* fix(creator): raise max_history_messages to 80 for polling workflows
Creator Hand's async video_generate path polls video_status every 15-20s
until completion (1-3 min typical), consuming ~5-15 turns per video
request. Combined workflows (video + TTS + music) plus normal back-and-
forth cross the kernel default of 40 messages quickly, which surfaced
in user logs as:
WARN run_agent_loop: Trimming old messages at safe turn boundary
agent=creator:creator-hand total_messages=41 trimming=2
INFO run_agent_loop: prompt cache metrics for turn
hit_ratio=0.0 creation=0 read=0
Every turn was hitting the trim cap and invalidating the prompt-cache
prefix. 80 covers ~30 polling iterations plus a comfortable pre-context
window without runaway memory growth. Other hands keep the default 40.
* ci(refresh-cache): open PR instead of pushing directly to main
Branch protection on `main` started rejecting the workflow's auto-commit
with GH006 "Changes must be made through a pull request" — see run
25632824585 on 2026-05-10 against commit 6785807 (the first push that
hit the tightened protection). Direct push is precisely what the file's
own security comment (#1) warns against ("Compromised maintainer pushes
a malicious plugins-index.json directly to main. Mitigation: GitHub
branch protection on main requires PR review"), so the fix preserves
that gate rather than working around it.
The workflow now creates a short-lived `automation/refresh-indexes-<sha>`
branch, commits the regen there, pushes, and opens a PR back to main
via `gh pr create`. Maintainers see a one-click squash-merge.
Permissions: add `pull-requests: write` to the existing `contents: write`
so `gh pr create` can be authorised through the default GITHUB_TOKEN.
The post-merge run on the index PR is a no-op (no diff under
`hands/**`, `plugins/**`, etc. between consecutive states), so no
`[skip ci]` marker is needed and no loop is possible.
Without this fix, every content PR landing on main leaves
plugins-index.json + registry-index.json stale, blocking new agents and
hands from reaching daemons until a maintainer manually regenerates.
* fix(hands): raise max_history_messages on long-workflow coordinators
Three hand coordinators have workflows that routinely exceed the kernel
default history cap on a single user turn:
- researcher (max_iterations=80) — deep web_search → web_fetch →
summarize loops with multi-source synthesis. 80 iterations × ~4
messages each → 200+ messages per user turn. Set to 120.
- devops (max_iterations=60) — incident response and CI/CD fan out
into long shell_exec chains (logs, retries, post-mortems). Set to 80.
- predictor (max_iterations=60) — long reasoning chains accumulating
signals across many web/knowledge queries, with scheduled re-checks
referring back. Set to 80.
Creator's existing override is rephrased "raise above the kernel
default" so the comment stays correct regardless of the order this PR
and the upstream kernel-default bump (librefang side) land in.
Other hands (lead/linkedin/reddit/clip/analytics/apitester/browser/
collector/strategist) stay on the kernel default; the upstream bump
covers them.
Hands Registry
Hands are pre-packaged capability bundles that compose agents, tools, skills, MCP servers, and plugins into a working application. Installing a hand gives you a complete, ready-to-use workflow — not just a single agent.
"You have many hands helping you."
A hand can contain one agent (single-agent) or multiple coordinated agents (multi-agent). Each agent in a multi-agent hand can have its own role-specific skills, model config, and capability restrictions.
File Format
Each hand lives in its own subdirectory:
hands/
├── researcher/
│ ├── HAND.toml # required: hand definition
│ └── SKILL.md # optional: shared reference knowledge for all agents
├── devteam/
│ ├── HAND.toml
│ ├── SKILL-pm.md # optional: role-specific knowledge for PM agent
│ ├── SKILL-engineer.md # optional: role-specific knowledge for Engineer agent
│ └── SKILL-qa.md # optional: role-specific knowledge for QA agent
HAND.toml format
id = "researcher"
version = "1.1.1"
name = "Researcher Hand"
description = "Autonomous deep researcher — exhaustive investigation, cross-referencing, fact-checking, and structured reports"
category = "productivity" # productivity | development | data | content | communication
icon = "lucide:flask-conical"
# Tools available to all agents in this hand
tools = [
"shell_exec", "file_read", "file_write", "web_fetch", "web_search",
"memory_store", "memory_recall", "knowledge_query", "event_publish",
]
# MCP servers all agents can use
mcp_servers = ["github"]
# Skills allowlist (empty = all available)
skills = []
# Plugin allowlist
allowed_plugins = ["todo-tracker", "auto-summarizer"]
# ─── Routing ──────────────────────────────────────────────────────────────────
[routing]
aliases = ["deep research", "investigate", "fact check"] # exact activation phrases
weak_aliases = ["research", "look into"] # keyword hints
# ─── Configurable settings ────────────────────────────────────────────────────
[[settings]]
key = "research_depth"
label = "Research Depth"
description = "How exhaustive each investigation should be"
setting_type = "select" # select | toggle | text
default = "thorough"
[[settings.options]]
value = "quick"
label = "Quick (5-10 sources, 1 pass)"
[[settings.options]]
value = "thorough"
label = "Thorough (20-30 sources, cross-referenced)"
# ─── Single-agent definition ──────────────────────────────────────────────────
[agent]
name = "researcher"
base = "researcher" # inherits from agents/researcher/agent.toml
[agent.model]
system_prompt = """Custom prompt override..."""
# ─── Multi-agent definition (alternative to [agent]) ─────────────────────────
[agents.pm]
coordinator = true
base = "planner" # inherits from agents/planner/agent.toml
invoke_hint = "Task coordination and issue triage"
[agents.engineer]
base = "coder"
invoke_hint = "Implementation"
[agents.qa]
base = "test-engineer"
invoke_hint = "Quality assurance and validation"
# ─── Dashboard metrics ────────────────────────────────────────────────────────
[dashboard]
[[dashboard.metrics]]
label = "Reports Written"
memory_key = "metric_reports_written"
format = "number"
# ─── i18n ─────────────────────────────────────────────────────────────────────
[i18n.zh]
name = "研究员"
description = "自主深度研究员 — 详尽调查、交叉核实、事实核查与结构化报告"
Installing and Using Hands
# List all available hands
librefang catalog hands
# Install a hand
librefang hand install researcher
# Install with a specific agent name
librefang hand install researcher --name my-researcher
# List installed hands
librefang hand list
# Remove a hand
librefang hand remove my-researcher
All Hands (18 total)
Productivity
| ID | Name | Category | Description |
|---|---|---|---|
| researcher | Researcher Hand | productivity | Autonomous deep researcher — exhaustive investigation, cross-referencing, fact-checking, and structured reports |
| strategist | Strategist Hand | productivity | Autonomous strategy analyst — market research, competitive analysis, business planning, and strategic recommendations |
| wiki | Wiki Hand | productivity | LLM-maintained personal knowledge base — builds an Obsidian-compatible wiki from raw sources with provenance tracking |
| browser | Browser Hand | productivity | Autonomous web browser — navigates sites, fills forms, clicks buttons, and completes multi-step web tasks |
Development
| ID | Name | Category | Description |
|---|---|---|---|
| devteam | Dev Team | development | Autonomous software development team — PM triages issues, Engineer implements, QA validates |
| devops | DevOps Hand | development | Autonomous DevOps engineer — CI/CD management, infrastructure monitoring, deployment automation, and incident response |
| apitester | API Tester Hand | development | Autonomous API testing agent — endpoint discovery, request validation, load testing, and regression detection |
Data
| ID | Name | Category | Description |
|---|---|---|---|
| analytics | Analytics Hand | data | Autonomous data analytics agent — data collection, analysis, visualization, dashboards, and automated reporting |
| collector | Collector Hand | data | Autonomous intelligence collector — monitors any target continuously with change detection and knowledge graphs |
| lead | Lead Hand | data | Autonomous lead generation — discovers, enriches, and delivers qualified leads on a schedule |
| predictor | Predictor Hand | data | Autonomous future predictor — collects signals, builds reasoning chains, makes calibrated predictions, and tracks accuracy |
| trader | Trading Hand | data | Autonomous market intelligence and trading engine — multi-signal analysis, adversarial bull/bear reasoning, and strict risk management |
Content
| ID | Name | Category | Description |
|---|---|---|---|
| clip | Clip Hand | content | Turns long-form video into viral short clips with captions and thumbnails |
| creator | Creator Hand | content | AI media studio — generates images, videos, music, and speech from text prompts |
Communication
| ID | Name | Category | Description |
|---|---|---|---|
| LinkedIn Hand | communication | Autonomous LinkedIn manager — profile optimization, content creation, networking, and professional engagement | |
| Reddit Hand | communication | Autonomous Reddit manager — monitors subreddits, posts content, replies to threads, and tracks engagement | |
| Twitter Hand | communication | Autonomous Twitter/X manager — content creation, scheduled posting, engagement, and performance tracking |
Data (additional)
| ID | Name | Category | Description |
|---|---|---|---|
| clip | Clip Hand | content | Turns long-form video into viral short clips with captions and thumbnails |
Resource Composition Summary
| Resource | How to compose | Notes |
|---|---|---|
| Agent templates | base = "coder" on [agents.*] |
Inherits prompt, model config, fallbacks from agents/coder/agent.toml |
| Tools | tools = [...] at hand level |
All agents in the hand share these built-in tools |
| Skills | skills = [...] at hand level |
Empty list means all available skills are allowed |
| MCP servers | mcp_servers = [...] at hand level |
Agent interacts via MCP tools, not hardcoded API calls |
| Plugins | allowed_plugins = [...] at hand level |
Empty list means all installed plugins are allowed |
| Per-agent knowledge | SKILL-{role}.md files |
Different reference prompts per agent role |
| Per-agent capabilities | [agents.*.capabilities] |
Fine-grained shell / network / memory per agent |
Adding a New Hand
- Create
hands/<name>/HAND.tomlwith at leastid,name,description, andcategory. - Add
SKILL.md(shared) orSKILL-{role}.md(per-agent) files for reference knowledge. - Use
base = "agent-name"in each[agents.*]block to inherit from existing agent templates. - Specify
mcp_servers,skills, andallowed_pluginsfor resource composition. - Ensure
idmatches the directory name. - Run
python scripts/validate.py. - Submit a PR.
See CONTRIBUTING.md for the full guide.