📦memory-shield❖ Community
Keeps your agent from rewriting or wiping what it remembers about you: by default the agent may add facts to the owner profile (USER.md) wherever it may write and may correct one only when the owner asks in a direct chat, the CLI or a trusted chat, and nobody may delete one; the agent's notes (MEMORY.md) cannot be deleted; group chats are read-only except for the people and owner-only chats you trust, and once trusted_users is set a direct chat with anyone not listed is read-only too; Hermes' unattended background review may not touch the owner profile. Block, ask through Hermes' approval prompt or just log, and undo edits and deletions from snapshots. Disclosure — no network calls, credentials, shell commands or background processes. One pre_tool_call hook reads the turn's platform, chat type, chat id and name, sender id and name and the cron flag (gateway.session_context) and whether the run is Hermes' unattended review (tools.skill_provenance.is_unattended_review), checks memory tool calls, and checks write_file, patch, terminal and execute_code calls only for a write into, or a removal of, USER.md, MEMORY.md or the memory folder (reading a memory file or copying it elsewhere passes in calls up to 16 KB; a longer call that names them is refused); mode approve asks through Hermes' approval gate in the owner's direct chats and the CLI and blocks in shared chats, cron and direct chats with people not in trusted_users. Writes plugin-data/memory-shield/audit.jsonl (the last 500 refused or flagged writes: time, chat, sender and a 160-character excerpt) and snapshots/ (full copies of USER.md and MEMORY.md taken right before an allowed edit or deletion, 20 per file by default). Reads the memory files and holds the memory store's lock files while it reads or writes them (not on Windows); /memory-shield restore overwrites one memory file. /memory-shield log and restore answer only in direct chats, the CLI and trusted_chats, and once trusted_users is set only the people listed there (a session without a user id, such as the CLI, counts as the owner); /memory-shield, snapshots and whoami answer in any chat with settings, counts, times, sizes and the caller's own id, name and chat key.
General