@@ -4,10 +4,10 @@
# Changelog
## Unreleased
- Make Tune shell-free across platforms by running `.pi/tune/benchmark.mjs` with Pi's Node executable and using checked direct Git calls for discard
- Remove the `mode`, `shame`, `ssh-tools`, and `terminal-signals` extensions
-- Add an `/overkill aftermath` design for improving one confirmed skill from all past Pi sessions, with checkable task mining, deterministic checks plus LLM rubric fallback, hash-split validation, strict no-tie acceptance, resumable staged results, and no automatic adoption or scheduling
+- Add an `/overkill aftermath` design for improving one confirmed skill from all past Pi sessions, with checkable task mining, deterministic checks plus LM rubric fallback, hash-split validation, strict no-tie acceptance, resumable staged results, and no automatic adoption or scheduling
- Fix Overkill Aftermath persistence on Windows by retrying transient `EPERM` atomic file replacements
- Fix npm audit's moderate `protobufjs` vulnerability by updating the root lockfile entry to 7.6.5
- Add a read-only `modernize` prompt and skill for auditing repositories against the latest Pi changelog and APIs, using resolved Pi package versions to scope the migration window
@@ -37,6 +37,8 @@
`web_search`), while the step `tools` allowlist stays the only gate on what is
active and ultra's own `workflow` tool is stripped from every sub-agent
allowlist (recursion defense); set `"none"` to keep sub-agents on core tools
+- Expose Ultra's inline workflow schema to calling agents so they can construct workflows without reading Ultra's source code
+- Improve Ultra inline workflow guidance with exact interpolation rules, reject duplicate or reserved phase IDs, and support the `max` thinking level and tier suffix
- Add ultra `modelTiers` setting so workflow steps can use `small`, `medium`, or
`big` aliases, with unset tiers falling back to the session model and optional
thinking suffixes such as `openai/gpt-5-mini:low`; bundled workflows assign
@@ -162,10 +164,17 @@
- Fix leaks assignment detection so code references such as `loadToken(email)`,
template expressions, property chains, and CamelCase type-like values are not
redacted into `__LEAK_*__` placeholders
+- Reduce leaks false positives by validating JWT contents, matching complete
+ sensitive query and cookie names, requiring provider-shaped assignment values,
+ ignoring environment metadata and context-only names, and bounding PuTTY
+ private-key redaction to its declared payload lines
- Fix leaks hydration for tool-result `content` and `details` so redacted
provider-context placeholders are restored before local display/session storage
- Keep leaks provider redaction active when a stale UI context is encountered
during provider request status/notification updates
+- Add a precision-first leaks reliability design with structurally validated detectors, durable encrypted placeholder mappings across reloads and resumes, fail-open redaction, user-visible diagnostics, blocked unknown placeholders, and a dedicated two-minute fuzz suite
+- Persist authenticated leaks placeholder mappings in session history so they survive reloads, resumes, and branch navigation; block unknown or incompletely inspected tool placeholders and fail open with diagnostics when mappings cannot be stored
+- Fix leaks reliability by rejecting mappings that failed to persist, preserving literal placeholders while maintaining the leaks extension, and tightening age and Minisign secret-key validation
- Add the super `mockup` tool for browser-based visual-option feedback with a
minimal title/question/options/multi schema, fragment-only validation,
blocking browser submit, selectable cards, annotations/global notes tabs,