Skip to content

v16.18.0

Choose a tag to compare

@dyoshikawa dyoshikawa released this 29 Aug 16:05
· 1308 commits to main since this release
Immutable release. Only release title and notes can be modified.
a17c788

What's Changed

New Tool Support

  • zcode: add ZCode (Z.ai) support for rules, commands, skills and MCP by @dyoshikawa in #2818
    • A new zcode target writing ZCODE.md and the .zcode/ tree, with project and global scope for rules, commands, skills and MCP. Subagents stay unsupported for now, because ZCode only discovers them under a global-only path that the subagents processor cannot yet express.

New Features

  • deepagents: sync the dcode shell allow list and fix the global directory by @dyoshikawa in #2824
    • permissions now translates Bash allow rules into dcode's shell.allow_list, reducing each rule to the executable name dcode actually compares. Entries that cannot survive that reduction — globs, shell metacharacters, quoted or backslash-escaped names, and names longer than 255 characters — are skipped with a warning instead of being silently widened, and import refuses the same spellings so a round trip loses nothing asymmetrically. Rules that rulesync cannot express as an allowlist (ask and deny) are reported rather than dropped in silence, including when they are shadowed by a wider allow.
    • The global deepagents directory is now written to the location dcode reads.
  • factorydroid: add the review-guidelines checks surface and settings follow-ups by @dyoshikawa in #2820
    • Factory Droid's .factory/review-guidelines/ directory is now a first-class checks surface with a single owner, so it is no longer half-claimed by the skills feature. Hand-authored review guidelines are preserved, machine-local imports are named, and the two autonomy override keys the prose omitted are documented.
  • fetch: mark skill names that cannot be told apart on sight by @dyoshikawa in #2810
    • The interactive skill picker now flags remote skill names that are visually confusable with one another — mixed-script and whole-script lookalikes, invisible characters, punctuation and width lookalikes, and case-folding collisions — so a fetched skill cannot impersonate a neighbour in the list. Labels are measured in terminal columns rather than code points, so wide characters no longer break the layout.
  • fetch: prune stale files inside fetched skill directories by @dyoshikawa in #2802
    • Re-fetching a skill now removes files the remote skill no longer ships, instead of leaving them behind. The prune judges each candidate by the file it actually is, refuses remote paths that resolve to two different local paths, stands down when the fetched listing is knowingly incomplete, and reports every deletion legibly.
  • vibe: support nested AGENTS.md, managed-shell and MCP tool permissions by @dyoshikawa in #2779
    • Vibe rules can now be written as nested AGENTS.md files, and permissions covers Vibe's managed-shell tables and MCP tool categories, including fanning a Bash decision out to every managed shell while leaving hand-authored shell tables intact.
  • permissions: let the roo target author its own roo-cline command lists by @dyoshikawa in #2791
    • The roo alias now writes roo-cline.allowedCommands / deniedCommands itself instead of inheriting the Zoo Code spelling, and emission fails closed in both directions when a pattern cannot be expressed as a command prefix.
  • mcp: carry Rovo Dev enable_instructions and point global mcpConfigPath by @dyoshikawa in #2793
    • The per-server enable_instructions key no longer leaks across targets, and the global-scope mcpConfigPath pointer is now written, with a warning that tells a user with a withheld file what to do.
  • mcp: let musecode author the documented per-server mode key by @dyoshikawa in #2788
    • Meta Muse Code's documented per-server mode key is now authorable, and an undocumented mode is dropped rather than leaked to other tools.
  • hooks: let pi beforeSubmitPrompt hooks cancel the prompt by @dyoshikawa in #2773
    • Pi's prompt gate can now block a submission and report why, with the block reason sanitized and bounded so it stays valid UTF-16 when truncated.

Behavior Changes

  • subagents: write agentsmd subagents to the cross-vendor .agents/agents/ root by @dyoshikawa in #2774
    • The simulated agentsmd subagent writer emitted .agents/subagents/, a directory no documented AGENTS.md-era client scans, so its output was inert. It now writes .agents/agents/ — the root Antigravity discovers workspace agents in, and the one Kimi Code reads alongside its own tree — using the same serialization as the native Antigravity targets, so the file on disk is identical whichever target runs last. Stale outputs under the old path stay gitignored via a hand-maintained entry. If you generated agentsmd subagents before this release, the files under .agents/subagents/ are now orphaned and can be deleted.
  • generate: exit non-zero when a .rulesync source fails to load by @dyoshikawa in #2800
    • generate previously reported success and exited 0 when a .rulesync source file failed schema validation. It now fails loudly, and distinguishes an absent source from an unreadable and from an unparseable one. CI that relied on the old exit code will now see the failure it was hiding.
  • fetch: start the interactive skill prompt with nothing selected by @dyoshikawa in #2782
    • The interactive skill picker no longer pre-selects every skill, so fetching installs only what was deliberately chosen.

Bug Fixes

  • generate: stop targets sharing an output directory from deleting each other's files by @dyoshikawa in #2776
    • Tree ownership is now decided structurally and each written file is claimed, so two targets that share an output directory no longer sweep each other's output. A generated skill directory named . or .. is rejected.
  • generate: refuse to sweep a directory outside the root it was found in by @dyoshikawa in #2806
    • The orphan sweep is anchored to the processor's own output root, runs the positional backstop after the ownership check, and never sweeps a shared root this run wrote nothing into.
  • skills: enumerate skill directories with readdir instead of a glob by @dyoshikawa in #2803
    • Skill enumeration no longer reads glob metacharacters out of the project's own path, keeps hidden entries out, and takes each skill's real name from the directory entry rather than from its path.
  • skills: sweep orphan takt knowledge files on --delete by @dyoshikawa in #2807
    • Takt's flat knowledge files are now swept when they are orphaned, without touching the shared facet root.
  • generate: stop --delete from removing the shared takt facet root by @dyoshikawa in #2784
  • permissions: reject blank and prototype-named permission patterns by @dyoshikawa in #2798
    • Blank patterns are filtered from tool-scoped blocks too, a category emptied by that filter is removed rather than written empty, and import warns when it drops one.
  • vibe: honor disabled_tools glob spellings on import by @dyoshikawa in #2817
    • disabled_tools globs are walked rather than translated to regexes, matching upstream's entry normalization, class chunking and deny ordering.

Other Changes

Contributors

Full Changelog: v16.17.0...v16.18.0