Releases: antoniofulg/workflow-toolkit
Release list
Workflow Toolkit 2.0.1
Selected images and designs now bind visible composition by default. Builders must compare mobile and desktop renders with the source, correct material mismatches, and hand off evidence for independent visual verification.
- Record concrete UI requirements and each necessary adaptation before coding; remove blanket project-token exemptions.
- Fail material differences in theme, header, filters, cards or footer even when behavior tests pass.
- Check sticky controls, inherited dark themes and potentially misleading venue placeholders in actual viewports.
- Reject incomplete visual evidence, non-PASS visual results and recorded binding-source contradictions in the completion gate.
- Add a venue-page regression example and clarify optional security lifecycle companion skills.
Update the complete skill set using the installation instructions.
Validation: full toolkit suite and validator self-test passed for the implementation; release metadata and distribution checks passed for 2.0.1. Image fidelity remains an independent inspection responsibility; automated checks enforce the evidence record.
Release PR: #133
Workflow Toolkit 2.0.0
Workflow Toolkit 2.0.0
Workflow Toolkit is now a set of 12 self-contained Agent Skills installed through a skill installer. This is a breaking change from the former npm package installer. WTK no longer publishes an npm package or writes project AGENTS.md, provider configuration, or QA records.
Install
npx skills add antoniofulg/workflow-toolkit \
--skill wtk wtk-deep-review wtk-discover wtk-implement \
wtk-knowledge-check wtk-lean wtk-plan wtk-qa wtk-qa-execute \
wtk-qa-plan wtk-reuse-review wtk-ship \
--agent '*' --copy --yesThe full set is required; phase skills share the wtk core and other WTK references.
Upgrade from the old installer
Read the legacy cleanup guide before installing the skills. It limits deletion to verified installer-owned files and preserves project documentation, QA records, .specs/, custom instructions, and native agent settings.
Other changes
- Project-native agent files own provider, model, and effort settings.
.wtk.toml,wtk-config, generated provider packets, and the package migration helper are retired. - Ponytail, security lifecycle, and other companion skills are recommended independently, not bundled.
- Jev integrations are removed. QA
autostarts with Playwright MCP, then an available IDE-native adapter, then manual verification. - Deep Review runs on demand; remediation defaults to three consecutive stalls.
Release PR: #131
Workflow Toolkit 1.4.5
Fix
The guided installer now treats readline close as cancellation even when a pending question does not resolve. This preserves the no-write cancellation promise on Linux and macOS.
Upgrade
Run npx workflow-toolkit@1.4.5 install to update an adopted project. The npm description and GitHub homepage remain in the package metadata.
Validation
The exact release candidate passed bun run test:all on GitHub Ubuntu before this release, as well as locally: 96 Bun tests, 217 installer tests, and all Python suites. The attached workflow-toolkit-1.4.5.tgz archive contains 243 files and has SHA-256 de7a73da78524c14de9e63c62ff95c301bb071a1109ff84a70fa138634881a85.
Workflow Toolkit 1.4.4
Fix
The packed installer cancellation probe now sends PTY control signals without an extra carriage return. Its cancellation and zero-residue assertions pass on macOS and Linux.
Upgrade
Run npx workflow-toolkit@1.4.4 install to update an adopted project. The npm description and GitHub homepage remain in the package metadata.
Validation
The merged tree passed 96 Bun tests, 216 installer tests, and all Python suites locally. The focused packed-installer cancellation test also passed in a Node 22 Debian Linux container. The attached workflow-toolkit-1.4.4.tgz archive contains 243 files and has SHA-256 7b2f623bb902243f80a542e01b7e1b5afecccfd458e4e34b5888d24bd8d359b3.
Workflow Toolkit 1.4.3
Fix
The GitHub-hosted release test job installs expect before running the existing installer suite. This removes the Ubuntu runner prerequisite that blocked the first trusted-publishing run.
Upgrade
Run npx workflow-toolkit@1.4.3 install to update an adopted project. The npm description and GitHub homepage introduced in 1.4.2 remain included.
Validation
The merged release tree passed 96 Bun tests, 216 installer tests, and all Python suites locally. The attached workflow-toolkit-1.4.3.tgz archive contains 243 files and has SHA-256 94ffd0f0f91877c10d52b8ecf20d4a27cfce4b3ac98b11a34e8eedc99984c996.
Workflow Toolkit 1.4.2
Changes
- GitHub release publication now runs the full frozen test gate and automatically publishes the tested package to npm through a trusted OIDC publisher.
- The npm package has a clearer description and direct links to its GitHub source.
Upgrade
Run npx workflow-toolkit@1.4.2 install to update an adopted project.
Validation
The merged release tree passed 96 Bun tests, 216 installer tests, and all Python suites. The attached workflow-toolkit-1.4.2.tgz archive contains 243 files and has SHA-256 035f3b34ba18620e8d8e22b35dfffb72c176527ef201a06b84f317e60ec27670.
Workflow Toolkit 1.4.1
Changes
- Added
security-pentestto the core skill bundle for authorized runtime testing of web apps and APIs. - Updated Ponytail skill descriptions and Ponytail Help's npm/Homebrew update guidance.
- Recorded
wtk-deep-reviewas a local bundled skill and removed duplicate installation tests.
Upgrade
Run npx workflow-toolkit@1.4.1 install and review the managed skill updates.
Validation
The merged release tree passed 89 Bun tests and 216 installer tests. The attached workflow-toolkit-1.4.1.tgz archive contains 243 files and has SHA-256 fba720485a013f2419f3bfa59ef3eb598b5bd4cd96c6d3b25a43e0526e1b8b2c.
Workflow Toolkit 1.3.1
Fix duplicate Jev consultations when Workflow Toolkit and jev-gateway are used together.
- Confirmed gateway coverage takes precedence everywhere the integrations overlap: gateway A/B/C plus workflow adviser C/D/E becomes gateway A/B/C and adviser D/E.
- Use the explicit adviser only for decisions outside that coverage; a higher-level label does not justify a duplicate consultation. Gateway fallback does not trigger a second workflow call for the same decision.
- Standalone or disabled/unknown gateway routing retains the existing consultation behavior. Installation alone does not establish active routing.
- Approval, action, and verification authority remains unchanged.
Upgrade with npx workflow-toolkit@1.3.1 install. Launch sessions through your configured gateway and identify their routing state. This release does not install/configure the gateway or add a transport bypass. Live combined behavior and net token savings have not been benchmarked.
Validated by seven scoped hotfix checks plus a clean archived-package installation, byte readback, and standalone preview. The overlap clarification additionally passed three affected checks and refreshed archive byte readback. Runtime is unchanged.
Workflow Toolkit 1.3.0
Jev is now the default adviser for semantic decisions across planning, implementation, verification, review, QA, and shipping whenever available. A small core command returns typed recommendations, uncertainty, input fingerprints, and token usage. Existing agents retain action, approval, and gate authority.
Upgrade with npx workflow-toolkit@1.3.0 install. Reuse TYPESAFE_API_KEY from your caller environment or trusted ~/.config/workflow-toolkit/qa.env; the lifecycle adviser needs no browser or Vercel credential. Browser QA remains separately configured.
Validated with eight independent checks, five caught fault injections, a synthetic live API smoke, offline CLI QA, and a clean-package installation/readback. Actual host-agent compliance remains untested under the source QA policy, and net token savings have not been measured.
Workflow Toolkit 1.2.0
Workflow Toolkit 1.2.0 bundles the complete reviewed security lifecycle in every core installation: security-audit-coordinator, security-spec, security-threat-model, security-implementation, and security-review. The skills install offline through the normal preview, conflict, backup, rollback, alias, and adoption-manifest flow. The former standalone network installer is removed.
This release also makes browser QA default to the auto route: Jev, Playwright MCP, one declared Orca or Maestri adapter, then manual. Constructor-time Jev timeouts may fall back safely; later ambiguous or post-action timeouts remain fail-closed.
Migration: run npx workflow-toolkit@1.2.0 install and review the managed security-skill additions. Remove automation that invokes scripts/install_security_skills.py; no replacement step is required.