chore(release): memhub v0.87.0 - #278
Conversation
Promoted from XTraceAI/agent-plugins-internal by scripts/promote_ship.py. Source-RevId: 711c0c1a0d8f88353d4bb9e970232852576706bf
…1145) A promotion replaces plugins/memhub/ only, so public's tests/ and README stayed at 0.76.1 while the plugin moved to 0.87.0. Six suites then failed guard and probe-tests on #278, each on an intentional internal change: the add_memory gate (22 hooks, #57), the companion skill (#47/#51), the author-child guard (#58), the one-line spec reminder (#61/#63), and the rulebook-verify and starter-rulebook wording/source_ref changes. The six suites are internal's at 711c0c1 (the promoted commit), with plugins/memhub-staging rewritten to plugins/memhub. The README gains the /memhub:companion entry and the seventeen-skill count the doc test pins. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01H6kYog7yKLFVuXb12AAF2m
test: bring public's suites and README up to the v0.87.0 plugin (ENG-1145)
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f5b1eddd5f
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| patch = inp.get("command") if isinstance(inp, dict) else None | ||
| if not isinstance(patch, str) or "*** Begin Patch" not in patch: | ||
| return [] |
There was a problem hiding this comment.
Read Codex patches from their actual input field
Codex hook payloads provide an apply_patch body as tool_input.patch (as exercised in tests/codex_hooks_setup_test.py), while transcript parsing also recognizes input; neither reaches this command lookup. Consequently apply_patch_files returns no files for normal Codex edits, so the newly added synthetic edit events never run and Codex edit/ordering rules and gates remain silent for every patch.
Useful? React with 👍 / 👎.
| name = payload.get("tool_name") | ||
| if not isinstance(name, str) or not _ADD_MEMORY.match(name): | ||
| return False | ||
| args = payload.get("tool_input") | ||
| return isinstance(args, dict) and "user_message" in args |
There was a problem hiding this comment.
Limit the memory gate to MemHub servers
When capture is active, this accepts any MCP tool whose name ends in __add_memory and happens to have a user_message argument. An unrelated installed MCP server can legitimately expose mcp__other_service__add_memory with that shape, and its calls will then be denied as though they were MemHub writes, removing that server's tool from Claude sessions that have this plugin enabled.
Useful? React with 👍 / 👎.
MemHub plugin v0.87.0, built from internal main.
Source-RevId:
711c0c1a0d8f88353d4bb9e970232852576706bfSHA256SUMS:
3c93e12af37b689d271c5ac1a41f2c5743ef62248617c0e7417865b38a685749Built by promote run 36077808698 at
XTraceAI/agent-plugins-internal@711c0c1a0d8f88353d4bb9e970232852576706bf: the plugin suites pass at that commit, and theexport is verified — named
memhub, one version across all four manifests, the productionbackend in
.mcp.json, and nothing shaped like a credential. Every file's digest wasre-checked against
SHA256SUMSin the clone this branch was pushed from, so what is here iswhat that run produced.
This PR replaces
plugins/memhub/and nothing else.Before this can merge:
mainrequires theReal agent evidencecheck, which is a commitstatus, not a check run — it exists only once someone dispatches it on this PR's exact head:
Push again and the new head needs a new run.
After merge, in this order (RELEASING.md):
memhub--v0.87.0and push the tag first — the Claude pincannot resolve a ref that is not there yet.
refandshain.claude-plugin/marketplace.jsonto that tag, by PR.Codex and Cursor ship the moment this merges: their catalogs carry no pin and cache by
version string.