Install
$ agentstack add skill-thedotmack-claude-mem-version-bump ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Version Bump & Release Workflow
IMPORTANT: Plan and write detailed release notes before starting.
CRITICAL: Commit EVERYTHING (including build artifacts). At the end of this workflow, NOTHING should be left uncommitted or unpushed. Run git status at the end to verify.
Preparation
- Analyze: Determine if the change is PATCH (bug fixes), MINOR (features), or MAJOR (breaking).
- Environment: Identify repository owner/name from
git remote -v. - Paths — every file that carries the version string:
package.json— the npm/npx-published version (npx claude-mem@X.Y.Zresolves from this)plugin/package.json— bundled plugin runtime deps.claude-plugin/marketplace.json— version insideplugins[0].version.claude-plugin/plugin.json— top-level Claude-plugin manifestplugin/.claude-plugin/plugin.json— bundled Claude-plugin manifest.codex-plugin/plugin.json— Codex-plugin manifestplugin/.codex-plugin/plugin.json— bundled Codex-plugin manifestopenclaw/openclaw.plugin.json— OpenClaw plugin manifest
Verify coverage before editing: git grep -l "\"version\": \"\"" should list all eight. If a new manifest has been added since this doc was last updated, update this list.
Workflow
- Update: Increment the version string in every path above. Do NOT touch
CHANGELOG.md— it's regenerated. - Verify:
git grep -n "\"version\": \"\""— confirm all eight files match.git grep -n "\"version\": \"\""— should return zero hits. - Build and sync:
npm run build-and-syncto regenerate artifacts, sync the local marketplace copy, restart the worker, and clear the queue. Do not use plainnpm run buildfor release validation because it can leave the local marketplace/worker out of sync. - Commit:
git add -A && git commit -m "chore: bump version to X.Y.Z". - Tag:
git tag -a vX.Y.Z -m "Version X.Y.Z". - Push:
git push origin main && git push origin vX.Y.Z. - Publish to npm — HAND OFF TO HUMAN. The human maintainer raised npm
security, so publishing now requires credentials/2FA only they can provide. The agent MUST NOT run npm publish (or np / npm run release:*, which also publish) itself. Hand off NPM publishing to the human now: stop and tell them the version is committed, tagged, and pushed, and that they must publish to npm to make npx claude-mem@X.Y.Z resolve. Give them the command: ``bash npm publish # run by the HUMAN — the prepublishOnly script rebuilds the package ` Wait for the human to confirm they published, then verify it landed: `bash npm view claude-mem@X.Y.Z version # should print X.Y.Z ` If the publish build touched local artifacts, run npm run build-and-sync` again afterward.
- GitHub release:
gh release create vX.Y.Z --title "vX.Y.Z" --notes "RELEASE_NOTES". - Changelog: Regenerate via the project's changelog script:
``bash npm run changelog:generate ` (Runs node scripts/generate-changelog.js, which pulls releases from the GitHub API and rewrites CHANGELOG.md`.)
- Sync changelog: Commit and push the updated
CHANGELOG.md. - Notify: Run the Discord notification from
~/Scripts/claude-mem/, where the.envwith Discord webhook details lives:
``bash cd ~/Scripts/claude-mem/ && npm run discord:notify vX.Y.Z ` Do this even when the release worktree does not have a local .env`.
- Finalize:
git status— working tree must be clean.
Checklist
- [ ] All eight config files have matching versions
- [ ]
git grepfor old version returns zero hits - [ ]
npm run build-and-syncsucceeded - [ ] Git tag created and pushed
- [ ] NPM publishing handed off to the human (agent does NOT run
npm publish— human raised security); once they publish,npm view claude-mem@X.Y.Z versionconfirms it (sonpx claude-mem@X.Y.Zresolves) - [ ] GitHub release created with notes
- [ ]
CHANGELOG.mdupdated and pushed - [ ] Discord notification run from
~/Scripts/claude-mem/ - [ ]
git statusshows clean tree
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: thedotmack
- Source: thedotmack/claude-mem
- License: Apache-2.0
- Homepage: https://claude-mem.ai
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.