Skip to content

Ghost Hands v0.9.0

Choose a tag to compare

@littlestjames82-sys littlestjames82-sys released this 09 Oct 03:36

This release carries the three waves built since v0.6.0 — v0.7.0, v0.8.0, and v0.9.0 — plainly: an evaluation harness and Android gestures, human-readable audit reports and MCP parity, and a field kit for diagnosing the whole stack and proving the phone flow.

v0.9.0 — field kit

  • ghost-hands doctor — seven read-only checks covering the Python runtime, Chromium discovery, all four policy packs, model-key presence (presence only; values are never printed), GhostBus when configured, the Android phone bridge when configured, and adb. Every non-pass row includes a plain-language fix; JSON output is available.
  • ghost-hands phone-proof — the guided five-step on-device proof: configuration, adb forwarding, bridge status, the harmless test approval decided on the phone, and a summary with the exact next commands. Exit codes distinguish proven, error, needs-setup, and denied-or-timeout outcomes.

v0.8.0 — receipts + reach

  • ghost-hands report — render any trail JSONL as one self-contained HTML audit report: summary statistics, a step-by-step timeline, governor verdicts and approval channels, heals, dialogs, downloads, and network events. Page-controlled strings are escaped; password-shaped typed values are masked.
  • MCP parity — GHOST_HANDS_DRIVER=fake|chromium|simphone|android selects the MCP session body, and GHOST_HANDS_APPROVER=phone routes consequential-action asks through phone approval. Responses name the deciding channel.
  • seatbelt policy pack — a fourth policy pack whose governor-level deny_patterns deny injection-shaped targets regardless of action class, while benign near-misses remain allowed.

v0.7.0 — proof + depth

  • Model-evaluation harness — ghost-hands eval runs eight graded tasks, four on real Chromium, scoring success, steps, wall time, approximate perception tokens, actions by class, approvals, and heals. The deterministic stub suite passes 8/8 as harness proof; the RuleDecider baseline scores 3/8. A real-model run did not execute for this wave because no usable key was reachable in the build environment, so no model-quality number is claimed.
  • Android gestures — the Android body and MrGhosty v1.8.0 bridge support double_click, drag, and validated click_at in addition to the existing actions.
  • GhostBus file-store proof — the full bus demo and a parallel agent/poller barrage pass against a file-backed GhostBus store with zero HTTP 400s, closing the loop on the store fix shipped upstream in GhostBus 0.4.1. A broader many-simultaneous-writers read-modify-write characteristic remains documented in the changelog.

Verification

  • pytest: 395 passed
  • offline bench: 95/95
  • live bench: 2/2
  • zero runtime dependencies; Python standard library only

Full details are in the CHANGELOG for 0.7.0, 0.8.0, and 0.9.0.