ReferenceReferenceCLI

CLI

bash
npx memnox setup              # no install: the first run, with no account
npm install -g memnox         # or install it
memnox --help                 # the commands typed at a terminal
memnox help --all             # every command
memnox help <command>         # one command and its flags

Everything here runs on your machine. There is no account, no key and no network call anywhere in this page. What the runtime writes, it writes under ~/.memnox/ or into the repository you are standing in, and memnox uninstall takes all of it back out.

After memnox setup, Memnox lives in your agent session: the agent is told the boundary, reminded of decisions already taken, and can ask Memnox why something was stopped, what the session did, or to rewind. See Memnox in your session. So memnox --help lists only the eight commands a person types at a terminal, and says that everything else happens in the session. memnox help --all lists every command, all of them still wired and supported.

This page starts with those eight, then the rest in the order somebody meets them: see the machine, put the agents under it, write the rules, run one, read what happened. The ones used least are named at the end.

At the terminal

These are what memnox --help shows. setup, status, doctor and login are described in full in their sections below.

$memnox setup

Put this machine under Memnox, once, with no account. Described in full under The agents on this machine.

$memnox status

Where this machine stands: what is held, and what happened today. Bare memnox shows the same once setup has run.

$memnox rewind

Put the working tree back to before an agent touched it: files and nothing else, no commit, no branch, no stash. --list for the milestones with the agent, session and reason of each, --to <id> for one of them, --session <id> for before that session first changed anything, --last for the most recent session. It takes its own milestone first, so a rewind is undoable. The agent can ask for the same thing from the session, with its person's approval. The Recover and decide ahead page has the rest.

$memnox doctor

What on this machine is risky, why, and the one change that closes each. --wiring says whether each seam is in the path, and --prove attempts a refusal at every seam. Described in full under What can act here.

$memnox stop

Turn protection off on this machine, on purpose and on the record. Every seam and hook lets everything through without ruling, and the daemon puts nothing back while the stop holds. --for <duration> brings it back on by itself, such as --for 30m or --for 2h, and --reason <text> says why, in the words your team will read. The mode is left as it was, the stop and who made it are written to the record, memnox status shows it first, and a session that starts while it holds is told protection is stopped. On a connected machine the team sees the stop on the next sync.

$memnox start

Turn protection back on, in exactly the mode it was stopped in. Where a timed stop already ran out, it says so rather than recording a start of its own.

$memnox update

Print the installed version and the latest published one, and upgrade only after you say yes, with the command for how this copy was installed, npm or pnpm. From the npx cache, or anywhere the path does not say, it prints the command instead of guessing. After the upgrade the new copy runs the same wiring setup draws, so the hooks and the daemon point at it, and the rules are left alone. Offline, it says so and changes nothing.

$memnox login

Connect this machine to a workspace, so it gets your rules. Described in full under Connecting to a workspace.

Options several commands accept

Option

--json

The structured form instead of the human one. The human wording may change; the JSON is the contract. Accepted by scan, agents, explain, doctor, why, timeline, watch, approvals, collisions and trace.

-f, --file <path>

Which policy file to read. Defaults to whichever of memnox.policies.toml or memnox.policies.yaml exists here.

--no-probe

Do not start MCP servers to ask what they hold. Starting somebody else's server is the one thing a scan does that runs code, so this turns it off and tools come from the cache instead.

What can act here

$memnox

What can act on this machine and what it can reach, read off your own disk. The default command on a machine nobody has set up; once memnox setup has run, bare memnox shows memnox status instead and memnox scan is the scan. Credentials lead, and the last two lines are the gap: how much can change something outside this laptop, and how much of that any rule covers.

$memnox scan --mcp <server>

One MCP server before you trust it: its tools split by what they do, what it can reach, and the risk band with the rules that fired.

$memnox scan --usage 7d

Granted against used. Tools that can change external state and never have are the list protect --from-usage drafts from.

$memnox scan --share

A card of counts only, safe to paste anywhere. No paths, no names, no values.

$memnox explain <subject>

Where one capability came from: a tool, a path, a server, an agent or an authenticated CLI. For a CLI it prints the credential, the projects it is linked to, the verb table and the rule that governs it, and that verb table is the one enforcement reads.

$memnox doctor

What is risky, why, and the one change that closes each. --wiring answers a different question: whether Memnox is gating anything at all right now, and it names the rule set in force by content hash. --prove goes further and attempts a refusal at every seam.

$memnox scan --since <when>

What changed since the last saved scan, which is the same scan compared against the one already kept. --fail-on write-capable exits non-zero in CI when something widened, and --from/--to compares two saved scans.

The agents on this machine

Finding them and putting them under Memnox on this machine needs no account. Enrolling one into a workspace needs one, because that enrolment is approved by a person: run memnox login, then memnox setup again. See Enrolling an agent.

$memnox setup

The whole first run in one command, with no account and no network call. It finds the agents, MCP servers, CLIs and credentials here, prints what each agent can already reach, and asks once whether to put them under Memnox, because whether to govern something that can read ~/.aws/credentials is a different decision from something that can only read this checkout. It then wires the machine: the interceptors, a hook before every tool call in Claude Code, Codex, Cursor, Gemini CLI and Windsurf where installed, the MCP servers through the proxy, the memnox-session server in each installed agent so it can ask Memnox from inside a session, a baseline rule set, with the secret denies in ~/.memnox/machine.policies.toml so they apply in every repository, and a daemon the operating system keeps running. It stays in observe and ends by saying nothing left the machine. --yes wires without the question, for a terminal nobody is at; without it and without a terminal, nothing is wired. --enforce starts in enforce, --no-probe starts no MCP server, and --url <base> connects to that control plane too, as memnox login does. After memnox login, running it again names each agent in the workspace and puts it there.

$memnox status

Where this machine stands: protected or not, the mode, the agents, the MCP servers, the rules in force, today's actions, asks and denials, the approvals waiting, what is still on probation and until when, agents dormant for thirty days that still hold reach, and whether a workspace is connected. --json for a script. Bare memnox shows the same once setup has run. The daemon keeps the boundary in between: an agent or MCP server installed later is wired automatically, a removed Memnox hook is put back, and each raises a desktop notice.

$memnox agents discover

Scan this machine for agents and report what was found: each one by the name you gave it, the product it is, and what it can reach. The default subcommand. It asks what to call each one, and Enter keeps the detected name. Where this machine is connected, the scan goes up on the same pass a sync uses.

$memnox agents list

What this machine hosts, from the scan already taken rather than a fresh one, and whether each is onboarded. A discovery starts every MCP server it finds and takes seconds; listing is the thing somebody runs twice in a row.

$memnox agents name <agent> [name]

Call an agent whatever you call it. The id stays the identity every ledger row is keyed on; the name is what every screen prints, and every command answers to either one. --clear puts the detected name back.

$memnox agents status <agent>

One agent, and the file that proved each surface it has. The path says who granted the reach, which is the half somebody can act on.

$memnox agents onboard [agent]

Enrol one agent, back its configuration up first, and add a single MCP entry named memnox to it. A person approves the enrolment with a device code. --name says what the workspace should call it rather than being asked. With no agent named, it lists what could be onboarded. Authority is unchanged: what the agent may do is still decided on this machine.

$memnox agents offboard <agent>

Put that configuration back from the backup and revoke the credential. Both halves are reported as what happened rather than as what was attempted, because restoring the file and leaving live reach is the wrong half.

$memnox agents trust <agent>

End an agent's probation now, on the record, so only your rules decide what it does. An agent the daemon adopted asks before its writes, outward and destructive actions for seven days otherwise. See [Untrusted repositories and new agents](/govern/untrusted).

$memnox agents control [agent]

Collect what an operator has said to the agents here, one agent or all of them. Printed before it is acknowledged, and a turn is handed over once. A message is not permission.

Writing rules

$memnox protect

Proposes reversible steps and prints the undo before it runs anything. --apply writes them, --revert puts the machine back.

$memnox protect --yes

Take the recommended answer for every domain and write a baseline. --interactive walks them instead.

$memnox protect --for <cli or server>

Rules for one thing only. For an authenticated CLI this denies the credential file and leaves the CLI working, which is the distinction that makes any of this adoptable.

$memnox protect --interceptors

Install the PATH wrappers, so shell and CLI commands meet the rules too. Only binaries this machine actually has are wrapped, and the ones it does not have are named.

$memnox protect --hooks

Install git pre-push and pre-commit hooks in this repository, so a denied push stops even when the wrappers are not on PATH.

$memnox protect --os-guard

Write a kernel sandbox profile from your filesystem rules. A denied path then stays unreadable even to a binary that never saw a wrapper. Any pattern the kernel cannot express as a literal path is printed rather than dropped.

$memnox protect --from-usage 30d

Draft ask rules for what was granted and never used. It drafts ask and never deny: unused for thirty days is not the same as never needed.

$memnox protect --observe / --enforce

Record verdicts and deny nothing, or apply them. Observe is where a first run starts.

$memnox protect --ask <action...>

Always ask a person before these. --deny <action...> never runs them, and --allow <action...> stops asking about something already approved enough times. Written at once, and on an enrolled machine offered to the team on the next sync as a proposal a second admin decides.

$memnox protect --revert-claude-hook

Take the edit hook out of Claude Code, and keep it out: the daemon records the decision and does not put it back. --claude-hook puts it back in.

$memnox protect --apply-native

Also write these rules into Claude Code's own permissions, with a backup. --revert-native restores the file byte for byte.

$memnox config list

Every setting and its value. config get <key> and config set <key> <value> for one.

Running an agent under it

$memnox run -- <agent command>

Start an agent with the interceptor directory first on PATH, the governed shell as SHELL, the egress proxy in its proxy variables, a session id, a working-tree milestone, and the kernel sandbox when a profile exists. Writes outside the repository ask in enforce. Hands back the agent's own exit code. --no-milestone skips the milestone, --no-guard the sandbox, --transcript keeps what it printed, and --task, --paths, --repos, --services, --envs, --expect and --role declare what it was asked to do.

$memnox run --untrusted -- <agent command>

For a repository nobody here vouched for: writes stay in it, credentials and home dotfiles are unreadable, the network reaches only this session's proxy and asks for anything but package registries and the model provider, and every outward or destructive action asks. Held by seatbelt on macOS and by Landlock on Linux, which is new; where no kernel can hold it the run refuses to start. See [Untrusted repositories and new agents](/govern/untrusted).

$memnox watch

Report what arrives: new servers, new write tools, credentials that became reachable, agents that updated themselves.

$memnox uninstall

Remove the interceptors, the hooks and the wrapping, and put every backup back. --purge also deletes ~/.memnox, including the history and your rules.

Calls waiting for a person

$memnox approvals

Calls held for somebody to answer. A hold written to disk is what lets a second terminal release something the first is still waiting on.

$memnox approve <id>

Release one. First answer wins; a second is told what already happened rather than shown a failure.

$memnox deny <id>

Refuse one.

Connecting to a workspace

Optional, and off until you run it. Everything above works with no account and no network; this is the only part of the runtime that talks to anything, and with no account file it makes no call at all. See Connecting to a workspace for exactly what crosses the wire.

$memnox login

Connect this machine to a workspace, so it gets the rules that workspace publishes. The one deliberate step towards the cloud, approved in a browser; run memnox setup afterwards to put each agent in the workspace. --url for a different control plane, --enforce to start enforcing, --no-open to print the URL rather than open a browser.

$memnox logout

Forget the credential. Rules already pulled stay in force, because a machine that silently stopped being governed would be the worse failure.

$memnox whoami

Which workspace this machine is enrolled in, if any. The answer to whether this one is connected at all, which every other question here depends on.

$memnox sync now

Pull the rules and send what happened, immediately rather than on the daemon's next heartbeat.

What you could let it do next

The ledger read backwards. Not what an agent did, but what a person has already approved often enough that being asked again is the tool wasting their attention. No model reads any of this: the counts are the argument, and a single refusal disqualifies rather than averages away.

$memnox next

What you could safely stop being asked about, from what you have already approved. --since 30d for the window.

$memnox next --agent <name>

What that agent would do on its own and what would still be asked, rendered by asking the engine action by action rather than by summarising the rules. Under next because it answers the same decision from the other side: bare next reads the ledger backwards, this reads the rules forwards. --role <name> for the boundary of a job rather than of a product, --roles for every job the rules name.

What happened

$memnox timeline

What the agents on this machine actually did, in order, grouped by session. --since, --agent, --only allow|ask|deny|blocked, and --export jsonl|json|bundle.

$memnox why [id]

Why the last thing that did not simply proceed was decided that way: the rule, the reason, the alternative and the evidence. Read back from the row, never re-evaluated against today's rules.

$memnox timeline --export bundle --out audit.json

A signed bundle of a period, stating the range it covers and what was excluded.

$memnox replay [session]

One session step by step: every action with its verdict, exit codes, breaker trips and who resumed them, holds still waiting and the milestones kept for it, with the five actions before a failure marked. No session, or --last, means the most recent; --json for a script. See [Recover and decide ahead](/govern/recover#replay).

$memnox doctor --prove

Ask every seam to refuse something and report what came back. A different question from --wiring, which reads the configuration: this one attempts the action, and the gap between the two is where this fails worst. A seam that is absent has declined the test rather than failed it, and never fails the command.

Everything else

These are in memnox help --all, run exactly the same way and are supported exactly the same; they are here rather than up there because a first page of every command is one nobody finishes. memnox help <command> prints the flags for any of them.

Command

memnox policy check [file]

Read every rule file this machine would load and say what is in force, what moved and what will not parse. Exits non-zero on a broken file, so CI can run it. policy use <file> registers one, policy test '<action>' evaluates a single action and changes nothing.

memnox check '<intent>'

Decide before the loop starts rather than being interrupted half an hour in. The same engine and rules, run against the actions an intent resolves to, with nothing executed. Exits non-zero when something would stop.

memnox freeze <subject> --for 2h

Stop external-state actions for a while. Every freeze carries an expiry, and --lift ends one early.

memnox budget list

What is set and how much is left. budget set <name> adds one with --actions, --limit, --window and --unit; budget suggest writes a starting set; budget remove <name> drops one. Counted from the ledger, so it survives a restart.

memnox paused

Sessions Memnox is holding, and why. memnox resume <session> --by <who> lets one carry on, and also lifts the wariness a session is put under after an instruction-shaped tool result. Who lifted it stays in the record.

memnox lock <path>

Hold a path while you work on it, so a second agent waits rather than writing over you. --for 30m, --list, --release <id>, --forget.

memnox collisions

Two agents in one file, and two agents building one thing. --days <n> for the window.

memnox trace <id>

One action end to end: the command, the rule that governed it, the exit code, the duration and the argument digest. When the session kept a transcript, the tail of what it printed. An id prefix is enough.

memnox report

What your agents did in a window, and what of it was redone. --since 1d.

memnox claims [session]

What an agent said it did, against what the record says it did. Reported and never refereed: contradicted is the one that matters.

memnox skills

What your agents run on beyond their config: skills they taught themselves and personas somebody installed. --accept [name] marks them reviewed.

memnox mcp wrap

Repoint every MCP server at the proxy, keeping a backup. mcp unwrap puts them back byte for byte, and on a machine setup reached it also stops the daemon wrapping new ones until mcp wrap is run again. mcp trust <server> ends a newly wrapped server's seven days of probation.

memnox mcp session on|off

Put the memnox-session server into every installed agent, or take it out of all of them. It is what lets an agent ask Memnox why, status, replay and decisions, and ask for a rewind its person approves; no tool on it can approve, trust, lift, change the mode or edit a rule. Off is recorded, so the daemon leaves it out; after on, restart the agent. See Memnox in your session.

memnox env

The environment an agent needs when something else starts it. --format sh|systemd|docker, because a unit file and an image read no shell profile. It prints; it edits nobody's unit file.

memnox daemon

Hold the rules in one process, and pull what the workspace publishes. --install hands it to the machine so it starts at login, --status says whether anything does, --uninstall stops it. On a machine setup reached it also keeps the boundary: it hooks an agent installed later, puts back a hook something removed and puts a new MCP server through the proxy, each with a desktop notice, and never puts back what a person took out on purpose. It also notices drift on its own, records every config change in the ledger, flags dormant agents, and runs the egress proxy on 127.0.0.1:8888. Optional for a verdict: an interceptor that cannot reach it evaluates in process on the same rules. Not optional for a workspace, because nothing else pulls a rule set or carries a held call back to a machine nobody is sitting at.

memnox purge

Drop history past the configured retention. --dry-run says what would go.