Update agent-sh/agnix action to v0.55.0 - #18
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Owner
|
@rultor please, try to merge, since 8 checks have passed |
yegor256
approved these changes
Jul 3, 2026
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
July 4, 2026 18:04
c723dc5 to
b787421
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
July 5, 2026 02:03
b787421 to
d3519ea
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
July 15, 2026 18:13
d3519ea to
b03065a
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
2 times, most recently
from
July 16, 2026 15:51
c1231ad to
f4606cf
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
2 times, most recently
from
July 27, 2026 10:07
e3a59b1 to
a0bc579
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
July 31, 2026 02:45
a0bc579 to
36f6dc9
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
2 times, most recently
from
July 31, 2026 19:41
85b6a91 to
87eae5d
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
2 times, most recently
from
August 5, 2026 16:11
d07ebcf to
f428a3e
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 9, 2026 00:39
f428a3e to
31fe761
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 9, 2026 12:51
31fe761 to
1e58f1e
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 15, 2026 05:01
1e58f1e to
f3988ea
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 15, 2026 17:48
f3988ea to
b2a2002
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 25, 2026 13:45
b2a2002 to
dbbbd9d
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 27, 2026 01:08
dbbbd9d to
8138857
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 27, 2026 06:11
8138857 to
6674b6e
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
August 27, 2026 17:11
6674b6e to
568908b
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
September 6, 2026 01:46
568908b to
896c833
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
September 14, 2026 01:46
896c833 to
0d12e2d
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
September 16, 2026 11:32
0d12e2d to
c430747
Compare
renovate
Bot
force-pushed
the
renovate/agent-sh-agnix-0.x
branch
from
September 27, 2026 18:51
c430747 to
e3448bb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.36.2→v0.55.0Release Notes
agent-sh/agnix (agent-sh/agnix)
v0.55.0Compare Source
Added
would otherwise make the skill silently fail to load.
Fixed
omitClaudeMdsubagent field andvalidates its boolean type through the agent schema.
.cline/rules/now receive the same content andfrontmatter checks as Markdown rules under
.clinerules/.PermissionRequestwhilecontinuing to allow prompt hooks on that event.
amp.runner.autoUpdate.enabled,amp.remoteThreadCreation.enabled, andamp.updates.modesettings keys.ServerConfigname, keeping warning-deniedbuilds clean after the rmcp 3.4 update.
Changed
writing the formula directly to its default branch.
less-noise, Claude Code tov2.1.283, Cline tov4.1.21, Codex CLI torust-v0.157.1, Cursor to3.22.7, Gemini CLI tov0.61.0, Kiro CLI to2.24.0, and OpenCode tov1.18.32after reviewingtheir live releases. The OpenCode and Gemini releases do not change a
validated configuration format.
at v2.87.18, and anthropics/claude-code-action at v1.0.231.
Cursor, and MCP documentation. The Cline rules layout and Claude hook
behavior changes are handled above.
AGENTS.mdfallback and combined-instruction supportto the tracked compatibility surface. Existing AGM and XP rules already
validate the documented file, imports, hierarchy, and size constraints.
v2.1.278, Codex CLI torust-v0.155.1, and Cursorto
3.21.16; refresh the five changed Claude documentation hashes afterreviewing the current vendor sources. The other release changes affect
runtime classifier and reasoning-summary defaults outside validated schemas.
actions/setup-javav6.0.1, andanthropics/claude-code-actionv1.0.226.one-runner-is-now-enough, Claude Code tov2.1.276, Clineto
v4.1.19, Codex CLI torust-v0.155.0, Cursor to3.21.9, and Kiro CLIto
2.22.0after reviewing their primary release notes. Only Amp changed avalidated configuration contract; the other releases cover runtime, UI,
security, model, and session behavior outside the current schemas.
v0.54.0Compare Source
Added
matcherfield on Cursor hook entries as a regexstring, now that the hooks documentation types it as one.
Changed
versionin.cursor/hooks.jsonand checks that it is apositive integer, matching the hooks documentation's per-file options table.
after review. CUR-006 now cites the help-center migration guide, where the
.cursorrulesdeprecation notice moved.v2.1.273, Cursor to3.20.21, Gemini CLI tov0.60.0, and OpenCode tov1.18.31after reviewing their primary releasenotes. The changes are runtime, security, session-restoration, provider, and
cloud-agent updates outside agnix's validated configuration schemas.
rustlsto 0.23.45 to addressRUSTSEC-2026-0285, which allowedselected TLS 1.3 handshake messages at the wrong encryption level.
Fixed
egressAllowlist,egressMode,chromeExecutablePath,enable_testing,image, andbuild.dockerfileContentsfields, and validates their types.v0.53.0Compare Source
Added
maxEffortLevelcaps added inClaude Code 2.1.267.
Changed
features.worktrees,features.unified_exec_tty, and the new TUI preferences.and OpenCode release baselines after reviewing their primary release notes.
Refresh Cursor's hooks specification hash; its documented event and field
contracts remain covered by CUR-010 through CUR-019.
v2.1.263and refresh thecurrent hooks, memory, plugins, skills, and subagent documentation hashes.
The patch release contains reliability fixes only, and the documented
configuration contracts remain covered by existing rules.
v0.52.2Compare Source
Added
managedMcpServers.Changed
Cursor/Copilot spec, and Copilot inventory baselines.
action pins.
Fixed
Changed
CC-SET-030for local-command entries that Claude Code silently skips in
managedMcpServers; accept Codex CLI 0.153'stui.auto_recap,tui.disable_paste_burst, and experimental context-management keys; andrefresh Amp, Cline, Cursor, Kiro, OpenCode, and changed specification hashes.
and refresh the VS Code and docs-site npm lockfiles.
v2.1.258and Codex CLI to
rust-v0.152.1. Their primary notes contain only a macOSlaunch repair, remote-session message replay repair, and Guardian Node REPL
policy fix; neither patch changes a configuration schema agnix validates.
v1.18.26; its primaryrelease notes contain model-provider, replay, timing, patch metadata, Azure
sign-in, and desktop bug fixes, with no change to a configuration surface
agnix validates.
fable-5.1, ClaudeCode to
v2.1.257, Codex CLI torust-v0.152.0, Cursor to3.18.25, andGemini CLI to
v0.58.0after reviewing their current primary release notesand validated configuration surfaces. Refresh the Claude hooks, plugins,
skills, and subagent documentation hashes after confirming the documented
event, manifest, frontmatter, and matcher contracts remain covered by the
existing rules. Claude's new clock and read-boundary preferences are not
correctness constraints agnix currently validates; Codex's package-style MCP
names, per-tool output limits, app-server timeout, and opt-in planning flag
are accepted by the current lenient nested configuration handling. The Amp,
Cursor, and Gemini markers do not change a schema agnix validates.
uuidto 1.26.0, synchronize bothCodeQL steps on 4.37.8, and refresh the pinned setup-java, install-action,
and Claude Code action revisions.
amp-on-ios-and-macos, ClaudeCode to
v2.1.251, Codex CLI torust-v0.151.0, Cursor to3.18.9, OpenCodeto
v1.18.25, and Kiro CLI to2.20.0after reviewing their current upstreamnotes and validated configuration surfaces. Claude Code added the
PreModelSwitchandPostModelSwitchhook events, now accepted by theexisting
CC-HK-001rule; the other releases do not change a schema agnixvalidates. The
Codex research inventory now also records its shared
MCPrule family andaccepted
.yml,.mcp.json,[mcp_servers.*], and managed-environmentrequirements.tomlsurfaces, with parity regression assertions.Fixed
v0tag pushes no longer trigger the release pipeline. Therelease workflow matched every
v*tag, so the manually pushed floatingaction tag ran the entire pipeline with version "0": the semver verification
guards stopped crates.io, npm, PyPI, and VS Code, but a junk GitHub release
was created, a junk Zed update PR was opened, and a version-"0" plugin update
reached the JetBrains marketplace (all three cleaned up the same day; the
marketplace update was deleted via the vendor API). The trigger now matches
only semver-shaped tags (
v[0-9]*.[0-9]*.[0-9]*), which the automatedfloating-tag move never produces - and that move uses
GITHUB_TOKEN, whoseevents do not start workflows anyway.
Fixed
uses: agent-sh/agnix@v0did not resolve. The README, configurationguide, and marketplace snippet all instruct
agent-sh/agnix@v0, but nov0tag or branch has ever existed - every user who copied the documented GitHub
Action snippet got "unable to resolve action". The repo's own CI never
noticed because it exercises the action as
uses: ./. The floating tag nowexists (pointing at v0.52.1) and the release workflow force-moves it to each
new release commit, so the documented ref tracks the latest release the way
major-version action tags are expected to.
Fixed
brew install agnixbuilt v0.18.0from source because nothing told the tap about new releases: the tap's
update-formula.ymllistens for arelease-publisheddispatch that the mainrepository never sent. The tap has been dispatched to v0.52.1 manually, the
vestigial in-repo
Formula/agnix.rbcopy is synced to match, and release.yml nowdispatches the tap directly from a new
homebrewjob. A separaterelease: publishedworkflow could never have worked here: the release ispublished with the default
GITHUB_TOKEN, and events created byGITHUB_TOKENdo not start workflow runs - which is exactly how the driftstayed invisible. The job reuses the existing cross-repo
COMMITTER_TOKEN(already pushing to other repos in the zed and version-docs jobs), so no new
secret is needed; the dispatch shape was verified live against the tap's
update-formula.yml. Manual fallback staysgh workflow run update-formula.yml --repo agent-sh/homebrew-agnix -f tag=<tag>.Changed
section claimed v0.37.3 fifteen releases later; nothing in the bookkeeping
sync touches that line, so it now points at GitHub releases instead of
hardcoding a number that drifts.
v0.52.1Compare Source
Fixed
(#1444,
#1445). The
files:patternin
.pre-commit-hooks.yamlwas^(...)$-anchored with root-level entries, soSKILL\.mdmatched only a repository-root SKILL.md - a skill at its normal.claude/skills/<name>/SKILL.mdlocation, a nestedAGENTS.md, a pluginmanifest, or a scoped Copilot instruction file never reached agnix, and the
hook reported Passed with nothing validated. The pattern now covers
every tool-scoped path shape
file_types/detection.rsrecognizes: thefilename-based entries (
SKILL.md, theCLAUDE.md/AGENTS.mdvariants,GEMINI.md,plugin.json,mcp.json,*.mcp.json,mcp-*.json,opencode.json{,c},gemini-extension.json, the.cursorrules,.clinerules,.roorules/.roomodes/.rooignore, and.windsurfruleslegacy files) match at any depth via a shared
(?:.*/)?prefix, and the.claude,.github,.cursor,.codex,.gemini,.amp,.agents,.roo,.windsurf, and.kirodirectory surfaces are enumerated -including
.cursor/rules/**/*.mdso CUR-020 can flag plain-markdown rulesCursor silently ignores. Also covers plugin
hooks/hooks.jsonat any root, bareagents/directories (which detectionvalidates as agent configs,
agents/README.mdincluded),.kiro/settings.json,and the undotted
codex/requirements.tomlsystem surface - while deliberatelynot matching
.codex/requirements.toml, which Codex does not read. Verifiedagainst the 149 concrete paths in
detection.rs's own tests; the onlyremaining exclusions are deliberate: detection's loose fallback arms outside a
tool directory (a bare
settings.json,hooks.json,environment.json,POWER.md, orrequirements.tomlanywhere), uppercase directory spellings,and generic markdown. Verified end to end: a repo with a nested skill, a
package-level AGENTS.md, GEMINI.md, and a scoped instruction file - all
invisible to the old pattern - now produces their diagnostics through the
hook.
v0.52.0Compare Source
Changed
(#1439). The three hooks in
.pre-commit-hooks.yamlmove fromlanguage: systemtolanguage: python,so
pre-commitandprekcreate a virtualenv and pull theagnixwheel thatmatches the pinned
revinstead of requiring a manualcargo installonPATH. This is what the new PyPI distribution makes possible. A root
pyproject.tomlexists solely for that install: pre-commit clones the repoand
pip install .s it, so the clone has to be pip-installable, and this shimdeclares the matching
agnix==<version>as its only dependency.scripts/sync-versions.shmoves the shim's version and its pin together, so ahook pinned at
rev: vX.Y.Zalways runs agnix X.Y.Z. Platforms without awheel can still pin
language: systemin their own config, which theconfiguration guide now documents.
Added
feedbackDraftssetting(#1435). Claude Code v2.1.247
added the
SendFeedbacktool and thefeedbackDraftssetting that governs it.The setting is a string enum -
notify,quiet, oroff- so the naturalguess of a boolean silently leaves the default
notifyin place. Flags anyvalue outside the documented enum.
spinnerTipsOverrideshape(#1435). v2.1.247 extended the
key with tip objects (
id,text,cooldownSessions,priority),tipsFile,and
label. Claude Code drops an invalid tip with a debug warning instead ofrejecting the file, so a malformed tip is simply never shown. Validates the
object's fields, each tip entry, the documented
id/textlimits, the0-1000and-10-10numeric ranges, the 40-characterlabelcap, andthat
tipsFileis absolute or~/-rooted.nameas a kebab-case identifier with no spaces, and v2.1.247 hardenedmarketplace handling to reject names containing control or invisible
characters. Those fail kebab-case by construction, so this catches them before
a plugin reaches a marketplace.
Fixed
SendFeedbackandListAgentsreported as unknown tools(#1435).
KNOWN_AGENT_TOOLShad not been refreshed since 2026-07-31, so CC-AG-009/010 flagged two
documented built-in tools -
ListAgentsfrom Claude Code v2.1.224 andSendFeedbackfrom v2.1.238 - as invalid names in an agent'stoolsordisallowedToolslist. Diffed the whole list against the live tools reference,and these were the only two missing.
Changed
#1435,
#1436,
#1437). Claude Code
v2.1.246tov2.1.247, Clinev4.1.15tov4.1.16, and Codex CLIrust-v0.149.1torust-v0.150.0. Cline's release moves hook workspaceresolution from shared global state to the VS Code window, which changes
runtime behaviour rather than any validated file contract. Codex adds an
Interrupthook event; CDX-PL-013 validates hook shape without an event-nameallowlist, so nothing false-positives, and the missing allowlist is recorded in
RESEARCH-TRACKING along with the uncovered
spinnerVerbssetting.Fixed
which the watcher degrades silently to "post the raw changelog": the
GLM_API_KEYsecret had expired, andscripts/glm-extract.jsran with anoutput budget too small for a thinking model. Reasoning tokens are drawn from
the same
max_tokensbudget as the answer, so at 4096 the model intermittentlyspent the entire budget reasoning and returned
finish_reason: "length"withempty
content(reproduced at 1 failure in 3 runs, 4095 of 4096 tokens onreasoning).
MAX_TOKENSis now 32768, roughly six times the 1.9k-5.2kreasoning observed on real triage prompts, and thinking stays enabled because
it measurably improves the "does this touch a validated config surface?"
judgement. The default model is now named
glm-5.3explicitly rather thanrelying on the endpoint's
glm-5alias, so an alias move cannot change triagebehaviour silently. The empty-content error now also reports
finish_reason,reasoning size, and usage instead of just "empty content", and
scripts/glm-extract.test.js- which no workflow ran - is now part of CI.v0.51.0Compare Source
Added
pip install agnixanduvx agnix .now work. Thewheels in
pypi/bundle the release binary for each supported target(manylinux and musllinux x86_64, manylinux aarch64, macOS Apple silicon,
Windows x86_64), so there is no Rust toolchain to install and nothing is
downloaded after install.
python -m agnixand a small Python API(
agnix.run,agnix.lint,agnix.version) mirror the Node wrapper.pypi/build_wheels.pyrepacks the archives the release already built andverified against their
.sha256sidecars, deriving each manylinux tag fromthe binary's own glibc symbol references rather than a hardcoded floor.
(#1346). IntelliJ on Windows
can now run
agnix-lspfrom inside a WSL distribution for projects that livein WSL, without Remote Development. The plugin launches an argument-safe
wsl.exe --distribution <name> --exec <path>command, maps document andworkspace URIs at the LSP boundary, validates configuration, and skips the
host-local binary installer. Native launches remain unchanged.
Changed
#1426,
#1427,
#1428,
#1429). Advanced Claude Code
from
v2.1.245tov2.1.246, Cursor from3.17.19to3.17.21, and amp fromfriendly-urls-for-sharing-orbstosetup-without-a-commit, and re-baselinedthe eight drifted spec sources (Claude Code hooks/skills/plugins-reference;
Cursor rules/hooks/subagents/mcp and the environment schema). Reviewing all
eight against the rules they back found no contract change that agnix asserts
incorrectly: Claude Code's 31 known hook events still cover every event the
hooks reference documents, the skill frontmatter allowlist still covers all 20
documented fields, the plugin path-bearing keys remain a superset of the
documented table, Cursor's hook events (including the still-supported
beforeShellExecution/beforeMCPExecution) and per-script options areunchanged, subagent frontmatter and model-parameter syntax still validate, the
environment schema's property set still matches
ALLOWED_ROOT_FIELDS, andneither MCP nor hook entries reject unknown fields, so newly documented keys
cannot produce false positives. Coverage gaps the review surfaced (upstream's
new wildcard-permission warning, unvalidated
keybindings.json, Cursor'snow-required MCP
typeand STDIO-onlyenvFile) are recorded inRESEARCH-TRACKING. amp's release stores pre-clone and pre-setup scripts in
server-side project settings rather than any validated file. Cline
(
v4.1.16) and Codex (rust-v0.150.0) published after those issues wereopened and are deliberately left at their previous baselines so the watcher
files their own triage issues.
v2.1.243tov2.1.245and OpenCode fromv1.18.22tov1.18.23after reviewing theirlive release notes. Claude Code's change is a Linux glibc 2.44 startup-crash
fix; OpenCode's changes fix Cloudflare AI Gateway routing, Anthropic model
slugs, parent-session headers, and immutable-OIDC GitHub auth. None changes
an agnix-validated configuration contract. Advanced Gemini CLI from
v0.56.0to
v0.57.0; its changes affect OAuth redirects, IDE and Git worktree state,runtime retry and cancellation behavior, agent enablement, and command help,
without changing an agnix-validated configuration contract.
Fixed
npm/README.mdadvertised405 rules against a canonical 451, and no automation covered it, so the number
had drifted for several releases and was copied into the new PyPI README.
Corrected, and both wrapper READMEs are now in
sync-rule-bookkeeping.js'sCOUNT_FILESso CI fails on the next drift.v0.50.0Compare Source
Added
CC-SET-025for theuser-or-managed
modelPickerscope and documented option shape,CC-SET-026for thepromptCacheTtlenum, andCC-SET-027for thesubagentPromptCacheTtlenum.Changed
v2.1.243, Codex CLI torust-v0.149.1, Cursor to3.17.19, and OpenCode tov1.18.22. AcceptCodex's new
compaction_image_budgetfeature flag; the remaining releasechanges outside the three Claude settings above do not alter a validated
configuration contract.
v4.1.15and Amp tofriendly-urls-for-sharing-orbsafter reviewing the intervening live releasenotes. The changes affect runtime MCP approval behavior, model metadata,
telemetry, and shared-orb URLs, not an agnix-validated configuration contract.
v2.1.241, Cline tov4.1.13, OpenCode tov1.18.21, and Amp toexplain-usageafter reviewingthe live releases against agnix's validated configuration surfaces. Refresh
all CodeQL action pins to
v4.37.7; these pins move together to avoid theaction's mixed-version configuration failure.
plugins, skills, and subagent documentation hashes. The current documented
hook lifecycle and configuration surfaces are already represented by the
existing schemas and rule families, so no validator rule changes are needed.
CUR-016for the publisheddisableAllMcpServersandmcpServerAllowlistfields, including HTTP andstdio server identities, optional tool allowlists, and closed-field checks.
v2.1.238, Codex CLI torust-v0.149.0, Cursor to3.17.8, Kiro CLI to2.19.0, Gemini CLI tov0.56.0, OpenCode tov1.18.19, and Amp tomcp-in-orbs. Apart from theCursor schema change above, the reviewed releases do not change an
agnix-validated configuration contract.
Fixed
format!callthat is now rejected by
clippy::useless_format.elicitation_url_dialogmatcher instead of reporting it as invalid, andadvance the reviewed Claude Code hooks, memory, plugins, skills, and
subagent specification baselines.
hashes with the sentinel's trailing-newline normalization so those sources
do not immediately re-report drift.
h2from 0.4.13 to 0.4.16 to addressRUSTSEC-2026-0258 (unbounded empty DATA frames).
Changed
v2.1.232tov2.1.235, Cline fromv4.1.9tov4.1.10, and Amp's release marker fromglobal-plugins-and-skillstoedu-discount. These releases do not changean agnix-validated configuration surface, so no validator or rule update is
required.
v0.49.0Compare Source
Added
sandbox.ripgrep(#1358). Claude Code
v2.1.232 honors the sandbox ripgrep binary only from user settings, managed
settings, and the
--settingsflag, so a value in a repository's.claude/settings.jsonor.claude/settings.local.jsonis silently ignored.agnix now warns on that dead override and points at the scopes that still
apply. User and managed settings are unaffected.
Changed
tracked releases for Kiro CLI (
2.17.0to2.18.0), OpenCode (v1.18.17tov1.18.18), Claude Code (v2.1.229tov2.1.232), Cline (v4.1.8tov4.1.9), and Cursor (3.15.19to3.16.17). Only the Claude Code and KiroCLI releases touched a validated surface; the OpenCode, Cline, and Cursor
deltas were bookkeeping only.
AGENTS.mdsteering (#1356). Kiro CLI 2.18.0loads nested
AGENTS.mdfiles as steering context from anywhere in theworkspace tree, so the tool inventory and release baseline now list
AGENTS.mdand theagents_mdvalidator (AGM rules) for Kiro. No validationbehaviour change - agnix already validated those files.
v0.48.1Compare Source
Changed
Claude Code (
v2.1.226tov2.1.229), OpenCode (v1.18.15tov1.18.17),Kiro CLI (
2.16.0to2.17.0), Cline (v4.1.6tov4.1.8), Cursor(
3.15.6to3.15.19), Gemini CLI (v0.54.4tov0.55.1), and amp (newsmarker
size-the-orbs-of-productiontoglobal-plugins-and-skills), plus thecursor-environmentspec hash. Registered theoutput_style,gemini_agent,and per-client skill validators in the tool inventory and filled in the
matching config surfaces and rule prefixes (
CC-OS,MCP,OC-SK,CR-SK,GM-AG) inknowledge-base/RESEARCH-TRACKING.md. Watcher bookkeeping only -no validation behaviour changes.
Fixed
by top-level
excludeor[files].excludewhen calculating the 8 MB skilldirectory total, while continuing to validate the rest of the skill.
line (#1368). The
workspace root came from the parent of the first path, so a file in a
subdirectory listed first became the root and
CLAUDE.md's root-relative@importswere reported as escaping the project. Since pre-commit passesmatched files in sorted order,
.claude/...sorted ahead ofCLAUDE.mdandthe same tree passed or failed depending on argument order. The root is now
the deepest common ancestor of every path, walked up to the nearest
.gitor.agnix.tomlmarker, so results no longer depend on argument order or onwhich files a commit happens to touch.
(#1371). The x86_64 gnu
build ran natively on
ubuntu-latest, so it linked the runner's glibc andfailed at load time with
version 'GLIBC_2.39' not foundon Debian bookworm,RHEL/Rocky 9, and Ubuntu 22.04. Both gnu targets now build through
crossagainst an old sysroot (currently
GLIBC_2.18), a release gate fails thebuild if any binary needs newer than
GLIBC_2.31, andnpm install -g agnixplus
scripts/download.shprobe the downloaded binary and retry with thestatic musl archive when the host cannot load it.
Security
GHSA-5p4m-2wfm-xmqj (quadratic
!!omapcomplexity) and nanoidGHSA-2v37-7h3g-55p8 (zero-size generator loop). Lockfile-only; no manifest
range changes.
v0.48.0Compare Source
Fixed
explicit
nameordescription, validate the documenteddisallowed-toolsfield with the existing Claude tool vocabulary, and parse prompt-hook
continueOnBlockas a boolean.plugins, skills, and subagent documentation hashes after auditing the current
validation contracts.
v0.47.0Compare Source
Added
crossSessionInboundanddialogExpiryenums. Rule count 445 -> 447.Changed
v2.1.226, Codex CLI torust-v0.147.0, OpenCode tov1.18.15, Cline tov4.1.6, Cursor to3.15.6, Gemini CLI tov0.54.4, and Amp's release marker tosize-the-orbs-of-productionafter reviewing their current validated surfaces.rmcpto3.1.2,ignoreto0.4.33, andsimilarto3.1.2.actions/setup-nodeto7.0.0,github/codeql-actionto4.37.6,softprops/action-gh-releaseto3.0.2, andactions/attestto4.2.2, keeping synchronized action families and SHA assertions in lockstep.Fixed
decodeandmaskClaims, AWS credential pairs, and SigV4 policies.v0.46.0Compare Source
Added
remoteControlAtStartup: truein project settings; agnix now warns on the ignored value while allowing project-levelfalseand managed settings. Rule count 444 -> 445.Changed
v2.1.222, OpenCode tov1.18.13, Cline tov4.1.4, Cursor to3.14.27, the Agent Skills specification to217be548739f, and Amp's release marker toattach-anythingafter reviewing their current release notes and validated configuration surfaces (closes #1311, #1312, #1313, #1316, #1317, #1318, and #1319).Fixed
allowPlaintextInject; accept mask-only fields that Claude Code ignores ondenyentries; accept the newly documentedskills: "."plugin-root path under CC-PL-007.metadataand metadata entries with non-string keys or values, matching the clarified Agent Skills specification instead of silently coercing YAML scalars.Security
v0.45.0Compare Source
Added
.cursor/rules/must use.mdc; plain.mdfiles are ignored. agnix reports the silent failure and suggests renaming the file. Rule count 443 -> 444.Fixed
composer-2.5[]andclaude-opus-5[effort=high]; validate prompt hooks as non-empty strings; accept comments and enforce the full publishedenvironment.jsonschema; and infer HTTP transport for documented URL-only servers in.cursor/mcp.json, including MCP-017 HTTPS enforcement for remote endpoints (closes #1306).2026-07-28, compare newly detected MCP releases directly, and add Cursor MCP documentation to drift coverage (closes #1305).Changed
3.14.7, Gemini CLI tov0.53.1, and Kiro CLI to2.16.0after reviewing their validated configuration surfaces. Gemini's patch is error-reporting only; Kiro adds/tangentand context display without changing persisted config (closes #1307, #1308).v0.44.0Compare Source
Added
project_doc_max_bytescap is cumulative across the instruction chain, not per-file - it "stops adding files once the combined size reaches the limit". XP-007 checks eachAGENTS.mdin isolation, so a project split across several mid-size files was truncated with no diagnostic at all. The new project-level rule builds the chain the way Codex discovers it (root down, at most one file per directory,AGENTS.override.mdbeforeAGENTS.md), sums root-first, and reports on the file where the running total crosses the limit - that file and everything deeper is what Codex drops. Rule count 442 -> 443 (closes #1289).argson command hooks. The exec-form field - "When present,commandis resolved as an executable and spawned directly withargsas the argument vector, with no shell involved" - was absent from the schema, so it was silently ignored and two rules could not tell exec form from shell form.Removed
context: forkhad noagentfield and shipped an unsafe autofix insertingagent: general-purpose. The skills reference states "Theagentfield specifies which subagent configuration to use... If omitted, usesgeneral-purpose", so the rule demanded that users restate a default the tool already applies. Rule count 443 -> 442.Setuphook event was deprecated in favor ofSessionStartand shipped an unsafe autofix that rewrote the event key.Setupis not deprecated: it is documented as a current event that fires on--init-onlyand on--init/--maintenancein-pmode, with its own matcher set (init,maintenance), exit-code row, and decision-control entry.SessionStartfires on every session begin/resume, so applying the "fix" silently changed when a hook ran. The rule cited no upstream deprecation notice when it was added. Rule count 444 -> 443. Follows the origin-less-rule removal precedent from PR #979.Fixed
excludeAgentvalue and autofixed it wrong. The valid values arecode-reviewandcloud-agent; agnix listedcoding-agent, which was never upstream - so the doc's own value errored, and the unsafe autofix rewrote a correct value into the invalid one.coding-agentis retained as a deprecated alias so configs written against agnix's previous wrong advice keep validating, reported at info level rather than accepted silently, and kept out of the autofix candidate list so the fixer can never write it. Fixed across the validator, all 12 locale files, bothrules.jsoncopies, and the knowledge-base docs.applyTo. "You can specify multiple patterns by separating them with commas", withapplyTo: "**/*.ts,**/*.tsx"as the doc's own example. The whole string went toglob::Pattern, so every such config errored. A correct brace/bracket-aware splitter already existed with 18 passing tests but was marked#[allow(dead_code)] // reserved for future useand never called.globs. Same class as COP-003, same upstream wording ("Separate multiple patterns with commas"). This one was intermittently wrong, which is why it survived: the doc's literal exampledocs/**/*.md, docs/**/*.mdxhappens to parse as one pattern, whilesrc/**, tests/**does not.versionin.cursor/hooks.json. It is documented with a default of1and several of the doc's own examples omit it. Now optional, and type-checked as a number (not an integer) only when present.commandon prompt hooks. "Prompt hooks use an LLM to evaluate a natural language condition" and carrypromptinstead - the doc's example has onlytype,prompt,timeout. CUR-018 already checkedpromptfor those.installin.cursor/environment.json. The published schema has norequiredarray at all (definitions.common) andrequired: [](definitions.container), and the setup page's own snapshot example omitsinstall. Terminal entries now require onlycommand(name/descriptionare optional per bothoneOfbranches, and the array branch is accepted), andupdate- absent from the schema, which setsunevaluatedProperties: false- is reported as renamed toinstallrather than accepted as valid.timeoutsuggestions said milliseconds. The option is "Execution timeout in seconds"..mdcfiles.ClaudeMdValidatoris registered forFileType::CursorRulefor its generic prose checks, so a.cursor/rules/*.mdcfile was reported asCLAUDE.md has N non-empty lines, exceeding the recommended 200 line limit- wrong filename, wrong threshold (Cursor documents 500), wrong tool attribution. Now scoped to Claude memory files.docs.github.com/en/copilot/customizing-copilot301-redirects anddocs.cline.bot/features/cline-rules/overview308-redirects; both are updated inrules.jsonand.github/spec-baselines.json, so those two sentinel sources can match again.AGENTS.override.mdwas not recognized as an instruction file. Codex checks it beforeAGENTS.mdin each directory, butis_instruction_file()did not list it, so it was invisible to every cross-platform rule. This also made theAGENTS.override.mdhandling added to XP-007 in the previous release unreachable in practice.!`occurrences, so inertKEY=!`cmd`forms inflated the count (the doc: a!following another character "is left as literal text and the command does not run"), while```!fenced blocks - where every line is a command - counted as zero. Counting now honors both documented forms and ignores plain fences.$ARGUMENTS. The substitution table documents four forms; a body using the$Nshorthand or a$namedeclared inargumentswas reported as ignoring its own arguments, and$0escaped CC-SK-016 entirely. Theargumentsfrontmatter field is now parsed so named placeholders can be resolved. The shorthand is matched as a single digit, matching the documented examples, so${CLAUDE_SKILL_DIR},x$3y, and prose amounts like$500are not mistaken for positional arguments.${user_config.*}is rejected only in shell form: "Plugin hooks additionally substitute${user_config.*}values, in exec form only". The rule fired regardless ofargs, so{"command": "${user_config.formatter}", "args": ["--fix"]}errored.args. In exec form the script sits inargswhilecommandnames an interpreter, so exec-form hooks - the form the doc recommends for path placeholders - got no script-existence checking at all.references/paths. The spec scopes skill resources to "scripts/,references/, orassets/" and usesscripts/extract.pyin its own example, so deepscripts/andassets/paths were invisible. Git ref paths stay excluded.namefrom the directory ("namesets only the display label... the command still comes from the directory or file name"), and a plugin skill'snamedeliberately replaces the last command segment - the reference's ownname: fancyinskills/review/example errored. Scoped out for Claude Code skills, following the AS-008 precedent; the agentskills.io baseline still requires the match.commands/,agents/,skills/,workflows/,output-styles/,themes/,monitors/, andhooks/as forbidden inside.claude-plugin/.workflows,mcpServers,outputStyles,lspServers,experimental.themes, andexperimental.monitorsaccepted absolute paths,..traversal, and.claude-plugin/targets unchecked. Dottedexperimental.*keys are now traversed, which a plain field lookup could not do.AGENTS.override.md. Codex reads it first in each directory, so it draws on the sameproject_doc_max_bytesbudget; the code comment claiming Codex "reads this file, not local/override variants" was contradicted by the current guide. The cap is cumulative across the root-to-cwd chain while this check remains per-file - noted in the rule docs as a known gap.2026-07-28is now the current MCP revision and the unversioned/specificationURL serves it, but agnix compared against a single pinned default of2025-11-25. With no revision pinned, both are now accepted: the two are behaviorally incompatible rather than sequential (2026-07-28 drops theinitialize/initializedhandshake andMcp-Session-Idsessions), so a config written for either is legitimately current and demanding one would only move the false positive onto the other. Pinning[spec_revisions] mcp_protocolstill enforces exactly one revision and keeps the autofix; the unpinned diagnostic now names every accepted revision instead of claiming a single one is required. A revision outside the current set is still reported.sonnet, opus, haiku, inherit, or claude-*after the accepted list had been widened.codex-cli-agents-mdsource URL was dead.https://developers.openai.com/codex/guides/agents-md/308-redirects tohttps://learn.chatgpt.com/docs/agent-configuration/agents-md- the doc moved host and site, so the Spec Drift Sentinel baseline for that source could never match again. Updated inspec-baselines.json, in all 20 affectedevidence.source_urlsentries, and across the knowledge-base docs.tools: Agent(worker, researcher), Read, Bash(npm run test:*)- the sub-agents reference's own verbatim example - reportedUnknown tool 'researcher)','run', and'test:*)'under CC-AG-009/010, because the string deserializer split on commas and spaces before parentheses were stripped. The skill validator already had a paren-aware tokenizer; it is now shared asvalidation::split_tool_listsoallowed-tools,tools, anddisallowedToolscannot drift apart again.autoandmanual, and accepted the undocumenteddelegate. The permission-modes reference documents six modes (default,acceptEdits,plan,auto,dontAsk,bypassPermissions) plusmanualas a CLI alias fordefault(v2.1.200+).delegateappears in neither that reference nor sub-agents and was added without a cited source, so it is no longer accepted.model"Accepts the same values as the--modelflag", sodefault,best,fable,opusplan,sonnet[1m], andopus[1m]are all valid and were all erroring. The alias list is now shared between the agent and skill validators rather than duplicated.tasksis in the 2025-11-25 capability-negotiation table - the revision agnix already pins - andextensionswas added in 2026-07-28. Note the spec calls capabilities an open set ("any server can define its own, additional capabilities"), so this rule is advisory.@~/.claude/my-project-instructions.mdas the way to share personal instructions across git worktrees; Claude Code gates external imports behind a one-time approval dialog rather than rejecting them. Existence is still checked, and the path-shape guard is retained for non-memory files under REF-001, where no spec sanctions escaping the project root.depth + 1 > MAX, so the diagnostic first fired at six..claude/rules/was only validated one level deep. The doc says "All.mdfiles are discovered recursively, so you can organize rules into subdirectories likefrontend/orbackend/", but both the file-type detector and the validator requiredrules/to be the immediate parent. Nested rule files got no validation at all - CC-MEM-011/012 never ran on them.forkSessionStart matcher.forkcovers--fork-sessionwith--resume/--continue, the/forkbackground copy, and/branch. It was missing from the known-value list, so a valid hook config was flagged. (resumestays valid: before Claude Code v2.1.214 a forked session reportedresume.)skillsadds to the default (the defaultskills/directory is always scanned), whilehooks/mcpServers/lspServershave their own merge rules. Neither can shadow, so bothskillsandhooksproduced false warnings on plugins that kept their default folder. The rule now checks only the six documented replace-semantics fields, which also closes a coverage gap:workflows,outputStyles,experimental.themes, andexperimental.monitorswere never checked. Folder names that differ from their manifest key are handled (outputStyles->output-styles/,experimental.*-> root-levelthemes/,monitors/)..github/spec-baselines.jsonmappedclaude-code-subagentstoCC-SA-001..007,github-copilottoGH-001..004, andcline-rulestoCLINE-001..003- none of which were ever in this repo; the real rules areCC-AG-*,COP-*/CP-SK-*, andCLN-*/CL-SK-*. It also still listedAS-014, removed in PR #979. Every drift issue rendered these straight into the "rules may need review" list, sending the reader to rules they could not look up. Mappings are now derived from each rule's own evidence URLs, and a newtest_spec_baseline_rule_ids_existparity test fails CI if an unknown ID is ever added.v0.43.0Compare Source
Changed
validation::is_valid_mcp_tool_formataccepts the server-only MCP form. The function is in the Public/Unstable tier and its signature is unchanged, but it now returnstrueformcp__<server>where it previously returnedfalse, so a downstream caller relying on the stricter behavior will see a change. Whitespace in the server segment is newly rejected.Fixed
[[overrides]]had no effect on any skill rule. Reported as Windows-specific path matching, but the platform was incidental:SkillValidator's internalValidationContextstored the&LintConfigthatPerFileLintConfigderefs to, so the per-file override layer was discarded before anyis_rule_enabledcall. Every AS-* and CC-SK-* rule ignored[[overrides]]on all platforms, with no way to suppress one for a single file. The context now holds the per-file view, and an end-to-end regression test covers the case (closes #1277).mcp__playwrighterrored while the doc-equivalentmcp__playwright__*passed, even though the permissions reference lists both as valid ways to name every tool from one server. Both forms are now accepted. A glob in the server segment (mcp__supabase-*,mcp__*) is still rejected, since a rule must name a specific configured server, and the tool segment may still glob (mcp__github__get_*).Workflow,Artifact,ReportFindings,SendUserFile, andEndConversationare in the built-in tools reference but were missing from CC-SK-008's known-tools list. CC-AG-009/010's list was further behind - 26 documented tools absent, including theCron*/Task*families,PowerShell,LSP,ToolSearch, and the worktree and MCP-resource tools - so a subagent declaring any of them failed. Tools that subagents never receive stay listed: Claude Code filters those from the resolved pool rather than rejecting the name.v0.42.0Compare Source
Added
referencekey as@deprecated Use 'references' field instead; the new rule warns and offers a safe autofix rename. Rule count increased from 443 to 444.Fixed
SKILL.mdhighlighting. RegisterSKILL.mdwith the bundled Markdown language and declare the Markdown plugin dependency, restoring syntax highlighting and Markdown editor features in supported JetBrains IDEs.shell_environment_policy.filters, validate itsinclude/excludeactions and legacy-list conflicts, recognize the four new feature flags, validate structuredfeatures.non_prefixed_mcp_tool_names, and refresh the managedrequirements.tomlallowlist without the removedallowed_permissionskey.plugin.jsonmanifests, validate required metadata types, inspect Codexapps,hooks, andinterfacefields underextensions.com.openai, accept all supported hooks forms, stop after unsupported schemas, and avoid Claude plugin location false positives.environmentmaps as string-to-string objects and reject the unsupportedenvspelling that OpenCode ignores.workspaceOpenhooks. Recognize the documented hook event without a CUR-011 unknown-event warning.scripts/check-rule-counts.pyenforced the rule total in 13 locations thatscripts/sync-rule-bookkeeping.jsnever wrote — the six editor/website docs, the per-category tables inknowledge-base/INDEX.mdandknowledge-base/VALIDATION-RULES.md, and theSPEC.mdtable — so every rule addition failed the "RuleConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.