Changelog
What changed between releases. Newest version first. Update to the current release with devkit sync. This English page is the record; the German edition follows the same release history.
An entry appears here as soon as the version is tagged; it reaches the stable channel once the publish job is through, so the newest heading can be one release ahead of what devkit sync hands you. devkit status names the version you actually run.
Unreleased
Action required after devkit sync
- Projects with a project
.mcp.jsonthat also use Codex or OpenCode: rundevkit initonce to mirror those servers;devkit doctorthen lists the env vars each one needs. - Shopify themes that used
devkit liquid-settings: add thetheme:settingsscript topackage.jsonafterdevkit skills pull.
Sessions now get a second context hint at 300k tokens (61.5% of measured calls ran above 200k) and a nudge against sed -n range reads (273 of them against 75 Read calls), /offload hands specs to a connected Orca server without waking your session on every heartbeat, and project .mcp.json servers finally reach Codex and OpenCode. Update with devkit sync.
119 commits since v0.50.0 · Specs 013, 688, 702, 703, 705
✨ Highlights
📡 Offload specs to an Orca server
/offload starts one worker per spec on a connected Orca server and fetches the result over SSH, so no branch lands on GitHub. Started from a throwaway terminal, heartbeats no longer wake your session (four wake-ups in the Spec 702 run), and collect reuses the server's review instead of a second one that has cost up to 164k tokens.
/offload 702
/offload collect 702🔌 Project MCP servers in Codex and OpenCode
Codex and OpenCode do not read the project .mcp.json, so agents there never saw servers such as the MCP gateway. devkit init now adds each missing server to .codex/config.toml and opencode.json (add-only; literal credentials are skipped and never written), and devkit doctor warns on a missing env var.
devkit init
devkit doctor🧭 Two nudges against expensive sessions
A second context hint fires at 300k tokens even without a clean cut, because the 150k hint almost never found one: 61.5% of calls in a 7-day audit ran above 200k and the 400k+ bucket carried 22% of input. The third consecutive sed -n range read of one file now gets a one-line advisory (273 range reads against 75 Read calls, 85% single-tool calls); neither blocks.
export DEVKIT_SESSION_COMPACT_TOKENS=300000🛡️ Secret guard: fewer false denials, one bypass closed
A regex anchor such as </ul>$ or a quoted heredoc word no longer reads as a .env glob, which had denied read-only commands and cost a delegate two turns. In return, cat <<EOF with $(cat .env) in its body no longer slips past the guard, and the deny text now names the token that tripped it.
(matched: `<token>`)🥧 Pi implement on macOS, Sonnet 5.5 tiers
delegate-exec wraps pi in a Seatbelt profile on macOS (worktree, git dir, ~/.pi/agent and tmp writable, credential dirs unreadable), so pi implement is selectable without DEVKIT_PI_SANDBOX=off; a real run wrote inside the worktree and got EPERM outside. All four Pi tiers now route to anthropic/claude-sonnet-5-5 at medium effort.
devkit runtime-route --inventory implement⚖️ Judge an unresolved AC, review new surfaces twice
spec-work-run <ID> judge ticks a judgement: AC that stays at exit 3 and records the evidence path and sha256, so runners stop hand-editing specs. A spec that adds a skill or devkit command now completes only after two distinct review runtimes passed, one with the ponytail section; Spec 702 had lost six defects to a single reviewer.
devkit spec-work-run <ID> judge <AC-id> --evidence <file>🔧 /index stores only what the code cannot tell
In 26 A/B runs on two boilerplates the agents read package.json and git ls-files first in every arm, never opened an on-demand context file, and the prepared context cost 5–16 % more at equal quality. /index therefore no longer writes STRUCTURE.md (an existing generated one is deleted) or the on-demand pointer line, and SUMMARY.md holds at most 25 lines of facts outside the code: client, deploy, external systems, invisible decisions. It also repairs stale context itself instead of hinting "update manually", and context-drift-check now runs in the quality gate.
/indexWhat changed for you
Now available
/offload <id>and/offload collect <id>hand specs to a connected Orca server (setDEVKIT_OFFLOAD_ENVandDEVKIT_OFFLOAD_SSH); it is a user-only skill.devkit syncinstalls node as a required tool (brew on macOS, apt on Linux; nvm or volta satisfies it), because thirteen npm-installed tools were silently missing without it.
Behavior changed
- Inside Orca,
/spec-work … per /delegateruns the claude implementer as a watchable child worktree instead of an invisible native agent, trading about 3 minutes for visibility. - Delegate runs no longer receive the main-only ADHD ruleset, whose five-item cap could push a reviewer's findings out of view; ponytail stays.
core.mdand the delegate routing now prefer one self-checking script over N model turns, and keep throwaway scripts out of the repo.- The ponytail ladder is carried into
/specauthoring and the/spec-workimplementer prompt. devkit commit-prepprintsfile:lineand RuleID (never the secret) when the gitleaks scan fails, and spec-verify lists introduced fallow findings, capped at 20, on a red gate.- Spec validation names the accepted form on
review_focus_unpinned,verify_vacuous_at_head,AC_EVIDENCE=missingand a wrongSpec-Version, flags German prose under strict authoring and accepts legacy Complexitysmall/large. devkit spec-renumbernow renames legacy specs whose title carries no ID, so the repairduplicate_specprescribes works on all 20 colliding files.- Spec review packages classify other specs' commits by any ID spelling (
Spec 013,Spec #13,spec_13, body-only), and a native Claude round no longer counts as the second runtime. - Delegate preflight names
host_pathandcli_pathfor a codex host skew and ignores foreign installs;returnskips a symlink that points back at main's own path. - The cd-guard note now says the command still ran in the stripped
cd's directory, so subagents stop re-running it with absolute paths. - Tool install runs the install script for pnpm and opencode instead of leaving placeholder binaries, and plugin reconcile repairs the rpiv-todo manifest so Pi loads one typebox copy.
pi-goal-xis dropped (no release covers Pi 0.99.1); existing installs stay untilpi uninstall pi-goal-x.pi-mcp-adaptermoves from 3.2.0 to 4.0.0 for the Pi 0.99 peer range.tool-reviewand the dependency check work again on npm 12, which wrapsnpm view --jsonin an array.
Moved
devkit liquid-settingsmoved into the Shopify boilerplate asnpm run theme:settings(sp-theme-scripts);--unusedand the JSONL rows are unchanged.
🚀 Features
- rules — one self-checking script, no look-first or verify turn (93c4bdd)
- spec-work — run the claude implementer visibly inside Orca (6198a73)
- quality-gate — route context-drift-check as a scanner (b7317fa)
- rules — prefer one script over N model turns (b4449ae)
- index — turn the stale-context hint into a truth pass (83a112a)
- delegate — sandbox pi implement with Seatbelt on macOS (bed2fd4)
- tools — drop pi-goal-x (Spec 688) (89df20f)
- review — gate new-surface specs on two review runtimes (Spec-703) (628c867)
- hooks — nudge on the third sed -n range read of one file (3c1f20d)
- hooks — second context hint at 300k without a clean cut (68425b9)
- skill-lint — fail stale step and anchor pointers in skill references (1902681)
- review — gate new-surface specs on Codex and Pi reviews (Spec-703) (Spec 702) (8a93d67)
- tools — install node as a required tool (9fa6998)
- offload — hand specs to a connected Orca server (Spec-702) (ba02081)
- mcp — mirror project .mcp.json servers into Codex and OpenCode (57c3fa1)
- spec — carry the ponytail ladder into spec authoring and implementers (244af10)
- spec-work — add judge to settle an unresolved judgement AC (b548abe)
- devkit-issues — decide requests via the ponytail ladder (dd4fa33)
🐛 Fixes
- tool-pin-audit — read the darwin platform block, never query gh without a repo (e86eb10)
- tools — bump pi-mcp-adapter to 4.0.0 for the Pi 0.99 peer range (e9bc43e)
- delegate — keep throwaway scripts out of the repo (de4d76c)
- commit-prep — print redacted gitleaks findings on scan failure (b3a6697)
- spec-verify — list introduced fallow findings on gate failure (9ea47a5)
- context-drift-check — ignore history logs and home/env-rooted refs (cebd8d5)
- drift — attribute foreign committed deletions as foreign (42a4eca)
- spec-review-prep — a native Claude round is not the second runtime (Spec 703) (f84d29f)
- tool-registry-check — cover dshPlugins, fail on unregistered, check peer ranges (7db6761)
- offload — have the worker run the affected suites before committing (Spec 703) (adb7a5e)
- offload — scan every Run by id, delete the server branch via git (Spec 703) (82c722b)
- offload — mark the skill explicit-only for Codex (45f9c41)
- spec-review-prep — classify other specs' commits by any id spelling (Spec 013) (89e87e5)
- spec-meta — say Spec-Version is a format version, not a revision (2ef2e3b)
- spec-renumber — rename legacy specs whose title has no ID (bfe72b8)
- dev-sync — keep dev versions younger than 12h when pruning (d6a3b81)
- offload — surface a stopped worker instead of a silent ask (Spec 703) (4726aee)
- spec-validate — repair the unit test and clippy after #369 and #370 (bb653b3)
- offload — refuse a half-done result, add collect --wait (e5074f9)
- offload — search live workers across every Run, unbound (cad4090)
- offload — read every Run page before trusting no live worker (2d979e2)
- hooks — keep the main-only ADHD ruleset out of delegate runs (d7d95b7)
- spec — repoint stale step and heading references (7d1f25a)
- offload — gate cleanup and restart on the worker's Orca state (a8d020e)
- offload — stop server terminals before the cleanup HEAD check (64998ce)
- offload — close the Pi delta-review follow-ups (a75a8b0)
- offload — close the Pi and Codex review blockers (d6b533d)
- offload — start from a throwaway shell terminal (Spec 702) (dbf87a0)
- spec-validate — name the missing Review Focus part and the evidence route (6dee299)
- spec-meta — accept legacy Complexity small and large (5863047)
- offload — reuse the server review instead of reviewing twice (7ba2a1b)
- offload — close the four Spec 702 review follow-ups (e8f1654)
- delegate — end the frozen-codex repair hint with codex update (743fd6d)
- offload — accept a cherry-picked result in collect --cleanup (Spec 702) (7614b24)
- hooks — stop reading a regex
$anchor as a live expansion (352af41) - mcp — skip mirroring servers whose url or args need ${VAR} (327c760)
- spec-validate — flag German prose in a spec under strict authoring (99a59be)
- spec-validate — name the accepted shapes in verify_vacuous_at_head (9f1ebdd)
- cd-guard — say the command still ran in the stripped cd's directory (ac5bd17)
- devkit-issues — ask the maintainer only process questions (31e6cdd)
- devkit-issues — put devkit on the worktree agents' PATH (889cb11)
- delegate — return skips a symlink that points back at main's own path (d7aa849)
- delegate — host-skew names host and cli paths, skips foreign installs (381ed56)
- delegate — state pi's real MCP reach in the runtime notes (ff05af4)
- tools — run install scripts for npm bins that are placeholders (b20638f)
- spec-verify — audit only the declared TS/JS files with fallow (b2678cb)
- lint-prep — drop --diff from php-cs-fixer check; name the red gate in freeze-ready (4554f71)
- spec-validate — give per-runner ANSI advice for piped PHP tests (618c86d)
- pen-design — fit the cdp mobile-import step into its budget (ec777aa)
- hooks — stop reading a quoted heredoc word as a .env glob (fe2866c)
♻️ Refactoring
- test-runner — drop the static shell checks (1f4fef9)
- review-prep — filter go.mod, Gemfile and requirements natively (4e23e82)
- review-prep — use support::git for verify and cat-file (7b4bdc1)
- review — share the review package dir and publish steps (ad69fbd)
- scripts — one markdown fence/heading scanner (b1498b3)
- skills — drop prose the scripts already enforce (c37c810)
- review — share lens_for and sort_unique, factor dependency projections (420f2ef)
- spec — reuse shared helpers instead of private copies (6211266)
- liquid-settings — move the audit into the Shopify boilerplate (ef2aabe)
📖 Documentation
- tools — review agy 1.2.13 now that the binary is installed (5a9cde0)
- tools — record that cb has no newer release than its 0.1.0 pin (31031b6)
- tools — review shellcheck v0.9.0 to v0.11.0 (5eec5f4)
- tools — review ripgrep 14.1.0 to 15.2.0 (f6faf3f)
- tools — review pandoc 3.1.3 to 3.11 (e092590)
- tools — refresh the gitleaks review, no upstream movement (2dd3702)
- tools — review gh v2.45.0 to v2.102.0 (ec17299)
- tools — review delta 0.16.5 to 0.19.2 (9f7497e)
- tools — review claude-code 2.1.261 to 2.1.286 against the wired surfaces (fbd5cee)
- specs — add Spec-705 codegraph gate exempts running spec files (8ecdfc6)
- delegate — run the bulk script unasked (69123a6)
- accept the spec-work runner change (9d76bcd)
- workflows — accept the docs-source digest (c139e63)
- workflows — /index now repairs stale context (c8fa33b)
- stack — test-prep no longer runs static shell checks (cea2745)
- context-bundles — name the native commands, not retired .sh scripts (1cf4788)
- context — rotate oversized DECISIONS entries into the archive (2c65808)
- agent-browser — fold the profile note into the existing login step (55be110)
- context — drop stale shell facts and dead gotchas (6ed51d9)
- spec-work — disambiguate phases 0-3 in runner prompt (181bf04)
- agent-browser — per-project profile convention for logins (76ba6f2)
- accept the spec-work drift-rule wording (8506fd2)
- devkit-issues — fix every issue through pi in a visible Orca child (26f6078)
- agents — move test procedure and language detail out of AGENTS.md (5eb3801)
- spec-703 — re-cut to two distinct review runtimes (7b2ebd7)
- spec-703 — record the review block on three contract defects (73cc11a)
- run-cost-prep — name the --agents TSV columns in help (912411c)
- accept the spec and review pointer refactors (Spec 703) (78fd972)
- spec — add Specs 703 and 704 for the new-surface review gate (Spec 702) (3ce0815)
- conventions — say where script subcommands are registered (6f5ec68)
- ponytail — name a revisit trigger on three deferrals (a6e353c)
- optional-tools — list ponytail among the default plugins (3246553)
- accept the spec skill drift after the ponytail sentence (4bf48be)
- spec-work — say where judge evidence files belong (9bc8d9c)
- agents — make the ponytail ladder the first step of every change (a67d313)
🧪 Tests
- share-render — pin the argv of pandoc, mmdc and archify (dc82c04)
🏗️ Chores
- todo — add delegate-visible-a-report-only-implement-run-rea (4f44cd0)
- content-language — accept the archived DECISIONS German line (6243082)
- todo — park the pre-committed-surface gap of the new-surface gate (5dbb975)
- spec-703 — rustfmt the new-surface suite (80801a9)
- improve — stamp an empty friction worklist run (801aa9f)
No commit type
- Route Pi tiers to Sonnet 5.5 and repair the rpiv-todo manifest on sync (128c202)
v0.50.0 — 2026-09-30
Action required after devkit sync
- Projects that run prettier on
*.md(a.prettierignoreor prettier inpackage.json): rundevkit initonce, so prettier stops rewriting sealed specs underdevkit/. - Want kimi, codex or opencode as delegate runtimes on this host: run
devkit sync --optional, thendevkit runtime-route --inventory implementto see which runtime is ready and why not.
A small Pen fix now approves a design instead of costing a ~20-minute agent redraw (75–140 tool calls), the spec review package no longer inlines 550 KB of foreign diff for a 15 KB change, and 8 of 17 pi fanout returns that read as "missing" now land. Update with devkit sync.
146 commits since v0.49.0 · Specs 681, 698, 699, 700, 701
✨ Highlights
✏️ Fix it in Pen, name the frame, done
The owner may correct a frame directly in Pen.app, save and name its numbers ("12 and 13 adjusted") — that message approves those frames, and design-read --diff prints only the changed, added and removed nodes, so the agent implements the diff instead of redrawing (Spec 701).
node content/skills/pen-design/scripts/design-read.mjs 12 13 --diff🪶 ponytail joins every review
/review runs ponytail-review on the same diff and lists each new ponytail: marker as a follow-up with a todo offer; audit mode adds ponytail-audit. Its advice sits in its own block and never turns a clean round into PASS_WITH_FOLLOWUPS, and /todo trims its own diff with it before the commit.
/review🏃 /spec-work hands the run to a fresh runner
Main only steers now: Steps 0–3 go to a fresh agent that implements and hands back at freeze-ready, and Main runs the independent review itself. Inline is the named exception.
/spec-work 712 --in-place🔀 Parallel todos
/todo next --parallel N picks up to N ready todos whose refs and paths do not overlap, skips decision todos and hands them to one delegate-fanout run; plain /todo next stays serial.
devkit todo list --ready --disjoint 3🧾 Spec freeze stops blocking on work that is not the spec's
freeze-ready no longer goes red on devkit sync output, generated agent state, a commit that landed after the start outside the spec's scope, a contract reopened by /spec-update, or a Progress Log line quoting a verify; spec-verify step results now count. The frozen review package names out-of-scope paths instead of inlining them (550 KB → scope of a 15 KB change) and separates prior spec commits.
devkit spec-work-run <ID> freeze-ready🤝 Delegate returns land what the child did
Eight of seventeen pi fanout children on 2026-09-30 printed a complete handoff that read as missing; fanout now reads pi's real shapes and prints each child's full block. Staged deletions land, additive edits to a file another child just landed 3-way merge, an empty implement run stops with DELEGATE_RETURN_EMPTY, and --commit takes the subject from the brief's first line.
devkit delegate-fanout pi implement --commit --brief a.md --brief b.md🧰 Runtimes install on every host
kimi installs pinned (2.1.1) through a sha256-checked vendor script, codex and opencode install on Linux through npm, devkit sync writes pi's mcp-adapter.json so interactive pi gets the MCPs, and runtime-route plus devkit doctor --target pi name the failed pi readiness check and its fix.
devkit sync --optional && devkit runtime-route --inventory implement🧹 Idle sessions and dead worktrees
worktree-gc --sessions lists idle Orca agent terminals as safe/ask/keep and closes only the safe ones with --apply; SessionStart names the counts once a day. Measured cause: 13 claude sessions idle for days ran a Mac out of swap, a Linux host kept 6.3 GB of dead delegate worktrees (Spec 698).
devkit worktree-gc --sessions --apply🛍️ Liquid settings audit
devkit liquid-settings reads schemas, templates, section groups and settings_data.json and prints one JSONL row per option occurrence; --unused names default-only options and dead section and block types. The Liquid graph and component inventory now hold one record per line, so rg returns whole records (Specs 699, 700).
devkit liquid-settings --unused🛡️ Guards that block less of the right thing
A cat of a 14-line file passes the codegraph gate like a small Read, an env-file name inside a commit message is data, the doctor's own chmod 600 .env passes the secret guard, macOS gets a timeout form the wait guard accepts, and subagents are exempt from the background-wait guard.
chmod 600 .envWhat changed for you
Now available
- pen-design pins
@pen.dev/cli0.3.10 (.penformat 2.20) and triescdpviewport emulation for the 390 px mobile import before a manual window resize. Rundevkit sync --optionalwhere you design; re-save an older canvas once throughpen interactiveiftool-pin-auditflags it. - pen-design has a Next.js + shadcn/ui adapter next to the existing stack adapters.
design-sheet-fillimports Lucide-style icons (<circle>,<line>, stroked<g>) and names the rule behind everyUNSUPPORTEDrow.--from-templatemarks each starter componentTemplate: ersetzen, anddesign-statuslists the ones still left.design-sort --renumbernumbers more than eight row groups instead of aborting.- Strict spec validation lints inline
php -randnode -everify bodies at authoring, without running them.
Behavior changed
- Every Codex and Pi GPT seat, Prime implement and the Codex escalation route to
gpt-6.1-sol/medium; Prime falls through to the next runtime until it lists the model. - Confidential projects start a preview only on fixture or synthetic data; a screenshot had sent real spreadsheet data to the model.
lint-preprunsphp-cs-fixer check --diff, since PHP CS Fixer 3.95 rejectsfix --dry-runand failed the gate on every PHP project./fetch-taskwrites a brief from the digest and asks once: direct or spec, with/spec-updatewhen a spec already carries the task.git stashis forbidden in the core git rule every agent reads; its stack crosses worktrees.- The review package drops Definition-of-Done bullets for stacks the diff does not touch, and the reviewer's verdict words map to
spec-finishverdicts. design-checkcounts declaredVariant:frames once in B2, ignores rows of component instances, and no longer truncates piped--jsonreports.- A leftover
@storyblok/nuxtdependency no longer marks a plain Nuxt project as nuxt-storyblok; the module innuxt.configis required. devkit initno longer reports skill category folders as broken skills (29 false warnings across two vaults), and the doctor skips env files and codegraph indexes another account owns.- The doctor names an older
devkitearlier onPATHas the cause of a version skew. - A delegate killed by its time bound prints
DELEGATE_TIMEOUTand the review namesREVIEW_DISPATCH_TIMEOUTinstead of an empty answer.
🚀 Features
- pen-design — try cdp viewport emulation for mobile imports (d56c050)
- tools — pin @pen.dev/cli 0.3.10 (0866355)
- mcp — write pi's mcp-adapter.json so interactive pi gets the MCPs (fe76fba)
- tools — install kimi through a pinned vendor script (56a13df)
- tools — roll out codex, opencode and runtime hints on every host (775f4aa)
- pen-design — add a Next.js + shadcn/ui adapter (26c01cd)
runtime-routeanddevkit doctor --target pinow name the failed pi readiness check and its fix (cdc7de0)- B2 no longer flags rows of component instances, and B4 no longer matches frames on a coarse type fingerprint (5c29273)
- session-foreign untracked files are no longer inlined, and markdown lines no longer show up as removed symbols (ba9653a)
- #326 and #333 are fixed, and #329 was already fixed in HEAD (f37b3ee)
- pen-design — owner edits in Pen approve, design-read --diff shows them (Spec 701) (8b5a13a)
- spec — lint php -r and node -e verify bodies at authoring (4a24d18)
- review — drop DoD bullets of stacks the diff does not touch (ea26669)
- pen-design — count declared variant frames once in B2 (6366928)
- pen-design — mark starter components and list the leftovers (2f94a4d)
- pen-design — import Lucide-style shapes in sheet-fill (0c87c30)
- liquid — add liquid-settings usage and unused query (Spec 699) (8b9bc3c)
- worktree-gc — add session inventory and daily hygiene hint (Spec 698) (b6b4f95)
- index — write one record per line in Liquid graph and inventory (Spec 700) (2dacda9)
- fetch-task — route the fetched task on instead of suggesting /spec (3a2a91a)
- spec-work — hand every run to a fresh runner by default (dba77e9)
- todo — /todo next --parallel N over delegate-fanout (5c32842)
- pen-design — number more than eight row groups (54c93c7)
- todo — trim a todo's diff with ponytail-review before finish (53eecfd)
- review — feed ponytail-audit and ponytail: markers into /review (87776e9)
- review — run ponytail-review alongside every diff review (1d98e1e)
🐛 Fixes
- npm — unwrap npm 12's one-element array from view --json (ffb4986)
- ci-cleanroom — drop the global git identity CI does not have (324c101)
- doctor — don't call a foreign-owned codegraph index damaged (c8a047e)
- doctor — don't call a foreign-owned codegraph index damaged (337cf55)
- init — name why the legacy removal was blocked (b7dc098)
- init — treat a skill category folder as intact (93babf9)
- sync — build the dev worktree at a fixed path with its own target (9ade28e)
- doctor — report a lagging dev build as a note (8b70204)
- pen-design — survive imported .pen libraries in the scripts (bcadb45)
- doctor — skip env files another account owns (59417b3)
- delegate — end a final-message handoff at its open list (920d331)
- hooks — let a lone chmod on an env file pass the secret guard (b92ed1b)
- delegate-fanout — take the commit subject from the brief (eafc221)
- sync — build a dirty maintainer checkout's HEAD from a worktree (e707ed5)
- spec — keep the template within its token budget (7a4c488)
- doctor — detect skew by a shadowing devkit on PATH (40a7a1f)
- delegate — accept finding lines under open: in a handoff (87b1deb)
- doctor — stop steering a maintainer checkout off dev mode (dbdc9fa)
- pen-design — keep the owner-edit example phrase in English (f66c2af)
- hooks — give macOS a timeout form the wait guard can pass (5409804)
- review — separate prior spec commits from the reviewed diff (7018dc1)
- spec-work — keep the start baseline across a contract reopen (7f22bb0)
- rules — preview confidential projects on fixture data only (e39aefb)
- spec-work — let review-memory ingest record a native review round (6927f7a)
- spec-work — keep devkit sync output out of spec drift (0fb357f)
- pen-design — name why sheet-fill rejects an icon (a1836f8)
- pen-design — record --icons Source on an existing icons sheet (16d717a)
- review — list foreign paths by name and bind nested-repo files (b56d464)
- delegate-return — compare against the mirror base, not HEAD (515697a)
- spec — read verify commands only from Step and AC rows (400f622)
- spec-work — let freeze-ready accept spec-verify step results (897a033)
- lint-prep — run php-cs-fixer check instead of fix --dry-run (7861e74)
- review — map the reviewer verdict words to spec-finish verdicts (61fdb30)
- spec-work — keep review-verdicts rule anchors after the delta fix (887d5ab)
- spec-work — name both paths a delta review dispatch takes (Spec 698) (ba3f323)
- fetch-task — drop the todo route from the hand-off (632bcfb)
- spec-work — count commits after start outside scope as foreign (bfb6ac2)
- delegate — print the full handoff block per fanout child (1c9ab8f)
- review — collapse the nested entry split for clippy (7346202)
- rules — fit the git stash rule into the always-on budget (e171c83)
- hooks — treat an env-file name in a commit message as data (0c90abd)
- hooks — let small Bash reads past the codegraph gate (7f0e02c)
- design-inventory — rebuild before rendering design tables (a0f8e30)
- delegate — keep the fallback Orca log and name pi write roots (2158ebc)
- runtime-route — name why pi implement is not ready (44b505b)
- review — fill PROJECT CONTEXT from numbered and path gotchas (2f47942)
- spec-work — keep generated agent state out of spec drift (c2b6049)
- pen-design — prove variable-count grids at every count (ad64423)
- rules — forbid git stash in core git hygiene (d50c712)
- sync — route dev-build homes on a devkit checkout to dev-sync (e213b2f)
- delegate — read pi's real handoff shapes, name the pi sandbox root (6162a45)
- review — name dispatch timeouts and stop citation bleed (f44f388)
- spec-reconcile — accept root-level files from Files to Modify (ed1ca10)
- delegate-return — land deletions, merge additive edits, flag empty (063c3e6)
- hooks — exempt subagents from the background-wait guard (964457e)
- detect-stack — need the Storyblok module, not only the dependency (6d7d854)
- pen-design — stop truncating piped --json reports (1afc07f)
- review — keep ponytail advice outside the review verdict (cb14e2c)
- init — keep prettier off the devkit/ directory (4256a27)
♻️ Refactoring
- last dead item and temp-name helper copies (e3ca629)
- drop release-cleanroom, date shell-outs and dead wrappers (63b2ed9)
- scripts — drop SpecLayout and last identical helpers (2c68043)
- spec — one Files-to-Modify parser and one spec resolver (5ef81bb)
- scripts — share last identical json, text and git helpers (5fe25b4)
- maint — drop legacy .sh aliases and unset env overrides (f45d0a9)
- maint — compile shared maint helpers once, drop dead entries (1c348fb)
- scripts — merge identical helper copies into support (6de4c19)
- drop blanket dead_code allows and delete what they hid (678af6a)
- scripts — share cmdsub and is_regular_file via support::fs (c1f4b0c)
- scripts — share duplicated spec helpers via spec_meta (0bd5922)
📖 Documentation
- reference — decision rows for Specs 698, 699, 700, 701 (f897907)
- harnesses — keep the German page under the prose limit (2ea25a9)
- design — accept the pen-design import and adapter changes (3cf12b6)
- workflows — accept the delegate-fanout commit-subject change (0cc34ad)
- design — name owner edits and design-read --diff on the page (c0f179d)
- spec — add spec 701 owner edits in Pen as approval (cbaf96a)
- accept the specs page digest after the spec-work fixes (b340767)
- accept the design page digest after the pen-design fixes (14fc5df)
- design — fit the icons sheet row into the prose limit (5672be0)
- accept docs-source digests after the issue fixes (23aa481)
- spec — add specs 699 and 700 for Liquid audit artifacts (8d9172c)
- spec — add spec 698 worktree and session hygiene (fd9a08a)
- install — name OpenSSL 3 as the first-install trust anchor (5702e77)
- re-set docs-source markers after the fix wave (3503e48)
🧪 Tests
- delegate-return — give the fixture repo its own git identity (7754f3e)
- pi — give the doctor --target pi test a fake pi and no sandbox (2984a1e)
- delegate — retry the bridge exec on ETXTBSY (e978cfe)
- one env-cleared git helper for the skills-pull tests (3d32cef)
- share spec-reconcile and git helpers via parity::support (36cd562)
🏗️ Chores
- todo — narrow project leftovers to the onedot-os vault (7e646de)
- todo — add projekt-reste-nach-devkit-init-dangling-skills-o (6b147ef)
- todo — complete devkit-issues-326-342 (279b0df)
- fanout codegraph (116a554)
- fanout secretguard (2cea247)
- fanout todo (665debd)
- fanout commitprep (60c251f)
- fanout authoring (55e9655)
- fanout skew (6f78822)
- todo — add devkit-issues-326-342-17-issues-from-2026-09-30 (7a18c6a)
- todo — add spec-finish-completed-spec-701-although-freeze-r (f122f48)
- todo — add design-read-diff-follow-ups-spec-701-review-diff (33e11e3)
- todo — add flaky-unit-tests-under-parallel-load-session-sta (309f3bc)
- todo — add spec-699-follow-up-liquid-bodies-keep-and-commen (f43e247)
- todo — add spec-700-follow-ups-design-inventory-test-for-em (a3bc96c)
- todo — add worktree-gc-help-row-lacks-sessions-main-rs-208 (54ad7ad)
- todo — close delegate-fanout todo, fixed in 063c3e6e and 6162a458 (1a005b7)
- todo — record 2026-09-30 decisions on three parked todos (c779087)
- todo — close cost-transparency todo as obsolete (e1a25ac)
- todo — close four stale todos after maintainer decision (Spec 681) (e557991)
- todo — close five todos already done on main (41019c8)
- todo — record lost deletions and empty pi returns (17748f2)
- todo — note recurring read-only pi fanout child (487ad9f)
- todo — add delegate-fanout-3-way-merge-additive-returns-ins (b764b3e)
- devkit — restore audit, research, brainstorm and evaluation evidence (8105476)
- delete uncalled maint commands and dead test scaffolding (63b815c)
- devkit — drop committed artifacts nothing reads (dba32cb)
No commit type
- Switch routing to gpt-6.1-sol/medium across all GPT seats (ce3d46a)
v0.49.0 — 2026-09-29
Action required after devkit sync
- Shopify projects whose hooks call
devkit path skill stack-shopify-liquid: rundevkit skills pullonce so the name resolves tosp-theme-scripts. - A spec already in progress keeps the old merge-base default for drift checks; pass its start commit explicitly:
devkit spec-drift-check <id> <start-sha>.
Spec drift checks now diff against the commit a spec started from, claude-only hosts get a review route instead of NO_ROUTE, and lite specs stop after one review round. Update with devkit sync.
27 commits since v0.48.0 · Specs 677, 696
✨ Highlights
🎯 Drift checks measure the spec, not the branch history
spec-drift-check and freeze-ready default to the HEAD recorded at spec-work-prep --start, so a branch cut from another base or carrying earlier pushed work no longer floods the check with unrelated files; an explicit base ref is honoured, and edits claimed by a parallel session count as foreign.
devkit spec-drift-check <id> <base-ref>🧭 Review route on claude-only hosts
With no codex, kimi or dsh installed, the review tier resolves to claude marked as a same-harness stand-in instead of failing with a friction signal; a required independent review still reports not_reviewed.
devkit runtime-route review # RUNTIME=claude RUNTIME_FALLBACK=claude:same-harness🔁 Lite review path enforced
A spec at Effort and Risk low or medium gets one review round: after a round with only non-security, non-data-loss, non-AC findings, a new dispatch is refused instead of starting another fix loop.
REVIEW_LITE_PATH_CLOSED🎨 pen-design folds approved drafts into their masters
After approval the draft frame moves into its master frame or component and is deleted; design:marker flags a draft that outlives its shipped master, so the canvas stays the source of truth.
node content/skills/pen-design/scripts/design-marker-check.mjs🛍️ Shopify projects resolve stack-shopify-liquid again
The old skill name resolves to the pulled sp-theme-scripts, a missing replacement points at devkit skills pull, and a clone without access to the private boilerplate says so instead of failing silently.
devkit skills pull --checkWhat changed for you
Now available
devkit spec-finish <id> --phases prep=3m,implement=12mrecords where a spec's time went in its COMPLETED line.devkit token-audit --project <slug>now also scopes the prune savings to that project./researchoffers an optional evaluation receipt that records what the run compared against local coverage.
Behavior changed
- A judgement-only acceptance criterion no longer aborts
spec-work-run check --phase acceptance; it defers to review and the phase exits 3. spec-work-prep --startprintsREFUSE=readiness_unresolvedwhen unresolved paths block a start, instead of a silent exit 2.- Every
not_reviewedfromdevkit review-quicknamesREASON_CLASSand aDIAGNOSTICSlog path; a used-up quota is named as such. devkit quality-gatefails on an#[ignore]a changed Rust test file adds.- Post-edit lint also checks files a Bash command wrote (
sed -i, heredoc,cat >), not only shell scripts. - Spec validation ignores citation-shaped text in Progress and Review Log and reports a vacuous half of a chained verify.
- File claims from a backgrounded delegate are recorded for the real session, so review fingerprints no longer mix sessions.
devkit syncno longer reports a fresh pen install as a PATH shadow of itself;devkit doctorskips an MCP whose tool is absent./boilerplate-feedbackis named next to/friction-feedback, so reusable client changes reach it without an explicit call.devkit delegate-fanout --committakes each commit subject from the delegate's HANDOFF summary instead of a generic line.devkit design-tidy --imageslists every image it keeps asKEEP design/<file>.devkit index-prepnames the file and OS error when it cannot write AGENTS.md or the index manifest, instead of exiting 1 silently.
🚀 Features
- quality-gate — fail on a newly added #[ignore] (7600b1f)
- delegate-fanout — commit subject from the handoff (1e017e7)
- token-audit — scope prune ledger to --project (7a12e07)
- spec-finish — record phase times in the COMPLETED line (c7eda0c)
- review-runtime — enforce the lite review path (473e778)
- pen-design — consolidate approved drafts into masters (7500648)
🐛 Fixes
- index-prep — name why the AGENTS.md block write failed (be3e9ef)
- design-tidy — close the Spec 696 image follow-ups (740c638)
- spec-validate — skip log sections, report vacuous chain halves (8d1c9f0)
- post-tool — session identity and lint for Bash edits (1cc38bd)
- runtime-route — same-harness review fallback on claude hosts (2c667f3)
- spec-work-run — defer judgement-only ACs to review (5bbe997)
- skills — resolve replaced skills and name access failures (45ecc68)
- spec-work-prep — print REFUSE= on unresolved readiness (08af7e8)
- spec-drift-check — honor base-ref and foreign sessions (803e4db)
- review-quick — name the reason behind not_reviewed (facfaff)
- skill-lint — flag paths: on an explicitly invoked skill (1a249ef)
- rules — trigger /boilerplate-feedback outside explicit calls (fe46fd0)
- tools — probe
versionsubcommand when--versionfails (f2d6386)
📖 Documentation
- changelog — Unreleased head for the issue and todo batch (2758307)
- accept drift markers after the issue and todo batch (8b1b840)
- site — English labels on generated skill pages (5b3d6a0)
- specs — point specs README at specs-and-todos (4ca7dc1)
- research — optional evaluation receipt (e054121)
🧪 Tests
- statusline — render-level todo and plan-line tests (129782f)
🏗️ Chores
- todo — add delegate-return-counts-the-mirror-commit-as-dele (4f5aa72)
- todo — close six todos already done on main (Spec 677) (56e46a4)
v0.48.0 — 2026-09-29
Pi receives shared skills without Codex, Pen imports that left 121 MB of PNGs shrink to WebP, and review batches no longer send 24–42 sequential file-by-file calls. devkit sync and devkit doctor now repair shadowing tools and offer their own fixes. Update with devkit sync.
154 commits since v0.47.0 · Specs 685, 688, 689, 691, 692, 693, 694, 695, 696, 697
✨ Highlights
🧭 Pi gets shared skills without Codex
A Pi-only setup now installs the shared od- skills; Pi /spec-work can prepare its own implementation route. Previously those skills were installed only when Codex was enabled.
devkit config pi on
devkit apply📋 Worktree plans stay visible across sessions
devkit todo plan stores steps per worktree across runtimes and compaction. The statusline shows progress, the active step and ready todos; park unfinished steps as todos instead of losing them.
devkit todo plan add "Write changelog head" "Build docs"
devkit todo plan⚡ Faster implementation fallback on Sonnet 5.5
Implementation routes now prefer Pi, then Claude before Prime; on three one-shot replay tasks Pi was 2.2–5.1× faster than Prime, so treat that result as directional. Both Sonnet seats use 5.5 at medium effort, and Pi resolves the family alias on newer releases.
devkit runtime-route implement🔎 Fewer sequential review dispatches
An oversized diff previously sent one file per Codex call, producing 24–42 sequential dispatches at about 40 seconds each. review-quick now packs files under the byte cap while preserving the final scope check.
devkit review-quick --own📦 Spec work keeps run state and review blockers
spec-work-run exposes the next step, scoped brief, verification and freeze readiness in one run ledger. Its review memory keeps unresolved confirmed findings in fix-only briefs instead of restarting a full implementation.
devkit spec-work-run 688 next
devkit spec-work-run 688 brief --fix-blockers🩺 Pi setup failures become visible
devkit doctor --target pi checks the managed instructions and hook bridge against the files the bridge actually executes. Missing Pi MCP imports now surface in doctor and SessionStart rather than disappearing with hook output.
devkit doctor --target pi🧹 Browser checks close only their own tabs
/agent-browser and the design-live flow close Orca pages they opened after checking, without touching tabs you opened yourself.
/agent-browser📤 Large DSH briefs reach the delegate
A review brief above 128 KiB used to fail at process launch; briefs above 100,000 bytes now travel through a private file. A 146 KB brief was verified live.
/delegate dsh review🖼️ Pen imports shrink to WebP
A Pen browser import saved every image as a full-size PNG; one run left 121 MB. design-tidy --images lists the images to shrink and the orphans; --write converts each referenced raster to WebP at twice its drawn width and deletes orphans, refusing while Pen.app holds the canvas open.
devkit design-tidy --images --write🎨 Pen design checks catch import residue and cost fewer tokens
design-check now names what a live import leaves behind: frozen marquees, invisible text strokes and unnamed icons. The active-editor check is a one-line probe instead of a ~3k-token component list on every call, measured at 36 calls in one import run.
/pen-design🔧 Sync and doctor fix what they find
A foreign binary shadowing a pinned tool no longer aborts devkit sync with a manual which -a step: a stale brew copy is unlinked, any other shadow is offered a reversible rename. devkit doctor offers each fix it names instead of leaving you to copy it.
devkit doctor🌊 Wave workers survive a cold Codex start
Slice dispatch gave the agent 3 seconds to become ready, so a cold Codex start failed with reason=timeout while it was still loading. The readiness window is now 120 seconds, and a timeout prints the recovery commands.
export DEVKIT_WAVE_READY_TIMEOUT_MS=180000🧾 Spec runs keep an independent review
The default /spec-work runner is a subagent without an Agent tool, so it reviewed its own Risk:medium diff. It now stops at freeze-ready and Main runs the independent review; freeze-ready also accepts judgement criteria and names the stale check that blocks it.
/spec-work 697What changed for you
Now available
- In Pi-only installs, use
/od-spec-workafterdevkit config pi onanddevkit apply; Codex no longer has to be enabled for shared skills. - Run
devkit todo planto see your worktree's current steps across sessions, ordevkit todo plan parkto save unfinished ones as todos. - Run
devkit doctor --target pito inspect Pi's managed instructions and hook bridge. - Pass
--helpin any position: 46devkitcommands answered78 --helpwith a usage error and a friction code.
Behavior changed
/delegate implementwithout a spec and the default implementation route now lead with Pi; Claude precedes Prime as fallback./spec-workreads the live Claude permission mode before resolving convenience choices; STOP and destructive-action gates still apply./agent-browsercloses only the Orca tabs its checks created.devkit initignores Pi goal-state files in target projects instead of showing them as untracked./pen-designpaginates design checks that exceed the 64 KB CLI output cap instead of losing their findings./review --quickincludes diff-review evidence and reports a reviewer's refusal reason instead of onlynot-reviewed.- The prompt hook ignores friction codes printed by failing Rust test fixtures, so it does not ask you to file an unrelated issue.
devkit quality-gateprintsTESTS_NOT_RUNon a green run; rundevkit test-prep --affected-onlyfor the suites your diff affects.- The SessionStart index hint no longer asks for
/indexon every indexed project;index-prep --reportcounts only markers Fill can clear. - A retried
spec-finishno longer appends a second identicalREVIEWEDreceipt, andspec-sealno longer crashes on an em dash after a verify command. - The secret-env guard no longer blocks commands whose quoted text contains escaped backticks, and it still blocks a real substitution behind an escaped backslash.
- Always-on rules find their reference companions through
devkit path ruleon Codex, OpenCode and Pi, not only under~/.claude. index-prepnames the path and error when the manifest write fails instead of exiting 1 silently.
🚀 Features
- doctor — offer the named fixes and classify legacy context7 entries (1661387)
- tools — offer to move a foreign binary that shadows a tool (3a4a2a1)
- design-tidy — Spec-696 shrink import images to WebP, clear orphans (84e1588)
- pen-design — Spec-695 report live-import residue in design-check (2a27425)
- pi — materialize od-skills for Pi without Codex (f3b5bfb)
- spec-work-prep — accept --runtime pi (8ea5046)
- routing — claude ahead of prime in the default implement rule (224c3ea)
- todo — show plan and backlog in statusline and list (Spec-694) (Spec 693) (8e77ba9)
- todo — add worktree plan shared across sessions (Spec-693) (e504fe8)
- print affected suites in spec-route-prep (Spec 692) (567b4c1)
- add brief-gate --check for spec-work briefs (Spec 691) (4f0ac3b)
- add review-memory to spec-work-run (Spec 689) (4a4bb8d)
- tool-review — delta for sha pins and vanished release refs (d8bb25f)
- tool-pin-audit — audit piPlugins against npm (3e0a8ea)
- routing — run the second Claude escalation on Opus 5.5 at max (078b41b)
- routing — let pi route by Claude family alias (cd153d0)
- routing — move Sonnet tiers to Sonnet 5.5 at medium effort (66be041)
- add spec-work run helper (Spec 688) (12ceb4d)
- pi — add doctor target (206ccc0)
🐛 Fixes
- spec-work — default runner hands back before the review (f3e80ca)
- spec-finish — do not append a receipt that is already the last one (451be50)
- spec-validate-prep — no panic on multibyte text after a verify command (b937aab)
- cli — accept --help anywhere in the argument list (c58fb60)
- todo — plan park skips items a failed run already parked (8e5f684)
- ci-cleanroom — test the committed HEAD by default (a4aca1d)
- quality-gate — say on a green run that no tests ran (e320a03)
- index-prep — name why the manifest write failed (1bfb75d)
- design-tidy — never delete an image behind a percent-encoded url (02311e7)
- spec-work-run — name the criterion behind a verification block (Spec 696) (d3513b3)
- tools — unlink a stale brew copy that shadows a pinned install (e78b88e)
- spec-work-run — let freeze-ready accept a judgement criterion (Spec 695) (029a2e1)
- pen-design — state how execute routes filePath, tighten the probe (589daf9)
- design-tidy — refuse an open canvas before printing the plan (fd34249)
- pen-design — insert no group label during an --ids apply (9d620b1)
- spec — accept a symlinked absolute candidate run dir on cleanup (6123e17)
- hooks — pair backslash escapes before judging a quoted span live (90c1b2f)
- hooks — treat escaped backticks in double quotes as prose (1c0ef0b)
- wave — match a leftover worktree through its resolved path (b466818)
- pen-design — break text-size ties in rebind by line-height, weight and viewport (a95bf7d)
- pen-design — wrap the system row at 10000 px on every canvas (4d0b1d4)
- pen-design — wrap a new system frame at the system row's wrap width (56c1193)
- hooks — name the bounded wait when the second sleep-poll is blocked (543a049)
- pen-design — confirm the active editor with a one-line probe (c397ef5)
- design-seed — make the seeded canvas pass the commit-prep secret scan (4a1755c)
- design-tidy — refuse --write while Pen.app holds the .pen in front (11657d9)
- pen-design — reset omitted instance properties to their default in rebind promote (6efc2d8)
- pen-design — never hand a freed number to a new frame (7b98da8)
- pen-design — place a new column frame below its group's last unit (f55825f)
- pen-design — place a new row frame beside the frames that stay (5e9bc1b)
- wave — give worker-start a real agent-readiness window and name the recovery (0c9886c)
- index — count only coverage markers the Fill step can clear (c97f044)
- rules — resolve rule companions through devkit path rule (0346940)
- issues-prep — quote the --show jq filter (e582eea)
- pen-design — page design-check output past the 64 KB CLI cap (e272a27)
- spec — shorten cargo filter rule to fit the template budget (bfa0d3f)
- spec-finish — say where DECLINED-RULING lines must sit (3dd4da8)
- brief-gate — let --check honor --override (dc60a77)
- agent-browser — close Orca tabs the agent opened (148cee2)
- satisfy clippy in tool_review rust_segments (3ecfb14)
- model-benchmark-pull — name routed models Epoch has not measured (6677e4c)
- runtime-route — read prime's model list from stderr (76d4a4f)
- routing — lead the spec-less implement route with pi (3228276)
- todo — name the worktree route when claim refuses a dirty tree (1640d27)
- tools — hold dsh at 0.1.5-rc.3 until memsearch#763 is fixed (0ddd728)
- delegate — hand a dsh brief above the argv limit over as a file (b3bfa79)
- skills — read /spec-work auto mode from the live permission mode (bc824fe)
- mcp — surface missing Pi MCPs in doctor and SessionStart (37028c1)
- hooks — ignore OD_FRICTION codes inside cargo test output (8c83255)
- tool-review — match name-prefixed surfaces in every consumer kind (475b6b4)
- tool-review — read Rust and JSON consumers through string literals (ca1f6af)
- mcp — name the exact Pi import instead of pi-mcp-adapter init (5a0a83b)
- agent-state — gitignore Pi goal state in target projects (0fd395d)
- codegraph-gate — a $(grep -n …),+N sed window is targeted (fe85f3d)
- mcp — read pi-mcp-adapter 3.x config from mcp-adapter.json (90fa266)
- orca-detect — read a sandbox-denied status answer as blocked socket (1ca4662)
- tool-review — drop punctuation and comment lines from surfaces (6c2a200)
- spec-candidate-dir — cleanup accepts an absolutized run path (e1cceb9)
- maint — drop pre-5.5 and GPT-5.6 model defaults from maint tools (bec7749)
- tools — review record for pi-goal-x, registry check reads piPlugins (e6641a6)
- spec-work — keep Goal/Out of Scope reads, spec-verify needs --phase (31cdeae)
- doctor — Pi bridge check mirrors what the bridge executes (4be6cf5)
- friction — maintainer repo parks todos instead of filing issues (5dcb218)
- skills — stop devkit-claude-changelog from triggering ultrathink (b39ccf5)
- spec-checks — same-day identical AC-EVIDENCE is not appended twice (Spec 688) (3ef4c1b)
- review-quick — brief carries ACs/manifest, refusals name the cause (835e76d)
- skills — treat an unconfigured interactive session as auto mode (0755f2f)
- docs — say AGENTS.md reaches Claude Code via the CLAUDE.md import (ca0dad6)
- retain dsh fanout logs on failure (Spec 688) (b9b3a0c)
- test — retry transient busy executable launch (1e58276)
- release — publish approved GitHub page through native gate (46234b9)
⚡ Performance
- review-quick — pack codex batches greedily under the byte cap (292a7a0)
📖 Documentation
- reference — decision rows for Specs 695, 696 (db96760)
- specs-and-todos — accept markers after the spec-work runner fix (cd4da28)
- specs-and-todos — accept marker after the plan-park fix (ca6965a)
- accept design page drift after design-tidy --images (74b59c0)
- spec — Spec-696 shrink Pen import images to WebP, clear orphans (a4c6ad7)
- accept drift markers after the issue fixes (ca8e44c)
- reference — decision rows for Specs 688 689 691 693 694 (ca1bef8)
- adapters — align Pi skill guidance in German (6843380)
- describe the worktree plan in specs and todos (3af5145)
- spec — cargo test filters name the function, not the module path (Spec 685) (9db1452)
- audit — implement route benchmark, pi vs prime vs claude (5873e64)
- spec — owner-scoped plan, JSON status and progress bar (693, 694) (96413f1)
- spec — plan worktree todo plan and its visibility (693, 694) (cab3531)
- audit — record published harness benchmarks (ae2f2f2)
- delegate — cite the V4.1 Flash Pi/DSH comparison (e07664b)
- tools-changelog — probe the consumer route twice (c7646e7)
- tools — record the adoption checks for jscpd, fallow and orca (2ec76c2)
- tools-changelog — install order, shared-checkout rules, release handoff (69ea898)
- spec — fold 690 into 692 as the /spec wording step (e4f87ee)
- spec — 691 builds on spec-work-run brief via brief-gate --check (Spec 688) (488364e)
- spec — 690 shrinks to /spec wording over route-prep output (1003d3a)
- spec — 692 route-prep owns path-to-suites, drop affected-explain (c78e91e)
🧪 Tests
- sync — cover the ponytail always-on opt-out transition (e0cbfda)
- init — assert the legacy-setup restore under root too (df2b891)
- pen-design — end the design-check stub output with ROWS_END (5519ebf)
- follow Spec 695/696 changes that CI turned red (Spec 696) (fc32be8)
- design-guard — cover the two design-tidy --images forms (120cd68)
- skills — follow the reworded pen-design lines in the moved fixture (8adf519)
- make five suites pass on macOS (252ae5f)
- delegate-fanout — edit the fixture with portable sed (bb4baa2)
- run true from /usr/bin, which macOS still ships (e733c73)
- pen-design — end the design-check pen stub with ROWS_END (7f3b5c0)
- session-start — expect only fillable markers in the index hint (ccc8011)
- refs — accept rule companions under rules/references (2b4c29c)
- own suites for spec-lifecycle scripts, gate unmapped scripts (5b824bf)
🏗️ Chores
- todo — close the rust-toolchain pin todo (2083e45)
- pin Rust 1.98.1 and fmt-check the devkit crate in CI (53400cb)
- todo — close six pre-release todos and one stale one (ed75bc9)
- todo — add pin-the-rust-toolchain-so-local-rustfmt-matches (53cc737)
- todo — add run-the-k2b-design-check-test-against-the-real-p (dbab143)
- todo — add design-tidy-images-close-the-spec-696-review-fol (1c56390)
- todo — add find-why-spec-finish-learning-capture-exits-1 (9d8c496)
- tests — rustfmt the runtime-inventory skip assertions (ed8005a)
- tests — drop a needless borrow clippy denies (b1d7058)
- tests — rustfmt runtime_inventory (4838526)
- format four integration tests (c5b4847)
- todo — add render-level-tests-for-statusline-todo-segment-a (c22565b)
- todo — park prime-run turn-stream gap (fd6c375)
- format brief_gate_check test (be6f570)
- todo — add todo-plan-park-two-phase-commit-and-plan-removal (fb2db17)
- todo — add spec-verify-drift-gate-counts-parallel-sessions (1a35bef)
- format pi_delegate test (b72b9ce)
- todo — add delegate-fanout-commit-derive-the-commit-message (1345b49)
- todo — add dsh-delegate-stdin-brief-and-json-event-capture (7b95994)
- tools — bump pins after changelog review (184cfe8)
- todo — add friction-counter-counts-od-friction-lines-from-t (37f08ef)
- todo — add spec-work-auto-mode-detection-ignores-a-permissi (34c85c9)
- todo — add review-quick-long-batched-codex-review-invalidat (fe2a6c9)
- ledger — resolve sonnet-5-5-model to 66be0418 (a334ad8)
- git — ignore the claude-changelog stamp lock file (22f2390)
- ledger — record Claude Code 2.1.281-2.1.284 verdicts (4661f1c)
No commit type
v0.47.0 — 2026-09-28
Action required after devkit sync
- Run
/indexin projects that show the setup hint; accept its step-0 offer to rundevkit initand remove verified legacy setup files.
The setup hint now reaches 17 of 19 previously missed projects, browser checks shrink about 12 manual calls to two, and review and delegate work gains one-call paths. Update with devkit sync.
352 commits since v0.46.0 · Specs 334, 560, 570, 616, 652, 663, 664, 665, 666, 667, 668, 669, 670, 671, 672, 673, 674, 675, 676, 677, 678, 679, 680, 681, 682, 683, 684, 685, 686, 687
Breaking Changes
/backlogis renamed to/todo, the one todo skill (c4d9eba) Migration: type/todo <text>to park a todo and/todoto list or work them; "backlog" still routes there.
✨ Highlights
📋 Untracked open work becomes a todo automatically
Offering open work as a todo used to depend on the agent remembering; every closing question now offers it, and around 30 tool calls or after a compaction the session checks devkit todo list and parks the untracked remainder unasked. PreCompact names the resume step first, under its own Untracked Open Work section.
devkit todo list
/todo <text> # parks a todo in one line
/todo # resumes parked work in a new session⏱️ Auto-compact override retired, Bash backgrounds later
A fixed override blocked /autocompact and let sessions run to ~767k context, where calls above 200k already carried 71% of input tokens; devkit sync now withdraws it. Bash now backgrounds a command after 120s instead of 30s — at 30s, 785 commands backgrounded in three days, each costing an extra full-context turn.
devkit sync
# withdraws CLAUDE_CODE_AUTO_COMPACT_WINDOW, /autocompact takes over🌙 A cold prompt-cache rewrite gets named before it costs you
The prompt cache expires after a pause over an hour, and the next prompt re-writes the whole context — 35% of all cache-write tokens (17.4M) over 200 sessions were lost to this. The hint now names the rewritten count against its TTL (300s or 3600s), so the next break starts with /clear or /compact.
# UserPromptSubmit after a >1h pause:
# HINT_COLD_CACHE rewrite=482000 tokens ttl=3600s📬 Subagents return a handoff, not a report
Subagent reports were the largest return sink measured — 401 in 14 days, median 3295 characters, 83% over 1200, reviews alone 44% of the volume. Every native subagent, delegate and wave slice now gets the handoff contract on dispatch and answers in the compact form: one line per finding, no PASS lines.
HANDOFF status: done — <one sentence>
changed: <path:line> - <what> · open: <none or blocker>🔀 Wave and Delegate share one runtime-selection path
Wave's slice-dispatch/-retry picked a runtime/model through helpers knowing only claude/codex, skipping runtime-route's preference, readiness and usage-limit checks; a retry defaulted to codex regardless. Slices now resolve through the same path /delegate uses; --runtime <name> overrides any registry runtime.
runtime-route --in-place --runtime <name>📣 Every dispatched agent reports friction, not just success
A blocker hint used to reach only the transcript UI, never the agent acting on it. The hint now lands in the model's own context, and every dispatched agent (Wave slice, Delegate, Prime) ends its report with a DEVKIT-FEEDBACK block or reports its own friction signal immediately, instead of staying silent until asked.
DEVKIT-FEEDBACK
- <script/skill/gate/rule> — <what it did wrong> — <path:line>📊 devkit token-audit + /token-check — see where your tokens go
devkit token-audit reads your own transcripts — cost, context buckets, startup breakdown, per project — with no prompt or tool content leaving your machine; apply sets skillOverrides/enabledPlugins/deniedMcpServers/disableClaudeAiConnectors directly. /token-check ranks the sinks, applies only the levers you pick.
devkit token-audit --days 14
devkit token-audit apply enabledPlugins ponytail🧹 devkit-prune — local compaction instead of a lossy summary
Crossing 200k context now prunes stale tool output through a local engine instead of a summary, opt-in via CLAUDE_CODE_ENABLE_FUNCTION_HOOKS. It cuts every result older than the newest 6 messages to a 300-char head, skips runs under a 25% reduction, and token-audit prints the break-even turn count per model.
devkit hook compact-prune --trigger✂️ Skill and rule bodies cut by about a third, nothing removed
Branch-only sections of eight skills and three path rules moved behind one-line reference pointers instead of reloading in full: 160.7k to 108.6k combined bytes, about 32% less reloaded weight, every line still reachable in a reference. AGENTS.md itself dropped from 10,665 to 6,379 bytes.
# spec, spec-work, wave, delegate, spec-update, review, index, agent-browser
# same instructions, moved behind rules-references/*.md pointers🧭 devkit init finishes legacy setup migration
The session hint now persists until the setup epoch is current; 17 of 19 older local projects had missed the previous hint. devkit init removes only verified, unedited ai-setup leftovers, and can commit its own changes.
devkit init --yes --commit🔎 Review prep and re-review in one call
Diff review previously took 5–7 manual calls; review-quick now scopes the package to owned paths, dispatches it, records the verdict and can replay only prior findings. Compact spec reviews can use a smaller package and low-risk reviews run natively.
devkit review-quick --own
devkit review-quick --own --delta📦 Spec review gets bounded evidence
One completed spec produced a 1.95 MB review package, 97% from one unrelated commit block. Prep now bounds history to that spec and includes relevant project context, callers and tests; a compact delta is sent only when smaller than the full package.
devkit spec-review-prep 686🌐 Browser checks bundle prep and evidence
The agent-browser flow used about four setup and eight evidence calls after each frontend edit. browser-prep and browser-evidence now run those stages once each and validate screenshots from actual PNG data.
devkit browser-prep
devkit browser-evidence --url http://localhost:3000📬 Parallel delegates land in brief order
Six of ten parallel delegate returns had refused sibling edits in shared files. delegate-fanout runs the briefs and lands returns in order; delegate-return accepts identical rows and merges disjoint edits while refusing conflicting ones.
devkit delegate-fanout codex implement --brief briefs/a.md --brief briefs/b.md🧩 Spec authoring and worktree landing get direct commands
Spec authoring previously took about six setup calls and four calls per seal. spec-author-init and spec-seal bundle them; spec-work-prep --land checks ownership before bringing managed worktree changes back.
devkit spec-author-init --slug my-feature
devkit spec-seal --candidate /tmp/spec.md --target devkit/specs/001-my-feature.md🚀 /release publishes a project's changelog
Projects with tags and a changelog can now use /release to complete the Unreleased entry, bump the manifest, push an annotated tag and publish GitHub release notes.
/release🎨 Design acceptance has a native check
/pen-design now uses devkit design-check with baseline diffing for acceptance, and its browser evidence verifies decoded PNG content.
devkit design-check design/main.pen --baseline design/baseline.json🧹 Finished worktrees can be cleaned safely
Interrupted delegate and Prime runs left 17 worktrees in one project. worktree-gc finds branches already landed by patch equivalence and removes them with --apply, while keeping dirty or unmerged work and fresh worktrees under two hours old; this also fixes 12 of 12 false cleanup failures.
devkit worktree-gc --apply✅ Todos can finish with one command
Parking a todo took three calls and finishing one took about ten manual Git commands. todo add --commit commits only its new file; todo finish verifies the claim, commits owned paths and completes the worktree.
devkit todo add "My task" --commit
devkit todo finish <id> --token <token> --message "feat: complete task" -- path/to/fileWhat changed for you
Now available
/releaseturns a project's Unreleased changelog into a tagged GitHub release.devkit init --yes --commitremoves verified legacy setup files and commits exactly that run.devkit browser-prepanddevkit browser-evidencebundle frontend verification stages.devkit delegate-fanoutruns parallel briefs and lands their returns in order.devkit design-checkcompares design output with its baseline.devkit spec-review-prep <id>builds bounded review evidence and sends a compact delta only when it is smaller.devkit worktree-gc --applycleans merged delegate and Prime worktrees while preserving dirty or unmerged work.devkit todo add --commitanddevkit todo finishbundle the Git steps for todos.devkit token-audit [--days N] [--project dir] [--json] [--save-baseline] | apply <lever> <name>— token spend from your own transcripts, plus applyingskillOverrides/enabledPlugins/deniedMcpServers/disableClaudeAiConnectorsdirectly./token-check— ranks the measured token sinks and applies only the levers you pick.devkit hook compact-prune [--trigger]plus thedevkit-pruneplugin — local pruning of stale tool output past 200k context, opt-in viaCLAUDE_CODE_ENABLE_FUNCTION_HOOKS./todo <text>parks a todo in one line;/todo(formerly/backlog) also resumes the open work a session parked for you unasked.
Behavior changed
- A setup hint stays visible each session until the project has run the current
devkit initmigration. - Codex review uses medium effort for routine tiers, with Astra reserved for architecture escalation.
- Low-risk specs now review natively after 18% of 434 completed runs found blockers, versus about 50% at medium risk.
/reviewuses scoped Diff Mode with recorded verdicts; stale review receipts are invalidated when the tree changes.- Wave retry now starts a fresh dispatch when a premature worker-done event left the old one stuck as completed.
devkit token-audit --levers --top Nalso ranks installed skills that have not been used.- Pulled project skills retain their names, and stack skill scripts are wired only into projects based on the corresponding boilerplate.
/pen-designacceptance runs throughdevkit design-checkwith baseline comparison.- The retired
stack-shopify-liquidskill now lives in the Shopify boilerplate. devkit syncwithdraws the fixed auto-compact override;/autocompactand Claude Code's native default apply instead of a session growing to ~767k context.- A long Bash command backgrounds after 120s instead of 30s.
- A prompt-cache rewrite after a pause over an hour now names the rewritten token count so you know to
/clearor/compact. - Subagents default to Sonnet instead of Opus, after 15% of measured token volume ran there.
- Every native subagent, delegate and wave slice returns a compact handoff — one line per finding, no PASS lines — instead of a full report.
- A response that leaves work open now offers it as a todo in its closing question; around 30 Main tool calls, or right after a context compaction, the session checks
devkit todo listand parks any untracked remainder unasked. - Every dispatched agent (Wave slice, Delegate, Prime) ends its report with a
DEVKIT-FEEDBACKblock or reports its own friction signal immediately, instead of staying silent. - Wave's slice dispatch and retry route through the same runtime-selection path as
/delegate, with preference, readiness and usage-limit checks included;--runtime <name>overrides any registry runtime explicitly. /spec-workdispatches implementation to a fresh agent by default instead of continuing in the same session.- Skill and rule bodies most sessions reload lost about a third of their reloaded weight; every line stays reachable in a reference file.
🚀 Features
- native design-check, dsh handoff contracts, and delegate-return me (7dcd283)
- routing — codex tiers on medium, astra only for escalation (d70105c)
- token-audit — skill-name-only lever ranks unused installed skills (926d752)
- skills — pull names a project skill sharing a pulled skill's trigger (f38e7d5)
- spec-work — managed worktree lands through spec-work-prep --land again (5bb34ee)
- prep — index-prep --report, readiness later-step suites, spec-work --worktree (2a17cb2)
- delegate — delegate-return --expect and brief-gate --closure (43d6676)
- review-quick — batch oversized packages, pass refusal reasons through (b23c075)
- gate — tamper-check in quality-gate, advisory added-comment lint (617f0a7)
- maint — issues-prep --close-covered, run-cost --base auto (78a357b)
- prep — arch-prep, share-prep --verify, learning-capture-prep --ref (5362caf)
- token-audit — --levers --top N for /token-check (b9f0e8e)
- debug-prep — --mutate runs the red-check and always restores (33a3c17)
- skills — wire stack skill npm scripts on pull (bd7145b)
- delegate — delegate-fanout runs N briefs and lands returns in order (d97f869)
- review — /review Diff Mode runs through devkit review-quick (fecde81)
- review — review-quick, scoped review-prep and delta re-review (dfc6068)
- agent-browser — browser-prep and browser-evidence (e6ebaca)
- rules — script-first — deterministic steps run through devkit/CLI (320a516)
- prep — wave slice steps, checkin/research/workspace prep folds (07ff2e1)
- spec-work — spec-verify and spec-review-prep --freeze (9c9d0c3)
- spec — spec-author-init and spec-seal bundle authoring steps (6d3675d)
- scripts — feedback-issue --search, release-prep and release-publish (d54dd1b)
- spec-review-prep — review-ready package — bounded diff base, dropped Main-only sections, project context and related symbols (Spec 570, 686) (57d36a2)
- codegraph-db — add symbols_in_files, callers and callees queries (73f04c6)
- git — shared scoped-git helpers and commit-prep --stage (ee812cb)
- init — remove ai-setup leftovers and commit the run (Spec-687) (54b7808)
- todo — add --commit and finish bundle the todo git steps (fd85f88)
- cli — group and align devkit help output (e44c9ad)
- spec-review-prep — diff-focused package for compact specs (Spec 686) (0a06037)
- review-runtime — low-risk and light specs review natively (2ebfa33)
- release — release notes lead with the user-facing head (02e5498)
- init — nag every session until devkit init has run (f426584)
- skills — add /release for CHANGELOG-driven GitHub releases (4647cb2)
- spec-update — --add-file narrowing flag for caller-migration files (Spec 681) (17d5229)
- worktree-gc — clean merged delegate and prime leftovers (747ea1e)
- skills — rename /backlog to /todo, the one todo skill (c4d9eba)
- review-runtime — derive dispatch sections and require AC-EVIDENCE (Spec 675) (Spec 669) (05bcd4c)
- rules — every bug fix hunts siblings and fixes the cause (a8ed3b4)
- hooks — precompact carries untracked open work into todos (9a296ed)
- rules — always offer open work as a todo, park it before limits (7e26651)
- spec-validate — warn when an AC verify reaches only a helper (Spec 680) (8e2c9a8)
- wave — wave coordinator waits on worker_done/escalation (Spec 677) (ffedca8)
- brief-gate — honor a spec's own Cut-Rationale as implicit override (Spec 679) (cea3511)
- spec-work — dispatch to a fresh agent by default (Spec 682) (1aafd33)
- plugins — add devkit-prune function-hook plugin (Spec-666) (33e9523)
- always-on — keep the Claude session prompt cache warm (Spec 672) (74704d8)
- spec-work — let Main apply a small exact fix list itself (fcdf0be)
- spec-validate — require a registry file for every new tools.json pin (Spec 666) (00e6a43)
- spec-deps-check — exempt friction-sites.tsv from wave overlap gate (Spec 676) (7733413)
- spec-validate — warn on a path named only in a Files-to-Modify reason (58875ec)
- spec-work — implementer self-reviews the recurring review blockers (7d7859c)
- codegraph-first — exempt small whole-file reads from the gate (Spec 683) (dcd3fbf)
- spec-route-prep — print SUBSYSTEMS=<n> before the first authoring review (Spec 678) (cb52862)
- spec-validate — block undefined thresholds and outer-only input bounds (Spec 665) (584c368)
- hooks — add compact-prune engine and PRUNE token-audit records (Spec-665) (Spec 666) (9dcfd38)
- friction — emit OD_FRICTION on runtime-route no-usable-route (Spec 669, 674) (705c198)
- friction — instrument Prime Agent lifecycle with OD_FRICTION codes (Spec 669, 673) (d503785)
- friction — wire the friction hint into agent context, ship feedback rule (Spec 670) (b09ebc9)
- friction — instrument delegate-dispatch lifecycle with OD_FRICTION codes (Spec 669, 671) (273be11)
- friction — one shared OD_FRICTION emitter, panic code, site test (Spec 669) (85b7514)
- core — offer small unfinished work as a todo (ad4ca86)
- routing — send small deferred work to todos, land before done (0fa4508)
- wave — slices route through runtime-route like /delegate (Spec 668) (149a3de)
- feedback-issue — add --comment mode for a follow-up on a filed issue (435f146)
- hooks — inject the handoff contract into every native subagent (754907a)
- agents — return only a handoff from subagents, delegates and slices (d350f2d)
- skill-lint — reject high effort outside the four listed skills (a58d968)
- token-check — rank token sinks and apply the levers you pick (Spec-664) (30a76ce)
- token-audit — measure Claude Code token spend and apply settings levers (Spec 663) (79d9530)
- sync — accept model: inherit in skill frontmatter (1671496)
- hooks — cold-cache hint from 300k, switch entry and tests (8bf4c1b)
- hooks — name the cache rewrite after a pause over an hour (bed89ea)
- session-start — trim an oversized auto-memory index automatically (deaa4a1)
🐛 Fixes
- token-audit — skill lever reads decoded frontmatter name and description (6689605)
- delegate-return — sibling appends that share a row refuse, never guess (331c7b6)
- tamper-check,delegate-return — close heuristic gaps, no duplicate appends (a73a4a4)
- sync — seed cb and gh into sandbox.excludedCommands (308be2e)
- ci-cleanroom — refuse a second concurrent run on the shared work dir (817fd83)
- gate — tamper-check stays advisory; park its heuristic gaps (902a4cb)
- close round-2 re-review findings (debug-prep, tamper-check, review-quick, delegate-return, issues-prep, token-audit) (8df6302)
- skills — skip line names an older boilerplate layout as a migration (c58505d)
- init — remove ai-setup generated Codex agents as legacy leftovers (d1d6266)
- learning-capture-prep — use support::git instead of a private git_stdout (d5199f1)
- guard — gh api PATCH/DELETE blocks only the git/refs endpoint (80c0858)
- index-prep,spec-work-prep — real init markers, --land ownership, resumable landing (828e58e)
- skills — pull boilerplate skills only into boilerplate-based projects (d06dae8)
- gate — tamper-check advisory again until its re-review lands (c1a4ec2)
- delegate-return,brief-gate — committed diffs, dir prefixes, honest closure coverage (7d65232)
- delegate — no union merges, no symlink writes, no pending-merge commits (2fd8da3)
- token-audit — path-frontmatter advice only for rule files (caac8b9)
- learning-capture-prep — keep explicit short spec IDs (533e05d)
- review-quick — batching verifies the tree, invalidates stale receipts (6b5a9c4)
- maint — issues-prep scope and landing checks, run-cost base on history (6c5eb54)
- guard — keep command context across backslash-newline, allow -S (42c333b)
- tamper-check — fixture-aware skips, untracked files, exceptions, fail closed (679744a)
- debug-prep — mutate reports restore failures, kills the process group (9101300)
- spec-work — keep managed-worktree on the hand path until --land checks ownership (ddb92d1)
- guard — message exemption needs a real, separate -m value (71d74b0)
- delegate-fanout — stage new files, delta-only commits, merge-aware appends (24824c7)
- hold tamper-check advisory and /review off review-quick batching (15db410)
- tests — rebuild delegate_return tests after a broken union merge (6eb30de)
- guard — message prose naming the dotenv file is not a read (5f7bec2)
- skills — confine wiring files to agent context, refuse bad scripts (5a986cb)
- delegate-return — already-present check is a context-aware reverse apply (60b052e)
- review-quick — delta per source file, private temp, scope-keyed results (fbd7761)
- review-quick — enforce prep gates, scoped delta history, true identities (425cf75)
- close re-review findings in browser-prep, browser-evidence, freeze (802676b)
- release — bind confirmation to HEAD and target, remote default branch (c68d0eb)
- agent-browser — safe evidence dir, dotenv precedence, no query secrets (94eb1df)
- spec-work — freeze validates first, spec-verify keeps gates and evidence (e070721)
- prep — friction fixture rows, isolated research payload, restart cleanup (b8d1ab1)
- spec-seal — use the metadata parser for the digest field (7c9bebf)
- test-prep — no rtk condensing around devkit's own runner (d00d79e)
- spec-review-prep — codex native-review — 5 P2 findings in the related-symbols/project-context excerpts (1f75e90)
- spec-review-prep — never dispatch a compact delta bigger than the package it rides beside (Spec 686) (be3e9d0)
- init — stale REBASE_HEAD no longer skips the legacy phase (d535477)
- delegate — dsh briefs keep the report in the handoff (e730d5b)
- friction-hint — move helper above the test module for clippy (4b3cb0c)
- friction-hint — count only emitted OD_FRICTION lines (9754768)
- spec-work — dsh implementer reports inline (e06896b)
- skills — pull updates untouched skills changed upstream (c24ded8)
- cli — drop help row, bare devkit already prints it (c57f536)
- release — first release without a tag starts at 1.0.0 (42aca22)
- todo — accept the title as a bare argument in todo add (75c187c)
- release — push the release tag atomically with the branch (b02d653)
- wave — slice-retry names a live dispatch instead of failing raw (a8b77bb)
- skills — no stack-skill pull inside the boilerplate itself (73c1589)
- design — reuse-only fast path skips preview and canvas reads (7b93eb7)
- wave-prep — slice-retry redoes a dispatch stuck at completed (e70ae34)
- docs-drift-check — accept hashes a foreign dirty source from HEAD (9113c91)
- review-dispatch — prompt-size refusal, killed-process diagnostic, sibling-write attribution, citation-literal fix (Spec 685) (45ee70f)
- worktree-gc — no FAILED row when orca already removed the branch (9665dec)
- worktree-gc — keep worktrees created or moved in the last 2 hours (39ecd9b)
- content-budget — gate the always-on rules by bytes (3ce91ce)
- rules — bring always-on rules back under the byte budget (789f0be)
- rules — never commit around a foreign pending merge (8585359)
- rules — load quality rules on Rust files (d9ff30a)
- rules — dedupe todo checkpoint, fire once per turn end (654be63)
- brief-gate — mixed space/tab indentation cannot smuggle a Cut-Rationale (Spec 679) (25a2bad)
- docs — revert docs/workflows.md docs-source reset for Spec 682 (Spec 677) (d821857)
- devkit-prune — drop the unused options parameter from register (fe54095)
- wave-accept — a moved declared file or a file under a listed dir is owned (Spec 334) (68ada08)
- session-scope — prefer transcript-path identity over payload session_id (Spec 684) (9f541a3)
- tool-pin-audit — accept a path-sourced marketplace plugin without sha (1ea6d33)
- spec-readiness — stop verify-span parser from re-reading judgement notes (Spec 678) (633fa11)
- delegate-visible — no friction for a run outside any checkout (e13781c)
- spec-wave-approve — validate evidence in the slice worktree (f00b4ce)
- delegate-exec — report unattributed read-only drift without friction (8c4ca3c)
- spec-drift-check — list another active spec's files as foreign (8939984)
- spec-readiness — count a Step-named missing path as created (Spec 665) (7f160b7)
- rules — bring the always-on rules back under the 5566-byte budget (f6704fd)
- spec-contract-apply — print help after the mode argument (f1b05e0)
- spec-readiness — a spec editing the affected map may own unmapped paths (Spec 669) (2ebd3ad)
- todo — fold umlauts in ids, clean up landed worktrees (3803c6e)
- backlog-lint — count todo files instead of a doubled zero (37d7dcd)
- spec-review-prep — warn when AC-EVIDENCE is missing before the freeze (Spec 668) (f816197)
- spec-validate — a cargo --manifest-path is no AC product (Spec 668) (54ce55f)
- prime-run — wait longer for worker-start under --require-orca (Spec 667) (e1e0136)
- wave — a baseline that never reached its tests is incomplete (fbfc976)
- spec-dead-refs — accept a Files entry the spec itself deletes (Spec 667) (aeaa0a7)
- review-runtime — say --context is Diff Mode only (848022b)
- review-runtime — never size-refuse an authoring candidate (05b8f57)
- close the delta-review findings on the handoff and split fixes (65d05f8)
- delegate — read-only delegates return findings, not a report file (1d6054c)
- hooks,token-audit — close review findings on today's Rust changes (565a493)
- skills — restore every-run rules the skill split hid behind pointers (a5d3fd0)
- token-audit — refuse skill-name-only for plugin skills (a7b3bf4)
- runtime-route — mark pi implement not ready without the hook bridge (997269c)
- tests — retry the skills_smoke token count with a private uv cache (dd1b7d8)
- delegate — send panel briefs without the context pack (b178c3e)
- content-budget — retry the exact count with a private uv cache (50c082c)
- tests — pin the pi sandbox off in runtime-route inventory tests (fcf397f)
- pen-design — design-sort suggests a fix and keeps numbers (b22cfd8)
- devkit-issues — brief agents on fmt order and api node_modules (4840102)
- rules — trigger credential/quality rules on .mjs and .cjs scripts (3145aa8)
- init — seed the shopify-plugin Claude plugin for shopify-liquid projects (c0cf3ba)
- runtime-route — probe the pi bwrap sandbox before reporting implement ready (8ee6458)
- devkit-issues — classify bug vs request before any fix (74453c0)
- delegate — chain per-spec Spec Mode review after a spec implement (23b6905)
- quality-gate — run native scanners from a worktree build when stale (18fef5c)
- plugins — enforce plugin pins in the daily background auto-upgrade (dd1ec06)
- sync — prune dangling devkit links that state.json lost (b13b09c)
- plugins — retry a pin reinstall whose uninstall or install failed (b6c50cd)
- skills — step devkit-claude-changelog effort down to medium (7ae6205)
- model-benchmark — map fable alias to Claude Fable 5.1 (a967bcf)
- rules — drop removed content/scripts path from script contract (Spec 560) (b7f1b00)
- content-language — scan .agents/skills and translate codex-changelog (6accdde)
- skills — step pen-design and workspace effort down to medium (1493c0f)
- token-audit — write deniedMcpServers entries as serverName objects (ac89c51)
- spec-dead-refs — accept absent-asserted paths and planned parent dirs (733432b)
- spec-validate — never flag vendor manifest names as path twins (9be6d77)
- rules — bring skill-editing rule back under its token budget (c0b1359)
- hooks — time the cold-cache hint by the TTL the session uses (f85b1a2)
- skills — run the remaining inline skills on opus (0772f04)
- rules — bring core.md back under the always-on budget (dff238a)
- usage — count a streamed message once in model_mix (44a69b5)
- skills — run /delegate on opus (1b18cf7)
- skills — run the maintainer skills on opus (72b4eef)
- skills — run /wave, /test, /debug, /friction-feedback on opus (a49d39a)
- skills — keep /commit and /fetch-task on the session model (7f3e901)
- ci-cleanroom — say when a green run records no release evidence (75155dd)
- sync — stop managing the compact window, default subagents to sonnet (78306f6)
⚡ Performance
- routing — run codex/pi architecture at high instead of xhigh (9957cde)
- skills — move branch-only sections of four more skills to references (d9b4176)
- skills — move branch-only sections of four large skills to references (1ae1940)
- session-start — keep maintainer notes out of wave slice workers (c60e3a0)
- rules — move branch-only sections of three path rules to references (36002d2)
- cd-guard — shorten the rewrite note to one clause (77af55f)
- agents — move seven maintainer procedures out of AGENTS.md (116915c)
- canon — read VISION only before a design or cut decision (556d781)
- hooks — send the verbosity reminder once per session (c69465e)
- rules — batch tool calls, move long chains to subagents (f3110b3)
- env — auto-background Bash after 120s instead of 30s (9c266f9)
- env — compact at 300k instead of 800k context (590e8e0)
♻️ Refactoring
- skills — retire stack-shopify-liquid into the boilerplate (Spec 652) (0eb7e88)
- devkit — consolidate Orca binary resolver (R030) (44896af)
- support/git — share the repo-env scrub and no-prompt config (37d7b65)
- tools — reuse mcp::parse_json for the first JSON-stream value (c407213)
- support — share the Euclidean civil-date conversion (43aad7c)
- workflows — drop output-format prose that schema already enforces (9cb8e5c)
📖 Documentation
- release — align publish guide with current gates (4e854bc)
- reference — record completed spec decisions (906d5d4)
- agents — repository-canon is read as a file, not a skill (50e3d8f)
- spec-review-prep — reviewer-prompt package is complete, no bootstrap read (6a13be2)
- todos — refresh docs-source marker after todo finish (c38907b)
- todos — where finished todos go, bulk parking vs. working (cf07176)
- explain specs, todos and every skill with examples (2012846)
- spec-work — spec-finish --harness is the implementer, not the reviewer (Spec 686) (f45eb85)
- spec-work — resolve the review runtime per spec (b763c44)
- wave — slice-retry recovers a premature worker_done itself (54e2578)
- workflows — accept docs-source digest after wave standing orders (f29fb08)
- wave — redo a falsely-done slice, spec-complete only, shared markers (bbfbd4e)
- workflows — accept docs-source digest after worktree-gc (f88ea8e)
- prime-agent — show --provider with --model in the dispatch example (114fe88)
- changelog — /todo rename as breaking change in Unreleased (6168276)
- workflows — accept docs-source digest after /todo rename (89f53d7)
- changelog — Unreleased head for 187 commits since v0.46.0 (2e7c594)
- workflows — agent offers and parks open work as todos (b3a8acc)
- conventions — scripts/ unit tests are bin-only too, like maint/ (Spec 675) (3b2352c)
- workflows — refresh docs-source digest after spec-work fix-direct rule (4c7a73f)
- specs — add approved specs 675, 677, 680, 681, 682, 685 for wave dispatch (3b04de0)
- spec — name the MODIFIED and REMOVED fields in the compact skeleton (b2821b0)
- workflows — refresh docs-source digest after wave/delegate edits (225b1d8)
- skills — align wave/delegate routing prose with Spec 668 (Spec 616) (c18339a)
- specs — ground 665's head rule in the replay evidence (c994caf)
- research — record the Julia-1 distillation result (39c5e4b)
- spec — add Spec 672 devkit-owned always-on rulesets (5201ac4)
- fix routing-prose redundancy (R032, R034, R049, R050) (451f984)
- audit — redundancy audit of the whole setup (3fe989f)
- audit — keep the Jev selector replay evidence (3ae3f67)
- research — record the isolated replay rerun and the conclusion (dcd9742)
- re-accept the workflows page marker after the wave baseline fix (a4f42ec)
- research — add a zero-shot Julia-1 check on the replay candidates (fea282a)
- spec — author Spec 667 cross-session todos (854f332)
- research — record Laya fine-tune, Kev-27B and the replay confound (1969b54)
- brainstorm — converge lightweight todos across sessions (c0d96a3)
- research — add the planning-with-files comparison (212cc78)
- research — record the panel-driven Laya recheck (25818be)
- research — replace the invalid Laya comparison with a replay test (88dabe9)
- research — compare Laya with Jev on the replay candidates (203da1c)
- research — record the pruning replay pilot and the Jev concept (0699752)
- design — accept the pen-design drift and mirror the rows row (df26012)
- research — map awesome-jev patterns onto the token baseline (9fd088b)
- research — record the Codex audit of the Jev eval (ecadaee)
- workflows — accept drift from the spec-work IMPLEMENT_RUNTIME note (7ab86dd)
- spec-work — clarify IMPLEMENT_RUNTIME is not the implement route (5f6760d)
- research — record the corrected Jev eval against a local rule (ed7b8ab)
- research — retract the Jev AUC verdict after a label defect (4e99675)
- research — record the Jev AUC eval and drop the model (fc04384)
- research — compare fast-jev with the TypeSafe cookbooks (1a79092)
- research — add Jev prefix runs and the jev-pruner check (9e3433a)
- research — record the live Jev run on a devkit transcript (b39580b)
- agents — drop history narratives from the always-loaded context (c8a2bda)
- specs — author 665 prune engine and 666 devkit-prune plugin (d4623f0)
- research — evaluate fast-jev-compaction against the token baseline (6242c9a)
- backlog — park the switch of inline skills to model: inherit (3b614c0)
- spec — add specs 663 and 664 for devkit token-audit and /token-check (454a05e)
- harnesses — cut the DeepSeek cell back to what a reader acts on (281f9a2)
🧪 Tests
- wave-prep — accept --task integration test with a fake orca (370641b)
- delegate-exec — oversized-prompt test ignores inherited DEVKIT_DELEGATE_* (255a684)
- tamper-check — assert advisory gate output again instead of #[ignore] (34322fd)
- tamper-check — regression tests from the round-2 fix, gate-red test active (773e461)
- tamper-check — assert the advisory gate output instead of #[ignore] (0aaf637)
- tamper-check — park the gate-red test while the gate call is advisory (7bb5836)
- skills-smoke — browser session pin follows browser-prep (07d7cd1)
- affected-map — map spec_route_prep.rs to its own suite (Spec 678) (273f348)
- devkit — serialize process-global env mutation in unit tests (Spec 674) (f79f7b9)
- friction — close the two Spec 669 review follow-ups (281eb4b)
- affected-map — route devkit-codex-changelog skill to the refs suite (c41f5ff)
- affected-map — route tools/rust-only.tsv to the rust_only suite (50d8e83)
- affected-map — route repository-canon edits to the refs suite (8704003)
- give every clock-stamped fixture directory a sequence (64663ae)
- pi-delegate — give every fixture its own directory (4705e4e)
- pi-delegate — let the bwrap stub run its probe on macOS (37bacfe)
🏗️ Chores
- todo — add ci-cleanroom-tests-the-dirty-tree-not-the-commit (6f506e4)
- todo — add guard-ignored-rust-tests-at-edit-time (cd77351)
- guard — drop the commit-message exemption, keep REV:<dotenv> (cc7aff0)
- todo — add test-isolation-oversized-review-prompt-test-inhe (7fff537)
- todo — merge stray review-quick note into its todo (39ac225)
- todo — add script-review-quick-batches-an-oversized-package (1eff745)
- review — keep /review off review-quick until its gate fixes land (51ba19e)
- todo — add script-arch-prep-share-prep-verify-learning-capt (5f41d82)
- todo — add script-spec-readiness-accepts-suites-a-later-ste (3ca9baa)
- todo — add script-flag-added-comment-lines-in-lint-delta (16dc448)
- todo — add script-devkit-tamper-check-inside-quality-gate (49a8251)
- todo — add script-index-prep-report (11aa801)
- todo — add script-maint-run-cost-base-auto (fab4841)
- todo — add script-maint-issues-prep-close-covered (64f47a6)
- todo — add script-debug-prep-mutate-for-the-red-check (74327cb)
- todo — add script-brief-gate-closure-lists-callers-outside (3bffae7)
- todo — add script-delegate-return-expect-files-stray-missin (70dc33b)
- todo — add script-token-audit-levers-top-n-for-token-check (48e0e99)
- todo — fanout must land parallel returns without DIRTY refusals (3c5c3ea)
- todo — add script-spec-work-worktree-create-and-patch-back (464b0cb)
- todo — add script-delta-re-review-from-the-previous-round-s (7816160)
- todo — add script-review-prep-scope-to-the-session-s-own-pa (31d2edc)
- todo — add script-one-call-diff-review-devkit-review-quick (bba2cb7)
- todo — add devkit-delegate-fanout-plus-todo-next-parallel (97ccad1)
- set up devkit (53ca240)
- todo — add secret-env guard false positive (0658d38)
- todo — add script-bundling candidates from skill sweep (7a9e228)
- todo — add bulk todo mode idea (934bc52)
- todo — add docs follow-ups (2693eb6)
- todos — close the first boilerplate releases todo (5bbc2cc)
- todos — first boilerplate releases published (4595e63)
- todos — park first /release of the sb and sw boilerplates (cc7773d)
- todos — park the spec-path/Files-to-Modify parser consolidation (96ee6e7)
- delegate-visible — rustfmt json.rs and mirror.rs (2044301)
- skills — rustfmt the boilerplate origin test (fed2170)
- todos — park always-on budget unit mismatch (25af728)
- todos — park mechanical enforcement of the review lite path (d41463e)
- todos — park a fast spec-work-prep and phase-level duration metric (e25e829)
- todos — park three friction clusters from the 14-day log (8d33d23)
- todo — add measure-jev-as-a-completion-gate-before-building (9215b85)
- todos — park the four spec-flow optimizations the maintainer picked (ae07281)
- todos — park the four wave speed-ups the maintainer picked (4f4f14c)
- tests — rustfmt the wave baseline regression test (55a8002)
- tests — rustfmt the plugin-seed init tests (42b4a63)
- token-audit — rustfmt the deniedMcpServers assertion (7145c50)
No commit type
- Update Unreleased changelog with init migration guidance and full 0.46 r (4dd41b6)
- add usage snapshot for 2026-09-28 (30-day window) (15a0550)
- Spec-667: complete cross-session todos after review PASS (6d275f4)
- Spec-667 fix 4: detect open backlog entries structurally (7ea6eba)
- Spec-667: record run 2 delta BLOCK on padded open rows (2d087ec)
- Spec-667 fix 3: raw attempt patches, lossless migration, safe retry (954066d)
- Spec-667 fix 2: keep saved attempts, bind migration to source rows (0bac392)
- Spec-667: drop the obsolete test count from Step 3 verify (3f99cc1)
- Spec-667: record review round 2 BLOCK and the open findings (f82c240)
- Spec-667 fix 1: close the ten review findings (5430bc4)
- Spec-667 Step 5-7: route capture and backlog through todo files (d44f5ad)
- Spec-667 Step 1-4: add devkit todo with worktree-visible claims (9bf96f6)
v0.46.0 — 2026-09-26
Ponytail's lazy-first ruleset now ships as a pinned plugin reaching every agent devkit runs, replacing the devkit rule text it duplicated; Pi now falls back through a per-tier candidate list to DeepSeek V4.1 Flash (20–26s vs dsh's 43–56s) when its primary provider is usage-limited, and a wedged delegate is flagged mid-run instead of only after burning its whole bound (8 of 115 dispatches hit it). Update with devkit sync.
58 commits since v0.45.0 · Specs 181, 657, 659, 660, 661, 662
✨ Highlights
🐎 Ponytail: pinned plugin, duplicate ladder cut
Upstream DietrichGebert/ponytail (sha-pinned, 1622 tokens) now reaches Claude, Codex, OpenCode, Pi and every delegated agent (Prime, Kimi, DeepSeek Harness) as the lazy-first / YAGNI ruleset; devkit's own duplicated ladder in code-reuse.md and quality.md is gone, so upstream updates arrive as a sha bump instead of a rewrite.
devkit sync
# installs ponytail@devkit-pins when node is on PATH🔀 Pi never runs dry — per-tier model fallback
A usage-limited or signed-out provider used to take the whole pi seat out of routing. Pi now tries its primary tuple, then an ordered pi_fallbacks list per tier (DeepSeek V4.1 Flash first, then Codex on implement), and records the limit under the provider that actually ran.
runtime-route pi implement
# PROVIDER/MODEL/EFFORT plus MODEL_SKIPPED=<provider>/<model>:<reason>,… for passed-over candidates🤫 Silent delegates get called out mid-run
8 of 115 delegate dispatches burned their whole wrapper bound with nothing to show for it. A streaming delegate (codex, opencode) that stops producing output now prints DELEGATE_SILENT every stall interval while it still runs, and a bound-hit line now names how long ago the last output landed.
DELEGATE_SILENT runtime=codex silent=300s elapsed=612s bound=900s🔁 /spec-update runs itself, nowhere left to ask
/spec-update used to stop and ask before running whenever a gate or script named it as the next step, and a stale Approved-Digest stopped /spec-work and /review the same way. All three now invoke it themselves and continue.
# no more "should I run /spec-update?" — it just runs📊 Per-agent-type subagent cost report
devkit run-cost-prep --agents groups the subagent transcripts Claude Code already keeps by agent type — runs, cache writes, output tokens, median turns and wall time — with no second log file; a duplicate-record bug that double-counted a message split across content blocks (2838 records for 1599 unique messages in the sample) is fixed alongside it.
devkit run-cost-prep --agents --days 14🔐 Codex hooks trust themselves
devkit sync now writes the trusted_hash entries Codex 0.156 requires, so a Codex session never has to answer the per-hook trust prompt for devkit-managed hooks. devkit config codex-hook-trust devkit|all|off picks the scope.
devkit config codex-hook-trust devkit🧹 Post-edit shfmt sweep stays in scope
post-edit-lint's fallback for a Bash command that only mentioned a .sh path used to sweep and reformat any shell file touched in the last 60 seconds anywhere under the repo, tripping wave's foreign-file guard in 3 of 4 slices on one reported project. It now only touches a shell file the command itself names and git shows as changed.
⏳ Usage limits route around themselves
runtime-route kept re-picking a runtime/provider already sitting in a weekly or quota limit — 18+ transcripts show the same retry time hit again, each ending in a manual fallback. A hit is now recorded with its parsed reset time and the route skips that runtime/provider until then, on both the try again at and the resets <date> phrasing.
# no manual fallback after a weekly-limit hit — the next route call skips it automaticallyWhat changed for you
Now available
devkit run-cost-prep --agents [--days N]— per-agent-type subagent cost table, sorted by cache-write.devkit config codex-hook-trust devkit|all|off— scope for Codex's automatic hook trust.- Ponytail lazy-dev-mode ruleset, installed automatically by
devkit syncwhennodeis on PATH.
Behavior changed
/spec-updateruns wherever it's named instead of asking first;/spec-workand/reviewrun it themselves on a stale approval.- Pi routing falls back through
pi_fallbacks(DeepSeek V4.1 Flash, then further candidates) instead of skipping the whole seat on a usage limit. - A stalled streaming delegate (codex, opencode) now prints
DELEGATE_SILENTwhile it still runs, and a bound-hit line names the last-output age. post-edit-lint's shfmt fallback only touches shell files the command names, not every recently touched file nearby./specsearchesghand Context7 for an existing solution before designing a new general capability, and records a build-vs-buy line either way./improve-codebase-architecture's clone scan now covers Rust, PHP, Twig, Liquid, Vue and Python via jscpd, not only TS/JS./capturegained two more keep filters (reads-alone, not-derivable) and a merge action alongside supersede/dedupe.delegate-returncherry-picks a delegate's own commits onto the return target instead of discarding them when the delegate committed its work.- Wave's
ensure-depsnow installs every locked npm package of a workspace-less monorepo (one lockfile per package dir) instead of failing the whole baseline on the dependency-free root package.json.
🚀 Features
- runtime-route — Pi falls back to the next model per tier (Spec-662) (1f7b03d)
- rules — auto-invoke /spec-update wherever it is named (ce7a2dd)
- spec-work,review — run /spec-update on stale approval unasked (ae65deb)
- spec-661 — extend always-on rulesets to Pi and delegated agents with scope filtering (db9fef5)
- plugins — pin ponytail and cut the duplicated YAGNI ladder (Spec-659) (bf98e62)
- delegate — report silent streaming runs and last-output age (Spec-660) (57bc9bd)
- codex — pre-trust Codex hooks so sessions never ask (aff1152)
- codex — wire maintainer dev-sync hooks for Codex (87cb194)
- improve-codebase-architecture — clone scan beyond TS/JS (cd1c38b)
- pen-design — component-reuse rule for canvas drafts, plus a B4 probe (26afe74)
- run-cost — per-agent-type subagent cost report (Spec-657) (3bd2462)
- capture — four keep filters and a merge action before writing (3c3bd5a)
- spec — search finished solutions before designing a new capability (e05937d)
🐛 Fixes
- spec-dead-refs — keep --test targets visible inside (cd rust && …) (6122ddb)
- spec-dead-refs — resolve verify operands after cd against that dir (Spec 181) (284280e)
- spec-reconcile — treat legacy '# Spec:' title as title, not provenance (23a7743)
- wave — install each locked npm package of a workspace-less monorepo (1451caa)
- runtime-route — skip a runtime/provider until its usage limit resets (252b2c0)
- docs — migrate the remaining Prime and Opus model names (0967d95)
- pen-design — surface the CLI's raw reply when get_app_state disagrees with the app (0162393)
- pen-design — design-sort keeps the board's own row/column shape by default (823441e)
- pen-design — page View starts from the standard hero, not a campaign hero (d4f0520)
- delegate-return — cherry-pick delegate commits instead of deleting the branch (803a22c)
- wave — correct swallowed-Enter recovery, orca remedy is not runnable (b39ad70)
- post-edit-lint — never shfmt a clean script a command only runs (a27bacc)
- post-edit-lint — scope shell-file fallback to named command operands (b2ba3dc)
- model-runtimes — migrate prime route off superseded gpt-5.6-sol (e14046d)
- review-runtime — name why the package identity was refused (b94d5fb)
- delegate-exec — read the reset time from Claude's weekly-limit line (b7d8cdc)
- spec-validate-prep — name the unresolved evidence citation (a33253f)
- spec-review-prep — ignore session claims older than the path's commit (Spec 657) (8103d90)
- spec-work — hand the reviewer the lint results or SKIPPED reasons (Spec 657) (fe43966)
- spec-review-prep — lens from touched files, add manifest freshness (Spec 657) (c5eedf8)
- delegate-exec — classify Claude's weekly limit as a usage limit (25387e1)
- docs-drift-check — no false "no marker" after a dirty-source refusal (7422470)
♻️ Refactoring
- improve-codebase-architecture — stack checks for structure (fefa403)
- session-scope — consolidate four duplicate classifiers into one module (ddb1960)
📖 Documentation
- reference — decision rows for Specs 657, 658, 659, 660, 661, 662 (ef063d5)
- workflows — re-set the docs-source marker after the spec-update edits (e0dd7ae)
- research — record the Jev routing tools and queue Spec 662 (8e28dab)
- audit — add the implement run to the Pi DeepSeek Flash trial (c2c509f)
- team setup for agy and Pi on DeepSeek V4.1 Flash (aea9a92)
- research — record measured verdicts for the Pi candidates (Spec 660) (5946649)
- pi — map AskUserQuestion to rpiv's ask_user_question (9423017)
- research — evaluate twelve Pi packages against the delegate path (5834b13)
- devkit-issues — make the sibling hunt a gate, not a paragraph (a7d1d5f)
- devkit-issues — brief agents against issue-narrative comments (885bac5)
- design — name the reuse order and the board-keeping sort default (e17a132)
- design — document sort shape, page-View hero and B4 check (505d6b3)
- changelog — note the changed-file rule of the shfmt fallback (4cdaadd)
- changelog — record the post-edit shfmt sweep scope fix for #202 (2fad15a)
- audit — session-scope classifier deepening proposal (13bc01f)
- trial — keep Context7, decline a vendor llms.txt-first docs rule (1ed8862)
🧪 Tests
- rules — allow the deliberately extended /spec-update routing row (8839e0d)
🏗️ Chores
- tests — map claude-marketplace and plugins payload paths (Spec 659) (b533300)
- pen-design — drop issue-narrative comments from the reuse and save fixes (05bab33)
- tests — rustfmt the evidence-citation test (eecc2b4)
- devkit-release — announce only a new skill or a manual step (d18de38)
v0.45.0 — 2026-09-25
A forced tool-search setting was silently doubling MCP token cost — removing it cuts first-call context from 72k to 28k tokens and per-task cost by up to 45%. Update with devkit sync.
52 commits since v0.44.0
✨ Highlights
💸 Tool-search forcing withdrawn
ENABLE_TOOL_SEARCH=auto:5 on a 1M-token window only activated tool search at 50k tokens of deferrable definitions, so ~44k tokens of MCP tool definitions went into every request regardless. Withdrawing it measured first-call context dropping from 72k to 28k tokens, and cost from 0.89 to 0.55 $ (Nuxt) and 1.01 to 0.80 $ (Shopify) on two pinned benchmark tasks.
devkit sync🤖 Agent closes out its own change
/test and /review --quick are now model-invocable, so the agent runs them itself after a coherent code change instead of waiting for you to type the command — measured at 0 of 6 benchmark runs calling either before this.
# happens automatically after a code change; review stays gated
# to multi-file or risky diffs since it runs on Opus📉 Lighter rules on every code touch
agent-graph.md (10.3k → 3.4k characters), code-reuse.md (9.8k → 3.8k) and design-system.md (6.5k → 5.2k) load on the first touch of a source file in every session — the cut removes narrative and duplicated routes the enforcing hook already covers, not the norms or commands.
🔒 Headless sessions no longer lose work
A claude -p session ends with the turn, so a blocked wait on a background task (git stash, long build) never got a notification to resume it — measured losing a finished change in 2 of 3 headless Shopify benchmark runs. Headless sessions now wait on their own background tasks via timeout instead of the blocking guard.
🎨 Pen design scripts agree with each other
design-check, design-verify, design-rebind, design-adapter-check, design-sort and design-fonts each read variable-family and group-layout rules from their own copy, so a hyphenated token name (space-4), a canvas over 8 view groups, or --write/--apply --all could pass one script and silently fail another. All six now share lib/adapter.mjs/lib/tw.mjs as the source of truth.
🌊 Wave and spec-deps refuse bad state earlier
Wave's slice-dispatch now refuses an unapproved spec before creating the worktree instead of after (WAVE_SLICE_DISPATCH_UNAPPROVED); the plan reports a spec held back by a stale or missing approval as BLOCKED: <id> — <reason>; and a duplicate spec ID now lists every colliding path instead of stopping at the first one.
devkit maint spec-deps-check --planWhat changed for you
Now available
devkit --versionanddevkit -Vnow answer with the version instead of an unknown-command error.
Behavior changed
- Session start now names a local update source whose checkout is over 7 days old, with the command to switch to http.
- The Bash auto-background threshold moved from 5s to 30s, so short git/test/docker calls stay on the main turn (measured 16 of 330 Bash calls affected in one benchmark session).
- Shopify preflight now fails a section or block schema name over 25 characters, and a theme name over 50 — both previously passed silently and 404'd in production.
/spec-work's authoring probe now warns when a negated search (! rg ...) would still match undeclared files, before the spec is approved.- Planning artifacts (drafts, brainstorms, research, audit files) from a parallel session in a shared checkout no longer trigger
SPEC_DRIFT_DETECTED. - A codegraph read guard no longer blocks a
sed -nrange built from a variable offset (${N},$((N+40))p) as a whole-file read. - Headless (
claude -p) sessions no longer receive the interactive "offer to the user" hint, since nobody is there to accept it. /indexleaves aCLAUDE.mddeleted when your git history deleted it on purpose, instead of recreating it on the next run.devkit syncnow reinstalls a drifted plugin whose update is a no-op (same pinned commit), instead of leaving the drift unrepaired.
🚀 Features
- telemetry — report why an install does not auto-update (0d446b7)
- pen-design — let Pen's agent file devkit friction without asking (117dfeb)
- routing — let the agent close Flow 1 with /test and /review --quick (322f6b7)
🐛 Fixes
- session-start — name a frozen local update source (51f2793)
- shopify — fail a schema name over the documented 25 characters (2e4ebf8)
- constraints — stop loading on every JSON and XML edit (cc454a6)
- cli — answer --version and -V instead of an unknown-command error (6dc4743)
- spec-drift — planning artifacts from parallel sessions are not drift (9cd19ac)
- content-audit — re-check delegated findings before reporting (87e97b4)
- wave — refuse an unapproved spec in slice-dispatch (bee343d)
- pen-design — report an unknown groups layout in adapter-check (96e1736)
- pen-design — accept hyphenated token names in design-check and verify (59ebf1b)
- spec-validate — name undeclared files a negated search still matches (1eab0c8)
- spec-deps — hold a spec without a valid approval out of the wave plan (1ba4a82)
- spec-deps — point the duplicate-ID hint at spec-renumber (8680a59)
- hooks — treat a sed range around a grep line as a targeted read (2619226)
- sync — retry the codex guard probe on ETXTBSY and say why it failed (1052cf2)
- spec-deps — list every duplicate spec ID with its paths (2d8b8f5)
- index — leave a CLAUDE.md deleted when the history deletes it (4c21bfc)
- sync — reinstall a plugin whose update keeps the drifted commit (d43d2b9)
- pen-design — keep the file's serialization on design-fonts --write (c038a51)
- pen-design — let design-rebind match hyphenated variable families (2299dc4)
- pen-design — report a rows list beyond eight view groups in adapter-check (40fbc75)
- pen-design — keep a lane note's own text on design-sort --apply --all (0144e36)
- parity — spawn cp by absolute path in write_exec (419d028)
- index — keep gitignored directories out of STRUCTURE.md (0d34d43)
- hooks — skip user-offer hints in headless sessions (f21d21c)
- hooks — let headless sessions wait on their background tasks (b9dd0b9)
- sync — stop forcing ENABLE_TOOL_SEARCH=auto:5 and withdraw it (16968da)
⚡ Performance
- rules — cut code-reuse.md and design-system.md on first code touch (d9469d7)
- sync — raise the Bash auto-background threshold to 30s (8b693e1)
- rules — cut agent-graph.md from 10.3k to 3.4k characters (ab40282)
♻️ Refactoring
- rules — move claude -p automation out of tooling-inventory (6e71490)
- wave — table the slice-dispatch markers and exit stages (421d127)
- content — drop restated contracts from capped payload files (040e129)
📖 Documentation
- usage — record the spec-drift diagnosis and the 3-day snapshot (9573540)
- devkit-usage — work rollout first and prove a finding is current (4c02da1)
- spec-work — name devkit init where the route said project-migrate (12bec4a)
- workflows — re-mark the page after the wave plan change (da52bc3)
- dev-mode — name dev-sync by its maint subcommand (9fa01d3)
- workflows — bring the German page back under the prose limit (5a9e559)
- vision — calibrate the signal to cost parity at equal quality (55464bf)
- workflows — say the agent runs /test and /review --quick itself (09bbdcb)
- decisions — record the devkit-vs-native outcomes (29c76f7)
- evaluation — record the tool-search variant and the lost-work mode (5f77bcf)
- evaluation — state that the pilot covers the autopilot layer only (c7bc6ad)
- evaluation — record the first devkit-vs-native pilot campaign (335b773)
🧪 Tests
- usage-report — record the update-cause column in rollout rows (a3565d5)
- hooks — give each wait-guard test marker a unique directory (348a398)
- affected-map — route rust_only.rs to its own suite (61d57f0)
🏗️ Chores
- devkit-issues — hunt the siblings of every fixed issue (47d3cdc)
- sync — cargo fmt the env withdrawal change (75e96d4)
v0.44.0 — 2026-09-25
Boilerplate skills now sync automatically in the background, the stack-shopify-liquid regression that broke every Shopify Vite build is fixed, and a batch of pen-design fixes from ten real friction reports lands: canvas-edit detection, renumbering, row layouts and a sub-pixel clip false-positive. Update with devkit sync.
33 commits since v0.43.0 · Specs 652
✨ Highlights
🔄 Boilerplate skills sync themselves
A boilerplate rename or fix used to reach a client project only after someone ran devkit skills pull by hand — a Shopify project could resolve a retired skill name for weeks. Session start now pulls each project's boilerplate skills in the background once a day, names what changed at the next start, and a retired name still resolves through the registry's replaces map:
devkit path skill stack-shopify-liquid # -> resolves to sp-theme-scripts via replacesA skill the boilerplate itself dropped is now removed locally too, as long as it was never edited by hand, and a clone over SSH now falls back to HTTPS when the host has no SSH key set up.
🩹 Shopify Vite builds work again
0.43 deleted the stack-shopify-liquid skill on the assumption that every caller had migrated; sp-alpensattel and every other Shopify Vite project still resolved its scripts through devkit path skill stack-shopify-liquid in vite.config.js, several package.json scripts and the pre-commit hook, so npm run build and preflight broke on this release. The scripts are restored — devkit path skill stack-shopify-liquid resolves again without a workaround:
devkit path skill stack-shopify-liquidRun devkit skills pull in the affected project afterwards to move onto the boilerplate's own copy for good (#172).
🎨 pen-design: canvas edits no longer drift silently
A shipped frame's stamp can now carry a content hash of its subtree, including any master it references and every token value it reads — a fill, spacing or text edit made directly in Pen after shipping used to leave the code stamp looking current. design-status.mjs --hash <nr> prints the field for a frame; a mismatch after that reports CANVAS GEAENDERT with the affected code file:
node "$(devkit path skill pen-design)/scripts/design-status.mjs" --hash 24🖌️ pen-design: ten friction reports fixed in one pass
design-sort.mjs --renumber now rewrites every @frame marker spelling (not only comma lists) and the first line of concept files, and keeps mobile/desktop pairs even/odd; design-rebind.mjs accepts quoted suffix frame numbers; design-save.mjs keeps a file's existing pretty or minified format; a new adapter key lays view groups out as rows instead of columns; the K2 clip check now tolerates up to 0.5 px of rounding error instead of flagging it as a clip; the inventory table written into design/AGENTS.md shows each setting's type, allowed values and default plus which child blocks a component accepts; the design-guard hook it wires no longer carries one machine's absolute paths; and setup.md now matches the Code: line the inventory script actually reads (a project following the old wording paired 6 components instead of 47).
What changed for you
Now available
/boilerplate-feedbackfiles a reusable change made in a Shopify, Nuxt/Storyblok or Shopware client project as an issue on its stack's boilerplate — on its own or on request.
Behavior changed
- Guard hooks (branch-switch, restore/checkout, wait-poll, secret-env) no longer block a command that only quotes a trigger word inside a string, commit message or heredoc body — each was hit at least once this cycle.
/visionnow reads a vision file kept outside.agents/context(e.g.docs/VISION.md) as its richest source instead of treating the project as having none.
🚀 Features
- skills — migrate clients to boilerplate skills with the update (f7ade2b)
- skills — add /devkit-boilerplates to keep the boilerplates current (5754853)
- pen-design — report a canvas edit made after a frame was stamped (a2432ce)
- maint — audit the boilerplates against the current payload (cd2d3e2)
- skills — remove skills the boilerplate dropped on the next pull (2cd3db5)
- boilerplate-feedback — file reusable client changes into the boilerplate (0638a20)
🐛 Fixes
- guard — judge a whole-tree restore by its own git segment (373fb26)
- vision — pick up a vision file kept outside .agents/context (2f8212c)
- index — name devkit index-prep in the STRUCTURE header (a4af705)
- guard — ignore loop words inside quoted text in the wait guard (dcb9b9d)
- skills — warn when removing a retired skill fails (ea88474)
- pen-design — tolerate sub-pixel overflow in the K2 clip check (5f1a13c)
- devkit-issues — comment before closing, the trailer close is async (58a22c6)
- design-inventory — show setting types, values and accepted blocks (933ed83)
- design-inventory — write a portable design-guard hook and name it (6ebc0fc)
- guard — ignore branch switches named inside quoted text (6ecd4d8)
- devkit-issues — comment when a Fixes trailer already closed the issue (f20a1ae)
- pen-design — pair components on Code: and flag missing design setup (54e2554)
- guard — treat a quoted grep pattern naming .env as data (3c3cbc8)
- pen-design — point setup.md at the generated inventory file instead of a stale index frame (#175) (5c815d3)
- pen-design — trim canvas-lifecycle.md wording to clear content-budget and content-language (#173) (3b9544a)
- pen-design — broaden @frame marker rewrite, fix mobile/desktop parity, accept suffix rebind numbers (#173) (a6a9ffc)
- pen-design — add adapter groups: rows layout option to design-sort.mjs (#174) (4cb5d22)
- skills — restore stack-shopify-liquid scripts devkit path still resolves (Spec 652) (2659a86)
- skills — fall back to HTTPS when the boilerplate SSH clone fails (6c7bd60)
- help — point dev-sync at its maint subcommand (da009c9)
- boilerplate-feedback — keep client identity out of shared issues (6abce07)
📖 Documentation
- readme — state the glibc 2.39 floor of the Linux binary (271900c)
- evaluation — warn that Harbor drops devkit's user payload (b833837)
- vision — add the repo north star with alignment test (e8ad829)
- design — re-review the design page after the groups adapter key (6860bdc)
- publish — relay token covers the boilerplate repos (ee78fda)
🧪 Tests
- rust-only — count the restored stack-shopify-liquid category (2d7dac7)
v0.43.0 — 2026-09-25
Action required after devkit sync
- Run
devkit initonce (/indexnow does this for you and asks first), then re-run/index— it converts an olderCLAUDE.md -> AGENTS.mdsymlink to the one-line@AGENTS.mdimport Claude Code documents for multi-agent repos.
devkit sync now adds a missing codegraph/context7 MCP server itself instead of printing a command to copy, and asks once per missing optional tool with a plain-language reason instead of hiding all nine behind --optional. Update with devkit sync.
34 commits since v0.42.6
✨ Highlights
🔌 Sync sets up your MCP servers and optional tools itself
A colleague's sync used to end with MCP commands to paste into a terminal and optional tools nobody knew existed. Sync now runs the client's own mcp add for a missing server, offers a working repair for a conflicting one, and asks per optional tool with a one-line reason:
$ devkit sync
✓ MCP claude/codegraph hinzugefügt
Optionale Tools — 3 noch nicht installiert. Ein Nein merkt sich devkit.
1/3 codex
zweite Meinung von einem anderen Modell bei Reviews
Installieren? [y/N]📇 /index sets the project up, not just its context
/index now dry-runs devkit init first, names each pending change and applies it after one yes, so it is the one command to run after every devkit update — not only on a fresh clone:
/index
→ Projekt-Setup: CLAUDE.md wird zum @AGENTS.md-Import. Jetzt anwenden? [Y/n]CLAUDE.md is now the single line @AGENTS.md, matching how Claude Code documents a repo shared with other agents, instead of a symlink that surprised people on ACL'd or synced checkouts. A vault, marketing or docs repo no longer gets a STACK.md full of runtime/deploy questions it has no answer for.
🤖 Ask an agent for devkit's own docs
https://devkit.one-dot.io/llms.txt and /llms-full.txt now exist — the full text is about 95 KB, the 700 KB changelog is only linked — so an agent can answer a setup question from the published docs instead of guessing:
curl https://devkit.one-dot.io/llms-full.txt🎨 Pen canvases sort and group themselves
/pen-design groups canvas frames by their Spur automatically and numbers each group in one pass — a plain "sortier das Canvas" is now enough, and it runs headless when Pen.app is closed:
/pen-design sortier das CanvasWhat changed for you
Now available
devkit tools --missing-optionallists what is not installed yet with its description;devkit tools --install <name>adds one on request.
Behavior changed
- A plugin whose installed commit drifted from its pin gets one automatic
claude plugin updateinstead of only a warning. - A required MCP conflict still stops the sync, but now offers the repair command instead of only naming it.
/indexwritesAGENTS.mdandSTRUCTURE.mdwith the file's existing permissions instead of 0600, which had locked a second service user out of the repo.- Every yes/no question in the CLI reads
[Y/n];jandjastill count as yes. /pen-design's renumber report dropped from 36 KB to 601 bytes on a 168-frame canvas — it now prints only the action lines plus a count,--verbosefor everything.
🚀 Features
- pen-design — a plain 'sortier das Canvas' is enough (edcbb27)
- index — seed STACK.md only where a stack exists (709cddd)
- index — /index brings the project up to date, /onboarding goes (ab0e9fe)
- init — CLAUDE.md becomes a one-line @AGENTS.md import (fd358ac)
- pen-design — put the group name in every view frame name (eb1e445)
- pen-design — run canvas scripts headless when Pen.app is closed (e4111aa)
- pen-design — group canvas frames by Spur with group-block numbers (deb6976)
- design — slop-check flags four taste-skill tells (af970ea)
- docs — publish llms.txt and llms-full.txt (3808d88)
- skills — /onboarding walks a colleague through the full setup (0d9d1b9)
- sync — ask per optional tool and end on the /index hint (f8e0a4b)
- sync — add missing MCPs itself and offer the rest as a prompt (bff298c)
🐛 Fixes
- init — satisfy clippy's byte-string lint in the fence scan (cef17ac)
- scaffold — allowlist Pencil's fileToken in the project gitleaks config (0af63fb)
- pen-design — close Codex's second-round findings on renumbering (6fe59ae)
- pen-design — close Codex's review findings on canvas renumbering (bde33ed)
- close Codex's third-round findings on migration and STACK.md (ace25c1)
- pen-design — make group renumbering hold on a real 168-frame canvas (fe30c48)
- close Codex's second-round findings on init, index and sync (a83ae0c)
- index — publish AGENTS.md and STRUCTURE.md with a readable mode (65c1868)
- design — drop noisy slop patterns, find the ignore file (72db1d0)
- docs — llms-full.txt resolves links against their source page (8a399a9)
- sync — close the gaps Codex found in the auto-setup (19cf2f0)
- maint — content-language names its real command (02704cb)
- maint — rust-only names the real remedy for a shell spawn (197c3a8)
⚡ Performance
- pen-design — design-sort prints only what needs action (54ffc5a)
📖 Documentation
- optional-tools — name the per-tool question a plain sync asks (fa3a9df)
- workflows — re-set the source marker after the STACK.md fix (fadd972)
- pen-design — name group sorting and renumbering in the skill body (9296013)
- bundles — fit the STACK.md seed note into the content budget (b657f23)
- workflows — re-set the source marker after the STACK.md change (064bac3)
- workflows — re-set the source marker after the /index fix (a7bef5b)
- workflows — re-set the source marker after the /index change (14a4834)
🏗️ Chores
- content-language — accept the German CLI output quoted in the 0.43.0 entry (318a1b2)
v0.42.6 — 2026-09-25
The five stack-* skills are retired after four readings found 0 of 237 sessions loading one, their facts now seeded via /index. The ten-spec wave that shipped this also hardened Wave itself: acceptance reads a slice's full log instead of only its last line, and a check that once held a slice for 8h21m is now bounded to 30s. Update with devkit sync.
66 commits since v0.42.5 · Specs 647, 648, 649, 650, 651, 652, 653, 654, 655, 656
✨ Highlights
🧹 The stack-* skills are gone — their facts live in your context bundles
stack-laravel, stack-nuxt, stack-python, stack-shopify-liquid and stack-shopware never got loaded: four straight team-telemetry readings (1/185, 2/234, 0/216, 0/237) found no stack-file session pulling one in. What they carried beyond public framework knowledge — the handful of environment facts no vendor doc states — now seeds automatically into a Laravel or Shopify-Liquid project's STACK.md the moment you index it, in a new project and an already-indexed one alike:
devkit index-prep
# .agents/context/STACK.md gains a ## Agent Environment sectiondevkit skills pull also stops linking any stack-* skill into a project and removes the symlinks it created earlier, and the implementer, /spec-work and /improve-codebase-architecture now read a project-local skill or .agents/context/STACK.md/CONVENTIONS.md instead.
📇 One CrewBuddy fetch skill instead of three
fetch-project-task and fetch-my-project-task are gone; /fetch-task now covers a single task, every open task of a project, and only your own:
/fetch-task 50131
/fetch-task --project 42
/fetch-task --project 42 --my📊 Usage telemetry counts what you actually type and follow
A typed /name slash command counts toward typed_commands whether it lands as a plain line or Claude Code's <command-name> block, and a hint now converts when you follow it by hand — not only when the model calls the skill tool. The checkin and context-usage hints write their own events for the first time, so their conversion rate becomes measurable by 2026-10-24.
🛠️ Wave got eight reliability fixes from running a ten-spec wave on itself
Acceptance and the pre-wave baseline used to read only the last line of a compressed test log — a real rust_only failure in one slice reached main before this was caught. They now follow the rtk recall <id> link test-prep leaves behind and see every red suite. Alongside it: a review package now carries its own stack lens instead of depending on a hand-written brief line, a slice worktree's whole diff is attributed to that slice even when a headless delegate wrote it, and the wave plan names an approved-but-uncommitted spec before it wastes a worktree on it:
devkit spec-deps-check --plan
# UNCOMMITTED: <id> — commit the spec before a wave dispatch⏱️ A wave slice no longer loses hours to a silent hang
spec-validate-prep's advisory reuse-detect call ran without a deadline; when its search stalled, a whole wave slice sat blocked for 8 hours 21 minutes. The call is now bounded to 30 seconds. A separate fix in the official plugin-marketplace audit cut a different multi-minute hang (20+ min) to about 30 seconds the same way — a full-buffer pipe deadlock, not a slow server.
🧭 /vision now asks why the project exists, not only what it does
A new stage reads the oldest commits and decisions for the origin and asks for the value the project adds over today's workaround. A --idea mode runs the same staged interview for a business idea that has no repo yet, sourcing facts from the pitch and a cited market-research pass instead of a codebase. A challenge only you can settle now comes back as a follow-up question instead of being silently smoothed into the draft, and each stage's reasoning is kept in an on-demand depth file instead of being dropped to fit the summary.
What changed for you
Now available
/fetch-task --project <id> [--my]replaces/fetch-project-taskand/fetch-my-project-task./vision --ideainterviews a business idea outside any git repository./capturegets a proactive hint the first time a prompt states a project rule or names an unlinked related repo.- "grill this" now routes to
/brainstorm's frontier rounds; the standalone/grillskill is gone.
Behavior changed
- The five
stack-*skills,/ai-setup-update,/failure-learn,/find-skillsand/design-previeware removed from the payload;devkit syncand/devkit-retrocover what they did. - Codex SessionStart is now detected without a
turn_id(its schema never sends one), so a Codex session reliably getscore.mdand the rest of the payload instead of being silently treated as Claude. - A same-day local experiment with devkit-specific ADHD-mode additions (a Stop-time length gate, a Claude-session precedence line) was reverted; the
i-have-adhdplugin now ships byte-identical to its pinned upstream, with only the existing subagent/Codex hand-off kept. - A
devkit skills pullno longer createsstack-*symlinks and cleans up ones it made earlier. devkit toolsretries once with a refreshed apt index when a required package's install fails on a stale mirror (hit on a fresh runner installinggit-delta), instead of aborting the whole run.
🚀 Features
- spec-deps — name uncommitted specs in the wave plan (9968014)
- telemetry — count typed commands and measure every prompt hint (Spec-656) (d9c8c99)
- capture — prompt hints for project knowledge and related repos (324973d)
- hooks — enforce the adhd length budget at Stop (a43d170)
- vision — capture why a project exists and the value it adds (3218014)
- vision — interview business ideas without a repo (7ab2aea)
- vision — grill unresolved challenge hits as follow-up questions (74bf82e)
- index — seed an Agent Environment section for Laravel and Shopify (Spec-647) (d31eb03)
- vision — keep the interview's reasoning in on-demand depth files (64d058a)
- skills — route 'grill this' to /brainstorm (8ba5b3f)
🐛 Fixes
- cleanroom — run the spec lifecycle check CI's shard 1 runs (2c389a6)
- tools — refresh the apt index once when a package install fails (8933c1e)
- wave — read the full test log behind an rtk recall link (088195e)
- design-inventory — keep pre-648 recipes working after the generator move (Spec 648, 652) (b1497fe)
- wave — stage a slice whose worker already staged a deletion (33ff68a)
- tools — realign the memsearch pin and the i-have-adhd consumer rows (339d000)
- wave — count a slice worktree's whole diff as the slice's own (6c209e4)
- review — carry the stack lens in the review package itself (b6e5c6a)
- spec-validate-prep — bound the advisory reuse-detect call (3b43796)
- i-have-adhd — stop focus mode from overriding reply length (751d76a)
- wave — accept a Files to Modify glob such as <suite>.*.obs (541a014)
- tool-pin-audit — compare prerelease versions instead of dropping them (b131122)
- wave — name failing suites from a compressed test-prep report (fcb41ba)
- tests — follow the design-preview and warp-skill-doctor removals (c29c905)
- index-prep — accept ./AGENTS.md and absolute CLAUDE.md links (86422d0)
- tool-pin-audit — read marketplace.json raw instead of piping base64 (533b224)
- wave — keep the coordinator's own replies out of the sweep inbox (a6db6e5)
- wave — classify a contract error before any baseline keyword (0573e2e)
- wave — read a turn parked on a background shell as active (1673322)
- wave — refuse an uncommitted spec before the slice worktree exists (101b6c6)
- hooks — recognize Codex SessionStart without a turn_id (5e83c4b)
- hooks — carry the adhd precedence line into Claude sessions (c0bd7c8)
- tests — route the skill-lint and first-seen baselines to a suite (9f0f3ea)
- tools — name python3's real consumers in tools.json (7b2cf62)
- tests — route the devkit-usage maintainer skill to skills_smoke (d9d9860)
- telemetry — trim the devkit version sent with each upload (a7b6e8c)
- guard — stop blocking a double-quoted regex as a .env glob (f53947d)
⚡ Performance
- test-prep — run only the changed map rows' suites on a map edit (95c3c90)
♻️ Refactoring
- skills — fold /failure-learn into /devkit-retro (Spec-654) (5e3e293)
- skills — delete the five stack-* skills (Spec-652) (9667db2)
- skills — fold the project fetch skills into fetch-task (Spec-655) (6fa06d6)
- skills — stop linking stack-* lenses and remove old links (Spec-650) (a110b4c)
- routing — take stack knowledge from project context, not stack skills (Spec-651) (29e9a93)
- adhd — ship the pinned plugin as-is, drop devkit additions (1abf9ef)
- pen-design — own the Nuxt component-registry generator (Spec-648) (41fca8e)
- usage — retire the Stack-Lens metric (Spec-649) (da318b1)
- skills — remove /ai-setup-update (Spec-653) (3359226)
- skills — remove grill, find-skills and design-preview (0d0e56d)
📖 Documentation
- specs — mark archived 638 completed for its location (520b2bd)
- reference — decision rows for Specs 638, 647-656 (36c09bc)
- specs — archive 638, stopped by its own measurement gate (001a310)
- spec-work — stop asking Main to hand-write the review stack lens (0b91e08)
- wave — brief Rust slices to run cargo fmt --check before worker_done (12f79a3)
- tools — record the codegraph deprioritize adoption (67e4712)
- specs — add 647-652 from the 2026-09-24 skill and hint audit (029b6ed)
- specs — add 653-656 from the 2026-09-24 skill and hint audit (9a7831e)
- brainstorm — 009 hints that convert (Spec 656) (4c61e94)
- reference — drop ten watch-list repos and thirteen native parks (653774a)
🧪 Tests
- hooks — write post_tool's fake executables without a leaked write fd (f952ffa)
- rules — exempt the removed grill, find-skills and design-preview rows (98a9ec8)
🏗️ Chores
- tools — record the i-have-adhd review at upstream 839872f (c1a43dc)
- tools — i-have-adhd pin to upstream 839872f (9097881)
- codegraph — deprioritize parity harness and skill scripts in ranking (a9d250c)
- tools — rtk 0.50.0, prime-agent 0.9.6, memsearch 0.4.21 (8ecab40)
- maint — drop warp-skill-doctor and candidate-audit-check (6b03a04)
- usage — 2026-09-24 snapshot and expectation review (f7580ff)
v0.42.5 — 2026-09-24
devkit sync in a terminal now shows one spinner and one result row per phase plus a numbered to-do list with one command each — the 53-line log a teammate got from 0.42.3 renders as 20 lines. Update with devkit sync.
5 commits since v0.42.4 · Specs 646
✨ Highlights
🧭 Sync shows phases and a to-do list
Update, Skills & Regeln, Tools, Editor-Plugins, MCP-Server and Upgrades each get a spinner and a ✓/!/✗ row; npm output, installer JSON and plugin inventory lines stay hidden, and every action lands under Zu tun with exactly one command, e.g. gh auth login && devkit sync for a missing GitHub login.
devkit sync # phase view
devkit sync --verbose # the previous line-by-line outputWhat changed for you
Now available
devkit sync --verboseprints the previous line-by-line output on a terminal.
Behavior changed
- Missing MCP servers become one to-do per runtime whose command chains all
claude mcp add …(orcodex mcp add …) calls with&&. - Piped, CI,
NO_COLORandDEVKIT_PLAIN=1runs ofdevkit syncprint byte-identical output to 0.42.4. /spec-workreviews refuse to start without a reviewer brief instead of returning a pass that checked only one checklist section.
🚀 Features
- sync — phase view with spinner and to-do list (Spec-646) (63e9d4a)
🐛 Fixes
- spec-work — name the review brief on stdin and its stack lens (Spec 646) (9d02825)
- review-runtime — refuse a dispatch without a role brief (Spec 646) (e8a8adf)
📖 Documentation
- reference — decision rows for Specs 646 (2034c73)
- spec — Spec 646 — sync phase view and to-do list (8b207e7)
v0.42.4 — 2026-09-24
Macs that updated from devkit 0.40.0 no longer receive a Linux build: the legacy download now carries a binary for every platform, and a broken install repairs itself on the next install.sh run. Update with devkit sync.
3 commits since v0.42.3
What changed for you
Action required
devkitfails withexec format errororcannot execute binary fileafter an update from 0.40.0 → runcurl -fsSL https://devkit.one-dot.io/install.sh | bashonce; it installs 0.42.4 for your platform.
Behavior changed
- Clients still on 0.40.0 now download one package with a binary for macOS arm64/x86_64 and Linux arm64/x86_64 and a launcher that picks the right one, instead of a copy of the Linux x86_64 build.
devkit install/devkit syncreplace a same-version folder whose only difference is itsbin/devkit(moved aside asversions/.replaced-<v>.<id>) instead of refusing with "existiert bereits mit anderem Inhalt".
🐛 Fixes
- release — publish a universal payload as the legacy alias (b0f7d08)
- sync — restage a same-version folder whose only drift is bin/ (9248ea2)
- release-prep — keep a tagged release's approval valid past new commits (9e89d87)
v0.42.3 — 2026-09-24
Friction reports from people without repo access now arrive: when gh cannot file, /friction-feedback uses the devkit relay. Update with devkit sync.
3 commits since v0.42.2 · Specs 644, 645
What changed for you
Behavior changed
devkit feedback-issue --confirmfiles through the relay whenghis missing or fails; the issue URL comes back with exit 0, and exit 3 with the manual link now means bothghand the relay failed.- Every friction report names its reporter (
reporter:from your gituser.name), since relay-filed issues all carry the same author.
🚀 Features
- feedback-issue — file through the relay when gh cannot (Spec 645) (Spec 644) (5de7258)
🐛 Fixes
- feedback-issue — name the reporter; harden the relay call and tests (Spec 645) (582ff54)
📖 Documentation
- reference — decision row for Spec 645 (7ab1b69)
v0.42.2 — 2026-09-24
Spec and review commands measure from the right base again, reuse-detect no longer hangs on a large diff, and pen-design reads large canvases completely. Update with devkit sync.
20 commits since v0.42.1 · Specs 644, 645
What changed for you
Behavior changed
spec-drift-check,spec-review-prep,review-prepand the fallow audit measure from whichever ofmainandorigin/mainyour branch is closer to: a stale localmainno longer reports merged work as drift, and unpushed local commits no longer do either (#161).review-runtimeaccepts zero-padded spec IDs such as001(#160), and/spec-worksendsREVIEW_RUNTIME=claudeto the native review instead of a dispatch that refuses it (#159).spec-review-prepno longer hangs whenreuse-detectgets a large diff (#158).- pen-design:
design-statusreads boards past the 64 KB pen output cap,design-checkhonoursPEN_FILE, anddesign-readno longer aborts a read that completed (#157).
🚀 Features
- api — relay friction reports into issues server-side (Spec 644) (d16f9d1)
🐛 Fixes
- release-prep — anchor on the newest release tag merged into HEAD (c01e9cb)
- pen-design — design-read.mjs pagination stops itself, not a pre-count (62d4f72)
- pen-design — design-check.mjs honors PEN_FILE without a positional arg (2412109)
- pen-design — page design-status.mjs past the 64 KB pen CLI cap (882f6eb)
- api — answer 502 when GitHub's 201 carries no issue number (Spec 644) (fab450c)
- reuse-detect — write child stdin on a thread to stop pipe deadlock (090e5e1)
- git — measure diffs from the fresher of main and origin/main (b409df4)
- review-runtime — route REVIEW_RUNTIME=claude to native dispatch (3397671)
- review-runtime — normalize zero-padded --spec IDs (9f5e312)
- spec-drift-check — anchor base on origin tracking branch, not stale local main (4c5b39a)
📖 Documentation
- reference — decision row for Spec 644 (ae61147)
- workflows — re-set the marker after the review-runtime routing fix (e90a85f)
🧪 Tests
- design_guard — tolerate a hook that exits before reading stdin (4e7f4f9)
- write executable stubs through parity::support::write_exec (dd6cbab)
- pen-design — follow the windowed status read; satisfy clippy 1.98 (b67399e)
- parity — write executable stubs through an external cp (655bf77)
- spec-complete — cover closing a reviewed nested-repo spec (7d04998)
- pi_materialize — sync a private payload copy, not the live checkout (7c9af04)
No commit type
- Add specs 644 and 645 for a public feedback relay endpoint (Spec 644, 645) (fb3bc94)
v0.42.1 — 2026-09-24
Installs on 0.40.0 refused every release since 0.41.0 at the Codex guard check; 0.42.1 ships the files their sync checks for, so they update again. Update with devkit sync.
3 commits since v0.42.0
What changed for you
Behavior changed
devkit syncon a 0.40.0 install accepts this release instead of refusing it on the Codex guard check (#163).
🐛 Fixes
- release-build — ship shims so 0.40.0 installs accept new releases (e3e0fc3)
🧪 Tests
- pi_materialize — name the sync error when Pi AGENTS.md is missing (6b955df)
- release_workflow — write executables through an external cp (cf8ac2f)
v0.42.0 — 2026-09-24
Action required after devkit sync
- Run
devkit init, then/index, in every project:AGENTS.mdbecomes the instruction source andCLAUDE.mdits symlink (Spec 630) —syncdoes not migrate this,devkit doctoronly warns. - Pi implements for you: install bubblewrap (
bwrap) — without itpi implementrefuses the dispatch (Spec 642). - Codex: run
devkit doctor; if it flags[features] hooks = falsein~/.codex/config.toml, remove that line, otherwise no devkit hook runs. - You pinned
DEVKIT_RUNTIME_IMPLEMENT=autohandorinterpreter: pick another runtime, both are retired.
A Spec is now earned by complexity, a handoff or an open decision, and risk alone gets an independent review — over 161 Specs, BLOCK hit 7/7 at 7+ Steps but 7/22 at 1-3 files. Pi now implements under hooks and a bwrap sandbox, and /vision anchors a project's north star. Update with devkit sync.
238 commits since v0.41.0 · Specs 614, 615, 616, 617, 618, 619, 620, 621, 622, 623, 624, 625, 626, 627, 628, 629, 630, 631, 632, 633, 634, 635, 636, 637, 638, 639, 641, 642
✨ Highlights
📏 A Spec is earned, not the default
More than 5 Steps, or 6+ files over 2+ subsystems, a handoff, an open decision or a request earn a Spec; everything else runs direct or via /delegate. Parser, secret, permission, write-path and release changes get an independent /review — 16/21 Specs at 7+ files were blocked, 14 small ones ran 2+ rounds without a BLOCK.
/review🧭 /vision — a project's north star
A staged interview writes goal, non-goals and decision principles to .agents/context/VISION.md, and /spec, /brainstorm and /challenge check against it; --calibrate reopens only what a named conflict touches.
/vision
/vision --calibrate "a non-goal got hit twice"🔒 Pi delegates run guarded
pi implement now loads the devkit PreToolUse/PostToolUse hooks (a git reset --hard from Pi is blocked), runs inside a fail-closed bwrap sandbox, and cannot persist a new MCP server into Pi's global config.
DEVKIT_PI_SANDBOX=off # explicit opt-out only🏎️ Routing on faster, cheaper models
Pi on anthropic/claude-sonnet-5 leads light, medium and Effort-high Specs (one fix brief: 14 s vs 124 s on Claude implement); Codex and Pi move to GPT-6 Sol and Luna at half the GPT-5.6 price; pi implement skips context-file and skill discovery (1390 s vs 1562 s over three Specs, 39 verifies green).
devkit runtime-route implement⚡ Leaner Spec and Wave runs
Low and medium Specs get one review round and fix only security, data-loss or failed-AC findings (slice 637 had spent 64 min and 298 tool calls on 12 edits). Wave slices orient from the readiness block, which re-reading had cost 877k of 1.08M output tokens across ten sampled transcripts, and run the gate once instead of 56 times.
/spec-work 642🌐 Browser checks never write to production
Before the first state-changing action, agent-browser resolves which backend the dev server talks to and stops unless it is loopback, .local/.test or a documented dev host; read-only checks stay exempt.
/agent-browser check the checkout flow🎨 pen-design: starter canvas and guarded canvases
A new project seeds a ready canvas (eleven section masters on 25 standard variables, 0 design-check findings) instead of five drawing rounds, and no checker reads or saves a canvas other than the one in front.
design-seed.mjs --from-template starter🖥️ Visible progress for install, sync and tools
Interactive terminals show sections, spinners, elapsed time and the real error of a failed tool install instead of a silent step; piped and CI output stays byte-identical.
devkit syncWhat changed for you
Now available
/visionwrites and recalibrates.agents/context/VISION.md.devkit toolsinstalls the matching LSP plugin when its language server is onPATH(Spec 618).devkit design-tidy --writesortsdesign/into its standard layout.- The docs site has one setup page per routed harness — install, sign-in and check for all nine.
Behavior changed
/spec-workno longer commits each green Step; finish a passed Spec with/commit.- Every v2 Spec gets the independent implementation review (Spec 641); a review reports a finding class once instead of round by round.
- Every question to you goes through
AskUserQuestion. - Kimi leaves the implement rules, DSH stays a fallback; autohand and interpreter are gone.
- The secret-file guard no longer blocks safe
rg,jqand docs commands. devkit initnames every leftover of the legacy npx ai-setup, and asks before replacing a project context7 entry.
🚀 Features
- release-prep — a local clean-room pass replaces the hosted CI gate (2a7b813)
- audit-gate — --append writes the missing decision rows (2c96b35)
- release-prep — manual post-update steps open the changelog entry (e0b9a86)
- vision — interview and calibrate a project's north star (4ca9a96)
- init — devkit init names every legacy npx-ai-setup leftover (Spec 637) (5bcdca8)
- init — report every legacy ai-setup leftover (Spec 639) (3ebb2f7)
- review — report a finding class once, park only on real blockers (97bdcd2)
- spec — every v2 spec gets the independent implementation review (Spec 641) (7406773)
- spec-renumber — move a spec to a free ID without losing approval (5f53377)
- design — agents sort design/ themselves with design-tidy --write (645a76c)
- design — add devkit design-tidy to organize design/ folder structure consistently (ceda3fd)
- rules — every question to the human goes through AskUserQuestion (266c7c7)
- pi — pi implement runs inside a bwrap sandbox (Spec 642) (bc16ba6)
- wave — slices implement through headless Pi/DSH when the route names it (Spec 616) (d9a0b4d)
- spec-finish — refuse completion while declined review lines are unruled (Spec 623) (2cf0aee)
- run-cost — report repeated tool calls with line anchors (Spec 621) (f6218c3)
- spec — specs name up to five implied inputs, reviewer checks them (Spec 624) (3155766)
- skills — read-only shell preload in skills, gated by skill-lint (Spec 619) (92b7704)
- pen-design — canvas check covers every building block (Spec 627) (620bc65)
- tools — install LSP plugins when the server is on PATH (Spec 618) (afe14df)
- review — reviewer grades spec-silent behavior and lists declined (Spec 622) (672b199)
- pi — pi implement skips context-file and skill discovery (Spec 625) (07eb41e)
- pen-design — a new project starts from a starter canvas (6ecff16)
- routing — Pi on Claude Sonnet also leads Effort high specs (Spec 630) (02561df)
- routing — Pi on Claude Sonnet leads light and medium specs (8b44ae5)
- routing — Claude leads light and medium-effort implement work (e28ea65)
- init — AGENTS.md is the instruction source (Spec 630) (db38749)
- hooks — a design guard keeps Pen's agent out of code (Spec 628) (e2af170)
- pen-design — icon sheet reads a Liquid snippet (Spec 636) (590aa9f)
- pen-design — sheets fill from the code (Spec 632) (027a497)
- pen-design — shipped frames get their own zone (Spec 626) (fc41f34)
- pen-design — an imported page becomes components (Spec 631) (55038a0)
- pen-design — one rule source for every drawing agent (Spec 627) (b1c06b5)
- quality-gate — a duplicate spec ID reddens the gate (Spec 634) (b9f973e)
- tool-review — read an npm upstream, drop three false surfaces (Spec 633) (0cd9eb4)
- pen-design — the canvas check covers every building block (Spec 625) (d2e9749)
- pen-design — design-save saves the front canvas from the terminal (8011300)
- design-inventory — pair numbered canvas masters with code (b02b9da)
- pen-design — design-rebind binds an imported frame to the tokens (9893101)
- delegate — block MCP installs in Pi delegates (05e5d4d)
- tool-pin-audit — flag installs newer than their review (0eac4d9)
- spec-validate — flag cargo test --lib over a bin-only module (Spec 620) (138efee)
- skills — run failure-learn forked, lint forked AskUserQuestion (Spec 620) (8d4f1ac)
- delegate — Luna explore at high, codex runs unattended (1fccd0f)
- routing — move codex/pi to GPT-6 Sol and Luna (59de382)
- agent-browser — block writes when the dev server talks to prod (0f0dbe9)
- wave — sweep classifies every escalation into a fixed class (Spec 615) (b78579a)
- devkit — add fancy terminal UI for install/sync/tools, fix pen-desi (5183bfa)
- wave — the slice supervisor implements every slice (Spec 616) (193b6de)
- wave — slice-dispatch binds the readiness pack at dispatch (Spec 614) (e17559c)
- release-prep — assemble writes the changelog entry, not the model (a8116f4)
- maint — session hint names the changelog backlog (8161fa4)
- wave — reintegrate resolves docs-marker-only conflicts itself (b7bf5a2)
- pen-design — components sheet of refs, checked by S1 (a7831d5)
🐛 Fixes
- design-tidy — call support git_ok instead of a private copy (0b86b9f)
- release-prep — match the German action-block title in assemble and card (6500dbb)
- hooks — mask an rg pattern in any pipeline segment, not only the first (cab3733)
- wave-prep — refuse a slice whose spec is blocked, paused or completed (Spec 638) (e88bf8f)
- wave-prep — a working Codex slice reads as active, not idle (b51a750)
- spec-review-prep — collect scoped paths from nested git repos (76c8467)
- hooks — a sleep after reading a finished task is no background wait (82d0827)
- grill — accept space-separated prerequisite ids (46bf981)
- release-build — run the content contract before the target binary lands (83c0cbb)
- wave-prep — a merge that could not write a locked index is no merge (6b6d852)
- wave-prep — a slice retry keeps the implement tier's model and effort (Spec 637) (6a61aeb)
- index — give framework-less Node repos their own stack profile (5cde0cf)
- test-prep — print the failing output again (Spec 637) (bc57d1d)
- specs — move the legacy-scan spec to 643 after a second 639 (e3a9b5c)
- doctor — keep parallel codex_features_hooks tests in separate dirs (964d24a)
- spec — complexity or a handoff earns a Spec, risk earns a review (0a570fb)
- wave-prep — keep review ledgers at teardown, read only a real red list (9b9fe75)
- init — remove the .mcp.json transaction dir after success (48db8dc)
- init — show one plain usage line, move flags to special cases (93ac136)
- spec — git takes code back, so direct and /delegate are the default (1291a53)
- tools — register the four LSP plugins Spec 618 added (9345da8)
- init — ask before replacing a project context7 entry (fb9b3be)
- rules — ROUTE=judge means write the test, not open a Spec (5e44c42)
- rules — route small work direct or via /delegate, not into a Spec (3a6169e)
- review-runtime — a sentinel named inside a sentence is no verdict (Spec 641) (4b29687)
- spec-wave-approve — name the slice's worktree to the overlap check (Spec 637) (7d46294)
- specs — renumber three spec IDs another clone had taken (38383d1)
- wave — coordinator owns task-update; turn budget counts Steps only (Spec 638, 639) (01be726)
- spec-deps-check — never read the caller's own worktree as a sibling (Spec 637) (8df9584)
- spec-validate — an unparsable verify blocks a v2 spec outside authoring (Spec 637) (05ea3df)
- wave — catch a slice parked on a Codex dialog before it goes silent (3188990)
- specs — carry the new IDs into the renumbered spec titles (fb25ca4)
- specs — renumber this clone's duplicate spec IDs to 639-641 (1ee2a77)
- wave — a blocked slice reports through worker_done, not task-update (5178d3c)
- spec-review-prep — bound the Committed diff at HEAD (Spec 621) (9abd447)
- spec-validate — a cargo --lib verify over a bin-only module is an error (d3ed877)
- wave-prep — a numbered summary above an open prompt is no dialog (d30486d)
- wave-prep — print the terminal a slice retry landed in (82f89eb)
- reference — drop the notes folders of removed watch-list entries (c8297db)
- sync — record an older release under a dev build as a no-op fetch (8b7d2c7)
- hooks — let jq filters name the env key without tripping the guard (cff3dae)
- wave-prep — refuse a slice whose files a live sibling still owns (6512b57)
- pen-design — design-check flags a radius that ignores its frame (225ca31)
- wave-prep — name the red targets of a baseline instead of hiding them (55c5bc2)
- docs-drift — say the marker is a digest, name the real command (e18618b)
- codex — name the frozen CLI copy behind a code-mode host skew (6eacb22)
- delegate-return — skip main's own mirrored deletions (90926e6)
- orca-detect — end the --print-bin output with a newline (8949220)
- context-drift-check — satisfy clippy manual_contains in evidence skip (d8953d0)
- test-prep — narrow node --test the same as vitest/jest/pytest (c7689b7)
- index-prep — tell non-Claude agents to read the @-imports themselves (fb62f21)
- index-prep — only @-import RELATED.md when it has real content (bd1ac77)
- index-prep — rewrite the context-imports block in place (1dd58f1)
- index-prep — detect a one-level-deep workspace stack profile (bf0d0de)
- index-prep — detect docker-compose.yml and Coolify for Hosting & Deploy (3020d8a)
- gotcha-recall — warn on Critical entries a non-## heading or missing Trigger hides (c7e1a9e)
- context-drift-check — skip CLAUDE.md/AGENTS.md copies under a verification/evidence assets tree (5e393fe)
- context-drift-check — resolve refs after
cd <dir> &&relative to that dir (79d1245) - context-drift-check — resolve nested AGENTS.md refs relative to its own directory (008cde1)
- context-drift-check — dedupe scanned CLAUDE.md/AGENTS.md by realpath (Spec 630) (ee8b6b6)
- sync — refuse a release payload that breaks the content contract (a9d7b0a)
- sync — name repeated identical fetch failures in SessionStart (ee73d5c)
- sync — prune retained stage candidates before a new attempt (77ebf03)
- sync — rewrite stale devkit-owned Codex hook paths on wire (e01ffb3)
- doctor — verify the Codex hooks feature flag and command resolution (47da436)
- hooks — treat a regex escape in a quoted rg pattern as data (11f914b)
- spec — check docs facts in review, no waiver for docs pages (Spec 631) (3e664be)
- review — fall through Kimi quota and record the answering runtime (515abc1)
- routing — keep dsh as an implement fallback (ae02b15)
- hooks — let echo/printf prose name the secret env file (c3ad8d5)
- tests — map content/switches.json to the refs suite (ea08866)
- pi — refuse Claude subscription OAuth for pi delegates (149eb28)
- pi — pi implement runs under the devkit tool hooks (a85cf09)
- tests — retry a fixture's rustc compile before failing (40e3a65)
- prime-run — name a provider usage limit as a quota setup defect (33de6a1)
- sync — a fixture DEVKIT_HOME no longer rewires the PATH link (19a5ddd)
- deps-check — a retry slice spec-628b maps to spec 628 (24a678a)
- wave — a Rust slice runs clippy before worker_done (1258f0c)
- pen-design — THEME FEHLT needs a themed variable (Spec 635) (e68e61d)
- pen-design — --promote works in Pen, and a rolled-back block fails (aeb2228)
- wave — a red acceptance names the suites that failed (c2b6822)
- switches — register DEVKIT_SPEC_ID_FETCH_MINUTES (Spec 634) (5765fca)
- delegate — a memsearch-dsh probe timeout is transient, not a verdict (54a5a79)
- wave — reintegrate waits out a foreign index.lock and says why (b559608)
- pen-design — design-check names a top-level parent "Ebene 0" (Spec 625) (ecaf575)
- wave — a slice brief owns its own spec file for the lifecycle (f2b418a)
- wave — the baseline names the suites a red runner failed (00638c6)
- spec-validate — resolve symlinks before the repo-path check (b39c469)
- tests — compare the physical path in the toolchain probe test (dc30394)
- reference — drop notes folders whose watch-list rows are gone (0849184)
- pen-design — bring the gate on main back to green (45411ae)
- pen-design — design-status leaves system sheets out of the drafts (2fc577a)
- design-inventory — an unknown profile names the starters that exist (406e693)
- stack-nuxt — the registry scans srcDir/components first (d9389c7)
- pen-design — an optional template key needs no form per stack (ac3be7a)
- pen-design — the token seed is an execute call pen interactive runs (468d23b)
- pen-design — design-fonts refuses a file Pen.app has open in front (cc55f18)
- pen-design — count display-face lines per parent, add head-gap check (b1d6c32)
- pen-design — design-tokens slashes a project's own namespaces (f599ba6)
- pen-design — no checker reads or writes a canvas that is not in front (2d32fac)
- design-verify — read page frames in windows, measure heading gaps (ccd0a3f)
- spec-readiness — a missing affected map is advisory, not unresolved (4a31dc8)
- pen-design — design-tokens slashes a project's own namespaces (b037d1a)
- pen-design — no checker reads or writes a canvas that is not in front (d32f741)
- tool-pin-audit — report a corepack shim's own version (0e4e8a3)
- tests — isolate fixture repos from an inherited GIT_DIR (4bf67f7)
- spec-update — name the command that prints the contract digest (Spec 620) (43d8005)
- runtime-route — bound probes in-process instead of via timeout(1) (91a8547)
- hooks — codegraph gate ignores paths absent from the checkout (bc86602)
- runtime — resource lookups wait out a running sync (7f7dd72)
- remote-exec — clarify SSH host allowlist and session restart requirement (21dce06)
- spec-work — stop committing each green Step (ac6d9c8)
⚡ Performance
- spec-work — a lite path for low and medium specs (918522c)
- wave — cut the slice work that caught nothing in wave 2026-09-24 (1f36026)
- release — reuse artifacts and build targets in parallel (Spec 617) (e515216)
♻️ Refactoring
- roles — tune implementer and reviewer prompts to vendor docs (f6061ab)
- spec-work — retire the native Claude implementer fork (8813d42)
- delegate — retire autohand and interpreter runtimes (aef7679)
- pen-design — prose on one spine (Spec 629) (7d132a4)
📖 Documentation
- reference — decision rows for Specs 614-643 (f9f7107)
- agents — make /devkit-retro on request, not a completion step (948d8ed)
- workflows — re-set the marker after /vision wiring (0c0afaa)
- workflows — re-set the marker after merging main (cd2aa25)
- workflows — re-set the marker after the complexity route (f2a3d85)
- workflows — re-set the marker after the spec route simplification (cb9c4c0)
- workflows — re-set the marker after the spec routing edit (359d07c)
- design — re-set the marker after the design-tidy agent rule (91e4871)
- design — re-set marker after source changes (8afe537)
- workflows — re-set the marker after the question-rule edit (78e0400)
- spec — rebind the approval digest of Spec 641 after its renumber (9b0a890)
- spec — park Spec 638 on its Step 0 measurement gate (9da24df)
- workflows — re-set the marker after the wave watcher edit (282a560)
- spec — bind the approval digests of Specs 637 and 638 (80d708c)
- spec — gate Spec 638 on a 14/15 uncorrected-map measurement (689e262)
- workflows — re-set the marker after the index skill edit (911d466)
- index — name the RELATED.md gate and root-relative context paths (8ae2ebc)
- spec — draft optional task-map generation phase for index-prep (Spec 638) (4416fab)
- spec — Spec-637 contract to retire the review waiver (2397e06)
- harnesses — Spec-631 one setup page per routed harness (98df5c3)
- design — re-set the marker after the starter template (7330655)
- specs — 630 runs pi implement inside a bwrap sandbox (a3672ad)
- spec — draft init legacy ai-setup cleanup detection (#150) (615cf0b)
- backlog — park the boilerplate canvas idea (859d9d2)
- specs — renumber the pen-design drafts 617-620 to 626-629 (f993519)
- workflows — re-set the docs-source marker after the wave auto rule (f05c731)
- specs — 628 guards the drawing session with a hook (cb829b3)
- specs — 630 AGENTS.md becomes the instruction source (26a476f)
- specs — 629 pen-design prose on one spine (dd13eaf)
- specs — draft 635 and 636 (5966c7d)
- specs — draft 631-634 from the pen-design end-to-end run (328b8be)
- specs — renumber the pen-design specs 617-620 to 625-628 (63b4de8)
- specs — 617 retires the rules node everywhere, preamble moves (364ca97)
- design — re-set the docs-source marker after the --pairs line (3065960)
- specs — draft 617-620 for one pen-design rule set every agent keeps (993ff0f)
- specs — draft 617-620 for one pen-design rule set every agent keeps (98bb524)
- changelog — record unreleased changes including Spec 617 (a093b17)
- reference — drop four zero-yield watch-list entries (f12f56d)
- reference — drop three dead watch-list entries (78d72ea)
- tools — review codex 0.148.0 -> 0.156.1 (534f26b)
- context — name the cargo target for maint unit tests (Spec 620) (2e89904)
- reference — scan obra/superpowers v6.4.1 (caeac19)
- workflows — re-certify the marker after the spec-work commit rule change (1df174b)
- specs — add specs 614-616 for wave slice hardening (74ab5a5)
- changelog — v0.41.0 lists the digest fix it shipped (922 commits) (4c8965f)
🧪 Tests
- map — drop the shim rows Spec 625 no longer creates (1fc4ace)
- map — route pi argv and the Spec 625 implement shim to pi_delegate (16b67df)
- map — content/switches.json maps to refs (Spec 628) (bafbad1)
- content-language — a Rust target for the language baseline (Spec 629) (c1ff141)
- make install, pi_delegate and runtime_inventory pass on macOS (fc370e9)
- drop the 471 parity fixtures no target reads anymore (a2c5e2f)
🏗️ Chores
- hooks — rustfmt the design-tidy match arm (6b5f2a4)
- hooks — rustfmt design_guard match arm (f04aeba)
- tests — rustfmt two pen-design suites (cf26f47)
- tools — pen 0.3.9, canvas on format 2.19 (e4e5dc4)
- tools — review nine audit rows, bump four pins (e9dbda8)
- ignore reference-ledger flock files (111c666)
- autohand — untrack the machine-local memory log (37ebfe9)
- autohand — untrack the machine-local memory log (b7bbab4)
- release — skip test shards when ci.yml is green on the tagged SHA (f237dec)
No commit type
- Revert "refactor(spec-work): retire the native Claude implementer fork" (bf42d59)
- Reapply "feat(routing): Pi on Claude Sonnet leads light and medium specs" (9f1e784)
- Revert "fix(pi): refuse Claude subscription OAuth for pi delegates" (903d685)
- Revert "feat(routing): Pi on Claude Sonnet leads light and medium specs" (ecf529f)
- Add specs 618–624 for LSP plugins, skill shell preload, run-cost repeats (ca76946)
v0.41.0 — 2026-09-23
devkit is now one compiled Rust binary: 51,000 shell lines are gone, a Bash call pays 22 ms of hook time instead of 155, and jq and node are no longer required. Routing now picks the harness for each spec, pi can implement, and a wave plan that needed 7 waves needs 3. Update with devkit sync.
922 commits since v0.40.0 · Specs 426, 453, 454, 459, 460, 461, 464, 465, 471, 472, 473, 474, 475, 476, 477, 478, 479, 480, 481, 482, 483, 484, 485, 486, 487, 488, 489, 490, 491, 492, 493, 494, 495, 496, 497, 498, 499, 507, 514, 515, 516, 517, 518, 519, 520, 521, 522, 523, 525, 526, 527, 528, 529, 530, 531, 532, 533, 534, 535, 536, 537, 538, 539, 540, 541, 542, 543, 544, 545, 546, 547, 548, 549, 550, 551, 552, 553, 554, 555, 556, 557, 558, 559, 560, 561, 568, 569, 570, 571, 572, 573, 574, 575, 576, 577, 578, 579, 580, 581, 582, 583, 584, 585, 586, 587, 588, 589, 590, 591, 592, 593, 594, 595, 596, 597, 598, 599, 600, 601, 602, 603, 604, 605, 606, 607, 608, 609, 610, 611, 612, 613
Breaking Changes
- The shell runtime is deleted; the compiled binary is the only devkit (89ff391) Migration: a source checkout no longer carries a runnable devkit — build it with
cargo build --release -p devkitor install a release withdevkit sync. - The shell hook dispatcher and its 16 policy scripts are deleted (77ca518) Migration:
DEVKIT_HOOK_SHELL_DISPATCHis gone; a checkout without a built binary has no PreToolUse/UserPromptSubmit policies untilcargo build --release -p devkitordevkit sync. devkit project-migrateno longer migrates npx-ai-setup projects (cbff4ce) Migration: remove leftovers such as.ai-setup.jsonand its copied template files by hand.
✨ Highlights
🦀 devkit is one Rust binary — and every call got faster
The Bash entry, lib/, every content/scripts/*.sh, all shipped hooks and all 57 maintainer tools now run inside one signed binary per platform, and 51,000 shell lines are deleted. A Bash call pays 22 ms of hook time instead of 155, a script call through devkit run takes 12 ms instead of 98, and jq and node are no longer needed on the machine.
devkit sync🧭 Smart routing picks the harness for each spec
devkit runtime-route reads a spec's Effort, Risk and Class and picks the harness: high risk to Claude or Codex, light work to pi or dsh, everything else to Prime. It combines the native provider catalogs with your own policy, and a runtime that failed to start is skipped for 24 h.
devkit runtime-route implement --spec devkit/specs/<NNN>-<slug>.md🤖 More harnesses can implement, and a cut-off run resumes
pi now implements in its own worktree with a 3,600 s bound, and --continue-from resumes a cut-off run with its edits instead of a hand-exported patch. With codegraph, one pi lookup took 3 turns and ~31k tokens instead of 9 turns and ~119k. Prime's runner is native, and its Orca start bound drops from 120 s to 30 s.
devkit delegate-visible pi implement --continue-from <kept-worktree>🧠 Opus 5.5 and cheaper reviews
Routing moves to Opus 5.5 and Fable 5.1, and Opus efforts step down one level for the spec, review and planning skills. The fourth fix round escalates to Opus 5.5 ($4/$20) before Fable ($10/$50). A diff from pi, Prime, Codex or dsh is reviewed by Claude Sonnet medium instead of Opus, and a small finding is fixed right away in one follow-up commit.
devkit model-route review claude model🌊 Waves plan tighter and delegates start with context
Specs that only append to shared registries no longer wait for each other, so a plan drops from 7 waves to 3. Wave approval no longer blocks falsely on completed specs, live slices or Prime scratch trees. Every delegate starts with an 8 KB project context pack and a codegraph index (0.04 s + 1.2 s to seed), and the cost gate names the supervisor and the implementer for each slice.
/wave🔌 pi is a full harness now
pi can implement wave slices, reaches every devkit tool over MCP, and runs the same hooks as Claude and Codex — the destructive-command guard included — through one compiled manifest and a TypeScript adapter. It stays opt-in, with a managed block in ~/.pi/agent/AGENTS.md.
devkit config pi on✂️ Slimmer skills, fresh sessions for implementation
Stale and duplicated prose is cut from the skills: agent-browser drops from 2,427 to 1,036 words, delegate from 3,255 to 2,540, challenge from 1,519 to 885, prime-agent from 2,773 to 2,113 and spec-update from 2,491 to 2,051. /spec now hands /spec-work into a fresh session: 150–165k cached tokens per turn instead of 430–470k. Subagents no longer receive the 7.2 KB ADHD ruleset.
/clear
/spec-work 603⚡ Less waiting
A cold dev build takes 42 s of CPU instead of 270 s. 80 codegraph caller lookups are one 4 ms query instead of 11.6 s, and the sleep-poll guard blocks a pattern that cost ~180k tokens per session. The tool upgrade in devkit sync no longer blocks other devkit commands. /pen-design seeds the fixed canvas structure instead of drawing it; one such phase had cost 208k tokens.
devkit syncWhat changed for you
Changed
devkit initreplacesdevkit project-migrate: one command sets up a project checkout, new or from an older devkit version, and applies the plan directly — git is the undo,devkit init --dry-runonly shows it. At a terminal it guides: it offersgit init, asks before applying, offers the stack skills and achore: set up devkitcommit, and ends on the next step (/index);--yesor a run without a terminal applies without asking. A new session in a git project without devkit context namesdevkit initonce a day (DEVKIT_SKIP_INIT_HINT=1silences it).--applyis gone, anddevkit project-migratenow exits 2 namingdevkit init. The run log moves to~/.onedot-devkit/project-init.log, whichdevkit doctorreads.- The maintainer test layer is Rust only: every
tests/*.shsuite,tests/all.sh,tests/test-lib.shandtests/lib/are deleted, each suite lives on as a Rust integration target (the fourrust-targets-N.shwrappers and thetest-sandboxscanner are retired unported), anddevkit maint test-prep [--suite <target>] [--shard i/n]runs them. CI, the release preflight,npm testandtools/ci-cleanroom.shcall it; in this checkoutdevkit run test-prep.sh --affected-onlynow emitsdevkit maint test-prep --suite <target>fromtests/affected-map.txt, while a target project keeps itsbash tests/all.sh --suiteunchanged. - All 57 maintainer tools now run as hidden
devkit maint <name>commands. Their shell files are deleted, repository hooks, CI, tests, skills and quality scanners call the binary, and the unambiguous legacy names still work throughdevkit run <name>.sh. - Every shipped hook runs inside the binary. The remaining 25 shell files under
content/hooks/andhooks/are deleted,hooks.jsoncarries anativeCommandon every entry, anddevkit syncwires<home>/current/bin/devkit hook <name>into Claude's settings and the Codex hook config — theDEVKIT_NATIVE_HOOKSswitch is gone, because there is no script path left to select. Every hook decision a script made is recorded per case (process output plus the files it leaves behind) and replayed against the binary in CI. Nothing changes for you at the prompt; the SessionStart notice, the guards, the advisories and their kill switches keep their names and their wording. /indexwrites theod:context-importsblock intoAGENTS.mdwhen a project has noCLAUDE.md, and keeps it inCLAUDE.mdwherever one exists. Claude Code readsAGENTS.md—@-imports included — for any folder without aCLAUDE.mdsince 2.1.277 (probed here against 2.1.278), and Codex and OpenCode read that file anyway, so a new project now gets one instruction file instead of one per runtime. Projects that already carry aCLAUDE.mdare untouched. Where a session cannot readAGENTS.md— Claude Code below 2.1.277, the first session after that upgrade, Bedrock/Vertex/Foundry, hooks switched off — the documented bridge is aCLAUDE.mdholding@AGENTS.md.context-drift-check.shscansAGENTS.mdalongsideCLAUDE.mdfor broken references, duplicate@-imports and a file that holds nothing but the managed block.devkit syncnow provisions dsh's own profile plugins: it installspnpm@12.5.1and reconciles@zilliz/memsearch-dshinto theheadlessandwebprofiles plusdsh-find-pluginintoweb, idempotently and non-fatally. Your own~/.dsh/profiles/*/cordis.patch.ymlis never touched, and a machine without dsh or pnpm stays green.devkitis the compiled Rust binary and nothing else: the Bash entry, itslib/runtime and everycontent/scripts/*.shhelper are deleted.devkit sync,devkit run,devkit hookand the automation commands keep their names, anddevkit run <name>.shresolves<name>to the binary's native subcommand instead of a shell script. A machine that runs the released artifact needs no Rust toolchain; a maintainer who builds from a checkout does.- Releases ship one signed tarball per platform target (
od-<version>-<triple>.tar.gz) with alatest.json.targetsindex, anddevkit syncselects the host target instead of verifying the same Linux x86_64 archive on every machine. devkit bin-reconcile, the prime-run lifecycle and the wave-prep Orca half run natively, and the hooks and the statusline call the binary instead ofcontent/scripts/*.sh.install.shbuilds the binary from a checkout that ships nobin/devkit(a Rust toolchain is then required), so a source install takes the same entry path as a release.devkit has script <name>answers from the binary's dispatch table, so a skill guard such asdevkit has script research-cli.shkeeps working;devkit path script <name>has no file to return and fails closed. The quality gate runs backlog-lint and the design-token check from the binary instead of skipping them when the script file is absent.devkit run test-prep.sh --affected-onlyand--since <ref>narrow natively: thetests/affected-map.txtderivation, the-exemption, the session-scope drop of a parallel session's paths, the CodeGraph fallback and the changed-tests last resort keep their exact output (AFFECTED_MODE:,AFFECTED_SCOPE_DROP:,AFFECTED_UNAVAILABLE:); a three-field map row is invalid and fails closed as before.- The PreToolUse and UserPromptSubmit hooks run inside the binary (
devkit hook pretool|prompt): the shell dispatcher and its 16 policy scripts undercontent/hooks/are deleted, every decision is pinned by the recorded hook corpus, and a Bash call pays 22 ms of hook time instead of 155 ms. The background-wait guard now blocks the second sleep-poll of a session after advising on the first (DEVKIT_SKIP_BG_WAIT_GUARD=1disables both). devkit project-migrateno longer cleans up legacy npx-ai-setup projects: the.ai-setup.jsonmanifest phase, the content sweep and--forceare gone, anddevkit syncno longer prunes npx-ai-setup hook copies from~/.claude/settings.json. Remove leftovers such as.ai-setup.jsonand its copied template files by hand.devkit design-inventory(--init/--check/--find/--show/--design-claude) builds a component inventory per stack from its own declarations (Liquid schema, Blade@props, Twig blocks, a Nuxt registry command) plusused_byfrom codegraph, the Liquid graph or a pattern scan, driven by an.agents/design-inventory.jsonrecipe; the output.agents/context/component-inventory.jsonis gitignored, sinceused_bydiffers per machine./indexruns it before the DESIGN.md fill and reads it instead of the five largest component files;index --check/--mapcover it,--find/--showanswer one line per match instead of the whole JSON, and pen-design and the stack bundles check it is fresh before drawing.- Every delegated agent —
/delegate,prime-agent,/wave— now starts with a capped (8 KB) context pack built from.agents/context: run and test commands, conventions, Critical gotchas, and a DESIGN/design-inventory pointer for UI files, prepended to the brief before the credential scan (DEVKIT_CONTEXT_PACK=0turns it off). STACK.md's testing section now names the commandtest-prepactually runs, with a node-less fallback that follows thetest:unit/test:cipreference, instead of reading onlypackage.json'sscripts.test;/testand/debugprint that same documented command onNO_TESTS_DETECTEDinstead of guessing one. Codex's prompt hook now recalls a matching Critical gotcha the way Claude's does, every subagent is pointed at the Critical headings, and the review package carries the project context pack too. - SessionStart's context hint now also fires when
/indexflagged a project's context stale (naming the reason) or left context markers unfilled (naming the count and the first file), not only on age or a missing codegraph index. SubagentStart no longer injects the ~7.2 KB i-have-adhd ruleset into every subagent — subagent output is read by the main agent, not by you; the hook is renamedsubagent-context, andadhd-subagentstays a silent alias for settings written before the rename. pican now implement (read/bash/edit/write in its own child worktree on gpt-5.6-sol/medium), so a small spec no longer waits for Prime's Orca start and cold compile; thedshpin moves to0.1.5-rc.3after0.1.5-rc.1died at plugin load (it boots again).runtime-route implement --specreads a spec's Effort/Risk/Class and picks the harness — high risk to claude/codex, light work to pi/dsh first, everything else to prime then pi — records a runtime that failed to start so the next pick skips it for 24 h, and/spec-worknow dispatches through it instead of a fixed chain, naming the chosen harness on itsCOMPLETEDline.- A pi, prime, codex or dsh diff is now reviewed by a native Claude Plan at the review tier (moved from opus to sonnet medium); a Claude-authored diff keeps
review-runtime.sh's own seat. A small advisory finding is fixed right after the review receipt as one followup commit instead of only being logged. devkit's dev build no longer compiles at opt-level 2: a cold test build drops from 270 s to 42 s CPU (measured 2026-09-23), which every delegate worktree pays on each dispatch. Prime's orcaworker-startbound drops from 120 s to 30 s — an answered start returns in ~10 s, and a silent one never answers, so the old bound only delayed the headless fallback.devkit run <unknown>fails withunknown scriptinstead of tryingbash content/scripts/<name>, and compat probes,agent-evaltasks,harness-benchmarkandscript-usage-auditno longer run shell scripts. devkit now spawns a shell only to run a command string you or a spec supplied (spec verify, Prime gate, dsh fanout, the wave project runner) or to syntax-check pushed.shfiles;devkit maint rust-onlyturns red on any otherbash/shspawn.- A
piimplement run may take 3600 s instead of 1800 s, anddelegate-visible <runtime> implement --continue-from <kept worktree>resumes a cut-off run: the new worktree starts with its edits (DELEGATE_CONTINUED) instead of a hand-exported patch. A provider answer ending in "Please try again" counts as transient (exit 4), so it is retried or hopped instead of being blamed on the brief. - The repo ships no
.shfile any more.devkit installreplacesinstall.sh(same steps; a checkout source builds with cargo). The one-linercurl -fsSL https://devkit.one-dot.io/install.sh | shkeeps working: that URL now serves the output ofdevkit install --print-bootstrap, which checks the release signature before any binary runs and then hands over todevkit install. From a checkout, runcargo run -p devkit -- installinstead of./install.sh. devkit writes the SwiftBar plugin filedevkit.1m.shitself (devkit menubar --print-plugin); the release still ships it undercontent/swiftbar/, so older versions and a rollback keep a working menu. - Skills, rules and docs now name native commands the way you type them:
devkit quality-gate,devkit review-prep,devkit maint test-prepinstead ofdevkit run quality-gate.sh. The old spelling keeps working (devkit run <name>.sh,devkit has script <name>.sh), so project files, specs and notes that still carry it need no change. package.jsonis read in Rust (serde_json) instead of throughnode -e, sotest-prep,lint-prepand the quality gate no longer answer "nothing" on a machine without node.test-prep,review-prep, the post-tool hook and context-fill now share one test-path predicate instead of disagreeing on what counts as a test file.delegate-returnapplies a delegate's changes as onegit diff --binaryover every tracked path instead of per file, so a mid-apply conflict can no longer leave some files applied and others not.devkit runtime-routenow derives its pick from native provider/model/effort catalogs plus explicit selection and personal policy instead of a fixed tier table;piresolves providers from its own catalog and auth instead of a hard-wiredopenai-codexseat, and the autopilot kernel rules treat typed and transcribed intent alike when choosing direct work, Delegate or Wave.- Wave planning merges append-only registries (
tests/affected-map.txt,maint/commands.tsv,tools/gate-affected-map.tsv) withmerge=unionand skips overlap on any path.gitattributesmarks that way: a plan that needed 7 waves purely from registry-append conflicts now needs 3.
Fixed
- The quality gate turns red when backlog-lint, docs-locale-check, builtin-wiring-check, docs-drift-check or comment-continuation fail; the native gate had relayed only their green output and printed
QUALITY_GATE_PASSEDover a red scanner. devkit offanddevkit unlinkremove the Codex skill links and the managed block in Codex'sAGENTS.md; the native materialize pass had dropped those paths fromstate.json. A refuseddevkit onleaves devkit off instead of reporting on with no runtime./pen-designsaves throughprintf 'save()\nexit()\n' | pen interactive --app desktop --in <file>and ends a canvas cycle on a changed md5/mtime of the.pen;design-statusnow reports a stamp the app shows but the file lacks asUNGESPEICHERTinstead ofUMGESETZT. The oldopen -a Pen+ ⌘S route could save a foreign window or nothing at all (#98, #103).design-verifymeasures badge backgrounds, borders and icon fills, names the node type behind everyNICHT GERENDERTcolour, fails on a--selectorthat matches nothing, and says when an unthemed frame's findings come from one width only (#99, #105, #106).- The
/pen-designreferences document the guillemet sample-data convention, three pencil API traps (Unknown editId, emptyn.text,Copy()'s_suffix), the browser-node route for an exact live-import width and the update-proof~/.onedot-devkit/currentpath (#100, #101, #102, #104, #107, #108). devkit run <name>anddevkit path script <name>accept a script name without.shon a shipped runtime, and strict spec authoring treatsverify: judgement: <judge>as a judge instead of running it as a command (#109).pi's implement run is no longer idle-aborted at 900 s: its text mode prints only the final answer, which used to read as silence and killed a run that had already written hundreds of lines.- A provider's transient "please try again" error (seen from the openai-codex provider) is now retried instead of being classified as a brief-caused failure — which used to skip retry and hop and strand the finished partial work.
devkit maint spec-wave-approveno longer fails closed on a spec that completed onmainwhile a leftover worktree still carried it as draft, on a live wave slice whose name wasn'tspec-<id>, on a Prime implementer's scratch tree, or on.memsearch//.claude/agent-memory*/bookkeeping paths — four related false blocks hit in one wave run.devkithelp and usage text across every native command now saydevkit <name>, not<name>.sh, now that the shell-parity corpus is gone.design-verifyderives the third inset width from the page's own widestmax-width(+240, 1.5× of the widest frame as floor) instead of a fixed 1.5× multiplier, so a self-padded fluid section no longer passes the check (Closes #131).- A reviewer subagent's own
.claude/agent-memory*/notes no longer void--verify-input-shaand discard a whole review pass (Fixes #130). - Codex can read its own frozen review package from a linked wave-slice worktree; the guard only exempted
.git/od-spec, not.git/worktrees/<name>. - pi runs the same hook manifest as Claude and Codex, including the destructive-command guard, once opted in with
devkit config pi on(Spec 543). /wavemerges a slice throughdevkit wave-prep reintegrateinstead of a hand-run sequence, and catches a line amerge=unionregistry would otherwise silently revive from a stale slice base./spec-workrebuilds its readiness pack (files, symbols, callers, affected suites, verify targets) against the live base at start, not only at authoring time (Specs 612, 613).
🚀 Features
- wave — reintegrate a slice in one deterministic call (9eb6d69)
- spec-work — readiness pack regenerated at /spec-work start (Spec 613) (3e05daa)
- tools — cargo installs and audits through rustup on Linux (Spec 611) (d123194)
- pi — devkit hook bridge for pi via compiled manifest (Spec 543) (37cbe0c)
- spec — spec-readiness resolves every path and verify target (Spec 612) (1597ae3)
- tools — recommended cb tier with GitHub access preflight (Spec 553) (9d57ef1)
- mcp — pi as MCP target with pi-mcp-adapter provisioning (Spec 537) (99bfb73)
- maint — deterministic tool-review subcommands (Spec 606) (579e206)
- release — preflight before any push, bound to a private run (Spec 609) (cbe08f8)
- spec — derive a Risk floor before granting the review waiver (e19115b)
- spec — earned review waiver holds for wave and delegated diffs (ea15809)
- rules — prepared project tools are required steps in every project (Spec 537) (1ddda33)
- sync — pi as opt-in runtime target with a managed AGENTS.md block (Spec 536) (1c4b63c)
- maint — content-budget --list (Spec 610) (98f2380)
- gate — active specs with dead references redden the quality gate (5f3964d)
- maint — reference-ledger decide and lift (Spec 608) (e05bd52)
- pen-design — keep the canvas inventory current and implement from it (Spec 602) (3004aa0)
- spec — strict authoring blocks a verify command that cannot run (Spec 579) (6aad7bb)
- maint — claude-changelog delta and stamp subcommands (Spec 607) (a98f15c)
- test — reuse a green suite result while its inputs stay unchanged (Spec 578) (af65ef1)
- maint — tool-pin-audit names foreign packages and newer installs (Spec 605) (c592e1a)
- wave — slice-retry resends the brief and standing orders (5f45585)
- wave — slice-dispatch appends the standing orders to every brief (a16a3ad)
- wave — slice-dispatch refuses a spec whose verify names a dead test target (ac9e477)
- design — design-inventory reads the Pen canvas components (Spec 601) (742f7c2)
- index — keep a cumulative retrieval-savings ledger (Spec 573) (944cdda)
- gate — scan the distributed payload for secrets (Spec 561) (715e6a5)
- maint — spec-outcome measures whether a completed spec held (8a893cc)
- usage-report — filter to interactive current-version sessions (768ea2c)
- maint — usage-trend compares the last usage snapshots (4cfd44d)
- eval — report negative deltas and ablate steered tools (Spec 572) (cf833e5)
- wave — name supervisor and implementer per slice at the cost gate (919251e)
- routing — smart runtime routing with native Pi provider selection (36cb1d2)
- install — install.sh and the SwiftBar shim move into the binary (366e6df)
- delegate — pi reaches codegraph through pi-mcp-adapter (a3e199a)
- delegate — every worktree delegate gets the codegraph index (6c7d45e)
- delegate — pi implement gets 3600 s; --continue-from resumes a cut-off run (3e656ee)
- review — cross-vendor Sonnet reviews, small findings fixed at once (a2715c4)
- review — dispatcher records review rounds; prep and finish read them (b7018bb)
- init — guide the project setup at a terminal (Spec 586) (343a2dd)
- cli — devkit init replaces devkit project-migrate (d904b0d)
- delegate — pi implements, dsh pin boots again (6ac8adc)
- agent-browser — delta snapshots, load-state wait, aarch64 Chrome route (c97098f)
- agent-browser — launch with --no-webmcp (10b9512)
- hooks — trust the pasted Orca dispatch in wave slice worktrees (Spec 582) (d1255f1)
- routing — resolve known task roles without Jev (7a9d157)
- parity — parity-fixture edits frozen fixtures as text (da6e9c2)
- delegate — keep unattended Claude runs going past status turns (251a4f5)
- rust-only — sanctioned boundary for Python extensions (68c776f)
- routing — scope native Jev runtime discovery to eligible targets (38ddaaf)
- delegate — add read-only Pi tasks through Codex OAuth (2894d26)
- review — bind explicit policy context to frozen reviews (8d47da4)
- project-migrate — drop the npx-ai-setup legacy migration (Spec 569) (cbff4ce)
- spec — hand off /spec-work into a fresh session (f885185)
- support — one shared helper module and sha2 for SHA-256 (346a706)
- evaluation — scaffold the native Jev client crate (Spec 571) (5e5e313)
- review — reviewer seat runs medium, low-risk diffs step to low (83bc465)
- routing — escalate the Claude fix loop to Opus 5.5 before Fable (86afef1)
- maint — native skill-lint checks the frontmatter itself (b5fc8b3)
- jev-route — bounded native runtime inventory for route picks (e203936)
- routing — step Opus efforts down one level for Opus 5.5 (c2aad95)
- skills — read a new model's vendor docs in devkit-claude-changelog (61fdee2)
- maintainer — add replayable verification and learning loop (d8b23b2)
- tools — ci-cleanroom.sh runs the Rust workspace like the CI test shard (Spec 560) (706845f)
- hooks — delete the shell hook dispatcher and its 16 policy scripts (77ca518)
- evaluation — transcript-failures lens ranks the turns where the human pushed back (d0390e1)
- hooks — entries run devkit hook; repeated sleep-polls are blocked (Spec 560) (3d4b156)
- test-prep — native affected-mode narrowing (3d1a609)
- delete the shell runtime — the compiled binary is the only devkit (Spec 560) (89ff391)
- devkit — last content/scripts dependencies run through the binary (Spec 560) (a72658c)
- devkit — worktree-setup, backlog-lint and reuse-detect run natively (Spec 560) (e04360e)
- cli — port remaining entry subcommands (db6703f)
- port plugin reconciles to native devkit (1523247)
- sync — native CLAUDE.md managed-block cleanup in materialize (e07d4f0)
- wave — port Orca preparation natively (707f814)
- prime — port runner lifecycle to Rust (c291b08)
- spec-meta —
--digest <file>; skills stop sourcing prep-lib.sh (796e3f5) - install — build the binary from a checkout that ships no bin/devkit (Spec 560) (1e115ba)
- hooks — wire the statusline to the devkit binary (Spec 560) (82ab921)
- sync — native devkit bin-reconcile (f4db2f6)
- sync — select host release target (2b34a74)
- release — build per-target artifacts (f92c1f6)
- dev-sync — ship the compiled binary as the dev version's bin/devkit (3086dd7)
- hooks — call the devkit binary instead of content/scripts (Spec 560) (7a61b96)
- sync — native runtime hook wiring; devkit sync runs without the shell entry (87febf1)
- sync — native devkit_env_reconcile (settings.json .env merge) (aa448ad)
- rust — delete the shell runtime, make the binary the devkit entry (Spec 560) (4742736)
- delegate-exec — dispatch prime into the native runner, drop the shell bridge (bafeead)
- devkit — native config source arms and apply; decouple cli/run/resolver parity (Spec 559) (5799283)
- rust — native context-fill and design-fill, drop the sourced_library_call bridge (6d0b77b)
- entry — route devkit run through the native subcommand first (Spec 520) (b7e6203)
- rust — native delegate panel, drop the shell bridge (fc8eb5d)
- rust — port the remaining doctor shell_fn callers natively (a4fe098)
- rust — native doctor MCP shadow and mcp_doctor checks (1dc968d)
- rust — native review-runtime dispatch, drop the shell bridge (055c2ab)
- rust — native delegate-visible orchestration, drop the shell bridge (d6119cf)
- rust — native delegate-exec argv dispatch, narrow the shell bridge to prime/panel (37076e4)
- rust — native hook prompt policies and policy scripts, drop the shell bridges (e1d6b6f)
- rust — native review-runtime probe, drop the delegate-exec bridge (8b637c4)
- rust — native Orca detect in delegate-return, drop the shell bridge (879c8d6)
- rust — run spec completion validity in-process, drop the shell helper (1e05d64)
- rust — native codegraph-first stack coverage, drop the detect-stack bridge (645e8dd)
- jev — add route, verify and find probes with vendored TypeSafe docs (4c1bc72)
- jev — document route, verify and find probes; exclude vendored docs (4d69513)
- rust — native prime-run argument/status half, narrow the bridge (Spec 552) (f661361)
- rust — native index-prep and workspace-run, remove the bridges (Spec 547) (46185c4)
- rust — native doctor check, remove the lib-sourcing bridge (Spec 550) (6b3d4fb)
- rust — native wave-prep filesystem/preflight/accept half (Spec 546) (445f090)
- rust — native quality-gate scanner selection/execution, remove the bridge (Spec 545) (0ff8afd)
- rust — native spec-work-prep halves, narrow the bridge (Spec 549) (7927172)
- rust — native share-prep rendering, remove the bridge (Spec 548) (9139626)
- rust — native test-prep runner, remove the shell bridge (Spec 544) (9012bbb)
- release — per-platform binary build and release-chain fixture (Spec 542) (6b7b6c6)
- rust — native project-migrate (Spec 541) (58633fa)
- rust — native sync transaction (Spec 540) (a84a4d7)
- rust — native codex/opencode materialization (Spec 539) (c154d0e)
- rust — native MCP reconcile/unreconcile and state writers (Spec 538) (6cf12bd)
- rust — native remote verify/fetch (Spec 535) (f7b19d5)
- rust — native skills subsystem (Spec 534) (1ce52fb)
- rust — native doctor (Spec 533) (23d78e1)
- rust — native tools subsystem (Spec 532) (562c451)
- hooks — native advisories and codegraph-first (Spec 530) (db7b8ac)
- rust — native codex/opencode rendering (Spec 529) (e01cbea)
- rust — native MCP manifest/desired/actual/status (Spec 528) (065da71)
- rust — native state/config read and typed mutations (Spec 527) (56b157a)
- rust — native version safety, rollback selection, markers, activation (Spec 526) (6cd9b02)
- rust — native runtime resolver (Spec 525) (c701d70)
- hooks — native devkit hook layer behind DEVKIT_NATIVE_HOOKS (Spec 521) (65db067)
- index — make AGENTS.md the instruction file /index writes (62f735b)
- tools — add the dsh spec fan-out runner (fbb0e90)
- pen-design — the adapter says what a canvas variable becomes in code (940200b)
- stack-nuxt — generate the component inventory the adapter asks for (f9cf07c)
- pen-design — make the build order a gate — components before pages (6086153)
- rust — complete partial port batch 499 (Spec 499) (a15ffe8)
- rust — complete partial port batch 498 (Spec 498) (cc98e44)
- rust — native parity batch 497 (Spec 497) (fb640e3)
- rust — native parity batch 496 (Spec 496) (fe9c074)
- rust — native spec-validate-prep (Spec 495) (9ef0019)
- rust — native parity batch 494 (Spec 494) (bbe27e6)
- rust — native parity batch 493 (Spec 493) (2282068)
- rust — native parity batch 492 (Spec 492) (33591f8)
- rust — native parity batch 491 (Spec 491) (f098de5)
- rust — native parity batch 490 (Spec 490) (61753a7)
- rust — native parity batch 489 (Spec 489) (61b1394)
- rust — native parity batch 488 (Spec 488) (7981ac4)
- rust — native parity batch 487 (Spec 487) (145d42f)
- rust — native parity batch 486 (Spec 486) (ae433cc)
- rust — native parity batch 485 (Spec 485) (7352f33)
- rust — native parity batch 484 (Spec 484) (0283fab)
- rust — native parity batch 483 (Spec 483) (6fce53e)
- rust — native parity batch 482 (Spec 482) (ce700c6)
- rust — native parity batch 481 (Spec 481) (d645909)
- rust — native parity batch 480 (Spec 480) (ab0a8f7)
- rust — native parity batch 479 (Spec 479) (bec6f8c)
- rust — native parity batch 478 (Spec 478) (1a355cc)
- rust — native brief-gate and friction-hint-prep (Spec 477) (72f9878)
- rust — native spec-candidate-dir effect parity (Spec 476) (ee9cc63)
- rust — native budget-prep and spec-reject-log effect parity (Spec 475) (8ac9742)
- pen-design — seed the constant canvas structure instead of redrawing it (bb70f73)
- rust — native spec-id-next effect parity (Spec 474) (ee158f2)
- devkit — hard-wire migrated scripts into the run path (d8ba1e7)
- quality — fail a change that introduces a raw colour beside a token source (500381a)
- rust — native parity batch 473 (Spec 473) (89536ec)
- rust — native parity batch 472 (Spec 472) (2737a9d)
- index — point at DESIGN.md from the CLAUDE.md context block (0e6d60a)
- pen-design — read one section of a frame instead of the whole thing (c143a2c)
- rust — native parity for runtime-route, learning-capture-prep, orca-detect (Spec 471) (2087a8a)
- tools — probe the contracts a version pin cannot see (8d02efb)
- rust — native fast-path bridge and caller switch (08347d2)
- rust — native parity for 12 scripts (Specs 466-469) (785fc75)
- rust — native devkit detect-stack parity (Spec 465) (e3e683b)
- rust — native devkit model-route parity (Spec 464) (9e85244)
- rust — parity-verified devkit CLI core (Spec 461) (c36ee3d)
🐛 Fixes
- release-prep — digest check reads only the target version's entry (63c72e1)
- release-prep — preflight runs the audit gate before the tag (83b4075)
- fix(release-prep,wave): point preflight fails at /devkit-docs, tidy form (a9db4de)
- maint — docs-drift-check takes pages after --include-dirty (3c21d98)
- wave — catch lines merge=union revives from a stale slice base (604e1ce)
- spec — spec-readiness counts a symbol without callers as zero (c324432)
- spec — spec-readiness reads verify commands only from Steps and ACs (Spec 613) (643af22)
- prime-run — an unfinished run exits 7 instead of passing its patch (e52e71d)
- wave — reintegration builds every test target, not only the binary (d9c4763)
- tests — pi_mcp sets SyncEnv.pi_dir added by Spec 536 (6972a24)
- rules — fit the mandatory-tools rule into the always-on byte budget (6f4e36b)
- wave — one owner per slice rule; retries carry current standing orders (e8e7027)
- prime — fall back locally when the caller is itself an Orca worker (54b62fa)
- spec-work — give the implementer report an absolute, outside-tree path (a29bf46)
- review — a fix round after a same-day BLOCK gets its delta package (Spec 608) (05ea416)
- prime — place Prime worktrees under the main checkout from a slice (2ffb1de)
- maint — run-cost reports a Codex transcript as unavailable, not zero (14b01e4)
- tests — route content/pi/* to the refs suite (Spec 536) (0ed38f7)
- wave — accept tests the whole slice, not the coordinator's session scope (2429978)
- delegate — every session-less runtime resumes as a fresh round (0df22a7)
- tests — route tools/gate-affected-map.tsv to a suite (Spec 561) (5d67b79)
- spec — spec-work-prep overlap follows the wave approval skips (Spec 537) (e58819f)
- delegate — run a fresh Prime round on resume instead of refusing (f78a29b)
- spec — a spec completed on main no longer blocks wave approval (Spec 537) (c90b467)
- spec — recognise Prime scratch trees regardless of HOME (e9a6a55)
- spec-drift — plugin and agent-memory state is not scope drift (806e403)
- spec — wave approval no longer fails closed on live slices (21f186d)
- telemetry — count external reviews and keep hint conversions (61b879c)
- hooks — let Codex read review packages in linked worktrees (31e4f2f)
- pen-design — measure the third width above the layout max-width (e62388c)
- review — agent-memory writes no longer void the review input SHA (0aae1dc)
- docs — repoint tool evidence and workflows page to devkit
<name>(c16d340) - cli — help and usage name devkit
<name>, not<name>.sh(59463d9) - review — keep Claude verdicts out of plan mode (e1b9530)
- install — reuse support::proc, rustfmt; test-prep floor follows the corpus cut (8007fee)
- codegraph-first — a $VAR or ~ read path is outside the root checkout (b24deea)
- tests — drop borrowed format! args clippy denies (c73f30e)
- context-drift — report scripts a project skill runs that are gone (2d98901)
- pen-design — design-seed stops when Pen.app fronts another canvas (a3a2d78)
- pen-design — every stack adapter describes the naming key (11c39da)
- delegate — treat a provider's 'please try again' as transient (97e42d8)
- spec-work — keep the pre-move review-verdicts text intact (aca6e1e)
- init — use support::git::git_toplevel, not a private copy (0f2e46f)
- delegate-visible — never idle-abort pi (Spec 584) (0402aa5)
- ci-cleanroom — print the compiler error when the build fails (512c32d)
- usage-report — range-check Retry-After HTTP-date fields (Spec 581) (cc23eef)
- spec-review-prep — deleted markup no longer demands a Frontend review (Spec 581) (43dbfde)
- hooks — single-quoted regex is not a secret-env glob (81878f9)
- maint — content-budget answers --help instead of rejecting it (7d92052)
- spec-review-prep — package carries Progress Log decisions (Spec 577) (7aea6a9)
- skills — tools-changelog surface grep and pre-install probe (87c0ff3)
- maint — tool-pin-audit resolves codex, prime-agent and cargo honestly (94d5ba3)
- rules — move the adhd precedence line into the adhd ruleset (0a5d3d0)
- delegate — show why a visible delegate failed (Spec 590) (3fa4255)
- spec-deps-check — a candidate no longer overlaps its own spec (c82bcd7)
- spec-validate — split verifies with 2>&1 and a cd prefix (e4ae9cd)
- hooks — put rustup cargo ahead of a distro cargo in Claude shells (5ee7656)
- maint — docs-drift-check answers --help (763bed7)
- wave — mark slice worktrees, name the trust prompt, skip plugin state (Spec 582) (bb9a055)
- test-prep — detect Cargo projects (Spec 582) (a5b8841)
- sync — read MCP state from $HOME/.claude.json (16022ff)
- hooks — style reminder honors the typed stop adhd mode switch (c511c4c)
- hooks — index-gap-hint refreshes its listing after the index changes (9e7f885)
- wave — create slice worktrees in the main checkout's repo (64c91d6)
- devkit-eval — list trials in name order before validating them (9a83e06)
- spec-reconcile — keep Author as provenance, allow adding it (7031448)
- codegraph-first — stay silent on reads outside the root checkout (2182133)
- orca — drop the open-changed consumer row review no longer has (d854bf9)
- spec-review-prep — completion-validity tolerates out-of-scope drift (6dd99e4)
- fix(spec-review-prep,spec-drift-check): name and block nested-checkout scope (3161d52)
- spec-review-prep — reanchor DIFF_BASE on a wave slice at main's tip (943b75b)
- spec-update — allow green-at-head with an --ac-correction fix (4d758d6)
- spec-update — rebind stale digest and preserve Author on reconcile (48ebac6)
- orca — stop agents from opening editor tabs (18033eb)
- delegate — dedicated exit for an expired Codex credential (a22f120)
- delegate — delete the delegate branch with its worktree on removal (30c1cc6)
- post-edit-lint — scope the shfmt sweep to real .sh/.bash operands (ed54ef0)
- secret-env-guard — allow native --env-file loaders, mask literal heredocs (efda79f)
- spec-work — resolve review runtime separately from implement runtime (3b32e41)
- fetch-task — name the PAT fallback for a failing cb browser login (59423de)
- pen-design — guard against pencil MCP ignoring filePath (7a6646d)
- pen-design — remove frame-commit-check commit-msg hook (ad6df53)
- pen-design — fix K\d project-criteria cap and name shape-first reuse (cd673dc)
- rust-only — --accept takes a path relative to the working directory (Spec 576) (64b4343)
- test-runner — prove a planted per-target temp dir is refused (Spec 570) (cfbe9de)
- rule-effect — count a timed-out arm as invalid explicitly (Spec 569) (2f99e47)
- maint — kill the whole process group when a harness timeout fires (Spec 569) (5552ce4)
- test-prep — check-run evidence no longer waits for python3 (Spec 574) (aafd55e)
- review — preserve Claude eligibility and scope architecture signals (27fad3e)
- parity — isolate implicit runtime from the parent agent (d0a75cc)
- spec-review-prep — the review package carries the ACs and their evidence (a4b926e)
- parity — two recordings stop pinning the day they were taken (a27c098)
- spec-work — implementer returns its report as text when the write is refused (Spec 570) (dbd05ba)
- delegate — stream oversized Claude briefs through stdin (e0f2a74)
- skill-usage-audit — read transcript dates with GNU stat too (5ff77f9)
- agent-eval — skip files that vanish during the manifest hash (a9a8fd7)
- ci-cleanroom — install rustfmt, clippy and the npm tree like CI (c1a0c6c)
- content-budget — keep the skill-ceiling arm on one line (895185b)
- ci-cleanroom — pass the prebuilt binary as an absolute path (acb5281)
- ci-cleanroom — run tests/all.sh like the CI shard by default (7764301)
- pin-check-reminder — emit the note on empty or non-JSON stdin (3d03bca)
- docs-drift-check — name the de/ twin on the finding line (675201e)
- content-language — only an unresolved scan root with rows is red (1cc1213)
- content-budget — classify --measure-text from the candidate text (64f45b1)
- skill-lint — port the shell gate's contract to devkit maint (Spec 569) (32bb42d)
- wave-probe-check — port the rule engine and self-test (Spec 569) (13a1ce0)
- docs-locale-check — check German-only and unlinked German pages (Spec 569) (8eee5c9)
- tests — point skill references at real rule headings (5d1dbbe)
- tests — re-baseline fixtures to the native devkit maint names (Spec 569) (08b68cf)
- ci-cleanroom — put the home bin dir on PATH like the runner (20b98fb)
- parity — statusline case renders reset times in UTC (ecaac69)
- release-cleanroom — run spec-lifecycle-check through the built binary (Spec 569) (4938d1a)
- parity — gate and budget-prep tests follow the native scanners (Spec 569) (81e3a7c)
- parity — hook_corpus resolves json_value through the devkit crate (Spec 571) (2fca139)
- parity — retrieval-savings help names devkit maint content-budget (Spec 569) (4d51344)
- spec-finish — slice receipt dates on a char boundary (Spec 569) (422b88c)
- gate — four red scanners back to green (Spec 571) (8a9f03d)
- last30days — reject JSON false and null like jq -e did (5a122c1)
- spec-review-prep — hash the strict JSON file, not its path (Spec 571) (0015198)
- maint — compat-pen-file-format tolerates pen exiting before stdin (010baec)
- prime-run — re-run every gate before publishing a patch (af18127)
- cli — stop advertising project-migrate --force and .ai-setup.json (2aefc04)
- hooks — a one-line sed print is not a whole-file read (621dff2)
- spec — say who writes Approved-Digest after spec-meta --digest (Spec 577) (2985c09)
- spec-validate — name a Step continued on indented lines (d911ac7)
- spec-update — review-route headers are contract metadata (8a28a52)
- run-cost — resolve the session transcript from the invoking checkout (dab9ce3)
- review-prep — the design signal no longer fires on formatter_class= (ed75ea1)
- cli — sync and tools answer --help instead of running (9c5a813)
- spec — call model-route with its required model|effort argument (1ba2aae)
- tests — skill-create fixtures follow the Opus 5.5 effort mapping (cfb9f58)
- plugins — install i-have-adhd over https, not the github ssh source (e2c1b97)
- spec-update — route revisions by /spec's full triggers, not a stale copy (042ad89)
- spec-deps — a non-matching glob no longer aborts the overlap scan (cc0e92c)
- content — restore both quality gates on committed main (5ec23e6)
- parity — match the switches listing and the reverted help texts (a6f476a)
- tool-pin-audit — drain the uv inventory instead of grep -q (Spec 569) (a20b620)
- content — pay two budget overages the stubbed gate had hidden (bbbef65)
- maint — bring the 57 shell tools and their call sites back (Spec 569) (71464f4)
- maint — keep the release signing key 0600 and gone on every path (a8aef9e)
- maint — drop the unspecified trial-preflight restore (11d6797)
- skills — name validator-parsed delta labels; Python checks follow the project (4ecaea8)
- eval — reject provisional Claude CLI stream usage (b7d0cde)
- codex-guard — stop three false positives and a false fallback (32aa04c)
- parity — follow the committed help and stop-gate texts (Spec 569) (6d0b117)
- hooks — announce gate lets a turn wait on a background task (21be72a)
- parity — refuse to record when the shell producer is gone (360ce9c)
- hooks — codegraph-first no longer blocks an in-place sed edit (c5b2a34)
- maint — point dev-sync hints at devkit maint dev-sync (Spec 569) (e7e4573)
- maint — map opus/fable aliases to Opus 5.5 and Fable 5.1 (e6db45a)
- spec-review-prep — a prefix filter needs no child process (Spec 569) (33d76e5)
- maint — a blank line at end of file is a CI whitespace failure (e43d37a)
- sync — the staged binary is not source drift (Spec 568) (a083061)
- parity — git's own housekeeping is not a hook decision (570a2eb)
- spec-review-prep — feed a child's stdin beside the read, not before it (Spec 568) (3ca5fa9)
- delegate — host-skew preflight checks every code-mode host the CLI can load (6e6da22)
- cli — a child that exits before reading stdin still counts as answered (0b9b9f3)
- cli — keep SIGPIPE ignored, exit 141 quietly on a gone stdout reader (97e36a1)
- last30days — feeding jq survives a jq that exits before reading (7f92cb9)
- skills — pull visits registry skills in name order (5c274a4)
- tests — prefer the rustup toolchain over a distro cargo (3faaa92)
- sync — ensure_config creates DEVKIT_HOME and names a failed write (bd808fd)
- devkit — gate reds relay scanners, off/unlink own the codex links (5b7cf78)
- dev-sync — build the binary before staging it (Spec 560) (3e590de)
- route native reconcile changes (a7ebfe0)
- hooks — classify a Bash read per pipeline stage in codegraph-first (7aa3dc7)
- rust — resolve the checkout for a debug binary built outside the tree (e2faa3f)
- delegate — count the run's process-tree CPU as liveness in the idle watchdog (4e309d0)
- tools — register cargo; repair the codex execpolicy evidence (a423d2b)
- delegate — drop the worktree branch with it, prune settled branches at dispatch (ef85e64)
- delegate — resolve dsh patch paths under content/dsh, not content/scripts/.. (7761d75)
- review-prep — drop the content/scripts guards on the native design-slop/reuse calls (e399abd)
- harness — robust idle watchdog and repo-marker; close delegate stdin (27bfb20)
- delegate-visible — close stdin so codex does not block; decouple script_parity_472/473/475/476/477 (Spec 522) (36f78d3)
- delegate — forward DEVKIT_DELEGATE_BOUND into fresh Orca terminal (98eebd7)
- wave — match filename-prefix globs in the accept ownership check (Spec 554) (d25e01c)
- delegate — find the mirror baseline by subject, not at HEAD (6ce2ca5)
- delegate — return a delegate's committed work, not only its working tree (4299501)
- rust — drop the unverified 471/481/488 conversions pending a reliable recorder flow (288a0c1)
- pen-design — save through pen interactive, check the file on disk (8ef6e7e)
- design-verify — measure non-text colours, name root and width gaps (e119d70)
- spec-validate — treat
verify: judgement: <judge>as a judge (308dc4e) - runtime — resolve a script name given without .sh (55abbce)
- rust — avoid the clippy chunks_exact lint in the parity recorder (d806164)
- rust — address independent-review findings (21d0e84)
- rust — match the shell on Linux for home display and JSON errors (34ec1a3)
- rust — make mcp_reconcile_parity env-hermetic (b79d852)
- hooks — clear the clippy lints in the native guard (4e48229)
- rust — format the parity test the batch merges left unformatted (1cb72f0)
- rust — clear fmt and clippy regressions from the fan-out merges (840a621)
- spec-validate — the probe's own scratch files are not a mutation (73b53b7)
- pen-design — K2 reads the disabled flag, design-fonts separates its groups (9c9a57c)
- rust — restore the minutes in the statusline's GNU date fallback (d28f16b)
- pen-design — measure after hydration and name the element behind a value (2669d7a)
- shopify-liquid — fail JSON inside a double-quoted HTML attribute (92bd8b7)
- rust — remove fake library subcommands and fix a spec-review-prep unbound var (466e0a7)
- lint-prep — the LINT_SCOPE_EMPTY branch was dead under set -e (Spec 482) (92f13bf)
- mcp — an optional server's conflict no longer blocks the whole runtime (fdd99a0)
- cli — let read-only resource commands wait for the mutation lock (7156fb5)
- mcp — the blocking conflict names the two commands that clear it (19bc235)
- hooks — graph-first as a gate, and every advisory keyed per agent (4cde37a)
⚡ Performance
- test-prep — derive affected Rust targets from references, not workspace (44335cb)
- wave — a low-effort slice skips the second implementer agent (428dcd5)
- wave — one retro per wave instead of one per slice (3a6b1e6)
- wave — a slice never runs the full suite (018780f)
- wave — stop serializing specs on append-only registries (b129c5b)
- build — drop opt-level 2 for the devkit package in dev (7c22768)
- prime-run — worker-start bound 120 s → 30 s (ade0d19)
- perf(prime,tests): stop five parallel runs from starving each other (ffaf813)
- sync — run the tools upgrade after the mutation lock is released (85a2680)
♻️ Refactoring
- rust-only — devkit spawns bash only where a shell is the contract (5f7e0ca)
- usage-report — rustfmt the scratch-path normalize pattern (3cd6a16)
- delegate — rustfmt the credential marker check (4c18b6d)
- hooks — rustfmt the comment-mask guard in codex_guard (b05d33a)
- routing — remove Jev and retire its specs (6d0536d)
- spec-review-prep — rustfmt the nested-checkout and reanchor fixes (30a65e5)
- delegate — rustfmt the branch-removal assertion (259f88e)
- tests — share the suite support module through parity (7c7b7ed)
- parity — rustfmt quality_gate_parity (a4b246b)
- tests — rustfmt helper_dedup (0487c8f)
- scripts — a–o helpers resolve onto crate::support (481f4d9)
- core — core, doctor and hooks helpers resolve onto crate::support (8b2ba64)
- scripts — p–r helpers resolve onto crate::support (Spec 571) (704148f)
- scripts — spec_* and s–z helpers resolve onto crate::support (9c2f396)
- skills — cut drift and duplicate prose from knowledge skills (9a2fa14)
- skills — cut drift and duplicate prose from orchestration skills (43ef501)
- skills — cut drift and duplicate prose from tool and stack skills (1017f17)
- spec — cut duplicated prose from the spec skills (ade40d1)
- tools — drop the last maintainer references to content/scripts (20c54e8)
- release — inline the OpenSSL resolver into build.sh (Spec 560) (05788b8)
- rust — satisfy clippy -D warnings in the newly decoupled parity tests (74cf3c2)
- rust — run check-run in-process from test-prep (42c6ba2)
- rust — auto-register script subcommands via build.rs (b6dde4c)
📖 Documentation
- reference — decision rows for the 51 specs completed since 531 (a967a5a)
- changelog — cover wave 1's 20 specs in Unreleased (139fac1)
- wave — provider quota ends the implementer route in a slice (Spec 613) (f701334)
- wave — one bounded fix past the review cap runs without asking (2451f27)
- workflows — re-set drift marker after the Risk-floor note (058a11c)
- spec — specs 612/613 resolve and hand over a readiness pack (170294c)
- spec — name the derived Risk floor where /spec writes the waiver (ccc0d6f)
- spec — simple specs skip the implementation review, in waves too (738a619)
- agents — the prepared tools are required workflow steps (512d9eb)
- workflows — re-set drift marker after review of today's skill edits (1701ab3)
- wave — a refused nested implementer is fixed by the supervisor (92887fe)
- wave — brief bounds review overruns, dependencies and setup waits (884c684)
- wave — reintegrate after worker_done and start unblocked specs early (e401a7f)
- wave — brief carries the four facts wave-1 workers asked for (2b44ad8)
- devkit-docs — Unreleased gets the head, highlights filtered for users (4babeb4)
- changelog — lead the Unreleased entry with the Rust move and routing (963c117)
- spec — move Spec 553 tests off the retired tools_parity target (0b3d123)
- tools — review orca 1.4.209 against our call surfaces (b60acdb)
- tools — point i-have-adhd and memsearch evidence at live consumers (a839d73)
- design — tighten the pen-design page to what each run writes (4292415)
- changelog — native command names in skills and docs (d2de3b7)
- teach devkit
<name>instead ofdevkit run <name>.sh(aa1de29) - menu-bar — name the generated plugin without its .sh file name (58a94ee)
- changelog — install.sh and the SwiftBar shim live in the binary (0ba4d99)
- pi — record the Pi extensions reviewed and why only one was adopted (b6755a9)
- sync — drop the shell-era comment block in the sync transaction (Spec 520) (5b30dfe)
- specs — retarget 537, 543, 553, 561, 573 to the Rust-only code (df4682b)
- specs — complete Spec 531 (b4252da)
- changelog — bash-spawn removal and pi continue/bound (4accab9)
- devkit-issues — format only own files in the shared checkout (15da510)
- design — the seed names its foreign-canvas stop (a926dea)
- changelog — today's design inventory, routing and speed work (0e92669)
- specs — complete Spec 603 (2b2f756)
- specs — Spec 603 in review, steps and AC evidence recorded (e1e4fd7)
- design — re-set markers after the pen-design --check wording (393ca80)
- specs — complete Spec 585 (5557324)
- specs — complete Spec 587 (d71d255)
- specs — complete Spec 588 (00e35c8)
- specs — complete Spec 586 (739cbd0)
- specs — complete Spec 584 (2ed7e41)
- specs — complete Spec 591 (4698a3d)
- specs — complete Spec 600 (71cad32)
- specs — complete Spec 583 (19d02e2)
- specs — complete Spec 596 (1c24d0e)
- specs — complete Spec 593 (9e5a08f)
- specs — complete Spec 598 (4c24f73)
- specs — complete Spec 589 (4f35a36)
- specs — complete Spec 594 (1f0c9e2)
- specs — complete Spec 599 (8e31cf7)
- specs — complete Spec 597 (60fcdbe)
- specs — complete Spec 595 (d1d8d22)
- specs — complete Spec 590 (2b19a0c)
- specs — complete Spec 592 (9edb47f)
- workflows — /spec-work chooses the harness per spec (Spec 604) (531d496)
- spec — remote-service Steps verify failure paths through a stub (Spec 581) (9ebb467)
- specs — add draft specs 578, 579, 601 and 602 (2045282)
- re-set design and workflows markers after Spec 584 (6c11645)
- design — /index builds the inventory; one command table (Spec 585) (41098c1)
- specs — 596 owns hooks/prompt.rs for the module visibility (0ab3888)
- specs — 603 routes light specs to pi and dsh (4fd85aa)
- prime-agent — trap row for a brief whose premise forbids new files (Spec 594) (8ca8755)
- specs — add spec 611 for a rustup installer arm on Linux (8f9f78d)
- specs — add specs 605-610 for deterministic maintainer helpers (3048b33)
- specs — add specs 603-604 for per-spec implement runtime choice (3fba07d)
- design — list the files /index and the pen-design setup create (c7fcf82)
- backlog — park the SwiftBar menu (572940d)
- specs — add specs 583-600 for design inventory and context pipeline (c2fc2f3)
- rules — i-have-adhd outranks report templates in the answer (e1ba967)
- spec — two verify rules from the Spec 580 retro (d864443)
- conventions — name parity-fixture for frozen fixture edits (07acdea)
- agent-graph — name the nested-checkout exemption of the read gate (1aec52b)
- devkit-issues — parallel worktree route and its integration duties (14ab4f6)
- workflows — re-anchor after spec-update, review and wave edits (0872b8c)
- content — adopt Opus 5.5 prompting guidance (e29087e)
- eval — reject broad Jev effort-property batch (e6f4a8f)
- eval — verify Jev recovery after provider outage (9316fba)
- eval — retain routing integration and overhead experiment evidence (6972e2a)
- eval — record green native verification after fixture repairs (2c18d2d)
- eval — record native review context verification (e97e684)
- decisions — Spec 570 retro — the review package carries its ACs (bdddf97)
- evaluation — record catalog and canon delivery trials (35156fb)
- workflows — acknowledge the corrected delegation reference (235683a)
- eval — headroom-proxy README names devkit-eval usage (Spec 575) (90ceb99)
- spec — pre-change recordings come from a base-commit binary (Spec 571) (f6678dd)
- spec — parity recordings must pin a real-input case per port (Spec 569) (af39339)
- spec — read SPEC_GATE_FAIL reason=none as telemetry, not failure (3d4f61c)
- troubleshooting — say that native legacy apply stops before deleting (bd7672b)
- stop promising a native legacy cleanup that does not run yet (593b937)
- audit — instruments for implement tier and second opinion on Opus 5.5 (a2b2833)
- audit — Rust harness overhead pilot and Gortex research (571b362)
- spec — draft specs 572 and 573 for evaluation accounting (b0e69f6)
- context — Rust-only and pinned crate allowlist (spec 571) (887f82f)
- tools — codex host skew via the libexec twin, 2026-09-22 (4793377)
- audit — CI green on 7f92cb9e, the five CI-only host classes named (9070e23)
- audit — record the CI-only host classes and the verifying run (58dc740)
- drop the clean-room section from the reader pages (3582724)
- clean-room loop in AGENTS.md, tool consumers point at the Rust hooks (af4bf70)
- audit — rust migration before/after at the Spec 560 end state (9f6ec8a)
- handoff — native hook entries and the measured before/after (6ba020d)
- conventions — no new shell — executable logic is Rust (02dfdaf)
- research — Laya as open-weight judge behind the jev-probe scripts (91b500d)
- research — ECC research and spec 561 payload secret scan (835ec7c)
- workflows — re-set the docs-source marker after the skill path edits (Spec 560) (0904f37)
- changelog — native affected mode, gate reds, off/unlink ownership (e6d0704)
- handoff — D6 affected mode and the review fixes (09d202a)
- changelog — has script, path script and the native gate arms (49b0233)
- describe the binary-only runtime (9aa1b62)
- delegate — keep the skill under its token budget (3e153ea)
- workflows — re-set docs-source marker after the prep-lib decoupling of /spec (ee381fb)
- gate follow-ups for the dev-sync binary and the pen-mcp subcommand (09f1517)
- rust — handoff START HERE for session 2 (state, in-flight ports, E design) (70c4df8)
- delegate — a dsh implement cannot commit in a linked worktree (430edb2)
- rust — handoff START HERE for the next session (state, next steps, method) (62ca153)
- rust — correct the record — 560 reverted; Codex audit findings and real scope (01edb5a)
- rust — complete 560, mark 520 executed, record the finished migration (cc927cb)
- rust — coverage map done; 522's last step is the gated 560 deletion (e6f03fc)
- rust — full tests/all.sh gate green; record the six fixed reds (a4903b2)
- decisions — backfill ledger rows for the enforced Rust-migration specs (Spec 523) (35d7b9b)
- rust — the delegate/review bridges are native; name the remaining bash uses (f656e1b)
- rust — name the Spec 520 blocker behind cli/run/resolver parity (fdac135)
- rust — wave 554-558 complete, 5/5 merged; note the remaining live-shell targets (bb2eb84)
- rust — wave 554-558 progress (4/5 merged) and the two setup fixes (abb8204)
- rust — record the in-flight 554-558 wave handles (Spec 522) (9c4a2e6)
- rust — record the 518 full-suite load flake (Spec 522) (73ea4d3)
- rust — record the 522 enablers, progress and remaining target set (0d07542)
- audit — Pi harness readiness inspection (a81b362)
- design — list design-status's unsaved state on the reader page (24a4fd2)
- changelog — unreleased entries for issues #98-#109 (3cebb87)
- delegate — dsh reads brief inputs from $HOME, not /tmp (1b8228d)
- pen-design — name the stable path for update-proof references (8842f29)
- pen-design — three pencil API traps from the field (416bb20)
- pen-design — set live-import width with a browser node (502be06)
- pen-design — document the guillemet sample-data convention (0fd3c3b)
- workflows — re-anchor the marker after the delegate-visible clarification (878d735)
- delegate — make the delegate-visible child route explicit (fa94b9f)
- rust — record wave 1 and the real dispatch route in the handoff (df923b9)
- rust — close 551 as superseded and correct the handoff (Spec 551) (fe72b71)
- specs — add spec 553 for cb as a recommended tool (f81e6b9)
- jev — record the fast-jev-compaction re-check (unchanged, decline stands) (946334f)
- rust — hand off the integration state to the next session (2c70484)
- refresh the workflows page marker after the context-fill change (231043f)
- reference — record the 2.1.275-2.1.278 changelog verdicts (3263f04)
- design — re-set the docs-source marker after the naming key (40ff5cd)
- audit — add the next-session handoff runbook (f014efb)
- audit — record the fully-spec'd remaining plan (507-522) (4be5513)
- design — re-set the docs-source marker after the build-order review (ee85caf)
- delegate — record that the HTTP runtime shape is gone, add brainstorm 008 (bb819db)
- audit — partial ports completed (498/499) (0a9e7cb)
- audit — record wave 2 (specs 477-497, 62 native modules) (46d994a)
- audit — close out the rust migration wave (43 native modules) (ce7818a)
- audit — record spec-id-next (474) in the migration status (f456e9a)
- audit — full before/after sweep for the 23 native subcommands (653ba0e)
- audit — close out the read-only rust migration surface (ccfdf65)
- pen-design — adopt three pen CLI surfaces the skill ignored (56ab38e)
- how Pen's chat runs on a Claude subscription (1dd3180)
🧪 Tests
- rules — sync from a private payload snapshot, not the live checkout (eb70a74)
- rules — show devkit sync's output when the sync check fails (dde4d5b)
- review — a refusal's closed stdin is not a test failure (413520a)
- support — nested_repo_boundary test survives a stray ancestor .git (a38866f)
- usage-report — record mode re-records from the native binary (ecbc3c8)
- retire the shell-parity recording corpus (0ea6481)
- context-pack — run the fake codex without the host PATH (b4b6642)
- rules — tooling.md drops the project-migrate line on purpose (615fb52)
- parity — jq recordings carry Spec 584's design-inventory step (9af1c44)
- usage-report — normalize scratch paths under any temp root (f5ca916)
- parity — switches recordings carry the Spec 577 guard text (38ae377)
- parity — map the recorded adhd-subagent hook to subagent-context (Spec 597) (a72f779)
- refs — check bare header pointers and fix the two dead ones (4a15b15)
- delegate — claude_stdin allows the fixed unattended-turn prompt in argv (d457839)
- usage-credentials — the hint names devkit maint usage-report (Spec 581) (ec19d3a)
- devkit-eval — make the missing-acceptance case host-independent (04a75cc)
- affected-map — run crate unit tests for every devkit source edit (dfd4230)
- rules — accept the deliberate orca row rewrite in the pre-baseline (dc08be6)
- rust-only — re-record the help fixture for the extension note (c96970e)
- affected-map — route delegate and review-runtime sources (5d27ddf)
- cleanroom — stub npm for the captured clean-room script (00effc1)
- delegate — reproduce oversized Claude brief failure (2315a04)
- support — gate against new private helper copies (43ccb84)
- skew recordings carry the host path token, rust-targets slices may skip without cargo (215159d)
- ci — optimized dev binary, Rust targets in four slices, real suite seconds (4d5de78)
- rust — wave-prep and doctor fixtures stop reading the runner's arch and PATH (2277c52)
- rust — the parity mirror never links tree (815ca71)
- rust — entry fixture pins platform and arch (eeae1f5)
- rust — hermetic tools fixtures (f9cad37)
- rust — hermetic project-migrate fixtures (0754655)
- rust — hermetic index-prep fixtures (a756b36)
- rust — doctor fixture stubs npm so tool freshness stops reading the host (06efe5d)
- rust — parity fixtures stop depending on the recording box (Spec 560) (4ec14a5)
- rust — doctor broken-home fixture dangles a fixed workflow link (166262a)
- rust — doctor parity fixtures no longer depend on the recording box (49a89cf)
- fixture runners hand the prebuilt binary to their all.sh copy (a3a1e90)
- run the survivor suites against the binary, drop the shell-mapped ones (0373eeb)
- rust — script_parity_507 fixtures no longer freeze $TMPDIR (b21e480)
- rust — re-record the switches --json runtime fixture (2191768)
- rust — re-record the switches --json resolver fixture (62a051e)
- rust — drop the caller's home PATH entries under the sandboxed test HOME (406f24b)
- rust — mask age_days in the index-prep parity twins (3279d6d)
- rust — hermetic PATH for the plugin reconcile fixtures (0e3b13f)
- rust — hermetic PATH for the prime-run parity fixtures (3e08b83)
- rust — hermetic doctor tools case; the shell twin stays on the shell (f52b71e)
- rust — decouple runtime_hooks_parity from the live shell (110b2d9)
- coverage — map env-block and release to native targets (685035c)
- release — make the release chain standalone and Rust-gated (Spec 560) (3f3b361)
- parity — mask calendar dates and derived digests in 475/490 (c10e83b)
- rust — decouple index_prep_parity from the live shell (normalised modes/checkout/version) (f7afe18)
- rust — drop orphaned index_prep fixtures after reverting its decoupling (3b0f5e6)
- rust — decouple index_prep_parity from the live shell (018e51a)
- rust — decouple doctor_parity (present-green; script-count lines remain a 560 item) (ae99f86)
- rust — decouple prime_run, wave_prep and workspace_run parity from the live shell (9dbd10d)
- rust — decouple script_parity_507 from the live shell (3cfdbfc)
- rust — decouple skills, spec_work_prep and test_prep parity from the live shell (47d2c09)
- rust — decouple quality_gate and share_prep parity from the live shell (dsh) (1c23195)
- rust — decouple agents and agents_materialize parity from the live shell (39af197)
- rust — decouple script_parity_499/514/515/516 from the live shell (7692d2a)
- rust — decouple script_parity_498; mask path-dependent prompt byte count (f4ca0b5)
- rust — decouple script_parity_494/495/496/497 from the live shell (5394452)
- rust — decouple script_parity_487/489/490/491/493 from the live shell (e9ce2c3)
- rust — decouple script_parity_480/482/483/485/486; tokenise repo root in recorded_shell (178173c)
- gate — add tests/coverage-map.tsv for Spec 522 AC2 (cc0e284)
- gate — clear the six pre-existing tests/all.sh reds (f6d9286)
- rust — decouple project-migrate and generic script parity from the live shell (Spec 558) (f4b8d78)
- rust — decouple state, sync, sync_transaction, rollback and config parity from the live shell (Spec 555) (c6df950)
- rust — decouple detect-stack, runtime and tools parity from the live shell (Spec 557) (3b29cb8)
- rust — decouple remote and openssl parity from the live shell (Spec 556) (f8971d8)
- wave — use mk_sandbox in the glob case to stay under the raw-temp budget (e80b059)
- rust — decouple mcp parity targets from the live shell (Spec 554) (11047f0)
- rust — decouple model_route parity from the live shell (Spec 522) (f540aac)
- rust — decouple script_parity 471/481/488 via the sequence recorder (Spec 522) (5883502)
- rust — decouple script_parity 478/479/517/518/519 from the live shell (Spec 522) (19ec34f)
- rust — give the parity recorder a call-order id API (bc57916)
- rust — decouple script_parity 471/481/488 from the live shell (Spec 522) (d8fbd94)
- rust — decouple nine more script_parity suites from the live shell (Spec 522) (e5f4c17)
- rust — decouple script_parity 474/484 from the live shell (Spec 522 pilot) (890026b)
- rust — add the parity recorder foundation for the Spec 522 migration (75e94f0)
- rust — make the parity gate host-independent on Linux (7c237cb)
- rust — gate the rust workspace in tests/all.sh (770f48c)
🏗️ Chores
- release — cross-build Intel macOS on the Apple Silicon runner (c7e520b)
- run GitHub Actions only for a release (7bb7ebb)
- rust-only — accept the pi hook adapter and its node test (Spec 543) (dee8a13)
- usage — snapshot 2026-09-23 and mark the expectations ledger (5b9f636)
- gitignore the component inventory in this checkout (Spec 586) (cb43489)
- tools — bump eight tool pins and review six external rows (f70b8c1)
- ledger — record the Opus 5.5 review, escalation and measurement rows (c283f3b)
- index — refresh STRUCTURE and fix the placeholder grep (d32bf25)
- maint — follow Spec-569's deleted shell tools in tests and maps (Spec 569) (3e8ab6e)
- ledger — resolve Opus 5.5 effort step-down (98a5b79)
- ledger — record Claude Code 2.1.280 verdicts (d444263)
- cache rust/target per shard so the devkit crate is not rebuilt from zero (a7e6e93)
- cache the cargo workspace across test shards and installer-smoke (9247807)
- spec — complete Spec 560, record the executed switch, repoint the tool registry (ec6b788)
- switches — point every script and lib source at its native reader (c9d9b04)
- release — publish all platform artifacts (b422680)
- install pinned CI tools through the compiled devkit binary (1a290e6)
- rust — complete 559 (native config sources + apply) (c85ed50)
- rust — author 559 (native config sources + apply) and 560 (delete shell runtime) (Spec 520) (d3d7180)
- rust — author the 554-558 wave input for the remaining parity targets (Spec 522) (418f8d3)
- specs — close 538-542/544-550/552 by owner decision (9416a26)
- rust — add 551 (sync content contract) and 552 (prime-run bridge) (d178b96)
- rust — add 549/550 (spec-work-prep, doctor checks) bridge slices (d4d5ab7)
- rust — add 548 (share-prep bridge removal) (42dbd6d)
- rust — add 546 (wave-prep) and 547 (index-prep/workspace-run) bridge slices (b0f2b1a)
- rust — add 545 (native quality-gate runner), bridge removal (d59c702)
- rust — add 544 (native test-prep runner), bridge removal slice (e7e3219)
- rust — add 540/541/542 (sync transaction, project-migrate, release chain) (44712e3)
- specs — close 525-529 by owner decision (8f0576e)
- specs — close 530/532-535 by owner decision (f16ca4d)
- rust — add 538 (MCP reconcile) and 539 (agents materialize) (ceb4834)
- rust — add 530/532-535 (hook advisories, tools, doctor, skills, remote) (2d97004)
- rust — add 529 (native codex/opencode rendering), chain slice (e021588)
- rust — add 528 (native MCP read/normalize), chain slice (ab43f42)
- rust — add 527 (native state/config), chain slice (8e5d8ff)
- rust — refresh the 526 contract digest after the Out of Scope change (2928d93)
- rust — add 526 (native sync/rollback core), supply-chain slice (349fa7d)
- rust — add 525 (native runtime resolver), first slice of the CLI-core chain (565eb68)
- specs — close the remaining five specs by owner decision (78fb16b)
- specs — close the implemented specs by owner decision (09644f8)
- specs — complete the 44 implemented rust parity specs (639c950)
- rust — log the Spec 521 review-fix-4 round and landing (b3ba075)
- repo — move the maintainer context into AGENTS.md (a14722b)
- rust — ignore the hook-pilot prototype build dir (Spec 460) (7edf054)
- rust — add 523 (audit-gate enforcement) and note it in the audit (f5a164d)
- rust — add 522 (test layer migration) (81a973d)
- rust — add specs 507,514-521 for the remaining runtime (next-session migration) (a9df45c)
- rust — add 498-499 (complete partial ports) (0fefe85)
- rust — add batches 496-497 (review engines) (2bbe354)
- rust — add 495 (native spec-validate-prep) (94ffc5a)
- rust — add batches 493-494 (read-only engines) (7a3a3ae)
- rust — add batches 491-492 (4a466e0)
- rust — add batches 488-490 (163e33e)
- rust — add batches 485-487 (read-only) (9e348af)
- rust — add batches 483-484 (58979c7)
- rust — add batches 480-482 (read-only) (11659c6)
- rust — add batches 478-479 (read-only) (6fd55f4)
- rust — add 477 (native brief-gate, friction-hint-prep) (434cb36)
- rust — add 476 (native spec-candidate-dir) (f697826)
- rust — add 475 (native budget-prep, spec-reject-log) (9e6cc36)
- rust — add 474 (native spec-id-next, effect parity) (5b5f68c)
- rust — add batches 472-473 (read-only close-out) (500beed)
- rust — add batch 471 (runtime-route, learning-capture-prep, orca-detect) (cf67026)
- rust — add batches 466-469 and the candidate triage (c8b31a1)
No commit type
- Refactor type alias for metric closures; format test conditional (6b55e98)
- Spec-604: pi dispatch row, spec completed (55a8e06)
- Spec-585 followup: pen-design names the exit-2 path of --check (18fd094)
- Spec-585: adapter inventory line names the recipe on its first line (db1e94c)
- Spec-584/600 followups: skip malformed inventory rows, fresh pointer test (c7ba79d)
- Spec-591 followup: strip the documented block only on NO_TESTS_DETECTED (4625554)
- Spec-600 followup: realign the graph.json row in agent-graph (9d3b8af)
- Spec-596 followup: review context stays inside its 4096-byte budget (5ee849b)
- Spec-593 fix: node-less fallback follows the test-script preference (5f3d62b)
- Spec-593 fix: STACK.md names the npm test script without node on PATH (661657d)
- Spec-590 followup: query codegraph references in 500-name slices (d82c50c)
- Spec-587: index --check and --map cover the design inventory (a316aec)
- Spec-604: /spec-work dispatches the implementer runtime-route picks (9ca6677)
- Spec-595: package.json is read in Rust, not through node -e (917d241)
- Spec-596: gotchas reach Codex, subagents and the review package (e537284)
- Spec-603: runtime-route picks the implement harness per spec (96918d0)
- Spec-584: /index builds the component inventory before the design fill (a524fcb)
- Spec-581: completed — Rust migration closeout (09d8f22)
- Spec-586: one agent-state list; the inventory is gitignored (2463d55)
- Spec-585: bundles, pen-design and the adapter name design-inventory (c3b0526)
- Spec-594: one test-path predicate for four callers (fa7d920)
- Spec-581: evidence after fix round 7 (fa93f5c)
- Spec-581 fix round 7: Retry-After accepts an HTTP date (f1ec537)
- Spec-581: evidence after fix round 6 (cff1b85)
- Spec-581 fix round 6: Blob retries honor Retry-After (89b92df)
- Spec-581: evidence after fix round 5 (c97838f)
- Spec-581 fix round 5: retry Blob requests without concatenated bodies (6a164c2)
- Spec-588: design-inventory --find/--show, the rule queries it first (634adc4)
- Spec-583: devkit design-inventory builds the component inventory (fa33b2f)
- Spec-600: context imports name STRUCTURE.md, graph row names Nuxt (93968ec)
- Spec-591: /test and /debug print the documented test commands (846016b)
- Spec-589: every delegated agent starts with the project's context (7c54780)
- Spec-592: SessionStart names context /index flagged stale or left unfilled (063b08a)
- Spec-581: evidence after Spec-598 touched usage_report.rs (c6ebec4)
- Spec-598: one stack table and one codegraph extension list (7a73249)
- Spec-593: STACK.md names the test command test-prep actually runs (504b4ed)
- Spec-599: delegate-return applies a delegate's changes all or nothing (72a50c3)
- Spec-590: read codegraph's database with a pinned, bundled rusqlite (40162b2)
- Spec-597: subagents no longer receive the ADHD ruleset (43eb849)
- Spec-577: completed after Performance review PASS (cc5a8ba)
- Spec-581: evidence after fix round 4 (7ae71a1)
- Spec-581 fix round 4: usage-report reads the private Blob store (d3868c7)
- Spec-577: evidence after fix round 1b (d707349)
- Spec-577 fix round 1b: heredoc test name stays out of the task_wait filter (481d9da)
- Spec-577: hook cost measurement and evidence after fix round 1 (a74a115)
- Spec-577 fix round 1: a heredoc body is not a wait loop (889df74)
- Spec-577: in review (2198823)
- Spec-577: evidence, all steps and ACs green (05c9325)
- Spec-577 Steps 1-4: deny wait loops on harness background tasks on first sight (2cbe7ec)
- Spec-581: in review (6d274ec)
- Spec-581 fix round 3: ci-cleanroom keeps its native help; AC2 scope (9e87976)
- Spec-581: in review (c93e9d9)
- Spec-581: evidence after fix round 2 (dae01a3)
- Spec-581 fix round 2: maint_parity tables for the three new commands (630e8a3)
- Spec-577: start (052e16a)
- Spec-577: draft — block wait loops on harness background tasks (0e694d7)
- Spec-582: completed — review PASS after one fix round (dbc9f3e)
- Spec-581: evidence, all steps and ACs green (68f8031)
- Spec-581 fix round 1: devkit-usage calls devkit maint usage-report (36fd3dd)
- Spec-582 fix round 1: empty budget flag values are a usage error (c14543d)
- Spec-581: all steps green (f962311)
- Spec-581: start (80e5e92)
- Spec-581: file list covers dispatch, sha1 and parity tables (63fa985)
- Spec-582: acceptance evidence, all ACs green (0501820)
- Spec-582 Step 4: A/B measurement of the wave time-budget signal (1d124e0)
- Spec-581 Step 5: devkit menubar renders the SwiftBar menu, the plugin is a shim (5839939)
- Spec-581 Step 7: rust-only exempts reasoned categories, baseline is empty (ef9fba3)
- Spec-581 Step 2: devkit maint usage-report replaces tools/usage-report.mjs (31eaed3)
- Spec-581 Step 3: devkit maint corpus-probe replaces both Python copies (9e854b0)
- Spec-580: completed — move to devkit/specs/completed (dfa3a7c)
- Spec-580: evidence after fix round 2 (36d989a)
- Spec-580 fix round 2: bound JSON nesting in the verify scanner (b735423)
- Spec-581 Step 4: the release chain test runs natively (fe0065c)
- Spec-580: evidence after fix round 1 (7d2d3e2)
- Spec-580 fix round 1: record temp file is random and removed only when created (f709279)
- Spec-580: all steps and ACs green, in review (ec3c770)
- Spec-580 Steps 1-6: the last live Jev probes become native binaries (bc49731)
- Spec-581 Step 1: devkit maint ci-cleanroom replaces tools/ci-cleanroom.sh (67cb575)
- Spec-582 Step 1-3: sweep reports elapsed time against a budget (fafc801)
- Spec-582: start — wave time-budget signal (1f58f94)
- Spec-581 Step 6: delete the dead non-Rust scripts (b5d2add)
- Spec-581: drop the dependency on 580 for Steps 1-6 (ce93a1d)
- Spec-581: draft — Rust migration closeout (75d1d2d)
- Spec-580: start (e3d18f7)
- Spec-580: draft — last Jev probes become native binaries (ac4f552)
- Spec-576: completed — move to devkit/specs/completed (12360cf)
- Spec-576: evidence after fix round 1 (84734aa)
- Spec-576 fix round 1: rust-only scans from the worktree top (877219f)
- Spec-576: steps and acceptance evidence, in review (5ad506f)
- Spec-576: contract — the parity table and recordings the gate needed (acd8cc8)
- Spec-576 Step 5: name the rust-only gate in the Rust-only convention (287e223)
- Spec-576 Step 4: route non-Rust changes to rust-only, watch its baseline (6fe8c5e)
- Spec-576 Step 3: run rust-only as the gate's 15th scanner (79889f2)
- Spec-576 Step 2: freeze the 78 existing non-Rust files as baseline (b63df61)
- Spec-576 Step 1: add devkit maint rust-only scanner (7b55630)
- Spec-576: contract — reconcile scanner count after Specs 569/570 (cc32ab3)
- Spec-570: completed — move to devkit/specs/completed (e17ad2c)
- Spec-570: evidence after fix round 1, in review (2ad5909)
- Spec-570: contract — Step 2 owns the private temp-root helper (69cb33a)
- Spec-570 fix round 1: the runner's temp root is private and exclusive (f50089e)
- Spec-570: acceptance evidence after the Step 2 fix, in review (b376774)
- Spec-570 Step 2 fix: pin the tracked evaluation target, not a foreign one (e494b05)
- Spec-570: steps and acceptance evidence (fec1d8d)
- Spec-570 Step 8 fix: AC11 heading, dual help examples, runner case (17eec67)
- Spec-570: contract — Steps 2 and 8 own the eleven files they touched (dbd0187)
- Spec-570 Step 8: delete the shell test layer, repoint to test-prep (222c1da)
- Spec-570 Step 3: fold the 15 gate-tool suites into maint_parity (82b044e)
- Spec-570 Step 2: devkit maint test-prep runner, retire test-sandbox (9d1c566)
- Spec-570 Step 1: record the shell suites' verdicts in suite_parity (fbcc3b6)
- Spec-570 Step 5: port the evaluation/telemetry suites to Rust targets (5d9163b)
- Spec-570 Step 4: port the Node/design skill-script suites to Rust (b7d65ca)
- Spec-570 Step 6: port the content/reference suites to Rust targets (1fb998c)
- Spec-570 Step 7: port api and context-tier suites to Rust targets (4dbfaf8)
- Spec-575: completed — move to devkit/specs/completed (2b0003b)
- Spec-575: steps and acceptance evidence, in review (af5cb10)
- Spec-575 Step 6 follow-up: clippy-clean the devkit-eval targets (c84427f)
- Spec-575 Step 6: delete the Python evaluation tools (324770f)
- Spec-575 Step 5: point evaluation callers at devkit-eval (ced8df0)
- Spec-575 Step 4: native devkit-eval usage (221ff70)
- Spec-575 Step 3: native devkit-eval compare (2bc5cf3)
- Spec-575 Step 2: native devkit-eval inventory and check (9499122)
- Spec-575 Step 1: record devkit-eval Python observations (fad6647)
- Spec-571: completed — move to devkit/specs/completed (d4e21a4)
- Spec-571: acceptance evidence after fix round 1 (be53a8e)
- Spec-571 fix round 1: jq 1.7 number printing and honest twins (e1f0b03)
- Spec-570: contract — re-cut against the landed 568/569/571 tree (569ab43)
- Spec-569: completed — move to devkit/specs/completed (132343e)
- Spec-571 Step 9: jq-missing cases compare against jq-present runs (9afe79d)
- Spec-569 fix round 1: credential rotation, clean-room build, timeouts (2577e78)
- Spec-569 Step 8: delete the 57 shell tools, every consumer native (ed61682)
- Spec-569: contract — Step 8 owns every consumer of a deleted script (02a6f40)
- Spec-571: contract — Step 9 covers every jq-missing and jq-naming case (64e6448)
- Spec-571 Step 5: the 15 script parsers give way to json_value (70bc5fa)
- Spec-571 Step 7: the spec-lifecycle jq programs become Rust (b4b38b3)
- Spec-571 Step 6: index-prep and the spec scripts parse and print once (bc4fc40)
- Spec-571: contract — Step 5 owns the five nested Json callers (bd736be)
- Spec-571 Step 8: the remaining jq programs become Rust (1ad2b0d)
- Spec-569 Step 4: Slice C ports discriminate — all 57 tables green (8a15c52)
- Spec-571 Step 2: mask ISO clocks and invented names in jq_parity (3736309)
- Spec-571 Step 2: mask time-derived bytes in the index snapshots (3e6d90a)
- Spec-569 Step 2: Slice A ports are real (b7831ea)
- Spec-569 Step 3: Slice B ports discriminate, secrets written private (23ab29f)
- Spec-569 Step 5: Slice D reference ports discriminate (e45ea10)
- Spec-569 Step 6: Slice E ports discriminate, dev-sync works privately (342e440)
- Spec-571 Step 3: the hook path runs without jq (a15cd3a)
- Spec-571 Step 4: core JSON on the facade, jq gates gone (0362407)
- Spec-571 Step 2: record with jq alone, re-record on the jq-era tree (f102c09)
- Spec-569 Step 7: Slice F ports discriminate and write privately (8b3844f)
- Spec-569 Step 2 (part): Slice A pairs recorded against the shell tools (9f33d27)
- Spec-571 Step 2: record jq-era observations before any migration (b0aa480)
- Spec-571 Step 1: serde_json facade with jq 1.7 reader and printer (22fdf06)
- Spec-569 Step 1: discriminating recorder harness (d2c0e8c)
- Spec-571: contract — every JSON parser and jq child onto one facade (acc2c2f)
- Spec-574: completed — review PASS (Security), 5/5 steps, 4/4 ACs (ce07a3a)
- Spec-569: contract — recordings must reject stubs, secret writers private (7532f89)
- Spec-574 Step 5: docs generator counts 0 scripts when content/scripts is absent (634bb24)
- Spec-574: contract — Step 5 keeps the docs generator working without content/scripts (8a52333)
- Spec-574 Step 4: delete check-run.py and shopify-schema-lint.py (eba1f43)
- Spec-574 Step 3: pipeline-bench-run trusts the sandbox natively (a78539d)
- Spec-574 Step 2: regression test for spec-checks without python3 (f4f9589)
- Spec-574 Step 1: spec-checks runs verifies through native check-run (0b9e1e2)
- Spec-574: contract — spec-checks and pipeline-bench-run stop spawning python3 (2044f06)
- Spec-576: contract — A rust-only gate turns a new non-Rust executable red (7642e70)
- Spec-575: contract — The maintainer evaluation CLI becomes a native devkit-eval binary (e203ef4)
- Spec-569: record the blocking state and the review's findings (bc3cbea)
- Spec-568 retro: wire the two lessons the run paid for (7673a45)
- Spec-569: record the run's lifecycle state (4f41ae5)
- Spec-569 Step 8: a ported compat probe is a module, not an executable (38a8ce4)
- Spec-569 Step 8: delete the 57 maintainer shell files and repoint every consumer (6542198)
- Spec-568: move the completed contract into completed/ (e32462f)
- Spec-569 Step 3: port Slice B, the CI, release and registry tools (ca06bcc)
- Spec-569 Steps 5+6+7: port Slice D, E and F to devkit maint (3796d18)
- Spec-569 Steps 2+4: port Slice A and Slice C to devkit maint (8a1c23f)
- Spec-569 Step 1: name each recorder test after the slice that owns it (58ef2e6)
- Spec-569 Step 1: record every maintainer script before it is ported (9844b0d)
- Spec-568: close three guard holes the sections review found (40b3a96)
- Spec-568: close the delta round's follow-ups (c1b7956)
- Spec-568: close the review's five blocking findings (3e06c1a)
- Spec-568 Step 5: the Codex guard rows name their subcommand in full (e95a990)
- Spec-568 Step 7: the 25 shipped hook scripts are gone (5d4abf9)
- Spec-568 Step 6: the wiring writes the binary, unconditionally (0cac621)
- Spec-568 Steps 2/4/5: parity fix round — every recorded hook replays (92656d9)
- Spec-568 Step 3: PostToolUse group ported natively (8293851)
- Spec-568 Step 2: SessionStart group ported — parity fix round pending (f67d73a)
- Spec-568 Step 4: Stop, PreCompact, SessionEnd, SubagentStart, spec-route-probe ported — parity fix round pending (adc06d4)
- Spec-568 Step 5: Codex guard group ported — parity fix round pending (80ea1f2)
- Spec-568 Step 1: deterministic fixture commits, hex runs tokenised before digit runs (a2bff12)
- Spec-568 Step 1: record every shipped hook script into parity fixtures (74d1711)
- Spec-570: contract — every shell test suite becomes a Rust target, the runner becomes devkit maint test-prep (6e488d5)
- Spec-569: contract — every maintainer shell tool becomes a hidden devkit maint subcommand (9e3dec5)
- Spec-568: contract revised — SwiftBar decoupled (owner decision 2026-09-22) (0aee6fd)
- Spec-568: contract — every shipped hook, the update boundary and SwiftBar run inside the binary (6c4c902)
- Revert "test(rust): decouple index_prep_parity from the live shell" (b263374)
- Revert "feat(rust): delete the shell runtime, make the binary the devkit entry (Spec 560)" (36b2964)
- Revert "docs(rust): complete 560, mark 520 executed, record the finished migration" (be98b95)
- Spec-531: close review MEDIUM/LOW, record fix round (9fc0406)
- Revert "test(rust): decouple nine more script_parity suites from the live shell" (d3e06be)
- Spec-531: cover the caret pin form in the dsh idempotency fixture (4c6005a)
- Spec-531: record independent review (BLOCK, 3 findings) (c9d57d3)
- Spec-531: steps and ACs green, in-review (b050b3b)
- Spec-531: dsh implement (7d80029)
- Spec-531: fix AC1 verify, add pnpm registry page scope (2873c9d)
- Spec-453: dsh implement (33aa5d5)
- Spec-459: dsh implement (9d9804e)
- Spec-454: dsh implement (08abd8a)
- Spec-519: dsh implement (18b107a)
- Spec-518: dsh implement (245a44d)
- Spec-517: dsh implement (0e03745)
- Spec-516: dsh implement (1005f9a)
- Spec-515: dsh implement (9878f42)
- Spec-514: dsh implement (2164d79)
- Spec-507: dsh implement (e97a718)
- Spec-523: dsh implement (b680a42)
- Spec-460: dsh implement (a343b7c)
- Add Spec 465: native devkit detect-stack parity (6109cce)
- Add Spec 464: native devkit model-route parity (cd92839)
v0.40.0 — 2026-09-18
/pen-design ships as the working version — 203 to 1,276 lines, twelve checkers, every stack we ship. Specs lost two gates: starting /spec-work is the approval, and /spec-verify with its UAT pass is gone after 0 invocations over 138 completed specs. A broad prompt cost 1,760 hook tokens and now costs ~618. Update with devkit sync.
187 commits since v0.38.0 · Specs 065, 079, 084, 412, 444, 445, 449, 450, 451, 452, 454, 455, 457, 458, 460, 461
✨ Highlights
🎨 /pen-design ships as the working version, on every stack
The skill grows from 203 to 1,276 lines — the version that produced 122 measured findings over four weeks on a live Shopify redesign — and its twelve checkers now travel into every project instead of living in one repo. Nuxt, Nuxt/Storyblok, Shopware and Laravel join Shopify on one tokens/inventory/rows/owners contract, and the index shrank from 22,372 tokens to 2,934 plus 19 references.
node "$(devkit path skill pen-design)/scripts/design-adapter-check.mjs"🖊️ /pen-design brings its own tools — CLI and MCP now ship with the setup
The skill arrives with both of its tools left to the reader: npm i -g @pen.dev/cli by hand, and a pencil MCP block hand-written into ~/.claude.json pointing into /Applications/Pen.app. A second machine got the 1,276-line skill and nothing to run it with. Both are declared now — the CLI is pinned in the tool manifest, and the MCP runs the platform server binary that ships inside that same package, resolved at start time instead of hardcoded, so it works on arm64 and x64, macOS and Linux, with or without Pen.app installed.
devkit sync --optionalIt stays an optional tool because the package is 732 MB (measured) — the same reason mmdc is optional. Pen.app itself remains a download from pen.dev; there is no Homebrew cask. Without the running app the MCP still starts and fails at the first design call rather than hanging the session.
The pencil entry is Claude-only on purpose: measured on opencode, a delegate that merely inherited it spent 5 tool calls and 21.7k first-turn tokens on it before seeing its own brief, so the dsh overlay now mirrors only the servers targeted at Codex.
🧰 Every optional tool on one page, with what it costs and what it unlocks
Nine tools ship declared but uninstalled — 2.6 GB together — and until now the only place that named them was one sentence in the quick start, without saying what any of them do. Optional tools gives each one its workflow, its measured size and the step that is still yours: codex wants a login, dsh a provider key, pen a subscription and Pen.app. It also says what happens when one is absent, which is not the same everywhere — /share refuses a Markdown file without pandoc, while /commit without osv-scanner commits and reports the skipped scan.
devkit sync --optional🚪 Starting /spec-work is the approval
/spec and /spec-update no longer ask Approve/Refine/Abort — they write the validated, reviewed contract, and starting /spec-work binds it. /spec-verify and the UAT commit gate are gone with it (0 invocations, 2 files over 138 completed specs), and a failed AskUserQuestion — 28 of its last 29 calls inside Pen's agent — falls back to plain text.
/spec-work 452🔄 Tools update themselves
devkit tools --auto-upgrade upgrades every installed tool under its own kernel lock, throttled to once per 24 hours; devkit sync now runs it too (DEVKIT_TOOLS_AUTO_UPGRADE=0 opts out). Six benchmark rounds building it took the native implementer from 29.5 to 15.3 minutes.
devkit tools --auto-upgrade🛡️ A broad prompt no longer buries the turn in gotchas
gotcha-recall.sh holds the only exception from the 300-token per-turn hook cap, justified as bounded by the number of Trigger: matches. Nothing bounded it: a prompt matching six Critical entries emitted 1760 tokens, 5.9× the cap. DEVKIT_GOTCHA_RECALL_MAX (default 2) now bounds it to ~618. A held-back entry keeps its marker unwritten and arrives on a later matching prompt — the cap delays, it never drops.
DEVKIT_GOTCHA_RECALL_MAX=2🔁 The always-on ruleset returns on a cadence instead of on every prompt
content/hooks/style-reminder.sh re-emitted the pinned i-have-adhd pre-send check on every user prompt. Each copy is ~200 tokens, the transcript keeps all of them, and the N-th turn pays for every earlier one. Measured on one live session: 26 identical copies. The hook now re-emits only once the last copy is more than DEVKIT_STYLE_REMINDER_TURNS user turns back (default 5); DEVKIT_STYLE_REMINDER_TURNS=0 restores the old every-turn behaviour without a code change, and a typo in that value falls back to the default instead of disabling the gate.
DEVKIT_STYLE_REMINDER_TURNS=5🔁 Review re-checks shrink again
A reviewer now reads a recorded suite instead of re-running it — one run spent 4 of its 8 minutes re-running a 191-assertion suite already recorded on the same SHA. spec-checks runs an identical whole-verify command once instead of up to eight times per acceptance pass, drift outside a spec's declared file list no longer voids the review (Spec 451 lost a full re-prep to a byte-identical scoped diff), and a parallel session's diffs enter the review package as a stat line instead of a full 72 KB dump.
/spec-work 450🤖 /delegate implement picks its own runtime and doesn't idle forever
The implement chain falls back prime → dsh → kimi → claude, each hop depth-capped so a delegate can't re-delegate past its limit. A claude -p run wrote code for 19.5 minutes without running one test, so implement now passes --allowedTools Bash, runs in the foreground, and ends itself after 900 seconds of silence.
runtime-route.sh --inventory implement🔀 OpenCode joins the delegate registry for the read-only tiers
opencode (oc) runs research and architecture questions isolated from your own OpenCode and Claude Code config — without that isolation a user's own MCP servers answered five tool calls inside a review and the first turn cost 21.7k tokens instead of 14.9k. It carries no review seat: the free models 403 the moment the devkit-review permission block lands, so review still routes codex → kimi → dsh.
/delegate opencode research🧭 /spec prints its mechanical route before judging
spec-route-prep.sh reads the planned file list against the irreversible-surface rules and the test-suite map and prints ROUTE=direct|spec|judge with the paths that decided it, before /spec's own route table. Two five-file changes with deterministic suites had gone to a full spec by feel and cost ~25 minutes of gates each.
spec-route-prep.sh <path...>📋 spec-checks.sh --evidence-from imports a gate run from another host
A project whose gate only passes on Linux CI recorded a false exit=1 on every AC checked from a Mac. --evidence-from <summary> imports a gate's evidence from a summary written on the other host, after checking phase, digest and AC selection.
devkit run spec-checks.sh devkit/specs/452-*.md --run-dir /tmp/checks \
--phase acceptance --section acs --append-evidence --evidence-from ci-summary.json🧹 A foreign linter now counts only what you changed
96 pre-existing theme-check errors read as 137 after a merge — looking like 41 self-inflicted regressions that were none of them. lint-delta.sh filters any linter's output to the files this tree actually changed; --baseline also lints a clean base worktree and shows only what's new.
devkit run lint-delta.sh -- npx theme-check --path .🎨 A first pen-design setup run survives its own gate
A first-time pen-design setup run peaked at 140,643 tokens and auto-compacted mid-task; handed to a fork, the same work finished at 120,268. The fork is now the default for setup, which also draws its two system sheets and no longer fails its own acceptance gate on them.
node "$(devkit path skill pen-design)/scripts/design-check.mjs"What changed for you
Now available
/delegate opencode research|architecture— OpenCode as a read-only delegate next to codex, kimi and dsh.runtime-route.sh --inventory [tier]— lists every delegate runtime's state (ready, disabled, not-ready) for a tier.devkit tools --auto-upgrade— throttled, self-locking upgrade of every installed tool; also runs insidedevkit sync.! cb tasks fetch <id>— the three CrewBuddy fetch skills name the shell prefix in their argument hint: the CLI runs in seconds with no model turn (a colleague measured 28 s through the skill vs 2–5 s in the terminal).devkit tools --outdatednow tracksdshandprime-agentwhen they were installed through theirtools.jsonpins.lint-baseline— reports a file's new and fixed lint findings against its base and exits 0 when nothing was added; repeat calls read a per-blob cache instead of re-linting.design-tokens.mjs --diff— writes only new or changed canvas tokens and reports a same-value alias instead of a duplicate (measured: 44 equal, 0 to write, 3 aliases over 41 bound nodes).--evidence-from <summary>onspec-checks.sh— import a gate's acceptance evidence from another host (needs--append-evidence,--phase acceptance --section acs).DEVKIT_DELEGATE_MODEL,DEVKIT_DELEGATE_EFFORT,DEVKIT_DELEGATE_NO_RETURN,DEVKIT_DELEGATE_IDLE_ABORT_SECS— per-call overrides for a delegate run.- Stack references for Nuxt, Nuxt/Storyblok, Shopware and Laravel under
/pen-design— the same adapter contract Shopify already had. devkit run lint-delta.sh -- <lint-command>— a foreign linter's findings cut to the files you changed;--baselinealso lints a clean base tree.- Optional tools — one page for all nine declared-but-uninstalled tools (2.6 GB together), with each one's workflow, measured size and the step that stays yours.
Behavior changed
/specand/spec-updateno longer ask Approve/Refine/Abort; starting/spec-workor/waveis the approval./spec-verifyand the UAT commit gate are gone;/commitno longer readsdevkit/uat/(0 invocations across every project since it shipped on 2026-08-15).- Any failed
AskUserQuestioncall now falls back to one plain-text question instead of stalling the turn. /delegate opencodehas no review seat — the free models 403 under the review agent's permission block, soreviewroutes codex → kimi → dsh./delegate implementunder Claude runs in the foreground with Bash allowed by default, and ends itself after 900 seconds of silence./delegate implementruns at high effort instead ofxhigh; the implementer batches every turn and verifies at most twice per Step — 146 → 76 turns, 22 → 2 suite runs on one spec.- The three
cbfetch skills lost their preflight and flag-forward trap: measured 38.5 s / 7 turns → 29.8 s / 4 turns on one task. - The three fetch skills print
devkit toolsand stop whencbis missing, instead of falling back to MCP tools that write no digest and no fence. - A review no longer voids when drift lands outside the spec's declared file list — only a declared or contract path moving still exits 3.
- Your own OpenCode sessions start without a permission prompt for every tool; delegate runs were already isolated and are unaffected.
- Orca-visible delegate runs no longer steal your active worktree view or leave stray Terminal/Setup tabs behind.
spec-id-next.shnow also counts specs on unmerged branches, so two authors working on separate branches can no longer land on the same spec number./specno longer pulls the written spec into the Orca editor — it names the path instead (a seven-spec session had a file yanked forward a dozen times).spec-finishrefuses a receipt gap before it appends anything, so a retry no longer needs a fresh prep and a new reviewer confirmation.spec-validateaccepts a declared path whose deletion git tracks, and an AC whose verify runs the quality gate needs no Step that pretends to edit it.- A rebased commit no longer reads as design drift;
design-statusreports a rewritten stamp and names the replacement by subject. - A
/pen-designcomponent frame (reusable, orEbene: Component|Block) needs--selectorondesign-verify, or the run fails with a missing-anchor finding instead of a page-wide false pass. - A
custom_*_classchain with!importantor more than 8 classes on a Shopify template instance is now a preflight finding (CLASS CHAIN) — it names a component that belongs in its own block. - The four Shopify build helpers take their entries and token path as arguments or from the adapter, and exit 2 with a message instead of a node trace.
.agents/design-check.project.js(K8 and up) is read from the project only — the core checker no longer carries one project's own vocabulary.- A
/pen-designframecontextover 600 characters is now adesign-marker-checkfinding — the field carries the frame's claim against the code, not owner decisions or draft history (measured: 61k characters across 108 contexts in one project). /agent-browsertriggers on a live-URL check, not only on a file edit.- A bumped plugin pin now actually lands: the marketplace ref is moved first and the update receipt confirms the new version (memsearch was stuck at 0.4.18).
/pen-designsetup now forks by default and draws two system sheets (tokens, icons) that its own acceptance gate no longer rejects.design-tokens.mjsconverts oklch/rgb/hsl/lab/lch/color() to hex instead of passing them through;--diffalso reports a canvas-only token as NUR IM CANVAS.design-adapter-check.mjsno longer truncates a monorepo path (dashboard/app/...) to its known directory name and reports it as dead.stack-shopify-liquidnames the vite-tag.liquid trap: a runningshopify theme devblocks every merge/rebase/pull touching it, with the one-line fix.- The hook token policy now loads while you are writing a hook:
content/rules/hooks-token-policy.mdlistscontent/hooks/**beside.claude/hooks/**, pinned by a test. - A workflow script stays under 10 agents: Claude Code 2.1.271 lowered the "medium" size guideline from 15.
/spec-worksees a monorepo's nested member repo: drift, tests and review resolve against the member rather than the outer checkout./pen-designearns a section's full bleed from the adapter'sbleedkey instead of assuming it, and measures radius and container in the value gate.spec-updateno longer deadlocks validation when a review waiver is installed.- A blocked runtime reader gives up instead of spinning forever.
/pen-design's marker check follows a snippet to every render site and names each caller that carries no frame marker of its own; an unresolvable render target is disclosed instead of quietly skipped.korrektur-checkneeds--entryor--ledgerand exits 2 without one — it no longer defaults to the newest block, which used to verify a stale entry and report it complete.skill-lintno longer printsprintf: write error: Broken pipeon a green run — the eightprintf | grep -qpipes that raced under load are here-strings now.
Action required
- Start a new session after
devkit sync— this range ships new hooks and writes an OpenCode permission entry, and neither reaches a running session. - On a canvas that already has variables, run
design-tokens.mjs --diff(not the plain form) before writing — a fullSetVariablescan add dead duplicate tokens beside the canvas's own names. - A component frame's
design-verifycall now needs--selector <element>; add it wherever a/pen-designcommand runs one without it.
🚀 Features
- spec — The approve gate yields on direct work, opens the candidate, ends at completed (b2fd91b)
- pen-design — The skill migrates completely, the stack checkers move with it (efa6376)
- scripts — The twelve pen-design checkers now run in every project (20ee4e2)
- delegate — Opencode joins the registry for the read-only tiers (Spec 444) (dd7b7de)
- tools — dsh and prime-agent install optionally through tools.json (0867a90)
- spec — spec-route-prep.sh prints the mechanical route before /spec judges (0a61f5b)
- review — Drift confined to paths outside Files to Modify keeps the verdict (Spec 451) (4909540)
- spec-id — Count specs on unmerged branches, name the check dir inline (10310c1)
- delegate — a silent run ends early instead of burning its bound (657b644)
- delegate — DEVKIT_DELEGATE_MODEL picks another opencode seat (1477e7e)
- scripts — lint-baseline compares a file's findings with its base (3c55b82)
- delegate — DEVKIT_DELEGATE_EFFORT overrides one claude call (Spec 452) (3d08e16)
- spec-checks — import acceptance evidence from another host (856ff33)
- opencode — start without permission prompts for every user (738e6bf)
- pen-design — design-tokens --diff names aliases instead of writing (4176000)
- delegate — DEVKIT_DELEGATE_NO_RETURN keeps a comparison run (Spec 452) (e7b996e)
- routing — implement tier runs at high effort (Spec 452) (9f06466)
- spec — starting /spec-work is the approval, no gate question (328c1ac)
- pen-design — the design flow runs on every stack we ship (72be77c)
- stack-shopify-liquid — the four build helpers move along (56af507)
- run-cost — read dsh session usage as a cost source (b9db1e6)
- telemetry — drain Codex rollouts on Codex session start (1d2c65a)
- telemetry — Codex usage aggregate and runtime field (Spec 458) (ad3f274)
- evaluation — add the skill-routing lens and repair the assertion extractor (5aad3d5)
- delegate — opencode reviews on a free non-DeepSeek seat (465aaa8)
- spec — warn on untracked consequence readers at authoring (Spec 455) (16f86db)
- distinguish delegate work from elapsed time in run-cost (Spec 457) (cb9e2ba)
- evaluation — qualify TypeSafe Jev and add two maintainer triage lenses (3166265)
- tools — ship the pen.dev CLI and pencil MCP with the setup (055525c)
- pen-design — a section's full bleed is earned, not assumed (0b1efa8)
- pen-design — the section-geometry rules are decided, not just printed (7816008)
- pen-design — measure radius and container in the value gate (d41d73c)
- spec-work — drift, tests and review see a monorepo's nested member repo (ab76980)
🐛 Fixes
- fetch-skills — Name the shell-prefix path that skips the model (14860a0)
- pen-design — skillDir finds the shipped skill, not only a project copy (9bc7363)
- fetch-skills — Remove the auth preflight and flag-forward trap (2813bd2)
- delegate — A visible run no longer steals the Orca view or leaves stray tabs (7afaf6f)
- spec-work — An implementer proves every negative case red on its own (Spec 450) (746b429)
- spec-444 — Record retro and wire the write-path rule into the delegate skill (Spec 444) (0c441e1)
- delegate — Forward CLAUDECODE and the depth cap into the Orca terminal (Spec 444) (4bbd8c0)
- delegate — Resolve a relative --brief against the caller's checkout (Spec 444) (66ad596)
- hooks — ship the background-wait-guard advisory its row already names (744d7a6)
- docs-locale — docs/shared is a /share source, not a site page (56f11bc)
- delegate — claude implement runs without background tasks (Spec 452) (3b7cef7)
- spec-finish — refuse a receipt gap before appending anything (bea97e4)
- spec-validate — accept deleted paths and gate-only acceptance ACs (91bbfc2)
- content-language — skip agent worktrees under .claude/worktrees (38aeea5)
- issues-prep — count only Closes/Fixes/Refs trailers as coverage (deacf47)
- spec — stop opening the written spec in Orca on every run (fbc331c)
- pen-design — slashed tracking/leading tokens, no pair for parts (6de0f43)
- agent-browser — trigger on live-URL checks, not only edits (0aa4090)
- fetch-task — name the install route when cb is missing (81a3647)
- issues-prep — stop matching commit hashes as issue numbers (Spec 065) (d276795)
- pen-design — six findings from the sp-alpensattel badge session (9675836)
- delegate — claude implement may run Bash (Spec 452) (c700003)
- rules — ask in plain text when AskUserQuestion errors (84caa07)
- pen-design — kimi review — geometry fallback, adapter paths, stale rules (55a0555)
- pen-design — third review round — complete reads, scoped sort, stack-neutral paths (f470692)
- pen-design — second review round — rows, stamps, tokens, exit codes (62b8976)
- plugins — confirm a pin bump from the update receipt (00c1bb2)
- hooks — the policy guard survives macOS bash 3.2 (f5112ee)
- plugins — move the declared marketplace ref before a pin bump (7e6b0d8)
- tool-pin-audit — audit github-checkout pins by commit (d969f97)
- tests — a content/skills change runs the refs suite (75bbf4f)
- pen-design — checkers read the project's adapter, not one project's constants (66c0df7)
- stack-shopify-liquid — helpers stop carrying one theme's rules (e29a1e0)
- pen-design — flags are no canvas path, clean-assets cleans the project (631b385)
- scripts — help and error messages no longer name the deleted project path (4c525b9)
- tests — repair two defects this session introduced (f1bb253)
- delegate — the idle watchdog only judges a streaming runtime (aa939ce)
- tests — make the proof-store mode check run on macOS (8788686)
- hooks — format shell scripts written through a Bash call (Spec 084) (5020d63)
- telemetry — keep a forked Codex rollout's own session id (Spec 458) (d16029d)
- rules — load the hook token policy where hooks actually live (b2bf0e8)
- delegate — return named ignored artifacts and quiet the idle log read (e5c4b4c)
- skills — name the /delegate → /prime-agent relationship, and test the context cap for real (d0f9900)
- rules — forbid a manual browser checklist in place of the self-test (6acd2b4)
- pen-design — --help on every checker, and a named project-file error (7d0ebe8)
- spec-review — keep --completion-validity to one stdout line (77cafab)
- delegate — drop opencode's review seat, cache lint-baseline against its base blob (991769e)
- scripts — put stat GNU-first at three call sites that had it backwards (4e58ed4)
- tools — restore the plugin update receipt Spec 452 removed (f689683)
- reference-scan — corpus-probe ledger filter never matched a hash (c9359e5)
- pen-design — path regex survives a monorepo app root (d222f91)
- pen-design — colours reach the canvas as hex, --diff sees both sides (f62c161)
- pen-design — setup forks, draws its sheets, and passes its own gate (a165988)
- tests — restore the executable bit on tests/all.sh (a7b884f)
- pen-design — the checkers resolve a scan root instead of assuming depth (a59f00c)
- spec-update — an installed review waiver stops deadlocking validation (343bef6)
- devkit — a blocked runtime reader gives up instead of spinning forever (5a80299)
- tests — repair the three assertions that kept CI red (Spec 079) (b10e808)
- pen-design — the frame marker check follows a snippet to every render site (d37b749)
- pen-design — korrektur-check verifies the entry it is given, never a stale one (9bb8f1e)
- tests — shard coverage counts which suites ran, not which passed (dac5987)
- skill-lint — the gate stops writing EPIPE noise to stderr (025f400)
⚡ Performance
- review — Keep a parallel session's diffs out of the review package (Spec 450) (4f87db3)
- review — A reviewer reads a recorded suite, never re-runs it (a01224d)
- checks — Run a byte-identical whole verify once per spec-checks run (Spec 449, 450) (b2372f5)
- tests — refresh the shard weights from a measured run (a7cba20)
- hooks — cap gotcha-recall at two entries per prompt (81636a3)
- spec — skip the probe for single test-suite verifies (Spec 412) (094f6ad)
- hooks — return the always-on ruleset on a cadence, not on every prompt (d23b5da)
♻️ Refactoring
- pen-design — The checkers belong to the skill, not the shared pool (f2a46e2)
- Remove /spec-verify and the UAT commit gate (f2c5e32)
- pen-design — the skill fits its budget, the bundles carry every adapter key (38df965)
- pen-design — English identifiers and comments in the checker scripts (f67b2a3)
- design-check — K8+ belongs to the project, not the core (bd11450)
- spec — move full-route authoring review to a reference (Spec 455) (57e6af5)
📖 Documentation
- evaluation — Document headroom-proxy trial arm-a results and retry harness (559eef4)
- release — Add release notes, headroom/pi trials, and verbosity sign (2307779)
- Re-set the workflows.md marker for the /spec route line (5ca99c7)
- de — Keep workflows.md under the reader prose limit (Spec 450) (94b7795)
- devkit-docs — Rank user-side gains first and write their numbers into the lead (898119c)
- decisions — the in-process Agent stays the spec-work implementer (97b9b5e)
- reader — bring design and workflows back under the prose limit (3bea5d1)
- re-set docs-source markers after #60 and the DESIGN.md abstract move (41d6e96)
- spec-work — the implementer batches every turn (Spec 452) (7925bc3)
- workflows — re-set docs-source marker after #64 (884b413)
- spec-work — Spec 452 retro consequences (Spec 452) (d359f9e)
- design — refresh the source marker (b6a4c16)
- design — refresh the source marker (3ea9fda)
- refresh source markers after the hook and pen-design fixes (086387e)
- spec — 452/453 tools update themselves for every user (402d3af)
- design — refresh the source marker (5026b99)
- design — name the supported stacks and the token command (3b66e89)
- design — a page for designing with Pen (e6c1dbc)
- spec — Spec 452 Steps 1/2 verify against the lint baseline (34762c7)
- spec — draft Spec 454 on context DESIGN fill status (4d93a55)
- research — lavish-axi tool trial and research note (52e14fa)
- changelog — fill Unreleased with the 65 commits since v0.39.0 (9726766)
- pen-design — document context field length cap and table formatting (1737882)
- reference — checkpoint the partial first-party scan (3786272)
- changelog — extend v0.40.0 to the five commits after the prep (ae5f55d)
- stack-shopify-liquid — name the vite-tag trap that blocks every merge (38ee31d)
- pen-design — document stale-render trap on Move; add Rust hook pilot (8ca9a68)
- tools — give the nine optional tools their own page (4b8d5a2)
- design — keep both design pages under the reader byte limit (928f608)
- design — the adapter's bleed key and what RAND now reports (429f17f)
- pen-design — add anti-pattern for missing theme axis value (b606445)
- pen-design — consolidate render-stale-state traps into one entry (63a93de)
- pen-design — tighten setup.md wording to cut token budget (5f96ed5)
🧪 Tests
- rules — Fixture and baselines follow the spec-verify removal and the tools.json pins (ec6b429)
- skill-scripts — pin design-tokens --diff exit 1 on an alias (466f1a9)
- affected-map — a content/skills change runs skill-scripts (a7f182c)
- skill-scripts — shipped skill scripts take the project from the project (ae90bcc)
- routing — follow the implement tier onto high effort (ef46549)
- lint — report a foreign linter's findings for changed files only (9b521fd)
🏗️ Chores
- test-sandbox — accept the opencode PATH stub dir in delegate-exec (c853a55)
- content-language — accept the OHNE ANKER marker in proof.md (7fffb6d)
- ledger — Claude Code 2.1.267–2.1.274 reviewed (2e8baff)
- tools — review and bump pins after the 2026-09-17 changelog run (2f580c9)
- spec — re-verify Spec 452 after the parallel implementation (8ad3b7d)
- tools — add the agent-internal exception list to the registry (31abb1f)
- spec — complete Spec 458 (Claude review PASS_WITH_FOLLOWUPS) (1e4fbe8)
- scripts — restore shfmt on four committed files so the full suite can run (3628f42)
- spec — close Spec 458 as blocked pending the independent review (e1fce10)
- tools — review python3, and repair the sweep that reported it (558c23d)
- spec — Spec 452 carries the state its code is already in (3efde34)
No commit type
- Spec 450 completion: review receipt and move to completed (ad0a01b)
- Spec-450 fix 2: case (g) exercises the anchored id match, (f') pins the union (6b7fba3)
- Spec-450 fix: closure over both snapshots, anchored line ids, intact --help (88d77bf)
- Spec 449 completion: review receipt and move to completed (0f43dbb)
- Spec-449 follow-up: pin that an exception-red AC earns no review waiver (1b31dec)
- Spec 451 completion: review receipt and move to completed (88b4115)
- Spec-450 Step 4: re-set the workflows.md marker for the spec-update change (593359a)
- Spec-450 Step 1-4: spec-update reopens a named set plus its closure (f9b6916)
- Spec-449 Step 1-4: strict validation names a verify that is red by exception (37340d1)
- Spec 445 completion: record retro entry, wire consequences to docs-drift-check.sh (d5fe8b5)
- Spec-451 fix: skip non-UTF-8 files with a diagnostic, accept a BOM, cover blocks (c32c3d6)
- Spec-445 Step 4 fix: re-set the workflows.md marker after the delegate skill guard fix (f03e29b)
- Spec-451 Step 1-5: shopify-schema-lint reports server-side schema rejections before push (3ab7b5b)
- Spec-445 Step 3 fix: guard sentence names the implement exception (9302b58)
- Spec-444: completed receipt (d6ab5f3)
- Spec-445 Step 4: keep the /delegate cell under the 600-char reader limit (b27ec5b)
- Spec-445 Step 4: workflows.md says /delegate picks the runtime itself (98e9ba4)
- Spec-445 Step 3: /delegate resolves the implement runtime via runtime-route.sh (d51ef1b)
- Spec-445 Step 2: seamed inventory cases for runtime-route.sh (4a88cc9)
- Spec-445 Step 1: runtime-route.sh --inventory [tier] lists every runtime's state (d7d5df2)
- Spec-444 Step 2+3: claude implement allowed from a Claude session, depth-capped (24cf2f8)
- Spec-444 Step 1+4: implement chain prime→dsh→kimi→claude, runtime-route cases (c05ed76)
- Update spec 452 tools auto-upgrade: rework lock/state handling and fix d (962f3c7)
- Spec-452 Step 1: state write adds no shellcheck finding over the baseline (81dc71d)
- Spec-452 Step 1-5: tools upgrade themselves via sync and --auto-upgrade (11e3680)
- spec(reference-scan): add batch cap for freshness backlog (c2da720)
- Update pen-design docs and changelogs for setup fork default, colour contrast and adapter keys (d1fcd4f)
- Correct measured spawn-cost finding for the Rust spike audit (ea0c8e4)
- Add Spec 461: Rust devkit core parity-verified CLI surface (5260924)
v0.38.0 — 2026-09-17
Review rounds drop and the harness gets faster: a prose-only fix carries its PASS instead of a full round, the re-review package is 1,655 B instead of 6,847 B on the fixture, hooks cost 143 ms per Bash call instead of 365, reuse-guard 15 ms instead of 493, and the quality gate's skill-lint runs in 10 s instead of 81. Update with devkit sync.
73 commits since v0.37.0 · Specs 396, 406, 442, 443
✨ Highlights
🔁 Fewer review rounds
A prose-only fix now carries its PASS forward instead of a full re-dispatch — Spec 396 paid three full rounds for three prose fixes to one skill instruction before this. spec-work commits every green Step as Spec-NNN Step k: and review-prep re-reviews only that Step (1,655 B delta vs a 6,847 B full package), off-scope findings go to a deferred: ledger that never extends the loop, and an oversized diff-route package is refused with REVIEW_PACKAGE_OVERSIZED before the paid Codex call (issue #46).
/spec-work 443💸 Cheaper reviewer seat, measured
Reviewer effort steps down to medium on inferred-low, signal-free diffs — Spec 443's reviewer spent 190k tokens over two rounds on the high-effort seat before this (DEVKIT_REVIEW_LOW_RISK_EFFORT overrides) — and the Codex second opinion runs only on inferred-high risk or an architecture signal, never by default. A controlled run on ten frozen packages found sonnet as reviewer missed 8 confirmed HIGH/MEDIUM findings and spent 5 % more tokens, so tiers.review.claude stays opus/high.
DEVKIT_REVIEW_LOW_RISK_EFFORT=high # keep the high seat on every diff📉 Leaner specs, smaller skill bodies
A compact, Risk-low draft whose ACs all carry a deterministic verify now waives the implementation review by default, its Approval Capsule shrinks to Verstanden als + Ziel + Digest, and one split threshold (6 Steps / 5 files) replaces the scattered ones. The skill bodies shed what a script already prints: spec 4429 → 4116 tokens, review 4591 → 4211, spec-work −2.2 KB of restated contract text.
/spec # compact route: Implementation-Review: waived when every AC has a deterministic verify🌊 Waves stop losing hours to silent failures
A dispatch that dies on startup now prints WAVE_SLICE_STARTUP_BLOCKED and exits 7 instead of a false green — one wave lost 9 h 23 min of a 15 h run to that (issue #54) — and a parked slice releases its file claim via Status: blocked instead of deadlocking its sibling (issue #57). prime-run bounds Orca's worker start at 120 s and falls into the headless launch instead of hanging nine minutes with no token spent.
DEVKIT_PRIME_WORKER_START_SECS=120 # bound on orca worker-start before the headless fallback🎯 Review packages anchor on the right diff
A wave slice's review package anchors on the branch's merge-base with main instead of the spec's intro parent — it used to carry ~66,000 foreign lines and PASS on nothing (issue #55), and a package whose foreign paths outnumber the declared ones now warns before dispatch. A spec implemented on main as Step commits anchors on its first Step: Spec 442's package dropped from 936 KB over 60 foreign commits to 33 KB.
SPEC_REVIEW_PREP_WARN reason=foreign-paths-dominate # printed to the worker before the reviewer sees it🔀 The second opinion never stalls on Codex
delegate hops a transient Codex failure (exit 4, read-only mode) to dsh, then kimi, on its own — the hopped answer carries a === <runtime> (<model>) header so you see who answered, and hermes leaves the registry and every adapter.
DEVKIT_DELEGATE_NO_HOP=1 # opt out of the hop chain🔒 devkit doctor catches an OpenCode agent running blind
An OpenCode primary loses a built-in whenever any merged config layer denies it, and its default subagent_depth of 1 refuses a skill's second delegation hop — devkit doctor --target opencode now names each denied built-in, the file that denies it, and a depth below 2; devkit apply writes the fix.
devkit doctor --target opencode🔔 SessionStart: one hint, and it knows your spec
SessionStart used to stack up to four banners; a single dispatcher now runs them in priority order and stops at the first one with output, and it names your active spec's status, Step and AC counters (max 3 specs, 14 ms with none active, 365 ms for three).
DEVKIT_SKIP_RESUME_HINT=1 # opt out of the spec-status hint⚡ Hooks cost a third of what they did
Hook dispatch parses the event payload once and runs advisory hooks concurrently — 10-run medians: hook-dispatch-pretool 365 → 143 ms, hook-dispatch-prompt 228 → 109 ms, reuse-guard 493 → 15 ms — and the session-scope hash batches into one git call (102 → 54 ms at 13 dirty files). The ADHD ruleset (~1,800 tokens) no longer injects into every Plan/Explore subagent, and a paired harness-on/off benchmark puts the stack below the noise floor (27.0 s vs 28.9 s, N=2).
DEVKIT_REUSE_GUARD_LIVE=1 # re-enable the symbol detector on the Edit path🧪 Maintainer loop: gate and suites in a fraction of the time
The quality gate's trigger-collision check dropped from 81 s to 10 s — it was 90 s of every five-minute gate run. hook.sh split into ten per-family suites (114 → 41 s total, 4–27 s each), and staging the test payload once per suite instead of per sandbox cut several suites by half (runtime-hardening 350 → 143 s, safety 159 → 85 s, codex 159 → 110 s, hook 185 → 130 s, model-routing 98 → 92 s).
bash content/scripts/test-prep.sh --affected-only🎯 /fetch-my-project-task: assignee-scoped CrewBuddy digests
Fetches only the open tasks of a CrewBuddy project that are assigned to you, instead of every open task like /fetch-project-task — cb 0.1.0 already combines --project with --my.
/fetch-my-project-task 42🧭 /agent-browser no longer skips Orca silently
Four of the last 30 days' /agent-browser runs on Orca hosts started with a bare command -v agent-browser check and never called the detector, so they silently fell back to the plain CLI instead of the Orca browser (measured across 887 transcripts). Orca routing is now an explicit Step 0 with widened Bash access.
orca-detect.sh # Step 0, runs before every agent-browser commandWhat changed for you
Newly available
devkit sync --optional(ordevkit tools --optional) now installs the two delegate CLIs that used to be hand-installed globals: the DeepSeek Harnessdsh(@deepseek-ai/dsh@0.1.5-rc.1via npm) and Prime Agentprime-agent(the v0.9.5 release tarball, since the package is not on the npm registry). A plaindevkit syncleaves both out. Pre-release pins such as0.1.5-rc.1and a--versionprinted on stderr now count as installed instead of being reinstalled on every sync.- Fetch only your own assigned tasks from a CrewBuddy project with
/fetch-my-project-task <project-id>;/fetch-taskand/fetch-project-tasknow runcb tasks fetchas well. - A Dev Mode page explains how to run the setup from a checkout —
devkit dev-sync, the daily loop, why a baredevkit synccan't do it, and how to leave it. devkit doctor(any target) flags a foreign MCP server entry whose stdio command no longer resolves, instead of failing silently at spawn.devkit doctor --target opencodefails loud (exit 1) when an OpenCode agent would run the shared skills blind: it names every built-in (read,glob,grep,list,bash) that a global,OPENCODE_CONFIG, project or.opencode/layer denies, the file that denies it, per-agent denies, required tools inexperimental.primary_tools, and asubagent_depthbelow 2. The same checks run inside a plaindevkit doctorwhile the adapter is on — see OpenCode prerequisites./friction-feedbackstill reports from an agent without a shell: it drafts the inputs, writes the detail file and hands the twofeedback-issue.shcommands to you./friction-feedbacknow files the issue without a confirmation question — the dry run and its byte-bound SHA already guard what goes out, so you see the filed title, body and URL in the same turn./commitwarns withSPEC_CONTRACT_DRIFT <path>when a staged edit changes a path an approved spec declared, so a repo-wide rename can't silently invalidate a spec's Approved-Digest.spec-validatewarns when a verify criterion resolves amktemp -dfixture path that never matches on macOS (/varvs/private/var).
Behavior changed
/specwaives implementation review by default on a compact, Risk-low draft where every AC has a deterministic verify; the compact Approval Capsule shrinks toVerstanden als + Ziel + Digest.spec-workcommits each green Step on the current branch, so you review commit by commit and re-review only reads the new Step (wave slices, managed worktrees and workspace runs stay commit-free)./reviewreviewer effort steps down to medium on low-risk, signal-free diffs; the Codex second opinion is no longer a default — it runs only on inferred-high risk or an architecture signal. Prep now builds the re-review delta itself: over 30 days MODE=delta ran in 11 of 33 Claude dispatches and in no Codex dispatch, because Codex had no delta mode. Twenty reviewer passes over ten of this week's commits confirmed 11 defects the original reviews had missed; all are closed in this release.- Indirect permission questions ("sag mir", "ob ich", "darf ich", "soll ich" and their English variants) now end the turn instead of being blocked by the announce gate; the
agent-state-ignoregate now also fires on state dirs and the index, not only the manifest (closes #58). devkit applynow also writessubagent_depth: 2into~/.config/opencode/opencode.jsonnext to the tool keys (a personal value stays); OpenCode's default of 1 stopped every shared skill that delegates twice withSubagent depth limit reached (1).DEVKIT_DELEGATE_BOUNDnow sizes a delegate run the tier table can't./agent-browserchecks Orca routing first on every run, so an Orca host no longer falls back silently to the plain CLI.devkit project-migratereports every dangling.hooksentry — a wired.claude/hooks/<name>.shscript that no longer exists — asPROJECT_HOOK_DANGLING(dry-run addsPROJECT_HOOK_PLAN … action=strip count=<n>) and strips it under--apply; only.hooksis ever rewritten, and the closing summary counts only drift that still exists instead of aNext: --apply --forcerow for copies it just deleted.PROJECT_NPX_DRIFTED/PROJECT_LOCAL_SKILLname a devkit-shadowing copy and a local skill file referencing a script the sweep already removed;--apply --forcenow also sweeps npx-drifted copies, except.claude/settings.json,.claude/settings.local.jsonand.mcp.json.- A full Sonnet ID pin (
claude-sonnet-4-6, with or without[1m]) is now removed exactly like an Opus ID pin instead of being rewritten to the baresonnetalias; alias pins stay untouched. run-costtakes the last cumulative total per task id instead of summing every resume (one run read 6.5M tokens by event vs 782k by handle) and reports how long a delegate ran against the wall clock (54 % of 2 h 38 min on that run).- Every shipped script prints usage on
--helpand exits 0 before any side effect — a usage audit over 159 scripts, hooks and tools found 28 with a broken--help(two ran their real work until the bound) and 20 with ShellCheck warnings; 36 are repaired andtests/script-help-contract.shpins all 119. devkit dev-syncserializes concurrent runs with a lock dir and resets a source that points at a deletedod-dev-sync.*export dir — two overlapping runs used to swap config backups and break every later sync.
Action required
- On OpenCode, run
devkit applyafterdevkit sync—syncships the doctor check, but onlyapplywritessubagent_depth: 2and the tool keys intoopencode.json; confirm withdevkit doctor --target opencode. - A running session doesn't pick up this release's hook, SessionStart or OpenCode config changes on its own — OpenCode reads its config once at start, so restart it, or start a new Claude/Codex session, after
devkit sync. - If a project ever hit the Stop-hook error, run
devkit project-migrate . --apply --forcethere to strip the dangling.hooksentry — devkit ships the fix, it does not run by itself in the target project.
🚀 Features
- opencode — fail loud when an agent lacks the built-ins od-skills need (0ead033)
- audit — Spec 442 — measure a lighter review tier, verdict reject (Spec 442) (f250ae5)
- hooks,spec-review — one SessionStart hint dispatcher, contract-receipt carry behind a switch (4085388)
- spec,delegate — waiver by default on compact, one-line compact capsule, second-opinion hop chain (b3b9fbb)
- release — --repoint moves latest.json back to a published version (16d4296)
- review — Step commits reach the reviewer once, deferred ledger, delta effort (ac4d551)
- doctor — warn when an MCP server command no longer resolves (c080952)
- spec-work — commit each green Step as the delta-review anchor, one split threshold (c1feccc)
- cb — update task fetch commands for project scope (41cf844)
- skills — add /fetch-my-project-task for assignee-scoped digests (9894cbf)
- review-runtime — refuse an oversized diff-route package before the codex dispatch (719d63a)
- review — the re-review delta package is built by prep, and the Codex dispatch takes it (1064f55)
- review — the Codex second opinion is a measured package signal, never a default (2dd0ef3)
- hooks — SessionStart names the active spec's status, step and AC counters (567e92b)
- tools — script usage audit — every shipped script measured for use, tests and contract (434e583)
- review — reviewer effort steps down to medium on low-risk, signal-free diffs (Spec 443) (b6c5295)
- tools — paired harness-on/off benchmark, first measurement shows no slowdown (fa13e07)
- spec-review-prep — classify the review intersection so prose-only edits carry the PASS (Spec 396) (ac2aa34)
- devkit-issues — maintainer skill that triages open issues against specs and commits (e64e3a9)
- commit-prep — warn when a staged edit voids an approved spec contract (5a35717)
- spec-validate — warn on a mktemp -d fixture a verify never resolves (Spec 443) (504e29d)
- run-cost — sum tokens per handle and measure delegate time against the wall clock (Spec 443) (476147f)
- friction-feedback — file the issue without asking the human (46b9e05)
🐛 Fixes
- scripts — docs-build-check honors --help, lifecycle usage drops the specs literal (e7ef106)
- close the eleven findings the Spec 442 review-tier measurement surfaced (Spec 442) (a640ad9)
- delegate — DEVKIT_DELEGATE_BOUND sizes a run the tier table cannot (fdf7b58)
- spec-review-prep — anchor a main-branch spec's diff on its first Step commit (Spec 442) (c2e3e6a)
- hooks — agent-state-ignore gates on state dirs and index, not only the manifest (794e586)
- hooks — announce gate lets indirect permission request end the turn (0ce48c4)
- dev-sync — serialize concurrent runs and heal a source left on a deleted export dir (4289fcf)
- scripts — every shipped script honors --help — 36 repaired, suite pins all 119 (f5851db)
- tools,hooks — honor the --help contract and clear ShellCheck warnings in 20 files (793901e)
- prime-run — bound orca worker-start instead of waiting on it forever (26bc62b)
- wave-prep — name a dispatch that dies on startup instead of reporting green (7c3d81e)
- feedback-issue — anchor the credential-prefix screening at a token start (e327ae0)
- spec-deps-check — a parked slice releases its file claim via Status: blocked (bb0f316)
- spec-review-prep — anchor the fallback diff base on the merge-base with main (1eec840)
- project-migrate — complete spec 443 — verdict after force sweep, docs, retro (Spec 443) (0e92824)
- project-migrate — strip dangling hook wiring and drift-sweep with --force (Spec 443) (cbf8151)
- agent-browser — make Orca routing the first command, pre-approve Bash (ea2e649)
⚡ Performance
- tests — split hook.sh into one suite per hook family (63431f6)
- tests — stage the payload once per suite and clone it into each sandbox (1ff83da)
- hooks — parse the payload once, run advisories concurrently, reuse-guard off the Edit path (9f36290)
- skill-lint — compute trigger collisions in one awk pass — 81 s to 10 s (7654444)
- hooks — batch the session-scope hash, skip the ADHD ruleset for Plan/Explore, add hook-latency instrument (1570fa2)
♻️ Refactoring
- skills — spec and review skills keep the decision, scripts keep the format (8ee0295)
📖 Documentation
- agent-browser — diagnose a Design Mode picker hidden by page CSS (374cb0f)
- skills — name the pull step for Pen's element picker (b7b2a97)
- tools — close the lean-ctx question — personal install removed (Spec 442) (87541e9)
- audit — close the lean-ctx benchmark brief with the Spec 442 result (Spec 442) (8287f79)
- changelog — mirror the Unreleased block into the English page (Spec 443) (a03ef3f)
- tools — record the lean-ctx trial as an external tool note and decision (0f7ce51)
- changelog — record the 5 commits since v0.37.0 under Unreleased (1ec5742)
- add the Dev Mode page so contributors can run the setup from a checkout (5562ec8)
- audit — record the user-side findings beside the measured ones (b0c966d)
- agent-browser — check a device-emulated screenshot before judging the page (54cb4e5)
- agent-browser — headless is not the Orca vs agent-browser discriminator (ba6aeb1)
- audit — caveman proxy trial — zero token compression on Claude Code 2.1.273 (e3a370b)
🧪 Tests
- hook — own Codex homes per rotated sandbox, injection sandbox unprimed (74961d1)
- spec-routing — GNU-first stat fallback in the four mode assertions (7be2417)
- hook — pin the announce fixture and drop the inherited CLAUDE_PROJECT_DIR (069cd0f)
🏗️ Chores
- specs — Spec 406 stays paused until the release that carries this week's cuts (Spec 406) (ed68574)
- tools — drop the lean-ctx tool note and neutralize its fixture names (e98e4e1)
- gate — accept the announce-gate example phrase in the language baseline (50c7424)
- share one test matrix between ci.yml and release.yml (0bc5a0d)
- tools — remove five audit gates whose audits are finished; wire release-cleanroom into PUBLISH.md (896f5f6)
- gate — clear the three reds the quality gate carried on main (Spec 443) (e568e6f)
- delegate — remove hermes from the runtime registry and every adapter (0ed36fb)
No commit type
- Spec-442 Step 3: record the reject verdict and its re-open bar (6ea94a0)
- Spec-442 Step 2: run both review arms on ten frozen packages, one row per task and arm (5650a41)
- Spec-442 Step 1: write the review-tier instrument before the run (5c124aa)
- Add DEVKIT_SPEC_WORK_DRIVER=workspace signal so workspace members stay c (9a26ca8)
- Add lean-ctx benchmark brief and Kasetto research note (a058557)
v0.37.0 — 2026-09-15
GOTCHAS.md leaves the always-on CLAUDE.md import — 2914 tokens per session here, 63 in a fresh project — and a Critical entry arrives only on a trigger match. The pinned i-have-adhd plugin is the one source of the response form for Claude, Codex and OpenCode behind one flag that devkit sync creates once and your removal then sticks. A new archify tool renders diagrams in /share pages at zero always-on cost. Update with devkit sync.
52 commits since v0.36.0 · Specs 001, 182, 435, 437, 438, 439, 441
✨ Highlights
🪶 GOTCHAS.md leaves the always-on import
/index no longer @-imports GOTCHAS.md into CLAUDE.md — 2914 always-on tokens per session in this repo, 63 for a fresh project's skeleton (Spec 438); a Critical entry reaches you only when gotcha-recall.sh's Trigger: matches your prompt, at most 654 tokens in this repo's own measurement, and only then. An existing project drops the import on its next /index.
/index
grep GOTCHAS CLAUDE.md # only on the "Further context files on demand" line🎨 The pinned i-have-adhd plugin is the one source of the response form
core.md's own 700-character paraphrase of the response rules and the per-prompt style-reminder.sh copy are gone (Spec 435); the sha-pinned plugin copy shipped in the payload now reaches Claude subagents, Codex's SessionStart hook and OpenCode's managed block behind the same .i-have-adhd-always flag, on a Codex- or OpenCode-only install without the claude CLI too.
stop adhd mode # turns the ruleset off for the session📐 archify: a passive, sha-pinned diagram tool for /share
An ```archify <type> fence (architecture, workflow, sequence, dataflow, lifecycle) whose body is the JSON spec renders through deliver into a standalone, theme-aware SVG behind a data-URI <img>, so the page stays script-free and a fenceless page renders byte-identical (Spec 437). It installs as a github-checkout tool (blobless, sparse, sha-pinned) and is routed by the path-scoped doc-authoring rule only — a skill entry would have cost 132 always-on tokens per session; the trial measured ~7.6k tokens per rendered diagram.
```archify workflow
{ "schema_version": 2, "diagram_type": "workflow", "meta": { "title": "Agent tool call" }, "nodes": [ … ], "edges": [ … ] }
```📤 /share (Orca artifact) is the default publish route
core.md › Skill First now names /share before the Claude Artifact tool, which is the fallback only when orca-detect.sh finds no Orca: the Orca link reaches people without an Anthropic account and runs behind share-prep's secret gate. orca artifacts --help is the proof the group exists — orca --help (363 lines) and orca agent-context never list it.
orca artifacts --help🧭 Stack lenses open with an imperative and reach nested app directories
The model invoked a path-matched lens in 5 of 280 sessions that edited a routed file over 30 days, so each description now opens with the instruction the picker needs; Laravel and Nuxt globs gain nested-app variants, and the Nuxt lens fires on app/storyblok/ (28–48 files per sb-nuxt project, none under components/) while the Shopify lens guards the 87 committed Vite builds under assets/ and names blocks/.
paths: ["**/app/storyblok/**", "**/blocks/**", "**/src/entrypoints/**"]🛡️ rm, rsync and stash guards resolve instead of failing closed
A root-owned, non-enterable ancestor directory no longer refuses a legitimate rm target in every spelling (issue #48) while a symlinked alias of a protected root stays blocked, and the block message names the refused token and the closed set of reasons; rsync --info=*, --stats, -i, -u, -c and --verbose join the read-only allowlist, and a plain git stash push is no longer read as a remote push (git -C <dir> stash push stays blocked).
git stash push -m "$(date +%F)"🌳 Every visible delegate run gets its own child worktree
delegate-visible.sh runs every mode — not only implement — in its own Orca child worktree, mirroring your uncommitted state for a read-only run and removing the worktree afterward instead of working in the shared checkout; autohand 0.9.7 runs --offline --plan because --bare needs a cloud key and --restricted denies reads. The tier bound now also holds on stock macOS without coreutils timeout: TERM at the deadline, KILL 20s later, exit 124.
/delegate codex review🔁 /checkin opens with a plain-language status card
An opening statement (what, where, next — no evidence lines) now precedes the evidence sections, so a reader without the transcript can grasp session state without decoding paths, counts or commands.
/checkin🧹 dev-sync never prunes a version a process is still running from
A parallel session's prune deleted the dev version directory a delegate-visible.sh run was executing from, its return step failed and the finished worktree stayed behind; the prune now skips any version whose fully-qualified path appears in a live process, and only pgrep's "no match" clears the way.
bash tools/dev-sync.sh --worktreeWhat changed for you
Now available
- Diagrams in
/sharepages via```archifyfences, rendered as a data-URI SVG image with no script tag;devkit path tool archifyresolves the pinned checkout. /checkinopens with a plain-language summary before the evidence sections.- Audit reports have a named home,
devkit/audit/<name>.md, stated by the path-scoped doc-authoring rule and the scaffold README. /delegate <runtime> architectureand panel replies open with SHIP IT, SHIP WITH CHANGES or RETHINK, name the weakest point of a sound plan, and the summary keeps each member's strongest objection.
Behavior changed
- A Critical entry from GOTCHAS.md reaches a Claude session only through the recall hook's
Trigger:match on your prompt; Claude subagents no longer receive the file at all, while Codex, Prime and dsh still read it through the canon read order. - Responses take their form only from the pinned i-have-adhd plugin, behind
.i-have-adhd-always— created once bydevkit sync, and a removal you make afterwards is respected — in Claude subagents, Codex and OpenCode alike. /share(Orca artifact) is the default publish route; the Claude Artifact tool is the fallback only whenorca-detect.shfinds no Orca.- A
/sharepage prefers Inter and JetBrains Mono (system stack otherwise) and the docs-site palette; below 64rem (Orca's ~955px browser) the chapter rail is inline and the canvas follows dark mode. - The Nuxt, Shopify and Shopware lenses lead with the profile-wide default, make each boilerplate specific a checkable condition, and no longer fire on vendor trees or skill sample files.
- Six findings were fixed after a skill-doctor run failed 9 of 12 sampled sessions:
specoffers before the first edit,researchfires on the phrase you type,checkinnames the assumption. - CLAUDE.md names the real gate paths, GOTCHAS says a backgrounded task notifies on exit (5 sessions had added waiters), and
skill-editingnames who still receives a cut rule. HINT_INDEX(623 sessions, 1 conversion in 30 days) speaks once per project per day instead of on every session start.- The usage report counts a spec's review across sessions, keyed
org/repo#NNN("Spec 001" had merged 30 sessions from several repos), and an externalreview-runtime.shdispatch counts as a review. - A
kind: planfile is worked one row at a time, one commit or spec per row, and a finding is fixed in the artefact it indicts within the same slice. friction-hintalso fires when an agent writes a project-local.claude/rules/*.md, and/friction-feedbacksays when the agent files itself instead of waiting for you.- Tests can no longer dispatch a real Kimi or Codex review,
spec-review-prep.shre-anchors when a foreign commit lands the code before the spec file,context-drift-check.shskips gitignored trees. - A legacy
specs/layout no longer produces a SessionStart line;devkit project-migratestill names it (the hint fired in 534 sessions over 30 days with 0 conversions). - The
spec,spec-workandreviewskills cost 9–11 % fewer tokens per invocation (4843→4385, 4399→3956, 4981→4433,tools/content-budget.sh --measure): enumerations the scripts already enforce now live with the scripts. - A rejected
/spec-verifyverdict now stops/commiton that spec instead of being shown and ignored;DEVKIT_ALLOW_REJECTED_UAT=1commits over it. /reviewnames/speconce and stops when a diff carries an architecture signal but no spec file — inline work finally has a mid-flight exit, and reads the AC evidence/spec-workalready recorded instead of re-running the same commands a third time in one run./specis offered once per path class per session before you edit a release file,api/, a pinned tool sha or a credential surface — the probe offers, never blocks (Spec 441).- With the always-on ADHD flag set, the pinned pre-send check arrives with the verbosity measurement instead of an advisory note.
Action required
- Run
/indexin each existing project:devkit syncships the generator, but the@.agents/context/GOTCHAS.mdline in your CLAUDE.md block leaves only on the next/indexrun. - Check that every
## Criticalentry in.agents/context/GOTCHAS.mdcarries aTrigger:regex (/capturewrites one) — it is now the entry's only channel into a Claude session. - Clear
DEVKIT_SKIP_GOTCHA_RECALL=1if you had set it: with the import gone, a disabled recall hook means no Critical entry arrives at all. - Install
nodeif you want archify diagrams — the tool is pinned but its runtime is node, and a sync without it skips the renderer; check withdevkit path tool archify. - Remove
~/.claude/.i-have-adhd-alwaysfor a lasting style opt-out; saying "stop adhd mode" only turns it off for the current session.
🚀 Features
- hooks — offer
/specbefore an edit to a named irreversible surface (Spec 441) (defda38) - style — enforce the pinned pre-send check on every prompt behind the flag (b371ac0)
- review — adjudicate the recorded AC evidence instead of re-running it (3cd7289)
- commit — a rejected UAT verdict stops the commit prep (e4d020e)
- review — name the inline path's exit to
/spec(2644961) - hooks — retire the spec-layout SessionStart hint (Spec 439) (c915403)
- maintainer — vendor Warp skill-doctor as a project-local skill (9100d4a)
- share — Inter, the docs-site palette and a scheme-aware diagram canvas (a6eff29)
- rules — Orca artifact is the publishing default, Claude Artifact the fallback (848aeb4)
- skills — tell the model to load a stack lens before the edit it was surfaced for (cfe93cf)
- telemetry — throttle two zero-yield hints and read the review gate per spec (Spec 001) (829c2f1)
- plugins — ship the pinned i-have-adhd skill in the payload and reach every runtime from it (551129e)
- tools — pin archify as a passive github-checkout tool with share-render fences (Spec 437) (407d657)
- rules — make the pinned i-have-adhd plugin the only source of the response form (Spec 435) (ef9fc05)
- stack-skills — lenses follow the boilerplates as of 2026-09-15 (b5863d2)
- rules — name where an audit lives (4d421e0)
- rules — route publishing to the Orca artifact before the Claude Artifact tool (6ab20d9)
- checkin — open status card with plain-language summary (a7eb990)
🐛 Fixes
- tests — record the UAT_REJECTED friction site in the fixture (03ea9e0)
- content-budget — keep the exact tokenizer working without a writable HOME (710a080)
- spec-validate — a deleted declared path is not its own twin (Spec 439) (bb85924)
- spec-id-next — stop burning a spec ID on --help (4f0a79b)
- test-prep — detect a Node project one directory down (96e265c)
- index — stop @-importing GOTCHAS.md into CLAUDE.md, fix autohand 0.9 (510000b)
- hooks — resolve rm-guard through non-enterable ancestors, surface un (0f35d85)
- policy-guard — resolve rm targets past a directory the caller cannot enter (Spec 182) (beb4617)
- content — six findings from the first skill-doctor run (a96d878)
- dev-sync — never prune a dev version a process still runs from (3c1d6a8)
- tools — close the four review findings on the archify integration (8ae7802)
- delegate — bound the runtime on hosts without coreutils timeout (a519f90)
- policy-guard — git stash push is a local stash, not a remote push (3064d48)
- stack-skills — nuxt lens fires on app/storyblok, shopify lens guards Vite output (4e2cecf)
- release-prep — card's trailing-blank filter runs on BSD sed too (2307506)
📖 Documentation
- specs — author Spec 441 and 442 for the two open audit findings (ce4f04f)
- specs — author Spec 439 — retire the spec-layout SessionStart hint (Spec 439) (a7b4941)
- brainstorm — say how a living plan is worked, not only how it is written (07049be)
- specs — complete Spec 437 — archify passive tool pin (Spec 437) (3ad3277)
- audit — probe how a directory-source plugin behaves behind the current symlink (c044594)
- specs — author Spec 437 — archify as a passive, sha-pinned diagram tool (Spec 437) (301a695)
- audit — headroom verdict split into operational decline and unmeasured performance (3e53e2e)
- tools — headroom proxy trial declined for the routed default (6e1cc41)
- audit — record the archify trial against the Mermaid route (aea495a)
- skills — tool-trial names the acquisition shape and measures a proxy on both sides (45d0046)
- delegate — closed verdict and rejected-objection rule for opinion modes (c96bac2)
🧪 Tests
- tests — satisfy shfmt in
tests/plugin.sh(99ee407) - repair three pins that today's commits left red on macOS (f0ffd75)
🏗️ Chores
- audit — usage snapshots for 2026-09-15 and an expectations ledger (c752a0f)
- tools — retire the watch-i-have-adhd blob pin (c8e09f6)
- codex — drop the headroom init residue that failed on every Codex Bash call (ec41d16)
No commit type
- Ich bin im Plan Mode – für einen reinen Commit-Message-Auftrag brauche i (6f75e8e)
- Reconcile Spec 438 completion and follow-up fixes to review infrastructu (1d80ca8)
- Erstelle Commit-Message ohne weitere Aktionen (6788cf8)
v0.36.0 — 2026-09-15
Agents are gone — 746 of 923 dispatches in 30 days named one, and roles are now prompt files; the CrewBuddy CLI installs from its private GitHub release; the spec lifecycle now runs from three scripts instead of Main's hand steps; /delegate now opens a visible Orca terminal for Codex, Kimi and dsh runs instead of running them unseen. Update with devkit sync.
262 commits since v0.35.0 · Specs 198, 336, 375, 406, 409, 410, 411, 412, 415, 417, 418, 420, 422, 423, 424, 425, 426, 427, 428, 429, 430, 431, 432, 433, 435, 436
✨ Highlights
🪦 Agents are gone: roles are prompt files, no agent installation
746 of 923 subagent dispatches in 30 days named a content/agents/ role; the last three are retired, and a role is now a prompt file next to its skill, run as a native general-purpose or Plan subagent. devkit sync removes only devkit's own links, and the retired commands answer AGENTS_RETIRED for one release.
devkit sync
devkit has agent code-reviewer.md # AGENTS_RETIRED use devkit path skill <name>, exit 2🔁 /checkin syncs a running session with you, on measured thresholds
Across 616 local sessions the trailing run of unasked edits sat at p50 6, p75 15, p90 25, and 466 sessions never asked. /checkin puts only the load-bearing choices into one question, and checkin-hint.sh nudges after 15 unasked edits (DEVKIT_CHECKIN_HINT_EDITS) and every 10 after that.
/checkin🔐 cb installs from its private GitHub release over gh
The CrewBuddy CLI is a required tool on macOS and Linux, pinned to 0.1.0 with the four sha256 hashes from its release's checksums.txt; a github-release platform block may now carry download: gh, and the installer fetches the asset with gh release download from github.com while the pin, archive screening, exec probe and atomic rename run unchanged (Spec 436). A failed download reports gh's own last error line, and a missing or logged-out gh names gh auth login.
gh auth login # once, with an account that can read onedot-digital-crew/cli-crew_buddy
devkit sync # installs cb 0.1.0 as a required tool🌳 Prime and wave worktrees hang under their caller
prime-run.sh executes a private snapshot of itself, so editing the script during a run no longer feeds the live wrapper garbage and tears down a worktree holding a finished patch (a four-file patch was lost that way on 2026-09-14). Its Orca worktree is a child of the calling terminal instead of --no-parent, and every /wave slice is a child of the main checkout instead of a scattered top-level card.
devkit run wave-prep.sh slice-dispatch --run <run_id> --spec-id <id> --name <slice> --main <main-checkout> --brief-file <path>🧾 Bash-made edits belong to the session that made them
session-scope.sh recorded only Edit, Write and MultiEdit payloads, so a sed, heredoc or python edit — and a parallel session's commit — stayed unattributed and moved another spec's Review input SHA (Spec 436: a foreign commit during the review voided the verdict). hook-dispatch.sh now snapshots the dirty tree before every Bash command and the PostToolUse pass attributes each path whose blob differs from it; a path dirty before the snapshot stays foreign.
{ "name": "session-scope", "event": "PostToolUse", "matcher": "Edit|Write|MultiEdit|Bash" }🧭 Every spec records the model and harness behind it
A finished spec's AUTHORED/COMPLETED lines now carry model: and harness:, resolved by spec-agent-ref.sh from the running session or passed to spec-finish.sh for delegated runs. An unresolvable value is recorded as —, never omitted.
devkit run spec-agent-ref.sh --model <id> --harness <id>
devkit run spec-finish.sh <ID> --verdict PASS … --model <id> --harness <id>🍎 SwiftBar's plugin folder registers itself on sync, and stays put
On macOS, devkit sync registers the stable $DEVKIT_HOME/swiftbar as SwiftBar's PluginDirectory when SwiftBar is installed and none is configured, so the manual ⇧⌘G step disappears. A folder you set yourself is never overwritten, and a registration pinned to a versions/<v> path a prune deleted is migrated.
devkit sync⚙️ The menu bar switch grew into a settings panel
The SwiftBar menu now shows and sets every config.json setting — Codex/OpenCode materialisation, the update channel on an HTTP source, the /review reviewer, each /delegate runtime's allow state — and applies a runtime or channel choice at once. devkit status --json grows the fields behind it.
devkit status --json # source_type, channel, staged_version, runtimes, review_runtime, registry_runtimes, missing_tools🍎 CLI tools, doctor and the docs from the menu bar
The SwiftBar menu lists every tools.json entry with its installed and outdated state, offers the matching devkit tools action only while something is missing or outdated, opens devkit doctor in a Terminal window and links devkit.one-dot.io — all from devkit status --json, which gains tools[].{name,tier,installed,outdated} and tools_outdated_check without a network call.
devkit status --json | jq '.tools, .tools_outdated_check'👁️ /delegate opens visibly in an Orca terminal by default
delegate-visible.sh is now the default entry of /delegate: a Codex, Kimi or dsh implement run gets a child worktree terminal in Orca, and after a green run delegate-return.sh applies the diff and removes the worktree by itself. Without a reachable Orca it prints DELEGATE_VISIBLE_FALLBACK and falls back to delegate-exec.sh.
/delegate implement --brief brief.md # opens a child worktree terminal in Orca, live stderr🧠 The i-have-adhd ruleset ships as a pinned plugin, to Claude, Codex and OpenCode
The upstream ayghri/i-have-adhd plugin puts its full 7.2 KB skill on top of the 700-character core.md > Responses cut: pinned by sha in the devkit-owned marketplace devkit-pins, appended to Codex's SessionStart hook and written into OpenCode's managed block. Deleting ~/.claude/.i-have-adhd-always opts out for good; cost is ~67 always-on tokens plus 1747 per SessionStart.
devkit sync🧑⚖️ Review Level B: compact specs need no model authoring review, one reviewer seat per diff
171 of 225 reviewer runs in three weeks — 13 reviewer hours — covered authoring or ideation, and 10 of 31 authoring reviews took three rounds or more. A compact spec now goes from strict validation and the Approval Capsule straight to you, full keeps one round plus one delta, each diff gets one reviewer seat.
devkit config review-runtime codex⏱️ Verify chains reuse proven checks, and test-prep skips a parallel session's suites
Spec 412 measured 1433 s for twelve runs of one suite; split && verify chains brought the same phase to 256–376 s with 11–12 of 20–21 segments reused, while blanket suite reuse was withdrawn again after stale passes surfaced. --affected-only now drops a parallel session's paths first, so it stops running that session's suites.
- [ ] AC3: … → verify: `grep -qF 'label' tests/spec-routing.sh && bash tests/all.sh --suite spec-routing`🤝 /delegate routes architecture, Prime and native Codex reviews through one door
Continuations need an explicit session ID, codex review targets and an architecture tier exist, Prime runs through delegate-exec.sh with a credential scan, and review results are validated against result.schema.json. A brief above 100000 B travels on stdin, and a codex host/CLI skew warns before dispatch.
devkit run delegate-exec.sh codex review --brief brief.md
devkit run delegate-exec.sh prime implement --brief brief.md --gate 'bash tests/all.sh --suite x'🧠 Auto-compact fires at a pinned window
Compaction used to land wherever the model's own context limit fell — the status line showed "0% until auto-compact" and the summary cut in mid-instruction. The managed env block now pins CLAUDE_CODE_AUTO_COMPACT_WINDOW, which takes precedence over /autocompact and the setting.
CLAUDE_CODE_AUTO_COMPACT_WINDOW=800000 # managed env block, set by devkit sync🔍 Renamed pastes no longer escape reuse detection
jscpd 5.2.0's --ignore-identifiers catches a block pasted under new variable names, which neither the symbol detector nor jscpd's verbatim-token match saw, and Type-3 similarity runs in the uncapped review scan. fallow-run.sh runs fallow doctor first, so an empty report no longer hides an unresolved config.
devkit run reuse-guard.sh # runs --ignore-identifiers on every edit, 2s budget
devkit run fallow-run.sh audit --format json # warns first if fallow's own setup isn't ready🧰 External CLIs are audited against their upstream releases
Eight external CLIs (kimi, hermes, dsh, orca, prime-agent, agy, context7, last30days) had no upstream comparison; kimi sat three minor versions stale (0.36.1 against 0.39.1). tool-pin-audit.sh now compares each kind: external entry against its newest upstream release, monorepo and pre-release tag families included.
bash tools/tool-pin-audit.sh🧱 dev-sync runs from a linked worktree and the gate builds the docs site
tools/dev-sync.sh --worktree builds the worktree's HEAD instead of bouncing through the main checkout, four times in one completion chain, and keeps the prune ledger in the git common dir. A docs-build scanner is red on a dead link or render error; baseline-widen and baseline-age watch the baselines.
bash tools/dev-sync.sh --worktree
devkit run quality-gate.sh📏 The always-on rules are coherent again
48 of 51 redundancy proposals in the rules audit concerned path-scoped rules or on-demand references, so among the rules response style now lives in one place (core.md > Responses) and 16 references across 10 files to two deleted rules are repointed. The script contract no longer claims the harness silently truncates large output.
devkit path rule core.md🧰 spec-work runs from three scripts: prep, checks, finish
spec-work-prep.sh <ID> does Step 0 and 1 in one KEY=value block, spec-checks.sh writes checkboxes and evidence line from its own run, and spec-finish.sh <ID> writes both receipts. Spec 415, first on the new flow, took 1 h 37 m for 5 of 5 Steps and ACs with 17 script-bearing calls from Main.
devkit run spec-work-prep.sh <ID> --start
devkit run spec-checks.sh <spec-path> --run-dir <dir> --phase acceptance --tick --append-evidence
devkit run spec-finish.sh <ID> --verdict PASS --review-input-sha <64hex> --reviewers <csv> --sections none⌨️ cd-guard rewrites the command instead of costing a turn
A leading cd into the directory the Bash call already starts in cost a retry turn per hit; the hook now returns the command without the prefix via hookSpecificOutput.updatedInput and says so in additionalContext. cd <cwd> || exit is rewritten too, other || shapes run with a note, invalid shapes still block.
cd /path/to/cwd && bash tests/all.sh --suite x # runs as: bash tests/all.sh --suite x🔍 A read-only delegation now proves it was read-only
Three runtimes cannot enforce the read-only tier they are dispatched at, and delegate-exec.sh had no git status in its 1138 lines. Every dispatch now compares git status --porcelain -uall plus a diff fingerprint before and after; a read-only mode that changed the worktree prints DELEGATE_READONLY_VIOLATION.
DELEGATE_READONLY_VIOLATION runtime=kimi mode=review new_entries=0 content_changed=1💀 A host kill is no longer sold as a transient failure
A host-killed run used to exit 4 and buy a second dispatch into the same ceiling; a SIGKILL inside the wrapper bound is now exit 2 (split the brief), and timeout gained -k 20s. A 15 s <bin> --version probe refuses a wedged binary before it burns an 1800 s tier bound (after amElnagdy/delegate-skills, MIT).
devkit run delegate-exec.sh codex review --brief brief.md # exit 2 on SIGKILL: split the brief; exit 4 only at the wrapper's own boundWhat changed for you
Now available
- Autohand delegates review, research and architecture with its model pinned in the runtime registry; implementation is refused,
--bareisolates it from project state,--pathpicks the repo. - The macOS menu bar is a full settings panel that applies a runtime or channel choice at once and syncs on demand — setup instructions.
devkit run spec-agent-ref.shresolves the current model and harness, andspec-finish.sh --model <id> --harness <id>records them on theAUTHORED/COMPLETEDlines,—when unresolved.kind: watchedindevkit/tools/*.mdpins anupstream_pathand blob SHA;bash tools/tool-pin-audit.shreportsok,behind,missingorunknown.- DeepSeek Harness delegation receives the
codegraphandcontext7MCP servers through--patch, verified against dsh 0.1.5-rc.1. - Plugin inventory changes are reported during install and update by count, so a swap at the same count stays invisible; tool admission now has six criteria.
/checkinsurfaces a running session's load-bearing assumptions in one question, andcheckin-hint.shnudges after a measured run of unasked edits.devkit run delegate-exec.sh prime implement|statusruns Prime Agent through the same entry as codex and claude, with a credential scan;codex reviewand thearchitecturetier are new targets.devkit config review-runtime codexputs the onecode-reviewerseat per diff on Codexgpt-6-astraand asks Codex before a load-bearing decision.fallow doctorruns automatically beforefallow-run.sh audit|health|dupes|dead-codeand warns when the project setup is not ready.- The quality gate builds the docs site (
docs-buildscanner) when node andnode_modules/vitepressexist, else names itunavailable;baseline-widenandbaseline-agewatch the baselines. - The frozen
Review input SHAcovers a change manifest — declared files plus every change outside## Files to Modify, merged spec commits included — instead of the whole worktree; 344 of 344 earlier reviewer returns had no scope check. tools/dev-sync.sh --worktreeruns from a linked worktree of the source checkout; the prune ledger lives in the git common dir.tools/content-budget.sh --measure <file>prints exact token count, cap and headroom instead of only violations.tools/docs-drift-check.sh --accept <page...>accepts several pages per call, validated before the first rewrite.bash tools/tool-pin-audit.shauditskind: externalCLIs against their upstream releases and resolves monorepo and pre-release upstreams per tag family (four of fiveunknownclosed).docs-page.sh findnames the term and the cache's age when it finds nothing, instead of printing nothing.- The two changelog skills run every upgrade and its wiring in one pass; only a route change or a cut still asks you.
- Every context bundle's
DESIGN.mdcarries an adapter block — stack, tokens, inventory, gate — that a design skill reads first;design-fill.shfills it from the project. /spec-workasks for far less plumbing: the scripts carry Step 0/1, checkboxes and receipts, andspec-work-prep.shexit 2 refuses and names why, exit 3 is an overlap, exit 4 an internal error.review-prep.shhas--helpand--all, and names its caps asREVIEW_BATCH_HINT=andREVIEW_BATCHING=offnext toREVIEW_COVERAGE=partial, instead of leaving 19 of 41 files unread without a continuation.cb(CrewBuddy CLI) 0.1.0 is a required tool on macOS and Linux, installed bydevkit syncfrom its private release through an authenticatedgh(Spec 436).cb updatemoves the binary off the pin;devkit tools --outdatedreports that anddevkit tools --upgradereturns it.- A
github-releaseplatform block intools.jsonmay carrydownload: gh; curl stays the default and an unknown transport fails before any network call. - The SwiftBar menu lists CLI tools with their installed and outdated state, runs
devkit doctorin a Terminal window and links the docs;devkit status --jsoncarriestools[]andtools_outdated_check. AGENTS.mdat the repo root gives Codex, OpenCode and every other runtime that skipsCLAUDE.mdthe canon read order and the self-repair mandate.bash tools/tool-pin-audit.shaudits amarketplace_dirplugin against its repo-local manifest and names the differing field asmismatch:versionormismatch:sha.- The docs site groups onboarding into one Workflows page and both runtimes into one Runtime Adapters page.
/fetch-taskand/fetch-project-taskbuild their digest throughcb— path rule,.gitignore, relation marks, the untrusted-content fence, attachments — instead of two prep scripts (777 lines, 115 assertions retired), and run under Codex too.- The docs site renders the Pen.app design 1:1: restyled navbar, numbered steps, line-numbered code with shell prompts, gridded tables, breadcrumbs and a footer, every landing number bound to
counts.json.
Behavior changed
devkit syncregisters the SwiftBar plugin folder on macOS when none is configured, targeting the stable$DEVKIT_HOME/swiftbar; a folder you set yourself stays and gets theln -sfallback.- devkit ignores Orca's
OPENCODE_CONFIG_DIRinside an Orca-hosted terminal and falls back to~/.config/opencodeinstead of writing into Orca's hooks bundle; your own value stays in force. - Hetzner Inference is removed from the registry, the panel and the docs (measured at 1400–1800 s per answer), and with it the panel's HTTP dispatch path — a panel member is a bin runtime now.
/delegateopens a visible Orca terminal by default instead of an unwatched background process; without a reachable Orca it printsDELEGATE_VISIBLE_FALLBACKand runsdelegate-exec.shdirectly.- The six flow pages are one Workflows page, so a bookmarked
docs/flows/<name>URL 404s; site prose fell from 891 to 513 lines (66k to 35k characters),feature.mdalone had grown 1179→8273. - All six landing-page flow cards open their actual guides; four used translated slugs that led to the 404 page.
- Required-review fallback walks Codex → Kimi → DeepSeek Harness before Claude, and exploration moves to medium effort in Codex and to Sonnet in Claude — routing changes, not measured speedups.
- Every selected quality scanner names its coverage or says it reported none, and the run prints
GATE_SCANNERS_SELECTED; documentation edits select the docs build in affected-path mode too. - One oversized file is advisory at
brief-gate.sh(WARN=lines:<n>, exit 0) because a single file has no seam to split; multi-file and check-count limits stay enforced. - Rule candidates are measured without rewriting the live rule:
--measure-textreads proposed bytes and picks the budget class from their frontmatter. - Rollback to an agent-based release uses that target's own runtime; the current materializer refuses legacy agent content instead of certifying an incomplete installation.
- Review identities hash actual file bytes, LF/CRLF changes hidden by Git clean filters included, and the delegation watcher detects edits to pre-existing untracked files.
- Review metrics recognize native Plan reviewers and external runtime receipts, counting findings by tool identity so repeated notifications are deduplicated.
- Spec authoring reports dropped or unparsable file declarations and per-AC probe verdicts; seven unparsable paths once passed strict authoring.
content/agents/is gone:devkit syncremoves only the links devkit created, anddevkit has|list|path agentanswerAGENTS_RETIRED use devkit path skill <name>(exit 2) for one release.- A
compactspec gets no model authoring review (18 of 31 needed one round): strict validation, the overlap preflight and the Approval Capsule are the gate;fullkeeps one round plus one delta. /spec-workpermits one full implementation review and one delta round, then a blocking residual setsblockedand the rest becomes follow-ups.- Spec 412 needed nine rounds on a 486-line diff; across 245 receipts with 443 rounds, a cap of two would have cut 73.
- The dispatcher verifies the frozen input on every external reviewer return, Main on native ones; a moved tree is
REVIEW_INPUT_DRIFT, a mistyped SHAREVIEW_INPUT_SHA_MALFORMED(exit 1). - Spec 412 ran 37 Codex dispatches with that input check done by hand before the dispatcher took it over.
- An AC verify may reuse declared checks in an
&&chain only when their dependencies are complete; repo suites run fresh, andcheck-run.pyclearsBASH_ENV,ENV,SHELLOPTS,BASHOPTS. spec-review-prep.shno longer counts a spec-only commit (authoring, a status flip) as merged implementation, and an extensionless or root-level declared path now enters the review package.- The policy guard reads
rmflags and targets per shell segment, so anrmword quoted inside another command no longer borrows-rfand a root target from its neighbours. review-runtime.sh --dispatchresolves a checklist path adev-syncremoved, checks reviewer JSON againstresult.schema.json, andNO PERF VERDICTvoids only a dispatched Performance section.- A review brief above 100 KB no longer dies with
Argumentliste ist zu lang(a 220 KB brief did at Linux's 131072-byte argv limit): it travels as a brief file and to codex on stdin. /delegatescans briefs and gates for credentials, a Codex continuation recovers its complete final message from the JSON events, and the version probe no longer inherits your stdin./delegateto codex warns on a host/CLI version skew, needs an explicit session ID to continue, routes hard diagnoses through the architecture tier, and opts kimi out of the secondary model pool.repo-exploreris retired; broad or noisy discovery routes to the nativeExploreagent (Claude) or the built-in explorer (Codex).- The Codex reviewer's read-only boundary is enforced again.
- Live design extraction is bound to its worktree's browser session, so it inspects the page it was asked about; recovery pins and registry paths match the distributed tools.
- A payload without
model-routing.jsonfails skill validation closed, while a legacy payload signed before manifests still validates, so rollback keeps working. - Root-level
## Files to Modifyentries resolve, and the array handling behind it is safe on Bash 3.2 (macOS system bash). reuse-guard.shand the review-time clone scan both catch a renamed-variable paste that escaped jscpd, and a scan that could not run is reported as unavailable instead of clean.- The managed env block pins the auto-compact window (
CLAUDE_CODE_AUTO_COMPACT_WINDOW), so compaction fires at a known threshold instead of wherever the model's own limit fell. - Readable Git output routes through RTK behind a closed command grammar, and the hooks keep policy output and existing trust routes intact during RTK dispatch.
/researchrequires a bounded agent runner instead of falling back to an unbounded one; Orca is preferred for managed worktrees and tabs.- Among the rules, response style lives only in
core.md > Responses, 16 references to two deleted rules are repointed, andscript-contract.mdno longer claims the harness silently truncates large output. - The docs site builds again: the delegate skill names its task-routing reference as a backticked path like every other skill.
shfmtis pinned to 3.14.1 on Linux and macOS from the sha256-verified mvdan/sh release (apt shipped 3.4–3.8 and disagreed with brew), and all 279 shell files format clean.- A tool's install block is resolved per platform (
linux/darwin), so a version pinned for CI is pinned on macOS too instead of floating on brew. - The session-start notice reports a failed background fetch — a VERSION collision had pinned one machine to 0.35.0 for two days without a symptom; the next successful fetch clears it.
- Do not hop a delegation the host killed: it exits 2 now and the message says so — split the brief instead.
- A review ends after two rounds; if a third feels needed, re-cut the scope, and the
review:field in the COMPLETED receipt records the rounds and how many blocked. bash tests/all.shprints each suite's assertion count on its result line, read from the suite's own.donefile, so a count no longer costs a second run.- The Spec 375 loss proof grew a second layer:
tests/fixtures/skill-rules/holds verbatim anchors for the rules, and only lines under 20 characters left the baseline (- Case 1matched anything). - The
/spec-workbody sits at 4407 of its 4500-token cap after two added clauses and/reviewat 5000 of 5000; read either withdevkit run content-budget.sh --measure <file>. - A concurrent session's edits no longer void your spec review: the
Review input SHAcovers only your own and unattributed changes, and stays fail-closed without a session record. - The implementation-review waiver is one predicate for routing and completion: the
Implementation-Review: waivedheader above the first section, every criterion a deterministic verify. - The authoring probe classifies a
tests/all.sh,test-prep.shorquality-gate.shverify aspolicyand leaves it to the implementation run instead of misreporting a 60-second timeout. - A panel member that stops serving the dispatched tier is skipped, not asked; no shipped member is affected today, since codex, kimi and hermes all carry
reviewintiers; the guard had covered 3 of 8 runtimes. - A comment edit that only moves a security term no longer selects the Security review section; a matching code line, a new term or a security-ish path still does.
bash tests/all.sh --suite runtime-routeno longer depends on an installedprime-agent: its baseline is stub-backed and its one unseamed case keeps a hermetic PATH.- Review-cost measurements are recorded apart from gates: 242 completed specs had median 2, p90 3, max 9 rounds, 18% above two; Spec 425 took 4 rounds, Spec 427 took 2, neither with drift.
- The OpenCode adapter enables the session tools and never removes a key, even an explicit
null;devkit offleavesopencode.jsonuntouched,devkit doctornames conflicts (Spec 429). - dsh and prime delegates keep the tools a profile would strip: a devkit
tools.patch.ymllayers after the MCP patch, andprime-run.shrejects an unowned--no-tools(Spec 430). - A review survives an unusable seat and an ordinary commit: the dispatcher walks
routes.reviewto kimi/dsh, and the package anchors on the spec's authoring point, not aSpec-NNNsubject. test-prep.sh --affected-onlydrops proven-foreign paths with one drop-count notice, so it no longer runs another session's suites; an unusable store keeps the full set (Spec 431).- The spec implementation review carries reuse candidates:
reuse-detect.shruns over the scoped diff, and a confirmed duplicate is a finding that faces the same material-impact test as any other. - CodeGraph applies where it runs:
detect-stack.shcounts*.jsx,*.mjsand*.cjs,brainstormmay use Grep/Glob/codegraph_explore, andagent-graph.mdstates each subcommand's arguments. - Review blocks only on a demonstrated reachable failure of behavior, security, data or verification; minor findings become follow-ups, and
spec-finish.shno longer refusesPASSabove two rounds. review-prep.sh --worktreereviews the open changes without unpushed commits (REVIEW_SCOPE=full|worktree), and a codex brief above 16000 B is named before dispatch (issue #46).review-runtime.sh --dispatch --candidate-shareviews an authoring candidate with no spec file yet, andDELEGATE_READONLY_VIOLATIONsplits changed paths into named and unnamed (issue #44).spec-validate-prep.sh --strict-authoringfails a citation whose line does not carry its identifier asevidence_off_lineinstead of passing (issue #44); past draft, a drift into aFiles to Modifyfile is only a warning.devkit doctornames dead{file:...}references in the project'sopencode.jsonthat madeopencoderefuse to start, and warns about pre-type: "local"MCP entries (issue #43).cd-guardrewritescd <cwd> || exit 1likecd <cwd> && …; any other||alternative runs unchanged with a note instead of a block (issue #47).skill-lintprints each installed plugin skill it cannot check asplugin-skill <marketplace>/<plugin>/<skill>without moving the exit code;DEVKIT_SKILL_LINT_PLUGIN_ROOTpoints elsewhere.- A Codex, Kimi or dsh implement worktree comes home by itself: after a green run
delegate-return.shapplies the diff, refuses paths dirty in main (DELEGATE_RETURN_DIRTY) and removes it; Prime still returns a patch for you to apply. - The always-on plugin opt-in writes its marker before the flag, so a deleted flag is never re-created, and
plugin listwarns when the pin has no user-scope install instead of never opting in. - A Prime run under Orca 1.4.201 no longer dies after one poll with "no trustworthy worker state": the settlement loop accepts the
worker.dispatchIdkey live Orca returns. - A Prime run executes a private snapshot of
prime-run.sh, so editing the script mid-run no longer crashes the wrapper or deletes its finished worktree. - A Prime worktree is a child of the calling Orca worktree (
--parent-worktree active) instead of--no-parent, and a/waveslice is a child of the main checkout passed as--main. - Edits made through Bash (
sed, heredoc, python) are attributed to the session that ran them, so a parallel session no longer moves your spec's Review input SHA. - The stale-index hint reaches the model as
additionalContext, so the first answer of a session names/indexitself instead of leaving a grey line for you to notice. - OpenCode receives the pinned i-have-adhd ruleset in its managed
AGENTS.mdblock on everydevkit applywhile~/.claude/.i-have-adhd-alwaysexists, and loses it on the next apply without the flag. delegate-exec.shtreats a whitespace-only stdout as no result (exit 2) and reports a delegate's rewrite of an already-dirty path instead of an empty touched-files list.check-run.pyrecords the effective--timeoutastimeout_sand names records and logs<criterion>-<execution-id>, so a failed AC's log is findable by its id.- Every agent in this repo, delegated or not, repairs a setup defect it hits in the same run and reports defect and fix together, as
AGENTS.mdnow mandates. tests/check-run.shandtests/tool-pin-audit.share green on macOS, not only in CI; no assertion changed its meaning.delegate-exec.shnames a Codex usage-limit stop asDELEGATE_USAGE_LIMIT runtime=<rt> retry_at=<when>instead of a bareexited with 1, so it costs no wasted re-dispatch.docs-drift-check.sh --acceptnow names every source it certifies, so a drift acceptance shows exactly which files it covered.devkit doctorrun from$HOMEno longer advisescodegraph initover the whole home directory or a dead memsearch repair command; both now match the actual project state.- Long autonomous implementation routes to Prime by itself; the rule had lived in one person's memory and was applied by hand in three runs before it reached
agent-dispatch.md. - Delegation follows the registry's tiers, Codex modes and
routesinstead of hardcoded refusals;devkit config runtime <name> auto|on|offis the switch. - Spec authoring drops the machinery precheck (256 mentions in 52 sessions), and validator warnings block nothing on the compact route: errors block, warnings travel into the approval question.
- The reviewer prompt reports every finding with confidence and severity instead of hiding those below 80; Main's blocking-class adjudication is the filter, and the unenforced 15-turn budget is gone.
- Unmeasured review counts read
null, not 0, and the impact report names its unknowns instead of summing them as zero (Spec 417). - The docs gates go red on a table cell over 600 characters, a page over 6000 bytes of prose, a
content/path in two markers, or a page without its English original or a sidebar link. - Main no longer builds a bidirectional spec-diff matrix, and a
Prevalence:line is required only for a claimed recurring failure or a number-bound criterion. - The authoring review package carries a
Sources:line naming the files the reviewer may open, the ID uniqueness check reserves no further IDs, andspec-meta.sh --fieldno longer returns error JSON as a digest. - A correction review answers every original blocker as addressed or unaddressed and reports only regressions the fix introduced; an unrelated observation stays advisory unless it passes the material-impact test on its own.
- A skill with
paths:is held out of the listing until a Read, Write or Edit touches a matching path, then listed — its body is never auto-loaded, so a prompt that names no file makes such a skill less discoverable, not more. /waveproves a worker's release withorchestration worker-list --run <run_id> --terminal-state reclaimable --json, and a multi-line terminal brief is confirmed by--wait-submit 5 --jsonreportinginput_accepted, not by the paste alone./devkit-tools-changelogreads every call site a second time per upgrade and checks the PR content against the fields, exit codes and states those callers assume; an unchanged command name no longer counts as compatibility.- A Claude session receives
core.mdonce: the pinned ruleset already loads it always-on, so the SessionStart hook now emits it only to Codex, which has no such path. - A required tool fetched over
ghfrom a private release no longer abortsdevkit syncon a machine withoutgh auth login: it counts as missing,status,doctorand the menu bar show it, the next sync after the login installs it.
Action required
- Only if your own hooks name
code-reviewer,implementerorrepo-exploreror calldevkit has|list|path agent: dispatch a native subagent with the prompt file fromdevkit path skill <name>. - Only if you continue Codex or Interpreter delegations by hand: keep the session ID the dispatch printed —
resumewithout one is refused. - Codex users: the updated
rtk-rewritehook needs your native/hookstrust review before it runs; until then readable Git output stays unrouted. - If
/delegatewarnscode-mode host X against codex-cli Y: align the two before dispatching — the recipe that fixed 0.153.4 under 0.154.0 is indevkit/tools/codex.md. - If you set
/autocompactorautoCompactWindowyourself: the managedCLAUDE_CODE_AUTO_COMPACT_WINDOW=800000now takes precedence. - If you installed
uvoragent-browserby hand: the pins moved, anddevkit syncdistributes pins, not binaries, so update them yourself. - A spec split across parallel implementers needs a stated owner per assertion, and no arm runs a shared gate until every arm has returned — a file-cut split on Spec 415 paid a 190 s rerun.
- A fix outside
## Files to Modifygoes through/spec-updatebefore the review: that line is digest-bearing, and editing it in place voidsapproval_validafter the review is spent. - A
Successor-Ofspec against ablockedpredecessor fails validation assuccessor_predecessor_blocked: drop the header and itsdepends_onedge, keep the relationship in Context. - Hand
spec-checks.sha check directory frommktemp -doutside the tree, not prep's in-projectRUN_DIR; the rejection now says so instead of costing an exit-4 cycle. - Run
gh auth loginwith an account that can readonedot-digital-crew/cli-crew_buddy; until thencbstays missing — the sync completes and namesgh auth login, the nextdevkit syncafter the login installs it. - Log in to CrewBuddy once for
/fetch-taskand/fetch-project-task:cbprints the login hint itself — never paste a credential into the chat. - Update bookmarks to the old flow, concepts, comparison, Codex and OpenCode pages: Workflows, How it works, Runtime Adapters.
- For a project that uses a design skill: rebuild its context or run
design-fill.shsoDESIGN.mdcarries the adapter block, then clear itsTODO — confirmvalues. - Own external review calls must pass the frozen identity —
--specwith--review-input-sha,--review-tree-shain Diff mode,--candidate-shafor an authoring candidate without a spec file — or the dispatcher refuses them. - To opt out of the always-on i-have-adhd ruleset, delete
~/.claude/.i-have-adhd-always; devkit never re-creates it, and OpenCode drops it on the nextdevkit apply. - A green Codex, Kimi or dsh implement run applies its diff and removes the worktree; keep one with
devkit run delegate-return.sh <worktree> --keep, and clear main's dirty paths onDELEGATE_RETURN_DIRTY. - Prime keeps its own lifecycle and hands you a patch to review and apply yourself.
- If your own
opencode.jsonvalues keep the added session tools out: rundevkit doctor, resolve the conflicts it names, and remove the added keys yourself if you ever want them gone —devkit offdoes not. - If SwiftBar already has your own plugin folder: link it once,
ln -s ~/.onedot-devkit/swiftbar "<your folder>/devkit"— the automatic registration never replaces a configured folder.
🚀 Features
- review — finding assessment owns the material blocking test and spec-finish drops the round cap (8b1c85e)
- opencode — enable the session tools additively and report them (Spec 429) (9c6f258)
- review — block on material impact, correction-only re-review, budget separate from completion (Spec 412) (8b16f1b)
- review — the spec review package carries reuse candidates (0ec36d0)
- spec-finish — refuse a PASS over the two-round review cap (40da4ee)
- cli — add a macOS menu bar switch for devkit on/off (5756c33)
- spec-validate — the authoring probe skips policy and suite verifies (b9d4755)
- tools — report what a plugin update changes instead of discarding it (dc5e112)
- delegate — MCP servers (codegraph, context7) on dsh via --patch overlay (8855e53)
- tools — Watched blob pin for adopted upstream sources (Spec 424, WIP) (f6c8641)
- delegate — Panel dispatch passes the tier choke point (Specs 422, 420) (c8c05c1)
- review — One predicate decides the implementation-review waiver (Spec 423) (4ebbbdb)
- review — A foreign session's edits do not void a spec review (Spec 418, WIP) (08e22c9)
- delegate — Per-tier runtime resolver replaces the hardcoded refusals (Spec 420, WIP) (679f8f0)
- spec-validate — Strict-authoring JSON discloses per-AC probe verdicts (7ff7c1a)
- delegate — Measure the read-only claim instead of asserting it (8afb6b0)
- delegate — Wire autohand as a read-only delegate runtime (50e1b5e)
- dispatch — Route long autonomous work to Prime (9476aba)
- routing — Foreign-vendor reviewer, explore at medium effort (fae6e95)
- review — Review-prep names its batch caps, takes --all and --help (d2fec26)
- review — Dispatcher re-verifies input, prep validates strictly (Spec 412) (42a7c44)
- checks — Spec-checks --tick/--append-evidence, brief-gate advisory (Spec 412) (39f9048)
- spec-work — Prep and finish scripts replace Main's plumbing (3eb1321)
- spec-review-prep — Freeze the review on a change manifest (Spec 412) (b2afc87)
- quality-gate — Build the docs site as a gate scanner (e0809a1)
- dev-sync — Accept a linked worktree of the configured source (868d3b5)
- tools — Pin shfmt to 3.14.1 on both platforms (5fadb7c)
- tools — Resolve a per-platform block, not just linux (ee06e64)
- routing — Codex review and architecture seats on gpt-6-astra, second opinion by default (0e25361)
- agents — Retire content/agents and its projection (Spec 411) (911f401)
- dispatch — Read roles from skill-local prompt files on native subagent types (Spec 410) (1decadb)
- review — Verify the frozen review input after every reviewer return (Spec 409) (e822389)
- tools — Content-budget.sh --measure prints count, cap and headroom (3751030)
- index — DESIGN.md traegt den Adapterblock fuer Design-Skills (61d98ad)
- spec — Review policy Level B — no authoring review on compact (7160e67)
- quality-gate — Add baseline-widen and baseline-age advisory scanners (37c0f2b)
- tools — Resolve monorepo and pre-release upstreams per tag family (450cce5)
- skills — Drop the upgrade gate from both changelog skills (c9ad251)
- reuse — Wire jscpd type-2/3 detection and a fallow doctor preflight (980c6a1)
- skills — /checkin syncs a running session with the human (5dd7208)
- tools — Audit kind:external CLIs against upstream releases (448c280)
- env — Pin the auto-compact window in the managed env block (0b916d6)
- hooks — Deliver the pinned i-have-adhd ruleset to Codex at SessionStart (0eb3608)
- delegate — Run every delegate visibly in an Orca terminal by default (f71c1d1)
- plugins — Pin i-have-adhd as a sha-pinned Claude plugin (Spec 435) (41a7fd1)
- docs — Implement the devkit.pen landing and doc-page design (914e793)
- swiftbar — Runtime, reviewer and channel settings in the menu (5baeb8e)
- gates — Make docs accretion, shared sources and orphan pages red (16a5105)
- swiftbar — Apply a runtime choice at once, add a sync entry (0056160)
- delegate — Bring a delegate's worktree home and remove it; four workflow fixes (Spec 435) (d39fde6)
- tools — install cb from its private GitHub release over gh (Spec 436) (d0d4a0e)
- swiftbar — list CLI tools, run doctor and link the docs from the menu (7900e1a)
- opencode — materialize the pinned i-have-adhd ruleset into the managed block (32021bc)
- hooks — deliver the stale-index hint to the model, not only as a grey line (f9b27c6)
- fetch-task — run the CrewBuddy digests through cb, retire the prep scripts (52532e1)
🐛 Fixes
- devkit-tools-changelog — second read per call site, not a name-diff (fbd4cf2)
- spec-review — a spec whose implementation predates its doc stays reviewable (Spec 420) (d78bd06)
- issues — #43–#47 — material-impact test, scope propagation, SIGPIPE, dead references, unquoted whitespace (d437428)
- spec-review — review input survives an ordinary commit (f3eda53)
- review — parse a fenced or prose-wrapped verdict from a fallback runtime (84ceacd)
- review — fail over to the next review runtime on an unusable seat (84776ef)
- tooling — make CodeGraph usable where it applies (1122b64)
- docs — point flow cards at their existing pages (65d123e)
- rollback — materialize legacy agents with their target runtime (72b8182)
- gates — build docs when affected inputs change (3cf6a2e)
- docs — read cache timestamps portably on macOS (4931684)
- budgets — classify rule candidates from their own text (68f828e)
- metrics — count native and external review receipts (12b75e2)
- delegate — detect edits to existing untracked files (5f30c26)
- review — retain security scope when controls are deleted (84a3c5a)
- review — bind review evidence to unfiltered file bytes (bcdd30e)
- checks — rerun suites with incomplete cache input coverage (97cb89c)
- menubar — ship the SwiftBar plugin as executable (350d7f3)
- tools — close seven review findings on the watched blob pin (05c94e7)
- rules — Say what
paths:on a skill actually does (00d1063) - check-run — The run-dir error names the check directory (113a7ea)
- spec — Strict authoring refuses Successor-Of on a blocked predecessor (Specs 422, 420) (cbe78e3)
- review — A re-flowed comment no longer selects the Security section (Spec 422) (21192d3)
- review — Close the fail-open edges in the spec review identity (Spec 418) (33b90a8)
- spec — The authoring review package names the sources a claim rests on (758f5ea)
- spec — Files to Modify names what it drops, and counts files not bullets (229fcbf)
- tests — Update the Gate 5 pin to the corrected wording (31532ab)
- metrics — Unmeasured review counts read unknown, not zero (Spec 417) (078b1eb)
- content-budget — --help actually documents --measure and --measure-text (65b4872)
- review — Blocking class 6 covers a fresh assertion, not only a weakened one (be4662e)
- test-prep — A .agents/context edit now selects the content-language suite (a8732b8)
- review — Gate 5 is a presence check, never a re-run (c254603)
- review — Name the rerun knob the prep actually reads (Spec 415) (71a9ff4)
- gate — The four silent scanners print their own counts (f83b647)
- hooks — Cd-guard respects the quote class and refuses a broken tail (9e0066d)
- gate — Every selected scanner names itself, silent or not (13d2486)
- hooks — Cd-guard rewrites the command instead of costing a turn (34b6144)
- tooling — Price a candidate wording, and stop --field emitting errors (8089642)
- docs-drift — --accept names every source it certifies (feaa2a9)
- lifecycle — Close five review follow-ups in the spec scripts (Spec 415) (0c59776)
- delegate — A usage-limit stop is named, not buried in exit 1 (79e7715)
- spec — Finish the warning-gate removal in spec-update and the skeleton (3bbeaee)
- review — Coverage-first reviewer prompt, drop model-era filters (Spec 336) (8c7dcff)
- docs-drift — Accept several pages per call, validated before the first rewrite (0013a0d)
- spec-review-prep — A spec-only matched commit is not merged work (2ed8b99)
- review-runtime — Re-resolve a stale checklist, scope the perf sentinel (f63dcd9)
- hooks — Read rm flags and targets per shell segment (Spec 412) (7d5bbc1)
- spec-checks — Reuse a declared suite inside an && verify chain (Spec 412) (6aaa7d6)
- hooks — Preserve policy output and existing trust routes (6164bf9)
- tools — Repair browser binding and stale consumers (af264ca)
- hooks — Route readable Git output through RTK (c22c495)
- dev-sync — Keep the prune ledger in the git common dir (8077296)
- docs — Keep the relabelled scripts node inside the landing graph (Spec 411) (51db046)
- review — Expose unavailable clone scans (05206f9)
- research — Require a bounded agent runner (b88448c)
- routing — Keep skill validation without a manifest (Spec 411) (ade78b2)
- docs — Link the delegate task-routing reference the way every skill does (3e1d164)
- spec-review-prep — Reject a malformed review input sha before comparing (Spec 409) (75f89d9)
- routing — Prefer Orca for managed worktrees and tabs (4b533ca)
- delegate — Close stdin on the codex version probe (59f9cbe)
- review-runtime — Hand the dispatch prompt to delegate-exec as a brief file (b1605a8)
- delegate — Hand a prompt above the argv limit to codex on stdin (77c1f79)
- spec-review-prep — Keep extensionless nested paths in the declared file list (682d020)
- review — Persist the Diff-mode drift line in the review package (Spec 409) (a3e3980)
- hook — Report a failed background fetch at session start (3ede5ed)
- delegate — Bind Codex follow-ups to explicit sessions (50864d6)
- codex — Make the read-only reviewer boundary real again (1d3a4f9)
- scripts — Resolve root-level Files to Modify entries and bash 3.2 array safety (4c60345)
- delegate — Opt kimi out of the default-on secondary model pool (4f647b4)
- delegate — Catch a code-mode host skew before the dispatch (0aea6dd)
- rules — Repair the Karpathy adaptation's dead pointers (633ada0)
- skills — Docs-page.sh find says why it found nothing (e0844ab)
- rules — The harness does not silently truncate large output (fbb9b8e)
- rules — Repoint 16 references to two deleted rules (a3a3066)
- spec — Three setup defects met while authoring and running Spec 435 (Spec 435) (88057dc)
- swiftbar — Stable plugin folder; ignore Orca's OPENCODE_CONFIG_DIR (b535b46)
- plugins — Close the three Spec 435 review follow-ups in the always-on opt-in (Spec 435) (a093714)
- prime-run — Accept the camelCase worker key Orca 1.4.201 returns (00790dc)
- hooks — attribute Bash-made edits to the session that made them (Spec 436) (477855a)
- tools — pin the gh release fetch to github.com (Spec 436) (73e8e08)
- tests — check-run and tool-pin-audit suites green on macOS, not only in CI (1f884c1)
- tools — close the Spec 436 review follow-ups on the gh transport (Spec 436) (942f2d6)
- delegate,checks — no silent delegate success; observable budgets; audit sha-pinned plugins (9c5b190)
- wave — create every slice worktree as a child of the main checkout (1225f3e)
- prime-run — run from a private snapshot and hang the worktree under the caller (Spec 436) (f5983de)
- prime-run — give worktree an explicit parent instead of --no-parent (ddcff18)
- doctor — index health from $HOME stops advising codegraph init and a dead memsearch command (4dc385a)
- rules — stop double-emitting core.md to Claude sessions (cf691be)
- tests — five suites red in CI behind the shfmt gate, green again (94c075c)
- tools — a download:gh tool without gh login is missing, not fatal (681251c)
⚡ Performance
- test-prep — affected selection drops foreign session edits (Spec 431) (e546e05)
- checks — declare every suite in the reuse policy (b5fd79b)
♻️ Refactoring
- spec — reuse the canonical AC checklist parser (c764975)
- menubar — ship the plugin as its own SwiftBar folder (fc2fded)
- spec-work — Skill text names scripts instead of their steps (55e0945)
- spec — Prevalence only for claimed failures, one delta-round rule (Specs 412, 375) (9581b20)
- spec — Drop the machinery precheck, analyze stage and warning gates (Spec 198) (dc45490)
- index — Adapter block without target, inventory with precedence order (e5772a6)
- agents — Retire repo-explorer, route discovery to native Explore (cd2167d)
- rules — Close the audit's rule rewrites and dead duplicates (938d1f6)
- rules — Unify response-style policy under core.md > Responses (cb4845d)
📖 Documentation
- workflows — accept the drift marker after the 0.36.0 source review (d37e509)
- menu-bar — the macOS menu bar switch gets its own page (e4d54dd)
- devkit-docs — a newly added skill sorts first in the Highlights (54cd1a5)
- tools — review orca v1.4.201, wire terminal send --wait-submit (24ef29e)
- wave — prove worker release with worker-list, not memory (5e0ffcf)
- devkit-docs — a skill delta is a mandatory changelog highlight (d6cac07)
- research — record the review-process simplification assessment (8caf1d8)
- changelog — record the post-v0.36.0 work in both changelogs (2b13794)
- audit — pin measured review and fix-loop tails (0a3e8bb)
- workflows — align review guidance with active routing (f01e690)
- audit — add the spec 427 review-cost row (0475cd2)
- changelog — record the spec 427 review-round cap (4b72f73)
- audit — add the first post-change review-cost row (fe83ed2)
- changelog — record the spec 425 probe-skip fix (f7df4b7)
- tools — the six-point bar a plugin candidate has to clear (7ed6367)
- tools — record what stays a CLI, and what the memsearch pin misses (5341082)
- audit — baseline the per-spec review cost before the next run (47f3a94)
- tools — anchor when a capability becomes a plugin (d1883ef)
- changelog — Record the spec 423 waiver-predicate fix (Spec 423) (84622c6)
- changelog — Record the spec 418 review-identity fix (Spec 418) (1b3dabe)
- flows — Re-accept four markers after reading the one line that moved them (f28bf40)
- devkit — Land the orca spec panel audit, the TypeScript brainstorm and the autohand log (7ba54af)
- specs — Add the 418 and 420 spec documents (54b0f6f)
- spec — Drop the stale verified_assumptions_missing hint from the light skeleton (48b6fcf)
- flows — Name the /spec-update route and the split owner seam (76f488f)
- changelog — Record the spec 417 review-metrics fix (Spec 417) (3fd2dc5)
- gate — Name the CHECKS/NO_CHECKS invariant where a scanner is added (25c4cf2)
- changelog — Source the run figures, correct two more counts (Spec 415) (a5b21ed)
- changelog — Correct the Unreleased numbers an audit refuted (Spec 415) (f930ae5)
- changelog — Fill Unreleased with the 17 commits since v0.36.0 (Specs 415, 412) (b855cd1)
- spec-work — Name the seam for a split, and the route out of scope (Spec 415) (61ad3f9)
- spec-work — One review round plus one delta, then adjudicate (Spec 412) (2e21eea)
- skills — Devkit-docs harvests every measured number and asks Codex for completeness (102e3d4)
- changelog — Rebuild Unreleased from the 86 commits since v0.35.0 (d56e547)
- backlog — Name the finding cap and the lint in the header (19340d6)
- backlog — Keep the verify-probe row inside the finding cap (a3881d7)
- flows — Re-set the flow page markers after the spec-work rule change (eeef062)
- changelog — Friction fixes of the Spec 412 run, verify-probe backlog row (Spec 412) (778fa76)
- spec-work — Delta rounds while each closes its findings, tick AC boxes (c7bbf15)
- context — Record the change-manifest decision of Spec 412 (Spec 412) (4c2385f)
- flows — Re-set the knowledge page source marker (5f4a8a8)
- spec — Author Spec 412 — change manifest for review package and SHA (Spec 412) (835b1fa)
- audit — Close-out section for the rules-vs-frontier audit (Spec 412) (6160cb0)
- general — Mirror today's changelog rows into the German page and trim a flow row (9da0915)
- flows — Split two over-long paragraphs and re-set the reviewed markers (6fe6472)
- hooks — Explain RTK runtime activation (3a8b60f)
- tools — Register every installed tool consumer (a9a685b)
- review — Drop the Codex-Main frontmatter aside to stay under budget (b49086b)
- spec — Complete Spec 411 — reviewed by codex gpt-6-astra (Spec 411) (e33f1d1)
- changelog — Record today's review-transport and package-scope fixes (797d189)
- review — Drop the triage bullet that duplicates contract item 3 (472976c)
- spec — Complete Spec 410 — reviewed by codex gpt-6-astra (Spec 410) (26fd4b4)
- spec — Complete Spec 409 — reviewed by codex gpt-6-astra and claude Plan (Spec 409) (fda84d4)
- tools — Point fallow's implementer consumer at its new path (Specs 411, 410) (0b7d499)
- backlog — Worktree-wide review fingerprint blocks back-to-back spec completion (8680445)
- general — Record the 0.154.0 host repair and the agent-retirement changelog entries (acf9b87)
- audit — Reference sweep — no missing speed tool, 21 of 43 candidates refuted on cost (e4da3a8)
- gotchas — Point the budget gotcha at content-budget.sh --measure (d8c392c)
- changelog — Record the review policy, explorer and codex changes (a558ec9)
- audit — Rules-vs-frontier audit and the agent-retirement specs (0a9b131)
- tools — Close the kimi secondary-model open item (090c4ba)
- changelog — Fill Unreleased with the last 14 commits (d6ee737)
- menu-bar — Plain fence titles; accept quoted menu labels in the changelog (8d52b46)
- Changelog Unreleased for menu settings, SwiftBar folder, Orca OpenCode dir, Hetzner removal (08e499d)
- site — Fold the six flow pages into one Workflows page (68f00fa)
- site — Write the pages for the user, not the maintainer (6c7822f)
- reference — Record the i-have-adhd plugin adoption in the watch notes (c94e47f)
- specs — Author Spec 436 — install cb from its private release over gh (Spec 436) (7890d7f)
- specs — complete Spec 436 — cb installed over gh, review PASS_WITH_FOLLOWUPS (Spec 436) (1334f0d)
- agents — add AGENTS.md with the canon bootstrap and self-repair mandate (1e5ef11)
- canon — every agent repairs a setup defect it hits, unasked (ee392c3)
- Changelog Unreleased for cb over gh, child worktrees, Bash attribution (c3a53ae)
- workflows — describe the delegate return path; drop the stale card sentence (ce89759)
- menu-bar — keep the German intro under the 600-character paragraph limit (8a90f5b)
- specs — give Spec 420 the COMPLETED line its closing commit skipped (29e2be3)
🧪 Tests
- delegate — Spec 430 proves dsh tool re-enable and prime disable-flag refusal (Spec 430) (250847b)
- off-on — freeze the payload source before doctor asserts clean (ff14198)
- rules — The rule inventory is checked in both directions (d5234b5)
- fixtures — Restore the loss-proof subset, keep the anchors beside it (d155c1e)
- fixtures — The loss proof anchors rules, not prose (Spec 375) (5fd4a9d)
- hooks — Protect policy output during RTK dispatch (aa6482d)
- hooks — Define safe RTK routing boundaries (1107ffe)
- review — Reproduce false clean clone scans (2db49b6)
- research — Reproduce unbounded agent fallback (a44b96f)
- hook — Make the 90-day stamp work on BSD date (fe1b31c)
- delegate — Reproduce ambiguous Codex continuation (4b1240c)
- fixtures — Register REVIEW_INPUT_DRIFT and sync the review-verdicts snapshot (b48dec1)
- native-sweep — Hold the docs-page.sh no-match message (e0408e8)
🏗️ Chores
- specs — complete Spec 426 plugin skill inventory (b0711ce)
- specs — pause Spec 406 pending a release, Harbor and a spend cap (Spec 406) (28e4256)
- specs — close Spec 420 as shipped-in-HEAD (Spec 420) (55c1612)
- specs — archive Spec 428 as superseded by the material-impact review policy (Spec 428) (7af04b2)
- devkit-improve — Stamp the 2026-09-12 run (ea1c8d7)
- ledger — Record the 2.1.263-2.1.266 window (129a417)
- tools — Bump jscpd, fallow, uv and agent-browser to current (7188b71)
- runtimes — Remove Hetzner Inference from the registry and panel (de76484)
- runtimes — Drop the HTTP dispatch path with Hetzner (ae1468c)
No commit type
- allow(Bash(devkit run feedback-issue.sh *)) (70fe754)
- Skill-lint gains a read-only inventory of installed plugin skills, and d (Spec 429) (d07eb3a)
- style(tests): reformat for the pinned shfmt (cb5a972)
- Delegate: unify Codex/Claude/Prime routing and add structured review rec (5b4e37c)
- Add SwiftBar auto-registration and spec/harness provenance tracking (Spec 432, 433) (d041da1)
- Add model/harness provenance to spec Progress Log lifecycle lines (6f9f4d8)
- Add design/devkit.pen — landing page mockup for the setup (a8ad4e8)
- Update changelog with SwiftBar auto-registration and spec provenance ent (f096acd)
- style: shfmt lib/opencode.sh and tests/delegate-exec.sh (87f8a58)
v0.35.0 — 2026-09-08
/commit now shows your recorded review and QA verdicts, and Wave auto-selects Codex for implementation whenever your Orca host can run it. Update with devkit sync.
78 commits since v0.34.0 · Specs 347, 375, 386, 398, 399, 400, 401, 404
✨ Highlights
🔁 /commit shows your recorded review and QA verdicts
/commit now reads back what /review and /spec-verify already decided about the staged spec and prints it before the diff — no more committing a spec whose UAT was actually rejected because nobody scrolled up to check.
=== VERDICT SIGNAL ===
review: last PASS 12 minutes ago — not bound to this staged tree
uat: rejected 402🌊 Wave picks Codex for you, only where it can actually run
Wave's slice dispatch now auto-selects Codex for implementation whenever your Orca host can launch it composed (--agent/--model/--effort), and falls back to Claude everywhere else — one flag if you want to force it.
devkit run wave-prep.sh slice-dispatch --run <run_id> --spec-id <id> --name <slice-name> --main <main-checkout> --brief-file <path> [--runtime auto|claude|codex]📐 A spec measures its own prevalence before candidate bytes exist
/spec now requires exactly one Prevalence: line before Phase 2 — a measured count, a named rare-risk blast radius, or a reason the population yields none — so a "this happens often" claim needs evidence before it can justify a full spec.
Prevalence: rare — blast radius: <what breaks and for whom>🔁 /delegate reaches three more reviewers by their product name
The registry was keyed by binary, so asking for DeepSeek by name hit "unknown runtime 'dsh'". Every entry now carries its product aliases, and an unknown name lists what it would have accepted.
devkit run delegate-exec.sh deepseek review --brief <file>🔐 Cross-session messages need explicit acceptance again
A SendMessage between sessions in different permission-mode classes (an unattended wave terminal versus your prompting session) was parked behind a dialog nobody could click and dropped after dialogExpiry. Every sync now enforces the accepting key instead of only seeding it once.
"crossSessionInbound": "accept"What changed for you
Now available
devkit run delegate-exec.sh deepseek review --brief <file>resolves a runtime by its product name (deepseek,open-interpreter,hermes-agent,openai), not only its binary.devkit list agents --scope projectnow sees a project-local agent the waydevkit has agentalready did.rtk bun,rtk bunx,rtk denojoin the existingrtk npm/rtk npxwrappers (rtk 0.48.0)./commitprints a report-only=== VERDICT SIGNAL ===section showing the recorded/reviewPASS and/spec-verifyUAT verdict for the staged spec.
Behavior changed
devkit syncseeds four narrow read directories instead of your whole~/.claudehome — see Action required if an earlier sync already widened it.devkit syncnow enforcescrossSessionInbound: "accept"on every run, correcting a stalehold/refuseinstead of only seeding it once.- Wave's cost-approval question runs unconditionally before the first orchestration mutation; the self-certified "already authorized" skip is gone.
- An unsupervised Prime give-up now stops the agent it started before touching the worktree, instead of force-removing a checkout a live agent is still writing to.
- A Spec's
## Files to Modifyentry naming a path that does not exist is rejected at approval when the repo already carries the same file under a different path or a near-identical name. - A single untracked file another session drops in your checkout no longer breaks
--affected-onlyfor the whole team; the test map can now say a path drives no suite at all. /testnarrowing works after a commit: with a clean working tree it selects suites from the unpushed range (@{upstream}..HEAD),--since <ref>names another basis, and theAFFECTED_MODEline says which one was used. Every route stays fail-closed — it never falls back to the full suite.- The
codexreview/implement wall-clock floor is 1800s (was 1200s), andhermesruns parse--reasoning/--resumecorrectly ahead of the prompt.
Action required
If an earlier
devkit syncalready widened your~/.claude/settings.json, drop the bare~/.claudeentry it seeded there:bashbashjq '.permissions.additionalDirectories -= ["~/.claude"]' ~/.claude/settings.json > /tmp/s.json && mv /tmp/s.json ~/.claude/settings.json
🚀 Features
- skills — Adopt what pays by default, ask only for a decision (5c0cf7f)
- permissions — Seed the runtime directories as readable (7bb25c5)
- skills — Make both changelog skills wire what they find (4f0a1c6)
- automation — Deny prompts on the unattended headless runs (3d4e616)
- spec — Add routing coherence gate spec, reverse-skill research, and (Spec 404) (2329f40)
- spec — Disclose an acceptance-criterion verify that could not be split (Spec 399) (bc743ad)
- review — Gate a spec's file list against its companion files (d08e0ee)
- spec — Fail authoring on a reviewer role no agent can dispatch (Spec 347) (a67b6a0)
- prime — Record which paths came from an external patch (Spec 401) (28efc04)
- hooks — Block a redundant leading cd that forces a permission prompt (2ad24c7)
- spec — Close two review-free paths to completed (Spec 400) (5d91cbe)
- commit — Report the recorded review and UAT verdicts at commit time (Spec 398) (fad2e9c)
- wave — Offer the friction escalation unprompted after every run (f6ad99e)
- wave — Require a DEVKIT-FEEDBACK block in every end report (fc645dd)
- hooks — Enforce crossSessionInbound accept on every wire (a22111d)
🐛 Fixes
- tests — Isolate the ORCA_* environment in test-lib, not per suite (230bfcf)
- tests — Stop the wave suite inheriting ORCA_TERMINAL_HANDLE (2242b63)
- test-prep — Narrow against the unpushed range when the tree is clean (3587c51)
- release-prep — Fail scope-check on a VERSION bump with no prep commit (26f6609)
- prime — Only a clean not-found answer may skip the terminal close (a8cd107)
- rules — Say how to commit a file another session also edited (be5a43c)
- prime — Tear the started agent down on every unsupervised give-up (e3df62b)
- wave — Restore the unconditional cost gate and bind Codex to composed launch (38a09d2)
- permissions — Narrow the seeded read scope to the payload link dirs (d0618e5)
- prime — Settle native Orca runs from worker state (bf89e18)
- skills — Close the four findings this session's own runs produced (67bac0d)
- tests — Let the output-contract assertion follow the citation (e9a92ce)
- measure — Abort a measurement run on an unknown model id (e3dc700)
- scripts — Count /skill-doctor, /diff and /advisor as built-ins (71a796b)
- commit — Match a bulleted or bolded UAT verdict key (Spec 398) (6a8fa04)
- delegate — Name the codex host skew before blaming the brief (3c81cd4)
- runtime — Let list agents see the project scope has agent already sees (c922169)
- commit — Resolve the UAT verdict for padded ids and loose spellings (Spec 398) (8fc36e7)
- spec — Stop three wave rounds that were pure contract friction (8f6828a)
- delegate — Make three of five reviewers reachable again (f457814)
- hooks — Make an announce-gate block diagnosable after the fact (fa4cbee)
- hooks — Detach session-end apply-pending to dodge SessionEnd abort (11625cb)
- spec-verify — Say the spec is completed when routing a finding (fe37cbb)
- review — Name follow-up findings in the answer when Diff Mode runs (49c7842)
- test-prep — Let the map say a path drives no test suite (22c3b09)
- content-budget — Pin the five largest skills where CI pins them (Spec 375) (b34e72c)
- pre-push-gate — Fail on shfmt drift, not only on syntax (bb54b87)
📖 Documentation
- flows — Re-accept the two markers the test-prep change moved (46829ac)
- devkit-release — Name the merge-invalidates-digest route at step 1 (be0fb5c)
- release — Cut v0.35.0 changelog and version bump (2e3ac1e)
- tools — Record the claude-code review this session actually ran (b7bac93)
- tools — Date the parked blockers instead of implying them (50c79e1)
- rules — Name the routes the last two releases opened (44f9b78)
- spec — Add 405 — measure the problem, then converge the review (20c712f)
- spec — Complete 398, 400 and 401 (22a527b)
- spec — Cut 402 to the failure the measurement actually found (Spec 386) (e41d553)
- spec — Add 402 — bind AC evidence to its criterion (ada65cc)
- spec — Record the 400 and 401 implementation reviews (89c535c)
- spec — Add 399 — say when a verify could not be split (e8a7788)
- spec — Record the 398 implementation review and its two fixes (7480672)
- review — An externally produced diff keeps the implementation review (Spec 401) (ddf61d1)
- spec — Add 401 — record which paths came from an external patch (8730227)
- spec — Add 400 — close two review-free paths to completed (c432423)
- changelog — Record the two friction fixes under Unreleased (a1f350c)
- spec — Add 398 — commit prep reports review and UAT verdicts (5a28a33)
- changelog — Mirror the crossSessionInbound entry into the German page (6a0d0b6)
- changelog — Point the entry at the commit that shipped it (bf997b2)
- spec-work — Cite testing.md instead of restating the full-suite rule (3a7442f)
- flows — Re-accept the feature drift marker after the review change (956cb68)
- changelog — Record the test-prep map marker under Unreleased (71efc1d)
- changelog — Record the two gate fixes under Unreleased (ce372f0)
🧪 Tests
- prime — Prove the prune keeps a fresh external record (Spec 401) (dd7ff72)
🏗️ Chores
- audit — Add usage snapshot for 2026-09-07 (30d window) (02bf13f)
- misc — Ignore the python bytecode the new eval suites leave behind (5e02af1)
- reference — Resolve the three retroactive wirings (80a4ac6)
- reference — Flip permission-prompts-none from parked to chosen (f817650)
- tools — Bump rtk to 0.48.0 and jscpd to 5.1.2 (8f0b4c2)
- reference — Resolve the built-in command correction to its commit (683211d)
- reference — Record the 2.1.258-2.1.261 native verdicts (5cdae72)
- gitignore — Ignore the local autohand state directory (5782b99)
No commit type
- Generate commit message for staged spec-workflow evaluation tooling (c677118)
- Generate commit message for staged spec-workflow changes (09745e5)
- Fix the CODEX_HOME/CODEX_SKILLS_DIR test isolation bug and rework prime- (1a28dc9)
v0.34.0 — 2026-09-02
/workspace now runs the member specs it authored, a release worktree no longer parks every wave, and /delegate … implement reaches codex-cli again. A hook names the index gap at the read that hit it. Update with devkit sync.
65 commits since v0.33.0 · Specs 369, 370, 374, 381, 382, 383, 385, 386, 388, 389, 390, 391, 392, 395, 396
✨ Highlights
🏗️ /workspace runs the member specs it wrote
Authoring wrote one spec per sibling repo but left every /spec-work to be started by hand, and the wave route wanted an Orca host and two terminals per member. The driver runs them from the mapping file, skipping any member that is not idle and clean.
devkit run workspace-run.sh plan <mapping-file>
devkit run workspace-run.sh start <mapping-file> --yes
devkit run workspace-run.sh status <mapping-file>🌊 A wave stops parking over a worktree it cannot name
The overlap gate read a slice id only from a directory name and failed closed on everything else, so an open release checkout blocked every wave (#36). A worktree now names its spec by directory or branch, and one that names none is skipped by name instead of stopping the run.
WAVE_APPROVE_WORKTREE_SKIPPED … reason=no-spec-id|detached🤝 /delegate … implement reaches codex-cli again
codex-cli 0.151.0 made --sandbox and --approve-for-me mutually exclusive, so every implement dispatch died with exit 2 before a token was spent (#35). A run that still loses its tool channel now names the workaround — split the brief — instead of inviting a re-run (#37).
/delegate implement "…"🪝 The index gap is named at the read that hit it
A file read outside what /index has mapped left the agent to notice the gap on its own, or not at all. The advisory hook says so at that moment, stays silent where there is nothing to say, and carries its own kill switch.
DEVKIT_SKIP_INDEX_GAP_HINT=1🗺️ /index --map answers without a rebuild
--map reports stack, languages, refresh state and the top hub rows from the artifacts already on disk, and writes nothing — orientation costs no rebuild.
/index --map🧠 A Critical gotcha arrives on the prompt it fits
GOTCHAS.md reached a session only as a cold nine-entry block. A Trigger: regex restates one Critical entry on the prompt it matches, once per entry per session.
Trigger: devkit run|content/(scripts|hooks)🤖 Four runtimes measured as wave workers — none finishes the handshake
Spec 395 probed prime-agent, kimi, hermes and dsh live through Orca. All four reach the Orca CLI; none delivers an accepted worker_done, because Orca grants the dispatch capability only to the agent integrations it implements itself.
/wave # a worker still runs ClaudeWhat changed for you
Now available
workspace-run.sh statusclassifies every member: idle, running, done, blocked, failed./index --map— read-only orientation report, no rebuild.REVIEW_IMPACT=1— impact appendix in/review, input hash unchanged.devkit unlinknames every foreign path it kept behind, with thermto remove it.
Behavior changed
/delegate … implementruns again on codex-cli; atool-channel faultsrun says to split the brief rather than re-run it.- The implement tier runs at xhigh effort, and the escalation seat is Fable 5.1.
devkit doctorwarns on reads blocked outside the working directories and onSUBAGENT_MODEL_FORCEoverriding agent frontmatter./specfails loudly instead of allocating a spec ID that is already taken./indexreports a retrieval saving only where one was actually measured.- A wave reads the idle verdict from the terminal screen instead of the stream, installs the baseline worktree's dependencies before measuring, and collapses a sibling wave's inbox rows into one counted line.
- Telemetry counts a hint as converted by the action it named, not by the skill name.
- A spec review recovers its diff when the work was merged before the review ran.
Action required
rtk0.47.0 is breaking:rtk grep --file-type/-tis gone, and-l/-t/-mnow reach native grep.
🚀 Features
- review — offer an opt-in impact appendix (Spec 386) (31fd0a5)
- hooks — point at the index gap right after the read that hit it (Spec 385) (326301d)
- index — report a retrieval saving only where one was measured (Spec 389) (dcdcf58)
- model-routing — raise the implement tier to xhigh effort (Spec 369) (ce3a3ab)
- telemetry — measure hint conversion by the action, not the skill name (Spec 370) (43daafd)
- wave — measure four runtimes as workers, behind a checkable record (Spec 395) (230d847)
- gotcha-recall — restate a Critical gotcha on the prompt it applies to (Spec 392) (d349566)
- agent-eval — freeze the inputs and label the count for what it is (Spec 390) (fb4db2e)
- index — give /index a read-only orientation map (Spec 388) (68b1c5f)
- unlink — name every foreign path unlink kept behind (Spec 391) (3fec52f)
- doctor — warn when reads outside the working directories are blocked (453123c)
- model-routing — move the escalation seat to Fable (8b6e7a2)
- project-migrate — close a run on what the reader still has to decide (be2b157)
- specs — contract the three Graft adaptations that change a script (a1e613c)
- routing — record the evidence behind the tier table (21e5d64)
- rules — bind graph lookups to a stop condition and closed tool sets (f39f2f5)
- workspace — run member specs unattended from the umbrella mapping (aefa871)
🐛 Fixes
- delegate — name the workaround in the tool-channel fault marker (45bc09b)
- wave — read the terminal screen for the idle verdict, not the stream (6e16da5)
- workspace — count only spec files when deciding a member is done (b0a4b6e)
- wave — an unnameable worktree that holds work fails closed again (219e74e)
- spec-review — match the spec id in the subject, not the whole message (Spec 383) (768eee8)
- wave — stop a release worktree from parking every wave (e9441a7)
- codex — resolve the project hook from PATH, not a macOS home (3218978)
- spec-386 — make AC2 measure the switch instead of its own side effect (Spec 386) (bd036ba)
- hooks — stop @tsv from mangling the hook JSON it carries (e7322db)
- delegate — mark a codex run that lost its shell output (e36c278)
- test — derive the codex fixture's effort from the tier table (Spec 369) (b8f8615)
- gate — clear the two standing reds in the main checkout (Spec 374) (56fa241)
- spec-review — recover the diff when the work was merged before review (Spec 383) (1ace985)
- wave — install the baseline worktree's dependencies before measuring (3013f65)
- wave — a detached worktree is no sibling slice, so it must not park one (754f36f)
- wave — collapse a sibling wave's inbox rows into one counted line (360f2a8)
- doctor — warn that SUBAGENT_MODEL_FORCE ignores agent frontmatter (761cfa3)
- context-fill — group the fill log by verb instead of per section (4612a06)
- prime-run — name the continuation ceiling, not the brief (818e755)
- spec-id — fail loudly instead of allocating a taken ID (fde4da7)
- delegate — stop pairing --sandbox with codex --approve-for-me (953e816)
- drift-check — stop reporting refs this repo cannot resolve (dd1cd66)
- spec-work — keep the implementer report and the review freeze alive (Spec 396) (c0e1724)
- spec-review-prep — drop the trailing space that reddens shfmt (415a760)
- spec-work — bring the skill body back under the 4500-token ceiling (29610cc)
⚡ Performance
- audit-prep — classify the signals in one pass (Spec 383) (681f7cd)
📖 Documentation
- flows — carry the tool-channel fault workaround into flow 3 (d9b04c5)
- tools — record the Orca v1.4.195 review (e7485d0)
- wave — clear a foreign red at acceptance, not only at the gate (Spec 369) (d190785)
- language — open the closed German list for Trigger regexes (Spec 392) (6e0dc32)
- wave — attribute a red pre-commit gate before aborting the merge (Spec 390) (f8db432)
- wave — name the installed-runtime trap a mid-wave repair walks into (26b0d09)
- reference — close the read-scope and detached-background rows (d341017)
- model-routing — name Fable 5.1 as what the fable alias now resolves to (fbf46f3)
- reference — record the 2.1.252-2.1.257 changelog verdicts (bcac772)
- research+specs — audit codebase-memory-mcp and EvoMap, draft three (3479293)
- audit — record the agency-agents reference scan (533fa4e)
- research — record the Graft adaptation audit and its deferred items (0143235)
- api — point the ingest schema at its published contract (3c227d0)
- changelog — fill Unreleased with the 57 commits since v0.33.0 (4bda2fb)
- backlog — add findings on model routing for review, specs and waves (a0b5ee4)
- devkit-docs — drop the changelog head cap, keep the per-item bar (8ddd375)
🧪 Tests
- hook — prove the context warning fires well before compaction (Spec 382) (5e6c85d)
- hook — close the two prune assertions the spec still owed (Spec 381) (4636665)
- affected-map — select model-routing when lib/doctor.sh changes (6c17e9c)
🏗️ Chores
- tools — bump uv, agent-browser, fallow and rtk pins (78658ef)
- autohand — add memory event log and index (b71a10c)
No commit type
- Expand context-fill and design-fill dependency detection, add self-pruni (8a51e44)
v0.33.0 — 2026-08-31
Spec authoring stopped waiting on the repository: the planning reuse sweep no longer treats every backtick as a file it must scan for, and the review package hashes the working tree in one git process instead of 2406. Update with devkit sync.
28 commits since v0.32.0 · Specs 028, 162, 368, 380, 383
✨ Highlights
⚡ Strict validation stopped sweeping the repository
Every backtick in ## Files to Modify counted as a file the spec creates, so a flag name earned its own repository-wide scan. Measured on one spec: 3069 ms down to about 700, 2215 processes down to 409.
devkit run spec-validate-prep.sh --strict-authoring --candidate <path> --target <path>🔎 An acceptance criterion that proves nothing now says so
ac_verify_silent_gate warns when a verify command cites a gate that stays silent on success — 134 of 3758 verify commands in the corpus do.
- [ ] AC1 — … → verify: `bash tools/content-budget.sh` # warns: silent on passWhat changed for you
Now available
trigger_collisionin the quality gate flags two skills that answer the same trigger phrase.DEVKIT_PRIME_RUN_RETENTION_DAYS=0keeps every Prime run directory; the default prunes terminal ones after three days.
Behavior changed
- The implementer brief now names a report file, so a truncated run leaves a handoff instead of nothing.
/challengejudges a spec draft; a vague idea routes to/brainstorm.- The quality gate prints the unregistered-tools report it used to discard.
🚀 Features
- spec — warn when an acceptance criterion leans on a silent gate (Spec 368) (2885c66)
- skill-lint — catch two skills that answer the same trigger phrase (1fcb3af)
- prime — prune terminal run directories older than the retention window (ff526f1)
🐛 Fixes
- tests — follow the two contracts this session actually changed (6d9c0a1)
- prime — reap the agent daemon no run owns any more (529a93a)
- delegate — report a curl transport failure instead of an empty answer (50ead99)
- spec-work — give the implementer brief the report file it is asked for (fd35a2a)
- gate — let the unregistered-tools report reach a reader (9578bda)
- skills — three contracts that contradicted their own callers (afacdc0)
- rules — resolve the comment contradiction and stop overclaiming rtk (ccce673)
- prime — name git's reason when the worktree cannot be created (124819c)
- spec-complete — prune orphaned completion run directories (6ea0650)
- tests — run the five assertions finish had cut off (Spec 162) (da9a550)
- usage — measure whether the index hint is ever taken up (4c68963)
- review — name the step that made the review package unwritable (4a451a5)
⚡ Performance
- spec — tally the behavioral-delta fields once instead of per key (Spec 383) (2e80f82)
- review — hash the tree in one git process, not one per file (Spec 368) (7d1b350)
- spec — scope the planning reuse sweep to declared paths (Spec 368) (1682950)
📖 Documentation
- audit — a second, independent measurement of the spec workflow (cfbab63)
- flows — re-anchor the three markers after the spec-path changes (27f1e94)
- audit — measure what the language gate cannot see (7a7a95a)
- prime-agent — record what nine parallel runs actually cost (Spec 380) (6a1d362)
- audit — measure the real cold load and the plan-slice backlinks (Spec 028) (960952d)
- core — measure the cold load CLAUDE.md claims instead of quoting a stale one (3709762)
- gate — describe the output the gate actually produces on green (60fa824)
🏗️ Chores
- tools — bump jscpd, fallow and agent-browser pins (492b367)
- prep-lib — expand symlink-guard one-liners in review_package_write (87a9a29)
- audit — refresh the 2026-08-31 usage snapshot to the evening window (4cfb9ee)
v0.32.0 — 2026-08-31
Spec validation went from 962 seconds to 62, a filling context now warns in the conversation, and devkit apply removes the legacy hooks devkit replaces. Update with devkit sync.
33 commits since v0.31.0 · Specs 154, 250, 381, 382, 383
✨ Highlights
⏱️ Spec validation stops re-running the same suite
Criteria sharing one suite ran it once each. The verify now splits on &&, so the shared part runs once — 962 seconds to 62 on one measured spec.
devkit run spec-validate-prep.sh --strict-authoring --candidate <f> --target <spec>🧭 A filling context warns you while you can still act
One line at 115000 tokens, then every 51000 — both measured across 101 sessions. It never goes quiet above the threshold.
DEVKIT_SKIP_CONTEXT_WARN=1🧹 Old npx hooks come out, the rest stays wired
An entry goes only when its file is byte-identical to an npx artifact and devkit ships that name. The other 18 stay.
cat ~/.claude/.od-hooks-pruned.jsonWhat changed for you
Now available
DEVKIT_SKIP_CONTEXT_WARN=1turns off the context warning for a session.DEVKIT_SKIP_HOOK_PRUNE=1turns off the legacy-hook removal for a session.
Behavior changed
- Session start may remove legacy npx hook entries devkit replaces, each backed up first.
devkit doctorno longer closes on "Alles gesund." over its own warnings;devkit statusnames the command behind open migration items.
Action required
- A hook you miss is in
~/.claude/.od-hooks-pruned.json; restore it from there.
🚀 Features
- reuse — close the five remaining semantic-duplication gaps (14c1853)
- hooks — warn about a filling context while there is still room to act (Spec 382) (849d232)
- reuse — look up an existing source before the second view is built (f96c602)
- hooks — prune the legacy hooks devkit itself replaces (Spec 381) (13bf973)
- reuse — detect two components reading one source on a page (9992a62)
🐛 Fixes
- tools — stop an empty npm prefix array from killing the sync (1269566)
- wave — name the nested-repo boundary before a slice loses its work (9b65a69)
- status — close the three gaps a prime-agent sweep confirmed (0ce2de6)
- delegate — stop codex research from timing out at 150s (5cab655)
- doctor — stop a green verdict from standing over its own warnings (7531b24)
- errors — give two bare exit codes their reason (be352b1)
- migrate — count a kept legacy file in the apply verdict too (9ce8af9)
- doctor — name the command behind open migration items (ac191aa)
- design — name a reason when the fill step has no stderr (7cd4842)
- migrate — count a dry-run's drifted copies in its own verdict (4a5e85f)
⚡ Performance
- spec-383 — collapse the last three repetitions and map the sandbox suite (Spec 383, 154) (93543a4)
- spec-383 — collapse the review-batch and quality-gate repetitions (Spec 383) (f81e418)
- spec — probe an AC verify per conjunct, not per criterion (Spec 250) (da1a4cf)
📖 Documentation
- fixtures — add git-stderr reason to migration failure message (485b938)
- troubleshooting — name the hook a prune can remove (Spec 381) (fcf416e)
- spec — add Specs 382 and 383 — context warning, repetition fixes (b24548c)
- spec — add Spec 381 — prune only the legacy hooks devkit replaces (Spec 381) (a212552)
- audit — record the AC-probe cost analysis and its correction (Spec 250) (222c2b6)
- changelog — record the two issue fixes under Unreleased (18212d9)
- audit — record the defect-class sweep and its verification (1b2809e)
- onboarding — say what an open migration item asks of you (502a1e0)
- site — link the CLI reference from the landing page (92341a3)
- changelog — say what devkit apply is and when stable lags (1aa5b34)
🧪 Tests
- skill-lint — stop case (g) from reddening on stderr it never read (8a507c9)
- make two silent fixture skips announce themselves (c193bb1)
🏗️ Chores
- spec — drop the 383 candidate scratch file (c1ec826)
- audit — capture 30-day usage snapshot for 2026-08-31 (e8bb5f5)
- backlog — park the two ONEDOT items that need their own cut (d8c1dab)
v0.31.0 — 2026-08-30
Every session loads 1267 fewer tokens before it works, every matching edit 4666 fewer. Update with devkit sync.
35 commits since v0.30.0 · Specs 321, 372
✨ Highlights
⚡ Less text before the first line of work
GOTCHAS.md went from 2639 to 1372 tokens, three path-scoped rules from 6860 to 2194.
bash tools/content-budget.sh🧪 Judge a payload change instead of reading it
Two arms, the same fixture tasks; a difference inside the run-to-run spread counts as noise, never an improvement.
bash tools/agent-eval.sh --tasks tools/agent-eval/tasks📦 A new dependency answers for its identity
One verdict per added package — accepted, review, blocked, unavailable. Every failure path yields unavailable, never accepted.
printf 'package-lock.json' | devkit run dep-acceptance-prep.shWhat changed for you
Now available
bash tools/agent-eval.shmeasures a skill, rule or agent change against a control payload instead of judging it by reading.devkit run dep-acceptance-prep.shreports identity, provenance and licence per newly added package.devkit run budget-prep.shissues a turn and elapsed-time ceiling for every delegate run.
Behavior changed
- One hook process runs per tool call instead of five; a blocking policy exits the moment it decides.
quality-gate.shruns only the payload scanners your change can break;--fullandDEVKIT_QUALITY_GATE_FULL=1still run all eleven.- An always-on rule now states that retrieved text is data, never an instruction.
🚀 Features
- agents — give the implementer a 1h prompt cache TTL (39e01e3)
- tools — make jscpd a required tool (f00de2a)
- eval — measure a payload change instead of reading it (2f3ea4a)
- deps — a new package answers for identity, not only for CVEs (81345a1)
- budget — give every dispatch a ceiling it cannot quietly exceed (2f82ce1)
- rules — state the untrusted-content boundary as an always-on rule (d383adc)
- routing — route the review tier onto opus (1612a09)
🐛 Fixes
- ci — gate the tag on a hosted run of the SHA, not on a local emulation (5735842)
- tests — stop EPIPE in a producer from reddening its assertion (de64d0e)
- ledger — let a parked row be closed at all (031aeb5)
- hooks — refuse a symlinked marker dir before mkdir and chmod touch it (Spec 372) (9df7682)
- doctor — subagent model env is a default, not an override (478b94e)
- wave — label a sweep row that belongs to another run (b774ee9)
- delegate — give the explore tier a bound a research brief fits in (c1f3582)
⚡ Performance
- rules — three kernels keep the decision, the rest moves behind a pointer (56eaf5f)
- gate — route the payload scanners by changed file (556797d)
- context — GOTCHAS carries invariants, the archive carries incidents (11b47da)
- hooks — one payload parse per event instead of five (ce20972)
- skills — move branch detail out of the five largest skill bodies (5f0dccc)
- routing — drop two coordinator skills off opus (f7c5219)
- routing — match twelve skills' effort to what their bodies do (29068cf)
📖 Documentation
- changelog — record the EPIPE assertion fix under Unreleased (eb08e89)
- tools — register jscpd and record why its absence was silent (Spec 321) (8294b5e)
- tools — record kimi's upgrade path and the refusal that hides it (a2d57f5)
- tools — register kimi as an external delegate runtime (e930a77)
- spec — nine specs from the perf/token audit and the blocks research (19a454e)
- audit — record the model/effort routing audit over all 39 artifacts (e71121a)
🧪 Tests
- agents — document the experimental frontmatter key (03241c3)
- hook — pin the jscpd format map, register the last three runtimes (07891c9)
- rules — follow the text specs 374 and 375 moved into references (7f41c92)
- affected-map — cover opencode and model-routing.json (99afde5)
🏗️ Chores
- tools — record the tool-pin review cadence marker (b60a945)
- tools — bump uv, agent-browser, fallow and headroom pins (f20dd62)
- reference — record the 2.1.247-2.1.251 changelog verdicts (ffea080)
No commit type
- style(tests): apply shfmt to the EPIPE assertion guard (5d84514)
v0.30.0 — 2026-08-28
/delegate gains DeepSeek Harness as a fourth runtime that also implements, gates that could report green without checking anything now fail, and a pending version is applied at session end. Update with devkit sync.
52 commits since v0.29.0 · Specs 298, 347, 360, 361, 362, 363, 364, 365, 366, 367
✨ Highlights
🤝 A fourth delegate runtime, and it writes
DeepSeek Harness runs as dsh: read-only for review, workspace-write for implement, pinned per mode. It implemented all seven specs in this range.
devkit run delegate-exec.sh dsh review "judge this diff"
devkit run delegate-exec.sh dsh implement --brief brief.md🚨 A gate that checked nothing is red
An unreadable file entered the language scan with counter 0 and counted as checked; twelve success assertions matched a prefix that swallowed a checked 0.
bash tools/content-language.shWhat changed for you
Now available
devkit run delegate-exec.sh dsh <review|research|implement>, withDEEPSEEK_API_KEYin$DSH_HOME/.env./devkit-improveworks the accumulated friction and the findings a review rejected.
Behavior changed
- A pending version is applied when a session ends, not only at the next start;
DEVKIT_SKIP_SESSION_END_APPLY=1disables it. hook-installno longer seeds the env block:devkit applywrites it (an automation command — the SessionStart hook runs it, you never call it yourself),hook-uninstallremoves it.- Strict spec validation errors on an undefined AC reference and an empty verify command.
- The binding spec approval now stands behind the authoring review.
🚀 Features
- release — run the workflow's steps, not a list of remembered ones (8b35cf7)
- hooks — apply a pending version at the session-end boundary (Spec 364) (e07bd6a)
- spec — record rejected findings and mine the friction they leave (Spec 367) (dfd5941)
- spec — make an unresolvable AC reference and an empty verify block (Spec 361) (8138f1a)
- manifest — harden the session manifest and its impact report (Spec 360) (b330175)
- hooks — give the env block one owner and a withdrawal path (Spec 363) (538ae60)
- delegate — give dsh a real implement tier via workspace-write (c33b5d3)
- delegate — add dsh as review-only delegate runtime (5007fda)
🐛 Fixes
- spec — stamp the outcome line eight closed specs never got (c4b0f23)
- hooks — keep the improver nudge inside the repo that owns the skill (Spec 367, 365) (694d5f1)
- delegate — stop truncating away the line that says what failed (e950967)
- spec-work — show the PASS receipt the completion kernel accepts (7a020e5)
- prime-run — refuse a patch against a base the checkout left (0c7ae89)
- delegate — give the implement tier a 3600s bound (fe2b19f)
- hooks — name the sentence that blocked the stop (6b80454)
- prime-run — keep a parallel run's worktree out of cleanup (db40085)
- gates — report only what the gates actually checked (Spec 366) (d9f4307)
- spec — stop template.md prescribing a silent-on-pass budget gate (Spec 367) (3b56202)
- delegate — pin dsh review to read-only and drop its panel arm (78b5e09)
- delegate — treat a balance/quota refusal as transient, not terminal (9b980d8)
- spec-validate-prep — stop reporting a fail status as a script defect (7144740)
- brainstorm,challenge — name the Ideation checklist section in the brief (9e6ce5f)
- review — restore four review questions spec 347 dropped (Spec 347) (afd5c08)
- codex-policy-guard — keep inert heredoc bodies out of the policy scan (4059901)
♻️ Refactoring
- spec — move the binding approval behind the authoring review (Spec 365) (921ce94)
📖 Documentation
- changelog — record the 47 commits since v0.29.0 (Spec 363) (5e17035)
- spec — fix the inverted kill switch in spec 364 (Spec 364) (2a3a58e)
- spec — drop the gate waiver triage.md still described (Spec 365) (244ffe2)
- spec — extend spec 361 to the acceptance criterion nobody produces (Spec 361, 366) (3cc7610)
- spec — add spec 367 to close the improvement loop (Spec 367, 298) (891c4c5)
- spec — add spec 365 and close the last backlog row (Spec 365) (3eecae7)
- spec — add spec 366 so the gates report only what they checked (Spec 366) (5ea00e1)
- spec — add specs 360 and 363, closing the last backlog rows (f93d936)
- spec — add spec 361 for the AC reference and empty-verify gates (Spec 361) (1aefd58)
- review — number the Authoring checklist gates (36681a4)
- brainstorm — settle the verify form for the Claude review adapter (25ec200)
- spec — add spec 364 for applying a pending version at session end (Spec 364) (9f37f41)
- spec — add spec 362 for the deleted review-workflow assertions (Spec 362, 347) (a7f2b94)
- session-close-hint — record that the Stop systemMessage is rendered (97d79f1)
🧪 Tests
- review — cover the review workflow paths nothing exercised (Spec 362) (d910943)
- delegate — accept the seventh raw sandbox left by 9b980d8 (d06d13c)
🏗️ Chores
- tests — format the two files the static gate flagged (5107957)
- gates — accept the wave's sandbox and docs baselines (Spec 364) (de16369)
- spec — close spec 364 (Spec 364) (f0c58a9)
- spec — close spec 367 (Spec 367) (eb5e6dd)
- spec — close spec 361 (Spec 361) (2565a6d)
- spec — close spec 360 (Spec 360) (1ac25f1)
- spec — close spec 363 (Spec 363) (dc38aaf)
- spec — close specs 362 and 365 (f191f50)
- spec — close spec 366 and accept the eighth raw sandbox (Spec 366) (344634d)
- backlog — bind four rows to their landed spec and brainstorm (62de1fd)
- backlog — record the drain decisions for 15 open entries (51ccb82)
v0.29.0 — 2026-08-27
Gates that reported green without checking anything now fail, a blocked run finally names the line that blocked it instead of a class shared by 22 sites, and /delegate reaches two more runtimes. Fresh installs work again too. 30 commits. Update with devkit sync.
30 commits since v0.28.0
✨ Highlights
🚨 A green that checked nothing is red
A renamed content root made the language scan print checked 0 file(s), 0 violations and exit 0 — indistinguishable from a clean run. The baseline is the witness now: rows for files nothing resolved mean a broken scan.
bash content/scripts/quality-gate.sh🔍 A blocked run names the site, not the class
capability stood for 22 distinct failure points, invalid_target for 10. The reason enum stays fixed for callers, and the exact site goes to stderr — line numbers and error codes, never spec bytes.
devkit run spec-update-prep.sh --json <ID> 2>err.log🤝 Hermes and Open Interpreter answer a delegation
Four runtimes take a brief. Hermes refuses implement — no workspace sandbox, only a flag that skips every approval — and Open Interpreter stays out of the panel until interpreter login ran.
devkit run delegate-exec.sh hermes review "<question>"What changed for you
- A fresh
curl | bashinstall completes where npm's global prefix is root-owned. - A Prime run that never took a turn now fails loudly instead of publishing an empty patch.
- Every panel answer names the model behind it, so shared base models stop reading as agreement.
🚀 Features
- release — the card carries the whole hand-written entry, not just its lead (d3a569c)
- delegate — add Open Interpreter, drop hetzner from the panel (7e7e645)
- delegate — name each panel member's model in its block header (72397a6)
- delegate — register Hermes Agent as a fourth runtime (48412c9)
🐛 Fixes
- gate — a language scan that resolves nothing is red, not an empty green (35f8a8c)
- spec-update — every blocked reason names the site that produced it (be357bb)
- spec — candidate_invalid names its cause, and the reviewer stops hashing (01e7141)
- prime-run — a run without a turn is a failure, and it names its cause (3c3b5f1)
- ci — the smoke asks the CLI for its version the way the CLI spells it (13e6d2d)
- tools — install a package manager before the entry that needs it (f075c2d)
- release — the installer gate is a job, and its assertion checks the job (1144af0)
- tools — install globals where the user can write, and gate it in CI (91bf2d8)
- delegate — two trigger phrases, one concrete and one generic (bcaaf62)
- tools — pin a plugin version to what its ref ships, not to the tag (4a8a179)
📖 Documentation
- devkit-docs — compute the release digest after every other commit (ee1c516)
- changelog — record the reason-collapse and empty-green fixes (53b3527)
- changelog — record the prime-run and candidate_invalid fixes (7002752)
- flows — the spec route leads with reversibility, delegate names its runtimes (e6287b3)
- reference — park Open Interpreter as a candidate (b9ac10b)
- tools — note that scripted prime-agent shutdown needs --force (ea89f07)
- audit — record the adversarial validation of the tool-pin update (5e1068b)
- delegate — hermes reads source through a secret mask (f04d7d1)
- delegate — a shared base model is correlation, not one opinion (0df8ed5)
- tools — record that a prime-agent bump breaks live runs (a9eb04f)
- rules — teach agent-graph what codegraph 1.6.0 returns (51bf7bf)
🧪 Tests
- release — read the notes projection without a pipe (0abc8d8)
- content-language — six sandboxes come from mk_sandbox, and the baseline goes (adb3175)
- core — name the doctor finding, and sandbox the resume-grant fixture (ed9d530)
🏗️ Chores
- backlog — park the API-ref guard's false positive on its own documentation (5d6e399)
- tools — bump codegraph, rtk and headroom to reviewed pins (f33e606)
v0.28.0 — 2026-08-26
/debug reproduces a bug as a failing test before the fix exists, and the candidate ledger gives way to an append-only file: 412 undecided rows against 61 landings. Update with devkit sync.
76 commits since v0.27.0 · Specs 065, 145, 334, 358
✨ Highlights
🐛 /debug writes the red test first
The skill refuses to continue until the test reproducing the bug has actually gone red. A fix with no test that failed first is a guess that happened to work.
/debug the wave sweep counts a permission dialog as idle📓 Reference decisions live in one flat file
docs/reference/decisions.md takes one line per decision an external project informed — no verdicts, no backlog, no clock. A finding nobody decided on is written nowhere, which is what 517 parked rows turned out to be.
grep -i '<topic>' docs/reference/decisions.mdWhat changed for you
Now available
/debug <symptom>reproduces a bug as a failing test, then fixes it —--redand--greengate the two halves.devkit run task-digest.shturns a project's open tasks into one digest per task, linked issues included.
Behavior changed
/devkit-harvestis gone and the scan writesdocs/reference/decisions.md; the old ledger is frozen and stays readable.- A spec review receipt fingerprints the whole worktree, so an untracked source file no longer leaves a verdict green.
- A suite that ends early can no longer report green:
finishwrites a completion filetests/all.shrequires.
🚀 Features
- reference — Replace the candidate ledger with an append-only decisions file (bfdd06a)
- ledger — Add park and drain the 412-row backlog with it (0b1aab2)
- ledger — Add unbatch so a reversed batch decision can be withdrawn (be3f96d)
- hooks — Fire the recall ladder on the question, not on a file touch (d6be6be)
- audit-gate — Require a recorded needle per sidecar row (aade74a)
- ledger — Add the reject verb and start the batch clock at commit (b372b98)
- skills — Record linked issues, pulls and the AI analysis in the task digest (Spec 358) (a400d89)
- reminder — Name the unlanded harvest backlog before the scan nudge (283266e)
- debug — Reproduce a reported bug as a failing test before the fix (dcbea5b)
- migrate — Roll the CodeGraph index out with project-migrate (27b3035)
- skills — Let every dispatching skill resume its own delegate (64ba276)
- skills — Enumerate a project's open tasks into per-task digests (4514e4d)
🐛 Fixes
- tests — Give mk_repo a local git identity, and withhold HOME in the clean room (b7f85eb)
- tests — Derive the codex hook count from the file it ships (e1e4bca)
- tool-trial — Record decisions in the file that is still open for writes (b9fbef2)
- ledger — Stop promising a reversibility no code provides (f730fc2)
- harvest — Require a delegated classification to commit its sidecar (2b4797d)
- memsearch — Repair the two open findings of the usage audit (571f01b)
- review — Close three PASS-without-checking paths (e885d42)
- orca — Repair the eight misuses the 1.4.188 surface audit found (88f2161)
- audit — Require a quoted evidence fragment where it is cited (b1e7e1c)
- prime-run — Delete the run branch and report what cleanup left (4f2e0d0)
- tooling — --bare silently fails to authenticate, so stop recommending it (2c02114)
- audit-gate — Flag a sidecar row the expected set does not carry (753457c)
- test-prep — Derive no suite name from a tests/lib helper (600a2f6)
- prime — Stop losing a finished run to the shfmt stage (97e92e3)
- skills — Teach the changelog scan to sweep the grant surface (657176f)
- telemetry — Name 18 native slash commands as built-ins (d37cf1c)
- spec-work — Size the brief by lines and anchor-read the file list (Spec 065) (8a7644d)
- wave — Ship the approved spec revision and name a blocked worker (898c4a6)
- test-prep — Narrow to changed test files when no index answers (96f5403)
- runtime — Resolve agents and skills up to the host project root (6659f3e)
- scripts — Stop a prep crash from reading as a refusal (bb6104b)
- review — Pin the collation the batch offset slices by (3a67637)
♻️ Refactoring
- ledger — Remove the four verbs the queue took with it (fce2a82)
- harvest — Delete the skill whose input the freeze removed (c198022)
- scan — Write decisions, not candidates (00498ed)
- harvest — Cut the queue machinery and close the tap that filled it (Spec 145) (6409690)
- harvest — Make the queue drainable instead of row-by-row (d477e9d)
📖 Documentation
- audit — Recover the harvest verdict sidecar the seven batches lost (4bbaff2)
- audit — Keep the B2 patch and name the regression that blocks it (8ba28b2)
- audit — Review the six Orca guides the surface audit skipped (ff628e4)
- audit — Orca surface audit against app 1.4.188 (286ab9d)
- audit — Brief batch B2, three green-PASS defects in the review chain (93b0b88)
- audit — Brief the long-tail harvest batch (262115a)
- audit — Brief the gstack harvest batch (43d313e)
- audit — Brief the gsd-core harvest batch (8d453a7)
- tooling — Setup-token needs the subscription, not an API key (c5567ab)
- audit — Brief the headroom harvest batch (553963d)
- audit — Brief the EveryInc harvest batch (8edbac7)
- audit — Brief the mattpocock harvest batch (de6b438)
- audit — Brief the harvest pre-pass for a Prime run (43cf3ae)
- changelog — Record the codegraph rollout and the truncated suite (Spec 334) (5006865)
- reference — Close the two adopted 2.1.246 rows (3916d12)
- audit — Record how the setup actually uses codegraph (deb80ba)
- reference — Record the 2.1.235-2.1.246 native verdicts (9f7429d)
- changelog — Record what the four friction issues changed (3e8cb43)
🏗️ Chores
- tooling — Restore shfmt formatting in pin-check-reminder (13d2063)
- audit — Delete the harvest artifacts their own runs consumed (bf3c08e)
- ledger — Open batch B3-evidence-matches-claim with four rows (24a6c10)
- ledger — Land batch B2-review-pass-integrity (ea45049)
- audit — Gate the adversarial Orca adoption pass (a9253b8)
- audit — Gate the Orca surface audit against the frozen CLI schema (24f5f2a)
- ledger — Open batch B2-review-pass-integrity with three rows (9dd0d50)
- ledger — Decide three of the reinvented rows (3744783)
- ledger — Close three long-tail candidates the batch located (3a01f8c)
- ledger — Close three gstack candidates the batch located (29b9423)
- ledger — Close five headroom candidates, withdraw two superseded (3e2310a)
- ledger — Close two EveryInc candidates the batch located (383abdb)
- ledger — Close two mattpocock candidates the batch located (cacae96)
- ledger — Close three native candidates the pre-pass located (ba2e6d9)
- ledger — Close three candidates the Prime pre-pass proved landed (1cc7f04)
- ledger — Close capped-window-reports-true-total as landed (be1cca2)
- ledger — Close three seam candidates landed by /debug (4db486b)
- backlog — Close the load flake row with what 3a67637 actually fixed (0f901a7)
- backlog — Park the skipped installer smoke and the load flake (654709d)
v0.27.0 — 2026-08-26
The largest update so far, and it is about speed. Always-on context drops from 24,760 to 3,166 bytes, eight agent definitions become three, one review replaces the role fan-out: fewer tokens before the first line, one dispatch less per spec. 125 commits, ten specs. Update with devkit sync.
125 commits since v0.26.0 · Specs 042, 095, 346, 347, 348, 349, 350, 351, 352, 354
Breaking Changes
ccusage,ast-grep,repomixandtyposleave the fleet install, andmmdcleaves Linux aarch64.Migration:
/devkit-retroreports no cost for Codex and Kimi runs, the warn-onlyAST_LINTlane leaves the quality gate,post-edit-lintdrops its typo hint,/researchfalls back to plain acquisition. Install any of them yourself to keep it.
✨ Highlights
🪶 24,760 bytes of always-on context become 3,166
Nine rule files loaded into every session, and every subagent inherited them again. One carries the rest.
printf '{}' | bash hooks/session-start-notify.sh | jq -r '..|.additionalContext?//empty'What changed for you
Behavior changed
- Only
core.mdloads unconditionally; every other rule waits for itspaths:trigger. - The implementer returns at most 1,200 characters; an empty reviewer return blocks as
not_reviewed. - Telemetry is off under
CI, and five hint hooks write tosystemMessage, not the model's context.
Action required
- Run
devkit syncper project, then confirm a session carriescore.md.
🚀 Features
- tools — drop four tools that never earned their install (54a7cae)
- scripts — continue the right session, wait natively, reindex when told (8e9f1aa)
- scripts — sandbox the public render, modernise the secret scan, audit uv locks (18934e0)
- scripts — isolate the parsers rg, python3 and shfmt depend on (1d72e6b)
- skills — pin the browser session, narrow fallow, fail closed on headroom (c0d220f)
- prime-agent — understand before dispatch, name the setup defect (7a0d6d9)
- tools — gate the per-tool depth trial on measured surfaces (9365a38)
- tools — gate a tool-integration audit on recounted call sites (8c24499)
- quality-gate — keep the compact page shape from drifting back (e4bdd79)
- quality-gate — fail when a published page is written for maintainers (9dc6b0e)
- review — silence is not a pass, and a fix outside the list is not in scope (3cc5f4c)
- spec — the authoring gates hand the reviewer its checklist (Spec 347) (acc4702)
- review — the checklist path reaches the reviewer, or the run fails visibly (Spec 347) (c1266a0)
- review — a reused review must have covered the sections the signal selects (Spec 346) (b26ee7c)
- telemetry — the collection names itself, skips CI, and stops billing hints to the model (43fed4e)
- agents — the implementer reports to a file and a stuck fix loop escalates once (d6e0fd9)
- rules — the always-on set drops from 24,760 bytes to one 3,166-byte file (38dcce8)
- prime — let a run name its provider, and route Prime through sol (835a0a8)
- telemetry — every session leaves a manifest a release can be read from (Spec 352, 351) (65b6d8c)
- tests — a green run names its coverage, an empty one fails (Spec 350) (83a3ffb)
- agents — remove the last two reviewer roles — eight definitions become three (Spec 347) (9cfba6f)
- agents — remove the security, performance and design reviewer roles (31dce70)
- review — require a package for reviewer dispatch and enforce the return cap (1bf6d7a)
🐛 Fixes
- devkit-release — the clean room withholds what a runner withholds (59e8d29)
- runtime — hand a payload script the CLI path it needs to call back (ebe0ea9)
- changelog — match the heading breaking-check actually greps (4c39f0b)
- delegate — keep the answer when codex writes no last-message file (93522c5)
- tools — follow the python3 consumer evidence to the -I call (18b0124)
- tools — the depth gate missed a template behind a per-row label (9f0afc6)
- prime-agent — parallel runs, write-first order, failed patches (e22a65e)
- tests — the MemSearch pin follows its bump, and states its own invariant (13caf9c)
- index — route the context index into the collection recall searches (Spec 095) (1f78378)
- tools — audit the pin the platform actually installs (a3b7a53)
- tests — a suite that inherits CI tests the CI policy, not its own subject (Spec 351) (d8820b7)
- telemetry — separate consent from the CI upload policy (Spec 351) (f421e74)
- settings — the deny list names the secrets, not every .env sibling (b035013)
- backlog — the row carries the claim, the audit file carries the proof (691d047)
- gates — four parked findings, each one measurable (dba85b2)
- spec-work — the fix-loop paragraph fits its budget again (4615d40)
- routing — the fourth-round escalation leaves the tier list (Spec 349, 042) (06c6d27)
- spec — 351 routes its security signal instead of naming a deleted role (Spec 346) (f2f582a)
- spec — 349 named a test suite that does not exist (15ab808)
- spec — 349 no longer asks for a rename that already landed (75e0d65)
- spec — 348 counted the frontmatter key, not what the pattern matches (a1c90d4)
- spec — 348 measures the always-on sum that HEAD actually has (4728500)
- tests — a php-less host skips visibly, and skills-smoke reads the right step (Spec 350, 347) (8d4b8bc)
- tools — comment-continuation used bash 4 syntax against a 3.2 baseline (e8adce4)
- telemetry — the manifest hook must not hold a session open, or name anyone (Spec 352) (d298c9e)
- tests — a suite proves it ran, and the gate says what it checked (Spec 350) (6e1e08a)
- review — give the one reviewer its audit and delta modes back (a70275d)
- hooks — restore a comment hash that was disabling every hook-install (e18d1bb)
- spec — English section headings in 347 (f1c9e2b)
- review — register DEVKIT_ALLOW_TMP_HOME and restore the reviewer focus literals (fc73e53)
- review — hand the reviewer a path it can actually open, and stop the hook guard wedging installs (fd2c187)
- review — connect the checklist the role removal only moved (f82e3db)
- review — separate "cannot judge" from "cap exceeded" and single-source the runtime (3557831)
- review — stop routing every review through the runtime wrapper (8a2d429)
- review — close the two blocking findings from the 343 implementation review (e8fb2f9)
- scripts — stop gates from reporting green without checking anything (823eed9)
📖 Documentation
- changelog — declare the tool removals as breaking (08c389e)
- audit — record what survives two validation passes (f27c23e)
- audit — the ccusage removal loses more than it claimed (019fa10)
- flows — prime-agent runs in parallel over disjoint file sets (4630a56)
- audit — measure fallow and close the tool depth pass (87da29f)
- audit — measure batch 2 of the tool depth pass (ac1e361)
- audit — measure batch 3 of the tool depth pass (e207914)
- audit — measure batch 5 of the tool depth pass (4e621c1)
- audit — measure four of batch 4 in the tool depth pass (e897cca)
- audit — measure batch 1 of the tool depth pass (c7dc147)
- audit — record the pinned-tool integration audit (4577505)
- context — record handover-file rejection and log Stop hook backlog (1e0721b)
- audit — record the memsearch usage audit and its three defects (Spec 095) (63324be)
- site — compact the published pages (2dcbb69)
- site — rewrite the skill overview for readers (02de34b)
- flows — document delegation to another model in Flow 3 (fccd187)
- site — write the published pages for readers, not maintainers (7ca33a7)
- devkit-docs — a lead may carry three sentences when the range earns them (273a775)
- changelog — rewrite Unreleased from all 78 commits since v0.26.0 (04f9cf7)
- changelog — carry the parallel session's Unreleased progress (b5f0c91)
- backlog — park the paired study with what six review rounds proved (675c96b)
- backlog — close the four rows the batch fixed (fb1322d)
- security — state the controls, and drop the CI credential nobody needed (5a4acbf)
- backlog — close four rows the recent specs already answered (38ece7c)
- prime-agent — gate the shape of the patch, not the presence of a string (3f6367d)
- changelog — record the 64 commits since v0.26.0 (961f9fc)
- vision — the canon says what the code does about scheduling and projection (e1a1e1d)
- backlog — a Prime deliverable in /tmp does not survive a reboot (Spec 348) (a7e425f)
- plan — four specs completed, and what the reviews cost to get there (c6ca518)
- spec — complete 350, and record what this session's reviews cost (d424091)
- spec — complete 347, and count the second suite that could not (Spec 350) (8533920)
- spec — complete 346 with the two holes its review found (aa831d6)
- spec — reconcile 346 and 347 against what actually landed (c82e4fc)
- backlog — the workflow route dispatches a reviewer without the checklist (Spec 346) (bacbd4e)
- core — the review is one reviewer, not a parallel stage of specialists (4a7b67e)
- plan — record 346 landing, the settings leak and the receipt loop (5a65b5f)
- plan — settle that spec-contract-reviewer falls with the others (7692bee)
- plan — record the measured slimming backlog as plan 008 (f97d8e8)
- review-runtime — name --package in the header usage line (12cb3dd)
- agents — name unbriefed test excursions as scope creep (acd605c)
🧪 Tests
- agent-portfolio — write the contract fixture instead of deriving it (5c287f3)
- agent-portfolio — a broken fixture says so instead of failing downstream (323a165)
- impact — take the sandbox from mk_sandbox, not raw mktemp (1e047ba)
- core — pull five suites onto the three-agent portfolio (Spec 347) (b0c8725)
- hooks — detect a comment continuation that lost its hash (746a307)
🏗️ Chores
- audit — declare batches 2 to 5 of the tool depth pass (a86e879)
- audit — declare batch 1 of the tool depth pass (61e8f58)
- tools — bump five pins after the changelog review (0f26a0b)
- review — report an unresolvable checklist instead of failing the report (Spec 354) (79c53f0)
- 353,354,355 — the review reuse gate, the checklist path, and its two callers (16257a0)
- spec — 349 and 351 completed and moved (05c4b93)
- spec — 348 carries the completion state git mv left behind (6476a32)
- spec — 348 completed and moved (99865f1)
- spec — complete 343 and correct the --enforce scope comment (Spec 347) (8ac63c7)
- 352 — measure effect instead of activity counts (5240f46)
- 351 — disclose telemetry and send hints to the right recipient (999e6a3)
- 350 — green runs name their coverage (d4a6c14)
- 349 — cap the implementer return, add escalation and model evidence (642da37)
- 348 — carry the always-on context through the SessionStart hook (d3bf85e)
- 347 — fold the last two reviewer roles into the one (d36beef)
- 346 — make AC6 red-capable by counting the agent files (ff61f3f)
- 346 — remove the security, performance and design reviewers (a5b06d2)
- 343 — bind reviewer dispatch to a package and cap the return (ca2961c)
- audit — add 30-day usage snapshot for 2026-08-23 (eb59f97)
No commit type
- Bind reviewer dispatch to a frozen package and cap enforced report lengt (ab55b68)
- Throttle backlog-hint.sh to once per project per day (032e78c)
v0.26.0 — 2026-08-23
The spec workflow costs one reviewer dispatch and about 1,100 tokens less per run, and a long audit can now be handed to Prime Agent. Update with devkit sync.
142 commits since v0.25.0 · Specs 311, 314, 319, 320, 321, 324, 328, 329, 330, 331, 334, 335, 336, 338, 340
✨ Highlights
🔍 One review stage per spec
/spec-work no longer waits for a contract reviewer before the correctness review; one frozen stage does both, so a normal spec plans one implementation-review dispatch instead of two serial ones.
bash tests/execution-contract-review-trial.sh --self-check-red🪶 A lighter spec update
/spec-update kept its successor and wave-mode policy in the root that every run loads. Both moved behind conditional references, so a normal update pays about 1,100 tokens less before it starts.
devkit run spec-review-prep.sh --completion-validity <ID>What changed for you
Now available
devkit run delegate-exec.sh codex review --brief <file>hands a delegate the task as a file.devkit run prime-run.sh --brief <file> --gate <cmd>delegates a long run to Prime Agent.
Behavior changed
- A normal spec review plans one implementation-review dispatch instead of a serial contract pass plus a correctness pass.
/spec-updateloads successor and wave policy only on those routes, so a normal update pays about 1,100 tokens less.v0.26.0was tagged but its release CI failed, so it never reached the blob store; upgrading from0.25.xlands you on both ranges at once.
🚀 Features
- review — one frozen review stage instead of a serial contract pass (Spec 338) (ba676af)
- delegate — delegate-exec.sh takes the task from a file (Spec 340) (eb12d90)
- spec — review an explicit commit range, not only a branch or the tree (38a548a)
- spec — forward --base from completion to the review station (bfa405c)
- prime — gate the candidate audit on its own inputs, not on its headings (d4bb28a)
- prime — scope the candidate audit to one source repo per run (d42e4a8)
- orca — fail loudly and retry launch when Orca declines a worker (5af61e6)
- run-cost — attribute token spend to the role that spent it (7dfbb86)
- scripts — add worktree-setup.sh dependency install entry point (a0df97c)
- prime — route worktree dependency install through worktree-setup.sh (a63e664)
- wave — supervise delegated runs through Orca orchestration (fc7d7e2)
- prime — give a delegated run the canon, one terminal, and a linted skill tree (d9c9dfe)
- prime — run a delegated task in an Orca-managed worktree (70dbed6)
- prime — give a delegated run a visible Orca tab (479938c)
- prime — delegate long autonomous work to a throwaway worktree (92bf7bd)
- review — gate Spec Mode on the contract before buying a fan-out (Spec 336) (3136b89)
- review — bind the one-pass rule in the reviewer bodies (Spec 336) (260d5e0)
- release — harden pipeline security, reproducibility, and CI docs bu (7aa4035)
- core — automate wave contract reapproval, add review blocking-bar spec (Spec 334, 336) (24da1fa)
- wave — auto-approve contract escalations, drain inbox via sweep (Spec 334) (b193a01)
- spec — derive the gate recommendation from the candidate (12e727a)
- spec — reversibility vetoes the spec route, two triggers remain (8bc197a)
- gates — a bare --accept must name what it accepts (Spec 335) (a350de1)
- content-budget — count tokens instead of estimating them (Spec 328) (Spec 328) (8d8dd80)
- permissions — ship the wave permission rules instead of only naming them (a060738)
- hooks — load the debug protocol at the symptom, name the denial's real cause (Issue 21) (95cc7ec)
- spec — an acceptance criterion declares how it is proven (Spec 331) (Spec 331, 330) (0106e91)
- devkit-pipeline-benchmark — measure one spec run under controlled conditions (473c299)
- delegate — report prompt size on every dispatch, relax spec split g (544ec7d)
- wave — start a slice with one call instead of two (Spec 324) (6f726af)
- reference-scan — separate the accepted backlog from committed work (d92fd8e)
- reuse-guard — detect copied blocks, not just repeated symbols (Spec 321) (447c3bf)
- pen-design — seed the canvas from the project tokens and name the route (Spec 329) (19bbc11)
- agents — make the codegraph the first lookup, not an option (Spec 319) (20d190d)
- devkit — add codegraph-first hook, tool review docs, and three new (Spec 321) (472c489)
- pen-design — make live import the default route for existing sections too (8b16585)
- pen-design — make the mobile frame a mandatory deliverable (ba4dd35)
- pen-design — import the live page instead of describing it (a5a844a)
- skills — extend pen-design with a file convention and task templates (634ea91)
- skills — put pen-design under version control (Spec 314) (047ed6d)
🐛 Fixes
- scripts — keep the diff when a prime run dies on its gate budget (Spec 340) (ed0ac5b)
- scripts — hand shfmt only the shell files a prime run touched (c78dbcb)
- prime — reject a delegated audit that answers the gate instead of the question (c0f72dd)
- ci — install uvx from the pinned uv archive instead of aliasing it (aab12f7)
- ci — let the tokenizer fallback name its cause, probe it before the suite (523a2f5)
- ci — give the runner the pinned tools the suite measures against (323dad8)
- trial — make the loop-until-dry rule refuse an early verdict (7d33acf)
- prime — raise the autonomous limits a flaky gate spends in one run (dd2f915)
- review — require independent contract receipt before reuse/completio (8a1d653)
- review — close two ways the new contract gate could be bypassed (033af5c)
- prime — use Orca-detect resolver and supported Codex flags in Prime (ce7250a)
- prime — run the repo setup hooks in a delegated worktree (ecb094b)
- prime — judge a silent provider only when assistant turns exist (9c10d33)
- prime — treat a silent provider as a failure, and let a run pick its model (6c958b8)
- prime — wait for an Orca worktree to be populated before starting (3e53a10)
- prime — close eight hazards the delegate found in its own wrapper (d025cc6)
- skills — repair the wiring 45 skills were audited against (1fe6de7)
- review — close six paths where a failure read as a pass (e40446e)
- tooling — close six wiring defects the audit found (d28b337)
- tests — let the rm guard clear ignored scratch inside the checkout (c5e6960)
- hooks — tighten telemetry payload validation and stop-gate matching (Spec 336) (56a19b9)
- spec — name what the review waiver gives up, at the gate (bc4e137)
- spec — make the review waiver enforceable and close the panel findings (223a163)
- brief-gate — count the checks a brief owes, not just its files (4a47d04)
- tests — the two hooks from Issue 21 never reached the codex hook counts (4898574)
- gates — five gates that could not report what they were built to catch (13df976)
- statusline — warn against the point auto-compaction actually fires (066a216)
- gates — close the four gaps a green run was hiding (Spec 330) (8c1ec74)
- wave — keep the new slice-dispatch coverage inside the gates it has to pass (bf36f4e)
- spec — uncomment the Behavioral Delta heading in the light skeleton (e360745)
- wave — say what actually ran instead of reporting a green it never saw (Spec 320) (b4fde4a)
- wave — resolve spec files through padded ID prefixes (10a2d94)
- spec — renumber pen-design spec from 314 to 329 (Spec 314) (6b5bad7)
- delegate-exec — treat unconfigured panel members as skipped, not fai (c2c0ae6)
- reference-scan — stop rejections from swallowing our own capability (3264809)
- pen-design — live import brings the real webfonts along (1ff1ade)
- pen-design — split the CLI document out and switch the import route to execute (dad4336)
- pen-design — the CLI agent cannot import, and imports need a viewport (d098781)
- pen-design — design sources in a visible folder (a84464b)
- index — derive the codegraph candidate gate from the parser extension list (Spec 311) (0ad06a1)
⚡ Performance
- spec — stop buying a contract review an implementation-only fix cannot need (60f7cf5)
- spec — split completion validity out of the full review report (d2d4074)
- spec — let a followups receipt complete its own reviewed SHA (baa7858)
- tests — split project-migration, the suite that alone set the wall clock (cac1fe1)
- validate — one frontmatter pass per file, one routing table per validate (d20fc39)
- tools — one apt simulation for every package, not one per package (7f937dd)
- sync — stop asking the filesystem what a symlink already answers (36445f7)
- runtime — read the readiness verdict once per process, not five times (6e0d2bf)
- tests,hooks — the reuse guard's watchdog was a floor, not a ceiling (e6255e0)
- wave — a plan reads open specs, a slice starts in one call (Spec 324) (f078373)
- spec — fast-path completed specs in --plan, prep script polish (Spec 330) (2927d6f)
- spec — one authoring round, no carry-forward machinery (Spec 330) (Spec 330) (33c73aa)
- spec — scope the authoring review to the gates nothing else carries (39f82fe)
♻️ Refactoring
- spec-update — load successor and wave policy only on their routes (76b613d)
📖 Documentation
- spec — mark the 338 completion round superseded, claim no receipt (Spec 338) (5ea0f2f)
- audit — two independent designs for a shorter spec workflow (b6083ce)
- audit — correct two workflow-cost findings against the shipped code (bdd6bae)
- audit — measure where Flow 1 and Flow 2 lose duration and tokens (0217e9e)
- audit — audit the 79 open candidates from compound-engineering-plugin (5c77c73)
- changelog — record what landed, and drop three flags nothing implements (c8614ac)
- spec — answer the cost question with what is measurable and what is not (Spec 336) (6235dda)
- agents — re-derive every role verdict against the three-stage gate (feba64b)
- agents — name what a dispatch buys now that Main runs on frontier models (282827f)
- changelog — bring both Unreleased blocks to the full 72-commit range (Spec 328) (3f0c1b3)
- changelog — correct the bullet format and three wrong spec owners (a4f65ae)
- pen-design — put the brief templates and the prompt example into English (7561bf5)
- changelog — bring both Unreleased blocks up to the full range (a862d64)
- devkit-pipeline-benchmark — add power/gap self-diagnosis to benchma (9f2a24d)
- context-bundles — drop the restated pristine-guard paragraph (8f7caba)
- triage — re-decide the route when a run crosses a trigger it started without (fd21223)
- reference-scan — model comparisons as interventions, not artifacts (3efed0a)
- rules — treat foreign session files as unowned work, not ownership (eef66a8)
- pen-design — add a sort prefix and layer order to the grid convention (d48cd4b)
- pen-design — move phase 0.5 to a project file (394f0e4)
- changelog — record the codegraph gate fix and trial verdicts under Unreleased (536c098)
- spec — 314 - Pen.app als einzige Design-Oberflaeche (43251c8)
🧪 Tests
- rm-guard — add coverage for rm-guard boundaries and runner completi (21e85ae)
- release — the artifact may carry only tracked payload (9c21ad1)
🏗️ Chores
- spec — complete 338 and 340 (b5e8d0f)
- 340 — delegate-exec.sh takes the task from a file, not only from argv (8a03bd8)
- 338 — merge the execution contract review into correctness review (f8fdd7b)
- spec — mark spec 336 completed, move to specs/completed/ (Spec 336) (7c75235)
- 335 — mark bare --accept refusal spec in-progress (5ff0b84)
- 334 — a wave never waits on the human (07ea511)
- 335 — a bare --accept stops certifying reviews nobody did (e4898eb)
- reference — close the artifact-exclusion row against 9c21ad1 (eca11f4)
- tests — refresh SUITE_SECONDS from a measured run, all 64 suites (e4a9fa7)
- tests — shfmt tests/reuse-detect.sh (ea57ba2)
- spec-328 — pinned local tokenizer as the budget gate's unit (Spec 328) (17dc752)
- bench,reuse-detect,spec-328 — mark wallclock invalid under concurr (Spec 328) (f778cec)
- core — commit the working tree so a dev-sync build can contain it (Spec 328) (900dfad)
- gates — the last raw sandbox, and two hook messages recorded as exceptions (2905163)
- gates — record the benchmark record line and put the parity test in a sandbox (5d5d2a1)
- spec — shfmt the spec-331 changes and accept the benchmark trigger phrases (Spec 331) (23063db)
- tests — shfmt hook.sh and reference-scan.sh (8a1376b)
- reference — backtest the four largest scans under the chain unit (9acf4e3)
- tests — shfmt hook.sh and reuse-detect.sh (4d2f269)
- reference — record the Glean and Serena tool-trial verdicts (5fda246)
No commit type
- Revert "feat(spec): review an explicit commit range" and its forwarding (e8883f3)
- Reconcile spec 336 receipt-verdict wiring and shell fixes across gates (2de2bac)
- Add codegraph-first PreToolUse hook plus manifest-tracked skip reasons, (7c1d168)
- Rework spec 314: seed canvas tokens and gate the repair phase (c59dddb)
v0.25.0 — 2026-08-20
Leaner everywhere it counts: ~2100 tokens off every subagent dispatch, a review package that carries each changed hunk once, and coordinator reads that arrive filtered. Update with devkit sync.
61 commits since v0.24.0 · Specs 301, 306, 309, 310, 311, 312, 313, 314, 316, 317, 318
✨ Highlights
⚡ Every dispatch got ~2100 tokens lighter
The debugging protocol moved into a cold debugging.md and mcp-mutation-verify became path-scoped, so a subagent loads them only when its files call for it. The always-on context drops from 24,760 to 3,166 bytes.
♻️ The review package stopped duplicating itself
Specialist evidence moved into per-role evidence-<role>.diff slices, and reviewers now get the call sites of every changed symbol instead of re-deriving them.
devkit run review-prep.sh # one copy per hunk, plus a Call Sites sectionWhat changed for you
Now available
devkit run reuse-detect.sh --changed-siteslists the call sites of every function a diff touched, capped and with explicit refusal rows./workspacenow carries the author-only route;/umbrella-specis gone as a separate skill.
Behavior changed
- A review receipt missing a role your diff's signals demand no longer counts as reusable.
- Wave teardown reports success only after reading back that the worktree is really gone.
Action required
- Stack lenses install per detected stack now — run
/indexin a project whose lens set should change.
🚀 Features
- spec-work — fail a brief that hands an implementer more than five files (Spec 317) (437e9fb)
- sync — install the stack lenses per project instead of globally (Spec 314) (760b70f)
- spec — block review reuse when the receipt misses a signalled role (Spec 313, 310) (29fc19e)
- review — hand reviewers the call sites of every changed symbol (Spec 311) (4d224a0)
- wave — prove the worktree is gone before teardown reports success (Spec 309) (9d4bacb)
- release — show and pin the announcement card before tagging (26914fa)
- release — announce a release in one sentence, and not at all for a patch (5b64500)
- wave — install slice dependencies before the gate, not after the block (05a9131)
- hooks — name /index once the context manifest has aged (481918b)
🐛 Fixes
- wave — stop the brief from restating the channel Orca already injects (8a8fb20)
- test-prep — print the raw tail only when the failure filter is thin (38ddb64)
- rules — bring skill-editing.md back under its 2500-token budget (03ebcf3)
- wave — read the inbox the coordinator actually receives questions on (c391f87)
- spec — stop procedural review blocks from PASS hints and stale branches (1b727f0)
- agents — stop the implementer preamble from eating the turn budget (Spec 301) (aa6152f)
- docs — move three v0.24.0 fix bullets out of the page header (869f38e)
- scripts — restore the branch in a bare repo, distrust a handle-less terminal list (4ee052d)
- tools — let brew's own no-such-formula verdict count as reachable (acabed4)
- tools — stop drift-check's skip from reading as a passed gate (bc8c87c)
⚡ Performance
- wave — read orca output pre-filtered instead of whole into context (Spec 318) (0fc9d91)
- review — carry every changed hunk in the package exactly once (Spec 312) (05d3342)
- scripts — shrink the two oversized --help surfaces (4c28529)
- agents — raise implementer turn budget, per-step handoff, spec-update effort high (d186e45)
♻️ Refactoring
- context — split DECISIONS.md into a bounded core plus an archive (Spec 316) (a730945)
- skills — fold umbrella-spec into workspace as its author-only route (Spec 313) (275b5df)
- agents — replace implementer stack table with the routing pointer (2798377)
- hooks — move the 14.7k-char hooks.json rationale to docs (4a99178)
- skills — demote four zero-use skills to user-only invocation (4e70bb1)
- skills — cap Trigger lists at two phrases across all descriptions (52a5103)
- rules — cut ~2100 tokens from the per-dispatch always-on payload (d5cd5d1)
- spec — cut both spec artifacts back under their token budgets (b84086d)
📖 Documentation
- changelog — record the wave's last four results under Unreleased (d4771e3)
- changelog — fill Unreleased with the token-efficiency batch, fence the hooks rationale (f914d98)
- backlog — close six rows landed as specs 314-318 or direct fixes (33fb7df)
- spec — add spec 318 — wave coordination reads filtered JSON only (Spec 318) (1a487f9)
- spec — add specs 316 and 317 — DECISIONS archive split, brief size gate (87fb4db)
- gotchas — silent-on-pass budget gate cannot back a headroom figure (9783242)
- spec — add spec 314 — stack lenses install per detected stack (Spec 314) (6a486c1)
- backlog — drop the VISION-digest entry per user decision (6b541b0)
- context — capture the unsatisfiable label-grep AC as a critical gotcha (ea7bf43)
- backlog — scope the VISION cold-load entry to the maintainer repo (d9b6fdc)
- spec — add spec 313 — merge umbrella-spec into workspace (Spec 313) (72c204c)
- spec — add spec 312 — review package stops duplicating diff content (Spec 312) (e69ffd8)
- changelog — fill Unreleased and close the four drifted prose pages (18c6590)
- spec — add spec 311 — call sites of changed symbols in the review package (Spec 311) (918bf23)
- changelog — record the implementer turn-budget fix under Unreleased (2f0a897)
- spec — add spec 306 — universal skill sources (Spec 306) (e9b238f)
- repo — give the installer smoke a red branch and a resume, correct the env names (2ccdc43)
🧪 Tests
- wave — pin the corrected inbox rule instead of the wrong one (19a4b6d)
- release — route the drift-check sandbox through mk_sandbox (a5cfd7e)
- switches — assert the legacy env tables structurally instead of by hand (4a4c0ad)
- repo — cover the handle-less terminals payload in wave teardown (feadd78)
🏗️ Chores
- repo — retire the npx-ai-setup drift guard and follow two contract changes (Spec 314) (85165e9)
- gate — accept content-language baseline for spec 311's Call Sites strings (Spec 311) (c2d1015)
- spec — drop spec 306 — universal skill sources not needed (Spec 306) (b4d1b9c)
- backlog — measure both cost arms, close the last open row (3b33657)
- backlog — drop the impeccable hook-arming slice (8605b0a)
- backlog — close the delegate panel row, sharpen the cost-gap row (7a1ce59)
- usage — snapshot the 30-day window before it ages out (8514f0c)
- backlog — record this drain's outcomes (608187c)
No commit type
- Note: this is a commit-message generation request, not a planning task — (047f96c)
v0.24.0 — 2026-08-19
The backlog leaves the context bundle every session paid for, and /fetch-task can finally download a task's attachments. Update with devkit sync.
52 commits since v0.23.0 · Specs 147, 274, 288, 296, 298, 300, 301, 302, 303, 304, 305
✨ Highlights
📋 The backlog stops costing tokens
It moved out of .agents/context/ into devkit/backlog.md as a length-capped table with its own lint, so no session loads it any more. /capture, /backlog and the session hint follow it there.
devkit run backlog-lint.sh devkit/backlog.md📎 /fetch-task downloads attachments
The transfer sits in the script, not the skill body: the presigned URL arrives on stdin and never becomes an argument. A task directory whose ignore rule could not be placed refuses the download itself.
/fetch-task 50135 --attachmentsWhat changed for you
Now available
/fetch-task <id> --attachmentsstores a task's files beside its digest and links them from it.devkit config review-runtime codexis accepted now that eligibility comes from the runtime registry.devkit project-migratealso moves a legacyspecs/tree intodevkit/specs/.
Behavior changed
- The backlog lives in
devkit/backlog.mdnow. /spec-workdispatches a fresh implementer from the handoff note instead of resuming a spent run.- A
/waveslice resumes a timed-out question instead of stopping with an unsent answer.
Action required
- Run
devkit sync, then/backlogonce so a leftover.agents/context/BACKLOG.mdis migrated.
🚀 Features
- migrate — move a target project's specs into the devkit/ layout (Spec 305) (5f951d8)
- backlog — move the parking lot to devkit/backlog.md as a capped table (Spec 303) (1f51dbe)
- review — decide review-runtime eligibility from the registry (Spec 274, 304) (88cc067)
- reference — split the registry into a slim index plus one folder per repo (Spec 300) (0e51e27)
- rules — measure the important-if marker before adopting it (Spec 302) (2b33ca0)
- spec-work — dispatch a fresh implementer instead of resuming a spent run (Spec 301) (363f118)
- spec — allow a second consolidated question in full mode (717c8af)
- usage — per-user devkit adoption in the usage report (9bda19d)
- skills — route design-preview's upgrade path to the built-in /design (5b589f9)
🐛 Fixes
- spec — finish the 305 renumbering that its own commit left half-done (3e91a48)
- fetch-task — close the review round 2 findings on the attachment download (63afba4)
- wave — a timed-out ask keeps its question — resume it, do not stop (691c75a)
- spec — renumber the layout-migration spec to 305 (08671dd)
- wave — a slice blocks on a durable gate, never on a dying ask (e7a8a13)
- wave — inbox is not a read-only stand-in for check --run (7333e6e)
- spec — teach the reconcile kernel the headers the validator reads (Spec 300) (38de75d)
- wave — keep check and its ack out of the background poll loop (c471204)
- spec — re-derive spec 300 counts against the current registry (Spec 300) (afc3030)
- spec — renumber the conditional-relevance draft to 302 (cfe519b)
- capture — gate a gotcha on an enforcement form before writing it (d40e155)
- reference-scan — let a partial run keep the candidates it found (d3f2c63)
- reference-scan — peel an annotated tag before comparing (df3aedb)
- telemetry — honour opt-outs that were silently ignored (d13f281)
- orca — name the real cause behind an unreachable Orca runtime (81502a0)
- wave — report missing python deps as friction (c683a86)
- spec — make the split thresholds block authoring instead of warning (Spec 296) (298a793)
- tools — stop counting the telemetry allowlist as built-in wiring (c2fab61)
- tests — record the python-deps friction site in the fixture (4b9d410)
- tests — follow spec 305 into the suites it changed but never ran (Spec 305) (312393d)
- tools — drop the bash-4 associative arrays from rule-effect.sh (Spec 302) (588e661)
📖 Documentation
- drift — close the reviewed drift findings on quick-start and undertaking (1b0d070)
- rules — Bezeichner sind englisch, auch neben deutschen Daten (d241873)
- spec — commit spec 304 so a wave slice can reach it (Spec 304) (2ed0e94)
- spec — add spec 301 for migrating legacy spec layouts (Spec 301, 147) (914e80e)
- spec — give spec 300 the cut rationale its threshold now needs (Spec 300) (f70ee13)
- spec — add spec 300 for a per-repo reference layout (Spec 300) (305ccfe)
- spec — contract the fresh dispatch that replaces an unbounded resume (906b0e1)
- content-audit — check the rejected ledger before proposing a cut (bf63d09)
- brainstorm — route the writer bound through maxTurns, not a resume counter (05ebe27)
- spec — add spec 298 for conditional-relevance rule markers (Spec 298) (800f87a)
- permission baseline and devkit's MCP canon (347dffc)
- reference — record reference-scan wave results and doc-authoring cu (4abfeab)
- brainstorm — bound the implementer brief at runtime, not only at authoring (58576d4)
🧪 Tests
- wave — pin the contract that keeps a slice from dying on latency (66941df)
- spec — pin the question budget to one, two in full (5196a5c)
🏗️ Chores
- spec — reapprove spec 288 so its review fix loop can resume (Spec 288) (b27a955)
- spec — reapprove specs 300 and 302 (60e7988)
- reference — finish the watch list, 390 candidate rows (023b1d3)
- reference — scan 23 reference repos, 253 candidate rows (c9b95be)
- reference — resolve builtin-design-canvas-skill to 5b589f9 (cb69379)
- tools — bump uv, osv-scanner and python3 after changelog review (918b784)
No commit type
- add(spec): draft backlog table migration to devkit/backlog.md (b163991)
v0.23.0 — 2026-08-18
Stack lenses load themselves through native paths: frontmatter, and the telemetry reports a funnel instead of activity. Update with devkit sync.
36 commits since v0.22.1 · Specs 014, 076, 218, 225, 290, 291, 293, 294, 295, 296, 298
✨ Highlights
🎯 A stack lens loads itself
Each lens declares the files it covers, so Claude Code loads it before the edit — the hint it replaces converted at 1 of 185 sessions.
paths:
- "custom/plugins/**/*.php"
- "src/**/*.php"📊 The report answers with a denominator
gates, hints and run_od_version turn blocked runs, hook advice and version attribution into rates that name their denominator, over the last 90 days of collected sessions.
🧭 A plan states its slices
A plan carries one row per slice; the reader resolves each against the spec or commit it names.
devkit run plan-status.sh devkit/plans/005-cpo-adoption.mdWhat changed for you
Now available
devkit run plan-status.sh <plan>derives every slice state from the spec or commit its row names.- The 90-day usage report prints
Ereignisse,Hint-KonversionandGates.
Behavior changed
/specnow hands off through/clearbefore/spec-work: planning context adds nothing to implementation and spends the window the run needs.- Stack lenses route by path glob now. Codex and OpenCode lose stack-lens routing entirely — both strip a skill's frontmatter when projecting it.
- A spec no longer loses its approval when
/spec-workwrites its first Progress Log entry.
Action required
headroom0.35.0 clears CVE-2026-71554 in h2. Rundevkit sync.
🚀 Features
- fetch-task — ✨ enhance attachment handling with flags (f146451)
- telemetry — measure the funnel, and route stack lenses natively (Spec 296, 295) (9b6e9dd)
- plans — derive slice state from the specs instead of typing it (Spec 076) (d4e7843)
- plans — specs 290 and 294 for machine-readable plan slices, plus three reference scans (Spec 076, 290, 294) (cdbee19)
- tooling — per-tool consumer registry with a drift gate (spec 291) (Spec 291, 014, 218) (44efee0)
- project-migrate — close every run on one verdict, and answer it in status (e2e4046)
- grill — interview an undertaking in dependency-ordered rounds (Spec 293) (a57f213)
🐛 Fixes
- specs — put 288 back where its status says it belongs (Spec 288) (eff9cbe)
- tests — make the wave wrapper call the script instead of itself (Spec 180) (23e9852)
- release — restore shfmt formatting in release-prep.sh (23b3b14)
- spec — a Progress Log no longer voids its own approval (Spec 298) (0bdb427)
- orca — tell a broken Orca entrypoint apart from no Orca at all (39d8fe6)
- hooks — seed the theme with the custom: prefix Claude Code requires (4aa3a81)
- rules — keep the redaction pointer resolvable (94c13f8)
- hooks — read the remote-exec class from the quoted command spelling (66fbfc5)
- skill — 🐛 update attachment handling and relation completeness checks (909c34f)
⚡ Performance
- skills — move path-gated blocks behind references/ pointers (Spec 225) (250ac25)
♻️ Refactoring
- release — drop the manual core-flow smoke and its gate (6f1bd77)
- delegate — read panel HTTP token from the registry (e6da00d)
📖 Documentation
- changelog — refresh the German v0.23.0 type sections (1d73306)
- changelog — the German v0.23.0 twin (c77bcb0)
- changelog — swap the maintainer-only point for the /clear handoff (1a93f4d)
- flows — require /clear between /spec and /spec-work (d8dd851)
- changelog — give Unreleased its Highlights and pay the head budget (5d7fd71)
- changelog — bring the German Unreleased block level with the English (c7c0a4d)
- changelog — note the brief-cut rule and re-anchor three flow pages (3382f15)
- spec-work — cut a brief by files touched, not only by Steps (Spec 296) (492a001)
- changelog — record the plan reader, the lens globs and the digest fix (1321e8f)
- context — record that a new Progress Log section voids an approval (1266e59)
- release — publish the release body in German and cap the entry head (4665075)
- rules — redact before quoting the debug loop (52c66de)
- reference — record the mattpocock/skills and kunchenguid/vision scan (5465328)
🏗️ Chores
- skills — drop the superseded retro skill from the payload (94d9585)
- tools — bump fallow, ccusage, headroom and pandoc pins (6396ea2)
No commit type
- Fix test/skill wording: filter DEVKIT_EVENT lines from wave.sh assertion (78f18b7)
- Add per-spec run tracking, review-gate denominator fix, and stack-lens c (0c22b2b)
v0.22.1 — 2026-08-17
devkit no longer writes into repositories that are not its own: the agent-state hook now requires a project to be onboarded before it touches any .gitignore, so private and third-party checkouts on the same machine stay untouched. Alongside it, the troubleshooting page documents the one exclude pattern that actually works when a second Claude world runs beside devkit. Update with devkit sync.
7 commits since v0.22.0 · Specs 289
✨ Highlights
🔒 The agent-state hook stays inside devkit's own projects
Its only gate used to be "is this a git repository", so every SessionStart appended five ignore patterns plus a header comment to whatever checkout sat below your home directory — measured in a fresh sandbox carrying no .memsearch, no .codegraph and no .agents at all: six lines written, exit 0. It now requires .agents/context/index-manifest.json, the marker /index writes, and exits silently without it. The cost is deliberate: a project you never onboarded gets no ignore lines any more.
/index🌍 Running a second Claude world beside devkit
Claude Code's ancestor walk loads ~/.claude's rules into every session started under your home directory, devkit's included. claudeMdExcludes keeps them out of an unrelated world — but it matches the resolved symlink target, and a leading ~ is not expanded in the glob. Measured on one machine: with ~/.onedot-devkit/** all ten rule files still loaded; with the pattern below, zero.
{ "claudeMdExcludes": ["**/.onedot-devkit/**"] }What changed for you
Behavior changed
- The agent-state hook no longer writes into every git repository below your home directory — it now requires
.agents/context/index-manifest.json, so private and third-party checkouts on your machine stay untouched. - Linter and test-runner detection finds tooling a uv project keeps inside its own environment, so a repo with
[tool.ruff.lint]and a workinguv run ruff checkno longer reportsNO_LINTER_DETECTED. - A
/waveslice installs optional dependency extras and gets the environment its acceptance run assumes, instead of inheriting a red baseline it did not cause. - A spec written in the pre-v2 house header format is readable by the metadata kernel again, so
deps-check,review-prepand completion stop refusing it.
Action required
- A project that has never run
/indexgets no agent-state ignore lines any more. Run/indexthere once, or add.codegraph/and.memsearch/to its.gitignoreyourself. - Running devkit beside a second, unrelated Claude Code config: exclude the devkit store with
**/.onedot-devkit/**, not~/.onedot-devkit/**— a leading tilde is not expanded in the glob and silently matches nothing. See Troubleshooting.
🚀 Features
- usage — read telemetry credentials from the user's own config file (6e53b70)
🐛 Fixes
- hooks — write agent-state ignores only into devkit's own projects (9a3fa1d)
- prep — resolve the project's own linter and test runner (5994daa)
- wave — give a slice the environment its acceptance run assumes (ff2859b)
- spec — parse the legacy house header through the metadata kernel (f9d90df)
📖 Documentation
- spec — add spec 289, stop writing into foreign repositories (Spec 289) (79e0f97)
- rules — a mutation never survives the turn that made it (756bffc)
v0.22.0 — 2026-08-16
A Bash command that runs long now moves to the background by itself, /spec-verify walks you through a finished spec one plain-language test at a time, and correcting a single Step no longer unchecks a whole spec. Update with devkit sync.
68 commits since v0.21.0 · Specs 176, 259, 263, 265, 270, 274, 275, 276, 278, 283, 286, 287
✨ Highlights
⏱️ Long commands background themselves
A Bash call that runs longer than five seconds no longer holds the session until somebody presses Ctrl+B. A wired installation seeds the timeout in ~/.claude/settings.json; Claude Code applies it in the main agent only and clamps anything below 2000 ms. Your own value wins untouched, and hook-uninstall leaves the key behind.
{ "env": { "CLAUDE_CODE_AUTO_BACKGROUND_TIMEOUT_MS": "30000" } }🧪 /spec-verify — acceptance in plain language
An opt-in pass after a completed spec. It walks each user-observable change one test at a time, in prose rather than commands, and records the outcome in its own file under devkit/uat/. It changes no Status: and blocks nothing; /spec-work names it as an optional next step whenever a spec's Behavioral Delta is user-observable.
/spec-verify 265✂️ Correct one Step without reopening the spec
/spec-update gained --step-correction <N>. The kernel reports a preserve reopen policy, clears only that Step and the ACs it claims, and keeps every other box with its evidence. It refuses as step_correction_not_applicable whenever anything outside ## Steps differs, the named Step is missing, or the corrected Step's file list overlaps another still-checked Step.
/spec-update 270 --step-correction 4🔀 Legacy OD_* names keep working in the installer
Spec 286 retired the OD_* fallbacks, but install.sh and release/build.sh were deliberately left out. A set OD_ name is now adopted onto its DEVKIT_ twin, named once on stderr, and exported — so it also reaches the devkit sync child. The release build accepts either secret spelling for the signing key, so the org secret can be renamed in whichever order suits you.
OD_HOME=~/devkit curl -fsSL https://devkit.one-dot.io/install.sh | bashWhat changed for you
Now available
/spec-verify <ID>runs a conversational acceptance pass over a completed spec and records it underdevkit/uat/./spec-update <ID> --step-correction <N>corrects one Step's instruction without unchecking the rest of the spec.devkit config review-runtime <name>picks which model runs the/reviewfan-out; no runtime is review-eligible yet, so every name falls back toclaudewith a stated reason.- The docs drift check now answers which prose pages a file list affects before work starts.
devkit run wave-prep.sh baseline <worktree>measures a wave's red baseline and saysWAVE_BASELINE_INCOMPLETEinstead of passing an aborted run off as clean.
Behavior changed
- A Bash command over five seconds backgrounds itself; set
CLAUDE_CODE_AUTO_BACKGROUND_TIMEOUT_MSyourself if that is too eager. - Lint findings now carry up to three marked source excerpts, so a finding can be acted on without reading the file back first.
/specchecks a candidate against every open spec for a name and file-list collision before the approval gate, and prints aKollisionen:line per shared file.- Legacy
OD_*names ininstall.shandrelease/build.share adopted with one stderr line instead of being read through a silent chained fallback. - The spec count in the status line survives working in a subdirectory, and a wave refuses a worktree carrying both
specs/anddevkit/specs/. - On Linux the Orca CLI is resolved through one shared order and proven by a parseable
status --json, so the GNOME screen reader can no longer answer for it.
Action required
- Nothing. Every rename in this release keeps its legacy spelling working and says so once on stderr.
🚀 Features
- install — Adopt legacy OD_* env names instead of dropping them (Spec 286) (89ec094)
- hooks — Background a Bash run past five seconds automatically (a1c0420)
- spec — Record which authoring gate failed (93b3787)
- spec — Cross-spec collision preflight before approval (298b613)
- review — Resolver for the review runtime, with no runtime eligible (d86e371)
- doctor — Verify the file mode of project credential files (5f1d1e4)
- telemetry — Per-tool payload attribution (a5601d8)
- core — Reintegrate slice wave-281-delegate-panel (d338268)
- core — Reintegrate slice wave-279-rule-effect (ec0f5c6)
- wave — See a worker turn that simply ended, not just one that died (Spec 274) (af7c59b)
- docs-drift — Answer which pages a file list drags in, before the work (Spec 274) (4866256)
- devkit — Enforce built-in-skill wiring and add three groundwork spe (681f882)
- changelog-skill — Let a correction land in the run that found it (a34374f)
- hooks — Give lint findings the code they are about (a864a2b)
- wave — Add baseline measurement and spec-presence preflight check (Spec 278) (bc4a188)
- hooks — Name a clean session cut when nothing is left open (640d266)
- release — Publish release pages from the changelog and announce them in Slack (951ea15)
- spec-verify — Add opt-in conversational UAT after a completed spec (3970f55)
- spec — Correct one Step without unchecking the whole spec (Spec 263, 270) (70684e6)
🐛 Fixes
- wave — Follow spec 286 and name the idle window DEVKIT_, not OD_ (Spec 286) (a0e57ea)
- hooks — Survive the session-close scan on macOS system bash (2b2743b)
- wave — Fold the dead-turn verdict into the call the round already makes (Spec 176) (7f76ff3)
- wave — Make the missing-permissions finding the user's, not the agent's (0540af0)
- rules — Drop the task-list premise from the compact-response rules (171c729)
- wave — Make a run report the state it actually established (Spec 275) (a0d4291)
- wave — Detect torn-down terminal missing from list, not just ptyKill (1628db7)
- usage — Count a slash command by its turn, not by its line start (447a4b3)
- sync — Build the symlink journal outside the recovery glob (d3d683f)
- telemetry — Keep the realistic fixture, drop the anchor assertion (f887c5c)
- spec — Renumber the orca-cli spec off the colliding ID 259 (1fd663d)
- telemetry — Model the slash fixture as separate user messages (37239e7)
- tools — Honour the OD_ fallback in the release-base seam (4a9f51f)
- orca — Resolve one Orca CLI binary for every caller (3c2efb9)
- spec — Renumber the Orca-resolution spec off the colliding ID 259 (1b8abb7)
- usage — Count every typed slash command, not only the first line (c1302d0)
- specs — Bind spec-layout detection to the repository root (2c53814)
- tools — Resolve tool-pin upstream without a local package manager (d0f36b6)
- usage — Stop counting pasted paths as typed slash commands (81476a1)
- tests — Stop the suites reading the developer's PATH (Spec 263) (ec059b4)
♻️ Refactoring
- runtime — Drop the legacy OD_ fallback arm (a7bf001)
📖 Documentation
- changelog — Give v0.21.0 the lead line its release card needs (f1a4a53)
- changelog — Record the six unreleased items that were still missing (df48eca)
- specs — Spec 287 — adopt legacy env names instead of dropping them (Spec 287, 286) (84335e2)
- specs — Correct spec 274 to ship no runtime adapter, add spec 283 (Spec 274, 283) (32c8a63)
- wave — Put the branch-only worktree paths behind a reference (54a3a61)
- wave — Route coordinator decisions through gates, not a racing ask (Spec 274) (df3aaf4)
- reference — Record five scans and tighten the coverage evidence rule (a2fd5c2)
- backlog — Park the delegate panel mode before implementation (Spec 276) (8708203)
- spec — Add specs for review runtime resolver and delegate panel mod (Spec 274, 276) (134a9b9)
- reference — Measure the completions endpoint on real classification payloads (b8a9132)
- rules — State that a key belongs to a person, not to the payload (11f544a)
- reference — Record the Hetzner inference API trial (e3d404e)
- spec — Commit spec 276 so the wave slice can read its contract (Spec 276) (fa684d1)
- spec — Add spec 259 for Orca CLI resolution on Linux (Spec 259) (6927149)
- backlog — Park the three review residuals from specs 269 and 273 (b3bafa0)
- changelog — Record the 265 and 270 entries, wire the spec-verify hint (Spec 270, 265) (a0b886c)
- core — Record the destructive-restore trap and the 263 changelog entry (Spec 263) (158667d)
🏗️ Chores
- specs — Commit spec 283, untouched for eight hours (Spec 283) (4702e9f)
- specs — Commit two specs a parallel session left untracked (0ab8616)
- registry — Record the idle friction codes and the elision kill-switch (fc3597a)
- specs — Free the taken 278 id so the lifecycle scripts run again (82a4dee)
- specs — Renumber the delegate panel spec off a taken id, again (619b425)
- ledger — Record where the todo-tools verdict landed (8eee3aa)
- specs — Renumber the delegate panel spec off a taken id (70d8851)
- tools — Pin fallow 3.16.0 (1c40ebe)
No commit type
- spec(278): mark wave run reliability as in progress (ac35531)
- spec(278): author wave run reliability contract (3d437f3)
- style(tests): restore shfmt formatting in spec-authoring (c4f5ce5)
v0.21.0 — 2026-08-14
/fetch-task pulls a CrewBuddy task straight into a spec-ready digest, skill-lint now fails a skill that uses a tool its frontmatter never granted, and /spec-work shows which reviewers a change's own signals selected. Update with devkit sync.
20 commits since v0.20.1 · Specs 148, 255, 256, 257, 258
What changed for you
Now available
/fetch-taskretrieves a CrewBuddy task and writes its digest, with the task ID validated and the fetched body handled as untrusted content.skill-lintgained a seventh check,tool_ungranted: it fails a skill whose body instructs the model to use a tool the frontmatter never granted. Three shipped skills mandatedAskUserQuestionwithout listing it, and no gate had caught any of them. Run it viadevkit run skill-lint.sh; the baseline now keys on check plus skill plus value, so an unaccepted tool can no longer ride in on an accepted sibling./spec-workStep 4 now sees aSignal reviewers:line beside the declaredReviewers:header. The signal patterns moved intoprep-lib.sh, so/reviewand the spec path derive the same roles from the same regexes — including the design signal, which had been available since spec 212 with no caller in the spec path. Nothing is dropped automatically: a header demanding more roles than the diff earns is simply visible as such.
Behavior changed
- Every subagent starts about 2930 tokens lighter.
docs/VISION.mdis no longer imported into the eagerly loaded hierarchy — it was 24 percent of the 12020 tokens paid before a subagent read its own assignment, and a reviewer or implementer never decides a cut. Maintainer decisions read it on demand and name the pillar that carried them. In the same vein, four dispatch-only sections left the always-onagents.mdfor the path-scopedagent-dispatch.md, freeing another 1688 bytes. - A later authoring or review round continues the same agent instead of paying for a cold one.
/specand/reviewnow holdSendMessage, the only tool that resumes an agent, and a later round gets the diff plus the touched gates rather than the whole candidate. Measured: 297s and 423s for cold rounds at 94k tokens, against 44.8s and one tool call for the first resumed round. - A review finding no longer lands in
/spec-updateby default. Section 0 states the criterion: only a defect in the contract itself reopens a spec — a missing or wrong requirement, an acceptance criterion pinning the wrong behaviour, a Step whose file list cannot produce it. Wrong code, a missing test or an unhandled edge case stays in the fix loop on the same handle, and uncertainty resolves to fix. That undefined branch is what produced a five-round run on a single-file skill spec. - The cross-model check in
triage.mdis a mandate rather than a conditional buried in a bullet about reviewer selection. Measured against the alternative: 20479 tokens for 12 findings, against 381687 tokens and three BLOCKED verdicts that found zero code defects. /spec-workcan stop a runaway reopen cycle:spec-resume-prepemitsreopen_cyclesfrom digest-exempt REOPENED receipts, andspec-validate-prepflags aReviewersrole beyondcode-reviewerthat has no matching## Reviewer Signalsline.- A failed
github-releasetool install is reported as a failure.chmodandmv -freturn codes were discarded, so a failed move returned 0 anddevkit syncclaimed the tool was installed with the old binary still in place. The exec probe also runs under a pure-bash watchdog on hosts with neithertimeoutnorgtimeout. - Gate 4 and gate 5 of the reviewer gate list no longer claim coverage the validator does not have: only acceptance-criterion verifies are probed, and fixtures are not checked at all — both are the reviewer's own work.
Features
- review — Share reviewer signal detection between both prep scripts
- spec — Bound reopen cycles and close the reviewer-signal gap
- skill-lint — Catch a mandate whose tool the skill was never granted
- review — Give
/reviewits resume tool and make gate 7 answerable (Spec 256) - spec — Let the reviewer be resumed instead of re-dispatched
Fixes
- tools — Stop reporting a failed github-release install as success
- reviewer — Stop the gate list claiming coverage the validator lacks
- tests — Close the three suite regressions this range introduced
- spec — Renumber the fetch-task spec off the colliding ID 259
Performance
- context — Stop importing VISION.md into every subagent
Refactoring
- rules — Move dispatch detail out of the always-on agents rule
Documentation
- spec — Define when a finding reopens a spec and mandate the round-zero check
- research — External practice for subagent context and tools
- reference — Record the OpenSpec trial verdict (Spec 255)
- spec — Add spec 258 for a gate against ungranted tools (Spec 258)
- spec — Add spec 257 for the always-on agents rule split (Specs 257, 148)
- spec — Add spec 256 for the two unexecutable mandates (Specs 256, 255)
- docs — Unbreak the docs build and close the reviewed drift markers
Chores
- fetch-task — Add the
/fetch-taskskill for CrewBuddy task retrieval - claude — Remove the leftovers from npx-ai-setup
v0.20.1 — 2026-08-13
1 commit since v0.20.0
What changed for you
Behavior changed
- The test suite no longer fails on a machine that does not have
pandoc. Both share suites treated it as a hard dependency even though devkit marks it optional, so a plaindevkit syncproduced a checkout whose own suite could not pass. They skip now instead of making a default checkout red.
Fixes
- tests — Let the suite run on a machine without the optional tools
v0.20.0 — 2026-08-13
74 commits since v0.19.0 · Specs 207, 225, 227, 229, 230, 234, 235, 237, 238, 239, 242, 250
What changed for you
Now available
/sharepublishes a Markdown or HTML file as a public Orca artifact only after a preflight it cannot skip: the skill renders the page itself with raw HTML escaped, scans exactly the bytes it will publish and refuses rather than guessing. A credential split across a line wrap passed the earlier per-line pass — measured, exit 0 withblocked:false, while the same bytes contiguous exit 2. The published page is wrapped in the ONEDOT template instead of going out as a bare pandoc page: mark, type stacks, light and dark tokens, table and callout styling, mermaid fences as inline SVG.A fresh install lands on a defined terminal theme pair and view mode instead of whatever the terminal happened to carry. The seed only fires into an empty value, so a deliberate choice is never overwritten, and a
TERM=dumb/CI guard keeps it out of non-interactive runs where a view mode has no meaning.Inside an Orca worktree the frontend check now reads console output, page errors, network requests and Core Web Vitals again.
orcaships no command for any of those, so/agent-browserreaches them throughorca exec --command "errors" --page <id>— Orca bundles its own agent-browser binary, so it is the same tool against the same tab you are looking at./agent-browsercan verify two roles in one run. An isolated Orca browser profile carries its own storage partition, so a guest view and a logged-in view no longer overwrite each other. The Shopify, Shopware and Laravel stack skills now ask for it whenever a change touches price, cart, availability or anything behind a gate — the state your own browser is already in is exactly the one you would otherwise never test.Responsive and dark screenshots come from the same browser:
orca set device --name "iPhone 16"andorca set media --color-scheme dark. Thedesign-revieweralready knew how to read both; it simply never received them. There is no reset flag —orca reloadclears the device emulation.A full Lighthouse audit is documented where the gap actually is. Neither
/agent-browsernororcascores accessibility or SEO;npx lighthousedoes, needs no install, and ships with thejqline that matters — the raw report was 222 KB of JSON for a one-element page, against 153 bytes of usable output.devkit run reuse-detect.sh --helpprints the reuse detector's interface: its flags, the TSV it returns, its exit code and the languages it actually reads. It used to exit silently, so the contract was readable only in the source./design-previewshows a UI idea as a picture before any code exists. It renders a throwaway preview from the project's own token files, screenshots it and takes one approval decision. The existing browser mandate only fires after the edit, so until now the first picture arrived once the code was already written. Local rendering is the default because it works headless, under Codex and inside wave slices; the Claude Design canvas stays the optional upgrade for attended work./friction-feedbackturns a blocked gate into an issue in the devkit repo, naming the project the complaint came from. Nothing is sent until you confirm the displayed title, body and detail. Beyond the one-line sentence it takes--where— which skill, gate or script was running — and--detail-file, a markdown file up to 6000 characters that is posted as a follow-up comment on the created issue. The first two reports through it showed why both exist: one wave run produced seven findings that had to be squeezed into 280 characters, and the maintainer got symptoms without the surface they occurred on. The detail file is screened for secrets exactly like the sentence and covered by the same confirmation hash.A delivered hook entry can declare its own
timeoutin seconds. The Codex projection has bounded every hook at 30 seconds since it was written while the Claude side left them unbounded; an entry without the field is emitted exactly as before, so no existing hook changes.A reference repo whose payload is one long file of atomic claims now has a deterministic route.
/devkit-reference-scanextracts, hashes and diffs those claims against a committed ledger, so a verdict survives into the next scan instead of the scan comparing repo metadata and leaving the claims unread.devkit skills pullfetches the stack-specific skills a project's boilerplate owns, instead of cloning the whole boilerplate repo just to copy a few project skill directories out of it. It reads the stack from.agents/context/index-manifest.json, resolves it through the new stack registry to one of the three ONEDOT boilerplates, and copies every skill devkit doesn't already ship — a name devkit ships is never overwritten, and a skill you've since edited locally is left alone unless you pass--force.--checkreports what a pull would do without writing anything./indexnow adds a one-line offline drift check on top: it compares the last pull's lockfile against the cached boilerplate clone and tells you how many pulled skills are outdated or how many new skills showed up upstream, without ever fetching over the network itself./umbrella-specauthors one requirement into one spec per touched sibling repository in a folder umbrella, plus a mapping file that carries order and nothing else. Each member spec stays independently executable, so a repo can be worked or dropped without unpicking the others.workspace-prep.shgainedumbrella-detectandumbrella-link-statusfor member detection and status.
Behavior changed
Agent state stays out of git. memsearch memory, the codegraph index and the machine-local context caches are ignored,
/commitblocks them the moment they are staged (AGENT_STATE_STAGED), and every session start ensures the five ignore lines exist in the project's.gitignore. That hook is additive only: it never untracks, it usesgit check-ignore --no-indexso a global excludes file or a broader pattern is not duplicated, and it stays silent when there is nothing to add. Measured before the fix across 31 local checkouts: 137 such files in 15 indexes, 111 already pushed. Kill switch:OD_SKIP_AGENT_STATE_IGNORE=1.Wave acceptance no longer runs a project's entire test suite when it cannot narrow it. The slice prints
WAVE_ACCEPT_TESTS_DEFERRED <reason>and stays acceptable, CI owns the full run, andOD_WAVE_ACCEPT_FULL_SUITE=1restores the old behaviour under its own marker. Measured twice on 2026-08-12: a foreign drift in the static gate reported as two green slices' own failure and parked both.A wave survives its own edge cases:
--planno longer refuses the whole graph over one unreadable spec,wave-prep.shgainsworker-probeandteardown,ensure-depsrestores the lockfiles it touched, andacceptscans for a stash entry on the slice's own branch before anything else.Only the Critical gotchas load into every session. The Reference tier moved to
.agents/context/GOTCHAS-ARCHIVE.md, which agents grep on demand — seeded into new and existing projects and named on the pointer line, never in the import list.Spec authoring probes each verify command once per run instead of once per criterion. 19% of acceptance-criteria verify commands across completed specs are exact duplicates of another criterion in the same spec, and each criterion still receives its own diagnostic.
A turn can no longer end on work the agent only announced. "I'll now write the spec." followed by silence used to leave you typing "ok" so the agent would do what it had just said it would; a Stop hook now blocks that turn and the work happens in the same turn. It reads only the last sentences, because an intent stated mid-report and then carried out is worded identically — a question, the
> Naechster Schritt:hint and a conditional offer all still end the turn normally. Kill switch:OD_SKIP_ANNOUNCE_GATE=1.A developer who cloned the repository and ran
./install.shused to keep an update source pointing at their own checkout, sodevkit syncre-read that clone and never fetched a release. A first install now configures the signed blob source; a re-run leaves whatever you configured alone, andDEVKIT_SOURCE_LOCAL=1keeps the local source for development builds.devkit doctornow warns instead of dimming when the update source is a local checkout outside~/.onedot-devkit— intended on a maintainer box, a defect anywhere else. The exit status is unchanged.A research report now carries its own source check. Every repository it names is verified against the GitHub API and marked exists or NOT FOUND, because a fabricated repo arrives with plausible file paths and code and reads exactly like a real one — three of four did in the run that prompted this. The check is silent when
ghis missing or unauthenticated, so an unverifiable claim is never dressed up as a checked one./index --design-liveno longer stops with "install agent-browser" when it runs under Orca. It routes to the worktree browser like every other browser call, and its style extraction takes the argument form there, because--stdindoes not survive the Orca passthrough.A wave slice touching frontend files now binds its verification to its own worktree tab (
orca tab list --json→--page <id>). Two slices verifying at the same time used to compete for one tab.Under Orca the login-wall chain no longer runs. The worktree tab already carries your session, so the skill skips the profile hunt, the saved-state dance and the
.envread instead of working around a wall that is not there.The reuse scan covers Python. A
.pyedit now gets the same "this already exists" warning as TypeScript, Vue and PHP, and a review classifies Python candidates instead of receiving an empty list that read as "no duplicates found".devkit doctorcompares the MCP client state against the canon in both directions. A disabled canon server is a problem with an exit code, while foreign servers and scope-less disable entries are reported as information; claude.ai connectors and plugin servers stay out of it.The MCP rule separates removal from disabling.
claude mcp removedeletes the entry, but it neither clears the per-project disable lists nor revokes the OAuth grant — that lives in the OS keychain and piles up there for servers that are long gone, so revoke at the provider instead.The code-reuse rule sends its Bash fallback through
rtk rg -n/rtk grep -rnand names the detector the way a target project can reach it,devkit run reuse-detect.sh. It also states which languages the detector reads, so an empty result elsewhere says "not covered" instead of reading as "nothing similar exists".Local development sync stops with exit 2 when a payload file is uncommitted, instead of building without it. It exports the committed tree, so an untracked or modified file was simply absent while the run still reported success — and the "already on this state" shortcut claimed current while the edits under test were missing. Commit them, or use
--worktreefor the self-edit loop. The Stop hook surfaces the failure at the next session start, so the omission is visible even if nobody read the output.The dev sync also runs when a session stops, not only when one starts, so a change made late in a session reaches the runtime without a second command.
The
/researchcommunity layer returns results again. No engine was installed and the wrapper's own--quickflag dropped the GitHub lane, so a lane that returns ten dated posts in six seconds returned none; discovery now also finds a plain clone under~/.local/share/last30days/<version>. A provider that gets skipped now says why, instead of exiting 0 with empty output.A filed friction report is triageable on arrival. Its title carries a summary of the sentence instead of reading
devkit friction: NONE, it is labelledbug, and the recorded devkit version is complete — it used to be cut at 20 characters, which dropped the commit SHA and left a partial timestamp that still looked like a valid version.A blocked gate now tells you it is worth reporting.
od_frictionalready recorded why a gate blocked, but the reason only ever reached an anonymous aggregate and your own sentence never travelled; a visible line now says so at the moment it happens.The usage report answers whether anyone actually types
/commit. Typed slash commands were collected per session and never rendered, the same regex counted/var/folderspaths as commands, and a deliberatedisable-model-invocationrefusal was booked as a skill error — two of the three signals the report leans on were wrong at the source.Editing a
.shor.phpfile now runsbash -norphp -lon it right away, so a parse error surfaces at the edit instead of at the push gate. Blade templates are skipped — their directives are inline HTML to the PHP parser, so a passing lint would prove nothing. A project-wide typecheck was deliberately left out of the same slot: it has no sound per-file mode, a project run costs 10-60s on every edit, and its errors are transient while a multi-file change is still in flight./skill-createrefuses the skill namesynced. Claude Code reserves that folder for skills downloaded from claude.ai, and a skill authored there is skipped without an error — the symlink resolves, so neitherdevkit doctornor the resolution check notices either.A wave no longer parks a slice because its test suite was starved. Ten slices each starting a full suite pushed runtimes from a 93s baseline to 425s without a single failed assertion, and acceptance still reported red. Suites now queue behind a lock in the shared git dir, the marker carries the runner's own exit code and its last 30 lines, and a busy suite is a retry for the next round instead of a park.
The setup now takes the
statusLinefield unconditionally and backs up whatever it found, verbatim and on every wire, so a choice you make between two wires survives;devkit hook-uninstallrestores it. The old no-clobber guard almost always preserved an old copy of ourselves from the predecessor setup and blocked the one thing it was meant to enable. The line itself says more in less: a short@<sha7>on a dev build, a trailing arrow when a sync is pending, and no moredefaulteffort segment./devkit-reference-scanno longer skips a reference because of its file name. The freshness gate ignores README churn so badge edits cannot trigger an expensive comparison, and the skill had turned that into a name-based exclusion which also dropped the payload of entries that compare normally — the criterion is the file tree, not the name.The spec authoring reviewer no longer re-opens every file a candidate cites. The validator already resolves those citations, so it now ships their line contents in the JSON the reviewer receives, capped at 300 characters each.
Tool pins move with the next
devkit sync: fallow to 3.15.0 and headroom to 0.34.0, the latter clearing CVEs in aiohttp and cryptography.codexis declared as the brew cask it actually is — it was declared npm, and becausenpm ls -g --parseableexits 0 with empty output for a package it does not have, the outdated check compared it against the wrong registry and reported current no matter what.
Action required
- Once per repository:
devkit project-migrate . --applytakes the agent-state files that are already tracked out of the index. Ignoring never untracks what is already committed, and the session-start hook deliberately leaves that half alone — it only names how many files are still in the index.
Features
- hooks — Ensure agent-state ignore lines at session start (Spec 237)
- share — Render shared documents into the ONEDOT artifact template (Spec 235, 227)
- umbrella-spec — ✨ add
/umbrella-speccommand for multi-repo requirements - share — Gate a document behind a scan before it becomes a public link (Spec 227)
- agent-state — Keep memsearch, codegraph and context caches out of git (Spec 237)
- skills — Pull stack skills from the boilerplate repos (Spec 234)
- terminal — Ship theme pair and seed terminal view defaults (Spec 238)
- wave — Close the five defects two reported wave runs left open
- context — Move the GOTCHAS Reference tier off the always-on path
- spec-validate — Hand the authoring reviewer its cited lines
- reference-scan — Judge a one-file claim corpus against the canon
- hook — Syntax-check bash and php files on edit
- hooks — Let a hooks.json entry carry an optional timeout
- statusline — Own the statusLine everywhere, and say more in less (Spec 230)
- reference-scan — Contract a corpus route for prose-heavy references (Spec 242)
- feedback — Tell the developer what to report when a gate blocks (Spec 229)
- specs — Settle the ONEDOT artifact template against a measured prototype (Spec 235, 227)
- hooks — Stop a turn that only announces work instead of doing it
- telemetry — Report typed slash commands and stop miscounting noise (Spec 225)
- skills — Add design-preview for pre-code visual approval
- mcp — Diff the actual client state against the canon in devkit doctor
- reuse-detect — Cover Python and document the CLI contract
- browser — Route the frontend-verify mandate through the Orca browser
Fixes
- release — Repair the four suites the release range broke
- runtime — Restore the OD_ fallback on two DEVKIT_ reads
- wave — Stop acceptance from running the whole suite it cannot narrow
- skill-create — Refuse the reserved skill name
synced - wave — Stop acceptance from reporting a starved suite as red
- feedback — Make a filed friction report triageable on arrival
- install — Give a cloned-repo install a real update source (Spec 239)
- research — Verify every repo a research report names
- research — Make the community-signal layer actually return results
- dev-sync — Stop instead of building a payload that omits the change
- dev-sync — Say when a HEAD build omits uncommitted payload files
Performance
- spec-validate — Probe each verify command once per run
Docs
- changelog — Close the thirteen uncovered commits since the 56-commit sync
- spec — Reissue 227 after the wrap-split and CSP review findings
- changelog — Close the eight uncovered commits since the 23-commit sync
- spec — Contract the wave accept fallback off the full suite
- changelog — Close the 23 uncovered commits since the impeccable verdict
- spec — Contract the probe dedupe and record the savings research (Spec 250)
- spec — Add the approved contracts for specs 246 and 247
- spec-235 — Render through spec 227's gate instead of before it (Spec 235, 227)
- context — Mark the hook timeout contract as landed
- quick-start — Clarify default source config after install
- context — Re-cut the impeccable rollout into three contracts
- context — Record why the impeccable distribution spec was rejected
- spec-235 — Keep the markdown source, treat the rendered page as disposable (Spec 235)
- reference — Record the human verdict on the detector's findings
- context — Park the impeccable adoption decision in the backlog
- context — Record two traps from the impeccable trial
- reference — Add nine watch entries from the community practice index
- spec — Point spec 230 at no branch instead of a deleted one (Spec 230)
- reference — Record the impeccable trial verdict (Spec 207)
- changelog — Close the seven uncovered commits and resync the German page
- changelog — Record the announce gate and the research source check
- specs — Add approved specs 225, 227, 229 and 230
- changelog — Cover the research fix and the dev-sync hard stop
- changelog — Record the dev-sync fix and the Stop-hook dev loop
- changelog — Close the two uncovered commits and the MCP removal case
- changelog — Record the reuse-detect, doctor and rule changes
- rules — Route the code-reuse scan through rtk and devkit run
- changelog — Record the Orca browser routing under Unreleased
Chore
- devkit — Sync changelog checkpoint to 2.1.229
- tools — Repair pin-audit provenance and bump the tools it was hiding
- reference — Record the 2.1.227-2.1.228 changelog scan
- settings — Allow this repo's own gates and read-only inspection
- dev-loop — Run the dev sync on Stop as well, not only at session start
Style
- tests — Format feedback.sh so the static gate can run
WIP
- spec-227 — Implementation state before the contract reissue (Spec 227)
No commit type
- Update
- Update
- update
- update
v0.19.0 — 2026-08-10
46 commits since v0.18.0 · Specs 206, 207, 208, 211, 212, 213, 214, 215, 217, 218, 219
What changed for you
Now available
/backlogdrains a parking lot for findings that turn up while you are working on something else./capturegainedBacklogas a seventh target, and a SessionStart hint tells you when something is waiting — so a finding neither derails the current task nor gets lost.- The design-slop check decides the four AI-slop tells a single line can settle — gradient text, the side-stripe card,
transition-allandhover:scale-. It accepts a file or directory, exits 1 on a hit, and exits 2 on an unknown pattern name. A project suppresses a false positive in.agents/context/design-slop-ignore.txt, not inDESIGN.md, which/indexrefills and would drop the exception on the next run. - A
design-reviewerrole joins a review by itself whenever the changed files carry a frontend extension. It reads only, and it gets its own evidence section carrying the filtered diff plus the detector's output — so a design finding rests on the same kind of evidence as a correctness one. The remaining anti-patterns stay a reviewer lens, because they need judgment across several lines or the rendered page. /index --design-live [url]fillsDESIGN.mdfrom the token sources a running stack actually uses, rather than from what the repo declares. Run it after the static/indexwhen the page and the document have drifted apart.devkit syncfinishes on Linux without Homebrew. Every tool that used to be brew-only now carries a second path —aptwhere the distribution ships it, otherwise a version-pinned GitHub release whose payload is checked against a hash committed in this repo, not one fetched from the same release.
Behavior changed
- The
rtkandcodegraphrows in the tooling rules now describe what those tools actually ship:rtkpoints at its own--helpinstead of pretending to list 8 of over 80 subcommands, andcodegraphnamesaffected,syncandunlock— the last being the only documented way out of a stale index lock. A new check refuses a tool row that names an agent which has no shell to run the tool with. - A wave now measures the red baseline once, at the base commit, and every slice brief carries it verbatim. What fails there is never the slice's to fix; anything beyond it is. Until now each slice rediscovered the same pre-existing failures as its own.
- The wave dependency check works on the closure that actually matters, so one broken foreign spec no longer blocks every parallel slice, and the preflight reports the facts a non-Node repo needs instead of Node facts it has no use for.
- The run-cost report counts a message as a subagent resume only when this run dispatched that address itself. Since Claude Code 2.1.224 the same tool also carries notes to parallel sessions, and counting those turned a token total into a claimed upper bound.
fallowpins its audit base the same way the review package does, so a review and its findings can no longer attribute against different commits. A "no callers" claim now names its prover —dead-code --trace, run by the main loop, since a reviewer has no shell.- Authoring a spec now rejects an acceptance criterion whose verify command can never go red — one whose negation never fires. Such a criterion passes before the work exists and proves nothing, and until now nothing stopped it from reaching approval.
devkit project-migrate <root> --applynow warns withPROJECT_LEGACY_DIRTY_TREEbefore it writes into the project Claude settings file that carries an uncommitted edit. Until now that warning existed only under--force, and since the run no longer leaves a recovery backup, such an edit had no way back. The exit code is unchanged — this is a signal, not a block.settings.local.jsonstays out of it: it is gitignored, so a git status check can say nothing about it.- The same run now purges the recovery transaction it created instead of leaving it behind, so a migration no longer grows a directory nobody reads back.
- Every
devkit project-migraterun appends to~/.onedot-devkit/project-migrate.log: a header line with version, mode and checkout, one line perPROJECT_*marker including the ones that stopped the run, and a closing line with the outcome of each phase. The warnings that matter most — a dangling reference, a skipped file, a retained backup — used to scroll past in a long run and were afterwards provable nowhere. The log is best-effort and never fails a migration; it is also never created, so a project-migrate run without a devkit installation still touches nothing outside the checkout. /wavedrives Orca's own supervised worker loop instead of rebuilding one: a bound run, a task per slice, andworker_doneas the completion authority. A slice that goes quiet is now distinguishable from one that failed./spec-worknow dispatches a long verification alongside the review instead of ahead of it, so a slow gate no longer holds the reviewer back./devkit-retroruns the cross-model check first and then fixes what it finds, rather than reporting it for later.reuse-detectunions the codegraph and ripgrep candidate sets and widens its glob to the whole language family, so a helper that already exists is found even when the graph misses it.- A wired installation now pins
env.CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTHto1in the personal Claude settings, so a subagent can no longer spawn subagents of its own. Claude Code raised that default to 3 in 2.1.219, and no agent this setup ships carries the Agent tool — nesting could therefore only ever happen unasked, on the built-in roles. Your own value wins untouched, andhook-uninstallleaves the key behind.
Action required
- Nothing in this range requires action in a target project. If you rely on
project-migrateleaving a recovery backup, stop — it is gone by design, and the new dirty-tree warning is what replaces it.
Features
- tooling — tool rows describe the surface the tools actually ship (Spec 218)
- wave — measure the red baseline once, not once per slice
- tools — devkit sync completes on Linux without Homebrew (Spec 214)
- wave — scope the dependency check and make the preflight stack-aware (Spec 219)
- backlog — a parking lot for findings that surface mid-work (Spec 215)
- fallow — pin the audit base and name the dead-code prover (Spec 217)
- hooks — turn subagent nesting off by default
- spec-work — run long verification beside the review, not before it
- spec-validate — reject a verify command whose negation never fires (Spec 214)
- project-migrate — warn before writing into an uncommitted settings.json (Spec 208, 213)
- review — add a design reviewer that fires on a frontend signal (Spec 212)
- design — detect the four line-decidable AI-slop tells (Spec 211)
- project-migrate — purge the recovery transaction the run created (Spec 208)
- design-fill — fill DESIGN.md from the real token sources of a running stack (Spec 207)
- retro,triage — make the cross-model check run first and the retro fix what it finds (Spec 208)
- spec — 208 — project-migrate leaves no recovery backup behind
- project-migrate — persist every run marker to a migration log
- wave — drive Orca's supervised worker loop instead of rebuilding it (Spec 206)
Fixes
- tests — stop two fixtures from depending on the host they run on
- tools — screen archive links by type instead of parsing tar's prose
- tools — count only subagent resumes in the run-cost report
- tools — give the four new DEVKIT_ sites their OD_ fallback
- (none) — restore the OD_ fallback chain and the last stale Codex hook count (Spec 215)
- tests — update the Codex hook and agent counts the last two changes moved (Spec 215)
- (none) — repair three assertions the last few commits left stale (Spec 215)
- tests — stop a failing smoke assertion from killing the whole suite
- agents — list design-reviewer in the routing table (Spec 212)
- reuse-detect — union codegraph and rg candidates, widen glob to language family
Docs
- specs — complete spec 214 after acceptance on the real Linux host (Spec 214)
- changelog — carry the unreleased range to 42 commits
- specs — let spec 214's step verifications run at the project's severity (Spec 214)
- specs — record spec 214's verification pass against the committed code (Spec 214)
- specs — repair the four verify commands spec 214 could never run (Spec 214)
- reference — record what the cross-session messaging test measured
- flows — close three reviewed docs-source findings (Spec 215)
- spec-215 — record the authorized docs/flows/knowledge.md edit in the file list (Spec 215)
- changelog — carry the unreleased range to 22 commits
- specs — add approved specs 215, 217, 218 and 219
- changelog — extend the unreleased range and document background verification
- changelog — document unreleased range and signal review roles
- reference — record the docs-mcp-server trial verdict
- spec — 214 — devkit sync completes on Linux without Homebrew
- context — capture two traps found while auditing the global setup
- spec-work — treat an empty reviewer return as not_reviewed
- spec — add specs 207, 211, 212, 213
- (none) — retro consequences for spec 208, wave sweep friction marker, spec (Spec 208)
v0.18.0 — 2026-08-09
31 commits since v0.17.0 · Specs 147, 201, 202, 203, 204, 205
What changed for you
Now available
/workspacecoordinates one undertaking across a folder of sibling repositories that has no git of its own: one frozen contract, one committed spec per repository, and each repository's own/waverunning as a real agent worker under a single Orca run. A single repository stays on/wave— this is for the case where the work genuinely spans several./failure-learnmines your past transcripts read-only for tool-call mistakes that keep recurring, and hands the result to/capturefor writing. It writes nothing itself.headroom audit-readssizes how much of your context budget goes to Read waste, andheadroom learn --verbosityderives an answer-length level from your actual interrupts instead of guessing. Both now have a routing line, so they get reached for rather than merely installed./devkit-tool-trialdecides adoption of an external tool by running it: pinned install behind a config snapshot, every surface enumerated mechanically, and a verdict carrying two arms — how much it moves and whether the output is actually better.
Behavior changed
- A spec Step that declares no acceptance criteria now fails
--strict-authoringinstead of merely warning. The gap could previously ride all the way into a completed, digest-bound spec, where repairing it would void the approval — so the only point at which the contract is still editable is where it is now caught. - An acceptance criterion whose verify command only text-searches a markdown file is now reported as an advisory warning. Searching for a string proves the string is present, never that the behaviour is. It warns rather than blocks, because only the command shape is provable from outside.
devkit syncno longer leaves you with a tool that reports success and stays broken. When an installer finishes cleanly but an older binary earlier in PATH keeps serving the name, the correctly pinned binary is symlinked into devkit's own bin directory; only if that link still loses does the run fail — and then it names the shadowing path and the version it found.devkit project-migrate --applynow tells you when it broke something. A deleted file whose path is still wired somewhere — a.husky/pre-pushcalling a removed script, a CI step naming a removed hook — is reported asPROJECT_LEGACY_DANGLINGwith both the deleted path and the file that still points at it. Until now the run looked clean and the breakage surfaced on the nextgit push.- The
PROJECT_NPX_DRIFTEDlines are trustworthy again. They used to be printed before the manifest phase ran, so a file the same run went on to delete was still announced as kept, and a project's ownscripts/oragents/directory was flagged just for sharing a name with a template directory. Drift is now reported after every delete pass, only for paths still on disk, and only under the Claude, Codex and RTK configuration trees. /wavefinds the slice specs in a repository that uses thedevkit/specslayout. Every sweep and stalled row returnedWAVE_SWEEP_USAGEthere, because the coordinator's own spec directory never reaches a foreign worktree; both layouts are now resolved against the worktree itself.- The run-cost retro finds your spec files again in a project on the
devkit/specslayout. It looked for them under a hardcodedspecs/, found nothing, and therefore reported every slice asROUTE_UNRECORDED— a flag that reads as "the review this route owed was never triggered" while the actual cause was the lookup. devkit run verbosity-prep.shnow also printsVERBOSITY_LONGWORD_TOP, the five long prose words you repeat most, with code fences, inline code and URLs stripped first. It is report-only and gates nothing — the character budget stays the only threshold.- An external candidate is now judged on what it does to the work, not on how well it fits what we already wrote. Adoption is the default, building it ourselves carries the burden of proof, and a collision with one of our own rules prices the migration instead of ending the discussion. Ownership and version pinning are unchanged.
- Every token figure
run-cost.shreports is summed from transcript entries rather than read from a provider-reported field, and it now says so. Two measured traps make that load-bearing: the.usageblock describes the last turn rather than the run, and a budget-capped run reports itself as cleanly completed in every documented field.
Action required
- If you keep a project on the legacy flat
specs/layout, nothing changes for you. This repo moved ontodevkit/, and the spec-path resolvers read both — but a spec written from now on assumes the resolver, not a hardcoded directory.
Features
- spec-validate — catch weak contracts at authoring time (Specs 204, 205)
- tool-trial — close the headroom coverage loop and fix the remaining gate
- workflow — route the two headroom measurement surfaces
- workspace — route an undertaking across sibling repositories (Spec 203)
- specs — 202 wave slice
- specs — 201 wave slice
- specs — 203 multi-repo workspace coordinator
- specs — make the trial bench converge instead of sampling (Specs 202, 201)
- specs — 202 trial bench, and make adoption wholesale by default (Spec 202)
- tools — state the cost basis run-cost.sh actually reports
- specs — 201 adopt headroom learn read-only, /capture as sole writer
- canon — make adoption the default and results the deciding criterion
- verbosity — measure the readability half of the compact contract
Fixes
- rules — correct two native-feature claims the changelog check found stale
- tool-trial — let griffe reach the module it is asked to enumerate
- wave — resolve a slice spec in both layouts, not the caller's
- tools — heal PATH-shadowed npm binaries during reconcile
- project-migrate — report dangling references and stop mislabeling drift
- tests — derive the candidates exclude needle from the layout resolver
- devkit-release — bind the clean room to CI's environment, drop a flaky time budget
- spec-backfill — resolve completion commits across the devkit/ rename
Documentation
- reference — record where the two native corrections landed
- coverage — headroom trial round 2, the library surface honestly counted
- reference — harvest headroom under the Adoption Rule
- canon — sync changelog, troubleshooting, and reference candidates
- changelog — record the devkit/ layout range under Unreleased
- context — capture that the release clean room must not set OD_TEMPLATES_DIR
- flows — list /workspace and /failure-learn on their flow pages
Refactoring
- specs — move this repo onto the flat devkit/ layout (Spec 147)
No commit type
- Add headroom init proxy config for Codex
- rename specs/ to devkit/ for flat directory layout, aligning wiring and
v0.17.0 — 2026-08-07
46 commits since v0.16.0 · Specs 089, 091, 180, 184, 185, 187, 191, 193, 195, 198, 199
What changed for you
Now available
devkit project-migraterecognises leftover npx-ai-setup files by their content, so a project whose.ai-setup.jsonis gone gets cleaned up instead of reporting nothing to do — including copies sitting in stale worktrees. Protected surfaces (.mcp.json,.agents/**, specs, settings) stay untouched and every removal goes through a recovery transaction.- The usage report now prints the friction channel and the per-tool counts it has been collecting all along. The friction heading carries its own denominator, because the field only ships from 0.16.0 on.
- A prose docs page can declare the delivered files it describes, and the docs drift check reports every page whose sources moved on since that marker.
docs/comparison.mdsays where this setup differs from superpowers, spec-kit and OpenSpec — and where those are genuinely ahead.
Behavior changed
/specnow executes each acceptance criterion's verify command at the authoring gate instead of only checking that a snippet is present. A green that precedes the work blocks approval, as does a red produced by the harness rather than the assertion. Kill switch:OD_SKIP_VERIFY_PROBE=1./specalso refuses an acceptance criterion whose verify searches for nothing the criterion names, warns about an oversized brief while cutting it is still cheap, and fills the provenance header from the session itself instead of asking you for the field syntax./testrefuses aphp artisan testrun that would migrate your application's own database. It refuses only on a proven collision — every unknown passes through and says so. PinDB_DATABASEinphpunit.xmlwithforce="true"if the check reports one./indexreports GOTCHAS and DECISIONS entries with duplicate subjects, so an outdated twin stops being read as current. Report-only; judging the pair stays your call./wavecorrects four rules this run proved wrong: a worker question now names its channel, a wake-up needs the transcript to agree that a slice is idle,completedis not acceptance, and reintegration requires only the touched paths to be clean.- The run-cost retro no longer flags every slice as having skipped its review — the counter matched a tool name the harness stopped emitting.
- Discarding your whole working tree is blocked:
git restore .andgit checkout .erase uncommitted work as thoroughly asreset --hardbut leave no reflog entry to recover from. Path-scoped restores,git restore --staged <path>and branch switches stay allowed. - You are no longer asked to paste an API key, CI secret or OAuth token into the chat. A credential goes straight into the file or into
gh secret— out of the transcript, which every later context window would otherwise carry. - Opening or reloading a docs page by its direct link no longer returns 404 on the published site.
/devkit-tools-changelogstops treating an unchanged version string as proof that a tool still behaves the same, so a dictionary or rule refresh is visible instead of silently passing.
Action required
- Run
devkit syncto pick this up. Nothing in this range breaks an existing project. - Laravel projects: if
/testreports a database collision, pinDB_DATABASEinphpunit.xmlwithforce="true"before the next test run.
Features
- spec — add tree-mutation and root-level exemption checks to verify (Spec 198)
- spec — execute verify commands at the authoring gate (Specs 089, 091, 199)
- docs — flag a prose page whose code moved on without it
- index — surface duplicate subjects in GOTCHAS and DECISIONS
- test — refuse a PHP test run that would drop the app's own database
- spec — fill in where a spec came from instead of asking for the syntax
- spec — flag an acceptance criterion whose verify searches for nothing it names
- usage-report — print the friction and per-tool data we already collect (Spec 180)
- project-migrate — sweep npx-ai-setup remnants by content, manifest or not
Fixes
- tests — skip the npx-sweep assertions when the predecessor checkout is absent
- project-migrate — drop the duplicate spec-path literal from the content sweep
- run-cost — count the dispatch tool under both its names
- spec — warn about an oversized brief while cutting it is still cheap
- tests — let two full-content scans see past the shipped npx inventory (Spec 184)
- wave — correct four rules this run proved wrong, at no budget cost
- devkit-docs — anchor the Unreleased replacement to a heading
- hooks — block discarding the whole working tree
- skill — separate version equality from behaviour equality in the tool gate
- docs — serve extensionless doc routes on Vercel
- reference — point the landed_ref at the commit that survived
Refactoring
- spec-work — move branch-only material behind references
Documentation
- flows — document project-migrate options and its context phase
- changelog — record the 24 commits the Unreleased block was missing
- reference — add open-gsd/gsd-core to the watch list
- retro — a fix that adds a clause without its criterion buys another round (Spec 187)
- rules — teach three ways an edit to a long-lived file goes wrong (Spec 193)
- specs — approve 187, a gate against a test run that drops the live database
- spec — require an AC's threshold to be measured before approval (Spec 185)
- comparison — say where we differ from the big setups, and where we don't
- reference — scan Karpathy skills repo, no new candidates
- repo — fill the changelog while the work lands, not at release
- plans — living plan for the alignment and skill-size findings (Spec 193)
- rules — answer what to do when a skill budget goes red
- rules — decide context boundaries where the window actually fills
- context — capture that "the agent asked" is unprovable from inside (Spec 193)
- reference — record the mattpocock/skills verdicts
- budget — record why the skill budget is 5000 tokens
- rules — never ask for a credential in chat
- specs — record spec 191 and the orchestration-depth research (Spec 191)
- rules — name what the native worktree guard does and where it stops
- context — record that a green local run proves nothing about CI
Tests
- — resolve the shared test sandbox once instead of per fixture (Spec 184)
Build
- reference — close the three harvested rows against their commit
- tools — bump typos, fallow and repomix
- reference — record the 2.1.222 sweep verdicts
No commit type
- Add spec 195: docs drift gate for prose pages (Spec 195)
v0.16.0 — 2026-08-04
59 commits since v0.15.0 · Specs 042, 154, 157, 158, 159, 161, 162, 163, 166, 167, 168, 169, 170, 172, 174, 175, 176, 177, 182
What changed for you
Now available
/reviewin diff mode now paginates instead of handing over an unbounded diff —REVIEW_MAX_FILES,REVIEW_MAX_TOKENSandREVIEW_OFFSETbound the package, and it ranks the files a human should read first.- A Step may declare what it satisfies as
— ACs: AC1, AC3; strict validation then reports orphaned Steps and unclaimed criteria for you. - Three optional tools join the setup:
osv-scannerscans staged lockfiles at/commit,ccusagegives/devkit-retroa cost figure without a Claude transcript,ast-grepruns structural lint in the quality gate. /devkit-claude-changelogsweeps Claude Code's own docs for features that make parts of our canon redundant.
Behavior changed
- Strict spec validation warns you when a verify command names a path that neither exists nor is declared, and when a loop verify would report the inverse of what it claims.
/wavetears a slice down when it lands rather than at the end of the wave, finds a stalled slice, and reintegrates from the declared file list.- The spec artifact family sits flat under
devkit/, and/specrefuses a Branch field naming the repo's own main branch. - Your agent frontmatter is checked against the documented key set, and the shipped opus alias no longer points at the account-gated 1M variant.
Action required
- Run
devkit syncto pick this up. Nothing in this range breaks an existing project.
Features
- telemetry — blocking gates report their reason through the usage channel
- spec — hand the reviewer the evidence already computed (Spec 177)
- wave — the coordinator finishes a run without asking back (Spec 176)
- routing — check the tier table against current benchmark data (Spec 174)
- spec — catch a verify loop that inverts its own exit status (Spec 172)
- spec — let a Step declare its acceptance criteria (Spec 172)
- hooks — carry the stack lens to the reviewer, and measure whether it lands (Spec 170)
- review — give diff mode a read budget instead of an open-ended diff (Spec 168)
- tools — adopt osv, ccusage and ast-grep where they replace our own work (Spec 154)
- spec-work — ask the architect once when a block diagnoses CORRECTION (Spec 162)
- claude-changelog — sweep the native docs for what makes our canon obsolete (Spec 161)
- spec — check verify commands for addressable paths (Spec 168)
- wave — tear a slice down when it lands, not when the wave ends
- tools — close the blind spots in the outdated check
- review — rank the changed files a human should read first (Spec 159)
- context — give a related repo an owner instead of a pointer (Spec 163)
- wave — adopt Orca's own agent habits instead of working around them
- wave — find the stalled slice, and reintegrate from the file list
- rules — adopt /goal as the completion condition for headless runs (Spec 166)
Fixes
- tests — report only the suites this shard actually started
- tests — heal two assertions that were green only on the laptop (Spec 172)
- release — bind the suite to the tagged bytes instead of the desk
- guard — recognise repo root and HOME behind a symlink too (Spec 182)
- release — make the preflight usable in a repo several sessions work at once
- devkit-claude-changelog — the skill produced both of the defects it reported
- rules — sandbox.credentials was documented as a boolean
- spec-work — a return without a report is not a finished run
- routing — take the kimi tier key back out; it blocks sync and rollback (Spec 042)
- agents — carry the Step mapping only where the validator proves it (Spec 172)
- hooks — seed the bare opus alias, not the account-gated 1M variant
- spec — refuse a Branch field that names the repo's own main branch (Spec 168)
- spec — refuse a Step id the contract digest cannot neutralise (Spec 162)
- wave — drain the inbox, and hold the mirror apart by one variable (Spec 154)
- wave — let acceptance read a declared directory, not just a named file (Spec 158, 161)
- retro — keep the shipped run-cost mirror in sync with the maintainer copy (Spec 154)
Performance
- tests — assign each suite to the lightest shard instead of dealing them round-robin
Refactoring
- spec — flatten the spec artifact family under devkit/ (Spec 169)
Documentation
- specs — add the three approved contracts for the next wave
- spec — add Spec 182, the guard resolves paths physically (Spec 182)
- spec — 177 review-evidence payload, field note on worker_done for 176
- wave — settle whether a slice can run on Codex, by measuring it (Spec 175)
- de — bring the 0.16.0 entry to the full committed range
- de — translate the 0.16.0 entry
- context — record why a third routing target has to wait (Spec 042)
- spec — move 172 into review
- reference — record the scan results of this run
- wave — skip a slice whose spec names the main branch
- spec — add Spec 172, Steps declare their acceptance criteria (Spec 172)
- spec — two contracts for the flat layout and the stack-lens bridge
- spec — point Spec 168 at the code that carries its claim (Spec 168)
- de — translate the documentation and empty the locale backlog (Spec 157, 158)
- wave — ban git stash in a slice, and record why
Tests
- spec-path — recognise spec_layout_path as a fourth sanctioned site (Spec 169)
- agents — check agent frontmatter against the documented key set (Spec 167)
CI
- repo — make the test run manually dispatchable
- repo — install shfmt, the gate added this morning needs it
- repo — shard the release test job the way ci.yml already does
Build
- tests — keep the tree formatted, not only on edit
Reverts
- routing — take the review-light tier back out
v0.15.0 — 2026-08-03
45 commits since v0.14.0 · Specs 143, 144, 145, 147, 148, 151, 152, 157
What changed for you
Now available
- The documentation is bilingual now: an English and a German edition, each with its own navigation. The pairing check rejects an English page without a German counterpart unless it is in the deliberate translation backlog.
/devkit-harvestpulls a chosen reference candidate into the canon, or closes a ledger row that already landed without an entry.bash tests/all.sh --shard i/nspreads the suites over several runs, and CI drives four runners instead of one. The full local run dropped from 1063 s to 387 s.DEVKIT_PROJECT_VIEW=human|markerspicks explicitly between the phase view and the marker output ofproject-migrate;--verbosebrings the markers back at the terminal.- The wave cost report now sums the slice sessions as well as the coordinator. Each slice runs as its own session in its own worktree, so quoting the coordinator alone reported a fraction as if it were the run — measured 381,687 tokens for the coordinator against 524,272 for eight slices.
Behavior changed
npm installruns postinstall scripts only after you allow them explicitly. Measured on 2026-08-03: a plain global install wrote itself into~/.zshrc, the personal Claude settings and two MCP configs without asking.allow_scriptsis now configured per tool and is off by default.- Code review demands the stack lens as mandatory evidence. Without it the reviewer answers
REVIEW_EVIDENCE_REQUIREDinstead of reading Laravel, Nuxt or Liquid code like generic Bash. /specagrees with you on the goal before anything gets built. Every handover leads with two to four plain sentences, and the approval covers that sentence just like it covers the bytes. The direct route had no gate at all and gets one.- Wave acceptance runs the tests of the slice. Two slices reported themselves as finished while their own suite was red. Kill switch:
OD_SKIP_WAVE_ACCEPT_TESTS=1. - A spec contract whose correctness depends on the mechanics around it now needs a cross-model check before approval. Two in-family reviewer rounds cleared spec 162; Codex then found three blockers in the same draft, one of which would have changed the contract digest and blocked its own run.
- The remote-exec guard now catches wrapper prefixes too:
sudo -u deploy ssh prod uptimeused to pass, and seven previously allowed commands block now. - Capped output from the prep scripts reports the real total. Seeing 20 hits used to mean 20 — even when 200 were found.
- The spec location is detected per repo instead of switched globally, so
specs/anddevkit/specs/can exist side by side. Both at once fails loudly instead of one side silently winning. - The reference scan fetches only the changed part of a watched source instead of the whole package, and the ledger proves the reference exists instead of merely checking its shape.
/retromeasures the session you meant to measure instead of the one written to last — with parallel sessions that used to be the wrong one. A wave slice that wrote in the main session without recording it in its progress log is now reported asROUTE_UNRECORDED— measured over two waves, five of eight slices skipped the review their route owed and still looked green.- Beyond 1.25× budget the length reminder names a shape instead of an adjective: at most six visible lines, no closing paragraph.
/indexanddevkit syncare noticeably faster:index-prep.sh --dry-runfell from 4.7 s to 1.2 s, and re-applying an unchanged tree from 8.6 s to 2.4 s.
Action required
- The documentation pairing check now rejects one-sided English or German page edits unless the page is in the deliberate translation backlog.
- A spec step whose verify runs the whole suite now draws a
verify_runs_full_suitewarning. It stays a warning because a deliberate closing gate is legitimate, but spec 151 paid for an accidental one four times over: 118,754 tokens against 34,886 for the cheapest slice of the same wave. - CLI tools now run postinstall scripts only with an explicit
allow_scriptsopt-in. Without it they install without lifecycle scripts.
Features
- docs — set the documentation up bilingually and secure the pairing (Spec 157)
- reference-scan — prove the reference instead of only checking its shape (Spec 145)
- review — make the stack lens mandatory evidence instead of an option
- tools — run npm postinstall scripts only after explicit approval
- policy-guard — stop remote exec behind wrapper prefixes too (Spec 144)
- spec-layout — detect the spec location per repo instead of switching globally (Spec 147)
- spec — let agent and human agree on the goal before anything gets built
- reference-scan — fetch only the changed part instead of the whole package (Spec 143)
- project-migrate — give the terminal run a phase view instead of a wall of markers
- project-migrate — make the status readable at a glance and switch the output to English
- reference-scan — give discovery a second, verified arm
- style — escalate from a request to a shape limit when the measurement justifies it
- retro — measure the slice sessions of a wave as well
- retro — name the slice that wrote inline without recording it
Fixes
- prep — report the real total when the output is capped (Spec 152)
- tests — let spec-routing read the rule pair, and separate red from not-measurable (Spec 148)
- wave — pass effort and worktree along when starting a worker
- wave — let acceptance run the tests of the slice
- wave — make the wave mandates checkable and read file lists in full
- project-migrate — make the run convergent and clean up context7 entry by entry
- retro — measure the run that is meant to be measured, not the last one typed
- spec — make the full-suite verify checkable and heal the third 148 suite
- tests — bring the fallback and the review fixtures up to their own contracts
Performance
- tests — start the longest suites first and shard the run
- index — hash file lists in one process instead of five per file
- sync — materialize unchanged links instead of recreating them
Refactor
- rules — cut agents.md down to its core and move the detail out (Spec 148)
Docs
- devkit-docs — write the changelog in English, bindingly
- devkit-docs — drop the verbatim carve-out from the changelog language
- triage — demand the cross-model check for mechanics-dependent contracts
- — bring README and the rule index up to date
- spec — five new contracts and the script contract rule
- dev — describe the Orca development environment
- reference — record the scan results of the run
- wave — name the contract gap in acceptance and the discarded fix (Spec 147, 148)
- spec — review attention as a ranking derived from the git history
- spec — four new contracts from the reference scan
- lang — switch the canon to English and make it measurable
- spec — three approved contracts from the reference scan
- reference — scan eight changed references and take on two new ones
- spec — forbid the verify that searches its own suite for a label
- rules — make rtk mandatory and name the trap when narrowing
- context — switch the spec 162 decision record to English
Tests
- cli — check foreign CLI calls in a roundtrip instead of only their existence (Spec 151)
No commit type
- Add Spec 168: diff-mode read budget for /review
v0.14.0 — 2026-08-02
62 commits since v0.13.0 · Specs 009, 028, 091, 098, 111, 133, 138, 139, 141
v0.13.1was never tagged and never released. Its one commit therefore sits below under Fixes instead of claiming a version nobody can install.v0.13.0still carries no artifact — the release run aborted back then in the test job, the tag stays in place, and its content is fully included here.
What changed for you
Now available
devkit offdisables the setup without uninstalling it,devkit onre-enables it. For when you need a session without hooks, rules and skills./find-skillssearches the public marketplace for a ready-made skill and installs it after a trust check — before you write your own./retromeasures, after a finished undertaking, what the run cost and whether the route was appropriate for it.! devkit run project-overview.shshows you, in an unfamiliar repo, the spots with the highest change rate, the size distribution and the entry points. Writes nothing, costs no tokens./indexnow reports context files that exist but only contain the error message of a failed generation run — such files used to load silently at every session start.
Behavior changed
- Usage telemetry actually collects now. It had been broken since its introduction and never delivered a single aggregate. Each finished session sends a roughly 1 KB, anonymized aggregate to our own endpoint: which skills ran, which failed, which stack, which tokens. No prompt text, no file contents, no paths. The hook costs you no tokens and about 0.6 s at session start. If you don't want that:
OD_TELEMETRY=0in the environment, then nothing happens at all. Details indocs/TELEMETRY.md. /commitasks for the decision when your commit contains a new dependency, a migration or a new module — the answer lands inDECISIONS.md. Whoever already wrote it down isn't asked./skill-createasks before writing whether a skill is even the right form, and points you to the hook for a check and to the script for a computation.- Response length is measured instead of merely requested; when exceeded you see the measured number in the turn.
- The branch guard now tells you first what to do instead, and only after that how to disable it.
- A git worktree does not isolate parallel writers. The rule claiming that is withdrawn: ref namespace and object store are shared, and one arm can adopt another's finished work. Parallel writers stay sequential until real isolation is proven.
Action required
- Spec drafts now live under
specs/_candidates/instead of in.git/. Whoever wired the old path into their own scripts needs to update it. - In projects without
.agents/context/index-manifest.json, run/indexonce. Without the manifest neither the brownfield preflight nor telemetry knows the project's stack — this currently affects the majority of measured sessions.
Features
- telemetry — count the subagent costs too
- wave — own the teardown the skill's own workers need
- skill-create — ask before writing whether a skill is the right form
- usage-report — put the per-skill session profile against a baseline
- usage-report — keep non-git directories out of the migration list
- usage-report — separate indexed projects from the rest of the rollout
- reference-scan — find new references instead of only checking known ones
- telemetry — make the batch size configurable per session start
- docs — update CLI references and add new sections in documentation
- telemetry — actually deliver session aggregates (Spec 028)
- skills — add find-skills as its own marketplace discovery skill (Spec 009)
- cli — finish the rename to devkit via the npm bin map
- index — remove the legacy ai-setup block and move it into project-migrate (Spec 138, 139)
- style — measure the response length instead of just requesting it
- spec — clean up candidate run directories itself (Spec 098)
- commit — ask for the decision instead of hoping for it
- scripts — show on demand where a repository hurts
- index — report context files without project knowledge
- tests — refuse rm targets at, above or inside the checkout
- spec — move the candidate into a visible folder and make the authoring review a choice (Spec 098)
- wave — measure preflight against the real base ref and require a context index (Spec 133)
- retro — measure what a finished run cost and whether its route was earned
- cli — add devkit off/on to disable the setup without uninstalling it (Spec 111)
Fixes
- test — derive the memsearch pin from tools.json instead of repeating it
- usage-report — measure the review gate at the subagent, not the skill
- rules — retract that a git worktree isolates parallel writers
- wave — close three traps a live wave run hit
- telemetry — keep session built-ins out of the roadmap (Spec 028)
- telemetry — read the stack from the manifest instead of dead markdown (Spec 028)
- telemetry — also find project paths with a dot in the name
- hooks — name the correct behavior in the branch guard before the kill switch
- switches — add the decision-signal switch to the manifest
- telemetry — give every usage payload its own temp file
- test — make the audit budget assertion order-independent
Refactor
- retro — bring the shipped retro up to the maintainer state
- naming — rename internal od_ symbols to devkit_ with an OD_ fallback
- context-bundles — switch the seeded templates to English
Docs
- devkit-docs — reader section first, one bullet per commit below it
- changelog — write the entry for the readers, not for the commits
- reference — record the landed candidates and close 143 + 145
- changelog — continue the 46 commits since v0.14.0
- devkit-usage — record the refuted spec-update cost thesis
- spec — record the contract for the remote-exec gate
- codex — record the known failure patterns of this runtime
- delegate — record that model agreement is not authorization
- rules — require that a regression test was red once
- devkit-usage — point to memsearch for the red skill
- reference — close two landed candidates and correct four IDs (Spec 028)
- reference — record the 2026-08-02 reference scan
- devkit-usage — record the verified blob access
- skills — require a mechanism and a reuse scan in ICA phase 2
- reference — enumerate the public OD_ names for spec 141 (Spec 141)
- context — record the plugin-namespace measurement and the marker decision
- skills — mark shipped skills with a [devkit] prefix
- specs — record the replacement of the npx bootstrapper as a contract
- site — document devkit off/on on the docs site (Spec 111)
- decisions — record why approval_valid is not proof a contract is implementable (Spec 098)
- spec — add the approved contracts for 098 and 133
- skills — tighten authoring guidance and record the day's decisions
Tests
- hook — cover bin-reconcile and make the one red test green (Spec 091)
Chores
- deps — sync the lockfile root version with package.json
No commit type
- update
v0.13.0 — 2026-07-31
19 commits since v0.12.0 · Specs 019, 074, 094, 095, 096
Features
/indextakes the context files into the memsearch index.Until now
.agents/context/was in no index — neither Gotchas nor Decisions nor Conventions were searchable, they only loaded via the always-on import. That meant the knowledge hung on exactly one access path. The step detects memsearch itself, fails silently on errors or a missing tool, is controllable via--memsearch/--no-memsearch, and records the timestamp only in the gitignored graph manifest; the sharedindex-manifest.jsonstays untouched./devkit-retromeasures from the session transcript what a run cost.Every started agent records its consumption in the transcript, so the cost is a fact on disk. A number remembered at the end of a long session, by contrast, is the one number nobody can verify — and that's exactly the one that gets quoted. The skill reads the numbers and then checks the chosen route against
triage.md. The trigger was a spec that took thecompactroute even though none of the four triggers held: about 1.01M tokens for 102 changed lines.
Fixes
The audit batch is bounded by payload, not by file count.
AUDIT_MAX_FILESbounded how many files a batch carries — but the cost depends on the bytes, and file sizes spread by a factor of 44 around the median. A supposedly capped 40-file batch measured 448,630 tokens, 2.2× a 200k window;/review --auditwithout a path couldn't finish a single batch. The cap looked like a limit without being one. With the added token budget it's 127,009 tokens over the same scope.On rerun, the smaller of delta and package is passed, not always the delta.
Measured over 19 real rerun packages, the delta was larger than the package it replaced in two cases:
diff -ucarries both sides plus context, and a jump in scope flips the saving. So the obvious rule would have been wrong exactly in the rounds where the most happened.dev-syncrestores a source that an aborted run had bent out of shape.A hard abort — SIGKILL, a closed terminal, a timeout — skips the EXIT trap, and the source keeps pointing at that run's export directory. The next run then died at the guard with an action instruction, because the guard can't distinguish this state from a genuine misconfiguration. The leftover backup is exactly the missing signal; the guard stays in place as a fallback.
A replay cut short by budget no longer counts as a result.
The run reported
is_error: false,terminal_reason: completedandsubtype: success, while the spec sat there paused with a red verify. No documented field distinguishes the cutoff from a finished run; only the cost against the cap gives it away. Second pitfall from the same measurement:.usagedescribes only the last turn (478 output tokens) against.modelUsagefor the whole run (37,466) — whoever computes savings from it measures orders of magnitude too low.OD_SKIP_STYLE_REMINDERis registered inswitches.json.The hook shipped without registering its switch, so
tests/switches.shonmainwent red for every unrelated change.The release's upload step still named the stashed command in its output — in exactly the line that gets copied on a new machine to set the source. The naming guard scans the shipped surfaces and the tests,
release/sits outside that, so nothing caught it.
Refactor
Re-reviews run over a computed delta instead of a request.
A line-limited request used to bound only the question, not the load path: the reviewer contract still required reading every changed file in full, so a two-line change cost 164,000 tokens for four confirmation lines. Review packages are content-addressed and both sides stay available, so
diff -udelivers a deterministic set.MODE=deltanow also applies to the specialists and is pinned by a gate.The delta contract only existed for correctness; a rerun of the security or performance role still read everything. Architecture stays deliberately excluded: its value is the structural blast radius, which a hunk-limited view can't see. Measured over 19 reruns, 739k tokens drop to 86k.
The run retrospective sits at the maintainer level.
The
devkit-prefix is reserved for maintainer-only skills that are never shipped. The renamed skill therefore left the delivered payload, while its check remains available to maintainers.
Docs
The changelog reads commit bodies for breaking changes and rationale.
release-prep.sh commits/breaking-checknow feed/devkit-docsfrom the bodies instead of only the subjects; that produces a breaking-changes section and a catch-all section for commits without a conventional prefix./devkit-releasechecks the new section before the tag.Spec 094 is complete, including the gotcha about materialization.
The entry protects the next session from suspecting the canon when an empty
~/.claude/rulesis actually a stale local development materialization that a rebuild repairs.Delta guard recorded, dispatch threshold discarded.
71% of specs produced zero blocking findings — but that measures
P(Blocker), notP(Blocker | classifier says skip). Spec 074 decides the question: every verify and the budget green, and the reviewer still found a genuine semantic weakening.The shadow backtest is discarded as statistically undecidable.
Of 27 blocking findings, only 15 are described finely enough to be classified. Even with a perfect evaluation and zero observed leaks, the upper bound sits at 18%; with a realistic cohort, between 31 and 45% — removing a review gate demands 1 to 5%.
Six commits from a parallel session that landed without a type prefix and were therefore silently dropped have been added retroactively.
Three of them carried changes a reader needs: the
spec-contract-reviewer, the explicit branch handling in/spec-work, and the useful hintproject-migratenow gives without a git repository.
Tests
The backfill harness can rerun and grade a completed spec.
The completion commit carries the implementation diff, the outcome line the path there; a replay from its parent reproduces the starting conditions. Everything except the replay itself is deterministic and free.
bin-reconcileis covered: the suite knew it with zero hits even though five ACs verified over exactly it. 16 assertions now cover kill switch, fail-open, idempotency, concurrency and the stderr separation.
No commit type
Add spec-layout path resolver (spec-path.sh + prep-lib.sh) and migrate a
Add UserPromptSubmit style-reminder hook and document the devkit rename
update
v0.12.0 — 2026-07-30
Features
The command is now
devkit. The old nameodwas the same as the POSIX toolod(1), and because our PATH entry resolved first, anod -An -N6 < /dev/urandomsilently returned our help text instead of random bytes — no error, exit 0, so the value kept flowing unnoticed; PhpStorm's terminal reported an error on every command. An alias would have kept exactly the shadowing this is about, sooddisappears entirely. The old PATH link retracts itself at the next session start, and only when it demonstrably points into our own home: a self-placed~/.local/bin/od → /usr/bin/odstays untouched. Environment variables, the home directory, the internal prefixes and the names of the release artifacts stay as they were — only the command is renamed, nothing else./researchcan draw on a second, independent evidence source: dated posts from Reddit, Hacker News and GitHub including engagement numbers, when the question asks about adoption, sentiment or recency. Until now only the web search sat there, and that doesn't answer whether a tool is actually used. The connection is optional and fails silently: if the engine is missing, the output is empty and the run continues instead of blocking the research.The effort tiers of the skills no longer sit only as an expectation in the rule text — they're checked. A rule set describing which tier belongs where changes nothing about a frontmatter that says something else.
The drift check now also covers
CLAUDE.md. It was the only file in the context bundle whose dead references nobody would have noticed.New machines fetch the distribution via a named URL instead of an opaque blob address, and the CI/release interlock is simplified accordingly.
A dedicated reviewer checks spec drafts. Until now the same role judged both the contract and the finished implementation, even though those are two different questions: whether a contract holds up is decided by different criteria than whether a diff satisfies it. Reviewing the draft is therefore separated from reviewing the implementation.
/spec-worknow derives branch handling explicitly from the contract instead of guessing it. If the header names a branch that doesn't exist, nothing gets switched in the shared checkout — parallel sessions and delegated worktrees work there; materialization only happens via the route provided for it.When a git repository is missing,
project-migratesays what to do instead of just aborting: it works per repository and needs git as a way back because it deletes files — the hint names the command to find the right directory under a collection folder.If a change alters a script's output format, exit code or file location, that is now a named trigger for the one full local suite run. Until now the smallest affected suite applied, and that can't see a script's readers: nowhere does it say who parses its output or branches on its exit code. All five places carrying the exception list now say it identically, and a fixture keeps them in sync so the list can't drift apart again. The always-on version in
git.mdnames the trigger without the rationale sentence, because the always-on budget sits at its limit — the rationale lives canonically intesting.md.Orca routing added in three places:
/reviewopens the changed files as a diff in the human's editor when Orca is the host, instead of leaving the finding only as terminal text; the routing hints now point to Orca's ownorca-cliandorchestrationskills; and the hand-maintained command table inagent-browsergave way to a reference to Orca's own bundled, version-matched source. The copy had already drifted — Orca now documents the element ref without@and routes concurrent flows via a page ID instead of the active worktree, while the table claimed both differently. A table we maintain by hand doesn't stay true across Orca releases; the source does.A new
/wavecommand processes several approved specs in parallel across separate Orca worktrees. The existing deterministic plan mode still computes the wave plan; new are the checks around it, because that's exactly where the manual work used to fail. A preflight catches three cases before a worker starts: a worktree Orca created from a stale remote state, a dirty tree and missing node dependencies. An acceptance check then verifies that the changed files really all sit in the contract, that the status reads completed, and that the closing line is present. Workers run on the model tier provided for them instead of the session's default. Merging and cleanup stay explicitly with the human and the coordinating agent.An agent now deterministically recognizes which changed files come from its own session. Until now only an appeal in the rules covered this, and a model that misremembers its own history doesn't notice the mistake. A hook records every edited path under the session ID, and review prep sorts three-valued: own, foreign, unknown. Deliberately three-valued — anything the storage knows nothing about stays fully in the review, so an incomplete mechanism marks own work as unknown at worst but never makes work disappear. The rule text now points at this signal and got smaller in the process.
Two simultaneous spec runs no longer get the same number. Number assignment now claims its number before handing it out, under the shared git directory — the place linked worktrees also look at together, since that's exactly where the observed double assignment came from. Claimed numbers count toward the calculation, so a second run takes the next one. If write access is missing, assignment falls back to the old computation and says so; the collision check at creation time stays the last boundary either way.
The spec directory no longer sits as a text literal in the shipped toolchain, but as a named constant with an unchanged default value. Before, it appeared in 33 places across 14 files and in five different spellings — one overlooked spot in the number assignment would have been enough for an empty hit list to be read as "there are no specs yet" and already-assigned numbers to come out again.
Fixes
- Usage telemetry uploaded the just-started session at every launch and then marked it done — so the complete session never got uploaded. The cause was a variable name: the hook checked
CLAUDE_SESSION_ID, but what's set isCLAUDE_CODE_SESSION_ID, so the comparison value was always empty and the exception for the running session never kicked in. The old name stays in place as a fallback. - When a tool was missing, both local gates reported the result as clean, even though the corresponding check hadn't run at all. The quality gate silently skipped the shellcheck check and still printed the green token; the commit gate left out the secret scan without mentioning it in the context block. The leniency was a deliberate choice, its invisibility wasn't: both now flag the partial state, though the quality gate only when there actually would have been files to check. Exit codes stay unchanged, no reader changes behavior.
- On its way, the rename hit three places that record the past and produced falsehoods there: a gotcha claimed our
devkitshadows a same-named BSD tool, and six changelog lines in already-published versions spoke of a command that didn't exist yet at the time. Both are withdrawn. In the gotcha's place stands the state that actually bites now: there's a window in which no CLI sits on the PATH under any name, and the way back is the absolute path — explicitly not the install one-liner, since the release archive contains no install script at all. - The maintainer tool
dev-syncrequired the renamed command on the PATH, even though that very link is only created by the sync. It therefore reliably failed on every machine that needed it; it now calls the CLI via its path in the checkout. - The spec route again decides via a size threshold above the risk triggers, and the canonical routing table matches the risk-based rule again. On top of that, the background lookup now only claims exclusivity where it actually applies.
Docs
- The shipped
specs/README.mdnow names its owner and says that the directory's structure and lifecycle belong to the skills — a foreign file inside it is read by nothing, a hand-set status is not a state change. That achieves the real purpose of an undertaking that wanted to move the whole folder into a visible namespace: a developer in the client repo sees who owns the directory. The move itself is stopped after four review rounds and a second opinion, because automatic migration of existing projects fails on missing provenance — own artifacts such as JSON evaluations underplans/data/don't follow the spec naming grammar, and a migrator that takes them along can no longer safely tell our files apart from the client's. - Whether a piece of work deserves a spec or belongs inline is now decided by risk, not by the number of files. A counting rule denies planning to small but irreversible changes and forces it onto harmless batch edits.
- Recorded that
devkit runexecutes the installed version, not the working tree. During acceptance of a spec that ships a new script, this made seven criteria come back falsely red — and one falsely green, because the sought text happened to appear in the CLI's error message. The false green is the real danger, because a run like that looks passed. - The adoption plan from the reference scan is closed: four contracts have been incorporated, seven cuts stay deliberately parked and carry their rationale.
v0.11.0 — 2026-07-29
Features
- A new maintainer tool measures whether a rule changes the answer at all. Until now the always-on rule set was changed by judgment, never by measurement — and since the always-on budget sits at its limit, every addition displaces something else without evidence. The tool builds two disposable canons, a full one and one without the rule under test, runs the same task against both several times, and reports. It deliberately doesn't decide: complete separation across three runs happens by chance in one out of ten cases, and whether a rule looks effective depends more on the task than on the rule.
- The probe rates the shape of the answer instead of its length. Word count was the wrong signal — it swung between two runs of the same experiment and doesn't carry what the rule actually demands: result first, no filler words, no closing sentence, bullets instead of prose for reasoning. These four are deterministically checkable and proven red-capable against fixtures.
- The reference scan's candidate ledger gets a harvest path. It collected candidates, but no row was ever closed — thirteen chosen entries, none with a pointer to where the idea landed. The new field takes a spec ID or a commit of its own; only the commit form makes small adoptions closeable at all, because a one-line rule change never gets a spec.
- The reference scan now holds its result in a queryable queue instead of a free-text field that didn't survive the session. A path filter fetches the changed paths via the compare API and skips repos that only moved at README, CI or lockfile paths; every non-classifiable case deliberately falls back to "changed", never to "skipped".
/spec-worknow runs the same verify command only once per unchanged tree; a later step naming it again reuses the result. Invalidation is deliberately total — a change to the working tree, an implementer return, or a context compaction discards everything, because any partial rule would carry stale evidence forward. On top of that, the strict authoring check now measures its warnings against the starting state instead of the whole candidate.install.shnow activates only after complete staging, binds the manifest data to version, channel and size, protects a foreign bin directory, and wires the PATH with safe quoting. Context filling now covers all stack profiles instead of only Nuxt/Storyblok,STRUCTURE.mdis generated unabridged and purely directory-based, and the drift check filters by path class, which cuts down false alarms.
Fixes
- The diff mode of
/reviewpointed at evidence that no longer lived there: the canonical collection had moved into a package file, but the instruction still spoke of standard output. It now names the package path and says what an unavailable diff means — a failed git call is not an empty working tree and must stop the review, not let it pass. - A test assertion searched for a code line verbatim and no longer found it after
install.shhad moved the call into a helper — even though the intended invariant held unchanged. It now checks the invariant instead of the wording and stays sharp doing so.
Docs
- The vision draws the reference line between pinned and owned and floating and foreign — not between tool and prose. Foreign prose with attribution and a version-pinned foreign capability are both permitted; what stays out is a foreign behavioral authority that loads always-on and that we neither own nor can pin to a version.
- Below the spec threshold, inline work is now the named route. The hint table only knew the spec side of the line, and the repo instruction demanded the full test suite before every push across the board — both dragged small changes into ceremony they don't deserve.
- The response rules' strip list allows a hedge again that carries genuine uncertainty. It used to demand unconditional removal, which pushed answers toward a confidence they didn't earn. Offset in the same file so the always-on budget stays in place.
- Three traps recorded from the eval probes: a headless run's closing event reports
successeven for a failed run, a tool allowlist bounds what a run does and not where, and our ownodshadowed the same-named coreutils tool on the PATH. - The approval gates in
/specand/spec-updatenow run through a single selection dialog instead of prose. - The stack-coverage gate in
/indexis documented;--no-asknow skips both interactive questions, not just one. - Eval candidate resolved and the discarded apparatus marked as parked, so the next scan renegotiates it against evidence instead of starting from zero.
- GitNexus scan added; specs 076, 079–083 included, wave planning and adoption backlog brought up to the current state.
- Stale prose on model routing and MCP mutation verify removed.
- The quick start names the PATH wiring the install performs — otherwise the step reads as done while
odstill isn't callable in the running shell.
v0.10.0 — 2026-07-27
Features
- Review evidence is now trimmed to the declared files right at the producer, instead of pushing a full diff through the main context — measured against spec 067, that was 77 KB, and again in every review round. Stdout now carries only headers, counts and the path to the package file. Untracked files stay deliberately untrimmed, because an undeclared new file is exactly what a reviewer needs to see; anything outside the declared scope is reported, not hidden.
/reviewdistinguishes a failed check from a clean result. Until now every git call swallowed its error — a broken index, a timeout and an empty working tree looked identical, and the assigned reviewer reported PASS over a diff that never existed. Exit codes are now checked, an unavailable diff says so and aborts. The evidence sits in an atomically written package file, so no full diff runs through the main context anymore; the residual scan additionally weighs where a match was found —mockDatainsrc/is a finding, the same line intests/is not.- A provably separable extension to a running spec becomes its own successor contract instead of replacing the existing one and re-running every already-green step. The predecessor stays byte-identical and finishes honestly, the successor carries
depends_onand waits for it. Four conditions decide the route, only two of which are machine-checkable — on uncertainty it falls back to a full fresh draft. - OpenCode is supported as a third runtime: the same custom agents and global work instructions as Claude and Codex, opt-in and off by default. Routing is derived from the Claude route instead of declared separately — a third tier key would have broken every not-yet-updated
odduring sync, because validation runs the installed version against the new content. A guard test pins this boundary down. - After saving a CSS file, stylelint runs — but only where the project itself brings a configuration. Three conditions must hold: a CSS file, an executable binary, a resolvable config. A green run stays silent, so does a missing config, and all subsequent checks continue.
/specnow shows a short capsule before approval — goal, what changes, what stays out — extracted from the candidate with the displayed SHA, never summarized into being. At medium and high risk, every discarded alternative gets named in one line. Before, the full contract sat there for the decision, which invites approving the unread.- New
RELATED.mdas a manifest for neighboring repos — boilerplate, contract partner, fork source. It records pointers, never content: path, when to look, and when explicitly not to. LikeGOTCHAS.md, it's seeded from the default bundle and imported inCLAUDE.md, so it's available to a fresh project from day one. - Python is a full-fledged stack profile: its own detection, its own context bundle, its own knowledge lens and complete routing wiring, on par with Laravel, Nuxt, Shopify Liquid and Shopware. A Python repo no longer lands in the
defaultprofile because of it. - Spec IDs are now assigned deterministically:
spec-id-next.shdetermines the next free integer major acrossspecs/andspecs/completed/instead of leaving it to the model. Thepre-push-gateadditionally warns when two specs carry the same ID — before, a collision only surfaced at the next/spec-workasambiguous_spec. Along the way, four forks per file inprep-lib.shwere dropped: a directory scan over 273 specs now takes 59 milliseconds instead of 3,412. - Four rule slices from plan 004: an authoring doctrine for prose artifacts (form matches error type, no open hedge clauses,
descriptiondoesn't summarize the flow), a falsifiability requirement for new tests including independently derived expected values, boundary diagnosis before the first hypothesis for multi-component failures, and the same three-round cap for/specand/spec-updatethat/spec-workalready had. The skill inventory is no longer checked against a hardcoded number, but against the actual directories — in both directions.
Fixes
- The installer now writes the PATH line even when neither
~/.zshrcnor~/.bashrcexists. On a fresh macOS account it used to land nowhere before, and the install still reported success — the user's next command wasod: command not found, with nothing in the output pointing at the cause. - Six routing assertions kept reading review evidence from stdout, even though the producer now writes it to a package file —
mainwas red because of it. They now read the package file. - Four permission checks chained
stat -f … || stat -c …in one substitution. But under GNU,-fmeans--file-system: the first call writes the filesystem block to stdout and only then fails on the invalid operand — the fallback appended the real value onto that noise. Now GNU is checked first, which is safe because BSDstatrejects-cwith no output at all.
Refactor
- The always-loaded rules in
quality.mdare tightened linguistically and sit under the token budget again. No rule was dropped — they just say it in fewer words. An always-on rule is paid for in every single session, so its growth is a decision, not a byproduct of longer prose.
Docs
- OpenCode adapter documented: its own page with activation, materialized artifacts and the rationale for the derived routing; the README and quick start now name the third runtime too.
- Backlog recorded for adopting the official Claude plugin structure.
- Spec 069 uses the shared review package instead of its own pagination.
- Config seed dropped from the stylelint slice.
- OpenCode routing is derived instead of introducing a third tier key.
- Producer-side review evidence and the successor route planned.
- Slice A of the successor route discarded and its own derivation corrected.
- Spec-kit audit and a measured cadence for staying current recorded.
- Reference-first sits in VISION as the canonical decision rule, extending standards-first: reinvent nothing a maintained reference repo has already solved. Applies to prose artifacts; the bash mechanics stay exempt.
- New collection point
specs/plans/004-spec-workflow-slimming.md— findings from a real spec run on why the mechanics make work for themselves. - Evidence recorded for the delta-review groundwork and the counter-evidence from the spec-033 calibration.
- Two measurable slices added from the deep comparison with a reference repo.
- Findings corrected against a cross-model check, and the external comparison added.
- Slice added for the repeatedly-run verification.
- Reference-first established as the working method, with the four boundaries against it.
- Result of the three-model audit carried into the plan.
- Recorded which slices landed and which were withdrawn.
v0.9.0 — 2026-07-26
Features
od project-migratenormalizes stale model pins: full Opus ID pins are removed so the project inherits the global default, full Sonnet ID pins move to thesonnetalias, alias and unknown pins stay untouched.od project-migrateremoves redundantWrite(X)permission rules from the project Claude settings file — but only whenEdit(X)sits in the same list; allow and deny are never merged. Claude Code no longer evaluatesWrite(path)and warns at startup for every dead rule.- Both phases protect the file with a runtime gate instead of a backup: writing only happens once it's proven that nothing deviates besides the intended key. The gate deliberately doesn't compute with the same logic that produced the candidate.
/reviewgets a diff-less audit mode (--audit [path]) for repo-wide multi-category checks without a diff.- Release preparation now shares one implementation for anchor, version suggestion, digest and scope checks instead of duplicating shell logic across two maintainer skills.
Refactor
/specroutes by risk intodirect,compactorfull— a small reversible change no longer pays the full spec ceremony. Spec completion now uses one shared transaction instead of embedding the sequence in the skill.
Fixes
design-filluses the Sonnet family alias instead of a fixed model ID.
Docs
- Flow 5 now describes
od project-migratewith all four phases; troubleshooting coversforeign-context7, the exit-code fallacy, the missingCLAUDE.md, and theWrite(...)startup warnings.
v0.7.0 — 2026-07-24
Features
- Internal docs site (VitePress): landing page in codegraph dark style, 6 flow chapters, reference (skills/agents/rules/hooks) generated from the delivered configuration at build time.
devkit-docsskill: writes this changelog from commits and suggests narrative doc changes.
Fixes
delegate-exec.sh: fixed the Kimiimplementpath —kimi -pdoesn't tolerate--auto/--yolo, non-interactive writes run without a permission flag.