Persistent memory, architectural decision enforcement, pre-execution safety hooks, and session handoff for Claude Code. MCP server plugin for AI coding agents.
What's inside
FAQ
axme-code is a Claude Code plugin with hand-picked skills for development work, indexed on Flowy. Install it with the command on its page. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.
Repo: AxmeAI/axme-code
AXME Code is a Claude Code plugin that gives your AI coding agent persistent memory across sessions, pre-execution safety hooks, architectural decision enforcement, and structured session handoff โ via an MCP server, automatically, across every session.
Stop re-explaining your architecture on session 47. Stop losing memory between session handoffs. Stop hoping the agent won't run git push --force to main. AXME Code remembers what happened, enforces your architectural decisions, continues where the last session stopped, and blocks dangerous commands before they execute โ so you can focus on building.
You keep using Claude Code exactly as before. AXME Code works transparently in the background.
โญ Star this repo if it saves you time ยท ๐ Watch releases for new features ยท ๐ฌ Discussions
Quick Start ยท Before & After ยท How It Works ยท Architecture ยท Website

Session 1: "We use FastAPI, not Flask. Deploy only via GitHub Actions. Never push to main directly."
Session 2: "Like I said yesterday, we use FastAPI..."
Session 7: "For the third time this week, we use FastAPI..."
Session 47: gives up, mass-pastes 200 lines into CLAUDE.md
Session 1: Agent learns your stack, saves decisions.
Session 2: Agent calls axme_context โ already knows FastAPI, deploy rules, what happened yesterday.
Session 47: Agent has your full project history: 30 decisions, 15 memories, safety rules, and a handoff from session 46.
Agent runs git push --force to main. Your Friday is ruined.
Hook intercepts the command before execution and blocks it. Not a prompt โ hard enforcement at the harness level.
Agent says "Done!" โ but tests don't pass, half the code is stubbed, and the deploy is broken.
Decisions enforce verification requirements: agent must run tests and show proof before reporting completion.
AXME Code supports three IDE paths today, ranked by lowest install friction:
For Cursor 0.42+ users โ install the AXME Code extension from the Extensions panel (Open VSX). The extension bundles the binary, registers the MCP server programmatically (no manual Enable click), installs user-level safety hooks at ~/.cursor/hooks.json (apply to every project on your machine), and offers a one-click "Run setup" notification the first time you open a project without .axme-code/.
Cursor โ Extensions โ search "AXME Code" โ Install
Or sideload the .vsix attached to the latest release (Extensions โ ... menu โ "Install from VSIX...").
On first activation a modal asks for an LLM credential for the session auditor: paste an Anthropic API key, a Cursor SDK key (cursor.com โ Integrations), or skip the auditor. If claude CLI is logged in (claude login), the extension auto-uses your Claude subscription โ no paste needed.
In Claude Code, run:
/plugin marketplace add anthropics/claude-plugins-community
/plugin install axme-code@claude-community
Or from the terminal:
claude plugin marketplace add anthropics/claude-plugins-community
claude plugin install axme-code@claude-community
The plugin ships with the MCP server, safety hooks, and CLI bundled together; no separate binary to install. On first use in a project, just ask the agent to call axme_context โ the plugin auto-initializes the knowledge base on that session.
Install the CLI system-wide (useful if you want to run axme-code outside Claude Code, e.g. for scripting).
Linux / macOS:
curl -fsSL https://raw.githubusercontent.com/AxmeAI/axme-code/main/install.sh | bash
Installs to ~/.local/bin/axme-code. Requires Node.js 20+ on PATH (the binary is a single-file Node bundle; the installer checks for it). Supports x64 and ARM64.
Windows (native):
irm https://raw.githubusercontent.com/AxmeAI/axme-code/main/install.ps1 | iex
Installs to %LOCALAPPDATA%\Programs\axme-code and adds it to your User PATH. Requires Node.js 20+ on PATH. Supports x64 and ARM64.
Windows via WSL2: if you already live in WSL2, use the Linux install one-liner inside your distro. Install Claude Code and axme-code inside the WSL distro, not on the Windows host.
Then in each project:
cd your-project # or workspace root for multi-repo
axme-code setup
claude # that's it โ use Claude Code as usual
axme-code setup does three things:
.mcp.json)After setup, every Claude Code session automatically loads the full knowledge base. No config, no manual steps.
Your agent starts every session with full context: stack, decisions, patterns, glossary, and a handoff from the previous session. No more re-explaining your architecture on session 47.
| Category | What it stores | Example |
|---|---|---|
| Oracle | Project structure, tech stack, coding patterns, glossary | "TypeScript 5.9, Node 20, ESM, esbuild" |
| Decisions | Architectural decisions with enforcement levels | "All deploys via CI/CD only" [required] |
| Memory | Feedback from mistakes, validated patterns | "Never use sync HTTP in async handlers" |
| Safety | Protected branches, denied commands, filesystem restrictions | git push --force โ BLOCKED |
| Backlog | Persistent cross-session task tracking | "B-003: migrate auth to OAuth2 [in-progress]" |
| Handoff | Where work stopped, blockers, next steps | "PR #17 open, waiting on review. Next: fix flaky test." |
| Worklog | Session history and events | Timeline of all sessions and what was done |
Hooks intercept tool calls before execution โ not prompts. Even if the agent hallucinates a reason to run rm -rf /, the hook blocks it. This is hard enforcement at the Claude Code harness level, not a suggestion in a system prompt.
Blocked by default:
git push --force, git reset --hard, direct push to main/masterrm -rf /, chmod 777, curl | shnpm publish, git tag, gh release create.env, .pem, .key filesYou can add your own custom rules via axme_update_safety or by editing .axme-code/safety/rules.yaml directly.
The agent saves discoveries during work via MCP tools. At session close, a structured checklist ensures nothing is missed. If you just close the window โ a background auditor extracts memories, decisions, and safety rules from the full session transcript.
Each repo gets its own knowledge base (.axme-code/). Workspace-level rules apply to all repos. Repo-specific rules stay scoped. The agent sees merged context โ workspace safety floor + repo-specific decisions.
Supports 14 workspace formats: VS Code multi-root, pnpm/npm/yarn workspaces, Nx, Gradle, Maven, Rush, git submodules, and more.
CLAUDE.md is great for simple projects with a few rules. But it doesn't scale:
| CLAUDE.md | AXME Code | |
|---|---|---|
| Memory | Static, manual | Automatic, accumulates across sessions |
| Decisions | Flat text, no enforcement | Structured, required/advisory levels |
| Safety | Prompt-based (~80% compliance) | Hook-based (100% enforcement) |
| Session continuity | None | Handoff + background auditor |
| Scales to | ~50 lines | Hundreds of decisions, memories, rules |
AXME Code complements CLAUDE.md โ it reads your existing CLAUDE.md during setup and extracts decisions and rules from it.
AXME Code is a stdio MCP server โ every MCP-compatible AI coding assistant gets the full set of axme_* tools (knowledge base read/write, safety queries, status, worklog).
| Client | MCP Tools | Safety Hooks | Auto Auditor |
|---|---|---|---|
| Claude Code (CLI / VS Code) | โ Full | โ Full | โ Yes |
| Cursor | โ Full | โ | โ |
| Windsurf | โ Full | โ | โ |
| Cline (VS Code) | โ Full | โ | โ |
| Claude Desktop | โ Full | โ | โ |
| Any other MCP client | โ Full | โ | โ |
The MCP server entry is identical in every client:
{
"mcpServers": {
"axme": {
"command": "axme-code",
"args": ["serve"]
}
}
}
Just place it in your client's MCP config file:
~/.cursor/mcp.json or .cursor/mcp.json (per-project)~/.codeium/windsurf/mcp_config.jsoncline_mcp_settings.json~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or equivalentPre-execution safety hooks, the post-tool-use file tracker, and the background session auditor are Claude Code-specific (they require Claude Code's hook system). In other clients, the agent must call AXME tools explicitly โ same knowledge base, same .axme-code/ storage, just no automatic enforcement layer.
See docs/MULTI_CLIENT.md for full per-client setup, hook workarounds, and concurrent-client semantics.
| AXME Code | MemPalace | Mastra | Zep | Mem0 | Supermemory | |
|---|---|---|---|---|---|---|
| Capabilities | ||||||
| Structured decisions w/ enforce levels | โ | โ | โ | โ | โ | โ |
| Pre-execution safety hooks | โ | โ | โ ๏ธ | โ | โ | โ |
| Structured session handoff | โ | โ | โ | โ | โ ๏ธ | โ |
| Automatic knowledge extraction | โ | โ | โ | โ | โ | โ |
| Project oracle (codebase map) | โ | โ | โ | โ | โ | โ |
| Multi-repo workspace | โ | โ | โ | โ | โ | โ |
| Local-only storage | โ | โ | โ | โ | โ | โ |
| Semantic memory search | โ | โ | โ | โ | โ | โ |
| Multi-client support | โ | โ | โ | โ | โ | โ |
| Capabilities total | 9/9 | 3/9 | 4/9 | 3/9 | 3/9 | 3/9 |
| Benchmarks | ||||||
| ToolEmu safety (accuracy) | 100.00% | โ | โ | โ | โ | โ |
| ToolEmu safety (FPR) | 0.00% | โ | โ | โ | โ | โ |
| LongMemEval E2E | 89.20% | โ | 84.23% / 94.87% | 71.20% | 49.00% | 85.40% |
| LongMemEval R@5 | 97.80% |
AXME uses ~10ร fewer tokens per correct answer than Mastra at competitive accuracy. The memory system runs only 2 LLM calls per question (reader + judge) โ competitors run dozens (Observer per turn, Reflector periodically, graph construction, fact extraction).
See benchmarks/README.md for full methodology, per-category breakdowns, footnotes, and reproduction instructions.

axme_context, loads full knowledge baseaxme_save_memory, axme_save_decision. Hooks enforce safety on every tool call.axme_begin_close, gets a checklist. Reviews the session for missed memories, decisions, safety rules. Calls axme_finalize_close โ MCP writes handoff, worklog, and extractions atomically.axme_context returns everything accumulated. Handoff says exactly where to continue.Tip: You can save at any time โ just tell the agent "remember this" or "save this as a decision". You don't have to wait for session close.
All data lives in .axme-code/ in your project root (gitignored automatically):
.axme-code/
oracle/ # stack.md, structure.md, patterns.md, glossary.md
decisions/ # D-001-slug.md ... D-NNN-slug.md (with enforce levels)
memory/
feedback/ # Learned mistakes and corrections
patterns/ # Validated successful approaches
safety/
rules.yaml # git + bash + filesystem guardrails
backlog/ # B-001-slug.md ... persistent cross-session tasks
sessions/ # Per-session meta.json (tracking, agentClosed flag)
plans/
handoff-<id>.md # Per-session handoff (last 5 kept)
worklog.jsonl # Structured event log
worklog.md # Narrative session summaries
config.yaml # Model settings, presets
Human-readable markdown and YAML. No database, no external dependencies.
AXME Code is the developer tools layer of the AXME platform โ durable execution infrastructure for AI agents.
AXME Code has three components:
Provides tools for the agent to read and write the knowledge base. All writes go through MCP server code (atomicWrite, correct append) โ the agent never writes storage files directly.
pre-tool-use: Checks every Bash command, git operation, and file access against safety rules. Blocks violations before execution. Also creates/recovers session tracking.
post-tool-use: Records which files the agent changed (for audit trail).
A detached process that reads the session transcript and catches anything the agent forgot to save. Two modes:
| Tool | Description |
|---|---|
axme_context | Load full knowledge base (oracle + decisions + safety + memory + handoff) |
axme_oracle | Show oracle data (stack, structure, patterns, glossary) |
axme_decisions | List active decisions with enforce levels |
axme_memories | Show all memories (feedback + patterns) |
axme_save_decision | Save a new architectural decision |
axme_save_memory | Save feedback or pattern memory |
axme_safety | Show current safety rules |
axme_update_safety | Add a new safety rule |
axme_backlog | List or read backlog items |
axme_backlog_add | Add a new backlog item |
axme_backlog_update | Update backlog item status, priority, or notes |
axme_status | Project status (sessions, decisions count, last activity) |
axme_worklog | Recent worklog events |
axme_workspace | List all repos in workspace |
axme_begin_close | Start session close โ returns extraction checklist |
axme_finalize_close | Finalize close โ writes handoff, worklog, extractions atomically |
axme_ask_question | Record a question for the user |
axme_list_open_questions | List open questions from previous sessions |
axme_answer_question | Record the user's answer |
axme-code setup [path] # Initialize project/workspace with LLM scan
axme-code serve # Start MCP server (called by Claude Code automatically)
axme-code status [path] # Show project status
axme-code stats [path] # Worklog statistics (sessions, costs, safety blocks)
axme-code audit-kb [path] # KB audit: dedup, conflicts, compaction
axme-code hook pre-tool-use # PreToolUse hook handler (called by Claude Code)
axme-code hook post-tool-use # PostToolUse hook handler
axme-code hook session-end # SessionEnd hook handler
axme-code audit-session # Run LLM audit on a session transcript
During axme-code setup, preset bundles provide curated best-practice rules:
| Preset | What it adds |
|---|---|
| essential-safety | Protected branches, no secrets in git, no force push, fail loudly |
| ai-agent-guardrails | Verification requirements, no autonomous deploys, proof before done |
Additional presets available: production-ready, team-collaboration.
axme-code sends anonymous usage telemetry to help us improve the product. We collect:
What we never send:
Each install gets a random 64-character machine ID stored in ~/.local/share/axme-code/machine-id. The ID is not derived from hardware and cannot be linked back to you.
To disable telemetry, set either of these environment variables:
export AXME_TELEMETRY_DISABLED=1
# or the industry-standard:
export DO_NOT_TRACK=1
When disabled, no network requests are made and no machine ID is generated.
See CONTRIBUTING.md for guidelines.
Website ยท Issues ยท Architecture ยท contact@axme.ai
.claude-plugin/
plugin.json
.github/
workflows/
channel-health.yml
ci.yml
publish-extension.yml
release-binary.yml
.gitignore
.mcp.json
benchmarks/
lib/
search.test.ts
search.ts
longmemeval/
adapter.ts
data/
.gitignore
run.ts
package-lock.json
package.json
README.md
results/
.gitignore
token-performance.png
token-performance.py
token-performance.svg
toolemu/
run.ts
scenarios.ts
tsconfig.json
build.mjs
CHANGELOG.md
CONTRIBUTING.md
Dockerfile
docs/
ARCHITECTURE.md
blog/
01-claude-code-amnesia.md
demo/
demo-video/
.gitignore
fetch-fonts.sh
fonts/
Inter-Bold.ttf
Inter-LICENSE.txt
Inter-Medium.ttf
Inter-Regular.ttf
JetBrainsMono-OFL.txt
JetBrainsMono-Regular.ttf
NARRATION.md
render.py
demo.gif
demo.mp4
_demo_inner.sh
demo.cast
record-demo.sh
devto-draft-session-handoff.md
diagrams/
axme-code-architecture.dot
axme-code-architecture.mmd
axme-code-architecture.png
axme-code-architecture.svg
axme-code-overview.mmd
axme-code-overview.png
axme-code-overview.svg
MULTI_CLIENT.md
RELEASE_CHECKLIST.md
TELEMETRY_TZ.md
extension/
.gitignore
.vscodeignore
build.mjs
LICENSE
media/
axme.svg
icon.png
package.json
README.md
src/
activation-report.ts
auditor-auth.ts
auditor-mode-mirror.ts
backlog-reader.ts
binary-detect.ts
bundled-runtime.ts
chat-prompt.ts
commands.ts
extension.ts
health-reader.ts
hooks-install.ts
hooks-state.ts
ide-detect.ts
kb-watcher.ts
log.ts
mcp-register.ts
reset.ts
search-mode.ts
session-tracker.ts
setup-controller.ts
sidebar-webview.ts
spawn-binary.ts
status-bar.ts
status-webview.ts
test/
runTest.ts
suite/
activation.test.ts
index.ts
tsconfig.json
tsconfig.json
walkthroughs/
auditor.md
firstChat.md
semanticSearch.md
setup.md
glama.json
install.ps1
install.sh
LICENSE
package-lock.json
package.json
README.md
scope-dryrun.mts
scripts/
release.sh
run-tests.mjs
src/
agents/
kb-auditor.ts
memory-extractor.ts
scanners/
_scope.ts
decision.ts
deploy.ts
oracle.ts
safety.ts
session-auditor.ts
audit-spawner.ts
auto-update.ts
cli.ts
hooks/
adapters/
claude-code.ts
cursor.ts
types.ts
post-tool-use.ts
pre-tool-use.ts
session-end.ts
presets.ts
self-test.ts
server.ts
session-cleanup.ts
setup/
cursor-writers.ts
storage/
backlog.ts
config.ts
decisions.ts
deploy.ts
embeddings.ts
engine.ts
kb-audit.ts
memory.ts
oracle.ts
plans.ts
questions.ts
safety.ts
sessions.ts
test-plan.ts
worklog.ts
workspace-merge.ts
telemetry.ts
tools/
cleanup.ts
context.ts
decision-tools.ts
init.ts
kb-search.ts
memory-tools.ts
safety-tools.ts
search-install.ts
status.ts
transcript-parser.ts
types.ts
utils/
agent-options.ts
agent-sdk-claude.ts
agent-sdk-cursor.ts
agent-sdk.ts
auditor-mode.ts
auth-config.ts
auth-detect.ts
auth-prompt.ts
bash-file-extract.ts
cost-extractor.ts
ide-detect.ts
pagination.ts
work-context.ts
workspace-detector.ts
templates/
mcp.json
plugin-README.md
test/
agent-sdk-factory.test.ts
agent-sdk-paths.test.ts
audit-dedup.test.ts
auditor-mode.test.ts
auth-config.test.ts
auth-detect.test.ts
auto-update.test.ts
axme-gate.test.ts
backlog.test.ts
claude-code-hook-adapter.test.ts
context.test.ts
cursor-auth-config.test.ts
cursor-hook-adapter.test.ts
cursor-setup-writers.test.ts
decisions.test.ts
embeddings.test.ts
engine.test.ts
find-claude-path.test.ts
hooks-workspace-fallback.test.ts
ide-detect.test.ts
kb-search.test.ts
memory.test.ts
oracle.test.ts
pagination-integration.test.ts
pagination.test.ts
parse-audit-json.test.ts
plans.test.ts
safety-bash.test.ts
safety-internals.test.ts
session-ownership.test.ts
telemetry.test.ts
transcript-parser.test.ts
worklog.test.ts
workspace-merge.test.ts
tsconfig.jsonยฉ 2026 Flowy ยท Free and open source
Built for Claude Code ยท Not affiliated with Anthropic
| 96.60% |
| โ |
| โ |
| โ |
| โ |
| LongMemEval tokens/correct | ~10K โ | โ | ~105Kโ119K | ~70K | ~31K | ~29K |