Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude-plugin/marketplace.base.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@
"plugins": [],
"metadata": {
"description": "Agent collaboration plugin marketplace",
"version": "7.0.6",
"version": "7.0.7",
"repository": "https://github.com/sumitake/agent-collab"
}
}
4 changes: 2 additions & 2 deletions .claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
{
"name": "agent-collab",
"description": "Unified collaboration package with semantic actions, source-grounded context, empirical project estimation, and a verified plugin-relative direct native runtime.",
"version": "7.0.6",
"version": "7.0.7",
"author": {
"name": "John Osumi"
},
Expand All @@ -34,7 +34,7 @@
],
"metadata": {
"description": "Agent collaboration plugin marketplace",
"version": "7.0.6",
"version": "7.0.7",
"repository": "https://github.com/sumitake/agent-collab"
}
}
41 changes: 21 additions & 20 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
# agent-collab

`agent-collab` publishes one collaboration plugin for Claude Code, Codex, and
compatible hosts. Version 7.0.6 pairs a routing-only public client with the
compatible hosts. The package pairs a routing-only public client with the
co-packaged direct native runtime. Callers choose logical work; provider output
remains opaque content for the calling agent to interpret.

This public repository's current source is **agent-collab** (v7.0.6).
This public repository's current source is **agent-collab** (v7.0.7).

Current published release: **7.0.6** ([`v7.0.6`](https://github.com/sumitake/agent-collab/releases/tag/v7.0.6)).
It carries signed provider runtime `5.0.7`. Host installation, readiness, and
Expand All @@ -18,22 +18,23 @@ machine-operational contract for the repository source. The dated
records the completed publication and keeps repository, tag, release,
installation, and readiness claims separate.

## What's new - v7.0.6
## What's new - v7.0.7

When independent review is required, the skills make reviewer independence a
caller responsibility. Before dispatch, the caller establishes the primary and
artifact-author families and checks the proposed reviewer. Afterward, it verifies the observed reviewer
family and source before accepting independent evidence. Unknown lineage stays
unknown; a routing result alone does not establish independence.
Ordinary code review can still use available Gemini when no eligible independent
reviewer exists, with an explicit advisory label and no independent-approval claim.
The 7.0.7 source prepares runtime `5.0.8`. Native calls keep the operating
account's login context and SSH session markers. Bounded native output remains
available when optional event metadata or Unicode is irregular. Eligible
read-only Gemini work can complete one correlated empty successful turn within
the same native process, retaining the original diagnostic and recovered answer.

This content update retains the signed runtime `5.0.7` and wire schema 12
unchanged. The release is published, and all 178 released files match each of
the four observed local installations. Provider-free planning and migration
checks passed from the control session against those roots; existing tasks
still need a fresh session to load updated skills. The dated status snapshot
records those limits and the unresolved Claude subscription-access denial.
Reviewer selection considers every contributing author family. Independent
approval requires response-correlated native evidence; unverified results stay
advisory. A demonstrated caller setup defect permits at most one corrected
read-only request per original request across all descendants, without
replaying uncertain mutations or switching providers.

Signed dual-architecture delivery and staged qualification are in progress.
The currently published release remains 7.0.6; this source preparation does not
claim a new release, installation, or provider availability.

For earlier release history, see the full [CHANGELOG](CHANGELOG.md).

Expand Down Expand Up @@ -122,18 +123,18 @@ size-branded source or generated skill surface is supported.
## Runtime trust boundary

The canonical workspace build owns the final binary and generated manifest.
The published package carries:
The 7.0.7 source targets:

- manifest schema 4;
- runtime protocol 5;
- native manifest contract 4;
- provider runtime version `5.0.7`;
- provider runtime version `5.0.8`;
- one top-level closed `wire_contract` plus canonical
`wire_contract_sha256`, bound into each artifact record; and
- wire schema 12 with 12 logical actions and per-action timeout modes.

The checked-in signed artifact rows are the imported 5.0.7 / wire-schema-12
generation for both macOS architectures.
Both macOS architectures carry the imported signed and notarized 5.0.8
artifact set. Wire schema 12 is unchanged.

Production provider work uses admitted progress inactivity so active work is
not killed by a strict elapsed timer. Homogeneous `total_deadline` requests
Expand Down
9 changes: 9 additions & 0 deletions changelog.d/2026-09-14-001-read-only-fresh-review.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
### Changed

- Document one bounded caller fresh-review for read-only review and
governance skills: after a completed or terminated attempt with no
substantive result and no uncertain external mutation, the caller may
issue at most one new corrected work unit to fix a demonstrated setup
defect while retaining the failed attempt. Shared consumed-work
no-replay, worker, dev-delegate, and merge-resolve contracts stay
unchanged.
7 changes: 7 additions & 0 deletions changelog.d/2026-09-15-001-native-home-recovery.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
### Fixed

- Use the OS account's canonical home for native execution and preserve SSH
session markers so providers retain their own login behavior. Request files
remain temporary; login profiles are not copied.
- Clarify that native recovery stays within the original invocation and that
existing operator authorization persists across tool steps in the same scope.
14 changes: 14 additions & 0 deletions changelog.d/2026-09-15-002-reviewer-selection-evidence.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
### Changed

- Clarify that provider-free planning reports route eligibility, not reviewer
family identity. Candidate selection may use currently known configuration or
response-scoped observations; independent approval after return requires
response-scoped evidence distinct from the primary and every contributing
author family. Governance-review and plugin README invocation use the same
caller-verified checks. Chain keeps its existing routing exclusions; those
exclusions do not prove response identity or all-contributor independence.
- Seat required initial reviewers first and reserve a tiebreaker only from spare
independent eligible reviewers. A sole eligible independent reviewer is used
initially; unmet required panel size stays visible.
- Document optional response-scoped native model-identity observations in
provider-neutral public guidance without expanding the signed wire.
6 changes: 6 additions & 0 deletions changelog.d/2026-09-16-review-guidance-boundaries.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
### Fixed

- Align architecture handbook guidance with all-contributor family exclusion and response-correlated native reviewer identity. Configuration may identify a candidate but cannot establish independent approval. Missing reviewer evidence leaves independent approval unmet and content advisory; it is not provider unavailability.

- Keep logic-check status advisory until response-scoped evidence establishes reviewer independence, and compare every contributing author family during reviewer selection.
- Limit the caller's corrected read-only review to one correction per original request across descendants; explicitly exclude ambiguous native mutations in generated guidance.
7 changes: 7 additions & 0 deletions changelog.d/2026-09-16-runtime-508-distribution.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
### agent-collab 7.0.7 — runtime 5.0.8

- Pair runtime 5.0.8 with the public client that preserves canonical account HOME and native SSH context. Both macOS architectures must pass the coordinated signing, import and staged qualification gates before publication.
- Gemini's existing native carrier supports one correlated read-only completion after an empty successful turn in the same process, keeping the original diagnostic and recovered answer. Codex tolerates nonprotocol startup noise and malformed optional tool metadata. Codex and ACP preserve irregular Unicode and correctly scope optional model observations. Shared interactive stdin writes remain under supervision and backpressure handling.
- Existing native transports and descriptor-admitted actions remain in place; no provider fallback, automatic request replay, replacement login profile, broker, or new route is introduced. Claude and Grok transport selection is unchanged; no omitted Claude profile is activated.
- Keep wire schema 12, protocol 5, native contract 4, 12 logical actions, eight logical agents and wire digest `a675807e0ff5f0544d7cc9d659914ce2dadac9be8efd0fb56635815e5c3e842a` unchanged. Bind the new public client and release-exact manifest schema to the signed producer.
- Retain caller-owned independent-review checks, advisory results when evidence is missing, all-author reviewer selection and a nonrenewable corrected-review allowance.
3 changes: 2 additions & 1 deletion docs/architecture/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,8 @@ The public repository and package preserve these invariants:
2. Callers select a skill or logical collaboration job. They do not receive a
raw provider-execution escape hatch.
3. Governance review requires a model family independent of the active primary
and the reviewed artifact's known author family.
and every contributing artifact-author family, established through native
identity evidence correlated to the returned review.
4. Route authorities are closed. Read-only, output-only, and unavailable
actions do not promote themselves because another route failed.
5. Provider output is an artifact for the trusted primary to inspect. It does
Expand Down
15 changes: 9 additions & 6 deletions docs/architecture/capabilities-and-workflows.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,16 +94,18 @@ the primary for integration.
1. Identify the artifact, primary, authors and whether the task requires
independent approval.
2. Use the appropriate review skill. For required independence, verify a
reviewer outside the primary and author families and bind that selection to
the live call. Verify observed reviewer lineage and exact source afterward.
candidate outside the primary and every contributing author family and bind
that selection to the live call. After return, verify native identity
evidence correlated to that response and the exact reviewed source;
configuration-scoped identity alone cannot establish independent approval.
3. For ordinary code review, an available Gemini reviewer can still help when
no distinct-family reviewer is available. Label same-family or unknown
lineage as advisory; leave any independent approval requirement unmet.
4. Preserve and adjudicate the raw findings. Do not infer independence from
routing, role names or a subscription, repeatedly attempt an unavailable
provider, or replay a consumed request to repair formatting or evidence.

This is caller-owned behavior in the [released code-review
This is caller-owned behavior in the [code-review
skill](../../skill-specs/code-review.md). The routing request has no dynamic
primary/artifact-author lineage exclusion fields.

Expand Down Expand Up @@ -175,9 +177,10 @@ A capability is usable only when all applicable gates pass:

Runtime and planning diagnostics describe the attempted route; they do not
perform the caller's family-exclusion check or establish provider-wide failure.
Missing independent-review evidence leaves that requirement unmet. Preserve
available advisory content without claiming broader authority, silently
substituting an operator-named target, or replaying a consumed request.
Missing independent-review evidence leaves that requirement unmet; it is not
provider unavailability. Preserve available advisory content without claiming
broader authority, silently substituting an operator-named target, or replaying
a consumed request.

For installation and recovery, continue to
[Lifecycle and operations](lifecycle-and-operations.md).
9 changes: 5 additions & 4 deletions docs/architecture/claude-participation.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,10 +67,11 @@ authors and integrates work, adjudicates cross-family feedback, runs
verification, and owns landing decisions within operator authority.

The native document-intent route does not change independence rules. When the
active primary or artifact author is Anthropic-family, the primary and repository/skill workflow must exclude
same-family evidence where an independent family is required. Conversely,
when another family is primary, Claude document intent remains context only;
it cannot satisfy a review or governance evidence contract.
active primary or any contributing artifact author is Anthropic-family, the
primary and repository/skill workflow must exclude same-family evidence where
an independent family is required. Conversely, when another family is primary,
Claude document intent remains context only; it cannot satisfy a review or
governance evidence contract.

## Asynchronous participation

Expand Down
53 changes: 33 additions & 20 deletions docs/architecture/governance-and-authority.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,22 +10,29 @@ tool call is not evidence that the caller should receive broader permissions.
## Independence model

For governance-grade review, repository and skill policy requires a recorded
active-primary lineage and artifact-author lineage. The primary must select
and preserve evidence from a reviewer outside both required families. If either
lineage is unknown, the governance workflow fails closed. OpenCode is a
transport/host surface; the selected model's lineage supplies family provenance.
active-primary lineage and the lineage of every contributing artifact author.
The primary must select a reviewer outside the primary and all contributing
author families. If any required lineage is unknown, independent approval
remains unmet. Missing reviewer identity evidence is not provider
unavailability: keep usable advisory content, do not stop ordinary read-only
advisory work, and do not replay a consumed request to improve lineage.
OpenCode is a transport/host surface; the selected model's lineage supplies
family provenance.

The current public runtime request has no primary or artifact-author-lineage
field. It does not dynamically perform this exclusion. The skill and repository
workflow require it, and the primary verifies the selected reviewer and the
substance of the exact-head review.

For an authorized independent review, the caller binds its verified reviewer
selection to the actual request, honors an operator-named provider, and checks
observed native lineage afterward. Planning an untargeted call does not reserve
that selection for a later call. Role names, receipts and routing success do
not establish independence, and a consumed request is not replayed to improve
its evidence. The [released review skill](../../skill-specs/code-review.md)
For an authorized independent review, known native configuration or earlier
observations can identify a candidate. The caller binds that selection to the
actual request and honors an operator-named provider. After return, independent
approval requires response-scoped native identity evidence correlated to that
specific response, plus verification of the reviewed source and findings.
Configuration alone cannot establish that approval. Planning an untargeted
call does not reserve a selection for a later call. Role names, receipts and
routing success do not establish independence, and a consumed request is not
replayed to improve its evidence. The [review skill](../../skill-specs/code-review.md)
contains the caller procedure.

Ordinary code review remains useful when no independent reviewer is available.
Expand All @@ -41,11 +48,11 @@ cannot become governance evidence through a role assignment or successful call.

```mermaid
flowchart LR
Artifact["Artifact plus author lineage"] --> Eligibility["Caller verifies required lineages"]
Artifact["Artifact plus all contributing author lineages"] --> Eligibility["Caller verifies required lineages"]
Primary["Active primary lineage"] --> Eligibility
Eligibility --> Exclude["Caller excludes primary and author families"]
Exclude --> Reviewer["Caller selects an independent reviewer"]
Reviewer --> Evidence["Review artifact or governance verdict"]
Eligibility --> Exclude["Caller excludes primary and every author family"]
Exclude --> Reviewer["Caller selects a reviewer candidate"]
Reviewer --> Evidence["Caller verifies response identity, source and findings"]
Evidence --> PrimaryGate["Primary integration and repository gates"]
```

Expand All @@ -72,7 +79,9 @@ No failure converts one row to another. In particular:
unavailable;
- the runtime does not itself apply output; callers must supply a disposable
copy and verify it before application;
- the governance workflow cannot accept an unknown primary or artifact family;
- independent approval cannot accept an unknown primary or contributing
author family; that missing evidence leaves the requirement unmet and
does not make the provider unavailable;
- an explicit target is not silently replaced by a different provider; and
- a successful result does not gain merge, deployment, release, or policy
authority.
Expand Down Expand Up @@ -115,8 +124,9 @@ The trace proves that required evidence was recorded in the expected form. It
does **not** cryptographically prove that quoted review prose came from the
claimed reviewer. This is an intentional, documented residual boundary:

- skill and repository policy require family independence, verified by the
primary against the actual selected reviewer;
- skill and repository policy require family independence from the primary
and every contributing author, verified against native identity evidence
correlated to the returned response;
- repository automation validates trace form and presence; and
- the primary, independent reviewer, and operator validate substance and exact
head before merge.
Expand Down Expand Up @@ -146,11 +156,14 @@ and its evidence is verified.
## Why these controls matter

- **Different failure modes:** independent model families are more likely to
expose correlated assumptions than another instance of the author's family.
expose correlated assumptions than another instance of the primary or a
contributing author's family.
- **Least authority:** a route receives only the permission its work requires,
reducing the cost of a hallucination or prompt-injection failure.
- **Honest evidence:** unavailable execution and explicitly unknown lineage
remain uncertain; neither is converted into successful governance evidence.
- **Honest evidence:** unavailable execution describes that attempt;
unknown lineage is missing independence evidence. Neither alone establishes
provider-wide failure or independent approval. Preserve usable advisory
content without claiming broader authority.
- **Separation of duties:** authoring, reviewing, integrating, merging, and
releasing remain distinct accountable acts.
- **Recoverability:** an unavailable native artifact stops execution
Expand Down
Loading
Loading