The operator pointed at ~/repos/claude-code-100x/claude-code-100x/build-site.js
as the annotation reference from the start. v4.2/v4.3 built a bespoke
playground instead. v5.0.0 deleted it. v5.0.1 pointed at /playground
document-critique (Claude-leads, wrong direction). v5.0.2 was operator-led
but too thin (line-click + freeform note, no intent). v5.0.3 finally
matches the reference.
scripts/annotate.mjs rewritten:
- Markdown rendered as proper article HTML (h1/p/li/ul/table/blockquote/pre)
instead of line-numbered raw lines.
- Pencil-toggle annotation mode in the topbar, default ON.
- Select text OR click any element → form popover at cursor.
- Three intent buttons: Fiks (red) / Endre (orange) / Spørsmål (blue).
- Comment textarea. Save (Cmd+Enter), Cancel (Esc).
- Section context auto-detected from nearest h1/h2.
- Sidebar panel: annotations grouped by section, intent badges,
snippet quotes, delete buttons, click-to-scroll with flash highlight.
- Copy Prompt: structured markdown export with intent labels.
- localStorage persistence keyed on absolute artifact path
(voyage-annotate:v2: prefix to avoid colliding with v5.0.2 state).
Tests: 12 (up from 10), all passing. npm test: 518 / 516 pass / 0 fail / 2 skipped.
Reference: ~/repos/claude-code-100x/claude-code-100x/build-site.js
lines 1431–2255 (annotation UI section).
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
108 KiB
Changelog
All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog.
v5.0.3 — 2026-05-13 — Annotation UX matches the claude-code-100x reference
No new breaking changes beyond v5.0.0. Forks consuming v5.0.2's
annotation HTML keep working — the file path and entry point are
unchanged. The internal localStorage key bumps from voyage-annotate: to
voyage-annotate:v2: to avoid mixing the v5.0.2 shape (line-click,
freeform notes) with the v5.0.3 shape (intent-tagged annotations).
Why
v5.0.2 shipped a too-simple annotation surface: click a line, write a
freeform note, save. The operator pointed at the existing
claude-code-100x/build-site.js annotation system as the actual
reference — pencil-toggle mode, text-selection capture, three intent
categories (Fiks / Endre / Spørsmål), a popover form at the
cursor, structured markdown export with intent labels. v5.0.3 brings
scripts/annotate.mjs up to that pattern.
This reference had been mentioned by the operator early in the conversation; the iteration through v5.0.0 / v5.0.1 / v5.0.2 reflects me reading past it and trying alternatives instead of just matching it. The loss is real and is documented here in plain terms so future maintainers don't repeat it.
Changed
scripts/annotate.mjs— rewritten to match theclaude-code-100x/build-site.jsUX:- Article rendering — markdown is rendered to proper HTML elements
(
<h1>/<p>/<ul>/<li>/<table>/<blockquote>/<pre>), not as line-numbered raw lines. Document reads as a normal article. - Annotatable elements — every heading, paragraph, list item, table
cell, blockquote, and code block gets a stable
data-anchor-id. - Pencil-toggle button in the topbar — annotation mode default ON. Toggle OFF to read normally and follow links.
- Click any annotatable element (in mode) → opens a form popover
at the cursor with: section context (auto-detected from nearest
h1/h2), anchored snippet (the exact selected substring via
window.getSelection()if any text is highlighted, else the element's text content up to 200 chars), three intent buttons (Fiks / Endre / Spørsmål), comment textarea, Cancel + Save. Save is disabled until an intent is picked. - Sidebar panel — collapsed by default; "Show annotations" button in the topbar opens it. Annotations grouped by section, sorted by document order. Each card shows the intent badge (colored by category), the anchored snippet, the operator comment, and a delete button. Click a card to scroll the article to that element + flash highlight.
- Copy Prompt — structured markdown:
### N. [Intent] Section: <section>+Quote: «<snippet>»+Comment: <text>. Copies to clipboard. - Clear all — wipes every annotation for the current artifact (after confirm).
- Persistence —
localStoragekeyvoyage-annotate:v2:<abs path>. Refresh/close/reopen the same HTML keeps every annotation. - Toast feedback for save / copy / clear.
- Article rendering — markdown is rendered to proper HTML elements
(
tests/scripts/annotate.test.mjs— refreshed for the v5.0.3 shape: pins the three intent buttons (data-intent="fiks"/"endre"/"spørsmål"), form popover, selection capture, section auto-detect,voyage-annotate:v2:storage key prefix,data-anchor-idcoverage, Copy Prompt + Clear all affordances, and the markdown renderer's heading / list / table / blockquote / code-fence output. 12 tests (up from 10), all passing.
Notes
- The producing commands (
/trekbriefStep 4g,/trekplanPhase 10,/trekreviewPhase 8) callscripts/annotate.mjsthe same way as in v5.0.2 — no change to their wiring beyond the build-output now being the v5.0.3 interactive surface. npm test: 518 tests, 516 pass, 0 fail, 2 skipped (up from 516 — 2 new annotate tests for hostile-content escape + renderMarkdown table/ blockquote coverage).- Reference:
~/repos/claude-code-100x/claude-code-100x/build-site.jslines 1431–2255 (annotation UI section). - Version bump 5.0.2 → 5.0.3 in
.claude-plugin/plugin.json,package.json,package-lock.json, pluginREADME.mdbadge.
v5.0.2 — 2026-05-13 — Operator-driven annotation HTML (the actual fix)
No new breaking changes beyond v5.0.0. Forks that consumed the v5.0.1
/playground document-critique invocation from the producing commands'
final report should switch to opening the .html that scripts/annotate.mjs
now produces directly.
Why
v5.0.0 added a read-only scripts/render-artifact.mjs HTML render that
didn't afford annotation. v5.0.1 deleted that and pointed operators at
/playground document-critique instead — but the document-critique
template pre-generates Claude's suggestions and asks the operator to
approve/reject them. The operator asked for the opposite: a surface where
they select content and write their own notes, then ship those
notes back to Claude. v5.0.1 still missed the actual ask.
v5.0.2 ships scripts/annotate.mjs — a small, focused, zero-dependency
Node script that takes any artifact .md and writes a self-contained
HTML next to it. The HTML renders the document with line numbers, lets
the operator click any line to attach their own note, keeps a sidebar of
all notes (editable + deletable, persisted in localStorage per artifact
path so refresh doesn't lose work), and exposes a "Copy Prompt" button
that gathers every note into one structured prompt. The operator copies
that prompt and pastes it back into Claude; Claude revises the .md
freehand from the notes. One file → one HTML → click + write notes →
copy prompt → paste back. No Claude-generated suggestions in the loop.
The operator drives every annotation.
This is the v4.2/v4.3 concept (operator-driven annotation) without the
broken v4.2/v4.3 UX, without the 388 KB SPA, without /trekrevise,
without anchor parsers + Handover 8 + the JSON batch round-trip. ~430
lines of self-contained .mjs. Zero npm deps. Deterministic.
Added
scripts/annotate.mjs— operator-annotation HTML generator. Takes<artifact.md>, writes<artifact>.html(or--out <file>). Self-contained, design-system-aligned (light + dark + print), zero external network, deterministic. CLI:node scripts/annotate.mjs <artifact.md> [--out <file.html>]. Alsonpm run annotate -- <artifact.md>.tests/scripts/annotate.test.mjs(10 tests) — self-contained HTML shape, no external<link>/<script src>, inline script parses, source content + path embedded, HTML escaping in title + body (XSS surface), determinism, default output path, arg parsing, and the operator-driven affordances (Click any line, Your annotations sidebar, Copy Prompt, Clear all, localStorage).npm run annotateconvenience script.
Changed
commands/trekbrief.mdStep 4g,commands/trekplan.mdPhase 10,commands/trekreview.mdPhase 8 — each now runsscripts/annotate.mjsafter the artifact is final and prints the resultingfile://<abs path>link with explicit "Click any line to add YOUR OWN note" instructions. The v5.0.1/playground build a document-critique playground for …line is removed from all three.tests/lib/doc-consistency.test.mjs— replaced the v5.0.1/playgroundpins with v5.0.2 pins:scripts/annotate.mjsexists; producing commands invoke it; producing commands no longer print the v5.0.1/playground document-critiqueline; producing commands signal operator-driven annotation in their prose; CHANGELOG has a v5.0.2 entry.- Plugin
CLAUDE.md+README.md+ rootCLAUDE.md+ rootREADME.md+.claude-plugin/marketplace.json— voyage description updated from "v5.0.1 /playground invocation" to "v5.0.2 operator-annotation HTML (scripts/annotate.mjs)".
Notes
/playgroundis unchanged — the officialclaude-plugins-officialplaygroundskill is great for the Claude-leads, operator-reacts flow; it just wasn't the right tool for operator-leads, Claude-reacts.npm test: 516 tests, 514 pass, 0 fail, 2 skipped (up from 503 — 10 newannotate.test.mjstests + 3 net new doc-consistency pins).- Version bump 5.0.1 → 5.0.2 in
.claude-plugin/plugin.json,package.json,package-lock.json, pluginREADME.mdbadge.
v5.0.1 — 2026-05-13 — Drop the standalone HTML render; print a literal /playground invocation
No new breaking changes beyond v5.0.0. Forks that consumed
scripts/render-artifact.mjs directly (or invoked npm run render) must
remove that integration. Nothing else moves.
Why
v5.0.0 had /trekbrief, /trekplan, and /trekreview each finish by
both rendering a read-only {artifact}.html view (via the new
scripts/render-artifact.mjs) and printing a vague instruction to "run
the /playground plugin (document-critique template) on the .md and
paste the prompt back". In practice the operator saw two HTMLs in their
project dir, no annotation UI on the rendered .html, and had to guess
the right /playground invocation. The read-only .html added confusion
without affording annotation — it duplicated work the /playground
HTML already does (formatted document on the left, annotations on the
right, Copy Prompt button at the bottom).
v5.0.1 deletes the redundant render and makes the printed /playground
invocation literal and copy-paste-ready. One paste from the operator
launches the playground skill, which loads its document-critique
template, reads the .md, builds the interactive HTML, opens it. Mark
suggestions, click Copy Prompt, paste back. Done.
Removed
scripts/render-artifact.mjs— the v5.0.0 standalone Markdown→HTML renderer (~280 lines, zero deps). Redundant with/playground's HTML.tests/scripts/render-artifact.test.mjs(and the now-emptytests/scripts/dir).npm run renderscript alias inpackage.json.- All references to
render-artifact.mjs,brief.html,plan.html,review.htmlinCLAUDE.md(plugin + root),README.md(plugin + root),.claude-plugin/marketplace.json, and the three command files' final-output blocks.
Changed
commands/trekbrief.mdStep 4g (Finalize),commands/trekplan.mdPhase 10 (Present and refine),commands/trekreview.mdPhase 9 (Present summary) — each now ends by printing a single boxed block with the literal text/playground build a document-critique playground for {abs_path}and a one-paragraph explanation of the paste-mark-copy-paste loop. The literal string is pinned bytests/lib/doc-consistency.test.mjsso it cannot soften back into "run the/playgroundplugin" without a test failure.tests/lib/doc-consistency.test.mjs— replaced the v5.0.0render-artifact.mjs exists+producing commands reference render-artifact.mjspins with v5.0.1 pins:render-artifact.mjsno longer exists; producing commands include the literal/playground build a document-critique playground forinvocation; producing commands no longer referencerender-artifact.mjs;package.json scripts.renderis gone; CHANGELOG has both v5.0.0 and v5.0.1 entries.- Plugin
CLAUDE.md— "Render-and-link (v5.0.0)" paragraph rewritten to "Post-command annotation invocation (v5.0.1)" explaining the literal-paste contract; project-directory contract no longer lists.htmlsiblings; "State" section's project-root inventory no longer lists.htmlfiles. - Plugin
README.md— "Rendered artifacts & annotation (v5.0.0)" section rewritten to "Reviewing and annotating artifacts (v5.0.1)" with a worked example of the printed output and a "What v5.0.1 changed from v5.0.0" sub-note. Top-of-README one-liner + bottom "Known limitations" note updated. - Root
CLAUDE.md+ rootREADME.md+.claude-plugin/marketplace.json— voyage description updated to v5.0.1 + the one-paste invocation model.
Notes
/playgroundis theplaygroundskill fromclaude-plugins-official. It must be installed in the operator's environment for the printed command to work. If it isn't, the same effect is achievable by pasting the.mdcontent into Claude with "review this and suggest changes" — manual freehand revision.npm test: 503 tests, 501 pass, 0 fail, 2 skipped (down from 509 — 8render-artifact.test.mjstests removed; the doc-consistency pins were updated to v5.0.1 contracts, net +2 tests).- Version bump 5.0.0 → 5.0.1 in
.claude-plugin/plugin.json,package.json,package-lock.json, pluginREADME.mdbadge.
v5.0.0 — 2026-05-12 — Remove the bespoke playground; render artifacts to HTML + link
Breaking. /trekrevise is removed. The playground/ directory, Handover 8
(annotation → revision), and all of its supporting lib/ modules and tests are
gone. Forks that depended on /trekrevise, the playground HTML, lib/parsers/anchor-parser.mjs,
lib/parsers/annotation-digest.mjs, lib/util/markdown-write.mjs, or
lib/util/revision-guard.mjs must migrate to the official /playground plugin
(document-critique / diff-review templates).
Why
v4.2/v4.3 built a ~388 KB bespoke playground SPA — vendored markdown-it +
highlight.js + DOMPurify, a design-system copy, a dashboard, drill-down, custom
annotation gestures, an anchor parser, and a Playwright e2e suite — to let
operators annotate brief/plan/review artifacts in a browser and fold those
annotations back via /trekrevise (Handover 8). A 2026-05-12 browser
walkthrough found it borderline unusable (annotation broken in the drill-down,
dashboard didn't take over, no in-context anchor markers, wrong anchor
derivation, broken guide-panel chrome). And it duplicated work the official
/playground plugin already does well: document-critique and diff-review
templates produce clean, self-contained single-file HTML for exactly this. The
NIH cost was real; the lasting value of v4.2/v4.3 is this cautionary record.
Lesson: reach for existing capabilities before building bespoke ones, and
walk the UI in a browser before shipping it.
Removed
plugins/voyage/playground/— the whole directory:voyage-playground.html, itsREADME.md, vendoredlib/(markdown-it / highlight.js / DOMPurify / manifests), and the vendoredplayground-design-system/copy (the canonicalshared/playground-design-system/is untouched — other plugins still use it)./trekrevise—commands/trekrevise.mdand thetrekreviseblock insettings.json.- Handover 8 (annotation → revision) — deleted from
docs/HANDOVER-CONTRACTS.md; back to seven handovers. lib/parsers/anchor-parser.mjs,lib/parsers/annotation-digest.mjs,lib/util/markdown-write.mjs(readAndUpdate),lib/util/revision-guard.mjs.scripts/vendor-playground-libs.mjs,playwright.config.mjs,tests/e2e/(a11y + network specs + snapshots),tests/playground/,tests/fixtures/playground/,tests/fixtures/screenshot-project/,tests/fixtures/annotation/.- Tests for the removed modules —
tests/parsers/anchor-parser.test.mjs,tests/parsers/annotation-digest.test.mjs,tests/integration/annotation-roundtrip.test.mjs,tests/integration/annotation-block-boundary.test.mjs,tests/integration/annotation-export-schema.test.mjs,tests/integration/schema-rollback.test.mjs,tests/lib/revision-guard.test.mjs,tests/lib/markdown-write.test.mjs,tests/lib/source-annotations.test.mjs,tests/validators/{brief,plan,review}-validator-annotation-fields.test.mjs, and the oldtests/scripts/render-artifact.test.mjs(a fresh one ships in this release). docs/annotation-quickstart.md,docs/sc1-checklist-verification.md,docs/screenshots/.commands/trekplan.mdPhase 9plan_critic-injection block (and itsagents/planning-orchestrator.mdmirror) — itimported the now-deletedlib/util/markdown-write.mjs. Theplan_criticfrontmatter field is no longer written.devDependencies(@axe-core/playwright,@playwright/test) and thetest:e2escript inpackage.json;package-lock.jsonsynced (no runtime deps — it's near-empty).- The annotation-frontmatter HTML-comment preambles in
templates/{trekbrief,plan,trekreview}-template.md(the validators still tolerate unknown frontmatter keys; nothing emitsrevision:/source_annotations:/annotation_digest:anymore).
Added
scripts/render-artifact.mjs— a small (~280 lines), zero-dependency Node renderer. Reads a.mdartifact, folds frontmatter into a<details>block, renders a hand-rolled markdown subset (ATX headings, ordered/unordered/nested lists, fenced code blocks, inline code, bold/italic, links, blockquotes, GitHub-style tables, horizontal rules), and emits a self-contained HTML file with an inlined, design-system-aligned stylesheet (light + dark + print). Zero external network, zero build step, deterministic (byte-identical on re-run). CLI:node scripts/render-artifact.mjs <artifact.md> [--out <file.html>]; alsonpm run render.- Render-and-link step at the end of
/trekbrief,/trekplan, and/trekreview— each renders its just-written.mdto{project_dir}/{artifact}.htmland prints thefile://link plus a one-liner: to annotate, run the/playgroundplugin (document-critique) on the.mdand paste the generated prompt back; Claude revises the artifact freehand. tests/scripts/render-artifact.test.mjs(fresh, 8 tests) — self-contained-document shape, frontmatter<details>folding, title derivation, headings/code-fences/lists/tables/blockquotes rendering, HTML escaping, determinism, default output path, arg parsing.tests/lib/doc-consistency.test.mjsv5.0.0 pins —playground/gone,commands/trekrevise.mdgone, Handover 8 gone,render-artifact.mjsexists, producing commands referencerender-artifact.mjsand/playground, CHANGELOG has a v5.0.0 entry and retains the v4.2.0 entry, and no source file (outside CHANGELOG) referencestrekrevise.
Notes
- Resolves the three v4.3.1-deferred findings as moot:
87069b35andc6c64a58targetedplayground/voyage-playground.html(deleted);4cc3bfc9targeted the Phase 9readAndUpdateblock incommands/trekplan.md(deleted). - Command count: seven → six (
/trekbrief,/trekresearch,/trekplan,/trekexecute,/trekreview,/trekcontinue; plus the/trekendsessionhelper). npm testis the fork-readiness gate;npm run test:e2eis gone (no Playwright).
v4.3.0 — 2026-05-10 — Playground rebuild: dashboard-centric + visual parity + anchor-rendering matures
Additive. No breaking changes. Forward-compat with every brief / plan / review / playground export written before v4.3.
The v4.2 playground proved the annotation loop. v4.3 rebuilds it from the ground up against the design-system reference (plugins/llm-security/playground/llm-security-playground.html) and brings anchor-rendering to maturity. Dashboard-centric layout, file://-loader (webkitdirectory + drag-drop + URL-parameter), block-boundary anchor placement, screenshots-spor convention, and a hardened test pyramid (Groups A-D).
Added
- Dashboard-centric layout —
fleet-gridoffleet-tileper artifact (brief / plan / research / review) with status badges; click drills into artifact-detail surface. Two-overflate-modell matches voyage's domain (one plugin, no onboarding) — alternative 4-overflate-router rejected per Alternatives Considered. - File://-loader with three entry points —
webkitdirectorydirectory-picker (Chromium primary, Firefox 150+ secondary with Windows-bug guard), drag-drop withwebkitGetAsEntryrecursive walk, and URL-parameter?project=/abs/pathergonomic shortcut. Path-traversal + symlink/dotfile filter (isProjectPathSafe) blocks../node_modules//dist//build// hidden-paths witharia-liveannounces. - Anchor-rendering matures — block-boundary placement with code-fence/table/list-item fallback (Prettier #18066 workaround); browser-side
parseAnchormirrors Node-sidelib/parsers/anchor-parser.mjsregex; numbered-badge gutter + yellow-tint highlight replaces v4.2's pencil-icon; hidden-by-default sidebar-rail with ordered list, filter, and jumplist count; J/K keyboard navigation + Esc dismiss + aria-live announces; two-opacity pattern (active 100% / inactive 40% / resolved 30% strikethrough). - A11Y panel built from DS-primitives (Wave 5 Step 22) —
guide-panel--infocontainer withkey-statsseverity-grid +findings__itemsordered list;wireA11yTogglecouples topbar-button to panel;window.__voyage.scheduleRender({ a11yViolations })hook lets Playwright spec populate severities. - Screenshots-spor convention (Wave 5 Step 23) —
window.__voyagenamespace withnavigate(target),scheduleRender({ a11yViolations }), andgetProjectArtifacts()methods;docs/screenshots/README.mddocuments manual + Playwright-driven screenshot procedure (defers inline gallery to v4.4). - DOMPurify ≥ 3.1.1 vendored (Wave 5 Step 24) —
playground/lib/dompurify.min.js(22 KB UMD bundle);sanitizeAnnotationwraps user-comment markdown rendering; total bundle 388 KB / 460 KB HALT-gate (72 KB margin). HTML-comment indirect prompt-injection mitigation (Wave 5 Step 25) gatesstripUnsafeCommentsviaparseAnchorallowlist beforemd.render. - Voyage-scope DS-tokens (Wave 0 Step 1) —
--color-scope-voyage+badge--scope-voyageadded additively toshared/playground-design-system/dist/base.cssand re-synced into the playground vendor copy. Other plugins (architect / okr / llm-security / config-audit) re-sync on next playground touch (additive-only change). - Test pyramid Groups A-D (Wave 7) — Group A 17 static-HTML grep tests (SC1 10-element checklist + SC3 webkitdirectory/drag-drop + SC6 export markers + SC7 tag-level no-CDN), Group B 9 structure tests (DS-tokens + theme-toggle + sidebar-tab + keyboard pattern), Group C 7 export-bundle schema +
annotation_digestSHA-256 validity tests (SC-GAP-3), Group D 4 Playwright e2e tests (light/dark axe-core + pixel-diff baseline + zero-external-network authoritative gate). - Playwright + @axe-core/playwright devDeps +
playwright.config.mjs—testDir: 'tests/e2e',snapshotPathTemplate: '{testDir}/snapshots/{arg}{ext}',npm run test:e2escript. Chromium browser binary installed locally. tests/fixtures/playground/—v43-export-bundle.json(canonical export shape) +v43-plan-pre-annotate.md(revision: 0 seed with ANN-0001/ANN-0002 anchors).tests/e2e/snapshots/a11y-baseline.json— WCAG-violations delta-baseline (aria-hidden-focus,color-contrastper.key-stat--critical__label); a11y spec compares current against baseline, fails only on NEW or GROWN violations. Actual fix deferred to v4.4 (HTML FROZEN in Sesjon 6).docs/sc1-checklist-verification.md— per-element pass/fail with evidence (Group A test references + manual side-by-side); 8/10 PASS literal + 2/10 PASS-redef (Element 4 onboarding-grid → fleet-grid, Element 6 screenshots-spor → hooks + docs convention) per scope-guardian Assumptions 21+22.playground/README.md— v4.3 architecture, three entry-point usage,.claude/projects/discoverability, annotation flow,window.__voyagehooks, known limitations (FF150-Win, no FSA, baseline'd WCAG), bundle-size breakdown, test-suite overview.
Changed
- Test count: 672 → 711 pass / 0 fail / 2 skipped (713 total — Groups A/B/C node-test additions from the rebuild and the Sesjon 13–18 re-review remediation; +5 Playwright e2e specs run via
npm run test:e2e). - Theme bootstrap IIFE (Wave 2 Step 6) sets
data-theme="dark"as default; respectslocalStorage('voyage-theme')→prefers-color-scheme: darkmatchMedia → fallbackdark. Theme-toggle button in topbar (Wave 2 Step 7) persists user choice. - Page-shell pattern (Wave 2 Step 9) —
page__eyebrow+page__title+page__lede+page__metamatches DS reference. - Annotation export filename —
annotated-{target}.mdwhere target = brief|plan|review|artifact (derived from frontmatter).
Fixed
- Browser-side anchor regex synced with Node-side allowlist (Wave 4 Step 16) —
VOYAGE_ANCHOR_RE/VOYAGE_ANCHOR_ID_REmirrorlib/parsers/anchor-parser.mjs:20-25;parseAnchorvalidates ID + intent + line-number per attribute regex. - Hard-coded WIP token strings (Wave 1 Step 4) — voyage tokens normalized to canonical
--color-scope-voyage+--ds-color-*tokens; literal pixel font-sizes replaced with DS scale. - Plan-determinism test reference path (Wave 0 Step 3) —
tests/synthetic/plan-determinism.test.mjs:115updated toplan-run-C.md(alphabetic convention matching A/B).
Re-review remediation (Sesjon 13–18)
After the rebuild, an independent /trekreview (Sesjon 13) flagged 11 findings (5 BLOCKER + 5 MAJOR + 1 MINOR). Waves 1–3 of remediation closed all 11 with delivered code + tests — notably reinstating an inline screenshots gallery (renderScreenshotGallery, finding 31d28f65; supersedes the original "deferred to v4.4" item below), wrapping renderArtifact's bodyHtml in DOMPurify.sanitize (1d3591d4), converting the SC2 a11y spec to absolute zero-violation mode and removing a11y-baseline.json (09132940), documenting the Phase 9 plan_critic frontmatter injection (906f155d), and asserting the .fleet-grid 4-column CSS parity (99707f51). A Sesjon 18 re-review then found 3 new findings introduced by the remediation code itself — deferred to v4.3.1 (see Known issues below).
Deferred to v4.4
- WCAG-violations fix (HTML FROZEN in Sesjon 6 per Wave 7 verification-only scope; superseded for the a11y-spec by the absolute zero-violation conversion in the Sesjon 13–18 remediation).
- File System Access API (FSA) write-back (currently
Blob-download only). <project>/design/-folder traversal.IndexedDBprimary persistence (localStorage stays primary for v4.3).- Hybrid claude-design-skill → canvas → frontend-design workflow (research/02 deferred to v4.4+).
Known issues — deferred to v4.3.1 → all resolved in v5.0.0 (moot)
The Sesjon 18 re-review surfaced 3 findings in code the Sesjon 13–18 remediation introduced. They were deferred to a planned v4.3.1 patch; v5.0.0 makes all three moot by removing the playground entirely:
87069b35(SECURITY_INJECTION, defense-in-depth) —renderScreenshotGallery()interpolatedscreenshots[].dataUrlraw into an<img src>. Moot in v5.0.0 —playground/voyage-playground.htmlis deleted.4cc3bfc9(PLAN_EXECUTE_DRIFT) —commands/trekplan.mdPhase 9 used a backtick template literal as an ESimportspecifier (SyntaxError). Moot in v5.0.0 — the Phase 9plan_critic-injection-via-readAndUpdateblock is deleted.c6c64a58(MISSING_TEST) — no test covered the gallerydataUrlinjection path. Moot in v5.0.0 — the gallery and its host file are deleted.
Notes
- Brief, research (4 briefs), plan, and execute (6 sessions) all produced from the v4.3 pipeline itself. SC11 pipeline-self-eat gate continues to hold.
- Path A/B/C decision (cache-first / sequential
--no-ffwaves / hybrid identical-tool) unchanged from v3.4.0 — Path B remains in production. - Plan quality score 86/100 Grade A APPROVE_WITH_NOTES (adversarial review Phase 9, 22 revisions documented in plan.md Revisions table). Sesjon 13–18 remediation plans reviewed independently; Sesjon 18 re-review verdict BLOCK with 3 findings (now v4.3.1).
v4.2.0 — 2026-05-09 — Annotation pipeline + first voyage playground
Additive. No breaking changes. Forward-compat with every brief / plan / review written before v4.2.
Voyage's first interactive playground. The /trekrevise command and the
annotation pipeline (Handover 8) close the operator-feedback loop: render an
artifact in the browser, anchor comments at block boundaries, export a batch,
paste back as /trekrevise --apply for in-place revision with audit trail.
Added
/trekrevisecommand (commands/trekrevise.md) — seventh pipeline command. Phase 1 parse/validate, Phase 2 read source + rollback hygiene, Phase 3 parse anchors + validate placement, Phase 4 compute revision diff + digest, Phase 5 atomic apply, Phase 6 post-write integrity check, Phase 7 optional review-gate, Phase 8 stats + report. Accepts--profile,--gates,--reason,--from-file,--target.- Handover 8 (annotation → revision) documented in
docs/HANDOVER-CONTRACTS.md(~100 lines). Producer/consumer contract, schema for the four additive frontmatter fields (revision,source_annotations,annotation_digest,revision_reason), block-level anchor format, lifecycle, single-iteration MVP rationale. playground/voyage-playground.html— single self-contained HTML file with vendoredmarkdown-itv14.1+ +highlight.js(nomarkedper Issue #3515). Three annotation creation gestures (drag-select, hover-anchor, click-anchor), modal form with intent taxonomy (change/add/remove/ clarify/risk), sidebar with critique-card-list, export flow with one-click clipboard copy, A11Y baseline (keyboard nav, ARIA roles, focus traps).playground/lib/vendored markdown-it + highlight.js + front-matter plugin, withVENDOR-MANIFEST.jsonrecording version + license + sha. Locked at minimum versions per research-03.scripts/render-artifact.mjsserver-side render CLI — emits the same HTML the playground produces. Used by the SC11 pipeline-self-eat gate (rendering.claude/projects/*/brief.md+plan.mdexits 0 with non-empty output).scripts/vendor-playground-libs.mjsvendor-refresh helper — fetches pinned versions and updates the manifest.lib/parsers/anchor-parser.mjs— pure-function anchor parser:parseAnchors,addAnchors,stripAnchors,validateAnchorPlacement. Block-boundary discipline (no in-list, no mid-paragraph, no line-start collisions). Round-trip tested with byte-identical fixture (tests/fixtures/annotation/annotation-example.md).lib/parsers/annotation-digest.mjs— pure-function deterministic SHA-256 over canonical-sortedsource_annotations. First 16 hex chars. Idempotent: same batch → same digest.lib/util/markdown-write.mjs—serializeFrontmatter+atomicWriteMarkdown(tmp-file + rename, same crash-safety asatomic-write.mjs).lib/util/revision-guard.mjs— atomic-write rollback guard for/trekrevisePhase 6 round-trip integrity check (plan-critic M4). Restores byte-identical pre-write file from*.local.bakon failure.docs/annotation-quickstart.md— operator-facing 7-step walkthrough, referencestests/fixtures/annotation/annotation-example.mdfor hands-on verification.tests/fixtures/annotation/— 5 fixtures coveringbrief,plan,plan-large,review, and the canonicalannotation-example.md.- 9 new test files + extension to
tests/lib/doc-consistency.test.mjs:tests/lib/markdown-write.test.mjs(round-trip)tests/parsers/anchor-parser.test.mjs(parse/add/strip/validate)tests/parsers/annotation-digest.test.mjs(determinism)tests/validators/{brief,plan,review}-validator-annotation-fields.test.mjs(forward-compat: validators tolerate the four optional fields)tests/integration/annotation-roundtrip.test.mjs(SC2/SC3/SC7 byte-identical + scale)tests/integration/schema-rollback.test.mjs(SC5b validator-FAIL rollback)tests/integration/source-annotations.test.mjs(frontmatter audit trail)
Changed
- Forward-compat policy documented in
lib/validators/{brief,plan, review}-validator.mjsheaders — validators silently accept the four optional annotation fields without bumping*_version. tests/lib/doc-consistency.test.mjsextended with ~16 new pins: Handover 8 section, templates' annotation-field comment blocks,playground/directory,marked-ban,scripts/render-artifact.mjs,lib/util/revision-guard.mjs,parseAnchorsround-trip on the example fixture,/trekrevisein CLAUDE.md / plugin README / marketplace root README,## v4.2.0in CHANGELOG,docs/annotation-quickstart.mdexistence + ≤7 numbered steps +annotation-example.mdliteral reference.PIPELINE_COMMANDSconstant in doc-consistency tests — was 6 (brief/research/plan/execute/review/continue), now 7 (+ revise). Pin test renamed from "all six pipeline commands" to "all seven pipeline commands".settings.jsonknown-scopes allowlist —'trekrevise'added to the recognized top-level scope list (was added in Wave 2 Step 6 to keep tests green pre-Step 12).- Templates (
templates/{plan,trekbrief,trekreview}-template.md) prefixed with comment-only documentation block of the four optional annotation fields. No*_versionchange; existing templates still parse and validate identically.
Notes
markedis banned fromplayground/*(risk-assessor H1 + doc-consistency pin). Issue #3515 corrupts content silently after HTML comments in lists — voyage anchors after step-list would be invisible.markdown-itv14.1+ is the locked renderer.- Single-iteration MVP per research-05. Each operator batch produces
one
revision:increment. Multi-iteration loops (revise → re-review → revise again) are deferred indefinitely; the brief's SC4 wording is single-revision. - No
*_versionbump for v4.2 — the four new fields are additive. Brief/plan/review artifacts written before v4.2 validate asrevision: 0without migration. - Atomic-write contract for
/trekrevise— singlewriteFileSync+renameSync(research-05 Option B). Option C (atomicWriteJson + Edit-toolsplit-write) was inadmissible per risk-assessor C2: no crash-safe window between frontmatter patch and body Edit. - 608 tests pass (606 → 0 fail → 2 skipped Docker) — baseline before v4.2 was 490; this release adds ~118 tests.
v4.1.0 — 2026-05-09
Additive. No breaking changes. Forward-compat with all v4.0.0 plans.
Two new feature surfaces: model profiles (--profile <name>) and
opt-in OpenTelemetry / Prometheus export at session-end.
Added
- Model profile system (
lib/profiles/{economy,balanced,premium}.yaml,lib/profiles/resolver.mjs,lib/validators/profile-validator.mjs). Three built-in tiers + custom-yaml support. Lookup order: explicit--profileflag → plan frontmatterprofile:→VOYAGE_PROFILEenv-var →balanceddefault. Seedocs/profiles.mdfor the decision tree, custom authoring, and cost estimation disclaimer. --profile <name>flag documented in all 6 pipeline commands (commands/trek{brief,research,plan,execute,review,continue}.md).- 5 additive profile fields in JSONL stats (
profile,profile_source,phase_models,model_used,phase_models_resolved) for cost-attribution and drift detection. - OpenTelemetry / Prometheus export at session-end via new Stop
hook (
hooks/scripts/otel-export.mjs, wired inhooks/hooks.json). Strict opt-in viaVOYAGE_EXPORT_MODE:textfile— Prometheus exposition format → node-exporter textfileotlp— OTLP/JSON POST → otel-collectoroff(default) — no work done
- Local Docker Compose stack at
examples/observability/(Prometheus 3.0.1 + node-exporter 1.10.2 + Grafana 11.4.0 + OTel Collector 0.115.0, all version-pinned per research/01). - Operator documentation at
docs/observability.md(151 lines: env-var matrix, security mitigations, limitations, CVE-pinned minimum versions). - Cross-tier Jaccard smoke test
(
tests/integration/profile-jaccard-smoke.test.mjs) with parked- synthetic fixtures and 0.55 conservative starting threshold per research/02. Empirical recalibration deferred to v4.2. - MANIFEST_PROFILE_DRIFT warning in
plan-validator --strictwhen plan frontmatterprofile:differs from any step manifest'sprofile_used. Plan remains valid (warning, not error).
Changed
lib/parsers/arg-parser.mjsFLAG_SCHEMA — additively adds--profile <name>to all 6 commands. Existing flags unchanged.lib/parsers/manifest-yaml.mjsschema — additively adds newOPTIONAL_STRING_KEYScollection withprofile_usedas the first member. Forward-compat: legacy plans withoutprofile_usedparse unchanged; new plans with it round-trip cleanly.
Fixed
- Doc-consistency coverage now spans all 6 pipeline commands
(was 5 —
/trekcontinuewas missing per HIGH risk-assessor). - Plan-validator strict mode detects profile-drift between plan- level frontmatter and step-level manifests (brief Assumptions block 7).
Notes
- Forward-compat: every v4.0.0 plan validates
valid: trueunder v4.1.0'splan-validator --strict. No migration needed. - Tests: 361 baseline → 484 pass + 2 skipped (Docker-dependent).
- Path A/B/C decision (v3.4.0) is unchanged. Path C remains closed.
- v4.2 deferred items: ROUGE-L scoring, char-4gram MinHash, empirical
Jaccard re-calibration,
balanced.external_research_enabledoperator-override.
v4.0.0 — 2026-05-05
Breaking. Rebrand. No migration path.
The ultraplan-local plugin is renamed to Voyage. All seven commands
are renamed from /ultra*-local to /trek*:
/ultrabrief-local→/trekbrief/ultraresearch-local→/trekresearch/ultraplan-local→/trekplan/ultraexecute-local→/trekexecute/ultrareview-local→/trekreview/ultracontinue-local→/trekcontinue/ultraplan-end-session-local→/trekendsession
Internal renames: FLAG_SCHEMA keys, stats filenames, env vars, branch
namespace, type discriminators, hook stderr prefixes, settings.json scope
keys all updated to trek* form. Plugin identity is now voyage.
No backward compatibility. Old artifacts on user disks are orphaned. Fork-and-own users re-fork from main if they want to follow upstream; there is no migration helper.
See TRADEMARKS.md for the new trademark hygiene notice clarifying
independence from Anthropic.
Out-of-scope handoff (operator follow-up): plugin directory rename
plugins/ultraplan-local/ → plugins/voyage/, marketplace-root
coordination across ../../README.md, ../../CLAUDE.md, and
../../.claude-plugin/marketplace.json.
[3.4.1] - 2026-05-04 — /ultracontinue-local hot-fix + ultra-cc-architect doc-rydding
Forward-patch on top of v3.4.0. Fixes four bugs in the multi-session
resumption path discovered post-3.3.0 ship, plus a doc-rydding sweep
that generalizes references to the ultra-cc-architect plugin (no
longer publicly distributed). Non-breaking: the architecture/overview.md
filesystem contract (Handover 3) is preserved for any compatible
producer.
Fixed
- Bug 1 —
/ultracontinue-localPhase 0 + auto-discovery.commands/ultracontinue-local.mdno longer prints a usage block on bare invocation; it enters auto-discovery (sorts active state files numerically byDate.parse(updated_at), not lexicographically — fixes cross-timezone wrong-order).--help/-his the only flag that surfaces the usage block. (Steps 1–3) - Bug 2 — Phase 2 placeholder leakage.
{state-file-path},{project-dir},{path-a}and similar template tokens are gone fromcommands/ultracontinue-local.mdPhase 2 prose. The command now reads the resolved path inline rather than asking the model to substitute. (Steps 4–5) - Bug 3 — frontmatter consistency for
NEXT-SESSION-PROMPT.local.md. Producers (/ultraexecute-localPhase 8,/ultraplan-end-session-local) now writeproduced_by:+produced_at:(ISO-8601) frontmatter on the prompt file./ultracontinue-localPhase 1.5 cross-checksproduced_atagainst the sibling state file'supdated_atand refuses to proceed on inconsistency (NEXT_SESSION_PROMPT_INCONSISTENT). Files without frontmatter remain tolerated (warning, not error) for backwards compatibility. State-anchored staleness check is the primary signal; 24h wall-clock is a soft warning only. (Steps 6–8) - Bug 4 —
--cleanupfor completed projects./ultracontinue-local --cleanup <project-dir>(dry-run by default) and/ultracontinue-local --cleanup --confirm <project-dir>(deletes the state file + sibling prompt file). Refuses non-completed status with no force flag. Idempotent — safe to re-run after partial cleanup. (Steps 9–10) - ESM/CJS regression in
commands/ultraplan-end-session-local.md. Phase 3 now invokesatomicWriteJsonvianode --input-type=modulerather than the brokenrequire()call. State writes from the helper command are no longer silently lost on Node 18+. (Collateral in Step 7) plugin.jsondescription drift. "Five-command" → "Six-command"; trailingultra-cc-architectsentence removed. (Step 13)
Added
lib/util/cleanup.mjs— refuse-unless-completed gate + dry-run + confirm-aware deleter for state file and sibling prompt file.lib/validators/next-session-prompt-validator.mjs— frontmatter validator + state-anchored staleness check + CLI shim.tests/commands/ultracontinue.test.mjs— new test directory; covers SC-1 (auto-discovery sort + usage block), SC-2 (.md diagnostic), SC-3 (path-guard ALLOW + no placeholder), SC-4 (consistency), SC-5 (cleanup wiring).tests/validators/next-session-prompt-validator.test.mjs— unit coverage for frontmatter consistency: matching, mismatch, wall-clock, no-frontmatter, missing-field.tests/lib/cleanup.test.mjs— cleanup util tests.--cleanup+--confirmflags on/ultracontinue-local.
Changed
docs/HANDOVER-CONTRACTS.mdHandover 7 gains a § Lifecycle subsection documenting producer/consumer arbeidsdeling, the stale-file principle (operator-invoked--cleanup, no auto-cleanup, no force flag), theproduced_by:+produced_at:frontmatter contract, and idempotency.CLAUDE.md,README.md,SECURITY.md— generalize references toultra-cc-architectplugin to "opt-in upstream architect plugin (not bundled)".CHANGELOG.mdhistorical references are preserved with a 2026-05-04 banner stating the plugin is no longer publicly distributed.
Tests
- 322 (v3.3.0 baseline) → 358 (post-Wave 4) → 361 (Step 11 doc-pins) → ~363 at release. New tests: arg-parser FLAG_SCHEMA extensions, ultracontinue auto-discovery + diagnostic + path-guard + consistency + cleanup wiring, next-session-prompt-validator frontmatter checks, cleanup util, and 3 new doc-consistency pins for Handover 7 § Lifecycle + next-session-prompt-validator CLI shim.
[3.4.0] - 2026-05-04 — Ultra-pipeline speedup
Hardenings + scaffolding to support an autonomy chain from brief approval
through main-merge with parallel-wave execution. Non-breaking: all existing
flags continue to work; --gates is opt-in autonomy control. Plan-step
delivery covered by 18 plan-v2 steps split across three Waves.
Added — autonomy + parallelism
lib/util/autonomy-gate.mjs— autonomy-gate state machine (idle → approved → executing → merge-pending → main-merged) for the brief-to-merge chain (Step 4)lib/review/plan-review-dedup.mjs— deterministic plan-review dedup helpers reused by Phase 9 inline dedup (Step 5)lib/stats/event-emit.mjs— single-source stats event emitter for autonomy-gate transitions and main-merge-gate (Step 6 + 12)--gates {open|closed|adaptive}flag on all four pipeline commands (Step 11). Controls how many autonomy checkpoints surface to the operator. Defaultadaptive.hooks/scripts/post-compact-flush.mjs— PostCompact hook re-injects session-state after context compaction so multi-session work survives a compaction boundary (Step 13)
Added — hardenings + defense-in-depth
commands/ultraplan-local.mdPhase 8 schema-drift defense — post-generationplan-validator --strictrun blocks plans containing narrativeFase/Phaseheaders or missing Manifest YAML; addresses the documented Opus-4.7 plan/list-emission drift (Step 7, builds on v1.8.0 fix in commit9ecd669)commands/ultraplan-local.mdPhase 9 parallelization with inline dedup — single-message multi-Agent dispatch + plan-review-dedup helper (Step 8)commands/ultraexecute-local.mdPhase 2.6 wave-executor — 11 sub-hardenings for plugin-in-monorepo + gitignored-state topology: GIT_OPTIONAL_LOCKS, --max-turns, --max-budget-usd, scoped --allowedTools, --append-system-prompt-file, SHARED_CONTEXT_FILE, SAFETY_PREAMBLE, deferred git push origin, push-before-cleanup ordering, GH #36071 awareness (Step 9)templates/headless-launch-template.md— mirrors Phase 2.6 hardenings so the headless launcher is consistent with Phase 2.6 prose (Step 10)commands/ultraplan-local.md+agents/planning-orchestrator.mdPhase 8 main-merge gate — emit stats event for main-merge gate decisions (Step 12)
Added — quality infrastructure
tests/lib/agent-frontmatter.test.mjs— pins agent frontmatter invariants (Step 1-test)tests/synthetic/plan-run-A.md+plan-run-B.md+plan-determinism.test.mjs— SC7 plan-determinism floor (Jaccard ≥ 0.833) (Step 15)tests/synthetic/review-run-A.md+review-run-B.md+review-determinism.test.mjs— SC7 review-determinism floor (Jaccard ≥ 0.833) (Step 15)tests/hooks/path-guard.test.mjs— pins pre-write-executor BLOCK rules; regression detection if BLOCK_RULES are silently weakened (Step 18)tests/hooks/bash-guard.test.mjs— pins pre-bash-executor BLOCK rules (Step 18)examples/01-add-verbose-flag/perf-measure.local.sh(gitignored) — operator-driven SC1 wall-time measurement harness (Step 16)examples/01-add-verbose-flag/perf-baseline.local.md(gitignored) — SC1 gate template + measurement protocol (Step 16)
Changed
lib/parsers/manifest-yaml.mjs— schema extended additively to recognizeskip_commit_checkandmemory_writeflags (forward-compat: unknown keys ignored). Used by Step 14 and other steps that legitimately don't produce a git commit (Step 4).gitignore— generalized*.local.md+*.local.jsonrules into a single*.local.*glob, covering.local.shand any future.local.<ext>(Step 16)package.json—version3.3.0 → 3.4.0.claude-plugin/plugin.json—version3.3.0 → 3.4.0README.md+CLAUDE.md— version refs +--gatesflag docs + Wave 1+2+3 architecture notes- Marketplace root
README.md— ultraplan-local version line bumped 3.3.0 → 3.4.0
Memory updates (Step 14)
~/.claude/projects/-Users-ktg--claude-plugins-marketplaces-ktg-plugin-marketplace/memory/project_ultraplan_opus47_gap.md— rewritten per Path B (memory truth gate). New body: (a) historical context referencing commit9ecd669(v1.8.0 fix, 2026-04-17), (b) empirical evidence (5 organic plans 2026-04-18 → 2026-05-01 all clean per research/04 D1), (c) defense-in-depth added in Step 7 (commands/ultraplan-local.mdPhase 8), (d) residual risk surface for plugins NOT using ultraplan-local prompt arch.~/.claude/projects/.../memory/MEMORY.md— one-liner updated to flag mitigation status. The drift mechanism stays a known model-level risk; the plugin-level mitigation is documented.
These memory edits are recorded here because the files live outside the repo and have no git checkpoint of their own.
Architecture decision (Path B not Path C)
Brief offered three architectural options for the speedup work:
- Path A — cache-first (drop --allowedTools per child) — REJECTED. Inverts security model; plugin hooks don't fire reliably in
claude -p(research/06 GH #36071). - Path B — sequential
--no-ffparallel waves with manifest-driven failure recovery — CHOSEN. v3.4.0 ships this. - Path C — hybrid (cache-warm sentinel + identical-tool parallel) — DEFERRED to v3.5.0 contingent on cache-telemetry data harvested by Step 6's stats events. Requires unverified Q3 (CLAUDE_CODE_FORK_SUBAGENT cache-prefix preservation at 150-250K context).
Tests
- 265 baseline (post-Wave-2) → ~290+ green after Wave 3 (Steps 15 + 18 add ~25 tests; doc-consistency may add a couple more pin tests)
Open Questions for v1.1
- Real-LLM determinism measurement — synthetic floor (0.833) is anchored; the foreign-repo run against
examples/01-add-verbose-flag/for SC1+SC4+SC5 measurement is a separate post-ship session. - Cache-telemetry harvest — Step 6 stats events emit shapes useful for Path C decision; harvesting + analysis is v1.1 work.
- Marketplace-level autonomy-gate — currently per-plugin scope. Marketplace-wide policy + dashboards are out of scope for this solo project.
[3.3.0] - 2026-05-01
Adds /ultracontinue-local — a zero-friction multi-session resumption command —
plus the contracted Handover 7 (.session-state.local.json) that any
session-end mechanism may write. Non-breaking: existing brief / research / plan /
execute / review pipelines are untouched. The state file is the contract;
/ultracontinue only reads.
Added
/ultracontinue-localcommand — read.session-state.local.jsonand immediately resume the next session in a multi-session ultraplan project (model: opus)/ultraplan-end-session-localhelper — informal multi-session flows write the state file via this command (model: sonnet)lib/validators/session-state-validator.mjs— schema-v1 validator + CLI shim for.session-state.local.json(forward-compat: unknown top-level keys ignored)lib/util/atomic-write.mjs—atomicWriteJson(path, obj)extracted frompre-compact-flush.mjsfor reusetests/fixtures/session-state/{valid-in-progress,malformed}.json— synthetic fixtures- Handover 7 (.session-state.local.json) — full schema documented in HANDOVER-CONTRACTS.md
- Doc-consistency pins:
Handover 7,session-state-validatorCLI shim,/ultracontinue-localin CLAUDE.md commands table - ~22 new tests (163 baseline → 185 green; atomic-write + session-state-validator + doc-consistency pin extensions)
Changed
commands/ultraexecute-local.md— Phase 8 (canonical end-of-session), Phase 2.55 (pre-flight stop), Phase 4 (entry-condition stop) now write.session-state.local.jsonas a sibling toprogress.json(Handover 7 producer)hooks/scripts/pre-compact-flush.mjs— also refreshes.session-state.local.jsonbefore context compaction (monotonic; never advances state to a non-resumable status).gitignore— covers*.local.json(state files never enter git)
Tests
- 163 baseline → 185 green (+22 new)
Open Questions for v1.1
- graceful-handoff convergence: graceful-handoff v2.2 may dual-write
.session-state.local.jsonso a single chat-end mechanism feeds/ultracontinue. v3.3.0 ships the contract; convergence is additive. /continuebuiltin Claude Code collision (unverified) —/ultracontinueprefix mitigates risk; monitor release notes.
[3.2.0] - 2026-05-01
Adds /ultrareview-local as the fifth and final command in the ultra-suite —
independent post-hoc review of delivered code against the brief — and the
contracted Handover 6 (review → plan) feedback loop. Non-breaking: existing
brief/research/plan/execute pipelines are untouched.
Added
/ultrareview-localcommand — fifth and final command in ultra-suite (independent post-hoc review of delivered code against brief)lib/validators/review-validator.mjs— schema validator for newtype: ultrareviewartifactlib/review/rule-catalogue.mjs— 12 canonical rule keys (version-pinned)lib/parsers/finding-id.mjs— stable SHA1 finding-ID computationlib/parsers/jaccard.mjs— Jaccard similarity for determinism testing- 4 new agents: review-orchestrator (opus inline ref), brief-conformance-reviewer, code-correctness-reviewer, review-coordinator (Judge Agent pattern)
- Handover 6 (review → plan) — contracted feedback loop documented in HANDOVER-CONTRACTS.md
- ~43 new tests (109 → ~152 baseline; rule-catalogue + finding-id + jaccard + review-validator + brief-validator extension + arg-parser extension + project-discovery extension + 4 doc-consistency pins + 3 review-determinism integration + 3 source-findings SC3(b) integration)
Changed
brief-validator.mjsacceptstype: ultrareviewin addition toultrabrief(Handover 6 enabler)/ultraplan-localconsumestype: ultrareviewbrief — extracts findings as plan goals + populatessource_findingsarray in plan frontmatterlib/parsers/project-discovery.mjsdiscoversreview.mdand supports'review'phaselib/parsers/arg-parser.mjsaddsultrareviewcommand to FLAG_SCHEMAhooks/scripts/session-title.mjsadds/ultrareview-localto COMMANDS map- Severity vocabulary aligned with llm-security:
Critical | High | Medium | Low | Info(rule-catalogue retains the 4-tier brief vocabulary; 5-tier migration is a v1.1 candidate)
Tests
- 109 baseline → ~152 green (+43 new)
Open Questions for v1.1
- Migrate 4-tier severity (BLOCKER/MAJOR/MINOR/SUGGESTION) → llm-security 5-tier (Critical/High/Medium/Low/Info) — research/02 advised but deferred to keep brief contract intact.
- Real-LLM determinism measurement (current SC4 test uses synthetic fixtures).
- SC2 end-to-end false-positive integration test (currently agent-prompt-level only).
[3.1.0] - 2026-05-01
Quality program: pure quality lift, no scope creep. Built around the fork-er onramp — anyone cloning this plugin should get value out of the box. 109 zero-dep tests gate readiness.
Added — testing & validation infrastructure (Spor 0+1)
package.jsonwithnode:testrunner and zero npm dependencies (engines.node>=18)lib/util/{result,frontmatter}.mjs— Result-shape helpers and a hand-rolled YAML subset parser supporting list-of-dicts (the form used bymust_containin real plans)lib/parsers/{plan-schema,manifest-yaml,project-discovery,arg-parser,bash-normalize}.mjs— primitive parserslib/validators/{brief,research,plan,progress}-validator.mjsandlib/validators/architecture-discovery.mjs— wrappers over parsers, each with a CLI shim (if (import.meta.url === ...)) so they can be invoked from Bash vianode ${CLAUDE_PLUGIN_ROOT}/lib/validators/X.mjstests/lib/*+tests/validators/*— 109 teststests/lib/doc-consistency.test.mjs— pins agent-table count, command-table coverage, plan_version invariant, and settings.json scope cleanliness; first-red surfaces drift between docs and code
Changed — wiring (Spor 1)
| Site | Was | Is |
|---|---|---|
/ultrabrief-local Phase 4g |
implicit trust | node lib/validators/brief-validator.mjs --json |
/ultraplan-local Phase 1 |
inline frontmatter parse + test -f |
brief-validator --soft + research-validator --dir + architecture-discovery |
agents/planning-orchestrator.md Phase 5.5 |
three grep -cE calls |
single node lib/validators/plan-validator.mjs --strict --json |
/ultraexecute-local Phase 2.3 (--validate) |
inline regex | plan-validator --strict + progress-validator |
Validators default to strict: false. Only --validate mode and Phase 5.5 use --strict. Existing in-flight projects under .claude/projects/ continue to work.
Added — handover contracts (Spor 2)
docs/HANDOVER-CONTRACTS.md(~310 lines) — single source of truth for the 5 pipeline handovers (brief→research, research→plan, architecture→plan EXTERNAL, plan→execute, progress.json resume). Per-handover sections: Producer / Consumer / Path conventions / Frontmatter schema / Body invariants / Validation strategy / Versioning / Failure modes. Architecture handover is explicitly an external contract — drift-WARN never drift-FAIL.
Added — PreCompact resume integrity (Spor 2, P0 fix)
hooks/scripts/pre-compact-flush.mjs— PreCompact-event hook (CC v2.1.105+) that reconcilesprogress.jsonwith git history before context compaction. Atomic write (tmp + rename), monotonic only (current_step never decreases), fail-open (always exit 0). Closes the documented progress.json drift bug fromdocs/ultraexecute-v2-observations-from-config-audit-v4.md—--resumenow works after long conversations.hooks/hooks.jsonregisters the PreCompact entry.
Added — examples (Spor 3)
examples/01-add-verbose-flag/— calibrated end-to-end pipeline demo for a small realistic task (add--verboseto a CLI parser). Includesbrief.md,research/01-cli-parser-conventions.md,plan.md(7 steps with full manifest YAML), andprogress.json. All four artifacts pass their respective validators. Hand-calibrated, not LLM-generated, so the example stays reviewable.examples/REGENERATED.mdper example documents calibration date and regeneration triggers.examples/README.mdwalks fork-ers through what to study first.
Changed — plan-critic semantic rubric (Spor 3, P0 fix)
agents/plan-critic.md rule #7 split into two parts:
- Literal blockers (exact-string):
TBD,TODO,FIXME,XXXalways fire. - Semantic rubric (instruction-shaped): 8 deferred-decision tests covering vague modifiers, imperatives without targets, forward references without expansion, volume/quality without spec, edge-cases delegated, production-readiness delegated, path mismatch, and over-stuffed steps.
Calibrated against 5-phrase corpus the v3.0 exact-string blacklist missed: "implement as needed", "wire it up", "make it production-ready", "add tests where appropriate", "handle edge cases" — all five now flagged with rule citations.
Added — CC v2.1.x feature adoption (Spor 3)
- F8 —
MCP_CONNECTION_NONBLOCKING=truedocumented under "Headless multi-session tuning" in README (CC v2.1.89+) for parallelclaude -psessions - F9 —
hooks/scripts/session-title.mjs(UserPromptSubmit, CC v2.1.94+) setsultra:<command>:<slug>titles for ultra invocations - F3 —
hooks/scripts/post-bash-stats.mjs(PostToolUse, CC v2.1.97+) appendsduration_msper Bash call to${CLAUDE_PLUGIN_DATA}/ultraexecute-stats.jsonl - F12 —
disableSkillShellExecution: truerecommended in README "Security hardening" +SECURITY.md(CC v2.1.91+) for fork-ers handling untrusted plans
Deferred: F2 (hook if-field scoping). The plan called for scoping pre-bash-executor / pre-write-executor to ultraexecute sessions to "reduce false-positives in brief/plan" — but brief/plan don't issue Bash commands that match the destructive denylist, so the rationale doesn't hold. Universal protection wins.
Added — security & extension docs (Spor 3)
SECURITY.md— Forgejo private-issue reporting, supported = current minor only, scope (4 hooks + denylist), hardening recommendationsdocs/architect-bridge-test.md— manual smoke checklist for the ultraplan ↔ ultra-cc-architect bridge (1 paragraph, intentionally not CI)README.md— new "Extending the plugin" section: how to add an agent, switch the planning model, disable external research, find the data contract, disable the architect bridge
Removed — vestigial config (Spor 0)
settings.jsonexplorationandagentTeamblocks (read by zero code; verified via grep before deletion)docs/ultra-suite-brief_2.mdarchived as_archive-(was paste from another plugin's work)
Tests
109 tests, all green. npm test is the fork-readiness gate.
Hook table (after v3.1.0)
| Hook | Event | CC version | Purpose |
|---|---|---|---|
| pre-bash-executor.mjs | PreToolUse(Bash) | 2.0+ | Block destructive shell commands |
| pre-write-executor.mjs | PreToolUse(Write) | 2.0+ | Block writes to sensitive paths |
| session-title.mjs | UserPromptSubmit | 2.1.94+ | Set ultra:<cmd>:<slug> titles |
| post-bash-stats.mjs | PostToolUse(Bash) | 2.1.97+ | Log Bash duration_ms to JSONL |
| pre-compact-flush.mjs | PreCompact | 2.1.105+ | Reconcile progress.json with git history |
Files changed
This release is plugin-internal — no breaking changes to artifact formats or CLI surface. Forkers should npm test after pulling to confirm readiness.
[3.0.0] - 2026-04-30
Note (2026-05-04): the ultra-cc-architect plugin is no longer publicly distributed. The architecture/overview.md filesystem contract remains supported but no public producer ships.
Architect extracted to its own plugin
The /ultra-cc-architect-local and /ultra-skill-author-local commands, all
seven of their agents, the cc-architect-catalog skill, the ngram-overlap.mjs
script, and the skill-factory test fixtures moved out of ultraplan-local and
into the new ultra-cc-architect plugin (v0.1.0).
Why
ultraplan-local had drifted into containing two distinct domains:
- A universal planning pipeline (brief → research → plan → execute) that is technology-agnostic and works for any implementation task.
- A Claude-Code-specific architecture phase that only makes sense when building features for Claude Code itself.
Keeping them in one plugin caused three problems:
- Users who wanted only the planning pipeline had to clone an unfinished CC-feature catalog and seven architect/skill-author agents they would never invoke.
- The architect catalog (~11 seed skills) and the planning pipeline lived on different release cadences. Architect work blocked pipeline development and vice-versa.
- New users saw six commands when only four belonged to the core flow.
The architect was already marked optional, v2.2 and was fully decoupled at
the code level — only one filesystem touchpoint remained: /ultraplan-local
auto-discovers architecture/overview.md if present, and gracefully handles
its absence. The split is therefore non-breaking for the planning flow.
What moved to ultra-cc-architect
- Commands:
/ultra-cc-architect-local,/ultra-skill-author-local - Agents:
architect-orchestrator,feature-matcher,gap-identifier,architecture-critic,skill-author-orchestrator,concept-extractor,skill-drafter,ip-hygiene-checker - Skills:
skills/cc-architect-catalog/(13 files) - Scripts:
scripts/ngram-overlap.mjs,scripts/ngram-overlap.test.mjs - Test fixtures:
tests/fixtures/skill-factory/,tests/fixtures/skill-drafter/
All moves used git mv, so history follows the files into the new plugin.
What stayed unchanged in ultraplan-local
/ultraplan-localPhase 1 still auto-discoversarchitecture/overview.md. The discovery is filesystem-based, not plugin-based — installing both plugins gives you the full pipeline (brief → research → architect → plan → execute).agents/planning-orchestrator.mdretains its architecture-note cross-reference.- All other commands (
/ultrabrief-local,/ultraresearch-local,/ultraexecute-local) are untouched.
Migration
If you only used /ultrabrief-local, /ultraresearch-local,
/ultraplan-local, and /ultraexecute-local: no action needed. Update the
plugin and continue.
If you used /ultra-cc-architect-local or /ultra-skill-author-local:
install the new plugin alongside this one. In ~/.claude/settings.json:
{
"enabledPlugins": {
"ultraplan-local@ktg-plugin-marketplace": true,
"ultra-cc-architect@ktg-plugin-marketplace": true
}
}
Custom seed skills you added to cc-architect-catalog/ follow with the
catalog. Use git log --follow if you need to track them in the new
location.
plugin.json changes
version:2.4.0→3.0.0description: now describes a four-command pipeline; CC-feature matching is described as living in the separateultra-cc-architectpluginkeywords: removedcc-architecture
[2.4.0] - 2026-04-19
Breaking change — background mode removed
Default mode for /ultraplan-local, /ultraresearch-local,
/ultra-cc-architect-local, and auto-mode in /ultrabrief-local is now
foreground. The command blocks the session until the brief/plan is ready.
Why
Background mode promised a swarm of specialized agents (docs-researcher,
community-researcher, architecture-mapper, plan-critic, feature-matcher,
gap-identifier, …) spawned by a background orchestrator. It did not work:
the Claude Code harness does not expose the Agent tool to sub-agents
(including ones run with run_in_background: true). The orchestrator
silently degraded to inline reasoning in a single Opus context, without
WebSearch, Tavily, WebFetch, or Gemini. Briefs were tagged "high confidence"
but were built on guesses from training data.
Source: github.com/anthropics/claude-code/issues/19077
Empirically confirmed in a plugin investigation on 2026-04-19: a probe
sub-agent reported its exposed tools as Bash, Edit, Glob, Grep, Read, Skill, ToolSearch, Write. The Agent tool was not present, active or
deferred. Foreground execution from the main context spawns sub-agents
correctly (docs-researcher with Tavily intact).
What changes
- Default execution: foreground for all four commands.
--fgflag is preserved as a no-op alias (backward compatibility).- Orchestrator agent files (
agents/research-orchestrator.md,agents/planning-orchestrator.md,agents/architect-orchestrator.md) are redefined from "background executor" to "inline reference" — the command markdown itself runs the phases in the main context where the Agent tool is available. ultrabrief-localauto-mode now runs research sequentially inline instead of parallel background. The ANTHROPIC_API_KEY billing check is removed (irrelevant for foreground runs on subscription).skills/cc-architect-catalog/background-agents-reference.mdhas been corrected: Shape A (orchestrator handoff) is now documented as an anti-pattern, nested spawn from a sub-agent is NOT SUPPORTED.
For headless/long-running runs
Use claude -p in a separate terminal window. Each headless session has
its own main context with the Agent tool, so the swarm works correctly.
Migration
No code changes required for users. Scripts or documentation that assume background execution must be updated — the commands now block until done.
[2.3.2] - 2026-04-18
Fixed — skill-drafter slug-collision hint
skill-drafter now checks for an existing file at
{catalog_root}/<slug>.md before writing its draft to .drafts/.
When a collision is detected, the agent prepends a warning block to
its confirmation output showing the overwrite risk and a suggested
qualified slug derived from the concept handle. The draft is still
written to .drafts/<slug>.md — the check is a hint, not a block.
Why. v2.3.0 dogfood surfaced the risk (logged as
post_dogfood_findings[0] in that run's progress.json): when the
drafter produced .drafts/hooks-pattern.md with an existing approved
hooks-pattern.md seed present at the catalog root, the pipeline
gave no signal that manual mv during promotion would silently
overwrite the seed. The v2.3.1 qualified-slug convention gave us the
mechanism to resolve collisions, but skill-drafter still didn't
surface them at the right moment — before promotion, not after.
Changes.
agents/skill-drafter.md— new Step 2 "Check for slug collision at the catalog root" between slug computation (Step 1) and reading the source (Step 3). Subsequent workflow steps renumbered 3→7. New "Suggesting a qualifier" guidance derives a kebab-case qualifier from theconceptfield (or source basename as fallback). Output format gains aCollision:field (none | approved | pending | auto-merged | soft) and an optional warning block when the collision is non-none. New Hard Rule "Slug-collision pre-write check".tests/fixtures/skill-drafter/slug-collision-expected.md— new reference fixture documenting the expected confirmation-output shape across four scenarios (no collision, approved collision, soft pending collision, collision with no good qualifier). Skill-drafter is prompt-driven and not auto-tested; the fixture anchors the shape for human verification and downstream parsers.
Non-breaking. No changes to .drafts/ layout, frontmatter
contract, tool scope, or filename regex. Existing pipelines see an
extra field (Collision:) and an optional warning block — both
purely additive. No version-gated changes in
skill-author-orchestrator or ip-hygiene-checker.
[2.3.1] - 2026-04-18
Added — Qualified slug convention for cc-architect-catalog
Catalog files now follow <cc_feature>[-<qualifier>]-<layer>.md. The
unqualified slug (e.g., hooks-pattern.md) remains the canonical
baseline for a (feature, layer) pair. Qualified slugs (e.g.,
hooks-observability-pattern.md) cover specific sub-patterns without
displacing the baseline.
Why. v2.3.0 dogfood surfaced a design gap: the skill-factory
produced a draft hooks-pattern.md from a specialized source (progressive-
alert observability) that collided with the existing generic hooks-pattern.md
seed. Promoting would have replaced the general pattern with a narrow
one; discarding would have lost real catalog growth. Qualified slugs
resolve this by letting one feature host multiple named patterns at
different abstraction levels.
Changes.
skills/cc-architect-catalog/SKILL.md— slug convention section added; coverage table gains "qualified patterns" column; matcher logic documented for N patterns per feature; modification rules cover qualified-vs-canonical choice and slug-collision handling.agents/feature-matcher.md— catalog map is nowcc_feature → {layer → [skills]}; new "Selecting among multiple patterns per feature" section (baseline by default, qualified when justified, multiple when non-overlapping, never purely cosmetic);supporting_skillaccepts one-or-more skill names.agents/gap-identifier.md— addspattern_count[cc_feature]signal to the catalog coverage audit.agents/architecture-critic.md— adds supporting-skill verification: every cited skill name must exist in the catalog; blocker severity.- First qualified skill:
hooks-observability-pattern.md(promoted from.drafts/, sourced fromai-psychosis/README.md, ngram-overlap 0.01, review_status approved).
Non-breaking. Existing unqualified slugs keep working. No changes to
cc_feature taxonomy. Hallucination gate unchanged (still validates
against cc_feature values, not slugs).
[2.3.0] - 2026-04-18
Added — Skill-factory Fase 1 MVP (/ultra-skill-author-local)
Manual one-skill-at-a-time generator for the cc-architect-catalog.
Channel 2 of the skill-factory strategy: a curated local source enters,
one draft skill exits in skills/cc-architect-catalog/.drafts/, with
n-gram containment scored against the source and stamped into the
draft frontmatter (or the draft is deleted when overlap is too high).
Why now. /ultra-cc-architect-local (v2.2.0) enforces a
hallucination gate that only permits feature proposals backed by the
catalog. With 10 seed skills covering 8 features × 2 layers, the
feature-matcher rarely finds a match and silently produces empty
proposals. Fase 1 unblocks catalog growth without spinning up
automation: one source, one draft, manual review, manual mv for
promotion.
Pipeline. Sequential, no retry, no parallelism:
/ultra-skill-author-local <source>
→ concept-extractor (sonnet, JSON output, gap-class C/D + cc_feature gate)
→ skill-drafter (sonnet, .drafts/<slug>.md with 9-field frontmatter)
→ ip-hygiene-checker (sonnet, runs scripts/ngram-overlap.mjs)
verdict accepted/needs-review → stamp ngram_overlap_score
verdict rejected → rm draft (no preservation)
IP-hygiene utility. Pure Node stdlib. Word-5-gram containment similarity (asymmetric draft⊆source) plus longest-consecutive-shingle- run secondary signal. Verdict bands: accepted (<0.15 AND <8), needs-review (mid), rejected (≥0.35 OR ≥15). Short-text fallback to n=4 when min(words) <500. CLI emits JSON.
Calibration fixtures. Three source/draft pairs in
tests/fixtures/skill-factory/ pin the verdict bands against
representative prose: accepted (containment 0.014), needs-review
(0.211), rejected (0.676). Re-verify any threshold change against
these fixtures.
New files:
commands/ultra-skill-author-local.mdagents/skill-author-orchestrator.md(opus)agents/concept-extractor.md(sonnet)agents/skill-drafter.md(sonnet)agents/ip-hygiene-checker.md(sonnet)scripts/ngram-overlap.mjs+scripts/ngram-overlap.test.mjsskills/cc-architect-catalog/.drafts/.gitkeeptests/fixtures/skill-factory/{source,draft}-{accepted,needs-review,rejected}.mdtests/fixtures/skill-factory/README.md
Non-goals (explicit, Fase 1):
- No automation, cron, or watcher
- No CC changelog diffing or auto-research
- No batch processing or review command
- No decision-layer skills (cross-feature comparison is Fase 2+)
- No URL or remote sources — local files only
- Manual
mvfrom.drafts/to catalog root is the promotion mechanism
New stats file:
${CLAUDE_PLUGIN_DATA}/ultra-skill-author-local-stats.jsonl.
[2.2.0] - 2026-04-18
Added — /ultra-cc-architect-local optional pipeline step
New optional command that sits between /ultraresearch-local and
/ultraplan-local. Reads the task brief plus any research briefs, matches the
task against available Claude Code features (Hooks, Subagents, Skills, Output
Styles, MCP, Plan Mode, Worktrees, Background Agents), and produces an
architecture note with brief-anchored rationale and an explicit coverage-
gap section.
Pipeline position (5-steg):
/ultrabrief-local → /ultraresearch-local → /ultra-cc-architect-local (optional)
→ /ultraplan-local → /ultraexecute-local
The architecture note is designed as priors for planning, not mandates —
/ultraplan-local still runs its own exploration and may override proposals
with evidence.
New files:
commands/ultra-cc-architect-local.md— command entry point (7 faser: parse → background → read inputs → feature matching → synthesize → review → present).agents/architect-orchestrator.md(opus) — background orchestrator.agents/feature-matcher.md(sonnet) — matches CC features against brief + research, with brief-anchored rationale per feature and a documented fallback minimum list when the catalog is empty.agents/gap-identifier.md(sonnet) — emits issue-ready gap drafts (no auto-posting; no auto-generation).agents/architecture-critic.md(sonnet) — adversarial review with a hallucination gate (features outside catalog + fallback list → blocker).skills/cc-architect-catalog/SKILL.md— manifest + frontmatter contract.- 10 seed skills in
skills/cc-architect-catalog/:hooks-reference,hooks-pattern,subagents-reference,subagents-pattern,skills-reference,output-styles-reference,mcp-reference,plan-mode-reference,worktrees-reference,background-agents-reference. All handwritten (no third-party content copied, per brief §4.4).
New flags:
--project <dir>(required) — reads{dir}/brief.md+{dir}/research/*.md, writes to{dir}/architecture/.--fg— foreground execution.--quick— skip adversarial review.--no-gaps— do not writegaps.md(gap-section remains insideoverview.md).
New stats file: ${CLAUDE_PLUGIN_DATA}/ultra-cc-architect-local-stats.jsonl.
Changed — /ultraplan-local auto-discovers architecture notes
Brief §5 of the ultra-cc-architect design said "no changes to existing
commands". This release makes one permitted, documented exception:
/ultraplan-local now auto-discovers {project_dir}/architecture/overview.md
when running in project mode. The file is additive context — missing file
produces no error, and behavior when the file is absent is identical to
v2.1.0. Non-breaking.
Minimal edits:
commands/ultraplan-local.md— Phase 1--projectbranch setshas_architecture_note/architecture_note_pathwhen the file exists. Phase 3 launch prompt passesArchitecture note: {path or "none"}to the orchestrator.agents/planning-orchestrator.md— Input section documents the new optional field. Phase 4 synthesis cross-references proposed features with exploration findings and carries the note's Coverage gaps into Risks and Mitigations when relevant.
Non-goals (explicit)
- Skill-factory is not part of this release. Cataloging, n-gram computation, auto-generation from CC changelog, concept extraction from reference repos — all deferred to a separate development process. Together with v2.2.0's architect command, that process will eventually land as v3.0.
- No
/ultra-autochaining. - No auto-creation of Forgejo/GitHub issues from gap drafts.
- No changes to
/ultrabrief-local,/ultraresearch-local, or/ultraexecute-local.
[2.1.0] - 2026-04-18
Changed — Dynamic, quality-gated interview in /ultrabrief-local
The Phase 3 interview is no longer a hardcoded Q1–Q8 list with a numeric
cap (3–4 questions in --quick, 5–8 in default). It is now a
section-driven completeness loop: the command maintains per-section
state (Intent, Goal, Success Criteria, Research Plan, and five optional
sections), picks the next question from the section with the weakest
signal, and keeps probing until all four required sections meet an
initial-signal gate. Quality drives the loop, not a counter.
Phase 4 adds a draft → brief-reviewer → revise loop. The brief is
drafted in memory, written to brief.md.draft, reviewed by the
brief-reviewer agent as a stop-gate, and only renamed to brief.md
after all five dimensions pass (completeness/consistency/testability/ scope_clarity ≥ 4 and research_plan == 5). If the gate fails, a
targeted follow-up is generated from the weakest dimension's detail
field and the draft is re-reviewed. The loop is capped at 3 review
iterations to bound cost; exhaustion writes the brief with
brief_quality: partial and an explicit ## Brief Quality section.
Force-stop path: when the user says "stop" during Phase 4, the current review findings are surfaced with per-dimension scores before asking whether to continue or accept a partial brief. No silent exits.
Not breaking. The /ultrabrief-local [--quick] <task> interface is
unchanged from the outside; only internals change. --quick now means
"start compact, escalate if gates fail" rather than "max 4 questions".
Added
- JSON output from
brief-reviewer— the agent now emits a final fencedjsonblock with per-dimensionscore(1–5) anddetailarrays (gaps,issues,weak_criteria,unclear_sections,invalid_topics) alongside the existing prose report. The JSON block is mandatory; empty arrays andscore: 5are required when a dimension passes cleanly.planning-orchestratorcontinues to use the prose verdict unchanged. brief_qualityfrontmatter field on task briefs —complete(default) when the Phase 4 gate passed, orpartialwhen the iteration cap was hit or the user force-stopped with known issues.planning-orchestratorcan inspect this to decide how heavily to weight brief sections as assumptions.review_iterationsandbrief_qualityin ultrabrief-stats — recorded per run for telemetry.
Changed
- Hard rule added:
/ultrabrief-localnever writesbrief.mdwhile the review gate is pending. The draft lives inbrief.md.draftuntil the loop terminates. - Hard rule added: no hard cap on Phase 3 questions; the brief-review gate is the only loop bound (3-iteration cap) and is in Phase 4.
[2.0.0] - 2026-04-18
Breaking — Four-command pipeline with dedicated brief step
v2.0.0 introduces /ultrabrief-local as a first-class step in the pipeline.
The interview previously embedded inside /ultraplan-local has been extracted
into a dedicated command that produces a structured task brief — the
contract between user intent and planning. /ultraplan-local now requires
a brief as input and no longer conducts interviews.
All artifacts converge into one project directory:
.claude/projects/{YYYY-MM-DD}-{slug}/ contains brief.md, research/NN-*.md,
plan.md, sessions/, and progress.json. --project <dir> works across
/ultraresearch-local, /ultraplan-local, and /ultraexecute-local.
See MIGRATION.md for v1 → v2 upgrade guide.
Breaking changes
/ultraplan-localrequires--brief <path>or--project <dir>. Running without either exits with an error and a pointer to/ultrabrief-local./ultraplan-local --spec <path>is removed. Convert specs to briefs by adding## Intentand## Research Plansections (see MIGRATION.md).- Interview inside
/ultraplan-localis removed. Planning no longer asks questions — all intent must be captured in the brief upstream. spec-revieweragent renamed tobrief-reviewerwith a new 5th dimension (Research Plan validity). Old spec-reviewer file is deleted.
Added
/ultrabrief-localcommand — interactive interview (3-8 questions with adaptive depth) that produces a task brief with explicit research plan. Features: project directory creation, research topic identification with copy-paste-ready/ultraresearch-localcommands, optional auto-orchestration (Claude runs research + plan in foreground), and stats tracking.templates/ultrabrief-template.md— canonical task brief format with## Intent,## Goal,## Non-Goals,## Constraints / Preferences / NFRs,## Success Criteria,## Research Plan(N topics with research_question, scope, confidence, cost), and## Open Questions / Assumptions.brief-revieweragent — renamed from spec-reviewer with a new 5th dimension: Research Plan validity (each topic has a valid research question ending in?, hasRequired for plan steps:andConfidence needed:, and research files exist whenauto_research: true).--project <dir>flag on/ultraresearch-local,/ultraplan-local, and/ultraexecute-local. Single directory holds the full pipeline's artifacts./ultraresearch-local --projectauto-increments{dir}/research/NN-slug.md.- Two-kinds-of-briefs terminology documented across README and CLAUDE.md:
"task brief" (from
/ultrabrief-local) vs "research brief" (from/ultraresearch-local). Prefix used consistently in agent prompts and docs. - MIGRATION.md — step-by-step guide for upgrading v1 projects to v2.
Changed
planning-orchestratornow acceptsBrief file:input instead ofSpec file:. Intent→Context mapping: brief's## Intent+## Goalfeed the plan's Context section directly (structured, no inference needed). Phase 1b now usesbrief-reviewerinstead ofspec-reviewer. WithProject dir:in input, writes plan to{dir}/plan.md./ultraresearch-localsupports--project <dir>with auto-indexed output path ({dir}/research/NN-slug.md, where NN is the next available two-digit index)./ultraexecute-localsupports--project <dir>. Reads{dir}/plan.md, writes progress to{dir}/progress.json.- plugin.json description rewritten to reflect four-command pipeline.
Removed
/ultraplan-local --spec <path>flag. Spec files are not a valid input for v2.0+. Convert to brief via/ultrabrief-localor manual conversion (see MIGRATION.md).- Interview Phase in
/ultraplan-local(was Phase 2). Use/ultrabrief-localto conduct the interview upstream. agents/spec-reviewer.mdfile. Replaced byagents/brief-reviewer.md.
Rationale
The v1.x interview inside /ultraplan-local conflated two concerns: capturing
intent and producing an executable plan. Briefs and plans have different
lifecycles — a brief should be reviewable and editable before any research or
planning starts, because every downstream decision traces back to it. Extracting
the brief into its own command makes the pipeline more honest: the brief is the
source of truth for what we want, research briefs are sources of truth for
what we learned, and the plan is the contract for how we'll do it. Separating
these makes each artifact reviewable on its own terms and enables deterministic
re-planning from the same brief when research reveals new constraints.
The explicit ## Research Plan section in briefs closes a common gap: plans
were implicitly assuming knowledge that neither the user nor Claude had verified.
Research topics are now declared upfront, scoped, and traceable back to plan
decisions.
[1.8.0] - 2026-04-17
Opus 4.7 prompt literalism — closing the schema-drift gap
Opus 4.7 reads agent instructions more literally than 4.6 (per 4.7 system
card §6.3.1.1). The v1.7 planning-orchestrator described the Step+Manifest
schema via prose + procedural rules ("read the template"), which 4.6
inferred correctly but 4.7 sometimes rendered as narrative "Fase N" prose.
The result: plans that executed cleanly on 4.6 were rejected by
ultraexecute Phase 2 parsing on 4.7 — first observed during v6.2.0 planning
for llm-security. v1.8.0 closes the gap by replacing prose rules with a
literal copyable template, explicit forbidden-format clauses, and a
pre-handoff schema self-check.
Added
- Inline literal Step+Manifest template in
planning-orchestratorPhase 5 — a complete, copyable example (JWT middleware step) replaces "read the template" prose. Removes ambiguity about heading format, field order, and manifest YAML structure. - Forbidden heading-format clause in Phase 5 — explicit denylist for
## Fase N,### Phase N,### Stage N, and other narrative formats the executor cannot parse. Negative constraints land harder on 4.7. - Phase 5.5 schema self-check in
planning-orchestrator— after writing the plan, grep-verify canonical### Step N:count matchesmanifest:count, and narrative heading count is zero. Rewrite plan if self-check fails, before handing to plan-critic. --validatemode inultraexecute-local— schema-only check that parses steps and manifests, reportsREADY | FAILwith specific error hints, and exits without security scan or execution. Intended as a fast sanity-check between/ultraplan-localand full execution:/ultraplan-local "task" /ultraexecute-local --validate <plan>.md # READY or actionable FAIL /ultraexecute-local <plan>.md # full execution
Changed
planning-orchestratorPhase 5 now embeds the canonical Step template inline (~60 lines of literal example) rather than referring totemplates/plan-template.md. Template file remains authoritative for cross-referencing but is no longer load-bearing for plan generation.ultraexecute-localPhase 2.3 added as a hard exit point for--validatemode; Phase 2.4 security scan explicitly skips this mode.
Rationale
v1.7.0's self-verifying chain assumed the orchestrator reliably produces
the v1.7 schema. That held on 4.6. v1.8.0 makes the assumption robust to
4.7-style literal interpretation by moving from "describe the format" to
"show the exact format and forbid alternatives", plus a self-check loop
before human-visible output. Pairs with --validate as a user-facing
verification step that catches any residual drift before execution side
effects begin.
[1.7.0] - 2026-04-12
The self-verifying plan chain
Wave 1 of a parallel 6-session build revealed three failure modes: (1) a
session reported status=completed after only 2/5 steps — last tool call
was an arbitrary file review, not a completion check; (2) 3/6 sessions
had push blocked inside the sub-agent bash sandbox after all work was
done; (3) plans and blueprints were prose, so the orchestrator had no
machine-readable way to verify completion. v1.7.0 closes all three by
making the plan itself an executable contract.
Added
- Per-step verification manifest in plan format (
plan_version: 1.7). Every step now ends with a YAMLmanifest:block declaringexpected_paths,min_file_count,commit_message_pattern,bash_syntax_check,forbidden_paths,must_contain. The manifest is the objective completion predicate — the Verify command is necessary but not sufficient. - Plan-critic dimension 10 — Manifest quality (hard gate). Missing
or invalid manifest (unparseable regex, path contradiction, missing
block) is a
majorfinding. v1.6 plans get a legacy-mode warning instead of a block. - Session Manifest aggregate in session specs — synthesized by
session-decomposeras the union of per-step manifests. Givesultraexecute-locala single YAML block per session to audit against. - Step 0: Sandbox pre-flight — obligatory first step in every
generated session spec. Runs
git push --dry-run origin HEAD; exit 77 = sandbox cannot push, session status becomesblocked(notfailed), no real work attempted. Escape hatch:ULTRAEXECUTE_SKIP_PREFLIGHT=1. - Launch script pre-flight —
headless-launch-template.mdadds agit push --dry-runcheck outside the sandbox, before any session spawns, catching credential issues at the earliest possible point. - Phase 7.5 — Manifest audit (independent). After all steps complete,
ultraexecute-localre-verifies expected paths, commit count, commit message patterns, bash syntax, and forbidden-path untouched-ness from git log and filesystem. Agent's own bookkeeping is ignored. Disagreement with progress file → status overridden topartial. - Phase 7.6 — Recovery dispatch (bounded). When Phase 7.5 detects
drift in multi-session parent context, synthesize a temp session spec
containing only missing steps and dispatch via existing
claude -p "/ultraexecute-local --session N".recovery_depth ≤ 2hard cap — third drift escalates to user. - Hard Rule 17: Manifest is the completion predicate. A step may not be marked passed if its manifest does not verify, regardless of Verify's exit code.
- Hard Rule 18: Last-activity rule. Executor's final tool call before Phase 8 must be a manifest check, never an arbitrary file review. Prevents hallucinated completion.
Changed
- Plan template (
templates/plan-template.md) — addsplan_version: 1.7metadata line,Manifest:field on every step, "Manifest — objective completion predicate" section. - Plan-critic scoring rebalanced: Headless readiness 0.15 → 0.10, Manifest quality 0.05 added. Legacy v1.6 plans skip the Manifest dimension and keep Headless readiness at 0.15.
- Planning-orchestrator Phase 5 adds "Manifest generation rules
(REQUIRED for every step)" with mechanical derivation from
Files:and Checkpoint. Validates regex compilation and path existence before handoff to plan-critic. - Session-decomposer parses plan manifests and propagates them
verbatim into session specs. For v1.7+ plans with missing manifests:
abort with pointer to failing step. For legacy v1.6 plans: synthesize
minimal manifests and flag
legacy_synthesis: true. - ultraexecute-local Phase 2 parses manifest YAML. Ugyldig YAML =
abort with pointer to step. v<1.7 plans: synthesize + log
legacy_plan: true. - ultraexecute-local Phase 6 — sub-step D renamed to D1 "Command
verification"; new D2 "Manifest verification" runs after D1 with 5
checks. F "Checkpoint" adds
checkpoint_driftlogging when HEAD message doesn't matchcommit_message_pattern(non-fatal). - Phase 8 report — table gets Manifest column; JSON summary adds
plan_version,manifest_audit,drift_details,recovery_dispatched,recovery_depth,legacy_plan. Result vocabulary strict:completed | partial | blocked | failed | stopped. - Division of labor clarified in README —
/ultraresearch-localgathers context (no decisions),/ultraplan-localtransforms intent into an executable contract (manifests, plan-critic gate),/ultraexecute-localexecutes the contract disciplined (does NOT compensate for weak plans — escalates).
[1.6.0] - 2026-04-08
Added
/ultraresearch-localcommand — deep research combining local codebase analysis with external knowledge. Produces structured research briefs with triangulation, confidence ratings, and source quality assessment. Supports modes: default (background),--quick(inline),--local(codebase only),--external(web only),--fg(foreground).- 6 new agents for the research pipeline:
research-orchestrator(opus) — runs full research pipeline as background taskdocs-researcher(sonnet) — official documentation via Tavily, WebSearch, Microsoft Learncommunity-researcher(sonnet) — real-world experience from issues, blogs, discussionssecurity-researcher(sonnet) — CVEs, audit history, supply chain riskscontrarian-researcher(sonnet) — counter-evidence and overlooked alternativesgemini-bridge(sonnet) — independent second opinion via Gemini Deep Research MCP
- Research brief template (
templates/research-brief-template.md) — structured format with dimensions, confidence ratings, triangulation, and source quality assessment. --researchflag for/ultraplan-local— accepts up to 3 research brief paths. Enriches the interview (focuses on decisions, not facts) and injects brief context into exploration agents. Research-scout skips already-covered technologies.- Research-aware planning orchestrator —
planning-orchestrator.mdnow accepts research briefs, injects summaries into sub-agent prompts, and cross-references brief findings during synthesis. - Research settings in
settings.json— configurable Gemini bridge (enabled/timeout), interview depth, dimension limits, and stats tracking.
Changed
- Plugin description and keywords updated to reflect research capabilities.
- CLAUDE.md expanded with ultraresearch command, modes, agents, architecture, and state.
[1.5.0] - 2026-04-07
Fixed
- CRITICAL: Parallel session data loss — Phase 2.6 ran parallel
claude -psessions in the same working directory, causing git race conditions and repository corruption. Each parallel session now runs in its own git worktree with isolated branch, index, and working files. Branches are merged back sequentially after each wave completes.
Added
- Phase 2.55 (Pre-flight safety checks) — validates clean working tree, committed plan file, no scope fence overlaps between parallel sessions, and no stale worktrees before launching parallel execution.
- Git worktree isolation for all parallel sessions — one branch per session
(
ultraplan/{slug}/session-{N}), merged with--no-ffafter wave completion. - Merge conflict detection — if merging a session branch produces conflicts, the merge is aborted and conflicting files are reported. No silent data loss.
- Unconditional worktree cleanup — worktrees and session branches are always removed, even on failure. Manual cleanup commands are reported if automated cleanup fails.
- Hard rules 11-13 — worktree isolation mandatory, cleanup unconditional, merge sequentially with conflict abort.
- Session-scoped progress file naming —
--session Nuses.ultraexecute-progress-{slug}-session-{N}.jsonto prevent merge conflicts.
Changed
- Headless launch template uses git worktrees with
cleanup_worktreestrap on EXIT, clean-tree pre-flight check, and sequential merge after each wave. - Phase 2.6 rewritten with 5-step worktree lifecycle: create → launch → wait → merge → cleanup.
[1.4.0] - 2026-04-06
Renamed
/ultraexecute→/ultraexecute-local— renamed for namespace consistency with/ultraplan-localand future-proofing against potential Anthropic naming. File:commands/ultraexecute.md→commands/ultraexecute-local.md. Note:ultraexecute_summaryJSON key andultraexecute-stats.jsonlfilename are unchanged for backward compatibility.
Added
convention-scanneragent (sonnet) — dedicated agent for discovering coding conventions: naming, directory layout, import style, error handling, test patterns, git commit style, documentation patterns. Replaces inline Explore agent prompt for medium+ codebases.- Success Criteria section in spec template — falsifiable "definition of done" conditions that the spec-reviewer validates and ultraexecute-local uses for verification.
- Dry-run multi-session preview —
--dry-runnow shows session groupings, wave structure, billing status, andclaude -pcommands when plan has an Execution Strategy. - External verification rule in headless launch template — wave verification must run commands independently, never parse session logs as proof.
- Billing preamble in headless launch template —
unset ANTHROPIC_API_KEYprevents accidental API billing. - Phase mapping comment in planning-orchestrator — documents how orchestrator phases 1-7 map to command phases 4-10.
Fixed
git add -Ain escalation — replaced with targeted staging of only files from completed steps. Prevents staging secrets, binaries, or unrelated work.- False
background: trueclaim — command documentation incorrectly stated the orchestrator hasbackground: truein its frontmatter. Corrected to explainrun_in_backgroundon the Agent tool.
Changed
- Execution Strategy reconciliation in session-decomposer — respects existing
## Execution Strategyas input instead of re-analyzing from scratch. Warns on file-overlap conflicts. - Headless launch template uses
--dangerously-skip-permissionsinstead of--allowedToolsfor more robust headless execution. - Session-decomposer updated with
--dangerously-skip-permissionsandunset ANTHROPIC_API_KEYfor generated scripts. - Convention Scanner references in command and orchestrator updated to use dedicated plugin agent.
- ROADMAP.md translated from Norwegian to English.
- plugin.json: added homepage, repository, license, keywords. Version bumped to 1.4.0.
- README badge updated to v1.4.0.
[1.3.0] - 2026-04-06
Added
- Session-aware parallel execution —
/ultraexecuteauto-detects## Execution Strategyin plans and orchestrates multi-session parallel execution viaclaude -p. No manualbash launch.shrequired.--fgflag — force foreground sequential execution, ignoring Execution Strategy--session Nflag — execute only session N from the plan's Execution Strategy (used by child processes)- Phase 2.5 (Execution strategy decision) — determines single-session vs multi-session mode
- Phase 2.6 (Multi-session orchestration) — launches parallel
claude -psessions per wave, waits for completion, aggregates results
- Execution Strategy in plan template — new
## Execution Strategysection with sessions, waves, scope fences, and execution order. Generated by planning-orchestrator for plans with > 5 steps. - Execution Strategy generation in planning-orchestrator — Phase 5 analyzes step file-overlap to build dependency graph, groups connected components into sessions of 3–5 steps, and organizes sessions into parallel waves.
Changed
- planning-orchestrator Phase 5 extended with Execution Strategy generation logic
- ultraplan-local Phase 8 now lists Execution Strategy as 10th required plan section
- Plan template includes
## Execution Strategysection template with grouping rules - CLAUDE.md updated with new ultraexecute modes and architecture
- plugin.json version bumped to 1.3.0
[1.2.0] - 2026-04-06
Added
/ultraexecutecommand — disciplined plan executor with 9-phase workflow. Reads an ultraplan or session spec, executes steps sequentially with strict failure recovery, tracks progress for resume, and reports results in machine-parseable JSON.- 4 modes: default (execute),
--resume(continue from checkpoint),--dry-run(validate without executing),--step N(single step) - Per-step protocol: implement → verify → on-failure handling → checkpoint
- Failure recovery from plan's On failure clauses (revert/retry/skip/escalate)
- 3-attempt retry cap per step (initial + 2 retries)
- Progress file (
.ultraexecute-progress-{slug}.json) for crash recovery and resume - Entry/exit condition checking for session specs
- Scope fence enforcement for session specs (never-touch file protection)
- JSON summary block in output for headless log parsing
- Stats tracking to
ultraexecute-stats.jsonl
- 4 modes: default (execute),
Changed
- CLAUDE.md restructured with two commands table (plan + execute)
- plugin.json version bumped to 1.2.0
[1.1.0] - 2026-04-06
Added
--decomposemode — splits an existing plan into self-contained headless sessions. Analyzes step dependencies, groups steps into sessions of 3–5 steps each, identifies parallel execution waves, and generates session specs + dependency graph + launch script.--export headlessformat — shortcut for--decompose. Produces the same session decomposition output.- session-decomposer agent (sonnet) — dedicated agent for plan decomposition. Parses step dependencies, builds dependency graph, groups steps into sessions, generates session specs with scope fences and failure handling.
- Session spec template (
templates/session-spec-template.md) — defines the format for individual session specs: context, scope fence, steps, entry/exit conditions, failure handling, handoff state. - Headless launch template (
templates/headless-launch-template.md) — template for generating bash launch scripts that execute sessions in parallel waves usingclaude -p. - Failure recovery per step — plan template now includes
On failure:(revert/retry/skip/escalate) andCheckpoint:(git commit) fields for every implementation step. - Headless readiness dimension in plan-critic — new 9th review dimension checking for On failure clauses, Checkpoint fields, and circuit breakers. Weighted at 0.15 in the quality score.
Changed
- Plan-critic scoring rebalanced: 6 dimensions (was 5), weights adjusted to accommodate headless readiness
- Plan template step format extended with On failure and Checkpoint fields
- Planning-orchestrator Phase 5 updated with failure recovery generation requirements
- CLAUDE.md updated with new agent, modes, and state paths
[1.0.0] - 2026-04-06
Added
--quickmode — skips exploration agent swarm. Runs interview → lightweight Glob/Grep scan → planning → adversarial review. For when the developer knows the codebase and needs structure, not cartography.--exportmode — generates shareable output from an existing plan file. Three formats:pr(PR description),issue(issue comment),markdown(clean plan without internal metadata).- task-finder three-tier categorization — findings categorized as Must-change (must be modified), Must-respect (contract that must not break), or Reference (context/reuse). Replaces flat file list.
- Adaptive interview depth — interview adapts to answer quality. Detailed answers trigger fewer, more targeted questions. Short/uncertain answers trigger simpler questions with offered alternatives.
- Complete
plugin.jsonmetadata — author, homepage, repository, license, keywords added. - README badges — version, license, and platform badges.
- Known limitations section in README — IaC projects (Terraform, Helm, Pulumi, CDK) get reduced value from exploration agents.
- Forgejo issue templates — bug report and feature request YAML templates.
- CONTRIBUTING.md — rewritten for honest solo-project model.
Changed
- plugin.json version bumped to 1.0.0
- Command header updated to Ultraplan Local v1.0
- Orchestrator accepts
mode: quickin prompt for lightweight scanning path
[0.4.0] - 2026-04-06
Added
- 3 new agents for information-complete planning:
task-finder— dedicated agent for finding task-relevant files, functions, types, and reuse candidates. Replaces inline Explore agent.git-historian— analyzes git log, blame, active branches, code ownership, and hot files for planning context.spec-reviewer— reviews spec quality (completeness, consistency, testability, scope clarity) before exploration begins. New Phase 1b/4b.
- Plan scoring — plan-critic produces a quantitative quality score (0–100) across 5 weighted dimensions with letter grades (A–D) and verdicts (APPROVE/REVISE/REPLAN).
- No-placeholder rule — plan-critic flags TBD, TODO, vague instructions, and underspecified steps as unconditional blockers. 3+ blockers = REPLAN regardless of score.
[ASSUMPTION]marking — planning-orchestrator marks all unverifiable claims and warns when >3 assumptions exist.
Changed
- All agents run for all codebase sizes. Small codebases get the same 6 core agents as large ones. Agent turns scale down for small codebases instead of dropping agents entirely.
- Phase 4b (spec review) added before exploration in both command and orchestrator.
- Orchestrator Phase 2 agent table expanded: 6 always + 1 conditional + 1 medium-only.
- Plan-critic review checklist expanded with no-placeholder checks (section 7) and scoring output.
- Orchestrator rules updated with assumption-marking and no-placeholder requirements.
[0.3.0] - 2026-04-05
Added
- planning-orchestrator agent — dedicated background agent (
background: true) that handles Phases 4–10 autonomously. Replaces generic background agent spawning with a purpose-built orchestrator running on Opus withmaxTurns: 50. effortandmaxTurnson all agents — fine-grained cost and depth control:- Exploration agents:
effort: medium,maxTurns: 15–20 - Review agents (plan-critic, scope-guardian):
effort: high,maxTurns: 10 - Research-scout:
effort: medium,maxTurns: 10
- Exploration agents:
- Plugin
settings.json— default configuration for mode, research, agent counts, interview limits, and team settings. Users can override in their own settings. - Worktree isolation for Agent Teams — team members use
isolation: "worktree"to prevent file conflicts during parallel implementation - Session tracking (Phase 12) — writes JSONL records to
${CLAUDE_PLUGIN_DATA}/ultraplan-stats.jsonlwith task metadata, agent counts, review verdicts, and outcomes
Changed
- Phase 3 now launches the
planning-orchestratoragent instead of a generic background agent - Agent Team implementation uses worktree isolation by default
[0.2.0] - 2026-04-05
Added
- Interview phase — iterative requirements gathering with AskUserQuestion before exploration. Produces a spec file that feeds into planning.
- 7 specialized agents in
agents/directory:architecture-mapper— deep architecture analysis, anti-patterns, smell detectiondependency-tracer— import-chain following, data-flow analysis, side-effect catchingtest-strategist— test strategy design based on existing patternsrisk-assessor— threat modeling, edge cases, failure modesplan-critic— dedicated adversarial reviewer with hardcoded critical perspectivescope-guardian— scope creep and scope gap detectionresearch-scout— external research via WebSearch/Tavily for unfamiliar technologies
- External research capability — research-scout agent searches documentation, known issues, and best practices when the task involves external/unfamiliar technology
- Background mode — default mode runs interview in foreground, then plans in background. User is notified when done.
- Spec-driven mode (
--spec) — skip interview, provide a pre-written spec file, plan entirely in background - Foreground mode (
--fg) — all phases in foreground, blocks session (v0.1.0 behavior) - Agent Team support — when plan has 3+ independent steps, offers parallel implementation via Agent Teams
- Spec template in
templates/spec-template.md - Research Sources section in plan template for citing external research
- Dual adversarial review — plan-critic and scope-guardian run in parallel
Changed
- Exploration agents replaced with named specialized agents from
agents/directory - Agent count scales with codebase: 3 (small), 5 (medium), 7 (large)
- Plan template extended with Research Sources and external tech fields
- Handoff phase supports "execute with team" option
- Command workflow expanded from 9 to 11 phases
[0.1.0] - 2026-04-05
Added
- Initial release
/ultraplanslash command with 6-phase workflow- Parallel Sonnet exploration (3 agents: architecture, task-relevant, conventions)
- Opus-driven plan generation from structured template
- Plan refinement loop with execute/save handoff
- Plan template with context, analysis, steps, alternatives, risks, verification
- Cross-platform support (Mac, Linux, Windows) — pure markdown, no scripts