v0.5.4 — SkillContext, skill chains, CLI themes, and deceptive_ui_guard v2
Skillware 0.5.4 ships SkillContext for one-line multi-skill host wiring, named skill chains in YAML with CLI validation and dry-run, configurable CLI presentation themes, and a major deceptive_ui_guard v0.2.0 upgrade — plus docs, examples, and manifest-driven tool dispatch fixes for agent loops.
Install: pip install skillware==0.5.4 or pip install -U skillware or just pip install skillware
Update from 0.5.3: pip install -U skillware — no breaking framework API changes; new core helpers, CLI subcommands, and bundled skill upgrade only. Re-run pip install -e . if you use an editable clone so new CLI entrypoints (context, chain) are registered.
Added
SkillContext and named skill chains (#330, #297, #332)
Registry hosts can now load, filter, and run skills without hand-rolling discovery, prompt merge, and tool adapters on every loop.
SkillContext— discovery filters (categories,tags,skills), progressive disclosure modes (brief,directives,tools_only),prepare()/execute(),merge_system(),tools(), and provider helpers (ollama_prompt, etc.)- Named chains — declare
chains:in.skillware.yaml/ global config;run_chain(name, input)with stepwhen:conditional skip - CLI —
skillware context show;skillware chain list|show|validate|run|dry-run - Docs — Skill chaining and registry context (closes #297)
- Examples —
examples/skill_context_gemini_loop.py,examples/sanitize_input_chain_demo.py;ollama_skills_test.pyrefactored toSkillContext
from skillware import SkillContext
ctx = SkillContext(categories=["security"], mode="brief")
ctx.prepare()
result = ctx.execute("security/prompt_injection_firewall", {"text": user_input})# .skillware.yaml
chains:
sanitize_then_scan:
steps:
- skill: security/input_sanitizer
- skill: security/prompt_injection_firewall
when: "steps[0].output.is_safe == false"Host simulation stress coverage
23-scenario stress suite (tests/test_host_simulation_stress.py) exercises SkillContext and chain edge cases for registry hosts.
Changed
CLI presentation themes (#248, #305)
- User-configurable
pastel,ocean, andmonothemes - Interactive menu selection persists globally; project config can override; unknown values fall back to
pastel - Mail submenu and direct mail commands follow the active theme
security/deceptive_ui_guard v0.2.0 (#314, #327)
Major skill upgrade:
- DOM zone classification (checkout, modal, cmp, navigation, general) with severity multipliers
- KB allowlists (screen-reader accessibility, CMP consent banners, SEO metadata)
- Expanded taxonomy (prechecked opt-ins, drip pricing, fake scarcity timers, nag loops)
- Mobile profile heuristics, session fingerprint tracking
- Optional Playwright computed-style render diffing lane
- 23 golden HTML test corpus fixtures
Docs ripple
SkillContext modes, edge cases, and Ollama multi-skill guidance in skill_chaining.md, ollama.md, introduction.md, cli.md; one-line chain pointers on middleware skill catalog pages.
Security support windows
- >= 0.5.4 — patched (security reports accepted here)
- 0.4.6 – 0.5.3 — silent band (no security fixes; upgrade recommended)
- < 0.4.6 — unsupported (CLI advisory)
Fixed
- Examples: Derive agent-loop tool dispatch names from the loaded manifest in
claude_tos_evaluator.py,ollama_tos_evaluator.py, andollama_novelty_extractor.py(#178, #329)
What's possible today
| Capability | How |
|---|---|
| Multi-skill host context | SkillContext(categories=[...]).prepare() |
| Named pipelines | chains: in YAML + run_chain("name", input) |
| Inspect context | skillware context show --categories security |
| Validate / dry-run chains | skillware chain validate my_chain / skillware chain dry-run my_chain |
| CLI themes | skillware config → presentation theme, or set in config YAML |
| Deceptive UI v2 | SkillLoader.load_skill("security/deceptive_ui_guard") (v0.2.0) |
| Full registry + framework | pip install "skillware[all]" or pip install -e ".[dev,all]" for development |
Upgrade notes
- No breaking loader or skill contract changes since 0.5.3
- New exports:
from skillware import SkillContext - New CLI subcommands:
context,chain— reinstall editable installs (pip install -e .) so entrypoints refresh - Chain dry-run does not simulate real skill outputs;
when:steps are evaluated against placeholder step results - deceptive_ui_guard bumped to v0.2.0 in the bundled registry — review catalog diff if you pinned behavior on v0.1.0 heuristics
- Citing: Zenodo concept DOI
10.5281/zenodo.21552745stays stable; record Skillware 0.5.4 for reproducibility (CITATION.cffupdated)
Full changelog
Contributors
Thanks to everyone who landed work since v0.5.3:
- @rosspeili — SkillContext and named skill chains (#330, #332, #297); docs, examples, and host stress tests; example manifest tool dispatch fix (#178, #329); deceptive_ui_guard catalog sync (#327); release cut
- @harshthakur3 — CLI presentation themes (#248, #305)
- @tusharjamunkar — deceptive_ui_guard v0.2.0 skill upgrade (#314, #327)
Citation
Zenodo concept DOI: 10.5281/zenodo.21552745 — record Skillware v0.5.4 for reproducibility (CITATION.cff updated).