chore: sync private v5.0.0 (a14d3cd) - #40
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
v5.0.0.sync/v5.0.0-a14d3cd.Release notes
Fixed
agent-kit cursor-awareness --check: walk up from--cwdto finddocs/cursor-native-audit.md(fixes false Missing inventory when the shell is underpackages/clior another nested path); consumer/missing-docs path returns an actionable--cwdhint. Native-audit Action table: A5 Done (rootAGENTS.mdpresent), A4 Partial with dual-lane next step, A7 Open with scoped multi-IDE next step; A6 unchanged.Pre-v5.0.0 evidence gate: R14-pair mid-batch monitors
plan-monitor-fix-staging-ci-and-queue-end-product-residuals.mdandplan-monitor-close-ship-5.0-npm-npx-install-residuals.mdwith_index.mdAudits rows and regeneratedocs/evidence/knowledge-classification.jsonsopnpm evidence:knowledge-classification:checkis green again (Still open A from ship-5.0 clean pre-git-prod gate).Pre-v5.0.0 tag gate: re-verify lint/typecheck/tests/deny-links/evidence/landing/Path-C-pack on staging
71dbbae; persist matrix atdocs/evidence/runtime/ship-5.0-pre-tag-green-gate-2026-08-12.md; R15 Closed-by A/B onplan-monitor-ship-5.0-clean-pre-git-prod-gate.md. No tag; no/git-prod.Landing closeout: factory CI runs
pnpm landing:build+landing:build:check; Align Closed-by pointer notes public LICENSE still pending/git-prod; R15 Closed-by appends on the five queue-end monitors (Design SoR re-absorb + clipboard success-path evidence still owed before next sync).Mission Control broadcast: live
missionkit.io/mc/open.htmlmatches repo harden (R1 verified by sha256);start-broadcastdegrades to LAN/token print when share encode rejects non-RFC1918 primary LAN (Tailscale 100.64/10); HTTP-level serve auth matrix covers/open+/open.htmlwithout token vs token-gated data.Mission Control preferred-browser residuals: CLI uses
resolveContextConfigPath; OS-default and fallback opens detect failure before claiming success; reject win32/cmdmetacharacters" % ^ ' = , +; expand hermetic which/win32 spawnSync tests; ADR trust-boundary + failure-honesty updated.Dogfood L0 nits:
/run-plan-allper-plan worker template states orchestrator already skimmed Unprocessed; drop inert PO dogfoodread_scopepaths; promote/continue-plandogfood preflight to its own hard stop (runs regardless ofexternalPlanReview.preflight); overlay hash set +2.Dogfood Unprocessed parser: accept markdown table rows and numbered list items; terminate the Unprocessed section on any
Processed Filesheading (stops mixed H2/H3 leaks).Knowledge-classification CLI: default to the handoff fixture and refuse baking live
.cursor/HANDOFF.mdinto the tracked ledger unless--allow-live-handoff(prevents repeated Evidence-check red after barenode …mjsregenerations).Staging Evidence checks: regenerate
docs/evidence/knowledge-classification.jsonviapnpm evidence:knowledge-classification(handoff fixture) and R14-pair five queue-end plan monitors plus_index.mdAudits rows soevidence:knowledge-classification:checkis green again.missionkit.io install / prompt copy CTAs: await clipboard writes, show honest failure UI (not optimistic ✓), and fall back to
execCommandwhen the Clipboard API rejects; decorative "Copy plan path" / "Copy /git-staging" mock buttons marked disabled. Built vialanding:build, deployed to Hostinger; Design SoR re-absorb notes inUPSTREAM-DESIGN-FIX-PROMPT.md.Mission Control preferred-browser residuals (A–H): validate
preferredBrowseras an app/binary name (reject path separators and shell metacharacters); attach spawnerrorhandlers and fall back once to the OS default opener with honest starter messages; alignstart-broadcast.mjspreference root withresolveSnapshotRepoRoot; sharenormalizePreferredBrowser/OS_DEFAULT_TOKENSwith the CLI; document per-platform values and factory/CLI-only/dashboard-broadcastslash; expand hermetic tests (win32,spawn-failed,invalid-url, fallback). Pack-gate hygiene I remains on broadcast F8. ADR2026-08-11_mission-control-preferred-browser.mdDogfood Broad Intake / sessionStart now accept consumer
## Unprocessed Filesas well as factory###(parser ends on same-or-higher heading);/dogfoodpins H3 on new consumer writes; ADR decision 2 append-only correction; bucket-count prose uses table-as-SoT (no hardcoded numeral);/run-plan-allorchestrator owns Unprocessed preflight (workers skip re-recite);docs/external-plan-review.mdBroad Intake row names the dogfood bucketCache lock release fail-closes when owner metadata is missing, unreadable, or mismatched (no longer deletes a successor's lock during the mkdir → owner publish window); owner.json is published via temp file + rename; install
RootRefusedErrormatches update (process.exitCode = 1+ return) so cleanup/finally stay reachableCrew Monitor structural pin (residuals E/F from
close-crew-glyph-avatar-still-open):expectBadgeIsRowSiblingBeforeActornow whole-template-counts${chipHtml}/ chip classes to zero and requires exactly one${badgeHtml}, closing the half-locked sibling gap left by the retired feed-label helper; empty-template assertion names thecrewMonitorRowRenderTemplatemarker for clearer diagnosticsnpm pack --dry-run --jsonnow receives clean JSON on stdout because the CLI dashboard prepack sync message is written to stderr.Close multi-workspace install isolation residuals D2/L1/L2/L4/P2/P3: mode-independent root guard for
--yes/$HOME///no-git+no-manifest with--force-rootescape hatch; cache lock ownership token (PID/UUID) with mtime refresh and ownership check before stale reclaim/release; hold cache lock across install/update/add/diff/contribute registry copy; refusedupdateexits non-zero;dashboard-broadcast.mdderivesMC_PORTfrom repo root;install.mdPort B notes chat-install Ask as theconfirmProjectRootequivalent. D3/L3/P1 were already fixed at HEAD (see.cursor/memory/plan-monitor-multi-workspace-install-isolation.mdClosed-by section).Close vscode-first-install dashboard onboard residuals C/E/K/J-vscode: skip-if-exists guard for
.vscode/settings.json,.github/copilot-instructions.md, and.vscode/security-review.agent.md; generated artifacts registered inprotectedPathsandPersonalizationResult.items;generator/vscode.test.tspins the guard;docs/getting-started.mdsplitsnpx -y(suppressesnpx's own confirmation) from CLI--yes/AGENT_KIT_YES=1(skips project-root prompt);terminal.test.tspinsisNonInteractivefor CI,AGENT_KIT_YES, andstdin.isTTY. A/B fixed at HEAD; D2 owned by multi-workspace plan; F/G/H/I out of scope.Close BIGFIX PTY monitor still-open residuals R1–R7:
buildjob checkout now usesfetch-depth: 0; risk-hotspot scorer no longer depends on a shallow-unresolvable git range; knowledge-classification--checkignores commit provenance fields; ledger census scopes to tracked paths; HANDOFF Gaps updated to honest red-build voice; behavioral tests added forwait_for_pty_progressbanner-baseline and deadline logic; liveness probe for cap/warn concurrent-arm refusal documented as backlogConfig persona Inherit default sends null to clear a stored mode override (guards merge delete path)
Overlay update: end-to-end ledger-absent evidence that known-shipped files refresh while customized peers stay preserved (
docs/evidence/overlay-update-preserve-refresh.md)SECURITY.md: private vulnerability reporting preferred first when enabled; public no-detail issue is fallback; PVR enable remains repo-admin HITL
CLI welcome helmet outline uses
HELMET_OUTLINEvia trueColor; test asserts rendered ANSICLI welcome grouped help: await citty
Resolvable<CommandMeta>inhelp-groups.tsand accept genericCommandDef<T extends ArgsDef>sopnpm typecheckandpackages/cliDTS build pass after the bare-invoke welcome workRegenerated
docs/evidence/knowledge-classification.jsonand tracked three queue-end plan monitors with paired_index.mdAudits rows soevidence:knowledge-classification:checkis greenShip
packages/cli/LICENSEin the published packagefileslist so npm tarballs include PolyForm Noncommercial textLanding Mission Control demo (
landing-missionkit/remote/mc): refresh#mc-mock-dataCurrent Mission agent toTech Leadand feed labels to design-v2 wire tokens (Eng/SQ). The tracked snapshot does not ship productCREW_ACTOR_MASK/crewActorRole, so the iframe still renders wire tokens verbatim (not long display masks). Correcting the earlier false claim that fixtures were display-masked; demo lexicon restoration waits on product-snapshot regen or Design export →landing:sync(do not hand-editremote/as SoT). Seedocs/agentkit-landing.mdEvidence anti-overwrite:
generate-codebase-findings.mjs --writepreserves on-disk reviewed coverage batches; non-mutating findings/hotspots checks ignore HEAD-volatilegeneratedAt/ working-tree digest fieldsBackfilled 11 registry skill hashes into
KNOWN_SHIPPED_OVERLAY_HASHESand pin registry SKILL.md coverage in VitestCapability inventory: regenerate launch-announcement anchors, restore SHA-verified counts, document factory-only
/public-issue-triagecounting policyCapability inventory: re-verify README positioning anchors against HEAD (Anchor L# column) and point verified-against SHA at
7fdb03cConfig tab: persona mode "Inherit default" skips empty mode overrides; document
/api/configtoken exemption in write verification matrixSECURITY.md: list working private maintainer channel first while public PVR remains disabled
CLI welcome nits:
guardmeta(shell, prompt), column-aligned hints, broader CI env detect,hasCliSubcommandtests, helmet outline uses light text colorKNOWN_SHIPPED_OVERLAY_HASHESwas missing.cursor/skills/core/docs-repo/SKILL.md, so an unedited consumer copy of that skill was misread as customized and never refreshed byagent-kit update. Ledger refreshed to 75 entries (prior hashes retained)Overlay anti-overwrite: backfilled current hash for
.cursor/commands/dogfood.mdinKNOWN_SHIPPED_OVERLAY_HASHESand added a Vitest pin that every L0 overlay artifact body is present in the ledger (closes residual L3 drift that permanently stalled unedited consumer refreshes)Evidence anti-overwrite (AUDIT-001 follow-through):
generate-codebase-findings.mjsandscore-codebase-risk-surface.mjsrefuse to rewrite reviewed JSON unless--write/--fix; package.json generators pass--write; pin test asserts everyevidence:*:checkscript stays non-mutatingRisk-hotspot scorer additionally excludes
.cursor/plans/from the product corpus so the manifest is independent of gitignored local backlog files;docs/evidence/codebase-risk-hotspots.jsonregeneratedClosed staging-evidence R14 still-open residuals A–G: verified R1 allowlist pin reconciliation, corrected
close-staging-evidence-checks-r14-index.mdClosed-by B/C honesty, added HANDOFF Gaps voice / merge-gate ownership / R15 provenance notes toclose-staging-evidence-checks-r14-a-d-residuals.md, and qualified the_index.mdevidence-checks-greentag toevidence-checks-green-at-98e0cbaClosed MC health healthcenter R1–R3 still-open residuals: removed the fallback-specific negative pin at
packages/cli/src/dashboard/plugin-ux-validation.test.ts(then believed covered by the broader scan), bounded the remainingHEALTH_SEVERITY_CHROMEpin to the object literal scope so unrelatedtoken:strings below the literal do not fail the severity-chrome test, and noted R14 batch monitor hygiene (later corrected as already closed bya9498ca)Closed landing Mission Control session production-shot residuals B-H: documented the canonical
missionkit.iocutover and five-asset legacy rollback bundle, differentiated Mission Control tab copy, refreshed inventory wording, aligned the 20x20 logo spec, and exposed row/image labels without a framerole="img"subtree trapLanding legacy rollback truth (R1–R5): removed the false self-contained claim for blob
d0e43278cda5; documented that no production-shot single-file artifact exists (CSS-mockup blob11197c8db22f@611c232is the last pre-shot self-contained file); switched both legacy HTML files to root-relative/dashboard/+/assets/production/paths; dropped the stale worktree byte-identity assertion; refreshed source-monitor Audits tagsMission Control Healthcenter residuals R1–R3 (post-PR #632): drop unread
tokenfrom allHEALTH_SEVERITY_CHROMEseverities and fallback; correct false comment that tiedtokento[data-sev]CSS; remove redundant E3 pin and assert no chrometokenfield; document SoTdashboard/dashboard.html(never gitignoredpackages/cli/dashboard/mirror) in plan template and plan-routineStaging-evidence R14 residuals A/C (post-PR #626/#627): R15 Closed-by cites on public-ci-skip (R1/R4) and landing-v1-v6 (B) monitors for
743de13/ PR #626; R14-pairplan-monitor-close-staging-evidence-checks-r14-index.mdwith its_index.mdAudits row and regenerate knowledge-classification ledger (B/D note-only; merge-gate enforcement deferred to public-ci-skip R8)Crew Monitor residuals R1–R4 (post-PR #631): replace inert whole-file avatar↔chip proximity regex with render-block structural pin (
feedSegSpans[0] + chipHtml+ no${chipHtml}between avatar and feed-label); regeneratedocs/evidence/knowledge-classification.jsonand R14-pair the close monitor with its_index.mdAudits row (PR #637/#638)Landing v1–v6 monitor residuals C/D/E: split runtime-captured counts from source-of-record values in
docs/evidence/runtime/landing-a11y-a-e-2026-08-01/(newsot-counts.txtwith "not served" header;live-counts.txtreduced to runtime capture); qualify README follow-on as source-of-record not yet served and mark pinned WP URL deprecated; reword wpautop guard comment in landing SoT files to avoid literal<br>(grep-clean); refresh.cursor/project-context.mdproduct version and npm CLI lane4.8.4→4.8.9. A delegated to deploy residuals plan; B to R14 companion.Mission Control Healthcenter residuals (E1–E3): widen git Autofix to
git init && git commit --allow-empty(zero-commit repos); unify memory path CTA toCopy pathwith README; drop unusedtokenon aggregateHEALTH_SEVERITY_CHROME.errorMission Control Healthcenter residuals (C/E/F/G/I): prune unreachable per-check
errorchrome; remap Autofix forhandoff/git/memory; drop deadhealthCheckKeydown/showHealthInfo/.health-message; scope seven-check test toHEALTH_CHECK_METALanding static SoT: lighten
--text-mutedto#7f93a8(WCAG AA on card/gradient); document footer CTA cluster; rewritelive-counts.txtas real newlines; note deadbrguard and unused purple contrast trapAdded
Mission Control broadcast Share URL mask:
dashboard:broadcast/agent-kit dashboard-broadcastprint a cosmetic Mission Kit (or BYO) share link (https://missionkit.io/mc/open.html#v1.…by default). The Share URL embeds the live token (same secret handling as the raw token); soft TTL is advisory. Fragment stays client-side; not a WAN relay. Resolver rejects non-private targets; BYO base must be HTTPS (loopback http allowed for local preview). Env:MISSION_CONTROL_SHARE_BASE,MISSION_CONTROL_SHARE_TTL_SEC(0= never),MISSION_CONTROL_SHARE_SHOW_LAN. ADR2026-08-11_mission-control-broadcast-url-mask.mdMission Control broadcast share residuals: default share base uses live
…/mc/open.html; pack gate assertsdashboard/lib/**+open.html;--no-openhelp matches Share-primary print; auth-gate tests cover/open+/open.htmlexemption matrix.Mission Control preferred browser: shared
dashboard/lib/open-browser.mjsopens at most one OS browser (configmissionControl.preferredBrowser, envMISSION_CONTROL_PREFERRED_BROWSER, CLI--browser);--no-open/MISSION_CONTROL_NO_OPENstill skip. Slash/dashboardstays IDE MCP only;/dashboard-broadcastis one surface (OS preferred or IDE verify). ADR2026-08-11_mission-control-preferred-browser.mdBroad Intake Unprocessed dogfood bucket (factory
dogfood/README.mdor consumer.cursor/dogfood/README.md##or### Unprocessed Files) on/start-project,/backlog-add, and Write residuals; advisory preflight on/continue-plan,/run-plan, and/run-plan-all. Same triage labels; never auto-analyze. ADR2026-08-11_dogfood-unprocessed-broad-intake-bucket.mdCommunity health C–F residuals:
scripts/check-public-deny-links.mjsnow scans.github/**/*.{yml,yaml}(issue-template forms, CI) in addition to markdown, with three new tests (9/9 pass). ADR2026-08-05_community-health-files-live-under-github-dirpoint 5 corrected to "adapted in Enforcement section only".docs/CONTRIBUTING.mdStandards bullet names both repos explicitly (mainfor public,stagingfor factory)..cursor/memory/_index.mdtrailing newline added.Design system pointer doc (
docs/design-system.md): Claude Design project id (4451a0e9-5258-45cd-91f7-a837bdcbde81), upstream/downstream surface map, code-wins-on-divergence rule,--text-mutedtoken divergence note. Crosslink added todocs/agentkit-landing.md. Comment added indashboard/dashboard.htmlbeside--text-muted: #6d8094citing the landing AA exception (#7f93a8). Closes residuals A+D from transport monitorplan-monitor-design-system-transport-claude-design.md; B/C/E/F noted as operator-decision or supersededCLI bare-invoke welcome: branded Mission Kit helmet ASCII,
agent-kit/@dadado/agent-kit-cliversion line, print-and-exit utility hints (--help,doctor,status,dashboard,init);NO_COLOR/ CI / non-TTY plain fallback; grouped root--help(SETUP / MISSION / DASHBOARD / INTEGRITY). Does not reuse run-plan persona banners. Dual-name ADR2026-08-06_mission-kit-vs-agent-kit-namingFactory-only
/public-issue-triageslash command for maintainers: list, classify, comment, label, and close incoming issues onagent-kit-startup/agent-kitwith HITL gates; omitted from L0 install and excluded from public-sync; bridges optionally to dogfood, memory WRITE, or/backlog-add. ADR2026-08-05_factory-only-public-issue-triage-commandDogfood inbox notes (2026-08-05): external design source-of-record gaps when a deploy artifact moves off-repo;
/run-plan-allqueue orchestration pitfalls (inferred park written to HANDOFF, refused-command retry, stale audit-session pile)Plan monitors (post-hoc):
design-system-transport-claude-design,github-community-health-profile(paired_index.mdAudits rows)Crew Monitor real-time rows for two activity classes the operator previously could not see at all.
subagentrows track Task worker lifecycle (running/done/failed) read from the worker transcript's terminal record under~/.cursor/projects/<slug>/agent-transcripts/<parent>/subagents/, labelled with the dispatched worker type and the to-do id lifted from the dispatch prompt.plan_reviewrows point at each recentplan-monitor-*.mdand say whether it is still awaiting triage. Both kinds are additive toMONITOR_ACTIVITY_KINDS; both are bounded by the same recency / size / count discipline as the existing prompt and report collectors, and both degrade to an empty list rather than an error state. Flight Log and the attention inbox keep sole ownership of triage - aplan_reviewrow is a pointer and never marks anything reviewedCrew Monitor row density toggle (compact / comfortable) in the card header, stored under the namespaced
agent-kit:monitor-densitykey and restored before first paint. With no stored preference the mode is auto-picked from viewport width (comfortable at >=900px). Comfortable rows wrap the label to at most two lines instead of hard-truncating a token mid-word; thelabelFulltitle tooltip stays required in both modes, because the display label is still capped upstreamGitHub community health profile:
.github/CODE_OF_CONDUCT.md(Contributor Covenant 2.1),.github/SECURITY.md(private disclosure via GitHub private vulnerability reporting, supported versions, documented Mission Control loopback / sandbox-disabled posture as out-of-scope-by-design),.github/SUPPORT.md(question routing,doctor --jsonfirst),.github/ISSUE_TEMPLATE/(bug + feature forms,config.ymlwith blank issues disabled and contact links), and.github/PULL_REQUEST_TEMPLATE.mdmirroring thedocs/CONTRIBUTING.mdquality gate. All files sit under.github/soscripts/public-sync.manifestcovers them via the existing.github/**include - no allowlist delta.docs/CONTRIBUTING.mdstays the CONTRIBUTING source of truth (GitHub discoversdocs/), and README Contribute plus the docs index carry thin cross-linksCursor Marketplace packaging:
.cursor-plugin/plugin.jsonnow declares explicit component paths (rules,skills,agents,commands,hooks) pluslogo,homepage, and an object-shapedauthor. Without those entries the plugin would have listed with zero components, since Cursor's default discovery readsrules//skills//agents//commands/at the repo root and Agent Kit keeps everything under.cursor/.skillspoints at.cursor/skills/core— one level deeper than the obvious path, because discovery only matches direct children holding aSKILL.md— which also keeps stack skills onagent-kit addname+descriptionfrontmatter on all 27 files in.cursor/commands/, required by the Marketplace submission checklist.namematches the existing filename slug, so no slash command was renamedLanding build pipeline for missionkit.io:
landing:sync(Claude Design zip export →.cursor/context/landing-missionkit/remote/, React vendored and SRI-verified against the hashes the design runtime declares),landing:build/landing:build:check(derives the asset list from the canvas; drops unreferenced stylesheets; self-hosts React; injects a static<title>/OG head for crawlers), andlanding:serve(loopback stage with Range support andno-store, for hands-on testing before deploy). Self-containment is proven by an offline headless render, not asserted: DOM byte-identical with all external DNS blocked, zero unresolved bindingsLanding deployed to
missionkit.iovia the design-runtime bundle: favicon (assets/logo.svg), Open Graph image (assets/hero-astronaut.png), full Twitter Card withsummary_large_image, andbuild-landing.mjscrawler<head>inject extended to mirror icon,og:image,twitter:image/title/descriptionwith absolutized URLs. P1-1 (YouTube-on-load before modal open) fixed upstream: the demo modal iframe now uses a lazydemoSrcbinding (empty at rest, set only inopenDemo, cleared incloseDemo), so first-paint issues zero external requests.docs/agentkit-landing.mdrewritten for the new pipeline;check:landing-body-equalityguard retired; legacy.cursor/context/landing-agentkit/files kept for rollback reference onlyPublic-sync compatibility evidence for the README and public maintainer guides:
docs/evidence/runtime/public-sync-readme-residuals-2026-08-11.mdrecords the allowlist dry-run, guard tests, and deny-link scanMulti-workspace install isolation: CLI root-confirm guard (
confirmProjectRoot) on bothinstallandupdatecommands; directory-lock (acquireCacheLock) serializes concurrent~/.cache/agent-kit/registry/refreshes; ADR surfaces matrix (L0 per-project, cache shared, MC per-workspace port);/dashboard-broadcastkill guidance aligned with never-kill-foreign-workspaceIDE-agnostic CLI install resilience:
--yesflag and non-interactive terminal detection (isNonInteractive) for CI, VS Code output panels, and piped stdin; actionable error classification for EPERM, exit 255, registry 403, and network failures with recovery stepsDashboard first-failure UX: structured recovery message when
dashboard/start.mjsis absent in L0-only consumer trees, naming four resolution paths (upgrade CLI, env var, sibling, direct script)VS Code onboard path:
generateVSCodeArtifactswired into personalization flow (.vscode/settings.json,.github/copilot-instructions.md, optional.vscode/security-review.agent.md); IDE-agnostic readiness docs with CLI equivalents table and slash-less onboard checklistRegistry clone error messaging: auth/access vs network vs generic failures with actionable recovery in
resolve.tsDogfood bridge: consumer install-fallback and dashboard-runtime-block notes (2026-08-02); memory errors for npm-cache EPERM/exit-255 and dashboard-host-missing/registry-403
Mission Control landing production shots: four PNGs under
assets/production/(Current mission, Checklist, Crew Monitor, Flight Log); design sources stay local under gitignoredassets/design/Mid-batch plan monitors (6) for residual closeouts (crew-monitor R1–R3, docs-indicative A–L, mc-chrome-icon A–F, mc-health R1–R3, public-ci-skip R7–R10, staging-evidence R14 A–D) with
_index.mdAudits rows; knowledge-classification ledger regeneratedDogfood note:
/git-prodshould prove tag CI green on the close-release commit before creating or pushing an annotatedv*tagCI Registry catalog parity:
node scripts/build-registry.mjs && git diff --exit-code registry/registry.jsonso SKILL frontmatter ↔registry/registry.jsondrift fails the builddocs/DEVELOPMENT.md: factory topology, local CLI loops, and public-sync awareness for maintainers (root README stays consumer storefront)Onboard domain-skills scaffold: after essentials are ready,
/agent-kit-onboardoffers a HITLScaffold domain skills/Defer/Skipgate before finish-setup //start-projectCTAs, reusing install-time personalization/doctor evidence and recording the outcome inonboarding.domainSkills(shipped as squashd00fb50; publicagent-kit-startup/agent-kit#36closed later via residuals with cross-repo evidence comment)Queue-end plan monitors (7) under
.cursor/memory/with triage headings;_index.mdAudits rows R14-paired (including crew-monitor + docs-indicative); knowledge-classification ledger regeneratedEvidence checks merge-gate policy: ADR
2026-08-01_evidence-checks-merge-gate(no silent continue-through-red; HANDOFF Gaps honesty)Docs indicative; delivery truth: always-apply read-time section in
docs-professional-standard, ADR2026-08-01_docs-indicative-delivery-truth, tightened external-review prompt/monitor templates (evidence-backed findings; no filler)CI private-origin allowlist pin: Vitest asserts
github.repository == 'agent-kit-startup/agent-kit-dev'remains in.github/workflows/ci.yml(Path C remirror guard)Static landing deploy artifact
.cursor/context/landing-agentkit/index.html(full document wrapper over redesign SoT)Landing Product proof: four alternating MC rows (L/R/L/R) with MC product header chrome (logo + Mission Control + workspace) replacing browser-chrome mockup; production PNGs from
assets/production/; a11y labels per rowLanding workflow copy: seven narrative sections in
COPY.md(onboarding, orchestration, HITL/triage, DevOps, settings/update, dogfood, MC tabs) integrated fromCOPY-WORKFLOW-DRAFT.mdafter HITL rewrite (version 4.8.9 pin, no autonomous pitch)Landing DESIGN-SYSTEM: mockup chrome rewritten from browser window (traffic lights + URL pill) to MC product header; framing invariant updated
Changed
Public root
README.mdstorefront rewrite: Mission Kit product voice for strangers on GitHub (PolyForm Noncommercial / source-available /sales@missionkit.io); install and CLI keep real Agent Kit identifiers without ADR paths, private memory links, or dual-name legal essays. Maintainer naming table moved todocs/DEVELOPMENT.md.missionkit.io license copy cutover: Claude Design export synced (
landing:sync/landing:build), Hostinger deploy ofdist/, and as-served HTML verified with PolyForm Noncommercial / source-available /sales@missionkit.io(zero unqualified open-source claims).docs/agentkit-landing.mdSEO section flipped from as-served-vs-target to live PolyForm wording. Public-sync allowlist/denylist unchanged (deny-link + dry-run guards pass). Public GitHub license label remains advisory until/git-prodHITL.Align Mission Kit public-compliance residuals (A–F): document that PR #698 already staged
783ca90; flip the Crew-lexicon as-served table indocs/agentkit-landing.mdto Design-export labels (Engineering Manager/Squad ·); disclose that the same Design sync refreshedremote/mc/*lexicon incidental to license copy (product SoT / display-mask ownership unchanged); record deployedsha256evidence; add an unqualified open-source wording assertion tolanding:build:check. Public mirrorLICENSEpromote stays operator/git-prodHITL.Onboard domain-skills scaffold residuals A–J: closed public
agent-kit-startup/agent-kit#36with evidence citingd00fb50(cross-repoClosesform documented in PR template +docs/CONTRIBUTING.md); documented instruction-only scaffold +.cursor/skills/domain/one-way category; added## Relevant skillsto project-context generator and factory.cursor/project-context.md; HITL fallback free-text + gates table; moved domain-skills command pin tolifecycle/l0.test.ts; dogfood Processed provenance honesty; allowlist pin verified at 6 (CI green on staging). Squash honesty: original 4-phase plan landed as single squashd00fb50(plan file gitignored), so per-tick verdicts are reconstructed from that commit rather than per-phase SHAs.Landing v1–v6 CDE still-open residuals (R1–R7): regenerated evidence ledger for green Knowledge checks; corrected stale "not yet live" SoT/README prose against WP-deprecated +
agent.startupkit.com.br301→missionkit.io delivery truth; documentedindex.htmldrift / retired byte-identity (no redeploy); R14/R7 process notes; append-only Closed-by onplan-monitor-close-landing-v1-v6-monitor-residuals-cde.mdShip-5.0 npm/npx honesty residuals: go/no-go record restated as NO-GO until CI-green-at-tagged-SHA + gate sign-off; Release Latest / storefront rows marked POST-PUBLISH; cite drift fixed;
docs/npm-publish-checklist.mddistinguishes tree 5.0.0 from registry 4.8.9; pack evidence atdocs/evidence/npm-pack-5.0.0-2026-08-11/npm-pack-5.0.0.json(stdout JSON parseable after prepack stderr fix). Blank-foldernpx @5.0dogfood remains blocked until publishPlan audit residuals termination:
/plan-review-triageand continuous/run-plan//run-plan-allpaths prefer Ack and stop or Fix nits only when Still open is nits/process-only or closeout depth is already capped (max depth 1 per theme family); Write residuals must not mint unboundedclose-*conveyors (ADR2026-08-11_plan-audit-residuals-termination.md). Throughput operator knobs documented under external plan review. Unprocessed dogfood Broad Intake visibility is ADR2026-08-11_dogfood-unprocessed-broad-intake-bucket.md(not this process policy).Public vs dev README R2–R10 still-open residuals: restamp public-sync evidence
Source SHAto green staging84dbaa3(342 allowlisted files); runsync-public --dry-runcontent denylist in the normal private CI deny-link step (pin count unchanged at 6); document private-filename content invariant beside the paid-spec path exclusion in the sync manifest; append-only A/D/F closeout corrections and a single S1 owner pointer (close-public-ci-skip-r7-r10-still-open.plan.md); CHANGELOG names theDEVELOPMENT.mdprivate paid-spec filename generalization that unblocked denylist sync sincec41efde(8705144); optional capability-inventory line-number assertion deferred (pattern scan only). Shared R14 ledger ownership unchanged.Deploy-agent startupkit post-merge residuals S5-S8: append-only R4 shared-owner basename correction (
plan-monitor-prefix), historical S1-S4 honesty vs mergedfcf1de0, allowlist counter-maintenance warnings onsync-publicandpublish-npm(count pin unchanged at 6), removed orphanscripts/check-landing-body-equality.mjs, and aligned DESIGN-SYSTEM deprecated Target line with the Current 301. Shared R14 Evidence ownership unchanged.Closed MC health healthcenter N2/N3 still-open residuals: restored a bounded
token:pin on thehealthSeverityChromefallback return object and a positiveconst HEALTH_SEVERITY_CHROME = { … };shape anchor inplugin-ux-validation.test.ts(literal-scoped pin kept; unbounded regex not restored); append-only R15 corrections on the source monitor for the lost fallback coverage claim and the stale R14 hygiene note (a9498capredecessor); acceptance language asserts suite success and exit 0 rather than a hard-coded test count. N1 batch ledger ownership unchanged.VS Code first-install residuals closeout metadata (N2/N3): source monitor heading normalized to
## Closed by residuals plan (C, E, K, J-vscode); acceptance wording aligned to shipped skip-if-exists (no merge path). N1 ledger ownership unchanged.R14 queue-end still-open monitors: durable triage / Residuals headings plus N1 Closed-by appends staged add-by-name with regenerated
docs/evidence/knowledge-classification.json(pnpm evidence:knowledge-classification:checkgreen locally). Unblocks Evidence gate for sibling residual lanes; does not close product Still open on those themes.Mission Control chrome citation R3/R4/R5 still-open closeout: append-only re-cite of parent
271d4d2/PR #504 for mixed-surface lint evidence; Evidence-gate Validation and ledger-regen policy corrections; R15 bottom-up supersession readability ADR; knowledge-classification regenerated for edited monitorsMission Control chrome citation residuals R1-R5 closed through append-only monitor corrections: lint evidence reclassified as already recorded, assertion-message pins stabilized, shared ledger and HANDOFF Gaps ownership documented, and the supersession pointer aligned.
Public sync slug resolution:
scripts/sync-public.mjswarns on stderr wheneverPUBLIC_REPO_SLUGdiverges from a slug derivable from--url, the configuredpublicremote, orPUBLIC_REPO_URL(not only when the URL env var wins); invalidowner/reposhape exits 1;--self-test-slugcovers precedence. Docs updated indocs/public-launch.mdanddocs/repository-boundaries.mddocs/design-system.md: drop markdown links into.cursor/memory/(public-deny-link guard) and remove a denylisted private client path from the upstream surface table so CI / public-sync stay greenseedManagedHashLedgerdocuments that the walk includes user-added non-kit basenames under overlay prefixes (harmless while those names stay outside the L0/pack/skill apply set)Docs/copy alignment to missionkit.io Mission Kit 5 positioning under dual-name contract (ADR
2026-08-06_mission-kit-vs-agent-kit-naming): README hero/tagline, consumer docs index/getting-started/CONTRIBUTING/claim matrix/github-about Website,install.mdintro, public launch announcement,project-context.mdversion lane5.0.0, capability-inventory positioning rows; legacyagent.startupkit.com.br/landing-agentkitqualified as redirect/rollback-only. Landing canvas underlanding-missionkit/remote/untouched.Consumer and maintainer documentation alignment: the README Mission Control pointer promises production constraints only; getting-started restores copy-only paste destinations, removes the duplicated maintainer three-way loop in favor of a pointer to
docs/DEVELOPMENT.md, and keeps the consumer guide consumer-focused.docs/DEVELOPMENT.mddescribes private exclusions generically (no denylist-triggering private paid-spec filename) so private→public sync dry-run stays green afterc41efde.Crew role mask SoT sync (plan
crew-role-mask-sot-sync): glossary ADR display-mask contract updated to wire-short / display-long (CREW_ACTOR_MASK+crewActorEngRole); Eng collision withdrawn at display; team-member framework core-slot lexicon aligned (Tech Lead / DevOps / Project Manager / Developer / Product Owner); landing Mission Control fixture JSON uses wire tokens (Eng/SQ) and Current Mission agentTech Lead. Landing iframe#mc-mock-datalexicon refreshed in residuals Phase 3 (was still Engineering Manager / Squad). Product masks unchanged (already shipped PR #662)Crew Monitor row redesign via Claude Design brief (plan
crew-monitor-design-brief-claude-design): tinted initials badge returns as the kind + identity cue; separate kind glyph removed; compaction hides whole fields at breakpoints instead of mid-token ellipsis;Engdisplay split fromkind(delivery → DevOps); plan chip has no max-width cap. Three porting deltas vs the mirrored design recorded in.cursor/context/mission-control-design/remote/v1/ACCEPTANCE.md. Glossary ADR amended; Mission Control visual SoR stays the repo (one-off brief ADR2026-08-05_mission-control-design-one-off-brief)Crew Monitor rows are compact and glyph-first. The kind glyph moved to the start of the row (it was mid-label, between actor and verb) and the avatar/initials box was removed entirely. The avatar shipped in #631 and #637-#639 and its removal is deliberate: initials were a lossier copy of the actor string two segments later, and the 18px box pushed the kind glyph off the left edge an operator scans down. Long profession display masks were replaced with the operator's short lexicon (
Engineering Manager->Eng,Squad->SQ,Scrum Master - awaiting gate->PM - awaiting gate, and so on), which retires the previously accepted actor-mask-vs-noshrink tradeoff instead of re-deciding it. (Interim compact-labels pass; design-v2 above restored long display masks while keeping short wire tokens.) Kind ids,#hero-activity, and the.monitor-row*class prefix are unchanged. ADR:2026-07-27_crew-monitor-vs-plan-monitor-glossaryDelivery rows read
merged, notshipped. The row is derived from a merge/squash entry that already carries its PR number and SHA, andshippedimplied a production promote that/git-stagingnever performed.shippedis retired from the row wording contract's verb list;failedjoins it for subagent runs that end in errorCrew Monitor column stability: actor and verb segments carry a min-width floor so the metadata column starts at the same x on every short-mask row (long kit agent ids still grow past the floor rather than truncate), and the plan filename now gives up width before the mid segments
Domain migration: canonical URLs updated to new domains (missionkit.io, dadado.dev, startupkit.rocks, agentkit.works → GitHub). Legacy domains redirect via 301 to preserve links.
Landing source of record moved to the external design project; the design mirror is versioned so the deploy is reproducible from git alone, and the now-duplicate
assets/production/*.mp4/*.webmmasters are gitignored (ADR2026-08-05_landing-external-design-source-of-record)Residual closeout plans: composite squash commits trade per-tick observability for batch efficiency; post-hoc verification against the merged state is the documented delivery-truth pattern (ADR
2026-08-08_ledger-regen-policy)Deploy-agent startupkit residuals R1-R8: corrected the DESIGN-SYSTEM current URL and its append-only monitor claim, documented shared ledger and HITL evidence paths, aligned the retired equality-guard wording, and added the CI allowlist counter coupling comment
docs/cursor-native-audit.mdinventory refreshed: plugin3.0.0→5.0.0, rules 23 → 25, commands 10 → 27, skills 7 → 9, hooks 2 events → 5. Also corrected a stale claim that CLIinitwritesplugin.jsoninto target projects — no generator does/plan-review-triage: paced Write residuals for multi-path walks (wave size 2 Tasks; write-confirm collapse when operator authorizes remaining set; per-monitor plans when themes diverge)Relocate Mission Control icon/vector sources off repo root into local
assets/design/(removed tracked root.aifiles)Memory cite hygiene: mc-chrome-icon Closed-by C/G narrowed (circle/ellipsis intro →
ec64be5/PR #584;>= 1+chip/door →6acb2d7/PR #592; ADR/git-staging§3 amended in place; ellipsis/chip/door pins and thresholds re-derived at HEAD)Docs-indicative A–L residuals (D–G, I, K): restore R15 Still open rows on source monitor; prompt template R14 same-commit pairing + single-pipe Audits sample; name
audits-wait-freshsentinel in/plan-external-review; HANDOFF mid-batch monitor pointer; CI registry catalog parity stepPublic CI skip R7–R10 residuals: merge-gate ADR closeout contract (
gh pr checks/ Evidence green before Gaps-none);knowledge-classification.jsonregenerated by05f6713sobuildis green at6d32c57;PUBLIC_REPO_SLUGhonored whenPUBLIC_REPO_URLunset (warn when both set); denylist pin uses tolerant regex; allowlist exact-count pin updated to 6 (landing body equality step)Public vs dev README separation: root
README.mdis consumer storefront only; maintainer dual-repo table moved todocs/DEVELOPMENT.md;docs/CONTRIBUTING.mdpoints at Development for monorepo loops; public-sync.manifest comments document the boundary (ADR2026-08-02_public-vs-dev-readme-separation)Crew Monitor feed hygiene (residuals C/E/F + D note): drop unreachable empty-segment branch; prune inert chip wrapper CSS; harden avatar↔chip sibling pin in
plugin-ux-validation; document latent flat-label glyph-at-end in glossary ADRPublic sync slug SoT:
sync-publicderivesgh --repoowner/repo fromPUBLIC_REPO_URL(removed hardcodedPUBLIC_REPO_SLUGfrom CI); docs/ADR note push + gh redirect; allowlist pin exact count 5 + denylist quote variants + skip whenci.ymlabsent/plan-external-reviewcommand doc: §What Claude should produce aligned with prompt template (delivery truth first, finding priority, evidence mandate, forbidden filler)docs-reposkill version0.1.0→0.1.1(registry.json+ skill frontmatter mirrors) after delivery-truth content wireMemory cite hygiene:
plan-monitor-mc-chrome-icon-style-consistencyClosed-by F/C/G/E corrected (exact pins retained; C→6acb2d7/PR #592; G→52a1fc3+ADR; E deferred); close-monitor R15 Closed-by for A–DPublic CI skip guards: flip denylist (
!=public slug) to allowlist (== agent-kit-startup/agent-kit-dev) on sync-public, publish-npm, and private-only build steps; ADR + public-launch / repository-boundaries / gitupdate docs; verify checklist notes Path C one-release lagCrew Monitor feed row: order is avatar → actor → kind glyph → verb → metadata → time; kind chip is glyph-only (no solid fill); avatar carries the kind
*-bgtintLanding docs: live URL truth for
https://agent.startupkit.com.br(Hostinger ALIAS + static subdomain); WP/agentkitnow 301 redirects to the subdomain via theagentkit-redirectWordPress pluginLanding SEO/a11y: hero promoted to
<h1>,twitter:carddowngraded tosummaryuntil an OG asset ships, andINVENTORY.md/docs/agentkit-landing.mdcurrent URL corrected toagent.startupkit.com.brLanding SoT guard:
scripts/check-landing-body-equality.mjs+pnpm check:landing-body-equality+ CI step pinindex.html<body>topage-content.htmlfragmentSource
a14d3cdsync/v5.0.0-a14d3cd