fleet-memory/hindsight-integrations/ai-sdk
Nicolò Boschi ea27ef95ec
fix: resolve all Dependabot security vulnerabilities (#486)
* fix: resolve all Dependabot security vulnerabilities

npm (package-lock.json):
- fast-xml-parser: 4.5.3 → 4.5.4 (critical entity encoding bypass + DoS)
- serialize-javascript: 6.0.2 → 7.0.4 (high RCE via RegExp/Date)
- minimatch: 3.1.2 → 3.1.5, 5.1.6 → 5.1.9, 9.0.5 → 9.0.9 (high ReDoS)
- ajv: 6.12.6 → 6.14.0, 8.17.1 → 8.18.0 (medium ReDoS with $data option)
- qs: 6.14.1 → 6.15.0 (low arrayLimit bypass DoS)
- rollup: 4.57.x → 4.59.0 in ai-sdk and openclaw integrations (high path traversal)

Python (uv.lock / pyproject.toml):
- cryptography: 46.0.3 → 46.0.5 (high subgroup attack on SECT curves)
- pillow: 12.0.0 → 12.1.1 (high out-of-bounds write in PSD loading)
- langchain-core: 1.2.7 → 1.2.17 (low SSRF in ChatOpenAI token counting)
- langsmith: 0.4.42 → 0.7.11 (medium SSRF via tracing header injection)
- protobuf: 6.33.1 → 6.33.5 (high JSON recursion depth bypass)

Rust (Cargo.lock):
- bytes: 1.11.0 → 1.11.1 in hindsight-clients/rust (medium integer overflow)

Remaining unfixable: diskcache <= 5.6.3 (no patched version available)

* fix: remove over-broad schema-utils ajv override that broke docs build

The 'schema-utils': {'ajv': '^8.18.0'} override was forcing schema-utils@3.x
(used by url-loader/file-loader with ajv-keywords@3.x) to use ajv@8.18.0.
In 8.18.0, internal property _formats was renamed to formats, breaking
ajv-keywords@3.x's _formatLimit.js which accesses ajv._formats.date.

Removing the broad override: schema-utils@4.3.3 (root level) already has
ajv@8.18.0 in its nested install from the prior npm update, while
schema-utils@3.x correctly falls back to the hoisted root ajv@6.14.0.
2026-03-04 13:14:50 +01:00
..
src feat: improve ai sdk tools (#394) 2026-02-18 13:06:03 +01:00
.gitignore feat: ai sdk integration (#299) 2026-02-04 20:25:59 +01:00
package-lock.json fix: resolve all Dependabot security vulnerabilities (#486) 2026-03-04 13:14:50 +01:00
package.json fix: resolve all Dependabot security vulnerabilities (#486) 2026-03-04 13:14:50 +01:00
README.md docs: add AI SDK integration documentation (#304) 2026-02-05 17:05:18 +01:00
tsconfig.json feat: ai sdk integration (#299) 2026-02-04 20:25:59 +01:00
vitest.config.ts feat: ai sdk integration (#299) 2026-02-04 20:25:59 +01:00

Hindsight Memory Integration for Vercel AI SDK

Give your AI agents persistent, human-like memory using Hindsight with the Vercel AI SDK.

Quick Start

npm install @vectorize-io/hindsight-ai-sdk @vectorize-io/hindsight-client ai zod
import { HindsightClient } from '@vectorize-io/hindsight-client';
import { createHindsightTools } from '@vectorize-io/hindsight-ai-sdk';
import { generateText } from 'ai';
import { anthropic } from '@ai-sdk/anthropic';

// 1. Initialize Hindsight client
const hindsightClient = new HindsightClient({
  apiUrl: 'http://localhost:8000',
});

// 2. Create memory tools
const tools = createHindsightTools({ client: hindsightClient });

// 3. Use with AI SDK
const result = await generateText({
  model: anthropic('claude-sonnet-4-20250514'),
  tools,
  system: `You have long-term memory. Use:
  - 'recall' to search past conversations
  - 'retain' to remember important information
  - 'reflect' to synthesize insights from memories`,
  prompt: 'Remember that Alice loves hiking and prefers spicy food',
});

console.log(result.text);

Features

Three Memory Tools: retain (store), recall (retrieve), and reflect (reason over memories) AI SDK 6 Native: Works with generateText, streamText, and ToolLoopAgent Multi-User Support: Dynamic bank IDs per call for multi-user scenarios Type-Safe: Full TypeScript support with Zod schemas Flexible Client: Works with the official TypeScript client or custom HTTP clients

Documentation

📖 Full Documentation

The complete documentation includes:

  • Detailed tool descriptions and parameters
  • Advanced usage patterns (streaming, multi-user, ToolLoopAgent)
  • HTTP client example (no dependencies)
  • TypeScript types and API reference
  • Best practices and system prompt examples

Running Hindsight Locally

# Install and run with embedded mode (no setup required)
uvx hindsight-embed@latest -p myapp daemon start

# The API will be available at http://localhost:8000

Examples

Full examples are available in the GitHub repository.

Support

License

MIT