Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -342,7 +342,7 @@ both will fire, so it goes to you as a decision.

### Harness-tied memory (flagged off)

On by default since v0.69.0 (set `MEMHUB_HARNESS_EXTRACT=0` to turn it off), the plugin helps a
With `MEMHUB_HARNESS_EXTRACT=1` in the environment, the plugin helps a
correction you make in a session become a proposed team rule. At each turn's
Stop, a detached child sends a redacted slice of that turn to MemHub
(`POST /v1/team/rulebook/harness/classify`), whose classifier says whether the
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub-staging/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "memhub-staging",
"description": "STAGING build of the MemHub plugin \u2014 identical behavior to `memhub` but pointed at the staging backend (api.staging.memhub.xtrace.ai) for MemHub developers iterating on the service. Skills, hooks, and scripts are shared with `memhub` (symlinked), so the two never drift; only the backend URL and OAuth client differ. Install this instead of `memhub` \u2014 never both (both register an MCP server named `memhub`). Spec workflows: spec-work guides implementation, spec-check freshly reviews changes, and spec-maintain offers local/cloud bootstrap and reviewable Git or Brain proposals through the shared spec entry point.",
"version": "0.74.0",
"version": "0.76.0",
"license": "Apache-2.0",
"hooks": "./hooks/claude-hooks.json",
"author": {
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub-staging/.codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "memhub-staging",
"description": "MemHub staging for Codex: team memory and Rulebook hooks. Use the setup skill to verify the active hook route and credential. Repository shell commands in projectless tasks must include an explicit cd prefix when the host omits workdir. Spec workflows: spec-work guides implementation, spec-check freshly reviews changes, and spec-maintain offers local/cloud bootstrap and reviewable Git or Brain proposals through the shared spec entry point.",
"version": "0.74.0",
"version": "0.76.0",
"license": "Apache-2.0",
"author": {
"name": "XTrace",
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub-staging/.mcp.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"mcpServers": {
"memhub": {
"type": "http",
"url": "https://api.staging.memhub.xtrace.ai/mcp-server/mcp?memhub_plugin_version=0.74.0",
"url": "https://api.staging.memhub.xtrace.ai/mcp-server/mcp?memhub_plugin_version=0.76.0",
"auth": {
"CLIENT_ID": "mYTjrWldX9ZFGtDES3hQDEHSis9gIjiq"
},
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub/.claude-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "memhub",
"description": "Auto-capture Claude Code sessions into MemHub team memory. A Stop hook ships each turn as it happens \u2014 sending only the transcript bytes written since the last successful flush, so a session is captured even if it never reaches a clean exit \u2014 alongside flushes on commit/PR events (PostToolUse hooks) and a SessionEnd backstop. The memhub MCP runs tool-aware (agentic) extraction of facts, episodes, and artifacts with watermark-based delta dedup, batching extraction so per-turn capture doesn't fragment episodes. A PreToolUse hook surfaces situated team directives (lessons/procedures) before each Edit/Write/Bash by firing the memhub recall_directives symbol-tripwire on the in-flight call and injecting any hits as context (a client-side precision gate drops directives whose triggers don't concretely match the call, e.g. an over-broad repo-name trigger). Includes skills for: plugin install/health (setup), plugin authentication with its own hook credential (login), repo brain creation and seeding (onboard), terminal artifact uploads (save-artifact), on-demand session import (import-session), team-memory recall (search-memory), teammate session handoff (handoff-session), git-authored spec development with ownership frontmatter (spec), Rulebook rule authoring (create-rule), rules proposed from CLAUDE.md and past sessions in one run (start-rulebook), and PR babysitting (pr-babysit) \u2014 a hook arms a self-paced loop after `gh pr create` that fixes review-bot findings and saves the fixing process to the repo's agent brain. Rules live in RULEBOOKS \u2014 containers with their own membership, so a rule reaches exactly the people its book binds, and one person can be bound by several (their org's book plus their team's): the authoring skills resolve which book a rule lands in and offer to create one when there is none, the hooks cache every book that binds you, and when two books fire on one call the wider book's rule is the one the per-call cap keeps. A PostToolUse hook reminds authors when an edited file belongs to a git-authored spec. Spec ownership frontmatter replaces the retired artifact map; the backend maintains read-only mirrors and opens bootstrap or audit PRs. Sessions are named with the title their own host shows \u2014 Claude Code's generated title, or on Codex the thread_name Codex generated (from the rollout, else ~/.codex/session_index.jsonl), passed through verbatim so MemHub's sessions list matches the editor's; a session its host never named falls back to a title derived from its first prompt \u2014 and route into the repo's own agent brain via a per-user room cache (~/.config/memhub-plugin/rooms.json, never written into the repo) \u2014 resolved once by /memhub:onboard and read by every writer, including the two automatic capture paths, so team memory lands in the repo's room instead of personal memory. Session \u2194 PR linking: after a call that addresses GitHub (`gh pr \u2026`, a `curl`/`gh api` REST request, or a GitHub MCP tool) whose output names exactly one pull request, a PostToolUse hook asks the backend one question and injects one instruction \u2014 a session that ran `gh pr create` \u2014 or the GitHub MCP create tool \u2014 links itself unconditionally (opening it is work the session did, and a PR has many sessions), while every other GitHub call, a hand-rolled `curl` POST included, leaves the authorship judgment to the agent, and an org with no GitHub integration is told once that connecting it is what links sessions to shipped code. The hook is stateless apart from one short-lived negative answer (an enabled org with GitHub disconnected, cached 30 minutes per credential, and never inferred from a reply that merely says the feature is off) and degrades to silence on every failure. Two skills complete it: link-pr (link this or a named session by hand \u2014 also the answer for a PR opened by a script or CI helper, which is deliberately not detected) and find-contributing-sessions (scan this machine's local session history for the sessions that wrote a PR's code, rank the candidates by the evidence that matched, and link the ones you approve). Every rulebook fire is now disclosed to the user in a fixed shape on two channels: the hook's own terminal line leads with `\ud83d\udccf Rule fired: <the rule>` (`\u26d4\ufe0f` when a gate actually blocked the call) above the detail line it already showed, and the agent is told to echo that same byte-identical line at the top of its reply so the fire reaches the transcript everything downstream reads. Session start now says what rules ARE \u2014 standing instructions from teammates carrying CLAUDE.md's weight \u2014 before listing them. The agent records ONE work type for a pull request it links (feat, fix, chore, docs, perf, refactor, other), and only when the PR has none yet \u2014 the first label is permanent, and asking again would cost the link, not just the type. Spec workflows: spec-work guides implementation, spec-check freshly reviews changes, and spec-maintain offers local/cloud bootstrap and reviewable Git or Brain proposals through the shared spec entry point.",
"version": "0.74.0",
"version": "0.76.0",
"license": "Apache-2.0",
"hooks": "./hooks/claude-hooks.json",
"author": {
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub/.codex-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "memhub",
"description": "XTrace MemHub team memory in Codex: automatic session capture, situated directive recall, artifact sync, plus skills for setup, login, onboarding, artifact upload, session import, search, handoff, spec-driven development, Rulebook rule authoring (create-rule) and a team's first Rulebook — tested starter rules fitted to the repo, and rules proposed from CLAUDE.md + past sessions (start-rulebook), and PR babysitting. A rule lives in a RULEBOOK \u2014 a container with its own membership, so it reaches exactly the people that book binds; the authoring skills resolve which book it lands in and offer to create one when there is none. Run memhub:setup to verify hook routing and authentication. Current desktop builds support bundled hooks; older hosts need the user bridge. Bundled handlers defer to matching installed user bridge handlers, which require trust. Codex's own threads are not captured as your sessions: spawned subagents, guardian action-reviews and memory consolidation are recognised from the rollout's thread_source and skipped by name, while every other kind \u2014 including a product surface we have not seen, since Codex's ThreadSource type is open-ended \u2014 is captured, because refusing an unknown kind would silently and unrecoverably drop real work. Every rule fire is reported under the same namespaced session id capture uploads, so a fire is linked to the Codex session it fired in. Session \u2194 PR linking: after a call that addresses GitHub (`gh pr \u2026`, a `curl`/`gh api` REST request, or a GitHub MCP tool) whose output names exactly one pull request, a PostToolUse hook asks the backend one question and injects one instruction \u2014 a session that ran `gh pr create` \u2014 or the GitHub MCP create tool \u2014 links itself unconditionally (opening it is work the session did, and a PR has many sessions), while every other GitHub call, a hand-rolled `curl` POST included, leaves the authorship judgment to the agent, and an org with no GitHub integration is told once that connecting it is what links sessions to shipped code. The hook is stateless apart from one short-lived negative answer (an enabled org with GitHub disconnected, cached 30 minutes per credential, and never inferred from a reply that merely says the feature is off) and degrades to silence on every failure. Two skills complete it: link-pr (link this or a named session by hand \u2014 also the answer for a PR opened by a script or CI helper, which is deliberately not detected) and find-contributing-sessions (scan this machine's local session history for the sessions that wrote a PR's code, rank the candidates by the evidence that matched, and link the ones you approve). The agent records ONE work type for a pull request it links (feat, fix, chore, docs, perf, refactor, other), and only when the PR has none yet \u2014 the first label is permanent, and asking again would cost the link, not just the type. Spec workflows: spec-work guides implementation, spec-check freshly reviews changes, and spec-maintain offers local/cloud bootstrap and reviewable Git or Brain proposals through the shared spec entry point.",
"version": "0.74.0",
"version": "0.76.0",
"license": "Apache-2.0",
"author": {
"name": "XTrace",
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub/.cursor-plugin/plugin.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "memhub",
"displayName": "MemHub",
"description": "XTrace MemHub team memory in Cursor: search_memory / save_artifact / import_conversation tools plus skills for setup, login, onboarding, artifact upload, session import, recall, handoff, spec-driven development, Rulebook rule authoring (create-rule) and a team's first Rulebook — tested starter rules fitted to the repo, and rules proposed from CLAUDE.md + past sessions (start-rulebook), and PR babysitting. A rule lives in a RULEBOOK \u2014 a container with its own membership, so it reaches exactly the people that book binds; the authoring skills resolve which book it lands in and offer to create one when there is none. Sessions are captured automatically. Session \u2194 PR linking ships as skills on Cursor: link-pr and find-contributing-sessions. Cursor's shell hooks are observational \u2014 `afterShellExecution` defines no reply the agent can see \u2014 so the automatic post-`gh pr create` link that Claude Code and Codex get is not available here. The agent records ONE work type for a pull request it links (feat, fix, chore, docs, perf, refactor, other), and only when the PR has none yet \u2014 the first label is permanent, and asking again would cost the link, not just the type. Spec workflows: spec-work guides implementation, spec-check freshly reviews changes, and spec-maintain offers local/cloud bootstrap and reviewable Git or Brain proposals through the shared spec entry point.",
"version": "0.74.0",
"version": "0.76.0",
"license": "Apache-2.0",
"author": {
"name": "XTrace"
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub/.mcp.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"mcpServers": {
"memhub": {
"type": "http",
"url": "https://api.memhub.xtrace.ai/mcp-server/mcp?memhub_plugin_version=0.74.0",
"url": "https://api.memhub.xtrace.ai/mcp-server/mcp?memhub_plugin_version=0.76.0",
"auth": {
"CLIENT_ID": "xHoQkYd7uNUfaNX6Tyv143e1Ev7u3XS0"
},
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub/hooks/claude-hooks.json
Original file line number Diff line number Diff line change
Expand Up @@ -204,7 +204,7 @@
{
"type": "command",
"timeout": 10,
"command": "IN=$(cat); case \"${MEMHUB_HARNESS_EXTRACT:-}\" in 0|[Oo][Ff][Ff]|[Ff][Aa][Ll][Ss][Ee]|[Nn][Oo]) exit 0 ;; esac; if [ -n \"${CLAUDE_PLUGIN_ROOT:-}\" ] && printf %s \"$IN\" | python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/claude_hook_guard.py\" ignore Stop; then printf %s \"$IN\" | python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/harness_stop.py\" stop; fi"
"command": "IN=$(cat); case \"${MEMHUB_HARNESS_EXTRACT:-}\" in 1|[Oo][Nn]|[Tt][Rr][Uu][Ee]|[Yy][Ee][Ss]) ;; *) exit 0 ;; esac; if [ -n \"${CLAUDE_PLUGIN_ROOT:-}\" ] && printf %s \"$IN\" | python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/claude_hook_guard.py\" ignore Stop; then printf %s \"$IN\" | python3 \"${CLAUDE_PLUGIN_ROOT}/scripts/harness_stop.py\" stop; fi"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Normalize the flag before applying the shell gate

When MEMHUB_HARNESS_EXTRACT contains surrounding whitespace, such as " 1 " or " on ", harness_extract.extract_enabled() strips it and the updated unit test explicitly treats " 1 " as enabled, but this shell case exits before Python runs because it compares the untrimmed value. As a result, a supported enabled value silently leaves the feature disabled when invoked through the actual Stop hook; trim the value here or make the accepted-value semantics consistent across all three gates.

Useful? React with 👍 / 👎.

}
]
}
Expand Down
2 changes: 1 addition & 1 deletion plugins/memhub/mcp.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"mcpServers": {
"memhub": {
"type": "streamable-http",
"url": "https://api.memhub.xtrace.ai/mcp-server/mcp?memhub_plugin_version=0.74.0"
"url": "https://api.memhub.xtrace.ai/mcp-server/mcp?memhub_plugin_version=0.76.0"
}
}
}
2 changes: 1 addition & 1 deletion plugins/memhub/plugin.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "memhub",
"description": "XTrace MemHub team memory: search_memory / save_artifact / import_conversation MCP tools plus skills for setup, login, onboarding, artifact upload, session import, team-memory recall, session handoff, spec-driven development, Rulebook rule authoring (create-rule) and a team's first Rulebook — tested starter rules fitted to the repo, and rules proposed from CLAUDE.md + past sessions (start-rulebook), and PR babysitting. A rule lives in a RULEBOOK \u2014 a container with its own membership, so it reaches exactly the people that book binds; the authoring skills resolve which book it lands in and offer to create one when there is none. Session auto-capture ships through the host-native plugin layer (hooks are outside the Agent Plugins spec). Session \u2194 PR linking: after a call that addresses GitHub (`gh pr \u2026`, a `curl`/`gh api` REST request, or a GitHub MCP tool) whose output names exactly one pull request, a PostToolUse hook asks the backend one question and injects one instruction \u2014 a session that ran `gh pr create` \u2014 or the GitHub MCP create tool \u2014 links itself unconditionally (opening it is work the session did, and a PR has many sessions), while every other GitHub call, a hand-rolled `curl` POST included, leaves the authorship judgment to the agent, and an org with no GitHub integration is told once that connecting it is what links sessions to shipped code. The hook is stateless apart from one short-lived negative answer (an enabled org with GitHub disconnected, cached 30 minutes per credential, and never inferred from a reply that merely says the feature is off) and degrades to silence on every failure. Two skills complete it: link-pr (link this or a named session by hand \u2014 also the answer for a PR opened by a script or CI helper, which is deliberately not detected) and find-contributing-sessions (scan this machine's local session history for the sessions that wrote a PR's code, rank the candidates by the evidence that matched, and link the ones you approve). The agent records ONE work type for a pull request it links (feat, fix, chore, docs, perf, refactor, other), and only when the PR has none yet \u2014 the first label is permanent, and asking again would cost the link, not just the type. Spec workflows: spec-work guides implementation, spec-check freshly reviews changes, and spec-maintain offers local/cloud bootstrap and reviewable Git or Brain proposals through the shared spec entry point.",
"version": "0.74.0",
"version": "0.76.0",
"license": "Apache-2.0",
"author": {
"name": "XTrace",
Expand Down
27 changes: 13 additions & 14 deletions plugins/memhub/scripts/harness_extract.py
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
"""Harness-tied memory, the client half: which moments of a session deserve
the coding agent's attention.

Nothing here writes a rule. At each turn's Stop — on by default since v0.69.0,
off with `MEMHUB_HARNESS_EXTRACT=0` — `harness_stop.py` runs that turn through
this pipeline in a detached child:
Nothing here writes a rule. At each turn's Stop — only with
`MEMHUB_HARNESS_EXTRACT=1`; off by default — `harness_stop.py` runs that turn
through this pipeline in a detached child:

router deterministic regexes over the turn, no model and no cost.
It labels a moment (a correction, a retraction, a reuse
Expand Down Expand Up @@ -47,7 +47,6 @@

FLAG = "MEMHUB_HARNESS_EXTRACT"
_ON = ("1", "on", "true", "yes")
_OFF = ("0", "off", "false", "no")

CLASSIFY_PATH = "/v1/team/rulebook/harness/classify"
# The server bounds its judge at 20 s. One attempt, and this is the whole wait:
Expand All @@ -60,19 +59,19 @@


def extract_enabled(environ=None) -> bool:
"""The one switch for the whole sensor. Default ON.
"""The one switch for the whole sensor. Default OFF.

It was opt-in through the dogfood: the sensor spends a classifier call per
Opt-in because of what on costs: the sensor spends a classifier call per
flagged turn, and the drain behind it spends a headless authoring run per
moment on the PERSON'S OWN model quota. (Naming that command literally here
trips `test_nothing_in_the_client_writes_a_rule`, whose substring scan
cannot tell prose from code — and the guard is worth more than the
sentence: nothing in THIS module may author.) Default-on means an install starts doing
both without being asked, which is a product decision (Felix, 2026-09-20)
and not one this function should relitigate — but it is why the off switch
has to keep working for every spelling someone reaches for."""
moment on the PERSON'S OWN model quota, filing proposals into a shared team
rulebook. (Naming that command literally here trips
`test_nothing_in_the_client_writes_a_rule`, whose substring scan cannot
tell prose from code — and the guard is worth more than the sentence:
nothing in THIS module may author.) v0.69.0 through v0.75.x defaulted this
ON; it went back to opt-in so an install never starts spending that
without being asked. Unset, blank and unrecognised values are all off."""
env = os.environ if environ is None else environ
return str(env.get(FLAG, "")).strip().lower() not in _OFF
return str(env.get(FLAG, "")).strip().lower() in _ON


# ------------------------------------------------------------------- files
Expand Down
Loading
Loading