- install_skill: adopt an existing skill from a local dir, SKILL.md,
.zip, or git URL; symlinks when the source already lives in a
recognized external skills folder (.claude/skills, .agents/skills)
instead of vendoring a duplicate, with install provenance recorded
per skill. Skill discovery now also reads those external folders
read-only, so skills placed by other tools are visible with no
install step at all.
- export_terminal_log: full tmux scrollback export, visible only
inside a live tmux session (TOOL_ENV_GATES, a new env-conditional
layer on top of the existing keyword-based lazy tool loading).
- Chunked lexical RAG (SQLite FTS5 + bm25, no vectors/embeddings):
new chunks table wired into record_save, shell/subagent output
spill, and terminal log export, searchable via the existing search
tool (kind chunk) with full chunk text returned, not just a
snippet. delete_record cleans up a record's chunks with it.
- Fix a regression where create_skill's default scope silently
became context-dependent instead of always "project".
- Rewrite README.md to document all of the above plus the existing
context/tool-selection and search/memory internals in depth.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
web_fetch is now a real HTTP client: methods, custom headers, string
bodies, configurable timeout, status plus content-type plus size on
every response, content-aware rendering (HTML to text, JSON raw),
and server error bodies surfaced on HTTP failures. Shell, schema
descriptions, and the system prompt steer all HTTP(S) to web_fetch;
curl/wget shell use earns a model-side hint instead of a refusal.
Shell output streams live in a rolling 4-line window for the active
agent only, with an exit line showing return code, elapsed time,
line count, and byte size. Workers, pipes, and capture stay silent.
Fixed step budget replaced by a progress budget: productive steps
(unseen actions, unseen results, user interaction) reset the stall
counter; identical repeats get a loop warning at 3 and a stop at 5;
wider stalls stop at the patience budget; 500-step total cap
backstops everything. 210 + 16 tests green.
Per-profile bots (system plus history, shared vault): create_bot with
nicknames, /bots and /bot with resume, @mention one-turn routing filed
in both histories.
Unified retrieval: one trigger-synced FTS5 index over records, events,
and audit with safe tokenized MATCH, porter stemming, BM25 rank, and
marked snippets. New search tool with kind filters and graph expansion;
recall, record_search, and audit rank through the same index.
Sealed search without weakening the seal: each boot decrypts events
into a :memory: FTS5 index (newest 10000, incrementally synced, never
on disk), so sealed stores rank like plaintext ones. LIKE fallback kept
for partial tokens. Documented in README under Sealed search with the
researched alternatives (SQLCipher, blind indexes, SSE) and rejections.
Also in this batch: sysinfo, create_skill, markdown renderer with
colors, scheduler with subagent rule, --yolo/--auto, denial-loop fix,
read-before-write guard, WAL plus timeouts, records/graph/spillover,
audit time travel, self-backup and releases, lazy skill blueprints,
smart tagging, profile isolation, lazy tool payload, install
subsystem, and multi-profile rotation fix. 176 + 16 tests green.