Agent Editor, Scoped Profiles & Tool Policies
This release introduces the Agent Editor — a full-featured interface for creating, customizing, and managing agent profiles directly from the WebUI. It also brings scoped tool and skill policies, significant hardening across profile and chat lifecycle operations, and a collection of important fixes.
Agent Editor
- New Agent Editor UI with Easy and Advanced modes for editing agent identity, prompts, model presets, tool policies, skill visibility, and avatars — all without destructive overwrites or model calls.
- Project-scoped profiles: switch between Global and project scope when managing agents; sparse reads, writes, resets, and policy configs stay bound to the selected layer.
- Profile lifecycle management: per-scope availability, duplication, active-profile status, inline project selection, scoped restore for inherited profiles, and synchronized profile switching across the sidebar and runtime.
- Reusable profile commands: create profiles quickly via
/profilein chat or through the Connector API, then open a fresh chat with the new profile in the selected scope. /permissionsslash command: opens the current profile's Agent Editor directly from chat.- Tools, MCPs, and Skills get explicit default switches with segmented per-item policy controls, preserving sparse overrides.
- Polished layouts and interactions: responsive Easy and Advanced surfaces, direct prompt editing, compact transfer lists, per-row profile actions, full-height ACE editor, themed segmented controls using the standard blue accent, and streamlined Manage Agents with separator rows.
- Comprehensive documentation replacing legacy guided-profile instructions with screenshot-led workflows covering sparse YAML, Markdown, and JSON overrides.
Scoped Tool & Skill Policies
- Scoped tool access policies: a unified project/profile-aware resolver for local, plugin, and MCP tool identities, enforced across prompts, schemas, connectors, execution, and delegated agents.
- Hardened layered policy enforcement: empty upper configs no longer shadow inherited restrictions; canonical tool identities carry through local and MCP execution; blocked tools are removed from rendered prompts.
- Profile skill visibility policies: sparse allow/block rules with an explicit default for future skills, enforced across discovery, loading, and chat activation while preserving history and legacy behavior.
Agent Profile Infrastructure
- Presence-aware profile overrides: layered profile metadata merges by field presence — missing keys inherit, explicit empty values clear inherited values.
- Hardened profile mutations: validated destructive requests and project-derived scopes at the API boundary; atomic project availability; collision, confirmation, and running-profile guards.
- Hidden utility profile: the internal default profile is omitted from profile selectors, new chats, and legacy global settings are normalized to Agent 0.
- Lightweight profile catalog reads: sparse editor overrides are detected without building full removal plans for every agent.
Built-in Plugins
- Migrate Agents plugin: bundled five-harness migration workflow with preview/import safeguards, documentation, WebUI assets, and corrected upload modal.
- Enhanced native Kokoro voice blending: updated American voice catalog, speed controls, in-memory weighted blending, singleton pipeline reuse, and blend input validation.
- Capability discovery alignment: MCP catalog labels are humanized with server names; skill discovery prompts are suppressed when
skills_toolis unavailable;behaviour_adjustmentprompt moves under the Memory plugin. - Slash commands separated from skills: skill results come only from
skills_tool; command discovery and invocation stay with the Commands plugin. - Scoped plugin configuration indexes: project- or agent-scoped plugins can open the shared settings surface even without a custom form.
- Thumbnails for core utilities: Tool Access, Pin to Top, Chat Naming, and Agent Editor get distinct artwork optimized for fast rendering.
Time Travel Retention
- Shadow-repo cleanup: automatic retention sweeps remove orphaned shadow repositories from deleted chats, optionally age-out stale history, repair stranded
index.lockfiles, and set aside corrupt repos — all configurable from plugin settings. - Sweeps run in a background thread (default every 6 hours) with durable logging and running totals.
Fixes
- SSRF regression in document queries (CVE-2026-4308): remote document downloads now route through the public-only HTTP fetcher, rejecting private targets including through redirects.
- File download path resolution: individual and bulk downloads resolve from the filesystem root, matching what the File Browser and editor expose.
- Chat deletion guard: empty or whitespace-only context IDs are rejected before any cleanup begins, preventing malformed requests from resolving to the shared chat directory.
- Project change persistence: project updates and deletion no longer rewrite every loaded chat — only affected chats are saved.
- Assistant-first provider history: orphaned leading assistant messages are omitted so Claude-compatible providers receive a user-first conversation.
- Plugin Hub dirty-edit preservation: tracked plugin edits are stashed during updates and restored if the update conflicts, with the conflict surfaced in the UI.
- Responses API fallback: opaque 400 errors from OpenAI-compatible Responses endpoints trigger a retry through Chat Completions.
- OAuth Codex version header: upstream model gates are satisfied by attaching the resolved Codex client version header.
- Desktop canvas resize: the live desktop iframe no longer captures pointer events during left-edge resize drags.
- Idle goal polling removed: goal revisions push through the shared state monitor instead of recurring API requests.
- Hour-aware duration formatting for the goal elapsed counter and other long-running displays.
- Open file button in canvas tab bar: existing files can now be opened at any time without closing all editor tabs.