- Added `edit.blockAutoGenerated` setting to control enforcement of auto-generated file detection.
- Improved auto-generated file detection to use language-specific comment parsing instead of broad regex patterns, reducing false positives.
- Enhanced marker detection to scan only leading header comments (1024-byte limit) rather than entire file prefix for better accuracy.
- Fixed tool argument validation to properly handle string 'null' values on optional LLM tool arguments.
- Improved type safety by changing validateToolCall and validateToolArguments return types from any to ToolCall["arguments"].
- Added support for quoted paths in grep, ast_grep, find, and ast_edit tools to handle paths with spaces.
- Introduced normalizePathLikeInput() utility function for consistent path and glob parameter normalization across tools.
- Enhanced ast_grep error messaging to warn about parse issues and suggest narrowing path/glob or setting lang parameter.
- Added comprehensive tests for quoted path handling in grep, ast_grep, and find tools with pattern matching.
* Add MCP tool discovery search and live refresh
* Fix MCP discovery review feedback
* Address remaining MCP discovery review comments
* feat: compact MCP discovery search results
* fix: align MCP discovery search contract
* feat: add MCP server tool counts to discovery hints
* fix(agent): corrected stale toolChoice validation against active tools
- Fixed stale forced toolChoice passed to provider after mid-turn tool refresh by validating against active tools.
- Added refreshToolChoiceForActiveTools() to filter invalid tool choices when available tools change.
- Changed getToolChoice config to use computed function instead of static property for dynamic validation.
- Fixed MCP tool selection tracking in coding-agent to distinguish between discovery-enabled and non-discovery sessions.
- Updated search_tool_bm25 to filter already-selected tools before applying limit parameter.
---------
Co-authored-by: can1357 <me@can.ac>
- Fixed boolean type coercion in fetch and executor modules by wrapping truncation flags with Boolean() cast.
- Removed maxBytes property from truncation metadata to simplify output metadata structure.
- Normalized optional result properties with explicit fallbacks in output-meta module.
- Updated test expectations to reflect undefined truncation properties instead of false/null values.
- Added pluggable code search provider system supporting Exa and grep.app with provider selection via `providers.codeSearch` setting.
- Removed Exa-specific tools (`exa_linkedin`, `exa_company`, `exa_search_deep`, `exa_crawl`) and simplified web search tools to focus on core functionality.
- Refactored code search from Exa-only to provider-agnostic architecture with new `code_search` tool supporting context-aware grep.app queries and Exa fallback.
- Removed `exa.enableLinkedin` and `exa.enableCompany` configuration settings in favor of provider-based architecture.
- Added comprehensive test coverage for code search functionality including grep.app result normalization and provider fallback behavior.
- Added Parallel AI provider integration for web search with fast and research modes.
- Added Parallel extract API for URL content and YouTube video extraction with fallback support.
- Added /login parallel command and PARALLEL_API_KEY environment variable authentication.
- Added providers.parallelFetch configuration setting to control Parallel extract usage.
- Integrated Parallel provider into web search priority order between Exa and Kagi.
- Updated HTML-to-text and YouTube scrapers to prefer Parallel extract over fallback providers.
- Added optional `details` field to TodoItem type for storing implementation specifics, file paths, and edge cases.
- Enhanced todo item display to show multi-line details with automatic indentation in interactive and reminder modes.
- Updated eager-todo system prompt to enforce separation of short task content (5-10 words) from detailed implementation information.
- Extended TodoWriteTool to support creating and updating tasks with details field via add_task and update operations.
- Added comprehensive test coverage for details field handling across todo operations (replace, add_task, update).
- Fixed path resolution to accept bare directory names without trailing slashes in comma/space-separated path lists.
- Added existence check for bare path tokens before rejecting them as invalid, allowing directory names like 'packages' to be resolved correctly.
- Added test case verifying grep tool accepts bare space-separated directory names without trailing slashes.
- Added support for comma/space-separated path lists in find, grep, ast_grep, and ast_edit tools, allowing users to search multiple directories with a single query (e.g., 'apps/,packages/,phases/' or 'apps/ packages/ phases/').
- Added resolveMultiSearchPath and resolveMultiFindPattern utility functions to path-utils for intelligent parsing and resolution of multi-path search inputs with automatic common base path detection.
- Updated tool documentation for find, grep, ast_grep, and ast_edit to clarify that path parameters accept files, directories, glob patterns, or comma/space-separated path lists.
- Refactored path resolution logic in find, grep, ast_grep, and ast_edit tools to use unified multi-path handling with intelligent delimiter detection (comma or whitespace).
- Added Tavily web search provider with API key authentication and credential discovery from environment or database.
- Integrated Tavily as highest-priority search provider in fallback chain with structured response mapping and error handling.
- Added Tavily OAuth login flow in CLI and auth-storage with manual API key input and validation.
- Added comprehensive test suite for Tavily provider covering registration, response mapping, error handling, and credential validation.
Fixes#313
- Removed Kagi Universal Summarizer integration from fetch tool and YouTube scraper.
- Removed `fetch.useKagiSummarizer` configuration setting from settings schema.
- Simplified renderHtmlToText() and renderUrl() functions by removing Kagi summarization fallback logic.
- Fixed indentation inconsistencies in test files from tabs to spaces.
- Replaced vi.spyOn fetch mocking pattern with hookFetch utility across 5 test files.
- Migrated fetch mocks to use resource management with 'using' keyword for automatic cleanup.
- Removed @ts-expect-error comments related to fetch.preconnect type issues.
- Updated ts-hook-fetch rule documentation with expanded patterns and clearer lifecycle guidance.
- Extracted fetch mocking logic into reusable `hookFetch()` utility function with middleware-style handler pattern.
- Replaced manual `globalThis.fetch` assignment and restoration across 10 test files with `hookFetch()` calls using `using` statement for automatic cleanup.
- Implemented Disposable pattern with Symbol.dispose for fetch hook resource management, eliminating try-finally blocks.
- Exported `hookFetch` from utils public API to enable consistent fetch mocking across packages.
- Added `env` parameter to bash tool for safe environment variable passing without shell re-parsing.
- Added support for rendering partial environment variable assignments in command preview during streaming.
- Updated bash tool prompt to recommend `env` parameter for multiline, quote-heavy, and untrusted values.
- Refactored tool execution component to conditionally merge partial JSON arguments during streaming.
- Added helper functions for environment variable normalization, escaping, and formatting.
- Moved llms.txt endpoint discovery to fallback strategy when rendered page content is low quality, prioritizing page-specific content over site-wide files.
- Enhanced llms.txt endpoint detection to scope candidates to the requested URL path, searching section-specific files before site-wide ones.
- Replaced getOrigin() with buildLlmEndpointCandidates() to generate path-scoped endpoint candidates with depth-based fallback strategy.
- Updated tryLlmEndpoints() to accept full URL and return endpoint metadata alongside content for better fallback tracking.
- Added 2 integration tests validating section-scoped llms.txt discovery and preference for rendered content over site-wide files.
- Renamed parameter names in ast-grep and ast-edit tools from `patterns`/`selector` to `pat`/`sel` for brevity across schema, implementation, and tests.
- Expanded ast-grep and ast-edit tool documentation with 12+ new usage guidelines, examples, and critical notes on pattern syntax, metavariable placement, and error handling.
- Updated CHANGELOG.md to document parameter renames and expanded tool guidance for AST pattern syntax and metavariable usage.
- Reformatted test assertions and type annotations across ast-edit and ast-grep test files for improved readability.
- Added `glob` parameter to `ast_grep`, `ast_edit`, and `grep` tools for filtering files relative to `path`.
- Implemented `combineSearchGlobs()` utility to merge glob patterns from multiple sources instead of throwing errors.
- Changed `grep` tool to combine glob patterns when both `path` and `glob` parameters are provided.
- Updated tool documentation to recommend pairing `path`, `glob`, and `lang` for language-scoped search in mixed repositories.
- Added comprehensive test coverage for combined path and glob parameter handling across grep, ast_grep, and ast_edit tools.
- Removed three @ts-expect-error comments that are no longer needed for fetch.preconnect mocking.
- The test mocks now work without requiring type suppression.
- Added automatic Ollama model capability detection via /api/show endpoint to discover reasoning and input modality support.
- Improved Kagi API error handling with structured error parsing for JSON and plain text response formats.
- Fixed Cerebras streaming compatibility by omitting stream_options.include_usage parameter.
- Simplified API key credential storage to always replace credentials instead of merging for non-minimax providers.
- Updated Kagi Search API key format from 'kagi_...' to 'KG_...' and clarified beta access requirement in provider description.
Fixes#326.
Fixes#321.
Fixes#298.
* idiomatic rust fixes
* idiomatic rust fixes
* display an image if we are fetching an image
* MIME type strictness
* codex nagging me
* codex nagging
* handoff instead of compaction as context filled strategy and surfacing
* handoff instead of compaction as context filled strategy and surfacing p2
* handoff instead of compaction as context filled strategy and surfacing p3
* handoff instead of compaction as context filled strategy and surfacing p4
* handoff instead of compaction as context filled strategy and surfacing p5
* handoff instead of compaction as context filled strategy and surfacing, fixes
* failing fetch test from the fetch tool updates
* handoff focus prompt skeleton
* handoff focus prompt skeleton p2
* fetch bugs
* further codex improvements
* further codex improvements
---------
Co-authored-by: Brit <lol@no.com>
* idiomatic rust fixes
* idiomatic rust fixes
* display an image if we are fetching an image
* MIME type strictness
* codex nagging me
* resize so we do not blow up the terminal we are in
* codex nagging
* codex nagging
* codex nagging
* codex nagging
* codex nagging
---------
Co-authored-by: Brit <lol@no.com>
- Added language module with 39 supported languages and tree-sitter parser bindings for ast-grep integration.
- Exported dedupeParseErrors utility function to remove duplicate parse error messages in tool output.
- Fixed duplicate parse error messages when multiple patterns fail on the same file.
- Replaced language alias lookup with O(1) phf::Map and added 30+ new language aliases (golang, julia, toml, zig, etc.).
- Migrated from ast-grep-language to direct tree-sitter language dependencies for improved language support.
- Added `fetch.useKagiSummarizer` configuration setting to toggle Kagi Universal Summarizer usage in fetch tool.
- Updated fetch tool to conditionally apply Kagi summarization based on configuration setting.
- Added comprehensive test coverage for Kagi summarizer toggle behavior with mocked dependencies.
- Replaced timeout-based cancellation with AbortSignal-based cancellation in ask tool for unified abort handling.
- Added signal parameter to UIContext select() and input() methods to support external cancellation propagation.
- Fixed race condition in dialog overlay handling by replacing direct resolve() calls with settled flag wrapper.
- Added comprehensive test coverage for ask tool cancellation behavior across user-initiated and timeout scenarios.
- Added render_mermaid tool to convert Mermaid diagrams to ASCII output with configurable rendering options.
- Added renderMermaid.enabled setting to control availability of the render_mermaid tool.
- Changed Mermaid rendering from PNG terminal graphics to ASCII text format across theme and TUI components.
- Migrated mermaid utilities from pi-tui to pi-utils package with new ASCII rendering functions.
- Removed PNG-based mermaid rendering APIs (getMermaidImage, renderMermaidToPng) in favor of ASCII alternatives.
PendingAction.apply() and reject() now receive the reason string that was
passed to resolve(). This lets custom tools surface the agent's rationale
in their apply/discard output or use it for logging.
- PendingAction interface: apply(reason) and reject?(reason)
- CustomToolPendingAction: same signatures, reject is optional
- CustomToolLoader: threads reject through when building PendingAction
- AstEditTool: accepts _reason (unused, reserved for future tracing)
- resolve.test: covers reason forwarding on apply and reject paths,
and verifies reject return value replaces the default discard message
- docs/resolve-tool-runtime.md: updated interface table, built-in
producer description, usage example, and developer guidance
- Introduce `deferrable?: boolean` on AgentTool, CustomTool, and ToolDefinition.
AstEditTool sets it to true; resolve is now injected only when at least one
active tool is deferrable (previously unconditional).
- Replace single-slot PendingActionStore (set/get/clear) with a LIFO stack
(push/peek/pop/clear). Multiple deferrable tools can stage independent
preview actions; resolve always consumes the topmost one first.
- Wire pendingActionStore through discoverAndLoadCustomTools / loadCustomTools /
CustomToolLoader so custom tools can call pushPendingAction(action) to
register a resolve-compatible pending action with label, apply callback,
optional details, and optional sourceToolName.
- Export HIDDEN_TOOLS and ResolveTool from the SDK for manual tool composition.
- Add CustomToolPendingAction type and pushPendingAction to CustomToolAPI.
- Update createAgentSession to re-inject or remove resolve after the deferrable
audit, consistent with createTools behavior.
- Add LIFO resolve test, update existing tests (set -> push, get -> peek).
- Add docs/resolve-tool-runtime.md covering PendingActionStore internals,
built-in producer example, and custom tool usage guide.
- Simplified resolve tool output rendering from boxed layout to inline highlighted format for cleaner display.
- Updated resolve tool to parse source tool name from label using colon separator instead of separate metadata field.
- Replaced CachedOutputBlock with direct line rendering using padToWidth and inverse styling.
- Removed actionBadge helper function and consolidated action/state logic into single rendering path.
- Updated 1 test to verify inline rendering behavior and label parsing.
providers/google-gemini-cli:
- parseGeminiCliCredentials() handles legacy, alias (project_id/refresh/expires),
and enriched credential JSON formats
- shouldRefreshGeminiCliCredentials() + refreshGeminiCliCredentialsIfNeeded()
proactively refresh OAuth tokens 60s before expiry for both providers
- normalizeAntigravityTools() converts parametersJsonSchema -> parameters
in function declarations for Antigravity compatibility
- VALIDATED tool calling config applied for Antigravity + Claude model combos
- maxOutputTokens removed from generation config for Antigravity non-Claude models
- Antigravity system instruction injection scoped to Claude + gemini-3-pro-high models
- Antigravity session ID: signed decimal int63 derived from SHA-256 of first user
message (or random bounded int63), replacing truncated hex hash
- Antigravity requestId uses agent-{uuid}; non-Antigravity requests omit
requestId/userAgent/requestType from payload
- ANTIGRAVITY_DAILY_ENDPOINT corrected to daily-cloudcode-pa.googleapis.com;
sandbox kept as fallback
- ANTIGRAVITY_SYSTEM_INSTRUCTION exported
oauth/google-antigravity:
- PKCE removed from OAuth flow (no code_challenge)
- loadCodeAssist metadata ideType changed to ANTIGRAVITY
- discoverProject uses single production endpoint; falls back to onboardUser LRO
(up to 5 retries, 2s interval) instead of hardcoded default project ID
- ANTIGRAVITY_LOAD_CODE_ASSIST_METADATA exported
oauth/google-gemini-cli:
- PKCE removed from OAuth flow
oauth/index:
- getOAuthApiKey includes refreshToken, expiresAt, email, accountId in
Gemini/Antigravity JSON payload for proactive refresh support
discovery/antigravity:
- Tries production daily endpoint first, sandbox as fallback
- Removed recommended/agentModelSorts filter; applies denylist instead
- ANTIGRAVITY_DISCOVERY_DENYLIST filters low-quality/internal models
- Request body no longer includes project field
coding-agent:
- gemini_image: corrected responseModalities to uppercase IMAGE/TEXT
- Gemini web search: endpoint fallback (daily->sandbox) with retry on 429/5xx,
aligned Antigravity request metadata, ANTIGRAVITY_SYSTEM_INSTRUCTION injection
- buildGeminiRequestTools() helper for composable googleSearch/codeExecution/urlContext
- Web search schema: expose max_tokens, temperature, num_search_results params
- Web search: explicit provider falls back to auto chain when unavailable
Tests: google-antigravity-auth, google-gemini-cli-alignment, web-search-gemini
providers/anthropic:
- Bump claudeCodeVersion to 2.1.63; system instruction identifies as Claude Agent SDK
- X-Stainless-Os and X-Stainless-Arch now runtime-computed via mapStainlessOs/mapStainlessArch
- Remove X-Stainless-Helper-Method; update package version to 0.74.0, runtime to v24.3.0
- Remove fine-grained-tool-streaming-2025-05-14 from default beta set; add
context-management-2025-06-27 and prompt-caching-scope-2026-01-05
- Accept-Encoding updated to 'gzip, deflate, br, zstd'
- Inject x-anthropic-billing-header block (SHA-256 payload fingerprint) and
Claude Agent SDK identity block with ephemeral 1h cache-control for OAuth requests
- Auto-generate cloaking user IDs for OAuth metadata.user_id when absent/invalid
- applyClaudeToolPrefix / stripClaudeToolPrefix skip Anthropic built-in tool names
- buildClaudeCodeTlsFetchOptions attaches SNI + default TLS ciphers for api.anthropic.com
- Non-Anthropic base URLs now use Bearer auth regardless of OAuth status
- Prompt-caching no longer strips then re-applies; skips if blocks already have cache_control
oauth/anthropic:
- Token URL changed from platform.claude.com to api.anthropic.com
- OAuth scopes trimmed to org:create_api_key user:profile user:inference
- Code exchange strips URL fragment from callback code (fragment used as state override)
- AnthropicOAuthFlow exported
- OAuth callback server timeout extended from 2 min to 5 min
usage/claude:
- user-agent updated to claude-cli/2.1.63 (external, cli)
- anthropic-beta header extended with full production beta set
coding-agent web search:
- Anthropic provider uses buildAnthropicSearchHeaders instead of buildAnthropicHeaders
Tests: anthropic-alignment, anthropic-oauth, claude-usage-headers, web-search-anthropic
BREAKING CHANGE: ast_find parameter 'pattern' (string) is replaced by
'patterns' (string[]). ast_replace parameters 'pattern' + 'rewrite' are
replaced by 'ops: Array<{ pat: string; out: string }>'.
Native (pi-natives / crates/pi-natives):
- astFind accepts patterns[] array; all patterns run per file, results
merged and sorted by path/line/column before offset+limit are applied
- astReplace accepts rewrites Record<string,string>; all patterns compiled
once upfront and applied per file in a single pass
- Deterministic result ordering via BTreeSet/BTreeMap
Coding-agent tools:
- ast_find: multi-pattern deduplication, '>>' prefix on match-start lines,
padded line numbers, directory-tree grouping (# dir / ## └─ file headers),
scopePath/files/fileMatches in tool details
- ast_replace: ops[] interface with duplicate-pattern rejection, diff-style
(-before/+after) previews grouped by directory, parse errors shown on
zero-replacement path, fileReplacements in tool details
- Tool prompts updated to document new interfaces with multi-pattern examples
- Task item id maxLength raised from 32 to 48 characters
- Added ast_replace tool test suite
## New: schema compatibility validation API
Add `validateSchemaCompatibility(schema, provider)` in
`packages/ai/src/utils/schema/compatibility.ts` that performs a static
audit of a JSON Schema against three provider targets:
- `openai-strict`: checks forbidden keys, required/properties symmetry,
additionalProperties constraint, and that every node declares a type,
combinator, or $ref
- `google`: checks unsupported keyword set and array-valued type
- `cloud-code-assist-claude`: checks forbidden keywords, array type,
null type, nullable keyword, and combiner presence; also validates via
AJV 2020 draft
Add `validateStrictSchemaEnforcement(original, result)` to assert the
fail-open contract: when strict enforcement succeeds the output must pass
openai-strict validation; when it fails the output must be the original
schema object (same reference).
Export both functions and their types from `./utils/schema/index.ts`.
## New: shared constants in fields.ts
Extract `COMBINATOR_KEYS` (`anyOf`, `allOf`, `oneOf`) and add
`CCA_UNSUPPORTED_SCHEMA_FIELDS` as exported constants, eliminating the
local duplicate in `strict-mode.ts` and providing a canonical field set
for Cloud Code Assist (much narrower than the Google set — CCA supports
validation keywords like `additionalProperties`, `minLength`,
`pattern`, etc.).
## Fix: cycle detection in all recursive schema traversals
All recursive walkers now carry a `WeakSet<object>` guard. Previously any
schema with a reference cycle (or a schema object that appears at two
nodes in the tree) would cause an infinite loop or a stack overflow:
- `sanitizeSchemaForStrictMode` / `enforceStrictSchema`
- `normalizeSchemaForCloudCodeAssistClaude`
- `normalizeNullablePropertiesForCloudCodeAssist`
- `stripResidualCombiners`
- `sanitizeSchemaImpl` (Google sanitizer)
- `hasResidualCloudCodeAssistIncompatibilities`
`hasResidualCloudCodeAssistIncompatibilities` previously returned `true`
for already-visited nodes, producing false positives that forced the CCA
fallback schema on valid (but multiply-referenced) schemas. It now
correctly returns `false`.
## Fix: stripResidualCombiners iterates to fixpoint
The previous single-pass approach missed chained combiner reductions
where one collapsed variant exposed another reducible combiner. The
rewriter now loops until no further reduction occurs.
## Fix: mergeObjectCombinerVariants required-field computation
The merged object schema now takes the intersection of all variants'
`required` arrays, then unions in own-level required properties that
exist in the merged schema. Previously the `required` field was silently
dropped from the flattened schema, making all properties effectively
optional.
## Fix: sanitizeSchemaForGoogle improvements
- Type inference for const-collapsed enums: type is derived from all
variants (must unanimously agree), falling back to inference from enum
values; mixed null/non-null infers the non-null scalar type and sets
`nullable: true`
- Const→enum deduplication now uses deep structural equality instead of
`Object.is`
- Recursion spreads the full options object so new fields (`unsupportedFields`,
`seen`) are not silently dropped when descending into sub-schemas
- Array-valued `type` is filtered to strings before processing
- Removed incorrect stripping of `additionalProperties: false` (the
field is valid and should be preserved)
- Parameterized `unsupportedFields` in `SanitizeSchemaOptions` enables
code reuse between the Google and CCA sanitizers
## Fix: sanitizeSchemaForStrictMode / enforceStrictSchema
- `nullable: true` is now stripped during sanitization and expanded into
`anyOf: [schema, {type: "null"}]` in the enforcer output, matching
what OpenAI strict mode requires
- Type inference: `type: "array"` is inferred when `items` is present;
a scalar type is inferred from uniform `enum` values
- Const→enum merge uses deep equality to avoid duplicate entries when
both `const` and `enum` exist with the same value
- `additionalProperties` is now dropped unconditionally in sanitization
(previously only object-valued `additionalProperties` was recursed;
non-object values were passed through)
- `enforceStrictSchema` recurses into `$defs` and `definitions` blocks
- `enforceStrictSchema` handles tuple-style `items` arrays
- `enforceStrictSchema` skips double-wrapping: optional properties
already expressed as `anyOf: [..., {type: "null"}]` are not wrapped again
- `tryEnforceStrictSchema` now caches results in a `WeakMap` keyed on
the input schema object to avoid redundant work on repeated calls
## Fix: mergeCompatibleEnumSchemas deep equality
Uses `areJsonValuesEqual` instead of `Object.is` when deduplicating
enum members, so structurally equal objects are not duplicated.
## New: test coverage
- `packages/ai/test/schema-normalization.test.ts`: comprehensive unit
tests for strict mode, Google, and Cloud Code Assist normalization
- `packages/ai/test/schema-compatibility.test.ts`: unit tests for all
three provider targets in the new compatibility validator
- `packages/coding-agent/test/tools/provider-schema-compatibility.test.ts`:
integration test that instantiates every builtin and hidden tool, runs
their parameter schemas through all three provider pipelines, and
asserts zero compatibility violations