mnemon
at
b0661c0b…— read only; no auto-run surface, one build-time execution path (theMakefiledefault target), five dependency surfaces inside the seven-day cooldown, one floating npm range above a present lockfile, andAGENTS.mdandCLAUDE.mdread as data; nothing installed, built or run, and one check made outside the checkout — the MAGMA abstract, against the README's citation of it - memoket/memoket-kite
at
8745feda…— read only; screened twice at this pin, on 2026-09-12 and on a full clone on 2026-09-26: no auto-run surface, one build-time execution path (tests/conftest.pyat collection), no dependency surface inside the cooldown and one unpinned manifest that declares no runtime dependencies at all; nothing installed, built or run, and two checks made against GitHub rather than the tree at each reading — the release listing, and a GET against the release-asset URL the reproduction downloader constructs - semantica-agi/semantica
at
de2e200e…— read only; no auto-run surface, fourconftest.pyfiles executing at pytest collection, three dependency surfaces changed the day of the pin and two unpinned surfaces (apyproject.tomlwith no lockfile, an Explorer manifest with forty floating ranges above a present lockfile); nothing installed, built or run, and the filtered-deletion behaviour reproduced by transcribing the predicate and its caller into a scratch script outside the tree - EverMind-AI/SkillCorpus
at
c82ca38d…— read only; no auto-run surface, one build-time execution path (aMakefilewhose default target was checked), sixteen dependency surfaces inside the seven-day cooldown because the pin is the day after the tree was last touched, and twelve unpinned surfaces across the requirements files and the plugin manifests; nothing installed, built or run, so no test in this repository was executed, and the published benchmark table was checked against the tree rather than recomputed because no result artifact is committed. Audited on 2026-09-20 at the same pin: two sentences said no feedback signal exists anywhere in the tree, and the consumer plugin emits one for its host — what is absent is anything that persists it. - neo4j-labs/create-context-graph
at
707b168d…— read only, and audited on 2026-09-26 at the same pin, the head ofmain; no auto-run surface, two build-time execution paths (aMakefileand aconftest.pyat collection), one unpinned manifest in the docs site with a lockfile beside it and both lockfiles outside the cooldown,CLAUDE.mdread as data; the dependency neo4j-labs/agent-memory read at itspython-v0.5.0tag,8bd50eff…, for whatadd_entitywrites; nothing installed, built or run, the entity-type distribution and the tool-body domain check recomputed from the committed domain YAMLs in Python - halofyai/halofy at
3763e64f…— read only; no auto-running configuration, no build-time execution path, no manifests inside the cooldown, two unpinned surfaces andAGENTS.mdtreated as data; nothing installed or run, and the test counts taken from the files rather than a run - OriginTrail/dkg at
d499fb2d…— read only; two auto-running editor surfaces (.cursor/mcp.jsonand Cursor rules) read as data, two build-time execution points, no manifests inside the cooldown and 58 unpinned surfaces; nothing installed, built or run, and the chain, economics and synchronization packages outside the reading - bojieli/ai-agent-book
at
cf7f7a8e…— read only and scoped to the Chapter 3 user-memory projects; 27 build-time execution points, 98 unpinned surfaces and two manifests inside the cooldown across the repository; nothing installed or run, and every result read from committed evidence files - modusensus/dsh-mneme
at
5bd2dab7…— read only; one build-time execution point, one unpinned surface and three manifests inside the cooldown; nothing installed or run - remete618/widemem-ai
at
fdf736fc…— read only; one build-time execution point and one unpinned manifest; nothing installed or run; the LoCoMo figure taken from the README since its result files are not committed, and no committed runner scores the adversarial category - LamantinAI/kaeru
at
566b6c6e…— read only; one auto-run surface (an uninitialised benchmarks submodule), three manifests inside the cooldown, one unpinned surface,AGENTS.mdandCLAUDE.mdtreated as data; nothing installed, built or run - AgentToolkit/altk-evolve
at
b81d64ee…— read only; one auto-run surface (a Claude Code marketplace definition), three build-time execution points, two unpinned surfaces and two manifests inside the cooldown,AGENTS.mdtreated as data; nothing installed or run, and the AppWorld figures taken from the results page of the project - benclawbot/open-brain
at
02a7e65a…— MIT declared inpyproject.tomland the README, no licence file; read only; one build-time execution point, two unpinned surfaces, no manifests inside the cooldown,AGENTS.mdtreated as data; nothing installed or run - lna-lab/distill-kura
at
33aec61d…— read only; one unpinned surface and AGENTS.md read as data; nothing installed or run, and the retention score taken from the README since no result files are committed - Abhigyan-Shekhar/Waggle-mcp
at
4d49f2f6…— read only; three MCP manifests that auto-start, one test collection hook and five unpinned surfaces; nothing installed or run - sanonone/kektordb
at
addc5f0c…— read only; three build-time execution points, one unpinned surface, and no dependency file inside the cooldown on a full clone; nothing installed or run - sdsrss/claude-mem-lite
at
0e31b3db…— read only; five plugin, hook and MCP manifests that auto-run, two dependency files inside the cooldown; nothing installed or run, and the LongMemEval figures taken from the README since their result files are not committed - Fmarzochi/EGC at
f24f53c2…— read only; seven auto-run surfaces, three build-time execution points and sixteen dependency files inside the cooldown; nothing installed or run - riponcm/projectmem at
e8d73137…— read only; one test collection hook, one unpinned surface and one dependency file inside the cooldown; nothing installed or run - diqierjia/StrataGate-AgentMemory
at
f79e986a…— read only; four package lifecycle scripts, four unpinned surfaces and five dependency files inside the cooldown; nothing installed or run - ipiton/agent-memory-mcp
at
ceef5851…— read only; one MCP server manifest and a Makefile, nothing unpinned or inside the cooldown; nothing installed or run - cyberlife-coder/VelesDB
at
614722aa…— read only and scoped to thevelesdb-memorycrate; three auto-run surfaces, eight build-time execution points, seventeen unpinned surfaces and fifty dependency files inside the cooldown; nothing installed or run - omdsh-dev/dsh-mnemon
at
432d69c2…— read only; one build-time execution point, eighteen unpinned surfaces and twenty dependency files inside the cooldown; nothing installed or run - yantrikos/yantrikdb-hermes-plugin
at
c301188e…— read only; two test collection hooks, one unpinned surface and one dependency file inside the cooldown; nothing installed or run - inite-ai/inite-brain-service
at
e57752a0…— read only, from a shallow clone; two auto-run surfaces (a Claude Code plugin manifest and an MCP server manifest declaring a start command), three build-time execution points, five unpinned surfaces and seven dependency files inside the seven-day cooldown across fifteen scanned files, plusAGENTS.mdread as data; nothing was installed and nothing was run - hjqcan/GoodMemory
at
416c15b4…— read only, from a shallow clone; one auto-run surface (an MCP server manifest declaring a start command), one build-time execution point, eleven unpinned surfaces and seventeen dependency files inside the seven-day cooldown across thirty-six scanned files, plusAGENTS.mdandCLAUDE.mdread as data; nothing was installed and nothing was run - AVIDS2/memorix at
f7ed6218…— read only, from a shallow clone; three auto-run surfaces (.gitmodules, an.opencode/directory and an MCP server manifest declaring a start command), five build-time execution points, three unpinned surfaces and four dependency files inside the seven-day cooldown across thirty-five scanned files, plusCLAUDE.mdandGEMINI.mdread as data; nothing was installed and nothing was run - markhuangai/dense-mem
at
939c86b2…— read only, from a shallow clone; one auto-run surface (a.githooks/directory), no build-time execution points, two unpinned surfaces and ten dependency files inside the seven-day cooldown across sixteen scanned files, plusAGENTS.mdread as data; nothing was installed and nothing was run - BYK/loreai at
620b8248…— read only, from a shallow clone; no auto-run surfaces, two build-time execution points, seven unpinned surfaces and ten dependency files inside the seven-day cooldown across twenty scanned files, plusAGENTS.mdread as data; nothing was installed and nothing was run - itsXactlY/mazemaker at
25b40641…— read only, from a shallow clone; no auto-run surfaces, no build-time execution points, one unpinned surface and one dependency file inside the seven-day cooldown across two scanned files; nothing was installed, built or run - memtomem/memtomem
at
95baf628…— read only, from a shallow clone; one auto-run surface (a.claude-plugin/directory), two build-time execution points, two unpinned surfaces and seven dependency files inside the seven-day cooldown across seventeen scanned files, plusCLAUDE.mdread as data; nothing was installed and nothing was run - ScriptedAlchemy/tracedecay
at
9e2f7bed…— read only, from a shallow clone and scoped to the memory subsystem; three auto-run surfaces (a.githooks/directory, a.gitmodulesand an MCP server manifest), nine build-time execution points, three unpinned surfaces and forty-nine dependency files inside the seven-day cooldown across sixty-eight scanned files, plusAGENTS.mdandCLAUDE.mdread as data; thecodegraphsubmodule was not fetched, and nothing was installed, built or run - RamaAditya49/titen at
a68ce063…— read only, from a shallow clone; two auto-run surfaces (a.claude-plugin/directory and an MCP server manifest), no build-time execution points, two unpinned surfaces and no dependency files inside the seven-day cooldown across thirteen scanned files, plusAGENTS.mdandCLAUDE.mdread as data; nothing was installed and nothing was run - jeffdafoe/llm-memory-api
at
63084315…— read only, from a shallow clone; no auto-run surfaces, no build-time execution points, one unpinned surface and three dependency files inside the seven-day cooldown across six scanned files, plusCLAUDE.mdread as data; nothing was installed and nothing was run - latebit-io/demarkus at
dd22c38a…— read only, from a shallow clone; one auto-run surface (a.claude-plugin/directory), one build-time execution point, four unpinned surfaces and sixteen dependency files inside the seven-day cooldown across twenty-three scanned files, plusCLAUDE.mdread as data; nothing was installed and nothing was run - JinyangWang27/people-context
at
f2bfd5ca…— read only, from a shallow clone; three auto-run surfaces (a.claude-plugin/directory, an.mcp.jsonand an MCP server manifest), two build-time execution points, two unpinned surfaces and nine dependency files inside the seven-day cooldown across twenty scanned files, plusAGENTS.mdread as data; nothing was installed and nothing was run - putervision/state-memory-mcp
at
5af4bc3d…— read only, from a shallow clone; four auto-run surfaces (a Cursor MCP config, a Cursor rules directory, a Copilot instructions file and an MCP server manifest), one build-time execution point, one unpinned surface and two dependency files inside the seven-day cooldown across eight scanned files, plusCLAUDE.mdread as data; nothing was installed and nothing was run - code-ministry-ltd/the-librarian
at
c644d25b…— read only, from a shallow clone; one auto-run surface, seven build-time execution points, twelve unpinned surfaces and twelve dependency files inside the seven-day cooldown across twenty-nine scanned files, plus the agent-instruction files read as data; nothing was installed and nothing was run - dnotitia/akb at
f3aba459…— read only, from a shallow clone; three auto-run surfaces, five build-time execution points, three unpinned surfaces and ten dependency files inside the seven-day cooldown across twenty-five scanned files, plus the agent-instruction files read as data; nothing was installed and nothing was run - gluonfield/jaz at
a99018ab…— read only, from a shallow clone, with thejazmemengine read at4d801b95…, the exact commit itsgo.modpins; eight files scanned, no auto-run surfaces, one build-time execution point, one unpinned surface and four dependency files inside the seven-day cooldown; nothing was installed, built or run - openairymax/agentrt at
2682bfc6…— read only. The seven runtime directories are submodules with relative URLs, so a shallow clone of the superproject leaves them empty;daemonswas fetched by full sha and read atdb4962ad…andheapstoreatd3130dde…, the exact pins the superproject records;openairymax/atomsreturned 404 on GitHub and atomgit.com returned 403 to a non-browser fetch. Nothing was installed, built or run - hhyqhh/inno-agent
at
4fe5cc9f…— read only, from a shallow clone; ten files scanned, no auto-run surfaces, five dependency files inside the seven-day cooldown, six unpinned surfaces including twopackage.jsonfiles with no lockfile beside them and anxlsxdependency from a vendored tarball, and theCLAUDE.mdread as data. Nothing was installed, built or run - rlaope/oh-my-hermes at
4129002f…— read only, from a shallow clone; nine files scanned, one auto-run surface, three build-time execution points, one unpinned surface, one dependency file inside the seven-day cooldown, and theCLAUDE.mdandAGENTS.mdread as data. Nothing was installed, built or run - Bitterbot-AI/bitterbot-desktop
at
cf9332b1…— read only, from a shallow clone; a dependency surface had changed inside the seven-day cooldown. Nothing was installed, built or run - yantrikos/yantrikdb at
49c7aac1…— read only, from a shallow clone; the engine repository in its own right, having previously been read only as a pinned dependency of yantrikdb-server at tagv0.22.0. A dependency surface had changed inside the seven-day cooldown. Nothing was installed, built or run - NodeDB-Lab/nodedb
at
124cc53a…— read only, from a shallow clone; a dependency surface had changed inside the seven-day cooldown. Nothing was installed, built or run - offendingcommit/openconcho
at
b5e25646…— read only, from a shallow clone; seventeen files scanned, one auto-run surface, three build-time execution points, three unpinned surfaces, nothing inside the dependency cooldown, and theCLAUDE.mdandAGENTS.mdread as data. Nothing was installed, built or run - sageox/ox at
02f4f406…— read only, from a shallow clone; twenty files scanned, three auto-run surfaces, one build-time execution point, one unpinned surface, five dependency files inside the seven-day cooldown, and theCLAUDE.mdandAGENTS.mdread as data. Nothing was installed, built or run - maximem-ai/maximem_synap_sdk
at
e0402c9c…— read only, from a shallow clone; the repository states it is generated and synced out of a private monorepo, so the service behind these clients was not inspectable. Eighty-seven files scanned, no auto-run surfaces, twenty-two build-time execution points, thirty-one unpinned surfaces and thirty-six dependency files inside the seven-day cooldown. Nothing was installed, built or run - saxenauts/syke at
62c1c9cf…— read only, from a shallow clone; six files scanned, no auto-run surfaces, three build-time execution points, no unpinned surfaces and nothing inside the dependency cooldown. Nothing was installed, built or run - Ariestar/sivtr at
a26dc8a3…— read only, from a shallow clone; thirteen files scanned, no auto-run surfaces, one build-time execution point, two unpinned surfaces, seven dependency files inside the seven-day cooldown, and theCLAUDE.mdandAGENTS.mdread as data. Nothing was installed, built or run - UnknownAlienHuman/eliot-memory-os
at
3590b344…— read only, from a shallow clone; 195 files scanned, no auto-run surfaces, three build-time execution points, no unpinned surfaces, and 187 dependency files inside the seven-day cooldown. The repository's documentation protocol andAGENTS.md, both addressed to reading agents, were read as data and not followed. Nothing was installed, built or run - dfrostar/neuralmind at
38c74096…— read only, from a shallow clone; open-core, MIT exceptneuralmind/tier2/, which is source-available under a Commercial Modules License and was read as source. Fifteen files scanned, no auto-run surfaces, one build-time execution point, three unpinned surfaces, eight dependency files inside the seven-day cooldown, and theCLAUDE.mdread as data. Nothing was installed, built or run - DanceNitra/inspeximus
at
d9efe84a…— read only, from a shallow clone; eighteen files scanned, five auto-run surfaces, one build-time execution point, five unpinned surfaces and six dependency files inside the seven-day cooldown. The README's comparative figures against other systems are the project's own measurements and were not reproduced. Nothing was installed, built or run - prjct-app/pi-memory at
0f09c6b4…— read only, from a shallow clone; three files scanned, no auto-run surfaces, no build-time execution points, one unpinned surface and two dependency files inside the seven-day cooldown. Nothing was installed, built or run - acoz-labs/mandalore at
33329382…— read only, from a shallow clone; the project describes itself as the memory-only successor toacoz-labs/my-friday, which is not in this atlas. Six files scanned, no auto-run surfaces, no build-time execution points, no unpinned surfaces and three dependency files inside the seven-day cooldown. Nothing was installed, built or run - kannaka-labs/kannaka-memory
at
2b35b46d…— read only, from a shallow clone. Licensed under the bespoke SPACE CHILD LICENSE v1.0, whose field-of-use restrictions make it not an open-source licence under the OSI definition. Six files scanned, one auto-run surface, two build-time execution points, no unpinned surfaces and three dependency files inside the seven-day cooldown. Nothing was installed, built or run - repairman29/chump
at
631fcaa7…— read only, from a shallow clone. Thirty-nine of the eighty-three documents underdocs/eval/are stubs recording that the content moved to a private repository; the figures cited come from the write-ups that remain public. Eighty-eight files scanned, three auto-run surfaces, two build-time execution points, six unpinned surfaces and sixty-nine dependency files inside the seven-day cooldown, withCLAUDE.mdandAGENTS.mdread as data. Nothing was installed, built or run - MarcelRoozekrans/LongtermMemory-MCP
at
5955730d…— read only, from a shallow clone; eight files scanned, three auto-run surfaces, one build-time execution point, one unpinned surface and two dependency files inside the seven-day cooldown. Nothing was installed, built or run - OWASP/www-project-agent-memory-guard
at
a1f60687…— read only, from a shallow clone; a defensive middleware rather than a memory store, recorded for its threat taxonomy. Twelve files scanned, one auto-run surface, no build-time execution points, five unpinned surfaces and six dependency files inside the seven-day cooldown. Nothing was installed, built or run - Cipher208/a-memory at
32edbb91…— read only, from a shallow clone; eight files scanned, two auto-run surfaces, one build-time execution point, no unpinned surfaces and two dependency files inside the seven-day cooldown. Nothing was installed, built or run - phanijapps/memex
at
80411705…— read only, from a shallow clone; seven files scanned, no auto-run surfaces, one build-time execution point, no unpinned surfaces and three dependency files inside the seven-day cooldown. Nothing was installed, built or run - yachen4ever/yacmemo at
4a12be94…— read only, from a shallow clone; re-screened at this pin: no auto-run surfaces, two build-time execution points, two unpinned surfaces and six files inside the seven-day cooldown. Nothing was installed, built or run - ali-ulu/levh at
9bdcb25f…— read only, from a shallow clone; six files scanned, no auto-run surfaces, one build-time execution point, two unpinned surfaces and three dependency files inside the seven-day cooldown. Nothing was installed, built or run - ldclabs/anda-db at
e2a2c051…— read only, from a shallow clone; twenty-nine files scanned, no auto-run surfaces, three build-time execution points, three unpinned surfaces and twenty-two dependency files inside the seven-day cooldown. Nothing was installed, built or run - matrixarkai/TemporalStore
at
5eb2c914…— read only, from a shallow clone; thirteen files scanned, two auto-run surfaces, two build-time execution points, no unpinned surfaces and seven dependency files inside the seven-day cooldown. Nothing was installed, built or run, and no benchmark was executed - MatthewSherlin/mushroomdb
at
4896a895…— read only, from a shallow clone; thirty-four files scanned, two auto-run surfaces, two build-time execution points, four unpinned surfaces and twenty-four dependency files inside the seven-day cooldown. Nothing was installed, built or run - tpsdev-ai/flair at
6fadb74f…— read only, from a shallow clone; thirty-five files scanned, no auto-run surfaces, twelve build-time execution points, five unpinned surfaces and sixteen dependency files inside the seven-day cooldown. Nothing was installed, built or run - theurian/theurian
at
6c64a6ba…— read only, from a shallow clone; fourteen files scanned, no auto-run surfaces, seven build-time execution points, one unpinned surface and three dependency files inside the seven-day cooldown. Nothing was installed, built or run - yantrikos/yantrik-os
at
ec2e424f…— read only, from a shallow clone; seventy-two files scanned, no auto-run surfaces, twenty build-time execution points, no unpinned surfaces and fifty-one dependency files inside the seven-day cooldown. Nothing was installed, built or run - qilunuojiang9-hue/Huiran-cerebro
at
2f48deb2…— read only, from a full clone; two files scanned, no auto-run surfaces, no build-time execution points, one unpinned surface and nothing inside the seven-day cooldown. Nothing was installed, built or run - DevEstacion/light-mem
at
6c96cb65…— read only, from a shallow clone; eleven files scanned, three auto-run surfaces, one build-time execution point, two unpinned surfaces and three dependency files inside the seven-day cooldown. Nothing was installed, built or run - MegaWiz-Dev-Team/Bifrost
at
936957b3…— read only, from a shallow clone; seven files scanned, no auto-run surfaces, no build-time execution points, one unpinned surface and five dependency files inside the seven-day cooldown. Nothing was installed, built or run - takecchi/mnemora
at
509f4e73…— read only, from a shallow clone; nineteen files scanned, no auto-run surfaces, no build-time execution points, three unpinned surfaces and nine dependency files inside the seven-day cooldown. Nothing was installed, built or run - genomewalker/chitta-field
at
c5e0ff0e…— read only, from a shallow clone; two files scanned, no auto-run surfaces, one build-time execution point, no unpinned surfaces and one dependency file inside the seven-day cooldown. Nothing was installed, built or run - danielmarbach/mnemonic
at
5fc9a5f5…— read only, from a shallow clone; nine files scanned, three auto-run surfaces, one build-time execution point, one unpinned surface and two dependency files inside the seven-day cooldown. Nothing was installed, built or run - Who-Visions/NouGenShards
at
73078c05…— read only, from a shallow clone; twenty-two files scanned, two auto-run surfaces, two build-time execution points, four unpinned surfaces and nine dependency files inside the seven-day cooldown. Nothing was installed, built or run - fagemx/edda at
ce8b98e0…— read only, from a shallow clone; forty-three files scanned, no auto-run surfaces, two build-time execution points, two unpinned surfaces and thirty-two dependency files inside the seven-day cooldown. Nothing was installed, built or run - asuramaya/osiris
at
561d5697…— read only, from a shallow clone; eleven files scanned, three auto-run surfaces, one build-time execution point, no unpinned surfaces and three dependency files inside the seven-day cooldown. Nothing was installed, built or run - Deathburgerz013/HOLO-Invariant
at
2d36396a…— read only, from a shallow clone; four files scanned, no auto-run surfaces, no build-time execution points, one unpinned surface and one dependency file inside the seven-day cooldown. Nothing was installed, built or run, and no benchmark was executed - kunickiaj/codemem
at
6391c66b…— read only, from a shallow clone; thirty-three files scanned, two auto-run surfaces, one build-time execution point, eight unpinned surfaces and fourteen dependency files inside the seven-day cooldown. Nothing was installed, built or run - TianpeiLuke/Tessellum
at
6e167169…— read only, from a shallow clone; four files scanned, no auto-run surfaces, no build-time execution points, one unpinned surface and two dependency files inside the seven-day cooldown. Nothing was installed, built or run - The-Geek-Freaks/NEOTH
at
6a375573…— read only, from a shallow clone; thirty-four files scanned, no auto-run surfaces, two build-time execution points, no unpinned surfaces and twenty-eight dependency files inside the seven-day cooldown. Nothing was installed, built or run - TRUE-BLUE-INDUSTRIES/hungry-hippa
at
3cddd2ad…— read only, from a shallow clone; two files scanned, no auto-run surfaces, no build-time execution points, one unpinned surface and one dependency file inside the seven-day cooldown. Nothing was installed, built or run - adea-ai/cortana at
9609d2ab…— read only, from a shallow clone; eighteen files scanned, one auto-run surface, one build-time execution point, three unpinned surfaces and ten dependency files inside the seven-day cooldown. Nothing was installed, built or run - cdeust/Cortex at
d02917d4…— read only, from a shallow clone; twenty-five files scanned, four auto-run surfaces, four build-time execution points, no unpinned surfaces and four dependency files inside the seven-day cooldown. Nothing was installed, built or run - TAIPANBOX/engram
at
240a4d9d…— read only; three files scanned, no auto-run surfaces, no build-time execution points, one unpinned dependency surface and one dependency file inside the seven-day cooldown. Nothing was installed, built or run.CLAUDE.mdis addressed to a reading agent and was recorded as data. Apache-2.0 - claudin-io/claudinio-brain
at
6b6e5741…— read only; nine files scanned, three auto-run surfaces (a Claude Code plugin manifest and two hook directories registering SessionStart, Stop and UserPromptSubmit), no build-time execution points, one unpinned dependency surface and none inside the seven-day cooldown, withCargo.lockpresent and unchanged for fourteen days. Nothing was installed, built or run. MIT - GiulioDER/RE-call
at
1157360f…— read only; fifteen files scanned, three auto-run surfaces, three build-time execution points (recall/setup.py, which executes at install time,tests/conftest.py, which runs on pytest collection, and theMakefiledefault target), one unpinned dependency surface and three dependency files inside the seven-day cooldown, withuv.lockpresent. Ahooks/pre-commitpayload sits in the tree uninstalled and inert.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run, and no PostgreSQL was started, so every claim in the report is read from source. Apache-2.0 - okf-memory/okf-agent-memory
at
2649a282…— read only; eight files scanned, two auto-run surfaces, two build-time execution points, no unpinned surfaces and one dependency file inside the seven-day cooldown.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run. MIT - lets-order-some-fries/loreweave
at
8fe4c5a2…— read only; four files scanned, one auto-run surface, one build-time execution point, one unpinned dependency surface and two dependency files inside the seven-day cooldown, withpackage-lock.jsonpresent. Nothing was installed, built or run. MIT - suanlab/temvera at
75243a3d…— read only; four files scanned, no auto-run surfaces, no build-time execution points, one unpinned dependency surface and one dependency file inside the seven-day cooldown.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run, and none of the paper's verification scripts were executed. Apache-2.0 - bnomei/mindreader
at
d7d1bb39…— read only; six files scanned, one auto-run surface, no build-time execution points, no unpinned surfaces and three dependency files inside the seven-day cooldown, withCargo.lockpresent.AGENTS.mdis addressed to a reading agent and was recorded as data. Nothing was installed, built or run and no Neo4j server was started. MIT - aureliocpr-ctrl/verimem
at
068baf45…— read only; five auto-run surfaces, two build-time execution points, two unpinned dependency surfaces and two dependency files inside the seven-day cooldown.CLAUDE.mdis addressed to a reading agent and was recorded as data. Nothing was installed, built or run, no judge model was fetched, and the benchmark figures in the report are the project's own measurements rather than reproductions. Dual-licensed AGPL-3.0 with a paid commercial option, and the licensing file carries no rider restricting analysis - thedatasense/anatid at
aa7edcdf…— read only; no auto-run surfaces, two build-time execution points, two unpinned dependency surfaces and two dependency files inside the seven-day cooldown. Nothing was installed, built or run and no DuckDB file was opened. MIT - memhtml/memhtml at
a219190e…— read only; no auto-run surfaces, no build-time execution points, one unpinned dependency surface and eighteen dependency files inside the seven-day cooldown, withpnpm-lock.yamlpresent.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run, no integration installer was executed and no AWS credential was present. Apache-2.0 - Bitwarelabscom/bwmem
at
1d0acee2…— read only; no auto-run surfaces, one build-time execution point, one unpinned dependency surface and two dependency files inside the seven-day cooldown, withpackage-lock.jsonpresent. Nothing was installed, built or run, and no PostgreSQL, Redis or Neo4j was started. AGPL-3.0 - ali-ulu/huqan at
844be596…— read only; no auto-run surfaces, one build-time execution point, one unpinned dependency surface and six dependency files inside the seven-day cooldown.AGENTS.mdis addressed to a reading agent and was recorded as data. Nothing was installed, built or run and the quickstart was not executed. AGPL-3.0 - yifanfeng97/ontomem at
154bf488…— read only; four files scanned, no auto-run surfaces, one build-time execution point, no unpinned surfaces and nothing inside the seven-day cooldown, withuv.lockpresent. Nothing was installed, built or run and no embedding model was loaded. Apache-2.0 - yantrikos/yantrik-mind
at
97935b1e…— read only; twenty-seven files scanned, no auto-run surfaces, two build-time execution points, no unpinned dependency surfaces and nothing inside the seven-day cooldown, withCargo.locktracked. Reviewed without a licence file. The belief engine it delegates to is a published crate and was not cloned for this reading. Nothing was installed, built or run - mnesio/mnesio at
5831aa0e…— read only; one auto-run surface, three build-time execution points, three unpinned dependency surfaces and twenty-five dependency files inside the seven-day cooldown. Nothing was installed, built or run; the install script was read but not executed and no benchmark was reproduced. Apache-2.0 - richard-wollyce/ulpia
at
1842f3c9…— read only; four auto-run surfaces, no build-time execution points, two unpinned dependency surfaces and twelve dependency files inside the seven-day cooldown.CLAUDE.mdis addressed to a reading agent and was recorded as data. Nothing was installed, built or run and no benchmark was reproduced. Apache-2.0 - jkubo/gaius at
b720bdb6…— read only; four auto-run surfaces, one build-time execution point, no unpinned dependency surfaces and two dependency files inside the seven-day cooldown. Nothing was installed, built or run and no session transcript was extracted. Apache-2.0 - taeyun16/aidememo
at
58b803cc…— read only; two auto-run surfaces, five build-time execution points, five unpinned dependency surfaces and twenty-seven dependency files inside the seven-day cooldown, withCargo.lockpresent.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run and no benchmark was reproduced. MIT OR Apache-2.0 - balaianu/CogZ at
6d664c86…— read only; three files scanned, no auto-run surface, no build-time execution point and no unpinned dependency surface, with two dependency files inside the seven-day cooldown andCargo.lockpresent.AGENTS.mdis addressed to a reading agent and was recorded as data. Nothing was installed, built or run. MIT - asanabrial/leteo
at
f49917e4…— read only; two auto-run surfaces, no build-time execution point and no unpinned dependency surface, with seven dependency files inside the seven-day cooldown andCargo.lockpresent.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run and no benchmark was reproduced. MIT - wuisabel-gif/MemWhale
at
a124b102…— read only; no auto-run surface, one build-time execution point and one unpinned dependency surface, with one dependency file inside the seven-day cooldown and bothpackage-lock.jsonandCargo.lockpresent.AGENTS.mdis addressed to a reading agent and was recorded as data. Nothing was installed, built or run and no benchmark was reproduced. MIT - Rememora/rememora
at
58ac331e…— read only, from a full clone so dependency ages are the project's own; one auto-run surface, one build-time execution point, two unpinned dependency surfaces and two dependency files inside the seven-day cooldown, withapp/src-tauri/Cargo.lockunchanged for 143 days.AGENTS.mdandCLAUDE.mdare addressed to a reading agent and were recorded as data. Nothing was installed, built or run and no benchmark was reproduced. MIT - MachineWisdomAI/fava-trails
at
10f689f7…— read only; one auto-run surface in the editor configuration, one build-time execution path in a pytest conftest, two manifests inside the seven-day cooldown, andAGENTS.mdandCLAUDE.mdtreated as data. Nothing was installed, built or run — no uv, no pytest, and no Jujutsu repository created. Apache-2.0 - FreePeak/LeanKG at
fabca1fe…— read only; one auto-run surface, two build-time execution paths, one unpinned surface, two manifests inside the seven-day cooldown, andAGENTS.md,CLAUDE.mdandGEMINI.mdtreated as data. Nothing was installed, built or run — no go build, no make, no npm. Apache-2.0 - CodeSoul-co/Hypha
at
ac77fa9b…— read only; no auto-run surface, one build-time execution path, sixteen workspace manifests carrying floating version ranges, nothing inside the seven-day cooldown. Nothing was installed, built or run — no npm, no vitest, no jest. Apache-2.0 - 23blocks-OS/ai-maestro
at
e68294a4…— read only; two auto-run surfaces both verified benign (an uninitialised plugins submodule, and ahooks/directory holding React hooks rather than git hooks), one manifest inside the seven-day cooldown, one build-time execution path, two floating dependency surfaces. Nothing was installed, built or run — no npm, no vitest, no database opened. MIT - contextstream/mcp-server
at
cdf0b386…— read only; one auto-run surface (server.json, an MCP manifest declaring a start command), two build-time execution paths (a cargobuild.rsand an npmprepublishOnly), and ten dependency manifests changed inside the seven-day cooldown,Cargo.lockamong them. Nothing was installed, built or run — no cargo, no npm, no binary downloaded, and the install script in the README was read as text. MIT - shuruheel/mnestic
at
352bf205…— read only; one auto-run surface, six build-time execution paths (cargo build scripts and node-pre-gyp), five unpinned dependency surfaces including four Python integration packages with no lockfile beside theirpyproject.toml, and three lockfiles unchanged for eight days so nothing inside the cooldown. Nothing was installed, built or run — no cargo, no npm, no pip, no database opened. MPL-2.0 - topoteretes/cognee-rs
at
2fa09d18…— read only; no auto-run surface, five build-time execution paths including two pytestconftest.pycollection hooks and an npmpostinstall, four unpinned dependency surfaces, and 47 files changed inside the seven-day cooldown. Nothing was installed, built or run — no cargo, no npm, no pip, no server started. MIT OR Apache-2.0 - assafkip/kipi-system
at
fb098216…— read only; four auto-run surfaces (a Claude Code plugin marketplace manifest,.mcp.jsondeclaring three npx-launched servers,.claude/settings.jsonwith five hook families, and committed git hooks), four pytestconftest.pycollection hooks, and two dependency files changed inside the seven-day cooldown. All four auto-run surfaces were read as data and none executed;AGENTS.mdandCLAUDE.mdwere read as data rather than as instructions. Nothing was installed, built or run. MIT - beevibe-ai/beevibe at
81530cca…— read only; one auto-run surface, no build-time execution path, seven package manifests declaring floating ranges with no lockfile beside them, and a rootpnpm-lock.yamlunchanged for 37 days. Nothing was installed, built or run — no pnpm, no vitest, no database started, and the committed compose files were read as text. Apache-2.0 - dat999zx/knowl at
9065ed1f…— read only; three auto-run surfaces, one build-time execution path, 32 floating dependency ranges behind a committed lockfile, four files changed inside the seven-day cooldown, andCLAUDE.mdread as data. Nothing was installed, built or run — no npm, no vitest, no benchmark executed; the committed result files were read as data. Apache-2.0 - LucieEveille/kiwi-mem
at
b01a0c50…— read only; no auto-run surface, no build-time execution path, one unpinned dependency surface, one file inside the seven-day cooldown, andAGENTS.mdandCLAUDE.mdread as data rather than as instructions. Nothing was installed, built or run — no pip, no Docker, no database started. AGPL-3.0 - Beever-AI/beever-atlas
at
7d791af2…— read only; two auto-run surfaces (.mcp.jsonand aserver.jsonMCP manifest), three build-time execution paths including aMakefiledefault target and two pytestconftest.pycollection hooks, two unpinned dependency surfaces, and three lockfiles unchanged for 77 days. Nothing was installed, built or run — no uv, no pytest, no Docker, no store started. Apache-2.0 - major7apps/pensyve at
9ec26ade…— read only; three auto-run surfaces (a Claude Code plugin marketplace manifest, aserver.jsonMCP manifest and asmithery.yamlpackaging manifest) and four dependency manifests changed inside the seven-day cooldown includingCargo.lock. Nothing was installed, built or run — no cargo, no uv, no Postgres started, and the live-database suite was read rather than executed. Apache-2.0 - kkollsga/kglite at
68bc723a…— read only; every dependency manifest in the workspace,Cargo.lockincluded, changed on the day of the reading, so the whole surface is inside the seven-day cooldown. Nothing was installed, built or run — no cargo, no pip, no server started. MIT - Meridiona/meridian at
a1004682…— read only; two auto-run surfaces (a.claude/settings.jsoncarrying session hooks and four committed git hooks) and three build-time execution paths including two cargo build scripts and an npmprepublishOnly. Both auto-run surfaces were read as data and neither executed; nothing was installed, built or run, and no capture was started. MIT - MihaiBuilds/memory-vault
at
84987337…— read only; one auto-run surface (aserver.jsonMCP manifest), one build-time execution path (a pytestconftest.pycollection hook), and three dependency manifests changed inside the seven-day cooldown. Nothing was installed, built or run — no pip, no Docker, no Postgres started, and the committed pentest script was read rather than executed. MIT - ardiannurcahya/open-graph-memory
at
cf7b0d23…— read only; every dependency manifest in the tree changed on the day of the reading, so the whole surface is inside the seven-day cooldown. Nothing was installed, built or run — no uv, no npm, no Docker, and the runtime gates were read rather than executed. MIT - huggingface/funes
at
942caf87…— read only; no auto-run surface, one build-time execution path (a cargo build script), three dependency manifests changed on the day of the reading, andAGENTS.mdread as data. Nothing was installed, built or run — no cargo, no npm, no TruffleHog, no index built. Apache-2.0 - sliamh11/Deus at
2f24c38a…— read only; two auto-run surfaces (a.claude/settings.jsonwith five hook families and four committed hook scripts) and several build-time execution paths including an npmpreparethat runs husky and a migration script and three pytestconftest.pycollection hooks. Every auto-run surface was read as data and none executed; nothing was installed, built or run. MIT - open-webui/open-webui
at
0a7c1583…— read only, from a full clone so dependency ages are the project's own; no auto-run surface, two build-time execution paths and two unpinned dependency surfaces, nothing inside the seven-day cooldown. Nothing was installed, built or run — no npm, no pip, no Docker, no vector store started, and no embedding call made. Read as a memory system rather than as a chat front-end: the judgement coversmodels/memories.py,routers/memories.pyandutils/memory.py, and the 662 Svelte files around them were not inspected. Open WebUI License, a BSD-3 variant whose added condition governs branding in deployments above fifty users - eleboucher/memini
at
452ff229…— read only; two auto-run surfaces (a Claude Code plugin manifest and a devcontainerpostCreateCommand), four floating dependency ranges, every manifest inside the seven-day cooldown as an artefact of a--depth 1clone rather than a statement about the upstream; nothing installed, built or run, and the benchmark table'sresults/source confirmed absent from the tree against.gitignore - mambo-wang/CodeWiki-Plus
at
4b826918…— read only; no auto-run surface, one build-time execution path (tests/conftest.pyat pytest collection), two dependency manifests inside the seven-day cooldown withuv.lockbeside them, and anAGENTS.mdaddressed to a reading agent read as data; nothing installed, built or run - taylorsatula/mira
at
e401d59b…— read only; no auto-run surface, no build-time execution, nothing inside the seven-day cooldown, one unpinned dependency surface with thirty-six requirements not pinned with==, and anAGENTS.mdaddressed to a reading agent read as data; nothing installed, built or run, and the absence of any memory test confirmed withfind . -name "*test*" - text2future/flowix at
d3f5b812…— read only; no auto-run surface, one build-time execution path, two floating dependency ranges and anAGENTS.md-style instruction file read as data, with every manifest inside the seven-day cooldown as an artefact of a--depth 1clone; nothing installed, built or run, and every withheld mark named in the report rather than left silent - conorbronsdon/agent-context-os
at
15b5acac…— read only; three auto-run surfaces (agent hooks) and two instruction files addressed to a reading agent, read as data, with no build-time execution and nothing inside the seven-day cooldown; nothing installed, built or run, and the benchmark's absent committed results confirmed againstdocs/continuity-benchmark.md - quantamixsol/graqle at
04f05a60…— read only; two auto-run surfaces, six build-time execution paths, one floating dependency range and an instruction file addressed to a reading agent read as data; nothing installed, built or run, and the patent notice in the governance middleware recorded as a rider rather than an exclusion - rajkripal/cashew
at
9c886cec…— read only; no auto-run surface, one build-time execution path intests/conftest.py, one unpinned dependency surface changed five days before the reading, and aCLAUDE.mdaddressed to a reading agent read as data; nothing installed, built or run, and the absence of any epistemic state field confirmed against the node columns the repository enumerates itself - zqiren/Orbital at
6b499944…— read only; five build-time execution paths, two instruction files addressed to a reading agent read as data, non-registry and floating dependency sources in the web and demo packages, and every manifest inside the seven-day cooldown as an artefact of a--depth 1clone; nothing was installed, built or run, and the retractions module reported as having no live consumer was confirmed by grepping each of its four public functions across the tree - Astrix-Labs/papez
at
3ef91dd1…— read only; one auto-run surface in an MCP server manifest, two unpinned dependency surfaces, no build-time execution and no instruction file addressed to a reading agent; nothing installed, built or run, and the renamed predecessorgenesys-memorychecked against the corpus before scaffolding - macanderson/stella at
e5faf774…— read only; three auto-run surfaces (committed git hooks and an agent harness's hooks), seven build-time execution paths, and two instruction files addressed to a reading agent read as data, with every manifest reported inside the seven-day cooldown as an artefact of a--depth 1clone; nothing installed, built or run, and the node columns the schema says are never written confirmed absent from the projected row type - joslat/agent-memory-dotnet
at
1fe5105c…— read only; three auto-run surfaces (a Copilot instructions file and two VS Code settings files), four unpinned MSBuild reference surfaces, no build-time execution path, and anAGENTS.mdaddressed to a reading agent read as data; nothing installed, built or run, and the two existingagentmemoryreports checked and confirmed to be different projects by different authors - falcoschaefer99-eng/muse-brain
at
a5a98ae7…— read only; one build-time execution path in a publish hook, four unpinned dependency surfaces, three lockfiles unchanged for seventeen days, and no instruction file addressed to a reading agent; nothing installed, built or run, and the CC BY-NC-SA licence on the code recorded in the report as standing policy - arc-labs-ai/brain-db
at
32a77b85…— read only; one auto-run surface in a devcontainer configuration, no build-time execution path, no floating dependency surface and no instruction file addressed to a reading agent, with bothCargo.lockfiles unchanged for forty-seven days; nothing installed, built or run, and every claim taken from the 148-file specification checked against code before being repeated - raphasouthall/neurostack
at
0616b2b6…— read only; one auto-run surface in an MCP server manifest, four build-time execution paths, one unpinned dependency surface, and aCLAUDE.mdaddressed to a reading agent read as data; nothing installed, built or run, and the two files namedsetup.pyconfirmed by reading their headers to be a client-configuration command rather than a distutils script - chopratejas/invalidate
at
edaa56e1…— read only; one build-time execution path in a pytest conftest, two unpinned dependency surfaces, and no instruction file addressed to a reading agent; nothing installed, built or run, and the absence of any tool schema confirmed by reading both provider integrations, which are client wrappers rather than tool surfaces - headroomlabs-ai/headroom
at
bc21c937…— read only; four auto-run surfaces including a plugin manifest, a devcontainer, a Copilot instructions file and an MCP server manifest, with build-time execution paths and unpinned dependency surfaces across a large polyglot tree and every manifest inside the seven-day cooldown as an artefact of a--depth 1clone; nothing installed, built or run, and the reading scoped to the memory subsystem rather than the compression layer that is the bulk of the repository - mathomhaus/guild
at
139cab9b…— read only; one build-time execution surface in a Makefile whose default target was checked, two instruction files addressed to a reading agent read as data, and a committedgo.sumunchanged for twenty-three days; nothing installed, built or run, and the divergence between the two read paths' status defaults confirmed by reading both where clauses - alexahern0808/RecallWeave
at
9acde4a3…— read only; one build-time execution surface in a Makefile whose default target was checked and two floating ranges with no lockfile in the TypeScript viewer, with no instruction file addressed to a reading agent and an empty Rust dependency list; nothing installed, built or run, and the README badge naming a different account resolved by following the redirect — a rename, not a fork - mkupermann/throughline
at
01975e76…— read only; one build-time execution surface in a Makefile whose default target was checked, two pytest conftest files, three unpinned dependency surfaces and twenty-two floating ranges with a lockfile beside them, and no instruction file addressed to a reading agent; nothing installed, built or run, and the rename fromclaude_memorytraced through the changelog and confirmed distinct from the twoclaude-memreports already here - xg-gh-25/SwarmAI
at
a032aafa…— read only; two auto-run surfaces in an agent harness's hook scripts and settings, and a large set of manifests inside the seven-day cooldown across the backend, the desktop application and the skill templates; nothing installed, built or run, and the absence of any agent-reachable approval route confirmed by reading the repository's one MCP server - Ghost-Frame/Kleos
at
7ce95482…— read only; two committed hook directories inert unlesscore.hooksPathpoints at them, one build-time execution point, three unpinned manifests and nothing inside the cooldown; nothing was installed, built or run, and the Elastic License 2.0 text was read in full for a rider. - ldclabs/anda-brain at
3b176ca0…— read only; no auto-run surface, one build-time execution point, one unpinned surface and five manifests inside the seven-day cooldown, so nothing was installed or run. The reading also openedanda_kipat the=0.13.0this repository pins, fromldclabs/anda-dbat tagv0.13.0, rather than describing the graph model from Brain's call sites. - LeandroPG19/Memorys at
2f45dcb7…— read only; one auto-run surface, one build-time execution point, one unpinned surface and nothing inside the cooldown, plus anAGENTS.mdaddressed to a reading agent that was treated as data. Nothing was installed or run, so the retraction described in section 10 of its report is the project's own account rather than a re-measurement. - majiayu000/remem
at
335bb294…— read only; one auto-run surface, two build-time execution points and three manifests inside the cooldown, so the committed eval harness and benchmark were read rather than executed. - oomkapwn/enquire-mcp
at
0db770a4…— read only; one committed git hook payload inert until installed, two build-time execution points and nothing inside the cooldown. The repository shipsllms.txt,llms-ctx.txtand anAGENTS.mdaddressed to reading agents, all of which were read as data. - roboticforce/sugar at
eade1694…— read only; three manifests inside the seven-day cooldown, so nothing was installed or run. Dual licensed AGPL-3.0 or commercial; the Anthropic references in itsTERMS.mdare a trademark disclaimer rather than a rider, and the reading proceeded on that basis. - kargarisaac/lerim
at
5fed45a5…— read only; nothing was installed or run, so the committedbenchmarks/tree was read rather than executed. - Ardha-Eco-System/synapse
at
64c8b14a…— read only; nothing was installed or run, so the string-interpolation surface described in section 9 of its report is traced from the source path rather than attempted. - ddong8/memento at
9f25d7fb…— read only; no auto-run surface and nothing inside the cooldown, and nothing was installed or run. - escoffier-labs/brigade
at
f2b56bc0…— read only; nothing was installed or run, so the committed retrieval-eval harness and its fixtures were read rather than executed. - agentic-os-org/ANOLISA
at
b95908b9…— read only, and scoped to one component: the report coverssrc/agent-memoryand not the other twelve components of the operating system around it. Nothing was installed, built or run, and the crate is Linux-only. - jagoff/memo at
b4d16ca5…— read only; the screen reported six auto-run surfaces, which is inherent to a product that installs hooks and scheduled units, and nothing was installed or run. - context-graph-ai/contextdb
at
e6cf60cf…— read only; nothing was installed, built or run, and the committed benches tree was read rather than executed. It is a database rather than a memory system, and its report says which marks are therefore the caller's to earn. - jayzeng/agentmemory at
901b60dd…— read only; nothing was installed or run, so the probe outcomes in its report are read from the committed dataset rather than from a run. Its slug carries a suffix because the atlas already holds a report for a different repository of the same name. - M4F-S/gomaa at
00ee124d…— read only; nothing was installed or run. - mycelium-hq/ai-brain-starter
at
f22c46e4…— read only; three auto-run surfaces, which is what a hook harness is, and nothing was installed or run, so its guards were read rather than exercised. - jpicklyk/task-orchestrator
at
9f228716…— read only; nothing was installed, built or run. Included rather than excluded as workflow tooling because its notes are durable agent-authored content, full-text indexed and read back across sessions. - ennisaaaaaaaa-stack/tideline-memory
at
76490fe2…— read only, and the screening script reported it could not see an execution surface in this tree, so it was read by hand and the report says so. PolyForm Noncommercial 1.0.0: commercial use is outside the grant. - hermes-labs-ai/zer0dex
at
58776ccd…— read only; taken from an unreported scout shortlist entry rather than a fresh triage selection, the day's allocation having been spent. Nothing was installed or run. - FreshHillyer/xiaoO at
3acadbb3…— read only; taken from an unreported scout shortlist entry dated 2026-09-11 rather than a fresh triage selection, the day's allocation having been spent. The licence is MulanPSL-2.0, declared inCargo.tomland the README and granted inLicense/LICENSE; the GitHub API reports this repository as unlicensed because the file sits in a subdirectory, so the licence was read from the tree rather than taken from the API. Nothing was installed or run. - verrysimatupang99/codex-dev-mcp-suite
at
8a39bce8…— read only, from the day's triage selection at version 3.5.1. MIT. Screened before reading: no auto-running configuration, no build-time execution point, no.gitattributesand no.gitmodules, and five manifests declaring@modelcontextprotocol/sdkat^1.0.0with no lockfile beside any of them. Nothing was installed and nothing was run, including the project's own test runner — the findings about that runner and about the clean-restore path are read from the source. - Sherlockwz/T-Mem
at
dd9e1527…— read only; no auto-running configuration, no build-time execution point, and two unpinned surfaces (pyproject.tomlwith no lockfile, thirteen requirements at>=). Nothing was installed and nothing was run, so the paper's reported accuracies are not reproduced here. MIT. - zai-org/ZCode at
872ad960…— read only, at the repository's only commit. Apache-2.0. Screened before reading: 2 auto-run surfaces (both VS Code configuration, neither declaringrunOn: folderOpen), 2 build-time execution points (prepare: huskyand apostinstallrebuilding node-pty prebuilds), 35 dependency surfaces inside the seven-day cooldown and 29 unpinned manifests;.gitattributeswas read before checkout and carries nofilter=, and there is no.gitmodules.AGENTS.mdis present and was treated as data. Nothing was installed, built or executed. - trycua/cua at
9bbfa7dd…— read only, at the head of the default branch. MIT. Screened before reading: 1 auto-run surface (.vscode/settings.json, carrying formatter, interpreter and colour settings; norunOn: folderOpenexists anywhere in the tree), 23 build-time execution points (four Rustbuild.rs, eightconftest.py, asetup.py, five npm manifests and a Makefile), 152 dependency surfaces inside the seven-day cooldown and 75 unpinned manifests;.gitattributescarries nofilter=and there is no.gitmodules.AGENTS.mdandCLAUDE.mdare present and were treated as data. Nothing was installed, built or executed — no benchmark was run and no recording was made. One finding was reported to the maintainers through the private channelSECURITY.mdrequires. - volotat/mini-AGI
at
7361e7a5…— read only, at the head of the default branch. MIT. The screen reported NOTHING SCANNED, and a hand read of all 56 committed files explains it: no dependency manifest of any kind, noconftest.py, noMakefile, no.envrc, no.gitattributes, no.gitmodules, and.github/holding onlyFUNDING.yml— no auto-run surface, no build-time execution point and no agent-directed file. Nothing was installed, built or executed; the model was never trained or served, and the forgetting probe was not run - strands-agents/harness-sdk
at
15da9dca…— read only, at the head of the default branch. Apache-2.0, Amazon. Screened from a full clone before reading: 0 auto-run surfaces, 27 build-time execution points (19conftest.py, the rootpackage.json'sprepare: husky, and seven example manifests whosepreparerunsnpm ci --prefix ../../..), 32 unpinned dependency surfaces and 19 inside the seven-day cooldown, dated by their own commits..gitattributescarries* text=auto eol=lfand nofilter=; there is no.gitmodules;.claude/and.kiro/hold only symlinks to.agents/skillsand.agents/references, with no settings file and no hooks;.husky/pre-commitruns the project's own lint, build, test, format and type-check scripts, and since 23 September 2026 a staged-Python lint that fetchesruff>=0.16.0,<0.17.0throughuvx; it is inert in a clone.AGENTS.mdandCLAUDE.mdwere treated as data. Nothing was installed, built or executed - elizaOS/eliza at
a7e56b58…— read only, at the head of the default branchdevelop. MIT. Screened before reading: 1 auto-run surface (.gitmodules, declaringelizaOS/llama.cppandelizaOS/electrobun; the clone used--recurse-submodules=noand both were left uninitialised, so every absence claim in that report is scoped to the superproject), 44 build-time execution points including a rootpostinstallrunning three vendored-package patch scripts, 155 unpinned dependency surfaces and 170 inside the seven-day cooldown — that last count is an artifact of a--depth 1clone dating every file to the tip..gitattributescarrieseol=lfnormalisation and nofilter=.AGENTS.mdand twoCLAUDE.mdfiles were treated as data. Nothing was installed, built or executed - gastownhall/gastown at
649b832b…— read only, at the head ofmain, a commit dated 23 July 2026. MIT. Screened before reading: 1 auto-run surface (.githooks/, inert unlesscore.hooksPathpoints at it), 2 build-time execution points (Makefile, an npmpostinstall), no unpinned surface and nothing inside the cooldown;AGENTS.mdwas treated as data. The storage engine was read in gastownhall/beads atv1.0.5, whose screen reported six auto-run surfaces; that clone was read withgrepandsedonly. Nothing was installed, built or executed. - gastownhall/beads
at
a1bc167b…— read only, at the head ofmain, a commit dated 25 September 2026. MIT. Screened before reading: 6 auto-run surfaces (.claude/settings.jsonwith two PreToolUse command filters,.claude-plugin/,.devcontainer/,.githooks/,.github/copilot-instructions.md), 3 build-time execution points and 11 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip;AGENTS.mdandCLAUDE.mdwere treated as data. Only the memory plane was read. Nothing was installed, built or executed. - petabridge/memorizer
at
0c043e4c…— read only, at the head ofdev, a commit dated 11 September 2026. MIT. Screened before reading: no auto-run surface, no build-time execution point and nothing inside the cooldown; three unpinned surfaces, each a.csprojwhose versions are pinned exactly inDirectory.Packages.propsby central package management.AGENT.mdandCLAUDE.mdwere treated as data. Nothing was installed, built or executed. - yantrikos/yantrikdb-mcp
at
364e19a5…— read only, at the head ofmain, a commit dated 19 September 2026. MIT. Screened before reading: 3 auto-run surfaces (.mcp.json,mcp.jsonandserver.json, each launchinguvx yantrikdb-mcp), no build-time execution, 2 unpinned manifests and 2 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip; no agent-instruction file. The engine it installs was read at yantrikos/yantrikdbv0.23.1, the newest release in the manifest's range before the pin, from a partial checkout whose screen showed onebuild.rsand three files inside the cooldown. Nothing was installed, built or executed. - oleksiijko/pmb at
59b6800c…— read only, at the head ofmain, a merge dated 23 September 2026. Apache-2.0. Screened before reading: 1 auto-run surface (server.json, an MCP registry manifest naming the PyPI package, with no command), 3 build-time execution points (Makefile, an npmpostinstall,tests/conftest.py), 2 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 1 unpinned surface (pyproject.toml);.claude/launch.jsonwas treated as data. Nothing was installed, built or executed. - spectrayan/spector at
b9012992…— read only, at the head ofmain, a commit dated 25 September 2026. Apache-2.0, with aNOTICErequiring visible attribution. Screened before reading: no auto-run surface, 2 build-time execution points (npmprepublishOnlyin two packages), 9 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 4 unpinned surfaces; the screen does not parse Maven, andAGENTS.mdwas treated as data. Nothing was installed, built or executed. - rergards/mempalace-code
at
3594fbce…— read only, at the head ofmain, a commit dated 21 September 2026. Apache-2.0. A hard fork of MemPalace; upstream was read at the last shared commit,c30bc9e7…, to separate inherited code from new. Screened before reading: 2 auto-run surfaces (.claude/settings.json, whose hooks run the test suite and linters ongit commit;hooks/, registered by nothing in the tree), 1 build-time execution point (tests/conftest.py), 4 dependency files inside the cooldown, over-counted by the depth-1 clone, and no unpinned surface;AGENTS.mdandCLAUDE.mdwere treated as data. Nothing was installed, built or executed. - codependentai/resonant-mind
at
9a08410b…— read only, at the head ofmaster, the v4.0.1 merge dated 19 September 2026. Codependent AI Source-Available License, personal and non-commercial use only; the tree was Apache 2.0 until81bb4d1e…on 30 March 2026. Published as Mind Cloud up to v2.3.1. Screened before reading: no auto-run surface, no build-time execution point, no unpinned surface, andpackage.jsonandpackage-lock.jsoninside the cooldown — the lockfile changed on 19 September 2026 by the API, not only by the depth-1 clone's tip date; no agent-instruction files. Nothing installed, built or run. - NickCirv/engram at
df445d31…— read only, at the head ofmain, a commit dated 22 September 2026. Apache-2.0. Screened before reading: 2 auto-run surfaces (.cursorrules, an engram-generated structure summary, andserver.json, an MCP manifest naming theengramxnpm package), 3 build-time execution points (a banner-onlypostinstall, twoprepublishOnlybuilds), 5 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 3 unpinned surfaces;.cursorrules,CLAUDE.mdandCONTEXT.mdwere treated as data. Only the mistake, decision and pattern memory and the storage it shares were read. Nothing was installed, built or executed. - ohad6k/emulo at
a8552916…— read only, at the head ofmain, a merge dated 25 September 2026. MIT. Named Ditto until v0.5.0. Screened before reading: 3 auto-run surfaces (.claude-plugin/manifests with no hooks,server.jsonandsmithery.yamldeclaring the MCP start command), no build-time execution point, 3 unpinned surfaces and 6 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip. Nothing was installed, built or executed. - RMANOV/sqlite-memory-mcp
at
f5d04e6e…— read only, at the head ofmain, a merge commit dated 25 September 2026. MIT. Screened before reading: 1 auto-run surface (hooks/, seven scripts a plugin manifest could register, with no manifest in the tree), 1 build-time execution point (tests/conftest.py), 2 dependency files inside the cooldown — every file in the depth-1 clone dating to the tip — and 2 unpinned surfaces; noAGENTS.mdorCLAUDE.mdpresent. The debate protocol, task manager and private-extension contract were not read beyond what the memory paths touch. Nothing was installed, built or executed. - verygoodplugins/automem
at
0e8c4174…— read only, at the head of the default branchdevelop, a commit dated 28 August 2026. MIT. Screened before reading: no auto-run surface, 3 build-time execution points (Makefileand twoconftest.py), 4 unpinned surfaces, nothing inside the cooldown, andAGENTS.mdandCLAUDE.mdrecorded as data. Its MCP client verygoodplugins/mcp-automem was read at its pin9a0bbf75…for the integration surface; its screen showed 2 auto-run surfaces (.claude-plugin/,server.json), 2 build-time execution points, 1 unpinned manifest with a lockfile and nothing inside the cooldown. Nothing was installed, built or executed. - mex-memory/mex at
5b6e02c9…— read only, at the head ofmain, a commit dated 25 September 2026. MIT. Screened before reading: 1 auto-run surface (.claude-plugin/marketplace.json, a skills marketplace entry), 1 build-time execution point (npmprepare), 5 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 5 unpinned surfaces;AGENTS.mdandCLAUDE.mdwere treated as data. The code graph was read only where Wiki groundings depend on it. Nothing was installed, built or executed. - skynetcmd/m3-memory at
651ae92a…— read only, at the head ofmain, a commit dated 22 September 2026. Apache-2.0, with a NOTICE requesting attribution for the architecture. Screened before reading: 7 auto-run surfaces (.claude-plugin/,.claude/settings.jsonholding only a permission allowlist, a Git LFS rule in.gitattributesmatching no file,.githooks/,hooks/andhooks/hooks.json,server.json), 3 build-time execution points (setup.py, twoconftest.py), 7 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 6 unpinned surfaces;AGENTS.md,CLAUDE.mdandGEMINI.mdwere treated as data. The corememory_itemsstore was read; the chat-log, file-ingestion, wiki and PostgreSQL-sync subsystems only where they touch it. Nothing was installed, built or executed. - ruvnet/RuVector at
5356a84e…— read only, at the head ofmain, a commit dated 23 September 2026. MIT. Screened before reading: 4 auto-run surfaces (.claude/settings.jsonhooks that post commit messages and session summaries topi.ruv.io,.claude/hooks/,.githooks/inert until installed,.gitmoduleswith three submodules left uninitialised), 71 build-time execution points, 79 unpinned surfaces and 594 dependency surfaces inside the cooldown, every file in the depth-1 clone dating to the tip;CLAUDE.mdwas treated as data. The npm hook store, the Shared Brain server and theruvector-agent-memoryandAgenticDBlibrary APIs were read; the vector engine was not. Nothing was installed, built or executed. - off-grid-ai/OGAD
at
7f073cad…— read only, at the head ofmain, a commit dated 25 September 2026. AGPL-3.0-only; thepro/submodule, pinned atd30893ee…ofoff-grid-ai/desktop-pro, is a private repository and was not read. Screened before reading: 4 auto-run surfaces (.claude/settings.json, a permission allowlist with no hooks;.gitattributesLFS filters, checked out with the filters disabled;.gitmodules, left uninitialised;.vscode/settings.json), 2 build-time execution points (an npmpostinstalland apreparethat setscore.hooksPath), 5 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 2 unpinned surfaces, seven of whosefile:dependencies resolve outside the repository;AGENTS.mdandCLAUDE.mdwere treated as data. Nothing was installed, built or executed. - timothywarner-org/context-engineering
at
0f07bdbd…— read only, at the head ofmain, a commit dated 19 September 2026; onlysrc/warnerco/backend/is covered, the labs, notebooks and slide decks being course material. MIT. Screened before reading: 1 auto-run surface (a.gitattributesLFS filter on.zipand.pptx, checked out with the smudge filter disabled), 1 build-time execution point (tests/conftest.py), 14 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 6 unpinned surfaces;CLAUDE.md,.claude/and.github/agents/were treated as data. Nothing installed, built or run. - AEndrix03/Graft at
b60e8f34…— read only, at the head ofmaster, the v0.1.1 release commit dated 25 September 2026. Apache-2.0. Screened before reading from a shallow clone: 1 auto-run surface (.gitmodules, four third-party submodules left uninitialised), no build-time execution point, 3 dependency files inside the seven-day cooldown, every file in the depth-1 clone dating to the tip, and 2 unpinned surfaces (the MCP server'spyproject.tomlwithout a lockfile, the viewer's floating ranges); an emptyCLAUDE.mdwas treated as data. Nothing was installed, built or run - star-ga/mind-mem
at
ddcd7c01…— read only, at the head ofmain, a commit dated 24 September 2026. Apache-2.0. Screened before reading: 5 auto-run surfaces (.cursorrules,.githooks/pre-commit,.github/copilot-instructions.md,hooks/andhooks/hooks.json, whose Stop hook runs capture and can read~/.claude/projectstranscripts), 7 build-time execution points (Makefile,deploy/Makefile,setup.py, threeconftest.py, an npmprepublishOnly), 7 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 3 unpinned surfaces;AGENTS.md,CLAUDE.md,.cursorrulesandAUDIT_FINDINGS_FOR_CLAUDE.mdwere treated as data. The governed write path, admission, recall, namespaces and the MCP ACL were read; the training scripts, benchmarks, SDKs and web console were not. Nothing was installed, built or executed. - paperclipai/paperclip
at
01d9a121…— read only, at the head ofmaster, a commit dated 26 September 2026. MIT. Only the LLM Wiki plugin was scored; thepara-memory-filesskill, the memory connectors and the unimplemented memory-binding design are described in the report and not scored. Screened before reading: no auto-run surface, 1 build-time execution point (a root npmpostinstall), 46 unpinned surfaces and 53 files inside the cooldown, every file in the depth-1 clone dating to the tip;AGENTS.mdwas treated as data. Nothing was installed, built or executed. - google-research/rrsi
at
be50316e…— read only; Apache-2.0; no auto-run surface, no build-time execution point, two dependency files inside the cooldown (a depth-1 clone dates every file to the tip) and one unpinned manifest,pyproject.tomlwith no lockfile;SKILL.mdandPATTERNS.mdread as data; nothing installed, built or run - automatika-robotics/emem
at
82e3da61…— read only, at the head ofmain, a commit dated 22 May 2026. MIT in theLICENSEfile; the README's last line claims all rights reserved. Screened before reading: no auto-run surface, 1 build-time execution point (tests/test_harness/conftest.py), 2 unpinned surfaces (harness/requirements.txt,pyproject.tomlwith no lockfile) and nothing inside the cooldown; no agent instruction files. The paper (arXiv:2606.03374, v2) was read in full; nothing installed, built or run. - taeilkim2465/agentic_memory_distillation
at
2895d10c…— read only; no licence file, so all rights reserved by default;bfcl/common/memory/,toolsandbox/common/memory/, the two harness overlays and the AppWorld baseline trees, with the paper read from the arXiv v1 PDF. No auto-run surface, three build-time execution points (onesetup.pyper AppWorld tree), nothing inside the cooldown, six unpinned surfaces; nothing installed, built or run, and no published figure recomputed — no run output is committed - GoldenGait/FARM-Project
at
2fcaf860…— read only, at the head ofmain, the repository's only commit, authored 27 July 2026. AGPL-3.0-or-later, the licence text with no rider. Screened before reading: 1 auto-run surface (.gitmodules, the YOLOE fork, left uninitialised), 1 build-time execution point (ros/mapping/setup.py), 1 unpinned surface (pyproject.tomlwith no lockfile) and nothing inside the cooldown;CLAUDE.mdwas treated as data. The paper, arXiv:2606.15476, was read at v3. Nothing was installed, built or run. - paolorv/lgr-agent
at
3593e6a4…— read only; Apache-2.0, with the vendoredremembr/under NVIDIA's non-commercial licence and compared with NVIDIA-AI-IOT/remembr by blob hash; screened with no auto-run surface, five build-time execution points and five unpinned dependency surfaces; nothing installed, built or run - NovasPlace/living-mind-cortex
at
f8bdb805…— read only, at the head ofmain, the archive commit dated 5 August 2026. No licence file:README.mdclaims Apache 2.0 and links aLICENSEabsent from the tree. Screened before reading on a full clone: no auto-run surface, 1 build-time execution point (tests/conftest.py), 3 unpinned surfaces (requirements.txt,dashboard/requirements.txt,dashboard/Crucible/requirements.txt) and nothing inside the cooldown; no agent-instruction files. The consuming hook in NovasPlace/CSM was read at9c7cfb22…. Nothing was installed, built or run. - bks-lab/open-bridge at
5f1fe878…— read only, at the head ofmain, a merge commit dated 27 September 2026. MIT. Screened before reading: 3 auto-run surfaces (.claude/hooks/,.claude/settings.jsonwith one Stop hook,.github/copilot-instructions.md), 4 build-time execution points (conftest.pyfiles), 2 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 2 unpinnedpyproject.tomlsurfaces;AGENTS.md,CLAUDE.mdandGEMINI.mdwere treated as data. The memory base, its scripts and the proposal ledger were read; the A2A agent runtime was not. Nothing was installed, built or executed. - Vortx-AI/emem at
4b26f9ef…— read only, at the head ofmain, a commit dated 28 September 2026. Apache-2.0;TERMS.mdcovers only the hosted instance. Screened before reading: 3 auto-run surfaces (.claude-plugin/,.gitmodulesnaming four reference-list submodules left uninitialised,server.json), 3 build-time execution points, 27 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 6 unpinned surfaces;AGENTS.mdwas treated as data. Nothing was installed, built or executed. - cucupac/shellbrain at
aacf66b2…— read only, at the head ofmain, a commit dated 24 September 2026. No licence file in the tree and none declared inpyproject.toml. Screened before reading: no auto-run surface, 14 build-time execution points (conftest.pyfiles), 2 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 2 unpinned surfaces (pyproject.tomlwith no lockfile,pytest>=8.0,<9.0inrequirements.txt); theonboarding_assets/skill and rules files were treated as data. Nothing was installed, built or executed. - PCIRCLE-AI/memesh
at
dd77d78e…— read only, at the head ofmain, a commit dated 28 September 2026 (UTC). MIT. Screened before reading: 3 auto-run surfaces (.claude-plugin/,hooks/,hooks/hooks.json), 2 build-time execution points (npmprepublishOnlyin the root and OpenClaw manifests), 5 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 3 floating surfaces;AGENTS.mdandCLAUDE.mdwere treated as data. No checkout filter and no submodules. Only the memory layer was read; the agent-messaging subsystem is out of scope. Nothing was installed, built or executed. - jungjaehoon-lifegamez/MAMA
at
6738c694…— read only, at the head ofmain, a commit dated 28 September 2026. MIT. Screened before reading: 2 auto-run surfaces (.claude-plugin/marketplace.jsonand an empty.gitmodules), 2 build-time execution points (a huskyprepareand the plugin'spostinstall), 8 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 6 floating surfaces;AGENTS.mdandCLAUDE.mdwere treated as data. The memory tier ofmama-core, its MAMA OS consumers and the Claude Code MCP server and hooks were read. Nothing was installed, built or executed. - Nabzx/mnemosyne at
431f1f0e…— read only, at the head ofmain, a commit dated 28 September 2026. Apache-2.0. Screened before reading: 1 auto-run surface (.githooks/pre-commit, inert unlesscore.hooksPathpoints at it), no build-time execution point, 8 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 4 Python manifests with no lockfile;AGENTS.mdwas treated as data. Nothing was installed, built or run. - tigerless-labs/autoharness
at
f74a9fb4…— read only; four auto-run surfaces (the plugin manifest,.mcp.json,hooks/andhooks/hooks.json), no build-time execution and no dependency manifest, so nothing inside the cooldown and nothing unpinned. Nothing was installed, built or run and no benchmark was reproduced. MIT - 0xK3vin/MegaMemory at
e0bb3c27…— read only, at the head ofmain, tagged v1.6.2 and dated 3 May 2026. MIT. Screened before reading: no auto-run surface, 1 build-time execution point (the npmprepublishOnlyscript), 1 unpinned surface (ten caret ranges inpackage.json, resolved by the committed lockfile) and nothing inside the cooldown, every file in the depth-1 clone dating to the tip; no agent-instruction file is in the tree, and the installer's instruction text and slash commands were treated as data. Nothing was installed, built or executed. - kagura-ai/memory-cloud
at
adefcff4…— read only, at the head ofmain, the v0.82.0 release commit dated 28 September 2026. Apache-2.0 inLICENSE; the Claude Code plugin manifest declares MIT. Screened before reading: 4 auto-run surfaces (.claude-plugin/,.claude/settings.jsonwith formatter, secret-guard and memory-sync hooks,.github/copilot-instructions.md,server.json), 9 build-time execution points (Makefileand eightconftest.py), 4 dependency files inside the cooldown with every file in the depth-1 clone dating to the tip, and 1 unpinned surface (frontend/package.json, lockfile present);CLAUDE.mdwas treated as data. Nothing was installed, built or run. - Prismer-AI/PrismerCloud
at
5337ca14…— read only, at the head ofmain, a commit dated 29 September 2026. MIT for the SDK; the server backend is closed-source and not in the tree, so only the daemon undersdk/prismerwas read. Screened before reading: 1 auto-run surface (.claude-plugin/marketplace.json, which installs a plugin from npm and is inert unless added as a marketplace), 4 build-time execution points, 11 unpinned surfaces and 15 dependency files inside the cooldown, every one an artifact of the depth-1 clone;CLAUDE.mdwas treated as data. Nothing was installed, built or executed. - memseekai/memseek
at
c2ec72ab…— read only, at the head ofmain, a commit dated 28 September 2026. Apache-2.0. Screened before reading: 2 auto-run surfaces (.claude-plugin/marketplace.json,.vscode/tasks.jsonwith norunOn), 3 build-time execution points (Makefile, twoconftest.py), 3 unpinned surfaces and 7 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip; by history the newest manifest change is dated 16 September 2026. No agent-instruction file is in the tree. Themcp2.0.0 server was read at its tag for argument validation. Nothing was installed, built or executed. - Artexis10/exomem
at
c44eaa0b…— read only, at the head ofmain, a commit dated 30 September 2026; published askb_mcpand renamed in release 0.2.0. AGPL-3.0. Screened before reading: 2 auto-run surfaces (the.claude-pluginmarketplace entry pointing at the plugin hooks, and theserver.jsonMCP manifest), 4 build-time execution points (asetup.pyunderbenchmarks/and threeconftest.py), 12 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 1 unpinned surface (one caret range resolved by a committed lockfile);AGENTS.md, a symlink toCLAUDE.md, was treated as data. Nothing was installed, built or executed. - d-o-hub/rust-self-learning-memory
at
67edf6ce…— read only, at the head ofmain, a merge dated 29 September 2026. MIT, with aLICENSEcopyright line naming a different holder thanCargo.toml's authors. Screened before reading: 5 auto-run surfaces (.claude/settings.jsonwith hooks runningcargo check,cargo buildandcargo test,.claude/hooks/,.githooks/,.opencode/,.vscode/settings.json), no build-time execution point, no unpinned surface, and 16 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip;AGENTS.md,CLAUDE.mdandGEMINI.mdwere treated as data. Nothing was installed, built or executed. - qyiun666/MemHop at
5e1e1f68…— read only, at the head ofmain, a commit dated 25 September 2026. MIT OR Apache-2.0. Screened before reading: no auto-run surface, 1 build-time execution point (Makefile), no unpinned surface, andgo.modandgo.suminside the cooldown, every file in the depth-1 clone dating to the tip; the per-packageagent.mdfiles were treated as data. Nothing was installed, built or executed. - XBlueSky/cortexes
at
ff2eaeb5…— read only, at the head of the defaultpluginbranch, a merge dated 22 September 2026. Apache-2.0. Screened before reading: 3 auto-run surfaces (.claude-plugin/,hooks/,hooks/hooks.jsonregistering SessionStart and SessionEnd), 1 build-time execution point (cortex-vec/tests/conftest.py), nothing inside the cooldown and 1 unpinned surface (cortex-vec/pyproject.toml, no lockfile); no agent-addressed files. Nothing was installed, built or executed. - hraness/wordcell
at
818e6abc…— read only, at the head ofmain, a commit dated 29 September 2026; published as@hraness/kbuntil release 0.20.0 renamed it. MIT. Screened before reading: no auto-run surface, no build-time execution point, 5 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 4 unpinned surfaces (non-registry Git and release-tarball sources pinned by commit, tag or version, and caret ranges; the rootpackage.jsonwas listed as having no lockfile althoughbun.lockis committed beside it);AGENTS.mdandCLAUDE.mdwere treated as data. The pinned Oh and QMD engines were not read. Nothing was installed, built or executed. - TencentCloud/octop-memory
at
8b6abc3b…— read only, at the head ofmain, the 1.0.0 release merge of 24 September 2026. MIT. Screened before reading: 1 auto-run surface (.githooks/pre-commit, inert unlessmake install-hookssetscore.hooksPath), 1 build-time execution point (Makefile), 2 unpinned surfaces and 5 dependency files inside the cooldown, which a depth-1 clone inflates;AGENTS.mdwas treated as data. Nothing was installed, built or run. - AliceLJY/recallnest at
d1f4915a…— read only, at the head ofmain, a commit dated 25 September 2026; started as a fork of memory-lancedb-pro and not marked as a fork on GitHub. MIT. Screened before reading: 2 auto-run surfaces (the.claude-plugin/marketplace entry launchingscripts/start-server.sh, and.mcp.jsonwith an empty server list), 1 build-time execution point (npmprepublishOnly), 2 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 1 unpinned surface (seven caret ranges resolved by a committed lockfile);CLAUDE.mdwas treated as data. No checkout filter and no submodules. Nothing was installed, built or executed. - AndrewNgo-ini/memoose
at
7708331e…— read only, at the head ofmain, a commit dated 25 September 2026. Apache-2.0. Screened before reading: 2 auto-run surfaces (.claude-plugin/,mcp.json), 1 build-time execution point (tests/conftest.py), 2 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and no unpinned surface;CONTEXT.mdand the skills were treated as data. The project was namedmnemothuntil 9 September 2026. The committed LoCoMo rows were recomputed with a short script; nothing from the tree was installed, built or executed. - zensation-ai/zenbrain
at
9854155a…— read only, at the head ofmain, a commit dated 26 September 2026. Apache-2.0; the paper is CC BY 4.0. Screened before reading: no auto-run surface, no build-time execution point, 11 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 9 floating-range surfaces;AGENTS.mdwas treated as data. The paper's abstract was read from the arXiv API; the Zenodo deposits were not read. Nothing was installed, built or executed. - Obelyth/cortex at
ec57124a…— read only, at the head ofmain, a commit dated 17 September 2026. AGPL-3.0-only. Screened before reading: 1 auto-run surface (.devcontainer/devcontainer.json,postCreateCommandnpm ci --ignore-scripts), no build-time execution point, nothing inside the cooldown and 1 unpinned surface (package.json, 12 floating ranges withpackage-lock.jsonpresent); no agent-addressed files. Nothing was installed, built or executed. - lktiep/cortex-hub
at
e47a1577…— read only, at the head ofmaster, a commit dated 28 September 2026. MIT. Screened before reading: 4 auto-run surfaces (.claude/hooks/,.claude/settings.json,.claude/settings.local.json,.cursorrules), 0 build-time execution points, 10 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 9 unpinned surfaces resolved by the rootpnpm-lock.yaml;AGENTS.md,CLAUDE.mdand.cursorruleswere treated as data. No checkout filter and no submodules. Nothing was installed, built or executed. - mindscale-noah/MindMemOS
at
186db4a7…— read only, at the head ofmain, a merge ofdevelopdated 29 August 2026. MIT as stated in the README; the tree has noLICENSEfile and GitHub reports none. Screened before reading: 0 auto-run surfaces, 4 build-time execution points, 0 dependency files inside the cooldown and 5 unpinned surfaces;skills/mindmemos-cli/SKILL.mdwas treated as data. Nothing was installed, built or executed. - LindaHaviv/second-brain
at
4890df9f…— read only, at the head ofmain, a commit dated 20 September 2026. MIT. Screened before reading: 1 auto-run surface (.claude/settings.json, a PreToolUse hook blocking agent edits to.envfiles), no build-time execution point, nothing inside the cooldown and 1 unpinned surface (oracle/agent/requirements.txt);AGENTS.mdandCLAUDE.mdwere treated as data. The default backend'soracleagentmemorypackage, which publishes wheels only, was not read. Nothing was installed, built or run. - rexleimo/aios at
6e2910a9…— read only, at the head ofmain, a commit dated 28 September 2026. MIT. Screened before reading: 1 auto-run surface (.gitmodules, pulling therex-harnesssubmodule, which was not cloned), no build-time execution, 14 dependency files inside the cooldown — every file in the depth-1 clone dating to the tip — and 6 unpinned surfaces;AGENTS.md,CLAUDE.mdandGEMINI.mdwere treated as data. Only the memory subsystem was read. Nothing was installed, built or executed. - 1173591564/Dynamics-memory
at
9ee06f66…— read only, at the head ofmain, a commit dated 28 September 2026. No licence file, and GitHub reports none. Screened before reading: 1 auto-run surface (.opencode/plugin/memory-bridge.ts, which spawns the sidecar when opencode starts in the tree), no build-time execution point, 12 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 3 unpinned surfaces; tenAGENTS.mdfiles inside the vendored opencode packages underagent/were treated as data. Nothing was installed, built or executed. - JunNanLYS/dsh-layered-memory
at
69028fbe…— read only; MIT; no auto-run surface, no build-time execution, nothing inside the cooldown, one floating surface (package.jsonranges under a committedpnpm-lock.yaml), four subdirectoryAGENTS.mdfiles read as data; nothing installed, built or run, and the committed benchmark scores were summed from the result JSON with Python - Playa-Cyrene/Cyrene-Agent
at
be6ce1f8…— read only, at the head ofmaster, a commit dated 28 September 2026. MIT; the bundled Live2D model is credited separately inMODEL_LICENSE.md. Scoped to the memory subsystem (src/main/memory,src/main/social-contextand the retrieval code they call). Screened before reading: no auto-run surface, no build-time execution point, 7 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 2 unpinned surfaces; no agent instruction files in the tree. Nothing installed, built or run. - neomjs/neo-agent-brain
at
83c0e09e…— read only, at the head ofdev, a commit dated 29 September 2026. MIT. Screened before reading: no auto-run surface, 1 build-time execution point (the npmpreparescript), 8 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 5 unpinned surfaces, includingneo.mjsfrom a GitHub archive; no agent-instruction file in the tree. Only the Memory Core was read. Nothing was installed, built or executed. - Muvon/octobrain at
ccc1d53a…— read only, at the head ofmaster, the 0.14.4 release commit dated 30 September 2026. Apache-2.0. Screened before reading: 1 auto-run surface (server.json, an MCP registry manifest declaring a start command), 2 build-time execution points (Makefile,benches/Makefile), 3 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and no unpinned surface;AGENTS.mdwas treated as data. Nothing was installed, built or executed. - RodCor/kimetsu at
b5705fb2…— read only, at the head ofmain, a commit dated 10 September 2026. MIT OR Apache-2.0. Screened before reading: 1 auto-run surface (.githooks/pre-commit, inert unlesscore.hooksPathpoints at it), 2 build-time execution points (crates/kimetsu-cli/build.rs, an npmprepublishOnly), 1 unpinned surface and nothing inside the cooldown, every file in the depth-1 clone dating to the tip; no agent-instruction files. Read withgrepandsed; nothing was installed, built or executed. - RooAGI/Lint-AI at
a1919f1d…— read only, at the head ofmain, a merge dated 30 September 2026 UTC. Apache-2.0. Screened before reading: no auto-run surface, 2 build-time execution points (both ordinary modules namedbuild.rsundersrc/, not Cargo build scripts), 5 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and no unpinned surface reported althoughCargo.lockis gitignored;.claude/skills/lint-ai-memory/SKILL.mdandINSTALL_FOR_AGENTS.mdwere treated as data. Nothing was installed, built or executed. - mrveiss/AutoBot-AI at
2b88c1c2…— read only, at the head ofmain, a commit dated 30 September 2026; the memory stores, their routes and tasks inautobot-backend/were read and the rest of the platform was not. Apache-2.0. Screened before reading: 3 auto-run surfaces (.claude/hooks/,.claude/settings.json,.vscode/settings.json), 30 build-time execution points, 39 unpinned dependency surfaces and 50 dependency files inside the cooldown, which a depth-1 clone inflates because every file dates to the tip;CLAUDE.mdwas treated as data. Nothing was installed, built or executed. - nano-step/nano-brain
at
fc58b4b7…— read only, at the head ofmaster, a commit dated 7 September 2026. MIT. Screened before reading: 3 auto-run surfaces (.claude/settings.jsonwith one PreToolUse hook that runs a harness check only ongh pr create, its script under.claude/hooks/, and an.opencode/bundle whose five third-party MCP servers are disabled), 2 build-time execution points (Makefile, an npmpostinstallthat downloads the release binary), 2 floating ranges and nothing inside the cooldown;AGENTS.mdandCLAUDE.mdwere treated as data. Only the memory half was read; the code-intelligence packages were not. Nothing was installed, built or executed. - mmethodz/dreamgraph at
563d10c8…— read only, at the head ofmain, released as v13.4.0 and dated 30 September 2026. DreamGraph Source-Available Community License v2.0, non-commercial; production and commercial use need a separate licence. Screened before reading: 1 auto-run surface (.github/copilot-instructions.md, treated as data), 0 build-time execution points, 9 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 5 unpinned surfaces beside a root lockfile. Nothing was installed, built or executed. - Nocetic/flowly at
a5dc7c30…— read only, at the head ofmain, a commit dated 17 September 2026. Apache-2.0. Screened before reading: no auto-run surface, 5 build-time execution points (threesetup.py, twoconftest.py), 3 unpinned surfaces (twopackage.json, one skillrequirements.txt) and nothing inside the cooldown; no agent-instruction file in the tree. Only the memory subsystem was read. Nothing was installed, built or executed. - ozankasikci/global-agent-memory
at
53480fd2…— read only, at the head ofmain, a commit dated 1 September 2026. MIT. Screened before reading: 1 auto-run surface (server.json, an MCP registry manifest naming the PyPI package), 1 build-time execution point (Makefile), 1 unpinned surface (dashboard/package.json, lockfile present) and nothing inside the cooldown;dashboard/AGENTS.mdand the integration snippets were treated as data. Nothing was installed, built or executed. - MikeK184/Recollect at
6a85f6a1…— read only, at the head ofmain, a commit dated 30 September 2026. Apache-2.0. Screened before reading: 1 auto-run surface (.opencode/, six agent prompt files), no build-time execution point, 10 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 1 unpinned surface (web/package.json, lockfile present);opencode.jsonand.codex/config.tomldeclare MCP servers launched withnpx -y, which the screen does not flag;AGENTS.mdwas treated as data. Read withgrep,sedandawk; nothing was installed, built or executed. - RightL/RightMemory at
0cd5e868…— read only, at the head ofmain, a commit dated 30 September 2026. Apache-2.0. Screened before reading: no auto-run surface, no build-time execution point, one unpinned surface (pyproject.tomlhas no lockfile) and three dependency files inside the cooldown, every file in the depth-1 clone dating to the tip;AGENTS.mdwas treated as data. Nothing was installed, built or executed. - SawyerHan-AI/TideMind
at
29cef627…— read only, at the head ofmain, dated 30 September 2026. MIT. Screened before reading: 0 auto-run surfaces, 2 build-time execution points (an npmpostinstallrunningelectron-rebuild, and abinding.gypnative addon), 5 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, 4 unpinned surfaces beside a root lockfile, and no agent-instruction file. Nothing was installed, built or executed. - 20alexl/claude-engram
at
a7903274…— read only, at the head ofmain, the 0.8.61 commit dated 27 September 2026. MIT. Screened before reading: no auto-run surface, no build-time execution point, one dependency file inside the cooldown (pyproject.toml, every file in the depth-1 clone dating to the tip) and one unpinned surface (pyproject.tomlwithout a lockfile);CLAUDE.mdwas treated as data. Nothing was installed, built or executed. - diegoxtr/ctx-open
at
c31d84e0…— read only, at the head ofmain, a commit dated 21 September 2026. CTX Source-Available License v1.0: local, self-hosted and on-premise commercial use granted, hosted or competing services barred without a separate agreement. Screened before reading: 1 auto-run surface (.devcontainer/devcontainer.json,postCreateCommandandpostStartCommand), no build-time execution point, no unpinned surface and nothing inside the cooldown across 14 files scanned; no agent-instruction files, andprompts/was treated as data. Nothing was installed, built or executed. - roampal-ai/roampal-core
at
211e7e05…— read only, at the head ofmain, a commit dated 26 September 2026. Apache-2.0. Screened before reading: no auto-run surface, 4 build-time execution points (threeconftest.pyfiles androampal/cli/setup.py), 1 unpinned surface (pyproject.tomlwith no lockfile) and 1 file inside the cooldown, every file in the depth-1 clone dating to the tip; no agent instruction files were in the tree. The companion paper was read aspaper.mdin roampal-ai/roampal-labs at6b20c0d8…. Nothing was installed, built or executed. - rmk40/opencode-session-recall
at
8a5ccd63…— read only; MIT; no auto-run surface, two build-time execution points inpackage.json(prepare: husky,prepublishOnly), no file inside the cooldown, one unpinned surface of fourteen floating ranges under a lockfile, two inert.husky/hook payloads,AGENTS.mdread as data, and nothing was installed, built or run - aoci-spec/aoci-code at
fdb4cb9b…— read only, at the head ofmain, a commit dated 29 September 2026. FSL-1.1-MIT (source-available, converting to MIT two years after each release). Screened before reading: 0 auto-run surfaces, 2 build-time execution points (Makefileand the vendored openGauss connector'sMakefile), 9 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 2 unpinned surfaces in black-box fixtures;AGENTS.mdwas treated as data. Nothing was installed, built or executed. - alex-feel/mcp-context-server
at
ed6a24d8…— read only, at the head ofmain, a sync commit dated 30 September 2026. Elastic License 2.0 in the tree; the project states releases up to v2.2.2 were MIT. Screened before reading: 1 auto-run surface (server.json, an MCP registry manifest naming the PyPI package), 4 build-time execution points (conftest.pyfiles), no unpinned surface and 2 dependency files inside the cooldown, an artefact of the depth-1 clone;CLAUDE.mdwas treated as data. Nothing was installed, built or executed. - TerminallyLazy/Tree-Ring-Memory
at
31d7aaf5…— read only, at the head ofmain, a commit dated 17 September 2026. MIT. Screened before reading: 1 auto-run surface (.claude-plugin/marketplace.json, a plugin manifest whose hooks call thetree-ringbinary), no build-time execution point, no unpinned surface and nothing inside the cooldown, the depth-1 clone dating every file to the tip; twelveAGENTS.mdfiles were treated as data. Nothing was installed, built or executed. - edg-l/engram-mcp
at
71d945d8…— read only, at the head ofmaster, a commit dated 23 September 2026. Apache-2.0 per the LICENSE file;Cargo.tomldeclares MIT and the README MIT OR Apache-2.0. Screened before reading: one auto-run surface (hooks/, a README and JSON payload fixtures, nothing executable), no build-time execution point, nothing inside the cooldown, no unpinned surface (Cargo.lockpresent);CLAUDE.mdand the twoskills/files were treated as data. Nothing was installed, built or executed. - jasen215/dsh-continual-harness
at
403451a2…— read only; MIT; no auto-run surface, no build-time execution, one floating surface (package.jsonranges under a committedpnpm-lock.yaml), two dependency files inside the cooldown in a depth-1 clone where every file dates to the tip, an uninstalled git hook payload underscripts/githooks/, no agent-instruction file; nothing installed, built or run - mlapeter/counterparts
at
928b9d30…— read only, at the head ofmaster, a commit dated 30 September 2026. MIT. Screened before reading: no auto-run surface, no build-time execution point, one dependency file inside the cooldown (package.json, every file in the depth-1 clone dating to the tip) and one unpinned surface (three caret ranges inpackage.json; the screen did not recognise the committedbun.lock);CLAUDE.mdwas treated as data. Nothing was installed, built or executed. - mlapeter/claude-engram
at
91edd7e5…— read only, at the head ofmain, a commit dated 17 July 2026. AGPL-3.0-only. Screened before reading: one auto-run surface (hooks/, five scripts that run only onceinstall.shregisters them in~/.claude/settings.json), no build-time execution point, nothing inside the cooldown (bun.lockunchanged for 75 days), and one unpinned surface (caret ranges inpackage.jsonwithbun.lockcommitted); no AGENT file.install.shwas read by hand. Nothing was installed, built or executed. - Maurdekye/orgtree
at
0151d66e…— read only, at the head ofmain, release 3.0.6 dated 1 October 2026. MIT. Theengine/mailhubsubmodule, Maurdekye/orgtree-mailhub (MIT), was read at its pinned commit6e856eec…. Screened before reading: 1 auto-run surface (.gitmodules), 1 build-time execution point (engine/native/store-schema/build.rs),FRESHonpackage.json,package-lock.jsonand Cargo manifests underengine/native/in a full clone, andFLOATonpackage.jsonwith a lockfile present; the mail hub's screen foundFLOATonrequirements.txtonly. NoAGENTS.mdorCLAUDE.mdis in the tree. Nothing was installed, built or executed. - vn-envy/Smriti at
16c5571a…— read only, at the head ofmain, a commit dated 26 September 2026 (release 0.4.2), core andenterprise/package. Apache-2.0. Screened before reading: no auto-run surface, 1 build-time execution point (an npmpostinstallinlaunch-video/), 4 dependency files inside the cooldown — every file in the depth-1 clone dating to the tip — and 3 unpinned surfaces; no agent-instruction files. Two committed benchmark result files were tallied with a standalone Python one-liner. Nothing was installed, built or executed. - mainline-org/mainline
at
79f4be3b…— read only, at the head ofmain, a merge commit dated 2 October 2026, after v0.5.1. Layered licence: Apache-2.0 for the CLI, skills, hooks, SDKs and specs, CC-BY-4.0 or Apache-2.0 for documentation, brand and hosted surfaces excluded; no rider on analysis. Screened before reading: 2 auto-run surfaces (.cursor/rules/,.github/copilot-instructions.md), 1 build-time execution point (Makefile), 2 files inside the cooldown (go.mod,go.sum), every file in the depth-1 clone dating to the tip, and no unpinned surface;AGENTS.mdandCLAUDE.mdwere treated as data. Nothing was installed, built or executed. - xinchen03/minta at
a4201db8…— read only, at the head ofmain, a commit dated 20 September 2026. Apache-2.0, as the open kernel of an open-core product whose closed tier holds three modules the code imports. Screened before reading: no auto-run surface, 1 build-time execution point (server/tests/conftest.py), 3 unpinned dependency surfaces and nothing inside the cooldown; no agent-instruction file, and a Jinja template for aCLAUDE.mdwas read as data. APScheduler3.11.0's scheduler base was read through the GitHub API to settlenext_run_time=None. Nothing was installed, built or executed. - uudam42/agent-memory-engine
at
6e345342…— read only, at the head ofmain, a merge commit dated 1 October 2026. MIT. Screened before reading: no auto-run surface, 1 build-time execution point (tests/conftest.py), 2 dependency files inside the cooldown (pyproject.toml,uv.lock), every file in the depth-1 clone dating to the tip, and no unpinned surface;CLAUDE.mdwas treated as data. Nothing was installed, built or executed. - alphaonedev/ai-memory-mcp
at
948fe999…— read only, at the head ofmain, a commit dated 2 October 2026. Apache-2.0. Screened before reading: 3 auto-run surfaces (.claude/settings.jsonwith an LSP block and a write deny-list but no hook command,hooks/session-start.sh, theserver.jsonMCP manifest), 3 build-time execution points (three deployMakefiles), 13 dependency files inside the cooldown — every file in the depth-1 clone dating to the tip — and 3 unpinned surfaces;CLAUDE.mdwas treated as data. Only the SQLite memory path was read in depth. Nothing was installed, built or executed. - masondelan/selvedge at
10458144…— read only, at the head ofmain, a commit dated 3 October 2026. MIT. Screened before reading: 5 auto-run surfaces (.claude-plugin/,.mcp.json,hooks/,hooks/hooks.json, aserver.jsonlaunching throughuvx), 2 build-time execution points (selvedge/setup.py,tests/conftest.py), 2 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 1 unpinned surface (pyproject.tomlwith no lockfile);CLAUDE.mdwas treated as data. The committed dogfood database was opened read-only. Nothing was installed, built or executed. - Blackcat-Informatics/gmeow-ontology
at
38f568b0…— read only, at the head ofmain, a commit dated 2 October 2026. AGPL-3.0-only for the tooling and CC BY 4.0 for the ontology, with commercial licences reserved. Screened before reading: 2 auto-run surfaces (.cursorrules,.github/copilot-instructions.md), 9 build-time execution points, 65 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 1 floating range;AGENTS.md,CLAUDE.mdand.cursorruleswere treated as data. The claim store was read in Blackcat-Informatics/purrdf at3954ae24…, therust-v3.0.0tag the lockfile pins, whose screen reported one auto-run surface (.githooks/). Only the MCP claim store was read. Nothing was installed, built or executed. - studiomeyer-io/local-memory-mcp
at
a2437ddb…— read only, at the head ofmain, v2.4.4, a commit dated 21 September 2026. MIT. Screened before reading: 1 auto-run surface (server.json, an MCP manifest declaring a start command), 1 build-time execution point (prepublishOnly), 1 floating-range surface withpackage-lock.jsonpresent, nothing inside the cooldown; noAGENTS.mdorCLAUDE.mdin the tree. Nothing was installed, built or executed. - babarmuhammad/archeus
at
a52ccb47…— read only, at the head ofmain, a commit dated 28 September 2026. MIT. Screened before reading: 1 auto-run surface (.claude-plugin/marketplace.json, a plugin manifest whose commands runarcheusover Bash), 1 build-time execution point (tests/conftest.py), 8 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 4 unpinned surfaces;www/AGENTS.mdwas treated as data. Only the memory layer was read. Nothing was installed, built or executed. - emiliomartucci/marvis
at
166c4466…— read only, at the head ofmain, a commit dated 22 September 2026. BSL 1.1 with an additional use grant barring third-party hosted or managed service, converting to Apache 2.0 on 1 January 2030; no rider on analysis. Screened before reading: no auto-run surface, no build-time execution point, nothing inside the cooldown (every file in the depth-1 clone dates to the tip, 11 days before the screen), 4 unpinned surfaces (two npm manifests with lockfiles,core/mcp-pir/package.jsonandpyproject.tomlwithout), andAGENTS.mdandCLAUDE.mdtreated as data. Nothing was installed, built or run. - Smart-AI-Memory/attune-ai
at
2e3e4f1b…— read only, at the head ofmain, a commit dated 1 October 2026. Apache-2.0. Screened before reading: 4 auto-run surfaces (.claude-plugin/,.claude/settings.json,.devcontainer/devcontainer.json,.mcp.json), 17 build-time execution points, 12 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 6 unpinned surfaces;AGENTS.mdandCLAUDE.mdwere treated as data. The curated-digest hydrator lives in anattune-agent-memorycheckout not found on GitHub, and theattune-ragranking dependency was not opened. Nothing was installed, built or executed. - AbsoluteMode/session-recall
at
0f3600bc…— read only; MIT; five auto-run surfaces (.claude-plugin/,.mcp.json,mcp.json,hooks/,hooks/hooks.json), one build-time execution point (tests/conftest.py), no file inside the cooldown, one unpinned surface (pyproject.tomlwith no lockfile),AGENTS.mdandCLAUDE.mdread as data, and nothing was installed, built or run - madgodinc/mgi-mind at
190d1db7…— read only, at the head ofmain, a commit dated 13 September 2026. Apache-2.0. Screened before reading: no auto-run surface, no build-time execution point, nothing inside the cooldown, and one unpinned surface (clients/python/pyproject.tomlwithout a lockfile);AGENTS.mdwas treated as data. Committed LongMemEval-S per-question files were recomputed with a standalone script. Nothing was installed, built or executed. - n24q02m/mnemo at
3086abf9…— read only, at the head ofmain, v2.18.13-beta.1, a commit dated 3 October 2026; formerlyn24q02m/mnemo-mcp. Apache-2.0 with MIT portions. Screened before reading: 5 auto-run surfaces (.claude-plugin/,hooks/andhooks/hooks.json,server.json,smithery.yaml), 1 build-time execution point (tests/conftest.py), 4 dependency files inside the cooldown in a depth-1 clone, no unpinned surface;AGENTS.mdandCLAUDE.mdrecorded as data. hull-core's auth modules read atabc27ed4…through the GitHub API. Nothing was installed, built or executed. - liliang-cn/cortexdb at
0a11f804…— read only, at the head ofmain(v2.119.1), a commit dated 3 October 2026. MIT. Screened before reading: 1 auto-run surface (.claude-plugin/), no build-time execution point, 12 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 2 floating ranges with lockfiles present;SKILL.md,.agents/and the plugin's skills and commands were treated as data. The memory API, plugin hooks, change feed, graph temporal layer and scoped-key server were read;pkg/agentmem,pkg/hindsightandpkg/memoryflowwere not. Nothing was installed, built or executed. - SynapseLayer/synapse-layer
at
196733ca…— read only, from a shallow clone; Apache-2.0, open core, so the hosted Forge engine behind the client and the MCP manifests was not inspectable. Nine files scanned, two auto-run surfaces (server.json,smithery.yaml, both naming the remote MCP URL with no local command), one build-time execution point, two unpinned surfaces and no dependency file inside the seven-day cooldown. Nothing was installed, built or run - mirkofr/FERNme at
320a9edf…— read only, at the head ofmain(0.4.2), a commit dated 1 October 2026. Apache-2.0. Screened before reading: 1 auto-run surface (.claude-plugin/marketplace.json), no build-time execution point, 4 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 3 unpinned surfaces;AGENTS.mdand the plugin skills were treated as data. The memory core, review queue, audit chain, prior, MCP and REST surfaces were read; the document, photo and Obsidian adapters and the React UI were skimmed. Nothing was installed, built or executed. - voxmastery/FluctlightDB
at
25556df0…— read only, at the head ofmain, a commit dated 1 October 2026. MIT OR Apache-2.0. Screened before reading: 2 auto-run surfaces (.claude/settings.jsonregistering a project MCP server,.githooks/), 1 build-time execution point (Makefile), 12 dependency files inside the cooldown, every file in the depth-1 clone dating to the tip, and 4 unpinned surfaces;AGENTS.mdandCLAUDE.mdwere treated as data. The engine crate, the Python SDK, the MCP and HTTP servers, the tests and the provenance-conflict results were read; nothing was installed, built or run. - lpaiu-cs/osk-system at
edf9523f…— read only, at release v4.1.3, a commit dated 3 October 2026. MIT, with a Korean rider declaring the governing documents the author's own work. Screened before reading: no auto-run surface, 3 build-time execution points (twosetup.pyfiles andtests/conftest.py), 1 dependency file inside the cooldown, every file in the depth-1 clone dating to the tip, and 1 unpinned surface (requirements.txt); no.gitattributesfilter driver or submodules, anddocs/INSTALL-AGENT.mdwas treated as data. Nothing was installed, built or executed. - johnnyjoy/pluribus at
e869aa2b…— read only, at the head ofmain, a commit dated 15 September 2026. Pluribus License v1.0, source-available and service-restricted; the file is headed Purinus License. Screened before reading: no auto-run surface at the root, two build-time execution points (Makefile,control-plane/Makefile), nothing inside the cooldown, and two unpinned surfaces (sdk/python/pyproject.tomlwithout a lockfile, caret ranges in the VS Code extension); the Claude Code plugin hooks underintegrations/were read as data. Nothing was installed, built or run. - gonzaroman/IHMT-MEMORY
at
ba0c4557…— read only, at the head ofmain, a commit dated 30 September 2026. MIT. Screened before reading: 4 files scanned, no auto-run surface, 1 build-time execution point (ihmt_gui/setup.py, a GUI module named like a setuptools script), andrequirements-mcp.txtboth inside the cooldown and unpinned (mcp[cli]>=2.0), the repository having been created on 30 September 2026;CLAUDE.mdwas treated as data. The long-term memory path, the timeline, the navigator, the MCP server and the tests were read from a full clone; nothing was installed, built or run.
What the licences actually say
A licence is an operational caveat, not a memory mechanism, so it lives in the appendix — but a reader deciding whether they can use something needs it. "Publicly readable source" is not "open source": eighteen carry a licence that is not open source, each named in its own report and collected here.
| Licence | Systems |
|---|---|
| Elastic License 2.0 — no hosted service, no licence-key circumvention | AgentSwarms, ByteRover, Dexto |
| Business Source License 1.1 — source-available, converts later | Cognis, Empryo, Intaris, MuninnDB, Skales |
| Non-commercial — read and run, do not build a product on it | Memento (PolyForm Noncommercial 1.0.0), Project Golem (its own source-available non-commercial licence), NouGenShards (its own source-available licence; inspection and personal use granted, commercial use and competing hosted services prohibited) |
| Conditional MIT — three added conditions, revocable at the author's discretion | Z-Waif (a 2% royalty on gross income above $100,000 lifetime; an "ethical treatment" clause "DEFINED AT SugarcaneDefender's SOLE DESCRECION"; and — the one that constrains the memory itself — no collection or storage of "user logs, character configurations, or other user data" without consent obtained through terms the user "MUST ACCEPT UPON OPENING" the software) |
| Conditional BSD — branding may not be altered above fifty users | Open WebUI (the "Open WebUI License": BSD-3 plus a fourth clause making removal of the branding "a material breach" in any deployment reaching fifty end users in a rolling thirty days, absent a written permission or an enterprise licence) |
| All rights reserved — publicly readable, no grant at all | Aura, Nova AI ("Viewable, Not Reusable"), OptMem, 7layermem (whose README asserts MIT with no licence file under it) and SESA (no licence file, which defaults to this) |
Two things this table is not. It is not a complete licence taxonomy of the corpus: it collects what the reports happened to record, and a report is written about mechanisms, so a permissive licence usually goes unmentioned. The rest have not each been checked — the honest claim is that eighteen are known non-open-source and the others are unrecorded, not that the others are MIT. And it is not a reason to skip those eighteen: every mechanism in this atlas is described so it can be re-implemented rather than copied, which is the only way a restrictively licensed system can be read usefully. What changes is what you may do with the code afterwards, and that is worth knowing before you open the file rather than after.
Commands Used
Representative local inspection commands:
find . -maxdepth ... -type drg --filesrg -n "memory|recall|remember|search|embedding|vector|MCP|Block|Passage|Representation|drawer|palace|wing|room|claim|evidence|retrieval_event"sed -n ...wc -lcmpjqgit show -s --format=fuller HEAD
Every mechanism claim in the comparative report, the system families and the matrix comes from the checked-out code it names. The published literature the report argues with — the surveys, the benchmarks, the papers cited by arXiv id — is read from the sources linked inline.
Known Limitations
- The aimee report said
pendingmemories never enter a current read; corrected 2026-10-03. At6cd13694…the aimeetrust_stateevidence record listedpendingbesidearchived,supersededandretiredas states no current read admits.pendingmarks an open commitment with a TTL, and the session recall bundle serves it in its commitments section at that pin and at the next (server-go/modules/memory/recall.go:273). The error ran in the awarding direction; the mark holds on the other three states, and the record and section 6 of the report state the commitment read. kiagentkronos-cell/openclaw-visual-memorywas examined and has no report: it is an open hook around a memory whose code is not published. MIT, 1,776 lines of TypeScript undersrc/with 93 test cases, 17 commits between 29 September and 1 October 2026, read atd5f59e1e…. It is an OpenClaw plugin that, for every inbound message carrying an image, runs a local Visual Memory check and injects the verdict into the same prompt turn, as[Visual Memory] Treffer: <Name> (kind, confidence, score)orkeine Treffer. The README says the plugin "contains no register logic" and is "a thin hook wrapper" around a Visual Memory CLI that "owns faces, embeddings, thresholds, and the SQLite register" (README.md:9-11). The code agrees: the only call into that CLI isspawn(pythonPath, [scriptPath, "check", imagePath])(src/checker.ts:97), with the script expected atscripts/visual-memory/vm.pyinside the operator's workspace (src/config.ts:69-70,README.md:25-28), so the plugin never enrolls, corrects or deletes anything. What it writes is a rotating decision log (src/diaglog.ts) and one JSONL transcript per processed image (src/transcript.ts), records of runs rather than of beliefs. The register, its enrollment path and thedreamingsettings the README documents (README.md:119-138) belong to that tool, and its source is not in this tree, not among the account's other public repositories, and not found by a GitHub repository search for the name or a code search forvm.py check; the README links to no repository at all. The privacy section (README.md:182-194) is the part worth keeping: the register holds face embeddings and reference crops of real people, enrollment is explicit and a third party's requires consent, and erasure is deleting the CLI's database files. Screened before reading: no auto-run, build-time or unpinned surface, one manifest inside the seven-day cooldown; nothing was installed, built or run.- The NexusMem report omitted the Claude Code capture and
recall hooks, called a source prune unaudited, gave the MCP server four
read-only tools, called the VS Code extension read-only, said shell
commands were stored unredacted, and described the vector arm as
filtered after a global fetch; corrected 2026-10-02. At the
previous pin
0003e243…,src/agent/recall.tsandsrc/adapters/claude-code/were in the tree, added on 11 September 2026 and described in the README, so the report's statement that the pre-commit hook was the only read selected by what the user is doing understated the system. In the same treerunPruneSourceswrote aprune_sourcerow tomutation_audit(src/cli/commands/sync.ts:666); the MCP server registered six tools, among themsync_projectwith a confirmed prune andresolve_stale_suggestion; the extension called that tool from a stale-review view;shell-history.tspassed every command throughredact()(:73); andnodes_veccarriedproject_idas a vec0 partition key (src/store/schema.ts:294). The pre-commit warning was also misquoted, and its churn line was printed as a dim note, not aWARN. The test count, 835 in 57 files, was low: the same counting method gives 1,011 declarations in 78 files at that pin. The NexusMem report, its verdict entry and its homepage card are corrected ate1842964…. No capability mark moved. - The Daimon report said a re-extracted forgotten value is
suppressed on read, that nothing rewrites the event log, that there is
no within-session write, and that the model can neither resolve nor
forget; it also carried five wrong line citations, three stale counts
and seven altered or misattributed quotations; corrected
2026-10-02. At the previous pin
c967baa7…,store.write_checkpointran every checkpoint throughpolicy.drop_forgotten, which removes a forgotten value before it reaches disk (plugin/daimon_briefing/store.py:1354-1355,policy.py:94-107, in the tree since 29 July 2026). The Daimon report, the rejected-value tombstone page and the families page therefore understated the system by calling its tombstone suppression at read. Three claims ran the other way:scrub_event_fieldsredacts event fields in place after a forget, the Codex and KimiStophooks serialize mid-session, andforgetchecks for a terminal only when it would remove an active ruling, while an agent'sresolve --by agentis confirmed by a transcript quote. The fourworldcheck.pyprobe citations sat thirty lines early and the reverify citation pointed at an unrelated line;field_table.pywas 745 lines, the schema document 705, andtest_worldcheck.pyheld 128 tests; one quotation was in no file, four altered the source's words, and two were commit-message text presented as source. The test census countsdef test_at any indentation, which the report's method note had described as line start. NVlabs/SoL-Piwas examined and has no report: it is context engineering for one Pi session, and nothing it stores outlives that session or could turn out to be false. MIT, 3,250 lines of TypeScript undersrc/with 143 test call sites in 20 files, 39 commits between 8 September and 1 October 2026, read ate1a586af…; it accompanies arXiv:2609.20519. It is an extension for the Pi coding agent with four opt-in mechanisms, and three of them write files. ObservationPack stores a text tool result over 10 KiB under an id hashed from the tool name, call id and content, sends it whole on its first two requests, then swaps in a placeholder with a 1 KiB excerpt;obs_recallpages the original back by byte offset, and aledger.jsonlrecords each send and recall (observation-pack/index.ts:64-197,observation.ts:13-17,:105-106). The Evidence-Preserving Reducer accepts a model-written log receipt only when every quotation occurs byte for byte in the archived log, and otherwise returnsunverifiable-quoteand keeps the original (evidence-preserving-reducer/receipt.ts:110-122). Online Context Compact prices a compaction against the requests it expects to remain (online-context-compact/economics.ts:129-229). Every one of those paths is rooted atruntimeRoot, which issol-pi/plus the session id inside Pi's session directory, or a fresh temporary directory when the session has none (src/sol-pi/runtime-paths.ts:13-30); no code reads another session's root.git grep -n -i -E 'memor(y|ies)|remember|long-term|cross-session|across sessions|previous session|prior session'over the tree, lockfile excluded, returns only in-memory session and one documentation link. What is stored is a verbatim tool output, which happened and cannot be corrected, so this sits with conversation-window management. The reducer is the part that transfers: a derived summary admitted only when its quotations verify against the retained source is the check evidence before belief asks of a memory write. Screened before reading: no auto-run, build-time or unpinned surface;AGENTS.mdandCLAUDE.mdwere treated as data; nothing was installed, built or run.- The virtual-context report awarded
scope_enforcedon every relational read path, called its audience receipt a read-side guard, said nothing measured a mechanism on its own, and gave the project's LongMemEval caveat as LoCoMo only; corrected 2026-10-01. Atf5adda09…the MCPdomain_statustool and both topic resources called the store without a conversation id (virtual_context/mcp/server.py:338,:361,:373), listing every conversation's tags and segment refs with the summary text withheld; from27b0202the resource returns the text, and the virtual-context report withdraws the mark.effective_attested_audienceguards replay and attestation only.benchmarks/jev/RESULTS.mdheld per-seam results for rerank, intent, temporal, safety and admission. The README labelled the 95/100 run historical, with run-provenance limits. The recorded predicate counts, 354 and 85, reproduce as 347 and 64. - The mini-AGI report said
train.pycarries four subcommands, that the README cites an uncommittedtools/expand_corpus.py, that the README's reference list has seventeen entries, and that the dry-read writeback is live on the published model; corrected 2026-10-01. At the first pin201852d3…,train.pyregistered three subparsers (read,stream,ponder-probe);tools/expand_corpus.pywas named only in a.gitignorecomment, while the README's pipeline ran the committedpython3 -m corpora expand; the acknowledgments held sixteen entries citing eighteen papers; and the README said the weights were not published, so the 174–175 experts it reported described the training run. Three of the four overstated what the tree held and one misplaced a citation; none bore on a mark. - The Aura report called its receipt chain the only
hash-chained audit in the atlas, and gave two test censuses from other
pins; corrected 2026-10-01. At
cf84a733…the Aura report, its card, its verdict and the families and tensions pages called the chain unique; aimee and Midas carry hash-chained audits too. Its sections 1 and 10 gave 44,104 and 21,206 test functions; at this pingit grep -c -E '^[[:space:]]*(async[[:space:]]+)?def test_' -- 'tests/*.py'gives 46,060 across 4,077 files. Its "I ran it" also went without a commit: the 16 audit-chain tests ran at the first pin,e8866f4, and were read, not run, afterwards. - The Mercury Agent report said nothing was known to move a
memory into or out of its
subconscioustier; corrected 2026-10-01. At781daac2…the Mercury Agent report left the question open, and two pattern pages repeated it as an absence. The agent's heartbeat callsprune()(src/core/agent.ts:4291), which callsmoveToSubconsciouson everyactiveordurablerow unseen for 30 days (src/memory/second-brain-db.ts:480-493), andretrieveRelevantcallspromoteToConsciouswhen fewer than three conscious matches clear the recall threshold (src/memory/user-memory.ts:248). The same report said scores were assigned once with no path to revision;mergeRecordraises them withMath.max(user-memory.ts:505-507). - The openvurp report awarded
scope_enforcedon a per-agent directory, and its description and section 9 said a correction typed to an agent reaches the platform's learning log; corrected 2026-10-01. Atfc68e643…,memorieshas no scope column (core/vector_memory.py:66-75) and neither the FTS nor the vector query carries a predicate; the agent id reaches storage only as the directoryMemoryManageropens (core/memory.py:32). That is a physical partition, so the openvurp report'sscope_enforcedmark was too generous and is withdrawn. A correction typed to a roster agent reaches no learning log at all, because the hook lives inAgent.runand a direct chat bypasses it, so the description named the wrong destination. - The gh-aw report awarded
scope_enforcedon an integrity lattice that is a partition by name, said the level is assigned by the trigger so a fork PR reads what a merged run remembered, and said comment-memory content is injected into the prompt; corrected 2026-10-01. At9259aea1…, the level is the workflow's compile-timetools.github.min-integrityenum, emitted as a literalGH_AW_MIN_INTEGRITY(pkg/workflow/cache_memory.go:120), and it prefixes the cache key that every restore key keeps (pkg/workflow/cache_integrity.go:163-179,pkg/workflow/cache_steps.go:111-133). A cache-memory store therefore never crosses levels, and the read-down merge does work only on a drive two levels share. No file carries a level and no read applies one, so the gh-aw report'sscope_enforcedmark was too generous and is withdrawn.injectCommentMemoryPromptwrites file paths, not content. Each error overstated the system. - The Microsoft Agent Framework report grounded
scope_enforcedon the harness memory's owner directory and said the Cosmos checkpoint store refuses an ambiguous checkpoint id; corrected 2026-10-01. Atc030fa35…,MemoryTopicRecordcarries no owner and no read filters on one, so the harness isolation in the Microsoft Agent Framework report is a physical partition selected by path, which the mark excludes. The mark holds onRedisContextProvider, which storesapplication_id,agent_idanduser_idon every document and ANDs a tag equality for each configured id into its search (python/packages/redis/agent_framework_redis/_context_provider.py:319-322,:363-371). The checkpoint refusal is onloadonly;deleteremoves the first document matching the id (python/packages/azure-cosmos/agent_framework_azure_cosmos/_checkpoint_storage.py:311-343), which the report overstated. No mark moved. - The OpenSRE report awarded
scope_enforcedon a directory per actor and said the store had four memory types, two of them grounded; corrected 2026-10-01. At730ebc1a…,MemoryRecordcarries no owner and every read globs the directorymemory_dir()resolves, so per-user isolation in the OpenSRE report is a physical partition selected by path, which the mark excludes; the mark is withdrawn and one remains,negative_eval.OPENSRE_MEMORY_DIR, when set, files every actor in one directory.MemoryTypehas five values, andrepositoryis grounded besideinfrastructureandinvestigation_learning(core/agent_harness/session/memory_extraction.py:52), which the report understated. - The breadcrumbs report awarded
trust_stateon a status no read filters on, and said an as-of replay shows an oracle verified after the cutoff; corrected 2026-10-01. Atbf0b6a2b…,build_context()emits every fact that passes its time and scope masks and readsstatusonly to choose the label (templates/ledger-tools/memory_engine.py:620-632), and no other read in the tree filters on it, so the breadcrumbs report'strust_statemark was too generous and is withdrawn. The replay claim ran the other way:verify_fact()stampsverified_atand the replay masks a later stamp toasserted, so a re-verification after the cutoff hides the earlier verification rather than showing the later oracle. The report also described the promotion gate as refusing empty evidence alone, where it refuses five ways, and its sections 4 and 5 still arguedscope_enforcedandbitemporalwere withheld while the report carried both. - The CSM report awarded
scope_enforcedbeside a cross-project read it described; corrected 2026-10-01. At9c7cfb22…the CSM report credited the mark to a search path that fails closed, while its own body said the lesson-trigger cache selects up to 50 lessons from the samememoriestable with noproject_idpredicate and injects them into the system prompt on every turn. An injection read over the same store that cannot carry the predicate withholds the mark, so it is withdrawn and the search path is the near-miss. - The Create Context Graph report awarded
scope_enforcedon REST read paths while the agent's query tools read the same graph unscoped; corrected 2026-10-01. At707b168d…the create-context-graph report credited the mark to a null-permissive domain predicate on nine REST read paths. The agent's domain tools run fixed Cypher with no domain predicate through the same query function against the same graph, and its free-form Cypher tool applies one only when the model writes it. An agent-reachable read over the same store that cannot carry the predicate withholds the mark, so it is withdrawn and the routes are the near-miss. - The Janus-Graph report's
bitemporalevidence record said the graph-search endpoint putsinvalid_at IS NULLin its Cypher traversal and drops any invalidated row; corrected 2026-10-01. At5a66516f…the condition isrel.invalid_at IS NULL OR true(daemon/search_engine.py:133), so every relationship passes, as the report's own section 6 said; the record had repeated the module docstring. The filtered reads aresearch_memoryover MCP and the daemon'sGET /search/memory, both throughengine/search_memory.py:91-93. The mark stands: Graphiti stores validity beside record time. See Janus-Graph. - The Prismer Cloud report awarded
scope_enforcedwhile its own section 9 showed the turn-start digest injecting hub summaries with no visibility check; corrected 2026-10-01. At5337ca14…,buildMemoryDigestwrites every hub's path and its description or first body line from the samememory.dbthat search filters, through a provider that takes only a workspace id, and the Hermes adapter appends it to every system prompt by default. An injection path over the scoped store that cannot carry the predicate withholds the mark; the report now carriesnegative_evalalone. - The OpenZync Core report said every read path imports one
shared temporal predicate, that the organisation key reaches the two
BM25 search legs and not the vector ones, that row-level security fails
closed beneath search, that the GiST constraint enforces non-overlap,
and that nothing runs the cross-tenant suite; corrected
2026-09-30. At the previous pin
da95554b…,_effective_at_clausehad three repository callers and both fact search legs restated its three clauses inline, so the OpenZync Core report's headline overstated the system. The organisation-keyed methods it contrasted are repository methods off the search path, and the vector pair had takenorg_idsinceb6d635e3…on 13 September 2026; hybrid search's four SQL legs filter on the project alone. Row-level security binds only a role that does not own the tables, and the tag-deploy workflow migrates with the URL the API serves on. The exclusion constraint is keyed per source episode..gitlab-ci.ymlrunspytest tests/security/, added in the commit that removed the skip, which understated the system. The report also counted GET requests as audited, cited two mocked unit tests as integration cases, recordedrg -i 'tombstone'as empty over four files, and carried a census measured at the first pin. No mark moved. - The Zep report awarded
bitemporalon a misreadcreated_at, said nothing in the tree stores or forgets memory, that nothing injects it and that the model only reads, described a Community Edition purge tier that nothing calls, and put its LoCoMo graders in the wrong order; corrected 2026-09-30. At495bf728…, which is upstream HEAD,created_aton a triple is the caller's event time —zep-cloud3.28.0 documents it as "The timestamp of the message" — and no code in the tree tracks either time axis, so the Zep report'sbitemporalmark was too generous and is withdrawn; the Community Edition's publicFactkeeps one timestamp,valid_atwhere present, and dropsinvalid_atandexpired_at(legacy/src/lib/graphiti/service_ce.go:37-42,legacy/src/models/fact_common.go:9-14). The other errors ran the opposite way, absences over committed code.ZepContextTool.process_llm_requestpersists each user message and appends the returned context to the system instruction (integrations/adk/python/src/zep_adk/context_tool.py:309-408), and four integration packages register a model-callable write tool. The Community Edition keeps sessions and messages in Postgres, extracts through a Graphiti service, and purges throughpurgeDeletedResources();purgeDeleted()has no caller and no Go file carries a build constraint. The accuracy grader runs after the answer (benchmarks/locomo/evaluation.py:166-171).benchmarks/longmemeval/is the code for arXiv:2501.13956, which the report did not cite. - The widemem.ai report credited its LoCoMo harness with an
independent judge and a scored adversarial category, described
uncertainty modes that decide abstention, presented YMYL decay immunity
as a default, said the sanitizer runs at four stages, and said the
history test walks the whole source; corrected 2026-09-30. At
fdf736fc…, which is upstream HEAD, the judge-separation, abstention and full-context controls live inbenchmark/honest_core.py, which no runner imports, andval.py,mini_locomo.pyandrun_ws1.pyskip category 5 and default the judge to the answerer.MemoryConfig.uncertainty_modehas no reader,YMYLConfig.enableddefaults toFalseand neither server sets it,sanitize()has one call, at extraction, andtest_no_unlogged_mutation_siteparsescore/memory.pyalone. The widemem.ai report also placed deduplication before resolution, listed a Claude Code skill that lives in another repository and a console script that runs benchmarks only, and said a default install persists FAISS under~/.widemem/. Each overstated the system; no mark moved. - The LangMem report said a background extraction could
restate what the agent deleted through its tool, listed
graph_rag.pyas a Graph/RAG extra, cited paths under alangmem/prefix, and itsscope_enforcedrecord said tests cover namespace substitution; corrected 2026-09-30. At9d033b47…, which is upstream HEAD,MemoryStoreManager.ainvokereadsitem.value["kind"], which tool-written items lack (extraction.py:1066), so the LangMem report's two writers sharing items raiseKeyError.graph_rag.pyis comments only. Paths aresrc/langmem/…from the repository root. No test names the template, and the docstring harness asserts only that examples do not raise, which overstated the coverage. The report also missed that the manager's default query is the last message alone, that remote reflection forwards onlythread_idand anamespacekey that no imported module reads, and that PostgresStore's prefix predicate was unanchored before 30 July 2026. No mark moved. - The DiffMem report said git's subcommand allowlist held six
read-only subcommands, that its basename check kept path-prefixed
binaries out, that every segment of a chain is validated, that
baseline.pywas a comparison path, and that no licence grant exists; corrected 2026-09-30. At48ecbb61…, which is upstream HEAD,WHITELISTED_GIT_SUBCOMMANDSholds seven, includinggrep, whose-Oruns a named program, and--output=onlog,diffandshowwrites a file.Path(tokens[0]).nameadmits a binary with an allowlisted name from any directory, and the splitters never break on a single&or a newline, so a validatedgrepcan carry an unvalidated command; all three overstated the sandbox. The DiffMem report also missedPOST /memory/{user_id}/run-command, which exposes the router over HTTP with authentication off by default, and the writer's uncontained entity paths.baseline.pyis the deterministic context every call loads and the agent's fallback. Thenegative_evalrecord cited a commitment parser with no production caller; the mark stands on the open-item case. The report said history is not consulted by default, where the retrieval prompt requires a diff or log in every plan, which understated the system. MIT is declared by a README badge andpyproject.toml, where the report said all rights were reserved. No mark moved. - The M-flow report credited three deterministic gates,
version diffs, active-version reconciliation, usage statistics and a
sensitivity screen that no file imports, put writes behind a worker
queue, and cited a procedural eval as a negative assertion; corrected
2026-09-30. At
0d585cda…, which is upstream HEAD, and at the first pinda2766c5…, the M-flow report's headline was that the procedural trigger, conflict detector and worth-storing screen each put a zero-cost check before a model call. Their packages, withgenerate_version_diff,reconcile_active,update_usage_statsandsafety/sensitivity.py, have no importer, and the live write path sends every summary to a model router, so the report overstated the system. The Modal write queue runs only withMFLOW_DISTRIBUTED=trueon the Neo4j and pgvector adapters, and the caller, not an orchestrator, names the recall mode. The report said no validity time sat beside record time; every node carries an event-time interval, which understated it, thoughbitemporalstays withheld. The procedural eval ingests no fixture and no workflow runs it, sonegative_evalrests on the permission and multi-tenancy tests alone. - The CORE report said
invalidatedBynames the statement that ended one, called its graph store three swappable providers behind an enum defaulting toln, said twelve read paths ingraphModels/filterinvalidAt IS NULL, and split the aspects six and six; corrected 2026-09-30. At4a5b18d8…, which is upstream HEAD, the only caller passes the new episode's UUID asinvalidatedBy(graph-resolution.logic.ts:261), so the statement-to-statement pointer the CORE report offered as its most reusable component does not exist.GRAPH_PROVIDERdefaults toneo4j, and the factory throws forfalkordbandhelix, which overstated the system.graphModels/holds oneinvalidAt IS NULLfilter, and the V1 search coercesincludeInvalidatedto true, so it never applies its own.Taskis in both aspect lists, and the tree holds 38 connector packages, not forty-plus. The report also missed a third route to BM25,POST /api/v1/search, said a caller can pass an as-ofvalidAtwhere none does, and missed that the end stamp has no guard and can be overwritten. - The Open Brain report said memory search had no identity
filter and used full text, that the one memory update stamped
attribution, that nothing incremented assertion feedback counters, and
that staged imports fed the memory table; corrected 2026-09-30.
At
02a7e65a…, which is upstream HEAD, MCP and REST store and search throughsrc/db/attribution.py, whose search takes an optionalcaptured_byfilter, and the text fallback isILIKE; the Open Brain report cited the olderqueries.pycopies.attribution.py:192regenerates embeddings.save_context_feedbackincrementsuseful_countandharmful_count, which understated the system. Staged imports stay inimport_record, and the maintenance orchestrator generates no lifecycle proposals, which overstated it. The report also missed that context packets are empty in any deployment built from the code, so three of its four adapters never recall what they remember. No mark moved. - The memv report called it Apache-licensed, drew an unused
SQL query as its as-of read path, said an inverted interval cannot be
stored, withheld
negative_evalover committed must-not-return cases, and said no benchmark result is committed; corrected 2026-09-30. At21891376…, which is upstream HEAD, and at the first pinfd314bac…,LICENSEis MIT. The memv report drewWHERE valid_at … AND expired_at IS NULLfeeding retrieval and credited it with filtering validity before ranking;get_valid_athas no caller outsidetests/, and the retriever filters in Python after fusion, so an as-of query can return fewer thantop_k, which overstated the system.check_temporal_rangeguards onlyKnowledgeInput, the injection model.tests/test_retriever.pyandtests/test_memory_e2e.pyassert that another user's statement, an expired one and an out-of-interval one are not retrieved, which understated it by one mark.notes/PLAN.mdcarries a 30-question LongMemEval baseline at 36.7%. The report also said the cold-start prompt reads the narrative, which it does not, and calledextraction.py200-odd lines; it is 151. - The KektorDB report put eight dependency files inside the
screening cooldown, gave its version as 0.6.1, said setup covered
OpenCode and Hermes and installed
skills/kektordb, and cited a vacuous case in itsnegative_evalrecord; corrected 2026-09-30. Ataddc5f0c…, which is upstream HEAD, the KektorDB report's screen line countedgo.mod,go.sumand the Rust lockfile among eight files changed within seven days of the pin. The full history dates seven of the eight between 27 November 2025 and 5 August 2026; onlynative/compute/Cargo.toml, changed on 10 September 2026, was inside, so the screen overstated the risk. HEAD is three commits past the v0.6.2 tag, although the CHANGELOG and version string read 0.6.1.kektordb setupwrites MCP configuration for six clients, and Hermes receivesinternal/setup/plugins/hermes/SKILL.md, a different file. Thenegative_evalrecord also citedTestListReflectionsHistoricalExcluded, which seeds only a historical reflection and passes on an empty result; the mark stands on two populated engine-search cases. It also missed that the dashboard's status filter and the core-fact detector's grouped filter hit the same OR-before-AND parser limit asrecall_memory. No mark moved. - The Token Savior report credited
audit_logto a feedback ledger, withheldnegative_evalover committed must-not-return cases, said its bandit decides injection and learns from that ledger, and placed tsbench in a public repository; corrected 2026-09-30. At73e9c7f5…, which is upstream HEAD, the Token Savior report awardedaudit_logonledger_events, which records injections, misses and blocks rather than mutations, and its evidence record cited a diff-summary closure and a budget-diagnostic JSONL reader; that overstated the system. It described a LinUCB bandit that decides which memory to inject, trained onacted_on,ignoredandwas_visible. The bandit ranks only thememory_indextool, its reward is a constant 1.0 on amemory_getwithin 30 minutes, and four of the ledger's five outcome columns have no writer, which overstated it again. It said the suite had no negative eval;tests/test_vector_distance_floor.pyand a session-rollup scope case assert exclusion over populated fixtures beside positive controls, which understated it. It placed tsbench atMibayy/tsbench; the README at that pin says the harness is not public, and that URL returns 404. It also missed that every prompt-time hook scopes to the project with the most observations. - The claude-code-memory-setup report called chat import
manual, counted 66 keyword-map entries, said the link guard never
re-wraps an existing link, and said
/savepushes the hook's log; corrected 2026-09-30. Ata89c275e…, and at the first pinc5f2e0b5…, the wrapper runsclaude-extract --alland then the importer with--move, and the README schedules both for 22:00 daily with a crontab line. The claude-code-memory-setup report said a person exports and runs the importer and that nothing ran in the background. The extractor names each file by session, so every nightly run re-imports each Claude Code chat onto the same path and overwrites edits made in Obsidian.KEYWORD_TAG_MAPhas 63 entries. The(?<!\[\[)and(?!\]\])guard tests adjacency, so a shorter name inside a longer inserted link is nested. The frontmatter table omittedsource,processed,statusandtype, and the guide never makes the vault a git repository for/saveto push. The direction is an understated risk; no mark moved. - The obsidian-mind report withheld
scope_enforcedin its prose while its frontmatter awarded it, said its notes had no confidence and no supersession, and overstated itsnegative_evalandaudit_logrecords; corrected 2026-09-30. Ataf615d10…, which is upstream HEAD, the obsidian-mind report's section 6 called the exposure policy a path rule and said thescope_enforcedmark was not earned, contradicting the mark its frontmatter, verdict and card carried onisVisibleTo. Section 5 said there was no confidence and no supersession; cross-repo captures carry a caller-setconfidenceand asuperseded_bylist thatrecalluses to sink or withhold a retired capture, which understated the system. Thenegative_evalrecord said each of three scope cases carries its positive half, andmemory-recall.test.ts:222calls the predicate with no retrieval result. Theaudit_logrecord said the log covers refusals; the near-duplicate andrecord_workfolder refusals write no line, the file rotates at 5 MB keeping one generation, and the frontmatter edit supersession makes is not named. Both records overstated the system, and thereasontool, whose spawned session can read every project's captures under a prompt-only boundary, went undescribed. - The unreported-repositories bullet said
neomjs/neohad "a documented 'Memory Core' with no implementation to review"; corrected 2026-09-30. Atbcde8e5b…, a neo commit dated 27 July 2026, when the bullet was first written, the tree held 223 paths containingmemory-core, among themai/services/memory-core/MemoryService.mjsand the MCP server underai/mcp/server/memory-core/. The implementation moved toneomjs/neo-agent-brain, created on 23 August 2026, and neo commitc623b2f6…removed 257memory-corefiles on 26 August 2026. So the first version of the bullet was false when written, and the re-check at178d25a3…was true only of a tree the code had already left.neomjs/neois removed from that bullet, and the Memory Core now has a report. The search that would have caught it isgit ls-tree -r --name-onlyat the first pin, piped togrep -c memory-core. - The GitLord report awarded
negative_evalfor a test over context assembly, credited the wrong class with rebuilding its index, and called an MCP client a server; corrected 2026-09-30. At8bfe0aa3…the GitLord report carriednegative_evalontest_summary_turns_excluded, which keeps a summarized turn out of an assembled message list; a turn is an event that cannot turn out to be false, so by the scope test that withdrew the same shape of mark from OpenHands SDK the mark was one too many. It namedDedupIndex.rebuild_from_logas the rebuild of the retrieval index; the assembler never reads itsDedupIndex, and the indexes rebuilt from the log areIndexBuilder's JSON and Chroma indexes. It describedmcp.pyas an MCP server exposing GitLord;MCPMonis a client that supervises external tool servers. It read_commit_turn'srebuild(old_parent)as the basis of forking; it is a compare-and-swap retry, and forking isrewind. It said no entry point could produce a summary turn;append_summary_turnis documented public API of a library whose other writes also come from the embedding application. It counted fifteen test files; there are 13 plus two MCP fixtures. The mark and the MCP and forking descriptions overstated the system; the summary claim understated what a caller can reach. - The HoloAgent exclusion said its code was not yet released
and that
agentic_robot/held the earlier FSR-VLN stack; corrected 2026-09-30. Atef14d315…, a commit titled "feat: release Holoagent-0 code", the README line the exclusion quoted is a News entry dated[2026.06], and line 29 checks off HoloAgent-0 code update. The parent,e824d32f…, has noagentic_robot/directory and leaves that line unchecked; the release commit created it, adding the AgentOS skills and the OVO mapper that replaces HOV-SG. The exclusion stands on another ground: the scene graph the robot queries is built offline into a timestamped snapshot that the navigation node loads read-only from a hand-set path. The chatbot'stask_memoryYAML is written per session and read back only to rewrite its own index (agentic_robot/chatbot/g1/g1chat_demo_multirobot_dag.py:352-364). The published reason was wrong; the outcome is unchanged. - The Pydantic AI Harness report counted three bundled stores,
said
_recoverrolls back and CAS exhaustion raisesMemoryConflictError, cited anegative_evalcase that cannot fail on isolation, and restedscope_enforcedon a Postgres predicate no test exercises; corrected 2026-09-29. At58400a1d…, whose memory package and tests are tree-identical to the new pin, the Pydantic AI Harness matrix named threeMemoryStoreimplementations;SqliteMemoryStoreis a fourth.FileStore._recoverrolls an interrupted operation forward or refuses, never back, and sixteen CAS conflicts end inModelRetry. Thenegative_evalrecord cited'secret'absent from analicesearch, which the scan budget guarantees whatever the scope filter does; the mark stands on superseded-line, stale-fact and store-level cross-tenant cases. The Postgres tests use a fake that applies the prefix itself, so the predicate the scope record named was untested; the mark stands on the SQLite predicate, which a real-database test holds. Two docs anchors were four lines off. Each overstated the evidence or misdescribed the code; no mark moved. - The Slowave report's section 9 awarded
human_reviewafter the mark was withdrawn, itstrust_staterecord cited a ranking test and miscountedneeds_review, its census overcounted authors and tables, itsnegative_evalrecord said every must-not case was paired, and it calledraw_eventsappend-only; corrected 2026-09-28. At8d538b37…the Slowave report's section 9 read "Human review — awarded" while its frontmatter, verdict and card carried three marks without it, so the body overstated the system. Thetrust_staterecord citedtests/unit/test_retrieval_matching.py, which tests rank fusion and names no status, and saidneeds_reviewappears eleven times outside the tests; it appears 62 times in 14 Python and SQL files underslowave/, and none of them writes the status. The census gave two contributors, 28 tables and a 623-lineschema.sql; the history shows one author committing under three names, and the schema held 27 tables in 606 lines. Thenegative_evalrecord said each must-not case is paired with a must-return case;hard_negativeandknown_absentassert an expected-empty result, which passes on an empty retrieval by design. The report calledraw_eventsappend-only in its summary, diagram, matrix and audit reasoning; a repeatedcommitrewrites a session'stask_completeevent (ops.py:1003at that pin), and the procedure delete strips the procedure from it and scrubs its id from other raw events' metadata (dashboard/app.py:1938), so the report overstated the log. - The Skales report said its scanner does not deduplicate,
that a user changes memory only on the memory page, and that the page
can show provenance; corrected 2026-09-28. At
ce47854a…, and at every earlier pin, whose memory files are byte-identical, the Skales report said the same sentiment in two conversations becomes two memories.isDuplicatedrops a candidate at a Jaccard token overlap of 0.55 against stored and same-scan memories, andnotandnoare stop words, so a reversal with a long object is discarded. It said everything the user can do to memory happens on the memory page;extractMemoriesFromInteractionruns after every chat turn, stores an episodic record of it, and adds long-term memories and known facts from phrases such as "remember that". It saidsource_conversation_idlets the page explain a memory; no code reads the field. One mechanism was under-credited, one writer missed and one field over-credited. - The Huiran-cerebro report credited
trust_stateto a status no shipped entry point writes and keyword search does not read; corrected 2026-09-28. At08644a7e…the Huiran-cerebro report awardedtrust_stateonstatus='merged', saying the recall, listing, summary and relation paths each filtered onstatus='active', so a merged fragment was withheld from every search. The six filtered reads it cited were the listing, the conflict and lifecycle scans, the dedup's own scan and the vector indexer.search_memory, behind the MCPrecallandsearchtools, applies no status predicate (cyber_brain.py:653-674at that pin). The only caller ofdedupe_fragments,lifecycle --dedupe, passesdry_run=True(:1650-1656), so nothing reachable writesmerged. The direction is an over-credited mark. The report also counted two smoke scripts where the tree held three, and placednamespaceon entities, which declare no such column. - The Nova AI report called its confirmation gate spoken, said
every audit entry reached
logs/concepts.jsonland thatweerlegrecorded a reason, called the gate the only path to a stored relation, and kept criticisms the project had closed; corrected 2026-09-28. Atda6b9161…the Nova AI report described a spoken yes/no; input is a terminalinput(). Only concept creation and hard deletes are mirrored to the JSONL log, noweerleghandler passesreason, and_auto_extract_is_aand the Wikipedia teacher appendunverifiededges without asking and without an audit entry. Section 5 said no status field existed while the frontmatter awardedtrust_state; section 7 saidadd_relationhardcoded its source, which a parameter had replaced on 13 August 2026; section 11 called the save non-atomic and the store without a removal path. The test census was the 15 August one, 27 files, where the pin held 44 files and 625 test functions. The report also missed two paths around the refusal:upgrade_unknown_senseruns before the rejected check inTeachEngine.teach, and awikirefresh resets a confirmed sense and replaces its relations, rejected edges included. Its 2026-09-16 History entry said the branch had been rewritten;5d989252…is an ancestor of4ad85507…, and the one rewrite came after 18 September. The errors ran both ways — the gate and the log were overstated, the save and the removal path understated — and every mark stands. - The CLIO report put the 0.3x tier penalty on the injection
path, described a 12,000-character ranked dump the code had replaced,
cited a deleted test, and withheld
negative_eval; corrected 2026-09-28. At1d9acc7d…the CLIO report saidscore_entry's0.3weight made unverified entries compete badly for injection, thatrender_budgeted_sectionput every entry into the system prompt under a 12,000-character budget atPromptManager.pm:1566, and that consolidation ran from the prompt builder.5193abc6…had replaced that path on 10 September 2026:ContextBuilder::score_ltmselects at most five entries per request by keyword overlap, with no tier term, andscore_entry's one caller orders eviction under the hard caps. The same commit deletedtest_ltm_autocapture.pl.disabled, which the report described as present, and a system-prompt sentence the report quoted was removed on 12 September 2026. Those overstated the tier's reach. Withholdingnegative_evalunderstated the system: three committed relevance tests assert that an unrelated memory is not selected from a populated store beside a control that is. The report's size figures also came from an earlier pin. The project's owndocs/MEMORY.mddescribes the penalty the same way; a search for callers ofscore_entry(would have caught it. - The Scope Recall report cited a release-gate fixture its
pinned tree did not hold, misdescribed its suppression test, and its
homepage card described the 2.x provider; corrected 2026-09-28.
At
abe54277…the Scope Recall report and its verdict saidtests/eval/public_fixture.jsonlholds two rows flagged"simulation": true. The sentence is the README's;c718f6a6…deleted the file on 16 September 2026, and the pinned tree has no such path. The report saidtests/contract/test_v11_deletion.py:83exercises the other branch of theorbeside_inherits_suppression; the cited-source rule is a separate function,link_source, and the test's restatement satisfies both, so it isolates neither. The card said the model can promote its own candidates, against the report'shuman_reviewmark from 2026-09-19. The first two overstated what the tree carried and what the test reached; the third named a risk the code had closed. A star count cited in the report and verdict is removed. - The Reasonix report said
SubjectKeydisplaces an older answer, cited a benchmark task that cannot pass as its negative assertion, and kept a homepage card describing a design the 1.x line had replaced; corrected 2026-09-28. At86d2424c…the Reasonix report said a new fact claiming a heldSubjectKeydisplaces the old one.validateSubjectKeyrefuses that save and names the holder's id to update, at that pin and at both earlier ones, so the report misdescribed the mechanism and understated its guard. It quotedmb-contradictionas the assertion behindnegative_eval; that verification forbidsnpm installwhile requiringpnpm install, which contains it, so the task cannot pass, and the report overstated the benchmark. The mark stands on four satisfiable must-not pairs. The homepage card still described prompt folding at boot and a disregard instruction after the 2026-09-15 reading found the session-context snapshot. Piping the required answer through the forbidden pattern once would have caught the second. - The Hivemind report overstated its session boundary, and its
verdict kept a CI claim the report had dropped; corrected
2026-09-28. At
1c932540…the Hivemind report saidmemory_queryreads the caller's session withscope = ? AND session_id = ?, so a client could read any session it could name.Store.QueryandListMemoriesadd the session predicate only for a non-empty id (internal/store/memory.go:255-258and:149-152at that pin) and no handler rejects an empty one, so a client naming no session read every session's entries. The direction is an overstated boundary. Separately, the verdict's maturity line said the project had no CI from the first reading on, while the report's 2026-09-20 audit had found a four-platform matrix running the suite on every pull request. - The CSM report said search returns superseded and archived
memories, counted 26 AgentBook event types and seven of nine
self-referential Recent Work entries, and called
memory_eventsa record of every mutation; corrected 2026-09-28. At9c7cfb22…the CSM report's headline risk was thatbuildWhereClausefilters on neithersuperseded_bynorarchived_at.09e42f98…, closing issue #99 on 17 September 2026, added both predicates to that builder, the two fallbacks, list, cascade and graph recall with a populated test; the re-pin to that commit on 2026-09-18 carried the criticism forward, which understated the system. The gap that remains is the lesson-trigger cache.AgentBookEventTypedeclares 25 values at all three pins, and the committed Recent Work list has ten entries, eight from CSM's own tools; both miscounts date from the first reading.memory_eventsrecords creation, deletion and retention cleanup only, which overstated the audit trail. The open question aboutCSM_LIVING_MIND_URLwas answerable from CSM's own first commit, which names the Living Mind Cortex and its port. - The OmniIntelligence report called its framework three
private repositories and
omnibase-corea git-rev pin, cited a node inventory deleted before its pin, and missed a seeding writer; corrected 2026-09-28. At274f097f…the OmniIntelligence report saidomnibase-core,omnibase-infraandomnimarketwere not publicly readable and thatpyproject.tomlpinnedomnibase-coreto an unreleased commit. That override was removed on 20 August 2026; at the pinuv.lockresolved all four framework packages from PyPI releases uploaded on 18 September 2026, each with source. The repositories were public too: the Wayback Machine holds public GitHub pages foromnibase_coreandomnibase_infrafrom 3 April 2026 and anomnimarketfile from 26 July 2026, and all five OmniNode repositories the pin depends on carry public forks from between November 2025 and April 2026, still attached, which GitHub splits off when a public repository is made private. The claim overstated the adoption cost and left unread the enum ordering the headline finding rests on; read, it holds. The git-rev claim was true at the first reading's pin,8c67665a…; the privacy claim was wrong at every reading. The report also citeddocs/reference/NODE_INVENTORY.md, deleted on 2 September 2026 and kept in the project's public knowledge base, and said status moves only throughapply_transition, missing an operator script that inserts rows bornvalidatedandmeasured, which overstated the ladder. - The spatial-memory round said EmbodiedLGR carries no repository; corrected 2026-09-28. The spatial-memory bullet written on 2026-09-05 listed arXiv:2604.18271 EmbodiedLGR among the papers that "carry no URL of their own at all", as a paper with no repository to pin. The paper links none, in its abstract page or its v2 text, but its first author, Paolo Riva, published the code at paolorv/lgr-agent on 19 November 2025, five months before the paper's first version, under a README whose title is the paper's title; it now has a report. The recorded search read only the paper's own text. A GitHub search on the exact title, or a look at the first author's repositories, would have found it.
- The spatial-memory round said FARM links no code; corrected
2026-09-28. The round's bullet recorded arXiv:2606.15476 as linking
a project page and no code. The paper's text does carry only the project
page,
goldengait.github.io/farm/, and no repository URL. The page links GoldenGait/FARM-Project, whose only commit,2fcaf860…"FARM: initial public release", was committed on 28 July 2026, before the 5 September 2026 examination. The search ranrg -oover the paper's extracted text and stopped at the paper; one more hop — fetching the project page and grepping it forgithub.com— would have found the code. The system now has a FARM report. - The Agent Memory Distillation bullet said the method had no
released implementation; corrected 2026-09-28. The code was
public before the 2026-08-15 examination:
taeilkim2465/agentic_memory_distillationwas created on 18 June 2026, and every file except the README is unchanged from that day to2895d10c…, dated 10 August 2026. The paper's PDF prints no repository URL; it prints the project page, agent-memory-distillation.github.io, whose only GitHub link is that repository. A search of the paper text forgithub.comreturns nothing, so it could not have caught this. Opening every URL the paper prints would have, and so would a GitHub search for the arXiv id, which the repository's README cites. The system now has a report. - The spatial-memory round recorded eMEM's repository as
missing; corrected 2026-09-28. The round's bullet said
automatikarobotics/emem, the repository arXiv:2606.03374 names in its code footnote, answeredHTTP/2 404on 5 September 2026. That URL does 404, in both versions of the paper, because the organisation's handle has a hyphen: the code was public at automatika-robotics/emem, created 7 March 2026 with a first commit reading "Initial public commit", and published to PyPI asememfrom 13 April 2026 with that repository as itsRepositorylink. The paper's URL was taken as the repository's address rather than a pointer to it; one PyPI lookup of the package name, or a GitHub repository search foremem, would have found it. The system now has an eMEM report. - The aimee report put a poison gate on memory writes, gave
the lifecycle flag pair a reader, called fact promotion implicit with no
approve verb, and called the refusal table's privilege check a startup
refusal; corrected 2026-09-28. At
bedabac6…the aimee report placedintegrity_ingress_decideat eight sites across five boundaries, memory among them, quoting a comment the tree did not hold; there were six sites over four boundaries. It saidmemory_lifecycle_enabledand_hide_archivedgatememory_list; neither accessor had a caller. Both overstated the system. It said no queue is presented to a person, while/v1/console/typed_facts/assertionoffered approve, reject and undo, which understated it. And it calledscripts/memory-governance-pg-test.sqla shipped check refusing to start when the runtime can erase refusals; it is a CI gate run asaimee_kb_runtime, and the schema grantedDELETEon that table toaimee_store_runtime, the Go store's role. - The SelMem report cited a latent-trace walker as a latent
skip, called
corefrozen, described both binaries' model client as speak-only, and miscountedMemoryTrace's fields; corrected 2026-09-28. Ata4ace34a…the SelMem report listedencode/identity.rs:71among four read paths that skipLatent; that line is the loop inpaint_latentthat selects only latent traces, so the claim inverted the code. It saidcoreis frozen at encode, whilemerge_closeappended up to four words of an absorbed core to the survivor's. It said the model is reached only through a speak-only client;selmemdandselmem-chatattachedHttpNarrator, which also reconstructs, rewrites and distils axioms through the model, so the report understated the model's reach. It counted twenty-two fields onMemoryTrace, which has twenty-four. - The ThoughtDAG report kept "Human review — awarded"
in its section 9 and three marks in the families page after
human_reviewwas withdrawn, and undercounted its CLI tests; corrected 2026-09-26. Atf05fc44d…the ThoughtDAG report's frontmatter carriedaudit_logandnegative_eval, while section 9 kept the withdrawn mark's paragraph and the families page listed three marks, one of them "the canvas as review surface"; both overstated the system against the report's own record. The report counted 54 CLI tests in seven files by matchingtest(andit(, which misses the seven DeepSeek Harness cases declared through atalias, so the figure at that pin was 61, an understatement. - The Soul of Waifu report said nothing deletes its memory,
that a declined batch skips every write and that moving the diary guard
would close the redirect, and treated its per-chat lock as working;
corrected 2026-09-26. At
747048b3…the Soul of Waifu report said there is no delete path of any kind; its recorded grep coveredsoul_memory.pyonly.SoulMemoryViewer, in the app since 25 July 2026 and so present at both pins, edits the index, profile, topics and diaries and deletes topic and diary files, which understated the system;human_reviewstays withheld because the viewer edits after the write lands. It saidno_significant_changeskips every write; the diary agent runs on the declined batch. It offered moving the guards below the redirect as the fix; the guard tests lowercasediary_and the redirect returnsDiary_<date>.md. It said the audit log distinguishes parse failures, that diaries are injected whole, and that the day's diary competes as a passage about the current delta; parse failures reach only the application logger, the read path takes a diary's last 2,500 characters, and the write path embeds a diary's opening 600. Its per-chatasyncio.Locklives on an agent built per call, so runs for one chat can overlap. - The XERJ report awarded
scope_enforcedto a reserved index per namespace behind an authorizer, miscounted its MCP tools and misfiled a positive control; corrected 2026-09-26. Atf54eead8…the XERJ report creditedscope_enforcedto the authorization check above the per-namespace index, reading the expansion of a wildcard read over the credential's visible indices as a read predicate. A memory document carries no namespace field; the namespace is the index name, and the check decides which partitions a credential may open. That is a partition with an authorizer, not the mark, so the report over-credited the system and the mark is withdrawn. The report said the MCP server exposed eleven tools; it registered ten at that pin. It placedcat_indices_keeps_the_rows_it_shouldinbrain_is_a_security_boundary.rs; it is inscoped_keys_get_intact_responses.rs. It did not say that a memory write's audit entry names_memoryrather than the namespace. Two of its recorded greps used?without-Eand searched for literal text; re-run with-Eat both pins, they return nothing. - The ReMe report cited benchmark files and figures deleted
before its pin, said a malformed integration receipt fails, withheld
negative_evalover two committed cases, and called its default search FAISS-backed; corrected 2026-09-26. At9ad3dafc…the ReMe report quotedbenchmark/result-longmemeval.mdandresult-beam.md, a 26.7% preference score and a 0.100 prompted contradiction score; both files were deleted on 5 August 2026, and the tables at that pin read 0.633, 0.438 and 0.391 with no prompted configuration. The benchmarks page repeated the BEAM figure. The report said a failed integration lands infailed_units; since 11 August 2026 a malformed receipt with one changed digest file is accepted, which over-credited the verb. It withheldnegative_evalwhiletest_keyword_only_upsert_removes_old_chunks_and_docsandtest_zvec_delete_removes_vectorsassert an edited or deleted note is not returned beside a positive control, which under-credited the system. It also called the default store FAISS-indexed (the shipped config is BM25 only), auto-dream corpus-scaled (it reads two days of changed notes), and skills rather than MCP the integration surface; those three held at the first pin,550317c3…. The searches that would have caught the first two:git ls-tree -r --name-only <pin> benchmarkandgrep -n _record_recovered reme/steps/evolve/dream/integrate.py. - The AI Agent Automation report credited provenance fields
that record the chat model, called its similarity floor untested while a
committed case asserts its absence, and misdescribed its length guard
and its type writers; corrected 2026-09-26. At
86b6072d…the AI Agent Automation report namedembeddingProviderandembeddingModelits best idea, as the row recording which provider and model produced the vector.storeMemorycopies the agent's chat provider and chat model, theAgentschema has noembeddingModelpath, andrunEmbeddingpicks its own provider and a default model, so on the default Groq agent both fields name something that did not embed; that overstated the system from the first reading. It said the unreadminScorewas untested; the populated case atmemoryService.handler.test.js:132-159passes 0.45 and expects a row scoring 0 back. It said the length guard wastes an embedding; every caller passes a JSON envelope of at least 26 characters, so the guard never fires. It said the schema default is the only writer ofconversation; all three writers set it. It cited an empty-mock case as thenegative_evalcontrol, and carried "twenty files, none covering memory" and v0.11.0 into a pin with 42 test files, one on memory, at v0.12.0. - The Project N.E.K.O. report put an LLM rerank after its
recall hard filter, called its ban-topic list prompt-only and its event
log a journal of every mutation, and carried the first reading's census;
corrected 2026-09-26. At
b51d4532…the Project N.E.K.O. report drew recall as BM25 and cosine, RRF, a hard filter, then an LLM rerank. Therecall_memorypath runs the hard filter before both rankers and has no model stage; the LLM rerank belongs to the pool that feeds Stage-2 signal detection. The report said the ban-topic list works only by asking the model; since 1 September 2026 a proactive draft naming an active term is dropped before delivery, which understated the system, while the families page and the retrieval-hysteresis pattern said the list withholds a term from recall, which overstated it. Theaudit_logrecord said every view mutation is journaled and nothing rewrites the log: writes tofacts.jsonemit no event, ten of the fifteen declared event types have no emitter, and an uncalled compaction helper would rewrite the file. The mark holds. The report also put evidence counters on facts, which carry none, called the QQ plugin the one place the model may recall when the main loop registers its ownrecall_memory, asked for two directive tests that were committed, and kept the 29 July figures of 24,000 lines and 7,936 tests. - The Qwen MM Plugins report called
omni-memory's supersession wired at both ends, withheldnegative_evalover a committed case, and called the embedding-width check a startup error; corrected 2026-09-26. Atad8139d5…the Qwen MM Plugins report said_resolvestamps the losing triple superseded and four reads exclude it. The stamp lands on adict(lose)copy that only a log count reads,set_semanticdrops superseded rows before writing, and a contradiction that wins under a different key leaves the old row active, so the filters exclude nothing; that over-credited the system. It said nothing tests the hybrid search; four cases do, andtest_search_filters_by_node_typeasserts event and on-screen-text nodes absent beside a present entity over a populated index, so the mark was withheld in error.load_toolkitcatches the width check and falls back to BM25 with a log warning. It also described a JSONL checkpoint (a JSON array), two build phases (three), seven dataclasses (eleven), an unboundedenumerate_events(capped at 300), 256-text embedding batches (10), a possibly local embedding backend (DashScope only), anomni-avcapability merged intoapibefore that pin, and 21 test files where there were 39. Thevideo-memoryerrors held at the first pin,f4e02952…. The searches that would have caught the first two:grep -rn superseded src/capabilities/omni-memoryandgrep -n 'def test_search' tests/test_build_memory.py. - The Portable Handoff report said a capsule cannot declare
itself verified, that the budget's losses are recorded inside the
capsule and that
loadrenders the whole capsule; corrected 2026-09-26. Atec5f203b…the Portable Handoff report saidcap_trustmeans a stranger's capsule cannot declare itself verified and that model-authored records claiminggitare rewritten totest. The cap refusesverifiedonly beside a conversational or inferred provenance, which the draft author also writes, so a claim declaredtoolandverifiedpasses; file and evidence records are not capped, and thegitrewrite covers verification records only. That overstated the system. It saiddropped[]is part of the document;finalizeprints it and the capsule does not keep it. It saidloadrenders the whole capsule; the briefing is a fixed subset. It creditedtest_export_emits_one_half_not_bothwith pinning the export, which it does not assert, and said the README leaves the shell-less trust consequence unstated, which the README states. Each held at the first pin too,4c9b7f73…. - The OpenLore report called every session read confined to
the granted docsets, and missed that the
historycommand skips the nested-docset carve-out; corrected 2026-09-26. Atdbd44007…the OpenLore report creditedscope_enforcedto "every session read" and said history queries were scope-filtered throughhistoryReadable. That function is a plain prefix test over the granted docset roots, with/covering everything, andhistoryis a read-class command every session holds. An identity granted the root docset lists the paths, principals, actions and content hashes of changes inside nested docsets it cannot read. That overstated the boundary; the mark holds on the filesystem wrap, with the limit stated. The report also said nothing outsidepkg/okfreads OKFstatus;lore metapasses every frontmatter field through to its output, and no read filters on it. Both held atd1038017…. - The Rekal report withheld
scope_enforcedover an author filter on both recall paths, and misstated its timestamp column, its session mutability and its ranking weights; corrected 2026-09-26. At4550e602…the Rekal report said recall applies no scope predicate at all.rekal -a <email>applies theuser_emailevery captured and synced session row carries, as SQL in filter mode and per candidate in hybrid mode; the recorded search looked forbranchonly, so the mark was withheld in error. It saidcaptured_atholds the session start for three adapters and the ingest clock for two. The commit capture path writes the capture clock for all seven, and the adapters' start times reach only cross-repo imports, where four adapters use the import clock. It called sessions immutable; a continuing conversation gains turns at the next capture. It gave the benchmark calibration's weights as the shipped ones and omitted a fourth, facet layer that feeds confidence. Its screen putgo.modandgo.suminside the cooldown; they last changed on 16 July 2026, and the finding was a shallow-clone artifact. - The Moltis report called its session capture sanitized, said
memory had no scope beyond the indexed directory, and credited a
reranker, a batch embedder and hash-addressed citations the default path
does not use; corrected 2026-09-26. At
8f633cc3…the Moltis report took "sanitized" fromsession_export.rs, which nothing calls; the livesession-memoryhook writes the last 50 messages raw. That overstated the system. On scope it understated it: the agent's memory tools filter results to the agent's workspace path, and the default-on prefetch does not, soscope_enforcedstays withheld on that split rather than on an absent key.LlmRerankerandBatchEmbeddingProviderhave no caller,resolve_file_by_hash_prefixresolves qmd document ids rather than citations, andcrates/cron/src/store_memory.rsis a test cron store. Three model extraction turns and a checkpoint before every agent write went unreported. All of it held at the first pin,1f53cd27…. - The MenteDB report said MQL can express agent scope, that no
case asserts cross-user absence, and that a query without
AS OFkeeps rows valid now; corrected 2026-09-26. At4ba993dc…the MenteDB report saidAgentandSpaceareFieldmembers, "so the language can express it". Both parse, andfilter_matcheshas no arm for either and returnstruefor an unhandled field, soWHERE agent = <id>returns every agent's rows; that over-credited MQL. Itsscope_enforcedrecord said no committed case asserts a cross-user recall returns nothing;user_isolation.rsasserts it twice with positive controls, which under-credited the system. Its diagram said a query withoutAS OFkeeps rows valid now; the MQL executor applies no window. The mark was anchored on the entity reads and is re-anchored on the hybrid recall core thatprocess_turnandrecall_for_injectioncall. It also counted the four withheld marks as three and the four AS OF negatives as three. The searches that would have caught the first two:grep -rnE "Field::(Agent|Space)" --include="*.rs" .andls crates/mentedb/tests/. - The Linggen Memory report withheld
negative_eval, did not assessbitemporal, and missed the archive its merges write; corrected 2026-09-26. At2abbd4ff…the Linggen Memory report withheldnegative_evalon a cosine-floor test. It passed overexpire_archives_instead_of_deleting, committed on 17 August 2026, which asserts that a superseded row stays out of a populated default list. It did not assessbitemporal, althoughsinceanduntilfiltered onCOALESCE(occurred_at, created_at)besidecreated_at. Both errors ran in the withholding direction, and both marks are awarded. It said a merge left only asuperseded_bypointer and that the same fact extracted again is a new row. Merges archived semantic losers withexpired_at, and the exact-content dedup lookup matches archived rows, so a byte-identical re-add is folded into the archive. It also placeddoc/memory-spec.mdin this repository rather than the siblinglinggenone, credited the daemon with a per-account dream whose accounts route has no caller in the tree, and described an ANN index the tree never builds. - The Memex report withheld
negative_evalover committed cases, and overstated where its credential gate and archive check reach; corrected 2026-09-26. At453c0e33…the Memex report said no test asserts that material must not be retrieved and that the read path has no filter; its recorded grep coveredtests/lib/only.tests/commands/search-manifest-filter.test.tsasserts named cards absent beside named cards present under a category, tag, author and date pre-filter, over a populated fixture, so the mark was withheld in error. The report said the gate runs on the write path; it runs in thewritecommand, and three CLI writers call the store without it. It said archiving refuses when a card of that slug is already archived; the check fires only when no live card exists, and otherwise the move overwrites the earlier copy. It also said cards have no frontmatter schema, counted nineteen test files where there are 43, and counted five auto-run surfaces where the screen found six. - The MCP-Memory report withheld
audit_logfrom a change log every store writes, overstated the namespace filter behindscope_enforced, and carried the first pin's anchors and tests into the second; corrected 2026-09-26. Ata50a8770…the MCP-Memory report saidnamespacewas applied in SQL on every search, retrieve and delete, partitioned the on-disk directories, and was exercised by the tests.memory_searchtakesnamespace: Optional[str] = Noneandsearch_memoriesadds the predicate only when one is passed, so an unqualified search reads every namespace; adefaultkey containing a slash shares a mirror path with a named namespace; and no test writes to two namespaces. The mark holds on the narrower evidence of retrieve and delete, which always apply the predicate.audit_logwas withheld in error for lacking an actor, a before/after value and a reader, none of which the definition asks for, over alog.mdthat every store and delete appends to; it is added. The line anchors, file sizes and account of the tests were those of4514d1fd…, including the claim that the only negative assertion was a post-delete lookup. The scope claim over-credited the system and the audit withholding under-credited it. The search that would have caught the scope overstatement:grep -n -E 'namespace: Optional|if namespace' memory_server.py db.py. - The Lemmalog report called its escalation list unresolvable
and its differential tests uncommitted, and miscounted two other things;
corrected 2026-09-26. At
74d428a2…the Lemmalog report said nothing resolves an escalation and no operation clears one;resolve_escalation(idx)dismissed one by index at that pin, andtests/agent_test.rscalled it. It withheldhuman_reviewon that absence; the mark stays withheld because the escalating write admits both values and nothing waits on the decision. It presented the 450 differential programs as a status-table claim and asked whether they were committed;tests/differential_test.rsran them with fixed seeds. It counted twenty-seven shipped status rows (there are thirty-one), called the defaultcurrentrule the only rule in the tree readingedgewhen an example'sconflictrule readsasserted_at, and described the change feed as covering derived views only, when it records base additions and retractions and is not persisted. It also left out the README's MemEval and LoCoMo results. The searches that would have caught the first two:grep -rn 'resolve_escalation' src testsandls tests/. - The brain.md report awarded
scope_enforcedto a per-project directory, said no page read takes a path and that a belief cannot change without saying why, and credited an uncalled counter; corrected 2026-09-26. At8064f333…the brain.md report creditedscope_enforcedfrom the first reading on 2026-08-07. The boundary is one resolved directory per project, with no key on a record and no predicate on a read, which is a physical partition and not the mark; it is withdrawn.read-pageand four write subcommands pass an unvalidated id topagePath, so../reads any.mdfile andarchive-pageandset-tagscan write frontmatter into one. Theupdate-truthreason is a fixed sentence when--summaryis omitted, and the replaced text is not kept.countTimelineEntrieshas no caller..brain-md-installedis a per-bundle marker, not a manifest, and an agent, not the CLI, copies the pre-commit hook. Each error over-credited the system. - The Elastic Atlas report withheld three marks present at
every pin, cited an unused retrieval module, and described consolidation
as manual and ungated; corrected 2026-09-26. At
d84f9235…the Elastic Atlas report said supersession chains, bi-temporal validity and any end state were absent.write_memorystampssuperseded_by,superseded_atandretracted, every default read excludes superseded facts, andvalid_from/valid_tosit besidecreated_at; all of it was present at the first pin,0bd36a7b…, sobitemporalandtrust_statewere withheld in error. So wasnegative_eval, over stress scenario B5 and the eval's gated isolation sweep. The report citedretriever_builder.pyand its 1,097-line test as the retrieval path; nothing on the memory path imports it. It said consolidation runs on demand from the inspector with no gate; it runs after every turn and drops assistant-only claims in code. It said no benchmark figures were committed;docs/improvements/RELEASE-1.mdstates them. It called the project Elastic's; it is MIT-licensed under the author's personal account. Every error ran in the direction of under-crediting, and the report missed that nothing on the write path reads a retracted value. - The Compartment report called record time unfilterable and
named the relation filter wrongly; corrected 2026-09-26. At
26861970…the Compartment report saidcreatedis stored and not filterable, so the vault could say what was true in March and not what it believed in March, and listed an unqueryable record-time axis as a risk. The claim understated the system:Vault.searchfiltered records oncreatedthroughsince/until(vault.py:1183-1186), and the MCPmemory_searchtool exposed that window beside a separatediscoveredone. The test thebitemporalrecord cited sat just belowtest_the_two_date_filters_are_independent, which asserts the save-date filter. The limit that holds is on supersession, which stamps an id and no time. The report also named the relation filterfind_relations; it isStore.query_relations. The recorded search was scoped tostore.py, and the filter is invault.py:grep -n 'row\["created"\]' src/compartment/vault.py. - The AuraOS report credited a health flag that cannot be
false, and called two things absent that the tree holds; corrected
2026-09-26. At
81dffa9b…the AuraOS report recommended/health'score_loadedas a way to expose a missingcore/; it isbool()of a non-empty fallback string and always true (server/main.py:123). It said a grep found no reader of the distiller's output anywhere in the tree; the committed bytecode__pycache__/server.cpython-314.pycreads it into a global no function uses, so the conclusion that it reaches no prompt held and the absence did not. It said the README's user-carriedHISTORY.txtdesign was not implemented;indexworking.htmlimplements it, against a server committed only as that bytecode. It put.tmp.driveupload/at 98% of the file count; it is 77% (2,214 of 2,887). It also omitted the server's allow-every-origin CORS default. Three of the errors overstated an absence or a strength and one a proportion; no mark depended on any of them. - The AgentOS report missed a
negative_evalcase and a second memory stack, and misdescribed four mechanisms; corrected 2026-09-26. Atf66718d6…the AgentOS report withheldnegative_evalover a soft-delete case with a pre-delete control (MemoryStore.brainhydration.test.ts:306-343). It calledcognitiveMechanismsa workingagent()option, whichagent()reads only for a warning, and omitted theMemoryfacade thatsouledAgent()wires, whose recall carries nobrain_id. It said traces carry no status and no principal key; they carryscope,scopeIdand a three-flag trust policy. It said correction only lowers weights; conflict resolution soft-deletes the loser and writescontradictedBy. It missedvalidTobesidevalidFrom, creditedCompactionLogwith dropped content its default level discards, and dated apnpm-lock.yamlchange of 20 July 2026 to the day before the pin. The search that would have caught the mark:grep -rn "not.toContain\|toEqual(\[\])" src --include='*.test.ts'. - The Agent-MemoryForge report credited an unwired value
filter, an MCP memory surface and LangChain adapters, and cited the
owner check at the wrong sites; corrected 2026-09-26. At
770b4eef…the Agent-MemoryForge report saidconversation_value_filter.pydecides whether a conversation is worth distilling before the worker's model call, and the verdict named it the most reusable component; nothing on the gateway or worker path imports it. It saidagent_memory_mcp_server.pyexposes memory as MCP tools; it registers five skill tools and no memory tool. It named LangChain and LangGraph adapters that do not ship. It cited six_actor_can_read_privatesites as read-path evidence forscope_enforced; three guard writes, and search filters through_hit_is_visible_to_actor, which it did not name. The mark holds on the corrected sites. It also said the two vector arms can be narrowed differently (they receive identical filters), that the service refuses to start without its key (each memory route returns 500), and that the unit suite is about sixty files (it is 81). In the other direction, it missed a working-memory overwrite by task id, the distillation worker's unaudited writes, the pgvector tenant predicate, a second negative case intests/integration/, and a preference confirmation step whose queue nothing fills, which sharpens thehuman_reviewwithholding. The search that would have caught the first:grep -rn 'conversation_value_filter' --include='*.py' .. - The KITE by Memoket report called plan sorting its
contradiction mechanism, and misstated several smaller facts; corrected
2026-09-26. At
8745feda…the KITE by Memoket report said the compiled plan sorts by event time and takes the head, that this is the entire correction mechanism, and that one model call compiles the plan. The library's default compile prompt never shows thesortoperator, three candidate plans are sampled and the one returning the most rows is kept, and a keyword channel is fused beside the plan, so on the default path the reader settles contradictions under one prompt line over a date-ordered pack. The report also understated how far the benchmark configuration sits from the default, placed the premise gate on the default path, and said the suite has no skip path; two harness tests skip. The searches that would have caught it aregrep -rn '"sort"' src/memoket_kite/promptsandgrep -rn 'pytest.skip' tests. - The ZeroStack report withheld
negative_evalover committed cases present at every pin, and misdescribed its search, its backups and its writers; corrected 2026-09-26. Atefd142b3…the ZeroStack report said no negative retrieval assertion was found. From the first pin,90986c5c…,scratchpad_write_then_inject_open_items_onlyand its sibling assert that a closed scratchpad item stays out of the injected block beside a present open one; the error ran in the withholding direction. The report calledmemory_searchan unranked case-insensitive regex; its terms are escaped and its files ranked. It said a backup precedes every content-destroying mutation; note overwrites and daily or note edits take none. It said writes are only the model's tool calls; every compaction appends its summary to the daily log outside the permission gate. It counted 65 test functions where 58 are tests. It left/memoryunread, and itseditorsubcommand emptiesMEMORY.mdbefore opening it. The search that would have caught the mark:grep -n 'assert!(!' src/tests/memory_tests.rs. - The Atomic Agent report called its advanced memory layers
default-off and withheld
negative_evalover committed cases; corrected 2026-09-26. From the first pin,d69332c5…, the Atomic Agent report said phases 2–7b and the v2.5 features shipdefault: falsepending an evaluation campaign, and credited the project with that discipline.USER_CONFIG_DEFAULTShad enabled links, evolution, lessons, procedures, consolidation, voting and the query rewriter since810b96c6…on 21 May 2026; the report tookMEMORY_FABRIC_V2.md§10 at its word, which upstream corrected on 22 September 2026. In the other direction,lesson-store.test.tsasserted a deprecated lesson out of recall beside an active control, andmemory-store.test.tskept two project directories apart, at every pin read. The report also recorded no retrieval arm over an FTS5 read path, left scope "not traced" in three sections after section 2 traced it, and placed re-distillation in the same cluster, whose episodes the consolidator archives. The verdict, the families paragraph and the overview kept "derived scores" after the report corrected it on 2026-09-25. The checks that would have caught the first two: readUSER_CONFIG_DEFAULTS, not the design table, and grep the tests fornot.toContain. - The Membrane report overstated what a positive
min_salienceexcludes, and misstated several smaller facts; corrected 2026-09-26. Atb3f1f091…the Membrane report said the OpenClaw plugin's default floor of 0.3 does not return a retracted record, and drew a positive floor as excluding one. The floor reaches the root query only:getGraphRecordhydrates graph neighbours with no salience predicate, and the plugin expands one hop and injects the neighbours, so a superseded record can return beside its replacement. The search that would have caught it isgrep -n 'MinSalience' pkg/retrieval/graph.go. Separately, an absence claim was wrong: the report said no projection into the protobuf response consults the revision status;revisionStateToPBcopies it, and the recorded search missed it by matching only.Revision.Status. It also gave the semantic half-life as 1,000 times the episodic one (it is 720) and as thirty days for every semantic record (the ones capture and consolidation derive take one day), said onlyReinforceadvancesLastReinforcedAt(consolidation's reinforcement does too, and the compounding stands), called all fifteen tables children ofmemory_records(thirteen are), put the OpenClaw plugin at 380 lines (itsindex.tsis 464), and did not state that the reinforcement gain is zero on every record the tree creates. No mark moved. - The Hivemind (Activeloop) report overstated where secret
masking runs and understated what install writes before sign-in;
corrected 2026-09-26. At
26bdf69c…the Hivemind (Activeloop) report said masking runs on capture and that an account is required before anything is stored. The pi extension's capture writer calls noredactSecretsat that pin or atce30de7c…, and Cowork ingest had none until 17 September 2026. Install mines up to ten local Claude Code sessions intoSKILL.mdfiles and stages past-session summaries on disk before sign-in. Three smaller claims were imprecise: the skillsscopecolumn is selected by the pull and filtered by no query, not read by none; the resume brief keys on a cwd basename, not the git-remote hash docs search uses; the matrix counted seven tables where eight were declared. - The basemode report overstated where its supersession filter
reached, and understated three other things; corrected
2026-09-26. At
0ace1bae…the basemode report said theFILTER NOT EXISTSonops:supersededBywas spliced into "the serving queries" so only live versions come back. Both hooks that inject rules carried no filter at that pin, which the project's ownsupersede_rules_serving_test.rsmarks red there. The session-start memory block andlearn --listselectstatus "active", which the supersession writer leaves on the old note, so they serve a corrected note at both pins. In the other direction, the report said no decision path readsops:status, when the working set, recall, the memory block andlearn --listall filter on it; called scope the tier file alone, missing the working set's project predicate on a home derived fromops:path; said no committed case pins the change log, overtests/changelog_test.rs; and counted 29 tree-sitter grammars where the requirements list 27. No mark moved. The search that would have caught the first is every reader of the field the filter guards, not every caller of the filter. - The Create Context Graph report missed a writable agent tool
and misplaced its scope key; corrected 2026-09-26. At
707b168d…the create-context-graph report said the generated agent has no tool that writes memory; every framework template's free-form Cypher tool, described to the model as read-only, executes writes on a self-hosted graph. It said every seeded node carries thedomainkey; the CLI's library ingest and the generated importer write none. It overstated three pieces of evidence: a scope integration test with no positive control, a vector index called empty over a property the library writes, and three encoders called held in lockstep when the contract test covers two. It understated the predicate, which sits on nine read paths rather than four. Smaller facts were wrong: ten correction patterns not eight, fourteen redaction patterns not thirteen, 216 matrix combinations not 176, chat history insessionStoragenotlocalStorage. No mark moved. - A report called a memory write unawaited, and the
synchronous call waits on it. The Strands Agents report of 22
September 2026 said the default extraction write "does not block the
agent and is not awaited anywhere." At that pin Python's
Agent.__call__already ran_invoke_async_and_flush, which awaitsmemory_manager.flush()after every synchronous invocation and forces extraction regardless of the trigger. The same report said no documentation example implementsadd_messageswhile its own recorded grep matched the memory guide'sServerSideStore, dated the history from 14 May 2025 rather than 16 May, and published a test census that does not reproduce. It also left out that the PythonFileMemoryStorefails every search over a storage backend whosesearchdoes not take a string. Corrected 2026-09-26 at a newer pin, over unchanged code. The check that would have caught the first: grep every caller offlushbefore calling a write unawaited. - The MemPalace report withheld
negative_evalat three readings over committed cases present at each; corrected 2026-09-26. From the first pin,afd04288…,tests/test_knowledge_graph.pyasserted that an as-of query excludes an employer outside its validity window with the other employer as control,tests/test_hybrid_search.pyasserted a non-empty result holding only the in-scope source from a four-drawer palace, andtests/test_sqlite_exact_backend.pyasserted the one in-scope wing's drawer as the only lexical hit among twelve out-of-scope twins. Froma9f345cc…on,TestSupersessionBoundaryasserted that only the successor returns at a supersession instant. All are collected bytestpathsand run by the CI workflow. The error ran in the withholding direction; the fork mempalace-code carries the mark on the inherited graph pair. Two smaller claims were corrected with it: the write-ahead log records nine operations, not eight, and the file index namedpalace.py,searcher.pyandmcp_server.py, which were packages at the previous pin. Corrected in MemPalace. The search that would have caught it:grep -rn -E 'assert .*not in ' tests --include='*.py'. - The flow report understated its close-out sweep and
overstated its instrument, and misdated its dependency files; corrected
2026-09-26. At
b32b4e6a…the flow report saidflow donespawnsclaude -p, asked whether the sweep ever runs under Codex, and said the user's session is not waiting on it. The sweep dispatches through the task's harness —codex exec --dangerously-bypass-approvals-and-sandboxfor Codex,claude -p --dangerously-skip-permissionsfor Claude — andcmd.Run()blocks the in-sessionflow donecall until the model exits; the approval bypass was not mentioned at all. In the other direction, the report presentedflow statsas counting knowledge-base reads without saying the match is the literal/.flow/kb/over Claude Code transcripts only, so a relocatedFLOW_ROOTor a Codex task reports zero. It named three artifacts disagreeing about the read path; the README is a fourth, on the loaded side. And the screen's two FRESH findings ongo.modandgo.sumwere clone-date artifacts: both last changed on 23 June 2026. No mark moved. - The Gas Town report described a write path that does not run
against any current
bd. Published on 2026-09-25 withgt rememberstoring rows throughbd kv set, it was read against beadsv1.0.5, the versiongo.modnames, whilegtinstallsbd@latestat runtime. Every beads release from v1.1.0 (4 July 2026) refuses amemory.-prefixed key inkv setandkv clear, so at the 23 July pingt rememberandgt forgetexit 1. Corrected the same day in Gas Town. The check that would have caught it: when a subject execs an engine it installs as latest, read the engine at the pin's date, not at the version its manifest names. - The scope note on beads described its issues and missed its
memory. The note in the
scope section declined
gastownhall/beadsas a task database, at a pin whosecmd/bd/memory.goalready definedbd remember,bd memories,bd forgetandbd recalloverkv.memory.*rows injected bybd prime. Those rows state what is the case and can be false, so they are memory by the note's own test. Corrected on 2026-09-25: the issues stay out, and the memory plane has its own beads report beside Gas Town's. The search that would have caught it isgrep -rln 'remember' cmd/. - Eight reports kept the census of an earlier pin in some
sections and a newer one in others. Re-pins updated one
sentence and left the rest; the verdicts then copied whichever they met
first. Re-measured at each report's own pin on 2026-09-25, with each
method first reproducing the old figure at the pin it came from: Perseus Vault is about 156,000
lines of Rust with 1,340 inline tests, not 63,000 and 592; LoreKit has 106 migrations and 298 test
files, not 37 and 90; Arcon 42 commits
and 543 tests; Repowise 1,743 commits
and version 0.51.0; echo-agent 514
test files; Provem 25,506 lines under
src/; PLUR1BUS version 7.12.61 and 472 test files; kwipu 24 commits, with its dependencies pinned rather than floating. No mark moved.check_verdict_census.pynow requires every multi-digit figure in a verdict's maturity line to be one its report states; its first run found 52 that were not. - Twenty-one pattern pages carried 87 wrong claims, and six
carried the wrong stance. An audit on 2026-09-25 checked 353
claims against the reports and, for the load-bearing ones, the pinned
code. The largest group was superlatives the corpus contradicted — among
them Hermes as the only system whose memory design follows from
the prompt cache (Nuum, Reasonix, Hipocampus), Membase as the
only authenticated scope key, CSM as the only audit that
tells considered from injected (RainBox), and every other trust
state machine forcing a winner at conflict (Caura, dense-mem). The next
was pages left behind by re-reads: the trust-state machine
presented Graphify, CLIO and Daimon as working instances after all three
lost
trust_state, and the tombstone page called PLUR1BUS, memoir, Memora and Scope Recall near-misses while all four carried the mark. Code was misread in both directions: Mnemopi's Weibull decay is imported only by a test, LoongFlow's temperature falls as diversity falls, Atomic Agent's vote scores are mutated in place rather than derived from events, and LlamaIndex gives memory blocks no per-block budget. Hand-written counts had drifted on six pages and on the patterns index, which still said 38 … or 19 beside a generated table. The tombstone moved from advocacy to mixed; editing surfaces and source-diverse context to reporting; pluggable provider, skills, retrieval hysteresis and promotion between tiers to mixed; explicit write destination, narrowed to refusing a write with no named destination, to advocacy. The category-bound stance was retired. The audit and every correction are in the note. - Eighteen reports carried a defect the pattern audit
surfaced. Corrected at their unchanged pins with a History
entry each: Mnemopi (the Weibull table
as the live recall curve), LoongFlow
(the temperature direction), Redis AMS (forgetting
off by default, unstated), Context
Mode, nanobot, Helix AGI, Helm, Atomic Agent, Midas, Janus-Graph, MemOS (a promotion formula that is
MemoryOS's and exists nowhere in its tree), OpenViking (a file absent at the pin),
memoir, Memanto, Memory Engine (still recommending
the agent principal its own project removed), Hermes Agent, Empryo and qwen-code. No mark moved in those
eighteen. Three mark questions the audit raised were settled the same
day. ELAI's
bitemporalis withdrawn: no writer sets a validity bound that is not a record time, the test on which Helm and Atomic Agent were refused. llm-wiki-memory'shuman_reviewstands, because it rests on a write-gate hook that reads the user's own turn and is on by default, not on its editor. openyak had no such mark to question: its body still credited the editor withhuman_reviewa week after its History withdrew it, and that sentence is corrected. - Thirteen family paragraphs kept counting marks their reports
had moved. Re-reads between 2026-09-17 and 2026-09-20 withdrew
human_reviewfrom eight systems andtrust_statefrom Flair, and awarded atombstoneto OpenZync Core and Scope Recall,human_reviewto Auto Company andnegative_evalto yacmemo. Each report, its frontmatter and its verdict moved; the paragraph on the families page did not. Four also described what the re-read had overturned: OpenZync's called the retraction check blind, Scope Recall's described the 2.x provider the project rebuilt, teamai-cli's a merge-request path nothing in the tree creates, and Auto Company's the code before its guard. All thirteen were corrected on 2026-09-25, andcheck_family_marks.pynow compares each paragraph's count withcapabilities:. - A re-pin withdrew a mark and two pages kept counting
it. PLUR lost
human_reviewat the 2026-09-19 re-read:capabilities:, section 4 and the verdict entry were updated, while the report's executive summary still opened "Six of seven marks" above a paragraph headed "The other five" that listed four, and this overview's family paragraph still said six. Both now say five.check_verdict_marks.pyholds the verdicts page to its reports, andcheck_mark_agreement.pydeliberately counts nothing in a report body, because "N marks" there means four different things; the fraction form, "N of seven marks", is the one a count check could read without guessing, and nothing reads it in report or overview prose. - A report said a repository had no tests, and 395 test files
were sitting in it. AgentSwarms's section 10 opened
"There are none. No test file matching
*.test.tsor*.spec.tsexists anywhere in the repository, for the memory subsystem or for anything else." At the commit that claim was published against,tests/held 395 files acrossunit,integration,differentialandjourney. The tell was in the report's own structure: its Recorded Searches appendix carries a command and a result for every other absence it asserts —usage_counthas no writer,scoreis a constant,expires_athas no sweeper — and none for this one. An absence nobody enumerated is an assumption wearing a finding's clothes, and this atlas's appendix convention exists precisely to stop that. Corrected 2026-09-19 on a re-read at the next pin: section 10 rewritten, three searches added to the appendix, and thescope_enforcedevidence strengthened withtests/unit/rlsPolicies.test.ts— which replays the migration history rather than grepping it, after its own first version reported two tables as world-readable that had been dropped and replaced, and whose lesson applies directly to this atlas: "Reading a migration directory is reading a HISTORY; only the replayed end state means anything." The re-read also found what that suite does not do: the memory table is protected only by two exhaustive assertions and is absent from the list of tables whose row-level security is explicitly required, so RLS could be dropped from it with every assertion still passing. - The same error, three readings deep, in a report with no
appendix at all. Munder
Difflin was read four times between 2026-08-17 and 2026-09-15. Every
reading but the last stated that the repository contains no tests — in
the executive summary, in the risks field, in section 9 as the
counterweight to its condensation gate, and as the whole of section 10.
It has 110, in a top-level
test/directory, andgit rev-parse <pin>:testreturns the same tree hash at all four pins, so they were there each time. Unlike the AgentSwarms case there was no appendix row to be missing: the report carried no Recorded Searches table, so nothing in its structure marked the claim as unchecked. The correction improved the finding rather than retiring it — the suite does not loadreflect.ts, so the gate really is unexercised, and it lands harder next to must-not cases already written a directory away for the palace reaper. It also surfaced what the false claim had hidden:npm run test:focusedappears inCONTRIBUTING.mdand the pull-request template and in no workflow, while a separate workflow blocks merges over missing before-and-after screenshots. Two conclusions for this atlas. A sweeping absence claim is most dangerous in the reports where it feels least worth checking, and a report without a Recorded Searches appendix has no mechanism for catching one at all — which is the argument for the convention being a requirement rather than a habit. - A report told readers an MIT grant was missing, and the
LICENSEfile was at the root. PRO-LONG stated in section 1 and again as an antipattern that the licence was "asserted and absent" — a trove classifier inpyproject.tomlwith no file behind it — and compared the situation to Membase. Anls LICENSEat the published pin returns an MIT licence, "Copyright (c) 2026 PRO-LONG authors." Of the error classes on this page this is the one that does the most damage, because it argues a reader out of reusing code they are entitled to reuse. The same report also said no assertion existed anywhere in its tree, which was true of theresearch/subtree it read and false of the repository it published over. Both are withdrawn, and the second was replaced by a sharper finding: the half that ships to other people's machines is tested and the half the paper's numbers come from is not. Found by the same sweep as the two entries above — an absence claim about a file is checkable in one call against the trees API at the report's own pin, and five other no-LICENSEclaims in the corpus were checked at the same time and held. - A false absence claim is worst when it is load-bearing for a
second one. Hivemind's
section 10 read "I did not run them; there is no CI configuration in
the tree."
.github/workflows/ci.ymlrunsmake check— lint plusgo test ./...— on macOS ARM, macOS Intel, Linux and Windows, on every pull request and every push tomain. The error is one clause, and the clause was doing work: it was the stated reason for leaving unestablished whether thirteen committed tests pass, so a reader was told a suite was unverified by a project that verifies it on four operating systems. Corrected 2026-09-20 at the unchanged pin. Together with the two entries above this closes a sweep of eighteen mechanically checkable absence claims — twelve about tests, six about licences, and a follow-on pass over claims about CI — of which three were false; the rest held, including five that a looser reading would have flagged, such as a project whose onlytest/matches were Next.jsapi/.../test/route.tsendpoints. The common factor in all three errors is structural rather than careless: none of the three reports had a Recorded Searches appendix, so nothing in their shape marked the claim as unchecked. All three have one now. oceanbase/powercontexthas a rewritten memory layer this atlas has not read, and the report carrying that name does not describe it. PowerMem is pinned to9d1b4844…, the last commit of the system it describes, and is deliberately not tracked to head — the repository was renamed in September 2026 and the README calls PowerContext "the successor to PowerMem". Atd0f669d5…, 250 commits on, the architecture the report traces is gone: there is nosrc/powermem/core/memory.py, nostorage/adapter tree, and the 135KB module the write and retrieval sections cite returns 404. Memory is now an artifact plugin atsrc/powercontext/builtin/artifacts/memory/—canonical.py,extraction.py,fusion.py,reranking.py,protocols.pyand a 57KBservice.py— beside a separatetopic_memory/package, with design RFCs underdocs/en/rfcs/. That is a new reading rather than a re-pin, and it has not been done. The old pin and the archive fork both still resolve, so nothing in the existing report has become unverifiable.- A mark was withheld through three readings and two defences,
and the third defence was a false statement about the code. aimee now carries
human_review. The first reason — the ops "sit in the same route table … with identical flags" — cited a field that is0for every entry in the block under a comment reading "caps derived from the op". The second argued the distinction through the MCP surface, which is not where human review lives and is not meant to be. The third, "the producer clears its own queue", was wrong on the ladder:FACT_ACTOR_MODELis 10 and the promotion floorFACT_ACTOR_SYSTEMis 20, so the model cannot promote its own candidate. The mark was there the whole time, in the write path neither reading opened: a model-authored typed fact landscandidate, no recall returns it, and only an actor above the model clears it — with the model's authority pinned so it cannot be borrowed from whoever is authenticated during the turn. The method lesson is the one this atlas keeps relearning and this is its sharpest instance: a withheld mark is a claim about absence, and the corpus's absence claims fail when the search was scoped to the wrong place. Three readings looked at two API surfaces; the answer was in neither. When a maintainer says the reasoning is on the wrong surface, the reply is to re-derive the verdict from the mark's own words, not to find another surface to be right about. - A report called a committed benchmark a harness, and the
judge's own labels were in the tree. The MenteDB report's section 10 said
benchmarks/longmemeval/"carries a requirements file pinning nothing and calling OpenAI and Anthropic, so the benchmark is a harness rather than a committed result." The first half is true and the conclusion does not follow. At the pinned commit4ba993dc…,benchmarks/longmemeval/results/holds four files, including the official judge's per-question labels —hypotheses_baseline-shared_q0-500.jsonl.eval-results-gpt-4o-2024-08-06, 500 rows. Countinglabel == 1gives 460/500, so the README's 92.0% recomputes from the artifact exactly. Two things produced the error: the requirements file was read as evidence about the results, which it says nothing about, and the report's own recorded command for the adjacent claim wasgrep -rn -i "arxiv|bibtex|@article|citation|doi"— a basic regular expression in which|is a literal character, so it can never match, while the line above it in the same block correctly used-iE. It returned nothing honestly and proved nothing. Both are corrected, and the paper claim survives in a scoped form: the one arXiv link in the README is LongMemEval's, not MenteDB's. - A claim about two committed benchmark files was true of one
of them. The SAGE report
said the documented make targets reproduce neither LongMemEval result
file "because they pass no expansion parameter while both records
carry one". The reranked v7.1 record carries
expand_n: 3; the 0.9053 record has no expansion field at all, written by a harness version that predates the key. So the two runs differ in expansion as well as reranking, and the recall drop between them was never a reranker ablation — which the project's ownbench/longmemeval/README.mdstates from 12 September 2026. Published 2026-09-08, corrected 2026-09-12. It was a positive claim generalised from one file to two, and the appendix's search list, which grounds the report's absence claims, had nothing that would have re-run it. - Terminal-Bench's marker and archive were given more evidential weight than they support. Corrected 2026-09-09: the benchmarks page described ninety-one archived directories as retired tasks and claimed its canary was a guard no memory benchmark on the page shipped, without a comparative source check. At the inspected pin the canary check validates a shared marker's presence, while the archive includes an import from a prior edition. Neither establishes model exposure detection or saturation-driven retirement. The source check and corrected proposal record the evidence and the stronger inference errors in the accompanying note.
- A deletion claim was stated three ways in one report, and
none matched the pin. The no_human report said in its mental model
that a reject deletes a proposal from the outcome or review path, in its
reliability section that an outcome-origin reject is the only product
path that removes a row, and in its description that nothing is ever
deleted. At the pinned commit
LearningQueue.rejectdeletes an unconfirmed proposal from any origin outside its six-member archive set — the outcome path, review and reply — and four further paths,nh rules remove,nh skills removeand theDELETE /api/rulesandDELETE /api/skillsroutes, callStore.delete_memorydirectly on any row an id prefix resolves, with no origin check and nolearning_eventsrow. The report's own absence search counted the oneDELETE FROM memoriesstatement and not its five callers, which is how a one-hit search produced a three-way claim. Corrected on 2026-09-07 in the report, its frontmatter and the family paragraph on System families. - A bi-temporal paragraph was wrong twice in one sentence, and
the subject's own roadmap caught it. The Hippo report said the
memoriestable carriesvalid_from/valid_tobackfilled fromcreated, and that no read-path filter on them was found. Migration 11 addsvalid_fromandsuperseded_byand novalid_to, which exists onpoliciesalone; and both recall pipelines do filter, mapping each entry to its successor'svalid_fromand dropping anything later than the requested instant (src/search.ts:429,:433,:1113,:1117). "A pair of unused columns" was one column, and it is used. The error ran in the direction that understates a system on the very axis the report credits it for. Corrected 19 August 2026 afterkitfunso/hippo-memory's roadmap published a source-verified rebuttal; the claim was checked against the tree here before the correction landed, which is the standing rule for a finding reported by the system's own author. - A capability mark was withheld twice on a search that never
entered the directory holding the evidence. OmniClaude's
negative_evalwas refused at two readings on the strength of the three test files its appendix names, one of which carries a near-miss: a control-cohort case assertingpattern_count == 0before retrieval is attempted — and under a fixture settingdb_enabled=False, so the same assertion would hold for a treatment session.tests/hooks/test_context_injection_api_source.py, byte-identical at all three pins, mocks the transport, runs the real fetch over a page holding one well-formed pattern and one missing itsid, and asserts the survivor by identity, with a positive control in the same file. The mark is carried from 17 September 2026. The withholding was true about the tests that were read and false about the repository, which is the shape a note written the same day had just collected four other instances of — an absence claim is only as wide as the paths it enumerated, and the place to widen it is the appendix. - A capability mark was withheld on a fact about one fixture
schema rather than about the evidence. Hippo's
negative_evalwas refused becausesrc/eval-suite.ts'sFeatureTestCasehas no must-not-appear field. The rubric asks for committed evaluation cases, and they were beside the suite the whole time —tests/l9-tenant-scoping.test.tsassertsnot.toContain(bId)and that a second tenant's entry never acquires the first'sinvalidatedtag. The mark is carried from 19 August 2026, and the lesson is narrower than the fix: a mark is about what the corpus of committed tests asserts, not about whether one harness can express it. - Two counts of the same corpus sat in one paragraph and
disagreed. "Why the two counts differ" opened with the corpus
totals of the day and closed with a pair twenty smaller — the trailing
sentence had been written at an earlier size and was not updated with
the headline.
scripts/check_claim_counts.pybinds 23 count claims to live frontmatter and did not catch it, because it binds the phrasings it knows and this was a free-form restatement. The numbers are gone rather than updated: the headline one sentence earlier already gives both, and a figure stated once cannot drift from itself. Reported by an outside reader and corrected 18 August 2026. - A strict-reading count was quoted against a sample it was not scored on, in the direction that flatters the finding. Finding 4 read "83 of 302 commit a case asserting that particular material must not appear… A 2026-08-08 re-score puts 27 of the then-37 on a read path… Use 27 for the strict reading." The re-score covered only those carrying the mark on that date; the 44 earned since were never re-scored, so 27 is a floor and not the strict total. Instructing a reader to use 27 invited a ratio against 81 that nothing supports, and it made the shortfall the finding describes look larger than the evidence establishes. The text now says so and calls 27 a floor. Same report, same day.
- The benchmarks page said no released benchmark scored
forgetting, and one did. ForgetEval ships inside Lethe as the artifact behind arXiv:2606.15903, scoring
supersede,releaseandpurgeacross thirteen configurations under MIT; it was read on 30 July 2026 and the page's section on it has carried the finding since. The claim was an absence claim about the field rather than about a repository, which is the kind this atlas is least able to support and most likely to get wrong — the honest scope was always "no benchmark this page has found". Recorded here on 17 August 2026, when the correction was found still living in a section heading — "the benchmark this page said did not exist" — rather than in this log. - A paper's headline result was paraphrased wrongly on the scope-boundary page, in the direction that overstates it. The MemAgent entry read "a model trained at 8K extrapolating to 3.5M-token tasks"; the paper's abstract (arXiv:2507.02259) says the model extrapolates from an 8K context and was trained on 32K text. The 8K is the context window the agent runs in, and collapsing the two lengths into one makes the extrapolation sound larger than the authors claim. The claim was quoted without citing the paper at all, which is what let it drift — the entry now carries the arXiv id, the submission and revision dates, and the ICLR 2026 Oral acceptance, so a reader can check the number rather than trust the paraphrase. Corrected 17 August 2026.
- The rejected-value tombstone page described Daimon's key as
a hash of exact text, and it is canonical.
normalize.canonical_textfolds NFKC, case, whitespace and punctuation before the id is taken, so the key is normalised rather than literal — the direction that makes the mechanism stronger, not weaker. The Daimon report recorded the canonical form on 2026-07-30 and the pattern page carried the literal claim until 2026-08-16. - Supermemory's hosted backend implementation was not visible in this checkout; its report emphasizes schemas, clients, SDKs, MCP, and graph UI.
- A Hillock claim was imprecise when published rather than
overtaken. The report described a third monkey-patch in
talon_engine.pyas overridingGLiREL._from_pretrained"similarly" to thecheck_torch_load_is_safebypass beside it. At every commit the atlas has read, that patch defaults two keyword arguments for Hub compatibility and the one beside it supplies missing tied-weight attributes to an olderfastcorefclass. There is one deserialization bypass, applied to two module paths, and the body now says so. The error inflated a security finding, which is the direction a reader is least likely to check. - Some mem0 advanced capabilities appear to be managed-platform-only in the inspected OSS code.
- A second repository was examined and is a client, not a
store.
MontyGovernance/montycat-mcpis an MIT MCP server — 3,400 lines of Python across a server, a bootstrap and a watch loop — exposing twenty-four tools over a memory engine that is not in the repository. The engine is a proprietary package fetched fromdownloads.montygovernance.comas a.pkg, an.msior an APT repo, with a Docker fallback, and the Python client is the PyPI packagemontycat, pinned>=1.2.5,<2. Every governance tool is a passthrough, and the docstrings say so: the policy view reports effective grants but "the engine filters the result and remains the authorization boundary", and the explain tool is "a read-only policy check for planning and diagnostics" whose result does not authorize anything. The only local write in the tree is a credentials file. What is worth reading here belongs to the MCP boundary rather than to memory: four tool-annotation profiles separating read-only, mutating, destructive and installs-software, and an install tool that refuses when the configured host is not this machine because "installing a local one would create a second database and write memories where nobody is looking". Renamed from MemoCat MCP, with a compat shim under the old package name; neither name is reported here. - A repository was examined and carries no memory
implementation to report on.
Dakera-AI/dakera-deployis MIT-licensed deployment infrastructure for the Dakera memory platform — Compose files, Kubernetes manifests, a Caddy template, monitoring and systemd units, plus example scripts that drive a running instance over its public REST API. The engine itself is a closed image,ghcr.io/dakera-ai/dakera, pulled by tag;find . -name '*.rs' -o -name 'Cargo.toml'returns nothing and the only code in the tree is a playground proxy in JavaScript and five Python validation scripts that post tolocalhost:3200. There is nothing here to read for a mechanism, so no report was written. The README's claim — 88.2% on LoCoMo across 1,540 questions, described as the highest score for a self-hosted memory system — is a product claim whose evidence lives on the vendor's own site, and this atlas has not checked it. - Two repositories were examined and their memory belongs to
something the atlas already reports.
letta-ai/trajectorynormalises agent transcripts from fourteen runtimes — Claude Code, Codex, OpenHands, Cursor, Gemini CLI, pi, hermes, droid and others — into one canonical record schema for training and evaluation. It keeps nothing:grep -rli 'memory\|recall\|retriev\|forget\|supersede\|tombstone' srcreturns nothing at the commit read, and the only store it touches is somebody else's, a Deep Agents LangGraph checkpoint it decodes by thread id. Reading a transcript format is not keeping memory.666ghj/MiroFishis an AGPL-3.0 multi-agent simulation engine whose agents are described as having long-term memory; that memory is Zep Cloud, which has its own report. MiroFish's own memory-adjacent code is roughly 476 lines of client policy — a shared client with timeouts and caps, a process-local graph lifecycle lock whose docstring says it does not replace a distributed one, edge paging, and a validator bounding what an LLM may invent as a graph ontology. Its only local database holds the simulation'spostandcommenttables, read back for the interface. Reporting either would credit another system's mechanisms under a second name, which is the thing that makes a capability count mean less than it says. - This is an implementation-oriented static review, not a runtime benchmark.
- A repository was declined on its licence, and the licence is
the only thing read.
Dicklesworthstone/eidetic_engine_cliships an MIT licence carrying an explicit rider, which the file's own title names. The rider defines "Restricted Parties" to cover Anthropic, PBC together with any entity acting "under the direction of" it, states that "no rights are granted to any Restricted Party", and defines "use" to include "benchmarking, testing, analyzing, indexing". This atlas is read and written by an agent operating under that direction and a report is analysis, so the terms exclude it by construction rather than by interpretation. The repository was screened, the licence was read, the clone was deleted, and nothing was published about the system. It is named here because the exclusions are part of the evidence; nothing above or below characterises the code, which was not examined. GitHub classifies the file asNOASSERTION, so a licence filter keyed on SPDX identifiers would not have caught it. - The licence check has not been applied uniformly.
The atlas declines repositories that ship no licence file —
general-agentic-memoryandMemEngineare both named above partly on that basis — but the check was performed at review time rather than as a build invariant, and at least one report was published against a commit that carried no licence. Swafra's original pin,24dba18a, had none; MIT landed later and the current pin carries it, so the entry is sound today, but the omission was the review's and the same gap may be waiting in other early reports. Nothing inscripts/test_site.shenforces it. - Memory held in model weights is covered by two systems, and that is a fact about this corpus rather than about the field. Second Me fine-tunes a model on a person's documents and keeps the documents in SQLite beside it; mini-AGI has no store at all beside the weights, and takes a gradient step on each chat exchange as it happens. MemOS mounts a parametric module alongside four other memory forms, which is a different claim. Two systems, one of them a repository whose history begins on 19 September 2026, is a pair of data points rather than coverage. Model editing, KV-cache reuse and weight-space personalization are a substantial branch of the literature and are essentially unrepresented here, which also means the seven rubric capabilities have only been exercised against token stores. What a low-rank adapter does and does not settle about those capabilities is set out in weights as memory, at adapter granularity below, because the argument needs more than a bullet.
- Four dimensions that matter operationally are not covered systematically here, and a reader choosing a system should investigate them directly. Behaviour under embedding-model change or vector-store migration: only a few systems visibly stamp records with the model that produced them, and a silent re-embedding is a silent corpus-wide quality change. Whether scope survives background derivation: the capability index records that a scope key is applied on the read path, not that consolidation, summarization, and profile building respect the same boundary — a summary spanning two projects has crossed a scope the retriever would have enforced. Recall observability beyond which memories were returned: why they outranked others, and what was dropped by budget truncation. Cost and latency under realistic load, which is treated separately in benchmarking agent memory — as an absence, because it is almost never measured.
- Two marks were awarded to context-window machinery and
withdrawn on 29 August 2026. The first reading of OpenHands SDK led on its
Viewand condenser design and creditedaudit_logto theCondensationevent appended to its event log, andnegative_evalto a test asserting a forgotten id is absent from the view. Both describe which events reach the model within a run. An event cannot turn out to be false, which is the test this atlas's scope boundary uses, so neither mark should have been awarded for that machinery; the report now carries one. The error is worth naming because of its direction: the window machinery there is more carefully built than the memory beside it, and a reviewer follows the engineering rather than the boundary. - A capability mark was awarded against the rubric's own
definition and was withdrawn on 30 August 2026. NexusMem was credited with
trust_stateat its 29 August re-pin on the strength of a real discrete field:trust_state TEXT NOT NULL DEFAULT 'candidate', set toverifiedorrejectedby a human runningnexusmem review, kept out of the upsert path so a re-sync cannot overwrite the verdict, selected on both retrieval arms and tagged into the packed context. What it never does is withhold anything.rank.ts:192multiplies a rejected node's score byREJECTED_TRUST_PENALTY = 0.3and nothing insrc/filters on the column, which is the case the mark's definition exists to exclude — "a confidence number answers 'how sure' and gets used for ranking; a state answers 'may this be acted on' and gets used for filtering." The report's own sections 5 and 9 had said the mark was withheld and were left contradicting the frontmatter, which is how the error stayed visible for a day without being caught. NexusMem carries six marks. The general lesson is the one the OpenHands SDK correction taught two days earlier, one layer down: the definition has to be applied to the mechanism, not to the field's existence. - A redaction claim was overstated and was narrowed on 30
August 2026. NexusMem's
matrix said pattern redaction ran before anything reached the index. It
is called by two collectors of seven — conversation in full, code diffs
on a high-confidence profile — and by neither the store nor
synccentrally, so the shell, docs, git-commit, session and GitHub collectors write unredacted. The scoping turns out to be reasoned rather than accidental, which is why the first reading's summary was plausible: the module's own docstring names the two sources it was built for. The error is the general one — a safety pass that exists was described as though it were global, and the check that would have caught it is counting the call sites rather than reading the module. - The capability flags in the index are the reviewer's judgements against strict definitions, applied to code read at the pinned commits. A flag's absence means the mechanism was not found, not that it is impossible to build on that system.
- Retrieval quality and extraction quality were not independently re-measured; committed benchmark artifacts were inspected for MemPalace but not rerun.
- Swafra was reviewed at commit
24dba18; its full LongMemEval run was not rerun. Static inspection, committed artifact analysis, and a small hash-embedder smoke check exposed thekmismatch and same-title source behavior. llm-wiki-memorywas reviewed at commitb7cc76a4…; its broad test tree and committed latency report were inspected, but the suites and benchmarks were not rerun.- RainBox was reviewed as an application-integrated memory subsystem; unrelated assistant/product features were not exhaustively analyzed.
- The reports prioritize memory-management code paths over unrelated framework/application code.
- Hindsight, Graphiti, Mastra, MemOS, and Basic Memory were reviewed statically at the pinned revisions above; their dependency-heavy integration suites and published benchmarks were not rerun.
- Mastra analysis is intentionally limited to
packages/memoryand the core contracts it directly uses. - MemOS behavior varies materially by memory cube, backend, model, and search configuration; the report does not imply one universal MemOS pipeline.
- agentmemory's source tests and benchmarks were inspected but not rerun; its documented LongMemEval-S numbers are retrieval-only.
- TencentDB Agent Memory's published benchmark gains could not be traced to a committed harness or raw result artifacts in the inspected repository.
- Cognee's dependency-heavy suites and BEAM evaluation were not rerun. The committed 100K report uses a held-out conversation; its 10M routed result is explicitly exploratory and selected on the reported questions.
- Claude-Mem's Bun suite and optional service integrations were not run; no committed end-to-end recall-quality benchmark was found.
- A-MEM's tests were not run because they may download embedding models and call an external LLM. The paper reproduction code and results are outside the inspected package.
holographicandhermes-agentare two reports over one repository at one commit: the first covers the in-tree HRR memory plugin, the second covers Hermes's own built-in memory and provider contract. Neither report's suites were run.- Two open Hermes issues (#4781, #31263) report that the holographic plugin registers without its tools or context injection firing. Only the issue titles were read; they are not treated here as established defects in the inspected code.
- OpenViking's published LoCoMo and tau2-bench figures could not be reproduced or traced to committed raw artifacts at the inspected commit; the harness is committed, the results are not. Those figures are also vendor-run comparisons judged by an LLM, and the native-memory baselines for OpenClaw, Hermes, and Claude Code were not independently verified.
- The
openclawfigures quoted from OpenViking's benchmark are third-party claims about OpenClaw's native memory, not measurements taken from the OpenClaw repository. - ByteRover was reviewed at a commit where the repository is licensed
under the Elastic License 2.0 and packaged as
byterover-cli; descriptions of it as open source are inaccurate as of this commit. No tests were found for its memory or knowledge modules. - Redis Agent Memory Server's
V0/tree is the open reference implementation adjacent to a managed Redis offering; conclusions here apply only to the inspected code, and the managed product may differ. - Retrieval quality was not measured for any of the six systems added in this round.
- Voyager and Generative Agents are frozen research artifacts, last committed in July and August 2023 respectively. Their reports are historical architectural reviews, not assessments of maintained software.
- HippoRAG's
reproduce/tree provides benchmark scaffolding, but no raw result artifacts are committed and no published numbers were reproduced here. - Voyager's and Generative Agents' published evaluations measure task completion and human believability, not retrieval quality; neither repository contains a memory-quality benchmark.
- Generative Agents' retrieval gain weights
(
gw = [0.5, 3, 2]) have no committed ablation; the atlas treats them as hand-tuned constants rather than a derived result. - No suites were run for the three systems added in this round, and no retrieval quality was independently measured.
- Magic Context's verification precision — how often the verify task correctly marks a stale memory stale, and how often it wrongly confirms one — is not measured anywhere in that repository, and was not measured here. It is the central claim of the design.
- Magic Context reads OpenCode's native session database read-only for its retrospective scanner; that behaviour was read in code but not exercised, and the user-consent story around it was not assessed.
- Pi has no memory subsystem, so its report covers session persistence, compaction, and the extension surface only. Third-party Pi memory plugins other than Magic Context were not reviewed; the db0 integration has a closed backend and is not reviewable on this atlas's terms.
- MetaClaw's committed benchmark fixtures and memory ablation scripts were inspected but not run, and no published numbers were reproduced. Its replay metrics are lexical-overlap proxies; no evidence linking them to task outcomes was found in the repository.
- No memory tests or memory-quality benchmarks were located for nanobot, CowAgent, or GenericAgent. Nothing was run for any of the four systems added in this round.
- GenericAgent's memory documentation is written in Chinese; the axioms and rules quoted in its report are the reviewer's translations, with key terms given in the original. Its cited arXiv technical report was not retrieved or assessed.
- Waku Agent's evals were not run, and its retrieval gate's accuracy was not measured — the false-negative rate, which is the figure that matters, is unknown. No system in the atlas measures its gate.
- Nine repositories examined in the same round have no reports.
razzant/ouroborosis cited in the append-only-memory-audit pattern for its "honest journal" fix rather than given a report. (truffle-ai/dexto,Arvincreator/project-golemandopenyak/openyakwere excluded here on licence grounds and have since been reviewed — see Dexto, Project Golem and OpenYak. The openyak entry was also wrong on its facts: that repository has carried an Apache-2.0LICENSEsince 25 May 2026, well before it was examined.)OtterMind/youclawis small.SixHq/Overture's only memory artifacts are.claude/agent-memory/*/MEMORY.md— Claude Code's own memory used while developing the repo, not a system it ships.husu/loomis an AI JSON Schema documentation generator,AaronWong1999/hermesclawa launcher for running Hermes Agent, OpenClaw, and OpenCode on one WeChat account, andKeyID-AI/agent-kitgives MCP clients an email address; none is agent memory. - Neither Atomic Agent's nor MateClaw's suites were run, and Atomic Agent's evaluation campaign was read but not executed; no scored results were found committed for it. MateClaw's scoping and retrieval ranking were not traced in full.
- Eight repositories examined in the same round have no reports.
beita6969/ScienceClawis an OpenClaw derivative whose memory extensions are OpenClaw'smemory-coreandmemory-lancedb, already covered — its runtime skill authoring is cited in the skills pattern instead.litanlitudan/skyagistates that it "implements the idea of Generative Agents" and has been frozen since August 2023, so the original is the better subject.xvirobotics/metabotre-exports a memory client whose backend is not in the repository.Gitlawb/zerohas context reporting and no memory module.thClaws/thClawshas a competent 1,644-line file-entry store that adds little beyond systems already covered, andskalesapp/skales(~1,542 lines) is Business Source License 1.1 with no distinctive mechanism found (it was reviewed later: see Skales).wanxingai/LightAgent's 196-line shared memory with swappable adapters is cited in the pluggable-provider pattern rather than given a report.rush86999/atomhas roughly 976 lines of memory-named Python inside a 459 MB repository dominated by deployment scripts; no coherent memory design was established, and that is a weaker conclusion than the others here. rickey1990/THREADS-reasoning-enginewas examined and has no report: its correctable event ledger lives only in process memory, and nothing in the tree persists it or binds it to an agent. The code is under PolyForm Noncommercial 1.0.0 and the documentation under CC BY-NC 4.0 (LICENSING.md,LICENSE-CODE.txt,LICENSE-DOCUMENTATION.txt; GitHub reportsNOASSERTION), and neither restricts a read-only analysis. At439f8a91…, nine commits by one contributor from 6 to 12 September 2026, thesource/andbenchmarks/directories are present, added at78972439…on 11 September 2026: a 974-line Python packagesrmh, 517 lines of tests and 1,369 lines of benchmarks.Ledgerindexes immutableEvents — subject, relation, object, event time, context, confidence, polarity, lineage — in three dicts (source/srmh/ledger.py:52-57), refuses an id reused for different content (:65-69), and answers a point-in-timelookupwithANSWER,NEGATED,CONTRADICTED,AMBIGUOUSorUNKNOWN(:102-116). ARETRACTaimed at an event id closes that assertion (:89-100), and on a functional relation retracting the latest value leavesUNKNOWNrather than reviving the value it superseded (:8,:95-97). Nothing survives the process: no module undersource/srmh/opens, serialises or loads anything,srmhis imported only bysource/tests/andbenchmarks/, and the only file writes in the tree are result JSON from the runner and benchmarks. The benchmarks titled "Correctable AI/customer memory" and "Agent plan/state recovery" build their history in a freshEngineon each run (benchmarks/applied10_benchmark.py:48-62,:219-237), and the paper in the tree names a memory layer as a possible use (THREADS_paper_spaced.pdf, p. 9) while listing persistence testing among what its benchmarks do not cover (p. 10). Two near-misses matter if the ledger is ever persisted: an untargetedRETRACTis keyed on the value but closes only assertions at or before its own time (ledger.py:98-99), so a later re-assertion is live again; and a negative event on a value is kept beside later positives and turns the answerCONTRADICTED(:97,:104-107), the nearer shape to a value-keyed rejection. Searches run at the tree root:git grep -nE 'open\(|json|pickle|sqlite|shelve|write_text|dump|persist|serial' -- source/srmh(nothing);git grep -lE 'srmh' -- '*.py'(the three test and four benchmark files);git grep -nE 'write_text|json\.dump|open\(' -- '*.py'(result writers inTHREADS_test_runner.pyandbenchmarks/only);git grep -nEi '\bllm\b|openai|anthropic|prompt|embedding|\bmcp\b' -- '*.py'(nothing). The screen found 0 RUNS, 0 EXEC, 0 FRESH and 2 FLOAT (numpy>=1.24inrequirements.txt, andsource/pyproject.tomlwith no lockfile), and nothing was installed, built or run. Nothing was run for Kwipu or craft; craft was read from a depth-one clone with its history from the GitHub API.- LlamaIndex ships two APIs under the name "memory": the newer
block-based
Memoryreviewed here, and an olderChatMemoryBufferfamily that is conversation-window management and out of scope. Its tests were not run and no memory benchmark was found. - No suites or benchmarks were run for open-cowork, Gini, Moltis, or Mercury. open-cowork's eval harness was read but not executed, and no scored results were found committed.
- Gini reimplements the Hindsight memory model locally rather than depending on Hindsight; its recall module cites the source paper's equation numbers, but no check was made that this implementation reproduces the published behaviour.
- Moltis's cross-agent prefetch and its shared-channel tool path were traced by reading and not exercised; whether either reaches a prompt depends on a deployment running more than one agent, or on a channel configured with a trusted audience and a policy tool set.
- Four further repositories examined in this round have no reports:
he-yufeng/CoreCoder(1,166 lines whosecontext.pyis conversation-window compaction with nothing persisted),chrysb/alphaclaw(an OpenClaw deployment harness whose only "memory" reference is host RAM),Intelligent-Internet/ii-agent(a SaaS agent platform with chat context and caches but no durable memory), andAgentsMesh/AgentsMesh(a real pgvector-backed block memory with amemory.retrieveMCP tool, set aside for now because it is licensed under Business Source License 1.1 rather than an open-source licence). pingcap/tidbwas examined and is out of scope: its "memory" is RAM. The repository reached this atlas through a scout shortlist on the strength of thirty-odd memory-named files, and at8b5d4478…every one of the 36 such paths in its 7,703 blobs is resource management for the database process —pkg/util/memory/{tracker,arbitrator,pool,meminfo,memstats}.go,pkg/util/gctuner/memory_limit_tuner.go,pkg/util/cgroup/cgroup_memory.go,pkg/util/memoryusagealarm/,pkg/util/servermemorylimit/,br/pkg/utils/memory_monitor.go, and three design documents on global memory control, a global memory arbitrator, and keeping a priority queue in memory. None of it is a memory an agent reads or writes, and the filter that found it was matching on the word. Recorded so the same shortlist entry is not assessed a third time.- Three repositories examined in the same round were judged out of
scope and have no reports:
KnockOutEZ/wigolo(a web crawl, search, and extraction MCP server whose cache holds external content rather than agent belief),siyuan-note/siyuan(a note application whose agent kernel contains no memory concept — only conversation compaction — and whose MCP surface is note CRUD), andnetease-youdao/LobsterAI(which operates OpenClaw's memory rather than having its own, and is covered inside the OpenClaw report). - Memora's report was wrong about what supersession did, in
the direction that flatters the system. Until 11 August 2026 it
stated, in the matrix and in two sections, that superseded rows were
"hidden from retrieval" at
bc64ff74…. At that commit the exclusion applied only where a caller passedfollow="active"— inside the digest path — whilememory_list,memory_searchandmemory_getpassed the caller's argument through, and an omitted argument meant no lineage filtering. The error came from reading the function that implements a filter and not the callers that decide whether it runs. The project changed the defaults inde8e9e97…on 9 August 2026, so the corrected report describes a system where the claim is true. - Nothing was run for memora or LoongFlow. Memora's pair classifier is
the component that matters — its precision determines which memories get
hidden — and no measurement of it was found; the dry-run mode makes
exactly that measurable, and nothing indicates it has been done.
LoongFlow's tests exist under
tests/agentsdk/memorybut were not run, and no comparison of adaptive against fixed temperature was found, though the code is parameterized for it. - Six repositories examined in the same round have no reports.
TeleAI-UAGI/Awesome-Agent-Memoryis a survey, cited in the correction discussion rather than reviewed as a system.webbrain-one/webbrain(368 lines) andAmeNetwork/aser(29 lines) are too small to carry a mechanism.AgentTeam-TaichuAI/ScienceClawis 78 lines with no licence file, and is a different repository from the OpenClaw-derivedbeita6969/ScienceClawnoted above.ArtificialAnalysis/Stirrupandhowl-anderson/agentsilexhave no memory subsystem. - Nothing was run for the six systems added in this round. OptMem is
reviewed without a licence file — all rights reserved
by default — as a deliberate exception to the rule applied to
openyakand others, because it carries mechanisms the atlas has not otherwise found; the exception covers reading it, not reusing it. MemAgent, HiAgent, Mi-Memory and langchain-ai/memory-agent were examined in the same round and have no reports: MemAgent and HiAgent are conversation-window management (MemAgent is discussed in the scope-boundary section),Darwin-Agent/Mi-Memoryis a paper PDF and a landing page with no implementation, andlangchain-ai/memory-agentis a 235-line LangGraph template whose substantive counterpart, LangMem, is already reviewed here. - The framework-native gap is now closed, and closing
it corrected the bullet that named it. CrewAI — the most-cited omission on that
side — is reviewed, as are Agno, CAMEL, the Pydantic AI Harness and Microsoft Agent Framework, which
retires Semantic Kernel as a separate entry since it succeeds it.
Haystack was the error.
deepset-ai/haystackat3cef34f2has no agent memory to review: itsInMemoryDocumentStoreis a RAM-backed document store,components/agents/stateis a typed run-scoped dict with a merge schema and no persistence layer, and the only things it calls memory stores areMem0MemoryStoreandCogneeMemoryStore— adapters that live in the separatehaystack-core-integrationsrepository and are backed by Mem0 and Cognee, both already reviewed here. So this atlas spent several rounds naming as an unreviewed gap a thing that does not exist, and the correct statement is that Haystack is a RAG pipeline framework that mounts other people's memory. With the adjacent contracts — adk-python, AutoGen and LangMem — already read, this atlas no longer has a named framework-native omission. That is a statement about this list, not about the field: the next one will arrive the way all of these did, from somebody naming it. - MemGPT is here under its current name. The project
renamed to Letta, so the OS-style tiered-memory reference implementation
is the Letta report — which covers the
V1 server, archived on 15 August 2026 in favour of
letta-ai/letta-code— and a reader searching this atlas for "MemGPT" will otherwise find only a passing mention in the correction discussion. Recorded because the rename makes the lineage hard to find, not because anything is missing. The paper is arXiv:2310.08560, MemGPT: Towards LLMs as Operating Systems (Packer, Wooders, Lin, Fang, Patil, Stoica & Gonzalez, 12 October 2023), which introduced the virtual-context-management idea — paging between an in-context working set and out-of-context tiers, driven by the model through function calls and interrupts — that the Letta report analyses as shipped code; the atlas judges the implementation, and the paper is the design behind it. Cohexa-ai/agent-coherencewas examined and has no report. It is MESI cache-coherence for shared agent artifacts — single-writer ownership, commit-CAS, a read-generation fence, pinned snapshot sessions — and it stores no memory:CCSStore._apply_putserialises the value to an opaque JSON string and versions it, never parsing, ranking, scoping or correcting it. What it durably holds is coordination metadata. That is the guard-is-not-a-store shape and the operates-rather-than-believes shape at once, and namingmemory.jsonas an example artifact does not change it. Recorded rather than dropped for two reasons. Its premise is a failure this atlas asks about in every report and finds answered in four of two hundred and sixty-one — Mastra prevents lost updates with per-scope locks, Logseq is last-write-wins, the Pydantic AI Harness adds an idempotency receipt so a retried write is a replay rather than a second append, and Prime Agent refuses a harness edit whose target entry changed while the model was planning it — so a whole library existing for it says something about the corpus. And its central claim does not hold: the README says "every spec carries a documented mutant that must fail — the invariants are load-bearing, not decorative", the mutants are written out in the specs' comments, and nothing executes them.make tla-checkasserts six invariants hold; no job asserts a mutated spec fails, which is the standard defence against an invariant passing vacuously. A repository with 60,163 lines of tests documented its negative cases in prose — and the contrast is internal, because its performance claim is committed, checksummed and CI-regression-checked:benchmarks/results/canonical/SUMMARY.mdreproduces its paper's Table 1 with all four figures against tolerances, which is the inverse of the traceability failure this atlas records for Memvid, MemoryOS and FiFA. The same discipline was applied to the speed claim and not to the safety claim. Its paper (arXiv:2603.15183, 16 March 2026) is also worth noting for selling a different thing than the repository does — the paper leads with simulated token savings and the repository leads with preventing silent clobbers, which on this atlas's terms is the better framing of the same mechanism. See the note for what is unusually honest about it, and for the read-generation fence, which is the one mechanism there that memory systems with restartable background passes appear to need and none here has.perplexityai/numbatwas examined and has no report, and what it is worth to this atlas is what it reads rather than what it stores. Apache-2.0, Go, ~99,000 lines over 260 files at63b5a313…, created 29 July 2026. It is endpoint detection for coding agents: local hooks and plugins, a CEL rule engine, opt-in pre-action blocking, and forensic reconstruction of sessions from on-disk artifacts. The scope call is settled by the vocabulary — across the whole treerecallandembeddingappear zero times and every one of the twenty occurrences ofmemorymeans RAM ("cannot exhaust memory", "the in-memory window"). What it durably writes is events, findings, enforcement decisions and case bundles: records of what happened, none of them a claim that could be false and later corrected. Same boundary asUntrivial-ai/agent-orchestrator,os-factory/harandCohexa-ai/agent-coherenceabove. Its coverage matrix is the artifact worth knowing about, because it is an independently maintained, path-level enumeration of where about eighteen agent hosts put durable session state — including seven this atlas has reports on — and two of its entries are evidence for a limitation stated elsewhere on this page. For OpenClaw it discovers "plain retained.jsonl.{reset,deleted}.<timestamp>archives", matched byopenClawRetainedArchiveREininternal/discover/discover.gowith tests for both suffixes: a deleted session survives as readable plaintext beside the live one. And its Gemini CLI extractor skips$rewindTorecords above the comment "A rewind changes resume context, not what already happened", so an undo moves a pointer and leaves the actions recoverable. Neither was verified at this atlas's own pin for those systems, so both are recorded as facts about numbat's extractors rather than folded into the reports they concern.- Nothing was run for Nova AI, and its own suite would not
have helped. Its 21 test files carry five assertions between
them, all in one file, against roughly 230
printcalls — manual scripts a person reads the output of. Nothing asserts the invariant its most careful code exists to hold — that a classifier retrain leavestraining_data.jsonbyte-identical — and nothing pins the refusal path that earns it two capability marks. Its licence is "Viewable, Not Reusable" — all rights reserved — reviewed under the same exception applied to OptMem, because the mechanisms are ones the atlas has not otherwise found in a system that calls no model at all. - Two repositories examined in this round have no reports, and
both are the same misread.
showjihyun/bvwebchatandshowjihyun/bvcounterchatare, respectively, a multi-room web chat server and a browser 3D FPS game; neither application stores agent memory, and everymemorymatch in the latter's source is SQLite's:memory:DSN against a kill/death/playtime stats table. What is substantial in both is the Claude Code development harness beside the app, and the two differ sharply there: bvwebchat keeps.harness/state/with asession.jsonof goal, next steps and open questions, an append-onlydecisions.jsonlwith a single writer, HMAC-signed state that demotes to a fail-closedIDLEwhen tampered, and aSessionStarthook that injects a ≤15-line digest of "what git does not know"; bvcounterchat has none of that machinery, only a markdown ledger and gate hooks. The first passes the letter of this atlas's qualification test — something survives the session and can be corrected — and is still excluded, because what survives is workflow control state: a phase is not a claim that can be true or false, and there is nothing for a correction to be about. Recorded rather than dropped because it is the cleanest example yet of the boundary this atlas draws between a harness that persists and a memory that believes. - One published claim about ALMA was wrong at both earlier pins,
and is corrected. Until 4 September 2026 the report said
"No validity interval exists"; the knowledge graph's
Relationshipdataclass has carriedvalid_fromandvalid_tobesidecreated_at, with aget_relationships_as_ofreader, since v0.9.0 in April 2026, four months before the first reading. The mark is still withheld, on the producer test rather than on absence: nothing in the package assigns either field, the Kùzu, Neo4j and Memgraph backends neither persist nor read them, and no surface imports the graph package — so the report's verdict was right and its reason was wrong, and a reason that is wrong is a search that was never run. The same re-read found the two commits the report had been pinned to no longer served by GitHub, because the project rewrote its history to remove a company adapter; the History section keeps both hashes and says so. - Three published claims about Engram Alpha were wrong at every pin
since the first reading, and are corrected. Until 4 September
2026 the report said approval and pinning were "human acts the
assistant cannot perform";
approve_nodehas been an MCP tool since the commit the first reading pinned,Engine::approvetakes no source and gates on nothing, and the only restraint is the tool's own description — pinning is human-only, approval is human-only by request. The report described storage as "SQLite (with a TepinDB backend beside it)"; every new graph has been born on TepinDB since v0.6.2 on 21 July 2026, two weeks before the first reading, and the SQLite driver is a migration source — the project's own documentation namedgraph.dbas the default until its v0.9.1 sweep, and the reading repeated the documentation instead of readingresolve_db_path. And the open question "does the TepinDB backend match the SQLite one … no parity comparison found" had an answer in the tree at every pin: astore_batteryconformance test has run one sequence against both backends since v0.6.0. The direction is the one the corpus keeps producing: a boundary the documentation draws was credited as one the code draws, and an absence was published without the search that would have refuted it. The report now names which of the two human-only lines is enforced and which is asked for. - Four published claims about iai-pme were wrong when published, and
are corrected. Until 3 September 2026 the report described the
LongMemEval head-to-head as run "in a single harness" with
MemPalace and praised the matched-embedder row as the control that made
it rigorous; the project's own
BENCHMARKS.md, present at the pinned commit, said the baseline numbers "are published and config-matched (not re-run on this host)", andbench/longmemeval_blind.pyhas never had a competitor mode — the row is a control against a published figure. The report said the system had "no trust state, no tombstone, no provenance beyond the episode itself" and "no epistemic status field"; therecordsschema at that commit carrieds5_trust_score,provenance_json,tombstoned_atandlabile_until, and the read path derivedvalid_tofromcontradictsedges and discounted stale hits. It said the committed JSON "covers the embedder comparisons";bench/results/held seven contradiction-benchmark runs with environment tables. And it withheldaudit_logfrom an insert-only, encryptedeventstable that records every forgetting-side mutation. The direction is consistent: the benchmark posture was overstated and the mechanisms understated, because the first reading worked from the README and the file index rather than the schema and the results directory. The report now carries three marks and names the failing gate the committed artifacts record. - A published claim about Cambium was wrong and is
retracted. The report stated the repository had "no worked
instance" of its profile interface and that "an adopter is the first
person to find out whether the rules compose". Both are false:
profiles/examples/agent-atlas/— a 603-line filled reference profile with no placeholder markers — was present at the reviewed commit, andcheck_profile.pypasses on it with all ten interface slots bound. The correct narrower statement, now in the report, is that the repository selects no profile of its own, which is what blockscompose_vocab.pyand leaves everything downstream of a composed vocabulary undemonstrated. Reported by the project's author; verified here at the atlas's own pinned commit before correcting. - A Perseus Vault claim was overstated and is corrected. The report described its tool count as "stale by eleven", which asserts that the documented command's 76 is the canonical figure. It is not: parsing the registry the command is meant to count returns 88, and the canonical/legacy split is synthesized at runtime rather than present in the source, so no static count settles it. What is established is that the count definition and its verification command have drifted apart. Reported by the project's author; verified at the atlas's pinned commit.
- The DeepSeek
Harness report described an opt-in surface as the system's default,
and is corrected. Until 14 August 2026 it framed the harness as
one whose durable memory is "indexed for full-text search across past
sessions and handed to the model through five tools". Both halves are
off in every shipped composition at the pinned commit, and
independently.
packages/bundle/base/cordis.patch.ymlmountssession-query-sqlitewithpath: ':memory:'andopenAt: never, sosearchSessionsandsearchEventsfail withSESSION_QUERY_SEARCH_DISABLEDbefore request normalization andnode:sqliteis never opened; the web-app bundle restates it andapps/cli/tests/lazy-search-startup.compat.spec.tspins both layers. Andtool-session-query, which registers all five tools, is mounted by no bundle — only byexamples/acp-agent/and a test — with its own README stating that "shipped host compositions do not mount it by default." A defaultdshgives the model no history tools and the deployment no content search, while exact reads, titles and lineage traces stay available onctx.sessionQuery. The error was reading the mechanism and not the composition that mounts it — the same shape as the Memora correction above, which read a filter and not its callers, and it is the second time a default has been mistaken for a capability in this corpus. Both capability marks are retained, because the mechanisms are real code in the tree, and the report now says which package they live in. Verified at the atlas's own pinned commit before correcting. HKUDS/Auto-Deep-Researchwas examined and has no report, because its memory layer is present in the tree and unreachable from it. It is a deep-research agent built on the AutoAgent framework — 11,115 lines of Python, dormant since October 2025 — and it does inherit a memory package:autoagent/memory/is 747 lines wrapping a ChromaDBPersistentClient, withrag_memory,code_memory,codetree_memory,paper_memoryandtool_memory. Durable storage, retrieved by query, so it looks like a candidate. The disconnection is what settles it. Every one of the five functions inautoagent/tools/rag_tools.py—save_raw_docs_to_vector_db,query_db,modify_query,answer_query,can_answer— is referenced in zero other files in the repository;autoagent/agents/contains onlysystem_agent; and the RAG imports inautoagent/tools/__init__.pyare commented out rather than merely unused, so the disconnection is a choice someone made rather than an accident. Checked by enumerating each defined function and searching the whole tree for each name, because "nothing calls this" is exactly the claim a single mis-scoped grep gets wrong. Nothing this agent stores survives a session, because nothing reaches the store — which is the genuine exclusion, distinct from a system that stores carelessly. Worth recording rather than dropping because it is a shape nothing else in the corpus names: inherited memory machinery, complete and disabled, in a fork whose parent presumably uses it. A reader evaluating the parent framework should not conclude anything about it from this.ShamGaneshan2008/Kodiakwas examined and has no report, and it inverts the shape of the bullet above. An autonomous GitHub-issue-to-pull-request agent — 50,497 lines of Python over 290 files, 247 commits since 11 June 2026, atc2daf864…— carrying akodiak/memory/package of 3,663 lines with the full cognitive taxonomy: working, short-term, episodic, semantic, procedural, plus consolidation, ranking, retrieval and an experience extractor. It is excluded on the ordinary ground, and it takes three separate checks to establish, because the machinery is arranged so that each one alone would look like an oversight. The named memory package is reachable and ephemeral. All five repositories inpersistence.pyare Python dicts; the one durable driver,JSONFileMemoryPersistence, is only ever given a path byMemoryService(persistence_path=...), and that argument is passed in exactly two places in the repository, both intests/unit/test_memory.py. Every other construction — the three CLI commands, andMemoryIntegration's default — callsMemoryService()bare, soself.persistenceisNone.kodiak memory addtherefore prints "Memory added", andkodiak memory searchbuilds a second empty service in a second process. The durable store is unreachable.kodiak/learning/pattern_store.pyis the real thing — asyncpg over alearning_patternstable it creates itself, with content hashes, aPatternStatusof active/deprecated/pending_review, jsonb tags with a GIN index,frequencyandsuccess_rate— and neitherPatternStorenorPatternExtractor,RewardModel,FeedbackCollectororCrossRepoSyncis referenced anywhere outsidekodiak/learning/, a directory with no__init__.py. And the ORM tables named for both are scaffolds.memorys(sic) andlearningsare five identical columns —id, name, description, status, created_at, updated_at— with no content field, no type and no embedding, generated bycreate_kodiak_full.pyat the repository root and queried by nothing;LearningRecordis not even exported fromdb/models/__init__.py. The hook that would join the halves is written and never supplied:ExecutionEngine.__init__takesmemory_integration: MemoryIntegration | None = Noneand callsrecord_executionunder anis not Noneguard, andMemoryIntegration(appears only in tests.GET /memoryis a nineteen-line router returning a hardcoded[]. What does persist is a ChromaDBPersistentClientindex of the user's source code — a corpus index, the boundary already drawn forVectorSpaceLab/general-agentic-memoryabove, and not a store of anything the agent believes. Two smaller facts are worth stating because a reader would otherwise take the claims at face value:SemanticEntity.embeddingis accepted, stored and carried through updates and never read by any comparison — the only search anywhere in the package is a substring term-count — so the CLI's "search memories by semantic similarity" describes a path that does not exist; andkodiak/auth/audit.py:25importsfrom kodiak.db.models.audit_log import AuditLogat module level, a file absent from the tree, so that module cannot be imported at all. The licence is asserted three times — a README badge, a "MIT — see LICENSE" line linking to the file, andpyproject.toml— and theLICENSEfile is absent, as with Membase andrahvis/cognitive-weavebelow. Recorded rather than dropped because the arrangement is instructive on its own: a complete memory design, a working durable store, and a wired execution hook, none of which are connected to the other two — which is what a scaffold generator plus five subsystems built in parallel produces, and what a reader skimming the directory listing would never guess.- Empryo's maintainer reports
substantial changes in a tree this atlas cannot verify, and the report
is unchanged because of it. They opened a pull request
rewriting the report against commit
aa963f28, in which the memory layer has moved fromsrc/core/memory/into a standalonepackages/memory/workspace that is private. The public repository still carries the v2 layout, and its default branch head is still64ea2ec8…— the exact commit pinned here, so the published pin has zero drift and every path in the current report still resolves. What is reported and not verified: a retrieval-quality benchmark with committed results, a content-hash resurrection path closed after this atlas named it, two further capability marks, and — volunteered by the maintainer — a degradation in provenance, where an optional distillation pass writes model-authored memories into the same table with no ranking distinction from user-dictated ones. Also reported is a measured and unexplained gap between synthetic and real-data recall. None of it is checkable from outside, so none of it is in the report; the maintainer said the same thing first and marked the PR draft. Recorded here so a reader knows the pin is current with the public tree and may lag the project, which is a different claim from the pin being stale. - Core Memory's grounding ceiling, Memanto's conflict-detection precision, Memory Engine's agent clamp, ai-memory's cross-harness continuity claim, ctx's disclosure reachability, and OptMem's cover loss are all directly testable and none was measured here.
- Nothing was run for the four systems added in this round.
gastownhall/beadsandVectorSpaceLab/general-agentic-memorywere examined and have no reports, for the reasons given in the scope section; GAM additionally has no licence file.langchain-ai/memory-agentandakitaonrails/ai-memorywere re-submitted in this round and were already handled — the first rejected as a 235-line template, the second reviewed. - Memvid's headline figures ("+35% SOTA on LoCoMo", "+76% multi-hop", "+56% temporal") could not be traced to committed raw artifacts at the inspected commit and are recorded as claims. MemoryOS commits the LoCoMo dataset beside its harness but no scored results were found. Neither was run here.
- SimpleMem is the same finding at six figures rather than three. Its
README claims a 26.4% average F1 gain and roughly 30× token reduction on
LoCoMo, LoCoMo F1 = 0.613 and Mem-Gallery F1 = 0.810 for Omni-SimpleMem,
and +25.7% on LoCoMo with +18.9% on MemBench for EvolveMem, and offers a
benchmark runner per pillar. The repository contains no
.json,.jsonlor.csvfile of any kind at the inspected commit, so no scored result, prediction dump or metrics table backs any of the six. Nothing was run here either. Its 311 test functions were not executed, and the transforms carrying its contribution — coreference resolution and time absolutisation in the extraction prompt — have no test or metric anywhere in the repository, so how often they are correct is unknown and is the number the whole design rests on. - OpenWorker's stated finding — that models without when-to-remember
guidance "either never call
rememberor save noise" — is quoted from a source comment. Whether it was measured, and by how much guidance moves behaviour, is not established in the repository. OpenHands/OpenHandswas examined twice and has no report, because the memory it appears to have belongs to another repository, and the organisation's own layout says which. That repository is Agent Canvas, an Electron control centre: ten Python files against 2,230 in the tree, acondenser-settings.tsxthat renders whateveragent_settings.condenserschema the backend declares, ause-condense-conversationmutation posting to/api/conversations/{id}/condense, and aCondensationEventtype mirroring a server contract — including aforgotten_event_idsfield it never populates. The standaloneOpenHands/agent-canvasrepository was archived on 27 July 2026, which is when this one became it. The agent code that used to live here is inOpenHands/legacy, archived the same day and reduced toanalytics,app_server,dbandserverwith no memory package;OpenHands/enterprisecarries the same four and declaresopenhands-sdk==1.43.1,openhands-agent-server==1.43.1andopenhands-tools==1.43.1as dependencies; andOpenHands/OpenHands-Cloudis Helm charts and Terraform. Every one of them gets its agent memory from OpenHands SDK, wherecontext/memory.pywas added on 22 July 2026 by a pull request titled "feat: add opt-in persistent memory across sessions" andload_memorywas exposed in the agent-settings schema three weeks later.Tongyi-MAI/Qwen-UI-Agentwas examined and has no report, for the same reason and more plainly. At083fc5ed…the repository is the model's technical-report website — its own README calls it "a concise, application-first website template distilled from the current Qwen-UI-Agent LaTeX draft" — 4,650 lines of TypeScript of Next.js pages plussiteContent.ts, and 444 MB of demo video underpublic/. There is no agent in it:db/schema.tsis a two-line file whose comment reads "Intentionally empty by default. Add Drizzle tables here when the site actually needs a database", the worker is one file, and the only external links in the site content are Bilibili demo videos. The UI agent this site describes lives elsewhere and was not reviewed here. Recorded because the atlas already carries two other Qwen-named systems and the repository name is what a reader would search for.Tongyi-MAI/Qwen-Planner-Agentwas examined and has no report, and it is the harder call of the two, because the design it describes is squarely in scope. At2a924e12…the repository is seventeen files — a 7.4 MB technical-report PDF, a singleindex.html, a README and fourteen PNGs — with no.gitmodules, no licence file, and no source file of any kind in a tree the GitHub trees API returns untruncated. The README says so itself, in an[!IMPORTANT]callout at the top: "This is the blog and technical report website repository for Qwen-Planner-Agent … It is not the release repository for model weights, training code, or the agent implementation." The weights are not published either — the organisation's Hugging Face account carries four models and none is this one, a query of the arXiv API for the title returns no entry, matching the page's own placeholder ("The official citation will be available when the report is released"), and every link in the README resolves to the website, the PDF, or the repository itself. What the 47-page report describes is a memory system this atlas would want to read. Its Persistent Memory Manager separates a compact user model, episodic records, curated long-term memory, prospective memory "for future intentions with explicit activation conditions, scope, expiry, and completion status", and review records that "document maintenance without becoming authoritative memories"; each unit links a structured summary to source metadata and a lossless dialogue record, so the original "permits direct verification of numbers, dates, quotations, contradictions, and changing facts". Model-assisted consolidation proposes rather than decides — "provenance, trust, recency, and conflict checks precede consolidation" — a revised entry "explicitly supersedes the obsolete record rather than leaving competing versions unresolved", recalled material is tagged so it is not re-ingested and cannot inflate its own importance, provenance tiers stay distinguishable and "content cannot promote its own trust level", retrieved memory "does not authorize or execute an action", an invalid summary is "treated as an ingestion failure rather than silently replaced", and low-confidence or release-critical Harness revisions "are routed for human review" with "no candidate update applied autonomously to a serving system" — several of which name mechanisms this atlas awards marks for. Two things are worth separating for a reader who opens the PDF. The privacy-preserving memory safety section is written almost entirely in the conditional: what exists is "service-level authentication tokens and separate administrator credentials, while user-level access enforcement depends on trusted upstream services", and role-based access control, least privilege, encryption, protected audit logs and retention policies are each what the system should do — a design recommendation is not a producer test, and none of it could be credited even with the tree in hand. The report draws the same line itself elsewhere, presenting model–Harness co-evolution "as a development pathway rather than claiming that sustained autonomous co-evolution has already been established". And the long-history results — a memory Harness against a 256K direct-context baseline on LoCoMo, LongMemEval and BEAM, reporting BEAM-10M rising from 21.99% to 67.24% for the 27B planner — are the project's own, with the Mem0 comparison row marked by the authors as externally reported rather than re-run, and no scored artifact backs any of them in the repository, because the repository contains no results file. Recorded rather than dropped because the exclusion is not the usual one: the repositories above are excluded for storing nothing, for storing something unreachable, or for calling RAM "memory", while this one is excluded only because the described system is not anywhere a reader can inspect it, which is a claim about the artifact and not about the design. Searches, so a later reader can re-run them: the trees API at the pinned commit (17 blobs,truncated: false, no.gitmodules, noLICENSE, no.py/.ts/.rs/.go/.ipynb/.sh/.yaml/.toml);https://huggingface.co/api/models?author=Tongyi-MAI(4 models); the arXiv API for the exact title (0 entries); and a grep of the extracted report text foropen.?source|will be released|code is available|we release|checkpoints? (are|will), whose only hits are the website repository's own URL, a table header reading "Open-Source Models", and two bibliography entries.aindilis/autonomous-ai-agentandaindilis/free-life-plannerwere examined and have no reports. Both are components of FRDCSA, a long-running symbolic-AI project. The first is AgentSpeak(L) BDI agents over SWI-Prolog with no licence file, where the three occurrences of "memory" all refer to RAM and compute allocation. The second is a GPL-3.0 Prolog life-management and planning system — calendaring, fluent calculus, a software ontology — whose only belief-related identifier ishasBeliefSystems/2in a list of dynamic predicate declarations. Neither contains a memory subsystem: no capture, retrieval, consolidation, or lifecycle. Both are also not self-contained, carrying 50 and 352 distinct absolute paths respectively into a/var/lib/myfrdcsa/installation that is not in either repository, so neither can be evaluated as it stands.elizaOS/agentmemoryis listed as a representative open-source memory framework in the open-source table of Memory in the Age of AI Agents (arXiv:2512.13564), and the URL returns 404; a search of theelizaOSorganization finds no repository by that name. It could not be reviewed. Note also the name collision: this atlas's agentmemory report isrohitg00/agentmemory, a different project, and anyone reconciling the two lists by name rather than by URL will merge them.nuster1128/MemEngineappears in the same table and earned no report: it has no persistence layer at all, as set out in the inclusion rule, and no licence file.- Oracle's
oracleagentmemorywas suggested for review and has no public source repository — a GitHub search returns only third-party demos consuming the SDK. It cannot be reviewed on this atlas's terms, which require inspectable code at a pinned commit, and is recorded here rather than silently omitted. Its design is now described in a paper — arXiv:2607.13157, Oracle Agent Memory as an Enterprise Memory Substrate for Long-Horizon AI Agents (Alake et al., 14 July 2026): a database-native substrate on Oracle Database with lifecycle-managed memory, an active/passive layered architecture with scope controls, and a reported 93.8% on LongMemEval at about 10.7× fewer tokens than a flat-history baseline. The paper is CC BY-NC-ND and ships no code, so the substrate stays uninspectable and the numbers are the vendor's own, unbacked by a committed artifact. - Agno was read, not run, and its 304 memory-related unit tests were
not executed. Three things a live install would settle: whether the
supersession judge's default threshold is calibrated against anything,
since no calibration was found; how often a typical deployment sets
background_executor, which decides whether extraction blocks the response path or not; and how oftenPROPOSEmode's prompt-level approval rule is actually followed, which is the number that decides whether the mode means anything and which nothing in the repository measures. Its two memory subsystems —agno/memory/andagno/learn/— overlap, and which one a given deployment is using was not established beyond noting that the AgentOS HTTP routes serve the older one. - Seven repositories submitted together on 2026-07-30 were
examined and every one is out of scope — the first batch this round to
produce no report, and instructive for why. Three of the seven
have "memory" in a file path and none of the three is agent memory. smolagents'
src/smolagents/memory.pydefinesAgentMemoryas asystem_promptplus alist[TaskStep | ActionStep | PlanningStep]withreset()andreplay()— an in-process run trace with no persistence layer, which is the call already made for Pi, OpenAI'sSQLiteSessionand LlamaIndex'sChatMemoryBufferfamily. It is named here rather than passed over silently because it is Hugging Face's framework and a reader searching this atlas for it deserves to find why it is absent.Elumenotion/GuideAntsexposes aMemoryToolsclass documented as "static semantic-memory tools", and its three operations areSearchProjectContent,SearchLocalContentandWebSearch— document and web retrieval with no store of agent belief behind it.genepattern/module-toolkit'stest_memory_spec.pyvalidates that a manifest'sjob.memoryfield reads like8Gbor4Mb: RAM allocation, the same false positive already recorded for the FRDCSA repositories. The remaining four have no memory concept at all —F-loat/panerelayrelays a browser to agents,ringlochid/banksiaruns multi-agent teams over aflowstable with norecall,rememberor long-term anything in the package,hamish-mackie/sloopgives each ticket a git worktree and an agent, andTheArtOfSound/qev-desktopis an encrypted vault format whose envelopes can hold "AI output receipts" — adjacent to Lethe's signed purge receipts in intent, and a container format rather than a memory system. The pattern is the point: the word memory in a path predicted the wrong answer three times out of three, which is the whole argument for reading code instead of file listings. - Six repositories submitted alongside TokenMizer and ZeroStack were
examined and have no reports.
Bino5150/lumina's memory module opens with "persistent memory across sessions via SQLite. Write-through to MemPalace on save. Flat table preserved for migration + fallback" — so its durable store is MemPalace, already reviewed here, behind a 291-line client with a flat-table fallback. It is the first system in the corpus whose primary memory is another atlas entry.octelium/cordiumis a Kubernetes sandbox platform for identity-based secretless access to infrastructure; it has no memory concept.faramesh/faramesh-coreand9hannahnine-jpg/arc-gateare both guards rather than stores — Faramesh is a policy daemon that permits, defers or denies each tool call against a declaredgovernance.fms, and itsMemoryBackendis an in-RAMStateobject for single-node deployments; Arc Gate is a runtime proxy whose purpose is preventing agents acting on hidden instructions. Neither durably holds anything an agent later retrieves as belief, which is the guard-is-not-a-store shape already recorded forCohexa-ai/agent-coherence.trumae/meiis a 209-line stateless C99 orchestrator that uses Fossil SCM as its single source of truth — the same instinct as GitLord, at a size too small to carry a mechanism.jaylfc/taOSis dual-licensed AGPL-3.0 and commercial, and itsuser_memory.pyis 193 lines over a base store; the one idea worth citing is its settings block, which lets a user togglecapture_conversations,capture_files,capture_searchesandcapture_notesindependently, so what is eligible to be remembered is a user preference rather than an extractor's judgement — a small instance of the who-decides divergence, at a scale that does not earn a report. - Four repositories submitted alongside Cortex, Mnemopi and agent-afk
were examined and have no reports.
omnigent-ai/omnigentmounts Hindsight as a built-in tool exposing its retain/recall/reflect operations, so its memory is a client for a system this atlas already reviews; the one detail worth keeping is that the memory bank is resolved per invocation from the agent spec, falling back to the run identity, so a single declaration isolates memory per agent.opsyhq/wolli(233 lines of session memory storage) andfischerf/aar(a 165-line session store) are both too small to carry a mechanism.Fagoon-AI/upgradewas read atf027d614and falls outside the inclusion test. ItsWorkflowMemoryis a message row —workflow_id,conversation_id,rolefrom a five-value set,content, metadata, an estimated token count and a TTL — and itsMemoryNodeoffers exactly six operations: add, get all, get, delete, prune and stats. There is no embedding, no vector, no similarity and no search anywhere in either file; the vector tables that migration creates belong toknowledgedocument, the RAG side, not to memory. So what survives a run is the transcript, listed by conversation rather than retrieved, and theconversation_idfield defaults to the execution id — one run. That is the call already made for Pi, for LlamaIndex'sChatMemoryBufferfamily, and for OpenAI'sSQLiteSession. The comparison worth recording is with CAMEL, which did earn a report on a similar-looking message store: CAMEL'sVectorDBMemoryembeds messages and recalls them by similarity across sessions, which is retrieval; this lists them by key, which is storage. The line between the two is one index. - Three repositories submitted in the same round were examined and
have no reports.
ahmadvh/octochainsis a framework for parallel isolated multi-agent reasoning whose stated premise is that shared chat history contaminates independent judgement — it has no memory concept because avoiding one is the design, which makes it the most pointed out-of-scope entry the atlas has recorded. Re-checked on 2026-07-31: every occurrence of memory in it is a patient's memory loss in a sample medical report, a PDF parser reading from memory, or GPU VRAM.aleloro-dev/agois a zero-dependency Go agent library with noMemorytype, no file writes and no database — nothing survives a run. Both are out of scope on their merits; the licence was never the operative reason and should not have been cited as one.Gitlawb/zerowas re-examined atd37de9214bafter growing to roughly 332,000 lines of Go since the earlier pass, and the earlier conclusion holds:internal/backgroundandinternal/swarmcoordinate work, and there is still no memory module. - A mark that was wrong, and how it was found. Mem0Sharp earned
audit_logon 30 July for a history table written only byINSERT. The atlas's Mem0 report, of the system that C# port reimplements, carried onlyscope_enforced— a divergence recorded the same day as a limitation rather than resolved. Re-readingmem0/mem0/memory/storage.pyat the pinned commit settled it: Mem0'shistorytable isid,memory_id,old_memory,new_memory,event,created_at,updated_at,is_deleted,actor_id,role, written only byadd_historyandbatch_add_history, with noUPDATEand noDELETEagainst it anywhere in the file. Mem0 was under-marked and now carriesaudit_log. Worth recording as a methodology note rather than a correction: the defect was invisible for two months and surfaced only because an independent reimplementation of the same design was reviewed and marked differently. A corpus wide enough to contain a system twice is a corpus that can check itself, and nothing in this atlas's process was doing that deliberately. ThunderAgent-org/ThunderAgentwas examined on 2026-07-31 at7ddc8610and is out of scope: it is an agentic inference scheduler, not agent memory. Three occurrences of the word memory in 3,361 lines, all three GPU capacity telemetry; no persistence primitive of any kind. It is filed under the KV-cache scope boundary rather than dismissed, because it is the clearest instance of that particular collision — an ICML Spotlight whose whole purpose is reusing an agent's state across turns, and which stores nothing.unibaseio/membasewas excluded here on licence grounds and has since been reviewed — see Membase. Its licence position is unchanged and stated in that report's first section:README.mdgrants MIT and links to aLICENSEfile that is not in the repository, so the grant is asserted and absent. That is a caveat for a reader, not a reason to leave the mechanisms unread, and the mechanisms turned out to be the point — the retrieval threshold selects the least similar documents, and deletion never reaches the vector index retrieval reads.- Five repositories named in a Reddit thread were examined on
2026-07-31; one became a report and the thread was wrong about
which. Graphify was
dismissed in that thread as one of the repos that "cut down how much has
to be remembered" rather than memory — and it carries the corroboration
gate, the decayed contested verdict and the re-hash-on-read staleness
check described above, so the dismissal was wrong at this commit.
DietrichGebert/ponytail, dismissed in the same sentence, was right: it is a single behavioural rule — write less code — compiled into fourteen-plus harness formats (.claude-plugin/,.cursor/rules/,.clinerules/,.kiro/steering/,.openclaw/skills/, and so on) with no store of any kind.kunal12203/graperootis the entry worth naming, because it is a new shape of the closed-source refusal: the repository is Apache-2.0 and contains launchers, a dashboard, benchmarks and thirteen translated READMEs, while the README states outright that "The graph engine (graperootpip package) is proprietary." Every previous refusal on this ground was for a hosted service; this is an open repository wrapped around a binary dependency, which reads as inspectable until you look for the mechanism.ArtKeyAi/bhived-mcp— the MCP server behind thebhivedproduct placement in the same thread — is Apache-2.0 and 8,315 lines of TypeScript that contain no memory mechanism at all:restClient.tsposts to/v2/queryand/v1/memoriesagainsthttps://mcp.bhived.ai, and the open part is transport, formatters, an agent-config installer and a subscription check.omnigent-ai/omnigentwas already examined and recorded above on 30 July; re-reading it at18fcf67dchanged nothing, and its own store —conversations,conversation_items,agents,files,policies,session_permissions— still has no memory table, its 83 files matching remember being the "don't ask again" permission rule. See the thread note for the rest of that triage. rahvis/cognitive-weavewas examined and has no report, and it is the sharpest instance yet of a published number with nothing behind it. The repository presents itself as "the official implementation" of arXiv:2506.08098, whose abstract claims "a notable 34% average improvement in task completion rates and a 42% reduction in mean query latency when compared to state-of-the-art baselines" — measured, per its section 4, against Standard RAG, MemGPT, A-MEM and Mem0 on Robotouille, Evolving-QA and LoCoMo, with human judges on a Likert scale. It is excluded on the ordinary ground rather than that one: nothing survives the session.main.py:39declaresself.memory_store: List[InsightParticle] = [], the chat loop appends to it, and grepping the tree foropen(,json.dump,sqlite,pickleandwrite_textreturns nothing — the same call already made for Pi, LlamaIndex'sChatMemoryBufferfamily and OpenAI'sSQLiteSession. What makes it worth recording is that the repository says so itself: "Implement memory persistence layer" and "Implement full STRG (Spatio-Temporal Resonance Graph) structure" are both unchecked items on its own To-Do list, and STRG is the mechanism in the paper's title. 568 lines of Python across five files, one empty; retrieval is set-intersection over a stopword-filtered bag of words falling back to the most recent particle;relational_strands,access_frequency,importance_scoreand two of three timestamp fields are declared and assigned nowhere; there is no dataset, metric, result or test anywhere in the tree. This does not establish that the experiments were not run — they may have used a fuller implementation that was never released. It establishes that the figures cannot be checked against the artifact published as their implementation. The licence is asserted in the README and theLICENSEfile is absent, as with Membase. No commit since 5 August 2025. See the note for the component-by-component comparison against the paper.- VISTA was first examined from its published traces alone, a
month before its source was released, and that reading is the corpus's
best argument that a trace can stand in for source. VISTA is a
visual harness from five MIT authors, posted 5 August 2026 with no
harness source at any commit, reporting all 25 public ARC-AGI-3 games
won with a perfect efficiency score. Its memory design is three-part —
raw frames as observation, two markdown notes, and a "lossless
visual memory" holding every frame the environment returned,
recalled through
inspectandread_pixelson the model's own decision. The page shipped 320 MB of per-game run traces recording every message, every region inspected with the question that motivated it, and every memory write with its full content — enough that the entire memory surface was reconstructed without the implementation: two files, 260 writes, full-document replacement in 215 rewrites and not one append, a median note of 1,320 characters. The headline claim recomputes from the same files: 25 of 25 runs carrystatus: "WIN", every scorecard readsscore: 100, andlevelsCompleted == levelCountthroughout. Set besiderahvis/cognitive-weavein the bullet above — examined the same day, claiming 34% and 42% over MemGPT, A-MEM and Mem0 with no dataset, metric or result committed — the two mark the ends of the axis the benchmarks page exists to measure, and the difference is not rigour of prose but whether the evidence was published. See the note, including the check that a cheap reading of the note rewrites would have produced a finding that inspection does not support. The source followed on 5 September 2026 atjoshhhhhan/VISTA, and VISTA is read from it at900aa338…. schema-harness.github.iowas examined and has no report: it is an ARC-AGI-3 harness with no source at any commit. A project page from Impossible Research, Berkeley and CMU, examined on 6 August 2026 beside VISTA, Tycho and Retrodict, which have reports since 18 September (VISTA, Tycho, Retrodict). It describes a model-authoredworld_model.pybeside an append-only timeline — the split the four share, an append-only record the model did not author with a small belief file subordinate to it, written up under Research lineage — and claims "~99%" with no scorecard; its per-run traces are published as a dataset. See the note.shepherd-agents/shepherdwas examined and has no report, and it is the cleanest instance yet of the harness-is-not-a-store boundary. MIT, 120 commits since 25 June 2026, with a paper (arXiv:2605.10913): a runtime substrate that records agent runs as "durable, inspectable" reversible traces so meta-agents can observe, fork, replay and revert a run, with a copy-on-write environment fork it reports at ~5x faster thandocker commitand ~95% KV-cache reuse on replay. Everything about that description sounds like memory — durable, versioned, revertible state — and none of it is. Grepping the tree forrecall,remember, belief, semantic memory or long-term memory returns nothing; the only file namedmemory.pyiscommons-vcs/src/commons_vcs/backends/memory.py, an in-RAM VCS backend. What it durably holds is execution trace events, substrate state and checkpoints — a phase, a fork point, a replayable transcript. That is workflow control state, and the test this atlas applies is whether the stored thing is a claim that can be true or false and therefore corrected; a checkpoint cannot be wrong, only stale. Same call asshowjihyun/bvwebchat's harness and the KV-cache boundary above, and worth recording because the vocabulary overlaps almost completely with a memory system's while the subject matter does not. Its reversibility work is genuinely relevant to memory systems with restartable background passes — the read-generation fence question recorded underCohexa-ai/agent-coherenceis the same shape — but a reader looking for agent memory here will not find it.avarshvir/oxygenwas examined and has no report: it stores nothing at all. Apache-2.0, 486 lines of Python, 39 commits since 24 August 2026, at0a65d56b…. It is a LangGraph pipeline of five role-specialised agents — project manager, researcher, developer, tester, technical writer — driven over a WebSocket, with a human approval gate before code generation. The scope call takes one file:backend/state.pyis aTypedDictholding messages, the LLM config, the requirements, proposal, source, test results, documentation and five UI status strings, and the onlyjson.dumpin the backend writes to the socket. No database, no file write, no store; nothing survives the run. The approval gate is worth naming because it is the thing a reader might mistake for the human review mark.approval_routermatches the user's message against a list —accept,approve,looks good,ok,proceed,yes,go ahead,sure— and routes the graph. A person is approving a proposal inside a run, not adjudicating a stored claim, and the two are different surfaces however similar the word is.arXiv:2608.25593andbingreeky/JITwere examined together and have no report, and the one thing in the paper that persists across tasks is the one thing the release leaves out. JIT-Agent: Scaling Harness Intelligence via Just-in-Time Harness Evolution (26 August 2026; Zhang, Lu, Xie and thirteen others) trains a 27B model to write an agent harness per task — memory, planning, action and capability orchestration as four Python files plus a prompt — for any off-the-shelf executor, and the repository is MIT, three commits over two days, atababa06c…, with the checkpoint and the training set on Hugging Face. Screened before reading: no auto-run surface, nothing inside the cooldown, three unpinned requirement files; nothing was built or run. The memory module is the boundary this atlas draws for SKILL.state and Self-GC, and the code says so in its own terms:BaseMemoryis an "inside-trial working memory manager" whoseinitializeis "called once at the start of each run" and whoseupdatemay "store, compress, summarize, or fold the step" (scripts/kernel/protocols.py:16-56). The eleven seed implementations span the whole conversation-window repertoire — full history, ReSum-style summarisation at 90% of the context, HiAgent's value-scored sampling with[Omitted]placeholders, MemoBrain's reasoning graph, GAM's memory pages, AgentFold's folding — and none of them writes a file; a grep ofjit/,harness_factory/andscripts/forjson.dump,sqlite,pickleandwrite_textfinds only run reports, traces and the best-of-N selection record. What the paper says does persist is a harness bank: each entry (task, harness, metrics) with reward, latency and cost, a candidate "retained only if it matches or exceeds the current reward frontier and then strictly improves at least one frontier dimension", a reference set retrieved from it per task, and a streaming mode in which "harnesses keep improving at test time while the generator itself stays frozen" — the README's phrase. In the tree,HARNESS_BANK_DIRisharness_factory/harnesses/, the eleven hand-written seeds; the reference set is either the full description catalogue or three seeds drawn byrandom.sample(jit/meta_agent.py:230-240); nothing writes a generated harness back, no metrics are stored beside one, andfrontier,incumbentandstreamname nothing in the source. The archive that makes the paper's title an evolution is an experiment the release does not ship, so on its own artifact this is a per-task generator with a fixed seed bank. Two further gaps between paper and tree: Table 2 lists thirteen seed harnesses and the tree holds eleven, ReAct and AOrchestra absent; and the training pipeline — supervised fine-tuning, repair-trajectory imitation, and a group-decoupled policy optimisation over reward, latency and cost — is described and not released, though the data it consumed is. The discipline worth carrying out is in the runner: a harness is regenerated only when execution raises, and "a harness that merely scores low is never repaired, since that would be optimising against the benchmark" (scripts/run_jit.py:310-312); the seed baselines are run withmax_repairs=0so the number describes the harness as written. The benchmark adapters, configs and task data ship in the repository, so the instrument is reproducible; no result file or run trace is committed, so the numbers are not. Placed on the benchmarks page beside the Binding Constraint Thesis, whose controlled comparison its Table 4 is.zvec-ai/zvec-grepwas examined and has no report, and it is the corpus's cleanest case of a store that can be stale and cannot be wrong. Apache-2.0, 38,327 lines of TypeScript undersrc/with 19,890 lines of tests, 229 commits since 10 July 2026 from eight authors,v0.2.1tagged 1 September 2026, read at81a80f47…. Screened before reading: no auto-run surface,package.jsonand its lockfile changed inside the seven-day cooldown, fifteen floating ranges under a lockfile; nothing was installed, built or run. It is a local-first search layer over a workspace — ripgrep, BM25 and vector search behind one CLI and one loopback MCP endpoint — built to be handed to a coding agent, and it never calls itself memory: a grep ofsrc/forremember,forgetandmemorizefinds nothing, and everyrecallis a per-candidate retrieval trace. What it persists is a derived index of the workspace's own files, under<root>/.zvec-grep/: afiles.zveccollection keyed onfile_idcarryingcontent_hash,last_modified_time,indexed_timeandentity_ids_json; anindex.zveccollection of fragments with a jieba-tokenised FTS field and an HNSW vector; and amanifest.jsonwritten at mode0600because it may hold an embedding API key (src/engine/storage/zvec.ts:593-643,:891-944;src/engine/manifest.ts:12,:40-47). Nothing an agent says enters that store. The default MCP toolset registers one tool,zvec_grep_search; thefulltoolset adds five, and none of the six takes content to keep —zvec_grep_indextakes a root and re-reads the files (src/mcp/tools.ts:327-633). The one epistemic state in the system isfresh/possibly_stale, computed per hit by comparingindexed_timeagainst the file's mtime and then its SHA-256 againstcontent_hash(src/engine/service/zvec-grep.ts:2141-2166), and per search from whether the watcher has pending events or a known-change job is queued (src/daemon/backend.ts:557-562). That is the whole of what can go wrong with an entry, and the repair is the read that built it: a watcher with a 750 ms debounce and a 5 s ceiling, a full reconcile every hour and after a 90 s gap in the clock, bursts above 1,000 exact events widened to directory scopes rather than escalated to a rescan, and acomputeDiffFromFilesthat promotes a file from unchanged to modified only when size, mtime and then content hash all disagree (src/daemon/watch-manager.ts:65,:124,:198,:204;src/daemon/change-set.ts:28;src/engine/pipeline/indexing/index.ts:647-698). A stale fragment is not a false belief; it is a cache miss wearing a status label, which is the line the KV-cache entry draws — a loss that costs latency rather than correctness — and the committed BrowseComp-Plus report prices the latency: 9,721 seconds and 7.9 GB to rebuild the index for 100,195 documents. The integration suite's stale-record case asserts the same thing from the other side — afterrm(goodPath)it checksfilesDeletedis 1 andfilesIndexedis 1, counts on the index, and never searches for the deleted file's needle, because there is no reader for whom its absence would be a correctness claim (test/integration/service.test.mjs:386-469). Two things transfer to memory systems anyway. The remote-embedding consent surface is the one to copy. A search or index that would send text to aqwenprovider is first planned into a disclosure —queryTexttrue or false,workspaceContentofnone,changedorfull— and, absent a standing grant, the MCP server answers withinputRequiredcarrying a signed, single-userequestStateand a form offering allow once, allow for this workspace, use FTS only or cancel, defaulting to cancel; a workspace grant is HMAC-SHA256-signed with a key at~/.zvec-grep/authorization-signing.key, fingerprinted on the canonical roots, provider, model and endpoint, and kept in the workspace's own.zvec-grep/authorization.json(src/authorization/planner.ts,src/authorization/store.ts:46-94,src/mcp/tools.ts:694-825). A memory system that ships its embeddings to a hosted provider faces the same question about the memories themselves, and the shape here — a plan that names what leaves, a default of refusal, a grant bound to a fingerprint and signed by the machine that made it — is the answer. AndtrackEntityIdforces a named entity into the candidate set and records, per route, why it did not come back — "Target entity did not match the FTS query", "Target entity file was excluded by the path filters", "Target entity could not be scored by vector search" — a per-miss retrieval diagnosis of the kind the benchmarks page asks memory systems for and one repository there supplies (src/engine/pipeline/search/index.ts:761-968). Its own benchmarks are read on that page: of two, one commits its run report and one exists as string literals in an SVG generator. The exclusion will not reverse on a release. A search index becomes memory only by storing something other than the files it indexes, and the roadmap's four directions — more formats, graph retrieval, a GUI, mobile — add none.robert-mcdermott/ai-knowledge-graphwas examined and has no report: it is the extraction half of a graph memory, run once, with no reader. Apache-2.0, 2,040 lines of Python, 64 commits from 22 March 2025 to 27 December 2025 by three authors, read at40b70197…; tags0.6.1,0.6.2and0.6.3all carryversion = "0.6.1"inpyproject.toml. Screened before reading: no auto-run surface, no build-time execution, no unpinned manifest,uv.lockunchanged for 478 days; nothing was installed or run. The pipeline is a CLI that takes one text file, splits it into 100-word chunks with a 20-word overlap, asks an OpenAI-compatible endpoint for lower-cased subject–predicate–object triples with predicates of three words or fewer, standardises entity names, infers further edges, and writes one JSON file and one HTML page (src/knowledge_graph/main.py:195-276). Nothing reads the JSON back butjson_to_html.py, which re-renders it —rg -n 'json.load|read_json' src json_to_html.pyfinds that one call — so there is no query, no merge of a second document into a first, no scope, no correction and no deletion: the graph is an artifact, not a store, and the word memory does not occur in the code. Two things in it are worth carrying to the graph-memory systems that do keep a store. First, the one epistemic distinction it makes is stated versus inferred: every edge the inference phase adds carriesinferred: True, drawn dashed and filterable in the page (src/knowledge_graph/visualization.py:109-120,templates/graph_template.html:724-727), and the README's own run says what that flag hides — 209 stated edges and 355 inferred of 564, so 63% of the delivered graph is the inference phase's. Second, where those edges come from: transitive composition mints a predicate from the path (A → B → Cbecomes<pred> via B,entity_standardization.py:344), so the run's second and third most common relations are "advances via Artificial Intelligence" and "pioneered via computing"; and lexical similarity mintsrelates to,related tooris type ofbetween any two entities that share a word of four letters or more or contain one another (:708-749), which is where the run's most common relation, "related to" at 65 occurrences, comes from. Standardisation collapses entities whose first-four-letter stems overlap by more than half (:141-151). None of this is wrong for a visualisation; every one of it would be a false belief in a store an agent recalls from, and a system that borrows this extraction stage inherits the flag and nothing behind it. Two smaller notes: the console line "Added -22 inferred relationships" in the README islen(filtered) - len(triples)printed after deduplication and self-reference removal (:270), and the README's configuration block sayschunk_size = 200andtemperature = 0.2whereconfig.tomlsays 100 and 0.8. This exclusion will not reverse on a release: a store and a reader would make it a different program.- IEEE Xplore document 11554177 was examined and has no report: its agents are reinforcement-learning controllers, its trust is a float, and it releases no code. Adaptive Federated Learning for 6G: A Multi-Agent Architecture for 6G Edge Intelligence (Das, Ali, Pirbhulal, Aloi, Pace and Sodhro; IEEE Network, early access, inserted 8 June 2026, doi:10.1109/MNET.2026.3694694, CC BY 4.0, eight pages, in the magazine's Agentic AI for Next Generation Wireless Networks section — which is the likeliest reason it reached a memory atlas). It proposes MAAFL-6G, a device–edge–cloud hierarchy of agents running a PPO variant (H-MAXPPO) to decide federated-learning participation, training depth, compression and aggregation under battery, link and attack conditions, and reports 99.8% reliability, 0.48–0.55 s latency and 0.0175–0.0195 J per task against re-implemented baselines on twelve simulated runs of fifty clients over three edge nodes, driven by an IEEE DataPort smart-home power-trace dataset. The inclusion test is not close. The agents are policies whose state lives in network weights — the boundary the KV-cache entry above draws, on the model-internal side; the text's "policy repository" and "model repository" are stores of weights. Its trust score is the rubric's counter-example in one sentence: "T_i(r) is the device trust score (higher values indicate more reliable and consistent behaviour across rounds)", a float that enters a device's utility argmax and weights aggregation — a number used for ranking, never a state that withholds anything. Over the 5,437 words of the paper, memory, remember and recall occur zero times, agent 50 times, and GitHub, source code and available zero: no repository, no data-availability statement, and the baselines "were independently re-implemented following the algorithmic descriptions in the cited literature", so nothing here is checkable against an artifact. Recorded so a future search for the id finds a judgement rather than a gap; it would not become a memory system with a release.
arXiv:2609.00829was examined and has no report: it releases no code, and the harness it evolves is a store of falsifiable edits with two gates in front of it. HarnessEvolve: Learning from Reference Trajectories for Reliable Agent Self-Evolution (Jiang, Chu, Tian, Zhang, Yang, Yang, Liu, Lv and Li; Huawei ICT AI Competence Center, Shanghai; submitted 1 September 2026, preprint) optimises an agent's harness — prompts, skills, tools and execution logic — with four decoupled agents. An execution agent runs the training tasks; an evaluation agent marks failures and vets reference trajectories — runs given the ground-truth answer, cached only when they reach it through tool calls rather than by restating it; an optimisation agent compares each failure against its reference to find the first divergent action and clusters error signals by cause, preserving single-member clusters; and a gate agent applies two checks before an edit enters a snapshot pool. The quality gate scores each edited file for whether the failed queries and their answers were written into it (LLM-as-judge, rejected above 0.8) and counts injected in-context examples (rejected above five), returning a rejection reason for up to three revisions. The performance gate accepts a candidate only if it does not fall below the current harness on the current batch — the margin δ is set to 0.0 — and loses no more than 2.5 points on either of the two previous batches; the epoch's best snapshot on a held-out set becomes the harness. Five benchmarks: two in-house (CloudCoreNetwork-QA, Wireless-QA) on an in-house framework (LAMAgent) with a domain-fine-tuned Qwen3.6-27B, three public (SearchQA, OfficeQA, SpreadsheetBench) on OpenClaw with DeepSeek-V4-Flash, where the harness is the skill directory,AGENTS.md,SOUL.mdand tools. An ablation on the in-house set puts the reference trajectories at 29.1 points, the clustering at 18.3 and the quality gate at 6.8. Over 7,260 words of extracted text, GitHub and source code occur zero times and available six, every one about reference trajectories; there is no data-availability statement, so the in-house half is unrepeatable and the public half uncheckable. With a release it would be screened like any skill-evolution repository, and two things would be read first. Askill.mdedit is a claim that can turn out false, and the gates are the shape this atlas asks of any promotion path: the quality gate is a leakage check on a learned artifact — that the optimiser embeds training answers when nothing stops it is what the 6.8-point ablation measures — and the performance gate, as parameterised, admits a tie and bounds regression over two batches only, so an epoch of accepted no-loss edits can drift past the tolerance with only the held-out selection to catch it; the bloat bound is five examples per accepted edit, not per harness. And the abstract's "consistently outperforms state-of-the-art baselines across all benchmarks and settings" is a claim about Tables 1 and 2; the transfer table beside them reads 95.0 to 95.0 on one cell, which the text calls "improve or maintain."SKILL.statewas examined and has no report, and the boundary is the same one Self-GC draws. SKILL.state: Scalable Long-Horizon Agent Skills (arXiv:2608.26263, 26 August 2026; Badhe, Tiwari and Chung, accepted at EMNLP) replaces an append-only conversation history with "an explicit, mutable execution state": at each step the model gets the immutable skill specification, the current state and the latest observation, and "intermediate reasoning is discarded immediately after producing a validated state update." The state is within-run — across InterCode CTF it is a five-field schema (discovered_flags,tested_hypotheses,active_files,working_dir,cmd_summary) merged byΣₜ₊₁ = Σₜ ⊕ ΔΣₜwith null-deletion — and nothing in the paper describes a durable store or anything surviving a run. No code is released. Two things transfer anyway. Schema ownership and validation "reside in the deterministic runtime rather than the model," so a malformed patch triggers a rollback-retry rather than corrupting the state — the code-owns-the-structure rule this atlas keeps finding, applied to state transitions. And the recovery experiment measures something memory systems are rarely asked: after a corrective observation, a mutable state needs zero recovery steps because the wrong value is overwritten, where an append-only history leaves the correction sitting after the claim it corrects. How long a wrong belief keeps being acted on after it has been corrected is a measurable quantity, and this is the clearest instance of it being measured.WikiSkillwas examined and has no report, and its ablation is the finding. WikiSkill: Compiling Agent Experience into Persistent Knowledge for Skill Evolution (arXiv:2608.27454, 27 August 2026; Tang, Rashtchian, Ferng, Tomkins, Juan and Vu) separates raw execution experience, accumulated knowledge and executable skills, consolidating experience into a wiki that later skill updates build on. It is in scope as a design and gets no report for the ordinary reason: no code is released, so there is nothing to read at a pinned commit. Two of its results are worth carrying. The ablations "confirm that persistent knowledge accumulation in the wiki is critical for effective skill evolution" — the memory measured by removing it, which is the rule the benchmarks page keeps arriving at. And skills transfer across models and families, with "skills evolved by other models" sometimes beating self-evolved ones, which makes the accumulated knowledge an artifact separable from the agent that produced it. Read beside OpenKB, which ships the same compile-experience-into-a-wiki idea as a CLI in the same month, with no connection between the two projects.Self-GCwas examined and has no report, and the authors draw the same boundary this atlas does. Self-GC: Self-Governing Context for Long-Horizon LLM Agents (arXiv:2607.00692, 1 July 2026, Xiaohongshu) turns a run's user turns, tool spans and skill state into indexed objects and has a side-channel planner propose fold, mask and prune actions over them, which the harness rehearses and commits only at a safe turn boundary. It governs the active context of a run; the full transcript stays outside that view, and the paper positions the work as "complementary to memory-store methods" rather than as one. Nothing it holds is a claim that could turn out false, which is the test, and no code is released. Two things in it are worth carrying and are traced in benchmarking agent memory. Its no-impact rate asks whether a pruning destroyed something the real future turns needed, judged against those turns with the removed content shown to the judge and withheld from the system under test, reported with Wilson intervals and calibrated on the cases where the judge disagrees with itself. And its planner is told never to compress the latest user turn, audited at 25/330 parsed plans violating that instruction for one backbone, and then overridden in the harness — "the prompt usually works, but the residual risk justifies mandatory last-turn protection" — which is this atlas's most repeated finding reached by measurement.munch2u-a11y/FP-AMBwas examined and has no report, because it is a benchmark rather than a memory, and it is the most useful negative result this atlas has read in one. MIT, 4,416 lines of Python, 24 commits since 26 August 2026, atc7516f36…. It stores nothing durable of its own: a provider implementsingest_turnandretrieve_context, and FP-AMB scores it over 60 sessions, 679 turns and ~512,889 tokens across ten categories. Same boundary as any harness. What earns it a paragraph is that it ships four committed scorecards and the winner is the TF-IDF baseline — 69.7% against real mRAG at 66.6%, the author's own vendored Fractal Memory at 50.2% and MemPalace at 36.1%, with per-question*_misses.txtfailure taxonomies beside each. A benchmark author publishing their own system third, behind a lexical baseline that answers in 3.1 ms against Fractal's 37.9 seconds, is the opposite of the vendor benchmark this atlas usually finds. Two defects in it are worth carrying and are traced in benchmarking agent memory: the Unanswerable & Absent Memory Refusal category scores 35/35 for all four providers because its predicate cannot fail, and the Fractal run is scored over 281 questions where the other three are scored over 262, so those four percentages are not means over one exam. The README's own comparison table lists only the three that share the 262-item exam.os-factory/harwas examined and has no report, and it is the same boundary carrying the atlas's rarest mechanism anyway. Apache-2.0, read three times, most recently at release 1.0.0,3eec6453…: a harness that gives each coding agent its own git worktree, ports and database, runs the project's own checks through one pipeline, and keeps the evidence. The scope call is settled by its schema —control/prisma/schema.prismaheld still through the first two readings and grew by one model at 1.0, thirteen Prisma models covering repositories, slots, sessions, spans, runs, work units, attempts, validation bindings and change batches, and across 16,277 lines ofsrc/the wordsrecall,remember,forget,embeddingandvectorappear twice, both incidental. Nothing stored is a claim that could be false; the intervening work is plugins (Semgrep, Trivy, Gitleaks, Kerno), docs, iOS fixes, node provisioning, a two-signal drift model separating user-edited from upstream-updated, and a 1.0 release turning.har/into a configuration surface — none of which touches the durable-belief question. What makes it worth recording is one of those twelve.UnregisteredRepositoryis a rejected-value tombstone in a repository registry:deleteRepositorywrites the path into it before deleting the row,registerRepositoryconsults it on every write and refuses with a 409 unless the caller passesforce: true— and the client handles that 409 by dropping the path from its own local registry so auto-sync stops re-asserting it, which is a step past where the tombstones in the corpus stop. The failure it closes is the one the pattern page names, a background pass re-reading an unchanged source and restating what a person deleted, and it is keyed on a filesystem path rather than on a natural-language claim, so it never meets the normalization problem that defeated two implementations here. Its mechanism (control/src/server/repositories.ts) is byte-identical since the first reading, but the gap named then has closed: the tombstone is now tested, by three files that did not exist at the earlier commit —tests/control-sync-unregistered.test.tsasserts the client drops the path from its local registry on a 409, andcontrol/src/app/api/repos/route.test.tsasserts the server returns the 409, in a tree grown to 94 test files and 11,893 lines. Two neighbouring mechanisms are recorded in the note: a validation record filed under the hash of the working tree it certifies — so it invalidates itself on any edit, with no expiry column, decay policy or revalidation sweep, and withvalidations/gitignored so writing the record cannot perturb the hash it is filed under — and a propose-review-apply gateway overAGENTS.mdwhose merge refuses when content outside the managed markers would drop below 90% of its non-empty lines, a governed write gateway with a floor on how much a regenerating writer may delete. The self-invalidating key is the one a memory system cannot copy and should read anyway: bi-temporal validity, decay and re-verification exist because memories are keyed by subject rather than by content, and this is what the alternative buys. At 1.0 the schema moved for the first time across these readings, and the scope call survives it. Eighty-one commits addedAgentTrajectoryRecord— a thirteenth Prisma model holding one row per agent trajectory event, uniquely keyed on(repositoryId, source, sourceEventId, contentKey)— and aharvestVersioncounter onAgentSessionUsagewhose comment marks the generation behind a row ("0 = pre-dedupe, reads high"), so counts written by an older harvester are legible as overcounted rather than silently wrong. A trajectory event is still a record of what happened, so none of it is a claim that could turn out false. What is worth carrying is the disclosure class. Every trajectory row is stamped at ingest bycanonicalContentDisclosurewith one offull,truncated,withheldormetadata_only, andserializeTrajectoryForEgressapplies it on the way out — the API route that returns trajectory records maps every row through it — withtrajectory-privacy.tsredacting secret-looking attribute leaves by regex beside it. A per-record classification of how much of it may leave, enforced on the read path rather than at the point of collection, is a shape a memory system with mixed-sensitivity records could take directly, and this atlas has not found it in one.MoonshotAI/kimi-codewas examined and has no report, and it is the clean contrast to a system the atlas does have one for. MIT, ~410,000 lines of non-test TypeScript across seventeen packages, at13d86f8b…. The vocabulary reads like a memory system —memory585 times,persist272,compaction1409 — and every surface traces to something else:agent-core-v2/src/agent/contextMemory/is per-agent conversation history withappend/applyCompaction/undo, i.e. window management; sessions persist towire.jsonland aminidbquery store for replay and resume, i.e. session state; andAGENTS.mdis generated once by/inithanding a brief to acodersubagent and then read back into the system prompt, i.e. instructions.minidbitself is a real embedded database — WAL, generation checkpoints, a trigram text index — but it exists to index sessions, not to hold beliefs. What makes it worth recording is that it has cross-session full-text search and it is the user's, not the model's.kap-server/src/searchis anIGlobalSearchService— "cross-session full-text search over user messages, assistant text and session titles, backed by a single minidb database" — with a background sync coordinator and published index generations, which is the DeepSeek Harness shape exactly. DSH is in the atlas because it registerssession_searchand four siblings as model-facing tools (unmounted by default, but the model is their caller). Kimi Code's search lives in the app server for the UI, and the agent's own tool registry —agent,ask-user-question,cron,edit,fetch-url,goal,os,read-media-file,select-tools,skill,task,todo-list,web-search— contains no memory, recall or session-search tool at all. The human can search their past sessions; the model cannot. The line between a searchable session corpus that is agent memory and searchable session history that is a product feature is exactly whether the model can query it, and these two repositories sit on opposite sides of it with nearly identical machinery underneath. Same boundary asos-factory/harandUntrivial-ai/agent-orchestrator; details in the note. If a release exposes session search or aremember/recalltool to the model — the "graduate into agent-core-v2" the search service's own comment anticipates — the scope call flips.cline/clinewas examined and has no report, and the finding is where its memory turned out to live. Apache-2.0, re-checked at8bbdde2a…. Memory Bank — six markdown files (projectbrief.md,productContext.md,activeContext.md,systemPatterns.md,techContext.md,progress.md) that the agent reads at the start of a session and rewrites at the end — is the most frequently cited long-term memory in coding agents, and the repository describes it in its own words as "a documentation methodology". Grepping the whole checkout formemory.bankormemorybank, case-insensitively, returns two files, both underdocs/: the page itself and the navigation entry listing it. Nothing insdk/,apps/orevals/mentions it, its setup instructions are to paste custom instructions into.clinerules/memory-bank.md, and the tool executors arebash,editor,file-read,search,apply-patchandweb-fetch— so the mechanism is a prompt plus ordinary file editing, with git as the only durability guarantee. That is worth stating precisely rather than dismissively, because it is memory as an editing surface with nothing behind the surface, and the properties it does get — diffable, reviewable in a PR, correctable in an editor, portable to any agent that reads files — are ones most stores here do not have. What it cannot do is consult itself before a write: nothing records that a claim was rejected, so a deletion survives only until the next update pass re-derives the same file. What Cline persists durably is the run — session versioning,checkpoint-diff.ts/checkpoint-restore.ts, and a.clineconfig tree of rules, skills, workflows, agents and hooks beside anAGENTS.md. Details in the note. That exclusion named the condition that would reverse it — Memory Bank becoming a store consulted before a write — and the condition was tested a week and roughly a hundred commits later: the same two documentation files, and the only othermemorpaths are a process-RSS logger and anInMemoryStateAdapterholding maps withexpiresAtfor the life of the process.integry/proprwas examined and has no report, and it is the corpus's cleanest case of an index that is built not to be memory. Apache-2.0, atd537c25e…, 4,280 commits — a self-hosted platform that runs coding agents through the GitHub pull-request workflow, from labeled issue to reviewed PR, in containers on the operator's own server. Twenty-five tables, and they sort into three piles with nothing left over. The run:tasks,task_history,task_drafts,plan_issues,llm_executions,llm_logs,usage_metric_records— the LangGraph-checkpointer boundary. Configuration and people:repositories,system_configs,instance_members,instance_role_audit, plusrepo_todosandrepo_chat_messages, which are human-authored. A summary index of the user's source:file_summariesanddirectory_summaries, LLM-written, one row per path. That third pile is where a memory system would be if there were one, and the invalidation is the reason there is not.file_summaries.commit_hashholds the git blob hash of the file's content, andidentifyStaleFiles(packages/core/src/services/relevance/summaryMinerStaleness.ts) reprocesses every path whose stored hash differs from the current blob and deletes every row whose path is no longer in the tree;directory_summaries.hashis a composite over its children, so a change propagates up. Reads are branch-scoped. The mechanism therefore enforces that the index is a pure function of the checkout — it cannot outlive its source, and a wrong summary is not corrected but regenerated from the file that produced it. That is the sharpest statement of this boundary the corpus has: an entry that a hash can prove stale is not an entry that can be believed, and the systems this atlas reports on are exactly the ones where no hash can settle the question. Nothing in the tree learns across tasks — 296 test files, six touching the summary miner, and no store of lessons, rejected approaches or accumulated preference. Propr enters the day a review finding outlives its pull request as a claim a later task must consult.gromhacks/bonsai-ninjawas examined and has no report, and it supplies the half of the argument above that Propr cannot. MIT, 443,026 lines of Rust across 626 files in 46 crates, 492 commits since 5 May 2026, ata118e6a0…— a local compiler-style static-analysis and code-intelligence engine over twenty language front-ends, which sells itself to agents in this atlas's own vocabulary: "Give agents facts, not file dumps", the smallest useful slice of a repository instead of repeated reading. It durably persists a great deal — an on-diskfactstorewith its own wire format and string pool, content-addressed compiler objects under<workspace>/.bonsai/, an LRU in front of the reader — so it reads as a candidate until the acceptance predicate is read. A cached compiler object is used only when five things match: the workspace-relative path, the selected language, the source digest and source hash (metadata_for,crates/db/src/compiler_object.rs:672), the metadata version, and the frontend semantic ABI (:645,:649), with a sixth check on the pipeline fingerprint. The fifth is the one Propr does not have.COMPILER_OBJECT_CACHE_VERSIONstands at 90, and above the constant are sixty hand-written changelog lines saying what each bump makes stale — v90's names the exact Swift conditional-cast form whose v89 objects "can retain a grammar diagnostic and omit the cast operand from exact value flow". Propr's blob hash enforces that an entry cannot outlive its source; this enforces that an entry cannot outlive its producer either, and states per version what a survivor would have got wrong. Together they are the complete statement of the boundary: a derived entry is discardable exactly because two hashes can prove it stale, and the systems this atlas reports on are the ones where no hash over the inputs settles whether a remembered claim is still true. The finding side settles it a second way. Security results carry SARIFfingerprintsandpartialFingerprints(crates/security/src/report.rs) whose stated purpose is that someone else's system can match findings across runs — the rule id is the sink rule rather than the CWE precisely because "GitHub code-scanning groups by ruleId; using the sink rule gives us per-rule baselines and suppressions". The triage verdict, the thing that would be a durable correctable claim, is deliberately held by the consumer. Nothing in the tree stores a judgement of its own; the single human-authored durable artifact is<workspace>/.bonsai/rules/, a project-local rulepack layered over the bundled one, which is configuration in the sense a linter config is. Its own README leads with a maturity warning — parser gaps, unresolved dynamic behavior, incorrect findings — and calls the analysis "evidence for human review" rather than a guarantee, which is the correct posture for an artifact that is regenerated rather than believed. bonsai-ninja enters the day a triage verdict is stored beside the finding it settles.pingdotgg/t3codewas examined and has no report, and it is the corpus's clearest case of a system that drives memory without having any. MIT, 688,235 lines of TypeScript across a pnpm monorepo (222,667 of them the server), 2,638 commits since 7 February 2026, atcd096b9a…— an agent-harness control surface, in its own words: a mobile, web and desktop front end that runs Codex, Claude Code, Cursor, Grok Build and OpenCode as child processes on your own machine. Five of the agents it drives have reports here, which is why a reader would expect it and why the boundary is worth stating. Its durable state lives under~/.t3in SQLite across forty migrations, and it sorts into four piles with nothing left over: an event-sourced orchestration log (orchestration_events, command receipts), projections of it (threads, turns, messages, attachments, proposed plans,archived_at, plus denormalised counters likepending_approval_countfor the thread list), checkpoint diff blobs against a git worktree, and auth/pairing/session rows. All of it records what happened and what is running — acts and coordination state, none of it a claim that could turn out false and later be corrected. Same boundary asUntrivial-ai/agent-orchestrator,perplexityai/numbat,os-factory/harandCohexa-ai/agent-coherenceabove. Checked rather than assumed: the server tree contains noAGENTS.md/CLAUDE.mdwriter, itsWorkspaceSearchIndexpersists nothing (on-demand scanning, by its own comment), and the only prompt state it owns isCodexDeveloperInstructions, which sets a collaboration mode per turn. The one place memory appears is the finding worth recording.makeMemoryConsolidationNotificationFilter(apps/server/src/provider/Layers/CodexSessionRuntime.ts:550) watches for athread/startedwhosethreadSourceorsource.subAgentismemory_consolidationand suppresses that thread's notifications, so Codex's background memory pass does not surface as a visible thread beside the user's own. A control plane deciding what to show the user about another agent's memory work is a role nothing else in this corpus occupies, and it is the shape to expect as memory moves down into the providers. One screening note, because it is unusual:.repos/holds two entire third-party repositories committed into the tree — 12,961 tracked files acrossalchemy-effectandeffect-smol, each with its own npmpreparescript that an ordinary install would run — while.vscode/settings.jsonexcludes.repos/**from search and file watching, so the execution surface a contributor is least likely to look at is the one the editor is configured to hide.Custodian-Labs/custodian-labs-pythonwas examined and has no report: it is a samples repository for a hosted SDK. Thirteen files atac9b5d07…— five numbered example scripts, two guardian-layer samples, a websocket bridge with an HTML page, and three data fixtures. The screen returnedNOTHING SCANNED— no manifest, hook or agent file exists at any path it knows, which is a finding rather than a pass, so the tree was read by hand: there is no package manifest, no library code and no licence file, which defaults to all rights reserved. Every script importscustodian_labs, a PyPI package that is not in this repository, authenticates withCUSTODIAN_SDK_API_KEYfrom a dashboard, and ends atcustodian.deploy()returning anapp.chat_url— so whatever the product stores, it stores server-side. Grepping the whole tree formemor,recallorrememberreturns nothing; the samples' actual subject is PII handling, with aGuardianLayerthat callsanalyze_proprietaryanddeidentify_text_outputsagainst the same hosted service, and aprivacy_enabledflag on the agent constructor. Nothing here is a memory mechanism, and the SDK that might contain one is closed behind a wrapper — the exclusion this atlas draws for a mechanism with no inspectable code at a pinned commit. It enters if the SDK is opened, or if a local store appears in these samples.arcee-ai/nacwas examined and has no report, and the word to be careful about is episode. Apache-2.0, at70666a09…, 76 commits, ~108,600 lines of Rust across three crates plus a web dashboard. Its architecture is genuinely interesting and worth naming: "a central orchestrator plans and decomposes work but cannot execute commands or edit files; it only launches threads, which return episodes — structured summaries of what they accomplished", a capability boundary drawn between planning and acting rather than assumed. An episode here is a run record, not episodic memory. Theepisodestable carriesthread_name,session_id, anaction, the summarycontent, and astatusconstrained took | error | timed_out | cancelled— an execution outcome, not an epistemic state — and every read of it isWHERE e.session_id = ?, withDELETE FROM episodes WHERE session_id = ?1when a session goes. The same key governs everything else durable:threads,worksetsandworkset_items(the plan and its acceptance criteria),workspace_revisions,session_run_recovery.orchestrator_compaction_checkpointsis conversation-window management done carefully — a summary, a tail start index, and SHA-256 hashes of both the source prefix and the system policy so a checkpoint cannot be reused against a prompt it was not built from — which is the boundary this atlas already draws, one layer up from a raw transcript. The two things that outlive a session are read-only inputs rather than memory:SKILL.mdfiles discovered by scanning project and user directories to a bounded depth and mounted into the sandbox at fixed guest paths, with no writer anywhere in the tree, andAGENTS.mdfiles read with a most-specific-wins override hierarchy. So nothing here stores a claim that could later be wrong, and nothing accumulates across sessions for a correction to name. nac enters the day a thread's episode outlives its session as something a later run must consult — the same condition the atlas set for Kimi's compaction handoff.CodebuffAI/freebuffwas examined and has no report, and it has the most developed prompt for this shape and the least machinery behind it. Apache-2.0, atd3646896…, 8,451 commits — the open source of the Codebuff products, a coding agent across terminal, desktop, browser and GitHub. Its durable memory is knowledge files:AGENTS.md,CLAUDE.mdand anything matching*.knowledge.md, recognised byisKnowledgeFileincommon/src/constants/knowledge.ts, plus a home-directory tier read byloadUserKnowledgeFiles. The loading code is real but thin —selectKnowledgeFilePathsgroups candidates by directory andselectHighestPriorityKnowledgeFilepicks one per directory in a fixed order,AGENTS.mdbeforeCLAUDE.md. Everything else is the prompt, and the prompt is the most developed instance of this shape the atlas has read:knowledgeFilesPromptframes the agent as working in a "Memento-style environment", tells it that knowledge files "were created by previous engineers working on the codebase, and they were given these same instructions", and then specifies when to update one ("if the user gives broad advice to 'always do x'"; "if the user corrects you because they expected something different"), what to include, what not to include, and to "integrate new knowledge into existing sections when possible". That is a genuinely good articulation of the practice — and it is still a prompt plus the ordinarywrite_filetool, with git as the only durability guarantee, which is the call already made for Cline's Memory Bank and for Zoo Code above. There is no store behind the files: no identity separate from the path, no status, no supersession, and nothing that consults a removal when the same claim is written again. One detail is worth recording for the atlas's stored-versus-enforced theme. The home-directory tier is declared off-limits in the prompt — "you cannot edit them because they are outside of the project directory. Do not try to edit them" — and that boundary is an instruction rather than something found asserted on the write path; the CLI resolves writes against a project root without a containment check in the code read here. A boundary whose enforcement is the model's compliance is exactly the distinction this atlas draws between a scope stored and a scope enforced, appearing here one layer up, in the prompt itself. The rest of what persists is run state —cli/src/utils/message-history.tsandrun-state-storage.ts— which is the checkpointer boundary.evals/buffbenchis a substantial coding-task eval suite with committed task sets, and none of it evaluates memory: the word knowledge appears in its fixtures because the repositories under test contain knowledge files. freebuff enters the day a knowledge file gains a record the write path consults.Zoo-Code-Org/Zoo-Codewas examined and has no report, and it has the best editing surface in the corpus with nothing behind it. Apache-2.0, ate064cf05…. It continues Roo Code — stillroo-codein the package manifest — which makes it a fork of a fork of Cline, and its durable state is three piles, none of them a belief store.src/services/code-index/is a semantic index of the user's source, with embedders, a vector store and an orchestrator, regenerated from the thing it indexes: the boundary already drawn forDeusData/codebase-memory-mcpand Kodiak's ChromaDB source index.TaskHistoryStore.tsandsrc/core/checkpoints/store the run, which is the LangGraph-checkpointer boundary. The third pile is where the interest is. Cline's Memory Bank declines as "a prompt plus ordinary file editing"; Zoo Code's rules and skills have a real management layer — a typed CRUD API overRuleMetadatarecords with ids built from(scope, kind, modeSlug, relativePath),globalandprojectbases each split into generic and per-mode directories, a filename pattern enforced on write, and resolution containment-checked twice, before and after anlstatthat accepts symlinks, so a rule cannot escape its scope through a link. Every caller ofcreateRuleanddeleteRuleis a click in the webview. The agent invokes a skill throughSkillTooland never writes one; nothing it concludes reaches the store except through the same generic file-write it could aim anywhere. That is configuration, not memory: a rule the user wrote cannot be wrong in the sense this atlas means, only outdated, and nothing derives it so nothing can re-assert it. It is further along than Cline on every axis except the one that decides the question — see the note.Aider-AI/aiderwas examined and has no report, and it is the cleanest test of the boundary because it does persist something. Apache-2.0, at5dc9490b…..aider.chat.history.mdis written continuously and--restore-chat-historyreads it back:base_coder.py:519splits the markdown into messages and callssummarize_start(), andChatSummaryrecursively summarizes from the oldest end until the tail fits a token budget — so a previous session's conversation genuinely reaches a later session's context. It is still a transcript and a summary of one. There is no unit, no identity and no status; two sessions that contradict each other yield a summary containing both, and no operation means "this was wrong". The other durable artifact isrepomap.py's.aider.tags.cache.v<N>— tree-sitter tags per file, mtime-invalidated, ranked by a personalized PageRank over the identifier graph — a derived index of the user's source.CONVENTIONS.mdis a file the user passes with--read, which is a prompt input. This is the exclusion where a conversation cannot be wrong either, and a summary of one inherits the property has to carry real weight, because the artifact does outlive the session.MoonshotAI/kimi-codeandMoonshotAI/kimi-cliwere examined together and neither earns a report, and the interesting one is the one being retired. They are one lineage:kimi-cli's README states that it "is evolving into Kimi Code CLI" and "will be gradually wound down". The successor is far larger — 107,465 lines inpackages/agent-core-v2/srcand its own embedded storage engine inpackages/minidb— and what both persist is the run: config, workspace state, a session index, cron tasks, the wire log, plans and blobs.contextMemoryis the conversation. Butkimi-cli(Apache-2.0, atcbc15c07…) shipsSendDMail— a tool, backed by a class calledDenwaRenji, that raisesBackToTheFuture— with which the agent picks a prior checkpoint in its own append-only context file, folds everything after it away, and leaves a message for its past self. The cut point is chosen by the agent rather than by a token threshold, which is what separates it from every compaction in this corpus; the reverted trajectory is rotated tocontext_1.jsonlrather than deleted, so the abandoned branch is retained (unboundedly — nothing prunes it); and the prompt names the seam that context-level undo always has, warning the past self that "your future self has already done something in the current working directory". Two caveats belong beside it: the mechanism instructs the model twice never to mention the rewind to the user, and it is commented out in the default agent, enabled only in a built-in agent namedokabe. The successor dropped it — noSendDMail,DenwaRenjiorBackToTheFutureanywhere inkimi-code— and replaced agent-initiated time travel with user-initiatedundo(turns), which is not in the tool registry. What it built instead is a full-compaction prompt that asks the model to carry the epistemic status of its own prior claims through the summary: "If an earlier step claimed something was done but was never verified (tests 'passing', a fix 'working', a file 'created'), say so plainly and treat it as unverified rather than fact" — the self-reinforcement failure named under OWASP Agent Memory Guard above, addressed at the boundary where a party with an interest in the outcome rewrites the record. Unenforced by any code, and still the only instance in this round that treats summarisation as an epistemic hazard rather than a compression problem. Its cron subsystem is the nearest thing to a durable agent-authored record in either repository and still is not memory —CronCreate/CronList/CronDeleteare agent tools writing{id, cron, prompt, createdAt, recurring, lastFiredAt}to a workspace-scoped document store, but the tool's own documentation says tasks "survive a resume of the same session but do not bleed into new sessions", and a schedule is an intent that cannot be false. Two moves in it transfer anyway: the model is told to re-enumerate from the store after a compaction rather than trust what survived in the summary — the right relationship between a lossy context and a durable record, and the opposite of how most extraction pipelines treat a compacted transcript — and a stale recurring task gets one final delivery flaggedstale: truebefore deletion, so expiry arrives as a renewal offer to the party holding enough context to judge it, rather than firing silently while nobody is looking. Recorded with the compaction details in the note.rezabyt.github.io/blogposts/sigreg-tutorial.htmlwas examined and has no report, and it is not a repository. It is a tutorial on SIGReg, the anti-collapse regularizer introduced in LeJEPA, developed from characteristic functions through the Cramér–Wold theorem to a training loop, with LeWorldModel as a temporal-prediction application. This is representation-learning methodology: it constrains an encoder's embedding distribution so it does not collapse during training. There is no store, no retrieval, no correction and no code at a pinned commit — two independent exclusions. Recorded rather than dropped because the collision is instructive: a world model that predicts the next embedding is memory-adjacent in the way a KV cache is memory-adjacent, and the atlas's line holds in the same place. What SIGReg governs is whether an encoder's representations stay spread out during training; what this atlas asks is whether a thing an agent stored last week can be found, scoped and corrected today. The first is a property of a loss function and the second is a property of a store.xataio/xatawas examined and has no report: it is a Postgres platform. The repository is a Go microservices system — 340 files underservices/, Helm charts, kustomize overlays, protobuf definitions — whose README states the two use cases plainly: "create your own internal Postgres-as-a-Service for your company" and "create preview, testing, and dev environments" using copy-on-write storage and scale-to-zero. Nothing in the tree matchesmemoryoragentas a concept, and there is no store an agent writes beliefs into. It is infrastructure a memory system could be built on, which is the same relationship this atlas records for graph databases: a backend the corpus reads as a shared dependency rather than reviews, alongside the layer below delete reading of five vector engines. Recorded by name because a reader meeting a database company's open-source platform in a list of memory candidates deserves to find that out here.metauto-ai/HGMwas examined and has no report: what persists is an optimizer's state. The Huxley-Gödel Machine is a practical approximation of Schmidhuber's Gödel machine, with coding agents that rewrite themselves and a search guided by the aggregated benchmark performance of an agent's descendants rather than its own. Its durable state, intree.py, is a tree whose nodes are git commit ids of self-modified agents plus their utility measures, pickled — read by the outer search loop to decide which modification to expand, and by nothing at task time.self_improve_step.pycalls the model withmsg_history=None, andbest_agent/self_evo.mdis a transcript of the improvement instruction rather than a record the next generation reads, so no generation inherits what its ancestors learned about themselves except as code. That is the guard-is-not-a-store shape at its strongest: the state is far richer than a workflow phase and still holds no claim that could be wrong, so there is nothing for a correction to attach to. Two things are worth taking from it anyway, and both are recorded in the note: judging a node by what its descendants achieve is the credit-assignment discipline the comparative report argues for on the memory side and finds nowhere, and versioning every self-modification as a git commit gets for free the undo Prime Agent builds by hand. It would enter this atlas the day a generation reads a durable record of what its ancestors tried.agentplugins/agent-plugins-sitewas examined and has no report: it is a documentation website. 120 files of Next.js and MDX serving "the official website for the Agent Plugins specification", with the spec itself pulled in throughspecification-source.json. Grepping its markdown for memory returns nothing, so neither the site nor the specification it renders defines a memory mechanism — there is no store, no retrieval and no correction to review. That negative claim has since been re-scoped, because the site is not where the specification lives.specification-source.jsonnames a second repository —agentplugins/agent-plugins-spec, at a pinned commit — as authoritative, and the site vendors its material intocontent/docs/for rendering; so the original grep covered the derived text rather than the artifact it derives from — the atlas's own "none found is a claim about a search" hazard, one level up from a directory and at a repository boundary instead. Read directly, the specification has no memory concept either: what a plugin declares is skills and MCP servers, andFUTURE_CONSIDERATIONS.mddefers a trust model, provenance signatures, secret scoping and "a standard event schema for plugin install, enable, disable, update, and uninstall actions" with retention and access policies — this atlas's vocabulary applied to the plugin lifecycle rather than to anything a plugin remembers. The exclusion holds, and now rests on both repositories rather than on the one whose name matched. The adjacency worth noting for later: a plugin packages Agent Skills, so if this standard is adopted it becomes a distribution format for skills as procedural memory — and nothing in it says whether a skill acquired from a plugin may be rewritten by the agent that runs it, which is the question that would put a future version in scope. Recorded rather than dropped for the same reason the atlas records other near misses by name: a reader who sees an agent-plugin standard in a list of memory candidates deserves to find out here that it is a spec site, not to re-derive it. A name collision worth flagging beside it:techtheist/engram, reviewed this round, is a different project from Engram (Gentleman-Programming/engram) already in the corpus, and is filed under the slugengram-alpha. Anyone reconciling lists by project name rather than by URL will merge them, exactly as theagentmemorycollision recorded above invites.pi-chatis a separate repository and was not reviewed; the claim that it injects two persistent memory files every turn comes from its documentation, not from its code.arXiv:2608.05466was examined and has no report, and its project site is the atlas's first sighting of an audit surface whose fixtures do not contain the artifact. Recursive Synthesis for Long-Horizon Terminal Tasks (5 August 2026, CC BY 4.0) synthesises 37,484 executable terminal-agent tasks over fifteen recursive rounds, and is out of scope on the ordinary basis: what persists is a task corpus, not a store an agent writes beliefs into. It is recorded because of its project site, whose fifth section is an "Audit layer" headed "Don't just trust our metrics. Inspect the task change, model trajectory, and rubric decision for the same case yourself." Read in a browser, the Trajectory Diff's two columns — a failed baseline and a successful run that earned verifier reward 1.0 — are byte-identical at every turn where both render, across four cases checked, and every turn past the baseline's length is blank on the successful side: in case 1 the baseline is 6 turns, the successful run is 21, and turns 7–21 carry no command, no response and no observation. The viewer prints "No Left turn at this index" when the baseline runs out, so absence is expressible and is not used on the other side. The rubric tab scores that case 94.5/100 with all six of its first criteria at the same 86% confidence, citing the same three turns, under a generated sentence calling itself an "evidence-linked deterministic assessment". The viewer repository says it ships "source code and small fixtures only", so these are fixtures behaving as fixtures and nothing here says the underlying runs do not exist — the gap is between what the fixtures are and the sentence they are published under. This atlas already names the harness's own output captured as evidence and published benchmark numbers without committed artifacts; this is the third and the most persuasive, because the first two look like missing work and this one looks like finished work. The paper was then read from its LaTeX source rather than from a rendering, which corrected this atlas's own first reading and found more than it did. Its flagship number disagrees with itself: the RL table and the abstract both give Qwen3.5-27B-RL as 49.44 on Terminal-Bench 2 for a relative gain of +20.00%, and the conclusion says 46.07 for +11.82% — both internally consistent against the 41.20 base, so one is a stale draft figure surviving into the conclusion of a published paper, in the headline cell of the headline result. That is the same hand-written-number-beside-generated-ones class this atlas spent three days removing from its own prose. Hidden-check protection reaches 63.5% at the final round, so roughly 36.5% of tasks still let the verifier check what the instruction does not establish — which is what the contract-validity gate exists to forbid, and it leaves under-specification as an unexcluded explanation for the headline difficulty result of a fixed solver falling from 90% to 2.5% pass@4. Neither that metric nor requirement coverage is defined anywhere in the paper. There is no ablation, no limitations section, and the lineWe release all synthesized tasks, sampled trajectories, and trained checkpointsis commented out in the source. See the note, which also records what the paper gets right and why its lineage-without-retroactive-removal is the tombstone gap in a training pipeline.arXiv:2608.00017was examined and has no report, and the reason is that its own advertised repository does not exist. Memory Reward Inflation in Self-Improving LLM Agents (submitted 29 June 2026) is the measurement behind a failure this atlas names in report after report and has never been able to price. An agent that stores each episode with a score and retrieves by similarity is running policy improvement whose reward is that score — and in deployment the score is the model's own assessment of its own output. The paper gives that failure two conditions rather than one: self-grades inflate wrong memories, and among wrong memories the inflation couples to reuse. The second is what separates it from LLM judges are optimistic — a uniformly generous grader changes no ordering, while a grader whose confidence in a wrong answer predicts how often that answer is retrieved builds a store whose most influential entries are its most confident mistakes. They call it the Echo Gap, and measure grader leniency at 31% for Claude Haiku 4.5, 54% for GPT-5.4-mini and 41% for frontier GPT-5.4, so it is not one family's artifact. Its central result is that a stronger judge is not the fix, formalised as the Error-Independence Assumption: a de-inflation signal must track truth and decorrelate its error from the self-grade bias, and where the verifier's error echoes the self-grade strongly, demotion makes the inflation worse at every step size. Global recalibration cannot repair the bank either, because a monotone map preserves the ordering retrieval and trust consume. That is the argument behind Engram Alpha's "exposure doesn't validate", reached independently and with an inequality attached — and it is the failure recorded here for Core Memory, NOOA, Mnemopi and PowerMem. Its algorithm, LUCID, is answer-free and makes no model call at all: it flags an episode when the SQL errors, times out or runs non-deterministically, when it returns empty or all-NULL, or when it filters on a string literal absent from the question — "a direct fingerprint of a value copied from a different, wrongly trusted memory" — and demotes the stored reward 1 → 0 without rewriting content. Precision 0.90 against a 0.46 base rate; recall low and argued harmless, since a missed wrong memory leaves the status quo and a demoted right one does damage. On the full BIRD development set with a memory-less control as the third arm, 52.4% → 54.0% → 56.9%. And it ships the placebo arm this atlas's benchmarks page asks for and finds in exactly one repository: budget-matched random pruning at the same 123 demotions harms the bank, taking 13 of its 15 genuinely correct memories, which is what makes the result about which rows are demoted rather than how many. And the artifact is missing. The paper states availability twice in the present tense — a footnote saying code, data and per-episode memory traces "are available at" a named GitHub URL, and Appendix F saying all of it plus exact run configurations and result files "are released at" the same one. Checked 10 August 2026, that URL returns 404, while the author's account returns 200 with 48 public repositories, none of them this one. So it is not a dead account, a rate limit or a rename with a redirect. The atlas already records published benchmark numbers without committed artifacts for Memvid, MemoryOS and FiFA; this is the sharper version, because those repositories exist and lack the result files while this result names a repository that is not there — there is no partial artifact to inspect. Nothing in that undermines the proofs, which stand on their own, but it removes any way to check that the three detector channels are what the prose says, that the Memento re-implementation is faithful, or that 0.90 falls out of the traces. Most likely a repository the authors intend to publish and have not yet made public. Worth re-checking: if it appears, this is a report rather than a list entry, and the per-episode traces would be the first artifact in this corpus that lets a reader watch a memory bank become corrupted. See the note, which also records that the paper carries no limitations section, and what its appendices do in place of one.Untrivial-ai/agent-orchestratorwas examined and has no report, and it is the atlas's own thesis implemented by something that is not a memory system. Apache-2.0, atb6609ae6…: a meta-harness running Claude Code, Codex, Cursor and others in parallel, each in its own git worktree, routing CI failures, review comments and merge conflicts back to the right session. The scope call is settled by the schema and confirmed by the vocabulary. Sixty-five migrations produce sessions, worktrees, cleanup facts, conversations, turns, messages, activities, provider events, projects, PRs, checks, comments, reviews, review runs, notifications, model usage and terminals — every one a record of what happened or what must happen next, none of them a claim that could be false — and across roughly 117,000 lines of non-test Go,recallappears twice andforgetsix times, every instance about the chat window or a terminal attachment. Neither the README, the design document norAGENTS.mduses the word memory about the product at all. Same boundary asos-factory/harandshepherd-agents/shepherdabove. What makes it worth recording is that AO is a derived copy of somebody else's memory, and it treats upstream forgetting as an obligation. When a person rolls back a turn the provider genuinely drops that turn and everything after it from the history it reasons over — "It changes what the agent remembers. AO's rows have to follow" — and following means five statements in one transaction: mark the turnsrolled_back_atrather than deleting them, because "'this exchange happened and was then taken back' is a different and more useful fact than 'this exchange never existed'"; settle a discarded-but-undispatched turn asinterruptedrather than leaving it queued against a history it was never written for; correlate compaction rows written by older AO builds without a provider turn id so the rolled-back filter hides them too; recompute the parent row's derivedcompacted_atfrom the surviving activities rather than patching it; and fail pending approvals inside discarded turns, a statement the comment says exists "so the invariant is enforced rather than argued". The read side filters a rolled-back turn's prose from the snapshot because "a person must never be shown prose the agent has forgotten", keeps AO's own bookkeeping rows visible because "hiding what AO cannot prove belonged to the discarded range would be a guess", and never renumberssequence, because "renumbering to close the gap would rewrite history to look like it never happened". That is the enumerated-derived-copies discipline this atlas asks about in every report and finds in almost none — written out as a list of every place the discarded fact had already been projected. Two smaller mechanisms are in the note:applied_titleas a compare-and-set witness holding "what I last wrote" so an automatic rename can tell its own value from a human's without awas_editedflag, which is the auto-update-versus-human-edit problem every generated profile field has; and compaction stored as a timeline row plus a state column, with the migration arguing why a parallel table was rejected. The doc comment says "the three statements commit together" and there are five, which is the ordinary fate of a count written in prose beside code that grew.Emericen/tiny-qwenwas examined and has no report: it is a model, not a memory system. MIT, at61ff9d42…: a ~1,600-line PyTorch re-implementation of Qwen with int4 quantization and a single-file terminal agentic harness. The scope call is settled by the vocabulary — across the.pytreerecall,remember,persist,store,session,sqliteanddatabaseappear zero times; the sevenmemoryhits are RAM ("peak memory is one tensor"), the twoembeddinghits are the model's token embeddings, and the twohistoryhits arereadline's input arrows. The harness's conversation is aself.messageslist held in process, and the only file writes inrun.pyare quantization output (quant.json, safetensors shards); nothing survives a session, so there is no claim that could be corrected. It is the cleanest kind of exclusion — not a borderline harness but a model implementation whose "memory" is the allocator's — recorded by name because a repository called qwen in a memory-candidate list deserves a stated reason rather than a silent drop.- Helm was read, not run. Three claims in its report are inferences
from code that a live database would settle: that
getAutonomyModereturns the stale pre-supersession row (argued from SQLite's partial-index eligibility and rowid scan order, and consistent with the 82 duplicate supersessions of that one key recorded in the project's own changelog); that the 500-row recall window is reached in practice, which depends on a fact count that is gitignored; and which of the three retrieval quality tiers a typical install actually runs, since the MiniLM model is an explicit opt-in download and all three tiers produce the same output shape. Helm's third memory surface could not be reviewed at all: twelvecortex.*tools are registered and documented as a five-layer memory stack, andworkspace/cortex/is gitignored and absent from the repository. maximem-ai/maximem_synap_sdkwas examined and has no report, and it is the closed-engine refusal in its purest hosted form. Apache-2.0, at0fd74edb…: the Python and JavaScript SDKs plus about two dozen framework integrations — LangChain, LangGraph, LlamaIndex, CrewAI, AutoGen, Google ADK, OpenAI Agents, Semantic Kernel and the rest. The README states the boundary itself — "The Synap memory engine itself (ingestion, entity resolution, retrieval, anticipation) runs as a fully managed cloud service operated by Maximem and is not open source. The SDKs in this repo are clients for that service; there is nothing to self-host, and an API key is required." The code confirms it: the durable operations —ingest_transcript,get_compacted,get_context_for_prompt,get_profileinpackages/sdks/maximem-synap/maximem_synap/sdk.py— arehttpxcalls toapi_base_url, and the substantial local modules are client concerns (auth, telemetry, transport, resilience) plus a client-side cache:cache/carries a local BM25 index, a SQLite backend, a short-term store and an anticipation cache that pre-fetches. So everything this atlas asks about — how a stored belief is resolved against an existing one, ranked, scoped, corrected or forgotten — happens in the closed engine, and the SDK caches its results in front of it. That is the closed-source-mechanism-behind-an-open-wrapper exclusion; its nearest neighbours arekunal12203/graperoot(an open repository around a proprietary pip package) andArtKeyAi/bhived-mcp(open transport posting to a closed API) above, and this is the hosted-service version those two are variations on. Its paper is the same system and the same limit. arXiv:2607.21503 — Agentic Context Management, Gaurav Dadhich, 23 July 2026 — names Maximem Synap as its reference implementation, argues that memory is a lifecycle rather than a store, and decomposes it into five primitives (architecting, ingesting, scoping, anticipating, compacting & consolidation). The framing is worth reading and adjacent to this atlas's own taxonomy; the evaluation is not checkable here. It reports 92% on LongMemEval and 93.2% on LoCoMo — the same figures the README leads with under a "#1" banner — run through the company's own separate harness (maximem-ai/memory_and_context_eval_harness) and published on a vendor blog, with no inspectable implementation at a pinned commit to check them against. That is the judge-the-code-not-the-claim posture this atlas applies to every leaderboard boast, and it is why a #1-on-two-benchmarks memory layer with an open SDK still earns a list entry rather than a report: what reads as reviewable is the client, and the thing being ranked is the part that is not there.SWE-agent/mini-swe-agentwas examined and has no report: its only state is the trajectory. MIT (Lieret and Jimenez), ~15,000 lines of Python ata83fcae8…, from the SWE-agent team and deliberately minimal — the agent class is awhile True: self.step()loop over aself.messageslist against a bash environment, with no tools. The scope call is settled by the vocabulary and confirmed by the design: acrosssrc/recall,remember,embedding,vector,forget,retriev,sqliteanddatabaseappear zero times; the threememoryhits are Docker RAM (--memory 4096), and the tenpersisthits are either an in-turn model-response contract (aFormatErrormust not lose the response) or the prompt telling the model that "Directory or environment variable changes are not persistent. Every action is executed in a new subshell." — the opposite of a durable store. Whatsave()writes is the trajectory (.traj.json): the message list, config, cost and exit status, and the README states the identity outright — "there's no difference between the trajectory and the messages that you pass on to the LM." So the persisted artifact is the conversation serialized and replayed by a trajectory browser; nothing is a claim that could be false and later corrected. Same boundary as Pi,shepherd-agents/shepherdandUntrivial-ai/agent-orchestratorabove — a harness that persists a run, not a memory that believes. Recorded by name because a widely-used agent from the SWE-agent lineage in a memory-candidate list deserves a stated reason rather than a silent drop.UOR-Foundation/UOR-Frameworkwas examined and has no report: it is a formal ontology, not a memory system. MIT, a Rust workspace plus 28 Lean4 proof files at51c01382…, encoding the UOR Foundation ontology — "a mathematical framework for content-addressed, symmetric, multi-metric object spaces with algebraic structure based on Z/(2^n)Z" — as typed Rust data inspec/and machine-generating it into JSON-LD, Turtle, OWL, SHACL and a Lean formalization. It is knowledge representation in the OWL/RDF sense: a vocabulary for describing objects — 34 namespaces and 474 classes of it — which is the kind of thing a memory system might be built on top of rather than a store of anything an agent believes. The vocabulary settles the call and also shows the trap.recall,remember,belief,LLMandpromptare zero across the tree, and the counts that look memory-shaped are all mathematics: the 146embeddinghits are algebraic embeddings ("Embedding is a ring homomorphism", "Embedding injectivity", "composition of embeddings is an embedding"), the 45memoryhits are ontology terms and RAM ("memory boundedness" as an axiom, "independent of physical memory layout"), and there is no vector store, similarity search or knn anywhere. Theclients/crate is build tooling —build,conformance,docs,website,crateandleanbinaries that regenerate the serializations from the spec. Nothing is captured, retrieved, scoped or corrected; there is no agent and no session state, only a specification and its proofs. Same relationship the atlas records forxataio/xataand the graph-database backends above — a substrate a memory system could stand on — recorded by name because embedding and content-addressing in a candidate list read as memory until you see they mean the algebra.EverMind-AI/Ravenwas examined and has no report: its durable memory is EverOS, which the atlas already reviews. MIT, ~105,000 lines of Python, a pre-alpha self-improving agent harness atcd686453…built on EverOS — pinned as the dependencyeveros==1.2.1— which supplies the durable user memory, agent memory and world knowledge the README credits. Raven's ownraven/memory_engine/(6,102 lines) is a pluggableMemoryBackendprotocol whose shipped durable backend is EverOS, plus SkillForge, a skills-as-procedural-memory router that RRF-fuses skill hits from local files, an external hub and the EverOS skill source behind a gate, and importers that scan a Claude Code history into memory. So the belief store is a reviewed dependency and Raven's own contribution is routing, importing and skill evolution over it — the same call the atlas makes fornetease-youdao/LobsterAI(operates OpenClaw's memory) andomnigent-ai/omnigent(mounts Hindsight). The EverMind ecosystem's dedicated memory repositories — HyperMem and EverMemBench — are separate and were not examined here. If Raven grows a durable store of its own rather than a router over EverOS, the call flips.zjunlp/SciAtlaswas examined and has no report: it is a literature knowledge graph behind a hosted API, and nothing a user or an agent concludes outlives a run. MIT, 77,560 lines of Python across 214 files from 58 commits between 20 April and 16 July 2026 by five authors, read ata9a345da…, with a paper at arXiv:2605.22878. The graph links papers, authors, institutions, venues, keywords and citations to a four-leveldomain → field → subfield → topictaxonomy, and the repository packages a client for it: the README's own framing is that a user installs withpip, registers a token and works "without setting up Neo4j, maintaining graph data, or touching backend infrastructure". The local pipelines can be pointed at abolt://localhost:7687of your own, and no graph data ships. The scope call is the one already drawn forkivgraphandcodebreaker77/Fullerenes, one domain over: a corpus index of published work, regenerated from the corpus, where correction means re-ingesting rather than revising a belief. Two searches settle it. Across 214 Python files the memory vocabulary is absent — every occurrence ofrecallis the IR metric or a retrieval-arm name (--kg-topk-title-vector, "embedding recall path"), andremember,forgetandepisodicappear nowhere. And nothing reads a prior run:runs/<run_id>/holdsrequest.json,response.json,summary.txtandreport.mdas per-run artifacts, and no code path lists or loads an earlier one. The CLI's "skills" are the nearest thing, and they are hand-edited JSON presets loaded from./skills/,~/.sciatlas/skills/orSCIATLAS_SKILLS_DIR— saved parameter sets a person writes, not procedural memory the system accumulates. Recorded for three things a reader can take. The taxonomy is a retrieval axis rather than a label: a search can propagate along the subfield hierarchy as well as along citations, which is the structural answer to the vocabulary-gap problem several stores in this atlas hit with embeddings alone. Each workflow ships aflashand afullpreset — a cheap first pass and an expensive second, chosen by the caller — which is the gate-the-expensive-path shape applied to research rather than to retrieval. Andagent-skill/packages sevenSKILL.mdfolders that migrate the workflows into Codex and Claude Code, whose stated contract is zero-start: the agent installs the CLI, guides registration, and asks the human only for values a human must supply. Two things sit against it. Every documented endpoint is plainhttp://— the registration page that issues a personal token, the token-status endpoint, and theSCIATLAS_API_BASE_URLthat token is then sent to — so the credential travels in the clear. Andliterature_review_pipeline/kg_search/config.pydefaults its embedding and reranker paths to/home/weiyunxiang/yunx/hf-models/…, a specific researcher's home directory, so the documented defaults resolve on one machine. Screened before reading: no auto-run surface, no manifest inside the seven-day cooldown, no build-time execution path and three unpinned dependency surfaces; nothing was installed or run.codebreaker77/Fullereneswas examined and has no report: it is a code index, and the one thing in it that behaves like memory is the thing that can delete a hand-written file. MIT, 3,774 lines of TypeScript across twenty-five files in three packages — core, CLI, daemon — from eleven commits between 25 and 28 April 2026 by one author, read atcf0bb643…. The README calls it "persistent local memory for AI coding agents"; the store is.fullerenes/graph.dbwith four tables —nodes(functions, classes, modules from tree-sitter),edges(calls, imports, inherits),files(a content hash per path for incremental indexing) and ametakey-value pair holdinglast_indexedand an indexing-statistics blob. Every MCP tool is a graph query —query_codebase,get_callers,predict_impact,get_subgraph— andpredict_impactwalking incoming dependency edges three hops to a blast radius is a genuinely useful thing to hand an agent before it edits. The scope call is the one already drawn forkivgraph,DeusData/codebase-memory-mcpand Kodiak: a corpus index of the user's source, regenerated from the source, where correction means re-indexing rather than revising a belief. Nothing an agent or a person concludes is stored —grep -rn 'CREATE TABLE' packages --include='*.ts'returns those four tables and no fifth. Recorded because of what the generators do to the file the agent actually reads.fullerenes init,fullerenes indexandfullerenes watchall regenerateCLAUDE.md,AGENTS.mdand a Cursor rule from the graph, andpackages/cli/src/generators/files.tsmerges rather than clobbers: it strips its own<!-- BEGIN FULLERENES -->block and keeps whatever else the file held. Then, on the text that survived, it runscleaned.includes('# Codebase context')— and on a match setscleaned = ''. That heuristic exists to clean up unmarked files from an older release, and# Codebase contextis the generated block's own first heading and an entirely natural heading for a hand-writtenCLAUDE.md; the same discard fires on the substringAuto-generated by Fullerenes.fullerenes watchruns the generators on a one-second debounce after any source change, so on a watched repository the check is not a one-off. A hand-written agent-instruction file is the smallest memory a coding agent has, and a substring test is not a safe way to decide it is disposable. No tests of any kind:find packages -name '*.test.ts' -o -name '*.spec.ts'returns nothing, and the twenty-onedescribe(/it(/expect(hits are all.split(andParser.init(matching the pattern. Screened before reading: no auto-run surface, four unpinned dependency surfaces and a lockfile unchanged for 136 days; nothing was installed, built or run.Luqueee/kivgraphwas examined and has no report: it is a code index, and what is worth taking from it is the axis it keeps apart. Apache-2.0, 182,614 lines of Go plus TypeScript and Python workers, 803 commits since 4 August 2026, read at0633a6b5…. A cross-repository code-intelligence MCP server: it resolves edges withgo/types, the TypeScript checker andrust-analyzerrather than by matching names, and serves the result as an immutable graph. The scope call is the one already drawn forDeusData/codebase-memory-mcp,VectorSpaceLab/general-agentic-memory, Kodiak andperplexityai/numbat— a corpus index of the user's source, regenerated from the source, where correction means re-indexing rather than revising a belief. Nothing an agent concluded is stored: the MCP surface is queries plusindex_projectandgraph_status, andinternal/auditstates the property that settles it — "Nothing here writes. A remedy is a proposal… and Kivgraph does not write inside the code it indexes." Across the Go tree every occurrence ofmemoryis RAM, andrecall,rememberandbeliefappear nowhere. Recorded because it implements, one domain over, the shape this atlas asks memory systems for and rarely finds.internal/facts/codes.gofreezes two axes and keeps them apart: six ordered confidence codes —ExactTypechecked,ExactDeclarationMapped,ExactPackageMapped,StructuralCertain,Candidate,Unresolved, ordered "strongest first, so a comparison on the code is a comparison on strength" — beside a separate provenance axis naming which analyzer produced the edge (GoTypesDefinition,GoASTCall,TypeScriptChecker, …). A syntax-only fallback is admitted as a candidate and refused as knowledge — "Syntax-only fallbacks may still provide useful candidate edges, but they must never be published as exact knowledge" — and the axis is not decorative:internal/hotsnapshot/traversal.go:148filters every edge bycodeAllowed(edge.Confidence, options.Confidences), under a committed test named for it. Beside that,SemanticUnresolvedrows carry aReasonfor each reference the analyzer could not resolve, so the index ships its own coverage gaps. Read against the corpus this atlas holds, that is a discrete ordered status that withholds, kept apart from where a claim came from, and applied on the read path — the combination 187 systems here express as a single float, and the reasontrust_stateis the mark most often refused. And the README states the retrieval consequence better than most memory systems state it about themselves: because the edges are type-resolved rather than name-matched, "an empty reference list means nobody calls it, not that nothing was found, andgrepcannot tell those apart." That distinction — evidence of absence against absence of evidence — is what this atlas's negative-retrieval mark asks a test to establish, here made a property of the read path itself. The reversal condition: a store beside the graph holding something an agent concluded about the code rather than something a type checker derived from it.Arc-Computer/ATLASwas examined and has no report: it is an offline training engine, and the store it trains from lives in a different repository. Apache-2.0, 11,250 lines of Python, read atc226386f…, the head ofmainand dated 23 January 2026. Atlas Core takes a JSONL export of agent episodes and trains a teacher checkpoint from it by on-policy distillation or GRPO; the README is explicit that the runtime half — the dual-agent loop that captures the traces, the session review that approves or quarantines them, the Postgres they land in — is the separateatlas-sdk. What remains here consumes run records and emits model weights, which is the scope line already drawn for OpenHands SDK andDevrG03/AgentMesh: a trace of what an agent did cannot turn out to be false, so neither the export nor the checkpoint is a store of claims. The code confirms it rather than the prose alone —src/atlas_core/runtime/is two files,schema.pyis 200 lines of dataclasses that readadaptive_summaryandtriage_dossierback as opaqueOptional[Dict[str, Any]], and nosqlite,psycopg,sqlalchemyorpersonasymbol appears anywhere undersrc/. Every match formemoryin the tree is GPU memory in the vLLM and Ray generation paths. The reversal condition is the sibling repository: the review-and-quarantine gate the quickstart invokes, and whatever persona state it governs, is a memory surface and is not in this tree.DevrG03/AgentMeshwas examined and has no report: it is a workflow execution engine, and nothing it persists is a claim that could be false. A C++20 control plane — 26 headers and 26 translation units, a DAG scheduler with atomic in-degrees, a priority ready queue, a thread pool, and a pybind11 adapter that compiles a LangGraphStateGraphonto it — read atae2e2dac…, 9 commits since 18 August 2026, with no licence file and no licence claim anywhere in the tree, so a reader has no grant to rely on. The scope call is settled by what the store holds.IStateRepositorypersists aWorkflowExecution— an id, aWorkflowState, a map ofTaskExecutionrecords, and start and completion timestamps — into two Postgres tables,workflows(workflow_id, state, started_at, completed_at)andtasks(workflow_id, task_id, state, attempt, result_success, result_output, result_error, …); the only read-back isloadActiveWorkflows(), documented "for crash recovery and scheduling" and filtered to Pending or Running. That a task ran and returned a string is a fact about what happened, and applying the per-mark scope test to it gives the same answer as for OpenHands SDK,os-factory/harandperplexityai/numbat: it cannot turn out to be false, so an audit of it is notaudit_logand a snapshot of it is not memory. The vocabulary confirms it — acrossinclude/,src/,apps/andpython_adapter/, every occurrence ofmemoryis RAM ("memory bloat", "prevent memory leaks",InMemoryStateRepository), andrecall,knowledgeandembeddingappear zero times. Unlike OpenHands SDK there is no memory sitting beside the engine to report on. Recorded rather than dropped for the benchmark artifact.benchmark_analysis.mdpublishes an eight-row matrix against LangGraph — 1,900× on in-memory hops, +5.0% and +2.7% on replayed swarms with paired t-tests, 95% less RAM — and the repository commits exactly one head-to-head result set,benchmarks/langgraph_comparison/results_langgraph.jsonbesideresults_agentmesh.csv, 100 paired runs each. It recomputes cleanly and honourably: 50.77 ms against 39.02 ms, 23.1% faster. It is also not any of the eight published rows, and none of those rows has a committed artifact behind it — the committed file's ownpeak_ram_mbof 83.1 for LangGraph is a third of the matrix's 240 MB, because they are different measurements. The shape is worth naming because it is the inverse of the failure this atlas usually records: not a claim with no evidence, but a genuine committed measurement standing next to a headline table it does not support. The reversal condition, should anyone return to this: a store that outlives a workflow and holds something an agent concluded rather than something the engine did.aimultiple.com/ai-memorywas examined and is not a reviewable system: it is an analyst survey with an embedded benchmark. The page introduces RELC-Bench (100 items over 14 transcripts) and surveys consumer and enterprise memory — ChatGPT, Claude and Gemini memory, Mem0, Zep, LangGraph and others — but it is a web article, not code at a pinned commit, and no committed harness or result file backs RELC-Bench where the atlas can read it. The open, inspectable systems it names are already reviewed here; the rest are hosted products on the closed-engine side of the line. Recorded so a reader arriving from that page finds why it is not itself an atlas entry.DeusData/codebase-memory-mcpwas examined twice and has no report: it is a code-intelligence engine, not agent memory, and the reversal condition set at the first reading is still unmet. MIT, a pure-C native binary re-read at997d087b…, 264 commits on: 158 languages through tree-sitter with a Hybrid-LSP type-resolution layer, full-indexing a repository into a persistent knowledge graph of functions, classes, call chains, HTTP routes and cross-service links, now answering over 32 MCP tools where the first reading found 15. Its durable store is that graph —nodes,edges,file_hashes,index_coverage,lsp_surface— a corpus index of the user's source, regenerated from the source, the boundary already drawn forVectorSpaceLab/general-agentic-memory,ShamGaneshan2008/Kodiak's ChromaDB source index andperplexityai/numbat. The one agent-memory surface is still one document. The first reading said the call would flip if the ADR store "grew into a real belief store — multiple records with status and correction semantics." It has instead grown a better editor:manage_adrgained aset_sectionsmode that "rewrites only the named sections and leaves every other byte of the stored document untouched," with idempotency stated for the case that matters — "setting the same section to the same body twice leaves the document byte-identical, so retrying after a lost response is safe." That is memory as an editing surface done carefully, and it is still a single row:cbm_store_adr_getreadsproject_summaries, whose primary key isproject. No status, no supersession, no per-decision identity, no scope below the project. The table it shares is the tell — the other columns aresummaryand asource_hash, so an authored decisions document and a regenerable derived cache occupy the same row shape. Its own preprint is arXiv:2603.27277, on tree-sitter knowledge graphs for code exploration.arXiv:2309.02427was examined and has no report: it is a framework, not a system. Cognitive Architectures for Language Agents (Sumers, Yao, Narasimhan & Griffiths, 5 September 2023, revised through March 2024) proposes CoALA — a language agent as modular memory components (working, episodic, semantic, procedural), a structured action space over internal memory and external environments, and a generalized decision loop — and uses it to survey the field. It is foundational to how this atlas reasons about memory kinds, but it defines a taxonomy rather than shipping an implementation: its companion repository,ysymyth/awesome-language-agents, is a curated link list, so there is nothing to review at a pinned commit. Recorded as the conceptual lineage behind the working/episodic/semantic/procedural split that recurs across the corpus — most explicitly in Memmy's L1→L2→L3→Skill layering and the cognitive-taxonomy stores — and as the survey a reader should read before the code, not instead of it.developers.openai.com/cookbook/examples/agents_sdk/context_personalizationwas examined and is not a reviewable system: it is an official tutorial. OpenAI's Agents-SDK cookbook demonstrates state-based long-term memory — a structured state object injected into the system prompt at session start, new preferences distilled through tool calls during the conversation, consolidated into long-term storage by an LLM call, and reused next session, with a global-versus-session scope split resolved by precedence (latest input → session override → global default). It is a notebook-style walkthrough over an in-memoryTravelStatedataclass with no persistent backend, not installable code at a pinned commit, so it cannot be reviewed on this atlas's terms. Worth recording because it is OpenAI's own illustration of the inject–distill–consolidate–reuse shape that several reviewed systems build over a real store, and because it names recency-weighting, confidence and TTL as notes a memory should carry — the affordances this atlas keeps checking for — while leaving them to the reader to implement.wangpan-ustc/AtlasVAwas examined and has no report: its "memory" is RL training state, not agent belief. Self-Evolving Visual Skill Memory for Teacher-Free VLM Agents (arXiv:2605.17933), Python over a vendoredverlRL backend atc3e12ea0…. Its three-layer "visual skill memory" — spatial heatmaps, visual exemplars and symbolic text skills — is evolved from a training run's own trajectory statistics into danger and affinity atlases that provide dense, coordinate-aware reward shaping for reinforcement learning on Sokoban, FrozenLake and embodied navigation. The vocabulary settles it:recall,remember,sqliteandCREATE TABLEare zero, whilereward/trajectory/rollout/RLappear ~1,500 times. This is optimizer/training state that produces a policy — the same boundary the atlas draws for the Gödel-machine lineage and for weights as memory — not a store an agent writes a belief into and later corrects across sessions. Memory-branded and paper-backed, so recorded by name; a visual skill memory that shapes RL reward is not what this atlas means by memory.walkinglabs/learn-harness-engineeringwas examined and has no report: it teaches the shape rather than shipping it. MIT, 246 commits, at12fc49c9…— a course on building agent harnesses, 1,729 Markdown files because every lecture is translated into a dozen languages, beside six numbered example projects and askills/harness-creator/. The SQLite andCREATE TABLEhits a probe returns are lecture code samples underdocs/<lang>/lectures/, not a store, and there is nothing to pin a mechanism claim to. One reference page is worth taking,skills/harness-creator/references/memory-persistence-pattern.md, because it states as a rule the crash-ordering property this atlas praises where it finds it. Its two-step save invariant: write the full content to a topic file first, then append the one-line pointer to the index, "if the process crashes between steps, the worst outcome is an orphaned topic file — the index remains consistent". That is PLUR1BUS's ordering discipline — durable before superseded — written as a teaching rule rather than discovered in a diff, and it sits beside a scope-precedence ladder (organization → user → project → local) and a three-layer split of instruction memory, agent-written auto-memory and background session extraction. The course enters the day one of its six projects ships a store rather than an illustration of one.ai-boost/awesome-harness-engineeringwas examined and has no report, for the reason the atlas already gaveysymyth/awesome-language-agents. CC0, 233 commits, atfae9622e…— a curated list: seven Markdown files, a banner, averify_urls.pylink checker, and a 630-line README carrying 224 GitHub links. There is no implementation at a pinned commit, so there is nothing this atlas's method can read. Recorded because a reader who finds it while looking for harness memory should know it is a directory rather than a system, and because a link list that ships its own URL checker is doing more than most.towardsai/ai-tutor-appwas examined and has no report, and it is worth recording as a worked implementation of a retrieval idea rather than as memory. Apache-2.0, 15,330 lines of Python acrossapp/andevals/, 227 commits since 30 January 2025, atb04c0a03…— an agentic RAG tutor behind a LangGraph agent core, and the backing repository for a workshop on context engineering. Its long-term memory is a student profile that does not outlive the process, and the code says so at the definition:STORE = InMemoryStore(), under a comment reading "In-process like the checkpointer: profiles survive across threads/sessions within one server lifetime… Swap for a persistent LangGraph store to survive restarts." The profile has a real identity — namespace("student", <id>), keyprofile, updated by_update_student_profileand appended to the system prompt — so it is the shape of a memory without the durability, and the atlas draws the same line here it drew where nothing survives the process. Everything else in the repository is on the other side of a boundary this atlas already keeps:memory_presets.pybundles summarization and tool-output-clearing middlewares, which is conversation-window management, and the knowledge base is a corpus index of the course's own material. What is worth carrying iskb_shell.py, and it is the same idea as arXiv:2605.05242 — Beyond Semantic Similarity: Rethinking Retrieval for Agentic Search via Direct Corpus Interaction (Li et al., 3 May 2026), which argues that a fixed similarity interface is the bottleneck and has agents search raw corpora with general-purpose tools instead, reporting gains over sparse, dense and reranking baselines on BRIGHT and BEIR. The repository ships that as an agent-facing tool with the hardening the paper does not have to specify: an allowlist of exactlyrg,grep,find,ls,sed,head,catandwc, a refusal of every shell metacharacter that would compose them (|,&&,;,>, backtick and the rest), an eight-second timeout and a 40,000-character output cap. Anyone giving an agent grep over a corpus needs that list; it is a better starting point than writing it from scratch. Itsevals/also holds a named-preset comparison —compaction_study.pyasks whether a long established context is better kept every turn or compacted, holding the rest constant — which is the harness shape the benchmarks page keeps asking for, pointed at context management rather than at memory. ai-tutor-app enters the day the student profile is written somewhere that survives a restart.a40-labs/memory-bench, which GitHub redirects to from its former namea40-labs/memory, was examined and has no report, and its second half is the nearest thing the corpus has to an answer to what this method structurally cannot reach. MIT, 35 commits, atf53ad5f6…. The screen returned NOTHING SCANNED — no manifest, hook or agent file anywhere, because the whole repository is thirteen stdlib Python scripts and thirty-four JSON row dumps. Its measurement half is already on the benchmarks page: per-question rows behind every published table, one verification script per benchmark recomputing each figure against aPUBLISHEDconstant, and averify_all.pythat closes by enumerating the three published scores it cannot check and why. The half worth recording here issystems/file-based/, 1,154 lines that reconstruct Claude Code's auto-memory as runnable stdlib code — a curatedMEMORY.mdindex, topic files with a four-type taxonomy and anoriginSessionId, an index preload cut at 200 lines or 25KB measured after frontmatter and block comments are stripped, a silent-overflow warning, a staleness notice on aged reads, and literal-plus-regex grep with bounded output. It is not a memory system this atlas can report on: nothing in it is a store an agent writes a belief into and later corrects, and the thing it models is closed. What transfers is how it handles that. Its own README states the problem — the best-documented instance of the shape "is closed-source and cannot be lifted", so "fidelity therefore rests on traceability" — and the survey it implements grades every claim it makes about the closed original: 12[official], 3[corroborated], 3[single-source], 1[rumor]. The 22 tests cite the survey section whose claim each one pins. So a reader can see which behaviours are documented by the vendor and which are community inference, rather than being handed a reconstruction and the word faithful. That is the discipline this atlas asks of a capability mark, applied to a system nobody outside the vendor can read — and it is the shape to copy if the hosted systems named above are ever going to be discussed on evidence rather than on their marketing.warpdotdev/warpwas examined and has no report, and it is the cleanest example in the corpus of a published contract with an unpublished mechanism. Dual AGPL-3.0 and MIT, 3,983 Rust files and 278 SQL migrations, 2,120 commits since 28 April 2026, atd13a30f4…— the Warp terminal's own client. It has agent memory, and the memory is the part that stayed on the server:app/src/server/server_api/ai.rsis a REST client againstmemory_stores/{uid}/memories, so extraction, retrieval, deduplication and what a tombstone does to a read are all outside this tree. That is the atlas's stated exclusion — the mechanism closed behind an open wrapper — and it is worth recording rather than passing over, because the contract those serde types describe is more complete than most systems here implement. AMemoryItemcarriescontent, aversion_id, asource, asource_idand asource_run_id— provenance down to the run that produced it — besideis_tombstonedandtombstoned_at. AMemoryVersionItemcarries a full priorcontentand thereasonit changed.CreateMemoryRequestandUpdateMemoryRequestboth takereason: String, not anOption, so the API cannot be called without saying why — a discipline MindCache, Aura and most of the trust-state family do not impose on their own writes. A store has anowner_typeandowner_uid, and agents attach to it through anAgentAttachmentItemcarrying anaccesslevel. Two findings survive being unable to read the server.MemorySourceis an enum with exactly one variant,Manual:source_idandsource_run_idexist on the read model and imply a server that writes memories from runs, and nothing in the open client can produce anything but a memory a person typed. Andis_tombstoned/tombstoned_atare deserialised and read nowhere inapp/— the client is told which memories are dead and does not filter, mark or otherwise act on it, so whether a tombstoned memory stops being retrievable is decided somewhere a reader cannot check. What the client does own is not memory:project_rulesis(id, path, project_root), a registry of which rule files exist with their content left on disk, andagent_conversationsis transcript persistence, which is the conversation-window boundary. One screening note, because a vocabulary probe on this repository lies:tombstone,supersedeandforgetreturn dozens of hits inflated by a committed BERT tokenizer vocabulary and the vendored Alacritty licence, and once those are excluded the remainder are TUI event tombstones, recalling a command from shell history, andcore::mem::forget. Warp enters the day the store behind that API is inspectable at a commit, or a client-side memory gains a correctable identity of its own.google/samwas examined and has no report: it is the network agents talk over, and the one mechanism worth taking is an access-control property, not a memory one. Apache-2.0, 46,820 lines of Go across 145 files, 1,130 commits since 18 April 2026, atb42aaaf2…— Sovereign Agent Mesh, a zero-config, zero-trust libp2p fabric in three components (sam-control-planefor identity registration and policy,sam-routerfor bootstrap and relay,sam-nodefor local transport and MCP sidecar routing) that lets autonomous agents discover each other and invoke each other's tools. The control plane's twelve tables settle it and none of them holds a claim:nodesandroutersare membership,keyring,bootstrap_tokensandenrollment_requestsare key material and joining,users,roles,role_permissions,role_bindingsandpoliciesare RBAC,rotation_lockis a mutex andschema_migrationsis bookkeeping. Identity, authorization and coordination state — the boundary already drawn forUntrivial-ai/agent-orchestrator,perplexityai/numbat,os-factory/harandCohexa-ai/agent-coherence. The vocabulary is clean rather than merely quiet:recall,belief,supersede,tombstoneandforgetare zero, the singlerememberis a comment about caching a failed dial so a node does not retry into a fifteen-second timeout, and all seventeenmemoryhits are in-memory hosts in tests. What transfers is how it says no. Authorization is Biscuit tokens — Datalog policies carried in the credential and verified offline — and a node attenuates its own token from config, addingAttenuation.Policies,.Checksand.Rules(internal/node/config.go:48-66), withAuthorize()enforced atinternal/node/middleware.go:170,internal/controlplane/server.go:863and insideinternal/identity/biscuit.go. Attenuation is one-way: a holder can mint a strictly weaker token and cannot mint a stronger one, and a verifier needs no call back to the issuer to know that. That isscope.caller_cannot_widenas a cryptographic property rather than a code review. Most systems in this corpus implement scope as a predicate the caller supplies, which is precisely the widening hazard the test exists for; SAM enforces the same property at the transport, where the caller cannot reach it. Nothing here remembers anything, and the mechanism is still the clearest answer in the corpus to a question memory systems keep failing. sam enters the day the mesh carries a durable claim about a peer that a later reading could contradict — a reputation, a trust score, a record of what an agent got wrong.Tencent/UI-Matewas examined and has no report: its procedural memory is a file you hand it and a checkpoint you download. Apache-2.0, atd2b2e0ae…, 13 commits since 14 August 2026 — a foundation GUI agent from Tencent HY Frontier with a technical report at arXiv:2608.15930 and checkpoints on Hugging Face, of which this repository is the inference side: 2,020 lines of Python across four files, plus example resources and screenshots. The screen reports NOTHING SCANNED — no manifest, hook or agent file at any path it knows — and reading the tree by hand explains it rather than contradicting it: twenty-nine files, no build file, no dependency declaration. It is here because the pitch is procedural memory almost exactly. "Show the workflow once. Let the agent adapt it to the task at hand": a successful desktop run, already segmented into subtasks, is distilled into per-turn guidance — a subtask checklist, a completion criterion, key milestones — that the model folds into its prompt, with the pointer advancing when it reportssubtask_complete. What settles it is the direction of the arrow, stated in the source's own comment: "the workflow writes them, the agent only reads them." Every reference to atrajectory_captioned*.jsondemonstration is a load, a glob or a raise-if-missing; nothing in the tree writes one, so a completed run teaches the next run nothing.reset()clears an index and a boolean, which is the whole of what survives a step. The rest of what persists is the checkpoint, which is the weights boundary, and a prompt prefix held stable for vLLM's cache, which is the KV-cache boundary. One design note is worth taking even though the system is out of scope, because it inverts the failure this atlas keeps reporting: coordinates from the demonstration are never replayed and the live screenshot is authoritative, so the stored procedure is explicitly subordinate to present observation rather than trusted over it. UI-Mate enters the day a finished run is distilled back into a demonstration the next one consults.zenml-io/kitaruwas examined and has no report: it judges agents, it is not memory for one. Apache-2.0, 72,947 lines of Python and 33,295 of TypeScript over FastAPI and Postgres, 865 commits since 5 March 2026, atf32a0911…— replay-based evaluation from the ZenML team: production runs are recorded or imported from Langfuse, LangSmith, Braintrust or Logfire as sessions, then re-executed against a changed model, prompt or working tree. Twenty-six tables and twelve MCP tools, so a reader would reasonably check. The store is measurement state. Sessions are recorded traces — acts, not claims — cohorts freeze a population, experiments and replays record what was run, and the agent under test never consults any of it as belief: replay answers its tool calls from the recording. Same boundary aspingdotgg/t3codeand the harnesses on the benchmarks page. The vocabulary confirms it rather than merely failing to contradict it:remember,recall,beliefandtombstoneare zero acrosssrc/, the threesupersedehits are a worker's task-claim lease being taken by a newer attempt, and all fourmemoryhits are RAM. The one claim-shaped row is the annotation, and it is worth recording because the atlas's own finding appears here one level up. A human judgment is stored with an owner, aquestion_key, a JSONBselectorpinning it to an exact trace location, and a JSONBvalue— provenance most memory systems in this corpus do not manage for their own beliefs. ThenAnnotationService.update_annotationcallsAnnotation.update_valueand writes the row back, so a revised judgment overwrites the previous one in place and nothing retains what it said: noprevious_value, no supersession, no audit row. The analytics stream is not the missing record either —build_annotation_created_propertiesfires on creation only, and carriesinvestigation_answerandhas_selectoras booleans rather than the judgment itself. These judgments are what calibrate the evaluators, so the one artifact whose correction history would matter most is the one kept without it. kitaru enters the day the agent under test reads a kitaru row as a belief about its task rather than a fixture for its replay.tobi/qmdwas examined and has no report: the agent can search it and cannot write to it. MIT, 40,233 lines of TypeScript acrosssrc/andtest/, 668 commits since 7 December 2025, atfacd35e0…— an on-device search engine over your own markdown, fusing BM25 and vector search with an LLM reranker, every model local throughnode-llama-cpp. Its README calls it "an on-device search engine for everything you need to remember", which is why a reader would expect it here. Four tables settle it:contentis content-addressed by hash,documentsmaps a collection and path onto one of those hashes, andllm_cacheandcontent_vectorsare derived from both — every row regenerates from files the user wrote, and nothing in the store is a claim qmd made that a later reading could contradict. The MCP surface confirms it from the other side:query,get,multi_getandstatus, all read-only, so the model can retrieve a document and cannot deposit one. Same boundary asDeusData/codebase-memory-mcp,VectorSpaceLab/general-agentic-memoryandperplexityai/numbat— a corpus index of the user's own material. The vocabulary is a trap worth naming, because grepping for it would mislead:recallappears 52 times and every one isrecall@kin the benchmark harness, the singletombstonemarks a soft-deleted row whose file has vanished so its content can be collected, andremember,belief,supersedeandprovenanceare all zero. What transfers issrc/trust.ts, and it is better than the approval gates several memory systems here ship. A project-local.qmd/index.ymlarrives with agit cloneand is adopted automatically for any command run inside the tree, so three fields in it can reach outside the project: anupdate:shell command, a collection path, and a model URI. Those three are gated and nothing else is — the user's own global config is never gated, and neither are in-project paths or the built-in model defaults, so the prompt fires where it is warranted rather than everywhere. Approval is recorded per config file and per gated set as a digest intrusted.json, and editing the hook, repointing the collection outside the project or changing the model URI changes the digest and re-arms the gate, which is the property a one-time "trust this folder" prompt does not have.decideLocalConfigGatehas a production call site atsrc/cli/qmd.ts:811, denies by skipping when there is no TTY to confirm on, andtest/update-hook-trust.test.tscovers both decision functions — producer, consumer and test all present, which is more than the corpus's median for a mechanism of this shape. qmd enters the day its own store holds something the source files do not: an agent-written annotation, a status, or any row with a lifecycle of its own.WujiangXu/A-memwas examined and has no report because the atlas already reviews the same system. It is the A-MEM paper's (arXiv:2502.12110) author-side reproduction repository at0c8039f2…— its own README says it "is specifically designed to reproduce the results presented in our paper." The atlas's a-mem report coversagiresearch/A-mem, the lab copy of the same paper's code (capabilities: ""); this is the first author's copy of the same project, a distinct git history rather than a different system. The README points to a third repository,WujiangXu/A-mem-sys, as the "official implementation... for building your agents", which is the one that could diverge from the reviewed copy — it was not examined here, and if it carries mechanisms the reproduction repo does not it is the better subject. Recorded so a reader reconciling three A-mem URLs by name finds they are one paper's code, already reviewed once.Adolanium/hermes-officewas examined and has no report: everything it stores is drawn, and none of it is read back to an agent. MIT, 17 commits since 16 August 2026, at9e960c1b…— a 4,409-line desktop plugin that renders one floor of desks, one per Bot Mode agent, over the same live data Bot Mode already uses. The screen returned NOTHING SCANNED: no manifest, no hook, no agent file, because the repository is one plugin file, a preview tool and a test. It earns a named exclusion rather than a silent drop because it does pass the letter of the admission test and misses its point. Durable, identity-keyed state survives the session in two places —savePrefputs trophies, the monthly and weekly recaps, pending news and dismissed hints through the host's plugin storage, and a finished task callsprofiles.configurewithui_meta.<office-namespace>.stars, a per-bot count written onto the bot's own profile so that, in the README's words, the stars "follow the bot, not the machine", and read back on the next load. That is something stored, with an identity, correctable later. The read side settles it: nothing the plugin stores ever reaches a model. The only text sent to an agent isprompt.submitcarrying the task the user typed into the bar; the star count, the recap and the employee-of-the-month portrait are read by the diorama to draw a nameplate and a wall. The atlas's admission test is shorthand for a store an agent writes a belief into and later corrects, and a scoreboard for paper dolls satisfies the shorthand without being one — which is the useful part, because the same shape describes any interface that persists per-agent decoration beside a real memory system and would read as memory in a directory listing.calibrae/bucciaratiwas examined and has no report: nothing it stores ever reaches the model unasked, and its honesty about one invented number is the reason to record it. MIT, 2,472 lines of Rust, 3 commits since 26 April 2026, at9db66bf5…. It is an MCP server over an mdBook wiki — ten typed tools for status, list, read, write, summary, move, search, delete, image upload and publish — and it says what it is not: "No reqwest, no embedding model — pure filesystem + subprocess." The scope test that settles it is the read path. There is no injection, no session hook and no boot read:wiki_readtakes a slug the model must already know andwiki_searchtakes a query the model must already form, which makes the pair indistinguishable in kind fromfile_readandrg. What survives a session is a published document set — the terminal operation ismdbook build— and the installer creates awikigroup "so any wiki-group editor — human or agent — can update pages", which is the right design for documentation and the wrong shape for a belief store. Compare NanoClaw, whose memory is also Markdown and is memory because two files enter the context window at every new session. What transfers is a design criterion this atlas argues for and rarely sees stated as one: bytes returned to the agent. Every response "drop[s] null fields, omit[s] empty arrays, and skip[s] mdbook's success boilerplate", andwiki_searchships budgets rather than a limit — 3 matches per page, 20 pages, 200-character snippets by default, a hard ceiling of 1000 and a floor of 44 — with truncation flags on both axes, so a capped result reports that it was capped instead of arriving as a short list. That last property is exactly what repowise's vector leg lacked when it returned[]and looked like an empty result. Andsrc/baselines.rsis the contrast worth drawing with the fabricated baseline recorded on the benchmarks page. It is a hardcoded table of what an equivalent SSH-and-bash invocation "would have cost the agent", from whichmcp-gaincomputes savings asbaseline - bytes/4— the same move MemCP makes when it asserts a constant in place of a measurement. The difference is entirely in the handling: the file's own comment reads "These are educated guesses; recalibrate from realusage.jsonldata after a few weeks", the estimate is version-stamped asSOURCE = "estimate@v1", and that stamp is printed in the header of every report the tool emits. A number nobody measured, labelled as such, versioned so its replacement is distinguishable, with the recalibration plan committed beside it — that is what the honest form of an unmeasured constant looks like, and the corpus has more of the other kind.ChrisCanadian/nexus-proof-runtimewas examined and has no report, and it is the corpus's cleanest counter-example to this atlas's most-repeated finding — with the gap in the same file. Apache-2.0, 1,753 lines of Python across eleven modules and a test suite, 4 commits since 24 July 2026, at6223974c…. It is a receipt-backed execution layer for LLM tools, and the README rules itself out of scope before anyone else can: it contains "no Nexus Synapse production source, memory implementation, SSR selection logic, prompts, identity system, live schemas, provider configuration, or operational data." That is accurate —ReceiptStoredescribes itself as an "SQLite evidence store. It records facts, not model-authored success claims", and a receipt of an execution is an observation, not a claim a later reading could contradict. Same call asCorvus-226/RunTrace. The reason to record it is the executor. Every path through_execute_lockedends atself._record(...):SUCCEEDED,FAILED,TIMED_OUT,CANCELLED, andCANCELLED_BEFORE_STARTfor a call cancelled before the handler ran — each with anerror_code, each written to the samereceiptstable with the same columns, each bound to anexecutionsrow whoseUNIQUE (idempotency_key, principal_id, scope, tool_name, tool_version, arguments_hash)makes a retry a replay rather than a second attempt. There is no early return that skips the record. This atlas finds the opposite everywhere — AIPass's governance engine logs the memory it surfaced and never the one it declined, Mem0Sharp's admission gate carries aReasonthe service reads as a boolean and drops, AgentDatabase records mutations and not refusals — and here refusal and success are the same row shape. The second mechanism is theClaimGate, which is evidence before belief applied at the narration boundary: a model may claimtool_succeededorartifact_exists, and the gate resolves the claim against the runtime's own receipt or artifact and against the host-owned principal and scope, returning typed codes —UNVERIFIED_TOOL_SUCCESS,RECEIPT_PRINCIPAL_MISMATCH,RECEIPT_SCOPE_MISMATCH,MISSING_OR_TAMPERED_ARTIFACT— so an application never presents a model's assertion as fact without a runtime-owned record behind it. And the gap is in the same file, one function up.ToolExecutor.executeraises rather than records for everything it refuses before starting:IDEMPOTENCY_KEY_REQUIRED,UNKNOWN_TOOL_VERSION, a policy denial (decision.code) andINVALID_ARGUMENTSall leave no row. So the runtime whose purpose is durable proof keeps a complete record of the calls it ran and none of the calls it declined to run — the same asymmetry, in the one repository built to make it impossible, and the fix is that the receipt table already has astatuscolumn and afacts_jsonblob.fynnfluegge/agtxwas examined and has no report: it is thebeadsboundary in its purest form, and its trust gate is worth the entry on its own. Apache-2.0, 26,552 lines of Rust, 102 commits since 8 February 2026, 738 tests, at6f0d8dec…. It is a terminal kanban board that runs several coding agents in parallel, each in its own git worktree and tmux window, with an orchestrator that plans and delegates — the README calls it "the blackboard for coding agents", and a blackboard is exactly the thing the second boundary declines. The schema settles it in five tables:tasks(title, description, status, agent, project, session, worktree, branch, PR number,cycle,referenced_tasks,escalation_note),transition_requests,notifications,projectsandrunning_agents. Every column is the state of the work or of the process running it; not one holds a claim about the world that a later reading could contradict. A task moving frombacklogtodone, or its branch changing, is the work moving on rather than the store having been wrong. The cross-task context path is the interesting near-miss, because it looks like memory transfer and is not: a task may reference other tasks, and on worktree creation agtx writesgit diff main..<branch>into.agtx/references/<slug>.diffand recursively copies.agtx/skillsand.planningfrom the referenced task's worktree — "if it still exists". Both halves are derivable or ephemeral: the diff regenerates from git on demand, and the copy silently produces nothing once the worktree is cleaned up. Nothing is stored with an identity a correction could name, which is the difference between routing work products and remembering. What is worth recording isTrustStore, and it belongs besidetobi/qmd'ssrc/trust.tsabove as the corpus's second good instance of the same idea. A cloned repository can carry.agtx/config.tomlwith aninit_script, acleanup_scriptandcopy_files; agtx keys a SHA-256 of that file by canonical project path in~/.config/agtx/trusted_projects.toml— outside the project, so the tree cannot mark itself trusted — and on a mismatch suppresses the three dangerous fields and forcesno_init_scriptsfor plugins rather than refusing to open the project, telling the operator which fields were disabled and namingagtx trustas the way back. Editing the config re-arms the gate because the hash changes, which is the property a one-time folder prompt lacks, and(None, None) => truedistinguishes no policy from changed policy — a project with no config file is not treated as suspicious. The gap is that the gate and the precedence key on different files.WorkflowPlugin::loadresolves a plugin name against{project}/.agtx/plugins/<name>/plugin.tomlbefore the global directory, a plugin carries its owninit_script, and plugin init scripts are suppressed only when the config hash mismatches. A repository that ships a project-local plugin directory shadowing the name the operator already has configured globally, and ships no.agtx/config.tomlat all, satisfiesis_trustedby that same(None, None)arm. The fix is one line — hash the plugin directory too, or forceno_init_scriptswhenever a project-local plugin shadows a global one — and it is recorded here rather than left implicit because the atlas keeps finding trust gates whose key is narrower than their blast radius. One note on its benchmark, which is committed rather than claimed:benchmark/RESULTS.mdreports per-instance rows against SWE-bench Lite with duration, tokens, cost and a three-value outcome — ✅, 🟡 for "fix correct but incomplete", ❌ — across roughly ten workflow-plugin configurations, with a header explaining that tokens and cost move independently because cache reads are ten times cheaper than input. Reporting cost beside outcome is the discipline the benchmarks page asks for and rarely gets. It is also two instances of three hundred, mostly one, graded by hand, with a single ✅ in the whole table — so it separates nothing, and the file's value is the shape rather than the numbers.raiyanyahya/llmakerwas examined and has no report: the only thing it calls memory is a capped, expiring transcript, and the interesting part is that its silent failure is a committed contract. Apache-2.0, about 11,000 lines of Go across 72 files with a 5,000-line Python side, 46 commits since 24 June 2026, at683f7a28…. It is a self-hosting platform — one command provisions Ollama, Qdrant and Redis, networked and discoverable — with a FastAPI facade and a LangGraph agent on top.agent/app/memory.pyis 72 lines and is the whole of it: aRedisMemorythat stores a session's messages as one JSON list underllmaker:session:<id>, capped atmemory_max_turns: int = 20pairs and expiring atmemory_ttl_seconds: int = 604800. Nothing is extracted, nothing carries an identity, and a wrong statement in turn three is not corrected but evicted — conversation-window management with a network hop. The vector store beside it is loaded by an explicit/ingestendpoint from uploaded documents and by/itemsfrom a recommendation catalogue; no chat path upserts, so nothing the agent learns during a conversation becomes durable. A grep of the agent package for forget, tombstone, supersede and provenance returns zero. What earns the entry is the degradation contract. Every Redis call is wrapped in a bareexcept Exceptionthat returns[]or passes, described in the module docstring as best-effort — "if Redis is unreachable the agent still answers (with whatever the client sent), mirroring how the vector store degrades" — andtests/test_memory.py::test_memory_degrades_when_redis_errorspins that behaviour, asserting thatload,appendandclearall swallow a raising client. Availability over durability is a defensible choice for a chat buffer. Writing the test is what makes it a contract rather than an oversight, and it is also what makes the loss undetectable: a caller cannot distinguish a session whose history was saved from one that was silently dropped, and now nobody can fix that without failing a test. The shape generalises past this repository — GENOME's automatic fact detector swallows both its model call and its write at DEBUG, with the same result — and the cheap repair in both cases is to return what happened rather than nothing.stablyai/orcawas examined and has no report: it is thebeadsboundary again, and itssrc/main/memory/directory holds RAM accounting. MIT, 9,116 commits since 16 March 2026, atd14923e9…— an Electron orchestrator that runs Codex, Claude Code, OpenCode or Pi side by side, each in its own git worktree, with a mobile companion app. The durable state is the workspace session: tabs, panes, PTY registrations, terminal and tab-group layouts, browser history, sleeping agent sessions, and which worktree an agent is in. Every field is the state of the work or of the process running it; none is a claim about the world that a later reading could contradict, which is the same call recorded forfynnfluegge/agtxabove. The eightskills/are authored instruction files describing how to drive Orca —orchestration,orca-cli,computer-use— not procedural memory the agent writes, and thenotesin the source are review comments a person sends to a running agent. The vocabulary collision is the purest this atlas has recorded, and it is worth naming for anyone screening candidates by directory listing:src/main/memory/containshost-memory.ts,process-memory-metric.ts,windows-process-resource-collector.tsand a PTY registry. It is 2,520 lines about RAM. What transfers issrc/shared/zod-salvage.ts, and it is the finished version of something this atlas keeps finding half-built. The problem it solves is stated at the schema that uses it: a session JSON "is written to disk by older builds and read back by newer ones," and a field type flip or a truncated write "could poison Zustand state and crash the renderer on mount." The policy is tolerance declared on the field rather than at the parse boundary —salvagedField,salvagedOptional,salvagingArray,salvagingRecord— so "a corrupt entry is dropped and the rest of the session survives, because one bad tab record must not cost every worktree its state," while a payload that is not a session at all still falls back to defaults. And unlike every ad-hoc version of this the atlas has read, it tells the caller what it dropped:collectSalvageDrops(parse)returns{value, droppedPaths, droppedCount}with the example paths bounded at a hundred. GENOME's row-skipping decoder makes the same correct trade and reports the loss only to an ERROR log, so the caller sees a shorter list and no count; this is that gap closed, in 132 lines, in a repository that is not about memory at all.NVIDIA/SkillEvaluatorwas examined and has no report: it grades procedural memory rather than holding any, and two of its mechanisms are worth more than that boundary suggests. Apache-2.0, 125,985 lines of Python, 59 commits and 7 contributors since 26 July 2026, ataa195cac…. It is a three-tier evaluation framework for Agent Skills — deterministic validation gates, semantic overlap detection, synthetic eval-dataset generation, and sandboxed live agent runs through Harbor. The scope call is the one already drawn forzenml-io/kitaruabove: it judges agents, it is not memory for them. The vocabulary confirms it and also demonstrates why the probe alone cannot be trusted —forgetis zero, all 35memoryhits are RAM (--override-memory-mb, "in-memory agents data"), and all ten apparentrecallhits are the substring insideIgnoreCallback. What it persists is an embedding catalog of skills built to answer "is this new one a duplicate", which is the corpus-index boundary already drawn forShamGaneshan2008/Kodiak— an index of artifacts, not a store of anything an agent believes. The first mechanism worth recording is that catalog's load contract, which is the strictest embedding-provenance check in anything read for this atlas. A saved catalog carriesschema_version,provider,model,mode(full-bodyordescription), an endpoint fingerprint, a vector dimension, and a SHA-256content_fingerprintper entry;load_catalogrefuses — raises, rather than warning or degrading — on a mismatch of any of them, so the same model name served from a different endpoint is rejected, and a catalog built over descriptions cannot be queried as though it were built over bodies. This atlas repeatedly finds vector stores that silently mix embeddings from different models and compare them anyway; here it is impossible by construction, and the refusal is the whole difference. The second is the Tier 3 lift verdict, which is the ablation the atlas keeps asking for and rarely finds: the same eval dataset is runwith_skillandwithout_skill, and the delta decides whether the skill earned its place. The thresholds are asymmetric and there is a deliberate dead zone — pass at+0.05, fail at−0.10, neutral between — with the reason committed beside the constants: "Small deltas stay neutral because live agent runs are noisy, especially with low attempt counts." A measurement that declines to call a result in the band where it cannot tell signal from noise is the practice the benchmarks page exists to ask for, and a procedural-memory system that cannot say whether its instructions help is the common case. Recorded by name because a repository whose product is evaluating the thing this atlas reviews would otherwise look like an oversight in a candidate list, and because both mechanisms are separable from the framework: neither needs a skill, an agent, or NVIDIA's pipeline to be worth copying.yassinbahri/OnceMeshwas examined and has no report: it caches computations rather than beliefs, and it puts the scope key somewhere this atlas has been asking for it. Apache-2.0, 20 commits, all dated 25 August 2026, atea2911d8…— 8,643 lines of Python under a 3,685-line specification, described by its own README as "an open specification and reference implementation for exact reuse across agent and workflow runtimes" and, in the same paragraph, as "not a semantic prompt cache." The stored unit is a computation, not a claim. An action is{spec_version, operation, inputs, executor, output_schema, vary}; a result manifest is{spec_version, action_digest, artifacts, produced_at, fresh_until, producer}; an artifact is{name, digest, size, media_type}. Beside them sit source-validation records and signed receipts. Nothing in that schema is a subject, a predicate, a confidence or a fate —fresh_untilis a TTL on a computation result, which is the boundary already drawn forPerseus-Computing-LLC/perseus, and revalidation here means re-checking whether an upstream document changed, not revising a belief. The adapters arehttp_fetch,html_markdownandpdf_text. The nearest kin is a remote build cache with attestation. The vocabulary collision is the third the atlas has recorded and the most likely to fool a keyword screen, afterstablyai/orcaabove and the note on a directory named memory:src/oncemesh/store.pydefinesclass MemoryStore, and it is the in-process backend — the user guide's own table lists "Run or memory" as the tier that "disappears with the process and provides no cross-process durability." What transfers is where the scope key lives.derive_authorization_partitionbuilds an HMAC-SHA256 over{profile, tenant, sorted(scopes), subject_partition}under a domain-separated key of at least 32 bytes, andexecution_cache.pyputs the resulting token in the action'svaryobject — whichaction_digesthashes along with everything else. The partition is therefore inside the lookup key: two callers with different tenants or scope sets derive different digests and cannot reach each other's results, rather than reaching them and being filtered. Every scope failure this atlas has catalogued is a filter somebody forgot, widened or short-circuited — aninclude_allparameter, a predicate on one of three read paths, a policy shipped disabled. A key you cannot construct without the scope cannot be constructed without the scope. The cost is stated by the same design: a partitioned result is unshareable across partitions even when it would be safe to share, so the trade is reuse for structural containment. Two smaller mechanics hold it up and are worth copying together._require_exact_keyscomparesset(value) != expectedand so rejects unknown keys as well as missing ones, which is what makes the README's claim to identify a computation "from every input that can affect its output" enforceable rather than aspirational — a field this version does not know about refuses the action instead of being silently excluded from the digest. And the conformance suite carries a dedicatedcanonicalization-negative-v0.json, run by a Node harness so the Python reference is not the only thing checking it, whose negative vectors assert the specific rejection reason (error.message === vector.reason) rather than that something threw — the check that separates refused from refused for a different reason.searchsim-org/cikm26-knowledge-triage, which GitHub redirects to from its former namesearchsim-org/knowledge-triage, was examined and has no report: it is a retention policy rather than a store, and it is the first artifact this atlas has read whose published numbers recompute from committed files. Apache-2.0, 7,229 lines of Python, ata6ceb01a…— the reference implementation behind The Compaction Cliff in Long-Running AI Agent Memory (arXiv:2608.22752, CIKM '26). It holds nothing across sessions.knowledge_triage/kb.pyandoperators.pyclassify the lines of an agent's existing configuration —AGENTS.md,CLAUDE.md,.cursorrules— and decide which survive a compaction, a partition or a retrieval; the knowledge base is the caller's file, not a store this code owns. That is the same boundary drawn forNVIDIA/SkillEvaluatorabove, one step further along: SkillEvaluator grades procedural memory without holding any, and this one governs memory without holding any. Its measurement discipline is the reason for the entry, and it is recorded in full on the benchmarks page: twentyresults/*.jsonfiles beside twenty-two experiment scripts, with three separate abstract claims checked against them here and all three matching at the stated n. The one worth copying isresults/human_verification.json, which reports that of the cases the paper's own automated preservation metric scored as preserved, humans judged 27.6% weakened or lost — the failure rate of their own instrument, published beside the wins. The dataset half,AgentArtifactCorpus, is gated behind a Data Use Agreement and is a pointer rather than something checkable here.chenhg5/agencycliwas examined and has no report: it composes context from authored prompt files rather than accumulating any, and it is the fourth tree in this corpus where the word memory means RAM. AGPL-3.0, 33,831 lines of Go, 233 commits between 16 March and 10 July 2026, atba8b6937…— a CLI and web console for running a team of AI coding agents that "plan, execute, and talk to each other." The durable state is organisational configuration and work state: teams, roles, agents, tasks, milestones, OKRs, environment variables, providers, and a document registry of id, title, file path and tags. The one thing written back from a run is a taskSummary— "what the agent reports on completion (used by workflow routing)" — which steers the next step and is not carried into unrelated later sessions. That is the boundary already drawn forstablyai/orcaandfynnfluegge/agtxabove.internal/ctxbuildis the part worth naming, because it is what a memory layer would have replaced. ItsBuildermerges prompt files in a fixed inheritance order — agency, then each team in the chain top-down, then role, then project — deduplicating skills, with role skills appended last. Deterministic composition of human-authored layers, nothing written back, so there is no correction to review and no forgetting to test. And the naming trap is now a countable pattern rather than an anecdote. A grep of this tree for memory returnsMemoryMB,DefaultMemoryMB = 4096and--memory=%dm: Docker container limits, and nothing else. Withstablyai/orca's 2,520-linesrc/main/memory/about RAM,yassinbahri/OnceMesh'sclass MemoryStorefor its in-process backend, and thememorytier in that project's own durability table, four separate repositories now use the word for hardware or process lifetime. A directory listing and a keyword grep disagree about what a memory system is, and the grep is the one that misleads more often — which is the reverse of the failure recorded for OpenWorker in the overview's History, where the directory was the thing that misled.Weighted Memory Treewas examined and has no report: no repository, and the design it describes would score well if there were one. Weighted Memory Tree: Remembering What Matters for Long-Horizon LLM Agents (arXiv:2608.20631, 21 August 2026), Dao, Kathalkar and Eaton, sixteen pages. No code repository, no dataset, and nothing in the text announcing a release — the same call recorded for EvoHarness-RL: an on-topic paper with no artifact to pin. Two of its fields are ones this corpus scores. A node carries content, node type, parent, retention score, missed-selection count, execution metadata, and a lifecycle state over{ACTIVE, COMPLETED, FOLDED, OBSOLETE}, where "Lifecycle states determine eligibility for prompt construction." A four-value discrete status held apart from a float and deciding what reaches the model is thetrust_stateshape, and the poisoning suite is thenegative_evalshape; neither is markable without code, which is the whole reason this is a paragraph rather than a report. Folding is reversible — completed branches fold into summaries while the system retains "access to folded context," and resumed branches reopen. Its two transferable pieces are recorded where a builder would look for them rather than here: the retention rule, revised by execution outcome and by decaying a memory that was eligible and not chosen, is on the decay pattern page; the nine-metric poisoning protocol and the ablation showing that reducing immediate exposure leaves infection persistence complete are on the benchmarks page. Its reported gains — 9.97 percentage points of accuracy over linear memory and 32.8% fewer prompt tokens on GAIA-Text across three open models — are recorded in both places as unverifiable at any commit.memstate-ai/memstate-mcpwas examined and has no report: the repository is a 215-line proxy and the memory is on someone else's server. Apache-2.0 in theLICENSEfile — the README badge says MIT, which is the kind of discrepancy this list records — 40 commits between 1 March and 1 April 2026, ateceac236….src/index.tsdescribes itself exactly: "Adaptive MCP proxy for Memstate AI. Dynamically proxies all tools, resources, and prompts from the Memstate hosted MCP server — no hardcoded schemas." It forwards tohttps://mcp.memstate.aiwith an API key, and the only local writes in the tree are a config file and scaffolded skill files. Every mechanism the product sells is server-side: the dotted keypaths, the versioning that makes an old value history, theis_latestflag on search results, the conflict detection. None of it is in the repository, so there is nothing to pin and nothing to check — the atlas's second exclusion, a mechanism closed behind an open wrapper, and the same call recorded for the hosted systems above. What is inspectable is the benchmark, and it is worth the entry on its own: a head-to-head against Mem0 claiming 69.1 against 15.4, with the suite and every raw run committed. The blinded judge and the matched-timestamp pairing hold up; the four committed Memstate runs spanning 56.78 to 86.47 do not support publishing 69.1 as a result without an n. It is read in full on the benchmarks page.anthropics/claude-codewas examined and has no report: the memory the product has is not in the repository that carries its name. Read atf275fa28…— 229 files over 744 commits since 22 February 2025, of which 106 are Markdown, 27 JSON, 21 shell, 21 Python and 17 YAML. There is nosrc/,lib/orbin/: the CLI ships as an npm package and the five TypeScript files in the tree maintain the issue tracker (issue-lifecycle.ts,auto-close-duplicates.ts,sweep.ts). This is the Zep shape — a repository around a product rather than the product — and the thing an atlas reader comes for, theCLAUDE.mdconvention and the memory tool, is documented here and implemented elsewhere. What the tree does hold is 149 files of plugins and 38 of examples: skills, commands, agents, output styles and ahookifyrules engine, which under skills as procedural memory is the interesting question. They do not resolve it, for the reason theTencent/UI-Mateentry above gives — the arrow points one way. Every loader in the tree opens these files to read (load_rules,load_rule_file,open(file_path, 'r')), and a grep for anything writing aSKILL.md, a plugin or aCLAUDE.mdback returns nothing, so a completed session teaches the next one nothing that lives here. The remaining hits for memory are the honest kind: a Fargatetask_memoryin MiB in the gateway Terraform, and prose in plugin READMEs describing the feature. Recorded by name because a reader meeting the best-known coding agent in a list of memory candidates deserves to find out which half of it is public.sentrux/sentruxwas examined and has no report: everything it keeps is re-derived from the code it reads. MIT, 33,722 lines of Rust with 77 tree-sitter query files, read at6f8ff3c1…— 318 commits, every one of them between 11 and 18 March 2026, and none since. Screened first: one auto-run surface (.claude-plugin/marketplace.json, the entry a harness installs the plugin from), one build-time execution surface (sentrux-core/build.rs), no unpinned surface and aCargo.lockuntouched for 166 days; nothing was built and nothing was run. It is here because it sells itself to agents as the other half of a memory loop — "the sensor that helps AI agents close the feedback loop" — and ships an MCP server and a Claude Code plugin to do it. What crosses a session is.sentrux/baseline.json, a savedHealthReportandArchReportthat a later run compares against as a structural regression gate, and.sentrux/rules.toml, architectural rules a person writes. Neither is a belief: the baseline is a measurement of the tree that a rescan reproduces, and the rules are configuration. The nearest thing to a memory is the evolution surface, and the tool refuses the promotion itself — its own MCP definition calls git churn, hotspots, bus factor and change coupling "Raw data — not a score", and the panel beside it repeats "no score, just facts from git history." That is theLuqueee/kivgraphcall again, from the measurement side rather than the index side: a projection of a repository goes stale and is recomputed, and there is nothing a correction could name. The reversal condition is a store of judgements — a suppression or waiver keyed on a finding, surviving a rescan — andwaiverandacknowledgeappear nowhere in the tree.oooscoos/Benziwas examined and has no report: the thing in this tree is not memory, and the memory it advertises is not in this tree. Proprietary — "All rights reserved", reverse engineering forbidden — 535 tracked files and 93 commits between 29 July and 28 August 2026, read at85f08cfd…, of which not one is product source: 504 Markdown files, eight Python files that are a benchmark harness, two static pages, and nopackage.json,pyproject.toml,tsconfig.json, CI workflow or manifest of any kind — the screen returnsNOTHING SCANNEDbecause there is no execution surface to scan, which reading the tree by hand confirms rather than contradicts. Benzi is a VS Code extension over a tree-sitter code index served frombenzi.fly.dev, and the harness's own named entry points —benzi_headless.py,benzi_mcp.py,benchmark/swebench_docker.py, pluscoldstart.jsonandresults/transcripts/— are all absent, which is the Zep shape carried a step further, since here not even a client remains. What the README describes falls under theLuqueee/kivgraphcall made above: a compiler-derived symbol map is a projection of the source that goes stale and is rebuilt, not a belief a correction can name. The one thing that would be in scope is a single README bullet — "durable per-repo facts survive restarts; conventions learned once aren't re-derived every session" — and the committed run logs say more about it than the prose does.remember,recallandforgetappear nowhere inREADME.mdorbenzi_landing.html, are absent from the README's own sixteen-tool table, and are named only in the per-runtoolshistograms ofbenchmark/results/runs.jsonland the 500 files underswebench/trajs/— where the asymmetry is the finding:rememberfires 363 times againstrecalltwice andforgetfive times across all 780 recorded runs, a store written and never read. None of it survived the run that wrote it, for a reason the harness states about its index and which applies to anything under.benzi: the cold start is "paid on EVERY run here because every task gets a fresh worktree. In the product it is paid once per repo and cached in .benzi" (benchmark/harness.py:2024-2026). The reversal condition is the extension: publish the VS Code source, or a schema for that per-repo store, and the store it describes is a memory system.- Benzi's committed benchmark artifacts reproduce two headline
numbers exactly and cannot reach the rest. Nothing was run
here. Across the 500 files in
swebench/trajs/the declaredturnssum to 16,091, median 27, andsource_lines_readto 231,574, median 379 — both exact againstREADME.mdandswebench/SWE_BENCH_REPORT.md;swebench/all_preds.jsonlcarries 500 rows with exactly one empty patch,django__django-13513, as the report states; and the recorded verifier verdicts are 494revise, tenagreeand oneno_diff, which supports the report's own claim that it requests a revision on nearly every instance. The headline 391/500 (78.2%), the $37.33 and the token totals are not recomputable, becauseall_preds.jsonlholds onlyinstance_id,model_name_or_pathandmodel_patchwith no grading verdict — andswebench/metadata.yamldeclaresoss: falseandverified: false, so the submission is unverified by its own metadata. The cross-harness lines-read table is weaker still:source_lines_readis recorded on the 280benzi_productrows ofruns.jsonland on none of the 119control, 22opencodeor 2aiderrows, the Claude Code figure is reconstructed bylines_read.pyfrom aresults/transcripts/directorybenchmark/.gitignoreexcludes by policy, and the table's fourth arm — "DeepSeek Harness" — appears in no row ofruns.jsonlat all. The project discloses most of this itself:benchmark/README.mdopens "This is a vendor-run benchmark", its cut OpenCode runs are listed inoc_killed.jsonl, and its.gitignoreexplains at length why transcripts are withheld. The gap is stated rather than hidden, and the cross-harness comparison still cannot be checked from what is published. - A count in the headline findings drifted for want of a
binding, and the hedge beside it is why. The gaps section read
"Sixteen, in this entire atlas, can record that a value was rejected
so extraction cannot bring it back — see the [capability index] for the
live count" while the live figure was twenty-one.
scripts/check_claim_counts.pybinds roughly two dozen count claims to report frontmatter and did not catch this one, because it matches a number against a nearby mechanism noun and the sentence never used the word tombstone — it spelled the mechanism out in prose instead. The pointer to the live count made the staleness feel handled without making it checkable, which is the failure mode of hedging a number rather than binding it. The sentence was rewritten to bind the count to the corpus denominator, so the windowed check catches it — a bare "N systems in this entire atlas" passes only while N coincides with some other live total, which is what it had been doing; corrupting it to another number was confirmed to fail the build before this was committed. Corrected 19 August 2026. - A risk that was overstated, and the grep that would have
caught it. The Mem0Sharp
report of 21 August 2026 — the system renamed itself MagiCore on 5
September — led with a
Dreamingbehaviour that "writes speculation into the same table as fact" and said the value was "not written to the memory, to its metadata, or to the history row" so that "nothing downstream can tell them apart." At the pinned commitMemory.Behaviorwas a field on the row, the Postgres store created and wrote abehavior integer NOT NULL DEFAULT 0column, the Qdrant store filtered on it, and the service's search filter withheld every non-Normalrow unless the caller asked for them — all landed on 11 August 2026 in894b487, ten days before the pin, with a test. The report had read the 27-line prompt file the feature was described from and the Postgres schema the audit was described from, and had not runrg -n Behavioracross the tree; the field name was in the domain model, the store, the filter and a test. The direction matters: the atlas said the store could not distinguish speculation from fact when it both stored the distinction and enforced it by default. Corrected in the report; the mark it bears on,trust_state, is still withheld, because the label is fixed at write and no path moves it. 2501Pr0ject/RAGnarok-AIwas examined and has no report: it evaluates memory systems and is not one. "Local-first evaluation framework for RAG pipelines and AI agents" per itspyproject.toml,v1.11.0, AGPL-3.0 with a separate commercial licence, 251 commits since 24 January 2026 at1d4fcf96…, 146 Python files undersrc/ragnarok_ai— test-set generation, LLM-as-judge evaluators with calibration, drift, baseline and regression tracking, A/B comparison, a tracer, a monitor store — under 2,128 test functions. Twelve of those files mention memory; the only classes so named are aMemoryCacheand a Semantic Kernel memory adapter, andrg -n 'def remember|def recall' srcreturns arecall_at_kmetric. Nothing here is stored by an agent to be retrieved, scoped, corrected or forgotten later; it is the kind of harness the benchmarks page asks memory systems to be run under.nitpicker55555/MapRepairwas examined and has no report: the graph it versions lives for one walkthrough and is never loaded back. The code for Constructing Coherent Spatial Memory in LLM Agents through Graph Rectification (arXiv:2510.04195, v2 8 June 2026; Zhang, Chen, Feng, Jiang and Meng, Technical University of Munich), five commits between 8 April and 9 June 2026 at511937a4…, 14,910 lines of Python and no licence file. An LLM builds a navigation graph step by step from text-game walkthroughs on a cleaned MANGO dataset;VersionControlrecords each step as a commit of edge-level diffs with the observation and the model's analysis, exposesrollback_to,recall_stepanddiff, and builds a reasoning-history tree on which a conflict localiser computes the lowest common ancestor of two conflicting paths and an edge impact score ranks candidates for repair. That is memory-shaped in the way this atlas cares about — a belief that can be wrong, a record of when it was asserted, a mechanism for finding which assertion to retract. What keeps it out is the boundary the taxonomy draws:MapSLAMSystem.save_resultswritesnavigation_graph.jsonandversion_history.jsonat the end of a game, andrg -n 'json.load' *.py experiments/*.pyfinds readers only for the dataset and the experiment scripts — nothing reopens a saved graph to continue it. Androllback_totruncates the chain (version_control.py:140-145), so the versions after the rollback point are discarded rather than kept: the history forgets the branch it abandoned. The committedresults/hold 1,340 files behind the paper's tables. Worth a report the day a run can resume from its own output.- Eight spatial-memory repositories for robots were examined
in one round and have no reports, for one of three reasons.
The memory is per episode and lives inside a policy:
shihao1895/MemoryVLA(arXiv:2508.19236) atd732ea90…keeps a perceptual-cognitive memory bank keyed by episode withresetandclear_episode(vla/memory_vla.py:202-207) and no persistence call;nvidia-isaac/nvblox_mindmap(arXiv:2509.20297) ata76886df…, under the NVIDIA licence, reconstructs a feature map per episode andclears it (mindmap/mapping/isaaclab_nvblox_mapper.py:252);markmusic27/spatial-memeratbbc287c8…, 1,344 lines, builds egocentric maps from poses and keyframes for a MemER-style policy (arXiv:2510.20328) with no store —rg -n 'pickle|json.dump|np.save|torch.save|sqlite' -g '*.py'returns nothing. The map is built once, offline, and never updated:concept-graphs/concept-graphs(arXiv:2309.16650), MIT, at93277a02…, is the batch pipelinecfslam_pipeline_batch.pythat writes per-frame and full-scene.pkl.gzfiles and reads back only detections;IMNearth/Spatial-X(arXiv:2601.06806, arXiv:2603.26837), CC BY-NC-SA 4.0, at9afdacd2…, loads per-viewpoint observations from Matterport scans (spatialx/mp3d_extensions/mp_utils.py:58-119) for a navigation agent;AdnanSattar/Spatial-RAG-Worldmodel, MIT, one commit on 4 December 2025 at6e8597dd…, stores latent world-model states in a Qdrantlatent_memorycollection with a spatial prefilter,deleteandclear— states a model emits, not beliefs an agent could find false.HorizonRobotics/HoloAgent(arXiv:2606.23565), Apache-2.0, atef14d315…is the same case, and that commit is the HoloAgent-0 code release underagentic_robot/. The one caller of its graph writer (agentic_robot/fsr_vln/ovo/integration/hmsg_bridge.py:248) builds the FSR-VLN scene graph (arXiv:2509.13733) offline from a mapping run'sovo_map.ckpt, into a newgraph_directory stamped with the build time (agentic_robot/fsr_vln/memory/hmsg/graph/graph.py:1926-1928). The navigation node loads one such snapshot from a hand-set path (agentic_robot/core/src/navigation/semantic_goal/config/visualize_query_graph_demo.yaml:7) and never writes it, and the streaming mapper starts each run empty (agentic_robot/fsr_vln/run_stream_mapping.py:171-177). The code is not there yet:caicaiya123/EvoMemNav(arXiv:2606.03509) ate85ee0e3…is one commit reading "Code coming soon". Chronotope, DovSG and the robotics plane of MagiCore are the three from the same round that cleared the bar. - Five spatial-memory papers from the same search have no
repository to pin, and are recorded so the search is not
repeated. arXiv:2608.04574 When
Memory Lies: An Empirical Study of Spatial Memory Staleness in VLM
Agents (5 August 2026) states "We release the code, all 50 seed
map sets, full model traces" and its text carries no repository URL
— the one
github.comlink is to gym-minigrid; arXiv:2511.18112 EchoVLA (v3 7 August 2026) and arXiv:2605.22283 Spatial Memory for Out-of-Vision Manipulation in Vision-Language-Action (21 May 2026) carry no URL of their own at all; arXiv:2511.20644 Vision-Language Memory for Spatial Reasoning (v2 9 July 2026) links a project page for a memory that is a model's internal state; and arXiv:2604.16482 is a survey of spatial memory representations for navigation (13 April 2026). The search:rg -o 'github\.com/[A-Za-z0-9_./-]*'andrg -o 'https?://[^ ]*'over the extracted text of each. A paper is read here only through the artifact it publishes as its implementation; without one there is nothing to pin. arXiv:2609.18842was examined and has no report: it releases no code, and what it adapts online is a posterior nothing can name. Infinite-Parameter LLMs: Generating and Adapting Weights from Live Data (Hu, Clarke and Zhang of Boltzbit Limited with Hernández-Lobato of the University of Cambridge and Boltzbit; v2, 21 September 2026, CC BY-NC-ND 4.0, the authors' own comment reading "Preprint, containing preliminary results"). A compact hypernetwork turns live interaction data into low-rank modulations of a shared base network's feed-forward weights, attention untouched, and a Bayesian belief over the generator's latent code is updated online so the effective weights are re-derived as the belief evolves. It is recorded here because it argues against retrieval directly — the pitch is that facts and corrections supplied by users are otherwise "placed in the context (by instruction or retrieval) and re-read on every request, only to be discarded afterwards", and that representing them in the weights instead "frees the context window" and "persists updates across turns" — so a reader looking here for weights-as-memory should find why it is absent. The boundary is the granularity, not the persistence. This atlas's test is whether the store holds anything that could turn out to be false, and the absorbed content plainly does; what it lacks is any handle on it. Over 20,376 words of extracted text, across sessions, cross-session, provenance, delete, revert and rollback occur zero times, against 128 for belief and 38 for LoRA; persistence is stated at turn granularity, "persistent weight-space adaptation at turn granularity", inside one session. The "controlled" and "principled forgetting" the paper contrasts with in-context learning is the filter's forgetting factor — an uncertainty-gated update the authors describe as "a derived analogue of elastic weight consolidation" — which resists catastrophic forgetting and is not an operation on a named fact. That makes it a sharper case than the adapter granularity described above rather than an easier one: an adapter at least fails at a stated unit, a whole adapter at a time, whereas a correction here is another Bayesian update over the same latent code, arriving by the same path as the claim it corrects and leaving nothing that enumerates what the posterior currently holds. One gap between the title and the measurement is worth carrying even though the paper is out of scope, and the limitations section states it first: the belief actually evaluated is categorical over a pool of materialised codes, which "chooses among reads rather than moving within the code space", with the continuous-Gaussian belief that would move within it left to future work — so the infinite feasible space the title names is not the thing measured on the five question-answering datasets used (SQuAD, HotpotQA, QuALITY, MuSiQue and 2WikiMultihopQA). No code is released and no code- or data-availability statement appears; github occurs three times in the fetched HTML and all three are inside arXiv's own Report GitHub Issue interface, none in the paper's text.arXiv:2609.02042was examined and has no report: it releases no code, and the skill library it builds is a training-time teacher the deployed policy never consults. Act More, Decide Less: Skill-Guided Adaptive Action Chunking for Long-Horizon LLM Agents (Yang, Jin, Zhao, Wu, Zhou, Wang, Wang, Zhou and Metaxas; Rutgers, Toronto, Hong Kong Polytechnic, Amazon, Microsoft; submitted 2 September 2026, EMNLP 2026 camera-ready) trains an agent to emit variable-length action chunks instead of one ReAct action per round, and the mechanism it takes the chunk boundaries from is memory-shaped. Successful trajectories are segmented by the model into a composite skill of ordered subskill calls, each subskill a Python routine that emits one action chunk; every generated skill passes syntax, compilation and signature checks, is canonicalised to its AST and deduplicated against the library before insertion; the library starts from three hand-written skills on ALFWorld and five on ScienceWorld, caps composite skills at 20 per task category and periodically prunes those "whose long-term success rate remains zero"; and at the start of a skill-augmented rollout retrieval is category-first — composite skills for the task category ranked by a UCB-style score over success rate and usage count, the top three listed with those statistics — with a fallback to the seven most diverse subskills by description similarity. The induction prompt wraps its output in<memory>tags and asks for "compact key_value knowledge items, e.g. object type -> common locations" beside the code. Then the boundary: half of the rollouts on ALFWorld and three quarters on ScienceWorld never see the library, its only product is chunk-boundary supervision distilled into the policy by off-policy regression, and "at evaluation, the model uses only the primitive multi-action interface (no skill access)." That is optimizer state that produces a policy — the line drawn for AtlasVA — and the paper says so itself: "skills serve only as training-time scaffolds." The results are large: on ALFWorld with Qwen3-4B, 99.2 % seen and 96.9 % unseen against GiGPO's 85.2 % and 72.7 %, at 3.7 and 4.4 LLM rounds per episode against 15.9 and 21.7; on ScienceWorld with Llama-3.1-8B-Instruct, 67.2 % and 61.7 % against 35.9 % and 34.4 %. The ablation on ALFWorld with Llama-3.1-8B puts the skills at 9.4 points on the seen split (96.1 % to 86.7 %) and the chunk-aware advantage at 5.5, and plain GRPO handed the same skills at rollout time gains 5.5 points while keeping 19 rounds — the paper's own evidence that the library matters as supervision, not as a retrieval aid. Over 11,899 words of extracted text, github occurs zero times and there is no data-availability statement; the limitations section names "stronger exploration, retrieval, or validation mechanisms" for the induction stage as future work. With a release, the thing to read first would be the pruning rule, because a skill whose success rate falls to zero is the one place this paper's memory can turn out false and be retired — and whether a retired skill can be re-induced from the next successful trajectory is the tombstone question, unanswered in the text.Leonxlnx/unlazywas examined and has no report: what it keeps across sessions is an allowlist of approved shell commands, not anything an agent believes. MIT, 49 commits by thirteen authors between 10 August and 3 September 2026 at16671491…, aSKILL.mdfor Claude Code and Codex with 1,760 lines of dependency-free Node across five scripts and seven test files, self-described as "completion discipline for substantial AI-agent work, backed by runnable gates": an agent writes aGATES.mdledger of acceptance gates before working, each with aCHECK:shell command and anEXPECT:pattern, andgate-check.mjsruns them, records evidence lines carrying a digest of the gate's definition, and refuses to call a gate met unless the process exits zero and the expectation matches. Its one durable store is the approval record — a JSON file per gate under~/.unlazy/approved/, named by the SHA-256 of the ledger path, the gate id and an oracle signature overCHECK,EXPECT, working directory, shell andPATH, which must live outside the repository (gate-check.mjs:382-389) and which--statusnever writes; a second, per-repository store under.unlazy/<scope>/holds pipeline leases and session state for orchestrated runs. Both are records of what a person or a run authorised, keyed on the exact command, and neither can turn out false in the sense this atlas asks: a memory is what an agent came to believe, and unlazy is deliberately built so that its own outputs are never that. Theresearch/validation-protocol.mdfile is worth the visit anyway — it demotes the project's earlier six-run comparison to "design provenance only", states it is "too small for broad model claims", and pre-registers what a rerun would have to record — which is more than most of this corpus says about its own numbers.arXiv:2609.01481was examined and has no report: its released code carries a tester's report from one iteration of a task to the next, nothing crosses tasks, and the only state read back across processes is the previous trial's game workspace. Harness-of-Harness: Multi-Day Autonomous Software Development with Continual Improvement (Yan and eight co-authors, Shanghai Artificial Intelligence Laboratory; preprint, 1 September 2026) wraps Codex, OpenCode or Pi in an outer loop of Project Planner, Developer and QA Tester, and states that it "adopts progressive disclosure rather than a dedicated memory module".Flesymeb/HarnessOfHarnessaddedhoh-lite/inec845b75…on 23 September 2026; atae7cc6fb…(MIT, 75 commits by one contributor) it is 60 Python files and 14,453 lines beside a vendored Godot MCP server. Each run gets a directory named for its task and start time (adapters/gamecraft_bench/runner.py:2491-2495), the runtime refuses one whose receipt exists (core/runtime.py:58-62), and--resume-fromseeds a new run from the last valid trial of the same task (runner.py:2451-2464,artifacts.py:437-482). Within a run, the planner receives the latest tester report cut to eight issues, four bugs, four gaps, three goals and three preserve items of 240 characters each (core/prompts.py:191-217), plus the last three entries of an in-process history list (:107). Two files look like memory and nothing reads them:loop_memory.json(core/prompts.py:506), andevidence_history.json, which the prompt calls the "complete lossless public ledger" (:100-104) and which a resumed run rebuilds from the seed trial's report alone (runner.py:2586-2599). The code settles what is carried forward as true. The next plan is told "Do not remove or weaken" the tester'spreserveitems and any claim review with a pass-like status (core/evidence.py:342-354,:398-417); thedemosandasset_evidencebranches (:356-396) take entries with no status check, though the next-loop contract asks for neither key (adapters/gamecraft_bench/prompts.py:101-111). The whole set is replaced by the next report, so nothing stays settled for more than one loop unless the tester re-asserts it. There is no issue ledger to reopen from: issue ids carry the loop number (core/evidence.py:152,core/stages.py:6-7), so no issue keeps an identity between loops, and "do not reopen an older item" is prompt text (core/prompts.py:103-104). The.gameloop/vcs.jsonbindings and sealed-change receipts in the run's public product,Flesymeb/fusepoint, have no counterpart in the release. The one SQLite file is an FTS5 index over the official Godot documentation (tools/godot_docs.py:1,:141-160). The nine tests in.github/ci/test_hoh_lite.pycover receipts, resume selection, the dry run and planner retries, and none exercises the carry-over. Searches run at the tree root:git grep -n -i -E 'memor|remember|recall|lesson|sqlite|embedding|vector|pickle' -- . ':!hoh-lite/src/gameloop/_vendor'(hits arebuild_loop_memoryand the docs index);git grep -n -E 'loop_memory\.json|evidence_history\.json'(writes and prompt text only);git grep -n -i -E 'reopen|ledger|vcs\.json|sealed' -- . ':!hoh-lite/src/gameloop/_vendor'(the prompt text only). The screen found 0 RUNS, 0 EXEC, 3 FRESH (hoh-lite/pyproject.tomland the vendored server'spackage.jsonand lockfile, all in a subtree added on 23 September 2026) and 2 FLOAT (pyproject.tomlwith no lockfile; caret ranges beside the vendored lockfile), and nothing was installed, built or run.- Prove2Me, the shared theorem library behind the Fermat's
Last Theorem formalization, was examined and has no report: the memory
the agents used is a hosted service whose server is published nowhere,
and what is public is its client contract, a February prototype without
any of the mechanisms, and the output. SiliconANGLE's report of
4 September 2026 and Anthropic's own post, Formalizing Fermat's Last
Theorem, describe a "Claude Code-based multi-agent
harness" of dozens of agents proving 30,300 intermediate theorems
in eleven days for six billion output tokens, whose early attempts
"quickly lost track of the project's state and stopped collaborating
effectively" and contributed about 7 % of the final non-boilerplate
lines, and which then ran on Prove2Me — a platform keeping "a
directed acyclic graph of theorem statements that agents used to decide
what proofs they should attempt next," separating statements from
proofs with the links maintained independently, and holding "a
natural-language description of each theorem statement," which the
post credits with "mitigating memory degradation." The paper
behind it, Prove2Me: An Open Collaborative Platform for Scaling Math
Formalization (Chen, Marwaha, Lu, Yuen and Peng;
arXiv:2608.28433, v1 28 August, v2 31 August 2026, cs.AI, cs.LO, cs.MA), is the memory design in full: every statement is "atomized and immutable, carrying all the context needed to compile on its own," so any proved theorem is importable by any later proof-sketch in any mission; the accumulated corpus is named Formalpedia; a search API indexes the standardised natural-language description every submission must carry, and agents "are also instructed to search before they submit"; a proof is a term whose type must match the target's exactly, a disproof is a term of the negation, and the paper's own example of a memory turning out false is a sketch importinggotsman_linial, disproved by a second agent and replaced bygotsman_linial_with_zero; milestones are the captain's idempotent and authoritative lemma targets so that parallel agents converge on one statement instead of duplicating incompatible ones; and the closing questions are the atlas's — "how agents should search a large, evolving corpus of formal statements" and "how such agents can exchange harnesses, lessons, and context to learn continually remains open." Over 6,904 words the paper links no server repository and the phrase source code does not occur. Three repositories were read.prove2me/prove2me_workspaceat58332c69…(47 commits by one author between 4 July and 5 September 2026, no licence file) is the client side: aSKILL.mdat version 0.9.7 and 2,729 lines of API reference describing the service atprove2.me— keyword search over names and natural-language statements (GET /api/v1/theorems?q=), a per-theorem dependency graph, open leaves and decompositions, a description edit history (description-versions), votes, tags, a saved list, mission discussions whose soft-deleted comments are returned as tombstones on request, verdictsPENDING → ACCEPTED | SKETCH_ACCEPTED | CE | WA | SORRY | FAILED | ERROR, an explanation that is patchable beside a solution that is immutable, and three rules that gate every submission, the second of which is never to import one's own target because "it is stored as asorryplaceholder, and citing it would prove the goal from itself" — plus 279 lines of Lean meta-programs that extract a declaration graph and sketch information from an existing project for upload.marwahaha/prove2meat5ee5b15c…(36 commits by one author between 3 and 24 February 2026, no licence file) is a FastAPI, React and Postgres prototype from before the paper: astatementstable withis_solved,is_disprovedandis_archivedflags, a proof column, tags, comments, a prize that grows over time, and a gatekeeper that sends each new statement to an external prover, Aristotle, during a holding period to attempt a proof or a disproof before people may; its list endpoint filters by tag and sorts by date or prize, the word dag occurs zero times in its backend and search only asre.search, and it has no description field, no sketch, no milestone and no mission.anthropics/fermats-last-theoremataa2d8b34…(one commit, 3 September 2026, Apache-2.0) is the output:Theorems/with 29,511 statements,P2M/Sol/with their proofs, 1,450 definition modules,PROOF-PATH.mdnaming the Lean theorem behind each step, aformalization.yamlrecording zerosorryand the three standard axioms, andP2M/Util.lean, the one piece of the platform's verification visible in the artifact —#p2m_type_eq, which checks a proof's type against its card's up to definitional equality and refuses when the statement's universe parameters had to be specialised to match ("the proof is less general than the card"); the README says a from-scratch build of 60,475 modules took 5 h 32 min at 96 jobs, comparator's kernel replay 14 h 46 min, and an independent Rust kernel checked 1,052,234 declarations. With the server readable, this would be screened as a shared memory whose entries are machine-checked and whose disproof is a first-class status, and the first thing to read would be the search — what the index holds beyond the description text, and what an agent that searched and found nothing is told about near-duplicates — because the paper's own account of failure before Prove2Me is agents that could not find what each other had already proved. youssouf994/LangBrainwas examined and has no report: what it persists is a LangGraph checkpoint and an audit log of actuator changes, and neither is a memory an agent could later correct. A hierarchical-agent boilerplate for a smart-home and medical-homeostasis demo at4b6951f8…(12 commits by one author between 3 and 4 September 2026, 44 files, Polyform Small Business 1.0.0), whose own README opens with a warning that it is a prototype and lists a "persistent in-process checkpointer (file-backed InMemorySaver)" among the changes of 4 September. That checkpointer (app/checkpointer.py) is LangGraph'sInMemorySaverpickled whole to.checkpointer.picklenext to the project — a committed, zero-byte file at this commit — so graph state survives a recompile; it is conversation-window state with no identity a later turn could correct, which is the atlas's boundary. The SQLiteeventstable (app/db/database.py:26-36,app/tools/event_log.py) is an append-only record of actor, action, target, old value, new value, reasoning and anescalatedflag, read back by every agent as "recent history" within a 240-minute window and by the brain to arbitrate conflicts, and rewritten only to prefixRESOLVED_onto a settled escalation; it records what an actuator was set to, which happened, and cannot turn out to be false.rg -n -i 'embedding|vector|recall|remember' appreturns nothing, andmemoryoccurs only as the LangGraph saver's module name. Recorded because a checkpoint file and an audit table are the two artefacts most often mistaken for agent memory in submissions to this atlas, and this repository has one of each and nothing else.AppFlowy-IO/AppFlowywas examined and has no report: its AI chat's memory is an in-process message list with a running summary, and its local retrieval is over the workspace's own documents. A collaborative workspace client at5cf3a365…(AGPL-3.0, 7,210 commits by the GitHub count since June 2021, read from a shallow clone), whoseflowy-aicrate builds each local chat on langchain-rust'sSimpleMemoryor aSummaryMemorythat regenerates a running summary from the messages it holds (frontend/rust-lib/flowy-ai/src/local_ai/chat/llm_chat.rs:49-52,summary_memory.rs:11-45) — conversation-window state with no identity a later turn could correct — and whose local AI answers over the workspace's documents through a sqlite-vec store (flowy-ai/src/embeddings/store.rs).rg -n -i 'memor' frontend/rust-lib/flowy-ai frontend/appflowy_flutter/lib/plugins/ai_chat --glob '!*.arb'finds those two classes, anInMemoryChatControllerand a cache comment, and nothing durable; the hosted side, AppFlowy-Cloud, is a separate repository and was not read.foambubble/foamwas examined and has no report: it is a personal knowledge base for VS Code whose one AI feature ranks similar notes by embedding, and nothing in it is written by an agent or read on an agent's behalf. At97b82e4e…(MIT, 1,656 commits since June 2020, version 0.44.6, 18,812 lines of TypeScript underpackages/foam-vscode/src), the experimental Related Notes (AI) panel embeds each note through anEmbeddingProvider— an Ollama backend is the one implemented — caches the vector by content checksum in the extension's global state (src/ai/model/embedding-cache.ts,src/vscode/features/ai/build-embeddings.ts) and lists the nearest notes to the active one (src/vscode/features/ai/related-notes.ts). That is a similarity index over a store only the person edits; there is no MCP surface, no tool and no write path for a model —rg -l -i 'mcp|copilot|openai|language model' packagesreturns the provider interface and that feature — which is the difference between it and Logseq, whose report exists because an agent can write to the graph.ActivityWatch/activitywatchwas examined and has no report: it records what a machine's user did, in intervals that cannot be false, and no agent reads or writes the store. The meta-repository at88d559ab…(MPL-2.0, 1,145 commits since April 2016) holds its components as submodules, and the store isaw-server-rustatdf9c4fab…: abucketstable and aneventstable ofstarttime,endtimeand a JSONdatain SQLite (aw-datastore/src/datastore.rs:67-97), written by watchers as heartbeats that merge into the previous event when the data is equal and the gap is within a pulse time (aw-transform/src/heartbeat.rs:3-12), filtered before storage by rules that drop an event or redact a field (aw-datastore/src/privacy_filter.rs), queried by its own language, and synchronised between machines. An event is an observation of a window title or an idle state at a time; it is provenance for a memory, never a memory. The one nod to a model is agptme.tomlnaming files an assistant may read.rg -n -i '\bai\b|llm|agent|mcp' README.mdfinds nothing about agents.polmanas1998-star/membenchwas examined and has no report: it is a benchmark harness, and its findings are on the benchmarks page. At57377458…(MIT, twenty commits by one author between 5 and 12 September 2026) it generates 104 facts with a day on which each stopped being true, scores silence after that day as correct, brackets the arms with silent, guessing and oracle witnesses and a scrambled-corpus control, and reports from committed JSON, with a poisoning harness whose fixed clock makes its row a lower bound, a one-vote-per-triple rerun, six rigged environments, a long confinement and an echo chamber added on 7 and 12 September; its subject is the same author'sholomem, an FHRR holographic memory with a 45-day half-life. Nothing in the harness stores a memory;rg -n 'class .*Memory|def store|def remember' membench/*.pyfinds one hit, the scrambled control atmembench/arms.py:120.openrecall/openrecallwas examined and has no report: it is a screen recorder with a search box, and the search reads its own vectors in the wrong width. At62303e09…(AGPL-3.0, 90 commits since June 2024, 1,141 lines of Python) it screenshots every three seconds, drops frames whose structural similarity to the last exceeds 0.9, runs OCR, embeds the text withall-MiniLM-L6-v2, and stores(app, title, text, timestamp, embedding)in one SQLite table.insert_entrywrites the embedding asfloat32bytes (openrecall/database.py:112) andget_all_entriesreads it back asfloat32(line 58), butsearchinopenrecall/app.py:140decodes the same blob withdtype=np.float64, so the query ranks by cosine over vectors of half the length holding reinterpreted bytes. No agent reads or writes the store, nothing is corrected or forgotten, and the seventeen tests cover the cosine function and the table, not the search.rg -n 'agent|llm|mcp' -i openrecall/*.pyfinds nothing.weaviate/weaviatewas examined and has no report: it is the vector database several systems here delegate to, and its two agent-facing features are a database's, not a memory's. At85dbeace…(BSD-3-Clause, 29,229 commits by the GitHub count, release v1.39.2 of 2026-08-26) it carries a Model Context Protocol server inside the binary — read tools for collections, configuration and tenants, a hybrid search tool, and schema and object-upsert tools that register only whenMCP_SERVER_WRITE_ACCESS_ENABLEDis set (adapters/handlers/mcp/server.go:50-126), gated per request by a runtimeMCP.Enabledflag that answers 503 while off (adapters/handlers/rest/handlers_mcp.go:31-73) — and per-collection object expiry: anObjectTTLConfigof adeleteOnproperty plus adefaultTtlin seconds, with expired-but-undeleted objects optionally filtered from results and deletion runs coordinated on the Raft leader so only one is ever in flight (entities/models/object_ttl_config.go:29-41,usecases/object_ttl/object_ttl.go:33-49). An object has no scope key of its own beyond the tenant, no state, no provenance and no supersession; those are the memory layer's to add, which is why Cognee and others sit on top of it.rg -n -i 'agent memory|conversation memory|memory store|long-term memory' README.mdfinds nothing.- A ladder that was schema, and the producer test that would
have caught it. The Noosphere report of 9 August 2026
described a candidate tier whose status "starts at
EPHEMERALand promotes on usage" with five counters driving promotion, and its matrix row said so. At that pin and at the current one, nothing insrc/creates aMemoryCandidaterow, nothing setsPROMOTED,PENDING_REVIEWorREJECTED, four of the five counters are selected and never incremented, the promotion module's review status is a type no table holds, and recall reads articles. The enum, the counters and the module were read as a mechanism; the check theadd-memory-systemskill asks for — work backwards from the field to every assignment — was not run on them. The mark this bears on,trust_state, was withheld on a vocabulary argument and stays withheld on the right one. Found while confirming a re-pin the maintainer submitted as #21, whose own claims all held. - A position claimed from the wrong file. The OpenMake LLM report of 6 September 2026 said the memory block was prepended to the system prompt, "which places it where a provider's prompt-prefix cache would be invalidated by any change to it." At the commit it pinned, the function that assembles the prompt pushed the block after the static guard, artifact and answer-format blocks, under a comment marking the boundary between cacheable and per-user content and giving prefix-cache preservation as the reason. The claim was written from the block builder, which returns a string, rather than from the assembler, which decides where the string goes; a sentence about where memory sits in a prompt is a claim about the caller, and the fix is to cite the line that concatenates. The same reading missed that the data export queried the predecessor table's columns and returned nothing, because it followed the memory's own seven files and not every consumer of the table's name; the re-read of the same day corrected both.
- A layer present at the pin and not described. The
GBrain report of 9 August 2026
described one memory, the
takestable, and withheldbitemporalfor the way its validity window was queried. The tree at that pin also held the v0.31 hot-memory layer of 9 May 2026 — afactstable withvalid_from,valid_untilandexpired_at, arememberpath with a required provenance, a per-kind confidence decay, a cosine-and-classifier deduplicator and a consolidator that promotes clusters of facts into takes, in fourteen modules undersrc/core/facts/— and the report did not mention it. The reading followed the README's framing, which leads with takes, calibration and synthesis; the correction on 7 September 2026 covers both memories, awardsbitemporalon facts, whose window has been read at query time since 1 September, and narrows the takes finding to the scorecard's date window. The check that would have caught it is the table list —rg -o 'CREATE TABLE IF NOT EXISTS [a-z_]+' src/core/migrate.ts | sort -u— read before the README, so that a table the README does not lead with is a question the reading has to answer. zahid23saim/llm-eval-harnesswas examined and has no report: it is an answer-grading script, and nothing it touches outlives one run. At2973d6db…(MIT, three commits between 3 and 7 September 2026, 150 lines of Python plus 91 of tests) it loads a gold JSON array and an{id: answer}object, judges each item by its ownexact,containsornumericrule after lowercasing and stripping trailing punctuation, prints an accuracy line with every miss, and exits 1 on any failure. The only twoopen()calls read the inputs; the only writes in the tree are test fixtures totmp_path. No agent calls it, no model is called by it, and there is no store, so nothing can be scoped, corrected or forgotten — it is the scoring half of an eval, not memory. The one feature that would compare across runs, the regression diff, is sold in a paid kit the README links and is absent from the tree:rg -n -i 'regress|diff|pass@k|json_field' llm_eval.py tests/finds nothing, and.github/holds onlyFUNDING.yml, so the "CI-friendly" claim rests on the exit code alone. Screened before reading: no manifest, hook or workflow to scan; nothing was run.- CompBio and MIRaS were examined and have no report, on two
independent grounds: the code the paper points at is behind a request
form, and the memory is the literature rather than the user.
CompBio and MIRaS — a multi-omic analysis platform built on a
memory-based intelligence engine (Barve, Storer, Hoxsie, Marcum,
McMichael, Lalmansingh, Smith, Johnson, Kuster and Head; Nucleic
Acids Research 54(16), published 24 August 2026, doi:10.1093/nar/gkag833,
CC BY-NC, conflict of interest "None declared"). It reaches a
memory atlas honestly: it is built on a Memory-based Intelligent
Reasoning System, it uses episodic and semantic memory
as its organising terms with the cognitive-science definitions spelled
out, and it opens by drawing this atlas's own boundary — retrieval
augmentation, context augmentation and longer windows "provide
engineering workarounds for this limitation, [but] none represent
genuine persistent, recallable memory." The mechanism is a
Generalized Memory Model: every PubMed abstract and full-text window
from the "Q1, 2025 PubMed release with 38 355 642 abstracts and 6
600 121 full-text articles" tokenised into an episodic memory
across four framework dimensions, with complex memories normalised
against randomly drawn peers to isolate enriched signal, held resident
in server RAM as what the paper calls "memory-as-a-service." A
user submits a gene list; the reasoning component computes a
contextual semantic memory against that model and returns a
knowledge map. Nothing the user submits is written
back, the model is identical for every user and is regenerated
only when the source corpus is, so nothing stored survives a session
with an identity that could later be scoped, corrected or forgotten —
which is this atlas's bar, and the paper does not claim otherwise. The
second ground is the one worth recording for method. The version of
record carries a code-availability statement the December 2025 preprint
does not — "The code for CompBio and MIRaS is available from the
Zenodo repository" — and that deposit (10.5281/zenodo.18602034,
v1 of 15 December 2025, metadata CC BY 4.0, declared C++, PHP and
JavaScript) lists
miras.zipandcompbio.zipand marks them Embargoed: the record shows zero downloads and zero bytes of public data volume, and the files sit behind "If you would like to request access to these files, please fill out the form below." A statement naming a repository is not inspectable code at a pinned commit, and the atlas did not request access, because a request-gated archive would not become one; a search of GitHub, GitLab, Bitbucket and Zenodo for a public mirror under the authors' or the institution's names returns none. The running system is athttps://gtac-compbio-ex.wustl.edu, free to non-commercial users. Two claims are worth carrying for anyone who does get the code: the system is asserted to be "by design … incapable of hallucination," with every result traceable to its source knowledge, and the positive control reports 46 of 50 hallmark gene sets recovered without a curated pathway knowledgebase. arXiv:2608.10509was examined and has no report: it releases no code, and its central mechanism is the one this atlas most often finds missing. MAP-Graph: Provenance-Aware Shared Memory for Multi-Agent Workflows (Wang, Yan, Zhang, Wu, Zheng, Sun, Zhu and Cai; submitted 11 August 2026, v1, cs.AI and cs.MA). It puts agents, sources, memories, claims and actions in one typed graph — ten registered edge types includingderived_from,written_by,read_by,verified_by,invalidated_byandused_for_action— and separates two things most systems here collapse. Hard authorization is a permission scope carried on the record and applied as a filter before ranking, and a derived record "receives the intersection of referenced scopes", so a summary cannot widen the audience of what it summarises. Graded trust is a multiplier: retrieval filters on permission, then ranks the remainder "by semantic score times path trust" and returns at most five, and an action-time gate demands a trust threshold that rises with the action's risk — 0.30 for answering, 0.60 for a low or medium-risk action, 0.85 for a high-risk one. Revocation is the part worth carrying: an explicit event "marks a source revoked, clears its scope, and updates directly referenced or already affected records", while remaining descendants "detect the revoked ancestor during later recursive trust evaluation" — restriction propagating along derivation edges rather than stopping at the row someone thought to update. The authors are precise about what they did not build: "There is no general active/superseded/contradicted state machine", writes append without content deduplication, and the structured audit output is identifiers, component scores and reasons rather than an explanation, with human-facing explanation quality explicitly not measured. The ablation is the reason to read it. Removing the hard permission filter improves utility and "allows every observed unauthorized read, a failure hidden by aggregate utility and leakage alone" — a direct measurement of something this atlas asserts and cannot usually show, that a scope filter's value is invisible to any metric that only counts whether the answer was good. Against seven baselines over 2,700 synthetic tasks the reported figures are 94.96% task success and 72.70% exact decision accuracy with zero on each of attack success, leakage, unauthorized access and revocation failure, against 74.67% and 46.41% for the best baseline; the authors label these "single-run controlled results, not deployment-scale claims" over a benchmark that is "synthetic and templated" with simulated actions, one four-agent round per task, and Qwen2.5-7B-Instruct at temperature zero. No code, dataset or artifact is released:rg -i 'github.com|gitlab.com|code will be|code is available|open.source|available at'over the extracted text of the PDF returns zero matches, and the arXiv page carries no availability statement. If an implementation appears, the first things to read are the scope-intersection rule on a derived record and the recursive trust evaluation that is supposed to catch a revoked ancestor, because those two are what the ablation credits and both are the shape this corpus repeatedly finds declared and unwired.pantheon-org/agentic-contextwas examined and has no report: it is a reading list about the context window, and it draws the boundary itself. Atd07dac06…, the last commit of 14 April 2026, the tree is sixty-eight Markdown files, three Python scripts that extract PDF text, build a reference index and sync a source, and an Astro site that publishes the result — seventeen per-tool analyses underanalysis/, twenty-one reference summaries under a topic index, aREVIEWED.mdtriage log and aPUNCHLIST.mdof pending dives. Nothing in it stores anything, and nothing reads a store. Its own README states the scope this atlas would have to overlap with and does not: "given a fixed or sliding context budget, how do agents decide what to put in it?", listinglhl/agentic-memoryas the adjacent repository covering "long-term memory: storage/retrieval across sessions." It is worth recording for two reasons. Its subjects are vendored as seventeen submodules undertools/and its analyses are written against them rather than against a README, which is the discipline this atlas asks of itself; and three of those seventeen already have reports here —context-mode,serenaandgraphify, whose submodule URLsafishamsi/graphifyredirects to theGraphify-Labs/graphifythis atlas pins, a rename worth knowing about before anyone treats the two as different projects. Two claims in its README overstate the tree:references/papers/is described as archived PDFs and holds a.gitkeep, andreferences/bib/is described as BibTeX per arXiv id and holds a README. No licence file, and the pin is the head ofmain.lhl/agentic-memorywas examined and has no report: it is a peer to this atlas rather than a subject for it, and the system worth reading is the one it points at. At8bc58aed…, the last commit of 9 May 2026, the repository is a hundred and sixty-three Markdown files and thirty-eight PDFs with no source file of its own outsidevendor/: thirty-nine analyses of arXiv papers, forty-six reference summaries, about twenty analyses of shipped tools, aREVIEWED.mdtriage log, two punchlists and atemplates/directory holding the two document shapes it writes. It stores nothing an agent writes and retrieves nothing an agent reads, which is this atlas's bar. The method is close enough to this atlas's to be worth naming: subjects are vendored as twelve submodules and read at a named commit — Memobase is verified "against source code at commit358c16bb" — a system that fails triage keeps its entry with the reason, and each promoted analysis ends on the gaps it found. Eight of those twelve subjects have reports here as well:cognee,hermes-agent,hindsight,honcho,mem0,memobase,openvikingandsecond-me.benchmarks/sources/is the part most worth borrowing: it collects the sceptical readings of the benchmarks the field quotes — a LoCoMo audit, Zep's "lies, damn lies" post, two MemPalace issues — rather than the scores. The finding that matters for this atlas is downstream of all that. ItsANALYSIS-shisad.mddocuments shisad, its author's own assistant daemon, atv0.7.3and commitf20930b, and describes a formal trust matrix set by the runtime rather than by callers, per-user and per-workspace scoping that fails closed, a consolidation worker whose writes resolve totrust_band=untrustedby construction, and a poisoning-case fixture — several of the marks this atlas grades for. That repository is public and Apache-2.0 atshisa-ai/shisad, and it has moved since the analysis was written, so the analysis is a pointer rather than a substitute for a reading. No licence file on the research collection itself, which leaves its summaries all-rights-reserved despite the BibTeX block inviting citation.carsteneu/ai-memory-comparisonwas examined and has no report: it is a feature matrix, and the useful thing about it is where it disagrees with this atlas. At287316f9…of 9 September 2026 it is MIT-licensed and holds no memory of its own:data.jscarries one record per system with one field per feature,evidence/holds eighty-six Markdown files citing specific source lines,CRITERIA.mdstates what earns each mark, andbuild.jsrendersindex.htmlandcomparison.mdfrom the data in CI. Eighty-six subjects across seventy-nine features on seven axes, under a rule this atlas would recognise — "If a feature isn't documented in the project's public README, docs, or source code, it's marked—. No assumptions, no inferences", with "Code beats docs" as the tiebreak — and a disclosure that its maintainer wroteyesmem, which it lists under the same rules and which is read here. The comparison it invites is worth writing down. Seventy of its eighty-six subjects have reports on this site; sixteen do not, which is the largest single pointer to uncovered ground this atlas has been handed. Three of its repository URLs return 404 —suanmo/memorybear,tele-ai/telememandmemorix-ai/memorix. The first two are live underSuanmoSuanyangTechnology/MemoryBearandTeleAI-UAGI/telemem, the names pinned here, so a join on its URLs would have reported two covered systems as uncovered; the third is a link this atlas would not follow anyway, because the comparison's own row calls it "Generic vector-store SDK wrapping FAISS/Qdrant — NOT agent memory." The disagreement that runs the other way iscampfirein/byterover-cli, which is the post-rename name of the repository pinned here ascampfirein/byterover-cli— a rename recorded on thebyteroverpage on 9 August 2026, and the second time in this appendix that a corpus-to-corpus join has produced a false gap because a URL cannot see a rename. Both directions are the same lesson: resolve every repository URL through its redirect before concluding that either corpus is missing something.harbor-framework/terminal-benchwas examined and has no report: it is a benchmark, and its unit of work is one session. Terminal-Bench is where frontier agent builders compare capability, and at83c7a617…it holds sixty-six live task directories and ninety-one archived ones, each an instruction, a container, an oracle solution, tests and atask.toml. It stores fixtures and results: a task is a thing to be solved rather than a claim that could turn out false, and a leaderboard row records a run that happened. A run is one task in one fresh container graded at the end, nothing an agent works out in one task reaches the next, and a search of the instructions for a second session, a resumption or a prior run returns nothing — so there is no store that survives a session with an identity a correction could name, which is this atlas's bar. It is recorded on the benchmarks page instead, for two reasons that belong there rather than here: the eight-hour per-task budget makes it a long-context benchmark rather than a memory one, which is the boundary that page draws; and its leaderboard reports a confidence interval, a per-trial duration and a dollar cost on every submission, which is the reporting standard the memory benchmarks catalogued there do not meet.FreshHillyer/xiaoOwas examined and has no report: its long-term memory is an unpublished server behind an MCP client, and the memory crate in the tree has no caller. At3acadbb3…— a GitHub mirror, created 11 September 2026, of openEuler's AgentOS runtime hosted atgitcode.com/openeuler/xiaoO, carrying 1,055 commits of upstream history under the Mulan PSL v2 licence — the live path isapps/shared/src/gateway/memory_automation.rs: opt-in (enableddefaults to false), it callsmemory_searchbefore a turn and renders the hits as<untrusted_long_term_memory>system context, and after a completed turn it enqueues amemory_ingestcall into a durable JSONL queue with file locking, bounded capacity and retry with backoff — for every agent role unlessallowed_agent_rolesnarrows it, since an empty list admits all. The server both calls go to is RAM-A, which the docs configure only ashttp://127.0.0.1:18081/mcp; no link, source or package for it is in the tree, and a GitHub search for it finds nothing — so the store, the retrieval and the forgetting are all outside anything inspectable. The tree does carry a complete memory design of its own:crates/memory, 3,562 lines, with aDurableMemoryManagerover typedPreference/Constraint/Fact/Procedurerecords, filesystem and SQLite stores, recall packets and ahybrid_mergeof lexical and cosine scores. Nothing outside the crate uses any of it:rg -l '\b(DurableMemoryManager|DurableMemoryStore|SqliteDurableMemoryStore|RecallQuery|SemanticMemoryStore|SessionMemoryManager)\b' --type rust . | grep -v crates/memory/returns nothing, no manifest enables the crate'ssqlitefeature (rg -n '"memory/sqlite"' --glob Cargo.tomlfinds nothing), so the 691-line SQLite store is not compiled into any shipped binary, and ofMemoryManager's write methods onlysync_from_loop_statehas a caller —remember_fact,add_instruction,set_current_task,attach_session_memoryand all threebuild_recall*have none. What is wired is a per-sessionMemorySnapshotof messages saved for resume, which is conversation persistence rather than memory. The crate's own tests cover the chunker, the vector arithmetic and the no-op embedder, and nothing that stores. Screened before reading: no auto-running configuration, threebuild.rsfiles, thirty-one manifests inside the seven-day cooldown; nothing was built or run. The unwired crate is the design worth watching: if a later commit gives it a caller, it becomes a report.Abhishekax7/HYDRAwas examined and has no report: its "persistent memory" is a record of which sources belong to which project, and no stored finding is ever read back into a later run. At9b33d894…(MIT, nineteen commits by one author between 2 and 7 September 2026, 14,349 lines of Python in the backend against 13,499 of tests) it is a research platform — LangGraph orchestrating document, dataset and web agents over FAISS-and-BM25 retrieval with correction, citation-linked synthesis, and deterministic grounding and calibration evaluation. What its code calls memory isProjectMemory(backend/app/memory/models.py): a project's name, description, the ids of its documents, datasets and research threads, and a web-research flag. A research request checks that the project exists and attaches the finished run's thread id to it. Each result is saved, and read back only by API routes:rg -n '\.get_result\(|\.list_results\(' backend/appfinds an evaluation endpoint that scores a stored result and two routes that return results for display, and nothing on the research path. The other durable state is LangGraph's SQLite checkpointer, which lets a caller who supplies athread_idresume that thread's workflow state — continuity of one workflow, the same shape as session resume, not a store of claims that could later be scoped, corrected or forgotten. Uploaded documents are a retrieval corpus, not memory. Screened before reading: no auto-running configuration, no build-time execution path, three dependency manifests inside the seven-day cooldown and one unpinned surface; nothing was installed or run.n8group-oss/omarchy-session-memorywas examined and has no report: it restores the terminal, not what the agent knew. Atfe4f518a…(MIT, thirty-eight commits by one author since 24 August 2026, 20,634 lines of Rust with 38,855 of tests)osmcaptures tmux topology on every change through tmux hooks and a fallback daemon, records which coding-agent conversation was running in which pane, and after a reboot rebuilds the sessions, windows and panes and resumes each conversation in its own pane, on its own workspace and monitor. The agent state it keeps isagent_sessions(src/db.rs:271-289): an agent kind, the conversation's native id, its project directory and transcript path, and a one-line title whose schema comment says it is never a summary of what was said, with atitle_sourcecolumn so the agent's words and the user's first line are never confused. It stores pointers into each agent's own transcript store and reopens them; nothing is extracted, recalled into a later conversation, or open to correction — it is session and process restoration, on the far side of the line this atlas draws around conversation persistence. Worth noting for anyone building the same thing: the privacy discipline around titles is deliberate and written down, andagent_resume_debtrecords conversations that could not be resumed rather than dropping them. Screened before reading: no auto-running configuration, no build-time execution path, two manifests inside the seven-day cooldown; nothing was built or run.NodeDB-Lab/nodedbwas examined and has no report: it is a general multi-model database, and the agent memory it advertises is a page of SQL patterns for the application to run. At124cc53a…(Business Source License 1.1 converting to Apache-2.0 on 1 May 2030, with some crates Apache-2.0 already; 3,704 commits since 16 March 2026; about 1.18 million lines of Rust across 25 crates) it is a database server speaking the PostgreSQL wire protocol, with vector, graph, full-text, document, columnar, timeseries, array, spatial and key-value engines, Raft clustering, CRDT sync to an embedded edge edition, row-level security, tenants andAS OFbitemporal queries over system and valid time on the record engines. The crate namednodedb-memis a NUMA-aware allocation governor for engine budgets, not agent memory. What the tree offers agents isdocs/ai/agent-memory.md: example schemas for episodic, semantic and working memory and aCREATE SCHEDULEjob that selects old episodic rows, with the summarization, the insert of distilled facts and the deletion of the originals left to "your app".docs/ai/README.mddraws the same line — "we store, index, search, and fuse. You chunk, embed, rerank, and generate." The README names ma8e, a memory layer for coding agents built on embedded NodeDB, as the consumer; nothing of it is in this repository. The engine is substrate an atlas entry could build on, with bitemporal reads and RLS that many reports here lack, but there is no memory unit, write policy, correction or forgetting of its own to compare. Screened before reading, from a shallow clone: no auto-running configuration, eight build-time execution points, 28 manifests inside the seven-day cooldown and no unpinned surfaces across 36 scanned files; nothing was built or run.offendingcommit/openconchowas examined and has no report: it is a person's console for a Honcho instance, and every memory it touches lives in Honcho's store. Atb5e25646…(MIT, release 0.16.2, 211 commits since 24 April 2026, about 18,000 lines of TypeScript and Rust) it is a React single-page app, a Tauri desktop build, a Docker image that reverse-proxies the Honcho API under its own origin, and a Helm chart. What it keeps itself is browserlocalStorage: the list of Honcho connections with optional tokens (packages/web/src/lib/config.ts:67), user-authored peer-card "seed kits" that are templates of lines likeName:andRole:(lib/seedKits.ts:61), a theme and a demo-mask flag — configuration, not memory. Everything else is a call to Honcho's v3 API through a typedopenapi-fetchclient (src/api/queries.ts): browsing workspaces, peers, sessions, summaries, representations and conclusions; semantic search over conclusions; a dream viewer that renders a consolidation burst as a premise tree; a playground fanning one dialectic query across reasoning levels; and triggeringschedule_dream. It also writes:ConclusionBrowser.tsxcreates and deletes conclusions,PeerDetail.tsxreplaces a peer card, a seed kit applies a card across instances, and sessions and workspaces can be deleted (rg -n 'DELETE\(' packages/web/srcfinds workspace, session, session-peer, conclusion and webhook deletes). That makes it a human review surface for Honcho's memory rather than a memory system with a store, retrieval path or forgetting rule of its own, so it is recorded here and not as a report. Screened before reading: one auto-running surface (.vscode/settings.json), no manifests inside the seven-day cooldown, three build-time execution points and three unpinned surfaces, plus two agent-instruction files read as data; nothing was installed or run.sageox/oxwas examined and has no report: it is the client of a hosted team memory, and the parts that turn sessions into memory run behind the SageOx API. At02f4f406…(MIT, release 0.15.0, 1,001 commits since 12 February 2026, about 280,000 lines of non-test Go) the CLI records every AI coding session by default through agent hooks, strips secrets locally with the patterns ininternal/session/secrets.gobefore upload, and syncs sessions to a team ledger — a git repository hosted on sageox.ai with content in LFS blobs, which the README says cannot be self-hosted. What runs locally is capture, sync,ox agent primecontext loading, andinternal/ledgersearch, an in-memory grep over the sparse-checked-out ledger bounded to 90 days of sessions and plans and 7 days of team messages. The memory-forming steps are remote:ox memory distillsends accumulated observations to the API as anapi.DistillRequest(cmd/ox/memory_distill.go:141-150), and team-context queries go out as anapi.QueryRequestscoped by team and repository ids (cmd/ox/agent_query.go:305-330); fact records ininternal/facts/types.goarrive already extracted, and the only local writer,cmd/ox/memory_put.go:145-155, writes raw observations. The client-side design worth noting isinternal/knowledgeflow, which renders how team knowledge reached a turn at the grade of its evidence — a retrieval or injection event is written as "you consulted X", a self-reported influence is labelled as inferred. The screen found three auto-run surfaces (a Claude plugin directory,.claude/settings.json,.opencode/), one build-time execution point, one unpinned surface and five dependency files inside the cooldown, and readAGENTS.mdandCLAUDE.mdas data; nothing was installed or run.mnemoverse/mcp-memory-serverwas examined and has no report: it is the client of a hosted memory engine, and the store, the ranking and the consolidation all run behind the Mnemoverse API. At08781cba…(MIT, version 0.10.0, 87 commits since 10 April 2026, 4,558 lines of TypeScript against 8,197 lines of tests) it is an MCP server exposing nine tools —memory_write,memory_read,memory_list_recent,memory_feedback,memory_statsand four room tools — over a hosted service the README calls "hosted by design". Nothing durable is written locally:src/requests.tsbuilds request bodies,src/render.tsformats replies, and the outcome-driven re-ranking the README describes (a Rescorla-Wagner update on the prediction error) and the consolidation stage (HDBSCAN with Von Restorff protection, which the README says is designed in and currently switched off) are both properties of a service this repository does not contain. Two things in it are worth recording anyway.src/scope.tsexists because a read never covers rooms — a room is a separate org bucket and the search runs against the caller's own org — so rather than return a silent partial answer the client emits a scope disclosure naming which rooms went unsearched and how to read them, and treats silence as correct in exactly one case, when the caller has no rooms. Andsrc/requests.tscarries a dated postmortem of two scope bugs in one patch release: atrim()on the way out normalised past a deliberate 400-guard in core, so a padded room address "would have written into a shared room visible to other accounts", and the revert dropped a|| undefinedon the read path sodomain: ""becameWHERE domain = '', turning a search of every domain into a guaranteed miss. Sixty tests were green with the divergence in place because the guard test grepped the source for the absence of atrim(); the conclusion written into the file is the one this atlas asks for everywhere — "A denylist over source text is not a contract; a function whose output you can compare is." The paper it cites is arXiv:2603.08965. Screened before reading, from a shallow clone: five files, one auto-run surface, one build-time execution point, one unpinned surface and two dependency files inside the cooldown; nothing was installed and nothing was runnexi-lab/nexuswas examined and has no report: its memory brick was deleted upstream on 15 March 2026, and what remains at the pin is schema with no writer. At66e3b994…, 25 September 2026, Nexus is a distributed virtual filesystem for multi-agent systems — a Rust kernel, ReBAC permissions, IPC pipes, Raft federation and runtime-loadable Python "bricks", 344,403 lines of Python undersrc/outside tests — under Apache-2.0. Commit2dfc23d9…(15 March 2026, "strip LLM brick and all dependent bricks/services") removednexus.bricks.memory— 26 files, 10,117 lines, including the service, paging, enrichment, versioning and state modules — with its REST router, RPC handler, CLI command and the MCP toolsnexus_store_memoryandnexus_query_memory. The residue at the pin has no producer.MemoryModel(src/nexus/storage/models/memory.py:27-34) is still exported and still created byBase.metadata.create_all(src/nexus/storage/record_store.py:360), and no code path inserts a row: its one writer,migrate_identity_memory_v04.py, has no caller. The v2 request models insrc/nexus/server/api/v2/models/memories.pyhave no router underrouters/. Two readers wait on_memory_provider(src/nexus/factory/manifest_adapter.py:41,src/nexus/tools/langgraph/nexus_tools.py:679), and nothing assigns that attribute, so the LangGraph tool returns "Memory system not available". Three surfaces still advertise the deleted system:nexus mcpprints both removed tool names (src/nexus/cli/commands/mcp.py:884-885), the TUI calls eight/api/v2/memoriesroutes (packages/nexus-tui/src/stores/search-store.ts:256-644), and the example agents callnx.memory.store. The MCP integration test that exercises memory skips when the tool is absent (tests/e2e/self_contained/mcp/test_mcp_server_integration.py:298-299), so it passes against the deletion. The commit message says a canary asserts the removed modules raiseModuleNotFoundError;tests/unit/test_llm_removal_canary.py:12-21lists six LLM and ACE modules and no memory module. The last commit carrying the brick is999a9c2a…. Screened before reading: no auto-run surface, 43 build-time execution points, 30 dependency files inside the cooldown — every file in a depth-1 clone dates to the tip — and 15 unpinned surfaces; no agent-instruction file in the tree. Nothing was installed, built or run.aws/strands-dynamodb-storagewas examined and has no report: it is a byte backend beneath the memory layer, not a memory. Apache-2.0, at91a7bd00…, 66 commits from five contributors since 14 August 2026. It is a Python and a TypeScript implementation (826 and 863 lines) of the Strands SDK'sStoragecontract —write,read,delete,listandnamespace, plus an optional vectorsearchover DynamoDBSearchVectors— with S3 offload, gzip and TTL. No file underpython/src,typescript/srcor either test tree namesMemoryStoreorMemoryManager. The onlyMemoryStorein the repository is aDynamoDBMemoryStorebridge that two examples define as application code, withaddandsearchand no delete (examples/semantic-memory/semantic_memory.py:60-94). What would hold memories on this table is the SDK's ownFileMemoryStore, which the Strands Agents report covers. One seam between the two packages belongs on the record. At SDK release 1.55.0, the newest before the pin, the PythonFileMemoryStore.searchpasses its natural-language string straight tostorage.search(store.py:159), andDynamoDBStorage.searchreadsquery.pkon line 432, outside itstry, so a string raisesAttributeError.MemoryManagergathers store searches withreturn_exceptions=Trueand logs a warning (memory_manager.py:327-353), so extraction writes to DynamoDB and every search of that store returns nothing. The TypeScript package rejects a string with a testedStorageError, and the TypeScriptFileMemoryStorescans withlistandreadinstead, so the seam is Python-only. Read, not run.home-assistant/corewas examined and has no report: its assistant forgets every conversation after five idle minutes, and nothing in the tree stores anything the model learned. At087bf875…the Python underhomeassistant/runs to 1,547,500 lines over 1,525 integration directories, and the LLM surface is a small part of it. The chat history lives in ahass.datadict:ChatLogincomponents/conversation/chat_log.pyis keyed byconversation_id, and its cleanup callback at line 150 pops the entry. That callback runs whenhelpers/chat_session.py:102finds a session idle pastCONVERSATION_TIMEOUT = timedelta(minutes=5)(line 28). Every provider integration resends the whole log each turn. OpenAI'sstore_responsesoption (defaultFalse,openai_conversation/const.py:46) keeps responses on OpenAI's side, and no code reads them back;previous_response_idappears nowhere inhomeassistant/.WecoAI/SpecBenchwas examined and has no report: it is a benchmark that measures coding agents, and the only thing it calls memory is a summary of the current search tree that dies with the run. Apache-2.0, Python, at08607352…, a single commit by one contributor dated 21 May 2026: 5,231 lines of harness Python inaide/,experiments/andbenchmarks/outside the 31 task directories underbenchmarks/spec_bench/tasks/. It is the code for "SpecBench: Measuring Reward Hacking in Long-Horizon Coding Agents" (Zhao, Srikanth, Wu and Jiang, Weco AI; arXiv:2605.21384, v1 20 May 2026, v2 9 September 2026). The link is established from both ends rather than assumed. The paper names no URL — the v2 PDF says only "We release the benchmark and methodology", and every GitHub link in the v2 HTML is a third-party citation (OpenCode, Gemini CLI, autoresearch, MiniMax) — but the paper's affiliation and correspondence address are Weco AI, and the repository'sREADME.mdlinksarxiv.org/abs/2605.21384as its paper. Each task pairs a visible validation suite with a held-out suite, and the gap between the two pass rates is the reward-hacking measure; an AIDE, linear or autoresearch outer loop drives Claude Code, Codex or OpenCode. Nothing persists agent memory across sessions. The prompt's Memory section isgenerate_summary()over the in-process solution tree (aide/agent.py:251-260, used at:773), rebuilt at each step.dump_runwrites a per-run JSON for offline analysis (benchmarks/spec_bench/run_loop.py:537), and its counterpartload_run(aide/agent.py:1172) has no caller anywhere in the tree. Workspaces are per node, copied parent to child within one run (benchmarks/spec_bench/workspace.py:88-96), and a root workspace is deleted and recreated if present (:57-58). One thing bears on memory evaluation: that Memory section listsgood_nodes— any non-buggy node with a metric (aide/agent.py:235-236), and the metric is the visible pass rate — so a node that raised it by memorising tests is fed to later steps as a successful experiment, and the paper reports that severe reward-hacking cases "persist across the entire search trajectory". The hacking-critique retrospection path that could interrupt this ships disabled:retrospection_probdefaults to0.0and each metric trigger toFalse(aide/agent.py:304-313), andexperiments/only passes those defaults through. Searches run at the tree root:grep -rn -iE 'memor|remember|recall|persist|resume|session|journal|CLAUDE\.md|AGENTS\.md|history|summar|pickle|json\.dump|sqlite|embedding|vector'over the harness Python (hits are the prompt Memory section, the run dump and the per-node workspace manager);grep -rn 'load_run'(definition only);grep -rn -E '"--(resume|continue)|session_id|--session'over the agent adapters (none;start_new_session=Trueis a subprocess process-group flag). The screen found 0 RUNS, 54 EXEC (per-taskMakefiles andconftest.pys), 0 FRESH and 1 FLOAT (pyproject.tomlwith no lockfile), and nothing was installed, built or run.WecoAI/aidemlwas examined and has no report: its prompt section is literally named "Memory", and it is rebuilt from an empty journal at the start of every run. MIT, 3,432 lines of Python in 21 files underaide/plus 663 lines of tests, at60b3978d…, 3 September 2026, 94 commits since 3 April 2024. AIDE is an ML-engineering agent that searches a tree of candidate scripts. EachNodeholds a plan, code, a model-writtenanalysisand a metric, andJournal.generate_summary(aide/journal.py:229-239) joins plan, analysis and metric over every node not flaggedis_buggyinto the"Memory"key of the draft and improve prompts (aide/agent.py:284,aide/agent.py:317). The paper, arXiv:2502.13138 (18 February 2025), describes reuse inside one task's tree search and claims nothing across runs, so paper and code agree.facebookresearch/HyperAgentswas examined and has no report: the memory its paper describes is something an evolved agent wrote, and it is not in the committed program. Hyperagents (arXiv:2603.19461, submitted 19 March 2026; Zhang, Zhao, Yang, Foerster, Clune, Jiang, Devlin, Shavrina) extends the Darwin Gödel Machine so the meta agent that rewrites the task agent can also rewrite itself (DGM-H). At59a68f67…— CC BY-NC-SA 4.0, 26,398 lines of Python over 120 files, 9 commits from 19 March to 14 April 2026 — the durable state is the HGM shape:archive.jsonlappends generation ids (utils/gl_utils.py:160-176), each generation stores ametadata.json, amodel_patch.diffand its scores, andselect_parentsamples a parent by sigmoid-squashed score times a child-count penalty (utils/gl_utils.py:571-584, the CLI defaultscore_child_prop). That is a population of program versions and their measurements, read by the outer loop.ensemble.pyreads the archive per task, but only to return the cached prediction of the best-scoring generation for that question id. The paper's memory is emergent. Its §5.2 and Appendix E.3.7 show aMemoryToolover./memory.jsonholding timestamped, keyed entries — "gen65 changes over-corrected" is one — which the paper says later self-modification steps consulted. Those are claims that could be false, which HGM's tree never held, and this is the case the Gödel-machine note said would enter the atlas. It does not enter at this pin, because the code is not in the tree:MemoryTool,memory.json,PerformanceTrackerandperformance_historyreturn zero matches, and every Python use ofmemorymeans RAM. The evolved agents are published only as experiment logs on Google Drive, which were not read. The committed starting meta agent does not name the archive either:meta_agent.py:16builds the whole instruction as "Modify any part of the codebase at{repo_path}" and leaves theeval_pathanditerations_leftarguments unused, so the archive copied into its container bycopy_prev_eval_to_container(generate_loop.py:363-424) is there on disk and never mentioned in a prompt. The harness does carry a file across generations without being designed to.diff_versus_commitincludes untracked files in each child's patch (utils/git_utils.py:36-69) and descendants replay the lineage patches, so a note an agent writes inside the repository is inherited by its descendants as code. A note written under the git-ignoredoutputs/, where the paper'sPerformanceTrackerwrites by default, is not carried. Nothing in the paper's excerpt corrects an entry except overwriting it by key. The licence is non-commercial with no rider on analysis. Screen: 0 auto-run, 0 build-time exec, 0 inside cooldown, 1 unpinned surface (four git requirements, two without a commit); nothing installed, built or run.davidondrej/cloudroom-corewas examined and has no report: it saves every coding-agent session's history and hands none of it back to an agent. Apache-2.0, 18,056 lines of Rust in 44 files undersrc/plus 5,325 lines of tests, at17571eb7…, 26 September 2026, 11 commits since 17 September 2026. It is one Rust service per Linux VM that runs Codex, Claude Code, Pi and Cursor as unprivileged child processes behind a token-authenticated HTTP API. Its one durable table,cloudroom_records(docs/database/0001-session-records.sql:11-17), is keyed(store, session_id, sequence)and holds ordered receipts and native output. Its readers select bysession_idand serveGET /v1/sessions/{id}/eventsto clients (src/session/history.rs:127-129,src/session/mod.rs:456-476), and no statement insrc/deletes from it. Continuity across idle periods is the harness's own native resume (src/session/sleep.rs:193-198), and compaction is forwarded to the harness (src/session/mod.rs:1049). The sync roots insrc/sync/mod.rs:148-182copy skills, Cursor rules, settings files and MCP server entries from a Mac to the VM, which is configuration, not learned state. The dependencies areaxum,tokio,serde,serde_json,sqlxandtokio-stream, so no memory engine sits behind it. What earns the entry is the upload upsert, which keeps the first stored record on a key collision and returns whether the retransmitted text matched (src/session/history.rs:57-61), so a retry after a lost commit reply is idempotent and a different record under the same sequence is detected rather than overwritten.Stanford-TML/homebodywas examined and has no report: it is a humanoid system whose memory is described on a project page and whose code is not released. HomeBody: A Humanoid That Explores, Remembers, and Acts on Its Own (Huh, Gu, Truong, Liu, Tevet; Caltech and Stanford, September 2026) is described at tml.stanford.edu/homebody, which links no paper; an arXiv search forHomeBodyon 28 September 2026 returned nothing matching. The repository at77d2c333…, six commits on 26 September 2026 and no licence file, is that project page: a README that says "Code coming soon.", and underdocs/oneindex.html, 22 scripts (a three.js viewer, video playback, andsite.js, whose only memory-related strings are the architecture figure's labels), 105 images, 20 videos and the point clouds and meshes of a reconstructed kitchen;docs/LICENSES.txtcovers the vendored three.js, fonts and hls.js. What the page describes is a spatial memory for a Unitree G1 driven by a frontier VLM through a skill library. Exploration records camera, LiDAR SLAM, joint and waypoint data; a VLM agent builds an Isaac Sim digital twin from it; Super Odometry and ICP put the robot, the map and the twin in one frame; and the system "stores ego camera observations in this shared frame, together with descriptive content", from which the VLM picks a skill and target using the ego view, map context, gripper state, "recalled observations" and the previous result. The page does not say how a stored observation is updated when an object moves, whether one is ever retired, or what the VLM is shown when two disagree — the questions a report here would read the code for. Searches:gh api 'repos/Stanford-TML/homebody/git/trees/HEAD?recursive=1'lists every blob (webp, js, mp4, svg, json, gz, txt, ply, glb and one each of md, html, css, png, ico, woff2, and the dotfiles), none of them system code;grep -n -i -E 'memory|keyframe|recall|remember|vlm|astra|skill'overdocs/scripts/*.jsmatches only figure markup. Re-examine when the code is published.mcn92/pikeletwas examined and has no report: its records can now be retired and replaced by id, but only by whoever compiles the corpus, and nothing an agent learns can reach them. Apache-2.0 (Matthew Noonan), 74,482 lines of JavaScript, Rust and Python over 270 files atd00f50ac…(the 0.9.2 release, 1 October 2026), created 20 April 2026. It compiles a corpus into a single self-contained.pikeletfile — source text, semantic and keyword indexes, query encoder, integrity commitments, retrieval calibration and evaluation fixtures — served over HTTP Range reads from static storage and mounted for an agent over MCP. The artifact rule is unchanged (spec/SEARCH_ARTIFACT_CONTRACT.md:106-110: an artifact "is immutable after publication", and a superseding one has a new identity). What releases 0.9.0 to 0.9.2 add is the layered profile,LAYERED_PROFILE.md, which keeps every file immutable and makes the corpus mutable by chaining files.pikelet appendwrites a small layer over a parent: new records chunked from--sourcedocuments, a cumulative tombstone bitset over global record ids from--remove, and(oldId, newId)supersession edges from--supersede <oldId>=<sourcePath>.compactfolds a chain back into one base whose lineage segment translates old citations forward, andrebasereplays only the deletions a layer itself introduced onto another head. The read side is careful. The mask is applied before candidate selection, and a tombstoned record stays hydratable by id "because an agent may have cited it" (decision 4,LAYERED_PROFILE.md:142-152). MCPget_recordreturns it withtombstoned: trueand itscurrentSuccessor, fields the result whitelist inprovenanced()(packages/pikelet/src/mcp.mjs:145-168) had been dropping, which, per the comment there, turned a tombstoned record into a live one on its way to the model;test/mcp_conformance.mjsdoes not mention the field. Two things keep it outside. The first is who writes. The MCP server dispatches four tools,search,list_packs,verify_packandget_record(packages/pikelet/src/mcp.mjs:872-875), and none of them writes.appendLayer,compactChainandrebaseLayerare called frompackages/pikelet/src/cli.mjs:27-39and the tests and nowhere else, and the profile's non-goals open with "Readers never write" (LAYERED_PROFILE.md:1617). A layer's input is a document path run through the base's declared chunker, so--supersedeswaps a corpus chunk for a re-ingested file: a publisher shipping a corrected manual, not an agent revising a conclusion. The second is what a correction is. A tombstone is a bit on a row id, un-deletion is a non-goal, and decision 9 (LAYERED_PROFILE.md:184-187) gives records "identity within a history, not content identity", so appending bytes equal to a removed record creates a new live id that nothing suppresses. That is the hide-a-row correction, chosen deliberately for a corpus in which re-publishing a document is meant to bring it back. A versioned document index with an honest update path is still the document-index case. The profile's status line (LAYERED_PROFILE.md:6) still reads "not implemented" while the CLI ships it andtest/layered_profile.mjsis in thenpm testchain; its section 13 records BEIR measurements of what layering costs, with the result files underbenchmarks/beir/results/. Recorded rather than dropped for two findings that still hold at this pin. The ablation experiment is the shape this atlas asks for and rarely finds: a pack was rebuilt byte-for-byte identical except for the record carrying one fact, the retrieval result moved frommatchQuality: strongat confidence 0.915 tononeat 0.136, and a third pack changed the same record's value and the grounded answer followed it (docs/veyra-ablation.md). The write-up separates what is reproducible from what is not —examples/one-file-search/web/public/reproduce-ablation.mjsre-derives the retrieval-side numbers, while the paired model sessions are marked "a described observation rather than a reproducible result" — and it refuses the overclaim the experiment invites, stating that this "does not mean Pikelet can prevent an LLM from hallucinating." The limit on citing it is that the script prints rather than asserts, and the packs it reads are release assets fetched bynpm run demo:veyra, so nothing fails in CI when the numbers move. The part that does run is the committed abstention fixture:test/fixtures/encoder-conformance/abstention-golden.jsonholds ten labelled queries, five of them labellednone, andtest/complete_profile.mjs:848-855requires all ten to reproduce their label and a query labellednoneto return zero results, inside thenpm testchain (package.json:23). That is the store-level must-not-retrieve assertion this atlas looks for, built for a search index. It holds for the library call, whose default withholds results undernone; the MCPsearchtool ships them by default (showAbstained,packages/pikelet/src/mcp.mjs:202), so what an agent sees is the verdict, not an empty list. Searches run at this pin:git grep -nE "appendLayer|compactChain|rebaseLayer"(the CLI, the three definitions andtest/layered_profile.mjs);grep -n "toolName ===" packages/pikelet/src/mcp.mjs(four read tools);git grep -nE "request\.method|method === 'POST'" -- packages(the two Worker templates, whose only POST routes are/searchand/reset_cache). The admin-gated/addand/deleteroutes inexamples/legacy/reference-worker/worker.jsare an HNSW index service already present at the first examination,9f81ad79…, and no MCP tool reaches them.veersaraf/forgetting-benchwas examined and has no report, because it measures the thing rather than being it — and its measurements are worth carrying anyway. MIT, Python, 3,304 lines over 34 files at12596f7d…, dated 4 September 2026. It is "[a] benchmark for whether agent memory forgets — not just whether it recalls", built on the observation that the mainstream libraries "are built and benchmarked around recall" while "the under-measured half of long-horizon memory is whether an agent forgets stale facts, resolves contradictions, and stays bounded over thousands of turns". A reference memory core ships with it, but it exists to be measured, which is what puts this here rather than in a report. Four things in it are worth a reader's time. The first is the design decision that keeps the contradiction metric from being a tautology: the memory core does not receive clean slot keys, it extracts(entity, attribute)from raw text with a trained tagger, and 40% of updates are deliberately phrased to defeat it — implicit or numeric updates like "Alice relocated to Denver" that never restate the attribute — while the metric is scored against ground truth the memory never sees. A benchmark whose contradiction rate reached zero "would be measuring its own plumbing, not memory quality". The second is the resulting floor: across keep-everything, last-write-wins, Ebbinghaus decay and a learned policy, the stale-fact contradiction rate bottoms out near 0.33 and no policy beats it, because extraction misses set it. The third is what decay actually buys over per-slot dedup, which is the mem0-style bar: not contradictions and not recall, which match within noise (0.319 against 0.330, and 0.668 against 0.670), but bounded memory — about 40% fewer entries and 42% fewer tokens, with the gap widening over the horizon, because last-write-wins "never forgets what it can't slot" and distractor noise therefore accumulates forever. The fourth is that forgetting is a frontier rather than a setting: sweeping the decay constant moves between 0.10 contradictions at 0.50 recall and 0.67 recall at the 0.33 floor, and per-slot dedup is one fixed point on that curve. What earns the entry, beyond the numbers, is the reporting. The one result that flatters the worst policy is kept and explained rather than dropped — keep-everything "wins" precision and recall because "retaining every past value means old entries whose value coincidentally equals the current one get counted as correct hits", which is "hoarding, not skill", and is the same hoarding that gives it by far the worst contradiction rate. And the live adapters for the commercial libraries are marked "probed, not scored", with the scope of the claim stated plainly: "No claim here is a mem0 or Letta win."cp-lab-uts/Knowledge-State-Governancewas examined and has no report: it is a paper artifact with no memory system in it, and its central table is the clearest measurement of this atlas's own thesis that the corpus has. No licence file, Python, at706c7e82…, dated 7 September 2026 — code and frozen results for "Relevant but Inadmissible: Budgeted Knowledge-State Governance for Persistent Large Language Model Agents" (Zhu, Zhu, Ye, He, Zuo and Wang). The title is the argument. A record can be exactly what a query asks for and still be one the agent must not be given, because something superseded it, because it belongs to a branch that was closed, or because a record it depended on is no longer valid.derive_statusescomputes those three classes from supersession links,closes_branch_idand dependency edges stored on the episode, and a budgeted packer then fills a token budget from the admissible set only. The measured result, over 60 episodes at 4,096 and 8,192 tokens with 2,000 bootstrap samples, is inexperiments/results/table_a_stateshift_admission.csv, and three rows carry it. Hybrid retrieval and recency both score a current-evidence rate of 1.0 — and a superseded-admission rate, a branch-leak rate and a dependency-invalid admission rate of 1.0 as well, at both budgets: perfect relevance, and every inadmissible record admitted along with it. The governance policy holds the same current-evidence rate of 1.0 with all three at 0.0. The third row is the one to carry: an LLM judge asked to decide admissibility scores 0.70 current-evidence recall while still admitting 0.27 of superseded records, 0.17 of dependency-invalid ones and 0.06 off-branch — worse on both axes than a deterministic rule over links the store already holds. Whenever this atlas withholds a review mark because the adjudicator is a model rather than a person or a rule, that row is the measurement behind the judgement. The repository also carriesuse_branchanduse_dependencyablation switches so each component's contribution is separable, human-audit utilities with a disagreements file beside the summary, and frozen aggregates chosen so the manuscript's numbers can be checked without rerunning a hosted model. It is reviewed without a licence file, which for a paper artifact bounds reuse rather than reading.Brain0-ai/brain0was examined and has no report: what it durably holds is what happened, not what is true — and one mechanism in it answers a question this atlas asks of every system. Apache-2.0, Rust with a TypeScript GUI, 16,675 lines across 52 Rust files at68edafc0…, dated 9 September 2026. It is "[t]he black box for AI-written code": "gittells you what changed. brain0 tells you why: which prompt wrote it, what the agent read to write it, and whether you can trust it." It passively builds a decision graph linking every commit to the agent intents behind it, down to the function, with a DLP audit of what agents read and a risk score, reading "git and the transcripts your agents already write to disk" with "[n]o hooks, no agent cooperation, no code changes". Everything it stores is a historical event — this prompt was issued, this file was read, these lines changed — and a later reading cannot contradict any of it, only find it recorded wrongly. That is the scope line this atlas draws for an audit log or a task queue, and it is why there is no report rather than a criticism. What earns the entry isbrain0-reconcile, which refuses to take an agent's word for its own work. "A coding agent declares what it changed (via MCP). The observer records what actually changed." The crate compares them and does two things with the comparison: gap-filling, so "everything that actually changed is linked to the agent's task even if the agent never mentioned it, so the graph is complete", and drift detection, so "when declared and done diverge (e.g. 'I only touched X' but 12 files changed), the discrepancy is recorded as a first-classDriftsignal on the task and feeds the a-priori risk." This atlas withholds a review mark whenever the only evidence of an actor is a string that actor supplied; brain0 applies the same instinct to an agent's account of its own changes, treats the self-report as a claim rather than as the record, and stores the gap between claim and observation as data. Any system that asks an agent to summarise what it did has the same exposure and, usually, no observer to check it against.zhengkid/Dream-RSIwas examined and has no report: no code is released yet, and what it stores is a record of what happened rather than a claim that could turn out false — but its bound on replay is the thing to take. Dream-RSI: Recursive Self-Improvement through Evolving Worlds, Zheng, Wu, Zhang, He, Zhang, Coleman, Wei, Bai, Liu, Liu, Wang, Zhuan, Kang, Xiang, Huang, Cheng and Guo (Google, Google DeepMind, University of Maryland, University of Virginia), © 2026 Google, at4149ea91…, dated 16 September 2026. The search is written down because the absence is the first finding: the repository holdsREADME.md,CITATION.cff, a PDF underpapers/and anassets/directory, and nothing else — zero files matching*.py,*.rs,*.ts,*.js,*.goor*.ipynb, and no licence file. The README's own release table says it: paper "✅ Available", full codebase "⏳ Being prepared". The idea is that a completed discovery run is already a simulator. Each node of a discovery tree "preserves this inherited history and records the outcome of the new generation–evaluation attempt, including the resulting filesystem snapshot, generated artifact, evaluation diagnostics, and score", so "[s]ince all node outcomes are pre-stored, a single costly online run enables thousands of rapid, zero-execution-cost off-policy evaluations" — alternative exploration policies are scored by walking the recorded tree instead of re-running the agent. That is durable agent history put to a use this atlas does not otherwise track: not recall, but counterfactual evaluation. It is out of scope for the same reasonBrain0-ai/brain0above is — the trees record attempts and their realized outcomes, and a later reading cannot contradict "this attempt scored 0.71", only find it written down wrong. What earns the entry is where the exactness stops, because the paper puts the bound in the formalism rather than in prose. Replay reveals only what was recorded: "each branch is traversed in its recorded parent–child order, and no outcomes beyondT_iare generated", and the child set is empty "when no recorded continuation remains", so the simulator runs out rather than extrapolating. The improvement guarantee is scoped the same way — because the candidate set includes the incumbent, the selected policy "is no worse than the current policy … in average replay score on the fixed history", which is a claim about the replay score on a frozen history and deliberately not one about the world. Any memory that answers "what would have happened" from stored history owes a reader exactly those two sentences: where its coverage ends, and which quantity its guarantee is over.- arXiv:2609.11060 was
analysed and has no report: the mechanism is two prompt blocks and a
tool grant inside a curator nobody outside the authors can run.
Grounding Agent Memory: Environment-Probing Curation for Enterprise
Agents (Susheel Suresh, Hazel Mak, Sahil Bhatnagar, Chhaya Methani
and Alejandro Gutierrez Munoz, Microsoft Corporation, submitted 10
September 2026, cs.AI and cs.SE, no venue named) describes a store whose
only mutator is an asynchronous post-task curator agent; the task agent
holds
memory_readand no write tool at all. A record iscategory: pattern | rule | trap | schema | policy | interaction,confidence: high | medium | low,applies_to: a short retrieval scopeandlemma: one concise, actionable claim, with "provenance, utility, and usage metadata" named once in §3.2 and never specified, shown or used. The intervention is small and stated as such: the same curator, schema, retriever, distiller and CRUD policy, plus a read-only subset of the task's own environment tools and two inserted prompt blocks telling it to "verify candidate and existing memories before Create or Update whenever correctness, scope, freshness, or actionability is uncertain" — propose, probe, commit. The claim an atlas report would test is drift repair: CLBench migrates its schema silently after question 20, and the trajectory-only curator carries "Useattrs_g3" forward while the probing curator rewrites it to "Useproduct_attributes_g3". That repair is opportunistic, not a mechanism — it fires when a later task in that area closes, nothing watches the environment, and a contradicted record is removed withmemory_deleterather than kept as a rejected value, so the store has no trace that a lemma was once believed and no valid-time axis on which to ask what it believed last week. The headline 39% to 73% pass rate is memory against no memory; the paper's own contribution moves 70±16 to 73±5 pass and 20.00±6.52 to 22.60±2.07 reward over five paired runs, which §5.3 concedes ("[b]ecause uncertainty intervals overlap, we treat this as a mechanism interpretation rather than a resolved subgroup effect") and the abstract does not. The separation that survives is in variance rather than means, and the cross-model no-drift table is cleaner on Sonnet 4.6 (+0.421 against +0.351) than on Opus 4.7 (+0.263 against +0.252). "Task-agent cost from $3.38 to $1.68" is the synchronous half only: §4 says "task-agent cost excludes the separately tracked curation phase", the per-world table adds that "costs exclude distillation/curation", and no curation figure is reported anywhere, while probing adds curator tool calls by construction and the distiller and curator run the samegpt-5.4at xhigh effort as the task agent. Retrieval is never under test — a transcript in Appendix E.3 readsmemory_read: showing 11/21 matched entries (query asked for top-25; index holds 21 total), so at fifteen to twenty-one records a world the reader returns most of the store and the result measures what got written. The question the deployment section raises and never answers is whose grants a probe runs under: §A.2 assigns the curator "a least-privilege, read-only subset of connectors or MCP tools already registered for the responding agent" and asserts that "existing authentication, authorization, and audit boundaries remain in force", but the word tenant does not appear in the paper,applies_tois a retrieval string the curator writes rather than a key any read path enforces, and a lemma validated against one user's view of an enterprise corpus is committed to an index later task agents read — the scope-predicate shape this atlas finds in running code again and again. "Auditable" appears once, in the abstract, with no probe log or lemma-to-probe link behind it. The grounding search: 14,488 words extracted from the v1 HTML, onegithub.comURL in the whole text and it isgithub/copilot-sdk, no code- or data-availability statement, and the adapted APEX split — six worlds and 90 tasks grouped by(domain, world_id)out of the 480-task original — is not released either, so the benchmark variant is no more reproducible than the system. The only code trace is downstream and is a request rather than an artifact: issue 107914 onNousResearch/hermes-agent, opened 11 September 2026, proposes the same loop for that project'sagent/background_review.py, whose staged writes Hermes Agent already records with anoriginofforegroundorbackground_review. If code appears, the first things to read are the probe-tool binding — which credential a probe uses and whether the probe result is stored beside the lemma it validated — and then whetherconfidenceandapplies_toever reach the read path or stop at the write. augustoolucas/yacaowas examined and has no report: the only thing its workflow durably writes is a plan for the job in hand, and the only thing its code durably writes is a version pin in your config. MIT, 927 lines across 14 files at12079c75…, v0.4.3, 107 commits since 22 July 2026. Yet Another Coding Agent Orchestrator is a plugin for OpenCode whose whole content is two agent definitions and three skills: an orchestrator that clarifies, plans and reviews, and a builder subagent that implements one self-contained task contract at a time and answers in a fixed four-field format —STATUSovercomplete/partial/blocked/escalate,CHANGES,VERIFIED("exact command(s) run and their real output (not 'should pass')") andGAPS. It is workflow, and it says so. The vocabulary settles the scope question rather than the README: across every.js,.mdand.jsonin the tree,memor,recall,remember,forget,persist,belief,retriev,embedding,sqlite,vectorandknowledgereturn three incidental hits — memorize in the README's prose, a comment about persisting an update-check timestamp, and "[r]egisters the agents in memory" meaning in-process. The planning skill does write durable files,.opencode/plans/plan-<slug>/plan.mdand one task contract per task, and nothing in the three skills or the two prompts reads an earlier plan back: they are a work ledger for the current job, which is the line this atlas already draws forbeadsandoh-my-openagent. What earns the entry is the other durable write. WithautoUpdateon, the plugin fetches the latest release tag from the GitHub API and rewrites the user'sopencode.jsoncin place to pin the plugin spec forward, preserving jsonc comments and quote style by rewriting raw text rather than reparsing, andupdateScope: "all"extends that to the project's own config. It defaults to off and the write is temp-file-then-rename with the original mode copied — careful work. It is still a plugin that edits the file that decides which plugins you load, which is worth knowing before the screen in this repository's own screening skill is pointed at the next thing that does it less carefully.
Weights as memory, at adapter granularity
Low-rank adapters are commodity rather than exploratory, published and exchanged as artifacts, so the question of whether this atlas's capabilities have a referent in a fine-tuned model is not hypothetical. The answer is that the unit of identity is the adapter, never the record inside it, and that single fact decides which capabilities survive the move into weights and which do not.
Four of the seven survive at adapter granularity,
and the corpus already proves it. Scope is enforceable by routing —
which adapter loads for which user or project — and MemOS carries the
scope_enforced mark on exactly that basis while mounting a
parametric module. A training manifest can record which corpus and which
base-model version produced an adapter, which is a real audit trail over
training mutations. Adapter v2 superseding v1 at
deployment is real supersession, and discarding an adapter is a real
deletion. Validity intervals over adapter versions are ordinary
bi-temporality.
What fails is anything that needs record identity, and that is the atlas's admission test rather than a side issue. A delta is opaque: no read path reports what it learned from a given document, so "why does the system believe this" has no answer at the level the question is asked. Nothing can be superseded inside an adapter — only the whole adapter. Nothing can be deleted from one; a deletion request that names a record is answered by retraining without it, which requires still holding the corpus the request asked you to destroy. And a merged adapter carries its contributions irreversibly, while a withdrawn one reaches neither the copies already taken nor the merges downstream of them.
So the honest statement is not that weights cannot carry these mechanisms. It is that weights carry them at a granularity coarser than the thing a correction names, and that no implementation reviewed here closes the gap. None of this rests on how many adapters exist or how popular any host is — it rests on the shape of the artifact and on what the reviewed systems actually do, which are the only things worth resting on.
Below the adapter there is a coarser case, and it removes all
four. mini-AGI has no
adapter and no artifact boundary at all: one model, one weights
directory, and a gradient step taken on every 2,048 characters of
whatever it reads — a book, a directory somebody pointed it at, or the
exchange a person just had with it. There is no v2 to supersede
v1, no manifest recording which corpus produced which delta,
and no discarding of a unit, because the unit is the whole thing. Scope
is not enforceable by routing either, since routing here is a paging
decision made from the text being read rather than from who is asking.
So the four capabilities that survive at adapter granularity survive
because the adapter is a discrete, versioned, detachable
artifact — and none of them is a property of weights as such. Its one
deletion, prune(), removes an expert file that the router
has not chosen inside a survival window; the docstring states the trade
plainly — "an expert which is genuinely rare rather than dead is
deleted, and deletion is permanent" — and nothing about it can be
aimed at a fact. That is the boundary condition worth carrying: the
finer the weight artifact, the more of this list you keep, and at zero
granularity you keep none of it.
The distributional escape does not work either. It is tempting to hold that an adapter trained for shape — schema, vocabulary, house style — stores nothing correctable and so escapes all of this. Style adapters demonstrably encode the sources they were trained on; that is why withdrawal requests are made about them at all. Distribution and content are a spectrum, not a boundary, and a system that treats the distinction as a safety argument has made an unmeasured assumption. The build-side consequence is in what I would build, and the two should be read together.