- New agent-plugins provider discovers packages with a root plugin.json
targeting the canonical schema (agent-plugins.org) from marketplace
installs, --plugin-dir, and configured extension roots; skills/ and
mcp.json load per spec with closed-schema validation,
${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
read via the new contained-path helpers, including skill:// resource
access from the read tool and bash; plugin skill files must
realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
surfaces of standard-targeting roots to the new provider and skip
fatally invalid packages.
The Agent Skills standard (agentskills.io/specification) uses
`disable-model-invocation: true` to hide skills from auto-discovery.
OMP only recognized `hide: true`. This patch treats both as equivalent,
improving compatibility with skills authored for Pi, Claude Code, and
other harnesses following the standard.
Changes:
- Check `disableModelInvocation` (camelCase after frontmatter parsing)
in all 3 skill-loading paths
- Add `disableModelInvocation` to SkillFrontmatter type with JSDoc
- Add regression test for disable-model-invocation frontmatter
- Add changelog entry
Ref: https://agentskills.io/specification#frontmatter-required
- Added optional `hide` metadata to skill capabilities so `SKILL.md` frontmatter intent is preserved when skills are loaded.
- Filtered system prompt skill rendering to exclude `hide: true` skills from the `<skills>` listing while keeping them loadable.
- Added `toExtensionId()` method to all capability types for granular extension identification and disabling.
- Added `disabledExtensions` and `includeDisabled` options to LoadOptions for filtering disabled capabilities by extension ID.
- Added plugin manifest support for `extensions` entry points with automatic discovery from installed plugins.
- Fixed skill loading to properly respect disabled skill names from custom directories.
- Improved cross-platform path handling by using `path.basename()` instead of string splitting in context file and state manager.
- Refactored capability index loading to validate source metadata and filter disabled extensions before processing.
- Removed Prettier configuration files (.prettierignore and .prettierrc) and migrated formatting to Biome.
- Updated Biome configuration from version 2.3.11 to 2.3.12 and changed arrowParentheses rule from 'always' to 'asNeeded'.
- Pinned @biomejs/biome dependency to exact version 2.3.12 in package.json and bun.lock.
- Applied consistent arrow function formatting across 489 files by removing unnecessary parentheses around single parameters.
- Removed blank lines after comment blocks and reorganized imports for consistency across the codebase.
- Added unified capability-based discovery system for loading configuration from 8 AI coding tools (Cursor, Windsurf, Cline, GitHub Copilot, Gemini, Codex, Claude, VS Code).
- Added Discovery settings tab in interactive mode for enabling/disabling configuration providers.
- Added provider source attribution showing which tool contributed each configuration item.
- Added support for tool-specific rule formats including Cursor MDC, Windsurf global_rules, and Cline .clinerules.
- Changed MCP tool name parsing to use last underscore separator for improved server name handling.
- Refactored core loaders (skills, hooks, custom tools, slash commands) to use capability API instead of manual directory scanning.