Claude-Mem Records Every Agent Tool Call Into a Local SQLite File and Feeds It Back Next Session
Software / news
Claude-Mem Records Every Agent Tool Call Into a Local SQLite File and Feeds It Back Next Session
The Apache-2.0 plugin has 95,940 stars. A July 2026 arXiv paper on poisoned memory files did not test it, but it describes the risk of any store an agent re-reads.
Claude-mem, a plugin that records what a coding agent does and feeds a compressed version back into later sessions, gained 627 stars on October 4, 2026 on GitHub trending and now has 95,940. It stores everything in a local SQLite database, uses an AI provider you choose to summarise it, and we found no published security analysis of it.
The repository, thedotmack/claude-mem, is credited to Alex Newman under the handle @thedotmack. GitHub's API shows an Apache License 2.0, a creation date of August 31, 2025 and 110 open issues.
What it captures and where it keeps it
The README describes it as a system that "captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions." Installation is one command, npx claude-mem install, and it supports Claude Code, OpenClaw, Codex and other agents.
Capture runs through five lifecycle hooks: SessionStart, UserPromptSubmit, PostToolUse, Stop and SessionEnd.
The database lives in ~/.claude-mem/ and uses SQLite 3 with FTS5 full-text search. A local HTTP worker, managed by Bun, serves a web viewer and search endpoints on a port set in settings.json. Observations are tagged by type, including decision, bugfix, security_alert and sensitive.
Who sees the data
Compression is not local by default. The README lists the default as the claude-mem observer, with a free 14-day trial, and alternatives of OpenRouter, the Gemini API or your own Anthropic plan. Whichever you pick receives the observations it is asked to summarise.
Optional cloud backup goes to cmem.ai, which the README says syncs "on write" and needs an email magic-link sign-in. A <private> tag excludes marked text from storage and compression entirely, so keeping a secret out depends on the user tagging it.
| Setting | What the README says |
|---|---|
| Storage | SQLite with FTS5, in ~/.claude-mem/ |
| Compression | claude-mem observer (14-day trial), OpenRouter, Gemini API or Anthropic plan |
| Cloud sync | Optional, cmem.ai, magic-link sign-in |
| Exclusion | <private> tags |
The README claims "~10x token savings." It describes the method as progressive disclosure: compact search results of roughly 50 to 100 tokens, then a timeline, then full details at roughly 500 to 1,000 tokens each for filtered IDs. That is the project's claim, and we found no independent measurement.
The risk the stored text creates
A store that an agent re-reads is a store an attacker can aim at. A paper posted to arXiv on July 16, 2026, Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems, by Soham Gadgil, David Alexander, Sai Sunku and Franziska Roesner, tested Claude Code and OpenAI's Codex across four models: Claude Haiku 4.5, Claude Opus 4.7, GPT-5.2 and GPT-5.5.
Its finding is narrow. The agents resisted overwriting their own memory with untrusted external content, but "payloads already planted in those files can successfully attack current and future sessions." Success varied by system, model and objective.
The paper studied memory files, not claude-mem, and we have not seen anyone test claude-mem against it. The shared lesson is about direction of trust. Anything an agent reads from a web page or a dependency during a session becomes an observation, and an observation that is summarised and re-injected next week is text the agent treats as its own history.
What a user can check today
Open ~/.claude-mem/ and read what has been stored after a week of use. Check which compression provider is set in settings.json, and whether cloud sync is on. Mark anything sensitive with <private>.
For more on agent security, see our earlier piece on leaky agent sandboxes, and for another fast-rising agent repository, Agent-Reach.
Sources
More in Software
- 01OpenCut Has 92,200 Stars, but the Editor People Use Is the Classic One and the Rewrite Is Not Taking ContributionsThe open-source CapCut alternative rebuilt its default branch in May. The README and a third-party walkthrough disagree on how much of the new code is Rust.
- 02Impeccable's Design Detector Runs Without a Model, but Its Open Issues Show Gaps Outside .htmlPaul Bakaus's design skill for coding agents ships 61 deterministic rules you can run from the command line. The bug tracker says where they are least reliable.
- 03A Hacker News Post Says Agents Need Documentation, Not Memory, and Its Author Wrote the Plugin That Does ThatKevin Liao's October 3 essay attacks snippet-recall memory plugins and promotes Operator Memory. A separate September essay argues the real gap is neither memory nor documents.
- 04Agent Reach, at 90,900 Stars, Reads X and Reddit for Your Agent Through Your Own CookiesThe MIT-licensed CLI routes agents to 20-plus sites with a backup backend per channel. Its README admits the login channels can get an account banned.