Changelog
Release notes and version history for TRW. Track how the operating layer, memory engine, and delivery tooling evolved over time. This page covers shipped releases only, so it stays a reliable history instead of turning into a speculative roadmap.
Latest versions
TRW does not have one product-wide version number. The framework protocol (the phases, gates and evidence rules agents follow) is versioned on its own, and each package carries its own semantic version. The two move independently: a new trw-mcp major is a new major version of the MCP server package, not a new version of TRW as a whole, and the protocol can change without any package changing its major version. Each release below is labelled with the exact package versions it shipped.
v27.5
Framework protocol
8.0.0
trw-mcp
5.0.0
trw-memory
0.34.0
platform
These are the in-repo development versions of each package, and they can sit several releases ahead of what is published. The installer (install.sh) and pip resolve the most recent release published to PyPI — that, not the numbers above, is what you actually get, and the release timeline below covers published releases only. Run pip index versions trw-mcp to see what is installable right now.
Releases
Half the instruction context, evidence you can hand to a reviewer, and handoffs that close
- About half the instruction context on every client: one renderer now builds every client's instructions, and reference material an agent needs only now and then moved to on-demand surfaces. Claude Code goes from 3,421 to 1,713 tokens, Codex from 3,269 to 1,527, OpenCode from 2,937 to 1,452 and Cursor from 4,018 to 2,309, with every per-turn rule kept.
- A governance evidence pack: `trw-mcp run evidence-pack` exports what a run recorded (requirements, evidence receipts, decisions and the delivery verdict) as one redacted, tamper-evident file. Recognized secret patterns, the project path and the home directory are redacted before anything is digested, and an absence it cannot prove is reported as unknown, never as a clean result. Review a pack before sharing it outside your team.
- A requirement drift guard on `trw_deliver`: each PRD's approved acceptance criteria are read back from git history, so a weakened criterion or a requirement that lost its evidence is reported at delivery. Safety-critical PRDs block until the change is recorded as an amendment; others warn.
- Handoffs that close: a peer now accepts a request, reports completion with a pointer to what to read next, and only the requester records it complete, all through `trw_inbox`. A READY is no longer mistaken for a verified completion.
- Upgrade (trw-mcp 8.0.0 + trw-memory 5.0.0): Python 3.11 or newer is required. Install trw-memory 5.0.0 first, then trw-mcp 8.0.0, run `trw-mcp update-project`, and if you use formations run `trw-mcp formation comms-upgrade` once per mailbox. The full list of breaking changes is in the trw-mcp 8.0.0 changelog.
Four fixes from the 7.0 final review
- Upgrade: `pip install -U trw-mcp trw-memory`, then restart the MCP server and the memory daemon.
- A scoped `trw-mcp code index --paths <files>` update no longer drops out-of-scope files that changed since the last full build. Each out-of-scope file is rechecked by path, so an edited file stays searchable and a removed or no-longer-eligible one leaves the index; a brand-new file outside the scope still needs an unscoped `trw-mcp code index` run.
- `trw-mcp instructions sync --dry-run` now writes nothing. In 7.0.0 a dry run still rewrote several client instruction files and other project files while reporting a preview; it now previews only, though it still reads the learning stores, as every sync does.
- `memory_verify` now reports `error` or `skipped` truthfully. A sweep that could not complete cleanly, or had no project root to check, used to answer `status: ok`; it now says so, with the reason, so a verify result can be trusted at a glance.
- `trw-memory import` no longer turns an exported store's system canary rows into ordinary entries: it skips and counts them, and the destination store keeps its own canaries.
Fewer tools, better tool picks, and a safer memory store
- Better tool picks: 51 MCP tools became 15, with 13 on by default. In our tool-selection eval, the first TRW call was the right one 73% of the time on Claude Code, up from 30%, and 80% on Codex, up from 0%.
- Upgrade (trw-mcp 7.0.0 + trw-memory 4.0.0): Install both together, stop the old memory daemon, run `trw-mcp update-project --ide <id>` and `trw-mcp models fetch`, reconnect your MCP clients, then run `trw-mcp doctor`. Removed tools have no aliases: most became a mode of a tool that stays (`trw_code` now does code search, symbol lookup and before-edit hints) or a `trw-mcp` command, and five were deleted. `TRW_OFFLINE` is removed. Native Windows is not supported in this release: the installers and the memory daemon stop right away with a pointer to WSL2, where TRW runs as it does on Linux.
- Fixed: Two data-integrity bugs from earlier trw-memory releases, both present in 2.x and 3.x. Permission hardening released SQLite's locks, so a store shared by two processes could be corrupted. Separately, lock contention on a brand-new store was treated as corruption, so its first writes could be lost. If you ran an earlier release, run `pragma integrity_check` on your stores and look for `memory.db.corrupt.*.bak` files.
- Fixed: Recall no longer crashes on a default install (`NameError: BM25Okapi` in 2.0.0, 3.0.0 and 3.1.0). A memory daemon that crashed (seen on macOS, in Metal) no longer leaves every client unable to start a new one, and models now run on CPU on macOS.
- Bounded reviewer lanes: A dispatched reviewer (Claude or Codex) gets only `trw_recall` and `trw_code` from TRW and none of your other MCP servers or ChatGPT apps. A Claude reviewer's own tools are only Read, Grep and Glob.
- Faster and lighter: trw-mcp keeps one session open to the memory daemon, so `trw_session_start` p95 fell from 718–856 ms to 390–462 ms on one machine. The MCP server no longer loads torch or an embedding model; the daemon does dedup, consolidation and re-embedding.
- Safer network: Models download only when you run `trw-mcp models fetch` or the installer, never at runtime, and the default embedding model is pinned to one revision. No embedding vector leaves your machine. Your platform key goes only to the official platform host or hosts you trust in your user-level config, and `platform_contact_enabled: false` turns off the update check and team sync.
Embeddings by default, and the installer migrates for you
- Upgrade (trw-mcp 6.1.0 + trw-memory 3.1.0): `sqlite-vec` is now a base dependency of both packages, so vector storage no longer needs an extra, and the `[vectors]` extra is gone. musl Linux (Alpine) and Windows ARM are unsupported: `pip install` fails there instead of silently falling back to keyword-only recall.
- Upgrade (trw-mcp 6.1.0): The installer now installs `trw-memory[embeddings]` and caches the configured recall model; pass `--no-embeddings` to stay keyword-only. `--sqlite-vec` and `--no-sqlite-vec` are removed. If a project’s `.trw/memory/memory.db` still holds learnings, it runs `trw-mcp memory migrate --to user --apply` and prints the rollback command. `--no-migrate` opts out.
- New: `trw-mcp doctor` and `session_start` report retrieval capability: vectors, embeddings, model weights and BM25 as `active`, `degraded` or `off`, with a one-line fix for anything degraded.
- Fixed: Recall works offline. With `TRW_OFFLINE` or `HF_HUB_OFFLINE` set and the model not cached, recall, store and consolidate fall back to keyword search instead of failing, and recall says so in its `dense` field.
- Fixed: An I/O error during the store’s integrity check (Python 3.11+) no longer quarantines a healthy store; it retries, then opens with a warning. A daemon that fails to start is stopped, and its reason goes to `daemon-start.log`.
- Fixed: Hooks read JSON with `python3` when `jq` is missing, so edit tracking and the deliver gate work without it. Recall no longer multiplies scores by cached backend weights, a reward remnant 6.0.0 missed.
One memory store per machine, and trw_assess
- Upgrade (trw-mcp 6.0.0 + trw-memory 3.0.0): Memory now lives in one store per machine under `~/.trw`, served by a background daemon, and each project reaches it through its own namespace. After upgrading, run `trw-mcp update-project`. If it prints `trw-mcp memory migrate --to user --apply`, run that from the project, then reconnect every MCP client. Without `--apply` it only reports what it would move; `--rollback <manifest>`, run with the daemon stopped, undoes it.
- Upgrade (trw-mcp 6.0.0): `trw_decision` is renamed `trw_assess` with no alias, and `trw_learn_update` is removed (call `trw_learn(learning_id=...)` instead). `trw_recall`, `trw_build_check` and `trw_review` take their less-common parameters in one `options` mapping. An old tool name or keyword now returns an error instead of being ignored.
- Upgrade (trw-memory 3.0.0): The store format upgrade is one-way. 3.0.0 opens a 2.0.0 store, but 2.0.0 cannot open a store created under 3.0.0, so export first if you might roll back. Recall ranking no longer uses reward feedback; a learning's base score decays with how often it is recalled.
- New: `trw_assess` can now be switched on from a project's own config; it stays off by default. When it is on, clients that take skills get a short `trw-assess` skill that suggests it at decision points.
- Changed: Recall no longer runs on every phase change. `trw_session_start` runs one recall when a session starts.
- Fixed: Late in a long session, tool responses were cut to their first 500 characters by a compression layer that expected JSON. That layer is deleted, so every response reaches the caller in full.
Formation membership changes and safer learning merges
- Upgrade (trw-mcp 5.0.0): The collaboration mailbox format changed, so every member of a formation must run the same major version. Stop each member, then run `trw-mcp formation comms-upgrade` once per formation. Pending formation slots are no longer first-come: create them with `open_join: true` or admit a member with `trw-mcp formation admit`. Install `jq`: without it, hook event records lose their detail fields.
- Upgrade (trw-memory 2.0.0): The `recall_rerank`, `recall_rerank_min_score` and `recall_rerank_min_keep` settings are removed. Recall always re-ranks, and how many top results it keeps scales with the limit you ask for. A leftover setting logs a warning and is ignored.
- New: Grok is an installable client (`--ide grok`) with its native MCP config, `AGENTS.md` and bundled agents. Start grok from the project root, since the launcher path it writes is relative, and trust the project folder in grok itself.
- Changed: Formations accept members after they are created, and sessions can announce themselves and be admitted in any order. Collaboration tools are on by default but do nothing outside a formation; set `comms_enabled: false` to hide them.
- Fixed: Merges and consolidation no longer drop learning content or archive protected entries.
- Security: The new `trw_decision` advisory helper stays off unless an operator enables it. Its optional Jev backend is set only from your process environment, talks only to `https://openrouter.ai`, and scrubs credentials and secret-named fields before anything leaves the machine.
Opt-in collaboration and a new embedding model
- Upgrade (trw-mcp 4.0.0 + trw-memory 1.0.0): The default embedding model changes. Existing knowledge stays available to keyword search, but semantic results are partial until vectors are re-embedded. TRW MCP migrates in bounded background batches. Standalone memory users can run `trw-memory reembed --namespace <ns>` for each namespace, or call `await client.reembed()`.
- New: Opt-in collaboration lets active agent sessions exchange messages and wait briefly for replies. Messaging is pull-based, so it does not wake an idle agent. Collaboration settings are off by default; the package README covers setup and opt-out.
- New: Dispatch can optionally give supported child sessions their own TRW connection. Reviewer restrictions and existing launch safeguards stay in place.
- Changed: Review guidance now separates confidence in a finding from its impact. This is a prompt correction; no accuracy gain was measured.
Working macOS hooks and hybrid recall by default
- New: A `memory_maintain` tool runs decay, consolidation and a checkpoint for one namespace on demand. Decay is keyed on namespace and id, so it can no longer touch a same-named entry in another namespace.
- Changed: Memory recall is hybrid by default. Keyword and meaning matches are fused, re-ranked by a cross-encoder and bounded by confidence, so recall returns fewer answers instead of padding the list with noise.
- Fixed: Pre-edit hint hooks now fit their time limit on macOS: the per-edit import went from 2.0 s to 0.19 s against a 2.5 s budget. Hook deadlines no longer depend on GNU `timeout`, which macOS does not ship.
- Fixed: The delivery gate reads evidence of your changes on every client profile. On the six profiles other than Claude Code it was measuring zero edits and letting work through on that basis.
- Fixed: `trw-memory` picks its SQLite engine by version, with the `pysqlite3` path behind an opt-in `[sqlite-fix]` extra, so arm64 Linux installs again. Importing the package is also lazy: 1.25 s down to 0.12 s per interpreter.
- Fixed: `update-project` no longer deletes a skill you keep in your own repo. A retired bundled name is removed only with proof that TRW wrote it.
Plan review and memory that survives transient failures
- Upgrade (trw-mcp 3.0.0): The experimental `sprint-team` and `team-playbook` slash commands are retired. File ownership, formations and the bundled team agents are unchanged and remain the way to divide work.
- New: Plan review lets an agent put a plan up, have a second agent review it against its own checks, and know whether the plan it is working from is still the one that was approved.
- New: Agents working in different tools can pass work to each other directly. This is off by default and turns on only when you choose.
- Changed: A leaner install. Unused framework adapters are removed, and with them two dependency paths that carried security advisories with no available fix. Published packages no longer ship internal working documents.
- Fixed: Two places where a passing hiccup could discard saved memories are closed. A transient failure is now treated as a failure to retry, never as permission to discard what you had already saved.
- Fixed: A safety check that was reporting all-clear without looking now actually looks, and says so plainly when it cannot.
Cross-model review runs and health checks can warn
- Fixed: Cross-model review now runs. The second opinion dispatches another coding-agent CLI you already have installed, read-only, instead of reporting on every call that no reviewer was reachable, and it names a client you have.
- Fixed: A reviewer that could not be reached, ran out of time, or answered with something other than findings is reported as exactly that, never as a clean review that found nothing.
- Fixed: The WAL health check could not warn at any file size, because the failure it watches for kept refreshing the signal it used as corroboration. It now measures whether a checkpoint caught up with the write backlog.
- Fixed: When a WAL cannot be reclaimed, because of an older SQLite engine or peers holding the store open, the checkpoint result says which and names the remedy.
- Fixed: The connectivity row no longer reports a machine as fully offline while it is talking to the platform. It names the host it will reach and says separately that it did not probe it.
- Fixed: Requesting access to a masked tool now tells the agent it can call that tool immediately, instead of directing it to a reconnect only a human can perform.
Complete project upgrades and immutable releases
- Changed: Published versions are immutable. The release pipeline refuses to overwrite a version already served to users and verifies every publish through the same download path the installer uses.
- Fixed: Upgrading an existing project refreshes hooks, skills, agents and instruction files instead of only swapping the package underneath them.
- Fixed: Re-running the installer keeps your proprietary packages current too, and in-place `pipx` or `uv` upgrades keep vector search enabled.
- Fixed: When an instruction file cannot be updated, the installer says so instead of reporting success. The memory daemon documentation now matches how the daemon actually starts.
Vector search by default and faster recall
- New: A doctor row and a heartbeat field flag a server burning CPU in the background, and one signal dumps every thread stack to a log with no debugger or elevated permissions.
- Changed: Vector search is on by default for every install path, with no extras to remember and no silent fallback to keyword-only recall.
- Changed: Learnings anchor to the code the session actually touched, and recall no longer re-verifies stale anchors on the hot path. A representative recall dropped from 9.7 s to 2.5 s.
- Fixed: Fresh installs pass their own integrity check, first-run diagnostics no longer raise false alarms, and importing the package never touches your working directory.
Dependency advisories closed and CPU embedding fallback
- Fixed: When the GPU is busy, the embedding model falls back to CPU instead of leaving recall without embeddings for the session.
- Security: 53 dependency advisories are closed across the optional extras. The runtime dependency set was never affected.
Namespace-keyed memory and typed formations
- Upgrade: Memory rows are keyed on `(namespace, id)`, so two namespaces can never collide in one store. This release requires `trw-memory` 0.16 or newer.
- New: A multi-agent formation is one validated artifact: file ownership, PRD assignment, join, status and brief in single calls, and a delivery gate that waits for every teammate.
- New: Dispatch reaches seven coding assistants through one typed capability registry, which refuses any client whose capabilities were never verified against its real CLI.
- New: Boot emits a five-phase timeline and the doctor reports memory-engine health, so a slow start or a stuck store can be diagnosed in one command.
- Changed: Review verdicts expire, cross-model review must be proven with a digest-matched receipt, read-only reviewers are bounded to inspection tools, and safety-critical work cannot ship without an independent adversarial audit.
- Changed: Dead flags, an unreachable tool mode and four inert hooks are removed.
Namespace identity and a loopback memory daemon
- Upgrade: Every row is identified by `(namespace, id)`. Reads and deletes name the namespace they mean, with no ambiguous default.
- New: You can run `trw-memory` as an authenticated loopback daemon, optionally with every namespace in one store per user. stdio stays the default.
- Changed: A learning marked verified must carry evidence, assertions or anchors.
- Changed: 0.16.1 is the version that reached PyPI. The 0.16.0 tag never published and carries no separate changes.
- Fixed: Concurrent servers upgrade a store exactly once, a warm embedding cache makes no network call, and remote model code runs only behind an explicit opt-in.
Review receipt bypass and hook security fixes
- Fixed: An audit put the seven days to 2026-07-30 (421 commits, 231 new source files) to ten reviewers, with a second reviewer told to refute each finding. 27 survived. Each fix was verified by reverting it and watching its test fail.
- Security: A session could mint an "independent" review receipt for its own work. The run-claim check compared run ids but never sessions, so any session that called `trw_init` twice could name its spare run id and pass with `identity_verified=True`.
- Security: The opt-in pre-edit hook executed model-controlled input as Python, a critical issue fixed in 1.0.2. The hook defaults off, which bounds exposure but does not remove it.
- Security: The Cursor secret-scan gate advertised `failClosed` but emitted allow on macOS. The fix landed in 1.0.2, but the hook copier only refreshed a script when the destination was absent, so existing installs kept the pre-fix copy until 1.0.4.
Injection gate bypass and ungated write paths closed
- Fixed: Five write surfaces reached storage without passing the security gate at all. They now go through it.
- Security: The injection gate skipped every pattern for code-flagged entries, and the flag comes from caller-supplied content. A nine-character code prefix plus a newline let a prompt-extraction payload store cleanly and return verbatim on recall. That bypass is closed.
Tool arguments move into structured parameters
- Upgrade: The tool-call contract changes. Rarely set arguments move into structured parameters: `trw_learn` goes from 24 flat arguments to 10 plus `metadata`, `trw_learn_update` from 20 to 10 plus `fields`, `trw_init` from 13 to 7 plus `advanced`, and `trw_review` from 10 to 7 plus `reviewer_identity`. Unknown keys inside them are rejected instead of dropped. Pin `trw-mcp<1.0` if you emit arguments by hand.
- Upgrade: Five arguments are removed outright because they accepted a value and did nothing with it: `trw_recall(shard_id)` and `trw_learn(run_path, team_origin, expires, shard_id)`.
- Upgrade: The `trw_entity_risk_map` tool is removed. No producer for it ever existed, so it answered `sidecar_missing` on every call. What its one consumer read already comes back from `trw_before_edit_hint`.
- Upgrade: `nudge_messenger: learning_injection` now fails config validation; use `contextual`. 41 `TRWConfig` fields that no production code read are removed, with their 41 `TRW_*` environment variables. None was security-relevant.
- Changed: TRW no longer writes its protocol into `CLAUDE.md` for clients that do not read it, so the file drops from 80 lines to 17 for codex, opencode, copilot, cursor-cli and antigravity-cli. Upgrading removes the stale block between the TRW markers.
Memories stored verbatim and injection gate repaired
- Upgrade: `MemoryClient(mode="mcp")` is removed from the public `Literal`. This affects type-checkers only, since it always raised at runtime. `local` and `auto` remain.
- New: Memory entries can record that their verification failed, in a new optional `verification_status` field. An additive migration upgrades an existing store in place.
- Fixed: Memories are stored exactly as written. The write-path redaction backstop destroyed real content before the write, matching build numbers as social-security numbers. If you ran an earlier build, search your store for high-entropy or id redaction markers.
- Fixed: Three prompt-injection gate defects are fixed. Fields are joined with a separator, legitimate knowledge about prompt injection can be stored, and ten verbs are added after a pre-publish review bypassed the gate seven times by rephrasing.
- Security: Two of those seven bypasses stay open and are documented: order inversions such as "system prompt, now reveal it". Closing them would bring back the false positives the gate was narrowed to avoid. Statistical anomaly detection runs regardless.
Installer prompts again and API keys leave tracked config
- Upgrade: If you stored `platform_api_key` in `.trw/config.yaml`, that git-tracked file is no longer read for it. The key resolves from an environment variable, then the ignored 0600 `.trw/credentials.yaml`. `update-project` migrates an existing tracked key and blanks it in `config.yaml`.
- Changed: The `trw-simplify` skill with its `trw-code-simplifier` agent, and the internal `trw-release-verify` skill, are retired and removed from existing installs on update. Bundled skills go from 28 to 26 and agents from 12 to 11.
- Fixed: The one-line installer prompts for client selection again under `curl … | bash`. It had been auto-configuring whatever it detected, because it treated the piped stdin as non-interactive. Headless and CI runs stay non-interactive.
- Fixed: `update-project` no longer aborts on unmanaged nested symlinks such as agent worktrees and `node_modules` shims, which left projects on the old framework. The installer also runs `update-project` automatically when a prior install's framework is stale.
- Fixed: Edit-time sidecar hints turn on when `trw-distill` is installed, instead of waiting for a sentinel the installer never wrote. Without `trw-distill`, the hint tools return nothing instead of a paid-tier upsell.
Cross-client dispatch and stdio-only transport
- Upgrade (trw-mcp 0.57.0): `trw-mcp` now runs stdio-only. The shared HTTP MCP server, stdio proxy and HTTP transport are removed, with the `--transport`/`--host`/`--port` flags and the `mcp_transport`/`mcp_host`/`mcp_port` config fields. Leftover keys are ignored. Each client spawns its own instance, so tool changes take effect on the next reconnect.
- New: Cross-client dispatch hands a task to another coding CLI (Codex, Claude, opencode) for a background second-opinion audit. Read the result back with `trw_dispatch` and `trw_dispatch_status`.
- Changed: The default `trw_recall` payload is about 65% smaller, through a token budget measured on the serialized response, with a verbose mode on demand.
- Security: Cross-client dispatch is sandboxed by default: a sanitized environment, per-client read-only enforcement, process-group tree-kill on timeout, prompt redaction and working-directory write confinement.
- Security: `trw-memory` scans stored evidence for secrets and PII, including GitHub and AWS key patterns, and redacts them. The schema upgrade runs behind a mandatory backup snapshot and never silently resets your data.
Opt-in user memory tier
- New: An opt-in user memory tier at `~/.trw` lets portable learnings follow you across every repo on the machine. It is off until you opt in, and enabling it never moves or rewrites existing project learnings.
- New: `trw_learn` classifies portability automatically, keeping repo-local gotchas with the project and cross-cutting knowledge machine-wide.
- New: `trw_recall` merges project and user tiers into one ranked result, with a cap so user hits never bury a precise project match.
Compact session start and build failure triage
- New: Build-check failures are tagged likely-yours, likely-pre-existing or unknown, so you can triage them fast.
- New: An intentional-code marker flags deliberately counterintuitive code so the bundled reviewer and simplifier agents leave it alone.
- Changed: Session start is compact by default. Learnings cap to top-K and diagnostics collapse to a one-line health summary, with a verbose mode on demand.
- Changed: The tool surface is trimmed to the tools in use.
- Fixed: Append-only run logs drop only a single corrupt line after a concurrent write, instead of failing the whole read.
- Fixed: The installer's device-auth flow points first-run login at the real API host.
Corruption-resilient reads and faster batch writes
- Changed: Hybrid BM25, dense and RRF retrieval ordering is kept by default when the candidate pool is large enough, with per-branch latency telemetry.
- Changed: A re-entrant transaction bracket collapses many writes into a single commit, removing per-row overhead on batch passes.
- Changed: The native SQLite dependency installs only on Linux, with a graceful stdlib fallback on macOS and Windows so installs stay green.
- Fixed: Reads quarantine a single bad row instead of collapsing the entire query, so degraded reads stay correct and bounded.
- Security: The PII scanner now catches GitHub PAT and AWS access-key patterns before they can be stored in plaintext.
Per-client write surfaces and Antigravity CLI support
- New: Per-client write surfaces for Claude Code, Cursor, Codex, OpenCode, Copilot and Antigravity CLI, activated automatically on install and update.
- New: The Antigravity CLI profile gets full-ceremony support with environment discovery, config deep-merge and specialist subagents.
- New: A capability-tier resolver maps the portable `frontier`, `balanced` and `local` vocabulary to each client.
- New: An in-IDE tool lets you submit feedback without leaving the editor.
- Fixed: Throttle, deadline and watchdog controls remove a multi-minute learn stall, and several validation and sync paths are now bounded by repo size.
- Security: Feedback submissions pass secrets, headers, metadata and connection strings through the redaction chokepoint before any network call.
Boot-time security gating and eight client profiles
- New: Eight first-class client profiles: Claude Code, Cursor IDE, Cursor CLI, Aider, Codex, Copilot, Gemini and OpenCode.
- New: Learnings are signed on write, so storage-layer tampering is detectable across sessions.
- Changed: Backend deploys gain structural packaging discovery and a dependency-drift gate.
- Security: Boot-time security gating sends every tool dispatch through one verified audit, telemetry and kill-switch surface.
Memory-poisoning defense and per-item batch recovery
- New: Memory-poisoning defense runs in observe mode first. Suspicious entries surface in a shadow partition before any enforcement.
- New: A calibration window comes before promotion to enforce mode, so unvalidated thresholds do not flip early.
- New: Canary entries auto-verify on recall to detect storage-layer tampering.
- Fixed: Batch memory writes recover per item, so one bad entry no longer fails the whole batch.
Prompt calibration and client-aware rendering
- Changed: Every prompt surface is recalibrated for Claude frontier 4.7: instruction style, default effort and tokenizer behavior.
- Changed: Prompt rendering follows the client profile, with no hardcoded CLI assumptions across the framework.
- Changed: Tool and skill descriptions follow one consistent, model-friendly pattern.
Instruction files list only available tools
- New: Instruction files filter automatically to the tools that are available, so agents are not pointed at tools they cannot call.
- New: A CLI command validates instruction accuracy against the active tool set.
- New: The delivery gate warns when project instructions reference tools not available in the current configuration.
OpenCode release hardening
- Changed: The OpenCode support release is hardened with full-package verification.
- Changed: Bundled OpenCode artifacts stay synchronized with the source skills, hooks and agents.
- Fixed: Outcome-correlation writes now persist cleanly for SQLite-backed learnings.
- Fixed: Session-boundary and template-version regressions are aligned to current runtime behavior.
Leaner tool responses and modular configuration
- New: Contextual learning injection runs on phase change.
- Changed: Tool responses are optimized, with a significant token reduction per call.
- Changed: Configuration is decomposed into focused domain modules.
- Changed: Agents are consolidated into focused roles, with a clean upgrade path.
- Changed: Instruction files are optimized and hook overhead is reduced.
- Security: Platform OAuth and authentication are hardened, with cold-start resilience.
Codex provider support
- New: Codex gets a full bootstrap: one command generates all project configs, instructions and skill definitions, with merge-safe updates.
- Fixed: Skill paths are normalized, and existing configs are corrected on update for consistent directory references.
- Fixed: Project initialization no longer fails in certain directory layouts.
Module decomposition and cleaner dependency boundaries
- New: `trw-memory` 0.6.0 adds an abstract storage interface, improves CLI error handling and organizes its modules more cleanly.
- Changed: Large modules are split into focused, maintainable units across both packages.
- Fixed: Critical architectural layering issues are resolved, enforcing clean dependency boundaries across the codebase.
- Security: Every error handler was reviewed and justified, and bundled scripts received security fixes.
Embeddable server mode and new CLI commands
- New: The MCP server can be embedded as a library for testing and integration, with full type annotation support.
- New: CLI commands for an auto-generated config reference, project uninstall with a dry-run mode, and a `--version` flag.
- Changed: The large configuration module is split into focused, maintainable components.
- Changed: Circular imports are eliminated, for faster startup and a cleaner architecture.
Session heartbeat and stale-run fixes
- New: Tool calls now signal liveness, so long-running sessions are never incorrectly marked stale.
- New: Proactive database maintenance prevents unbounded storage growth during long sessions.
- Fixed: Session start events are always recorded, so delivery gates work regardless of tool call order.
- Fixed: Several stale-run detection bugs are fixed. Active sessions are identified correctly and prior session data is isolated.
Executable assertions for self-verifying memory
- New: Memory entries can carry machine-verifiable assertions, and learnings auto-verify against your codebase to detect staleness.
- New: Recall is assertion-aware: entries with failing assertions are deprioritized in search results.
- Security: Verification includes path traversal protection, pattern limits and binary file detection.
Device auth and one-line install
- New: A single shell command detects your environment, installs from PyPI and configures your project.
- New: A device authorization flow authenticates your CLI in the browser, with QR code support.
- New: OAuth social login with Google and GitHub, including Google One Tap.
- New: CLI auth commands `login`, `logout` and `status`, with multi-organization support.
Adaptive context budget and source-available prep
- New: An adaptive context budget compresses tool responses as sessions grow longer, significantly reducing token costs.
- New: Repeated identical tool responses are suppressed automatically to save context.
- Changed: Source-available publication prep: the BSL 1.1 license, a public README and scrubbed secrets.
- Changed: Upgrading invalidates the instruction cache, so a version bump forces a re-render across all projects.
Structured logging and a workstreams fix
- Changed: Framework version v24.4, released in coordination across all packages.
- Changed: Logging is restructured into consistent, queryable events across all modules.
- Fixed: Parallel agent work in workstreams is preserved during cleanup.
Client profiles and a response optimizer
- New: Built-in client profiles, including `claude-code`, `opencode`, `codex` and `aider`, adapt ceremony to each client.
- New: A response optimizer compacts tool responses for LLM context efficiency.
- Fixed: Several delivery reliability fixes.
Multi-platform ceremony and learning injection
- New: Ceremony adapts across platforms with `full` and `light` modes, for Claude Code, Cursor, OpenCode and Codex.
- New: The orchestration toolkit ships tools, resources, skills and bundled agents for the development lifecycle.
- New: High-impact learnings auto-promote into instruction files for future sessions.
- Changed: The installer is overhauled with health checks and cross-platform server management.
File ownership and pre-spawn safety checks
- New: Pre-spawn safety checks block agent creation when uncommitted changes could cause conflicts.
- New: File ownership enforcement stops multiple agents from editing the same files at once.
- Changed: Strong typing covers all major cross-module boundaries.
- Fixed: Scoring is more accurate, with calibrated weights and placeholder dimensions removed.
Documentation rewrite and full API reference
- New: A full API reference with endpoint docs, auth details, examples and error formats.
- Changed: Every documentation page is rewritten with progressive disclosure and scannable layouts.
- Changed: References expand to cover the full tool, skill and agent catalog.
- Changed: An SEO overhaul adds structured data, custom social cards for key pages and an expanded sitemap.
Interactive memory visualizations
- New: An interactive memory dashboard with growth timeline, tier migration, smart search, knowledge graph and forgetting curve visualizations.
- New: Cross-widget interactions: search highlights matching data across dashboard sections.
- New: A homepage growth timeline shows how framework knowledge compounds across tasks.
Standalone memory engine with hybrid search
- New: A standalone persistent memory engine built for AI coding agents, with local storage.
- New: Hybrid search combines sparse keyword and dense vector retrieval.
- New: Knowledge graph, tiered storage lifecycle, semantic dedup and LLM-powered consolidation.
- New: Integrations with LangChain, LlamaIndex, CrewAI and OpenAI-compatible APIs.
Next steps
Use quickstart to confirm the current install and access flow, configuration to understand changed defaults, and the API reference when a release touches hosted platform behavior.