Releases: teddashh/TokenMonster
Release list
TokenMonster 0.1.0-rc.22 — Codex/Claude 原始碼直啟 + 11 姊妹語音版
TokenMonster 0.1.0-rc.22 — Codex/Claude 原始碼直啟 + 11 姊妹語音版
把 repo 交給已安裝、已登入的 Codex 或 Claude Code,就能由 agent 走完受審核的 doctor、精確依賴驗證、build、啟動與前後 audit,直接開起同一個 Token Monster (AI-Sister) 桌面 app。單一 app、兩個入口,共用同一套安全 lifecycle,不維護兩套安裝檔。
Agent 從 repo 直接啟動
先關閉可能正在執行的已安裝版 TokenMonster,再把 repo 開在 agent 裡並明確呼叫:
- Codex:
$launch-tokenmonster start - Claude Code:
/launch-tokenmonster start
狀態與停止:
- Codex:
$launch-tokenmonster status/$launch-tokenmonster stop - Claude Code:
/launch-tokenmonster status//launch-tokenmonster stop
兩個入口都會:
- 先跑 content-blind before audit 與 doctor;
- 只在 repo 內按精確 lock 與隱藏 receipt 驗證依賴,必要時才執行受限的本機
npm ci; - 若 Electron native executable 尚未存在,只透過鎖定的 installer/checksums 取得官方、checksum-verified Electron 43.1.1;
- build scoped desktop dependency closure,啟動相同的 Electron app/runtime,再以 exact readiness marker 與 after audit 確認成功;
- 只管理這次 workflow 自己建立並以 PID + ownership token 綁定的 process tree。
它不會讀取、安裝、更新或修改 Codex / Claude Code 的 CLI、登入狀態、credentials、設定或 cache;不會裝全域套件或系統工具,也不會掃描或終止不屬於它的 process。Windows readiness 改用每次啟動由 policy 產生的 ephemeral local named pipe,同一連線只接受 strict bounded、capability-authenticated HELLO → 有序固定、content-blind 啟動階段 → exact READY,或固定且已消毒的 terminal startup failure;只有固定階段/failure 名稱會進 bounded safe lifecycle log,pipe ID、capability 與 raw channel bytes 都不會寫入 log 或持久化。這個通道不宣稱 same-user-only 或 remote-client rejection;既有的 local trust boundary 是同一 OS login。其他平台仍只接受 stdout 上的 exact readiness marker。
這是 source-development parity,會跑同一個產品 app/runtime、一般本機資料、角色與語音 authority;但不是 OS 安裝:沒有開始選單/桌面捷徑、「新增/移除程式」、installed auto-update、簽章或安裝檔 identity。需要這些整合時請用本頁的 TokenMonsterSetup.exe。
Linux 仍必須有可用的 Chromium user-namespace sandbox,或已正確設定為 root-owned mode 4755 的 Electron chrome-sandbox helper;doctor 不會加 --no-sandbox、提權或修改 host security。
11 姊妹、55 條預錄語音
完整角色媒體包現在固定為 ai-sister-media-11-voice55-2026.07.23:11 位角色、891 張圖片與 55 條 canonical WAV,共 946 個項目。只有使用者在 app 內充分揭露後明確同意,才會對 cdn.ted-h.com 發出一次、與角色/解鎖/用量無關的完整 fixed-pack GET;ZIP 與每個 entry 都逐 hash 驗證後存入本機 cache。
語音播放預設關閉,只從已驗證的本機 cache 播放,不會依角色、trigger 或 token 狀態逐檔連網。未同意、下載失敗、離線缺 cache 或移除 pack 時,四位 starter 的內建立繪與 168 條雙語文字照常運作,其餘回到 placeholder,語音保持靜音。
rc.21 功能完整保留
- 第一位姊妹以翻卡抽卡降生,保留「想自己挑也可以」;未降生角色不進名冊。
- 安裝檔、捷徑、工作列與系統匣維持四姊妹 icon 與「Token Monster (AI-Sister)」名稱。
- 衣櫥顯示真實解鎖條件、進度條與下一套提示。
- 點擊說話提示誠實化,啟動後幾秒內有第一句。
套件識別碼維持 TokenMonster;rc.19 / rc.20 / rc.21 可直接安裝 rc.22 原地升級,不必先移除。
Source: 2f72a49864d39b19c66397fb881f853ca7708e5c on tag v0.1.0-rc.22, CI run 30009176782. The embedded Squirrel updater is rebuilt reproducibly from source in the same CI run, byte-verified against reviewed SHA-256 83b754a9b24742675678c5d8fa024a8140c2d18eb640116a87a364f0a897388a (1,841,664 bytes), then the installer passes a native clean-install/start/uninstall smoke on Windows before upload.
安裝檔未簽章(測試版),Windows SmartScreen 會顯示警告;選「其他資訊 → 仍要執行」即可。正式簽章版會在取得程式碼簽章憑證後推出。
Windows x64 安裝
- 下載
TokenMonsterSetup.exe並雙擊執行。已有 rc.19 / rc.20 / rc.21 時直接安裝即可升級。 - 安裝後 Token Monster (AI-Sister) 會出現在系統匣,之後可從開始選單啟動。
- 移除:設定 → 應用程式 → TokenMonster → 解除安裝。
CLI 安裝
需求:Node.js 24.15.0 + npm 11.12.1。
npm install /path/to/tokenmonster-0.1.0-rc.22.tgz
npx tokenmonster驗證
sha256sum --check TokenMonster-release-SHA256SUMS.txt本 release 只包含 9 個標準資產:Windows setup、full nupkg、RELEASES、runtime notices、CLI tgz、CLI checksum、兩份 source provenance JSON,以及總 checksum。沒有額外 agent asset;Codex / Claude Code 的啟動 skills 已在 repo 內。
TokenMonster 0.1.0-rc.21 — 抽卡初遇與 AI-Sister 品牌版 (gacha first-meet & AI-Sister branding)
TokenMonster 0.1.0-rc.21 — 抽卡初遇與 AI-Sister 品牌版 (gacha first-meet & AI-Sister branding release)
第一次啟動時,你的第一位姊妹現在用抽卡降生:翻開卡片才知道是誰來到你身邊(想自己挑也可以)。整個桌面版同步換上 AI-Sister 品牌 — 四姊妹應用程式圖示、Token Monster (AI-Sister) 名稱、品牌等待畫面 — 衣櫥也會誠實告訴你每套服裝的解鎖條件與進度。 CLI 版本同步發布。
On first launch your first sister is now born through a card draw — flip the card to see who arrived (picking manually stays available). The desktop build also gets its AI-Sister identity: the four-sisters app icon, the Token Monster (AI-Sister) name, branded waiting screens — and the wardrobe now honestly shows each outfit's unlock condition and progress. The same-version CLI tgz ships alongside.
這版做了什麼 / What changed
- 抽卡初遇 / Gacha first-meet — 第一次進入名冊時不再直接列出四位姊妹:抽一張卡,讓緣分決定第一位降生的姊妹(ChatGPT/Claude/Gemini/Grok)。翻卡動畫、降生台詞、以及「想自己挑也可以」的手動入口都在;之後隨時可換人。未降生的姊妹不會出現在名冊裡。
- 衣櫥解鎖條件 / Wardrobe unlock conditions — 打開衣櫥,每套還沒解鎖的服裝現在顯示真實的解鎖條件與進度條(例如再累積多少本機 token 用量),並提示「下一套服裝」離你最近的一套。全部依本機用量自然解鎖,不消耗 token。
- AI-Sister 品牌 / AI-Sister identity — 應用程式圖示與安裝捷徑改為四姊妹合圖(打包時由內建核准立繪組成,不引入任何新繪圖);視窗、工作列與系統匣名稱統一為「Token Monster (AI-Sister)」;等待畫面文案改為「你的第一個 AI 伴侶快要出生了…」;過場不再出現任何非 AI-Sister 的替代圖。
- 點了會說話 / Tap-to-talk honesty — 角色提示現在誠實反映狀態(例如「點一下和 Grok 打招呼」),第一句話在啟動後幾秒內就會開口,不再沉默。
升級說明:安裝套件識別碼維持 TokenMonster,rc.19 / rc.20 直接安裝本版即可原地升級。
Upgrade note: the Squirrel package id stays TokenMonster, so rc.19 / rc.20 upgrade in place.
Source: cfd0b19e on tag v0.1.0-rc.21, CI run 29982059241. The embedded Squirrel updater is rebuilt reproducibly from source in the same CI run (Apache-2.0 Microsoft.Web.Xdt 3.1.0; receipt sha256 83b754a9…), byte-verified against the integration review, then the installer passes a native clean-install/start/uninstall smoke on Windows before upload. Third-party notices for the installer: MERGED-RUNTIME-NOTICES.md (attached).
安裝檔未簽章(測試版),Windows SmartScreen 會出現警告 — 按「其他資訊 → 仍要執行」即可;正式簽章版會在取得程式碼簽章憑證後推出。
The installer is an unsigned test build, so Windows SmartScreen shows a warning — click "More info → Run anyway"; a code-signed build follows once signing credentials exist.
桌面版安裝 / Desktop install (Windows x64)
-
下載
TokenMonsterSetup.exe,雙擊執行。SmartScreen 警告時選「其他資訊 → 仍要執行」。已裝 rc.19 / rc.20 的話直接安裝即可升級,不必先移除。 -
安裝完成後 Token Monster (AI-Sister) 會出現在系統匣;之後從開始選單啟動。
-
移除:設定 → 應用程式 → TokenMonster → 解除安裝。
-
Download
TokenMonsterSetup.exeand double-click it. On the SmartScreen warning choose "More info → Run anyway". If rc.19 / rc.20 is installed, installing rc.21 upgrades it in place — no uninstall needed first. -
Token Monster (AI-Sister) appears in the system tray after install; launch it from the Start menu afterwards.
-
Uninstall: Settings → Apps → TokenMonster → Uninstall.
CLI 安裝 / CLI install (Windows / macOS / Linux)
需求 / Requires: Node.js 24.15.0 + npm 11.12.1.
npm install /path/to/tokenmonster-0.1.0-rc.21.tgz
npx tokenmonster啟動後用瀏覽器開啟畫面上顯示的網址;遠端機器加 --no-open 並照畫面指示開 SSH tunnel。
Open the printed dashboard URL; on remote machines add --no-open and follow the SSH-tunnel instructions.
驗證 / Verify
sha256sum --check TokenMonster-release-SHA256SUMS.txtTokenMonster-windows-source-v1.json 與 TokenMonster-cli-source-v1.json 記錄來源 commit、CI run 與 smoked 平台。
The two *-source-v1.json files record the source commit, CI run, and smoked platforms.
內容 / Contents
桌面版與 CLI 內建 8 張核准 WebP 啟動圖與 168 條 zh-TW/en 固定文字;應用程式圖示在打包時由這些內建立繪組成,不含任何新增圖檔。完整 891 張圖的角色包只在程式內明確同意後從 cdn.ted-h.com 下載一次,之後離線可用、可修復或移除。語音檔尚未包含在任何資產包(語音素材備妥後隨後續版本推出)。所有用量資料留在本機;預設零對外連線。
Both builds embed 8 approved WebP starter images and 168 fixed zh-TW/en lines; the app icon is composed at package time from those embedded images, with no new artwork added. The full 891-image character pack downloads once from cdn.ted-h.com only after explicit in-app consent, then works offline and can be repaired or removed. Voice audio is not part of any pack yet (it ships in a later release once the voice assets are prepared). All usage data stays local; zero outbound connections by default.
TokenMonster 0.1.0-rc.20 — 桌面夥伴修正版 (desktop companion fix)
TokenMonster 0.1.0-rc.20 — 桌面夥伴修正版 (desktop companion fix release)
rc.19 桌面版的角色資產有接線 bug:內建啟動圖與完整角色包的下載通道都沒接到桌面進入點,所以四位起始姊妹全部退回字母替身、也看不到完整包的同意下載。這版修正了它,並讓字母人真正活起來。 CLI 版本不受該 bug 影響,本版同步發布。
rc.19's desktop build had an asset wiring bug: the embedded starter art and the consent-gated full-pack channel were never composed into the desktop entry point, so all four starter sisters fell back to letter mode and the full-pack download never appeared. This release fixes that and makes the letter companions actually alive. The CLI was unaffected; the same-version tgz ships alongside.
這版修了什麼 / What changed
- 真的有姊妹了 / Real starter art on desktop — 四位起始姊妹(ChatGPT/Claude/Gemini/Grok)安裝後直接顯示內建的核准立繪;完整 891 張圖的角色包(含 GLM 等 11 位角色)在程式內明確同意後下載一次,之後離線可用。
- 字母人活起來 / Letter companions are alive — 還沒有立繪的角色以字母替身顯示時,現在會隨風擺動、偶爾抖耳朵,並且每 45–90 秒自己說一句本機固定台詞(不用 API key、不連網、不消耗每日互動額度)。
- 用量面板可以捲動了 / Usage panel scrolls again — 寵物視窗展開用量統計後可以往下捲(修正 Chromium
::details-content佈局)。
Source: aec8f86b7dec6178f964c03cf250db8dcec02840 on tag v0.1.0-rc.20, CI run 29972563640. The embedded Squirrel updater is rebuilt reproducibly from source in the same CI run (Apache-2.0 Microsoft.Web.Xdt 3.1.0; receipt sha256 83b754a9…), byte-verified against the integration review, then the installer passes a native clean-install/start/uninstall smoke on Windows before upload. Third-party notices for the installer: MERGED-RUNTIME-NOTICES.md (attached).
安裝檔未簽章(測試版),Windows SmartScreen 會出現警告 — 按「其他資訊 → 仍要執行」即可;正式簽章版會在取得程式碼簽章憑證後推出。
The installer is an unsigned test build, so Windows SmartScreen shows a warning — click "More info → Run anyway"; a code-signed build follows once signing credentials exist.
桌面版安裝 / Desktop install (Windows x64)
-
下載
TokenMonsterSetup.exe,雙擊執行。SmartScreen 警告時選「其他資訊 → 仍要執行」。已裝 rc.19 的話直接安裝即可升級,不必先移除。 -
安裝完成後 TokenMonster 會出現在系統匣;之後從開始選單啟動。
-
移除:設定 → 應用程式 → TokenMonster → 解除安裝。
-
Download
TokenMonsterSetup.exeand double-click it. On the SmartScreen warning choose "More info → Run anyway". If rc.19 is installed, installing rc.20 upgrades it in place — no uninstall needed first. -
TokenMonster appears in the system tray after install; launch it from the Start menu afterwards.
-
Uninstall: Settings → Apps → TokenMonster → Uninstall.
CLI 安裝 / CLI install (Windows / macOS / Linux)
需求 / Requires: Node.js 24.15.0 + npm 11.12.1.
npm install /path/to/tokenmonster-0.1.0-rc.20.tgz
npx tokenmonster啟動後用瀏覽器開啟畫面上顯示的網址;遠端機器加 --no-open 並照畫面指示開 SSH tunnel。
Open the printed dashboard URL; on remote machines add --no-open and follow the SSH-tunnel instructions.
驗證 / Verify
sha256sum --check TokenMonster-release-SHA256SUMS.txtTokenMonster-windows-source-v1.json 與 TokenMonster-cli-source-v1.json 記錄來源 commit、CI run 與 smoked 平台。
The two *-source-v1.json files record the source commit, CI run, and smoked platforms.
內容 / Contents
桌面版與 CLI 內建 8 張核准 WebP 啟動圖與 168 條 zh-TW/en 固定文字;完整 891 張圖的角色包只在程式內明確同意後從 cdn.ted-h.com 下載一次,之後離線可用、可修復或移除。語音檔尚未包含在任何資產包(語音素材備妥後隨後續版本推出)。所有用量資料留在本機;預設零對外連線。
Both builds embed 8 approved WebP starter images and 168 fixed zh-TW/en lines; the full 891-image character pack downloads once from cdn.ted-h.com only after explicit in-app consent, then works offline and can be repaired or removed. Voice audio is not part of any pack yet (it ships in a later release once the voice assets are prepared). All usage data stays local; zero outbound connections by default.
TokenMonster 0.1.0-rc.19 — Windows desktop installer + CLI (public test)
TokenMonster 0.1.0-rc.19 — 第一個 Windows 桌面安裝檔 (first Windows desktop installer)
這版有 TokenMonsterSetup.exe:雙擊安裝的桌面寵物。 系統匣寵物 + token 用量儀表板 + BYOK 聊天,搭配同版 CLI tgz。安裝檔未簽章(測試版),Windows SmartScreen 會出現警告 — 按「其他資訊 → 仍要執行」即可;正式簽章版會在取得程式碼簽章憑證後推出。
This release ships TokenMonsterSetup.exe — the double-click desktop pet installer. Tray pet + token usage dashboard + BYOK chat, alongside the same-version CLI tgz. The installer is an unsigned test build, so Windows SmartScreen shows a warning — click "More info → Run anyway"; a code-signed build follows once signing credentials exist.
Source: 4a6066ab18cf37729585d9e823fb3f48eb416b0f on tag v0.1.0-rc.19, CI run 29962746132. The embedded Squirrel updater is rebuilt reproducibly from source in the same CI run (Apache-2.0 Microsoft.Web.Xdt 3.1.0; receipt sha256 83b754a9…), byte-verified against the integration review, then the installer passes a native clean-install/start/uninstall smoke on Windows before upload. Third-party notices for the installer: MERGED-RUNTIME-NOTICES.md (attached).
桌面版安裝 / Desktop install (Windows x64)
-
下載
TokenMonsterSetup.exe,雙擊執行。SmartScreen 警告時選「其他資訊 → 仍要執行」。 -
安裝完成後 TokenMonster 會出現在系統匣;之後從開始選單啟動。
-
移除:設定 → 應用程式 → TokenMonster → 解除安裝。
-
Download
TokenMonsterSetup.exeand double-click it. On the SmartScreen warning choose "More info → Run anyway". -
TokenMonster appears in the system tray after install; launch it from the Start menu afterwards.
-
Uninstall: Settings → Apps → TokenMonster → Uninstall.
CLI 安裝 / CLI install (Windows / macOS / Linux)
需求 / Requires: Node.js 24.15.0 + npm 11.12.1.
npm install /path/to/tokenmonster-0.1.0-rc.19.tgz
npx tokenmonster啟動後用瀏覽器開啟畫面上顯示的網址;遠端機器加 --no-open 並照畫面指示開 SSH tunnel。
Open the printed dashboard URL; on remote machines add --no-open and follow the SSH-tunnel instructions.
驗證 / Verify
sha256sum --check TokenMonster-release-SHA256SUMS.txtTokenMonster-windows-source-v1.json 與 TokenMonster-cli-source-v1.json 記錄來源 commit、CI run 與 smoked 平台。
The two *-source-v1.json files record the source commit, CI run, and smoked platforms.
內容 / Contents
桌面版與 CLI 內建 8 張核准 WebP 啟動圖與 168 條 zh-TW/en 固定文字;完整 891 張圖的角色包只在程式內明確同意後從 cdn.ted-h.com 下載一次,之後離線可用、可修復或移除。所有用量資料留在本機;預設零對外連線。
Both builds embed 8 approved WebP starter images and 168 fixed zh-TW/en lines; the full 891-image character pack downloads once from cdn.ted-h.com only after explicit in-app consent, then works offline and can be repaired or removed. All usage data stays local; zero outbound connections by default.
TokenMonster CLI 0.1.0-rc.18 — public test prerelease
TokenMonster CLI 0.1.0-rc.18 — 公開測試預發行 (public CLI test prerelease)
在終端機追蹤 Claude Code / Codex / Gemini 等 AI CLI 的 token 用量,並用瀏覽器開啟即時儀表板。這是第一個公開測試版:手動安裝 tgz、手動升級,尚未上 npm registry;桌面版安裝檔(含系統匣寵物)會在程式碼簽名與更新元件的再散布審查完成後跟上。
Track token usage across Claude Code / Codex / Gemini and other AI CLIs, with a live browser dashboard. First public test build: install the tgz by hand, upgrade by hand — not on the npm registry yet. The desktop installer (with the tray pet) follows once code signing and the updater-component redistribution review are complete.
Source: b7b9d7e84d809a7575d69bd73e50c23cbbf7db5e on tag v0.1.0-rc.18. Embedded version: 0.1.0-rc.18. CI cross-platform smoke: Linux x64, macOS arm64, Windows x64.
安裝(含 Windows)/ Install (Windows included)
需求 / Requires: Node.js 24.15.0 + npm 11.12.1.
npm install /path/to/tokenmonster-0.1.0-rc.18.tgz
npx tokenmonsterWindows PowerShell 相同:
npm install C:\path\to\tokenmonster-0.1.0-rc.18.tgz
npx tokenmonster啟動後用瀏覽器開啟畫面上顯示的 http://127.0.0.1:34567/__tokenmonster/bootstrap/… 網址;遠端機器請照畫面指示開 SSH tunnel。
Open the http://127.0.0.1:34567/__tokenmonster/bootstrap/… URL it prints; for remote machines follow the on-screen SSH-tunnel instructions.
驗證 / Verify
sha256sum --check TokenMonster-cli-SHA256SUMS.txt
sha256sum --check TokenMonster-cli-release-SHA256SUMS.txtTokenMonster-cli-source-v1.json 記錄來源 commit、releaseMode 與 CI smoked 平台。
TokenMonster-cli-source-v1.json records the source commit, releaseMode, and CI-smoked platforms.
內容 / Contents
內建 8 張核准 WebP 啟動圖(ChatGPT/Claude/Gemini/Grok 各一張 avatar 與一張 tech 基本服裝)與 168 條 zh-TW/en 固定文字。完整 891 張圖的角色包只會在程式內明確同意後,從 cdn.ted-h.com 下載一次,之後可離線使用、修復或移除。
Ships with 8 approved WebP starter images (one avatar plus one tech base outfit each for ChatGPT/Claude/Gemini/Grok) and 168 fixed zh-TW/en lines. The full 891-image character pack downloads once from cdn.ted-h.com only after explicit in-app consent, then works offline and can be repaired or removed.