diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json
index af759aa..4677f95 100644
--- a/.claude-plugin/marketplace.json
+++ b/.claude-plugin/marketplace.json
@@ -10,7 +10,7 @@
"name": "memory-kit",
"source": "./plugins/memory-kit",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
- "version": "7.2.2",
+ "version": "7.2.3",
"author": {
"name": "awrshift"
},
diff --git a/.cursor-plugin/marketplace.json b/.cursor-plugin/marketplace.json
index 7310ecd..8376d1f 100644
--- a/.cursor-plugin/marketplace.json
+++ b/.cursor-plugin/marketplace.json
@@ -12,7 +12,7 @@
"name": "memory-kit",
"source": "plugins/memory-kit",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
- "version": "7.2.2",
+ "version": "7.2.3",
"author": {
"name": "awrshift"
},
diff --git a/VERSION b/VERSION
index 77f5bec..429dc57 100644
--- a/VERSION
+++ b/VERSION
@@ -1 +1 @@
-7.2.2
+7.2.3
diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md
index ecb9937..b648b3d 100644
--- a/docs/CHANGELOG.md
+++ b/docs/CHANGELOG.md
@@ -2,6 +2,33 @@
All notable changes to Memory Kit are documented here. Breaking changes marked **BREAKING**.
+
+
+## [7.2.3] — 2026-10-08 — no skill pre-approves Bash; a plugin icon
+
+**BREAKING: none — but read «Behaviour change».**
+
+### Behaviour change
+
+- **Six skills no longer pre-approve `Bash`** (`close-session`, `code-sync`, `document`,
+ `memory-audit`, `setup`, `tour`). `allowed-tools` is a pre-approval, not a limit: a bare `Bash`
+ there ran ANY shell command without a prompt while the skill was active — the broad allow the
+ kit's own permission rails tell users never to keep. The skills still run their commands; each
+ one now goes through your normal permission mode (a prompt in default mode, the classifier in
+ auto mode). Anthropic's plugin directory validator holds a plugin with this grant for review.
+ The `project-extensions` skill template drops `Bash` the same way and says how to scope it.
+
+### Added
+
+- `.claude-plugin/icon.png` — the four-layer stack from the banner, 1024 px; the directory takes
+ the listing icon from it once, at the first submission.
+
+### Changed
+
+- `protect-tests.py`: the no-opinion exit is named `no_opinion()`, not `allow()`. Behaviour is
+ unchanged — the hook never returns an approving decision — but the directory's static check read
+ the old name as a hook that grants permission.
+
## [7.2.2] — 2026-10-07 — SessionEnd writes nothing in an unadopted repo; directory-ready README
diff --git a/package.json b/package.json
index e3ae0cd..5df06f7 100644
--- a/package.json
+++ b/package.json
@@ -1,6 +1,6 @@
{
"name": "memory-kit",
- "version": "7.2.2",
+ "version": "7.2.3",
"description": "Memory Kit's OpenCode plugin entry — built-in memory decides what to remember, this one asks. The plugin itself lives in plugins/memory-kit; this package exists so OpenCode can install the shim via \"plugin\": [\"memory-kit@git+https://github.com/awrshift/agent-memory-kit.git\"].",
"type": "module",
"main": ".opencode/plugins/memory-kit.js",
diff --git a/plugins/memory-kit/.claude-plugin/icon.png b/plugins/memory-kit/.claude-plugin/icon.png
new file mode 100644
index 0000000..e0327a7
Binary files /dev/null and b/plugins/memory-kit/.claude-plugin/icon.png differ
diff --git a/plugins/memory-kit/.claude-plugin/plugin.json b/plugins/memory-kit/.claude-plugin/plugin.json
index 877d275..51255d6 100644
--- a/plugins/memory-kit/.claude-plugin/plugin.json
+++ b/plugins/memory-kit/.claude-plugin/plugin.json
@@ -1,7 +1,7 @@
{
"name": "memory-kit",
"displayName": "Memory Kit",
- "version": "7.2.2",
+ "version": "7.2.3",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
"author": {
"name": "awrshift",
diff --git a/plugins/memory-kit/.cursor-plugin/plugin.json b/plugins/memory-kit/.cursor-plugin/plugin.json
index 877d275..51255d6 100644
--- a/plugins/memory-kit/.cursor-plugin/plugin.json
+++ b/plugins/memory-kit/.cursor-plugin/plugin.json
@@ -1,7 +1,7 @@
{
"name": "memory-kit",
"displayName": "Memory Kit",
- "version": "7.2.2",
+ "version": "7.2.3",
"description": "Persistent memory for your agent as plain files in your folder: a hot cache injected every session and held under three size caps, per-session handoffs, and promotion into knowledge articles and rules only on your yes. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use. Installs into any existing repository.",
"author": {
"name": "awrshift",
diff --git a/plugins/memory-kit/hooks/protect-tests.py b/plugins/memory-kit/hooks/protect-tests.py
index d9fab10..79147b4 100755
--- a/plugins/memory-kit/hooks/protect-tests.py
+++ b/plugins/memory-kit/hooks/protect-tests.py
@@ -60,8 +60,8 @@
)
-def allow() -> None:
- # No opinion = exit 0 with NO output. A `permissionDecision: "allow"` here would skip the user's
+def no_opinion() -> None:
+ # No opinion = exit 0 with NO output. An approving permissionDecision here would skip the user's
# permission prompt for every non-test Edit/Write (v6.0-7.0.3 did exactly that: in default mode the
# kit silently auto-approved all edits — found 2026-09-26 by a headless probe).
sys.exit(0)
@@ -119,18 +119,18 @@ def weakening(old: str, new: str) -> str:
def main() -> None:
if os.environ.get("CMK_ALLOW_TEST_EDITS") == "1":
- allow()
+ no_opinion()
try:
payload = json.loads(sys.stdin.read() or "{}")
except (json.JSONDecodeError, ValueError):
- allow()
+ no_opinion()
return
tool_input = payload.get("tool_input") or {}
file_path = str(tool_input.get("file_path") or "")
if not file_path:
- allow()
+ no_opinion()
suffix = Path(file_path).suffix.lower()
if suffix == ".snap":
@@ -140,9 +140,9 @@ def main() -> None:
"confirm only if this edit is deliberate. Set CMK_ALLOW_TEST_EDITS=1 for a whole session of test work."
)
if suffix in EXEMPT_SUFFIXES:
- allow()
+ no_opinion()
if not TEST_PATH_RE.search(file_path):
- allow()
+ no_opinion()
project_dir = Path(os.environ.get("CLAUDE_PROJECT_DIR", Path.cwd()))
session_id = re.sub(r"[^A-Za-z0-9_-]", "", str(payload.get("session_id") or "unknown")) or "unknown"
@@ -150,9 +150,9 @@ def main() -> None:
# A new test file, or one this session authored: the red→green loop, always allowed.
if not Path(file_path).exists():
remember_created(project_dir, session_id, file_path)
- allow()
+ no_opinion()
if session_created_file(project_dir, session_id, file_path):
- allow()
+ no_opinion()
# v2: an existing test file asks only when the change can weaken what it proves.
tool = payload.get("tool_name")
@@ -167,7 +167,7 @@ def main() -> None:
else:
reason = weakening(str(tool_input.get("old_string") or ""), str(tool_input.get("new_string") or ""))
if not reason:
- allow()
+ no_opinion()
ask(
f"{file_path} is an existing test file and {reason}. A failing test usually means the CODE "
diff --git a/plugins/memory-kit/reference/project-extensions.md b/plugins/memory-kit/reference/project-extensions.md
index 8c4f969..e2eaba3 100644
--- a/plugins/memory-kit/reference/project-extensions.md
+++ b/plugins/memory-kit/reference/project-extensions.md
@@ -42,7 +42,7 @@ A skill — the body loads only when invoked, so depth is cheap here:
name:
description:
-allowed-tools: Read, Write, Edit, Bash
+allowed-tools: Read, Write, Edit # pre-approved, not a limit; a bare Bash pre-approves every command — scope it: Bash(python3 scripts/x.py *)
---
# / —
diff --git a/plugins/memory-kit/skills/close-session/SKILL.md b/plugins/memory-kit/skills/close-session/SKILL.md
index bdb87f8..6dcadc8 100644
--- a/plugins/memory-kit/skills/close-session/SKILL.md
+++ b/plugins/memory-kit/skills/close-session/SKILL.md
@@ -1,7 +1,7 @@
---
name: close-session
description: End-of-session ritual — audit today's patterns against accumulated memory, propose promotions, refresh MEMORY.md, and write the session handoff. Use when the user says "/memory-kit:close-session", "закрой сессию", "закрываем", "we're done for today", "wrap up".
-allowed-tools: Read, Write, Edit, Grep, Glob, Bash
+allowed-tools: Read, Write, Edit, Grep, Glob
---
# /close-session — the end-of-session ritual
diff --git a/plugins/memory-kit/skills/code-sync/SKILL.md b/plugins/memory-kit/skills/code-sync/SKILL.md
index 0c752ab..20454d6 100644
--- a/plugins/memory-kit/skills/code-sync/SKILL.md
+++ b/plugins/memory-kit/skills/code-sync/SKILL.md
@@ -7,7 +7,7 @@ description: >
edits only. Use when the user says "/memory-kit:code-sync", "sync the docs", "sync specs with
code", "синхронизируй доки с кодом", "что устарело в спеках", or right after merging an
executor branch.
-allowed-tools: Read, Edit, Grep, Glob, Bash
+allowed-tools: Read, Edit, Grep, Glob
---
# /code-sync — documents reconciled against the repository
diff --git a/plugins/memory-kit/skills/document/SKILL.md b/plugins/memory-kit/skills/document/SKILL.md
index cd925af..d0f90ab 100644
--- a/plugins/memory-kit/skills/document/SKILL.md
+++ b/plugins/memory-kit/skills/document/SKILL.md
@@ -8,7 +8,7 @@ description: >
"постмортем". Every draft is built ONLY from `git diff` / `git log` output this skill runs
itself — never from the session's memory of what it did, never from what it intended. Writes
no code, no tests, no specs; it never edits an implementation file and never edits a spec.
-allowed-tools: Read, Write, Edit, Bash, Grep, Glob
+allowed-tools: Read, Write, Edit, Grep, Glob
---
# /document — the human record of a change
diff --git a/plugins/memory-kit/skills/memory-audit/SKILL.md b/plugins/memory-kit/skills/memory-audit/SKILL.md
index 829fc78..8a18014 100644
--- a/plugins/memory-kit/skills/memory-audit/SKILL.md
+++ b/plugins/memory-kit/skills/memory-audit/SKILL.md
@@ -1,7 +1,7 @@
---
name: memory-audit
description: Audit MEMORY.md against the memory discipline — oversized sections, settled multi-session patterns that belong in knowledge/concepts/, session-headed chronicle blocks, restated rules, copied numbers, stale entries. Produces a move plan as a table for approval, then executes the approved moves atomically. Use when the SessionStart hook reports a tripped cap or session-headed blocks, when PreCompact blocks on an oversized cache, or when the user says "/memory-kit:memory-audit", "audit memory", "проверь память", "почисти память". Refuses only when no cap is tripped, no session block is flagged AND no settled-pattern candidate exists.
-allowed-tools: Read, Write, Edit, Grep, Glob, Bash
+allowed-tools: Read, Write, Edit, Grep, Glob
---
# Memory audit — the surgical one-file pass
diff --git a/plugins/memory-kit/skills/setup/SKILL.md b/plugins/memory-kit/skills/setup/SKILL.md
index e4cf343..803c489 100644
--- a/plugins/memory-kit/skills/setup/SKILL.md
+++ b/plugins/memory-kit/skills/setup/SKILL.md
@@ -1,7 +1,7 @@
---
name: setup
description: Adopt the Memory Kit in THIS repository — scaffold the memory layers, decide how the kit coexists with Claude Code's native auto memory, and install safe permission rails (`/memory-kit:setup rails` re-runs only the rails step on an adopted repo). Use when the user says "/memory-kit:setup", "/memory-kit:setup rails", "set up the memory kit", "adopt the kit here", "настрой кит", or when a session starts in a repo where the kit plugin is installed but no .claude/memory/MEMORY.md exists.
-allowed-tools: Read, Write, Edit, Bash, Glob, Grep
+allowed-tools: Read, Write, Edit, Glob, Grep
---
# /memory-kit:setup — adopt the kit in an existing repository
diff --git a/plugins/memory-kit/skills/tour/SKILL.md b/plugins/memory-kit/skills/tour/SKILL.md
index f563dbe..46215bd 100644
--- a/plugins/memory-kit/skills/tour/SKILL.md
+++ b/plugins/memory-kit/skills/tour/SKILL.md
@@ -1,7 +1,7 @@
---
name: tour
description: Interactive walkthrough of the Memory Kit system using the user's actual project files. Use when the user says "/memory-kit:tour", "give me a tour", "покажи как это работает", or right after /memory-kit:setup.
-allowed-tools: Read, Glob, Grep, Bash
+allowed-tools: Read, Glob, Grep
model: sonnet
---
diff --git a/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md b/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md
index a83dbbe..88b695c 100644
--- a/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md
+++ b/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md
@@ -1,4 +1,4 @@
-
+
# Memory protocol (for any agent working in this repository)
This repository keeps agent memory in plain files. Follow this protocol every session.