Skip to content
CAI
Software that uses CAICheck a score

thedotmack/claude-mem

49.1

Weak · 25 September 2026

105.7k

lines of production code

TypeScript

with JavaScript

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Claude-Mem is a local-first memory and context injection system that captures, stores, and retrieves AI agent observations to provide persistent context across coding sessions. It integrates with various IDEs and CLI tools via platform-specific adapters, utilizing a modular worker architecture to process data through SQLite or Postgres backends and vector search. The system supports real-time observation streaming, multi-device synchronization, and server-side generation capabilities, enabling agents to recall past interactions and maintain continuity.

Features

Add Claude-Mem plugin with observation feed and memory sync

The OpenClaw plugin now registers a persistent memory service that syncs to MEMORY.md, injects context via the system prompt, and supports an optional SSE-based observation feed to notify channels like Telegram or Discord. It registers commands (e.g., /claude\_mem\_feed) to show feed status and toggle it, and hooks into session lifecycle events (session\_start, after\_compaction, before\_agent\_start, before\_prompt\_build, tool\_result\_persist, agent\_end, gateway\_start) to maintain memory and emit observations. Configuration includes enabling the feed, specifying the target channel and recipient, bot token, and emoji styling for feed messages.

openclaw/src · high confidence

Add Observation TV viewer and status icons

The plugin UI now includes a web-based viewer for real-time memory streams, accessible via the new \tv.html\ page which displays observation cards with project and source metadata, supports Picture-in-Picture and full-screen modes, and uses a token for secure remote access. Additionally, four new SVG icons (\icon-thick-completed\, \icon-thick-investigated\, \icon-thick-learned\, \icon-thick-next-steps\) have been added to the \plugin/ui\ directory to support status indicators within the interface.

plugin/ui · high confidence

Add OpenCode plugin integration

Introduces a new plugin in src/integrations/opencode-plugin that hooks into OpenCode's tool execution and chat message events to capture session activity and forward it to the configured worker endpoint, including proper handling of session initialization and platform source stamping.

src/integrations · high confidence

Add native adapters for Antigravity, Claude Code, Codex, Cursor, and Windsurf

The CLI now includes dedicated platform adapters that translate hook inputs and outputs for Antigravity, Claude Code, Codex, Cursor, and Windsurf. These adapters normalize incoming hook data (such as session IDs, prompts, and tool calls) and format outgoing responses to match each platform's specific protocol requirements, enabling the CLI to integrate with these external AI coding tools.

src/cli/adapters · high confidence

Add script to generate OpenRouter list-price history for expense reports

A new build script (\scripts/openrouter-price-history/build-dataset.py\) and supporting source data (price ledgers, popularity eras, aliases, and work days) have been added to generate daily OpenRouter list-price datasets. This tool expands vendored price change-points into a daily join table covering July 1 to September 8, 2026, outputting JSON and CSV files to \docs/expense-pricing/\ to support expense reporting and cost analysis.

scripts/openrouter-price-history · high confidence

Added SQLite observation file parsing utility

The plugin/sqlite/observations module now includes a new files.js module that provides a parseFileList function. This utility handles parsing of file list data from the SQLite observations store, supporting both JSON array formats and single string paths, with fallback handling for non-JSON values. The module also includes logging infrastructure for debugging and error tracking within the observations plugin.

plugin/sqlite/observations · high confidence

Added sync-hub canary script for convergence and watchdog testing

A new standalone Bun script (\canary.ts\) has been added to the sync-hub canary location to exercise the HTTP sync lanes. This tool simulates a synthetic user with two device identities to assert that operations converge within a defined time bound, helping detect regressions in HTTP path handling. It also supports a 'flood' mode to deliberately trigger watchdog request-count thresholds, allowing teams to rehearse end-to-end alert chains and verify hibernation-defeat detectors without relying on WebSocket-lane monitoring.

workers/sync-hub/canary · high confidence

Anonymous usage analytics shipped with PostHog integration and strict privacy controls

The application now collects anonymous usage analytics via PostHog to support product growth and retention insights. This feature includes a new default opt-out policy (telemetry is off unless explicitly enabled), a robust consent system respecting the DO\_NOT\_TRACK environment variable, and a comprehensive privacy scrubber that whitelists event properties and redacts PII from error messages. The implementation features a CLI telemetry module for installer events, a buffering system that aggregates high-volume data into 5-minute or per-session rollups to reduce costs, and a one-time historical backfill of anonymized daily activity. Users can control data sharing via environment variables or configuration files, and error tracking is independently gated to allow opting out of error text while keeping anonymous counters.

src/services/telemetry · high confidence

Automated bug report generation using Claude Agent SDK

A new \scripts/bug-report\ tool has been added to automatically generate structured GitHub issue reports. The CLI collects system diagnostics—including versions, platform details, worker health, database table counts, and logs—and uses the Claude Agent SDK to format these details into a professional Markdown issue, including automatic translation of user descriptions to English. A template-based fallback is provided if the SDK call fails.

scripts/bug-report · high confidence

Durable tool\_uses backup index and get\_tool\_uses disclosure

The SQLite plugin now persists tool usage data in a dedicated \tool\_uses\ table with a durable backup index, making historical tool interactions queryable via the \get\_tool\_uses\ API. This change ensures that tool inputs, responses, and metadata are reliably stored and retrievable, enhancing observability and debugging capabilities for users.

plugin/sqlite · high confidence

Hackathon documentation and scoring materials for Claude-Mem

Added a set of five markdown files in the plans/hackathon directory to support the $1,000 Memory Prize hackathon. These include a field guide explaining the two-agent architecture, a cheat sheet, a step-by-step tutorial, the prize challenge description, and a detailed scorecard evaluating seventeen hackathon submissions. The scorecard assesses projects on integration depth, category fit, functionality, usability, and honesty, providing specific feedback on how each project utilized Claude-Mem's observation, timeline, and search capabilities.

plans/hackathon · high confidence

Interactive custom mode creation with optional Telegram alerts

Users can now create, install, and activate custom observation modes through an interactive interview process that proposes a domain-specific taxonomy of note types and concept tags. The new mode-creator skill guides users through drafting and validating the mode, optionally configuring Telegram notifications for specific observation types or concepts, and verifying the active mode in the startup context. This capability is delivered via the mode-creator skill definition, evaluation scripts, authoring references, and Node.js helper scripts for secure Telegram setup and mode installation.

plugin/skills/mode-creator · high confidence

Introduce AST-based code navigation and secure file access in smart-file-read

The smart-file-read service now provides AST-based code navigation, allowing users to explore code structure (functions, classes, interfaces, etc.) across 24 languages including PHP, Markdown, and SQL, rather than relying on simple text search. This new capability is powered by a new parser module that compiles tree-sitter grammars for efficient symbol extraction. Additionally, the service introduces a secure path-resolution mechanism that prevents directory traversal attacks, ensuring that file reads are strictly confined to the workspace directory.

src/services/smart-file-read · high confidence

Introduce Bun runtime support with cross-platform launcher and settings defaults

The plugin now supports running scripts via the Bun runtime. A new \bun-runner.js\ script acts as a cross-platform launcher that detects the Bun executable (handling Windows \bun.exe\/\bun.cmd\ resolution and avoiding \cmd.exe\ shell limits) and forwards stdin to the target script. Additionally, \context-generator.cjs\ has been updated to include a comprehensive \SettingsDefaultsManager\ that defines default values for all plugin configuration keys (such as model selection, Chroma settings, and telemetry options) and handles loading them from the user's settings file.

plugin/scripts · high confidence

Introduce CLI and watcher for configurable transcript ingestion

A new transcript service has been added, providing a CLI (\claude-mem transcript\) with \init\, \watch\, and \validate\ subcommands to manage file-based transcript watching. The system introduces a JSON configuration schema (\TranscriptWatchConfig\) that allows users to define watch targets, file paths, and event schemas. It includes a \FileTailer\ for streaming file reads, a \TranscriptEventProcessor\ to parse and route events (such as session init, user/assistant messages, and tool use), and logic to handle Codex-specific context suppression and native hook detection. This enables the platform to ingest and process external transcript data streams via a standardized, configurable pipeline.

src/services/transcripts · high confidence

Introduce Claude-Mem OpenClaw plugin with installer and E2E testing

The openclaw directory now contains the complete distribution package for the Claude-Mem plugin, enabling persistent memory and real-time observation streaming for OpenClaw agents. This includes the plugin manifest (openclaw.plugin.json) defining configuration options such as worker host/port, project scoping, and observation feed channels (Telegram, Discord, Slack, etc.), alongside a comprehensive one-line installer (install.sh) that handles dependency checks, plugin registration, and interactive setup. To ensure reliability, the release ships with a Docker-based end-to-end test suite (Dockerfile.e2e, test-e2e.sh, e2e-verify.sh) that validates plugin loading, SSE stream connectivity, and gateway integration in a clean environment.

openclaw · high confidence

Introduce Claude-Mem plugin for Cowork cloud sessions

Adds the \claude-mem-cowork\ plugin, enabling memory capture and injection for ephemeral Cowork cloud sessions. The plugin replaces the local worker with HTTP shims that stream tool-use observations to cmem.ai (where Pro runs the observer server-side) and injects compiled context back into new sessions and spawned agents. It includes hook definitions, a configuration file, a setup skill, a search skill, and a test suite verifying observation capture, secret redaction, and context injection.

cowork · high confidence

Introduce Knowledge Agents for querying corpora from claude-mem

Added a new Knowledge Agent system in the worker service that allows users to build, store, and query structured corpora of observations. The implementation includes a CorpusBuilder to aggregate observations based on filters (project, types, concepts, files, date range), a CorpusRenderer to format these into text and system prompts, and a CorpusStore for file-based persistence with strict name validation (returning 400 errors for invalid names). The KnowledgeAgent class orchestrates interaction with the Claude SDK, supporting priming a session with a corpus, querying it, and automatically handling session expiration by re-priming when necessary.

src/services/worker/knowledge · high confidence

Introduce native Codex hooks integration and CLAUDE.md management commands

This change adds the core CLI infrastructure for native Codex hooks integration, including new files in src/cli (hook-command.ts, stdin-reader.ts, types.ts) that handle hook execution, stdin safety, and platform adapters. It also introduces the claude-md-commands.ts file, providing generate and clean CLI commands for managing CLAUDE.md files, including auto-generated recent activity sections based on observation history. The hooks implementation includes improved resilience with fail-open behavior for malformed input, worker-unavailable error classification, and stderr buffering to prevent log leakage into model context.

src/cli · high confidence

Introduce shared server-side generation infrastructure for provider adapters

Added a new shared module in \src/server/generation/providers/shared\ that provides the core building blocks for server-side AI generation, decoupling it from the worker implementation. This includes \error-classification.ts\ for standardizing HTTP error handling (e.g., quota, rate limits, auth) into a unified \ServerClassifiedProviderError\ model, \prompt-builder.ts\ for constructing privacy-compliant XML prompts from agent events, and \types.ts\ defining the \ServerGenerationContext\ and \ServerGenerationProvider\ interfaces used by Gemini and OpenRouter adapters.

src/server/generation/providers/shared · high confidence

Introduce web-based viewer UI for real-time memory stream

Adds a new React-based web viewer application located in src/ui/viewer that connects to the backend via Server-Sent Events (SSE) to display live memory data. The interface provides a paginated feed of observations, summaries, and user prompts, allowing users to filter content by project. It includes a Context Settings modal for configuring AI provider options (such as Gemini and OpenRouter), a theme toggle for light/dark/system preferences, and a console logs drawer for debugging. The viewer also features a welcome card for first-time users and handles real-time queue depth indicators.

src/ui/viewer · high confidence

Introduce web-based viewer UI with session settings, live feed, and theme controls

The viewer now includes a new web-based interface for monitoring real-time memory streams. Users can access a Context Settings Modal to adjust memory injection parameters and preview terminal output, while the main feed displays observations, summaries, and prompts with infinite scroll and a scroll-to-top button. The header provides project filtering, a 7-day Pro trial call-to-action, and a theme toggle for light, dark, and system preferences. Additional UI enhancements include a GitHub stars button, a spinning favicon during processing, and a welcome card that explains the live feed, tuning, and recall features.

src/ui/viewer/components · high confidence

Introduces canonical v2 sync protocol with hub push/pull transport and mutation outbox

This change implements the canonical v2 projection pipeline for cloud synchronization, introducing a new wire format that enforces deterministic JSON serialization (sorted keys, decimal strings for large integers) and SHA-256 operation hashing to ensure data integrity. It adds a hub push/pull transport mechanism that drains local SQLite changes to the sync hub and applies remote changes with crash-safe, exactly-once semantics. The update also includes a mutation outbox for handling operations like title changes and project remaps, ensuring they are correctly sequenced and applied across devices.

src/services/sync · high confidence

Introduces embedded Process Supervisor for unified lifecycle management

Adds a new embedded Process Supervisor in src/supervisor that centralizes worker and child-process lifecycle management. It includes an environment sanitizer to prevent sensitive variables (like CLAUDE\_CODE\_EFFORT\_LEVEL) from leaking into SDK subprocesses, a process registry with identity validation to handle PID reuse, a health checker to prune dead entries, and a boot-time sweep to reap orphaned chroma-mcp process trees. The supervisor also manages signal handling and a structured shutdown cascade to ensure clean process termination.

src/supervisor · high confidence

Introduction of a configurable Mode system with inheritance support

The domain service now includes a new ModeManager that loads and manages operational modes defined by JSON configuration files. Users can define custom modes with specific observation types, concepts, and prompt templates. The system supports a single level of inheritance (e.g., 'parent--override'), allowing new modes to extend existing ones by merging configurations. Modes are loaded from user data directories, plugin directories, or development paths, with a fallback to a default 'code' mode if a specified mode is not found.

src/services/domain · high confidence

Legacy session adapters and v1 route implementations for Postgres and SQLite backends

This change introduces the route handlers and compatibility adapters that expose the server's capabilities. For the new Postgres-backed runtime, it adds \ServerV1PostgresRoutes\ which implements the v1 API (including usage metering, key issuance, and rate limiting) and \SessionsObservationsAdapter\/\SessionsSummarizeAdapter\ to translate legacy \contentSessionId\ payloads into the new event model. For the existing SQLite runtime, it adds \ServerV1Routes\ to handle the same core endpoints (sessions, events, memories) using the SQLite storage layer.

src/server/routes · high confidence

New ASCII animation banner for the npx CLI

The npx CLI now displays a custom animated banner during startup. This feature is implemented in the new \banner-frames.ts\ file, which defines a \BannerData\ interface and a \BANNER\ constant containing gzip-deflated, base64-encoded ASCII animation frames. The animation is rendered offline from a webm video using a luminance ramp, providing a visual enhancement to the command-line experience.

src/npx-cli · high confidence

New HTTP API routes for worker management and data access

The worker service now exposes a comprehensive set of new HTTP endpoints for managing and inspecting its internal state. Users can check the health and configuration of Chroma and CloudSync via /api/chroma/status and /api/sync/status, manage knowledge corpora (build, query, delete) through /api/corpus, and access raw data including observations, summaries, prompts, and tool uses via /api/observations, /api/summaries, /api/prompts, and /api/tool-uses. Additional endpoints allow saving manual memories (/api/memory/save), viewing and clearing logs (/api/logs), and managing settings and provider status (/api/settings, /api/mcp/status). The search and context injection logic has also been consolidated into new /api/search and /api/context routes.

src/services/worker/http/routes · high confidence

New IDE and CLI integrations with dedicated installation and configuration logic

The integration service now includes dedicated installers and configuration modules for the Antigravity CLI, Codex CLI, Cursor, and Grok Bot. These additions handle platform-specific path resolution (including Windows 8.3 short paths and macOS app bundles), write IDE-specific hook configurations (such as \hooks.json\ for Cursor and Antigravity), and manage local data structures like the CCS Align middle cache and Grok Bot awareness logs. This expands the system's ability to automatically configure and maintain memory context across a broader range of development environments.

src/services/integrations · high confidence

New README translation script with multilingual support and caching

A new CLI tool and library (\scripts/translate-readme\) has been added to automatically translate README.md files into multiple languages using the Claude Agent SDK. Users can now generate localized documentation via command-line arguments or programmatically, supporting over 30 languages including Chinese, Urdu, and others. The tool features parallel translation execution, a local cache to avoid re-translating unchanged content, budget controls, and the ability to reference existing translations for improved consistency. It supports various authentication methods, including local Claude Code sessions, API keys, AWS Bedrock, and Google Vertex AI.

scripts/translate-readme · high confidence

New SQLite-based server storage layer for projects, sessions, and authentication

The server now persists core data using a new SQLite backend located in src/storage/sqlite. This introduces dedicated repositories for managing projects, server sessions, agent events, and memory items, alongside a new AuthRepository that handles API key lifecycle management (creation, revocation, usage tracking) and audit logging. The implementation includes a comprehensive database schema with foreign keys, constraints, and indexes, as well as an FTS5 virtual table to enable full-text search across memory items.

src/storage/sqlite · high confidence

New agent processing and SSE broadcasting infrastructure

The worker agent layer now includes dedicated modules for handling agent responses and broadcasting events via Server-Sent Events (SSE). A new ResponseProcessor extracts file evidence (reads and modifications) from tool usage observations, while an ObservationBroadcaster sends new observations and summaries to connected clients, respecting project tracking settings. Supporting utilities include an AbortError checker and type definitions for worker references and SSE payloads.

src/services/worker/agents · high confidence

New anti-pattern detection script for error handling

A new script, \scripts/anti-pattern-test/detect-error-handling-antipatterns.ts\, has been added to automatically scan the codebase for fragile error handling practices. This tool identifies specific anti-patterns such as detecting error types via string matching (e.g., \error.message.includes(...)\), logging only partial error messages instead of the full error object, guessing error types through multiple string checks, and using empty promise catch handlers. The script supports an override mechanism using \\[ANTI-PATTERN IGNORED\]\ comments for approved exceptions, particularly in critical paths like provider implementations and session stores.

scripts/anti-pattern-test · high confidence

New build, validation, and operational scripts for hooks, workers, and UI

The scripts directory now includes a comprehensive set of new tooling: build-hooks.js generates hook and MCP server bundles with strict integrity checks to prevent build-path leaks; build-viewer.js compiles the React-based memory viewer UI; and build-worker-binary.js produces a standalone Windows executable for the worker service. Operational discipline is enforced by check-hook-io-discipline.cjs (ensuring handlers don't write directly to streams) and check-spawn-env-discipline.cjs (preventing credential leakage in subprocesses). User-facing management is improved with check-pending-queue.ts and clear-pending-queue.ts for monitoring and clearing the worker's message queue, while export-memories.ts allows users to export their memory data. Additional scripts include claude-mem-sync for cross-machine database synchronization, check-postinstall-allowlist.js to prevent CI hangs from unexpected dependency scripts, discord-release-notify.js for automated release announcements, and e2e-server-docker.sh for end-to-end testing of the new Docker-based server architecture.

scripts · high confidence

New changelog generation script for release notes

A new Node.js script, generate\_changelog.js, has been added to the version-bump plugin to automate the creation of project changelogs. This tool reads release data from standard input (expecting a JSON array of release objects) and outputs a formatted Markdown changelog file, including the release tag, publication date, and body text for up to the 50 most recent releases.

plugin/skills/version-bump/scripts · high confidence

New claude-mem Docker harness for local end-to-end testing

Adds a new Docker-based development harness in docker/claude-mem that packages the server-beta runtime, Bun, uv, and the Claude Code CLI into a single container for local end-to-end testing. The harness includes a Dockerfile, build/run scripts, and an entrypoint that supports server, worker, and shell modes, along with a dedicated E2E test driver (docker/e2e/server-e2e.mjs) that validates the server-beta API endpoints, authentication, and BullMQ/Redis health.

docker · high confidence

New core data schemas and worker lifecycle management services

This change introduces a new set of Zod-based data schemas in src/core/schemas/ (covering agent events, authentication, memory items, projects, sessions, and teams) to standardize data validation and typing. It also adds new service modules in src/services to manage the worker lifecycle: worker-spawner.ts handles daemon spawning and health checks, worker-shutdown.ts manages graceful shutdowns and restart handoffs, restart-verify.ts validates successful worker restarts, and context-generator.ts provides context injection utilities. These additions support a more robust and verifiable worker process management system.

src/services · high confidence

New database schema types and shell-quote type definitions

Added new TypeScript type definitions for the database layer in src/types/database.ts, introducing interfaces for table column info, indexes, schema versions, and specific record types for observations, session summaries, and user prompts (including platform source and memory session ID fields). Additionally, added type declarations for the shell-quote module in src/types/shell-quote.d.ts to provide proper typing for command parsing.

src/types · high confidence

New email investigation batch processor

Added a new \ragtime\ tool that processes email corpus files using Claude's email-investigation mode to extract entities, relationships, and timeline events. The processor runs in self-iterating loops with automatic transcript cleanup and configurable settings via environment variables.

ragtime · high confidence

New hook handler system for session lifecycle and file context

The CLI now uses a new set of pure hook handlers in src/cli/handlers to manage session lifecycle and file context. The context handler injects session-start context and trial banners while respecting project exclusions. The file-context handler deduplicates file observations per session using a SQLite gate to prevent redundant context injection. The session-init, observation, summarize, and session-end handlers route events to the worker or server runtime, with fallback logic for reliability. The file-edit handler records file modifications as observations. These handlers replace previous ad-hoc implementations with a consistent, testable, and resilient architecture.

src/cli/handlers · high confidence

New npx claude-mem CLI with diagnostic, IDE detection, and server management commands

The \src/npx-cli/commands\ directory now provides a comprehensive CLI interface for managing the claude-mem plugin. Users can run \npx claude-mem doctor\ to perform a read-only diagnostic check of the runtime environment (Bun, uv, plugin status, worker health, and Windows Git Bash availability) without mutating state. The \npx claem ide-detection\ command identifies installed IDEs (such as Claude Code, Cursor, Codex, and Windsurf) to inform integration. The \npx claude-mem server\ command exposes lifecycle management (start, stop, restart, status) and operator tools for the Postgres-backed server runtime, including API key rotation and a job queue console (\server jobs\) for managing generation tasks. Additionally, the \npx claude-mem telemetry\ command allows users to view and manage anonymous usage analytics consent.

src/npx-cli/commands · high confidence

New observation generation worker with bounded session inputs and post-commit metering

Introduces the ProviderObservationGenerator worker and its supporting processGeneratedResponse logic to handle server-beta observation generation jobs. The worker now bounds session-summary input by payload size (keeping head and tail of events) to prevent context window overflows, validates job payloads against a strict schema to reject tampered or malformed requests, and records usage metering only after the main database transaction commits to ensure observation persistence is never rolled back by metering failures.

src/server/generation · high confidence

New queue health monitoring and Redis configuration for BullMQ

The server now exposes detailed health status for the BullMQ observation queue via the /api/health endpoint, including per-lane job counts (waiting, active, completed, failed, delayed, stalled) and Redis connection details, allowing deployment probes to monitor queue saturation and engine availability. Additionally, the system introduces configurable Redis connection settings (host, port, URL, prefix, mode) for the observation queue, supporting external, managed, or Docker-hosted Redis instances, with validation for environment variables and file-based defaults.

src/server/queue · high confidence

New remote recall MCP server for hosted access

A new \createRecallMcpServer\ factory has been added to expose read-only recall tools (\search\, \context\, \recent\) via the Model Context Protocol. This allows hosted environments to provide the same memory retrieval capabilities as the local CLI, ensuring that pasted recall links and hosted interactions access identical data. The implementation is designed to be injected with a scoped backend, keeping the server layer pure and testable while handling tool dispatch and error reporting.

src/server/mcp · high confidence

New server runtime support for hooks with local API key bootstrap

Hooks can now operate in a 'server' runtime mode, allowing them to communicate directly with the server's /v1 REST endpoints instead of relying on the local worker process. This change introduces a runtime selector that respects the \CLAUDE\_MEM\_RUNTIME\ setting (accepting both the new 'server' value and the legacy 'server-beta' for compatibility) and reads configuration from new canonical keys (\CLAUDE\_MEM\SERVER\\\) while falling back to legacy \\\BETA\\*\ keys. A new bootstrap mechanism provisions local API keys with specific scopes (events:write, sessions:write, etc.) into the user's settings file with restricted permissions (0600). The server client handles authentication, timeouts, and error-based fallback to the worker path, and supports new capabilities like recording events with optional generation control and inserting/searching observations via the /v1/memories endpoint.

src/services/hooks · high confidence

New server-beta middleware suite for authentication, rate limiting, and usage tracking

The server-beta runtime introduces a new set of middleware components in src/server/middleware to handle core operational concerns. Authentication is now managed by dedicated middlewares (auth.ts and postgres-auth.ts) that support both SQLite and Postgres backends, accepting Bearer tokens with X-Api-Key as a fallback and allowing local-dev bypass under specific conditions. Rate limiting and monthly usage quotas are enforced via new middleware (rate-limit.ts) that tracks per-key request counts and per-team monthly caps, failing open to avoid service disruption. Additionally, request metering (usage-metering.ts) records request counts for usage tracking, and request ID generation (request-id.ts) ensures traceability across logs and services.

src/server/middleware · high confidence

New server-side observation providers for Claude, Gemini, and OpenRouter

The server now includes dedicated observation providers for Anthropic Claude, Google Gemini, and OpenRouter, enabling server-side generation capabilities. The Claude provider defaults to the 'claude-sonnet-5' model to avoid 404 errors from stale IDs, while the Gemini provider targets the 'gemini-flash-latest' model via the v1beta API to ensure compatibility with new keys. The OpenRouter provider supports a configurable base URL, allowing requests to be routed to custom endpoints like DeepSeek or LM Studio, in addition to the standard OpenRouter service. All providers implement specific error classification for better debugging and handle privacy-scoped memory contexts.

src/server/generation/providers · high confidence

New shared infrastructure for secure credential management and crash-safe settings

The \src/shared\ directory now includes a suite of new modules that centralize and harden core operations. \EnvManager.ts\ introduces a strict security boundary for API keys, loading credentials exclusively from \\~/.claude-mem/.env\ and blocking sensitive environment variables (like \ANTHROPIC\_API\_KEY\ and \ANTHROPIC\_BASE\_URL\) from leaking into SDK subprocesses. \SettingsDefaultsManager.ts\ provides a unified source for all configuration defaults and handles legacy migrations, such as updating Telegram notification triggers. \atomic-json.ts\ ensures crash-safe writes to \settings.json\ using atomic file operations, while \cmem-gateway.ts\ manages the trial-expiry fallback logic for the hosted memory key. Additional modules like \dependency-health.ts\ and \expand-home.ts\ standardize dependency status reporting and cross-platform path expansion.

src/shared · high confidence

New standup skill for multi-branch reconciliation

A new 'standup' skill has been added to facilitate read-only group chats between AI agents representing different git worktrees or pull requests. This feature allows multiple branches to discuss their changes, resolve conflicts, and agree on a single consolidation plan without performing any merges. The implementation includes a Node.js CLI tool (\standup.mjs\) that manages a shared markdown file as a chat room, supporting commands to list active worktrees/PRs, post messages, track consensus, and generate a final summation for the user to execute.

plugin/skills/standup · high confidence

New utility modules for context injection, project identity, and safety sanitization

Added a suite of utility modules in src/utils to support the Live Context System and worktree-aware project identity. bmp-safe.ts and context-injection.ts ensure that injected memory context is strictly BMP-safe to prevent Claude Code session-bricking errors caused by UTF-16 surrogate pair truncation. project-name.ts and worktree.ts resolve stable project identities using git repo roots and detect Git worktrees to create composite keys (parent/worktree). claude-md-utils.ts and agents-md-utils.ts handle the atomic writing of CLAUDE.md and AGENTS.md files with tag-based context replacement, while project-filter.ts provides glob-based exclusion logic. Additional utilities include cursor-utils.ts for Cursor IDE integration, json-utils.ts for robust JSON reading with BOM handling, logger.ts for structured logging with date-rolling, observer-audit.ts for security-sensitive tool-attempt logging, and tag-stripping.ts for cleaning persisted memory of internal protocol tags.

src/utils · high confidence

New web-based viewer UI and Observation TV broadcast interface

This change introduces two new web-based user interfaces in the \src/ui\ directory. The \viewer-template.html\ file provides a full-featured viewer with light, dark, and system-preference themes, displaying observations, prompts, and summaries with distinct color-coded badges. Additionally, \tv.html\ implements a read-only 'Observation TV' broadcast interface designed for large displays, featuring a minimalist card-based layout, live stream status indicators, and support for Picture-in-Picture and full-screen modes.

src/ui · high confidence

Postgres storage backend for Server Beta

The \src/storage/postgres\ directory now provides a complete Postgres-based storage layer for the Server Beta runtime. This includes schema bootstrapping, connection pooling, and dedicated repositories for managing teams, projects, API keys, audit logs, server sessions, agent events, observations, and generation jobs. It also introduces fixed-window rate-limit counters, per-team usage metering, and a data-deletion path that purges project-scoped content while preserving the project shell.

src/storage/postgres · high confidence

Repository baseline configuration and documentation scaffolding

This change establishes the foundational project structure by adding essential configuration and documentation files. It introduces \.dockerignore\ and \.npmignore\ to control artifact publishing and container builds, \.gitattributes\ to enforce consistent line endings, and \.npmrc\ to enable legacy peer dependency resolution. It also adds \bunfig.toml\ to configure the Bun test runner, Dockerfiles (\Dockerfile.test-installer\) and Compose files (\docker-compose.yml\, \docker-compose.e2e.yml\) for local development and E2E testing, and key documentation files (\CLAUDE.md\, \CHANGELOG.md\, \SECURITY.md\, \NOTICE\, \RECEIPT-JOIN.md\) to define build processes, security policies, and data contracts.

(repo-wide) · high confidence

Server runtime introduces BullMQ-backed job queues and generation workers

The server runtime now supports an asynchronous, BullMQ-based job queue system for generation tasks (event and summary lanes), replacing the previous in-memory or disabled queue state. This change introduces dedicated queue management, worker execution, and health reporting: the ActiveServerQueueManager and ActiveServerGenerationWorkerManager handle job dispatch and processing, while ServerService exposes per-lane metrics (waiting, active, completed, failed, delayed, stalled) on /api/health and /v1/info. The system enforces deterministic job IDs to prevent Redis collisions, validates payloads via Zod schemas at enqueue, and includes audit logging for stalled jobs. Additionally, the server runtime now serves the Viewer UI at the root path, making the viewer accessible in the server deployment.

src/server/runtime · high confidence

Sync Hub worker scaffolding and operational guardrails

The sync-hub worker is introduced with a new project structure, including ESLint rules to prevent anti-patterns in Durable Object code (such as blocking I/O or using timers), a canonical content schema for deterministic operation serialization, and a control-plane uptime probe that monitors the Pro application's health via the token verification endpoint. The worker also establishes a deployment runbook detailing the required KV namespaces, secret configurations, and device admission limits, alongside a lockfile pinning development dependencies like Wrangler and Vitest.

workers/sync-hub · high confidence

Viewer UI enhancements: theme toggle, spinning favicon, and real-time streaming

The viewer now supports a theme toggle (light, dark, and system preferences) persisted in localStorage, and displays a spinning favicon while the system is processing. Real-time updates are handled via a new Server-Sent Events (SSE) hook that streams observations, summaries, and prompts, and includes a queue depth indicator. Context previewing has been improved with a hook that isolates Claude and Codex session sources, and pagination logic has been refactored to handle filter changes and loading states more robustly. Additionally, settings are now saved with improved error handling, ensuring sensitive fields like CLAUDE\_CODE\_PATH are not sent to the backend.

src/ui/viewer/hooks · high confidence

Removals

Removal of JavaScript-based hook scripts and shared utilities

The JavaScript hook implementations located in the hooks directory have been removed. This includes the pre-compact, session-end, and session-start hooks, along with their shared configuration loader and helper utilities. Users relying on these specific JavaScript-based hooks for session context loading, pre-compaction validation, or session-end memory archiving will no longer have this functionality available in this location.

hooks · high confidence

Security

New SQLite-backed API key authentication with hardened security

The local server runtime now uses a new SQLite-backed authentication service for API keys, replacing the previous unsalted SHA-256 storage with a salted, slow, timing-safe scrypt scheme to prevent offline cracking. New API keys are created with default 'memories:read' and 'memories:write' scopes to ensure they work immediately against the local routes, avoiding the previous issue where keys with no explicit scopes were authorized for nothing. The system also supports transparent migration of legacy keys to the new hashing scheme on first use.

src/server/auth · high confidence

Observer security lockdown and output classification improvements

The SDK now enforces a defense-in-depth security model for Observer and KnowledgeAgent sessions to prevent unauthorized tool access, using a new hardened-options module that disables all built-in tools, restricts filesystem and MCP access, and audits every tool attempt. Additionally, a new output classifier distinguishes between valid XML, idle, and prose responses to prevent silent data loss, while the parser has been updated to preserve unsupported observation types, handle nested XML tags, and normalize concept tags to improve search accuracy.

src/sdk · high confidence

Worker HTTP service hardened with strict localhost access and structured error handling

The worker's HTTP layer now enforces that all admin endpoints are accessible only from localhost, rejecting remote requests with a 403 error. CORS is similarly restricted to localhost origins, preventing cross-origin access from external sites. Additionally, a new BaseRouteHandler standardizes error responses, ensuring that client errors (4xx) are logged as warnings while server errors (5xx) are routed to the error tracking system, and introduces consistent parameter parsing and platform-source normalization across routes.

src/services/worker/http · high confidence

Architecture

Worker service restructured into modular, provider-based architecture

The worker service has been refactored from a monolithic structure into a modular, provider-based architecture. This introduces dedicated provider classes (ClaudeProvider, GeminiProvider, OpenRouterProvider) that share a common OpenAICompatibleProvider base, standardizing session lifecycle, error classification, and retry logic across different LLM backends. The change also includes a new DatabaseManager for centralized SQLite and sync coordination, a FormattingService for consistent table-based search output, and a RateLimitStore to accurately track and enforce subscription usage limits, improving reliability and observability for background memory operations.

src/services/worker · high confidence

Behavioural changes

Centralized privacy validation with improved handling of missing prompts

A new PrivacyCheckValidator has been introduced to centralize user prompt privacy checks, replacing the previous boolean-based logic. This change specifically addresses an issue where missing prompt rows (due to race conditions during session initialization) were incorrectly treated as private, which previously caused observations to be silently dropped. The new validator now distinguishes between genuinely redacted prompts (which are suppressed) and absent prompt rows (which are allowed with a warning), ensuring that observations and summaries are no longer lost when a prompt row is merely missing.

src/services/worker/validation · high confidence

Context output now uses distinct Agent and Human formatters

The context formatting logic has been split into two dedicated classes, AgentFormatter and HumanFormatter, replacing the previous single formatter. AgentFormatter generates plain-text, machine-readable context headers, legends, and observation rows suitable for system consumption. HumanFormatter produces a color-coded, human-readable context index with detailed token economics, column keys, and usage instructions, improving clarity for users reviewing past work and session statistics.

src/services/context/formatters · high confidence

Improved session reliability with bounded conversation recycling and response pacing

The worker session logic now prevents unbounded request loops and budget livelocks by introducing a response pacer that ensures only one unanswered observer prompt is active at a time, and by recycling the observer conversation when it exceeds character limits. New handlers manage generator exits to preserve buffered work during quota, auth, or provider-switch pauses, while a dedicated completion handler ensures sessions are properly finalized and persisted to the database. These changes harden the worker against crashes and infinite retry storms caused by oversized prompts or stalled responses.

src/services/worker/session · high confidence

Installer now safely shuts down existing workers before proceeding

The installer service now includes a new shutdown helper that ensures any previously running worker process is properly stopped before installation continues. This prevents conflicts and data corruption by verifying the worker is fully stopped via health probes before overwriting settings, addressing previous issues where the installer might proceed while a worker was still active.

src/services/install · high confidence

Installer replaced with npx-based installation

The previous curl-pipe-bash and bundled JavaScript installers have been removed and replaced with a redirect to the new npx-based installation method. Users are now instructed to run 'npx claude-mem install' (requiring Node.js \>= 20) instead of the old installation scripts. The install.cmem.ai domain now serves these replacement messages via install.sh and installer.js, configured with Vercel rewrites and appropriate content-type headers.

install · high confidence

Introduces centralized configuration constants for the viewer UI

The viewer UI now uses a dedicated constants directory to manage its configuration, replacing ad-hoc values with centralized exports. This includes API endpoint definitions for observations, summaries, prompts, settings, and streaming; promotional messaging for a 30-day Pro trial with a 100% usage gain pitch; default settings for the AI provider (Claude), model (Sonnet 5), and alternative providers (Gemini, OpenRouter); timing parameters for SSE reconnection and stats refresh; and UI settings for pagination and load thresholds.

src/ui/viewer/constants · high confidence

Introduces structured error handling and security hardening for the server runtime

The server now includes a dedicated error handling module that standardizes API error responses with structured codes and messages, replacing ad-hoc error logic. Security is strengthened by applying hardening headers (such as X-Content-Type-Options and X-Frame-Options) to all responses and validating allowed operations and topics for the /api/instructions endpoint to prevent path traversal and injection. Additionally, the server startup and shutdown processes are hardened to prevent zombie processes and ensure clean teardown, while a new utility ensures responses are flushed before process exit.

src/services/server · high confidence

MCP server runtime scoping and protocol protection

The MCP server now intercepts console output to prevent JSON-RPC protocol interference and introduces runtime-based tool visibility: when the runtime is set to 'server', all tools are available, but for other runtimes (e.g., 'worker'), tools previously restricted to 'server-beta' (such as observation and memory management tools) are hidden from the advertised tool list.

src/servers · high confidence

Modular context section rendering with human/agent formatting

The context service now uses dedicated renderers (Footer, Header, Summary, Timeline) to construct context output, supporting distinct 'human' and 'agent' views. This change introduces token economics display in the footer, a session summary section (Investigated, Learned, Completed, Next Steps), and a day-grouped timeline that can show full observations or table rows, with human views additionally grouping by file.

src/services/context/sections · high confidence

New modular search strategy implementations for Chroma, Hybrid, and SQLite backends

The search subsystem now uses distinct, modular strategy classes to handle vector and SQL-based lookups. ChromaSearchStrategy implements vector search with explicit project scoping (including merged projects) and platform source filtering in its metadata queries. HybridSearchStrategy combines file-path metadata lookups with Chroma vector ranking to prioritize relevant observations. SQLiteSearchStrategy provides a fallback or primary SQL-based search path for observations, sessions, and prompts, ensuring consistent filtering by project, platform source, and date range across all strategies.

src/services/worker/search/strategies · high confidence

Prevention of duplicate user prompts via recent-duplicate detection

The system now includes logic to detect and prevent duplicate user prompts within a specified time window. A new service function queries the SQLite database to find recent prompts with identical text associated with the current session or content session, ensuring that accidental repeated submissions are identified. This change introduces a specific check mechanism to maintain prompt uniqueness during user interactions.

src/services/sqlite/prompts · high confidence

SQLite backend migrated to bun:sqlite with new search and tool-use capabilities

The SQLite service layer has been refactored to use the native \bun:sqlite\ module instead of the previous \better-sqlite3\ dependency, bringing improved performance and native integration. This change introduces a new \SessionSearch\ class that leverages SQLite FTS5 for full-text search across observations, session summaries, and user prompts, with automatic fallback to ChromaDB if FTS5 is unavailable. A new \tool\_uses\ table and associated storage logic have been added to persist raw tool-use payloads with content hashing and truncation, enabling durable backup and progressive disclosure of tool interactions. The \SessionStore\ has been updated to support these new structures, including manual session creation, prompt normalization, and enhanced schema migrations, while connection pragmas are now centralized in \connection.ts\ for consistent database configuration.

src/services/sqlite · high confidence

Search now supports date range filtering and graceful Chroma fallback

The search worker now respects date\_from/date\_to parameters, allowing users to filter results by time range. Additionally, if the semantic search backend (Chroma) is unreachable or returns no results, the system automatically falls back to keyword-based SQLite search to ensure results are still returned.

src/services/worker/search · high confidence

Standardized hook response format introduced

A new standardized response format for hooks has been introduced via the \STANDARD\_HOOK\_RESPONSE\ constant in \src/hooks/hook-response.ts\. This constant defines a JSON object with \continue\ and \suppressOutput\ set to true, ensuring consistent behavior across hook implementations and simplifying error handling by providing a uniform return structure.

src/hooks · high confidence

Fixes

Context injection now fits output to the 10,000-character hook limit and shows token economics

The context service now prevents silent context loss when a hook's output exceeds the 10,000-character limit by measuring rendered text and iteratively dropping the most expensive content (full observation narratives, last-session summaries, session history, and observations) until the block fits. It also calculates and displays token economics (read tokens, discovery tokens, and savings) in the context header and footer, and ensures observer-health warnings are always visible. Configuration loading now correctly filters observation types and concepts to the active mode's IDs, and prior message extraction strips system-reminder tags to avoid parsing errors.

src/services/context · high confidence

Fix Windows hook failures and cross-platform plugin resolution

This change introduces a centralized shell-template generator to ensure consistent plugin-root resolution across hosts, fixing several platform-specific issues. It resolves a Windows EACCES error in hook spawning by preventing broken-pipe errors during candidate enumeration, and fixes cross-platform compatibility for MCP plugins by replacing the unreliable 'sh' command with a pure Node.js launcher. Additionally, it optimizes performance by avoiding login-shell PATH rebuilds for Claude Code hooks and ensures version-sorted cache directory ranking to prevent restart storms.

src/build · high confidence

Fixes observation retrieval and storage robustness in SQLite backend

The SQLite observation service now correctly handles file paths stored as bare strings in the \files\_read\ and \files\_modified\ columns, ensuring that context injection works consistently even when path formats (absolute vs. relative) differ between events. It also introduces a null-byte delimiter in the observation content hash to prevent collisions and adds logic to scope observations by platform source and project, improving data isolation and retrieval accuracy.

src/services/sqlite/observations · high confidence

Improved Windows Git Bash detection and new CLI utility modules

The npx CLI now includes robust utility modules for path resolution, settings reading, and Windows-specific preflight checks. On Windows, the new \checkWindowsGitBash\ function replicates Claude Code's Git Bash resolution chain to detect missing bash environments early, providing a clear remediation message instead of a cryptic hook failure. The \paths.ts\ module centralizes configuration directory logic and adds safe version reading from plugin manifests, while \settings.ts\ introduces a helper to read flat settings records, unwrapping legacy nested structures.

src/npx-cli/utils · high confidence

Infrastructure hardening: graceful shutdown, health probes, and v12.4.3 cleanup

The infrastructure layer now includes a new GracefulShutdown module that ensures a complete teardown sequence (HTTP server, session manager, MCP client, Chroma MCP, database, and process supervisor) and specifically tolerates the ERR\_SERVER\_NOT\_RUNNING error to prevent aborted shutdowns. Health monitoring has been improved with bounded HTTP probes to /api/health (replacing /api/readiness) and socket-based port checks that are timed out to prevent hanging on ghost listeners, particularly on Windows. Additionally, a one-time v12.4.3 cleanup script has been added to handle database pollution by backing up and purging orphaned observer sessions and stuck pending messages, with safeguards for disk space and Bun runtime compatibility issues.

src/services/infrastructure · high confidence

Installer error handling and runtime detection are hardened

The installer now uses a centralized error-reporting system that classifies failures (such as missing Bun or uv binaries, ERESOLVE conflicts, or permission errors) and provides specific remediation steps. It also improves runtime detection by searching additional system paths for Bun and uv, and handles npm install failures more robustly by retrying only on peer-dependency conflicts while suppressing scripts to prevent hangs.

src/npx-cli/install · high confidence

Test coverage

Added SDK test coverage for observer output classification, parsing, and prompt construction; Added comprehensive test coverage for SQLite SessionStore; Added comprehensive test coverage for infrastructure components; Added comprehensive test coverage for telemetry subsystem; Added comprehensive test coverage for worker services; Added integration and unit tests for server observation generation and request handling; Added integration tests for CCS Align, Grok Bot, OpenCode, and Telegram integrations; Added test coverage for CLI handler behaviors; Added test coverage for Chroma sync and MCP manager behaviors; Added test coverage for export-memories, mirror-dir, pr-babysit-status, and worker-logs scripts; Added test coverage for hooks file-context, runtime selector, and server client; Added test coverage for server runtime components; Added test coverage for sync-hub authentication, kill-switch, and control-plane probe; Added test coverage for the sync worker subsystem; Added test coverage for transcript CLI, config, and integration logic; Added test coverage for utility functions and skills; Added test coverage for worker HTTP routes; Added test coverage for worker lifecycle, logging, and mode management services; Added test fixtures for OpenRouter compatibility and bot marketplace sessions; Added test helpers for Windows process lifecycle and ghost-state classification; Added tests for AgentFormatter output rendering; Added tests for CLI hook IO discipline, server jobs, and worker failure handling; Added tests for CORS middleware origin restrictions and preflight headers; Added tests for MCP tool visibility, naming safety, and schema declarations; Added tests for Observer tool enforcement and hardened SDK options; Added tests for Redis queue configuration and environment variable precedence; Added tests for SQLite session store query correctness and search scoping; Added tests for SearchOrchestrator fallback and date filtering logic; Added tests for Windows spawn contract and macOS Codex bundle detection; Added tests for context generation budgeting, read-only safety, and configuration filtering; Added tests for corpus observation type filtering and name validation; Added tests for platform-source scoping and server storage boundaries; Added tests for smart-file-read grammar reuse, Windows binary resolution, and workspace path security; Added tests for subagent input normalization and Codex file-context extraction; Added tests for the embedded Process Supervisor; Added tests for the remote recall MCP server; Added tests for worker agent error handling and response processing; Added tests for worktree adoption and error formatting; Added unit tests for SessionMessageBuffer and GeneratorExitHandler; Added unit tests for search strategy implementations; Expanded test coverage for core integration and runtime components; Expanded test coverage for npx-cli installer and runtime logic; Expanded test coverage for server runtime capabilities; Integration test coverage for Chroma sync, Windows worker lifecycle, and installer config repairs; Test coverage for shared infrastructure components.

Dependencies

Initial dependency manifests for claude-mem, plugin, and sync-hub

This change introduces the foundational package.json files for the project's core components. The main \claude-mem\ package (v13.25.3) defines its runtime dependency on \better-auth\ and lists build-time dependencies like \@anthropic-ai/claude-agent-sdk\, \bullmq\, and \express\ which are bundled into the worker. The \plugin\ package (v13.25.3) specifies the runtime dependencies for bundled hooks, including \zod\ and a comprehensive set of \tree-sitter\ grammars for code parsing. Additionally, a new \sync-hub\ worker package is added with dependencies for Cloudflare Workers deployment (\wrangler\, \miniflare\).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 49 (+4.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 72 → 63 (-9.2)
  • Architecture 91 (new)
  • Maturity 87 → 72 (-15.0)
  • Readiness 21 → 34 (+13.5)
  • Security 60 → 70 (+10.3)
  • Accessibility 55 (new)

Resolved (73)

  • ADR not followed: Overnight Fixes — Single Round (v13.12.4) (plans/2026-07-23-overnight-fixes-single-round.md)
  • ADR not followed: Remove Gemini CLI, Add Antigravity CLI (full parity) (plans/2026-07-03-antigravity-cli-migration.md)
  • Boundary-crossing change coupling: context-generator.cjs ↔ export-memories.ts (plugin/scripts/context-generator.cjs)
  • Boundary-crossing change coupling: viewer-bundle.js ↔ ContextSettingsModal.tsx (plugin/ui/viewer-bundle.js)
  • Boundary-crossing change coupling: worker-service.cjs ↔ FormattingService.ts (plugin/scripts/worker-service.cjs)
  • Boundary-crossing change coupling: worker-service.cjs ↔ export-memories.ts (plugin/scripts/worker-service.cjs)
  • Boundary-crossing change coupling: worker-service.cjs ↔ file-context.ts (plugin/scripts/worker-service.cjs)
  • Boundary-crossing change coupling: worker-service.cjs ↔ scrub.ts (plugin/scripts/worker-service.cjs)
  • Boundary-crossing change coupling: worker-service.cjs ↔ telemetry.ts (plugin/scripts/worker-service.cjs)
  • Boundary-crossing change coupling: worker-service.cjs ↔ telemetry.ts (plugin/scripts/worker-service.cjs)
  • Boundary-crossing change coupling: worker-service.cjs ↔ types.ts (plugin/scripts/worker-service.cjs)
  • Boundary-crossing change coupling: worker-service.cjs ↔ worker-service.ts (plugin/scripts/worker-service.cjs)
  • Dimension evaluation failed
  • FileTooLong: standup/standup.mjs (plugin/skills/standup/standup.mjs)
  • High CVE: [GHSA redacted] (plugin/bun.lock)
  • High CVE: [GHSA redacted] (workers/sync-hub/bun.lock)
  • High CVE: [GHSA redacted] (workers/sync-hub/bun.lock)
  • High CVE: [GHSA redacted] (workers/sync-hub/bun.lock)
  • High CVE: [GHSA redacted] (workers/sync-hub/bun.lock)
  • High: security finding (details withheld)
  • …and 53 more

New (600)

  • AntigravityCliHooksInstaller.checkAntigravityCliHooksStatus (cognitive 26) (src/services/integrations/AntigravityCliHooksInstaller.ts)
  • AntigravityCliHooksInstaller.checkAntigravityCliHooksStatus (cyclomatic 16) (src/services/integrations/AntigravityCliHooksInstaller.ts)
  • Boundary-crossing change coupling: SettingsDefaultsManager.ts ↔ settings.ts (src/shared/SettingsDefaultsManager.ts)
  • Boundary-crossing change coupling: summarize.ts ↔ SessionRoutes.ts (src/cli/handlers/summarize.ts)
  • Boundary-crossing change coupling: telemetry.ts ↔ ResponseProcessor.ts (src/npx-cli/commands/telemetry.ts)
  • Boundary-crossing change coupling: telemetry.ts ↔ scrub.ts (src/npx-cli/commands/telemetry.ts)
  • Boundary-crossing change coupling: types.ts ↔ DataRoutes.ts (src/cli/types.ts)
  • Boundary-crossing change coupling: uninstall.ts ↔ worker-service.ts (src/npx-cli/commands/uninstall.ts)
  • CanonicalContent.normalizeJson (cognitive 18) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.normalizeJson (cyclomatic 16) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.parseCanonicalOperation (cyclomatic 17) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.validateBody (cognitive 26) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.validateBody (cyclomatic 22) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.validateMutation (cognitive 27) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.validateMutation (cyclomatic 22) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.validatePayload (cognitive 33) (src/services/sync/CanonicalContent.ts)
  • CanonicalContent.validatePayload (cyclomatic 20) (src/services/sync/CanonicalContent.ts)
  • CcsAlignMiddleCache.appendMiddleCacheRecordsAtomic (cognitive 18) (src/services/integrations/CcsAlignMiddleCache.ts)
  • CcsAlignRulesWalker.discoverLayerPaths (cognitive 20) (src/services/integrations/CcsAlignRulesWalker.ts)
  • CcsAlignRulesWalker.walkRules (cognitive 87) (src/services/integrations/CcsAlignRulesWalker.ts)
  • …and 580 more

Changes since last survey

  • 300 commits — 142 feature/other, 158 fixes

By area

  • src/services — 69 commits
  • plugin/scripts — 62 commits
  • (root) — 33 commits
  • (repo) — 31 commits
  • src/npx-cli — 19 commits
  • docs/public — 11 commits
  • src/server — 8 commits
  • src/shared — 7 commits
  • src/cli — 6 commits
  • src/sdk — 6 commits
  • workers/sync-hub — 6 commits
  • plans/2026-09-09-ccs-align.md — 4 commits
  • plugin/hooks — 3 commits
  • scripts/grok-bot-session-inject.mjs — 3 commits
  • src/integrations — 3 commits
  • src/utils — 3 commits
  • .github/workflows — 2 commits
  • plugin/skills — 2 commits
  • src/supervisor — 2 commits
  • tests/cli — 2 commits

Notable commits

  • fix: Merge branch 'fix/oauth-only-installer-pr' into consolidate/observer-quota-oauth
  • fix: Merge origin/main into OAuth installer fix
  • fix: Merge pull request #3823 from thedotmack/fix/local-provider-skips-login
  • fix: Merge remote-tracking branch 'origin/fix/chroma-windows-process-tree' into windows-megafix
  • fix: Merge remote-tracking branch 'origin/fix/windows-build-and-sync' into windows-megafix
  • fix: Merge remote-tracking branch 'origin/fix/windows-git-bash-preflight' into windows-megafix
  • fix: Merge remote-tracking branch 'origin/fix/windows-tilde-expansion' into windows-megafix
  • fix: Merge remote-tracking branch 'origin/fix/windows-tree-sitter-exe' into windows-megafix
  • fix: chore: rebuild plugin bundles across the observer and quota fixes
  • fix: ci(windows): fix unterminated regex string in surviving-process diagnostic
  • fix: fix(antigravity): align hooks/adapter/transcript with agy 1.2.1 contract (#4058)
  • fix: fix(build): stop regex bundle rewrite that can delete a declaration (#4044)
  • fix: fix(chroma): capture child identity at spawn, not at cleanup
  • fix: fix(chroma): classify a dead-transport handshake as ChromaUnavailableError (#3631)
  • fix: fix(chroma): reap unreadable writer lock past grace (fixes #3916)
  • fix: fix(chroma): record failed live writes as pending (fixes #3917) (#3949)
  • fix: fix(chroma): record failed live writes as pending so the watermark cannot orphan them
  • fix: fix(chroma): stop JSON parse crashes from aborting the sync pipeline (rehost #3542) (#4040)
  • fix: fix(chroma): stop a backfill run after repeated batch failures
  • fix: fix(chroma): tolerate CJK list backfill
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

thedotmack/claude-mem was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 02cd0c9c47e38a849e764477290c571e84dfa043 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.