You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
2.8.0 — Bounded agent loops and trusted external research
Added a selective engineering-loop skill for independent exploration, isolated implementation, integration, review, and evidence-based refinement.
Added a read-only GitHub researcher profile and upstream-content trust contract.
Added explicit $find-skills discovery with project-local, immutable provenance requirements and a dependency-free lock validator.
Strengthened provenance verification to bind each lock entry to a local skill directory and verify its complete content digest; broadened shell write detection for sed and find inspection commands.
Refreshed newcomer routing maps and the interactive playbook for bounded engineering loops, external skill discovery, and read-only GitHub research, and aligned CI action pins with their scanner versions.
Added a paired direct-versus-delegated benchmark protocol without claiming unavailable live-agent metrics.
Confined hook state and receipt paths to repository-local hashed namespaces, rejected symbolic-link escapes, strengthened immutable action-pin validation, and aligned the TruffleHog action wrapper with scanner v3.97.0.