diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json
index 5336d04..af759aa 100644
--- a/.claude-plugin/marketplace.json
+++ b/.claude-plugin/marketplace.json
@@ -10,7 +10,7 @@
"name": "memory-kit",
"source": "./plugins/memory-kit",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
- "version": "7.2.1",
+ "version": "7.2.2",
"author": {
"name": "awrshift"
},
diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json
index d10d78d..7310ecd 100644
--- a/.cursor-plugin/marketplace.json
+++ b/.cursor-plugin/marketplace.json
@@ -12,7 +12,7 @@
"name": "memory-kit",
"source": "plugins/memory-kit",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
- "version": "7.2.1",
+ "version": "7.2.2",
"author": {
"name": "awrshift"
},
diff --git a/VERSION b/VERSION
index b26a34e..77f5bec 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-7.2.1
+7.2.2
diff --git a/docs/ARCHITECTURE.md b/docs/ARCHITECTURE.md
index 73130da..421d916 100644
--- a/docs/ARCHITECTURE.md
+++ b/docs/ARCHITECTURE.md
@@ -531,7 +531,7 @@ Six hooks, declared in the plugin's `hooks/hooks.json` — nothing to wire in yo
ls` in some repos, so projects dropped the deny; the hook gates reads without touching that
check. Fails open on a parse error; opt-out `CMK_SECRETS_GUARD=off`.
- **pre-compact.sh** — blocks compaction until MEMORY.md is BOTH fresh AND inside all three caps.
-- **session-end.sh** — SessionEnd timestamp logging.
+- **session-end.sh** — SessionEnd timestamp logging, adopted repositories only (7.2.2).
Beside them sits **stale-refs.py** (`hooks/lib/`), which the session-start hook runs to check that
file paths mentioned in CLAUDE.md + MEMORY.md still exist on disk — a stale belief that looks
diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md
index c4270dd..ecb9937 100644
--- a/docs/CHANGELOG.md
+++ b/docs/CHANGELOG.md
@@ -2,6 +2,35 @@
All notable changes to Memory Kit are documented here. Breaking changes marked **BREAKING**.
+
+
+## [7.2.2] — 2026-10-07 — SessionEnd writes nothing in an unadopted repo; directory-ready README
+
+**BREAKING: none.**
+
+### Fixed
+
+- **`session-end.sh` created `.claude/state/session-end.log` in every repository**, adopted or
+ not — the one hook that skipped the adoption test session-start and pre-compact already run.
+ With a user-wide install, every repo you opened got a `.claude/state/` folder it never asked
+ for, while the plugin README said the hooks "write nothing" there. It now exits first unless
+ `.claude/memory/MEMORY.md` or `context/handoffs/` exists.
+- `package.json` and the `AGENTS.md` protocol marker carried 7.2.0 through the 7.2.1 release
+ (CI on main was red from 62b8685 until the follow-up commit).
+
+### Changed
+
+- **Plugin README: a «What it reads, writes and sends» section** — no network calls, what
+ `system-audit` reads (`~/.claude/projects/` transcripts, settings files), what `/memory-kit:setup`
+ writes into `.claude/settings.json` and only after a yes, and where hooks run (Claude Code and
+ Cowork load them; Claude chat loads skills only). Written for Anthropic's plugin directory,
+ whose security scan looks for undisclosed behaviour; the directory shows this README as the
+ listing.
+- Plugin README images use absolute URLs: the installed plugin and the directory listing get
+ only the plugin folder, so `../../.github/assets/` never resolved there.
+- Repository: `SECURITY.md`, GitHub Actions pinned to commit SHAs, Dependabot for
+ github-actions.
+
## [7.2.1] — 2026-09-28 — orchestration: resume vs fresh subagent
diff --git a/package.json b/package.json
index 3ad6d99..e3ae0cd 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "memory-kit",
- "version": "7.2.1",
+ "version": "7.2.2",
"description": "Memory Kit's OpenCode plugin entry — built-in memory decides what to remember, this one asks. The plugin itself lives in plugins/memory-kit; this package exists so OpenCode can install the shim via \"plugin\": [\"memory-kit@git+https://github.com/awrshift/agent-memory-kit.git\"].",
"type": "module",
"main": ".opencode/plugins/memory-kit.js",
diff --git a/plugins/memory-kit/.claude-plugin/plugin.json b/plugins/memory-kit/.claude-plugin/plugin.json
index e4c9cc2..877d275 100644
--- a/plugins/memory-kit/.claude-plugin/plugin.json
+++ b/plugins/memory-kit/.claude-plugin/plugin.json
@@ -1,7 +1,7 @@
{
"name": "memory-kit",
"displayName": "Memory Kit",
- "version": "7.2.1",
+ "version": "7.2.2",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
"author": {
"name": "awrshift",
diff --git a/plugins/memory-kit/.cursor-plugin/plugin.json b/plugins/memory-kit/.cursor-plugin/plugin.json
index e4c9cc2..877d275 100644
--- a/plugins/memory-kit/.cursor-plugin/plugin.json
+++ b/plugins/memory-kit/.cursor-plugin/plugin.json
@@ -1,7 +1,7 @@
{
"name": "memory-kit",
"displayName": "Memory Kit",
- "version": "7.2.1",
+ "version": "7.2.2",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
"author": {
"name": "awrshift",
diff --git a/plugins/memory-kit/README.md b/plugins/memory-kit/README.md
index 372cc80..7770622 100644
--- a/plugins/memory-kit/README.md
+++ b/plugins/memory-kit/README.md
@@ -40,11 +40,29 @@ claude plugin update memory-kit@memory-kit
`id_rsa*`, `*.p12` — by the file tools or by a shell command, inline script or redirection;
`source` / `.`, `cp`/`ln`/`mv`, `ls`, `test`, `git`, `rm` pass, and `.env.example` is never
secret; `CMK_SECRETS_GUARD=off` opts out.
-- **SessionEnd** — timestamp logging.
+- **SessionEnd** — appends one timestamp line to `.claude/state/session-end.log`.
In a repository that never ran `/memory-kit:setup`, the hooks inject one pointer line and write
nothing.
+## What it reads, writes and sends
+
+- **Network: none.** No server, no telemetry, no package downloads: no hook or script in this
+ folder opens a connection. Every one is readable Python or shell, standard library only.
+- **Reads** the memory files of the repository you work in (below), and the `.claude/settings.json`
+ files the rails nudge and `system-audit` inspect. `system-audit` also reads this repository's
+ Claude Code session transcripts in `~/.claude/projects/` to count which layers actually fired;
+ the report stays in the conversation.
+- **Writes** only in an adopted repository: the memory state below and `.claude/state/` (session
+ counter, logs). `/memory-kit:setup` writes into `.claude/settings.json` only after you approve
+ the diff it shows: `"autoMemoryEnabled": false` if you choose kit-owned memory, and the
+ permission rails — `Read`/`Edit` deny rules for root `.env` files and, where you agree, a
+ narrow allow naming one exact script; never a broad allow, and never removing your rules.
+- **Blocks**, through the guards above; each guard names its opt-out variable.
+- **Where hooks run:** Claude Code and Cowork load them; Cursor CLI runs the SessionStart hook;
+ OpenCode uses its own shim. Claude chat loads only the skills (no hooks, no agents), so there is
+ no automatic injection there.
+
## Skills
| Skill | For |
@@ -61,8 +79,8 @@ nothing.
Agents: `executor` (builds to a spec file in a worktree) · `recon` (read-only facts) ·
`idea-validator` (isolated critic) · `qa` (one adversarial lens on the running app).
-
-
+
+
## Beyond Claude Code
diff --git a/plugins/memory-kit/hooks/session-end.sh b/plugins/memory-kit/hooks/session-end.sh
index 0c541c8..fde03ad 100755
--- a/plugins/memory-kit/hooks/session-end.sh
+++ b/plugins/memory-kit/hooks/session-end.sh
@@ -18,6 +18,13 @@ fi
PROJECT_DIR="${CLAUDE_PROJECT_DIR:-$PWD}"
STATE_DIR="$PROJECT_DIR/.claude/state"
+
+# Not a Memory Kit repository → write nothing (a user-wide install must not scaffold
+# .claude/state/ into a repo that never asked; same test as session-start and pre-compact).
+if [[ ! -f "$PROJECT_DIR/.claude/memory/MEMORY.md" && ! -d "$PROJECT_DIR/context/handoffs" ]]; then
+ exit 0
+fi
+
mkdir -p "$STATE_DIR"
LOG_FILE="$STATE_DIR/session-end.log"
diff --git a/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md b/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md
index 0164281..a83dbbe 100644
--- a/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md
+++ b/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md
@@ -1,4 +1,4 @@
-
+
# Memory protocol (for any agent working in this repository)
This repository keeps agent memory in plain files. Follow this protocol every session.