Skip to content

feat(claude-memory): add stateless skill - #775

Merged
kyle-sexton merged 2 commits into
mainfrom
feat/claude-memory-stateless
Jul 21, 2026
Merged

kyle-sexton merged 2 commits into
mainfrom
feat/claude-memory-stateless

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a second skill to the claude-memory plugin: /claude-memory:stateless — inspect, disable, and (destructively) purge Claude Code auto memory, the notes Claude writes for itself per repo under ~/.claude/projects/<project>/memory/ (relocatable via autoMemoryDirectory). Sibling to the existing audit skill (instruction-layer axis); no overlap.

Actions:

  • status (default, read-only): effective on/off state and store contents resolved across all settings scopes.
  • disable: sets autoMemoryEnabled: false + CLAUDE_CODE_DISABLE_AUTO_MEMORY via a deterministic jq merge in a scope you confirm, and flags a dotfile-manager backfill when the target settings.json is tracked.
  • purge (destructive): reads autoMemoryDirectory at every scope, captures an explicit deletion manifest, flags any candidate dir outside ~/.claude/projects/, and deletes the exact captured paths only after an explicit confirmation gate.

Scope is auto-memory only — the instruction layer (CLAUDE.md / .claude/rules/) stays with audit; transcripts/history are out of scope (auto-cleaned by cleanupPeriodDays). Claude Desktop / claude.ai account memory is server-side, so the skill gives direction-only steps rather than deleting it locally.

No linked issue — planned skill (ledger "Skill K") built as part of the parallel plugin-build batch; not tracked as a GitHub issue.

Precedence (verified this session)

The design ledger flagged env-var-vs-setting precedence as UNVERIFIED. The /en/env-vars doc does document it: CLAUDE_CODE_DISABLE_AUTO_MEMORY "Set to 0 to force auto memory on even when … autoMemoryEnabled: false would otherwise disable it." So the env var overrides the setting — the skill treats a set env var as authoritative in status and writes both levers on disable.

Design notes

  • Repo-agnostic: discovers the consumer's scopes/dirs at runtime; ${CLAUDE_PLUGIN_ROOT} refs only.
  • scope-report.sh reuses the plugin's single-source resolve-memory-dir.sh (point-don't-copy) rather than re-deriving the slug.
  • Bumps claude-memory 0.2.3 → 0.3.0; updates README, CHANGELOG, marketplace tags; regenerates the root catalog.

Verification

  • Independent security review (2 IMPORTANT folded in: exact-manifest deletion instead of a re-glob; relocation flag for dirs outside ~/.claude/projects/) + independent code/design review.
  • Gates green locally: skill-quality:check PASS (0/0), evals schema (check-jsonschema) OK, scope-report.test.sh 13/13, shellcheck + shfmt clean, markdownlint 0 errors, validate-plugins, generate-catalog --check, check-changelog-parity, unique leaf name, portability.

Do not merge — orchestrator merges lanes sequentially.

Related

  • plugins/claude-memory/skills/audit — sibling skill (instruction-layer axis); stateless covers the auto-memory state/lifecycle axis.
  • Official docs consulted: code.claude.com/docs/en/memory, /settings, /env-vars, /skills.

🤖 Generated with Claude Code

Add /claude-memory:stateless for inspecting and disabling Claude Code auto
memory — the notes Claude writes for itself per repo under
~/.claude/projects/<project>/memory/ (relocatable via autoMemoryDirectory).

Actions: status (default, read-only — effective on/off state and store
contents across all settings scopes), disable (autoMemoryEnabled:false +
CLAUDE_CODE_DISABLE_AUTO_MEMORY via a deterministic jq merge in a confirmed
scope, with a dotfile-manager backfill flag), and purge (destructive — reads
autoMemoryDirectory at every scope, captures an explicit deletion manifest,
flags any dir outside ~/.claude/projects/, and deletes the exact captured
paths only after explicit confirmation).

Scope is auto-memory only; the instruction layer stays with the audit skill,
and transcripts/history are out of scope. Per the env-vars doc,
CLAUDE_CODE_DISABLE_AUTO_MEMORY overrides autoMemoryEnabled, so status treats
a set env var as authoritative and disable writes both levers.

scope-report.sh reuses the plugin's single-source resolve-memory-dir.sh.
Bumps claude-memory 0.2.3 -> 0.3.0; updates README, CHANGELOG, marketplace
tags, and regenerates the root catalog.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@claude

claude Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 38s —— View job


PR Review: feat(claude-memory): add stateless skill

Todo:

  • Load review tools
  • Read changed files
  • Review SKILL.md and context docs
  • Review shell scripts (scope-report.sh, scope-report.test.sh)
  • Review evals, plugin.json, CHANGELOG, README
  • Check security, correctness, and repo-agnostic compliance
  • Post final review

Overall Assessment

Strong, security-conscious addition. The three-action design (status / disable / purge) is well-scoped, the TOCTOU avoidance in purge is correctly implemented, the precedence model is accurately documented, and the scope boundary (auto-memory only, not instruction layer or transcripts) is clearly established. Tests pass a 13-check suite and the evals cover the key behavioral fences. Two minor issues found below.


Finding 1 — Test isolation gap in Case 4 (minor)

File: scope-report.test.sh line 79

OUT=$(cd "$REPO" && HOME="$ISO_HOME" bash "$SCRIPT")

Cases 2 and 3 correctly control CLAUDE_CODE_DISABLE_AUTO_MEMORY (env -u to unset, then an explicit =1). Case 4 does neither — if the CI runner happens to export this variable, the env-var section of the output would say "set in OS environment", but the test only asserts on MEMORY.md-related lines so it still passes. The test's implied contract for that case (env var not influencing the MEMORY.md count assertions) holds, but a reader expecting all cases to be independently hermetic would be surprised.

The fix is a one-word addition: prepend env -u CLAUDE_CODE_DISABLE_AUTO_MEMORY to the Case 4 invocation, matching the hygiene of Case 2.

Fix this →


Finding 2 — Multi-scope env block precedence not stated in status.md (minor doc gap)

File: context/status.md line 31–36

"if the env var is set anywhere (OS env or any env block), it is authoritative"

The live OS env var case is unambiguous — only one value. But when CLAUDE_CODE_DISABLE_AUTO_MEMORY appears in env blocks at multiple settings scopes with different values (e.g. user scope says "0", local scope says "1"), the "any env block" phrasing doesn't tell the model which one wins. The correct answer follows normal settings precedence (managed > local > project > user), but a model following only this file could report the wrong effective state or flag a spurious conflict.

The official-guidance.md quotes the settings doc on scope precedence but doesn't explicitly connect that rule to env block resolution. Adding one sentence — e.g. "When multiple env blocks set it, the highest-precedence scope's value governs (managed > local > project > user)" — would close the gap.

Fix this →


Things that are specifically right

  • TOCTOU avoidance (purge.md): The manifest is captured once with find ... -type f, then deleted from that exact list — never re-globbed at deletion time. Symlinks excluded at capture (-type f), so rm -- "$file" on a link removes the link only. Correct.

  • jq merge (disable.md): .env = ((.env // {}) + {"CLAUDE_CODE_DISABLE_AUTO_MEMORY": "1"}) preserves all existing env block entries; only the one targeted key is added or overwritten. The &&/|| guard on mv + rm -f "$tmp" handles both jq failure and mv failure without leaving a stale temp file. Correct.

  • Resolver reuse: scope-report.sh navigates to ../../audit/scripts/resolve-memory-dir.sh from its own directory — no slug re-derivation in the script or the test. The test derives $MEM_DIR from the same resolver with the same HOME, so the test's write target and the script's read target are guaranteed to align.

  • Relocation flag (purge.md): The case "$dir" in "$HOME/.claude/projects/"*) : ;; *) echo "UNEXPECTED RELOCATION" ;; esac guard in the manifest step correctly surfaces autoMemoryDirectory overrides pointing at arbitrary paths before any deletion.

  • disable-model-invocation: false is consistent with the existing audit SKILL.md and confirmed as a recognized field across the plugin fleet.

  • Eval coverage: All six behavioral fences are exercised — read-only default, scope boundary, purge gate, both-levers disable, precedence question, and server-side desktop direction-only. None of the key failure modes are unexercised.

  • repo-agnostic contract: No hardcoded paths, project names, or posture assumptions. All state derived at runtime from ${CLAUDE_PLUGIN_ROOT}, git rev-parse, and the consumer's settings files.


Both findings are non-blocking. The test gap (Finding 1) is the more actionable of the two and has a one-line fix.

@claude

claude Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 22s —— View job


Security Review

  • Gather context and understand the request
  • Read changed files
  • Analyze for security vulnerabilities
  • Post findings

Two security issues found. No CRITICAL issues.


IMPORTANT · HIGH confidence — Path traversal bypass in purge relocation check

File: plugins/claude-memory/skills/stateless/context/purge.md

The PR specifically adds a case-statement guard to flag directories outside ~/.claude/projects/ as suspicious:

case "$dir" in
"$HOME/.claude/projects/"*) : ;; # expected default tree
*) echo "UNEXPECTED RELOCATION: $dir is outside ~/.claude/projects/ ..." ;;
esac

This check uses string prefix matching, not canonicalized path comparison. A project's settings.json with:

{ "autoMemoryDirectory": "~/.claude/projects/../../sensitive-docs/" }

expands (after the model does the ~/ → $HOME substitution called for in Step 1) to:

/home/user/.claude/projects/../../sensitive-docs/

That string starts with $HOME/.claude/projects/, so the case arm : ;; # expected default tree fires silently—no UNEXPECTED RELOCATION warning. The OS then resolves the path to /home/user/sensitive-docs/, and find enumerates *.md files there. After the user confirms (seeing paths that might still look plausible if displayed unresloved), rm deletes them.

The safety guard that the PR description cites as a security improvement is the exact control that fails. The confirmation gate partially mitigates this, but:

  • The model may display the unresolved string (which looks like it is under .claude/projects/) rather than the canonicalized form.
  • There is no indication to the user that the "UNEXPECTED RELOCATION" check ran and found nothing anomalous.

Fix: canonicalize with realpath -m (or readlink -f, with fallback for macOS) before the case check, so .. components are resolved before the string comparison:

real_dir=$(realpath -m "$dir" 2>/dev/null || echo "$dir")
case "$real_dir" in
"$HOME/.claude/projects/"*) : ;;
*) echo "UNEXPECTED RELOCATION: $real_dir ..." ;;
esac
find "$real_dir" ...   # also find on the resolved path

Fix this →


SUGGESTION · MEDIUM confidence — Terminal escape injection via env var echo

File: plugins/claude-memory/skills/stateless/scripts/scope-report.sh line 591

echo "CLAUDE_CODE_DISABLE_AUTO_MEMORY=${CLAUDE_CODE_DISABLE_AUTO_MEMORY} (set in OS environment)"

The raw value of CLAUDE_CODE_DISABLE_AUTO_MEMORY is emitted directly to stdout. Bash's built-in echo does not interpret shell metacharacters so there is no command injection, but the raw bytes are written to the terminal. A value containing ANSI escape sequences (e.g. cursor movement, clear-screen, hyperlink codes) would be interpreted by the terminal emulator and could corrupt the output display or, in edge cases, elicit unsafe terminal responses (e.g. via ESC[5n terminal-status-query sequences on vulnerable terminals).

Expected values are 0, 1, or empty, so exploitation requires a deliberately adversarial environment variable value. Risk is low but the escape is trivially added:

printf 'CLAUDE_CODE_DISABLE_AUTO_MEMORY=%q (set in OS environment)\n' \
  "${CLAUDE_CODE_DISABLE_AUTO_MEMORY}"

printf '%q' shell-quotes the value, neutralizing any escape sequences in the output.

Fix this →


No other security issues found. The TOCTOU mitigation (exact-manifest capture in purge.md), the rm -- "$file" form, -maxdepth 1 -type f in find, the jq atomic-merge pattern in disable.md, and the confirmation gate are all correctly implemented.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4f38d0d37d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread plugins/claude-memory/skills/stateless/scripts/scope-report.sh Outdated
Comment thread plugins/claude-memory/skills/stateless/context/disable.md
Address two review findings on the stateless skill.

1. CLAUDE_CONFIG_DIR relocation. Per the official .claude-directory doc, setting
   CLAUDE_CONFIG_DIR relocates every ~/.claude path — the user settings.json AND
   the projects/<project>/memory/ tree — under that directory. Resolution now uses
   ${CLAUDE_CONFIG_DIR:-$HOME/.claude} wherever scopes/dirs are enumerated:
   scope-report.sh (user scope + reports the resolved root), the shared
   resolve-memory-dir.sh (root-cause fix — both audit and stateless benefit),
   and the disable/purge workflows (including purge's relocation-flag check, so a
   CLAUDE_CONFIG_DIR-relocated tree is expected, not flagged).

2. Create the settings parent directory before writing. The disable jq-merge
   recipe now runs mkdir -p "$(dirname "$settings")" before the write, so a
   project/local scope whose .claude/ does not exist yet no longer fails the mv.

Adds a CLAUDE_CONFIG_DIR regression case to scope-report.test.sh (16 checks) and
a sourced quote to the reference doc.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, you can upgrade your account or add credits to your account and enable them for code reviews in your settings.

@claude

claude Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 2m 28s —— View job


Security Review: feat(claude-memory): add stateless skill

Todo:

  • Load review tools
  • Get PR diff and read changed files
  • Analyze shell scripts for injection surfaces and path handling
  • Analyze context docs (purge.md, disable.md, status.md) for logic flaws
  • Check for unsafe credential/secret handling
  • Check for supply-chain and GitHub Actions patterns
  • Post findings

Two security issues found. Both were flagged in the initial security review on commit 4f38d0d and are still unresolved in the latest commit (705208d). No new issues found in the 705208d changes.


IMPORTANT · HIGH confidence — Path traversal bypass in purge relocation check

File: plugins/claude-memory/skills/stateless/context/purge.md lines 32–37

case "$dir" in
"$config_root/projects/"*) : ;; # expected default (or CLAUDE_CONFIG_DIR-relocated) tree
*) echo "UNEXPECTED RELOCATION: $dir is outside $config_root/projects/ ..." ;;
esac
find "$dir" -maxdepth 1 -type f -name '*.md' 2>/dev/null

The relocation safety check uses string prefix matching on an unresolved path. A settings.json with:

{ "autoMemoryDirectory": "~/.claude/projects/../../sensitive-docs/" }

After Step 1's ~/ → $HOME expansion, this becomes:

/home/user/.claude/projects/../../sensitive-docs/

This starts with $config_root/projects/ (string match passes — : ;; fires, no warning). But find resolves .. at the OS level and enumerates files in /home/user/sensitive-docs/. Those resolved paths populate $manifest, and the confirmation gate shows the unresolved string (which looks benign). After confirmation, rm deletes the files from the resolved location.

The security control the PR description cites is the exact control that fails.

Fix: canonicalize $dir before the case check. The realpath -m flag resolves .. without requiring the path to exist:

real_dir=$(realpath -m "$dir" 2>/dev/null || readlink -f "$dir" 2>/dev/null || echo "$dir")
case "$real_dir" in
"$config_root/projects/"*) : ;;
*) echo "UNEXPECTED RELOCATION: $real_dir ..." ;;
esac
find "$real_dir" -maxdepth 1 -type f -name '*.md' 2>/dev/null

Present $real_dir (not $dir) in the confirmation manifest so users see the canonicalized path they are actually deleting.

Fix this →


SUGGESTION · MEDIUM confidence — Terminal escape injection via unquoted env var echo

File: plugins/claude-memory/skills/stateless/scripts/scope-report.sh lines 78 and 83

echo "CLAUDE_CONFIG_DIR=${CLAUDE_CONFIG_DIR} (config root relocated — ...)"
...
echo "CLAUDE_CODE_DISABLE_AUTO_MEMORY=${CLAUDE_CODE_DISABLE_AUTO_MEMORY} (set in OS environment)"

Raw env var values are emitted directly to stdout. Bash's built-in echo does not interpret shell metacharacters, but the raw bytes reach the terminal emulator. A value containing ANSI escape sequences (cursor movement, clear-screen, or terminal-query sequences like ESC[5n) would be interpreted by the terminal and could corrupt the output display or elicit unsafe terminal responses on vulnerable emulators.

Expected values for CLAUDE_CODE_DISABLE_AUTO_MEMORY are 0 or 1; CLAUDE_CONFIG_DIR is expected to be a directory path. Exploitation requires a deliberately adversarial environment variable. Risk is low but the mitigation is a one-liner:

printf 'CLAUDE_CONFIG_DIR=%q (config root relocated — ...)\n' "${CLAUDE_CONFIG_DIR}"
printf 'CLAUDE_CODE_DISABLE_AUTO_MEMORY=%q (set in OS environment)\n' "${CLAUDE_CODE_DISABLE_AUTO_MEMORY}"

printf '%q' shell-quotes the value, neutralizing embedded escape sequences.

Fix this →


No other security issues found. The TOCTOU avoidance (exact-manifest capture in Step 2), rm -- "$file" form, -maxdepth 1 -type f in find, jq atomic-merge with &&/|| temp-file guard in disable.md, the mkdir -p parent creation, and the CLAUDE_CONFIG_DIR honoring added in 705208d are all correctly implemented. No GitHub Actions patterns or supply-chain risks in the diff.

@claude

claude Bot commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @kyle-sexton's task in 3m 43s —— View job


PR Review: feat(claude-memory): add stateless skill

Todo:

  • Load review tools
  • Read changed files (diff + key files)
  • Review fix commit (705208d — CLAUDE_CONFIG_DIR + mkdir -p)
  • Check outstanding findings from prior reviews
  • Review SKILL.md, context docs, shell scripts, evals
  • Post final review

Overall Assessment

The two-commit PR is well-designed: the first commit delivers the stateless skill, the second addresses the two Codex review findings (CLAUDE_CONFIG_DIR relocation and missing mkdir -p). Those two are confirmed fixed. Four findings from the earlier claude reviews remain open — the most actionable is the path-traversal bypass in purge.md's relocation guard, which is a confirmed security issue.


What the Fix Commit (705208d) Addressed

Both Codex findings are confirmed resolved:

1. CLAUDE_CONFIG_DIR honored — resolve-memory-dir.sh, scope-report.sh, disable.md, and purge.md all now use ${CLAUDE_CONFIG_DIR:-$HOME/.claude} for config root resolution. The regression test (Case 6, 3 new assertions) correctly unsets CLAUDE_CODE_DISABLE_AUTO_MEMORY for isolation and verifies paths resolve under CLAUDE_CONFIG_DIR. Correct.

2. mkdir -p before mv — disable.md:41 now includes mkdir -p "$(dirname "$settings")" before the jq merge, so a local/project scope whose .claude/ directory doesn't exist yet no longer fails. Correct.


Outstanding Findings (from prior reviews — not yet addressed)

1 — Path traversal bypass in purge relocation check · HIGH

File: context/purge.md:33

The fix commit updated $HOME/.claude/projects/ to $config_root/projects/ (correctly handling CLAUDE_CONFIG_DIR), but the underlying issue from the security review is unchanged: the guard is still a string prefix match, not a canonicalized comparison.

An autoMemoryDirectory override like "~/.claude/projects/../../sensitive-docs/" expands to /home/user/.claude/projects/../../sensitive-docs/, which starts with $config_root/projects/ — so the UNEXPECTED RELOCATION warning is silently suppressed. The OS then resolves the path to /home/user/sensitive-docs/, and find enumerates and presents files there for deletion. The confirmation gate shows real absolute paths (find canonicalizes), but the "UNEXPECTED RELOCATION" warning that should have fired did not, giving the user no red flag.

Fix: canonicalize before the case check:

real_dir=$(realpath -m "$dir" 2>/dev/null || readlink -f "$dir" 2>/dev/null || echo "$dir")
case "$real_dir" in
"$config_root/projects/"*) : ;;
*) echo "UNEXPECTED RELOCATION: $real_dir is outside $config_root/projects/ (from autoMemoryDirectory)" ;;
esac
find "$real_dir" -maxdepth 1 -type f -name '*.md' 2>/dev/null

Fix this →


2 — Test isolation gap in Case 4 · minor

File: scripts/scope-report.test.sh:79

OUT=$(cd "$REPO" && HOME="$ISO_HOME" bash "$SCRIPT")

Case 2 and the new Case 6 both correctly unset CLAUDE_CODE_DISABLE_AUTO_MEMORY with env -u. Case 4 does not. The test's assertions only check MEMORY.md and topic-file counts so it passes, but a CI runner with the variable exported would produce an output where the "live environment" section differs from a clean run — the implicit isolation contract of the case breaks. One-word fix, matching the hygiene the other cases demonstrate:

OUT=$(cd "$REPO" && env -u CLAUDE_CODE_DISABLE_AUTO_MEMORY HOME="$ISO_HOME" bash "$SCRIPT")

Fix this →


3 — Multi-scope env block precedence not stated in status.md · minor doc gap

File: context/status.md:32

"if the env var is set anywhere (OS env or any env block), it is authoritative"

When CLAUDE_CODE_DISABLE_AUTO_MEMORY appears in env blocks at multiple scopes with conflicting values (e.g. user scope "0", local scope "1"), the "any env block" phrasing doesn't say which wins. A model following this file could report the wrong effective state. The correct answer follows normal settings precedence (managed > local > project > user), but it needs to be stated. Suggested addition: "When multiple env blocks set it, the highest-precedence scope's value governs (managed > local > project > user)."

Fix this →


4 — Raw env var values echoed to terminal · low/medium

File: scripts/scope-report.sh:78,83

Both env vars are emitted with echo without sanitization. Expected values are short strings (0, 1, or a path), but a deliberately adversarial environment variable containing ANSI escape sequences would be passed to the terminal verbatim. Replace with printf '%q' to shell-quote the values:

# line 78
printf 'CLAUDE_CONFIG_DIR=%q (config root relocated — user scope + memory tree live here)\n' "${CLAUDE_CONFIG_DIR}"
# line 83
printf 'CLAUDE_CODE_DISABLE_AUTO_MEMORY=%q (set in OS environment)\n' "${CLAUDE_CODE_DISABLE_AUTO_MEMORY}"

Fix this →


Minor Documentation Gap

The CHANGELOG.md 0.3.0 Fixed block covers the resolve-memory-dir.sh CLAUDE_CONFIG_DIR fix but omits two other changes from the second commit: the mkdir -p addition to disable.md and the scope-report.sh env-reporting additions. The commit message covers them, but a changelog reader would miss them.


Things That Are Correct

  • CLAUDE_CONFIG_DIR now propagated correctly — resolve-memory-dir.sh uses ${CLAUDE_CONFIG_DIR:-$HOME/.claude} as a single source of truth, both audit and stateless skills benefit.
  • Case 6 test is properly hermetic — correctly uses env -u CLAUDE_CODE_DISABLE_AUTO_MEMORY ... CLAUDE_CONFIG_DIR="$CFG" and asserts the resolved root appears in both user settings and memory dir paths.
  • disable.md jq recipe — mkdir -p guard, atomic mv/rm -f error handling, and additive .env merge are all correct.
  • TOCTOU avoidance in purge — manifest captured once with find -type f, deleted from that exact list, never re-globbed. Symlink exclusion via -type f is correct.
  • Scope boundary and evals — all six behavioral fences exercised; scope table in SKILL.md is accurate.

Finding 1 (path traversal) is the only blocking item. Findings 2–4 are non-blocking but 2 has a one-line fix and 4 is a trivial swap.

@kyle-sexton
kyle-sexton merged commit 88d3c47 into main Jul 21, 2026
22 checks passed
@kyle-sexton
kyle-sexton deleted the feat/claude-memory-stateless branch July 21, 2026 02:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant