diff --git a/.claude-plugin/marketplace.json b/.claude-plugin/marketplace.json index 6b37068..7debbb2 100644 --- a/.claude-plugin/marketplace.json +++ b/.claude-plugin/marketplace.json @@ -11,7 +11,7 @@ "homepage": "https://github.com/Drix10/agent-flow", "name": "agent-flow", "source": "./", - "version": "1.1.4" + "version": "1.1.5" } ] } \ No newline at end of file diff --git a/.claude-plugin/plugin.json b/.claude-plugin/plugin.json index 202e266..fc9b111 100644 --- a/.claude-plugin/plugin.json +++ b/.claude-plugin/plugin.json @@ -15,5 +15,5 @@ "license": "MIT", "name": "agent-flow", "repository": "https://github.com/Drix10/agent-flow", - "version": "1.1.4" + "version": "1.1.5" } \ No newline at end of file diff --git a/.github/workflows/harness-flags.yml b/.github/workflows/harness-flags.yml new file mode 100644 index 0000000..6ada6cc --- /dev/null +++ b/.github/workflows/harness-flags.yml @@ -0,0 +1,30 @@ +name: Harness flags + +# Installs each harness CLI and checks that the flags launch.md relies on still appear in its --help. +# No API keys, no model calls. Weekly, because these CLIs change without notice. +on: + schedule: + - cron: "17 4 * * 1" + workflow_dispatch: + pull_request: + paths: ["skills/invoking-agents/**", "scripts/check-harness-flags.mjs", ".github/workflows/harness-flags.yml"] + +jobs: + flags: + strategy: + fail-fast: false + matrix: + os: [ubuntu-latest, windows-latest] + runs-on: ${{ matrix.os }} + steps: + - uses: actions/checkout@v4 + - uses: actions/setup-node@v4 + with: + node-version: 22 + - name: Install harness CLIs (best effort) + shell: bash + run: | + for p in @anthropic-ai/claude-code @openai/codex @google/gemini-cli @earendil-works/pi-coding-agent; do + npm install -g "$p" || echo "::warning::could not install $p" + done + - run: node scripts/check-harness-flags.mjs diff --git a/CHANGELOG.md b/CHANGELOG.md index d369b9b..d17d141 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,7 +4,37 @@ All notable changes to this project are documented here. Format: [Keep a Changel ## [Unreleased] +## [1.1.5] - 2026-10-01 + +- Read each vendor's hook docs and source and fixed what they contradicted: Gemini's hook now matches every tool (the allow-list named a tool that doesn't exist and missed others); Cursor's Windows BOM on stdin no longer makes the guard fail open, and Cursor's Delete tool counts as a write; the OpenCode plugin is one flat file with no SDK import (v1 and v2 load it; it no longer writes `.opencode/package.json` or depends on `@opencode/plugin`). `docs/HARNESS-MATRIX.md` says, per harness, what is live-verified and what is docs-verified only, with the caveats each vendor's docs give (untrusted folders, fail-open exits, headless modes). + +- Codex guard hook live-verified on Linux/WSL (protected write, `--no-verify` commit and hook-config write all blocked); docs note that Codex's bypass-hook-trust / full-access options disable enforcement. +- Guard: PowerShell writes are judged like their POSIX twins — named parameters in any order (`-LiteralPath`, `-Destination`, …), Windows `\` paths, `Copy-Item` writes only its destination, and .NET `[IO.File]::Write*` calls count as writes. A live Codex-on-Windows probe found `Set-Content -LiteralPath .codex/hooks.json …` slipped through. +- Guard blocks also print a JSON deny (`permissionDecision`) on stdout besides exit 2 + stderr; set `AGENT_FLOW_GUARD_JSON_ONLY=1` to deny by JSON with exit 0 (experiment for a harness that ignores exit 2). +- `agent-flow sandbox [--ro] [--no-net] [--hide-home] [--allow