Releases: heznpc/AirMCP
Release list
v2.16.3
What's Changed
- docs: refresh contributing workflow by @Fhatu12 in #412
- chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 by @dependabot[bot] in #398
- docs: sync contribution templates with module manifest by @Fhatu12 in #415
- fix(release): widen registry propagation window so a shipped publish is not a red release by @heznpc in #413
- docs(security): match trust claims to the scope the code actually enforces by @heznpc in #414
- chore(ci): enforce src formatting so the gate cannot drift silently by @heznpc in #416
- test: cover summarize-audit fixture mode by @Fhatu12 in #417
- docs(template): ask PRs to link the issue with Closes by @heznpc in #419
- test(calendar): add script/outputSchema shape contract and fix three drifts by @heznpc in #420
- docs: lead the README with what the reader can do by @heznpc in #421
- test(notes,reminders,mail,finder): extend script/outputSchema contract, fix list_mailboxes by @heznpc in #422
- test(iWork): add injection-focused generator suites for Pages, Numbers, Keynote by @heznpc in #423
- fix(registry): add the Dockerfile Glama needs, and a CI gate so it cannot break silently by @heznpc in #424
- fix(release): gate the signed app lane on a variable instead of a phantom approval by @heznpc in #425
- fix(release): pin the signing guards to the project's real Developer ID by @heznpc in #426
- fix(docs,doctor): correct five places where docs and doctor disagreed with the code by @heznpc in #427
- docs: close the two release blockers before cutting 2.16.3 by @heznpc in #428
- chore(release): v2.16.3 by @heznpc in #429
Full Changelog: v2.16.2...v2.16.3
v2.16.2
What's Changed
- fix: run release npx smoke from clean cwd by @heznpc in #374
- feat: opt-in inbound webhook + Power Automate Cloud Flow modules (newtria port) by @heznpc in #376
- fix: refresh tool manifest constraints by @heznpc in #377
- fix: address multi-agent security & correctness review findings by @heznpc in #375
- chore(deps): bump the actions-minor-patch group across 1 directory with 3 updates by @dependabot[bot] in #380
- chore(deps-dev): bump the development-minor-patch group with 3 updates by @dependabot[bot] in #384
- chore(deps): bump the actions-minor-patch group across 1 directory with 5 updates by @dependabot[bot] in #388
- feat: harden governed workflows, Trust Center, and onboarding by @heznpc in #383
- chore(deps): bump postcss from 8.5.16 to 8.5.24 in /docs/site by @dependabot[bot] in #399
- chore(deps): bump svgo from 4.0.1 to 4.0.2 in /docs/site by @dependabot[bot] in #391
- chore(deps): bump astro from 7.0.6 to 7.1.5 in /docs/site by @dependabot[bot] in #389
- docs: refresh testing guide commands and Zod guidance by @Fhatu12 in #406
- chore(deps): bump the actions-minor-patch group across 1 directory with 6 updates by @dependabot[bot] in #397
- chore(deps): bump the production-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in #395
- chore(deps-dev): bump the development-minor-patch group across 1 directory with 6 updates by @dependabot[bot] in #405
New Contributors
Full Changelog: v2.15.0...v2.16.2
v2.16.1
Published to npm as airmcp@2.16.1 on 2026-07-29.
This Release was created retroactively to complete the tag history. The original publish run reached npm but aborted before the release step: the add-on publish gate timed out waiting for the npm registry read path to confirm an already-successful publish, and every step after it — tag creation, GitHub Release, signed app dispatch, release verification — was skipped. That gate is fixed in #413.
Commit b15eadd2d8b8d4275af280fa31e74181d7dd4218, taken from the gitHead recorded by npm for this version rather than inferred from history.
No airmcp-2.16.1.mcpb asset. The bundle was built inside the aborted CI run and never uploaded. Rebuilding it locally now would attach an artifact with different provenance than the one that shipped, so it is deliberately omitted. The authoritative shipped artifact for this version is the npm tarball:
npm view airmcp@2.16.1 dist.integrity gitHead
v2.16.0
Published to npm as airmcp@2.16.0 on 2026-07-29.
This Release was created retroactively to complete the tag history. The original publish run reached npm but aborted before the release step: the add-on publish gate timed out waiting for the npm registry read path to confirm an already-successful publish, and every step after it — tag creation, GitHub Release, signed app dispatch, release verification — was skipped. That gate is fixed in #413.
Commit 12bd71027127b69eaaef5984b3600f08c4792885, taken from the gitHead recorded by npm for this version rather than inferred from history.
No airmcp-2.16.0.mcpb asset. The bundle was built inside the aborted CI run and never uploaded. Rebuilding it locally now would attach an artifact with different provenance than the one that shipped, so it is deliberately omitted. The authoritative shipped artifact for this version is the npm tarball:
npm view airmcp@2.16.0 dist.integrity gitHead
v2.15.0
What's Changed
- feat: add task-scoped tool sessions by @heznpc in #357
- feat: require sessions for hidden tool dispatch by @heznpc in #359
- feat: add module pack runtime contract by @heznpc in #360
- chore: clarify module add-on package names by @heznpc in #361
- feat: harden modular runtime controls by @heznpc in #362
- feat: stage add-ons and lazy tool descriptions by @heznpc in #363
- test: verify add-on install and harness gates by @heznpc in #364
- test: harden add-on provenance gates by @heznpc in #365
- test: measure add-on split value by @heznpc in #366
- build: dedupe add-on shared runtime by @heznpc in #367
- feat: add on-demand module add-ons by @heznpc in #368
- feat(addons): harden release add-on UX by @heznpc in #369
- feat(addons): verify registry drift and repair UX by @heznpc in #370
- feat: add modular distribution drills by @heznpc in #371
- [codex] fix external issue regressions by @heznpc in #372
- fix: make release publish resumable by @heznpc in #373
Full Changelog: v2.14.0...v2.15.0
v2.14.0
What's Changed
- chore(deps): bump jose from 6.2.2 to 6.2.3 by @dependabot[bot] in #182
- chore(deps-dev): bump typescript-eslint from 8.58.2 to 8.59.2 by @dependabot[bot] in #181
- chore(deps-dev): bump @commitlint/cli from 20.5.0 to 21.0.0 by @dependabot[bot] in #180
- chore(deps-dev): bump globals from 17.5.0 to 17.6.0 by @dependabot[bot] in #178
- chore(deps-dev): bump eslint from 10.2.0 to 10.3.0 by @dependabot[bot] in #177
- chore(deps): bump yaml from 2.8.3 to 2.8.4 by @dependabot[bot] in #175
- chore(deps): bump @modelcontextprotocol/ext-apps from 1.5.0 to 1.7.1 by @dependabot[bot] in #174
- chore(deps-dev): bump typescript from 6.0.2 to 6.0.3 by @dependabot[bot] in #94
- chore(deps): bump github/codeql-action from 4.35.1 to 4.35.3 by @dependabot[bot] in #176
- chore(deps-dev): bump @commitlint/config-conventional from 20.5.0 to 21.0.0 by @dependabot[bot] in #179
- feat(skills): rfc 0012 phase 1 prep — cron + scheduler state + hitl queue + env by @heznpc in #207
- feat: outputSchema Wave 6 — 7 system + 3 music read tools by @heznpc in #205
- chore: audit fault-injection tests + count-stats mcpApps surface by @heznpc in #213
- chore(deps): bump softprops/action-gh-release from 2.3.2 to 3.0.0 by @dependabot[bot] in #146
- chore(deps): bump actions/upload-pages-artifact from 4 to 5 by @dependabot[bot] in #91
- chore(deps): bump github/codeql-action from 4.35.3 to 4.35.4 by @dependabot[bot] in #208
- chore(deps-dev): bump @jest/globals from 30.3.0 to 30.4.1 by @dependabot[bot] in #210
- chore(deps-dev): bump @types/node from 25.6.0 to 25.6.2 by @dependabot[bot] in #212
- feat: outputSchema Wave 7 — 6 numbers reads + system is_app_running by @heznpc in #215
- docs(readme): reframe hero + Why section to runtime layer narrative by @heznpc in #216
- fix(audit): close 12 findings from the 2026-05-13 code audit by @heznpc in #222
- feat(intents): per-tool destructive confirmation dialog body (RFC 0007 A.3) by @heznpc in #232
- docs(AirMCP): heznpc-session sweep — 5-label README + gitignore Claude state by @heznpc in #234
- chore: P0/P1/P2 modernization sweep (2026-05-21) by @heznpc in #241
- fix(http-transport): drop error stack from FATAL log to satisfy CodeQL by @heznpc in #243
- refactor(logger,circuit-breaker): simplify per review by @heznpc in #246
- fix(http-transport): redact oauth issuer value from validation error by @heznpc in #247
- fix(http-transport): drop oauth issuer scheme from validation error message by @heznpc in #248
- fix(circuit-breaker): single-probe contract under concurrent HALF_OPEN entry by @heznpc in #249
- chore(deps): bump qs from 6.15.0 to 6.15.2 by @dependabot[bot] in #250
- chore(deps): bump the production-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in #242
- chore(deps-dev): bump the development-minor-patch group across 1 directory with 7 updates by @dependabot[bot] in #245
- docs(readme): registry-traction honesty + opencode/Zed/Cline + MCP-servers ref by @heznpc in #251
- docs(readme): positioning sweep for WWDC 2026 + Google I/O 2026 by @heznpc in #252
- chore: audit flush perf + drop unimplementable cancellation promise by @heznpc in #253
- test(mcp-setup): integration tests for boot crossroads by @heznpc in #221
- docs(readme): remove "88% coverage" self-metric — align with own redaction policy by @heznpc in #254
- chore(deps): bump the actions-minor-patch group across 1 directory with 4 updates by @dependabot[bot] in #255
- docs(readme): anthropic containment alignment + claude code plugin path by @heznpc in #256
- docs(readme): containment 3-layer mapping + npm run mcp:validate by @heznpc in #257
- feat(plugin): claude code plugin package + CI mcp:validate gate by @heznpc in #258
- chore: post-review fixes from the 2026-05-27 code-review pass by @heznpc in #259
- docs(readme,plugin): wwdc d-10 hook + adjacent comp row + plugin filter keywords by @heznpc in #260
- chore(deps): bump vite from 7.3.1 to 7.3.3 in /docs/site by @dependabot[bot] in #240
- chore(deps): bump defu from 6.1.4 to 6.1.7 in /docs/site by @dependabot[bot] in #239
- chore(deps): bump astro from 6.0.4 to 6.3.6 in /docs/site by @dependabot[bot] in #238
- chore(deps): bump devalue from 5.6.4 to 5.8.1 in /docs/site by @dependabot[bot] in #237
- chore(deps): bump postcss from 8.5.8 to 8.5.15 in /docs/site by @dependabot[bot] in #236
- chore(deps-dev): bump lint-staged from 16.4.0 to 17.0.5 by @dependabot[bot] in #231
- chore(deps): bump smol-toml from 1.6.0 to 1.6.1 in /docs/site by @dependabot[bot] in #261
- chore(deps): bump zod from 3.25.76 to 4.4.3 by @dependabot[bot] in #183
- docs(rfc): add 0011 §5 post-WWDC scenario matrix by @heznpc in #219
- docs: align podcasts + safari deprecation surfaces with brokenOn by @heznpc in #218
- feat: smoke-test pattern for numbers batches 2 + 3 by @heznpc in #217
- chore(deps): bump picomatch in /docs/site by @dependabot[bot] in #235
- chore: refresh strategic-doc baseline + caret pin by @heznpc in #220
- docs(readme): drop named-competitor comparisons — capability-first only by @heznpc in #263
- docs(readme): fix DPoP overclaim + broken CHANGELOG pointer by @heznpc in #264
- chore(deps): bump the production-minor-patch group with 2 updates by @dependabot[bot] in #265
- chore(deps-dev): bump the development-minor-patch group across 1 directory with 6 updates by @dependabot[bot] in #268
- chore(deps): bump hono from 4.12.18 to 4.12.23 by @dependabot[bot] in #269
- chore(deps-dev): bump @types/node from 25.9.1 to 25.9.2 in the development-minor-patch group by @dependabot[bot] in #271
- chore(deps): bump @modelcontextprotocol/ext-apps from 1.7.3 to 1.7.4 in the production-minor-patch group across 1 directory by @dependabot[bot] in #270
- docs: resolve RFC 0011 + post-WWDC-2026 README positioning (Q2) by @heznpc in #273
- docs: tagline "Better Siri, powered by open source" → "More than Siri" by @heznpc in #274
- docs: sharpen tagline ("Open by design") + RFC 0011 session-345 accuracy by @heznpc in #275
- docs: correct WWDC verdict — MCP is two-layer (Siri no, Xcode/dev yes) by @heznpc in #276
- docs: tagline "Open by design" → "Open to every agent" by @heznpc in #277
- chore: plugin submission readiness — manifest enrich + README hero by @heznpc in #278
- docs(rfc): add RFC 0012 — tool-surface scope review (post-WWDC) by @heznpc in #279
- docs(rfc): add RFC 0013 — stratified review process for a broad codebase by @heznpc in #280
- test: commit + fix the manifest↔doc drift guard (RFC 0013 floor-fix #1) by @heznpc in #281
- docs(rfc): fix RFC 0012 number collision — daemon owns 0012, scope-review → 0014 by @heznpc in #282
- feat(review): make stratified review executable — review-route.mjs + CI + /review by @heznpc in #283
- chore(deps): bump the actions-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in #272
- ci: forcing function on the SHIPPED tarball (RFC 0014 root-cause) by @heznpc in #284
- docs: honest capability surface — starter-default vs --full, optional Swift bridge by @heznpc in #285
- docs(airmcp): correct starter tool count to ~111 + ignore Codex config by @heznpc in #286
...
v2.12.0
Headline shifts: every tool error now carries a typed category and a Trace: <id> line so a single failed call threads end-to-end through audit log + telemetry; RFC 0008 (Elicitation) Phase 1 lands the capability gate + env opt-out; RFC 0009 (iWork depth) Phase 1 ships the first three Numbers tools (tool surface 269 → 272); npx airmcp doctor --deep walks live audit-chain integrity + Swift bridge ping + module boot smoke for user-reported troubleshooting; the OAuth /.well-known/oauth-protected-resource document picks up SEP-985 alignment with DPoP advertisement + RFC 9728 optional fields. RFC 0001 typed-error adoption reached 29/32 modules with three intentional skips justified inline. Issue #145 (list_calendars empty after fresh permission grant, reported by @jagaliano on macOS 15.7.5) closed via a one-line EKEventStore.reset() in the shared authorize helper. Two future-direction drafts (RFC 0010 progressive disclosure / RFC 0011 post-WWDC) staked out.
Reading guide: entries are grouped by RFC track and audience.
- For users — features visible in the AI's tool surface, error messages, or
npx airmcp doctoroutput.- For developers — internal helpers, test infra, RFC 0001 helpers, error envelope shape.
- For operators — env var changes, audit / OAuth / rate-limit / network policy adjustments. See docs/environment.md for the full env knob index.
RFC 0001 typed errors — adoption complete (29/32 modules)
The toolError(action, e) fallback classifier in result.ts got companion errJxaFor / errSwiftFor / errUpstreamFor catch helpers (PR #173) that auto-attach cause.origin and the "Failed to <action>: <message>" prefix. Across PRs #166, #168, #169, #170, #171, #172, #173, #185, #186, #187, #188 every module that wraps runJxa / runSwift / runAutomation / HTTP fetches migrated their catch blocks from the fallback to the typed helpers. Adoption is now 29/32 tools.ts files.
The remaining three modules intentionally keep toolError because the fallback's internal_error classification is the right answer for them:
audit/tools.ts— fs reads of the on-disk JSONL audit log. ENOENT / EACCES are already handled inside the audit reader, and zod surfacesinvalid_inputautomatically for thesinceISO-8601 parameter. No category gain from migrating.memory/tools.ts— fs + JSON parse of~/.cache/airmcp/memory.json. Same shape asaudit: storage failures areinternal_error, input validation already runs through zod +errInvalidInput. PR #154 already hardened the write path (atomic temp+rename + serialized op queue + JSON-reviver prototype-pollution guard); the catch-block category isn't where the action is.podcasts/tools.ts— module is fully broken on macOS 26+ (Apple removed the Podcasts JXA scripting dictionary, see RFC 0004 /compatibility.brokenOn: [26]block). Migrating the dead-on-arrival catches isn't worth the noise; the deprecation is already advertised throughairmcp doctorandprint-compat-report.
toolError itself stays exported for these three modules and as the safety net for any future tool that hasn't yet picked up a typed origin.
Added — for users
- RFC 0008 Phase 1 — Elicitation capability gate + env opt-out (PR #196) — on review the elicitation path was already wired in
installHitlGuard(tryElicitApprovalcallsinner.elicitInputwhen the inner Server exposes it). RFC 0008 §3.2 + §3.3 named two gaps that hadn't landed yet: (1)AIRMCP_ELICITATION_DISABLE=trueenv opt-out for end-to-end scripted destructive pipelines that don't want any user prompt — falls through to the socket HITL channel exactly like a client that doesn't advertise elicitation; (2) explicitgetClientCapabilities()check before issuing the elicit request, avoiding a doomed call when the client declared no elicitation support. The existing try/catch stays as belt-and-suspenders for clients that lie about their capabilities. RFC 0008 status: Draft → Phase 1 Implemented. - RFC 0009 Phase 1 first batch — 3 Numbers depth tools (PR #197) —
numbers_list_tablesreturns{ name, rowCount, columnCount }per table; multi-table sheets are common (totals + breakdown + chart-source) but existing tools always readtables[0], so this lets a caller pick by name.numbers_get_formulareturns the literal expression behind a cell (=SUM(A1:A10)) instead of the evaluated value; returnsnullwhen the cell holds a constant — pairs with the existingnumbers_get_cell.numbers_rename_sheetrenames in place; Numbers does NOT allow duplicate sheet names so the JXA call throws and surfaces aserrJxa. Same-pass cleanup: migrated existing 9 numbers catches fromtoolErrortoerrJxaFor(RFC 0001 §3.1 cleanup that was missed in the earlier wave). Brings tool surface 269 → 272 across all auto-synced artifacts (manifest / llms / README / 232 AppIntents). 14 more Numbers tools queued in RFC 0009 §4.1; followups can lift this PR's pattern verbatim. npx airmcp doctor --deep(PR #198, polish in PR #200) — defaultdoctorstays fast.--deepopts into slower live probes for user-reported troubleshooting: HMAC chain verification across all on-disk audit JSONL files (surfaces single-line tampering with the exact file + line number viasummarizeAuditEntries.verifiedFirstBreak); Swift bridge live ping (distinguishes "not built" from "built but unresponsive"); module registry boot smoke (actually imports everytools.ts+prompts.tsto surface typos / missing transitive deps that ride the eager-import path at startup). Footer of defaultdoctorprints the hint pointing at--deep. PR #200 widened the audit-chain bad message with actionable follow-up: "Inspect the surrounding lines, then callaudit_summaryto see the full break window."initwalkthrough closes with example prompts (i18n across 9 locales) (PR #199, polish in PR #200) —npx airmcp initfinishes with a "Try asking your AI:" block of three representative prompts so the user has a concrete path from "setup complete" to first interaction (doctor --deephint added in passing). Three new i18n keys (prompt_calendar_today,prompt_summarize_notes,prompt_overdue_reminders) translated across all 9 locales the wizard already supports — PR #200 caught the original implementation hardcoded the strings in English even when the wizard ran in another locale.permission_deniedauto-hint pointing at System Settings (PR #199, polish in PR #200) —errPermissionnow adds a default hint pointing at System Settings → Privacy & Security when the caller didn't supply one. macOS-only — non-darwin (CI runners, etc.) fall through to no hint. Caller-supplied hints win verbatim. Closes the recurring "permission denied — but where?" UX gap. PR #200 hoisted the platform check to a module-levelDEFAULT_PERMISSION_HINTconst (resolved once at load instead of every error).- outputSchema Wave 5 — 4 photos read tools (
list_photos,search_photos,get_photo_info,list_favorites) — extends Wave 4's pattern to the photos module.list_photos/search_photos/list_favoritesroute throughokUntrustedLinkedStructured(photo metadata is user content);get_photo_infousesokUntrustedStructured.list_albumsdeferred — bareAlbumItem[]return shape, same array-vs-object breaking-change risk ascompare_notes. Weather forecast tools (get_daily_forecast/get_hourly_forecast) also deferred for the same reason. 7 new drift guards intests/output-schema-wave5.test.jscovering full / null-EXIF / empty-list shapes;tests/output-schema-structured.test.jsexhaustive coverage check picks up 4 fixtures so any future tool that adds outputSchema without a fixture breaks the build. - iOS Bearer token Keychain persistence (
ios/Sources/AirMCPServer/KeychainTokenStore.swift) — closes the (C) "Apple-native deeper, two devices" promise's pairing gap. PreviouslyMCPHTTPServer.init(token: nil)generated a fresh random token on every process start, so any client paired with the previous boot's token (Windows Claude Desktop, a Mac MCP client over the same Wi-Fi, etc.) silently broke. The newMCPHTTPServer.make(...)async factory routes through aKeychainTokenStoreactor which reads the persisted token (or generates + persists a fresh one on first boot). Stored askSecClassGenericPasswordwithkSecAttrAccessibleAfterFirstUnlockThisDeviceOnly— survives reboot but does NOT iCloud-sync (matches RFC 0002's loopback-by-default network policy: pairing is per-device on purpose).kSecAttrServicenamespaces by build flavour (com.airmcp.ios.token, override viaAIRMCP_KEYCHAIN_SERVICEenv for fork installs that share a device). Failure modes (Keychain unavailable in unentitled CLI runs, simulator quirks) fall back to a per-process random token with a stderr warning so the server still functions; that token doesn't persist and the operator sees the regression in logs. Newclear()API for "rotate token" / "unpair all clients" UI flows. The synchronousMCPHTTPServer.init(token: String)is retained as a non-nullable explicit-pairing entry point for tests + flows where the caller already has a token in hand.App.swiftupdated to callMCPHTTPServer.make(...). The legacyprivate static func generateToken()onMCPHTTPServerremoved — token generation lives on the persistence layer that owns the bytes.
Added — for operators
- Per-tenant rate-limit buckets keyed on OAuth subject (PR #159) — multi-tenant deployments behind OAuth get isolated rate-limit budgets per
subclaim. Stdio / single-tenant flows fall through to the shared global bucket. Closes the noisy-neighbor gap on shared HTTP transports. - **
/.well-known/oauth-protected-resourcealigned with SE...
v2.11.0
What's Changed
- feat: outputSchema Wave 3 + Safari macOS 26 gate + Hono CVE fix + RFC 0005 by @heznpc in #95
- refactor: simplify PR #95 — zod SSOT, shared shapes, terser tests by @heznpc in #96
- test: real script ↔ outputSchema contract guard (not a tautology) by @heznpc in #97
- test: swift bridge contract + CI smoke boot + RFC 0006 by @heznpc in #98
- docs(ios): refresh architecture for 2026-Q2 ecosystem shifts by @heznpc in #99
- docs(rfc): 0007 — MCP Tool ↔ App Intent auto-bridge (2-phase) by @heznpc in #100
- feat(rfc-0007): a0 — MCP tool manifest dump + CI drift guard by @heznpc in #101
- feat(rfc-0007): a1 — swift appintent codegen + router placeholder by @heznpc in #102
- feat(rfc-0007): a2a — wire router runtime on macOS + iOS by @heznpc in #103
- docs(rfc): amend 0007 with iOS 26.4.2 research findings by @heznpc in #104
- feat(rfc-0007): a2b.1 — broaden intents (10→154) + AppShortcutsProvider by @heznpc in #105
- feat(rfc-0007): a2b.2 — Codable output structs as drift guards by @heznpc in #106
- feat(rfc-0007): axis 6 — AskAirMCPIntent natural-language agent (FoundationModels) by @heznpc in #107
- chore(ios): App Store submission assets + Privacy Manifest by @heznpc in #108
- docs: market positioning + registry submission plan (2026-04-23 sweep) by @heznpc in #109
- feat(rfc-0007): axis 4.1 — Interactive Snippet views codegen (SwiftUI) by @heznpc in #110
- docs: Siri + Shortcuts + Spotlight user guide by @heznpc in #111
- ci: trigger CI on PRs to any base branch, not just main by @heznpc in #124
- fix(rfc-0007): full tool descriptions in manifest for Shortcuts UI by @heznpc in #113
- feat(rfc-0007): axis 4.2 wire snippet views into intent results by @heznpc in #112
- feat(rfc-0007): axis 3 destructive tool HITL via requestConfirmation by @heznpc in #137
- feat(rfc-0007): axis 4.3 interactive snippet follow-up taps by @heznpc in #115
- feat(rfc-0007): appenum codegen for enum @parameter inputs by @heznpc in #116
- ci(rfc-0007): verify golden-sample intents regression check by @heznpc in #117
- feat(rfc-0007): axis 4 destructive tools behind opt-in flag by @heznpc in #118
- chore(rfc-0007): manifest ineligibility diagnostics by @heznpc in #119
- feat(rfc-0007): type-aware formatters for scalar snippet views by @heznpc in #120
- feat(rfc-0007): follow-up taps for chats and messages, rename-aware by @heznpc in #122
- test(airmcpkit): unit tests for MCPIntentRouter by @heznpc in #123
- docs(rfc-0007): refresh shortcuts guide + README for post-stack coverage by @heznpc in #125
- test(rfc-0007): extract codegen helpers to lib + unit tests by @heznpc in #126
- test(rfc-0007): expand codegen helper coverage to 66 cases by @heznpc in #127
- ci(rfc-0007): structural validator for tool manifest contract by @heznpc in #128
- test(rfc-0007): extract collectEnums + renderAppEnum to lib by @heznpc in #129
- test(rfc-0007): extract swiftParamDecl + buildArgsBlock with 21 tests by @heznpc in #130
- test(rfc-0007): extract resolveFollowUpMap + factory-specs derivation by @heznpc in #131
- feat: well-known discovery card — tool + module inventory for registries by @heznpc in #132
- test(rfc-0007): extract outputSchema Codable codegen primitives by @heznpc in #133
- feat: .mcpb Desktop Extensions bundle for Claude Desktop one-click install by @heznpc in #134
- docs: mcpb install guide + well-known + codegen lib changelog entries by @heznpc in #135
- feat(release): codesign + notarize pipeline for AirMCP.app by @heznpc in #136
- feat(rfc-0005): oauth 2.1 + resource indicators discovery (step 1) by @heznpc in #138
- feat(rfc-0005): step 2 — oauth 2.1 jwt verifier + scope gate by @heznpc in #139
- feat: outputSchema Wave 4 — 7 read tools (mail/finder/safari/notes) by @heznpc in #140
- chore(release): v2.11.0 — oauth 2.1, mcpb, notarize, codegen phase A, output wave 4 by @heznpc in #141
Full Changelog: v2.10.0...v2.11.0
v2.10.0
What's Changed
- feat(schemas): outputSchema Wave 2 — 14 typed read tools with drift guards by @heznpc in #71
- feat(skills): add 5 showcase built-ins for on_error + loop + parallel + triggers by @heznpc in #72
- feat(http): declarative allowNetwork policy (rfc 0002 phase 1) by @heznpc in #73
- feat(audit): audit_log + audit_summary consumption tools by @heznpc in #74
- feat(safety): agent rate limit + emergency kill switch by @heznpc in #75
- feat(skills): per-step retry policy with exponential backoff by @heznpc in #76
- feat(events): screen_locked + screen_unlocked event triggers by @heznpc in #77
- feat(intelligence): ai_plan_metrics tool + expanded golden plan set by @heznpc in #78
- feat(skills): runtime inputs with typed schema by @heznpc in #79
- feat(apps): timeline_today — third interactive MCP App by @heznpc in #80
- feat(http): rfc 0002 phase 2 — proxy detection + doctor policy section by @heznpc in #81
- feat(skills): prompt-side inputs (argsSchema + bound value surfacing) by @heznpc in #82
- feat(memory): outputSchema + memory://recent resource + daily-journal skill by @heznpc in #83
- docs: readme refresh + demo tape update for v2.10 by @heznpc in #84
- docs: landing page adds "beyond siri" section with five concrete cards by @heznpc in #85
- docs: wire up claude in chrome to airmcp's http transport by @heznpc in #86
- docs: registry submission tracker + server.json v2.10 refresh by @heznpc in #87
- feat(app): onboarding module picker covers v2.10 surface by @heznpc in #88
- chore(release): v2.10.0 — skills dsl, memory, audit, timeline, http policy by @heznpc in #89
Full Changelog: v2.9.0...v2.10.0
v2.9.0
Published to npm as airmcp@2.9.0 on 2026-04-19.
Release created retroactively to complete the history — this version shipped to npm and was tagged, but no GitHub Release was ever cut. The existing v2.9.0 tag already points at the commit npm recorded, so only the Release was missing.
Commit d4e22c2993d25b7b65fd7a7fb2d940e3581c9c7c, cross-checked against the gitHead recorded by npm for this version.
No release asset, which matches every Release of this era (v2.8.0, v2.10.0, v2.11.0 carry none either) — bundling airmcp-<version>.mcpb onto the Release came later.
npm view airmcp@2.9.0 dist.integrity gitHead