How the Toolkit grows

Notes from the valley.

The release history below is rendered directly from the repository's canonical changelog.

View the source changelog

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.


Unreleased

1.44.0 — 2026-10-10

Added

  • The Library searches Skills and Agent Definitions together. The typed GET /api/v1/skills/catalog operation supplies provenance, dependencies, MCP requirements, and target compatibility separately from receipt-backed installation evidence.
  • World places support arrow-key focus and Enter activation, with the same canonical destinations as pointer navigation and the command palette.
  • First-run Desktop welcome opens into the semantic valley without creating sample projects, People, or runtime activity.
  • People history offers a reviewed fresh-session flow prefilled with the last project, runner, and model; it makes clear that conversation history is not resumed.

Changed

  • Replaced procedural building facades with original project homes and distinct shared landmarks, and refined the deterministic creek, paths, woodland, and project district composition.
  • Reduced World header controls to workspace context and the palette shortcut, giving the map more of the /world screen while preserving direct actions.
  • README and Desktop documentation now lead with genuine Electron screenshots, including a real Person session and reviewed Munder import. Removed obsolete unused native-GUI font assets and a stale test log.

1.43.0 — 2026-10-09

Changed

  • The shared valley avenue continues into the project quarter, while civic doors use shorter paths to the commons.

  • Replaced the five procedural tree silhouettes with a cohesive original six-variant tree set, including flowering, autumn, pine, creek willow and rune-lit forms; the source atlas, crops, prompt and asset hashes are versioned for offline generation and review.

  • Project roster tests now compare canonical symlink targets so temporary-directory aliases behave consistently on macOS.

  • The World operations landmark now has a distinct observatory silhouette, project interiors use aligned timber planks, and the creek is narrower with deterministic bank details. Dusk has stronger blue-hour contrast, and the README gallery now shows current Electron captures at compact and large sizes.

  • Desktop World, Library, People Start, Workspace, and the command palette now share the typed project roster API instead of parsing project list output. Workspace project rows show link health and open the same canonical project in World; verbose start-context and catalog reports are collapsed until requested.

  • Project room walls now include deterministic moonlit mural tiles, and the selected-place chip keeps local filesystem paths out of the visible world header. README status links are plain links beside authentic Electron screenshots rather than external SVG badges.

  • The Desktop Dusk world uses a stronger blue-hour terrain tint with warm clearing pools; visual-review capture waits for the loaded Library landmark before saving the map.

  • People Start now reviews a one-time editable task from the saved goal and sends its role/goal/task prompt to supported interactive runners without saving the task to the Person or changing runner permissions.

  • Electron now preserves the owning workspace and canonical session ID across its PTY bridge, so a real process exit updates the durable Person session instead of leaving stale running state.

  • World remains visible while live workspace data loads or the backend is unavailable; its loading plaque and offline notice distinguish known landmarks from incomplete runtime state.

  • Successful harness changes now update the URL-backed workspace scope for every destination. Project rosters revalidate when their view opens, and Person Start can use the supervised harness while the URL context initializes.

  • The README now leads with reviewed Electron screenshots, and release preparation uses a reviewed branch before tagging merged main.

Fixed

  • The Terminal destination now lets its session inventory scroll independently above the persistent dock at compact heights, keeping controls and the live PTY usable together.

1.42.0 — 2026-10-06

Added

  • Project interiors now gather the project board, records, files, and terminal into a compact room with crisp 5× scaling on large windows; live work remains the only source of runtime characters.

  • Command palette now opens the Library’s reviewed capability installation preview and offers catalog-backed MCP provider configuration reviews.

  • Library can review the exact GitHub Copilot instruction contents and destination in a linked project, reject destination symlinks, preserve existing instructions, bind install and removal to reviewed snapshots, preserve post-install edits, and show receipt evidence.

  • Library installation reviews can target selected user-level tools, report the exact targets applied, and show persistent evidence from real install receipts. World tool actions open the same target-specific review; repository-scoped Copilot installation remains outside this flow.

  • Library can install the complete catalog Skills tree into detected Claude Code and OpenCode homes through the existing dry-run transaction, and review receipt-based removal while preserving user-edited files.

  • Operations can inspect existing loop schedules, review the exact service/timer paths and cadence before installing or disabling one, expand the generated scheduler details when needed, and recover clearly when the OS scheduler rejects an install.

  • Desktop’s command palette adds direct Person actions: inspect a saved profile, start an offline collaborator through the normal review dialog, or open the real terminal for a live Person-bound PTY.

  • Library presents a typed MCP provider catalog with secret-free environment readiness, reviewed Toolkit-only setup/removal, local validation, and an executable probe that clearly does not imply a live MCP connection.

  • MCP discovery and setup resolve packaged embedded templates as well as checkout/XDG data, and the GitHub template pin now matches its reviewed file.

  • Project interiors now separate actual project files from shared/project memory: the filing cabinet opens read-only files from the registered project root through a typed, symlink-contained API, while the project overview board opens canonical project management. Both routes remain available through the standard workspace UI.

  • Desktop People can start real local PTY sessions in healthy project folders. Sessions retain Person and project identity, appear in the world only while the process is live, remain independent of the saved Person profile, and stay visible until a requested stop is confirmed by the process exit event.

  • Swarm role review now previews real backend resolution: explicit Person choices win, otherwise a unique active Person with a matching role/Agent Definition is assigned, with ephemeral fallback for unmatched roles.

  • Operations can pin or clear a workspace-default Person per swarm recipe role through the typed People bindings API; Auto uses those defaults before role matching and keeps the resolver guidance visible throughout the start review.

Fixed

  • Compact project interiors now inset the east window within the room instead of drawing it beyond the wall.

Changed

  • Dusk mode now dims meadow terrain while keeping water, foliage, labels, warm windows, and lanterns easy to distinguish.
  • The Desktop workflow ledger now records the People-by-role default editor and refreshed, reviewed compact/large swarm-start screenshots; remaining runtime-identity and World-projection gaps stay explicit.
  • Shared Files now has a readable sorting-depot landmark, while project Files stays a small filing desk inside the house; Settings now has its own rune-dial tower silhouette in the valley.
  • Valley woodland now reaches closer to walkable paths, while loose stones stay beside the creek instead of appearing as scattered meadow noise.
  • The five valley tree silhouettes now use a cohesive original pixel-art set with a rune-lit canopy, blossom, autumn, pine, and creek-willow varieties.
  • World groves now form deterministic overlapping tree clusters behind buildings and clear paths; flower glades are more frequent in open terrain.
  • Meadow ground now selects among 24 authored tile motifs, with broader clustered cover and occasional clover glints instead of a sparkle on every tile.
  • Project houses now keep a planted-width gap between lots so creekside clearings have room to read as gardens and groves.
  • Selecting a swarm run now moves its inspector below a compact run list and gives it the full reading width on large windows; run history remains scrollable without leaving half the screen empty.
  • Consecutive successful desktop actions now replace their transient receipt instead of stacking over inspectors; persistent failures and warnings remain visible until dismissed, and the full receipt history is retained.
  • Desktop now completes workspace switching through Settings: the backend restarts against the selected workspace, and the World reflects that workspace’s own project buildings after the service is live.
  • Recovering a Munder import ID collision by editing the Person now clears the stale save error before opening the create form.
  • People edit, archive, and restore now have a reviewed GUI lifecycle that keeps the saved collaborator offline until a real session is started.
  • Desktop’s World places shared services around a civic commons and registered project houses across a traversable creek; deterministic grass, willow, and shoreline art ground empty, single-project, and multi-project layouts.
  • Meadow colors now follow smooth deterministic terrain patches instead of changing palette tile by tile, and empty-workspace bridges align with the project’s real linking path.
  • Seeded meadow flowers, creek-bank trees, and edge undergrowth now appear more often. Active project settlements carry additional deterministic grove clusters while keeping tree trunks off paths and oversized canopies clear of building fronts.
  • Deterministic flower glades now form broader, readable beds in open ground while preserving connected trails and project entrances.
  • The creek now meanders from both sides of its bridge while staying within clear space between shared buildings and project homes.
  • The settlement now uses a tighter three-row composition so empty and one-project valleys fill compact windows at crisp 32px tiles while keeping every semantic place in frame.
  • Shared civic landmarks now gather around a staggered commons with clear front-door approaches from the Workspace Hall, connected stone paving at Operations, and a walkable southern lane.
  • The creek now takes a wider deterministic bend around real building footprints; its bridge stays joined to the shared route and water no longer overwrites landmark or project tiles.
  • Fit-to-world keeps crisp 32px tiles when the entire compact valley fits edge-to-edge, instead of shrinking one full tile row to preserve empty margin.
  • Desktop is packaged exclusively from the Electron app with a matching bundled V backend on Linux, macOS, and Windows. Release CI packages platform installers and verifies source, backend, and app version coherence.
  • Clean-machine acceptance launches the packaged Electron app with isolated user state. CLI gui now launches an installed Desktop or reports an actionable error instead of claiming an install or launch that did not happen.

Removed

  • Retired native V GUI sources, its packaging, Paper/Ink goldens, and Xvfb coordinate scripts. Current visual and runtime acceptance is through Electron E2E and packaged-app tests.

1.41.0 — 2026-10-02

Added

  • Desktop world camera: shared integer-zoom math for terrain, art and hit geometry; sprites keep manifest dimensions inside their semantic footprint; drag with a sub-5px threshold stays a click; zoom keeps the viewport center anchored; animation suspends under hidden inspectors and hidden tabs.
  • Desktop workflow ledger docs/desktop/workflows.yaml (Electron journeys, verified by workflowLedger.test.ts) and review ledger docs/desktop/PIXEL_VALLEY_REVIEW.md with the opened evidence set.
  • People contracts (docs/PEOPLE.md, ADR-036): agent-toolkit/person@1 and people-bindings@1 schemas, munder-difflin/hire@1 contract-only import mapping, mirror sync with SHA256 lock, and the offline scripts/validate-people.py validator. Workspace init scaffolds people/ and rejects symlinked destinations. GUI CRUD/import/Start/swarm-picker are explicit future work.
  • Desktop world project houses get dirt streets in the gutters between them, and the east creek is two tiles wide where the path crosses on a bridge.

Changed

  • World houses and shared landmarks are roof-first pixel buildings so the campus reads from above: cottage, studio, workshop, lab, library stacks, archive, operations, files, terminal, and settings.

Fixed

  • Loop runner parses multi-line goal:/request: YAML block scalars (|, >, chomping and indent indicators) instead of dropping them to empty. Full runbook prompts can now live in loop.yaml with no request.md sidecar.

1.40.0 — 2026-09-30

Changed

  • World building and landmark sprites fill their lot (nearest-neighbor), so houses and shared places read as buildings instead of small icons in a cell.

1.39.0 — 2026-09-30

Added

  • Desktop world grounds keep trees beside buildings and cross the east creek on a bridge. Decor stays non-inspectable.

1.38.0 — 2026-09-30

Added

  • Desktop world grounds grow a tile-aligned path, trees, and an east creek in empty cells only, on a tiled lawn. Decor is not a place, character, or inspectable entity.
  • Project interiors swap outdoor landmark sprites for room furniture (terminal desk, files shelf, records cabinet). Façade sprites sit on the lawn with labels underneath, not inside a card frame.

Fixed

  • OpenAPI surface version matches VERSION after the 1.37.0 bump.

1.37.0 — 2026-09-30

Added

  • Workspace Files panel over typed GET /api/v1/files (+ content / hits): real tree, masked/binary honesty, search hits — no invented nodes.
  • Desktop world commons: Operations and Settings places on the grounds (same destinations as the dock), plus a Files anchor inside project interiors.
  • Design boards for the cozy semantic world under docs/desktop/assets/design/ (no decorative NPCs from character rows).
  • Desktop world production sprites under apps/desktop/public/world/ mapped via theme façades. Project houses use stable cottage/studio/workshop/lab variants; commons landmarks are place-sized (Library, Archive, Operations, Files, Terminal, Settings, Attention).

Changed

  • Desktop world Escape leaves memory/tool detail first, then project interiors back to workspace grounds.
  • Memory archive tiles open the real memory-file inspector on /world. Files opens Workspace Files. Operations title replaces Workshop naming.
  • PRODUCT_VISION / UX_ARCHITECTURE / ADR-033: Electron + React is the shipping Desktop presentation; V remains core/serve authority.
  • Library place is labeled “Library”. Shared landmarks use place footprints. Interior room plate stays in the world. Grounds memory ledgers are capped.

Fixed

  • Desktop type-check: world memory fixtures match MemoryEntry (body) and nested provenance partials.

1.36.0 — 2026-09-30

Changed

  • Desktop world memory and tool detail inspectors expose a Back control and Escape that return to the project interior when ?project= is set, otherwise to the world grounds — without dropping the project.

Added

  • Desktop world memory-record and coding-tool detail inspectors stay on /world (?memory= / ?tool=). Memory loads GET /api/v1/memory/file?path=; tools show catalog fields from GET /api/v1/tools (enabled unknown stays unknown). Non-empty install_hint offers Install via POST /api/v1/install.

Changed

  • Desktop world activation opens existing inspectors: failed/rejected houses and blocked job characters → /office, calm/working project houses → /world?project=, terminal → /terminal, Library annex → /library, living jobs → /operations, memory records → /world?memory= (file read), tools → /world?tool= (catalog row). Map keyboard Enter/Space matches click; the structured list exposes the same targets.

  • Desktop world follows GET /api/v1/events: LiveProvider subscribes to memory. as well as backend., job., loop., swarm., and install.. job.updated patches known job status so house lamps and characters update before the next poll; memory.changed invalidates the memory domain without inventing archive rows; backend.ready / backend.resync resync jobs and memory (foreign boot = refetch, not a guessed picture). Swarm and loop events keep domain invalidation only — payloads lack a project id, so no house activity is invented from them.

  • Desktop world memory archive shows workspace-level records only; records whose provenance.project exactly names a roster project appear in that house. Empty provenance stays on the world archive — never copied into every interior. Job characters stand at a matching interior object when job.cmd exactly names memory, terminal/pty, or a detected tool.

  • Desktop world layout uses a fixed-width project district under the commons strip so house slots stay stable when the roster grows past √n thresholds. Failed/rejected houses and job characters open /office attention; queued and running still light the house and open Operations.

  • Command palette jumps focus semantic world places (memory archive, project houses, terminal, Needs you) and offer per-project “Open project …” rows from the live project list — no invented houses.

Added

  • Desktop semantic world default theme craft: richer Paper Co. DOM/CSS tiles (readable cottage silhouettes, wooden interior floors, card-index drawers, phosphor terminal desk), 48px tile scale, and CSS-only ambient motion that respects prefers-reduced-motion. No Pixi/Phaser; still semantic keys only; no invented knowledge rooms, NPCs, or metrics.

  • Upstream design/brag and design/brag-slim from latent-spaces/brag (MIT, pinned c893c5ed52aed84e3e2ee56787de869fccdae6b0). Full /brag vendors instructions, references, and helper scripts; bundled music/SFX under assets/ are omitted (unverified ende.app redistribution terms).

  • Electron + React Desktop (apps/desktop/, pnpm-only) over the canonical agent-toolkit serve backend: Office/Operations/Workspace/Library/ Insights/Settings/Terminal destinations, typed OpenAPI client with TanStack Query server state, named SSE job streaming, xterm terminals over a node-pty transport adapter, supervised bundled backend (health-gated, crash-detected, restartable), and electron-builder Linux AppImage/deb packaging (ADR-033).

  • First-party Desktop mutation gate: X-Atk-Desktop: 1 lets the Electron file:// client POST on loopback while cross-site browser pages stay rejected.

  • Job lifecycle on agent-toolkit serve: POST /api/v1/jobs/:id/cancel terminates a running job’s child (SIGTERM, grace, SIGKILL) and marks it canceled; DELETE /api/v1/jobs/:id removes terminal jobs (running jobs need ?force=true). Desktop Operations exposes cancel and delete.

  • Typed request bodies for the generic serve subcommand routes (skills, mcp, plugin, workspace, memory, project, loops, dc, swarms): per-family JSON options with OpenAPI requestBody schemas and a sub enum. The route path stays authoritative, unknown subcommands return 404, malformed bodies 400, and workspace/path/name fields are validated and contained.

  • Desktop design foundations: DESIGN.md tokens (Paper/Ink/System, Fraunces and IBM Plex), a primitive library with a native <dialog>, action receipts and per-destination error boundaries, a URL-backed context bar (workspace/agent/run, seeded from the #1314 harness IPC), a Ctrl/Cmd+K command palette, a persistent terminal dock, the design brief docs/desktop/ELECTRON_DESIGN_SYSTEM.md, and Playwright E2E that drives the built Electron app against the real backend under xvfb in CI.

  • Desktop default harness: the supervised backend runs in ~/.ai-workspace (cwd and AGENT_TOOLKIT_WORKSPACE) when it exists. The existing AGENT_TOOLKIT_WORKSPACE/HARNESS_DIR overrides still win. When neither resolves, Desktop falls back to the inherited cwd with a visible notice and never creates the directory. Settings and Office show the resolved harness and its source.

  • Desktop harness switch: Settings can pick a folder (atk:harness-choose / atk:harness-set) or return to the default (atk:harness-reset). The choice and an MRU list persist in <userData>/harness.json. Precedence is env override > persisted choice > ~/.ai-workspace > fallback. A switch restarts the supervised backend in the new cwd. New terminals default their cwd to the resolved harness.

  • Desktop backend binary resolution: ATK_BACKEND_BIN (authoritative) → bundled → staged → PATH, with a version-pin and serve capability probe before spawn. Incompatible binaries report failed/binary-rejected (or version-mismatch) with path, source, version and reason — not “crashed”.

  • Desktop Terminal workstation: session inventory (agent, run, cwd, process state) over the persistent dock — no second xterm — plus copy/paste, interrupt/terminate/kill, restart after exit, and drag-drop of file: paths into the PTY. Main keeps a 3000-line G1 tail. The world focuses a real session with ?pty= or agent/run/harness identity; unknown ids do not create a session. Electron E2E covers harness cwd, identity labels, navigation survival, world focus, and exit recovery.

  • Desktop Library, Insights and Settings: catalog tables from typed GET /api/v1/{agents,tools,providers} and real subcommands (skills/list, plugin/check, mcp/list). Detected / configured / enabled / verified stay distinct; running and cost stay unknown when the API does not report them. Settings extends the #1322 harness UI with Paper/Ink/System resolution and a rejected-binary table.

  • serve: global event stream GET /api/v1/events (SSE; job.*, loop.*, swarm.changed, memory.changed, install.*, backend.*). Each event has a process boot and SSE id <boot>-<seq>; Last-Event-ID wins over ?since and a cursor from another process yields backend.resync. GET /api/v1/jobs/{id} and POST /api/v1/jobs/{id}/retry (failed or canceled only).

  • Desktop Office is the attention inspector (not the product home): Needs you (crash / version-mismatch / harness / failed jobs / failing self-checks), Happening now, Failed, Completed, and What next. The semantic world opens it with href('/office') or href('/office', { inspect: <key> }). Rows use only real job fields. The palette’s “Next that needs me” cycles crash → failed jobs → running jobs. The renderer consumes GET /api/v1/events and says so when it must poll. Never claims the desk is quiet after a failed job or crash.

  • OpenAPI now carries typed response schemas (components.schemas) for health, selfcheck, jobs and events, sourced from docs/compatibility/api-schemas.yaml and parity-checked against the V structs. GET /api/v1/jobs is now documented.

  • serve: typed GET /api/v1/agents, /tools, /providers, /models (persona catalog, coding-agent CLI discovery, swarm runners and model profiles). Tool enabled is unknown until serve owns enablement.

  • serve: typed memory catalog — GET /api/v1/memory, /memory/hits, /memory/file; POST/PUT /memory/file; POST /memory/file/archive. List/search cover knowledge/{learnings,processes,todos}/ only (workspace knowledge files are not memory). GET /memory is 200 with an empty list when no workspace is configured. body is empty on list. Provenance is file/timestamp/project plus git author on read. GET is allowed for memory inject and todo (read-only).

  • serve: typed swarm runs/tasks/handoffs/approvals/artifacts and loop list/status/audit/history/cost. Cost is unavailable unless accounted.

  • Desktop Operations is the workshop inspector (jobs, loops, swarms, doctor), not a second home. It consumes GET /api/v1/events, job get/retry (#1320), loops list/status/run-as-job, doctor/fix, typed swarm run/task/handoff/ approval routes plus {sub} start bodies, and GET /api/v1/agents|tools|providers|models (#1324) for swarm/loop forms. Retry is offered only for failed/canceled jobs. Swarm and loop actions use OpenAPI bodies, not freeform argv. Events never invent progress.

  • serve: workspace-contained files — GET /api/v1/files, /files/hits, /files/content; PUT /files/content. Escaping symlinks are rejected, secret filenames are masked, and writes are atomic with size/binary guards.

Changed

  • serve no longer reaches loops run, loops gate-* or swarms attach through the generic :sub routes; use POST /api/v1/loops/{name}/run or the CLI.
  • Renamed docs/desktop/MUNDER_GAP.md to docs/desktop/WORKSTATION_REFERENCE_ANALYSIS.md and expanded it into the three-way workstation decision artifact (Agent Toolkit, Munder Difflin, Agent Office). The Electron capture recipe and baseline screenshot references are unchanged.

Fixed

  • memory add --type learning no longer corrupts the learnings table: each new row gets its own line (previously the second add left a blank line after the separator and glued rows together). A blank line left between the separator and existing rows by older builds is removed on the next add; rows older builds already glued together (| … || … |) need a manual split.

1.35.0 — 2026-09-29

Added

  • Measured-text core for the native Desktop GUI: measure_text/fit_text with a cache replaces fixed-average truncation and byte slicing, so labels and help bindings clip on grapheme boundaries at their real width.
  • Attention and help affordances: the Office zero-state scopes to failed and queued jobs, and the help card is content-sized to the longest measured binding line.

Changed

  • Palette Setup row opens the Settings panel with the setup-journey overlay, matching the row’s promise instead of a dead end.
  • Golden UI fixtures (paper + ink) re-promoted from CI actuals reviewed at full size; tool probes freeze to a bare machine under ATK_GUI_FREEZE so golden captures stay hermetic.

[1.34.0] — 2026-09-28

Added

  • Native Desktop onboarding that earns its place: a short staged flow whose finish state and pending-tool rows are covered by Engine-independent view tests.
  • Office floor orientation: the focused panel is named in place, dock tabs carry single-key badges, and header search is scoped to the visible floor.
  • Library safety: keyboard-initiated Remove on installed or MCP rows now asks for a second Enter before calling the Engine; clicks keep working directly.
  • Footer and empty-state hints that navigate: Office footers point at the tab that owns the state, and the Operations hint jumps to Agents, Loops, or History as named.

Changed

  • Desktop copy pass: user-voiced confirmations, sentence-case labels, and a two-line Operations hint that no longer clips mid-phrase.
  • Golden UI fixtures (paper + ink) re-promoted from CI actuals reviewed at full size for the orientation, confirm-gate, and navigation-link rendering.

[1.33.1] — 2026-09-28

Changed

  • Upstream skill sync vendored into main (blast-radius, unslop).

[1.33.0] — 2026-09-28

Added

  • Native Desktop UX convergence (V + gg/sokol, Paper Co. identity): floor IA with live onboarding rail and honest-empty dialogs, attention summary strip on the Office floor, Loops strip on the Operations floor, status-bar hints, and Engine-level job-to-agent attribution with a live agent roster.
  • Golden UI fixtures (paper + ink) promoted from CI actuals reviewed at full size for the combined hint + attention / Loops rendering.

[1.32.1] — 2026-09-20

Fixed

  • CI 100% green on main: provenance tests assert the honest experimental / unbound trust state (no forged review bindings), stale upstream pin synced, path-aware updates-discovery mocks, macOS launchd schedule asserts.

[1.32.0] — 2026-09-20

Changed

  • JIRA integration migrated to the thin upstream skill (jira-assistant v5.0.0, jira-as CLI as source of truth); the 13 granular skills were removed and all mirrors, docs, and embedded data resynced.
  • Loop engine convergence: token-aware gate-exec verifier persistence, kind-aware token accounting, wall-timeout floors, --force never bypasses token budgets, target-bound gate receipts, loop schedule service management (systemd/launchd) with --list/--status/--remove.
  • Desktop jobs supervisor cancel-race fix; swarm budget limits; agent-tools validation; stale JIRA mentions purged from plugin mirrors.

[1.31.0] — 2026-09-17

Loop helpers graduate into the CLI: loop run --runner dispatches seven LLM runners, the gh gate and CI waiting are built in, and workspace bin/ wrappers retire.

Added

  • loop run --runner claude|opencode|codex|cursor|copilot|muse|pi with PATH probe, cursor cursor-agent → agent → cursor chain, and fail-closed skeleton (ADR-020). AGENT_TOOLKIT_LOOP_MODEL pins --model on all seven.
  • Top-level agent-toolkit ci-wait <repo> <pr> (exit 0/1/2, exact-word matching, 15→60s backoff).
  • In-process gh gate for loop runs (per-run shim, receipts, attribution, gate-denials.jsonl audit); read-only release/gist/repo/secret/variable/ workflow subcommands pass.
  • loop schedule --runner/--platform; generated units carry WorkingDirectory; skeleton runs log the runner fail-closed note.

[1.30.3] — 2026-09-14

A reliability patch: deterministic distribution ordering, the headless-safe Desktop --version/--help, and the upstream-sync toolchain bootstrap.

Fixed

  • Distribution race: the npm, Homebrew-tap, and AUR notifiers triggered on tag push in parallel with the Release workflow and 404’d while assets were still uploading. They now run after Release completes successfully (workflow_run), so prerequisites are guaranteed; the wait loops remain only as CDN-propagation resilience.
  • Desktop binary: agent-toolkit-desktop --version and --help no longer initialize the GUI. Informational flags are served before any display/window setup, print and exit 0 with no DISPLAY/WAYLAND_DISPLAY required; unknown flags fail cleanly with exit 2. Covered by cmd/agent-toolkit-desktop/desktop_args_test.v.
  • Upstream sync: the scheduled Discover/sync workflow now provisions the canonical pinned V toolchain required by scripts/upstream_pr_body.vsh.
  • Dependabot: github/codeql-action/* updates are grouped so init and analyze bump atomically instead of failing on version skew.

[1.30.2] — 2026-09-14

A documentation release: real product screenshots across the root README and the npm/PyPI package pages, plus reconciled install floors.

Added

  • Six captures of the production desktop app (onboarding, Office hero, Library search, Operations, terminal, Insights) under static/screenshots/; hero + gallery in the root README, compact Desktop GUI sections in the npm and PyPI READMEs.

Fixed

  • Stale install floors (agent-toolkit-cli>=1.11.0 → >=1.30.1) and the VERSION 1.30.0 channel drift in packaging docs.

[1.30.1] — 2026-09-13

A product-hardening release: the native Agent Toolkit Desktop becomes a coherent, installable product with truthful Engine-backed state, a standalone Linux installation path, and a maintainable codebase. No new product surface beyond what 1.30.0 introduced — this release finishes it.

Native Agent Toolkit Desktop

  • Paper Co. product experience across six destinations — Office, Library, Operations, Workspace, Insights, Settings — plus a guided onboarding board: editorial mastheads, pixel-art scenery, destination-owned detail columns, honest empty states that name the real launch path.
  • Truthful state everywhere: every user-visible value comes from Engine evidence or renders explicitly as unknown/empty — no fabricated activity, jobs, agents, health, receipts, metrics, progress, or installs.
  • Embedded terminal: real PTY with Ghostty-compatible VT (SGR palettes, scrollback bounds, resize reflow, rune-safe CJK/emoji wrap), session picker, scrollback search, height modes; covered by headless suites that run in Required CI on Linux and macOS.
  • Shell layout persistence: panel, terminal mode, zoom, language, insights tab, and swarm backend restore on relaunch; derived state stays restorable, session-only values stay session-only.
  • Toast tray: Engine action feedback as auto-expiring paper stamps.

Standalone Linux installation

  • One canonical path: release tarball + receipt-backed per-user install-desktop.sh (no sudo, XDG user scope) — binary, launcher entry with absolute Exec, hicolor icons including a resolving scalable SVG, man page, and a schema-versioned install receipt.
  • Idempotent reinstall (byte-identical owned files refresh, user-modified files flip to preserved) and receipt-backed uninstall that removes only owned artifacts.
  • Proven in CI and sandbox: fresh install → reinstall → foreign-file preservation → uninstall, desktop-file-validate green, no source-path leakage, no secrets in receipts. AppImage evaluated and deferred — the tarball path is the single supported Linux install.
  • Clean-machine acceptance runs in CI: packaged artifact → clean install → GUI launch → onboarding → discovery → workspace → restart persistence.

Reliability and maintainability

  • Codebase reads as designed, not accumulated: historical implementation-campaign labels removed from production identifiers, comments, and tests (history preserved in git/ADRs/frozen audits).
  • Engine owns domain truth: workspace-scaffold probing, dock-layout and shell-layout persistence moved into typed Engine projections with focused tests; views consume facts instead of discovering them.
  • Obsolete Phase-0 GUI feasibility spike retired (−834 lines); production is gg/sokol-direct (recorded in ADR-032).
  • Hermetic V toolchain bootstrap: pinned V/VC/TCC inputs, pin-embedded cache key, retries — reproducible cold builds.
  • Tooling consolidated to V scripts with byte-identical output (prepare-package-data, prepare-native-bin, contrast/tofu checks, taxonomy, icon generation, surface/target-matrix generators); contrast gate enforced in CI for both themes.
  • Documentation reconciled: truth ledger and workflow coverage re-baselined with re-evaluated claims; install/packaging docs describe the proven path; platform support stated honestly.

Notable fixes

  • Palette registry Engine-pointer fix (first-keystroke segfault eliminated).
  • Bounded sprite cache with LRU eviction (glyphs no longer vanish when the sampler pool exhausts).
  • Linux/X11 text input, glyph coverage, type-ramp atlas safety, UTF-8 Arabic/CJK font routing.
  • Inspector overdraw, desk-label anchoring, job Cancel/Retry and swarm launch actions that previously only printed messages now execute through the Engine and report real results.

Known limitations

  • Desktop-menu click acceptance stays manual; macOS/Windows install paths unproven and unclaimed; updater honestly unavailable until a real feed exists. Accessibility remainder (reduced-motion view wiring, focus rings), i18n panel bodies, Arabic shaping decision, perf budgets, and responsive matrix are tracked post-release work.

[1.30.0] — 2026-09-02

  • Feat (desktop) — Paper Co. design pass on the native GUI: every panel on the warm paper ledger (cream/manila/kraft cards, brass rails, Fraunces letterheads) with the ink filing-cabinet chrome; unified paper letterhead paper_letterhead for all 13 panels
  • Feat (desktop) — Brand typography shipped in-binary-adjacent: Fraunces Display (letterheads), IBM Plex Sans (+SemiBold), IBM Plex Mono (real mono slot via IBMPlexSansMono naming), IBM Plex Sans Arabic, Noto Sans SC chrome subset (34 KB) — all OFL in assets/fonts/, resolved next to the binary, graceful system-font fallback
  • Fix (desktop) — Text input was dead on Linux/X11: V sokol delivers printables as separate .char events; on_event now replays them as key_down (per-frame dedupe for C backends). Palette, search, skills filter, memory recall and the Ghostty prompt all accept typing now
  • Fix (desktop) — Glyph coverage: replaced symbols missing from Plex (⌘ ⌕ ● ◐ ○ ◉ ▾ ▸ ◈ ≡ ✉ ■) with drawn primitives (draw_envelope, draw_search_lens, draw_floor_legend) and safe glyphs; minimum type size raised to 10 px
  • Fix (desktop) — Type ramp quantization (type_ramp): zoom snaps to 12 canonical sizes so the fixed fontstash atlas (sfons cannot expand) cannot overflow into tofu; release builds use -d gg_text_buff_size=4096
  • Fix (desktop) — needs_sc/needs_ar iterated UTF-8 bytes (for ch in s semantics in V 0.5.2) — now iterate .runes(); Arabic + CJK font routing works everywhere
  • Feat (desktop) — i18n 4-lang EN/ES/中文/عربي with RTL: dock/inspector flip for Arabic (bidi-lite run reversal), translated dock, header, status bar, palette labels/descriptions and panel letterheads; language chips in the header (click or palette)
  • Feat (desktop) — Insights grows to 7 tabs: new Realtime (EventBus live feed + GOD 4·t·(1−t) flow meter) and Gallery (living style guide: palette chips, type specimens, components); Budgets now renders recent loop history rows; tab hit-tests match the new layout
  • Feat (desktop) — Embedded terminal UX: GHOSTTY VT header with focus pill, height modes 1× / 2× / MAX / hidden (buttons + Ctrl+`), 16 px rows, per-desk VT preview enlarged (6 rows) in the inspector
  • Feat (desktop) — Office floor re-layout: 15 desks on a clean grid, GOD manager corner + station wall in a kraft-divided right corridor (no more card overlaps), legend swatches, fleet minimap
  • Feat (desktop) — Self-contained fonts: the 8 brand fonts are embedded in the binary ($embed_file) and auto-extracted to ~/.cache/agent-toolkit/desktop/fonts/ on first boot — released single binaries render the full stationery with no packaging steps (binary 10.0 → 11.3 MB)
  • Chore (desktop) — VERSION-aligned header, folder tab + manila stationery signatures, scripts/subset-sc-font.sh tooling

[1.26.0] — 2026-08-31

  • Feat (insights) — Re-port agent-toolkit insights as native V command (pure V, all runners): opencode, cursor, claude, windsurf, copilot, codex, pi, muse, all — with --days, --output, --json, --no-llm. No Python dependency. /api/v1/insights server route added.

  • Feat (swarm) — Graph-engineered swarms: feedback cycles (reviewer⇢implementer bounded by round-trip limit), swarm graph --json live topology, edge activation (autostart + wake on every handoff type)

  • Fix (loop) — Restore attribution support in V (was lost in the rewrite): attribution: false|true|{enabled,template} in loop.yaml

  • Fix (swarm) — Enforce graph delegation: --to flag shadowing fix, audit gate on commit handoffs, Python-parity aliases (recipe list, ls), swarm attach argv fix, herdr lifecycle fixes

  • CI — Validate workflow fix (paths+paths-ignore 422), swarm-e2e backend selection, macOS mcp test skip, plugin check advisory, loop help grep fix

  • Feat (swarm) — Full multi-agent orchestration parity with the legacy Python CLI, plus new capabilities:

    • swarm start flags --request-file/--issue/--base-ref/--workspace/--json (#883, #915); git worktree per writer with lazy initial_roles (#884, #912); compose_role_prompt + GLOBAL_PROTOCOL + per-role prompts (#885, #913)
    • Blocking attach (os.execvp-style) + swarm attach subcommand for tmux/herdr (#886)
    • Lifecycle: pause/resume/stop/cleanup/promote (#887, #914); init/plan/activate/deactivate (#905, #934)
    • Observability: watch/report/artifacts/handoffs/logs/approvals (#889, #922); status --json full payload (#896, #925); list --json + list_all_runs (#895, #918)
    • Atomic state store with STATE_VERSION, worktree dirty guard, task-contract (#891, #923); per-recipe budget (900k tok / $4 / 7200s pair/team, 1.2M / $8 / 10800s full) with budget_exhausted state (#892, #924)
    • runners + models commands (#893); recipes detail parity (#894, #917); config resolve_config + BUILTIN_RECIPES persona/policy (#897, #926)
    • swarm prune --older-than (7d default) + herdr --json fallback (#909, #938)
    • NEW (this release): graph-engineered swarms — the run is a directed graph, not a pipeline: nodes are roles, edges derive from consumes/produces (multi-successor fan-out), and feedback cycles (reviewer⇢implementer, bounded by the blocking round-trip limit) re-loop work for iteration. New swarm graph <run-id> [--json] renders the live topology: node status (running/waiting/unspawned), edges, and in-flight handoffs
    • NEW (this release): role-chain auto-start — when a work handoff (artifact/commit) reaches a waiting role, its runner launches automatically in its existing pane/window (swarm-forge handoffd behavior without the daemon): implementer → reviewer → integrator chain runs end-to-end; the “Will auto-start ” UX promise is now true
    • NEW (this release): real tmux UI spawn — swarm start --backend tmux now creates the dedicated socket (agent-toolkit-swarm-<id>), the session, and one window per role, launching the same runner surface as the herdr backend (previously it only attempted an attach to a session that was never created)
    • NEW (this release): visual test harness — scripts/swarm-visual/ (tmux pipe-pane continuous log → ANSI→PNG renderer + timeline GIF, per-role process probes, herdr pane read snapshots); runbook in docs/v/swarm-visual-testing.md
    • Fix: swarm attach — V’s os.execvp prepends prog to argv itself, so the duplicated argv[0] made tmux/herdr fail with unknown command: tmux; herdr attach now resolves the workspace id by label and runs workspace focus (workspace open does not exist in herdr 0.8)
    • NEW (this release): handoff audit gate — first commit handoff per (run, from, to, commit) returns AUDIT_REQUIRED; an identical re-run passes and queues; any payload change re-challenges (swarm-forge discipline, filesystem SoT)
    • NEW (this release): swarm recipe list, swarm ls alias (Python parity) and fix: handoff create --to ROLE was shadowed by the promote --to parser rule and silently ignored
  • Feat (V parity sprint) — close the Python→V capability gap: loop gh_gate + budget enforcement + pack parity (#898, #927); install compiler targets pi/windsurf + tool_mapping (#899, #928); doctor provenance/pack/MCP/matrix + swarm herdr/tmux checks (#900, #929); workspace 11-subcommand parity (#901, #930); project init + OWNER/REPO shorthand + --workspace/-C (#902, #931); devcompanion queue --template/--request/--id + run-once --no-llm + llm-status (#903, #932); mcp registry + offline + health/doctor parity (#904, #933); serve/tui not masked in contract (#908, #937)

  • Feat — Vendor 31 JIRA + Confluence skills as first-class upstream capabilities: 14 integrations/jira-* (grandcamel/JIRA-Assistant-Skills @ b583731) and 17 integrations/confluence-* (grandcamel/Confluence-Assistant-Skills @ 403eac8). Bodies byte-identical to upstream; Toolkit frontmatter overlay + provenance lock + trust.reviewed_provenance binding. jira-assistant / confluence-assistant are the router hubs. Require jira-as / confluence-as CLIs (provisioned by workstation, not toolkit)

  • Feat — Skill capability registry grows 85 → 116; all 31 owned by platform-engineer, wired into skills/core/assistant/references/ORCHESTRATION.md

  • Chore — Docs counts switched from exact (“85 skills”) to floor (“116+ skills”) with a new tests/test_docs_count_floor.py guard (floor never overstates catalog; precise SoT remains agent-toolkit inventory)

  • Feat (taxonomy) — Target capability registry (#862), skill capability map (#863), specialist taxonomy decision (#865), agent relationship graph (#866), portable Agent Plugin compiler (#867), adapter tiers (#868), nine-harness adapters (#869), swarm role alignment (#870)

  • Feat (build) — insights claude --days + context_budget clip 2000 parity in bin/tool-insights (#906, #935 — insights left the CLI per #526)

  • Docs — docs/v parity post-9163c93: cutover.md + rollback.md promoted from archive/, pypi-launcher.md + python-fallback.md synchronized to the hatch trampoline (#907, #936); single docs/adrs/ tree (34 records); distributions/ vs distribution/ disambiguation README; README/CONCEPTS/CONTRIBUTING made declarative (floors over counts, no stale links); docs/surface/openapi.json regenerated for 1.25.0; docs/compatibility/cli-contract.yaml synced to the shipped V surface (flags, subcommands, 21 entries)

  • CI — swarm-e2e gate added to Required CI, macOS matrix for check-v-modules + parity, path filtering for docs-only PRs (#941); Jira operations skill checks repaired; yamllint alignment with generated data; shipped profiles/plugins refreshed to 116+ floors and retired-insights references removed

1.24.0 — 2026-08-25

  • Feat — New skill architecture/architecture-diagram: create polished dark-themed architecture diagrams as self-contained HTML+SVG files (semantic color palette, spacing/legend layout rules, PNG/PDF export toolbar). Ships resources/template.html as the customization starting point. Registered in agent-toolkit-complete and the architecture domain (85 skills total)

1.23.1 — 2026-08-25

  • Feat — GET /api/v1/jobs/:id/events: SSE streaming of job lifecycle (status/log/done) — resolves the async-execution story (#859)
  • Feat — Deep selfcheck: route_manifest_match runtime diff of registered routes vs embedded OpenAPI (#859)
  • Feat — OpenAPI now documents server-native endpoints (health/openapi/selfcheck/jobs+events/doctor-fix/loops conveniences/swarms)
  • Fix — POST /api/v1/jobs: inject --workspace only for workspace-aware commands (loop); other commands run with the resolved workspace as working directory
  • Tests — Parity gates extended: registered_api_routes const ↔ route attributes ↔ OpenAPI exact match

1.23.0 — 2026-08-25

Breaking: the interactive TUI is no longer a supported product surface. agent-toolkit tui now prints a removal notice (exit 1). Capabilities remain fully available via the CLI and via the programmatic API (agent-toolkit serve). Rationale and migration: ADR-030.

  • BREAKING — Retire TUI: remove modules/agent_toolkit_tui, generated tui_registry.v, docs; CLI keeps an actionable removal stub ([#837] superseded by ADR-030)
  • BREAKING — Retire Web application: replace the dashboard SPA with a minimal static server status page; remove web_nav.json generation ([#838] superseded by ADR-030)
  • Arch — ADR-030 supersedes ADR-029: contract semantics move from presentation parity to capability description; parity gates now enforce contract ↔ OpenAPI ↔ registered server routes only
  • Feat — GET /api/v1/selfcheck: runtime coherence checks (embedded OpenAPI freshness vs running binary, jobs dir writability, bind policy)
  • Feat — Add missing programmatic surfaces for contract capabilities: POST /api/v1/loops/{sub}, /api/v1/dc/{sub}, /api/v1/swarms/{sub} (thin core proxies)
  • Contract — Drop insights/release entries (retired commands are not capabilities); add api: false for human-only meta capabilities (completion, serve)
  • Tests — Rewrite test_surface_parity.py: capability↔OpenAPI↔routes coverage, retired-artifact guard, scope/confirm metadata; TUI registry test removed

1.22.3 — 2026-08-24

  • Fix — TUI Skills: use find_toolkit_root() + embedded fallback (was lookup_checkout_root only, failed from ~/.ai-workspace with skills not found)
  • Fix — Server: jobs log not found — watch() now captures stdout/stderr and writes log_path, handles workspace param and --workspace injection, fixes arg duplication loop loop
  • Fix — Server: workspace routing — jobs_create/loops_* now honor workspace field / AGENT_TOOLKIT_WORKSPACE / walk-up instead of hardcoded os.getwd() (fixes other campu without --workspace)

1.22.2 — 2026-08-24

  • Fix — TUI: support legacy LOOP.md, add --workspace flag, fallback to bundled templates when workspace empty (fixes tui showing no loops in my-ai-workspace)
  • Fix — TUI: resolve_workspace now honors AGENT_TOOLKIT_WORKSPACE/HARNESS_DIR and walk-up loops/.git/AGENTS.md/knowledge

1.22.1 — 2026-08-24

  • Fix — Server embed: use to_string() not str() for $embed_file — web was returning EmbedFileData{...} debug struct instead of HTML (affects /, /openapi.json, /help)

1.22.0 — 2026-08-24

  • Feat — Real interactive TUI: ANSI colors, 4 screens (dashboard/loops/skills/doctor), j/k navigation, reverse-video selection, loop browser with goal preview, doctor checks with ✓/!/✗ colors, help screen, in-process core calls per ADR-494
  • Feat — Full Web dashboard SPA (330 lines): sidebar nav Overview/Loops/Skills/Doctor/Run, stats grid, loops table tier badges L1/L2/L3 color-coded, searchable skills table, doctor report, jobs list with status colors, log viewer monospace, toast system, hash navigation, 15s auto-refresh with AbortController
  • Fix — Embed web assets at compile time via $embed_file for self-contained serve, fix web tier= stripping, esc() XSS protection, refresh() undefined, pad_right negative panic, AbortError handling
  • Chore — Unify terminal help for tui/serve, workspace walk-up resolution

1.21.0 — 2026-08-24

  • Fix — Embed web/index.html, openapi.json, cli-help.md at compile time so serve works from any directory (#850, #851)

1.20.0 — 2026-08-24

  • Feat — TUI MVP: agent-toolkit tui dashboard with loops table (tier, cadence, status), in-process core calls, offline-first (#837, #848)
  • Feat — Web UI SPA: single-page dashboard served at / by serve (health badge, inventory counts, loops table, doctor report, run loop via Jobs API) (#838, #849)
  • Feat — Full CLI parity: 21/21 contract commands now have HTTP routes via serve (install, update, uninstall, skills, mcp, plugin, workspace, memory, project, build, swarms) (#836, #846, #847)
  • Docs — docs/security/threat-model-serve.md with STRIDE analysis and abuse-case checklist (#541, #847)

1.19.0 — 2026-08-23

  • Feat — Feature-complete serve (unified platform, SSOT contract): codegen generate_surface.py emitting openapi.json/cli-help.md/web_nav.json/tui_registry.v from cli-contract.yaml with parity tests (#831), ADRs 027-029 (thin adapter, security defaults, surface-parity SSOT) (#832), serve skeleton via veb (/health, /version, /openapi.json, remote bearer gate) (#833, #844), read-only APIs (/inventory, /doctor, /matrix, /diff, /loops) (#834), Jobs API with process-per-run + SSE (POST /jobs, GET /jobs, GET /jobs/:id/log) (#835), gated writes for full CLI parity (install, update, uninstall, skills, mcp, plugin, workspace, memory, project, build, swarms, loops/:name/run|schedule) (#836, #847)
  • Docs — docs/LOOPS.md remote execution via schedule --platform github-actions + examples/remote-loops, docs/security/threat-model-serve.md (STRIDE, 7 threats, abuse checklist) for #541
  • Fixed — serve now uses vlib/veb per maintainer decision (was net.http stub)

1.18.0 — 2026-08-21

  • Feat — Complete Epic #743 (cursor/plugins adoption): vendor tooling/cli-for-agents (#779), absorb fix-ci patterns into forge/gh-fix-ci (#780), add forge/fix-merge-conflicts (#781), extend core/workspace-knowledge-sync with learned facts (#792), and add first-party quality/deep-review rubric (#808)
  • Feat — Emit hooks/hooks.json for Cursor from the canonical capabilities/hooks/*.yaml registry (#794)
  • Feat — Spec-complete Cursor/Claude plugin.json manifests ($schema + author.url per Agent Plugins 1.0.0) (#795)
  • Feat — New stable agent-toolkit-craft product (unslop + deslop + blast-radius), registered in Claude Code and Cursor marketplaces (#796)
  • Chore — Integration audit: inventory counts (84 skills / 17 agents / 5 products), marketplace docs (four plugins) (#756)
  • Fixed — Catalog/profile/docs drift audit (20 issues): sync skills-layout.json ghost ui-ux-pro-max → 84 skills (#799, #810), remove ORCHESTRATION.md ghost (#800, #811), remove 3 dangling pack loops + phantom agent (#801, #812), fix SKILLS.md domain counts (#802, #813), expand AGENTS.md allowlist 9→14 domains (#803, #814), fix MCP dead links 7→8 (#804, #815), badge drift 80→84 + ADR-026 + wiki links (#805, #816), add test_skills_layout coverage (#806, #817), Pi/Muse-code profile parity (#807, #818)
  • Fixed — CHANGELOG missing 1.17.0 (#782, #819), Cursor README heredoc (#783, #820), duplicate forge/workflow-* stubs (#791, #821), complete missing 17 agents (#793, #822), profile parity contribution-planner + inline settings.json (#784, #785, #823), PROFILES.md Cursor per-agent (#788, #824), muse-code/codex/gemini profiles (#789, #790, #825), Pi docs (#787)

1.17.0 — 2026-08-21

  • Feat — Embed all capability data in V binary — standalone offline-first (distribution) (#778)

1.16.0 — 2026-08-19

  • Docs — Add upstream vs first-party governance (docs/UPSTREAM_VS_FIRST_PARTY.md), skill integration checklist, and ORCHESTRATION.md routing table (Epic #743, Wave 0) (#757)
  • Feat — Vendor quality/unslop, quality/deslop, and quality/blast-radius from cursor/plugins (complete product; provenance lock) (#759, #746)
  • Fixed — MCP templates use official servers only; remove all wrapper.sh launchers (#765)
    • Slack → @modelcontextprotocol/server-slack (SLACK_BOT_TOKEN + SLACK_TEAM_ID)
    • Notion → remote OAuth https://mcp.notion.com/mcp + local @notionhq/notion-mcp-server fallback
    • GitHub → ghcr.io/github/github-mcp-server (Docker)
  • Docs — Expand MCP template READMEs for Notion, Slack, and GitHub (#742, Resolves #339)
  • Docs — README footer: star CTA, issue templates, contributors grid (#764)
  • Fixed — Include quality/deslop in agent-toolkit-complete product membership
  • Docs — Regenerate docs/UPSTREAM.md after blast-radius vendor (10 capabilities)
  • Docs — Make static/*.svg command-accurate: real agent-toolkit install / documented install paths and per-tool dests from install.v; drop invented ~/toolkit --mode=production, muse skills install, Copilot/OpenCode agents-or-skills checkmarks, Cursor marketplace.json as an install dest, Pi loops, and L3 agentic-harness

1.15.0 — 2026-08-16

  • Feat — Restore literal upstream skill bodies and weekly sync PRs (#737)
  • Docs — Add npm / PyPI version + downloads, AUR, Homebrew, GHCR, and GitHub Release badges to the root README and published adapter READMEs; align AUR install examples to agent-toolkit-bin (#738)
  • Docs — Refresh static/*.svg to current inventory (80 skills, 7 tools including Muse Code, all 10 loop names, install channels); align live docs that still said 77 skills (#739)
  • Docs/CI — Invoke shebang .vsh scripts as ./scripts/… / ./make.vsh (not v run scripts/…); Windows GHA keeps "${VBIN}" run make.vsh exception (#736)
  • Fixed — bump-version.vsh updates generatorVersion in plugins/*/.provenance.json (not only digests / "version" sidecars)
  • Breaking (contributor) — Retire scripts/gen-surfaces.vsh and CI check-surfaces (ADR-003 Remove). Sole surface gates: agent-toolkit build --check + agent-toolkit plugin check (#734)
  • CI — Add Required check-v-modules (./make.vsh vet / test; fmt-check deferred — modules not fully vfmt’ed / json2 risk); drop coverage and test-uvx from Required (test-uvx = published PyPI smoke on main/dispatch only); experimental-v.yml is workflow_dispatch only; unify V install via setup-v in validate/parity/release/experimental
  • Chore — Remove dead scripts/validate-skills.sh, scripts/install.sh, and scripts/doctor.sh; docs/CI use V CLI and *.vsh validators (ADR-007 Remove phase)
  • Chore — Add scripts/validate-loops.vsh (python3+jsonschema); validate.yml validate-loops job calls it
  • Chore — Archive legacy schemas/skill.schema.json → docs/archive/ (skill.json removed; see MIGRATION.md); products.yaml version_source: VERSION
  • Docs — Present-tense V-first contributor docs (AGENT.md, generated catalogs, no installer/sources.py); move strangler-era docs/v/* to docs/v/archive/; ROADMAP post-1.14; ADR-003/004/007/012 amendments; docs/adrs/README.md index; Homebrew formula PR permissions note (#735)
  • CI — Skip Docker image smoke when GitHub Release v$(VERSION) does not exist yet (version-bump chicken-egg; Release.yml still publishes after assets)

1.14.1 — 2026-08-14

Patch release for post-v1.14.0 release hygiene that landed on main after the tag.

  • Fixed — bump-version.vsh now bumps Dockerfile ARG VERSION, Codex/Gemini/pi plugin sidecars, and refreshes plugins/*/.provenance.json digests for plugin.json so plugin check stays green after a version bump
  • Chore — Sync leftover 1.14.0 sidecars that the previous bump missed; tighten Dockerfile ARG VERSION regex in the bump script

1.14.0 — 2026-08-14

  • Docs — Align docs/v/* and ADR-012/021 amendments with launcher-only PyPI (no agent-toolkit-py); scrub leftover CONTRIBUTING / distribution present-tense quarantine wording
  • Refactor — Migrate V CLI dispatch to vlib/cli Command tree (Command.parse + execute callbacks; Consumer/Advanced groups). ADR-010 shim only for unknown flags → exit 2 (vlib uses 1); unit tests keep dispatch() walk (docs/v/cli-dispatcher.md, vlib-cli-spike.md)
  • Fixed — Re-setup() root Command after return-by-value before parse so Windows TCC parent pointers stay valid (agent-toolkit version Integration crash)
  • Chore — Rewrite make.vsh on vlib build (bobatea-style short tasks + upstream build_system example); remove Makefile; CI/docs use ./make.vsh <target> (shebang); install-cli --prefix=/path (hyphen flags skipped by context.run, parsed manually; PREFIX env fallback)
  • Tests — Expand npm trampoline suite (node --test) to mirror PyPI launcher coverage; add dedicated test-npm CI job (Node 22/24 × ubuntu/macOS/Windows)
  • CI — Bump primary Python to 3.14 (matrix still covers 3.10–3.14); Node jobs use 24 (markdownlint / Danger; npm tests also cover 22 LTS)

1.13.0 — 2026-08-14

  • Breaking — Remove quarantined Python CLI (agent-toolkit-py and src/agent_toolkit/{cli,compiler,installer,…}). PyPI is an npm-style trampoline over the V binary; CLI tests live in V (modules/**/*_test.v) and CI

1.12.2 — 2026-08-13

Audit cleanup and V-first ops: CI gates, Docker/Release coupling, scripts→.vsh, docs/packaging nits.

  • Fixed — pack_release_assets.vsh uses an absolute RELEASE_OUT_DIR so Windows zip packing after cd into a temp dir does not fail with I/O error
  • Fixed — Docker reusable workflow publishes via inputs.publish (caller event_name stays push, so event_name == workflow_call never matched)
  • Fixed — Docker metadata always applies raw VERSION tags (semver patterns alone miss :x.y.z on workflow_dispatch/branch callers)
  • Docs — Replace remaining ai-workspace brand with agentic-harness in skills/packs (Fixes #681)
  • Tests — Parity harness V_SEMANTIC disposition fixtures for insights/release; widen docs/v paths (Fixes #691)
  • Docs — Teach agent-toolkit loop instead of obsolete bin/loop in skills/packs/loop.yaml (Fixes #680)
  • Tests — Stop treating insights as a normal ADVANCED_COMMANDS harness entry (DEPRECATE #526)
  • CI — Fix validate.yml yamllint empty-lines after check-build insert
  • CI — ADR-003 dual-run: add check-build (build --check) alongside gen-surfaces (Fixes #678)
  • Products — Include agentic-security-reviewer in agent-toolkit-agents (Fixes #689)
  • CI — Drop stale packaging path from MegaLinter FILTER_REGEX_EXCLUDE
  • Chore — Migrate repo tooling scripts from Python to V (.vsh); add make.vsh with thin Makefile forwarder; keep provenance.py / validate-upstream.py and PyPI launcher Python; host skills use CLI / Grep (repo-root scripts/ is checkout/CI only)
  • Docs — Clarify experimental-v.yml header (ADR-018; drop PyInstaller channel wording)
  • Packaging — PyPI classifier Development Status Beta → Production/Stable
  • Docs — ADR-007 / install messaging aligned V-first (thin wrappers to agent-toolkit) (Fixes #682)
  • Docs — AUR playbook and release replay use agent-toolkit-bin; warn off legacy agent-toolkit AUR (Fixes #675)
  • Docs — Polish published npm/PyPI package READMEs to the cozy banner/badge style of packages/pypi/agent-toolkit-cli/README.md; document why the PyPI src/ launcher tree stays
  • CI — Build/push the Docker image from release.yml after V assets exist (GITHUB_TOKEN cannot trigger on: release)
  • Docs — PyPI republish guidance uses release.yml OIDC (not Publish manual)
  • Docs — Fix broken docs/SWARMS.md link to missing CLI_REFERENCE.md → CLI_SURFACES.md
  • Packaging — Bump Dockerfile default ARG VERSION to match VERSION
  • Docs — Note that wiki-style [[Page]] links in docs/wiki are intentional for wiki-sync
  • Docs — Mark insights DEPRECATE (#526) and release REMOVE (#527) in SCOPE.md / CLI_SURFACES.md
  • CI — Docker push-to-main is smoke-only; registry push requires Release assets (Fixes #679)
  • Chore — scripts/install.sh and doctor.sh are thin wrappers around the V CLI (Fixes #683)
  • CI — Include check-surfaces in required-ci needs so surface drift cannot merge (Fixes #677)
  • Docs — Homebrew README links in-repo ADR-023 path (keep #490 as discussion)
  • Fixed — distributions/products.yaml version_source points at packages/pypi layout

1.12.1 — 2026-08-13

  • Fixed — V CLI help matches or exceeds Python: real command blurbs, inventory/matrix usage, doctor --provenance, examples, and honest #526/#527 insights/release dispositions

1.12.0 — 2026-08-13

Inventory-honest docs and V-first install/upgrade paths. Ships Unreleased work since v1.11.0 (completions, Docker TARGETARCH, PyPI launcher/doctor root, Python CLI quarantine as agent-toolkit-py).

  • Docs — Align inventory counts (77 skills / 17 agents / 7 MCP / 7 packs), V-first install/update/uninstall, and collapse stale wiki mirrors that still described Python/install.sh as the product
  • Docs — Quarantine Python CLI as named agent-toolkit-py fallback (ADR-021 launcher stays; #540/#470). Product path remains V.
  • Docs — Contributor how-tos are V-first: docs/HOW_TO_DEVELOP_V.md (V 0.5.2, import json, Makefile), install matrix GitHub/brew/AUR/PyPI/npm, GitHub Release adapter no longer claims PyInstaller, uv run agent-toolkit removed from HOW_TO/certification docs
  • Docs — Install/release docs match V-first channels: GitHub Release, PyPI launcher, Homebrew, AUR agent-toolkit-bin, npm agent-toolkit-cli + platform packages, Docker debian:trixie-slim
  • Feat — V CLI completion emits bash/zsh/fish/PowerShell scripts (Closes #544)
  • Fixed — Docker multi-arch image honors BuildKit TARGETARCH (no amd64 default) so linux/arm64 installs agent-toolkit-linux-arm64; skip exec during QEMU cross-build and smoke version on a native load
  • Fixed — Install types-PyYAML in the PyPI adapter dev extra so incremental mypy can type yaml imports
  • Fixed — PyPI launcher exports wheel data/ as AGENT_TOOLKIT_ROOT; V doctor uses find_toolkit_root (wheel bin/../data) and embedded_version instead of a hardcoded 1.10.0; uvx CI checks out the repo so published wheels can resolve skills/loops
  • CI — Republish PyPI via workflow_dispatch on release.yml (Trusted Publishing is registered for that workflow, not publish.yml)
  • Packaging — Move PyPI adapter to packages/pypi/ (npm-parallel layout; platform-tagged wheels, not fake optionalDeps packages), drop the root uv workspace, tag Linux wheels manylinux_2_38_* after PyPI rejected linux_x86_64 on 1.11.0, and ship a V-first Docker image from GitHub Release binaries
  • Docs — Agentic Workstation adapter: CLI-only bootstrap, channel preference, no import agent_toolkit (#469)
  • Docs — V vs Python CLI performance baseline (startup/help/inventory/doctor) (Closes #533)
  • Docs — Audit: no first-party Python import agent_toolkit consumers outside this repo (Closes #561)
  • Docs — V development & distribution documentation index (Closes #545)

1.11.0 — 2026-08-13

First GitHub Release that attaches native V binaries (ADR-018 names, SHA256SUMS, manifest.json). v1.10.0 has empty assets — do not retag it.

  • Docs — Docker adapter: debian-slim + GitHub Release V binary; git/gh MUST (Closes #537)
  • Docs — macOS Gatekeeper / Windows SmartScreen / code signing policy (Closes #543)
  • Docs — V migration risk register with ADR status (Closes #478)
  • Docs — Python architecture map & subsystem classification for V waves (Closes #477)
  • Docs — CLI surfaces inventory maps every command to owner issue and disposition (Closes #475)
  • Feat — npm agent-toolkit-cli launcher over GitHub Release V binaries with OIDC trusted publish (Closes #536)
  • Docs — ADR-025 npm package is agent-toolkit-cli with optionalDependencies platform binaries (Closes #487)
  • Docs — AUR adapter contract: agent-toolkit-bin consumes GitHub Release V binaries (Closes #539)
  • Docs — Homebrew adapter contract: Formula consumes GitHub Release V binaries (Closes #538)
  • Docs — ADR-024 AUR agent-toolkit-bin installs GitHub Release V binaries (Closes #491)
  • Feat — GitHub Releases attach native V binaries, SHA256SUMS, and manifest.json (Closes #530)
  • Docs — ADR-023 Homebrew Formula installs GitHub Release V binaries (Closes #490)
  • Docs — Distribution wrapper threat model (wheel-bundle vs runtime download) (Closes #563)
  • Docs — ADR-022 machine-readable GitHub Release manifest.json (Closes #488)
  • Feat — PyPI agent-toolkit is a thin launcher over the bundled V binary (Closes #535)
  • Docs — ADR-021 PyPI ships platform wheels with bundled V binary + thin launcher (Closes #486)
  • Docs — Add distribution/ adapter contracts (GitHub Release canonical; no Formula/PKGBUILD copies) (Closes #534)
  • Docs — CI cost tiers (PR/main/release) with path filters, timeouts, Python-lane retirement trigger (Closes #532)
  • Feat — V swarm REDESIGN (recipes/start/status/doctor/approve/reject/cancel; filesystem SoT) (Closes #524)
  • Feat — V loop REDESIGN (init/run/status/audit/cost/schedule/sync; process-per-run skeleton) (Closes #523)
  • Feat — Execute MUST-platform V artifacts (--version/--help/inventory/doctor) with arch mismatch fail (Closes #531)
  • Feat — Native V MUST build matrix (linux x86_64/arm64, macos arm64/x86_64, windows x86_64; experimental names) (Closes #529)
  • Feat — Experimental native V CI artifacts (linux-x86_64, macos-arm64, windows-x86_64; experimental names only) (Closes #562)
  • Docs — ADR-020 V concurrency: process-per-run supervisor (no Python threads / no go workers) (Closes #528)
  • Feat — V devcompanion/dc filesystem queue (queue/run-once –no-llm/status/done/sync-todos) (Closes #525)
  • Docs — ADR-019 Linux glibc is the MUST/stable binary; musl is an optional extra name (Closes #485)
  • Feat — V project init/clone/list/add/remove/scan (repos/ + projects/ symlinks) (Closes #522)
  • Feat — V memory add/search/inject/review/todo (knowledge markdown; atomic writes) (Closes #521)
  • Docs — ADR-018 canonical release artifact names (floating stable + versioned archives; experimental prefix) (Closes #484)
  • Feat — V workspace command family (init/context/sync + personas/packs) (Closes #520)
  • Fixed — V install JSON merge (ownership=merged) writes without --force (Closes #611)
  • Feat — V binary is the in-repo canonical agent-toolkit (consumer CLI; Python package fallback for unfinished advanced commands) (Closes #555)
  • Docs — EPIC 5 advanced-command disposition (PORT/REDESIGN/DEPRECATE/REMOVE) (Closes #560)
  • Docs — ADR-017 package-manager ownership: update is capability-only; never overwrite brew/AUR/npm/uv binaries (Closes #489)
  • Feat — V agent-toolkit install via InstallTransaction (dry-run/force/receipts) (Closes #607)
  • Feat — V plugin sync|check gen-surfaces parity (Closes #519)
  • Feat — V mcp list/setup/health/doctor/uninstall (env names only; no secrets) (Closes #518)
  • Feat — V skills list/sync/validate command family (Closes #517)
  • Feat — V doctor --fix allowlisted profile refresh (Closes #550)
  • Feat — V capability update (profile refresh; –check/–pin; not self-update) (Closes #516)
  • Feat — V agent-toolkit diff (compile vs plugins/ added/changed) (Closes #515)
  • Feat — install receipt compatibility schema (schemas/install-receipt.schema.json) (Closes #511)
  • Feat — V uninstall/rollback from install receipts (created-only; dry-run) (Closes #514)
  • Feat — V atomic install transaction (stage/commit/rollback + receipt save) (Closes #513)
  • Feat — V read-only install receipt parser (SCHEMA + path-escape/secrets refuse) (Closes #512)
  • Feat — V remaining target emitters (copilot, windsurf, pi, gemini, muse, codex, agent-plugins) (Closes #552)
  • Feat — V build --check Tier-1 dry-run + plugins/ skill/agent drift detection (Closes #510)
  • Feat — V Tier-1 target emitters (cursor, claude-code, opencode) with provenance (Closes #509)
  • Feat — V provenance emission compatible with Python .provenance.json schema (Closes #508)
  • Feat — V capability loader + product selection from distributions/products.yaml (Closes #507)
  • Docs — ADR-016 versioning during Python→V migration: major at cutover, not experimental binary (Closes #495)
  • Feat — V content sync/download client (GitHub release data; offline never networks; staging validation) (Closes #557)
  • Feat — V content cache service (XDG hit/miss/offline; no network) (Closes #556)
  • Feat — V doctor read-only + --json with engine/version/platform (Closes #505)
  • Feat — V inventory lists skills/agents/products from the toolkit tree (Closes #503)
  • Feat — V matrix prints the platform capability matrix (Closes #504)
  • Feat — V version / --version resolves from VERSION file (fallback synced via bump-version) (Closes #502)
  • Feat — V toolkit root resolution per ADR-015 (env override → XDG → embedded → checkout → CWD; offline never downloads) (Closes #506)
  • Test — Python↔V golden CLI parity harness + CI seed job (Closes #548)
  • Feat — experimental V CLI dispatcher + make build-cli (build/agent-toolkit-v) (Closes #553)
  • Feat — V structured CommandResult + CLI human/JSON/quiet renderers (Closes #501)
  • Feat — V shared HTTP/network client (offline short-circuit, TLS, checksum hook) (Closes #558)
  • Feat — V process service (no-shell spawn, cwd/env/timeout/capture) (Closes #500)
  • Feat — V filesystem service (XDG paths, join, atomic write) (Closes #499)
  • Feat — V domain error model + CLI exit-code mapping (ADR-010 classes) (Closes #498)
  • Docs — vlib/cli spike matrix vs CLI contract; GO with thin exit/completion wrapper (Closes #554)
  • Chore — Makefile fmt/fmt-check/vet/test/build for V modules (Closes #497)
  • Chore — pin V compiler via .v-version (0.5.2) + upgrade policy (Closes #496)
  • Docs — configuration/env precedence contract (flags > env > config > defaults) + AGENT_TOOLKIT_* inventory (Closes #559)
  • Docs — machine-readable CLI contract manifest (docs/compatibility/cli-contract.yaml) (Closes #549)
  • Docs — Python↔V golden CLI parity harness design (taxonomy EXACT/NORMALIZED/SCHEMA/SEMANTIC/BEHAVIORAL; no harness code) (Closes #476)
  • Docs — ADR-015 runtime resolution (amends ADR-005 for V binary hybrid packaging) (Closes #547)
  • Docs — ADR-014 schema validation: typed validators in core + Python bridge only during parity (Closes #546)
  • Docs — ADR-013 YAML strategy: use vlib/yaml for toolkit config; no custom general YAML parser (Closes #483)
  • Docs — ADR-012 Python/V coexistence via experimental V binary; Python remains canonical until cutover (Closes #482)
  • Fixed — agent-toolkit update honors AGENT_TOOLKIT_OFFLINE and maps download OSError to skippable errors (CI flake)
  • Docs — ADR-011 hybrid capability packaging (embedded baseline + external override); resolution order remains ADR-005/#547 (Closes #481)
  • Docs — ADR-010 CLI/core boundary: structured domain results; CLI renders human/JSON; exit-code classes (Closes #480)
  • Docs — ADR-009 V module architecture: agent_toolkit_core + agent_toolkit_cli (no premature server/TUI stubs) (Closes #479)

[1.10.0] — 2026-08-12

Added

  • Providers — capability provider abstraction WHAT vs HOW (Closes #386), audit 8 candidates + 5 ADOPT via hierarchy (Refs #393), curated agentic-security/code-quality/architecture/design-engineering packs (Closes #390)
  • Design — Vercel web-design-guidelines + Microsoft frontend-design-review dual-source pinning (Closes #372, #391), design-assessment orchestration (Closes #373), browser-grounded design-improvement iteration (Closes #374), Chrome DevTools MCP provider (Closes #375)
  • A11y & Figma — WCAG 2.2 AA accessibility review (Closes #377), Figma ecosystem audit (Closes #376)
  • Security — MCP config + implementation audit (Closes #379), OWASP agentic review (Closes #380), STRIDE threat-modeling + agentic threats (Closes #381)
  • Quality — MegaLinter coding-agent orchestration v10 (Closes #382), CodeQL operational workflow (Closes #383), cloud Well-Architected + Mermaid/C4 diagrams (Closes #384, #385)
  • Governance — upstream provenance schema/trust tiers + validate-upstream (Closes #364), external provenance lock + integrity validation (Closes #370), supply-chain audit skill (Closes #378), update discovery for provenance lock (Closes #428), ADRs 0004/0005
  • CLI — doctor provenance/pack/MCP + matrix + context-cost + audit surface (Closes #387, #388, Refs #395, Closes #397), skill-catalog 73→77 + pack validation (Closes #390, #451, #450)

Fixed

  • CI green — MegaLinter PYTHON_RUFF + v10.0.0 alignment + providers.yaml empty-line fix (Closes #453, #454), Required CI aggregate gate, branch protection Required CI (app_id 15368) enforcement
  • Swarm — tear down tmux server on cleanup to stop orphan-socket leak
  • Workspace/Packs — validate nested packs, warn on unknown profile keys, regenerate catalogs

Changed

  • Docs — addyosmani documentation-and-adrs vs adr/docs-generator diff (Closes #394), third-party UI UX Pro Max as optional external (REJECT vendoring) per #392

[1.9.0] — 2026-08-10

Added

  • Agent Plugins 1.0 portable plugin standard — every plugin in plugins/ now ships as plugin.json ($schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json) + skills/ + mcp.json for Cursor, VS Code, GitHub Copilot, ChatGPT/Codex, Kiro. Dual emit keeps .claude-plugin/plugin.json for Claude Code (which does not yet support the spec). See docs/AGENT_PLUGINS.md, plugins/README.md, and schemas/agent-plugins/1.0.0/. Compiler target agent-plugins, validator scripts/validate-agent-plugins.vsh, and CI job validate-agent-plugins added; scripts/bump-version.vsh now preserves $schema/extensions.

Changed

  • Docs — docs/COMPATIBILITY.md clarifies Claude legacy-only and adds VS Code/Kiro + dedicated Agent Plugins 1.0 subsection; docs/TARGETS.md adds Agent Plugins 1.0 row to capability matrix.

[1.8.4] — 2026-08-07

Fixed

  • Swarm interactive bootstrap — when swarm start is run without a prompt (--recipe full --ui herdr --runner claude --attach), the first agent now does only a very brief context analysis (runs agent-toolkit workspace context if inside a workspace like ~/.ai-workspace, otherwise brief README/git status check) and stays on standby awaiting the user’s first request. Applies assistant discovery + workflow-generic-project (plan -> approval -> implement -> draft PR) once the task arrives. Prevents the planner from inventing work.

[1.8.3] — 2026-08-06

Fixed

  • CI ruff format — run uv run ruff format on tests/test_swarm_cli.py after pytest.skip line wrap (fixes Validate Ruff format check failure on 1.8.2).

[1.8.2] — 2026-08-06

Fixed

  • CI macos tmux — make test_swarm_auto_fallback_to_tmux skip when neither herdr nor tmux is available on runner (fixes 1 failure on macos-latest).

[1.8.1] — 2026-08-06

Fixed

  • CI portability — fix tests/test_swarm_cli.py hardcoded /home/ulisesjcf/... project path to Path(__file__).resolve().parents[1] so uv run --project works on any runner (fixes Validate test_swarm_cli 9 failures on Python 3.13).

[1.8.0] — 2026-08-06

Added

  • Swarm skills (Herdr-first) — 4 new swarm-focused skills: swarm (launcher via agent-toolkit swarm start --recipe pair/team/full --ui herdr/tmux --runner opencode/claude --model-profile balanced/economy --attach "task" with eager windows Waiting for handoff: <pred> -> <role> and _user_shell() zsh detection), swarm-observer (monitor status/handoffs/logs/attach and recover worktree_failed/headless fallback), swarm-handoff (artifact/commit file handoffs with worktree-per-writer and promotion), herdr (Herdr workspace/tab/pane management) and worktree (Git worktree isolation). All validated via muse skills validate and agent-toolkit skills validate (61 total) and integrated with code-reviewer/security-reviewer/github-cli-workflow/output-handshake.
  • Workspace orchestration skills — workspace (stateless ~/.ai-workspace workspace context + memory inject/todo + packs), project (project clone/list multi-repo), mcp (mcp setup/list/doctor), and inventory (inventory/matrix/skills list discovery). Completes end-to-end DX: workspace → project → swarm → handoff → promote → github-cli-workflow.
  • Skill catalog growth — total 52 → 61 skills across 9 domains; agent-toolkit-complete now includes all 9 new skills; badges, catalogs/skill-catalog.yaml, catalogs/skills-layout.json, and docs/SKILL_PRODUCT_MATRIX.md regenerated; README.md, packages/pypi/agent-toolkit-cli/README.md, docs/GETTING_STARTED.md, docs/TROUBLESHOOTING.md, docs/wiki/Home.md updated.

Fixed

  • Docs 100% current — regenerated catalogs (scripts/generate-catalogs.vsh, prepare-package-data.sh, generate-skill-matrix.py), fixed stale skills-52 badges and 50 skills assertions, and ensured agent-toolkit install deploys 61 skills to ~/.config/muse/skills and ~/.agents/skills.

[1.7.2] — 2026-08-06

Fixed

  • Swarm workspace UX polish — fix swarm list duplicate entries when aggregating from ~/.ai-workspace, make swarm status/stop/cleanup/attach/report/artifacts/handoffs/logs workspace-aware via find_run_dir_by_id (works from ~/.ai-workspace without --workspace and with --workspace OWNER/REPO/-C), and ensure prompt autodetect works for all Create-Node-App aliases. Ensures agent-toolkit swarm start "Fix https://github.com/Create-Node-App/..." from workspace root creates worktree in correct repo with isolated tmux -L agent-toolkit-swarm-<id> N-windows like swarm-forge ./swarm.

[1.7.1] — 2026-08-06

Added

  • Swarm prompt autodetect + workspace UX — agent-toolkit swarm start/plan now autodetects repo from prompt (https://github.com/OWNER/REPO, OWNER/REPO#123, aliases create-node-app/cna-templates → Create-Node-App/...) and resolves to ~/.ai-workspace/repos/github.com/OWNER/REPO, so agent-toolkit swarm start "Fix https://github.com/Create-Node-App/create-node-app/issues/240" works from ~/.ai-workspace without --workspace/--issue flags (like swarm-forge ./swarm but better: backend-neutral Herdr/tmux, isolated worktrees, handoffs). Adds --workspace/--repo/-C to plan/start and workspace-aware list/status (list_all_runs/find_run_dir_by_id aggregating across clones). Inspired by swarm-forge patterns (window-per-role tmux, worktrees, handoffs) clean-room.

[1.7.0] — 2026-08-06

Added

  • Swarm orchestration — new agent-toolkit swarm CLI (ADR-008) with backend-neutral orchestration (Herdr recommended, tmux fallback), recipes pair/team/full (lazy/elastic, pair→team→full promotion), Git worktree isolation per writer, durable filesystem handoffs (artifact/commit/feedback/decision_request), commit-based code transfer, human approval gates, budgets (tokens/cost/wall-clock/concurrency/round-trips), model profiles (economy/balanced/quality/private), runner abstraction (OpenCode primary, Muse/Claude/Codex/Cursor/Copilot), OpenCode per-role agent generation, Herdr backend (JSON CLI) + tmux backend (isolated socket agent-toolkit-swarm-<run-id>), Herdr plugin (integrations/herdr/agent-toolkit-swarm), and docs (docs/SWARMS.md, SWARM_ARCHITECTURE.md, SWARM_RECIPES.md, SWARM_HANDOFFS.md, SWARM_MODELS_AND_COSTS.md, SWARM_HERDR.md, SWARM_TMUX.md, SWARM_SECURITY.md, HOW_TO_CREATE_SWARM_RECIPE.md) with Mermaid diagrams and offline --runner skeleton demo. Complete cross-repo integration: Workstation provision (tmux/Herdr) and Harness reference workspace.

[1.6.0] — 2026-08-06

Added

  • Loop list command — agent-toolkit loop list (alias ls) lists detected loops in the same places loop run <name> searches (workspace/loops/ → bundled data/loops/), showing source, tier, cadence.

[1.5.1] — 2026-08-06

Fixed

  • Release 1.5.0 plugin bundles: sync plugins/*/.claude-plugin|*.cursor-plugin|*.codex-plugin|gemini-extension|pi-package|.provenance versions to 1.5.1 — fixes test_diff_no_changes_returns_0 (Validate diff).

[1.5.0] — 2026-08-06

Added

  • Muse Code support (Meta, https://developer.meta.com/ai/products/muse-code/) — new muse-code build target (muse alias) via MuseCodeAdapter (packages/pypi/agent-toolkit-cli/src/agent_toolkit/compiler/targets/muse_code.py) registered in capabilities/targets/registry.yaml (stable). agent-toolkit build --target muse-code and install --tools muse-code now deploy 50 skills to ~/.config/muse/skills/<name>/SKILL.md plus .agents/skills (universal fallback) per Agent Skills spec (muse skills import --from claude). New profile profiles/muse-code/README.md and docs README.md.

[1.0.1] — 2026-08-04

Fixed

  • Publish agent-toolkit-cli to PyPI (release.yml was missing build + publish steps in v1.0.0)
  • SVG animations: replace CSS @keyframes with native SVG (GitHub strips CSS)
  • Banner SVG: fix text overlap between title and right panel (shift from x=575 to x=530)
  • CLI wheel install: shared _paths.py resolves toolkit root correctly in all install modes
  • CI: remove pytest || true so test failures block the pipeline

[1.0.2] — 2026-08-04

Fixed

  • release.yml now correctly builds wheel and publishes to PyPI

[1.0.3] — 2026-08-04

Fixed

  • release.yml YAML syntax fixed for GitHub Actions validator

[1.0.4] — 2026-08-04

Fixed

  • Wheel install: data files (profiles/, loops/, skills/, etc.) now packed inside the wheel at agent_toolkit/data/ — works correctly with pip, uvx, and brew
  • _paths.py: resolve data from importlib.resources and direct package path before falling back to walking up the filesystem (which breaks in uvx cache)
  • Added agent-toolkit-cli as script alias so uvx agent-toolkit-cli works

[1.0.5] — 2026-08-04

Fixed

  • loop runner: resolve toolkit root from package data dir before CWD fallback, preventing it from picking up the user’s ai-workspace loops when run via uvx/pip

[1.0.6] — 2026-08-04

Fixed

  • CRITICAL: Local toolkit_root() in cli/install.py, doctor.py, mcp.py, skills.py, plugin.py was defined after the import from _paths.py, shadowing it — so the correct resolution logic was never called in wheel/uvx installs
  • Removed module-level TOOLKIT_DIR: Path = toolkit_root() (evaluated at import time, crashed before any function ran) — replaced with lazy toolkit_root() per call site

[1.0.7] — 2026-08-04

Fixed

  • skills list: now correctly parses YAML block scalars (>-, |-) in SKILL.md descriptions — all 52 skill descriptions now display properly instead of showing “>-”
  • install command: Copilot prompt no longer blocks in non-interactive/dry-run mode (stdin.isatty() check; skips automatically in CI, pipes, –dry-run)
  • pyproject.toml: added agent-toolkit-cli script alias so uvx agent-toolkit-cli works

[1.0.8] — 2026-08-04

Fixed

  • Copilot never auto-installed during install auto-detect — always requires --tools copilot (it needs a project path)
  • CI integration tests: use relative file paths instead of /tmp (cross-platform)
  • CI integration tests: fix Windows runner compatibility

[1.0.9] — 2026-08-04

Fixed

  • Windows compatibility: os.getuid() doesn’t exist on Windows — wrapped in try/except so agent-toolkit doctor no longer crashes on Windows runners

[1.0.10] — 2026-08-04

Fixed

  • loop run now works from pip/uvx installs — loop-gh-gate (the gh CLI security shim) is now included in the wheel at agent_toolkit/loop/loop-gh-gate
  • Windows compatibility: os.getuid() wrapped in try/except AttributeError

Added

  • uv workspace structure: packages/pypi/agent-toolkit-cli/ — ready for future packages (agent-toolkit-server, agent-toolkit-mcp, etc.)
  • Root pyproject.toml with [tool.uv.workspace] and shared dev tooling

1.1.0 — 2026-08-04

Added — Full workspace capability

agent-toolkit is now a complete workspace toolkit. Every capability from ~/.ai-workspace and agentic-harness is available as a CLI subcommand:

agent-toolkit workspace — Workspace scaffolding and session context

  • workspace init [--dir PATH] — scaffold harness workspace (AGENTS.md, knowledge/, packs/, personas/, loops/, projects/, repos/)
  • workspace context — session state snapshot for AI session start
  • workspace sync — sync loop escalations into knowledge todos

agent-toolkit memory — Persistent knowledge base (replaces bin/assistant-memory)

  • memory add --type <learning|process|todo> "content" — add to knowledge base
  • memory search "query" — search all knowledge files
  • memory inject — output full knowledge context block for AI session
  • memory review — show stale entries
  • memory todo — list pending todos

agent-toolkit project — Project clone and symlink manager (replaces bin/project-indexer)

  • project clone owner/repo — clone + symlink into projects/
  • project list — list indexed projects
  • project add <path> — symlink existing repo
  • project remove <name> — remove symlink
  • project scan — consistency check

agent-toolkit devcompanion — Background job queue (replaces bin/devcompanion)

  • devcompanion queue <project> [--request "..."] [--template NAME] — queue a job
  • devcompanion run-once [--no-llm] — execute oldest pending job
  • devcompanion status — show all jobs
  • devcompanion done <job-id> — mark job complete
  • devcompanion sync-todos — sync plan.md todos to knowledge

agent-toolkit insights — AI tool usage analytics (replaces bin/tool-insights)

  • insights opencode — OpenCode sessions from SQLite DB
  • insights cursor — Cursor agent transcripts
  • insights claude — Claude Code sessions
  • insights all — aggregate across all tools

Templates — workspace scaffold templates bundled in the wheel

  • 12 CLI modules, 42 template files (AGENTS.md, personas, knowledge, etc.)
  • agent-toolkit workspace init = what agentic-harness now scaffolds from

Profile updates — Claude Code, Cursor, OpenCode, Windsurf profiles updated with agent-toolkit CLI reference and session-start protocol

Changed

  • agentic-harness: bin/workspace-context and bin/assistant-memory are now thin wrappers that delegate to agent-toolkit CLI

1.2.0 — 2026-08-05

Added — Native multi-runtime compiler platform (Phases 3-7)

The canonical compiler pipeline now generates native artifacts for 9 AI coding targets:

Compiler targets:

  • Claude Code (plugin — .claude-plugin/) — stable GA
  • Cursor IDE/CLI (plugin — .cursor-plugin/) — stable GA
  • GitHub Copilot CLI (plugin — plugin.json) — stable GA
  • GitHub Copilot Repository (.github/ assets) — stable GA
  • Gemini CLI (extension — gemini-extension.json + commands.toml) — stable GA
  • OpenCode (companion-assets — .opencode/) — stable
  • Pi Coding Agent (companion-assets — pi-package.json) — stable
  • Windsurf/Devin (customization-bundle — rules + AGENTS.md) — accurately labeled (no marketplace)
  • OpenAI Codex (plugin — .codex-plugin/) — experimental

Canonical compiler pipeline:

  • distributions/products.yaml — declarative product catalog
  • src/agent_toolkit/compiler/ — model, loader, targets/
  • agent-toolkit build — compile to any target
  • agent-toolkit diff — show changes vs installed
  • agent-toolkit inventory — list all capabilities
  • agent-toolkit matrix — platform capability matrix
  • agent-toolkit release --dry-run — generate dist/ artifacts + checksums

MCP and hooks:

  • mcp/registry/ — canonical registry for 6 providers (github, slack, notion, linear, figma, clickup)
  • capabilities/hooks/ — canonical hook definitions with platform parity matrix
  • schemas/hook.schema.yaml — JSON Schema for hook definitions

Testing (227 tests):

  • Contract tests for all 9 compiler adapters
  • Golden/snapshot tests for deterministic output
  • Security tests: path traversal, secret redaction
  • Installer receipt tests
  • MCP registry tests
  • Hook registry tests
  • Provenance/diff tests

Docs:

  • docs/TARGETS.md — honest capability matrix for all 9 targets
  • docs/research/ — platform capability matrix, source ledger, audit
  • docs/adrs/ — ADR-001 (canonical IR), ADR-002 (Windsurf bundle)
  • docs/security/ — threat model

Security

  • Removed skipDangerousModePermissionPrompt from Claude Code profile
  • Replaced private LAN URLs in OpenCode profile with portable defaults
  • Updated schema $id to remove stale agentic-workstation references

Added — Loop runners, memory review, and consumer polish

  • Loop runners: Cursor Agent CLI, GitHub Copilot CLI (copilot -p), OpenAI Codex (codex exec)
  • loop run --runner / AGENT_TOOLKIT_LOOP_RUNNER for explicit runner selection
  • memory review — duplicates, contradictions, stale/orphan detection with --fix
  • Installer receipts, safe JSON merge, update/uninstall, profile sanitization
  • README Key Concepts table; Windsurf rule parity with Cursor
  • Blocking YAML lint in validate CI; docs/TARGETS and trust boundary guides

1.2.2 — 2026-08-05

Changed

  • Publish an elevated packages/pypi/agent-toolkit-cli/README.md to PyPI (parity with the monorepo root README: install, CLI surfaces, tool matrix, ecosystem)

1.2.1 — 2026-08-05

Fixed

  • loop status falls back to bundled templates when no workspace instances exist (uvx/pip installs)
  • Release CI: uv sync --package agent-toolkit-cli --extra all and current SBOM action pins