Skip to content
This repository was archived by the owner on Aug 15, 2026. It is now read-only.
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
62 commits
Select commit Hold shift + click to select a range
5569971
Prepare AgentKit v0.1.0: pure-Bash toolkit + multi-channel distribution
Jul 13, 2026
84ec5b2
Fuse ai-context, ai-git, ai-repo, ai-inspect, ai-session, ai-test int…
Jul 14, 2026
ff37bcd
Add docs/PACKAGES.md: packages, why, and real examples per command
Jul 14, 2026
d25109b
Add Phase 1 coverage tests: safety-critical ai-edit/ai-rollback/snaps…
Jul 14, 2026
26b537b
Add native Bash line-coverage tool and coverage improvement plan
Jul 14, 2026
2533176
Add Phase 2 coverage tests: ai-verify reporting/tool-policy/language-…
Jul 14, 2026
5e64f96
Add Phase 3a coverage tests: repomix internal engines (build-pack, an…
Jul 14, 2026
06bea46
Add Phase 3b coverage tests: ai-diff-context commands/helpers, ai-con…
Jul 14, 2026
7630a59
Add Phase 2 coverage tests: ai-verify duplication/plan-status/step-ru…
Jul 14, 2026
e486ce7
Document a known coverage-tracer limitation with scoped RETURN traps
Jul 14, 2026
c3d02b5
Update README coverage numbers to the confirmed 62.38% baseline
Jul 14, 2026
3f1762e
Add Phase 4b coverage tests: ai-git pr-context and origin
Jul 14, 2026
23b263b
Add refactor-scan: scc complexity + lizard NLOC/params/CCN refactor s…
Jul 14, 2026
c345d1a
Add Phase 4d coverage tests: lib/logging.sh edge branches
Jul 14, 2026
f764ba8
Add Phase 4c coverage tests: ai-test run-all and select
Jul 14, 2026
da4bee3
Add Phase 4d coverage tests: preview-file remaining flags
Jul 14, 2026
408250c
Add Phase 4a coverage tests: ai-search backends (results-rg, backend-…
Jul 14, 2026
5583f09
Add Phase 5a coverage tests: ai-edit/helpers and parse remainder
Jul 14, 2026
dc54082
Add Phase 5a coverage tests: ai-rollback and snapshot remainder
Jul 14, 2026
b60ece3
Add Phase 5b coverage tests: ai-verify run.sh and duplication remainder
Jul 14, 2026
ed5b842
Add Phase 5b coverage tests: lib/logging.sh remainder
Jul 14, 2026
e06a3f7
Add Phase 5c coverage tests: repomix-scc-router analysis-pack remainder
Jul 14, 2026
6448e72
Add Phase 5c coverage tests: ai-search backend/result-formatting rema…
Jul 14, 2026
e81f8eb
Add Phase 6a coverage tests: watch-loop
Jul 14, 2026
77286af
Add Phase 6a coverage tests: sh-introspect
Jul 14, 2026
096ad4b
Add Phase 6a coverage tests: ai-task
Jul 14, 2026
8322d5a
Add Phase 6a coverage tests: ai-structured
Jul 14, 2026
ab1e023
Add Phase 6a coverage tests: repo-stats
Jul 14, 2026
bf68e63
Add Phase 6a coverage tests: session-checkpoint
Jul 14, 2026
213f44f
Add Phase 6a coverage tests: ai-repo, ai-inspect, ai-session, bin/age…
Jul 14, 2026
f019611
Add Phase 6b coverage tests: logging.sh flock-acquire-failure branch
Jul 14, 2026
d330350
Add Phase 6b coverage tests: repomix-scc-router analysis-pack remainder
Jul 14, 2026
36c6a64
Add Phase 7 coverage tests: ai-search-multi and dispatch.sh remainder
Jul 14, 2026
0b1cd62
Add coverage tests for preview-file.sh's own --help, equals-form flags,
Jul 14, 2026
ebd11cc
Add coverage tests for rg-code.sh: --help, equals-form flags, and the
Jul 15, 2026
1df11c5
Fix fd-files.sh rg-fallback exclude globs; add coverage tests for the
Jul 15, 2026
ed113bb
Add coverage tests for plan-apply.sh: sd_apply via a stand-in sd binary,
Jul 15, 2026
3ac2bbf
Add coverage test for run-repomix-context.sh's tree-generation-failed
Jul 15, 2026
03afba4
Add coverage tests for docs-check.sh: explicit paths, --check/--help,
Jul 15, 2026
317f6e6
Fix flaky live-repo-state assertions in the new ai-search-multi batch
Jul 15, 2026
6bc379c
Update README coverage numbers to the final 69.62% result
Jul 15, 2026
0cad1fb
feat(install): add project-local --project mode with configurable fol…
Jul 15, 2026
262949c
Add coverage tests for ai-search-introspect/all-f-into-one, release r…
Jul 15, 2026
fc2a202
Fix secret-scan false positive in test-ai-context.sh and test-run-rep…
Jul 15, 2026
0a63e92
Enforce package.json/VERSION consistency in package-release.sh; updat…
Jul 15, 2026
f2bd29c
Mark RELEASE_CHECKLIST.md items with evidence from this session's ver…
Jul 15, 2026
672db2c
Clarify README coverage badge; complete safe GitHub release-prep sett…
Jul 15, 2026
d453c52
Apply the user-approved GitHub security settings and mark them done
Jul 15, 2026
334ef9e
Implement gh-actions-thin-plan sections A, B, F, and the A-half of G
Jul 15, 2026
aaea50c
Implement gh-actions-thin-plan sections C, D, and E
Jul 15, 2026
03a4cea
Add reproducible-build and security-policy badges to README
Jul 15, 2026
adfa956
Add step-security/harden-runner in audit mode (third and final policy…
Jul 15, 2026
3a922e6
Prepare v0.1.0 release
Jul 15, 2026
d32f559
Fix two real zizmor findings surfaced by the first real CI run
Jul 15, 2026
17ca124
Fix jq "label" keyword incompatibility and cmd_touched's hard fd depe…
Jul 15, 2026
1987e37
Make ai-git origin tests hermetic and skip --pack without a packer
Jul 15, 2026
8f451b8
Fix jq label-keyword and PATH-isolation bugs surfaced by re-run
Jul 15, 2026
762e395
Gate run-repomix-context die-branch tests on scc/repomix availability
Jul 15, 2026
72aa5f2
Cut test-suite wall time: fix the real bottlenecks, not guesses
Jul 15, 2026
31cdcab
Parallelize shellcheck: 93s -> ~41s, same coverage
Jul 15, 2026
518330b
Document the CI-slowness investigation and add a profiling instruction
Jul 15, 2026
78f6536
Fix uninstall leaving an empty .agent-kit/ behind after project-local…
Jul 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions .editorconfig
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
root = true

[*]
charset = utf-8
end_of_line = lf
insert_final_newline = true
trim_trailing_whitespace = true
indent_style = space
indent_size = 4

[*.md]
trim_trailing_whitespace = false

[*.{yml,yaml,json}]
indent_size = 2
12 changes: 12 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
* text=auto eol=lf
*.sh text eol=lf
bin/* text eol=lf
libexec/* text eol=lf
hooks/* text eol=lf
*.md text eol=lf
*.json text eol=lf
*.jsonl text eol=lf
*.png binary
*.jpg binary
*.zip binary
*.gz binary
8 changes: 8 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
* @UtmostCreator
/.github/ @UtmostCreator
/install.sh @UtmostCreator
/uninstall.sh @UtmostCreator
/lib/exec-guard/ @UtmostCreator
/lib/policy.sh @UtmostCreator
/lib/secrets.sh @UtmostCreator
/lib/log-redaction.sh @UtmostCreator
50 changes: 50 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
name: Bug report
description: Report reproducible incorrect behavior
title: "bug: "
labels: [bug, triage]
body:
- type: markdown
attributes:
value: Do not include secrets or private repository/session data.
- type: input
id: version
attributes:
label: Version or commit
placeholder: v0.1.0 or commit SHA
validations:
required: true
- type: input
id: environment
attributes:
label: Environment
placeholder: Ubuntu 24.04, Bash 5.2
validations:
required: true
- type: textarea
id: command
attributes:
label: Command and sanitized output
render: shell
validations:
required: true
- type: textarea
id: expected
attributes:
label: Expected behavior
validations:
required: true
- type: textarea
id: actual
attributes:
label: Actual behavior and minimal reproduction
validations:
required: true
- type: checkboxes
id: checks
attributes:
label: Checks
options:
- label: I removed secrets and private data.
required: true
- label: I searched existing issues.
required: true
8 changes: 8 additions & 0 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
blank_issues_enabled: false
contact_links:
- name: Usage questions and design discussion
url: https://github.com/UtmostCreator/agent-kit/discussions
about: Ask questions or discuss broad proposals.
- name: Security vulnerability
url: https://github.com/UtmostCreator/agent-kit/security/advisories/new
about: Report vulnerabilities privately.
30 changes: 30 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: Feature request
description: Propose a bounded improvement
title: "feat: "
labels: [enhancement, triage]
body:
- type: textarea
id: problem
attributes:
label: Problem
description: What repository-operation problem is not adequately solved?
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed contract
description: Include inputs, outputs, scope, failure behavior, and safety implications.
validations:
required: true
- type: textarea
id: alternatives
attributes:
label: Alternatives considered
- type: checkboxes
id: compatibility
attributes:
label: Compatibility
options:
- label: This can preserve existing command and output contracts.
- label: This requires a documented breaking change.
14 changes: 14 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
# Repository instructions

Follow the canonical instructions in `AGENTS.md`.

This is a Bash-based safety toolkit for coding-agent repository operations. Prefer existing `agent-kit` commands and shared modules over ad hoc shell logic. Preserve scope checks, execution guards, snapshots, rollback, redaction, machine-readable output, and exit-code contracts.

Never commit `.ai-logs/`, session data, context packs, credentials, or local environment files. Do not bypass a safety control to make a test pass. Add tests for behavior changes and run:

```bash
./scripts/check.sh
./scripts/check-publishable.sh
```

Report exact verification evidence and any checks that could not be run.
8 changes: 8 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "monthly"
cooldown:
default-days: 7
5 changes: 5 additions & 0 deletions .github/instructions/shell.instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
---
applyTo: "**/*.sh,bin/**,libexec/**,hooks/**"
---

Use Bash 4.4+ conventions unless the file declares another shell. Quote expansions, use arrays for argument lists, validate untrusted input, use `--` before positional paths where supported, and avoid `eval`. Use secure temporary directories and cleanup traps. Preserve stdout/stderr and exit-code contracts. Put reusable logic in `lib/` and keep command entry points thin. Add or update shell tests for every behavior change.
21 changes: 21 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
## Summary

<!-- What changed and why? -->

## Scope

<!-- Files and behavior intentionally changed; note excluded areas. -->

## Verification

```text
Exact commands and results
```

## Risk

- [ ] Output or schema contract changed
- [ ] Security boundary changed
- [ ] Installation or release behavior changed
- [ ] Backward compatibility changed
- [ ] Generated/session data checked and excluded
125 changes: 125 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,125 @@
name: CI

on:
push:
branches: [main]
pull_request:
workflow_dispatch:

permissions:
contents: read

concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
checks:
name: checks
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-22.04, ubuntu-24.04]
timeout-minutes: 20

steps:
- name: Harden the runner (audit-only; observes egress, never blocks)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout exact event revision without external actions
env:
REPOSITORY: ${{ github.repository }}
EVENT_NAME: ${{ github.event_name }}
COMMIT_SHA: ${{ github.sha }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
set -euo pipefail
git init .
git remote add origin "https://github.com/${REPOSITORY}.git"
if [[ "$EVENT_NAME" == "pull_request" ]]; then
git fetch --no-tags --depth=1 origin "refs/pull/${PR_NUMBER}/merge"
else
git fetch --no-tags --depth=1 origin "${COMMIT_SHA}"
fi
git checkout --detach FETCH_HEAD

- name: Install validation tools
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install --yes --no-install-recommends shellcheck jq ripgrep

- name: Validate publication boundary
run: ./scripts/check-publishable.sh

- name: Run lint and tests
run: ./scripts/check.sh

workflow-security:
name: workflow-security
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- name: Harden the runner (audit-only; observes egress, never blocks)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout exact event revision without external actions
env:
REPOSITORY: ${{ github.repository }}
EVENT_NAME: ${{ github.event_name }}
COMMIT_SHA: ${{ github.sha }}
PR_NUMBER: ${{ github.event.pull_request.number }}
run: |
set -euo pipefail
git init .
git remote add origin "https://github.com/${REPOSITORY}.git"
if [[ "$EVENT_NAME" == "pull_request" ]]; then
git fetch --no-tags --depth=1 origin "refs/pull/${PR_NUMBER}/merge"
else
git fetch --no-tags --depth=1 origin "${COMMIT_SHA}"
fi
git checkout --detach FETCH_HEAD

- name: Install pinned actionlint + zizmor (checksum-verified)
run: |
set -euo pipefail
cd "$(mktemp -d)"
curl -fsSL -o actionlint.tar.gz \
"https://github.com/rhysd/actionlint/releases/download/v1.7.12/actionlint_1.7.12_linux_amd64.tar.gz"
echo "8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8 actionlint.tar.gz" | sha256sum -c -
tar xzf actionlint.tar.gz actionlint
sudo install -m 0755 actionlint /usr/local/bin/actionlint

curl -fsSL -o zizmor.tar.gz \
"https://github.com/zizmorcore/zizmor/releases/download/v1.27.0/zizmor-x86_64-unknown-linux-gnu.tar.gz"
echo "277f2bd8fd37cf60c42ab7afca6faa884e65440fa31e02b44bdaae60f62a358f zizmor.tar.gz" | sha256sum -c -
tar xzf zizmor.tar.gz zizmor
sudo install -m 0755 zizmor /usr/local/bin/zizmor

actionlint -version
zizmor --version

- name: actionlint
run: actionlint -color

- name: zizmor
run: zizmor --strict-collection --persona=regular --min-severity=medium .

required:
name: required
if: ${{ always() }}
needs: [checks, workflow-security]
runs-on: ubuntu-24.04
steps:
- name: Confirm matrix and workflow-security success
env:
CHECKS_RESULT: ${{ needs.checks.result }}
WORKFLOW_SECURITY_RESULT: ${{ needs.workflow-security.result }}
run: |
set -euo pipefail
[[ "$CHECKS_RESULT" == "success" && "$WORKFLOW_SECURITY_RESULT" == "success" ]]
89 changes: 89 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
name: Release

on:
push:
tags:
- "v*.*.*"

permissions:
contents: read

jobs:
release:
runs-on: ubuntu-24.04
timeout-minutes: 20
permissions:
contents: write

steps:
- name: Harden the runner (audit-only; observes egress, never blocks)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Checkout exact tag without external actions
env:
REPOSITORY: ${{ github.repository }}
RELEASE_TAG: ${{ github.ref_name }}
run: |
set -euo pipefail
git init .
git remote add origin "https://github.com/${REPOSITORY}.git"
git fetch --no-tags --depth=1 origin "refs/tags/${RELEASE_TAG}:refs/tags/${RELEASE_TAG}"
git checkout --detach "refs/tags/${RELEASE_TAG}"

- name: Install validation tools
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install --yes --no-install-recommends shellcheck jq ripgrep zip

- name: Validate and test
run: |
set -euo pipefail
./scripts/check-publishable.sh
./scripts/check.sh

- name: Build release archives
env:
RELEASE_TAG: ${{ github.ref_name }}
run: ./scripts/package-release.sh "${RELEASE_TAG}"

- name: Publish GitHub release
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ github.ref_name }}
run: |
set -euo pipefail
gh release create "${RELEASE_TAG}" dist/* \
--verify-tag \
--generate-notes \
--title "AgentKit ${RELEASE_TAG}"

attest:
name: attest
needs: release
runs-on: ubuntu-24.04
permissions:
id-token: write
attestations: write
contents: read
steps:
- name: Harden the runner (audit-only; observes egress, never blocks)
uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0
with:
egress-policy: audit

- name: Download the just-published release asset
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ github.ref_name }}
run: |
set -euo pipefail
mkdir -p dist
gh release download "${RELEASE_TAG}" --repo "${{ github.repository }}" \
--pattern '*.tar.gz' --dir dist

- uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
with:
subject-path: 'dist/agent-kit-*.tar.gz'
Loading