ReferenceFormats and configConfiguration

Configuration

Everything here belongs to the open runtime, the part that runs on your own machine. Most people never open this page: the file you actually edit is memnox.policies.toml, and it lives in the repository it governs.

Where things live

Everything the runtime writes is under ~/.memnox/ or in the repository you are standing in. Nothing else on the machine is touched, and memnox uninstall takes all of it back out.

Path

memnox.policies.toml

Your rules, in the repository, reviewed in a diff like any other file. This is the one you edit. A memnox.policies.yaml somebody already has is still read, which is the only reason YAML is mentioned at all.

~/.memnox/machine.policies.toml

The rules about this machine rather than a repository: the denies on secret reads setup writes. Registered so every repository loads them, and kept where no checkout can delete or move them.

~/.memnox/config.toml

The seven settings below, mode 0600. Written on first run and never overwritten after that.

~/.memnox/policies.json

Which rule files exist on this machine. Paths only. Rule content never leaves the repository that owns it.

~/.memnox/memnox.db

The ledger, SQLite in WAL mode, append only by database trigger. What why, timeline, trace and collisions read.

~/.memnox/bin/

The PATH interceptors, one small wrapper per binary.

~/.memnox/backup/

A copy of every file the runtime rewrote, taken before it rewrote it. This is what mcp unwrap, protect --revert and uninstall restore from.

~/.memnox/kept.json

What the daemon keeps in place: the agents setup hooked, the ones somebody took the hook out of on purpose, and whether new MCP servers are wrapped. Written by memnox setup, removed by memnox uninstall, and absent on a machine nobody set up, which is why the daemon rewires nothing there. See The daemon keeps the boundary.

~/.memnox/keeper.json

The daemon's own baseline scan, which drift is measured against.

~/.memnox/probation.json

The agents and MCP servers on probation and until when. Unwritable from inside an --untrusted run.

~/.memnox/notice/

What each agent has done before, as digests, and what each session took or was told, so every seam notices the same unusual action.

~/.memnox/checkpoints.json

Which sessions already have a milestone kept, so a hook that owes nothing starts no process.

~/.memnox/daemon.log

What the daemon did, including a line for every agent it hooked, every hook it put back and every MCP server it put through the proxy.

~/.memnox/memnox.sock

The daemon socket, owner only. Absent when no daemon is running, which is a supported state.

~/.memnox/overlays.json

Freezes and other state facts, with their expiry. Lifted ones stay in the file: what was frozen and when is part of the record.

~/.memnox/snapshots/

Saved scans, so memnox scan --since has a baseline. The last thirty.

~/.memnox/guard/

The kernel sandbox profile, when protect --os-guard has written one: a seatbelt profile on macOS, a Landlock ruleset on Linux.

~/.memnox/pending/

Calls held for a person, so a second terminal can release one.

~/.memnox/transcripts/

What an agent printed, only for sessions started with run --transcript. Off by default and bound by the same retention as the ledger.

Milestones for memnox rewind are the exception: they are git objects under refs/memnox/ in the repository itself, because a working tree belongs to its repository and nowhere else. The newest twenty are kept in each repository.

The config file

Seven settings, and memnox config is the way to change them.

bash
memnox config list
memnox config get mode
memnox config set mode enforce

Setting

mode

off · observe · advise · enforce. A first run starts at observe, which records the real verdict and denies nothing, because a runtime that denies on day one gets uninstalled on day one. It stays there until memnox config set mode enforce, or memnox setup --enforce on the way in.

retentionDays

Days of history kept. memnox purge drops anything older. Default 30.

failOpen

Let a call through when the gate cannot answer. Default false: a firewall fails closed.

telemetry

Counts only, never contents, and only if you turn it on. Default false.

approvedAgents

Agents you have decided are allowed here; anything else that acts is reported as unregistered. Empty means nobody has decided, not that everything is approved, because flagging every agent on a machine nobody has configured is noise, and noise is how a real shadow agent gets missed.

noticeUnusual

Ask about an allowed action that this agent has never taken before, that completes a chain from a secret read to an outward send in one session, or that follows an instruction-shaped tool result. Default true. It asks only in enforce; in observe and advise it records what it would have asked. See What changed under you.

noticeWarmupDays

Days after setup when a first action is only recorded, so day one asks nothing. A whole number, zero or more. Default 3.

memnox protect --observe and --enforce are the same setting, reachable from the command that made you think about it.

Environment variables

Variable

MEMNOX_POLICIES

Which rule file to load, ahead of whatever is in the working directory.

MEMNOX_SESSION

The session id an action belongs to. memnox run sets it, which is what makes one piece of work read as one timeline.

MEMNOX_AGENT_NAME

The agent a rule's agents patterns are matched against.

MEMNOX_REAL_SHELL

The shell the governed shell hands a command to. memnox run sets it to the shell it displaced, and the wrapper refuses to resolve it to itself.

MEMNOX_HOME

Where ~/.memnox lives. Useful in a test, rarely otherwise.

Which wins

A rule file named on the command line beats MEMNOX_POLICIES, which beats the file in the working directory. Within the rules themselves the order is precedence, not file order: deny beats ask beats allow, and the most specific rule wins. There is no first match wins, because a rule set whose meaning depends on line order breaks the day somebody sorts it.