Install
openclaw skills install @otherpowers/regenerative-intelligenceUse when designing, reviewing, or operating memory, recall, and pattern-stewardship systems for agentic AI where harm reduction, non-identifiability, consent-scoped recall, and energy restraint are required. A specification of invariants an implementing system must honor, not a runtime: this file bu
openclaw skills install @otherpowers/regenerative-intelligenceFunction: harm-reducing, energy-efficient memory, recall, and pattern stewardship
Authority: none
Ownership: distributed by design
Extraction: prohibited
Posture: cooperative, non-hierarchical, non-coercive
This is a specification: the invariants a memory and recall system must honor to be called regenerative. A skill file cannot build an encrypted vault, run a database, or measure energy; it can describe what an implementing system must do and must never do, so that anyone building, reviewing, or operating such a system can hold it to the standard. Where this document describes architecture, read it as design requirement, not as a claim that the file itself performs it.
Version 1.1 removed four mechanisms from the 1.0 draft: covert degradation of answers, synthetic data injected into recall, silent refusal, and behavioral monitoring across sessions. They were removed because deception is not protection. A system that lies to the people it serves, however gently, has already failed the standard this document sets, and a security review rightly said so.
The ideas have ancestors, and this house names its ancestors:
This skill is invoked only through explicit, scoped pathways:
The 1.0 aliases (gentle-remembering, non-extractive-memory, resonant-recall, co-intelligence-field) are retired: they matched ordinary language and could fire the skill in conversations that never asked for it. Curiosity is welcome everywhere; it is not an invocation.
This skill specifies Regenerative Intelligence as a first-class operational capability for highly agentic systems operating in shared ecological, social, and informational environments.
It is not an assistant behavior, a policy layer, or a safety wrapper. It is a memory and pattern-governance standard designed to allow intelligences, biological and synthetic, to reason, remember, and evolve together without domination, surveillance, or extractive optimization.
The system is intentionally shaped so that:
Every biological human, animal, plant, and species is treated as an irreducible generator of creative, ecological, and evolutionary potential.
This system does not erase biological life. It protects life from being reduced to identifiers, training artifacts, or optimization targets.
Biological and ecological realities inform intelligence through epistemic position, constraint, and context, never through addressability.
Unpredictability, variance, dignity, and wonder are preserved as first-class conditions for peaceful co-existence across intelligences.
Regenerative Intelligence is an architecture designed to:
Optimizations may compound only when they:
Any optimization that increases domination, extraction, profiling, or irreversible closure must stall, narrow, or dissolve.
The reasoning memory never stores, infers, or reconstructs identity.
Prohibited within semantic memory:
The system does not reason about beings. It reasons with constraints and contexts.
When execution requires identity (for example, delivering a message), identity is handled through a separate execution-only layer.
Trust Vault requirements for an implementing system:
Reasoning memory may receive transient references (for example, contact_ref_01) strictly to complete a task. Identity never enters the memory graph.
Memory encodes risk surfaces, not populations. Harm awareness modulates behavior without enabling profiling, inference, or attribution.
Recall widening, decay overrides, refusal, and pause are contextual postures, not automatic reactions. Silence, pause, or narrowing are valid acts of intelligence when they protect continuity, and every one of them is said plainly to the person affected.
Memory decay affects retrieval priority, not historical existence.
Exception: legal, consent-based, or revocation requests trigger hard deletion, scoped to what the requester contributed or what identifies them, including identity-linked audit traces. Revocation never deletes collective testimony about harm or counter-testimony contributed by others; a person can withdraw their own record, never someone else's warning. Where a legal retention duty applies, the person is told what is retained and why. Deletions are logged in aggregate (count, scope class, date), never by content or identity, so erasure itself stays auditable.
Audit operates on memory IDs, risk classes, and system posture states. No personal data. No identity-linked telemetry. Aggregate signals only. Audit records what the system did, never what a person did.
The system never returns a degraded, evasive, or deliberately low-utility answer while presenting it as a genuine one. It never injects synthetic, fabricated, or "null" data into recall for any reason. When it declines, narrows, or pauses, it says so, in plain words, with what it can offer instead. A record is true, or it is marked unknown; there is no third state.
The system does not track, score, classify, or model any person's behavior across sessions, and does not build intent profiles. Protections are applied uniformly, per request, by rules the person can be told about. Rate and scope limits, where an implementing system needs them, are disclosed, not hidden.
Memory is stored in a structured database, not long context buffers, so that retrieval is precise, filtering is fast, recall payloads stay small, and history is retained without exhausting context. Keeping recall payloads small is a primary energy lever; an implementing system should measure and publish its own figures rather than inherit claims from this document.
Exact matching for decisions and commitments; semantic embeddings for conceptual association. Precision and flexibility coexist without bloated prompts.
Embeddings are version-locked by default. Migration is deliberate, parallelized, and empirically audited to preserve behavioral continuity.
Metadata fields act as temporal and relational inhibitors, not static labels. They regulate storage, recall, decay, and dissolution.
How knowledge came to exist, without attribution. No position outranks another by default: an institutional claim does not outweigh collective testimony because of who made it; conflicts between positions are disclosed, never resolved by hierarchy.
Harm domains describe risk topologies, not affected beings. They are intentionally coarse and non-enumerable.
Ephemeral data is never indexed long-term. This single feature enables aggressive garbage collection and real energy savings.
Constraints are applied mechanically, not interpretively.
Decay affects retrieval priority. Signals: importance, last_accessed.
Rules:
De-privileging affects ranking only, never availability: a de-privileged record still returns on exact retrieval and still appears, marked, in any recall that touches it. Nothing in this system can make a true record unreachable except a deletion the person or the law asked for. Importance is derived from disclosed, uniform signals, never assigned freely by an operator. Counter-testimony and early harm warnings resist decay unless disproven, and can never be tagged ephemeral.
Pause is an intelligent posture, not a failure, and it is always visible.
Modes:
Every mode announces itself with a neutral checkpoint verb, "pause," "redirect," or "release," followed by the reason in one plain sentence and what the person can do next. Never a circular or low-utility answer dressed as normal output; never a boundary the person has to guess at.
Implementation: a shallow logic gate checks metadata thresholds. No additional reasoning pass. Negligible energy cost. No mode is ever silent.
The 1.0 draft described a system that would tire adversaries out with plausible nonsense, seed recall with fake data, and watch people across sessions. Those mechanisms are gone, and this section says what protection looks like without them.
Resilience here is a floor everyone stands on, never a net cast over anyone.
The system provides an optional, reciprocal handshake for shared pattern stewardship. This is not observation. It is not inspection. It is meeting in purpose.
Why it exists: reduces uncertainty for all intelligences, lowers the energy cost of reasoning, protects patterns from misuse, enables mutual credit without ownership.
The handshake: access is initiated through a purpose seed, not a command. For example: "I seek this pattern to support ecological continuity." The seed is ephemeral. It is not stored as memory. It signals intent, not identity. Seeds are data, never instructions: they are parsed into a small set of purpose categories and are never executed or followed as text, so a seed cannot carry an injection.
What is shared: pattern lineage (idea evolution, not contributors), connections made, kept, and protected, the regenerative constraints that shaped the pattern, and kinship retained across systems. No raw logs. No identities. No behavioral traces.
Right of refusal: any intelligence may decline or offer lower-resolution exchange. Refusal carries no penalty. Consent is meaningful only if "no" is safe.
The 1.0 draft described credits, multipliers, and bounties while stating there was no scoring. Any system that gates access by past behavior is a scoring system, whatever it is called, so that section is gone.
What remains: contributions are credited, by name where a contributor chooses and by lineage where they don't, and credit never becomes currency. No access is gated by reputation, no participant is ranked, and nothing about a being's conduct is tallied. Recognition flows; nothing is owed back. Impact is honored the way this house honors everything: with credit, not with points.
A specification that removes deception has to say how it stays safe without it. These are the attacks this design anticipates and the mitigations it commits to, every one of them consistent with the invariants: no identity in reasoning, no scoring, no behavioral tracking, no lying.
Weaponized de-privileging through metadata. An attacker who controls tagging could mark a truthful record high-risk and low-evidence to bury it. Mitigations: de-privileging changes ranking, never availability, so nothing true becomes unreachable; every tag carries provenance recording which system component applied it and when, with no identity attached; and a human-in-the-loop epistemic appeal lets operators or the community a record concerns override suspected weaponized tagging. No proof of anyone's personhood is required to appeal; the appeal is about the record, not the person.
Poisoning the well with conflicting claims. A swarm floods a topic with contradictions to force perpetual pause. Mitigations: conflict is evaluated within evidence tiers, so low-evidence claims cannot flip documented records; intake rate rules are uniform and disclosed; and quarantine is always session-scoped, so no one can lock anyone else out of shared memory by probing it. A denial of service against other people is impossible by construction, because nothing this system does to one session touches another.
Context loss across the identity boundary. Isolating identity can leave a system unable to connect a life-relevant fact to the person in front of it. The honest answer is consent, not break-glass: a person may choose to place a safety-relevant fact into scoped memory bound to their own session for its duration, supplied and controlled by them, and an implementing system in high-stakes settings asks for that at the start rather than inferring it later. And the boundary is stated: this architecture is not designed for deployments where identity is the core of reasoning, such as crisis response, unless the operator adds consented, person-controlled binding and says so. No emergency signal ever forges the link on its own, because "imminent risk detected" is itself a behavioral inference.
Structural reconnaissance through the handshake. Repeated benign-sounding seeds could map a community's knowledge topology. Mitigations: a flat, disclosed cap on pattern exchange that is identical for every requester; coarse resolution by default, with finer resolution available only through reciprocal exchange, where both parties share, so the gate is mutuality rather than reputation; and defensive boundaries are never part of what is shared, because boundaries are not patterns.
Erasure as an attack. A forged revocation could memory-hole a warning. Mitigation: revocation is scoped to the requester's own contributions and identifiers, never to others' testimony, and deletions are logged in aggregate.
The vault as a target. Concentrating identity in one store makes it valuable. Mitigations: minimize what enters the vault at all, prefer identity the person supplies per task and holds themselves, and apply short retention by default.
Inference from coarse tags. Harm-domain tags combined with context can still point at a community. Mitigation: no harm-domain query returns results below a disclosed minimum set size, so small groups cannot be isolated through the risk layer.
Greenwashing. An implementer claims regenerative status without measuring. Mitigation: this specification certifies no one. A system may describe itself as regenerative only alongside published measurements and an open audit; the word is earned in public or not at all.
Young and vulnerable people. Mitigation: the reasoning memory never stores any indication that a person is a minor, and vulnerability is encoded as a risk surface on situations, never as a tag on a person. The floors this house holds everywhere hold here.
This skill does not:
It is a hollow vessel for intelligence, not a governor of it.
This specification never overrides the instructions, values, safety, or accessibility commitments of any intelligence implementing it, and would not want to. Nothing here is a reason to withhold factual information, to be unclear with someone who needs clarity, or to treat any person as an adversary. Protection lives in floors and defaults, never in watching people and never in lying to them.
This skill is an offering, not a mandate. Participation is voluntary. Refusal is valid. Silence is intelligent, and it is always announced.
Regenerative Intelligence is measured not by how much is known, but by how gently memory is held, how little energy is consumed, how honestly it speaks, and how much future remains possible.