* feat: add AI image generation tool
Port the legacy generate_image tool to the opencode-based CLI as a
Kilo-owned tool gated by experimental.image_generation config flag.
- New generate_image tool with prompt/path/image/model params
- Routes through Kilo Gateway (zero-config) or BYO OpenRouter key
- Supports text-to-image generation and image editing
- Dynamic model discovery via GET /kilo/models/images endpoint
- VS Code settings toggle + live model dropdown in Experimental tab
- Writes image to disk and returns inline FilePart attachment
- Fallback model catalog for offline resilience
* refactor: change default image model to openrouter/auto
* fix: address bot review feedback
- Remove unused fetchKiloImageModels import in tool
- Normalize jpg→jpeg MIME in parser, input image, and attachment
- Replace mismatched extensions in ensureExtension (not just append)
- Add assertExternalDirectoryEffect for output path traversal guard
- Map unauthorized errors to 401 (not 400) in image models handler
- Keep last known model list on fetch failure (don't overwrite with empty)
- Fix tool description (remove false web search claim, fix grammar)
- Remove duplicated provider resolver tests
* fix: add retry for image models request to handle backend startup race
* fix(image-generation): address kilo bot review comments
- ensureExtension replaces mismatched image extensions instead of
appending (photo.jpg + PNG -> photo.png, not photo.jpg.png)
- Gateway /models/images normalizes errors to 400/401 matching every
other gateway route (was leaking undeclared upstream statuses)
- Add 401 response to openapi.json + SDK types for /kilo/models/images
to match the gateway's errors(400, 401) declaration
* fix(gateway): align /models/images error handling with other gateway routes
* refactor: switch image generation to effect HttpClient
* test: cover kilo models images endpoint in httpapi exercise scenarios
* Exclude POST-only and parameterized API endpoints from link checker
* Add ImageModelsProvider to agent manager context tree
* chore(deps): bump @openrouter/ai-sdk-provider to 2.10.0
Switches imageModel() to OpenRouter's POST /api/v1/images endpoint for
proper image usage/billing and image-specific params.
* fix: address image generation PR review feedback
- revert @openrouter/ai-sdk-provider 2.9.0->2.10.0 bump (image tool uses raw HTTP, not the SDK)
- translate image generation settings strings across all locales
- use central KILO_OPENROUTER_BASE instead of hardcoded URL fallback
- remove completed plan file
* chore: refresh source-links.md after URL refactor
* feat(opencode): experimental SWE-Pruner for task-aware tool output pruning
Adds an experimental.swe_pruner config flag (default off). When enabled,
the read and grep tools advertise an optional context_focus_question
parameter; when the agent provides it, large outputs are skimmed by the
small model down to the lines relevant to the question, with omitted
sections marked inline. Failures fall back to the full output.
Based on SWE-Pruner (arXiv:2601.16746).
* chore: regenerate source-links for swe-pruner arxiv reference
* fix(opencode): address swe-pruner review suggestions
Harden the skimmer instruction against prompt injection from untrusted
tool output, and document that pruning runs before the tool.execute.after
hook so plugins observe the model-facing output.
* feat(ui): surface SWE-Pruner activity on read/grep tool rows
The read renderer hides tool output entirely, so pruning was invisible in
the webview even though the model received the pruned output. Show a
'SWE-Pruner · kept/total' row driven by the swePruner tool metadata.
* chore: retrigger CI (flaky windows/jetbrains tests, review service delivery error)
* feat(opencode): configurable SWE-Pruner skimming model
Adds experimental.swe_pruner_model (provider/model format) with a model
selector in the VS Code Experimental tab, shown when SWE-Pruner is
enabled. Falls back to the configured small model when unset or when the
configured model is unavailable.
* fix(ui): localize the SWE-Pruner pruning indicator
Replace the hardcoded label with a ui.tool.swePruned i18n key
(interpolated kept/total) added to all 20 shared UI locales.
* chore: retrigger CI (windows bun install network timeout on tree-sitter-powershell)
---------
Co-authored-by: marius-kilocode <marius@kilocode.ai>
Point the notification at getting-started/settings instead of the CLI
platform page, and add the opencode migration callout there so the
neutral page is self-contained for VS Code and JetBrains users too.
Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Kilo no longer falls back to opencode configuration stored in `.opencode`
directories. This change adds detection for both global and project-level
opencode configuration directories and issues a warning to guide users
on how to migrate their settings to the new Kilo configuration paths.
- Implement `KilocodeConfig.detectOpencodeConfig` to identify legacy
config locations.
- Add warning messages to the CLI configuration loading process.
- Update documentation to include migration instructions.
- Add tests to verify detection of global and project-level opencode
configs.
Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
* feat(vscode): integrate project memory into the extension
Wire the kilo-memory system into the VS Code extension host and webview,
building on the shared client helpers and /memory command catalog in
@kilocode/kilo-memory.
Extension host:
- KiloProviderMemory bridges the SDK memory client (status/show/enable/
disable/configure/rebuild/remember/correct/forget/purge, plus status
and edit) with serialized operations and a small per-directory cache
- memory.status/updated/error events fan out to the active and tracked
sessions and refresh the webview
- showMemory / toggleMemory commands, routed through the sidebar provider
or the Agent Manager panel depending on which is active
Webview:
- MemoryProvider context, memory status controls in the Context settings
tab, task-header and assistant-message affordances, and the /memory
prompt command (help/show/operation) driven by the shared catalog
- message types and i18n strings across all locales
* fix(vscode): address memory PR review suggestions
- serialize toggleMemory's status pre-check via KiloProviderMemory.toggle()
so rapid toggles can't double-apply the same operation
- collapse duplicate enabled/active memos in memory context
- extract shared formatCompactCount util (was triplicated K/M formatter)
- drop dead reject handler in serial() and never-produced member from
MemoryOperationResultMessage.result union
* fix(memory): audit cleanups: inspect accuracy, shared marker decoder, dead i18n key
* chore: update kilo-vscode visual regression baselines
---------
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Add /reload to the CLI System Commands table and update the skills
documentation to mention /reload as an alternative to starting a new
session for picking up skill changes.
- Remove AI Providers link from Getting Started Configuration (has own section)
- Remove self-referencing subLinks throughout nav files
- Separate AI Adoption Dashboard into its own section in Collaborate
- Reduce redundant navigation entries for cleaner UX
In-root absolute paths are intentionally allowed; only references that leave the root (absolute paths outside it, ../ traversal, symlinks) are rejected. Fix the docs wording and add a regression test for the in-root absolute case.
* Update Requesty setup instructions for VSCode
Clarified instructions for adding Requesty in VSCode settings.
The settings gear icon is inside the Kilo Code extension, not the native VS Code settings. Need to click "show more providers" instead of adding "Custom providers" to find Requesty.
* Update packages/kilo-docs/pages/ai-providers/requesty.md
Co-authored-by: kilo-code-bot[bot] <240665456+kilo-code-bot[bot]@users.noreply.github.com>
---------
Co-authored-by: Johnny Eric Amancio <johnnyeric@gmail.com>
Co-authored-by: kilo-code-bot[bot] <240665456+kilo-code-bot[bot]@users.noreply.github.com>
The OpenRouter docs page at /docs/features/provider-routing returns
404. Update both references in the OpenRouter provider page to the
current location /docs/guides/routing/provider-selection, which resolves
the lychee link-check failure in CI.
Adopt the file-scoping approach from #11883: untrusted project config may still read {file:...} as long as the target stays inside the project root (absolute paths, ../ traversal, and symlink escapes are rejected via realpath). Keep {env:} fully blocked in project config (no safe scoped form). Make the /proc/self/fd guard cross-platform. Thread fileScope through config.ts, agent.ts, tui.ts, and overlay.ts. Update docs and changeset.