rrpauls/esra-agents
v0.4.0Apache-2.0
Portable ESRA skills with a guarded autonomous controller for OpenClaw and Hermes Agent.
Changelog
0.4.0 — Unreleased
- Canonical VERSION and synchronized host manifests; validated machine-readable host/surface capability matrix and stable/main/immutable source channels.
- Preserve OpenAI marketplace archives; add direct local plugin and hooks-free web packages, plus distinct Claude Web and Gemini individual skill layouts.
- Native Hermes repository discovery, Claude marketplace and Grok Build compatibility; Antigravity receives a generated closed-schema manifest.
- Share unchanged candidate rejection rules between Python and OpenClaw through declarative policy data; preserve privacy and guarded promotion checks.
- Stronger deterministic artifact contracts, checksum coverage, isolated native smoke harness and release gates with controlled fast-forward stable promotion.
- Catalog publication, web uploads, API provisioning and absent host CLIs remain separate verification gates; no custom self-updater or implicit consent.
Unreleased
- Harden state, output, snapshot, installer, and packaging paths against traversal, symlinks, and hardlinked output overwrites; validate ZIP members.
- Rename the OpenAI distribution to
esra-agents-openai.zipand add the universal portable skills bundle for Gemini/Grok web import workflows. - Build, validate, and attach all tagged host distributions automatically on GitHub release publication, with complete SHA256 checksum coverage.
0.3.0 — 2026-09-29 (prerelease)
- Consolidate all host distributions into a unified release with deterministic archives and SHA256 checksums across OpenAI/Codex, Claude Code, Hermes Agent, OpenClaw, and Google Antigravity.
- Add Google Antigravity adapter with lifecycle hooks and portable skills integration.
- Replace legacy Hermes installer with a native Hermes 0.21 Python plugin, four lifecycle hooks, five native plugin ESRA skills,
/esra,hermes esraCLI, and constrained controller tool. - Apply approved candidates through Hermes
skill_managewith a one-time token. - Add privacy-bounded MCP evidence receipts for GitHub, security, browser-pilot, and SOFA evidence.
- Harden review recursion, completion evidence, and terminal candidate retention.
0.2.2 — 2026-09-15 (prerelease)
- Purge terminal candidate content, snapshots, and expired tokens after the 30-day retention window while preserving append-only hash receipts.
0.2.1 — 2026-09-15 (prerelease)
- Add the compiled JavaScript entry required for remote OpenClaw Git installs.
- Mark the host
openclawpeer dependency optional to avoid a nested host install.
0.2.0 — 2026-09-15 (prerelease)
- Add the guarded autonomous controller, explicit state machine, daily budgets, private storage, revision-bound tokens, snapshots, canary, and rollback.
- Add a native OpenClaw 2026.9.1 plugin with seven sanitized/evaluation hooks.
- Add the OpenClaw release archive and isolated autonomous gate tests.
0.1.0 — 2026-09-15
- Establish one portable Agent Skills catalog for OpenAI, Claude Code, and Hermes Agent.
- Add a dependency-free shared runtime, privacy-allowlisted lifecycle adapter, and deterministic ESRA 1.2 exporter.
- Add thin host manifests and installation adapters.
- Add deterministic marketplace, Claude, and Hermes release distributions.
- Add structural, runtime, privacy, exporter, adapter, and packaging tests.