Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add terrizoaguimor/celiums-memorynpx agentmods add plugins/terrizoaguimor/celiums-memory/plugin-claude-codegit clone --depth 1 https://github.com/terrizoaguimor/celiums-memoryGrade A, and why
celiums scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "celiums",
"version": "0.6.1",
"description": "Persistent memory for Claude Code through the authenticated native Rust server. 5 hooks + 6 MCP tools + 9 cognitive reflex skills.",
"author": {
"name": "Celiums Solutions LLC",
"email": "[email protected]",
"url": "https://celiums.ai"
},
"homepage": "https://celiums.ai",
"license": "Apache-2.0",
"mcpServers": {
"celiums-memory": {
"command": "node",
"args": ["${CLAUDE_PLUGIN_ROOT}/src/bridge.mjs"],
"env": {
"CELIUMS_MEMORY_URL": "${memory_url}",
"CELIUMS_TENANT_ID": "${tenant_id}",
"CELIUMS_MEMORY_USER_ID": "${user_id}",
"CELIUMS_API_KEY": "${api_key}"
}
}
},
"hooks": {
"SessionStart": [
{ "matcher": "*", "hooks": [{ "type": "command", "command": "node ${CLAUDE_PLUGIN_ROOT}/src/hooks/session-start.mjs" }] }
],
"UserPromptSubmit": [
{ "matcher": "*", "hooks": [{ "type": "command", "command": "node ${CLAUDE_PLUGIN_ROOT}/src/hooks/user-prompt.mjs" }] }
],
"PostToolUse": [
{ "matcher": "*", "hooks": [{ "type": "command", "command": "node ${CLAUDE_PLUGIN_ROOT}/src/hooks/post-tool-use.mjs" }] }
],
"Stop": [
{ "matcher": "*", "hooks": [{ "type": "command", "command": "node ${CLAUDE_PLUGIN_ROOT}/src/hooks/stop.mjs" }] }
],
"SessionEnd": [
{ "matcher": "*", "hooks": [{ "type": "command", "command": "node ${CLAUDE_PLUGIN_ROOT}/src/hooks/session-end.mjs" }] }
]
}
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 42 lines scan A e87622c3193e
celiums is a plugin published in the GitHub repository terrizoaguimor/celiums-memory (23 stars, last pushed 9d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
claude-mem
Memory compression system for Claude Code - persist context across sessions.
claude-mem-cowork
Claude-Mem for Cowork: captures tool use via hooks, streams fragments to cmem.ai (Pro runs the observer), and injects observations back into new sessions and spawned agents.
hivemind marketplace
Plugin marketplace listing 1 plugin: hivemind.
hivemind
Cloud-backed persistent memory powered by Deeplake — read, write, and share memory across Claude Code sessions and agents.
claude-mem
Memory compression system for Claude Code - persist context across sessions.
memseek-memory
Durable, provenance-aware project memory for Claude Code.