Upgrading from v0.78.0

Review permissions before installing

Stop agnostic-ai watch before installing or regenerating files. Package install hooks can run sync, so make these permission edits first.

Bare lowercase permission rules now take effect. In v0.78.0, allow: [shell] matched no native tool. In v0.79.0, it allows the whole shell capability. The same change applies to bare read, edit, write, web, and whole-server mcp:<server> rules under allow or ask.

Review each such rule in your settings specs before upgrading. Remove an unintended rule or scope it, for example to shell(git status), read(src/**), or mcp:github/get_issue. web has no scoped neutral form; use a target-native rule or a scoped Claude Code alias where supported. LINT038 and sync notes name the effective native permissions. See permission rules.

Codex exact allows get narrower. Sync now omits an exact allow such as Bash(git push) when translating it would also allow extra arguments. Keep that omission if you intended an exact command. To permit the whole prefix, change the rule explicitly to Bash(git push:*). With on-unsupported: error, a rule that would widen stops sync. See Codex exec policies.

Kilo Code also applies Edit deny and ask rules to writes. Overlapping rules let deny and ask win over allow. A previously allowed write can now require approval or be refused.

Install the release through your usual install channel. For a standalone binary:

agnostic-ai upgrade --version v0.79.0

If your config pins requires or a schema version, update the pin for this release. Preserve a deliberate minimum or range. upgrade --requires replaces requires with an exact installed-version pin and runs sync, so use it only when that is your intended policy and after the permission review. Global home pins need a manual edit.

Prepare MCP values for stricter checks

MCP env and headers values should use ${NAME} references for secrets and !literal for plain settings. LINT035 is a warning in v0.79.0, and sync still writes unmarked values. lint --strict fails on them. A later release will make lint and sync refuse them; the switch will be announced one release ahead.

Preview and apply the secrets migration:

agnostic-ai migrate --only secrets --dry-run
agnostic-ai migrate --only secrets

Set every environment variable the command names before using the affected servers. Inspect any skipped values yourself. The migration cannot decide every credential-shaped case, and it leaves pack specs to their author.

A plain setting and a token reference look like this inside an MCP spec:

env:
  GITHUB_TOKEN: ${GITHUB_TOKEN}
  NODE_ENV: !literal production

For an editor using the YAML language server, add !literal scalar to yaml.customTags. See MCP secrets and plain settings for exceptions and variable handling.

Adopt the new spec forms when useful

Old hook forms, Claude Code tool aliases, and agnostic.config.yaml remain valid. These migrations are optional:

agnostic-ai migrate --list
agnostic-ai migrate --only config,hooks,capabilities --dry-run
agnostic-ai migrate --only config,hooks,capabilities

The config group renames the old config filename. hooks adopts portable events where the native event and matcher map exactly. capabilities rewrites agent tools, skill allowed tools, and permission aliases where the neutral form means the same thing. Each skipped case is reported.

Use migrate --global for specs in your global home, including secrets and capabilities. It also checks the home's local layer. Packs remain unchanged. Set any new secret references there too. See the migration reference.

Finish with agnostic-ai lint, agnostic-ai sync, and agnostic-ai sync --check. For a global home, run those commands with --global as well. Restart watchers after the regenerated files pass your checks.

What agnostic-ai changed

Name what an agent or skill may do

Agents accept can, skills accept allowed-tools, and settings permission lists accept neutral capabilities. You can name read, edit, shell, web, delete, or an MCP server without choosing one vendor's tool names. read and edit accept path patterns; shell accepts command patterns.

An agent frontmatter example:

---
name: reviewer
description: Review changes under src without editing them.
can: [read(src/**), shell(git diff *), mcp:github/get_issue]
---

Use the same list under a skill's allowed-tools. Claude Code aliases remain valid, and you can mix them with neutral names. delete maps only where the target has a native tool for it.

explain shows each target's native tool names, overrides, and added access. For example, Kiro's edit category includes deletion too. Sync names that widening, and on-unsupported: error rejects it. A tool's own permission system still controls what it can enforce. See agent capabilities and skill allowed tools.

Import uses neutral names when native tools map exactly. Optional lint --suggest-capabilities suggests conversions without adding warnings to the default lint run.

Share a guard across hook systems

Portable on events and match tool kinds map to 13 targets. Native overrides still apply, and import recognizes the effective event, matcher, command, and arguments. An unsupported event or tool kind raises a coverage note.

A before-tool guard can opt into JSON decisions:

name: review-shell
on: before-tool
match: shell
decision: stdout
command: .agnostic-ai/scripts/review-command.sh

At exit 0, the script can print {"decision":"deny","reason":"Use --force-with-lease."} to block the call. ask blocks too. Empty stdout or an allow decision continues under the tool's existing permissions. Malformed output, raw control bytes checked by the parser, and parser-limit failures block. Send logs to stderr.

The wrapper needs bash. Augment cannot run it, and decision: stdout cannot combine with PowerShell or commandWindows. Cursor and Copilot portable wrappers also need bash; their usual PowerShell command path on Windows cannot start them. Check the hook reference before adopting the protocol.

Cursor gains portable session and prompt events as well as before-tool. After-tool and stop events remain unmapped because Cursor cannot block them with the same semantics. Project hooks shared with Claude Code avoid a second run on Cursor under the documented conditions. Cline's hook files now reach its CLI and VS Code extension, and exit 2 blocks. See the portable event matrix for each tool's limits.

hook run uses Git Bash for Claude Code on Windows and preserves command failures even when another result is excluded from comparison. Run it after sync to test the guard your targets will execute.

Catch spec mistakes while the agent works

init --demo seeds a force-push guard and two spec guards. After a spec edit, the agent sees lint errors in the files it touched. At stop, it sees a notice when specs need sync. The guards report problems without running sync themselves.

lint --files and hook guard also let you add those checks to existing projects. New agent scaffolds omit a model choice, and lint flags placeholder TODO descriptions. See spec guard hooks.

Keep instructions portable without duplicating roles

Body references such as {{$AGENT:reviewer}} and {{$SKILL:commit}} render each tool's invocation phrase. Shared entry points, review sections, and nested AGENTS.md files expand path variables when all readers agree on the path. When they disagree, sync keeps the token and names the file. See body references.

Amp, Crush, Warp, and Zed can opt into agents as on-demand skills through outputs.<target>.agents: skill. The role then runs inline. If a tool with subagents reads the same skill directory, sync refuses that fallback there and names the conflict. Use a private skills directory to keep the roles separate. See agents as skills.

Every change is in the v0.79.0 release notes.

What changed in the targets

The October 4 target check examined these Kiro features. Their launch dates precede v0.78.0; the support limits below describe what you can use with this release.

Kiro Workflows, September 30: CLI 2.26.0 and IDE 1.2.4 introduced opt-in background workflows. Enable them in Kiro and keep recipes under .kiro/workflows/. The feature must be available for your account, and an untrusted workspace cannot load its recipes. agnostic-ai writes agent definitions but does not generate workflow recipes. Kiro Workflows, dated changelog.

Kiro CLI 2.27.0, October 1: steering can include live file context with #[[file:docs/api.md]]. CLI V3 also accepts line ranges and folder listings. Put this syntax in a rule scoped to targets: [kiro]: agnostic-ai preserves the text, and Kiro resolves it under its file-read policy. Steering reference.