Commit Graph
41 Commits
Author SHA1 Message Date
Evan 102b506b0b fix(agents,hands): per-agent/per-hand mcp_servers / skills allowlists (#87) (#92)
All 32 agent manifests and 17 hands shipped with empty mcp_servers /
skills lists, which the kernel interprets as "no filter" — every
globally-configured MCP server's tools and every installed skill get
injected into the prompt on every LLM call. On a typical instance (9
MCP servers, ~85 MCP tools + ~82 built-in tools) that's ~50k input
tokens per turn spent on definitions the agent never uses.

Changes
-------

32 agents/*/agent.toml:
  - mcp_servers: 1-4 per agent. memory wherever state persists across
    turns; fetch / exa-search / brave-search only where the prompt
    actually calls for web; git / github / filesystem on engineering
    agents; gmail / google-calendar / linear / jira on productivity
    agents whose prompts mention them.
  - skills: per-role allowlist driven by what the system_prompt names
    (e.g. coder → rust/python/typescript/git/shell-scripting; devops-
    lead → docker/kubernetes/terraform/ansible/ci-cd/helm/prometheus/
    sysadmin). Generalists (assistant) keep skills = [] (see "Open
    items" below).
  - skills_disabled = true on the four short-conversational agents
    (hello-world, recipe-assistant, health-tracker, home-automation).
    Their system prompts never instruct the LLM to consult any skill,
    so loading all 60 was pure waste. They also drop the explicit
    max_history_messages override and inherit the kernel default (60).
  - max_history_messages tiered by workload shape:
      60  short conversational (hello-world, recipe, health-tracker,
          home-automation) — inherits the rising kernel default
          (`DEFAULT_MAX_HISTORY_MESSAGES = 60`); no override needed.
      60  single-turn task agents (writer, translator, doc-writer,
          email-assistant, customer-support, sales-assistant, recruit-
          er, social-media, personal-finance, tutor, travel-planner,
          meeting-assistant, ops, devops-lead, planner) — explicit
          override at the same value to lock the cap if the kernel
          default moves again.
      80  multi-step / tool-heavy (coder, debugger, architect, code-
          reviewer, test-engineer, security-auditor, analyst, data-
          scientist, academic-researcher, researcher, legal-assistant)
      120 coordinators (assistant, orchestrator) — long multi-agent
          sessions where prompt-cache continuity is critical
    All values sit at or above the kernel default. Pinning lower
    would thrash the prompt cache (the failure mode #91 fixed for
    the creator hand by *raising* the cap, not lowering it).

17 hands/*/HAND.toml:
  - hand-level mcp_servers / skills now declared on every hand, so
    every [agents.*] inside inherits a sensible allowlist.
  - skills_disabled = true placed on each [agents.*] inside clip and
    creator (pure media pipelines that don't benefit from any skill).
    HandDefinitionRaw in librefang-hands does NOT have a top-level
    skills_disabled field — declaring it at the hand top level would
    be silently dropped by serde, so the setting must live on the
    AgentManifest of each sub-agent role.
  - devteam: expand existing mcp_servers = ["github"] to include
    memory / git / filesystem; populate skills with the expected
    dev-team expertise (replacing the placeholder skills = []).
  - wiki: replace placeholder mcp_servers = [] with [memory, fetch,
    filesystem]. Hand-level skills stays [].
  - lead: hand-level skills was originally [email-writer, writing-
    coach, interview-prep]; interview-prep is for job-interview
    preparation, not lead generation. Replaced with data-analyst
    (used by the qualification-scoring step in the prompt).

schema.toml: register mcp_servers / skills / max_history_messages on
the agent field schema so machine consumers (RegistrySchema in
librefang-types) see the new top-level fields. The
max_history_messages description now points at
librefang_runtime::agent_loop::DEFAULT_MAX_HISTORY_MESSAGES (60
today) by name, so the schema doesn't go stale when the constant
moves again.

agents/README.md: example block + "Adding a New Agent" checklist
mention the allowlists; max_history_messages example is shown
commented out with a prompt-cache caveat.

Open items
----------

`assistant` (the default user-facing agent) keeps `skills = []`
deliberately. It is the generalist entry point — capping its skill
surface at a small allowlist would defeat its "delegate to any
specialist" job. The trade-off is that this single agent still pays
the full skill-definition load on every turn; operators who want a
strict allowlist for `assistant` can override it after install.

Why not adopt PR #89's approach
-------------------------------

#89 covers similar ground but with three issues this PR avoids:

1. mcp_servers = ["_none"] sentinel. #89's body explicitly notes
   it's pending upstream librefang#4808 (mcp_disabled). Shipping a
   magic-string today means coming back later to clean it up. This
   PR uses real allowlists.
2. max_history_messages = 8 / 12 / 15 / 20. Far below today's
   kernel default (60) and #91's direction for long-workflow hands
   (80–120). Every turn that hits the cap invalidates the cached
   prompt prefix; the cost of cache misses exceeds the saving from
   shorter history. This PR uses 60–120.
3. Doubling max_llm_tokens_per_hour (coder 200k→500k, assistant
   300k→500k) widens the per-agent budget — the opposite direction
   from #87's "reduce per-call cost" goal. Left to the operator's
   instance-specific tuning.

Refs librefang/librefang-registry#87, librefang/librefang-registry#89
2026-05-12 09:30:21 +09:00
Evan 651ff1b34d fix(creator): raise max_history_messages + repair refresh-cache CI (#91)
* fix(creator): raise max_history_messages to 80 for polling workflows

Creator Hand's async video_generate path polls video_status every 15-20s
until completion (1-3 min typical), consuming ~5-15 turns per video
request. Combined workflows (video + TTS + music) plus normal back-and-
forth cross the kernel default of 40 messages quickly, which surfaced
in user logs as:

  WARN run_agent_loop: Trimming old messages at safe turn boundary
    agent=creator:creator-hand total_messages=41 trimming=2
  INFO run_agent_loop: prompt cache metrics for turn
    hit_ratio=0.0 creation=0 read=0

Every turn was hitting the trim cap and invalidating the prompt-cache
prefix. 80 covers ~30 polling iterations plus a comfortable pre-context
window without runaway memory growth. Other hands keep the default 40.

* ci(refresh-cache): open PR instead of pushing directly to main

Branch protection on `main` started rejecting the workflow's auto-commit
with GH006 "Changes must be made through a pull request" — see run
25632824585 on 2026-05-10 against commit 6785807 (the first push that
hit the tightened protection). Direct push is precisely what the file's
own security comment (#1) warns against ("Compromised maintainer pushes
a malicious plugins-index.json directly to main. Mitigation: GitHub
branch protection on main requires PR review"), so the fix preserves
that gate rather than working around it.

The workflow now creates a short-lived `automation/refresh-indexes-<sha>`
branch, commits the regen there, pushes, and opens a PR back to main
via `gh pr create`. Maintainers see a one-click squash-merge.

Permissions: add `pull-requests: write` to the existing `contents: write`
so `gh pr create` can be authorised through the default GITHUB_TOKEN.

The post-merge run on the index PR is a no-op (no diff under
`hands/**`, `plugins/**`, etc. between consecutive states), so no
`[skip ci]` marker is needed and no loop is possible.

Without this fix, every content PR landing on main leaves
plugins-index.json + registry-index.json stale, blocking new agents and
hands from reaching daemons until a maintainer manually regenerates.

* fix(hands): raise max_history_messages on long-workflow coordinators

Three hand coordinators have workflows that routinely exceed the kernel
default history cap on a single user turn:

- researcher (max_iterations=80) — deep web_search → web_fetch →
  summarize loops with multi-source synthesis. 80 iterations × ~4
  messages each → 200+ messages per user turn. Set to 120.
- devops    (max_iterations=60) — incident response and CI/CD fan out
  into long shell_exec chains (logs, retries, post-mortems). Set to 80.
- predictor (max_iterations=60) — long reasoning chains accumulating
  signals across many web/knowledge queries, with scheduled re-checks
  referring back. Set to 80.

Creator's existing override is rephrased "raise above the kernel
default" so the comment stays correct regardless of the order this PR
and the upstream kernel-default bump (librefang side) land in.

Other hands (lead/linkedin/reddit/clip/analytics/apitester/browser/
collector/strategist) stay on the kernel default; the upstream bump
covers them.
2026-05-12 08:55:22 +09:00
Evan d4f15fd662 feat: add web_search capability to all agents and hands (#74)
Adds the web_search tool to every agent.toml and hand HAND.toml that did
not already declare it. Without this capability the runtime gates the
tool with 'Capability denied: tool not in allowed list', leaving agents
unable to perform web searches even when a search provider is
configured.

For tools arrays that already contained web_fetch, web_search is
inserted directly after it (its natural companion). For arrays without
web_fetch, web_search is appended to the end.

24 files updated total: 21 agents and 3 hands.
2026-04-25 23:07:24 +09:00
Evan d43077afa9 fix(providers): remove ~anthropic, skip ~ prefixes in sync script (#69)
* fix(providers): remove ~anthropic, skip ~ prefixes in sync script

OpenRouter uses ~ prefixes for internal auto-routing aliases (e.g. ~anthropic).
These are not real providers — they already route through openrouter.toml.
The generated ~anthropic.toml was confusing (looked like a stale backup)
and redundant with the existing openrouter provider.

- Delete providers/~anthropic.toml
- Skip provider IDs starting with ~ in sync-pricing.py --create-missing

* fix(providers): remove morph, aider, kwaipilot

- morph: specialized code-editing/patching tool, not a general LLM provider
- aider: CLI meta-tool wrapper (base_url empty), redundant with claude-code/codex-cli/gemini-cli/qwen-code
- kwaipilot: Kwai internal coding assistant routed via OpenRouter, niche

* fix(sync): add morph/aider/kwaipilot to SKIP_PROVIDERS to prevent re-creation

* feat(sync): merge OpenRouter-only providers into openrouter.toml

Instead of generating standalone .toml files that just wrap the OpenRouter
endpoint, merge their models directly into openrouter.toml with the
standard 'openrouter/{provider}/{model}' ID convention.

- Add _build_model_fields() and _model_lines() helpers to deduplicate
  model rendering between standalone and merged paths
- Add merge_into_openrouter() that appends new models idempotently
- generate_provider_toml() now only runs for providers in PROVIDER_API
- --create-missing routes OpenRouter-only providers to merge_into_openrouter

* fix(providers): remove 14 OpenRouter-only standalone files

These providers have no direct public API and all route through
openrouter.ai/api/v1. Per the new sync-pricing.py policy, their models
will be merged into openrouter.toml on the next CI run instead of
living in separate files that just wrap the OpenRouter endpoint.

Removed: allenai, deepcogito, essentialai, inclusionai, inflection,
liquid, meituan, nex-agi, nousresearch, prime-intellect, relace,
switchpoint, tngtech, writer

* fix(providers): remove 7 niche providers with no driver support

No dedicated LLM driver code exists for these providers — they rely
purely on OpenAI-compatible passthrough with no special handling.
Removing them reduces registry noise; users can still reach them via
openrouter.toml if needed.

Removed: microsoft, ibm-granite, xiaomi, upstage, inception, aion-labs, arcee-ai

* fix(providers): remove ai21, chutes, venice

All three use ApiFormat::OpenAI with no special handling — pure passthrough.
No registry entry needed; users can reach them via openrouter.toml or by
adding a custom provider.

* docs(providers): rewrite README with full provider catalog and inclusion criteria

- List all 46 providers grouped by category with descriptions
- Document why each provider exists (direct API, unique endpoint, dedicated driver, local, CLI)
- Add inclusion criteria section explaining when to create standalone files vs merging into openrouter.toml
- Document sync script routing logic
- Update model counts: 49→46 providers, 339→232 models

* docs: add comprehensive READMEs for all registry sections + deepinfra provider

- agents/README.md: 32 agents across 7 categories with capability field reference
- channels/README.md: 44 channels across 5 categories with protocol reference table
- hands/README.md: 18 hands across 5 categories with HAND.toml format guide
- mcp/README.md: 33 MCP servers across 5 categories with transport/auth format
- plugins/README.md: 12 plugins with hook protocol documentation
- skills/README.md: 60 skills across 9 categories with SKILL.md format guide
- providers/deepinfra.toml: add DeepInfra serverless inference (5 models)
2026-04-24 00:02:33 +09:00
Evan 7881d327a5 refactor: migrate icon fields from emoji to lucide:<name> tokens (#63)
* refactor: migrate icon fields from emoji to lucide:<name> tokens

Every TOML manifest's `icon = "<emoji>"` line is replaced with
`icon = "lucide:<kebab-name>"` — a reference to a lucide-react icon,
which the librefang.ai site and dashboard render as crisp SVG. Reasons
for the switch:

- Emoji render very differently across OS/browser/font stacks; the
  registry catalog looked inconsistent from one row to the next.
- Five manifests (clip / creator / linkedin / reddit / twitter) had
  their icons stored as literal Python-style escape strings
  ("\\U0001F3AC") because the TOML parser upstream never decoded
  them. Switching away from emoji drops that class of bug entirely.
- As a drive-by, also decode the \\uXXXX accent escapes in the
  [i18n.fr] block of hands/creator/HAND.toml so "Créateur" shows
  up correctly.

87 files touched. example manifests left untouched (still "TODO").

* fix: backfill i18n name + drop the single-member email category

- Every existing [i18n.<lang>] block now has a `name` field. 60 files
  previously translated description but kept the English name
  implicitly — which rendered as "some English some Chinese" in the
  registry UI. Fill in the missing name from the English brand (or a
  known localized equivalent: DingTalk→钉钉, Feishu→飞书, Email→
  电子邮件 / メール / E-Mail / Correo / Courriel, and a handful of
  hands that have Chinese product names like 视频剪辑 Hand).
- channels/email.toml was the only item under category="email";
  reclassify it as "messaging" so the sub-category filter chip list
  on the category page isn't littered with singletons.

* feat(i18n): localize 76 agents/integrations/plugins into 7 languages

Adds full [i18n.zh], [i18n.zh-TW], [i18n.ja], [i18n.ko], [i18n.de],
[i18n.es], [i18n.fr] blocks with name + description to every manifest
that previously shipped English-only.

Coverage:
- 32 agents (academic-researcher, analyst, architect, assistant,
  code-reviewer, coder, customer-support, data-scientist, debugger,
  devops-lead, doc-writer, email-assistant, health-tracker,
  hello-world, home-automation, legal-assistant, meeting-assistant,
  ops, orchestrator, personal-finance, planner, recipe-assistant,
  recruiter, researcher, sales-assistant, security-auditor,
  social-media, test-engineer, translator, travel-planner, tutor,
  writer)
- 33 integrations (AWS, Azure, Bitbucket, Brave Search, Discord,
  Dropbox, Elasticsearch, Exa Search, Fetch, Filesystem, GCP, Git,
  GitHub, GitLab, Gmail, Google Calendar, Google Drive, Google Maps,
  Jira, Linear, Memory, MongoDB, Notion, PostgreSQL, Puppeteer, Redis,
  Sentry, Sequential Thinking, Slack, SQLite, Teams, Time, Todoist) —
  brand names kept as-is across all locales, only descriptions
  translated.
- 11 plugins (auto-summarizer, context-decay, conversation-logger,
  episodic-memory, guardrails, keyword-memory, mempalace-indexer,
  sentiment-tracker, todo-tracker, topic-memory, user-profile)

The descriptions are one-line summaries — hand-translated rather than
machine-generated, so technical terms (MCP, PR, CI/CD, etc.) stay
consistent across locales.

* feat(i18n): close remaining per-lang gaps for channels, workflows, devteam

Third pass on i18n coverage. Every non-example manifest now carries a
full set of [i18n.zh], [i18n.zh-TW], [i18n.ja], [i18n.ko], [i18n.de],
[i18n.es], [i18n.fr] blocks.

- 44 channel adapters: added French descriptions (zh/zh-TW/ja/ko/de/es
  were already present). Brand names kept as-is in all locales so users
  recognize Discord / Slack / LINE / etc. consistently.
- 22 workflows: filled zh-TW / ja / ko / de / es / fr blocks. Each
  translation mirrors the existing zh one in structure and tone so the
  catalog reads consistently across locales.
- hands/devteam/HAND.toml: added the four langs that were missing
  (zh-TW, de, es, fr).

Only the 6 templates under examples/ are left without i18n blocks on
purpose — they still contain "TODO:" placeholders.
2026-04-17 22:04:26 +09:00
Adrian Rogala 3d1bfb4240 fix(wiki-hand): restore missing [agents.analyst] section header (#56) 2026-04-15 11:02:09 +09:00
Evan 6ab7002a2a fix(hands): use valid token_consumption enum value for wiki hand (#55) 2026-04-15 01:46:09 +09:00
Adrian Rogala f9c7456900 feat(hands): add wiki hand for LLM-maintained knowledge bases (#44)
Squashed replay of the original 9-commit branch onto current main.  The
original branch was 30+ commits behind, forked from before the skills
refactor (PR #42) and workflow template expansion (PR #36), so a
standard rebase hit heavy add/add conflicts on workflows/*.toml that
are unrelated to the wiki hand.

This replay keeps only the final hands/wiki/ tree state, which is the
actual intent of the PR (the author iterated several times on the same
files; squashing matches that).

Implements the "LLM Wiki" pattern (Andrej Karpathy) for building a
personal, Obsidian-compatible knowledge base.  Instead of on-the-fly
RAG, the wiki hand incrementally maintains a Markdown vault:

  hands/wiki/
  ├── HAND.toml           # hand manifest + [agents.*] sections
  ├── README.md           # user-facing docs
  ├── SKILL-main.md       # Librarian (coordinator) routing + FS ops
  ├── SKILL-ingestor.md   # Source extraction + [[wikilink]] writing
  ├── SKILL-analyst.md    # Synthesis with provenance citations
  └── SKILL-linter.md     # Broken link / orphan / contradiction audit

Closes librefang/librefang-registry#44 (via replay, not merge).
2026-04-10 22:04:18 +08:00
Evan Hu fc650e4ed3 fix(hands): resolve routing alias conflict between devteam and coder 2026-04-10 12:50:39 +09:00
Evan 2b8259a0c0 feat(hands): add devteam hand (#41)
* feat(hands): add devteam hand -- autonomous software development team

Multi-agent hand with 7 roles (PM, Architect, Frontend, Backend, DevOps, QA, Designer)
and 3 team size tiers (simple/standard/full) for different project scales.

PM coordinator auto-scans GitHub issues, triages, assigns tasks to specialists,
and tracks progress on an in-memory project board.

* refactor(hands): slim devteam to 3 agents (PM + Engineer + QA)

7 agents with serial agent_send = massive token waste and info loss at every
handoff. Merge architect/frontend/backend/devops into one Engineer with full
context. Keep QA separate for independent verification. Drop designer.

Tiers: lite (PM + Engineer) and standard (PM + Engineer + QA).

* fix(hands/devteam): fix workspace isolation and git workflow gaps

- PM uses GitHub API for code browsing, no repo clone needed
- Engineer explicitly clones repo, branches, commits, pushes, creates PR
- QA explicitly clones repo, checks out branch under review
- PM tracks last_scan timestamp to filter already-triaged issues
- approval_mode now means PR stays open for review, not skip commit

* fix(hands/devteam): use shared repo checkout instead of per-agent clones

All 3 agents share one checkout at ../shared/repo/. Engineer clones it
on the first task; PM and QA read from the same path. Eliminates
duplicate clones and cross-workspace visibility issues.

* fix(hands/devteam): read issue comments before triaging

Comments contain clarifications, reproduction steps, duplicate markers,
and resolution status. Also skip already-assigned and wontfix issues.

* fix(hands/devteam): fix interactive git add, add merge/close APIs, add fix iteration flow

- Replace git add -p (interactive) with git add <specific files>
- PM prompt now has explicit merge PR and close issue API calls
- Engineer has explicit fix-request handling (same branch, push, no new PR)

* feat(hands/devteam): add full GitHub interaction -- PR review, issue comments, labels

PM:
- Labels issues during triage, comments triage status
- Scans open PRs for external review requests
- Comments on issues linking merged PRs

Engineer:
- Replies to review comments on PR after fixing
- Reviews external PRs with APPROVE/REQUEST_CHANGES + line comments

QA:
- Leaves PR review (APPROVE or REQUEST_CHANGES with line comments)
- All findings visible on GitHub, not just via agent_send

SKILL.md:
- Added PR diff, reviews, review comments, reply, merge API references

* fix(hands/devteam): enforce English comments, line-level reviews, comment-before-close

- All GitHub comments/reviews must be in English (added global rule)
- PR reviews must use comments[] with path+line, not body-only
- Comment on issue with resolution details BEFORE closing/merging
- Improved comment templates with structured info

* fix(hands/devteam): 8 logic fixes from end-to-end workflow review

1. Filter PRs from Issues API (pull_request key)
2. PM sends PR number to QA for review
3. Deduplicate PR scanning via devteam_reviewed_prs
4. QA reports test gaps instead of pushing code to shared branch
5. branch_strategy wired into Engineer (gitflow branches from develop)
6. approval_mode: ON = wait for human, OFF = auto-merge after QA
7. scan_interval mapped to schedule_create every_secs
8. git checkout -B instead of -b to handle existing branches

* fix(hands/devteam): second-pass review — 6 more logic fixes

1. Engineer extracts PR number from create-PR API response
2. PM falls back to GitHub Contents API when shared repo not yet cloned
3. QA gets external PR review flow (was only on Engineer)
4. PM checks CI status + mergeable before merging
5. PM handles merge conflict (409) by sending back to Engineer to rebase
6. i18n approval_mode description synced with actual semantics

* fix(hands/devteam): third-pass — runtime scenarios

1. Deduplicate cron schedule on daemon restart (check schedule_list first)
2. Max 3 review rounds before escalating to user (prevent infinite loop)
3. Clean working directory before switching tasks (git checkout -- . && git clean)
4. Add user direct commands (work on #42, status, review PR #50)
5. Pass tech_stack to Engineer in task delegation
6. Fix duplicate step numbering in Review Cycle

* fix(hands/devteam): fourth-pass — state consistency and edge cases

1. QA force-syncs to remote branch (git checkout -B origin/branch) for force-push safety
2. Board sync step: reconcile with GitHub each scan cycle (catch external closes/merges)
3. Prune devteam_reviewed_prs of closed PRs, cap done list at 30
4. PM checks CI before sending to QA (don't waste QA on red builds)
5. Stop/cancel command: remove from board, comment on issue
6. Explicit rebase commands for Engineer (fetch + rebase + force-with-lease)

* fix(hands/devteam): fifth-pass — crash prevention

1. Guard empty repo_url: stop and tell user to configure it
2. Add python3 to requires (all JSON parsing depends on it)
3. Engineer git config user.name/email on first clone (prevents commit rejection)
4. Explicit build/lint/test commands per tech stack (Rust/TS/Python/Go/Java/Swift)
5. event_publish on task completion so user gets notified
6. Global rule: check API HTTP status before parsing JSON

* feat(hands/devteam): add gh CLI / MCP / curl API three-layer fallback

- Add GitHub MCP integration (mcp_servers = ["github"])
- Add gh CLI as optional requirement (preferred over curl)
- All 3 agents: gh > MCP > curl priority for GitHub operations
- Add issue_tracker setting (github/linear/jira)
- Add agent_list to shared tools
- SKILL.md: add full gh CLI reference section
- i18n: add issue_tracker translation

* feat(hands/devteam): full MCP/integration/notification layer

MCP allowlist: github, linear, jira, sentry, slack, discord
- Sentry: Engineer reads crash reports/stack traces when fixing bugs
- Slack/Discord: PM posts status updates (triaged, completed, QA results)
- Linear/Jira: alternative issue trackers

New settings: notify_channel (none/slack/discord), issue_tracker (github/linear/jira)
New optional requires: npx (MCP runtime), SENTRY_AUTH_TOKEN

PM prompt: notification section, channel-aware status posting
Engineer prompt: Sentry context lookup for bug fixes
i18n: added translations for new settings

* feat(hands/devteam): workflows, onboarding, knowledge, standup, rollback

Workflows (8 integrated):
- PM: bug-triage, product-spec, weekly-report, incident-postmortem
- Engineer: code-review, test-generation, refactor-plan, api-design
- QA: code-review, test-generation

New capabilities:
- Repo onboarding: first activation analyzes repo structure/stack/CI
- Knowledge accumulation: store lessons per issue, detect module hotspots
- Daily standup: cron schedule, board summary via notify_channel
- Rollback: gh pr revert + postmortem workflow + re-open issue

Also:
- Added workflow_run to tools, skills = [] (all allowed)
- Rewrote README with full architecture, lifecycle, workflow table
- PM prompt now has 15 sections covering full lifecycle

* feat(hands/devteam): per-agent capabilities, resources, profiles, fallbacks

Each agent now has full AgentManifest config (not just system_prompt):

PM:
- profile: automation
- capabilities: web, memory, schedule, knowledge, event, workflow, agent_send
- shell: gh, curl, cat, python3
- resources: 200k tokens/hr

Engineer:
- profile: coding
- capabilities: file r/w, shell, web, memory, knowledge, workflow
- shell: cargo, npm, python, go, swift, mvn, git, gh, docker, make
- resources: 300k tokens/hr, 10 concurrent tools
- network: * (needs to push to GitHub)

QA:
- profile: coding (read-heavy, no file_write)
- capabilities: file read, shell (test/lint commands only), web, workflow
- shell: cargo test/clippy/audit, npm test, pytest, go test, gh
- resources: 150k tokens/hr

All agents have fallback_models configured.

* feat(hands/devteam): rewrite with proper resource composition

First hand to use the new composition features:

Agents:
- PM: base=planner, capabilities restricted to gh/git shell only
- Engineer: base=coder, full shell access, network=*
- QA: base=code-reviewer, tool_blocklist=[file_write], test/lint shells only

Composition:
- base: inherit from agents/planner, agents/coder, agents/code-reviewer
- mcp_servers: github (agents interact via MCP, not curl in prompts)
- workflows: bug-triage, code-review, test-generation via workflow_run tool
- plugins: todo-tracker, auto-summarizer, episodic-memory
- per-agent skills: SKILL-pm.md, SKILL-engineer.md, SKILL-qa.md
- per-agent capabilities: QA can't write files, PM can't run builds

Prompts are clean and focused (role + methodology + principles),
not stuffed with curl commands. GitHub interaction goes through
MCP tools or gh CLI.

* fix(devteam): complete planner methodology in PM prompt

Added SCOPE/SEQUENCE/RISK/MILESTONE keywords from the planner
base template's methodology into the PM's triage workflow.

* docs: update hands README, fix repo_url reference in prompts

- hands/README.md: document full composition model (base, MCP, workflows,
  plugins, per-agent skills, per-agent capabilities)
- Updated hand count to 15 (added devteam)
- Engineer prompt: clarify repo_url comes from User Configuration, not
  a template variable
- PM prompt: same clarification

* fix(devteam): override name/description from base templates

Without explicit name, agents inherit base names (planner/coder/code-reviewer)
instead of hand-specific names (pm/engineer/qa). This affects display and
the prefixed name used in agent registry (devteam:pm vs devteam:planner).

* style: format HAND.toml with taplo
2026-04-10 10:24:26 +08:00
Evan 05bdf02169 feat(workflows): expand template library from 9 to 22 + multiline string cleanup (#36)
* feat(workflows): add 13 workflow templates across engineering, business, and productivity

Engineering:
- bug-triage: reproduce path → root cause → fix plan
- api-design: resource model → endpoints → OpenAPI spec
- incident-postmortem: timeline → RCA → full postmortem report
- test-generation: code analysis → edge cases → full test suite
- refactor-plan: smell analysis → prioritised opportunities → migration plan

Business:
- competitor-analysis: profiles → SWOT → strategy report
- product-spec: problem definition → user stories → full PRD
- market-research: landscape → segments → research report

Productivity/Thinking:
- meeting-summary: raw notes → structured summary → follow-up email
- decision-matrix: criteria → weighted scoring → recommendation memo
- learning-plan: gap analysis → roadmap → week-1 day-by-day plan
- job-application: job analysis → tailored resume → cover letter → interview prep
- blog-post: research → outline → draft → SEO optimisation

Closes #1912 on librefang/librefang

* fix(workflows): overhaul existing 9 templates

- data-pipeline: redesigned — original 'extract from URL' step was
  broken (LLMs cannot fetch URLs); replaced with paste-data approach
  (profile → clean_transform → analyse) with analysis_goal parameter
- translate-polish: added target_language and register parameters;
  added back-translation step for accuracy verification
- weekly-report: added team/audience parameters, richer extraction
  step, added Metrics and Notes sections
- content-pipeline: added audience/tone parameters, added outline step
  between research and writing
- content-review: fix category 'content' → 'creation'
- customer-support: fix category 'support' → 'business'

* style(workflows): convert all prompt_template strings to TOML multiline syntax

Replace \n escape sequences with real newlines using triple-quote
multiline strings ("""...""") across all 22 workflow templates.
No content changes — formatting only.

* style(hands): replace \n escape in reddit writer format example with multiline code block
2026-04-01 18:21:09 +08:00
Chukwuebuka (Gaus Octavio ) 98e6601249 fix(researcher): add memory_list tool to researcher hand (#31)
The researcher hand was trying to call memory_list but lacked the capability,
causing 'Tool execution failed: Permission denied' errors.

This fix adds memory_list to the tools list in the researcher hand's HAND.toml.

Fixes: librefang/librefang#1774
2026-03-31 22:56:34 +08:00
Evan d012a4a26d feat: add tags = ["popular"] to top hands and channels (#24) 2026-03-25 13:31:13 +09:00
Evan 1e8f75b120 feat: add Chinese (zh) i18n for all hand agents (#23)
Add [i18n.zh.agents.*] sections to all 15 HAND.toml files,
providing Chinese translations for agent names and descriptions.

Total: 51 agent translations across 15 hands.
2026-03-25 12:44:20 +09:00
Evan 9b24879c4f feat: add i18n descriptions to all hands and channels (#22)
Add [i18n.zh], [i18n.zh-TW], [i18n.ja], [i18n.ko], [i18n.de], [i18n.es]
sections with translated descriptions to:
- 15 Hand TOML files (hands/*/HAND.toml)
- 44 Channel TOML files (channels/*.toml)

This enables the website to display localized Hand and Channel descriptions
based on the user's selected language.
2026-03-25 12:25:57 +09:00
Evan 1440059e99 fix: add shell execution rules to collector hand system prompt (#20) 2026-03-25 02:39:39 +09:00
Evan ecc5215cae feat(hands): add Creator Hand for media generation (#17) 2026-03-23 14:09:51 +09:00
Evan 945bbbd763 chore(hands): bump all HAND.toml versions to 1.1.0 (#16)
* chore(hands): bump all HAND.toml versions to 1.1.0

Triggers version-aware sync in librefang runtime (librefang/librefang#1530).
Previously sync_subdirs() skipped existing hands regardless of version.
With the runtime fix, bumping from 1.0.0 → 1.1.0 ensures users get
updated hand definitions on next registry sync.

* chore: fix taplo formatting for 4 agent.toml files

* fix(hands): fix invalid install fields in analytics and browser

- analytics: `linux` → `linux_apt`/`linux_dnf`/`linux_pacman` (parser
  only recognizes platform-specific variants, not generic `linux`)
- analytics: remove `pip = "python3 --version"` (version check, not
  an install command)
- browser: remove `pip = "python3 --version"` (same issue)

* fix: enrich sub-agent prompts and add missing requires across all hands

- analytics: fix linux → linux_apt/dnf/pacman, remove invalid pip check,
  enrich analyst and modeler sub-agent prompts
- apitester: add [[requires]] for curl
- browser: remove invalid pip check, enrich researcher and extractor prompts
- clip: enrich editor and transcriber sub-agent prompts
- collector: enrich scout, scholar, and localizer sub-agent prompts
- devops: add [[requires]] for curl, git, docker (optional), GITHUB_TOKEN
  (optional), enrich sub-agent prompts
- lead: enrich outreach, recruiter, and messenger sub-agent prompts
- linkedin: enrich content and researcher sub-agent prompts
- predictor: enrich orchestrator, planner, and modeler sub-agent prompts
- reddit: enrich monitor and composer sub-agent prompts
- strategist: enrich architect, counsel, and analyst sub-agent prompts
- trader: enrich accountant and researcher sub-agent prompts
- twitter: enrich curator and composer sub-agent prompts
2026-03-23 11:21:29 +09:00
Evan d778da72a2 fix(validate): check for [agents] instead of [agent] in HAND.toml (#15)
* fix(validate): check for [agents] instead of [agent] in HAND.toml

All 14 hands use [agents.main] (plural) for multi-agent config,
but the validator was checking for [agent] (singular), causing
all hands to fail validation.

* fix(routing): resolve 19 routing alias collisions

Agent is a sub-unit of hand, so hands take priority for routing.
Remove conflicting aliases from agent side when hand already owns them.

- analyst: remove data analysis, analyze data, dashboard (owned by hand/analytics)
- data-scientist: remove statistical analysis, forecast, prediction (owned by hand/analytics, hand/predictor)
- sales-assistant: remove prospecting, sales, pipeline (owned by hand/lead, hand/devops)
- devops-lead: remove incident response, kubernetes, terraform (owned by hand/devops)
- researcher: remove deep research, research, literature review (owned by hand/researcher)
- academic-researcher: remove literature review, systematic review (owned by hand/researcher)
- social-media: remove duplicate content calendar from weak_aliases
- hand/collector: remove competitive analysis (owned by hand/strategist)
2026-03-23 09:41:29 +09:00
Evan Hu 506a201329 feat: muti agent hand 2026-03-23 02:41:02 +09:00
Evan Hu fd752c50e2 fix(hands): fix TOML parse error in clip i18n — unescaped quotes 2026-03-23 01:24:13 +09:00
Evan Hu 6cb1d904bf fix(hands): resolve merge conflict markers left by PR #12
Remove git conflict markers from linkedin, reddit, and twitter
HAND.toml and SKILL.md files. Keep the more complete version
(with new settings i18n translations) and fix French/Spanish
accent issues (dépasser, entraîner, média, réponse, conexión,
imágenes, Mode de croissance).
2026-03-23 01:22:54 +09:00
Evan Hu 825d6d389d fix(twitter): use single quotes for i18n string containing Chinese quotes 2026-03-23 00:51:26 +09:00
Evan Hu 3da827e6da feat(hands): improve linkedin, reddit, and twitter hands
- linkedin: API fallback strategy, queue JSON schema, 3 new settings, algorithm deep dive, crisis management
- reddit: concrete rule parsing, anti-spam/shadowban detection, engagement scoring, new settings
- twitter: structured trend analysis, queue schema, engagement criteria, algorithm awareness, new settings
2026-03-23 00:51:26 +09:00
Evan Hu ed595230cf feat(hands): improve 6 lower-scoring hands — system prompts and SKILL.md depth
- browser: 5→7 phases, SPA detection, error recovery decision tree, 3 new settings
- strategist: framework integration methodology, 7 anti-patterns, uncertainty quantification
- lead: remove clip language, add BANT/MEDDIC qualification, 3 new settings + CRM export
- researcher: CRAAP→CRAAP+, 7-step conflict resolution, 6-item cognitive bias audit
- collector: concrete change classification (structural/content/metadata), 5-factor scoring, 2 new settings
- apitester: OWASP Top 10 checklist, 4 load test profiles, contract testing phase, GraphQL/Webhook patterns
2026-03-23 00:31:13 +09:00
Evan Hu 33d279889c feat(hands): complete i18n fixes, SKILL.md enhancements, and README overhaul
- Fix French accent characters (é/è/ê/ç/â/ô) across all 14 HAND.toml files
- Fix German special characters (ä/ö/ü/ß) across all 14 HAND.toml files
- Add category translations to all 6 i18n language blocks in all 14 hands
- Enhance SKILL.md content for 9 hands with practical examples and workflows
- Trim bloated SKILL.md files (apitester 1400→892, devops 1301→870)
- Rewrite root README.md with accurate stats, complete hand/integration tables
- Update hands/README.md with full 14-hand listing and i18n documentation
2026-03-23 00:18:18 +09:00
Evan Hu 315f955ce2 fix(i18n): move [i18n.zh] sections to end of HAND.toml files
The i18n table was placed before category/icon/tools, causing TOML
parser to swallow subsequent keys into the i18n table.
2026-03-22 23:04:17 +09:00
Evan Hu 123350e2b2 feat(i18n): add Chinese translations for all 14 hands
Add [i18n.zh] sections with localized name and description to every
HAND.toml in the registry.
2026-03-22 22:55:34 +09:00
Evan Hu fb45e39dcb fix(hands): migrate Reddit auth to client_credentials, document Twitter OAuth 1.0a
Reddit:
- Remove REDDIT_USERNAME and REDDIT_PASSWORD requirements (deprecated
  password grant)
- Switch to grant_type=client_credentials (app-only auth)
- Update system_prompt and SKILL.md auth examples

Twitter:
- Add optional OAuth 1.0a credentials (API key/secret, access
  token/secret) for user-context operations
- Document Bearer Token vs OAuth 1.0a authentication modes in SKILL.md
- Note which endpoints require user-context auth
2026-03-22 20:28:16 +09:00
Evan Hu 8923c4e0c3 docs(browser): expand SKILL.md with comprehensive browser automation guide
Expand from ~124 to ~816 lines covering navigation, form handling,
screenshots, JavaScript execution, error handling patterns, and
best practices for the browser automation hand.
2026-03-22 17:57:57 +09:00
Evan Hu 68c9c65e6e feat: add missing [metadata] to clip, linkedin, reddit, twitter
All 14 hands now have consistent metadata sections with frequency,
token_consumption, and default_active fields.
2026-03-22 17:38:40 +09:00
Evan Hu 0e06459613 feat(apitester): add approval_mode for destructive operations
Queue write requests, load tests, and security tests for user review
instead of executing directly. Default enabled for safety.
2026-03-22 17:06:29 +09:00
Evan Hu 8f0cdfe5ab fix: format TOML files with taplo 2026-03-22 16:56:37 +09:00
Evan Hu 5d947e8da0 feat(hands): add version fields, approval_mode, and stronger routing aliases
- Add version = "1.0.0" to all 14 hands
- Add approval_mode toggle to clip and devops hands (queue actions
  for user review before executing)
- Strengthen routing aliases for analytics, apitester, browser,
  collector, devops, lead, predictor, researcher, strategist
2026-03-22 16:42:27 +09:00
EvanandClaude Opus 4.6 8f2244eb6f chore: remove router agent (#5)
* chore: remove router agent

builtin:router has been replaced by LLM intent routing in the kernel.
Assistant is now the sole entry point — see librefang/librefang#1336.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* style: format all TOML files with taplo

Fix CI taplo format check by running `taplo fmt` on all 132 TOML files.

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-21 03:26:11 +09:00
Evan Hu 6cc5c745be fix(docs): add missing settings to clip, reddit, trader, twitter READMEs
- clip: add ElevenLabs API Key setting
- reddit: add Minimum Karma to Post setting
- trader: add Alpaca API Key and Secret Key settings
- twitter: add Twitter Bearer Token setting
2026-03-21 02:31:52 +09:00
Evan Hu 4b38372463 docs: add README for every subdirectory
33 agent READMEs, 14 hand READMEs, 2 plugin READMEs
(echo-memory + hooks), and 2 skill READMEs
(custom-skill-prompt + custom-skill-python).

Each README documents the component's purpose, configuration,
and usage based on its TOML definition.
2026-03-21 02:27:34 +09:00
Evan Hu 206169c1d7 docs: add README for every content directory
Each directory (agents, hands, integrations, plugins, providers,
scripts, skills) now has a README documenting its TOML format,
current contents, and contribution steps.
2026-03-21 02:24:22 +09:00
Evan Hu d1bc8ead69 chore: cleanup repo and enhance validation
- Add .gitignore (.DS_Store, .vscode, __pycache__)
- Remove stale .gitkeep files (directories have content now)
- Expand schema.toml to document all 6 content types (agent, hand, integration, skill, plugin)
- Add plugin validation and contribution guide
- Add id/name vs directory name consistency checks
- Add cross-type routing alias collision detection (14 warnings found)
2026-03-21 02:21:24 +09:00
Evan Hu 17d32ed4a7 feat: sync content definitions from core repo
Copy all TOML content definitions from librefang core repo:
- 33 agent definitions (agents/*/agent.toml)
- 14 hand definitions with docs (hands/*/HAND.toml + SKILL.md)
- 25 integration templates (integrations/*.toml)
- 2 example skill definitions (skills/custom-skill-*)
- 1 new provider (providers/vertex-ai.toml)

Part of the framework-vs-content registry split (RFC v0.7).
2026-03-21 02:06:07 +09:00
Evan Hu ded26ce300 feat: add dir 2026-03-21 01:57:04 +09:00