Skip to content

Changelog

Notable changes to AIOS, newest first. Dates are ISO-8601.

MCP setup is included in the toolkit. aios mcp install configures the hosts you select: Claude Desktop, Claude Code, Codex and Cursor. Guided onboarding offers the same optional setup after a successful Brain connection, defaulting to No. Installing or upgrading the toolkit alone does not change host configuration. See Connect your agent.

The installer pins the separately published @aiosbrain/mcp@0.2.1 by integrity, keeps credentials out of host configuration, and refuses unsafe or concurrently edited files. It verifies the recorded server command. Restart selected hosts yourself and confirm tools appear; command verification does not establish host loading. The standalone server exposes five read-only tools for external members and nine for team members, including evidence search.

This release also includes inline terminal setup/status improvements and retains the 2.0 credential-redaction, migration and exact-artifact publication safeguards. The publisher now waits for bounded npm processing delays after an accepted upload without repeating the upload.

The documented Brain API contract is v1.27, documentation revision 1.29. This is a Workspace release, not a Brain production deployment. The five governed GitHub route deferrals remain explicit in the API reference.

Install this exact version only after its Git tag and npm registry entry are available. Required release verification includes the same packed toolkit across Linux/macOS on Node 22/24/26, additional Windows MCP installer cells, independent review, registry byte identity and deployed documentation.

Published the major CLI cutover. The v2.0.0 tag and @aiosbrain/aios@2.0.0 registry artifact were verified on 2026-09-17.

The canonical executable is aios, including built-in aios linear and aios slack. The npm package supplies an immutable toolkit, stamp format 2 and committed content-addressed merge bases. Supported runtimes are Node 22/24/26; the acceptance matrix covers Linux/macOS. Windows is outside this release’s validated platform scope. Bare linear and slack remain delegates with stderr warnings through v2; earliest removal is v3. The devtools dependency remains pinned to 0.3.1 and its package bin is not a new canonical CLI.

Breaking/migration: stage and verify exact 2.0.0, migrate every existing 0.12.0 workspace while the old package remains in place, then replace that installation. Do not overwrite the old package before the stamp and base store migrate. Repeat update, interruption recovery and config-drift-aware rollback are described in the upgrade guide. Candidate installs remain engine-strict; only legacy 0.12.0 installation on Node 24/26 requires scoped engine relaxation.

Linear now selects environment, user reference, then legacy workspace credentials, refuses incomplete selected sources, and does not echo malformed key values. Unsupported JSON flags fail before credentials. Equivalent simple Markdown links no longer produce false description drift. Ambiguous Slack writes require readback before retry. An environment-sourced Slack token is refused toward a workspace-domain Brain; explicit aios slack connect --stdin supplies consent for that destination.

Workspace retains Brain API v1.24; this is not a Brain product release or proof of live server activation. The five GitHub integration routes listed in the API reference remain governed, contract-first, feature-flagged deferrals. Live Slack write validation and registry acceptance require their own retained evidence; earlier candidate smokes do not establish this release’s identity.

Release provenance is generated from the pinned Workspace commit in src/data/upstream-facts.json. The publisher must consume the single accepted tarball from all six cells, and registry verification must prove its byte identity before closure.

A minor release, and the licence changes. AIOS Workspace is now AGPL-3.0-only (it was MIT through 0.11.1), with an Apache-2.0 carve-out for the vendored .harness/ directory. If you depend on the package, read that first. @aiosbrain/foundation moves to 0.1.2 for the same registry-immutability reason, in two steps: 0.1.1 carried the relicensed manifest, and 0.1.2 adds the credential fix below.

Ships Brain API contract v1.22 (v1.21 adds the in_review task status; v1.22 makes coverage arrive with its denominator).

Three defects that only a published install could see are fixed:

  • slack and linear on your PATH now run. Both bins shipped without the executable bit in 0.11.1, so invoking either by name returned permission denied. The bins are now the credential-resolving wrappers themselves, shipped 0755 and asserted that way in the packed tarball.
  • A published install can decrypt a workspace .env without direnv or a global dotenvx. The decryption dependency shipped as a devDependency, so the published package carried no copy and credential resolution silently failed on machines without a global install — both connectors reported “key not set” with the key sitting encrypted next to a valid .env.keys. It is now a runtime dependency, resolved via Node module resolution so every install layout works.
  • aios spec eval finds its rubric on a published install.

Also in this release: a connector routing guard that steers provably AIOS-targeted Linear work to the AIOS CLIs, a packed-artifact golden-path CI gate (install the real tarball into a clean prefix and drive it), two new validators (OGR16 validator citations, OGR17 shared skill sync), the check-claim skill, project create/list support in the Linear CLI, and a one-command self-test for the write-time secret guard.

Upgrading: npm i -g @aiosbrain/aios@0.12.0. No migration steps.

A patch release. Install it if you installed 0.11.0. A clean-container test of the published 0.11.0 artifact found that the write-time secret guard could fail open silently.

  • The secret guard no longer needs jq, and can no longer fail open silently. jq was an undeclared runtime dependency of the shipped hooks/team-ops-guard.sh. On any machine without it, the guard returned “allow” and said nothing: every jq call was wrapped 2>/dev/null || true, so the missing binary never tripped set -euo pipefail, the tool payload came back empty, and the script fell through to its final exit 0. An AWS key was written straight through the guard in testing at exit 0, with no output on either stream. Access-tier and frontmatter enforcement run through the same hook and were equally inert. Payload extraction now tries jq, then falls back to node, and no verdict fails closed with a named diagnostic that says jq is the cause. The permissive behaviour is still available behind an environment variable, but it announces itself on every invocation — silence is not reachable in any branch. macOS ships /usr/bin/jq and GitHub’s ubuntu-latest pre-installs it, which is why the dev machine, CI and the release gate all agreed the guard worked.
  • The install docs no longer pin a release that rots. GETTING-STARTED.md and README.md told new users, in bold, to clone v0.10.0 — the release whose validators fail on a clean install. Both now resolve the newest tag at clone time. Prerequisites document jq, the node fallback, and the install-dependencies-before-validating caveat.
  • aios validate — runs the toolkit’s validators against a workspace. A scaffolded workspace’s own validation/ holds only secret-patterns.txt, so it cannot run the validator suite from its own tree, and a global install previously had to know the path inside node_modules. It works from anywhere, including outside a workspace, and so does aios validate --help.
  • Install the release with npm install -g @aiosbrain/aios@0.11.1.
  • Nothing in a scaffolded workspace changes shape. Run aios update from an existing workspace to pick up the corrected hook and docs, then review and commit the result normally.
  • Roll back with npm install -g @aiosbrain/aios@0.11.0 — but note that is the release with the guard defect above.

The Team Brain member-facing contract is unchanged at v1.20.

The Workspace GUI moves to its own repo, every new workspace gets the evolve skill, and connectors gain a declared v1 contract. This release also folds in the patch work that landed after the 0.10.0 tag — 0.10.1 was prepared but never published, so upgrade straight from 0.10.0 to 0.11.0.

  • evolve ships in the scaffold — every new workspace now comes with nineteen skills instead of eighteen. evolve audits which skills are actually being read and routed to, flags repeated friction, and proposes what to build next. Prompt text is omitted by default; when an operator opts into excerpts, secret-bearing values are redacted in full.
  • Structured maturity guidance — aios analyze --json now exposes typed chat, command, edit, and doc actions for every maturity axis, plus the exact blockers to the next spine level whenever the workspace is below L5.
  • Integration contracts v1 — connectors declare a capability taxonomy and a mutation class, and provider hosts are validated, so an integration’s blast radius is stated up front rather than discovered at run time. aios connector installs AIOS connectors globally, and Slack messages keep their line breaks.
  • Runtime-agnostic reviewer presets — adversarial-review steps inside aios loop name a reviewer preset rather than a provider-specific model, so the same loop runs under Claude, Codex, or OpenCode.
  • Code Maintenance Loop, phase zero — codebase health separates the observed score from evidence completeness and automation admission. Missing, stale, or errored required evidence produces an unknown gate that can never admit background remediation. Findings are report-only in this release.
  • Per-PR review-evidence gate — in the Workspace repo itself, a pull request is mergeable only while a reviewer’s attestation names its current head SHA. Pushing a new commit makes prior evidence stale.
  • The Workspace GUI now lives in aiosbrain/aios-workspace-gui. gui/ and src-tauri/ are deleted from aios-workspace; the standalone repo is authoritative. Point it at a Workspace checkout with AIOS_TOOLKIT_DIR.
  • validation/validate-all.sh runs fourteen checks, not fifteen. OGR09 (skill-library integrity) moved to the GUI repo alongside the library it validates, where the equivalent gate runs in CI.
  • Node’s upper version bound is gone, and the supported range is now proven in CI rather than asserted in engines.
  • Codex maturity analysis recognises current custom-tool events and delegated child sessions and attributes them to their human-root session. The analysis cache moves to schema v2, so the first run after upgrading reparses stale entries once.
  • Brain reporting in scaffolded CI is opt-in rather than on by default.
  • Delegated commands now run against exactly @aiosbrain/aios-devtools@0.2.1.
  • A scaffolded workspace’s CLI shim resolves its aios-workspace checkout from the source line the scaffolder already writes into .aios-toolkit-version. It no longer needs an environment variable or one of three hardcoded sibling layouts. AIOS_TOOLKIT_DIR still wins when set.
  • Worktree and Cursor harness guards are scoped to the repo that vendors them, so a multi-root session no longer denies every tool call, and a scaffolded workspace never inherits the toolkit’s own commit/push policy.
  • Transcript ingestion normalises the private audience alias instead of hard-failing the whole batch.
  • Secret-scan findings still name the rule, file, and line, but the matched source line is replaced with [REDACTED] before anything is written or printed. Explicit-only skills reject malformed $id-suffix and /id-suffix invocations and ignore sigils that appear inside URLs and filesystem paths.
  • Optional coverage-dependency installation is genuinely fail-open, so an npm ci failure can no longer stop a repository from reaching its Brain scan.
  • Install the release with npm install -g @aiosbrain/aios@0.11.0.
  • Validation ownership changed. Anyone who vendors or operates the GUI Skill Library must run its integrity gate from aiosbrain/aios-workspace-gui; the core validator is no longer an OGR09 substitute.
  • A global install does not rewrite managed files already copied into an existing workspace. Run aios update from that workspace to pick up the scaffold and workflow changes, then review and commit the result normally.
  • Roll back with npm install -g @aiosbrain/aios@0.10.0 — the last published release.

The Team Brain member-facing contract moves to v1.17, additively within v1. Revision v1.16 documented two authenticated reads that were already shipped — GET /api/v1/attribution and GET /api/v1/timeline — with no wire or runtime change. Revision v1.17 accepts a backward-compatible v2 shape for metrics.codebase_health; the v1 shape is still accepted verbatim, and the new shape grants no write or remediation authority.

The Workspace CLI is now an independently installable package with the devtools extraction completed. This release also adds the guided Team Brain Create path and makes scaffolded codebase reporting produce trustworthy coverage and health evidence.

  • One-click Team Brain Create — aios onboard explains the Railway deployment and cost boundary, asks before opening the stable deployment guide, and resumes through the existing origin and API-key validation path. Onboarding never persists an unverified Brain origin or key.
  • Devtools preflight — operators can verify all five delegated commands and see whether each resolves from the exact npm dependency or an adjacent checkout.
  • Brain-reporting scaffold workflow — new workspaces report real codebase-health and coverage evidence after protected-main pushes.
  • aios-deck — a reusable deck-building skill with brand theming and rendered visual QA.
  • ship, build, roadmap-run, spec, and consolidate-findings now execute from exactly pinned @aiosbrain/aios-devtools@0.2.0; their former Workspace implementations were removed.
  • Scan workflows now use immutable Actions and scanner revisions, exact hash-locked dependencies, disabled install scripts, and step-scoped Brain credentials.
  • Failed suites still produce a coverage artifact, absent GUI coverage is no longer reported as zero, SR18 scope fences handle nested and sibling headings correctly, and malformed daily due dates are rejected.
  • Install the release with npm install -g @aiosbrain/aios@0.10.0.
  • Adjacent devtools contributors can export AIOS_DEVTOOLS_DIR; the preflight identifies that source explicitly. Everyone else uses the exact packaged dependency.
  • Roll back to @aiosbrain/aios@0.9.1 to restore the last tarball containing the in-tree devtools implementations.

The Team Brain member-facing contract is unchanged at v1.15.

The multi-repo split release. The one-repo Workspace layout is cut along declared, tested seams into a published foundation package, a standalone GUI repo, and a devtools repo — while the core toolkit in aios-workspace stays authoritative for every cut surface until the deferred deletion PRs land.

  • @aiosbrain/foundation 0.1.0 published to npm (public) — the shared hub modules (runtimes, workspace-parse, brain-config, linear-client, brain-client, git-files, constitution) extracted into the packages/foundation/ npm workspace. The old scripts/ paths remain as one-line re-export shims, so nothing consuming them breaks.
  • GUI + desktop shell cut to aiosbrain/aios-workspace-gui — filtered history from the Workspace repo. The in-tree gui/ + src-tauri/ remain present and authoritative in 0.9.0; their deletion from the core repo is a deferred post-demo change (tracked as AIO-612).
  • Devtools command set cut to aiosbrain/aios-devtools — bootstrapped via aios repo-bootstrap with pinned-toolkit CI. The in-tree scripts/ implementations remain authoritative until the removal lands.
  • aios codebase-health — a composed codebase-health scorer + rubric + CLI with an advisory CI baseline delta. Brain API revision 1.15 adds an optional, scalar-only codebase_health object on POST /api/v1/codebases; attaching it to the scan-on-merge payload is opt-in and default-off.
  • aios repo-bootstrap — governance stamp installer for split repos, used to bootstrap the cut repositories.
  • aios delivery status — cross-repo PR/worktree/branch reconciliation over a durable split-delivery manifest.
  • GUI seam commands — catalog, gen-catalog, and connector are now first-class registry commands: the GUI server shells the aios CLI instead of reaching into toolkit scripts.
  • Existing workspace owners: run aios update once, and set AIOS_TOOLKIT_DIR in your workspace .envrc to your toolkit checkout. No re-scaffold is needed.
  • Standalone GUI installs (from aios-workspace-gui) must locate the toolkit explicitly — set AIOS_TOOLKIT_DIR or pass --toolkit-dir. The built-in relative fallback only resolves in the in-tree monorepo layout.
  • In-tree GUI still works: because the deletion is deferred, npm run gui from the Workspace repo is unchanged this release.
  • Desktop (Tauri) is adjacent-checkout mode only and not demo-ready; self-contained bundling is tracked in the GUI repo (AIO-581).

This release ships member-facing Brain API contract v1.15 (additive within major v1).

  • Onboarding V2 — one inspect-first onboarding contract across the Workspace, Team Brain, and public website, with three explicit paths: Personal, Join, and Create.
  • Safe upgrades — aios update --preview shows the planned update and safety checks before any mutation, followed by an explicit human approval.
  • Reliable Team Brain connection — the API key is authoritative, team_id is optional, the exact Brain origin requires approval, and GET /api/v1/me validates the connection before setup is marked complete.
  • Team Brain keeps workstation setup discoverable without blocking Pulse, including for members joining an already-active team.
  • The Create path is guide-only, and onboarding never pushes workspace content.
  • Public quickstart, contributor, troubleshooting, landing animation, and agent prompt now describe the same shipped flow.
  • Cross-repository contract fixtures and docs-drift checks now prevent the public onboarding instructions from silently diverging from the Workspace implementation.
  • Team Brain durably records a successful /api/v1/me connection while ordinary API authentication remains available if non-critical usage telemetry fails.

This release ships member-facing Brain API contract v1.14.

Cognitive Ergonomics shadow band (workspace + Team Brain)

Section titled “Cognitive Ergonomics shadow band (workspace + Team Brain)”
  • Workspace CLI — aios analyze --push now includes an optional ce_band scalar (0–4 or null) on each daily POST /api/v1/metrics payload. Scored client-side relative to your own baseline; the four raw attention signals still never leave the machine.
  • Team Brain — Individual Maturity dashboard shows CE beside AM: a CE column on the people table, a CE stat card on member deep-dive, and a dashed amber CE timeline (gaps when no reading). Every CE element is badged shadow · uncalibrated; CE does not enter radar, spine distribution, or team-axis rollups.
  • Display rename — “Agentic Engineering Maturity (AEM)” → Agentic Maturity (AM) in product UI and docs (wire metric id aem-individual unchanged).

Sync contract stays v1 — ce_band is an additive v1.3 field on the existing metrics endpoint. See Brain API and the workspace repo’s docs/brain-api.md.

  • Landing — deck synthesis — Principles and Honesty sections on the editorial landing page; collective brain architecture diagram in How It Works; Problem lead paragraph bridging deck narrative.
  • Docs — anatomy reference — The 8 organ systems Starlight page adapted from Team Brain ARCHITECTURE.md, with shipped/partial/planned status.
  • Product deck — standalone slideshow at /deck/ (keyboard + touch navigation), linked from the site footer.

The aios ship pipeline (workspace toolkit)

Section titled “The aios ship pipeline (workspace toolkit)”

One gated command per issue, one walker per roadmap. The proven plan → adversarial review → build → bot review → consolidated fix loop → gated merge workflow is now first-class tooling in the workspace repo:

  • aios ship <ISSUE> — runs the whole loop for a single tracker issue: recon → plan (adversarial PLAN_READY gate) → isolated worktree build → PR → bot + GPT reviews → consolidated fix rounds → merge gate → cleanup, with operator gates on by default (--auto / --auto-merge to run unattended) and a local-only audit trail per issue.
  • aios roadmap-run — the serial walker: picks the top unblocked issue from a label/epic/project, ships it, fast-forwards main, moves to the next; defined escalation conditions and a morning digest.
  • aios pr — push the build branch + open the PR with the issue key in the title (idempotent); push/PR is the tool’s job, never the build agent’s.
  • aios consolidate-findings — dedupes CI + review-bot + model-review findings into one severity-ranked must-fix list (a merged finding inherits the max source severity, never downgraded) that feeds fix rounds automatically.
  • Per-step model config — .aios/loop-models.yaml maps every pipeline step to a model + effort, with a fail-closed diversity guard: the builder and its reviewer must be different model families.
  • Hardening — the build agent runs with a scoped worktree fence and a cleaned environment; review calls auto-retry on timeout with size-scaled limits; the bot wait gate is fail-closed by default (--any to opt out).

Sync contract unchanged: the Brain API stays v1 — no protocol change in this release. Full details in the workspace repo’s CHANGELOG.md at tag v0.6.0.

  • Individual maturity — aios analyze builds an AEM report from your local agent-session logs (Claude/Codex/Cursor) and, with --push, sends a daily aggregate to the brain. Only ratios and counts cross the boundary — raw session content never leaves your machine; the brain recomputes the canonical Spine/axes so team rollups have one authority.
  • Codebase agent-readiness — aios assess-codebase scores a repo’s agent-readiness (L0–L5) against the shared rubric; --push records the scan in the brain. A scanner-side Python scorer applies the same rubric on the ingestion path.
  • New endpoints (additive — the sync contract stays v1): POST /api/v1/codebases (codebase scan ingest) and POST /api/v1/metrics (AEM individual daily aggregate). Both are team-tier only — an external-tier key gets 403 forbidden_tier, and the metrics endpoint persists aggregates only (never raw session text).
  • aios relay — an automated Opus ↔ Cursor plan/review loop: Opus plans, Cursor executes, Opus reviews, repeating for N rounds (default 3).
  • Onboarding from a link now drafts into two-axis durable memory (.claude/memory/USER.md + WORKSPACE.md) — confirm before write.
  • Suggested integrations — after a link-draft, the agent matches detected tools to connectable integrations and offers to connect them (advisory; never auto-connects).
  • Update memory on request (“remember that …”, “update my tooling”) and an opt-out background memory reviewer that conservatively saves durable facts with undo.
  • Marketplace tier — install first-party Anthropic skills from claude-plugins-official via fetch-on-install with byte-diff authenticity (alongside the official and community tiers).
  • BYOA: OpenClaw on the ACP adapter (hardened stdout) + recorded-transcript CI gates.
  • Encrypted .env — connector secrets are encrypted at rest via dotenvx.

The Team Brain sync contract is unchanged (still v1).

v0.3.0 — 2026-06-17 — The cockpit overhaul

Section titled “v0.3.0 — 2026-06-17 — The cockpit overhaul”

The local cockpit (npm run gui) becomes a real workspace cockpit. No change to the spine, validators, guard, harnesses, or the Team Brain sync contract.

  • Model picker — choose Sonnet 4.6 (default) or Opus 4.8 and switch mid-session with no reconnect; the choice persists to aios.yaml.
  • Resumable chats — a sidebar of saved conversations; reopen one to resume the same session, or start a new one.
  • Context (est.) meter — an approximate read of how much of the model’s window the last turn used.
  • Markdown rendering — assistant replies render as GitHub-flavored markdown.
  • Personality presets — AIOS, Analyst, Coach, Operator. A style layer only; it never overrides your rules, CLAUDE.md, or skills.
  • One-click install of official Anthropic skills, vendored from anthropics/skills, hash-locked, all Apache-2.0: skill-creator, mcp-builder, web-artifacts-builder, claude-api, frontend-design.
  • Document skills (Word, Excel, PowerPoint, PDF) are Anthropic-hosted pointers — Enable in Claude — not copied into your repo.
  • Community installs, scanned — install skills beyond the official library behind a static safety scan and a consent gate. The scanner flags bundled code (including extensionless shebang scripts), network calls, secret reads, external URLs, and prompt-injection; a high-risk skill requires a typed confirm. Scanning is advisory — official skills stay one-click.
  • Draft your profile from a link — paste a URL and the agent reads it with Firecrawl, then drafts .claude/CLAUDE.md for you to confirm before it’s written.