Releases: opencapx/OpenCapX
Release list
OpenCapX 0.4.1
macOS 用户请先看这里 / macOS users read this first
macOS 构建未做代码签名与公证,首次打开会弹出「Apple 无法验证"OpenCapX"是否包含恶意软件」。这是预期行为,不是木马。 新版 macOS 上"右键 → 打开"已无法绕过;把应用拷入「应用程序」后,任选其一:
- 终端执行:
/usr/bin/xattr -cr /Applications/OpenCapX.app(用全路径,部分环境的PATH里xattr缺-r) - 系统设置 → 隐私与安全性 → 页面底部 → 仍要打开
The macOS build is not code-signed or notarized, so Gatekeeper shows "Apple cannot check 'OpenCapX' for malicious software" on first launch. This is expected, not malware. Run /usr/bin/xattr -cr /Applications/OpenCapX.app after copying the app to /Applications, or System Settings → Privacy & Security → Open Anyway. See INSTALL.md.
What's new
- Fixed phantom "in progress" sessions. Each omp tool-call check minted its own never-finishing working session — one omp run could show 16 in-progress sessions in the tray. Id-less payloads no longer create session rows, and the omp extension now identifies its real session. All other agent CLIs were audited and were never affected.
- Expired sessions are swept at startup. Short app runs (open, quit inside a minute) no longer leave dead sessions in the active table.
Full changelog: CHANGELOG.md
🤖 Generated with Claude Code
OpenCapX 0.4.0
macOS 用户请先看这里 / macOS users read this first
macOS 构建未做代码签名与公证(购买 Apple Developer 会员已推迟到有商业需求时),首次打开会弹出「Apple 无法验证"OpenCapX"是否包含恶意软件」。这是预期行为,不是木马。 新版 macOS 上"右键 → 打开"已无法绕过;把应用拷入「应用程序」后,任选其一:
- 终端执行:
/usr/bin/xattr -cr /Applications/OpenCapX.app(用全路径,部分环境的PATH里xattr缺-r) - 系统设置 → 隐私与安全性 → 页面底部 → 仍要打开
The macOS build is not code-signed or notarized, so Gatekeeper shows "Apple cannot check 'OpenCapX' for malicious software" on first launch. This is expected, not malware. The right-click → Open bypass no longer works on recent macOS; after copying the app to /Applications, run /usr/bin/xattr -cr /Applications/OpenCapX.app, or System Settings → Privacy & Security → Open Anyway. See INSTALL.md.
What's new
- Windows sandbox — AppContainer.
opencapx sandboxgains a third OS backend: the kernel isolation primitive Edge/Chrome use — a lowbox token with no user SID, granted per-run through ACLs and revoked when the run ends. No admin rights, no virtualization.--checkreportsbackend: appcontainer;--requirefinally has a real backend to require on Windows. Network fenced by the capability list (no capabilities = no sockets); timeouts kill a Job Object. Windows previously ran everything unguarded with a warning. - OS-permission preflight on every platform. The probes that tell you whether screen / camera / microphone built-ins can actually work now run on Windows and Linux too, with a new
unavailablestatus ("this machine cannot do this at all" vs "grant something first"), Linux session classification (X11 / Wayland / headless), and RDP monitor enumeration on Windows.
Full changelog: CHANGELOG.md
🤖 Generated with Claude Code
OpenCapX v0.3.0
See the assets to download and install this version.
OpenCapX v0.2.0
What's new
Install opencapx onto your PATH
- One click, from the tray or Settings — the tray menu shows Install opencapx Command while the command is missing (and drops the item once it is installed); Settings → General → Command line manages install/remove and shows the state. macOS asks for your password once when
/usr/local/binis root-owned. - From a terminal:
opencapx install-cli(anduninstall-cli). The installed command is a symlink to the app's stable copy at~/.opencapx/bin/opencapx, so it survives app moves, re-installs and updates. - This fixes the documented first step (
opencapx connect claude) not working on a fresh DMG install — the CLI used to be reachable only by its full path inside the app bundle.
A real CLI front door
opencapx --helplists every command with a description (it previously showed only the signing toolchain, no matter how much was added since); every subcommand documents its own flags (opencapx pack --help,opencapx sandbox --help, …); a typo errors with a suggestion instead of silently launching the app; andopencapx --versionexists.
Also in this release
- The commands themselves are unchanged:
connect,sandbox,rewrite,rules,guard,automation, and the plugin signing toolchain (keygen/pack/verify/verify-package/sign-index/verify-index). Agent hooks and MCP entries never needed the CLI install — they already point at the stable copy by absolute path.
OpenCapX v0.1.1
What's new
Bubble overhaul
- Position lifecycle fixed — the saved side applies at startup (no more one-second wrong layout and visible jump); changing pet size under a "bottom" layout recomputes the window height; near a monitor edge the bubble auto-flips to the other side so the pet stays put. New gap setting (0–24px) between pet and bubble.
- New themes: manga & blueprint — manga carries a heavy black outline, hard offset shadow and speed-line texture; blueprint is a printed cyanotype sheet with a white two-axis grid and dashed outline. 12 themes total, all persona phrases now localized (en / 简体中文 / Tiếng Việt).
- New mode: focus — promotes the single most urgent session (a waiting one outranks a working one) and counts the rest below the row, instead of rotating through everyone.
- Show Bubble tray toggle, side layouts scroll when an ask box outgrows the window, and number settings clamp to their real bounds.
Also in this release
opencapx sandboxexecutor pack (macOS seatbelt / Linux bubblewrap), thecurl … | shdanger guard, Oh My Pi (omp) host support, stable~/.opencapx/bin/opencapxCLI path in agent configs, session-start capability injection, and command-rule write-back for Factory Droid / Cursor / Copilot CLI.
Full changelog: CHANGELOG.md
Install
macOS (Apple Silicon): .dmg · Windows: x64-setup.exe / .msi · Linux: .deb / .rpm / .AppImage
macOS builds are unsigned — if Gatekeeper blocks the first launch, right-click the app and choose Open.
🤖 Generated with Claude Code
OpenCapX v0.1.0
See the assets to download and install this version.