Agent skill

Slm Governance

by qualixar in qualixar/superlocalmemory

Governed-workspace behavior for SuperLocalMemory. An agent skill from qualixar/superlocalmemory.

AGPL-3.0Auto-check: notesLegal & Compliance

Install Slm Governance

skills CLI
$ npx skills add qualixar/superlocalmemory --skill slm-governance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install qualixar/superlocalmemory slm-governance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/qualixar/superlocalmemory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugin/skills/slm-governance .claude/skills/slm-governance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
slm-governance
GitHub stars
230
Token cost
~2.3k tokens
SKILL.md length
1,020 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Governed-workspace behavior for SuperLocalMemory. An agent skill from qualixar/superlocalmemory.

  • Works in 3 steps: Stop the current operation immediately. → Report the requirement to the user. → Never cache, retry, or work around the…
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Role model, require-login, Retention and lifecycle and Audit trail, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Slm Governance is an agent skill from qualixar/superlocalmemory. Governed-workspace behavior for SuperLocalMemory. Covers roles (admin/member/viewer) and company mode, retention and lifecycle settings, the audit trail, GDPR export and erasure, and how agents must behave when operating under workspace governance. The audit and retention tools need the power MCP profile. Agents must never bypass governance controls.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering Privacy and GDPR. It works with Model Context Protocol. The repository describes itself as: Open-source governed, local-first memory control plane for AI agents and teams. arXiv:2608.08253. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “/slm-governance”

Requirements

  • Pre-approved tools (allowed-tools): audit_trail, set_retention_policy, get_retention_stats, get_lifecycle_status, compact_memories, consistency_check, recall, search, remember, Bash

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Stop the current operation immediately.
  2. Report the requirement to the user.
  3. Never cache, retry, or work around the block.

What it can do on your machine

Read from SKILL.md and the folder at commit 26f8c68. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • audit_trail
    • set_retention_policy
    • get_retention_stats
    • get_lifecycle_status
    • compact_memories
    • consistency_check
    • recall
    • search
    • remember
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Slm Governance loads about 2.3k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,020 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: audit_trail, set_retention_policy, get_retention_stats, get_lifecycle_status, compact_memories, cons

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from qualixar/superlocalmemory at commit 26f8c68, republished under its AGPL-3.0 licence (© qualixar). 1,020 words, ~2,284 tokens.

Download SKILL.mdSave it as .claude/skills/slm-governance/SKILL.md (or your agent's skills folder).
name
slm-governance
description
Governed-workspace behavior for SuperLocalMemory. Covers roles (admin/member/viewer) and company mode, retention and lifecycle settings, the audit trail, GDPR export and erasure, and how agents must behave when operating under workspace governance. The audit and retention tools need the power MCP profile. Agents must never bypass governance controls.
allowed-tools
audit_trail, set_retention_policy, get_retention_stats, get_lifecycle_status, compact_memories, consistency_check, recall, search, remember, Bash
when_to_use
- "What can I do in this workspace?" (role check) - "Move cold memories to archive after 60 days" - "Show the audit trail for recent memory operations"…

slm-governance — Governed Workspace Behavior

SuperLocalMemory can run with named users and roles per workspace (company mode), keeps a compliance audit trail, applies a retention lifecycle, and ships GDPR export and erasure commands. This skill documents how an agent must behave in a governed workspace and what the governance tools really do. The MCP audit and retention tools are in the power tool set (see slm-profile).


Role model

By default SLM is single-user: whoever runs it is the owner and nothing asks for a login. Company mode adds named users, each with one role per workspace (profile). A role in one workspace grants nothing in another.

RoleReadWriteShare (shared/global writes)DeleteManage users and settings
viewerYesNoNoNoNo
memberYesYesYesNoNo
adminYesYesYesYesYes

Agent behavior by role:

  • Viewer: Only call recall, search, fetch, list_recent and other reads. Never call remember, update_memory, delete_memory or any write tool. If a write is refused, say so: "This workspace is read-only for my role."
  • Member: May write memories, including scope="shared" and scope="global" when the user explicitly asks for them. May not delete memories or change users, roles or settings.
  • Admin: Everything above plus deletion and user administration.

No MCP tool or slm command reports your role (only a signed-in dashboard session can ask the daemon, at GET /api/rbac/whoami). Do not guess it: attempt what the user asked and treat a permission refusal as final. Setting up users, roles and "Require login" is done in the dashboard under Settings → Access; there is no slm user or slm role command. The machine operator keeps user administration in every mode so a mistake cannot lock everyone out.


require-login

When login is required, every operation on memories needs a signed-in user, including the connection your assistant uses. SLM handles this at the daemon level; agents do not pass credentials in tool calls. If a tool call returns an authentication or permission error, you must:

  1. Stop the current operation immediately.
  2. Report the requirement to the user.
  3. Never cache, retry, or work around the block.

In this mode, include_global=True and include_shared=True on recall are quietly turned off while the recall policy forbids cross-profile reads (the default), so an opt-in recall can come back with only personal facts. Do not try to work around it. See slm-scope.


Retention and lifecycle

Every memory moves through lifecycle states as it goes unused: active, warm, cold, archived. Two tools set and inspect that, and a third runs the forgetting cycle. They need the power tool set.

Set the thresholds
set_retention_policy(
  cold_after_days: int = 30,      # days of inactivity before a memory goes cold
  archive_after_days: int = 90,   # days before it is archived
)

It sets two thresholds and returns them. There is no profile_id argument and there are no named retention zones or per-tag policies; tagging a memory does not route it to a different policy.

Look at the state
get_retention_stats(profile_id="")
get_lifecycle_status(limit=50, profile_id="")

get_retention_stats reports, from the retention table, the count and average retention score per Ebbinghaus zone (active, warm, cold, archive, forgotten) and the totals. get_lifecycle_status counts the active, warm, cold and archived state of up to limit memories and returns up to ten short samples of each. Neither says when the next cycle runs.

Apply it
forget(dry_run=True)          # preview the decay cycle for the active profile
compact_memories(dry_run=True) # preview lifecycle-state transitions

The MCP forget tool is not a delete: it recomputes retention scores and moves memories between zones. compact_memories moves memories whose lifecycle state has become due (for example cold to archived); it does not merge duplicates. Both default to a dry run. Run the preview first, show it to the user, and only then pass dry_run=False. Do not run either without the user's say-so.


Show full SKILL.md (435 more words)Show less

Audit trail

audit_trail(limit: int = 50)

Returns the newest limit rows of the compliance audit for the active profile, as {"success", "entries", "count"}. Each entry has audit_id, profile_id, action, target_type, target_id, details and timestamp. There are no filter arguments. Entries are compliance actions (store, retrieve, delete, export and the like).

Use it for compliance reviews, for investigating an unexpected change, and for audit reports to a data controller.


GDPR

bash
slm gdpr status [--profile P] [--json]            # posture: receipts, audit counts, known gaps; read-only
slm gdpr export --profile P [--output FILE] [--json]   # Art. 15/20 access and portability
slm gdpr erase --profile P --dry-run [--json]     # preview an erasure
slm gdpr erase --profile P --yes [--json]         # Art. 17 erasure, IRREVERSIBLE
slm gdpr verify --receipt-id ID [--profile P]     # check an erasure receipt (exit 0 ok, 1 tampered, 2 not found)

slm gdpr erase erases a profile. It refuses to run without both --profile and --yes, and without them it only previews. It is the only irreversible operation here, so confirm the subject, the profile and the authority to erase with the user before running it. slm gdpr status lists the known gaps (for example backups and the code graph) rather than claiming completeness.

To remove individual memories rather than a whole profile, use the deletion commands from slm-remember:

bash
slm forget "<subject or project name>" --dry-run --json   # ALWAYS first
slm forget "<subject or project name>" --yes --json
slm delete <fact_id> --yes --json

Memories that belong to a reviewed correction cannot be deleted this way; the refusal names the case. After an erasure, confirm with slm recall "<content>" that nothing comes back, and never try to re-derive erased content from other stored facts.


Scope enforcement in governed workspaces

  • Viewers cannot write anything, whatever the scope argument.
  • Members and admins can write shared and global facts; writing either scope needs the share permission, which both roles hold.
  • Agents must not split a global fact into several shared facts, or otherwise accumulate visibility the user did not ask for.

Integrity checks

consistency_check(limit: int = 100)

Runs a sheaf-consistency check over up to limit memories and returns pairs of facts that contradict each other, with a severity (fact_a, fact_b, severity, content_a), plus facts_checked, facts_errored and total_contradictions. If the checker is disabled it says so in note. For the health of the store itself (orphan rows, erased words left behind, unfinished deletes) use slm db integrity and slm db repair; see slm-status.


Agent checklist for governed workspaces

Before each write operation:

  • The user asked for it, and a refusal from the workspace is respected
  • Scope is personal unless the user explicitly asked to share
  • Pass session_id so the write is attributed

Before running any destructive or state-changing operation (forget, compact_memories, slm forget --yes, slm gdpr erase --yes):

  • The user authorized it in this conversation
  • Ran the dry run or preview and showed it to the user
  • GDPR: confirmed the subject or controller authorized the erasure

  • slm-scope — scope model details (personal/shared/global)
  • slm-profile — memory profiles and tool sets
  • slm-remember — fact storage, corrections and deletion
  • slm-recall — retrieval reference (includes scope read flags)
  • slm-mesh — mesh tools
  • To use this memory from a web assistant or another computer, see the slm-web-access skill.

SuperLocalMemory v4.1.24 · Qualixar · AGPL-3.0-or-later

© qualixar, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugin/skills/slm-governance of qualixar/superlocalmemory.

Open the folder on GitHubat commit 26f8c68

Compare with similar skills

Slm Governance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Slm Governance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Slm Governance this skillqualixar/superlocalmemory230—~2.3kAutomated safety check: NotesAGPL-3.0
Pii Contract Analyzegregmos/PII-Shield150—~8.9kAutomated safety check: NotesMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Repo Prepglebis/claude-skills391—~1.6kAutomated safety check: PassMIT
Find Law Firmjeremylongshore/tons-of-skills-marketplace2.8k—~3.6kAutomated safety check: NotesMIT
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Repo Prep

    glebis/claude-skills

    Interactively prepare a code repository for publication — LICENSE, NOTICE, AUTHORSHIP, README sections, package metadata, .gitignore, community docs (CONTRIBUTING/CODEOFCONDUCT/SECURITY/CHANGELOG)…

    391 GitHub stars~1.6k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Find Law Firm

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US B2B law firms — corporate, IP/patent, M&A and securities, employment, commercial litigation…

    2.8k GitHub stars~3.6k tokensUpdated yesterday
    Legal & ComplianceAuto-check: notes
  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from qualixar/superlocalmemory

All 17 skills in this repo
  • Superlocalmemory

    qualixar/superlocalmemory

    AI agent memory with mathematical foundations. An agent skill from qualixar/superlocalmemory.

    230 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Slm Graph

    qualixar/superlocalmemory

    Index and query a codebase as a structural graph — build the code graph, trace blast radius of a change, find callers/callees/inheritors, semantic code search by meaning, assemble PR review context…

    230 GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Slm Loop

    qualixar/superlocalmemory

    Gate-verified bounded loops with SuperLocalMemory as the durable ledger.

    230 GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Slm Recall

    qualixar/superlocalmemory

    Search and retrieve facts, decisions, and past context from SuperLocalMemory.

    230 GitHub stars~5.1k tokensUpdated today
    Auto-check: notes
  • Slm Remember

    qualixar/superlocalmemory

    Capture durable facts, decisions, constraints, and gotchas into SuperLocalMemory.

    230 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Slm Scope

    qualixar/superlocalmemory

    Controls memory visibility across profiles — personal (private, default), shared (selected profiles), or global (all profiles on this machine).

    230 GitHub stars~1.6k tokensUpdated today
    Auto-check: notes

Questions about Slm Governance

What does Slm Governance do?

Governed-workspace behavior for SuperLocalMemory. An agent skill from qualixar/superlocalmemory. Slm Governance is an agent skill from qualixar/superlocalmemory. Governed-workspace behavior for SuperLocalMemory.

When should I use Slm Governance?

Slm Governance fits situations like: tasks that involve Privacy and GDPR.

How do I install Slm Governance in Claude Code?

Run `npx skills add qualixar/superlocalmemory --skill slm-governance -a claude-code`. Or copy the skill folder (plugin/skills/slm-governance in qualixar/superlocalmemory) into .claude/skills/slm-governance in your project. Claude Code loads it when a task matches its description.

How do I install Slm Governance in Codex?

Run `npx skills add qualixar/superlocalmemory --skill slm-governance -a codex`. Or copy the skill folder (plugin/skills/slm-governance in qualixar/superlocalmemory) into .agents/skills/slm-governance in your project. Codex loads it when a task matches its description.

Can I use Slm Governance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add qualixar/superlocalmemory --skill slm-governance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/slm-governance, .gemini/skills/slm-governance, .github/skills/slm-governance and .opencode/skills/slm-governance in your project.

What does Slm Governance need to run?

SKILL.md names no scripts, command-line tools or credentials: Slm Governance is instructions for the agent only. Its frontmatter pre-approves these tools: audit_trail, set_retention_policy, get_retention_stats, get_lifecycle_status, compact_memories, consistency_check, recall, search, remember, Bash.

Does Slm Governance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Slm Governance safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Slm Governance use?

Slm Governance is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Slm Governance use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Slm Governance?

Skills that share tags, products or a category with Slm Governance: Pii Contract Analyze (gregmos/PII-Shield, 150 stars), Audit Report (harness/harness-skills, 115 stars), Repo Prep (glebis/claude-skills, 391 stars) and Find Law Firm (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Slm Governance?

qualixar (a GitHub organization) maintains it in qualixar/superlocalmemory, which has 230 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.

Source: qualixar/superlocalmemory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.