All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog and this project adheres to Semantic Versioning.
Contributors add user-facing entries under [Unreleased] in the same PR. Maintainers rename that section to a version and date when cutting a PyPI release. See CONTRIBUTING.md.
- Governance / Licensing (SPDX & Copyright Headers): Standardized top-of-file SPDX license identifiers (
SPDX-License-Identifier: MIT) and explicit copyright notices (# Copyright (c) 2026 ARPA Hellenic Logical Systems) across all core framework source files (skillware/**/*.py), CLI entry points, and authoring templates (templates/python_skill/) to protect against attribution stripping and ensure enterprise SCA compliance (#416). - Tests / CI: Added
tests/test_spdx_headers.pyasserting that all Python source files underskillware/andtemplates/enforce valid top-of-file SPDX license identifiers and copyright notices (#416).
- Governance / Security (The Permissive Fortress): Established repository and supply-chain defense-in-depth under the MIT License — inbound
Legal notice and code ownershipterms inCONTRIBUTING.md(irrevocable license grant, non-revocability, patent non-assertion, no malicious logic), PR template confirmation checkbox, and strengthenedCODE_OF_CONDUCT.mdenforcement authority against credential exfiltration and rogue execution. - Skill (
security/deepfake_guardv0.1.0): Air-gapped forensic verification and document authenticity guard for synthetic media, digital tampering, C2PA provenance, and ICAO 9303 MRZ validation. Features cyclic(7, 3, 1)check digit calculations across TD1, TD2, and TD3 passports and ID cards; ISO 7810 ID-1 geometry verification; high-pass Laplacian noise residual variance analysis; JPEG Error Level Analysis (ELA); 2D FFT moiré screen recapture grid detection; copy-move spatial cloning detection; and C2PA JUMBF / generative AI metadata extraction (#48). - Core / Security: Pluggable
credential_fncallable support inBaseSkill.__init__andBaseSkill.credential()for hermetic, sandboxed secret resolution without polluting process-globalos.environ. - CI / Security: Added
.github/workflows/security.ymlfor automated AST security audits (bandit -lll), dependency vulnerability checks (pip-audit), anti-obfuscation and linting (ruff), and static typing (mypy). Addedtests/test_security_audit.pyenforcing zero dynamic execution primitives (eval,exec,compile) and prohibiting rawos.environsecret reads inskills/. - Skill (
office/web_form_mapperv0.1.0): Universal web form mapper and submitter skill for automated web form discovery, address booklegal_profileintegration, non-mutating preview diffs, and confirmation-gated dispatch with automatic hidden field / anti-CSRF token / ASP.NET__VIEWSTATEpreservation and fail-closed anti-bot challenge detection (#45). - Core / Async: Native asynchronous skill execution parity (
BaseSkill.aexecute,SkillContext.aexecute,SkillContext.acall) with non-blocking default fallback viaasyncio.to_threadfor all existing skills, bidirectional sync/async bridging, per-calltimeoutenforcement, and semaphore-backed concurrency throttling viaSkillContext(max_concurrency=N)(#18). - Orchestration / Chains: Asynchronous skill chain runner (
skillware.chains.arun_chain) supporting deterministic step execution, conditionalwhen:skipping, parameter mappings, short-circuit error handling, and chain-level timeouts without blocking the host event loop (#18). - Examples / Docs: Added
examples/async_tool_loop.pydemonstrating concurrent async fan-outs withasyncio.gather, concurrency limits, and async chain execution; updateddocs/usage/agent_loops.mdanddocs/usage/skill_chaining.md(#18). - CLI / Tests: Guard
open_path_in_osinskillware.cli_osand mock target intests/test_cli.pyto prevent automated test runs from launching external OS file managers or application windows on the host desktop.
- Skill (
compliance/mica_modulev0.1.2): Statutory knowledge notice — catalog callout, directive and constitution framing,statutory_snapshoton execute output and card UI; documents offline snapshot cutoff (Regulation (EU) 2023/1114) as informational reference, not formal legal counsel (#397). - Docs / templates: CONTRIBUTING and
templates/python_skill/README.mddocument the statutory notice pattern for future regulatory skills (#397). - Docs: TESTING.md — Clone dev setup subsection (dedicated venv, editable vs PyPI wheel, import sanity check, recovery via
doctor --installand dev install scripts); cross-links from CONTRIBUTING.md and ai_native_workflow.md (#232). - Templates: Modernize
templates/python_skill/starter bundle — dynamically loadmanifest.yamlinskill.py, demonstrate schema parameter validation (self.validate_params()) and structured error handling, aligncard.jsonfields withmanifest.yamloutputs, fixtest_skill_manifest_consistencyfailure, verifySkillLoaderbundling, and expandREADME.mdwith complete skill creation workflow, Do's/Don'ts, and card UI schema fixture requirements.
- Skills: Load co-located
manifest.yamlin stub skills (compliance/mica_module,compliance/pii_masker,data_engineering/novelty_extractor,optimization/prompt_rewriter) via sharedBaseSkill.load_manifest_from_dir()helper instead of hardcoded metadata dicts (#203). - Skill (
office/pdf_form_fillerv0.1.1): Load the bundle helpers once at import time (relative, package, thenimportlibunder a unique module name, matchingdefi/evm_reader) instead of appending the skill directory tosys.pathon everyexecute()and importing a top-levelutilsmodule, which grewsys.pathin long-running hosts and clashed with a host application's ownutilsmodule in both directions (#398).
- CLI / packaging: Harden version display when editable and PyPI installs overlap —
get_package_version_display()never printsNone;detect_install_conflicts()viaassess_install_health(); startup stderr hint;skillware doctor --installwith recovery commands; install summary inskillware config show(#333). - Scripts:
scripts/dev_install.shandscripts/dev_install.ps1— uninstall overlapping installs and reinstall editable dev deps. - Core / CLI: EVM operator config layer — bundled
skillware/data/evm_defaults.yaml, writable userevm.yaml,skillware.core.evm_configmerge helpers (load_merged_evm_config,resolve_chain,resolve_rpc_url,normalize_evm_address), andskillware evmcommands (init,chains list,chain add,rpc enable,validate,open). Project/global YAML uses top-levelevm:(or read-onlyweb3:alias) — distinct from orchestrationchains:(#379). - Docs: EVM operator config — shared defi RPC setup guide; cross-links from CLI, API keys, DeFi catalog,
evm_tx_handler, andtoken_security_scanner(#379). - Core / CLI: Shared address book
public_0xfield, relaxed contact validation (email or wallet), top-levelskillware addressbookcommands (list,edit,set-wallet,remove,open),skillware config open,skillware evm token add, andskillware evm tokens listfor operator token registry (#373, #374). - Docs: Address book operator config — shared contact identity guide (mail + defi, schema, CLI, cross-links); glossary
public_0x/ shared address book terms; transfer-by-name usage examples onevm_tx_handler(#373, #374). - Examples:
gemini_gmail_minimal.py— README quick-start interactive Gemini + Gmail loop;pay_and_notify_demo.py— reproducibleSkillContextpay + notify recipe with documented prerequisites. - Skill (
defi/evm_tx_handlerv0.3.0): Central address book recipient resolution withneeds_inputdisambiguation; merges operator EVM chain/token config fromskillware.core.evm_config(#373). - Docs: Structured hub architecture for catalog discovery — compact root README category table, docs/sitemap.md, and landing pages at
docs/skills/<category>/README.mdwith catalog pages beside them (docs/skills/<category>/<skill_name>.md). Runtimeskills/<category>/<skill_name>IDs andSkillLoader.load_skill()are unchanged (#370). - Skill (
security/prompt_injection_firewallv0.2.0): OWASP LLM01 Layer-1 trust-boundary input defense upgrade — local evasion detection engine (leetspeak deobfuscation, multi-token ROT13 and token-reversal, typoglycemia scrambled keywords, mixed-script homoglyphs, markdown and HTML image exfiltration channels), academic/advisory mention-vs-use false-positive controls, operator policy telemetry (policy_action:allow|flag|block,removed_span_count,sanitized_length_delta), finding enrichments (decode_chain,decoded_preview), and DoS soft resource caps failing closed safely (#273, #361). - Skill (
defi/token_security_scannerv0.1.0): Read-only GoPlus Token Security scan (scan,supported_chains) with normalizedrisk_tier/signalsJSON for pre-trade agent checks; chain resolution viaskillware.core.evm_config(#365, #368). - Skill (
defi/evm_readerv0.1.0): Read-only EVM state plane (erc20_metadata,erc20_balance,erc20_allowance,erc721_metadata,erc721_balance,erc721_owner_of,call_view,multicall,resolve_holder) without signing or private keys; high-precision decimal formatting, EIP-55 checksum validation, Multicall3 batch queries, central address book resolution withneeds_inputdisambiguation, and shared EVM operator config integration (#367).
- Docs: CONTRIBUTING.md — editable vs PyPI on the same Python; CLI docs for
doctor --install(#333). - Docs: Catalog pages include a standardized intent header (problem solved, host agents, runtime / key requirements) for search matching without stuffing (#370).
- Docs / CI: Doc-drift guards follow nested catalog paths; CONTRIBUTING, PR/issue templates, and the skill template point at category hubs and the sitemap (#370).
- Skill (
defi/evm_tx_handler): Setup envelope docs URL now points atdocs/skills/defi/evm_tx_handler.md(#370). - Skill (
office/pdf_form_filler):short_descriptionno longer implies a Claude-only mapper (#370). - Card UI (
security/prompt_injection_firewall): Exposepolicy_action,removed_span_count, andsanitized_length_deltaincard.jsonand sync sample fixture (#273, #361). - Docs: Glossary cross-links on hub and catalog pages (#363).
- README: Quick-start usage example is Gemini +
office/gmail_handler(gemini_gmail_minimal.py) instead of the prompt-injection firewall snippet.
- Skill (
linguistics/korean_slangv0.1.0): Newlinguistics/category and offline Korean Gen-Z slang pack — interpret / suggest / lookup over a September 2026 curated KB, honorific audience gates, and constitution filters for slurs (#34). - GitHub:
cat: linguisticsin.github/labels.jsonand the New Skill Proposal category dropdown; GitHub UI labels sync on merge tomain(#34). - Examples:
korean_slang_demo.py— offline interpret, suggest, lookup, unmatched, and blocked-term paths (#34). - Scripts:
korean_slang_stress_sim.py— offline interpret/suggest stress harness (#34). - Docs: Glossary and inclusive language — operator / contributor / host agent / end user; skill bundle vs PyPI package; anatomy roles (#252).
- Core: Pluggable secret providers —
SecretProvider,EnvSecretProvider,MappingSecretProvider,CallableSecretProvider, andSkillLoader.resolve_env_vars()inject manifestenv_varsintoBaseSkill(config=...)without requiring globalos.environmutation (#39). - Core:
BaseSkill.credential()— config-first credential lookup withos.environfallback for local.envworkflows (#39). - Core:
SkillContext(secret_provider=...)resolves credentials on eachexecute()and passes them viaconfig(supports ephemeral tokens from custom providers) (#39). - CLI:
skillware doctorENVS column — reports missing required manifestenv_vars(#39). - Examples:
secret_provider_demo.py— host-injected credentials withoutos.environ(#39). - Core:
SkillLoader.to_bedrock_tool()for AWS Bedrock Converse tool-use API — maps manifest parameters totoolSpec/inputSchema.json(#262). - Docs: Enterprise cloud usage guides — enterprise_cloud.md (hosting + adapter routing), bedrock.md, azure_openai.md, vertex.md (#262).
- Examples:
bedrock_tos_evaluator.py— Bedrock Converse loop withto_bedrock_tool()(#262). - Skill (
creative/deck_builderv0.2.0): Enterprise presentation platform baseline — procedural Pillow placeholders, image fit policies, layouts (timeline,metrics,comparison),lint_deckquality gates,suggest_outlinearchetypes, governance ribbons/footers, anddeck_builder_chain_demo.py(#336, #337). - Examples:
deck_builder_chain_demo.py—suggest_outline→bg_remover→lint_deck→renderviaSkillContext(#337). - Skill (
optimization/context_optimizerv0.1.0): Query-aware extractive context selection — localfastembedchunk scoring againstagent_goal, traceablechunks_selected, fail-closedempty_result, and constitution-bound extractive-only output (#44). - Examples:
context_optimizer_demo.py,context_optimizer_chain_demo.py(firewall → optimizer), optionalcontext_optimizer_gemini_loop.py,context_optimizer_claude_loop.py(#44). - Skill (
finance/uk_companies_house_handlerv1.3.0): Phase v2c upgrade with deterministic matchers, filing helpers, and pagination controls — pure deterministic officer role matchers (officer_role) supporting 3 canonical categories (directors,secretaries,corporate) and 29 official Companies House statutory roles interminology_map.yamlwithout NLU in Python; case-insensitive officer name substring matching (officer_name/officer_filter); multi-page officer scanning up to 10 pages (1,000 records max) in 100-item chunks for filtered queries; deterministic filing history sorting descending by date; filing helperslatest_only: true(single most recent filing) andlatest_per_category: true(latest filing per category); direct host agentrun_pipelineorchestration with<from_resolve>parameter substitution for multi-intent queries, removing redundantmap_intentfrom manifest actions and agent directives; new decoupled composite actionresolve_company_officer(resolve company -> halt onneeds_inputif ambiguous -> filter matching officer(s) by role and/or name in one turn); active vs. resigned transparency and disclaimers in envelopes (active_only,matched_count,terminology_note); strict context isolation preventing sticky filter contamination across turns (#310, #220).
- Docs: Terminology pass on current anatomy (Contract / Effect / Directive / Assurance / Presentation) — Skill bundle standard,
calling agent→ host agent, trust-model “Most operators”, README domain wording, MiCA example “Available tools”; tests/CI use placeholder names instead of dummy (#252). - Docs (
context_optimizer): Catalog execute snippets use a tight token budget so copy-paste runs demonstrate selection; card UI fixture aligned to sample policy;optimize_document_contextnamed chain in.skillware.yaml.example(#44). - Docs: Revamp skill trust model — trust-forward operator guide aligned with secret providers,
SkillContext, doctor/paths tooling, and untrusted-input chains; soften README and usage index credential callouts. - Docs: Add host-context guidance for choosing full Directives, brief registry lines, and host-managed progressive loading (#348).
- Core:
SkillContext.tools("bedrock")exposes Bedrock Converse tool specs for multi-skill hosts (#262). - Skills: Bundled skills with
env_varsnow useself.credential()for config-first secret resolution (#39).
- Skill (
finance/uk_companies_house_handlerv1.3.0): Excised redundantmap_intentaction, internal helper methods (_map_intent,_normalize_keyword,_lookup_terminology), andintent_to_actionfromterminology_map.yamlin favor of direct host agentrun_pipelinestep composition (#220).
- Skill (
finance/uk_companies_house_handlerv1.3.0): Officer name filtering (officer_name) matches all word parts across candidate name, deterministically resolving natural order ("Firstname Lastname") vs UK registry inverted order ("SURNAME, Firstname") (#220). - Skill (
finance/uk_companies_house_handlerv1.3.0):run_pipelinehalts<from_resolve>substitution upon encountering subsequent company resolution steps, preventing cross-company parameter corruption in multi-company pipelines; contextcompany_nameinheritance guarded against mismatched company numbers (#220).
- Tests: Five-provider Usage Examples guard in
tests/test_skill_docs.py— every catalog page must expose Gemini, Claude, OpenAI, DeepSeek, and Ollama snippets withload_skillandskill.execute(#104). - CLI:
skillware theme [pastel|ocean|mono]subcommand — set or interactively choose the global presentation theme;--helptopic index now includes Context, Chains, and Theme alongside existing groups (#335). - Skill (
creative/deck_builderv0.1.0): Deterministic Microsoft PowerPoint (.pptx) presentation assembly from structured JSON deck specifications — 10 slide layout types (title, section, bullets, two-column, image, image with caption, quote, table, chart, blank), 3 bundled 16:9 widescreen master templates (pitch, corporate, minimal), theme token customization, pre-flight validation with soft-limit truncation warnings, directory traversal defenses, and inspection actions (#276). - Skill (
data_engineering/semantic_web_proxyv0.1.0): Semantic web proxy that reduces a live page or raw HTML to token-efficient Markdown, plain text, or JSON via trafilatura — boilerplate, script, and navigation stripping, opt-in comment threads, document metadata, estimated token savings with optional context-window share, an SSRF guard that re-validates every redirect hop, and apage_likely_requires_javascriptwarning instead of a silently empty payload for client-rendered pages (#42). - Examples:
semantic_web_proxy_demo.py— offline fixture-backed demo of boilerplate stripping, comment inclusion, the render warning, and the SSRF guard (#42). - Examples:
claude_uk_companies_house_handler.py— interactive UK Companies House v1.2.1 Claude loop with multi-turn tool chaining and disambiguation hints (#346). - Scripts:
uk_companies_house_host_simulation.py— maintainer stress harness for host/Gemini/Claude NLP loops against live Companies House API (not run in CI).
- Core: Sanitize registry IDs in
SkillLoader.to_claude_tool()so Claude API tool names match the^[a-zA-Z0-9_-]{1,128}$pattern (#104). - Examples: Claude demo scripts match
SkillLoader.to_claude_tool()names instead of raw manifest IDs (#104). - Docs: Align Claude tool-name guidance in
agent_loops.mdandcli.mdwith sanitized adapter names (#104). - CI: Format
tests/test_extras_sync.pywith Black after the install-extras guard landed (#340 follow-up).
- Skill (
finance/uk_companies_house_handlerv1.2.1): Stabilization upgrade for multi-turn agent loops — single-step stack pop execution forrun_pipeline(steps.pop(0)) preserving turn-level steering and intermediate visibility; in-flight<from_resolve>parameter substitution across remaining steps; decoupled composite actions (resolve_and_get_officers,resolve_and_get_filings) executing directly without wrapping_run_pipelineand skipping profile fetch whencompany_numberis already known; breaking rename ofmap_intentoutputsuggested_pipelinetostepswith parameter merging viaaction_params; removed hallucinatedsnippet_typefrom_resolve_companycandidate parsing; strictstatus: "partial"lifecycle reserved exclusively for in-flightrun_pipelinecalls with remaining steps (standard 10-item previews returnready); sanitized session context to lean keys (company_number,company_name,last_action,selected_transaction_id) dropping persisted filter hints; excised deprecatednext_actionsenvelope field; directive expanded for empty registry rows and mandatory user-facing replies;agent_hinton emptyofficers[]/filings[](#341, #346). - Docs (skill catalog): Backfill runnable five-provider agent loops on all catalog pages — including
gmail_handler,semantic_web_proxy, and stub Ollama sections — aligned withdocs/usage/skill_usage_template.md(#104). - Docs (
install_extras.md): Backfilldeck_builder,gmail_handler, and[all]package rows; add CI guard comparing the install guide topyproject.tomloptional-dependencies. - Docs (skill catalog): Skill history sweep — merge SHAs for
deck_builderandsemantic_web_proxy,#345rows for Gemini 3.5 bumps (mica_module,tos_evaluator,mental_coach,synthetic_generator,token_limiter). - Docs / examples: Default Gemini model IDs migrated from 2.5 Flash / Flash-Lite to
gemini-3.5-flashandgemini-3.5-flash-liteacross catalog pages, runnable examples, skill defaults, anddocs/usage/gemini.md(#265). - Docs / examples: Default Claude Haiku snippets migrated to
claude-haiku-4-5-20251001across catalog pages,docs/usage/claude.md, andexamples/claude_token_limiter.py;model_pricing.jsonupdated (#346). - Docs (
uk_companies_house_handler): Rate-limit links, agent-loop host guidance, multi-turn Claude snippet; UK pipeline/composite patterns moved from genericagent_loops.mdto the catalog page; generic multi-turn guidance only inagent_loops.md(#346). - Examples: Gemini/Claude UK Companies House loops use
bundle["class"]()and printneeds_inputdisambiguation hints (#346). - Skills (
compliance/tos_evaluator,compliance/mica_module,wellness/mental_coach,data_engineering/synthetic_generatorv0.1.1): Default Gemini evaluator / generator model IDs updated to 3.5 Flash / Flash-Lite (#265). - Skill (
monitoring/token_limiter):model_pricing.jsonupdated with Gemini 3.5 Standard-tier list prices (Sep 2026) (#265). - CLI: Brief
skillware --helptopic list aligned with Context, Chains, and Theme command groups (matchingdocs/usage/cli.md) (#335). - Security: Bump support windows —
>= 0.5.5patched,0.4.6–0.5.4silent (no security fixes),< 0.4.6unsupported with CLI advisory (SECURITY.md,version_policy.py).
- Core:
SkillContext— one-line registry host context with discovery filters, progressiveprepare()/execute(), and provider tool adapters (#330). - Core: Named skill chains —
chains:in YAML,run_chain(), stepwhen:conditional skip,skillware chain list|show|validate|run|dry-run, andskillware context show(#330). - Docs: Skill chaining and registry context — closes #297; implements #330.
- Examples:
skill_context_gemini_loop.py(SkillContext+ Gemini),sanitize_input_chain_demo.py(run_chainlocal);ollama_skills_test.pyrefactored to useSkillContext.
- Docs: SkillContext modes, edge cases, and Ollama multi-skill guidance in
skill_chaining.md,ollama.md,introduction.md,cli.md; one-line chain pointers on middleware skill catalog pages. - CLI: User-configurable
pastel,ocean, andmonopresentation themes; interactive menu selection persists globally, project config can override it, and unknown values fall back topastel(#248). - CLI: The mail submenu and direct mail commands now follow the active presentation theme (#248).
- Skill (
security/deceptive_ui_guardv0.2.0): Upgraded deceptive UI scanner with DOM zone classification (checkout, modal, cmp, navigation, general) and severity multipliers, KB allowlists (screen-reader accessibility, CMP consent banners, SEO metadata), expanded taxonomy (prechecked opt-ins, drip pricing, fake scarcity timers, nag loops), mobile profile heuristics, session fingerprint tracking, optional Playwright computed-style render diffing lane, and 23 golden HTML test corpus fixtures (#314, #327). - Security: Bump support windows —
>= 0.5.4patched,0.4.6–0.5.3silent (no security fixes),< 0.4.6unsupported with CLI advisory (SECURITY.md,version_policy.py).
- Examples: Derive agent-loop tool dispatch names from the loaded manifest in
claude_tos_evaluator.py,ollama_tos_evaluator.py, andollama_novelty_extractor.py(#178).
- Skill (
monitoring/kpi_gatev0.1.0): Deterministic business-KPI gate evaluating a metrics snapshot against an operator-maintained policy charter and optional versioned benchmark data — error/warning findings plus honestinsufficient_datarefusals with reason codes, fail-closed contract errors from a closed registry, stdlib-only validation, and the catalog/docs surface (#317). - Tests (
tests/test_examples_smoke.py): Added automated CI smoke test suite for local-execute offline demo scripts underexamples/, catching import regressions and SkillLoader dispatch errors without requiring live API keys (#237). - Docs (
docs/TESTING.md): Documented the example smoke testing layer and skip policy for live model provider loops in CI (#237).
- Docs (
README.md,docs/introduction.md): Refresh opening narrative, tighten Quick Start, shorten Gemini hero example (monitoring/token_limiter), rectangular How it works Mermaid, simplify introduction diagrams, remove legacy Body/Mind/Conscience aliases, and align Presentation (card.json) with registry bundle standard (#326). - Security: Bump support windows —
>= 0.5.3patched,0.4.6–0.5.2silent (no security fixes),< 0.4.6unsupported with CLI advisory (SECURITY.md,version_policy.py). - Docs: Document
issuer.orgdesign-ownership policy; align ARPA-driven registry skills (prompt_injection_firewall,bg_remover,novelty_extractor) and catalog Issuer lines (#295).
- Docs (
README.md,docs/introduction.md): How it works Mermaid — rectangularAnyHost["Any Host"]node aligned with Registry and Loader blocks (#326). - Tests: Isolate
pytest tests/from the operator's globalconfig.yamlvia autouseSKILLWARE_CONFIG_DIRintests/conftest.py; add configured-mode discovery and loader coverage alongside legacy-order tests (#302).
-
Skill (
security/deceptive_ui_guardv0.1.0): Deterministic deceptive UI surface scanner for web HTML — dual DOM vs visible extraction, structural/lexical heuristics, corroboration gates, trust score, and agent guidance for pre-click and pre-context guardrails (#78). -
Documentation: Skill catalog pages include a Version header and Skill history table (commit links, dates, versions, and linked GitHub contributor handles); docs/skills/README.md adds a Version column to category tables.
-
Tests:
test_catalog_pages_have_version_and_history_blocks()andtest_skill_library_index_has_version_column()intests/test_registry_docs.pyguard catalog version/history coverage. -
Skill (
finance/uk_companies_house_handlerv1.2.0): Phase v2b upgrade —run_pipelinefor sequential multi-step execution with automatic halting onneeds_input(disambiguation) orerror, step-slicing resumption (steps[prior_completed:]), placeholder auto-substitution (<from_resolve>), and cumulative data payload merging (#220). -
Skill (
finance/uk_companies_house_handlerv1.2.0): Composite actionsresolve_and_get_officersandresolve_and_get_filingsto resolve companies and fetch target records in single-turn operations (#220). -
Skill (
finance/uk_companies_house_handlerv1.2.0): Default limit 10 previews withpartialresponse status andagent_hintmetadata for officers and filing history (#220). -
Skill (
finance/uk_companies_house_handlerv1.2.0): Session context carry-forward across sequential turns (company_number,company_name,role_hint,officer_filter,next_actions) (#220). -
Documentation:
docs/skills/finance/uk_companies_house_handler.md— updated architecture reference for 9 action handlers, partial response previews, and pipeline orchestration (#220). -
Tests: Expanded unit test suite in
skills/finance/uk_companies_house_handler/test_skill.pycovering pipeline resumption, composite actions, partial previews, map_intent guards, and punctuation-safe queries (#220).
- Skill (
security/deceptive_ui_guardv0.1.0): Production deception lexicon with taxonomy metadata and eight categories; standalone agent instructions; demo fixtures recreating documented dark patterns;install_extrassecurity category row (#78). - Docs: Updated contributor instructions guidance in
CONTRIBUTING.md,ai_native_workflow.md, andtemplates/python_skill/to emphasize concise, append-only skill context over persona starters (#258, #284). - Docs: Aligned
ai_native_workflow.mdandtemplates/python_skill/README.mdchecklists with catalog Version and Skill history requirements. - Meta: GitHub issue templates refreshed for v0.5.1 CLI (
doctor,config show, paths/mail submenus) andoffice/gmail_handlerfiling paths; label taxonomy adds all registrycat: <category>labels (shared pastel color) so category filters never collide with repo-wide labels such assecurity(#294). - Skill (
finance/uk_companies_house_handlerv1.2.0):get_officersdefaultactive_onlyis now true (v1.x default was false) — resigned officers are excluded unlessactive_only: false(#220). - Skill (
finance/uk_companies_house_handlerv1.2.0): Removed conversational prefix stripping from composite actions; agents must pass cleanquery/company_queryplus optionalrole_hint.map_intentreturnsneeds_inputwhen a company name is required but missing (#220). - Skill (
finance/uk_companies_house_handlerv1.2.0):map_intentwiresdocument_types,entity_types, andstatus_mappingsfromterminology_map.yamlintoterminology_mapoutput; richeragent_hinton rate-limit, timeout, and connection errors (#220). - Documentation:
skills/finance/uk_companies_house_handler/instructions.md— skill-context instructions, disambiguation playbook, and parameter-hygiene guidance aligned with #258/#284 (#220). - Examples:
examples/uk_companies_house_handler_demo.pyand shared helpers updated for v2b composites, pipelines, partial previews, and disambiguation resume (#220).
- Meta: Shorten
cat: securitylabel description to fit GitHub's 100-character limit; enforce max length in label sync and tests.
- Skill (
office/gmail_handlerv0.2): Reply signature parity, preview metadata (signature_applied,signature_source,signature_profile); attachment list onread_message,download_attachment, and outbound send/reply attachments via flexible paths (local,file://, HTTP(S), optional cloud URIs with fsspec); multi-profile signatures viamail.signaturesandskillware mail signature profiles|add-profile|set-profile(#293). - Config: Top-level
mail:section in.skillware.yamland globalconfig.yaml— address book path, plain-text signature (inline or file), scan state, and send ledger paths foroffice/gmail_handler(#292). - CLI:
skillware mailsubmenu — address book init/show/validate/set-path/add; signature init/show/set/validate/clear; default HTML signature with Skillware logo (40px) and links; interactive menu option7/mail(#292). - CLI:
skillware config showdisplays merged resolvedmail.*settings including signature source (#292). - Skill:
office/gmail_handlerreads signature from merged config when skill-localdefault_signature_plainis unset; shipsdata/config.yaml.example(#292). - Documentation:
docs/skills/office/gmail_handler.md— attachments, multi-profile signatures, untrusted attachment disclaimer;docs/usage/cli.mdanddocs/usage/api_keys.mdupdated (#293). - Packaging: PyPI metadata —
keywords, expandedclassifiers(development status, intended audience, Python 3.10-3.12, AI and library topics), andDocumentation,IssuesandChangelogentries in[project.urls]. Metadata only; wheel contents are unchanged (#299).
- Packaging: PyPI
Homepage→https://skillware.site; canonicalARPAHLScasing on GitHub URLs in[project.urls](release chore).
- Meta: Removed maintainer-only GitHub release draft (
.github/RELEASE_v0.4.9.md); useCHANGELOG.md+ GitHub Releases UI instead (#290).
- Skill:
office/gmail_handler— deterministic Gmail IMAP/SMTP handler for agent mail workflows: recipient resolution via editable address book, preview/confirm send and reply, inbox search/read, sent-folder and send-ledger search, scan cursor, and context carry-forward (#208, #291). - Examples:
examples/gmail_handler_demo.py— mocked resolve, preview, search, and read flow (no live Gmail credentials);examples/gemini_gmail_handler.py— interactive Gemini tool loop (demo mode viaGMAIL_HANDLER_EXAMPLE_DEMO=1). - Documentation:
docs/skills/office/gmail_handler.md— integration guide, env setup, action reference, and address book schema. - CI:
tests/test_registry_identity.py— CI guard asserting every registry-layout skill'smanifest.namematches its path-derived registry ID and that all manifest names are globally unique (#280, #288).
- Documentation: README, introduction, vision, skill trust model, and CLI usage docs — clarify legacy vs config path resolution, tier order, and that bundled registry skills remain available without a local
skills/tree (#289).
- Config: Persistent YAML configuration (global
config.yamland project.skillware.yaml);pathssection drives skill root discovery when present; bundled registry always included (#246). - CLI:
skillware config showprints merged configuration (read-only);skillware pathstips updated for config files (#246). - CLI: Interactive paths submenu (menu
4) — view bundled registry, persist project/external paths to.skillware.yaml, shadowing and flat-layout diagnose; tiered help topics (menu6); universal navigation (0exit,bback); doctor spinner while diagnosing (#247). - Loader:
SkillLoader.load_skill(..., execute_module=False)inspect-only load (manifest, instructions, card, requirement pre-flight) without executingskill.py; clearerImportErrorwhenskill.pyimport fails after pre-flight (#235). - CLI:
skillware doctorchecks manifest deps andskill.pyimport readiness per skill (DEPS/LOADtable); optional skill ID,--category, and--skills-root(#235).
- CLI:
skillware examplestable — wider EXTRA column; GITHUB shows script filename as a clickable link (full URL on ctrl+click) (#247). - CLI: Interactive menu option
6description reflects grouped help topics (#247). - Loader: Skill-not-found errors list searched roots with tier labels (
project,external,bundled) (#247). - Loader:
SkillLoader.load_skill()validates manifestrequirementsversion specifiers (for exampleweb3>=6.0.0) against installed package versions before loadingskill.py; unpinned entries still require importability only (#14). - GitHub: New Skill Proposal template category dropdown synced with the registry (
creative,security); addedcreativelabel (#279, #277).
- Skill:
security/prompt_injection_firewall— offline-only deterministic pre-flight scanner (no LLM path) with localkb/detectors for hidden text, Unicode/confusable evasion, nested encodings, instruction overrides, corroboration-based sensitivity, and sanitization output (#46). dev_tools/issue_resolver: Caller-fetchedISSUE_RESOLVER.mdrepository profiles — ordered profile discovery URLs,load_repository_profileparsing with provenance-labelled context, profile standard doc, and Skillware dogfood profile under.github/ISSUE_RESOLVER.md(#145, #271).- Documentation:
docs/contributing/issue_resolver_profile.md— normative contract and examples for repository-maintained agent context files.
creative/bg_remover: Hardened to v0.2.0 — rembg session reuse, Base64 and file validation, 25 MB limit, path traversal rejection, parent directory creation foroutput_path, demo script, and expanded bundle tests (#257, #268).dev_tools/issue_resolver: Profile discovery prefers.github/ISSUE_RESOLVER.mdover a repo-root fallback; expanded Skillware dogfood profile aligned with contributor workflow and stage gates.- Version policy: Raise security support floor to
>= 0.4.7; legacy band0.3.5–0.4.6(upgrade recommended, silent CLI); unsupported advisory for installs below0.3.5.
- Citation: Root
CITATION.cffand README Citing section for formal software citation; first Zenodo-archived GitHub release (#269, #270).
- Documentation: OpenAI-compatible host guide and runnable Groq example covering shared
to_openai_tool()usage, provider base URLs, credentials, and local servers (#261). - Framework:
skillware/core/ui_schema.pyhelpers to resolve dot paths and validate output-card field keys (#199). - CI: Parametrized guard
tests/test_card_ui_schema.py— every registry skill with output-cardui_schemamust ship a fixture undertests/fixtures/card_ui_schema/whose samples cover all field keys (#199).
compliance/mica_module,compliance/pii_masker: Aligncard.jsonoutput fields with actualexecute()return shape (#199).
finance/wallet_screening: Paginate Etherscantxlist(up to 10k normal txs) and surfacemetadata.warningswhen history is truncated or unavailable; bump skill version1.0.0→1.0.1(#214, parent #115).- Skills (finance/uk_companies_house_handler): Completed Phase v2a upgrade (#220). Added
contextparameter to carry forward session state (company_number,company_name,officer_filter, etc.). Addedpartialenvelope status and optionalpipelinestate to support paused multi-step pipelines (noted as v2b prep in instructions). Updated_get_officersto fallback tocompany_namefrom context and added tests for fallback logic. Updatedexamples/gemini_uk_companies_house_handler.pyinto a fully interactive chat loop. - Documentation: CONTRIBUTING and contributor workflow checklists — update
card.jsonand output fixtures together when changingexecute()output (#199).
- Added
creative/bg_remover, an offline background removal skill powered by rembg (#196). - Packaging: Category, per-skill, and
[all]optional extras generated from skill manifests viascripts/sync_extras.py; hand-maintaineddev, SDK extras, and meta[agents](#236). - Documentation: Install extras — canonical guide for
pip install skillware[...]targets (#236). - Framework:
skillware/core/extras.pyand richerImportErrorhints fromSkillLoaderwhen manifest requirements are missing (#236). - CI: PyPI wheel packaging smoke test — builds a wheel, installs it in a fresh venv (base deps only), and verifies every bundled registry skill is present and loadable via
scripts/wheel_smoke_test.py(#182). - Documentation: Cross-linked wheel-smoke CI job in
CONTRIBUTING.mdanddocs/contributing/ai_native_workflow.md(#182). - CLI:
skillware pathsshows skill root resolution order (external → project → bundled), tier labels, shadowing summary, and operator tips; interactive menu option4wired (#81). - Framework:
skillware/core/discovery.py— shared skill root discovery forSkillLoaderand the CLI (tier labels, shadowing, registry ID listing; foundation for config-driven paths in #246). - Framework:
BaseSkill.validate_params()— optional helper to validate tool arguments against manifestparametersJSON Schema; raisesSkillwareParamValidationErroron mismatch. Not called automatically by the loader orexecute()(#125). Reference:examples/claude_wallet_check.py,examples/gemini_tos_evaluator.py. - Framework: Registry manifests standardize on
outputs:(legacy singularoutput:removed fromfinance/wallet_screening) (#125).
- Framework: Map manifest requirement
pillowto import namePILinSkillLoaderdependency checks (#196). - Packaging (breaking): Removed legacy extras
cli,embeddings;[all]is skill runtime deps only (not SDK packages). Use[agents]for Gemini + Claude + OpenAI SDK deps (#236). - CLI:
skillware listprints a pointer to the install extras guide (#236). - Documentation: README, CONTRIBUTING, TESTING, skill catalog pages, and examples index updated for the new extra taxonomy; every skill doc recommends its per-skill extra (#236).
- Framework:
SkillLoaderdelegates root resolution todiscovery.get_skill_roots()so load, list, test, andpathsuse the same order (#81). - CLI: Help and menu list
pathsas available (no longer “coming soon”) (#81). - Documentation: README — trim redundant Contributing cross-links, add
skillware pathsto install verification, and link the skill trust model in the docs table; cross-linkskillware pathsindocs/introduction.mdanddocs/usage/README.md. - Documentation: Add operator expectations (bundled vs external, out-of-band changes, where to report issues) and an instruction-only content note to
docs/security/skill-trust-model.md; add trust-model cross-links from README configuration and CONTRIBUTING Skill Package Standard (#243).
- Framework: Added
_sanitize_gemini_tool_name()toskillware/core/loader.pyto explicitly map provider tool naming constraints. - Tests: Added
test_sanitize_gemini_tool_name()totests/test_loader.pyto verify safe translation andtest_skill_docs_gemini_anti_patterns()totests/test_registry_docs.pyto enforce documentation hygiene by preventing manual tool wrapping and mutation anti-patterns in skill catalog pages. - Documentation: Added canonical dispatch guidelines to
docs/usage/gemini.mdanddocs/usage/skill_usage_template.md. - Documentation: Category selection guidance for contributors; issue-first policy for new top-level folders in
CONTRIBUTING.md(#204).
- GitHub: Overhauled issue templates (CLI, Skill Upgrade, Examples, Packaging), issue chooser
config.yml, PR template, and label taxonomy with pastel colors; labels sync automatically from.github/labels.jsonvia CI on merge tomain(#227). - Framework:
SkillLoader.to_gemini_tool()now returns agoogle.genai.types.Toolobject instead of a raw dictionary, ensuring compatibility with thegoogle-genaiSDK when passing tools toGenerateContentConfig. - Tests: Updated
tests/test_loader.pyto assert against the properties of thegoogle.genai.types.Toolobject forto_gemini_tool(). - Documentation: Updated Gemini integration snippets across all skill catalog pages and
introduction.mdto reflect theto_gemini_tool()API change and correct tool name sanitization. - Documentation: Aligned
agent_loops.mdandcli.mdwith Gemini sanitized tool-name dispatch after #229 (#230 follow-up). - Examples: Removed manual
types.Toolwrapping, and consistently utilizeSkillLoader._sanitize_gemini_tool_name()for derived tool names in gemini examples.
- Framework:
SkillLoader.to_gemini_tool()returned a plain dictionary instead ofgoogle.genai.types.Tool, causing runtime failures when passed toGenerateContentConfig(tools=...)with thegoogle-genaiSDK. Fixes #223.
- CLI: Interactive splash — correct SKILLWARE ASCII logo, Rich 3-stop gradient on logo and tagline (
#D4E4F1→#79B6D8→#EBD8DC), shared_package_version_str()for splash and--version, taglineSkillware v{version} — Skill Management Framework(#222). - Documentation: Compact architecture Mermaid diagrams — shorter README labels, model-agnostic adapter nodes in introduction, horizontal agent-loop layout with role table (#210 follow-up, #221).
- Documentation: Docs sweep — README Mermaid Registry alignment;
vision.mdpinned to v0.4.x; skill catalog and usage guides preferbundle["class"]()with explicitbundle["module"].ClassName()noted as still supported (#225).
finance/uk_companies_house_handler: New skill for UK Companies House REST API — deterministic company search, profile, officers, PSC, filing history, and intent-to-operation mapping with UK corporate terminology translation; bundled endpoint index and terminology map; status-based response envelope (ready/needs_input/error) with disambiguation support (#172, #218).- Documentation: Add
docs/security/skill-trust-model.mddocumenting the skill execution model, on-disk resolution order and shadowing, provenance tiers (Bundled / Project / External), and operator security guidance; wire links from SECURITY, usage, CONTRIBUTING, and CODE_OF_CONDUCT (#109). - Documentation: Add minimal Mermaid architecture flow diagrams to README, introduction, and agent loops; cross-links, Step 1 mini-pipeline, adapter fan-out, and direct-path footnotes (#210, #217).
- Loader:
SkillLoader.load_skill()auto-discovers the singleBaseSkillsubclass in eachskill.pyand exposes it asbundle["class"];get_skill_class()helper added. Existingbundle["module"]usage is unchanged (#89). - Loader:
SkillLoader.load_skill()validates thatmanifest.yamlnamematches the path-derived registry ID forcategory/skill_namelayouts; emitsSkillwareIdentityWarningon mismatch (warn-only v1). Flat private skills under a skill root are unchanged. Bundles now include optionalregistry_id(#200). - Version policy: Raise security support floor to
>= 0.3.5, legacy band0.3.0–0.3.4(silent CLI), unsupported advisory for installs below0.3.0(#192). - Documentation: Clarify skill ID vs manifest
namevs provider tool names indocs/usage/cli.md,docs/usage/agent_loops.md, anddocs/introduction.md; require full registry IDs in CONTRIBUTING manifest standard (#201).
office/pdf_form_filleranddefi/evm_tx_handler: Alignmanifest.yamlnamewith registry paths (office/pdf_form_filler,defi/evm_tx_handler); update examples and docs to use manifest-derived tool dispatch (#201).
monitoring/token_limiter: New monitoring skill that evaluates cumulative token usage and returns CONTINUE, WARN, or FORCE_TERMINATE for autonomous agent loops; bundled indicative model pricing, ROI scaffold fields for v2, local and provider loop examples (#23, #207).- New
monitoringskill category in CONTRIBUTING,ai_native_workflow.md, anddocs/skills/README.md. - Tests:
tests/test_registry_docs.py— CI doc-drift guards that verify skill catalog, examples index, and agent-loops reference matrix stay in sync with the registry (#183, #189). - Documentation: Cross-linked
tests/test_registry_docs.pyinai_native_workflow.mdandCONTRIBUTING.mdso contributors know doc-drift guards run in CI; added explicit PR checklist reminder inCONTRIBUTING.md(#193, #197).
- Documentation:
docs/skills/monitoring/token_limiter.md— budget disclaimer callout, limitations clarity, and enterprise disclaimer (#23). - Documentation: README Stats section and live PyPI download badges (pepy / PyPI Stats dashboards, header
DLs ↓total) (#198). - Documentation: Aligned CLI and examples docs (
docs/usage/cli.md,examples/README.md,docs/vision.md,README.md) with theskillware test/skillware examplesbehavior (#191, #194).
- CLI:
skillware examplesandlist --examplesfetchexamples/README.mdfrom GitHub when no local copy is found (pip installs and directories outside a checkout).
- Tests:
tests/test_skill_issuer.pynow requirestest_skill.pyfor every registry skill underskills/(#160). - Documentation: Clarified that bundle tests must mock network calls and model downloads in CI (#170).
- Documentation: Added a Status section to TESTING.md summarizing the current testing model (#179).
- Documentation: Post-release alignment — category tables, Python 3.10+ badge, dev install (
[dev,all]vs[dev]), README configuration via.env.example, DeFi env vars in.env.example, framework env vars in api_keys.md (#154).
- CLI:
skillware testruns bundle tests via pytest — all roots, by skill ID, or by--category; supports-vand--no-header. Documented in cli.md, TESTING.md, and contributor guides (#83). - CLI:
skillware list --examplesshows per-skill example script counts;skillware examples [skill_id]lists indexed runnable scripts fromexamples/README.mdwith GitHub source links; interactive menu option examples (#126).
wellness/mental_coach: Deterministic wellness coaching firewall with crisis triage, hard scope limits, embedded public KB, optional Gemini scope evaluator, and catalog documentation (#148).
- Tests: Moved
tests/test_mica_module.pytotests/skills/compliance/test_mica_module.pyso maintainer skill tests follow thetests/skills/<category>/layout;tests/root is framework-only (#86). wellness/mental_coach: Set real issuer contact email and add health disclaimer on the catalog page (PR #174 follow-up).
finance/wallet_screening: Align examples and docs withfinance/wallet_screeningmanifest tool name; fixgemini_wallet_check.pyandclaude_wallet_check.pyto match tool name dynamically from manifest; correctcard.jsonUI fields to match actual skill output schema; updateinstructions.md, provider snippets, Data Schema, and usage docs (#173).
- Tests: Backfilled
test_skill.pyfor six registry skills (mica_module,pii_masker,synthetic_generator,wallet_screening,pdf_form_filler,prompt_rewriter); all registry skills now ship co-located bundle tests. Fixedprompt_rewriterpackage export so pytest can collect the bundle (#158). - CLI:
skillware/__main__.pyenablespython -m skillwareas a fallback when theskillwarecommand is not on PATH (#135). Addedcmd_help()for rich-formatted help, wired toskillware --help/-hand interactive menu option4. Added--version/-Vflag.
novelty_extractor: Bundle tests mock fastembed embeddings so CI avoids HuggingFace downloads and rate limits (#159 follow-up).finance/wallet_screening:WalletScreeningSkill.manifestloadsmanifest.yamlfrom the bundle directory (#165).
- CI: GitHub Actions runs
pytest skills/thenpytest tests/after lint (bundle + framework/maintainer tests; closes #90) (#159). - CI: CodeQL GitHub Action upgraded from v3 to v4.
- Dependencies: Extended
[all]with registry skill runtime deps (web3,fastembed,numpy); added[defi]and[embeddings]optional extras. Documented manifest ↔pyproject.tomlconvention in CONTRIBUTING and TESTING.md. - Documentation: TESTING.md, CONTRIBUTING.md, ai_native_workflow.md, and README architecture tree document the bundle / framework / maintainer / example testing model. Pytest collects
tests/andskills/only (examples/ignored). - Dependencies: Moved
rich>=13.0from[cli]extra to core dependencies; CLI is now available immediately afterpip install skillware. The[cli]extra is kept as an empty deprecated alias for backward compatibility (#135).
defi/evm_tx_handler(#142): Structured EVM agent wallet skill on Ethereum and Base —resolve, Uni V2quote/preview/execute(approve + swap),transfer,balances,wallet_info, YAML registries, optional CoinGecko USD preview,max_trade_usdfail-closed cap, balance pre-flight checks, and mocked Web3 tests. Examples:examples/gemini_evm_tx_handler.py,examples/claude_evm_tx_handler.py.
- CI: GitHub Actions installs from
pyproject.tomlonly (pip install -e ".[dev,all]"); runsblack --check,flake8, thenpytest tests/(#151, #153). Co-locatedskills/**/test_skill.pyremains a local pre-PR step. - Documentation: COMPARISON.md and README updated for Agent Skills (SKILL.md) and fairer MCP framing (#123); TESTING.md and CONTRIBUTING.md aligned with CI and Black gate (#151, #153);
defiskill category added to CONTRIBUTING.
dev_tools/issue_resolver: Replaced wide emoji regex in commit-message validation with explicit Unicode ranges (CodeQLpy/overly-large-range, #146).
dev_tools/issue_resolver: GitHub issue workflow with sequential stage checklists, conditional verify/commit gates, and commit-message validation (#143).- Examples:
gemini_issue_resolver.py,claude_issue_resolver.py, andollama_issue_resolver.pyfordev_tools/issue_resolver(#118). - Version policy:
skillware/version_policy.pywith supported-version thresholds; CLI prints one dim stderr advisory only for installs below0.2.6(#132). - Tests:
tests/test_version_policy.pyfor advisory thresholds, opt-out, and CLI hook (#132). - Documentation: Added docs/vision.md with project story, roadmap, and agent discoverability (#133).
finance/wallet_screening: Unified TRM/scam transaction risk index for analysis (#140).- SECURITY.md: Supported-version table aligned with
>= 0.3.1security support and unsupported< 0.2.6band (#132). - CLI: Calls version advisory once at
main()startup, not on menu re-loops (#132). - Dependencies: Added
packagingfor semver comparisons (#132). - Documentation: README Mission links to vision.md; wallet screening comparison table lives in COMPARISON.md; docs table and cross-links updated (#133).
- Changelog: Added root
CHANGELOG.mdfollowing Keep a Changelog, with retrospective release history from v0.2.0 and a README nav link (#108). finance/wallet_screening: FTM publicKey matching and an ETH sanctions index (#128).
- CLI: Visual redesign for
skillware list, including pastel table,short_descriptioncolumn, interactive splash, and menu (#129). - CLI: Interactive polish - splash footer links, menu re-loop, stub labels for #81 / #83, width-aware table, shared terminal context (#130, #131).
- Contributing: Aligned Code of Conduct, CONTRIBUTING, agent workflow, and PR template for CHANGELOG maintenance and co-authoring rules (#124).
- Documentation: README documentation table and
docs/introduction.mdlink toCHANGELOG.md; contributor template documents optionalshort_description(#130).
- Novelty Extractor Skill: Introduced the
data_engineering/novelty_extractorskill (#116, fixes #24). - Examples Index: Added
examples/README.mdto serve as the canonical index of runnable provider scripts (#107).
- SDK Migration: Migrated framework and examples from
google-generativeaito the newgoogle-genaiSDK (#97) and updated all usage documentation snippets (#92). - Documentation: Improved README navigation and overall skill catalog discoverability (#98).
- Documentation: Cross-linked runnable examples directly on skill catalog pages (#121) and synced
agent_loops.mdwith the central examples index (#122).
- CLI Tool: Introduced the
skillwarecommand-line interface, starting with theskillware listcommand for skill discovery (implemented by contributor @rizzoMartin) (#84). - CLI Features: The
listcommand prints a rich table of locally installed skills and supports filtering via--category,--issuer, and--skills-rootflags. - Optional Extras: Added optional dependency groups in
pyproject.toml([cli],[gemini],[claude],[openai],[office],[all],[dev]) so users only install the SDKs their specific skills require (#87).
- Leaner Core Install: Removed heavy SDKs (
anthropic,google-generativeai,pymupdf,openai) from the default installation, reducing core requirements to justrequests,pyyaml,python-dotenv, andbeautifulsoup4(#87). - Dependency Management: Consolidated dependency management entirely into
pyproject.toml. - Requirements File: Transformed
requirements.txtinto a dev-convenience pointer (runningpip install -e ".[dev,all]") rather than a duplicate flat dependency list.
- Issue Resolver Skill: Introduced the
dev_tools/issue_resolverskill for universal GitHub issue analysis and resolution (#56).- Validates and normalizes any public GitHub issue URL and returns a structured payload containing pre-computed GitHub API and raw content URLs.
- Guides calling agents through a 5-stage workflow (fetch issue, read repo context, analyze files, produce a ranked plan, implement after approval).
- Includes optional
github_tokenandextra_instructionsparameters. - Compatible with all five provider adapters (Gemini, Claude, OpenAI, DeepSeek, Ollama).
- Requires no network calls itself and has no runtime dependencies beyond PyYAML.
- Dev Tools Category: Introduced the new
dev_toolsskill category.
- Skill Catalog Revamp: Overhauled all pages under
docs/skills/to include a breadcrumb trail, per-provider Usage Examples, environment variable tables linking to the API keys guide, data schema blocks, and a limitations section (#82). - Documentation Polish: Removed emojis from all catalog pages and the main skills README index (#52).
- Metadata: Corrected the author name in
pyproject.tomlfromARPA Hellenic Logic SystemstoARPA Hellenic Logical Systems.
- Packaging: Full skill bundles on PyPI. Wheels now include
manifest.yaml,instructions.md,card.json, and skill data files, rather than only.pymodules. - Packaging: Configured
MANIFEST.into graft theskills/tree and updated[tool.setuptools.package-data]so new registry skills do not require per-skillpyproject.tomledits. - Registry: Added empty
__init__.pyfiles underskills/category packages (and skill folders where needed) to ensuresetuptoolspackages the complete tree. This requirement is now enforced in tests for new registry skills. - Documentation: Added a "Finding skills on disk" usage guide.
- Documentation: Added contributor notes for PyPI packaging in
CONTRIBUTING.mdand the skill template README.
- Skill Loader: Fixed skill resolution paths after
pip install(#13).SkillLoader.load_skill()no longer restricts searches tosite-packages/skills/. It now falls back through the following order:- An existing path on disk (absolute or relative)
- Roots defined in the
SKILLWARE_SKILL_PATHenvironment variable - A local
skills/folder in the current working directory (searching up to six parent directories) - Bundled registry skills shipped with the package (Note: If nothing matches, the error now explicitly lists the paths that were tried).
- Framework: Added OpenAI adapter (
SkillLoader.to_openai_tool()) for Chat Completions tool calling (#68). - Framework: Added DeepSeek adapter (
SkillLoader.to_deepseek_tool()) as a separate public API (#70). - Framework: Added shared function-name sanitization for OpenAI-compatible providers.
- Documentation: Added OpenAI and DeepSeek usage guides and corresponding integration examples (
examples/openai_tos_evaluator.py,examples/deepseek_tos_evaluator.py) (#69, #70). - Documentation: Added usage guides index, agent loops, and skill usage template (#71).
- Documentation: Added Usage Examples on all seven skill catalog pages (Gemini, Claude, OpenAI, DeepSeek, Ollama) (#71).
- Documentation: Added generic setup guide for API keys for skills (#67).
- Documentation: Added README links to usage index and agent loops (#71).
- Contributing: Added Agent Contribution Workflow, an agent-directed guide (#64, #65).
- Registry: Added Issuer attribution on all skills (
manifest.yaml,card.json,docs/skills/*.md, catalog) (#63). - Registry: Added Enterprise disclaimer on ARPA catalog skill pages (#59, #62).
- Tests: Added
tests/test_skill_issuer.pyfor registry issuer validation (#63).
- Documentation: Updated Ollama guide for current local models (#71).
- Contributing: Restructured
CONTRIBUTING.mdfor contribution types and skill standards (#64). - Contributing: Aligned the Usage Examples requirement in CONTRIBUTING and agent workflow (#71).
- TOS Evaluator Skill: Introduced the
compliance/tos_evaluatorskill for local-first website policy evaluation prior to automated access.- Checks
robots.txtpermissions for target URLs and user-agents. - Discovers candidate legal pages (Terms, Legal, Acceptable Use, API links).
- Extracts and evaluates policy clauses related to automated behaviors (scraping, crawling, indexing, monitoring, etc.).
- Returns structured verdicts (
SAFE,UNSAFE,CAUTION,INSUFFICIENT_EVIDENCE) alongside evidence payloads and next-step guidance. - Features an optional, provider-configurable low-cost LLM fallback for ambiguous clauses.
- Checks
- Skill Infrastructure: Added the complete package contents for the TOS Evaluator under
skills/compliance/tos_evaluator/(including manifest, logic, and instructions). - Testing: Added central tests (
tests/skills/compliance/test_tos_evaluator.py) and local skill tests. - Documentation: Added dedicated skill documentation (
docs/skills/compliance/tos_evaluator.md) and updated the central skill catalog. - Examples: Added integration scripts (
examples/gemini_tos_evaluator.py,examples/claude_tos_evaluator.py,examples/ollama_tos_evaluator.py). - Dependencies: Added
beautifulsoup4(bs4in the manifest) to the project for deterministic HTML parsing.
- MiCA Compliance Module: Added the
compliance/mica_moduleskill, featuring in-memory caching for ultra-low latency RAG (~1.7ms) and a weighted surgical router to prevent context window asphyxiation.
- Pure Cognitive Framework: Realigned all MiCA examples (Gemini, Claude, Ollama) to follow a prompt-based cognitive pattern that avoids opaque native tool-calling obstacles.
- Documentation: Comprehensive documentation updates for the new Compliance category and a refined core README.
- Quality Engineering: Resolved all PEP 8 and Flake8 violations across the registry and verified execution with 100% unit test success.
- Zero-Latency PII Masker Skill: Introduces the
compliance/pii_maskercomponent to act as a "Privacy Firewall", intercepting and scrubbing sensitive metadata (Names, Emails, Physical Addresses, Crypto Wallets) locally before external LLM dispatch. - Ollama Edge Interoperability: Leverages the 270M parameter
arpacorp/micro-f1-maskstructure for optimized, offline processing. - Dynamic Modalities: Added three processing modes for the masker:
mask: Preserves contextual entity tags (e.g.,[PERSON_1]).redact: Completely overwrites tokens with localized constants (xxxx).remove: Intelligently drops strings from the payload to decrease token size.
- Testing: Integrated rigorous Pytest mock structures intercepting the edge boundary.
- API Manifests: Rewrote API compliance manifest parameters to match the internal JSON Schema architecture.
- New Skill: Introduced the
data_engineering/synthetic_generatorskill for bulk-generating high-entropy synthetic training data to combat model collapse (Resolves #22). - Model Agnosticism: Added internal routing support for the synthetic generator to use
Ollama,Gemini, andAnthropic. - Zero-Dependency Entropy Scoring: Added a new
zlibcompression ratio heuristic to natively validate lexical entropy and block boilerplate outputs without heavy NLP dependencies. - New Documentation: Launched the
Data Engineeringcategory in the central skill registry along with comprehensive integration guides and integration scripts (examples/build_dataset_demo.py).
- Bug Fixes: Addressed all
flake8PEP8 linting issues across the module.
- Prompt Token Rewriter Skill: A new middleware skill (
optimization/prompt_rewriter) that heuristically compresses bloated prompts into fewer tokens, supporting low, medium, and high aggression levels. - Optimization Category: Established a new domain in the skill registry for architectural and operational efficiency tools.
- Skill Reference Card: Comprehensive documentation for the Rewriter at
docs/skills/optimization/prompt_rewriter.md. - Interactive Demo: Added
examples/prompt_compression_demo.pyfor offline testing of compression logic.
- Middleware Patterns: Updated the Gemini usage guide with "Skill Chaining" examples demonstrating the rewriter as an automated pre-processor.
- Standardized Manifests: Aligned all skill metadata with the new
parametersandconstitutionstandard.
- CI/CD Alignment: Fixed linting and formatting issues to ensure 100%
flake8compliance in core registry files.
- Consolidated and rolled forward into
v0.2.1.