grainulation/grainulator
v2.0.2
Evidence and verification for model-assisted work, with portable workflows and clear next actions.
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
[2.0.2] - 2026-09-08
Fixed
- Recognize the supported host security wrapper in both MCP configuration formats without changing or removing the wrapper. Verify that it references the expected configuration and server, and retain checks on the original launch command, arguments and environment.
- Protect native plugin configuration and integrity metadata from export overwrites, including paths through symbolic links and missing destination children.
- Enforce the workspace boundary when reading the implicit synchronization log through MCP tools.
- Return HTTP 400 for malformed preview request URLs instead of terminating the local server.
- Make workspace configuration cleanup remove only temporary files created by the current save operation.
- Redact known environment credential values from managed-runner results, stored traces and progress callbacks while preserving operational adapter/verifier inputs.
Verification scope
- Added focused regressions for these defects and checked provider redirects, origin validation, request/response limits and cancellation. See the security review for boundaries and remaining limits.
- GitHub release only; no npm publication. Previously published release tags are unchanged.
[2.0.1] - 2026-09-08
Fixed
- Make evidence command help read-only, including compile, initialization, and server commands.
- Export compiled sprint content instead of silently producing empty reports; reject incomplete input with actionable errors.
- Accept
--dirconsistently for export paths and report the actual unknown option. - Add
--version/-vand ship a verifiable file manifest in marketplace and tagged-source installations. - Save the native Codex workspace once with
grainulator setup --dir /absolute/project; explicit launch environment bindings still override the saved default.
Documentation
- Add a 1.x upgrade guide covering marketplace refresh, scope pins, host restarts, retired MCP server names, memory-store selection, and reviewed cleanup of generated instructions.
- Clarify that hidden tool aliases do not restore removed server registrations or the former remote DeepWiki connection.
Release scope
- GitHub release only; no npm registry publication. Existing source-verification, research-quality, and cumulative-cost limitations remain unchanged.
[2.0.0] - 2026-09-07
Changed
- Consolidate evidence, memory, exports, analytics, orchestration, and execution support into one Grainulator workspace and CLI.
- Expose one MCP server with 19 canonical tools and seven resources; retain hidden compatibility aliases for existing integrations.
- Require Node.js 24 or later, with Node 25 used for local development and both versions checked in CI.
- Replace the demo with a configurable research playground supporting session import, export, stop, resume, provider selection, and credential-safe handoff.
- Refresh the product site and installation guidance, and require grouped Auto/Manual next actions in core workflows.
Fixed
- Preserve provenance and custom claim fields across mutation, search, compilation, and migration.
- Protect concurrent ledger and memory writes, export destinations, and workspace boundaries.
- Correct installed Node-version diagnostics, relative sprint paths, packaged documentation, and Claude subagent tool access.
- Add Codex native plugin loading with explicit
GRAINULATOR_WORKSPACEbinding and tested session continuation. - Give local archives unique build identifiers and verify installed files against their manifests.
Removed
- Remove the standalone dashboard, permission connectors, and notification hook. Native hosts manage permissions and remote access.
Release scope
- Published as a GitHub release. Local archives can be installed from the tagged source; no npm registry publication is included in this release.
- Live-provider acceptance, independent citation verification, general research-quality gains, cumulative spending limits, and risk-closure semantics remain separately tracked limitations; structural validation is not source verification.
[1.7.1] - 2026-04-19
Changed
- Grainulator devDeps (
@playwright/test,serve) moved out of this repo into the maintainer's private ranch harness. Grainulator is now truly zero-devDep, matching the published ecosystem's zero-dep philosophy. E2E tests still pass (27/27); they now run locally only via the ranch harness — seeCONTRIBUTING.md.
Internal
- Biome autofix pass on hooks and plugin JSON files.
- CI: removed the e2e job (moved to the ranch harness, local-only).
- Added
release.yml—v*tag pushes now auto-create GitHub Release objects with CHANGELOG-extracted notes.
[1.7.0] - 2026-04-19
Added
- Bearer auth on farmer hooks. The sprint-status notifier hook now
attaches a Bearer token when
.farmer-tokenis present. Narrow-scope tokens ensure admin/viewer credentials can't be reused against hook endpoints — aligns grainulator's hook transport with farmer's opportunistic-auth hardening. /healthcheckhost-capability probe. Checks Claude Code's current tool/MCP contract and flags drift before it causes silent skill failures. Run before a sprint to verify the environment is compatible.
Fixed
- Windows hook compatibility. Inline JS in
hooks.jsonsilently failed on Windows cmd.exe (no fail-closed). Extracted to.cjsfiles invoked vianode ${CLAUDE_PLUGIN_ROOT}/hooks/<name>.cjsso Windows runs the same code path as macOS/Linux. - Port env override now respected by hook scripts.
Changed
- Skills: extracted shared WCAG checklist so
briefandpresentskills reference one source instead of duplicating.
Internal
.envadded to.gitignore.
[1.6.2] - 2026-04-18
Added
SECURITY.md— private-disclosure policy via GitHub Security Advisories orsecurity@grainulator.app, 90-day window, explicit scope and credit clauses.CODE_OF_CONDUCT.md+CONTRIBUTING.md— standard OSS files aligned with the rest of the ecosystem.- README "Troubleshooting" section covering MCP server reconnect
(
claude mcp add wheat|mill|silo ...) and pointing at the/healthcheckskill for diagnostics. skills/_templates/wcag-shared.md— shared WCAG checklist that brief + present skills now reference instead of inlining twice.scripts/sync-version.js— source-of-truth for the 3-way version sync (package.json → plugin.json → marketplace.json), wired into thenpm versionlifecycle hook so bumps stay in sync.
Changed
- Bumped
package.jsonversion from 1.6.0 to 1.6.2 so it matches plugin.json and marketplace.json entries; prior drift meant users pointing at the git HEAD saw one version while the marketplace served another.
Fixed
- Smart-fetch skill wrote
mcp__silo__smart-fetchbut the runtime tool name ismcp__silo__silo_smart-fetch. Tool was unreachable.
[1.3.0] - 2026-04-03
Added
/healthcheckskill — pre-flight MCP server verification with parallel pings, failure class diagnosis, and fix commands- Agent definition updated with healthcheck skill reference
[1.1.0] - 2026-03-31
Added
/setupskill for post-install MCP server verification and onboarding.- Privacy policy page (
site/privacy.html) for marketplace submission.
Changed
- MCP server source in marketplace.json switched from GitHub SSH to HTTPS git URL.
- Wheat MCP invocation changed from
wheat mcpsubcommand to dedicatedwheat-mcpbinary (fixes connection drops in Claude Code plugin transport).
Fixed
plugin.json: renamedmcpConfigtomcpServers(official schema).plugin.json: added./prefix to all paths (required by plugin spec).plugin.json: explicit agent file path instead of directory glob.hooks.json: converted to event-keyed object format with{ hooks: {} }wrapper for auto-discovery.- Smoke tests updated to match new plugin schema.
- Biome schema bumped to 2.4.9, template string lint warnings resolved.
- Contact email updated to info@grainulator.app.
[1.0.0] - 2026-03-21
Changed
- Removed all pricing and cost references from the landing page and metadata.
- Added focus trap to terminal dialog overlay for keyboard accessibility.
- Final copy polish pass (typography, quotes, dashes).
Fixed
- Terminal overlay now traps Tab focus and restores focus on close.
[0.1.0] - 2026-03-21
Added
- Plugin manifest (
.claude-plugin/plugin.json) with skills, agents, hooks, and MCP config. - 9 skills in subdirectory format (
skills/<name>/SKILL.md):/init-- start a new research sprint/research-- multi-pass investigation with evidence gathering/challenge-- adversarial testing of a specific claim/witness-- corroborate a claim against an external source/brief-- generate a compiled decision brief/status-- sprint dashboard snapshot/present-- generate a presentation deck/blind-spot-- structural gap analysis/router-- intent detection for plain-language messages
- Autonomous sprint agent (
agents/grainulator.md) with Plan-Compile-Execute loop. - MCP server configuration for wheat, mill, silo, and DeepWiki.
- Hooks: auto-compile on claim mutation, write-guard on
.wheat/directory. - Landing page at
site/index.htmlfor grainulator.app. - Smoke tests (
test/smoke.test.js) validating plugin structure. - MIT license.