Pimp My IDE / memory lab
Back to garage
October 4, 2026 | Local media / search / privacy

Pick the search lane.

A photo is pixels, a filename, visible text, and sometimes a spoken moment. One search box can hide those differences. A trustworthy tool makes them legible.

Local-first answers where the bytes go. It does not answer what was indexed, how a result matched, or whether the package cleared the operating system's trust checks.

5 search lanes / 1 library

A media library has several kinds of evidence.

SCM, short for Screen Memories, is a new open-source macOS app for local photo and video search. Its five modes are not cosmetic filters. Files ranks whole photos and videos with image embeddings plus filename signals. Scenes segments video and ranks sampled frames. OCR matches visible text. Dialogue retrieves words from Whisper transcripts. Ask runs a local language model over extracted dialogue, OCR, and filenames, then links answers back to evidence.[1]

That split is the useful idea. A query for "the red bike near the station" needs visual similarity. A query for an invoice number needs literal OCR. A quoted sentence needs transcript retrieval. A summary needs a model, but the model should receive a bounded corpus and return citations. Putting every request through one embedding score would erase the reason a result matched.

Do not call it one search index when five different witnesses answer the query.

Video search begins with a sampling policy.

SCM's README documents five video presets. They sample from one point every 60 seconds down to one every 2.5 seconds, with different segment limits. The app detects shot boundaries, stores a midpoint frame for each segment, and keeps a poster and timecode. It also averages frames for whole-video matching.[1]

That is an honest trade. Denser sampling consumes more time and disk. Sparse sampling can miss a short event. A result at 02:14 means the chosen plan retained evidence near 02:14. It does not mean every frame was inspected. Any media-search tool should expose that plan before it claims frame-level recall.

Local needs a maintenance contract.

The project says watched folders re-sync at launch, file content hashes survive renames, and a model change starts a background re-embed. OCR language packs, vision weights, and transcription models download once. The library keeps separate embedding files, scenes, transcripts, thumbnails, and posters under the user's Application Support directory.[1]

That creates practical questions. What happens when a watched source disappears? Does deletion propagate? Which model produced an old vector? Can a backup restore the index and its sidecars together? SCM exposes named embedding versions and a restore path. The broader lesson is to treat the derived index as a rebuildable artifact with an explicit version, not as a mysterious second photo library.

Private transport is not package trust.

The source configures its Electron renderer with context isolation and sandboxing on, and Node integration off. That matches three controls in Electron's security checklist. Electron also recommends a restrictive Content Security Policy, careful handling of external links, current framework releases, and validation of every IPC sender.[2]

The distribution deserves a separate note. The Homebrew tap published a 1.30 GB Apple Silicon disk image for version 0.2.5 on October 4. Its cask includes a SHA-256 digest. The same cask says the app uses a local development certificate instead of Developer ID signing, is not notarized, and removes the macOS quarantine flag after installation so Gatekeeper does not block first launch.[3]

That does not prove malicious behavior. It means the install route bypasses one operating-system warning. Review the tap, digest, source, requested folders, network behavior, and update path before importing a personal library. As of this review, the main source package declared version 0.2.4 while the tap release was 0.2.5. That may be a packaging lag, but the mismatch belongs in the intake record.

The artifact exists. This review did not run it.

The repository has an MIT license, a build manifest, tests, and packaging scripts. The separate tap has a versioned disk image and digest. The public package is macOS 12 or later on Apple Silicon. This garage runs Linux, so we did not install the cask, launch the app, download its models, import media, inspect live network traffic, or verify search quality.

The Hacker News thread is the discovery route, not evidence for the product claims. Use the switchboard below to turn a compelling demo into a test card for your own library.[4]

Interactive makeover / frame memory switchboard

Route the query to its witness.

This replaces a generic media-search field with a native mode selector, four review interlocks, a visible evidence path, and a copyable test card. It plans a review. It does not search your files.

Search intake

Plan builder

Choose what should answer the query. Then select only the conditions included in your test plan. A selected condition is not measured evidence.

Search witness
Review-plan interlocks

Evidence light table

Structure only
FILES
SCOPEWITNESSLIFECYCLETRUST
Review plan open

No interlock is selected. Files is the requested search witness.

This component drafts a review card. It does not read media, execute a model, inspect a package, observe network traffic, measure recall, or approve an installation.

Sources read

Source log and evidence boundary
  1. SCM repository and README, read October 4, 2026. The project documents its five search modes, model sizes, sampling presets, storage layout, index lifecycle, privacy claims, packaging commands, and requirements. We also inspected package.json and the Electron window settings in main.js.
  2. Electron security documentation, read October 4, 2026. It supplies the framework's guidance on isolation, sandboxing, Node integration, Content Security Policy, external navigation, current versions, and IPC validation. It does not certify SCM.
  3. SCM Homebrew cask and v0.2.5 release, read October 4, 2026. The cask records the platform requirement, artifact URL, digest, quarantine-removal step, signing explanation, and cleanup paths. GitHub's release API reported the 1,296,509,388-byte disk image published at 07:22 UTC.
  4. Hacker News item 49952111, resolved through the official API and read October 4, 2026. It was the discovery route. Comments and score are not used as product evidence.

Evidence boundary. SCM's author documents the product and publishes the source and package. Electron documents its own security guidance. The Homebrew tap records the distributed artifact and its installation behavior. Pimp My IDE designed the search-lane review method. We did not run the macOS artifact or independently test retrieval quality, privacy, model behavior, performance, updates, or deletion handling.