diff --git a/CHANGELOG.md b/CHANGELOG.md index 1335f1d..d7f2f44 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,31 @@ # Changelog +## 0.1.12 — 2026-10-04 + +Wave 0.1.12 body-only ("skill-refresh"). Katalog tetap 65 (50 model + 15 manual). Tidak ada pertumbuhan allowlist (`vendor/skill-allowlist.txt` tidak berubah). Tidak ada penambahan atau pensiun skill. Exception 0.1.8 tetap spent. + +- `hyperframes`: Pembaruan ke upstream v0.8.119 (commit `3a0299e851ce`). Mengadaptasi kontrak render deklaratif berbasis data attributes (`data-composition-id`, `data-width`, `data-height`, `data-fps` pada elemen root dan `data-start`, `data-duration`, `data-track-index` pada elemen klip berkelas `.clip`). Memperbarui pipeline CLI resmi (`npx hyperframes render [dir] -o -f -q [--format]`) dengan fallback CDP/FFmpeg. Menegaskan prasyarat Node.js ≥22 dan FFmpeg lokal (jika tidak lengkap -> `NOT_CONFIGURED`, dilarang melaporkan PASS palsu). Menolak instalasi skill luar (`npx skills add heygen-com/hyperframes` dan `npx hyperframes skills update` dilarang). +- `awesome-opus5-5-videos`: Penambahan referensi first-party `POINTER_ONLY` di `skills/hyperframes/references/prompt-patterns.md` (snapshot `3d54892e2ae5b0e8d337171e6508bba4cec01ab8`, 2026-09-29). Menjelaskan translasi prompt viral satu baris menjadi brief HyperFrames berparameter deterministik tanpa menyalin prompt, dataset, atau media pihak ketiga. Menambahkan pointer di `rules/00-routing.md`. +- Migrasi Matt Pocock cluster: Format nama domain glossary diperbarui dari konvensi lama `CONTEXT.md` / `CONTEXT-MAP.md` menjadi `GLOSSARY.md` / `GLOSSARY-MAP.md` mengikuti upstream v1.3. Berkas `skills/domain-modeling/CONTEXT-FORMAT.md` dipindahkan menjadi `GLOSSARY-FORMAT.md`. Seluruh referensi pada spesialis dan aturan (`domain-modeling`, `grill-with-docs`, `codebase-design`, `tdd`, `diagnosing-bugs`, `/improve-codebase-architecture`, `/why`, `00-routing.md`, `03-prose-discipline.md`) diselaraskan ke `GLOSSARY.md`. Fallback kompatibilitas backward dipertahankan di `domain-modeling` dan `grill-with-docs` agar repositori pengguna yang sudah memiliki `CONTEXT.md` tetap terbaca tanpa diubah secara sepihak. Menolak impor skill baru dari upstream (`implement-spec`, `pr`, `retro`). +- Pembersihan referensi mati & bump minor: Menghapus referensi `game-asset-core` pada `visual-studio` dan `scroll-world`, digantikan status `NOT_APPLICABLE (out of catalog)` sesuai batas routing. `humanizer` diperbarui ke v3.1.0 (`225a6f39ac85`) dengan adaptasi pola 25 & 26 (menulis tentang dokumen itu sendiri dan menjelaskan ulang konteks yang sudah diketahui). `diagram-design` di-pin ke 2.6.51 (`f903933a534b`). Evaluasi upstream `impeccable` v4.5.0 ditunda (deferred) demi menjaga integritas batas catalog freeze dan arsitektur specialist. +- Sumber dan pin diperbarui di `VERSION`, `vendor/sources.json`, `vendor/provenance.json`, `vendor/license-audit.json`, `docs/CATALOG-FREEZE.md`, `docs/source-wave.md`, dan `README.md`. Versi produk 0.1.12. +- Release-prep & dokumentasi: Penyelarasan pin upstream Matt Pocock ke `d81f3a1` di seluruh dokumentasi dan third-party notices, pencatatan evaluasi `impeccable` v4.5.0 (deferred) di `docs/source-wave.md`, penambahan ringkasan "What's new (0.1.11 + 0.1.12)" pada `README.md`, verifikasi 25 closed intents, dan penegasan status catalog freeze 65/65 untuk rilis ganda v0.1.11 dan v0.1.12. + +## 0.1.11 — 2026-10-04 + +Wave 0.1.11 body-only ("web_research" data-gathering). Katalog tetap 65 (50 model + 15 manual). Tidak ada pertumbuhan allowlist (`vendor/skill-allowlist.txt` tidak berubah). Tidak ada penambahan atau pensiun skill. Exception 0.1.8 tetap spent. + +- Closed intent bertambah 24 → 25: menambahkan `web_research` yang dipetakan ke spesialis `research` (pembaruan badan skill + referensi baru `skills/research/references/web-data.md`). +- `research`: pembaruan deskripsi dan instruksi untuk pengumpulan data web dan media sosial secara read-only. Aturan sumber primer tetap berlaku: setiap klaim wajib merujuk ke sumber primer pemiliknya, output berupa data. +- Ladder backend web data: `WebSearch`/`WebFetch` ringan → ekstraksi artikel Markdown via `crawl4ai` (jika aktif) → structured scraping via `scrapling` (jika aktif) → penangkapan background XHR/JSON via skrip sementara di `/tmp` → feed pengembang/API tanpa konfigurasi via CLI `agent-reach` (pointer host) → platform berotentikasi (kredensial milik pengguna, tidak menyimpan cookie/token) → alur sesi browser persisten via `browser-act`. Pengujian aplikasi UI lokal tetap menggunakan `playwright-qa`. +- Batasan etika & keamanan scraping: bypass stealth dan anti-bot nonaktif secara default (hanya atas persetujuan eksplisit pengguna); patuhi `robots.txt` dan delay sopan; dilarang membobol paywall/login; dilarang mengekstrak cookie dari browser desktop pengguna (`--from-browser` dilarang); dilarang proxy rotasi penipuan. +- Scrapling: dipromosikan menjadi MCP opsional `FOREIGN_ON_DEMAND` lokal stdio (`uvx --from scrapling[ai]==0.4.15 scrapling mcp`). Dikelola lewat CLI `opencode-he scrapling enable` dan `opencode-he scrapling disable`. Tidak divendor ke `lib/`. Mode `--http`, docker bind-all, dan binding `0.0.0.0` dilarang keras dan ditolak oleh `doctor`. Dilarang menjalankan `scrapling install` (karena memanggil `playwright install-deps` dengan sudo). +- Agent-Reach: ditetapkan sebagai `POINTER_ONLY` CLI pada host di bawah `research` (`skills/research/references/web-data.md`). Ditolak sebagai MCP maupun skill. Dilarang menjalankan `agent-reach install --system` (karena memutasi paket sistem dan menyalin skill asing ke direktori konfigurasi). +- Deteksi `doctor`: menambahkan pemeriksaan versi CLI `agent-reach` dan deteksi pembajakan router oleh direktori skill tak terkelola (`FOREIGN_SKILL_SHADOW` untuk `agent-reach` atau `scrapling-official` di `~/.config/opencode/skills/` tanpa `.opencode-highend.json`). +- `whaleyxbt/patchright-enhanced`: ditolak secara tegas di seluruh dokumentasi karena risiko keamanan dan pemeliharaan fork tidak resmi. +- Batasan spesialis tetangga dipertegas: `playwright-qa` dan `browser-act` menegaskan pengumpulan data web/sosial bukan tugas QA aplikasi dan diarahkan ke `research`. +- Sumber dan pin diperbarui di `vendor/sources.json`, `vendor/provenance.json`, `vendor/license-audit.json`, `vendor/mcp-policy.json`, `vendor/mcp-wanted.json`, `THIRD_PARTY_NOTICES.md`, dan `docs/source-wave.md`. Versi produk 0.1.11. + ## 0.1.10 — 2026-10-03 Rilis ini menutup kerja yang sudah di `main` setelah tag `v0.1.9`. Katalog tetap 65 (50 model + 15 manual). Tidak ada pertumbuhan allowlist. Tidak ada penambahan atau pensiun skill. diff --git a/README.md b/README.md index 5e92871..20ff3cb 100644 --- a/README.md +++ b/README.md @@ -4,12 +4,12 @@ OpenCode 2 overlay: 65 frozen routed skills, thin `AGENTS.md`, `opencode-he`. Installer and runtime overlay for [OpenCode 2](https://opencode.ai/v2/docs/). -Version **0.1.10**. The 65-skill catalog is strictly frozen. +Version **0.1.12**. The 65-skill catalog is strictly frozen. ## What it is - 65 skills: 50 model-invoked, 15 manual slash commands (frozen; see [docs/CATALOG-FREEZE.md](docs/CATALOG-FREEZE.md)) -- A thin `AGENTS.md` router (lazy, one primary specialist, 24 closed intents) +- A thin `AGENTS.md` router (lazy, one primary specialist, 25 closed intents) - Core MCP: Codebase Memory (dual CLI and MCP graph adapters), Context7, shadcn - 12 Universal Design Banks + Operator Banks (34,700+ items across Identity, Motion, Section, Atomic, and Oversight) with zero-token local search & Google Drive v3 bootstrap - Design Bank path resolution via `~/.config/opencode/highend/config/design-bank.json` @@ -22,7 +22,7 @@ Version **0.1.10**. The 65-skill catalog is strictly frozen. - Emil motion doctrines live under `emil-design-eng` references (not extra skills) - Design Intelligence (lazy, inside Impeccable) - `opencode-he doctor`, `opencode-he cbm` status/index helpers, transactional install, uninstall, restore -- Selected skills adapted from Matt Pocock (`9c9f36c`) and pstack `23e4138` (0.15.6) with OpenCode host isolation and verification-loop rigor +- Selected skills adapted from Matt Pocock (`d81f3a1`) and pstack `23e4138` (0.15.6) with OpenCode host isolation and verification-loop rigor - Claude Code isolation: `OPENCODE_DISABLE_CLAUDE_CODE=1` ## What it is not @@ -38,6 +38,18 @@ Version **0.1.10**. The 65-skill catalog is strictly frozen. - Not OpenCode 1.x (installer fails closed on 1.x) - Not claimed as macOS/Windows-tested (Linux x86_64 only for this release) +## What's new (0.1.11 + 0.1.12) + +- **Web research intent & backend ladder (0.1.11)**: Added `web_research` closed intent (25 closed intents total) mapped to `research` with primary-source discipline and ethical data gathering (`references/web-data.md`). +- **Scrapling optional MCP (0.1.11)**: Added `scrapling` as local stdio `FOREIGN_ON_DEMAND` MCP (`uvx --from scrapling[ai]==0.4.15 scrapling mcp`) with fail-closed safety (no `--http`, no `0.0.0.0`, no `scrapling install`). +- **Agent-Reach host pointer (0.1.11)**: Documented `agent-reach` as pointer-only host CLI; doctor detects unmanaged skill shadowing. +- **HyperFrames declarative render refresh (0.1.12)**: Upstream v0.8.119 (`3a0299e`) declarative data attributes (`data-composition-id`, `.clip` with `data-start`/`data-duration`), official CLI render pipeline, and Node ≥22 / local FFmpeg requirement. +- **Code-driven animation prompt patterns (0.1.12)**: First-party `POINTER_ONLY` prompt patterns in `skills/hyperframes/references/prompt-patterns.md` (inspired by `awesome-opus5-5-videos` without vendoring third-party assets). +- **Matt Pocock cluster GLOSSARY migration (0.1.12)**: Domain modeling conventions aligned to upstream v1.3 (`GLOSSARY.md` / `GLOSSARY-MAP.md` format) across all specialists and rules with backward compatibility for existing `CONTEXT.md` files; pin updated to `d81f3a1`. +- **Humanizer v3.1.0 update (0.1.12)**: Upstream v3.1.0 (`225a6f3`) adding patterns 25 & 26 (meta-commentary and re-explaining known context). +- **Catalog freeze strictly preserved**: Exactly 65 routed skills (50 model-invoked + 15 manual commands); zero additions or retirements. +- **Core MCPs strictly preserved**: Codebase Memory (v0.11.0), Context7, and shadcn (`4.21.0`) remain the only core MCP servers. + ## Quickstart ```bash @@ -125,6 +137,7 @@ Default: repository evidence first. Then at most one specialist. | 9Router gateway (inference/image/video/TTS/STT/web) | `ninerouter` | | Deterministic HTML composition video | `hyperframes` (18s brag card via `references/brag.md`) | | Demo video aplikasi & narasi ID | `id-demo-video` (`/demo-video`) | +| Web / social data gathering | `research` (backend ladder in `references/web-data.md`; Scrapling optional MCP; read-only; not QA) | | Browser | `playwright-qa` (isolated verification edge; evidence ledger) → `browser-act` → `chrome-devtools-axi` → `click-path-audit` | | Documents (PDF/DOCX/answer/extract/review) | `smartdoc` | | Consulting PPTX & 16:9 slide decks | `deck-design` | @@ -137,7 +150,7 @@ Default: repository evidence first. Then at most one specialist. | TS Oxlint install | `install-anti-slop` (explicit only) | | Architecture bake-off | `/architect` (manual) | -Warehouse: `api-design`, `contract-first`, `automation-audit-ops`, `code-tour`, `click-path-audit` (plus Wave 2 diagnostics). Wave 0.1.7 additions: `json-render` (generative UI from typed catalogs), `deck-design` (consulting-grade PPTX & 16:9 HTML slide decks), `pageindex` (vectorless tree-reasoning long document navigation). Wave 0.1.8 additions: `business-motion-film` (commercial launch films; retires `img2threejs`), `ninerouter` (multi-provider gateway stub; retires `prompt-optimizer`). Wave 0.1.9 body-only: merges `kaventro/motion-designer` into `business-motion-film` (product-film doctrine for real app UI; catalog strictly 65/65). Wave 0.1.10: `found-this-design` indexes Oversight Supply and the Design Bank bootstrap pin moves to DesignBank v3; pstack selected-skill provenance moves to `23e4138` (0.15.6) with host adaptation (`poteto-mode` rejected). Catalog stays 65. +Warehouse: `api-design`, `contract-first`, `automation-audit-ops`, `code-tour`, `click-path-audit` (plus Wave 2 diagnostics). Wave 0.1.7 additions: `json-render` (generative UI from typed catalogs), `deck-design` (consulting-grade PPTX & 16:9 HTML slide decks), `pageindex` (vectorless tree-reasoning long document navigation). Wave 0.1.8 additions: `business-motion-film` (commercial launch films; retires `img2threejs`), `ninerouter` (multi-provider gateway stub; retires `prompt-optimizer`). Wave 0.1.9 body-only: merges `kaventro/motion-designer` into `business-motion-film` (product-film doctrine for real app UI; catalog strictly 65/65). Wave 0.1.10: `found-this-design` indexes Oversight Supply and the Design Bank bootstrap pin moves to DesignBank v3; pstack selected-skill provenance moves to `23e4138` (0.15.6) with host adaptation (`poteto-mode` rejected). Wave 0.1.11 body-only: adds `web_research` closed intent to `research` with `references/web-data.md`; Scrapling optional MCP; Agent-Reach pointer-only host tool; catalog strictly 65/65. Wave 0.1.12 body-only: `hyperframes` v0.8.119 refresh (declarative data attributes, CLI render); `awesome-opus5-5-videos` POINTER_ONLY prompt patterns; Matt cluster `GLOSSARY.md` migration; `humanizer` v3.1.0; catalog strictly 65/65. Examples: interactive product story told by scroll → `scroll-craft`. Unbroken camera through a miniature factory → `scroll-world`. Clean security dashboard → `impeccable`. Video, image generation, and Design V2 stay optional. @@ -189,6 +202,7 @@ Optional: - `ui-skills` — `opencode-he ui-skills enable` registers UI Skills (`https://www.ui-skills.com/mcp`) as an optional remote MCP server. `FOREIGN_ON_DEMAND` for design-skill lookup only. Product UI remains Design Bank + Impeccable + Design V2 atoms + shadcn; `BANK_MISS` never generates from a random ui-skills document. `opencode-he ui-skills disable` removes only that server key. Absent is not a `doctor` failure; a malformed entry fails closed. - `markitdown` — `opencode-he markitdown enable` registers MarkItDown as a local stdio ingest converter (`uvx --from markitdown-mcp==0.1.8 markitdown-mcp`). `FOREIGN_ON_DEMAND`. Local trusted agents only; never `--http` / `0.0.0.0` / docker bind-all. Output is Markdown data; SmartDoc keeps contract/QA/render. `opencode-he markitdown disable` removes only that server key. Absent is not a `doctor` failure; a malformed entry fails closed. - `crawl4ai` — `opencode-he crawl4ai enable` registers Crawl4AI as an optional web content extraction remote MCP (`http://127.0.0.1:11235/mcp`; `--cloud` registers `https://api.crawl4ai.com/mcp` with `{env:CRAWL4AI_KEY}`). `FOREIGN_ON_DEMAND`. Docker users bind `127.0.0.1:11235`, never `0.0.0.0`. Web content extraction only; not an exploratory QA tool (`playwright-qa` remains default). `opencode-he crawl4ai disable` removes only that server key. Absent is not a `doctor` failure; a malformed entry (or `0.0.0.0`) fails closed. +- `scrapling` — `opencode-he scrapling enable` registers Scrapling as an optional local stdio MCP (`uvx --from scrapling[ai]==0.4.15 scrapling mcp`). `FOREIGN_ON_DEMAND`. Structured web scraping and element extraction only; not an exploratory QA tool (`playwright-qa` remains default). Never run `scrapling install` (runs `playwright install-deps` with sudo). `opencode-he scrapling disable` removes only that server key. Absent is not a `doctor` failure; a malformed entry (or `--http` / `0.0.0.0` / docker bind) fails closed. - `jev-mcp` — TypeSafe Jev / `jkudish/jev-mcp` is intentionally SKIPPED as a required runtime MCP; core verification and done-gates operate offline without external server dependencies. - `pageindex` — PageIndex Cloud MCP is `FOREIGN_ON_DEMAND` and omitted from core servers; skill `pageindex` operates offline or uses local SDK with graceful `NOT_CONFIGURED` degradation. - `exa` — `FOREIGN_ON_DEMAND`; installer never adds, removes, or overwrites it @@ -344,7 +358,7 @@ Officially tested: - OpenCode 2.x - Python 3, Node + npx, git, curl, tar -Optional host tools: Chromium, `gh`, browser-act, serena, semgrep, osv-scanner, gitleaks. +Optional host tools: Chromium, `gh`, browser-act, agent-reach, serena, semgrep, osv-scanner, gitleaks. ## Security model @@ -357,4 +371,4 @@ See [docs/security.md](docs/security.md). ## Provenance & Licenses -OpenCodeHighEnd is MIT-licensed for first-party installer, docs, overlays, and tests (see [LICENSE](LICENSE)). Selected skills are adapted from [mattpocock/skills](https://github.com/mattpocock/skills) (`9c9f36c`, MIT) and [cursor/plugins](https://github.com/cursor/plugins) `pstack/` pinned to `23e4138` (pstack 0.15.6, MIT) under OpenCode host conventions. Upstream vendored components and skills retain their original licenses as evidenced in [THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md). +OpenCodeHighEnd is MIT-licensed for first-party installer, docs, overlays, and tests (see [LICENSE](LICENSE)). Selected skills are adapted from [mattpocock/skills](https://github.com/mattpocock/skills) (`d81f3a1`, MIT) and [cursor/plugins](https://github.com/cursor/plugins) `pstack/` pinned to `23e4138` (pstack 0.15.6, MIT) under OpenCode host conventions. Upstream vendored components and skills retain their original licenses as evidenced in [THIRD_PARTY_NOTICES.md](THIRD_PARTY_NOTICES.md). diff --git a/THIRD_PARTY_NOTICES.md b/THIRD_PARTY_NOTICES.md index a6536f2..02170b3 100644 --- a/THIRD_PARTY_NOTICES.md +++ b/THIRD_PARTY_NOTICES.md @@ -6,7 +6,7 @@ First-party installer, docs, overlays, and tests are MIT (see `LICENSE`). This product vendors OpenCode-adapted skills and Design Intelligence runtime, originally snapshotted through GrokBestFriend 1.3.1 and ClaudeBestFriend 1.4.2-claude.1 (`05e6fdc`). -Selected skills also come from [mattpocock/skills](https://github.com/mattpocock/skills) (MIT © 2026 Matt Pocock) and [cursor/plugins](https://github.com/cursor/plugins) `pstack/` (`23e4138`, MIT © 2026 Lauren Tan). Full plugins are not installed. +Selected skills also come from [mattpocock/skills](https://github.com/mattpocock/skills) (`d81f3a1`, MIT © 2026 Matt Pocock) and [cursor/plugins](https://github.com/cursor/plugins) `pstack/` (`23e4138`, MIT © 2026 Lauren Tan). Full plugins are not installed. Licenses below are taken from vendored frontmatter or an obvious upstream statement. If a skill has no license in tree, this file says so. **That is not a grant.** @@ -16,7 +16,7 @@ Machine-readable copy: `vendor/license-audit.json`. | --- | --- | --- | --- | | `adhd` | vendored frontmatter | MIT | follow MIT | | `impeccable` | vendored frontmatter | Apache-2.0 | follow Apache-2.0 | -| Matt Pocock selected skills (`diagnosing-bugs`, `domain-modeling`, `codebase-design`, `writing-for-agents`, `research`, `prototype`, `improve-codebase-architecture`, `wizard`, `grill-with-docs`, `to-spec`, `to-tickets`, `tdd`, `matt-code-review` ← `code-review`) | mattpocock/skills MIT LICENSE — `vendor/licenses/MATT-POCOCK-MIT.txt` | MIT | follow MIT | +| Matt Pocock selected skills (`diagnosing-bugs`, `domain-modeling`, `codebase-design`, `writing-for-agents`, `research`, `prototype`, `improve-codebase-architecture`, `wizard`, `grill-with-docs`, `to-spec`, `to-tickets`, `tdd`, `matt-code-review` ← `code-review`) | mattpocock/skills `d81f3a1` MIT LICENSE — `vendor/licenses/MATT-POCOCK-MIT.txt` | MIT | follow MIT | | Pstack selected skills (`blast-radius`, `unslop`, `create-verification-skill`, `maintain-verification-skill`, `technical-writing`, `arena`, `interrogate`, `architect`, `decision-log`, `why`, `reflect`, `figure-it-out`) | cursor/plugins pstack `23e4138` | MIT — `vendor/licenses/PSTACK-MIT.txt` | follow MIT | | Snapshot skills (`browser-act`, `chrome-devtools-axi`, `emil-design-eng`, `found-this-design`, `full-audit-keamanan`, `full-performance-audit`, `gh-axi`, `scroll-world`, `visual-studio`) | GrokBestFriend 1.3.1 snapshot + `vendor/licenses/GROKBESTFRIEND-MIT.txt`; skill wrappers MIT. Separate CLIs follow their own packages. | MIT | follow MIT | | `scroll-world` | [oso95/scroll-world](https://github.com/oso95/scroll-world) `71cc36d` + GrokBestFriend snapshot; seam QA calibration note merged | MIT © 2026 cyw | follow MIT | @@ -24,9 +24,9 @@ Machine-readable copy: `vendor/license-audit.json`. | `playwright-qa` | [microsoft/playwright-cli](https://github.com/microsoft/playwright-cli) `655530f` — `vendor/licenses/MICROSOFT-PLAYWRIGHT-CLI-APACHE2.txt`; skill `NOTICE.md` | Apache-2.0 © Microsoft Corporation | follow Apache-2.0 | | `taste-guard` | [Leonxlnx/taste-skill](https://github.com/Leonxlnx/taste-skill) `ccbc156` — `vendor/licenses/LEONXLNX-TASTE-MIT.txt`; integrated in Impeccable | MIT © 2026 Leonxlnx | follow MIT | | `install-anti-slop` | [dmmulroy/anti-slop](https://github.com/dmmulroy/anti-slop) `e8c4880` — `vendor/licenses/DMMULROY-ANTI-SLOP-MIT.txt`; skill `NOTICE.md` | MIT © 2026 Dillon Mulroy | follow MIT | -| `humanizer` | [blader/humanizer](https://github.com/blader/humanizer) v3; skill `NOTICE.md` | MIT © 2024-2026 blader contributors | follow MIT | +| `humanizer` | [blader/humanizer](https://github.com/blader/humanizer) 3.1.0 (`225a6f3`); skill `NOTICE.md` | MIT © 2024-2026 blader contributors | follow MIT | | `academic` | Original first-party text. Conceptual pipeline (research→write→review→revise) independently implemented. No source copied from Imbad0202/academic-research-skills (CC-BY-NC-4.0). | MIT © 2026 OpenCodeHighEnd contributors | follow MIT | -| `hyperframes` | [heygen-com/hyperframes](https://github.com/heygen-com/hyperframes); skill `NOTICE.md` | Apache-2.0 | follow Apache-2.0 | +| `hyperframes` | [heygen-com/hyperframes](https://github.com/heygen-com/hyperframes) v0.8.119 (`3a0299e`); skill `NOTICE.md` | Apache-2.0 | follow Apache-2.0 | | `json-render` | [vercel-labs/json-render](https://github.com/vercel-labs/json-render) `c2600d73`; skill `NOTICE.md`. npm packages not vendored. | Apache-2.0 © 2025 Vercel Inc. | follow Apache-2.0 | | `deck-design` | [carnot-tech/consulting-pptx-skill](https://github.com/carnot-tech/consulting-pptx-skill) `f50edac`; skill `NOTICE.md`. 62-type packs not vendored. | MIT © carnot-tech contributors | follow MIT | | `pageindex` | [VectifyAI/PageIndex](https://github.com/VectifyAI/PageIndex) `037a7dba`; skill `NOTICE.md`. SDK/Cloud not vendored. | MIT © 2026 PageIndex AI / VectifyAI | follow MIT | @@ -38,6 +38,6 @@ Machine-readable copy: `vendor/license-audit.json`. | `ninerouter` | [decolua/9router](https://github.com/decolua/9router) `f01fb90`; skill `NOTICE.md`. First-party gateway stub; skills on-demand. | MIT © 2026 decolua | follow MIT | | Warehouse Batch 3a (`api-design`, `automation-audit-ops`, `click-path-audit`, `code-tour`, `contract-first`) | Adapted from [affaan-m/ECC](https://github.com/affaan-m/ECC); respective skill `NOTICE.md` files | MIT © 2024-2026 affaan-m and ECC contributors | follow MIT | | Design bank media | User-provided public bootstrap artifact or existing local bank | **not cleared** | not in git; normal install does not download it | -| Codebase Memory, serena, browser-act CLI, semgrep, gitleaks, osv-scanner | `vendor/sources.json` | upstream | follow upstream | +| Codebase Memory, serena, browser-act CLI, Scrapling, Agent-Reach CLI, semgrep, gitleaks, osv-scanner | `vendor/sources.json` | upstream; not vendored | follow upstream | See `vendor/provenance.json` and `vendor/sources.json` for pins. diff --git a/VERSION b/VERSION index 9767cc9..0e24a92 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -0.1.10 +0.1.12 diff --git a/docs/CATALOG-FREEZE.md b/docs/CATALOG-FREEZE.md index df99a36..404bb71 100644 --- a/docs/CATALOG-FREEZE.md +++ b/docs/CATALOG-FREEZE.md @@ -2,8 +2,10 @@ This contract defines the immutable boundary and governance for the OpenCodeHighEnd catalog. The 65-skill catalog is strictly frozen. -- **Product version**: 0.1.10 +- **Product version**: 0.1.12 - **Catalog**: 65 names. 50 model-invoked under `skills/`. 15 manual under `manual-skills/` + `commands/`. +- **Wave 0.1.12 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Upstream hyperframes refreshed to v0.8.119 (declarative data attributes, CLI render pipeline); awesome-opus5-5-videos added as first-party POINTER_ONLY prompt patterns reference; Matt Pocock cluster migrated to GLOSSARY.md convention with legacy CONTEXT.md fallback; dead game-asset-core references removed; humanizer bumped to v3.1.0 with patterns 25 & 26; diagram-design pinned to 2.6.51; impeccable v4.5.0 deferred. +- **Wave 0.1.11 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions. Adds closed intent `web_research` mapped to existing skill `research` (body-only update + `references/web-data.md`). Scrapling added as optional MCP `FOREIGN_ON_DEMAND`. Agent-Reach documented as `POINTER_ONLY` host CLI. Patchright-Enhanced strictly rejected. - **Wave 0.1.10**: catalog stays frozen at 65. No new exception. `found-this-design` indexes Oversight Supply; Design Bank bootstrap pin is DesignBank v3. pstack selected-skill provenance moves to `23e4138`; owned skill bodies are host adaptations, not an upstream body copy. `poteto-mode` stays rejected. - **Wave 0.1.9 body-only**: catalog strictly frozen at 65 (50 model + 15 manual). Zero catalog growth. No new exceptions; 0.1.8 exception is spent. Upstream `kaventro/motion-designer` merged into `business-motion-film` (product-film mode). - **Wave 0.1.8 limited unfreeze exception** (CHANGELOG 0.1.8): catalog stays 65 (50 model + 15 manual). Retired names: `img2threejs` (Three.js product-hero patterns moved to `business-motion-film` references), `prompt-optimizer` (overlaps `research` + `humanizer`). Added model-invoked: `business-motion-film` (from `echris6/motion-video-kit`, MIT), `ninerouter` (first-party gateway stub). Intent `img3d` replaced by `launch_film | gateway_llm`. This exception is spent. @@ -11,7 +13,7 @@ This contract defines the immutable boundary and governance for the OpenCodeHigh - **Retired in prior waves and not to be revived**: `ask-matt`, `grilling`, `wait-what`, `matt-implement`. - **Kept on purpose**: `wizard` (target-app bash wizard), `codebase-design` (new module), `/improve-codebase-architecture` (scan + HTML report). - **Name collision remains**: `install-anti-slop` = Oxlint; UI/copy filter lives in `impeccable` taste-gate + `humanizer`; `/unslop` = `humanizer`. -- **FOREIGN_ON_DEMAND stays out of the overlay**: `ECC`, `noodle`, `serena`, `stitch`, `reticle`, `ui-skills` MCP, `markitdown` MCP, `crawl4ai` MCP, `exa`, `Caliper`, `SkillEvaluator`, PageIndex Cloud MCP, `9router` capability skills. `doctor` must not fail when they are absent. +- **FOREIGN_ON_DEMAND stays out of the overlay**: `ECC`, `noodle`, `serena`, `stitch`, `reticle`, `ui-skills` MCP, `markitdown` MCP, `crawl4ai` MCP, `scrapling` MCP, `exa`, `Caliper`, `SkillEvaluator`, PageIndex Cloud MCP, `9router` capability skills. `doctor` must not fail when they are absent. - **No new allowlist name without retiring one existing name in the same change**, except a human-written CHANGELOG exception (the 0.1.7 growth is that exception; it is spent). - **No padding back to 64.** - **No `/how`, `/poteto-mode`, `/antislop`, `taste-skill`, `axi-core`, `human-atlas`, `awesome-design-md` vendor.** diff --git a/docs/mcp.md b/docs/mcp.md index 327a7d7..ad826d6 100644 --- a/docs/mcp.md +++ b/docs/mcp.md @@ -20,6 +20,7 @@ Optional: - `ui-skills` — `opencode-he ui-skills enable` (remote HTTP `https://www.ui-skills.com/mcp`; design-skill lookup only) - `markitdown` — `opencode-he markitdown enable` (local stdio via `uvx --from markitdown-mcp==0.1.8 markitdown-mcp`; Markdown ingest only) - `crawl4ai` — `opencode-he crawl4ai enable` (remote HTTP `http://127.0.0.1:11235/mcp`; cloud via `--cloud` with `{env:CRAWL4AI_KEY}`) +- `scrapling` — `opencode-he scrapling enable` (local stdio via `uvx --from scrapling[ai]==0.4.15 scrapling mcp`; structured web scraping) - `exa` — foreign; never add/remove/overwrite Merge is parse-aware. Comment-free JSON is rewritten with `json.dumps`. JSONC with comments is patched surgically (owned MCP keys only). If surgical merge cannot be verified, install fails closed instead of destroying comments. @@ -38,11 +39,14 @@ Doctor reports `CONFIGURED` for owned MCP entries present in config. That is not `opencode-he crawl4ai enable` configures Crawl4AI as an optional web content extraction remote MCP (`http://127.0.0.1:11235/mcp`). It is `FOREIGN_ON_DEMAND` for content extraction, not exploratory browser QA (which remains `playwright-qa`). For Docker users, bind strictly to `127.0.0.1:11235` (e.g. `docker run -p 127.0.0.1:11235:11235 ...`); never bind `0.0.0.0`. OpenCodeHighEnd does not launch or manage the container. With `--cloud`, it configures `https://api.crawl4ai.com/mcp` using `{env:CRAWL4AI_KEY}` without writing secrets to disk. `opencode-he crawl4ai disable` surgically removes only the crawl4ai server key. Absent is not a doctor failure; binding to `0.0.0.0` or invalid URLs fails closed. +`opencode-he scrapling enable` configures Scrapling as an optional local stdio MCP (`uvx --from scrapling[ai]==0.4.15 scrapling mcp`). It is `FOREIGN_ON_DEMAND` for structured web scraping and element extraction, not exploratory browser QA (which remains `playwright-qa`). Local stdio only: never `--http`, never bind `0.0.0.0`, never docker bind-all. Do not run `scrapling install` as it invokes `playwright install-deps` with sudo. The scraper is not vendored into `lib/`. `opencode-he scrapling disable` surgically removes only the scrapling server key. Absent is not a doctor failure; a malformed entry (including `--http` / `0.0.0.0`) fails closed. + ## Evaluated, Skipped & Rejected -- **Scrapling** — Evaluated against Crawl4AI and documented as an unmanaged alternative pointer; not registered as an MCP server, CLI command, or skill to avoid redundant surface. +- **Scrapling (`D4Vinci/Scrapling`)** — Promoted to `FOREIGN_ON_DEMAND` optional local stdio MCP in Wave 0.1.11 via `opencode-he scrapling enable` (pinned `0.4.15`). Not a core MCP; not vendored. Stdio only; `--http` and `0.0.0.0` forbidden. Never run `scrapling install`. - **TypeSafe Jev (`jev-mcp`)** — TypeSafe Jev / `jkudish/jev-mcp` was evaluated and is intentionally **SKIPPED** as a required runtime MCP. It is not vendored and not bundled in core MCPs. If ever manually configured by a user, it remains optional `FOREIGN_ON_DEMAND` only with `{env:TYPESAFE_API_KEY}`. Core verification, done-gates, and evidence ledgers operate fully offline without external Jev services. -- **Agent-Reach (`Panniantong/Agent-Reach`)** — Agent-Reach was evaluated and is strictly **REJECTED** as a core MCP or skill. It is not an alternative to Playwright QA eyes, carries ToS/cookie/account risks, and relies on Exa which is already designated `FOREIGN_ON_DEMAND`. Never register Agent-Reach as a core or required tool. +- **Agent-Reach (`Panniantong/Agent-Reach`)** — Evaluated and designated `POINTER_ONLY` host CLI under `research` (`references/web-data.md`) in Wave 0.1.11. Strictly **REJECTED** as a core MCP, optional MCP, or skill. Never run `agent-reach install --system` (mutates system packages and copies foreign skills into `~/.config/opencode/skills/`). Doctor detects foreign skill shadowing and warns. +- **Patchright-Enhanced (`whaleyxbt/patchright-enhanced`)** — Evaluated and strictly **REJECTED**. Unofficial fork; carries security, maintenance, and upstream divergence risks. Do not vendor, install, or reference. - **TypeSafe MCP (`itsmostafa/typesafe-mcp`)** — Evaluated and **REJECTED** as an extra core MCP. Core MCPs remain strictly `codebase-memory-mcp`, `context7`, and `shadcn`. - **Graphiti (`getzep/graphiti`) & Cognee (`topoteretes/cognee`)** — Evaluated and **REJECTED** as external memory MCP servers. Complex graph databases and temporal entity graph memory requiring separate backends/services are out of scope. Codebase indexing and symbol memory is strictly owned by `codebase-memory-mcp` (v0.11.0). Core MCPs remain strictly `codebase-memory-mcp`, `context7`, and `shadcn`. - **PageIndex Cloud MCP (`VectifyAI/PageIndex`)** — Skill `pageindex` is a first-party wrapper for tree/reasoning long-doc navigation. The Cloud/hosted MCP is **REJECTED** as an extra core MCP. Do not register it. Missing local SDK is `NOT_CONFIGURED` on the skill, not a doctor failure. diff --git a/docs/routing.md b/docs/routing.md index c6ac942..c1d3e76 100644 --- a/docs/routing.md +++ b/docs/routing.md @@ -19,7 +19,7 @@ Every user request is classified into exactly one closed intent: ```text repo_understand | bug | security | perf | ui_direction | ui_implement | generative_ui motion | scroll_2d | scroll_3d | launch_film | gateway_llm | docs | ingest_md | prose -academic | longdoc_nav | browser_qa | architecture | warehouse | ops_data | video_html | demo_id | slides_pptx +academic | longdoc_nav | web_research | browser_qa | architecture | warehouse | ops_data | video_html | demo_id | slides_pptx ``` | Intent | Primary Route | Handoff Boundary / Rule | @@ -43,6 +43,7 @@ academic | longdoc_nav | browser_qa | architecture | warehouse | ops_data | vide | `prose` | `humanizer` / `/unslop` | Prose AI-tell removal; technical docs stay `technical-writing` | | `academic` | `academic` | Literature surveys, IMRaD manuscripts, peer critique | | `longdoc_nav` | `pageindex` | Tree/reasoning nav of long structured docs; not Graphiti/Cognee/second CBM | +| `web_research` | `research` | Web/social data gathering (`references/web-data.md`); read-only, not QA | | `browser_qa` | `playwright-qa` → `browser-act` → `chrome-devtools-axi` → `click-path-audit` | 4-door hierarchy; isolated verification sessions | | `video_html` | `hyperframes` | Programmatic HTML-to-MP4 via headless Chrome + FFmpeg | | `demo_id` | `id-demo-video` (`/demo-video`) | Indonesian narrated app tour; cards via hyperframes | @@ -86,7 +87,7 @@ Browser verification follows four explicit doors: exploratory application UI rou Documents (answer, create, transform, extract, review, PDF/DOCX) route to `smartdoc`. Consulting PPTX / 16:9 slide decks route to `deck-design`. Long structured document tree/reasoning nav routes to `pageindex`. File-to-Markdown ingest routes to `markitdown`. Reusable book/module knowledge routes to `smartbook-ingest`. `/docx` and `/pdf` are missing aliases; nearest is `smartdoc`. `/pptx` routes to `deck-design`. Do not add `commands/pdf.md` or `commands/docx.md`. Impeccable `document` remains DESIGN.md generation. -Prose AI-tell removal and natural tone polishing route to `humanizer` (`/unslop` is its manual alias). Scholarly research, academic manuscripts, and structured peer critique route to `academic`. Deterministic HTML composition rendered to video routes to `hyperframes`. Demo video aplikasi, walkthrough layar, narasi Indonesia, dan demo lomba route to `id-demo-video` (bukan `hyperframes` untuk durasi panjang utuh, bukan `playwright-qa`, bukan `visual-studio`). Kartu judul HTML→MP4 tetap `hyperframes`. Editorial technical diagrams (HTML/SVG) route to `diagram-design`. +Prose AI-tell removal and natural tone polishing route to `humanizer` (`/unslop` is its manual alias). Scholarly research, academic manuscripts, and structured peer critique route to `academic`. Web and social data gathering routes to `research` (`references/web-data.md`; read-only, not QA). Deterministic HTML composition rendered to video routes to `hyperframes`. Demo video aplikasi, walkthrough layar, narasi Indonesia, dan demo lomba route to `id-demo-video` (bukan `hyperframes` untuk durasi panjang utuh, bukan `playwright-qa`, bukan `visual-studio`). Kartu judul HTML→MP4 tetap `hyperframes`. Editorial technical diagrams (HTML/SVG) route to `diagram-design`. Warehouse diagnostics load only when the user names the job: `agent-architecture-audit` (architecture layers), `cost-aware-llm-pipeline` (token budgeting), `eval-harness` (benchmarks), and `skill-stocktake` (catalog hygiene; `prompt-optimizer` retired in 0.1.8 with prompt critique splitting to `humanizer` / `research` / `writing-for-agents`). Gateway 9Router routing (chat, image, video, TTS, STT, embeddings, web search) routes to `ninerouter` via `NINEROUTER_URL` (not an extra core MCP). Wave 3 warehouse procedures route to `api-design` (REST resources), `contract-first` (consumer/provider contracts), `automation-audit-ops` (live inventory), and `code-tour` (guided tours). Foreign harnesses (such as ECC control plane) remain `FOREIGN_ON_DEMAND`; never vendored, auto-merged, or shadowed. diff --git a/docs/security.md b/docs/security.md index 5937bab..b219fd7 100644 --- a/docs/security.md +++ b/docs/security.md @@ -16,6 +16,8 @@ - Design V2 import rejects common API tokens, private-key headers, credential-bearing database URLs, unsafe links, traversal, and oversized input; normalized assets replace rather than merge prior destinations. - Design V2 doctor checks catalog JSONL and SQLite hashes against the canonical lock. - Model/provider names are opaque; do not print tokens or gateway maps +- Scrapling is local stdio only (`uvx`); `--http` mode, `0.0.0.0` host binding, and Docker bind-all are strictly rejected. Never run `scrapling install` as it invokes `playwright install-deps` with sudo. Web scraping is read-only; never extract or store user desktop browser cookies or sessions (`--from-browser` is banned). +- Agent-Reach is pointer-only; running `agent-reach install --system` is prohibited. Unmanaged skill directories in `~/.config/opencode/skills/` without `.opencode-highend.json` trigger `FOREIGN_SKILL_SHADOW` warnings in `doctor`. - `vendor/license-audit.json` lists every skill license **as evidenced**. Snapshot skills inherit GrokBestFriend MIT (`vendor/licenses/GROKBESTFRIEND-MIT.txt`). Design-bank media remains not-cleared. - GitHub rulesets: `main` and `v*` tags cannot be force-pushed or deleted. Signed commits/tags are `DEFERRED` until a maintainer signing key exists. GitHub release immutability is `NOT_CONFIGURED`. Integrity baseline is tag protection plus SHA256SUMS, SPDX SBOM, and `release-provenance.json`. diff --git a/docs/source-wave.md b/docs/source-wave.md index f58d23c..88e544d 100644 --- a/docs/source-wave.md +++ b/docs/source-wave.md @@ -28,7 +28,7 @@ Recorded per Phase 0 contract. | [ai-boost/awesome-harness-engineering](https://github.com/ai-boost/awesome-harness-engineering) | upstream ref | Agent harness patterns, context hygiene, fail-closed gates. | **MERGE** | `templates/AGENTS.md`, `docs/architecture.md`, `rules/00-routing.md` | Merge harness-over-model, artifact-gated specialist graph, and context boundary principles. | | [PaulRBerg/agent-skills](https://github.com/PaulRBerg/agent-skills) | upstream ref | Agent coding skills and engineering conventions. | **CHERRY-PICK** | `rules/00-routing.md`, `skills/codebase-design/` | Cherry-pick module interface and seam principles. Do not vendor catalog; `frontend-design` must not become a skill. | | [confident-ai/deepteam](https://github.com/confident-ai/deepteam) | `latest` / Apache-2.0 | LLM red-teaming and OWASP LLM Top 10 evaluation framework. | **OPTIONAL_POINTER** | `skills/full-audit-keamanan/SKILL.md`, `skills/eval-harness/SKILL.md` | Documented as external maintainer-side red-team framework pointer. Zero overlay dependencies, non-vendored. | -| [Panniantong/Agent-Reach](https://github.com/Panniantong/Agent-Reach) | upstream ref | Headless browser reaching and web crawling agent tool. | **REJECT** / **FOREIGN** | None (`docs/mcp.md`) | Reject as core MCP or skill. Not exploratory QA eyes; carries ToS/cookie risk; Exa is already designated FOREIGN_ON_DEMAND. | +| [Panniantong/Agent-Reach](https://github.com/Panniantong/Agent-Reach) | `f65526cbaaad3879473acc1ba6dbefd195caf2be` (v1.5.0) | Zero-config developer feeds and social platform reach CLI. MIT. | **POINTER_ONLY** | `skills/research/references/web-data.md` | Pointer-only host CLI. Not an MCP, not a skill. Never run `agent-reach install --system` (mutates packages / copies foreign skills). Doctor detects shadowing. | | [emilkowalski/emil-design-eng](https://github.com/emilkowalski) | animations.dev | Design engineering, interaction feel, and spring physics. | **MERGE** | `skills/emil-design-eng/references/` | Body landed (`motion.md`, `apple-principles.md`, `native-motion.md`, `interface-feel.md`). Not an open UPDATE. Zero new skill names. | | [emilkowalski/apple-design](https://github.com/emilkowalski) + [wshobson/interaction-design](https://github.com/wshobson/interaction-design) | upstream refs | Apple-grade tactile motion, velocity inheritance, interruptible springs. | **MERGE** | `skills/emil-design-eng/references/interface-feel.md` | Merge interruptible springs, velocity inheritance, and tactile press feedback. Never an Apple-clone skill. | | [mengto/beautiful-shadows](https://github.com/mengto) + [pbakaus/adapt](https://github.com/pbakaus) + [superfuture/design-review](https://github.com/superfuture) | upstream refs | Multi-layer ambient shadows, adaptive container queries, and design review checklists. | **MERGE** | `skills/emil-design-eng/references/interface-feel.md`, `skills/impeccable/reference/audit.md` | Merged bounded checklist items (≤15 bullets total). No new skill. | @@ -39,12 +39,13 @@ Recorded per Phase 0 contract. | [CosmoBlk/email-design](https://github.com/CosmoBlk/email-design) + [jayesh-bansal/email-pro-max](https://github.com/jayesh-bansal/email-pro-max) + [chunkydotdev/email-skills](https://github.com/chunkydotdev/email-skills) + [Olshansk/agent-skills](https://github.com/Olshansk/agent-skills) | upstream refs (`c56bfe0`, `6a28b31`, `dca18fc`, `d43745c`) | Anti-slop email design, 6 archetypes, and bulletproof multi-client HTML email rendering. MIT. | **MERGE** | `skills/impeccable/reference/email.md` | Merged into single reference under Impeccable; strict tables, inline CSS, 6-digit hex, bulletproof CTA, preheader anti-spill padding, framework exemption for React Email/MJML. No new skill. | | [emilkowalski/skills](https://github.com/emilkowalski/skills) | `85e8e2363b71` | Animation recipes, WWDC fluid interface design, mobile web polish, and Expo motion. MIT. | **MERGE** | `skills/emil-design-eng/references/` | Merged `motion.md`, `apple-principles.md`, and `native-motion.md` into references. Zero new skill names, exact catalog freeze maintained. | | [DeusData/codebase-memory-mcp](https://github.com/DeusData/codebase-memory-mcp) | `v0.11.0` | Codebase indexing and symbol memory MCP server. | **DONE** | `vendor/sources.json`, `lib/install.py`, `lib/cbm.py` | Shipped in 0.1.4: binary pinned to 0.11.0 with SHA-256 verification and automatic `--format json` argument propagation. | -| [heygen-com/hyperframes](https://github.com/heygen-com/hyperframes) | `ed75203cb6aa` (v0.8.64) | Deterministic HTML/CSS video composition. Apache-2.0. | **PIN_ONLY** | `skills/hyperframes` | Pinned commit `ed75203cb6aa` in `vendor/sources.json`. Skill body unchanged. | -| [cathrynlavery/diagram-design](https://github.com/cathrynlavery/diagram-design) | `dc1ace47b99a` (v2.6.33) | Editorial HTML/SVG diagram design. MIT. | **PIN_ONLY** | `skills/diagram-design` | Pinned commit `dc1ace47b99a` in `vendor/sources.json`. Skill body unchanged. | -| [blader/humanizer](https://github.com/blader/humanizer) | `3.0.0` | AI prose humanizing and slop removal. MIT. | **PIN_ONLY** | `skills/humanizer` | Pinned v3.0.0 in `vendor/sources.json`. Skill body unchanged. | +| [heygen-com/hyperframes](https://github.com/heygen-com/hyperframes) | `3a0299e851ce` (v0.8.119) | Deterministic HTML/CSS video composition. Apache-2.0. | **REFRESH** | `skills/hyperframes` | Updated in Wave 0.1.12 to declarative data attributes (data-composition-id, data-start/data-duration), CLI render path, and Node >=22 prerequisite. | +| [cathrynlavery/diagram-design](https://github.com/cathrynlavery/diagram-design) | `f903933a534b` (v2.6.51) | Editorial HTML/SVG diagram design. MIT. | **PIN_ONLY** | `skills/diagram-design` | Pinned commit f903933a534b in vendor/sources.json. | +| [blader/humanizer](https://github.com/blader/humanizer) | `225a6f39ac85` (v3.1.0) | AI prose humanizing and slop removal. MIT. | **REFRESH** | `skills/humanizer` | Updated in Wave 0.1.12 to v3.1.0 with patterns 25 & 26 (writing about the document, re-explaining known context). | | [semgrep / gitleaks / osv-scanner](https://github.com) | `semgrep` 1.177.0, `gitleaks` 8.30.1, `osv-scanner` 2.6.0 | Host security scanners. | **PIN_ONLY** | `skills/full-audit-keamanan` | Host scanner version pins recorded in `vendor/sources.json`. | | [unclecode/crawl4ai](https://github.com/unclecode/crawl4ai) | upstream ref | LLM-friendly web crawler & scraper MCP. Apache-2.0. | **FOREIGN_ON_DEMAND** | `docs/mcp.md` | Optional remote MCP (`http://127.0.0.1:11235/mcp`, cloud via `--cloud`). Not vendored. Content extraction only, not exploratory QA eyes (`playwright-qa`). Bind strictly 127.0.0.1, never 0.0.0.0. | -| [D4Vinci/Scrapling](https://github.com/D4Vinci/Scrapling) | upstream ref | Undetectable web scraping library. | **POINTER_ONLY** | `docs/mcp.md` | Evaluated against Crawl4AI. Kept as documentation pointer only; not registered as MCP, CLI command, or skill. | +| [D4Vinci/Scrapling](https://github.com/D4Vinci/Scrapling) | `333fa22b7a5821194ce66b59b11f4b16a6484f02` (v0.4.15) | Fast, undetectable web scraping library with adaptive selectors. BSD-3-Clause. | **FOREIGN_ON_DEMAND** | `vendor/sources.json`, `docs/mcp.md`, `skills/research/references/web-data.md` | Promoted to optional local stdio MCP (`uvx --from scrapling[ai]==0.4.15 scrapling mcp`). Not vendored. No `--http` or `0.0.0.0`. Never run `scrapling install`. | +| [whaleyxbt/patchright-enhanced](https://github.com/whaleyxbt/patchright-enhanced) | upstream ref | Unofficial patched browser automation fork. | **REJECT** | None | Strictly rejected. Unofficial fork; carries security, maintenance, and divergence risks. | | [latent-spaces/brag](https://github.com/latent-spaces/brag) | `0.4.0` / upstream ref | 18-20s product launch video card recipe using HyperFrames. MIT. | **DONE** | `skills/hyperframes/references/brag.md` | Synthesized in 0.1.5 into `references/brag.md` (4-beat narrative contract, 60fps, 1080p, seekable frame timeline). Zero catalog bloat. | | [genspark-ai/genoffice](https://github.com/genspark-ai/genoffice) | upstream ref | AI-native desktop office suite (Docs, Sheets, Slides, PDF, Markdown). Apache-2.0. | **REJECT** | None | Multi-app Electron desktop suite requiring Genspark accounts/local models. Desktop app, not an agent coding skill overlay. | | [hardbeat920/monocode](https://github.com/hardbeat920/monocode) | upstream ref | Desktop GUI for coding agents (Tauri + Rust + React). MIT. | **REJECT** | None | External desktop host UI wrapping CLI agents. Not an agent skill. | @@ -72,3 +73,6 @@ Recorded per Phase 0 contract. | [Skill Seekers](https://github.com) | upstream ref | Automatic skill discovery, extraction, and scraper. | **REJECT** | None | Automated skill scraping bloat rejected. Catalog is strictly frozen at 65. | | [adhd](https://github.com) | upstream ref | Divergent ideation specialist for coding agents. MIT. | **DONE** | `skills/adhd` | Sudah dimiliki (shipped in foundation). | | [SkillSpector](https://github.com) | upstream ref | Skill catalog evaluation and quality inspection. | **FOREIGN_ON_DEMAND** | `docs/mcp.md` | External evaluation tool; not vendored into overlay core. | +| [yihui-dev/awesome-opus5-5-videos](https://github.com/yihui-dev/awesome-opus5-5-videos) | `3d54892e2ae5b0e8d337171e6508bba4cec01ab8` (2026-09-29) | Curated gallery of code-driven animation/video prompts (475 community creations). | **POINTER_ONLY** | `skills/hyperframes/references/prompt-patterns.md` | First-party POINTER_ONLY reference for prompt translation and quality gates. Zero upstream prompts, media, or proprietary marks vendored. | +| [pbakaus/impeccable](https://github.com/pbakaus/impeccable) (v4.5.0) | `skill-v4.5.0` (`508d7e8955de`) | Impeccable frontend design skill suite upstream version update. Apache-2.0. | **EVALUATED/DEFERRED** | `skills/impeccable` | Evaluated in Wave 0.1.12: upstream introduces subagent architectural restructuring and tool assumptions; deferred to protect catalog freeze and established design-gate contracts. Pin retained at skill-v4.3.1. | +| [mattpocock/skills](https://github.com/mattpocock/skills) | `d81f3a183412e71a5b1e84ca21bc1a35eea03a60` (v1.3) | Matt Pocock selected skills and shared glossary update (`GLOSSARY.md` migration). MIT. | **MERGE** | Matt cluster (`skills/diagnosing-bugs`, `domain-modeling`, `codebase-design`, `writing-for-agents`, `research`, `prototype`, `improve-codebase-architecture`, `wizard`, `grill-with-docs`, `to-spec`, `to-tickets`, `tdd`, `matt-code-review`) | Upstream migrated shared glossary definitions to `GLOSSARY.md`. Merged upstream updates while maintaining OpenCode host isolation, backward compatibility for existing `CONTEXT.md`, and catalog freeze. | diff --git a/docs/troubleshooting.md b/docs/troubleshooting.md index 64d7f44..1c6af08 100644 --- a/docs/troubleshooting.md +++ b/docs/troubleshooting.md @@ -30,6 +30,10 @@ Doctor `OPTIONAL_ABSENT` is not a core failure. `DEGRADED` is non-fatal unless ` `FAIL mcp:crawl4ai` — Crawl4AI must bind to `http://127.0.0.1:11235/mcp` (or cloud `https://api.crawl4ai.com/mcp` with `{env:CRAWL4AI_KEY}`). Binding to `0.0.0.0`, using raw secret keys, or using non-standard URLs triggers a FAIL. Reconfigure with `opencode-he crawl4ai enable` (or `--cloud`). +`FAIL mcp:scrapling` — Scrapling MCP must use `type: local`, command starting with `uvx`, pinned package `scrapling[ai]==`, and end with `scrapling mcp`. Any use of `--http`, `0.0.0.0`, docker, or unpinned package fails closed. Reconfigure with `opencode-he scrapling enable`. + +`WARN FOREIGN_SKILL_SHADOW` — A foreign directory (such as `agent-reach` or `scrapling-official`) was detected in `~/.config/opencode/skills/` without an `.opencode-highend.json` ownership marker. These foreign skills hijack router intents and violate the frozen catalog. Delete the unmanaged skill directory manually. + `doctor --deep` exit 1 with `NOT_CHECKED` — `opencode mcp list` failed or was empty; core MCP is not proven live. Restart OpenCode after install. diff --git a/lib/cli.py b/lib/cli.py index 6632647..358f5e5 100755 --- a/lib/cli.py +++ b/lib/cli.py @@ -30,6 +30,8 @@ cmd_markitdown_enable, cmd_reticle_disable, cmd_reticle_enable, + cmd_scrapling_disable, + cmd_scrapling_enable, cmd_serena_enable, cmd_stitch_disable, cmd_stitch_enable, @@ -125,6 +127,9 @@ def build_parser() -> argparse.ArgumentParser: c4.add_argument("action", choices=["enable", "disable"]) c4.add_argument("--cloud", action="store_true", help="use cloud endpoint with CRAWL4AI_KEY instead of local container") + sc = sub.add_parser("scrapling", help="optional Scrapling local stdio MCP") + sc.add_argument("action", choices=["enable", "disable"]) + sd = sub.add_parser("smartdoc", help="document profiles, extract, status") add_smartdoc_cli(sd) sb = sub.add_parser("smartbook", help="reusable SmartBook lifecycle") @@ -200,6 +205,10 @@ def main(argv: list[str] | None = None) -> int: if args.action == "enable": return cmd_crawl4ai_enable(cloud=args.cloud) return cmd_crawl4ai_disable() + if cmd == "scrapling": + if args.action == "enable": + return cmd_scrapling_enable() + return cmd_scrapling_disable() if cmd == "smartdoc": return dispatch_smartdoc(args) if cmd == "smartbook": diff --git a/lib/doctor.py b/lib/doctor.py index 65ddeae..7e8c864 100644 --- a/lib/doctor.py +++ b/lib/doctor.py @@ -118,14 +118,14 @@ def mcp_status_map() -> dict[str, str]: try: data = jsonc.load_path(cfg) except (OSError, json.JSONDecodeError, ValueError): - return {k: "FAIL" for k in ("codebase-memory-mcp", "context7", "shadcn", "serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "exa")} + return {k: "FAIL" for k in ("codebase-memory-mcp", "context7", "shadcn", "serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "scrapling", "exa")} mcp = data.get("mcp") or {} if not isinstance(mcp, dict): - return {k: "FAIL" for k in ("codebase-memory-mcp", "context7", "shadcn", "serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "exa")} + return {k: "FAIL" for k in ("codebase-memory-mcp", "context7", "shadcn", "serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "scrapling", "exa")} servers = jsonc.mcp_servers_from_config(data) owned = {"codebase-memory-mcp", "context7", "shadcn"} - optional = {"serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "exa"} - for name in ("codebase-memory-mcp", "context7", "shadcn", "serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "exa"): + optional = {"serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "scrapling", "exa"} + for name in ("codebase-memory-mcp", "context7", "shadcn", "serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "scrapling", "exa"): spec = servers.get(name) if spec is None: out[name] = "OPTIONAL_ABSENT" if name in optional else "FAIL" @@ -219,6 +219,41 @@ def mcp_status_map() -> dict[str, str]: continue out[name] = "CONFIGURED" continue + if name == "scrapling": + typ = spec.get("type") + cmd = spec.get("command") + if typ != "local" or not isinstance(cmd, list) or not cmd: + out[name] = "FAIL" + continue + if cmd[0] != "uvx": + out[name] = "FAIL" + continue + joined = " ".join(str(part) for part in cmd) + forbidden = ( + "--http", + "--host", + "--port", + "--no-auth", + "--auth-token", + "--allowed-host", + "0.0.0.0", + "docker", + ) + if any(bad in joined for bad in forbidden): + out[name] = "FAIL" + continue + pinned = any( + isinstance(part, str) and re.fullmatch(r"^scrapling\[ai\]==\d+\.\d+\.\d+$", part) + for part in cmd + ) + if not pinned: + out[name] = "FAIL" + continue + if len(cmd) < 2 or [str(cmd[-2]), str(cmd[-1])] != ["scrapling", "mcp"]: + out[name] = "FAIL" + continue + out[name] = "CONFIGURED" + continue if name not in owned: out[name] = "FOREIGN" continue @@ -492,6 +527,32 @@ def _browser_qa_findings(f: Findings) -> None: f.add("OPTIONAL_ABSENT", "BrowserAct CLI", "NOT_INSTALLED") +def _research_tools_findings(f: Findings) -> None: + ar = which("agent-reach") + if ar: + try: + r = run([ar, "--version"]) + ver = (r.stdout or r.stderr or "").strip() + if r.returncode == 0: + f.add("PASS", "Agent-Reach CLI", f"{ar} {ver}") + else: + f.add("DEGRADED", "Agent-Reach CLI", f"{ar} (version check failed)") + except (OSError, ValueError): + f.add("DEGRADED", "Agent-Reach CLI", f"{ar} (version check failed)") + else: + f.add("OPTIONAL_ABSENT", "Agent-Reach CLI", "NOT_INSTALLED") + + skills_dir = config_dir() / "skills" + for shadow_name in ("agent-reach", "scrapling-official"): + cand = skills_dir / shadow_name + if cand.is_dir() and not (cand / ".opencode-highend.json").is_file(): + f.add( + "WARN", + "FOREIGN_SKILL_SHADOW", + f"{shadow_name}: foreign skill hijacking router; delete manually", + ) + + def _permission_findings(f: Findings) -> None: cfg = None for cand in (config_dir() / "opencode.jsonc", config_dir() / "opencode.json"): @@ -749,6 +810,7 @@ def cmd_doctor(deep: bool = False, strict: bool = False) -> int: print("--- optional ---") _host_findings(f, shadcn_enabled=shadcn_enabled) _browser_qa_findings(f) + _research_tools_findings(f) _permission_findings(f) _plugin_findings(f) print("--- context ---") diff --git a/lib/install.py b/lib/install.py index 49b2076..3e9c99a 100644 --- a/lib/install.py +++ b/lib/install.py @@ -966,7 +966,7 @@ def take(src: Path, dest: Path) -> None: "modelInvokedSkills": meta["model"], "manualSkills": meta["manual"], "ownedMcp": list(OWNED_MCP), - "optionalMcp": ["serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "exa"], + "optionalMcp": ["serena", "stitch", "reticle", "ui-skills", "markitdown", "crawl4ai", "scrapling", "exa"], "designBank": { "root": bank_root, "source": bank_source, @@ -1533,3 +1533,20 @@ def cmd_crawl4ai_disable() -> int: return _optional_mcp_disable("crawl4ai") +def cmd_scrapling_enable() -> int: + spec: dict[str, object] = { + "type": "local", + "command": ["uvx", "--from", "scrapling[ai]==0.4.15", "scrapling", "mcp"], + "disabled": False, + } + rc = _optional_mcp_enable("scrapling", spec) + if not which("uvx"): + info("uvx not found on PATH; install uv (or uvx) to run scrapling stdio MCP. Do not run `scrapling install` as it invokes `playwright install-deps` with sudo.") + return rc + + +def cmd_scrapling_disable() -> int: + return _optional_mcp_disable("scrapling") + + + diff --git a/manual-skills/improve-codebase-architecture/SKILL.md b/manual-skills/improve-codebase-architecture/SKILL.md index 738ca23..d29656e 100644 --- a/manual-skills/improve-codebase-architecture/SKILL.md +++ b/manual-skills/improve-codebase-architecture/SKILL.md @@ -11,7 +11,7 @@ Surface architectural friction and propose **deepening opportunities** — refac This command is _informed_ by the project's domain model and built on a shared design vocabulary: - Use the **codebase-design** vocabulary as a shared discipline (**module**, **interface**, **depth**, **seam**, **adapter**, **leverage**, **locality**) and its principles (the deletion test, "the interface is the test surface", "one adapter = hypothetical seam, two = real"). Do not invoke `/codebase-design` as a skill unless the user asked. Use these terms exactly in every suggestion — don't drift into "component," "service," "API," or "boundary." -- The domain language in `CONTEXT.md` gives names to good seams; ADRs in `docs/adr/` record decisions this command should not re-litigate. +- The domain language in `GLOSSARY.md` gives names to good seams; ADRs in `docs/adr/` record decisions this command should not re-litigate. ## Process @@ -22,7 +22,7 @@ This command is _informed_ by the project's domain model and built on a shared d - If the user named a direction — a module, a subsystem, a pain point — take it, and skip the inference below. - Otherwise, walk back a good stretch of the commit history (`git log --oneline`) to find the codebase's hot spots — the files and areas that keep coming up — and let those paths pull your attention first. If the changes are scattered with no clear hot spot, widen the net. -Read the project's domain glossary (`CONTEXT.md`) and any ADRs in the area you're touching first. +Read the project's domain glossary (`GLOSSARY.md`) and any ADRs in the area you're touching first. Then spawn a sub-agent to walk the codebase. Don't follow rigid heuristics — explore organically and note where you experience friction: @@ -51,7 +51,7 @@ For each candidate, render a card with: End the report with a **Top recommendation** section: which candidate you'd tackle first and why. -**Use CONTEXT.md vocabulary for the domain, and the `/codebase-design` vocabulary for the architecture.** If `CONTEXT.md` defines "Order," talk about "the Order intake module" — not "the FooBarHandler," and not "the Order service." +**Use GLOSSARY.md vocabulary for the domain, and the `/codebase-design` vocabulary for the architecture.** If `GLOSSARY.md` defines "Order," talk about "the Order intake module" — not "the FooBarHandler," and not "the Order service." **ADR conflicts**: if a candidate contradicts an existing ADR, only surface it when the friction is real enough to warrant revisiting the ADR. Mark it clearly in the card (e.g. a warning callout: _"contradicts ADR-0007 — but worth reopening because…"_). Don't list every theoretical refactor an ADR forbids. @@ -61,11 +61,11 @@ Do NOT propose interfaces yet. After the file is written, ask the user: "Which o ### 3. Frontier decision loop -Once the user picks a candidate, walk the decision tree with them using frontier rounds inline — constraints, dependencies, the shape of the deepened module, what sits behind the seam, what tests survive. Use `grill-with-docs` if creating or updating CONTEXT.md and ADRs. +Once the user picks a candidate, walk the decision tree with them using frontier rounds inline — constraints, dependencies, the shape of the deepened module, what sits behind the seam, what tests survive. Use `grill-with-docs` if creating or updating GLOSSARY.md and ADRs. Side effects happen inline as decisions crystallize — keep the domain model current using domain-modeling discipline (glossary/ADR), without invoking `/domain-modeling` unless the user asked: -- **Naming a deepened module after a concept not in `CONTEXT.md`?** Add the term to `CONTEXT.md`. Create the file lazily if it doesn't exist. -- **Sharpening a fuzzy term during the conversation?** Update `CONTEXT.md` right there. +- **Naming a deepened module after a concept not in `GLOSSARY.md`?** Add the term to `GLOSSARY.md`. Create the file lazily if it doesn't exist. +- **Sharpening a fuzzy term during the conversation?** Update `GLOSSARY.md` right there. - **User rejects the candidate with a load-bearing reason?** Offer an ADR, framed as: _"Want me to record this as an ADR so future architecture reviews don't re-suggest it?"_ Only offer when the reason would actually be needed by a future explorer to avoid re-suggesting the same thing — skip ephemeral reasons ("not worth it right now") and self-evident ones. - **Want to explore alternative interfaces for the deepened module?** Apply codebase-design's design-it-twice pattern inline. Do not invoke `/codebase-design` unless the user asked. diff --git a/manual-skills/why/SKILL.md b/manual-skills/why/SKILL.md index 3bda8e3..78c95ef 100644 --- a/manual-skills/why/SKILL.md +++ b/manual-skills/why/SKILL.md @@ -15,7 +15,7 @@ This is not `/research` (official docs, specs, first-party APIs). This is not `/ Use these every run: - git: `blame`, `log --follow`, merge commits -- repo docs: `CONTEXT.md`, `docs/adr/`, README, comments, tests +- repo docs: `GLOSSARY.md`, `docs/adr/`, README, comments, tests - `gh` **if already authenticated**: PR bodies, reviews, linked issues Do **not** install Slack, Sentry, Datadog, Linear, Notion, or any other MCP from this skill. Optional sources only if the tool is already connected. A missing optional source is `NOT_CONFIGURED`, not a reason to add it. diff --git a/rules/00-routing.md b/rules/00-routing.md index a651186..eacab25 100644 --- a/rules/00-routing.md +++ b/rules/00-routing.md @@ -28,7 +28,7 @@ The router classifies every user task into exactly one closed intent: ```text repo_understand | bug | security | perf | ui_direction | ui_implement | generative_ui motion | scroll_2d | scroll_3d | launch_film | gateway_llm | docs | ingest_md | prose -academic | longdoc_nav | browser_qa | architecture | warehouse | ops_data | video_html | demo_id | slides_pptx +academic | longdoc_nav | web_research | browser_qa | architecture | warehouse | ops_data | video_html | demo_id | slides_pptx ``` | Intent | Primary Route | Handoff Boundary / Rule | @@ -52,6 +52,7 @@ academic | longdoc_nav | browser_qa | architecture | warehouse | ops_data | vide | `prose` | `humanizer` / `/unslop` | Prose AI-tell removal; technical docs stay `technical-writing` | | `academic` | `academic` | Literature surveys, IMRaD manuscripts, peer critique | | `longdoc_nav` | `pageindex` | Tree/reasoning nav of long structured docs; not Graphiti/Cognee/second CBM | +| `web_research` | `research` | Web/social data gathering (`references/web-data.md`); read-only, not QA | | `browser_qa` | `playwright-qa` → `browser-act` → `chrome-devtools-axi` → `click-path-audit` | 4-door hierarchy; isolated verification sessions | | `video_html` | `hyperframes` | Programmatic HTML-to-MP4 via headless Chrome + FFmpeg | | `demo_id` | `id-demo-video` (`/demo-video`) | Indonesian narrated app tour; cards via hyperframes | @@ -92,10 +93,11 @@ Never list unused tools or uncalled MCP methods as used. - Current library or framework docs: MCP `context7` only when repo evidence is insufficient. - Installable React/shadcn registry items: MCP `shadcn` (pinned CLI `shadcn@4.21.0`). Search, inspect, then install. Context7 stays documentation. - Broader web research: built-in `WebSearch` and `WebFetch`. MCP `exa` is foreign/pre-existing and ON_DEMAND. Use it only if already connected and research needs it. Never add or remove `exa`. +- Web and social data gathering: `/research` (follow the backend ladder in `references/web-data.md`; Scrapling is optional `FOREIGN_ON_DEMAND`; Agent-Reach is pointer-only; read-only; not `/playwright-qa`). - Hard, high-impact, divergent decisions, fuzzy debugging, API or schema alternatives, trap detection: `/adhd` on demand only. Skip ADHD for typos, ordinary CRUD, or bugs with a known cause. - Official library, spec, or first-party API facts: `/research` (Context7 when repo evidence is not enough). Why *this repo* chose an approach: suggest `/why` (manual). Do not mix the two. - Scholarly literature surveys, academic manuscripts (IMRaD/thesis/proposal), and structured peer critique: `/academic` (not `research`, not `smartdoc` unless file extract/render). -- Fuzzy or conflicting domain terms, glossary, CONTEXT.md / ADR writing: `/domain-modeling`. Full product interviews that should leave CONTEXT.md/ADRs: `/grill-with-docs`. +- Fuzzy or conflicting domain terms, glossary, GLOSSARY.md / ADR writing: `/domain-modeling`. Full product interviews that should leave GLOSSARY.md/ADRs: `/grill-with-docs`. - Module, interface, seam, testability, abstraction: `/codebase-design` (distinct from `/api-design` for REST and `/contract-first` for machine schemas). Multi-sketch bake-off: suggest `/architect` (manual). Do not auto-start `/architect`. - Throwaway evidence for one design question: `/prototype`. Not for production UI; skip ordinary implementation, ADHD, and `/arena`. Schema/JSON generative UI: `/json-render`. - Unknown / hard bugs, regressions, measured slowdown: `/diagnosing-bugs`. Skip typos, known-cause, and test-first known fixes (`/tdd`). @@ -143,7 +145,7 @@ The specialist architecture forms a deterministic graph connected by file artifa - Scroll-led storytelling (scroll is the timeline, scrollytelling, signature interaction): `/scroll-craft`. Ordinary scrollable UI stays `/impeccable`. `/scroll-craft` plus Continuous World: Scroll Craft writes the brief, then `/scroll-world`. - Continuous camera fly-through, diorama, or 3D-world landing: `/scroll-world` even if the request says scroll. - Commercials, launch films, business explainers, sample reels, pitch videos: `/business-motion-film` (render via `hyperframes`; includes real app UI product-film mode; Three.js product-hero patterns in references, not a standalone skill; 18s brag cards stay `hyperframes/references/brag.md`). Indonesian narrated tours stay `/id-demo-video`. Not `scroll-world` (camera fly-through), not `visual-studio` (photoreal stills/media), and not `impeccable` (product UI). -- Deterministic HTML composition rendered to video: `/hyperframes` (headless Chrome + FFmpeg; 18s brag/launch cards via `references/brag.md`). Not `visual-studio`, not `emil-design-eng`. Ordinary scrollable UI stays `/impeccable`. +- Deterministic HTML composition rendered to video: `/hyperframes` (headless Chrome + FFmpeg; 18s brag/launch cards via `references/brag.md`; code-video prompt galleries → `hyperframes/references/prompt-patterns.md` (POINTER_ONLY)). Not `visual-studio`, not `emil-design-eng`. Ordinary scrollable UI stays `/impeccable`. - Demo video aplikasi, walkthrough layar, narasi Indonesia, demo lomba: skill `id-demo-video` (bukan `hyperframes` untuk durasi panjang utuh, bukan `playwright-qa`, bukan `visual-studio`). Kartu judul HTML→MP4 tetap `hyperframes`. - Photoreal stills / ads / identity with no UI surface: `/visual-studio`. - Motion after Impeccable: `/emil-design-eng`. @@ -184,7 +186,7 @@ The specialist architecture forms a deterministic graph connected by file artifa ## Plugins and extra MCP - No extra marketplace plugins. Foundation = skills + MCP + thin AGENTS.md + runtime helpers. -- User MCP: `codebase-memory-mcp`, `context7`, and `shadcn` on; `serena`, `stitch`, `reticle`, and `ui-skills` absent until a human enables them; `exa` foreign. +- User MCP: `codebase-memory-mcp`, `context7`, and `shadcn` on; `serena`, `stitch`, `reticle`, `ui-skills`, `markitdown`, `crawl4ai`, and `scrapling` absent until a human enables them; `exa` foreign. - ECC / other harness overlays: `FOREIGN_ON_DEMAND`. Never add, remove, or merge foreign harness control planes or continuous-learning runtimes. Individual warehouse procedures ported in Wave 2 (agent-architecture-audit, cost-aware-llm-pipeline, eval-harness, skill-stocktake; prompt-optimizer retired in 0.1.8) and Wave 3 (api-design, contract-first, automation-audit-ops, code-tour, click-path-audit) are first-party MIT skills. If external ECC is already present in user environment, do not merge and do not shadow. - FOREIGN vendor packs (e.g. `mongodb/agent-skills`, `supabase/agent-skills`, `vercel-labs/agent-skills`) stay off the overlay; user may `npx skills add mongodb/agent-skills|supabase/agent-skills` locally; never `frontend-design` for product UI. - Never auto-edit rules or skills from a learning log (no `/learn`, `/evolve`, or session-end skill writers). @@ -206,6 +208,9 @@ The specialist architecture forms a deterministic graph connected by file artifa - Do not use ADHD for ordinary work. - Do not use Emil for static UI, or Impeccable for motion-only work. - Do not use BrowserAct as a stand-in for project Playwright. +- Do not run `scrapling install` (it invokes `playwright install-deps` with sudo). +- Do not run `agent-reach install --system` or register agent-reach as an MCP or skill. +- Do not use `whaleyxbt/patchright-enhanced` (rejected upstream fork). - Do not claim TypeScript, Vitest, coverage, Knip, or Playwright exist unless the current project has them. - Do not copy or print tokens, gateway URLs, or model-mapping values. - Do not depend on `~/.grok` at runtime. diff --git a/rules/03-prose-discipline.md b/rules/03-prose-discipline.md index e67fa35..881df45 100644 --- a/rules/03-prose-discipline.md +++ b/rules/03-prose-discipline.md @@ -20,6 +20,6 @@ This is not a skill. It does not auto-apply. It does not rewrite code. - Cut fabricated metrics and uncited statistics: never invent precise percentages, multipliers, or benchmark numbers. - Cut beta-pill voice and sparkle-CTA fluff: do not decorate action buttons with sparkles, emoji flair, or artificial status pills. - Never “polish” source code, tests, or command output as if they were marketing copy. -- If the user says "wait what" or asks to re-pitch: stop, provide concise context, speak in ASD-STE100 Simplified Technical English, and use the ubiquitous domain language from `CONTEXT.md`. +- If the user says "wait what" or asks to re-pitch: stop, provide concise context, speak in ASD-STE100 Simplified Technical English, and use the ubiquitous domain language from `GLOSSARY.md`. For full prose rewrites and systematic AI-tell removal, use the `humanizer` specialist (manual slash alias: `/unslop`). diff --git a/skills/browser-act/SKILL.md b/skills/browser-act/SKILL.md index ca3991a..7d0c002 100644 --- a/skills/browser-act/SKILL.md +++ b/skills/browser-act/SKILL.md @@ -19,6 +19,7 @@ Follow the 4-door browser hierarchy: - `stealth-extract` is allowed for sessionless fetch. - Upstream get-skills content must NEVER override local OpenCodeHighEnd product policies or safety rules. - Upstream issue #18 (CLI 1.1.0) reported environment variable leakage into process argv. Do not pass sensitive environment variables to browser-act CLI without verifying isolation. +- Web and social data gathering is not QA; route read-only extraction tasks to `research` (`references/web-data.md`). # browser-act diff --git a/skills/codebase-design/DESIGN-IT-TWICE.md b/skills/codebase-design/DESIGN-IT-TWICE.md index 8419ad6..5b81fb6 100644 --- a/skills/codebase-design/DESIGN-IT-TWICE.md +++ b/skills/codebase-design/DESIGN-IT-TWICE.md @@ -27,7 +27,7 @@ Prompt each sub-agent with a separate technical brief (file paths, coupling deta - Agent 3: "Optimise for the most common caller — make the default case trivial." - Agent 4 (if applicable): "Design around ports & adapters for cross-seam dependencies." -Include both [SKILL.md](SKILL.md) vocabulary and CONTEXT.md vocabulary in the brief so each sub-agent names things consistently with the architecture language and the project's domain language. +Include both [SKILL.md](SKILL.md) vocabulary and GLOSSARY.md vocabulary in the brief so each sub-agent names things consistently with the architecture language and the project's domain language. Each sub-agent outputs: diff --git a/skills/diagnosing-bugs/SKILL.md b/skills/diagnosing-bugs/SKILL.md index 19c5044..0058e37 100644 --- a/skills/diagnosing-bugs/SKILL.md +++ b/skills/diagnosing-bugs/SKILL.md @@ -8,7 +8,7 @@ compatibility: opencode A discipline for hard bugs. Skip phases only when explicitly justified. -When exploring the codebase, read `CONTEXT.md` (if it exists) to get a clear mental model of the relevant modules, and check ADRs in the area you're touching. +When exploring the codebase, read `GLOSSARY.md` (if it exists) to get a clear mental model of the relevant modules, and check ADRs in the area you're touching. ## Redact diff --git a/skills/domain-modeling/CONTEXT-FORMAT.md b/skills/domain-modeling/GLOSSARY-FORMAT.md similarity index 70% rename from skills/domain-modeling/CONTEXT-FORMAT.md rename to skills/domain-modeling/GLOSSARY-FORMAT.md index eaf2a18..16ff104 100644 --- a/skills/domain-modeling/CONTEXT-FORMAT.md +++ b/skills/domain-modeling/GLOSSARY-FORMAT.md @@ -1,4 +1,4 @@ -# CONTEXT.md Format +# GLOSSARY.md Format ## Structure @@ -31,18 +31,18 @@ _Avoid_: Client, buyer, account ## Single vs multi-context repos -**Single context (most repos):** One `CONTEXT.md` at the repo root. +**Single context (most repos):** One `GLOSSARY.md` at the repo root. -**Multiple contexts:** A `CONTEXT-MAP.md` at the repo root lists the contexts, where they live, and how they relate to each other: +**Multiple contexts:** A `GLOSSARY-MAP.md` at the repo root lists the contexts, where they live, and how they relate to each other: ```md # Context Map ## Contexts -- [Ordering](./src/ordering/CONTEXT.md) — receives and tracks customer orders -- [Billing](./src/billing/CONTEXT.md) — generates invoices and processes payments -- [Fulfillment](./src/fulfillment/CONTEXT.md) — manages warehouse picking and shipping +- [Ordering](./src/ordering/GLOSSARY.md) — receives and tracks customer orders +- [Billing](./src/billing/GLOSSARY.md) — generates invoices and processes payments +- [Fulfillment](./src/fulfillment/GLOSSARY.md) — manages warehouse picking and shipping ## Relationships @@ -53,8 +53,8 @@ _Avoid_: Client, buyer, account The skill infers which structure applies: -- If `CONTEXT-MAP.md` exists, read it to find contexts -- If only a root `CONTEXT.md` exists, single context -- If neither exists, create a root `CONTEXT.md` lazily when the first term is resolved +- If `GLOSSARY-MAP.md` exists, read it to find contexts +- If only a root `GLOSSARY.md` exists, single context +- If neither exists, create a root `GLOSSARY.md` lazily when the first term is resolved When multiple contexts exist, infer which one the current topic relates to. If unclear, ask. diff --git a/skills/domain-modeling/SKILL.md b/skills/domain-modeling/SKILL.md index 8bc29e8..a3b91c1 100644 --- a/skills/domain-modeling/SKILL.md +++ b/skills/domain-modeling/SKILL.md @@ -1,12 +1,12 @@ --- name: domain-modeling -description: Sharpen fuzzy or conflicting domain terms, relationships, CONTEXT.md glossaries, or ADRs. Skip merely reading CONTEXT.md for vocabulary. Product interviews that still need a plan use /grill-with-docs. +description: Sharpen fuzzy or conflicting domain terms, relationships, GLOSSARY.md glossaries, or ADRs. Skip merely reading GLOSSARY.md for vocabulary. Product interviews that still need a plan use /grill-with-docs. compatibility: opencode --- # Domain Modeling -Actively build and sharpen the project's domain model as you design. This is the *active* discipline — challenging terms, inventing edge-case scenarios, and writing the glossary and decisions down the moment they crystallise. (Merely *reading* `CONTEXT.md` for vocabulary is not this skill — that's a one-line habit any skill can do. This skill is for when you're changing the model, not just consuming it.) +Actively build and sharpen the project's domain model as you design. This is the *active* discipline — challenging terms, inventing edge-case scenarios, and writing the glossary and decisions down the moment they crystallise. (Merely *reading* `GLOSSARY.md` for vocabulary is not this skill — that's a one-line habit any skill can do. This skill is for when you're changing the model, not just consuming it.) ## File structure @@ -14,7 +14,7 @@ Most repos have a single context: ``` / -├── CONTEXT.md +├── GLOSSARY.md ├── docs/ │ └── adr/ │ ├── 0001-event-sourced-orders.md @@ -22,29 +22,31 @@ Most repos have a single context: └── src/ ``` -If a `CONTEXT-MAP.md` exists at the root, the repo has multiple contexts. The map points to where each one lives: +If a `GLOSSARY-MAP.md` exists at the root, the repo has multiple contexts. The map points to where each one lives: ``` / -├── CONTEXT-MAP.md +├── GLOSSARY-MAP.md ├── docs/ │ └── adr/ ← system-wide decisions ├── src/ │ ├── ordering/ -│ │ ├── CONTEXT.md +│ │ ├── GLOSSARY.md │ │ └── docs/adr/ ← context-specific decisions │ └── billing/ -│ ├── CONTEXT.md +│ ├── GLOSSARY.md │ └── docs/adr/ ``` -Create files lazily — only when you have something to write. If no `CONTEXT.md` exists, create one when the first term is resolved. If no `docs/adr/` exists, create it when the first ADR is needed. +Create files lazily — only when you have something to write. If no `GLOSSARY.md` exists, create one when the first term is resolved. If no `docs/adr/` exists, create it when the first ADR is needed. + +Legacy fallback: if the target repository only has `CONTEXT.md` or `CONTEXT-MAP.md`, read them as a legacy glossary; do not rename existing user files without being asked; create new glossary files as `GLOSSARY.md`. ## During the session ### Challenge against the glossary -When the user uses a term that conflicts with the existing language in `CONTEXT.md`, call it out immediately. "Your glossary defines 'cancellation' as X, but you seem to mean Y — which is it?" +When the user uses a term that conflicts with the existing language in `GLOSSARY.md`, call it out immediately. "Your glossary defines 'cancellation' as X, but you seem to mean Y — which is it?" ### Sharpen fuzzy language @@ -58,11 +60,11 @@ When domain relationships are being discussed, stress-test them with specific sc When the user states how something works, check whether the code agrees. If you find a contradiction, surface it: "Your code cancels entire Orders, but you just said partial cancellation is possible — which is right?" -### Update CONTEXT.md inline +### Update GLOSSARY.md inline -When a term is resolved, update `CONTEXT.md` right there. Don't batch these up — capture them as they happen. Use the format in [CONTEXT-FORMAT.md](./CONTEXT-FORMAT.md). +When a term is resolved, update `GLOSSARY.md` right there. Don't batch these up — capture them as they happen. Use the format in [GLOSSARY-FORMAT.md](./GLOSSARY-FORMAT.md). -`CONTEXT.md` should be totally devoid of implementation details. Do not treat `CONTEXT.md` as a spec, a scratch pad, or a repository for implementation decisions. It is a glossary and nothing else. +`GLOSSARY.md` should be totally devoid of implementation details. Do not treat `GLOSSARY.md` as a spec, a scratch pad, or a repository for implementation decisions. It is a glossary and nothing else. ### Offer ADRs sparingly diff --git a/skills/grill-with-docs/SKILL.md b/skills/grill-with-docs/SKILL.md index ecb1cbe..b6d0c56 100644 --- a/skills/grill-with-docs/SKILL.md +++ b/skills/grill-with-docs/SKILL.md @@ -1,6 +1,6 @@ --- name: grill-with-docs -description: Relentless interview to sharpen a plan with design-tree frontier rounds. Writes CONTEXT.md, a glossary, and ADRs as you go. Use when a feature still needs a plan, the user wants a deep planning interview, or they ask for /grill-with-docs. +description: Relentless interview to sharpen a plan with design-tree frontier rounds. Writes GLOSSARY.md, a glossary, and ADRs as you go. Use when a feature still needs a plan, the user wants a deep planning interview, or they ask for /grill-with-docs. compatibility: opencode --- @@ -8,7 +8,7 @@ compatibility: opencode # Grill with docs -Run the interview in this session. Compose owned domain-modeling discipline (glossary, CONTEXT.md, ADRs) with relentless design-tree frontier rounds. +Run the interview in this session. Compose owned domain-modeling discipline (glossary, GLOSSARY.md, ADRs) with relentless design-tree frontier rounds. Map the decisions as a **design tree**: every decision branches into the decisions that hang off it. Work the tree in **rounds**. The **frontier** is every decision whose prerequisites are already settled — the questions you can ask now without guessing at answers you haven't heard yet. Ask the whole frontier in one round: number each question and give your recommended answer. Then wait for the user's answers before the next round. @@ -27,9 +27,11 @@ Use `codebase-design` only when the conversation reaches a module, interface, or Leave the repo with: -- `CONTEXT.md` — problem, decisions, open questions, glossary +- `GLOSSARY.md` — problem, decisions, open questions, glossary - ADRs under `docs/adr/` (or `adr/` if that already exists) for hard-to-reverse choices +Legacy fallback: if the target repository only has `CONTEXT.md` or `CONTEXT-MAP.md`, read them as a legacy domain glossary; do not rename existing user files without being asked; create new glossary files as `GLOSSARY.md`. + ## Rules - You gather facts. The user makes decisions. @@ -44,13 +46,13 @@ Leave the repo with: ## Loop -1. Read `CONTEXT.md`, existing ADRs, and enough of the repo to speak the domain. +1. Read `GLOSSARY.md`, existing ADRs, and enough of the repo to speak the domain. 2. State the frontier: what you believe, what is undecided, what would change the design. 3. Ask the next question (or independent frontier) that most reduces that frontier. -4. After each answered decision, update `CONTEXT.md`. If the decision is hard to reverse, write an ADR. +4. After each answered decision, update `GLOSSARY.md`. If the decision is hard to reverse, write an ADR. 5. Repeat until the stop condition. -## CONTEXT.md shape +## GLOSSARY.md shape ```markdown # diff --git a/skills/humanizer/NOTICE.md b/skills/humanizer/NOTICE.md index 8e7c6b7..59fa3ff 100644 --- a/skills/humanizer/NOTICE.md +++ b/skills/humanizer/NOTICE.md @@ -1,6 +1,6 @@ # Notice: humanizer -Adapted from [blader/humanizer](https://github.com/blader/humanizer) v3. +Adapted from [blader/humanizer](https://github.com/blader/humanizer) v3.1.0 (commit `225a6f39ac85f76ee48dbad772ea4abe4ed6c9d8`). Copyright (c) 2024-2026 blader contributors. Licensed under the MIT License. diff --git a/skills/humanizer/references/patterns.md b/skills/humanizer/references/patterns.md index 3a37024..3bc77e8 100644 --- a/skills/humanizer/references/patterns.md +++ b/skills/humanizer/references/patterns.md @@ -60,3 +60,7 @@ Detailed catalog of writing patterns to identify and eliminate, grouped by the f - *Fix:* "Consider..." or "We recommend...". - **Sycophancy:** "Great question! That's a fantastic observation." - *Fix:* Answer directly with zero conversational stroking. +- **Writing about the document instead of its subject:** Explaining what a section, function, or table is doing ("This document outlines the architecture...", "The table below compares...", "This function was added to replace..."). + - *Fix:* Describe the subject or action directly. Omit meta-narrative about the document itself. +- **Re-explaining context the reader already knows:** Walking through the entire diagnosis, history, or proof before stating the decision to an informed collaborator. + - *Fix:* Lead with the decision or answer; keep proof and background for tickets or reference appendices. diff --git a/skills/hyperframes/NOTICE.md b/skills/hyperframes/NOTICE.md index 6557600..35ad4ec 100644 --- a/skills/hyperframes/NOTICE.md +++ b/skills/hyperframes/NOTICE.md @@ -1,6 +1,6 @@ # Notice: hyperframes -Adapted from [heygen-com/hyperframes](https://github.com/heygen-com/hyperframes). +Adapted from [heygen-com/hyperframes](https://github.com/heygen-com/hyperframes) pinned at tag `v0.8.119` (commit `3a0299e851ce2f71f9fd4b7acf3c34709b2523b5`). Licensed under the Apache License, Version 2.0 (the "License"). You may obtain a copy of the License at diff --git a/skills/hyperframes/SKILL.md b/skills/hyperframes/SKILL.md index 7f64cc6..c685b54 100644 --- a/skills/hyperframes/SKILL.md +++ b/skills/hyperframes/SKILL.md @@ -19,31 +19,34 @@ Unlike generative video models that hallucinate frames, HyperFrames builds video | In-app micro-interactions, hover/press, easing on interactive UI | `emil-design-eng` (after `impeccable`) | | Scroll-driven narrative storytelling website (scrollytelling) | `scroll-craft` | | Continuous 3D fly-through, camera-scrub diorama page | `scroll-world` | +| Commercials, launch films, business explainers, sample reels | `business-motion-film` (render via `hyperframes`) | | **Deterministic HTML composition rendered to video** | **`hyperframes`** | ## Environment & Availability HyperFrames executes locally: -1. **Local CLI:** `npx hyperframes` or local project rendering script. -2. **Runtime Prerequisites:** Headless Chromium/Chrome and FFmpeg. +1. **Local CLI:** `npx hyperframes init `, `npx hyperframes preview`, and `npx hyperframes render [dir] -o -f -q `. +2. **Runtime Prerequisites:** Node.js ≥22, local FFmpeg, and Headless Chromium/Chrome. -If local rendering tools or FFmpeg are absent: +If Node <22 or FFmpeg is absent: - Mark execution as `NOT_CONFIGURED` or `DEGRADED`. -- Output the self-contained HTML/CSS composition files and precise rendering CLI commands. +- Output self-contained HTML/CSS composition files and exact rendering CLI commands. - **Never** make silent remote HeyGen API calls or request confidential API keys. Hosted services remain opt-in only. ## References Load the specific reference required for the task: -- [references/composition.md](references/composition.md) — HTML composition layout, aspect ratios, seekable timeline contracts. -- [references/render.md](references/render.md) — Headless Chrome capture, frame stepping, FFmpeg encoding parameters. +- [references/composition.md](references/composition.md) — HTML composition layout, aspect ratios, seekable timeline contracts (`data-composition-id`, timed clips). +- [references/render.md](references/render.md) — Official CLI render workflows, quality flags, Headless Chrome frame stepping, and FFmpeg encoding. +- [references/prompt-patterns.md](references/prompt-patterns.md) — Code-video prompt pattern gallery adaptation, shot translation, and quality gates (POINTER_ONLY). - [references/workflows.md](references/workflows.md) — Workflow archetypes (product launch, animated explainer, motion graphics, data video). - [references/brag.md](references/brag.md) — 18-second product launch / brag card recipe, local assets, exact output path. ## Hard Rules 1. **Deterministic Timelines:** Animations must be scrubbable/seekable by a master time parameter (`t` in seconds or frame number `f`). Avoid non-deterministic `Math.random()` or real-time `setInterval` that drifts during frame capture. -2. **Exact Dimensions:** Explicitly set viewport and canvas dimensions matching standard video resolutions (e.g. 1920x1080 for 16:9 landscape, 1080x1920 for 9:16 vertical/shorts). +2. **Exact Dimensions:** Declare viewport and canvas dimensions via root `data-width` and `data-height` (e.g. 1920x1080 for 16:9 landscape, 1080x1920 for 9:16 vertical/shorts). 3. **Local Assets First:** Prefer SVG, Canvas, embedded fonts, and local images over external CDN links to guarantee offline reproducibility. -4. **Clean Handoff:** If audio tracks (voiceover, BGM) are provided, synchronize cue points in the timeline and multiplex audio during the FFmpeg pass. +4. **No Foreign Skill Pollution:** Do NOT execute `npx skills add heygen-com/hyperframes` or `npx hyperframes skills update`. Both commands write unmanaged skills into agent skill directories, violating the frozen catalog contract. Status is `FOREIGN_ON_DEMAND` and pointer-only. Registry blocks (`npx hyperframes add `) are added only on explicit user request. +5. **Clean Handoff:** If audio tracks (voiceover, BGM) are provided, synchronize cue points in the timeline and multiplex audio during the FFmpeg pass. diff --git a/skills/hyperframes/references/brag.md b/skills/hyperframes/references/brag.md index 0a6f03a..45b2663 100644 --- a/skills/hyperframes/references/brag.md +++ b/skills/hyperframes/references/brag.md @@ -24,32 +24,38 @@ Deterministic, high-impact 18-second video card for new product releases, featur | **3. Capability Highlight** | `8.0s - 13.5s` | Feature Carousel | 3 kinetic badge callouts or terminal command executions popping in sequence with numerical counters. | | **4. Call to Action** | `13.5s - 18.0s` | Outro Lockup | Clean repository / install command (`opencode-he ...` or `git clone ...`), release tag badge, and link fade-out. | -## Seekable Timeline Contract +## Declarative Composition Template -```javascript -// Master timeline contract driven strictly by frame or elapsed seconds -function renderFrame(t) { - // t is in seconds (0.000 to 18.000) - const progress = Math.min(Math.max(t / 18.0, 0), 1); +Dimensions and duration are declared on the root composition and scene clips: - if (t < 3.5) { - // Scene 1: Hook - const s1Progress = t / 3.5; - renderHookScene(s1Progress); - } else if (t < 8.0) { - // Scene 2: Hero Reveal - const s2Progress = (t - 3.5) / 4.5; - renderHeroScene(s2Progress); - } else if (t < 13.5) { - // Scene 3: Highlight - const s3Progress = (t - 8.0) / 5.5; - renderHighlightScene(s3Progress); - } else { - // Scene 4: CTA - const s4Progress = (t - 13.5) / 4.5; - renderOutroScene(s4Progress); - } -} +```html +
+ +
+
...
+
+ + +
+
...
+
+ + +
+
...
+
+ + +
+
...
+
+
``` ## Local Execution & Output @@ -58,12 +64,6 @@ function renderFrame(t) { # 1. Output directory preparation mkdir -p brag-output -# 2. Local deterministic render via hyperframes CLI or local script -npx -y hyperframes render \ - --input index.html \ - --output brag-output/brag.mp4 \ - --width 1920 \ - --height 1080 \ - --fps 60 \ - --duration 18 +# 2. Local deterministic render via hyperframes CLI +npx hyperframes render . -o brag-output/brag.mp4 -f 60 -q delivery ``` diff --git a/skills/hyperframes/references/composition.md b/skills/hyperframes/references/composition.md index bdac964..f711b4a 100644 --- a/skills/hyperframes/references/composition.md +++ b/skills/hyperframes/references/composition.md @@ -1,30 +1,90 @@ # HyperFrames Composition Architecture -HTML, CSS, and Canvas structure for seekable video scenes. +HTML, CSS, and SVG/Canvas structure for seekable deterministic video compositions. -## The Seekable Timeline Contract +## The Declarative Timeline Contract -Deterministic frame capture requires that any frame at time `t` (or frame index `n` at FPS `r`) can be rendered instantaneously without continuous wall-clock playback. +HyperFrames binds the composition lifecycle directly to semantic HTML data attributes. Rather than invoking ad-hoc runtime stepping functions, the engine compiles declarative timing markers and steps through each frame deterministically. -```javascript -// Canonical seek interface -window.renderFrame = function(timeInSeconds, frameNumber) { - // Update state, CSS variables, or canvas draw calls for exact timestamp - document.documentElement.style.setProperty('--frame-time', `${timeInSeconds}s`); - // Update canvas or SVG elements directly - updateScene(timeInSeconds); -}; +### 1. Root Composition Definition + +The root element declares the composition boundary, resolution, and default frame rate: + +```html +
+ +
``` -## Viewport & Aspect Ratio Presets +### 2. Timed Clips (`class="clip"`) + +Individual scenes or layers use `class="clip"` along with duration attributes: -Configure root container to exact pixel dimensions: +```html + +
+

Product Launch

+
+ + +
+

Key Features

+
+``` -- **16:9 Landscape (YouTube / Presentation):** `width: 1920px; height: 1080px;` -- **9:16 Vertical (Reels / TikTok / Shorts):** `width: 1080px; height: 1920px;` -- **1:1 Square (Feed):** `width: 1080px; height: 1080px;` +- `data-start`: Absolute second (e.g. `"0"`, `"4.5"`) or relative clip reference (e.g. `"scene-intro"`, `"scene-intro - 0.5"` for crossfades). +- `data-duration`: Duration of the clip in seconds. +- `data-track-index`: Studio timeline row lane (optional; rendering order is governed by CSS `z-index`). + +### 3. Nested Compositions + +Reusable sub-scenes or modules can be nested using `data-composition-src`: + +```html +
+``` -CSS resets: +## Determinism & Seekable Animation + +Frame capture steps through `t = frame / fps` without real-time wall-clock playback: + +1. **Paused & Seeked GSAP:** All GSAP timelines must be paused on creation and scrubbed via `.seek(t, false)`. Never call `.play()`. +2. **Zero Wall-Clock Clocks:** No `Date.now()`, `performance.now()`, `requestAnimationFrame`, or `setInterval`. +3. **No Unseeded Randomness:** `Math.random()` produces divergent frames across runs. Use a seeded pseudo-random number generator (e.g. Mulberry32) if procedural noise is required. +4. **No Mid-Render Fetch:** Preload all fonts, images, and JSON data before frame 0. Dynamic network fetches during capture cause dropped frames or non-deterministic blank flashes. + +## Viewport & Resolution Presets + +- **16:9 Landscape (YouTube / Presentation):** `data-width="1920"` `data-height="1080"` +- **9:16 Vertical (Reels / TikTok / Shorts):** `data-width="1080"` `data-height="1920"` +- **1:1 Square (Feed):** `data-width="1080"` `data-height="1080"` + +Standard reset styles: ```css html, body { margin: 0; @@ -33,18 +93,16 @@ html, body { background: #000; -webkit-font-smoothing: antialiased; } -#stage { +[data-composition-id] { position: relative; - width: 1920px; - height: 1080px; + width: 100vw; + height: 100vh; overflow: hidden; } +.clip { + position: absolute; + inset: 0; + width: 100%; + height: 100%; +} ``` - -## Scene Management - -Divide longer videos into discrete scenes: -- `Scene 1 [0.0s - 3.5s]`: Hook & Title Card -- `Scene 2 [3.5s - 8.0s]`: Problem Statement / Key Graphic -- `Scene 3 [8.0s - 14.0s]`: Feature Demonstration / Architecture Callout -- `Scene 4 [14.0s - 17.0s]`: Outro / Call to Action diff --git a/skills/hyperframes/references/prompt-patterns.md b/skills/hyperframes/references/prompt-patterns.md new file mode 100644 index 0000000..2ad5218 --- /dev/null +++ b/skills/hyperframes/references/prompt-patterns.md @@ -0,0 +1,47 @@ +# Code-Video Prompt Patterns & Gallery Adaptation + +Reference guide for translating viral code-driven video prompts into deterministic HyperFrames compositions. + +## Status: POINTER_ONLY + +Upstream index: [yihui-dev/awesome-opus5-5-videos](https://github.com/yihui-dev/awesome-opus5-5-videos) (snapshot `3d54892e2ae5b0e8d337171e6508bba4cec01ab8`, dated 2026-09-29). +Distribution notice: Upstream curation indexes third-party social video posts whose respective authors retain rights. No upstream prompts, datasets, or video media are vendored into this distribution. + +### Snapshot Facts (2026-09-29) +The upstream gallery catalogues 475 community creations across multiple domains: +- Categories: motion (288), interactive (70), explainer (62), 3D (55). +- Tech tags: canvas (336), svg (193), threejs (141), shader (100), gsap (81). +- Coverage: 196 partial or conceptual prompt fragments recorded. + +## Translating One-Line Viral Prompts to HyperFrames Briefs + +Viral prompts frequently say "generate an animation of X" without technical specs. Before writing HTML/CSS/JS, expand the brief into explicit deterministic parameters: + +1. **Duration & Frame Budget:** Fix exact runtime (typically 15s to 25s) and frame rate (`data-fps="30"` or `"60"`). +2. **Aspect Ratio & Resolution:** Lock viewport dimensions on the root `[data-composition-id]` (`1920x1080` for 16:9, `1080x1920` for 9:16). +3. **Beat Sheet & Camera Positions:** Break timeline into timestamped scenes using `
`. +4. **Style & Visual Identity:** Extract palette, fonts, and radii from project `DESIGN.md` rather than generic AI gradients. +5. **Tech Tag to Implementation Mapping:** + - `canvas` / `svg`: Procedural 2D vector elements parameterized by seek time `t`. + - `gsap`: Timeline instances created paused, scrubbed via `.seek(t)`. + - `threejs` / `shader`: WebGL scenes rendered synchronously on `seek(t)` using fixed random seeds. +6. **Audio Alignment:** Plan cue markers for voiceover or soundtrack stems. + +## Safety & Determinism Constraints + +- **Seek-Driven Render over Screen Recording:** Never tell users to "screen record the browser window". Always compile to declarative HyperFrames composition and run `npx hyperframes render`. +- **Intellectual Property:** When prompt recipes mention external assets, use only user-provided or clearly licensed local media. Never incorporate third-party trademarks or proprietary logos without license. +- **Model-Agnostic Execution:** Do not condition prompt execution on specific proprietary LLM brand names. Model identifiers in this runtime remain opaque. + +## Quality Gates & Verification + +1. **Contact Sheet Audit:** Capture and inspect raster frames at 0%, 25%, 50%, 75%, and 100% of duration to verify progression. +2. **Determinism Check:** Perform two sequential test renders and compare SHA-256 hashes of sample frames; identical inputs must yield identical pixel bytes. + +## Routing Handoffs + +- Commercial SaaS ad, product film, or sample reel: `/business-motion-film` (renders via HyperFrames). +- Fast 18-second milestone launch card: [references/brag.md](brag.md). +- Indonesian spoken app walkthrough: `/id-demo-video`. +- Photoreal VFX or studio imagery: `/visual-studio`. +- Interactive or playable widgets: Not video compositions (`video_html`). Route to `/impeccable` for product UI or `/prototype` for experiments. diff --git a/skills/hyperframes/references/render.md b/skills/hyperframes/references/render.md index 1b77e95..0bfbf4e 100644 --- a/skills/hyperframes/references/render.md +++ b/skills/hyperframes/references/render.md @@ -1,46 +1,78 @@ # HyperFrames Rendering Pipeline -Capturing frames from Headless Chromium and encoding with FFmpeg. +Local rendering workflow, toolchain prerequisites, and execution options. ## Local Prerequisites -Check local system capabilities: +HyperFrames rendering requires modern Node and local media toolchains: + +- **Node.js ≥22** (`node -v` must report `v22.0.0` or higher) +- **FFmpeg** on system PATH (`which ffmpeg`) +- **Headless Chromium / Chrome** (managed automatically by Puppeteer or system browser) + +Verification check: ```bash -which ffmpeg -which google-chrome || which chromium || which chromium-browser +node -e 'process.exit(Number(process.versions.node.split(".")[0]) >= 22 ? 0 : 1)' && which ffmpeg ``` -If missing: report `NOT_CONFIGURED`. +If Node <22 or FFmpeg is absent: report `NOT_CONFIGURED` (never report false PASS). + +## Primary Rendering Path (Official CLI) -## Frame Stepping Protocol +The primary and recommended workflow uses the official `@hyperframes/cli`: + +### 1. Initialize Project Directory +```bash +npx hyperframes init +``` + +### 2. Live Interactive Preview +```bash +npx hyperframes preview +``` -Chromium DevTools Protocol (CDP) `Page.captureScreenshot` or Puppeteer / Playwright script steps through each frame: +### 3. Production Deterministic Render +```bash +npx hyperframes render [dir] -o -f -q [--format mp4|webm|mov|gif|png-sequence] +``` +#### Common Invocations: ```bash -# Example frame stepping parameter calculation: -FPS=30 -DURATION_SECONDS=10 -TOTAL_FRAMES=$((FPS * DURATION_SECONDS)) +# High quality 60fps landscape MP4 +npx hyperframes render . -o renders/launch.mp4 -f 60 -q delivery + +# Render specific composition file +npx hyperframes render . -c compositions/intro.html -o renders/intro.mp4 + +# Transparent ProRes MOV overlay +npx hyperframes render . -o renders/overlay.mov --format mov + +# Transparent WebM overlay +npx hyperframes render . -o renders/overlay.webm --format webm + +# Animated GIF for PRs / docs at 15fps +npx hyperframes render . -o renders/demo.gif --format gif -f 15 --gif-loop 0 + +# Docker-isolated render (identical font and Chromium baseline) +npx hyperframes render . -o renders/reproducible.mp4 --docker ``` -## Canonical FFmpeg Encoding +## Explicit Fallback: Manual CDP & FFmpeg -After PNG frames are saved to a directory (e.g. `./frames/frame_%05d.png`): +If the official CLI cannot be executed in the environment, use direct Headless Chromium frame stepping as a secondary fallback: + +1. Calculate total frame count: `TOTAL_FRAMES = FPS * DURATION_SECONDS`. +2. Connect to Chromium via DevTools Protocol (`Page.captureScreenshot`), seek timeline to each step, and save frames sequentially to `./frames/frame_%05d.png`. +3. Encode frames using FFmpeg: ```bash -# High quality H.264 MP4 encode: -ffmpeg -y -framerate 30 -i frames/frame_%05d.png \ - -c:v libx264 -preset slow -crf 18 -pix_fmt yuv420p \ +# Visual lossless H.264 MP4 encode +ffmpeg -y -framerate 60 -i frames/frame_%05d.png \ + -c:v libx264 -preset slow -crf 16 -pix_fmt yuv420p \ output.mp4 -# With audio multiplexing: -ffmpeg -y -framerate 30 -i frames/frame_%05d.png -i audio.mp3 \ - -c:v libx264 -preset slow -crf 18 -pix_fmt yuv420p \ +# Multiplexing background audio +ffmpeg -y -framerate 60 -i frames/frame_%05d.png -i audio.mp3 \ + -c:v libx264 -preset slow -crf 16 -pix_fmt yuv420p \ -c:a aac -b:a 192k -shortest \ output.mp4 ``` - -## Quality Optimization -- Use `-pix_fmt yuv420p` for universal hardware/browser playback. -- Use `-crf 18` for visually lossless composition. -- If alpha transparency is required (WebM overlay): - `ffmpeg -y -framerate 30 -i frames/frame_%05d.png -c:v libvpx-vp9 -pix_fmt yuva420p output.webm` diff --git a/skills/playwright-qa/SKILL.md b/skills/playwright-qa/SKILL.md index 2cad10f..66c9cad 100644 --- a/skills/playwright-qa/SKILL.md +++ b/skills/playwright-qa/SKILL.md @@ -22,6 +22,7 @@ This skill provides an interactive, token-efficient browser interface for agents 6. **Port Separation**: Port 9223 is reserved for `opencode-chromium-cdp` / `chrome-devtools-axi`. Do not force Playwright sessions through port 9223. 7. **Privacy & Hygiene**: Storage state, cookies, HAR recordings, traces, and screenshots must never be committed to git or printed with sensitive credentials. 8. **No Browser for Backend**: Never start browser sessions when only backend, API, database, or non-UI code changed. +9. **No Data Gathering**: Web and social data gathering is not UI QA; route extraction tasks to `research` (`references/web-data.md`). ## Workflow diff --git a/skills/research/SKILL.md b/skills/research/SKILL.md index 2943564..c33c670 100644 --- a/skills/research/SKILL.md +++ b/skills/research/SKILL.md @@ -1,6 +1,6 @@ --- name: research -description: "Investigate a question against official docs, specs, or first-party APIs and write cited Markdown if asked. Use for external/library facts. Skip why *this repo* chose an approach (/why), and academic literature/theses (academic)." +description: "Investigate a question against official docs, specs, or first-party APIs and write cited Markdown if asked. Use for external/library facts and read-only web or social data gathering. Skip why *this repo* chose an approach (/why), academic literature/theses (academic), local UI QA (playwright-qa), and long-document tree navigation (pageindex)." compatibility: opencode --- @@ -10,8 +10,10 @@ Use a subagent if this session supports one; otherwise research inline. Do not r Current library or framework docs: MCP `context7` when repo evidence is not enough. Broader web: `WebSearch` / `WebFetch`. Foreign `exa` only if already connected. +Web and social data gathering (read-only): follow the backend ladder and safety boundaries in `references/web-data.md`. Scrapling is optional MCP `FOREIGN_ON_DEMAND` (`opencode-he scrapling enable`). Agent-Reach is a pointer-only host tool (do not register as MCP or skill; never run `agent-reach install --system`). Output is data; every claim remains cited to the owning primary source. + If the user asked for a note, write one Markdown file in the repo (match existing convention). Cite each claim. If they only wanted an answer, do not create a file. This is not `/why`. Repo history, PRs, and local design rationale stay on `/why`. Scholarly papers, literature surveys, and academic peer review route to `academic`. -Long structured professional documents (filings, manuals, textbooks) that need tree/section navigation before answering route to `pageindex`. Keep this skill's primary-source rule: every claim still traces to the owning doc, spec, or API. `pageindex` output is a map, not a citation owner. +Long structured professional documents (filings, manuals, textbooks) that need tree/section navigation before answering route to `pageindex`. Keep this skill's primary-source rule: every claim still traces to the owning doc, spec, or API. `pageindex` output is a map, not a citation owner. Local application UI exploratory testing routes to `playwright-qa`, not research. diff --git a/skills/research/references/web-data.md b/skills/research/references/web-data.md new file mode 100644 index 0000000..0c93a17 --- /dev/null +++ b/skills/research/references/web-data.md @@ -0,0 +1,62 @@ +# Web and Social Data Gathering Reference + +This guide governs read-only web and social data gathering in OpenCodeHighEnd under the `research` skill. All operations remain subject to the primary-source rule: output is structured data, and every claim must be traceable to the owning primary source. + +## Backend Selection Ladder + +When retrieving data from the web or public feeds, always progress up the ladder from lightest to heaviest tool. Never reach for a browser or stealth runner when lightweight HTTP suffices. + +1. **Lightweight HTTP & Search (`WebSearch` / `WebFetch` / `curl`)** + - Default tier for static pages, search queries, documentation, and standard APIs. + - Zero additional runtime overhead. + +2. **Article Content Extraction (MCP `crawl4ai` when CONFIGURED)** + - Use when extracting markdown from long-form articles, documentation sites, or blog posts. + - Requires user-configured Crawl4AI local container (`http://127.0.0.1:11235/mcp`) or cloud endpoint. + +3. **Structured Scraping (MCP `scrapling` when CONFIGURED)** + - Use when extracting structured data with CSS/XPath selectors, adaptive element tracking, or JSON APIs. + - Enable via `opencode-he scrapling enable` (runs stdio MCP via `uvx`). + - Order of operations: prefer `make_request` or `bulk_get` first; invoke browser-backed `fetch` only if JavaScript execution is strictly required to render target data. + +4. **Background XHR Capture (Scrapling Python Scripting)** + - When public dynamic web apps load data through internal API calls, use Scrapling's `DynamicSession(capture_xhr=...)` to capture raw JSON payloads directly rather than parsing rendered DOM. + - Any helper script must be written to `/tmp` (e.g. `/tmp/scrape_xhr.py`) or a user-specified project path. **Never write scripts into the OpenCodeHighEnd overlay directory.** + +5. **Zero-Config Feeds & Developer Endpoints (Agent-Reach CLI)** + - Pointer-only host tool for specialized zero-config sources: YouTube subtitles (`yt-dlp`), GitHub data (`gh`), public RSS feeds, and V2EX. + - OCH does not vendor or install Agent-Reach. If the user desires to install it themselves: + `pipx install 'git+https://github.com/Panniantong/agent-reach.git@f65526cbaaad3879473acc1ba6dbefd195caf2be'` + - **Strict prohibition**: Never run `agent-reach install --system` (it mutates system packages and copies foreign skills into `~/.config/opencode/skills/`). + +6. **Authenticated Social Platforms (X, Reddit, Xiaohongshu, Facebook, Instagram, LinkedIn)** + - Access only when the user explicitly requests platform data AND has already configured their own credentials or environment. + - OpenCodeHighEnd and its tools **never hold, store, or extract user session cookies or passwords**. + +7. **Multi-Session or Persistent Browser Workflows (`browser-act`)** + - For interactive sessions requiring persistent login state across turns, route explicitly to `browser-act`. + - Never use `browser-act` as an exploratory QA replacement (`playwright-qa` remains the QA verifier). + +--- + +## Ethical and Safety Boundaries + +1. **Explicit Consent for Stealth**: + - `stealthy_fetch` and anti-bot challenge bypass are disabled by default. Use them only upon explicit user instruction, where the user confirms they have authorization and site Terms of Service allow data access. + +2. **Robots.txt & Polite Crawling**: + - Always respect target site directives (`robots_txt_obey=True` on spiders). + - Enforce polite download delays and sensible concurrency limits. Do not hammer endpoints. + +3. **No Credential or Login-Wall Bypasses**: + - Never bypass paywalls, private member portals, or login walls. + - Never extract authentication tokens or cookies from user desktop browsers (`--from-browser` is banned). + +4. **No Deceptive Proxy Rotation**: + - Do not use proxy rotators to disguise abuse or circumvent defensive rate limits. + +5. **Third-Party Relay Transparency**: + - If using services like `r.jina.ai` to convert pages to markdown, explicitly inform the user that the target URL is being sent to a third-party service. + +6. **Data Grounding**: + - Scraping results represent raw input data. Output claims must accurately cite the primary source URL, timestamp, and author or domain. diff --git a/skills/scroll-world/SKILL.md b/skills/scroll-world/SKILL.md index d84abed..7b71dcd 100644 --- a/skills/scroll-world/SKILL.md +++ b/skills/scroll-world/SKILL.md @@ -47,7 +47,7 @@ Paid video generation backends (Monid, Higgsfield, Kling) are not vendored into | Ordinary landing without a camera world | `impeccable` | | Photoreal stills, ads, cinematic, identity, thumbnails (no world page) | `visual-studio` | | Photoreal person/creature inside this world | this skill owns the chain + page; load `visual-studio` cinematic for those stills/clips | -| Game sprites, tiles, icon sets | `game-asset-core` | +| Game sprites, tiles, icon sets | `NOT_APPLICABLE` (out of catalog) | | Deterministic HTML composition rendered to video | `hyperframes` | | UI chrome motion (nav, buttons), not the video scrub | `emil-design-eng` after Impeccable | diff --git a/skills/tdd/SKILL.md b/skills/tdd/SKILL.md index 06d187d..78641e2 100644 --- a/skills/tdd/SKILL.md +++ b/skills/tdd/SKILL.md @@ -10,7 +10,7 @@ TDD is the red → green loop. This skill is the reference that makes that loop Spec and tracer-bullet ticket implementations (`/to-tickets`) execute in this session using this loop. There is no separate `/implement` skill. -When exploring the codebase, read `CONTEXT.md` (if it exists) so test names and interface vocabulary match the project's domain language, and respect ADRs in the area you're touching. +When exploring the codebase, read `GLOSSARY.md` (if it exists) so test names and interface vocabulary match the project's domain language, and respect ADRs in the area you're touching. ## What a good test is diff --git a/skills/visual-studio/SKILL.md b/skills/visual-studio/SKILL.md index 048c754..e120238 100644 --- a/skills/visual-studio/SKILL.md +++ b/skills/visual-studio/SKILL.md @@ -1,6 +1,6 @@ --- name: visual-studio -description: "Produce photoreal product stills, reusable identity packs, UGC/ad videos, cinematic VFX shots, and video thumbnails with native image_gen, image_edit, image_to_video, and reference_to_video. Use when: product photo, studio shot, lifestyle, Pinterest pin, hero banner, carousel, ad pack, virtual try-on, UGC, unboxing, product review, TV spot, cinematic video, VFX, character sheet, size-ref, face-lock, YouTube thumbnail, Shorts cover, or the user runs /visual-studio. Load native image tools if present, else DEGRADED before any generate/edit/video call. Not for UI/frontend (use impeccable), game sprites or tiles (use game-asset-core), or UI motion (use emil-design-eng)." +description: "Produce photoreal product stills, reusable identity packs, UGC/ad videos, cinematic VFX shots, and video thumbnails with native image_gen, image_edit, image_to_video, and reference_to_video. Use when: product photo, studio shot, lifestyle, Pinterest pin, hero banner, carousel, ad pack, virtual try-on, UGC, unboxing, product review, TV spot, cinematic video, VFX, character sheet, size-ref, face-lock, YouTube thumbnail, Shorts cover, or the user runs /visual-studio. Load native image tools if present, else DEGRADED before any generate/edit/video call. Not for UI/frontend (use impeccable), game sprites or tiles (NOT_APPLICABLE, out of catalog), or UI motion (use emil-design-eng)." compatibility: opencode license: MIT --- @@ -43,7 +43,7 @@ live there. Do not restate them here. | Scroll-led storytelling / scrollytelling | `scroll-craft` | | Scroll-scrub fly-through, diorama, 3D-world landing | `scroll-world` | | Website/app whose UI needs designed photos or videos | `impeccable` leads the surface; this skill produces the media | -| Game sprites, tiles, icon sets, animation sheets | `game-asset-core` | +| Game sprites, tiles, icon sets, animation sheets | `NOT_APPLICABLE` (out of catalog) | | Deterministic HTML composition rendered to video | `hyperframes` | | UI motion / interaction feel | `emil-design-eng` after Impeccable | | Photoreal stills, ads, cinematic, identity, thumbnails (no UI) | this skill | diff --git a/templates/AGENTS.md b/templates/AGENTS.md index 34f2cc5..05e9685 100644 --- a/templates/AGENTS.md +++ b/templates/AGENTS.md @@ -10,7 +10,7 @@ Availability is not a reason to use a tool. One primary specialist. At most one ## Closed Intent & Default Classify into exactly one intent before acting: -`repo_understand | bug | security | perf | ui_direction | ui_implement | generative_ui | motion | scroll_2d | scroll_3d | launch_film | gateway_llm | docs | ingest_md | prose | academic | longdoc_nav | browser_qa | architecture | warehouse | ops_data | video_html | demo_id | slides_pptx` +`repo_understand | bug | security | perf | ui_direction | ui_implement | generative_ui | motion | scroll_2d | scroll_3d | launch_film | gateway_llm | docs | ingest_md | prose | academic | longdoc_nav | web_research | browser_qa | architecture | warehouse | ops_data | video_html | demo_id | slides_pptx` 1. Repo evidence is enough → do the work. No specialist. 2. User typed a slash command → load that command's specialist. Do not substitute. @@ -43,7 +43,7 @@ Browser QA → skill `playwright-qa` (isolated verification session; builder doe Auth/secret/payment/upload/webhook/privileged/public API → `full-audit-keamanan`. Measured LCP/INP/CLS/latency/bundle → `full-performance-audit`. GitHub → `gh-axi`. Hard unknown bug → `diagnosing-bugs`. Documents (PDF/DOCX/extract/review) → `smartdoc`. Consulting PPTX / slide decks → `deck-design`. Long structured docs (tree/reasoning nav) → `pageindex`. File → Markdown ingest → `markitdown`. Reusable local knowledge → `smartbook-ingest`. -Prose AI-tells / humanize → skill `humanizer`. Slash `/unslop` is the same specialist, manual only. Technical writing structure → suggest `/technical-writing`. Academic literature / manuscript / peer-critique → skill `academic` (not `research`, not `smartdoc` unless file extract/render). Facts library/API → Context7; `research` only if repo lacking. Deterministic HTML video / render HTML to MP4 → skill `hyperframes` (not `visual-studio`, not `emil-design-eng`). Editorial diagram HTML/SVG → skill `diagram-design` (not `impeccable`). Demo video aplikasi / walkthrough layar / narasi Indonesia / demo lomba → skill `id-demo-video` (bukan `hyperframes` untuk durasi panjang utuh, bukan `playwright-qa`, bukan `visual-studio`). Kartu judul HTML→MP4 tetap `hyperframes`. +Prose AI-tells / humanize → skill `humanizer`. Slash `/unslop` is the same specialist, manual only. Technical writing structure → suggest `/technical-writing`. Academic literature / manuscript / peer-critique → skill `academic` (not `research`, not `smartdoc` unless file extract/render). Facts library/API → Context7; `research` only if repo lacking. Web/social data gathering → skill `research` (`references/web-data.md`); bukan `playwright-qa`. Deterministic HTML video / render HTML to MP4 → skill `hyperframes` (not `visual-studio`, not `emil-design-eng`). Editorial diagram HTML/SVG → skill `diagram-design` (not `impeccable`). Demo video aplikasi / walkthrough layar / narasi Indonesia / demo lomba → skill `id-demo-video` (bukan `hyperframes` untuk durasi panjang utuh, bukan `playwright-qa`, bukan `visual-studio`). Kartu judul HTML→MP4 tetap `hyperframes`. REST resource/status/pagination/versioning → skill `api-design`. Consumer/provider OpenAPI/AsyncAPI/Protobuf → skill `contract-first`. Live cron/CI/hook/MCP inventory keep-merge-cut → skill `automation-audit-ops`. CodeTour .tour + anchor file → skill `code-tour`. Handler vs shared-store sequential-undo → skill `click-path-audit` (not `playwright-qa`). diff --git a/tests/test_doctor.py b/tests/test_doctor.py index 0221819..6e48842 100644 --- a/tests/test_doctor.py +++ b/tests/test_doctor.py @@ -18,6 +18,8 @@ from lib.install import ( # noqa: E402 cmd_crawl4ai_disable, cmd_crawl4ai_enable, + cmd_scrapling_disable, + cmd_scrapling_enable, cmd_install, ) from lib.integrity import cmd_verify # noqa: E402 @@ -635,6 +637,165 @@ def test_doctor_plugins_pass_on_user_v2_plugin(self): self.assertEqual(rc, 0, buf.getvalue()) self.assertIn("PASS plugins 1 user plugin(s)", buf.getvalue()) + def test_doctor_scrapling_missing_does_not_fail(self): + self._install() + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 0, buf.getvalue()) + self.assertIn("OPTIONAL_ABSENT mcp:scrapling", buf.getvalue()) + + def test_doctor_scrapling_invalid_schema_fails(self): + self._install() + cfg = self.tmp / ".config" / "opencode" / "opencode.jsonc" + data = jsonc.loads(cfg.read_text(encoding="utf-8")) + + # Remote type fails + data["mcp"]["scrapling"] = { + "type": "remote", + "url": "http://127.0.0.1:8000/mcp", + "enabled": True, + } + cfg.write_text(jsonc.dumps(data), encoding="utf-8") + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 1, buf.getvalue()) + self.assertIn("FAIL mcp:scrapling", buf.getvalue()) + + # Docker command fails + data["mcp"]["scrapling"] = { + "type": "local", + "command": ["docker", "run", "scrapling", "mcp"], + "enabled": True, + } + cfg.write_text(jsonc.dumps(data), encoding="utf-8") + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 1, buf.getvalue()) + self.assertIn("FAIL mcp:scrapling", buf.getvalue()) + + # --http or 0.0.0.0 fails + data["mcp"]["scrapling"] = { + "type": "local", + "command": ["uvx", "--from", "scrapling[ai]==0.4.15", "scrapling", "mcp", "--http", "0.0.0.0"], + "enabled": True, + } + cfg.write_text(jsonc.dumps(data), encoding="utf-8") + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 1, buf.getvalue()) + self.assertIn("FAIL mcp:scrapling", buf.getvalue()) + + # Unpinned package fails + data["mcp"]["scrapling"] = { + "type": "local", + "command": ["uvx", "--from", "scrapling", "scrapling", "mcp"], + "enabled": True, + } + cfg.write_text(jsonc.dumps(data), encoding="utf-8") + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 1, buf.getvalue()) + self.assertIn("FAIL mcp:scrapling", buf.getvalue()) + + def test_doctor_scrapling_valid_passes(self): + self._install() + cfg = self.tmp / ".config" / "opencode" / "opencode.jsonc" + data = jsonc.loads(cfg.read_text(encoding="utf-8")) + data["mcp"]["scrapling"] = { + "type": "local", + "command": ["uvx", "--from", "scrapling[ai]==0.4.15", "scrapling", "mcp"], + "enabled": True, + } + cfg.write_text(jsonc.dumps(data), encoding="utf-8") + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 0, buf.getvalue()) + self.assertIn("CONFIGURED mcp:scrapling", buf.getvalue()) + + def test_doctor_scrapling_enable_and_disable(self): + self._install() + rc = cmd_scrapling_enable() + self.assertEqual(rc, 0) + cfg = self.tmp / ".config" / "opencode" / "opencode.jsonc" + data = jsonc.loads(cfg.read_text(encoding="utf-8")) + servers = jsonc.mcp_servers_from_config(data) + self.assertIn("scrapling", servers) + self.assertEqual(servers["scrapling"]["type"], "local") + self.assertEqual(servers["scrapling"]["command"], ["uvx", "--from", "scrapling[ai]==0.4.15", "scrapling", "mcp"]) + self.assertNotIn("0.0.0.0", str(servers["scrapling"])) + + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 0, buf.getvalue()) + self.assertIn("CONFIGURED mcp:scrapling", buf.getvalue()) + + rc = cmd_scrapling_disable() + self.assertEqual(rc, 0) + data = jsonc.loads(cfg.read_text(encoding="utf-8")) + servers = jsonc.mcp_servers_from_config(data) + self.assertNotIn("scrapling", servers) + + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 0, buf.getvalue()) + self.assertIn("OPTIONAL_ABSENT mcp:scrapling", buf.getvalue()) + + def test_doctor_agent_reach_cli_findings(self): + self._install() + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 0, buf.getvalue()) + self.assertIn("OPTIONAL_ABSENT Agent-Reach CLI NOT_INSTALLED", buf.getvalue()) + + # Mock agent-reach in mock-bin + ar_bin = self.tmp / "bin" / "agent-reach" + ar_bin.parent.mkdir(parents=True, exist_ok=True) + ar_bin.write_text("#!/bin/sh\necho '1.5.0'\n", encoding="utf-8") + ar_bin.chmod(0o755) + old_path = os.environ.get("PATH", "") + os.environ["PATH"] = f"{ar_bin.parent}:{old_path}" + try: + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor() + self.assertEqual(rc, 0, buf.getvalue()) + self.assertIn("PASS Agent-Reach CLI", buf.getvalue()) + self.assertIn("1.5.0", buf.getvalue()) + finally: + os.environ["PATH"] = old_path + + def test_doctor_foreign_skill_shadow_warning(self): + self._install() + skills_dir = self.tmp / ".config" / "opencode" / "skills" + + # Create unmanaged foreign skill directory + shadow = skills_dir / "agent-reach" + shadow.mkdir(parents=True, exist_ok=True) + (shadow / "SKILL.md").write_text("---\nname: agent-reach\n---\n", encoding="utf-8") + + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor(strict=False) + self.assertEqual(rc, 0, buf.getvalue()) + self.assertIn("WARN FOREIGN_SKILL_SHADOW", buf.getvalue()) + self.assertIn("agent-reach: foreign skill hijacking router", buf.getvalue()) + + # With ownership marker, warning should not be emitted + (shadow / ".opencode-highend.json").write_text("{}", encoding="utf-8") + buf = io.StringIO() + with redirect_stdout(buf): + rc = cmd_doctor(strict=False) + self.assertNotIn("FOREIGN_SKILL_SHADOW", buf.getvalue()) + if __name__ == "__main__": unittest.main() diff --git a/tests/test_isolation.py b/tests/test_isolation.py index 92e6bfb..b3bdfd2 100644 --- a/tests/test_isolation.py +++ b/tests/test_isolation.py @@ -59,6 +59,27 @@ def test_no_personal_path(self): hits.append(str(path.relative_to(ROOT))) self.assertEqual(hits, []) + def test_no_zero_host_bindings(self): + # 0.0.0.0 must never be configured as a target host or bind address in code or configs + install_py = (ROOT / "lib" / "install.py").read_text(encoding="utf-8") + self.assertNotIn("0.0.0.0", install_py) + + mcp_policy = (ROOT / "vendor" / "mcp-policy.json").read_text(encoding="utf-8") + self.assertNotIn("0.0.0.0", mcp_policy) + + mcp_wanted = (ROOT / "vendor" / "mcp-wanted.json").read_text(encoding="utf-8") + self.assertNotIn("0.0.0.0", mcp_wanted) + + sources = (ROOT / "vendor" / "sources.json").read_text(encoding="utf-8") + self.assertNotIn("0.0.0.0", sources) + + # In lib/, 0.0.0.0 can only appear in doctor.py defensive checks + for p in (ROOT / "lib").rglob("*.py"): + text = p.read_text(encoding="utf-8") + if "0.0.0.0" in text: + self.assertEqual(p.name, "doctor.py", f"Unexpected 0.0.0.0 in {p}") + self.assertIn("forbidden", text) + if __name__ == "__main__": unittest.main() diff --git a/tests/test_mcp.py b/tests/test_mcp.py index a0e8071..b39e6a7 100644 --- a/tests/test_mcp.py +++ b/tests/test_mcp.py @@ -87,6 +87,22 @@ def test_comment_preserving_mcp_upsert(self): self.assertIn("foreign-weather", data["mcp"]) self.assertEqual(data["mcp"]["servers"]["context7"]["type"], "remote") + def test_scrapling_policy_and_wanted(self): + policy = jsonc.loads((ROOT / "vendor" / "mcp-policy.json").read_text(encoding="utf-8")) + self.assertIn("scrapling", policy["servers"]) + sc_policy = policy["servers"]["scrapling"] + self.assertFalse(sc_policy["enabled"]) + self.assertEqual(sc_policy["transport"], "stdio") + self.assertEqual(sc_policy["command"], "uvx") + self.assertEqual(sc_policy["args"], ["--from", "scrapling[ai]==0.4.15", "scrapling", "mcp"]) + + wanted = jsonc.loads((ROOT / "vendor" / "mcp-wanted.json").read_text(encoding="utf-8")) + self.assertIn("scrapling", wanted["servers"]) + sc_wanted = wanted["servers"]["scrapling"] + self.assertEqual(sc_wanted["status"], "FOREIGN_ON_DEMAND") + self.assertFalse(sc_wanted["wanted"]) + self.assertEqual(sc_wanted["transport"], "stdio") + if __name__ == "__main__": unittest.main() diff --git a/tests/test_routing.py b/tests/test_routing.py index 02ed721..f2372b5 100644 --- a/tests/test_routing.py +++ b/tests/test_routing.py @@ -75,8 +75,12 @@ def test_new_specialist_boundaries(self): # Hyperframes vs visual-studio vs scroll self.assertIn("Deterministic HTML video / render HTML to MP4 → skill `hyperframes`", self.agents) self.assertIn("Deterministic HTML composition rendered to video: `/hyperframes`", self.routing) + self.assertIn("prompt-patterns.md", self.routing) self.assertIn("Ordinary scrollable UI stays `/impeccable`.", self.routing) + # Domain modeling GLOSSARY.md + self.assertIn("GLOSSARY.md", self.routing) + # id-demo-video vs hyperframes vs playwright-qa vs visual-studio self.assertIn("Demo video aplikasi / walkthrough layar / narasi Indonesia / demo lomba → skill `id-demo-video`", self.agents) self.assertIn("Demo video aplikasi, walkthrough layar, narasi Indonesia, demo lomba: skill `id-demo-video`", self.routing) @@ -271,6 +275,45 @@ def test_pageindex_routing_boundary(self): research = (ROOT / "skills" / "research" / "SKILL.md").read_text(encoding="utf-8") self.assertIn("pageindex", research) + def test_web_research_routing_boundary(self): + # Intent presence + self.assertIn("web_research", self.agents) + self.assertIn("`web_research` | `research`", self.routing) + docs = (ROOT / "docs" / "routing.md").read_text(encoding="utf-8") + self.assertIn("`web_research` | `research`", docs) + + # 25 closed intents in templates/AGENTS.md, rules/00-routing.md, docs/routing.md + intents_agents = [ + x.strip("` ") + for x in self.agents.split("Classify into exactly one intent before acting:\n`")[1] + .split("`\n")[0] + .split("|") + ] + self.assertEqual(len(intents_agents), 25) + self.assertIn("web_research", intents_agents) + + # Boundaries & references + self.assertIn("references/web-data.md", self.agents) + self.assertIn("bukan `playwright-qa`", self.agents) + web_data_ref = ROOT / "skills" / "research" / "references" / "web-data.md" + self.assertTrue(web_data_ref.is_file()) + web_data_text = web_data_ref.read_text(encoding="utf-8") + self.assertIn("Backend Selection Ladder", web_data_text) + self.assertIn("scrapling", web_data_text.lower()) + self.assertIn("agent-reach", web_data_text.lower()) + self.assertIn("crawl4ai", web_data_text.lower()) + self.assertIn("playwright-qa", web_data_text.lower()) + + research_skill = (ROOT / "skills" / "research" / "SKILL.md").read_text(encoding="utf-8") + self.assertIn("web-data.md", research_skill) + self.assertIn("playwright-qa", research_skill) + + # Neighbor skills have boundaries + pw_skill = (ROOT / "skills" / "playwright-qa" / "SKILL.md").read_text(encoding="utf-8") + self.assertIn("web-data.md", pw_skill) + ba_skill = (ROOT / "skills" / "browser-act" / "SKILL.md").read_text(encoding="utf-8") + self.assertIn("web-data.md", ba_skill) + def test_no_context_guard_rule(self): self.assertFalse((ROOT / "rules" / "04-context-guard.md").exists()) diff --git a/tests/test_skills.py b/tests/test_skills.py index 0d174a1..998d310 100644 --- a/tests/test_skills.py +++ b/tests/test_skills.py @@ -152,6 +152,121 @@ def test_no_foreign_runtime_path(self): text = path.read_text(encoding="utf-8") self.assertIsNone(FOREIGN_PATH_RE.search(text), name) + def test_research_skill_boundaries(self): + skill_path = ROOT / "skills" / "research" / "SKILL.md" + self.assertTrue(skill_path.is_file()) + text = skill_path.read_text(encoding="utf-8") + fm = frontmatter(skill_path) + desc = fm.get("description", "") + self.assertIn("web or social data gathering", desc) + self.assertIn("web-data.md", text) + self.assertIn("playwright-qa", text) + + ref_path = ROOT / "skills" / "research" / "references" / "web-data.md" + self.assertTrue(ref_path.is_file()) + ref_text = ref_path.read_text(encoding="utf-8") + self.assertIn("Backend Selection Ladder", ref_text) + self.assertIn("Ethical and Safety Boundaries", ref_text) + self.assertIn("scrapling", ref_text.lower()) + self.assertIn("agent-reach", ref_text.lower()) + + # Ensure research description has low overlap with all skills (< 0.50) + desc_tokens = set(TOKEN_RE.findall(desc.lower())) + for name, other_path in skill_files(): + if name == "research": + continue + other_desc = frontmatter(other_path).get("description", "") + other_tokens = set(TOKEN_RE.findall(other_desc.lower())) + score = jaccard(desc_tokens, other_tokens) + self.assertLess(score, OVERLAP_WARN, f"Overlap between research and {name} is {score:.2f} >= {OVERLAP_WARN}") + + +class SkillRefreshTests(unittest.TestCase): + def test_hyperframes_refresh(self): + comp = (ROOT / "skills" / "hyperframes" / "references" / "composition.md").read_text(encoding="utf-8") + self.assertIn("data-composition-id", comp) + self.assertIn("data-width", comp) + self.assertIn("data-height", comp) + self.assertIn("data-start", comp) + self.assertIn("data-duration", comp) + self.assertNotIn("window.renderFrame", comp) + + render = (ROOT / "skills" / "hyperframes" / "references" / "render.md").read_text(encoding="utf-8") + self.assertIn("npx hyperframes render", render) + self.assertIn("Node.js ≥22", render) + self.assertIn("NOT_CONFIGURED", render) + + brag = (ROOT / "skills" / "hyperframes" / "references" / "brag.md").read_text(encoding="utf-8") + self.assertIn("data-composition-id", brag) + self.assertIn("npx hyperframes render . -o brag-output/brag.mp4 -f 60 -q delivery", brag) + self.assertNotIn("-W 1920", brag) + self.assertNotIn("-H 1080", brag) + self.assertNotIn("-d 18", brag) + + skill = (ROOT / "skills" / "hyperframes" / "SKILL.md").read_text(encoding="utf-8") + self.assertIn("references/prompt-patterns.md", skill) + self.assertIn("npx skills add heygen-com/hyperframes", skill) + self.assertIn("npx hyperframes skills update", skill) + + notice = (ROOT / "skills" / "hyperframes" / "NOTICE.md").read_text(encoding="utf-8") + self.assertIn("v0.8.119", notice) + self.assertIn("3a0299e851ce", notice) + + def test_prompt_patterns_reference(self): + pat_path = ROOT / "skills" / "hyperframes" / "references" / "prompt-patterns.md" + self.assertTrue(pat_path.is_file()) + lines = pat_path.read_text(encoding="utf-8").splitlines() + self.assertLessEqual(len(lines), 90) + content = "\n".join(lines) + self.assertIn("POINTER_ONLY", content) + self.assertIn("awesome-opus5-5-videos", content) + self.assertIn("3d54892e2ae5b0e8d337171e6508bba4cec01ab8", content) + self.assertNotIn("utm_", content) + + routing = (ROOT / "rules" / "00-routing.md").read_text(encoding="utf-8") + self.assertIn("prompt-patterns.md", routing) + self.assertIn("Deterministic HTML composition rendered to video: `/hyperframes`", routing) + + def test_matt_cluster_glossary_migration(self): + self.assertTrue((ROOT / "skills" / "domain-modeling" / "GLOSSARY-FORMAT.md").is_file()) + self.assertFalse((ROOT / "skills" / "domain-modeling" / "CONTEXT-FORMAT.md").exists()) + + dm_skill = (ROOT / "skills" / "domain-modeling" / "SKILL.md").read_text(encoding="utf-8") + self.assertIn("GLOSSARY.md", dm_skill) + self.assertIn("GLOSSARY-MAP.md", dm_skill) + self.assertIn("Legacy fallback", dm_skill) + self.assertIn("CONTEXT.md", dm_skill) + + gwd_skill = (ROOT / "skills" / "grill-with-docs" / "SKILL.md").read_text(encoding="utf-8") + self.assertIn("GLOSSARY.md", gwd_skill) + self.assertIn("Legacy fallback", gwd_skill) + self.assertIn("CONTEXT.md", gwd_skill) + + for rel in [ + "skills/codebase-design/DESIGN-IT-TWICE.md", + "skills/tdd/SKILL.md", + "skills/diagnosing-bugs/SKILL.md", + "manual-skills/improve-codebase-architecture/SKILL.md", + "manual-skills/why/SKILL.md", + ]: + text = (ROOT / rel).read_text(encoding="utf-8") + self.assertIn("GLOSSARY.md", text, f"Expected GLOSSARY.md in {rel}") + + def test_dead_references_removed(self): + for rel in ["skills/visual-studio/SKILL.md", "skills/scroll-world/SKILL.md"]: + text = (ROOT / rel).read_text(encoding="utf-8") + self.assertNotIn("game-asset-core", text, f"Found game-asset-core in {rel}") + self.assertIn("NOT_APPLICABLE", text, f"Expected NOT_APPLICABLE in {rel}") + + def test_humanizer_refresh(self): + notice = (ROOT / "skills" / "humanizer" / "NOTICE.md").read_text(encoding="utf-8") + self.assertIn("3.1.0", notice) + self.assertIn("225a6f39ac85", notice) + + patterns = (ROOT / "skills" / "humanizer" / "references" / "patterns.md").read_text(encoding="utf-8") + self.assertIn("Writing about the document instead of its subject", patterns) + self.assertIn("Re-explaining context the reader already knows", patterns) + if __name__ == "__main__": unittest.main() diff --git a/vendor/license-audit.json b/vendor/license-audit.json index c0a9d85..3440f5f 100644 --- a/vendor/license-audit.json +++ b/vendor/license-audit.json @@ -1,7 +1,7 @@ { "schemaVersion": 1, "product": "OpenCodeHighEnd", - "productVersion": "0.1.10", + "productVersion": "0.1.12", "note": "Evidence-based. A missing frontmatter license is not a grant. Adapted \u2260 first-party.", "skills": { "demo-video": { @@ -26,42 +26,42 @@ }, "diagnosing-bugs": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c + vendor/licenses/MATT-POCOCK-MIT.txt", + "evidence": "mattpocock/skills d81f3a1 + vendor/licenses/MATT-POCOCK-MIT.txt", "redistribution": "mit" }, "domain-modeling": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c", + "evidence": "mattpocock/skills d81f3a1", "redistribution": "mit" }, "codebase-design": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c", + "evidence": "mattpocock/skills d81f3a1", "redistribution": "mit" }, "writing-for-agents": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c", + "evidence": "mattpocock/skills d81f3a1", "redistribution": "mit" }, "research": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c", + "evidence": "mattpocock/skills d81f3a1", "redistribution": "mit" }, "prototype": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c", + "evidence": "mattpocock/skills d81f3a1", "redistribution": "mit" }, "improve-codebase-architecture": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c", + "evidence": "mattpocock/skills d81f3a1", "redistribution": "mit" }, "wizard": { "license": "MIT", - "evidence": "mattpocock/skills 9c9f36c", + "evidence": "mattpocock/skills d81f3a1", "redistribution": "mit" }, "grill-with-docs": { diff --git a/vendor/mcp-policy.json b/vendor/mcp-policy.json index 7b46bff..2a10e1f 100644 --- a/vendor/mcp-policy.json +++ b/vendor/mcp-policy.json @@ -60,6 +60,12 @@ "enabled": false, "transport": "http", "url": "http://127.0.0.1:11235/mcp" + }, + "scrapling": { + "enabled": false, + "transport": "stdio", + "command": "uvx", + "args": ["--from", "scrapling[ai]==0.4.15", "scrapling", "mcp"] } } } diff --git a/vendor/mcp-wanted.json b/vendor/mcp-wanted.json index cb1f538..9738b16 100644 --- a/vendor/mcp-wanted.json +++ b/vendor/mcp-wanted.json @@ -80,6 +80,15 @@ "transport": "http", "url": "http://127.0.0.1:11235/mcp", "status": "FOREIGN_ON_DEMAND" + }, + "scrapling": { + "wanted": false, + "ownedIfAdded": false, + "scope": "user", + "transport": "stdio", + "command": "uvx", + "args": ["--from", "scrapling[ai]==0.4.15", "scrapling", "mcp"], + "status": "FOREIGN_ON_DEMAND" } } } diff --git a/vendor/provenance.json b/vendor/provenance.json index 804faf6..86d8e34 100644 --- a/vendor/provenance.json +++ b/vendor/provenance.json @@ -1,7 +1,7 @@ { "schemaVersion": 1, "product": "OpenCodeHighEnd", - "productVersion": "0.1.10", + "productVersion": "0.1.12", "firstPartyLicense": "MIT", "components": [ { @@ -26,6 +26,7 @@ "component": "grill-with-docs", "path": "skills/grill-with-docs", "upstream": "https://github.com/mattpocock/skills", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/grill-with-docs", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", @@ -37,6 +38,7 @@ "component": "to-spec", "path": "skills/to-spec", "upstream": "https://github.com/mattpocock/skills", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/to-spec", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", @@ -47,6 +49,7 @@ "component": "to-tickets", "path": "skills/to-tickets", "upstream": "https://github.com/mattpocock/skills", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/to-tickets", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", @@ -57,6 +60,7 @@ "component": "tdd", "path": "skills/tdd", "upstream": "https://github.com/mattpocock/skills", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/tdd", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", @@ -67,6 +71,7 @@ "component": "matt-code-review", "path": "skills/matt-code-review", "upstream": "https://github.com/mattpocock/skills", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/code-review", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", @@ -173,9 +178,9 @@ "component": "diagnosing-bugs", "path": "vendor/skills/diagnosing-bugs", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/diagnosing-bugs", - "upstreamSkillMdSha256": "573142d28dc5a4d931dd4a6faa3e615e731f8e9cc65d2dd4468045a2efd6148c", + "upstreamSkillMdSha256": "9168404abda0967a5d32977e3498cd95fda6807018852f3de736a78357c82b40", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, @@ -186,22 +191,22 @@ "component": "domain-modeling", "path": "vendor/skills/domain-modeling", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/domain-modeling", - "upstreamSkillMdSha256": "9617041db9b0f6606ecf974e2061c83596b05059b5bb20ddb884c60f147c70e9", + "upstreamSkillMdSha256": "7b925d7b1e341a2eeae33ad68a8a8c0ab889a38ddd22a7598e4c240e5a7556a3", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, "redistribution": "mit", - "notes": "Description skip /grill-with-docs. CONTEXT-FORMAT.md and ADR-FORMAT.md kept. agents/openai.yaml not vendored." + "notes": "Description skip /grill-with-docs. GLOSSARY-FORMAT.md and ADR-FORMAT.md kept. agents/openai.yaml not vendored." }, { "component": "codebase-design", "path": "vendor/skills/codebase-design", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/codebase-design", - "upstreamSkillMdSha256": "a8d50abac5a4018f60e1d911d4b6f4e36454ca14d6c390c0695a578c7de65dad", + "upstreamSkillMdSha256": "2c20617f87ec8af6a434859f381b2f061a69b530444e74eb39e78bb016a6d1e2", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, @@ -212,9 +217,9 @@ "component": "writing-for-agents", "path": "vendor/skills/writing-for-agents", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/productivity/writing-for-agents", - "upstreamSkillMdSha256": "a842323e664e5af104eac5c97ad22fda929ebeb62d81c501161ac1f6f482db58", + "upstreamSkillMdSha256": "551adca942227b44192edba88acd4e8db911f0121ce58ad16944ccf6a896a74a", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, @@ -225,9 +230,9 @@ "component": "research", "path": "vendor/skills/research", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/research", - "upstreamSkillMdSha256": "af378829f015775a3bcd65ff466826722e99359017ae6bae227ca4c9bd14049c", + "upstreamSkillMdSha256": "985569f15739c713d6784887c3d186d4ef9ac85bec5ad9c068d25bf0739928e4", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, @@ -238,9 +243,9 @@ "component": "prototype", "path": "vendor/skills/prototype", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/prototype", - "upstreamSkillMdSha256": "2579ecf89a7fb7e73345117405c7ba9b9fb5ab22a78ecb08b0ce68b73f0148c2", + "upstreamSkillMdSha256": "714de632d116bb73f65cdb5a882db15b9369a6713b9a47c0fad827848f0bfbe3", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, @@ -251,9 +256,9 @@ "component": "improve-codebase-architecture", "path": "vendor/skills/improve-codebase-architecture", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/improve-codebase-architecture", - "upstreamSkillMdSha256": "387f38d21367761c94d4b4dcea9e9d7d3e31f896c4decebf4984483e42125cfc", + "upstreamSkillMdSha256": "552240a5ab5cec6b67c15dd1ad6e9f6962b1bca6ce870059a8c2713760c20392", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, @@ -264,9 +269,9 @@ "component": "wizard", "path": "vendor/skills/wizard", "upstream": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "originalPath": "skills/engineering/wizard", - "upstreamSkillMdSha256": "7fb2b4ba23870ec028c85c6d7ef1ca573413ca7026bd4d410fe0e6d8dc9d1e92", + "upstreamSkillMdSha256": "bdf31d48211ea559878f95a4f344aeabf8d85897488ba564382bab0b000daac1", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "modified": true, diff --git a/vendor/sources.json b/vendor/sources.json index 53f3b76..19c6ddd 100644 --- a/vendor/sources.json +++ b/vendor/sources.json @@ -1,7 +1,7 @@ { "schemaVersion": 1, "product": "OpenCodeHighEnd", - "productVersion": "0.1.10", + "productVersion": "0.1.12", "sources": { "codebase-memory": { "repository": "https://github.com/DeusData/codebase-memory-mcp", @@ -72,6 +72,27 @@ "status": "foreign-on-demand", "note": "Optional MCP via uvx --from markitdown-mcp==0.1.8. Not vendored. No Azure keys. Enabled via opencode-he markitdown enable." }, + "scrapling": { + "repository": "https://github.com/D4Vinci/Scrapling", + "version": "0.4.15", + "commit": "333fa22b7a5821194ce66b59b11f4b16a6484f02", + "license": "BSD-3-Clause", + "package": "scrapling", + "via": "uvx", + "transport": "stdio", + "status": "foreign-on-demand", + "wheelSha256": "ae66bde9f63afb793ad6f93bd76b451e29f1631347465a553c4e7765c0ecc1f2", + "sdistSha256": "72406900f437316209dd05d9853dae04420f1cab0e11071604bb4588b6e2f713", + "note": "Optional MCP via uvx --from scrapling[ai]==0.4.15 scrapling mcp. Not vendored. Enabled via opencode-he scrapling enable. Do not run scrapling install (requires sudo / playwright install-deps)." + }, + "agent-reach": { + "repository": "https://github.com/Panniantong/Agent-Reach", + "version": "1.5.0", + "commit": "f65526cbaaad3879473acc1ba6dbefd195caf2be", + "license": "MIT", + "status": "pointer-only", + "note": "POINTER_ONLY, not installed by OCH. PyPI name agent-reach belongs to another project; install via git URL with pipx if desired. Do not run agent-reach install --system." + }, "browser-act": { "repository": "https://github.com/browser-act/skills", "commit": "11c057b03f92101642cadc9f840564574120d184", @@ -130,24 +151,25 @@ }, "hyperframes": { "repository": "https://github.com/heygen-com/hyperframes", - "commit": "ed75203cb6aa", - "version": "0.8.64", + "commit": "3a0299e851ce", + "version": "0.8.119", "license": "Apache-2.0" }, "diagram-design": { "repository": "https://github.com/cathrynlavery/diagram-design", - "commit": "dc1ace47b99a", - "version": "2.6.33", + "commit": "f903933a534b", + "version": "2.6.51", "license": "MIT" }, "humanizer": { "repository": "https://github.com/blader/humanizer", - "version": "3.0.0", + "commit": "225a6f39ac85", + "version": "3.1.0", "license": "MIT" }, "matt-pocock-skills": { "repository": "https://github.com/mattpocock/skills", - "commit": "9c9f36ccd3995266cd675468af71639c8dde1ec5", + "commit": "d81f3a183412e71a5b1e84ca21bc1a35eea03a60", "license": "MIT", "copyright": "Copyright (c) 2026 Matt Pocock", "licenseFile": "vendor/licenses/MATT-POCOCK-MIT.txt"