Skip to content
CAI
Software that uses CAICheck a score

danielmiessler/Fabric

59.8

Adequate · 24 September 2026

24.9k

lines of production code

Go

with TypeScript, Python

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Fabric is a command-line interface and local AI orchestration platform that aggregates interactions with numerous external providers, including OpenAI, Anthropic, Azure, and local models like Ollama. It enables users to manage AI contexts, execute structured prompts, and process various media types such as code, PDFs, and YouTube videos through a unified CLI and REST API. The system also includes utilities for automated changelog generation, shell integration, and desktop notifications, all packaged for reproducible builds via Nix.

How it got here

2024–2025 — Go migration and platform expansion

49 changes.

The project underwent a comprehensive rewrite from Python to Go, establishing a reproducible Nix-based build system and a SvelteKit web frontend. This period focused on rebuilding the core architecture with robust plugin support for numerous AI providers, implementing a secure REST API, and introducing extensive internationalization and automation tooling.

2026 — AI vendor expansion and tooling

5 changes.

This period focused on expanding AI backend support by adding plugins for DigitalOcean Gradient, OpenAI Codex, and an Azure AI Gateway that routes requests to multiple providers. It also introduced new utility tools, including a code scanning CLI and a Spotify metadata retrieval tool, alongside comprehensive testing for these integrations.

Features

Add Amazon Bedrock AI vendor support with flexible authentication

Users can now connect to Amazon Bedrock models via a new plugin. The setup process dynamically fetches available AWS regions and supports three authentication modes: simple Bearer token (ABSK) authentication, explicit AWS access/secret keys, or the standard AWS credential provider chain. The plugin implements the Vendor interface to integrate with the existing AI framework.

internal/plugins/ai/bedrock · high confidence

Add DigitalOcean Gradient AI Agents vendor support

Users can now connect to DigitalOcean's Gradient AI platform as a new AI vendor. The implementation adds a client that supports model listing via the DigitalOcean control plane API (using a specific token) or fallback to standard inference endpoints, and integrates i18n for error messages.

internal/plugins/ai/digitalocean · high confidence

Add Exolab AI plugin with custom model configuration

Users can now configure the Exolab AI provider through a new plugin that requires an API key, an API base URL (defaulting to localhost:52415), and a list of deployed models. The plugin leverages the OpenAI client structure but allows users to specify their own models via a comma-separated list, which are then used for listing available models instead of fetching them dynamically from the API.

internal/plugins/ai/exolab · high confidence

Add Microsoft 365 Copilot integration

Users can now connect to Microsoft 365 Copilot as a new AI vendor. This integration requires an Azure AD app registration with specific delegated permissions and supports configuration via tenant ID, client ID, and OAuth2 credentials. The plugin exposes a single unified model and handles conversation creation and message streaming through the Microsoft Graph API.

internal/plugins/ai/copilot · high confidence

Add Nix package definition for Fabric AI

This change introduces the Nix build infrastructure for the Fabric AI application, enabling users to install and run the tool via the Nix package manager. The package definition (default.nix) builds the Go-based application from source, pinning the version to 1.4.480 and configuring the build to prevent automatic Go toolchain downloads. It also ensures that shell completion scripts for Zsh, Bash, and Fish are installed alongside the binary.

nix/pkgs · high confidence

Add OpenAI Codex vendor with browser-based OAuth authentication

Users can now connect to the OpenAI Codex backend via a new vendor plugin. The setup process launches a local callback server to complete a browser-based OAuth flow (using PKCE), automatically extracting and persisting access, refresh, and account tokens. The client handles token refresh, persists credentials to the environment, and maps API errors to user-friendly messages, including specific handling for usage limits and login revocation.

internal/plugins/ai/codex · high confidence

Add Spotify podcast metadata retrieval tool

Users can now retrieve metadata for Spotify shows and episodes by providing a Spotify URL. This new tool in internal/tools/spotify integrates with the Spotify Web API using OAuth2 Client Credentials flow, requiring a Client ID and Client Secret configured via environment variables. It supports extracting metadata from show and episode URLs, searching for shows, and listing episodes for a given show. The tool also includes comprehensive unit and integration tests to verify URL parsing, metadata retrieval, and formatting functionality.

internal/tools/spotify · high confidence

Add custom patterns plugin with localized setup

A new internal tool plugin for managing custom patterns has been added. It introduces a setup flow that allows users to specify a directory for their custom patterns, automatically expanding home-directory shortcuts (e.g., \~/) and creating the directory if it does not exist. All user-facing strings, including the setup description and configuration prompts, are now localized via the i18n system rather than using hardcoded English text.

_internal/tools/custom\patterns · high confidence

Add internationalization (i18n) support with automatic locale detection and multiple language translations

The application now supports multiple languages, including English, Spanish, Portuguese (with distinct Brazilian and European variants), German, French, Japanese, Chinese, Persian, Italian, and Turkish. The system automatically detects the user's preferred language from environment variables (LC\_ALL, LC\_MESSAGES, LANG) or allows explicit configuration, falling back to English if no translation is available. Translations are bundled with the application and can be updated via remote download, ensuring consistent UI messaging across supported locales.

internal/i18n · high confidence

Add shell completions for Zsh, Bash, and Fish

Shell completions are now available for Zsh, Bash, and Fish, providing dynamic suggestions for patterns, models, contexts, sessions, vendors, strategies, extensions, Gemini TTS voices, and transcription models. The completions also support fixed-value flags (such as thinking levels, image dimensions, and debug levels) and file path completion for attachments, outputs, and configuration files. A setup script is included to automatically install these completions for the current shell.

completions · high confidence

Added example templates and scripts for the extension system

The Examples directory now includes a comprehensive guide and a set of ready-to-use templates demonstrating how to configure and use the extension system. These examples cover various scenarios, including a Python-based word generator, direct executable wrappers for SQLite3 and OpenAI, and shell scripts for generating local and remote security reports. The included YAML configurations and shell scripts illustrate how to define extension operations, handle input parameters, and manage output methods (stdout vs. file), providing users with concrete reference implementations for integrating external tools.

internal/plugins/template/Examples · high confidence

Anthropic client now supports Claude 5 models and structured thinking

The Anthropic plugin has been updated to support the latest Claude 5 family models (Fable, Sonnet, and Opus 5) and Opus 4.8, with automatic handling of their 1M context window requirements via beta headers. It also introduces support for structured thinking levels (Off, Low, Medium, High) and enforces parameter restrictions for newer models that reject non-default sampling settings. Additionally, the client now includes built-in web search tool support and comprehensive test coverage for model listing, parameter building, and search functionality.

internal/plugins/ai/anthropic · high confidence

Automated GitHub release description updates with fork support

The changelog tool now includes a new \--release\ flag that automatically updates the description of a GitHub release with the generated AI summary. This feature handles both standard repositories and forks; if the current repository is a fork, the tool attempts to update the release description in the upstream parent repository first, falling back to the fork itself if necessary.

_cmd/generate\changelog/internal · high confidence

Automated README feature section generation

Added a new Python script and documentation in the \scripts/readme\_updates\ directory to automate the generation of the 'Recent Major Features' section for the main README. The script queries the changelog SQLite database, applies keyword-based heuristics to filter for feature and improvement releases while excluding bug fixes and chores, and outputs formatted Markdown links. This allows maintainers to easily update the README with the latest significant product capabilities.

_scripts/readme\updates · high confidence

Cross-platform desktop notifications with secure command execution

Users can now receive desktop notifications on macOS, Linux, and Windows. The system automatically selects the best available backend (terminal-notifier, osascript, notify-send, or PowerShell) and uses environment variables to safely pass titles and messages, preventing shell injection attacks. On unsupported platforms, notifications are silently ignored.

internal/tools/notifications · high confidence

Initial Ollama plugin with streaming, multi-modal, and error-handling improvements

Users can now connect to local Ollama instances via a new plugin that supports streaming responses, multi-modal image inputs, and structured usage metadata. The plugin automatically converts single system-role messages to user-role to prevent empty responses, validates data URLs for images, and ensures the stream channel is closed on errors to prevent resource leaks.

internal/plugins/ai/ollama · high confidence

Introduce AI-powered changelog generation with incremental caching

The changelog generator now supports automated, AI-enhanced release notes. It uses incremental caching to speed up generation by reusing previously processed git history and PR data, only walking new commits since the last tag. The system aggregates incoming PR files and direct commits, correctly associating PR numbers with version tags and detecting merge commits via parent count and message patterns. For each version, it can invoke an external AI summarizer (defaulting to claude-opus-5 via the fabric CLI) to condense raw commit logs into concise, human-readable bullet points, while preserving PR headers and links. The generator also handles version date calculation based on the most recent commit in the PRs, ensures proper newline handling in the output file, and integrates with the incoming directory workflow for staged releases.

_cmd/generate\changelog/internal/changelog · high confidence

Introduce DryRun plugin for request simulation

A new DryRun plugin has been added to the AI plugin system, allowing users to simulate AI requests without sending them to a real provider. This plugin intercepts chat messages and options, formats them into a readable text representation (including model settings, temperature, and multi-content details), and returns a fake response with simulated token usage. It supports both streaming and non-streaming modes, enabling users to verify how their prompts and configurations would be structured before actual execution.

internal/plugins/ai/dryrun · high confidence

Introduce GitHub changelog client with PR and commit data models

This change adds the internal GitHub client and data types used to fetch Pull Request and commit information for changelog generation. The new \client.go\ implements concurrent fetching of PRs with a semaphore-based limiter, distinguishes between lightweight validation queries and full commit retrieval, and handles GitHub authentication via OAuth2 tokens. The \types.go\ file defines the \PR\, \PRDetails\, and \PRCommit\ structs, including support for author type classification (user, organization, bot) and email fields. Tests in \email\_test.go\ verify correct handling of commit email data.

_cmd/generate\changelog/internal/github · high confidence

Introduce PDF conversion, HTML readability, and Streamlit UI components

This change introduces three new capabilities: a Go-based command-line tool (cmd/to\_pdf) that converts LaTeX source files or stdin input into PDFs using pdflatex; an internal Go package (internal/tools/converter) providing an HtmlReadability function to extract clean text content from HTML using the go-readability library, accompanied by unit tests; and a Python Streamlit application (scripts/python\_ui/streamlit.py) that serves as a user interface for managing AI model configurations, executing patterns, and viewing outputs with persistent logging and session state management.

_cmd/to\_pdf, internal/tools/converter, scripts/python\ui · high confidence

Introduce automated pattern metadata extraction and management workflow

This change introduces a new system for managing pattern descriptions and tags, centered around the \extract\_patterns.py\ script. The script automatically scans the local patterns directory (e.g., \\~/.config/fabric/patterns\ or \data/patterns\), extracts the first 500 words of each pattern's \system.md\ file into \pattern\_extracts.json\, and creates initial placeholder entries in \pattern\_descriptions.json\. This workflow simplifies the process of adding new patterns by automating the creation of reference extracts and metadata structures, ensuring that new patterns are immediately recognized and ready for description and tagging updates. The system also includes documentation (\README\_Pattern\_Descriptions\_and\_Tags\_MGT.md\) explaining how to complete these metadata entries and maintain synchronization with the web interface.

_scripts/pattern\descriptions · high confidence

Introduce code2context CLI for scanning code projects into structured JSON

A new command-line tool named code2context is available to scan code directories or specific files and output a structured JSON representation of the project structure, file contents, and user-provided instructions. Users can run it in directory mode (providing a path and instructions) or pipe a list of files via stdin, with options to limit scan depth, ignore specific patterns (like .git or node\_modules), and direct output to a file.

cmd/code2context · high confidence

Introduce git repository walker for changelog generation

Added new internal packages (types.go, walker.go) to handle git repository operations for changelog generation. The walker provides functionality to retrieve the latest tag, walk commits since a specific tag, and parse commit messages to extract version numbers and pull request numbers. This enables the changelog generator to accurately associate PRs with version tags and identify unreleased changes.

_cmd/generate\changelog/internal/git · high confidence

Introduce prompt strategy management with secure loading

The application now supports a new 'Prompt Strategies' plugin that allows users to manage and load custom prompt strategies from JSON files. This feature includes an automated setup process that can download a default set of strategies from a Git repository, configurable via environment variables for the repository URL and folder path. The implementation ensures security by validating file paths to prevent directory traversal attacks when loading strategy files, and it handles configuration validation to ensure strategies are properly loaded and available for use.

internal/plugins/strategy · high confidence

Introduce standalone changelog generator CLI with AI summaries and GitHub release updates

A new \generate\_changelog\ command is added to the CLI, providing a high-performance tool to generate comprehensive changelogs from git history and GitHub pull requests. It features a one-pass git walking algorithm, SQLite-based caching for incremental updates, and concurrent GitHub API calls (optimized with GraphQL) to fetch PR details. Users can now generate changelogs for specific versions or the full history, enable AI-powered summaries via Fabric, and use the \--release\ flag to automatically update GitHub release descriptions with AI summaries. The tool also supports processing incoming PR files, synchronizing the local database with git history and GitHub, and allows processing closed PRs.

_cmd/generate\changelog · high confidence

Introduce structured chat message model and streaming chatter implementation

The internal chat and core packages now use a structured \ChatCompletionMessage\ type that supports multi-part content (text and image URLs), tool calls, and reasoning content, with custom JSON marshaling to handle both legacy single-content and new multi-content formats. The \Chatter\ component has been rewritten to support structured streaming, including a \SuppressThink\ option to filter out AI reasoning blocks from the output, case-insensitive model name matching, and improved error handling for stream updates. The \PluginRegistry\ now initializes a comprehensive set of AI vendors (including Codex, VertexAI, Azure Entra ID, and Microsoft 365 Copilot) with proper configuration and token persistence, and includes tests for vendor selection, model prefix parsing, and think-block suppression.

internal/core · high confidence

Introduces SQLite-based caching for changelog generation

The changelog generator now persists processed data to a local SQLite database, caching versions, commits, pull requests, and metadata. This allows the tool to track the last processed tag and avoid re-processing historical data, improving performance and reliability for subsequent runs.

_cmd/generate\changelog/internal/cache · high confidence

Introduces centralized debug logging with granular verbosity levels

The application now uses a centralized logging package in internal/log to manage debug output, replacing scattered stderr prints. Users can control verbosity via a new --debug flag (or SetLevel API) with five levels: Off, Basic, Detailed, Trace, and Wire. The Wire level specifically enables full logging of LLM request/response exchanges, aiding in debugging model interactions. All debug messages are prefixed with 'DEBUG:' and written to stderr by default, while critical messages use the unconditional Log function.

internal/log · high confidence

New Azure AI Gateway plugin supporting AWS Bedrock, Azure OpenAI, and Google Vertex AI

Users can now route AI requests through an Azure API Management (APIM) Gateway to access multiple backend providers—AWS Bedrock, Azure OpenAI, and Google Vertex AI—using a single unified interface. The plugin introduces setup questions for the gateway URL, subscription key, and backend type, with Azure OpenAI additionally supporting a configurable API version (defaulting to 2025-04-01-preview). It handles shared HTTP plumbing, authentication headers, and request formatting specific to each backend (e.g., Anthropic Messages API for Bedrock, OpenAI format for Azure OpenAI, and Gemini format for Vertex AI), while listing available models and enforcing a 10MB response size limit.

internal/plugins/ai/azureaigateway · high confidence

New Nix shell and treefmt configurations with Go toolchain isolation

This change introduces two new Nix files: \nix/shell.nix\ and \nix/treefmt.nix\. The shell configuration provides a development environment with Go tooling (gopls, gotools, goimports-reviser, gomod2nix) and a custom \update-mod\ helper script to manage Go modules and regenerate Nix packages. Crucially, it sets the \GOTOOLCHAIN=local\ environment variable to prevent automatic Go toolchain downloads. The treefmt configuration enables formatting and linting tools (deadnix, statix, nixfmt) and wraps Go-specific formatters (goimports, gofmt) to also enforce the \GOTOOLCHAIN=local\ setting, ensuring consistent behavior across development workflows.

nix · high confidence

New REST API server with authentication and security hardening

The internal server now exposes a new REST API (powered by Gin) that consolidates chat, pattern, context, session, and configuration management into a single service. Authentication is enforced via an X-API-Key header for all endpoints except Swagger documentation, and binding to non-loopback addresses requires a key to be set. Security is improved by masking API keys in configuration responses, rejecting path-traversal attempts in storage and pattern names, and hiding internal filesystem paths from error messages. The chat endpoint supports streaming responses, pattern variables, and multi-turn sessions, while the configuration endpoint allows updating provider keys and URLs.

internal/server · high confidence

New Template System with Secure Extension Execution and Internationalization

The internal template plugin now provides a comprehensive system for variable substitution and dynamic content generation using a double-brace syntax (e.g., {{name}}). This update introduces a plugin architecture with built-in capabilities for datetime operations (e.g., {{plugin:datetime:now}}), file system access (e.g., {{plugin:file:read}}), and HTTP fetching (e.g., {{plugin:fetch:get}}). A key behavioral change is the introduction of a secure extension executor that shell-escapes all user-controlled values to prevent command injection when executing external scripts. Additionally, all user-facing strings and error messages have been extracted for internationalization (i18n) support, and the system now includes a registry for managing and validating external extension configurations.

internal/plugins/template · high confidence

New Vertex AI provider supporting dynamic model listing and Claude models

Added a new Vertex AI plugin that enables access to Anthropic Claude models via Google Cloud Vertex AI, alongside Google's Gemini models. The provider dynamically lists third-party models (like Claude) from the Model Garden API and includes a curated list of Gemini models, presenting them to users in a prioritized order (Gemini first, then Claude). It supports both standard and streaming chat interactions, requiring configuration of a Google Cloud Project ID and Region.

internal/plugins/ai/vertexai · high confidence

New domain types for structured streaming, file management, and reasoning controls

This change introduces several new domain types and utilities in the internal/domain package. It adds structured streaming support via the StreamUpdate and UsageMetadata types to unify text deltas and token counts across providers. It introduces a FileChange model and associated parsing/application logic to handle LLM-generated file operations, including validation against directory traversal and size limits. It also defines ThinkingLevel constants and token budgets for reasoning controls, along with a regex-cached StripThinkBlocks function to filter AI reasoning output. Finally, it adds an Attachment type to manage content from paths, URLs, or raw bytes, and provides a NormalizeMessages utility to enforce message ordering in chat sessions.

internal/domain · high confidence

New maintenance audit script and Windows setup utility

Added a new \scripts/audit-patterns.sh\ tool that scans the patterns directory for maintenance issues, including thin or bloated pattern files, stale vendor model references (e.g., GPT-4, ChatGPT), missing input markers, i18n locale key gaps, and shell completion mismatches. Also introduced \scripts/setup\_fabric.bat\ to automate the installation of Fabric on Windows, handling prerequisites like Go and Git via Chocolatey, and prompting for API keys.

scripts · high confidence

One-line installer scripts for Fabric

Users can now install Fabric using a single command on Unix/Linux/macOS (via bash) and Windows (via PowerShell). The new scripts in the installer directory automatically detect the operating system and architecture, download the latest release binary, extract only the necessary executable, and place it in a specified directory (defaulting to \~/.local/bin or %USERPROFILE%\\.local\\bin). The installation process includes verification of the binary and provides clear instructions for updating the PATH if the installation directory is not already included.

scripts/installer · high confidence

OpenAI plugin refactored with Responses API support, model caching, and audio/image capabilities

The OpenAI plugin has been restructured into multiple focused files, introducing support for the new OpenAI Responses API alongside the existing Chat Completions API. Model discovery is now cached locally for 24 hours to reduce rate-limit errors, with a fallback to direct API fetching for non-standard providers. The plugin now supports audio transcription with parallel chunk processing and image generation via the Responses API, including tool-based workflows for search and image output. Streaming responses are handled with structured updates, and error messages are localized via i18n. Tests cover caching behavior, model fetching, audio validation, and image generation tool configuration.

internal/plugins/ai/openai · high confidence

Project migrates to Go with Nix build support and comprehensive documentation

The project has been rewritten in Go, replacing the previous Python implementation, and introduces a Nix flake for reproducible development and packaging (including a \fabric-slim\ variant and a full package bundling \yt-dlp\). To support this transition, the repository now includes a \.goreleaser.yaml\ configuration for building binaries across Linux, macOS, and Windows, alongside a complete overhaul of the documentation: the main \README.md\ and a new \README.zh.md\ (Chinese) provide updated installation guides, usage instructions, and feature lists reflecting the new architecture and supported AI providers.

(repo-wide) · high confidence

YAML configuration support and secure desktop notifications

Users can now persist CLI settings by providing a YAML configuration file via the new --config flag, with CLI arguments taking precedence over YAML values and defaults. The CLI also introduces cross-platform desktop notifications upon command completion, which can be customized via a --notification-command flag; this feature uses secure positional argument passing to prevent shell injection when executing custom notification scripts.

internal/cli · high confidence

Security

Introduce filesystem-backed storage with path traversal protection

The internal plugin database now uses a new filesystem-based storage implementation (fsdb) for patterns, sessions, and contexts. This change introduces strict validation for storage names, rejecting path traversal attempts (e.g., \..\, \/etc/passwd\) and Windows-specific reserved names (e.g., \CON\, \NUL\) to prevent unauthorized file access. It also adds atomic writes with exclusive file locking for \.env\ configuration updates to ensure data integrity during concurrent access, and supports custom pattern directories via the \CUSTOM\_PATTERNS\_DIRECTORY\ environment variable.

internal/plugins/db · high confidence

Behavioural changes

Azure OpenAI plugin now uses the openai-go SDK with Entra ID authentication support

The Azure AI plugin has been rewritten to use the official \openai-go/azure\ SDK, replacing the previous implementation. This change introduces a new \AzureEntra\ client variant that authenticates using Azure Entra ID (via \azidentity\) instead of API keys, while the standard Azure client continues to support API key authentication. Both clients now default to the \2025-04-01-preview\ API version if not explicitly configured and use a shared middleware to correctly inject deployment names into API request paths (e.g., \/openai/deployments/{name}/chat/completions\). The plugin also adds support for newer models like GPT-5 and o-series reasoning models, which are automatically detected to enable raw mode when necessary.

internal/plugins/ai/azure · high confidence

CLI error output redirected to stderr

The Fabric CLI now writes errors and streaming output to standard error (stderr) instead of standard output. This ensures that error messages do not interfere with command output when the CLI is used in scripts or piped to other tools, improving reliability for automation workflows.

cmd/fabric · high confidence

Case-insensitive vendor and model name matching

The AI plugin now handles vendor and model names in a case-insensitive manner, allowing users to specify vendors (e.g., "openai", "OpenAI") and models (e.g., "gpt-4o", "GPT-4O") without worrying about exact capitalization. The \VendorsManager\ stores and looks up vendors using lowercase keys, and the \VendorsModels\ component provides utilities to filter vendors and find specific model names regardless of case. This ensures that user input is matched correctly against the available AI providers and their models.

internal/plugins/ai · high confidence

Centralized GitHub token retrieval utility

A new utility function, GetTokenFromEnv, has been added to the changelog generation tool to standardize how GitHub authentication credentials are obtained. This function implements a specific precedence order for token resolution: it first checks a provided token argument, then falls back to the GITHUB\_TOKEN environment variable, and finally to the GH\_TOKEN environment variable. This change ensures consistent token handling across the tool's operations.

_cmd/generate\changelog/util · high confidence

Expanded provider support and improved model discovery for OpenAI-compatible plugins

The OpenAI-compatible plugin now supports a wider range of providers, including new additions like Abacus, Infermatic, MiniMax, and Z AI, alongside updated configurations for existing ones. Model discovery has been significantly enhanced: the system now attempts a standard SDK fetch first, then falls back to direct API calls for non-standard formats, and supports static model lists or custom endpoints (such as Abacus RouteLLM) for providers that do not support standard model listing. Additionally, error messages during model fetching now include provider names and response body details to aid troubleshooting, and the client structure has been refactored to propagate context and improve HTTP client reuse.

_internal/plugins/ai/openai\compatible · high confidence

Gemini plugin upgraded to new genai SDK with TTS, search, and thinking support

The Gemini plugin has been migrated to the new \google.golang.org/genai\ SDK, enabling dynamic model listing and support for the \gemini-2.5-flash-preview-tts\ model for text-to-speech audio output. Users can now enable web search with location validation, configure Gemini's thinking capabilities (low, medium, high, or custom token budgets), and receive responses with formatted source citations. The update also includes a curated list of selectable TTS voices and fixes for message role mapping and streaming stability.

internal/plugins/ai/gemini · high confidence

Git file fetching now uses a CLI fallback and displays localized error messages

The \FetchFilesFromRepo\ function in the \githelper\ tool now attempts to clone repositories using the \go-git\ library first, and automatically falls back to the system \git\ CLI if that fails, improving compatibility in environments where the Go library may struggle (such as DNS resolution issues on Termux). Additionally, all error messages generated during this process have been replaced with internationalization (i18n) translation keys, ensuring users see properly localized feedback in their supported language.

internal/tools/githelper · high confidence

LM Studio plugin adds optional API key authentication and structured streaming

The LM Studio AI plugin now supports optional API key authentication, automatically attaching a Bearer token to requests when a key is configured, and implements structured streaming that exposes token usage metadata (input, output, and total tokens) alongside content updates during chat completions.

internal/plugins/ai/lmstudio · high confidence

New utility functions for path resolution and grouped item selection

The internal/util package now includes new helper functions to improve configuration handling and user interface consistency. GetAbsolutePath resolves file paths by expanding tilde (\~) and symlinks, while GetDefaultConfigPath locates the default configuration file at \~/.config/fabric/config.yaml with improved error handling. Additionally, a new GroupsItemsSelector utility provides case-insensitive sorting and selection for grouped items, ensuring consistent ordering in user-facing lists.

internal/util · high confidence

Plugin setup now allows resetting required settings without validation errors

Users can now clear previously entered required configuration values during the plugin setup process by entering 'reset', which clears the value without triggering a validation error. This change also introduces a standardized \NewVendorPluginBase\ factory to simplify vendor plugin initialization and moves the default \NeedsRawMode\ implementation to the base plugin struct, while adding comprehensive tests for these behaviors.

internal/plugins · high confidence

Refactored CLI tooling with modular defaults, language settings, and robust pattern loading

The internal tools package has been restructured to support modular command handling and improved configuration management. A new defaults plugin now allows users to select and verify AI models via an interactive setup process, while a dedicated language plugin enables setting the output language with automatic tag validation. The patterns loader has been significantly enhanced to prevent temporary directory leaks by creating temp folders only during population and ensuring cleanup even on failure, and it now preserves custom user patterns when updating from the remote repository. These changes are backed by new tests verifying the safe handling of temporary files and configuration states.

internal/tools · high confidence

YouTube tool now supports optional API keys and configurable visual extraction

The YouTube tool has been refactored to make the YouTube API key optional, allowing users to extract transcripts without authentication while still supporting comments and metadata when a key is provided. Additionally, the tool now supports visual extraction using FFmpeg and Tesseract, with configurable CLI flags for parameters like concurrency and timeouts. The implementation also introduces smart subtitle language fallbacks, improved timestamp parsing (including fractional seconds), and better error handling for VTT parsing and duplicate segments.

internal/tools/youtube · high confidence

Dependencies

Initial dependency manifests for Go backend and SvelteKit web frontend

The project now includes its first dependency manifests, establishing the baseline for the Go backend and the SvelteKit web frontend. The Go module (go.mod) defines the backend stack, requiring Go 1.26.0 and pinning key libraries such as the Anthropic SDK (v1.67.0), OpenAI Go SDK (v1.12.0), AWS SDK for Bedrock, and Ollama. The web frontend (web/package.json) initializes the client-side stack with Svelte 5, Vite 8, Tailwind CSS, and Shiki, while also introducing security overrides for several npm packages (e.g., qs, form-data, esbuild) to mitigate known vulnerabilities.

(dependencies) · high confidence

Web UI scaffold and configuration overhaul

The web application has been restructured with a new SvelteKit-based scaffold, introducing a modernized development and runtime environment. This includes a new \.browserslistrc\ file to enforce support for recent browser versions (Chrome/Firefox/Edge ≥89, Safari ≥15), a \pnpm-workspace.yaml\ to manage package resolution and enforce security overrides for vulnerable transitive dependencies (such as \qs\, \cookie\, and \esbuild\), and a \vite.config.ts\ extension that increases the proxy timeout to 15 minutes. The project now utilizes Tailwind CSS 4 for styling, configured via \app.css\ and \tailwind.config.ts\, and integrates the Skeleton UI library with a new set of theme imports (including 'rocket' and 'nouveau'). Additionally, the repository now includes a \dependabot.yml\ for automated weekly dependency updates, a \prettierrc\ for Svelte-aware code formatting, and an \eslint.config.js\ to standardize linting rules for the new stack.

web · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 58 → 60 (+1.6)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 88 → 88 (-0.1)
  • Architecture 90 → 89 (-1.1)
  • Maturity 80 → 80 (+0.4)
  • Readiness 44 → 51 (+7.1)
  • Security 70 → 71 (+1.2)
  • Accessibility 63 → 55 (-7.2)

Resolved (50)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (cmd/generate_changelog/internal/git/walker.go)
  • Duplicated block (10 lines × 2) (internal/plugins/ai/anthropic/anthropic.go)
  • Duplicated block (10 lines × 2) (internal/plugins/ai/azureaigateway/backend_bedrock.go)
  • Duplicated block (10 lines × 2) (internal/plugins/template/extension_manager.go)
  • Duplicated block (10 lines × 2) (internal/server/ollama.go)
  • Duplicated block (10 lines × 2) (internal/tools/spotify/spotify.go)
  • Duplicated block (10 lines × 2) (internal/tools/spotify/spotify.go)
  • Duplicated block (11 lines × 2) (internal/plugins/ai/azure/azure.go)
  • Duplicated block (11 lines × 2) (internal/plugins/ai/perplexity/perplexity.go)
  • Duplicated block (11 lines × 2) (internal/plugins/ai/perplexity/perplexity.go)
  • Duplicated block (12 lines × 2) (cmd/generate_changelog/internal/github/client.go)
  • Duplicated block (12 lines × 2) (internal/plugins/ai/gemini/gemini.go)
  • Duplicated block (12 lines × 2) (internal/plugins/ai/gemini/gemini.go)
  • Duplicated block (12 lines × 2) (internal/plugins/ai/lmstudio/lmstudio.go)
  • Duplicated block (12 lines × 2) (internal/plugins/ai/perplexity/perplexity.go)
  • Duplicated block (12 lines × 3) (internal/plugins/ai/lmstudio/lmstudio.go)
  • Duplicated block (12 lines × 4) (internal/plugins/ai/lmstudio/lmstudio.go)
  • Duplicated block (13 lines × 2) (internal/plugins/ai/anthropic/anthropic.go)
  • …and 30 more

New (130)

  • +server.POST (cognitive 18) (web/src/routes/chat/+server.ts)
  • ChatHandler.HandleChat (cyclomatic 19) (internal/server/chat.go)
  • ChatService.createMessageStream (cognitive 18) (web/src/lib/services/ChatService.ts)
  • ClassTooLong: YouTube (internal/tools/youtube/youtube.go)
  • Client.ensureAccessTokenLocked (cognitive 18) (internal/plugins/ai/codex/auth_transport.go)
  • Client.ensureAccessTokenLocked (cyclomatic 16) (internal/plugins/ai/codex/auth_transport.go)
  • Coverage not measured — JavaScript/TypeScript suite
  • Dependency pinned to a stale untagged commit: github.com/kballard/go-shellquote
  • Deprecated module: github.com/go-shiori/go-readability
  • Documentation: hard to navigate (data/patterns/detect_silent_victims/README.md)
  • Documentation: hard to navigate (data/patterns/explain_math/README.md)
  • Duplicated block (10 lines × 2) (cmd/generate_changelog/internal/git/walker.go)
  • Duplicated block (10 lines × 2) (internal/plugins/ai/azure/azure.go)
  • Duplicated block (10 lines × 2) (internal/plugins/ai/openai/chat_completions.go)
  • Duplicated block (10 lines × 2) (internal/plugins/template/file.go)
  • Duplicated block (10 lines × 2) (internal/tools/spotify/spotify.go)
  • Duplicated block (10–11 lines × 3) (cmd/generate_changelog/internal/git/walker.go)
  • Duplicated block (11 lines × 2) (internal/plugins/ai/azureaigateway/backend_bedrock.go)
  • Duplicated block (11 lines × 2) (internal/plugins/ai/perplexity/perplexity.go)
  • Duplicated block (11 lines × 2) (internal/server/ollama.go)
  • …and 110 more

Changes since last survey

  • 45 commits — 33 feature/other, 12 fixes

By area

  • cmd/generate_changelog — 20 commits
  • (repo) — 12 commits
  • (root) — 4 commits
  • internal/i18n — 4 commits
  • internal/plugins — 2 commits
  • web/src — 2 commits
  • internal/tools — 1 commit

Notable commits

  • fix: Merge branch 'main' into fix/sse-utf8-stream-boundary
  • fix: Merge pull request #2200 from ksylvan/fix/codex-oauth-token-persist
  • fix: Merge pull request #2203 from pacocartones/fix/sse-utf8-stream-boundary
  • fix: Merge pull request #2206 from ksylvan/fix/storage-path-traversal
  • fix: Merge pull request #2211 from ksylvan/fix-left-behind-tempdir
  • fix: Merge pull request #2216 from ctbaum/fix/gpt-6-raw-mode
  • fix: fix(web): preserve multi-byte UTF-8 split across SSE chunks in chat stream
  • fix: fix: enable raw mode for GPT-6 models
  • fix: fix: persist refreshed Codex tokens and reactivate configured vendors
  • fix: fix: preserve split UTF-8 characters in streaming responses
  • fix: fix: prevent pattern loader temporary directory leaks
  • fix: fix: secure storage paths and authenticate REST and Ollama servers
  • change: Merge branch 'main' into add-synthorai-provider
  • change: Merge pull request #2198 from cuihuan/add-synthorai-provider
  • change: Merge pull request #2209 from kadiryildiz283/feat/add-turkish-locale
  • change: Merge pull request #2210 from ksylvan/add-pzero-to-vendors
  • change: Merge pull request #2220 from jiweiyeah/feat/add-y-api-provider
  • change: Merge pull request #2224 from ksylvan/github-models-retired
  • change: chore(release): Update version to v1.4.471
  • change: chore(release): Update version to v1.4.472
  • …and 25 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

danielmiessler/Fabric was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit e16762852f9a51388418fa365958e311b7679177 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.