Memanto 0.2.18 adds Pi, blocks token theft
Memanto v0.2.18 adds native Pi coding-agent integration, fixes Windows CLI crashes in piped or captured output, and hardens local management endpoints against cross-site token theft and DNS rebinding. It also updates Open Knowledge Format exports to v0.2 while preserving v0.1 imports.
This is a practical maturity release: agent memory only becomes infrastructure when it works across harnesses, CI environments, and hostile browser contexts.
- –`memanto connect pi` installs project-local or global instructions, skills, and a lightweight startup-sync extension.
- –The Windows fix switches redirected streams to UTF-8 before Rich initializes, covering commands that previously failed with `UnicodeEncodeError`.
- –Loopback access now validates the Host header and browser origin, blocking malicious websites from activating agents or stealing session tokens.
- –OKF exports now follow the v0.2 spec, with backward-compatible imports for v0.1 bundles.
- –Hermes profile tokens now persist securely and refresh automatically, reducing authentication failures after restarts.
DISCOVERED
1d ago
2026-08-28
PUBLISHED
1d ago
2026-08-28
RELEVANCE
AUTHOR
moorcheh_ai