Releases: stark-ai-de/agent-skills
Releases · stark-ai-de/agent-skills
Release list
v0.12.0
Added
- Added a dependency-free, root-bounded static-PNG and animated-GIF exporter for trusted repository-owned README logo recipes, with non-exporting contract checks, strict XML and artifact inspection, commit-time no-clobber protection, exact per-frame GIF timing validation, sanitized failures, deterministic fake-tool coverage, and transactional replacement.
- Added explicit target-contract and install-host data to the generated catalog so contract-backed cross-host installs are discoverable without changing runtime-specific artifacts.
- Added focused Claude and Cursor lifecycle evals with competing interviewer skills and repository-owned persistence checks.
Changed
- Updated
animated-readme-logoto 0.4.0 so product repositories retain only brand-specific source, motion, timing, palette, and path decisions while the skill owns reusable export mechanics. - Updated
drawio-diagramsto 0.4.0 with default native animation for new directed runtime, process, and data flows, explicit opt-out, a technical-geominimalist default plus four bounded adaptive design profiles, bounded reference-style adaptation, architecture content gating, compact ER/UML/C4/BPMN/SysML/ML notation recipes, icon-first logo/service coverage, Lobe Icons and Simple Icons provider routing, a single user-responsibility rights notice, improved local shape search, conditional discovery, bounded three-pass self-review, and a fair head-to-head benchmark protocol. - Updated
claude-spec-interviewerandcursor-spec-interviewerto 0.2.2 so planning, question, transition, and plan-exit instructions follow the execution host while target-specific evidence and execution output remain unchanged. - Updated incubator
skillopt-setupto 0.1.1, keeping the Codex OpenAI-compatible gateway local to that workflow until reuse and isolation justify extraction. - Updated incubator
handoffto 0.1.1 with agent-neutral trigger wording.
Fixed
- Superseded ADR-0026 with ADR-0028 so both proven reuse and fail-closed backend isolation are required before a gateway can be extracted from its owning skill.
- Removed natural-language directive classification from validation; OpenAI prompts now use a small fail-closed foreign-control-name check.
- Made complete skill frontmatter validation YAML-aware, including nested metadata, comments, quoted keys, and flow mappings.
- Parsed
agents/openai.yamlas YAML before validating nested types and checking the resolved default prompt. - Separated target runtime from installation host throughout catalog labels and commands, synchronized the documented host-ready install sets with the portable public catalog, and required every generated install command to have a host-specific accessible copy label.
- Hardened
drawio-diagramsexport verification so exit-zero Desktop runs cannot publish missing, stale, symlinked, structurally invalid, or concurrently changed artifacts; both outputs validate before commit, destination installation is no-clobber, and interrupted or replacement commits preserve recovery backups instead of deleting raced data. Portable-image validation now checks every HTML/CSS/srcset source, rejects missing and fragment-only image cells plus obfuscated active schemes, ignores navigation links, and stays in parity with SkillOpt. Also removed unsupported Desktop Mermaid-import and--layoutassumptions, corrected eval regexes, and added guarded implicit-activation coverage. - Hardened
animated-readme-logoexport with descriptor-bound output-parent creation, cumulative frame-byte limits, two complete deterministic render passes with verified-byte reuse, digest-bound multi-output commits, and retained replacement recovery that cannot delete same-inode concurrent updates. - Fixed SkillOpt Codex CLI target, judge, and reflector prompt transport to use explicit UTF-8 stdin, redact prompt echoes from captured streams, and reap large no-read timeouts, so large skill/resource snapshots no longer exceed argument limits or leak through process arguments and logs.
Deprecated
Removed
Security
- Kept fail-closed filesystem, process, tool, network, and environment isolation mandatory for every extracted or shared backend gateway.
v0.11.0
Added
Changed
- Updated
animated-readme-logoto 0.3.0 with an approval-gated minimal exporter preflight and a configured Chromium/agent-browserpreview fallback before any browser download.
Fixed
- Separated browser-preview failures from raster-export readiness and provider approval from local-tool installation approval.
Deprecated
Removed
Security
v0.10.1
Added
- Added ADR-0026 guidance that separates the executing client from the target agent ecosystem, keeps independently valuable skills unconstrained by catalog size, and leaves backend gateways with their owning workflow until reuse and isolation are proven.
- Added real disposable Codex, Cursor, and Claude Code destination-install smoke coverage plus live Claude- and Cursor-target-on-Codex activation evidence.
Changed
- Updated
claude-spec-interviewerto0.2.1so cross-host execution adapts planning and question controls without changing Claude Code evidence or output artifacts. - Updated
cursor-spec-interviewerto0.2.1with execution-host control translation and a matching OpenAI default prompt, and updatedarchitecture-compassto0.2.1with valid concise OpenAI metadata. - Made catalog install commands target-correct by category and replaced manual Claude skill copies with supported
-a claude-codeinstallation commands.
Fixed
- Validated every existing
agents/openai.yamlfile and rejected OpenAI prompts that require foreign-host-only planning or question controls.
Deprecated
Removed
Security
v0.10.0
Added
- Added once-per-task stable update checks for the selected CodeGraph/ast-grep analysis stack, with one itemized per-tool approval checkpoint, offline and opt-out handling, versioned actions, verification, and rollback disclosure.
- Added capability guidance for current and legacy CodeGraph releases, a focused optional-tool escalation guide, and expanded eval scenarios for update consent, runtime boundaries, legacy behavior, native LSP fallback, advanced codemods, security-policy routing, and bounded rewrites.
- Added deterministic
codegraph-ast-grepcontract validation, command-safety regression fixtures, and machine-regraded captured behavioral evals to the repository validation pipeline.
Changed
- Updated
codegraph-ast-grepto0.2.0with installed-help-first command selection, consolidated semantic exploration when exposed, watcher-aware graph freshness, capability-gated ast-grep outline, evidence reconciliation, and reviewed rewrite staging. - Reworked setup for exact package or checksum-verified release provenance, reproducible project-local launches, effective
CODEGRAPH_DIRhandling, and explicit Codex, Cursor, Claude Code, and generic MCP configuration boundaries. - Expanded Claude Code install documentation to include the portable
codegraph-ast-grepworkflow.
Fixed
- Removed unconditional assumptions about
codegraph_trace, CLIexplore,codegraph init -i, universal auto-sync, npm-only CodeGraph installation, and unpinned persistent ast-grep MCP execution. - Separated analysis-tool binary/package updates from runtime configuration refresh, prompt hooks, telemetry choices, graph operations, and unrelated application dependency updates.
- Made project-local ast-grep verification fail closed instead of allowing npm to fetch a missing command, and required affirmative approval before project-opening CodeGraph diagnostics that may migrate generated state.
- Preserved Team-pinned CodeGraph update scope and made native Windows checks, updates, and verification restore prior process environment state after telemetry/config guards.
Deprecated
Removed
Security
- Prevented automatic or blanket tool updates, pipe-to-execution installer defaults, unreviewed optional-tool installs, and rewrite snapshot/update-all shortcuts.
- Required stable-source provenance, exact update scope, checksum/build-policy disclosure, redaction, telemetry-disabled update checks unless separately approved, and explicit approval for every side-effect class.
v0.9.1
Added
- Added a concise public SkillOpt run summary for the accepted
drawio-diagramsrouting and readability optimization.
Changed
- Updated
drawio-diagramsto require explicit orthogonal waypoints around text and callout obstacles and to report validator names, connector rails, label backgrounds, and label spacing for dense diagrams.
Fixed
Deprecated
Removed
Security
v0.9.0
Added
- Promoted
animated-readme-logo0.2.0 with live Recraft V4.1 discovery and cost approval, a deterministic local SVG fallback, explicit task/provider/export statuses, and README-safe delivery guidance. - Added dependency-free strict SVG and GIF/APNG/WebP inspection with hidden-metadata rejection, a focused animated-logo fixture harness, and reusable bounded visual assertions shared with draw.io evaluation.
Changed
- Kept animated-logo routing portable across Codex, Cursor, Claude, and other Agent Skills hosts; provider capability and output contracts drive the route instead of agent-specific forks.
- Refactored draw.io visual evaluation behind a reusable six-assertion library without changing its public grammar.
Fixed
- Made README logo audits resolve assets inside an explicit repository root, parse bounded live Markdown/HTML image references, verify SVG and raster content, enforce meaningful reduced-motion/static fallbacks, and report readiness without fabricating unavailable artifacts.
Deprecated
Removed
Security
- Rejected absolute, UNC, root-escaping traversal, encoded scheme/entity, duplicate-attribute, and symlink-escaped README asset paths before reading files.
- Rejected symlinked or oversized visual-artifact trees, active/foreign/metadata-bearing SVG content, hidden raster metadata, and non-regular animated-image inputs before release proof.
v0.8.0
Added
- Added capability-detected Codex, Cursor, Claude, and unknown-host collaboration adapters to the portable
architecture-compassworkflow. - Added Architecture Compass lifecycle evaluation cases for conditional planning, ADR conflicts, stack deviations, fallbacks, no-write decision phases, bounded execution, audits, and PR reviews.
Changed
- Updated
architecture-compassto use a read-only planning phase for unresolved durable choices or broad, multi-boundary, behavior-changing, or phased refactors while keeping narrow behavior-preserving ADR-backed work direct, audits read-only, and diff reviews on the host review surface. - Added explicit planning, read-only-enforcement, architecture-decision, and execution fields; a pending-write-permission gate; exact route-matching continuations; and repository-state rechecks before approved changes are applied.
- Documented portable Architecture Compass installation and usage for Codex, Cursor, and Claude.
Fixed
- Replaced the release workflow's cross-runtime wildcard verification command with the explicit Codex-ready public skill list.
- Fixed SkillOpt split generation to preserve wrapped expected-behavior bullets instead of truncating semantic judge requirements.
- Corrected Cursor Plan evidence classification so behavioral no-write instructions are not reported as an enforced filesystem sandbox.
Deprecated
Removed
Security
v0.7.0
Added
- Added the incubating
skillopt-setupworkflow with local Microsoft SkillOpt installation and readiness checks, per-skill train/validation/test preparation, provider-backed, hybrid, and Codex CLI execution profiles, run artifact verification and summaries, and guardedbest_skill.mdadoption. - Added a local
.agents/artifact audit and a loopback-only Codex-backed OpenAI Chat Completions gateway with an end-to-end compatibility probe for SkillOpt experiments. - Added deterministic draw.io visual-eval support with six PNG/SVG artifact cases, fixture-backed assertions, generated full and text-only split variants, page-index export,
DRAWIO_BINoverrides, anddiagrams.netexecutable discovery. - Added runtime-specific native Plan-mode lifecycle and fallback eval coverage for the Codex, Cursor, and Claude spec interviewers.
- Added
drawio-diagramsarchitecture-readability guidance and eval coverage for connector-label gutters, fan-out lanes, hierarchy, whitespace, dark-mode labels, and logo fidelity. - Added repository validation for SkillOpt helper and adapter contracts and draw.io visual assertions.
Changed
- Updated all three public spec interviewers to require native Plan mode when supported, route transitions through each host's native controls, use structured clarification when available, and record conversational fallback only when Plan mode is unavailable or explicitly declined.
- Made Plan-mode interviewing read-only and moved approved spec and required ADR persistence to a save-only continuation after mode exit that stops before feature implementation.
- Strengthened SkillOpt setup and readiness reporting with strict training-ready checks, target/mode/profile-specific fresh manifests, active-split data floors, explicit model and credential blockers, and visual renderer readiness.
- Expanded
drawio-diagramsXML authoring, routing, theming, icon, and verification guidance to improve dense architecture readability and preserve real logo artwork. - Updated public usage examples for each runtime's native Plan-mode lifecycle.
Fixed
- Fixed save-only spec-interviewer persistence so a required ADR also receives the minimal index entry mandated by the repository's existing convention, while all other repo-facing documentation remains deferred to implementation.
- Fixed
drawio-diagramsconnector-crossing validation to honor explicit waypoints and side ports and calculate nested cell bounds before warning about callout overlaps. - Fixed draw.io visual assertion globs so Markdown escapes such as
\*.pngand\*.svgretain wildcard semantics in both JavaScript and Python matchers. - Fixed SkillOpt readiness to score the configured active split, ignore
Nonevisual sentinels, reject missing configured split directories, and block stale or mismatched adapter manifests. - Fixed generated SkillOpt case metadata to distinguish
text-onlyexecution fromisolated-artifact-writevisual execution instead of advertising legacy broad workspace writes.
Deprecated
Removed
Security
- Isolated every Codex-backed SkillOpt target, judge, and reflection launch with strict network-disabled permissions and minimal runtime reads; visual cases alone receive bounded temporary-workspace artifact writes, with protected control output and symlink rejection.
- Restricted the bundled Codex gateway to loopback-only, text-only operation that denies workspace reads and rejects all writes, host config/rules, inherited environments, and profiles; it also terminates full Codex process trees on success, timeout, or client disconnect. Remote deployment remains prohibited without OS/container host-read isolation.
- Hardened provider endpoint probes, optimized-skill adoption, and local-artifact promotion against leaked URL/auth secrets, raw transcripts and private paths, stale proof, and regressing test scores.
- Pinned release publication and annotated tags to the exact validated
maincommit, making the workflow fail closed ifmainadvances between readiness and publication.
v0.6.2
Added
Changed
Fixed
- Fixed
drawio-diagramsroute-crossing validation so transparent text boxes and callouts are still treated as connector obstacles. - Added regression coverage for connectors crossing transparent
fillColor=nonecallouts.
Deprecated
Removed
v0.6.1
Added
- Added strict XML preflight and browser URL helper coverage to the public
drawio-diagramsskill. - Added
drawio-diagramsrules for real-logo defaults, icon source cascades, connector routing, fixed-aspect logos, and simplified/detailed diagram views. - Added business AI workflow lookup terms to the
drawio-diagramsicon catalog for AI, automation, ERP/CRM, cloud, data, delivery, and security icon needs.
Changed
- Expanded
drawio-diagramssetup, delivery, verification, and icon-catalog guidance with concrete commands and curated style starters. - Updated
drawio-diagramsto ask for missing-logo fetch approval during initial setup and to use simplified icons consistently when approval or sources are unavailable.
Fixed
- Hardened
drawio-diagramsregression coverage for forbidden XML constructs, icon catalog smoke checks, and browser URL generation. - Added diagram-rule regression coverage for floating semantic edges and distorted image/logo cells.