Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add awrshift/claude-memory-kitnpx agentmods add plugins/awrshift/claude-memory-kit/memory-kitgit clone --depth 1 https://github.com/awrshift/claude-memory-kitGrade A, and why
memory-kit scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "memory-kit",
"displayName": "Claude Memory Kit",
"version": "6.2.0",
"description": "Persistent memory for Claude Code agents: a hot cache injected every session and held under three size caps, per-session handoffs, and agent-audited promotion into knowledge articles and rules. Carries the builder's layers too — executor/recon/idea-validator agents, session review, second opinion, agent QA and a system audit — all lazy-loaded skills you only pay for on use.",
"author": {
"name": "awrshift",
"url": "https://github.com/awrshift"
},
"homepage": "https://github.com/awrshift/claude-memory-kit",
"repository": "https://github.com/awrshift/claude-memory-kit",
"license": "MIT",
"keywords": [
"memory",
"context-management",
"session-handoff",
"knowledge-base",
"orchestration",
"agent-qa",
"system-audit"
]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 23 lines scan A 39f8fa422544
memory-kit is a plugin published in the GitHub repository awrshift/claude-memory-kit (31 stars, last pushed 5d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
config-guard
Who guards the guards: a PreToolUse hook that blocks the agent from tampering with its own guardrail configuration. Deny-by-default protection for settings.json, hook scripts and hooks.json manifests, .mcp.json, plugin manifests, and (at strict level) CLAUDE.md and rules/agents/commands, across Bash, Edit, MultiEdit…
dead-end-registry
Approach-level negative-knowledge memory for Claude Code. Mines your transcripts (Stop/PreCompact, both async and zero added latency) for approaches you TRIED and then REVERTED (with the reason, date, and estimated token cost of the detour) into a per-repo registry. On UserPromptSubmit it injects a 'you already tried…
guard-pack
All six guard hooks in one Node process: config-guard, block-dangerous-commands, protect-secrets, protect-tests, git-safety, and case-insensitive-guard, evaluated in that order with the first blocking verdict winning in that guard's own output format. Installing the guards individually costs six Node startups per…
instructions-audit
A prompt-injection tripwire for instruction files. An InstructionsLoaded hook audits CLAUDE.md / .claude/rules/.md content as it enters context and flags hidden or hostile directives: invisible Unicode smuggling (zero width characters, tag characters, variation-selector runs; the TrapDoor supply-chain signature), bidi.
nerf-receipts
A personal flight recorder for Claude Code quality. Background hooks (async, zero added latency) record your own per-session signals keyed by model id and Claude Code version: tool-failure rate, same-file edit churn, turn-end counts, and tokens-per-completed-task. At your next SessionStart (or on demand via…
protect-secrets
A secrets firewall for Claude Code. A PreToolUse hook screens every Read, Edit, Write, and Bash call against tiered patterns (critical/high/strict): sensitive files like .env, SSH keys, AWS/kube/gcloud/docker credentials, and keystores, plus shell commands that expose or exfiltrate them (cat .env, printenv, echo…