diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index 74cacb02b..3b1829755 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -6,13 +6,13 @@ }, "metadata": { "description": "Engineering guidance for coding agents: behavior-driven planning, shared domain language, independent validation, and reusable improvements.", - "version": "3.8.0" + "version": "3.9.0" }, "plugins": [ { "name": "agentops", "description": "Engineering guidance for coding agents: behavior-driven planning, shared domain language, independent validation, and reusable improvements.", - "version": "3.8.0", + "version": "3.9.0", "source": "./", "author": { "name": "Boden Fuller", diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index ff6e8e0cc..305326a44 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "agentops", - "version": "3.8.0", + "version": "3.9.0", "description": "Engineering guidance for coding agents: behavior-driven planning, shared domain language, independent validation, and reusable improvements.", "author": { "name": "Boden Fuller", diff --git a/.codex-plugin/plugin.json b/.codex-plugin/plugin.json index e4c4d745d..fd3bf1d79 100644 --- a/.codex-plugin/plugin.json +++ b/.codex-plugin/plugin.json @@ -1,6 +1,6 @@ { "name": "agentops", - "version": "3.8.0", + "version": "3.9.0", "description": "Engineering guidance for coding agents: behavior-driven planning, shared domain language, independent validation, and reusable improvements.", "skills": "./skills", "interface": { diff --git a/CHANGELOG.md b/CHANGELOG.md index dc7ce686e..8fe66a23d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,44 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [3.9.0] - 2026-10-03 + +AgentOps 3.9 narrows the product to its own guidance. The ten bundled external +tool skills are removed, three repository delivery workflows are retired, the +Codex plugin reads `skills/` directly instead of a generated copy, and +installation has three supported paths: the Claude Code plugin, the Codex +plugin, and `npx skills` for every other agent. Validation is now spent where a +mistake is costly instead of on every change. Interview and Navigate are new, +and Council gains duel and interview-panel modes. The optional menu goes from +36 to 28 skills; native work still requires none of them. + +See the [curated release notes](https://github.com/boshu2/agentops/blob/main/docs/releases/2026-10-03-v3.9.0-notes.md) +for upgrade instructions, breaking changes and known limits. + +### Added + +- Interview shapes a large outcome with the caller one question at a time before + agents work alone. Each question carries a recommendation and its main + tradeoff; acceptance is recorded as Given/When/Then examples. It creates no + goal or bead. +- Navigate picks the next wave on a bead graph and records results and + discoveries on the beads. It never dispatches, judges or closes work. The bead + graph contract and wave loop move here from Craft Goal. +- Council gains two modes. In a duel, members rank their own ideas, score every + other member's ideas on a rubric fixed before launch, then concede or defend + in one bounded round. In an interview panel, each member answers Interview's + questions in a separate context; agreed answers are marked and the caller + accepts or amends the result. The caller may give each member its own model, + effort and perspective. +- `ao skills build` creates an explicitly incomplete skill scaffold and its + generated projections; its three modes write the same scaffold and import no + content. `ao skills audit` reports static conformance, effect observations + and unmeasured behavior separately. `ao skills check-source` checks named + source packages. +- A gate checks that each retired workflow file contains only its metadata and + an immediate failure. A test requires the checked-in version to have exactly + one curated release-notes file. + ### Changed - Fresh validation is no longer owed on every change. For an ordinary change @@ -29,11 +67,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 unchanged. Codex plugin users should refresh the marketplace and re-add the plugin. Checked against codex-cli 0.156.1: a plugin install and a linked install each load all 28 skills with no load errors. -- `interview` now carries its Codex invocation policy in - `skills/interview/agents/openai.yaml`. The generator used to derive that file - from `disable-model-invocation: true`; it is now hand-maintained in each - explicit-only skill, and `scripts/validate-codex-api-conformance.sh` fails when - one is missing or does not parse. +- Each explicit-only skill carries its Codex invocation policy in its own + `agents/openai.yaml`, hand-maintained in `skills/`; the generator no longer + derives it. `scripts/validate-codex-api-conformance.sh` fails when one is + missing or does not parse. - `scripts/validate-codex-api-conformance.sh` checks `skills/` against what the Codex loader enforces (unique frontmatter keys, a non-empty description, a name of at most 64 characters, no nested `SKILL.md`) and the explicit-only @@ -44,7 +81,32 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - The `skill-eval` fixtures moved from `skills/_fixtures/` to `tests/fixtures/skill-eval/`. Codex loads every `SKILL.md` under the plugin's skill tree, so the fixtures would have shipped as a skill and a load error. - +- Craft Goal's frozen goal prompt states acceptance as Given/When/Then examples + and names domain terms once. +- Skill Builder's build, check, heal and audit scripts run through `ao skills`: + outside a source checkout they need `ao` 3.9 or later; inside one they build + `ao` with Go. Its audit reports conformance, effect observations, behavioral + evidence and review suspicions separately; + `skills/skill-builder/scripts/audit.sh --legacy` keeps the earlier format. + Build no longer writes a default report under `.agents/scratch/skill-builder/`, + and invalid creation inputs exit 1 instead of 2. +- AgentOps' own guards (policy dispatcher, read-budget, Codex read-budget and + installed-skill-edit guards) moved from `skills/cc-hooks/` to `hooks/guards/`. + Plugin users and already-installed guards need no action; update any direct + call to `skills/cc-hooks/scripts/install-hooks.sh` or `skills/cc-hooks/hooks/*` + to `scripts/install-policy-dispatch.sh` or `hooks/guards/`. A skill-only + install no longer carries a hook installer. +- `docs.cli-snippets` is a blocking gate that resolves `ao` commands cited in + code spans and fenced blocks of the live docs against the real command tree. + It is one of the fact checks that replaced documentation tests which froze + wording. +- The install drift check fails on a stale installed copy of any retired + workflow, in `~/.claude/workflows` and in a project's `.claude/workflows`. +- The release body's header links the update guide instead of a one-line + source-checkout update command. +- The README is rebuilt around the operational loop, with a goals section and a + grouped skill chart. It recommends upstream projects for some external tools + by link instead of bundling their skills. - Install narrowed to three paths: the Claude Code plugin, the Codex plugin, and `npx skills@latest add boshu2/agentops` for every other agent (Cursor, OpenCode, Gemini CLI/Antigravity, Pi, Grok Build, OpenClaw). Grok Bot takes @@ -87,38 +149,50 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 resolving. - The Skill Builder converter's Codex target no longer writes `prompt.md`; Codex does not read it. - - Bundled Flywheel tool skills (`account-rotation`, `agent-mail`, `cass`, `cc-hooks`, `dcg`, `ms`, `ntm`, `rch`, `sbh`, `using-flywheel`) and their generated Codex copies. - Obtain tools and skills from their upstream authors; see the README - recommendations. This changes the available skill names in the next release. - Existing personal installations are not automatically removed. -- AgentOps' own guards (policy dispatcher, read-budget, Codex read-budget and - installed-skill-edit guards) moved from `skills/cc-hooks/` to `hooks/guards/`. - Plugin users and already-installed guards need no action; update any direct - call to `skills/cc-hooks/scripts/install-hooks.sh` or `skills/cc-hooks/hooks/*` - to `scripts/install-policy-dispatch.sh` or `hooks/guards/`. - + AgentOps provides no replacement. The README recommends the upstream projects + for DCG, CASS, Meta Skill, the Agentic Coding Flywheel and Gas City; get those + tools and any skills for them from their authors. Copies installed earlier + with `npx skills` are not removed; a source link to a removed skill is left + dangling (see the release notes). +- The `skill-first-coord-guard.sh` hook and its reference page, and the generic + Claude Code hook reference pages that shipped inside `cc-hooks`. +- `scripts/install-ms-reindex-hook.sh` and `scripts/ms-reindex.sh`. +- The `ao doctor` check and repository gate that banned running Claude headless + in print mode (`claude -p`). Print mode is an ordinary dispatch option again. - The `bdd-foundry`, `ship-beads` and `bead-crank` Claude workflows. The names stay as tombstones that fail with a migration message before doing any work, like `operating-loop`. In place of `bdd-foundry`, state accepted behavior in the conversation or a bead. In place of `ship-beads` and `bead-crank`, deliver with native Git and BD under your repository's policy, or dispatch to a software factory through its coordinator. An installed copy of the old files now fails - the `workflow.install-drift` gate. `ao workflows link` does not replace it: for - `~/.claude/workflows` run `bash scripts/install-workflows.sh`, which backs up the - old file and links the tombstone; for a project's `.claude/workflows`, remove the - old file and then run `ao workflows link`. + the `workflow.install-drift` gate. `ao workflows link` does not replace a + copied file. For `~/.claude/workflows`, run `bash scripts/install-workflows.sh` + from the AgentOps checkout and name only the retired files you have (for + example `bdd-foundry.js`): each becomes a link to the current file, and a file + that differs is backed up first. Without file names the script installs every + workflow. For another project's `.claude/workflows`, remove the old file, then + run `ao workflows link --into /.claude/workflows` from the checkout. `scripts/check-bdd-foundry-markers.sh` is removed. - The 3.x curl and PowerShell skill installer tombstones (`scripts/install.sh`, `install-claude.sh`, `install-codex.sh`, `install-agy.sh`, `install-opencode.sh`, `install-codex.ps1`). Their raw URLs now 404, so an old - `curl … | bash` line silently does nothing; switch to a plugin or npx. + `curl … | bash` line installs nothing; switch to a plugin or npx. - The `images/gemini` package (`agentops-core-gemini`) and its generator branch. - Remove an installed copy with `agy plugin uninstall agentops-core-gemini`. + Remove an installed copy with `agy plugin disable agentops-core-gemini` and + then `agy plugin uninstall agentops-core-gemini`. ### Fixed +- The repository's skill evaluation suite under `evals/skills-rpi/` checks + task-bank controls through the exact packaged verifier and prepares both arms + with shared task and image identities before any trial starts, so packaging + and identity mismatches are rejected before model resources are spent. +- The documentation site banner no longer shows the retired 3.3 tagline, and + the site build no longer publishes its internal generator scripts. +- The CI job that syntax-checks workflow scripts parses them the way the harness + runs them, so a top-level `return` no longer fails it. - `ao skills link`, `unlink` and `ao doctor` use Pi's user skills dir, `~/.pi/agent/skills`, and detect Pi by `~/.pi/agent`. Links an earlier version made in `~/.pi/skills` are no longer swept by default; remove them with diff --git a/README.md b/README.md index 0b98b72fe..cb7e9e63a 100644 --- a/README.md +++ b/README.md @@ -330,12 +330,16 @@ With Go installed: `go install github.com/boshu2/agentops/cli/cmd/ao@latest`. ## Updating and advanced setup
-Upgrading to 3.8 +Upgrading to 3.9 + -Version 3.8 retains existing 3.7 command and skill names. Use the +Version 3.9 removes ten bundled external tool skills, retires three delivery +workflows, deletes the old curl installers and changes the Codex plugin to read +`skills/` directly. Read the +[3.9 release notes](docs/releases/2026-10-03-v3.9.0-notes.md) before updating. Use the [plugin update instructions](docs/install-day2-ops.md#install-and-update-runtime-plugins) or, for npx installs, `npx skills@latest update` ([update notes](docs/install-day2-ops.md#update)). For Homebrew: `brew update && brew upgrade agentops`. Start a new session @@ -344,8 +348,7 @@ afterward; new installs do not silently remove obsolete copies. **Upgrading from 3.6 or earlier:** read the [migration guide](docs/MIGRATION.md). Version 3.7 removed commands and skill names, including `learn`, `codebase-recon` and `swarm`; their current owners are `memory`, `research` and `agent-native`. -See the [3.8 release notes](docs/releases/2026-09-22-v3.8.0-notes.md) and -[3.7 removals](docs/releases/2026-09-13-v3.7.0-notes.md). +See the [3.7 removals](docs/releases/2026-09-13-v3.7.0-notes.md).
@@ -366,7 +369,7 @@ Skill installation does not install tool dependencies: | `using-gc` | `ao` | rig prep runs `ao gc prepare` and `ao gc check` | | `doc` | `ao`, optional | a requested continuity handoff may use `ao session handoff`/`rehydrate` | | `reverse-engineer` | `python3` | Phase 1's mechanical teardown runs `scripts/reverse_engineer.py` | -| `skill-builder` | `python3`, conditional | Create mode's `build.sh` runs `scripts/generate-skill-mesh.py`; heal/check/audit modes are bash-only | +| `skill-builder` | `ao` 3.9 or later outside a source checkout, Go inside one; `python3`, conditional | build, check, heal and audit run through `ao skills`; build (without `--init-only`) and heal's fix mode also run `scripts/generate-skill-mesh.py`, and `audit.sh --legacy` needs PyYAML | | `memory` | `python3`, conditional | a selected toil investigation can use the repository helper `scripts/toil-mining/recent_human.py` on cleared Codex sources | | `security` | `python3`, conditional | the composable suite and offline redteam surfaces run `security_suite.py` when that scan type is selected | diff --git a/cli/cmd/ao/main.go b/cli/cmd/ao/main.go index 85b008c4b..f18cd0707 100644 --- a/cli/cmd/ao/main.go +++ b/cli/cmd/ao/main.go @@ -5,7 +5,7 @@ package main // version is set at build time via ldflags (goreleaser: -X main.version={{ .Version }}). // The fallback identifies untagged source builds for the next release; // published binaries override it from the release tag via GoReleaser. -var version = "3.8.0" +var version = "3.9.0" func main() { Execute() diff --git a/cli/cmd/ao/version_manifest_parity_test.go b/cli/cmd/ao/version_manifest_parity_test.go index b11fefb37..74baa922a 100644 --- a/cli/cmd/ao/version_manifest_parity_test.go +++ b/cli/cmd/ao/version_manifest_parity_test.go @@ -133,3 +133,32 @@ func TestVersion_FallbackMatchesReleaseManifests(t *testing.T) { t.Errorf("%s: EXPECTED_VERSION default = %q, want %q (main.go release fallback)", verifyRel, got, version) } } + +// TestVersion_FallbackHasCuratedReleaseNotes guards the release-cut invariant +// that the checked-in `version` fallback has a curated release-notes file. +// +// `scripts/extract-release-notes.sh` hard-errors without one, and the publisher +// runs it only after the tag is pushed. `tests/docs/validate-doc-release.sh` +// surfaces the sibling CHANGELOG.md requirement before the tag; nothing +// surfaced this one, so a version bump without notes failed only at publish. +// The publisher takes the first match, so a second file for the same version +// makes the published body ambiguous and is rejected too. +func TestVersion_FallbackHasCuratedReleaseNotes(t *testing.T) { + if strings.Contains(version, "-g") || strings.HasSuffix(version, "-dirty") { + t.Skipf("version %q is an ldflags-injected build-describe string, not the checked-in fallback", version) + } + + root := findReleaseManifestRoot(t) + if root == "" { + t.Skip("not running inside an AgentOps checkout; no release notes to look for") + } + + pattern := filepath.Join("docs", "releases", "*-v"+version+"-notes.md") + matches, err := filepath.Glob(filepath.Join(root, pattern)) + if err != nil { + t.Fatalf("glob %s: %v", pattern, err) + } + if len(matches) != 1 { + t.Fatalf("found %d curated release-notes files matching %s, want exactly 1: %v", len(matches), pattern, matches) + } +} diff --git a/docs/CHANGELOG.md b/docs/CHANGELOG.md index dc7ce686e..8fe66a23d 100644 --- a/docs/CHANGELOG.md +++ b/docs/CHANGELOG.md @@ -7,6 +7,44 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +## [3.9.0] - 2026-10-03 + +AgentOps 3.9 narrows the product to its own guidance. The ten bundled external +tool skills are removed, three repository delivery workflows are retired, the +Codex plugin reads `skills/` directly instead of a generated copy, and +installation has three supported paths: the Claude Code plugin, the Codex +plugin, and `npx skills` for every other agent. Validation is now spent where a +mistake is costly instead of on every change. Interview and Navigate are new, +and Council gains duel and interview-panel modes. The optional menu goes from +36 to 28 skills; native work still requires none of them. + +See the [curated release notes](https://github.com/boshu2/agentops/blob/main/docs/releases/2026-10-03-v3.9.0-notes.md) +for upgrade instructions, breaking changes and known limits. + +### Added + +- Interview shapes a large outcome with the caller one question at a time before + agents work alone. Each question carries a recommendation and its main + tradeoff; acceptance is recorded as Given/When/Then examples. It creates no + goal or bead. +- Navigate picks the next wave on a bead graph and records results and + discoveries on the beads. It never dispatches, judges or closes work. The bead + graph contract and wave loop move here from Craft Goal. +- Council gains two modes. In a duel, members rank their own ideas, score every + other member's ideas on a rubric fixed before launch, then concede or defend + in one bounded round. In an interview panel, each member answers Interview's + questions in a separate context; agreed answers are marked and the caller + accepts or amends the result. The caller may give each member its own model, + effort and perspective. +- `ao skills build` creates an explicitly incomplete skill scaffold and its + generated projections; its three modes write the same scaffold and import no + content. `ao skills audit` reports static conformance, effect observations + and unmeasured behavior separately. `ao skills check-source` checks named + source packages. +- A gate checks that each retired workflow file contains only its metadata and + an immediate failure. A test requires the checked-in version to have exactly + one curated release-notes file. + ### Changed - Fresh validation is no longer owed on every change. For an ordinary change @@ -29,11 +67,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 unchanged. Codex plugin users should refresh the marketplace and re-add the plugin. Checked against codex-cli 0.156.1: a plugin install and a linked install each load all 28 skills with no load errors. -- `interview` now carries its Codex invocation policy in - `skills/interview/agents/openai.yaml`. The generator used to derive that file - from `disable-model-invocation: true`; it is now hand-maintained in each - explicit-only skill, and `scripts/validate-codex-api-conformance.sh` fails when - one is missing or does not parse. +- Each explicit-only skill carries its Codex invocation policy in its own + `agents/openai.yaml`, hand-maintained in `skills/`; the generator no longer + derives it. `scripts/validate-codex-api-conformance.sh` fails when one is + missing or does not parse. - `scripts/validate-codex-api-conformance.sh` checks `skills/` against what the Codex loader enforces (unique frontmatter keys, a non-empty description, a name of at most 64 characters, no nested `SKILL.md`) and the explicit-only @@ -44,7 +81,32 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - The `skill-eval` fixtures moved from `skills/_fixtures/` to `tests/fixtures/skill-eval/`. Codex loads every `SKILL.md` under the plugin's skill tree, so the fixtures would have shipped as a skill and a load error. - +- Craft Goal's frozen goal prompt states acceptance as Given/When/Then examples + and names domain terms once. +- Skill Builder's build, check, heal and audit scripts run through `ao skills`: + outside a source checkout they need `ao` 3.9 or later; inside one they build + `ao` with Go. Its audit reports conformance, effect observations, behavioral + evidence and review suspicions separately; + `skills/skill-builder/scripts/audit.sh --legacy` keeps the earlier format. + Build no longer writes a default report under `.agents/scratch/skill-builder/`, + and invalid creation inputs exit 1 instead of 2. +- AgentOps' own guards (policy dispatcher, read-budget, Codex read-budget and + installed-skill-edit guards) moved from `skills/cc-hooks/` to `hooks/guards/`. + Plugin users and already-installed guards need no action; update any direct + call to `skills/cc-hooks/scripts/install-hooks.sh` or `skills/cc-hooks/hooks/*` + to `scripts/install-policy-dispatch.sh` or `hooks/guards/`. A skill-only + install no longer carries a hook installer. +- `docs.cli-snippets` is a blocking gate that resolves `ao` commands cited in + code spans and fenced blocks of the live docs against the real command tree. + It is one of the fact checks that replaced documentation tests which froze + wording. +- The install drift check fails on a stale installed copy of any retired + workflow, in `~/.claude/workflows` and in a project's `.claude/workflows`. +- The release body's header links the update guide instead of a one-line + source-checkout update command. +- The README is rebuilt around the operational loop, with a goals section and a + grouped skill chart. It recommends upstream projects for some external tools + by link instead of bundling their skills. - Install narrowed to three paths: the Claude Code plugin, the Codex plugin, and `npx skills@latest add boshu2/agentops` for every other agent (Cursor, OpenCode, Gemini CLI/Antigravity, Pi, Grok Build, OpenClaw). Grok Bot takes @@ -87,38 +149,50 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 resolving. - The Skill Builder converter's Codex target no longer writes `prompt.md`; Codex does not read it. - - Bundled Flywheel tool skills (`account-rotation`, `agent-mail`, `cass`, `cc-hooks`, `dcg`, `ms`, `ntm`, `rch`, `sbh`, `using-flywheel`) and their generated Codex copies. - Obtain tools and skills from their upstream authors; see the README - recommendations. This changes the available skill names in the next release. - Existing personal installations are not automatically removed. -- AgentOps' own guards (policy dispatcher, read-budget, Codex read-budget and - installed-skill-edit guards) moved from `skills/cc-hooks/` to `hooks/guards/`. - Plugin users and already-installed guards need no action; update any direct - call to `skills/cc-hooks/scripts/install-hooks.sh` or `skills/cc-hooks/hooks/*` - to `scripts/install-policy-dispatch.sh` or `hooks/guards/`. - + AgentOps provides no replacement. The README recommends the upstream projects + for DCG, CASS, Meta Skill, the Agentic Coding Flywheel and Gas City; get those + tools and any skills for them from their authors. Copies installed earlier + with `npx skills` are not removed; a source link to a removed skill is left + dangling (see the release notes). +- The `skill-first-coord-guard.sh` hook and its reference page, and the generic + Claude Code hook reference pages that shipped inside `cc-hooks`. +- `scripts/install-ms-reindex-hook.sh` and `scripts/ms-reindex.sh`. +- The `ao doctor` check and repository gate that banned running Claude headless + in print mode (`claude -p`). Print mode is an ordinary dispatch option again. - The `bdd-foundry`, `ship-beads` and `bead-crank` Claude workflows. The names stay as tombstones that fail with a migration message before doing any work, like `operating-loop`. In place of `bdd-foundry`, state accepted behavior in the conversation or a bead. In place of `ship-beads` and `bead-crank`, deliver with native Git and BD under your repository's policy, or dispatch to a software factory through its coordinator. An installed copy of the old files now fails - the `workflow.install-drift` gate. `ao workflows link` does not replace it: for - `~/.claude/workflows` run `bash scripts/install-workflows.sh`, which backs up the - old file and links the tombstone; for a project's `.claude/workflows`, remove the - old file and then run `ao workflows link`. + the `workflow.install-drift` gate. `ao workflows link` does not replace a + copied file. For `~/.claude/workflows`, run `bash scripts/install-workflows.sh` + from the AgentOps checkout and name only the retired files you have (for + example `bdd-foundry.js`): each becomes a link to the current file, and a file + that differs is backed up first. Without file names the script installs every + workflow. For another project's `.claude/workflows`, remove the old file, then + run `ao workflows link --into /.claude/workflows` from the checkout. `scripts/check-bdd-foundry-markers.sh` is removed. - The 3.x curl and PowerShell skill installer tombstones (`scripts/install.sh`, `install-claude.sh`, `install-codex.sh`, `install-agy.sh`, `install-opencode.sh`, `install-codex.ps1`). Their raw URLs now 404, so an old - `curl … | bash` line silently does nothing; switch to a plugin or npx. + `curl … | bash` line installs nothing; switch to a plugin or npx. - The `images/gemini` package (`agentops-core-gemini`) and its generator branch. - Remove an installed copy with `agy plugin uninstall agentops-core-gemini`. + Remove an installed copy with `agy plugin disable agentops-core-gemini` and + then `agy plugin uninstall agentops-core-gemini`. ### Fixed +- The repository's skill evaluation suite under `evals/skills-rpi/` checks + task-bank controls through the exact packaged verifier and prepares both arms + with shared task and image identities before any trial starts, so packaging + and identity mismatches are rejected before model resources are spent. +- The documentation site banner no longer shows the retired 3.3 tagline, and + the site build no longer publishes its internal generator scripts. +- The CI job that syntax-checks workflow scripts parses them the way the harness + runs them, so a top-level `return` no longer fails it. - `ao skills link`, `unlink` and `ao doctor` use Pi's user skills dir, `~/.pi/agent/skills`, and detect Pi by `~/.pi/agent`. Links an earlier version made in `~/.pi/skills` are no longer swept by default; remove them with diff --git a/docs/MIGRATION.md b/docs/MIGRATION.md index e6554c5ba..9f71795cb 100644 --- a/docs/MIGRATION.md +++ b/docs/MIGRATION.md @@ -379,6 +379,7 @@ untested promise. Every live claim still needs evidence on the final installatio | Claude policy dispatcher | keep; [plugin hooks](https://github.com/boshu2/agentops/blob/main/hooks/hooks.json), [source wrapper](https://github.com/boshu2/agentops/blob/main/scripts/install-policy-dispatch.sh) and [packaged owner](https://github.com/boshu2/agentops/blob/main/hooks/guards/scripts/install-hooks.sh) | The dispatcher is automatically active when installed through the Claude plugin; source/copy installation uses the existing owner-selected installer. Native zero-skill work remains hookless. | | Read-budget and installed-skill edit guards | keep; [Claude read guard](https://github.com/boshu2/agentops/blob/main/scripts/install-read-budget-guard.sh), [Codex read guard](https://github.com/boshu2/agentops/blob/main/scripts/install-codex-read-budget-guard.sh), [edit guard](https://github.com/boshu2/agentops/blob/main/scripts/install-installed-skill-edit-guard.sh) | Preserve separate opt-in installation, Codex trust review, backups and documented enforcement limits. | | Claude named workflows | keep; [canonical workflows](../workflows/), [`ao workflows`](https://github.com/boshu2/agentops/blob/main/cli/docs/COMMANDS.md#ao-workflows), [user-level installer](https://github.com/boshu2/agentops/blob/main/scripts/install-workflows.sh) | Keep project-local owned-link refusal semantics. The user-level installer retains its distinct backed-up replacement semantics; do not assume the two installers are interchangeable. | +| Retired Claude workflows | retired tombstones: `bdd-foundry`, `ship-beads`, `bead-crank`, `operating-loop` | Each name fails with a migration message before doing any work. State accepted behavior in the conversation or a bead instead of `bdd-foundry`; deliver with native Git and BD under your repository's policy, or through a selected factory's coordinator, instead of `ship-beads` and `bead-crank`. Replace a copied (not linked) installed file from the AgentOps checkout: `bash scripts/install-workflows.sh` with only the retired file names you have (for example `bdd-foundry.js`) for `~/.claude/workflows` (a differing file is backed up first; without file names it installs every workflow), or remove the old file and run `ao workflows link --into /.claude/workflows` for another project. | | Optional BD binary installer | keep; [install-bd.sh](https://github.com/boshu2/agentops/blob/main/scripts/install-bd.sh) | Installs selected native BD; does not create or replace the repository's work store. | | Optional MS post-merge index hook | retired | Obtain MS maintenance guidance from [upstream](https://github.com/Dicklesworthstone/meta_skill). AgentOps no longer ships an MS index hook installer. | | Legacy 3.x skill curl/PowerShell installers | retire; deleted: `install.sh`, `install-claude.sh`, `install-codex.sh`, `install-agy.sh`, `install-opencode.sh`, `install-codex.ps1` | Their raw URLs now 404; see the breaking boundary below. `install-ao.ps1` is a retained CLI installer, not this retired skill installer. | diff --git a/docs/install-day2-ops.md b/docs/install-day2-ops.md index 9d4496b47..e195acc96 100644 --- a/docs/install-day2-ops.md +++ b/docs/install-day2-ops.md @@ -55,7 +55,7 @@ requirements. Most need nothing beyond the coding agent; these need more: | `using-gc` | `ao` | rig prep runs `ao gc prepare` and `ao gc check` | | `doc` | `ao`, optional | a requested continuity handoff may use `ao session handoff`/`rehydrate` | | `reverse-engineer` | `python3` | Phase 1's mechanical teardown runs `scripts/reverse_engineer.py` | -| `skill-builder` | `python3`, conditional | Create mode's `build.sh` runs `scripts/generate-skill-mesh.py`; heal/check/audit modes are bash-only | +| `skill-builder` | `ao` 3.9 or later outside a source checkout, Go inside one; `python3`, conditional | build, check, heal and audit run through `ao skills`; build (without `--init-only`) and heal's fix mode also run `scripts/generate-skill-mesh.py`, and `audit.sh --legacy` needs PyYAML | | `memory` | `python3`, conditional | a selected toil investigation can use the repository helper `scripts/toil-mining/recent_human.py` on cleared Codex sources | | `security` | `python3`, conditional | the composable suite and offline redteam surfaces run `security_suite.py` when that scan type is selected | @@ -194,11 +194,13 @@ npx installs: npx skills@latest update ``` -Contributor source links: +Contributor source links. Upgrade `ao` first when the release changes the CLI +(3.9 does: a 3.8 `ao` refuses a checkout without `skills-codex/`): ```bash cd ~/.local/share/agentops git pull --ff-only +(cd cli && go install ./cmd/ao) ao skills link --skill test --skill refactor ``` diff --git a/docs/releases/2026-10-03-v3.9.0-notes.md b/docs/releases/2026-10-03-v3.9.0-notes.md new file mode 100644 index 000000000..86abeb68c --- /dev/null +++ b/docs/releases/2026-10-03-v3.9.0-notes.md @@ -0,0 +1,308 @@ +## Highlights + +AgentOps 3.9 narrows the product to its own guidance. The ten bundled external +tool skills are removed. Three repository delivery workflows are retired. The +Codex plugin now reads the same `skills/` tree every other install uses, instead +of a generated copy. Installation has three supported paths: the Claude Code +plugin, the Codex plugin, and `npx skills` for every other agent. + +Validation is now spent where a mistake is costly. For an ordinary change the +checks and CI are the gate; the skills call for one fresh review only when you +ask, when a mistake can't be cheaply undone, or when no check covers what +changed. A review is one round, and a fix does not start another. + +Two skills are new. Interview settles a large outcome with you one question at a +time before agents work alone. Navigate picks the next wave on a bead graph and +keeps the graph honest toward the acceptance you froze. Council gains duel and +interview-panel modes, and you can give each member its own model, effort and +perspective. + +The optional menu goes from 36 to 28 skills. Native coding still requires none +of them. + +## Upgrade Notes + +- Update your managed plugin or selected source checkout using the + [update guide](https://github.com/boshu2/agentops/blob/main/docs/install-day2-ops.md#update), then start a fresh session. +- Codex plugin users: refresh the marketplace and re-add the plugin. The plugin + now ships `skills/` instead of the generated `skills-codex/` copy; skill names, + descriptions and bodies are unchanged. +- AgentOps no longer ships `account-rotation`, `agent-mail`, `cass`, + `cc-hooks`, `dcg`, `ms`, `ntm`, `rch`, `sbh` or `using-flywheel`, and + provides no replacement for them. The README's + [recommended tools](https://github.com/boshu2/agentops/blob/main/README.md#recommended-tools-and-skills) section links the projects it still + recommends: DCG, CASS, Meta Skill, the Agentic Coding Flywheel and Gas City. + Get those tools, and any skills for them, from their authors. Copies you + installed earlier with `npx skills` are not deleted by this release. +- If you track a source checkout, upgrade `ao` to 3.9 before running any `ao` + command from it: `brew upgrade agentops`, or `cd cli && go install ./cmd/ao` + in the checkout. A 3.8 `ao` looks for the deleted `skills-codex/` directory + and refuses the updated checkout. +- If you track a source checkout with `ao skills link`, pulling 3.9 removes the + ten skills from the checkout and leaves a dangling link for each in every + runtime's skill directory. `ao skills link` adds missing links and never + removes one. From the checkout, run `ao skills unlink` (preview with + `--dry-run`), then repeat the `ao skills link` command you first used. Pass + the same `--dest` to both if you linked into a custom directory. `unlink` has + no `--skill` selector, so repeat any `--skill` options on the second command; + a bare `ao skills link` links all 28 skills. +- If you install with an old `curl … | bash` line, switch to a plugin or + `npx skills@latest add boshu2/agentops`. Those scripts already refused to + install in 3.8; their URLs now return 404. +- If you copied the retired workflow files instead of linking them, replace + the copies. For `~/.claude/workflows`, run `bash scripts/install-workflows.sh` + from the AgentOps checkout and name only the retired files you have, for + example `bash scripts/install-workflows.sh bdd-foundry.js ship-beads.js`. + Each named file becomes a link to the current one, and a file that differs is + backed up first; without file names the script installs every workflow. For + another project's `.claude/workflows`, remove the old file, then run + `ao workflows link --into /.claude/workflows` from the AgentOps + checkout, which links every workflow that has no entry there yet. +- If you call the hook guard scripts directly, update + `skills/cc-hooks/scripts/install-hooks.sh` and `skills/cc-hooks/hooks/*` to + `scripts/install-policy-dispatch.sh` and `hooks/guards/`. Plugin users and + already-installed guards need no action. +- A skill-only install (`npx skills`) no longer carries a hook installer. The + guards come with the Claude plugin, which activates them itself, or with a + source checkout through `scripts/install-policy-dispatch.sh`. If you move to + the plugin, remove the `npx skills` copy first so each skill is not loaded + twice. +- If you use Skill Builder's scripts outside a source checkout, install `ao` 3.9 + or later. Inside a checkout they build `ao` with Go. +- If you installed the Gemini package, run + `agy plugin disable agentops-core-gemini` and then + `agy plugin uninstall agentops-core-gemini`, and install through + `npx skills`. +- If an earlier `ao skills link` put Pi links in `~/.pi/skills`, remove them + with `ao skills unlink --dest ~/.pi/skills`. Pi loads user-level skills from + `~/.pi/agent/skills`. +- If upgrading from 3.6 or earlier, follow the + [migration guide](https://github.com/boshu2/agentops/blob/main/docs/MIGRATION.md) first. + +## Breaking Changes + +- Ten skills are removed from the bundle: `account-rotation`, `agent-mail`, + `cass`, `cc-hooks`, `dcg`, `ms`, `ntm`, `rch`, `sbh` and `using-flywheel`. +- The `bdd-foundry`, `ship-beads` and `bead-crank` Claude workflows are + retired. Each name still resolves, and fails with a migration message before + doing any work. +- The 3.x curl and PowerShell skill installer stubs are deleted: + `scripts/install.sh`, `install-claude.sh`, `install-codex.sh`, + `install-agy.sh`, `install-opencode.sh` and `install-codex.ps1`. They + already refused to install; their raw URLs now return 404. +- The `images/gemini` package (`agentops-core-gemini`) is removed. +- The generated `skills-codex/` copy and its tooling are removed. Anything that + read `skills-codex/` directly must read `skills/`. +- The `skills/cc-hooks/` paths are gone. AgentOps' own guards now live under + `hooks/guards/`. The `skill-first-coord-guard.sh` hook is removed, not moved. +- `scripts/install-ms-reindex-hook.sh` and `scripts/ms-reindex.sh` are deleted. +- The fixed-dispatch RPI reference adapter (`skills/rpi/scripts/run_once.py`) + is removed. +- Skill Builder's scripts require `ao`. Build no longer writes a default + report under `.agents/scratch/skill-builder/`, and invalid creation inputs + exit 1 instead of 2. +- `ao skills check --json` no longer has `parity_drift` or a per-skill + `codex_parity`, and `skills/catalog.json` no longer has + `codex_override_present`. + +## At a Glance + +| Area | What changes for the user | +|---|---| +| Skill menu | 28 skills instead of 36: Interview and Navigate are new, ten external tool skills are removed. | +| Validation | Checks and CI are the gate; one fresh review only where a mistake is costly; one round, no re-review after a fix. | +| Codex plugin | Reads `skills/` directly; the generated copy is gone. Refresh the marketplace and re-add the plugin. | +| Shaping work | Interview settles a large outcome question by question; Navigate walks the resulting bead graph one wave at a time. | +| Council | Duel and interview-panel modes; per-member model, effort and perspective. | +| Delivery workflows | `bdd-foundry`, `ship-beads` and `bead-crank` fail with a migration message. Deliver with native Git and your tracker. | +| Installation | Claude Code plugin, Codex plugin, or `npx skills`. The curl installer stubs and the Gemini package are gone. | +| Skill authoring | Skill Builder runs through `ao skills build`, `audit` and `check-source`, and reports structure separately from evidence that a skill helps. | + +## Product Areas + +### Skills and Workflows + +- Changed: Validation is spent where a mistake is costly. For an ordinary change + the author's checks and CI are the gate. RPI, Validate, Implement, + Orchestrate, Craft Goal and Navigate call for one fresh review only when the + caller asks, a mistake cannot be cheaply undone after it lands, or no + deterministic check covers the changed behavior. The reviewer answers one + question, does not re-run checks, and reports as defects only what would + mislead a user, break install or the CLI, or remove protection for the + product. A fix is confirmed by a check and does not start another review. +- Added: Interview shapes a large outcome with the caller one question per + turn. Each question carries a recommendation and its main tradeoff, and + acceptance is recorded as Given/When/Then examples. It is invoked by a + person and creates no goal or bead. +- Added: Navigate picks the next wave on a bead graph: the acceptance matrix, + the ready frontier, a small wave, then results and discoveries recorded on + the beads. It never dispatches, judges or closes work. The bead graph + contract and wave loop move here from Craft Goal. +- Added: Council duel mode. Each member writes its own ranked ideas, scores + every other member's ideas on a rubric fixed before launch, then concedes or + defends in one bounded round. Ideas rank by cross-member agreement. +- Added: Council interview-panel mode. Each member answers Interview's + questions in its own context. Agreed answers are marked, one bounded debate + covers the open ones, and the caller accepts or amends the result. +- Changed: The caller may give each council member its own model, effort and + perspective. A perspective steers what a member examines, never what + evidence it receives. The same model in separate contexts counts as one + model's confirmation. +- Changed: Craft Goal, Interview and Navigate are marked stable. Craft Goal's + frozen goal prompt states acceptance as Given/When/Then examples and names + domain terms once. +- Changed: Skill Builder creates a minimal scaffold that is explicitly + incomplete. Its audit script reports conformance, effect observations, + behavioral evidence and review suspicions separately; the earlier report + format stays available through `skills/skill-builder/scripts/audit.sh --legacy`. +- Changed: Skill Builder's build, check, heal and audit scripts run through + `ao skills`: outside a source checkout they need `ao` 3.9 or later, and inside + one they build `ao` with Go. Build no longer writes a default report under + `.agents/scratch/skill-builder/`; pass `--report` or read stdout. Invalid + creation inputs exit 1 instead of 2. +- Fixed: Skill Builder's `heal.sh --check` exits 2 with a message when `ao` + cannot run; it used to report a pass. +- Removed: The ten bundled external tool skills listed under Breaking Changes. + AgentOps keeps its own session-identity and source-reading guidance. +- Removed: The `bdd-foundry`, `ship-beads` and `bead-crank` workflows. In place + of `bdd-foundry`, state accepted behavior in the conversation or a bead. In + place of `ship-beads` and `bead-crank`, deliver with native Git and BD under + your repository's policy, or dispatch to a software factory through its + coordinator. +- Removed: The fixed-dispatch RPI reference adapter, which modelled repeated + review rounds, with its tests and reference page. + +### CLI and Operator Commands + +- Added: `ao skills build ` + creates an incomplete skill scaffold and its generated projections. All + three modes write the same scaffold; `--source` is recorded as a hint and no + content is imported. +- Added: `ao skills audit` reports static conformance, effect observations and + unmeasured behavior as separate results for one skill package. +- Added: `ao skills check-source` checks named source packages without + claiming they are semantically complete. +- Changed: `ao skills check` audits `skills/` only. Its JSON no longer has + `parity_drift` or a per-skill `codex_parity`, and `--strict` fails on errors + alone. +- Fixed: `ao skills link`, `ao skills unlink` and `ao doctor` use Pi's + user-level skills directory, `~/.pi/agent/skills`, and detect Pi by + `~/.pi/agent`. Before, Pi user skills were linked into `~/.pi/skills`, which + is not Pi's user-level directory. +- Removed: The `ao doctor` check that flagged running Claude headless in print + mode (`claude -p`), and the doctor failure mode that synced the deleted Codex + copy into Codex's plugin cache. + +### Install, Upgrade, and Distribution + +- Changed: Installation is documented as three paths: the Claude Code plugin, + the Codex plugin, and `npx skills@latest add boshu2/agentops` for Cursor, + OpenCode, Gemini CLI/Antigravity, Pi, Grok Build and OpenClaw. Grok Bot takes + the same `SKILL.md` files through its own skill settings. +- Changed: `ao skills link` is documented as the contributor path. The docs no + longer suggest `--all -g`, which creates config directories for agents you do + not have. +- Changed: The metadata-derived skill inventory is 28. The Claude plugin and + the Codex plugin both ship it from `skills/` at version 3.9.0. +- Changed: A skill-only install no longer carries a hook installer. The Claude + plugin and a source checkout keep theirs. +- Removed: The six curl and PowerShell skill installer stubs and the Gemini + package, as listed under Breaking Changes. `install-ao.ps1`, the Windows CLI + installer, is kept. +- Removed: `scripts/install-ms-reindex-hook.sh` and `scripts/ms-reindex.sh`. + Get Meta Skill maintenance guidance from its upstream project. + +### Codex and Runtime Integrations + +- Changed: The Codex plugin reads `skills/` directly. Checked with codex-cli + 0.156.1: a plugin install and a linked install each load all 28 skills with no + load errors. The plugin now ships the full AgentOps frontmatter; Codex ignores + the extra fields. `prompt.md` and the generated markers are no longer shipped; + Codex did not read them. +- Changed: Each explicit-only skill (`craft-goal`, `interview`, `postmortem`, + `rpi`) carries its own `agents/openai.yaml` with + `policy.allow_implicit_invocation: false`, so Codex does not select it + implicitly. The files are hand-maintained in `skills/`. +- Fixed: The Codex policy check fails on the `agents/openai.yaml` shapes Codex + silently ignores: a non-object `interface`, `dependencies` without a `tools` + list, and a boolean spelled other than `true` or `false`. +- Changed: The skill evaluation fixtures moved from `skills/_fixtures/` to + `tests/fixtures/skill-eval/`; Codex loads every `SKILL.md` under the plugin's + skill tree and would have shipped them. +- Removed: The generated `skills-codex/` copy, its override catalog, generator, + hash and parity tooling, and the Gemini image, which was a second generated + copy of every skill. The Skill Builder converter's Codex target no longer + writes `prompt.md`. + +### Hooks and Lifecycle + +- Changed: AgentOps' own guards move from `skills/cc-hooks/` to `hooks/guards/`: + the policy dispatcher, the Claude and Codex read-budget guards and the + installed-skill-edit guard, with their policies and installers. The plugin's + `hooks/hooks.json` and the `scripts/install-*` entry points keep working. +- Removed: The `skill-first-coord-guard.sh` hook and its reference page. +- Removed: The generic Claude Code hook reference pages that shipped inside + `cc-hooks`. The guard docs link the official hooks reference instead. + +### Eval, Validation, and Release Gates + +- Fixed: The repository's skill evaluation suite under `evals/skills-rpi/` + runs task-bank controls through the exact packaged verifier, prepares both + arms with shared task and image identities, and rechecks both before launch. + Packaging and identity mismatches are rejected before model resources are + spent. The Skill Eval skill itself is unchanged. +- Added: A gate checks that each retired workflow file contains only its + metadata and an immediate failure, so code placed ahead of the failure is + rejected. The install drift check now fails on a stale installed copy of any + retired workflow, in `~/.claude/workflows` and in a project's + `.claude/workflows`. +- Added: A test requires the checked-in version to have exactly one curated + release-notes file, so a version bump without notes fails before the tag + instead of at publish. +- Changed: `docs.cli-snippets` is a blocking gate that resolves `ao` commands + cited in code spans and fenced blocks of the live docs against the real + command tree. It is one of the fact checks that replaced documentation tests + which froze wording. +- Fixed: The conformance probe that checks the Validate helper makes no Git, + tracker or delivery calls now intercepts calls made in-process; before, those + reached the real binaries unnoticed. +- Removed: The four gates that policed the Codex copy, the repository gate that + banned Claude print mode, and several gates with no live consumer. +- Fixed: The CI job that syntax-checks workflow scripts parses them the way + the harness runs them, so a top-level `return` no longer fails it. + +### Docs and Onboarding + +- Changed: The README is rebuilt around the operational loop, with a goals + section, Beads as the work graph, and a grouped skill chart. It adds + BDD/DDD links and a fuller Gherkin example, and recommends upstream projects + for some external tools by link. +- Changed: The contract (`AGENTS.md`), the workflow reference and the product, + architecture and how-it-works pages describe validation as checks and CI plus + one fresh review where a mistake is costly. +- Changed: The migration guide covers the removed skills, the deleted + installer stubs, the moved guards, the Codex plugin change and the retired + workflows. +- Changed: The release body's header links the update guide instead of a + one-line source-checkout update command. +- Fixed: The documentation site banner no longer shows the retired 3.3 + tagline, and the site build no longer publishes its internal generator + scripts. +- Docs: The AgentOps logo is redrawn. + +## Known Issues + +- `ao skills link` does not remove a link whose skill was removed from the + checkout. Until it does, use `ao skills unlink` and then repeat your + original `ao skills link` command (with the same `--dest`, and `ao` 3.9) after + an update that removes skills. +- The retired-workflow checks identify a workflow by its file name. An old + workflow body installed under a different file name is not detected. +- Codex's own bundled plugin validator rejects this plugin on fields unrelated + to loading, as it did in 3.8. Skills load normally. +- Structural checks do not establish that any skill improves outcomes. No + efficacy or token-cost improvement is claimed for Interview, Navigate or the + new Council modes. +- Restricted-source enforcement remains unavailable, as in 3.8. + +[Full changelog](../CHANGELOG.md) diff --git a/images/claude/verify.sh b/images/claude/verify.sh index 69e57a64f..83dfe021b 100755 --- a/images/claude/verify.sh +++ b/images/claude/verify.sh @@ -58,7 +58,7 @@ fi # Version guard: the Claude marketplace plugin manifest is the install entrypoint # for this image. Assert .claude-plugin/plugin.json declares the expected version # so a stale-version drift (plugin.json behind the release) fails the gate. -EXPECTED_VERSION="${AGENTOPS_EXPECTED_VERSION:-3.8.0}" +EXPECTED_VERSION="${AGENTOPS_EXPECTED_VERSION:-3.9.0}" plugin_manifest="$repo_root/.claude-plugin/plugin.json" if [ ! -f "$plugin_manifest" ]; then echo "FAIL: Claude plugin manifest not found: $plugin_manifest" >&2 diff --git a/scripts/extract-release-notes.sh b/scripts/extract-release-notes.sh index 9940a7799..5da57be2b 100755 --- a/scripts/extract-release-notes.sh +++ b/scripts/extract-release-notes.sh @@ -337,7 +337,7 @@ echo "Using curated release notes from $NOTES_FILE" >&2 { # Header cat <