Releases: ASMN-96/ai-agents-skills-toolkit
Release list
v0.2.5
v0.2.5 Source Freshness Refresh
Current controlled source-freshness release.
v0.2.5supersedesv0.2.4for watched-source freshness claims.
Benefit
v0.2.5 unblocks downstream project sync by refreshing watched-source review metadata after Playwright and GSD Core moved immediately after v0.2.4. The release keeps the v0.2.4 agent/risk hardening intact while making the freshness gate green again.
What Changed Since v0.2.4
- Refreshed Microsoft Playwright from
11797b0336d50ab0d8bc554f53fcd8d4aab8438eto32883517ffe7725ef45ac2dc020a63962c27d7a3. - Refreshed GSD Core from
0d56f544d2f6616fcdd0a80279f85380ead4ceb0to7195c2a90b1264e15a43ccc7b62a5a4ce0ac9034. - Updated root and embedded source records, watchlist metadata, and enterprise-risk evidence for those two watched sources.
- Regenerated compiled agents and the embedded
.ai-toolkitpackage for0.2.5.
Boundaries
This release is metadata-only for external sources. It does not import upstream source, install Playwright or GSD, activate runtime behavior, modify product repositories, change package files or lockfiles, configure CI/MCP, or modify global Codex config.
v0.2.4
v0.2.4 Agent And Risk Hardening
Current controlled release evidence.
v0.2.4supersedesv0.2.3for current agent/compiled parity, source-risk metadata, project-map safety, template routing, and embedded package validation claims.
Benefit
v0.2.4 turns the toolkit from a refreshed source package into a harder governance artifact for real project use. The main benefit is trust: approved agents can no longer quietly compile from weak source files, generated project maps no longer absorb nested worktree checkouts, baseline tool risk metadata records evidence and unknowns instead of uniform unknown status, and the embedded .ai-toolkit package mirrors root assets more explicitly.
How It Differs From v0.2.3
v0.2.3 focused on source freshness: it removed passive source holds, refreshed non-Vercel source records, and kept unsafe upstream behavior out of runtime paths.
v0.2.4 focuses on operational trust after that refresh:
- completes
frontend-agent,qa-test-agent, andsecurity-agentsource definitions; - promotes compiled agents with
compiled_status: approvedonly when source quality and parity pass; - validates compiled/source parity for agent path, commit shape, profile refs, method refs, source content, and
.ai-toolkitmirrors; - excludes
.worktrees,.worktree,worktrees, and.git-worktreesfrom project-context maps and rejects injected output paths; - records metadata-only enterprise-risk evidence for baseline tools, including current source identity, inspected areas, uninspected areas, rationale, and next review due date;
- aligns GSD Core and Repomix as governed metadata-only tools without install, execution, CI, MCP, global config, hook, or product-repo activation;
- adds product-neutral PR, commit, design-doc, and incident-report templates and routes them from the appropriate agents/skills;
- expands security-hardening guidance and measurable code-quality/UIUX evidence rules;
- bumps the embedded package and generated artifacts to
0.2.4.
Guardrails Preserved
- No package or lockfile changes.
- No CI, MCP, global Codex config, deployment config, or product-repo mutation.
- No external tool install or activation from registry presence.
- No raw upstream copying.
- No claim that approved compiled agents are runtime spawn proof.
- No change to
actualSpawnObservedoractualSpawnProofwithout task-specific runtime evidence.
Validation Scope
The release gate should include:
- source freshness after latest-main rebase;
- compiled agent regeneration;
- embedded
.ai-toolkitrebuild; - toolkit, project-tooling, runtime, version, public package, leak scan, eval, source-freshness, and full Node test validation;
- final changed-file grouping and explicit no-package/lockfile/CI/MCP/global/product-repo-change confirmation.
Residual Risk
Baseline tool enterprise-risk entries are evidence-backed metadata only. License legal approval, package release contents, telemetry behavior, execution network behavior, project-specific permissions, and CI behavior remain unapproved unless a later owner-reviewed tool adoption PR records that evidence.
v0.2.3
v0.2.3 Full Resource Refresh
Current controlled release evidence.
v0.2.3supersedesv0.2.2; do not use v0.2.2 source-freshness, tool-posture, or readiness evidence for current release claims without rerunning the relevant validators.
v0.2.3 resolves the source-freshness backlog without passive holds. The goal is not to hide risk; it is to review the latest upstream state, adopt useful guidance into toolkit-owned methods/routing/evals where safe, delegate live execution to first-party or project-owned tools where appropriate, and keep unsafe runtime behavior out of the toolkit.
Source Decisions
| Source | Latest reviewed commit | v0.2.3 outcome | Active toolkit use | Boundary |
|---|---|---|---|---|
| Supabase Agent Skills | 1356046015476711a769601079262b5635929427 |
SYNCED_PLUGIN_DELEGATED |
Cleanroom RLS/auth/API/release gates; live operations delegated to Supabase plugin/project tooling | No Supabase CLI, database, migration, RLS, env, MCP, package, product-repo, or raw skill behavior |
| Trail of Bits Skills | d5fe2e6a7896236c3102fd5477e833623ad70298 |
SYNCED_ADOPTED |
License-safe differential security review discipline | No raw CC-BY-SA text, plugin import, scripts, CI, MCP, package, or runtime behavior |
| Microsoft Playwright | ae106c05e5a40486ab5b9704234c32f0499e9719 |
SYNCED_PLUGIN_DELEGATED |
Browser-evidence and rendered-validation guidance; project-owned Playwright/browser execution | No browser downloads, upstream runner/config import, MCP, package, CI, or fake browser evidence |
| shadcn/ui | 7dfd933102fdb881f8abd24fc1ef11a669682b94 |
SYNCED_REFERENCE |
Design-system reference guidance in toolkit-owned UIUX method | No CLI, registry/component import, package metadata, lockfile, MCP, or dependency changes |
| Vercel find-skills | a561e790756b2785b9ddb82285c4eb0a08258ac9 |
SYNCED_REFERENCE |
Historical discovery-boundary reference; first-party Vercel plugin/docs preferred | No CLI/use/update/sync behavior, raw skill copy, install, or runtime activation |
| Impeccable | 6788085015400c3900cbf3a46b76f76bf489b3e3 |
SYNCED_ADOPTED |
UI quality, context-loading, polish, and rendered-evidence gates | No CLI, detector, live-browser scripts, package metadata, lockfiles, llms.txt import, or skill-bundle behavior |
| Everything Claude Code | eef31ad39ce92f437339c2b26edb1b71d3075666 |
SYNCED_REFERENCE |
Cross-harness source-safety awareness in source-safety scoring | No Claude/Cursor/Cline/OpenHands runtime support claim, adapters, MCP inventory, control plane, worktree lifecycle service, Kiro surface, workflow, command, bundled-default, or global config import |
| code-review-graph | 0c9a5ff3371cf78f89032ff6936e3d3a5fedf0b8 |
SYNCED_ADOPTED |
Active read-only context graph/token governance methods | No CLI, MCP, daemon, product indexing, generated graph claims, global config, or whole-repo dumps |
| RuFlo | d065b15927c6ba7318623e8af123e7980e4c6681 |
SYNCED_ADOPTED |
Static task-state, handoff, stop-condition, and failure-accounting discipline | No memory hooks, MCP, daemon, package, global config, background runtime, watchers, or persistence |
Method And Routing Updates
- Supabase guidance now strengthens backend RLS gates, application-security readiness, API contract readiness, release rollback readiness, database agent checks, backend contract checks, and routing validation gates.
- Playwright guidance now strengthens browser-evidence rules while delegating execution to project-owned browser tooling.
- shadcn/ui and Impeccable guidance now strengthens design-system and premium visual quality methods without importing components or live workflows.
- Trail of Bits guidance now strengthens differential security review using cleanroom review discipline.
- RuFlo guidance now strengthens static task-state handoff without runtime orchestration.
- Toolkit-authored governance/readiness methods now use explicit cleanroom provenance instead of unresolved external-source placeholders.
- The release-manager agent is a read-only advisory release coordinator that routes final readiness posture through
pr-release-gate. - Enterprise governance routing evals cover normal-language features, API consumer changes, performance/cache complaints, mobile/WebView risk, package-manager migration, unsafe commands, and lightweight negative cases.
- Key readiness methods now include compact good pattern, bad pattern, evidence required, and stop condition examples.
Positioning Boundary
v0.2.3 is enterprise-oriented toolkit hardening for governed AI coding-agent work. It does not claim certification, automatic installs, automatic runtime activation, broad cross-runtime active support, package publication, marketplace submission, default CI blocking, or product-repository mutation.
Non-Goals
- No product repositories touched.
- No RISS V2 changes.
- No dependency installs.
- No package or lockfile changes.
- No CI wiring.
- No MCP/global configuration.
- No Supabase/Vercel/env/secrets/database migration changes.
- No raw upstream runtime behavior imported.
v0.2.2 — Controlled Toolkit Activation Hardening
v0.2.2 Controlled Toolkit Release Notes
Release Type
v0.2.2 is a controlled toolkit-only hardening release for the AI Vibe Coding Toolkit.
This release strengthens AI coding-agent governance, activation posture, source-freshness handling, no-write leak-scan validation, public positioning, and release metadata. It does not publish a package, submit a marketplace listing, submit an external application, mutate a product repository, or activate external runtime tools.
Scope
- Added and documented no-write public/private leak-scan validation mode through
node scripts/scan-public-private-leaks.mjs --check. - Upgraded tool activation posture so project-owned tools can be recommended as
active-if-detected, while missing tools remainowner-approved-install. - Kept noisy or newly adopted CI checks as
ci-advisoryuntil calibrated and owner-approved forci-blocking-after-calibration. - Preserved static-only and forbidden-runtime boundaries for MCP, daemon, global config, memory, watcher, and persistence conflicts.
- Remediated source freshness with narrow source-record decisions: reviewed-held for runtime/tooling-sensitive drift and safe refresh for low-risk public-site styling drift.
- Cleaned current public positioning to describe an AI coding-agent governance toolkit rather than a single-runtime or single-tool submission workflow.
- Preserved historical v0.2.0 evidence in
docs/V0_2_0_RELEASE_NOTES.md. - Refreshed release version metadata and generated mirrors through repository-supported scripts.
Explicit Non-Claims
This release is not:
- Level 4 readiness.
- Level 5 readiness.
- Enterprise-certified.
- Production-certified.
- Automatic tool installation.
- CI wiring.
- MCP or global configuration.
- Product repository mutation.
- Package publication.
- Marketplace submission.
- External application submission.
- Broad cross-runtime active support.
Operating Model
- Sync does not auto-install tools.
- Toolpack installation is one-time owner-approved and scoped to the target project.
- Installed tools are dormant until task-relevant use is approved or safely project-owned.
active-if-detectedmeans a project-owned tool, config, or script can be recommended for the approved scope; it does not mean auto-execution.- Missing tools require
owner-approved-install. - Agents may run installed read-only tools only when task-relevant, scope-approved, and evidence is observed.
- CI blocking requires stable project evidence, calibration, and owner approval.
- Package-manager detection must happen before command recommendations; npm is not the default.
Tool Posture
| Tool or concept | v0.2.2 posture |
|---|---|
| React Doctor | active-if-detected when project-owned; owner-approved-install when absent; GitHub Action, PR write, and agent skill install require separate approval. |
| Playwright | active-if-detected when project-owned; ci-advisory first; ci-blocking-after-calibration only after stable evidence and owner approval; source drift may remain REVIEWED_HELD. |
| Gitleaks | active-if-detected or owner-approved-install baseline secret scanning. |
| OSV Scanner | active-if-detected or owner-approved-install dependency vulnerability baseline. |
| Semgrep | active-if-detected when project rules/config exist; owner-approved-install when absent; ci-advisory until rules are scoped. |
| Oxlint | active-if-detected or owner-approved-install; supplements ESLint for large JS/TS/React repos. |
| dependency-cruiser / Madge / jscpd | active-if-detected or owner-approved-install for architecture and duplication checks. |
| actionlint / zizmor | active-if-detected or owner-approved-install for GitHub Actions hardening. |
| GSD-style discipline | Active governance discipline/reference only; no vendoring, install, or global config without approval. |
| RuFlo-style concepts | held-static-only; memory hooks, MCP, daemon, global config, background processes, watchers, persistence, and package behavior are forbidden-runtime. |
Source Freshness Decision
- Microsoft Playwright moved from
c30ccc68f833378087338ed9168175e1ce942c00toae106c05e5a40486ab5b9704234c32f0499e9719. The drift touched injected script, test-runner, config-loader, plugin, web-server, type, and test surfaces, so it isREVIEWED_HELD. - shadcn/ui moved from
9c6a5ee1b14226efbcd31daf54e9bc2e91f647e9to7dfd933102fdb881f8abd24fc1ef11a669682b94. The drift touched package metadata andpnpm-lock.yaml, so it isREVIEWED_HELD. - Impeccable moved from
198aa9171948af0bea6d58596ad575cb2de67af7to6c7c04866cc98d992b0cdead355f361ceebc7d2a. The drift touched only public-site light-mode CSS and was safely refreshed as low-risk source-record metadata. - Post-merge validation then detected Impeccable movement from
6c7c04866cc98d992b0cdead355f361ceebc7d2ato347a0c06a2781578f0d3c6fe2cc3a8b64ad5b62d. That drift touchedbun.lock,package.json, and CLI skill-bundle extraction code, so it isREVIEWED_HELD.
These decisions do not approve importing, copying, installing, activating, extracting, running scripts, updating package files, wiring CI, configuring MCP/global settings, or changing product repositories.
Observed Validation Evidence
Observed release-branch output on 2026-06-05:
| Command | Observed result |
|---|---|
git status --short |
Intentional release-branch changes only before staging. |
git diff --check |
Exit 0; Git printed line-ending working-copy notices, not whitespace errors. |
node scripts/ai-toolkit/validate-codex-runtime.mjs |
PASS validate-codex-runtime; active runtime 5 skills, 12 project agents. |
node scripts/check-source-freshness.mjs --fail-on-change |
UNCHANGED 15, REVIEWED_HELD 5, CHANGED_LOW_RISK 0, CHANGED_REVIEW_REQUIRED 0, CHANGED_HIGH_RISK 0, CHECK_FAILED 0. |
node scripts/scan-public-private-leaks.mjs --check |
check-only mode, scanned files 390, findings 15, Current-tree blockers: 0, safe guardrail/scanner evidence and false positives only. |
node scripts/validate-toolkit.mjs |
PASS; 11 checks; WARN summary remained visible for embedded validator review metadata. |
node scripts/compile-agents.mjs --dry-run |
12 compiled-agent outputs previewed with size-ok. |
node scripts/compile-agents.mjs --confirm-write |
12 compiled-agent outputs regenerated with size-ok. |
node scripts/ai-toolkit/build-embedded-package.mjs |
Built .ai-toolkit package for 0.2.2. |
node scripts/ai-toolkit/validate-version-consistency.mjs |
PASS validate-version-consistency. |
node scripts/validate-project-tooling-profiles.mjs |
PASS; 12 checks. |
node scripts/validate-public-package.mjs |
PASS validate-public-package; public files scanned 41; findings 0. |
node scripts/ai-toolkit/run-toolkit-evals.mjs |
PASS run-toolkit-evals. |
node --test scripts/test-*.mjs |
36 tests; 33 pass, 3 skipped, 0 fail. |
| private/product trace search | No current tracked or working-tree matches for the requested private/product markers; hidden .git/logs only contains local historical reflog entries. |
| npm/package-manager search | Matches are negative guardrails, source-record rejected commands, validator patterns, and one unsafe-request eval; no active instruction treats npm as default. |
Only observed output may be claimed in the PR, tag, release, or completion report.
Rollback
- If a docs or metadata issue is found before tagging, revert or amend the release PR through the normal branch and PR flow.
- If the tag or GitHub release is already published, do not delete or rewrite it without owner approval; publish a correction or revert release PR as appropriate.
- Re-run source freshness, runtime validation, toolkit validation, and no-write leak scan after any rollback.
Next Milestone
The recommended next milestone is a separately approved controlled dry-run against an approved target repository. That follow-up must stay separate from this release and must not be treated as automatic product-repo authorization.
v0.2.0 controlled release
v0.2.0 Controlled Release Notes
Scope
v0.2.0 is a controlled Codex toolkit release after the v0.2 enterprise-style coding-time governance hardening and final release-candidate dry-run adoption check.
This release does not claim Level 4, Level 5, enterprise certification, production certification, automatic tool installation, CI wiring, MCP/global configuration, project-repository mutation, broad cross-runtime active support, package publication, or Codex OSS application submission.
Included Evidence
- Final hardening merge:
069a2ce Finalize v0.2 enterprise readiness hardening. - Final release-candidate check merge:
0ec0b47 Finalize v0.2 release candidate checks. - Runtime gate remained canonical at 5 active skills and 12 active repo-local project agents.
- Source freshness passed with no actionable changes.
- Leak scan reported
0current-tree blockers. - React/TypeScript SaaS planner and apply dry-run were exercised against a temporary non-product target.
node scripts/compile-agents.mjs --dry-runpreviewed 12 compiled-agent outputs withsize-ok.node scripts/compile-agents.mjs --confirm-writeregenerated onlycompiled-agents/*.compiled.md.node scripts/ai-toolkit/build-embedded-package.mjsregenerated the.ai-toolkitmirrors for toolkit version0.2.0.
Release Boundaries
- No product repositories are touched.
- No package files or lockfiles are changed.
- No CI workflow, MCP config, deployment config, global/user Codex config, or external service config is changed.
- No tools are installed.
- No raw upstream source content is copied into active runtime paths.
- Recommended tools remain governed metadata unless a separate owner-approved project task installs or runs them.
- Historical v0.1.0 publication and Codex OSS application draft records remain historical evidence; this release does not submit the Codex OSS application.
Validation Required Before Tag
Run and preserve the exact output for:
git status --short
git diff --check
node scripts/compile-agents.mjs --dry-run
node install/tooling-plan.mjs --project-type react-typescript-saas
node install/tooling-apply.mjs --target ./tmp-v0.2-release-candidate-dry-run-target --project-type react-typescript-saas
node scripts/validate-project-tooling-profiles.mjs
node scripts/ai-toolkit/validate-codex-runtime.mjs
node scripts/validate-public-package.mjs
node scripts/validate-toolkit.mjs
node scripts/check-source-freshness.mjs --fail-on-change
node scripts/scan-public-private-leaks.mjs
node --test scripts/test-*.mjs
node scripts/ai-toolkit/validate-ai-toolkit.mjs
node scripts/ai-toolkit/validate-version-consistency.mjs
node scripts/ai-toolkit/run-toolkit-evals.mjsStop before tagging if runtime is not exactly 5 skills and 12 project agents, source freshness has actionable changes, leak scan has current-tree blockers, version consistency fails, validators fail, planner/apply output suggests product/package/CI/MCP/global mutation, or a hard restriction would be crossed.
Rollback
If the release is found invalid before tagging, stop and fix through a normal PR. If the tag or GitHub release is created from the wrong commit, delete or supersede the release through an owner-approved GitHub release correction, remove the tag through normal reviewed repo operations, and publish a correction note that names the invalid commit and validation failure.
v0.1.0
v0.1.0
Controlled public release for Codex-first real-project use.
What is included
- Canonical active runtime: 5 skills and 12 repo-local Codex project agents.
- Deterministically regenerated compiled-agent fallback artifacts.
- Guardrail parity for reviewer, security, QA, release-manager, and frontend project agents.
- Practical Codex usage docs for planning-only, review, and controlled implementation modes.
- Public/private leak scan reporting 87 classified findings and 0 current-tree blockers.
- Version metadata aligned to 0.1.0 across compiled and embedded toolkit artifacts.
Validation evidence
- validate-public-package: PASS, 29 files scanned, 0 findings.
- validate-codex-runtime: PASS, active runtime 5 skills and 12 project agents.
- validate-toolkit: PASS, 11 checks.
- validate-ai-toolkit: PASS.
- validate-version-consistency: PASS.
- run-toolkit-evals: PASS.
- check-source-freshness --fail-on-change: UNCHANGED 22, CHECK_FAILED 0.
- scan-public-private-leaks: 87 findings, 0 current-tree blockers.
Non-claims
This release does not claim Level 4, Level 5, enterprise readiness, broad package maturity, active non-Codex runtime support, product repository changes, global/user Codex config changes, package/lockfile changes, CI/MCP/deployment changes, external installs, or Codex OSS application submission.
Next owner action
Codex OSS application submission remains a separate owner-approved action after this release.