Standardize on Claude Code's SKILL.md format as every skill's source of
truth. skill.toml becomes an optional metadata layer for runtime, input
schema, and versioning — never for the prompt body.
- validate.py: require SKILL.md in every skill dir; when skill.toml also
exists, cross-check name/description consistency to prevent drift
- Add SKILL.md to the two custom-skill examples
- Move the meeting-agenda prompt body out of skill.toml into SKILL.md
- Rewrite skills/README.md to document the md-first, toml-as-metadata convention
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Claude Code-style skills use SKILL.md with YAML frontmatter instead of
skill.toml. Validator now accepts either form, unblocking the 60 bundled
skills restored in #42.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat(hands): add devteam hand -- autonomous software development team
Multi-agent hand with 7 roles (PM, Architect, Frontend, Backend, DevOps, QA, Designer)
and 3 team size tiers (simple/standard/full) for different project scales.
PM coordinator auto-scans GitHub issues, triages, assigns tasks to specialists,
and tracks progress on an in-memory project board.
* refactor(hands): slim devteam to 3 agents (PM + Engineer + QA)
7 agents with serial agent_send = massive token waste and info loss at every
handoff. Merge architect/frontend/backend/devops into one Engineer with full
context. Keep QA separate for independent verification. Drop designer.
Tiers: lite (PM + Engineer) and standard (PM + Engineer + QA).
* fix(hands/devteam): fix workspace isolation and git workflow gaps
- PM uses GitHub API for code browsing, no repo clone needed
- Engineer explicitly clones repo, branches, commits, pushes, creates PR
- QA explicitly clones repo, checks out branch under review
- PM tracks last_scan timestamp to filter already-triaged issues
- approval_mode now means PR stays open for review, not skip commit
* fix(hands/devteam): use shared repo checkout instead of per-agent clones
All 3 agents share one checkout at ../shared/repo/. Engineer clones it
on the first task; PM and QA read from the same path. Eliminates
duplicate clones and cross-workspace visibility issues.
* fix(hands/devteam): read issue comments before triaging
Comments contain clarifications, reproduction steps, duplicate markers,
and resolution status. Also skip already-assigned and wontfix issues.
* fix(hands/devteam): fix interactive git add, add merge/close APIs, add fix iteration flow
- Replace git add -p (interactive) with git add <specific files>
- PM prompt now has explicit merge PR and close issue API calls
- Engineer has explicit fix-request handling (same branch, push, no new PR)
* feat(hands/devteam): add full GitHub interaction -- PR review, issue comments, labels
PM:
- Labels issues during triage, comments triage status
- Scans open PRs for external review requests
- Comments on issues linking merged PRs
Engineer:
- Replies to review comments on PR after fixing
- Reviews external PRs with APPROVE/REQUEST_CHANGES + line comments
QA:
- Leaves PR review (APPROVE or REQUEST_CHANGES with line comments)
- All findings visible on GitHub, not just via agent_send
SKILL.md:
- Added PR diff, reviews, review comments, reply, merge API references
* fix(hands/devteam): enforce English comments, line-level reviews, comment-before-close
- All GitHub comments/reviews must be in English (added global rule)
- PR reviews must use comments[] with path+line, not body-only
- Comment on issue with resolution details BEFORE closing/merging
- Improved comment templates with structured info
* fix(hands/devteam): 8 logic fixes from end-to-end workflow review
1. Filter PRs from Issues API (pull_request key)
2. PM sends PR number to QA for review
3. Deduplicate PR scanning via devteam_reviewed_prs
4. QA reports test gaps instead of pushing code to shared branch
5. branch_strategy wired into Engineer (gitflow branches from develop)
6. approval_mode: ON = wait for human, OFF = auto-merge after QA
7. scan_interval mapped to schedule_create every_secs
8. git checkout -B instead of -b to handle existing branches
* fix(hands/devteam): second-pass review — 6 more logic fixes
1. Engineer extracts PR number from create-PR API response
2. PM falls back to GitHub Contents API when shared repo not yet cloned
3. QA gets external PR review flow (was only on Engineer)
4. PM checks CI status + mergeable before merging
5. PM handles merge conflict (409) by sending back to Engineer to rebase
6. i18n approval_mode description synced with actual semantics
* fix(hands/devteam): third-pass — runtime scenarios
1. Deduplicate cron schedule on daemon restart (check schedule_list first)
2. Max 3 review rounds before escalating to user (prevent infinite loop)
3. Clean working directory before switching tasks (git checkout -- . && git clean)
4. Add user direct commands (work on #42, status, review PR #50)
5. Pass tech_stack to Engineer in task delegation
6. Fix duplicate step numbering in Review Cycle
* fix(hands/devteam): fourth-pass — state consistency and edge cases
1. QA force-syncs to remote branch (git checkout -B origin/branch) for force-push safety
2. Board sync step: reconcile with GitHub each scan cycle (catch external closes/merges)
3. Prune devteam_reviewed_prs of closed PRs, cap done list at 30
4. PM checks CI before sending to QA (don't waste QA on red builds)
5. Stop/cancel command: remove from board, comment on issue
6. Explicit rebase commands for Engineer (fetch + rebase + force-with-lease)
* fix(hands/devteam): fifth-pass — crash prevention
1. Guard empty repo_url: stop and tell user to configure it
2. Add python3 to requires (all JSON parsing depends on it)
3. Engineer git config user.name/email on first clone (prevents commit rejection)
4. Explicit build/lint/test commands per tech stack (Rust/TS/Python/Go/Java/Swift)
5. event_publish on task completion so user gets notified
6. Global rule: check API HTTP status before parsing JSON
* feat(hands/devteam): add gh CLI / MCP / curl API three-layer fallback
- Add GitHub MCP integration (mcp_servers = ["github"])
- Add gh CLI as optional requirement (preferred over curl)
- All 3 agents: gh > MCP > curl priority for GitHub operations
- Add issue_tracker setting (github/linear/jira)
- Add agent_list to shared tools
- SKILL.md: add full gh CLI reference section
- i18n: add issue_tracker translation
* feat(hands/devteam): full MCP/integration/notification layer
MCP allowlist: github, linear, jira, sentry, slack, discord
- Sentry: Engineer reads crash reports/stack traces when fixing bugs
- Slack/Discord: PM posts status updates (triaged, completed, QA results)
- Linear/Jira: alternative issue trackers
New settings: notify_channel (none/slack/discord), issue_tracker (github/linear/jira)
New optional requires: npx (MCP runtime), SENTRY_AUTH_TOKEN
PM prompt: notification section, channel-aware status posting
Engineer prompt: Sentry context lookup for bug fixes
i18n: added translations for new settings
* feat(hands/devteam): workflows, onboarding, knowledge, standup, rollback
Workflows (8 integrated):
- PM: bug-triage, product-spec, weekly-report, incident-postmortem
- Engineer: code-review, test-generation, refactor-plan, api-design
- QA: code-review, test-generation
New capabilities:
- Repo onboarding: first activation analyzes repo structure/stack/CI
- Knowledge accumulation: store lessons per issue, detect module hotspots
- Daily standup: cron schedule, board summary via notify_channel
- Rollback: gh pr revert + postmortem workflow + re-open issue
Also:
- Added workflow_run to tools, skills = [] (all allowed)
- Rewrote README with full architecture, lifecycle, workflow table
- PM prompt now has 15 sections covering full lifecycle
* feat(hands/devteam): per-agent capabilities, resources, profiles, fallbacks
Each agent now has full AgentManifest config (not just system_prompt):
PM:
- profile: automation
- capabilities: web, memory, schedule, knowledge, event, workflow, agent_send
- shell: gh, curl, cat, python3
- resources: 200k tokens/hr
Engineer:
- profile: coding
- capabilities: file r/w, shell, web, memory, knowledge, workflow
- shell: cargo, npm, python, go, swift, mvn, git, gh, docker, make
- resources: 300k tokens/hr, 10 concurrent tools
- network: * (needs to push to GitHub)
QA:
- profile: coding (read-heavy, no file_write)
- capabilities: file read, shell (test/lint commands only), web, workflow
- shell: cargo test/clippy/audit, npm test, pytest, go test, gh
- resources: 150k tokens/hr
All agents have fallback_models configured.
* feat(hands/devteam): rewrite with proper resource composition
First hand to use the new composition features:
Agents:
- PM: base=planner, capabilities restricted to gh/git shell only
- Engineer: base=coder, full shell access, network=*
- QA: base=code-reviewer, tool_blocklist=[file_write], test/lint shells only
Composition:
- base: inherit from agents/planner, agents/coder, agents/code-reviewer
- mcp_servers: github (agents interact via MCP, not curl in prompts)
- workflows: bug-triage, code-review, test-generation via workflow_run tool
- plugins: todo-tracker, auto-summarizer, episodic-memory
- per-agent skills: SKILL-pm.md, SKILL-engineer.md, SKILL-qa.md
- per-agent capabilities: QA can't write files, PM can't run builds
Prompts are clean and focused (role + methodology + principles),
not stuffed with curl commands. GitHub interaction goes through
MCP tools or gh CLI.
* fix(devteam): complete planner methodology in PM prompt
Added SCOPE/SEQUENCE/RISK/MILESTONE keywords from the planner
base template's methodology into the PM's triage workflow.
* docs: update hands README, fix repo_url reference in prompts
- hands/README.md: document full composition model (base, MCP, workflows,
plugins, per-agent skills, per-agent capabilities)
- Updated hand count to 15 (added devteam)
- Engineer prompt: clarify repo_url comes from User Configuration, not
a template variable
- PM prompt: same clarification
* fix(devteam): override name/description from base templates
Without explicit name, agents inherit base names (planner/coder/code-reviewer)
instead of hand-specific names (pm/engineer/qa). This affects display and
the prefixed name used in agent registry (devteam:pm vs devteam:planner).
* style: format HAND.toml with taplo
Providers with known public APIs use their official endpoints:
- meta-llama → api.llama.com/v1
- microsoft → models.inference.ai.azure.com (GitHub Models)
- ibm-granite → us-south.ml.cloud.ibm.com/ml/v1 (watsonx)
- tencent → api.hunyuan.cloud.tencent.com/v1
- morph → api.morphllm.com/v1
16 remaining providers without known public APIs route through
OpenRouter (base_url = openrouter.ai/api/v1, OPENROUTER_API_KEY).
sync-pricing.py updated with PROVIDER_API mapping.
Providers without their own public API now use OpenRouter as their
base_url with OPENROUTER_API_KEY, making them testable and usable
when the user has an OpenRouter key configured.
- 20 OpenRouter-only providers: set base_url to openrouter.ai/api/v1
- morph: set correct official API (api.morphllm.com/v1)
- sync-pricing.py: default to OpenRouter routing for new providers
- Merge unique models from duplicate providers into their hand-written
counterparts and remove the duplicates:
- alibaba (tongyi-deepresearch) → qwen
- amazon (nova-2-lite, nova-micro, nova-premier) → bedrock
- bytedance (ui-tars) → volcengine
- nvidia (nemotron-3-nano, nemotron-3-super, etc.) → nvidia-nim
- rekaai (reka-flash-3) → reka
- Set correct official API base_url for providers with public APIs:
arcee-ai, inception, morph, reka, upstage
- Set key_required=false for 20 providers only accessible through
hosting platforms (no public API)
- Update sync-pricing.py with SKIP_DUPLICATES, PROVIDER_API mapping,
and default key_required=false for future auto-generated providers
* feat: convert schema.toml to machine-parseable format
Replace comment-based documentation format with structured TOML that
can be deserialized into the RegistrySchema Rust type. All 6 content
types (provider, agent, hand, integration, skill, plugin) preserved
with every field, description, enum option, and nested section.
* fix: format options arrays in schema.toml for taplo compliance
* fix: add shell execution rules to collector hand system prompt
* fix: use latest taplo instead of hardcoded version
* fix: use uncenter/setup-taplo action with latest version
* fix: download taplo 0.10.0 directly instead of using broken action
* fix: add shell execution rules to collector hand system prompt
* fix: use latest taplo instead of hardcoded version
* fix: use uncenter/setup-taplo action with latest version
- Replace tier "free" with "fast" (valid tiers: frontier/smart/balanced/fast/local)
- Remove version suffix from teams-mcp integration id field
- Update sync-pricing.py to not generate invalid tier values
* fix: pin npm package versions in MCP integration templates
Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.
23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).
* fix: use stable azure/mcp version instead of beta
* feat: add pricing sync script and update model prices from OpenRouter API
- scripts/sync-pricing.py fetches real-time pricing from OpenRouter
- Updated 64 price fields across 13 provider files
- Run periodically or in CI to keep prices current
* fix: pin npm package versions in MCP integration templates
Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.
23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).
* fix: use stable azure/mcp version instead of beta
Add [i18n.zh.agents.*] sections to all 15 HAND.toml files,
providing Chinese translations for agent names and descriptions.
Total: 51 agent translations across 15 hands.
Add [i18n.zh], [i18n.zh-TW], [i18n.ja], [i18n.ko], [i18n.de], [i18n.es]
sections with translated descriptions to:
- 15 Hand TOML files (hands/*/HAND.toml)
- 44 Channel TOML files (channels/*.toml)
This enables the website to display localized Hand and Channel descriptions
based on the user's selected language.
* fix(validate): check for [agents] instead of [agent] in HAND.toml
All 14 hands use [agents.main] (plural) for multi-agent config,
but the validator was checking for [agent] (singular), causing
all hands to fail validation.
* fix(routing): resolve 19 routing alias collisions
Agent is a sub-unit of hand, so hands take priority for routing.
Remove conflicting aliases from agent side when hand already owns them.
- analyst: remove data analysis, analyze data, dashboard (owned by hand/analytics)
- data-scientist: remove statistical analysis, forecast, prediction (owned by hand/analytics, hand/predictor)
- sales-assistant: remove prospecting, sales, pipeline (owned by hand/lead, hand/devops)
- devops-lead: remove incident response, kubernetes, terraform (owned by hand/devops)
- researcher: remove deep research, research, literature review (owned by hand/researcher)
- academic-researcher: remove literature review, systematic review (owned by hand/researcher)
- social-media: remove duplicate content calendar from weak_aliases
- hand/collector: remove competitive analysis (owned by hand/strategist)
* feat: add Qwen International and US provider catalogs
* refactor: merge qwen-us into qwen-intl with regions support
* refactor: merge regional providers into single files with regions
Merge qwen-intl.toml into qwen.toml with [provider.regions] for
intl (Singapore) and us (Virginia) endpoints.
Merge minimax-cn.toml into minimax.toml with [provider.regions.china]
including separate api_key_env for China endpoint.
Uses new RegionConfig table format instead of simple string URLs.
* feat: add 4 context engine plugins
- topic-memory: keyword clustering for topic-aware memory recall
- episodic-memory: conversation segmentation and cross-session recall
- user-profile: persistent user profiling from conversation patterns
- context-decay: time-based memory decay with reinforcement dynamics
All plugins use the ingest/after_turn hook protocol with stdin/stdout JSON.
* chore: add plugin scaffolding, update docs and templates
- Add plugin.toml template with {{NAME}} placeholder
- Add new-plugin Makefile target with hooks/ scaffolding
- Update plugins/README.md with all 10 plugins
- Update README.md stats (10 plugins, 220+ models)
- Add Plugin checkbox and checklist to PR template
- Add Plugin to issue template content type dropdown
- Fix CONTRIBUTING.md: last_verified is recommended, not required
* fix: correct model pricing and remove deprecated entries
- openrouter/gemma-2-9b-it: fix pricing from 0.0 to 0.03/0.09 per M tokens
(free variant correctly stays at 0.0)
- github-copilot: remove deprecated copilot/gpt-4 model entry
(GPT-4 retired in favor of GPT-4o for Copilot)
* docs: annotate kimi-coding as membership-gated
Kimi Code CLI uses quota-based membership model (not per-token billing).
Free tier has limited weekly requests; underlying model is K2.5.
Pricing kept at 0.0 consistent with other subscription providers
(chatgpt, github-copilot) but with explanatory comments.
* style: fix trailing newline in github-copilot.toml
* fix: correct Moonshot/Kimi model pricing from official sources
All 5 models had incorrect pricing:
- moonshot-v1-8k: 0.10/0.10 → 0.20/2.00
- moonshot-v1-32k: 0.30/0.30 → 1.00/3.00
- moonshot-v1-128k: 0.80/0.80 → 2.00/5.00
- kimi-k2: 2.00/8.00 → 0.60/2.50
- kimi-k2.5: 2.00/8.00 → 0.45/2.20
Sources: platform.moonshot.ai/docs/pricing/chat, costgoat.com, getmaxim.ai
* feat: add MiniMax M2.7 and M2.7-highspeed models
Released 2026-03-18, MiniMax's latest flagship text model.
10B activated params, 200K context, 128K output, tool use, streaming.
Pricing: $0.30/$1.20 per M tokens (input/output).
Added to both international (minimax.io) and China (minimaxi.com) providers.
* chore: remove router agent
builtin:router has been replaced by LLM intent routing in the kernel.
Assistant is now the sole entry point — see librefang/librefang#1336.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* style: format all TOML files with taplo
Fix CI taplo format check by running `taplo fmt` on all 132 TOML files.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Add Doubao Seed 2.0 Pro (frontier, 256K context, 128K output)
- Add Doubao Seed 2.0 Code
- Add Doubao Seed 1.8 (multimodal agent model with vision)
- Add Doubao Seed 1.6 Vision
- Update existing 2.0 Lite/Mini with correct specs (256K/128K, vision)
- Update global alias "doubao" to point to 2.0 Pro
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Community-maintained TOML catalog for LibreFang. New models can be added
via PR without requiring a LibreFang binary release.
Includes validation script, bilingual docs, and GitHub templates.