Changelog · latest 5 releases
- ● v0.52.0
self-describing background-work tool names: delegate.task (in-chat helper), fanout.* (parallel analysis), queue.* (durable deliverable) — was agent.delegate/workflow.*/work.*.
- v0.51.0
anti-distortion memory prompts (measured A/B: utility +11pt, noise 8→1) + extractor hardening + --redistill-empty.
- v0.50.0
import: skip /tmp bench junk + headless --distill with failure causes; one global default model.
- v0.49.0
security audit follow-up: 25/30 findings closed — gateway takeover hardening, toolpack shadow-guard, response body caps + command expiry.
- v0.48.0
whole-repo security audit: 4 high + 12 medium fixes — readonly-mode bypass, forbidden-tool bypass, unicode smuggling, honest cost accounting.