HKUDS/nanobot
58.0
Adequate · 26 September 2026
180.6k
lines of production code
Python
with TypeScript
3
measurements over time
What this system is
Nanobot is a self-hosted, containerized AI agent framework that connects users to large language models through a wide variety of chat channels, including Slack, Discord, Telegram, WhatsApp, and email. It provides a unified interface via a React-based WebUI and a TypeScript terminal UI, enabling users to manage sessions, configure providers, and monitor token usage. The system features a plugin-based architecture for channels and tools, supporting file editing, CLI execution, and scheduled automations, while ensuring security through SSRF protection and strict access controls.
Features
Add Feishu channel setup and management UI
The Feishu channel now includes a dedicated web interface for configuration and management. Users can connect their Feishu account via a QR code scan flow, manage multiple assistant instances, and adjust settings such as group behavior policies, topic isolation, and allowed users. The interface supports multiple languages and provides clear status indicators for connection state.
nanobot/channels/feishu/webui · high confidence
Add Matrix channel support with end-to-end encryption and SAS verification
Users can now connect the bot to Matrix (Element) rooms. This new channel package provides full inbound sync and outbound message delivery, including support for end-to-end encryption (E2EE) and Secure Agreement Signaling (SAS) verification flows. It handles media uploads/downloads with size limits, processes Markdown and HTML content safely, and manages room joins and typing indicators. Configuration allows specifying the homeserver, authentication method (password or access token), and policies for group access and streaming.
nanobot/channels/matrix · high confidence
Add PWA support with service worker and manifest
The web UI now supports installation as a Progressive Web App on mobile devices. A new manifest.json defines the app identity, icons, and standalone display mode, while a new service worker (sw.js) handles precaching of static assets, manages icon caching for public requests, and ensures stale entries are pruned during activation to keep the offline shell consistent with the latest build.
webui/public · high confidence
Add QQ channel integration
This change introduces a new QQ channel plugin, enabling users to connect their QQ bot accounts to Nanobot. The implementation includes a setup manifest defining required credentials (appId, secret) and optional configuration options such as message format (plain or markdown), acknowledgment messages, and attachment handling settings. The runtime leverages the qq-botpy SDK to handle inbound C2C and group messages, supporting chunked attachment downloads with memory-safe streaming and outbound rich media messaging. It also implements robust WebSocket reconnection logic with exponential backoff to handle network instability, and includes URL validation for inbound attachments to prevent security issues like redirect-based attacks.
nanobot/channels/discord, nanobot/channels/mochat, nanobot/channels/qq · high confidence
Add QQ channel web UI configuration and localization
The QQ channel now includes its own self-contained web UI contribution, providing a branded logo, display name, and color scheme in the settings interface. Users can configure the channel by entering App ID and Secret credentials, restricting access via allowed Open IDs, and choosing between plain text or Markdown message formats. The setup flow is supported by localized strings in ten languages (English, Spanish, French, Indonesian, Japanese, Korean, Portuguese (Brazil), Vietnamese, Simplified Chinese, and Traditional Chinese), ensuring the configuration fields and help links are presented in the user's preferred language.
nanobot/channels/qq/webui · high confidence
Add Signal channel support
This change introduces a new Signal channel, allowing users to connect their Signal account via the signal-cli REST API. The implementation includes a setup manifest defining configuration fields such as phone number, daemon host/port, and allowlist policies for direct messages and groups, along with a runtime module that handles message parsing, markdown-to-Signal formatting, and table rendering.
nanobot/channels/signal · high confidence
Add Telegram channel support with rich message streaming
This change introduces the Telegram channel integration, allowing users to connect their bots via the WebUI. It includes full setup validation (token and proxy verification), support for both polling and webhook modes, and enables rich message streaming with in-place updates. The implementation handles Telegram-specific constraints, such as splitting long messages while preserving fenced code blocks and escaping HTML.
nanobot/channels/telegram · high confidence
Add WeCom (Enterprise WeChat) channel support
Users can now connect their WeCom (Enterprise WeChat) bot to Nanobot. This new channel uses a WebSocket long connection, so no public IP or webhook URL is required. It supports receiving and replying to text, images, voice, files, and mixed content, and includes a 200 MB download limit for media safety. Setup requires a Bot ID and Secret from the WeCom AI Bot platform, with optional configuration for allowed users and a welcome message. The channel is available in the WebUI setup flow with localized labels in English, Spanish, French, Indonesian, Japanese, Korean, Portuguese (Brazil), Vietnamese, Simplified Chinese, and Traditional Chinese.
nanobot/channels/wecom · high confidence
Add WhatsApp channel with QR-based linking and media support
This change introduces a new, self-contained WhatsApp channel plugin. It provides a WebUI-driven QR code linking flow (via \connect.py\ and \WhatsAppConnectFlow.tsx\) that manages linked-device sessions, handles database state, and supports configuration for proxies, allowed contacts, and group policies. The runtime (\runtime.py\) implements message handling and outbound media sending using the \neonize\ library, while \manifest.py\ registers the channel and its dependencies (\neonize\, \segno\). Comprehensive tests are included to verify connection, cancellation, and media handling behaviors.
nanobot/channels/whatsapp · high confidence
Add internationalization (i18n) support with a locale switcher
The web UI now supports multiple languages, including Brazilian Portuguese (pt-BR) alongside English, Simplified/Traditional Chinese, French, Japanese, Korean, Spanish, Vietnamese, and Indonesian. Users can switch languages via a new locale switcher, with the selection persisted in local storage and applied to the document language attribute. The system uses lazy-loaded translation resources for performance and includes fallback logic to English for unsupported or malformed locale inputs.
webui/src/i18n · high confidence
Discord channel WebUI configuration and localization
The Discord channel's WebUI settings panel is now self-contained, providing a dedicated interface for configuring bot tokens, proxy connections, access controls (allowed users and channels), and group behavior policies. This change includes full localization support for the setup fields across ten languages (English, Spanish, French, Indonesian, Japanese, Korean, Portuguese, Vietnamese, Simplified Chinese, and Traditional Chinese), ensuring users can configure the Discord integration in their preferred language.
nanobot/channels/discord/webui · high confidence
Email channel web UI setup and localization
The email channel's web UI configuration has been introduced, providing a self-contained setup interface for connecting to IMAP and SMTP servers. This includes built-in presets for Gmail, Outlook, and iCloud to auto-fill connection details, along with fields for managing sending/receiving credentials, polling intervals, and security options like DKIM/SPF verification. The interface is fully localized into English, Spanish, French, Indonesian, Japanese, Korean, Portuguese (Brazil), Vietnamese, and Chinese (Simplified and Traditional).
nanobot/channels/email/webui · high confidence
Initial WebUI release with WebSocket chat, settings, and workbench
The WebUI is now available as a first-class interface, replacing the previous text-only or external access methods. This release introduces a full-featured chat experience powered by WebSocket streaming, complete with a sidebar for session management, a settings view for model and capability configuration, and a tabbed pane workbench for multi-file editing. Key features include support for temporary chats, i18n with a language switcher, PWA installation for mobile, and a redesigned settings interface with autosave. The UI also includes a composer with model preset switching, inline token usage visualization, and automation management views.
webui/src · high confidence
Initial WebUI source release with Vite development and PWA support
The \webui\ directory now contains the full React/TypeScript source code for the nanobot WebUI, enabling local development via Vite with Hot Module Replacement (HMR) and a new \nanobot webui --dev\ command. The frontend is built on React 18, Tailwind CSS, and shadcn/ui, and includes internationalization (i18n) support with a locale switcher. Additionally, the application now supports Progressive Web App (PWA) installation on mobile devices, with specific styling adjustments to keep iOS controls within the safe area.
webui · high confidence
Initial project scaffolding and Docker support
The repository is initialized with core project files including a Dockerfile, docker-compose configuration, and entrypoint script that enable containerized deployment with a non-root user and privilege dropping. Standard repository metadata and configuration files are added, including .gitignore, .dockerignore, .gitattributes, LICENSE, SECURITY.md, CONTRIBUTING.md, AGENTS.md, and THIRD\_PARTY\_NOTICES. A pytest conftest.py is introduced to provide test isolation fixtures for sessions, pairing stores, and logging.
(repo-wide) · high confidence
Initial release of the embedded WebUI with WebSocket chat and guided setup
The nanobot/web package now includes the initial WebUI assets, which are bundled into the distribution wheel and rebuilt automatically via the webui-build Hatch hook. This update introduces a WebSocket-based chat flow and guided setup flows for users, while also supporting local development through the Vite dev server.
nanobot/web · high confidence
Introduce DM sender approval pairing system
The nanobot/pairing module has been added to enable a chat-native approval workflow for Direct Message senders. This feature introduces a persistent store (pairing.json) that manages pending pairing codes and approved sender lists per channel, allowing users to approve DM access via a generated code. The implementation includes utilities for code generation, approval, denial, and revocation, ensuring that only authorized senders can interact with the bot on specific channels.
nanobot/pairing · high confidence
Introduce DingTalk channel with private chat control and group reply formatting
This change adds the DingTalk channel implementation to the product. Users can now connect their DingTalk workspaces via Stream Mode, with setup requiring a client ID and secret. The channel introduces a new configuration option, \disablePrivateChat\, allowing administrators to reject 1:1 direct messages while keeping group interactions active. In group chats, replies are prefixed with the sender's mention to improve context visibility. The implementation also handles file and image attachments, supports rich text formatting, and includes safeguards to prevent late inbound task creation during shutdown.
nanobot/channels/dingtalk · high confidence
Introduce Email channel with IMAP/SMTP support and authentication verification
Adds a new Email channel that polls an IMAP mailbox for inbound messages and sends replies via SMTP. The channel includes setup validation for connection settings and enforces anti-spoofing measures by verifying DKIM and SPF results, requiring a list of trusted authentication service IDs when these checks are enabled. Users can configure connection parameters, polling intervals, and post-action behaviors (such as deleting or moving processed emails).
nanobot/channels/email · high confidence
Introduce Feishu/Lark channel with multi-instance support and QR onboarding
This change adds a new Feishu/Lark channel to the product, enabling users to connect their Feishu or Lark workspaces. The implementation supports multiple instances per deployment, configurable via the settings UI, and uses a QR-code-based onboarding flow for secure authorization. It relies on the lark-oapi SDK for WebSocket long connections and includes dedicated configuration, validation, and runtime modules to manage instance specs and message routing.
nanobot/channels/feishu · high confidence
Introduce OpenAI Responses protocol provider implementation
Added a new provider backend in the \nanobot/providers/openai\_responses\ module that implements the OpenAI Responses API protocol. This includes converters to translate internal chat messages and tool schemas into the Responses API format, parsing logic for handling SSE streams and SDK response objects, and state management for preserving conversation context, reasoning content, and native compaction boundaries. This enables the application to interact with models supporting the Responses API while maintaining compatibility with existing chat history and tool usage patterns.
_nanobot/providers/openai\responses · high confidence
Introduce OpenAI-compatible HTTP API for nanobot
The nanobot application now includes a new OpenAI-compatible HTTP API server (located in nanobot/api) that exposes /v1/chat/completions and /v1/models endpoints. This server routes requests to a persistent API session, supporting both standard JSON responses and Server-Sent Events (SSE) streaming. It handles input validation, including support for user messages with media attachments via JSON base64 and multipart/form-data, and captures LLM usage statistics to return in the response. The API is managed by a background process runtime that isolates state and logs per configuration.
nanobot/api · high confidence
Introduce WeChat (Weixin) channel with QR-based login and streaming support
A new WeChat channel is now available, allowing users to connect their personal WeChat account via a QR code login flow managed through the WebUI. The channel uses the iLink HTTP API (protocol v2.4.6) without requiring a local WeChat client, supporting text, media, and tool calls. It includes features like streaming responses, message splitting for long content, and automatic session recovery after token expiry. Users can configure connection parameters such as base URLs, polling timeouts, and streaming behavior through the channel setup interface.
nanobot/channels/weixin · high confidence
Introduce agent core module with proactive session auto-compaction
The nanobot/agent package now exposes a central entry point that aggregates the core agent components (loop, hooks, context, memory, skills, and subagent management). A key addition is the AutoCompact module, which proactively archives idle sessions to reduce token costs and latency by consolidating history when sessions exceed a configurable TTL, while respecting active task states and Dream session boundaries.
nanobot/agent · high confidence
Introduce background gateway runtime and OS service management
This change adds a new \nanobot/gateway\ module that provides a background runtime for managing the shared local gateway process. It introduces lifecycle management features, including health checks, state persistence, and client lease tracking, to ensure stable operation. Additionally, it adds service installation and management capabilities for Linux (systemd) and macOS (launchd), allowing the gateway to run as a persistent background service or system agent.
nanobot/gateway · high confidence
Introduce decoupled message bus for channel-agent communication
The nanobot/bus module now provides a dedicated asynchronous message bus that decouples chat channels from the agent core. It defines structured InboundMessage and OutboundMessage types, along with a suite of typed runtime events (such as progress, streaming, and turn completion) that are routed through the bus. This architecture allows channels to push user messages and receive responses or status updates independently, while the core publishes state transitions without waiting for network delivery.
nanobot/bus · high confidence
Introduce dedicated WebSocket channel for WebUI connectivity
The WebUI now uses a dedicated, self-contained WebSocket channel package to manage client connections. This change introduces a new server-side runtime that handles authentication (including trusted proxy assertions and token issuance), isolates slow clients to prevent memory bloat, and ensures reliable message delivery via bounded outbound queues. Users benefit from a more robust and secure real-time connection layer that is now explicitly configured and validated within the channel system rather than being implicitly managed by the gateway.
nanobot/channels/websocket · high confidence
Introduce dedicated components for file previews, attachments, and session management
The WebUI now features a suite of new components to enhance media handling and session organization. Users can view files and images through a dedicated FilePreviewPanel with syntax highlighting and lightbox support, while the AttachmentTile component standardizes the display of images, videos, and generic files in messages. Session management is improved with a redesigned ChatList that supports drag-and-drop grouping, persistent sidebar ordering, and visual session handles. Additionally, the interface now includes a ConnectionBadge to display real-time WebSocket status and a DeleteConfirm dialog that warns users about linked automations before deletion.
webui/src/components · high confidence
Introduce dedicated session management module
The \nanobot/session\ package has been introduced to centralize and improve session lifecycle management. This new module provides a robust \SessionManager\ and \Session\ class for handling conversation history, including durable recovery for interrupted WebUI turns, support for explicit sustained goals via the \/goal\ command, and the ability to assign readable, pronounceable session handles. It also introduces helpers for managing automation turn visibility, session-scoped model presets, and summary checkpoints, ensuring that internal or automated history entries are properly hidden from the user while maintaining data integrity across storage migrations and file operations.
nanobot/session · high confidence
Introduce high-level Python SDK with session, memory, and streaming APIs
The nanobot Python SDK now exposes a high-level interface for managing agent sessions, long-term memory, and runtime controls. Users can ingest, export, restore, and delete session transcripts via the SessionClient, read and write persistent memory files via the MemoryClient, and control the active model and workspace via the RuntimeClient. The SDK also provides Cursor/OpenAI-style event streaming through RunStream, allowing applications to consume real-time text, reasoning, and tool events during agent turns.
nanobot/sdk · high confidence
Introduce nanobot Python SDK and agent framework
This release introduces the nanobot Python SDK, providing a programmatic facade for running the agent via the Nanobot class and its from\_config() constructor. It adds a new event system for transport-independent notifications, a runtime context mechanism for appending persistent context to prompts, and a cross-platform process runtime for managing background agent processes. The package also includes a CLI entry point, a Pydantic-based configuration base, and support for optional features and environment variable interpolation in config secrets.
nanobot · high confidence
Introduce native Linear agent channel
Adds a new Linear channel that lets users connect their Linear workspace via OAuth, enabling the agent to receive @mention requests and post responses as Linear activities. The channel includes a WebUI setup flow, member-level access controls, and a local webhook listener for real-time event processing.
nanobot/channels/linear · high confidence
Introduce native Linear agent channel with workspace authorization and member access controls
This change adds the WebUI components for the new native Linear agent channel, enabling users to connect their Linear workspaces via OAuth, manage connected workspaces, and control which team members can use the agent without pairing codes. The update includes a dedicated setup panel for configuring OAuth credentials and webhook endpoints, a connection flow for authorizing workspaces, and a member access interface that allows administrators to search, refresh, and toggle access for individual Linear users. It also provides a reset connection feature to revoke all workspace authorizations and clear app settings, along with localized help content and UI strings in English, Spanish, and French.
nanobot/channels/linear/webui · high confidence
Introduce plugin-based tool discovery and runtime context protocol
The agent tools module has been restructured to support a plugin-based discovery system and a new runtime context protocol. This change introduces a formal \ToolContext\ and \RequestContext\ to pass per-request data (such as channel, chat ID, and session key) into tools, enabling context-aware execution. It also adds a \ToolLoader\ and \ToolRegistry\ to manage tool instantiation and lifecycle, alongside a new \Schema\ base class for standardized parameter validation. New tools and capabilities introduced in this area include a \CronTool\ for scheduling reminders, a \CliAppsTool\ to run installed CLI applications, an \ApplyPatchTool\ for structured multi-file edits, and a \WindowsJob\ helper to manage subprocess trees on Windows.
nanobot/agent/tools · high confidence
Introduce session-bound cron jobs with run history and timezone support
The nanobot/cron module now supports scheduling agent tasks that are bound to specific user sessions, ensuring replies are delivered back to the originating chat context. This change introduces a new CronService that persists job definitions and execution history to jobs.json, including support for cron expressions with timezone validation. It also adds run history tracking, allowing users to view per-run automation replies and details in the WebUI, while migrating legacy cron payloads to the new session-bound format for reliable routing.
nanobot/cron · high confidence
Introduce session-bound local triggers with persistent delivery queue
The \nanobot/triggers\ module now supports local triggers that are bound to a specific session. This adds a persistent store (\LocalTriggerStore\) for managing trigger definitions and a delivery queue that safely processes trigger events as session turns, including recovery of interrupted deliveries and run auditing. Deliveries are deferred until the session is idle to avoid mixing with live user input, and the system enforces channel enablement checks before processing.
nanobot/triggers · high confidence
Introduce shared nanobot/utils package with document extraction, artifact persistence, and Git-backed memory
This change introduces the new \nanobot/utils\ package, consolidating shared utilities previously scattered across the codebase. It adds document text extraction for PDF, DOCX, XLSX, and PPTX files with safety limits, artifact persistence for generated images, and a Git-backed version control system (\GitStore\) for memory files. The package also includes helpers for file-edit progress events, LLM runtime configuration, logging, and legacy module aliases to ensure backward compatibility.
nanobot/utils · high confidence
Introduce structured runtime notifications for context compaction, recovery, and retry status
The client-events package now defines and validates a unified set of runtime notifications that clients can consume to reflect backend state changes. This includes context compaction phases (started, succeeded, failed, cancelled), recovery state transitions (resuming, awaiting user, recovered, failed), and model retry status updates (waiting, recovered, cleared, exhausted). A new decoder validates these events and ensures terminal history rows do not regress when older live events arrive, providing users with accurate, real-time feedback on chat processing, error recovery, and connection retries.
packages/client-events · high confidence
Introduce tabbed workbench with resizable pane layouts
The workbench now supports a tabbed interface where users can organize content into multiple panes within a single tab. This change introduces a new \PaneWorkbench\ component and associated layout logic (\workbench-layout.ts\) that enables resizable, draggable panes arranged in various configurations such as columns, rows, grid, BSP, and main-stack. Users can switch between these layout modes via the UI controls, and the system preserves pane grouping and split ratios across sessions, allowing for flexible, multi-view workflows within the workbench area.
webui/src/components/workbench · high confidence
Introduce tmux skill for interactive CLI control
Added a new tmux skill that enables remote control of tmux sessions for interactive command-line interfaces. The skill includes a documentation file (SKILL.md) detailing usage for sending keystrokes, scraping pane output, and orchestrating parallel coding agents, along with helper scripts to find sessions across sockets and wait for specific text patterns in panes. This allows the system to manage interactive TTYs on macOS and Linux by creating isolated tmux sockets, sending commands, and monitoring output via pane capture.
nanobot/skills/tmux · high confidence
Introduce unified CLI Apps system with registry integration and safe execution
This change introduces the \nanobot.apps.cli\ module, providing a unified system for managing, installing, and executing CLI-based applications. It integrates with external registries (CLI-Anything and Nanobot Extensions) to discover tools, handles installation via pip/uv, and enforces security by isolating subprocess environments and preventing API key leakage. Users gain access to a catalog of CLI tools that can be invoked safely within the agent loop, with support for brand logos, workspace policies, and structured metadata for seamless integration.
nanobot/apps/cli · high confidence
Introduces new thread UI components for activity, navigation, and context management
Adds a suite of new React components to the thread view: AgentActivityCluster for rendering agent tool calls and file edits, PromptRail and PromptNavigator for navigating user prompts, ComposerUsagePopover for displaying token usage, and notices for context compaction, model fallbacks, stream errors, and task recovery. Also includes AssistantSelectionAction for quoting text and ModelPresetBadge for switching models.
webui/src/components/thread · high confidence
Mattermost channel setup UI and localization
The Mattermost channel now provides a dedicated web UI configuration interface, allowing users to set connection details (server URL, team ID, token) and fine-tune behavior policies. Users can independently configure how the bot responds in channels versus threads (mention-only, all messages, or allowlist), manage allowed users and channels, and enable features like direct messages, streaming, and emoji reactions. This change also adds complete localization support for the setup flow in English, Spanish, French, Indonesian, Japanese, Korean, Portuguese (Brazil), Vietnamese, Simplified Chinese, and Traditional Chinese.
nanobot/channels/mattermost/webui · high confidence
Native TUI build, packaging, and smoke-test tooling added
The tui/scripts directory now provides the tooling to build, package, and verify the native TypeScript terminal UI. build.ts compiles the TUI for supported platforms (darwin-arm64/x64, linux-arm64/x64, win32-x64) using Bun, enforcing platform boundaries and avoiding AVX2-only binaries on x64. prepare-target.ts installs the correct @opentui/core native packages for the target. package-release.py assembles self-contained release archives with third-party notices, licenses, and source archives, validating the pinned OpenTUI version. Smoke tests (pty\_smoke.py for POSIX and conpty\_smoke.py for Windows) exercise real terminal boundaries, verifying Unicode input, resize handling, alternate-screen restoration, and the session-resume command output.
tui/scripts · high confidence
Native terminal UI and Desktop integration for the CLI
The CLI now launches a native TypeScript-based terminal UI (TUI) by default for interactive chat, replacing the legacy Python prompt. Users can still access the classic prompt via the new --classic flag. The CLI also discovers and attaches to an already-running Nanobot Desktop instance via a local rendezvous protocol, allowing seamless switching between the Desktop and the terminal client. This change introduces new modules for TUI launching, Desktop target discovery, and gateway lifecycle management, while preserving backward compatibility for non-interactive and legacy usage patterns.
nanobot/cli · high confidence
New Microsoft Teams and NapCat (QQ) channel integrations
This update introduces two new built-in channel plugins. The Microsoft Teams integration provides a DM-focused MVP with a built-in HTTP webhook server, supporting text messaging, conversation reference persistence, sender allowlists, and optional inbound Bot Framework bearer-token validation. The NapCat integration connects to QQ via the OneBot v11 WebSocket protocol, offering configurable group reply policies (mention-only, open, or allowlist), new-member welcome messages, and image download capabilities. Both channels include full WebUI setup forms with localized labels in English, Spanish, French, Indonesian, Japanese, Korean, Portuguese (Brazil), Vietnamese, Simplified Chinese, and Traditional Chinese.
nanobot/channels/msteams · high confidence
New SSRF protection and workspace access controls
This change introduces a new security module in nanobot/security that adds Server-Side Request Forgery (SSRF) protection and workspace access controls. The network utilities now validate URLs against a blocklist of private and internal IP ranges (including IPv6-mapped IPv4 addresses and unspecified addresses) and support a configurable whitelist for specific CIDR ranges. Additionally, workspace access is enforced via path boundary checks, ensuring file operations remain within allowed project roots or specific allowed files, with support for system-level sandboxing status reporting.
nanobot/security · high confidence
New TypeScript TUI replaces Python client with comprehensive session, command, and media features
The terminal UI has been rewritten in TypeScript (Bun), introducing a full-featured interface that supersedes the previous Python client. This new TUI supports interactive slash command discovery and completion, session branching and navigation, and explicit follow-up queue management. It handles rich media input by allowing users to paste clipboard images (up to 4 per message) and large text blocks, which are managed via compacted placeholders to keep the composer responsive. The interface includes a context panel for token usage visibility, runtime controls for agent interaction, and a command menu for local actions like detaching or exiting. It also integrates with a 'Desktop' host for secure credential resolution and connection pinning, ensuring the UI remains responsive during long-running agent turns by coalescing updates and yielding to input.
tui/src · high confidence
New WebUI hooks for attachment handling, session state, and UI management
This change introduces a suite of new React hooks in the webui/src/hooks directory to power the updated chat interface. Key additions include useAttachedImages and useClipboardAndDrop for managing file and image uploads with size limits and MIME validation, useNanobotStream for handling real-time chat streaming and message projection, and useSessions for managing session history and continuity. The update also brings useSidebarState for sidebar persistence, useSkills for skill marketplace integration, useComposerMentionInput for advanced text input with undo/redo, and useFilePreviewState for managing file preview tabs. Additional hooks like useTheme, useMediaQuery, and usePageVisibility enhance the user interface responsiveness and theming capabilities.
webui/src/hooks · high confidence
New activity timeline components for file edits, reasoning, and tool runs
The thread activity view now uses a set of new, dedicated components to render agent actions more clearly. File edits display a collapsible unified diff with syntax highlighting and added/deleted line counts. Reasoning steps show a compact preview with a streaming indicator and a completion animation. Generic tool runs, web searches, and MCP browser actions are presented with status-aware icons, localized labels, and redacted sensitive data. These components replace the previous flat rendering, providing a structured, interactive activity timeline.
webui/src/components/thread/activity · high confidence
New configurable speech-to-text transcription service with multiple provider support
The audio module now includes a new transcription service that allows users to configure speech-to-text capabilities. This service supports multiple providers including Groq, OpenAI, OpenRouter, Xiaomi MiMo, StepFun, AssemblyAI, and SiliconFlow. Users can select their preferred provider, configure API keys and base URLs, and set parameters like model selection, language, and file size limits. The service handles audio validation, temporary file management, and dispatches to the selected provider's adapter.
nanobot/audio · high confidence
New configuration module with safe loading, atomic writes, and runtime watching
The \nanobot/config\ package has been introduced to centralize configuration management. It provides safe, user-friendly error reporting that redacts sensitive values in validation failures, and ensures \config.json\ is written atomically to prevent corruption. The system now supports runtime file watching to detect configuration changes, automatic timezone detection for agent defaults, and path helpers for managing instance-specific data directories.
nanobot/config · high confidence
New model and provider settings management interface
The model settings area has been restructured into a dedicated, domain-separated component suite (ModelsSettings, ProviderSettings, and associated hooks) to support a unified, autosave-enabled settings experience. This change introduces a searchable provider setup panel with OAuth authorization flows, inline preset name conflict detection, and atomic preset renames. Users can now manage model presets with immediate saveability, configure custom context window token budgets, and adjust provider-specific capabilities like OpenAI's fast mode or hosted search tools directly within the settings UI.
webui/src/components/settings/models · high confidence
New overview settings page with model, capability, and about sections
The settings interface now includes a dedicated Overview section that provides a centralized view of the current AI model, enabled capabilities (web search, image generation, voice input), and account information. Users can quickly see the status of these features and navigate to specific configuration pages. The section also displays token usage, version check results, and links to documentation, source code, and issue reporting, along with a prompt to star the project.
webui/src/components/settings/overview · high confidence
New shared UI component library for consistent web interface elements
The web UI now includes a new set of shared components (alert dialog, button, combobox, dialog, disclosure, dropdown menu, expandable text, floating portal/surface, form control, input, popover, segmented control, select, sheet, textarea, and tooltip) built on Radix UI primitives. These components provide a unified visual style, consistent focus rings, and standardized animations, ensuring a cohesive look and feel across the application.
webui/src/components/ui · high confidence
New shared settings components and auto-save logic
The settings interface now uses a new set of shared UI components located in webui/src/components/settings/shared, including ModelControls for provider and model selection, SettingsControls for dialogs and status messages, SettingsFeature for toggleable sections, SettingsHint for tooltips, SettingsTextEditor for editing long text, and TimezonePicker for timezone selection. Additionally, a new useAutoSave hook has been introduced to automatically save settings changes after a short delay, improving the user experience by reducing manual save actions.
webui/src/components/settings/shared · high confidence
New system settings components for Apps, Automations, Channels, and MCP management
The system settings area now includes dedicated UI components for managing system-level configurations. AppsSettings provides a catalog interface for installing and managing CLI apps and MCP presets, including OAuth flows and custom transport configuration. AutomationsSettings introduces a calendar view and task list for scheduling and monitoring automation jobs, with detailed run history and error inspection. ChannelsSettings offers a searchable, filterable list of available chat channels with setup panels. McpManagementDialog allows granular control over MCP server connections, tool selection, and status monitoring. RuntimeConfigSettings enables editing of runtime configuration fields with autosave and validation. These components replace or supplement previous system settings implementations with a more structured, feature-rich interface.
webui/src/components/settings/system · high confidence
Skill creator scripts now include validation and packaging utilities
The skill-creator scripts now provide a validation tool (quick\_validate.py) that checks SKILL.md frontmatter and structure, and a packaging script (package\_skill.py) that bundles validated skills into distributable .skill files, ensuring only allowed resource directories are included and symlinks are rejected.
nanobot/skills/skill-creator/scripts · high confidence
Unified LLM usage tracking and WebUI attachment ingress
The application now records content-free LLM usage metrics (tokens, duration, provider, model, and source) into a local SQLite store, making usage data available for visualization in the WebUI. Additionally, the WebUI now enforces strict validation and size limits on inbound message attachments (images, videos, and documents) before persisting them, ensuring that only allowed MIME types and file sizes are accepted.
nanobot/webui · high confidence
WeChat channel setup and connection UI
The WeChat (Weixin) channel now includes a dedicated web interface for configuration and connection. Users can manage channel settings through a new settings panel that supports primary and advanced configuration fields, and the connection flow handles QR code scanning, including a specific verification step for re-authentication when the login expires. The UI is fully internationalized, with locale files provided for English, Spanish, French, Indonesian, Japanese, Korean, Portuguese (Brazil), Vietnamese, Simplified Chinese, and Traditional Chinese.
nanobot/channels/weixin/webui · high confidence
WebUI core library initialization
The WebUI frontend now includes a comprehensive set of core library modules in \webui/src/lib\ to support the new chat interface. This includes \activity-timeline.ts\ for projecting and rendering message turns and agent activity, \ansi.ts\ for parsing and styling terminal-style text, \api.ts\ for handling gateway communication and mutations, and \bootstrap.ts\ for managing authentication secrets and WebSocket connections. Additional utilities cover session grouping (\chat-groups.ts\), composer draft persistence (\composer-draft.ts\), mention text handling (\composer-mention-text.ts\), file diff parsing (\file-diff.ts\), and image encoding via Web Workers (\imageEncode.ts\).
webui/src/lib · high confidence
Architecture
Introduce native LLM provider registry with lazy loading and conversation state management
The \nanobot/providers\ module now provides a structured, lazy-loaded registry for LLM backends, replacing ad-hoc imports with a declarative system that instantiates providers only when needed. This location introduces the core provider implementations (Anthropic, OpenAI-compatible, Azure OpenAI, AWS Bedrock, and others) along with a \ProviderConversationStateController\ that manages durable provider-private state and transcript boundaries to ensure reliable session resumption and compaction. The \FallbackProvider\ wrapper is also included here, enabling transparent failover to alternative models when the primary provider encounters transient errors, while the \factory\ module handles configuration resolution and provider instantiation.
nanobot/providers · high confidence
Introduce plugin-based channel architecture with declarative setup contracts
The channel subsystem has been refactored to use a self-contained plugin system where each chat platform (e.g., Telegram, Discord, Slack) is defined by a manifest declaring its runtime, dependencies, and setup requirements. This change introduces a standardized configuration schema with typed fields, validation rules, and instance support, allowing the WebUI and CLI to uniformly discover, validate, and configure channels without hardcoding platform-specific logic.
nanobot/channels · high confidence
Behavioural changes
Channel plugins now self-register UI contributions and localized setup strings
The channel plugin system has been refactored to make built-in channels self-contained. New modules in \webui/src/channel-plugins\ automatically discover and register each channel's UI components (panels, connect flows, help content) and localized setup messages via dynamic imports. This ensures that every concurrently loaded channel's locale is properly registered and that setup flows are organized with autosave capabilities, improving the consistency and reliability of the channel configuration experience.
webui/src/channel-plugins · high confidence
File edit activity tracking and cancellation handling
The agent now observes file-editing tool calls to emit start, end, and error events to the WebUI, providing users with progress visibility into file modifications. Additionally, if an agent run is cancelled while a file-edit tool is active, the system now explicitly emits an error event to ensure the UI clears the in-progress edit state rather than leaving it hanging.
nanobot/agent/hooks · high confidence
Introduce structured slash command routing and built-in handlers
The \nanobot/command\ module now provides a dedicated routing layer for slash commands, replacing ad-hoc parsing with a structured system that normalizes transport-specific suffixes (e.g., \@bot\ in Telegram/Discord) and dispatches commands via priority, exact, and prefix matching tiers. This change introduces built-in handlers for commands such as \/new\, \/compact\, \/stop\, \/restart\, \/status\, \/model\, \/history\, \/goal\, \/trigger\, \/dream\, \/skill\, and \/help\, each defined with specific lifecycles (e.g., side-channel, stop active turn) to control UI state and agent turn behavior. The router also includes validation logic to reject invalid or unknown commands with helpful suggestions, ensuring a consistent and robust command experience across all channels.
nanobot/command · high confidence
Mattermost channel now supports separate group policies for threads and channels
The Mattermost channel implementation has been refactored to allow independent configuration of group policies for direct channel interactions versus threaded replies. Users can now specify distinct policies (e.g., 'mention' for channels and 'open' for threads) via the new \groupPolicyInThread\ setting, while the system automatically preserves compatibility with existing configurations by inheriting the main group policy if no thread-specific override is provided. This change also introduces a self-contained package structure for the channel, including updated manifest definitions and runtime logic to handle these distinct policy scopes.
nanobot/channels/mattermost · high confidence
Native TUI bundled into platform wheels and installer hardened for externally managed environments
Users on desktop platforms now receive the native terminal UI (TUI) directly within the Python wheel, eliminating the need for separate binary downloads or manual setup steps. The installer scripts (install.sh and install.ps1) have been updated to detect and handle externally managed Python environments by suggesting or using isolated tools like uv or pipx, and the installation wizard is automatically skipped when running in non-interactive terminal sessions.
scripts · high confidence
New agent configuration templates for workspace, identity, and memory
The \nanobot/templates\ directory now provides a structured set of Markdown files that define how the agent behaves and stores information. \AGENTS.md\ guides the agent on workspace conventions, specifically instructing it to use the built-in \cron\ tool for reminders and \HEARTBEAT.md\ for periodic background checks rather than one-time memory entries. \HEARTBEAT.md\ serves as the active task list for the gateway's protected heartbeat cron job, which skips execution if no active tasks are present. \SOUL.md\ establishes the agent's persona as friendly and curious, emphasizing short responses and honesty. \USER.md\ offers a profile template for personalizing interactions, while \memory/MEMORY.md\ is designated for long-term facts that persist across sessions.
nanobot/templates · high confidence
Redesigned channel setup and management interface
The channel settings area has been rebuilt with a new guided setup flow, replacing the previous implementation. Users now encounter a unified catalog view (ChannelCatalogRow) for installing and enabling channels, alongside a structured setup panel (ChannelSetupPanel) that organizes configuration into logical sections (Account, Credentials, Connection, etc.) via ChannelCredentialFields. The update introduces support for multiple channel instances (ChannelInstancesPanel), QR-code-based connection flows (ChannelQrConnectFlow), and real-time validation progress indicators (ChannelValidationProgress). Brand logos are now handled with fallbacks (ChannelIdentity), and help resources are accessible via a dedicated help menu (ChannelHelpMenu).
webui/src/components/settings/channels · high confidence
Redesigned settings interface with new capabilities and usage tracking
The settings page has been completely restructured into a new layout featuring a sidebar navigation (Overview, Appearance, Models, Capabilities, System, Advanced, About) and a main content area. This update introduces dedicated configuration sections for Skills (including a new Skills Marketplace for discovering and installing skills), Image Generation (with provider and model selection), and Transcription. It also adds a comprehensive Token Usage dashboard that visualizes daily token consumption, cache hit rates, and usage breakdowns by source (Chat, API, Automations, Memory) and model over the last 30 days. Existing settings for Models, Providers, and Automations have been integrated into this new unified view.
webui/src/components/settings · high confidence
Self-contained UI setup flows for DingTalk, Matrix, Signal, and Slack
The web UI configuration panels for DingTalk, Matrix, Signal, and Slack are now self-contained within their respective channel directories. Each channel now provides its own \index.ts\ defining the setup fields (such as credentials, connection details, and access policies) and localized \locales\ files for setup labels and placeholders. This change moves the presentation and configuration logic for these channels directly into their plugin folders, ensuring the setup experience is bundled with the channel definition rather than relying on external or shared configuration sources.
(repo-wide) · high confidence
Slack channel refactored into a self-contained package with improved security and formatting
The Slack channel implementation has been restructured into a self-contained package (nanobot/channels/slack) to improve maintainability and isolation. This change introduces stricter security controls by validating file download URLs against Server-Side Request Forgery (SSRF) risks before transmission. It also fixes message formatting issues, ensuring that fenced Markdown tables are preserved correctly when converted to Slack's mrkdwn format, and resolves a threading bug where channel thread openers were incorrectly scoped across sessions.
nanobot/channels/slack · high confidence
Telegram channel WebUI now exposes proxy and connection settings
The Telegram channel's WebUI configuration panel has been updated to include fields for network proxy configuration (allowing users to specify a proxy URL) and connection mode selection (long polling or webhook). This change, part of making built-in channels self-contained, also adds localized labels for these new fields alongside existing settings like bot token, allowed users, and group behavior across English, Spanish, French, Indonesian, Japanese, Korean, Portuguese, Vietnamese, and Chinese locales.
nanobot/channels/telegram/webui · high confidence
Test coverage
Added comprehensive test suite for the Discord channel integration; Added comprehensive test suite for the WebSocket channel; Added regression tests for cron job persistence, execution safety, and tool schema contract; Added security tests for SSRF protection and workspace access controls; Added test coverage for DingTalk channel configuration and message handling; Added test coverage for QQ channel runtime and ack behavior; Added test coverage for Signal channel runtime and markdown conversion; Added test coverage for Telegram channel configuration and runtime behavior; Added test coverage for WebUI activity, automation, and bootstrap logic; Added test coverage for agent tools; Added test coverage for email channel authentication and validation; Added test coverage for the message bus event system; Added test coverage for utility functions; Added tests for CLI Apps service, tool, and utility logic; Added tests for CLI subprocess environment isolation; Added tests for Linear channel WebUI setup and configuration; Added tests for Matrix channel configuration validation and runtime behavior; Added tests for Slack channel message threading and configuration validation; Added tests for Weixin channel connection, state persistence, and hardening; Added tests for gateway service installation and runtime lifecycle; Added tests for local trigger store and queue behavior; Added tests for the native Linear channel; Added unit tests for built-in slash commands; Added unit tests for the Mattermost channel implementation; Added unit tests for the pairing store module; Comprehensive test coverage for tools module; Expanded CLI test coverage for interactive agent, input handling, and desktop integration; Expanded provider test coverage for Anthropic, Azure, Bedrock, and caching logic; Expanded test coverage for API, SDK, and agent features; Expanded test coverage for WebUI and LLM usage subsystems; Expanded test coverage for agent plugins, auto-compaction, and attachment handling; Expanded test coverage for channel infrastructure and specific integrations; Expanded test coverage for config loading, saving, and migration logic; Test coverage for session persistence, recovery, and state management.
Dependencies
Initial dependency manifests for nanobot-ai, TUI, and WebUI
The project introduces its primary dependency configuration files: \pyproject.toml\ defines the Python package \nanobot-ai\ (v0.3.5) with core libraries like \anthropic\, \openai\, \pydantic\, and \prompt-toolkit\, alongside optional extras for API, Azure, Bedrock, and document handling. The \tui/package.json\ sets up the terminal UI with \@opentui/core\, while \webui/package.json\ and its lockfile establish the web interface using React, Tailwind CSS, and Radix UI components.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 44 → 58 (+13.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 70 → 65 (-4.3)
- Architecture 86 (new)
- Maturity 70 → 76 (+5.8)
- Readiness 18 → 48 (+29.4)
- Security 70 → 77 (+7.0)
- Accessibility 61 (new)
Resolved (41)
- Coverage not measured — test suite did not build
- Critical CVE: [GHSA redacted] (webui/bun.lock)
- Critical CVE: [GHSA redacted] (webui/bun.lock)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (webui/package-lock.json)
- High CVE: [GHSA redacted] (webui/bun.lock)
- High CVE: [GHSA redacted] (webui/bun.lock)
- High CVE: [GHSA redacted] (webui/bun.lock)
- High CVE: [GHSA redacted] (webui/bun.lock)
- High CVE: [GHSA redacted] (webui/bun.lock)
- High CVE: [GHSA redacted] (webui/bun.lock)
- High CVE: [GHSA redacted] (webui/bun.lock)
- High IaC: DS-0002 (Dockerfile)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 21 more
New (1278)
- (anonymous) (cognitive 21) (webui/public/sw.js)
- (anonymous) (cyclomatic 17) (webui/public/sw.js)
- AgentActivityCluster.ActivityTraceRow (cognitive 22) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.AgentActivityCluster (cognitive 17) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.CliRunRow (cognitive 20) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.CliRunRow (cyclomatic 16) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.FoldedAgentActivity (cognitive 47) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.FoldedAgentActivity (cyclomatic 44) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.McpRunRow (cognitive 19) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.collectCliRuns (cognitive 16) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.collectMcpRuns (cognitive 16) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentActivityCluster.countActivity (cognitive 18) (webui/src/components/thread/AgentActivityCluster.tsx)
- AgentLoop.init (cognitive 20) (nanobot/agent/loop.py)
- AgentLoop.init (cyclomatic 19) (nanobot/agent/loop.py)
- AgentLoop._aclose_unlocked (cognitive 17) (nanobot/agent/loop.py)
- AgentLoop._build_turn (cognitive 35) (nanobot/agent/loop.py)
- AgentLoop._build_turn (cyclomatic 29) (nanobot/agent/loop.py)
- AgentLoop._dispatch_one (cognitive 39) (nanobot/agent/loop.py)
- AgentLoop._dispatch_one (cyclomatic 28) (nanobot/agent/loop.py)
- AgentLoop._persist_user_message_early (cognitive 19) (nanobot/agent/loop.py)
- …and 1258 more
Changes since last survey
- 300 commits — 104 feature/other, 196 fixes
By area
- webui/src — 114 commits
- nanobot/channels — 57 commits
- nanobot/agent — 38 commits
- tests/agent — 18 commits
- (root) — 8 commits
- nanobot/providers — 8 commits
- nanobot/cli — 7 commits
- tests/tools — 7 commits
- nanobot/webui — 6 commits
- tests/cli — 6 commits
- nanobot/utils — 5 commits
- tui/src — 5 commits
- .github/workflows — 3 commits
- nanobot/api — 3 commits
- nanobot/cron — 2 commits
- docs/chat-commands.md — 1 commit
- docs/cli-reference.md — 1 commit
- docs/configuration.md — 1 commit
- docs/guides — 1 commit
- docs/multiple-instances.md — 1 commit
Notable commits
- fix: fix(agent): complete automation cancelled before execution
- fix: fix(agent): discard stopped follow-up recovery journal
- fix: fix(agent): keep tool results stable across replay (#5695)
- fix: fix(agent): log mid-turn injected messages (#5878)
- fix: fix(agent): preserve per-session message order
- fix: fix(agent): preserve queued turn semantics and completion
- fix: fix(agent): preserve state for required Codex compaction (#5883)
- fix: fix(agent): redact private recovery and reconnect diagnostics
- fix: fix(agent): remove local context tail truncation (#5820)
- fix: fix(agent): report background task failures
- fix: fix(agent): respect temporary chat privacy in tool execution
- fix: fix(agent): run explicit recovery continuations
- fix: fix(agent): serialize session inbox processing
- fix: fix(api): preserve nullable stream compatibility
- fix: fix(api): require boolean stream values
- fix: fix(channels): drop compaction notices on channels without an in-place affordance (#5799)
- fix: fix(channels): keep the compaction outcome visible, gate only the start notice
- fix: fix(channels): make automatic compaction notices follow send_progress
- fix: fix(cli): explain session storage conflicts before startup
- fix: fix(cli): harden attach-only Desktop selection [skip ci]
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
HKUDS/nanobot was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit f62e0da9f6ac7a02fdd056bb2c19c58365952956 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-09659c52afae.