The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Memini listing page.
Never the same mistake twice. Mistake-prevention guardrails and persistent project memory for AI coding agents.
AI coding agents are stateless: every session starts with amnesia. The agent that broke your build editing vercel.json on Monday will happily try the exact same edit on Thursday. memini gives each repo a persistent memory of failed attempts, fragile files, decisions, and deployment rules — and force-feeds the relevant warning to the agent at the moment it's about to repeat history.
Not a notebook the agent may choose to read. A guardrail it can't skip.

.memini/ folder with a local SQLite index and human-readable, PR-reviewable markdown views. Local-first: nothing leaves your machine.
[WARNING] Editing vercel.json broke the build (recorded 2026-07-03)— Tried changing buildCommand; deploy failed. Actual fix: move checkout server-side and setVITE_STRIPE_USE_SERVER=true.
warn severity: the agent is warned once per session, then may proceed.block severity: the edit is always denied until a human archives the memory.remember_failed_attempt, remember_fragile_file, remember_decision, end_session_summary, plus recall_project_context and check_before_editing.pm stale flags memories whose evidence has changed, and stale memories stop firing guardrails until re-verified.That's it. Next time any Claude Code session in this repo tries to edit vercel.json, it gets the warning first.
Cursor, Windsurf, and other MCP clients:
Enforcement is a chain of gates, and memini covers several:
block → denied, warn → the user is prompted with the recorded history. Supported on:
pm init installs itpm install-mcp --write cursorpm install-copilotblock-severity file, no matter which IDE or agent made the edit (Windsurf, Cline, a human…).
Installed by pm init (or pm install-hooks --git). Fails open; overridable with
git commit --no-verify.check_before_editing / recall_project_context tools,
plus an always-applied Cursor rule steering the agent to use them.A memory tool is only as good as what's in it, and it rots if left alone. memini keeps it healthy:
pm remember. It stays silent on idle sessions.pm stats
shows which memories are pulling their weight and which have never fired.pm review — flags near-duplicates, contradictory guardrails on the same file, and dormant
guardrails that have never fired long after creation. All local heuristics, no LLM — you decide
what to keep, merge, or archive.pm stale / pm verify).| Command | What it does |
|---|---|
pm init | Set up .memini/, gitignore, and hooks |
pm remember <type> <title> [-b body] [--file f...] [--severity warn|block] | Record a memory |
pm recall [query] [--file f] [--digest] | Search memories / preview the agent digest |
pm check <path> | Guardrail check (exit 1 if risks recorded) — usable in CI |
pm list / show / archive / approve <id> | Manage memories |
pm stats | What your memory is doing — guardrail fires, coverage, staleness |
pm review | Surface quality issues: duplicates, contradictions, dormant guardrails |
pm stale / pm verify <id> | Detect and re-verify outdated memories |
pm mcp | Run the MCP server (stdio) |
pm doctor | Diagnose setup |
Memory types: decision, failed_attempt, fragile_file, architecture, deployment, client_preference, session_summary.
Some lessons are project-specific; some apply to every repo on your machine that belongs to the same org or client. memini has three scopes:
| Scope | Where it lives | Use it for |
|---|---|---|
project (default) | <repo>/.memini/ | this repo's failed fixes, fragile files, decisions |
workspace | .memini/ in a parent folder of your repos | org/client conventions shared by every repo under that folder |
user | ~/.memini/ | personal rules that follow you everywhere |
Every repo under the workspace folder — including ones you create later — gets those guardrails automatically. Resolution walks up the directory tree, like .gitconfig or ESLint configs. Workspace/user file guardrails match by glob (vercel.json matches any repo's vercel.json; config/**/*.yml works too), and wider-scope memories only fire when human-verified — agents can propose memories to project scope only, so a prompt-injected agent can't plant rules that spread across repos. pm doctor shows which scopes are active.
.memini/ that your team reviews like any other change.Local-first by design: no server, no account, no telemetry. Secrets are auto-redacted before storage, file references are contained to the repo, and injected memory text is size-capped and framed as data. See SECURITY.md for the full threat model — including the honest limitations (guardrails intercept edit tools, not arbitrary shell; warn is advisory, block is not).
Early (v0.1). Team sync — shared memory across your whole team, with a review workflow — is on the roadmap. Feedback and issues welcome.
MIT