Skip to content

Releases: GoatInAHat/vutoolkit

v0.4.2 — Microsoft session liveness repair

Choose a tag to compare

@GoatInAHat GoatInAHat released this 03 Oct 05:08

Fixes

  • Restores Microsoft session liveness checks using Microsoft Graph instead of the retired verification route.
  • Preserves separate Microsoft and Vanderbilt sessions and verifies Outlook mailbox access.
  • Updates Tool Factory to 0.4.3 so the upstream web scaffold validator passes.

Verification

  • 180 tests passed; 13 skipped live tests were not counted as passes.
  • All 28 Tool Factory validators passed, including browser and web smoke checks.
  • The real native Outlook inbox tool returned HTTP 200 after the gateway restart.

Distribution status

GitHub release assets are available here. npm publication is pending: the release workflow's existing npm credential was rejected (E404), and the vaulted publisher identity check returned HTTP 401. No credential was changed. The npm-dependent publishing legs have not completed.

v0.4.0 — deterministic one-call setup

Choose a tag to compare

@GoatInAHat GoatInAHat released this 27 Sep 12:03

Deterministic account setup

  • One setup.run call handles configured identity/password entry, existing-session reuse, dedicated passkey enrollment, vault persistence, and session establishment.
  • Existing and newly enrolled passkeys must pass a fresh isolated assertion before setup reports ready.
  • Explicit recovery, account matching, pending-key protection, and actionable missing-prerequisite/verification/runtime errors.
  • Compatible configured browser selection and a one-action Connect panel.
  • Native OpenClaw download bundles its core dependencies; no separate npm core publication is required.
  • Official requirement-path ranking and clearer incomplete-search reporting.

Verification

178 unit tests, 28 surface validators, production synthetic browser acceptance, and 13 read-only live tests passed. One-call setup on an existing real account verified its passkey and established Vanderbilt and Microsoft sessions. Fresh-passkey enrollment on a second account remains a separate deployment acceptance check. Academic enrollment and live cart mutations were not performed.

Installation

Download openclaw-plugin-vutoolkit-0.4.0.tgz and install with openclaw plugins install ./openclaw-plugin-vutoolkit-0.4.0.tgz. Configure your own identity and optional password through your host secret vault, then invoke vutoolkit_setup_run with confirm:true.

The core npm publication still requires authenticated first-publish bootstrap. Do not interpret the downloadable core tarball as an npm registry publication. ClawHub publication has its own security-scan status.

v0.1.1

Choose a tag to compare

@GoatInAHat GoatInAHat released this 16 Sep 21:41

v0.1.1 — pinned ceremony browser start

One hardening fix on top of v0.1.0.

Fixed

  • sessions.ensure now starts the managed browser pinned to the openclaw profile in headless mode (openclaw browser --browser-profile openclaw start --headless) instead of inheriting config defaults. After a Gateway restart, a zero-config node browser proxy auto-routed the default profile to a remote node (a Mac), launching Chrome there while ensure polled the local CDP endpoint and failed with BROWSER_UNAVAILABLE. The pinned command keeps the start local regardless of config-side defaults; the cdpReachable gate remains the source of truth for readiness. Gateway-side routing config is orthogonal and untouched.

Tests

  • 83/83 passing (81 + 2 new: the default start spawns the pinned command; no spawn when CDP is already reachable).

Engineering status

  • Same known blockers as v0.1.0: the CI release gate fails at toolfactory validate on pinned toolfactory@0.2.1 scaffold drift (self-inconsistent openclawVersion), so these assets are built and attached from the verified local tree; npm registry publication awaits an NPM_TOKEN secret / trusted publisher on the repo.

vutoolkit v0.1.0

Choose a tag to compare

@GoatInAHat GoatInAHat released this 16 Sep 20:06

vutoolkit v0.1.0 — first public release

Universal toolkit for Vanderbilt student life, built for AI agents first: zero-step SSO, a live academic record, GPA truth-checking, and a web UI — shipped as one MCP server, an OpenClaw plugin, a CLI, and a browser extension.

Zero-step auth

  • sessions.ensure — returns a cached session or mints one invisibly: OneVU passkey ceremony for Vanderbilt, Entra-carry (identifier-first + KMSI fallback) for Microsoft. The agent's only decision is calling ensure — never how auth happens.
  • Session liveness — cached sessions are probed against the real service; dead-but-unexpired sessions are re-minted automatically, so cookies never fail on first use. Freshly minted sessions skip the probe.
  • sessions.refresh (force re-mint), sessions.forget, sessions.list, sessions.open.
  • Session values live in a file-backed vault (0600, per-IdP domain allowlist, metadata-only tool output). Only two secrets are needed (VANDERBILT_EMAIL, VANDERBILT_PASSKEY) and the Microsoft chain needs none.

Academic record & GPA

  • record.fetch — live YES academic record through seamless auth: the aai shell is walked for the academic-record endpoint and parsed into a chronological transcript. If the session dies mid-fetch, one forced re-mint retry happens before surfacing a failure.
  • gpa.verify — recomputes per-term GPAs from posted marks and compares against the numbers Vanderbilt posted (truncation-aware exact match). Run it before trusting any what-if output.
  • grades.whatif — what-if GPA planning on the synthetic fixture or a live transcript.

Surfaces

  • MCP server (stdio and HTTP) and an OpenClaw plugin (gateway tools + a Control UI tab).
  • CLI (node --import tsx src/toolfactory/cli.ts <operation>).
  • Web UI (shadcn) served by the plugin at /plugins/vutoolkit/web or standalone.
  • Browser extension (Chrome/Firefox/Edge) paired to a kernel over the relay.

Install

  • OpenClaw: openclaw plugins install --link hosts/openclaw from a checkout, or install the released plugin tarball.
  • Local dev: bash .agents/setup, then npx toolfactory check / npm test.
  • After touching web/ or core source on a linked install: npm run relink rebuilds web/dist and refreshes the host plugin in one step.

Quality

61 unit tests across 10 files, toolfactory drift gates (check/build), per-surface upstream validators, and a scripted (no-LLM) end-to-end OpenClaw check run in release CI.

Release engineering status

  • This first cut was published from a verified local build: 61/61 unit tests, drift gates green, npm tarball ships the built web UI, plugin tarball and web bundle attached here.
  • npm registry publication and browser-store submission will ride the tag-driven CI on a subsequent cut once (a) the upstream toolfactory validate scaffold-drift is fixed (openclaw-native/web surfaces, toolfactory lane) and (b) an NPM_TOKEN secret is configured on the repository.
  • Browser-extension zips are not attached in this first cut; they arrive with the first CI-driven release.