NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist
Deterministic L2 Meta-Prompt compiler and briefing manager for coding agents.
Last release today
06 Oct 2026
Ships on a steady schedule
a new release about every 10 days
Nearly every release is documented
notes for 59 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 months old
92 releases · first in 2026
One column per month.
Added versioned operating-prompt manifests and typed prompt requests. Recipes explicitly declare level: 1|2; selected prompt IDs, arguments, rendered
level: 1|2; selected prompt IDs, arguments, rendered
content, source references, and template digests are carried in replayable
recall facts and bundle evidence.Goal, Context, Constraints,
Verification, and Done When. Verification defines how reality is measured;
Done When defines which observed result permits the task to stop.UNKNOWN.history/operating-prompt-outcomes.jsonl. Selected recipes can record
helpful, irrelevant, harmful, not_used, or unknown outcomes with
argument digest, application state, evidence, actor, task, compilation, commit,
and time. Future recall facts expose aggregate prior outcome counts without
automatically mutating recipe policy.operating_prompt_outcomes rows to the outcome draft so recipe use can be
evaluated separately from normal guidance use.MEMORY.md and other project-root evidence resolve through the
configured recall project root, with boundary checks that prevent path escape.bool|int|string values;
float formatting cannot silently change replay identity across runtimes.{{...}} text inside supplied argument values is preserved instead of
being mistaken for an unresolved manifest placeholder.docs/operating-prompts.md defines the L2 -> project-specific L1 flow, exact
five-section contract, manifest schema, project-capability evidence, recipe
outcome history, and the boundary that reusable prompt semantics belong in the
owning catalog while project facts stay in recall.The binary resolved its autoloader by preferring the package's own vendor/ directory. When one is present next to an installed copy - a path repositor
vendor/
directory. When one is present next to an installed copy - a path repository, a
mirrored checkout, a stale local install - that autoloader wins and silently
loads its dependencies instead of the project's. Found by a release-set smoke
test that reported Undefined property Session::$ephemeral against an
installed version that plainly had it. The outer autoloader is now tried first.Documented the --document-manifest format in the README: field meanings, max_chars bounds and truncation marking, and the three selection paths (path-
--document-manifest format in the README: field meanings,
max_chars bounds and truncation marking, and the three selection paths
(path-scope overlap, tag overlap, project-wide). The project-wide form -
scope empty, ["/"], or ["*"] - was supported but undocumented, so
environment-level guidance that has no path scope by nature had no obvious way
into a briefing.compile --map-search-index PATH (plus --map-search-limit N, default 8) turns agent-map 0.4.0's derived hybrid-search index into ranked candidates for
compile --map-search-index PATH (plus --map-search-limit N, default 8) turns
agent-map 0.4.0's derived hybrid-search index into ranked candidates for a task
that has a description but no exact --target yet. The candidates travel as a
navigation_candidates fact (map.search.candidates) and render in system.md
under Candidate Navigation (ranked, unverified).map.search.status fact - missing, stale, unavailable, skipped - and
rendered in the briefing. An absent section would be indistinguishable from
"the search found nothing", which is a different answer.map_snapshot does not match the map's analysis
fingerprint is refused rather than used, naming both snapshots.2.0 when no search index is configured,
so a compilation that does not use the feature keeps its previous bundle digest.Requires voku/agent-map ^0.4.0. The compiler keeps using the same Index and Context API, but the constraint is what lets a consumer install the 0.4.x
voku/agent-map ^0.4.0. The compiler keeps using the same
Index and Context API, but the constraint is what lets a consumer install
the 0.4.x line at all - the derived hybrid-search index
(agent-map search-index, .agent-map/search.sqlite) and the parallel chunk
extraction it brings are unreachable while any package in the tree still pins
^0.3.0.Deterministic verification plans. When a compilation resolves a map target, compile now emits two new artifacts next to the existing recall output:
compile now emits two new artifacts next to the existing recall output:
verification-plan.json - the public contract: knowledge probes with their
question, answer format and evidence ids, the evidence checklist, the
objective gates and which of them are required, the required evidence
types, the map digest and analysis fingerprint the plan was derived from,
and the omitted probe candidates with the reason each was rejected.verification-key.json - the verifier-owned answer key: canonical probe
answers bound to plan_sha256, target and map_digest.
The key is deliberately not referenced from system.md; the prompt receives
only the questions.system.md gains a "Repository-Knowledge Verification" section listing the
probes, and validation-plan.md gains a "Declared Verification Contract"
section listing the checklist, the objective gates, and the fixed scoring
rule a consumer must apply (objective_gate != passed -> gated_evidence_score = 0).meta.json gains verification_plan_sha256, verification_key_sha256 and
verification_generator, and both artifacts are included in output_hashes,
so a stale key cannot survive a map change unnoticed.verification-plan.json / verification-key.json left over from an earlier
run instead of leaving stale artifacts in the output directory.Requires voku/agent-map ^0.3.0. That release moves each top-level index section onto its own line (still ordinary JSON, and IndexReader reads both lay
voku/agent-map ^0.3.0. That release moves each top-level index
section onto its own line (still ordinary JSON, and IndexReader reads both
layouts), adds refresh/--merge for incremental index updates, and stops
the symbol extractor from executing host code while parsing. Recall only
reads indexes, so nothing in this package changed behaviourally.Added repeatable --edit-focus literals for target-aware compilation. They instruct agent-map to render bounded primary-source windows around local mat
--edit-focus literals for target-aware compilation. They
instruct agent-map to render bounded primary-source windows around local
matches, retaining the full target if none match.voku/agent-map 0.2.1 or newer for the focus-aware context policy.Added repeatable exact Class::method task targets through task briefs and inline --target, backed by voku/agent-map 0.2 JSON or TOON indexes.
Class::method task targets through task briefs and
inline --target, backed by voku/agent-map 0.2 JSON or TOON indexes.MapRecallProvider now delegates decoding, SHA-256 freshness checks, target
resolution, relation traversal, and source materialization to agent-map
instead of parsing the old JSON/SHA-1 schema itself.Rejected duplicate proposals with the same non-empty pattern_key as selected active guidance no longer block recall compilation merely because they sh
pattern_key as selected
active guidance no longer block recall compilation merely because they share a
target. They remain selected as historical warnings; only a rejected different
pattern targeting the same guidance surface is a contradiction.Approved work-brief behavior anchors are parsed, carried into task-context facts, and rendered in L2 prompts so agents retain the concrete behavior th
Accept active phpcs constraint manifests, validate either phpcs or php_codesniffer commands, and label the generated validation-plan section as PHPCS.
phpcs constraint manifests, validate either phpcs or
php_codesniffer commands, and label the generated validation-plan section
as PHPCS.Added an optional tags relevance axis, orthogonal to path scope. Task briefs, guidance/constraint/rejection/retirement records, and scoped document ma
tags relevance axis, orthogonal to path scope. Task
briefs, guidance/constraint/rejection/retirement records, and scoped
document manifest entries may declare tags; a fact is selected when its
path scope overlaps the task's files or it shares at least one tag with
the task. This lets a project register cross-cutting knowledge (e.g. an
LDAP learning) by domain/system/capability instead of directory prefix, so
selection works the same way regardless of how a project's codebase is
laid out. Purely additive: briefs and manifests without tags behave
exactly as before.SelectionReason::TAG_OVERLAP to distinguish a tag-only match from a
path scope_overlap or global match in selection-report.json.--tag LABEL (repeatable) to compile for ad hoc task input.Added internal RecallProvider contracts and a canonical, replayable recall.bundle.json snapshot. Providers now contribute source digests and structure
RecallProvider contracts and a canonical, replayable
recall.bundle.json snapshot. Providers now contribute source digests and
structured facts for task context, repository memory, approved learning and
hard constraints, optional map indices, typed Kanban projections, and
explicitly registered project Skills/ADRs.facts.json, selection-report.json, and
compilation-receipt.json. The first two are deterministic, hash-covered
consumer artifacts; the receipt is operational timestamp metadata and is
deliberately outside the replay identity.--map-root, --kanban-context, and repeatable
--document-manifest compile options. Project documents are selected only
by explicit scope/prefix rules and fixed excerpt limits.agent-session work briefs (task_id, goal, scope,
non_goals, validation, status, revision) are first-class task inputs.
Rendered L2 prompts are deterministic views of the canonical bundle; the
compiler never executes them or calls a model.agent-map index can now be verified against an explicitly
supplied host root. Missing or stale task files are emitted as explicit
navigation-status facts rather than being silently rebuilt or trusted.Contradiction detection now also covers retired proposals, not just rejected ones. RecallRepository::loadRetiredProposals() returns full RecallRetirem
RecallRepository::loadRetiredProposals() returns full RecallRetirement records (target, reason, scope, action) instead of bare IDs, and RecallDecisionEngine::decide() blocks compilation when newly selected guidance targets a rule that was retired for cause in the same task scope, surfacing the original retirement reason. loadRetiredProposalIds() is kept for callers that only need the ID list.Only treat a rejected proposal as contradictory when its scope also matches the current task; unrelated rejected proposals may share broad targets suc
MEMORY.md.review blindspots/review code now write their report/prompt files under a reviews/ subfolder of the same --output-dir they read compiled recall inputs
review blindspots/review code now write their report/prompt files under a reviews/ subfolder of the same --output-dir they read compiled recall inputs from, instead of a hardcoded, workspace-root-relative .agent-recall/reviews/ that ignored --output-dir entirely. A project that points --output-dir (or a downstream tool's recall-root config) somewhere other than .agent-recall/current now gets one consistent output tree for compile+review instead of review output always landing at the same fixed path regardless of configuration. The default output dir (.agent-recall/current when --output-dir is omitted) now produces reports under .agent-recall/current/reviews/ rather than .agent-recall/reviews/.Recall compilation no longer turns a historical irrelevant outcome into a warning for a different task. The outcome remains in the immutable history a
irrelevant outcome into a warning for a different task. The outcome remains in the immutable history and in projected usage statistics; only prior harmful guidance is surfaced as a current-task warning.recall-log.draft.json and feedback-assessment.draft.json are no longer recorded in a compiled meta.json's output_hashes. Both files are designed to be hand-edited after compile (guidance_outcomes, review verdicts), so including them in that tamper-evidence hash set made every correctly-completed task permanently fail a downstream verifier's staleness check.Added a deterministic review CLI workflow with blindspots and code subcommands. The workflow writes audit-ready Markdown/JSON review reports plus L2 b
review CLI workflow with blindspots and code subcommands. The workflow writes audit-ready Markdown/JSON review reports plus L2 blind-spot and code-review prompts under .agent-recall/reviews/ without invoking an LLM.docs/agent-loop-review-follow-up-prompt.md to carry the dogfooded review workflow and safety corrections into voku/agent-loop.compile and log-outcome, plus shared parsed-option value objects, so existing commands use the same command-oriented architecture as the new review workflow.file_put_contents() fails instead of printing success with missing or partial output.--name tokens instead of silently treating them as empty strings.--root, rejects traversal in output paths, bounds recursive session reads, and avoids pulling unrelated session notes through substring task-id matches.Retiring a voku/agent-learning proposal (0.7.0 ProposalStatus::RETIRED) removed it from loadActiveGuidance() as intended, but RecallDecisionEngine::de
voku/agent-learning proposal (0.7.0 ProposalStatus::RETIRED) removed it from
loadActiveGuidance() as intended, but RecallDecisionEngine::decide()'s "unknown rule ID" check
builds its known-ID set only from active guidance, constraints, and rejections. A historical
outcomes.jsonl event recorded while the proposal was still applied legitimately still
references its ID, so every later recall compile for any task BLOCKED with Conflict: outcome references unknown rule ID '<id>' the moment that proposal was retired, even though nothing about
the requested task was wrong. Found by dogfooding against a downstream repository immediately
after retiring a proposal there for the first time.RecallRepository::loadRetiredProposalIds() (reads proposals/retired/*.json, IDs only) and
a new decide(..., array $retiredProposalIds = []) parameter so retired IDs stay known to the
conflict check without ever being selectable as guidance. Cli.php's compile command now loads
and passes them through. Default value keeps the signature change backward compatible for direct
RecallDecisionEngine::decide() callers that omit the new argument.Added RecallRepository::loadRetiredProposalIds() (reads proposals/retired/*.json, IDs only) and a new decide(..., array $retiredProposalIds = []) para
RecallRepository::loadRetiredProposalIds() (reads proposals/retired/*.json, IDs only) and
a new decide(..., array $retiredProposalIds = []) parameter so retired IDs stay known to the
conflict check without ever being selectable as guidance. Cli.php's compile command now loads
and passes them through. Default value keeps the signature change backward compatible for direct
RecallDecisionEngine::decide() callers that omit the new argument.feat: add untrusted peer feedback handling and compilation conflict resolution
OutcomeLogger::log() could throw a spurious type mismatch error for any log-outcome draft that evaluated a legacy target_type: "file" guidance entry (
OutcomeLogger::log() could throw a spurious type mismatch error for any
log-outcome draft that evaluated a legacy target_type: "file" guidance
entry (e.g. a MEMORY.md-targeting proposal), even when that entry was not
selected. RecallDecisionEngine projected "file" onto GuidanceType::MEMORY
at compile time, but OutcomeLogger::knownGuidanceTypesById() re-derived the
type independently and fell back to GuidanceType::SKILL, disagreeing with the
compiled draft.GuidanceType::fromTargetType() so
RecallDecisionEngine, OutcomeLogger, and RecallPromptBuilder can no
longer drift apart on this mapping.Refactor recall compiler internals
improve suffix validation (without 'ext-ctype')
fix: handle mkdir failure when creating output directory
Add stable compilation IDs to compile output, with optional --compilation-id support and generated IDs when omitted.
--compilation-id support and generated IDs when omitted.history/recall-selections.jsonl and history/outcomes.jsonl during governed log-outcome close-out.compilation_id + guidance_id pairs.meta.json fields with schema version, compilation ID, task files, evaluated guidance, selection/exclusion reasons, selected constraint reasons, and output hashes.recall-log.draft.json editable guidance outcome rows and schema documentation.target_type=file records as memory guidance when projecting evaluated guidance events.recall-log.draft.json with empty usefulness buckets instead of pre-marking selected guidance as helpful.helpful, irrelevant, or harmful.Add outcome statistics for selected guidance and constraints, separating selected_count, helpful_count, irrelevant_count, harmful_count, and violation
selected_count, helpful_count, irrelevant_count, harmful_count, and violation_detected_count.system.md and meta.json outputs when prior outcome data exists.recall-log.draft.json with empty usefulness buckets instead of pre-marking selected guidance as helpful.helpful, irrelevant, or harmful.Emit selected hard constraints directly in system.md with a concrete execution contract and required validation commands.
system.md with a concrete execution contract and required validation commands.active_constraints_dir from learning-root config.json when loading active hard-constraint manifests.voku/agent-learning.Add constraint manifest parsing for active hard constraints.
* or / scopes.violation_detected, false_positive, rule_suppressed, and rule_disabled.validation-plan.md authoritative for selected constraints by listing required commands and rule identifiers.Add strict compilation-blocking checks (RuntimeExceptions) for:
approved or applied.constraint that do not define any validation commands.schema_version validation check ("1.0") to task briefs, guidance files, and outcome logs.selected and applied rule fields in generated outcome logs to separate prompt selection from actual rule utilization.validation-plan.md authoritative for selected constraints by listing required commands and rule identifiers.Initial release of L2 Meta-Prompt Compiler and Briefing Manager for coding agents.
HARMFUL or IRRELEVANT in past sessions.Your coding agent can read these notes before it upgrades. Set up the MCP server →