AG Kit 2026.7.26
Antigravity-native production release: six-phase runtime integration, native tool safety, MCP synchronization, optional plugin packaging, dedicated compatibility CI, and complete operator/release documentation.
Added
.agents/antigravity.jsonas the machine-readable Antigravity runtime contract.- Native
.agents/hooks.jsonregistration with aPreToolUsegate forrun_command. - Destructive-command policy covering Unix root deletion, filesystem formatting, raw-disk overwrite, Windows drive formatting, and forced Windows root deletion.
- Antigravity Doctor with read-only discovery, MCP, hook, orchestration, plugin, and release-readiness diagnostics.
- Explicit MCP plan/sync helper with placeholder blocking, conflict preservation, opt-in force, and timestamped backups.
- Antigravity plugin builder for skills, agents, rules, workflow commands, hooks, MCP example, and SHA-256 artifact inventory.
- Regression tests for hook payloads, destructive patterns, runtime capabilities, MCP planning, doctor checks, and plugin output.
- Dedicated
Antigravity CompatibilityGitHub Actions workflow. - Root migration guide.
Changed
- Google Antigravity is the primary supported production runtime; cross-runtime Markdown portability remains best-effort.
- Root, CLI, web, lock files, toolkit version, web changelog, manifest, and integrity lock are synchronized at
2026.7.26. - Managed integrity coverage now includes the Antigravity contract, native hook configuration, hook tooling, schemas, plugin templates, and tests.
- README documentation now provides complete English and Vietnamese production setup, validation, MCP, plugin, rollback, and support-boundary guidance.
- Agent flow and toolkit architecture documentation now show the Antigravity runtime boundary and six integration phases.
- Release setup requires the Antigravity native contract check.
- Dependency Review Action is pinned to the Node 24-compatible v5 release while preserving severity and license policy.
Security
- The default hook blocks only high-confidence destructive operations and does not replace Antigravity permission or workspace-trust controls.
- Invalid, oversized, or unrecognized hook payloads fail open with a warning to avoid runtime-wide lockout after upstream payload changes.
- MCP synchronization never writes without
--apply, rejects unresolved placeholders, preserves conflicts unless forced, and backs up existing target files. - Plugin generation reads repository files only and excludes environment variables and home-directory configuration.
- Security documentation now includes the Antigravity runtime threat model, false-positive response, secret handling, artifact review, and rollback boundaries.
Compatibility
- Existing agent, skill, rule, workflow, and memory names remain compatible.
- The native safety hook is newly enabled by default and can be temporarily disabled with
"enabled": falsefor compatibility diagnosis. - Plugin installation remains optional; the repository
.agents/directory is the project source of truth.