docs/readme-refresh
23 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
a0da02b6b3 |
Add GitHub Copilot CLI support (#534)
* feat: add Copilot CLI plugin asset slice - plugin/.plugin/plugin.json: Copilot manifest with name/version/skills/mcpServers/hooks refs - plugin/.mcp.copilot.json: MCP server config with type:local, npx, env passthrough, tools:[*] - plugin/hooks/hooks.copilot.json: Copilot hooks (version:1) with 11 supported events and PreToolUse matcher - test/copilot-plugin.test.ts: 11 tests covering manifest, MCP config, and hooks validation Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Copilot CLI connect support Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add GitHub Copilot CLI support Adds Copilot CLI support through a root plugin manifest, Copilot-specific MCP and hook configuration, and a connect adapter for MCP-only setup. Includes Windows-safe Copilot MCP command generation, COPILOT_HOME handling, Copilot hook payload normalization, generated hook scripts, and targeted tests for plugin shape, hook execution, and connect behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Harden Copilot hook handling Addresses upstream AI review suggestions by aligning the Copilot preToolUse matcher with the hook allowlist, narrowing hook payload fields at runtime, normalizing subagent fallbacks, and tightening hook config validation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add Copilot to first-run onboarding Includes GitHub Copilot CLI in the first-run agent picker and adds a regression test so the Copilot setup path remains discoverable. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Default onboarding to Copilot inside Copilot CLI Detect Copilot CLI environment markers during first-run setup so pressing Enter wires the current agent instead of the historical Claude Code default. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Support framed stdio MCP transport Accept Content-Length framed JSON-RPC messages in addition to the existing newline-delimited transport so Copilot CLI can initialize the standalone MCP server. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Narrow Copilot pre-tool session ids Ensures pre-tool-use only forwards string session IDs and falls back to unknown for invalid Copilot payload values, with regression coverage for the generated plugin script. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Ross Story <rostory@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Rohit Ghumare <ghumare64@gmail.com> |
||
|
|
d626b4ea60 |
perf(hooks): fire-and-forget telemetry hooks (#573) (#688)
* perf(hooks): fire-and-forget telemetry hooks (closes #573) Telemetry hooks (notification, post-tool-failure, post-tool-use, prompt-submit, stop, session-end, subagent-start, subagent-stop, task-completed) previously `await fetch(..., AbortSignal.timeout(N))` inside a try/catch. The await kept the hook process alive until the response arrived — up to N ms per request — which blocks Claude Code's next-prompt boundary on every assistant turn. Switch to fire-and-forget: fetch(url, { signal: AbortSignal.timeout(N) }).catch(() => {}); setTimeout(() => process.exit(0), 500).unref(); The unawaited fetch dispatches the request; the unref'd setTimeout force-exits the process after the request has been flushed to the local daemon's socket buffer (~500ms is enough). Without the setTimeout Node keeps the event loop alive waiting for any in-flight fetch to settle, which means the hook still blocks Claude Code's next-prompt boundary for up to the AbortSignal duration. Context-injecting hooks (pre-tool-use, pre-compact, session-start) still use `await fetch` because Claude Code reads their stdout for context injection — left untouched. AGENTS.md updated with the two-pattern guidance. * chore(hooks): drop verbose comments on fire-and-forget hooks * fix(hooks): bump stop+session-end exit delay to 1500ms Multi-request hooks (stop fires 2, session-end up to 4) need more than 500ms to initiate all fetches when AGENTMEMORY_URL points to a remote daemon — DNS + TCP + TLS handshakes can eat the budget before the second/third fetch is even dispatched. Bump to 1500ms on those two hooks only; single-request hooks keep 500ms. AGENTS.md updated with the multi-request exception. |
||
|
|
0468407249 |
fix(hooks): send repo basename as project, not full path (#474) (#687)
* fix(hooks): send repo basename as project, not full path (closes #474) Hooks were sending `data.cwd` (an absolute filesystem path) as the `project` field on every observe/session/start call. Native sessions, replay-import, and manual memory_lesson_save calls all use the repo basename. The mismatch caused auto-injected context to filter out the bulk of relevant lessons because the path never matches the stored project name. Add shared `resolveProject(cwd)` helper: 1. AGENTMEMORY_PROJECT_NAME env (per-repo escape hatch) 2. basename of `git rev-parse --show-toplevel` (handles subdirs) 3. basename of cwd (final fallback when not in a git repo) Applied to 9 hooks: notification, post-tool-use, post-tool-failure, prompt-submit, session-start, subagent-start, subagent-stop, task-completed, pre-compact. Build: split hook entries into per-entry tsdown configs so each hook bundles into a fully self-contained .mjs. Previous shared config hoisted helpers into hashed chunks that changed on every rebuild. * chore(hooks): drop issue-number ref from resolveProject comment * chore: trim verbose comments on _project.ts + tsdown.config |
||
|
|
3551241416 |
fix(hooks): stop also closes session for Codex (closes #493) (#579)
Codex does not fire a separate SessionEnd event, so its Stop hook is the only signal we get when a Codex session terminates. The current stop hook only POSTs /agentmemory/summarize, leaving the session row stuck on status:"active" in the viewer for Codex users (#493). Stop now ALSO POSTs /agentmemory/session/end, best-effort with a short 5s timeout. For Claude Code this is a harmless idempotent second call (session-end.mjs runs on the dedicated SessionEnd hook and sets the same endedAt + status fields). For Codex it's the only path that closes the lifecycle. Tests (1081) + build pass. plugin/scripts/stop.mjs regenerated by tsdown. |
||
|
|
3cb7f90894 |
fix: read tool_response instead of tool_output in PostToolUse hook (#561)
* fix: read tool_response instead of tool_output in PostToolUse hook Claude Code's PostToolUse payload sends the field as `tool_response`, not `tool_output`. The hook was reading `data.tool_output` which is always undefined, so `cleanOutput` was undefined, the observe request contained no `tool_output` value, and mem::compress consistently failed its XML schema validation (requires narrative >= 10 chars + facts >= 1). Fix: read `data.tool_response` with `data.tool_output` as a fallback so older integrations that emit the legacy field name keep working. Fixes #539 * style: remove explanatory comment per repo guidelines |
||
|
|
08d781d431 |
chore(release): v0.9.20 — hotfix Codex Stop revert (#501)
v0.9.19 shipped #495 which chained session-end.mjs after stop.mjs on the Codex Stop hook. Field-testing surfaced the underlying issue: Codex fires Stop multiple times within a single conversation (once per assistant turn), so chaining session-end marked sessions as completed while later observations were still arriving. #501 reverts the chain. Stop returns to summarize-only behavior. The SessionEnd-shaped solution (a dedicated terminate event the agent sends only once on real session end) tracks at #493. Files bumped (9): - package.json, packages/mcp/package.json - plugin/.claude-plugin/plugin.json, plugin/.codex-plugin/plugin.json - src/version.ts, src/types.ts - src/functions/export-import.ts - test/export-import.test.ts - CHANGELOG.md 1034/1034 tests pass. |
||
|
|
1ff5849d9c |
fix: cap session-start/subagent-start hook latency (#221) (#271)
Two hook scripts blocked Claude Code's startup waiting on REST responses they didn't actually need: - `session-start` awaited a 5000ms POST and discarded the response when `AGENTMEMORY_INJECT_CONTEXT=false` (the default). Pure latency. - `subagent-start` had a `// fire and forget` comment but the code awaited a 2000ms POST. Pure latency. Under fan-out (Slack-bot orchestrators, multi-agent harnesses, fanned `claude -p` jobs) the awaited timeouts stack and feed back into the engine; the reporter hit a positive feedback loop that OOM-killed iii-engine. Fix: - `session-start` — fire-and-forget when `INJECT_CONTEXT=false`. Cap the inject path at 1500ms (down from 5000ms) so a slow server can't block the agent indefinitely when stdout is actually consumed. - `subagent-start` — actually fire-and-forget, matching the existing comment. Cap at 800ms. Verified live against a black-hole TCP listener (accepts, never replies): - session-start (no inject): 5.05s → 0.85s - session-start (inject): 5.05s → 1.55s - subagent-start: 2.05s → 0.87s Built artifacts in `plugin/scripts/` regenerated via `npx tsdown`. Closes #221. |
||
|
|
0c73d868be |
chore(release): v0.9.5 — search recall + plugin compatibility (#261)
Bug-fix patch focused on search recall correctness and plugin compatibility. Pins iii-engine to v0.11.2 because v0.11.6 introduces a new sandbox-everything-via-`iii worker add` model that agentmemory hasn't been refactored for yet — pin lifts once that refactor lands. Adds a hard guard against silent vector-index corruption, fixes BM25 indexing for memories saved via memory_save, and lands four Hermes plugin fixes. Per AGENTS.md release checklist: - package.json version 0.9.4 -> 0.9.5 - src/version.ts VERSION constant - src/types.ts ExportData version union - src/functions/export-import.ts supportedVersions Set - test/export-import.test.ts assertion - plugin/.claude-plugin/plugin.json version - CHANGELOG.md detailed entries with contributor shoutouts Headlines (full detail in CHANGELOG): Fixed: - BM25 search now indexes memories saved via memory_save (#258, #257) Thanks @Nizar-BenHamida for the precise repro. - Embedding providers no longer silently corrupt the vector index when an API returns wrong-dimension vectors (#248, #247, #256) Thanks @AmmarSaleh50 for issue + fix + tests. - Hermes handle_tool_call returns JSON strings, not raw dicts (#255, #254) Thanks @KyoMio for the Anthropic-protocol repro. - Hermes status reflects real service state on systemd installs (#253, #250) Thanks @OptionalCoin for tracing it to env-source divergence. - Hermes hooks accept passthrough kwargs (#252, #249) Thanks @OptionalCoin again for the log analysis. - agentmemory demo now seeds observations correctly (#251, #229) Thanks @seishonagon for root-cause analysis. - LLM compression / summarization timeouts increased (#213) Thanks @xuli500177. - Pi / OpenClaw / Hermes integration plugin fixes (#230) Thanks @deepmroot. Changed: - iii-engine pinned to v0.11.2 across every install path (#260). v0.11.6 introduces a new `iii worker add` sandbox model that agentmemory still pre-dates; pin lifts when we refactor agentmemory to register as a sandboxed worker. Override with AGENTMEMORY_III_VERSION=<version> for users who've migrated manually. - README documents iii worker add extension surface (#242). - README iii Console install/launch commands corrected (#243). Validated: 852/852 tests pass, npm run build clean. |
||
|
|
51bcb09104 |
address CodeRabbit review on #187 + fix CI
Findings verified against current code on this branch; all four valid. 1. config.ts loadFallbackConfig (L281) — user could set FALLBACK_PROVIDERS=agent-sdk and bypass the AGENTMEMORY_ALLOW_AGENT_SDK gate added to detectProvider. Filter it out at the fallback layer too, with the same warning pointing at the opt-in flag. 2. summarize.ts (L87-92) — the empty_provider_response branch returned without recording failure metrics or a diagnostic log, unlike the parse/validation paths. Record the same metricsStore failure event and log provider name, prompt size, system size, and observation count so empty responses are visible in telemetry. 3. providers/agent-sdk.ts (L14-45) — setting process.env.AGENTMEMORY_SDK_CHILD = '1' without restoring it caused every subsequent .query() in the same parent process to hit the short-circuit guard and return '' (classified as a SDK child it is not). Capture prev, set in try, restore in finally (delete if prev was undefined). Child processes spawned during the for-await loop still inherit the marker because env is inherited at spawn time; we only restore after the loop completes. 4. plugin/scripts/sdk-guard-DI1NUOS9.mjs — tsdown extracted the shared guard helper into a hashed chunk. Hash rotates on every rebuild and churns the diff. Stopped using the shared module from hooks entirely and inlined the 6-line guard function into each hook .ts file instead. sdk-guard.ts stays in the tree because the unit tests cover it directly. Deleted the tracked hashed .mjs and confirmed no new chunk is emitted. Also applied the CI two-step install (npm install --package-lock-only then npm ci) on this branch, matching #184. Without it, npm ci fails because lockfiles are gitignored. Tests: 74 files / 819 tests pass. |
||
|
|
5e63846b29 |
fix(hooks): break Stop-hook infinite recursion via agent-sdk fallback
Reported: a user with no provider API key and AGENTMEMORY_AUTO_COMPRESS=false (which they believed protected them) hit unbounded recursion — Stop hook POSTs /agentmemory/summarize, handler calls provider.summarize(), agent-sdk provider spawns @anthropic-ai/claude-agent-sdk query(), which creates a full CC-style child session that reads ~/.claude/settings.json, registers the same plugin hooks, and fires its own Stop -> another child -> loop. ~579 ghost 'entrypoint: sdk-ts' sessions accumulated in a few minutes, draining Claude Pro tokens. #149 only added a stderr warning. AGENTMEMORY_AUTO_COMPRESS gated /compress but never /summarize, so users who followed the warning's implied guidance still got hit. Fix the loop at every layer: 1. config.ts detectProvider - Treat empty-string provider keys (ANTHROPIC_API_KEY=) as unset; they previously passed the truthiness check identically to a real key. - Stop defaulting to agent-sdk. When no key is set, return a 'noop' provider config and warn. Agent-sdk fallback now requires an explicit AGENTMEMORY_ALLOW_AGENT_SDK=true opt-in with a loud second warning. 2. providers/noop.ts (new) + providers/index.ts - NoopProvider implements MemoryProvider and returns empty strings for compress and summarize so callers can detect .name === 'noop' and short-circuit without spawning anything. - Add ProviderType 'noop' and wire it through createBaseProvider. 3. providers/agent-sdk.ts - Before spawning query(), check process.env.AGENTMEMORY_SDK_CHILD === '1' and return '' instead of recursing. Set the env var to '1' before the spawn so any child process (including the Agent SDK session's hooks) inherits it. 4. hooks/sdk-guard.ts (new) + all 12 hook scripts - Shared isSdkChildContext(payload) checks both AGENTMEMORY_SDK_CHILD=1 and payload.entrypoint === 'sdk-ts' (CC writes this into the stdin jsonl for SDK-spawned sessions). Every hook script now bails early when that returns true, so even if one guard layer fails the others break the loop. 5. functions/summarize.ts - Short-circuit with {success:false, error:'no_provider'} when provider.name === 'noop' — never reach .summarize(). - Treat an empty provider response as empty_provider_response instead of trying to parse it. Tests: 74 files / 819 tests pass (+7 new in stop-hook-recursion-guard.test.ts). Defense in depth means any ONE of the five layers breaks the loop. |
||
|
|
2edc02feb5 |
fix: resolve conflicts with main, address qodo-ai security findings
Resolves conflicts in: - src/state/schema.ts (merged imageRefs + accessLog) - src/functions/auto-forget.ts (kept audit, reordered ref decrement) - src/functions/compress.ts (collapsed iii-sdk imports, s/ctx.logger/logger/) - src/functions/evict.ts (kept audit + deleteAccessLog, deferred ref decrement until after delete succeeds) - src/functions/retention.ts (kept source-aware delete routing, fetch mem from resolved scope, defer ref decrement) - src/triggers/api.ts (kept main's registerFunction/trigger shape) - src/types.ts (kept superset of AuditEntry.operation union) qodo-ai action-required findings: - mem::forget now decrements image refs for every deleted memory and observation (including the session-wipe branch), which stops sensitive screenshots leaking to ~/.agentmemory/images/ after user-initiated forget. - Eviction / auto-forget now decrement refs only after the KV delete actually succeeds. The old order (decrement-then-delete) could desync ref counts when the delete threw. Follow-on fixes: - buildSyntheticCompression now carries modality and imageData through from raw to compressed, so the default zero-LLM path doesn't drop image metadata the viewer and governance paths rely on. - Test harness updated for the current registerFunction (name, cb) signature and iii-sdk partial-mock pattern — 11/11 multimodal tests pass, full suite 788/788. Closes #64. |
||
|
|
5d70ecfb3c |
feat: migrate agentmemory to iii v0.11 and add upgrade command (#116)
* feat: migrate agentmemory to iii v0.11 and add upgrade command
Migrate the codebase from legacy iii-sdk v0.3 APIs to v0.11 trigger/register patterns, update runtime configs, and align stream/state behavior with newer engine semantics. Add a new `agentmemory upgrade` CLI command so users can refresh dependencies and iii runtime components with one entrypoint.
* chore: remove pnpm lockfile from migration PR
Drop pnpm-lock.yaml from this branch to keep the migration PR focused on source and config changes only.
* fix(ci): sync npm lockfile with iii-sdk v0.11 dependency
Update package-lock.json so npm ci in CI matches package.json after the iii-sdk migration.
* fix(ci): resolve build parse errors after v0.11 migration
Fix malformed braces introduced during API migration in triggers/health/branch-aware files so tsdown build passes in CI.
* fix: harden migration follow-up fixes and audits
Apply the reviewed v0.11 follow-up fixes across runtime, docs, and tests by tightening validation, correcting upgrade/error handling, and adding missing audit coverage on state mutations. This also addresses stream fallback behavior, lock consistency, retention source-bucket cleanup, and test/mock alignment so build and test remain green.
* fix: address 9 unresolved CodeRabbit findings on iii v0.11 migration
CodeRabbit flagged 9 remaining issues on #116 — all real. Each was
verified against the current branch code before applying. Two
findings were deliberately skipped as policy/scope issues and are
documented at the bottom.
### Applied (9 real findings)
- src/triggers/api.ts — api.ts numeric query param validation:
multiple sites forwarded `parseInt(params.limit)` result to the
downstream function without a Number.isFinite check. A non-numeric
query value produced NaN at the iii-sdk trigger boundary. Added
parseOptionalInt and parseOptionalFloat helpers at the top of the
file, wired into api::crystal-list, api::lesson-list, and
api::insight-list (5 sites total).
- src/triggers/api.ts — api::observe, api::context, api::session::start,
api::session::end were forwarding req.body verbatim to sdk.trigger
with no validation. Added explicit type checks mirroring the existing
api::search pattern, construct a sanitized payload object before
triggering.
- src/cli.ts — p.confirm() can return a cancel Symbol on Ctrl+C, which
is truthy, so the upgrade path ran even when the user cancelled.
Added p.isCancel() check and explicit boolean comparison.
- src/cli.ts — removed dead `failed` flag in runUpgrade: every caller
already calls process.exit(1) immediately, so the final `if (failed)`
branch was unreachable. Simplified requireSuccess accordingly.
- src/functions/leases.ts — mem::lease-renew recorded audit events as
"lease_acquire", which conflated renewals with first claims. Renamed
the audit event to "lease_renew" so downstream audit filters can tell
the two operations apart.
- src/functions/relations.ts — the pair lock
`mem:${firstId}:${secondId}` serialized concurrent relate(A,B) calls
with identical pairs, but did NOT protect concurrent relate(A,B) +
relate(A,C). Both modify memory A's `relatedIds` array, which is a
classic last-writer-wins race producing lost relation edges. Fixed
by replacing the pair lock with nested per-entity locks in canonical
sort order: withKeyedLock(mem:firstId) wrapping withKeyedLock(mem:secondId).
Since the ids are sorted deterministically, no deadlock is possible.
- src/functions/sketches.ts + src/functions/summarize.ts + new
src/functions/audit.ts safeAudit helper — recordAudit was awaited
after kv.set calls. An audit write failure would reject and the
caller would see an error even though the target state was already
persisted. New safeAudit wrapper swallows audit errors and logs them
via ctx.logger.warn, preserving the mutation's success. Applied to
all 11 audit sites in sketches.ts and the single site in summarize.ts.
- src/mcp/server.ts — three issues in the MCP handler:
1. memory_profile's refresh flag used `args.refresh === "true"`,
ignoring boolean `true` from MCP clients that send proper types.
Now accepts both.
2. memory_sketch_create built sketchPayload with
`asNonEmptyString(args.title)` which could return undefined,
then forwarded that to the downstream function. Added explicit
validation + 400 response at the MCP boundary.
3. memory_recall, memory_team_feed, memory_audit_query used
`(args.limit as number) || 10` which replaced an explicit 0 with
10. Changed to typeof check so explicit 0 (rare but legal) is
preserved.
- src/functions/governance.ts — mem::governance-bulk used Promise.all
for the delete batch, which fails fast on the first error. The audit
record still said `deleted: candidates.length` even if only half
actually succeeded. Switched to Promise.allSettled, split results
into successfulIds and failures arrays, record audit with both counts
plus the per-failure details for traceability.
- src/functions/mesh.ts — mem::mesh-register, mem::mesh-sync,
mem::mesh-receive, mem::mesh-remove all dereferenced `data.*` without
checking that data was passed. A TypeError would bubble up on null
payload. Added early null/type guards returning structured errors.
- src/functions/obsidian-export.ts — resolveVaultDir(data.vaultDir)
was called without validating that vaultDir was a string, and
`new Set(data.types)` without validating types was an array of
strings. Added explicit validation returning 400-style error
responses.
- src/functions/retention.ts — the eviction loop silently swallowed
kv.delete errors via a bare `continue`. Added ctx.logger.warn on
catch, included memoryId and sourceBucket in the log, and now
returns `failed` count alongside `evicted` in the response.
- src/viewer/index.html — two WebSocket bugs:
1. connectWs assigned to the mutable global state.ws before binding
handlers, so old sockets could have their callbacks fire and
mutate retry/direct state after state.ws was overwritten by a
new socket. Fixed by creating a local `ws` variable, binding
all handlers to it, only then assigning state.ws = ws. Each
handler guards `if (state.ws !== ws) return` so stale callbacks
are dropped.
2. handleStreamEvent routed EVERY incoming event to routeWsMessage,
so non-observation events (session.activity, etc.) were being
treated as timeline observations and causing UI confusion. Added
a looksLikeObservation helper + event_type gate that only routes
real observation payloads.
- test/retention.test.ts — added an explicit sourceBucket eviction
test that seeds a semantic memory at high age, runs retention-score,
then runs retention-evict at high threshold and asserts BOTH
KV.semantic and KV.memories are empty. Proves the candidate.sourceBucket
branch added in this PR actually routes to the right bucket.
- src/types.ts — side fix: the ExportData.version union on line 254
used comma separators instead of pipes in 3 positions (0.7.9,
0.8.0, 0.8.1 → needed | between them). tsdown strips types so the
build passed, but tsc --noEmit would have thrown and any IDE showed
squiggles. Pre-existing latent bug, fixed while in the file.
### Deliberately skipped
- retention.ts eviction audit (CodeRabbit asked to add recordAudit
to the eviction loop): policy change, not a bug fix. Verified:
auto-forget.ts, evict.ts, retention-evict, remember-forget all
skip audit by convention — only governance audits. Adding audit
everywhere is a policy decision tracked in issue #125.
- file-index.ts sequential → parallel session lookup: micro-opt,
the loop is already cache-backed, negligible savings, not worth
the readability cost.
Tests: 655/655. Build clean.
* fix(api): harden request validation at HTTP boundaries
Validate and sanitize session, observe, and context inputs plus numeric query params before forwarding to memory functions, returning 400 for invalid values instead of propagating malformed payloads. Also remove duplicate CLI command registration introduced during merge resolution.
* fix: address 6 new CodeRabbit findings on iii v0.11 migration (#116 round 2)
CodeRabbit's second review pass on #116 flagged 6 real issues introduced
by the previous round of fixes (commit
|
||
|
|
3bad5430ed |
fix: SessionStart context gate (#143) + retention-evict semantic leak (#124) (#145)
* fix: stop burning Claude Pro tokens on every tool call (#143) 0.8.8 fixed the agentmemory-side Claude API burn (where the engine called Claude via the user's ANTHROPIC_API_KEY for per-observation compression). That addressed #138 for users with API keys, but it missed the second and much larger token-burn path: the PreToolUse hook writing context to stdout. Claude Code reads PreToolUse stdout and prepends it to the model's next turn. src/hooks/pre-tool-use.ts was POSTing /agentmemory/enrich on every Edit/Write/Read/Glob/Grep tool call and piping up to 4000 chars of response context into stdout. At ~20 tool calls per user message this silently injected ~20K tokens per message into Claude Code's input window — all charged against the user's Claude Pro allocation because Claude Code was the one sending them to Anthropic. 4 messages drained the cap, which matches @adrianricardo's report. session-start.ts had the same pattern (injected once per session, smaller blast radius). Fix: gate both hooks on AGENTMEMORY_INJECT_CONTEXT, default false. - pre-tool-use.ts: when disabled, exit immediately — no stdin read, no fetch, no stdout write. The hot path (~20x per message) becomes a no-op Node startup. - session-start.ts: when disabled, still POST /agentmemory/session/start so the session gets registered for observation tracking, but never write context to stdout. The session registration is cheap and doesn't touch Claude Code's input window. - src/config.ts: new isContextInjectionEnabled() helper. - src/index.ts: startup banner prints 'Context injection: OFF (default, #143)' on normal startup and a loud WARNING when opt-in is enabled. - test/context-injection.test.ts: 5 subprocess tests that spawn the compiled pre-tool-use.mjs and session-start.mjs hooks, feed real JSON payloads via stdin, and assert stdout is empty in all the off/default paths. Also asserts the disabled path exits under 1s and the opt-in path with an unreachable backend still exits cleanly. - README .env section: new AGENTMEMORY_INJECT_CONTEXT entry. - CHANGELOG [0.8.10] with prominent 'Behavior change' banner. Observations are still captured via PostToolUse regardless of the flag — the memory store and MCP search tools are completely unaffected by this change. The fix only severs the path where agentmemory silently shoves memory context into the user's Claude Code conversation. Bumps to 0.8.10 (main + @agentmemory/mcp shim). Test count: 724 passing (was 719 + 5 new). * chore: rewrite #143 CHANGELOG entry with corrected diagnosis PreToolUse stdout is NOT injected into the model context — per the Claude Code hook docs, only UserPromptSubmit and SessionStart stdout are injected. My initial #143 PR description and CHANGELOG claimed PreToolUse was the smoking gun behind 'Pro allocation burned in 4 messages', which is wrong. What's actually true: - SessionStart stdout injection IS real (~1-2K tokens per session) - PreToolUse stdout goes to debug log only — no tokens - Claude Pro's Claude Code quotas are tight by design (Anthropic has publicly acknowledged this); 4 messages to burn is plausible with or without agentmemory installed The gate on pre-tool-use.ts is still worth keeping as a resource cleanup (skips a 20x-per-message Node+HTTP hot path) and as forward-compat protection in case Claude Code ever changes PreToolUse hook contract. But the CHANGELOG entry has to stop claiming it saves tokens when it doesn't. * fix: mem::retention-evict no longer leaks semantic memories (#124) The eviction loop was unconditionally calling kv.delete(KV.memories, id) for every below-threshold candidate, but retention scores are computed for both episodic (KV.memories) and semantic (KV.semantic) memories. When a candidate came from KV.semantic, the delete silently became a no-op (key wasn't in mem:memories to begin with) and the semantic row stayed alive forever with a sub-threshold score. Semantic memories could not be evicted by this path at all. Fix: - Add a source: "episodic" | "semantic" discriminator to RetentionScore - Tag it at score creation in both loops of mem::retention-score - Branch the delete in mem::retention-evict on candidate.source, routing to KV.memories or KV.semantic accordingly - Pre-0.8.10 retention rows with no source field are treated as episodic for backwards-compat so upgraded stores continue to evict their old rows without re-scoring first - Response now includes evictedEpisodic and evictedSemantic counts so callers can see what was removed from each scope Adds 3 regression tests to test/retention.test.ts: - Scoring tags rows with the correct source - Evicting a mixed set of below-threshold episodic + semantic candidates removes both from their respective scopes - Legacy-shape score rows with no source field still evict to mem:memories (backwards-compat) Full suite: 727 passing (was 724 + 3 new). * review: probe namespaces for legacy retention rows (#124, round 2) CodeRabbit caught a real backwards-compat hole in the #124 fix: pre-0.8.10 stores already contain semantic retention rows with no source field (because the old mem::retention-score scored KV.semantic before the discriminator existed). My first fix defaulted missing source to episodic, which meant those legacy semantic rows still got delete-routed to KV.memories — the exact no-op that stranded them in the first place. Fix: when candidate.source is undefined, probe KV.memories first for the memoryId; if it's there, route to episodic, otherwise route to semantic. Count the resolved source in the response. Adds one new test case: a pre-0.8.10 semantic memory with a legacy-shape retention row (no source field) gets evicted from mem:semantic, not silently no-op'd. Existing 'defaults to episodic' test is kept and retargeted to the genuinely-episodic legacy case. Also fixes a README nit: the AGENTMEMORY_INJECT_CONTEXT comment previously implied SessionStart fires on every tool turn. It's once per session. Now broken out into two bullets explaining what each hook does differently, with the note that only SessionStart actually reaches the model (PreToolUse stdout is debug-log only per Claude Code docs). Full suite: 728 passing (was 727 + 1 new). * review: audit retention evictions + assert persisted source (#124 round 3) CodeRabbit round 3 findings, both real: 1. retention-evict performs structural deletes (memories / semantic / retention scores / access logs) but was not calling recordAudit(). Repo learnings say state-changing functions must be auditable except for read-path bookkeeping. Now emits one batched audit row per non-zero eviction sweep: operation: 'delete' functionId: 'mem::retention-evict' targetIds: every evicted memoryId details: { threshold, evicted, evictedEpisodic, evictedSemantic, reason: 'retention score below threshold' } Zero-eviction sweeps intentionally do NOT write an audit row (no state change, no need to flood the audit log during health checks). 2. The #124 scoring test only checked result.scores (transient response) but not the persisted mem:retention rows. Eviction reads back from stored rows, so a regression in kv.set/serialization would have still passed the old assertion. Now also does kv.get('mem:retention', id) and asserts { source: ... }. Two new tests: - Retention evict with a mixed set of 2 episodic + 1 semantic candidates writes exactly one audit row with all 3 ids in targetIds and the correct evictedEpisodic/Semantic breakdown in details. - Retention evict with zero candidates writes zero audit rows. Full suite: 730 passing (was 728 + 2 new). * review: audit retention-score + parallelize writes (#124 round 4) CodeRabbit round 3 outside-diff findings, both addressed: 1. mem::retention-score was persisting schema-relevant writes to KV.retentionScores (1000+ rows in a mature store) but never called recordAudit(). Per the repo audit-coverage policy, state-changing functions need an audit row. Added a single batched audit event per rescore: operation: 'retention_score' (new audit op — added to the AuditEntry union in types.ts) functionId: 'mem::retention-score' targetIds: [] (intentionally empty — a mature store can have 1000+ ids per sweep; flooding the audit log with every memoryId on every cron tick is worse than recording just the summary counts) details: { total, episodic, semantic, tiers, config } Zero-memory stores intentionally skip the audit call. 2. The per-memory kv.set inside the score loop was O(n) sequential round-trips. Refactored to collect pendingWrites: [id, entry][] while iterating, then flush with Promise.all at the end. On a mature store with 1000+ memories this is ~10x faster (depends on backend pipelining). Test updates: - Added 'mem::retention-score emits audit row per rescore' covering the new audit call, targetIds=[], and details.episodic/semantic. - Existing '#124 audit evict' and 'zero-evict skip audit' tests now filter the audit log by functionId === 'mem::retention-evict' because retention-score also writes one row per sweep now. Full suite: 731 passing (was 730 + 1 new, existing tests retargeted). |
||
|
|
e692cf0095 | feat: implement multimodal image memory | ||
|
|
e8f410b537 |
feat: v0.7.0 — lessons, tool visibility, auto-consolidation, obsidian export, npx bootstrap (#82)
* feat: v0.7.0 — lessons, tool visibility, auto-consolidation, obsidian export, npx bootstrap Five DX improvements based on competitive research against Mem0, Engram, CodeMem: 1. `npx agentmemory` zero-config startup - New CLI bootstrap (src/cli.ts) auto-detects and starts iii-engine - Tries `iii` binary first, falls back to `docker compose up -d` - Bundles iii-config.yaml and docker-compose.yml in dist/ 2. Simplified MCP tool surface (7 core tools by default) - AGENTMEMORY_TOOLS=all unlocks all 49 tools - Default: save, recall, consolidate, forget, sessions, diagnose, lesson_save - Call handler remains unfiltered — any tool callable by name 3. Auto-consolidation on session end - CONSOLIDATION_ENABLED defaults to true (was false) - Session-end hook: session/end → crystallize → consolidate → bridge sync - Consolidation pipeline always registered (timer gated by config) 4. First-class lesson memory type with confidence decay - Lesson interface: confidence (0-1), reinforcements, decayRate, source - 5 functions: lesson-save, lesson-recall, lesson-list, lesson-strengthen, lesson-decay-sweep - Dedup via SHA-256 fingerprint — duplicate saves strengthen existing - Crystal lessons auto-flow into lesson system at confidence 0.6 - Daily decay sweep with parallel KV writes 5. Obsidian-compatible Markdown export - Export to ~/.agentmemory/vault/ with YAML frontmatter + wikilinks - MOC.md (Map of Content) index file - Parallel KV reads, auto-export via OBSIDIAN_AUTO_EXPORT=true Stats: 49 MCP tools, 99 REST endpoints, 573 tests passing * docs: add AGENTS.md, fix tool/endpoint counts across README, plugin, cli - Create AGENTS.md with strict consistency rules for MCP tools, REST endpoints, versions, KV scopes, and audit operations - Fix MCP tool count: 38 → 41 across README.md (4 occurrences) - Fix REST endpoint count: 93/95 → 99 across README.md and index.ts - Fix plugin.json: version 0.6.1 → 0.7.0, tool count 5 → 41 - Fix cli.ts help text: 48+ → 41 MCP tools - Fix README api.ts path reference → triggers/api.ts * fix: address code review findings — consolidation guard, decay bug, async fs, export-import lessons Inline fixes: - Revert CONSOLIDATION_ENABLED to opt-in (=== "true"), matching original behavior - Add early-exit guard in consolidation-pipeline handler when disabled - Gate session-end crystallize+consolidation calls on CONSOLIDATION_ENABLED - Fix lesson decay over-decay bug: add lastDecayedAt to Lesson, compute incremental delta instead of reapplying full age every sweep run - Add LESSON_DECAY_ENABLED flag (default true) to gate the sweep timer Outside diff fixes: - Add lessons to export-import (export + import + replace cleanup) - Log warning instead of swallowing obsidian auto-export errors Nitpick fixes: - Switch obsidian-export to async fs/promises (mkdir, writeFile) - Add per-item try/catch in obsidian-export, return errors array - Replace governance_delete with smart_search in ESSENTIAL_TOOLS (non-destructive default) - Fix CLI whichBinary for Windows (uses "where" on win32) - Use dynamic port in CLI error message instead of hardcoded 3111 - Return 201 for newly created lessons, 200 for strengthened - Wrap lesson audit calls in try/catch so audit failure doesn't surface - Fix build script to not swallow tsdown failure - Remove exact tool count from test, use >=41 + uniqueness + required names - Add test/consistency.test.ts: validates version, tool count, README consistency - Add isConsolidationEnabled mock to consolidation-pipeline test 579 tests passing (573 original + 6 new consistency checks) * fix: guard remaining audit calls, correct endpoint count, add CI + npm publish Review fixes: - Wrap lesson_recall and lesson_strengthen audit calls in try/catch - Fix REST endpoint count: 99 → 100 (verified via grep) across index.ts, README.md, and AGENTS.md - Use regex in consistency test for README assertions (flexible phrasing) - Add consolidation gate tests: disabled returns early, force=true bypasses CI/CD: - Add .github/workflows/ci.yml — test on Node 18/20/22 - Add .github/workflows/publish.yml — auto-publish to npm on GitHub release (uses NPM_TOKEN secret + provenance) Nitpick: - Single-char term filter (t.length > 1) kept intentionally — prevents noise from single-letter matches; documented in AGENTS.md if needed 581 tests passing * fix(ci): add --legacy-peer-deps for zod v3/v4 peer conflict @anthropic-ai/claude-agent-sdk@0.2.56 requires zod@^4.0.0 as a peer dependency but the project uses zod@^3.23.0. The lock file resolves this locally but npm ci is strict about peer deps in CI. * fix(ci): drop Node 18 from matrix — tsdown requires Node 20+ tsdown/rolldown uses node:util.styleText which is only available in Node 20.12+. Updated engines field to >=20.0.0 to match. * fix(ci): add inlineOnly: false to tsdown config, target node20 tsdown errors on CI with "Consider adding inlineOnly option" when dependencies are bundled. Setting inlineOnly: false suppresses this. Also updated target from node18 to node20 to match engines field. |
||
|
|
857f71e3c6 |
feat: v0.6.0 advanced retrieval with real-world benchmarks (#76)
* feat: add 9 orchestration modules for v0.5.0 Add actions, frontier, leases, routines, signals, checkpoints, flow-compress, mesh, and branch-aware modules with full MCP tools, REST endpoints, and 170 new tests. Includes SSRF protection, race-condition-safe keyed mutex locking, SHA-256 fingerprinting, and fixes for 29 CodeRabbit review findings. - 9 new source files (src/functions/*) - 8 new test files (170 tests, total 386) - 10 new MCP tools, 23 new REST endpoints - 8 new KV scopes, new types for orchestration - Version bump to 0.5.0, README and viewer updated * feat: add sentinels, sketches, crystallize, diagnostics, facets modules 5 new modules inspired by beads patterns but with original naming and iii-engine real-time streaming (no polling): - sentinels: event-driven condition watchers (webhook, timer, threshold, pattern, approval) that auto-unblock gated actions via SSE - sketches: ephemeral action graphs with auto-expiry, promote or discard - crystallize: LLM-powered compaction of completed action chains into compact crystal digests with key outcomes and lessons - diagnostics: self-diagnosis across 8 categories (actions, leases, sentinels, sketches, signals, sessions, memories, mesh) with auto-heal - facets: multi-dimensional tagging (dimension:value) with AND/OR queries - 5 new source files, 5 new test files (132 tests, total 518) - 9 new MCP tools (total 37), 21 new REST endpoints (total 93) - 4 new KV scopes (total 33), new types for all modules - README stats and function table updated * fix: address code review findings across v0.5.0 modules - actions: validate edges before persisting, set blocked status for requires deps - leases: use mem:action lock key, reject blocked actions, check expiry on release - checkpoints: validate linkedActionIds exist, check requires edges in unblock - mesh: add SSRF validation on peer registration - routines: remove invalid "failed" action status check - export-import: add v0.5.0 scope export/import (actions, sentinels, sketches, etc) - mcp/server: validate CSV inputs are strings before splitting - schema: replace runtime require with static import - README: fix stale tool/endpoint counts (28→37, 72→93) * fix: second round code review — mesh locks, routines DAG, MCP input validation, README counts - mesh.ts: add withKeyedLock on action writes in receive path, add IPv6 private ranges to SSRF check - routines.ts: validate DAG (duplicate orders, unknown deps), set dep actions to blocked, refresh stepStatus in routine-status - checkpoints.ts: runtime type enum validation, set linked pending actions to blocked - leases.ts: validate ttlMs is finite positive number - export-import.ts: add skip strategy checks for all v0.5.0 import blocks - mcp/server.ts: typeof guards on tags, config JSON.parse, actionIds, linkedActionIds, categories - README.md: Tools 18→37, Functions 33→50, stats line updated - test: update checkpoint test for new blocked-on-create behavior * fix: third round review — lease renew/release safety, mesh locking, export replace cleanup, MCP input guards - leases.ts: renew extends from max(now, existing expiry) instead of now; release verifies action ownership before mutation - mesh.ts: withKeyedLock on memory writes in mesh-receive; applySyncData validates id/updatedAt and locks both memory and action writes - routines.ts: stepStatus maps "blocked" to "pending" explicitly; progress includes blocked/cancelled counts; routine-freeze wrapped in withKeyedLock - export-import.ts: remove unused RoutineRun import; replace strategy clears all orchestration namespaces; skip strategy for graphNodes/graphEdges/semantic/procedural - mcp/server.ts: sentinel_trigger JSON.parse with typeof+try/catch; facet_query typeof guards on matchAll/matchAny; remove redundant requires cast; .filter(Boolean) on concepts/files/tags/requires CSV splits - README.md: clarify API table is a representative subset * fix: fourth round review — redirect SSRF, blocked-on-create, missing action handling, boolean normalization - mesh.ts: add redirect:"error" to both outbound fetch calls to prevent SSRF via redirect - routines.ts: create actions with status "blocked" directly when hasDeps (eliminates two-pass race); handle missing actions in routine-status as cancelled; progress.total uses run.actionIds.length - mcp/server.ts: sentinel config accepts object values directly; normalize unreadOnly/dryRun for both JSON booleans and string values - README.md: consistent bundle size (365KB) across both occurrences * feat: v0.6.0 advanced retrieval — triple-stream search, stemming, real benchmarks Search improvements: - Porter stemmer for word normalization (authentication ↔ authenticating) - 40+ coding-domain synonym groups (db ↔ database, k8s ↔ kubernetes) - Binary-search prefix matching replaces O(n) full scan - Session diversification (max 3 results per session) - Co-occurrence graph edges between all concept pairs New retrieval modules: - Sliding window inference pipeline (context enrichment at ingestion) - Adaptive query expansion (LLM-generated reformulations) - Triple-stream search (BM25 + Vector + Graph with RRF fusion) - Append-only temporal knowledge graph (versioned edges, point-in-time queries) - Graph-augmented retrieval (entity search + neighborhood expansion) - Ebbinghaus retention scoring (decay + tiered hot/warm/cold/evictable) Real-world benchmarks (240 observations, 20 labeled queries): - Quality eval: 64.1% recall@10 with Xenova embeddings (vs 55.8% grep) - Scale eval: 92-100% token savings vs built-in memory at 240-50K observations - Cross-session: 12/12 queries found vs 10/12 for 200-line MEMORY.md cap - Token measurement uses actual search results (fixed fake constant bug) - Removed old microbenchmarks (bench.ts, run-bench.ts, COMPARISON.md) |
||
|
|
709905696b |
fix: package.json paths, standalone shebang, integration tests
- Fix main/bin/start to use .mjs extension (tsdown outputs ESM) - Remove duplicate shebang banner from standalone build config - Update integration test: health status "healthy" (v0.4.0), viewer HTML check - Add POST body to pre-compact hook for claude-bridge sync |
||
|
|
134cf96124 |
feat: agentmemory v0.4.0 — the memory layer for all AI coding agents (#9)
* feat: agentmemory v0.4.0 — the memory layer for all AI coding agents 7 new features: Claude Code memory bridge, standalone cross-agent MCP server, knowledge graph with entity extraction, 4-tier memory consolidation pipeline, team/shared memory, memory governance with audit trail, git-versioned snapshots. 33 functions, 18 MCP tools, 6 MCP resources, 3 MCP prompts, 49 REST endpoints, 21 KV scopes, 216 tests. All features opt-in via env vars. * fix: address 28 CodeRabbit findings across v0.4.0 codebase Critical: Fix bin path mismatch (dist/mcp-standalone.mjs -> dist/standalone.mjs) Bugs: Fix procedural decay, parseFloat||0.5 for zero values, snapshot restore missing graphNodes/observations, git catch too broad, N+1 graph query, BFS duplicate edges, array mutation in audit sort, date validation Improvements: Lazy readline in transport, JSON-RPC validation, persist error handling, ID collision prevention, defensive null coalescing for concepts/files, Windows backslash support in config, direction required for bridge sync tool, try-catch for audit/governance MCP, team profile fallback teamId, POST body for bridge sync hook, observations validation for graph-extract endpoint, await in test |
||
|
|
8b21ae2bf6 |
feat: agentmemory v0.4.0 — MCP resources, prompts, enrichment, confidence (#7)
* feat: agentmemory v0.4.0 — MCP resources, prompts, enrichment, confidence Add 4 MCP resources (status, project profile, recent sessions, latest memories), 3 MCP prompts (recall_context, session_handoff, detect_patterns), confidence-scored memory relations, and a unified enrich endpoint that aggregates file context, relevant observations, and past bug memories for PreToolUse hook injection. - Add confidence field to MemoryRelation with auto-scoring from co-occurrence, recency, and relation type - Add mem::enrich function aggregating 3 sources with resilient .catch() fallbacks - Add POST /agentmemory/enrich REST endpoint - Switch PreToolUse hook from file-context to enrich endpoint with search term extraction - Add minConfidence filter and confidence-desc sorting to mem::get-related - 27 new tests (171 total), all passing * fix: address review findings — input validation, XML escaping, confidence scoring - enrich.ts: Sort bug memories by recency before slicing top 3; add escapeXml() for narratives and bug content injected into XML tags - relations.ts: Use filter+max instead of find() for matchingRelation to pick highest confidence when multiple edges exist; normalize minConfidence with Number.isFinite + clamp to [0,1] - mcp/server.ts: Guard decodeURIComponent with try/catch returning 400 on malformed percent-encoding; use typeof checks for prompt args instead of truthy checks; normalize minConfidence/maxHops at MCP layer - api.ts: Validate files[] and terms[] element types are strings before calling mem::enrich - Tests: Add malformed URI and non-string prompt arg test cases (173 total) |
||
|
|
0e9d5ac76f |
fix: address 12 code review findings across validation, safety, and correctness
- observe.ts: extract fields from sanitizedRaw instead of payload.data - mcp/server.ts: add input validation per tool and try-catch error boundary - api.ts: validate request bodies for /remember, /forget, /migrate - post-tool-failure.ts: truncate tool_input and error to 4000 chars - pre-tool-use.ts: skip "pattern" key for Grep (regex, not file path) - recall/SKILL.md: escape $ARGUMENTS before injecting into curl JSON - consolidate.ts: use ?? instead of || for minObservations, add 30s timeout - file-index.ts: filter sessions by project, cache observations per session - patterns.ts: remove 80-char truncation on error keys - remember.ts: validate content non-empty, skip empty observationIds - index.ts: add missing /generate-rules log line - subagent-stop.ts: normalize timeout to 2000ms |
||
|
|
45795b6033 |
feat: v0.2.0 -- full memory upgrade with 12 hooks, MCP tools, skills, and intelligence
New hooks (7): - PreToolUse: inject file history before edits (Edit/Write/Read/Glob/Grep) - PostToolUseFailure: capture error patterns for learning - PreCompact: preserve memory context through compaction - SubagentStart/SubagentStop: track multi-agent workflows - Notification: capture permission prompts (tool preferences) - TaskCompleted: track team task completions New functions (4): - mem::file-context: file-centric memory index for PreToolUse - mem::consolidate: merge observations into long-term memories via LLM - mem::patterns + mem::generate-rules: detect co-change patterns and recurring errors - mem::remember + mem::forget: explicit save/delete for long-term memory MCP server (2 endpoints): - GET /agentmemory/mcp/tools: list 5 MCP tools (recall, save, file_history, patterns, sessions) - POST /agentmemory/mcp/call: dispatch tool calls to iii functions Skills (4): - /recall [query]: search past observations - /remember [insight]: save to long-term memory - /session-history: show past session timeline - /forget [target]: delete specific memory data New API endpoints (7): - POST /agentmemory/file-context - POST /agentmemory/remember - POST /agentmemory/forget - POST /agentmemory/consolidate - POST /agentmemory/patterns - POST /agentmemory/generate-rules - GET/POST /agentmemory/mcp/* Updated: types (7 new HookTypes, 3 new ObservationTypes), version 0.2.0 |
||
|
|
4c334b0a0e |
fix: system audit -- 10 bugs found and resolved
1. events.ts: Event triggers were calling api:: functions which require ApiRequest shape and auth headers. Rewrote to call core functions (kv.set, sdk.trigger) directly, bypassing auth. 2. All 5 hooks: Missing AGENTMEMORY_SECRET auth header. If secret was set, every hook would get 401 from the API. Now all hooks read AGENTMEMORY_SECRET and send Bearer token. 3. observe.ts: stripPrivateData on JSON string could break JSON structure when replacement text differs in length. Added try/catch fallback to string coercion. 4. post-tool-use.ts: truncate() for objects did JSON.parse(str.slice(0, max-1) + '}') which produces invalid JSON in nearly all cases. Changed to return truncated string. 5. compress.ts: LLM-returned importance was not clamped to 1-10 range. Added Math.max(1, Math.min(10, ...)) with NaN fallback. 6. compress.ts: LLM-returned observation type was not validated against ObservationType union. Invalid types now fall back to "other". 7. context.ts: Token estimate for observation blocks only counted inner content, not the "## Session..." header. Fixed to estimate the full block text. 8. viewer: WebSocket port now configurable via ?wsPort= query param for non-default III_STREAMS_PORT configurations. 9. plugin/scripts: Rebuilt with auth header support matching the updated hook source files. |
||
|
|
6df02d3e20 |
add plugin marketplace install support
- Add .claude-plugin/marketplace.json for /plugin marketplace add
- Build hook scripts into plugin/scripts/ (self-contained)
- Fix hooks.json to use ${CLAUDE_PLUGIN_ROOT} paths
- Update README with plugin install as primary quick start
|