Implements hybrid-custody NEAR key management where the agent holds scoped
function-call keys for routine operations while high-value operations require
explicit user approval through the existing channel approval flow.
Core infrastructure:
- Ed25519 key generation/import via ed25519-dalek (not near-crypto)
- AES-256-GCM encrypted storage via existing SecretsStore
- Hand-rolled borsh-serializable NEAR transaction types
- NEP-413 intent signing and MPC chain signature support
- Configurable policy engine with transaction analysis pipeline
- Daily spend tracking with automatic midnight UTC reset
- Encrypted backup/restore with Argon2id KDF
- CLI subcommands: generate, import, list, info, remove, export, policy, backup, restore
- NEAR ed25519 secret key leak detection (Critical/Block)
- WASM sign-payload host function (keys never enter WASM memory)
- KeyManager wired into AgentDeps for agent-wide access
Security invariants: private keys never reach the LLM or WASM boundary,
signing happens in host Rust code with Zeroize on drop, every transaction
is analyzed before signing, most-restrictive policy rule wins.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
* Start working on improved CLI
* Add tool result previews, boxed approval card, and polished help screen
REPL iteration 2: styled /help with grouped sections, box-drawing
approval card with colored params, dim separator before responses,
inline tool output previews via new StatusUpdate::ToolResult variant.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
---------
Co-authored-by: Claude Opus 4.6 <[email protected]>
- Fix MCP tool schema deserialization: rename input_schema to match
protocol's camelCase inputSchema, so models receive actual parameter
schemas instead of empty defaults
- Fix conversation history: add tool_calls field to ChatMessage and
include assistant message with tool_calls before tool results, as
required by OpenAI-compatible APIs
- Fix approval loop: pass resume_after_tool flag to run_agentic_loop
so the "force tool use" heuristic doesn't re-trigger after approval
- Fix shutdown: add Submission::Quit, Ctrl+C signal handler, and
graceful shutdown flow
- Fix MCP activate button: auto-attempt auth flow when activation
fails due to missing authentication
- Add inline approval cards in chat via SSE ApprovalNeeded events
- Add markdown rendering in chat (marked.js) with proper streaming
- Add structured fields to log entries (key=value pairs from tracing)
- Collapse log entries to single line with click-to-expand
Co-Authored-By: Claude Opus 4.6 <[email protected]>
Auth mode: when a tool requires an API key, the thread enters a special
mode where the next user message is routed directly to the credential
store, bypassing logs, turns, history, and compaction entirely. This
prevents tokens from leaking into debug output or persistent storage.
Fix MCP auth: auth_mcp now actually uses the token parameter (was
ignored as _token) and falls back to manual token entry when OAuth
and DCR are both unsupported.
Parallel loading: WASM tools, WASM channels, and MCP servers now load
concurrently at startup. Within each loader, individual items also
load in parallel (join_all for WASM, JoinSet for MCP servers).
Co-Authored-By: Claude Opus 4.6 <[email protected]>
- Add dedicated "heartbeat" target in memory_write tool so the LLM
routes HEARTBEAT.md writes to the database instead of the filesystem
- Update tool description to clarify it's database-backed storage
- Broadcast heartbeat notifications to all channels when no explicit
notify target is configured, instead of silently logging them
Co-Authored-By: Claude Opus 4.6 <[email protected]>
The heartbeat feature was dead on arrival: nothing ever created HEARTBEAT.md,
so the runner silently skipped every cycle. Now the workspace returns an
in-memory seed template when the file doesn't exist in the database (no DB
write), and the runner detects "effectively empty" content (headers, HTML
comments, bare list markers) to avoid wasting LLM API calls on placeholder
templates. The user creates the real DB entry via memory_write when they
actually want periodic checks.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
Thread message metadata through Channel::send_status so WASM channels
can route status updates (like typing indicators) to the correct chat.
The WasmChannel spawns a background task that repeats on_status every
4 seconds to keep Telegram's typing bubble alive until the response
is sent.
Co-Authored-By: Claude Opus 4.6 <[email protected]>
- Add escape_telegram_markdown() to handle underscores in tool names
(e.g., build_software was breaking Telegram's Markdown parser)
- Use Telegram-compatible *bold* syntax instead of **bold**
- Clarify workspace memory vs filesystem tool descriptions to prevent
LLM from using read_file on memory_tree paths
- Update build_software to strongly prefer Rust WASM for agent tools
- Rewrite WASM tool template to use Component Model with wit_bindgen
instead of outdated extern "C" approach
Co-Authored-By: Claude Opus 4.5 <[email protected]>
Remove the brittle natural language pattern matching from the router
and add job management tools to the normal tool registry instead.
- Add job tools: create_job, list_jobs, job_status, cancel_job
- Router now only handles explicit /commands
- Natural language goes through agentic loop with all tools
- LLM naturally picks appropriate tools based on user intent
- Share ContextManager between job tools and Agent
Co-Authored-By: Claude Opus 4.5 <[email protected]>
The test expected "Can you create a website for me?" to route as CreateJob,
but the extract_intent logic intentionally requires explicit job creation
patterns (containing both "create" and "job") to avoid capturing general
conversation as job requests.
Updated test to verify:
- "create job: ..." routes to CreateJob
- Messages with both "create" and "job" route to CreateJob
- General requests without explicit "job" fall through to Chat
Co-Authored-By: Claude Opus 4.5 <[email protected]>
This commit addresses three critical issues from code review:
1. Tool approval enforcement: Tools declaring requires_approval() (shell,
http, file write/patch, build_software) now gate execution. Adds
PendingApproval struct, session-scoped auto-approved tools set, and
approval flow with yes/no/always commands.
2. Tool definition refresh: Tool definitions now refresh each iteration
in both chat and job loops, so newly built tools become visible
immediately within the same session.
3. Worker tool call handling: Changed respond() to respond_with_tools()
when select_tools returns empty, properly executing tool calls instead
of formatting them as text.
Also includes prior work from the plan:
- Wire embeddings provider (OpenAI + NEAR AI) to workspace
- Load workspace system prompt (identity files) into LLM context
- Route heartbeat notifications through channel manager
- Enable auto-context compaction when threshold exceeded
- Refactor to config structs (AgentDeps, WorkerDeps, LlmCallRecord)
- Fix clippy warnings (saturating_sub, too_many_arguments)
Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Add HeartbeatConfig for proactive periodic execution with channel notifications
- Add use_planning option to Worker for ActionPlan generation before tool execution
- Implement tool failure tracking in database (V3 migration)
- Add auto-repair via Builder for broken WASM tools in self_repair.rs
- Record tool failures in Worker for self-repair tracking
- Update .env.example with new configuration options
Co-Authored-By: Claude Opus 4.5 <[email protected]>
- Add StatusUpdate enum with Thinking, ToolStarted, ToolCompleted, StreamChunk, Status variants
- Add send_status method to Channel trait (default no-op)
- Implement send_status in TuiChannel to show status in UI
- Add send_status to ChannelManager for routing to specific channels
- Update handle_message to send "Processing..." status for Chat/CreateJob
- Update handle_chat to send "Generating response..." and show errors
Now when a user sends a message, they see feedback that the agent is working.
Co-Authored-By: Claude Opus 4.5 <[email protected]>
When the TUI quits (Ctrl+D twice), it now:
1. Sends a "/shutdown" message through the channel before closing
2. Explicitly drops msg_tx to ensure channel closure
The agent loop now:
1. Returns Option<String> from handle_message (None = shutdown)
2. Handles /quit, /exit, /shutdown commands by returning None
3. Breaks out of the main loop on shutdown signal
4. Lists /quit in help menu
Co-Authored-By: Claude Opus 4.5 <[email protected]>
Persist jobs and actions to PostgreSQL using fire-and-forget pattern:
- Scheduler passes store to Worker, persists cancellations
- Worker persists job status changes and tool execution actions
- Agent persists new jobs on creation
- All DB writes use tokio::spawn to avoid blocking execution
Store remains optional to preserve --no-db mode.
Co-Authored-By: Claude Opus 4.5 <[email protected]>