Resolved file-backed memory://root URLs from the calling session cwd before falling back to the global registry.
Passed the caller cwd through bash internal-URL expansion so redirected memory paths cannot pick another live agent root.
Fixes#5079
Left unresolved internal URLs unchanged during bash command expansion so quoted literal mentions can execute verbatim.
Skipped expansion for URL tokens embedded inside larger quoted shell text while preserving resolvable path-argument expansion.
Fixes#4737
- Added immutable metadata to protocol handlers and had the router copy each handler's setting onto resolved internal resources.
- Updated read and search tools to honor `resource.immutable`, and made search suppress hashline anchors only for immutable source paths while preserving them for mutable files.
- Expanded internal URL tests to cover mutable local resources and mixed immutable/mutable search input hashline behavior.
- Refactor path normalization to combine expandPath and normalizeLocalScheme
- Add validation in utils.ts to reject local:// paths as filesystem paths
- Fix bash-skill-urls regex to handle hyphen-prefixed local:/ patterns
- Add tests for hyphen-prefixed and @local: patterns
- Add negative lookbehind to regex in bash-skill-urls to prevent matching local:/
inside paths like /repo/local:/PLAN.md
- Normalize local scheme before expanding paths in path-utils
- Add test cases for both changes
Expands the regex pattern to match local:/ (single-slash) URLs in addition to local:// (triple-slash), preventing potential Linux path leaks.
- Add regex patterns for single-quoted, double-quoted, and unquoted local:/ URLs
- Add test coverage for all three quote styles
- Replaced plan:// protocol with notes:// for session-scoped artifact storage and plan finalization.
- Added title parameter to exit_plan_mode tool to enable plan file renaming during approval workflow.
- Implemented NotesProtocolHandler for notes:// URL scheme with path traversal protection and session fallback.
- Added renameApprovedPlanFile function to handle plan artifact finalization with validation and error handling.
- Updated system prompt documentation to reference notes:// protocol and internal URL schemes for artifact access.