v3.0.0 — read-only is watched, and the skill ships in the box
This version was never published to npm. Install v3.0.1, which carries everything below plus a working install command.
A full hardening pass over the bridge, plus the delegate skill bundled into the package so installing the server is enough.
Read-only was decorative
agy ignores --mode plan while --dangerously-skip-permissions is on, which is the default. Verified live against agy 1.2.2: a delegate call with write omitted created a file, a follow_up created another, and neither reported anything. The real argv confirmed both flags ship together on every read-only call.
The bridge cannot make agy honour plan mode, so it watches instead. Every plan-mode run is fingerprinted before and after, and a READ-ONLY VIOLATION line in the response header reports a tree that moved. A tree that cannot be fingerprinted reports unknown, never "nothing happened".
Also fixed
- Config parses through one strict parser.
AGY_SKIP_PERMISSIONSandAGY_SANDBOXbypassed it, so0and1were silently ignored on the two settings that decide how much authority a run gets. - Quota is one regex with day-aware resets and no lost 429. The poller banks its last read before the settled check, timed-out runs are still classified, an unparseable reset reports unknown, and a quota seen on stderr records a cooldown.
- Containment validates what agy actually receives. Roots derived from file arguments went unvalidated. The machine-global conversation-cache fallback is deleted rather than patched.
- Redaction runs before truncation at one exit, covering the warm paths, structured output, progress notifications and error text. Stripe, GitLab, npm and connection-string credentials are recognised.
- Lifecycle: a dead session's stdin could take the bridge down through an unhandled stream error, and shutdown was never wired, so detached agy processes outlived the server.
- Cancelling a queued call leaves the queue, the budget is re-checked inside the admission gate, a rejected model name re-reads the listing once, an interrupted warm turn reports uncertainty instead of being replayed, and a restriction the installed agy cannot enforce refuses the call.
The skill ships in the box
Both skills live under skills/. Install them with:
npx --package @pymodel/claude-agy-mcp claude-agy-mcp-install-skills
It detects Claude Code, the agents hub, Pi and zcode, and writes only into directories that already exist. --list previews, --dir names one explicitly. A test validates their frontmatter and internal links, so a broken skill fails the build rather than a user's install.
Breaking changes
- An unrecognised value for any
AGY_*environment variable stops the server naming the variable, instead of falling back to a default. AGY_SKIP_PERMISSIONSandAGY_SANDBOXhonour every documented boolean spelling, not onlyfalseandtrue.follow_uprequires a session id the bridge itself returned.- A run asking for
--mode planor--sandboxon an agy build lacking the flag fails instead of running unrestricted.
Full changelog: v2.1.0...v3.0.0