The
[0.7.0]section below was silently rewritten in place by the commit
that produced most of this release (a883cec, #71), attributing this
release's own not-yet-shipped identity completion to the already-tagged
v0.7.0— whose immutable GitHub Release body still carries the original
wording. Restored verbatim here; the corrected, actually-new text moves to
this section, where an upgrader reading release notes will actually see it.
Changed
-
BREAKING: the
prd-spec-generatorplugin identity and release alias are
gone.v0.7.0kept the product and Claude/Codex/Gemini plugins under the
prd-spec-generatorname while only the MCP Registry entry and primary
bundle moved toai-architect-mcp-spec; this release finishes the
migration started there. The product, full-pipeline skill,
Claude/Codex/Gemini plugins, MCPB asset, and Registry entry are now all
ai-architect-mcp-spec; noprd-spec-generatorplugin or.mcpbrelease
alias is retained. Existing callers must replace the
prd-spec-generator:generate-prdskill qualifier with
ai-architect-mcp-spec:generate-prd, and anyone depending on the
prd-spec-generator.mcpbrelease asset must switch to
ai-architect-mcp-spec.mcpb—release.ymlno longer publishes the legacy
alias or its checksum. The internal@prd-gen/*workspace packages,
PRD_GEN_*environment variables,.prd-gendata directory, andprd-gen
MCP server/tool namespace remain stable protocol and storage identifiers;
none of them was ever a published plugin or marketplace identity, so none
of them changes here. (#71) -
BREAKING: the affected-symbols sidecar is now emitted (with empty
arrays) whenevertechnical_specificationran and found zero claims,
instead of being omitted. A docs-only or infra-only PRD that legitimately
produces no code-level claims was previously indistinguishable, by file
presence alone, from "extraction never ran."ai-architect-mcp-codebase
stages/stage-6.mdkeys its regex-fallback decision on the sidecar
file's absence, not on an empty payload — a consumer relying on the old
omit-when-empty behavior to detect "extraction didn't run" will now see the
file present with empty arrays for a zero-claims PRD. The
technical_specificationprompt was also corrected to always emit the
affected-symbols block, since the previous prompt instructed the model to
omit it when nothing was touched, masking the zero-claims signal at the
source. Source:ai-architect-mcp-codebasestages/stage-6.md, "Zero-claims
case — not the same as absent" (§4.2), pinned at commit
92216cd90f8f26cb15348675fc6556b8293edfc1. (#80) -
ecosystem-adapters' upstream client is renamed
AutomatisedPipelineClient→AiArchitectCodebaseClient, matching the
upstream server's own rename (automatised-pipeline→
ai-architect-mcp-codebase), with its config type and source file renamed
to match. The class is exported from@prd-gen/ecosystem-adapters, but
that workspace package is"private": trueand has never been published —
it has no consumer outside this repo, so the rename is not breaking for any
external caller. Self-referential doc comments that still called this
projectprd-spec-generator(its own former name) were also corrected.
(#78, closes #75) -
@modelcontextprotocol/sdk1.29.0 → 1.30.0;mcp-server/index.jsrebuilt
from source against the updated types. Existing test suites pass
unmodified. (#79)
Fixed
- The codebase-intelligence tool prefix pointed at a revoked plugin
spelling.ai-architect-mcp-codebaserenamed its server key to
ai-architect(canonical since its own v0.9.0), so the correct prefix is
mcp__plugin_ai-architect-mcp-codebase_ai-architect__. This repo still
named the pre-rename spelling inSKILL.md,EXAMPLES.md, and
preflight.ts's remediation text; the host silently drops calls to an
unresolvable tool name rather than raising, socall_pipeline_tool
returned nothing and the pipeline continued as if the call had succeeded.
mcp-tool-prefixes.test.ts's hand-copied allowlist carried the same dead
spelling, so the gate that should have caught this would have rejected the
fix; the allowlist moved in the same commit as the two call sites it
guards. A stalecortex@cortex-pluginsreference in the same remediation
text (that plugin renamed tohypermnesia-mcpin v4.15.0) was corrected
alongside it rather than left as the next silent failure. (#73)
Security
- Raise
fast-urito 3.1.5, the first patched version for
GHSA-7p8r-x3mc-p8w7, and rebuild the committed MCP bundle. - Raise
honoto 4.12.34, the first patched version for
GHSA-8j4g-w8fx-2239, and rebuild the committed MCP bundle. A production-tree
pnpm auditreports zero remaining vulnerabilities after both updates.
Docs
- Add
CLAUDE.mdwiring this repo into the global zetetic agent rules
(~/.claude/rules/model-behavior.md,coding-standards.md). (#76)
Canonical .mcpb bundle
Artifact: ai-architect-mcp-spec.mcpb
SHA-256: 1e21c45f00b4eb3874ebf5290e52bf593aa38226b197d0c4a3dc261e54362b6a