Skip to content

Commit 685db0c

Browse files
ndemiancclaude
andcommitted
docs: release notes for v0.9.1
Covers what actually shipped in the v0.9.1 tag: initial MCP support (S1-S3) and the calm-transcript chat overhaul, plus the Shift+Cmd+I focus fix and the smaller polish. Written against the tag's real contents — test counts (41 + 15 = 56 MCP cases) were read from the tagged tree, not recalled. The MCP section leads with the security model rather than the feature, because that is the honest framing for a first slice: servers are user-settings only and every tool is allow-list gated, so what ships is deliberately narrow. Deliberately omitted: /rme, whose own commit states it is undocumented and "meant to be found, not advertised" — listing it in release notes would defeat it. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent b736104 commit 685db0c

1 file changed

Lines changed: 50 additions & 0 deletions

File tree

RELEASE-NOTES.md

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
# LevelCode v0.9.1
2+
3+
Two big things this release: the agent gains **external tools via MCP**, and it learns to **narrate its work** instead of scrolling a wall of chips.
4+
5+
## Highlights
6+
7+
### The agent can use external tools — MCP support
8+
9+
LevelCode's agent now speaks the **Model Context Protocol**, so it can use tools from external MCP servers — a filesystem server, GitHub, Postgres, an internal company server — right alongside its own built-in tools. There's no glue code: an MCP tool becomes an agent tool directly.
10+
11+
Add a server in your **user settings** and its tools show up in the agent, namespaced `server__tool`:
12+
13+
```json
14+
"levelcode.ai.mcp.servers": {
15+
"filesystem": { "command": "npx", "args": ["-y", "@modelcontextprotocol/server-filesystem", "/path"] }
16+
}
17+
```
18+
19+
Security is the feature here, not a footnote — an MCP server is a process LevelCode spawns with your privileges:
20+
21+
- **User-authored only.** These live in your *user* settings; a repo's committed `.vscode/settings.json` can't add a server, so opening an untrusted project can never make LevelCode spawn a process. A repo's own `.levelcode/mcp.json` is read and listed but **never started** on its own.
22+
- **Nothing runs unless you allow it.** Every MCP tool call is gated by default — including under Autopilot. A tool runs only once you allow-list it in `levelcode.ai.mcp.toolPolicy`, and a server's own "destructive" hint can only ever *tighten* that, never loosen it.
23+
24+
This is the **first slice**: servers are configured in settings and tools are enabled through the allow-list. A per-call approval card and a one-click "Add MCP Server…" are what come next.
25+
26+
### A calmer, narrated transcript
27+
28+
An agent run now reads like a colleague narrating their work rather than a flat scroll of chips and cards.
29+
30+
- **Short prose between actions.** The agent says what it's about to do, then interprets what it found — in the same turn, so it never stops to chatter instead of working.
31+
- **Activity folds into one card.** Consecutive actions collapse into a single expandable group: while it runs, the header shows the *live* step; when it finishes, a past-tense summary takes its place — "Read and edited `PLAN.md` +56 −0, ran 2 commands."
32+
- **Failures read as findings.** A hiccup shows up as a one-line `Correction:` and a next step, not an alarm.
33+
- **Plain-language command labels.** A `run_command` shows what it *does* ("Run the extension unit tests"); the raw command stays tucked behind the card.
34+
- **One question at a time.** `ask_user` now asks a single question per prompt.
35+
36+
### Smaller things
37+
- **`Shift+Cmd+I` now focuses the chat** — previously only `Ctrl+Cmd+I` did.
38+
- A single circle-check glyph wherever a "done" check appears, and an HTML5 shield icon for `.html` files.
39+
40+
## Under the hood
41+
42+
- **MCP is three small, dependency-free modules** — no SDK, in keeping with the plain-JS extension style. `mcpProtocol.js` (JSON-RPC 2.0 framing + typed-content flattening, pure), `mcpConfig.js` (server config, tool-name namespacing, and the approval policy — pure), and `mcpClient.js` (the stdio subprocess: spawned detached and group-killed on New Chat and reload, with a per-call timeout and an output cap so one server can neither hang the agent nor flood its context). The full plan and threat model are in `docs/MCP.md`.
43+
- **The calm transcript ships as two halves** — the *voice* lives in the agent's system prompt (`agent.js`), the *grouping* in the chat webview (`chat.html`). Scope and design are in `docs/CALM-TRANSCRIPT.md`.
44+
45+
## Test coverage
46+
47+
- **56 MCP unit tests**, all off-editor (no process, no network): `mcpConfig.test.js` (41 — tool names stay provider-legal across a hostile corpus, a repo's config can never shadow or auto-start a server, untrusted keys are dropped before they can reach a prototype, and the allow-list never defaults to "allow") and `mcpProtocol.test.js` (15 — JSON-RPC framing with partial-line buffering, and base64 image/audio payloads never reaching the stored transcript).
48+
- The CI gate runs **every** bundled extension's suite on each release.
49+
50+
**Full changelog:** https://github.com/levelcodeai/levelcode/compare/v0.9.0...v0.9.1

0 commit comments

Comments
 (0)