- /changes diffs the last turn's file snapshot (added/modified/deleted), reusing undo infra via SnapshotStack.peek() - system prompt memoized behind version counters (notebook/memory/skills/plugins/tools/workspace); hit-rate in /cost, foundation for provider caching - web_search: DuckDuckGo Lite, keyless, 5 results, SSRF-filtered, in the net set with ask permission - /search <query>: full-text grep over saved sessions incl. tool-input JSON - workspace file list re-walks at a turn boundary after writes - maxSpendPerTurn: per-turn cap stops a runaway step with a notice - /fork: branch the session at the last turn boundary, original untouched 821 tests pass, typecheck clean, build green
6.4 KiB
6.4 KiB
TODO
Next up. One item, one outcome, verifiable when done.
Longer-term direction lives in ROADMAP.md.
Now
Empty — pick from Known rough edges below.
Next
Empty.
Maintenance
All caught up.
Known rough edges
Not bugs exactly, but things that will bite someone.
/clearwipes the terminal scrollback.<Static>output is already committed, so clearing React state alone leaves it on screen. The escape sequence works but takes the user's earlier terminal history with it.- Memory has no conflict resolution. Two contradictory notes both persist and both get
injected.
/memorymay merge them, or may keep both. - Windows
cmd /cdiffers frombash -lc. A command the model writes for one shell may fail on the other. The prompt states the platform; it does not translate. - Permission rules gate the call, not what it does.
bashwithgit *allowed will run agitalias that shells out to anything, and there is no sandbox around the shell. Codex solves this with OS-level isolation — Seatbelt, Landlock, a Windows equivalent — which is three platform-specific implementations and not something to half-ship. - The reasoning panel is per-turn, not per-step. Reasoning from an early step stays on screen through later ones until the turn ends.
- An interrupted command's effects are unknown, and the model is told so. Nothing can know how far a half-run migration got.
- An installed skill is a stranger's words in your system prompt. The install shows the
body first and
/skillsrecords the origin, but nothing re-checks it later: a registry that changes a URL's contents affects the next install, not one already on disk. - A registry index is trusted for its contents, not its authorship. There are no
signatures.
registryUrlis the whole trust decision.
Done
Kept for one release, then deleted.
1.0.0 release batch
- A spend ceiling (
maxSpendUsd): checked before each turn, refused at 100% naming the ceiling, warns once at 80%, headless exits non-zero. Unpriced models are not enforced - A cheaper subagent model (
subagentModel):exploreresolves against it,reviewandworkerkeep the parent's,/costsplits subagent spend by model id - Twenty new built-in tools (41 total) in a new
extraset: line edits, filesystem navigation, read-only git extensions, and code/environment reads - Twenty new bundled skills (29 total) plus the eleven originals deepened; all moved to
src/skills-md/*.mdas the Markdown source of truth, embedded at build - Ten new data-only plugins: safety refusals on by default (force push, pipe-to-shell, root, env credential writes) and opt-in workflow plugins (conventional commit, tests-first, small diffs, main-branch commits, git config, confirm-delete)
- Custom slash commands from Markdown files, with
$ARGUMENTS/$1and guarded shell substitution; a custom command never shadows a built-in - Auto-loaded external skills, tools, and plugins from
~/.shiro-neko/<kind>and.shiro/<kind>, all data, never code; a bad file is reported and skipped - The welcome interface redesigned into a structured dashboard with a session banner, a grouped environment panel, and a meta bar; the input in a two-tone box with a split footer
- The system prompt advanced: a failure-recovery loop, a delegation policy, compaction awareness
- The release workflow's dead
dry_runinput wired: manual dispatch publishes only when unchecked, tag pushes always publish
Post-1.0 — Now / Next / Maintenance (landed)
- Summarize the pruned span —
prune.droppedSpan+session.summarizeDiscarded, injected asNote (retained from compacted history), budgeted 6k excerpt + 3–6 lines, one call per compaction (test/compact.test.ts) - Hot-reload an installed entry —
Session.updateSkills/updatePlugins+cli.tsxhot-reload,pendingSkills/pendingHost+drainPendingHotReloadat turn boundary (test/hot-reload.test.ts) - MCP without the schema tax —
mcp_list/mcp_inspect/mcp_callphi meta-tools, prompt names-only, permissionmcp_call+bindMcpGuard,mcpExpose=phi|direct|auto(test/mcp.test.ts) - Derive the tool-name lists —
withMeta({ set, mutating }),setsFrom(tools)derivesTOOL_SETS/MUTATING_TOOLS/DEFAULT_PERMISSIONS(test/tool-derive.test.ts) - Subagent parallelism —
taskfans outtasks: TaskSpec[]viaPromise.allup to 8 (test/subagent-parallel.test.ts) - Undo a turn —
src/snapshot.tsper-turn capture cap 100,/undo+/redofiles+messages (test/undo.test.ts) - Pricing source + date —
PRICING_VERIFIED_AT='2026-09-09'+ source URLs,/costshowspricing verified: 2026-09-09 (est.) estimateTokenslabelling — heuristic doc +(est.)in/cost+~N est. in contextlistPathsstale walk —fileChangeSeqonrecordBeforeWrite/restoreFiles,@invalidatespathson seq changeMUTATING_TOOLSderivation —BASE_PERMISSIONS+buildDefaults()derives fromMUTATING_TOOLSviarequire('./tools')- Unknown
toolSetssilently dropped —unknownToolSetNames()+ startup noticeunknown toolSets ignored: …(test/config-toolsets.test.ts,5028ea6) @directories —walk({ includeDirs: true })yieldssrc/with trailing/,matchPathsranks dirs before files (test/complete-dirs.test.ts,4b4ddd0)
Session-feature batch (7 features)
/changes— diff the last turn's snapshot: added / modified / deleted, per absolute path, no bash effects (session.lastTurnSummary+snapshot.peek)- System-prompt memoization — version counters on notebook/memory/skills/plugins/tools/workspace, cached per version key, hit-rate in
/cost(foundation for provider prompt caching) web_search— DuckDuckGo Lite, no API key, 5 results with title/URL/snippet, SSRF-filtered throughcheckUrl, in thenetset/search <query>— full-text over saved sessions, matches transcript strings and tool-input JSON- Workspace file list refresh — after a turn that wrote files, re-walk at the boundary so the next prompt shows new paths
- Per-turn spend cap —
maxSpendPerTurn, aborts a step past the line with a notice /fork— clone the session at the last turn boundary to a new saved session; original untouched