About this project
dejavu-gates is a cross-session memory layer for AI coding agents. Agents repeat the same mistakes because they forget between sessions, and markdown rules do not fix that. This tool mechanically detects recurring tool-call failures (bash, read, edit, write, glob, grep) and promotes them into enforced gates: a reminder on the next attempt, a hard block on a same-session repeat offense.
One engine, many hosts. It runs as an OpenCode plugin and as a hook-handler CLI for Claude Code, Codex CLI, Gemini CLI, Cursor, Copilot CLI and Crush. Written in TypeScript and run with Bun, shipped as source with no build step.
How it works: a failing tool call gets a normalized signature (paths, numbers and hashes stripped), the pattern key is counted across sessions, and after 3 failures across 2 distinct sessions a gate is promoted. The next attempt receives a [dejavu] reminder with the call aborted; a retry that fails again triggers a hard block. Diagnostic commands stay remind-only, so the call runs and the reminder rides on the failing output as a NOTE once per session.
Design choices include: remind first and block only on repeat (pure blocking invites workarounds such as switching package managers); gate messages carry a CORRECTION and EVIDENCE rather than a bare prohibition; mechanical pattern keys only, with no LLM classification in the hot path; two scopes, repo-specific gates in the repository and agent-level habits in the user config; gates expire after 60 days without recurrence; and a recurrence-after-gate metric to check whether gates actually reduce repeats.
Enforcement has negative feedback. A gate that keeps recurring or keeps being explicitly bypassed demotes itself to watching and does not re-promote mechanically; a human can re-enforce it. Gates also heal: three consecutive successes matching an enforced gate retire it to watching, and a gate reminded many times with no reoffense retires as taught.
Safety and robustness details: only non-diagnostic bash commands can become blocking gates; file probes stay watching; signatures without residual identity may only watch; the hook CLI fails open, returning an empty decision and exit 0 on malformed payloads or internal errors. Secrets are scrubbed before persistence, terminal control characters are stripped, and stores are reconciled and repaired at init with corrupt files quarantined. Concurrency uses lockfiles with tmp+rename writes and retry on Windows errors, and the remind-to-block escalation chain is persisted on the gate so multiple windows and harnesses share it.
Installation is available via npx, native plugin channels for several harnesses, GitHub Packages, or from a clone with an installer script that merges hook entries idempotently into each harness config. Observability includes a doctor script, an analyze script, a /dejavu status command, and a debug environment variable.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.