Changelog
Notable changes to AIOS, newest first. Dates are ISO-8601.
Unreleased
Section titled “Unreleased”v2.1.0 — 2026-09-23
Section titled “v2.1.0 — 2026-09-23”MCP setup is included in the toolkit. aios mcp install configures the hosts
you select: Claude Desktop, Claude Code, Codex and Cursor. Guided onboarding offers
the same optional setup after a successful Brain connection, defaulting to No.
Installing or upgrading the toolkit alone does not change host configuration.
See Connect your agent.
The installer pins the separately published @aiosbrain/mcp@0.2.1 by integrity,
keeps credentials out of host configuration, and refuses unsafe or concurrently
edited files. It verifies the recorded server command. Restart selected hosts
yourself and confirm tools appear; command verification does not establish host
loading. The standalone server exposes five read-only tools for external members
and nine for team members, including evidence search.
This release also includes inline terminal setup/status improvements and retains the 2.0 credential-redaction, migration and exact-artifact publication safeguards. The publisher now waits for bounded npm processing delays after an accepted upload without repeating the upload.
The documented Brain API contract is v1.27, documentation revision 1.29. This is a Workspace release, not a Brain production deployment. The five governed GitHub route deferrals remain explicit in the API reference.
Install this exact version only after its Git tag and npm registry entry are available. Required release verification includes the same packed toolkit across Linux/macOS on Node 22/24/26, additional Windows MCP installer cells, independent review, registry byte identity and deployed documentation.
v2.0.0 — 2026-09-17
Section titled “v2.0.0 — 2026-09-17”Published the major CLI cutover. The v2.0.0 tag and
@aiosbrain/aios@2.0.0 registry artifact were verified on 2026-09-17.
The canonical executable is aios, including built-in aios linear and aios slack.
The npm package supplies an immutable toolkit, stamp format 2 and committed
content-addressed merge bases. Supported runtimes are Node 22/24/26; the acceptance
matrix covers Linux/macOS. Windows is outside this release’s validated platform scope.
Bare linear and slack remain delegates with stderr warnings through v2; earliest
removal is v3. The devtools dependency remains pinned to 0.3.1 and its package bin is
not a new canonical CLI.
Breaking/migration: stage and verify exact 2.0.0, migrate every existing 0.12.0 workspace while the old package remains in place, then replace that installation. Do not overwrite the old package before the stamp and base store migrate. Repeat update, interruption recovery and config-drift-aware rollback are described in the upgrade guide. Candidate installs remain engine-strict; only legacy 0.12.0 installation on Node 24/26 requires scoped engine relaxation.
Linear now selects environment, user reference, then legacy workspace credentials,
refuses incomplete selected sources, and does not echo malformed key values. Unsupported
JSON flags fail before credentials. Equivalent simple Markdown links no longer produce
false description drift. Ambiguous Slack writes require readback before retry.
An environment-sourced Slack token is refused toward a workspace-domain Brain;
explicit aios slack connect --stdin supplies consent for that destination.
Workspace retains Brain API v1.24; this is not a Brain product release or proof of live server activation. The five GitHub integration routes listed in the API reference remain governed, contract-first, feature-flagged deferrals. Live Slack write validation and registry acceptance require their own retained evidence; earlier candidate smokes do not establish this release’s identity.
Release provenance is generated from the pinned Workspace commit in
src/data/upstream-facts.json. The publisher must consume the single accepted tarball
from all six cells, and registry verification must prove its byte identity before closure.
v0.12.0 — 2026-08-21
Section titled “v0.12.0 — 2026-08-21”A minor release, and the licence changes. AIOS Workspace is now AGPL-3.0-only (it was
MIT through 0.11.1), with an Apache-2.0 carve-out for the vendored .harness/ directory. If
you depend on the package, read that first. @aiosbrain/foundation moves to 0.1.2 for the
same registry-immutability reason, in two steps: 0.1.1 carried the relicensed manifest, and
0.1.2 adds the credential fix below.
Ships Brain API contract v1.22 (v1.21 adds the in_review task status; v1.22 makes
coverage arrive with its denominator).
Three defects that only a published install could see are fixed:
slackandlinearon yourPATHnow run. Both bins shipped without the executable bit in0.11.1, so invoking either by name returnedpermission denied. The bins are now the credential-resolving wrappers themselves, shipped0755and asserted that way in the packed tarball.- A published install can decrypt a workspace
.envwithout direnv or a globaldotenvx. The decryption dependency shipped as a devDependency, so the published package carried no copy and credential resolution silently failed on machines without a global install — both connectors reported “key not set” with the key sitting encrypted next to a valid.env.keys. It is now a runtime dependency, resolved via Node module resolution so every install layout works. aios spec evalfinds its rubric on a published install.
Also in this release: a connector routing guard that steers provably AIOS-targeted Linear
work to the AIOS CLIs, a packed-artifact golden-path CI gate (install the real tarball into a
clean prefix and drive it), two new validators (OGR16 validator citations, OGR17 shared
skill sync), the check-claim skill, project create/list support in the Linear CLI, and a
one-command self-test for the write-time secret guard.
Upgrading: npm i -g @aiosbrain/aios@0.12.0. No migration steps.
v0.11.1 — 2026-08-17
Section titled “v0.11.1 — 2026-08-17”A patch release. Install it if you installed 0.11.0. A clean-container test of the
published 0.11.0 artifact found that the write-time secret guard could fail open silently.
- The secret guard no longer needs
jq, and can no longer fail open silently.jqwas an undeclared runtime dependency of the shippedhooks/team-ops-guard.sh. On any machine without it, the guard returned “allow” and said nothing: everyjqcall was wrapped2>/dev/null || true, so the missing binary never trippedset -euo pipefail, the tool payload came back empty, and the script fell through to its finalexit 0. An AWS key was written straight through the guard in testing at exit0, with no output on either stream. Access-tier and frontmatter enforcement run through the same hook and were equally inert. Payload extraction now triesjq, then falls back tonode, and no verdict fails closed with a named diagnostic that saysjqis the cause. The permissive behaviour is still available behind an environment variable, but it announces itself on every invocation — silence is not reachable in any branch. macOS ships/usr/bin/jqand GitHub’subuntu-latestpre-installs it, which is why the dev machine, CI and the release gate all agreed the guard worked. - The install docs no longer pin a release that rots.
GETTING-STARTED.mdandREADME.mdtold new users, in bold, to clonev0.10.0— the release whose validators fail on a clean install. Both now resolve the newest tag at clone time. Prerequisites documentjq, thenodefallback, and the install-dependencies-before-validating caveat.
aios validate— runs the toolkit’s validators against a workspace. A scaffolded workspace’s ownvalidation/holds onlysecret-patterns.txt, so it cannot run the validator suite from its own tree, and a global install previously had to know the path insidenode_modules. It works from anywhere, including outside a workspace, and so doesaios validate --help.
Migration and rollback
Section titled “Migration and rollback”- Install the release with
npm install -g @aiosbrain/aios@0.11.1. - Nothing in a scaffolded workspace changes shape. Run
aios updatefrom an existing workspace to pick up the corrected hook and docs, then review and commit the result normally. - Roll back with
npm install -g @aiosbrain/aios@0.11.0— but note that is the release with the guard defect above.
The Team Brain member-facing contract is unchanged at v1.20.
v0.11.0 — 2026-08-17
Section titled “v0.11.0 — 2026-08-17”The Workspace GUI moves to its own repo, every new workspace gets the evolve skill,
and connectors gain a declared v1 contract. This release also folds in the patch work
that landed after the 0.10.0 tag — 0.10.1 was prepared but never published, so
upgrade straight from 0.10.0 to 0.11.0.
evolveships in the scaffold — every new workspace now comes with nineteen skills instead of eighteen.evolveaudits which skills are actually being read and routed to, flags repeated friction, and proposes what to build next. Prompt text is omitted by default; when an operator opts into excerpts, secret-bearing values are redacted in full.- Structured maturity guidance —
aios analyze --jsonnow exposes typedchat,command,edit, anddocactions for every maturity axis, plus the exact blockers to the next spine level whenever the workspace is below L5. - Integration contracts v1 — connectors declare a capability taxonomy and a mutation class,
and provider hosts are validated, so an integration’s blast radius is stated up front rather
than discovered at run time.
aios connectorinstalls AIOS connectors globally, and Slack messages keep their line breaks. - Runtime-agnostic reviewer presets — adversarial-review steps inside
aios loopname a reviewer preset rather than a provider-specific model, so the same loop runs under Claude, Codex, or OpenCode. - Code Maintenance Loop, phase zero — codebase health separates the observed score from
evidence completeness and automation admission. Missing, stale, or errored required evidence
produces an
unknowngate that can never admit background remediation. Findings are report-only in this release. - Per-PR review-evidence gate — in the Workspace repo itself, a pull request is mergeable only while a reviewer’s attestation names its current head SHA. Pushing a new commit makes prior evidence stale.
Changed
Section titled “Changed”- The Workspace GUI now lives in
aiosbrain/aios-workspace-gui.gui/andsrc-tauri/are deleted fromaios-workspace; the standalone repo is authoritative. Point it at a Workspace checkout withAIOS_TOOLKIT_DIR. validation/validate-all.shruns fourteen checks, not fifteen.OGR09(skill-library integrity) moved to the GUI repo alongside the library it validates, where the equivalent gate runs in CI.- Node’s upper version bound is gone, and the supported range is now proven in CI rather than
asserted in
engines. - Codex maturity analysis recognises current custom-tool events and delegated child sessions and attributes them to their human-root session. The analysis cache moves to schema v2, so the first run after upgrading reparses stale entries once.
- Brain reporting in scaffolded CI is opt-in rather than on by default.
- Delegated commands now run against exactly
@aiosbrain/aios-devtools@0.2.1.
- A scaffolded workspace’s CLI shim resolves its
aios-workspacecheckout from thesourceline the scaffolder already writes into.aios-toolkit-version. It no longer needs an environment variable or one of three hardcoded sibling layouts.AIOS_TOOLKIT_DIRstill wins when set. - Worktree and Cursor harness guards are scoped to the repo that vendors them, so a multi-root session no longer denies every tool call, and a scaffolded workspace never inherits the toolkit’s own commit/push policy.
- Transcript ingestion normalises the
privateaudience alias instead of hard-failing the whole batch. - Secret-scan findings still name the rule, file, and line, but the matched source line is
replaced with
[REDACTED]before anything is written or printed. Explicit-only skills reject malformed$id-suffixand/id-suffixinvocations and ignore sigils that appear inside URLs and filesystem paths. - Optional coverage-dependency installation is genuinely fail-open, so an
npm cifailure can no longer stop a repository from reaching its Brain scan.
Migration and rollback
Section titled “Migration and rollback”- Install the release with
npm install -g @aiosbrain/aios@0.11.0. - Validation ownership changed. Anyone who vendors or operates the GUI Skill Library must run
its integrity gate from
aiosbrain/aios-workspace-gui; the core validator is no longer anOGR09substitute. - A global install does not rewrite managed files already copied into an existing workspace. Run
aios updatefrom that workspace to pick up the scaffold and workflow changes, then review and commit the result normally. - Roll back with
npm install -g @aiosbrain/aios@0.10.0— the last published release.
The Team Brain member-facing contract moves to v1.17, additively within v1. Revision v1.16
documented two authenticated reads that were already shipped — GET /api/v1/attribution and
GET /api/v1/timeline — with no wire or runtime change. Revision v1.17 accepts a
backward-compatible v2 shape for metrics.codebase_health; the v1 shape is still accepted
verbatim, and the new shape grants no write or remediation authority.
v0.10.0 — 2026-08-03
Section titled “v0.10.0 — 2026-08-03”The Workspace CLI is now an independently installable package with the devtools extraction completed. This release also adds the guided Team Brain Create path and makes scaffolded codebase reporting produce trustworthy coverage and health evidence.
- One-click Team Brain Create —
aios onboardexplains the Railway deployment and cost boundary, asks before opening the stable deployment guide, and resumes through the existing origin and API-key validation path. Onboarding never persists an unverified Brain origin or key. - Devtools preflight — operators can verify all five delegated commands and see whether each resolves from the exact npm dependency or an adjacent checkout.
- Brain-reporting scaffold workflow — new workspaces report real codebase-health and coverage evidence after protected-main pushes.
aios-deck— a reusable deck-building skill with brand theming and rendered visual QA.
Changed
Section titled “Changed”ship,build,roadmap-run,spec, andconsolidate-findingsnow execute from exactly pinned@aiosbrain/aios-devtools@0.2.0; their former Workspace implementations were removed.- Scan workflows now use immutable Actions and scanner revisions, exact hash-locked dependencies, disabled install scripts, and step-scoped Brain credentials.
- Failed suites still produce a coverage artifact, absent GUI coverage is no longer reported as zero, SR18 scope fences handle nested and sibling headings correctly, and malformed daily due dates are rejected.
Migration and rollback
Section titled “Migration and rollback”- Install the release with
npm install -g @aiosbrain/aios@0.10.0. - Adjacent devtools contributors can export
AIOS_DEVTOOLS_DIR; the preflight identifies that source explicitly. Everyone else uses the exact packaged dependency. - Roll back to
@aiosbrain/aios@0.9.1to restore the last tarball containing the in-tree devtools implementations.
The Team Brain member-facing contract is unchanged at v1.15.
v0.9.0 — 2026-08-01
Section titled “v0.9.0 — 2026-08-01”The multi-repo split release. The one-repo Workspace layout is cut along declared,
tested seams into a published foundation package, a standalone GUI repo, and a
devtools repo — while the core toolkit in aios-workspace stays authoritative for
every cut surface until the deferred deletion PRs land.
Repo topology
Section titled “Repo topology”@aiosbrain/foundation0.1.0 published to npm (public) — the shared hub modules (runtimes,workspace-parse,brain-config,linear-client,brain-client,git-files,constitution) extracted into thepackages/foundation/npm workspace. The oldscripts/paths remain as one-line re-export shims, so nothing consuming them breaks.- GUI + desktop shell cut to
aiosbrain/aios-workspace-gui— filtered history from the Workspace repo. The in-treegui/+src-tauri/remain present and authoritative in 0.9.0; their deletion from the core repo is a deferred post-demo change (tracked as AIO-612). - Devtools command set cut to
aiosbrain/aios-devtools— bootstrapped viaaios repo-bootstrapwith pinned-toolkit CI. The in-treescripts/implementations remain authoritative until the removal lands.
What’s new in the toolkit
Section titled “What’s new in the toolkit”aios codebase-health— a composed codebase-health scorer + rubric + CLI with an advisory CI baseline delta. Brain API revision 1.15 adds an optional, scalar-onlycodebase_healthobject onPOST /api/v1/codebases; attaching it to the scan-on-merge payload is opt-in and default-off.aios repo-bootstrap— governance stamp installer for split repos, used to bootstrap the cut repositories.aios delivery status— cross-repo PR/worktree/branch reconciliation over a durable split-delivery manifest.- GUI seam commands —
catalog,gen-catalog, andconnectorare now first-class registry commands: the GUI server shells theaiosCLI instead of reaching into toolkit scripts.
Migration (0.8.0 → 0.9.0)
Section titled “Migration (0.8.0 → 0.9.0)”- Existing workspace owners: run
aios updateonce, and setAIOS_TOOLKIT_DIRin your workspace.envrcto your toolkit checkout. No re-scaffold is needed. - Standalone GUI installs (from
aios-workspace-gui) must locate the toolkit explicitly — setAIOS_TOOLKIT_DIRor pass--toolkit-dir. The built-in relative fallback only resolves in the in-tree monorepo layout. - In-tree GUI still works: because the deletion is deferred,
npm run guifrom the Workspace repo is unchanged this release. - Desktop (Tauri) is adjacent-checkout mode only and not demo-ready; self-contained bundling is tracked in the GUI repo (AIO-581).
This release ships member-facing Brain API contract v1.15 (additive within
major v1).
v0.8.0 — 2026-07-28
Section titled “v0.8.0 — 2026-07-28”What’s new
Section titled “What’s new”- Onboarding V2 — one inspect-first onboarding contract across the Workspace, Team Brain, and public website, with three explicit paths: Personal, Join, and Create.
- Safe upgrades —
aios update --previewshows the planned update and safety checks before any mutation, followed by an explicit human approval. - Reliable Team Brain connection — the API key is authoritative,
team_idis optional, the exact Brain origin requires approval, andGET /api/v1/mevalidates the connection before setup is marked complete.
Changed
Section titled “Changed”- Team Brain keeps workstation setup discoverable without blocking Pulse, including for members joining an already-active team.
- The Create path is guide-only, and onboarding never pushes workspace content.
- Public quickstart, contributor, troubleshooting, landing animation, and agent prompt now describe the same shipped flow.
- Cross-repository contract fixtures and docs-drift checks now prevent the public onboarding instructions from silently diverging from the Workspace implementation.
- Team Brain durably records a successful
/api/v1/meconnection while ordinary API authentication remains available if non-critical usage telemetry fails.
This release ships member-facing Brain API contract v1.14.
v0.7.0 — 2026-07-04
Section titled “v0.7.0 — 2026-07-04”Cognitive Ergonomics shadow band (workspace + Team Brain)
Section titled “Cognitive Ergonomics shadow band (workspace + Team Brain)”- Workspace CLI —
aios analyze --pushnow includes an optionalce_bandscalar (0–4ornull) on each dailyPOST /api/v1/metricspayload. Scored client-side relative to your own baseline; the four raw attention signals still never leave the machine. - Team Brain — Individual Maturity dashboard shows CE beside AM: a CE column on the people table, a CE stat card on member deep-dive, and a dashed amber CE timeline (gaps when no reading). Every CE element is badged shadow · uncalibrated; CE does not enter radar, spine distribution, or team-axis rollups.
- Display rename — “Agentic Engineering Maturity (AEM)” → Agentic Maturity (AM) in
product UI and docs (wire metric id
aem-individualunchanged).
Sync contract stays v1 — ce_band is an additive v1.3 field on the existing metrics
endpoint. See Brain API and the workspace repo’s docs/brain-api.md.
Website
Section titled “Website”- Landing — deck synthesis — Principles and Honesty sections on the editorial landing page; collective brain architecture diagram in How It Works; Problem lead paragraph bridging deck narrative.
- Docs — anatomy reference — The 8 organ systems Starlight page adapted from Team Brain
ARCHITECTURE.md, with shipped/partial/planned status. - Product deck — standalone slideshow at
/deck/(keyboard + touch navigation), linked from the site footer.
v0.6.0 — 2026-07-03
Section titled “v0.6.0 — 2026-07-03”The aios ship pipeline (workspace toolkit)
Section titled “The aios ship pipeline (workspace toolkit)”One gated command per issue, one walker per roadmap. The proven plan → adversarial review → build → bot review → consolidated fix loop → gated merge workflow is now first-class tooling in the workspace repo:
aios ship <ISSUE>— runs the whole loop for a single tracker issue: recon → plan (adversarialPLAN_READYgate) → isolated worktree build → PR → bot + GPT reviews → consolidated fix rounds → merge gate → cleanup, with operator gates on by default (--auto/--auto-mergeto run unattended) and a local-only audit trail per issue.aios roadmap-run— the serial walker: picks the top unblocked issue from a label/epic/project, ships it, fast-forwardsmain, moves to the next; defined escalation conditions and a morning digest.aios pr— push the build branch + open the PR with the issue key in the title (idempotent); push/PR is the tool’s job, never the build agent’s.aios consolidate-findings— dedupes CI + review-bot + model-review findings into one severity-ranked must-fix list (a merged finding inherits the max source severity, never downgraded) that feeds fix rounds automatically.- Per-step model config —
.aios/loop-models.yamlmaps every pipeline step to a model + effort, with a fail-closed diversity guard: the builder and its reviewer must be different model families. - Hardening — the build agent runs with a scoped worktree fence and a cleaned
environment; review calls auto-retry on timeout with size-scaled limits; the bot
wait gate is fail-closed by default (
--anyto opt out).
Sync contract unchanged: the Brain API stays v1 — no protocol change in this
release. Full details in the workspace repo’s CHANGELOG.md at tag v0.6.0.
v0.5.0 — 2026-06-19
Section titled “v0.5.0 — 2026-06-19”Agentic Engineering Maturity (AEM)
Section titled “Agentic Engineering Maturity (AEM)”- Individual maturity —
aios analyzebuilds an AEM report from your local agent-session logs (Claude/Codex/Cursor) and, with--push, sends a daily aggregate to the brain. Only ratios and counts cross the boundary — raw session content never leaves your machine; the brain recomputes the canonical Spine/axes so team rollups have one authority. - Codebase agent-readiness —
aios assess-codebasescores a repo’s agent-readiness (L0–L5) against the shared rubric;--pushrecords the scan in the brain. A scanner-side Python scorer applies the same rubric on the ingestion path.
Team Brain
Section titled “Team Brain”- New endpoints (additive — the sync contract stays v1):
POST /api/v1/codebases(codebase scan ingest) andPOST /api/v1/metrics(AEM individual daily aggregate). Both are team-tier only — anexternal-tier key gets403 forbidden_tier, and the metrics endpoint persists aggregates only (never raw session text).
Tooling
Section titled “Tooling”aios relay— an automated Opus ↔ Cursor plan/review loop: Opus plans, Cursor executes, Opus reviews, repeating for N rounds (default 3).
v0.4.0 — 2026-06-17
Section titled “v0.4.0 — 2026-06-17”Onboarding & memory
Section titled “Onboarding & memory”- Onboarding from a link now drafts into two-axis durable memory
(
.claude/memory/USER.md+WORKSPACE.md) — confirm before write. - Suggested integrations — after a link-draft, the agent matches detected tools to connectable integrations and offers to connect them (advisory; never auto-connects).
- Update memory on request (“remember that …”, “update my tooling”) and an opt-out background memory reviewer that conservatively saves durable facts with undo.
Skills
Section titled “Skills”- Marketplace tier — install first-party Anthropic skills from
claude-plugins-officialvia fetch-on-install with byte-diff authenticity (alongside the official and community tiers).
Runtimes & security
Section titled “Runtimes & security”- BYOA: OpenClaw on the ACP adapter (hardened stdout) + recorded-transcript CI gates.
- Encrypted
.env— connector secrets are encrypted at rest via dotenvx.
The Team Brain sync contract is unchanged (still v1).
v0.3.0 — 2026-06-17 — The cockpit overhaul
Section titled “v0.3.0 — 2026-06-17 — The cockpit overhaul”The local cockpit (npm run gui) becomes a real workspace cockpit. No change to
the spine, validators, guard, harnesses, or the Team Brain sync contract.
Cockpit chat
Section titled “Cockpit chat”- Model picker — choose Sonnet 4.6 (default) or Opus 4.8 and switch
mid-session with no reconnect; the choice persists to
aios.yaml. - Resumable chats — a sidebar of saved conversations; reopen one to resume the same session, or start a new one.
- Context (est.) meter — an approximate read of how much of the model’s window the last turn used.
- Markdown rendering — assistant replies render as GitHub-flavored markdown.
- Personality presets — AIOS, Analyst, Coach, Operator. A style layer only; it
never overrides your rules,
CLAUDE.md, or skills.
Skills library
Section titled “Skills library”- One-click install of official Anthropic skills, vendored from
anthropics/skills, hash-locked, all Apache-2.0: skill-creator, mcp-builder, web-artifacts-builder, claude-api, frontend-design. - Document skills (Word, Excel, PowerPoint, PDF) are Anthropic-hosted pointers — Enable in Claude — not copied into your repo.
- Community installs, scanned — install skills beyond the official library behind a static safety scan and a consent gate. The scanner flags bundled code (including extensionless shebang scripts), network calls, secret reads, external URLs, and prompt-injection; a high-risk skill requires a typed confirm. Scanning is advisory — official skills stay one-click.
Onboarding
Section titled “Onboarding”- Draft your profile from a link — paste a URL and the agent reads it with
Firecrawl, then drafts
.claude/CLAUDE.mdfor you to confirm before it’s written.