* feat(devops): add auto-evolution loop (PR review + BMAD bug/feature pipeline)
Extends the DevOps Hand to periodically scan configured GitHub repos and:
- review open PRs via the existing code-reviewer sub-agent, posting a
single COMMENT review back to GitHub (never auto-APPROVE)
- triage open issues via labels first, single-prompt LLM fallback
- dispatch actionable issues (bug-fix / feature) to a new implementer
sub-agent which runs the BMAD pipeline (Brainstorm -> Architect ->
PRD -> Implement) scaled by bmad_strictness and produces a DRAFT PR
Safety floor (always on):
- draft PRs only, never auto-ready, never merge
- never push to main/master/protected branches
- escalates to devops_queue.json when touching workspace Cargo.toml,
migrations, secrets, or >30 changed files
- 70% per-turn token budget cap so subsequent ticks have headroom
New settings: auto_evolve, evolution_repos, evolution_check_interval,
bmad_strictness. New sub-agent: agents.implementer. New SKILL.md
sections: Issue Triage Playbook, PR Review Automation, Bug Fix
Playbook, BMAD Feature Pipeline, Draft PR Creation. Three new
dashboard metrics: prs_reviewed, issues_processed, draft_prs_opened.
* fix(devops): address PR review — close blocking + medium + style issues
Blocking (5):
- add max_changed_files setting (was referenced in implementer prompt
but never defined)
- drop metering_query reference (tool isn't in tools = [...] list);
agent self-paces against budget instead
- fix \n\n literal in jq --arg for issue cross-link comment; compose
body in shell with printf so newlines survive
- resolve BASE_BRANCH via /repos/owner/repo .default_branch instead
of relying on an undefined variable
- complete reviewer-verdict → GitHub review-event mapping (4 cases,
not just request_changes); block routes through REQUEST_CHANGES
with a blocking-prefix in the body, approve downgrades to COMMENT
Medium (5):
- correct Phase 6 → Phase 7 in the auto-evolution settings comment
- remove schedule_create busy-loop confusion; Phase 7 fires per-turn
while the Hand is already frequency = "continuous", with cadence
enforced via devops_evolution_cursor memory key
- generalize the forbid-main-worktree wording — discover and honor
whatever pre-commit / pre-push / commit-msg hooks the upstream
repo configures (was librefang-specific)
- clarify the AI-attribution rule: ban LLM-vendor attribution
(Claude, GPT, 🤖, etc.) but allow process attribution
(DevOps Hand → implementer) for traceability
- add USER_TYPE = "Bot" short-circuit that was extracted but never
applied (bots get a token-cheap skip, not a deep review)
Style (2):
- document the four event_publish event names (devops_evolution_*)
in a new SKILL.md table alongside the memory-keys table
- justify implementer's max_history_messages = 100 with a comment
(BMAD 4 phases × cargo build/test chains needs headroom)
* docs(devops): tighten evolution snippets (D1-D4 second-review nits)
D1 -- show SUMMARY_BODY (and VERDICT) assignment in PR review snippet:
add explicit jq -r .summary / .verdict extraction from reviewer_output.json
so the agent reading SKILL.md doesn't have to infer where these come from.
D2 -- reword strict-mode wait semantics in both HAND.toml and SKILL.md:
'Stop. Wait...' was misleading because the agent loop has no in-turn
pause primitive. Now spells out: end the current turn after queueing,
let the continuous tick re-read the queue, resume on approved / skip
on pending / abandon on rejected. Explicitly forbids busy-wait and
sleep loops.
D3 -- restructure bot / huge-diff short-circuit so agent-tool calls are
expressed as numbered agent steps, not as '# memory_store ...' comments
inside a bash block. The bash block now only extracts cheap signals;
the decision and the tool calls are clearly agent-level.
D4 -- remove the misleading 'exit 0' from the short-circuit bash and
add a one-liner noting that exit 0 inside shell_exec only ends one
shell session, not the Phase 7 pass; the agent must choose to move on.
Hands Registry
Hands are pre-packaged capability bundles that compose agents, tools, skills, MCP servers, and plugins into a working application. Installing a hand gives you a complete, ready-to-use workflow — not just a single agent.
"You have many hands helping you."
A hand can contain one agent (single-agent) or multiple coordinated agents (multi-agent). Each agent in a multi-agent hand can have its own role-specific skills, model config, and capability restrictions.
File Format
Each hand lives in its own subdirectory:
hands/
├── researcher/
│ ├── HAND.toml # required: hand definition
│ └── SKILL.md # optional: shared reference knowledge for all agents
├── devteam/
│ ├── HAND.toml
│ ├── SKILL-pm.md # optional: role-specific knowledge for PM agent
│ ├── SKILL-engineer.md # optional: role-specific knowledge for Engineer agent
│ └── SKILL-qa.md # optional: role-specific knowledge for QA agent
HAND.toml format
id = "researcher"
version = "1.1.1"
name = "Researcher Hand"
description = "Autonomous deep researcher — exhaustive investigation, cross-referencing, fact-checking, and structured reports"
category = "productivity" # productivity | development | data | content | communication
icon = "lucide:flask-conical"
# Tools available to all agents in this hand
tools = [
"shell_exec", "file_read", "file_write", "web_fetch", "web_search",
"memory_store", "memory_recall", "knowledge_query", "event_publish",
]
# MCP servers all agents can use
mcp_servers = ["github"]
# Skills allowlist (empty = all available)
skills = []
# Plugin allowlist
allowed_plugins = ["todo-tracker", "auto-summarizer"]
# ─── Routing ──────────────────────────────────────────────────────────────────
[routing]
aliases = ["deep research", "investigate", "fact check"] # exact activation phrases
weak_aliases = ["research", "look into"] # keyword hints
# ─── Configurable settings ────────────────────────────────────────────────────
[[settings]]
key = "research_depth"
label = "Research Depth"
description = "How exhaustive each investigation should be"
setting_type = "select" # select | toggle | text
default = "thorough"
[[settings.options]]
value = "quick"
label = "Quick (5-10 sources, 1 pass)"
[[settings.options]]
value = "thorough"
label = "Thorough (20-30 sources, cross-referenced)"
# ─── Single-agent definition ──────────────────────────────────────────────────
[agent]
name = "researcher"
base = "researcher" # inherits from agents/researcher/agent.toml
[agent.model]
system_prompt = """Custom prompt override..."""
# ─── Multi-agent definition (alternative to [agent]) ─────────────────────────
[agents.pm]
coordinator = true
base = "planner" # inherits from agents/planner/agent.toml
invoke_hint = "Task coordination and issue triage"
[agents.engineer]
base = "coder"
invoke_hint = "Implementation"
[agents.qa]
base = "test-engineer"
invoke_hint = "Quality assurance and validation"
# ─── Dashboard metrics ────────────────────────────────────────────────────────
[dashboard]
[[dashboard.metrics]]
label = "Reports Written"
memory_key = "metric_reports_written"
format = "number"
# ─── i18n ─────────────────────────────────────────────────────────────────────
[i18n.zh]
name = "研究员"
description = "自主深度研究员 — 详尽调查、交叉核实、事实核查与结构化报告"
Installing and Using Hands
# List all available hands
librefang catalog hands
# Install a hand
librefang hand install researcher
# Install with a specific agent name
librefang hand install researcher --name my-researcher
# List installed hands
librefang hand list
# Remove a hand
librefang hand remove my-researcher
All Hands (18 total)
Productivity
| ID | Name | Category | Description |
|---|---|---|---|
| researcher | Researcher Hand | productivity | Autonomous deep researcher — exhaustive investigation, cross-referencing, fact-checking, and structured reports |
| strategist | Strategist Hand | productivity | Autonomous strategy analyst — market research, competitive analysis, business planning, and strategic recommendations |
| wiki | Wiki Hand | productivity | LLM-maintained personal knowledge base — builds an Obsidian-compatible wiki from raw sources with provenance tracking |
| browser | Browser Hand | productivity | Autonomous web browser — navigates sites, fills forms, clicks buttons, and completes multi-step web tasks |
Development
| ID | Name | Category | Description |
|---|---|---|---|
| devteam | Dev Team | development | Autonomous software development team — PM triages issues, Engineer implements, QA validates |
| devops | DevOps Hand | development | Autonomous DevOps engineer — CI/CD management, infrastructure monitoring, deployment automation, and incident response |
| apitester | API Tester Hand | development | Autonomous API testing agent — endpoint discovery, request validation, load testing, and regression detection |
Data
| ID | Name | Category | Description |
|---|---|---|---|
| analytics | Analytics Hand | data | Autonomous data analytics agent — data collection, analysis, visualization, dashboards, and automated reporting |
| collector | Collector Hand | data | Autonomous intelligence collector — monitors any target continuously with change detection and knowledge graphs |
| lead | Lead Hand | data | Autonomous lead generation — discovers, enriches, and delivers qualified leads on a schedule |
| predictor | Predictor Hand | data | Autonomous future predictor — collects signals, builds reasoning chains, makes calibrated predictions, and tracks accuracy |
| trader | Trading Hand | data | Autonomous market intelligence and trading engine — multi-signal analysis, adversarial bull/bear reasoning, and strict risk management |
Content
| ID | Name | Category | Description |
|---|---|---|---|
| clip | Clip Hand | content | Turns long-form video into viral short clips with captions and thumbnails |
| creator | Creator Hand | content | AI media studio — generates images, videos, music, and speech from text prompts |
Communication
| ID | Name | Category | Description |
|---|---|---|---|
| LinkedIn Hand | communication | Autonomous LinkedIn manager — profile optimization, content creation, networking, and professional engagement | |
| Reddit Hand | communication | Autonomous Reddit manager — monitors subreddits, posts content, replies to threads, and tracks engagement | |
| Twitter Hand | communication | Autonomous Twitter/X manager — content creation, scheduled posting, engagement, and performance tracking |
Data (additional)
| ID | Name | Category | Description |
|---|---|---|---|
| clip | Clip Hand | content | Turns long-form video into viral short clips with captions and thumbnails |
Resource Composition Summary
| Resource | How to compose | Notes |
|---|---|---|
| Agent templates | base = "coder" on [agents.*] |
Inherits prompt, model config, fallbacks from agents/coder/agent.toml |
| Tools | tools = [...] at hand level |
All agents in the hand share these built-in tools |
| Skills | skills = [...] at hand level |
Empty list means all available skills are allowed |
| MCP servers | mcp_servers = [...] at hand level |
Agent interacts via MCP tools, not hardcoded API calls |
| Plugins | allowed_plugins = [...] at hand level |
Empty list means all installed plugins are allowed |
| Per-agent knowledge | SKILL-{role}.md files |
Different reference prompts per agent role |
| Per-agent capabilities | [agents.*.capabilities] |
Fine-grained shell / network / memory per agent |
Adding a New Hand
- Create
hands/<name>/HAND.tomlwith at leastid,name,description, andcategory. - Add
SKILL.md(shared) orSKILL-{role}.md(per-agent) files for reference knowledge. - Use
base = "agent-name"in each[agents.*]block to inherit from existing agent templates. - Specify
mcp_servers,skills, andallowed_pluginsfor resource composition. - Ensure
idmatches the directory name. - Run
python scripts/validate.py. - Submit a PR.
See CONTRIBUTING.md for the full guide.