0.51.1 — Scheduled runs in auto mode, agents clean their own scratch
🤖 Scheduled runs start in auto mode
dispatch-agent.shstarts each run with--permission-mode auto --permission-prompts noneinstead of--dangerously-skip-permissions. Auto mode's own rules call that flag an unsafe way to start an agent loop.- The Index and memory MCP tools are allowed by rule, so the classifier never judges a board write or a memory call.
- Every refused action is written to the run log as one
Permission denied:line, sub-agents included. A headless run exits 0 even when actions were refused, so the log is the only place to see them. - Commands with no rule, such as
gh pr create, are now judged by the classifier. Check the logs after the first runs.
🧹 Agents clean up their own scratch
- Watson, Holmes, the lens helpers, and Lestrade make scratch under the session scratchpad, or
~/Developer/scratchpadwhen none is named. They delete it themselves before they report. - A refused delete is retried with the literal path. It is never handed to you as a
!command. - Each scheduled run's folder now lives in
~/Developer/scratchpadand is deleted when the run ends, including on failure. Runs no longer leave folders in$TMPDIR. agents/lint-scratch-cleanup.shchecks that the rule stays in place.
⬆️ Upgrade
- Update the plugin.
- Run
/workbench-dev-team:setup. It reinstallsdispatch-agent.sh, so scheduled runs use auto mode only after this step. - After the first scheduled runs, check for refusals with
grep '^Permission denied: ' ~/.claude-workbench/dev-team-logs/*.log.
Folders left in $TMPDIR by earlier runs are not removed.
Full Changelog: 0.51.0...0.51.1