Skip to content

v0.5.4 — SkillContext, skill chains, CLI themes, and deceptive_ui_guard v2

Choose a tag to compare

@rosspeili rosspeili released this 03 Sep 16:19
· 47 commits to main since this release

Skillware 0.5.4 ships SkillContext for one-line multi-skill host wiring, named skill chains in YAML with CLI validation and dry-run, configurable CLI presentation themes, and a major deceptive_ui_guard v0.2.0 upgrade — plus docs, examples, and manifest-driven tool dispatch fixes for agent loops.

Install: pip install skillware==0.5.4 or pip install -U skillware or just pip install skillware

Update from 0.5.3: pip install -U skillware — no breaking framework API changes; new core helpers, CLI subcommands, and bundled skill upgrade only. Re-run pip install -e . if you use an editable clone so new CLI entrypoints (context, chain) are registered.


Added

SkillContext and named skill chains (#330, #297, #332)

Registry hosts can now load, filter, and run skills without hand-rolling discovery, prompt merge, and tool adapters on every loop.

  • SkillContext — discovery filters (categories, tags, skills), progressive disclosure modes (brief, directives, tools_only), prepare() / execute(), merge_system(), tools(), and provider helpers (ollama_prompt, etc.)
  • Named chains — declare chains: in .skillware.yaml / global config; run_chain(name, input) with step when: conditional skip
  • CLI — skillware context show; skillware chain list|show|validate|run|dry-run
  • Docs — Skill chaining and registry context (closes #297)
  • Examples — examples/skill_context_gemini_loop.py, examples/sanitize_input_chain_demo.py; ollama_skills_test.py refactored to SkillContext
from skillware import SkillContext

ctx = SkillContext(categories=["security"], mode="brief")
ctx.prepare()
result = ctx.execute("security/prompt_injection_firewall", {"text": user_input})
# .skillware.yaml
chains:
  sanitize_then_scan:
    steps:
      - skill: security/input_sanitizer
      - skill: security/prompt_injection_firewall
        when: "steps[0].output.is_safe == false"

Host simulation stress coverage

23-scenario stress suite (tests/test_host_simulation_stress.py) exercises SkillContext and chain edge cases for registry hosts.


Changed

CLI presentation themes (#248, #305)

  • User-configurable pastel, ocean, and mono themes
  • Interactive menu selection persists globally; project config can override; unknown values fall back to pastel
  • Mail submenu and direct mail commands follow the active theme

security/deceptive_ui_guard v0.2.0 (#314, #327)

Major skill upgrade:

  • DOM zone classification (checkout, modal, cmp, navigation, general) with severity multipliers
  • KB allowlists (screen-reader accessibility, CMP consent banners, SEO metadata)
  • Expanded taxonomy (prechecked opt-ins, drip pricing, fake scarcity timers, nag loops)
  • Mobile profile heuristics, session fingerprint tracking
  • Optional Playwright computed-style render diffing lane
  • 23 golden HTML test corpus fixtures

Docs ripple

SkillContext modes, edge cases, and Ollama multi-skill guidance in skill_chaining.md, ollama.md, introduction.md, cli.md; one-line chain pointers on middleware skill catalog pages.

Security support windows

  • >= 0.5.4 — patched (security reports accepted here)
  • 0.4.6 – 0.5.3 — silent band (no security fixes; upgrade recommended)
  • < 0.4.6 — unsupported (CLI advisory)

Fixed

  • Examples: Derive agent-loop tool dispatch names from the loaded manifest in claude_tos_evaluator.py, ollama_tos_evaluator.py, and ollama_novelty_extractor.py (#178, #329)

What's possible today

Capability How
Multi-skill host context SkillContext(categories=[...]).prepare()
Named pipelines chains: in YAML + run_chain("name", input)
Inspect context skillware context show --categories security
Validate / dry-run chains skillware chain validate my_chain / skillware chain dry-run my_chain
CLI themes skillware config → presentation theme, or set in config YAML
Deceptive UI v2 SkillLoader.load_skill("security/deceptive_ui_guard") (v0.2.0)
Full registry + framework pip install "skillware[all]" or pip install -e ".[dev,all]" for development

Upgrade notes

  • No breaking loader or skill contract changes since 0.5.3
  • New exports: from skillware import SkillContext
  • New CLI subcommands: context, chain — reinstall editable installs (pip install -e .) so entrypoints refresh
  • Chain dry-run does not simulate real skill outputs; when: steps are evaluated against placeholder step results
  • deceptive_ui_guard bumped to v0.2.0 in the bundled registry — review catalog diff if you pinned behavior on v0.1.0 heuristics
  • Citing: Zenodo concept DOI 10.5281/zenodo.21552745 stays stable; record Skillware 0.5.4 for reproducibility (CITATION.cff updated)

Full changelog

CHANGELOG.md — 0.5.4


Contributors

Thanks to everyone who landed work since v0.5.3:


Citation

Zenodo concept DOI: 10.5281/zenodo.21552745 — record Skillware v0.5.4 for reproducibility (CITATION.cff updated).