- Added `edit.blockAutoGenerated` setting to control enforcement of auto-generated file detection.
- Improved auto-generated file detection to use language-specific comment parsing instead of broad regex patterns, reducing false positives.
- Enhanced marker detection to scan only leading header comments (1024-byte limit) rather than entire file prefix for better accuracy.
- Fixed tool argument validation to properly handle string 'null' values on optional LLM tool arguments.
- Improved type safety by changing validateToolCall and validateToolArguments return types from any to ToolCall["arguments"].
- Added auto-generated file detection guard to prevent modification of generated code in Edit and Write tools.
- Implemented checkAutoGeneratedFile() to validate file paths against auto-generated markers (protoc, sqlc, buf, swagger).
- Implemented checkAutoGeneratedFileContent() to scan file content prefix for auto-generated patterns before processing.
- Added pre-write validation in Write tool to block overwriting of auto-generated files.
- Added support for quoted paths in grep, ast_grep, find, and ast_edit tools to handle paths with spaces.
- Introduced normalizePathLikeInput() utility function for consistent path and glob parameter normalization across tools.
- Enhanced ast_grep error messaging to warn about parse issues and suggest narrowing path/glob or setting lang parameter.
- Added comprehensive tests for quoted path handling in grep, ast_grep, and find tools with pattern matching.
- Added overload for `prompt()` method accepting string input with optional options parameter.
- Added type guard `supportsMCPToolDiscoveryExecution()` with `MCPDiscoveryExecutionSession` type predicate for safer session type narrowing.
- Added default parameter value to `refreshToolChoiceForActiveTools()` for improved robustness.
* Add MCP tool discovery search and live refresh
* Fix MCP discovery review feedback
* Address remaining MCP discovery review comments
* feat: compact MCP discovery search results
* fix: align MCP discovery search contract
* feat: add MCP server tool counts to discovery hints
* fix(agent): corrected stale toolChoice validation against active tools
- Fixed stale forced toolChoice passed to provider after mid-turn tool refresh by validating against active tools.
- Added refreshToolChoiceForActiveTools() to filter invalid tool choices when available tools change.
- Changed getToolChoice config to use computed function instead of static property for dynamic validation.
- Fixed MCP tool selection tracking in coding-agent to distinguish between discovery-enabled and non-discovery sessions.
- Updated search_tool_bm25 to filter already-selected tools before applying limit parameter.
---------
Co-authored-by: can1357 <me@can.ac>
- Exposed `settings` instance in `CustomToolContext` for session-specific configuration access.
- Improved artifact spill configuration to use session settings with schema defaults as fallback.
- Refactored type annotations and removed Required wrappers for better type safety in settings handling.
- Replaced AgentTool type with Tool type in tool registry for improved type consistency.
- Add compaction.thresholdTokens as fixed token limit alternative to percentage
- Token limit takes priority over percentage when set; options from 25K-500K
- Add more artifact spill threshold options (1KB-1MB) with size descriptions
- Add more artifact tail bytes/lines options with descriptions
- Clean up stale duplicate schema entries from tab reorganization
- Fix statusLine.separator UI metadata
Co-authored-by: Can Bölük <can1357@users.noreply.github.com>
Two /move bugs on Windows:
1. Quoted absolute paths (e.g. /move "C:\...") were treated as relative
because surrounding quotes weren't stripped before path.isAbsolute().
2. /move before any model response threw ENOENT because the session
.jsonl file hadn't been created on disk yet (lazy-persist).
Changes:
- Extract stripOuterDoubleQuotes() helper in path-utils.ts, use in
handleMoveCommand() with empty-after-strip guard
- Guard session file rename with existsSync in moveTo(), leaving
artifact dir rename independently guarded
- Guard #rewriteFile() with hadSessionFile || hasAssistant to preserve
lazy-persist while still updating header cwd for existing files
- Add comprehensive test suite (13 tests) covering all moveTo() edge
cases including header-only sessions, deferred persistence, and
artifact migration
* feat: spill large tool results to artifacts, show tail
- Add centralized spillLargeResultToArtifact() in wrappedExecute pipeline
- Tool results exceeding 50KB saved as session artifacts via saveArtifact()
- Content truncated to tail (20KB / 500 lines) instead of head
- Truncation notice includes artifact:// reference for full output retrieval
- Skip spill when tool already saved its own artifact (bash/python/ssh)
- Update formatFullOutputReference to use action-oriented wording
* feat: per-turn token usage display on assistant messages
* fix: TS errors in output-meta truncation fields
* fix(browser): route localhost through proxy when PUPPETEER_PROXY is set
Chrome bypasses proxies for localhost/loopback by default (since v72).
Add --proxy-bypass-list=<-loopback> so localhost traffic reaches mitmdump,
enabling proxy_traffic.log to capture auth flows for local targets.
Made-with: Cursor
* fix(browser): make proxy loopback bypass opt-in via PUPPETEER_PROXY_BYPASS_LOOPBACK
Made-with: Cursor
- Fixed boolean type coercion in fetch and executor modules by wrapping truncation flags with Boolean() cast.
- Removed maxBytes property from truncation metadata to simplify output metadata structure.
- Normalized optional result properties with explicit fallbacks in output-meta module.
- Updated test expectations to reflect undefined truncation properties instead of false/null values.
- Simplified TruncationResult interface by making maxLines, maxBytes, and other derived fields optional, reducing redundancy.
- Refactored noTruncResult helper to auto-compute totalLines and totalBytes, eliminating repetitive parameter passing.
- Removed truncatedBy null checks and conditional formatting logic in truncation notice functions for cleaner output.
- Consolidated internal URL handling to use noTruncResult and removed unused displayMode variable.
- Clarified documentation in read.md to distinguish filesystem output from text output formatting.
- Threaded Settings parameter through renderUrl and renderHtmlToText functions for dependency injection.
- Changed settings import from default export to type-only import in fetch.ts.
- Added vi.clearAllMocks() calls to test setup hooks for proper mock isolation.
- Added Parallel AI provider integration for web search with fast and research modes.
- Added Parallel extract API for URL content and YouTube video extraction with fallback support.
- Added /login parallel command and PARALLEL_API_KEY environment variable authentication.
- Added providers.parallelFetch configuration setting to control Parallel extract usage.
- Integrated Parallel provider into web search priority order between Exa and Kagi.
- Updated HTML-to-text and YouTube scrapers to prefer Parallel extract over fallback providers.
- Corrected buffer-to-base64 conversion by wrapping raw buffers with Buffer.from() to ensure proper encoding across image processing utilities.
- Updated 6 buffer conversion calls in fetch, image-input, and image-resize modules for consistency.
- Extracted diagnostic message formatting into reusable `formatGroupedDiagnosticMessages()` utility function.
- Consolidated diagnostic output formatting across lsp/index.ts and tools/output-meta.ts to use shared utility.
- Added `DIAG_PATH_RE` regex pattern to parse diagnostic message format with file path, line, and column.
- Added optional `details` field to TodoItem type for storing implementation specifics, file paths, and edge cases.
- Enhanced todo item display to show multi-line details with automatic indentation in interactive and reminder modes.
- Updated eager-todo system prompt to enforce separation of short task content (5-10 words) from detailed implementation information.
- Extended TodoWriteTool to support creating and updating tasks with details field via add_task and update operations.
- Added comprehensive test coverage for details field handling across todo operations (replace, add_task, update).
- Fixed path resolution to accept bare directory names without trailing slashes in comma/space-separated path lists.
- Added existence check for bare path tokens before rejecting them as invalid, allowing directory names like 'packages' to be resolved correctly.
- Added test case verifying grep tool accepts bare space-separated directory names without trailing slashes.
- Corrected error messages in ast-edit, ast-grep, grep, and find tools to reference the correct scope path variable instead of incorrect variable names.
- Added support for comma/space-separated path lists in find, grep, ast_grep, and ast_edit tools, allowing users to search multiple directories with a single query (e.g., 'apps/,packages/,phases/' or 'apps/ packages/ phases/').
- Added resolveMultiSearchPath and resolveMultiFindPattern utility functions to path-utils for intelligent parsing and resolution of multi-path search inputs with automatic common base path detection.
- Updated tool documentation for find, grep, ast_grep, and ast_edit to clarify that path parameters accept files, directories, glob patterns, or comma/space-separated path lists.
- Refactored path resolution logic in find, grep, ast_grep, and ast_edit tools to use unified multi-path handling with intelligent delimiter detection (comma or whitespace).
- Removed Kagi Universal Summarizer integration from fetch tool and YouTube scraper.
- Removed `fetch.useKagiSummarizer` configuration setting from settings schema.
- Simplified renderHtmlToText() and renderUrl() functions by removing Kagi summarization fallback logic.
- Fixed indentation inconsistencies in test files from tabs to spaces.
- Extracted OAuth identifier logic into public functions extractOAuthCredentialIdentifiers and extractOAuthTokenIdentifiers.
- Replaced single credentialIdentity string with multi-identifier resolveCredentialIdentifiers returning string[] for flexible matching.
- Changed credential deduplication from email-based to accountId-based matching in replaceAuthCredentialsForProvider.
- Updated auth-storage tests to verify accountId-prioritized deduplication behavior across soft-disable and hard-delete scenarios.
- Added documentation comments in coding-agent modules explaining partial JSON preservation for streaming tool previews.
- Documented streaming tool preview requirements and render paths in AGENTS.md.
- Added `env` parameter to bash tool for safe environment variable passing without shell re-parsing.
- Added support for rendering partial environment variable assignments in command preview during streaming.
- Updated bash tool prompt to recommend `env` parameter for multiline, quote-heavy, and untrusted values.
- Refactored tool execution component to conditionally merge partial JSON arguments during streaming.
- Added helper functions for environment variable normalization, escaping, and formatting.
- Moved llms.txt endpoint discovery to fallback strategy when rendered page content is low quality, prioritizing page-specific content over site-wide files.
- Enhanced llms.txt endpoint detection to scope candidates to the requested URL path, searching section-specific files before site-wide ones.
- Replaced getOrigin() with buildLlmEndpointCandidates() to generate path-scoped endpoint candidates with depth-based fallback strategy.
- Updated tryLlmEndpoints() to accept full URL and return endpoint metadata alongside content for better fallback tracking.
- Added 2 integration tests validating section-scoped llms.txt discovery and preference for rendered content over site-wide files.
- Renamed parameter names in ast-grep and ast-edit tools from `patterns`/`selector` to `pat`/`sel` for brevity across schema, implementation, and tests.
- Expanded ast-grep and ast-edit tool documentation with 12+ new usage guidelines, examples, and critical notes on pattern syntax, metavariable placement, and error handling.
- Updated CHANGELOG.md to document parameter renames and expanded tool guidance for AST pattern syntax and metavariable usage.
- Reformatted test assertions and type annotations across ast-edit and ast-grep test files for improved readability.
- Added `glob` parameter to `ast_grep`, `ast_edit`, and `grep` tools for filtering files relative to `path`.
- Implemented `combineSearchGlobs()` utility to merge glob patterns from multiple sources instead of throwing errors.
- Changed `grep` tool to combine glob patterns when both `path` and `glob` parameters are provided.
- Updated tool documentation to recommend pairing `path`, `glob`, and `lang` for language-scoped search in mixed repositories.
- Added comprehensive test coverage for combined path and glob parameter handling across grep, ast_grep, and ast_edit tools.
* Add PUPPETEER_PROXY and PUPPETEER_PROXY_IGNORE_CERT_ERRORS env vars
- PUPPETEER_PROXY: routes browser traffic through specified proxy
- PUPPETEER_PROXY_IGNORE_CERT_ERRORS: ignore HTTPS cert errors when set
Made-with: Cursor
* fix(browser): gate PUPPETEER_PROXY_IGNORE_CERT_ERRORS on explicit truthy parse
Previously any non-empty value (including 'false', '0') enabled
--ignore-certificate-errors, silently disabling TLS verification when
operators intended to keep it on. Now only 'true', '1', 'yes', 'on'
(case-insensitive) enable the flag.
Made-with: Cursor
* idiomatic rust fixes
* idiomatic rust fixes
* display an image if we are fetching an image
* MIME type strictness
* codex nagging me
* codex nagging
* handoff instead of compaction as context filled strategy and surfacing
* handoff instead of compaction as context filled strategy and surfacing p2
* handoff instead of compaction as context filled strategy and surfacing p3
* handoff instead of compaction as context filled strategy and surfacing p4
* handoff instead of compaction as context filled strategy and surfacing p5
* handoff instead of compaction as context filled strategy and surfacing, fixes
* failing fetch test from the fetch tool updates
* handoff focus prompt skeleton
* handoff focus prompt skeleton p2
* fetch bugs
* further codex improvements
* further codex improvements
---------
Co-authored-by: Brit <lol@no.com>
- Added `read.defaultLimit` setting to configure default line count for read tool output (default 300 lines).
- Added preset options (200, 300, 500, 1000, 5000 lines) for read default limit in settings UI.
- Updated read tool to distinguish between default and maximum limits per call in prompt documentation.
- Refactored read tool limit logic to use configurable default limit with bounds validation.
- Removed complex fuzzy matching logic including Levenshtein distance calculation and similarity scoring in favor of a simpler glob-based suffix pattern approach. Replaced findReadPathSuggestions with findUniqueSuffixMatch that returns a path only when exactly one candidate matches, eliminating ambiguous suggestions. Removed legacy ttsr_trigger and ttsrTrigger fields from RuleFrontmatter interface.
* idiomatic rust fixes
* idiomatic rust fixes
* display an image if we are fetching an image
* MIME type strictness
* codex nagging me
* resize so we do not blow up the terminal we are in
* codex nagging
* codex nagging
* codex nagging
* codex nagging
* codex nagging
---------
Co-authored-by: Brit <lol@no.com>
- Added language module with 39 supported languages and tree-sitter parser bindings for ast-grep integration.
- Exported dedupeParseErrors utility function to remove duplicate parse error messages in tool output.
- Fixed duplicate parse error messages when multiple patterns fail on the same file.
- Replaced language alias lookup with O(1) phf::Map and added 30+ new language aliases (golang, julia, toml, zig, etc.).
- Migrated from ast-grep-language to direct tree-sitter language dependencies for improved language support.
- Added `fetch.useKagiSummarizer` configuration setting to toggle Kagi Universal Summarizer usage in fetch tool.
- Updated fetch tool to conditionally apply Kagi summarization based on configuration setting.
- Added comprehensive test coverage for Kagi summarizer toggle behavior with mocked dependencies.
- Added Kagi Universal Summarizer integration for URL and YouTube video summarization with fallback support.
- Exported `searchWithKagi` and `summarizeUrlWithKagi` functions from new shared `web/kagi` module for reuse across components.
- Changed HTML-to-text rendering priority to attempt Kagi summarization first before Jina, Trafilatura, and Lynx.
- Refactored Kagi search provider to use shared utilities from `web/kagi` module, reducing code duplication.
- Added `KagiApiError` exception class for Kagi API-specific error handling with optional status code tracking.
- Fixed fetch result rendering to properly wrap long lines instead of truncating them.
- Replaced Bun.wrapAnsi with unified wrapTextWithAnsi utility across debug and output modules.
- Corrected content preview calculation to use actual wrapped line count instead of truncated count.
- Add dereferenceJsonSchema() that inlines local $ref pointers and strips
$defs/definitions from MCP tool schemas before they reach LLM providers.
Previously, Anthropic's convertTools() extracted only properties/required,
dropping $defs and leaving dangling $ref — the LLM never saw the actual
type definitions (e.g. SourceAnchorInput enum values from nucleus).
- Silence Ajv logger (logger: false) on all three instances that use
strict: false. MCP servers may declare non-standard format keywords
(e.g. "uint") that caused console.warn() to corrupt TUI output.
- Cache compiled Ajv validators per schema object identity in validation.ts,
eliminating redundant recompilation on every tool call.
Co-authored-by: Miroslav Drbal <miroslav.drbal@gendigital.com>
- Added mcp:// internal URL protocol for reading MCP server resources via the read tool.
- Removed read_resource tool; MCP resource reading now integrated into read tool with mcp:// URLs.
- Implemented McpProtocolHandler with URI template matching for resolving MCP server resources.
- Updated MCP resource notifications to recommend read(path="mcp://<uri>") syntax.
- Fixed URI template matching to handle empty string expansions in MCP resource queries.
- Fixed LM Studio URL validation to preserve invalid baseUrl instead of applying localhost fallback.
- Fixed MCP notification epoch handling to prevent unsubscribe calls when old subscriptions resolve after re-enabling.
- Extracted hardcoded LM Studio base URL to named constant for improved maintainability.
- Refactored notification epoch check logic for improved code clarity and readability.
- Normalize LM Studio discovery URLs to avoid duplicated /v1 segments
- Harden status-line PR cache with branch+repo context validation and guarded async writes
- Apply Foundry auth precedence correctly and preserve system trust roots when custom CA is provided
- Split Copilot premium multiplier handling by plan tier while preserving agent-initiated zero billing
- Catch MCP notification refresh failures and route read_resource via deterministic full template matching
- Add regression tests for each fix cluster and keep targeted suites green