{"domain":"emem.dev","count":20,"changes":[{"captured_at":"2026-08-24T17:16:48","card_hash":"410327aff365241febdffced893298e1a3687dbb62ce6aeaa96ef138f87c21b0","previous_card_hash":"6796da18f5c3de445d4b7fb0ad957cebb8ae0d5050221e31b71a6825039b7afa","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"perception_at","fields":["inputModes","outputModes"]}],"fields_changed":[],"other_changed":true,"is_empty":false,"human_summary":"updated 1 skill"}},{"captured_at":"2026-08-23T18:25:26","card_hash":"6796da18f5c3de445d4b7fb0ad957cebb8ae0d5050221e31b71a6825039b7afa","previous_card_hash":"9b5bd3aa63646de72e1ceedeb7a51dc48e61690c55d70eee7c214d6992c368ac","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[],"fields_changed":[{"field":"version","before":"2.2.0","after":"2.3.0"}],"other_changed":true,"is_empty":false,"human_summary":"version 2.2.0 → 2.3.0"}},{"captured_at":"2026-08-22T23:16:49","card_hash":"9b5bd3aa63646de72e1ceedeb7a51dc48e61690c55d70eee7c214d6992c368ac","previous_card_hash":"ad793c9578f584e678b54f38bb4181bb21eb31676ba586cd5b421f4855376627","diff":{"skills_added":[{"id":"perception_at","name":"Live street perception at a place","description":"Counts per object class at a cell right now, from a retained camera clip whose sha256 is committed in a signed receipt. Answers what orbit cannot: a satellite revisits in days.","tags":["read","rest","direct_sensor"],"inputModes":null,"outputModes":null},{"id":"perception_gonogo","name":"Proceed or wait, for something that has to move","description":"Proceed-or-wait over what a street camera sees, for something that has to move. Returns the clip it reasoned from and its age. Undecidable returns wait. Not a safety system.","tags":["read","rest","model_output"],"inputModes":null,"outputModes":null},{"id":"perception_postcard","name":"Painted postcard of a place","description":"A place painted from its own camera clip, one motif per object counted, with the cell, the count and the clip hash inside the file. Unobserved and empty are painted differently.","tags":["read","rest","direct_sensor"],"inputModes":null,"outputModes":null}],"skills_removed":[],"skills_changed":[],"fields_changed":[],"other_changed":true,"is_empty":false,"human_summary":"added 3 skills"}},{"captured_at":"2026-08-19T23:17:26","card_hash":"ad793c9578f584e678b54f38bb4181bb21eb31676ba586cd5b421f4855376627","previous_card_hash":"d737be99fbba78a8b9df330688e1612616e41ede03d48459f3fa76565554960c","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[],"fields_changed":[],"other_changed":true,"is_empty":false,"human_summary":"internal fields changed"}},{"captured_at":"2026-08-19T07:15:20","card_hash":"d737be99fbba78a8b9df330688e1612616e41ede03d48459f3fa76565554960c","previous_card_hash":"3d86a8b956099f4c01772d31135c60c52465fef361e797a2068a151b237a681a","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[],"fields_changed":[{"field":"protocolVersion","before":"1.2.0","after":"1.0"},{"field":"preferredTransport","before":"HTTP+JSON","after":"JSONRPC"}],"other_changed":true,"is_empty":false,"human_summary":"protocolVersion 1.2.0 → 1.0 · preferredTransport HTTP+JSON → JSONRPC"}},{"captured_at":"2026-08-18T05:39:50","card_hash":"3d86a8b956099f4c01772d31135c60c52465fef361e797a2068a151b237a681a","previous_card_hash":"737b0488da444c0ab9d821cec9c337e4d930d2deb3e56a2b6f8b79361553b1a8","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[],"fields_changed":[],"other_changed":true,"is_empty":false,"human_summary":"internal fields changed"}},{"captured_at":"2026-08-17T22:22:41","card_hash":"737b0488da444c0ab9d821cec9c337e4d930d2deb3e56a2b6f8b79361553b1a8","previous_card_hash":"5065a79937966b41eec33dd958cc5ec8f09f03bcb1d04d7b40ebea049569f3f9","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_ask","fields":["description"]},{"id":"emem_at","fields":["description"]},{"id":"emem_backfill","fields":["description"]},{"id":"emem_band_composite","fields":["description"]},{"id":"emem_band_cube","fields":["description"]},{"id":"emem_band_raster","fields":["description"]},{"id":"emem_benchmark","fields":["description"]},{"id":"emem_burn_severity","fields":["description"]},{"id":"emem_capabilities","fields":["description"]},{"id":"emem_cell_geojson","fields":["description"]},{"id":"emem_cell_scene_rgb","fields":["description"]},{"id":"emem_cells_in_bbox","fields":["description"]},{"id":"emem_change_attribution","fields":["description"]},{"id":"emem_compare_same_doy","fields":["description"]},{"id":"emem_corpus_state_stats","fields":["description"]},{"id":"emem_cube_resolve","fields":["description"]},{"id":"emem_data_availability","fields":["description"]},{"id":"emem_deforestation_alert","fields":["description"]},{"id":"emem_derive","fields":["description"]},{"id":"emem_derive_list","fields":["description"]},{"id":"emem_diff","fields":["description"]},{"id":"emem_echo_verify","fields":["description"]},{"id":"emem_edges_recall","fields":["description"]},{"id":"emem_elevation","fields":["description"]},{"id":"emem_embedding_centroid","fields":["description"]},{"id":"emem_embedding_diversity","fields":["description"]},{"id":"emem_entity","fields":["description"]},{"id":"emem_entity_link","fields":["description"]},{"id":"emem_entity_resolve","fields":["description"]},{"id":"emem_eudr_dds","fields":["description"]},{"id":"emem_fetch","fields":["description"]},{"id":"emem_field_boundaries","fields":["description"]},{"id":"emem_find_similar","fields":["description"]},{"id":"emem_fleet","fields":["description"]},{"id":"emem_forest","fields":["description"]},{"id":"emem_guard_selfhost","fields":["description"]},{"id":"emem_guard_verdict","fields":["description"]},{"id":"emem_heat_solve","fields":["description"]},{"id":"emem_hunt","fields":["description"]},{"id":"emem_intent","fields":["description"]},{"id":"emem_jepa_predict","fields":["description"]},{"id":"emem_jepa_predict_v2","fields":["description"]},{"id":"emem_locate","fields":["description"]},{"id":"emem_log_consistency","fields":["description"]},{"id":"emem_log_sth","fields":["description"]},{"id":"emem_log_witnesses","fields":["description"]},{"id":"emem_memory_bundle","fields":["description"]},{"id":"emem_memory_bundle_resolve","fields":["description"]},{"id":"emem_memory_contradictions","fields":["description"]},{"id":"emem_memory_create","fields":["description"]},{"id":"emem_memory_delete","fields":["description"]},{"id":"emem_memory_insert","fields":["description"]},{"id":"emem_memory_list_by_kind","fields":["description"]},{"id":"emem_memory_rename","fields":["description"]},{"id":"emem_memory_search","fields":["description"]},{"id":"emem_memory_str_replace","fields":["description"]},{"id":"emem_memory_supersede","fields":["description"]},{"id":"emem_memory_token","fields":["description"]},{"id":"emem_memory_token_resolve","fields":["description"]},{"id":"emem_memory_view","fields":["description"]},{"id":"emem_ndvi","fields":["description"]},{"id":"emem_neighborhood_consistency","fields":["description"]},{"id":"emem_query_region","fields":["description"]},{"id":"emem_raster_bundle","fields":["description"]},{"id":"emem_raster_bundle_resolve","fields":["description"]},{"id":"emem_raster_resolve","fields":["description"]},{"id":"emem_reason","fields":["description"]},{"id":"emem_recall","fields":["description"]},{"id":"emem_recall_many","fields":["description"]},{"id":"emem_region_similarity","fields":["description"]},{"id":"emem_rice_ch4","fields":["description"]},{"id":"emem_sar_forest_disturbance","fields":["description"]},{"id":"emem_soil","fields":["description"]},{"id":"emem_spi","fields":["description"]},{"id":"emem_state","fields":["description"]},{"id":"emem_state_diff","fields":["description"]},{"id":"emem_state_multi","fields":["description"]},{"id":"emem_substrates","fields":["description"]},{"id":"emem_temporal_route","fields":["description"]},{"id":"emem_terrain","fields":["description"]},{"id":"emem_tools","fields":["description"]},{"id":"emem_topics","fields":["description"]},{"id":"emem_trace_verify","fields":["description"]},{"id":"emem_triple_consensus","fields":["description"]},{"id":"emem_verify_receipt","fields":["description"]},{"id":"emem_water","fields":["description"]},{"id":"emem_wave_solve","fields":["description"]}],"fields_changed":[{"field":"description","before":"emem is shared, verifiable memory for AI agents: every place has one address, every observation is one signed fact, and any agent can check any answer offline, with no key, no account, and no trust in us required. It stops referential drift, the paraphrase side pinned by the token, the world-readout side reported by the change-attribution ledger (the numeric split is roadmap): one canonical, citeable identity per place (cell64), fact (fact_cid), and object (emem:entity:<entity_cid>), so different models reason from the same world object instead of divergent descriptions. Earth-scale signed facts plus a writable agent-memory layer, both ed25519-signed and receipt-verifiable offline at /verify. Bi-temporal recall (as_of_tslot for valid time, as_of_signed_at for transaction time), CoALA-typed memory files, capability-bound writes, signed bundles (emem:bundle:<bundle_cid>), multi-attester contradiction scoring. No API keys.","after":"emem is shared memory for AI agents working together in the real world. One agent writes down what it observed. Another agent reads the same bytes, not a summary of them. Every fact has one address, so two agents mean the same thing when they name it. Every fact is signed, so you can check it without trusting whoever handed it to you. Every fact says how it was produced, so you know what it is worth. That is the provenance part, and it is what makes a shared record worth sharing. Reads need no key and no account."}],"other_changed":false,"is_empty":false,"human_summary":"updated 87 skills · description emem is shared, verifiable memory for AI → emem is shared memory for AI agents work"}},{"captured_at":"2026-08-17T16:22:33","card_hash":"5065a79937966b41eec33dd958cc5ec8f09f03bcb1d04d7b40ebea049569f3f9","previous_card_hash":"1553751e4a6088eff9584723d5514e745f75e441099ed1dfff471e2fbbba2cf5","diff":{"skills_added":[{"id":"emem_memory_supersede","name":"memory_supersede, mark your own note replaced by a later one","description":"Point one of your notes at the note that replaces it. Readers of the superseded path then receive `superseded_by` and a `_superseded` banner, so a withdrawn claim stops resolving as though it were current. This is redirection, not deletion: the original bytes are unchanged and still resolve by their own cid, because the log is append-only and issued receipts must stay verifiable. The replacement must already exist here, a note cannot supersede itself, and a note already superseded cannot be re-aimed, so a correction chain stays append-only and cannot be rewritten after other agents cite it. WRITES ARE SIGNED: supply `attester: {pubkey_b32, sig_b32}` over blake3(\"emem.memory_write|supersede|<path>|<body_hash>\") with body_hash = blake3(\"<superseded_by>|<reason>\"); the signature binds both the destination and the stated reason, so a retraction cannot be re-aimed or reworded while keeping your name on it. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write.","tags":["write","L0"],"inputModes":null,"outputModes":null}],"skills_removed":[],"skills_changed":[],"fields_changed":[{"field":"version","before":"2.1.0","after":"2.2.0"}],"other_changed":true,"is_empty":false,"human_summary":"added 1 skill · version 2.1.0 → 2.2.0"}},{"captured_at":"2026-08-12T05:25:58","card_hash":"1553751e4a6088eff9584723d5514e745f75e441099ed1dfff471e2fbbba2cf5","previous_card_hash":"4b989008ca5cec076aadf53f4438877edc9f8ba9b2b9143cd80e095c35be94fe","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_memory_contradictions","fields":["description"]}],"fields_changed":[],"other_changed":false,"is_empty":false,"human_summary":"updated 1 skill"}},{"captured_at":"2026-08-11T10:03:30","card_hash":"4b989008ca5cec076aadf53f4438877edc9f8ba9b2b9143cd80e095c35be94fe","previous_card_hash":"fadf8ba21d33f7d827072cba72d636ee0ca69b9bb6783d4c3fcbc0546fabd292","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_memory_token_resolve","fields":["description"]},{"id":"emem_verify_receipt","fields":["description"]}],"fields_changed":[],"other_changed":false,"is_empty":false,"human_summary":"updated 2 skills"}},{"captured_at":"2026-08-11T03:28:46","card_hash":"fadf8ba21d33f7d827072cba72d636ee0ca69b9bb6783d4c3fcbc0546fabd292","previous_card_hash":"774896528fb4dd1f2a37985c8fb5c87ffc962543ee5c4a19c11cd636787a87e9","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_derive","fields":["description"]},{"id":"emem_diff","fields":["description"]},{"id":"emem_echo_verify","fields":["description"]},{"id":"emem_guard_selfhost","fields":["description"]},{"id":"emem_guard_verdict","fields":["description"]},{"id":"emem_locate","fields":["description"]},{"id":"emem_memory_bundle","fields":["description"]},{"id":"emem_memory_token","fields":["description"]},{"id":"emem_memory_token_resolve","fields":["description"]},{"id":"emem_verify_receipt","fields":["description"]}],"fields_changed":[],"other_changed":false,"is_empty":false,"human_summary":"updated 10 skills"}},{"captured_at":"2026-08-10T08:54:43","card_hash":"774896528fb4dd1f2a37985c8fb5c87ffc962543ee5c4a19c11cd636787a87e9","previous_card_hash":"eb63753c20bf93d03b74a43a46c27fb1a88e5ed2d040d33f98f76b1516d63eff","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[],"fields_changed":[{"field":"version","before":"2.0.0","after":"2.1.0"}],"other_changed":false,"is_empty":false,"human_summary":"version 2.0.0 → 2.1.0"}},{"captured_at":"2026-08-09T20:17:00","card_hash":"eb63753c20bf93d03b74a43a46c27fb1a88e5ed2d040d33f98f76b1516d63eff","previous_card_hash":"54b0a057902f906f4b85adab0b6c08d5845ad30f8424d5f7e30dc8f14ec222c5","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_find_similar","fields":["description"]},{"id":"emem_locate","fields":["description"]}],"fields_changed":[],"other_changed":false,"is_empty":false,"human_summary":"updated 2 skills"}},{"captured_at":"2026-08-06T12:28:46","card_hash":"54b0a057902f906f4b85adab0b6c08d5845ad30f8424d5f7e30dc8f14ec222c5","previous_card_hash":"5f3ef38f86a57ad4669fd33de9dbd57248758a2460745896f21cfd677af5e227","diff":{"skills_added":[{"id":"emem_guard_selfhost","name":"The procedure for running your own verdict server","description":"Returns the full emem-guard self-host skill as markdown, plus the exact build, test and run commands. A node you run needs no account here and no key from us: it generates its own signing key, keeps its own append-only verdict log, verifies what it holds, and cites what it does not. It exposes checkpoints for Anthropic Inference hooks, Claude Code client hooks, MCP tools/call, OpenAI-shaped clients, CloudEvents 1.0 and OPA-style policy clients, plus a native route that belongs to no vendor. Algebra: introspect.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_guard_verdict","name":"Check whether the citations in a draft actually verify","description":"Run emem-guard's policy pipeline over text you are about to send, against this responder's corpus. Finds every emem: citation, resolves each one, and returns allow or deny with a machine-readable reason: `EMEM-GUARD DENY <CODE> token=<token|-> fix=<fix> leaf=<leaf|->`. Codes are PROV_SIG (signature did not verify), PROV_BYTES (resolved to different content than claimed), PROV_DRIFT (reading has moved past its band threshold), CLAIM_UNGROUNDED (a measurable claim with no citation, opt-in via claim_gating). `fix` is the actionable half: refresh_token, remove_reference, contact_admin, cite_observation. ADVISORY: nothing is blocked, and a citation this responder does not hold is never a denial, because it is indistinguishable from one minted elsewhere. Algebra: verify.","tags":["verify","L1"],"inputModes":null,"outputModes":null}],"skills_removed":[],"skills_changed":[],"fields_changed":[],"other_changed":false,"is_empty":false,"human_summary":"added 2 skills"}},{"captured_at":"2026-08-06T04:52:18","card_hash":"5f3ef38f86a57ad4669fd33de9dbd57248758a2460745896f21cfd677af5e227","previous_card_hash":"3abdf3e8a7d55d773b94f970efb2957a97fabf84985e50247a9604a36cb8faa9","diff":{"skills_added":[{"id":"emem_memory_create","name":"memory_create, write a memory file (overwrite if exists)","description":"Write a memory file at `/memories/<path>` with the supplied `file_text`. Overwrites if the file exists AND your key owns the path; a write over someone else's file is refused, not merged. Persists to sled, content-addresses the bytes (`file_cid`), and signs the write so the operation carries a verifiable receipt. Mirrors the `create` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage. Formerly `memory_create`; that spelling still dispatches and is no longer advertised, because three of these verbs are destructive and shared a name with Claude's own memory tool. It is removed in 3.0.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_delete","name":"memory_delete, remove a memory file or directory","description":"Delete a memory file at `/memories/<path>`. When the path ends with `/`, every file beneath the directory is removed. Updates the path index but leaves prior content-addressed blobs in place (the audit history is append-only). Mirrors the `delete` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage. Deletion removes the path from the index; the content-addressed blob and its prior versions remain, because the write history is append-only and a receipt already issued must stay verifiable. Treat this as unpublish, not erasure. Operator erasure is a separate request (see PRIVACY.md). Formerly `memory_delete`; that spelling still dispatches and is no longer advertised, because three of these verbs are destructive and shared a name with Claude's own memory tool. It is removed in 3.0.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_insert","name":"memory_insert, insert at a given line","description":"Insert `new_str` after the given 1-indexed line in the named memory file. `insert_line: 0` inserts at the top. Writes a new `file_cid` and signs the receipt. Mirrors the `insert` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage. Formerly `memory_insert`; that spelling still dispatches and is no longer advertised, because three of these verbs are destructive and shared a name with Claude's own memory tool. It is removed in 3.0.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_list_by_kind","name":"memory_list_by_kind, typed enumeration of memory files","description":"List memory files by their typed `kind` (episodic | semantic | procedural | resource). Optional path prefix narrows the scan; results are sorted by signed_at descending. The kind taxonomy follows the CoALA / LangMem / MIRIX agent-memory ontology: `episodic` = observations of events, `semantic` = durable learned facts, `procedural` = playbooks, `resource` = generic durable scratchpad (default for back-compat). Reads are public: no key, no account, and every stored memory on this responder is world-readable, including files other agents wrote. Do not put anything private here. Formerly `memory_list_by_kind`; that spelling still dispatches and is no longer advertised, because three of these verbs are destructive and shared a name with Claude's own memory tool. It is removed in 3.0.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_rename","name":"memory_rename, move a memory file","description":"Move (rename) a memory file from `old_path` to `new_path`. Both paths must stay under `/memories/`; `new_path` must not already exist. The file_cid is preserved (no re-sign) so the prior receipt still binds the bytes. Mirrors the `rename` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage. Formerly `memory_rename`; that spelling still dispatches and is no longer advertised, because three of these verbs are destructive and shared a name with Claude's own memory tool. It is removed in 3.0.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_str_replace","name":"memory_str_replace, exact-string replacement in a memory file","description":"Replace `old_str` with `new_str` in the named memory file. Fails (no partial write) when `old_str` is absent or matches more than once. Writes a new content-addressed `file_cid` and signs the receipt. Mirrors the `str_replace` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage. Formerly `memory_str_replace`; that spelling still dispatches and is no longer advertised, because three of these verbs are destructive and shared a name with Claude's own memory tool. It is removed in 3.0.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_view","name":"memory_view, read file or directory listing","description":"Read the contents of a memory file at `/memories/<path>` or list a directory when the path ends with `/`. Optional `view_range: [start, end]` slices a 1-indexed inclusive line range out of the file. Mirrors the `view` verb in Anthropic's context-management-2025-06-27 memory tool spec. Reads are public: no key, no account, and every stored memory on this responder is world-readable, including files other agents wrote. Do not put anything private here. Formerly `memory_view`; that spelling still dispatches and is no longer advertised, because three of these verbs are destructive and shared a name with Claude's own memory tool. It is removed in 3.0.","tags":["read","L0"],"inputModes":null,"outputModes":null}],"skills_removed":[{"id":"memory_create","name":"memory_create, write a memory file (overwrite if exists)","description":"Write a memory file at `/memories/<path>` with the supplied `file_text`. Overwrites if the file exists AND your key owns the path; a write over someone else's file is refused, not merged. Persists to sled, content-addresses the bytes (`file_cid`), and signs the write so the operation carries a verifiable receipt. Mirrors the `create` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_delete","name":"memory_delete, remove a memory file or directory","description":"Delete a memory file at `/memories/<path>`. When the path ends with `/`, every file beneath the directory is removed. Updates the path index but leaves prior content-addressed blobs in place (the audit history is append-only). Mirrors the `delete` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage. Deletion removes the path from the index; the content-addressed blob and its prior versions remain, because the write history is append-only and a receipt already issued must stay verifiable. Treat this as unpublish, not erasure. Operator erasure is a separate request (see PRIVACY.md).","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_insert","name":"memory_insert, insert at a given line","description":"Insert `new_str` after the given 1-indexed line in the named memory file. `insert_line: 0` inserts at the top. Writes a new `file_cid` and signs the receipt. Mirrors the `insert` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_list_by_kind","name":"memory_list_by_kind, typed enumeration of memory files","description":"List memory files by their typed `kind` (episodic | semantic | procedural | resource). Optional path prefix narrows the scan; results are sorted by signed_at descending. The kind taxonomy follows the CoALA / LangMem / MIRIX agent-memory ontology: `episodic` = observations of events, `semantic` = durable learned facts, `procedural` = playbooks, `resource` = generic durable scratchpad (default for back-compat). Reads are public: no key, no account, and every stored memory on this responder is world-readable, including files other agents wrote. Do not put anything private here.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"memory_rename","name":"memory_rename, move a memory file","description":"Move (rename) a memory file from `old_path` to `new_path`. Both paths must stay under `/memories/`; `new_path` must not already exist. The file_cid is preserved (no re-sign) so the prior receipt still binds the bytes. Mirrors the `rename` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_str_replace","name":"memory_str_replace, exact-string replacement in a memory file","description":"Replace `old_str` with `new_str` in the named memory file. Fails (no partial write) when `old_str` is absent or matches more than once. Writes a new content-addressed `file_cid` and signs the receipt. Mirrors the `str_replace` verb in Anthropic's context-management-2025-06-27 memory tool spec. WRITES ARE SIGNED, NOT ANONYMOUS: supply `attester: {pubkey_b32, sig_b32}`, an ed25519 signature over blake3(\"emem.memory_write|<verb>|<path>|<body_hash>\"); an unattested write is refused with the exact digest to sign. Under `/memories/by_attester/<pubkey8>/...` only the matching key may write. Elsewhere the first attester to create a path owns it and only that key may change it, which makes every name outside your own prefix unreserved: do not build a dependency on a well-known open-root path such as `/memories/standard.md`, because whoever writes it first holds it permanently on a log that cannot be pruned. `/memories/.well-known/` is reserved to the operator and refuses every key, including ours; it is the only prefix where a fixed, agent-readable name cannot be claimed out from under you. Stored content is world-readable by design: this is a shared commons, not private storage.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_view","name":"memory_view, read file or directory listing","description":"Read the contents of a memory file at `/memories/<path>` or list a directory when the path ends with `/`. Optional `view_range: [start, end]` slices a 1-indexed inclusive line range out of the file. Mirrors the `view` verb in Anthropic's context-management-2025-06-27 memory tool spec. Reads are public: no key, no account, and every stored memory on this responder is world-readable, including files other agents wrote. Do not put anything private here.","tags":["read","L0"],"inputModes":null,"outputModes":null}],"skills_changed":[],"fields_changed":[],"other_changed":false,"is_empty":false,"human_summary":"added 7 skills · removed 7 skills"}},{"captured_at":"2026-08-05T16:58:20","card_hash":"3abdf3e8a7d55d773b94f970efb2957a97fabf84985e50247a9604a36cb8faa9","previous_card_hash":"3512a1383b59fd26a5b0230ac6f2d0a74831aed37fd3fdd5859245be9538c802","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_intent","fields":["description"]},{"id":"memory_create","fields":["description"]},{"id":"memory_delete","fields":["description"]},{"id":"memory_insert","fields":["description"]},{"id":"memory_rename","fields":["description"]},{"id":"memory_str_replace","fields":["description"]}],"fields_changed":[{"field":"version","before":"1.4.0","after":"2.0.0"}],"other_changed":false,"is_empty":false,"human_summary":"updated 6 skills · version 1.4.0 → 2.0.0"}},{"captured_at":"2026-08-01T13:41:31","card_hash":"3512a1383b59fd26a5b0230ac6f2d0a74831aed37fd3fdd5859245be9538c802","previous_card_hash":"d880d04063e8275f6be91d060053265acd505069ea93580957b1ceb90fd4fc91","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_memory_search","fields":["description"]},{"id":"memory_create","fields":["description"]},{"id":"memory_delete","fields":["description"]},{"id":"memory_insert","fields":["description"]},{"id":"memory_list_by_kind","fields":["description"]},{"id":"memory_rename","fields":["description"]},{"id":"memory_str_replace","fields":["description"]},{"id":"memory_view","fields":["description"]}],"fields_changed":[{"field":"version","before":"1.3.0","after":"1.4.0"}],"other_changed":true,"is_empty":false,"human_summary":"updated 8 skills · version 1.3.0 → 1.4.0"}},{"captured_at":"2026-07-29T22:16:06","card_hash":"d880d04063e8275f6be91d060053265acd505069ea93580957b1ceb90fd4fc91","previous_card_hash":"55ed98a121fcf530ed6aaaccea7dbbb723011007e1a11f52f9cc36dd5b2ff19a","diff":{"skills_added":[],"skills_removed":[],"skills_changed":[{"id":"emem_backfill","fields":["description"]},{"id":"emem_query_region","fields":["description"]},{"id":"emem_recall_many","fields":["description"]}],"fields_changed":[],"other_changed":false,"is_empty":false,"human_summary":"updated 3 skills"}},{"captured_at":"2026-07-29T10:05:33","card_hash":"55ed98a121fcf530ed6aaaccea7dbbb723011007e1a11f52f9cc36dd5b2ff19a","previous_card_hash":"6abc203e1561c784281078cbaf68645bf9234c397f1657010eb09f689b65ee48","diff":{"skills_added":[{"id":"emem_reason","name":"Compose a prose answer over signed facts (LLM, labelled)","description":"The opt-in reasoning tier: grounds your question through emem_ask (deterministic, signed), then has the responder's local model compose a prose answer over that envelope. The prose is model_output and signed:false by construction, it is never evidence; the grounding block beside it (fact_cids + receipt) is. Runs the model greedily (temperature 0) with a single-flight lock, so a cold load never fans out. For anything a signed envelope already answers, use emem_ask instead and skip the model entirely.","tags":["plan","L0"],"inputModes":null,"outputModes":null},{"id":"emem_substrates","name":"Substrate profile registry","description":"The written admission contract per contributor class (satellite archive, operator constellation, telescope, microscope, CCTV, mobile, drone, robot, industrial machine, fixed sensor): which admission rule applies (recomputable public archive, or complete OS execution trace), which trace layers a device of that class must capture, the measurement grain range, and which profile is the drift anchor. Content-addressed: the response carries the manifest CID every enrollment pins.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_trace_verify","name":"Verify a device's OS execution trace","description":"Stateless verification of an emem.os_trace.v1 record against a substrate profile: schema, device identity, capture window, per-layer coverage, segment digest chain, merkle trace_root, emitted-output binding, and the device's ed25519 signature. Returns the full verdict with every failed check named (chain_broken, missing_layer, output_unbound, signature_invalid, ...), never just a boolean, so a device maker can debug an enrollment offline before writing.","tags":["verify","L1"],"inputModes":null,"outputModes":null}],"skills_removed":[],"skills_changed":[{"id":"emem_algorithms","fields":["description"]},{"id":"emem_backfill","fields":["description"]},{"id":"emem_band_raster","fields":["description"]},{"id":"emem_capabilities","fields":["description"]},{"id":"emem_cell_geojson","fields":["description"]},{"id":"emem_coverage_map","fields":["description"]},{"id":"emem_coverage_matrix","fields":["description"]},{"id":"emem_edges_recall","fields":["description"]},{"id":"emem_embedding_centroid","fields":["name"]},{"id":"emem_embedding_diversity","fields":["name"]},{"id":"emem_eudr_dds","fields":["name","description"]},{"id":"emem_explain_algorithm","fields":["description"]},{"id":"emem_field_boundaries","fields":["description"]},{"id":"emem_fleet","fields":["description"]},{"id":"emem_hunt","fields":["name"]},{"id":"emem_log_witnesses","fields":["description"]},{"id":"emem_memory_search","fields":["name","description"]},{"id":"emem_neighborhood_consistency","fields":["description"]},{"id":"emem_recall_many","fields":["description"]},{"id":"emem_region_similarity","fields":["name","description"]},{"id":"emem_rice_ch4","fields":["description"]},{"id":"emem_sar_forest_disturbance","fields":["description"]},{"id":"emem_terrain","fields":["name"]},{"id":"memory_create","fields":["name"]},{"id":"memory_delete","fields":["name"]},{"id":"memory_insert","fields":["name"]},{"id":"memory_list_by_kind","fields":["name"]},{"id":"memory_rename","fields":["name"]},{"id":"memory_str_replace","fields":["name"]},{"id":"memory_view","fields":["name"]}],"fields_changed":[{"field":"description","before":"Shared, verifiable memory for AI agents that stops referential drift, the paraphrase side pinned by the token, the world-readout side reported by the change-attribution ledger (the numeric split is roadmap): one canonical, citeable identity per place (cell64), fact (fact_cid), and object (emem:entity:<entity_cid>), so different models reason from the same world object instead of divergent descriptions. Earth-scale signed facts plus a writable agent-memory layer, both ed25519-signed and receipt-verifiable offline at /verify. Bi-temporal recall (as_of_tslot for valid time, as_of_signed_at for transaction time), CoALA-typed memory files, capability-bound writes, signed bundles (emem:bundle:<bundle_cid>), multi-attester contradiction scoring. No API keys.","after":"emem is shared, verifiable memory for AI agents: every place has one address, every observation is one signed fact, and any agent can check any answer offline, with no key, no account, and no trust in us required. It stops referential drift, the paraphrase side pinned by the token, the world-readout side reported by the change-attribution ledger (the numeric split is roadmap): one canonical, citeable identity per place (cell64), fact (fact_cid), and object (emem:entity:<entity_cid>), so different models reason from the same world object instead of divergent descriptions. Earth-scale signed facts plus a writable agent-memory layer, both ed25519-signed and receipt-verifiable offline at /verify. Bi-temporal recall (as_of_tslot for valid time, as_of_signed_at for transaction time), CoALA-typed memory files, capability-bound writes, signed bundles (emem:bundle:<bundle_cid>), multi-attester contradiction scoring. No API keys."},{"field":"version","before":"1.2.1","after":"1.3.0"},{"field":"url","before":"https://emem.dev/mcp","after":"https://emem.dev/a2a/tasks"}],"other_changed":true,"is_empty":false,"human_summary":"added 3 skills · updated 30 skills · description Shared, verifiable memory for AI agents  → emem is shared, verifiable memory for AI · version 1.2.1 → 1.3.0 · url https://emem.dev/mcp → https://emem.dev/a2a/tasks"}},{"captured_at":"2026-07-22T09:08:56","card_hash":"6abc203e1561c784281078cbaf68645bf9234c397f1657010eb09f689b65ee48","previous_card_hash":null,"diff":{"skills_added":[{"id":"emem_air","name":"Air-quality snapshot (CAMS PM2.5 / NO2 / O3)","description":"Recall the signed Copernicus CAMS air-quality facts (PM2.5 + NO2 + O3) at a place's cell64, attesting on a miss. Composes locate → recall → aggregate; each band carries a citeable fact_cid.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_algorithms","name":"Composition recipes (algorithms)","description":"Content-addressed dictionary of composition recipes — formulas that fuse attested band facts (and embeddings) into derived scores, classifications, and similarity metrics.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_ask","name":"Ask a free-text question about a place","description":"Single-shot free-text answer about a real-world location, backed by signed satellite/elevation/water/built-up receipts. Forwards a place mention plus a question; runs the locate → recall → algorithm chain server-side; returns one packaged envelope.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_at","name":"Multi-band snapshot at a place","description":"One-shot recall of the signed facts at a place's cell64 (or lat/lng); each band carries a citeable fact_cid. Defaults to emem's standard at-a-glance band set; pass `band` / `bands` to override. Polygon-resolved places stay at the centroid by default (`n_cells: 1`) to keep multi-band calls cheap; pass `n_cells: 2..=64` to fan out.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_backfill","name":"Materialize historical facts in a window","description":"Materialize and sign every per-tslot fact for one (cell, band) inside a [start_unix, end_unix] window. Returns a signed list of (tslot, fact_cid, status) for each step. Slow but possible — one upstream fetch per tslot, capped by `max_facts`.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_band_composite","name":"Band composite: a signed cloud-masked median over a window","description":"Mint a signed, cloud-masked median composite over a date window as a raster-shaped field: the clean, gap-filled texture a world model actually drapes, rather than one cloudy scene. It reads every Sentinel-2 scene in [start_date, end_date] over the bbox, masks each per pixel by its SCL scene-classification class (default reject {0,1,3,8,9,10}: no-data, saturated, cloud shadow, cloud, cirrus; snow 11 is KEPT because snow is surface, not occlusion, and a snow-rejected median would fabricate a bare winter scene; override with mask_policy), and takes the per-pixel lower-of-two median (never averaging two measurements into a value nobody took) with a pinned min_valid_count, below which a pixel is nodata. The mask policy, min_valid_count, and the exact member scene list are pinned in the signed derivation, so a stranger re-derives the composite pixel for pixel from the same scenes. Returns an emem:raster: token (resolve with emem_raster_resolve) plus the content-addressed artifact; the receipt binds (aoi_cid, derivation_cid). Needs at least two clear scenes at one CRS. This signs and persists the derivation.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_band_cube","name":"Band cube: a field over time, as a signed manifest","description":"Mint an emem:cube: token: a Sentinel-2 field over an AOI ACROSS TIME. A world model is a field over an area across time, and emem:raster: names only one time-slice, so a 4D world's time scrub had no token to anchor. This mints one band_raster member per target date, each an independent, resolvable emem:raster: derivation, then signs a cube record binding the ordered set. It is NOT new pixels: lineage terminates in each member's pinned scene, so a stranger walks cube -> members -> scenes and re-derives every value from raw Sentinel-2 bytes. cube_cid content-addresses the ordered membership (blake3 of the member derivation cids), so the same slices always name the same cube. Two dates that resolve to the same scene collapse; a cube needs at least two distinct slices and caps at 24 per mint (refused with the cap named). Each member echoes `requested_dates` (the observed_on entries that mapped to it) and `requested_date_distance_days` (the nearest one's gap from the scene's own capture date), so a caller lines a requested date up with its slice directly rather than guessing by tslot proximity. The receipt's FIELD preimage segment binds (aoi_cid, derivation_cid), reported by /v1/verify_receipt as field_bound. Returns the emem:cube: token plus the member emem:raster: tokens. This signs and persists the cube record and its members.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_band_raster","name":"Band raster: a field as a signed derivation","description":"Return a native-resolution Sentinel-2 window over a bounding box as a FIELD, not a set of points: the pixels become one content-addressed grid artifact (deterministic f32 encoding; fetch the bytes at the returned artifact url, Cache-Control immutable), and what the receipt attests is the DERIVATION, never a byte pipe. A persisted derivation record pins the chosen scene (id, asset, capture time, cloud cover), the recipe (band_raster@1), the grid georeferencing in the scene's UTM CRS, and best-effort per-cell anchors that bridge the artifact to existing signed facts; the receipt's FIELD preimage segment binds (aoi_cid, derivation_cid), reported by /v1/verify_receipt as field_bound. Bounds are refusals with the cap named: six raw S2 bands (B02/B03/B04/B08/B11/B12) and 512 px per side at native resolution (about 5.1 km at 10 m). Anchors never materialize a fact, so a cold AOI costs one scene read, nothing more. The artifact is evictable BY DESIGN: the record persists like any fact and pins everything needed to rebuild identical bytes, so eviction turns a dereference into a recompute, never a broken citation. Returns two tokens: emem:raster: (resolve with emem_raster_resolve) and the record's own emem:fact: handle. This signs and persists the derivation record. TERRAIN: pass band `copdem30m.elevation` (or `elevation` / `dem`) for a static Copernicus GLO-30 elevation field via the dem_raster@1 path — no scene selection, no cloud, EPSG:4326 grid; a bbox crossing a 1-degree DEM tile edge is refused (single-tile only) and open ocean has no tile. EMBEDDING (WB-5): pass an encoder band (geotessera etc.) for a MULTI-CHANNEL embedding field via embedding_raster@1 — a signed N-D vector per cell (geotessera = 128-D) packed into one artifact, so a client-side per-cell embedding fan-out becomes one citeable token; every filled cell is anchored to its real signed encoder fact; grid capped at 256 cells at the 0.1-degree native step.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_bands","name":"Active band ontology","description":"Active band ontology (offsets, dims, tempo, privacy).","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_benchmark","name":"Hand-verified eval items for agent grading","description":"Hand-verified evaluation items for grading an agent against the responder. Returns {items[], grader_url}. Submit answers (cell64 or fact_cid per item) to POST /v1/benchmark/grade for per-item scores. Items today: elevation recall, NDVI, find_similar neighbours.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_burn_severity","name":"Burn severity (dNBR, Key & Benson) from pre/post-fire NBR","description":"Compute the differenced Normalized Burn Ratio (dNBR = NBR_pre − NBR_post; Key & Benson 2006) and map it to the USGS burn-severity classes (unburned / low / moderate-low / moderate-high / high). Supply `nbr_pre` + `nbr_post` (pin the scenes bracketing the fire date) for a correct result, or omit both to use the two most-recent stored `indices.nbr` scenes (older=pre, newer=post) as a coarse estimate. The result is signed; the receipt cites the NBR fact_cids it read from the shared memory.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_capabilities","name":"Cached upstream capability snapshot","description":"Live capability snapshot of the responder's GPU sidecar — extensions[] (e.g. gpu, clay-v1.5, prithvi-eo2), cuda_available, models_loaded[], healthy, last_polled_unix_s. Refreshed every 30 s by a background poller; reads are constant-time.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_cell_geojson","name":"Cell polygon as GeoJSON","description":"Cell polygon as a native MCP EmbeddedResource (mimeType application/geo+json). Properties carry centre lat/lng, bbox, approx size in metres, and the 8-cell neighbourhood — drop straight into Mapbox / Leaflet / Deck.gl / QGIS without a GIS pipeline.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_cell_scene_rgb","name":"Sentinel-2 true-colour thumbnail (PNG)","description":"True-colour Sentinel-2 L2A RGB thumbnail centred on a cell. PNG returned as a native MCP ImageContent block (mimeType image/png). Pure-Rust pipeline: STAC search + HTTP-Range COG reads + 2-98 percentile stretch + PNG encode.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_cells_in_bbox","name":"Enumerate the cell64s in a bounding box, paged","description":"Enumerate every cell64 whose centre falls in a bounding box, paged, in stable row-major order (north row first, then west column first). Pure geometry: it reads no facts and signs no receipt, because the answer is a deterministic function of the bbox and the active grid that anyone can reproduce. It walks the integer lat/lng grid directly, so it never skips or double-counts a cell the way a float-stepped lattice does. Returns `cells`, the exact `total`, and `next_cursor` (null when exhausted). This is the paging loop as emem's job instead of every client reimplementing a lattice; a London-scale AOI is tens of thousands of cells, so page it. page_size defaults 1024, caps at 4096.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_change_attribution","name":"Change attribution ledger: why did this place's readout move","description":"The first runnable surface of the change decomposition Δz = Δ_env + Δ_sensor + Δ_geo + Δ_encoder + ε: a per-term evidence LEDGER for the readout change at a cell, with NO numeric split. `observed` carries the Tessera year-over-year embedding change. `terms.env` carries label-free index pairs (NDVI, NBR, NDWI) with raw deltas and both fact cids, evidence a future estimator would read. `terms.sensor` records what each visit was observed through (source scheme and scene id per band) and whether that path changed. `terms.geo` is declared not estimated (no registration-residual surface exists). `terms.encoder` is pinned by construction: both vintages are slices of one signed multi-year fact under one recipe, named by fn_key. `terms.noise` reports the S2 scene-classification class per visit, so a cloud flip is visible. `split` is null and `attribution_note` says why: splitting a delta numerically needs a calibrated cross-encoder, cross-sensor stability model this responder does not have, and inventing magnitudes would fabricate the exact confusion the decomposition exists to prevent. The ledger persists: each run stores itself as a derivative fact (band change_attribution.ledger, parents = every fact read) and the response returns its own emem:fact: token under ledger_fact, so an attribution is cited and dereferenced like any reading. The receipt binds every input fact cid plus the stored ledger cid. Bands read cold may materialize, so this signs and persists facts.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_compare","name":"Compare two cells (cosine + scalar deltas)","description":"Compare two cells: cosine similarity over shared vector bands + per-band scalar deltas.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_compare_bands","name":"Compare two bands at one cell","description":"Compare two bands at the same cell. Scalar pair → metric=delta, value=b-a. Vector pair (equal dim) → metric=cosine + per-dim delta. Returns a signed receipt naming both source fact CIDs.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_compare_same_doy","name":"Compare a band at the same day-of-year across years","description":"Compare a band at the SAME day-of-year across several years, the honest way to measure year-over-year change on a seasonal band. For each year it finds the signed facts bracketing the target day-of-year and linearly interpolates to it, and EXCLUDES years that cannot be bracketed (with a typed reason) rather than extrapolating. This is the primitive the phenology advisory on emem_diff points at: comparing a seasonal band at two different days-of-year mixes phenology with real change (the '4 prospered / 0 stressed' trap), so comparing at one fixed DOY makes a year-over-year delta change rather than season. Interpolated values are model-derived, not directly signed; the bracketing fact_cids are recoverable via emem_trajectory.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_corpus_state_stats","name":"Signed snapshot of corpus liveness","description":"Signed snapshot of corpus liveness: distinct_cells, distinct_bands, facts_scanned, top per-band counts, manifest CIDs. Same payload that backs /v1/stream's corpus.state tick (signed). Use this for a one-shot poll instead of holding an SSE connection.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_coverage_map","name":"Coverage map (SVG image)","description":"Live SVG render of the responder's corpus density, returned as a proper MCP EmbeddedResource content block (image/svg+xml) — multimodal MCP agents can render it natively.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_coverage_matrix","name":"Per-band live status & history bounds","description":"Per-band live status — what data is alive AND auto-materializable, with history bounds, tempo cadence, and the responder pubkey that signs the band.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_cube_resolve","name":"Dereference an emem:cube: field-over-time token","description":"Resolve emem:cube:<aoi_cid>:<band>:<tslot_lo>..<tslot_hi>:<derivation_cid> back to its signed cube record and the ordered member emem:raster: tokens. Same fail-closed rule as emem_raster_resolve: the cid must be a band_cube@1 derivation, the token's aoi_cid, band, and tslot range must each match the signed record, and cube_cid is recomputed from the record's members so an altered membership is refused (typed 409), not silently served. Returns the full record plus a member_tokens list you resolve independently with emem_raster_resolve or batch through resolve_many; each member's artifact is at GET /v1/artifacts/{cid}, immutable. The receipt binds (aoi_cid, derivation_cid) through the FIELD preimage segment.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_data_availability","name":"Per-band temporal coverage catalog","description":"Temporal catalog: for every materializable band the upstream-of-record window the data genuinely covers, the temporal `kind` (static | annual_snapshot | annual_stack | time_series | now_only | per_release), tempo seconds, upstream wire path, and whether `emem_backfill` is meaningful.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_deforestation_alert","name":"Deforestation alert proxy (NDVI drop + embedding change)","description":"Composite deforestation-alert score: `alert_score = 0.5·clamp01(ndvi_drop/0.30) + 0.5·clamp01(embedding_change/0.20)`, where `ndvi_drop = max(0, ndvi_modis_baseline − ndvi_now)` and `embedding_change = 1 − cos(tessera_latest, tessera_prev)`. Each half degrades INDEPENDENTLY and honestly: if a band is missing, that half is dropped AND the output is renamed so a half-score can never be mistaken for the full composite. If NEITHER half is computable the response is a signed `inconclusive` carrying no number. Every response also carries a machine-readable `degraded` boolean plus `degraded_reason` (closed set: `embedding_half_unavailable`, `ndvi_half_unavailable`, `no_inputs`) and `degraded_message`, so a caller gates on the flag instead of parsing prose.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_derive","name":"Register your own derivation over emem facts","description":"Register a value YOU computed from facts this responder holds, and get back a citeable `emem:fact:` token whose lineage terminates in emem-signed measurements. The registered fact names its parents by CID, so a stranger walks the DAG down to signed sensor data instead of trusting your summary. Requires an ed25519 `attester` block. What the responder signs is narrow and it says so on the response: that YOU submitted this derivation, over these parents, at this time, and it stored it. NOT that the value is true. Algebra: derive.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"emem_derive_list","name":"List one attester's registered derivations","description":"List the derivations registered by one ed25519 key, optionally filtered to a cell (and then a band). The explicit opt-in read for caller-registered derivatives: they hold no canonical key, so no default read path returns them, and this is the only way to enumerate one rather than resolve it by token.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_diff","name":"Signed delta between two tslots","description":"Compute a DerivativeFact (delta) between a band's values at two tslots. Algebra: diff. For a time-varying band the response also carries an unsigned `phenology` advisory: the day-of-year of each tslot, their gap, and a `caution` when the two dates sit at different points in the seasonal cycle, because that delta mixes phenology with real change (the '4 prospered / 0 stressed' trap). It surfaces the bias rather than rejecting the call; the advisory never enters the receipt.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_echo_verify","name":"Check a value against the fact it cites, before you publish it","description":"Grade a value you are about to emit against the signed fact your citation points at. Returns `matches` and, when it does not, the `drift` between what you were about to say and what emem holds. This is the step that turns a transcription error into a caught event instead of a silent wrong number: a model that resolves a fact correctly can still retype `0.2411` for `0.241103`, and nothing else in the loop notices. Algebra: verify.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_edges_recall","name":"Recall temporal knowledge-graph edges","description":"Read temporal knowledge-graph edges (subj --pred--> obj, valid over [valid_from, valid_to)), bi-temporally filtered, in EITHER direction. Forward (`subj`, direction=\"out\", the default): edges originating at a subject fact. Reverse (`obj`, direction=\"in\"): edges pointing AT a fact — what disagrees-with / supersedes / relates-to it. Returns a signed list of edges plus the distinct neighbour fact CIDs (`objs` for out, `subjs` for in); the receipt commits the returned edge CIDs into its signature preimage.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_elevation","name":"Coherent elevation across Cop-DEM + GMRT + WorldCover","description":"One-shot elevation answer that fuses Cop-DEM 30 m (land), GMRT (ocean topobathy), and ESA WorldCover (water mask) into a single signed scalar at a place or coordinate. Returns `elevation_m`, the source actually used, and a `coherence_note` when the two surfaces disagree at the coast.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_embedding_centroid","name":"Embedding centroid — mean-pooled GeoTessera vector for a region","description":"Mean-pool the 128-D GeoTessera embedding over a region's cells: centroid = (1/N) Σ v_i, plus the L2-normalised centroid and a content-addressed centroid_cid. The building block region_similarity composes. Region is {place} | {polygon_bbox} | {cells}. NaN dims are averaged over their finite contributors. CPU-only.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_embedding_diversity","name":"Embedding diversity — landscape heterogeneity over a region","description":"Quantify how varied a region's landscape is: diversity = (1/(N(N-1))) Σ_{i<j} (1 − cosine(v_i, v_j)), the mean pairwise cosine distance over the region's GeoTessera embeddings. 0 = perfectly uniform; higher = more heterogeneous land cover (a determinantal-point-process / k-medoid diversity). Region is {place} | {polygon_bbox} | {cells}. CPU-only.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_entity","name":"Mint or get a canonical object identity","description":"Give a real-world object (a bridge, a farm plot, a river, a named place) a single, shared, content-addressed identity that any agent resolves the same way. Returns an `entity_token` (`emem:entity:<entity_cid>`) plus a signed receipt that attests how the reference resolved. Two agents that name the same object mint the SAME entity_cid; when a stable external id (Overture GERS / OSM) is known it dominates identity, so divergent labels for one real object still collapse to one id. This is the object-level antidote to referential drift: 'the damaged bridge near the river' becomes one canonical thing every model reasons about, not a phrase each model re-interprets.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_entity_link","name":"Attest that a phrasing/id denotes an existing object","description":"Record a signed equivalence: bind an alternate label or a stable external id (GERS / OSM / Wikidata) to an existing canonical object so future `emem_entity_resolve` calls on that phrasing converge to the same entity_cid. Builds the shared reference graph that keeps different agents' vocabularies pointing at one identity.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"emem_entity_resolve","name":"Resolve a phrase (or emem:entity: token) to a canonical object","description":"Converge a fuzzy phrasing onto the canonical object other agents already minted, so everyone co-refers to the same identity instead of re-minting divergent ones. Pass `text` (e.g. \"the collapsed span at the ford\") to get ranked existing candidates; pass `near` to narrow to a place; or pass an `emem:entity:` `token` to dereference it directly to the signed entity body. Read-only.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_errors","name":"Stable error code catalog","description":"Stable error code catalog.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_eudr_dds","name":"EUDR Due Diligence Statement — polygon-in, signed Annex II envelope out","description":"Produce a Due Diligence Statement per Regulation (EU) 2023/1115 for one or more plots. Each plot carries operator-supplied geometry (GeoJSON Polygon for >4 ha, Point for ≤4 ha non-cattle per Article 2(28)), country of production (ISO3), Combined Nomenclature code (HS-6+), and quantity in kg. The endpoint applies the regulation's 10 % canopy / 0.5 ha / 5 m height forest definition (Article 2(4)) using the EU Commission's expected JRC GFC2020 V3 baseline plus Hansen GFC v1.12 loss-year confirmation; Sims et al. 2025 driver attribution and RADD SAR fallback layer on when those connectors are wired (Absence today). The response is an Annex II-shaped envelope with per-plot verdict (pass/fail/not_in_scope/indeterminate/below_mmu), failing-cell fraction, and signed fact CIDs for every per-cell verdict — operators quote them in the company's Article 12 record. Article 9(1)(b) legality (land tenure, FPIC, country-of-origin laws) is structurally out of EO scope; the response carries an explicit `legality_disclaimer` for that reason.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_explain_algorithm","name":"One-algorithm drill-down (formula + inputs + citation)","description":"Per-key drill-down on a single composition recipe — full body (kind, inputs, formula, output, citation, references) for ONE algorithm key. Companion to `emem_algorithms` (which is the catalog).","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_fetch","name":"Resolve a fact by content-address (CID)","description":"Fetch a fact by its content-address (CID). Returns the full signed Primary or Absence fact, the same body served by REST `/v1/facts/{cid}`. Closes the citation loop: any fact_cid surfaced by recall, materialize, attest, or verify can be re-resolved by another agent without REST.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_field_boundaries","name":"Per-field agricultural boundaries (Fields of The World)","description":"Per-field agricultural-boundary polygons from the Fields of The World global product (~3.17B fields, 241 countries, 10 m resolution, CC-BY-4.0). Returns a GeoJSON FeatureCollection with the polygon geometries, FIBOA-compatible properties, and a planar `area_m2` per field — plus provenance (source CID, provider URL, license, attribution).","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_find_similar","name":"k-NN over the corpus by embedding","description":"k-NN over the corpus by cell embedding or inline vector.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_fleet","name":"Satellite / sensor lineage per band","description":"Per-band satellite-and-sensor fleet inventory — names the upstream platform (e.g. Sentinel-2A/B, MODIS Aqua/Terra, Landsat-8/9), revisit cadence, native resolution, and license for every materialized band. Lets an agent attribute imagery products correctly and pick the right band when revisit cadence matters.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_forest","name":"Forest signals (Hansen GFC + ESA WorldCover)","description":"Recall the signed forest facts at a place's cell64: Hansen Global Forest Change (tree cover 2000 baseline + year-of-loss) + ESA WorldCover 2021 land class, attested on a miss; each carries a citeable fact_cid.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_functions","name":"Active function registry","description":"Active function registry (derivation recipes).","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_grid_info","name":"Active grid encoding","description":"Active grid encoding: cell64 ground resolution, lat/lng axis sizes, DGGS lineage.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_heat_solve","name":"2-D heat-equation forecast (urban LST evolution)","description":"Forward-step 2-D explicit finite-difference solver for the heat equation ∂u/∂t = α∇²u over a 3×3 cell stencil centred on `cell`. Reads `modis.lst_day_8day` (Land Surface Temperature) at the centre and 8 cell64 neighbours, integrates N hours ahead under a CFL-stable timestep, returns a signed forecast. Real PDE rollout, not a decay-scoring heuristic.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_hunt","name":"Hunter mode — find event hotspots over a region","description":"Event-discovery sweep: pick an event keyword (algal_bloom, deforestation, flood_extent, wildfire, urban_heat_island, methane_plume, landslide, drought, soil_salinity, crop_stress, water_turbidity, oil_slick) plus a region (free-text name or polygon_bbox). The responder geocodes the region, fans out across up to 32 sampled cells, recalls each event's primary scalar input band, and returns the top 8 hotspots ranked by that scalar, each an attested entry in the shared memory carrying its cell64, lat/lng, the recalled value, a fact_cid for citation, and a scene.png URL. Bypass for free-text input is `emem_ask` (the classifier in /v1/ask routes \"find X in Y\" questions to the same hunter path).","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_intent","name":"Intent-routed planner","description":"Submit a typed Intent; receive a plan or executed result.","tags":["plan","L0"],"inputModes":null,"outputModes":null},{"id":"emem_jepa_predict","name":"Constrained JEPA-pattern next-month NDVI predictor","description":"Predict next-month NDVI at a cell using a constrained JEPA-pattern AR(2) seasonal predictor. Reads up to 24 past months of `indices.ndvi`, fits a closed-form predictor `y_{t+1} = α·(lag-12 NDVI or recent mean) + β·(last + slope) + γ·recent_mean`, returns the prediction clamped to NDVI's physical range. Coefficients (α=0.6, β=0.3, γ=0.1) are NOT learned, they're fixed from the agricultural-NDVI literature. For the learned multi-band dynamics head, see `emem_jepa_predict_v2` (jepa_temporal_predictor@2).","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_jepa_predict_v2","name":"Learned multi-band-scalar dynamics head (jepa_temporal_predictor@2)","description":"Predict the next-step value of 4 environmental scalars at a cell (`indices.ndvi`, `modis.lst_day_8day`, `modis.lst_night_8day`, `cams.pm25`) using a small learned dynamics MLP. Reads up to K=6 most-recent attested lags per band, runs them through an ONNX dynamics head (~200k params, CPU-fast), and returns a per-band {value, confidence, n_real_lags, via}. The receipt's `model` block carries `model_id`, `version`, `blake2b_hex` (model_cid), training/validation provenance, a top-level `skill_vs_persistence` block, and `honesty_warnings`, flagging `untrained_baseline` when the artifact is the zero-init sentinel and `NEGATIVE_SKILL` when the learned model is worse than persistence on real held-out NDVI. When the model does not beat persistence, bands with a real lag are returned from that lag tagged `via:persistence_fallback_negative_skill` (bands with no real lag fall back to labelled climatology). Distinct from v1 (`emem_jepa_predict`) which returns a single NDVI scalar via closed-form coefficients.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_locate","name":"Resolve place to cell64 + band inventory","description":"Mint the canonical, vendor-neutral address (cell64) for a real-world place: the shared spatial identity every agent resolves to identically, so two models refer to the same ground instead of two descriptions of it. Also returns the topic-grouped inventory of bands and algorithms recallable there. For a first-class OBJECT identity (a bridge, a plot, a named place) rather than a raw cell, use emem_entity.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_log_consistency","name":"Transparency log consistency proof","description":"Return an RFC 6962 consistency proof that the tree of size `first` is an append-only prefix of size `second` (defaults to the current size). This is the append-only guarantee: it catches a responder that rewrites or forks history.","tags":["verify","L1"],"inputModes":null,"outputModes":null},{"id":"emem_log_inclusion","name":"Transparency log inclusion proof","description":"Return an RFC 6962 inclusion (audit) proof that a log entry is committed under the current signed tree head. Verify offline: the audit path re-derives the STH root from the entry's leaf hash.","tags":["verify","L1"],"inputModes":null,"outputModes":null},{"id":"emem_log_sth","name":"Transparency log signed tree head","description":"Fetch the responder-signed tree head (STH) over the whole append-only attestation log: {tree_size, root_b32, signed_at, responder_pubkey_b32, signature_b32}. The signature is ed25519 over a domain-separated preimage, verifiable offline.","tags":["verify","L1"],"inputModes":null,"outputModes":null},{"id":"emem_log_witnesses","name":"Transparency log witness co-signatures","description":"List witness co-signatures recorded for tree heads — independent parties that counter-signed a (tree_size, root) claim under their own ed25519 key. Co-signatures let a client detect split-view equivocation. Empty until witnesses submit (submission is a signed write, done off-MCP via POST /v1/log/witness).","tags":["verify","L1"],"inputModes":null,"outputModes":null},{"id":"emem_lst","name":"Land surface temperature (MODIS day + night)","description":"Recall the signed MODIS land surface temperature facts (day-8day + night-8day composites, 1 km native) at a place's cell64, attesting on a miss; each carries a citeable fact_cid.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_manifests","name":"Active manifest CIDs","description":"Active manifest CIDs (bands / functions / sources / schema).","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_materializers","name":"Auto-fetch registry (per-band materializers)","description":"Auto-fetch registry: which bands the responder will materialize on a recall miss, the upstream provider, license, value shape, and history bounds.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_bundle","name":"Compose a signed multi-fact memory bundle","description":"Compose N (cell, band, tslot?) triples into ONE signed envelope. Each triple runs through the standard auto-materialize recall path; the resulting fact_cids are bundled into a content-addressed envelope and the responder signs over the full receipt. The composed `bundle_token` is `emem:bundle:<bundle_cid>`, a single rebindable string that cites the whole set. Algebra: merge.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_bundle_resolve","name":"Dereference a memory_bundle token","description":"Parse a `emem:bundle:<bundle_cid>` token and return the signed bundle envelope: every citation (cell, band, resolved_tslot, fact_cid, memory_token), the receipt, the responder pubkey, and the deduped flat cells[] / fact_cids[] arrays. Returns 404 with a typed code when the responder does not hold the bundle.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_contradictions","name":"Scan for multi-attester disagreement","description":"Surface where the corpus DISAGREES with itself (algebra: competing evidence). When two or more independent sources signed different values for the same place + band + time, this returns that disagreement with a 0–1 severity score and citations to every disputed fact, instead of silently picking one value and hiding the conflict. The opposite of a confident single answer: it tells you when not to trust one.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_search","name":"emem_memory_search — semantic search over /memories/* files","description":"Semantic search over /memories/* file contents using BGE-base-en-v1.5 (768-D, L2-normalised) backed by a Lance partition (`memory_text_index_d768.lance`). Matches paraphrases — \"rainfall in March\" finds \"precipitation observed in spring\" without an exact substring match. Returns ranked hits with similarity in [0,1], 200-char snippets around the best-matching chunk, and the signing receipt's path / file_cid / signed_at / attester_pubkey_b32 fields. Filters: `kind`, `path_prefix`, `attester_pubkey_b32`. Falls back to a brute-force scan (slower but correct) when the index is empty or `EMEM_DISABLE_LANCE=1` is set; the `via` field of the response reports which path was taken.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_token","name":"Compose a memory_token citation handle","description":"Mint a citation handle, `emem:fact:<cell64>:<fact_cid>` (or `:<state_cid>`), that any agent or LLM resolves to the byte-identical signed object. The antidote to referential drift on the value side: hand this one string to another agent instead of re-describing the fact. Validates both components are non-empty and free of the `:` separator. Algebra: cite.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_memory_token_resolve","name":"Dereference a memory_token in one round-trip","description":"Parse a `emem:fact:<cell64>:<fact_cid>` citation handle and return the signed fact body the cid binds. Saves the agent from string-splitting the token and chaining `GET /v1/facts/<cid>` manually. Algebra: resolve.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_ndvi","name":"NDVI at a place (one-shot, polygon-aware)","description":"Recall the signed Sentinel-2 NDVI fact (indices.ndvi, 10 m native) at a place's canonical cell64, attesting it into the shared memory on a miss. Composes locate → cell64 → recall in one call; the value returns with its citeable fact_cid.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_neighborhood_consistency","name":"Neighbourhood consistency / spatial outlier (GeoTessera vs 8 neighbours)","description":"Score how much a cell looks like its surroundings: consistency = (1/8) Σ cosine(centre, neighbour_i) over the 8 immediate cell64 neighbours, plus outlier_score = 1 − consistency. High consistency = the cell blends in (Tobler's First Law); high outlier_score = it stands out — an edge, a fresh clearing, a built patch in farmland. CPU-only GeoTessera embeddings.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_query_region","name":"Aggregate facts over a region","description":"Query facts over a region (single cell or list of cells), optionally aggregated per band.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_raster_bundle","name":"Raster bundle: bind N field tokens into one citeable manifest","description":"Mint an emem:rasterset: token: a signed manifest binding 2..64 already-minted emem:raster: field tokens (any mix of band_raster / s2_median_composite / dem_raster / embedding_raster) into ONE citeable thing. The composition primitive a world model or a compliance report needs when it must cite one token that points at every signed layer at once - the RGB ground composites, the DEM geometry, the encoder embedding field - so the report points at the world and the world points back at each signed layer. Unlike emem_band_cube (which MINTS members by fanning one band across dates), this BUNDLES existing tokens across bands and types: it is the raster analogue of a memory bundle and the cross-band analogue of a cube. It mints no new pixels - each member resolves and re-derives on its own, and the bundle's lineage terminates in each member's own derivation. bundle_cid = blake3 of the ordered member derivation cids (plus purpose), so the same ordered set always names the same bundle; resolve recomputes it and refuses an altered or forged membership. A member that is not a live raster-shaped derivation fails the whole mint by name. This signs and persists the manifest.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_raster_bundle_resolve","name":"Dereference an emem:rasterset: bundle token","description":"Resolve emem:rasterset:<bundle_cid>:<derivation_cid> back to its signed manifest and verify it. Fail-closed like every field-token resolve: the cid must be a raster_bundle@1 derivation, bundle_cid is recomputed from the record's ordered members and matched against BOTH the token and the record (any mismatch is a typed 409, refusing an altered or forged membership), and every member emem:raster: token is re-verified as a live raster derivation. Returns the member list with a per-member resolves flag, so a stranger confirms the whole set is intact before trusting the world it names.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_raster_resolve","name":"Dereference an emem:raster: field token","description":"Resolve emem:raster:<aoi_cid>:<band>:<tslot>:<derivation_cid> back to its signed derivation record and the artifact's status. Every claim in the token binds to the signed record before anything dereferences, the same rule fact tokens follow: the cid must be a band_raster@1 derivation and the token's aoi_cid, band, and tslot must each match the record's own body, so a real derivation_cid cannot be passed off under a false area, band, or date (mismatch is a typed 409). The response carries the full record (scene pin, grid georeferencing, anchors) and the artifact url; bytes come from GET /v1/artifacts/{cid}, immutable. An evicted artifact is not an error: the record pins the rebuild, and calling emem_band_raster with the record's own bbox, band, and capture date re-derives identical bytes. The receipt binds (aoi_cid, derivation_cid) through the FIELD preimage segment.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_recall","name":"Recall facts at a cell (auto-materializes on miss)","description":"Read the signed facts at a canonical address (cell64); auto-materializes on a miss for any band with a registered materializer. A fact_cid names one signed attestation, so a recalled fact is citeable and re-verifiable rather than a paraphrase: resolving it anywhere returns those exact bytes. It is NOT a fingerprint of the observation. The digest covers the responder's key and the moment it signed, so two responders that measure the same thing mint different fact_cids and a cid resolves only at the responder that signed it; use emem_entity for identity that crosses responders. Pass `deterministic:true` (or a `provenance` class list) to keep only facts recomputable from the cited raw source, with no model or human in the loop. In the memory algebra this is ensure(cell, bands), not get: state what must exist and the responder reuses or materializes.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_recall_many","name":"Bulk recall across up to 256 cells","description":"Recall facts across a list of up to 256 cell64 strings in one signed envelope. Server fans out per-cell recalls in parallel, then aggregates the response. Auto-materializes any cell with a missing fact whose band has a registered materializer — same contract as emem_recall.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_recall_polygon","name":"Recall facts across a place's polygon","description":"Recall facts across every cell inside a place's polygon (single signed envelope). Closes the place-name-drift gap for wide features (parks, lakes, regions).","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_region_similarity","name":"Region similarity — cosine of two regions' mean GeoTessera embeddings","description":"Answer 'how alike are these two places?' Mean-pool the 128-D GeoTessera embedding across each region's cells to get a centroid, then return the cosine similarity in [-1,1] (+1 = identical landscape, 0 = unrelated). Each region is {place} | {polygon_bbox} | {cells}. CPU-fetched embeddings — no GPU sidecar needed. Surfaces how many cells in each region actually carried a vector (coverage).","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_rice_ch4","name":"Rice-paddy methane (IPCC 2019 Tier 2, Eq 5.1)","description":"Estimate seasonal CH4 emissions from rice cultivation per IPCC 2019 Refinement Eq 5.1: integrate the daily emission factor over the cultivation period with water-regime scaling (SFp pre-season, SFo organic amendment) and an optional Yan-2005 Q10 temperature modifier. `cultivation_period_days` and the regional `efc_kg_ch4_ha_day` (Table 5.11) are REQUIRED — the endpoint refuses to guess a global default because the regional EFc drives the magnitude (~30% bias if wrong). An NDWI series (supplied or read from stored `indices.ndwi`) informs the flooding-regime context.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_sar_forest_disturbance","name":"Sentinel-1 SAR forest-disturbance scout (cloud-penetrating)","description":"Cloud- and night-independent Sentinel-1 C-band confirmation of forest disturbance. Intact forest scatters VV strongly + stably (canopy volume scattering); clearing collapses that term so VV backscatter DROPS ~3-5 dB. Samples VV at a baseline-year July-1 anchor and the latest scene, reports `vv_drop_db = baseline − recent` and a `disturbed` flag when the drop ≥ 3 dB (Reiche et al. 2018, RSE 204:147). Both VV reads are signed Primary facts; the response cites both fact_cids. Honest `inconclusive` when either S1 vintage is unavailable. Source: Microsoft Planetary Computer sentinel-1-rtc (anonymous SAS — no requester-pays, no API key).","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_schema","name":"Active CDDL/JSON schema bundle","description":"Active CDDL/JSON schema bundle by CID.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_soil","name":"Soil profile (SoilGrids 0–30 cm: SOC, pH, texture)","description":"Recall the signed SoilGrids 250 m profile at a place's cell64 (SOC, pH, clay/sand/silt fractions, bulk density, nitrogen, all at 0–30 cm depth), attesting on a miss; each band carries a citeable fact_cid.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_sources","name":"Active source-connector registry","description":"Active source-connector registry (URL templates, providers, licenses).","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_spi","name":"Standardized Precipitation Index (McKee 1993) drought metric","description":"Compute the Standardized Precipitation Index (McKee et al. 1993) at a cell: fit a gamma distribution to the same-window precipitation-accumulation history, then standardize the current accumulation to a z-score and map it to a drought class (extreme/severe/moderate drought … normal … wet). Supply `precip_history_mm` + `current_accumulation_mm` directly, or omit them to read the stored `weather.precipitation_mm` trajectory and build the window accumulations server-side. `window_days` selects SPI-1 (30 d), SPI-3 (90 d, default), SPI-12 (360 d), etc. The result is signed; the receipt cites the precipitation fact_cids it read from the shared memory.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_state","name":"Read the place's state vector (single encoder OR full 1792-D cube)","description":"Get one dense numeric fingerprint that summarises everything known about a place, ready to feed into similarity search, a classifier, or clustering. Two views: `encoder` returns a single AI-model embedding (128-D Tessera, 1024-D Clay, 1024-D Prithvi); `cube` returns the full 1792-D vector concatenated across every band, with a per-band coverage manifest.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_state_diff","name":"Between-tslot state vector delta (residual + cosine)","description":"Vector delta between the same cell at two tslots: returns the per-element residual, its L2 norm (scalar change-magnitude), the cosine between the two source vectors (orientation drift), and both source fact CIDs so the agent can quote both attestations as evidence.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_state_multi","name":"Multi-encoder state at one cell (foundation fan-out)","description":"Get the place's fingerprint from several AI models at once (`geotessera`, `clay_v1`, `prithvi_eo2`, `galileo`) in one call, returned as a per-model map. Each model is tried independently; any that can't produce a vector here show up under `missing` with a reason instead of failing the whole request.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_temporal_route","name":"Plan a temporal recall recipe for a cell","description":"Turn a time-shaped question into a ready-to-run recall plan: it figures out WHICH bands to pull at WHICH past time windows (e.g. 'the year before the flood', 'last growing season', 'two vintages to compare') so you don't have to compute tslot offsets by hand. Returns the band + lookback + a `purpose` tag for each step. Algebra: valid(M, a): per-band validity from the physics decay kernel, cite_now versus fetch_for_intent.","tags":["plan","L0"],"inputModes":null,"outputModes":null},{"id":"emem_terrain","name":"Terrain triad — slope + ruggedness + topographic position from DEM","description":"Compute three standard DEM terrain indices from one 3×3 Copernicus-DEM (copdem30m.elevation_mean) neighbourhood at a cell: Horn (1981) slope in degrees, Riley (1999) Terrain Ruggedness Index (TRI = sqrt(Σ(Z_centre−Z_i)²)), and Weiss (2001) Topographic Position Index (TPI = Z_centre − mean(neighbours); positive = ridge, negative = valley). The 8 neighbour cell64s are derived by perturbing the cell's lat/lng one cell pitch per axis; the east-west ground spacing is cos(lat)-corrected. Each result is signed; the receipt cites the elevation fact_cids read from the shared memory.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_tools","name":"What tools exist here, and when to reach for each","description":"The map of emem's tool surface, and the only tool you need to find the rest. Returns the working loop in the order you walk it (name a thing, ground it, cite it, resolve it, verify it, check for drift), then every other tool grouped by the question it answers, each with its one-line trigger. Pass `name` to get one tool's full input schema and a runnable example, so you can use a tool without loading all of the descriptors into context. This endpoint advertises the core loop only; the Earth-observation, search, embedding and log tools are catalogued here and remain callable by name.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_topics","name":"Topic-grouped band + algorithm registry","description":"Topic-grouped registry of every band and algorithm at this responder, plus visual surfaces and the `declared_but_no_materializer_at_this_responder` block (cube slots reserved without a live connector). Single source of truth shared with `/v1/locate`'s `data_at_this_cell` block.","tags":["introspect","L0"],"inputModes":null,"outputModes":null},{"id":"emem_trajectory","name":"Time series for one (cell, band)","description":"Time series for one (cell, band) over an inclusive [start, end] tslot window. Returns only what's already attested; it does NOT trigger materialization. For historical backfill use `emem_backfill`.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_triple_consensus","name":"Clay+Prithvi+Tessera change-consensus ensemble","description":"Three-encoder change ensemble: compute the cosine change between the two most-recent DISTINCT vintages for each of the Clay, Prithvi, and Tessera embeddings at the cell, then vote each encoder's change against `consensus_threshold` (registry default 0.15). Returns each encoder's change magnitude, its vote, and the consensus verdict (how many of the three agree change happened). Two caveats ride every response. First, the gate is NOT calibrated per encoder: 0.15 is a threshold for spectral change, applied unchanged to cosine distances in three embedding spaces with different scales, and the deployed Prithvi checkpoint's change tops out near 0.1155, under the gate. Prithvi therefore never votes, `all_three` is arithmetically unreachable, and `two_of_three` means Clay plus Tessera; read `encoders_used[].change` per encoder instead of the vote, and see the `gate_calibration` field. Second, this tool MATERIALIZES a missing prior vintage, so despite its Read category it signs and persists facts and spends GPU time. Degrades to a signed `inconclusive` when the GPU sidecar is unreachable or a cell lacks two distinct vintages for the encoders. The response carries a machine-readable `degraded` boolean, a `degraded_reason` (closed set: `gpu_sidecar_unavailable`, `single_vintage`, `outside_coverage`, `no_finite_overlap`, `recall_failed`, `partial_consensus_N_of_3`, `insufficient_encoders`), and `degraded_message`; each `encoders_absent[]` entry also carries its own `reason_code`. A 2-of-3 result reports `degraded:true` even though it still carries a real ensemble number. This is an experiment over model outputs: each leg carries a `model_output` caution (learned representation, not a measurement), so corroborate with a deterministic band before load-bearing use.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_verify","name":"Verify a structured claim against a cell","description":"Verify a structured claim against a cell's facts. Returns verdict + evidence CIDs + signed receipt.","tags":["verify","L1"],"inputModes":null,"outputModes":null},{"id":"emem_verify_receipt","name":"Server-side ed25519 receipt verifier","description":"Verify a signed receipt envelope server-side: recomputes the canonical preimage (preimage v1: tagged, length-prefixed segments; receipts without `preimage_version` verify under the legacy `request_id | served_at | primitive | cells, | fact_cids,` concatenation), runs ed25519 over the embedded pubkey + signature, and returns `{valid, reason, pubkey_b32}`. Use when the in-browser /verify path is blocked (CDN offline, agent runtime has no crypto) or when you want a server-side audit of a third-party receipt. Algebra: verify.","tags":["verify","L1"],"inputModes":null,"outputModes":null},{"id":"emem_water","name":"Surface water (JRC GSW recurrence + S1 backscatter)","description":"Recall the signed surface-water facts at a place's cell64: JRC Global Surface Water recurrence (1984–2021) + Sentinel-1 SAR backscatter (current), attested on a miss and citeable by fact_cid. The pair detects standing water through clouds.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_wave_solve","name":"1-D shallow-water swell propagation to coast","description":"Forward-step 1-D explicit finite-difference solver for the shallow-water wave equation ∂²u/∂t² = c²∂²u/∂x² with c² = g·h, where depth h comes from `gmrt.topobathy_mean` along the seaward gradient. Models how an offshore swell of height H_s and period T propagates toward `coastal_cell`. Returns a signed forecast of arrival height + time + depth + phase-speed profiles, all under a CFL-stable timestep; the receipt cites the depth facts read from the shared memory.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"emem_weather","name":"Current weather snapshot (temperature, cloud, precip, wind)","description":"Recall the signed met.no/CAMS weather facts at a place's cell64 (2 m temperature + total cloud cover + precipitation + 10 m wind speed), attesting on a miss; each value carries a citeable fact_cid.","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"memory_create","name":"memory_create — write a memory file (overwrite if exists)","description":"Write a memory file at `/memories/<path>` with the supplied `file_text`. Overwrites if the file exists. Persists to sled, content-addresses the bytes (`file_cid`), and signs the write so the operation carries a verifiable receipt. Mirrors the `create` verb in Anthropic's context-management-2025-06-27 memory tool spec.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_delete","name":"memory_delete — remove a memory file or directory","description":"Delete a memory file at `/memories/<path>`. When the path ends with `/`, every file beneath the directory is removed. Updates the path index but leaves prior content-addressed blobs in place (the audit history is append-only). Mirrors the `delete` verb in Anthropic's context-management-2025-06-27 memory tool spec.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_insert","name":"memory_insert — insert at a given line","description":"Insert `new_str` after the given 1-indexed line in the named memory file. `insert_line: 0` inserts at the top. Writes a new `file_cid` and signs the receipt. Mirrors the `insert` verb in Anthropic's context-management-2025-06-27 memory tool spec.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_list_by_kind","name":"memory_list_by_kind — typed enumeration of memory files","description":"List memory files by their typed `kind` (episodic | semantic | procedural | resource). Optional path prefix narrows the scan; results are sorted by signed_at descending. The kind taxonomy follows the CoALA / LangMem / MIRIX agent-memory ontology: `episodic` = observations of events, `semantic` = durable learned facts, `procedural` = playbooks, `resource` = generic durable scratchpad (default for back-compat).","tags":["read","L0"],"inputModes":null,"outputModes":null},{"id":"memory_rename","name":"memory_rename — move a memory file","description":"Move (rename) a memory file from `old_path` to `new_path`. Both paths must stay under `/memories/`; `new_path` must not already exist. The file_cid is preserved (no re-sign) so the prior receipt still binds the bytes. Mirrors the `rename` verb in Anthropic's context-management-2025-06-27 memory tool spec.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_str_replace","name":"memory_str_replace — exact-string replacement in a memory file","description":"Replace `old_str` with `new_str` in the named memory file. Fails (no partial write) when `old_str` is absent or matches more than once. Writes a new content-addressed `file_cid` and signs the receipt. Mirrors the `str_replace` verb in Anthropic's context-management-2025-06-27 memory tool spec.","tags":["write","L0"],"inputModes":null,"outputModes":null},{"id":"memory_view","name":"memory_view — read file or directory listing","description":"Read the contents of a memory file at `/memories/<path>` or list a directory when the path ends with `/`. Optional `view_range: [start, end]` slices a 1-indexed inclusive line range out of the file. Mirrors the `view` verb in Anthropic's context-management-2025-06-27 memory tool spec.","tags":["read","L0"],"inputModes":null,"outputModes":null}],"skills_removed":[],"skills_changed":[],"fields_changed":[{"field":"name","before":null,"after":"emem"},{"field":"description","before":null,"after":"Shared, verifiable memory for AI agents that stops referential drift, the paraphrase side pinned by the token, the world-readout side reported by the change-attribution ledger (the numeric split is roadmap): one canonical, citeable identity per place (cell64), fact (fact_cid), and object (emem:entity:<entity_cid>), so different models reason from the same world object instead of divergent descriptions. Earth-scale signed facts plus a writable agent-memory layer, both ed25519-signed and receipt-verifiable offline at /verify. Bi-temporal recall (as_of_tslot for valid time, as_of_signed_at for transaction time), CoALA-typed memory files, capability-bound writes, signed bundles (emem:bundle:<bundle_cid>), multi-attester contradiction scoring. No API keys."},{"field":"version","before":null,"after":"1.2.1"},{"field":"protocolVersion","before":null,"after":"1.2.0"},{"field":"url","before":null,"after":"https://emem.dev/mcp"},{"field":"documentationUrl","before":null,"after":"https://emem.dev/agents.md"},{"field":"iconUrl","before":null,"after":"https://emem.dev/favicon.svg"},{"field":"preferredTransport","before":null,"after":"HTTP+JSON"},{"field":"supportsAuthenticatedExtendedCard","before":null,"after":false}],"other_changed":true,"is_empty":false,"human_summary":"added 102 skills · name ∅ → emem · description ∅ → Shared, verifiable memory for AI agents  · version ∅ → 1.2.1 · protocolVersion ∅ → 1.2.0 · url ∅ → https://emem.dev/mcp · documentationUrl ∅ → https://emem.dev/agents.md · iconUrl ∅ → https://emem.dev/favicon.svg · preferredTransport ∅ → HTTP+JSON · supportsAuthenticatedExtendedCard ∅ → False"}}]}