Commit Graph
20 Commits
Author SHA1 Message Date
Evan Hu 74745f1f20 ci: sign plugins-index.json in-repo, drop worker signing dependency
Pair with the worker-side simplification on the librefang PR — the
worker is now a pure transport (no key material, no signing) and this
repo's CI takes over signature production.

scripts/sign-plugins-index.mjs reads REGISTRY_PRIVATE_KEY from a GitHub
Actions secret, signs plugins-index.json with Ed25519, and writes
plugins-index.json.sig alongside it. Aborts loudly when the secret is
missing so a misconfigured CI can't silently ship an unsigned payload.

The workflow now runs build → sign → commit (.json + .sig) → push →
poke worker /refresh. The worker fetches the committed .json + .sig
verbatim and stores both — the daemon then verifies against the
embedded pubkey it ships with.

Closes PR review CRITICAL #1: the worker is no longer a sign-anything
oracle reachable via REGISTRY_REFRESH_TOKEN. Trust root is now this
repo's branch protection + Actions secret scope, not a token any CI
job that can talk to stats.librefang.ai can use to mint signatures.

Note: the keypair was rotated as part of this change (PR not yet
merged so no daemon TOFU pins exist). New pubkey:
  ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0=
The plugins-index.json.sig committed here is signed with the matching
new private key, in lockstep with the daemon EMBEDDED_REGISTRY_PUBKEY
constant and all three worker [vars] entries.
2026-05-05 01:02:58 +09:00
Evan Hu ff6f3f2b25 ci: build registry-index.json in-repo for dashboard real-time updates
Pair with the existing plugins-index.json path (which feeds the
daemon's signed install lane). registry-index.json mirrors the
dict-shaped payload the registry-worker's cron currently builds via
40+ GitHub Contents API calls — but built locally from the checked-out
tree by scripts/build-registry-index.mjs, so the worker only fetches
ONE file per category type (2 total: plugins + registry) on refresh.

Workflow now picks up content changes across all 8 category dirs
(was: plugins/ only) so dashboard updates land within seconds of a
push instead of waiting for the 02:00 UTC cron tick.

The dashboard's /api/registry endpoint reads kv_store('registry_data');
the worker's forced-refresh now writes that key with these bytes and
purges the Cache-API entry, so the next dashboard hit sees fresh
data instead of the 1h-cached previous payload.

Generated counts on first build: 11p 17h 32a 60s 44c 57pr 22w 33mcp.
2026-05-05 00:43:30 +09:00
Evan Hu f9821d5867 ci: build plugins-index.json in-repo so worker refresh stays under budget
Walking ~40+ plugin TOMLs via the GitHub Contents API from the worker
exceeded the Workers Free 50-subrequest-per-invocation limit, leaving
the daemon's signed plugins index either empty or partial after every
forced refresh.

Move the walk into the repo: scripts/build-plugins-index.mjs reads each
plugins/<name>/plugin.toml directly from the checked-out tree and emits
a sorted flat array (name, version?, description?, needs?) at
plugins-index.json. The CI workflow regenerates and commits this file
on every push under plugins/, then pokes the worker's
/api/registry/refresh — which now fetches the single committed
plugins-index.json (1 subrequest), validates the JSON shape, and
re-signs it with Ed25519. Refresh cost is now constant in registry
size, not linear.

The dashboard's dict-shaped /api/registry payload is unchanged — that
still rebuilds via the daily 02:00 UTC cron.
2026-05-05 00:37:50 +09:00
Evan 82d5a6ecd5 feat(minimax): add image/audio/video/music model entries (#77)
Extend modality enum to support video and music, then register the
non-text MiniMax models that were already declared in
media_capabilities but had no concrete entries:

- image-01 ($0.0035/image)
- speech-2.8/2.6 hd & turbo ($60-$100 per 1M chars)
- Hailuo 2.3 Fast / 2.3 / 02 video models ($0.10-$0.56 per video)
- music-2.6, lyrics_generation

Per-call pricing is documented in inline comments since the schema's
token-based cost fields don't naturally fit per-call billing.

schema.toml and scripts/validate.py both updated; the change is
additive (existing modality values remain valid).
2026-04-27 09:44:14 +09:00
Evan 5909b024c1 feat(openai): add GPT Image 2 (image-generation modality) (#71)
Introduces image-generation models as a first-class [[models]] entry via
a new `modality` field on the model schema ("text" default, "image",
"audio"). When modality != "text", context_window / max_output_tokens
are optional since no conventional context gate exists — OpenAI's
gpt-image-2 docs omit them.

Adds `image_input_cost_per_m` / `image_output_cost_per_m` alongside
existing text token cost fields to cover the 4-price structure OpenAI
uses for image generation (text $5/$10, image $8/$30 per 1M tokens).

Validator updated to:
- accept any modality in {text, image, audio}
- require context_window/max_output_tokens only for modality=text
- range-check the two new cost fields

gpt-image-2 entry added to providers/openai.toml with pricing sourced
from https://developers.openai.com/api/docs/pricing. Snapshot
gpt-image-2-2026-04-21 listed as alias.
2026-04-25 13:30:07 +09:00
Evan d43077afa9 fix(providers): remove ~anthropic, skip ~ prefixes in sync script (#69)
* fix(providers): remove ~anthropic, skip ~ prefixes in sync script

OpenRouter uses ~ prefixes for internal auto-routing aliases (e.g. ~anthropic).
These are not real providers — they already route through openrouter.toml.
The generated ~anthropic.toml was confusing (looked like a stale backup)
and redundant with the existing openrouter provider.

- Delete providers/~anthropic.toml
- Skip provider IDs starting with ~ in sync-pricing.py --create-missing

* fix(providers): remove morph, aider, kwaipilot

- morph: specialized code-editing/patching tool, not a general LLM provider
- aider: CLI meta-tool wrapper (base_url empty), redundant with claude-code/codex-cli/gemini-cli/qwen-code
- kwaipilot: Kwai internal coding assistant routed via OpenRouter, niche

* fix(sync): add morph/aider/kwaipilot to SKIP_PROVIDERS to prevent re-creation

* feat(sync): merge OpenRouter-only providers into openrouter.toml

Instead of generating standalone .toml files that just wrap the OpenRouter
endpoint, merge their models directly into openrouter.toml with the
standard 'openrouter/{provider}/{model}' ID convention.

- Add _build_model_fields() and _model_lines() helpers to deduplicate
  model rendering between standalone and merged paths
- Add merge_into_openrouter() that appends new models idempotently
- generate_provider_toml() now only runs for providers in PROVIDER_API
- --create-missing routes OpenRouter-only providers to merge_into_openrouter

* fix(providers): remove 14 OpenRouter-only standalone files

These providers have no direct public API and all route through
openrouter.ai/api/v1. Per the new sync-pricing.py policy, their models
will be merged into openrouter.toml on the next CI run instead of
living in separate files that just wrap the OpenRouter endpoint.

Removed: allenai, deepcogito, essentialai, inclusionai, inflection,
liquid, meituan, nex-agi, nousresearch, prime-intellect, relace,
switchpoint, tngtech, writer

* fix(providers): remove 7 niche providers with no driver support

No dedicated LLM driver code exists for these providers — they rely
purely on OpenAI-compatible passthrough with no special handling.
Removing them reduces registry noise; users can still reach them via
openrouter.toml if needed.

Removed: microsoft, ibm-granite, xiaomi, upstage, inception, aion-labs, arcee-ai

* fix(providers): remove ai21, chutes, venice

All three use ApiFormat::OpenAI with no special handling — pure passthrough.
No registry entry needed; users can reach them via openrouter.toml or by
adding a custom provider.

* docs(providers): rewrite README with full provider catalog and inclusion criteria

- List all 46 providers grouped by category with descriptions
- Document why each provider exists (direct API, unique endpoint, dedicated driver, local, CLI)
- Add inclusion criteria section explaining when to create standalone files vs merging into openrouter.toml
- Document sync script routing logic
- Update model counts: 49→46 providers, 339→232 models

* docs: add comprehensive READMEs for all registry sections + deepinfra provider

- agents/README.md: 32 agents across 7 categories with capability field reference
- channels/README.md: 44 channels across 5 categories with protocol reference table
- hands/README.md: 18 hands across 5 categories with HAND.toml format guide
- mcp/README.md: 33 MCP servers across 5 categories with transport/auth format
- plugins/README.md: 12 plugins with hook protocol documentation
- skills/README.md: 60 skills across 9 categories with SKILL.md format guide
- providers/deepinfra.toml: add DeepInfra serverless inference (5 models)
2026-04-24 00:02:33 +09:00
Evan 38899238d7 chore: rename integrations/ directory to mcp/ (#64) 2026-04-17 23:38:44 +09:00
Evan HuandClaude Opus 4.6 6c0faf06ef refactor(skills): make SKILL.md the required entry point
Standardize on Claude Code's SKILL.md format as every skill's source of
truth. skill.toml becomes an optional metadata layer for runtime, input
schema, and versioning — never for the prompt body.

- validate.py: require SKILL.md in every skill dir; when skill.toml also
  exists, cross-check name/description consistency to prevent drift
- Add SKILL.md to the two custom-skill examples
- Move the meeting-agenda prompt body out of skill.toml into SKILL.md
- Rewrite skills/README.md to document the md-first, toml-as-metadata convention

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-10 20:23:06 +09:00
Evan HuandClaude Opus 4.6 adf2323330 fix(validate): accept SKILL.md as skill definition
Claude Code-style skills use SKILL.md with YAML frontmatter instead of
skill.toml. Validator now accepts either form, unblocking the 60 bundled
skills restored in #42.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-10 20:18:37 +09:00
Evan c192f493b4 fix: route providers through correct APIs (#39)
Providers with known public APIs use their official endpoints:
- meta-llama → api.llama.com/v1
- microsoft → models.inference.ai.azure.com (GitHub Models)
- ibm-granite → us-south.ml.cloud.ibm.com/ml/v1 (watsonx)
- tencent → api.hunyuan.cloud.tencent.com/v1
- morph → api.morphllm.com/v1

16 remaining providers without known public APIs route through
OpenRouter (base_url = openrouter.ai/api/v1, OPENROUTER_API_KEY).

sync-pricing.py updated with PROVIDER_API mapping.
2026-04-02 23:55:42 +08:00
Evan aa5822992a fix: route OpenRouter-only providers through OpenRouter API (#38)
Providers without their own public API now use OpenRouter as their
base_url with OPENROUTER_API_KEY, making them testable and usable
when the user has an OpenRouter key configured.

- 20 OpenRouter-only providers: set base_url to openrouter.ai/api/v1
- morph: set correct official API (api.morphllm.com/v1)
- sync-pricing.py: default to OpenRouter routing for new providers
2026-04-02 23:41:25 +08:00
Evan 2fa48bfdcb fix: clean up OpenRouter-generated provider configs (#37)
- Merge unique models from duplicate providers into their hand-written
  counterparts and remove the duplicates:
  - alibaba (tongyi-deepresearch) → qwen
  - amazon (nova-2-lite, nova-micro, nova-premier) → bedrock
  - bytedance (ui-tars) → volcengine
  - nvidia (nemotron-3-nano, nemotron-3-super, etc.) → nvidia-nim
  - rekaai (reka-flash-3) → reka
- Set correct official API base_url for providers with public APIs:
  arcee-ai, inception, morph, reka, upstage
- Set key_required=false for 20 providers only accessible through
  hosting platforms (no public API)
- Update sync-pricing.py with SKIP_DUPLICATES, PROVIDER_API mapping,
  and default key_required=false for future auto-generated providers
2026-04-02 23:30:56 +08:00
Evan fc37ce253b fix: correct invalid tier "free" and teams-mcp id with version (#29)
- Replace tier "free" with "fast" (valid tiers: frontier/smart/balanced/fast/local)
- Remove version suffix from teams-mcp integration id field
- Update sync-pricing.py to not generate invalid tier values
2026-03-25 23:49:39 +09:00
Evan 553ecc6947 feat: add pricing sync script and update model prices from OpenRouter (#27)
* fix: pin npm package versions in MCP integration templates

Prevent supply chain attacks by pinning exact versions instead of
using unpinned `npx -y @package` which pulls latest on every run.

23 of 25 integrations pinned. sqlite-mcp and aws skipped (packages
not found on npm registry).

* fix: use stable azure/mcp version instead of beta

* feat: add pricing sync script and update model prices from OpenRouter API

- scripts/sync-pricing.py fetches real-time pricing from OpenRouter
- Updated 64 price fields across 13 provider files
- Run periodically or in CI to keep prices current
2026-03-25 23:43:13 +09:00
Evan d778da72a2 fix(validate): check for [agents] instead of [agent] in HAND.toml (#15)
* fix(validate): check for [agents] instead of [agent] in HAND.toml

All 14 hands use [agents.main] (plural) for multi-agent config,
but the validator was checking for [agent] (singular), causing
all hands to fail validation.

* fix(routing): resolve 19 routing alias collisions

Agent is a sub-unit of hand, so hands take priority for routing.
Remove conflicting aliases from agent side when hand already owns them.

- analyst: remove data analysis, analyze data, dashboard (owned by hand/analytics)
- data-scientist: remove statistical analysis, forecast, prediction (owned by hand/analytics, hand/predictor)
- sales-assistant: remove prospecting, sales, pipeline (owned by hand/lead, hand/devops)
- devops-lead: remove incident response, kubernetes, terraform (owned by hand/devops)
- researcher: remove deep research, research, literature review (owned by hand/researcher)
- academic-researcher: remove literature review, systematic review (owned by hand/researcher)
- social-media: remove duplicate content calendar from weak_aliases
- hand/collector: remove competitive analysis (owned by hand/strategist)
2026-03-23 09:41:29 +09:00
Evan Hu a8b7c9d08b feat: comprehensive registry improvements
Community docs:
- CODE_OF_CONDUCT.md (Contributor Covenant v2.1)
- SECURITY.md (vulnerability reporting policy)
- CHANGELOG.md (initial release notes)
- CODEOWNERS (per-type review ownership)

GitHub config:
- Issue templates: bug-report, pricing-correction, documentation
- FUNDING.yml (GitHub Sponsors)

Validation enhancements:
- Cross-reference check: hand [[requires]] → integration existence
- Routing alias collisions as warnings (errors with --strict)
- --strict flag to promote warnings to errors
- --type filter to validate single content type
- CI: add taplo format check and lychee link check jobs

Developer experience:
- Makefile with validate, fmt, and scaffold targets
- Scaffold templates for all 5 content types
- .pre-commit-config.yaml (trailing whitespace, TOML check, validate)
- docs/content-guide.md (naming, descriptions, prompts, decision guide)

Content quality:
- schema.toml: add last_verified field for model pricing
- CONTRIBUTING.md: add pricing verification guide with source links
2026-03-21 02:46:04 +09:00
Evan Hu 206169c1d7 docs: add README for every content directory
Each directory (agents, hands, integrations, plugins, providers,
scripts, skills) now has a README documenting its TOML format,
current contents, and contribution steps.
2026-03-21 02:24:22 +09:00
Evan Hu d1bc8ead69 chore: cleanup repo and enhance validation
- Add .gitignore (.DS_Store, .vscode, __pycache__)
- Remove stale .gitkeep files (directories have content now)
- Expand schema.toml to document all 6 content types (agent, hand, integration, skill, plugin)
- Add plugin validation and contribution guide
- Add id/name vs directory name consistency checks
- Add cross-type routing alias collision detection (14 warnings found)
2026-03-21 02:21:24 +09:00
Evan Hu 1f3ef406ee docs: rewrite README and CONTRIBUTING for full registry scope
- README now covers all 5 content types (agents, hands, integrations, skills, providers)
- CONTRIBUTING has per-type instructions and checklists
- validate.py expanded to validate agents, hands, integrations, and skills
- PR template covers all content types
- Added new-content.yml issue template for non-model contributions
- CI workflow updated to Python 3.12
2026-03-21 02:10:12 +09:00
Evan 21c82e335c feat: initial model catalog with 196 models across 39 providers
Community-maintained TOML catalog for LibreFang. New models can be added
via PR without requiring a LibreFang binary release.

Includes validation script, bilingual docs, and GitHub templates.
2026-03-14 11:52:10 +09:00