From 7d27c10521da319f68e9cb7a1dff0a82089101d2 Mon Sep 17 00:00:00 2001 From: Sergey Date: Wed, 7 Oct 2026 23:52:58 +0300 Subject: [PATCH 1/2] security: SECURITY.md, Actions pinned to commit SHAs, Dependabot for github-actions The awesome-ai-plugins listing gate (HOL plugin scanner) scored the repo 76/100 against a threshold of 80 with no critical or high findings; the gaps were repo hygiene: no SECURITY.md, third-party Actions referenced by tag, no Dependabot config. Co-Authored-By: Claude Opus 5.5 --- .github/dependabot.yml | 7 +++++++ .github/workflows/checks.yml | 6 +++--- SECURITY.md | 26 ++++++++++++++++++++++++++ 3 files changed, 36 insertions(+), 3 deletions(-) create mode 100644 .github/dependabot.yml create mode 100644 SECURITY.md diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..2e8942f --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,7 @@ +version: 2 +updates: + # Workflow actions are pinned to commit SHAs; Dependabot keeps those pins current. + - package-ecosystem: github-actions + directory: / + schedule: + interval: monthly diff --git a/.github/workflows/checks.yml b/.github/workflows/checks.yml index be13942..c015567 100644 --- a/.github/workflows/checks.yml +++ b/.github/workflows/checks.yml @@ -9,8 +9,8 @@ jobs: repo-integrity: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-python@v5 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 with: python-version: "3.12" @@ -109,7 +109,7 @@ jobs: # The OpenCode shim is JavaScript and CI has no other reason to load Node — so load it: # syntax, module resolution from package.json, and the injection itself with a canary. - - uses: actions/setup-node@v4 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 with: node-version: "20" - name: OpenCode shim loads and injects diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 0000000..4cfd287 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,26 @@ +# Security + +## Reporting a vulnerability + +Please report privately through GitHub: **Security → Report a vulnerability** on this repository. +Do not open a public issue for a security problem. Expect a first reply within a week. + +Only the latest release is supported; fixes ship as a new version. + +## What the plugin runs on your machine + +Memory Kit has no server, no telemetry and makes no network calls. Its hooks are local Python and +shell scripts in [`plugins/memory-kit/hooks/`](plugins/memory-kit/hooks/), wired in +[`hooks.json`](plugins/memory-kit/hooks/hooks.json): + +- **SessionStart** reads `.claude/memory/MEMORY.md`, the newest handoff and the knowledge index from + your repository and prints them into the session context. +- **PreCompact** blocks compaction while `MEMORY.md` is stale or over its size caps. +- **PreToolUse** guards: asks before an edit removes or weakens a test assertion; blocks reads + and writes of secret files (`.env`, `*.pem`, `id_rsa*`, …) and destructive git commands + (`push --force`, `reset --hard`, `clean -f`, …). Each guard documents its opt-out variable. +- **SessionEnd** appends one timestamp line to `.claude/state/session-end.log`. + +No hook writes your memory files. Scaffolding (`/memory-kit:setup`) runs only after you say yes; +during a session the agent writes memory entries itself and asks before adding a rule or a +knowledge article. From b92d087f7f632541ddd41f1fccffda63cc9d0eb2 Mon Sep 17 00:00:00 2001 From: Sergey Date: Wed, 7 Oct 2026 23:52:58 +0300 Subject: [PATCH 2/2] release 7.2.1 follow-up: package.json and the AGENTS.md protocol marker carry 7.2.1 The 7.2.1 release bumped VERSION and the manifests but not these two; tools/check-repo.py caught it and CI on main has been red since 62b8685. Co-Authored-By: Claude Opus 5.5 --- package.json | 2 +- .../memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index c4587d4..3ad6d99 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "memory-kit", - "version": "7.2.0", + "version": "7.2.1", "description": "Memory Kit's OpenCode plugin entry — built-in memory decides what to remember, this one asks. The plugin itself lives in plugins/memory-kit; this package exists so OpenCode can install the shim via \"plugin\": [\"memory-kit@git+https://github.com/awrshift/agent-memory-kit.git\"].", "type": "module", "main": ".opencode/plugins/memory-kit.js", diff --git a/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md b/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md index 229d742..0164281 100644 --- a/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md +++ b/plugins/memory-kit/templates/workspace/AGENTS-MEMORY-PROTOCOL.md @@ -1,4 +1,4 @@ - + # Memory protocol (for any agent working in this repository) This repository keeps agent memory in plain files. Follow this protocol every session.