Releases: coco-research/coco
Release list
CoCo v1.2.0 — two new skills and a security pass
The first release since v1.1.0 on 2026-07-18. Two new skills, and a security pass across the installer, the CI workflows, and the funding configuration.
Added
coco-loop turns a plain-language goal into a readable charter that you confirm, then arms and runs a bounded autonomous loop in propose-only mode. It never commits on its own. It needs the coco-loops framework, which the skill now links with install steps.
scroll-world builds an immersive scroll-scrubbed landing page: a pre-rendered camera flies from outside each scene into its interior, then on to the next with no cuts, as one continuous flight. Contributed upstream by cyw under MIT, with the original licence retained at skills/scroll-world/LICENSE.
Security
Most of this work is by @imachiever (Rajat Bhatia), and it is worth reading if you install CoCo via the one-line bootstrap.
- The bootstrap installer now asks before it runs.
bin/coco-bootstrap.shclones first, prints the commit hash, date and message, and waits for explicit confirmation before executinginstall.sh. The default is fail-closed. OnlyCOCO_BOOTSTRAP_YES=1or--yesskips it. - GitHub Actions are pinned to commit SHAs with workflows scoped to
permissions: contents: read. Pins targetactions/setup-nodev7 andactions/setup-pythonv5, each verified to exist upstream and to match the commit its tag points to. - A DOM cross-site-scripting vector was fixed in the brainstorming helper, which built its selection indicator by concatenating a label into
innerHTML. - The Cursor adapter installer was hardened.
link_dir()could silently overwrite a real file, and aA && B || Cpattern could execute a real command when a dry-run echo failed. - The funding configuration was corrected.
.github/FUNDING.ymlstill referencedrkz91, the account name used before the 2026-07-18 rename tococo-research. An unrelated third party had since registered the vacated username. No funds could have been misdirected, because that account has no Sponsors listing, but the window is now closed. The same stale references were removed from the installer, where one was the documentedcurl-pipe-to-bashcommand. - A Content-Security-Policy was added to the generated diagram artifacts, CVE floor versions were raised in the
openai-apps-mcptemplate, andfind-skillsnow requires a resolved package name to be surfaced and confirmed before an agent installs anything on your behalf.
Counts
Asset counts now match the tree exactly: 149 skills (66 core plus 83 across bundles), 867 addressable assets, 126 in a core install. Spec Version is 1.2.0.
Install
bash <(curl -fsSL https://raw.githubusercontent.com/coco-research/coco/main/bin/coco-bootstrap.sh)You will be shown the commit you are about to install and asked to confirm.
Upgrading from v1.1.0? Nothing breaks. There are no schema or contract changes, so an existing install can update in place.
v1.1.0 — CoCo Super Intelligence + open-core
Changed
- Rebranded to CoCo Super Intelligence — the 389-persona advisory board leads as the hero capability; new brand lockups and social card.
- Migrated to the
coco-researchGitHub org — URLs, npm scope (@coco-research/coco-cli), Homebrew tap, and publish workflows. - Relicensed to open-core — core stays MIT; the Super Intelligence System (
systems/superintelligence/) is now proprietary (source-available, all rights reserved). Forward-only: MIT grants on prior releases remain valid for those snapshots.
Fixed
- Corrected asset counts (skills 146 → 147, etc.).
- Expanded attribution in CREDITS.md.
Full changelog: https://github.com/coco-research/coco/blob/v1.1.0/CHANGELOG.md
Coco v1.0.0
Coco v1.0.0 — first stable release
The 1.0 milestone: a full Superintelligence advisory board, a privacy-respecting update notifier, and docs that match the code.
Highlights
- Superintelligence board — 389 personas across 9 teams. Engineering (70), AI (59), Product & Design (56), Finance (47), Trading (46), Risk & Compliance (30), Strategy (29), Data & Analytics (29), Sales/GTM/Marketing (23), plus a cross-team meta-orchestrator that picks a 16–32 person panel across domains.
- 242 Superintelligence slash commands generated on install — 225 per-team (
/SI-<Team>-<Verb>) + 17 cross-team (/SI,/SI-Orchestrate,/SI-Decide, …). Generators are now path-portable. - Update notifier.
npx @rkz91/coco-cli versionorbash scripts/check-update.shtells you when a newer Coco is out. Checks the source repo only, cached 24h, no telemetry, opt out withCOCO_NO_UPDATE_CHECK=1. - Docs accuracy pass. Corrected
/schedule+/loopframing (host-CLI features),vscode-continueadapter status, and added Staying Current + Contributing sections.
Install
git clone https://github.com/rkz91/coco.git && cd coco && bash install.sh
# or
npm install -g @rkz91/coco-cliAsset totals (full install)
142 skills · 277 slash commands · 34 agents · 4 system bundles · 15 cross-IDE rules · 3 workflows · 389 personas.
See CHANGELOG.md for the full list.
Coco v0.1.0 — initial public OSS release
First public release of Coco. MIT licensed.
Highlights
- 59 skills across foundational, PM, engineering, design, ops, and meta domains
- 34 namespaced slash commands (team, email, design, eng, pm, util)
- 10 specialized subagents (code-reviewer, pm-advisor, mcp-specialist, refactoring-specialist, test-guardian, typescript-pro, ui-ux-designer, ai-engineer, data-specialist, database-architect)
- 3 system bundles —
gsd(68 orchestration skills + 24 GSD subagents),brain(6 knowledge skills),team(multi-agent pipelines) - 4 stable IDE adapters — Claude Code, Cursor, Codex CLI, Generic AGENTS.md
- Single-entry installer with auto-detection —
bash install.sh - npm wrapper —
package.jsonshipped (publish to npm pending) - Homebrew formula —
Formula/coco.rbshipped (tap repo pending)
Install
```bash
git clone https://github.com/rijulkalra2000/coco.git && cd coco && bash install.sh
```
Add orchestration bundles:
```bash
bash install.sh --systems gsd,brain,team
```
Documentation
- Getting started
- Quickstart cookbook
- Migration from raw prompts
- Comparison vs alternatives
- Architecture
Built on
- obra/superpowers — 15 foundational skills
- gsd-build/get-shit-done — 68-skill GSD orchestration framework
- JCodesMore/ai-website-cloner-template — clone-website
- Anthropic Skills spec
- agents.md spec
See CHANGELOG.md for full release notes.
Coming in v0.2
- VS Code adapter (via Continue)
- Antigravity adapter
- INDEX auto-regen in CI
- Skill creation wizard