Exhibit A: continuity.
Persistent memory & continuity engine for AI agents.
Memory that shows up before your coding agent makes the same mistake twice.
A local-first MCP server that gives Claude and other AI agents durable memory across sessions. It runs on SQLite with vector search for semantic recall, plus consolidation, decay, and reflection. Published on npm, PyPI, and the official MCP Registry.

01 · The gap it closes
Your agent should remember the work, not just the chat.
02 · Autopilot loop
What runs, and when.

Session starts
Injects a compact, agent-scoped memory briefing
You send a prompt
Recalls relevant evidence; explicitly durable phrases such as “remember that…” or “I prefer…” can become memories
Bash/edit/write is proposed
Checks exact prior failures, trusted rules, procedures, contradictions, and memory health
The tool finishes
Correlates tool_use_id to the Guard receipt and records the redacted outcome
A tool failure is reported
Forms a durable, sanitized failure memory for the next attempt
The turn stops or context compacts
Runs lightweight, due-only consolidation without holding the conversation open
03 · Guard, live
A failed deploy, and the retry Guard catches.
$ npm run deploy
Error: deployment target is missing
$ npm run deploy
Audrey Guard: BLOCKED
- recent_failure (high): This exact Bash action failed before: Prisma client was not generated. Run npm run db:generate before deploy.
- must_follow (high): Before running npm run deploy, run npm run db:generate because Prisma client must be generated first.
audrey demo --scenario repeated-failure. No API key or network call required.Pick a command
$ grep -rn "prisma" src/
Guard: silent
Outputs are the README's own documented examples, not a live classifier.
04 · Looking is not doing
The same line I have to draw in a state security audit.
Finding
A command whose every part is positively recognised as read-only (grep, git log, npm view, docker ps, sed -n '1,40p', and their kind, with no command substitution, no redirect except to /dev/null, no sudo or xargs, no environment assignment that could change what the verb resolves to) never reaches the Guard at all.
Remediation
The line between looking and doing is drawn fail-closed. Each way found to hide a write inside a harmless-looking command is closed and kept as a test case: a verb given by path, history -w, jobs -x, glued short options, and more. The fixes are in the public commit history.
Two limits remain by design: a git configuration that already names an external program runs on any read, and a file whose name is a flag can change what a pure reader does with a glob. Both require a prior write that Guard did see.
Status: closed
05 · What it remembers
Four kinds of memory, not one pile of text.
Episodic
Things that happened: a user decision, a tool result, a project fact, a preference.
Semantic
Principles supported by accumulated evidence.
Procedural
Ways of acting: how to retry, verify, avoid, or recover.
Contradictions
Stay visible instead of being silently overwritten.
06 · The numbers
Every figure, paired with its methodology.
From GuardBench, the project's local benchmark (npm run bench:guard), under the mock-provider methodology. See the repo for the full method.
Install Audrey.
Restart the host after installation.
npm install -g audrey
audrey install --host auto