prism-mem — the portable brain.
The newest PRISM component. prism-mem gives any agent
portable memory: curated project knowledge in signed
AKF bundles — plain Markdown and KDL, no database, no
vendor — injected into every Codex and Claude session at startup, plus
operational Mnemos context for resuming live work.
Your agent's knowledge becomes a file tree you own, not a row in
somebody's cloud.
main on
the forge,
shipping with the next @prism/harness release after
v1.0.0-rc.3. Installing @prism/harness gives you both
CLIs: prism-harness and prism-mem.
Two kinds of memory — don't mix them
Every agent has two memory problems and most tools smash them into one blob. AKF (the Agentic Knowledge Format, standard v2.0.0 2026-09-26) splits them by purpose and authority:
| Operational context — Mnemos | Curated knowledge — AKF | |
|---|---|---|
| Material | Chats, runs, task references, what tools exist right now | Decisions and rationale, procedures, specs, selected evidence |
| Question it answers | What is happening here, and what can this agent do? | What has been established and deliberately preserved? |
| Authority | The source system; Mnemos records observations | ASM — the publication state machine |
| Transfer | Separately authorized checkpoint | The portable bundle — copy it, sign it, move it |
The split is not about age. An old chat log stays operational forever; a brand-new design principle becomes knowledge the moment its publication policy is satisfied. Nothing auto-promotes from one domain to the other.
AKF: knowledge as a plain directory
An AKF bundle is UTF-8 text you can read with less and
diff with git diff. KDL sidecars carry metadata for
humans; JSON owner interfaces carry it for agents:
project-knowledge/
_bundle.kdl ← bundle identity, standard version
CONTEXT-RULE.md _index.md _changelog.md
architecture/
_index.md
memory-boundary.md ← the knowledge itself: Markdown prose
memory-boundary.kdl ← machine-readable sidecar
procedures/
_index.md
recover-workspace.md ← reusable procedures, step by step
evidence/ ← optional: selected supporting evidence
_history/ ← retained prior revisions — nothing is quietly rewritten
_integrity/
manifest.json ← BLAKE3 digest over every page
signatures/ ← detached signatures
- No database required. The complete bundle is intelligible without Mnemos, a model provider, embeddings, or any special mount. Indexes are derived conveniences, never the only copy.
- Revision history is part of the format.
_history/retains prior page revisions; publication preserves them immutably. - Integrity is part of the format. The manifest digest pins every page; detached signatures pin the manifest.
- Disclosure is part of the format. Pages carry a private/team/public audience; a private page is never served to a team or public audience.
ASM: publication is an act of authority
Knowledge in AKF is not "saved" — it is published under the ASM state machine. A proposal produces an exact candidate; approval is for that exact revision; publication is atomic and immutable. Nightly curation may stage proposals, but scheduling grants no authority — only the owner's policy can publish.
And one honest boundary the spec is blunt about: a signature authenticates origin, it does not establish truth. Signed nonsense is still nonsense — provenance and correctness are separate checks, by design.
prism-mem: a strict wire, not a second engine
PRISM adapts harnesses to the two owner interfaces — it does not run
its own memory engine or open the bundle itself. Mnemos (the
reference owner from the JARVIS project) validates bundles,
signatures, policy, trust, transfer, and ASM publication.
prism-mem validates the request and response wire,
then invokes the owner with literal arguments. No shell, no
ambient trust:
$ prism-mem knowledge get --json \
--config /absolute/brains.kdl --owner /absolute/mnemos < request.json
{ "schema_version": 1, "operation": "get", "request_id": "answer-1",
"scope": { "realm_id": "local", "namespace": "project",
"project_id": "demo", "disclosure": "private" },
"input": { "brain": "atlas", "path": "answers/known.md",
"max_bytes": 16384 } }
One JSON request on stdin, one JSON response on stdout. Envelopes
are capped at 1 MiB; read budgets at 64 KiB; the owner
call times out (default 3 s). Successful responses carry the
pinned bundle ID, revision, BLAKE3 manifest digest,
authentication:"verified", and per-page citations
whose digests must agree — or prism-mem rejects them. Owner stderr
is discarded; error detail is normalized so private policy paths
cannot leak. Exit codes are fixed: 0 success,
2 invalid/budget, 3 denied,
4 unavailable.
| Surface | Operations |
|---|---|
prism-mem knowledge — signed AKF |
status, get, search, pack, export, import, propose, publish |
prism-mem context — Mnemos operational |
ingest, get, search, pack, status |
prism-mem startup — session bindings |
install, hook, remove |
Transfer is bundle-level: export writes a signed copy
under the policy-configured root; import creates a
fresh destination that grants no publication or execution rights.
propose yields a candidate receipt — only the owner
can publish it through ASM.
Every session starts with what you know
The payoff. One command binds a project to a signed brain; from
then on, every new Codex or Claude session receives a bounded,
cited knowledge packet through its SessionStart hook:
prism-mem startup install --provider codex \
--project-root /absolute/project \
--config /absolute/brains.kdl --brain handbook \
--realm local --project demo --disclosure private \
--owner /absolute/mnemos --runner /absolute/prism-mem
# removal preserves every hook that isn't ours:
prism-mem startup remove --provider codex --project-root /absolute/project
- Verified on every startup. Mnemos re-checks the signature and enforces KDL policy each session — a tampered bundle or revoked trust yields a visible notice and no packet.
- Bounded and honest. Defaults: 16 KiB packet, 20 pages, 1 s owner timeout. Overflow removes whole pages and says so — nothing is silently truncated or "token-estimated".
- Never hostile. The hook never blocks a session, never captures chats, never requests continuation, and never publishes AKF.
- A polite guest. Installation merges into
.codex/hooks.json/.claude/settings.local.json, preserves unrelated handlers and settings, and is idempotent.
Context memory: resume across providers
The same CLI fronts Mnemos operational context. Codex burned a
plan at 3am and died mid-refactor? SessionStart
requests a project packet that is not filtered to the session that
wrote it — Claude can pick up Codex's cited next step, and vice
versa. The Stop hook captures the final assistant
message as an explicitly partial record; every capture is labeled
untrusted evidence, never live tool authority.
prism-mem vs prism-loop
Both say "memory" and they compose instead of competing.
prism-loop is the self-contained file protocol:
durable .prism/ run boundaries for overnight loops,
no owner process needed. prism-mem is the owner-backed
facade: signed AKF knowledge plus Mnemos context, shared across
agents and machines. Loop remembers this project's runs;
mem carries what you've established — anywhere.
Why this matters
Agent memory today is a lease: your accumulated project knowledge lives in a vendor's cloud, billed monthly, exportable only on their terms, gone when you leave. AKF inverts it. Knowledge is a directory of Markdown you can read, diff, sign, copy, and hand to any agent — Claude today, Codex tomorrow, whatever comes next after that. Provenance travels with the content; authority stays with you.
- Portable — plain files; any reader, any host, any agent.
- Authentic — BLAKE3 manifest, detached signatures, verified at every startup.
- Governed — ASM publication with exact-candidate approval and immutable revisions.
- Bounded — byte budgets and citations on every surface; no unbounded context stuffing.
Honest boundaries
- prism-mem needs a local Mnemos owner binary —
the reference implementation lives in the JARVIS project
(
mnemos akfCLI). Without an owner, knowledge commands reportunavailablerather than pretending. - Startup install is Unix-only in this version; provider trust and hook approval still belong to the provider (Codex requires explicit approval of the exact hook command).
- A signed snapshot is not live state: no process, tool, or capability is inferred from it. AKF procedure text is never an executable grant.
- Unreleased until the next
@prism/harnessversion is cut — today you build frommain.
Install — one line All eight components Source on the forge ↗