跳到主要内容
知仓学习社ZHICANG

agent-memory

Use when a project's CLAUDE.md has grown past what anyone reads and you want the agent to learn durable facts from its own sessions instead — or whe…

改身份文件执行命令读文件写文件严重 0 · 高危 6alirezarezvani/claude-skills

它会碰到什么

扫了多少10 个文本文件,107 KB
它会碰到什么改身份文件执行命令读文件写文件
命中总数14 处
命中统计严重 0 · 高 6 · 中 8 · 低 0
逐条看命中(6 条严重或高危)
  • assets/memory_schema.json:248identity-write
    "$comment": "Enforces the tier-dependent back-pointer format from DESIGN.md section 3.1.1. This is the one promotion rule with PII consequences — an unstripped 
  • scripts/memory_core.py:22identity-write
    stdlib only. No LLM calls (root CLAUDE.md anti-pattern).
  • scripts/memory_promote.py:22identity-write
    Nothing is written to CLAUDE.md. Promotions land in .memory/staged/ for an
  • scripts/memory_promote.py:247identity-write
    print("\nNothing was written to CLAUDE.md. Promotions stage for `adopt` (5.3).")
  • scripts/validate_examples.py:336identity-write
    # figure against the live byte count of repo-root CLAUDE.md: that file gets
  • scripts/validate_examples.py:345identity-write
    "the CLAUDE.md size claim names `wc -c` and cites a byte figure")

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Agent Memory — promotion is earned, not asserted

> Portability: stdlib only. No database, no embeddings, no network, no LLM calls.

The problem

A project's CLAUDE.md is a memory system with one tier and no eviction: every

durable fact and every passing preference land in the same always-loaded file,

until the important lines are diluted by the incidental ones. Facts learned

mid-session vanish at teardown unless someone writes them down.

The fix is not more storage — it is a promotion ladder. A claim earns its

way toward always-loaded context by recurring; a human confirms the last step.

The four tiers

Tiers are distinguished by injection policy, not storage format.

| Tier | Holds | Injected | Committed |

|---|---|---|---|

| L0 | raw session transcripts | never | no (already on disk) |

| L1 | candidate atoms | on relevance, at prompt time | no (gitignored) |

| L2 | this project's context | every session start | yes, after adopt |

| L3 | stable cross-project persona | always | yes, after adopt |

The gates

Nothing moves up because it sounded important. It moves up because it recurred.

  • L0 → L1 — an explicit marker fires (a directive, a correction, a stated

preference, a named lesson, a reproducible failure). Rule-based, high

precision, deliberately low recall.

  • L1 → L2 — ≥ 3 distinct sessions spanning ≥ 2 distinct calendar days. A

claim stated outright needs 2 sessions; the distinct-day rule still applies. A

verified claim promotes on one observation and is the only day-exempt path.

  • L2 → L3 — held in ≥ 2 distinct projects, aged ≥ 30 days, uncontested.

Two gates refuse rather than guess. A claim whose text was altered by

redaction never promotes on evidence alone — the flag firing is evidence the

source was sensitive, and a lexical filter finding one secret is not proof it

found all of them. A claim with an open contradiction is frozen at L1 until a

human resolves it; the incumbent is never silently overwritten.

Use it

# what is remembered, and what is blocking the next promotion
python3 scripts/memory_inspect.py --tier L1

# where did this line come from — sessions, days, transcript, quoted source
python3 scripts/memory_inspect.py --why "PR base branch is dev"

# every claim with an open contradiction, both directions of the join
python3 scripts/memory_inspect.py --contested

# dry-run the promotion pass; writes nothing
python3 scripts/memory_promote.py

Three hooks run the loop unattended: SessionStart injects L2 + L3,

UserPromptSubmit recalls relevant L1 atoms, SessionEnd captures and stages.

Each is disabled independently with AGENT_MEMORY_SESSIONSTART=0,

AGENT_MEMORY_USERPROMPTSUBMIT=0, AGENT_MEMORY_SESSIONEND=0. Every hook fails

open: a broken memory system costs you memory, never a session.

Hard rules

  1. Redact before writing. Every atom passes the filter before it reaches

disk. Anything altered is quarantined from promotion.

  1. Propose, never apply. Promotions land in .memory/staged/. Only an

explicit /cs:memory adopt touches a CLAUDE.md, and it backs both up first.

  1. Cite, don't invent. Every atom carries a back-pointer to the transcript

line that produced it. --why resolving to ambiguous prints nothing rather

than guess: a wrong citation is worse than a missing one.

  1. Never surface a contested claim as fact. It is still injected — hiding

the conflict is worse — but always tagged.

  1. The committed tiers carry no paths. Promotion strips the back-pointer

prefix, which embeds an OS username.

Forcing questions

Walk these one at a time before trusting the store.

  1. Which line in your CLAUDE.md did you last actually read before acting?
  2. Would you rather the agent forget a true thing, or remember a false one?
  3. When two remembered rules disagree, who decides — and when?
  4. What would make you delete .memory/ entirely?

Rationale, open decisions, field schema: [../../DESIGN.md](../../DESIGN.md).

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 26,030
本站分层T1
该仓技能数846
原文件路径engineering/agent-memory/skills/agent-memory/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 846 个技能

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 agent-memory 的技能。它们内容并不相同,别混用: