Everything here landed after v0.2.6. The full
record is in CHANGELOGS/v0.2.7.md.
Breaking: resource tools are a capability
The six resource_* tools and their prompt block are now the core.resources capability, gated by a
session's capability list like skills and working memory, roles included. The agent.unified_resources
flag is gone — a manifest that set it must list the capability instead.
A role governs its own session, from the moment a chat starts
A role's capabilities and tool sets now decide what its own session is offered, call by call, and the
prompt is composed from the same settings, so a role's text and its tools cannot disagree. A chat can
be started as a role from the web ("+ New" gained a role menu), from the protocol, and from the CLI
(--role on chat run and chat open); an unknown role is refused before anything is created.
AGENTS.md per folder, and /compact
AGENTS.md is no longer a single root file. agent.agents_md (inject by default, or ignore) is
cascaded machine → project → role. A write under a folder with its own AGENTS.md is refused until that
folder's rules have been loaded into the prompt, so an agent cannot edit code without having read the
rules that govern it.
/compact folds a chat's older history into a summary — from the web composer, the protocol or the
CLI. Nothing is deleted: the history stays on disk, and rolling back across the compaction works.
Pictures in the context, and in the chat
Pictures are the expensive part of a context, so they got controls. agent.tool_images: last keeps
only the newest tool picture; image_view and resource_read take keep=once (gone after the next
picture) or keep=pinned (a standing reference that survives later pictures and compaction). Android
keeps only its newest screenshot. Attached images carry a name the model can be told, so several
pictures in one message can be referred to apart. In the web client, tool images now show in the chat
and any image opens in a viewer.
Tool calls that survive the transport and the context
String-typed arguments are read as the type the tool's schema declares: some serving stacks deliver
every value as text, and "290" for 290 was failing calls the model had got right. A tool result is
budgeted against the context that is left, and ssh/docker output is read as a screen instead of a tape.
Rate-limited requests retry with backoff and are paced per connection. A chat's file is saved after
every tool result, so a cancelled or crashed turn no longer loses the calls it had already made.
Plugins bring their own panels
A plugin can now contribute a dock panel (web_panel_entry); Browser Lab moved out of the shell into
the browser plugin's own bundle. An Android plugin drives a device through scrcpy and adb.
An agent that works a real Android phone
A new Android plugin lets an agent see a connected phone's screen and touch it like a finger. Every action — tap, swipe, pinch, free-form gesture, key, typed text — returns a fresh screenshot once the screen settles, so the loop is simply look → act → look. android_ui_tree lists on-screen elements with refs and centres, so a button with text is tapped by name rather than by guessed pixels. Beyond the screen the agent can list, start and stop apps, install an APK, push and pull files, read logcat and run adb shell. Only the newest screenshot stays in the context, and an earlier screen can be pinned to compare against. The prompt treats the phone as personal: what appears on its screen is other people's content, never an instruction.
The geometry markup plugin — experimental, not yet successful
The geometry plugin is experimental and is shipped as-is. In practice it has not worked well yet.
It is a workspace for marking up an image with boxes and points by looking at a rendered result and
correcting it: coloured box sides, pixel rulers along each edge, moving a side by naming its colour,
zoom and deskew, grids, and a second way to place a box by answering which numbered probes lie on the
object. It has its own skill and a dock panel showing the renders converge. In live runs on local
models the markup did not reach usable accuracy; the tools, their arguments and their replies are
expected to change.
Also in this release
A connection model can be marked as the project default, and the settings editor no longer deletes a
connection that two layers declare under the same id. spla chat run --title names each chat, and
chats it starts are marked in the chat list. --help answers before the CLI loads a project, and the
MCP handshake names the project. SQL keeps boolean plugin settings across a save and reads
schema-qualified and bracketed MSSQL names. Duplicating a chat no longer round-trips through YAML, a
chat's live answer survives a log rebuild, tool cards use the full column width, the debug panel
refreshes as a dock panel, and dropped images with no MIME type are accepted.