Repository navigation
Adds index navigate and index outline-map: code for a plain-language question, found one
typed question per level, with a frozen benchmark beside it.
-
index navigate ROOT "question"finds the code for a plain-language question. It walks
directory, file and symbol with one typed question per level, follows every child at
least half as likely as the top child (up to four), keeps the rest in a backlog for
backtracking, and delivers only the best leaf of each file it reached.--jsonadds
the source text and the decision path (index.decision-path/v1). Code files only by
default;--include-docsadds prose and config. -
index outline-map ROOT --node IDprints one outline node's children as a map: a name
and description for a model, and a handle with the node id for the code. A host model
can walk the tree itself and only ever choose among nodes that exist. -
MCP tools
index.navigateandindex.outline-map, in the full server and the
read-only client profile. -
Benchmark on 60 frozen questions from merged pull requests (query file SHA-256
a264681f...): navigate recall@5 0.389 against grep 0.422 (difference -0.033,
interval -0.114 to 0.055) at 0.33 of grep's tokens (interval 0.27 to 0.41). The bar
set before the run passes on point estimates; the stricter interval version does not.
Details, the design-set shortfall and limits indocs/NAVIGATE.md; inputs, builder
and results inbenchmarks/navigate/. -
The local client profile marks Git as unavailable before any Git code runs. In a
Git workspace,index.mapno longer readsINDEX_GIT_TIMEOUT_SECONDSor copies the
environment for a Git call that the audit hook would refuse. A test with a planted
token checks that the client tools never read it. The full CLI and MCP server keep
their Git behavior. -
The plugin folder now carries its own copy of the server code under
client-plugin/server/src, so a directory install that receives only that folder
starts.python scripts/build_client_package.py --sync-vendoredrewrites it from
src/, and a test fails when the copy drifts. The launcher no longer falls back to
the repository'ssrcand reports a missing copy in one line. -
The plugin folder stays within the directory limits: 512 files, and 256 KiB for every file that is not an image or font.
-
The Claude plugin manifest carries directory listing fields: display name, keywords,
homepage, documentation, support, privacy and terms links, and a 1024 px icon. -
Claude Code now asks for the readable workspace and the optional state directory
when the plugin is enabled. The Claude.mcp.jsonpasses them as${user_config.*}
launch arguments with the same settings and defaults as the MCPB. Portable and Codex
manifests are unchanged. -
The client README gains a data and network table derived from the launcher code.
-
The client README and PRIVACY.md gain a "What this plugin runs and handles" section:
hooks (none), the exact launch command, network (none), files written in the state
directory, and every environment variable the client code reads.