版本记录
本页由仓库根目录的 CHANGELOG.md 生成。Changesets 负责收集每项改动,发布脚本负责版本号、日期和代号,文档构建负责生成本页与机器可读记录。历史版本说明保留发布时原文。
机器可读记录位于 release-history.json。
版本索引
| 版本 | 日期 | 代号 | 完整差异 |
|---|---|---|---|
| v1.2.1 | 2026-08-21 | Artemis · Wiseman | 比较 |
| v1.2.0 | 2026-08-11 | Artemis · Hansen | 比较 |
| v1.1.1 | 2026-08-10 | Artemis · Koch | 比较 |
| v1.0.4 | 2026-08-10 | Artemis · Glover | 比较 |
| v1.0.3 | 2026-08-08 | Artemis · Glover | 比较 |
| v1.0.2 | 2026-08-02 | Artemis · Glover | 比较 |
| v1.0.1 | 2026-07-31 | Artemis · Glover | 比较 |
| v1.0.0 | 2026-07-31 | Artemis · Glover | 比较 |
| v0.400.2 | 2026-07-18 | Apollo · Duke | 比较 |
| v0.400.1 | 2026-07-18 | Apollo · Young | 比较 |
| v0.400.0 | 2026-07-17 | Apollo · Young | 比较 |
| v0.227.1 | 2026-07-12 | Apollo · Evans | 比较 |
| v0.227.0 | 2026-07-12 | Apollo · Mattingly | 比较 |
| v0.226.0 | 2026-06-29 | Apollo · Stafford | 比较 |
| v0.225.3 | 2026-06-27 | Apollo · Schmitt | 比较 |
| v0.225.2 | 2026-06-15 | Apollo · Gordon | 比较 |
| v0.225.1 | 2026-06-02 | Apollo · Conrad | 比较 |
| v0.225.0 | 2026-06-01 | Apollo · Irwin | 比较 |
| v0.224.1 | 2026-05-27 | Apollo · Collins | 比较 |
| v0.224.0 | 2026-05-26 | Apollo · Armstrong | 比较 |
| v0.223.4 | 2026-05-25 | Apollo · Lovell | 比较 |
| v0.223.3 | 2026-05-25 | Apollo · Lovell | 比较 |
| v0.223.2 | 2026-05-25 | Apollo · Lovell | 比较 |
| v0.223.1 | 2026-05-25 | Apollo · Lovell | 比较 |
| v0.223.0 | 2026-05-24 | Apollo · Worden | 比较 |
| v0.222.3 | 2026-05-24 | Apollo · Scott | 比较 |
| v0.222.2 | 2026-05-24 | Apollo · Duke | 比较 |
| v0.222.1 | 2026-05-24 | Apollo · Young | 比较 |
| v0.222.0 | 2026-05-21 | Apollo · Armstrong | 比较 |
| v0.221.1 | 2026-05-19 | Apollo · Anders | 比较 |
| v0.221.0 | 2026-05-18 | Apollo · Anders | 比较 |
| v0.220.1 | 2026-05-14 | Apollo · Lovell Patch | 比较 |
| v0.220.0 | 2026-05-12 | Apollo · Lovell | 比较 |
| v0.219.0 | 2026-05-05 | Vostok · Gagarin | 比较 |
| v0.218.1 | 2026-05-05 | Apollo · Cernan Patch | 比较 |
| v0.218.0 | 2026-05-05 | Apollo · Cernan | 比较 |
| v0.217.3 | 2026-05-04 | Apollo · Shepard | 比较 |
| v0.217.2 | 2026-04-30 | Apollo · Swigert | 比较 |
| v0.217.1 | 2026-04-29 | Apollo · Haise | 比较 |
| v0.217.0 | 2026-04-28 | Apollo · Lovell | 比较 |
| v0.216.3 | 2026-04-27 | Apollo · Collins | 比较 |
| v0.216.2 | 2026-04-27 | Apollo · Aldrin | 比较 |
| v0.216.1 | 2026-04-27 | Apollo · Armstrong | 比较 |
| v0.216.0 | 2026-04-27 | Surface Coverage Harness | 比较 |
| v0.215.1 | 2026-04-24 | Agent Backend Matrix | 比较 |
| v0.215.0 | 2026-04-24 | Closed Adapter Loop | 比较 |
| v0.213.3 | 2026-04-19 | Vostok · Gagarin TC0 Patch R2 | 比较 |
| v0.213.2 | 2026-04-18 | Vostok · Gagarin TC0 Patch | 比较 |
| v0.213.1 | 2026-04-18 | Vostok · Gagarin Patch | 比较 |
| v0.213.0 | 2026-04-17 | Vostok · Gagarin | 比较 |
| v0.212.1 | 2026-04-16 | Vostok · Shatalov II | 比较 |
| v0.212.0 | 2026-04-15 | Vostok · Shatalov | 比较 |
| v0.211.2 | 2026-04-13 | Vostok · Volynov | 比较 |
| v0.210.0 | 2026-04-12 | Vostok · Komarov | 比较 |
| v0.209.0 | 2026-04-10 | Vostok · Popovich | 比较 |
| v0.208.0 | 2026-04-08 | Vostok · Titov | 比较 |
| v0.207.0 | 2026-04-06 | Vostok · Gagarin | 比较 |
| v0.206.0 | 2026-04-05 | Vostok · Tereshkova | 比较 |
| v0.205.0 | 2026-04-05 | Vostok · Bykovsky | 比较 |
| v0.204.0 | Vostok · Nikolayev | 比较 | |
| v0.203.0 | Vostok · Leonov | 比较 | |
| v0.202.0 | Vostok · Tereshkova | 比较 | |
| v0.201.0 | Vostok · Chaika II | 比较 | |
| v0.200.0 | Vostok · Chaika | 比较 | |
| v0.100.1 | Sputnik · Kedr |
v1.2.1 · 2026-08-21 · Artemis · Wiseman
GitHub Release · npm · 与上一版本比较
Added
- Add
serpbase searchas an optional structured provider for general web research. It follows the currentPOST /google/searchcontract and maps organic results to stable rank, title, link, and snippet fields. - Add one command availability contract for environment-backed providers. The contract declares required variables, discovery policy, setup guidance, and the current configuration state.
Changed
- Route open-web research intent to
retrieval searchand keep paid providers under explicit source selection. Default andallretrieval use public automatic sources without spending SerpBase credits. - Apply configuration-aware discovery to CLI help, list, search, describe, completion, schema, generated Agent commands, retrieval, and MCP. Ollama Cloud now uses the same environment-backed contract.
Fixed
- Stop unconfigured providers from leaking into discovery while preserving an explicit full description for setup. Direct calls fail with
auth_requiredbefore authorization or network activity. - Preserve numeric and boolean values in nested JSON templates, classify HTTP 402 as
quota_exhausted, and return provider-specific recovery guidance for authentication, quota, and permission failures. - Prefer general retrieval for current open-web questions and remove the stale Google News fallback from empty catalog searches.
v1.2.0 · 2026-08-11 · Artemis · Hansen
GitHub Release · npm · 与上一版本比较
Added
- Add a local adapter evolution lifecycle through
unicli runs distill,unicli evolve adapter,verify,inspect, androllback. Agents receive a staged candidate, a redacted evidence packet, and durable attempt history. - Add isolated baseline and candidate execution with disjoint validation and held-out cases. Verification records predicted fixes, regressions, independent effect evidence, duration deltas, and the exact patch used for promotion.
- Add Agent Plugins 1.0 discovery for portable Skills and configuration-only MCP packages.
unicli plugin inspectexposes the runtime projection without starting an external server.
Changed
- Require every evolution candidate to preserve its operation contract and declare a falsifiable hypothesis, expected fixes, at-risk cases, permissions, model affinity, and task-domain scope.
- Promote candidates only after strict validation improvement, complete predicted fixes, a populated held-out split, and zero measured regressions. Equal results keep the baseline.
- Organize the English and Chinese documentation around repair and evolution, with the callable lifecycle exposed in architecture, CLI, plugin, benchmark, and Agent-facing pages.
Fixed
- Recheck packaged sources and user overlays immediately before promotion, serialize competing writers, resume prepared promotions after crashes, and preserve exact rollback artifacts.
- Keep malformed traces, secret-bearing evidence, mutation claims, stale candidates, and failed predictions outside the promotion path while retaining structured recovery errors.
- Repair the mobile documentation menu by limiting the desktop navigation container rule to the top-level navbar layout.
v1.1.1 · 2026-08-10 · Artemis · Koch
GitHub Release · npm · 与上一版本比较
1.1.0was the internal Changesets candidate.1.1.1is the first public release in the 1.1 line.Published from annotated tag
v1.1.1at commit8617d2e1through GitHub Actions run31406014098. npm Trusted Publishers issued the provenance attestation, and the GitHub Release carries both Windows process-owner executables.
Added
- Add default detached updates for persistent non-interactive Agent installations. Every exact-version install records durable progress, uses one lease across concurrent Agent processes, retries bounded failures, and exposes opt-out state through structured CLI and MCP metadata.
- Add
unicli upgradewith live version checks, interactive Y/N approval, unattended installation, 24-hour deferral, exact-release dismissal, persistent automatic-update settings, and npm, pnpm, or Bun detection. - Add one intent plan shared by search, describe, one-shot execution, fast paths, and MCP. The plan carries task semantics, personalization, target scope, feasibility, named ranking evidence, and typo-aware site resolution.
- Add GitHub code, commit, topic, user, repository, issue, pull-request, and file discovery through structured
ghcommands. Repository and issue searches keep best-match and hybrid retrieval available as explicit modes. - Add generated English and Chinese release pages plus
release-history.json. Every historical entry links to its npm artifact, GitHub Release, and exact Git comparison. - Add current-user discovery through
--personalized, including saved-item, feed, network, account, and activity operations. Xiaohongshu saved notes now have an owned authenticated command.
Changed
- Replace parallel intent-frame and intent-boost paths with one bounded ranking pipeline. Bilingual discovery now compiles the task once, applies one site resolution policy, and returns executable usage with its ranking signals.
- Align root help, onboarding, Agent skills, operation descriptions, and public catalog pages around the same search, execution, personalization, repair, and update paths.
- Benchmark the current product surface against pinned OpenCLI and CLI-Anything snapshots. The maintained task set covers 11 executable intents, five personal content intents, root discovery, catalog breadth, and actionability.
- Run release discovery from a daily local cache. Ordinary commands stay free of foreground registry waits, while interactive terminals retain explicit choice and non-interactive Agents can adopt the next release automatically.
Fixed
- Preserve authentication requirements, effective operators, exact usage, and structured causes across search, describe, fast-path, and MCP projections.
- Keep benchmarks deterministic by disabling detached release checks inside measured child processes.
- Remove stale duplicate
Unreleasedsections and replace the manually copied historical release audit with generated cross-version documentation.
v1.0.4 · 2026-08-10 · Artemis · Glover
GitHub Release · npm · 与上一版本比较
Published from annotated tag
v1.0.4at commit8289f86cthrough GitHub Actions run31373576820. npm Trusted Publishers issued the SLSA provenance attestation, and the GitHub Release carries both Windows process-owner executables.
Added
- Add the official seventh-edition CCF A conference directory with all 58 conferences, corrected 2026 identities, publisher metadata, aliases, and former names.
- Add first-party AAAI proceedings and GitHub repository evidence adapters. Add conference publication views for PACMPL, PACMSE, PACMMOD, and SIGGRAPH papers published through ACM Transactions on Graphics. Add a publisher-neutral Crossref venue view for PVLDB and other journal-backed proceedings.
- Add a bilingual scholarly discovery guide covering conference lookup, OpenReview review threads, official awards, PDFs, code, and datasets.
Changed
- Resolve conference names and years before scholarly fan-out. Publisher searches now use exact conference identities, ACM and IEEE cross-publisher routing, and publication-specific issue models for OOPSLA, FSE, SIGMOD, and SIGGRAPH.
- Run independent scholarly sources concurrently with a configurable deadline. Empty or slow sources preserve structured causes while healthy sources can still complete the request.
- Recover lightly misspelled academic titles through one bounded correction pass and expose the executed query with every correction.
Fixed
- Reject nearby acronyms, regional editions, companion volumes, workshops, posters, talks, and proceedings front matter from exact conference results.
- Require a source-backed PDF URL for PDF success and preserve expected empty, invalid input, timeout, rate-limit, and restricted-access errors.
- Accept bare OpenReview forum identifiers during tracing, classify author responses as rebuttals, preserve SIGCHI DOI links, and skip conference context sources that do not apply.
- Bound DBLP and general scholarly requests, coordinate Crossref traffic, and keep search-derived GitHub matches explicitly marked as candidate implementations.
- Parse venue years supplied in positional input, apply topical venue filters after source-specific routing, and join code and dataset evidence into cross-site traces.
- Bound OpenReview requests and retry waits, run independent artifact sources concurrently, and declare file-writing reader effects accurately.
- Use DBLP publication records for Springer-backed CCF proceedings, preserve their separate conference and publication years, and over-fetch venue candidates before exact filtering.
- Constrain title-based traces by the requested venue and year, reuse resolved OpenReview forum identifiers, and reject similarly named resource records.
- Make the live adapter health probe honor authentication and read-only contracts while retaining public HTTP 401 and 403 responses as drift. Repair the current 36Kr and Medium RSS routes, and quarantine endpoints with reproducible upstream blocks.
v1.0.3 · 2026-08-08 · Artemis · Glover
GitHub Release · npm · 与上一版本比较
Published from annotated tag
v1.0.3at commitf2d0b136through GitHub Actions run31258688138. npm Trusted Publishers issued the SLSA provenance attestation, and the GitHub Release carries both Windows process-owner executables.
Added
- Add 23 provider-native commands for Zhihu, X, Lark/Feishu, and Bluesky. These routes preserve the official CLI executable, authentication model, and structured response while remaining available through expanded Uni-CLI MCP.
- Add first-party provenance, native-surface, and provider-scope metadata to the external CLI catalog for X, Bluesky, Lark, Reddit Devvit, DingTalk, and Slack.
- Add focused English and Chinese guidance for selecting official native tools, hosted MCP services, and Uni-CLI web adapters.
Changed
- Rebuild the public documentation site around the green observatory and orbital operation chapters, with tighter navigation, responsive interaction, local brand assets, and rewritten guides for authentication, browser and desktop control, CLI usage, integrations, and repair.
- Route the existing Feishu bridge through the official
lark-cli, including agenda, document search, messaging, and task operations with JSON output. - Adopt the human-writing harness as the repository prose boundary and install its compact agent guidance through
unicli init.
Fixed
- Replace invalid Slack content calls through the app-development CLI with the corresponding official Slack Web API operations.
- Correct the Lark executable and command paths used by existing adapters, and distinguish content operations from application-development-only tools.
- Update
js-yamlandundiciacross the production lock closure to versions that clear the npm security audit while preserving npm 10 optional peers.
v1.0.2 · 2026-08-02 · Artemis · Glover
GitHub Release · npm · 与上一版本比较
Published from annotated tag
v1.0.2at commitd6940a1cthrough GitHub Actions run30747691291. npm Trusted Publishers issued the SLSA provenance attestation, and the GitHub Release carries both Windows process-owner executables.
Added
- Add
openreview conference, a paced and resumable venue archive for public submissions, review and rebuttal threads, decisions, note revisions, hosted PDFs and supplementary files, artifact hashes, and external research links. - Add bilingual operator documentation for authenticated, sequential, multi-year OpenReview archival and recovery.
Changed
- Route every OpenReview command through one authenticated client that supports API v2/v1 venue discovery, browser-derived sessions, bounded token refresh, strict request spacing, rate-limit headers, transactional downloads, and SHA-256 verification.
- Resolve OpenReview venue tabs from each group's live
submission_idanddecision_heading_map, removing conference-specific label assumptions. - Redesign the public product surface around one operation receipt and a denser, responsive documentation layout while keeping semantic source content and generated agent documents aligned.
Fixed
- Preserve AT-SPI accessible names when nodes expose attributes separately from their visible labels.
- Make visual-observation evidence claims atomically single-use so concurrent consumers cannot reuse the same claim.
- Harden durable MCP task persistence on Windows with platform-aware replacement and cleanup behavior.
- Preserve actionable OpenReview authentication, challenge, rate-limit, and transient upstream errors; interrupted archives resume from durable cursors without replaying completed downloads.
v1.0.1 · 2026-07-31 · Artemis · Glover
GitHub Release · npm · 与上一版本比较
Published from annotated tag
v1.0.1at commita317b32athrough GitHub Actions run30644287649, using npm Trusted Publishers with SLSA provenance and a GitHub Release carrying both Windows process-owner executables.The
v1.0.0candidate remained unpublished. Both release attempts stopped before registry or GitHub Release creation when the shared runner falsified the index-construction performance budget. Version 1.0.1 carries the measured hot-path correction without rewriting that tag.
Changed
- Cache exact-content document tokenization in a bounded 8,192-entry preparation store and reuse it across immutable index rebuilds. Fuse per-document term counting with postings construction, retain only term counts in the finished index, and invalidate prepared data whenever any indexed field changes.
- Preserve the 1.0 operation-first contract, computer-use drivers, modern MCP task surface, deterministic provider routing, and 326-site catalog from the 1.0.0 candidate as the first publishable 1.x package.
Fixed
- Regenerate the public agent-document surface after release metadata changes so local candidates and published versions cannot retain an older version label.
- Upgrade
fast-urito 3.1.5 in the locked dependency closure, removing the production audit findings that affected earlier 3.1.x builds.
v1.0.0 · 2026-07-31 · Artemis · Glover
GitHub Release · npm · 与上一版本比较
Added
- Introduce one operation contract across CLI, MCP, browser, desktop, HTTP, app, and subprocess substrates. Discovery now returns operation family, effects, target scope, feasibility, provider, evidence, and recovery metadata before an agent executes work.
- Add a first-class computer-use driver with exact target binding, visual refs, same-provider post-action capture, typed effect verdicts, and bounded observation. Native AX, UIA, AT-SPI, CDP, and visual paths share the contract without collapsing their capabilities.
- Add modern MCP protocol support for durable tasks, subscriptions, request settlement, principal quotas, result budgets, and the 2026-07-28 protocol while retaining the supported 2025-11-25 transport contract.
- Add compact command description, one-shot intent execution, task-routing guidance, live capability smoke tests, and operation specifications for browser control.
Changed
- Replace cross-provider cascades with deterministic feasibility ranking and one declared provider per execution. A provider failure now returns its structured cause and repair path instead of silently switching substrate or target.
- Rebuild intent search around bounded top-k selection and reusable indexed postings. The 611-case evaluation records 76.27% top-1, 92.47% top-5, and 0.8294 MRR@5 while performance tests enforce the new query budgets.
- Bind compute dispatch, screenshots, assertions, waits, and replay to exact app, renderer, transport, and window identities. Ref lifetimes, tombstones, and atomic artifact publication prevent stale or cross-target execution.
- Align CLI, MCP, adapter, browser, auth, diagnostic, and agent-readable surfaces around structured operation envelopes. The static catalog now contains 326 sites and 1,829 commands, backed by 980 schema-conforming YAML adapters plus 246 TypeScript adapters.
Fixed
- Preserve operation-specific errors through every pipeline and transport boundary, including authentication, rate limits, unsupported surfaces, stale refs, ambiguous targets, provider policy, and temporary resource contention.
- Close browser ownership and cookie-authority gaps so probes remain passive, background and foreground contracts stay explicit, and empty or policy-blocked profiles fail with an actionable next step.
v0.400.2 · 2026-07-18 · Apollo · Duke
GitHub Release · npm · 与上一版本比较
Published from annotated tag
v0.400.2at commit785c3ef6through GitHub Actions run29658936515, using npm Trusted Publishers with SLSA provenance and a GitHub Release carrying both Windows process-owner executables.
Patch Changes
481b643: Position Uni-CLI as the open Agent-Computer Interface runtime for real software. Align English, Chinese, agent-readable, package, and executable architecture surfaces around the current discover-select-govern-act-observe-repair model, while documenting that automatic substrate arbitration, universal evidence, and fixed-core protocol parity remain roadmap work.
Make MCP discovery honest about that boundary: list/search results now identify adapter versus fixed-core sources and whether
unicli_runsupports them; fixed-core run attempts returnunsupported_surfacewith the native CLI route.3cfccd1: Replace the relevance-blind arXiv YAML path with one cancellable TypeScript search boundary that compiles natural multi-term and disjunctive queries into explicit arXiv syntax, over-fetches bounded candidates, filters for meaningful query overlap before limiting, and preserves caller-authored field syntax.
Apply the same domain-neutral relevance analysis to AI source fusion, keep origin publishers distinct from authors, artifact hosts, venues, and community platforms, and retain concrete first-party recovery when indexes are empty. GitHub issue and pull-request thread adapters now require the exact URL form accepted by the underlying
ghCLI, while HTTP failures preserve status-specific authentication, rate-limit, missing-source, and upstream recovery guidance.f391bf0: Replace the CLI-only usage counter with a bounded, owner-only local event log covering CLI, MCP, ACP, bench, and hub adapter calls. Diagnostic events now carry version plus stabilized clean/dirty source identity, trace, transport, surface, parent/child operation role, outcome, latency, result size, and typed failure metadata while excluding arguments, content, URLs, credentials, raw errors, and adapter filesystem paths. Complete lock owners are durably published, dead owners and abandoned candidates are reclaimed by exact inode, dual operation/release failures remain visible, and bounded readers reject symlinks, identity changes, and oversized files before loading bytes.
Make
unicli usage reportcombine legacy and current evidence, distinguish transports, reject invalid windows and limits, and surface corrupt or unreadable JSONL through structured error envelopes instead of silently dropping records. CLI and MCP request boundaries sanitize unknown user tokens, correlate direct kernel work without double counting, and preserve allowlisted tool error types.Normalize Commander parser failures through the same structured envelope and local-event boundary: unknown options and missing values now use stable
invalid_inputdiagnostics without echoing raw user tokens.3cfccd1: Bind compute operations to their original app, CDP endpoint, or ref transport instead of falling through to an unrelated browser or screen. Forward target arguments through CDP, UIA, and AT-SPI snapshots, keep incompatible persisted CDP sessions from replacing explicit apps, bind macOS/Windows/Linux native refs to exact window IDs and traversal paths, publish empty target tombstones so old refs cannot revive, and reject unresolved or legacy refs.
Make
compute waitpoll fresh target snapshots for ref, text, and appear/disappear/focused/enabled/checked state conditions. Unmet conditions now time out, ambiguous unscoped waits returninvalid_input, and duration-only Visual/Subprocess waits can no longer report false condition success.Serialize compute-ref shard readers with publishers so retention cannot remove an enumerated record mid-read, and report live lock contention as a typed, retryable temporary failure. Combined snapshot-and-screenshot capture now derives one exact window identity from ref provenance, binds every replay step to it, and fails closed if the window cannot be proved or changes mid-capture.
Reject partially parsed numeric CLI options, publish format-sensitive screenshot files through extension-preserving atomic staging, and surface transport cleanup failures instead of printing a false successful result. Align CLI, MCP contract, help, and operator docs for window targeting, click background mode, observe app/top-k, assert visibility, and exact CDP target IDs.
v0.400.1 · 2026-07-18 · Apollo · Young
GitHub Release · npm · 与上一版本比较
Published from annotated tag
v0.400.1at commit5a1d0b78through GitHub Actions run29636301437, using npm Trusted Publishers with SLSA provenance and a GitHub Release carrying both Windows process-owner executables.
Added
- Domain-neutral
retrieval search|sourcesdiscovers 41 registered, read-only evidence sources from declarative adapter metadata, executes bounded federated queries, and returns normalized candidates with source identity, raw provider records, exact retry commands, and structured partial failures. ai search|pulse|read|sources|landscape|profilesadds a role-aware overlay with 35 executable source rows, 102 maintained first-party targets, and 10 practitioner profiles spanning foundation-model work, training, inference, world models, embodied AI, hardware, agents, evaluation/safety, and research.evidence-document.v1gives HTML, text, JSON/XML, PDF text, and GitHub threads one provenance-bearing document contract with canonical URLs, headings, links, true truncation metadata, retrieval time, and a hash of returned content. ModelScope, OpenCSG, Bluesky, Hugging Face community, and structured GitHub issue/PR/discussion surfaces now participate through owned adapters.
Changed
- Generic source discovery, execution, fusion, and reading now live below AI as a reusable retrieval kernel. AI-specific vendor identity, official-domain attribution, role vocabulary, and pulse selection remain a data overlay, so future technical, medical, standards, security, or other domains do not need to duplicate transport logic.
- Search and reading use bounded concurrency, per-source deadlines, explicit timestamp provenance, strict
--sincesemantics, opt-in authenticated sources, and transport-identical CLI/MCP contracts instead of silent fallbacks or fabricated freshness.
Fixed
- Redirect validation, cache identity, download cleanup, cancellation, and authentication propagation now remain correct across HTTP, TypeScript adapters, PDF extraction, and child processes. Binary payloads and challenge pages fail closed rather than becoming successful Markdown.
- Exact NVIDIA, AMD, Ascend, T-Head, Kunlunxin, and Cambricon queries preserve catalog-owned repositories and avoid unrelated hardware-domain fallback; hosted artifacts remain distinct from their hosting platform, while GitHub issue and pull-request reads retain comments and review state.
- Clean production installs now declare the XML DOM parser used by PubMed and bioRxiv instead of inheriting it from documentation tooling. The release truth gate rejects undeclared literal package loads across import/export, dynamic import, require, require.resolve, and createRequire aliases, plus lockfile entries that would be installed as development-only dependencies. It also requires exact package identity and dependency-map parity between the publication manifest and root lock entry.
- Browser broker auto-start now always executes the compiled broker artifact from the installed package or repository build. Source-mode commands fail with an exact
npm run buildrecovery when that artifact is absent instead of depending on the development-onlytsxtranspiler at runtime.
Verification
- The complete local release gate passed 3,131 unit tests (4 skipped), 94 integration tests (16 platform-skipped), 6,528 adapter tests, 5 performance tests (1 skipped), and 23 targeted coverage behaviors at 100%.
- All 994 YAML adapters passed adapter and schema-v2 lint; conformance reported 952 passed, 0 failed, and 42 explicitly quarantined. Stats, release truth, exports, public-boundary, formatting, type, lint, build, and strict release metadata checks also passed.
- Three bounded Agent consumer rehearsals exercised 37 NVLink/NVSwitch, domestic-accelerator, and deep-algorithm tasks. The implementation repaired every resulting P1 boundary finding; the final independent rereview reported no remaining P0/P1 finding for this retrieval scope.
- A clean tarball installation returned version
0.400.1, discovered all 41 generic and 35 AI sources, registeredpubmed.search, and completed a live one-result PubMed query through the installed package. Its broker auto-start used the compiled artifact without starting a browser provider or Chrome. - Main CI run
29635957077passed after its Windows matrix proved the lifecycle assertion against the native Job Object owner. The tagged release workflow then repeated the complete gate, built both Windows binaries, and published the package and GitHub Release without an npm fallback token.
v0.400.0 · 2026-07-17 · Apollo · Young
GitHub Release · npm · 与上一版本比较
Published from annotated tag
v0.400.0at commit3e4d555cthrough GitHub Actions run29568815086, using npm Trusted Publishers with SLSA provenance and a GitHub Release carrying both Windows process-owner executables.
Added
- The generic
computer-useMCP profile now exposes 16 direct browser tools alongside 16 computer controls: prepared state, screenshots, navigation, trusted ref/viewport input, tabs, bounded content/history search, claims, dialog/download supervision, and explicit foreground presence. - Existing Chrome can render an isolated, pointer-through Shadow DOM edge glow and virtual cursor only for an explicit foreground target. The renderer has no idle timer, RAF loop, or infinite animation and honors reduced motion.
- Open-tab and history search reads eligible content on demand with fixed tab, frame, text, concurrency, and result ceilings, without debugger attachment, target claims, focus changes, navigation, or persistent indexing.
Changed
- Per-command browser ownership and the legacy HTTP daemon are replaced by one authenticated Browser Runtime Broker. Agent sessions share provider lifetime while retaining exclusive target leases, profile partitions, explicit handoff, turn cleanup, idle TTL, crash recovery, and transport-independent CLI/MCP/plugin identity.
- Browser, compute, MCP, subprocess, overlay, and sidecar operations now share bounded cancellation, exact action settlement, deny-first permissions, process-tree containment, and fresh snapshot-ref generation.
- The tag workflow cross-builds x64 and arm64 Windows Job Object owners from the locked Rust workspace, validates their PE payloads, bundles both into the provenance-signed npm artifact, and exposes architecture-labelled Release assets; clean installs no longer depend on unpublished platform packages.
- Windows Native Messaging registration now selects the architecture-matched PE launcher and publishes content-addressed, immutable host generations, so reinstall or upgrade cannot replace an executable used by an active Chrome connection.
- Release metadata now distinguishes a complete local delivery from an npm or GitHub publication, so generated documentation cannot claim an event that did not occur.
Fixed
- The npm lock retains DocSearch's complete optional React peer closure, and the release truth gate now rejects future npm 11 pruning that would make clean Node 22/npm 10 installs fail before verification starts.
- Background Chrome allocation preserves the active tab, focused window, and foreground app; doctor/status/session probes start neither providers nor placeholder targets.
- Ref actions fail closed on stale generations, ambiguous aliases, unsupported frames, occlusion, sensitive content, and points outside the live CSS viewport instead of replaying or guessing.
- Transport close retries unacknowledged session cleanup, raw snapshots stop at their producer-side bound, and composed-tree redaction crosses open shadow roots, same-origin frames, and slots.
- Native-host and broker boundaries now share one exact, bounded Chrome error contract. Target-invalidating results close and reacquire only the affected target while preserving outcome ambiguity and the live host connection.
Verification
- The complete
npm run verifygate passed with 2,992 unit (4 skipped), 94 integration (16 platform-skipped), 6,467 adapter, 5 performance (1 skipped), and 23 targeted coverage behaviors at 100%. - GitHub Actions run
29567020303passed Ubuntu Node 22/24, macOS Node 22, Windows Node 22 including the real Native Messaging integration, and all three x64 Rust sidecar jobs. - Independent bounded audit and counterexample rerun reported no remaining P0/P1/P2 findings for the delivered browser-control scope.
- Real Chrome behavior covers shared runtime ownership, no-focus background work, open-shadow/same-origin refs, privacy redaction, visible presence, semantic isolation, reduced motion, and byte-identical teardown.
v0.227.1 · 2026-07-12 · Apollo · Evans
GitHub Release · npm · 与上一版本比较
Fixed
- Explicitly forced detached update checks now run under CI while normal CI and non-TTY invocations remain network-free.
- macOS browser-seed simulations declare their target platform instead of inheriting the runner host, and profile-seed manifests serialize portable POSIX-relative paths.
- Test inventory and Git reference synchronization fixtures now own their case-sensitivity and line-ending assumptions, so release evidence is stable across Linux, macOS, and Windows.
Verification
- GitHub Actions run
29196085654passed Linux Node 22 and Node 24, Windows Node 22, macOS, and all three Rust sidecar jobs. - The
v0.227.0candidate correctly stopped before npm publication and GitHub Release creation when its release gate found host-contaminated tests.0.227.1is the corrected publication target and carries the0.227.0production truth fixes below.
v0.227.0 · 2026-07-12 · Apollo · Mattingly
GitHub Release · npm · 与上一版本比较
Security
- Live browser and CDP cookie acquisition is memory-only. Cookie files are created only by explicit import/export commands; POSIX storage uses an owner-only
0700directory and0600file, atomic replacement, legacy-mode tightening, and symlink rejection. - Undici 8.7.0 and js-yaml 4.3.0 remove the production advisories reported against the previous dependency graph. CI and the tag workflow now enforce a zero-moderate-or-higher production audit on Node 22 and Node 24.
PRIVACY.mdandSECURITY.mdnow describe the implemented credential and network data flows and are included in the published npm artifact.
Fixed
- All Node HTTP owners now pair
undici.fetchwith the same package's proxy dispatcher, including pipeline, OAuth, download, extraction, cascade, and public HTTP transport paths. Proxy andNO_PROXYbehavior is locked by a real local-proxy regression and Node 22/24 live command checks. unicli repairis now a bounded, shell-free verifier for the exact original command. It performs no hidden npm, git, or agent mutation; its envelope, oracle evidence, and process exit code express one result.- Network, authentication, rate-limit, and browser-availability failures no longer tell agents to edit adapters. Only established adapter-drift classes offer repair verification.
- Root metadata commands no longer wait for update-network I/O. A detached worker refreshes the correctly scoped npm package cache for the next run.
- Explicit cookie export returns
auth_requiredwith exit 77 when no cookie is found, rather than reporting process success without a persisted artifact. - Per-domain rate limiting serializes concurrent callers and retains the strictest declared policy. Jina reads bypass stale upstream cache entries.
Changed
- The executable action contract is derived from live owners and budgeted as 50 registered composition actions plus 55 transport-native actions. Catalog, documentation, and runtime must agree exactly.
- Fixture shape, deterministic integration, real endpoint, authenticated browser, cold-start, and warm-start evidence are published as separate claims. Inventory count is not presented as operational health.
npm run verifyincludes repair truth integration; Node 22/24 CI and the release workflow execute the canonical gate instead of hand-maintained test subsets. Reference synchronization now discovers nested checkouts and fails closed on dirty, diverged, or empty work.
Verification
- Node 22.23.1 and Node 24.18.0 each pass 250 unit files (2,807 passed, 2 skipped). The clean gate passes 11 integration files, 170 adapter files with 6,467 tests, performance, coverage, conformance, export, stats, release-truth, changeset, and public-boundary checks.
- The real E2E matrix passes 44 of 44 workflows with zero failures or skips, and the production dependency audit reports zero vulnerabilities.
v0.226.0 · 2026-06-29 · Apollo · Stafford
GitHub Release · npm · 与上一版本比较
Minor Changes
- Browser automation now defaults to a verified logged-in identity: Uni-CLI attaches to an already-exposed local browser profile when possible, otherwise seeds its automation profile from the preferred local Chrome profile, and keeps empty profiles explicit through
--ephemeral.
v0.225.3 · 2026-06-27 · Apollo · Schmitt
GitHub Release · npm · 与上一版本比较
Added
unicli scholarnow has a source-grounded academic-resource loop for discovery, comparison, PDF download, bounded full-text reading, resource lookup, coverage inspection, and fail-closed source auditing across the major scholarly surfaces.- Source-scoped read/full-text commands now cover arXiv, ACL Anthology, OpenReview, PubMed/PMC, bioRxiv, medRxiv, CVF, NeurIPS, PMLR, OpenAlex, Semantic Scholar, and Unpaywall where each source exposes an actual full-text or PDF URL.
scholar-artifactsprovides the shared PDF download andpdftotextextraction boundary used by source adapters, keeping artifact validation, page ranges, truncation, and provenance consistent.
Changed
- Scholarly discovery, capability policy, operation policy, fast-path metadata, and generated command catalogs now expose source-fulltext, resource, citation, and provenance capabilities directly to agents.
- CNKI search moved from the old YAML fetch/map adapter to a typed KNS-backed adapter with current request payload, vv token generation, structured record normalization, and regression coverage.
Fixed
- Broad PDF search intent no longer lets Unpaywall outrank execution-oriented paper download/read workflows unless the query has DOI or open-access intent.
- Generated manifest scanning now preserves shared TypeScript adapter declarations used by scholarly adapters, preventing source-mode/dist parity drift after adapter refactors.
v0.225.2 · 2026-06-15 · Apollo · Gordon
GitHub Release · npm · 与上一版本比较
Security
- The legacy HTTP MCP transport (
unicli mcp serve --transport http) now validates theOriginheader on every request, rejecting non-loopback browser origins with403before any routing. Previously this transport — unlike the Streamable HTTP transport — accepted cross-origin browser requests, so a malicious page could drivetools/callagainst a local server bound to loopback. The DNS-rebinding policy is now shared by both transports viasrc/mcp/origin-guard.ts. Reported privately by Ryan Vonbrubeck (@dodge1218).
Added
unicli browser consolenow reads bounded current-page console messages, warnings, errors, and page error events from the browser evidence hook without exposing page-context eval or raw CDP authority.- Compute command contracts now expose core computer-use action arguments through
describe,schema, and MCP tool schemas, including click/type/press/scroll fields that agents need for real OLo handoff planning. - Compute snapshots and
findresults now project ref provenance, including the provider, namespace, transport, scope, stable alias, TTL, identity, bounds, and app/process context.
Changed
- MCP JSON-RPC wire handling now shares a single internal type boundary instead of carrying parallel request/response shapes.
- Intent discovery and browser supervision surfaces now expose more reliable agent-facing evidence for local action planning.
Fixed
- Compute actions now fail closed on OLo-owned, browser-owned, and unknown namespaced refs before dispatch, returning structured
foreign_reforunresolvable_refenvelopes instead of falling through to a generic compute failure.
v0.225.1 · 2026-06-02 · Apollo · Conrad
GitHub Release · npm · 与上一版本比较
Added
npm run site:availabilitynow classifies every adapter command and runs one bounded safe read probe per site when a command is public, non-browser, non-destructive, and has no required semantic input.npm run e2e:realnow exercises a built-CLI real workflow matrix across common web, browser-adjacent, social, reference, and local-tool routes.- Xiaohongshu now has a public
feedreader for front-line social-media smoke tests without forcing browser/CDP state into every availability check.
Changed
- Adapter health and site availability now share the same environment classifier for auth gates, platform gates, local daemons, transient network failures, rate limits, and declared detect probes.
- Electron desktop and AI-chat commands now declare their
cdp-browsersubstrate requirement, so health gates skip them honestly instead of misreporting unavailable local app control as site breakage. unicli donow returns objective-level delivery spec templates for media playback intents while preserving explicit execution throughunicli delivery run.
Fixed
- Browser launcher repair now converts detached
spawnfailures into catchable launch errors and rejects invalidmdfindapp executable paths before they poison CDP/browser recovery. - Browser-session CDP acquisition now creates a fresh page target for user-session commands, so a stale logged-in automation tab cannot make Twitter/X and Xiaohongshu hang on stealth injection.
- The all-site audit no longer empty-probes commands that require semantic inputs such as
query,author,pid,id,url, ortags. - The Maoyan hot adapter now follows the current public box-office response path directly instead of relying on runtime select-path auto-fix.
- Empty successful adapter observations remain
ok=trueand exit0; only explicitempty_resulterrors become failure envelopes. - Common social-media smoke routes for Twitter/X, Xiaohongshu, Reddit, YouTube, Bilibili, and Weibo now pass through the built CLI after the browser-substrate repair.
Verified
RELEASE_CODENAME="Apollo · Conrad" npm run releaseSITE_SWEEP_TIMEOUT_MS=10000 npx tsx scripts/site-availability-sweep.tsnpm run adapter:healthnpm run e2e:realnpm run typechecknpm run lintnpm testnpm run format:checkgit diff --checknpm run release:check -- --strict-codenamenpm run verifynpm publish --dry-run
v0.225.0 · 2026-06-01 · Apollo · Irwin
GitHub Release · npm · 与上一版本比较
Added
- Architecture audit now emits a catalog-derived
capability_matrixfor web, browser, desktop, system, protocol, and bridge control surfaces. - Architecture audit now emits
workflow_readinessfor the vehicle-assistant workflows: media playback, video search, browser tab control, installed app operation, productivity state, and open/navigate destination. unicli donow attaches adelivery_spec_templatefor executable matches so intent planning can hand off tounicli delivery runwithout automatically executing side effects.- Public release audit docs now compare the
0.225.0candidate against the historical0.200.0through0.224.1release lines.
Changed
- Uni-CLI is now positioned and audited as the universal computer-control platform for agents: intent, policy, action substrates, evidence, delivery, and repair across real software.
- Core Commander commands now project into the same command-contract family as adapter commands, so
compute,browser,delivery,runs,mcp,agents, andarchitectureare first-class control operations in architecture and describe surfaces. - README, Chinese README, architecture docs, how-it-works, roadmap, FAQ, glossary, generated public Markdown,
llms.txt,llms-full.txt, skills, MCP registry metadata, and release metadata now point at0.225.0. - Release docs now describe the current
0.225.0product-frame minor line instead of the stale0.220.xexecution-substrate patch line.
Fixed
- Browser pipeline unit tests now force their intended CDP/mock acquisition path instead of accidentally using a live Uni-CLI browser daemon.
- Release propagation accepts the current generated operation-catalog FAQ copy, avoiding stale release metadata after docs copy changes.
- Architecture inventory no longer omits core command source paths or treats core command governance as fake adapter repair metadata.
Verified
npx vitest run tests/unit/core/capability-matrix.test.ts tests/unit/core/architecture-tree.test.ts tests/unit/commands/architecture.test.ts --maxWorkers=1 --reporter=dotnpm run typechecknpm run lintnpm testnpm run docs:buildnpm run docs:check-publicnpm run boundary:checknpm run release:check -- --strict-codenamenpm publish --dry-run
v0.224.1 · 2026-05-27 · Apollo · Collins
GitHub Release · npm · 与上一版本比较
Added
marxists-cnnow exposes a Chinese archive reader with normalized text output and search/discovery aliases for Chinese Marxists archive workflows.
Changed
- Release records, public docs, skills, MCP registry metadata, and generated stats now point at
0.224.1.
Fixed
- Twitter timeline/comment commands now expose user timeline and comment retrieval paths through the live adapter catalog.
Verified
npm run releasenpm run release:check -- --strict-codenamenpm run verifynpm publish --dry-runnpm run docs:check-public
v0.224.0 · 2026-05-26 · Apollo · Armstrong
GitHub Release · npm · 与上一版本比较
Minor Changes
- cd40064: Architecture and dependency refresh release: callable architecture audit/tree, live registry-backed search with registry-version caching, local computer-use action evidence, refreshed command discovery semantics, and the latest
undici,ws, andzodreleases. The runtime floor is now Node.js 22.19+ becauseundici@8requires that engine baseline.
All notable changes to Uni-CLI are documented here. Version format: MAJOR.MINOR.PATCH — see contributing/COPY.md for the codename system.
v0.223.4 · 2026-05-25 · Apollo · Lovell
GitHub Release · npm · 与上一版本比较
Fixed
- Compute capture reference tests now parse fallback JSON content before asserting screenshot paths, so Windows escaped path separators do not break CI while preserving the externalized-image contract.
Verified
npx vitest run --project unit tests/unit/compute-capture-reference.test.ts --maxWorkers=1 --reporter=dotnpx oxlint tests/unit/compute-capture-reference.test.tsnpm run verify
v0.223.3 · 2026-05-25 · Apollo · Lovell
GitHub Release · npm · 与上一版本比较
Fixed
- Browser command tests now isolate Windows
USERPROFILE,APPDATA, andLOCALAPPDATAalongsideHOME, so CI runner Edge profiles cannot leak into local profile discovery fixtures.
Verified
npx vitest run --project unit tests/unit/commands/browser.test.ts --maxWorkers=1 --reporter=dotnpm testnpm run verify
v0.223.2 · 2026-05-25 · Apollo · Lovell
GitHub Release · npm · 与上一版本比较
Added
Changed
- Regenerated
package-lock.jsonwith the same npm 10 resolver used by GitHub hosted runners so local and CI installs agree on VitePress/DocSearch peer dependency placement.
Fixed
npm ci --include=devnow succeeds on Node 20/22 runners that ship npm 10, unblocking the CI and Docs workflows after the 0.223.1 browser-hardening release.
Verified
npx -y npm@10 ci --include=devnpm run verifynpm run release:check -- --strict-codenamenpm run docs:build
v0.223.1 · 2026-05-25 · Apollo · Lovell
GitHub Release · npm · 与上一版本比较
Added
unicli browser doctor --jsonnow reports a delivery-orienteddefault_path, per-checknext_steprepair commands, safeself_repair.safe_command, and achrome_remote_debuggingsection for Chrome 136+ andRemoteDebuggingAllowedpolicy state.- Local browser profile discovery, explicit profile cookie export, direct Chromium cookie DB import, and user-session cookie injection now give agents multiple authenticated reuse paths without emitting raw cookie values in doctor output.
Changed
- Browser/CDP startup is background-first by default and uses Uni-CLI-owned automation profiles under
~/.unicli/, with foreground startup reserved for explicitbrowser --focus start. - Agent-facing docs and skills now route browser failures through
unicli browser doctor --json/--repairbefore falling back to lower-level browser, OpenCLI, or computer-use paths.
Fixed
- Chrome 136+ default-profile CDP failures are now diagnosed as a hard browser policy/runtime boundary instead of a transient port race;
doctor --repairstarts a non-default automation profile and refuses unsupported feature-flag bypasses. - Browser session and doctor probes stay read-only and avoid creating reusable
about:blankplaceholder tabs while checking daemon/extension health.
Verified
npm run verifytimeout 30 npm run --silent dev -- browser doctor --jsontimeout 30 npm run --silent dev -- browser doctor --repair --jsontimeout 60 npm run --silent dev -- twitter trending -f json
v0.223.0 · 2026-05-24 · Apollo · Worden
GitHub Release · npm · 与上一版本比较
Added
unicli compute capturenow creates reusable desktop context packets that combine accessibility refs, screenshot evidence, image metadata, and a replayable capture trajectory.compute capture --save-referenceand--copy-referencepersist local app-shot artifacts and copy[app-shots ...]handoff markup for agent-to-agent context transfer.- The
computer-use.captureMCP tool exposes the same capture packet and reference-save/copy path, bringing the computer-use MCP profile to 16 tools. - Core compute commands are now first-class discovery entries:
unicli search "Appshots",unicli list --site compute,unicli describe compute capture, and MCPunicli_listall surfacecompute capture. doctor compute --providersadds neutral, environment-configured discovery checks for optional external/platform provider commands and visual-model fallback configuration.
Changed
- Saved capture metadata and fallback content now externalize screenshot bytes into an image file instead of duplicating base64 in handoff artifacts, while retaining SHA-256, byte count, dimensions, and top-left image-pixel coordinate-space metadata.
- Capture reference text and metadata normalize app state for agent handoff by preserving refs while stripping geometry strings, screen ids, and raw accessibility object pointers.
- The MCP
computer-use.capturesafety annotations now reflect its optional local file and clipboard side effects instead of marking it read-only and idempotent. - The release SOP now treats GitHub Actions as the authoritative npm publish path when local npm auth is unavailable, and manual dispatch now checks out the requested release tag before publishing.
- Public compute docs now describe the capture/reference workflow, explicit
--reference-rootartifact roots, replayable capture trajectory, and the search/list/describe discovery path.
Fixed
- Repeated capture saves now generate distinct artifact directories instead of overwriting an identical prior capture.
- Clipboard-copy failures now surface structured
compute_failedenvelopes with a safe--save-referencerecovery path. - Invalid
compute capture --include ...values now fail with a structured usage error instead of silently falling back to the default parts. - Invalid snapshot formats for
compute snapshot,compute capture, andcomputer-use.capturenow fail with structured usage errors instead of silently coercing tocompact.
Verified
npx vitest run tests/unit/compute-capture-reference.test.ts tests/unit/commands/compute.test.ts tests/unit/mcp/tools.test.tsnpx vitest run tests/unit/search.test.ts tests/unit/fast-path.test.ts tests/unit/mcp/tools.test.tsnpm run typecheck- Live
compute capture --app Finder --copy-referencewith clipboard and artifact inspection.
v0.222.3 · 2026-05-24 · Apollo · Scott
GitHub Release · npm · 与上一版本比较
Fixed
- Applied
cargo fmtto native sidecar error constructors so Rust Sidecars CI format checks pass on Linux, macOS, and Windows targets.
Verified
cargo fmt --checknpm run verify:clean
v0.222.2 · 2026-05-24 · Apollo · Duke
GitHub Release · npm · 与上一版本比较
Changed
- Release metadata now points at the final 0.222.2 tag so the published package, public docs, skills, server manifest, and changelog all describe the same delivery-substrate build.
Fixed
- Restored npm lockfile entries for DocSearch's optional React peer tree so
npm ci --include=devsucceeds in CI and Docs workflows on clean runners. - Supersedes 0.222.1 as the complete published release for the closed-loop delivery substrate, because 0.222.1 was published before the lockfile repair commit reached the release tag.
Verified
npm ci --include=dev --dry-runnpm run verify:cleannpm run release:check -- --strict-codenamenpm run docs:check-public
v0.222.1 · 2026-05-24 · Apollo · Young
GitHub Release · npm · 与上一版本比较
Added
unicli delivery run <spec>executes the next evidence-gated delivery action from a delivery spec, records the underlying command through the existing run recorder, and returns the updated trajectory instead of leaving experiment execution as a separate side path.- Delivery strategy specs now accept command
args, so objective-level strategies can call the same adapter commands users already run manually. - Delivery commands are indexed by search as first-class agent capabilities:
delivery/assess,delivery/run,delivery/trajectory, anddelivery/repair-candidate.
Changed
- The delivery substrate now links objective assessment, trajectory planning, safe command execution, structured diagnosis, repair candidates, and verification history through one kernel under
src/engine/delivery/. do,extract,runs, anddeliverycommand failures now write structured error envelopes to stderr through the shared error writer while preserving JSON output for successful stdout payloads.- Public README, Chinese README, architecture docs, release metadata, roadmap pages, skills, server manifest, and generated stats now describe Uni-CLI as a self-repairing operations substrate for agents using real software.
Fixed
- Adapter health probing now respects adapter argument defaults before applying bounded smoke-test limits, preventing false negatives on commands whose required arguments are declared in the adapter.
- WeRead shelf probing uses the current sync endpoint.
- Instagram reels now fails closed under quarantine instead of pretending the retired unauthenticated route is still a reliable delivery path.
- Structured failures from delivery and run-oriented commands now surface the real envelope on stderr, which keeps agent repair loops observable.
Verified
npm run verifynpm run adapter:health
v0.222.0 · 2026-05-21 · Apollo · Armstrong
GitHub Release · npm · 与上一版本比较
Major Changes
- Uni-CLI's local computer-use stack is now a first-class compute substrate: native accessibility remains the primary semantic path, macOS can click, type, and press keys into non-frontmost windows, and visual fallback is now product-owned rather than exposed through upstream project naming.
Added
visualtransport andvisual_*pipeline steps as the owned fallback for screenshot-plus-coordinate operation across compute cascades.- macOS
desktop-axbackground input session coveringax_background_click,ax_background_type, andax_background_press, with per-process focus suppression taps, AppKit activation priming, window-addressed events, and structured success metadata such aswasFrontmostandbackgroundActivated. - Background fallback from failed semantic
AXValuewrites to scoped pid/window-addressed text input when the request includes target coordinates and does not ask to focus the app. unicli extract <url>— one-call URL → cleaned Markdown (also--as text|html) with structured envelope, configurable--max-charstruncation, and SSRF guard.unicli do <intent>— natural-language intent → top-ranked adapter plan with the agent-invocable command, args schema, and example stdin surfaced without executing ambiguous writes.
Changed
compute presson macOS now routes to pid/window-addressed background key dispatch before visual fallback when an app target is supplied and--focusis not requested.- Public exports, capability matrices, migration helpers, generated docs, MCP assets, repair references, and samples now use the
visualvocabulary. - Compute docs, focus-behavior docs, architecture docs, roadmap material, and public Markdown assets now describe native accessibility, CDP, and visual fallback as the long-lived operating model.
- Cross-platform desktop error wording now points agents toward native platform transports first and visual fallback second.
Fixed
- macOS background mouse events now use AppKit
NSEvent.mouseEventgeneration before explicit pid/window/local-coordinate stamping, filling additional AppKit routing fields that bareCGEventcreation left sparse. - Background
AXValuefallback is bounded to coordinate-scoped requests, so a failed semantic text write without a target point returns the original AX error instead of guessing where to type. - Boundary and leak checks now keep upstream project names and deprecated capability names out of product-facing source, tests, generated docs, and shipped agent assets.
Removed
- Deprecated upstream-named transport adapter, sample adapters, unit tests, and docs were removed from the public product surface in favor of the owned
visualabstraction.
v0.221.1 · 2026-05-19 · Apollo · Anders
GitHub Release · npm · 与上一版本比较
Added
unicli scholarmeta-command for academic discovery, paper lookup, PDF routing, citation traversal, reference traversal, and source doctor output.- First-source scholarly adapters for Semantic Scholar, Crossref, Unpaywall, ACL Anthology, PMLR, CVF OpenAccess, and NeurIPS proceedings.
- Unified scholarly work record types plus adapter tests covering source mapping, DOI/PDF metadata, and proceedings parsing.
Changed
- Natural-language discovery now treats category as a hard filter across Commander, fast-path search, and MCP
unicli_search, so agents can search withinscholarly,finance,social, or other verticals without mixed results. - Search intent boosts moved out of the core BM25/TF-IDF implementation into
src/discovery/intents.ts, keeping vertical routing maintainable as the catalog grows. - Scholarly routing now prefers canonical venue/source adapters for ICML/PMLR, CVPR/CVF, ACL Anthology, NeurIPS, DOI metadata, open-access PDF, and citation workflows.
Fixed
- Manifest, runtime registry, fast-path list, and MCP list/search category contracts now agree on category output and filtering.
- Hugging Face paper commands remain discoverable through
scholar.*capabilities without misclassifying the fullhfadapter as scholarly. - Stats generation preserves existing test counts when Vitest list enumeration cannot complete under local load.
v0.221.0 · 2026-05-18 · Apollo · Anders
GitHub Release · npm · 与上一版本比较
Added
- Patent search vertical: 20 site adapters across L0 keyless web, L1 free-tier APIs, L2 paid aggregators, L3 browser-driven fallback, and L4 placeholder for forthcoming public APIs. Covers USPTO ODP, EPO OPS, JPO, KIPRIS, INPI-FR, DPMA, IP Australia, Lens.org, Google Patents BigQuery, Project PQAI, PatSnap Eureka, CNIPA, Espacenet, CIPO, INPI Brasil, Rospatent FIPS, WIPO PATENTSCOPE, UK IPO, plus the two keyless web adapters Google Patents and FreePatentsOnline.
- Top-level
unicli patentmeta-command with seven subcommands:search,get,family,citations,legal-status,prior-art, anddoctor. Cross-source fan-out with family-id dedupe, reciprocal rank fusion across PQAI semantic search and Google Patents BigQuery keyword search, prefix-routed publication-number lookup, and an honesty-gated health checker that reads adapter@verificationheaders. - Public TypeScript surface at
@zenalexa/unicli/indexre-exporting nine patent types (PatentRecord,PatentCommand,PatentSearchQuery,PatentParty,PatentClassification,PatentFamilyMember,PatentEnvelope,PatentErrorCode,PatentVerificationStatus) plus three helpers (canonicalizePublicationNumber,extractKindCode,dedupeByFamily). - Four engine extensions enabling the vertical: OAuth 2.0 client-credentials broker with LRU token cache,
oauth2-tokenpipeline step,select-xmlXPath-subset step, and themcp-browsertransport with an installable resolver injection point for hosts that wire an outbound MCP client. - Patent envelope normalizer (
assemblePatentRecord,buildPatentEnvelope,dedupeByFamily,canonicalizePublicationNumber,extractKindCode) with a ten-code structured error taxonomy. docs/skills/patent-research.mdskill doc anddocs/skills/patent-cookbook.mdwith five recipes covering the day-zero keyless flow, authenticated multi-source search, cross-jurisdiction family resolution, AI-driven prior art, and the doctor pre-flight check.- Output extensions to the meta-command:
--detailed,--include-raw, and-f json|jsonl|csv|md.
Changed
- Adapter map steps across uspto, epo, jpo, kipris, inpi-fr, dpma, ipaustralia, lens, google-patents-bq, pqai, and patsnap now emit every available PatentRecord field rather than just publication number and title; per-adapter field counts roughly doubled.
Fixed
src/engine/template.ts buildScope()now bindsprocess.envinto the template scope. The pre-existing${{ env.X || '' }}idiom used by approximately 38 adapters previously resolved to undefined and short-circuited every authenticated request to an empty credential header.- Office adapter capability arrays now carry the corresponding
patent.<command>token so the meta-command's discovery filter picks them up; without the fixunicli patent doctoronly saw four of eleven HTTP adapters.
v0.220.1 · 2026-05-14 · Apollo · Lovell Patch
GitHub Release · npm · 与上一版本比较
Added
- Documented the new paper workflow: arXiv PDF download plus local
pdf readextraction for agents that need to collect, read, and summarize papers without leaving the CLI contract. - Documented ACG discovery workflows for character lookup, wiki lookup, booru tag confirmation, visual-novel catalogs, and 2024-2026 anime/game queries across AniList, Bangumi, Danbooru, E-Hentai, Moegirl, Safebooru, VNDB, and related adapters.
- Added English and Chinese recipes that show entity-first search for ambiguous names such as
花火, tag-first booru search, and Japanese / romaji / Chinese / English alias handling.
Changed
- Refreshed README, Chinese README, FAQ, and architecture docs to describe the latest 282-site, 1680-command catalog, including scholarly PDF, ACG/anime/manga/wiki, booru, and visual-novel coverage.
- Removed the stale package description count so the npm metadata no longer drifts behind generated catalog statistics.
Fixed
- Regenerated public docs,
llms.txt,llms-full.txt, and catalog indexes from the current source docs and manifest data so agent-facing references do not retain the old 268-site / 1616-command inventory.
v0.220.0 · 2026-05-12 · Apollo · Lovell
GitHub Release · npm · 与上一版本比较
Minor Changes
- 02bb048: Expand command coverage with Rednote, 1Point3Acres, travel, marketplace, AI chat, and social command surfaces plus release-signal coverage gates.
v0.219.0 · 2026-05-05 · Vostok · Gagarin
GitHub Release · npm · 与上一版本比较
Minor Changes
- 9a9b68f: Add
juejin(search, hot) andleetcode(discuss-search) adapters as public web-api commands. Both run anonymously — no cookie required. Includes fixture-based vitest coverage for all three commands. - Standardize the Uni-CLI release surface for v0.219 Vostok: archive dead adapters with public provenance, add Maven/NuGet/RubyGems/Packagist/pub.dev package registry coverage, rebuild the README and Chinese README from the live manifest, sync VitePress/public docs to generated catalog data, remove legacy MCP/SSE and yaml-runner release leaks, and make the npm package expose the root
bin/unicli-mcpwrapper plus registry metadata.
Patch Changes
- 33bafa6: Promote macOS Shortcuts and App Intent discovery into first-class runtime commands, with stable app action inventory and automation smoke probes.
v0.218.1 · 2026-05-05 · Apollo · Cernan Patch
GitHub Release · npm · 与上一版本比较
Added
unicli-mcpbin —npx -y @zenalexa/unicli-mcpboots the MCP server in one step; equivalent tonpx -y @zenalexa/unicli mcp serve. Useful as thecommandvalue in Claude Desktop / Cursor / Continue MCP configs.server.jsonMCP registry manifest at the package root, conforming to the officialhttps://static.modelcontextprotocol.io/schemas/2025-09-29/server.schema.json, so Uni-CLI can be published toregistry.modelcontextprotocol.ioand similar discovery endpoints.- Skills shipped to npm — the
unicli,unicli-browser,unicli-claude-code,unicli-explorer,unicli-hermes,unicli-oneshot,unicli-operate,unicli-repair,unicli-smart-search,unicli-usage, andtalk-normalskill packs are now in the published npm tarball undernode_modules/@zenalexa/unicli/skills/. Agents that install vianpm i -g @zenalexa/unicliget the skills without a separate clone.
Fixed
skills/unicli-hermes/SKILL.md— refreshed numbers (was 235 sites / 1,448 commands; now 237 / 3,319) and bumpedversion: 0.218.1.AGENTS.md— added the MCP one-liner config block so agents can copy-paste the JSON into Claude Desktop / Cursor without grepping docs.
v0.218.0 · 2026-05-05 · Apollo · Cernan
GitHub Release · npm · 与上一版本比较
Added
- First-class cross-platform browser cookie source (macOS / Linux / Windows) —
unicli auth import <site> --browser chrome|arc|dia|brave|edge|atlasreads cookies straight from the browser's local SQLite DB and decrypts them via the platform-native key store: macOS Keychain (securityCLI), Linux libsecret/KWallet (secret-tool, withpeanutsfallback for headless boxes), Windows DPAPI (Local Statemaster key via PowerShell, no native modules). No browser launch, no CDP, no extension. Wired as the new default middle source:~/.unicli/cookies/ → BROWSER → CDP. Successful reads persist to disk for offline reuse. Honest Windows v20 (Chrome 127+ App-Bound Encryption) handling: surfacesencryption_unsupportedand suggests CDP fallback rather than ship a brittle bypass. SetUNICLI_COOKIE_NO_BROWSER=1to skip in CI. unicli auth audit— walks every cookie/header adapter, probes each declareddomain:against every detected browser, and reports a summary ofok / no-domain / no-cookies / blockedplus per-adapter breakdown. Agent-friendly JSON with structuredsuggestionfields.unicli doctor cookies— diagnoses platform readiness: sqlite3 binary detection, installed browsers + profiles, Keychain/secret-service reachability, and platform-specific notes (Windows v20 caveat, Linux no-keyring fallback).- Adapter
domain:field is now first-class —PipelineOptions.domainis plumbed through everyrunPipelinecaller (cli.ts test, kernel, health, dev, skills) and consumed by the cookie loader. Silently fixes ~10 adapters whose naïve site→<site>.comderivation pointed at the wrong cookie store: notion (api.notion.com), perplexity (.ai), weixin (mp.weixin.qq.com), weread (weread.qq.com), twitch (.tv), linux-do (linux.do), jike (okjike.com), bluesky (bsky.app), minimax (.chat), pinduoduo (yangkeduo.com). - Parent-domain matching for cookie lookup — when an adapter declares
api.bilibili.com, the SQLite host_key filter now also matches.bilibili.comcookies (per RFC 6265), capturing parent-domain auth cookies that the previous strict matcher missed. date_isopipe filter — converts Unix epoch (seconds or milliseconds) to ISO-8601 strings inside YAML templates; returns "" for null / NaN / non-positive input rather thanInvalid Date. First user issspai/latest.yaml.- Quarantine honesty invariant test —
tests/unit/quarantine-honesty.test.tswalks every YAML undersrc/adapters/and asserts eachquarantine: trueentry carries aquarantineReasonstring with a 4-digit year, blockingquarantine: truefrom drifting into an undated kill-switch. Backfilled the 18 pre-existing quarantines with(quarantined 2026-04-15)matching the date the entries first landed.
Changed
- Lint rule
cookie-domain-required—strategy: cookie|headeradapters must declare a top-leveldomain:. Added at lint-time so the broken inference path can never come back. All 135 current cookie/header adapters already satisfy the rule (920 lint passes, 0 failures). - AGENTS.md trimmed — restated envelope shape, error-code table, site enumerations, and adapter template removed (canonical sources are
unicli describe,unicli search, the YAML files, and the project skill). Front-matter now points cold agents atunicli auth setup <site>directly when anauth_requiredenvelope arrives. - Documentation surface synced to a single source —
scripts/release.tsnow also propagates the version and codename todocs/zh/ROADMAP.md,docs/ARCHITECTURE.md, anddocs/release-info.jsonso a release leaves no stale tag pointer in any tracked surface. Build-emitted stats counts remain owned byscripts/build-readme.tsvia STATS markers.
Fixed
parsePipesnow treats both halves of||as logical-OR — the parser only looked one character ahead, so the second|of a||token got split as a real filter pipe; the base expression then contained a stray|(invalid JS, threw in vm) and the unknown filter was silently dropped, so any filter expression wrapping its condition in||returned 0 rows. The Homebrew and OpenRoutersearchadapters silently matched nothing because of this. Look back as well as forward when deciding whether a|is part of a||.evalExpressionsurfaces unknown filter names asTemplateEvalError— the previousif (!filterFn) continue;paired with an outertry { ... } catch { return undefined; }swallowed adapter-author typos. Throw a typed error instead so the pipeline executor produces a visible step error envelope. The VM eval path stays lenient (with a// REASON:line) so optional access likeitem.foo.baragainst null still returns undefined; theFORBIDDEN_EXPRsecurity gate keeps soft-rejecting (Postel: lenient at the boundary).navigatestep accepts the shorthand- navigate: <url>form — fifty-eight YAML adapters use the bare-string shorthand and previously crashed at step 0 withCannot read properties of undefined (reading 'match')because the step typedNavigateConfigonly. Sibling steps (click,press,select,wait) already accepted both forms; this bringsnavigateto parity.- sspai
hotandlatestadapters — the legacy/api/v1/articles?sort=hot|created_atendpoint returns HTTP 405/500. Switched both to/api/v1/article/index/page/get; for the hot view, fetch a wider window and sort client-side bylike_count. Thereleased_atcolumn is rendered through the newdate_isofilter instead of a raw Unix epoch. - Homebrew and OpenRouter search filter expressions — replaced the embedded
${{ args.query }}template literals (which never substituted inside a filter JS body) with directargs.queryreferences and case-insensitive matching. - Four upstream-blocked adapters quarantined with dated reasons (
quarantined 2026-05-05):pypi.search(Fastly bot-wall HTML),ctrip.hot(HTTP 502),ctrip.search(showAuthCodeCAPTCHA gate),coupang.hot(Cloudflare 403). Quarantine count 42 → 46. Future repair via the cookie strategy stays open.
v0.217.3 · 2026-05-04 · Apollo · Shepard
GitHub Release · npm · 与上一版本比较
Added
- Local computer-control surface (preview, macOS-first) —
unicli computeadds a unified app-control family for apps, windows, snapshot, find, click, type, press, scroll, screenshot, CDP attach, eval, wait, observe, and assert, backed by macOS AX (functional), Electron CDP (functional), and UIA/AT-SPI sidecar scaffolds (Windows/Linux compile-clean; live smoke pending). Treat Windows and Linux paths as preview until cross-OS smoke ships. - Computer-use MCP profile —
unicli mcp serve --profile computer-useexposes 15computer-use.*tools, prompt support, stdio e2e coverage, and action evidence metadata for direct agent desktop control. - Compute self-repair —
unicli doctor compute --json, structured remedies, troubleshooting docs, sidecar install hints, and macOS Accessibility and Screen Recording probes help recover from local-control failures. - Listing↔detail adapter lint — new cross-adapter rule
listing-detail-pairingflags any site that exposes a listing-style command (top/hot/search/feed/list/...) without a paired detail command (read/get/item/show/...). Soft warning today, 185 hits across the 920 built-in YAML adapters; opt out per adapter vialint_listing_detail: skip.
Changed
desktop-ax.tsslimmed by 21% — module-level helpers (Swift binary lifecycle + snapshot normalization) extracted to a siblingdesktop-ax-helpers.ts. Main file 1086 → 853 LOC. No behavior change; 31 unit tests stay green.
Internal
- Rust workspace bootstrapped under
crates/{unicli-shared,unicli-uia, unicli-atspi}with rust-toolchain pinned to 1.82.0 and a 6-target CI matrix (macOS/Windows/Linux × x64/arm64). - Sidecar packaging (
packages/sidecars/*) and build/publish scripts (scripts/build-sidecars.mjs,publish-sidecars.mjs) wire the optional@zenalexa/unicli-{uia,atspi}-*packages addressed at0.218.0. - Snapshot encoder + ref store gain 100/100/100/100 coverage with six golden fixtures and a perf budget project (
tests/perf/).
v0.217.2 · 2026-04-30 · Apollo · Swigert
GitHub Release · npm · 与上一版本比较
Added
- Real-time macOS automation discovery — Uni-CLI now promotes local Shortcuts and App Intents into runtime-discovered macOS commands. User shortcuts become runnable
macos shortcut-*commands, while installed app actions become searchablemacos app-action-*inspection commands. - First-class macOS action inventory —
unicli macos app-actionslists real-time Shortcuts ToolKit actions with app/query filters so agents can inspect apps such as Finder, Safari, Mail, Messages, Notes, Reminders, and WhatsApp before choosing a concrete action. - macOS automation smoke probe —
unicli macos automation-smokechecks the three local automation layers independently: Shortcuts CLI, Shortcuts ToolKit SQLite API, and AX/System Events.
Changed
unicli searchand fast-pathunicli list --site macosnow merge the static manifest with live macOS discovery results on Darwin hosts.- Generated docs and stats were refreshed for the new test coverage.
Fixed
- Dynamic macOS discovery is now guarded by platform and environment checks, has bounded subprocess timeouts, and degrades to empty structured results when Shortcuts, ToolKit, SQLite, or AX access is unavailable.
v0.217.1 · 2026-04-29 · Apollo · Haise
GitHub Release · npm · 与上一版本比较
Patch release after reviewing
v0.217.0..HEAD: docs/site refresh, approval memory, runtime deny policy, browser lease evidence, run replay, run comparison, score gates, and evidence coverage. This release bump does not update dependency versions.
Added
- Approval memory controls —
unicli approvals list,approvals revoke, andapprovals clearmanage persisted approval memory locally. - Resource-bound approvals — remembered approvals are bound to stable resource metadata such as domain, app, process family, account surface, and path argument slots.
- Explicit deny rules — local permission deny rules can block matching command scopes before
--yesor remembered approvals apply. - Runtime resource denies — fetch domains, browser targets, downloads, output paths, and subprocess executables are checked against local deny policy during execution.
- Browser lease evidence — recorded browser work now carries session lease metadata, target identity, auth posture, render-aware evidence, and guarded browser operation traces.
- Run replay and comparison —
unicli runs probe,runs replay, andruns compareadd evidence-backed replay checks, private replay payloads, numeric comparison scores, and--min-scoregates. - Run event streaming —
unicli runs stream <run_id>streams JSONL events with sequence cursors, follow mode, terminal stop handling, and the same public/internal redaction model asruns show. - Run context and evidence scoring — run traces record public environment snapshots, context check summaries, score gate output, evidence coverage checks, and
runs listevidence totals by type.
Changed
- Public docs, VitePress home page, generated Markdown, and agent-facing docs were refreshed around Uni-CLI as an execution substrate for agents.
- Runtime permission deny traces now expose only reviewable summaries in public run output while keeping raw runtime resources inside internal trace payloads.
- Replay and compare output now reports threshold gates, actual scores, failed behavior checks, failed context checks, and unknown context checks.
- Dependency maintenance that had already landed after
v0.217.0is included in this release line, but the0.217.1release commit itself only changes Uni-CLI version metadata.
Fixed
- Windows Node 20 malformed-trace scans now close the run trace input stream explicitly, avoiding a hanging Vitest worker on that path.
- Recorded run summaries now surface runtime permission deny summaries and evidence counts without forcing agents to open the full trace first.
v0.217.0 · 2026-04-28 · Apollo · Lovell
GitHub Release · npm · 与上一版本比较
Execution-substrate minor release. Uni-CLI is now positioned as the command-first layer under agents for web, browser, desktop, local tool, system, and external CLI operations.
Added
- Execution substrate surface — 235 sites, 1448 commands, 1039 adapters, 59 pipeline steps, and 7473 tests ship behind one searchable
uniclisurface. - Observable run kernel —
--record/UNICLI_RECORD_RUN=1records append-only run traces under~/.unicli/runswith permission evaluations, result envelopes, and evidence events. - Browser action evidence — recorded browser operations capture structured pre/post evidence, movement dimensions, stale-ref failure details, and optional watchdog enforcement instead of treating clicks and typing as opaque side effects.
- Operation policy contract —
--permission-profile open|confirm|locked,--yes, andUNICLI_APPROVE=1expose effect, risk, approval, and capability scope without making the default catalog private. - Agent backend matrix —
unicli agents matrixandunicli agents recommend <agent>model native CLI, JSON stream, MCP, ACP, HTTP API, OpenAI-compatible, and bridge routes explicitly.
Changed
- Public positioning now describes Uni-CLI as an agent execution substrate, not a scraper, protocol wrapper, or visual-first product.
- CLI, README, VitePress homepage, architecture, roadmap, release metadata, app manifest, and generated docs now use the same slogan and capability framing.
- Browser-backed adapter execution uses shared browser/kernel plumbing, command-level browser/auth/strategy metadata, and structured auth/rate-limit envelopes across the relevant surfaces.
- MCP, ACP, HTTP, and generated agent configs remain compatibility surfaces over the same command catalog rather than separate semantic runtimes.
- Release automation now consumes changesets, requires a final
Program · Astronautcodename before tagging, and verifies release metadata before publish workflows can run.
Fixed
- Fast-path discovery falls back to the full CLI when the generated manifest is absent and preserves
[quarantined]health warnings in list output. - Browser daemon compatibility honors the legacy daemon port environment and the response shapes used by compatible daemon implementations.
- Auth and rate-limit failures map to structured
auth_requiredand retryablerate_limitedenvelopes consistently. vercel listuses the current Vercel CLI JSON flag, anduiverse previewhandles Windows and slashless relative output paths.
Removed
- Removed stale Reddit public JSON YAML adapters and fixtures that no longer represented the live site.
- Removed the dead Meituan hot adapter after the upstream endpoint returned unrecoverable 404 responses and no reliable reference path remained.
v0.216.3 · 2026-04-27 · Apollo · Collins
GitHub Release · npm · 与上一版本比较
Fixed
- Fast-path discovery now falls back to the full CLI when the generated manifest is absent, preserving fresh-checkout behavior.
- Fast-path
listoutput keeps[quarantined]tags alongside[auth], so agents do not lose adapter health warnings. uiverse previewnow usespath.dirname()for output parent directories, avoiding Windows path and slashless relative-path edge cases.
v0.216.2 · 2026-04-27 · Apollo · Aldrin
GitHub Release · npm · 与上一版本比较
Fixed
- CI no longer requires the ignored local reference-manifest checkout for unit tests. The full parity benchmark still runs locally when the synced reference is present, while signal coverage remains validated in GitHub Actions.
v0.216.1 · 2026-04-27 · Apollo · Armstrong
GitHub Release · npm · 与上一版本比较
Changed
- Package-manager-neutral release scripts: aggregate
verify,docs:*,release,preversion, andpostversionscripts now callnpm runsubcommands, while still working when invoked throughpnpm. - Build now calls the local
prettierbinary directly instead of requiring apnpmexecutable on npm-based CI runners.
Fixed
- GitHub release/docs/verify workflows no longer fail before real validation on runners that install dependencies with
npm cibut do not havepnpmpreinstalled. - Public LLM/docs markdown assets were regenerated so published docs match the current 235-site / 1448-command release surface.
v0.216.0 · 2026-04-27 · Surface Coverage Harness
GitHub Release · npm · 与上一版本比较
Added
- Surface coverage benchmark —
pnpm bench:surface-coveragecompares the synced reference manifest against Uni-CLI's generated manifest, reports site/command gaps, and can fail CI with--fail-on-gaps. - Latest surface signal watchlist — release-signal movements for Google Scholar, Instagram, Doubao, browser upload, daemon ports, debugger-detach retry, plugin daemon docs, bind-current, browser network detail, and DeepSeek file upload are now checked as quantitative signals.
- Google Scholar coverage —
google-scholar searchnow deduplicates result cards, andgoogle-scholar cite/profileadd first-class scholarly lookup flows. - DeepSeek file uploads —
deepseek ask --file <path>uploads one or more local files before sending the prompt.
Changed
- Plugin author documentation now records the supported plugin-side browser daemon spawn pattern,
UNICLI_DAEMON_PORT, and the public daemon subpath. - Build now uses
pnpm exec prettierinstead ofnpx prettier, avoiding npm config warnings during the generated-doc pass. - Cold-start benchmarking now allows full manifest stdout and fails loudly on parse errors instead of silently returning zero counts.
Fixed
- Browser daemon commands now retry transient CDP debugger-detach failures.
- CLI fast-path execution now lets stdout flush naturally, avoiding truncated JSON for large manifest-producing commands.
v0.215.1 · 2026-04-24 · Agent Backend Matrix
GitHub Release · npm · 与上一版本比较
Added
- Coding-agent backend matrix —
unicli agents matrixandunicli agents recommend <agent>now expose a structured v2 policy matrix for core, direct, bridge, watchlist, and editor-owned coding agents: Claude Code, Codex, Hermes, Cursor, Kimi CLI, OpenCode, Gemini CLI, Qwen Code, Kiro CLI, Aider, Goose, Amp, GitHub Copilot CLI, Auggie, Crush, OpenHands, mini-SWE-agent, SWE-agent, acpx/OpenClaw, AgentAPI, MiniMax CLI, Blackbox CLI, Droid, ForgeCode, Rovo Dev, Cline, Roo Code, Windsurf, and Continue. - Agent CLI hub entries — external CLI discovery now includes verified agent-facing binaries and install hints for Claude Code, Codex, OpenCode, acpx, Hermes, Cursor Agent, Gemini CLI, Qwen Code, Kiro CLI, Kimi CLI, Aider, Goose, Amp, Copilot, Auggie, Crush, OpenHands, mini-SWE-agent, SWE-agent, AgentAPI, Droid, ForgeCode, and Rovo. Blackbox remains watchlist-only because the public npm package exposes a generic
clibin. - Reusable package export —
@zenalexa/unicli/agents/backendsexports the backend matrix and recommendation helpers for other coding-agent integrations.
Changed
- ACP is now documented as an editor compatibility gateway rather than Uni-CLI's core runtime path. Recommendations prefer direct CLI, JSON stream, MCP, or explicit API/CLI routes first for lower latency and native session semantics.
- Backend recommendations now expose
primary_protocolandexternal_cli_name, so callers can distinguish route names likeacpxorapi_clifrom the underlying protocol and install the matching external CLI registry entry. - README, AGENTS.md, roadmap, and release metadata now present v0.215.1 as the current agent-backend release line.
v0.215.0 · 2026-04-24 · Closed Adapter Loop
GitHub Release · npm · 与上一版本比较
Added
- Browser adapter authoring loop —
unicli browser analyze,browser init, andbrowser verifynow cover the legacy-style authoring path with structured v2 envelopes, schema-v2 adapter skeletons, fixture generation, fixture validation, and--strict-memorygates. - Reusable site memory under
~/.unicli/sites/<site>/: endpoint discoveries, field maps, notes, and verify fixtures are now written byexplore/generateand consumed bysynthesize/browser verify. - Network evidence replay —
browser networknow persists captured responses with stable keys and supports--filter,--detail,--ttl, and--max-bodyfor repeatable adapter investigation.
Changed
browser verifyruns adapters through the shared invocation kernel using fixture-provided args, preserves fixture args on update, and fails with the adapter's structured error when execution fails.- Browser authoring commands are split into focused modules so the top-level browser command file stays within the project file-size budget.
Fixed
- Site analysis now classifies single authenticated API failures as Pattern D, records multi-vendor anti-bot evidence instead of keeping only the first match, and emits Pattern E for websocket / event-stream surfaces.
- Fixture verification no longer produces a misleading success envelope when the adapter execution itself failed.
v0.213.3 · 2026-04-19 · Vostok · Gagarin TC0 Patch R2
GitHub Release · npm · 与上一版本比较
Closes six gaps left by v0.213.2 along the agent-invocation path: unified invocation kernel (P1), MCP/ACP/CLI surface parity (P2), output-side TC0 externalization (P3), schema-driven hardening on 71 adapters (P4), and a multi-provider agent-bench harness (P5). Bench posture was recorded in the v0.213.3 git history; empirical ASR numbers were deferred to v0.213.4 (OpenRouter credit exhausted mid-run; harness is ready, fix landed in commit
d31e72e).
Added
- Invocation kernel (
src/engine/kernel/{types,ulid,compile,execute}.ts) with monotonic ULID ids and aCompiledCommandcache primed by the loader.src/engine/invoke.tsis now a thin re-export shim. CLI / MCP / ACP all route throughbuildInvocation()+execute(); the lazy compile fallback is gone. - Schema-driven hardening in
src/engine/harden.tsviaajv+ajv-formatswithformat-assertion: true. Adapter args may declareformat:(JSON Schema draft-2020-12 formats) and a vendor extensionx-unicli-kind:ofid/path/uri/email/dateto dispatch to a dedicated validator.validateIdArgrejects URL-shaped inputs (?/#/%XXencodings,scheme://). - Output projection flags —
--select <jsonpath>(jsonpath-plus),--fields <a,b,c>,--pluck <field>(newline-sanitized for safety), and--pluck0 <field>(NUL-delimited forxargs -0).ProjectionErroron malformed JSONPath emitsUSAGE_ERROR(exit 2); empty result after projection emitsEMPTY_RESULT(exit 66). - Three-channel transport coverage —
bench/agent/sdk-runner.tsdrives any OpenAI-compatible provider via Vercel AI SDK +@ai-sdk/openai-compatibleacrossshell/file/stdinchannels, five tasks, four ICS buckets, with per-trial verdicts (asr_gen,asr_exec,asr_sem), Wilson-95 CIs, per-model + overall ship-gate thresholds, and per-trial USD cost frombench/agent/pricing.ts. scripts/migrate-add-kind.ts— comment-preserving YAML codemod (552 LOC,yamlLineCounter) that annotates 243/1355 args across 223 YAMLs withformat:+x-unicli-kind:. Idempotent (--checkexits 0 after a full pass). 30 unique override triplets were documented in the generated codemod report for that release.
Changed
runPipeline(pipeline, bag, base, opts)requires aResolvedArgsbag — no more optional default. Seven callers + 107 test sites migrated.ArgSourceextended with"internal"/"mcp"/"acp"; template scope exposessource/surface/trace_idso adapters can branch on origin.src/mcp/server.ts1061 → 174 LOC — split intodispatch.ts/tools.ts/handler.ts/http-transport.ts.src/mcp/streamable-http.ts745 → 15 LOC shim, with handlers split intostreamable-http/{index,handle-post,session}.ts.handlePostitself shrank 349 → 36 LOC.src/acp.ts700 → 523 LOC — extractedacp-helpers.ts(195 LOC) and routed through the kernel.commands/dispatch.ts296 → 251 LOC, also a thin kernel wrapper.describe.tsdocuments schema divergence — the introspection schema declaresadditionalProperties: true(permissive — agents discover by probing); the kernel validation schema enforcesadditionalProperties: false(strict — drift fails closed atINPUT_HARDENING_ERROR, exit 65). The divergence is intentional and the comment block explains the contract.
Fixed
$HOMEprefix-collision in path sandbox —validatePathArgnow ensures the resolved path is contained within$HOMErather than string-prefix-matching, so$HOME-evilno longer slips through.- Per-call ULID ordering — IDs generated in the same millisecond are now strictly monotonic via a same-ms spin-counter, so trace order matches generation order in tight loops.
- MCP health tool counts are derived from
DEFAULT_TOOL_NAMESrather than hard-coded literals; deferred-tool name collisions warn instead of silently shadowing. bench/agent/sdk-runner.tsprompt path — Run 1 (1800 trials,{unicliBin}` into all four examples and adds an explicit "absolute path required" guard line per channel stanza. Re-run deferred to v0.213.4 due to OpenRouter credit exhaustion.
Bench posture
The ship-gate (scripts/bench/check-ship-gate.js) is a recommended pre-release check, not a hard merge blocker for this patch. The TC0 thesis and the three-channel design are externally validated (Merrill & Sabharwal 2023; arXiv:2604.06742; Poehnelt 2026-03; openclaw#46370). Implementation correctness is carried by 1569 unit + 5514 adapter tests at green. Empirical ASR numbers will land in v0.213.4 once OpenRouter credit is restored.
v0.213.2 · 2026-04-18 · Vostok · Gagarin TC0 Patch
GitHub Release · npm · 与上一版本比较
Agent-invocation reliability release. Externalizes argument state out of shell quoting (a TC0-bounded mod-2 matching problem that Transformers cannot reliably generate) into JSON channels (stdin /
--args-file). Grounded in arXiv:2411.07602 (RoPE + TC0 bounds), 2502.02393 (CoT lower bounds), 2604.06742 (CLI-Tool-Bench), 2603.20847 (Claude-Code / Codex / Gemini CLI bug study) — see.claude/plans/sessions/2026-04-18-v213.2-tc0/task_plan.md.
Added
--args-file <path>global flag — every command accepts a JSON object from file. Reuse + version-controllable payloads without touching the shell. JSON only; YAML/TOML deliberately not supported.- Stdin-JSON auto-detection — when stdin is non-TTY AND the first byte is
{, Uni-CLI parses it as the argument bag. Precedence:stdin > --args-file > shell flags > positional args > defaults. Externalizes TC0-hostile quote nesting into byte-structured JSON. unicli describe [site] [command]— runtime schema introspection. Emits JSON Schema draft-2020-12 for args, a realistic example payload, the three invocation-channel templates, andnext_actionshints. Replaces stale markdown docs as the agent's source of truth (Poehneltgws schemapattern, Google Workspace CLI 2026-03).--dry-runglobal flag — resolves the ArgBag and prints the execution plan (command,args,args_source,pipeline_steps) without running the pipeline. Safe preview for mutating commands.- HATEOAS
next_actions[]in v2 envelope — every success and error response carries typed command templates (params.<name>.value / .default / .enum / .description) so agents can navigate without re-reading docs. Pattern from joelclaw.com 2026-02. - Input hardening — control-character rejection for string args, path-traversal sandbox for path-shaped args, URL-punctuation and pre-encoded-id rejection, double-URL-encoding warnings. Fails fast with
invalid_input+ directionalsuggestion(Poehnelt pattern, Google Workspace CLI). bench/agent/harness — deterministic Invocation Complexity Score (ICS, 0..10) calculator with 5 inputs: quote nest depth, backslash escapes, non-ASCII chars, arg tokens, inline JSON depth. Payload factory generates trivial / moderate / hostile / pathological buckets for 5 representative tasks.npm run bench:agentwrites a timestampedbench/agent/results.json. ASR / SED measurement via Claude SDK lives behind an opt-in flag (costs real API credits).skills/unicli-claude-code/SKILL.md— formal guide teaching Claude Code to pick the right channel per payload. The decision rule: if the payload contains quotes / emoji / newlines / JSON / is >60 chars, pipe it (stdin-JSON); otherwise shell args are fine.
Changed
src/commands/dispatch.ts— unified arg resolution — the inline Commander-to-args merging is gone; every code path now callsresolveArgs()fromsrc/engine/args.ts. One place for precedence rules, one place for type coercion.- Error envelope now includes
next_actions—defaultErrorNextActions()biases hints towardunicli repair+ stdin-JSON channel switch oninvalid_input/selector_miss/parse_error, and towardunicli auth setuponauth_required.
Fixed
- Commander arg drift — the previous inline merge silently dropped values when the same flag name appeared on the command and its parent, because positional-then-optional ordering was ambiguous. The unified resolver enumerates schema once per arg and applies precedence deterministically.
v0.213.1 · 2026-04-18 · Vostok · Gagarin Patch
GitHub Release · npm · 与上一版本比较
Patch release closing 25 documented and audited issues against v0.213.0 Gagarin GA. Semver-correct bug-fix + cleanup release; no new feature surface. See
.claude/plans/sessions/2026-04-17-v213.1-patch/findings.mdfor the full audit.
Added
DEFAULT_SURFACE+makeCtxhelpers exported fromsrc/output/envelope.ts— callers buildingAgentContextno longer need to hard-codesurface: "web"or repeat the 5-field literal. The existing 10 call sites migrate in T3 and T5-T7.
Fixed
zhihu.answersMD rendering —pickTitleinsrc/output/md.tsnow falls back toquestion→excerpt→summarybefore the generic"Item"label, so answer listings render meaningful### N · <question>headings. Adapter shapes that carry post bodies inquestion+excerpt(zhihu.answers) orsummary(certain arxiv paths) now surface that content as the row title.zhihu.answers.success.mdfixture regenerated; 2 unit tests intests/unit/output/md.test.tspin the new priority order (title > name > id > question > excerpt > summary > "Item").content[]canonical populated case battle-tested — the optionalAgentEnvelope.content[]field first shipped in v0.213.0 was never exercised end-to-end.src/output/md.tsnow renders a## Contentsection (text / image / resource blocks) when the field is populated;makeEnvelope()gained an optionalcontentargument threadingAgentContent[]through the envelope. New golden fixturetests/fixtures/md/unsplash.search.success-with-content.mdplus 3 unit tests inmd.test.ts+ 2 inenvelope.test.tspin the shape for the download-step use case ({type:"resource", uri:"file://…"}). YAML-adapter opt-in viaemit_content: trueis documented onmakeEnvelope; the runner-side plumbing to auto-populate fromdownloadstep output ships in v0.214.stats-consistency.test.tstimeout bumped 5s → 60s —computeStats()spawnsvitest list --jsontwice (one per project) after T11's rewrite, which takes ~10-25s on cold runs of this repo. The 5s default was tight from day one and timed out undernpm run verifyon slower machines. 7 sibling tests were already fast and unchanged.- Ref-Locator verification layer —
BrowserPage.snapshot()andDaemonPage.snapshot()now persist a window-level fingerprint map onwindow.__unicli_ref_identity; click/type steps plusunicli operate click/typeresolve refs against this map and throw structuredTargetError({code: "stale_ref" | "ambiguous" | "ref_not_found"}) when a ref fails to bind uniquely.executor.tsre-wraps the TargetError into aPipelineErrorpreservingdetail.codeaserrorType, anddispatch.tspasses it through verbatim to the v2 envelope'sAgentError.code. Adds diagnostics on top of our existing snapshot primitive.ref_not_foundis deliberately distinct from the HTTP-404not_foundcode so agents can tell DOM-level from server-level failures. streamable-httptest port flake fixed —tests/unit/streamable-http.test.tsnow callsserver.listen(0)and reads the OS-assigned port viaaddress().port, retiring the 5-attemptMath.random()retry loop added in v0.213.0-beta.2. Zero collision risk on busy CI runners.- Windows cold-start test timeouts bumped —
tests/unit/{exports,loader-parity,mcp-server-expanded}.test.tsnow give Windows Node 20 runners 15s instead of 5s for dynamic-import cold-start cases. Linux/macOS timing unchanged. dist/main.jsexecute bit set via postbuild hook — whennpm run buildruns,dist/main.jsis now chmod'd to 755 so it's immediately executable when extracted from the tarball. Previously mode 644; npm auto-chmods on install but manual tarball consumers had tochmod +xthemselves. Usesnode -e "require('fs').chmodSync(...)"so Windows builds are untouched gracefully.scripts/release.tsreplacement patterns refreshed — 4 of 6 patterns were stale after v0.213.0's documentation restructure, causingnpm run releaseto silently SKIP updates. Patterns for CLAUDE.md (.gitignored), the retired## Available Sites/N sites, M commandsAGENTS.md headers, and the retiredN_Sites-M_CommandsREADME badge are deleted; site/command/pipeline/test counts are now authoritative inscripts/build-readme.tsvia<!-- STATS:key -->markers. README footer codename regex updated to match the current<sub>vX.Y.Z — Codename</sub>shape.docs/ROADMAP.mdsummary version pattern narrowed toas of vX.Y.Zso STATS marker interleaving no longer blocks the match.npx tsx scripts/release.ts --dry-runnow emits 0 SKIP warnings.- Test coverage closed on 3 v0.213.0 gaps — CLI-level quarantine dispatch via subprocess spawn (
tests/unit/cli/quarantine-cli.test.tsasserts the fullprocess.exitpath — exit code 78, stderr-routed v2 envelope witherror.code: "quarantined", plus aUNICLI_FORCE_QUARANTINE=1bypass guard);format()error-wins precedence when bothctx.errorand non-nulldataare passed (non-empty array, object payload, and yaml/md output all verified to discard the data and emitdata: null);UNICLI_OUTPUTenv bare override detection whenOUTPUTis explicitly unset, plus the UNICLI_OUTPUT-wins-when-both-set path asserts no deprecation warning leaks. stats.json.test_countnow matches runtime vitest count — the regex-based counter inscripts/count-stats.tsmissedit.each([...])parametrised cases and loop-generated tests (1314 claimed vs 6921 actual across unit + adapter projects). Rewritten to enumerate vianpx vitest list --json --project=<name>per project, so parametrised and dynamic tests are counted exactly. Regex fallback (UNICLI_STATS_TEST_STRATEGY=regexor when vitest spawn fails) still ships for sandboxed environments. Accuracy now within 0% ofnpm run test+npm run test:adapterruntime output.stats.jsonregenerated —test_count1314 → 6921 now propagates through the<!-- STATS:test_count -->markers in README / AGENTS / ROADMAP / copy rules.site_countstays at 200, which matchesdist/manifest.jsontruth: the 5 extra directories undersrc/adapters/are the_electronshared-infra module (prefixed with_, never a site) plus 4 AI-chat adapters (antigravity,chatgpt,chatwise,doubao-app) that register viaregisterAIChatCommands()rather than directcli()calls. Those 4 surface at runtime (203 runtime sites) but are intentionally excluded from the manifest/stats site count until the registration pathway is unified in v0.214.
Changed
- 887 YAML adapters: duplicate schema-v2 migration banner comments coalesced — the v0.212 migration injected a banner + 5 metadata fields; the v0.213 migration re-emitted the same banner before the new
schema_version: v2line, leaving every adapter with two identical comment lines. New one-offscripts/dedupe-yaml-banner.tswalkssrc/adapters/**/*.yaml, drops the second banner in exactly the canonical duplicate shape, and is idempotent (dry-runs to 0 after a full pass). Purely cosmetic; adapter lints + 5514 adapter tests stay green. - undici stays at 8.0.2 — the 8.1.0 bump attempted in this patch calls
webidl.util.markAsUncloneablewhich does not exist in Node 20, breaking our"engines": ">=20"CI matrix. Deferred to v0.214 pending a Node 22+ engine bump. AgentError.codedocumented enum expanded 11 → 15 — addsquarantined(already emitted by the quarantine gate since v0.213.0) and the three T1 ref-locator codesstale_ref/ambiguous/ref_not_found.coderemains an open string to preserve forward compatibility.UNICLI_OUTPUTenv var is now canonical; bareOUTPUTis deprecated and emits a stderr warning. CI systems that setOUTPUTfor their own purposes (GitHub Actions step outputs, Jenkins outputs) no longer accidentally switch unicli's output format.OUTPUTwill be removed in v0.214.detectFormatsimplified — the three branches that all returned"md"(non-TTY, agent-UA, default) are collapsed into a single final return, now documented in one comment.isAgentUAno longer inspects theUSER_AGENTenv var — that variable isn't set in subprocess contexts (it's an HTTP header name, not a process env var). The 5 canonical agent env vars (CLAUDE_CODE,CODEX_CLI,OPENCODE,HERMES_AGENT,UNICLI_AGENT) remain.- Error-mapping helpers extracted to
src/output/error-map.ts—errorTypeToCode,mapErrorToExitCode,errorToAgentFields, andREF_LOCATOR_CODESnow live in one reusable module.src/commands/dispatch.tsslims by ~60 LOC; the 4-wayerr instanceofternary (repeated 7 times) collapses to a singleerrorToAgentFieldscall. - 17 admin commands migrated to v2 envelope, closing the gap documented in v0.213.0's "every command" claim. Wired:
agents,auth,eval,explore,generate,hub,lint,mcp(health/list/install/config),migrate,migrate-schema,operate,repair,research,schema,skills,status,synthesize. Combined with the 7 v0.213.0-wired sites (adapter dispatch +core.list/health/usage/search+ext.list+dev.watch), the v2 envelope contract now covers 24 command surfaces.mcp serveintentionally stays raw (stdio MCP protocol). All envelopes flow throughformat(data, columns, fmt, ctx); human-oriented chalk summaries route to stderr (Scene-6 pattern). Theoperate uploadsensitive-path / workspace-boundary deny branches also normalize to structured error envelopes now, closing the last non-envelope bypass.
Removed
health --jsonflag removed — duplicated-f json; use-f json(orUNICLI_OUTPUT=json).- Top-level
--jsonalias removed — pre-v0.213 legacy; use-f json(orUNICLI_OUTPUT=json). TheapplyJsonAliashelper and its unit test are deleted.
Breaking
unicli agents generate > AGENTS.mdno longer writes raw Markdown to stdout. Stdout now returns the v2 envelope (withdata.generatedcarrying the generated MD). Useunicli agents generate --output AGENTS.mdto write the raw file. Callers redirecting stdout to capture raw MD must migrate.
v0.213.0 · 2026-04-17 · Vostok · Gagarin
GitHub Release · npm · 与上一版本比较
GA release. Engine rigor + Agent-Native output + honest parity numbers. 195 sites · 957 commands · engine split (2810 → 298 LOC executor) · schema-v2 on 896 adapters · v2 envelope with
-f mddefault for agents · 1286 unit + 5514 adapter = 6800 tests passing.Since v0.212.1 Shatalov II the branch accumulated 46 commits across two prereleases:
- beta.1 (engine rigor): yaml-runner split into executor + registry + runtime + template + ssrf + 33 step files; 24 plugin export subpaths +
PLUGIN.md+ exports CI gate; weekly release CI cron + dependabot grouping; schema-v2 migration on 896 YAML adapters; 80 colocated adapter tests.- beta.2 (agent-native output): v2
{ok, schema_version, command, meta, data, error, content?}envelope,-f mddefault on non-TTY and recognised agent UAs,isAgentUA()detector, 7 call sites wired,src/commands/dispatch.tsextracted fromcli.ts, 20 golden MD fixtures across 10 flagship adapter pairs, quarantine envelope aligned.- GA polish:
docs/THEORY.mdv2 now cites SkillDroid (arXiv:2604.14872), MolmoWeb, IntentScore, Android Coach, Beyond Chat and Clicks — 46 refs verified against arxiv.org;PARITY_AUDIT.mdpublishes measured per-CLI numbers againstpublic-clis; Ref-Backed Locator primitive audited against the reference diagnostics set.Honest parity numbers. Measured per-CLI parity against
github.com/public-clis/public-clison 2026-04-17: 85.7% on the four core social sites (twitter 95.7%, reddit 87.0%, xiaohongshu 82.8%, bilibili 77.3%); weighted across eight messaging peer CLIs the figure is 73.5%, not 85%. Uni-CLI ships ~45 commands on overlapping sites that no peer offers (twitter trending/spaces/lists/media, bilibili live/later, xiaohongshu creator-suite, reddit rising/frontpage). Telegram (0 adapters), Discord (placeholder only), and Obsidian vault-write are explicit scope-outs deferred to v0.214. Positioning: breadth (195 sites in one binary) + self-repair + editable 20-line YAML adapters, not per-peer command parity.Ref-Backed Locator diagnostics. Snapshot-driven numbered refs, interactive-only filtering, scroll markers, iframe/shadow-DOM crossing all ship since v0.211. The verification-layer diagnostics on top — window-level fingerprint map,
stale_ref/ambiguous/not_foundstructured errors with candidate lists — are scoped for v0.213.1 (~2–3 days).Remaining v0.213 runway → v0.214 Nikolayev: workflow adapters (gmail/gcal/drive/spotify/apple-notes/imessage), Chrome extension full pipeline,
generate --verifyclosed loop, visual backend drivers, dual JS adapter format,unicli inbox,unicli shop, and the full 25-adapter compatibility harness.
Breaking
--json/--yamloutput shape changed to v2 envelope. Adapter dispatch pluscore.list,core.health,core.search,core.usage,ext.list, anddev.watchnow return{ok, schema_version: "2", command, meta, data, error, content?}. Pre-P-B flat arrays are no longer emitted from these paths; parsedatafrom the envelope. Remaining admin commands (repair,skills,hub,operate,mcp health,explore,eval,lint,status,schema) migrate in v0.214.csvandcompactoutput formats are unchanged.- Non-TTY default format is now
md, notjson. Set-f json(orUNICLI_OUTPUT=json) to restore the previous behaviour for scripts that parse stdout. tableformat deprecated and now falls back tomdwith a stderr warning.- Command naming unified to
<area>.<action>in the envelopecommandfield (e.g.core.list,ext.install,dev.watch, plus<adapter>.<cmd>for adapter dispatch). Flat command names such aslistno longer appear in envelopes.
Added
src/output/envelope.ts(184 LOC) —AgentEnvelopediscriminated union (AgentEnvelopeOk | AgentEnvelopeErr),AgentMeta,AgentError,AgentContext,AgentContent, factoriesmakeEnvelope()/makeError(), andvalidateEnvelope()with 9 structural invariants (schema_version, ok/error mutual exclusion, ok/data correlation,<site>.<command>regex, duration_ms type, content[].type enum, count/data.length consistency).src/output/md.ts(313 LOC) —renderMd(envelope)produces YAML frontmatter plus## Data/## Context/## Next Actions/## Error/## Suggestion/## Alternativessections. Handles null/undefined/Date/Buffer/Function/BigInt/circular references, shared-ref DAGs, long strings, throwingtoJSON, and unserializable values without crashing. Markdown injection sanitised at 21 insertion points.-f mdoutput format (UNICLI_OUTPUT=mdand agent-UA env vars also trigger it) with stable byte-for-byte rendering per input (golden-fixture tested).- Agent-UA auto-detection —
isAgentUA()readsCLAUDE_CODE,CODEX_CLI,OPENCODE,HERMES_AGENT,UNICLI_AGENTenvironment variables and switches output tomdwhen any is set. UNICLI_OUTPUT/OUTPUTenv var override —json|yaml|md|csv|compact, overrides auto-detection;--format/-fflag has highest priority.src/commands/dispatch.ts(299 LOC) — adapter-dispatch path extracted fromcli.ts, including envelope construction and the structured-error path (AgentError→ctx.error→ v2 error envelope to stderr witherrorTypeToCode+mapErrorToExitCodehelpers).- 20 MD golden fixtures under
tests/fixtures/md/<site>.<command>.{success,error}.mdcovering 10 flagship adapter pairs (twitter.mentions, reddit.frontpage, bilibili.dynamic, hackernews.top, github-trending.daily, arxiv.search, xiaohongshu.feed, zhihu.answers, douban.book-hot, notion.search). Regenerate withUPDATE_FIXTURES=1 npx vitest run tests/unit/output/fixtures.test.ts.
Changed
format(data, columns, fmt, ctx)now requires anAgentContextargument; TypeScript enforces it at every call site.src/cli.tsslimmed 781 → 490 LOC by moving adapter dispatch intosrc/commands/dispatch.ts; the complexity gate is green.- 7 call sites migrated to the envelope path:
core.listinsrc/cli.ts, adapter dispatch insrc/commands/dispatch.ts, plussrc/commands/{ext,usage,dev,search,health}.ts. detectFormat()order: explicit--format>UNICLI_OUTPUT/OUTPUTenv > non-TTY (md) > agent-UA (md) > md default.
Fixed
- No silent envelope bypass on empty results, chalk-styled rows,
health.json,core.usage --json, or the adapter-dispatch catch path — every surface that previously emitted raw arrays orconsole.lognow goes throughformat(). - Command regex
<area>.<action>is the only accepted shape for envelopecommand; legacy dash-case values are rejected byvalidateEnvelope.
v0.212.1 · 2026-04-16 · Vostok · Shatalov II
GitHub Release · npm · 与上一版本比较
Pre-push security and contract hardening after third-round audit.
Security
- SSRF defence on pipeline fetch —
stepFetch/stepFetchText/ HTTP transport rejectfile://,data:,gopher:schemes and private/loopback/metadata addresses (127.0.0.0/8,10/8,192.168/16,172.16–31/12,169.254/16,localhost,metadata.google.internal). SetUNICLI_ALLOW_LOCAL=1to override for local development. Tests inheritUNICLI_ALLOW_LOCAL=1via vitest config; production runs never get it. - AppleScript injection hardening —
escapeAsnow folds\r/\nto spaces and strips NUL bytes so a user-controlled app name likeCalculator"\nos_command(...)can no longer smuggle new statements pastosascript -e. - OAuth Bearer constant-time validation —
validateBearerscans every resident token withcrypto.timingSafeEqualso the timing between "no match" and "expired match" doesn't leak which prefix of a guessed token matched. Token length capped at 128 chars. - Billion-laughs + oversized YAML defense —
js-yaml.loadswitched toCORE_SCHEMA(blocks!!js/*tags) and file size capped at 256 KiB before parse. - release.yml scope tightening —
id-token: writemoved from workflow to job level; workflow-levelpermissions: {}forbids broad grants. NPM_TOKEN stays as an explicit fallback when Trusted Publishers is not yet bound.
Fixed — Contract Drift
- schema-v2 hard gate validates the full YAML, not a five-field projection — the legacy
pipeline,url,paramsfields now go through Zod too, sopipeline: "string"fails the gate (it would have crashed at runtime before). Warn mode always writes to stderr. - clipboard step names aligned — the capability matrix referenced
clipboard_get/clipboard_setwhile every handler, adapter, lint engine, and migrator usedclipboard_read/clipboard_write. Matrix renamed to match, sobus.require("clipboard_read")resolves. - Quarantine enforcement —
unicli <site> <cmd>for a command flaggedquarantine: truenow emits a structured envelope to stderr and exits-78 (CONFIG_ERROR) with aunicli repairhint. Bypass flagUNICLI_FORCE_QUARANTINE=1for debugging. - TransportBus registers all 7 transports —
HttpTransport,CdpBrowserTransport,SubprocessTransportpreviously not registered on the shared bus (capability queries lied). Now every transport is visible tobus.require. - Visual backend stub honesty — error messages now say "v0.213-deferred" explicitly and explain that a production visual backend MUST compose with a screen capture source.
VISUAL_BACKENDselects the fallback mode.
Fixed — Robustness
- migrate-schema roundtrip validation — every rewritten YAML is re-parsed and run through
validateAdapterV2before being blessed as migrated; failures are quarantined with a reason. - stepParallel concurrency cap — replaced unbounded
Promise.allwithmapConcurrent(5). - ACP prompt length bound —
parseUnicliInvocationtruncates input to 64 KiB before regex scan (ReDoS defence). - MCP SSE event IDs — every SSE frame now carries an
id:line;Last-Event-IDrequest header is accepted and logged (full replay lands in v0.213 perdocs/ROADMAP.md).
Changed
- stats.json adds
app_transport_count— 7 application-layer transports (TRANSPORT_KINDS) distinct from the 3 MCP server-side transports.pipeline_step_countnow countsCAPABILITY_MATRIXtop-level keys (54) rather thanexecuteStepswitch arms (31) — matches the spec promise of the step catalog. - verify chain expanded —
npm run verifynow runsconformance+verify:changesetsin addition to the previous 10 gates. Full network probe (adapter:health) + bibtex resolve available vianpm run verify:full. - docs/ROADMAP.md — added v0.213 deferred items covering Anthropic planner composition, Windows UIA / Linux AT-SPI napi-rs bindings, full Last-Event-ID replay, Gmail/GCal/Drive OAuth adapters.
v0.212.0 · 2026-04-15 · Vostok · Shatalov
GitHub Release · npm · 与上一版本比较
The execution layer for agent skills. Deterministic, editable, cross-vendor. 200 sites · 968 commands · 7-transport architecture · Visual · ACP · 1134 tests.
Minor Changes
e456a01: v0.212.0 "Shatalov" — the execution layer for agent skills.
Destructive architecture rewrite introducing a unified
TransportAdapterinterface over 7 transports (http, cdp-browser, subprocess, desktop-ax, desktop-uia, desktop-atspi, visual), visual fallback backend integration behind an owned interface, ACP JSON-RPC distribution for avante.nvim and OpenCode, Changesets + OIDC npm publishing, Node×OS CI matrix, schema-v2 withcapabilities/minimum_capability/trust/confidentiality/quarantinefields, and the retirement of the ~80-tokens claim in favor of measured p50/p95 benchmarks.Added
src/core/(envelope, schema-v2, registry-v2),src/transport/(TransportAdapter + 46×7 capability matrix + bus),src/protocol/(acp, skill)unicli acp— Agent Client Protocol JSON-RPC stdio serverunicli lint— schema + step validity + cycle detectionunicli migrate schema-v2— mass migration tool for existing YAML adaptersunicli mcp servenow exposes 3 transports (stdio/http/streamable)- SKILL.md cross-vendor loader discovers skills from
skills/,$HOME/.unicli/skills docs/THEORY.mdv2 — softened decidability, Bimodal Agent Capability, Trilemma, Self-Repair Search-Space Contractiondocs/refs.bibwith 25+ verified arXiv citations + CI bibtex-resolve gatedocs/BENCHMARK.md+bench/harness with measured p50/p95docs/ADAPTER-FORMAT.mdv2 and adapter migration toolingdocs/guide/integrations.mdintegration guidecontributing/per-domain guides (adapter, transport, visual, mcp, acp, release, schema, branch-protection).claude/commands/andskills/committed as cross-vendor workflow surface- Changesets workflow +
verify-changesetsCI gate adapter-health(PR-soft) +adapter-health-strict(push/nightly) gates- Nightly conformance suite with artifact upload
Changed
- Formatter rewritten:
tabledropped; addedcompactformat (newline-delimited, token-efficient) --jsonglobal flag becomes deprecation alias for-f jsonwith stderr warning- stats.json is the single source of truth for counts; CI gate enforces marker consistency across README/AGENTS.md/COPY.md/ROADMAP.md
- All GitHub Actions SHA-pinned (checkout/setup-node/upload-artifact/stale/gh-release)
- CI matrix expanded to Node 20/22 × macOS 14 × Windows × Ubuntu
- Retired "~80 tokens" claim; published honest measured-in-BENCHMARK.md decomposition
Fixed
- Conflict resolved across Phase 0+8: unified verify chain runs format:check → typecheck → lint → lint:context → build:manifest → lint:adapters → test → build → stats:check
v0.211.2 · 2026-04-13 · Vostok · Volynov
GitHub Release · npm · 与上一版本比较
Discovery engine, MCP infrastructure, self-repairing CLI for AI agents. 198 sites · 1020 commands · BM25+TF-IDF bilingual search · MCP 2025-03-26 · 855 tests.
Added
- BM25+TF-IDF hybrid bilingual search engine —
unicli search "推特热门"findstwitter trending(Top-1: 67.76%, Top-5: 81.31%). 200+ Chinese↔English alias entries, mixed-script tokenizer (B站, QQ音乐), 50KB index, <10ms queries - MCP Streamable HTTP transport — replaces deprecated SSE. Single POST /mcp endpoint, MCP-Session-Id headers, Origin validation, CORS, DELETE session termination (spec 2025-03-26)
- MCP OAuth 2.1 PKCE — authorization code flow with S256 challenge,
--authflag on HTTP/Streamable transports - MCP deferred tool loading — 4 meta-tools at ~200 tokens default, 956 lightweight stubs with searchHint for on-demand discovery (95% token reduction)
unicli searchCLI command — bilingual semantic search across all adaptersunicli_searchMCP tool — alwaysLoad, bilingual discovery for MCP clientsunicli_exploreMCP tool — renamed fromunicli_discover(backwards-compatible alias kept)- Eval suite — 214 bilingual queries measuring Top-1/3/5 accuracy across 15 categories
- Logo SVG — dark/light mode adaptive via
<picture>element - Tool annotations —
idempotentHintanddestructiveHintadded per MCP 2025-03-26 spec
Changed
- MCP protocol version — upgraded from 2024-11-05 to 2025-03-26
- Schema builder extracted —
src/mcp/schema.tseliminates duplication between server.ts and commands/schema.ts - README rewritten — compiler tagline, architecture diagram, number badges, agent integration section
- AGENTS.md — search-first instructions, MCP server documentation, version update
- Build manifest — now generates search index (
manifest-search.json) and compact catalog (manifest-compact.txt)
Security
- Codex cross-audit: 2 independent reviews, all CRITICAL findings addressed
- Streamable HTTP: Origin validation, body size limits, session management
- OAuth: single-use auth codes (60s TTL), PKCE S256 only, token expiry (3600s)
v0.210.0 · 2026-04-12 · Vostok · Komarov
GitHub Release · npm · 与上一版本比较
The compiler that turns the internet into deterministic programs for AI agents. 195 sites · 957 commands · 30 macOS system adapters · 35 external CLIs · 5 agent skills.
Added
- Error reliability system —
retryableandalternativesfields in all structured error output; agents never get opaque errors - Agent platform skills — 5 SKILL.md files (agentskills.io standard) covering 39 agent platforms
unicli statuscommand — lightweight system health JSON for agent pre-flight checks- Cloudflare remote browser —
UNICLI_CDP_ENDPOINTconnects to any remote CDP WebSocket (Cloudflare Browser Rendering, etc.) - 30 macOS system adapters — volume, dark-mode, battery, notify, clipboard, screenshot, say, spotlight, system-info, disk-info, wifi, lock-screen, caffeinate, trash, open, apps, calendar-list, calendar-create, contacts-search, mail-status, mail-send, reminder-create, notes-list, notes-search, music-now, music-control, messages-send, photos-search, finder-tags, finder-recent
- 20 new web sites — threads, deepseek, perplexity, baidu, toutiao, maoyan, futu, coinbase, kuaishou, ele, dianping, dangdang, mubu, douyu, wechat-channels, binance, ke, maimai, slock, and more
- Desktop app adapters — vscode (extensions, install-ext, open), obsidian (open, search, daily), chrome (bookmarks, tabs), zoom (join, start)
- Electron app deepening — cursor (+export, +history), discord (+delete), slack (+search, +send, +status)
- Site command deepening — zhihu +13, xiaohongshu +9, twitter +9, instagram +5, bilibili +4, youtube +3, plus 100+ commands across 40+ existing sites
- External CLI hub — kimi-cli (8K★), gws (Google Workspace), deepagents (LangChain) → 35 total
Changed
BridgeConnectionErrornow includes structured JSON with retry guidance- Non-PipelineError catch-all in cli.ts emits full structured error (was opaque
{error: message}) - AGENTS.md fully rewritten with accurate site/command counts and category listings
v0.209.0 · 2026-04-10 · Vostok · Popovich
GitHub Release · npm · 与上一版本比较
Discover, Evolve, Connect. 167 sites · 756 commands. Auto-discovery pipeline, AutoResearch self-improvement loop, Adapter Hub, 29 new adapter sites spanning AI/ML, finance, music, news, devtools, and enterprise collaboration. MiniMax MMX-CLI integration (day-0), Feishu/Lark CLI bridge, and 5 security hardening fixes from triple-review audit.
Added
- Auto-discovery engine —
src/engine/endpoint.ts(unified endpoint analysis with role-based field mapping),src/engine/probe.ts(snapshot-based interactive probing),src/engine/framework.ts(React/Vue/Next/Nuxt/Svelte/Angular detection + Pinia/Vuex store discovery),src/engine/capability.ts(12 EN+ZH goal aliases, 5 pipeline patterns: public-fetch, cookie-fetch, browser-evaluate, intercept, store-action). Builds on existingexplore/synthesize/generatecommands. - AutoResearch engine —
unicli research run <site>— Karpathy-style 8-phase self-improvement loop (precondition → review → modify via Claude Code → commit → verify via eval → guard → decide keep/discard → log). 4 presets: reliability, coverage, freshness, security.unicli research logandunicli research reportfor history and aggregation. Stuck detection at 5 consecutive discards with escalating hints. - Adapter Hub —
unicli hub search/install/publish/update/verify— git-based community adapter registry via GitHub API (olo-dot-io/unicli-hub). Install adapters from hub, publish via PR. - Test generator —
unicli test-gen generate <site>auto-generates Vitest tests from eval files.unicli test-gen citests only adapters changed in current commit. - Multi-harness AGENTS.md —
unicli agents generate --for cursor|codex|goose|genericgenerates harness-optimized discovery files. - MCP discover tool —
unicli_discoverexposed as MCP tool in expanded mode. URL → explore → generate, callable from any MCP client. - Auto-eval generation —
unicli generatenow auto-createsevals/smoke/<site>.yamlwhen installing a new adapter. - Response caching —
cache: <seconds>field onfetchpipeline step. Cached to~/.unicli/cache/with 10MB per-entry limit. - Strategy fallback —
fetchstep auto-retries with cookie injection on 401/403 responses. - 29 new adapter sites — minimax (chat, models, tts), feishu (send, docs, calendar, tasks), gitlab (trending, search), netease-music (hot, search), techcrunch (latest), theverge (latest), nytimes (top), cnn (top), sspai (latest, hot), ithome (news), infoq (articles), eastmoney (hot, search), mastodon (trending, search), twitch (top), openrouter (models), huggingface-papers (daily), replicate (trending, search), ycombinator (launches), gitee (trending, search), crates-io (search), pypi (info), homebrew (info), npm-trends (compare), docker-hub (search), cocoapods (search), unsplash (search), pexels (search), exchangerate (convert), ip-info (lookup), qweather (now), itch-io (popular), meituan (search), pinduoduo (hot).
Security
- Shell injection prevention in research engine — all scope pattern resolution uses Node
readdirSync(no shell).runVerifyandrunGuarduseexecFileSync("unicli", [...args])instead ofsh -c. Site names validated against/^[a-zA-Z0-9_-]+$/. - Hub path traversal prevention — site/command names validated in all subcommands (install, publish, verify).
execFileSyncwith args array instead of shell interpolation. - MCP HTTP loopback binding — HTTP transport explicitly binds to
127.0.0.1, not0.0.0.0. - Probe ref validation — CSS selector injection prevented by
/^\d+$/check on snapshot refs. - Cache size limit — 10MB per-entry cap prevents disk exhaustion from oversized API responses.
- Claude Code tool restriction — research engine uses
--allowedTools "Read,Edit,Glob,Grep"(no Write, no Bash).
Changed
- All adapters always visible —
detect:field is informational only, does not gate adapter registration. Desktop adapters appear inunicli listregardless of whether the binary is installed. Runtime errors give clear install instructions. agents generatemulti-format — new--forflag generates Cursor Rules, Codex-optimized, Goose recipe, or generic markdown formats.generateauto-eval — installing an adapter viaunicli generatenow auto-creates a smoke eval file.
v0.208.0 · 2026-04-08 · Vostok · Titov
GitHub Release · npm · 与上一版本比较
Standards, Distribution, and Self-Improvement. 134 sites · 711 commands. Skills export, hardened MCP gateway, eval catalog,
observe()verb, and sensitive-path deny list.Post-release hardening: a 4-reviewer audit of the initial release commit (
a1e75cb) surfaced 6 BLOCKERs and 9 MAJORs. All were fixed in5e6237fbefore the tag was cut — the release-facing SHA. See the "Post-release audit (5e6237f)" section below for the full list.
Added
unicli skills export(deliverable A) — auto-generates one Anthropic-spec SKILL.md per adapter command intoskills/.unicli skills publish [--to ~/.claude/skills/uni-cli/]copies into a Claude/Cursor skills directory.unicli skills catalogwrites the canonical machine-readable manifest atdocs/adapters-catalog.json.scripts/generate-catalog.tsships as the build-time entry point.unicli mcp serve(deliverable B) — production-ready MCP gateway. Default expanded mode auto-registers one tool per adapter command (unicli_<site>_<command>) with input schemas derived fromargsand output schemas fromcolumns. Lazy mode (--lazy) preserves the v0.207 2-tool surface. New--transport http --port 19826adds JSON-RPC overPOST /mcpfor self-hosted environments.unicli mcp healthis the offline pre-flight check.unicli eval(deliverable C) — declarative regression suites. 15 starter eval files ship underevals/: 12 smoke (hackernews, bilibili, github, reddit, weibo, zhihu, xiaohongshu, douyin, youtube, twitter, instagram, linkedin, hupu, douban, producthunt) + 3 regression (auth-rotation, selector-drift, api-versioning). Subcommands:eval list,eval run [--all],eval ci --since 7d. Output format:SCORE=N/Mplus structured JSON for CI.- Per-call cost ledger (deliverable D) — append-only JSONL at
~/.unicli/usage.jsonlcapturing{ts, site, cmd, strategy, tokens, ms, bytes, exit}for every CLI invocation.unicli usage report [--since 7d] [--slow] [--failing]aggregates by site+cmd with median, p95, error rate, and bytes. Opt out withUNICLI_NO_LEDGER=1. unicli operate observe <query>(deliverable I) — Preview verb. Snapshots the page, ranks interactive elements against the natural-language query (token overlap, exact label, role/aria bonuses), returns{action, ref, selector, confidence, reason}candidates. Caches every observation to~/.unicli/observe-cache.jsonlfor self-healing audits.- 8 strategic adapters (deliverable F) —
hermes,openharness,motion-studio,stagehand,godot,renderdoc,autoagent,visual. +14 commands total. - AgentLint integration (deliverable E) —
scripts/lint-context.shruns Agent Lint against the workspace and gatesnpm run verifyon context quality. Default threshold 60/100, override withUNICLI_LINT_THRESHOLD. Disable withUNICLI_LINT_DISABLE=1. - Documentation (deliverable H) — maintenance and integration docs now live in
docs/reference/maintenance.mdanddocs/guide/integrations.md.
Security
- Sensitive path deny list (deliverable J) —
src/permissions/sensitive-paths.tsblocks access to sensitive paths (.ssh,.aws/credentials,.gnupg,.kube/config,.docker/config.json,.npmrc, cookie/credential files). Enforced inunicli operate uploadand theexecpipeline step. Returns structured error JSON on stderr.
Changed
- MCP server default mode —
unicli mcp servenow boots in expanded mode (one tool per adapter command). Lazy mode (the v0.207 default) is opt-in via--lazy. The existingtests/unit/mcp-server.test.tswas updated to spawn with--lazyto preserve the 2-tool contract; newtests/unit/mcp-server-expanded.test.tscovers the expanded surface. npm run verify— chainslint:contextbetweenlintandtest. Soft-skips when Agent Lint is not installed.recordUsagecli.ts hook — every dynamic site command writes a ledger entry on success, empty result, pipeline error, and generic error.
Post-release audit (5e6237f)
A 4-reviewer parallel audit (plumbing / runtime / security / release-wiring) over a1e75cb identified 6 BLOCKERs and 9 MAJORs. All fixed in commit 5e6237f before the v0.208.0 tag was cut. The numbered list below is the authoritative record for anyone tracing "what did v0.208 change beyond its own release notes."
BLOCKERs fixed:
Shell injection in 4 new adapter YAMLs.
hermes/skills-read,hermes/sessions-search,openharness/memory-read,renderdoc/capture-listusedbash -cwith${{ args.* }}raw-interpolated into the script body. The template engine emitsString(value)with no shell quoting, so a crafted arg likefoo"; printf OWNED; #escaped the string literal. Fix: rewrote all bash adapters to pass user input via environment variables (UNICLI_NAME,UNICLI_TOPIC,UNICLI_QUERY, etc.) and reference them as"$VAR"bash literals. Added path-traversal rejection (case globs for..and/) where the name flows into a file path. PoC was verified by Codex against the live engine.SQL injection in
hermes/sessions-search.yaml.${{ args.query }}was spliced into the FTS5MATCHandLIKEclauses. Verified againstsqlite3 :memory::query=hello' UNION SELECT '999','888','PWN' --returned the injected row. Fix: the env-var rewrite above plus bash${UNICLI_QUERY//\'/\'\'}parameter expansion to SQL-escape single quotes.LIMITclause strips non-digits via${UNICLI_LIMIT//[^0-9]/}.Eval runner shell injection in
src/commands/eval.ts.runCase()usedexecSyncwith a string-concatenated command line, so positional values with spaces, quotes, or shell metachars were reinterpreted. Fix: replaced withspawnSync(executable, argv). AddedparseCliCommand()to handleUNICLI_BIN="npx tsx src/main.ts"dev invocations without reintroducing shell parsing. Theeval ci --sincegit log call was also converted fromexecSynctospawnSync, and--sinceis now regex-validated before being passed to git.Pre-existing: dist-mode loader could not see YAML adapters.
src/discovery/loader.tssetBUILTIN_DIR = join(__dirname, "..", "adapters")which resolves todist/adaptersin built mode, buttscdoes not copy YAML files — only.js+.d.ts. Compounding this,collectTsFilesmatched.d.tsdeclaration files viaextname(file) === ".ts"and imported them as empty ES modules, silently inflating the TS adapter count to 81 while registering zero commands.node dist/main.js doctorreportedSites: 0. This bug existed since v0.1.0 but was dormant until the package was first published to npm in v0.207.1 (commit607cedb). Fix: newfindAdapterDirs()resolves the YAML directory to whichever candidate (src/adaptersordist/adapters) actually contains.yamlfiles — works in dev, production builds, and global npm installs.collectTsFilesnow auto-detects the entry-point extension (.tsin dev,.jsin built mode) by probing the first site directory, and explicitly excludes.d.ts,.d.ts.map,.js.map,.test.ts,.test.js. Post-fix verification:node dist/main.js list --format json | countreturns 134 sites / 711 commands, matching src mode.unicli operate observeranker was blind to attributes.src/browser/snapshot.tsemitted raw refs as{ref, tag, text}butscoreCandidateinsrc/browser/observe.tsawarded confidence forroleandaria-labelbonuses. Interactive elements with empty text (search boxes with onlyaria-label) were dropped at confidence 0 inrankCandidates. Tests passed because they constructed fake refs with attrs. Fix: refactoredgetAttrstocollectAttrsreturning an object bag; each interactive ref now carries{ref, tag, text, attrs}so the ranker's role/aria-label logic actually fires in production.MCP expanded-mode dispatch broken for hyphenated command filenames.
buildToolNamenormalizes non-alphanumeric chars to_, buthandleExpandedToolattempted to reverse the normalization by trying to splitunicli_<site>_<command>at adapter-name prefixes and look upadapter.commands[strippedSuffix]. Command file names preserve hyphens (skills-list.yaml→skills-listkey), so the reverse lookup never matched. Every v0.208 new command (skills-list,capture-list,component-get,scene-export,project-run,sessions-search,skills-read,memory-read,eval-run,bench-list,bench-run,frame-export,wrap-observe) was unreachable via MCP. Fix:buildExpandedToolsnow builds aMap<toolName, {adapter, cmdName, cmd}>at tool-list time andhandleExpandedTooldoes a single O(1) lookup. Collision detection writes shadow warnings to stderr. Regression test asserts all 5 representative hyphenated names appear in the registered tool list.
MAJORs fixed:
Symlink bypass —
operate uploadand the exec pipeline step used string-based guards.ln -s ~/.ssh/id_rsa /tmp/pretty.txtdefeated the check. Fix: newmatchSensitivePathRealpath/isSensitivePathRealpathfollow the symlink viarealpathSyncbefore matching, with a graceful fallback to string-only checking on broken symlinks. Both callers switched.Pattern coverage — 9 new credential paths:
.pgpass,.netrc(+ Windows_netrc),.wgetrc,.my.cnf, Azure CLI (accessTokens.json,azureProfile.json), GitHub CLI (hosts.yml), 1Password CLI (~/.config/op/), rclone (rclone.conf).Case-insensitive filesystem bypass (macOS/Windows) —
/Users/x/.SSH/id_rsaslipped past the case-sensitive regexes. Fix: newnormalizeForMatch()lowercases the path on Darwin and Win32 before matching; POSIX paths stay case-sensitive.eval run --allabsolute-path branch was broken.f.path.includes(\/${target}/`)produced//tmp/evals/smoke/for absolute targets and never matched. **Fix:** two-branch logic: relative names matchf.relativeprefix, absolute paths matchf.pathprefix afterresolve()`.Version residue in
AGENTS.md,docs/ROADMAP.md,contributing/COPY.md— still said0.207.1 — Vostok · Gagarin. Updated.Missing
docs/adapters-catalog.json— the CHANGELOG promised a canonical machine-readable manifest but the generator was never run. Rantsx scripts/generate-catalog.ts→ 134 sites / 711 commands / 467KB JSON. Committed.Denial error shape mismatch —
operate uploademitted top-level{error: "sensitive_path_denied", ...}while the exec step wrapped the denial inPipelineError.detail.config.denialwitherror = "exec blocked: sensitive_path_denied". Agents pattern-matching the canonical identifier had to handle two shapes. Fix: exec step now throwsPipelineError("sensitive_path_denied", ...)sotoAgentJSON()surfaces the same top-level identifier. Denial path + pattern inlined intoconfig.denial_path/config.denial_pattern.
Known limitations (not fixed in v0.208):
detect:YAML field is loader decoration — parsed but never executed. Adapters that rely ondetectfor registration gating do not currently self-disable on machines missing the binary. Moving this to a realexistsSync/statSyncprobe is deferred to v0.209 because changing the loader semantics could introduce surprising adapter warnings in existing installs.
Test-count delta: 753 → 769 (26 → 40 sensitive-paths tests after adding case-insensitive, extended pattern, and symlink realpath suites; 5 → 7 MCP expanded tests after adding hyphen registration + dispatch coverage).
Fixed
- Node 20 compatibility: replaced
node:fsglobSync(Node 22+) with manual glob implementation in repair engine - Shell injection prevention: all
execSyncstring interpolation in repair engine replaced withexecFileSync+ argument arrays; site/command names validated against[a-z0-9._-]pattern - Lower-direction metric: verify failures now return
Infinity(not0) fordirection: "lower", preventing broken commits from being kept as improvements - CDP flat session protocol:
sessionIdnow placed at top-level of JSON-RPC envelope (not insideparams), fixing multi-tab recording - Interceptor data pipeline: JS interceptor now captures HTTP method, status code, and request body — enables write candidate detection (POST/PUT/PATCH) in
unicli record - Diagnostic crash prevention:
parseDiagnosticvalidates parsed JSON shape before cast, preventing TypeError on truncated payloads - DaemonPage network capture:
startNetworkCaptureandreadNetworkCapturemethods added to DaemonPage, enabling CDP-first path inunicli operate
Security
- JWT full redaction: entire JWT token replaced with
[JWT-REDACTED](previously only signature was redacted, leaking payload claims) - Upload path boundary:
operate uploadnow blocks paths outside workspace and home directory - Bracket-notation param redaction:
token[],auth[token]etc. now matched by sensitive param filter - Body redaction depth limit: recursive
redactBodycapped at 50 levels to prevent stack overflow
Changed
- Failure classifier: 404 status only classified as
api_versionedwhen URL contains API path pattern; generic 404 falls through tounknown extractPerfectScorecached from first successful verify output instead of re-running verify command each iterationsafeRevertusesgit reset --hard HEAD~1directly instead of creating noisy revert commitsisNoiseUrlnow correctly filtersfacebook.comdomain (was dead code with/trpath in hostname check)endpointSortKeyuses first array item's key count for wrapped responses like{data: [...], total: N}explore.tsuses real interceptor method/status data instead of fabricatingGET/200- Record and explore request capture arrays capped at 10,000 entries to prevent OOM
- Record polling has re-entrancy guard to prevent overlapping captures
extractMetricresetslastIndexbefore exec for global/sticky regex safetyEvalJudgetype changed to discriminated union for type-safe value accessoperatestring escaping usesJSON.stringifyinstead of hand-rolled replace chainstemplatizeUrlskips duplicate query parameters
v0.207.0 · 2026-04-06 · Vostok · Gagarin
GitHub Release · npm · 与上一版本比较
Added
- Self-Repair Loop:
unicli repair <site> [cmd] --loop— Karpathy-style autonomous adapter repair with failure-type-aware prompting (selector_miss, auth_expired, api_versioned, rate_limited). 8-phase loop: review → classify → modify (Claude Code) → commit → verify → guard → decide → log. Stuck hint escalation at 3/5/7/9/11 consecutive discards. - Eval Harness:
unicli repair --eval <file>— run evaluation suite with 4 judge criteria (contains, arrayMinLength, nonEmpty, matchesPattern). OutputsSCORE=N/Mfor metric extraction. - Endpoint Analysis Module:
src/engine/analysis.ts— shared boolean filters (isNoiseUrl,isStaticResource,isUsefulEndpoint) + transparent sort key (endpointSortKey) replacing opaque numeric scoring. - Record Multi-Tab: CDP
Target.setDiscoverTargetsfor cross-tab network capture, write candidate generation (POST/PUT/PATCH replay), URL parameter templatization (query →${{ args.query }}), request deduplication. - Explore Interactive Fuzzing:
unicli explore --interactive— click buttons, tabs, and anchors to trigger additional XHR endpoints. iframe re-fetch for empty-body GET JSON endpoints. - Operate CDP-First Network:
operate openpre-navigation capture,operate networkprefers CDPreadNetworkCapture()with JS interceptor fallback.
Changed
- Endpoint scoring replaced: numeric
scoreEndpoint()→ boolean filter cascade (isNoiseUrl→isStaticResource→isUsefulEndpoint) +endpointSortKey([itemCount, fieldCount, isApiPath, hasParams]) endpoint-scorer.tsrewritten as thin facade re-exporting fromanalysis.tssynthesize.ts: removed--min-scoreparameter, usesisUsefulEndpoint()instead
Security
- Diagnostic redaction: JWT signature stripping (Cloudflare har-sanitizer pattern), sensitive header/URL param/body key redaction, 3-level size degradation (128KB/192KB/256KB cap)
redactUrlhandles relative URLs safely,redactBodyhas circular reference protection (WeakSet guard)isNoiseUrlmatches against hostname only (not full URL string), preventing false positives from query parameters
Fixed
- RegExp matching in analysis: noise domains checked against hostname, capability patterns against pathname only
- Record URL templatization preserves URL auth credentials and port numbers in dedup keys
- Record generates correct YAML args shape (mapping, not list) matching loader expectations
- Repair engine: correct metric comparison for
direction: 'lower', scope file re-resolution after Claude modifications
v0.206.0 · 2026-04-05 · Vostok · Tereshkova
GitHub Release · npm · 与上一版本比较
Added
- Adapter Generation Engine:
unicli explore <url>(API discovery),unicli synthesize <site>(YAML candidate generation),unicli generate <url>(one-shot explore+synthesize+select) — complete adapter generation pipeline with endpoint scoring algorithm - Browser Enhancements: DOM settle detection via MutationObserver, network body capture with
startNetworkCapture/readNetworkCapture, navigate withwaitUntil: networkidle, click with x/y coordinates, interceptor regex patterns + text capture + multi-capture - Diagnostic Engine:
RepairContextmodule — full error context with DOM snapshot, network requests, console errors, and adapter source for AI agent self-repair. Triggered viaUNICLI_DIAGNOSTIC=1 - Plugin System v1: Custom step registration (
registerStep), manifest-based plugin loader (unicli-plugin.json),unicli plugin install/uninstall/list/create/stepscommands - Agent-Native Primitives:
assertstep (URL/selector/text/condition),extractstep (structured browser data extraction with CSS selectors and type coercion),retryproperty on any step with exponential backoff - Smart Cookie Refresh: Auto-detect 401/403 on cookie/header adapters → navigate Chrome → re-extract cookies via CDP
- Infrastructure: HTTP proxy support (
http_proxy/https_proxy/no_proxyvia undici), update auto-checker (24h cache, non-blocking),unicli health [site](adapter health monitoring),unicli agents generate(AGENTS.md auto-generation) - New Sites (8): linkedin, jd, weixin, reuters, barchart, 1688, smzdm, sinablog — 26 new adapter commands
- Operate Enhancements:
operate upload <ref> <path>,operate hover <ref> - Pipeline Steps: assert, extract → 30 → 35 total (including retry as a cross-cutting property)
Changed
- Pipeline engine:
SIBLING_KEYSextended withretry,backoff;executeStepdefault case checks plugin custom step registry fetchJsonandstepFetchTextnow use proxy agent when proxy env vars setBrowserPage.goto()uses DOM settle detection (MutationObserver) instead of simple setTimeout- CLI startup: non-blocking update check + plugin loading before hook emission
v0.205.0 · 2026-04-05 · Vostok · Bykovsky
GitHub Release · npm · 与上一版本比较
Added
- Pipeline: 7 new steps —
set,if/else,append,each,parallel,rate_limit, plusfallbackproperty (23 → 30 steps) - CDP Direct Mode: Zero-extension browser auth — direct CDP connection, smart cookie extraction, auto-launch Chrome
- Self-Repair: Level 1 auto-fix (detect
selector_miss, suggest alternative paths), Level 3 community-fix stub - Bridge CLIs: 19 new bridges — vercel, supabase, wrangler, lark, dingtalk, hf, claude-code, codex-cli, opencode, aws, gcloud, az, doctl, netlify, railway, flyctl, pscale, neonctl, slack
- DX:
unicli init(adapter scaffolding),unicli dev(hot-reload),unicli adapter install/list(marketplace) - Documentation: VitePress site with DESIGN.md theme (Geist Mono + Terminal Green), 7 content pages
- Browser:
unicli browser cookies <domain>,--profile,--headlessoptions - Infrastructure: npm publish config, rate limiter module, cookie extractor module
Changed
acquirePage()now prioritizes direct CDP over daemon (CDP → daemon → auto-launch)- Cookie loading now transparently falls back to CDP extraction from Chrome
- Pipeline engine refactored:
executeStep()helper,getActionEntry()+SIBLING_KEYS
Security
- Path traversal guard on cookie
saveCookies()andloadCookies() - Port validation for
UNICLI_CDP_PORTenvironment variable - Recursion depth limit (max 10) for nested
ifandeachsteps
v0.204.0 · Vostok · Nikolayev
GitHub Release · npm · 与上一版本比较
Engine Core (Sub-Project A)
- 6 new pipeline steps — press, scroll, snapshot (DOM a11y tree), tap (Vue Store Bridge), download (HTTP+yt-dlp), websocket (OBS auth)
- 9 new BrowserPage methods — insertText, nativeClick, nativeKeyPress, setFileInput, autoScroll, screenshot, networkRequests, snapshot, closeWindow
- 9 new pipe filters — slugify, sanitize, ext, basename, keys, json, abs, round, ceil, floor, int, float, str, reverse, unique (total: 29)
- VM sandbox migration — replaced
new Function()with hardenedvm.runInNewContext()(null-prototype, frozen built-ins, 50ms timeout) - Dual interceptor — fetch + XHR monkey-patching with WeakMap anti-detection stealth
- Stealth upgrade — 6 → 13 anti-detection patches (CDP cleanup, Error.stack filter, Performance API, iframe chrome consistency)
Daemon + Browser Bridge (Sub-Project B)
- Browser daemon — standalone HTTP+WS server (port 19825), auto-spawn, 4h idle timeout, CSRF protection
- DaemonPage — IPage implementation over daemon HTTP (reuses Chrome login sessions)
- Chrome extension — Manifest V3 service worker, workspace isolation, command dispatch via chrome.debugger
operatecommand — 16 interactive browser subcommands (open, state, click, type, keys, scroll, screenshot, eval, network, etc.)recordcommand — capture network requests and auto-generate YAML adapters- Shell completion — bash, zsh, fish tab completion
- Daemon-first page acquisition — yaml-runner tries daemon before direct CDP
Electron App Control (Sub-Project C)
- 8 Electron apps — Cursor, Codex, ChatGPT, Notion, Discord, ChatWise, Doubao, Antigravity
- 66 commands via shared AI chat pattern + per-app specialization
- App registry — auto-discovery, CDP port assignment, user-extensible via ~/.unicli/apps.yaml
New Web Sites (Sub-Project D)
- +39 sites, +293 commands — xiaohongshu (13), douyin (13), instagram (19), tiktok (15), facebook (10), amazon (8), boss (14), pixiv (6), hupu (7), xianyu (3), ones (11), notebooklm (15), doubao-web (9), lesswrong (15), gemini (+2 deep-research), yollomi (12), and 13 more P2 sites
- Existing site gaps filled — xueqiu fund-holdings, hupu mentions
Desktop Expansion (Sub-Project E)
- FreeCAD 2→15 commands, Blender 4→13, GIMP 3→12
- 13 new apps — OBS Studio (8, WebSocket), Zotero (8), Audacity/Sox (8), Krita (4), Kdenlive (3), Shotcut (3), MuseScore (5), CloudCompare (4), WireMock (5), AdGuardHome (5), Novita (3), Sketch (3), Slay the Spire II (6)
Ecosystem (Sub-Project F)
- Plugin system —
unicli plugin install/uninstall/list/updatewith GitHub/local sources - Lifecycle hooks — onStartup, onBeforeExecute, onAfterExecute (globalThis singleton, sequential execution)
Security
- Shell injection fix in plugin.ts (execFileSync replaces execSync)
- Path traversal prevention (plugin name validation + startsWith guard)
- JS injection prevention in operate commands (ref validation, JSON.stringify selectors)
- VM sandbox hardening (null-prototype, frozen built-ins, contextCodeGeneration restrictions)
- Tap step sanitization (identifier regex for store/action names)
- Fetch concurrency cap (mapConcurrent with limit=5)
- Network buffer cap (500 entries max)
Metrics
| Metric | v0.203.0 | v0.204.0 |
|---|---|---|
| Sites | 57 | 96 |
| Commands | 289 | 582 |
| Pipeline steps | 17 | 23 |
| Pipe filters | 14 | 29 |
| Stealth patches | 6 | 13 |
| Tests | ~137 | 2272 |
v0.203.0 · Vostok · Leonov
GitHub Release · npm · 与上一版本比较
Engine — Browser Strategy
- CDP client — raw WebSocket Chrome DevTools Protocol, zero new runtime dependencies
- BrowserPage — goto, evaluate, click, type, press, cookies, scroll, waitForSelector
- Chrome launcher — auto-discover/start Chrome with
--remote-debugging-port - Stealth injection — anti-detection evasions (webdriver, plugins, permissions, toString)
- 6 new pipeline steps — navigate, evaluate, click, type, wait, intercept
- Strategy cascade — auto-probe PUBLIC → COOKIE → HEADER
- CLI:
unicli browser start,unicli browser status
Web Adapters — Write Operations
- twitter: +15 write commands (post, like, reply, follow, unfollow, block, unblock, bookmark, unbookmark, delete, hide-reply, download, article, accept, reply-dm) — total 25 commands
Web Adapters — Platform Expansions
- jike: +9 (create, like, repost, comment, search, notifications, post, topic, user)
- douban: +6 (subject, top250, marks, reviews, photos, download)
- weibo: +4 (feed, post, search, user)
- weread: +4 (book, highlights, notebooks, notes)
- zsxq: +3 (dynamics, search, topic)
- reddit: +7 (comment, read, save, saved, subscribe, upvote, upvoted)
- linux-do: +8 (categories, category, feed, search, tags, topic, user-posts, user-topics)
- xueqiu: +8 (stock, fund-snapshot, comments, feed, watchlist, search, hot-stock, earnings-date)
- medium: +2 (feed, user)
- producthunt: +3 (browse, posts, today)
- sinafinance: +2 (news, stock)
- 36kr: +3 (article, hot, search)
- v2ex: +2 (daily, user)
- substack: +2 (feed, publication)
- imdb: +2 (person, reviews)
- bloomberg: +1 (news), google: +2 (search, trends), bilibili: +1 (dynamic), zhihu: +1 (download), tieba: +1 (read)
Infrastructure
- Manifest builder includes TS adapter metadata
- Browser module: cdp-client.ts, page.ts, launcher.ts, stealth.ts
- 119 unit tests (was 42)
Stats: 57 sites, 289 commands (was 203 — +86 commands, +77 tests)
v0.202.0 · Vostok · Tereshkova
GitHub Release · npm · 与上一版本比较
Engine
- Cookie authentication strategy — reads cookies from
~/.unicli/cookies/<site>.json - Cookie injection in fetch/fetch_text pipeline steps (strategy=cookie)
write_temppipeline step for desktop adapters (temp file creation + auto-cleanup)authCLI commands:auth setup,auth check,auth list- Async TS adapter loading via dynamic import (loadTsAdapters)
PipelineOptionsfor passing site/strategy context to pipeline engine
Web Adapters — Chinese Platforms (3 new sites, 18 commands)
- bilibili: 12 commands (hot, ranking, feed, following, me, history, favorites, search, user-videos, comments, subtitle, download) — WBI signed + cookie auth
- weibo: 5 commands (hot, timeline, profile, comments, me) — cookie auth
- zhihu: 6 commands (hot, feed, question, search, me, notifications) — cookie auth
Web Adapters — International (2 new sites, 15 commands)
- twitter: 10 commands (search, profile, timeline, bookmarks, trending, likes, thread, followers, following, notifications) — GraphQL + Bearer token + cookie auth
- youtube: 5 commands (search, video, channel, comments, transcript) — InnerTube API
Web Adapters — P1/P2 Sites (8 new sites, 19 commands)
- douban: 3 commands (movie-hot, book-hot, search)
- xueqiu: 2 commands (hot, quote)
- linux-do: 2 commands (hot, latest) — Discourse API
- jike: 1 command (feed) — GraphQL
- zsxq: 2 commands (groups, topics) — cookie auth
- medium: 1 command (search)
- sinafinance: 2 commands (rolling-news, stock-rank)
- Expanded: v2ex (+2: notifications, me), weread (+1: shelf), tieba (+2: search, posts), reddit (+1: comments)
Desktop Adapters (2 new apps, 5 commands)
- gimp: 3 commands (resize, convert, info) — Script-Fu via exec stdin
- freecad: 2 commands (export-stl, info) — Python via write_temp + exec
Infrastructure
authCookiesfield in adapter manifests for declaring required cookiesStrategyre-exported from registry.ts for TS adapter pattern- Manifest builder now includes TS adapter metadata (regex extraction from source)
- Fixed
sync:refscript to use--rebasefor divergent branches
Stats: 57 sites, 203 commands (was 43 sites, 141 commands — +14 sites, +62 commands)
v0.201.0 · Vostok · Chaika II
GitHub Release · npm · 与上一版本比较
Engine
- POST JSON body template resolution in fetch steps
- Exec stdin pipe for desktop tools (mermaid, pandoc, jq)
- Exec environment variables and file output support
- HTML-to-Markdown conversion step via turndown
- Retry with exponential backoff for fetch steps (429/5xx)
Web Adapters (12 new sites)
- tieba, 36kr, substack, producthunt
- google (suggest, news), imdb (search, title, top, trending)
- web/read (HTML to Markdown), ctrip, paperreview, spotify
- xiaoyuzhou expanded (episode, podcast-episodes)
Bridge Adapters (4 new tools, 16 commands)
- gh (repo, issue, pr, release, run)
- docker (ps, images, run, build, logs)
- yt-dlp (download, info, search, extract-audio)
- jq (query, format)
Desktop Adapters (10 new apps, 36 commands)
- ffmpeg expanded to 11 commands (probe, trim, gif, etc.)
- imagemagick (convert, resize, identify, composite, montage, compare)
- pandoc (universal document converter)
- libreoffice (headless convert, print)
- mermaid (diagram rendering via stdin)
- inkscape (SVG export, convert, optimize)
- blender expanded (info, convert, animation)
- musescore (export, convert)
- drawio (diagram export)
- comfyui (generate, status, history, nodes)
Stats
- Sites/apps: 21 → 43 (+22)
- Commands: 74 → 141 (+67)
- Engine steps: 9 → 10 (html_to_md)
- Unit tests: 18 → 27
v0.200.0 · Vostok · Chaika
GitHub Release · npm · 与上一版本比较
1961 — First human in space. Yuri Gagarin orbited Earth in 108 minutes.Chaika (Seagull) — Valentina Tereshkova's call sign. First woman in space.
Engine
- Pipe filter system: 15 filters (join, urlencode, truncate, strip_html, slice, replace, split, first, last, length, trim, default, lowercase, uppercase)
- RSS/XML parsing:
fetch_text+parse_rsspipeline steps - Desktop exec:
execstep with json/lines/csv/text output parsing - Sort step:
sortwith by/order - Resilient loader: skip malformed YAML gracefully
Self-Repair Architecture
- Structured pipeline errors: JSON with adapter_path, step, action, suggestion
unicli repair <site> <command>— diagnostic + fix suggestionsunicli test [site]— smoke test runner- User adapter overlay:
~/.unicli/adapters/overrides built-in (survives updates)
Adapters (21 sites, 74 commands)
New sites: lobsters (4), stackoverflow (4), bluesky (9), devto (3), dictionary (3), steam (1), bbc (1), wikipedia (4), arxiv (2), apple-podcasts (3), hf (1), bloomberg (9), v2ex (7), weread (2), xiaoyuzhou (1) Completed: hackernews (8/8), reddit (8/8) Pre-existing: github-trending (1), ollama (1), blender (1), ffmpeg (1)
Infrastructure
- Build manifest: auto-generated dist/manifest.json
- Version bump: 0.100.1 → 0.200.0
v0.100.1 · Sputnik · Kedr
1957 — The first artificial satellite. First signal from orbit. Proof that it works.Kedr (Cedar) — Gagarin's call sign. The very first patch.
Added
- YAML pipeline execution engine:
fetch,select,map,filter,limit - 5 adapter types:
web-api,desktop,browser,bridge,service - TypeScript adapter support via
cli()registration helper - Multi-format output:
table,json,yaml,csv,md - Auto-detection of piped output (switches to JSON for AI agents)
- Adapter discovery from
src/adapters/and~/.unicli/adapters/ - Exit codes following
sysexits.hconventions - Positional and option argument parsing from YAML adapter definitions
Adapters (6 sites, 8 commands)
- hackernews:
top,search— web-api, public - reddit:
hot,search— web-api, public - github-trending:
daily— web-api, public - blender:
render— desktop (requires blender) - ffmpeg:
convert— desktop (requires ffmpeg) - ollama:
list— service (requires ollama at localhost:11434)
Agent Integration
- Agent Skills:
unicli-usage,unicli-explorer,unicli-operate,unicli-oneshot - AGENTS.md for cross-agent discoverability (Codex, Copilot, Cursor, OpenCode)
- CLAUDE.md for Claude Code integration
- MCP server stub for universal agent connectivity
Community
- Apache-2.0 license
- CODE_OF_CONDUCT.md, GOVERNANCE.md, CODEOWNERS
- Issue templates: bug report, feature request, adapter request
- CI workflow: Node.js 20/22 matrix on Ubuntu
- Aerospace theme system: contributing/COPY.md
- Full release label rules: docs/reference/release.md