* Replace MCP Gmail/Calendar with Google Workspace CLI
Swap all MCP tool references (gmail_*, gcal_*) for gws CLI
equivalents in the postman agent and all 4 postman-related skills.
Add Bash to postman tools for gws execution. Include setup guide
for gws installation and OAuth configuration.
Addresses review feedback: Food Coach and Wellness Guide references
removed (those agents no longer exist on main).
* Update skills/weekly-agenda/SKILL.md
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Address Copilot review feedback
- Add gmail.send scope to setup guide and agent docs
- Use narrower calendar scopes (calendar.events + calendarlist.readonly)
- Make gcloud optional in prerequisites
- Fix .mcp.json example to remove only Gmail/Calendar entries
- Split label modify into separate add/remove examples
- Replace hard-coded dates with placeholders
- Fix after:{{yesterday}} to newer_than:2d for 48h filtering
- Update all docs/gws-setup-guide.md paths to repo-relative
- Add MCP fallback note for users without gws
- Add mandatory user confirmation before mark-read/archive actions
* Fix PR review findings: add security guardrails and update all MCP references for gws dual-support
- Add Security: External Content section to postman.md to prevent command injection from untrusted email content
- Update agents-registry.md, agents.md, CLAUDE.md, README.md to reflect gws CLI + MCP fallback duality
- Update TERMS_OF_USE.md and DISCLAIMERS.md legal text to mention gws alongside MCP
- Update onboarding skill to present gws as recommended option with MCP as fallback
- Fix placeholder in gws-setup-guide.md (was a raw template, now a concrete date)
- Update agent-template.md to document Bash for CLI tool access pattern
* Harden security for email/calendar operations and update legal coverage
- Postman agent: comprehensive security section covering prompt injection,
shell injection, write operation safeguards, and Bash command allowlist
- All 4 postman-related skills: add security sections with prompt injection
defense, shell injection rules, and explicit MCP fallback instructions
- TERMS_OF_USE.md: new Section 4A covering risks from email/calendar read
and write operations (adversarial content, unintended sends, deletions,
calendar disruptions), updated Limitation of Liability section
- DISCLAIMERS.md: new section explaining write operation risks in plain
language, MCP as safer read-only alternative, and acknowledgment of
prompt-based security limitations
---------
Co-authored-by: gnekt <dima9610@gmail.com>
* Add standardized template for custom agent creation
New file: references/agent-template.md
This is a reference document that the Architect reads when generating
custom agents. It defines the exact structure every agent must follow:
YAML frontmatter format, required sections (Language, User Profile,
Inter-Agent Coordination, Core Responsibilities, Operational Rules),
placeholder tokens, and inline conventions (naming rules, tool
permissions, multilingual triggers).
The template is not an agent itself. It is a structural guide that
ensures custom agents are generated with the same quality and
consistency as the core 8.
* Add custom agent support to orchestration references
agents-registry.md:
- Added "Custom Agents" section with rules for how custom agents
are added to the registry (naming, priority, creation flow)
- Custom agents always have lower priority than core 8
- Names must be lowercase with hyphens, no conflicts with core names
agents.md:
- Added "Custom Agents" section explaining what they are, how they
coordinate with core agents, and how to create/edit/remove them
agent-orchestration.md:
- Added "Suggested new agent" signal format so agents can flag when
the user needs functionality that no existing agent provides
- Added step in Dispatcher Decision Logic to check for this signal
- Added "Custom Agent Lifecycle" section covering creation, discovery,
routing, chaining, maintenance, and deletion
* Add "Suggested new agent" capability to all 7 non-architect agents
Each agent now has a "When to suggest a new agent" subsection inside
its Inter-Agent Coordination block. When an agent detects that the
user needs functionality that no existing agent can handle, it
outputs a "Suggested new agent" section with:
- Need: what capability is missing
- Reason: why no existing agent covers it
- Suggested role: what the new agent would do
The dispatcher reads this and asks the user if they want the
Architect to create a custom agent for the detected need.
Agents are also told when NOT to suggest a new agent (existing
agent can handle it, one-off task, outside vault scope).
* Add full custom agent creation flow to the Architect
The Architect can now create, edit, and remove custom agents through
an extended conversational flow with the user.
Changes to the frontmatter:
- Added trigger phrases for custom agent creation in 6 languages
("create a new agent", "custom agent", "crea un nuovo agente", etc.)
New section "Custom Agent Creation" with:
- 5-phase conversation flow (Understanding, Capabilities, Output,
Advanced, Confirmation) where the Architect asks one question at
a time and adapts follow-ups based on user answers
- Agent file generation following references/agent-template.md
- Automatic updates to agents-registry.md and agents.md
- Management commands: edit, remove, list custom agents
- Validation rules: no name conflicts with core 8, minimal tool
permissions by default, mandatory coordination sections
- Quality standards: Core Responsibilities must be detailed enough
to produce a production-quality agent
Also added the "Suggested new agent" subsection (same as other agents).
* Update dispatcher routing to support custom agents
- Changed "The ONLY agents you may use are these 8" to acknowledge
that custom agents created by the Architect are also valid
- Added row 9+ to the routing priority table for custom agents
(always lower priority than core 8)
- Added section 9 "CUSTOM AGENTS" with routing logic: when no core
agent matches, check agents-registry.md for custom agents
- Added check for "Suggested new agent" signals in the multi-agent
routing decision flow (step 6)
* Add custom agents to README, CONTRIBUTING, and TERMS_OF_USE
README.md:
- Badge changed from "8 Agents" to "8+ Agents"
- Added custom agents as point 4 of "What makes this different",
positioned right after the main pitch for maximum visibility
- Includes a table of real-life scenarios (budget tracking, journaling,
paper reading, project monitoring, client deadline management)
- Links to Terms of Use for the responsibility disclaimer
CONTRIBUTING.md:
- Renamed "Propose a new crew member" to "Propose a new core crew
member" with a note that users can create custom agents via Architect
- Added "Custom agents vs. core agents" section explaining the
distinction between personal custom agents and project-shipped
core agents
TERMS_OF_USE.md:
- Added new Section 9 "Custom Agents" with full disclaimer: custom
agents are entirely the user's creation and responsibility, no
warranty on their behavior, author accepts no liability
- Updated Section 7 (Limitation of Liability) to reference custom
agents explicitly
- Renumbered sections 9-11 to 10-12
* Force the Architect to always run the full conversation before creating a custom agent
The Architect was generating custom agents immediately from a single
user message instead of going through the 5-phase conversation flow.
Added explicit blocking instructions at three points:
- Section intro: "NEVER create an agent in one shot"
- Before the conversation phases: "Do NOT generate the agent
immediately, even if the request seems clear"
- Explicit rule: "You are NOT allowed to create the agent file
until Phase 5"
- Reinforced one-question-per-message rule
* Force custom agent descriptions to use only the user's language
The Architect was copying the multilingual pattern from core agents
and adding translations in 6+ languages to custom agent descriptions.
Custom agents should have their description and trigger phrases
written exclusively in the language the user speaks. Reinforced
this rule in both the generation instructions and the validation
rules section.
* Force custom agent body to always be written in English
The frontmatter description uses the user's language (for trigger
matching), but the agent body (system prompt) must always be in
English for better LLM instruction-following performance. The agent
still responds in the user's language at runtime thanks to the
language matching rule.
* Add confirmation prompt before overwriting existing installation
launchme.sh:
- Detects if .claude/ or CLAUDE.md already exist in the vault
- Shows the user what will be overwritten
- Asks for explicit confirmation before proceeding
- Clarifies that custom agents and vault notes are never touched
updateme.sh:
- Asks for confirmation before overwriting core files
- Same clarification about custom agents being preserved
* Deprecate removed files instead of leaving orphans in the vault
When a file is removed from the repo (agents, references, or skills),
the updater now renames it with a "-DEPRECATED" suffix and prepends
a "DEPRECATED DO NOT USE" header instead of silently leaving it.
updateme.sh:
- Core agents in .claude/agents/ that no longer exist in the repo
get renamed to {name}-DEPRECATED.md with deprecation header
(custom agents are never touched)
- References in .claude/references/ that no longer exist in the repo
get the same treatment
- The entire .claude/skills/ directory (removed from the project)
gets renamed to .claude/skills-DEPRECATED/ with deprecation headers
on each SKILL.md
- Summary now reports deprecated file count
launchme.sh:
- Added confirmation prompt before overwriting existing installation
- Skills generation and copying kept intact (generate-skills.py runs
first, then copies to .claude/skills/)
* Add first-run setup section to custom agent template and creation flow
Custom agents now have a "First Run Setup" section that defines what
the agent must do the very first time it is invoked: what questions
to ask the user, what config files or folders to create, and how to
detect that it has already been set up.
agent-template.md:
- New "First Run Setup" section between Core Responsibilities and
Operational Rules, with subsections for detection, questions to
ask, what to create, and post-setup behavior
architect.md:
- New Phase 4 "First Run Setup" in the conversational flow where
the Architect asks the user what the agent should do on first run
- Previous Phase 4 (Advanced) becomes Phase 5
- Previous Phase 5 (Confirmation) becomes Phase 6
- Updated blocking rules to reference Phase 6
* Redesign README header and broaden legal disclaimers for custom agents
Improve README header visual hierarchy: centered title, prominent Discord
CTA, metadata badges moved to secondary row. Replace two custom agent
examples with funnier, gender-neutral ones. Rewrite TERMS_OF_USE Section 3
from "Health and Wellness Agents" to "Custom Agents and Advice-Generating
Output" covering health, legal, financial, and all regulated domains.
* Fix reference paths in architect to use .claude/references/ prefix
The agent runs inside the vault where references live under
.claude/references/, not under references/ (which is the repo layout).
* Fix reference paths in agent-template to use .claude/references/ prefix
* Add core-manifest to protect custom agents from deprecation
launchme.sh and updateme.sh now write .core-manifest listing which agent
files were installed as core. The deprecation loop checks this manifest
before touching any file, so custom agents are never deprecated.
* Skip agent deprecation if target DEPRECATED file already exists
* Include skill count in updateme.sh summary condition and message
* Fix agents-registry.md paths in CLAUDE.md to use .claude/references/ prefix
* Add edit/remove/list trigger phrases to custom agent routing
* Deprecate stale core agents on reinstall before copying new ones
On reinstall (EXISTING=1), read the old .core-manifest and deprecate
any agent that is no longer shipped in the repo, before writing the
new manifest. Prevents stale core agents from lingering in the vault.
* Fix custom agent description: triggers are in user's language, not multilingual
* Fix updateme.sh: deprecate stale agents before rewriting manifest
The manifest was being truncated and rewritten before the deprecation
loop ran, so removed core agents were no longer in the manifest and
got skipped as "custom". Now: read old manifest -> deprecate -> copy
new agents -> rewrite manifest.
* Fix grep exit code handling when removing last entry from manifest
* Fix nested fenced code blocks in agent-template using tildes
* Add core-manifest for references to protect user-created reference docs
Same pattern as agents: launchme/updateme write a .core-manifest in
.claude/references/ listing installed core files. The deprecation loop
only touches files in the manifest, leaving user-created references
untouched.
* Move deprecated files to .claude/deprecated/ to prevent auto-discovery
Deprecated agents kept in .claude/agents/ could still be auto-discovered
by Claude Code via their frontmatter. Moving them to .claude/deprecated/
ensures they are completely invisible to the dispatcher while still
preserved for user reference.
* Harden updateme.sh from Copilot review feedback
Address multiple issues raised during PR code review:
- Skip deprecation entirely when .core-manifest is missing, preventing
accidental deprecation of custom agents/references on first update
- Preserve user's "## Custom Agents" sections in agents-registry.md and
agents.md during reference updates (merge strategy instead of overwrite)
- Update confirmation message to accurately reflect what is preserved
* Preserve custom agent content during install and update
- launchme.sh: skip overwriting agents-registry.md and agents.md on
reinstall to preserve custom agent entries
- updateme.sh: extract and re-insert custom table rows from the
registry table plus custom sections, preventing data loss when
updating from upstream
- Require manifest before deprecating to avoid false positives
* Update wardrobe-coach example phrase in README
* Use robust string matching and printf for user-mutable refs
- Replace grep -qw with bash substring match for filename detection
- Replace echo with printf '%s\n' to prevent content mangling
* Enforce step-by-step conversation in Architect and fix registry row reinsertion
- Add HARD CONSTRAINT blocks to both onboarding and custom agent creation
flows, forcing the use of AskUserQuestion for each question to prevent
the Architect from skipping phases or bundling questions
- Replace hard-coded "| postman |" match in updateme.sh with generic
last-table-row detection to avoid breaking custom row reinsertion if
core agents are renamed or reordered
* Improve input handling in launchme.sh and updateme.sh for non-interactive shells
* Extract 13 skills from agents and update full documentation
Architecture change: complex multi-step flows (onboarding, email triage,
transcription, etc.) are now skills that run in the main conversation
context instead of agent subprocesses. This fixes the state/context loss
that caused agents to skip phases during multi-turn conversations.
Skills created (13):
- Architect: /onboarding, /create-agent, /manage-agent, /defrag
- Postman: /email-triage, /meeting-prep, /weekly-agenda, /deadline-radar
- Transcriber: /transcribe
- Librarian: /vault-audit, /deep-clean, /tag-garden
- Sorter: /inbox-triage
Agent changes:
- architect.md: -70% (1554 → 473 lines)
- transcriber.md: -72% (530 → 147 lines)
- postman.md: -42%, librarian.md: -37%, sorter.md: -11%
- All agents: explicit post-it create-if-not-exists
Scripts:
- launchme.sh/updateme.sh: copy skills/ directly, remove generate-skills.py
Docs updated:
- README.md: new Skills section, mermaid diagrams, routing
- getting-started.md, examples.md: skill references
- docs/agents/*.md: capability tables with skill vs agent routing
- references/agents.md, agent-orchestration.md, agents-registry.md,
agent-template.md: skill registry, skill-first routing protocol
- generate-skills.py now respects SKILLS_DIR env var
- launchme.sh and updateme.sh generate into mktemp -d, copy to vault,
then clean up — no more untracked skills/ left in the repo
- Warn the user when python3 is missing so Cowork/Desktop users know
why .claude/skills/ is absent
- Remove "message board archival" from Librarian responsibilities
- Rename "Who to Message for What" → "When to Suggest Another Agent"
- Replace "Message to" column with "Suggest"
- Move coordination explanation above the table
- Update intro line to reflect dispatcher model
- Fix call-chain example consistency in CLAUDE.md and agent-orchestration.md
(chain lists already-invoked agents, "step N" matches chain length + 1)
- Renumber architect.md Task Checklist (was skipping 3) and replace
"Leave messages" step with dispatcher-driven "Suggested next agent"
- Replace "Leave a message to the Sorter" with signal via Suggested next agent
- Clarify "Do NOT write to other agents' files" → only prompt/config files
(.claude/agents/*.md), normal vault edits still allowed
- Fix agent count 10→8 in docs/getting-started.md
- Initialize SKILL_COUNT before conditional block in launchme.sh
README:
- Removed the "Skills" section since skills/ no longer exists
- Updated the project structure tree to reflect the current layout
- Clarified that agents are discovered natively by Claude Code
CONTRIBUTING:
- Replaced all references to "inter-agent messaging" with the new
coordination protocol (agent-orchestration.md)
- Updated the agent writing guidelines to use "Suggested next agent"
output format instead of the old shared file approach
What changed in every agent file:
- Removed the "Inter-agent messaging" section that referenced the
old shared file protocol (Meta/agent-messages.md)
- Added a "Suggested next agent" output block so agents can signal
follow-up work to the dispatcher without invoking other agents
- Simplified the prompts by removing routing logic that is now
handled centrally by CLAUDE.md
The agents no longer know about each other. They just do their job
and report what else might need attention. The dispatcher decides
whether to chain another agent.
Before this change, agents communicated directly with each other by
writing to a shared file (Meta/agent-messages.md), following the
protocol in references/inter-agent-messaging.md. This was fragile
and hard to control.
Now the dispatcher (CLAUDE.md) is the only coordinator. Agents do
not talk to each other. Instead, when an agent detects work for
another agent (e.g. missing vault structure, orphan notes), it
outputs a "Suggested next agent" section. The dispatcher reads it,
validates it against the agents-registry, and decides whether to
chain the next agent.
New files added:
- references/agent-orchestration.md: the new coordination protocol,
including call chain tracking, anti-recursion rules, and a max
depth of 3 agents per user request
- references/agents-registry.md: a capability registry that maps
each agent to its inputs, outputs, and chaining suggestions
Deleted:
- references/inter-agent-messaging.md: the old peer-to-peer protocol
The skills/ folder contained 8 SKILL.md files (one per agent) that
were auto-generated wrappers. They duplicated the same logic already
present in the agent files under agents/.
Claude Code discovers agents natively from .claude/agents/ by reading
their YAML frontmatter (name, description, tools, model), so the
skills layer was redundant and has been removed.