Cli Printing Press

repo: ~/Projects/cli-printing-press · 1053 commits · 0 in last 24h, 0 in last 7d ·

Search the build

1053 commits indexed

  1. aecf495a 2026-05-19 fix(cli): harden manifest-gen remote spec loader against hangs and silent truncation (#1699)
  2. 9eff1e20 2026-05-19 fix(cli): resolve shipcheck CLI binary name from .printing-press.json (#1700)
  3. b534884f 2026-05-19 feat(cli): GraphQL credential probe in doctor + actionable copy (#1701)
  4. 5261ae73 2026-05-19 fix(cli): return failure exit from verify json (#1693)
  5. 4093ef3e 2026-05-19 fix(cli): redact shipcheck api key in json (#1673)
  6. d8178077 2026-05-20 fix(cli): handle binary-only response endpoints (Accept + base64 envelope) (#1574)
  7. 1a243810 2026-05-19 feat(cli): add Quo (formerly OpenPhone) catalog entry and OpenAPI spec (#1597)
  8. 015478bf 2026-05-19 feat(cli): detect Auth0 SPA in-memory auth + emit CDP extractor (#1645)
  9. 75e4d1b9 2026-05-19 fix(cli): verify-mode HTTP-verb short-circuit + N1 envelope + doctor + read-only POST bypass (#1398)
  10. c5d86825 2026-05-19 fix(cli): create llm prompt temp files privately (#1674)
  11. 9a474335 2026-05-19 fix(ci): trust queued Greptile gate
  12. 96bc822e 2026-05-19 fix(ci): allow queue drafts to skip Greptile
  13. 019dcf3b 2026-05-19 chore(ci): enable parallel queue checks in Mergify (#1668)
  14. 81f07e53 2026-05-19 feat(skills): check public library for existing CLI before generating (#1650)
  15. cda9b43b 2026-05-19 fix(cli): make live-dogfood runner enum-aware and resilient to empty outcomes (#1656)
  16. 5cb39a69 2026-05-19 fix(skills): stop phase 4.95 code review from being skipped (#1655)
  17. 2c3271fc 2026-05-19 fix(cli): detect path params in browser-sniff URL grouper (#1657)
  18. 17cd2774 2026-05-19 fix(cli): dogfood prefers bundled <dir>/spec.yaml over caller --spec (#1625)
  19. ac3e15b4 2026-05-19 fix(cli): sync pagination, auth aliases, narrative timing, and codex prompt (#1341)
  20. 275646a3 2026-05-19 feat(cli): add auth set-token escape hatch for cookie-auth CLIs (#1641)
  21. f9bb82c8 2026-05-19 fix(skills): reprint discovers and carries prior patches (#1649)
  22. b5b1dd59 2026-05-18 feat(cli): add cliutil.LooksLikeJWT shared validator with length floor (#1602)
  23. ed17d302 2026-05-18 fix(cli): gate ship plans on agent readiness (#1638)
  24. 7eee7dfc 2026-05-18 fix(cli): harden browser-sniff PII placeholders (#1639)
  25. 8c955701 2026-05-18 fix(cli): correct live-check and helper emission (#1637)
  26. af9ba8c7 2026-05-18 docs(skills): document separate-file pattern for extending emitted files (#1624)
  27. 766354e6 2026-05-18 feat(cli): add sync --path-context KEY=VAL runtime override for template placeholders (#1631)
  28. 187b6992 2026-05-18 fix(cli): emit structured cache_warning JSON on auto-refresh failure (#1632)
  29. e798f671 2026-05-18 fix(cli): route Swagger 2.0 specs through openapi2conv to avoid OOM on circular refs (#1630)
  30. 042a78d4 2026-05-18 feat(cli): flag empty defaultSyncResources at dogfood time (#1633)
  31. 14bc18a4 2026-05-18 feat(cli): default mcp.transport=[stdio, http] for small APIs (#1629)
  32. f671b7ba 2026-05-18 feat(ci): mirror supply-chain hardening from printing-press-library (#1619)
  33. 1dfbf795 2026-05-17 chore(main): release 4.9.0 (#1495)
  34. ef81ca04 2026-05-17 test(cli): update TestPublishSkillSkipsCliSkillsMirrorRegen for new library gate name (#1618)
  35. dde2a4e0 2026-05-17 docs(skills): publish skill aligns with library's bot-only generated-artifacts rule (#1614)
  36. fef027fe 2026-05-17 fix(skills): retro skill scrubs secrets and PII before posting issue bodies (#1595)
  37. c3e1b87a 2026-05-17 feat(cli): emit .printing-press-patches.json on every generate (#1590)
  38. caa68801 2026-05-17 fix(cli): drop // PATCH marker instruction from generated AGENTS.md
  39. 875d64e9 2026-05-17 fix(cli): detect partial-failure response shape in :mutate handlers, add --allow-partial-failure flag (#1360)
  40. 80ba507e 2026-05-16 fix(ci): cancel-in-progress=false so cancelled check_runs don't pile up
  41. 833213ff 2026-05-16 fix(cli): drive browser-sniff http_transport from HAR HTTP-version distribution (#1540)
  42. 63f745b8 2026-05-16 fix(skills): split SQL example out of go-fenced block in NULL-safe scans guidance
  43. f7365c26 2026-05-16 fix(ci): close jq if-then-else with end so >10-thread path doesn't crash
  44. 94332417 2026-05-16 fix(ci): use job exit-code instead of POST/PATCH for check_run state
  45. c96ac5da 2026-05-16 fix(cli): writeThroughCache caches single-object responses keyed by non-id PKs (#1531)
  46. 5b8a8141 2026-05-16 fix(ci): scope settle delay to synchronize, strip head_sha from PATCH
  47. 162d9a32 2026-05-16 fix(ci): conversation-resolution check race + duplicate check_run
  48. f55f57a8 2026-05-16 fix(ci): address Greptile review on conversation-resolution check
  49. 21ae8a54 2026-05-16 feat(ci): surface unresolved review threads as a status check
  50. a8fa80a3 2026-05-16 fix(ci): require all review threads resolved before queue + merge
  51. 4e304df5 2026-05-16 fix(cli): scope-aware sync --param dispatch with --global-param fallback (#1529)
  52. 7396d66f 2026-05-16 fix(skills): add NULL-safe SQL scan guidance to Phase 3 store-query starter
  53. c31632b3 2026-05-16 feat(skills): add /printing-press-amend skill — dogfood + direct-input modes (#1490)
  54. c10d0b55 2026-05-16 fix(cli): move extra_commands SKILL.md block to its own top-level section (#1524)
  55. 99637941 2026-05-16 fix(skills): require codex completion marker before treating delegation as success (#1523)
  56. 82ad787b 2026-05-16 fix(cli): cap body-flag recursion depth to prevent compiler OOM (#1522)
  57. 0c3c8bcc 2026-05-16 fix(cli): detect integer page paginator and advance numerically in sync (#1519)
  58. ff562375 2026-05-16 fix(cli): drop MCP code-orch handler pre-marshal that base64-encoded mutating bodies (#1521)
  59. 95417401 2026-05-16 fix(cli): filter auth login --chrome cookies by spec auth.cookies allowlist (#1518)
  60. 34ca8149 2026-05-16 feat(cli): add --auth-preference flag for catalog-driven scheme selection (#865)
  61. 62838d04 2026-05-16 fix(cli): validate-narrative splits piped recipes and strips redirects (#1517)
  62. f5ea270d 2026-05-16 fix(cli): match both singular and plural required-flag cobra outputs (#1413)
  63. 43c90ba0 2026-05-16 feat(catalog): add OpenRouteService under new maps category (#1513)
  64. bf9014d4 2026-05-16 fix(cli): synthesize undeclared path placeholders in OpenAPI parser (#1510)
  65. c7e1b82b 2026-05-16 fix(cli): preserve body/content payload on single-object compact path (#1509)
  66. fe4a5ec3 2026-05-16 feat(cli): catalog auth_env_vars declares canonical credential env vars (#1508)
  67. bf7f3465 2026-05-16 fix(cli): route promoted-command file stem through safeResourceFileStem (#1489) (#1506)
  68. f64e9913 2026-05-16 fix(skills): drop cli-skills mirror regen from publish flow (#1502)
  69. 2abbfec0 2026-05-16 fix(scorer): resolve binary at build/stage/bin/ before cliDir (#1150) (#1412)
  70. 793d5b27 2026-05-16 fix(skills): surface novel-feature hand-code scope at Phase Gate 1.5 (#1501)
  71. ca4898a3 2026-05-16 fix(cli): apply Bearer prefix in composed and cookie AuthHeader paths (#1500)
  72. f3f70435 2026-05-16 fix(cli): refresh auth on redirects via CheckRedirect (#1497)
  73. dc0651ab 2026-05-16 fix(cli): exempt vendor OpenAPI/Swagger source under .manuscripts from PII scan (#1496)
  74. 9d3050b5 2026-05-15 fix(cli): always emit boolean body fields, no zero-guard (#1494)
  75. 96fca081 2026-05-15 feat(cli): expose PRINTING_PRESS_DOGFOOD env signal for long-running commands (#1493)
  76. 6fc98d75 2026-05-15 chore(main): release 4.8.0 (#1491)
  77. f8d3ba80 2026-05-15 fix(cli): short-circuit sync on dry-run sentinel response (#1471)
  78. 5f43de50 2026-05-15 feat(cli): add ElevenLabs generation support (#1307)
  79. 55f5b26b 2026-05-15 fix(cli): expand pm_stale timestamp-field list for non-updated_at APIs (#1461)
  80. 3bb6d37b 2026-05-15 fix(cli): doctor preserves configured User-Agent when API uses UA as auth credential (#1361)
  81. 2d0ad5ae 2026-05-15 fix(ci): switch queue update_method to merge so fork PRs can queue (#1492)
  82. 5460c32a 2026-05-15 fix(cli): probe nested path-param leaves so verify catches `args[]` index bugs (#1434)
  83. d7ccd850 2026-05-15 fix(cli): use Chrome User-Agent for synthetic/cookie/composed/session_handshake CLIs (#1479)
  84. e8eb4e30 2026-05-15 chore(main): release 4.7.0 (#1377)
  85. ede5c350 2026-05-15 fix(cli): honor explicit "mcp:read-only": "false" in tools-audit (#1485)
  86. f354bc7a 2026-05-15 docs(skills): document hierarchical resource_type in store-query skeleton (#1484)
  87. 77b91be6 2026-05-15 docs(cli): canonicalize README install block + cross-repo sweep dependency note (#1464)
  88. a9ffa08f 2026-05-15 fix(cli): research-dir state.json api_name overrides info.title-derived name (#1476)
  89. 272d8e83 2026-05-15 fix(cli): preserve OpenAPI param casing in detected pagination (#1460)
  90. 01c816da 2026-05-15 fix(cli): pick gid/sid/uid before name in PK heuristic (#1465)
  91. 72adfefd 2026-05-15 fix(cli): drop unused client import from param-less endpoint command files (#911)
  92. 35e515c1 2026-05-15 fix(cli): query generic resources_fts from search empty-type branch (#1462)
  93. bb5e2def 2026-05-15 fix(cli): validate &&-chained narrative recipes segment-by-segment (#1447)
  94. a1098f15 2026-05-15 fix(cli): populate printer + run_id in generated .printing-press.json (#1442)
  95. 9d70aee4 2026-05-15 chore(ci): add CODEOWNERS for workflows and CODEOWNERS itself (#1472)
  96. bd4dc641 2026-05-15 fix(cli): kebab-case SKILL.md and README endpoint examples (#1445)
  97. 5a04aca6 2026-05-16 fix(skills): correct install-internal-skills.sh path to repo skills/ (#1342)
  98. 096411ce 2026-05-15 fix(cli): strip root-level binaries from staged publish tree (#1449)
  99. b8b1b6a4 2026-05-15 fix(cli): force sync concurrency=1 under PRINTING_PRESS_VERIFY to avoid SQLITE_BUSY (#1441)
  100. dbfc6118 2026-05-15 fix(cli): propagate PRINTING_PRESS_VERIFY=1 to browser-session-proof probe (#1458)
  101. e36050fb 2026-05-15 fix(cli): substitute server-URL variables from env vars at runtime (#1448)
  102. c57345a1 2026-05-15 fix(cli): align publish-skill contract tests with api-slug staged path (#1459)
  103. ce3aeb4a 2026-05-15 fix(skills): use api-slug in publish Step 6 staged path (#1444)
  104. 2bf7d1e7 2026-05-15 fix(cli): clear every emitted credential field in ClearTokens (#1433)
  105. 73fe5673 2026-05-15 fix(cli): extend verify-skill recipe scan to README.md (#1430)
  106. 44f1ff79 2026-05-15 fix(cli): archive merged spec for multi-spec generate runs (#1432)
  107. acbb3dfe 2026-05-15 fix(cli): bypass response cache when polling async jobs (#1429)
  108. 95f03501 2026-05-14 fix(cli): derive doctor auth.verify_path from me-shaped endpoint (#1431)
  109. 2988814e 2026-05-14 fix(skills): canonicalize auth env var when slug-derived differs (#1428)
  110. 55b0f16b 2026-05-14 feat(skills): contain session-state.json outside DISCOVERY_DIR (#1425)
  111. c5a51ead 2026-05-14 fix(cli): scope HOME/XDG_CONFIG_HOME for verify/dogfood subprocesses (#1416)
  112. 33a6668b 2026-05-14 fix(cli): handle single-quoted args in validate-narrative shell tokenizer (#1424)
  113. d4b173d6 2026-05-14 docs(cli): document sync --resources parent-keyed dependent cascade (#1417)
  114. f32214ea 2026-05-14 feat(cli): surface per-endpoint evidence and confidence from browser-sniff (#1397)
  115. 770b65a6 2026-05-14 docs(cli): clarify issue ownership workflow (#1414)
  116. 46ad86b2 2026-05-14 fix(cli): stop generated main.go from printing every error twice (#1411)
  117. d0226602 2026-05-14 fix(cli): derive doctor probe path from auth.verify_path or me-shaped endpoint (#1406)
  118. 15964974 2026-05-14 fix(cli): tighten phone-us PII regex to NANP-valid first digits (#1405)
  119. fdca9f7a 2026-05-14 fix(cli): make cookie-auth login --chrome work on Windows (#1404)
  120. 89f38c4c 2026-05-14 fix(cli): isolate typed-table upsert failures with per-item SAVEPOINT (#1402)
  121. 2698690e 2026-05-14 fix(skills): emit PRINTING_PRESS_BIN marker so later phases survive PATH non-inheritance (#1399)
  122. ac83f0fd 2026-05-14 fix(generator): support single-env basic auth credentials (#1381)
  123. 3bcb9d90 2026-05-14 fix(cli): descend --select into list-envelope responses (#1379)
  124. 295fd03f 2026-05-14 fix(cli): drop shell line comments + skip happy_path on missing file fixtures (#1378)
  125. fb9125e8 2026-05-14 fix(cli): emit structured JSON error from parents invoked without a subcommand in --agent mode (#1373)
  126. d44587e9 2026-05-14 test(cli): regression tests for body-flag identifier collision shapes (#1376)
  127. 1f1b0bdb 2026-05-14 fix(cli): emit WithNumber/WithBoolean for OpenAPI-parsed numeric MCP params (#1372)
  128. 725e063f 2026-05-13 chore(main): release 4.6.1 (#1363)
  129. 1ff68537 2026-05-13 fix(cli): refuse publish package --dest overlay when mirror diverges from source (#1371)
  130. 2437cab7 2026-05-13 fix(cli): wire composed apiKey + bearer sibling headers through parser, templates, and MCP manifest (#1359)
  131. 51b758c7 2026-05-13 fix(cli): consume x-tenant-env-var so per-tenant sync paths ship populated (#1368)
  132. d697eb5a 2026-05-13 fix(cli): skip framework-auto-generated operationIds when deriving command names (#1367)
  133. ca1de8fa 2026-05-13 test(cli): pin args[] index for flag-exposed path param shape (#1369)
  134. 80f5bc6c 2026-05-13 fix(cli): coerce number-typed --limit param to int (#1370)
  135. a6010384 2026-05-13 fix(cli): detect cross-cutting novel features in dogfood scorer (#1364)
  136. 77fce43f 2026-05-13 fix(cli): percent-encode path param values in replacePathParam (#1366)
  137. 1fc5f62b 2026-05-13 fix(cli): drop MCP handler pre-marshal that base64-encoded mutating bodies (#1357)
  138. 0f8dc989 2026-05-13 fix(cli): strip embedded .git/ and .gitmodules in pipeline.CopyDir (#1358)
  139. a0fac288 2026-05-13 chore(main): release 4.6.0 (#1261)
  140. 3b283e04 2026-05-13 ci: exempt release-please PRs from Greptile review requirement (#1340)
  141. 69cefbe9 2026-05-13 fix(cli): propagate --timeout to surf transport ResponseHeaderTimeout (#1212)
  142. 3819b67f 2026-05-13 fix(cli): support $-prefixed pagination params for Socrata-style APIs (#1204)
  143. 900b335c 2026-05-13 feat(cli): emit fetchFull<X> companion for GET-embedded paged sub-resources (#1301)
  144. e21feae6 2026-05-13 fix(cli): close ResolveByName json_extract injection + dedupe cacheKey AuthHeader call (#1278)
  145. ea0cfd8d 2026-05-13 chore(cli): ignore local AI agent instruction files (#1326)
  146. 5ac1de7c 2026-05-13 fix(ci): collapse Mergify two-step CI to enable in-place mode (#1336)
  147. 1b466a64 2026-05-13 chore(ci): wire Greptile into Mergify, pin OSS-plan in-place mode (#1321)
  148. a117a741 2026-05-13 chore(ci): raise mergify batch_size and add queue safety knobs (#1306)
  149. 42093ad8 2026-05-13 fix(skills): extend retro pre-upload scrub with jurisdiction-specific PII patterns (#1302)
  150. 8cc7e655 2026-05-13 fix(skills): skip publish-validate in mid-pipeline polish (#1300)
  151. 513ae01d 2026-05-13 fix(cli): raise API error body truncation cap from 200 to 4096 bytes (#1285)
  152. ee3638b2 2026-05-13 fix(cli): hide const-default query flags from --help (#1287)
  153. b8488ee4 2026-05-13 fix(cli): route in:query params to URL on PUT/DELETE/POST/PATCH handlers (#1279)
  154. f5348488 2026-05-13 fix(cli): gate provenance diagnostic on wantsHumanTable (#1280)
  155. a8192b52 2026-05-12 chore(ci): enable greptile status checks (#1268)
  156. ff135309 2026-05-12 fix(cli): promote write-endpoint params to body when body is empty (#791)
  157. 90798403 2026-05-12 chore(main): release 4.5.2 (#1230)
  158. 9e0fe96c 2026-05-12 fix(cli): populate parent FK in generated UpsertBatch typed-table test fixture (#1253)
  159. bb9b9cb3 2026-05-12 fix(cli): make .printing-press.json authoritative for parsed.Name in mcp-sync (#1252)
  160. 28e2fa1b 2026-05-12 fix(cli): guard nil Phases in LoadState to prevent lock promote panic (#1193)
  161. 7010c102 2026-05-12 fix(ci): fold skill docs into lint gate (#1226)
  162. 09d72e68 2026-05-12 fix(cli): prioritize bearer + apply root-security filter in scheme selection (#1238)
  163. 5c359ba6 2026-05-12 fix(cli): gate refreshAccessToken emission on Auth.TokenURL non-empty (#1244)
  164. c05d3bc7 2026-05-12 fix(cli): always quote SQL identifiers emitted by safeSQLName (#1228)
  165. a8ad9820 2026-05-12 fix(skills): generate absolute manuscript URLs in publish PR body (#1235)
  166. e40389ef 2026-05-12 fix(cli): default Accept to application/json instead of */* (#1229)
  167. f1246ee1 2026-05-12 fix(cli): skip dogfood --live error_path probe for mutating commands (#1225)
  168. a169ca49 2026-05-12 chore(main): release 4.5.1 (#1170)
  169. dabf63f8 2026-05-12 fix(cli): map Cobra/pflag pre-RunE usage errors to exit code 2 (#1194)
  170. 6cda2606 2026-05-12 fix(cli): emit stderr truncation warning on single-page list responses (#1177)
  171. 4aba68e6 2026-05-12 docs(cli): cross-reference #1199 in mcp-handler positional-params learning (#1216)
  172. 7365fcc3 2026-05-12 fix(cli): resolve validation binary path with platform.ExecutablePath (#1213)
  173. 460d676e 2026-05-12 fix(cli): index args[] by positional ordinal in path-param emit (#1211)
  174. 9df8c5a2 2026-05-12 docs(skills): document x-mcp as the OpenAPI form of the mcp: enrichment block (#1201)
  175. c9a35b5e 2026-05-12 fix(cli): refuse to ship CLIs with placeholder base URL (#1186)
  176. c5a5441d 2026-05-12 fix(cli): dedupe nested body-field flatten collisions with sibling scalars (#1190)
  177. 660829ed 2026-05-12 fix(cli): preserve x-mcp config when merging combo specs (#1187)
  178. d0c4caca 2026-05-12 docs(skills): tighten Phase 3 Completion Gate to per-row Cobra resolution (#1173)
  179. ee13fb16 2026-05-12 fix(cli): make dogfood acceptance marker manifest read best-effort (#1179)
  180. a3c3c653 2026-05-12 fix(cli): redact $HOME paths from publish-tree JSON artifacts (#1181)
  181. 5e3667df 2026-05-12 fix(cli): route scorer subcommand --spec URLs through generate's fetch path (#1178)
  182. e8c03cff 2026-05-12 fix(cli): credit auth_protocol on structural OAuth surface, not "Bearer " literal (#1176)
  183. 84138f91 2026-05-12 fix(cli): handle PascalCase .NET-shape API responses in sync (#1135) (#1174)
  184. 7ba9c20a 2026-05-12 fix(cli): accept backtick raw-string Use: in dogfood walkers (#1169)
  185. f88a10b3 2026-05-12 fix(cli): preserve novel-command keys in --compact partial-strip path (#1167)
  186. 36976106 2026-05-12 fix(cli): scope HTTP cache to <api>/http so invalidateCache spares siblings (#1166)
  187. 12964486 2026-05-12 chore(main): release 4.5.0 (#1134)
  188. 22cc006f 2026-05-12 docs(skills): document post-PR review contract in publish skill (#1163)
  189. 88c5b696 2026-05-11 feat(skills): add native code review phase to printing-press (#1160)
  190. 403341c7 2026-05-11 docs(cli): require /printing-press-publish skill for CLI publish PRs (#1145)
  191. 44e7efe4 2026-05-11 docs(cli): refresh solution docs (#1146)
  192. 8990fc24 2026-05-11 feat(skills): offer browser-sniff backend install at preflight (#1132)
  193. d4c8bfbf 2026-05-11 chore(main): release 4.4.0 (#1073)
  194. 6536cfff 2026-05-11 fix(cli): exempt CLI-root vendor spec files from PII audit scope (#1121)
  195. 5f2bde7f 2026-05-11 fix(cli): suppress max_pages_cap_hit warning under --latest-only (#1120)
  196. 10cc48a8 2026-05-11 fix(cli): infer pagination defaults from plain params; preserve cursor=0 in paginatedGet (#1115)
  197. c626efca 2026-05-11 fix(cli): emit default Accept */* header in generated HTTP clients (#1112)
  198. c6420747 2026-05-11 fix(cli): honor Spec.BasePath in generated client URL construction (#1108)
  199. cb3c0974 2026-05-11 fix(cli): surface API body in sync_error events and add --param passthrough (#1104)
  200. cba06db1 2026-05-11 fix(cli): gate OAuth refresh-token params on x-oauth-refresh-token-mechanism (#1099)
  201. 1ca94b91 2026-05-11 fix(cli): gofmt rendered .go output in generator emit phase (#1100)
  202. ff4b6528 2026-05-11 fix(cli): unwrap single-key API envelopes before agent provenance envelope (#1095)
  203. 17d19307 2026-05-11 fix(cli): stage runstate manuscripts during lock promote (#1094)
  204. 3d515c45 2026-05-11 fix(cli): delegate workflow archive to syncResource (#1090)
  205. 705bad2d 2026-05-11 fix(cli): dispatch typed-table upserts on spec resource key, not snake table name (#1071)
  206. 5c4ef3a7 2026-05-11 fix(catalog): refresh google-flights entry to reflect fli native port (#1084)
  207. 27ad2dda 2026-05-11 fix(cli): skip Windows Python Store stub in verify-skill (#1086)
  208. 46481718 2026-05-11 docs(skills): clarify wrapper-only catalog entries have no generator path (#1056)
  209. 24962b7c 2026-05-11 feat(cli): sync.walker spec parameter for hierarchical APIs (#1060) (#1074)
  210. dc6fe879 2026-05-11 fix(cli): preserve unknown-shape records in compactListFields (#1078)
  211. d7e2d74f 2026-05-11 feat(cli): promote html_scrape reachability mode when captcha-tier protection blocks JSON + SSR sibling carries state blob (#1065)
  212. 424199a7 2026-05-11 fix(ci): drop cancel-in-progress from pr-title workflow (#1068)
  213. 910c228d 2026-05-11 fix(cli): emit --body-json fallback for oneOf/anyOf request bodies (#994)
  214. 242a56bc 2026-05-11 fix(cli): validate ListIDs resourceType to close SQL injection (#1000)
  215. 76db1cc4 2026-05-11 chore(main): release 4.3.0 (#898)
  216. 9a07f287 2026-05-11 fix(cli): walk parent dirs for research.json in live-check (#1057)
  217. d2770e16 2026-05-11 fix(cli): honor auth.prefix on bearer_token specs (#1054)
  218. e2f3a53c 2026-05-11 fix(cli): honor --resources filter in dependent sync fan-out (#1047)
  219. ed693b0d 2026-05-11 fix(cli): hide raw resource groups when api browser is generated (#1045)
  220. c93ce0c2 2026-05-11 fix(cli): reconcile MCPB manifest against internal/client env reads (#859) (#1035)
  221. dc5e8c55 2026-05-11 fix(cli): gate sync since-param emission per resource (#1036)
  222. 66fd401b 2026-05-11 fix(cli): Store.Get propagates sql.ErrNoRows so callers can gate on existence (#1031)
  223. 9e604a95 2026-05-11 test(cli): pin doctor authConfigured short-circuit for OAuth2 + EnvVarSpecs (#1034)
  224. b1dded7d 2026-05-11 fix(cli): classify doctor HTTP 403 as scope-limited WARN, not invalid FAIL (#1033)
  225. 3e56bedf 2026-05-10 fix(generator): preserve multi-spec server prefixes (#861)
  226. 5fabad63 2026-05-10 fix(cli): sync skips resources with unresolved {key} placeholders (#1009)
  227. a03a7b81 2026-05-11 fix(generator): rename trailing '_test' stems to avoid Go test-file exclusion (#1020) (#1021)
  228. 4fac827e 2026-05-11 feat(cli): point users at where to get a token (URL + instructions + auth setup --launch) (#871)
  229. a3e07d0a 2026-05-10 feat(cli): mechanical PII gate before promote/publish (#958) (#1023)
  230. 4b04f4c6 2026-05-10 fix(cli): reject control-plane flag injection in MCP shellout (#1022)
  231. 54f007f5 2026-05-10 fix(skills): gate polish Publish Offer on --standalone, not path detection (#1017)
  232. 3b050899 2026-05-10 fix(cli): emit AccessToken-only AuthHeader for all OAuth2 grants (#1010)
  233. fef70ba1 2026-05-10 fix(cli): bind typed upsert values in column-declaration order (#1018)
  234. 182395ca 2026-05-10 feat(cli): add cliutil.ExtractNumber/ExtractInt for JSON-string-encoded numeric fields (#1002)
  235. 6e086c00 2026-05-10 fix(cli): fold per-spec base URL path prefixes on multi-spec merge (#995)
  236. a9e9d006 2026-05-10 fix(cli): allow runtime override of OAuth2 OIDC URLs (#970)
  237. e952e807 2026-05-10 fix(generator): route receiver JSON helper through filters (#933)
  238. 5f8dae13 2026-05-10 fix(cli): reject reserved placeholder hosts in spec validation (#984)
  239. cb1697ed 2026-05-10 fix(cli): force UTF-8 stdio in verify-skill Python subprocess (#985)
  240. e0240cea 2026-05-10 fix(skills): forward --research-dir to scorecard --live-check in mid-pipeline polish (#980)
  241. 618fa456 2026-05-10 fix(cli): preserve hand-edits to templated files on --force regen (#967)
  242. 0562bca8 2026-05-10 fix(skills): preflight Go toolchain before generation runs (#973)
  243. ab6edbef 2026-05-10 fix(cli): route explicit --csv/--quiet/--plain above piped-pipe gate (#968)
  244. ebc8cd81 2026-05-10 feat(cli): emit nested-object body fields as parent-prefixed flags (#957)
  245. ff755316 2026-05-10 fix(cli): isolate generic resources by type (#901)
  246. 48cc2a31 2026-05-10 fix(cli): emit form-encoded request bodies (#947)
  247. 6cd57cc2 2026-05-10 fix(cli): infer resource-prefixed IDField from item-schema properties (#938)
  248. d7be66f0 2026-05-10 docs(cli): require claim and unclaim on issue ownership (#939)
  249. a1d39bf3 2026-05-10 fix(cli): seed template-var placeholders in verify mode (#934)
  250. dceb6e58 2026-05-10 fix(cli): preserve internal sibling packages on force regen (#897)
  251. d94d89dc 2026-05-10 fix(cli): handle empty sync pages (#903)
  252. fc291cae 2026-05-10 fix(cli): emit multipart requests for upload endpoints (#904)
  253. 8cf5459c 2026-05-10 fix(cli): block vendor-prefix secrets during publish (#852)
  254. 534c24ad 2026-05-09 chore(ci): speed up PR checks via shard split + lighter lint cache (#887)
  255. 26442897 2026-05-09 chore(main): release 4.2.2 (#840)
  256. 4b29a634 2026-05-09 fix(skills): correct update preflight compatibility (#854)
  257. 1a8f68ee 2026-05-09 fix(generator): scope caches by auth identity (#853)
  258. 9f2a4efe 2026-05-09 fix(cli): default Surf browser transport to h2 (#850)
  259. f34645a8 2026-05-09 docs(cli): add Cursor guide for printed CLIs (#833)
  260. 2d9a304a 2026-05-09 fix(cli): preserve manifest fields during dogfood sync (#844)
  261. 117544d0 2026-05-09 Ignore .omx workspace folders (#841)
  262. 5155331c 2026-05-09 Reject stale publish manifests before packaging (#836)
  263. 1c0d110b 2026-05-09 fix(cli): preserve operation server host overrides (#834)
  264. dfb879de 2026-05-09 chore(main): release 4.2.1 (#805)
  265. 19702102 2026-05-09 fix(catalog): Align Google Flights catalog with Flight Goat's current wrapper (#821)
  266. 7a1d83ad 2026-05-09 fix(cli): default cookie HTML scrapes to browser transport (#822)
  267. 9bb46da6 2026-05-09 fix(cli): correct HTTP Basic auth env vars (#810)
  268. 6138e88e 2026-05-09 chore(ci): Gate main CI by changed file scope and add a skill-docs check (#809)
  269. 296093c4 2026-05-09 Document publish PR novel commands and body-file usage (#808)
  270. 079cf52b 2026-05-09 docs(cli): clarify catalog entry inclusion rules (#807)
  271. 0020b78a 2026-05-09 fix(cli): use slash paths for embedded templates (#794)
  272. 5e04776b 2026-05-09 fix(skills): gate polish ship verdict on publish validate (#789)
  273. d0086ffe 2026-05-09 fix(cli): handle Windows shipcheck paths (#783)
  274. 2ff069e0 2026-05-09 fix(cli): stop credential status overclaims (#779)
  275. 3b929c6e 2026-05-08 chore(main): release 4.2.0 (#772)
  276. de34ec0e 2026-05-08 fix(cli): avoid duplicate token auth map keys (#775)
  277. 838f5a49 2026-05-08 feat(cli): support static config headers (#769)
  278. a5b57248 2026-05-08 chore(main): release 4.1.0 (#729)
  279. 1af0f275 2026-05-08 feat(ci): add verify-skill drift check (#766)
  280. 172c6c29 2026-05-08 fix(cli): close redfin retro verification gaps (#762)
  281. 745f2e75 2026-05-08 fix(cli): sync sibling list endpoints (#756)
  282. 6348c9f2 2026-05-08 fix(cli): unscore large code-orch token catalogs (#755)
  283. ecb35ab0 2026-05-08 ci(cli): skip title lint for merge queue batches (#760)
  284. ecb2cba0 2026-05-08 ci(cli): add Mergify merge queue (#757)
  285. 92d303ac 2026-05-08 fix(cli): infer bearer auth from prose-only specs (#753)
  286. 7990021b 2026-05-08 Add issue ownership guidance to AGENTS.md (#754)
  287. c332b534 2026-05-08 fix(cli): route live cache through typed upserts (#751)
  288. c397021f 2026-05-08 fix(cli): harden force-generate preservation (#750)
  289. ee8f6ad9 2026-05-08 feat(cli): credit original printer in per-CLI README (closes #745) (#748)
  290. ca580efc 2026-05-08 fix(cli): align generated install and rename metadata (#749)
  291. 9675f8b2 2026-05-08 fix(cli): preserve novel cli files on force generate (#747)
  292. 64363921 2026-05-08 fix(generator): use simple backticks in auth_client_credentials.go.tmpl (#734)
  293. 4ca4b7cf 2026-05-08 Add contributor PR template and guide (#744)
  294. a00e97b1 2026-05-08 fix(cli): populate manifest.Category from spec when catalog misses (#735)
  295. 6044e7ff 2026-05-08 Parallelize Main CI full suite jobs (#743)
  296. dfdf1831 2026-05-08 fix(cli): hydrate promote state across scopes (#738)
  297. 8721df4b 2026-05-08 fix(cli): preserve browser-sniffed request defaults (#737)
  298. 1d26ae77 2026-05-08 fix(cli): guard generated CLI build safety (#736)
  299. b4bdcf68 2026-05-08 fix(cli): handle wrapped paginated responses (#731)
  300. 979510c2 2026-05-08 fix(cli): score structural scorer behavior (#732)
  301. a4b0eb30 2026-05-08 fix(cli): anchor openapi loader normalization (#730)
  302. a9b9aa65 2026-05-08 feat(cli): emit AGENTS.md for printed CLIs (fast-track of #681) (#728)
  303. c9ebffaa 2026-05-08 ci: add Main CI workflow for post-merge build+test+golden gate (#716)
  304. c9dd54ae 2026-05-08 chore(main): release 4.0.6 (#711)
  305. 10230542 2026-05-08 fix(cli): shard sub-resource tables per parent on collision (#707)
  306. 9e039c0b 2026-05-08 fix(cli): source store columns from response schema, not query params (#708)
  307. b196bd81 2026-05-08 fix(cli): close MCP sql tool exfiltration vector with allowlist + read-only handle (#709)
  308. c46cf015 2026-05-08 fix(cli): correct named-array envelope detection and api_key set-token slot (#706)
  309. d1c3371e 2026-05-08 fix(cli): dedupe TypeField identifiers in same struct (#705)
  310. 35d7e842 2026-05-08 fix(cli): gate orphan token scaffolding on auth surface (#704)
  311. 41c87cf8 2026-05-08 fix(cli): parse x-mcp extension in OpenAPI parser (#702)
  312. e601b211 2026-05-07 chore(main): release 4.0.5 (#700)
  313. ac75b83c 2026-05-07 fix(cli): add scoped govulncheck gates (#699)
  314. af70886c 2026-05-07 chore(main): release 4.0.4 (#692)
  315. b188dc2d 2026-05-07 fix(cli): strip leading Markdown headings from CLI descriptions (#691)
  316. fe625c6b 2026-05-07 fix(cli): dedupe regen-merge registrations by command use (#690)
  317. 2c538be1 2026-05-07 chore(main): release 4.0.3 (#686)
  318. 39cbc189 2026-05-07 fix(cli): derive Google Discovery resources from operationIds (#680)
  319. da078d0e 2026-05-07 chore(main): release 4.0.2 (#684)
  320. 96420323 2026-05-07 fix(skills): align publish with library-backed skill mirror (#683)
  321. 823412df 2026-05-07 chore(ci): clean up release workflow warnings (#679)
  322. 2ceed889 2026-05-07 chore(main): release 4.0.1 (#678)
  323. 4832173d 2026-05-07 fix(cli): sync module path with v4 release (#677)
  324. 92940bd7 2026-05-07 chore(main): release 4.0.0 (#649)
  325. 5701f3e7 2026-05-07 Clarify polish source-of-truth guidance (#676)
  326. 3da34f16 2026-05-07 Fix catalog display_name precedence (#675)
  327. a880a7f7 2026-05-07 Annotate PM workflows as read-only (#674)
  328. a590b6b9 2026-05-07 Document write-time PII redaction in dogfood reports (#673)
  329. c69e77c8 2026-05-07 feat(cli): scope verify-skill flag-names; add canonical-sections check (#665)
  330. d2eca305 2026-05-07 fix(skills): repair publish generated-artifact flow (#672)
  331. a80cb5d4 2026-05-07 chore(skills): drop compound-engineering plugin and retro hand-off (#671)
  332. d4d10a8a 2026-05-07 fix(phase5): explain accepted marker levels (#647)
  333. 289b48c5 2026-05-07 docs(cli): group install paths at top of generated README (#660)
  334. 07c8f637 2026-05-07 docs(cli): tighten README and drop stale catalog counts (#659)
  335. 1afe5da0 2026-05-07 docs(cli): prefer npx-based installer over raw go install in README (#657)
  336. 83d2bb19 2026-05-07 docs(cli): expand commit-style guidance with type list and breaking-change examples (#658)
  337. 6d9ab664 2026-05-07 feat(cli): improve generated money workflows and artifact safety (#653)
  338. cf91eab3 2026-05-06 feat(cli): add public parameter names (#648)
  339. e6aa0326 2026-05-06 fix(cli): omit version field from SKILL.md frontmatter (#656)
  340. fd7fa6ea 2026-05-06 feat(cli): Hermes/OpenClaw frontmatter alignment for printed CLIs (#655)
  341. c7574bd4 2026-05-06 fix(dogfood): accept quick live passes with skips (#646)
  342. f486e4d2 2026-05-06 chore(main): release 3.10.0 (#616)
  343. 0cf04f73 2026-05-05 fix(cli): kind-aware auth env-vars and promoted-command --limit (#645)
  344. 3bc1a23a 2026-05-05 feat(cli): widen auth env-var model with kind/required/sensitive metadata (#632) (#639)
  345. 7eb951e0 2026-05-05 feat(skills): flatten retro issues and dedup against open issues (#641)
  346. 5776553b 2026-05-05 docs(cli): rewrite install steps and collapse secondary sections (#640)
  347. 2035b276 2026-05-05 fix(cli): score composed auth and shell continuations (#636)
  348. 0310d3fb 2026-05-05 feat(skills): data-driven Phase 6 menu and hold-path support (#637)
  349. cb3ef873 2026-05-05 fix(cli): require explicit retry no-ops (#635)
  350. b4a95cb7 2026-05-05 fix(cli): infer bearer auth from inline params (#634)
  351. 6b5945fd 2026-05-05 fix(cli): preserve canonical auth env hints (#633)
  352. 013f92ad 2026-05-05 fix(cli): correct no-auth 403 hints (#629)
  353. 5004e4b0 2026-05-05 fix(cli): harden destructive auth dogfood skips (#628)
  354. 622e15f5 2026-05-05 docs(cli): capture mcp handler path-vs-query positional recurrence (#626)
  355. 57e2d13a 2026-05-05 docs(cli): capture mutator-probe dry-run pattern in solutions library (#624)
  356. e08c268b 2026-05-05 docs(cli): codify lookup-priority discipline in layout contract (#625)
  357. 5b489da7 2026-05-05 fix(cli): generate usable oauth auth config (#617)
  358. c5e7a801 2026-05-05 chore(main): release 3.9.1 (#607)
  359. 84b22d28 2026-05-05 fix(cli): skip destructive-at-auth endpoints in live dogfood (#613)
  360. 9c5b882a 2026-05-05 fix(cli): emit invalidateCache() in every printed client.go (#612)
  361. 700e4672 2026-05-05 fix(cli): resolveManuscripts prefers API-slug keying over CLI-name (#615)
  362. 24e7e60f 2026-05-05 fix(cli): default live dogfood happy_path on mutators to --dry-run (#614)
  363. 1b0dc70a 2026-05-05 fix(cli): always derive install module from filesystem in migrate-skill-metadata (#611)
  364. 4897c593 2026-05-05 fix(cli): emit ClawHub-compliant nested YAML for SKILL.md metadata (#609)
  365. 6281f2be 2026-05-05 fix(cli): route sync --json events to stdout (#608)
  366. 37ee7e38 2026-05-05 fix(cli): stamp run_id into manifest at generate time (#606)
  367. 7359a18f 2026-05-05 fix(cli): align phase5 quick gate with runner verdict (#605)
  368. 6376d95e 2026-05-05 docs(cli): capture HTTP client cache-invalidation pattern (#604)
  369. 76d32e83 2026-05-04 chore(main): release 3.9.0 (#531)
  370. ebfa6bf1 2026-05-04 fix(cli): complete bearer refresh and path handling (#584)
  371. 67c977d8 2026-05-04 test(cli): live-dogfood resolve-success and search error_path coverage (#583)
  372. e9696c9b 2026-05-04 fix(cli): preserve query params in generated MCP handlers (#582)
  373. 7572b1e0 2026-05-04 fix(cli): live-dogfood matrix accuracy (WU-2, F4+F5) (#577)
  374. 542835d3 2026-05-04 fix(cli): generator template polish (WU-1, F1+F2+F3+F6) (#576)
  375. 708a6159 2026-05-04 fix(skills): speed up retro issue filing (#575)
  376. 26fb45ea 2026-05-04 docs(cli): consolidate AGENTS.md via progressive disclosure (#574)
  377. 5bc73909 2026-05-04 feat(cli): add spec-driven tier routing (#570)
  378. 314b5650 2026-05-03 feat(cli): compact repeated MCP parameter descriptions (#569)
  379. 847f7c5b 2026-05-03 fix(skills): tighten publish and polish workflows (#568)
  380. 18542129 2026-05-03 fix(cli): preserve operation-routing path params (#567)
  381. e588bf7e 2026-05-03 fix(cli): parse epoch Retry-After headers (#565)
  382. 34413e94 2026-05-03 fix(cli): reclaim locks from dead owners (#564)
  383. c0639cf0 2026-05-03 fix(cli): exempt generated-client source helpers (#563)
  384. 6242e101 2026-05-03 fix(cli): add client-call reimplementation directive (#562)
  385. 35fa7afe 2026-05-03 fix(cli): support OpenAPI auth metadata overrides (#561)
  386. b39a23d0 2026-05-03 fix(cli): separate sampled probes from live verification (#560)
  387. e973d5c5 2026-05-03 feat(cli): add live dogfood matrix runner (#559)
  388. 7a143818 2026-05-03 fix(cli): gate publishing on Phase 5 proof (#558)
  389. aae2af9f 2026-05-03 feat(skills): retro files parent issue + per-WU sub-issues (#555)
  390. f362dd44 2026-05-03 feat(skills): /printing-press-reprint orchestrator (#553)
  391. 74eb8769 2026-05-03 fix(cli): include cobratree tools in MCP token scoring (#552)
  392. e4e66bd3 2026-05-03 fix(cli): dry-run narrative examples in strict validation (#550)
  393. 8b099ba0 2026-05-03 fix(cli): sync root highlights from verified features (#549)
  394. 96dd07c0 2026-05-03 fix(cli): session_handshake auth correctness pass (#534)
  395. 13995da7 2026-05-03 feat(skills): brainstorm novel features via Task subagent (#533)
  396. f2450385 2026-05-03 feat(skills): browser-capture fallback options (chrome-MCP, computer-use) (#529)
  397. 7364324a 2026-05-03 chore(main): release 3.8.0 (#527)
  398. 593ce970 2026-05-03 feat(cli): OAuth2 client_credentials grant + bearer_token AuthHeader precedence fix (#528)
  399. e761d04d 2026-05-03 fix(cli): FedEx retro batch — 5 small fixes (WU-2, WU-3, WU-4, WU-5, WU-7) (#526)
  400. d364472b 2026-05-02 chore(main): release 3.7.0 (#523)
  401. 3c04a065 2026-05-02 feat(skills): retro defaults to don't-file; adversarial triage gates (#524)
  402. 53be1209 2026-05-02 feat(skills): pre-generation MCP enrichment for large surfaces (#522)
  403. d5594764 2026-05-02 chore(main): release 3.6.2 (#520)
  404. 734e00d1 2026-05-02 fix(cli): MCP template ports — NoCache=true + codeOrch stopword filter (refs #515 F1, F4) (#521)
  405. 358e46a6 2026-05-02 fix(cli): scorer respects runtime MCP surface selection (refs #516 WU-A4) (#519)
  406. 83df8ae7 2026-05-02 chore(main): release 3.6.1 (#512)
  407. 702f54a1 2026-05-02 fix(cli): OpenAPI parser walks per-operation servers as fallback (#511)
  408. 53203a0c 2026-05-02 chore(main): release 3.6.0 (#509)
  409. e37cff9d 2026-05-02 fix(cli): handle sentry openapi generation (#507)
  410. 73468bac 2026-05-02 feat(cli): README template links to release page for binary + MCPB (#508)
  411. 401fa7c8 2026-05-02 chore(main): release 3.5.0 (#501)
  412. 5584818b 2026-05-02 feat(cli): JSON:API support for OpenAPI parser (envelope, page[cursor], x-prefix) (#505)
  413. 6e2562d8 2026-05-02 docs(cli): bump README "Go 1.22+" prerequisite to "Go 1.26+" (#506)
  414. 31e63be4 2026-05-02 fix(cli): honor documented typed exit codes (#504)
  415. 97180c03 2026-05-02 fix(cli): route discriminator sync to typed tables (#503)
  416. 263be3b3 2026-05-02 fix(cli): strip build/ from publish staging (#502)
  417. 2817bdc7 2026-05-02 fix(cli): route resource base urls through mcp surfaces (#500)
  418. ec74c7a9 2026-05-01 chore(main): release 3.4.3 (#499)
  419. 0a741d32 2026-05-01 fix(cli): README template recommends MCPB drag-and-drop and skill install (#498)
  420. f84853b7 2026-05-01 chore(main): release 3.4.2 (#497)
  421. 3110d5ec 2026-05-01 refactor(cli): reuse generated operation id params (#496)
  422. e4773196 2026-05-01 docs(cli): reorganize README, add badges and support sections (#495)
  423. a97b18c1 2026-05-01 chore(main): release 3.4.1 (#494)
  424. 820ba7b1 2026-05-01 fix(cli): normalize lock name so slug and binary form share lock file (#493)
  425. 67597dbb 2026-05-01 fix(cli): preserve Unicode in OpenAPI display_name (#492)
  426. 37ba0afb 2026-05-01 docs(cli): split install into clone-and-run vs marketplace paths (#491)
  427. e8c0e574 2026-05-01 chore(main): release 3.4.0 (#490)
  428. bd102cf0 2026-05-01 fix(scorer): live-check treats CLI's graceful empty-handling as PASS, not FAIL (#488)
  429. aab364be 2026-05-01 fix(generator): three template defaults polish has to fix manually (#480) (#485)
  430. c76d3ec9 2026-05-01 fix(cli): scorecard APIName drops binary suffix (#489)
  431. 2899613d 2026-05-01 fix(cli): mcp-sync stops conflating API slug with binary name (#487)
  432. 9f265510 2026-05-01 fix(cli): scorer accuracy — insight prefix, MCP dir selection, freshness coupling (#486)
  433. 40cefcb5 2026-05-01 feat(cli): add curated Shopify wrapper spec (#476)
  434. 691ee25a 2026-05-01 chore(main): release 3.3.0 (#469)
  435. 63c9618c 2026-05-01 fix(browsersniff): accept v2-shape traffic-analysis.json on load (#474) (#478)
  436. 6d45d228 2026-05-01 fix(regenmerge): correct owner rewrite + skip injection on preserved hosts (#477)
  437. 20ffaaa4 2026-05-01 chore(skills): re-add context: fork to polish and output-review (#473)
  438. d1a8a467 2026-05-01 feat(generator): owner precedence chain — preserve attribution on regen (#470)
  439. abde446e 2026-05-01 feat(regenmerge): add TEMPLATED-BODY-DRIFT verdict to catch in-place body edits (#468)
  440. 08b88654 2026-05-01 chore(main): release 3.2.1 (#466)
  441. 05092ed1 2026-05-01 fix(generator): gate table creation on hasDomainUpsert (#465 follow-up) (#467)
  442. 45a7722b 2026-05-01 fix(openapi): preserve params on single-endpoint specs (#465)
  443. eeb12ea0 2026-05-01 fix(generator): wrapWithProvenance handles non-JSON response bodies (#464)
  444. 9bc8276e 2026-05-01 ci: drop the PR-title scope allow-list, keep requireScope (#463)
  445. 97ca7994 2026-05-01 fix(regenmerge): semantic dedup for AddCommand calls (#462)
  446. be309e6a 2026-05-01 chore(main): release 3.2.0 (#460)
  447. 4c7bd42d 2026-05-01 feat(cli): add regen-merge subcommand for library template sweeps (#461)
  448. a3ea32ed 2026-05-01 fix(cli): unbreak HasStore + non-GET promoted commands (#425) (#459)
  449. 052187a7 2026-05-01 chore(main): release 3.1.0 (#419)
  450. de3a4e7c 2026-05-01 feat(cli): cost-based throttling primitives for GraphQL CLIs (#434)
  451. 2c59d1c6 2026-04-30 refactor(cli): extract body-map block to a shared helper (#450) (#457)
  452. 8a548d09 2026-04-30 feat(cli): add validate-narrative subcommand to replace bash recipe (#433) (#456)
  453. d909d6cf 2026-04-30 Fix docs-only test filtering (#455)
  454. a197d414 2026-04-30 fix(cli): pagination cursor lookup recurses into well-known wrapper objects (#157 F3) (#453)
  455. 5920d005 2026-04-30 docs(cli): document OpenAPI extensions and link it from AGENTS (#454)
  456. c78cb181 2026-04-30 fix(skills): tighten human-time-estimate cardinal rule + clean up violations (#452)
  457. 00f83219 2026-04-30 fix(skills): add Phase 3 starter templates for novel feature commands (#451)
  458. 6aee6205 2026-04-30 fix(cli): emit mcp:read-only + plumb body fields in promoted commands (#426, #427) (#449)
  459. 1e4798f1 2026-04-30 fix(cli): migrate 15 templates off flags.printJSON + dogfood regression guard (#428) (#447)
  460. ba22f30a 2026-04-30 fix(cli): retro #421 WU-4, WU-6, WU-7 — search empty JSON, live-check tokenizer, raw database/sql carve-out (#446)
  461. 493a1b15 2026-04-30 fix(cli): thread ctx through wrapper functions in generated CLIs (#442) (#445)
  462. 6d357b36 2026-04-30 feat(cli): framework-collision detection in resource-name extraction (#444)
  463. d9472b76 2026-04-30 fix(cli): cliutil.BuildPath replaces buildProxyPath with proper URL encoding (#437, #439) (#443)
  464. c11d0d95 2026-04-30 fix(cli): store.OpenWithContext + fast-path version check (#436, #438) (#441)
  465. 9a135062 2026-04-30 feat(cli): WU-2 sync correctness pass (pagination, ID extraction, exit policy, write serialization) (#430)
  466. d24f60ed 2026-04-30 feat(cli,skills): five remaining retro WUs from postman-explore — store concurrency, narrative validator, proxy joiner, browser-sniff docs (#440)
  467. 1556ff1b 2026-04-30 fix(cli): emit StringVar for cursor/page/timestamp pagination flags (#435)
  468. b6c70893 2026-04-30 fix(ci): disable golangci-lint remote schema verify (#432)
  469. 8ceea6ad 2026-04-30 feat(cli,skills): three retro WUs from postman-explore — POST-as-query detection, novel-command --select, scorecard YAML (#424)
  470. 337840c8 2026-04-30 fix(skills): sharpen retro cardinal rule to name over-fitted machine changes (#422)
  471. 332e419b 2026-04-30 feat(skills): preflight gate with interactive upgrade prompt (#420)
  472. 30370ebb 2026-04-29 fix(skills): keep absorb gate showcase as its own turn (#418)
  473. aa80c9d9 2026-04-29 chore(main): release 3.0.1 (#416)
  474. ac98c00a 2026-04-29 fix(skills): drop context: fork from output-review so AskUserQuestion works natively (#417)
  475. 4e1db1e7 2026-04-29 fix(cli): repair v3 release — version regex, module path, CI gate (#415)
  476. 10fd0405 2026-04-29 chore(main): release 3.0.0 (#356)
  477. fe5d65c5 2026-04-29 fix(skills): polish syncs novel_features; publish detects squash-zombie branches (#414)
  478. cb91024d 2026-04-29 fix(cli): OpenAPI parser prefers description over summary on operations (#411)
  479. 0683ef1f 2026-04-29 fix(skills): drop context: fork from polish so AskUserQuestion works natively (#410)
  480. fe1e6d77 2026-04-29 fix(cli): dogfood agent-context discovery reads stdout only (#407)
  481. 0954bcaf 2026-04-29 fix(cli): scorecard human output shows N/A for opt-out dimensions (#406)
  482. 6586c0a2 2026-04-29 feat(cli): per-resource base_url override in spec schema (#405)
  483. 7670fe98 2026-04-29 fix(cli): mcp-sync bumps mcp-go pin when migrating to cobratree surface (#404)
  484. 85259159 2026-04-29 feat(cli): generator emits mcp:read-only on read-only novel commands (#401)
  485. 717a4de3 2026-04-29 test(cli): cover EndpointTemplateVars runtime substitution + byte-compat
  486. a0e1bb4a 2026-04-29 fix(cli): keep template-var env names out of verifier auth discovery
  487. 8cb57db3 2026-04-29 feat(cli): substitute EndpointTemplateVars in client.do() + cache key
  488. 289e5988 2026-04-29 feat(cli): emit buildURL helper + Config.TemplateVars for templated endpoints
  489. 7e08324a 2026-04-29 test(cli): cover templated BaseURL + GraphQLEndpointPath rendering
  490. 699e8ed7 2026-04-29 feat(cli): split BaseURL from GraphQLEndpointPath in GraphQL parser + client
  491. 73d136f7 2026-04-29 feat(cli): add GraphQLEndpointPath and EndpointTemplateVars to APISpec
  492. d1b9cd27 2026-04-29 fix(cli): mcp-sync auto-fixes spec.yaml name drift for internal YAML specs (#400)
  493. 2d9efda5 2026-04-29 fix(skills): polish loads AskUserQuestion via ToolSearch in forked context (#399)
  494. 262ab876 2026-04-29 feat(skills): add /printing-press-import to bring published CLIs into internal library (#398)
  495. fae7e6e0 2026-04-29 fix(cli): manifest description no longer doubles 'API' when display_name ends in 'API' (#397)
  496. 2b7a51e1 2026-04-29 feat(cli,skills): generator-time MCP description enrichment from spec (#396)
  497. e326adfd 2026-04-29 docs(skills): polish skill — read spec.json directly for required/optional, not the manifest (#395)
  498. cdd9153b 2026-04-29 fix(cli): tools-manifest.json classifies reclassified path params as path, not query (#394)
  499. 64f67981 2026-04-29 feat(cli): mcp-sync reads display_name from public library registry.json fallback (#391)
  500. 401bda54 2026-04-29 fix(cli,skills): manifest display_name preservation + divergence-check exemptions (#390)
  501. 0320269d 2026-04-29 feat(cli,skills): polish ledger per-item enforcement + AGENTS.md guidance (#389)
  502. e651d01f 2026-04-29 feat(cli): MCP description overrides + tools-audit scoring + polish skill nibbles (#382)
  503. fee6802e 2026-04-29 feat(cli): tools-audit checks MCP descriptions in tools-manifest.json (#381)
  504. 6727d0d8 2026-04-29 feat(skills): add divergence check to polish skill setup (#380)
  505. a9ca3f80 2026-04-29 refactor(skills): extract Phase 4.85 into printing-press-output-review sub-skill (#379)
  506. e4a0089c 2026-04-29 feat(cli): add tools-audit subcommand and merge polish into a single skill (#378)
  507. a8163024 2026-04-28 fix(cli): mcp-sync detects suggestFlag/Deliver across cli package, not just root.go (#377)
  508. 2b9f2fbb 2026-04-28 fix(cli): mcp-sync skips deliver/suggestFlag prolog blocks when absent (#376)
  509. 40d1ffad 2026-04-28 fix(cli): mcp-sync refreshes .printing-press.json from spec.yaml (#375)
  510. a158a629 2026-04-28 fix(cli): wire auth.optional through CLIManifest to MCPB user_config Required (#374)
  511. 9f57c41d 2026-04-28 fix(cli): mcp-sync preserves manifest brand-casing and hand-edited descriptions (#373)
  512. 283c9923 2026-04-28 fix(cli): transliterate spec strings to ASCII via Unidecode at every chokepoint (#371)
  513. 1a4bcae8 2026-04-28 fix(cli): mcp-sync handles older library CLI drift (cliutil + name validation) (#369)
  514. 358ff782 2026-04-28 feat(cli): MCP tool surface mirrors Cobra tree at runtime, with mcp-sync backfill (#367)
  515. 1b664d0f 2026-04-28 chore(cli): Update Go dependencies and generated CLI template (#368)
  516. 4a2caae0 2026-04-28 docs(cli): plan MCP tool surface mirrors Cobra tree, with mcp-sync backfill (#365)
  517. 174d23c8 2026-04-28 fix(cli): add source rate-limit guardrails (#366)
  518. 5777d267 2026-04-28 chore(cli): drop dead manifest_url + manifest_checksum from registry guidance (#364)
  519. 0e1b8508 2026-04-28 chore(cli)!: remove megamcp aggregate server and Composio plan (#363)
  520. 95cf6c88 2026-04-28 fix(ci): shard test lanes (#362)
  521. a5ba1b4a 2026-04-28 fix(ci): remove redundant generated compile work (#361)
  522. ddacddba 2026-04-28 fix(ci): speed up generated compile tests and caches (#360)
  523. 2e892e36 2026-04-28 fix(cli): manifest emission no longer gated by stale mcp_ready label (#359)
  524. 9e260025 2026-04-27 ci(ci): split fast and full test lanes (#357)
  525. 7f248d59 2026-04-27 feat(cli): emit MCP tools for novel CLI features via shell-out (#358)
  526. af214509 2026-04-27 feat(cli): MCPB manifest and bundle support for generated CLIs (#355)
  527. ff70c7eb 2026-04-27 chore(main): release 2.4.0 (#330)
  528. 4a6e5c7f 2026-04-27 test(cli): simplify shipcheck test setup (#354)
  529. 0ed2fbd8 2026-04-27 fix(cli): machine improvements from hackernews retro #350 (#352)
  530. 47fe3393 2026-04-27 fix(publish): gate packaging on skill verification (#348)
  531. 494abe48 2026-04-27 feat(cli): add printing-press shipcheck umbrella + Phase 4 enforcement + polish-worker hook (#353)
  532. f3c18d4c 2026-04-27 docs(cli): add MIT LICENSE matching README declaration (#349)
  533. 3f7410de 2026-04-27 ci(ci): guard low-risk checks and setup docs (#347)
  534. 4c64ffe6 2026-04-27 ci(ci): improve workflow coverage and guards (#346)
  535. 8617e06d 2026-04-27 test(cli): add golden coverage for generated artifacts (#345)
  536. d86d3af1 2026-04-27 fix(cli): sync dogfood novel features into CLI artifacts (#344)
  537. 5fa694a0 2026-04-27 feat(cli): printing-press machine fixes from food52 retro (#337) (#342)
  538. c74dcd45 2026-04-27 fix(cli): Cal.com retro #334 — 4 of 5 P1 machine fixes (per-endpoint headers, novel_features, auth set-token, PII scrub) (#341)
  539. b25c2b90 2026-04-27 fix(cli): recover RunID in NewMinimalState so lock promote enriches novel_features (#340)
  540. 907c6986 2026-04-27 feat(cli): add unknown-command check + sync test for verify-skill (#339)
  541. 4219e712 2026-04-27 feat(cli): emit promoted-leaf paths in SKILL.md (#338)
  542. 6b2be74d 2026-04-27 fix(cli): printing-press P1 machine fixes (issue #333) (#335)
  543. 8bad2efd 2026-04-27 fix(cli): score auth prefixes from config (#332)
  544. 09dccfb9 2026-04-27 feat(cli): add probe-reachability for no-browser challenge classification (#331)
  545. 5966298e 2026-04-26 feat(skills): reconcile prior novel features on reprint (#329)
  546. cae740f5 2026-04-26 chore(main): release 2.3.9 (#309)
  547. df551b37 2026-04-26 fix(ci): include refactors in release notes (#328)
  548. 52bde6b4 2026-04-26 refactor(cli): share generated naming helpers (#327)
  549. a2fe1581 2026-04-26 refactor(cli): simplify scorecard dimension bookkeeping (#326)
  550. 545ffb94 2026-04-26 refactor(cli): simplify generate orchestration (#325)
  551. 9b97201f 2026-04-26 docs(cli): use go fmt ./... for formatting instructions (#324)
  552. f9c9efd4 2026-04-26 test(cli): speed up generator test suite (#323)
  553. b1001491 2026-04-26 refactor(cli): split verify command helpers (#322)
  554. 18cf50f1 2026-04-26 refactor(cli): split verify exec helpers (#321)
  555. 7e733aa7 2026-04-26 refactor(cli): split structural verify runtime (#320)
  556. ee923f84 2026-04-26 refactor(cli): share verify report finalization (#319)
  557. faac0d39 2026-04-26 refactor(cli): table-drive dogfood verdict rules (#318)
  558. b54882aa 2026-04-26 fix(skills): inherit Codex model from ~/.codex/config.toml instead of hardcoding (#317)
  559. a5c59b33 2026-04-26 refactor(cli): table-drive fullrun comparison metrics (#316)
  560. 015ad88e 2026-04-26 refactor(cli): split scorecard scoring stages (#315)
  561. 52a3dbc5 2026-04-26 refactor(cli): split generator vision render stages (#314)
  562. 79b134aa 2026-04-26 refactor(cli): split generator render stages (#313)
  563. b8bb5c1e 2026-04-26 refactor(cli): share generated auth helpers (#312)
  564. fd2ea4f4 2026-04-26 refactor(cli): simplify refactor-safe helpers (#311)
  565. 0a1e80d9 2026-04-26 test(cli): add golden output harness (#310)
  566. f33d8e55 2026-04-26 fix(cli): harden store migrations for generated identifiers (#308)
  567. 42721ebc 2026-04-26 chore(main): release 2.3.8 (#304)
  568. 6181ee36 2026-04-26 fix(cli): retro #302 — nine fixes from pagliacci-pizza regenerate (#305)
  569. 0d4d2cba 2026-04-26 docs(cli): refresh README for launch (Apr 28) (#306)
  570. 8aad8d85 2026-04-26 fix(cli): retro #301 — six improvements from recipe-goat regenerate (#303)
  571. 574fc27d 2026-04-26 chore(main): release 2.3.7 (#299)
  572. 0cc70170 2026-04-26 fix(cli): use strconv.Atoi for major-version parsing in guard test (#300)
  573. 1ab789ea 2026-04-26 fix(cli): use /v2 module path so go install reports correct version (#298)
  574. 42b0f1f4 2026-04-25 chore(main): release 2.3.6 (#297)
  575. 1e06456c 2026-04-25 fix(cli): normalize routing prefixes in OpenAPI paths (#296)
  576. 19e996ae 2026-04-25 chore(main): release 2.3.5 (#295)
  577. 0aafafa3 2026-04-25 fix(cli): normalize generated env var prefixes (#294)
  578. a18088ad 2026-04-25 chore(main): release 2.3.4 (#292)
  579. ac74e7d2 2026-04-25 fix(cli): gate publishing on transcendence features (#293)
  580. 4a77f46c 2026-04-25 fix(catalog): update stale spec URLs + add download content-validity check (#282)
  581. 6ed197c4 2026-04-25 fix(cli): make firstCommandExample helper promotion-aware (#291)
  582. 5f68784d 2026-04-25 chore(main): release 2.3.3 (#277)
  583. 15529383 2026-04-25 fix(cli): extend flag-identifier dedup to request body fields (#288)
  584. ee6bd881 2026-04-25 fix(cli): refresh stale catalog entries and reject non-spec bodies (#286)
  585. 6361826d 2026-04-25 fix(cli): normalize object-shaped description fields before parsing (#285)
  586. 1a95a78a 2026-04-25 fix(cli): prepend T to type names that match Go reserved words (#284)
  587. 72a84a88 2026-04-25 fix(cli): dedup colliding flag identifiers in generated commands (#283)
  588. 6bbae936 2026-04-25 fix(cli): honor explicit --output flag in generate (#281)
  589. 55114c4e 2026-04-25 fix(cli): treat access-denied sync errors as warnings (#274) (#280)
  590. ea0fbe94 2026-04-25 fix(cli): validate generated JSON string flags (#278)
  591. 1a95d78b 2026-04-25 fix(ci): build from local checkout instead of proxying private module (#279)
  592. 892de38b 2026-04-24 fix(cli): backfill parent_id on store upgrade (#272) (#276)
  593. 7c9cce48 2026-04-24 chore(main): release 2.3.2 (#269)
  594. 8eea3a0e 2026-04-24 fix(cli): dispatch UpsertBatch to typed tables (#268) (#271)
  595. 6a184771 2026-04-24 fix(cli): stop doctor from claiming valid creds are invalid (#270)
  596. 24785ee5 2026-04-24 fix(cli): avoid duplicate batch store upsert generation (#231)
  597. 55b3f5e1 2026-04-24 fix(megamcp): reject env var values containing '}' in ApplyAuthFormat (#252)
  598. d35f25bc 2026-04-24 chore(main): release 2.3.1 (#266)
  599. 2c802afe 2026-04-24 fix(megamcp): validate placeholders before substitution in ApplyAuthFormat (#262)
  600. 28ba1e01 2026-04-24 fix(openapi): collect paths to delete before mutation in stripBrokenRefs (#259)
  601. 1645e962 2026-04-24 fix(cli): quote paths in emboss stderr output to prevent shell injection (#256)
  602. 5353fb38 2026-04-23 chore(main): release 2.3.0 (#250)
  603. 4291b3b9 2026-04-23 feat(cli): add machine-owned freshness coverage (#249)
  604. 92c5b2f4 2026-04-23 chore(main): release 2.2.0 (#184)
  605. bc13a5b4 2026-04-23 fix(ci): allow release-please PR title scope (#248)
  606. d14cefaa 2026-04-23 fix(skills): keep scratch artifacts out of repo docs (#247)
  607. e741db80 2026-04-23 feat(cli): generate replayable website CLIs (#241)
  608. 38db0610 2026-04-22 feat(cli): mcp-audit subcommand + docs for the new MCP surface (#246)
  609. 2d07a021 2026-04-22 feat(cli): scorecard dimensions for remote transport, tool design, surface strategy (#245)
  610. a4207be8 2026-04-22 feat(cli): code-orchestration thin surface for large-surface APIs (#244)
  611. 85d4ace9 2026-04-22 feat(cli): declare intent-grouped MCP tools in the spec (#243)
  612. bce586bc 2026-04-22 feat(cli): add http streamable transport to generated MCP servers (#242)
  613. 9dd5632a 2026-04-22 feat(cli): generate <cli> which <capability> resolver in every printed CLI (#240)
  614. 440f654d 2026-04-22 feat(cli): add live_api_verification scorecard dimension (#239)
  615. 00b9a0d4 2026-04-22 feat(cli): reimplementation gate in absorb scoring and dogfood (#238)
  616. e2ca1825 2026-04-22 docs(cli): add 9-phase pipeline contract at docs/PIPELINE.md (#237)
  617. 8ebb44f3 2026-04-22 docs(skills): improve printing press voice guidance (#235)
  618. 5e2ed6a8 2026-04-21 feat(cli): git-backed snapshot share + cache_freshness scorecard dimension (#234)
  619. 4c05e1ee 2026-04-21 feat(cli): auto-refresh stale caches before read commands (#233)
  620. e116a27c 2026-04-21 feat(cli): schema-version gate, doctor cache section, cache/share spec surface (#232)
  621. ab7254b1 2026-04-21 docs(cli): fix plugin install commands in README (#230)
  622. ac4d6aa2 2026-04-20 fix(cli): support nested --select paths + suppress provenance on non-TTY stdout (#229)
  623. 84043f3a 2026-04-19 feat(cli): support extra_commands: in spec.yaml for hand-written commands (#227)
  624. 72916ac1 2026-04-19 feat(cli): add auth doctor subcommand (#226)
  625. 23084c76 2026-04-18 refactor(cli): rename sniff to browser-sniff (#225)
  626. 86bdfd2e 2026-04-18 fix(cli): patch verifies target shape + runs build in target dir (#224)
  627. 8c54c4c8 2026-04-18 fix(cli): scope goimports to patched files only (#223)
  628. 331809da 2026-04-18 feat(cli): patch skips AST mutations owned by colliding features (#222)
  629. c5ed4369 2026-04-18 fix(cli): publish manifest must read spec.yaml alongside spec.json (#220)
  630. 16ed5a56 2026-04-18 feat(cli): printing-press patch — AST-inject PR #218 features into published CLIs (#221)
  631. 1d4e642c 2026-04-18 fix(cli): authenticate mega MCP library fetches with GITHUB_TOKEN
  632. 3fd4a5a8 2026-04-17 style(cli): simplify async-detect sibling-filter boolean
  633. 3ae025f8 2026-04-17 feat(cli): agent_workflow_readiness scorecard dimension
  634. c6223b41 2026-04-17 feat(cli): feedback subcommand for agent-in-band friction reports
  635. f6e74931 2026-04-17 feat(cli): --deliver routes command output to file or webhook
  636. 7140c3e7 2026-04-17 feat(cli): named-profile system for repeatable agent contexts
  637. 1c172850 2026-04-17 feat(cli): async-job detection, --wait flag, jobs command
  638. d4297f63 2026-04-17 docs(cli): plan HeyGen CLI learnings application
  639. dc5a8cc4 2026-04-13 feat(cli): apply Cloudflare Wrangler CLI learnings (naming check, MCP token efficiency, agent-context) (#216)
  640. 6f8b0c7d 2026-04-13 fix(skills): Phase 4.85 prompt refinements from calibration dispatch (#215)
  641. 270270ab 2026-04-13 feat(cli): machine-output-verification Wave B — live-check entity rule + Phase 4.85 agentic output review (#214)
  642. 65dacc25 2026-04-13 feat(cli): machine-output-verification Wave A — cliutil package + dogfood test-presence gate (#213)
  643. 18cb521e 2026-04-13 feat(cli): printing-press verify-skill + Phase 4 wiring + Phase 4.8 agentic SKILL reviewer (#212)
  644. 831040d5 2026-04-13 feat(cli): auth.optional spec field — doctor INFO not FAIL, README framing, auth cmd names env var (#211)
  645. df242da4 2026-04-13 feat(cli): scorecard --live-check samples novel-feature examples against real targets — closes #200 (#210)
  646. caa283ed 2026-04-13 feat(cli): kind: synthetic spec attribute for multi-source CLIs — closes #203 (#209)
  647. 26bc9057 2026-04-13 feat(cli): enum validation for params declared with enum constraints (#208)
  648. 3bef9d6c 2026-04-13 fix(skills): retro 2026-04-13 — stop the ship-broken pattern and require mechanical Phase 5 dogfood (#207)
  649. 4ebfa088 2026-04-12 fix(cli): promoted-command presence check uses promoted type (#196)
  650. 126b00d0 2026-04-12 fix(cli): path-aware dogfood novel-feature matcher (#195)
  651. 297c3c14 2026-04-12 feat(scripts): add verify-skill — static SKILL.md validator (#194)
  652. 0ac65134 2026-04-12 feat(cli): add travel and food-and-dining categories (#187)
  653. 1011df38 2026-04-12 fix(cli): enrich README and generate SKILL.md so printed CLIs stop looking like scaffolding (#186)
  654. e2009bb1 2026-04-12 fix(cli): cross-CLI retro findings - store, sync, scorer, GraphQL templates (#185)
  655. b436b081 2026-04-12 fix(cli): add transitive reachability to dogfood dead function scanner (#183)
  656. 7e640716 2026-04-12 chore(main): release 2.1.0 (#181)
  657. 8239f28b 2026-04-12 fix(ci): make validate-catalog fail loud on missing base ref (#180)
  658. 6cc5a5f6 2026-04-12 feat(skills): add DeepWiki codebase analysis to research phase (#156)
  659. 575a3f4f 2026-04-12 chore(main): release 2.0.0 (#170)
  660. 9da1cabd 2026-04-12 fix(cli): address remaining ESPN retro findings — verify hints, FTS5, doctor (#179)
  661. 096950fd 2026-04-11 feat(cli): wrapper-only catalog entries for reverse-engineered APIs (#177)
  662. 23ccc603 2026-04-11 fix(skills): add combo-CLI priority gate to prevent source inversion (#176)
  663. 8357850d 2026-04-11 fix(cli): address retro findings from yahoo-finance run (#174) (#175)
  664. cd93b172 2026-04-11 fix(cli)!: decouple printing-press-library into standalone marketplace
  665. c04b6c10 2026-04-11 fix(skills): add self-vetting gate for transcendence features
  666. a1fae23b 2026-04-11 fix(skills): user-first transcendence feature discovery
  667. 06569757 2026-04-11 fix(cli): double -pp-cli suffix in manifest + Phase 5 skips no-auth APIs
  668. 2e21807d 2026-04-11 fix(ci): auto-sync go install when installed binary exists
  669. 68bc76f3 2026-04-11 fix(cli): decouple CLI version from API version
  670. f07a795d 2026-04-11 fix(cli): default empty version to 1.0.0 and normalize to semver
  671. ad9e4aee 2026-04-11 fix(cli): movie-goat retro — generator param handling, write-through, sync ceiling, scorer (#172)
  672. ebd1d048 2026-04-11 chore(skills): remove duplicate version fields from marketplace.json
  673. ac47b18e 2026-04-11 fix: use git-subdir source for printing-press-library plugin (#169)
  674. 33d1ba11 2026-04-10 chore(main): release 1.3.2 (#167)
  675. e8aa611c 2026-04-11 fix(skills): enforce sniff gate with marker file contract (#166)
  676. 32d167a6 2026-04-10 chore(main): release 1.3.1 (#165)
  677. ab7f83c9 2026-04-10 fix(cli): address Kalshi retro findings — --name flag, sync keys, primary key detection (#163) (#164)
  678. d0ef71bf 2026-04-10 chore(main): release 1.3.0 (#155)
  679. 92074e67 2026-04-11 fix(cli): GraphQL type dedup, usageErr emission, and FTS5 manual sync (#149)
  680. 911dc290 2026-04-11 feat(cli): printing press improvements from agent-capture retro (#141)
  681. f9e6c108 2026-04-11 fix(cli): retro fixes from trigger-dev generation (#159)
  682. 4d3c31f8 2026-04-11 fix(cli): always emit usageErr helper (#162)
  683. cbcd67db 2026-04-10 feat(cli): add printing-press-library plugin to marketplace (#161)
  684. 8354f528 2026-04-10 feat(cli): apply PostHog agent-first learnings to MCP server generation (#160)
  685. 776d433c 2026-04-09 fix(skills): correct publish package flag name and staging workflow
  686. 49148b43 2026-04-09 feat(cli): add --dates sync flag and wrapper-object list detection (#154)
  687. af88767c 2026-04-09 chore(main): release 1.2.1 (#151)
  688. 178ae829 2026-04-09 fix(skills): constrain artifact writes to managed directories
  689. b1128d0e 2026-04-09 fix(cli): raise resource limit from 50 to 500 and add --max-resources flag (#152)
  690. 816a9fd6 2026-04-09 fix(cli): deduplicate config env var tags and add operations shorthand (#150)
  691. 36ed047f 2026-04-08 refactor(cli): library directories keyed by API slug instead of CLI name (#148)
  692. 2e3b7860 2026-04-07 chore(main): release 1.2.0 (#144)
  693. e041f50e 2026-04-07 feat(cli): mega MCP — generic HTTP proxy with activation model (#147)
  694. 3393ada0 2026-04-07 fix(cli): sync version files to 1.1.0 and fix release-please config (#146)
  695. 51afd778 2026-04-06 feat(cli): MCP readiness layer — per-endpoint auth awareness and metadata (#145)
  696. 349580af 2026-04-06 fix(cli): Dub retro — FTS batch indexing, retry cap, dogfood auth, root dedup, dead code (#143)
  697. 0e30fc53 2026-04-06 chore(main): release 1.1.0 (#134)
  698. d9629475 2026-04-06 fix(cli): generate correct library install path in READMEs
  699. 1b4b9844 2026-04-05 feat(cli): rename What's New Here to Unique Features, move after Quick Start
  700. 96b9b42c 2026-04-05 feat(cli): flow transcendence features into generated READMEs with integrity validation (#137)
  701. 3ea8601d 2026-04-05 fix(skills): add Phase 3 Completion Gate to prevent skipping transcendence features
  702. fb164adc 2026-04-05 feat(cli): per-endpoint header routing and auth inference from Authorization header params (#136)
  703. b5fddac0 2026-04-05 fix(cli): ensure Sync is always enabled when Store is true
  704. 3e9ac6d8 2026-04-05 chore(main): release 1.0.0 (#45)
  705. dd5abb1f 2026-04-05 feat(cli): auto-calibrate endpoint-per-resource limit from spec
  706. 95c96c4d 2026-04-05 fix(cli): address Cal.com retro findings — scoring, templates, parser, dogfood (#133)
  707. eae73f44 2026-04-05 fix(skills): improve retro issue format — priority sections, F-prefix findings, retro doc artifact
  708. c2076e02 2026-04-05 feat(skills): make printing-press-retro a public skill (#129) (#131)
  709. b5c91158 2026-04-04 fix(cli): replace MarkFlagRequired with RunE validation, remove import guards, fix type fidelity (#130)
  710. 0dac6232 2026-04-04 feat(cli): add name collision detection and resolution to publish workflow (#128)
  711. 81716728 2026-04-04 fix(cli): auto-award OAuth2 auth points until generator supports it
  712. 8ec4fc7e 2026-04-04 feat(cli): non-skippable dogfood gate and deeper data pipeline validation (#127)
  713. a1096f41 2026-04-04 fix(skills): inline dogfood protocol steps to prevent skipping
  714. 75ad9cdb 2026-04-04 feat(cli): infer API auth from spec description when securitySchemes missing (#126)
  715. 79a94585 2026-04-04 feat(cli): detect and emit required API headers from OpenAPI specs (#125)
  716. 26fe5727 2026-04-04 fix(cli): unhide sub-resource groups when wired into promoted commands
  717. b80d3140 2026-04-04 fix(cli): dogfood uses cobra Use: fields and recursive help walking
  718. 6e2e1b3c 2026-04-04 fix(skills): comprehensive README requirements for polish agent
  719. afcd3bd6 2026-04-04 fix(skills): polish agent picks useful Quick Start commands, not just working ones
  720. c4befa79 2026-04-04 fix(skills): polish agent reports skipped findings with reasoning
  721. af759a27 2026-04-04 feat(skills): extract polish protocol into polish-worker agent
  722. d509976c 2026-04-04 fix(skills): polish always runs after shipcheck, not just after dogfood
  723. e7f756b2 2026-04-04 fix(skills): auto-polish after dogfood testing when fixes were applied
  724. bc320846 2026-04-04 fix(cli): FTS trigger safety, envelope unwrapping, dogfood testing phase (#124)
  725. 289ac4bf 2026-04-04 fix(cli): SQL reserved word safety, promoted subcommands, verify classification (#122)
  726. 4b12b325 2026-04-04 feat(cli): hide raw resource commands when promoted exist, add api discovery (#121)
  727. 360db307 2026-04-04 fix(skills): publish skill checks for merged PRs before reusing branch
  728. 8763a05f 2026-04-03 fix(cli): sync path resolution for non-paginated list endpoints
  729. 729ad07d 2026-04-03 fix(cli): use catalog Homepage for README website link, remove Homebrew section
  730. 90cf5844 2026-04-03 feat(cli): search body construction, README website links, and profiler param detection (#120)
  731. b88aa97b 2026-04-03 feat(cli): add --data-source flag for live/local/auto read resolution (#119)
  732. ff465aac 2026-04-03 fix(skills): publish skill specifies full PR URL format
  733. 34e354f6 2026-04-03 feat(cli): enum sync expansion and generic API prefix stripping (#118)
  734. c29604c0 2026-04-03 fix(cli): fix extractKeyURL known-platform check and publish skill contract test
  735. 25e059c3 2026-04-03 docs(cli): mark scorer/pagination/proxy-routes plan as completed
  736. 5094562d 2026-04-03 fix(cli): scorer false positives, pagination param plumbing, and catalog proxy_routes (#117)
  737. 5026f516 2026-04-03 fix(skills): publish skill supports fork-based PRs for external contributors (#116)
  738. e9d9daa5 2026-04-03 fix(cli): scorer recognizes composed/cookie auth and apiKey header matching
  739. 6d2d059d 2026-04-03 feat(cli): browser auth, composed cookies, smart output, and sniff robustness (#115)
  740. b0a38151 2026-04-03 feat(cli): add Chrome cookie auth for sniff-discovered APIs (#113)
  741. 10150ad3 2026-04-03 feat(cli): runstate isolation and lock lifecycle for parallel build safety (#114)
  742. a28d1b48 2026-04-02 fix(cli): add primary workflow verification to printing press pipeline (#112)
  743. 0993d60c 2026-04-02 fix(cli): add --dest flag to publish package for direct repo writes (#111)
  744. 1f9148f0 2026-04-02 feat(skills): populate README source credits from absorb manifest
  745. 67980886 2026-04-02 fix(cli): README title, code block spacing, scorer placeholder fix
  746. 9ab8aa12 2026-04-01 fix(cli): README scorer alias, template placeholder, verify env discovery
  747. 125188d1 2026-04-01 fix(skills): goal-driven sniff strategy replaces page-crawl approach (#109)
  748. 998908b5 2026-04-01 refactor(skills): extract conditional sections to reference files (#108)
  749. b037ac01 2026-04-01 fix(cli): publish skill registry format and manuscript resolution (#106)
  750. fc94557c 2026-04-01 fix(skills): add secret leak prevention rules (#107)
  751. 2c9d57d7 2026-04-01 feat(cli): add printing-press polish --remove-dead-code (#105)
  752. 55c5525b 2026-04-01 fix(cli): machine context compensation — scorer, generator, skill improvements (#104)
  753. 6da6fd09 2026-04-01 feat(cli): generator pipeline improvements — auth inference, verify env, sync paths (#103)
  754. 3af5d2d7 2026-04-01 fix(ci): add post-merge hook to rebuild binary after git pull
  755. 82a36148 2026-04-01 fix(cli): generator template improvements — ID typing, dead imports, README cookbook (#102)
  756. 8a5d01cc 2026-04-01 fix(cli): scorer behavioral detection — path validity, insight/workflow, dogfood false positives (#101) (#101)
  757. 1c5d6ca9 2026-03-31 fix(cli): Steam retro improvements — scorer bugs, cache poisoning, template defaults (#100)
  758. 34a91421 2026-03-31 fix(skills): fix authenticated sniff session transfer daemon lifecycle (#99)
  759. 23648d47 2026-03-31 fix(skills): correct briefing copy for CLI output description (#98)
  760. 63970f8f 2026-03-31 feat(skills): add proactive auth intelligence and session transfer for sniff gate (#97)
  761. 8311b137 2026-03-31 feat(skills): add onboarding briefing and showcase novel features at absorb gate (#96)
  762. 129cdea2 2026-03-31 feat(skills): add Victorian printing press operator voice (#95)
  763. ed552cb3 2026-03-31 docs(cli): add glossary section to AGENTS.md (#94)
  764. ebc132f6 2026-03-31 fix(ci): auto-rebuild printing-press binary on worktree creation (#93)
  765. 151ec979 2026-03-31 fix(cli): actionable auth errors with env var names, key URLs, and 400 handling (#92)
  766. bed2f97c 2026-03-30 feat(skills): add API reachability gate before generation (#91)
  767. 03487972 2026-03-30 feat(skills): add /printing-press-polish standalone skill (#90)
  768. 6c3c8db8 2026-03-30 fix(cli): four generator improvements from Redfin retro (#89)
  769. 7f02e107 2026-03-30 fix(cli): filter crowd-sniff auth env var hints by API name relevance (#86)
  770. dfc20ac0 2026-03-30 fix(skills): add mandatory publish checkpoint after archive (#88)
  771. d289a892 2026-03-30 feat(skills): auto-brainstorm features before absorb gate (#87)
  772. 5bc0b6b8 2026-03-30 fix(skills): add mandatory sniff gate checkpoint before absorb gate (#85)
  773. c4a7dcf2 2026-03-30 fix(ci): add gofmt pre-commit hook and lint pushed files (#83)
  774. 14b9e74f 2026-03-30 fix(skills): merge codex detection into setup contract (#84)
  775. 79568409 2026-03-30 Revert "fix(skills): merge codex detection into setup contract"
  776. 43d21f22 2026-03-30 fix(skills): merge codex detection into setup contract
  777. 8a8916fd 2026-03-30 fix(cli): crowd-sniff and generator improvements from Steam retro (#82)
  778. 64ded0ae 2026-03-30 fix(skills): improve retro skill prioritization and skip/do criteria (#81)
  779. 1f918585 2026-03-30 fix(skills): archive manuscripts unconditionally after shipcheck, not inside publish gate (#80)
  780. fba41deb 2026-03-30 fix(cli): generator improvements from postman-explore retro (#76)
  781. 4a9843df 2026-03-30 feat(cli): add crowd-sniff command for community-based API discovery (#67)
  782. 3093e11a 2026-03-30 feat(skills): read MCP source code during ecosystem absorb (#79)
  783. e1135992 2026-03-30 feat(cli): auth onboarding UX for generated CLIs (#78)
  784. bd844414 2026-03-30 docs(cli): add local build and plugin dev instructions to README (#77)
  785. df6f86c0 2026-03-30 docs(cli): replace Discord with HubSpot as hero example
  786. b2ad7a86 2026-03-30 docs(cli): replace 'stealing' with 'absorbing' in README
  787. 7a49df71 2026-03-30 docs(cli): replace emdashes with regular dashes in README
  788. cc28b36f 2026-03-30 docs(cli): comprehensive README rewrite reflecting current product (#75)
  789. 89ca2ffd 2026-03-30 feat(skills): add browser-use version compatibility check to sniff gate (#74)
  790. cac7eac2 2026-03-30 feat(skills): add URL detection and disambiguation to printing-press skill (#73)
  791. 91c87cde 2026-03-30 feat(cli): add Sources & Inspiration section to generated README (#72)
  792. 99b0768d 2026-03-30 feat(skills): implement codex delegation mode in printing-press skill (#71)
  793. 9bad30af 2026-03-30 feat(cli): add discovery/ manuscript directory for sniff provenance (#70)
  794. 788a696d 2026-03-30 fix(skills): add cd to publish-repo before gh pr create/edit (#69)
  795. 154626ed 2026-03-30 fix(cli): write .printing-press.json manifest during generate command (#68)
  796. 797049f5 2026-03-29 fix(cli): add smart-default table output for POST endpoints (#66)
  797. f0bb0de2 2026-03-29 feat(cli): add proxy-envelope client pattern to generator (#65)
  798. 244c4845 2026-03-29 feat(cli): use local module path at generation, rewrite at publish (#63)
  799. bafe3563 2026-03-29 fix(skills): require CLI description rewrite after generation (#64)
  800. e26505e5 2026-03-29 feat(cli): add adaptive rate limiting for sniffed APIs (#62)
  801. f5716d90 2026-03-29 feat(cli): add spec_source, auth_required, client_pattern to catalog schema (#61)
  802. 283ab9bf 2026-03-29 feat(cli): add smart-default output format to generator templates (#60)
  803. f27c735e 2026-03-29 docs(cli): add "Why These CLIs Win" section to README (#59)
  804. 4a1bd289 2026-03-29 feat(skills): offer publish after CLI generation completes (#57)
  805. 590a07b1 2026-03-29 feat(skills): show existing CLI context and clarify regeneration menu (#58)
  806. 035d0974 2026-03-29 chore(cli): remove stale planning docs (#56)
  807. bf14db97 2026-03-29 feat(cli): add publish skill to ship CLIs to printing-press-library (#54)
  808. ccf7b2ee 2026-03-29 fix(skills): make sniff gate reliable with CLI-driven browsing and time budget (#55)
  809. 5ee774c8 2026-03-29 fix(cli): reject external symlinks during copy (#53)
  810. cd61dd88 2026-03-29 fix(skills): recommend installing both capture tools in sniff gate (#52)
  811. 0f765d10 2026-03-29 fix(skills): don't call unauthenticated endpoints a "public API" (#51)
  812. a350f419 2026-03-29 feat(skills): auto-suggest novel CLI features before absorb gate (#50)
  813. 66cbbc98 2026-03-29 fix(skills): strengthen sniff gate and add absorb gate options (#49)
  814. ca675212 2026-03-29 fix(skills): auto-install printing-press binary in setup contract (#46)
  815. b2b47320 2026-03-29 feat(skills): offer to install capture tools when sniff gate fires (#48)
  816. 82bc5a37 2026-03-29 feat(skills): add browser-use as primary sniff capture backend (#47)
  817. a8a003da 2026-03-29 feat(generator): make generated CLIs agent-native by default (#43)
  818. 334a52af 2026-03-29 feat(skills): integrate sniff into printing-press skill workflow (#44)
  819. 6821a433 2026-03-29 feat(cli): add .printing-press.json manifest to published CLIs (#41)
  820. c1219dec 2026-03-29 docs(cli): use brew for lefthook install instructions (#42)
  821. 2afbb8f2 2026-03-28 ci: re-trigger release-please
  822. 7d9f8c7c 2026-03-28 ci: re-trigger release-please after enabling PR creation permissions
  823. 99d2dde8 2026-03-28 chore(cli): add lefthook pre-push lint and deny --no-verify bypass (#39)
  824. cc098e67 2026-03-28 feat(cli): accept name or path in emboss command (#38)
  825. 96bc65df 2026-03-28 feat(websniff): add captured traffic test fixture generator
  826. 91e04cca 2026-03-28 feat(websniff): add auth session capture with domain binding and security hardening
  827. 7df1537a 2026-03-28 docs(cli): fix Trevin article link in credits (#36)
  828. 46a94efe 2026-03-28 docs(cli): update README install instructions for standalone binary + plugin (#35)
  829. dfc0eedc 2026-03-28 refactor(cli): decouple skills and binary from repo checkout (#32)
  830. 4f4dd9c4 2026-03-28 feat(websniff): add APISpec generator and sniff CLI command
  831. f9b8e141 2026-03-28 feat(websniff): add JSON schema inference from captured payloads
  832. 07f158f6 2026-03-28 feat(websniff): add API endpoint classifier with analytics blocklist
  833. 6c6c9cf5 2026-03-28 feat(websniff): add HAR and enriched capture parser
  834. c779648a 2026-03-28 feat(ci): automated releases, linting, and commit conventions (#34)
  835. 03a19223 2026-03-28 fix(ci): shared build cache and Go module caching to prevent test timeouts (#33)
  836. 03882623 2026-03-28 feat(templates): add flag suggestions, sync NDJSON events, and MCP response quality
  837. d9801c33 2026-03-28 fix(skill): require interactive API key consent in Phase 0
  838. 4120dfcb 2026-03-28 feat(pipeline): move mutable runs into scoped runstate (#30)
  839. 7a1c1646 2026-03-28 fix(scorecard): handle unscored auth semantics (#29)
  840. 6727b860 2026-03-28 feat(skill): add 7-principle agent build checklist and Priority 1 review gate to Phase 3
  841. 432041e2 2026-03-28 docs(readme): agents-first design, Absorb & Transcend, emboss, verify
  842. 49b98a3b 2026-03-28 feat(skill): add Phase 1.5 Ecosystem Absorb Gate - build the GOAT by stealing every best idea
  843. fe1038e4 2026-03-28 fix: resolve merge conflicts with upstream, fix RunScorecard 4th arg
  844. 25b07be0 2026-03-28 fix(skill): enforce 2-pass agent readiness reviewer loop (#28)
  845. b0d775d4 2026-03-28 docs: add Phase 4.9 Agent Readiness to README phase list (#27)
  846. 23925ce9 2026-03-28 docs: add compound engineering plugin to setup instructions
  847. 421c81bd 2026-03-28 fix(pipeline): clean generated cli artifacts
  848. 3a850fc5 2026-03-28 fix(pipeline): match short path declarations
  849. 0dca872a 2026-03-28 fix(skill): preserve codex fix delegation
  850. feef5fa5 2026-03-28 fix(skill): force agent readiness review to run in foreground
  851. cf3fcd99 2026-03-27 docs(scorecard): add scoring architecture best-practice guide and source plan
  852. bc358ef8 2026-03-27 fix(skill): add 7 improvements from Cal.com CLI run
  853. e3a07f7b 2026-03-27 fix(skill): enforce Phase 4.9 agent readiness review dispatch
  854. 6b4aea3a 2026-03-27 docs: add Cal.com CLI research and planning artifacts
  855. 49f5d8b7 2026-03-27 fix(scorecard): fix PassRate units, gate sync path-param credit, tighten empty sync detection
  856. 2ce13e77 2026-03-27 fix(pipeline): handle remote URLs and YAML-to-JSON conversion in spec copy
  857. 5ed49878 2026-03-27 docs(scorecard): document intentional workflow/insight prefix overlap
  858. 98977f23 2026-03-27 fix(score): preserve spec extension, remove hardcoded repo path
  859. 64e5ea58 2026-03-27 refactor(scorecard): extract infra maps and add workflow/insight tests
  860. dfef94f4 2026-03-27 fix(scorecard): address code review findings on accuracy changes
  861. 8ab911a7 2026-03-27 docs: mark score command plan as completed
  862. c08aedc7 2026-03-27 feat(skill): add /printing-press-score for standalone CLI scoring
  863. a00ebdb2 2026-03-27 feat(pipeline): copy spec into output dir after generation
  864. 1bebcb0a 2026-03-27 fix(scorecard): improve accuracy for non-trivial CLIs
  865. 32a4ec90 2026-03-27 docs: rename score command spec to -plan suffix
  866. 03155a6e 2026-03-27 docs: move score command spec to docs/plans
  867. bc9932e3 2026-03-27 docs: add design spec for /printing-press-score skill
  868. 0906e2cc 2026-03-27 fix(skill): use AskUserQuestion tool in Phase 5.9 emboss prompt
  869. 9d256d74 2026-03-27 docs: remove superseded design spec for Phase 4.9
  870. fe6a3634 2026-03-27 docs: update specs to reflect stable-numbered PlanPath approach
  871. 630cd0b5 2026-03-27 refactor(pipeline): use stable-numbered PlanPath instead of name-only
  872. 0d4e711c 2026-03-27 fix(cli): propagate ReadDir error in explicitOutput collision guard
  873. e2e68fb9 2026-03-27 docs: mark implementation plan as completed
  874. bc686731 2026-03-27 test(cli): add integration tests for claimOrForce behavior
  875. 51ba9996 2026-03-27 docs(cli): update --force flag description to reflect auto-increment behavior
  876. ca5c11fd 2026-03-27 fix(cli): capture explicitOutput before default assignment
  877. 3a9e977b 2026-03-27 fix(pipeline): backfill PlanStatus in migration and persist state
  878. da9500e4 2026-03-27 refactor(cli): use ClaimOutputDir for atomic output directory claiming
  879. 0fd4cba6 2026-03-27 test(pipeline): add concurrency test for ClaimOutputDir
  880. 93b8b4cc 2026-03-27 feat(pipeline): add ClaimOutputDir for atomic directory claiming
  881. 5a6c8095 2026-03-27 feat(skill): add Phase 4.9 agent readiness review loop to SKILL.md
  882. bdc9a90f 2026-03-27 feat(pipeline): add PhaseAgentReadiness and plugin dependency
  883. e49ec256 2026-03-27 docs: add implementation plan for Phase 4.9 agent readiness review loop
  884. 914755d6 2026-03-27 docs: address review findings for Phase 4.9 requirements doc
  885. 298b4959 2026-03-27 docs: address document review findings for Phase 4.9 spec
  886. 574c434f 2026-03-27 docs: add Phase 4.9 agent-readiness review loop design spec
  887. fa6b172e 2026-03-27 docs: update README for v2 overhaul - three benchmarks, table stakes, api-pp-cli naming
  888. 854ff601 2026-03-27 feat(skill): v2 overhaul - 14 changes from Notion + Linear post-mortems
  889. 01a3c1c7 2026-03-27 docs: rename plan file from shelf to library
  890. 96c28ea4 2026-03-27 refactor(generator): rename shelf/ to library/ for generated CLI output
  891. cf381bbb 2026-03-27 fix(review): extract DefaultOutputDir helper, update main skill and docs
  892. 34e646c2 2026-03-27 feat(generator): route generated CLI output to shelf/ directory
  893. 430d6095 2026-03-27 docs(onboarding): clarify that /printing-press skill is the primary entry point
  894. 66abf782 2026-03-27 fix(skill): Phase 0.1 must WAIT for API key answer before proceeding
  895. 75c37eb6 2026-03-27 feat(emboss): complete baseline persistence, delta computation, and full-mode UX
  896. efbf4b88 2026-03-27 feat(emboss): add second-pass improvement command for generated CLIs
  897. b5e6f02d 2026-03-27 fix(plugin): remove invalid skills field from plugin.json
  898. 28036ae7 2026-03-27 docs(readme): simplify install to just /install-skill
  899. 445bf957 2026-03-27 docs: add research plans from GitHub CLI run + quality overhaul + API candidates
  900. ebe45d51 2026-03-27 fix(marketplace): align marketplace.json with Claude Code schema
  901. ad4812f3 2026-03-27 feat(skill): add product thesis, market research, naming pass, runtime verify phase
  902. 9c4349a3 2026-03-27 fix(parser): check OpenAPI before GraphQL to prevent false positives
  903. 4f93e79f 2026-03-27 feat(verify): add runtime verification command with mock server + fix loop
  904. dbd5b3a2 2026-03-27 docs(readme): add install link, fix star count, remove self-credit
  905. d91566f9 2026-03-27 feat(templates): add structured confirmation envelope for mutating commands
  906. c3eacf94 2026-03-27 feat(dogfood): add ExampleCheck to validate help example correctness
  907. b86384b1 2026-03-27 docs: add testing guidance to AGENTS.md
  908. 538e65c4 2026-03-27 feat(cli): differentiate exit codes by failure type
  909. b494c3b8 2026-03-27 feat(cli): add --dry-run flag to generate command
  910. 7f5c3520 2026-03-27 feat(cli): add --json flag to generate, print, and vision commands
  911. 862dfa70 2026-03-27 fix(generate): reject non-empty output directory without --force
  912. df0474e8 2026-03-27 docs: split CLAUDE.md into AGENTS.md for Codex compatibility
  913. f6f63599 2026-03-27 docs: prevent concurrent worktree build collisions
  914. 633eefc3 2026-03-27 feat(cli): add Example fields to all Cobra commands
  915. d174491e 2026-03-27 docs: add ONBOARDING.md for new contributor orientation
  916. 50ecc63a 2026-03-27 fix(skill): Phase 0.1 auto-detects API tokens before asking
  917. 4d2a87bf 2026-03-27 docs: rewrite lead narrative - Every Endpoint. Every Insight. One Command.
  918. 771d3793 2026-03-27 docs: fix README narrative - 323 AND 11, not vs
  919. c123304c 2026-03-27 chore: gitignore go-build cache and binary
  920. ce96c0c3 2026-03-27 chore: remove all stale generated CLIs
  921. 2974f412 2026-03-27 docs: update README with MCP generation, codex mode, proof of behavior, live testing
  922. ff9f5e61 2026-03-27 feat(skill): add opt-in Codex delegation mode for token savings
  923. 0606df64 2026-03-27 fix(pipeline): 5.5 live test failures auto-trigger fix loop
  924. 06b9270a 2026-03-27 feat(pipeline): ship loop, live API testing, rename Steinberger scoring
  925. 6a80b5af 2026-03-26 feat(generator): generate MCP server alongside CLI from OpenAPI spec
  926. 8e926036 2026-03-26 feat(templates): discrawl-inspired sync performance upgrades
  927. efaec84b 2026-03-26 feat(pipeline): add Proof-of-Behavior verification phase
  928. 345b0753 2026-03-26 docs: update README with v2 overhaul, agent-first features, credits
  929. 300c01bd 2026-03-26 feat(templates): auto-JSON piping, --no-input, --compact (Ramp CLI learnings)
  930. 64c58d86 2026-03-26 feat(templates): agent-friendly error messages, truncation hints, wired flags
  931. 8c92c19d 2026-03-26 feat(graphql): add GraphQL SDL parser for CLI generation
  932. 82bae3ee 2026-03-26 feat(dogfood): add mechanical CLI validation command
  933. 7bcacea3 2026-03-26 feat(skill): add Phase 4.6 hallucination audit and anti-gaming rules
  934. 0063ee76 2026-03-26 fix(generator): auth format, module path, and example values
  935. eb59816b 2026-03-26 feat(generator): wire BuildSchema to store/sync/search templates
  936. bba34c42 2026-03-26 feat(scorecard): add Tier 2 domain correctness dimensions
  937. 86c5d908 2026-03-26 feat(generator): Apache 2.0 license on generated CLIs with NOTICE attribution
  938. 307e67c9 2026-03-26 docs: rewrite README with NOI as hero, discrawl story, gogcli/last30days narrative
  939. b52da339 2026-03-26 docs: add agent-native thesis with research-backed token economics to README
  940. 0c1316fb 2026-03-26 docs: update README with Creative Vision Engine, NOI system, and domain archetypes
  941. 63b89f6d 2026-03-26 feat(generator): add schema builder with data gravity scoring and insight scorecard dimension
  942. f55405b8 2026-03-26 feat(generator): add PM workflow and behavioral insight templates
  943. f5369dd0 2026-03-26 feat(generator): add Non-Obvious Insight system, domain archetype detection, and entity mapping
  944. 31a8bed4 2026-03-26 docs: comprehensive README rewrite for 8-phase pipeline
  945. b1651b50 2026-03-26 fix(press): dynamic API type detection, registry is hint not gate
  946. 9e8cc5d5 2026-03-26 feat(press): support GraphQL APIs - warn but proceed, don't block
  947. ced6cefc 2026-03-26 feat(press): expand Phase 4.5 with report-fix-retest cycle
  948. 7b5ce383 2026-03-26 feat(press): add Phase 4.5 Dogfood Emulation - spec-derived API testing
  949. 6775a862 2026-03-26 feat(press): add Phase 0.7 prediction engine, Discord CLI, 6-artifact pipeline
  950. 13860ec0 2026-03-25 feat(press): v2 - depth over breadth, creativity over mechanical
  951. d51d1e89 2026-03-25 feat(generator): add compound workflow template with archive and status
  952. bbd0a47c 2026-03-25 feat(store): generate per-resource SQLite tables from profiler output
  953. 611f4b67 2026-03-25 feat(llmpolish): add LLM Vision Synthesis for domain-aware customization
  954. a783ac12 2026-03-25 fix(profiler): improve HighVolume and NeedsSearch heuristics
  955. de296d1f 2026-03-25 feat(scorecard): implement two-tier Vision scoring
  956. bba88f65 2026-03-25 feat(generator): wire vision templates into Generate()
  957. f499c4b5 2026-03-25 feat(profiler): add API Shape Intelligence Engine
  958. 5c6840d5 2026-03-25 fix(scorecard): replace presence checks with quality-based scoring
  959. e25a1b45 2026-03-25 feat(vision): add Phase 0 Visionary Research - the press thinks before it prints
  960. bb0acf37 2026-03-25 feat(skill): v1.1.0 dual Steinberger analysis, deep research, complex body fields
  961. 44daea3a 2026-03-25 fix(skill): enforce 5-phase loop with inlined research and phase gates v1.0.0
  962. 68f63167 2026-03-25 feat(skill): restore plan-execute-plan-execute loop - the press is smart again
  963. 4ee08952 2026-03-25 fix(skill): always research, polish, and score - never skip the brain
  964. 6e934000 2026-03-25 refactor(skill): Claude Code IS the brain, not the Go binary
  965. 95e26838 2026-03-25 feat(scorecard): add breadth dimension + fix LLM runner + integration tests
  966. c266b6fb 2026-03-25 feat(templates): add --human-friendly flag and NDJSON pagination events
  967. b8c762c6 2026-03-25 docs: rewrite README to reflect what the press actually does now
  968. a1e7af4e 2026-03-25 feat(llm): add LLM brain before generation - the press understands before it builds
  969. 76d082f5 2026-03-25 feat(llmpolish): add LLM polish pass - the press is now smart, not just fast
  970. b862cf4c 2026-03-25 feat(templates): agent-native CLI improvements - stdin, idempotency, --yes, examples
  971. 3b4f89db 2026-03-25 fix(templates): improve doctor health checks and add HTTP response cache
  972. 99de67ec 2026-03-25 feat(pipeline): full press run with MakeBestCLI, scorecard fixes, and comparison table
  973. 731b0ce7 2026-03-25 feat(pipeline): press intelligence engine - dynamic plans, competitor intel, doc-to-spec, scorecard
  974. ffb7a7e6 2026-03-25 feat(parser): add lenient mode + comprehensive test suite from overnight learnings
  975. 5e0f4714 2026-03-25 docs: overnight hardening results - 10/10 gauntlet, 30 tests, 2 new CLIs
  976. 451b7cb7 2026-03-25 feat(catalog): generate Pipedrive CLI from official OpenAPI spec
  977. 66bc4ea8 2026-03-25 feat(catalog): generate Plaid CLI from official OpenAPI spec
  978. 02d022fe 2026-03-25 test: add coverage for research, dogfood, comparative, textfilter, readme_augment
  979. 2370b45b 2026-03-24 fix(templates): guard readme.md.tmpl against empty Auth.EnvVars
  980. 780c6b51 2026-03-24 feat(templates): add --select flag, error hints, README rewrite, and Owner variable
  981. 1f5871bd 2026-03-24 feat(pipeline): add comparative analysis scoring and GoReleaser brews section
  982. bc5c5db8 2026-03-24 feat(pipeline): add dogfood automation, anti-AI text filter, and README augmentation
  983. 466715fb 2026-03-24 feat(pipeline): add Research and Comparative phases with catalog extensions
  984. 0b892938 2026-03-24 feat(linear): generate Linear CLI with 12 resources and 45 commands
  985. 10640caf 2026-03-24 docs: update gauntlet findings to 10/10 pass rate
  986. 1eda222a 2026-03-24 fix(generator): harden toCamel, flagName, defaultVal and dedup body params
  987. 651d11e1 2026-03-24 fix(generator): doctor tries health endpoints before reporting status
  988. 5b3d281e 2026-03-24 feat(generator): add CRUD aliases to generated CLI commands
  989. 96f0d513 2026-03-24 feat(cli): add --force flag to generate command
  990. 7ca3e75b 2026-03-24 refactor(pipeline): rewrite seed templates as thin ce:plan prompts
  991. 37008dd9 2026-03-24 feat(skill): update Workflow 4 to check plan_status for seed vs expanded
  992. 1f360464 2026-03-24 refactor(pipeline): use MarkSeedWritten in Init instead of MarkPlanned
  993. fa2459dd 2026-03-24 feat(pipeline): add plan_status field to PhaseState for seed expansion tracking
  994. 15f3d250 2026-03-24 docs(plans): template sanitization round 2 + pipeline E2E plan
  995. d8a93e0a 2026-03-24 fix(generator): harden toCamel, flagName, types template for special chars in schema names
  996. 2501e565 2026-03-24 docs(plans): update gauntlet findings after parser fixes - 4/10 pass (was 3/10)
  997. 3f096bce 2026-03-24 fix(parser): sanitize schema names, cap title length, handle missing servers, resolve URL templates
  998. 0f1beba2 2026-03-24 feat(catalog): add telegram, launchdarkly, sentry from dogfood gauntlet
  999. d81e961a 2026-03-24 feat(pipeline): add 10 new APIs to known specs registry for dogfood gauntlet
  1000. aae78017 2026-03-24 feat(pipeline): add autonomous dogfood phase with 3-tier test system
  1001. 59ae5340 2026-03-24 docs: rewrite README with full feature coverage and Steinberger-inspired tone
  1002. ea086759 2026-03-24 docs(plans): mark pipeline chaining and E2E petstore plans as completed
  1003. 9734d0c1 2026-03-24 feat(skill): add autonomous pipeline workflows with nightnight-style chaining
  1004. 01f44396 2026-03-24 docs(plans): nightnight chaining plan + E2E test plan for pipeline
  1005. 6be0e67f 2026-03-24 Revert "feat(skill): add autonomous pipeline workflow with nightnight-style chaining"
  1006. eab64edd 2026-03-24 feat(skill): add autonomous pipeline workflow with nightnight-style chaining
  1007. cd1cea5a 2026-03-24 docs(plans): update pipeline plan with plan-first architecture
  1008. 6a76cb26 2026-03-24 feat(cli): add 'printing-press print' command with plan-per-phase pipeline
  1009. 5d456c67 2026-03-24 feat(pipeline): spec discovery registry and overlay merge types
  1010. e2560ea7 2026-03-24 feat(pipeline): add pipeline state manager with phase tracking
  1011. 9cfae3e4 2026-03-24 docs(plans): autonomous CLI pipeline plan and status updates
  1012. bb12a605 2026-03-24 feat(cli): multi-spec composition with --spec repetition
  1013. dacda31f 2026-03-24 feat(generator): OAuth2 auth flow for generated CLIs
  1014. 2e70bc46 2026-03-23 feat(cli): accept URLs for --spec with local caching
  1015. 3cb6e869 2026-03-23 feat(generator): add color and TTY detection to generated CLIs
  1016. babd0c66 2026-03-23 fix(openapi): filter global query params that appear on >80% of endpoints
  1017. 08dc4eef 2026-03-23 fix(openapi): deep sub-resource detection with common prefix collapse
  1018. 332fe595 2026-03-23 feat(generator): auto-detect pagination and generate --limit/--all flags
  1019. 086f1d45 2026-03-23 feat(generator): retry logic, structured exit codes, and dry-run support
  1020. c5618c08 2026-03-23 feat(generator): auto-detect array responses and render as formatted tables
  1021. e993ba6e 2026-03-23 feat(generator): auto-generate usage examples in command help
  1022. 33d06483 2026-03-23 fix(openapi): handle nullable types in OpenAPI 3.1 specs
  1023. 2915ae3e 2026-03-23 fix(generator): auth mapping for Discord BotToken scheme
  1024. 3d07636b 2026-03-23 feat(generator): sub-resource grouping for nested API paths
  1025. 54e55a66 2026-03-23 fix(generator): dogfood to Steinberger quality across Petstore, Stytch, Discord
  1026. ceacb135 2026-03-23 docs: final dogfood plan - fix press until Steinberger quality
  1027. 21a7c6aa 2026-03-23 docs: add dogfood quality plan
  1028. 399c9678 2026-03-23 fix(generator): 6 dogfooding fixes for production-quality CLI output
  1029. c8942bc3 2026-03-23 docs: add Steinberger parity plan
  1030. 84823431 2026-03-23 fix(openapi): smart operationId cleaning for clean command names
  1031. 588c694e 2026-03-23 fix(generator): add PATCH support + skip unexported fields in types
  1032. d3393f88 2026-03-23 docs: add Phase 4 plan
  1033. 16b39bf2 2026-03-23 docs: add README and CLAUDE.md
  1034. 97ff74ff 2026-03-23 ci: add catalog validation pipeline for PRs
  1035. 45045b92 2026-03-23 feat(skill): add /printing-press submit workflow for catalog contributions
  1036. 3ff4500f 2026-03-23 feat(skill): add /printing-press-catalog for browsing and installing CLIs
  1037. cd4824a9 2026-03-23 feat(catalog): add catalog schema validator with tests
  1038. 96649272 2026-03-23 feat(catalog): add 12 official catalog entries for popular APIs
  1039. 07d0564a 2026-03-23 feat(plugin): add Claude Code plugin manifest
  1040. f369ea6d 2026-03-23 docs: mark Phase 3 plan as completed
  1041. 9f3fdc3f 2026-03-23 docs: add Phase 3 plan (natural language skill)
  1042. 412c2fe6 2026-03-23 feat(skill): add /printing-press Claude Code skill
  1043. c547fa57 2026-03-23 docs(skill): add known-specs registry and spec-format reference
  1044. 4934eb50 2026-03-23 fix(openapi): Swagger 2.0 detection + resource name sanitization
  1045. 6011234c 2026-03-23 feat(openapi): integration tests + oneline template fix for multiline descriptions
  1046. 60009103 2026-03-23 feat(cli): auto-detect OpenAPI vs internal spec format
  1047. e81fc872 2026-03-23 feat(openapi): add OpenAPI 3.0+ parser with kin-openapi
  1048. 4e3888ab 2026-03-23 feat(spec): extend internal format for OpenAPI + add real OpenAPI test fixtures
  1049. 87526922 2026-03-23 docs: add plan files to repo
  1050. 4b510ed7 2026-03-23 feat(validate): quality gates + Clerk/Loops test specs + integration tests
  1051. a78f0979 2026-03-23 feat(templates): Go templates for all generated CLI files
  1052. b4ab56ba 2026-03-23 feat(spec): YAML spec parser with validation and Stytch test fixture
  1053. 454739bd 2026-03-23 feat(scaffold): initial project structure with CLI skeleton

Authors

Agents used

  • none detected

Skills used

  • /printing-press89
  • /cli82
  • /plans69
  • /printing-press-library54
  • /pipeline50
  • /generator50
  • /golden46
  • /simplify38
  • /spec29
  • /graphql29
  • /client26
  • /library22
  • /templates22
  • /claude22
  • /main18
  • /cli-printing-press18
  • /json17
  • /cmd16
  • /solutions16
  • /mvanhorn16
  • /search16
  • /internal15
  • /sync15
  • /config14
  • /printing-press-polish14
  • /claude-code14
  • /mcp13
  • /code13
  • /sql13
  • /composed12

Creative ideas + design notes

Commits with substantial prose (≥120 chars) — the rationale behind each move.

aecf495a · 2026-05-19 · fix(cli): harden manifest-gen remote spec loader against hangs and silent truncation (#1699)
* fix(cli): harden manifest-gen remote spec loader against hangs and silent truncation

loadSpec in cmd/manifest-gen had two defects when fetching remote specs:

1. No timeout on the HTTP request. http.Get with the default client has no
   overall request timeout, so a remote host that flushes headers and then
   blocks on the body would hang manifest-gen indefinitely.

2. Silent truncation. io.LimitReader(body, 50MiB) followed by io.ReadAll
   returned the first 50 MiB of any oversized response with no error, so the
   caller could not tell a real 49 MiB spec from a multi-gigabyte stream
   truncated mid-document.

Fix: route the request through http.NewRequestWithContext with a 60s timeout,
and read limit+1 bytes so we can return an explicit "spec exceeds N bytes"
error when the response is over the limit. The 50 MiB cap is preserved.

Adds main_test.go covering happy path, local file, non-200, stalled server
(with a short timeout override so the test runs in well under a second),
oversized response, and exactly-at-limit response.

* fix(cli): eliminate data race in manifest-gen loadSpec tests

The previous test helpers `withTimeout` / `withMaxBytes` mutated the
package-level `remoteSpecTimeout` and `maxRemoteSpecBytes` vars while
the `httptest.Server` handler goroutine read those same vars to size
its response. There was no happens-before relationship between the
test-goroutine write and the handler-goroutine read, so `go test
-race ./cmd/manifest-gen/...` could flag a data race.

Refactor `loadSpec` to take its byte limit and timeout as explicit
parameters. The single production caller in `main()` passes
`maxRemoteSpecBytes` and `remoteSpecTimeout` directly; tests pass
their own local values. No package-level state is mutated, so the
handler closures close over local vars and the race is gone by
construction.

Restore the package-level identifiers to `const` since tests no
longer override them. Production behavior is unchanged (same 50 MiB
limit, same 60s timeout).
9eff1e20 · 2026-05-19 · fix(cli): resolve shipcheck CLI binary name from .printing-press.json (#1700)
* fix(cli): resolve shipcheck CLI binary name from .printing-press.json

shipcheckCLIPath and shipcheckCLIPathForGOOS derived the binary name from
filepath.Base(o.dir), which is wrong for slug-keyed library dirs. For
~/printing-press/library/notion, basename is "notion" but the binary is
"notion-pp-cli", so validate-narrative was invoked with a binary path
that does not exist on disk.

Resolve the binary name from .printing-press.json's cli_name via
pipeline.ReadCLIBinaryName, and fall back to filepath.Base(dir) when the
manifest is absent or unparseable (preserves legacy behavior).

Clawpatch finding: fnd_sig-feat-cli-command-e17f734225-_8ca7979519

* test(cli): cover unparseable-manifest fallback in shipcheckBinaryName

Adds TestShipcheckCLIPath_FallsBackOnUnparseableManifest to pin the
parse-error branch of pipeline.ReadCLIBinaryName: when
.printing-press.json exists but is malformed JSON, the binary name
must fall back to filepath.Base(dir) rather than propagate the parse
error or yield an empty name.

Greptile P2 on #1700 — the godoc promised the fallback for the
"absent or unparseable" case but only the absent path was tested.
b534884f · 2026-05-19 · feat(cli): GraphQL credential probe in doctor + actionable copy (#1701)
* feat(cli): verify GraphQL credentials in doctor + actionable unverified copy

The doctor Credentials check emitted `WARN Credentials: present (not
verified — set auth.verify_path in spec ...)`. Two problems: the operator
running the CLI doesn't own the spec, and there was no next step. GraphQL
APIs (Linear, GitHub, Shopify) also couldn't declare a probe at all since
there's no REST verify endpoint to point at.

- Add `auth.verify_query` spec field. When set, doctor POSTs
  `{"query": "<value>"}` to base_url and treats HTTP 2xx + no top-level
  `errors` as verified, 401/403 as rejected. Routed through
  PostQueryWithParamsAndHeaders so verify-mode doesn't suppress the read.
  VerifyPath wins when both are set (REST probe is cheaper).
- Replace the unverified-state copy with a runnable suggestion resolved at
  doctor-time: walk the cobra tree for the first endpoint-mirror leaf with a
  list/get verb and no positional args. Gated on the pp:endpoint annotation
  so it never suggests local-read framework commands, and recurses through
  Hidden resource parents (whose endpoint leaves stay runnable).
- Downgrade the unverified state WARN -> INFO; "we didn't check" is not a
  warning and shouldn't render yellow in CI dashboards.

Additive: behavior for CLIs that already set auth.verify_path is unchanged.

* fix(cli): split 403 from 401 in doctor GraphQL credential probe

The GraphQL probe collapsed HTTP 401 and 403 into "invalid — check your
credentials". 403 means a valid-but-scope-limited token, so that copy told
operators to replace a working token when they only needed to add scopes.
Mirror the REST probe's split: 401 -> invalid, 403 -> scope-limited.
5261ae73 · 2026-05-19 · fix(cli): return failure exit from verify json (#1693)
* fix(cli): return failure exit from verify json

* fix(cli): preserve verify text failure exit

* test(cli): assert verify json failure exit

* fix(cli): silence verify json failures at root
d8178077 · 2026-05-20 · fix(cli): handle binary-only response endpoints (Accept + base64 envelope) (#1574)
* fix(cli): handle binary-only response endpoints (Accept + base64 envelope)

Generated CLIs hardcoded `Accept: application/json` in the HTTP client
when no per-endpoint override was set, and ran every response through
the JSON sanitizer before returning it as `json.RawMessage`. Endpoints
whose only 2xx content type is non-JSON (e.g. `application/octet-stream`
PDF/file downloads) were therefore rejected by the server with HTTP 406,
and even with the right Accept the bytes would be mangled by the
sanitizer. This is a generic generator gap: it hits any spec with a
binary-only success response.

Fix, using existing plumbing with minimal surface:

- openapi parser: detect success responses whose media types are all
  non-JSON / non-`*/*` / non-`+json` and pin `Accept` to that type via
  the existing per-endpoint header-override path. New `upsertHeaderOverride`
  (and a merge in `applyHeaderOverrides`) keeps the Accept override stable
  when configured per-endpoint headers also apply. JSON and `*/*`
  endpoints are untouched.
- client.go.tmpl: content-type-gated base64 envelope
  (`{"_pp_binary":true,...,"data":"<b64>"}`) for genuinely binary
  success bodies so they survive the json.RawMessage contract. JSON,
  `*/*`, XML and every text/* type (incl. text/html, so
  response_format:html CLIs are unaffected) pass through unchanged. The
  error path is byte-identical (still sanitized + truncated).
- command_promoted.go.tmpl: promoted (top-level) GET commands now pass
  per-endpoint header overrides, matching typed commands. Without this
  the Accept override never reached the client for promoted commands.

Golden: extended testdata/golden/fixtures/golden-api.yaml with one
binary-only endpoint per docs/GOLDEN.md (general machine behavior),
froze its generated command file, and regenerated affected expected
fixtures. All 17 golden cases pass; every diff is attributable to the
envelope path or the one added endpoint.

Verification: go build ./..., go vet ./... (changed pkgs), go test ./...
(0 failures), 5 new parser tests, scripts/golden.sh verify (17/17).
Live-verified against a real binary endpoint: `Accept: application/json`
reproduces HTTP 406; `Accept: application/octet-stream` returns the
file (200, correct content-type).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cli): thread HeaderOverrides through MCP code-orchestration execute

The original binary-response fix covered typed CLI commands and promoted
commands, but the code-orchestration MCP path (<api>_execute) builds
requests from a slim endpoint table and called c.Get/Post/... directly,
so the per-endpoint Accept override never reached binary-only endpoints
— <api>_execute on a PDF/octet-stream endpoint still 406'd while the CLI
worked.

Add HeaderOverrides to codeOrchEndpoint, emit it in the generated
registry from endpoint.HeaderOverrides, and dispatch through
c.*WithHeaders when present. The client's content-type-gated base64
envelope (already in this branch) then handles the binary body.

Golden: generate-mcp-api/code_orch.go updated (struct field + WithHeaders
dispatch; table emission inert when no endpoint has overrides).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cli): thread header overrides through typed MCP tools

* fix(cli): avoid text response Accept overrides

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Trevin Chow <trevin@trevinchow.com>
1a243810 · 2026-05-19 · feat(cli): add Quo (formerly OpenPhone) catalog entry and OpenAPI spec (#1597)
Add catalog/quo.yaml plus an in-repo OpenAPI spec for Quo (formerly
OpenPhone), so the Printing Press can generate a printed CLI for the
Quo business-phone API.

Spec covers 18 operations across 14 paths in 6 resource groups:
contacts, conversations, phone-numbers, users, messages, calls. Auth
is via a plain API key in the Authorization header (non-Bearer),
captured in the spec's securitySchemes block.

Provenance:
- tier: community. Quo does not publish a vendor OpenAPI document,
  so this spec is community-curated from their public docs. Matches
  the kayak / plaid / telegram / sentry pattern.
- info.x-spec-provenance records source: official-docs, the docs URL,
  and a confirmed_quirks list. Every path is derived from the
  official Quo API reference and cross-verified by live testing
  against api.openphone.com/v1. No endpoint relies on MCP tool
  schemas or undocumented probing as its sole source of truth.

Quo API quirks captured in x-spec-provenance.confirmed_quirks and
inline schema descriptions:
- POST /messages: 'to' is an array of E.164 strings on both the
  request body and the Message response schema. The API rejects a
  bare string and returns 'to' as an array even for single-recipient
  messages.
- POST /messages: the request body uses 'content' for the message
  text while the Message response returns the same text under 'body'.
  Real Quo API naming asymmetry, not a curator typo.

POST /messages requestBody wraps the schema in oneOf so the parser
emits a --body-json fallback (and a body_json MCP input) instead of
per-field typed flags. The generator's typed body path serializes
array fields as JSON-strings, which the Quo API rejects; the
--body-json surface lets agents and humans send the array verbatim
("to": ["+155..."]) without round-tripping through a string.
Verified by regenerating and reading
internal/cli/messages_send.go + internal/mcp/tools.go.

testdata/golden/expected/catalog-list/stdout.txt: insert the new Quo
row in social-and-messaging (alphabetical between front and telegram).

No generator code, template, scorer, MCP, or pipeline code changes.

Verification:
- go build -o ./printing-press ./cmd/printing-press
- go test ./... (all packages pass)
- go fmt ./... (no Go files touched)
- go vet ./... (clean)
- scripts/golden.sh verify (20/20 cases pass)
- ./printing-press catalog show quo renders the new tier, provenance,
  and notes
- ./printing-press catalog list places Quo in
  social-and-messaging between front and telegram
- ./printing-press generate --spec catalog/specs/quo-spec.yaml emits
  the expected --body-json fallback warning for POST /messages and
  produces a buildable printed CLI that PASSes go mod tidy,
  govulncheck, go vet, go build, --help, version, and doctor.

Closes #782 (superseded by #1597).

Co-authored-by: ninjaforhire <andrew@mightyphotobooths.com>
015478bf · 2026-05-19 · feat(cli): detect Auth0 SPA in-memory auth + emit CDP extractor (#1645)
* feat(cli): detect Auth0 SPA in-memory auth at sniff time and emit CDP extractor

Some sites (Auth0 SPA SDK v2+ with cacheLocation: memory) keep the access
token in JS heap and never write it to cookies or localStorage. The
cookie-jar extractor in auth login --chrome has no path to those tokens —
DevTools paste was the only way to land them in config until WU-3a (#1641)
added auth set-token.

This change closes the automation gap. Sniff-time detection looks for
/oauth/token responses that carry access_token in the body without a
JWT-shaped Set-Cookie on the same response, and annotates the spec with
auth.subtype: auth0_spa_in_memory. The generator routes that subtype to
auth_browser.go.tmpl, which emits an --auth0-spa flag on auth login --chrome.
The CDP path attaches to a running Chrome at --debug-port, installs a
Fetch.enable interceptor via chromedp, and captures the next outbound
Authorization: Bearer JWT — validated via cliutil.LooksLikeJWT before
SaveTokens.

Side-effect-command floor applies: the CDP path short-circuits when
cliutil.IsVerifyEnv() or cliutil.IsDogfoodEnv() is set, so the verifier
matrix and dogfood --live runs never attempt a real Chrome attach.

Refs #1598 (WU-3b).

* fix(cli): reset auth0 spa token expiry

---------

Co-authored-by: Cathryn Lavery <cathryn@bestself.co>
75e4d1b9 · 2026-05-19 · fix(cli): verify-mode HTTP-verb short-circuit + N1 envelope + doctor + read-only POST bypass (#1398)
Closes plan 2026-05-13-001 (U1-U10), the N1 envelope follow-up surfaced in the petstore agent-readiness review, and the greptile P1 read-only-POST finding.

- **Transport-layer gate** (`client.do()`): mutating verbs (DELETE/POST/PUT/PATCH) under `PRINTING_PRESS_VERIFY=1` short-circuit with a synthetic `{"__pp_verify_synthetic__":true,"status":"noop","reason":"verify_short_circuit",...}` envelope. `PRINTING_PRESS_VERIFY_LIVE_HTTP=1` opts back into the real wire for the verify pipeline's mock-mode subprocesses.
- **Read-only POST bypass** (greptile P1): `client.do()` is now a thin wrapper around `doInternal(..., readOnlyIntent bool)`; a new `doRead()` passes `readOnlyIntent=true`. New `PostQueryWithParams` / `PostQueryWithParamsAndHeaders` route through `doRead`. The endpoint template emits `PostQuery*` for `.IsReadOnly` POST commands so GraphQL queries, JSON-RPC reads, and POST-based search dial through the real transport even under verify mode.
- **N1 envelope propagation**: outer command envelope reports `verify_noop: true` and `success: false` when the synthetic sentinel is detected. Naive validators no longer read the noop as a real mutation.
- **Doctor diagnosis line** (U9): `<cli> doctor` surfaces verify state ("normal operation" / "ACTIVE — short-circuit" / "ACTIVE — live HTTP opt-in") so an operator inheriting `PRINTING_PRESS_VERIFY=1` detects the foot-gun without inspecting a response body.
- **Live-verifier env strip** (U10): `live_dogfood` and `workflow_verify` strip both verify env vars from subprocess env via `filterVerifyEnv` so they cannot inherit verify-mode short-circuiting.
- **Per-CLI emitted test** (U5): every regenerated CLI ships `internal/client/client_verify_short_circuit_test.go` covering all four gate states (mutating + verify, LIVE_HTTP opt-in, no env, GET control) plus a `_ReadOnlyPOST` sub-test asserting `doRead` dials through. A template edit that drops the gate fails downstream `go test` rather than silently re-opening the readiness gap.
- **Docs** (U6): AGENTS.md "Side-effect commands" section + `cliutil_verifyenv.go.tmpl` docstring document the transport-layer gate, the LIVE_HTTP opt-in, the `doRead` read-only bypass, the live-verifier strip, and the doctor diagnosis anchor.
- **Regen-merge fixture** (U7): pins `TEMPLATED-WITH-ADDITIONS` classification for the canonical scenario where an operator has hand-added a top-level helper to `client.go` and the fresh template introduces the short-circuit.
- **Rollout playbook** (U8): `docs/solutions/best-practices/verify-mode-short-circuit-rollout-2026-05-13.md` covers the tier:official-first sweep order and known foot-guns.

Verified live on the petstore smoke pipeline: `PRINTING_PRESS_VERIFY=1 petstore-pp-cli pet delete 42 --json` returns the synthetic envelope with no network call.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
019dcf3b · 2026-05-19 · chore(ci): enable parallel queue checks in Mergify (#1668)
* chore(ci): enable parallel queue checks in Mergify

Raise `merge_queue.max_parallel_checks` from 1 to 3 and split
`queue_conditions` / `merge_conditions` so Mergify can speculate on
multiple queued PRs in parallel via `mergify/merge-queue/*` draft PRs.

The prior config pinned both `batch_size` and `max_parallel_checks` to
1 under the belief that both were paywalled features on the OSS plan.
Mergify support clarified (2026-05-19) that only `batch_size > 1`
triggers the paid "Merge Queue Batch" feature; `max_parallel_checks`
is a separate, free knob. `batch_size` stays at 1.

Greptile compatibility, which was the secondary reason for the old
pinning, is handled by the new split:

- `queue_conditions` (gates entry on the source PR) keeps the Greptile
  + `#review-threads-unresolved = 0` requirements.
- `merge_conditions` (gates the merge after the speculative draft PR's
  CI passes) requires only the CI checks that actually run on bot-owned
  branches. Greptile silent-skips bot branches by design, so requiring
  it here would block every queued PR.
- `merge_protections` continues to re-enforce Greptile + review-threads
  on the source PR before the GitHub merge, as belt-and-suspenders.

* docs(ci): capture mergify parallel-checks learning under docs/solutions/

Add a knowledge-track learning doc that explains the corrected mental
model for Mergify on the OSS plan: `batch_size > 1` is paywalled (the
"Merge Queue Batch" feature), `max_parallel_checks > 1` is not, and
the three-block (queue_conditions / merge_conditions / merge_protections)
pattern is what makes draft_pr mode safe alongside Greptile, which
silent-skips bot branches by design.

Cross-references the wrong-turn history (#1306 raise, #1321 revert,
#1336 single-block narrowing) and the present fix (#1668) so the doc
is useful both as forward guidance and as context for why the prior
config was conservative.

* fix(ci): drop pr-title from mergify merge_conditions

Greptile flagged this as a P1 on PR #1668: `.github/workflows/pr-title.yml`
skips semantic validation only for titles starting with `merge queue:`
(the batch-mode prefix from #1306). In `draft_pr` mode with `batch_size: 1`,
Mergify's draft PR title format is not guaranteed to match that prefix,
so requiring `check-success = pr-title` on the draft could stall every
queued PR.

The source PR's title is already validated at `queue_conditions` entry
and cannot change while queued, so re-checking it on the speculative
draft is redundant. Drop it from `merge_conditions` and document the
trap in the comment block so the next person editing this config sees
why the omission is intentional.

Also update the learning doc with this as a third non-obvious failure
mode under "Why This Matters".
81f07e53 · 2026-05-19 · feat(skills): check public library for existing CLI before generating (#1650)
* feat(skills): check public library for existing CLI before generating

Catches the case where a user kicks off /printing-press for a CLI that
already exists in the public library before Phase 1 research burns
30-60 minutes. The new gate sits in Phase 0 alongside the local-library
check (mutually exclusive, never double-prompts) and reads
mvanhorn/printing-press-library/registry.json via gh api.

Matching is agent-driven over the registry, not string-match, so
semantic input like "Hacker News reader" finds hackernews, "Cal.com"
finds cal-com, and "prediction market" surfaces kalshi. High-confidence
hits route the user to /printing-press-reprint; medium-confidence hits
present alternatives; low confidence is skipped silently to keep the
gate from becoming a dismiss-me prompt. Fails open on network errors.

* Address PR review feedback (#1650)

- Multi-High match now has its own prompt with correct framing
  (same product under different names, not "similar/may overlap")
  and explicit cap-at-2 with truncation guidance for 3+ candidates
- Tempfile cleanup guarded with [ -n "$REGISTRY" ] && rm -f
  so the trailing cleanup doesn't run rm -f "" when the fetch
  branch already cleaned up and emptied $REGISTRY

* Address PR review feedback (#1650)

- Specify Combo CLIs prompt concretely with template, cap rule, and
  confidence tagging. Cap displayed reprint options at 2 across all
  sources combined to stay under the AskUserQuestion 4-option limit;
  ordering rule (High over Medium > primary over secondary > canonical
  slug); truncation note for >2 matches. Continue-with-combo becomes
  the recommended default since combo CLIs are usually informational.

* fix(skills): make combo library check reachable

---------

Co-authored-by: Cathryn Lavery <cathryn@bestself.co>
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
cda9b43b · 2026-05-19 · fix(cli): make live-dogfood runner enum-aware and resilient to empty outcomes (#1656)
* fix(cli): make live-dogfood runner enum-aware and resilient to empty outcomes

Three independent fixes for the live dogfood runner, all in the
matrix-builder / acceptance-writer / summary-renderer codepath.

1. Enum-aware happy_path values. `exampleValue` now prefers the first
   declared enum value when a param carries spec-level enum constraints,
   so `pet find-by-status --status available` runs instead of the
   API-rejected `--status example-value`. PII-synthetic shapes still
   win to keep browser-sniff captures from leaking customer data into
   examples.

2. `--write-acceptance` writes on every outcome. The flag previously
   only emitted `phase5-acceptance.json` on PASS, forcing operators to
   hand-author the FAIL marker the Phase 5.6 gate also forbids editing.
   The runner now writes `status: "pass"` or `status: "fail"`
   accordingly; the FAIL marker carries a `failure_summary` block
   bucketing failures by category (transport_error, http_4xx, http_5xx,
   exit_nonzero, output_mismatch, other) plus the contributing
   commands. `phase5_gate.go` already routed `status: "fail"` to the
   hold path, so the gate behavior is unchanged.

3. Path Validity N/A for empty matrix. `printDogfoodReport` rendered
   `0/0 valid (FAIL)` when SpecPath was present, the check was not
   Skipped, and Tested was 0 — cosmetic divide-by-zero misalignment
   with the scorecard, which reports 10/10 in the same run. Empty
   matrices now render `N/A`, matching the failure aggregator at
   `FailedIssues` that already guards on `Tested > 0`.

The phase5-acceptance JSON Schema gains an optional `failure_summary`
definition, drops the unconditional `tests_passed >= 1` floor, and adds
a conditional rule that keeps the floor for `status: "pass"` markers.

Closes #1384

* fix(cli): tighten live-dogfood failure classifier per Greptile review

Address both findings on PR #1656 review of classifyLiveDogfoodFailure:

1. Match "invalid json" / "not json" independently of the "output"
   substring so the runner's own literal "invalid JSON" reason strings
   bucket as output_mismatch rather than falling through to exit_nonzero.

2. Check "http 4" before "http 5" so a retry-count log mentioning
   "http 5" earlier cannot shadow a real 4xx response (e.g.,
   "retried http 5 times, status http 404").

Adds TestClassifyLiveDogfoodFailure covering both regressions plus the
transport_error, output+mismatch conjunction, exit_nonzero, and other
branches so future drift trips a targeted assertion instead of the
existing aggregate bucket-sum check in TestRunLiveDogfoodWritesFailMarkerOnFail.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
5cb39a69 · 2026-05-19 · fix(skills): stop phase 4.95 code review from being skipped (#1655)
* fix(skills): stop phase 4.95 code review from being skipped

Phase 4.95's instruction told Claude Code to invoke `/review` for an
in-place code review. But `/review` is PR-shaped — it fetches an open
GitHub PR and comments back via `gh`. At Phase 4.95 there is no PR
yet, so the agent hit the wrong-shape mismatch, then rationalized
skipping the entire phase under the harness-exemption clause ("no
built-in code review"). Code review was silently dropping out of the
pipeline on Claude Code.

Rewrite the section goal-shaped (intent: local review *before* PR
open; CI-time review is the wrong fix window). Tool selection becomes
a survey-and-pick step with `compound-engineering:ce-code-review` and
`/codex:review` as candidate skills and direct reviewer-subagent
dispatch via the Agent tool named as the universal fallback. Explicit
anti-pattern callout on `/review`. Narrow the harness exemption: skip
is only legitimate when neither a review skill nor subagent capability
exists, and "first tool name didn't fit", "no PR yet", and "PR-time CI
will catch it" are explicitly non-acceptable rationales.

Also slim the findings artifact. Fixed-in-place items collapse to a
one-line summary + commit hashes — the commits are already the record.
Full enumeration is reserved for the three non-fix buckets
(template-shape retro candidates, out-of-scope retro candidates,
surface-to-user findings) plus convergence outcome and review-path
chosen.

* fix(skills): clarify phase 4.95 round semantics and trim redundancy

Resolves Greptile P2 findings on #1655:

1. Direct-subagent-dispatch path was ambiguous about what a "round"
   means when 3-5 reviewers run in parallel. An agent could fix
   correctness findings, re-run only that subagent, see it clear,
   and declare convergence with security/maintainability findings
   still open. Add: a round means re-running ALL spawned reviewers
   in parallel, findings merge into a single set before autofix,
   convergence is the merged set being empty.

2. The Autofix policy block restated "cheapest fix window" verbatim
   from the opening paragraph. Drop the second occurrence.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
2c3271fc · 2026-05-19 · fix(cli): detect path params in browser-sniff URL grouper (#1657)
* fix(cli): detect path params in browser-sniff URL grouper

HAR-sniffed specs collapsed variable path segments into literal endpoint
names because the normalizer only recognized UUID v4, lowercase hex
hashes, and pure-numeric segments. Application IDs that ship a short
type prefix (`t_xxx`, `cus_xxx`), long opaque base62 / ULID / nanoid
tails, or colon-composite discriminators (`create-image:reference:gpt-
image-2`) all landed in the spec as literal paths, producing per-ID
command files that worked for the exact rows captured and nothing else.

This change:

- Extends `normalizeEntryPath` with prefixed-ID, long-opaque-alnum, and
  colon-composite heuristics, each guarded by a non-trivial-token or
  mixed-case-or-digit floor so route literals like `subscriptions` or
  `host:80` don't get parametrized.
- Derives the placeholder name from the parent path segment
  (`tables/t_xxx` -> `tables/{table_id}`) using a conservative
  snake-case + trailing-`s` singularizer, with `{id}`/`{uuid}`/`{hash}`
  as the fallback when the parent isn't usable as an identifier root.
- Adds a `collapseVariantGroups` post-pass to `DeduplicateEndpoints`
  and `DeduplicateTrafficEndpoints` that merges groups whose paths
  differ in exactly one segment when at least one member's value
  matches a strong ID shape, so cross-entry variance backstops shape
  heuristics that miss.

Tests cover the OpenArt history-ID, Clay prefixed-ID, OpenArt colon-
composite form-ID, and the issue's positive/negative acceptance cases.

Closes #1386

* fix(cli): address Greptile findings on browser-sniff path-param detection

Two issues flagged in PR #1657 review:

1. (P1) `collapseVariantGroups` was unreachable as written. Its
   `anyOpaque` gate called `looksLikeIDShape`, which uses the exact same
   six regex patterns as `normalizeEntryPath` — so any segment that
   would satisfy the gate had already been replaced by a placeholder in
   the per-segment pass, putting it in a different bucket from the
   literal-shaped peer it was supposed to merge with. Replace the gate
   with `looksParameterizable`, a weaker check that's TRUE when a
   segment has a digit, mixed case, or any strong-ID shape. Also
   require ALL members at the varying position to satisfy this gate
   (not just one), so a real literal like `health` paired with a
   data-shaped sibling stays separate.

   Adds a test covering the case Greptile flagged:
   `/api/messages/abc123` and `/api/messages/xyz456` (6-char opaque
   IDs, no prefix) now collapse to `/api/messages/{message_id}`.

2. (P2) When two ID segments sit directly under the same parent
   (`/resources/123/456`), the second one walked back past the
   freshly-emitted `{resource_id}` placeholder, found `resources`
   again, and emitted a second `{resource_id}` — producing a path with
   duplicate parameter names that OpenAPI rejects. Track per-path
   placeholder name use and append a counter suffix on collision, so
   the path normalizes to `/resources/{resource_id}/{resource_id_2}`.

   Adds dedicated single-entry and two-entry tests for the consecutive-
   ID case.

* fix(cli): address Greptile follow-up findings on variance pass

Two new P1 findings on the previous fix:

1. `collapseVariantGroups` could still emit duplicate placeholder names
   when a per-segment-placed `{resource_id}` lived earlier in the same
   path. The variance pass walked back through the existing placeholder,
   found `resources` again, and emitted a second `{resource_id}`. Build
   a per-target use-count from the existing path's placeholders and
   route the variance emission through `disambiguatePlaceholder`, so the
   collision becomes `{resource_id_2}` just like the per-segment path.

2. `collapseVariantGroups` was host-blind. `DeduplicateTrafficEndpoints`
   keys its dedup map on host but `EndpointGroup` carried no host
   field, so the variance pass bucketed entries from different hosts
   together and could merge unrelated services into one group. Add a
   `Host` field to `EndpointGroup`, populate it in
   `DeduplicateTrafficEndpoints`, and include it in the variance
   skeleton key.

Adds tests for both: a two-entry case where per-segment normalization
plants a placeholder before the variance position; and a multi-host
case asserting that two distinct hosts stay in separate groups even
when their path shapes coincide.

* fix(cli): narrow variance-pass gate to digit-only widening

P1 follow-up: a pure mixed-case branch (hasUpper && hasLower) in
looksParameterizable was matching PascalCase route literals like
/api/CreateDocument and /api/ListDocuments, which are common in
action-style REST routes (ASP.NET, gRPC-HTTP transcoding). Two such
distinct endpoints would land in the same skeleton bucket and merge into
/api/{api_id}, destroying both routes.

Drop the mixed-case branch entirely. The has-digit branch alone is the
correct widening for the variance pass's target — short opaque IDs like
abc123/xyz456 all carry a digit. The rare digit-free opaque ID is left
for users to parametrize manually rather than risk false-positive
collapses on PascalCase action names.

The variance-pass disambiguation test now exercises digit-bearing
short-opaque IDs (abc123/xyz456 under /resources/) so it stays correct
under the narrowed gate. Adds an explicit negative case: PascalCase
route literals must stay separate.

* fix(cli): make disambiguator scan past suffixed placeholders

P1 follow-up: when a path already carries multiple suffixed
placeholders (`/resources/{resource_id}/{resource_id_2}/...`) and the
variance pass tries to emit a colliding `{resource_id}`, the previous
disambiguator pre-populated `used` with full placeholder strings and
returned `{resource_id_2}` — a name already in the path. Result:
`/resources/{resource_id}/{resource_id_2}/{resource_id_2}`, invalid
OpenAPI.

Rework `disambiguatePlaceholder` to loop on candidate names: start at
the base name, then `_2`, `_3`, ... until a name not already in `used`
is found. Marks every emitted name in `used` so chains stay unique
regardless of how the variance pass pre-populates the map.

Adds a triple-consecutive test asserting that
`/resources/123/456/abc123` and `/resources/789/012/xyz456` normalize
to `/resources/{resource_id}/{resource_id_2}/{resource_id_3}`.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
17cd2774 · 2026-05-19 · fix(cli): dogfood prefers bundled <dir>/spec.yaml over caller --spec (#1625)
* fix(cli): dogfood prefers bundled <dir>/spec.yaml over caller --spec

When the caller invokes `printing-press dogfood --dir X --spec Y` and X
contains a spec archived by `publish package`, the archived spec is now
authoritative — caller's --spec is overridden. Fixes false-negative
Path Validity / Auth Protocol regressions on multi-spec manuscripts
runs (browser-sniff, crowd-sniff, hand-authored-on-top-of-official),
where the caller picks the upstream spec instead of the CLI's own.

Falls through to caller's --spec unchanged when no bundled spec exists.

Fixes #1620

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cli): typed DogfoodSpecSource const, drop ticket refs

Address Greptile review:
- Introduce DogfoodSpecSource type + DogfoodSpecSourceBundled /
  DogfoodSpecSourceCaller consts (AGENTS.md: categorical strings ->
  typed const at introduction). Matches MCPSurfaceState pattern.
- Remove ticket-number references from code comments (AGENTS.md: no
  ticket numbers in code comments).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(golden): refresh dogfood fixtures for bundled-spec auto-discovery

Two intentional behavior changes from the dogfood spec-resolution fix:

- dogfood-verdict-matrix: stderr gains the `dogfood: using spec ...
  (bundled)` line; fail-path-auth-dead.json gains spec_source field.
- generate-golden-api: same stderr + JSON additions. Also, auth_check
  and browser_session_check now run substantively (they were skipped
  previously because the test invokes `dogfood --dir X` without
  --spec; with bundled-spec auto-discovery the checks engage against
  <X>/spec.yaml as intended).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cli): clarify auth_check.detail when bundled spec has no recognized scheme

Now that dogfood resolves a bundled spec instead of short-circuiting on
no-spec, checkAuth's "expectedPrefix empty" branch is reachable with a
spec present. The old message "spec not provided or no bot/bearer/basic
scheme detected" contradicted spec_source="bundled" + a non-empty
spec_path in the report. Drop the "spec not provided" half — that case
no longer reaches this branch.

---------

Co-authored-by: Mark van de Ven <10142972+markvandeven@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
Co-authored-by: Trevin Chow <trevin@trevinchow.com>
ac3e15b4 · 2026-05-19 · fix(cli): sync pagination, auth aliases, narrative timing, and codex prompt (#1341)
* fix: sync pagination, auth aliases, narrative timing, and codex prompt

Six independent generator-level findings surfaced during a downstream CLI
generation run against an offset-paginated REST API. Each is generic; the
discovery context is not in the diff or test data.

1. AuthHeader OR-semantics for legacy x-auth-env-vars (spec.go)

   IsAuthEnvVarORCase only returned true when all EnvVarSpecs were
   non-required per_call. Specs using the legacy x-auth-env-vars list
   form (or a populated EnvVars slice with default Required=true) fell
   through to the canonical-only path: only the first env-var alias
   reached AuthHeader, the rest were populated by Load() but never
   read. Updated IsAuthEnvVarORCase to also return true when:
     * EnvVarSpecs has 2+ entries that are all request-credentials, OR
     * legacy EnvVars list has 2+ entries.
   New pin: TestAuthHeader_LegacyEnvVarsList_OrSemantics.

2. validate-narrative side-effect classifier (narrativecheck.go)

   --full-examples ran every command whose --help advertised --dry-run,
   including auth set-token YOUR_TOKEN_HERE and auth logout. The first
   persisted the literal placeholder to the user's ~/.config; the
   second wiped saved credentials. Added isSideEffectfulNarrativeExample
   skip-classifier covering auth set-token, auth logout, auth setup,
   auth login, --launch, and bare --apply. Skipped commands return
   StatusUnsupported with an explanatory reason rather than executing.
   New pins: TestRunFullExample_SkipsAuthSetToken,
   TestRunFullExample_SkipsAuthLogout.

3. Empty-array marshalling guidance (codex-delegation.md)

   Codex-generated novel-feature commands declared var results []T,
   which marshals nil to JSON null. Empty list outputs broke jq '.[]'
   agent pipelines. Updated the transcendence-command prompt template
   to require results := make([]T, 0) for all list-shape outputs, with
   a paragraph at the top of CONVENTIONS spelling out the contract.

4. Shipcheck leg ordering (shipcheck.go)

   dogfood ran first and synthesized README.md and SKILL.md from
   research.json.novel_features_built — including any planned commands
   whose command-paths didn't actually resolve against the built binary.
   validate-narrative ran later and caught them but the user-facing
   files were already wrong. Reordered: verify, validate-narrative,
   dogfood, workflow-verify, verify-skill, scorecard. Comment updated
   to reflect the dependency: verify builds the binary; validate-narrative
   checks research.json against the binary BEFORE dogfood renders from it.

5. Offset+has_more pagination loop (sync.go.tmpl)

   The sync loop's break-condition required nextCursor != "" alongside
   hasMore=true. APIs using offset+has_more (no cursor token in the
   response) returned hasMore=true with empty nextCursor on every page,
   so the loop broke after page 1 and only the first page worth of
   records reached the local store. Fixed at both occurrences (linear
   and parent-child sync paths): when cursorParam=="offset" and the
   envelope returned no cursor despite hasMore, compute nextOffset
   client-side as currentOffset + pageSize.limit. Cursor-based APIs
   that genuinely return no cursor still break (existing behavior;
   silent infinite-loop guard). New pin:
   TestGeneratedSyncAdvancesOffsetWhenHasMoreWithoutCursor.

6. Per-resource pagination param gate (profiler.go + sync.go.tmpl)

   Sync sent ?limit= and ?offset= to every list endpoint regardless of
   whether the spec declared those params for that endpoint. List
   endpoints that don't paginate (typical for /me, /settings, small
   reference resources) rejected the synthetic params with HTTP 400
   "Invalid query parameter". Added profiler.SupportsPagination per
   syncable+dependent resource (detected from endpoint params at
   generate time). Generator template emits resourceSupportsPagination()
   from the per-resource map; sync gates limit/offset setting on its
   return value. New pin:
   TestGeneratedSyncGatesPaginationParamsPerResource.

Test coverage:
  * go build ./... — pass
  * go vet ./... — pass
  * go test ./... — pass (30 packages, ~13min runtime)

* fix: use exact side-effect flag matching

* fix: detect cursor-only pagination support

* test(cli): refresh sync pagination goldens

---------

Co-authored-by: Trevin Chow <trevin@trevinchow.com>
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
275646a3 · 2026-05-19 · feat(cli): add auth set-token escape hatch for cookie-auth CLIs (#1641)
* feat(cli): add auth set-token escape hatch for cookie-auth CLIs

The auth_browser template now emits an `auth set-token <jwt>` subcommand
alongside login/status/logout. This is the escape hatch for sites whose
access token cannot be reached by the cookie-jar extractor in
`auth login --chrome` — most commonly Auth0 SPA SDK v2+ deployments that
keep the JWT in JS heap memory and never expose it to cookies or
localStorage. Users (or agents) paste the bearer from DevTools instead of
hand-editing config.toml.

Validation runs through cliutil.LooksLikeJWT (shipped in PR #1602 / WU-2),
so short Cloudflare-shaped tracking cookies like `__cf_bm` get rejected
with a hint pointing back at the DevTools paste flow. Emission is gated
on Auth.Type != "none", so auth.type=none + persisted-query CLIs (the
only path that routes a no-credentials spec through this template) don't
ship a subcommand they have nothing to save into.

Two stale assertions in the cookie/composed auth_browser regression
tests used the literal "set-token" as their proxy for "this is not the
auth_simple template." That proxy no longer holds — auth_browser now
legitimately emits set-token too. Swapped to `newAuthSetupCmd` as the
auth_simple-only signature, since auth_browser uses newAuthLoginCmd for
the cookie/chrome flow instead.

Refs #1598 (WU-3a).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(cli): zero TokenExpiry in auth set-token to avoid stale write

SaveTokens used to receive cfg.TokenExpiry from the loaded config, which
in the escape-hatch scenario is a past timestamp from an expired prior
session. The auth_browser status command doesn't consult TokenExpiry
today, so the bug wasn't immediately surfacing — but writing a known-
stale value violates the zero-on-write invariant that ClearTokens and
SaveBearerToken already follow in config.go.tmpl, and would mislead any
future expiry-aware status check.

Passing time.Time{} keeps the API "we don't know the lifetime"; the real
expiry surfaces via 401 on the next call, same as the rest of the
browser-auth flow.

Refs #1598 (WU-3a).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
f9bb82c8 · 2026-05-19 · fix(skills): reprint discovers and carries prior patches (#1649)
* fix(skills): reprint discovers and carries prior patches

Reprinting silently dropped post-publish hand-fixes recorded in
.printing-press-patches.json, regressing live-validated API quirks
and architectural patterns. Phase B now re-fetches the public
patches file (covering the case where amends landed without a
regen, so local can lag even when run_id matches), and Phase D
threads non-empty patches into the /printing-press hand-off under
a new "## Prior Patches" heading.

Patches are framed as an informational watch-list, not a re-apply
mandate — the machine may have absorbed some upstream, and the
retro+bugfix loop is the right mechanism for that drift, not a
per-patch reconciliation gate.

* fix(skills): make patches discovery's fetch durable

Address Greptile P2 findings: the prior mktemp-based fetch leaked the
temp file on the success path (accumulating across repeated reprint
runs) and used the ephemeral path as the downstream `$PATCHES_SOURCE`
reference, which a long-running /printing-press hand-off could find
absent.

Refresh the local patches file from public via mktemp + atomic
rename instead. The temp file is always either renamed or removed,
and PATCHES_SOURCE is always the stable local path the downstream
agent can open.
b5b1dd59 · 2026-05-18 · feat(cli): add cliutil.LooksLikeJWT shared validator with length floor (#1602)
* docs(cli): file factor75 retro — 3 systemic findings from live dogfooding

Live debugging surfaced three machine-side gaps that compound on any
sniffed BFF CLI:

1. Hand-authored sync silently drops URL personalization params,
   degrading responses to a generic preselect without changing JSON shape.
2. looksLikeJWT has no minimum-length floor and saves short Cloudflare /
   tracking cookies as access tokens.
3. auth login --chrome can't reach Auth0 SPA SDK in-memory tokens (now
   the SDK default since v2 deprecated localStorage as XSS-unsafe).

Tracked as GitHub issue #1598 with three WUs that can be picked up
separately. The Factor75 printed CLI's matching syncer fix is in the
local library (~/printing-press/library/factor75/) and is unaffected by
this commit.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* feat(cli): add cliutil.LooksLikeJWT shared validator with length floor

Adds a generator-emitted cliutil helper that every printed CLI now
carries: LooksLikeJWT(string) bool and FindJWTInCookieJar(jar) string,
both with a 150-char total / 20-char header minimum that filters out
Cloudflare bot-management cookies, CSRF tokens, and other short shapes
that share JWT's three-base64url-segments structure.

Until now, sniffed CLIs that need to validate a JWT shape (e.g. when
extracting a Bearer from a cookie jar) had to hand-author the check,
and the hand-authored versions inherit a false-positive: any three-
segment base64url string passes regardless of length. The factor75
printed CLI hit this with the Cloudflare `__cf_bm`-shaped value
`01KRPVRYA2SNQT9BAGD6984WAG_.tt.1` (31 chars), which got saved as the
access token and produced confusing HTTP 401 "invalid character"
decode errors on every subsequent API call.

The helpers are purely additive — no current template calls them, so
no rendered output changes for existing CLIs. They become useful as
soon as auth templates start needing them (next PR: WU-3a `auth
set-token` subcommand uses LooksLikeJWT as its validator).

Refs #1598 (WU-2).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(cli): address PR review feedback on jwtshape helper (#1602)

- Tighten boundary tests to hit 149/150 exactly so constant changes
  (150 -> 155) or off-by-one comparison drift surface immediately.
  Previous fixtures sat at 108 and 158 chars, neither exercising
  the floor.
- FindJWTInCookieJar now strips a leading "Bearer " from the cookie
  value before returning, matching LooksLikeJWT's input normalization.
  A cookie carrying the Authorization wire value ("Bearer eyJ...")
  used to return the prefixed form, which would produce a double-
  prefixed Authorization header when a caller built the header from
  the result. New test case proves the bare token comes back.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
ed17d302 · 2026-05-18 · fix(cli): gate ship plans on agent readiness (#1638)
* fix(cli): gate ship plans on agent readiness

* docs(cli): document readiness ship gate learning

* fix(cli): clean readiness finding rendering

* fix(cli): normalize readiness table findings

* fix(cli): clarify readiness verdict holds

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
af9ba8c7 · 2026-05-18 · docs(skills): document separate-file pattern for extending emitted files (#1624)
* docs(skills): document separate-file pattern for extending emitted files

Add a Phase 3 callout to skills/printing-press/SKILL.md warning that
hand-edits to any generator-emitted file (`config.go`, `client.go`,
`auth.go`, `store.go`, `root.go`, plus the `cliutil_*` / MCP / sync
families) are wiped on `printing-press generate --force` and reconciled
by `printing-press regen-merge`. Only whole hand-authored files survive
across regen; inline additions (struct field, header in do(),
AddCommand call, migration row) are not preserved.

Names the separate-file pattern per common extension case:

- Custom config fields -> internal/config/<api>_config.go
- Custom request headers -> internal/client/<api>_headers.go
- Custom auth flow -> internal/auth/<api>_auth.go
- Extended store schema -> internal/store/<api>_migrations.go
- New novel command -> internal/cli/<feature>.go

When no separate-file route exists (an AddCommand call with no registry
hook, a case branch in a method switch), the callout directs agents to
file a generator issue rather than inline-editing.

Closes #1604

* docs(skills): reconcile novel-command bullet with Phase 3 skeleton; scope header injection

Two Greptile findings on PR #1624:

P1 - "New novel command" bullet contradicted the existing Phase 3
skeleton (lines 2491-2495), which instructs agents to wire hand-authored
commands via AddCommand in root.go. The earlier text implied the body
file alone was sufficient, and the closing paragraph routed AddCommand
edits to "file a generator issue." An agent following that guidance
would ship a command file that is never registered in the Cobra tree.

Reworded to:
- The command body lives in internal/cli/<feature>.go (survives regen).
- The AddCommand call still goes in root.go per the existing skeleton.
- `generate --force` wipes that call, but `regen-merge` re-injects it via
  the lost-registration mechanism in internal/pipeline/regenmerge/apply.go.
- Prefer regen-merge over --force for refreshes.
- Spec-declared commands need no hand-wired AddCommand at all.

P2 - "Custom request headers" bullet said the exported func is called
"before each request," implying global injection. The generated client.go
has no per-request mutator chain; the only injection surface is
GetWithHeaders / PostWithHeaders called explicitly by novel code.

Reworded to make the scope explicit: the helper builds the header map,
novel code passes it to GetWithHeaders/PostWithHeaders, and generated
endpoint commands are unaffected.

Also tightened the closing fallback to exclude AddCommand (which is
already covered by regen-merge) and call out which inline diffs actually
warrant a generator-issue ask.

* fix(skills): correct auth extension path and remove fictional method switch

The custom-auth-flow extension pattern pointed agents at
`internal/auth/<api>_auth.go`, but no `internal/auth/` package exists —
all four auth templates (`auth.go.tmpl`, `auth_simple.go.tmpl`,
`auth_browser.go.tmpl`, `auth_client_credentials.go.tmpl`) emit to
`internal/cli/` under `package cli`. Following the guidance produced
an orphan package that nothing in the generated tree imports.

Also dropped the reference to a "templated method switch in `auth.go`":
the generated `auth.go` uses constructor functions
(`newAuthLoginCmd`, `newAuthSetupCmd`, etc.), not a switch.

Aligns the auth extension with the side-by-side same-package invariant
that the other four extension patterns already follow
(`internal/config/`, `internal/client/`, `internal/store/`,
`internal/cli/`).

* Update skills/printing-press/SKILL.md

Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
766354e6 · 2026-05-18 · feat(cli): add sync --path-context KEY=VAL runtime override for template placeholders (#1631)
* feat(cli): add sync --path-context KEY=VAL runtime override for template placeholders

The narrower spec-extension fix #1368 makes per-tenant sync work when the
spec declares `info.x-tenant-env-var` and the user's environment holds
the value. That covers the steady-state ServiceTitan case but leaves
three gaps named on the issue:

- One-off override at the call site (env says A, this run should target B).
- Placeholders the spec did NOT annotate with an env var, so the
  existing `EndpointTemplateVars` substitution has nothing to read.
- The workspace/org generalization beyond `{tenant}`.

The `--path-context KEY=VAL` flag (repeatable) on `sync` plugs all three
into the same generated machinery `EndpointTemplateVars` already uses.
At RunE time the values land in `c.Config.TemplateVars`, so the existing
`buildURL` substitution pipeline picks them up for every request without
new request-path manipulation.

Profiler-driven emission: gated on `.EndpointTemplateVars` being non-
empty so plain APIs (which have nothing to substitute) keep their
existing sync flag surface intact. The matching byte-compat test asserts
the flag is absent from plain CLIs.

Closes #1332

* fix(cli): warn on unknown --path-context keys; drop assertions belonging to #1632

Greptile flagged two findings on PR #1631:

1. Four test assertions referenced template output (emitCacheRefreshFailedEvent,
   cache_warning, refresh_failed) that does not exist on this branch. Those
   symbols come from PR #1632's auto_refresh template change and were
   accidentally included here. Removing them so the freshness-helper test
   passes on this branch; #1632 carries the matching assertions.

2. --path-context silently accepted keys outside endpointTemplateVarSet,
   so typos like --path-context tneant=... would store the value in
   Config.TemplateVars without substituting anywhere, leaving the run
   looking correct but using the env-resolved default. Emit a one-line
   stderr warning per unknown key. Non-fatal so callers passing
   forward-compat keys aren't blocked.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
187b6992 · 2026-05-18 · fix(cli): emit structured cache_warning JSON on auto-refresh failure (#1632)
* fix(cli): emit structured cache_warning JSON on auto-refresh failure

When autoRefreshIfStale's bounded refresh hits an upstream error and the
command proceeds with the stale cache, the generator now emits a
one-line JSON event to stderr alongside the existing prose warning:

  {"event":"cache_warning","reason":"refresh_failed","resources":["homes"],"error":"..."}

meta.freshness already carries this signal in --json output for commands
that wrap with wrapWithProvenance, but novel commands that build their
own response shape (and most agent-facing fan-outs to printed CLIs) only
saw the prose warning on stderr. Agents reading the stdout stream had no
parseable way to know subsequent rows were served from a cache that
doesn't reflect their requested filters.

The new emitter sits next to the prose warning so both stay aligned; the
prose stays for humans, the JSON line gives agents a single grep-able
signal that matches the established sync_warning/sync_error vocabulary.
The matching auto_refresh_test.go.tmpl exercises the emitter shape in
every generated CLI with cache enabled.

Closes #1263

* fix(cli): panic-safe captureStderr + generator assert for auto_refresh_test.go

Addresses Greptile findings on #1632:
- P1: captureStderr lacked deferred cleanup, so a panic in fn() would leak
  the io.ReadAll goroutine and hang the test binary. Add a defer that
  closes the write end of the pipe and restores os.Stderr, leaving the
  happy-path explicit calls as the primary path.
- P2: TestGenerateFreshnessHelperEmitted now asserts auto_refresh_test.go
  is emitted with the expected helpers and snippets. Golden fixtures have
  no cache-enabled case, so without this a Go syntax error in the
  template would only surface when a customer runs go build.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
e798f671 · 2026-05-18 · fix(cli): route Swagger 2.0 specs through openapi2conv to avoid OOM on circular refs (#1630)
* fix(cli): route Swagger 2.0 specs through openapi2conv to avoid OOM on circular refs

Swagger 2.0 specs with circular $ref chains in definitions/ (Tripletex,
NetSuite REST, Salesforce Tooling) caused the generator to burn 15-30
minutes of CPU at 1.8-4.4 GB RSS and eventually OOM. The same content
converted to OpenAPI 3.x externally via swagger2openapi generated in
about three minutes.

Detect Swagger 2.0 at the parser boundary (normalized JSON has top-level
"swagger": "2.0") and route through openapi2conv.ToV3WithLoader before
the OpenAPI 3 loader runs. The conversion rewrites #/definitions/X to
#/components/schemas/X so the existing cycle-aware OpenAPI 3 code path
handles resolution. openapi2conv is a sub-package of kin-openapi, which
is already a dependency.

Emit one stderr line announcing the conversion so operators have
visibility into the multi-minute resolution phase. The retro called out
the silent phase as the biggest UX issue in the failure mode.

Closes #1241

* fix(cli): address Greptile feedback on Swagger 2.0 loader (P1 + 2 P2s)

P1 (Missing ReadFromURIFunc): the conversion path's loader did not
install the custom ReadFromURIFunc that the main OpenAPI 3 path uses,
so a Swagger 2.0 spec loaded with a file location whose external $refs
pointed at YAML companion files would skip the YAML->JSON normalization
step and fail deep inside ToV3WithLoader. Extract the loader setup into
newConfiguredOpenAPI3Loader and call it from both paths.

P2 (Overly permissive version match): drop the "swagger":"2" prefix
variants; the Swagger 2.0 spec mandates exactly "2.0" so the bare
"2" forms only matched hypothetical future version strings. Add
test fixtures asserting "2" and "2.5" do not trigger detection.

P2 (Goroutine leak on timeout): document the intentional leak in the
30s-timeout branch of the cyclic-ref regression test. Parse exposes no
cancellation hook; failing the test fast and abandoning the goroutine
is the lesser evil compared to letting CI sit for ~25 minutes before
OOMing.

Refs #1241

* fix(cli): detect Swagger 2.0 via streaming JSON decode, not head substring

Greptile P1: the substring-scan detector silently missed real-world
Swagger 2.0 specs. normalizeSpecData round-trips through encoding/json,
which sorts map keys alphabetically — so "swagger" (s) lands AFTER
"definitions" (d) and "paths" (p) in the serialized output. For a
multi-MB vendor spec (Tripletex, NetSuite, Salesforce), the "swagger"
marker is far past any reasonable head-buffer window, and the detector
returned false on the exact specs this PR was built to handle.

Switch to a streaming json.Decoder that walks top-level keys, returning
true only when a top-level "swagger" key has the value "2.0". Stops
reading after the swagger value is found; for non-Swagger 2.0 specs it
traverses tokens at the top level (skipping nested values en bloc),
which is still fast for the ~2MB upper bound of real specs.

Add a regression test that builds a Swagger 2.0 fixture whose alphabetized
serialization pushes the "swagger" marker well past the 4KB mark.

Refs #1241

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
042a78d4 · 2026-05-18 · feat(cli): flag empty defaultSyncResources at dogfood time (#1633)
* feat(cli): flag empty defaultSyncResources at dogfood time

When a spec exposes no bulk-list endpoint (only parameterized detail pages and
required-query searches, e.g. Allrecipes), the profiler correctly produces an
empty SyncableResources slice, but the generator still emits `sync` as a
runtime no-op alongside store-dependent novel commands (cookbook, pantry,
top-rated, ...). The CLI ships with no advertised path to populate the store.

Add a dogfood pipeline_check signal that detects the empty-list emission of
defaultSyncResources() in the generated sync.go and surfaces it as WARN so the
gap is visible at shipcheck time. Also emit a one-line runtime hint (stderr
in human mode, sync_warning JSON event in agent mode) when the structural
precondition holds, so callers see "no bulk-list endpoints in spec; populate
the store via single-fetch commands" instead of a silent total_records:0.

Closes #1156

* fix(cli): always emit sync_file_emitted in pipeline_check JSON

Greptile flagged a JSON-tag asymmetry on PipelineResult: SyncFileEmitted
carried `omitempty` but SyncResourcesPresent did not, so when sync.go is
absent a downstream consumer sees `sync_resources_present: false` with no
sync_file_emitted signal, which incorrectly reads as "should have resources
but does not." Drop the `omitempty` so both fields always appear together
and consumers can disambiguate the three real states:

  sync_file_emitted=false, sync_resources_present=false  no sync surface
  sync_file_emitted=true,  sync_resources_present=true   healthy
  sync_file_emitted=true,  sync_resources_present=false  empty (issue #1156)
14bc18a4 · 2026-05-18 · feat(cli): default mcp.transport=[stdio, http] for small APIs (#1629)
* feat(cli): default mcp.transport=[stdio, http] for small APIs

Specs that leave the mcp.transport field unset now get http compiled in
alongside stdio when the typed-endpoint surface is at or under
spec.DefaultRemoteTransportEndpointThreshold (30). Stdio-only servers
can only reach clients that can spawn a subprocess; cloud-hosted agents
need a remote transport. Adding http at small surface sizes costs
nothing in tool count or agent context and lifts mcp_remote_transport
from 5/10 to 10/10 in the scorecard.

Explicit transport lists pass through unchanged: a spec that opts into
mcp.transport: [stdio] stays stdio-only even at small endpoint counts.
Larger APIs continue to fall back to stdio-only by default, where the
dominant problem is tool-count, not reach, and warnUnenrichedLargeMCPSurface
keeps recommending the orchestration pattern.

Resolution lives on a new APISpec.EffectiveMCPTransports helper so the
template branch reads from a single source of truth that knows both the
configured field and the endpoint count. MCPConfig.EffectiveTransports
remains the unconditioned view for spec validation and mcp_audit.

Closes #1603

* docs(cli): clarify Transport field comment per Greptile review

The inline struct-tag comment on MCPConfig.Transport said "empty == [stdio]",
but after the small-API default the empty case resolves via
APISpec.EffectiveMCPTransports to [stdio, http] for small APIs and to
[stdio] only for larger ones. Update the comment to reflect that.
f671b7ba · 2026-05-18 · feat(ci): mirror supply-chain hardening from printing-press-library (#1619)
* feat(ci): mirror supply-chain hardening from printing-press-library

Adds a layered PR-time gate against the workflow-trust and Go-module env
attack shapes observed in May 2026 (TanStack mini-Shai-Hulud,
BufferZoneCorp, node-ipc).

Two layers, applied to PRs touching .github/workflows/**:

1. Deterministic Python scan in .github/scripts/verify-supply-chain/,
   vendored from mvanhorn/printing-press-library (source dated 2026-05-17).
   scan.py is verbatim; signals.py is adapted to the generator-repo signal
   set — R3 (replace directives in library/**/go.mod), R5 (npm lifecycle),
   and R6 (module-path drift) are omitted because they protect surfaces
   that don't exist here. R1 (pull_request_target + PR-head checkout),
   R2 (id-token outside allowlist; empty allowlist here), and R4
   (GOPROXY/GOFLAGS/GONOSUMCHECK overrides) apply with minor adaptation.
   15 unit + integration tests pass.

2. Four Greptile rules covering the same signals plus a judgment-only
   credential-path read rule for internal/**/*.go and cmd/**/*.go.

Companion PR in mvanhorn/printing-press-library:
https://github.com/mvanhorn/printing-press-library/pull/665

Canonical incident timeline and primary-source citations live in the
published-library repo's docs/solutions/security/2026-05-supply-chain-hardening.md
— single source of truth across both repos.

Informational on landing — promote to required check after a one-week
green window confirms no false-positive miscalibration on real PRs.

* fix(ci): close scanner self-bypass gap in supply-chain workflow

Mirrors the workflow fix from mvanhorn/printing-press-library#665.

Original posture: workflow checked out PR head, so the scan.py
executing the gate was whatever the PR shipped. A malicious PR
could weaken scan.py and bypass detection of its own payload.

New posture: check out the base branch from the base repo (the
trusted scanner version runs), fetch the PR head SHA as a
detached ref, and pass it to scan.py via --head-ref.

Forward-looking concern — this check is informational on
landing but matters once promoted to a required gate.

(R3 / block-form replace evasion does not apply here — the
generator-repo mirror omits R3 entirely; see signals.py header.)

* fix(ci): bootstrap fallback when base has no scanner yet

Mirrors the printing-press-library fix. The previous workflow rewrite
runs scan.py from the base branch, but this PR is what introduces
scan.py, so base has nothing to run. Adds an if-not-exists fallback
that restores .github/scripts/verify-supply-chain/ from the PR head
SHA. No-op after merge.

* fix(ci): R1 flow-sequence trigger + diff-aware R1/R2/R4

Mirrors the printing-press-library fix. Two gaps Greptile flagged
on PR #665 of the published-library repo apply equally here:

1. R1 trigger regex missed YAML flow-sequence form
   `on: [pull_request_target, push]`. Added a second regex
   (_PR_TARGET_TRIGGER_FLOW) and unified via _has_pr_target_trigger().

2. R1/R2/R4 scanned full head_content rather than diff additions.
   Refactored via a shared _lines_to_scan() helper: full scan for
   new files, added_lines only for existing files. Prevents false
   positives if main ever drifts to contain a pattern these rules
   cover.

19 tests pass (was 15).

* chore(ci): mirror scan.py signature change from printing-press-library

PR #665 added rename-aware diff handling to scan.py: changed_files()
returns old_path for renames/copies, and build_change() fetches
base_content from old_path on renames. The signature change is benign
in the generator-repo mirror (R3/R5/R6 are omitted here, so no signal
currently consumes the rename information), but kept in lock-step
with the source to make future cherry-picks of signal changes
mechanical.

Mirror commit only. Tests unchanged (19 pass).

* fix(ci): deletion-guard + id-token regex edge case (mirror)

Mirrors the printing-press-library fix:

1. Workflow gains a deletion-guard step that hard-fails any PR which
   removes files under .github/scripts/verify-supply-chain/. Closes the
   staged delete-then-replace attack against the bootstrap fallback.

2. _ID_TOKEN_WRITE regex now accepts an optional trailing YAML comment
   (`id-token: write  # justification`) so attackers can't evade the
   strict end-of-line match.

20 tests pass (was 19).

* docs(agents): trim supply-chain section to operational guidance

Mirror of the printing-press-library trim. AGENTS.md no longer narrates
the incident set or enumerates signals; greptile.json is authoritative
for rule coverage, and the published-library solutions doc carries the
incident timeline + primary sources.

* fix(ci): YAML-parse R1/R2/R4 to close block-scalar bypass

Greptile flagged on PR 1619 (4/5): a workflow using YAML block-scalar
notation evades the single-line regex.

  ref: >-
    \${{ github.event.pull_request.head.sha }}

Both the regex `_DANGEROUS_REF` and `_ID_TOKEN_WRITE` required the
sensitive value on the key's line; valid YAML with the value folded
onto the next line silently passes. Each new YAML quirk (block-form
replace, flow-sequence trigger, now block-scalar values) needed its
own regex patch — that's a brittle approach.

Switched R1/R2/R4 to parse the workflow with pyyaml (pre-installed on
ubuntu-latest runners) and walk the parsed dict tree:

- R1 walks jobs → steps → uses=actions/checkout* → with.ref, and
  matches the loaded ref value against a (still-regex) pattern for
  dangerous expressions. YAML normalises block-scalars before the
  match runs, so all forms collapse to the same string.
- R2 walks workflow-level and job-level `permissions.id-token`. Also
  catches `permissions: write-all` which grants id-token implicitly.
- R4 walks env blocks at workflow, job, and step level.

Diff-awareness is now STRUCTURAL: parse both base and head, fire only
if head has the dangerous pattern AND base didn't. Replaces the
line-level _lines_to_scan approach for these signals — more robust
because reformatting (reindent, change YAML style) of an unchanged
dangerous pattern no longer false-fires.

Two new tests cover the folded (`>-`) and literal (`|-`) block-scalar
ref forms. The refs/pull regex also fixed to use [^\\n] instead of
[^\\s] so spaces inside \${{ ... }} don't break the match.

22 tests pass (was 19).

* fix(ci): R1 catches github.head_ref + merge_commit_sha shortcuts

Greptile P1: the dangerous-ref pattern missed github.head_ref (shorthand
alias for event.pull_request.head.ref) and event.pull_request.merge_commit_sha
(GitHub's synthesised test-merge commit). Both resolve to PR-author-controlled
content under pull_request_target — same elevated-context attack surface as
the previously-covered forms.

Same fix mirrored in mvanhorn/printing-press-library#667.

24 tests pass (was 22).

* chore(ci): gitignore __pycache__ and untrack stray .pyc files

verify-supply-chain Python tests were generating .pyc files that got committed because .gitignore had no Python rules.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
ef81ca04 · 2026-05-17 · test(cli): update TestPublishSkillSkipsCliSkillsMirrorRegen for new library gate name (#1618)
#1614 (docs(skills): publish skill aligns with library's bot-only
generated-artifacts rule) updated the publish skill's prose to
reference the new `Fail on changes to generated artifacts` gate that
mvanhorn/printing-press-library#659 introduced. The existing contract
test still asserted the old strings:

- "Guard against hand-edits to cli-skills mirror" (gate name retired)
- "Do NOT regenerate or commit \`cli-skills/pp-<api-slug>/SKILL.md\`
  here" (now extended to cover both cli-skills and registry.json)

#1614's CI passed because change-scoped test selection didn't include
the pipeline shard (the skill change touched skills/, not internal/
pipeline/). The full-suite matrix that runs on release-please PRs
caught the divergence on the next release prep (release-please#1495
failing on test (pipeline)).

Updated the assertions to match the current skill text. Intent is
unchanged: verify the skill names the current rejection mechanism and
explicitly warns against committing the generated files.
dde2a4e0 · 2026-05-17 · docs(skills): publish skill aligns with library's bot-only generated-artifacts rule (#1614)
mvanhorn/printing-press-library#659 replaces the older Guard +
auto-fix + fork-only drift trio with a single check, `Fail on changes
to generated artifacts`, that hard-fails any PR — fork or same-repo —
whose diff touches `registry.json` or `cli-skills/pp-*/SKILL.md`. The
in-PR auto-fix path is gone; the only legitimate flow is to drop those
files from the diff and let post-merge regen (`generate-skills.yml`,
`generate-registry.yml`) produce them.

Three references in the publish skill described the old behavior:

1. The intro paragraph after the trigger phrases (line ~30) cited
   `Guard against hand-edits to cli-skills mirror`.
2. The Step 6 bash comment block (line ~461) described the
   fork-only-pre-rejection + same-repo-auto-fix split.
3. The Greptile-feedback section (line ~942) cited "your edits will
   be overwritten" without naming the gate.

Each now references `Fail on changes to generated artifacts` and the
single uniform behavior.

No behavior change in the skill itself — Step 6 already does not
regenerate or commit these files. This is doc alignment only.
fef027fe · 2026-05-17 · fix(skills): retro skill scrubs secrets and PII before posting issue bodies (#1595)
* fix(skills): retro skill scrubs secrets and PII before posting issue bodies

The retro skill already scrubs artifact zips (via references/secret-scrubbing.md
Layers 1-4) before catbox upload, but issue body text went straight from the
retro doc to `gh issue create` with no scrub step. A finding *about* a
secret-leak could quote the actual leaked value as "evidence" and re-leak it
in a public GitHub issue. The retro doc itself was also unscrubbed despite
being preserved in manuscript proofs and read by future runs' dedup scan.

This change closes both gaps:

1. **New cardinal rule** at the top of the retro skill's Cardinal rules
   section: issue bodies and retro docs are public surfaces and must be
   scrubbed before posting / writing. Specifically warns against the
   "quote the leaked value as evidence" failure mode that retro findings
   about secret leaks are most vulnerable to.

2. **New Layer 0 in `references/secret-scrubbing.md`**: a reusable
   `scrub_body` shell function that operates on a single markdown file
   (the retro doc or an issue body). Hard-fails on unredacted vendor-prefix
   tokens (Stripe, GitHub, Slack, AWS, OpenRouter, Anthropic, Linear,
   Mailchimp, JWT, Bearer-with-value); auto-redacts PII (real emails,
   NANP phones, ZIP+4, Mailchimp inbox-ids) in place. Allowlists RFC 2606
   reserved example domains and NANP fictional 555-01XX phone numbers
   so legitimate documentation examples pass through unchanged.

3. **Phase 5 (retro doc write) scrubs the doc** immediately after writing
   it, before the manuscript proofs + scratch copies are made canonical.
   Hard-fails surface as a stop with explicit redaction instructions; PII
   auto-redacts and writes the cleaned version in place.

4. **Phase 6 Step 3 (issue/comment post) scrubs body files** before each
   `gh issue create` / `gh issue comment` call. Per-WU hard-fails route
   into the existing `$FAILED_ISSUES` reporting as a new `scrub-failed`
   outcome kind so the user sees what needs hand-redaction.

5. **Body template updated** to explicitly warn agents to redact in the
   "What we observed" section of new issue bodies; references the Layer 0
   shape so the agent has the redaction format at hand.

6. **New skill-level rule** added to the Rules section: never quote a
   leaked secret as evidence of a secret-leak finding.

Verified end-to-end with smoke tests against four input shapes:
- clean input (no findings) passes through with zero diff
- Linear API key (`lin_api_<40+ chars>`) hard-fails with line numbers
- Mailchimp API key (`{32-hex}-us6`) hard-fails with line numbers
- PII (real email, NANP phone, ZIP+4, Mailchimp inbox-id) auto-redacts;
  RFC 2606 example.com and NANP 555-01XX pass through unchanged

`go test ./internal/cli/...` green; `scripts/golden.sh verify` green.

Scope: skill markdown only, no Go code changes. No new binary subcommand
needed in this change; the scrubbing is bash-resident in the skill so
users running the skill outside a printing-press source checkout still
get the protection.

* fix(skills): retro scrub_body — fictional 555-01XX exclusion handles paren format (Greptile P2 on #1595)

The original NANP phone regex anchored the (?!555[-\s.]?01) negative lookahead
before the optional opening paren \(? — so when a fictional number is written
as `(555) 012-3456`, the position before the `(` is not where `555` lives,
the lookahead never fires, and the fictional number gets auto-redacted as
PII. API doc examples in that style would be mangled in scrubbed output.

Replace the negative lookahead with a capture-and-decide-inline approach:
extract the area code ($1) and exchange ($2), then check `$a eq "555" &&
$e =~ /^01/` inside a /e replacement.

Two Perl gotchas the new form has to handle:

1. **`$1`/`$&` aren't reliably accessible after the regex engine hands the
   replacement to the callback.** Snapshot into lexicals immediately.
2. **The inner `$e =~ /^01/` test resets `$&` to "01".** Without snapshotting
   `$&` before the inner match, the carve-out path returns just "01" instead
   of the whole original phone string.

The fix snapshots `$&`, `$1`, `$2` into `$w`, `$a`, `$e` *before* running
the inner regex, then uses `$w` (lexical copy of the whole match) for the
preserved path.

Verified against an expanded test matrix:

  REAL phones (redact):
    425-761-6499, (425) 761-6499, +1 425-761-6499, +1 (425) 761-6499,
    4257616499, 425.761.6499 — all → <REDACTED:phone-us>

  FICTIONAL 555-01XX (pass through):
    555-0142, 555-0100, (555) 012-3456, (555) 0123456, +1 555-012-3456,
    +1 (555) 012-3456, 5550123456, 555.012.3456 — all preserved

  OTHER PII (redact): emails, ZIP+4, Mailchimp inbox-id — all redact
  ALLOWLIST (pass through): @example.com, @example.net, @example.invalid
  HARD-FAIL (refuse to write): lin_api_*, {32-hex}-us\d{1,2} — all hard-fail

Comment + code update explain the Perl variable-lifetime trap so future
maintainers don't accidentally re-introduce it.

* fix(skills): preserve scrub-failed body files; reconcile inline-bodies principle with --body-file (Greptile P2 on #1595)

The retro skill's first scrub-body pass had two follow-up gaps Greptile flagged
on the re-review of d4d4c27f:

1. **The cleanup destroyed the recovery path it advertised.** The
   `scrub-failed` failure message tells the agent the body file is "left at
   $BODY_TMP for hand-redaction" — but the unconditional `rm -rf
   "$ISSUE_TMPDIR"` at the end of the loop wiped the file before the agent
   could read it. The recovery message was a lie.

   Fix: cleanup is now conditional on the scrub-failed count. If any WUs
   failed scrub, the temp dir survives so the body file is hand-redactable;
   the loop emits a NOTE to stderr telling the user where the surviving
   files are. The dir lives in `mktemp -d` so it self-cleans on the next
   `tmpwatch` / OS reboot regardless. Clean runs (no scrub-failed) wipe the
   dir as before.

2. **The "Execution principles" block forbade `--body-file`** because in
   the original design body construction via the `Write` tool added a
   per-WU tool round-trip — the single largest source of perceived
   latency. The new scrub_body step writes to a bash-resident temp file
   inside one `Bash` invocation, scrubs, then passes the scrubbed file to
   `gh --body-file`. There are no extra tool round-trips; the principle's
   *intent* (avoid Write-tool calls per issue) is still honored, but the
   wording ("never pass --body-file") read as forbidding the new approach.

   Fix: update the principle to specifically allow bash-resident temp files
   while still forbidding per-WU Write-tool round-trips. Adds a one-line
   explanation that `--body-file` is the natural consumer of the scrub
   step's file output.

Both fixes flow from Greptile's framing: "the hard-fail protection works,
but the recovery path it advertises is broken" and "the stale execution
principle contradicts the new --body-file approach." Confidence on the new
shape should land at 4-5/5 after the re-review.
caa68801 · 2026-05-17 · fix(cli): drop // PATCH marker instruction from generated AGENTS.md
The patches index manifest is the single recorded artifact for library-side
customizations. Pairs with the library-side relaxation at
mvanhorn/printing-press-library#644 which drops the verifier check
requiring bidirectional pairing between .printing-press-patches.json
entries and // PATCH source comments.

The template's "Local Customizations" section now describes a single step
(catalog the change in the patches manifest) rather than two (mark every
source site AND catalog). A closing note clarifies that inline // PATCH
comments are optional navigation aids if an agent wants them, but the CI
no longer requires them.

Golden fixtures updated for generate-golden-api and
generate-golden-api-rich-auth (the two cases whose expected AGENTS.md
include the customizations section); all 20 golden cases pass verify.

Existing printed CLIs keep their old AGENTS.md until they regen. No
retrofit needed because the library verifier (post-#644) doesn't check
the source markers either way.
875d64e9 · 2026-05-17 · fix(cli): detect partial-failure response shape in :mutate handlers, add --allow-partial-failure flag (#1360)
* fix(cli): detect partial-failure response shape in mutate handlers

Add --allow-partial-failure flag. Mutate envelope's success now depends
on both HTTP status and absence of body-level partial-failure (e.g.
Google Ads partialFailureError). Generic detector lives in helpers.go,
not coupled to one API: any 2xx body with a top-level
partialFailureError carrying a non-zero code or non-empty message is
flagged, results[].resourceName is extracted, and the typed exit
(code 6, distinct from apiErr's code 5) fires unless
--allow-partial-failure downgrades it to a stderr warning.

Detection runs once per mutate call before output-mode selection so
table, JSON envelope, --quiet, and raw paths all surface the same
exit code. partialFailureReport is emitted into the envelope under
partial_failure with field/message/code/details/resource_names so
agents can route per-operation remediation.

Runtime test in generator_test.go drops a *_test.go into a generated
Petstore CLI module and runs go test against the emitted
detectPartialFailure; this is the load-bearing safeguard that proves
the detector works on a Google-Ads-shaped body, not just that the
strings are emitted.

* fix(cli): enforce partial-failure exit on mutate raw/quiet output path

Codex review flagged a gap: when neither the wantsHumanTable nor the
asJSON/piped branch handled a mutate response, control fell through to
printOutputWithFlags without checking partialFailure. That meant
--quiet, --csv, --plain, and default terminal raw output would exit 0
on a detected partial failure even though the warning was printed to
stderr — same silent-swallow regression the patch is supposed to be
preventing for JSON consumers.

Wrap the fall-through call so the typed code-6 exit fires unless
--allow-partial-failure is set, matching the table and JSON paths.

* test(cli): update golden fixtures for partial-failure detection

Updated 18 golden cases to reflect the new emitted code:
  - helpers.go gains detectPartialFailure + partialFailureErr +
    partialFailureReport.
  - root.go gains the --allow-partial-failure persistent flag and the
    rootFlags.allowPartialFailure field.
  - mutate command handlers (POST/PUT/PATCH/DELETE) gain the detection
    block at the top of the response handling, partialFailure-aware
    envelope serialization, and the fall-through partial-failure exit
    guard so --quiet/--csv/--plain/raw output paths surface code 6 too.

Behaviour change is intentional and matches the patch in the prior two
commits.

* fix(cli): include allowPartialFailure in JSON envelope success

When --allow-partial-failure is set and a partial failure is detected, the
process exits 0 (the user opted in to allow it) but the JSON envelope was
still emitting success: false. Automated callers parsing the envelope to
decide whether to retry or alert would see a failure signal on an
intentionally-allowed partial result, disagreeing with the exit code.

Align the envelope's success expression with the exit-code semantics:
treat the request as successful when the status is 2xx AND there is no
partial failure OR the caller passed --allow-partial-failure. Regenerated
goldens mirror the template fix in every affected case.

---------

Co-authored-by: dior <agents@futureremodeling.com>
Co-authored-by: Trevin Chow <trevin@trevinchow.com>
80ba507e · 2026-05-16 · fix(ci): cancel-in-progress=false so cancelled check_runs don't pile up
Mirrors printing-press-library#625. With cancel-in-progress: true,
multi-event bursts (synchronize + review.submitted + multiple
review_comment.created within seconds) leave cancelled auto check_runs
behind that we can't PATCH away post-Feb 2025. Switch to
cancel-in-progress: false so queued runs execute serially and all
complete with terminal success/failure conclusions.
833213ff · 2026-05-16 · fix(cli): drive browser-sniff http_transport from HAR HTTP-version distribution (#1540)
* fix(cli): drive browser-sniff http_transport from HAR HTTP-version distribution

Pre-fix the browser-sniff parser wrote spec.http_transport = browser-chrome-h3
whenever reachability.mode was browser_clearance_http and the bare
browser-chrome enum whenever mode was browser_http, regardless of the HTTP
version the HAR actually recorded. Origins that serve H/2 but not H/3 (most
Cloudflare and Next.js + Vercel SaaS today) shipped CLIs that failed their
first live call with CRYPTO_ERROR 0x128 (remote): tls: handshake failure.

Adds a new browser-chrome-h2 enum + UsesBrowserHTTP2Transport predicate.
Captures HAR httpVersion on every entry, computes a per-target distribution
in TrafficAnalysisSummary, and maps the majority version to the matching
transport: H/3 -> browser-chrome-h3, H/2 -> browser-chrome-h2, H/1.1 ->
browser-chrome (no version force). Empty distribution falls back to bare
browser-chrome so the runtime negotiates rather than guesses.

The bare browser-chrome enum now means "no version force"; the implicit
HTTP/2 force from the pre-fix template requires opt-in via browser-chrome-h2.
EffectiveHTTPTransport's default-sniffed and browser-auth-for-HTML branches
return browser-chrome-h2 instead of bare browser-chrome so the implicit H/2
force is preserved for shipped CLIs that did not go through browser-sniff.

ApplyReachabilityDefaults now runs before applyHTTPTransportDefault so the
HAR-driven mapping wins for browser_http / browser_clearance_http modes.
browser_required intentionally leaves HTTPTransport empty since the operator
must drive a real browser.

Closes #1387

* fix(cli): allow --transport browser-chrome-h2 via the CLI flag

normalizeHTTPTransport's CLI-flag allow-list was the one place that did
not learn about the new browser-chrome-h2 enum. Operators passing
--transport browser-chrome-h2 hit the validator's reject path even
though the value is accepted by spec.Validate, catalog.Validate, and the
generator's enum predicates. Add it to the allow-list and extend the
error message and the existing test to cover the new value.

Refs #1387

* fix(cli): preserve implicit H/2 force on protection-driven transport path

applyHTTPTransportDefault writes spec.HTTPTransportBrowserChrome (bare,
no force after the template change) whenever trafficAnalysisRecommendsBrowserTransport
fires for non-reachability-mode signals: Cloudflare/DataDome/Akamai/PerimeterX
protections, html_scrape protocol, generic browser/scrape hints. Pre-PR the
template's else branch unconditionally emitted ForceHTTP2() for bare
browser-chrome; post-PR it emits neither, so specs flagged via those
heuristics lost their implicit H/2 force.

Switch this fallback to browser-chrome-h2 so the generated client still
forces HTTP/2 in the absence of HAR HTTP-version data. The reachability-
driven paths (browser_http / browser_clearance_http) keep using the HAR
distribution via ApplyReachabilityDefaults; explicit H/3 hints still win
over the protection default.

Refs #1387

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
63f745b8 · 2026-05-16 · fix(skills): split SQL example out of go-fenced block in NULL-safe scans guidance
Per Greptile review on PR #1530: the COALESCE example was appended
inside the same ```go fenced block as the Go snippets, so syntax
highlighters, AI tools that read SKILL.md, and lint passes that
validate fenced blocks would all interpret the bare SELECT as Go.
Move the SQL into its own ```sql fenced block with a short
introductory sentence, leaving the Go snippets self-contained.
f7365c26 · 2026-05-16 · fix(ci): close jq if-then-else with end so >10-thread path doesn't crash
Mirrors printing-press-library#623: outer if in the listing jq filter
was missing 'end'. jq emits a parse error and exits non-zero; set -e
bails the shell before the step summary and ::error:: annotation can
write, so authors see a cryptic jq error instead of the thread list.
94332417 · 2026-05-16 · fix(ci): use job exit-code instead of POST/PATCH for check_run state
Mirrors printing-press-library#623 redesign. POST/PATCH approach
hits HTTP 403 in CI as of Feb 2025: GitHub Actions runtime rejects
workflow-side modification of check_run status/conclusion. Switch
to relying on the auto-created check_run for the job (its conclusion
mirrors the job's exit status) and exit 1 when threads are unresolved.

Net: simpler workflow, no API calls, no duplicates, behavior matches
the post-Feb-2025 GitHub Actions runtime.
c96ac5da · 2026-05-16 · fix(cli): writeThroughCache caches single-object responses keyed by non-id PKs (#1531)
* fix(cli): writeThroughCache caches single-object responses keyed by non-id PKs

writeThroughCache guarded its single-object cache write with
`if _, ok := envelope["id"]; ok` — APIs whose primary key is named
CertNo / sku / invoiceId / etc. silently fell through every lookup.
The user saw HTTP 200 and correct stdout while every downstream
feature that reads from the local SQLite store (smart presets,
holdings analysis, offline search) got no data.

Drop the hardcoded "id" guard and delegate primary-key resolution
to UpsertBatch's existing resourceIDFieldOverrides path, which the
parser already populates from `x-resource-id` and the response-schema
inference chain.

Tightened the guard to skip list-shaped envelopes whose array
happened to be empty — `{"items": []}` must not write a row keyed
by the whole envelope. Caught by TestClientBasePathLiveRequest on
the first pass; explicit regression added.

Closes #1439

* fix(cli): verify list-wrapper field is an array before skipping cache write

Greptile flagged that the list-envelope guard checked for KEY presence
only — any detail object whose own field happened to be named data,
results, or items (with a scalar/object/null value) would be treated
as an empty list envelope and silently dropped. That regressed the
prior envelope["id"] path, which would have cached the row.

Tightened the guard to verify the value at the wrapper key actually
unmarshals as a JSON array. A scalar-valued field with a colliding
name is a regular response field, not a list envelope, and the row
still goes through UpsertBatch.

Added TestWriteThroughCacheCachesObjectWithListWrapperFieldName as
explicit coverage for the collision case Greptile called out.

* fix(cli): distinguish JSON null from empty array on list-wrapper field

Greptile noted that json.Unmarshal("null", &arr) succeeds with arr
left nil, so the previous unmarshal-only check would misclassify
{"CertNo":"x","items":null} as an empty list envelope and silently
drop the row. Require arr != nil so true empty arrays stay in the
skip branch while JSON null falls through to UpsertBatch as a
regular field collision.

Added TestWriteThroughCacheCachesObjectWithNullWrapperFieldName as
the missing coverage Greptile called out.

* chore(cli): empty commit to force CI rerun after flaky text file busy

* fix(cli): require list envelope to be fully metadata-shaped before skipping

Greptile flagged round-3: a detail object whose own field happened to
be named items/data/results AND holds an empty array (e.g.
{"id":"order_123","items":[],"status":"pending"}) was being treated
as an empty list envelope and silently dropped. The previous "any
wrapper key with array value" heuristic was too permissive.

Switch to a structural check: an envelope is list-shaped only when
EVERY top-level key is either the wrapper itself (results/data/items)
or one of a known pagination-metadata key (next_cursor, has_more,
total, links, meta, response_metadata, etc.). A single non-metadata
key signals real per-row data and the row gets cached.

Codifies the metadata allowlist as a package-level var so it stays
auditable. Adds explicit regression tests for the multi-key detail
shape and for the real list-envelope-with-metadata shape.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
5b8a8141 · 2026-05-16 · fix(ci): scope settle delay to synchronize, strip head_sha from PATCH
Mirrors Greptile feedback addressed on printing-press-library#623:

P1: head_sha is valid in POST /check-runs but is not a valid body
parameter for PATCH /check-runs/<id>. If GitHub strictly validates
and 422s the unknown field, the PATCH would fail and set -e bails.
Strip head_sha for the PATCH branch via jq del().

P2: settle delay fired for every pull_request_target action. Only
synchronize moves the commit pointer and triggers GitHub's async
thread auto-resolution, so only synchronize can race it. Gate the
delay on action=synchronize to avoid an unnecessary 8s wait on PR
opens and draft transitions.
162d9a32 · 2026-05-16 · fix(ci): conversation-resolution check race + duplicate check_run
Three flaws in the workflow shipped with this PR that printing-press-library
#587 surfaced (then closed in mvanhorn/printing-press-library#623). Backing
the same fixes into the cli-printing-press copy before this merges:

1. Race condition. synchronize fires the moment a push lands, but GitHub
marks review threads outdated/resolved asynchronously based on the new
file content. Querying immediately races that resolution and can report
stale 'unresolved' for a thread that is about to flip resolved a second
later. Add 8s settle delay on pull_request_target events specifically.

2. Job name collision. The job was named the same as the user-facing
check ('All conversations resolved'), so GitHub Actions auto-created a
check_run with that name reflecting only the job's exit status (always
success). Our explicit POST created a SECOND check_run with the same
name reflecting actual thread state. Both showed up on the SHA. Rename
the job to 'Evaluate review threads' so the auto-created check_run has
a distinct internal name and stays out of the merge widget.

3. Duplicate check_runs across runs. Every workflow run POSTed a new
check_run rather than updating, so a stale failure could sit next to a
fresh success indefinitely. Switch POST to PATCH-if-exists keyed on
(name=All conversations resolved, app=github-actions).

After this lands the merge widget shows exactly one
'All conversations resolved' entry per PR, with state always matching
the latest workflow run.
f55f57a8 · 2026-05-16 · fix(ci): address Greptile review on conversation-resolution check
Three findings from Greptile on this PR:

1. (P1) Failure summary cited the Mergify condition by name in
.mergify.yml, but #1536 has not merged so that condition does not
exist on main yet. Replaced with a repo-convention message accurate
both today and after #1536 lands.

2. (P2) The --arg PR_NUMBER binding was passed to jq but no longer
referenced in the listing function (I removed the use in the
cli-printing-press port but left the binding). Dead arg, dropped.

3. (P2) The draft-PR guard only checked pull_request_target events,
so reviews and comments on draft PRs still fired the workflow.
Rewrote the guard to skip drafts across every PR event source while
allowing workflow_dispatch through as an explicit manual ask.
21ae8a54 · 2026-05-16 · feat(ci): surface unresolved review threads as a status check
Ports the conversation-resolution-check workflow from the downstream
library repo (mvanhorn/printing-press-library#620, #621). The gate
itself is enforced by Mergify (#1536 adds the
`#review-threads-unresolved = 0` condition to .mergify.yml). This
workflow is the visibility layer.

Why both: Mergify's existing `Mergify Merge Protections` check_run
is the most readable surface for "what's missing" after a maintainer
applies `ready-to-merge`, but pre-label it just says "skipping" with
no specific signal about thread state. An author who pushed a fix
but didn't click "Resolve conversation" sees green CI, green Greptile
Review, and no obvious cue. This workflow puts an explicit
"All conversations resolved" check_run in the status list regardless
of label state.

Lifecycle coverage: pull_request_target for new commits,
pull_request_review for new reviews from Greptile, and
pull_request_review_comment for new inline findings.
concurrency.cancel-in-progress coalesces bursts. Workflow_dispatch
provides a manual escape hatch.

Note: GitHub Actions does NOT support pull_request_review_thread as
a trigger event, so clicking "Resolve conversation" in the UI does
not auto-fire this workflow. The check refreshes on the next push,
review, or comment. This gap is documented inline in the workflow
file. (Library repo #621 was the hotfix that taught us this.)
a8fa80a3 · 2026-05-16 · fix(ci): require all review threads resolved before queue + merge
Mergify's queue_conditions and success_conditions both gate on the
Greptile Review check_run being success/neutral/skipped, but that
check_run only reflects the confidence score — it does not track
whether Greptile's inline P0/P1 findings have actually been resolved.
So a PR with unresolved review threads can today:

1. Pass all CI checks (build-and-test, generated-test, etc.)
2. Pass Greptile Review (score >= threshold)
3. Get labeled ready-to-merge
4. Auto-merge via Mergify, with the findings still open

PR #1514 is the canonical example today: mergeStateStatus=CLEAN with
one unresolved Greptile thread. The downstream library repo had the
same gap and closed it via a ruleset rule + a visibility check_run
(mvanhorn/printing-press-library#620, #621). This repo uses Mergify
instead of rulesets, so the equivalent fix is a Mergify-native
condition.

Adding `#review-threads-unresolved = 0` to both queue_conditions and
success_conditions means:

- Mergify won't queue a PR with unresolved threads
- Mergify won't merge a PR that picks up new findings during the
  in-place queue re-run
- Mergify's status comments will explicitly cite the unresolved
  threads as the blocker, so authors see what to do

Release-please PRs are bot-generated and reliably have zero review
threads, so the condition passes them through transparently — no
exemption needed for the existing release-please branch pattern.
4e304df5 · 2026-05-16 · fix(cli): scope-aware sync --param dispatch with --global-param fallback (#1529)
* fix(cli): scope-aware sync --param dispatch with --global-param fallback

Asana, Jira, GitHub, and similar APIs reject path-scoped dependent
requests when a top-level scope param is re-injected on top of the path
context (e.g. /projects/<gid>/tasks?workspace=<gid> trips Asana's
"Must specify exactly one of project, tag, ..." error). The sync
command's --param flag injected indiscriminately into every request,
forcing a manual two-phase workaround.

Split syncUserParams.global into flatGlobal (--param) and trueGlobal
(--global-param). applyTo gains an isDependent bool: dependent
path-scoped calls skip flatGlobal but still apply trueGlobal and
per-resource params. Existing single-phase syncs on APIs without
dependent resources behave identically.

Operators who relied on the old apply-everywhere semantic opt back in
with --global-param key=value.

Closes #1393

* refactor(cli): rename parseSyncUserParams perResourceFlags param

Make the parameter name in the helper signature match the call-site name resourceParamFlags. No behavior change; just removes a name-mismatch readability snag inside the function body.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
7396d66f · 2026-05-16 · fix(skills): add NULL-safe SQL scan guidance to Phase 3 store-query starter
Novel-feature commands authored against generated typed FTS/upsert
tables or against json_extract on the resources blob silently drop
every row whose scanned column is NULL. `database/sql`'s `rows.Scan`
into a bare `string`/`int64`/`float64` returns a non-nil error on NULL
("converting NULL to string is unsupported"), and the conventional
`for rows.Next()` loop continues past scan errors — so the query
returns zero records, no error reaches the caller, and the feature
looks healthy because the upstream API call succeeded.

The Phase 3 store-query RunE skeleton in skills/printing-press/SKILL.md
documents the resources-table-keyed query pattern but says nothing
about NULL handling. Add an inline scan-comment in the skeleton and a
parallel-shape "NULL-safe SQL scans MUST use sql.Null* targets (or
COALESCE) for any column that can be NULL" paragraph after the
streaming-frame normalizers callout, with right/wrong code snippets.

The generator does not emit per-resource typed query helpers
(writeThroughCache stores opaque JSON via UpsertBatch; resolveLocal
reads opaque JSON), so the issue's `comp:generator` framing was off —
the fix surface is the SKILL prompt that drives Phase 3 novel-feature
authoring.

Closes #1438
Refs #1469 (NULL-safe SQL sub-bullet addressed here; the
helper-enumeration sub-bullet remains open under that issue)
c31632b3 · 2026-05-16 · feat(skills): add /printing-press-amend skill — dogfood + direct-input modes (#1490)
* feat(cli): add verify-internal-skill subcommand

Lints internal-skill SKILL.md files (frontmatter + canonical sections).
Distinct from verify-skill, which validates a printed CLI's SKILL.md
against its Go source — internal skills (polish, retro, publish, amend)
have no internal/cli/ to verify against.

Checks: frontmatter-parse, frontmatter-required (name, description,
allowed-tools), name-matches-dir, allowed-tools-shape, body-has-heading
(warn). All three existing internal skills pass cleanly.

* feat(skills): scaffold printing-press-amend skill

New skill that wraps the dogfood-to-PR loop for a printed CLI in
mvanhorn/printing-press-library. Mines the active session transcript
for friction, scopes with the user, plans + executes the fix, scrubs
PII, opens a PR. Two user-in-loop checkpoints (scope, PR draft).

This commit lands the SKILL.md skeleton (frontmatter + setup contract +
phase-header placeholders) plus the brainstorm requirements doc and
implementation plan that drove it. Phase bodies (U2-U7) land in
follow-up commits.

Adds skills/printing-press-amend/SKILL.md to the
TestSkillSetupBlocksMatchWorkspaceContract test slice — setup-contract
parity with publish/score/catalog enforced.

* fix(cli): use strings.SplitSeq in verify-internal-skill

Satisfies golangci-lint modernize hint. Pure refactor — same behavior,
no test changes needed.

* feat(skills): flesh out printing-press-amend phase bodies + references

Adds the substantive Phase 1-7 bodies to skills/printing-press-amend/
SKILL.md, plus three reference files:

- transcript-parsing.md (Phase 1: read active session transcript,
  extract friction signals, classify bug-vs-feature, auto-detect
  target CLI, confirm with user)
- pii-scrubbing.md (Phase 5: three-layer scrub — credentials reused
  from retro/secret-scrubbing.md, entities from a user-maintained
  stop-list at ~/.printing-press/amend-config.yaml, plus first-mention
  defense for unrecognized capitalized phrases)
- library-pr-plumbing.md (Phase 6+7: managed-clone bootstrap, branch
  collision detection, issue ownership, push + gh pr create with
  durable HEAD_SHA evidence URLs — adapted from publish Steps 5/7/8)

Phase 4 operates directly on the managed clone of mvanhorn/printing-
press-library at $PRESS_HOME/.publish-repo-$PRESS_SCOPE (per the
plan's pre-implementation decision), enforces the public library's
mandatory `// PATCH(...)` source-comment + .printing-press-patches.json
contract, and runs `printing-press publish validate` with up-to-3
retry iterations.

Two user-in-loop checkpoints: scope confirmation after capture (U4),
PR draft review before any gh command fires (U7).

* docs(cli): add /printing-press-amend to README skill catalog

One-line entry under Publish, in the same details/summary shape as the
other skills.

* feat(skills): expand printing-press-amend frontmatter for direct-input mode

Broaden description to cover both dogfood and direct-input input modes.
Add trigger phrases for user-supplied asks (rename, add feeds, sniff for
new APIs, amend with these ideas).

U1 of docs/plans/2026-05-16-001-feat-printing-press-amend-direct-input-mode-plan.md

* feat(skills): add Phase 0 input mode detection to printing-press-amend

Insert a new "## Phase 0 — Input Mode Detection" section between Setup
and Phase 1. Documents the detection rubric (dogfood, direct, both,
ambiguous), the AskUserQuestion fallback, the default-dogfood preservation
rule, and the runstate persistence path. Phase 1's existing dogfood body
is untouched; U3 introduces the direct-input sub-section.

U2 of docs/plans/2026-05-16-001-feat-printing-press-amend-direct-input-mode-plan.md

* feat(skills): split printing-press-amend Phase 1 into mode-conditional sub-sections

Rename "## Phase 1 — Friction Capture" to "## Phase 1 — Capture" and
split into ### 1a (dogfood, existing body lifted verbatim) and ### 1b
(direct-input, new). Document the shared typed finding list shape with
new "provenance" field. Reserve ### 1b.i for the sniff subroutine
(filled in by U4).

transcript-parsing.md gets a scope note pointing to direct-input-parsing.md
for the new mode; its body is unchanged.

U3 of docs/plans/2026-05-16-001-feat-printing-press-amend-direct-input-mode-plan.md

* feat(skills): add sniff finding subroutine to printing-press-amend Phase 1b

Document the opt-in sniff path that runs printing-press crowd-sniff (and
optionally browser-sniff with a user-supplied HAR) against the target
CLI's source URL, then converts each discovered candidate endpoint to a
Tier-3 add-endpoint finding with provenance: sniff.

Includes the six steps (resolve URL, crowd-sniff, optional browser-sniff,
convert to findings, degraded-path table, provenance surface at Phase 3).
Sniff is gated on an explicit kind: sniff ask — never auto-invoked.

U4 of docs/plans/2026-05-16-001-feat-printing-press-amend-direct-input-mode-plan.md

* feat(skills): add direct-input-parsing reference for printing-press-amend

New reference doc loaded by Phase 1b. Documents the ask-to-finding
parsing rubric (six finding kinds), the finding shape (with new
provenance field), target-CLI resolution rules (regex extraction + Phase 0
fallback), and edge cases (multi-CLI, ambiguous verbs, bare URLs,
conflicting kinds, combined-mode merging).

Mirrors transcript-parsing.md structure so Phase 1a and Phase 1b reference
docs feel parallel.

U5 of docs/plans/2026-05-16-001-feat-printing-press-amend-direct-input-mode-plan.md

* docs(skills): v0.2 addenda to amend brainstorm + plan; add direct-input plan

Append a v0.2 amendment section to the original brainstorm and original
v0.1 plan pointing at the new direct-input plan. Preserves both originals
as the dogfood-mode design record; the v0.2 design (input-mode detection,
direct-input parsing, sniff finding type) lives in its own plan file.

Add docs/plans/2026-05-16-002-feat-printing-press-amend-direct-input-mode-plan.md
covering U1-U6 of the v0.2 expansion. Sequence number 002 to avoid
collision with the parallel-session bugbounty-goat plan filed today.

U6 of docs/plans/2026-05-16-002-feat-printing-press-amend-direct-input-mode-plan.md

* fix(skills): count only newly-added PATCH markers in printing-press-amend parity check

Greptile P1: the parity check used grep -rc to count // PATCH(...) markers
across all Go files in $CLI_DIR, including markers from prior amend runs.
That cumulative count compared against the per-run declared patch_count
silently passed when prior history made the running total meet or exceed
the declared count, even with zero new markers added.

Switch to git format-patch --stdout + grep '^+.*// PATCH(' so the count
reflects only newly-added markers in this run's diff against upstream.
format-patch is used over git diff to stay robust against environments
where git diff is intercepted by a pager/shim that reformats unified-diff
output.

Resolves Greptile finding on PR #1490.

* fix(skills): relabel printing-press-amend PR-body Evidence block

Greptile P1: the Evidence block labeled .printing-press-patches.json as
"Plan doc" and the next line said "see the plan doc at the path above"
- the URL points at the patches JSON, not the plan doc, which lives
locally at $PRESS_MANUSCRIPTS/<slug>/<run-id>/proofs/... and is never
committed to the public library.

Relabel the URL as "Patch record", point per-finding rationale at the
Findings table + patch record, and note the local plan doc location as
context for the original printer (not as a clickable artifact for
external reviewers). The plan doc stays local by design - it's a
PII-scrubbed audit record, not part of the PR contract.

Resolves Greptile finding on PR #1490. Origin R27's requirement for a
full GitHub URL to the plan doc is unsatisfiable as written and is
silently revised here; flag for retro follow-up.

* fix(skills): hard-stop existing-open-PR path in library-pr-plumbing

Greptile P2: when existing_open was non-empty the snippet printed a
warning and a # AskUserQuestion: ... shell comment, then unconditionally
ran git checkout -b "$BRANCH_NAME" - which fails with a confusing
already-exists error because the local branch from the open PR exists.

Replace the inert comment with a hard exit 1, a concrete two-option
resolution menu printed to the user, and a follow-up prose block that
documents the AskUserQuestion-then-re-enter contract the skill driver
must honor. Literal shell-flow execution now stops at the right place
with an actionable message.

Resolves Greptile finding on PR #1490.

* fix(cli): mark --dir as required on verify-internal-skill

Greptile P2: --dir was validated via a manual `if dir == ""` check in
RunE, which works but doesn't surface the constraint in Cobra's --help
output and runs the validation later than necessary.

Replace with cmd.MarkFlagRequired("dir") after the StringVar
declaration. Missing --dir now produces "required flag(s) \"dir\" not
set" via Cobra's standard flow and the flag is annotated as required
in --help output. The manual check is removed as redundant.

Resolves Greptile finding on PR #1490.

* fix(skills): make 90-days-ago date portable in printing-press-amend

Greptile P1: `date -v-90d` is BSD/macOS-only. On Linux it emits
"date: invalid option -- 'v'" to stderr and produces empty stdout,
leaving the GitHub search qualifier as `merged:>` with no value.
The recently-merged-PR dedup guard then silently returned no results,
defeating Phase 2a's purpose on any non-macOS machine.

Replace with a three-way fallback: GNU `date -d '90 days ago'` first,
BSD `date -v-90d` second, python3 timezone-aware UTC date as final
fallback. Hard exit 1 if all three fail rather than letting the dedup
guard silently drop out.

Resolves Greptile finding on PR #1490.

* fix(skills): assign dogfood_status=N/A in direct-input mode

Greptile P1 (re-review 18:50): the PR body template printed `- Dogfood:
$dogfood_status` and the Phase 8 RESULT block included `dogfood_status:
<PASS|FAIL|N/A>`, but Phase 4's output spec omitted the variable
entirely and no phase instruction assigned it in direct-input mode.
Every PR from a direct-input run would show an empty `- Dogfood:` line.

Add dogfood_status to Phase 4's output spec with a per-mode contract:
  - MODE=dogfood: PASS|FAIL from the dogfood validation step
  - MODE=direct:  always N/A (no transcript to dogfood against)
  - MODE=both:    PASS|FAIL on the transcript half of the findings
Default must be set by end of Phase 4 so Phase 7/8 never see empty.

Also add defensive ${dogfood_status:-N/A} in the PR body template as
belt-and-suspenders against any future phase forgetting to assign it.

Resolves Greptile finding on PR #1490.

* fix(skills): force-checkout main on managed-clone refresh

Greptile P1 (x2, SKILL.md:460 + library-pr-plumbing.md:86): if a prior
run aborted between Phase 4's file edits and Phase 7's commit, the
managed clone is left on an amend branch with uncommitted changes in
$CLI_DIR. The refresh block's `git checkout main` then fails because
those edits would be overwritten, and the subsequent `git reset --hard
upstream/main` never runs - leaving the clone stuck in a broken state.

Add -f to discard local edits. The managed clone is documented as a
scratch surface owned by the skill; any leftover edits are by definition
abort residue that must be discarded before the next run reuses it.
This is consistent with the existing reset --hard immediately after.

Resolves Greptile finding on PR #1490.

* fix(skills): use working-tree git diff for parity check (not format-patch)

Greptile P1: my prior G1 fix used git format-patch --stdout
upstream/main..HEAD, but the parity check runs in Phase 4 Step 6 -
BEFORE Phase 7's commit. The edits live only in the working tree, so
upstream/main..HEAD is an empty commit range and format-patch emits
nothing. new_patch_markers is always 0:

  - When patches_entry > 0 (any real patch run): 0 < patches_entry is
    true and exit 1 fires unconditionally, blocking every valid run.
  - When patches_entry = 0: the check silently passes regardless.

Switch back to working-tree git diff (the right tool for pre-commit
state). Add --no-pager + --no-color + --no-ext-diff to defeat
colorized output and any configured diff.external tool that would
reformat the diff away from unified-diff shape.

Smoke-tested the corrected snippet against a fresh repo with uncommitted
PATCH-bearing edits: returns 1 for the 1 new marker, as expected.

Resolves Greptile finding on PR #1490 (refines G1's prior fix).

---------

Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com>
Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
c10d0b55 · 2026-05-16 · fix(cli): move extra_commands SKILL.md block to its own top-level section (#1524)
* fix(cli): move extra_commands SKILL.md block to its own top-level section

extra_commands declared in internal-YAML specs (shopify, producthunt,
…) used to render under a **Hand-written commands** subsection nested
inside ## Command Reference. The Cobra emitter never reads the field,
so those rows were promises the generator could not back. verify-skill
walks ## Command Reference for inline backticks shaped like
`<binary> <cmd>` and correctly fails the unknown-command check on
every entry.

Lift the block into its own top-level ## Hand-written Extensions
section with an explainer line that says they require separate
wiring. verify-skill's _extract_inline_commands is scoped to the
Command Reference body (regex in scripts/verify-skill/verify_skill.py),
so a sibling section is invisible to the unknown-command walker.
Generating from catalog/specs/producthunt-spec.yaml and running
`printing-press verify-skill --dir <out>` now exits 0.

Closes #1451

Sweep tracking issue for already-published CLIs (shopify, producthunt):
mvanhorn/printing-press-library#616

* fix(cli): place Hand-written Extensions after Finding the right command

Greptile flagged that inserting `## Hand-written Extensions` between
the Command Reference body and Freshness Contract silently reparented
`### Finding the right command` under the new section for any CLI
with extra_commands but no Freshness Contract (extra_commands +
HasDataLayer=false case).

Markdown nests every `###` under the most recent `##`, so the fix is
positional: render the Extensions block after the `### Finding the
right command` subsection (and before `## Recipes`). `### Finding`
stays a child of `## Command Reference` for every combination of
ExtraCommands + Freshness state. Added a regression assertion that
locks the relative ordering.

End-to-end re-verified: producthunt regens with `## Command Reference`
→ `### Finding the right command` → `## Hand-written Extensions` →
`## Auth Setup`, and verify-skill still exits 0.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
99637941 · 2026-05-16 · fix(skills): require codex completion marker before treating delegation as success (#1523)
* fix(skills): require codex completion marker before treating delegation as success

Codex `exec` can exit non-zero or be killed mid-run (sandbox abort, OOM,
SIGINT, internal toolchain crash) and leave partial work behind that
looks identical to a successful end-of-prompt exit. The existing
post-codex validate step only checks `go build && go vet` and a
non-empty `git diff`, both of which can pass against partial output, so
the parent skill silently treats partial completion as success and
proceeds to the next priority task with the partial files in tree.

Each of the four prompt templates now ends with a COMPLETION MARKER
section instructing Codex to write `_codex-result.json` (with
`{status,files_written,timestamp}`) only after VERIFY succeeds. The
Delegate step removes any stale marker before the codex invocation so a
file from a prior task can't fool the next one, and the Validate step
treats missing-or-not-complete marker as a Codex failure that falls
through to the existing revert + Claude-fallback path and feeds the
circuit breaker.

Closes #1288

* fix(skills): make completion-marker validate snippet self-describing on failure

Per Greptile review on PR #1523: the previous validate snippet chained
the marker check and the build step with `&&`, so a missing/incomplete
marker exited non-zero silently with the same exit code as a build
failure. The surrounding prose told the agent to surface a specific
error message, but the snippet itself never printed it, leaving the
agent to second-guess which arm failed.

Rewrite both Validate snippets (Phase 3 step e, Phase 4 step 5) as an
`if` block that echoes the exact `codex output marker missing` message
to stderr before exiting non-zero. The build/vet branch is unchanged.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
82ad787b · 2026-05-16 · fix(cli): cap body-flag recursion depth to prevent compiler OOM (#1522)
* fix(cli): cap body-flag recursion depth to prevent compiler OOM

Deeply nested OpenAPI request bodies (Tripletex, NetSuite, SAP S/4HANA, and
similar enterprise specs) produced POST/PUT command files with 40k+ lines as
the body-flag emitters recursed through every nested object. The Go compiler
ran out of memory (signal: killed) before finishing the package.

Caps recursion at maxBodyFlagDepth = 3 across the four body-emitter helpers:
renderBodyMap, renderBodyVarDecls, renderBodyFlagRegs, renderBodyRequiredChecks.
When the next depth would meet the cap, the object's subtree is skipped
uniformly across all four; deeper fields are reachable via the existing
--stdin flag on POST/PUT/PATCH commands.

The --stdin flag's help text is rewritten when truncation fires so an
operator inspecting --help sees the affordance without reading the issue
tracker. Behavior for shallow specs (<= 2 levels of nesting) is unchanged
across all 20 golden fixtures.

Closes #1240
Refs #1520

* fix(cli): walk flattened body for depth-cap truncation signal

bodyExceedsFlagDepth read endpoint.Body directly, but the four emitters
walk flattenCollidingBodyFields(endpoint.Body). When dot-flattened
identifier collision clears an object's Fields, the emitters treat that
subtree as a JSON-string leaf and never recurse past it, so no depth-cap
truncation actually occurs. The predicate, however, still saw the
original deep structure and returned true, rewriting the --stdin help
text to the truncation-warning variant even though every field was
exposed as a per-field flag.

Walk flattenCollidingBodyFields in the predicate so detection and
emission cannot drift. Adds a regression test for the
collision-flattened deep subtree case.

Refs #1240

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
0c3c8bcc · 2026-05-16 · fix(cli): detect integer page paginator and advance numerically in sync (#1519)
* fix(cli): detect integer page paginator and advance numerically in sync

OpenAPI specs that paginate by integer ?page=N (Freshworks family,
Atlassian Cloud, HubSpot, ~30-40% of REST APIs) used to fall through
detectPagination's "after" cursor default, so the generated sync loop
tried to extract a body cursor that never existed and terminated after
page 1.

The OpenAPI parser now recognizes page / page_number / pageNumber /
page[number] as a Type="page" paginator after the existing
cursor/token/offset branches (cursor wins on mixed-form specs). The
sync template adds a runtime fallback: when cursorParam == "page" and
no body cursor is extracted but the page is full, advance the integer
counter so subsequent pages are fetched. Mirrored in the
dependent-resource sync loop for parity.

Link-header pagination (the other case called out in #1296) is a
separate code path (HTTP header parsing rather than body extraction)
and stays a follow-up.

Closes #1296

* fix(cli): guard page-int sync fallback on cursor type, not param name

Greptile flagged that the original guard `pageSize.cursorParam == "page"`
only fires for APIs that literally name the param `page`. The parser
also recognises `page_number`, `pageNumber`, and `page[number]` and
preserves their original case in CursorParam, so those three variants
would silently skip the fallback and still truncate after page 1.

Plumb the paginator class through the runtime: PaginationProfile gains
CursorType (aggregated from endpoint.Pagination.Type), determine-
PaginationDefaults emits both cursorParam (request-key name) and
cursorType ("page"/"cursor"/…) into paginationDefaults, and the two
fallback blocks compare on cursorType so every canonical spelling
shares the same guard.

Generator test is now parametrised over all four spellings.

---------

Co-authored-by: mergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
ff562375 · 2026-05-16 · fix(cli): drop MCP code-orch handler pre-marshal that base64-encoded mutating bodies (#1521)
Sibling fix to #1357. The code-orchestration MCP handler template
(mcp_code_orch.go.tmpl) had the same defect the endpoint-mirror template
already fixed: POST/PUT/PATCH branches json.Marshaled `params` into a
[]byte, then handed the []byte to c.Post/Put/Patch as the body. The
generated client.do() then json.Marshaled the []byte again, which
encoding/json base64-encodes into a quoted string. Strict APIs reject
the payload with errors like 'Request data must be a JSON object, not a
string'.

Pass `params` (map[string]any) directly to c.Post/Put/Patch and let
client.do() do the single marshal pass. The intermediate marshal-error
branch is removed; client.do() already wraps any marshal error with the
same "marshaling body" prefix (client.go.tmpl:878).

Add TestMCPCodeOrchPassesParamsMap mirroring TestMCPHandlerPassesBodyArgsMap
to pin the orchestrator emission shape: no json.Marshal(params)
intermediate, and the literal forms c.Post(path, params),
c.Put(path, params), c.Patch(path, params).

Golden fixture mcp-cloudflare/internal/mcp/code_orch.go updated in
lockstep per AGENTS.md "Generator Output Stability".

Closes #1426.

File tree

3310 files tracked. Click any to browse the source at HEAD.

Other build journals

← Claude Webdev Accelerator  ·  all 4 projects  ·  Clipreviewbydave →

Export

commits.csv · feed.atom · project.json · commits.json

rendered in 10ms