Skip to content

Releases: ShadowfetchAI/agent-oasis

Agent Oasis 3.0.1

Choose a tag to compare

@ShadowfetchAI ShadowfetchAI released this 03 Aug 03:31

Patch release. HermesKanbanCard had a custom decoder expecting created_at as a raw epoch number, but no matching encoder - the synthesized Encodable wrote it as an ISO 8601 string instead, which the decoder then rejected. Any workspace with a blocked kanban card would fail to reopen on the next launch.

Fixed

  • HermesKanbanCard.encode(to:) now mirrors the decoder's epoch format.
  • New regression test testKanbanCardRoundTripsCreatedAtThroughPersistence encodes and decodes a card the same way the encrypted workspace does.

80 tests (was 79).

Verify

shasum -a 256 -c SHA256SUMS
spctl -a -vvv -t open Agent-Oasis-3.0.1.dmg

Agent Oasis 3.0.0 - Hermes Fleet

Choose a tag to compare

@ShadowfetchAI ShadowfetchAI released this 03 Aug 02:50

Hermes goes from a 221-line aggregate-only sync button buried in Agents to a first-class dashboard.

Hermes Fleet

  • Live kanban shape and its oldest blockers, read via hermes kanban stats/list --json.
  • The open decision queue, grouped by authority level with ack-deadline urgency, read via the standalone decide.py list --json tool.
  • Roster and gateway process liveness, read via hermes profile list / hermes gateway list.
  • Fleet structural integrity from fleet_integrity.py's state file.
  • Per-agent session/message/token telemetry, carried over from the prior release.
  • Works against any Hermes install, not just Shadowfetch's own - every remote path (profiles, tools, state, gateway unit pattern) is configurable and validated against the same injection-resistant charset already used for the SSH host.
  • No fleet-wide "duty success rate" is invented: no such aggregate exists on a real Hermes install, and a locked-in test fails the build if a field shaped like one is ever added.

Redaction, by construction

Kanban card bodies and decision context/recommendation/options text - which on a real install contain internal strategic content - are never decoded into the app. The Swift models simply have no property for that data, so JSONDecoder drops it before a value exists. Two new tests re-encode a parsed model built from a real sensitive-looking payload and assert the sensitive text is verifiably absent.

Docs

New docs/HERMES-FLEET.md: the exact commands run, exact fields kept versus dropped, and the full threat model for the expanded SSH surface.

Verification

79 tests (was 70), all green. Signed with a Developer ID Application certificate, notarized, and stapled - spctl -a -vvv -t open accepts the DMG.

Verify

shasum -a 256 -c SHA256SUMS
spctl -a -vvv -t open Agent-Oasis-3.0.0.dmg

Agent Oasis 2.0 - Decision Intelligence

Choose a tag to compare

@ShadowfetchAI ShadowfetchAI released this 03 Aug 01:09
c8630d4

Agent Oasis 2.0 turns the encrypted operating ledger into a private decision workspace for products, agents, experiments, and spending.

What is new

  • Decision Lab: evidence-ranked Scale, Hold and measure, Investigate, Refresh data, and Add evidence postures.
  • Scenario Studio: price, volume, refund, proceeds-rate, variable-cost, operating-cost, and labor-capacity sensitivity with whole-unit break-even.
  • Agent frontier: measured cash value and modelled capacity value stay visibly separate.
  • Executive briefing: secret-free Markdown and self-contained HTML decision briefs.
  • Direct Apple evidence: read-only latest daily Sales Summary sync through App Store Connect, with separate least-privilege app-record and Sales and Reports keys.
  • Accounting integrity: signed units and proceeds are applied exactly once, corrected reports replace matching evidence, and currencies are never silently mixed.

Verification

  • Version 2.0.0 (build 5)
  • 70 tests, zero failures
  • Universal binary: Apple silicon and Intel
  • Developer ID signed, hardened runtime enabled, app and DMG notarized and stapled
  • Gatekeeper accepted

SHA-256: 575e5ffb7cf784c3bb8c6a4b683f3dd4bd8fedb1b62ffe7e1288f7fa9681fec8

See the Decision Lab guide, App Store Connect setup, and security model.

Operator Workspace v1.1.0

Choose a tag to compare

@ShadowfetchAI ShadowfetchAI released this 31 Jul 01:22

Flagship Upgrade — Operator Workspace

Built for people who live in the ledger every day.

Download

  • Agent-Oasis-1.1.0.dmg — signed, notarized, universal (Apple Silicon + Intel)
  • SHA-256: fbdf9310b9d96238b92657b6007402a315ca20d51926cc94a2bbd717f68c6ded

Attention Inbox

  • Command Center now lists only actionable gaps: blocked agents, refused experiment attribution, stale/error connections, high modelled value with zero measured inputs, stale measured agents, experiments waiting on data, and missing/old encrypted backups.
  • Click any item to jump straight to the record that needs a decision.
  • Empty inbox means nothing needs you — not that the dashboard is bored.

Command palette & keyboard

  • ⌘K — jump to any section or run import / export / lock / What’s New
  • ⌘1–⌘9 — navigate sections
  • ⌘N — context-aware create
  • ⌘I — import with preview
  • ⌘E — export ledger CSV
  • ⌘/ — shortcuts cheat sheet
  • ⌘⇧L — lock

Import preview & drag-and-drop

  • See apps / observations / ledger counts before anything is written
  • Drop CSV/TSV onto Command Center or Ledger
  • Toolbar Import / Export menu for common paths

Duplicate without inventing evidence

  • Duplicate agents and experiments from the detail view or context menu
  • Agent duplicates reset telemetry and mark value inputs as estimated (Manual duplicate)

Notes

  • Version 1.1.0 (build 4)
  • Settings shows the real bundle version
  • What’s New sheet appears once per marketing version on unlock
  • 55 tests, all green

See CHANGELOG.md.

Flagship Release v1.0.0

Choose a tag to compare

@ShadowfetchAI ShadowfetchAI released this 31 Jul 00:43

Flagship Upgrade

  • Refined UI: Polished glassmorphism and SF Symbol animations (.pulse and .bounce) for priority signals.
  • Search: Added .searchable support in Agents and Portfolio for quick filtering.
  • Context Menus: Right-click to quickly copy Agent IDs, Bundle IDs, and Net Values to your clipboard.
  • Version Bump: Official 1.0.0 stable release.

Agent Oasis 0.1.1

Choose a tag to compare

@ShadowfetchAI ShadowfetchAI released this 29 Jul 12:33

Agent Oasis now has a signed, notarized universal macOS release.

What changed

  • Ships as a Developer ID signed and Apple-notarized DMG for macOS 14 or later.
  • Includes both Apple Silicon and Intel architectures.
  • Enables the data protection keychain with an authorized keychain access group.
  • Binds the workspace key to owner presence in the signed release.
  • Keeps unsigned source builds usable through the documented legacy-keychain fallback.
  • Removes a Swift 6 concurrency warning in Hermes process output handling.
  • Adds a fail-closed release pipeline that validates the profile, entitlements, hardened runtime, architectures, app ticket, DMG ticket, and Gatekeeper result.

Verification

  • Bundle ID: com.realbobcorbin.AgentOasis
  • Version: 0.1.1 (2)
  • SHA-256: 279abd763a93aeb0c51bbfba022ebec377addeec345d0794506d5e66fae5f06e
  • Tests: 51 passed, 0 failed
  • Gatekeeper: accepted, source Notarized Developer ID

Open the DMG and drag Agent Oasis to Applications. No account or Agent Oasis server is required.

Agent Oasis 0.1

Choose a tag to compare

@ShadowfetchAI ShadowfetchAI released this 29 Jul 10:22

First public source release.

There is no signed binary yet — Agent Oasis needs a Developer ID certificate to pass Gatekeeper on someone else's Mac, and shipping an unsigned build that dies at a security warning is worse than shipping none. Build from source, it takes about a minute: see SETUP.md.

What makes it different

  • Cash and modelled value never merge. Three of the four terms behind an agent ROI are usually estimates. They are computed and displayed separately, and never summed anywhere in the app.
  • Confidence measures evidence, not activity. An agent whose value inputs are all hand-entered scores zero confidence no matter how many tasks it completed.
  • Experiments refuse attribution when a confounder is recorded, rather than reporting a lift you cannot distinguish from seasonality.
  • Nothing is fabricated. A new workspace is empty. The sample-data generator lives in the test target, so the shipped binary is structurally incapable of inventing a record — and a test fails if that changes.
  • The audit trail is hash-chained and verifiable, not decorative.

Privacy

No server, no account, no telemetry, no analytics, no crash reporting. Two hosts appear anywhere in the source, both opt-in. Verify it yourself:

grep -rhoE "https?://[a-zA-Z0-9.-]+" AgentOasis | sort -u

Requirements

macOS 14+, Intel or Apple Silicon. MIT licensed.

51 tests, zero warnings. CI fails on any Swift warning and on a debuggable Release build.