Completes the prose-CLI scrub the spec already documents as shipped: deletes tools/cli (the @openprose/prose-cli Oclif binary + eval harnesses), drops tools/cli from the workspace and lockfile, and removes the separately-authored `### Criteria` section from the reactor and reactor-cli contract loaders (postconditions live solely in `### Maintains`). Updates the accompanying skill tests, changelog, and release docs. Verified green: reactor SDK 458/0/10, reactor-cli 186/1 (pre-existing doctor test), devtools 96/0, skill 413/0.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(cli): typecheck repository-reactor-bridge test against branded Receipt fields
#106 hard-branded the reactor Receipt identity fields (node: NodeId,
contract_fingerprint / fingerprints: Fingerprint) and added this bridge test in
the same commit, constructing the Receipt fixture from raw strings — so the test
was born failing tsc. CLI Release Check only runs on tools/cli + release-script
paths and main has no required checks, so #106 merged with the typecheck red and
it stayed hidden (no cli-path change re-ran the check) until a release-infra PR
surfaced it.
Author the fixture with the same brand constructors the production bridge uses
(asNodeId / asFingerprint from @openprose/reactor/internals). The constructors are
identity-at-runtime brands, so behavior is unchanged: the affected test passes
10/10 and tsc is clean.
Note: this unmasks a SEPARATE pre-existing failure, also from #106 — the
repository-ir compiler fixtures were regenerated with kind
"openprose.compile-phase-ir" while validateRepositoryIr and its tests still expect
"openprose.repository-ir" (23 failing tests). That is a distinct IR-reconciliation
fix, tracked separately.
* fix(cli): restore repository-ir v0 validator tests with CLI-owned fixtures
#106 migrated the SKILL compiler's golden outputs (repo-root
tests/open-prose/compiler/) from repository-ir v0 to compile-phase-ir v2, but the
CLI's own compile path (compileRepositorySource -> validateRepositoryIr ->
repositoryIrToTopology) stayed v0. repository-ir.test.ts and
responsibility-status.test.ts borrowed those golden files across the package
boundary, so the v0 validator was being fed v2 inputs -> 21 failing tests.
Give the CLI's v0 validator tests their OWN v0 fixtures under
tools/cli/tests/prose/fixtures/repository-ir/ (recovered from f12dcda~1, the last
commit before the migration; the CLI compiler and validator are unchanged since,
so they still describe the current contract). The two compilers no longer share
fixtures: the SKILL compiler's compile-phase-ir fixtures are validated by
compiler-ir.test.ts; these repository-ir v0 fixtures are the CLI's. A README in the
fixtures dir documents the split and the migration path.
No validator or compiler change (not papering over) — the v0 validator is simply
fed correct v0 inputs. tools/cli suite: 573 -> 594 passing; the v0 validator suite
is 30/30. The 2 remaining failures (quickstart's dangling deleted-demo reference
and the agent-observatory example's missing id) are unrelated non-IR #106 fallout,
tracked separately.
* chore: deprecate prose-cli npm publish flow; park the eval suite
The `prose` CLI (@openprose/prose-cli) is deprecated in favor of the reactor
harness (@openprose/reactor + @openprose/reactor-cli) and the SKILL/plugin. This
removes its npm publish flow (it will be marked deprecated on npm manually) and
parks the eval harness out of the working tree.
Rip out the prose-cli publish flow:
- delete .github/workflows/{release,cli-release-check,cli-real-harness-smoke}.yml
and scripts/release-preflight.sh (the "OpenProse Release" publisher + its
preflight/checks).
- drop the `cli` track from .version-bump.json (only the skill/plugin track
releases here now) and the prose-cli sections from RELEASE.md.
- decouple the root build/test/lint scripts from @openprose/prose-cli.
Park the eval suite (it is rethought from scratch in the reactor backlog):
- remove the judge-era harness tools/cli/src/evals (45) + tools/cli/tests/evals
(18) and spec/04-Evals.md; they are copied verbatim into the planning
backlog-reactor for rehydration, and the methodology is synthesized there.
The harness was import-isolated (no code imported it); removal breaks nothing.
- fix the now-dangling spec/02 cross-reference to 04-Evals.md.
- remove the obsolete quickstart.test.ts (it read a #106-deleted demo test file).
The reactor packages, the new reactor-native tools/eval-harness, the skill
examples gate, and plugin-manifest are unaffected; prose-cli still typechecks.
A Claude-Code session scanner piped into domain world-state. A cheap classifier
(session-signal) fans per-domain signals into four maintained truths
(decisions-log, eng-backlog, use-case-guide, attention-queue) and a coalesced
dashboard, so cost scales with surprise: a session moves only the domains it
touches; the rest memo-skip.
- 7 contracts + reactor.yml (OpenAI gpt-5.4-mini renders, gpt-5.4 compile),
inline-flow static fixtures, opt-in real scanner (connectors.cjs.example),
README + PIPELINE-DESIGN.md.
- Committed replay/ from a captured run (11 rendered, 2 skipped, 0 failed,
~38k fresh tokens) so the reactor eval-harness is reproducible.
- eval-harness: additive, env-gated Anthropic judge (JUDGE_PROVIDER=anthropic
+ JUDGE_MODEL, default claude-opus-4-8) via the CLI's native-Anthropic provider
builder. Default OpenRouter behavior unchanged; REACTOR_OFFLINE still forces
judges off. Eval result: 2/2 grade A (deterministic + opus judge).
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Closes the 3 critical Dependabot alerts (one advisory, GHSA-5xrq-8626-4rwp, CVSS 9.8). vitest is a devDependency; both configs run environment: node only. Offline gate verified green on the 3→4 bump. Resolved a pnpm-lock.yaml conflict with main by regenerating from main's base.
Adds `react` to the prose CLI command model so `prose react "<use case>"`
is a first-class forwarded command alongside run/serve/write — consistent
with the open-prose skill's `prose react` routing (reactor.md) added in #112.
- command-model.ts: add `react` to the CommandName union, supportedCommands,
and usageByCommand; validate `[use case...] [--start]` (free-form text plus
an optional --start flag; reject unknown long options and duplicate --start).
canonicalPrompt forwards `prose react <args>` to the agent unchanged.
- commands/index.ts: register the `react` forward command (auto-wired into the
command registry).
- command-model.test.ts: forwarding + validation cases for react.
- CHANGELOG: Unreleased entry.
Default forwards the reactor commands for the user to run; `--start` drives
the live lifecycle. Validated: command-model test (53 passing) + my files
typecheck clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Ships @openprose/reactor 0.3.0, @openprose/reactor-cli 0.2.0, @openprose/reactor-devtools 0.2.0: the Reactor harness (compile-once-intelligent then dumb reconciler, content-addressed receipts, cost scales with surprise) with the distilled ideal public API — curated front door, full @openai/agents passthrough, one typed handle, one Substrate, unified observe, branded ids, and additive forward seams for the fixpoint.
Add a section-level ### Tools contract for service and system files, with deterministic cli:<name> resolution at compile time. Document the semantics across Contract Markdown, compiler, Forme, VM, and IR, add a declared-tools example, and teach the CLI to fail closed before harness forwarding on invalid or unresolved declarations.
Forward PROSE_CODEX_ADD_DIR and PROSE_CODEX_NETWORK into Codex SDK thread options so workspace-write runs can grant narrow extra filesystem and network capabilities without danger-full-access.
Also refresh vulnerable transitive production dependencies in the CLI lockfile so the release audit remains green.
* feat(spec): declared ### Skills section with fail-closed compile resolution
Implements the spec from issue #60. Components declare required harness
skills via a `### Skills` section (colon form, e.g. `document-skills:pdf`).
`prose compile` resolves declared skills against ./skills/, ~/.claude/skills/,
~/.codex/skills/, and ~/.agents/skills/, and fails closed with
`skill_unresolved` before forwarding to the agent harness when any are
missing.
- Spec: skills/open-prose/contract-markdown.md gains a ### Skills row in
the Canonical Sections table and a ## Skills H2 covering colon naming,
search order, the BYO-harness invariant, and fail-closed semantics.
- Implementation: tools/cli/src/skills/declared.ts (parser + resolver +
directory walker + DeclaredSkillsUnresolvedError). Pure functions; no
I/O beyond readFile / readdir / stat.
- Wiring: tools/cli/src/commands/compile.ts pre-checks declared skills
before forwarding the compile prompt; fails closed with
CompileValidationError when any are unresolved. Gated behind the
existing skillPreflight option for test parity.
- Example: skills/open-prose/examples/declared-skills/ shows the
document-skills:pdf canonical pattern.
- Tests: 19 new (18 in declared.test.ts covering parser/resolver/walker/
error formatter; 1 in cli.test.ts asserting compile fails closed before
the harness is invoked when a declared skill is missing).
- BYO harness: OpenProse never installs harness skills; resolution failure
is the user's signal to install the named skill themselves.
Resolves#60.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* feat(spec): move skill resolution into compiler program; trim spec per review
Address review feedback on #62:
- contract-markdown.md: drop the "not duplicated in frontmatter" clause —
the rejected alternative shouldn't propagate into the spec.
- contract-markdown.md: fail-closed clause now mentions only `prose compile`;
`prose run` enforcement is deferred per the PR description.
- compiler/index.prose.md: add a `skills_resolver` agent that owns the
search-path order, scope aggregation, BYO invariant, and fail-closed
semantics. Skill resolution is now a compiler/program-level
responsibility, not a harness responsibility, so other harnesses running
the compiler get the same behavior.
- skills/declared.ts: add a header comment pointing at the program-level
spec; this module is the harness implementation of `skills_resolver`.
- examples/declared-skills/README.md: update wording to reference the
compiler agent.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix(ci): make smoke artifacts case-specific
* fix(ci): use deterministic audit policy
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
The Claude Agent SDK defaults settingSources to empty, so the
claude-sdk harness silently ignored ~/.claude and <repo>/.claude:
user skills, project skills, hooks, MCP servers, and project
CLAUDE.md never reached the agent. Set ["user", "project"] so prose
runs match the workspace a user already configured for Claude Code.
Adds three tests: settingSources is always forwarded; auth_status
messages stream their output lines to stderr; auth_status with an
error field exits 1 (the existing branch was untested).
The CLI now ships first-party agent SDKs only. The `codex` harness —
a thin shim around `codex exec` — has been removed. Supported
harnesses: `codex-sdk`, `claude-sdk`, `mock`.
BREAKING CHANGE: `--harness codex` (and `PROSE_HARNESS=codex`) no
longer works. Switch to `--harness codex-sdk` for first-party,
in-process Codex SDK execution. `codex-sdk` remains the default,
so most users are unaffected.
- Delete `codex-cli.ts` and `process-harness.ts`; keep
`process-runner.ts` for the OpenProse skill installer
- Trim `codex-options.ts` to SDK-shaped helpers
- Drop `codex` from the smoke script and CI matrix
- Align README, post-release playtest, and package metadata
Moves `@openprose/prose-cli` from `cli/` to `tools/cli/` and seeds a
`tools/` convention at the repo root for shippable tooling published as
standalone artifacts. Package internals are unchanged — only paths
outside the package that hard-code the `cli/` segment were updated.
## What changed
- `git mv cli tools/cli` — package files render as 100%-similarity
renames, so `git log --follow` is preserved.
- `.github/workflows/cli-publish.yml`,
`.github/workflows/cli-release-check.yml`, and
`.github/workflows/cli-real-harness-smoke.yml`: every literal `cli/`
path (`paths:`, `working-directory:`, `cache-dependency-path:`,
artifact `path:`, and inline `node`/`bash` invocations) now points
at `tools/cli/`. `cli-skills-smoke.yml` had no `cli/` references and
is untouched.
- `tools/cli/package.json`: `repository.directory` and `homepage` flip
to `tools/cli` so the npm registry "Repository" link resolves.
- `README.md`: the badge nav, the prose-layout paragraph, and the repo
layout table now point at `tools/cli/`, plus a new `tools/` row
introducing the convention.
- `RELEASE.md`: cross-references to `cli/RELEASE.md` updated.
- `tools/cli/README.md`, `tools/cli/RELEASE.md`,
`tools/cli/POST_RELEASE_PLAYTEST.md`: public installer URL updated to
`https://raw.githubusercontent.com/openprose/prose/main/tools/cli/install.sh`.