v1.18.0
harness-bootstrap
Changed
-
Process is now proportional to the change. Until now every change ran the same route: through
the orchestrator, decomposed into tasks, with a reviewer pass after each agent. For a one-line
backend fix that meant a planning pass, a task file, a test agent and two reviewers before
anything landed - slow enough that people stop reaching for the harness on small work, which is
most work.AGENTS.mdnow carries a tier table, read before anything is dispatched:- Direct - one module, reversible, no contract, schema, auth, payment or infrastructure
touched. The owning agent is called straight. No orchestrator, no task file. - Standard - one domain, several files, or an FR behind it. Still the owning agent; a task
file only when the work has to survive a compacted session. - Guarded - two or more domains, or schema, auth, money, a public contract, a migration, a
deploy, or personal data. The orchestrator, and the full flow.
Choosing a heavier tier than the change needs is now stated to be a defect, not caution.
- Direct - one module, reversible, no contract, schema, auth, payment or infrastructure
-
The orchestrator hands back work it should not have taken. Its description and its dispatch
section both say so: a single-domain assignment off the Guarded list is named back to the seat
that owns it. Decomposing anyway is pure overhead - every sub-task is a dispatch, a brief, a board
row and a log entry. -
Gates run once, on the branch, not after every agent.
/review-changesis that boundary. A
reviewer dispatched after each agent re-reads the same files once per agent and reports the same
findings each time, which is most of what made a small change feel expensive. Security review
belongs to that boundary and to any moment you ask for it; it is no longer a per-task step, and
security-reviewer,code-reviewerandreviewereach say so in their own description. -
The orchestrator waits instead of checking. It no longer polls a running agent for progress,
and it no longer re-derives a finished agent's conclusion to satisfy itself that the work
happened. When the agent reports, the check is on the result and it is one call:git statusand
git diff --statanswer "did this land, in the files it said". The full diff is read for a
Guarded change, or when the stat disagrees with the report. -
The other half of that trust: dev agents report evidence, not status. Nobody re-runs their
work to find out whether it happened, so a bare "done" is no longer a result. The seat names the
files it changed, the criterion each change satisfies, the command whose output proves it, and -
explicitly - whatever it could not verify.
spec-builder
No functional change in this release. The version moves with harness-bootstrap: the two skills
always share one number.
Tools
Downloadable builds for Windows, macOS and Linux are attached to this release.
harness-view
Added
- A roster editor. A seat's
model,effort,toolsanddescriptioncan be edited from the
graph, with pickers backed by a reference of four vendors (Claude Code, OpenAI Codex, Gemini CLI,
Z.AI GLM). Every model and tool carries averifiedflag, and unverified entries are marked
wherever they appear. The reference is yours to change: additions, edits and deletions are stored
per repository in.claude/state/references.jsonand merged over the shipped seed, so an upgrade
never loses them and the shipped file is never written. A seed entry'sverifiedalways comes
from the seed - an override can correct a label, not promote or demote a claim. - The Command Steps panel became an editor. Autocomplete for agent names, rule files, hook names
and relative paths; steps can be inserted at any position; markdown inside a step renders, tables
included, and shows its source again when you edit it. - Frontmatter writes touch only the keys that changed. The body below the frontmatter is copied
through byte for byte; unknown keys, comments, blank lines and key order all survive, and CRLF
stays CRLF.
Changed
- Custom dialogs and toasts replace the browser's
alertandconfirm, with focus trapping,
focus restored on close, and an accessible name on every icon-only button. Every button carries an
icon. - Disabling a rule, hook or command no longer collapses the detail panel: the selection survives the
reload.
Install
unzip harness-bootstrap-v1.18.0.zip -d ~/.claude/skills/unzip spec-builder-v1.18.0.zip -d ~/.claude/skills/- Verify with
sha256sum -c SHA256SUMS