* feat: add AI image generation tool
Port the legacy generate_image tool to the opencode-based CLI as a
Kilo-owned tool gated by experimental.image_generation config flag.
- New generate_image tool with prompt/path/image/model params
- Routes through Kilo Gateway (zero-config) or BYO OpenRouter key
- Supports text-to-image generation and image editing
- Dynamic model discovery via GET /kilo/models/images endpoint
- VS Code settings toggle + live model dropdown in Experimental tab
- Writes image to disk and returns inline FilePart attachment
- Fallback model catalog for offline resilience
* refactor: change default image model to openrouter/auto
* fix: address bot review feedback
- Remove unused fetchKiloImageModels import in tool
- Normalize jpg→jpeg MIME in parser, input image, and attachment
- Replace mismatched extensions in ensureExtension (not just append)
- Add assertExternalDirectoryEffect for output path traversal guard
- Map unauthorized errors to 401 (not 400) in image models handler
- Keep last known model list on fetch failure (don't overwrite with empty)
- Fix tool description (remove false web search claim, fix grammar)
- Remove duplicated provider resolver tests
* fix: add retry for image models request to handle backend startup race
* fix(image-generation): address kilo bot review comments
- ensureExtension replaces mismatched image extensions instead of
appending (photo.jpg + PNG -> photo.png, not photo.jpg.png)
- Gateway /models/images normalizes errors to 400/401 matching every
other gateway route (was leaking undeclared upstream statuses)
- Add 401 response to openapi.json + SDK types for /kilo/models/images
to match the gateway's errors(400, 401) declaration
* fix(gateway): align /models/images error handling with other gateway routes
* refactor: switch image generation to effect HttpClient
* test: cover kilo models images endpoint in httpapi exercise scenarios
* Exclude POST-only and parameterized API endpoints from link checker
* Add ImageModelsProvider to agent manager context tree
* chore(deps): bump @openrouter/ai-sdk-provider to 2.10.0
Switches imageModel() to OpenRouter's POST /api/v1/images endpoint for
proper image usage/billing and image-specific params.
* fix: address image generation PR review feedback
- revert @openrouter/ai-sdk-provider 2.9.0->2.10.0 bump (image tool uses raw HTTP, not the SDK)
- translate image generation settings strings across all locales
- use central KILO_OPENROUTER_BASE instead of hardcoded URL fallback
- remove completed plan file
* chore: refresh source-links.md after URL refactor
* feat(opencode): experimental SWE-Pruner for task-aware tool output pruning
Adds an experimental.swe_pruner config flag (default off). When enabled,
the read and grep tools advertise an optional context_focus_question
parameter; when the agent provides it, large outputs are skimmed by the
small model down to the lines relevant to the question, with omitted
sections marked inline. Failures fall back to the full output.
Based on SWE-Pruner (arXiv:2601.16746).
* chore: regenerate source-links for swe-pruner arxiv reference
* fix(opencode): address swe-pruner review suggestions
Harden the skimmer instruction against prompt injection from untrusted
tool output, and document that pruning runs before the tool.execute.after
hook so plugins observe the model-facing output.
* feat(ui): surface SWE-Pruner activity on read/grep tool rows
The read renderer hides tool output entirely, so pruning was invisible in
the webview even though the model received the pruned output. Show a
'SWE-Pruner · kept/total' row driven by the swePruner tool metadata.
* chore: retrigger CI (flaky windows/jetbrains tests, review service delivery error)
* feat(opencode): configurable SWE-Pruner skimming model
Adds experimental.swe_pruner_model (provider/model format) with a model
selector in the VS Code Experimental tab, shown when SWE-Pruner is
enabled. Falls back to the configured small model when unset or when the
configured model is unavailable.
* fix(ui): localize the SWE-Pruner pruning indicator
Replace the hardcoded label with a ui.tool.swePruned i18n key
(interpolated kept/total) added to all 20 shared UI locales.
* chore: retrigger CI (windows bun install network timeout on tree-sitter-powershell)
---------
Co-authored-by: marius-kilocode <marius@kilocode.ai>
A plain Error thrown when no changes are found became an untyped
defect through EffectBridge.fromPromise, which the error middleware
masked as a generic 500 "Unexpected server error". Declare a
CommitMessageNoChangesError (Schema.ErrorClass, httpApiStatus 422)
on the endpoint and translate the domain NoChangesError defect into
that typed failure, so the real message surfaces. The extension now
shows it directly instead of prepending a redundant prefix.
* feat(commit-message): add language parameter to commit message generation
Add support for generating commit messages in the user's selected UI language.
The language parameter flows through the entire stack: VSCode extension passes
the selected locale, the HTTP API accepts the new field, and the generation
service appends language instructions to the system prompt for non-English
locales.
- Update CommitMessageRequest types to include optional language field
- Modify VSCode service to pass selected locale to the API
- Append language requirements to system prompt when language is not English
- Update OpenAPI specification and regenerate SDK types
- Add test coverage for language instruction generation
* feat(commit-message): add configurable language setting for AI-generated commit messages
Add a new `kilo-code.new.languageCommitMessage` VS Code setting that allows
users to choose a specific language for AI-generated commit messages,
independent of the UI language. When set to "sync" (default), the commit
message language follows the Kilo Code UI language.
- Add language selector dropdown to CommitMessageTab settings UI
- Add getCommitMessageLanguage() helper in i18n service
- Pass languageCommitMessage setting through KiloProvider to webview
- Add translation strings for all 20 supported locales
* refactor(locale): standardize commit message terminology across locale files
Replace literal translations of "commit" with the loanword form in Brazilian
Portuguese and Spanish locale dictionaries, correct a Korean typo (커AI → 커밋),
translate an untranslated English label in Norwegian, and align terminology with
conventional usage across all four affected language packs.
* style(i18n): fix prettier formatting on commit-message language strings
---------
Co-authored-by: marius-kilocode <marius@kilocode.ai>
Reboots the per-directory instance, reloading config, skills, agents,
commands, and MCP prompts changed on disk without restarting the
server. Sessions and history are preserved; only the per-directory
instance caches are torn down and rebuilt.
Server: POST /instance/reload wraps the existing atomic
InstanceStore.reload path (the same one project.git.init uses). The
rebuild completes before the 200 response, so clients can refetch with
no race. Returns 409 ConflictError while a session is actively
running. Emits the existing server.instance.disposed SSE event, which
the TUI and extension already use to auto-refetch.
CLI: /reload palette command calls the endpoint; the TUI already
bootstraps on server.instance.disposed.
Extension: /reload slash command, a reload button in the task header
and settings panel, and a Kilo Code: Reload Config and Skills command
palette entry. The handler clears the command cache and reuses
reloadAfterAuthChange to re-fetch config, providers, agents, skills,
and commands. Reload targets the current session's directory so Agent
Manager worktree sessions reload their own worktree instance rather
than the workspace root.
SDK: regenerate so client.instance.reload is available to external
integrations.
* feat(memory): opt-in project memory — capture, recall, CLI + TUI integration
Add project memory: the standalone @kilocode/kilo-memory effect layer plus the
opencode CLI/server/TUI integration. Memory is disabled by default, so it is a
no-op until enabled (no behavior change when off).
Capture (turn-close consolidation): per-op parse salvage, secret redaction that
skips the offending op instead of aborting the batch, supersede-only auto-updates
(never model-driven deletes), correction-aware echo handling, non-LLM fallback
digests on interrupted/error turns, a shared interval throttle with idle-flush.
Recall + injection: keyword tokenizer with camelCase/compound splitting, light
stemming, and an English-first stopword filter (Unicode-aware; non-English falls
back to plain token-overlap), a live relevance floor, a budget-reserved startup
index, a session-digest catalog, and per-session prompt-cache pinning of the
injected memory block.
Surfaces: kilo_memory_save / kilo_memory_recall tools, the memory HTTP API
(contract schemas live in the package), and a status-focused TUI sidebar showing
auto-save, loaded context, and active recall, plus the /memory dialog.
* fix(memory): address PR review feedback
- C1: bump @kilocode/kilo-memory in the changeset
- C2: redact secrets before they hit the audit log (skip + salvage paths);
redact before truncating in salvageTyped so a secret straddling the
500-char cap can't leak an unmatched fragment; opText -> salvageText
- C3: de-abbreviate savedOperations, "changes" wording, ops.ts -> operations.ts
- C4: log.warn on the remaining silent-catch fallbacks (turn diff, memory
context injection, tool-visibility check)
- C5: relocate memory storage from ~/.kilo to Global.Path.data, delete the
now-dead needsDependencyInstall guard, add /memory status (root path) and
/memory edit ($VISUAL/$EDITOR + auto-rebuild)
- C6: replace the hardcoded English stopword list with corpus-derived
ubiquitous-term filtering (df across the user's own entries) and the
English suffix stemmer with suffix-tolerant term matching, so recall
noise-filtering works in any language
- C8: delete the CORRECTION_INTENT English regex; echo turns now run typed
capture (digest stays echo-gated), bounded by the interval throttle, with
the typed prompt as the language-agnostic content filter
- C9: exclude generated paths (dist/build/coverage/*.gen.*/*.map/snapshots)
from the durable-diff churn fallback so generated churn can't burn a
consolidation call
- C11: fix duplicated assert in httpapi-memory test; assert the error body
- kilo-code-bot batch: clause-boundary regex fix, byte-safe catalog
truncation, max-length guards on remember/correct/forget payloads (text,
query, key, sessionID), trim consistency in reconcile, param-shadowing
rename, missing doc entry for kilo_memory_recall, dead-code removal,
dialog UI fixes, memoryEnabledCache eviction bound, dedicated Configure
schema, recall permission renderer, covered-session pointer cap, redact
chat transcript before the consolidation model call, split configProtected
metadata from disableAlways so memory-save prompts don't show config-file
copy, drop unused MemoryService.layer provide from tool registry
- redact colon-separated low-entropy secrets too (password: hunterx),
accepting the prose false-positive tradeoff (secret: enabled) in favor of
not missing a real secret
- rename lastConsolidatedAt -> lastTypedConsolidationAt to make its narrow
scope (typed-consolidation throttle clock) explicit; regen openapi/SDK
- drop now-dead home/config fields from MemoryPaths.Host after the data-dir
relocation; add Process.splitCommand for quoted $EDITOR/$VISUAL paths with
spaces, used by /memory edit and the pre-existing Editor.open utility
* refactor(memory): shared client helpers, capture hardening, /memory UX rework
- extract client-side derivations into kilo-memory so both frontends share
one implementation: MemoryDecisions.summarize (decision-log summary),
MemoryAutosaveStatus.summarize (autosave-status semantics), and
MemoryMarkerMeta (marker wire contract encode/decode)
- match exact-key upserts via the canonical stored id (slugged key,
normalized section) so a re-emitted spaced/uppercase key updates the
entry instead of falling to fuzzy dedupe
- salvageTyped throws on valid JSON without an operations array so the
caller's fallback path records a parse error instead of a silent
zero-op success
- rename memory tool metadata files -> sources (stripPartMetadata rewrites
tool-part metadata.files assuming apply_patch records, mangling string[])
- read state instead of status for tool enabled checks; dedupe TUI helpers
(errorMessage, shared route(), Locale.number, relativeTime)
- /memory UX: bare /memory opens a help modal driven by a structured
command catalog in kilo-memory; /memory on|off become the canonical
toggle verbs (enable/disable kept as quiet aliases); /memory status opens
a clean overview dialog (root path, autosave, startup context, source
counts, index size) instead of a toast; /memory show is the single full
audit view (inspect removed)
* feat(agent-requirements): gate agents on declared requirements
* feat(cli): add agent requirements preflight helpers
Introduce a Kilo-owned CLI requirements module that preflights agent
declarations before session creation. The helper resolves requirement
status via the SDK, blocks agents with unmet skills, errored MCPs, or
VS Code extension dependencies, and produces grouped actionable
guidance for terminal users.
Includes planning documents and a focused test suite covering all
blocking and allow paths.
* chore: update kilo-vscode visual regression baselines
* fix(vscode): guard extension subscription and suppress empty invalidations
Wrap vscode.extensions.onDidChange in a typeof check so the subscribe
callback is undefined in environments where the API is unavailable.
Skip posting agentRequirementsInvalidated when the controller cache is
already empty to avoid spurious messages to the webview.
Update the associated test to seed cache state before asserting on the
clear-triggered invalidation flow.
* refactor(agent-requirements): replace numeric generations with object-identity tokens
Switch the controller's supersession tracking from incrementing counters
to ephemeral object references, ensuring stale tokens are cleaned up on
both success and failure paths. This eliminates a class of race
conditions where cleared counters could alias with fresh requests.
Conditionally emit the "Install the required skills..." footer in the
CLI formatter only when skills or MCPs are actually present, preventing
misleading guidance for extension-only requirement failures.
* test(httpapi): add exercise scenario for agent requirements endpoint
Cover the GET /kilocode/agent/requirements route in the HTTP API
exercise harness, asserting that the response echoes the requested
agent, uses the routed workspace directory, and correctly reports
the disabled state with empty skills/mcps/extensions arrays.
* feat(agent-requirements): enforce guard across all clients and relax ID validation
Lift the VS Code–only restriction from the requirements guard so
that blocked skills/MCPs fail for CLI and other clients as well.
VS Code extension requirements remain client-specific. The evaluate
function now accepts pre-decoded requirements as an explicit input
rather than decoding internally, and the schema switches from the
strict alphanumeric ID pattern to a permissive non-whitespace Name
pattern allowing slashes and spaces in skill/MCP identifiers.
Update prompt interfaces to surface RequirementBlockedError in the
typed error channel and preserve "ready" results in the webview
cache alongside blocked/error states.
* chore(opencode): fix requirement guard annotations
---------
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Let Agent Manager chat tools choose a model and reasoning effort per session,
discover what is available without loading the full catalog, and resolve the
provider automatically so the agent does not have to know provider plumbing.
- agent_manager tasks accept a `model` (by name) and a model-specific `variant`.
Selection is resolved to a concrete provider/model, preferring the provider
behind the user's default model and falling back to the Kilo Gateway, with a
qualified provider/model accepted as an escape hatch. A model selection
requires an initial prompt so the session persists it.
- New agent_manager_models tool searches models grouped by name (not provider),
capped at 20 results per call and paginated, so the catalog never bloats the
conversation context. Matching is lenient (case, punctuation and order
insensitive) so an exact name is not required.
- Wrong guesses return closest-name suggestions and the success output echoes
how each named model resolved (provider and variant) for transparency.
Add a create action to the notebook_edit tool so an agent can make a new empty
.ipynb on disk, then insert cells. The VS Code notebook API has no way to create
a notebook file at a path (openNotebookDocument only makes an unsaved untitled
notebook), so the bridge writes a minimal valid empty .ipynb and opens it.
Reuses the existing notebook_edit permission and native_notebook_tools
experiment; .ipynb only for now, parent directory must already exist.