gaurav890/everything-agentic-engineering
v0.1.0MIT
Durable product, design, engineering, verification, and collaboration skills for compatible AI agents.
Changelog
All notable changes will be documented here.
This project follows Semantic Versioning.
Unreleased
Added
- A machine-readable Perplexity, Firecrawl, Playwright, Claude Code, Codex, and Agent Plugins MCP compatibility matrix plus a read-only doctor, provenance snapshots, clean-client test plan, negative fixtures, and fail-closed portable-package gate.
- An additive Agent Plugins 1.0 portable, skills-only package with a closed root manifest, contained fixed-location skill discovery, an offline doctor, deterministic tests, and an explicit separation from Codex-native metadata and project-local MCP configuration.
- A strict, read-only capability decision engine that combines active profiles and durable task evidence into built-in, recommended, optional, missing, or blocked states with provenance, authority limits, risks, and safe next steps; it validates but never executes plan-only adapters.
- A deterministic specialist capability broker with reviewed Agency Agents provenance, profile-aware task routing, reversible manifest activation, required risk reviews, local-role fallback, independent-evaluator evidence, and no automatic external installation or runtime-authority expansion.
- Profile-aware Emil Kowalski design-engineering integration with a reviewed, pinned ten-skill manifest; a local anti-slop/motion router; explicit-only prototyping, library-selection, and animation-review gates; Claude Code and Codex installation; and deterministic coverage tests.
- Resumable PR finalization that recovers only an exact interrupted task-ledger transition, re-verifies it before commit, and waits a bounded interval for GitHub to register required checks before reporting a safe retry.
- A registry-backed
./agenticcommand interface that groups 24 supported workflows, classifies every shell file, hides internal policy helpers and security hooks from public discovery, and preserves existing script paths as compatibility adapters during a measured migration. - A human-approved PR finalizer with dry-run, clean-worktree and PR identity checks, ledger-only staging, recovery from an already-ready PR, required- check waiting, and explicit guarantees that it never approves or merges.
- A machine-readable Claude Code and Codex runtime policy plus a read-only advisory/strict/JSON doctor that separates compatibility from authority and keeps optional self-hosted, cross-session, plugin, MCP, and automatic- approval capabilities human-gated.
- A read-only post-merge closeout report that verifies default-branch task truth, merged PRs, closing issue state, volatile handoff claims, and safe local cleanup targets without performing any mutation.
- A deterministic GitHub Issue ↔ task ↔ PR contract with explicit issue-free exceptions, multi-task closure safety, task-planner guidance, required offline policy validation, and optional read-only live drift inspection.
- Seven project-scoped, read-only Codex specialist roles for product, architecture, research, design, security, QA, and integration review, with deterministic authority and schema validation.
- A native Codex adapter with shared repository skills, bounded project configuration, reviewed safety-hook wiring, a skills-only plugin manifest, runtime doctor, multi-terminal worktree guidance, and automated drift tests.
- A Playwright visual-regression gate for the Showcase's normal, loading, empty, and error states across desktop and mobile, with reviewed Linux baselines and failure artifacts.
- An adaptive product-design intake that asks only relevant questions for the active platform, creates comparable visual directions, and requires explicit human approval before canonical design-system or token changes.
- Mode-aware semantic color tokens, light/dark parity validation, required WCAG contrast checks, and a generated token specimen for review evidence.
- A ready-for-review PR policy gate that requires the linked task to be
done, preventing merged work from leaving stale execution state behind.
Security
- Portable MCP packaging remains blocked until credential references, deterministic package resolution, protocol negotiation, client trust and rollback, and independent security evidence all pass; no MCP was installed, authenticated, contacted, or executed during the review.
- Claude Code 2.1.224–2.1.225 version guidance for filesystem-deny, cross-session, self-hosted, workspace-trust, and OAuth hardening, with optional runtime surfaces disabled by default.
- Codex 0.147.0 capability gates for portable plugins, MCP 2026-07-28, and automatically reviewed approvals without installing or enabling them.
- Version-qualified Claude Code guidance for credential-file masking, zsh permission hardening, and corrected nested-subagent defaults without enabling new runtime settings or exposing credential paths.
- Version-qualified Claude Code worktree/background-agent fixes and Codex cyber-model review defaults without enabling models, permissions, hooks, or remote-control capabilities.
- Version-qualified Claude Code 2.1.223 guidance for shell approval, workflow-sandbox, and managed bypass-permission fixes without changing the repository's runtime or permission configuration.
0.1.0 - 2026-07-25
Added
- A repository-centered agent harness with durable product, design, engineering, execution, evaluation, and collaboration context.
- A phase-based product-design engine with product-specific authority, specialist routing, independent critique, and Playwright evidence.
- DTCG-compatible design-token sources and generated CSS, TypeScript, and React Native outputs.
- Controlled, evidence-gated daily ecosystem research that proposes changes without modifying the harness autonomously.
- A complete product-design resource catalog with source links and routing.
- Deterministic, non-destructive project profiles and a guided initializer with explicit active and inactive capability plans.
- A confirmation-gated task launcher that turns
TASKS.jsonlentries into reviewed branch or worktree plans. - Signalroom, a responsive reference product for supervising AI-agent work, including interaction, accessibility, and visual evidence.
- GitHub issue, branch, pull-request, review, CI, security, and contribution contracts for human-agent collaboration.
Security
- Deterministic hooks for destructive-command prevention and secret detection.
- Human approval gates for releases, deployments, credentials, destructive migrations, and other irreversible actions.