sipeed/picoclaw
54.2
Adequate · 24 September 2026
141.2k
lines of production code
Go
with TypeScript
4
measurements over time
What this system is
PicoClaw is a modular, multi-channel AI agent framework that connects to diverse messaging platforms like Telegram, Discord, and WeChat. It provides a unified CLI and web dashboard for managing LLM providers, skills, and Model Context Protocol (MCP) integrations. The system features advanced context management with short-term memory compaction, self-evolving skills, and robust security through credential encryption and process isolation.
Features
Add AWS Bedrock provider with tool calling and streaming support
Users can now use AWS Bedrock as an LLM provider by building with the \bedrock\ tag. This new provider supports unified access to multiple model families (Claude, Llama, Mistral, etc.) via the Bedrock Runtime Converse API, including tool/function calling and real-time token streaming. It automatically handles AWS credential discovery and allows configuration of region, profile, base endpoint, and request timeout. The implementation also includes logic to drop the \temperature\ parameter for models that deprecate it (e.g., Claude Opus 4.8+), preventing validation errors.
pkg/providers/bedrock · high confidence
Add Azure OpenAI provider with Entra ID authentication support
Users can now connect to Azure OpenAI endpoints using the new Responses API. This change introduces a dedicated Azure provider that supports both static API keys and Azure Entra ID authentication via DefaultAzureCredential (available when building with the azidentity tag). The provider handles token acquisition, request formatting for the Responses API, and includes configurable request timeouts and user-agent headers.
pkg/providers/azure · high confidence
Add CLI command to configure and switch default models
Users can now manage their default AI model directly from the command line. The new \picoclaw model\ command displays the current default and lists available models, while passing a model name switches the default. A new \picoclaw model add\ subcommand allows users to register custom OpenAI-compatible endpoints by providing an API base URL and key; it can interactively fetch and select from available models or accept a specific model ID directly, automatically saving the configuration and setting it as the default.
cmd/picoclaw/internal/model · high confidence
Add DingTalk channel support via Stream Mode
Users can now connect the agent to DingTalk (钉钉) using WebSocket Stream Mode for receiving messages and API for sending replies. The implementation supports both direct and group chats, handles group mention-only triggers by stripping leading @mentions, and stores session webhooks per chat to enable reliable reply delivery. A factory registration allows the channel to be enabled via configuration, and unit tests verify inbound message parsing, sender identity canonicalization, and mention stripping behavior.
pkg/channels/dingtalk · high confidence
Add HTTP API provider with Gemini support and streaming
The new \pkg/providers/httpapi\ package introduces an HTTP-based provider layer that includes a dedicated Gemini provider (\gemini\_provider.go\) and a generic OpenAI-compatible wrapper (\http\_provider.go\). The Gemini provider enables streaming responses via Server-Sent Events, supports model-specific protocol parsing, and correctly handles reasoning content and tool call signatures. The OpenAI-compatible provider delegates to the existing \openai\_compat\ implementation, allowing users to connect to any OpenAI-compatible API endpoint with the same streaming and tool-calling capabilities.
pkg/providers/httpapi · high confidence
Add IRC channel integration
Users can now connect the bot to IRC servers. This change introduces a new channel type that supports connecting to IRC networks, joining channels, and handling both direct messages and group conversations. It includes support for SASL and NickServ authentication, TLS connections, and IRCv3 capabilities like message-tags for typing indicators. The integration handles bot mention detection using word boundaries and common prefixes (colon or comma), allowing the bot to respond appropriately in group chats.
_pkg/channels/irc, pkg/channels/whatsapp\native · high confidence
Add Linux USB device hotplug notifications
The device service now monitors USB hotplug events on Linux using udevadm, allowing the system to detect when USB devices are connected or disconnected. When enabled via the MonitorUSB configuration flag, the service publishes formatted notifications (including vendor, product, and capability details) to the user's last active channel upon device add or remove events. A stub implementation ensures the service starts without error on non-Linux platforms.
pkg/devices · high confidence
Add MQTT channel support
Users can now configure and use an MQTT-based communication channel. This change introduces the MQTT channel implementation, including connection handling, topic subscription, and message processing, allowing integration with MQTT brokers for agent communication.
pkg/channels/mqtt · high confidence
Add Matrix channel support with end-to-end encryption and rich-text rendering
Users can now connect to Matrix servers as a communication channel. This implementation supports end-to-end encrypted (E2EE) messages, renders rich-text content aligned with Matrix CommonMark guidelines, and handles inbound media downloads by streaming them to disk. The channel also includes improved group mention detection and manages room caching to optimize performance.
pkg/channels/matrix · high confidence
Add OAuth-based providers for Google Antigravity, Claude, and OpenAI Codex
New OAuth-enabled provider implementations have been added to the \pkg/providers/oauth\ package, allowing users to authenticate via stored credentials rather than static API keys. This includes the \AntigravityProvider\ for Google's Cloud Code Assist (Gemini) with support for streaming thought and visible content, the \ClaudeProvider\ wrapping the Anthropic SDK, and the \CodexProvider\ for OpenAI's Codex backend with native web search and streaming output support. Each provider includes comprehensive tests verifying request building, response parsing, and tool call handling.
pkg/providers/oauth · high confidence
Add OneBot channel adapter with secure media handling
Introduces a new OneBot channel adapter that registers via the channel factory, enabling users to connect to OneBot-compatible bots via WebSocket. The implementation includes secure inbound media handling that blocks local/loopback URLs and redirects to prevent SSRF-style attacks, while safely downloading and storing external media assets. It also supports group message reactions (emoji likes) and standard channel lifecycle management.
pkg/channels/onebot · high confidence
Add WeCom (WeChat Work) channel with streaming and media support
Introduces a new WeCom channel implementation that enables real-time streaming responses via WebSocket and supports sending and receiving media files (images, files, voice, video) with chunked uploads and AES decryption. The channel registers itself via the standard factory pattern, manages conversation turns and request-ID routing with persistence, and includes tests for media handling and streaming behavior.
pkg/channels/wecom · high confidence
Add migration support for OpenClaw
Users can now migrate their configuration and data from OpenClaw to PicoClaw. This change introduces a new migration handler in the \pkg/migrate/sources/openclaw\ package that detects OpenClaw installations (via \\~/.openclaw\ or the \OPENCLAW\_HOME\ environment variable), parses their \openclaw.json\ configuration, and converts it into the PicoClaw format. The migration covers agent definitions, model provider settings, and supported channel configurations (including Telegram, Discord, Slack, WhatsApp, and others), while also migrating specific files like \AGENTS.md\ and directories like \memory\ and \skills\.
pkg/migrate/sources · high confidence
Added support for Bangla, Portuguese (Brazil), and Czech locales
The web frontend now includes translation resources and date formatting support for Bangla (bn-IN), Portuguese (Brazil) (pt-BR), and Czech (cs), in addition to the existing English and Chinese (zh) locales. This change enables users to interact with the application interface and view dates in their preferred language, with automatic language detection and fallback to English.
web/frontend/src/i18n · high confidence
Atomic file writing utility added to fileutil package
The new \pkg/fileutil\ package introduces \WriteFileAtomic\, which ensures data integrity by writing to a temporary file, syncing to disk, and atomically renaming it to the target path. This prevents partial or corrupted files from appearing if the process crashes or is interrupted during a write operation, and is specifically designed to handle edge cases like flash storage and concurrent writes safely.
pkg/fileutil · high confidence
Centralized slash command registry with new session and agent controls
The command system has been refactored into a centralized registry that standardizes how slash commands are defined, routed, and executed across all channels. This change introduces several new user-facing capabilities: you can now clear your chat history with /clear, stop a running task with /stop, and reload configuration with /reload. Session management is enhanced with /context to view detailed token usage (including compress and summarize thresholds), /btw to ask side questions without affecting history, and /subagents to view the active subagent task tree. Configuration queries are expanded via /show and /list, which now support sub-commands for agents, skills, and MCP servers, while /check channel provides a dedicated way to verify channel availability.
pkg/commands · high confidence
Discord channel now resolves message links and channel references
The Discord channel adapter now automatically detects and resolves Discord message links (e.g., https://discord.com/channels/...) and channel mentions (e.g., \<\#123456789\>) within user messages. This allows the bot to understand and act upon cross-channel or cross-message context provided by users. The implementation includes pre-compiled regular expressions for efficient parsing and is supported by dedicated unit tests for the link and reference resolution logic.
pkg/channels/discord · high confidence
Feishu channel support for 64-bit architectures with enhanced message handling
The Feishu channel is now available on 64-bit architectures (amd64, arm64, riscv64, mips64, ppc64), while 32-bit systems will receive a clear error message indicating the channel is unsupported. This update introduces robust support for Feishu Interactive Cards (JSON 2.0) with full CommonMark markdown rendering, enabling richer message formatting. It also adds comprehensive media handling, allowing the channel to extract and process images, files, and audio from inbound messages, as well as send media attachments. Reply context is now enriched by fetching and including the content of the message being replied to, improving conversation continuity. Additionally, the channel includes a custom token cache that correctly invalidates credentials on authentication errors, ensuring reliable reconnection and retry behavior.
pkg/channels/feishu · high confidence
Introduce CLI commands for managing MCP server configurations
Users can now manage Model Context Protocol (MCP) servers directly from the command line using the new \picoclaw mcp\ subcommand group. This includes \add\ to register new servers with support for stdio, HTTP, and SSE transports (including the new \streamable-http\ alias), environment variables, and \.env\ files; \remove\ to delete servers; \list\ to view configured servers with optional live status probing; \show\ to inspect server details and available tools; \test\ to verify connectivity; and \edit\ to open the configuration file in the user's preferred editor. The \add\ command also validates local executable permissions and normalizes transport types before saving.
cmd/picoclaw/internal/mcp · high confidence
Introduce LINE channel with webhook body size limit
Added a new LINE channel implementation (pkg/channels/line) that registers via init() and uses the official LINE Bot SDK v8. The webhook handler now enforces a 1 MiB request body limit to prevent memory exhaustion (DoS), returning HTTP 413 for oversized payloads before signature validation. Tests verify this limit, method restrictions, and signature rejection.
pkg/channels/line · high confidence
Introduce LOCOMO memory benchmark tool with LLM-as-Judge evaluation
The \cmd/membench\ command-line tool is added to benchmark memory retrieval capabilities using the LOCOMO dataset. It supports ingesting conversation samples into both a legacy session store and the Seahorse retrieval engine, and provides evaluation modes that compare results using token-level F1/hit-rate metrics or an LLM-as-Judge scoring system. The tool includes configurable token budgets, concurrency limits, and retry logic for LLM API calls, along with comprehensive unit tests for the ingestion, evaluation, and metrics logic.
cmd/membench · high confidence
Introduce Model Context Protocol (MCP) integration
Added a new MCP integration that allows the application to connect to and manage external MCP servers. This includes a Manager component for handling server connections, an isolated command transport for secure subprocess execution, and event publishing for server lifecycle and tool discovery. The implementation supports both HTTP and stdio transports, includes environment variable loading from .env files, and provides integration tests to verify compatibility with streamable HTTP and real server configurations.
pkg/mcp · high confidence
Introduce OpenAI-compatible provider with advanced reasoning and streaming support
Adds a new OpenAI-compatible provider implementation that enables users to connect to any OpenAI-API-compatible endpoint. This provider supports streaming responses, parses reasoning content from models like DeepSeek, and maps specific reasoning levels (e.g., thinking\_level) to provider-specific fields. It also handles model-specific nuances such as using \max\_completion\_tokens\ for GLM and GPT-5 era models, supports native search injection, and allows custom headers and extra body fields for flexible configuration.
_pkg/providers/openai\compat · high confidence
Introduce Pico Protocol channel and Pico Client channel
Users can now connect to a remote Pico Protocol WebSocket server using the new Pico Client channel, which handles authentication, reconnection, and message streaming. The existing native Pico channel has been enhanced to support tool calls, thought messages, and per-turn token usage reporting, allowing clients to see detailed model usage and intermediate processing states.
pkg/channels/pico · high confidence
Introduce Pico chat interface with rich message rendering and context management
The chat area now features a new Pico chat UI that supports image attachments via paste and drag-and-drop, syntax-highlighted code blocks with line numbers and wrap toggles, and collapsible sections for reasoning thoughts and tool calls. Users can view context usage via a ring indicator, select models from a grouped selector, and manage session history through a dropdown menu.
web/frontend/src/components/chat · high confidence
Introduce TTS (Text-to-Speech) package with OpenAI and Xiaomi MiMo support
This change adds a new \pkg/audio/tts\ package that enables text-to-speech synthesis in PicoClaw. It introduces providers for OpenAI-compatible endpoints (defaulting to the \/audio/speech\ API with \opus\ format and \alloy\ voice) and Xiaomi MiMo (using \mp3\ format and \default\_zh\ voice). Configuration is handled via \voice.tts\_model\_name\ pointing to a \model\_list\ entry, with API keys stored in \.security.yml\. The implementation supports provider-specific overrides (such as voice and response format) through \model\_list\[\].extra\_body\, includes automatic fallback scanning for TTS-capable models, and handles API base URL normalization. Documentation for setup and configuration is included in English and Chinese.
pkg/audio/tts · high confidence
Introduce agent self-evolution capability for skills
This change adds a new self-evolution subsystem in pkg/evolution that allows the agent to automatically generate, review, and apply skill drafts based on its past task performance. The system includes a cold-path runner to asynchronously process learning records, a draft generator (with both default and LLM-based modes) to create skill updates, a review step that quarantines drafts containing secrets or validation errors, and an applier that safely writes new or updated SKILL.md files with rollback support. It also manages skill lifecycles (active, cold, archived, deleted) based on usage and retention scores, and persists learning cases and skill profiles.
pkg/evolution · high confidence
Introduce in-process runtime event bus for component observability
The \pkg/events\ package now provides a process-local runtime event bus that allows PicoClaw components to observe internal lifecycle and activity events without coupling to agent-specific envelopes. This new capability includes an \EventBus\ for publishing events, an \EventChannel\ for filtering by kind, source, and scope, and a subscription model with configurable backpressure policies (drop newest, drop oldest, or block), concurrency modes (concurrent or locked), and panic recovery. The bus exposes detailed statistics on published, matched, delivered, dropped, and blocked events, and defines a comprehensive set of event kinds covering agent turns, LLM interactions, tool execution, channel lifecycle, gateway status, and MCP server connections.
pkg/events · high confidence
Introduce interactive product tour for new users
Added a new TourGuide component that provides a step-by-step walkthrough for first-time users, guiding them through the models navigation, gateway, and documentation sections with contextual popovers and navigation controls.
web/frontend/src/components/tour · high confidence
Introduce network binding package with adaptive multi-host support
Added the \pkg/netbind\ package, which provides logic to detect available IP families (IPv4/IPv6) and build binding plans that support adaptive loopback and any-host selection. This enables the application to listen on multiple specific addresses (e.g., both \127.0.0.1\ and \::1\) or adapt to the host's capabilities, with platform-specific handling for IPv6-only socket options on Unix and Windows.
pkg/netbind · high confidence
Introduce process-level isolation for child processes on Linux and Windows
The new \pkg/isolation\ package provides a unified startup path for child processes, allowing \picoclaw\ to run them in an isolated environment without sandboxing the main process. On Linux, this uses \bubblewrap\ to create a minimal filesystem view with IPC namespace isolation and optional host path mounting. On Windows, it applies restricted tokens, low integrity levels, and Job Objects to limit process privileges. Child processes also receive a redirected per-instance user environment (e.g., \HOME\, \AppData\) to keep data isolated. The feature is controlled via the \isolation\ configuration block and is currently supported on Linux and Windows, while macOS and other platforms are not yet implemented.
pkg/isolation · high confidence
Introduce structured protocol types for LLM interactions
The \pkg/providers/protocoltypes\ package now defines the core data structures for the provider interface, including \Message\, \LLMResponse\, \ToolCall\, and \ToolDefinition\. These types establish a standardized schema for handling chat messages, tool usage, and model responses, supporting features such as structured system parts with cache control, reasoning content, media attachments, and internal prompt layering metadata.
pkg/providers/protocoltypes · high confidence
Introduce unified media file lifecycle management
The media package now includes a centralized \MediaStore\ interface and \FileMediaStore\ implementation to manage the lifecycle of media files. This change introduces scoped storage where files are registered under specific scopes and can be released in bulk via \ReleaseAll\. It supports configurable cleanup policies: \delete\_on\_cleanup\ (default) automatically removes files when the last reference is released, while \forget\_only\ preserves the underlying file on disk. The store also supports shared file paths with reference counting to prevent premature deletion, and includes an optional background TTL cleaner for automatic expiration of old media entries.
pkg/media · high confidence
Introduces model complexity routing and declarative agent dispatch
The routing package now automatically selects between light and heavy models based on a language-agnostic complexity score derived from message length, code blocks, tool usage, and attachments, ensuring complex tasks like coding or multi-modal inputs are handled by capable models. Additionally, it supports declarative dispatch rules that route messages to specific agents based on channel, account, space, or sender, with configurable session dimensions and identity links.
pkg/routing · high confidence
Introduces secure PID file management with process validation and auth tokens
The gateway now uses a new PID file mechanism to enforce single-instance execution and improve reliability. The PID file stores a cryptographically random authentication token alongside process metadata, enabling secure control-plane operations like /reload and pico channel connections. Singleton checks are hardened to verify that a recorded PID actually belongs to a running picoclaw process (checking process liveness and image name), preventing false positives from PID reuse or stale files left by containers (specifically treating PID 1 as stale). Stale or invalid PID files are automatically cleaned up, and the file is written atomically with restricted permissions.
pkg/pid · high confidence
Native Anthropic Messages API provider support
Added a new provider implementation for the Anthropic Messages API, enabling direct communication with Anthropic models (defaulting to claude-sonnet-4.6) via HTTP without requiring an SDK. This provider supports standard message formats, tool definitions, and configurable request timeouts, while also allowing users to set a custom User-Agent header for API requests.
_pkg/providers/anthropic\messages · high confidence
New 'status' command displays provider availability and authentication state
The PicoClaw CLI now includes a 'status' command (alias 's') that reports the current configuration state, including version, build info, and workspace validity. Crucially, it now infers provider availability (OpenAI, Anthropic, OpenRouter, etc.) directly from the model list entries rather than relying on legacy provider fields, and displays the authentication status (authenticated, expired, or needs refresh) for configured OAuth credentials.
cmd/picoclaw/internal/status · high confidence
New CLI-based LLM providers and structured auth error classification
Users can now invoke the Claude and Codex command-line tools as LLM providers, with the system automatically reading OAuth tokens from the Codex CLI's local auth.json file. Additionally, the provider layer now classifies authentication failures into specific kinds (missing, invalid, or expired API keys/tokens), enabling more precise error handling and user feedback when credentials are misconfigured.
pkg/providers · high confidence
New Docker images and entrypoint for PicoClaw services
This change introduces a comprehensive set of Dockerfiles and compose configurations for PicoClaw, including a minimal runtime image (Dockerfile), a full MCP-support image with Node.js and Python (Dockerfile.full), a heavy image with browser automation capabilities (Dockerfile.heavy), and dedicated launcher images (Dockerfile.launcher, Dockerfile.goreleaser.launcher). It also adds a first-run entrypoint script that automatically handles initial onboarding when no config or workspace exists, and cleans up stale PID files to prevent startup conflicts. Users can now deploy PicoClaw as an agent, gateway, or launcher via Docker Compose profiles, with the launcher exposing ports 18800 and 18790 for web console access.
docker · high confidence
New Docker-backed integration test infrastructure and MCP streamable suite
The project introduces a new integration testing layer that runs Go tests inside Docker containers to ensure reproducible, CI-safe validation of component wiring. This includes a shared runner configuration (\docker-compose.runner.yml\) using the \golang:1.25-bookworm\ image, a reference test suite for the MCP streamable HTTP protocol (\integration/suites/mcp-streamable\), and a fixture server (\integration/fixtures/mcp-streamable-server\) to simulate real dependencies. The setup allows CI to automatically discover and execute suites, verifying that PicoClaw can correctly connect to, discover tools on, and invoke a real MCP server over HTTP.
integration · high confidence
New GitHub and ClawHub skill registries with search, caching, and installation
Users can now discover and install skills from two new sources: GitHub repositories and the ClawHub platform. The system includes a unified registry manager that coordinates multiple providers, allowing skills to be searched across enabled registries with results sorted by relevance. A trigram-based search cache reduces redundant API calls by matching similar queries. GitHub registry support handles custom base URLs (e.g., GitHub Enterprise), authentication tokens, proxy settings, and parses various URL formats (owner/repo, full URLs with branches/paths). ClawHub registry support includes configurable endpoints, timeouts, size limits, and automatic retry on rate-limit (429) responses. Both registries support downloading and installing skills from ZIP archives, with metadata validation and moderation flags (malware/suspicious) returned to the caller. The skills loader also now validates skill info (name/description) and handles frontmatter parsing with support for different line endings.
pkg/skills · high confidence
New Logs page with ANSI rendering and scroll handling
The Logs page now renders gateway logs using a new \AnsiLogLine\ component that parses ANSI segments and wraps long lines based on viewport width. The \LogsPanel\ component implements auto-scroll behavior that sticks to the bottom only when the user is already viewing the latest logs, improving usability during high-volume output. Additionally, a \LogLevelSelect\ component allows users to adjust the gateway's log level (debug, info, warn, error, fatal) directly from the UI, with changes persisted via the app config API.
web/frontend/src/components/logs · high confidence
New OAuth and token-based authentication for OpenAI and Anthropic
The auth package now supports logging in via OAuth flows for OpenAI and Google (Antigravity), as well as token-based login for Anthropic. Users can authenticate using a browser-based OAuth flow with PKCE, a headless mode that allows pasting the redirect URL or authorization code manually, or by pasting an Anthropic setup token (sk-ant-oat01-). The system also includes a credential store to manage tokens across providers, handles token expiration and refresh needs, and can fetch Anthropic OAuth usage statistics.
pkg/auth · high confidence
New PicoClaw migration tool for OpenClaw workspaces
Users can now migrate their existing OpenClaw workspace and configuration to PicoClaw using the new \picoclaw migrate\ command. This feature introduces a pluggable migration framework in \pkg/migrate\ that plans and executes the conversion of OpenClaw config files to PicoClaw format and copies workspace data. The tool supports dry-run previews, force overrides, and specific modes for migrating only configuration or only workspace data, ensuring a safe transition from the previous environment.
pkg/migrate · high confidence
New QQ channel adapter with media, group, and typing support
Added a new QQ channel adapter that enables sending and receiving messages via the Tencent Bot API. The adapter supports group and direct (C2C) chats, including handling attachments (images, files) by downloading and storing them as media references, and preserves original filenames during uploads. It implements time-based message deduplication to prevent duplicate processing, sends typing indicators during long replies, and calculates audio duration for voice messages (WAV/OGG) to enforce the 60-second limit. A custom logger demotes noisy heartbeat traffic to debug level to reduce console spam. Tests verify inbound message handling, attachment processing, and local file upload as base64.
pkg/channels/qq · high confidence
New Skill Marketplace Hub for discovering and installing skills
A new Skill Marketplace Hub has been added to the Agent interface, allowing users to search for and install skills from a registry. The hub includes a search panel for querying the marketplace, a results panel displaying skill cards with installation status, and a hook that manages the search and installation flows. Users can now discover new capabilities, view installation progress, and see tooltips explaining why install buttons might be disabled.
web/frontend/src/components/agent/hub · high confidence
New Weixin (WeChat) channel support via Tencent iLink API
Users can now connect to WeChat as a messaging channel. This change introduces a new \weixin\ channel implementation that communicates with the Tencent iLink REST API (version 2.1.1). It supports interactive QR-code login for authentication, persistent session state (sync buffers and context tokens) saved to disk to survive restarts, and full media handling (images, voice, files, video) with AES-encrypted CDN download/upload. The channel also includes typing indicators, long-polling message updates, and configurable proxy support.
pkg/channels/weixin · high confidence
New agent subcommand with Cobra CLI structure
The agent interaction is now exposed via a dedicated \agent\ subcommand built on the Cobra library, replacing the previous implicit or flat CLI structure. This command supports flags for specifying a message (non-interactive mode), session key, model, and debug logging, and it initializes the agent loop with configurable provider and message bus components.
cmd/picoclaw/internal/agent · high confidence
New build, testing, and CI scripts for macOS, Windows, and integration testing
Added several new scripts to the \scripts/\ directory to support new platform builds and testing workflows. \build-macos-app.sh\ automates the creation of a macOS .app bundle for the PicoClaw Launcher, while \setup.iss\ provides an Inno Setup installer script for Windows. \copydir.go\ introduces a Go utility for safely copying directories within the repository root, supporting Codespace placeholders. Testing capabilities are expanded with \run-integration-tests.sh\ for orchestrating Docker-based integration suites, \test-docker-mcp.sh\ to verify MCP tool availability in Docker images, and \test-irc.sh\ to spin up a local IRC server for channel integration tests. Additionally, \lint-docs.sh\ enforces documentation structure and naming conventions for translations.
scripts · high confidence
New channel configuration forms for Discord, Feishu, MQTT, Slack, Telegram, WeCom, and WeChat
The channel settings UI now includes dedicated configuration forms for Discord, Feishu (with Lark domain switching), MQTT, Slack, Telegram, WeCom, and WeChat (Weixin). These forms provide structured inputs for channel-specific credentials (tokens, app IDs, secrets), connection details (proxies, broker URLs, base URLs), and access controls (allow-from lists). The WeCom and WeChat forms feature an integrated QR-code binding flow for account linking, while the Feishu form supports group chat triggers and random emoji reactions. Additionally, a generic form component and a streaming configuration field are introduced to support flexible channel setups and enable streaming output controls.
web/frontend/src/components/channels/channel-forms · high confidence
New common provider utilities for schema sanitization, message serialization, and HTTP handling
This change introduces a new \pkg/providers/common\ package that consolidates shared logic for LLM provider implementations. It adds \SanitizeSchemaForGoogle\ (aliased as \SanitizeSchemaForGemini\) to strip unsupported JSON Schema keywords (like \$ref\, \anyOf\, \pattern\) and flatten unions for Gemini-compatible backends, and \NormalizeBaseURL\ to standardize Anthropic API endpoints by managing \/v1\ suffixes and trailing slashes. It also provides \SerializeMessages\ to convert internal message structures into OpenAI-compatible wire formats—handling text, images, audio, tool calls, and reasoning content—along with \NormalizeStoredToolCall\ and \InferToolNameFromCallID\ for robust tool call resolution. Additionally, it includes \NewHTTPClient\ for creating HTTP clients with optional proxy support and \HandleErrorResponse\/\WrapHTMLResponseError\ for consistent error handling, all accompanied by comprehensive unit tests.
pkg/providers/common · high confidence
New file editing, appending, and image loading tools
The \pkg/tools/fs\ package now includes \edit\_file\, \append\_file\, and \load\_image\ tools. The \edit\_file\ tool replaces exact text within a file and returns a unified diff of the changes, while \append\_file\ adds content to the end of a file. The \load\_image\ tool allows the agent to load local image files into the media store for vision analysis in subsequent turns. These tools are built on the existing filesystem validation and media pipeline infrastructure.
pkg/tools/fs · high confidence
New foundational UI component library
The web frontend now includes a comprehensive set of reusable UI components in the \src/components/ui\ directory, built on top of Radix UI primitives and styled with Tailwind CSS. This new library introduces accessible and theme-aware elements including dialogs, alert dialogs, sheets, dropdown menus, popovers, collapsibles, command palettes, cards, badges, buttons, inputs, labels, separators, scroll areas, selects, and a responsive sidebar with mobile support and keyboard shortcuts. These components provide a consistent visual language and interaction pattern across the application, serving as the building blocks for future feature development.
web/frontend/src/components/ui · high confidence
New frontend API client layer for launcher dashboard
The frontend now uses a dedicated API client layer in \web/frontend/src/api\ to communicate with the launcher backend, replacing previous ad-hoc fetch calls. This layer introduces a standardized \launcherFetch\ utility that handles same-origin authentication, automatically redirecting to the launcher login page on 401 errors while preventing loops on auth routes. It provides typed modules for managing channels, gateway lifecycle (start/stop/restart/logs), model configuration (including default chains and inline testing), OAuth provider flows, session history, skills registry, system settings, and tool configurations, ensuring consistent error handling and type safety across the dashboard.
web/frontend/src/api · high confidence
New frontend hooks for model management, gateway control, and credential flows
The frontend now includes a suite of new React hooks in the \src/hooks\ directory to manage core application states. \use-chat-models\ handles fetching available models, setting the default model with restart-required feedback, and categorizing models by authentication method (local, API key, OAuth). \use-gateway\ and \use-gateway-logs\ provide controls to start, stop, and restart the backend gateway, along with a polling mechanism to display live gateway logs. \use-credentials-page\ implements the OAuth login/logout flow, including device flow polling and browser-based authentication. Additional hooks include \use-highlight-theme\ for applying syntax highlighting to code blocks, \use-pico-chat\ for managing chat sessions and messages, \use-session-history\ for paginated session loading, \use-sidebar-channels\ for displaying enabled communication channels, \use-copy-to-clipboard\ for text copying, \use-mobile\ for responsive breakpoint detection, and \use-log-wrap-columns\ for dynamic log line wrapping.
web/frontend/src/hooks · high confidence
New frontend store modules for chat, gateway, and onboarding
The frontend now includes dedicated Jotai store modules in src/store to manage application state more granularly. The chat store centralizes message history, tool call visibility, and assistant detail preferences, while the gateway store implements a polling mechanism to sync the backend service status (running, stopping, etc.) with the UI. Additionally, a tour store has been added to persist and drive the first-time user onboarding flow, and a code-block store manages user preferences for code wrapping.
web/frontend/src/store · high confidence
New frontend utility libraries for ANSI rendering, clipboard, auth paths, and UI helpers
This change introduces several new utility modules in the frontend library to support recent feature work. The new \ansi-log.ts\ module parses ANSI escape codes (including 256-color and true-color support) into styled segments, enabling the frontend to render wrapped and colored logs correctly. A new \clipboard.ts\ module provides a robust \copyText\ function that falls back to a textarea-based method if the modern Clipboard API is unavailable. Path-handling utilities in \launcher-login-path.ts\ normalize URLs and identify launcher-specific login and setup routes, supporting the new token-protected SPA login flow. Additionally, \restart-required.ts\ adds toast notifications for configuration changes that require a restart, and \utils.ts\ exports a \cn\ helper for merging Tailwind CSS classes.
web/frontend/src/lib · high confidence
New hardware tools for I2C, SPI, and serial communication
Added new hardware tools in pkg/tools/hardware that allow interacting with I2C, SPI, and serial ports. The I2C tool (Linux only) supports detecting buses, scanning for devices, and reading/writing bytes with safety guards. The SPI tool (Linux only) enables listing devices and performing full-duplex transfers or reads. The serial tool is cross-platform (Linux, macOS, Windows) and supports listing ports, reading, and writing with configurable baud rates, data bits, parity, and stop bits. All tools include platform-specific implementations and comprehensive tests.
pkg/tools/hardware · high confidence
New health check server with readiness probes and protected reload endpoint
The \pkg/health\ package now provides a dedicated HTTP server for container orchestration health checks. It exposes \/health\ for liveness probes (returning status and uptime) and \/ready\ for readiness probes, which aggregate registered dependency checks (e.g., database, redis) to determine if the service is ready to accept traffic. Additionally, a \/reload\ endpoint is available to trigger configuration reloads, protected by an optional bearer token to prevent unauthorized access.
pkg/health · high confidence
New integration tool suite for messaging, skills, and web search
This change introduces a new \pkg/tools/integration\ package providing a suite of tools for the agent: \message\ (send text and optional local media attachments), \reaction\ (add reactions to messages), \install\_skill\ and \find\_skills\ (discover and install skills from registries), \send\_tts\ (synthesize and send speech), \mcp\_tool\ (wrap Model Context Protocol tools), and \web\ (web search and fetch with providers like Kagi, Brave, and Sogou). It also includes helper utilities for sanitizing LLM content and parsing arguments, along with comprehensive tests for all new components.
pkg/tools/integration · high confidence
New model management UI with catalog integration and fallback chains
The models management page has been rebuilt with a new UI that includes a catalog dialog for browsing and adding models from a central catalog, a default chain dialog for configuring model fallback chains, and improved add/edit sheets with real-time validation and provider-specific configuration options.
web/frontend/src/components/models · high confidence
New modular dashboard layout with gateway controls and secure credential handling
The web frontend now uses a new AppLayout that wraps the interface in a sticky AppHeader, an AppSidebar, and a TourGuide. The header provides gateway lifecycle controls (start, stop, restart) with confirmation dialogs and displays a 'restart required' indicator, while also handling standard HTTP logout. The sidebar organizes navigation into collapsible groups for chat, models, channels, agents (hub, skills, tools), and settings (config, logs). To improve security, secret inputs now use a KeyInput component with a show/hide toggle, and a maskedSecretPlaceholder utility ensures partial masking of short secrets (e.g., 7-character secrets) to avoid full exposure.
web/frontend/src/components · high confidence
New pico-echo-server example for testing pico\_client WebSocket channel
Added a new example application, pico-echo-server, which implements a minimal Pico Protocol WebSocket server. This tool allows users to test the pico\_client outbound channel by accepting WebSocket connections, authenticating via token, echoing messages, and broadcasting stdin input to connected clients. It serves as a practical reference for integrating and verifying the pico\_client configuration in config.json.
examples · high confidence
New scheduling, delegation, and discovery capabilities for agents
The \pkg/tools\ package introduces three new tool categories to enhance agent autonomy and operational control. First, the \CronTool\ enables scheduling of one-time reminders, recurring tasks, and direct shell command execution, with configurable security restrictions for remote channels and command allowlists. Second, the \DelegateTool\ allows an agent to synchronously hand off a task to a specific named sub-agent, respecting allowlists and ensuring the target agent uses its own workspace and model. Third, \RegexSearchTool\ and \BM25SearchTool\ provide on-demand discovery of hidden tools via pattern matching or natural language queries, temporarily unlocking them for use. These changes are supported by new facade files (\fs\_facade.go\, \hardware\_facade.go\, \integration\_facade.go\) that re-export tool constructors from internal packages, and comprehensive test coverage for the new tools and registry behaviors.
pkg/tools · high confidence
New self-update mechanism with robust release selection and extraction
The \pkg/updater\ package introduces a new self-update capability that downloads and applies binary updates from GitHub releases. It features robust asset selection logic that prefers tar.gz archives on Linux and zip archives on Windows, verifies download integrity via SHA256 checksums, and uses the \minio/selfupdate\ library to atomically replace the running executable with a rollback backup. The implementation includes retry logic for network requests and proper error handling for resource cleanup.
pkg/updater · high confidence
New skills management CLI with registry-backed installation
The \picoclaw skills\ command group is now available, providing a complete interface for managing skills. Users can list installed and builtin skills, search for new ones, and install them from GitHub or configured registries (using the \--registry\ flag). The system now tracks installation metadata (origin, version, registry) in \.skill-origin.json\ files, supports builtin skill installation, and includes safety checks such as malware detection and validation of skill archives during installation.
cmd/picoclaw/internal/skills · high confidence
New skills management interface with import, filtering, and detail views
Users can now manage agent skills through a dedicated page that supports importing skills via drag-and-drop or file selection, viewing detailed skill information in a side sheet with markdown preview, and managing skill lifecycles. The interface includes a filter bar to search and sort skills by name or origin (builtin, third-party, manual), toggle between grid and grouped layouts, and delete workspace-specific skills via a confirmation dialog.
web/frontend/src/components/agent/skills · high confidence
New standalone WebUI launcher with dashboard and gateway management
The \web/\ directory now provides a complete, standalone launcher application that bundles a React-based dashboard and a Go backend. This launcher manages the \picoclaw gateway\ process, offering a browser-based interface for chat, model configuration, credential management, and channel setup. It introduces password-based authentication for the dashboard, supports system tray integration on desktop platforms, and includes build targets for Android ARM64. The launcher listens on port 18800 by default and allows for public access with optional CIDR restrictions and trusted proxy support.
web · high confidence
New unified 'auth' CLI command with WeCom and Weixin channel onboarding
The authentication workflow is now accessed via a dedicated \picoclaw auth\ command group, replacing scattered login mechanisms. This new command structure introduces subcommands for managing credentials (login, logout, status) and managing models. Key additions include a \wecom\ subcommand that enables users to scan a QR code to configure the WeCom channel, and a \weixin\ subcommand that allows scanning a QR code to connect a WeChat personal account. The \login\ subcommand has been expanded to support OAuth flows for OpenAI, Anthropic (including a new setup-token option), and Google Antigravity, with support for headless device-code login and a \--no-browser\ flag. The \status\ command now correctly canonicalizes legacy 'antigravity' credentials to 'google-antigravity'.
cmd/picoclaw/internal/auth · high confidence
New utility libraries for search, context management, and secure networking
This release introduces several new capabilities in the \pkg/utils\ package. A generic BM25 search engine is added, allowing applications to perform ranked text searches over any document type with precomputed indexing for performance. Context handling is improved with utilities to calculate, measure, and intelligently truncate message history based on rune counts, preserving system messages and recent context. Network safety is enhanced with a safe HTTP client that blocks access to private and local network hosts (with whitelist support), validates URLs against SSRF risks, and implements robust retry logic that honors HTTP 429 \Retry-After\ headers. Additional utilities include streaming file downloads with size limits, configurable HTTP clients with proxy support, and an HTML-to-Markdown converter that sanitizes dangerous content.
pkg/utils · high confidence
New web-based configuration interface for launcher and agent settings
A new web frontend has been introduced to manage application configuration, replacing or supplementing previous methods. This interface provides a structured UI for core agent settings (such as workspace restrictions, tool feedback, execution controls, and context windows), launcher-specific settings (including port, public access, CIDR allowlists, and dashboard password authentication), and Model Context Protocol (MCP) server definitions. It also includes a raw JSON editor for advanced users, a factory reset capability, and visual indicators for unsaved changes requiring a restart.
web/frontend/src/components/config · high confidence
Project initialization and foundational configuration
This change establishes the initial project structure for PicoClaw, introducing essential configuration and build files including \.dockerignore\, \.env.example\, \.gitattributes\, \.golangci.yaml\, and \.goreleaser.yaml\. It adds the \Makefile\ with comprehensive build targets for various architectures (including ARM, MIPS, RISC-V, and LoongArch), the \config.example.json\ template, and the \onboard\_workspace\_embed.go\ file to embed default workspace templates. Documentation is also added with \CONTRIBUTING.md\, \ROADMAP.md\, and an updated \README.md\ that clarifies the project's independent status and features.
(repo-wide) · high confidence
Seahorse short-term memory engine with budget-aware context assembly and compaction
The seahorse package now implements a short-term memory engine that manages conversation context through budget-constrained assembly and automatic compaction. The new Assembler splits context into a protected 'fresh tail' of recent messages and an evictable prefix, ensuring the active tool-call turn is preserved even when it exceeds the token budget. A CompactionEngine automatically triggers leaf and condensed summarization when context usage exceeds 75% of the window, with a safety cap to prevent infinite loops during aggressive compaction. The underlying SQLite schema has been updated to support these features, including new \message\_parts\ tables for structured tool data, \reasoning\_content\ and \model\_name\ columns, and FTS5 full-text search indexes with trigram tokenization for CJK support. User input for search queries is now sanitized to prevent FTS5 operator injection.
pkg/seahorse · high confidence
Shared utilities for OpenAI Responses API integration
Added a new \openai\_responses\_common\ package providing shared utilities for providers using the OpenAI Responses API (such as Azure OpenAI). This includes functions to translate internal message formats into the Responses API input structure (handling system instructions, user/assistant/tool messages, and multipart media), resolve tool call details, and convert tool definitions. Comprehensive unit tests were added to verify message translation, tool call resolution, and error handling.
_pkg/providers/openai\_responses\common · high confidence
Slack channel adapter refactored into a dedicated subpackage with Socket Mode and media support
The Slack integration has been restructured into a new \pkg/channels/slack\ subpackage, introducing a Socket Mode-based connection for more reliable real-time messaging. This update adds support for sending media attachments via the \MediaSender\ interface, enabling richer content delivery in Slack conversations. The adapter now properly handles threaded replies and includes comprehensive unit tests for chat ID parsing, outbound target resolution, and bot mention stripping to ensure robust message routing.
pkg/channels/slack · high confidence
Structured session scoping and JSONL persistence backend
Session management now uses a structured scope (version 1) with dimensions like space, chat, topic, and sender to determine session keys, replacing the previous flat routing logic. A new JSONL backend wraps the memory store to provide durable, fire-and-forget persistence with alias promotion and metadata resolution, while the legacy SessionManager is updated to sanitize file paths (replacing colons and slashes) and normalize timestamps. This change ensures that sessions are correctly isolated by context (e.g., Telegram forum topics remain separate by default) and that history is persisted reliably with support for summaries and tool calls.
pkg/session · high confidence
Unified file-edit diff previews and structured tool results
File-edit tools now show a unified diff of changes directly in the chat, helping you verify edits and understand context. The diff preview is limited to 16 KB for users and 64 KB for the model, and it correctly handles files that lack a trailing newline. Tool execution results are now structured with separate content for the user and the model, supporting silent updates, async operations, and error reporting.
pkg/tools/shared · high confidence
Unified identity matching with canonical platform:id format
The identity package now supports a canonical "platform:id" format (e.g., "telegram:123456") for allow-list entries, enabling precise cross-platform identity matching. This change introduces backward compatibility with legacy formats, including pure numeric IDs, @username prefixes, and compound "id\|username" strings. It also fixes support for negative integers in numeric ID matching, which is required for Telegram group/channel IDs.
pkg/identity · high confidence
Architecture
Agent loop refactored into modular sub-packages with adapter interfaces
The agent loop implementation has been restructured into focused sub-packages (agent.go, agent\_command.go, agent\_event.go, agent\_init.go, agent\_inject.go, agent\_mcp.go, agent\_media.go, agent\_message.go) to improve code organization and maintainability. New adapter interfaces (ChannelManager, MessageBus) in the adapters package provide a clean abstraction layer for channel and message bus interactions, decoupling the agent loop from concrete implementations. This refactoring introduces dedicated modules for command handling, event emission, initialization, dependency injection, MCP integration, media processing, and message routing, making the agent loop more modular and easier to test while preserving all existing functionality.
pkg/agent · high confidence
Channel system refactored with factory registry, structured messaging, and centralized orchestration
The channel subsystem has been restructured to improve reliability and extensibility. Channel implementations have been moved from the top-level \pkg/channels\ package into isolated sub-packages (e.g., \telegram/\, \discord/\, and the new \deltachat/\), registered via a factory registry to eliminate direct import coupling. The \Manager\ now handles centralized orchestration, including worker queues, rate limiting, send retries with error classification (using new sentinel errors like \ErrRateLimit\ and \ErrTemporary\), and automated typing/placeholder management. Message routing has been standardized by promoting \Peer\ and \MessageID\ from generic metadata to structured fields in the \MessageBus\, and a new \BaseChannel\ abstraction provides shared logic for allow-lists and group trigger filtering.
pkg/channels · high confidence
Migrate frontend to modern tooling and UI component library
The web frontend has been restructured to use a modern development stack, introducing a new configuration for the Shadcn UI library (Radix Vega style with Tabler icons), a flat ESLint configuration, and Prettier with import sorting. This change also establishes standard project scaffolding with .editorconfig, .gitignore, and index.html, laying the groundwork for the modular web frontend and improved management UX.
web/frontend · high confidence
Behavioural changes
Anthropic provider adds extended thinking support and fixes tool call handling
The Anthropic provider now supports extended thinking modes (adaptive, low, medium, high, xhigh) for Claude models, automatically clearing temperature when thinking is enabled and clamping the thinking budget to respect the user's max\_tokens limit. Additionally, the provider fixes a bug where tool calls with empty names were causing API errors by skipping them, and adds a fallback to resolve tool names and arguments from the Function field when history is reloaded from the session store, ensuring tool\_use and tool\_result blocks remain properly paired.
pkg/providers/anthropic · high confidence
CLI restructured to Cobra command framework with new config and version commands
The PicoClaw command-line interface has been migrated from a custom switch-based argument parser to the Cobra library, providing a structured subcommand architecture. This change introduces dedicated commands for managing configuration (including a new \config reset\ command to restore factory defaults) and displaying version information, while maintaining existing functionality for agent, gateway, status, cron, skills, and other operations under a unified, modern CLI structure.
cmd/picoclaw · high confidence
Config system restructured with new channel settings, secure credential handling, and migration support
The configuration system has been significantly refactored to support a more modular and secure setup. A new \config\_channel.go\ introduces a unified \Channel\ struct with a \RawNode\ type that seamlessly handles both JSON and YAML formats, including deep merging for settings. Secure credentials (API keys, tokens) are now managed via \SecureString\ and \SecureStrings\ types, which support encryption and prevent accidental logging or exposure in JSON outputs. The system also includes migration logic (\config\_old.go\) to convert legacy V0 provider maps into the new \model\_list\ format. Additionally, new configuration options for event logging (\events.go\) and gateway settings (\gateway.go\) provide finer control over runtime behavior and diagnostics.
pkg/config · high confidence
Configurable home and config paths via environment variables
Users can now override the default Picoclaw home directory and configuration file location using the PICOCLAW\_HOME and PICOCLAW\_CONFIG environment variables. If PICOCLAW\_CONFIG is set, it is used directly as the config file path; otherwise, the config file is loaded from the directory specified by PICOCLAW\_HOME (defaulting to \~/.picoclaw). This change centralizes path resolution logic in the internal helpers, ensuring consistent behavior across the CLI for locating configuration and workspace data.
cmd/picoclaw/internal · high confidence
Cron service refactored for concurrency safety and event-driven scheduling
The cron service now uses an event-driven model with a wake channel and dynamic timers instead of a fixed 1-second ticker, improving responsiveness and resource usage. Concurrency safety is enhanced by locking the store during job checks and executing jobs outside the lock to prevent deadlocks. The scheduler now recomputes next run times when job schedules or enabled states change, and GetJob returns a deep copy to prevent external mutation of internal state. Additionally, the cron store file is now saved with restrictive permissions (0600) to protect sensitive job data.
pkg/cron · high confidence
Cron subcommand migrated to Cobra CLI structure
The cron management interface has been rebuilt using the Cobra library, introducing a structured \picoclaw cron\ command with subcommands for listing, adding, removing, enabling, and disabling scheduled jobs. This change replaces the previous implementation with a unified command-line interface that resolves the job store path dynamically from the configuration at execution time, ensuring consistent behavior across all cron operations.
cmd/picoclaw/internal/cron · high confidence
Gateway command adds host override and no-truncate flags
The gateway subcommand now supports a --host flag that allows users to override the gateway binding address for the current run, with input normalized via the netbind package to handle multi-host formats. Additionally, a --no-truncate (shorthand -T) flag has been added to disable string truncation in debug logs, though it requires the --debug flag to be enabled. These changes are implemented within the Cobra-based command structure for the gateway component.
cmd/picoclaw/internal/gateway · high confidence
Gateway startup reliability, logging, and channel availability improvements
The gateway now logs startup errors before exiting and writes a PID file to enforce a singleton instance, preventing conflicting runs. It also publishes structured runtime events (including duration and error details) for better observability. The Matrix channel is now explicitly excluded on unsupported platforms (mipsle, NetBSD, FreeBSD/arm) to avoid build failures, while other channels like Slack Webhook, VK, and MQTT are available. Additionally, the gateway supports multi-host binding and includes tests for startup failure scenarios and listener behavior.
pkg/gateway · high confidence
Heartbeat service refactored with configurable intervals and async task support
The heartbeat service now supports configurable check intervals (defaulting to 30 minutes, with a 5-minute minimum) and handles asynchronous task execution via a new handler interface. It routes results through a message bus, logs output to a workspace file, and provides robust start/stop lifecycle management with proper concurrency safety.
pkg/heartbeat · high confidence
Introduce Cobra-based migrate command with flexible migration options
The migrate command has been refactored to use the Cobra CLI framework, providing a structured interface for migrating configurations and workspace files from other platforms (such as OpenClaw) to Picoclaw. Users can now control the migration process via specific flags: \--from\ to specify the source platform, \--dry-run\ to preview changes without applying them, \--refresh\ to re-sync workspace files, \--config-only\ or \--workspace-only\ to target specific data types, \--force\ to skip confirmation prompts, and \--source-home\/\--target-home\ to override default directories. This change standardizes the command structure and offers granular control over the migration workflow.
cmd/picoclaw/internal/migrate · high confidence
Introduce internal channel detection logic
Added a new constants file defining a set of internal channels (cli, system, subagent) and a helper function to identify them, enabling the system to distinguish internal communication channels from user-facing ones.
pkg/constants · high confidence
Logger refactored to Zerolog with panic capture and token masking
The logging subsystem has been migrated from a custom implementation to the Zerolog library, enabling structured logging with a configurable console formatter that highlights components and properly handles multiline strings and JSON objects. A new panic logging mechanism has been added to capture stack traces and error details to a dedicated file on both Unix and Windows systems. Additionally, sensitive data protection is now built into the logger, specifically masking Telegram bot tokens in log output by preserving only the first and last four characters of the secret for identification purposes.
pkg/logger · high confidence
Message bus refactored with structured contexts, backpressure, and runtime events
The message bus in pkg/bus has been significantly restructured to improve reliability and observability. Inbound and outbound messages now use a normalized InboundContext struct for addressing, with legacy fields automatically mirrored for backward compatibility. The bus buffer size was reduced from 100 to 64 for core streams, while audio chunk buffers were increased to 256 to handle streaming workloads. Backpressure handling was added: critical streams (inbound, outbound, media, voice) block on full buffers, while audio streams drop messages after a 150ms timeout to prevent memory hazards. The bus now publishes structured runtime events for publish failures, message drops, and lifecycle states (close started/drained/completed). New types include SenderInfo for platform identity, OutboundScope for session scoping, ContextUsage for token tracking, and dedicated AudioChunk/VoiceControl types for voice streaming.
pkg/bus · high confidence
Migrate launcher to modular web frontend with new routing and theming
The launcher's web interface has been restructured into a modular frontend architecture. This change introduces a new application provider layer (\app-providers.tsx\) that initializes the highlight theme, and a centralized entry point (\main.tsx\) that wires up React Query, TanStack Router, and internationalization. A new global stylesheet (\index.css\) defines the design system, including Tailwind CSS configuration, CSS variables for light/dark modes, and custom scrollbar styling. The generated route tree (\routeTree.gen.ts\) establishes the new navigation structure, exposing pages for models, logs, launcher setup/login, credentials, configuration, agent management (tools, skills, hub), and channels.
web/frontend/src · high confidence
New append-only JSONL session store with legacy migration
Session history is now persisted using an append-only JSONL format (one message per line) with a separate metadata file, replacing the previous storage mechanism. This change improves crash safety and write performance by avoiding in-place file modifications. The system automatically migrates existing legacy JSON session files to the new format on startup, preserving message history, summaries, tool calls, and model names. Session keys are sanitized to prevent invalid file paths, and metadata such as aliases and scope is now stored and persisted alongside the conversation history.
pkg/memory · high confidence
New explicit ASR configuration and multi-provider transcription support
The \pkg/audio/asr\ package introduces a structured, explicit configuration model for voice input, replacing the previous implicit voice handling. Users must now define ASR-capable entries in \model\_list\ and reference them via \voice.model\_name\, with API keys stored in \.security.yml\. The system supports three transcription routes: ElevenLabs (using the \scribe\_v1\ model), OpenAI-compatible Whisper endpoints (e.g., Groq, OpenAI), and multimodal audio-capable chat models (e.g., Gemini, GPT-4o-audio). The \DetectTranscriber\ function resolves the appropriate provider based on these explicit settings, falling back to legacy auto-detection only for backward compatibility. This change also includes comprehensive documentation and unit tests for the new agent, transcribers, and configuration logic.
pkg/audio/asr · high confidence
New launcher authentication flow and modular route structure
The frontend now enforces a standard HTTP login and setup flow for the dashboard, introducing dedicated routes for launcher authentication (/launcher-login and /launcher-setup) that handle password-based credential management and initial configuration. The root layout has been updated to proactively check session status and redirect unauthenticated users to these new pages, while also initializing the chat store only for authenticated views. Additionally, the routing structure has been modularized to support new agent management capabilities, with new routes for the agent hub, skills, and tools, as well as dedicated pages for channels, configuration, credentials, logs, and models.
web/frontend/src/routes · high confidence
New launcher dashboard authentication and channel configuration APIs
The web backend now provides a complete password-based authentication system for the launcher dashboard, replacing the previous token-based approach. This includes endpoints for setup, login, logout, and status checks, protected by cross-site request forgery (CSRF) validation and per-IP rate limiting. Additionally, new read-only API endpoints expose a catalog of supported communication channels and their configuration settings, ensuring that sensitive credentials are never leaked in the response while indicating which secrets are currently configured.
web/backend · high confidence
Onboarding now supports credential encryption and structured workspace templates
The onboard command now includes a new --enc flag that allows users to enable credential encryption by generating an SSH key and setting a passphrase, which is used to encrypt API keys in the configuration file. Additionally, the workspace initialization process has been updated to use a structured set of agent files (AGENT.md, SOUL.md, USER.md) instead of the previous legacy templates (AGENTS.md, IDENTITY.md), ensuring a more organized workspace setup for new users.
cmd/picoclaw/internal/onboard · high confidence
Persistent workspace state with atomic saves and migration
The application now persists the last active channel and chat ID in a dedicated state file (state/state.json) within the workspace directory, automatically migrating data from the previous root-level state.json location. State updates are performed atomically using a temporary file and rename pattern to prevent corruption, and concurrent access is protected by read-write locks.
pkg/state · high confidence
Redesigned channel configuration management with secure secret handling and list editing
The channel settings interface has been rebuilt to improve usability and security. Users can now edit array-based configuration fields (such as allow-lists) via a dedicated list editor that supports adding and removing items. Secret values (tokens, passwords, keys) are no longer exposed in plain text; instead, the UI uses masked fields that only accept new values, preserving existing secrets unless explicitly changed. The configuration page also handles nested config structures and provides clear prompts when a restart is required after saving changes.
web/frontend/src/components/channels · high confidence
Redesigned chat architecture with native image support and structured message handling
The chat feature has been rebuilt with a new internal architecture that introduces native support for pasting and dragging-and-dropping images into the composer, alongside a refined message state system. This system now distinguishes between normal, thought, and tool\_calls message kinds, allowing users to selectively control the visibility of assistant details (thoughts and tool usage) via a new preference setting that migrates from the legacy 'show thoughts' toggle. The update also improves connection stability by deriving WebSocket URLs from the browser's current location and ensures robust handling of tool calls and legacy feedback formats.
web/frontend/src/features/chat · high confidence
Structured terminal UI with styled panels and columns
The PicoClaw CLI now renders help text, status reports, version info, onboarding messages, and MCP server details using a modern, structured layout. On wide interactive terminals, output is presented in bordered panels and two-column formats (e.g., separating command flags from descriptions, or status paths from provider states) with color-coded accents; on narrow terminals, non-TTY outputs, or when color is disabled, the CLI gracefully falls back to plain, line-oriented text.
cmd/picoclaw/internal/cliui · high confidence
Telegram channel restructured with MarkdownV2 support and robust command registration
The Telegram channel implementation has been refactored to improve reliability and formatting fidelity. Command registration now runs asynchronously with jittered exponential backoff, ensuring that temporary API failures do not block message intake. Outbound message formatting has been upgraded to use Telegram's MarkdownV2 parse mode, featuring a new parser that correctly handles complex entities like inline URLs, code blocks, and special characters without breaking links. Additionally, the channel now supports custom Telegram Bot API servers via a configurable base URL and includes comprehensive unit tests for the new parsing logic and registration behavior.
pkg/channels/telegram · high confidence
Tmux skill files relocated to workspace directory
The tmux skill's documentation and scripts (SKILL.md, find-sessions.sh, wait-for-text.sh) have been moved from the root skills directory to the workspace/skills/tmux path. This structural change aligns the skill's location with the new onboard workflow that supports installing built-in agent files and skills, ensuring these resources are correctly positioned for workspace-specific usage.
workspace/skills/tmux · medium confidence
Tools page restructured into tabbed library and web search settings
The Tools page now uses a tabbed interface with a 'Tool Library' tab for browsing, searching, and filtering available tools by status, and a 'Web Search' tab for configuring web search providers, global settings, and API keys. This change introduces new components for the tabbed layout, tool status badges, and web search configuration UI, along with hooks to manage tool toggling and web search settings persistence.
web/frontend/src/components/agent/tools · high confidence
WhatsApp channel restructured into a dedicated subpackage with improved lifecycle and error handling
The WhatsApp channel implementation has been moved from a single file into a dedicated \pkg/channels/whatsapp\ subpackage, introducing a formal initialization routine that registers the channel factory. This change refactors the channel's lifecycle management to use explicit context cancellation, ensuring that the background listener goroutine stops cleanly when the channel is stopped. Error handling is standardized with specific sentinel types for temporary failures, and logging is upgraded to a structured logger. Additionally, the \Send\ method now returns message IDs, and incoming messages are consistently forwarded to the bus rather than being consumed locally for generic commands.
pkg/channels/whatsapp · high confidence
Workspace migration planning and execution logic added
The migration subsystem now includes internal logic to plan and execute workspace migrations. This change introduces utilities to resolve target home directories, expand tilde paths, and plan file and directory copies between source and destination workspaces. It defines a structured approach for handling migration actions (copy, skip, backup, create directory) and provides a \CopyFile\ function that correctly handles and reports close errors on writable files, ensuring data integrity during the migration process.
pkg/migrate/internal · high confidence
Fixes
Filter invalid reasoning-only assistant messages from chat history
The message utility package now includes logic to identify and remove transient assistant thought messages from conversation history. These are messages that contain only reasoning content without any actual response, tool calls, or media, which are considered invalid persisted records. The new FilterInvalidHistoryMessages function allows the system to clean up such entries before replaying or reconstructing chat sessions, ensuring that only canonical history records are preserved.
pkg/providers/messageutil · high confidence
Dependencies
Major dependency upgrades and Go version bump
The web frontend has been upgraded to React 19.2.5, Vite 8.0.16, Tailwind CSS 4.3.0, and shadcn 4.12.0, while the Go backend has been updated to Go 1.25.13 and upgraded key libraries including the Anthropic SDK, AWS SDK v2, and SQLite driver.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 58 → 54 (-4.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 70 → 49 (-20.7)
- Architecture 100 → 87 (-13.0)
- Maturity 82 → 82 (-0.2)
- Readiness 56 → 61 (+4.6)
- Security 62 → 59 (-2.6)
- Accessibility 53 → 52 (-1.1)
Resolved (243)
- Change coupling: config.go ↔ factory.go (pkg/config/config.go)
- Change coupling: factory.go ↔ provider.go (pkg/providers/factory.go)
- Change coupling: migration.go ↔ factory.go (pkg/config/migration.go)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (cmd/membench/eval.go)
- Duplicated block (10 lines × 2) (cmd/membench/eval.go)
- Duplicated block (10 lines × 2) (cmd/picoclaw/internal/auth/wecom.go)
- Duplicated block (10 lines × 2) (cmd/picoclaw/internal/auth/wecom.go)
- Duplicated block (10 lines × 2) (cmd/picoclaw/internal/cliui/help_cmd.go)
- Duplicated block (10 lines × 2) (cmd/picoclaw/internal/mcp/show.go)
- Duplicated block (10 lines × 2) (cmd/picoclaw/internal/skills/helpers.go)
- Duplicated block (10 lines × 2) (pkg/agent/turn_context.go)
- Duplicated block (10 lines × 2) (pkg/audio/tts/mimo_tts.go)
- Duplicated block (10 lines × 2) (pkg/channels/feishu/feishu_64.go)
- Duplicated block (10 lines × 2) (pkg/channels/manager.go)
- Duplicated block (10 lines × 2) (pkg/channels/onebot/onebot.go)
- Duplicated block (10 lines × 2) (pkg/channels/slack/slack.go)
- Duplicated block (10 lines × 2) (pkg/channels/weixin/api.go)
- Duplicated block (10 lines × 2) (pkg/evolution/drafts.go)
- …and 223 more
New (715)
- Change-coupling hub: factory.go → config.go, migration.go, provider.go (pkg/providers/factory.go)
- ClassTooLong: ContextBuilder (pkg/agent/context.go)
- ClassTooLong: DeltaChatChannel (pkg/channels/deltachat/deltachat.go)
- ClassTooLong: DiscordChannel (pkg/channels/discord/discord.go)
- ClassTooLong: FeishuChannel (pkg/channels/feishu/feishu_64.go)
- ClassTooLong: Manager (pkg/channels/manager.go)
- ClassTooLong: OneBotChannel (pkg/channels/onebot/onebot.go)
- ClassTooLong: PicoChannel (pkg/channels/pico/pico.go)
- ClassTooLong: QQChannel (pkg/channels/qq/qq.go)
- ClassTooLong: Runtime (pkg/evolution/runtime.go)
- ClassTooLong: Store (pkg/seahorse/store.go)
- ClassTooLong: TelegramChannel (pkg/channels/telegram/telegram.go)
- ClassTooLong: WeComChannel (pkg/channels/wecom/wecom.go)
- Dependency advisory scan runs only on code events
- Documentation: no architecture or design documentation (docs/channels/maixcam/README.md)
- Documentation: no architecture or design documentation (docs/channels/matrix/README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (cmd/membench/eval.go)
- Duplicated block (10 lines × 2) (cmd/picoclaw/internal/auth/helpers.go)
- …and 695 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- web/frontend — 1 commit
Notable commits
- change: feat(models): add configurable default fallback chain (#3200)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
sipeed/picoclaw was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit bbf6893ca7afad27f1d00a0f5a45982a549c6ed6 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.