v16.18.0
·
1308 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
What's Changed
New Tool Support
- zcode: add ZCode (Z.ai) support for rules, commands, skills and MCP by @dyoshikawa in #2818
- A new
zcodetarget writingZCODE.mdand the.zcode/tree, with project and global scope for rules, commands, skills and MCP. Subagents stayunsupportedfor now, because ZCode only discovers them under a global-only path that the subagents processor cannot yet express.
- A new
New Features
- deepagents: sync the dcode shell allow list and fix the global directory by @dyoshikawa in #2824
permissionsnow translates Bash allow rules into dcode'sshell.allow_list, reducing each rule to the executable name dcode actually compares. Entries that cannot survive that reduction — globs, shell metacharacters, quoted or backslash-escaped names, and names longer than 255 characters — are skipped with a warning instead of being silently widened, andimportrefuses the same spellings so a round trip loses nothing asymmetrically. Rules that rulesync cannot express as an allowlist (askanddeny) are reported rather than dropped in silence, including when they are shadowed by a widerallow.- The global deepagents directory is now written to the location dcode reads.
- factorydroid: add the review-guidelines checks surface and settings follow-ups by @dyoshikawa in #2820
- Factory Droid's
.factory/review-guidelines/directory is now a first-classcheckssurface with a single owner, so it is no longer half-claimed by the skills feature. Hand-authored review guidelines are preserved, machine-local imports are named, and the two autonomy override keys the prose omitted are documented.
- Factory Droid's
- fetch: mark skill names that cannot be told apart on sight by @dyoshikawa in #2810
- The interactive skill picker now flags remote skill names that are visually confusable with one another — mixed-script and whole-script lookalikes, invisible characters, punctuation and width lookalikes, and case-folding collisions — so a fetched skill cannot impersonate a neighbour in the list. Labels are measured in terminal columns rather than code points, so wide characters no longer break the layout.
- fetch: prune stale files inside fetched skill directories by @dyoshikawa in #2802
- Re-fetching a skill now removes files the remote skill no longer ships, instead of leaving them behind. The prune judges each candidate by the file it actually is, refuses remote paths that resolve to two different local paths, stands down when the fetched listing is knowingly incomplete, and reports every deletion legibly.
- vibe: support nested AGENTS.md, managed-shell and MCP tool permissions by @dyoshikawa in #2779
- Vibe rules can now be written as nested
AGENTS.mdfiles, andpermissionscovers Vibe's managed-shell tables and MCP tool categories, including fanning a Bash decision out to every managed shell while leaving hand-authored shell tables intact.
- Vibe rules can now be written as nested
- permissions: let the roo target author its own roo-cline command lists by @dyoshikawa in #2791
- The
rooalias now writesroo-cline.allowedCommands/deniedCommandsitself instead of inheriting the Zoo Code spelling, and emission fails closed in both directions when a pattern cannot be expressed as a command prefix.
- The
- mcp: carry Rovo Dev
enable_instructionsand point globalmcpConfigPathby @dyoshikawa in #2793- The per-server
enable_instructionskey no longer leaks across targets, and the global-scopemcpConfigPathpointer is now written, with a warning that tells a user with a withheld file what to do.
- The per-server
- mcp: let musecode author the documented per-server mode key by @dyoshikawa in #2788
- Meta Muse Code's documented per-server
modekey is now authorable, and an undocumented mode is dropped rather than leaked to other tools.
- Meta Muse Code's documented per-server
- hooks: let pi
beforeSubmitPrompthooks cancel the prompt by @dyoshikawa in #2773- Pi's prompt gate can now block a submission and report why, with the block reason sanitized and bounded so it stays valid UTF-16 when truncated.
Behavior Changes
- subagents: write agentsmd subagents to the cross-vendor
.agents/agents/root by @dyoshikawa in #2774- The simulated
agentsmdsubagent writer emitted.agents/subagents/, a directory no documented AGENTS.md-era client scans, so its output was inert. It now writes.agents/agents/— the root Antigravity discovers workspace agents in, and the one Kimi Code reads alongside its own tree — using the same serialization as the native Antigravity targets, so the file on disk is identical whichever target runs last. Stale outputs under the old path stay gitignored via a hand-maintained entry. If you generated agentsmd subagents before this release, the files under.agents/subagents/are now orphaned and can be deleted.
- The simulated
- generate: exit non-zero when a
.rulesyncsource fails to load by @dyoshikawa in #2800generatepreviously reported success and exited0when a.rulesyncsource file failed schema validation. It now fails loudly, and distinguishes an absent source from an unreadable and from an unparseable one. CI that relied on the old exit code will now see the failure it was hiding.
- fetch: start the interactive skill prompt with nothing selected by @dyoshikawa in #2782
- The interactive skill picker no longer pre-selects every skill, so fetching installs only what was deliberately chosen.
Bug Fixes
- generate: stop targets sharing an output directory from deleting each other's files by @dyoshikawa in #2776
- Tree ownership is now decided structurally and each written file is claimed, so two targets that share an output directory no longer sweep each other's output. A generated skill directory named
.or..is rejected.
- Tree ownership is now decided structurally and each written file is claimed, so two targets that share an output directory no longer sweep each other's output. A generated skill directory named
- generate: refuse to sweep a directory outside the root it was found in by @dyoshikawa in #2806
- The orphan sweep is anchored to the processor's own output root, runs the positional backstop after the ownership check, and never sweeps a shared root this run wrote nothing into.
- skills: enumerate skill directories with
readdirinstead of a glob by @dyoshikawa in #2803- Skill enumeration no longer reads glob metacharacters out of the project's own path, keeps hidden entries out, and takes each skill's real name from the directory entry rather than from its path.
- skills: sweep orphan takt knowledge files on
--deleteby @dyoshikawa in #2807- Takt's flat knowledge files are now swept when they are orphaned, without touching the shared facet root.
- generate: stop
--deletefrom removing the shared takt facet root by @dyoshikawa in #2784 - permissions: reject blank and prototype-named permission patterns by @dyoshikawa in #2798
- Blank patterns are filtered from tool-scoped blocks too, a category emptied by that filter is removed rather than written empty, and
importwarns when it drops one.
- Blank patterns are filtered from tool-scoped blocks too, a category emptied by that filter is removed rather than written empty, and
- vibe: honor
disabled_toolsglob spellings on import by @dyoshikawa in #2817disabled_toolsglobs are walked rather than translated to regexes, matching upstream's entry normalization, class chunking and deny ordering.
Other Changes
- revert: remove the scheduled Dependabot auto-merge workflow (#2702) by @dyoshikawa in #2778
Contributors
Full Changelog: v16.17.0...v16.18.0