per-user-isolation

A set of implementation patterns for keeping each Akashic Context user's files, database, and working memory separate. Akashic Context is an MCP server that stores persistent memories for AI agents.

In plain words
What is it for?
Use it when implementing per-user folders, SQLite database paths, memory files, memory directories, and context.json working-memory files.
Why use it?
It shows how to prevent users from sharing memory data accidentally while keeping a default workspace for callers that provide no user ID.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/tostechbr/memoryclaw/per-user-isolation
Any agent
npx skills add tostechbr/memoryClaw --skill per-user-isolation
Clone the repo
git clone --depth 1 https://github.com/tostechbr/memoryClaw

Made for: Claude Code, Codex.

Per session 42 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,329 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00042 $0.01329
Opus 5 $0.00021 $0.00665
Sonnet 5 $0.00008 $0.00266
Haiku 4.5 $0.00004 $0.00133

Measured 2d ago against content hash 58cb80d9c317, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

per-user-isolation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/skills/per-user-isolation/SKILL.md · 177 lines

How it starts

The opening of the file, as written. The whole thing — 177 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Per-User Isolation Patterns

Target Directory Structure (Sprint 0)

{dataDir}/
└── users/
    ├── default/              <- no userId given = backward compatible
    │   ├── memory.db         <- isolated SQLite DB
    │   ├── MEMORY.md         <- main memory file
    │   ├── context.json      <- working memory (scratchpad)
    │   └── memory/
    │       └── *.md
    ├── user_123/
    │   ├── memory.db
    │   ├── MEMORY.md
    │   ├── context.json
    │   └── memory/*.md
    └── 5511999999999/        <- WhatsApp phone as userId
        └── ...

Storage Layer Change (storage.ts)

Current (flat):

const dbName = `memory_${config.userId}.db`;
this.dbPath = path.join(ensureDir(config.dataDir), dbName);
// Result: {dataDir}/memory_mcp-user.db

Target (per-user):

const userDir = path.join(config.dataDir, "users", config.userId);
ensureDir(userDir);
this.dbPath = path.join(userDir, "memory.db");
// Result: {dataDir}/users/user_123/memory.db

Manager Layer Change (manager.ts)

Current (shared workspace):

const memoryFile = path.join(this.config.workspaceDir, "MEMORY.md");
const memoryDir = path.join(this.config.workspaceDir, "memory");

Target (per-user workspace): The workspaceDir passed to MemoryManager should already be the user-specific dir. Responsibility: the MCP server constructs the per-user workspaceDir before creating MemoryManager.

// In mcp-server getManager(userId):
const userWorkspaceDir = path.join(this.baseWorkspaceDir, "users", userId);
await fs.mkdir(userWorkspaceDir, { recursive: true });
await fs.mkdir(path.join(userWorkspaceDir, "memory"), { recursive: true });

const manager = new MemoryManager({
  dataDir: this.dataDir,
  userId,
  workspaceDir: userWorkspaceDir,  // user-specific workspace
  memory: this.memoryConfig,
});

Working Memory Interface (working-memory.ts)

// packages/core/src/memory/working-memory.ts

export interface WorkingMemory {
  session_id?: string;
  active_topic?: string;
  last_interaction?: string;      // ISO 8601
  pending_decisions?: string[];
  entities_seen?: string[];
  updated_at: string;             // ISO 8601
}

const DEFAULT_WORKING_MEMORY: WorkingMemory = {
  updated_at: new Date().toISOString(),
};

export async function getWorkingMemory(workspaceDir: string): Promise<WorkingMemory> {
  const contextPath = path.join(workspaceDir, "context.json");
  try {
    const content = await fs.readFile(contextPath, "utf-8");
    return JSON.parse(content) as WorkingMemory;
  } catch {
    return { ...DEFAULT_WORKING_MEMORY };
  }
}

export async function setWorkingMemory(
  workspaceDir: string,
  data: Partial<WorkingMemory>
): Promise<WorkingMemory> {
  const current = await getWorkingMemory(workspaceDir);
  const updated: WorkingMemory = {
    ...current,
    ...data,
    updated_at: new Date().toISOString(),
  };
  const contextPath = path.join(workspaceDir, "context.json");
  await fs.writeFile(contextPath, JSON.stringify(updated, null, 2), "utf-8");
  return updated;
}

Read the full file on GitHub · 177 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 177 lines · 42 tokens per session scan A 58cb80d9c317

Subscribe to this mod's changes

per-user-isolation is a skill published in the GitHub repository tostechbr/memoryClaw (8 stars, last pushed 5mo ago), licensed MIT. It adds 42 tokens to every session and 1,329 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

notion

Notion API for creating and managing pages, databases, and blocks. Use when the user wants to create a Notion page, query a Notion database, update Notion properties, search Notion, add content to Notion, manage Notion blocks, or interact with Notion data sources and workspaces via the API.

elizaOS/eliza · 69 tokens

agentic-supply-chain-detection

Detect agentic supply-chain risks: compromised dependencies, malicious plugins/tools/models, and untrusted update sources.

Tencent/AI-Infra-Guard · 0 tokens

skill-vetter

Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.

netease-youdao/LobsterAI · 42 tokens

ondb

A logical analysis and reasoning tool for AI. Use when decomposing documents into structured knowledge, querying entities and relations, validating consistency, or indexing files. Trigger on "remember", "what do I know about", "link X to Y", "show dependencies", "analyze this document", entity CRUD, or cross-skill…

x-cmd/x-cmd · 71 tokens

finding-protocol

Operational-tier finding template — minimal fields for sub-agent decision support. Heavyweight deliverable promotion lives in skills/decepticon/final-report.

PurpleAILAB/Decepticon · 32 tokens

babysit

Same-session monitoring loop for PRs, CI runs, tickets, and deployments using the monitorstart / monitorupdate / autonudgestop MCP tools. The loop re-injects your check instructions into THIS session on an idle interval — same context, same tools — and works from dashboard chat, Slack threads, and Discord DMs. Use…

kirodotdev/KiroCrew · 137 tokens