Repository navigation
Releases: GoatInAHat/vutoolkit
Release list
v0.4.2 — Microsoft session liveness repair
Fixes
- Restores Microsoft session liveness checks using Microsoft Graph instead of the retired verification route.
- Preserves separate Microsoft and Vanderbilt sessions and verifies Outlook mailbox access.
- Updates Tool Factory to 0.4.3 so the upstream web scaffold validator passes.
Verification
- 180 tests passed; 13 skipped live tests were not counted as passes.
- All 28 Tool Factory validators passed, including browser and web smoke checks.
- The real native Outlook inbox tool returned HTTP 200 after the gateway restart.
Distribution status
GitHub release assets are available here. npm publication is pending: the release workflow's existing npm credential was rejected (E404), and the vaulted publisher identity check returned HTTP 401. No credential was changed. The npm-dependent publishing legs have not completed.
v0.4.0 — deterministic one-call setup
Deterministic account setup
- One
setup.runcall handles configured identity/password entry, existing-session reuse, dedicated passkey enrollment, vault persistence, and session establishment. - Existing and newly enrolled passkeys must pass a fresh isolated assertion before setup reports ready.
- Explicit recovery, account matching, pending-key protection, and actionable missing-prerequisite/verification/runtime errors.
- Compatible configured browser selection and a one-action Connect panel.
- Native OpenClaw download bundles its core dependencies; no separate npm core publication is required.
- Official requirement-path ranking and clearer incomplete-search reporting.
Verification
178 unit tests, 28 surface validators, production synthetic browser acceptance, and 13 read-only live tests passed. One-call setup on an existing real account verified its passkey and established Vanderbilt and Microsoft sessions. Fresh-passkey enrollment on a second account remains a separate deployment acceptance check. Academic enrollment and live cart mutations were not performed.
Installation
Download openclaw-plugin-vutoolkit-0.4.0.tgz and install with openclaw plugins install ./openclaw-plugin-vutoolkit-0.4.0.tgz. Configure your own identity and optional password through your host secret vault, then invoke vutoolkit_setup_run with confirm:true.
The core npm publication still requires authenticated first-publish bootstrap. Do not interpret the downloadable core tarball as an npm registry publication. ClawHub publication has its own security-scan status.
v0.1.1
v0.1.1 — pinned ceremony browser start
One hardening fix on top of v0.1.0.
Fixed
sessions.ensurenow starts the managed browser pinned to theopenclawprofile in headless mode (openclaw browser --browser-profile openclaw start --headless) instead of inheriting config defaults. After a Gateway restart, a zero-config node browser proxy auto-routed the default profile to a remote node (a Mac), launching Chrome there while ensure polled the local CDP endpoint and failed withBROWSER_UNAVAILABLE. The pinned command keeps the start local regardless of config-side defaults; thecdpReachablegate remains the source of truth for readiness. Gateway-side routing config is orthogonal and untouched.
Tests
- 83/83 passing (81 + 2 new: the default start spawns the pinned command; no spawn when CDP is already reachable).
Engineering status
- Same known blockers as v0.1.0: the CI release gate fails at
toolfactory validateon pinned toolfactory@0.2.1 scaffold drift (self-inconsistentopenclawVersion), so these assets are built and attached from the verified local tree; npm registry publication awaits anNPM_TOKENsecret / trusted publisher on the repo.
vutoolkit v0.1.0
vutoolkit v0.1.0 — first public release
Universal toolkit for Vanderbilt student life, built for AI agents first: zero-step SSO, a live academic record, GPA truth-checking, and a web UI — shipped as one MCP server, an OpenClaw plugin, a CLI, and a browser extension.
Zero-step auth
sessions.ensure— returns a cached session or mints one invisibly: OneVU passkey ceremony for Vanderbilt, Entra-carry (identifier-first + KMSI fallback) for Microsoft. The agent's only decision is calling ensure — never how auth happens.- Session liveness — cached sessions are probed against the real service; dead-but-unexpired sessions are re-minted automatically, so cookies never fail on first use. Freshly minted sessions skip the probe.
sessions.refresh(force re-mint),sessions.forget,sessions.list,sessions.open.- Session values live in a file-backed vault (0600, per-IdP domain allowlist, metadata-only tool output). Only two secrets are needed (VANDERBILT_EMAIL, VANDERBILT_PASSKEY) and the Microsoft chain needs none.
Academic record & GPA
record.fetch— live YES academic record through seamless auth: the aai shell is walked for the academic-record endpoint and parsed into a chronological transcript. If the session dies mid-fetch, one forced re-mint retry happens before surfacing a failure.gpa.verify— recomputes per-term GPAs from posted marks and compares against the numbers Vanderbilt posted (truncation-aware exact match). Run it before trusting any what-if output.grades.whatif— what-if GPA planning on the synthetic fixture or a live transcript.
Surfaces
- MCP server (stdio and HTTP) and an OpenClaw plugin (gateway tools + a Control UI tab).
- CLI (
node --import tsx src/toolfactory/cli.ts <operation>). - Web UI (shadcn) served by the plugin at
/plugins/vutoolkit/webor standalone. - Browser extension (Chrome/Firefox/Edge) paired to a kernel over the relay.
Install
- OpenClaw:
openclaw plugins install --link hosts/openclawfrom a checkout, or install the released plugin tarball. - Local dev:
bash .agents/setup, thennpx toolfactory check/npm test. - After touching
web/or core source on a linked install:npm run relinkrebuilds web/dist and refreshes the host plugin in one step.
Quality
61 unit tests across 10 files, toolfactory drift gates (check/build), per-surface upstream validators, and a scripted (no-LLM) end-to-end OpenClaw check run in release CI.
Release engineering status
- This first cut was published from a verified local build: 61/61 unit tests, drift gates green, npm tarball ships the built web UI, plugin tarball and web bundle attached here.
- npm registry publication and browser-store submission will ride the tag-driven CI on a subsequent cut once (a) the upstream toolfactory
validatescaffold-drift is fixed (openclaw-native/web surfaces, toolfactory lane) and (b) an NPM_TOKEN secret is configured on the repository. - Browser-extension zips are not attached in this first cut; they arrive with the first CI-driven release.