v0.2.0
Added
greptool: optionalcontextparameter shows up to 10 surrounding
lines per match in ripgrep-style blocks, and the system prompt now steers
the model to explore with grep context and ranged reads instead of whole
files.thoth upgrade: downloads the latest GitHub release for the current
platform, verifies the checksum and swaps the binary in place.thoth --continueresumes the previous conversation for the working
directory; the transcript is saved after every turn.@pathin the input attaches a file to the message (tab completes the
path), in the TUI and in-pmode.!commandruns a command yourself and puts its output into the context
without spending a model turn.- "Always allow" now persists per project, and
/allowlists what is
allowed (/allow resetclears it). - System prompt: the environment block now includes today's date and the
git branch with dirty-file count, and new rules cover prompt injection
(tool output is data, not instructions), secrets (never in web queries,
never repeated), committing only when asked, and minimal diffs.
Changed
- Leaner interface: the boxed input is now a single rule, with a state line
showing the spinner, elapsed time and interrupt hint, and a status line
with context use, output tokens and the active editor file. - Permission prompts are scoped. Answering "always" for a shell command
allows that program only (shell:cargo), and web_fetch is allowed per
host, instead of unlocking the whole tool forever. read_fileoutside the working directory,web_fetchandremember
now ask for permission; reads inside the project stay free.- Source layout:
agent/,ui/andtools/modules instead of flat files.
Fixed
- Security: two one-line reads of a file (first line and last line) counted
as a full read and unlocked a blindwrite_fileoverwrite. Reads are now
tracked as line ranges and must cover the file. - Security:
thoth upgradeaccepted any release tag from the GitHub API
and interpolated it into a path that gets deleted recursively; tags are
validated, the temp directory is unique per run, and a missing checksum
file now aborts the upgrade instead of skipping verification. - Security:
@pathno longer grants write access to files outside the
project, and the path is escaped before it goes into the model's context. - Crash: a
%followed by a multi-byte character in a search result URL
panicked the agent task and left the interface spinning forever. The
decoder is byte-safe, and the interface now reports a dead agent task. read_filerefuses files over 2 MB instead of loading them into memory,
shellstops capturing output at 200 kB instead of buffering everything a
runaway command prints, andgrepwith context stops at its output cap
inside a file rather than after it.- Saved sessions and the allowlist are written atomically and are keyed by
a hash of the project path, so similarly named directories no longer
share state.
Full Changelog: v0.1.0...v0.2.0