Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add awrshift/claude-memory-kitnpx agentmods add plugins/awrshift/claude-memory-kit/marketplacegit clone --depth 1 https://github.com/awrshift/claude-memory-kitGrade A, and why
memory-kit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "memory-kit",
"owner": {
"name": "awrshift",
"url": "https://github.com/awrshift/claude-memory-kit"
},
"description": "Memory for Claude Code agents that survives the session boundary — and the builder's layers distilled from a year of daily production use.",
"plugins": [
{
"name": "memory-kit",
"source": "./plugins/memory-kit",
"description": "Persistent memory for Claude Code: a hot cache under three size caps, per-session handoffs, agent-audited promotion into knowledge and rules — plus the optional orchestration and QA layers as skills you only ever see when you invoke them. Installs into any existing repository.",
"version": "6.2.0",
"author": {
"name": "awrshift"
},
"keywords": [
"memory",
"context-management",
"session-handoff",
"knowledge-base",
"orchestration",
"agent-qa"
]
}
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 28 lines scan A feee9ee82362
memory-kit is a plugin published in the GitHub repository awrshift/claude-memory-kit (31 stars, last pushed 5d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
instructions-audit
A prompt-injection tripwire for instruction files. An InstructionsLoaded hook audits CLAUDE.md / .claude/rules/.md content as it enters context and flags hidden or hostile directives: invisible Unicode smuggling (zero width characters, tag characters, variation-selector runs; the TrapDoor supply-chain signature), bidi.
config-guard
Who guards the guards: a PreToolUse hook that blocks the agent from tampering with its own guardrail configuration. Deny-by-default protection for settings.json, hook scripts and hooks.json manifests, .mcp.json, plugin manifests, and (at strict level) CLAUDE.md and rules/agents/commands, across Bash, Edit, MultiEdit…
config-watch
Tripwire for out-of-band config changes in Claude Code. A ConfigChange hook fires whenever settings (user, project, local, policy) or skills change mid-session, from an installer script, an npm postinstall payload, or any other process rewriting settings while a session runs, and makes the change loudly visible via…
dead-end-registry
Approach-level negative-knowledge memory for Claude Code. Mines your transcripts (Stop/PreCompact, both async and zero added latency) for approaches you TRIED and then REVERTED (with the reason, date, and estimated token cost of the detour) into a per-repo registry. On UserPromptSubmit it injects a 'you already tried…
dead-rules-audit
A CLAUDE.md compliance flight-recorder for Claude Code. At SessionStart it parses CLAUDE.md into numbered atomic rules; on every Edit/MultiEdit/Write a PostToolUse hook (async, zero added latency) passively tallies how often each rule was relevant and whether it was followed or violated; at SessionEnd (or on demand…
format-code
Auto-formats files the moment Claude writes them. A PostToolUse hook on Write|Edit runs ruff (check --fix + format, via uv) on Python and prettier (via npx) on JS/TS/JSON/MD/YAML/HTML, resolving relative paths against the session cwd and passing file paths as argv so shell metacharacters in filenames can never inject…