execuro/sw-ecosystem-agentic-harness
v0.1.12MIT
Shopware 6 agentic harness: sw-* skills and sub-agents for requirements, specs, implementation, verification and documentation, with an installer CLI that writes them into Claude Code, Codex, GitHub Copilot and Cursor. The knowledge-base MCP and the editor tools are separate npm packages.
Changelog
All notable changes to the Shopware Ecosystem Agentic Harness are recorded here.
The format follows Keep a Changelog, and
versioning is semver — 0.x until the first stable
release.
[Unreleased]
[0.1.12] - 2026-09-25
Changed
sw-discover-tenderruns analysis automatically, in page-order chunks — the Analyze step is gone. Confirming the extraction starts assessment on its own, about 15 items at a time in page order, split into groups of ~5 with anapplyper group as it lands; re-estimate work joins the same chunking. Every Configuration, Extension, ISV or Custom item now needs a proposal with a numericpdSaved, or anoProposalreason —applyrefuses otherwise.SKILL.md,reference/procedure.md,reference/editor-session.mdandreference/agent-briefs.mddescribe the new flow;agents/sw-shopware-architect.mdand its adapters carry thenoProposalrequirement.- The working document's Effort column is now Estimation — column header
and order change only (client inputs ID · Prio · Requirement first, then
the working fields); the report JSON key stays
effort. An older-order orEffort-headed document is read the same way and rewritten on its next write.reference/analysis-template.md,reference/estimation-model.md,reference/response-rules.md,reference/coverage-mapping.mdandreference/client-question-rules.mdupdated.
[0.1.11] - 2026-09-21
Changed
- Environment repair lives in
sw-setupalone. The other skills no longer repair the setup themselves; they carry only lean preconditions and defer tosw-setupfor the fix. - A tech spec is rendered before the editor opens, so the page shows the document rather than opening onto an unrendered one.
[0.1.10] - 2026-09-20
Changed
- The design skills follow the Specs Editor's split of PRD and tech-spec
workflows.
sw-design-requirementsandsw-design-solution(theirSKILL.md, editor-mode, editor-gate, readiness and pre-check references) andREADME.mdnow describe one session per document, with--docnaming the document, and a feature's PRD and spec as two independent sessions.
[0.1.9] - 2026-09-19
Changed
README.mdnamessw-setupas part of the installation flow. Documentation only.
[0.1.8] - 2026-09-19
Changed
- The lock file moved to
var/sw-ai-sdk/harness.lock.json, and the.gitignoreline is gone with it. A Shopware project ignores the whole ofvar/through theshopware/coreFlex recipe (/var/*, with a single!/var/.htaccessnegation) and already keeps its machine-local state there —var/cache,var/log— so the installer no longer creates a directory in the repository root and no longer writes to.gitignoreat all. A root with novar/(--scope userunder $HOME, or a checkout that is not a Shopware project) keeps.sw-ai-sdk/and its managed line, unchanged. Nothing here reads a path outside the install root, on any platform. Migration is automatic and lossless: a lock still at the old path is read, rewritten to the new one, and the old file, its directory and the managed.gitignoreblock are removed. Declined rules, recorded agents and file hashes all survive, so the first run after upgrading reinstalls nothing — it reportsmigrated[]in--jsonand one line in the human summary.lock_filein every result body now carries the resolved path; anything that hard-coded.sw-ai-sdk/should read that key instead.
Removed
- BREAKING: the "extra component" mechanism is gone. The CLI no longer
detects, installs, updates or removes the two optional visual editors
(Specs Editor, Tender Discovery Tool); each package installs its own skill,
orchestrated by the
sw-setupskill. Removed with it: theextra_components[]key fromstatus --json, the--no-extra-componentsflag oninstall/plan/apply, theskippedfield fromplan's andapply'ssummary(nothing else could produce that state), theskill-copyaction kind, and the "Optional extra components" section ofguide. Anything readingextra_components[]or countingsummary.skippedmust stop. Why: the mechanism had never once worked. It spawnednpx --no-install <pkg>@<pin> install-skill --printand required stdout to begin with---, but both editors document asource:/next_step:preamble before the skill document, so the check could never pass and neither skill was ever installed.--no-installalso suppresses installing but not resolving, so everystatus,planandapplyissued a real request to the npm registry —statuswas never offline-safe, contrary to what the module claimed. - The two editors are now invoked as
@latesteverywhere, including in theallowed-toolspermission grants ofsw-design-requirements,sw-design-solutionandsw-discover-tender, which still named an exact version and would therefore have denied the calls. The@latestcheck now guardsallowed-toolslines as well as prose.
Added
status --jsonreportsskills_dirper agent — the directory that agent actually reads skills from, and the--targetsw-setuphands to an editor package's owninstall-skill/uninstall-skill.
[0.1.7] - 2026-09-19
Changed
- BREAKING:
install,status,plananduninstallprint a human summary, not JSON. Typinginstalland getting several hundred lines of JSON made success unreadable; the result object is now rendered for a person on stdout — what changed, grouped by coding agent, and the restart each one needs. A run with nothing to do is one line. Conflicts, drift and manual steps are never collapsed: each names its file and its remedy, and an agent this project has not installed is never named at all. Pass--jsonfor the previous object, unchanged apart from the key rename below, and--verbosefor the per-file detail alongside the summary. Every skill, script or agent parsing this output must add--json. - BREAKING:
--hostis now--agent, with no alias.--hostis rejected as an unknown option (exit 2, with runnable--agenthelp), thehostskey in every result body is nowagents, and the lock file recordsagents. A lock written by an earlier version underhostsis still read and is rewritten asagentson the next run, so an existing install keeps its recorded selection. Consistent with the earlier--no-companions->--no-extra-componentsbreak. WARNING — the lock migration is one-way: writingagentsdrops the legacyhostskey, so after any run of this version an older pinned CLI (npx …@0.1.6) exits 2 in that repository with "no --host given, this repository has no recorded install". Verified against the published 0.1.6 tarball. installinvoked with a bad flag now reportsinstall, notapply, in its usage help.
Fixed
statusno longer labels a conflict as "edited since install". Itsdrift[]entries now carry the action'sstate, and the human renderer titles conflicts as conflicts.
[0.1.6] - 2026-09-18
Changed
README.mdonly (commit subject: "Test"). No code change.
[0.1.5] - 2026-09-17
Fixed
install/applyno longer write into every detected host when--hostis omitted. They now resolve which host(s) to use in order:--hostif given; else the hosts a lock file already records; else an interactive picker when a terminal is attached; else exit 2 naming the fourinstall --host <h>commands ashelp, instead of silently defaulting to Claude Code, Codex, Copilot and Cursor.statusanduninstallkeep covering every host by default, andplanpreviews all four and says so when nothing was selected.
[0.1.4] - 2026-09-17
Added
sw-setupgained a twelfth readiness row, "Package updates". It checks whether the harness, the Specs Editor and the Tender Discovery Tool are at their target versions (the harness at npm's latest, each editor at its ownextra_components[].versionpin, never npm's latest) via threenpm viewlookups, each with a 10-second timeout — a failed or timed-out lookup reports "could not check" rather than failing the row. Folds into step 3's single question; never blocks readiness. The KB MCP keeps its existing row (registered as@latest, nothing to update).
[0.1.3] - 2026-09-17
Changed
- The
vendor/row now names the specific missing file when unticked.sw-setup's printed line says which ofvendor/shopware/core,composer.lockorvendor/bin/phpunitis missing instead of just marking the row unticked, so a--no-devvendor tree (which has the first two but notvendor/bin/phpunit) is diagnosable at a glance. Same fix as before,composer install --no-interaction, offered the same way. - The update documentation now covers every component.
README.md's Keep up to date section became Keeping it up to date and says how each of the three parts updates on its own schedule: this package throughinstall, the MCP servers by themselves (they are registered as@latest, so a host fetches the newest build when it next starts one), and the Specs Editor and Tender Discovery Tool through their ownnpm i -Dline followed by a re-run ofinstall. The section also moved below Install's own subsections, which it had been separating from their heading. - The two extra components are now named individually, with the exact
pinned
npm i -Dcommand for each, in bothREADME.md's new The optional editors subsection andguide's output — replacing the earlier<package>@<version>placeholder — because the probe accepts only the exact versionEXTRA_COMPONENTSpins and skips the skill for anything else, including@latest. - Breaking: the "companion" terminology is renamed to "extra component".
The CLI flag
--no-companionsis now--no-extra-components, and thestatusJSON output keycompanionsis nowextra_components. Anything scripting against0.1.2or earlier that readscompanionsor passes--no-companionsmust update to the new names — there is no backwards- compatible alias. sw-storefront-developer's locate proofs now check for deprecated forwarder files andfeature()branches, and read the active theme'sviewschain. Proof 1 rejects a template whose header names it a removed forwarder; proof 2 notes thefeature()branch a block sits in; proof 3 also greps the theme'stheme.jsonviewsorder. The chain order and where an override belongs are now deferred to the storefront guideline's expert template-inheritance and override-placement sections instead of being restated in the agent body.
[0.1.2] - 2026-09-16
Changed
- Install/update instructions now anchor to
@latest. Everynpxinvocation of this package inREADME.md,sw-setup'sSKILL.mdandreference/rows.mduses@execuro-sw-ecosystem/sw-ecosystem-agentic-harness@latestinstead of a bare package name or a frozen version — a bare invocation can resolve to a stale copy already in thenpxcache ornode_modules. Added a Keep up to date section toREADME.mdand a Keeping it current section toguide's output.
[0.1.1] - 2026-09-16
Added
- An
installcommand —apply --yesunder a friendlier one-step name. Typing the verb is the consent, so it never prompts and needs no--yes; the scriptableapply --yesis unchanged and stays what skills and CI call.
Fixed
- CI and the GitHub Pages setup for the plugin marketplace.
[0.1.0] - 2026-09-16
Added
- An npm package with an installer CLI —
bin/cli.mjspluslib/, published as@execuro-sw-ecosystem/sw-ecosystem-agentic-harnesswith the binsw-ecosystem-agentic-harness. Commandsstatus,plan,apply,uninstallandguide, each printing one JSON object with a mandatorynext_step;exit 2on a usage error with ahelparray of runnable commands. Zero runtime dependencies, no install hooks. - Installs into all four hosts — Claude Code, OpenAI Codex, GitHub Copilot and Cursor, each into its own native discovery directories, with the MCP servers written in each host's own format.
copilot/agents/*.agent.md— Copilot adapters generated byscripts/gen-copilot-agents.mjs, with Claude tool names mapped through Copilot's alias table. An unknown tool name fails the build rather than disappearing.content/AGENTS.md— generated from the shipped skills and agents byscripts/gen-agents-md.mjs. Codex, Copilot and Cursor read it from the installed tree, and Codex never readsCLAUDE.md.scripts/frontmatter.mjs— the frontmatter reader shared by all three generators.scripts/check-pack.mjs— fails when the tarball would carry anything outside thefilesallow-list, or when a lifecycle script is declared..github/workflows/release.yml— OIDC trusted publishing with--provenance, gated on the generators, the tests, the pack check and the licence metadata.- A full
node --testsuite, zero dependencies, covering the whole risk surface the compatibility guide names: install idempotency asserted on mtimes, malformed and JSONC configs, the uninstall round trip, Windows command wrapping and POSIX lock keys, and per-host error aggregation. - The remaining
sw-*skills —sw-setup,sw-discover-tender,sw-design-requirements,sw-design-solution— so the package now ships all 10 skills and 7 sub-agents. The Specs Editor's own skill ships inside its own package, not here.
Changed
sw-setupis now a stub skill. It runs the CLI'sstatus, renders the table, asks its one question and runsapply --yes. It never writes a host file and no longer carries the rule list — the CLI is the single source of truth for what gets installed.- Every
SKILL.mdis under 8 KB, Codex's effective cap, enforced by a test.sw-discover-tender(27.5 KB),sw-design-solution(17.8 KB) andsw-design-requirements(12.7 KB) were reorganised intoreference/router files — reorganised, not compressed: each split was audited line-by-line against its pre-split copy. - No Claude-only construct is left anywhere. All
${CLAUDE_SKILL_DIR},$ARGUMENTS,SendMessage,subagent_typeand literal.claude/…paths are gone, and everyAskUserQuestionin prose now names the capability with both hosts as an aside. mcp.jsonis now the portable Agent Plugins 1.0 form — it carries the$schemaand atype: "stdio"per server, and is no longer a copy of Claude Code's.mcp.json. They are different formats.README.mddocuments the installer rather than a marketplace install.
Removed
extensions.com.openai.codexfrom the rootplugin.json. No Codex manifest struct has anagentsfield, so the declaration was a no-op.- The "carries no executables" claim from both plugin descriptions. The package now carries exactly one: the installer.
Notes
- Distribution is the installer, not a plugin marketplace. The plugin manifests are kept valid in CI although nothing reads them today.
- The
ShopwareDevKnowledgeBaseandplaywrightMCP registrations both track@latest; every other pinned thing in this package is pinned exactly.