Parallel fleet audit (2 background agents) + direct work:
- src/commands/memory.mjs: `memory put --allow-secrets` was read as
`flags.allowSecrets` (camelCase) but the CLI parser only emits
kebab-case keys, so the flag was always undefined/false. Fixed to
`flags['allow-secrets']`.
- Docs: `lh graph --brief` was referenced 14x across 5 agent.md files,
harness.instructions.md, 4 SKILL.md files, onboard.prompt.md, and
README, but `lh graph` has no --brief flag (terse output is already
the default, --json/--severity are the only flags). Corrected every
reference to match actual CLI surface.
- .github/workflows/ci.yml: run npm install/validate/test on node 20+22.
- Self-dogfooded `lh init --yes` in this repo, producing .agents/
(harness.config.json, architecture.md, conventions.md, memory
shards). `lh doctor` now reports all required checks green.
- Deduped .gitignore harness block against init's auto-managed block.
Verified: 53/53 tests pass, validate 0 errors, doctor all-green.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>