Releases: SenjuWoo/Ultimate-AI-Starter-Bundle
Release list
v8.7.35: Task-directed capabilities
v8.7.35 — task-directed capabilities
Routing
One canonical recipe map joins existing skills, component IDs and MCP profiles
for 19 task categories. All five provider trees carry the same map. All 172
canonical skills remain; this adds no duplicate skill-index entry. The shared
profile writer accepts -ListTasks, composable -Task IDs and read-only -Plan.
An empty new project is supported without fabricating project markers.
Task activation uses existing prerequisites, project scopes, backups and Grok's
server budget. It does not claim personal registrations or refresh their
transport/policies. Windows desktop now requires explicit global opt-in even
when selected by a task. Unowned profiles are not removed by -Disable.
Unity/Godot creation, packaged-game modding, Blender assets, Skyrim evidence,
web UI and publication use distinct phases. Universal Modder is CLI/skills;
its upstream fal MCP requires an account/paid usage and is not registered.
No audited Unreal editor MCP is added. Publication preparation is not public
publishing authorization. Visual/gameplay quality still requires actual output.
Hermes
The existing native clone/config/backup/rollback migrator gains blender,
unity, godot and web phase profiles only when their prerequisites exist.
Default remains the small core. Existing creative, code, roblox, skyrim
and personal profiles remain available. Models, aliases, filters and timeouts
retain the existing preservation rules. Installation records actual profile
names rather than a stale hardcoded subset.
This is agent-directed task routing, not a daemon that silently switches an
open chat. Required editor/add-on installation and reload/restart boundaries
are reported, with available CLI work continuing in the meantime.
The outgoing AIO preamble is archived before replacement so installed copies
converge without accumulating contradictory instruction blocks.
Audited updates
- RTK 0.51.0: verified official Windows archive size and SHA-256; tested status
equivalence on staged, unstaged, renamed, deleted, Unicode and untracked files.
The four pinned git corpus byte counts are unchanged. The candidate passes
the safe-hook self-test; broad upstream rewriting remains disabled. - Ponytail 4.10.1: verified upstream tag commit, passed 16 OpenCode adapter tests
and retained/passed the existing Cursor security regression patch. - Existing documented compatibility holds remain; newest is not automatically
safest. The catalog audit is recorded separately from live editor proof. - Final freshness recheck found new GitHub MCP 1.14.0, Firecrawl 3.27.3 and
Super-MCP Router 2.8.3 releases. All passed initialize/tools-list before their
pins changed. The official GitHub Windows asset hash/size was verified;
scoped GitHub schemas remain 47 tools/129,567 bytes. Firecrawl and the router
remain unregistered by default; no authenticated scraping or router child
dispatch was certified. - Component names now split and deduplicate when passed as a comma-separated
string throughpowershell -File, matching provider selection. A regression
check executes the actual normalization rather than accepting a skipped run. - The extracted Unicode-path gate exposed a legacy-console crash in the skill
auditor. Diagnostic output now escapes unprintable characters without
changing the host encoding or suppressing real validation failures.
Verification
TESTS/Test-TaskRecipes.ps1 exercises the real profile writer in disposable
homes with spaces and Unicode, read-only plans, task composition, repeat
activation, personal configuration preservation, opt-in Windows scope and
owned removal. It is part of TESTS/Test-Pack.ps1.
The release-contract suite validates every recipe against shipped profiles,
skills and CLI component IDs. TESTS/test_rtk_candidate.py --rtk <candidate>
reproduces the pinned RTK corpus/status checks. Native Hermes phase topology
is verified after configuration writes; MCP handshake proof is separate from
an actual editor connection. See validation.
v8.7.34 - Current docs and narrow Hermes compression repair
v8.7.34 — current documentation and retired compression repair
2026-10-02
The canonical skill count remains 172 across five provider trees.
Documentation
- Shorten duplicate README history and link current docs plus the preserved
historical changelog directory. Fix moved/missing documentation targets. - List all catalog third-party projects with their real upstreams; distinguish
bundled/fetched, optional and evaluated entries. Add missing canonical credits. - Correct offline bootstrap, repeated-install, profile scope, privacy and native
web-search claims. AIO-GUIDE now reflects included Forge and scoped MCP wiring. - Remove the diagram's blanket zero-chat-cost claim; indexed skills/plugins and
disconnected MCP payloads are different. Check the rendered README, not only text. - Replace the old Skyrim provider/model ranking and unsupported reliability
percentages with task/capability/evidence routing. Correct universal LM Studio
floor and slowdown claims using the inspected runtime's explicit local exception. - Correct the same floor claim in the local-model skill across all provider trees;
qualify local privacy, fallback, quota and KV-quality claims by their actual conditions. - Add dated model guidance from the public OpenRouter catalog and official Hermes
provider docs. New frontier candidates are comparison options, not unmeasured
“best” defaults. Legacy aliases and main/auxiliary preferences are preserved. - Bind Hermes starter documentation checks to the actual agent/compression blocks
rather than allowing another auxiliary setting to satisfy the assertion.
Exact retired setting migration
The public catalog no longer lists inclusionai/ling-3.0-flash-vl:free. Its paid
sibling is not a replacement chosen by the bundle. The portable starter uses
thinkingmachines/inkling:free with max effort, whose catalog context and supported
efforts cover the existing compression settings. Timeout and summary-failure
abort remain unchanged.
The existing Hermes migrator matches only OpenRouter plus that exact retired
free ID (including its OpenRouter-prefixed form). The writer rechecks the old
value, changes only that compression model and ultra-to-max effort, and retains
custom models/providers, paid Ling, extra fields, main settings and aliases.
Verified backup/rollback and app-closed guards remain in force.
Verification boundaries
Runnable production-writer fixtures cover positive, prefixed, custom-effort,
paid-sibling, custom-provider/model and repeat cases. Documentation contracts
check current local links, all upstream listings and the shipped alias mappings.
Release checks use the exact pushed commit and extracted archives. No inference
API call, summary-quality benchmark, game/editor/GPU runtime or fresh whole-PC
installation is implied by these checks. No new dependency or always-on schema.
Local validation before publication: 136 release contracts passed; Windows
PowerShell pack gate passed; Hermes bootstrap passed five cases (15 skills).
Two deliberately unsafe migration mutations were caught by the production-writer
regression. Installed-state doctor passed with zero errors/warnings after the
ownership-aware skills/state sync. The live migrator needed no config changes;
all seven local profile configs already lacked the retired free Ling ID.
The existing Claude GitHub MCP completed initialize/tools-list (47 tools);
this is a transport check, not proof of every authenticated repository action.
v8.7.33 - Universal Modder and evaluated component refresh
v8.7.33 - Universal Modder and evaluated component refresh
New capability without a wider always-on surface
Universal Modder 0.2.0 is vendored from MIT upstream
rehan-remade/universal-modder at immutable commit
15d6f9d5fbd32de9b1884f29ddec3be9133bd912.
The default installer supplies one shared um command and one canonical skill
to Claude, Codex, Grok, Kimi and Hermes: 172 canonical entries total.
Ten original guides and their references load on demand. They are named
GUIDE.md, not discoverable nested SKILL.md entries.
Existing engine-specific and Skyrim Forge routes remain authoritative.
Local features include read-only engine discovery, sprites/palettes/sheets,
Blender-to-sprite rendering, footage contact sheets, FFmpeg edits and field notes.
The wheel includes the pinned knowledge snapshot, Windows PowerShell helpers,
Blender support and SIL OFL fonts. Its dependency pins are Pillow 12.3.0,
NumPy 2.5.3 and PyYAML 6.0.3; uv selects managed Python 3.13.
Core installs from vendored source when the wheel is absent.
The upstream fal MCP, provider plugin manifests and POSIX session hooks are
not installed. No paid call, credential handling, game mutation, editor setup
or desktop action occurred in validation. FFmpeg and Blender are separately
discovered prerequisites. Runtime/dependency setup still needs network access
on a machine without the required downloads/cache, including Full-Offline.
Windows adaptations and checks
The live installer exposed a Hermes startup warning on stderr that PowerShell
5.1 incorrectly promoted to a fatal profile-migration exception. The shared
native runner now captures diagnostics under a local non-terminating preference,
restores the caller preference and checks the real exit code. A native-command
regression proves warning-success, diagnostic retention and exit-7 failure.
- Explicit UTF-8 note/index I/O and redirected CLI output; Unicode survives a
legacy Windows code page instead of becoming corrupted or raising an error. - POSIX publication inventory paths, independent of Windows separators.
- Discover Steam through user/machine registry and environment roots rather
than assuming the C: drive. A synthetic registry fixture isolates the check. - Upstream tests use
shutil.whichinstead of the absent Windowswhichbinary. - 22 upstream tests pass, including generated sprite work, note validation,
publication checks and a tiny FFmpeg EDL render/probe. This is not live-game,
paid fal, Blender scene or GPU-inference proof. - A disposable wheel install successfully runs
um --versionand searches
the bundled knowledge without a clone or remote synchronization. - The bundle gate runs a dependency-free CLI/recon/package/all-provider test.
Empty-home installer and upgrade fixtures remain separate from live-state
doctor checks; neither implies a fresh whole-Windows-machine certification.
Evaluated updates (2026-10-02)
| Component | Pin | Observed check |
|---|---|---|
| Playwright MCP | 0.0.83 | initialize/tools-list; 25 tools, 20,286 schema bytes |
| Firecrawl MCP | 3.27.2 | initialize/tools-list; 25 tools, 80,509 schema bytes |
| GitHub MCP | 1.13.0 | scoped initialize/tools-list; 47 tools, 129,567 schema bytes |
| shadcn MCP | 4.21.1 | initialize/tools-list; 7 tools, 4,495 schema bytes |
| Blender MCP | 2.1.3 | initialize/tools-list; 36 tools, 45,121 schema bytes |
| Windows MCP | 0.8.7 / Python 3.14 | initialize/tools-list; 20 tools, 22,984 schema bytes |
| Playwright CLI | 0.1.22 | unique headless Chrome session: open/evaluate/close |
| Optional ComfyUI CLI | 1.22.0 | telemetry-disabled version and workflow-validation help |
Schema bytes describe compact UTF-8 protocol output, not billed tokens or
per-turn usage. No authenticated scraping/GitHub calls or editor/desktop actions
were invoked. GitHub's official Windows ZIP SHA-256 matches its release digest:
75accfd7f98c2d06c8cbda43d7d243a51a97baced7e6a5d61dd6f7df710fd464.
Profiles reference the same evaluated package pins as the catalog.
Deliberate holds and economy
The first exact-SHA CodeQL scan flagged three credential-logging flows. SARIF
traces started at static public signature labels, not matched credential values.
Keep the detection rules but output fixed credential diagnostics plus affected
file paths, never the detector payload. A synthetic-credential regression proves
rejection without echoed values; the final commit is rescanned before release.
Keep houseCARL 1.9.0 pending its incompatible 2.x API migration; patched
Impeccable CLI 3.6.1 / skill 4.1.3 pending a verified engine replacement;
credential-dependent Perplexity 1.2.1; editor-dependent Unity 0.91.0;
and the non-installed historical OMNI reference 0.7.9.
The freshness auditor reports holds and pinned Universal Modder commit drift.
Windows MCP remains manually opt-in and off by default. RTK remains at 0.50.0
with its tested narrow rewrite policy; no broad command filtering was added.
Reviewed personal skill overrides and independently configured MCPs remain
user-owned. No new general memory/browser MCP, plugin installer or background
hook was added. README's stale source-version badge and skill counts are repaired.
v8.7.32 - Codex Impeccable hook cleanup
Fix repeated Codex Design deep pass and Checking UI changes failures
caused by obsolete global Impeccable executable hooks.
- Upgrade cleanup retires only the exact legacy command pair, with original-byte backups.
- Current project-local Impeccable hooks, custom commands, trust settings, personal skill overrides and profiles are preserved.
- The installed-state doctor detects stale entries; installer regressions cover preservation, backups and repeated upgrades.
- No new dependency, always-on design engine, MCP schema or broader RTK routing.
Run START-HERE.bat to upgrade, then restart Codex so already-open chats reload
their hooks. Historical failure counters are not reset.
Core downloads missing tool payloads during installation. Full-Offline includes
the bundled payloads. Both archives carry the same hook cleanup and 171 skills.
v8.7.31 - hook cleanup and Cursor security fix
v8.7.31 - native Codex hook upgrade cleanup
Reported failure and cause
The local Codex native hooks.json still held two bundle PreToolUse gates and
their two Stop handlers, all pointing at a WindowsApps Python alias. The
installer disabled the old bundle plugin but never inspected this native
manifest, so subsequent successful installs left those commands behind.
PowerShell reproduces a parse error for the old quoted-executable command;
the restricted Windows launch also fails to execute the alias. Invoking the
alias directly outside that restriction succeeds, so it is not claimed to be
a universally broken Python installation.
Codex now supports native hook manifests
and inline hooks, not only plugins. The bundle's policy still supplies its
reliability skills/native plugin rules and narrow RTK instructions to Codex;
it does not forge trust or install executable bundle gates there.
Repair and upgrade behavior
- Retire only handlers whose command targets a full script path under the
resolved bundle statehooksdirectory. A similarly named custom script is
not sufficient evidence of ownership. - Preserve other handlers in the same matcher group, other events, metadata,
BOM choice and exact original backup bytes. Atomic replacement; unchanged
repeated repairs do not write another backup. - Include the new backup family in normal cleanup's three-copy retention,
respecting custom Codex homes and leaving unrelated backup names alone. - Run retirement before interpreter discovery, including check-only/uninstall.
Honor process/userCODEX_HOMErather than assuming a default home. - Constrain the retired plugin's
enabledreplacement to its own TOML table.
Missing flags cannot disable the next plugin or rewrite hook trust. - The installed-state doctor uses the same classification without mutation
and fails on retired native handlers or a manifest it cannot inspect.
Verification and overhead
GitHub CodeQL #228 identified polynomial backtracking in the vendored Ponytail
Cursor adapter's unanchored script-name regex. A word/hyphen boundary makes
only one candidate start possible per filename run and also preserves personal
filenames containing an embedded ponytail- substring. The executable
TESTS/ponytail-cursor-regression.cjs timed out before the fix and passes after
it, using a 900 KB adversarial command plus normal and personal-name fixtures.
The existing upstream Cursor adapter suite remains applicable.
The unused raw upstream Ponytail ZIP is removed from the current offline
payload: skills-copy does not read it, and native offline fallbacks consume
the vendored plugin tree. This avoids shipping a second, unpatched copy or
misrepresenting modified bytes as an official upstream archive. Independently
managed upstream provider marketplace caches are not patched by editing the
vendored source; those providers do not execute this unused Cursor adapter.
TESTS/Test-CodexHookRetirement.ps1 executes the real installer in isolated
custom homes and checks fresh, legacy, partial, malformed and repeated repair
cases, including absent Python, spaces/Unicode, mixed handlers and backups.
It runs from the Windows PowerShell 5.1 pack gate.
Four stale local handlers were backed up and retired. Historical app counters
are not erased; restart Codex to reload its native configuration. This does not
certify every independently installed hook or a pristine Windows VM install.
Testing the extracted Core download exposed a cache-test assumption that the
Full-Offline RTK ZIP existed. Core now uses a local command fixture for the
same real version-parser, atomic replacement, lock and rollback checks;
Full-Offline continues exercising its actual RTK binary. CI now runs the
full pack gate from its freshly built and extracted Core archive as well as
from source, rather than checking only archive integrity.
The v8.7.30 component refresh, compatibility holds and 171-skill distribution
remain. No new dependency, standing MCP schema, or broad RTK rewrite is added.
v8.7.30 - Audited refresh and provider hardening
Audited refresh, without extra always-on overhead
- Refresh Headroom, RTK, Superpowers, Ponytail, CodeBurn, Playwright, Chrome DevTools, Blender, Firecrawl and Windows MCP to tested compatible versions.
- Keep the narrow tested RTK policy and scoped MCP activation. Windows desktop control remains off by default and now selects its required Python 3.14 runtime explicitly.
- Ship 171 canonical skills, including on-demand Superpowers diagnostics; synchronize all five provider trees and retain reviewed personal overrides during upgrades.
- Fix Hermes foreign-plugin discovery, YAML-capable hook installation and stdout/stderr JSON separation. Preserve portable Linux command-helper permissions in both archives.
- Add opt-in ComfyUI CLI guidance for local creative workflows, with no default install, cloud login, model download or standing MCP.
- Include the previously pushed Hermes/SillyTavern installer and loaded-model selection fixes.
Compatibility holds remain intentional: houseCARL's API-breaking 2.x update, Impeccable's failing parser candidate, credential-dependent Perplexity verification and Unity's unverified editor upgrade are not silently installed.
Core: smaller download; obtains missing third-party payloads during installation. Full-Offline: includes the vendored payloads. Both include Skyrim Forge source and SHA-256 files.
v8.7.28 - Hermes Superpowers stays Hermes-only
v8.7.28 - Hermes Superpowers stays Hermes-only
170 canonical skills total. No new dependency and no new MCP server.
GitHub was still serving v8.7.27. This release is commit 5da6dc32b84fb88563f2b5c8a1232c1348765520.
The gap
Hermes loads Superpowers from .hermes-plugin, one directory below the plugin root. Discovery walks that extra level, so the Claude, Codex, Cursor, Devin, and Kimi plugin.json files in the same tree were parsed as Hermes plugins. Every gateway start logged plugin.json declares an unsupported or missing Agent Plugins schema for those five manifests. The Hermes adapter itself still loaded.
The installer also restarted a gateway that had been running as soon as the plugin refresh finished. Profile migration writes config.yaml after that. A running gateway saves the copy it loaded at start, so the migration could be overwritten.
A skills-only install left this machine on Context7 4.1.0 and Playwright CLI 0.1.19 after the catalog had moved to 4.1.1 and 0.1.20. last-github-update.json had collapsed to a single RTK v0.46.0 object after the installed binary was 0.47.0.
The fix
The shared Superpowers tree is unchanged, because Kimi installs .kimi-plugin from it. The Hermes git bridge and the installed Hermes copy drop .claude-plugin, .codex-plugin, .cursor-plugin, .devin-plugin, and .kimi-plugin. The strip refuses to run inside BUNDLED-TOOLS\plugins.
A gateway that was already running stays stopped until profile migration finishes, then restarts. Migrate-HermesProfiles.ps1 -Apply refuses to run while the gateway is up.
The installed-state doctor fails when the Hermes Superpowers copy still has those foreign manifests, when a Hermes profile's Context7 pin disagrees with CATALOG.json, or when a recorded npm spec disagrees with the catalog.
last-github-update.json merges by component id and stays an array. installed_version is recorded without erasing the last fetched tag.
Verification
TESTS\Test-Pack.ps1 passed locally, including the new strip, guard, and ledger cases. python .github/scripts/check_versions.py agreed on v8.7.28. python .github/scripts/verify_manifest.py reported verified=8475 missing=0 mismatch=0. The Hermes doctor passed after the live pin update.
CI on 5da6dc32b84fb88563f2b5c8a1232c1348765520 is green: pack gate, manifest, version strings, every Forge job, and CodeQL for Go, JavaScript/TypeScript, Actions, and Python. The archives below were built from that commit. Their published bytes are checked against these digests after upload.
Ultimate-AI-Starter-Bundle-v8.7.28-Core.zip799cb8784ac71a8d8d61e35dc986027ca98b1387aed2353b243c71b989e5851aUltimate-AI-Starter-Bundle-v8.7.28-Full-Offline.zip770296776424d878644e0f32a4afdc8a6b683dcb82faae7406420b028d606dea
v8.7.27 — preamble edits converge installed machines
v8.7.27 - preamble edits converge installed machines
170 canonical skills total. No dependency, pin, config or runtime change.
The gap v8.7.26 left
v8.7.26 rewrote the preamble writer to match complete owned text instead of an opening line through EOF,
which protects user instructions appended after the block and refuses to guess ownership from a first
sentence. That is the right default - but it left one case open: when the pack's OWN text changes, a
machine wired by the older release carries text this release no longer ships, so nothing matches. The old
block stays and the new one appends. A release that edits 3-PREAMBLES/SOUL.md or
0-UNRESTRAINT-PACKS/AIO-INSTRUCTION.md would silently stack a second block on every installed machine.
Reproduced before fixing: a target holding the previous block plus personal notes, run against changed
sources, came back with both blocks in one file.
The fix
Outgoing text is archived in 3-PREAMBLES/history/ (one .md per archived text) and stripped exactly
like a source file. The writer stays conservative - it still only removes text that matches a known owned
copy, byte for byte - but "known" now includes what previous releases shipped.
The maintainer step is one line in 3-PREAMBLES/README.md and release-checklist step 0: copy the
outgoing text into history/ before you edit a source. Archived copies are never written anywhere; they
are only ever deleted from installed files.
Verification
Test-PreamblePreservation.ps1 now covers six cases - plain trailing notes, marked trailing notes,
opening-line collision, duplicate plain blocks, literal $1/$& replacement characters, and
previous-release text replaced via history (old text gone, personal notes kept, current text exactly
once, idempotent on re-run). All six pass. The full release contract suite, the pack gate, the version
gate and the manifest ran green before tagging, and the extracted archive re-ran them plus the
preservation test. No paid inference was used for any claim in this note.
v8.7.26 — preserve user instructions and harden review gates
v8.7.26 - Preserve personal instructions and verify audit failures
170 canonical skills; no new dependency, model preference or always-on MCP.
- Fix the marker-free preamble writer: a matching opening sentence no longer
claims everything through end-of-file. Replace complete source blocks or
explicitly bounded legacy blocks; preserve user notes before and after them.
Unknown or edited unmarked text is retained rather than guessed away. - Add executable regression cases for trailing notes, legacy markers, opening
sentence collisions, duplicate blocks, literal dollar text and idempotence. - Make the Impeccable engine audit reject runtime failures, empty output and
invalid JSON shapes instead of treating them as clean negative fixtures.
The existing compatibility hold stays unchanged. - Incorporate reviewed Windows launcher guidance from local Hermes notes.
Correct premature-release and destructive overlay advice; published asset
replacement still needs explicit permission. The shared release checklist
now uses the installer's override protection and native-skill deduplication,
not the older direct-copy helper. - Correct the Ling free summarizer context comment to the public catalog's
262144 tokens (checked 2026-09-20), not 1M. No paid inference was run and
no personal model or effort setting was changed.
Local configuration migration must not race a running Hermes application.
Skill deployment, static validation, MCP handshakes and editor/model runtime
behavior are separate checks; a passing archive gate does not prove all four.
v8.7.25 — impeccable hold re-audited against the real engine
v8.7.25 - the impeccable hold, re-audited against the real engine
170 canonical skills total. No dependency, pin, config, runtime or skill change.
What was asked
Whether CLI 4.1.0 / skill 4.3.1 is better than the audited CLI 3.6.1 / skill 4.1.3 the catalog held
back on 2026-09-13.
What the upstream payload actually is
The npm 4.1.0 package is a 17,840-byte stub (six files). Its shim resolves $IMPECCABLE_BIN, then the
pinned platform package @impeccable/cli-<os>-<arch> (published for win32/darwin/linux; win32-x64 is
14.7 MB unpacked and integrity-checked by npm), then a version-pinned cache in ~/.impeccable/bin/<version>/,
then a download from engine-v<version> release assets with a fail-closed .sha256 sidecar. Engine
version 0.1.5 travels as the pinned optionalDependencies; engines.node >= 22.18. The skill side
(4.3.1, 56 files) is plain files with read-only launcher shims - the bundle would remain the single
writer of provider skill trees, except that the engine's install/link/update/check commands can
write them, so the bundle must never invoke those.
Why the hold stays
The bundle's 3.6.1 payload carries a 2026-09-02 patch that keeps bodies of browser-valid malformed close
tags (</script \t bogus>, </style bogus>) out of text analysis. Run against the real 0.1.5 engine,
the same fixtures leak:
| fixture | engine 0.1.5 | vendored 3.6.1 (patched) |
|---|---|---|
well-formed <script> bait |
0 findings | 0 findings |
</script \t bogus> bait |
1 finding (leak) | 0 findings |
</style bogus> bait |
1 finding (leak) | 0 findings |
| control: visible buzzword text | 1 finding | 1 finding |
The engine is compiled, so the patch cannot follow. Adopting 4.x would delete the audited implementation,
reintroduce the defect and add a first-use download surface - not better on the axis that matters.
What ships
TOOLS/audit-impeccable-engine.pyreruns the four fixtures against any real engine and exits non-zero
on a leak, so the next audit is one command.test_impeccable_hold_records_a_real_engine_auditpins the hold text to its evidence, the audit tool to
its fixtures, and the audited pair from moving without a re-audit.- The catalog hold now records the measurement (engine 0.1.5, what leaked, why it cannot be patched);
docs/TOOL-EVALUATIONS.mdcarries the full write-up.
Verification scope
Executed before release: the audit fixtures against the real 0.1.5 engine (leak reproduced, control
passes), the bundle's own regression suite against the vendored payload (pass), the full release contract
suite, Test-Pack.ps1, version gate, manifest regeneration, and the extracted-archive gate suite. No paid
inference was used for any claim in this note.