Skip to content

Latest commit

 

History

History
631 lines (457 loc) · 68.6 KB

File metadata and controls

631 lines (457 loc) · 68.6 KB

Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

Contributors add user-facing entries under [Unreleased] in the same PR. Maintainers rename that section to a version and date when cutting a PyPI release. See CONTRIBUTING.md.

[Unreleased]

Added

  • Governance / Licensing (SPDX & Copyright Headers): Standardized top-of-file SPDX license identifiers (SPDX-License-Identifier: MIT) and explicit copyright notices (# Copyright (c) 2026 ARPA Hellenic Logical Systems) across all core framework source files (skillware/**/*.py), CLI entry points, and authoring templates (templates/python_skill/) to protect against attribution stripping and ensure enterprise SCA compliance (#416).
  • Tests / CI: Added tests/test_spdx_headers.py asserting that all Python source files under skillware/ and templates/ enforce valid top-of-file SPDX license identifiers and copyright notices (#416).

[0.5.8] - 2026-10-07

Added

  • Governance / Security (The Permissive Fortress): Established repository and supply-chain defense-in-depth under the MIT License — inbound Legal notice and code ownership terms in CONTRIBUTING.md (irrevocable license grant, non-revocability, patent non-assertion, no malicious logic), PR template confirmation checkbox, and strengthened CODE_OF_CONDUCT.md enforcement authority against credential exfiltration and rogue execution.
  • Skill (security/deepfake_guard v0.1.0): Air-gapped forensic verification and document authenticity guard for synthetic media, digital tampering, C2PA provenance, and ICAO 9303 MRZ validation. Features cyclic (7, 3, 1) check digit calculations across TD1, TD2, and TD3 passports and ID cards; ISO 7810 ID-1 geometry verification; high-pass Laplacian noise residual variance analysis; JPEG Error Level Analysis (ELA); 2D FFT moiré screen recapture grid detection; copy-move spatial cloning detection; and C2PA JUMBF / generative AI metadata extraction (#48).
  • Core / Security: Pluggable credential_fn callable support in BaseSkill.__init__ and BaseSkill.credential() for hermetic, sandboxed secret resolution without polluting process-global os.environ.
  • CI / Security: Added .github/workflows/security.yml for automated AST security audits (bandit -lll), dependency vulnerability checks (pip-audit), anti-obfuscation and linting (ruff), and static typing (mypy). Added tests/test_security_audit.py enforcing zero dynamic execution primitives (eval, exec, compile) and prohibiting raw os.environ secret reads in skills/.
  • Skill (office/web_form_mapper v0.1.0): Universal web form mapper and submitter skill for automated web form discovery, address book legal_profile integration, non-mutating preview diffs, and confirmation-gated dispatch with automatic hidden field / anti-CSRF token / ASP.NET __VIEWSTATE preservation and fail-closed anti-bot challenge detection (#45).
  • Core / Async: Native asynchronous skill execution parity (BaseSkill.aexecute, SkillContext.aexecute, SkillContext.acall) with non-blocking default fallback via asyncio.to_thread for all existing skills, bidirectional sync/async bridging, per-call timeout enforcement, and semaphore-backed concurrency throttling via SkillContext(max_concurrency=N) (#18).
  • Orchestration / Chains: Asynchronous skill chain runner (skillware.chains.arun_chain) supporting deterministic step execution, conditional when: skipping, parameter mappings, short-circuit error handling, and chain-level timeouts without blocking the host event loop (#18).
  • Examples / Docs: Added examples/async_tool_loop.py demonstrating concurrent async fan-outs with asyncio.gather, concurrency limits, and async chain execution; updated docs/usage/agent_loops.md and docs/usage/skill_chaining.md (#18).
  • CLI / Tests: Guard open_path_in_os in skillware.cli_os and mock target in tests/test_cli.py to prevent automated test runs from launching external OS file managers or application windows on the host desktop.

Changed

  • Skill (compliance/mica_module v0.1.2): Statutory knowledge notice — catalog callout, directive and constitution framing, statutory_snapshot on execute output and card UI; documents offline snapshot cutoff (Regulation (EU) 2023/1114) as informational reference, not formal legal counsel (#397).
  • Docs / templates: CONTRIBUTING and templates/python_skill/README.md document the statutory notice pattern for future regulatory skills (#397).
  • Docs: TESTING.md — Clone dev setup subsection (dedicated venv, editable vs PyPI wheel, import sanity check, recovery via doctor --install and dev install scripts); cross-links from CONTRIBUTING.md and ai_native_workflow.md (#232).
  • Templates: Modernize templates/python_skill/ starter bundle — dynamically load manifest.yaml in skill.py, demonstrate schema parameter validation (self.validate_params()) and structured error handling, align card.json fields with manifest.yaml outputs, fix test_skill_manifest_consistency failure, verify SkillLoader bundling, and expand README.md with complete skill creation workflow, Do's/Don'ts, and card UI schema fixture requirements.

Fixed

  • Skills: Load co-located manifest.yaml in stub skills (compliance/mica_module, compliance/pii_masker, data_engineering/novelty_extractor, optimization/prompt_rewriter) via shared BaseSkill.load_manifest_from_dir() helper instead of hardcoded metadata dicts (#203).
  • Skill (office/pdf_form_filler v0.1.1): Load the bundle helpers once at import time (relative, package, then importlib under a unique module name, matching defi/evm_reader) instead of appending the skill directory to sys.path on every execute() and importing a top-level utils module, which grew sys.path in long-running hosts and clashed with a host application's own utils module in both directions (#398).

[0.5.7] - 2026-09-29

Added

  • CLI / packaging: Harden version display when editable and PyPI installs overlap — get_package_version_display() never prints None; detect_install_conflicts() via assess_install_health(); startup stderr hint; skillware doctor --install with recovery commands; install summary in skillware config show (#333).
  • Scripts: scripts/dev_install.sh and scripts/dev_install.ps1 — uninstall overlapping installs and reinstall editable dev deps.
  • Core / CLI: EVM operator config layer — bundled skillware/data/evm_defaults.yaml, writable user evm.yaml, skillware.core.evm_config merge helpers (load_merged_evm_config, resolve_chain, resolve_rpc_url, normalize_evm_address), and skillware evm commands (init, chains list, chain add, rpc enable, validate, open). Project/global YAML uses top-level evm: (or read-only web3: alias) — distinct from orchestration chains: (#379).
  • Docs: EVM operator config — shared defi RPC setup guide; cross-links from CLI, API keys, DeFi catalog, evm_tx_handler, and token_security_scanner (#379).
  • Core / CLI: Shared address book public_0x field, relaxed contact validation (email or wallet), top-level skillware addressbook commands (list, edit, set-wallet, remove, open), skillware config open, skillware evm token add, and skillware evm tokens list for operator token registry (#373, #374).
  • Docs: Address book operator config — shared contact identity guide (mail + defi, schema, CLI, cross-links); glossary public_0x / shared address book terms; transfer-by-name usage examples on evm_tx_handler (#373, #374).
  • Examples: gemini_gmail_minimal.py — README quick-start interactive Gemini + Gmail loop; pay_and_notify_demo.py — reproducible SkillContext pay + notify recipe with documented prerequisites.
  • Skill (defi/evm_tx_handler v0.3.0): Central address book recipient resolution with needs_input disambiguation; merges operator EVM chain/token config from skillware.core.evm_config (#373).
  • Docs: Structured hub architecture for catalog discovery — compact root README category table, docs/sitemap.md, and landing pages at docs/skills/<category>/README.md with catalog pages beside them (docs/skills/<category>/<skill_name>.md). Runtime skills/<category>/<skill_name> IDs and SkillLoader.load_skill() are unchanged (#370).
  • Skill (security/prompt_injection_firewall v0.2.0): OWASP LLM01 Layer-1 trust-boundary input defense upgrade — local evasion detection engine (leetspeak deobfuscation, multi-token ROT13 and token-reversal, typoglycemia scrambled keywords, mixed-script homoglyphs, markdown and HTML image exfiltration channels), academic/advisory mention-vs-use false-positive controls, operator policy telemetry (policy_action: allow | flag | block, removed_span_count, sanitized_length_delta), finding enrichments (decode_chain, decoded_preview), and DoS soft resource caps failing closed safely (#273, #361).
  • Skill (defi/token_security_scanner v0.1.0): Read-only GoPlus Token Security scan (scan, supported_chains) with normalized risk_tier / signals JSON for pre-trade agent checks; chain resolution via skillware.core.evm_config (#365, #368).
  • Skill (defi/evm_reader v0.1.0): Read-only EVM state plane (erc20_metadata, erc20_balance, erc20_allowance, erc721_metadata, erc721_balance, erc721_owner_of, call_view, multicall, resolve_holder) without signing or private keys; high-precision decimal formatting, EIP-55 checksum validation, Multicall3 batch queries, central address book resolution with needs_input disambiguation, and shared EVM operator config integration (#367).

Changed

  • Docs: CONTRIBUTING.md — editable vs PyPI on the same Python; CLI docs for doctor --install (#333).
  • Docs: Catalog pages include a standardized intent header (problem solved, host agents, runtime / key requirements) for search matching without stuffing (#370).
  • Docs / CI: Doc-drift guards follow nested catalog paths; CONTRIBUTING, PR/issue templates, and the skill template point at category hubs and the sitemap (#370).
  • Skill (defi/evm_tx_handler): Setup envelope docs URL now points at docs/skills/defi/evm_tx_handler.md (#370).
  • Skill (office/pdf_form_filler): short_description no longer implies a Claude-only mapper (#370).
  • Card UI (security/prompt_injection_firewall): Expose policy_action, removed_span_count, and sanitized_length_delta in card.json and sync sample fixture (#273, #361).
  • Docs: Glossary cross-links on hub and catalog pages (#363).
  • README: Quick-start usage example is Gemini + office/gmail_handler (gemini_gmail_minimal.py) instead of the prompt-injection firewall snippet.

[0.5.6] - 2026-09-20

Added

  • Skill (linguistics/korean_slang v0.1.0): New linguistics/ category and offline Korean Gen-Z slang pack — interpret / suggest / lookup over a September 2026 curated KB, honorific audience gates, and constitution filters for slurs (#34).
  • GitHub: cat: linguistics in .github/labels.json and the New Skill Proposal category dropdown; GitHub UI labels sync on merge to main (#34).
  • Examples: korean_slang_demo.py — offline interpret, suggest, lookup, unmatched, and blocked-term paths (#34).
  • Scripts: korean_slang_stress_sim.py — offline interpret/suggest stress harness (#34).
  • Docs: Glossary and inclusive language — operator / contributor / host agent / end user; skill bundle vs PyPI package; anatomy roles (#252).
  • Core: Pluggable secret providers — SecretProvider, EnvSecretProvider, MappingSecretProvider, CallableSecretProvider, and SkillLoader.resolve_env_vars() inject manifest env_vars into BaseSkill(config=...) without requiring global os.environ mutation (#39).
  • Core: BaseSkill.credential() — config-first credential lookup with os.environ fallback for local .env workflows (#39).
  • Core: SkillContext(secret_provider=...) resolves credentials on each execute() and passes them via config (supports ephemeral tokens from custom providers) (#39).
  • CLI: skillware doctor ENVS column — reports missing required manifest env_vars (#39).
  • Examples: secret_provider_demo.py — host-injected credentials without os.environ (#39).
  • Core: SkillLoader.to_bedrock_tool() for AWS Bedrock Converse tool-use API — maps manifest parameters to toolSpec / inputSchema.json (#262).
  • Docs: Enterprise cloud usage guides — enterprise_cloud.md (hosting + adapter routing), bedrock.md, azure_openai.md, vertex.md (#262).
  • Examples: bedrock_tos_evaluator.py — Bedrock Converse loop with to_bedrock_tool() (#262).
  • Skill (creative/deck_builder v0.2.0): Enterprise presentation platform baseline — procedural Pillow placeholders, image fit policies, layouts (timeline, metrics, comparison), lint_deck quality gates, suggest_outline archetypes, governance ribbons/footers, and deck_builder_chain_demo.py (#336, #337).
  • Examples: deck_builder_chain_demo.py — suggest_outline → bg_remover → lint_deck → render via SkillContext (#337).
  • Skill (optimization/context_optimizer v0.1.0): Query-aware extractive context selection — local fastembed chunk scoring against agent_goal, traceable chunks_selected, fail-closed empty_result, and constitution-bound extractive-only output (#44).
  • Examples: context_optimizer_demo.py, context_optimizer_chain_demo.py (firewall → optimizer), optional context_optimizer_gemini_loop.py, context_optimizer_claude_loop.py (#44).
  • Skill (finance/uk_companies_house_handler v1.3.0): Phase v2c upgrade with deterministic matchers, filing helpers, and pagination controls — pure deterministic officer role matchers (officer_role) supporting 3 canonical categories (directors, secretaries, corporate) and 29 official Companies House statutory roles in terminology_map.yaml without NLU in Python; case-insensitive officer name substring matching (officer_name / officer_filter); multi-page officer scanning up to 10 pages (1,000 records max) in 100-item chunks for filtered queries; deterministic filing history sorting descending by date; filing helpers latest_only: true (single most recent filing) and latest_per_category: true (latest filing per category); direct host agent run_pipeline orchestration with <from_resolve> parameter substitution for multi-intent queries, removing redundant map_intent from manifest actions and agent directives; new decoupled composite action resolve_company_officer (resolve company -> halt on needs_input if ambiguous -> filter matching officer(s) by role and/or name in one turn); active vs. resigned transparency and disclaimers in envelopes (active_only, matched_count, terminology_note); strict context isolation preventing sticky filter contamination across turns (#310, #220).

Changed

  • Docs: Terminology pass on current anatomy (Contract / Effect / Directive / Assurance / Presentation) — Skill bundle standard, calling agent → host agent, trust-model “Most operators”, README domain wording, MiCA example “Available tools”; tests/CI use placeholder names instead of dummy (#252).
  • Docs (context_optimizer): Catalog execute snippets use a tight token budget so copy-paste runs demonstrate selection; card UI fixture aligned to sample policy; optimize_document_context named chain in .skillware.yaml.example (#44).
  • Docs: Revamp skill trust model — trust-forward operator guide aligned with secret providers, SkillContext, doctor/paths tooling, and untrusted-input chains; soften README and usage index credential callouts.
  • Docs: Add host-context guidance for choosing full Directives, brief registry lines, and host-managed progressive loading (#348).
  • Core: SkillContext.tools("bedrock") exposes Bedrock Converse tool specs for multi-skill hosts (#262).
  • Skills: Bundled skills with env_vars now use self.credential() for config-first secret resolution (#39).

Removed

  • Skill (finance/uk_companies_house_handler v1.3.0): Excised redundant map_intent action, internal helper methods (_map_intent, _normalize_keyword, _lookup_terminology), and intent_to_action from terminology_map.yaml in favor of direct host agent run_pipeline step composition (#220).

Fixed

  • Skill (finance/uk_companies_house_handler v1.3.0): Officer name filtering (officer_name) matches all word parts across candidate name, deterministically resolving natural order ("Firstname Lastname") vs UK registry inverted order ("SURNAME, Firstname") (#220).
  • Skill (finance/uk_companies_house_handler v1.3.0): run_pipeline halts <from_resolve> substitution upon encountering subsequent company resolution steps, preventing cross-company parameter corruption in multi-company pipelines; context company_name inheritance guarded against mismatched company numbers (#220).

[0.5.5] - 2026-09-14

Added

  • Tests: Five-provider Usage Examples guard in tests/test_skill_docs.py — every catalog page must expose Gemini, Claude, OpenAI, DeepSeek, and Ollama snippets with load_skill and skill.execute (#104).
  • CLI: skillware theme [pastel|ocean|mono] subcommand — set or interactively choose the global presentation theme; --help topic index now includes Context, Chains, and Theme alongside existing groups (#335).
  • Skill (creative/deck_builder v0.1.0): Deterministic Microsoft PowerPoint (.pptx) presentation assembly from structured JSON deck specifications — 10 slide layout types (title, section, bullets, two-column, image, image with caption, quote, table, chart, blank), 3 bundled 16:9 widescreen master templates (pitch, corporate, minimal), theme token customization, pre-flight validation with soft-limit truncation warnings, directory traversal defenses, and inspection actions (#276).
  • Skill (data_engineering/semantic_web_proxy v0.1.0): Semantic web proxy that reduces a live page or raw HTML to token-efficient Markdown, plain text, or JSON via trafilatura — boilerplate, script, and navigation stripping, opt-in comment threads, document metadata, estimated token savings with optional context-window share, an SSRF guard that re-validates every redirect hop, and a page_likely_requires_javascript warning instead of a silently empty payload for client-rendered pages (#42).
  • Examples: semantic_web_proxy_demo.py — offline fixture-backed demo of boilerplate stripping, comment inclusion, the render warning, and the SSRF guard (#42).
  • Examples: claude_uk_companies_house_handler.py — interactive UK Companies House v1.2.1 Claude loop with multi-turn tool chaining and disambiguation hints (#346).
  • Scripts: uk_companies_house_host_simulation.py — maintainer stress harness for host/Gemini/Claude NLP loops against live Companies House API (not run in CI).

Fixed

  • Core: Sanitize registry IDs in SkillLoader.to_claude_tool() so Claude API tool names match the ^[a-zA-Z0-9_-]{1,128}$ pattern (#104).
  • Examples: Claude demo scripts match SkillLoader.to_claude_tool() names instead of raw manifest IDs (#104).
  • Docs: Align Claude tool-name guidance in agent_loops.md and cli.md with sanitized adapter names (#104).
  • CI: Format tests/test_extras_sync.py with Black after the install-extras guard landed (#340 follow-up).

Changed

  • Skill (finance/uk_companies_house_handler v1.2.1): Stabilization upgrade for multi-turn agent loops — single-step stack pop execution for run_pipeline (steps.pop(0)) preserving turn-level steering and intermediate visibility; in-flight <from_resolve> parameter substitution across remaining steps; decoupled composite actions (resolve_and_get_officers, resolve_and_get_filings) executing directly without wrapping _run_pipeline and skipping profile fetch when company_number is already known; breaking rename of map_intent output suggested_pipeline to steps with parameter merging via action_params; removed hallucinated snippet_type from _resolve_company candidate parsing; strict status: "partial" lifecycle reserved exclusively for in-flight run_pipeline calls with remaining steps (standard 10-item previews return ready); sanitized session context to lean keys (company_number, company_name, last_action, selected_transaction_id) dropping persisted filter hints; excised deprecated next_actions envelope field; directive expanded for empty registry rows and mandatory user-facing replies; agent_hint on empty officers[] / filings[] (#341, #346).
  • Docs (skill catalog): Backfill runnable five-provider agent loops on all catalog pages — including gmail_handler, semantic_web_proxy, and stub Ollama sections — aligned with docs/usage/skill_usage_template.md (#104).
  • Docs (install_extras.md): Backfill deck_builder, gmail_handler, and [all] package rows; add CI guard comparing the install guide to pyproject.toml optional-dependencies.
  • Docs (skill catalog): Skill history sweep — merge SHAs for deck_builder and semantic_web_proxy, #345 rows for Gemini 3.5 bumps (mica_module, tos_evaluator, mental_coach, synthetic_generator, token_limiter).
  • Docs / examples: Default Gemini model IDs migrated from 2.5 Flash / Flash-Lite to gemini-3.5-flash and gemini-3.5-flash-lite across catalog pages, runnable examples, skill defaults, and docs/usage/gemini.md (#265).
  • Docs / examples: Default Claude Haiku snippets migrated to claude-haiku-4-5-20251001 across catalog pages, docs/usage/claude.md, and examples/claude_token_limiter.py; model_pricing.json updated (#346).
  • Docs (uk_companies_house_handler): Rate-limit links, agent-loop host guidance, multi-turn Claude snippet; UK pipeline/composite patterns moved from generic agent_loops.md to the catalog page; generic multi-turn guidance only in agent_loops.md (#346).
  • Examples: Gemini/Claude UK Companies House loops use bundle["class"]() and print needs_input disambiguation hints (#346).
  • Skills (compliance/tos_evaluator, compliance/mica_module, wellness/mental_coach, data_engineering/synthetic_generator v0.1.1): Default Gemini evaluator / generator model IDs updated to 3.5 Flash / Flash-Lite (#265).
  • Skill (monitoring/token_limiter): model_pricing.json updated with Gemini 3.5 Standard-tier list prices (Sep 2026) (#265).
  • CLI: Brief skillware --help topic list aligned with Context, Chains, and Theme command groups (matching docs/usage/cli.md) (#335).
  • Security: Bump support windows — >= 0.5.5 patched, 0.4.6–0.5.4 silent (no security fixes), < 0.4.6 unsupported with CLI advisory (SECURITY.md, version_policy.py).

[0.5.4] - 2026-09-03

Added

  • Core: SkillContext — one-line registry host context with discovery filters, progressive prepare() / execute(), and provider tool adapters (#330).
  • Core: Named skill chains — chains: in YAML, run_chain(), step when: conditional skip, skillware chain list|show|validate|run|dry-run, and skillware context show (#330).
  • Docs: Skill chaining and registry context — closes #297; implements #330.
  • Examples: skill_context_gemini_loop.py (SkillContext + Gemini), sanitize_input_chain_demo.py (run_chain local); ollama_skills_test.py refactored to use SkillContext.

Changed

  • Docs: SkillContext modes, edge cases, and Ollama multi-skill guidance in skill_chaining.md, ollama.md, introduction.md, cli.md; one-line chain pointers on middleware skill catalog pages.
  • CLI: User-configurable pastel, ocean, and mono presentation themes; interactive menu selection persists globally, project config can override it, and unknown values fall back to pastel (#248).
  • CLI: The mail submenu and direct mail commands now follow the active presentation theme (#248).
  • Skill (security/deceptive_ui_guard v0.2.0): Upgraded deceptive UI scanner with DOM zone classification (checkout, modal, cmp, navigation, general) and severity multipliers, KB allowlists (screen-reader accessibility, CMP consent banners, SEO metadata), expanded taxonomy (prechecked opt-ins, drip pricing, fake scarcity timers, nag loops), mobile profile heuristics, session fingerprint tracking, optional Playwright computed-style render diffing lane, and 23 golden HTML test corpus fixtures (#314, #327).
  • Security: Bump support windows — >= 0.5.4 patched, 0.4.6–0.5.3 silent (no security fixes), < 0.4.6 unsupported with CLI advisory (SECURITY.md, version_policy.py).

Fixed

  • Examples: Derive agent-loop tool dispatch names from the loaded manifest in claude_tos_evaluator.py, ollama_tos_evaluator.py, and ollama_novelty_extractor.py (#178).

[0.5.3] - 2026-09-01

Added

  • Skill (monitoring/kpi_gate v0.1.0): Deterministic business-KPI gate evaluating a metrics snapshot against an operator-maintained policy charter and optional versioned benchmark data — error/warning findings plus honest insufficient_data refusals with reason codes, fail-closed contract errors from a closed registry, stdlib-only validation, and the catalog/docs surface (#317).
  • Tests (tests/test_examples_smoke.py): Added automated CI smoke test suite for local-execute offline demo scripts under examples/, catching import regressions and SkillLoader dispatch errors without requiring live API keys (#237).
  • Docs (docs/TESTING.md): Documented the example smoke testing layer and skip policy for live model provider loops in CI (#237).

Changed

  • Docs (README.md, docs/introduction.md): Refresh opening narrative, tighten Quick Start, shorten Gemini hero example (monitoring/token_limiter), rectangular How it works Mermaid, simplify introduction diagrams, remove legacy Body/Mind/Conscience aliases, and align Presentation (card.json) with registry bundle standard (#326).
  • Security: Bump support windows — >= 0.5.3 patched, 0.4.6–0.5.2 silent (no security fixes), < 0.4.6 unsupported with CLI advisory (SECURITY.md, version_policy.py).
  • Docs: Document issuer.org design-ownership policy; align ARPA-driven registry skills (prompt_injection_firewall, bg_remover, novelty_extractor) and catalog Issuer lines (#295).

Fixed

  • Docs (README.md, docs/introduction.md): How it works Mermaid — rectangular AnyHost["Any Host"] node aligned with Registry and Loader blocks (#326).
  • Tests: Isolate pytest tests/ from the operator's global config.yaml via autouse SKILLWARE_CONFIG_DIR in tests/conftest.py; add configured-mode discovery and loader coverage alongside legacy-order tests (#302).

[0.5.2] - 2026-08-27

Added

  • Skill (security/deceptive_ui_guard v0.1.0): Deterministic deceptive UI surface scanner for web HTML — dual DOM vs visible extraction, structural/lexical heuristics, corroboration gates, trust score, and agent guidance for pre-click and pre-context guardrails (#78).

  • Documentation: Skill catalog pages include a Version header and Skill history table (commit links, dates, versions, and linked GitHub contributor handles); docs/skills/README.md adds a Version column to category tables.

  • Tests: test_catalog_pages_have_version_and_history_blocks() and test_skill_library_index_has_version_column() in tests/test_registry_docs.py guard catalog version/history coverage.

  • Skill (finance/uk_companies_house_handler v1.2.0): Phase v2b upgrade — run_pipeline for sequential multi-step execution with automatic halting on needs_input (disambiguation) or error, step-slicing resumption (steps[prior_completed:]), placeholder auto-substitution (<from_resolve>), and cumulative data payload merging (#220).

  • Skill (finance/uk_companies_house_handler v1.2.0): Composite actions resolve_and_get_officers and resolve_and_get_filings to resolve companies and fetch target records in single-turn operations (#220).

  • Skill (finance/uk_companies_house_handler v1.2.0): Default limit 10 previews with partial response status and agent_hint metadata for officers and filing history (#220).

  • Skill (finance/uk_companies_house_handler v1.2.0): Session context carry-forward across sequential turns (company_number, company_name, role_hint, officer_filter, next_actions) (#220).

  • Documentation: docs/skills/finance/uk_companies_house_handler.md — updated architecture reference for 9 action handlers, partial response previews, and pipeline orchestration (#220).

  • Tests: Expanded unit test suite in skills/finance/uk_companies_house_handler/test_skill.py covering pipeline resumption, composite actions, partial previews, map_intent guards, and punctuation-safe queries (#220).

Changed

  • Skill (security/deceptive_ui_guard v0.1.0): Production deception lexicon with taxonomy metadata and eight categories; standalone agent instructions; demo fixtures recreating documented dark patterns; install_extras security category row (#78).
  • Docs: Updated contributor instructions guidance in CONTRIBUTING.md, ai_native_workflow.md, and templates/python_skill/ to emphasize concise, append-only skill context over persona starters (#258, #284).
  • Docs: Aligned ai_native_workflow.md and templates/python_skill/README.md checklists with catalog Version and Skill history requirements.
  • Meta: GitHub issue templates refreshed for v0.5.1 CLI (doctor, config show, paths/mail submenus) and office/gmail_handler filing paths; label taxonomy adds all registry cat: <category> labels (shared pastel color) so category filters never collide with repo-wide labels such as security (#294).
  • Skill (finance/uk_companies_house_handler v1.2.0): get_officers default active_only is now true (v1.x default was false) — resigned officers are excluded unless active_only: false (#220).
  • Skill (finance/uk_companies_house_handler v1.2.0): Removed conversational prefix stripping from composite actions; agents must pass clean query / company_query plus optional role_hint. map_intent returns needs_input when a company name is required but missing (#220).
  • Skill (finance/uk_companies_house_handler v1.2.0): map_intent wires document_types, entity_types, and status_mappings from terminology_map.yaml into terminology_map output; richer agent_hint on rate-limit, timeout, and connection errors (#220).
  • Documentation: skills/finance/uk_companies_house_handler/instructions.md — skill-context instructions, disambiguation playbook, and parameter-hygiene guidance aligned with #258/#284 (#220).
  • Examples: examples/uk_companies_house_handler_demo.py and shared helpers updated for v2b composites, pipelines, partial previews, and disambiguation resume (#220).

Fixed

  • Meta: Shorten cat: security label description to fit GitHub's 100-character limit; enforce max length in label sync and tests.

[0.5.1] - 2026-08-19

Added

  • Skill (office/gmail_handler v0.2): Reply signature parity, preview metadata (signature_applied, signature_source, signature_profile); attachment list on read_message, download_attachment, and outbound send/reply attachments via flexible paths (local, file://, HTTP(S), optional cloud URIs with fsspec); multi-profile signatures via mail.signatures and skillware mail signature profiles|add-profile|set-profile (#293).
  • Config: Top-level mail: section in .skillware.yaml and global config.yaml — address book path, plain-text signature (inline or file), scan state, and send ledger paths for office/gmail_handler (#292).
  • CLI: skillware mail submenu — address book init/show/validate/set-path/add; signature init/show/set/validate/clear; default HTML signature with Skillware logo (40px) and links; interactive menu option 7 / mail (#292).
  • CLI: skillware config show displays merged resolved mail.* settings including signature source (#292).
  • Skill: office/gmail_handler reads signature from merged config when skill-local default_signature_plain is unset; ships data/config.yaml.example (#292).
  • Documentation: docs/skills/office/gmail_handler.md — attachments, multi-profile signatures, untrusted attachment disclaimer; docs/usage/cli.md and docs/usage/api_keys.md updated (#293).
  • Packaging: PyPI metadata — keywords, expanded classifiers (development status, intended audience, Python 3.10-3.12, AI and library topics), and Documentation, Issues and Changelog entries in [project.urls]. Metadata only; wheel contents are unchanged (#299).

Changed

  • Packaging: PyPI Homepage → https://skillware.site; canonical ARPAHLS casing on GitHub URLs in [project.urls] (release chore).

[0.5.0] - 2026-08-18

Removed

  • Meta: Removed maintainer-only GitHub release draft (.github/RELEASE_v0.4.9.md); use CHANGELOG.md + GitHub Releases UI instead (#290).

Added

  • Skill: office/gmail_handler — deterministic Gmail IMAP/SMTP handler for agent mail workflows: recipient resolution via editable address book, preview/confirm send and reply, inbox search/read, sent-folder and send-ledger search, scan cursor, and context carry-forward (#208, #291).
  • Examples: examples/gmail_handler_demo.py — mocked resolve, preview, search, and read flow (no live Gmail credentials); examples/gemini_gmail_handler.py — interactive Gemini tool loop (demo mode via GMAIL_HANDLER_EXAMPLE_DEMO=1).
  • Documentation: docs/skills/office/gmail_handler.md — integration guide, env setup, action reference, and address book schema.
  • CI: tests/test_registry_identity.py — CI guard asserting every registry-layout skill's manifest.name matches its path-derived registry ID and that all manifest names are globally unique (#280, #288).

Changed

  • Documentation: README, introduction, vision, skill trust model, and CLI usage docs — clarify legacy vs config path resolution, tier order, and that bundled registry skills remain available without a local skills/ tree (#289).

[0.4.9] - 2026-08-12

Added

  • Config: Persistent YAML configuration (global config.yaml and project .skillware.yaml); paths section drives skill root discovery when present; bundled registry always included (#246).
  • CLI: skillware config show prints merged configuration (read-only); skillware paths tips updated for config files (#246).
  • CLI: Interactive paths submenu (menu 4) — view bundled registry, persist project/external paths to .skillware.yaml, shadowing and flat-layout diagnose; tiered help topics (menu 6); universal navigation (0 exit, b back); doctor spinner while diagnosing (#247).
  • Loader: SkillLoader.load_skill(..., execute_module=False) inspect-only load (manifest, instructions, card, requirement pre-flight) without executing skill.py; clearer ImportError when skill.py import fails after pre-flight (#235).
  • CLI: skillware doctor checks manifest deps and skill.py import readiness per skill (DEPS / LOAD table); optional skill ID, --category, and --skills-root (#235).

Changed

  • CLI: skillware examples table — wider EXTRA column; GITHUB shows script filename as a clickable link (full URL on ctrl+click) (#247).
  • CLI: Interactive menu option 6 description reflects grouped help topics (#247).
  • Loader: Skill-not-found errors list searched roots with tier labels (project, external, bundled) (#247).
  • Loader: SkillLoader.load_skill() validates manifest requirements version specifiers (for example web3>=6.0.0) against installed package versions before loading skill.py; unpinned entries still require importability only (#14).
  • GitHub: New Skill Proposal template category dropdown synced with the registry (creative, security); added creative label (#279, #277).

[0.4.8] - 2026-08-03

Added

  • Skill: security/prompt_injection_firewall — offline-only deterministic pre-flight scanner (no LLM path) with local kb/ detectors for hidden text, Unicode/confusable evasion, nested encodings, instruction overrides, corroboration-based sensitivity, and sanitization output (#46).
  • dev_tools/issue_resolver: Caller-fetched ISSUE_RESOLVER.md repository profiles — ordered profile discovery URLs, load_repository_profile parsing with provenance-labelled context, profile standard doc, and Skillware dogfood profile under .github/ISSUE_RESOLVER.md (#145, #271).
  • Documentation: docs/contributing/issue_resolver_profile.md — normative contract and examples for repository-maintained agent context files.

Changed

  • creative/bg_remover: Hardened to v0.2.0 — rembg session reuse, Base64 and file validation, 25 MB limit, path traversal rejection, parent directory creation for output_path, demo script, and expanded bundle tests (#257, #268).
  • dev_tools/issue_resolver: Profile discovery prefers .github/ISSUE_RESOLVER.md over a repo-root fallback; expanded Skillware dogfood profile aligned with contributor workflow and stage gates.
  • Version policy: Raise security support floor to >= 0.4.7; legacy band 0.3.5–0.4.6 (upgrade recommended, silent CLI); unsupported advisory for installs below 0.3.5.

[0.4.7] - 2026-07-25

Added

  • Citation: Root CITATION.cff and README Citing section for formal software citation; first Zenodo-archived GitHub release (#269, #270).

[0.4.6] - 2026-07-23

Added

  • Documentation: OpenAI-compatible host guide and runnable Groq example covering shared to_openai_tool() usage, provider base URLs, credentials, and local servers (#261).
  • Framework: skillware/core/ui_schema.py helpers to resolve dot paths and validate output-card field keys (#199).
  • CI: Parametrized guard tests/test_card_ui_schema.py — every registry skill with output-card ui_schema must ship a fixture under tests/fixtures/card_ui_schema/ whose samples cover all field keys (#199).

Fixed

  • compliance/mica_module, compliance/pii_masker: Align card.json output fields with actual execute() return shape (#199).

Changed

  • finance/wallet_screening: Paginate Etherscan txlist (up to 10k normal txs) and surface metadata.warnings when history is truncated or unavailable; bump skill version 1.0.0 → 1.0.1 (#214, parent #115).
  • Skills (finance/uk_companies_house_handler): Completed Phase v2a upgrade (#220). Added context parameter to carry forward session state (company_number, company_name, officer_filter, etc.). Added partial envelope status and optional pipeline state to support paused multi-step pipelines (noted as v2b prep in instructions). Updated _get_officers to fallback to company_name from context and added tests for fallback logic. Updated examples/gemini_uk_companies_house_handler.py into a fully interactive chat loop.
  • Documentation: CONTRIBUTING and contributor workflow checklists — update card.json and output fixtures together when changing execute() output (#199).

[0.4.5] - 2026-07-16

Added

  • Added creative/bg_remover, an offline background removal skill powered by rembg (#196).
  • Packaging: Category, per-skill, and [all] optional extras generated from skill manifests via scripts/sync_extras.py; hand-maintained dev, SDK extras, and meta [agents] (#236).
  • Documentation: Install extras — canonical guide for pip install skillware[...] targets (#236).
  • Framework: skillware/core/extras.py and richer ImportError hints from SkillLoader when manifest requirements are missing (#236).
  • CI: PyPI wheel packaging smoke test — builds a wheel, installs it in a fresh venv (base deps only), and verifies every bundled registry skill is present and loadable via scripts/wheel_smoke_test.py (#182).
  • Documentation: Cross-linked wheel-smoke CI job in CONTRIBUTING.md and docs/contributing/ai_native_workflow.md (#182).
  • CLI: skillware paths shows skill root resolution order (external → project → bundled), tier labels, shadowing summary, and operator tips; interactive menu option 4 wired (#81).
  • Framework: skillware/core/discovery.py — shared skill root discovery for SkillLoader and the CLI (tier labels, shadowing, registry ID listing; foundation for config-driven paths in #246).
  • Framework: BaseSkill.validate_params() — optional helper to validate tool arguments against manifest parameters JSON Schema; raises SkillwareParamValidationError on mismatch. Not called automatically by the loader or execute() (#125). Reference: examples/claude_wallet_check.py, examples/gemini_tos_evaluator.py.
  • Framework: Registry manifests standardize on outputs: (legacy singular output: removed from finance/wallet_screening) (#125).

Changed

  • Framework: Map manifest requirement pillow to import name PIL in SkillLoader dependency checks (#196).
  • Packaging (breaking): Removed legacy extras cli, embeddings; [all] is skill runtime deps only (not SDK packages). Use [agents] for Gemini + Claude + OpenAI SDK deps (#236).
  • CLI: skillware list prints a pointer to the install extras guide (#236).
  • Documentation: README, CONTRIBUTING, TESTING, skill catalog pages, and examples index updated for the new extra taxonomy; every skill doc recommends its per-skill extra (#236).
  • Framework: SkillLoader delegates root resolution to discovery.get_skill_roots() so load, list, test, and paths use the same order (#81).
  • CLI: Help and menu list paths as available (no longer “coming soon”) (#81).
  • Documentation: README — trim redundant Contributing cross-links, add skillware paths to install verification, and link the skill trust model in the docs table; cross-link skillware paths in docs/introduction.md and docs/usage/README.md.
  • Documentation: Add operator expectations (bundled vs external, out-of-band changes, where to report issues) and an instruction-only content note to docs/security/skill-trust-model.md; add trust-model cross-links from README configuration and CONTRIBUTING Skill Package Standard (#243).

[0.4.3] - 2026-07-10

Added

  • Framework: Added _sanitize_gemini_tool_name() to skillware/core/loader.py to explicitly map provider tool naming constraints.
  • Tests: Added test_sanitize_gemini_tool_name() to tests/test_loader.py to verify safe translation and test_skill_docs_gemini_anti_patterns() to tests/test_registry_docs.py to enforce documentation hygiene by preventing manual tool wrapping and mutation anti-patterns in skill catalog pages.
  • Documentation: Added canonical dispatch guidelines to docs/usage/gemini.md and docs/usage/skill_usage_template.md.
  • Documentation: Category selection guidance for contributors; issue-first policy for new top-level folders in CONTRIBUTING.md (#204).

Changed

  • GitHub: Overhauled issue templates (CLI, Skill Upgrade, Examples, Packaging), issue chooser config.yml, PR template, and label taxonomy with pastel colors; labels sync automatically from .github/labels.json via CI on merge to main (#227).
  • Framework: SkillLoader.to_gemini_tool() now returns a google.genai.types.Tool object instead of a raw dictionary, ensuring compatibility with the google-genai SDK when passing tools to GenerateContentConfig.
  • Tests: Updated tests/test_loader.py to assert against the properties of the google.genai.types.Tool object for to_gemini_tool().
  • Documentation: Updated Gemini integration snippets across all skill catalog pages and introduction.md to reflect the to_gemini_tool() API change and correct tool name sanitization.
  • Documentation: Aligned agent_loops.md and cli.md with Gemini sanitized tool-name dispatch after #229 (#230 follow-up).
  • Examples: Removed manual types.Tool wrapping, and consistently utilize SkillLoader._sanitize_gemini_tool_name() for derived tool names in gemini examples.

Fixed

  • Framework: SkillLoader.to_gemini_tool() returned a plain dictionary instead of google.genai.types.Tool, causing runtime failures when passed to GenerateContentConfig(tools=...) with the google-genai SDK. Fixes #223.

[0.4.2] - 2026-07-08

Changed

  • CLI: Interactive splash — correct SKILLWARE ASCII logo, Rich 3-stop gradient on logo and tagline (#D4E4F1 → #79B6D8 → #EBD8DC), shared _package_version_str() for splash and --version, tagline Skillware v{version} — Skill Management Framework (#222).
  • Documentation: Compact architecture Mermaid diagrams — shorter README labels, model-agnostic adapter nodes in introduction, horizontal agent-loop layout with role table (#210 follow-up, #221).
  • Documentation: Docs sweep — README Mermaid Registry alignment; vision.md pinned to v0.4.x; skill catalog and usage guides prefer bundle["class"]() with explicit bundle["module"].ClassName() noted as still supported (#225).

[0.4.1] - 2026-07-08

Added

  • finance/uk_companies_house_handler: New skill for UK Companies House REST API — deterministic company search, profile, officers, PSC, filing history, and intent-to-operation mapping with UK corporate terminology translation; bundled endpoint index and terminology map; status-based response envelope (ready/needs_input/error) with disambiguation support (#172, #218).
  • Documentation: Add docs/security/skill-trust-model.md documenting the skill execution model, on-disk resolution order and shadowing, provenance tiers (Bundled / Project / External), and operator security guidance; wire links from SECURITY, usage, CONTRIBUTING, and CODE_OF_CONDUCT (#109).
  • Documentation: Add minimal Mermaid architecture flow diagrams to README, introduction, and agent loops; cross-links, Step 1 mini-pipeline, adapter fan-out, and direct-path footnotes (#210, #217).

Changed

  • Loader: SkillLoader.load_skill() auto-discovers the single BaseSkill subclass in each skill.py and exposes it as bundle["class"]; get_skill_class() helper added. Existing bundle["module"] usage is unchanged (#89).
  • Loader: SkillLoader.load_skill() validates that manifest.yaml name matches the path-derived registry ID for category/skill_name layouts; emits SkillwareIdentityWarning on mismatch (warn-only v1). Flat private skills under a skill root are unchanged. Bundles now include optional registry_id (#200).
  • Version policy: Raise security support floor to >= 0.3.5, legacy band 0.3.0–0.3.4 (silent CLI), unsupported advisory for installs below 0.3.0 (#192).
  • Documentation: Clarify skill ID vs manifest name vs provider tool names in docs/usage/cli.md, docs/usage/agent_loops.md, and docs/introduction.md; require full registry IDs in CONTRIBUTING manifest standard (#201).

Fixed

  • office/pdf_form_filler and defi/evm_tx_handler: Align manifest.yaml name with registry paths (office/pdf_form_filler, defi/evm_tx_handler); update examples and docs to use manifest-derived tool dispatch (#201).

[0.4.0] - 2026-06-30

Added

  • monitoring/token_limiter: New monitoring skill that evaluates cumulative token usage and returns CONTINUE, WARN, or FORCE_TERMINATE for autonomous agent loops; bundled indicative model pricing, ROI scaffold fields for v2, local and provider loop examples (#23, #207).
  • New monitoring skill category in CONTRIBUTING, ai_native_workflow.md, and docs/skills/README.md.
  • Tests: tests/test_registry_docs.py — CI doc-drift guards that verify skill catalog, examples index, and agent-loops reference matrix stay in sync with the registry (#183, #189).
  • Documentation: Cross-linked tests/test_registry_docs.py in ai_native_workflow.md and CONTRIBUTING.md so contributors know doc-drift guards run in CI; added explicit PR checklist reminder in CONTRIBUTING.md (#193, #197).

Changed

  • Documentation: docs/skills/monitoring/token_limiter.md — budget disclaimer callout, limitations clarity, and enterprise disclaimer (#23).
  • Documentation: README Stats section and live PyPI download badges (pepy / PyPI Stats dashboards, header DLs ↓ total) (#198).
  • Documentation: Aligned CLI and examples docs (docs/usage/cli.md, examples/README.md, docs/vision.md, README.md) with the skillware test / skillware examples behavior (#191, #194).

[0.3.9] - 2026-06-26

Fixed

  • CLI: skillware examples and list --examples fetch examples/README.md from GitHub when no local copy is found (pip installs and directories outside a checkout).

[0.3.8] - 2026-06-26

Changed

  • Tests: tests/test_skill_issuer.py now requires test_skill.py for every registry skill under skills/ (#160).
  • Documentation: Clarified that bundle tests must mock network calls and model downloads in CI (#170).
  • Documentation: Added a Status section to TESTING.md summarizing the current testing model (#179).
  • Documentation: Post-release alignment — category tables, Python 3.10+ badge, dev install ([dev,all] vs [dev]), README configuration via .env.example, DeFi env vars in .env.example, framework env vars in api_keys.md (#154).

Added

  • CLI: skillware test runs bundle tests via pytest — all roots, by skill ID, or by --category; supports -v and --no-header. Documented in cli.md, TESTING.md, and contributor guides (#83).
  • CLI: skillware list --examples shows per-skill example script counts; skillware examples [skill_id] lists indexed runnable scripts from examples/README.md with GitHub source links; interactive menu option examples (#126).

[0.3.7] - 2026-06-22

Added

  • wellness/mental_coach: Deterministic wellness coaching firewall with crisis triage, hard scope limits, embedded public KB, optional Gemini scope evaluator, and catalog documentation (#148).

Changed

  • Tests: Moved tests/test_mica_module.py to tests/skills/compliance/test_mica_module.py so maintainer skill tests follow the tests/skills/<category>/ layout; tests/ root is framework-only (#86).
  • wellness/mental_coach: Set real issuer contact email and add health disclaimer on the catalog page (PR #174 follow-up).

Fixed

  • finance/wallet_screening: Align examples and docs with finance/wallet_screening manifest tool name; fix gemini_wallet_check.py and claude_wallet_check.py to match tool name dynamically from manifest; correct card.json UI fields to match actual skill output schema; update instructions.md, provider snippets, Data Schema, and usage docs (#173).

[0.3.6] - 2026-06-15

Added

  • Tests: Backfilled test_skill.py for six registry skills (mica_module, pii_masker, synthetic_generator, wallet_screening, pdf_form_filler, prompt_rewriter); all registry skills now ship co-located bundle tests. Fixed prompt_rewriter package export so pytest can collect the bundle (#158).
  • CLI: skillware/__main__.py enables python -m skillware as a fallback when the skillware command is not on PATH (#135). Added cmd_help() for rich-formatted help, wired to skillware --help/-h and interactive menu option 4. Added --version/-V flag.

Fixed

  • novelty_extractor: Bundle tests mock fastembed embeddings so CI avoids HuggingFace downloads and rate limits (#159 follow-up).
  • finance/wallet_screening: WalletScreeningSkill.manifest loads manifest.yaml from the bundle directory (#165).

Changed

  • CI: GitHub Actions runs pytest skills/ then pytest tests/ after lint (bundle + framework/maintainer tests; closes #90) (#159).
  • CI: CodeQL GitHub Action upgraded from v3 to v4.
  • Dependencies: Extended [all] with registry skill runtime deps (web3, fastembed, numpy); added [defi] and [embeddings] optional extras. Documented manifest ↔ pyproject.toml convention in CONTRIBUTING and TESTING.md.
  • Documentation: TESTING.md, CONTRIBUTING.md, ai_native_workflow.md, and README architecture tree document the bundle / framework / maintainer / example testing model. Pytest collects tests/ and skills/ only (examples/ ignored).
  • Dependencies: Moved rich>=13.0 from [cli] extra to core dependencies; CLI is now available immediately after pip install skillware. The [cli] extra is kept as an empty deprecated alias for backward compatibility (#135).

[0.3.5] - 2026-06-05

Added

  • defi/evm_tx_handler (#142): Structured EVM agent wallet skill on Ethereum and Base — resolve, Uni V2 quote/preview/execute (approve + swap), transfer, balances, wallet_info, YAML registries, optional CoinGecko USD preview, max_trade_usd fail-closed cap, balance pre-flight checks, and mocked Web3 tests. Examples: examples/gemini_evm_tx_handler.py, examples/claude_evm_tx_handler.py.

Changed

  • CI: GitHub Actions installs from pyproject.toml only (pip install -e ".[dev,all]"); runs black --check, flake8, then pytest tests/ (#151, #153). Co-located skills/**/test_skill.py remains a local pre-PR step.
  • Documentation: COMPARISON.md and README updated for Agent Skills (SKILL.md) and fairer MCP framing (#123); TESTING.md and CONTRIBUTING.md aligned with CI and Black gate (#151, #153); defi skill category added to CONTRIBUTING.

Fixed

  • dev_tools/issue_resolver: Replaced wide emoji regex in commit-message validation with explicit Unicode ranges (CodeQL py/overly-large-range, #146).

[0.3.3] - 2026-05-29

Added

  • dev_tools/issue_resolver: GitHub issue workflow with sequential stage checklists, conditional verify/commit gates, and commit-message validation (#143).
  • Examples: gemini_issue_resolver.py, claude_issue_resolver.py, and ollama_issue_resolver.py for dev_tools/issue_resolver (#118).
  • Version policy: skillware/version_policy.py with supported-version thresholds; CLI prints one dim stderr advisory only for installs below 0.2.6 (#132).
  • Tests: tests/test_version_policy.py for advisory thresholds, opt-out, and CLI hook (#132).
  • Documentation: Added docs/vision.md with project story, roadmap, and agent discoverability (#133).

Changed

  • finance/wallet_screening: Unified TRM/scam transaction risk index for analysis (#140).
  • SECURITY.md: Supported-version table aligned with >= 0.3.1 security support and unsupported < 0.2.6 band (#132).
  • CLI: Calls version advisory once at main() startup, not on menu re-loops (#132).
  • Dependencies: Added packaging for semver comparisons (#132).
  • Documentation: README Mission links to vision.md; wallet screening comparison table lives in COMPARISON.md; docs table and cross-links updated (#133).

[0.3.2] - 2026-05-27

Added

  • Changelog: Added root CHANGELOG.md following Keep a Changelog, with retrospective release history from v0.2.0 and a README nav link (#108).
  • finance/wallet_screening: FTM publicKey matching and an ETH sanctions index (#128).

Changed

  • CLI: Visual redesign for skillware list, including pastel table, short_description column, interactive splash, and menu (#129).
  • CLI: Interactive polish - splash footer links, menu re-loop, stub labels for #81 / #83, width-aware table, shared terminal context (#130, #131).
  • Contributing: Aligned Code of Conduct, CONTRIBUTING, agent workflow, and PR template for CHANGELOG maintenance and co-authoring rules (#124).
  • Documentation: README documentation table and docs/introduction.md link to CHANGELOG.md; contributor template documents optional short_description (#130).

[0.3.1] - 2026-05-25

Added

  • Novelty Extractor Skill: Introduced the data_engineering/novelty_extractor skill (#116, fixes #24).
  • Examples Index: Added examples/README.md to serve as the canonical index of runnable provider scripts (#107).

Changed

  • SDK Migration: Migrated framework and examples from google-generativeai to the new google-genai SDK (#97) and updated all usage documentation snippets (#92).
  • Documentation: Improved README navigation and overall skill catalog discoverability (#98).
  • Documentation: Cross-linked runnable examples directly on skill catalog pages (#121) and synced agent_loops.md with the central examples index (#122).

[0.2.9] - 2026-05-22

Added

  • CLI Tool: Introduced the skillware command-line interface, starting with the skillware list command for skill discovery (implemented by contributor @rizzoMartin) (#84).
  • CLI Features: The list command prints a rich table of locally installed skills and supports filtering via --category, --issuer, and --skills-root flags.
  • Optional Extras: Added optional dependency groups in pyproject.toml ([cli], [gemini], [claude], [openai], [office], [all], [dev]) so users only install the SDKs their specific skills require (#87).

Changed

  • Leaner Core Install: Removed heavy SDKs (anthropic, google-generativeai, pymupdf, openai) from the default installation, reducing core requirements to just requests, pyyaml, python-dotenv, and beautifulsoup4 (#87).
  • Dependency Management: Consolidated dependency management entirely into pyproject.toml.
  • Requirements File: Transformed requirements.txt into a dev-convenience pointer (running pip install -e ".[dev,all]") rather than a duplicate flat dependency list.

[0.2.8] - 2026-05-22

Added

  • Issue Resolver Skill: Introduced the dev_tools/issue_resolver skill for universal GitHub issue analysis and resolution (#56).
    • Validates and normalizes any public GitHub issue URL and returns a structured payload containing pre-computed GitHub API and raw content URLs.
    • Guides calling agents through a 5-stage workflow (fetch issue, read repo context, analyze files, produce a ranked plan, implement after approval).
    • Includes optional github_token and extra_instructions parameters.
    • Compatible with all five provider adapters (Gemini, Claude, OpenAI, DeepSeek, Ollama).
    • Requires no network calls itself and has no runtime dependencies beyond PyYAML.
  • Dev Tools Category: Introduced the new dev_tools skill category.

Changed

  • Skill Catalog Revamp: Overhauled all pages under docs/skills/ to include a breadcrumb trail, per-provider Usage Examples, environment variable tables linking to the API keys guide, data schema blocks, and a limitations section (#82).
  • Documentation Polish: Removed emojis from all catalog pages and the main skills README index (#52).

Fixed

  • Metadata: Corrected the author name in pyproject.toml from ARPA Hellenic Logic Systems to ARPA Hellenic Logical Systems.

[0.2.7] - 2026-05-18

Added

  • Packaging: Full skill bundles on PyPI. Wheels now include manifest.yaml, instructions.md, card.json, and skill data files, rather than only .py modules.
  • Packaging: Configured MANIFEST.in to graft the skills/ tree and updated [tool.setuptools.package-data] so new registry skills do not require per-skill pyproject.toml edits.
  • Registry: Added empty __init__.py files under skills/ category packages (and skill folders where needed) to ensure setuptools packages the complete tree. This requirement is now enforced in tests for new registry skills.
  • Documentation: Added a "Finding skills on disk" usage guide.
  • Documentation: Added contributor notes for PyPI packaging in CONTRIBUTING.md and the skill template README.

Fixed

  • Skill Loader: Fixed skill resolution paths after pip install (#13). SkillLoader.load_skill() no longer restricts searches to site-packages/skills/. It now falls back through the following order:
    1. An existing path on disk (absolute or relative)
    2. Roots defined in the SKILLWARE_SKILL_PATH environment variable
    3. A local skills/ folder in the current working directory (searching up to six parent directories)
    4. Bundled registry skills shipped with the package (Note: If nothing matches, the error now explicitly lists the paths that were tried).

[0.2.6] - 2026-05-17

Added

  • Framework: Added OpenAI adapter (SkillLoader.to_openai_tool()) for Chat Completions tool calling (#68).
  • Framework: Added DeepSeek adapter (SkillLoader.to_deepseek_tool()) as a separate public API (#70).
  • Framework: Added shared function-name sanitization for OpenAI-compatible providers.
  • Documentation: Added OpenAI and DeepSeek usage guides and corresponding integration examples (examples/openai_tos_evaluator.py, examples/deepseek_tos_evaluator.py) (#69, #70).
  • Documentation: Added usage guides index, agent loops, and skill usage template (#71).
  • Documentation: Added Usage Examples on all seven skill catalog pages (Gemini, Claude, OpenAI, DeepSeek, Ollama) (#71).
  • Documentation: Added generic setup guide for API keys for skills (#67).
  • Documentation: Added README links to usage index and agent loops (#71).
  • Contributing: Added Agent Contribution Workflow, an agent-directed guide (#64, #65).
  • Registry: Added Issuer attribution on all skills (manifest.yaml, card.json, docs/skills/*.md, catalog) (#63).
  • Registry: Added Enterprise disclaimer on ARPA catalog skill pages (#59, #62).
  • Tests: Added tests/test_skill_issuer.py for registry issuer validation (#63).

Changed

  • Documentation: Updated Ollama guide for current local models (#71).
  • Contributing: Restructured CONTRIBUTING.md for contribution types and skill standards (#64).
  • Contributing: Aligned the Usage Examples requirement in CONTRIBUTING and agent workflow (#71).

[0.2.5] - 2026-04-28

Added

  • TOS Evaluator Skill: Introduced the compliance/tos_evaluator skill for local-first website policy evaluation prior to automated access.
    • Checks robots.txt permissions for target URLs and user-agents.
    • Discovers candidate legal pages (Terms, Legal, Acceptable Use, API links).
    • Extracts and evaluates policy clauses related to automated behaviors (scraping, crawling, indexing, monitoring, etc.).
    • Returns structured verdicts (SAFE, UNSAFE, CAUTION, INSUFFICIENT_EVIDENCE) alongside evidence payloads and next-step guidance.
    • Features an optional, provider-configurable low-cost LLM fallback for ambiguous clauses.
  • Skill Infrastructure: Added the complete package contents for the TOS Evaluator under skills/compliance/tos_evaluator/ (including manifest, logic, and instructions).
  • Testing: Added central tests (tests/skills/compliance/test_tos_evaluator.py) and local skill tests.
  • Documentation: Added dedicated skill documentation (docs/skills/compliance/tos_evaluator.md) and updated the central skill catalog.
  • Examples: Added integration scripts (examples/gemini_tos_evaluator.py, examples/claude_tos_evaluator.py, examples/ollama_tos_evaluator.py).
  • Dependencies: Added beautifulsoup4 (bs4 in the manifest) to the project for deterministic HTML parsing.

[0.2.4] - 2026-04-11

Added

  • MiCA Compliance Module: Added the compliance/mica_module skill, featuring in-memory caching for ultra-low latency RAG (~1.7ms) and a weighted surgical router to prevent context window asphyxiation.

Changed

  • Pure Cognitive Framework: Realigned all MiCA examples (Gemini, Claude, Ollama) to follow a prompt-based cognitive pattern that avoids opaque native tool-calling obstacles.
  • Documentation: Comprehensive documentation updates for the new Compliance category and a refined core README.

Fixed

  • Quality Engineering: Resolved all PEP 8 and Flake8 violations across the registry and verified execution with 100% unit test success.

[0.2.3] - 2026-04-09

Added

  • Zero-Latency PII Masker Skill: Introduces the compliance/pii_masker component to act as a "Privacy Firewall", intercepting and scrubbing sensitive metadata (Names, Emails, Physical Addresses, Crypto Wallets) locally before external LLM dispatch.
  • Ollama Edge Interoperability: Leverages the 270M parameter arpacorp/micro-f1-mask structure for optimized, offline processing.
  • Dynamic Modalities: Added three processing modes for the masker:
    • mask: Preserves contextual entity tags (e.g., [PERSON_1]).
    • redact: Completely overwrites tokens with localized constants (xxxx).
    • remove: Intelligently drops strings from the payload to decrease token size.
  • Testing: Integrated rigorous Pytest mock structures intercepting the edge boundary.

Changed

  • API Manifests: Rewrote API compliance manifest parameters to match the internal JSON Schema architecture.

[0.2.2] - 2026-04-03

Added

  • New Skill: Introduced the data_engineering/synthetic_generator skill for bulk-generating high-entropy synthetic training data to combat model collapse (Resolves #22).
  • Model Agnosticism: Added internal routing support for the synthetic generator to use Ollama, Gemini, and Anthropic.
  • Zero-Dependency Entropy Scoring: Added a new zlib compression ratio heuristic to natively validate lexical entropy and block boilerplate outputs without heavy NLP dependencies.
  • New Documentation: Launched the Data Engineering category in the central skill registry along with comprehensive integration guides and integration scripts (examples/build_dataset_demo.py).

Fixed

  • Bug Fixes: Addressed all flake8 PEP8 linting issues across the module.

[0.2.1] - 2026-03-21

Added

  • Prompt Token Rewriter Skill: A new middleware skill (optimization/prompt_rewriter) that heuristically compresses bloated prompts into fewer tokens, supporting low, medium, and high aggression levels.
  • Optimization Category: Established a new domain in the skill registry for architectural and operational efficiency tools.
  • Skill Reference Card: Comprehensive documentation for the Rewriter at docs/skills/optimization/prompt_rewriter.md.
  • Interactive Demo: Added examples/prompt_compression_demo.py for offline testing of compression logic.

Changed

  • Middleware Patterns: Updated the Gemini usage guide with "Skill Chaining" examples demonstrating the rewriter as an automated pre-processor.
  • Standardized Manifests: Aligned all skill metadata with the new parameters and constitution standard.

Fixed

  • CI/CD Alignment: Fixed linting and formatting issues to ensure 100% flake8 compliance in core registry files.

[0.2.0] - 2026-03-21

  • Consolidated and rolled forward into v0.2.1.