Local code memory
Give your agent focused, current code context from a private local index.
On this page
Index once. Ask for the part you need.
Leash keeps a persistent SQLite index for an explicitly selected project. The agent can search a few relevant snippets, retrieve a named symbol or inspect imports instead of repeatedly loading whole files. No model, embedding service or provider key is used to index or search.
Every query checks current files. Changed files are reparsed, deleted or newly ignored files are removed, and unchanged ASTs are reused across CLI or MCP restarts. This is read-time freshness, not a background watcher.
leash memory index --repo /absolute/path/to/project
leash memory search calculateTotal --repo /absolute/path/to/project
leash memory status --repo /absolute/path/to/projectConnect an agent over MCP
Configure an MCP client to launch leash memory serve --repo /absolute/path/to/project. Stdio is the only transport. The root is fixed at launch; tools cannot choose another directory. The server exposes index_codebase, codebase_status, search_code, get_symbol, impact and architecture.
Start with architecture or search_code, then request a particular symbol. Search returns at most 20 matches; symbol snippets have a 2,400-character ceiling. Results include coverage and truncation notices. No arbitrary shell, SQL, project-file writes or remote URL fetching is exposed.
{
"mcpServers": {
"leash-memory": {
"command": "leash",
"args": ["memory", "serve", "--repo", "/absolute/path/to/project"]
}
}
}Real syntax, clear limits
The index is bounded to 10,000 files, 32 MiB of source and 512 KiB per file. For a larger repository, choose a package root or add .leashignore rules. Query content stays within a 24,000-byte budget before its small measurement envelope.
| Language or query | Current coverage |
|---|---|
| TypeScript / JavaScript / TSX / JSX | Actual TypeScript AST: declarations, static imports and named calls |
| Other allowed text/code formats | Text outlines and full-text search; no semantic parser claim |
| Impact | Syntactic name matches; aliases, dynamic calls and runtime reachability are not proven |
| Architecture | Bounded file/language/import overview; no runtime or cross-language type graph |
Private source stays in your local index
The index directory is ~/.leash/code-memory (or LEASH_HOME/code-memory), with mode 0700; each repository database is mode 0600. Canonical real paths give repositories separate identities. The database contains source text and must be treated as private code. Leash does not upload the index or query snippets to its control plane.
Nested .gitignore and .leashignore rules apply. Environment/credential/private-key files, common secret directories, dependencies/build outputs, binary and oversized files, symlinks and hard links are excluded. Recognized secret patterns are also excluded, but no pattern can detect every secret in ordinary source: add explicit ignores for sensitive files.
A requesting coding agent can send returned snippets to its own model provider. Its normal data-sharing policy still applies. To delete an index, stop its memory server and remove that repository’s SQLite file; a later explicit memory invocation rebuilds it.
Measure context, not imagined savings
Results report exact serialized UTF-8 response bytes, a characters/4 token estimate and the full bytes of unique files matched by that query. The full-file baseline is explicit; it is not proof an agent would otherwise read every byte or that answer quality stayed identical. These figures are not provider tokens or invoice savings.
The automated fixture proof launches the real CLI and MCP server outside the checkout, checks incremental freshness and input/privacy boundaries, and records a synthetic full-file comparison. Leash makes no fixed 30× or 99% customer savings claim from that fixture.
pnpm exec vitest run apps/cli/src/memory.test.ts
node scripts/memory-proof.mjs