Skip to content

v3.0.0 — read-only is watched, and the skill ships in the box

Choose a tag to compare

@elkaix elkaix released this 12 Sep 17:28
· 5 commits to main since this release
3f049c2

This version was never published to npm. Install v3.0.1, which carries everything below plus a working install command.

A full hardening pass over the bridge, plus the delegate skill bundled into the package so installing the server is enough.

Read-only was decorative

agy ignores --mode plan while --dangerously-skip-permissions is on, which is the default. Verified live against agy 1.2.2: a delegate call with write omitted created a file, a follow_up created another, and neither reported anything. The real argv confirmed both flags ship together on every read-only call.

The bridge cannot make agy honour plan mode, so it watches instead. Every plan-mode run is fingerprinted before and after, and a READ-ONLY VIOLATION line in the response header reports a tree that moved. A tree that cannot be fingerprinted reports unknown, never "nothing happened".

Also fixed

  • Config parses through one strict parser. AGY_SKIP_PERMISSIONS and AGY_SANDBOX bypassed it, so 0 and 1 were silently ignored on the two settings that decide how much authority a run gets.
  • Quota is one regex with day-aware resets and no lost 429. The poller banks its last read before the settled check, timed-out runs are still classified, an unparseable reset reports unknown, and a quota seen on stderr records a cooldown.
  • Containment validates what agy actually receives. Roots derived from file arguments went unvalidated. The machine-global conversation-cache fallback is deleted rather than patched.
  • Redaction runs before truncation at one exit, covering the warm paths, structured output, progress notifications and error text. Stripe, GitLab, npm and connection-string credentials are recognised.
  • Lifecycle: a dead session's stdin could take the bridge down through an unhandled stream error, and shutdown was never wired, so detached agy processes outlived the server.
  • Cancelling a queued call leaves the queue, the budget is re-checked inside the admission gate, a rejected model name re-reads the listing once, an interrupted warm turn reports uncertainty instead of being replayed, and a restriction the installed agy cannot enforce refuses the call.

The skill ships in the box

Both skills live under skills/. Install them with:

npx --package @pymodel/claude-agy-mcp claude-agy-mcp-install-skills

It detects Claude Code, the agents hub, Pi and zcode, and writes only into directories that already exist. --list previews, --dir names one explicitly. A test validates their frontmatter and internal links, so a broken skill fails the build rather than a user's install.

Breaking changes

  • An unrecognised value for any AGY_* environment variable stops the server naming the variable, instead of falling back to a default.
  • AGY_SKIP_PERMISSIONS and AGY_SANDBOX honour every documented boolean spelling, not only false and true.
  • follow_up requires a session id the bridge itself returned.
  • A run asking for --mode plan or --sandbox on an agy build lacking the flag fails instead of running unrestricted.

Full changelog: v2.1.0...v3.0.0