v0.8.5 — the MCPs you run are the versions AIOS names, and eleven fixes for failures nobody saw
What you can now do. Know which version of Slack, Atlassian and NotebookLM you are running, because AIOS now names one and your install follows it. Read the Slack server's code in your vault and know it is the code that runs. Trust
/aios:update,/today,/close-dayand your commits to say so when a check could not run, instead of reporting success. On Windows, use every skill your agents declare.
Your MCP servers run the version AIOS names. Three of them resolved whatever their registry published at launch, and the Python ones never updated at all: every install was guarded by "only if there is no .venv yet", so a machine set up months ago kept those versions whatever AIOS pinned later. NotebookLM was found at 0.3.4 while 0.8.2 shipped. Now:
- Slack is pinned to
@jtalk22/slack-mcp@5.0.0, and the vendored copy inmcps/slack-mcp/is that exact package, byte for byte, where it used to be an older subset no registration ran. It posts as you, so reading it is now reading what runs. Its two dependencies still resolve at launch;SECURITY.mdsays so. - Atlassian is pinned to
mcp-atlassian==0.23.1. Both pins were smoke-tested against live accounts first. - NotebookLM is pinned to
notebooklm-py==0.8.2, and setup now reinstalls a Python MCP whenever its pinned requirements change. 0.8 moves your session into~/.notebooklm/profiles/<name>/on its first run; the two AIOS helper scripts follow it. - The GitHub MCP is retired. Its package is deprecated and archived upstream, and nothing in AIOS called it; sessions use the
ghCLI./aios:companynow detects a GitHub substrate withgh auth status.
superpowers moves to v6.4.1, with your stop conditions stated above it. v6 runs a plan continuously, and upstream tells the model to rule on ambiguities and keep going. AIOS's contract outranks that (upstream agrees), so its four stops apply plus anything your INTENT.md marks ask or escalate: pricing, legal, public or client-facing decisions are never one of its rulings. skills/_index.md says so, and names what it still does unasked. diagnosing-superpowers is left out: it files bug reports upstream. The folder also gains the MIT license its earlier copy lacked.
Eleven fixes contributed by an operator, each checked and extended so vaults shaped differently are covered too (#175–#183, #185, #186). The pattern they share is a check that could fail without saying so:
/aios:updatetreated a hash it could not compute as a result, could reorder.gitignorerules, and read a missing folder as "no drift". Each now fails closed, and it hashes withsha256sumwhereshasumis missing. Binary files (images, PDFs) now compare by their actual content: in a UTF-8 locale every one of them read as empty, so any two compared identical and an update to one never landed. Two updates at once no longer delete each other's clone; a crashed one no longer blocks the next.- Commits refused to pass unscanned when the secret check could not run, and now also scan the commit message and files containing NUL bytes. Large binaries stay fast: files over 20 MB are scanned as text and named in the output.
/todayno longer asks you to close a day that hasn't happened (the notes/7plancreates ahead), checks the remote your vault actually pushes to, and keeps every carry — a carry with no reason tag now escalates as it keeps coming back: flagged at its third carry, asked for a reason at the sixth, escalated at the tenth. A carry with a reason tag, a target date or a parked status is left as it was./close-sessionnow asks its two questions before it writes the block, because the block is committed the moment it lands. A session without an id no longer loses its second close./close-dayredrawsecosystem.mdon its own clock, so a map that gets a small note every few weeks is still redrawn; it reads insights Tier A already routed, finds reports by the date it is closing, and snapshots through the helper — which now stops when it is interrupted instead of archiving on without its lock, and never leaves a half-written copy under a snapshot's name./aios:housekeepingstops reporting every vendored source as behind. Its context-loading audit now takes your primary sessions fromUSER.md's## Identitytable, where it used to match one operator's session names, so on every other vault it counted the real primary as a worker; it also sees an outward action anywhere in a worker's session, not only in its first 120 calls. Expect it to flag more workers than before — those that shipped something before reading yourdeclared/files.
Headless routines, and one sentence in CLAUDE.md. A routine's Bash inherits the allow rules of your project settings as well as your user settings; MODEL-ROUTING.md gives the two ways to close that and what each costs, and /aios:housekeeping reports broad rules in both. Reported privately by an operator. And CLAUDE.md no longer says writing an inbox request is never gated: a kill can need your approval in the session that writes it.
Windows gets the skills its agents declare. The Windows skill registrar still skipped the Anthropic skills after the macOS/Linux one stopped, so agents using doc-coauthoring, internal-comms, theme-factory, mcp-builder or skill-creator got nothing. A test now keeps the two registrars in step.
Action required — check each first; do only what applies:
- NotebookLM, if you installed it (
mcps/notebooklm-mcp/.venvexists): runbash mcps/setup.sh notebooklm-mcpto move to 0.8.2. Thenmcps/notebooklm-mcp/.venv/bin/notebooklm list; if it says your authentication expired, runnotebooklm loginyourself — it opens a browser for your Google sign-in. - The GitHub MCP, if
claude mcp listshowsgithub: it keeps working until npm removes the package. If you don't use it,claude mcp remove github; theghCLI covers what AIOS does. - Slack, if
claude mcp listshowsslackrunning@jtalk22/slack-mcpwith no version: it runs 5.0.0 today and would float to the next release. To pin it, re-register it in the scope it was added:claude mcp remove slackthenclaude mcp add slack -- npx -y @jtalk22/slack-mcp@5.0.0. - Start a new Claude session after updating, so the revised commands and the new superpowers skills load.