Sekha — AI skill for Claude Code
Zero-dependency AI memory system with hook-level rules enforcement for Claude Code.
How to install Sekha
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Thoth-soft/sekha and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Sekha does
Zero-dependency AI memory system with hook-level rules enforcement for Claude Code.
Alternatives in AI
- n8n Node Configuration — Node configuration with dependency rules and AI connections 3.6k ★
- WindsurfAPI — Turn Windsurf / Devin Desktop's 100+ AI models (Claude, GPT, Gemini, DeepSeek, Kimi, GLM, SWE) into OpenAI-, A 3k ★
- Pro Workflow — 1,400+ Battle-tested Claude Code workflows from power users 1.4k ★
README
Sekha
**Persistent memory for Claude Code. Zero dependencies. Plain markdown. Plus: the only AI memory system that can hard-block destructive tool calls.**
What Sekha does
**1. Remembers things across sessions.** Tell Claude in one session, ask about it in the next, and it knows. Preferences, decisions, project context, anything — saved as plain markdown files under `~/.sekha/`. Close Claude Code. Open it again tomorrow. The memory is still there.
Claude invokes `sekha_save` / `sekha_search` / `sekha_list` / `sekha_delete` via MCP to manage the memory itself. You just talk to Claude normally.
**2. Blocks dangerous tool calls (the moat).** Sekha hooks into Claude Code's `PreToolUse` event and returns `permissionDecision: "deny"` when a tool-input matches a regex rule you've written. The AI **cannot bypass this**, even with `--dangerously-skip-permissions`. `rm -rf`, `git push --force`, `DROP TABLE` — whatever you choose to guard. Rules are plain markdown in `~/.sekha/rules/`, so your enforcement policy is as reviewable as any other config under version control.
Every other memory system (MemPalace, Mem0, Letta, Zep, Basic Memory, CLAUDE.md) only stores rules. Sekha enforces them at the hook boundary.
Honest scope
**What Sekha enforces (hard):** regex-matchable tool-input patterns -- `rm -rf /`, `git push --force origin main`, `DROP TABLE users`. The PreToolUse hook vetoes the tool call before it runs.
**What Sekha does NOT enforce:** behavioral rules like "always confirm before acting" or "no assumptions." Those remain prompt-level reminders and the AI can override them. See the [Threat Model](#threat-model) for why this is a fundamental limit of today's Claude Code hook surface, not a bug in Sekha.
Memory across sessions

*Claude remembers what you told it in a previous session — saved as a markdown file under `~/.sekha/`, retrieved via the `sekha_search` MCP tool on demand.*
Blocking a
Related Skills
Yotta Memory
File-based cross-agent memory standard for AI agents. Zero-dependency CLI (init/remember/recall/forget/archive
AI Coding Rules Scaffold
Two-layer enforcement (pre-commit hook + CI mirror) for small teams using AI agents. Catches debug leaks, file
Aapp Kit
Zero-drift autonomous pair-programming architecture for Antigravity, Claude Code, Cursor & AI agents. Decouple
Datafog Python
Offline PII firewall for AI agents and LLM apps: fast local detection and redaction, Claude Code hook, LiteLLM
CoalGob
Recoverable-delete guard for AI coding agents - BETA, classifier only: a pure zero-dependency parser that read
LLM Secret Manager
The secret manager for LLM agents: create, rotate, and use secrets they can never read. OS-native keyvault (ma
Related Agents
Research Orchestrator
Use this agent when coordinating multi-phase research pipelines that require dependency tracking, agent dispat
Sf Security Engineer
Security Engineer of the Software Factory cell. Use to run SAST/dependency/secret scans, verify zero-trust sec
Dependency Gatekeeper
Reviews any pom.xml change that adds, upgrades, or removes a dependency. Use proactively whenever a block is t