Patch release.
Security
- Bump js-yaml, axios (GHSA-gcfj-64vw-6mp9), fast-uri (CVE-2026-18446) to clear HIGH CVEs — all within existing semver ranges.
Memory
- Looser schema, deeper dreaming, bi-temporal facts; compressed memory instructions; documented checksum provenance.
Skills
- Replace skills-guide with a writing-for-agents guide, add unslop skill; move source attribution into skill frontmatter; drop user-invocation from skill mechanics.