@@ -8,6 +8,27 @@ Newest first. `Unreleased` is what is on `main` and not yet tagged.
88
99## Unreleased
1010
11+ ### A skill can be written in the conversation instead of retyped into a form
12+
13+ A skill is four fields and an instruction a Bot follows, and the instruction is the one that decides
14+ whether the skill works. The only place to write it was a textarea on ` /skills ` , which meant having
15+ the conversation, getting a good draft in the transcript, and then copying it out and retyping it.
16+ Mostly nobody bothered, which is how a deployment runs for months with no skills in it.
17+
18+ The example package now ships a ` skill-creator ` skill, granted to ` general-assistant ` . A Bot holding
19+ it is offered four tools for listing, reading and saving skills; every other Bot is offered none of
20+ them. It interviews you about the skill you want, looks at what already exists before naming it,
21+ rehearses it against one realistic request, and then saves it.
22+
23+ The save is a card, not something that happens quietly. It draws the command, the title, the declared
24+ tools and the whole instruction, and writes nothing until a button is pressed. A skill appears in
25+ everybody's ` / ` menu with somebody's name on it, and saving is also how an edit is spelled, so an
26+ unattended save could replace a skill somebody is already using.
27+
28+ The tools run in the browser as the signed-in person, over the same ` POST /api/plugins/skills ` a
29+ person uses, so who may take a slug is answered the same way and the ` configuration.changed ` audit
30+ row is written the same way.
31+
1132### A person can set standing instructions that every coworker follows
1233
1334Settings now has a box for standing instructions: one piece of text per person, saved once and
@@ -24,6 +45,43 @@ any prompt until somebody writes something, so a deployment where nobody uses th
2445as before.
2546
2647This adds migration ` 0026_user_instructions ` , which creates one table.
48+ ### A coworker can be made in the conversation, and it starts able to reach nothing
49+
50+ A coworker without an endpoint runs on its role description, which becomes the standing instruction
51+ handed to a model on every turn in every channel it is in. It is the hardest thing anybody is asked
52+ to write cold, so people write a sentence, get a coworker that answers vaguely, and never go back to
53+ the field that decided everything.
54+
55+ The example package now ships a ` bot-creator ` skill, granted to ` general-assistant ` , with tools for
56+ listing, reading and saving coworkers. It asks the follow-up your last answer calls for, reads the
57+ roster to say when something already does the job, and can be told to make one like an existing
58+ coworker but for a different job, then go and read what that coworker actually runs on.
59+
60+ The card shows the name, the job, the skills and the entire role description, scrolled rather than
61+ clamped, because that text runs on somebody's behalf. What is made is granted nothing: it can reach
62+ no connector, no tool and no browser until somebody grants it, and a conversation with it says so.
63+
64+ Like the skill tools above, these run in the browser as the signed-in person over the endpoints a
65+ person uses, so who may create a coworker is answered the same way and ` bot.created ` carries the
66+ actor.
67+
68+ ### A conversation has a name of its own
69+
70+ A channel's name was only the names of the Bots in it, so asking one Bot about six unrelated things
71+ gave six rows reading the same thing, told apart by a preview of whatever was said last, which is
72+ usually the tail of an answer and says nothing about the question. A conversation is now named from
73+ its opening exchange, and the roster's second line holds that name instead of the preview, falling
74+ back to the preview until a name exists. A row is never blank and never worse off than before.
75+
76+ Two things a deployment should know. The opening exchange, up to 600 code points, is sent to whatever
77+ ` tenantPackage.model ` names, which is the same provider the Bots already use, so it is not new egress
78+ but it is sent as housekeeping rather than because somebody asked for it. And the second line now
79+ says what the conversation is about instead of what was last said.
80+
81+ It runs on the work queue rather than as a headless turn, so naming a conversation never takes the
82+ Intelligence thread lock and cannot refuse somebody's own next message with a 409. A deployment with
83+ no model key names nothing and carries on.
84+
2785### The trail says who a coworker was opened to
2886
2987Making a coworker public admits every signed-in person to it, and being admitted to a coworker is
@@ -67,6 +125,21 @@ what did not work here was short by exactly the rows they came for. A per-person
67125this path every time somebody's token expires, so this was the most common failure the product has
68126and the one the trail was quietest about. Both now read as ` Did not happen ` , and both are in that
69127saved view. Neither is filed as a refusal: nothing was forbidden on either row.
128+ ### A blank agentId on a channel activity says which field was wrong
129+
130+ ` POST /api/channels/:id/activity ` accepted an ` agentId ` of only spaces, trimmed it to nothing, then
131+ looked that up and answered ` 404 Agent not found ` . The field was malformed rather than the agent
132+ missing, so the answer sent whoever was integrating to look for a coworker that was never named. It
133+ is now a ` 400 ` naming the field, which is what the same endpoint already did for malformed text.
134+
135+ ### Audit payloads are redacted by the store as well as by its caller
136+
137+ Redaction of secrets out of audit payloads happened in ` recordAuditEvent ` , and every caller in the
138+ tree goes through it. The store underneath it is exported, though, and its ` insert ` wrote whatever it
139+ was handed, so a future direct caller would have written secrets to the audit table in cleartext.
140+ ` insert ` now redacts too. Redaction is idempotent, so nothing about the existing path changes; this
141+ is the floor under it rather than a fix to it.
142+
70143### A stray space in NODE_ENV no longer lets the public example key through
71144
72145A deployment that never changed ` KEY_ENCRYPTION_KEY ` encrypts its credential vault with the key
@@ -76,6 +149,14 @@ private-host browsing — trimmed first. Both read the same env file, and a trai
76149invisible: Docker's ` env_file ` preserves it and so does every hosting dashboard with a text box. So
77150` NODE_ENV=production ` tripped one refusal, slipped past the other, and started the deployment on the
78151public key with only a warning at boot. Both gates now ask the same question the same way.
152+ ### A tool result from an MCP server with an empty part no longer crashes the turn
153+
154+ Reading a tool result cast every part to an object and asked for its type. A ` null ` or missing entry,
155+ which a vendor's MCP server is free to send, threw instead, and the turn that had just called the
156+ tool failed. Such a part is now named ` [unknown] ` , which is the same naming-rather-than-dropping the
157+ surrounding code already does for parts it does not recognise, so the rest of the result still
158+ reaches the Bot.
159+
79160## 0.0.6
80161
81162### Setting up needs one Intelligence credential, not two
0 commit comments