JuliusBrussee/caveman
54.8
Adequate · 25 September 2026
121.6k
lines of production code
Go
with TypeScript, JavaScript, Python
5
measurements over time
What this system is
Caveman is a local-first platform designed to reduce AI coding agent costs by compressing context and optimizing token usage before requests reach upstream providers. It provides a suite of tools including a compression engine, a reverse proxy for traffic interception, and SDKs that integrate with major coding agents and frameworks. The system enables lossy but recoverable context reduction, local browser interaction, and durable agent memory, all while maintaining strict security and cross-platform compatibility.
Features
Added build scripts for the Pi extension
A new build script (bundle.mjs) has been added to the packages/pi-extension/scripts directory. This script uses esbuild to bundle the extension's source code (src/index.ts and src/testable.ts) into ESM format for Node.js 22, outputting the results to the dist directory.
packages/pi-extension/scripts · high confidence
Anthropic provider adapter introduces prompt-cache optimization and content compression
The new Anthropic adapter in the proxy now supports two key optimizations: it can automatically inject Anthropic prompt-cache breakpoints (on the last tool or system block) or a top-level automatic cache marker to improve cache hit rates for pay-as-you-go sessions, and it implements content compression by identifying and compressing the 'live' (uncacheable) tail of conversation messages while preserving the frozen prefix. These changes allow the proxy to reduce upstream token costs and bandwidth usage for Anthropic requests without altering the model-visible output.
proxy/providers/anthropic · high confidence
Caveman 2.0.0 release with new proxy routing, Azure validation, and token counting
This release introduces the Caveman 2.0.0 engine, including a new proxy layer with advanced routing capabilities (cascade, benchmark, and confidence-based selection), strict Azure OpenAI API version validation, and robust token counting logic for Anthropic and Gemini providers. It also adds SDKs and a unified CLI to manage these features.
(repo-wide) · high confidence
Caveman Mode browser extension launches with directive injection and per-site controls
The Caveman Mode browser extension is now available, adding a short instruction to outgoing messages on ChatGPT, Claude, and Gemini to encourage compact, high-density replies. The extension operates locally with no network requests or analytics, storing only user preferences (on/off toggle, intensity level, and active sites) in chrome.storage.sync. Users can control the feature via a popup interface that allows toggling the mode, selecting intensity levels (lite, full, ultra), and enabling/disabling the extension on specific supported sites. The extension uses content scripts to intercept the send gesture and prepend the directive before submission, with the injected text remaining visible in the chat. The extension is built as a Manifest V3 extension with no build step required for installation.
extension · high confidence
Caveman hooks now support per-session mode state and per-agent model overrides
The Caveman hooks have been restructured to track the active mode per Claude Code window (session) rather than globally, preventing one window from overriding another's mode choice. The system now stores session state in \$CLAUDE\_CONFIG\_DIR/.caveman-sessions/\<session\id\>.mode\ while maintaining a legacy mirror for compatibility. Additionally, users can now pin specific models for per-agent tasks (reviewer, builder, investigator) using environment variables (\CAVECREW\\*\_MODEL\), which are applied via a new \cavecrew-model-overrides.js\ hook that safely patches agent frontmatter without modifying source checkouts. The hooks also include improved resilience against missing sibling files and better handling of Windows-specific edge cases.
src/hooks · high confidence
Caveman init tool now supports idempotent updates and multiple IDE agents
The new \caveman-init.js\ tool allows users to install the Caveman activation rule across various IDE agents (Cursor, Windsurf, Cline, Copilot, OpenCode, and OpenClaw) in an idempotent manner. It uses fenced markers for shared files to safely refresh or remove the rule without corrupting user content, and handles atomic writes to prevent corruption during interrupted runs. The tool also respects the \--force\ flag for refreshing existing rule files and supports a \--dry-run\ mode for previewing changes.
src/tools · high confidence
Firefox packaging and verification tooling
The extension build process now supports a dedicated Firefox target. A new build script stages shared runtime files flat at the root to comply with WebExtensions restrictions, swaps in a Firefox-specific manifest, and packages the result into a zip file. A verification script enforces a strict allowlist of shippable files and validates that content-script CSS does not use relative URLs that would fail when injected into third-party pages. An end-to-end test script automates the installation of the staged build in a real Firefox instance via web-ext to verify content script injection.
extension/scripts · high confidence
Initial release of Caveman 2 with split licensing and new engine architecture
This change introduces the initial codebase for Caveman 2, establishing a split-license model where the core skill, CLI, and SDKs remain MIT, while the new compression engine, proxy, and related Go modules are licensed under Business Source License 1.1 (BSL-1.1). The repository now includes the foundational structure for the compression engine (\engine/\), a provider proxy (\proxy/\), and a unified installer (\bin/install.js\) that supports over 30 AI coding agents. Documentation files such as \README.md\, \INSTALL.md\, and \LICENSING.md\ define the product's value proposition of reducing input tokens via local compression and clarify the commercial boundaries of the engine-linked runtime.
(repo-wide) · high confidence
Initial release of the Caveman CLI package
The \@caveman-ai/cli\ package is now available, providing the \caveman\ (and \cave\) command-line interface for wrapping coding agents to enable local metering and context compression. The CLI is a TypeScript application with zero runtime dependencies, relying on companion Go binaries for heavy lifting like compression and streaming recovery. Key capabilities include agent wrapping (\caveman claude\), an interactive local setup score and improvement guide (\caveman learn\), a private offline dashboard for token and cost statistics (\caveman stats\), and secure authentication via OS keychain or credential files. The package includes build scripts, documentation, and a publishing workflow for both the JS CLI and signed Go binary companions.
packages/cli · high confidence
Introduce @caveman-ai/agent SDK with sandboxed execution, budget controls, and framework adapters
The new \@caveman-ai/agent\ package provides an opinionated TypeScript framework for building production agents. It introduces a strict tool sandbox that isolates untrusted code in OS-level network namespaces (Linux/macOS) and enforces Node permission models, while offering an explicit 'host' mode for interactive coding agents that runs in-process. The runtime includes deterministic circuit breakers to detect loops and fan-out limits, alongside a budget system that enforces best-effort USD or token caps using a public provider catalog. It also ships with exact-pinned adapters for Vercel AI SDK (7.0.43), Eve (0.29.2), and Mastra (1.55.0) to execute locked agent builds, and supports a local 'Caveman Engine' for context compression and telemetry, degrading gracefully to 'observe-only' mode when the engine is unavailable.
packages/agent · high confidence
Introduce Caveman Engine with local context compression and byte-exact recovery
The Caveman Engine is a new local component that detects content types (JSON, code, logs, tables, etc.) and applies safety-classed compression to reduce context size before sending it to an AI model. It stores the original bytes in a local SQLite recovery store (CCR) so that lossy transformations can be retrieved byte-for-byte later. The engine exposes a stable four-call API (Compress, Retrieve, Detect, Stats) shared by the proxy, CLI, SDKs, and WASM build, and ships with 15 built-in compressors including JSON, code, logs, diffs, search results, text, HTML, tables, config, tool schemas, tool-schema annotations, TOON, accessibility trees, repetition, and terminal output. It runs locally without a Caveman account, uses inferred token reduction estimates, and enforces a 512 MiB default storage budget for recovery payloads.
engine · high confidence
Introduce Caveman MCP server for reversible compression recovery
Adds the Caveman MCP server, a local stdio JSON-RPC adapter that exposes five tools (caveman\_compress, caveman\_retrieve, caveman\_stats, caveman\_toon\_encode, caveman\_toon\_decode) to MCP hosts like Claude Code and Cursor. The server links the Caveman Engine in-process to provide lossy but fully reversible compression, allowing agents to recover elided content via recovery handles. It uses a shared file-based recovery store by default (configurable via CAVEMAN\_CCR\_DB or CAVEMAN\_HOME) to ensure recovery handles remain valid across process restarts and host compaction, while strictly reporting inferred metrics and maintaining zero network egress.
mcp · high confidence
Introduce Caveman Mode to intercept and modify chat messages
Adds a new 'Caveman Mode' feature that intercepts the send gesture on supported chat platforms (ChatGPT, Claude, Gemini) to prepend a directive to outgoing messages, enforcing a terse, article-dropping writing style. The implementation includes a content script (caveman.js) with robust, per-site DOM selectors to locate editors and send buttons, a directive builder (directive.js) for generating style instructions, and a background script (background.js) to manage the extension's enabled state and toolbar badge. A visual indicator (indicator.css) is also added to show the mode's status in the chat interface.
extension/src · high confidence
Introduce Caveman native extension for Pi with context compression and recovery
Adds the \@caveman-ai/pi\ extension, which integrates the Pi coding agent with the Caveman native runtime to provide context compression and recovery. The extension registers a \caveman\_retrieve\ tool to recover original content from compression handles, routes model traffic through a local proxy gateway for byte-stable compression, and bridges lifecycle events (session start, tool use) to the native runtime. It includes Windows-safe command resolution for spawning the Caveman CLI and MCP binary, robust error handling to prevent extension failures from crashing the host, and strict validation of provider routing to ensure only supported endpoints are compressed.
packages/pi-extension/src · high confidence
Introduce Python middleware package with native framework adapters
The \packages/middleware/python\ directory now contains the \caveman-middleware\ Python package (version 0.1.0a1), providing native adapters for frameworks like Agno and Anthropic, as well as an ASGI middleware for explicit LLM routes. This package enables compression and recovery capabilities by intercepting provider calls and streaming responses, while enforcing strict version ranges for supported framework dependencies.
packages/middleware · high confidence
Introduce benchmarking suite to measure Caveman's token savings
A new benchmarking suite has been added to the project to quantify the cost and efficiency improvements of the Caveman skill. The suite includes a Python runner (\benchmarks/run.py\) that executes a set of predefined coding and debugging prompts against the standard Claude assistant, a 'terse' control instruction, and the Caveman skill, then calculates output token savings. It also features a charting script (\benchmarks/render\_charts.py\) that generates static SVG visualizations of these savings for the documentation. The implementation addresses security concerns by strictly limiting environment variable loading to the \ANTHROPIC\_API\_KEY\ and fixes cross-platform encoding issues to ensure reliable execution on Windows and macOS.
benchmarks · high confidence
Introduce caveman middleware for request compression and recovery
The proxy now includes a new middleware component that compresses request segments to reduce token usage without requiring an inference hop. This feature adds HTTP endpoints for optimizing requests, retrieving original content via recovery handles, and submitting usage receipts. It enforces strict JSON-only access on loopback, validates request schemas and capabilities, and manages scoped retention and recovery state to ensure data integrity and cost verification.
proxy/internal/middleware · high confidence
Introduce caveman-browse: local browser interaction via MCP tools
Adds the \caveman-browse\ module and CLI, providing a local browser-interaction MCP server that attaches to Chrome, reads the accessibility tree, compresses it using the engine's \a11y\ compressor, and exposes \browser\_snapshot\, \browser\_act\, \browser\_eval\, and \browser\_recover\ tools. The package includes a Node.js launcher (\caveman-browse.mjs\) and a binary installer (\binary-installer.generated.mjs\) that handles cross-platform installation, signature verification, and safe file replacement. The Go driver (\cdp.go\) manages Chrome sessions via CDP, enforcing bounded actionability (same-origin, predictable controls) and handling cross-platform process detachment. The change also includes comprehensive integration tests (\cdp\_integration\_test.go\, \main\_integration\_test.go\) verifying the snapshot-act-verify-recover loop, token efficiency, and cross-process state persistence, alongside documentation (\README.md\, \CLAUDE.md\, \BENCHMARK.md\) and licensing files.
browse · high confidence
Introduce caveman-shrink MCP middleware to compress tool descriptions
A new stdio proxy, caveman-shrink, is available to wrap any MCP server and compress prose fields (such as tool descriptions) in list responses. This reduces the token count the model must process without altering tool semantics or mutating request bodies and call responses. The proxy handles cross-platform spawning (including Windows .cmd shims), manages graceful shutdown with signal escalation, and can be configured via environment variables to target specific fields or enable debug logging.
src/mcp-servers · high confidence
Introduce cavemem: durable, cross-session agent memory with BM25 recall and token budgeting
The \mem\ area now ships \cavemem\, a durable memory system for agents that stores raw facts in a local SQLite database and retrieves them using deterministic BM25 ranking. Users can \remember\, \recall\, \supersede\, \history\, and \forget\ memories via a Go CLI (\cavemem\), an MCP server, or thin JS/Python clients. Recall results are compressed through the Caveman engine to provide honest inferred token costs, with a default 2000-token budget to prevent context overflow (oversized hits return a head plus a recovery handle). The system enforces a 256 KiB limit on individual memories and ensures byte-safe writes so no data is lost during compression.
mem · high confidence
Introduce local repository intelligence with deterministic evidence bundling
The proxy now includes a new local repository intelligence system (repointel) that builds deterministic maps of project source files and generates task-specific evidence bundles. This system restricts evidence to project source only, requiring direct path or symbol matches to qualify for model visibility, while filtering out dependency trees and sensitive content. It supports both CGO-based tree-sitter parsing and a conservative Go-AST fallback, ensuring consistent, reproducible results for local repository context.
proxy/internal/repointel · high confidence
Introduce native-pack v1 with mandatory Core instructions and six classified skills
The proxy now embeds a compiled native-pack (schema caveman.native-pack.v1, version 2.2.0) that enforces a mandatory Core instruction set and six classified skills—investigate-first, lean-build, migration, safe-refactor, surgical-patch, and verify-and-stop—each with defined entry/stop conditions, guardrails, and token budgets. The pack includes target-specific activation mappings for Claude, Codex, Hermes, Gemini, OpenCode, and Aider, and the Go loader validates schema identity, Core budget constraints, unique skill IDs, and conflict resolution before exposing a Select API that picks the highest-precedence skill for a given task type. Tests confirm the pack loads correctly, all six skills are present, selection works for known task types, and unknown types fail closed to Core.
proxy/internal/nativepack · high confidence
Introduce standalone \`caveman-proxy\` binary with BYOK and byte-safe transforms
The proxy location now ships a standalone, self-hosted reverse proxy binary (\caveman-proxy\) that allows users to intercept and transform LLM traffic locally without cloud dependencies. It supports Bring-Your-Own-Key (BYOK) authentication via \CAVEMAN\_AUTH\_TOKEN\, enforces strict SSRF protection on all upstream connections, and applies byte-safe provider-native transforms (such as compression and pixel mode) that fail open to pass-through on errors. The proxy records per-request spend to a local SQLite database, labeling all savings as 'inferred' rather than 'verified', and shares its provider adapter logic with the managed gateway.
proxy · high confidence
Introduce structured agent profiles and conformance tooling
The agents directory now includes a formal registry (\agents.json\) defining supported CLI agents (Aider, Claude Code, Codex, Gemini, Hermes, Kilo) with their installation commands, wire protocols, and environment injection settings. To support this, a new build-time compiler (\compile.mjs\) validates profiles against a JSON schema and generates CLI artifacts, while a probe script (\probe-installed.mjs\) checks installed binary versions against pinned versions. A drift-reporting tool (\drift-report.mjs\) automatically creates GitHub issues when upstream agent versions exceed the pinned tested versions, and a scope-checker (\check-profile-scope.mjs\) enforces CI lane boundaries for profile changes.
agents · high confidence
Introduce subagent-tax to measure coding harness prefix overhead
A new local measurement tool, subagent-tax, is available to quantify the size of the system prompt and tool schemas (the 'prefix') that coding harnesses like Claude Code, Codex, Gemini, and OpenCode send on every agent call. The tool runs a local HTTP sink to capture these first requests from installed harnesses, analyzes the JSON character counts, and reports the breakdown of system instructions versus tool schemas (including MCP plugin contributions where identifiable). It provides both estimated token counts (calibrated against Anthropic's tokenizer) and optional exact counts via Anthropic's API, while ensuring no provider API calls are made by default and sensitive data is redacted in the generated repro packs.
packages/subagent-tax · high confidence
Introduce token-compression evaluation harness with three-arm methodology
Adds a new evaluation suite in the \evals/\ directory to measure real token compression of skills by running prompts through Claude Code under three conditions: a no-prompt baseline, a terse control instruction, and the terse instruction plus a specific skill. The harness (\llm\_run.py\) captures real LLM outputs and snapshots them to \results.json\, while \measure.py\ calculates token savings using tiktoken and \plot.py\ generates interactive boxplots via Plotly. This design isolates the skill's specific contribution by comparing it against the terse control arm, correcting previous inflation issues, and provides median, mean, min, max, and standard deviation metrics to assess result reliability.
evals · high confidence
Introduces byte-level JSON splicing to preserve formatting and avoid re-encoding
Added a new \jsonsplice\ package that manipulates JSON responses at the byte level rather than decoding and re-serializing them. This allows the proxy to insert fields (such as cache markers) and replace values while preserving original whitespace, key order, and escape sequences. This change supports the fix for Bedrock providers by enabling precise insertion of cache markers without the side effects of standard JSON marshaling.
proxy/providers/jsonsplice · high confidence
Introduces secure, validated proxy run-state management
The proxy now maintains an out-of-band state file (JSON) to communicate its status to the CLI, ensuring safe interactions through strict validation. This state includes a unique instance token and process ID, which are verified against the running process and listener identity to prevent race conditions or trust issues with stale or foreign state. The implementation writes the state atomically with restricted file permissions (0600) and provides platform-specific process querying (Windows vs. non-Windows) to support these integrity checks.
proxy/internal/runstate · high confidence
Learn report detectors and store tests for cache, config, and outcome analysis
The store package now includes a suite of new detectors and corresponding tests that power the Learn report's behavioral insights. These changes add logic to measure and report on cache churn and efficiency, config file growth trends, MCP server tax, and session outcomes (specifically identifying sessions that produced no commits). The implementation includes a new \config\_scan.go\ for reading local agent configuration, \detect\_cache\_hygiene.go\ for analyzing cache usage patterns, \detect\_compaction.go\ for tracking context window compaction costs, \detect\_config\_trend.go\ for monitoring config file growth, \detect\_mcp\_tax.go\ for assessing MCP server overhead, and \detect\_outcomes.go\ for correlating sessions with repository commits. Tests verify the correct calculation of these metrics, including handling of legacy database migrations, budget constraints for git operations, and proper filtering of noise.
proxy/internal/store · high confidence
Native opencode plugin for Caveman mode management
A new native plugin for the opencode editor replaces the previous npx-skills fallback, enabling dynamic Caveman mode tracking directly within the opencode session. The plugin uses opencode's lifecycle hooks to write a mode flag on session start and intercepts user prompts to toggle modes via slash commands (e.g., /caveman, /caveman-compress) or natural language. It injects a per-turn reinforcement banner into the system prompt to keep the active mode in the model's attention, while relying on a separate AGENTS.md file for the base ruleset. The implementation is designed to be robust across environments, including compiled Bun runtimes and Windows, by defensively loading shared configuration and parsing helpers.
src/plugins/opencode · high confidence
Native runtime introduces deterministic session isolation, repository intelligence, and structured output handling
The proxy now includes a native runtime layer that manages local agent session state, providing deterministic behavior for tool outputs and repository context. It introduces a secure session key system with HMAC-signed markers to correlate sessions without leaking raw data, and implements repository intelligence that safely captures local git state (excluding untrusted fsmonitor hooks) to inform tool decisions. The runtime also enforces structured output handling, ensuring that large JSON, CSV, and log outputs are preserved for the elision engine rather than being masked, while still providing a recoverable reference for the agent. Additionally, it generates detailed session receipts that track execution metrics, policy usage, and provider cost data for transparency.
proxy/internal/nativeruntime · high confidence
New AWS Bedrock provider adapter with routing, signing, and cache support
The proxy now includes a dedicated AWS Bedrock provider adapter that enables routing to Bedrock Runtime and the opt-in Mantle endpoint, enforcing strict allowlists for regions, models, and actions. It handles AWS SigV4 signing over the exact upstream wire bytes, strips hop-by-hop headers, and supports both API-key and IAM authentication. The adapter also injects provider-native cache markers for Anthropic Claude models on supported endpoints and parses Bedrock-specific usage telemetry, including cache hit/write statistics.
proxy/providers/bedrock · high confidence
New CLI build, benchmarking, and release automation scripts
The CLI package now includes a suite of new build and utility scripts to support the Caveman 2.0 release. These scripts automate the bundling of the TUI, the PI extension, and the delegate agent into the distribution directory. A new benchmarking script measures the performance of native hooks against a target latency, while generation scripts create TypeScript constants for binary release versions and signing keys, and produce standalone wedge installers for various components. Finally, a shebang script ensures the main CLI entry point is executable.
packages/cli/scripts · high confidence
New Caveman Delegate tool for bounded subtasks
The agents/delegate area now includes a new stdio-based MCP server (caveman-delegate-mcp.mjs) that exposes a single 'caveman\_delegate' tool, allowing users to run bounded, mechanical subtasks (such as search, test runs, or log triage) in a token-efficient worker agent. This tool spawns a child process using a new portable-process.mjs module, which ensures cross-platform compatibility (Windows/macOS/Linux) by handling Windows command shims, process isolation, and safe cleanup. The delegate returns the worker's report along with provider-reported usage metrics (input/output tokens, cache reads/writes, and cost). Tests in portable-process.test.mjs verify the cross-platform process spawning and cleanup logic.
agents/delegate · high confidence
New OpenAI provider adapter with caching, compression, and token counting
The proxy now includes a new OpenAI provider adapter that introduces several capabilities to improve performance and cost tracking. It injects a stable \prompt\_cache\_key\ to increase cache-hit rates for long prompt prefixes, compresses live user and tool message content to reduce payload size, and implements accurate token counting for the Responses API by projecting requests to the dedicated input-tokens endpoint. Additionally, it offers an optional output-brevity feature to cap generation length and ensures data integrity by preventing integer rounding errors during JSON processing and rejecting malformed requests with trailing bytes.
proxy/providers/openai · high confidence
New agent skill registry and MCP client for CLI telemetry and workflow management
The CLI now includes a generated agent skill registry (\agent-skills.generated.ts\) and a native MCP client (\agent-mcp.ts\) that enable structured interaction with Caveman Cloud. The skill registry defines capabilities such as 'caveman' (output compression), 'caveman-discover' (workflow labeling), 'caveman-learn' (token cost reduction), and 'caveman-setup' (gateway wiring). The MCP client provides the underlying infrastructure for these skills, including a strict allowlist of trace fields to ensure metadata-only access and a set of report API paths for querying costs, savings, and usage.
packages/cli/src · high confidence
New build, installation, and verification tooling for the Caveman CLI and Go binaries
The scripts directory now includes a suite of new tooling to streamline building, installing, and verifying the Caveman platform. The \build-release-binaries.mjs\ script automates cross-platform compilation of six Go binaries (caveman-proxy, caveman-engine, caveman-mcp, cavemem, caveman-browse, caveman-shrink) for macOS, Linux, and Windows, generating SHA-256 checksums. Installation is simplified via \install-local-cli.sh\ and \install-local-cli.ps1\, which handle building the Node.js CLI, creating shims, and compiling the Go companions into a local home directory. To ensure data integrity, \sign-binary-checksums.mjs\ provides cryptographic signing and verification of the release artifacts. Additionally, \generate-agent-catalog.mjs\ automates the creation of the agent's pricing catalog from a central YAML source, and \probe-native-codex-recovery.mjs\ offers a sandboxed test harness for validating native Codex recovery on macOS. Windows compatibility is further secured by \test-windows-compat.mjs\, which runs a comprehensive suite of runtime and compilation tests.
scripts · high confidence
New caveman skills: cavecrew, caveman-commit, caveman-compress, caveman-discover, and caveman-evidence-review
This change introduces five new skills to the skills directory. The \cavecrew\ skill provides a decision guide for delegating tasks to three subagents (\cavecrew-investigator\, \cavecrew-builder\, \cavecrew-reviewer\) that return compressed output to save context. The \caveman-commit\ skill generates terse, conventional commit messages. The \caveman-compress\ skill compresses natural language memory files (like \CLAUDE.md\) into a shorter format to reduce input tokens, including a Python implementation with validation, locking, and backup management. The \caveman-discover\ skill helps identify and label LLM workflows in a repository for spend tracking. The \caveman-evidence-review\ skill provides a read-only interface to review Caveman Cloud data such as cost, scores, and traces.
skills · high confidence
New cross-platform installer libraries and OpenClaw integration support
The installer now includes robust, cross-platform libraries for command-line argument parsing, Windows command shim resolution, and platform-specific path handling, ensuring reliable execution across different operating systems. It introduces a new JSONC settings reader that safely handles comments and trailing commas without corrupting string values, and implements strict ownership management to prevent overwriting user files or symbolic links. Additionally, the installer now supports OpenClaw as a first-class agent target, managing its workspace and skill integration, while also fixing compatibility issues with the OpenCode agent by stripping invalid frontmatter fields.
bin/lib · high confidence
New framework-recipe registry for AI SDK integrations
The integrations area now ships a declarative recipe registry that provides one-line base-URL routing snippets for 12 AI SDKs and frameworks (including OpenAI, Anthropic, Google Gen AI, LangChain, LiteLLM, CrewAI, Vercel AI SDK, Pydantic AI, and curl). A zero-dependency build-time compiler (compile.mjs) validates these recipes against the provider pricing catalog and emits a published registry (recipes.json) along with embedded TypeScript copies for the CLI and the web app, ensuring that every shipped model ID is priced and correctly referenced.
integrations · high confidence
New shared device-auth package for OAuth 2.0 Device Authorization Flow
A new \packages/device-auth\ library has been added to support the OAuth 2.0 Device Authorization Grant flow. This package exposes a \runCavemanDeviceFlow\ function that handles the complete lifecycle: requesting a device code, polling for the access token, and managing retry logic (including backoff on \slow\_down\ errors). It returns a \DeviceGrant\ object containing the credentials and an \acknowledge\ method, which allows the application to confirm durable credential delivery to the server only after it has been safely persisted locally. The package includes TypeScript definitions, a build configuration, and unit tests for the polling interval logic and acknowledgement behavior.
packages/device-auth · high confidence
New shared platform libraries for AWS signing, credential resolution, and certificate handling
This change introduces a new \shared/platform\ package containing core infrastructure components for the Caveman engine. It adds \awssig\ for AWS Signature Version 4 request signing (used for Bedrock and S3) without external SDK dependencies, and \awscreds\ for resolving credentials from environment, web identity, container, and IMDSv2 sources with strict security controls to prevent secret leakage. It also includes \cabundle\ for building TLS trust pools from system stores and operator-supplied PEM files, and \cacheguard\ for detecting cache epoch drift and volatile content patterns. These libraries provide the foundational security and platform abstraction for the proxy's AWS integrations.
shared · high confidence
New wire contracts for agent builds, runs, and evaluation
This release introduces a comprehensive set of JSON Schema 2020-12 contracts in packages/shared/contracts to standardize cross-service and SDK data shapes. Key additions include schemas for immutable agent builds (cave-build), execution plans (cave-plan), and normalized trace spans (canonical-span) to support trace intelligence and replay. It also defines the agent-run-receipt for content-blind economic tracking (estimated costs, token usage, and spend caps) and the adapter-conformance record to verify static contract alignment across harnesses like Pi and Claude. Additionally, a grader registry schema and data file are added to define the 29 supported evaluation grader types, while existing policy and practice schemas are documented alongside new validation scripts to ensure schema integrity.
packages/shared/contracts · high confidence
Python SDK 1.1.0 adds middleware protocol client
The Python SDK (\caveman\_cloud\) has been updated to version 1.1.0, introducing a new \caveman\_cloud.middleware\ module. This addition provides a dependency-free protocol client that handles validation, deadlines, and receipts, serving as the foundation for \caveman-middleware\ adapters. The change is accompanied by a comprehensive cross-language conformance suite in \packages/sdk/parity\ (including \fixtures.json\ and specific middleware preflight/protocol fixtures) to ensure the Python SDK's wire contract and behavior remain identical to the TypeScript SDK.
packages/sdk · high confidence
Security
Introduces hardened Git execution to prevent arbitrary code execution in untrusted repositories
A new \gitsafe\ package has been added to safely execute Git commands against untrusted repository contents. This change prevents attackers from exploiting repository configuration (such as \core.fsmonitor\ or \core.hooksPath\) to execute arbitrary code when the proxy interacts with a user's working directory. The implementation hardens Git invocations by disabling dangerous configuration knobs, stripping inherited \GIT\\\ environment variables, and ensuring system-level configuration remains accessible to avoid ownership errors on shared systems.
proxy/internal/gitsafe · high confidence
Behavioural changes
28 commits (5 fixes) modifying dist
A change to existing behaviour in dist — 28 commits (5 fixs), 1 file.
dist · medium confidence · unverified
Caveman Compress skill introduces cross-platform stability and security hardening
The caveman-compress skill has been consolidated and updated to address critical cross-platform issues and security risks. It now prevents data loss and encoding errors on Windows and macOS by enforcing UTF-8 handling and atomic writes. Security is improved by blocking the compression of sensitive files (such as credentials, keys, and environment files) to prevent accidental data leakage. Additionally, the skill now correctly identifies and skips build files and scripts, ensuring they are not mistakenly treated as compressible prose.
plugins/caveman/skills/caveman-compress · high confidence
Gemini and Vertex provider adapters: content compression, token counting, and credential routing
The Gemini adapter now supports request content compression by extracting and rewriting only the latest user-turn text and function responses, while preserving byte-identical substitutions for earlier turns to maintain cache stability. It also adds token counting support for generateContent and streamGenerateContent endpoints. Credential handling is refined to resolve Google API keys from request headers and query parameters without overriding the resolved principal, ensuring that inbound query keys do not replace or augment a selected OAuth or API-key principal. The Vertex adapter introduces publisher and model allowlists (defaulting to Google and Anthropic) with environment variable overrides, validates upstream endpoints against SSRF constraints in production, and correctly routes accounting requests for both publishers. It also ensures that Application Default Credentials (ADC) are passed through statelessly without persistence, and that inbound query keys do not alter the resolved Vertex principal.
proxy/providers/gemini, proxy/providers/vertex · high confidence
Introduce deterministic fidelity gate for trajectory step rewrites
The rewriter module now enforces a strict acceptance gate that prevents the LLM from silently dropping critical failure information. Rewrites are rejected if they omit failure signals (e.g., 'error', 'panic'), alter source locations (including Windows drive/UNC paths and line numbers), or change non-zero exit codes. This ensures that while the rewriter can condense passing test output and other noise, the agent retains the exact coordinates and details needed to diagnose and fix failures.
rewriter · high confidence
Introduce signed binary installation with Windows update reliability fixes
The CLI now automatically downloads, verifies, and installs prebuilt Go binaries (caveman-mcp, caveman-shrink) from GitHub releases using Sigstore signatures and SHA-256 checksums, ensuring users get authentic executables without manual setup. On Windows, the installer now retries replacing locked daemon files with exponential backoff, preventing update failures when the binary is in use. The installation location defaults to \~/.caveman/bin, and users can override the binary path via environment variables (CAVEMAN\_MCP\_BIN, CAVEMAN\_SHRINK\_BIN) or the CAVE\_BINARY\_RELEASE\_BASE setting.
mcp/bin, packages/shared/binary-installer, shrink/bin · high confidence
New provider adapter layer with precise usage accounting and credential isolation
The proxy now uses a new provider adapter layer that isolates client credentials from upstream requests, ensuring that internal keys (such as x-cave-api-key) are never forwarded to providers. It introduces precise usage accounting by preserving raw provider usage payloads for re-pricing, correctly merging split usage chunks across streaming responses, and accurately resolving billing regions for OpenAI and Bedrock endpoints. Additionally, it adds strict credential validation for Google APIs and implements a compression coverage matrix to safely handle request compression for supported routes.
proxy/providers · high confidence
OpenAI-compatible provider now supports wire-dialect mounts for Anthropic protocol handling
The OpenAI-compatible provider adapter now supports named mounts that declare a specific wire dialect (e.g., Anthropic), enabling correct usage accounting and content compression for upstreams that deviate from the standard OpenAI shape. This change introduces a \wireDialect\ configuration that selects the appropriate usage parser and compression-zone grammar per request path, ensuring that Anthropic-specific features like \cache\_control\ breakpoints are handled correctly without breaking existing OpenAI-shape mounts. Additionally, header forwarding is now strictly scoped to mount-specific attribution headers and respects HTTP \Connection\ nominations to prevent hop-by-hop headers from leaking to upstreams.
proxy/providers/openaicompat · high confidence
Proxy lifecycle, identity, and reporting improvements
The standalone proxy now logs serve-mode warnings to \~/.caveman/proxy.log to prevent lost diagnostics when spawned detached. It publishes the instance identity header only on loopback binds to avoid leaking instance tokens on shared listeners, and validates that the listener matches the current run-state generation before trusting it. The native hook bridge now returns on the first complete JSON payload rather than waiting for EOF, and the proxy no longer expires during idle periods when owned by the wrap CLI. A new stats report subcommand allows generating detailed HTML reports with filtering options, and the status command now correctly reports 'unknown' owner when the configuration fails to load.
proxy/cmd · high confidence
Standalone proxy authentication, credential routing, and provider-specific auth handling
The standalone proxy now enforces a shared operator token for inbound requests, stripping the \x-cave-api-key\ header before forwarding to upstream providers to prevent secret leakage. It introduces a robust AWS Bedrock credential chain that resolves IAM signing credentials from environment variables or the AWS default chain (ECS task role, EKS pod identity, IRSA) while failing closed on partial environment pairs to prevent accidental identity switching. For Google Gemini, the proxy now supports \key\ and \$key\ query parameters and \x-goog-api-key\ headers, correctly handling conflicts and preserving caller OAuth tokens. Additionally, the proxy ensures that token-counting requests bypass content compression and recovery storage, and validates that native streaming responses from providers like Anthropic, OpenAI, and Bedrock are correctly parsed and recorded.
proxy/internal/standalone · high confidence
Stricter config validation and hardened proxy security defaults
The proxy now enforces stricter configuration rules and security defaults: it refuses to start if \auth\_token\ is present in \caveman.yaml\ (forcing operators to use the \CAVEMAN\_AUTH\_TOKEN\ environment variable), rejects non-loopback listen addresses unless an auth token is provided, and validates that unknown modes fail closed to 'record'. Additionally, it introduces a \wire\_dialect\ setting for OpenAI-compatible mounts to correctly parse usage accounting for non-OpenAI providers, and adds SSRF protection by allowing explicit upstream proxy configuration and custom CA bundles while ignoring unsafe forward headers.
proxy/internal/config · high confidence
Unified cross-platform installer replaces shell scripts
The installation process is now handled by a single Node.js script (bin/install.js) that consolidates the previous separate shell and PowerShell installers. This change provides a unified source of truth for macOS, Linux, and Windows, eliminating quoting bugs that previously broke JSON configuration merging and ensuring consistent behavior across platforms. The installer now pins remote fetches to a specific release tag (v2.7.0) to prevent silent changes from the main branch, and it includes improved handling for hook management and provider skills.
bin · high confidence
shrink: durable recovery store and new CLI/launcher
The shrink module now ships with a Go library (shrink.go), a CLI (caveman-shrink), and an npm launcher (bin/caveman-shrink.mjs). The library’s Shrink and Recover functions now use a durable CCR recovery store (defaulting to CAVEMAN\_CCR\_DB or \~/.caveman/ccr.db) so that a handle minted by Shrink can be resolved later from a separate process via Recover; this replaces the previous in-memory store that made handles unresolvable after Shrink returned. The CLI exposes stdin→stdout compression, lint, and recover commands, and the npm launcher downloads the prebuilt binary on first run. Documentation (README.md, CLAUDE.md, AGENTS.md) and licensing (LICENSE, LICENSE.launcher, BINARY\_LICENSE.md) are added, clarifying that the Go core and binary are BSL-1.1 while the launcher is MIT, and noting that compression is lossy, fail-open, and inferred-only.
shrink · high confidence
Test coverage
Added comprehensive test suite for the Caveman extension; Added integration tests for the MCP launcher and package distribution; Added smoke tests for per-session mode state; Added test coverage for benchmarking, Claude timeouts, cavecrew model overrides, init, parsing, stats, and compression; Added test fixtures for CLI binary release verification, agent session context, and provider compatibility; Added test for package packing and binary installation; Added tests for Windows hook path resolution and standalone installer safety; Expanded CLI test coverage for agent integration and configuration; Expanded test coverage for the Pi extension's Windows compatibility, routing, and recovery logic; Installer test coverage expanded for agent registry, platform binaries, and multi-host installation flows; New gateway tests and auth fallback logic.
Dependencies
Initial dependency manifests for Caveman components and tooling
This change introduces the initial dependency manifests for the Caveman project, establishing the baseline versions for its core components. It adds a Go module definition (go.mod) pinning the Go runtime to 1.26.5 and specifying dependencies for browser automation (chromedp), database access (pgx, sqlite), and compression. For the Node.js ecosystem, it adds package.json and lockfiles for the CLI, agent framework, browser extension, and various SDKs, setting minimum Node versions to 18 or 22.13 depending on the package. Python dependencies are defined in pyproject.toml files for the SDK and middleware, requiring Python 3.13+. Additionally, a benchmarks requirements.txt is added to specify the Anthropic client version for performance testing.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 41 → 55 (+13.9)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 41 → 47 (+6.9)
- Architecture 89 → 88 (-1.0)
- Maturity 63 → 84 (+20.4)
- Readiness 23 → 48 (+24.5)
- Security 80 → 79 (-1.1)
- Accessibility 64 (new)
Resolved (60)
- (anonymous) (cognitive 54) (src/hooks/caveman-mode-tracker.js)
- (anonymous) (cyclomatic 35) (src/hooks/caveman-mode-tracker.js)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- FileTooLong: cli/install.js (cli/install.js)
- FileTooLong: hooks/caveman-stats.js (src/hooks/caveman-stats.js)
- FileTooLong: installer/e2e.freshinstall.test.mjs (tests/installer/e2e.freshinstall.test.mjs)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: cli/install.js (cli/install.js)
- Hotspot: cli/lib/settings.js (cli/lib/settings.js)
- No exposed public API
- No tests found
- …and 40 more
New (1341)
- (anonymous) (cognitive 95) (extension/src/caveman.js)
- (anonymous) (cyclomatic 102) (extension/src/caveman.js)
- Adapter.ApplyProviderNativeTransforms (cognitive 17) (proxy/providers/openai/cache_key.go)
- Adapter.ApplyProviderNativeTransforms (cognitive 18) (proxy/providers/anthropic/cache_breakpoints.go)
- Adapter.ApplyProviderNativeTransforms (cyclomatic 18) (proxy/providers/anthropic/cache_breakpoints.go)
- Adapter.ApplyProviderNativeTransforms (cyclomatic 20) (proxy/providers/openai/cache_key.go)
- Adapter.InspectRequest (cognitive 21) (proxy/providers/bedrock/routing.go)
- Adapter.InspectRequest (cyclomatic 17) (proxy/providers/bedrock/routing.go)
- Adapter.ResolveUpstreamURL (cognitive 29) (proxy/providers/bedrock/routing.go)
- Adapter.ResolveUpstreamURL (cyclomatic 21) (proxy/providers/bedrock/routing.go)
- Adapter.SanitizeAndMapHeaders (cognitive 28) (proxy/providers/bedrock/signing.go)
- Adapter.SanitizeAndMapHeaders (cyclomatic 22) (proxy/providers/bedrock/signing.go)
- App.do (cyclomatic 22) (shared/platform/githubapp/githubapp.go)
- Base.InspectRequest (cognitive 22) (proxy/providers/adapter.go)
- Base.SanitizeAndMapHeaders (cognitive 39) (proxy/providers/adapter.go)
- Base.SanitizeAndMapHeaders (cyclomatic 20) (proxy/providers/adapter.go)
- CDPDriver.Act (cognitive 29) (browse/cdp.go)
- CDPDriver.Act (cyclomatic 19) (browse/cdp.go)
- CDPDriver.waitActionable (cognitive 33) (browse/cdp.go)
- CDPDriver.waitActionable (cyclomatic 21) (browse/cdp.go)
- …and 1321 more
Changes since last survey
- 300 commits — 136 feature/other, 164 fixes
By area
- packages/cli — 63 commits
- (repo) — 33 commits
- proxy/internal — 26 commits
- (root) — 19 commits
- .github/workflows — 12 commits
- src/hooks — 12 commits
- proxy/providers — 10 commits
- shared/platform — 10 commits
- agents/agents.json — 9 commits
- dist/caveman.skill — 9 commits
- engine/ccr — 9 commits
- packages/middleware — 8 commits
- docs/technical — 7 commits
- packages/pi-extension — 6 commits
- skills/caveman-compress — 6 commits
- extension/firefox — 5 commits
- packages/sdk — 5 commits
- src/mcp-servers — 5 commits
- tests/installer — 5 commits
- agents/compile.mjs — 4 commits
Notable commits
- fix: Merge branch 'fix/1001-upstream-proxy'
- fix: Merge pull request #1077 from sebastianrueckerai/fix/tsx-grammar-fallback
- fix: Merge pull request #1079 from sebastianrueckerai/fix/ssrf-tunnel-test-hijack-buffer
- fix: Merge pull request #787 from ries44-web/fix/readme-ultra-example-arrows
- fix: Merge pull request #948 from zsltg/fix/pi-opencode-go-routing
- fix: fix(agents): drop Claude-only tools frontmatter so Gemini CLI loads cavecrew agents (#966)
- fix: fix(agents): give the Hermes custom provider the /v1 base URL it appends to
- fix: fix(awscreds): a cancelled caller gets its own error, not a coin flip
- fix: fix(awscreds): narrow the plaintext credential allowlists and bound one chain walk
- fix: fix(awssig): canonicalize non-S3 SigV4 paths the way botocore does
- fix: fix(bedrock): splice cache markers instead of decode-remarshal
- fix: fix(benchmarks): chart the skill against its terse control, not the baseline
- fix: fix(ccr): dedupe RepositoryMap payloads across sessions
- fix: fix(ccr): dedupe a RepositoryMap by content alone, and resolve refs off the cursor
- fix: fix(ccr): do not quarantine a recovery store that was only unreadable for a moment
- fix: fix(ccr): fail closed when the recovery database is replaced under an open handle
- fix: fix(ccr): inspect the generation through the canonical temp path in tests
- fix: fix(ccr): preserve SQLite locks during chmod
- fix: fix(ccr): skip the POSIX loose-parent quarantine test on Windows
- fix: fix(ci): bind drift reports to probe lanes
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
JuliusBrussee/caveman was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2fd153c67988e980fb0b2455c90832159a6a5a25 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.