惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
腾讯CDC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
WordPress大学
WordPress大学
Engineering at Meta
Engineering at Meta
M
MIT News - Artificial intelligence
H
Hackread – Cybersecurity News, Data Breaches, AI and More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
N
Netflix TechBlog - Medium
罗磊的独立博客
G
Google Developers Blog
Microsoft Azure Blog
Microsoft Azure Blog
美团技术团队
MongoDB | Blog
MongoDB | Blog
雷峰网
雷峰网
Recent Announcements
Recent Announcements
The Cloudflare Blog
小众软件
小众软件
大猫的无限游戏
大猫的无限游戏
The GitHub Blog
The GitHub Blog
博客园 - Franky
博客园 - 三生石上(FineUI控件)
T
Tenable Blog
A
Arctic Wolf
www.infosecurity-magazine.com
www.infosecurity-magazine.com
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
V2EX - 技术
V2EX - 技术
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
Threat Research - Cisco Blogs
D
Docker
Y
Y Combinator Blog
博客园 - 叶小钗
PCI Perspectives
PCI Perspectives
P
Privacy & Cybersecurity Law Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
C
CERT Recently Published Vulnerability Notes
P
Proofpoint News Feed
NISL@THU
NISL@THU
C
Cyber Attacks, Cyber Crime and Cyber Security
GbyAI
GbyAI
Application and Cybersecurity Blog
Application and Cybersecurity Blog
T
The Exploit Database - CXSecurity.com
P
Proofpoint News Feed
Spread Privacy
Spread Privacy
L
LangChain Blog
N
News and Events Feed by Topic
量子位

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Memory code audit: the anti-drift discipline
Michel Faure · 2026-05-02 · via DEV Community

If you have 30 seconds. A Claude Code agent without versioned memory drifts — measurably, empirically, and all the more so as the project grows. This article gives the setup I use for 91,000 lines produced in 29 days: five types of memory files (user, feedback, project, reference, sessions), three audit rituals (immediate feedback, session after a project closes, biweekly cross-reading), and a regular ping-pong memory ↔ code that catches regressions before they ship. Useful if you see your agent confabulating about things you fixed last week.


The green build that wasn't

April 10th, 2026, overhaul of the attendance module. I'm moving with a Claude Code agent dedicated to our ERP, I chain five blocks of changes in two hours, and at every step the agent returns the same line: "Compiled successfully." I push. The Vercel runtime crashes. I reread the output: the agent references QRCodeSVG when the import has been removed, passes isSeancePassed to a component that no longer accepts it, leaves orphan JSX refs after a revert. TypeScript was screaming red; the agent was announcing green. Four times in one session.

While I'm noting the incident, Gaspard sticks a post-it on a folder open on the desk next door. Outside IT contractor for years, he handles hosting, DNS, admin accounts. His position is disappearing in September 2026 because Claude Code and I replace him in effect. I know it, he knows it. We haven't said it to each other. On the post-it, a Hostinger password and the rotation date. « C'est bon, ça tourne »All good, it's running — on his way out.

On the fourth false positive, I stop the work and write a thirty-line file in ~/.claude/agent-memory/: a dated, named, indexed feedback. The rule fits in one sentence: demand the raw pnpm build output, refuse any announcement that doesn't include it, recursive grep to verify reverts. Two weeks later, on a far more sensitive refactor — splitting an 1174-line P&L engine into six modules — the same dynamic starts. Except the rule exists. The agent this time produces the raw output. I see the error before the push. Integrity held because a file, somewhere, was questioning the present from the past.

That's the setup I want to describe here.

What memory does, what it doesn't

A coding agent without versioned memory drifts. This is empirical, it's measurable, and it's all the more true as the project lengthens. In four weeks and 91,000 lines, I've seen the agent confabulate about tables that no longer existed, reintroduce an anti-pattern fixed three days earlier, systematically overstate build status. The problem isn't the model's intelligence. It's the absence of a fixed point.

Written memory doesn't replace verification. It organizes it. It transforms oral rules — "remember that Server Components don't take onClick" — into verifiable, datable, indexable artifacts. And above all: it enables cross-auditing. Memory questions the code (is the rule still honored?). Code corrects memory (has the fact changed?). Without this regular ping-pong, memory atrophies as surely as code drifts.

This workstream is quiet. It produces no line of code committable in the application repo. Yet it manufactures the condition for all the others. It's the trace as an operator of integrity — writing what has been done so we can verify what is. Le tracème — a term I keep to myself, it's an adjacent research field — designates here the minimal node where an inscribed gesture (the commit) and its vigilance rule (the feedback) cross to produce a reproducible verification point.

I only understood late what this setup looked like from the outside. For fifteen years, the house's technical memory lived in Gaspard's head. Which admin account had which recovery email, which DNS redirect dated from when, which old vhost we didn't dare cut. He would answer, log in, repair. Embodied memory, reliable, entirely dependent on one man. The files in ~/.claude/agent-memory/ do the work his memory used to do, except that they remain once the man leaves. I don't hold this discipline purely out of technical hygiene; I hold it also because Gaspard is leaving, because what isn't inscribed will walk out with him. I'm writing the literate version of a human dependency I'm in the process of dismantling. I don't know whether to take pride in that.

The concrete architecture

The ~/.claude/agent-memory/ folder today contains a MEMORY.md index file and about fifty topical files, sorted by type. Five types only, each with a distinct function:

  • user — who the user is, what they know, what they don't want re-explained.
  • feedback — corrections of approach, rules drawn from incidents. Each feedback is structured: the rule, a Why line, a How to apply line. It's the most expensive to maintain and the most valuable in use.
  • project — the state of a workstream. Why a decision was made, by whom, on what date. Relative dates ("next week") are always converted to absolute — otherwise the memory rots.
  • reference — pointers to external systems: an Airtable base, a Slack channel, a Vercel cron, an internal doc.
  • sessions — a dated journal. 54 files to date, format YYYY-MM-DD_topic.md, constant structure: context, done, decisions made, next up. Chronological order makes sense, but so do neighborhoods: a session that rereads the previous three catches patterns invisible at the scale of a single conversation.

The MEMORY.md index is a flat table of contents. One line per file, under 200 characters. It's a discipline constraint: if the index becomes unreadable, it means the entries are too long or the topical granularity is wrong. The MEMORY.md is itself an audited artifact.

The three rituals

The setup only holds thanks to three rituals, each triggered by a different event.

First ritual — immediate feedback. As soon as a correction of approach happens during a session, you write the feedback before the session ends. Not at the end of the project, not "when I have time." Right away. The cost is five minutes, the benefit is measured three weeks later when the same mistake would have cost three hours. The 43 current feedback_* files all come from this ritual — each is the inscription of a moment where I had to tell the agent, out loud: "no, that, we don't do again."

Second ritual — session after closure. When a significant piece of work ends (not a quick question), you write a sessions/YYYY-MM-DD_topic.md file. Four sections, no more: context, done, decisions made, next up. The trap to avoid is completeness: the session must be usable, not exhaustive. What you write that you can no longer retrieve from a git log three months later are the arbitrations — why this choice rather than that, which assumption was accepted without debate, which constraint was worked around. The rest, you reread in the code.

Third ritual — periodic cross-reading. It's the least automatable and the most important. Periodically — every two to three weeks — you open a memory-vs-code audit session. You pick a handful of feedbacks at random, you verify the rules are still honored in current code. You pick a handful of projects marked "in progress," you verify they still are. It's during these audits that you discover a rule has been bypassed three times without the feedback being updated, a project marked open has actually been closed for two weeks, a fact described in a reference_* is no longer accurate. You fix in both directions: the memory or the code, depending on which drifted.

What you can copy into your project

Five directly applicable elements for your own Claude Code workflow:

  1. A versioned memory/ folder at the root of your project or in ~/.claude/agent-memory/, with five file types: user_* (who you are, who works on the project), feedback_* (rules drawn from incidents), project_* (state of ongoing workstreams), reference_* (pointers to external systems), sessions/ (dated journal in YYYY-MM-DD_topic.md format)
  2. A flat MEMORY.md as index, one line per file under 200 characters. If it becomes unreadable, your entries are too long or your granularity is wrong
  3. Three dated rituals: immediate feedback (before the end of the session where the incident occurred), session after closure (four sections: context / done / decisions / next up), cross memory ↔ code audit every two to three weeks
  4. The compact feedback format: the rule, a **Why:** line, a **How to apply:** line. Shorter beats more exhaustive
  5. Absolute dates: never "next week," always 2026-04-19. Your memory doesn't age if it's dated

And a deeper discipline: before recommending from memory, verify that it's still true in the code. A file can freeze in time faster than the code it describes.

And you — what information about your Claude Code project is currently written nowhere but could be tomorrow? I read the comments.

The ping-pong

The day the setup earns its keep is when you see a feedback catch a regression before it ships. In the case of feedback_agent_erp_build_verification, I had that precise sensation two weeks after the initial incident: the agent was starting to announce a green build without attaching the raw output; I demanded the output; it contained a TS2304 error. Thirty seconds of friction, zero broken push. The feedback had lived in the file between the two moments, silently, and it had done its job.

That's what anti-drift is. Not real-time surveillance. Not a monitoring tool. An inscription device that turns an isolated incident into an opposable rule, and that operates at the next occurrence. Memory isn't an archive; it's a contract the agent makes with itself, through a third party — the file — that doesn't confabulate.

What you end up understanding, from holding this discipline, is that it has nothing specific to Claude Code. Any long collaboration with an AI agent produces drift. The only question is whether you organize the trace that lets you detect it. Code without memory drifts. Memory without code atrophies. Between the two, the anti-drift discipline holds the integrity of the long gesture.

Last night, Gaspard came back in for the backup server. He had prepared a spreadsheet on his USB stick, four columns, thirty rows, the access credentials that lived in his head. « Si c'est ça que vous voulez, je l'exporte en CSV pour votre agent »If this is what you want, I'll export it as CSV for your agent — without irony. I imported it into reference_acces_gaspard.md, indexed in MEMORY.md, dated. Written trace took the place of embodied trace. The setup just gained thirty lines, the house just lost something I don't have the words to name.


Companion code: rembrandt-samples/claude-md/feedback-template.md — the structure of feedback_* files (Rule + Why + How to apply) with a worked example, MIT, copy-pastable.