fix: harden unified memory boundaries

This commit is contained in:
Affaan Mustafa
2026-07-26 04:35:46 -04:00
parent 60919b9472
commit c64875d9c6
22 changed files with 632 additions and 56 deletions
+16 -5
View File
@@ -54,7 +54,16 @@ Use this as the minimal surface to reproduce the setup without leaking private s
ECC Memory Vault provides one file-first handoff layer instead of a separate
inbox or transcript store for every agent. Initialize it from the repository
that the agents share:
that the agents share. Skill-only, minimal, manual, and Claude plugin installs
do not add the Memory Vault runtime to `PATH`; install it separately first:
```bash
npm install -g ecc-universal
ecc memory --help
command -v ecc-memory-mcp
```
Then initialize the vault:
```bash
ecc memory init --scope project --scope team
@@ -68,10 +77,12 @@ unreviewed context; human acceptance means promoting verified knowledge into
governed project documentation.
Hermes can call the CLI directly or use the opt-in `ecc-memory-mcp` stdio
server. Claude, Codex, Cursor, and OpenCode can connect to the same server or
use the same CLI. Every harness must launch from the same repository working
directory or receive identical `ECC_MEMORY_PROJECT_ROOT` and
`ECC_MEMORY_USER_ROOT` overrides.
server. Harnesses may share the same installed binary and vault storage, but
each harness must launch its own server process with its own distinct lowercase
`ECC_MEMORY_HARNESS` identity; they must not connect to one shared server
process. Every process must launch from the same repository working directory
or receive identical `ECC_MEMORY_PROJECT_ROOT` and `ECC_MEMORY_USER_ROOT`
overrides.
A Hermes-to-Codex handoff can be written without putting the body in the
process list:
+14
View File
@@ -177,6 +177,20 @@ Codex、Hermes 等 harness 之间传递上下文。常规搜索只召回 `projec
`ECC_MEMORY_ALLOW_USER_SCOPE=1` 后,MCP 调用才能显式请求 `user` 范围。
该服务默认不会启用。
仅安装 skill、最小配置、手动复制或 Claude 插件不会把记忆库运行时加入
`PATH`。请先单独安装 ECC npm 运行时:
```bash
npm install -g ecc-universal
ecc memory --help
command -v ecc-memory-mcp
```
如需启用 MCP,请从 `mcp-configs/mcp-servers.json` 复制
`ecc-memory-vault` 配置到对应 harness,并为每个 harness 分别启动一个服务
进程,例如 `ECC_MEMORY_HARNESS=codex ecc-memory-mcp`。不同 harness 可以共享
同一个二进制文件和记忆库目录,但不能共用同一个服务进程。
## 快速开始
在 2 分钟内启动并运行: