Skip to content
CAI
Software that uses CAICheck a score

ZSeven-W/openpencil

57.1

Adequate · 29 September 2026

718k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

OpenPencil is a cross-platform, Rust-based design and code generation platform that converts visual layouts into editable documents and production-ready code. It features a robust peer-to-peer collaboration engine with secure relay infrastructure, allowing real-time editing across desktop, mobile, and web environments. The system integrates AI agents to automate design creation, quality validation, and code synthesis, supporting multiple frameworks and platforms through a modular, extensible architecture.

Features

AI code generation pipeline ported to Rust

The AI-driven code generation pipeline has been ported from TypeScript to Rust within the \op-codegen\ crate. This change introduces a pull-based, transport-agnostic state machine that handles planning, chunking, assembly, and rescue phases, allowing the host application to drive the process via \step()\ and feed back streamed text. The implementation includes deterministic fallback generators for multiple frameworks (React, Vue, Svelte, Flutter, etc.), a structure bundle packager for exporting design assets, and logic to extract and rewrite embedded image data-URLs into stable asset paths to optimize prompt sizes.

crates/op-codegen/src/ai · high confidence

Add AI support pitch deck template

A new six-page presentation template named 'ai-support-pitch-deck' is now available in the editor's scene library. Designed for pitching an autonomous customer service AI product, it includes structured slides for the cover, pain points, market trends, solution pillars, workflow, key metrics, a customer case study, roadmap, team, and funding ask.

_crates/op-editor-core/assets/scene\templates · high confidence

Add HTML snapshot extractor script

Added a new JavaScript asset (\snapshot-extractor.js\) that captures the visual structure of an HTML page into a JSON snapshot. The script traverses the DOM, capturing element styles (including complex properties like gradients, transforms, and stacking contexts), text content, and media, while enforcing limits on node count (40,000) and image data size (24 MiB) to ensure performance and payload manageability.

crates/op-html/assets · high confidence

Add OpenPencil VS Code extension session management and tests

This change introduces the core session management layer for the new OpenPencil VS Code extension (located in packages/op-vscode). It adds the PenSession state machine, which handles the document protocol lifecycle (booting, ready, saving, conflict resolution) via a postMessage bridge, and the SessionRegistry to track active sessions per file. Comprehensive unit tests are included for both the session logic and the registry to ensure correct behavior for init retries, state transitions, and active file tracking.

packages/op-vscode/src/session · high confidence

Add P2P collaboration smoke test binary

A new \op-collab-smoke\ binary is introduced to validate two-process peer-to-peer collaboration. It launches distinct owner and guest processes that perform a Noise XX handshake, verify signed tickets, and exchange collaboration frames over TCP. The binary includes a supervisor mode that runs a matrix of scenarios (such as alternating commits, reconnect catch-up, and epoch changes) and a LAN mode for physical-device acceptance testing, ensuring both processes converge to the same canonical document hash.

crates/op-collab-smoke · high confidence

Add per-node render-parity diff harness

Added a new script-based tooling suite in \scripts/render-parity\ to automatically compare rendered outputs between the Pencil baseline and the OpenPencil Rust implementation. The \prep\_parity.sh\ script handles the deterministic preparation of source files and renders, while \diff\_nodes.py\ performs per-node analysis using SSIM, CIE76 color difference, and bounding-box metrics to classify differences as LAYOUT, PAINT, or PASS, generating a detailed JSON and Markdown report.

scripts/render-parity · high confidence

Added G3 A/B testing harness for design generation agents

Introduced a new shell script at scripts/ab-g3/run.sh that executes an A/B comparison between the built-in agent loop and a single-shot orchestrator for OpenPencil design generation. The harness runs a defined corpus of 15 prompts across various contexts (dashboards, mobile apps, landing pages) against specified models (defaulting to glm-5.2, with optional OpenAI-compatible strong models), capturing results and gaps in a configurable output directory to facilitate audit and performance analysis.

scripts/ab-g3 · high confidence

Added build and type-generation tooling for the op-web-sdk crate

The op-web-sdk crate now includes local build scripts to manage its WebAssembly bundle and TypeScript bindings. The new build-wasm.sh script automates the compilation of the SDK to wasm32, runs wasm-bindgen, and enforces a 6 MiB gzip size limit to prevent bundle bloat, while also verifying that the resulting binary has no environment imports. Additionally, gen-types.sh generates TypeScript type definitions from the jian-ops-schema and places them in the crate's bindings directory, ensuring the vendor submodule remains clean after generation.

crates/op-web-sdk/tools · high confidence

Added headless relay reconnect probe example

A new \relay\_probe.rs\ example has been added to the \op-collab-host\ crate to allow headless testing of the public-relay reconnect loop. This tool drives the \CollabRuntime\ without a GUI, enabling an owner and a guest to meet over the real relay using a shared invite file, which is useful for verifying connection stability and reconnection behavior in isolated test environments.

crates/op-collab-host/examples · high confidence

Added local ACP test agent fixture for E2E validation

A new example agent (\op-acp-test-agent.rs\) has been added to support end-to-end testing of the desktop local-process transport. This fixture listens on standard input for JSON-RPC frames, validates initialization and session parameters against strict ndJSON expectations, and returns predefined responses. It allows the desktop application to exercise the production stdio transport with a controlled, deterministic agent during testing.

crates/op-host-desktop/examples · high confidence

Added maintenance phase prompt skills for design consistency and editing

The maintenance phase of the AI skills engine now includes specific prompt definitions to guide design modifications. These new skills enforce style consistency (colors, typography, spacing) when updating existing designs, provide rules for incrementally adding new elements while matching sibling patterns, and define a structured JavaScript-based interface for local edits and node updates.

crates/op-ai-skills/skills/phases/maintenance · high confidence

Added vision-based design QA validation skill

A new validation phase skill has been introduced that performs quality assurance on UI designs by analyzing screenshots alongside their underlying node tree structures. This skill automatically detects and proposes fixes for visual issues such as width inconsistencies, spacing errors, text clipping, alignment problems, and missing elements, while also providing a quality score. It includes specific logic to distinguish between rendering defects and intentional design patterns, such as horizontal scrollers and chart marks, ensuring that valid layouts are not incorrectly flagged.

crates/op-ai-skills/skills/phases/validation · high confidence

Android JNI engine bindings and native mobile infrastructure

This change introduces the Android JNI layer for the OpenPencil engine, providing the native bridge required for mobile operation. It includes a dedicated engine thread for safe FFI dispatch, a handle registry to manage engine lifecycles, and specific bindings for editor features (sign-in, account center, locale, and export), text input (IME and caret management), and media handling (remote images and fonts). The implementation also adds Android-specific logging via logcat and native window management for the rendering surface.

crates/op-engine-jni · high confidence

Bundled OpenPencil design skill with CLI reference and codegen pipeline

The CLI now ships with a bundled design skill (installed to the scanned skills directory) that provides a comprehensive reference for the OpenPencil design system, including the PenNode schema, semantic roles, layout rules, and common UI patterns. This skill exposes the full codegen pipeline (plan, submit, assemble, clean) and layered workflow (skeleton, content, refine) to AI agents, and includes a \skill:export\ command to package these assets for external use.

crates/op-cli · high confidence

Centralized image enrichment with visual judging and deterministic fallbacks

The \op-image-enrich\ crate now centralizes image-slot enrichment logic previously split between the desktop host and MCP services. It introduces a visual relevance judge that scores search candidates (On/Weak/Off) and re-ranks them, ensuring only relevant images are selected. When a search fails or yields no suitable results, the system applies a deterministic fallback policy: it generates theme-adaptive placeholder tiles (thumbnails, media blocks, or silent covered blocks) based on slot size and layout context, rather than leaving empty grey boxes. Additionally, imported images are automatically down-scaled to a maximum edge of 2048px to prevent document bloat, and all network requests use rustls for secure transport.

crates/op-image-enrich · high confidence

Chrome extension core adds account integration, design system extraction, and delivery targets

The \op-chrome-extension-core\ crate introduces the foundational logic for the new OpenPencil Chrome extension. It adds account management (account.rs) supporting dual-region Hub origins (China and Global) with a public-client authentication flow, and delivery routing (delivery.rs) that allows signed-in users to send captures to their Hub account or the local editor. It also implements intelligent design system extraction (design\_md.rs, design\_md\_job.rs, design\_md\_palette.rs, design\_md\_render.rs) which parses browser evidence into deterministic Markdown and handles async job polling for LLM-enhanced output.

crates/op-chrome-extension-core · high confidence

Complete i18n coverage across menus, providers, and panels

The op-i18n crate now provides full localization support for 15 locales (including German, Chinese, Japanese, and others) across the entire application. This update introduces comprehensive translation catalogs for core UI elements, the new prompt center, scene templates, and collaboration features, ensuring a consistent localized experience for users across all panels and providers.

crates/op-i18n · high confidence

Generated TypeScript bindings for OpenPencil SDK

The \crates/op-web-sdk/bindings/ops.ts\ file has been added, providing the generated TypeScript type definitions for the OpenPencil SDK. This file, produced by ts-rs, exposes core types such as Action, AppConfig, and various UI node definitions (e.g., CheckboxNode, EllipseNode), enabling TypeScript consumers to interact with the SDK's API surface with proper type safety.

crates/op-web-sdk/bindings · high confidence

Headless agentic loop smoke testing and model discovery

The smoke testing harness now supports a headless agentic tool-loop mode (OPENPENCIL\_SMOKE\_LOOP) that exercises the design agent's iterative tool-calling against a live EditorState, including a minimal scaffold seed path for weak models. It adds a best-of-N candidate selection mechanism (OPENPENCIL\_SMOKE\_BEST\_OF) to score and pick the highest-quality generation, and introduces a post-loop image-fill step (OPENPENCIL\_SMOKE\_FILL\_IMAGES) to resolve image-search queries using an optional vision judge. A new audit rubric (OPENPENCIL\_SMOKE\_AUDIT) provides deterministic metrics for chrome completeness, vocabulary richness, interactivity, and content completeness. Additionally, a new op-builtin-model-discovery crate enables runtime discovery of model catalogs from configured providers with bounded, secure HTTP requests.

crates/op-smoke · high confidence

Initial release of OpenPencil for VS Code

This change introduces the OpenPencil VS Code extension, enabling users to open, view, and edit \.op\ design files directly within the editor via a custom webview backed by a local daemon. Key capabilities include live preview, managed account login, LAN/public-relay collaboration, \.fig\ file import, and AI-driven code generation for React or Vue. The extension also integrates with AI tooling through a local MCP proxy, allows installation of design skills, and provides a \@openpencil\ chat participant, all while respecting workspace trust settings.

packages/op-vscode · high confidence

Introduce @zseven-w/op-web-sdk for read-only document viewing

The \packages/op-web-sdk\ package is now available as a read-only web SDK for OpenPencil \.op\ files, backed by a Rust/WASM renderer. It provides a \createViewer\ API that binds to an HTML canvas, allowing users to load documents, inspect metadata (document name, page count), control the viewport (pan, zoom, fit), and export the current view to SVG. The SDK intentionally excludes editing capabilities (node creation, selection, or property panels) and includes a demo page and a comprehensive test suite to verify event handling, navigation, and schema compatibility.

packages/op-web-sdk · high confidence

Introduce Agent Client Protocol (ACP) client crate

Added the \op-acp\ crate, a Rust implementation of the Agent Client Protocol client that enables third-party AI agents to integrate with OpenPencil. This new component manages the full lifecycle of agent connections—supporting both local child processes (via stdio) and remote endpoints (via WebSocket)—and handles the JSON-RPC 2.0 handshake, session management, and streaming prompt interactions. It includes robust error handling for process spawning (specifically retrying transient \ETXTBSY\ errors on Linux/macOS), bounded stderr capture for debugging agent failures, and an event adapter that maps agent notifications into the application's chat delta vocabulary.

crates/op-acp · high confidence

Introduce OpenPencil VS Code extension with AI code generation and MCP configuration

This change adds the \op-vscode\ extension, providing a custom editor for \.op\ design files and a \.fig\ import workflow that converts Figma designs to the OpenPencil format. It introduces a 'Generate Code' command that uses the VS Code Language Model API to create React or Vue components from designs, with strict validation to prevent path traversal and size-limit violations. Additionally, it adds commands to configure and remove MCP (Model Context Protocol) settings for AI agents, including a diff-preview before writing, and registers a read-only 'OpenPencil' chat participant for design advice.

packages/op-vscode/src/vscode · high confidence

Introduce OpenPencil Web Capture Chrome extension

Adds a new Chrome extension that captures the rendered state of web pages and imports them as editable design nodes into OpenPencil, or extracts a reusable design-system summary (design.md). The extension runs a Rust logic core compiled to WebAssembly and provides four actions: capturing the full page, capturing a specific element, downloading a ready-to-open .op file, and extracting design.md evidence. It supports account-based uploads to the OpenPencil hub with fallback to the local desktop app, handles internationalization for multiple languages, and enforces strict security policies including loopback-only communication and content security constraints for WebAssembly.

packages/op-chrome-extension · high confidence

Introduce React and Vue adapters for the OpenPencil read-only web viewer

This change adds two new framework-specific packages, \@zseven-w/op-web-sdk-react\ and \@zseven-w/op-web-sdk-vue\, which wrap the core \@zseven-w/op-web-sdk\ to enable embedding the read-only design canvas in React 19 and Vue 3 applications. The React adapter provides a \DesignView\ component and hooks (\useDocument\, \useViewport\, \useActivePage\) that use \useSyncExternalStore\ to efficiently sync viewer state with React's render loop. The Vue adapter offers a \DesignView\ component and composables (\useDocument\, \useViewport\, \useActivePage\) that leverage Vue's reactivity system to update views on viewer events. Both adapters handle the asynchronous loading of the underlying WebAssembly binary and provide a \DesignProvider\/\provideViewer\ mechanism for advanced layouts.

packages/op-web-sdk-react · high confidence

Introduce Rust-native batch\_design tool with lenient model-input normalization

The \op-mcp\ crate now includes a Rust implementation of the \batch\_design\ tool, enabling atomic insertion of node forests via an \operations\ DSL (e.g., \I(parent, node)\), \nodes\_json\, or a sandboxed \script\ input. To accommodate imperfect model outputs, the tool applies lenient normalization: it maps Figma/Pencil dialects (like \layoutMode\ to \layout\), flattens structured layout objects, normalizes fill type names (e.g., \linear-gradient\ to \linear\_gradient\), and repairs gradient stop fields (\pos\ to \offset\). The tool predicts host-assigned node IDs in its response to match TypeScript behavior and ensures transactional integrity by rejecting batches on any single validation error.

crates/op-mcp · high confidence

Introduce Unix-only HSM-backed relay locator signer

Added a new \op-collab-relay-locator-hsm\ crate that provides a PKCS\#11-backed daemon for signing relay locators. This component is strictly limited to Unix platforms, relying on POSIX-specific security guarantees such as Unix-domain socket peer credential authentication (\SO\_PEERCRED\/\getpeereid\), strict file ownership and permission checks for configuration and PIN files, and exclusive file locking. It manages an isolated PKCS\#11 token to store Ed25519 key pairs, supporting key provisioning, readiness canaries, and the signing of canonical locator payloads via a dedicated binary interface.

crates/op-collab-relay-locator-hsm · high confidence

Introduce centralized account state and agent settings models in editor core

The editor core now owns the plain-data models for user authentication and AI agent configuration, moving them out of host-specific UI layers. A new \AccountState\ enum tracks signed-in status and profile display details, while \AgentSettings\ and its sub-modules (\config\_types\, \mutators\, \acp\_connection\) define the structure for built-in agents, ACP connections, image-generation profiles, and MCP CLI toggles. This centralization provides a single source of truth for account and agent state that is platform-agnostic and ready for host integration.

crates/op-editor-core/src · high confidence

Introduce headless op-host-web-server binary

A new headless binary, op-host-web-server, is available to run the OpenPencil web and MCP server without any GUI dependencies. It delegates command-line mode handling to op-host-services and supports three modes: --serve-web for the headless web-canvas daemon, --mcp for a JSON-RPC stdio MCP server, and --mcp-http for a Streamable-HTTP MCP server. This allows container or server images to remain GUI-free while providing the same dispatch logic as the desktop binary.

crates/op-host-web-server/src · high confidence

Introduce host-free ACP agent probe and web AI proxy services

The \op-host-services\ crate now hosts the core logic for ACP agent connection probing and the web AI proxy, previously located in desktop-specific modules. The new \acp\_agent\_probe\_host.rs\ provides a platform-agnostic probe job that validates agent connectivity and session lifecycle, while \ai\_proxy.rs\ implements the backend proxy for the WASM web bundle, handling structured model routing, skill expansion, and SSE streaming. Additionally, \chat\_attachment.rs\ moves attachment handling (base64 encoding and temp-file spilling) to this shared location to support both CLI and web transports.

crates/op-host-services/src · high confidence

Introduce op-collab crate for deterministic, resource-bounded document collaboration

The new \op-collab\ crate provides the core logic for OpenPencil's peer-to-peer collaboration, handling versioned wire DTOs, deterministic document hashing, and exact atomic operations on the \PenDocument\ schema. It enforces strict resource limits—such as maximum operations per transaction, subtree size, tree depth, and validation visits—to prevent resource exhaustion during document edits. The crate supports a specific M1 edit matrix, allowing property changes (like text content, opacity, or layout) and structural changes (inserting, deleting, or moving basic nodes like frames and rectangles) while rejecting unsupported fields or complex mixed edits. It also manages session state, including owner/guest roles, namespace-scoped ID counters, and replay verification to ensure that generated collaboration transactions deterministically reproduce the target document state.

crates/op-collab · high confidence

Introduce public WebSocket relay client for collaboration

The \op-collab-relay-client\ crate is now available, providing a native relay data-plane client that adapts the existing loopback TCP collaboration transport to a public WebSocket relay. This client bridges local TCP connections to a remote relay endpoint without terminating or inspecting the inner Noise session, supporting both guest and owner roles with bounded lifetimes and strict authentication via a caller-owned \RelayAuthenticator\. It enforces security by requiring \wss://\ in production, capping bearer credentials, and pinning relay public keys, while offering reduced-assurance compatibility modes for specific relay configurations.

crates/op-collab-relay-client · high confidence

Introduce public collaboration relay protocol with challenge-bound authentication and short pairing codes

This crate defines the wire protocol for OpenPencil's public collaboration relay, enabling users to connect via short, 10-character region-tagged pairing codes instead of long invite strings. The protocol introduces a new authentication mode (v2) that replaces reusable possession attestations with relay challenges bound to the caller's X25519 shared secret, enhancing security. It also supports a v2 sealed pairing invite envelope using ChaCha20-Poly1305, while maintaining backward compatibility with legacy v1 envelopes during rollout. The protocol specifies fixed-size binary formats for locators, invites, and client hellos, along with waiting-window advertisements to manage unpaired peer lanes.

crates/op-collab-relay-protocol · high confidence

Introduce public collaboration relay server with hardened authentication and connection management

This change adds the \op-collab-relay-server\ crate, providing the server-side implementation for public peer-to-peer collaboration. The relay enforces strict authentication via X25519 challenge-response proofs and bearer credentials, supporting production modes with pinned trust roots and reduced-assurance ticket binding. It manages connection lifecycles with configurable timeouts for waiting, idle, and tunnel lifetime, and includes a lease mechanism to keep unpaired owner lanes alive. Connection teardown is hardened to prevent RST-induced data loss by using a bounded linger period and embedding rejection reasons in WebSocket close frames. The server exposes configuration via environment variables and command-line flags for production, development, and health-check modes.

crates/op-collab-relay-server · high confidence

Introduce public relay collaboration with region-tagged pairing codes and hardened control-plane logic

This crate adds the control-plane core for public relay collaboration, replacing the previous public-invite model with a pairing-code flow (publish and claim endpoints) that uses 10-char region-tagged codes to exchange sealed invites. It introduces a hardened HTTP client that enforces HTTPS-only, disables redirects and proxies, applies bounded connect/request timeouts and response-size limits, and redacts sensitive data in debug output. The locator-issuance service now classifies control-plane failures (unauthorized, rate-limited, rejected) so clients can distinguish authentication issues from temporary service pressure, and it binds collaboration tickets to the owner's device DH key before delegating signing to an external HSM/KMS via the RelayLocatorSigner trait. The pairing service enforces per-owner quotas, TTL clamping, and idempotent storage, while wire formats for pairing and locator requests are strictly bounded and version-checked.

crates/op-collab-relay-control-plane · high confidence

Introduce read-only web viewer SDK with pan/zoom, SVG export, and smoke test

The \op-web-sdk\ crate now provides a read-only viewer for embedding OpenPencil documents in the browser. Users can load \.op\ JSON documents, navigate via pan/zoom (including wheel and pinch-to-zoom support), and export the active page to SVG. The SDK includes a robust render loop that idles when clean and handles failure states gracefully, along with a smoke test page to verify basic functionality.

crates/op-web-sdk/src · high confidence

Introduce relay locator server with hardened trust roots and resource limits

The relay locator server now ships with a new \op-collab-policy-file\ crate that enforces strict security checks on pinned verification key files, rejecting symlinks, foreign ownership, and group/world-writable permissions to prevent trust-root tampering. The server itself includes a bounded in-memory pairing store that caps total codes and per-owner limits to prevent squatting, and implements fixed-window rate limiting with both global and per-client ceilings to protect against resource exhaustion. Configuration is validated to ensure timeouts and concurrency limits are sensible, and Unix-specific HSM signing is isolated behind platform gates.

crates/op-collab-relay-locator-server · high confidence

Introduce shared OpenPencil config store with sandboxed mobile support

A new \op-config-store\ crate provides a unified, file-backed configuration system for the application. On desktop, it defaults to the \\~/.openpencil\ directory, while embedded mobile hosts can explicitly configure a private app-sandbox root via \configure\_user\_root\ to ensure settings are isolated from the desktop environment. The store supports atomic JSON read/write operations and includes a test-specific \redirect\_user\_root\_for\_tests\ helper to prevent parallel tests from modifying live user configuration files.

crates/op-config-store · high confidence

Introduce structured template generation system with shared design specifications

Added a new Python-based generator framework in \templates/step0/\_generators\ that defines shared design contracts for card and deck templates. This includes \cardlib.py\ for card system metrics (canvas sizes, grid, type scale) and \deckkit.py\ for deck-specific constraints (1920x1080 stage, board placement, typography rules). The system now supports generating specific template families, including screenshot tutorials (\tpl1.py\), knowledge carousels (\tpl2.py\), and high-formality strategy decks (\deck\_sounding\_navy.py\, \deck\_tidemark\_slate.py\), along with utilities to bake hint assets and generate preview cards for the editor's template gallery.

_templates/step0/\generators · high confidence

Introduces Rust-based AI skill engine with token budgeting and design system presets

The \op-ai-skills\ crate provides a phase-driven prompt-skill resolution engine, ported from the TypeScript \pen-ai-skills\ package to run natively in Rust (including wasm32 targets). It embeds a corpus of skill and style-guide markdown files, parsing them via a lightweight frontmatter parser to resolve skills by phase, intent keywords, and category priority. A key behavioral addition is the \trim\_by\_budget\ system, which enforces per-skill token caps and a total phase budget, allowing specific skills to be pinned against truncation. The crate also bundles four built-in design-system variable presets (halo, lunaris, nitro, shadcn) for light/dark theming and exposes a guideline system for topics like web-app, mobile, and slides. This change adds the core logic for skill loading, budgeting, and composition, along with comprehensive tests ensuring corpus integrity and correct prompt assembly.

crates/op-ai-skills/src · high confidence

Introduces managed daemon lifecycle, HTTP client, and pooling for the VS Code extension

The \op-vscode\ extension now manages a background \op-host-web-server\ daemon process to handle document operations. This change adds a \DaemonClient\ that spawns the daemon, performs a secure handshake (redacting tokens from logs), and handles graceful shutdown. A \DaemonHttp\ client provides token-authenticated access to the daemon's endpoints, including a new \figmaConvert\ API for converting \.fig\ files to \.op\ format. A \DaemonPool\ manages one daemon per open file, handling concurrent access, crash recovery (single restart), and active-file routing. Comprehensive unit tests verify the handshake, security, HTTP interactions, and pool lifecycle.

packages/op-vscode/src/daemon · high confidence

Introduces secure, authenticated collaboration transport with resource protection

The collaboration transport now requires authenticated admission via signed tickets, binding device identity and optional profile data (display name, avatar) to each connection. To prevent resource exhaustion, the transport enforces strict limits on pending handshakes (128 global, 4 per IP), active connections (64), and inbound reassembly buffers (128 MB aggregate), while chunked transfers are capped by class (Control, Ticket, Txn, Snapshot) with dedicated timeouts. Platform-specific secure storage (e.g., iOS Keychain with ThisDeviceOnly accessibility) protects the X25519 device identity, and the admission layer validates ticket signatures, issuer/subject/device UUIDs, expiry, and profile constraints, failing closed on malformed or expired claims.

crates/op-collab-transport/src · high confidence

Introduction of op-auth-bridge with ABI v3 support and strict provenance validation

The new op-auth-bridge crate establishes the boundary for OpenPencil's authentication and collaboration ticket verification. It integrates prebuilt, proprietary op-auth libraries (ABI v3) for ten desktop and mobile targets, enforcing strict provenance checks via Ed25519 signatures and SHA-256 digests to prevent replay attacks. The build system now validates these artifacts, isolates bundled Rust runtime symbols to avoid linker conflicts, and supports local development overrides for ABI v2 and v3 archives. Additionally, it configures regional login and collaboration trust through environment variables like OPENPENCIL\_SSO\_URL and OPENPENCIL\_COLLAB\_ISSUER, ensuring that collaboration policies are verified against a pinned offline root.

crates/op-auth-bridge · high confidence

MCP proxy and config adapters for multi-IDE support

The extension now includes a local MCP proxy that routes requests to the active document's daemon, enforcing security by rejecting non-POST methods on /mcp (returning 405), blocking requests with Origin or mismatched Host headers (returning 403), and echoing JSON-RPC errors when no document is active. It also introduces per-IDE MCP configuration adapters that detect the editor (VS Code, Cursor, Trae, Windsurf) and write typed HTTP server entries to the correct config file path while preserving existing comments and sibling fields.

packages/op-vscode/src/mcp · high confidence

MCP session auto-finalization and headless design agent capabilities

The MCP serve module now includes an auto-finalization system for file-backed sessions that automatically runs the design pipeline and saves the document when the session has been idle for a configurable period (default 45 seconds) or upon shutdown, with the behavior controlled by the OPENPENCIL\_MCP\_AUTO\_FINALIZE and OPENPENCIL\_MCP\_AUTO\_FINALIZE\_IDLE\_SECS environment variables. A new headless design agent tool (run\_design\_agent) allows the MCP to execute a full design loop against the active document using configured builtin AI providers, with structured error handling for missing providers, timeouts, and empty results. Additional tools expose design quality scanning (get\_design\_quality), image enrichment (enrich\_images), and code generation workflows (codegen\_plan, codegen\_submit\_chunk, codegen\_assemble, codegen\_clean), while document sync helpers provide REST API parity for whole-document synchronization.

_crates/op-host-services/src/mcp\serve · high confidence

Native macOS window chrome, localization, and hardened runtime entitlements

The desktop host now ships with a native \Info.plist\ and \entitlements.plist\ for the macOS bundle. The app supports a wide range of localizations (en, zh-Hans, zh-Hant, ja, ko, fr, es, de, pt, ru, hi, tr, th, vi, id) and uses the user's preferred language for native system panels. To allow the binary to link against Homebrew OpenSSL dylibs under the hardened runtime, the \com.apple.security.cs.disable-library-validation\ entitlement is enabled. Additionally, the app declares local network usage for collaboration discovery via Bonjour.

crates/op-host-desktop/src · high confidence

Native rendering host and smoke tests for Chrome UI

The native host now includes a \basic\_window\ example and manual smoke-test documentation for Linux, macOS, and Windows that verify the core rendering pipeline (Skia context, \NativeBackend\, and \RenderBackend\ implementation). This confirms that chrome elements—filled/stroked rectangles and CJK text—are painted correctly on desktop platforms, establishing the baseline for native UI rendering.

crates/op-host-native · high confidence

New AI skill knowledge base for code generation and design conversion

Added a new knowledge directory to the op-ai-skills crate containing structured markdown guides for the AI agent. This includes a 'code-to-design' skill for reverse-engineering existing frontend codebases into OpenPencil designs, and specific code generation rules for multiple frameworks including React, React Native, Flutter, Jetpack Compose, SwiftUI, Vue, Svelte, and plain HTML/CSS. The knowledge base also provides guidelines for component composition, design system hierarchy, copywriting, and general design principles to ensure consistent and high-quality output.

crates/op-ai-skills/skills/knowledge · high confidence

New C ABI for embedding the OpenPencil engine in native mobile shells

The \op-engine-ffi\ crate now exposes a stable C ABI header (\op\_engine.h\) and Rust bindings that allow platform shells to host the full OpenPencil editor on iOS and Android. This interface provides functions to create the engine with a document and platform surface, pump the frame loop, and handle input events (pointers, keyboard, IME). It also exposes a shell-action queue for platform-specific operations such as opening documents, saving files, and managing the user session (login, account center, and locale selection). A background work pump is included to allow the engine to continue processing generations and design tasks while the app is backgrounded or the display surface is suspended.

crates/op-engine-ffi/src · high confidence

New CJK typography and preview freshness QA gates

Added a suite of quality-assurance scripts in the \templates/step0/\_generators/qa\ directory to enforce CJK typography rules and verify preview asset freshness. \cjkcheck.py\ and \cjkreal.py\ work together to detect line-break issues (such as punctuation at the start of lines or orphaned characters) by simulating wrapping and cross-referencing against actual layout metrics to filter false positives. \trackcheck.py\ enforces negative letter-spacing limits for CJK text based on font size ratios. Additionally, \freshcheck.py\ audits preview artifacts (frames, overviews, and cards) by re-rendering them with the current binary and comparing byte-for-byte to catch stale images caused by renderer updates. These tools are orchestrated by \gate.sh\ to serve as a final validation step for template changes.

_templates/step0/\generators/qa · high confidence

New CSS cascade engine with UA defaults and media query support

The HTML importer now includes a dedicated CSS cascade implementation in the \op-html\ crate. This engine parses stylesheets, resolves the cascade (including specificity, origin, and layering), and applies a built-in User Agent stylesheet that defines default styles for common HTML elements like headings, paragraphs, and tables. It also supports \@media\ queries for viewport-based styling and handles CSS logical properties (such as \margin-inline-start\) by mapping them to physical properties based on text direction.

crates/op-html/src/css · high confidence

New HTML importer crate with CSS parsing and encoding support

The \op-html\ crate introduces a new HTML import pipeline that parses HTML5 DOMs into a simplified tree structure and handles CSS color and length unit parsing. It includes robust encoding sniffing for both HTML and CSS byte streams, supporting BOM detection, \@charset\ rules, and Windows-1252 fallbacks to ensure legacy stylesheets render correctly. The importer also extracts \@font-face\ declarations to warn users when web fonts are not downloaded, and includes comprehensive end-to-end tests for layout fidelity, including Tailwind CSS grid/flex behavior, list markers, and responsive image selection.

crates/op-html/src · high confidence

New HarmonyOS player shell for phone, tablet, and 2-in-1 devices

This change introduces the complete packaging skeleton for the OpenPencil HarmonyOS player, enabling the app to run on HarmonyOS 5 (API 12+) across phone, tablet, and 2-in-1 form factors. The entry module wires the prebuilt Rust NAPI engine (\libopenpencil.so\) into an ArkUI shell that renders the UI via an \XComponent\ surface. It includes the native sign-in SDKs for WeChat, Alipay, and Douyin, implements the full editor input pipeline (IME, pointer events, and keyboard handling), and supports system file pickers for opening, saving, and importing documents. The shell also handles desktop-class features like mouse input, hardware key modifiers, and background generation tasks for AI services.

packaging/harmony/entry · high confidence

New Rust-based Figma import engine

The \op-figma\ crate introduces a complete Rust implementation for importing Figma designs, replacing the previous TypeScript-based logic. This change adds support for parsing the native binary \.fig\ Kiwi format (including Zstandard/deflate decompression and ZIP archive handling), decoding Figma HTML clipboard payloads, and converting Figma node trees into the internal \PenNode\ schema. It also implements specific rendering behaviors for boolean operations, component property swaps, and icon lookups, along with comprehensive end-to-end and unit tests for the new pipeline.

crates/op-figma/src · high confidence

New Rust-based code generation crate for HTML, CSS variables, and motion

A new \op-codegen\ crate has been introduced to provide Rust implementations of the design-to-code pipeline. It includes a \CssVariables\ generator that outputs CSS custom properties (including shadcn-compatible dark mode selectors) and an \Html\ generator that produces static HTML with inline absolute positioning, form widget mapping (inputs, selects, tabs, etc.), and CSS motion declarations (keyframes, transitions, and reduced-motion support). The crate establishes a \Codegen\ trait and scaffolds the architecture for future framework-specific targets (React, Vue, Svelte, Flutter, SwiftUI, Compose, React Native) while currently shipping the HTML and CSS-variable capabilities.

crates/op-codegen/src · high confidence

New Rust-based document loader and layout adapter

The \op-pen-loader\ crate now provides the canonical Rust implementation for loading \.op\ and \.pen\ documents into the desktop editor. It bridges the \jian-ops-schema\ \PenDocument\ into the editor's \DocPayload\ by delegating flex layout to \jian-core\'s \LayoutEngine\ (using a Skia-backed measure cache for accurate text sizing) and mapping all 12 node variants into \NodePayload\ structures with computed absolute coordinates. The loader supports both standard layout resolution and a 'preserve geometry' mode for Figma imports, and includes specific handling for active-page scene building, legacy component references, and canvas preview parity.

crates/op-pen-loader/src · high confidence

New account management widgets and sign-in flow

The editor now includes dedicated widgets for account management, including an avatar painter that overlays the user's profile image on initials, a press-flow handler for the sign-in modal and account dropdown, and a settings panel tab for signing in, signing out, and viewing account details. These components centralize the account UI logic and integrate with the existing settings and top-bar interfaces.

crates/op-editor-ui/src/widgets · high confidence

New build and release automation scripts for Android, macOS, Windows, and OpenHarmony

This change introduces a suite of new shell and PowerShell scripts in the \scripts/\ directory to standardize and secure the build, packaging, and installation processes across platforms. For Android, \android-version.sh\ derives a stable \versionCode\ from the Rust workspace SemVer, while \build-android-release.sh\ orchestrates the build using pinned SDK/NDK versions and verified Skia binaries. macOS packaging is handled by \bundle-macos.sh\, which generates the \.app\ bundle and correctly registers \.fig\ file associations via UTI declarations. Windows installation is automated via \install-op.ps1\, which resolves the latest release, verifies checksums, and installs the required Visual C++ runtime. A cross-platform \install-op.sh\ script provides similar CLI installation for macOS and Linux. Additionally, \build-ohos.sh\ and its associated toolchain wrappers enable cross-compilation for OpenHarmony, including necessary patches to the Skia build system.

scripts · high confidence

New build scripts for icon catalog generation and SDK version synchronization

Added \generate-iconify-catalog.mjs\ to extract and split icon data from Lucide, Feather, and Simple Icons into core and brand JSON catalogs for the editor UI, and introduced \sync-version.mjs\ to keep package versions consistent across root and SDK manifests, TypeScript entry points, and the Bun lockfile using TypeScript AST parsing and JSONC comment support.

packages/scripts · high confidence

New color system with WCAG contrast checking and design palettes

The \op-ai-skills\ crate now includes a new color module that provides a design style-resolution system. It introduces a palette engine supporting seven named themes (such as 'Alloy Blue' and 'Amber Field') in both light and dark modes, mapping semantic roles like \surface.primary\ and \accent.primary\ to specific colors. The system uses OKLCH color space for generating 12-step neutral and accent scales. Additionally, it adds WCAG-compliant contrast checking utilities, including a function to automatically determine appropriate foreground text colors for a given background and a scanner to flag color pairs that fail accessibility contrast targets.

crates/op-ai-skills/src/color · high confidence

New daemon-side collaboration service for the web canvas

The web canvas server now supports real-time collaboration through a new daemon-side service exposed via \/api/collab/\*\ routes. A dedicated background driver thread pumps the collaboration runtime, handling session state, presence updates, and UI actions without blocking the REST API. Clients can query the current projection state, enqueue UI actions (with conflict detection for concurrent requests), and publish local cursor presence. The implementation includes strict security gates for online deployments (refusing LAN-discovery actions from untrusted origins) and separates document versioning from projection sequencing to prevent unnecessary browser refetches on cursor movements.

_crates/op-host-services/src/web\_canvas\server · high confidence

New declarative Nix integration surface for OpenPencil

The Nix flake now exports a versioned integration contract (OpenPencil.pkl) and a generated Nix sidecar (openpencil.nix) that downstream flakes can consume to access OpenPencil's package outputs (runtime, web-server, skills), executables (desktop, CLI), and MCP transport configurations. The integration surface defines adapters for various AI harnesses (Claude, Codex, Gemini, etc.) and includes a Skillnet manifest for the design skill, providing a standardized way to integrate OpenPencil into Nix-based environments without duplicating configuration details.

nix · high confidence

New design-lint detectors for structural quality, GPU budget, and AI-generated patterns

The \op-design-lint\ Rust crate now includes a comprehensive suite of detectors that analyze design documents for structural issues, performance budgets, and common AI-generated artifacts. Users will see new warnings for empty filled panels, inconsistent sibling properties (height, corner radius, padding), and excessive nesting. The linter also enforces motion budgets (limiting animated nodes to 32 and durations to 1500ms) and shader costs (flagging invalid SkSL, excessive uniforms, or full-bleed shader passes that exceed platform-specific budgets). Additionally, it detects "AI slop" patterns like purple-glow gradients, generic three-card feature rows, and rounded-card walls, helping users identify and refine generic or low-quality design outputs.

crates/op-design-lint/src/detectors · high confidence

New diagnostic and benchmark examples for Figma import pipeline

Added a suite of command-line examples in \crates/op-figma/examples\ to support debugging, performance profiling, and validation of the Figma import pipeline. \bench\_memory\ and \bench\_prepared\ provide memory allocation tracking and stage-by-stage timing for binary \.fig\ imports. \probe\_fig\, \probe\_frame\, \probe\_icons\, \probe\_layout\, \probe\_vec\, and \probe\_vn\ serve as diagnostic tools to inspect raw Kiwi fields, node geometry, vector network blobs, and layout conversions. Additionally, \split\_op\_pages\ allows extracting individual pages from multi-page \.op\ documents.

crates/op-figma/examples · high confidence

New domain-specific design skill contracts for AI generation

The \crates/op-ai-skills/skills/domains\ directory now contains a comprehensive set of markdown-based skill contracts that define strict design rules for specific UI domains. These new files—\cards.md\, \cjk-typography.md\, \dashboard.md\, \deck-contract.md\, \deck-patterns.md\, \form-ui.md\, \landing-page.md\, \logo-contract.md\, \mobile-app.md\, and \slides.md\—provide the AI generation engine with detailed, domain-specific constraints. Key capabilities include enforcing CJK typography rules (language consistency, specific font families, line-height bands), defining dashboard density and data-table structures, establishing deck narrative arcs and page-type routing, and mandating a three-section architecture for mobile apps (status bar, app content, bottom navigation). These contracts ensure that generated designs adhere to professional standards for layout, typography, and component behavior within their respective domains.

crates/op-ai-skills/skills/domains · high confidence

New generation-phase skills enforce design quality, layout, and interactivity rules

The \crates/op-ai-skills/skills/phases/generation\ directory now contains a comprehensive set of markdown-based skills that guide the AI generation engine. These include \anti-slop\ to prevent generic aesthetics, \codegen-planning\, \codegen-chunk\, and \codegen-assembly\ to structure code generation, \design-system\ and \design-code\ for visual consistency, \layout\ and \mobile-ui\ for responsive and platform-specific layouts, \interactivity\ for state and event handling, \jian-components\ for native widget usage, and \kinetic-typography\ for text animations. These files define the rules and schemas the generation phase uses to produce higher-quality, more consistent, and interactive designs.

crates/op-ai-skills/skills/phases/generation · high confidence

New host-core modules for code generation, chat, and collaboration

The \op-editor-host-core\ crate now includes dedicated modules for code generation (\codegen\, \codegen\_session\, \codegen\_runtime\_state\, \codegen\_export\), chat (\chat\), and collaboration (\collab\). The codegen module introduces a background worker pipeline that builds input from the editor state, manages session lifecycles with cancellation and stale-session retirement, and produces downloadable artifacts (source files or ZIP bundles) with strict size limits. The chat module provides a shared worker and transcript folding logic, including a tool executor that forwards calls to the host UI thread. The collaboration module adds transport-neutral guest and owner editor sessions, handling document installation, local edits, and frame queuing with configurable limits.

crates/op-editor-host-core/src · high confidence

New op-editor-ui crate with accessibility, avatar, and SVG export capabilities

The editor UI has been extracted into a new \op-editor-ui\ crate, providing a platform-agnostic widget facade for both native and web hosts. This change introduces a complete accessibility tree assembler (\accessibility.rs\ and \accessibility\_regions.rs\) that maps editor regions to screen-reader nodes, ensuring the UI is navigable by VoiceOver, Narrator, and Orca. It also adds a runtime for fetching and caching authenticated collaboration avatars (\collab\_avatar\_runtime.rs\) with SSRF-safe handling and LRU eviction, and a new SVG export module (\svg\_export.rs\) that serializes the active page or selected nodes with canvas-parity, including support for gradients, image fills, and ancestor clipping.

crates/op-editor-ui/src · high confidence

New op-util crate consolidates shared utilities

The new \op-util\ crate introduces a set of dependency-free, cross-platform utilities that replace previously copy-pasted implementations across the codebase. It provides a canonical hex-color parser supporting \\#RGB\, \\#RGBA\, \\#RRGGBB\, and \\#RRGGBBAA\ formats with configurable strictness, and a lightweight image dimension reader that extracts intrinsic sizes from PNG, JPEG, GIF, WebP, and SVG headers without requiring a full pixel decoder. For CLI interactions, it adds a \BoundedTail\ mechanism that captures child-process output in a bounded, redacted manner to prevent credential leaks while preserving diagnostic evidence. Additionally, it standardizes JSON and XML escaping, defines a canonical grammar for collaboration document IDs, and establishes shared contracts for shader turbulence presets.

crates/op-util · high confidence

New release and security validation tooling for macOS, Android, and collaboration boundaries

The \tools/\ directory now includes a suite of new scripts that enforce structural and security contracts for release pipelines and collaboration infrastructure. \bundle-macos.sh\ assembles the desktop binary into a code-signed \OpenPencil.app\ bundle, ensuring the signing identity matches the TypeScript app to inherit macOS TCC folder-access grants. Structural validation for mobile releases is provided by \check-android-release-workflow.sh\ and \check-ios-app-store-workflow.sh\, which verify that the GitHub Actions workflows for Android and iOS adhere to strict security policies (e.g., secret scoping, environment requirements, and artifact provenance). Collaboration security is hardened by \check-collab-security-boundaries.sh\ and its associated test cases, which enforce deployment boundaries, credential ownership assertions, and relay URL canonicalization via \check-collab-bootstrap-urls.py\. Additionally, \check-file-line-cap.sh\ enforces the 800-line-per-file convention to maintain codebase discipline.

tools · high confidence

New shared process I/O primitives for spawning and managing child processes

The \op-process-io\ crate introduces a new library of shared primitives for managing external processes. It provides \LineStreamChild\ for asynchronous spawning with piped stdin/stdout/stderr, allowing users to feed input, read output line-by-line, and manage process lifecycles. The library also includes \ProcessTree\ utilities to safely terminate entire process groups on Unix (using process groups) or descendant trees on Windows, ensuring that child processes and their descendants are properly cleaned up. Additionally, it offers blocking helpers like \wait\_for\_child\_or\ for polling readiness signals while monitoring process exit status, and \spawn\_null\ for launching detached daemon-like processes with null stdio.

crates/op-process-io · high confidence

New web shell host page and missing-bundle error page

The \op-host-services\ daemon now serves a dedicated \index.html\ for the OpenPencil web shell, which initializes the WASM canvas, handles device-pixel-ratio scaling, and logs smoke-test markers to the console for headless verification. Additionally, a \missing\_bundle.html\ page is served when the required WASM bundle files are not found, providing clear instructions on how to rebuild the bundle or configure the \OPENPENCIL\_WEB\_BUNDLE\_DIR\ environment variable.

_crates/op-host-services/src/web\static · high confidence

OpenHarmony NAPI engine bindings for mobile editing

This change introduces the \op-engine-napi\ crate, providing the Node-API (NAPI) bindings that allow the OpenHarmony (OHOS) ArkTS shell to load \libopenpencil.so\ and communicate with the OpenPencil engine. It exposes the full editor API surface—including lifecycle management, canvas gestures, text editing, IME, and document save/export workflows—mapped to OHOS-specific input mechanisms like mouse wheel zoom, hardware key modifiers, and system pasteboard integration. The bindings reuse the engine-thread marshalling and handle registry from the Android JNI crate to ensure consistent teardown ordering, while target-gating the OHOS-specific code so the crate compiles as an inert stub on non-HarmonyOS platforms.

crates/op-engine-napi · high confidence

Ported Rust design-lint crate for automated design diagnostics and fixes

The \op-design-lint\ crate introduces a Rust-based implementation of the design diagnostics layer, ported from the TypeScript \pen-ai-skills\ package. It provides pure, editor-agnostic detectors that analyze the \PenDocument\ tree for issues such as missing progress rings, WCAG color contrast violations, empty panels, and structural inconsistencies. The crate includes a \fixes\ module that automatically applies safe corrections (like clearing effects or adjusting padding) and a \design\_form\ classifier that identifies root surfaces as mobile, page, deck, or card based on artboard dimensions. This enables the editor to run pre-validation repairs and report structural quality before rendering.

crates/op-design-lint/src · high confidence

Preview session now supports multi-screen App Mode with automatic navigation wiring

The preview environment now detects documents containing multiple screen-marked frames and automatically enters a routed multi-screen 'App Mode'. If a document lacks explicit screen markers, the preview engine automatically wires up the navigation paths at entry time, allowing seamless switching between screens via a pill-based switcher and standard back-navigation gestures. This change ensures that hand-drawn or imported multi-screen designs behave like generated apps in preview, while preserving any manually authored navigation bindings.

crates/op-preview-core · high confidence

Production deployment scaffolding for overseas-to-CN collaboration relay and locator ingress

This change introduces the \deploy/collab-relay-edge\ and \deploy/collab-relay-locator-edge\ directories, providing the complete production deployment configuration for connecting overseas users to China-anchored collaboration relays and locator services. It includes Nginx stream proxy configurations that perform nested TLS wrapping (outer mTLS over inner client TLS) to ensure the Global edge never terminates or inspects user traffic. The deployment uses Docker Compose with strict security constraints (read-only filesystems, non-root users, dropped capabilities) and pinned image digests. It also provides shell scripts for installing host-level nftables rate-limiting rules for new connections, validation scripts to enforce configuration integrity, and helper scripts for rotating Certificate Revocation Lists (CRLs) for the outer mTLS backhaul.

deploy · high confidence

Project initialization and repository scaffolding

The repository has been initialized with the foundational structure for the OpenPencil project. This includes the addition of standard configuration files such as \.dockerignore\, \.editorconfig\, \.gitattributes\, and \.gitmodules\ to manage submodules and formatting. The project is now licensed under the MIT License, and the \AGENTS.md\ file provides guidance for AI coding assistants. Additionally, localized README files (German, Spanish, French, Hindi, Indonesian) have been added to support international users, and a Dockerfile for the Rust web host has been introduced to containerize the application.

(repo-wide) · high confidence

Structured three-way merge for OpenPencil documents

The new \op-opmerge\ crate introduces a structural, node-level three-way merge engine for \.op\ documents, replacing fragile textual JSON merging. It automatically merges independent property changes (such as moving or recoloring distinct nodes) while surfacing genuine divergences—like conflicting edits to the same node, structural reorders, or reparenting—as \NodeConflict\ objects for the editor to resolve. This ensures that collaborative edits are preserved without silent data loss or broken JSON structures.

crates/op-opmerge · high confidence

Style guide system now supports user imports and provides detailed hover cards

Users can now import custom style guides via the \DESIGN.md\ convention, with the system leniently parsing names, tags, platforms, and color swatches from varied file formats. The style guide interface has been expanded to include a detailed hover card that displays the guide's name, source (user vs. corpus), color palette, fonts, and description, helping users verify which style is active. Additionally, the system now extracts and exposes 'Key aesthetics' and 'Signature recipes' from guides, allowing subagents to access richer stylistic context beyond basic colors and fonts.

_crates/op-ai-skills/src/style\guide · high confidence

Vendor Anthropic Agent SDK for Rust

The \vendor/anthropic-agent-sdk\ directory has been added as the source-of-truth for the Rust SDK, bringing in version 0.2.75. This update introduces OAuth 2.0 authentication with PKCE support for Claude Max/Pro subscribers, allowing browser-based login without API keys. It also adds experimental file checkpointing and rewind capabilities, new hook input types for session management, and a comprehensive TUI demo with interactive features. The SDK maintains full parity with the TypeScript version, including support for MCP servers, permission callbacks, and secure subprocess communication.

vendor/anthropic-agent-sdk · high confidence

iOS packaging scaffolding and native sign-in assets

The iOS packaging directory now includes the foundational project structure and assets for the mobile shell, including the Info.plist with URL schemes for WeChat, Alipay, and Douyin, entitlements for Apple Sign-In and universal links, and asset catalogs for provider icons. It also introduces the native sign-in implementation files (such as AlipayNativeSignIn and AccountCenterViewController) and localized strings for the login, registration, and account management flows, enabling platform-native authentication and account management on iOS.

packaging/ios · high confidence

Removals

Removed initial editor UI components

Deleted the initial set of React components that formed the application's user interface, including the Header, EditorLayout, Toolbar, and LayerPanel, as well as the PropertyPanel and its sub-sections (Size, Fill, Stroke, Appearance, CornerRadius, Text) and shared UI primitives (ColorPicker, NumberInput, SliderInput, DropdownSelect, IconButton).

src/components · high confidence

Architecture

Canvas engine refactored into modular React hooks

The monolithic Fabric.js canvas implementation in src/canvas has been decomposed into a set of specialized, reusable React hooks to improve maintainability and separation of concerns. The previous single-file FabricCanvas component and associated constants have been replaced by dedicated hooks: use-fabric-canvas for initialization and resizing, use-canvas-events for pointer interactions and tool handling, use-canvas-selection for managing object selection state, use-canvas-viewport for zoom and pan logic, and use-canvas-sync for keeping the Fabric canvas in sync with the document store. Supporting utilities like canvas-object-factory and canvas-object-sync have also been modularized. This change restructures how the canvas engine is wired together without altering the underlying rendering capabilities.

src/canvas · high confidence

Extract collaboration runtime into dedicated op-collab-host crate

The collaboration runtime logic has been extracted into the new \op-collab-host\ crate, separating it from the desktop application code. This new crate provides a host-agnostic runtime that manages owner and guest actors, admission queues, relay control planes, and ticket verification. It introduces a \BlockingExecutor\ trait to bridge asynchronous network operations (like JWKS fetching) to synchronous host loops, and a \CollabHost\ trait to abstract editor state mutations and ID allocation policies, allowing the same runtime to drive both GUI hosts and headless test/daemon environments.

crates/op-collab-host/src · high confidence

Extracted op-ai crate for transport-free AI chat and agent settings

The \op-ai\ crate has been extracted from \openpencil-shell-core\ to centralize transport-free data shapes and logic for the editor's AI chat and agent integration. This new module provides the core types and behaviors for the multi-section settings modal (including agent providers like Claude Code, Copilot, and DeepSeek Harness, and MCP CLI toggles), a sliding-window chat history trimmer that preserves context continuity, and a model catalog structure. It also includes transport-agnostic SSE payload parsers for Anthropic and OpenAI-compatible providers, stateful tool-call accumulators for agent loops, and shared helpers for generating and cleaning design.md system prompts. By isolating these components, the crate ensures that the native desktop and web shells share identical AI logic without pulling in platform-specific dependencies like Tokio or reqwest.

crates/op-ai · high confidence

Refactor chat intent module into focused sub-modules

The \chat\_intent\ module has been split into separate files (\context.rs\ and \turns.rs\) to improve maintainability and keep the main module under the 800-line limit. This refactoring preserves all existing functionality, including append intent detection, design modification planning, and turn routing logic, while organizing the code into logical components for better readability and future development.

_crates/op-host-services/src/chat\intent · high confidence

Behavioural changes

5 commits (0 fixes) modifying crates/op-host-desktop/assets

A change to existing behaviour in crates/op-host-desktop/assets — 5 commits, 3 files.

crates/op-host-desktop/assets · medium confidence · unverified

Build system now detects changes to built-in agent skill files

A new build script has been added to ensure that modifications to the built-in agent's skill definitions (located in the \skills/\ directory) trigger a rebuild of the crate. Previously, adding or editing a skill markdown file would not cause the binary to rebuild, potentially leading to the application serving a stale corpus of skills until a manual rebuild was performed.

crates/op-ai-skills · high confidence

Enforce pre-commit checks for version consistency and Rust code quality

A new pre-commit hook has been added to automatically verify version consistency and enforce Rust code standards before changes are committed. The hook runs a version synchronization check and ensures that Rust code is properly formatted and free of clippy warnings, preventing non-compliant code from entering the repository.

.githooks · high confidence

Fixes for weak-model layout artifacts and parallel agent visibility

The orchestrator now automatically repairs common layout mistakes generated by weak models: it detects and restructures flat vertical dashboards with full-width sidebars into proper horizontal app-shells (sidebar + content column), and fixes already-split shells that stack columns instead of placing them side-by-side. It also removes duplicate, abandoned artboard roots that models sometimes leave behind, and introduces distinct visual identities (colors and names) for parallel design sub-agents to improve canvas clarity.

crates/op-orchestrator/src · high confidence

Git version control engine migrated from subprocess to in-process libgit2

The \op-git\ crate now implements all Git operations (branching, merging, history, remotes, status, and credential management) using the in-process \libgit2\ library instead of spawning the system \git\ executable. This change eliminates the dependency on a system \git\ binary, resolving sandboxing issues on macOS and ensuring version control works on machines without \git\ installed. The public API surface and error handling remain compatible with the previous implementation, but the underlying execution model is now fully self-contained within the application binary.

crates/op-git · high confidence

Improved reliability and context management for AI design generation

The agent loop now enforces a strict HTTP retry and adaptive throttle policy (up to 5 retries with exponential backoff) to prevent design runs from failing on transient provider rate limits. To keep context windows manageable, screenshots are automatically downscaled or elided based on the model's output token budget, and older screenshots are replaced with text markers to prevent quadratically growing payloads. Additionally, the loop now includes dedicated corrective rounds for structural blockers and unfilled screens, ensuring that critical design issues are addressed before finalization rather than silently completing with errors.

crates/op-chat-agent · high confidence

Introduce Ed25519-based collaboration authentication with minimized relay tokens

The collaboration authentication system now uses strict Ed25519 JWS credentials instead of the legacy polymorphic EdDSA identifier. This change introduces a new, minimized relay bearer token that contains only the session expiry and channel-binding data, deliberately excluding account subjects, device IDs, and profile information to prevent third-party relays from reconstructing the social graph. The system also implements a bounded, rotation-aware JWKS cache that supports both legacy JWKS endpoints and new offline-signed union policies, ensuring that key verification remains secure and resource-bounded during trust-root rotations.

crates/op-auth-bridge/src · high confidence

Introduce signed, hardened op-auth ABI v3 prebuilt matrix

The \crates/op-auth-bridge/prebuilt\ directory now contains a complete, signed release matrix for op-auth version 0.8.5 across ten targets (macOS, iOS, Android, Linux, and Windows on x86\_64 and ARM64). These prebuilt libraries are hardened (stripped, fat LTO) and bound to ABI v3, with provenance signed by a new Ed25519 trust root (\PROVENANCE\_PUBKEY\). This enables the application to accept and verify these signed artifacts, ensuring that the private authentication components are immutable and auditable without requiring a local rebuild for every source change.

crates/op-auth-bridge/prebuilt · high confidence

Live MCP endpoint now enforces strict browser-screening admission control

The local live MCP endpoint now rejects requests from foreign hosts or origins to prevent DNS rebinding attacks, while removing the previous per-instance token requirement for local clients. This change introduces an admission gate that validates the \Host\ and \Origin\ headers, allowing only loopback addresses and the instance's own origin, with specific exceptions for browser extensions and stateless probes. Existing local tools like the CLI and VS Code proxy continue to work without the token, as trust is now established through boundary checks rather than shared secrets.

_crates/op-host-services/src/mcp\live · high confidence

OpenPencil VS Code extension restructured into workspace package with unified editor and daemon lifecycle

The OpenPencil VS Code extension has been moved into the \packages/op-vscode\ workspace directory and restructured to manage a unified custom editor provider that adapts to workspace trust. In untrusted workspaces, the extension displays a restricted placeholder; upon granting trust, it asynchronously assembles the full stack—including the platform daemon, MCP proxy, and session registry—and reopens the editor tabs. The extension now ships with a bundled platform daemon and web assets, resolving the binary from the vsix when available, and supports opening \.fig\ files by converting them via the daemon endpoint. A smoke test has also been added to verify the toolchain.

packages/op-vscode/src · high confidence

Removal of legacy TanStack Router setup and global styles

The application has removed the previous TanStack Router configuration files (\src/router.tsx\ and \src/routeTree.gen.ts\) along with the global stylesheet (\src/styles.css\). This eliminates the manually defined route tree and Tailwind-based base styles, indicating a migration to a new routing or styling architecture that no longer relies on these specific legacy setup files.

src · high confidence

Removal of legacy canvas and document stores

The legacy \canvas-store.ts\ and \document-store.ts\ files have been deleted from the \src/stores\ directory. This removes the previous Zustand-based state management implementations for canvas interactions (tools, viewport, selection) and document tree operations (node insertion, removal, and movement), indicating a shift to a new store architecture or state management approach.

src/stores · high confidence

Removal of legacy route definitions

The root layout, editor, and landing page route files have been deleted from the application. This removes the previous implementation of the main shell component, the editor interface, and the home page, indicating a structural change to how the application's navigation and core views are defined.

src/routes · high confidence

Removal of legacy type definitions for canvas, nodes, styles, and variables

The type definitions located in src/types (canvas.ts, pen.ts, styles.ts, and variables.ts) have been deleted. This removes the previous schema for document nodes (such as FrameNode, TextNode, and RefNode), styling properties (including fills, strokes, and effects), and canvas interaction states. Users relying on these specific type exports for external tooling or custom integrations will need to update their code to align with the new type structure introduced in the current version.

src/types · high confidence

Removal of local keyboard shortcut handling hook

The \useKeyboardShortcuts\ hook in \src/hooks\ has been removed, eliminating the local implementation that mapped keys (such as V, F, R, O, L, T, P, H for tools, Escape, Delete, Cmd+A, brackets, and arrows) to canvas actions like tool switching, selection, deletion, and nudge. Users relying on these specific keyboard bindings will no longer have them processed by this hook; the functionality has likely been migrated or replaced elsewhere in the application.

src/hooks · high confidence

Revived A/B testing corpus with v3 prompts for new tools and composite layouts

The A/B testing corpus has been restored to the \scripts/ab-v9\ location and upgraded to version 3. This update preserves the original 40 prompts from v1 to ensure result comparability, while adding 7 new prompts that cover recently introduced element tools (such as \setting\_row\, \filter\_group\, and \activity\_log\) and 5 new 'composite' difficulty prompts designed to evaluate the model's ability to handle multi-component layouts where no single tool applies.

scripts/ab-v9 · high confidence

Safer document saves and collapsed layer panels on open

The document I/O layer now uses atomic file writes (creating sibling temporary files and replacing the destination) to prevent data loss during crashes or overlapping saves, with a dedicated Windows serialization path to avoid file-replacement races. When opening a document, top-level frames are now collapsed in the Layer Panel by default, making large decks easier to navigate. The system also introduces a typed error model for document I/O and a compatibility report that tracks legacy schema repairs, sidecar usage, and metadata inference.

_crates/op-host-services/src/doc\io · high confidence

Fixes

Build-time validation of collaboration hub URLs

The collaboration host crate now validates the \OPENPENCIL\_BUILD\_COLLAB\_BOOTSTRAP\_URL\_CN\ and \OPENPENCIL\_BUILD\_COLLAB\_BOOTSTRAP\_URL\_GLOBAL\ environment variables at build time. If a release pipeline injects a malformed hub URL—such as one with surrounding whitespace, a non-HTTPS scheme, or an incorrect path—the build will fail immediately. This prevents shipped binaries from silently failing to connect to the collaboration relay due to configuration errors.

crates/op-collab-host/src/runtime · high confidence

Fixes export race conditions and adds mobile WebP support gating

The export system now serializes concurrent image decodes to prevent a race where a background decode pump steals image IDs, which previously caused exports to ship placeholder art instead of the actual bitmap. It also introduces a new \UnsupportedFormat\ error to explicitly block WebP exports on iOS and Android builds where the Skia encoder is omitted, rather than failing silently or with a generic error. Additionally, the export logic has been reorganized into the new \op-render-export\ crate, consolidating raster, SVG, and PDF rendering paths.

crates/op-render-export · high confidence

Test coverage

Added TypeScript bridge protocol codec and tests for VS Code extension communication; Added end-to-end smoke tests for the managed web server daemon; Added golden regression tests for op-design-lint Rust implementation; Added integration and unit tests for the collaboration transport layer; Added integration tests for the daemon client and MCP proxy; Added regression tests for fixed-size flex layout behavior; Added test coverage for authentication bridge components; Added test fixtures for HTML import and snapshot fidelity; Added test for pre-validation of full-bleed hero padding; Added tests for Rust planner prompt parity with TypeScript golden files; Added tests for chat agent identity, streaming stop behavior, and instance history states; Added tests for chat, codegen, and design session logic; Added unit tests for AI chat model picker, layer panel gutter, and widget rendering; Android packaging structure and contract tests introduced; New FFI integration tests for engine ABI, editor, and mobile safe-area contracts.

Dependencies

Rust workspace bootstrap and dependency lockfile generation

The project has been bootstrapped as a Rust workspace, introducing a \Cargo.lock\ file and a root \Cargo.toml\ that defines the workspace structure, default members, and release profile optimizations (thin LTO, codegen-units=1, symbol stripping). This change establishes the foundational dependency graph for the Rust-based editor, hosts, and CLI tools, replacing the previous TypeScript/Electron build system.

(dependencies) · high confidence

Vendor submodules initialized for agent, casement, and jian

The repository now tracks three new vendored submodules: \vendor/agent\ (commit 1bff904), \vendor/casement\ (commit ffdd672), and \vendor/jian\ (commit 338c0ba). These additions establish the baseline versions for the agent runtime, the winit-based windowing layer (casement), and the core UI/rendering framework (jian) used by the editor and renderer.

vendor · high confidence

Vendored CanvasKit artifacts for the web host

The web host now includes vendored CanvasKit assets (canvaskit.js and canvaskit.wasm, version 0.40.0) to enable rendering without relying on external node\_modules or embedded Skia runtimes. These files are served at the /canvaskit/ prefix and initialized via the op\_ck\_bridge.js FFI, ensuring the Rust web shell can render independently of the TypeScript application environment.

crates/op-host-web · high confidence

Housekeeping

Empty placeholder files created

The diff shows the creation of three new empty files (3210/done, 3211/done, 3212/done). These files contain no code or logic, so this change has no functional impact on the product.

3210, 3211, 3212 · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 57 → 57 (+0.1)
  • Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 59 → 59 (-0.4)
  • Architecture 99 → 95 (-3.9)
  • Maturity 62 → 68 (+5.8)
  • Readiness 64 → 62 (-2.1)
  • Security 69 → 72 (+2.9)
  • Domain Modelling 100 → 100 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)
  • Accessibility 48 → 48 (+0.0)
  • Performance 85 (new)

Resolved (243)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Duplicated block (10 lines × 2) (crates/op-host-desktop/src/image_enrich_cli/retry.rs)
  • Duplicated block (10 lines × 2) (crates/op-image-enrich/src/net/fetch.rs)
  • Duplicated block (10 lines × 2) (crates/op-preview-core/src/present.rs)
  • Duplicated block (11 lines × 2) (crates/op-codegen/src/codegen_targets.rs)
  • Duplicated block (13 lines × 2) (crates/op-host-native/src/widget_host/slides_panel.rs)
  • Duplicated block (15 lines × 2) (crates/op-engine-ffi/src/lifecycle.rs)
  • Duplicated block (16 lines × 2) (crates/op-html/src/special_image.rs)
  • Duplicated block (17 lines × 2) (crates/op-orchestrator/src/concurrent.rs)
  • Duplicated block (20–22 lines × 2) (crates/op-host-services/src/import_html_url.rs)
  • Duplicated block (6 lines × 2) (crates/op-host-services/src/web_canvas_server/tenant.rs)
  • Duplicated block (6–7 lines × 2) (crates/op-host-web/src/iconify_web.rs)
  • Duplicated block (7 lines × 2) (crates/op-codegen/src/codegen_targets.rs)
  • Duplicated block (7 lines × 2) (crates/op-codegen/src/codegen_targets.rs)
  • Duplicated block (7 lines × 2) (crates/op-codegen/src/codegen_targets.rs)
  • Duplicated block (8–9 lines × 2) (crates/op-host-services/src/chat_provider_llm.rs)
  • Duplicated block (9 lines × 2) (crates/op-host-desktop/src/image_enrich_cli/retry.rs)
  • Duplicated block (9 lines × 2) (crates/op-orchestrator/src/stub_repair.rs)
  • Duplicated block (9 lines × 6) (crates/op-orchestrator/src/geometry_bottom_gap.rs)
  • …and 223 more

New (420)

  • Ambiguous semantic overlap between 'close' and 'delete'. In many session-based APIs, 'close' terminates the active session but may keep state, while 'delete' removes it entirely. However, the naming close_session_if_supported and delete_session_if_supported suggests these are capability-gated operations. If the underlying protocol treats them as distinct lifecycle stages, the names are okay, but if they are often used interchangeably or one implies the other, this is confusing. Given the presence of supports_session_close and supports_session_delete, they are likely distinct, but the API surface feels cluttered with capability checks that could be handled internally or via a single terminate_session method.
  • BindingOverlay::consume_scroll_requests (cognitive 16) (crates/op-preview-core/src/binding_overlay.rs)
  • Duplicate intent across different types. Both OpenAiToolCollector and AnthropicToolCollector have a handle method that takes a string and returns a ChatDelta. This suggests a common trait or interface should be defined for tool collectors to abstract away the provider-specific parsing logic.
  • Duplicated block (10 lines × 2) (crates/op-chat-agent/src/design_agent_tools/root_seed.rs)
  • Duplicated block (10 lines × 2) (crates/op-editor-core/src/icon_path_normalize.rs)
  • Duplicated block (10 lines × 2) (crates/op-host-services/src/web_image_generate.rs)
  • Duplicated block (10 lines × 2) (crates/op-orchestrator/src/card_inner_padding.rs)
  • Duplicated block (10 lines × 2) (crates/op-orchestrator/src/concurrent.rs)
  • Duplicated block (10 lines × 2) (crates/op-preview-contracts/src/effect.rs)
  • Duplicated block (10 lines × 2) (packaging/ios/Sources/AuthCodeFormViewController.swift)
  • Duplicated block (10 lines × 2) (templates/step0/_generators/tpl1.py)
  • Duplicated block (10 lines × 2) (templates/step0/_generators/tpl_gradient_tech.py)
  • Duplicated block (10 lines × 3) (templates/step0/_generators/tpl2.py)
  • Duplicated block (10 lines × 5) (crates/op-orchestrator/src/absolute_child_clamp.rs)
  • Duplicated block (10 lines × 5) (templates/step0/_generators/tpl_journal_card.py)
  • Duplicated block (10–13 lines × 2) (templates/step0/_generators/tpl_toolkit_carousel.py)
  • Duplicated block (11 lines × 2) (crates/op-editor-ui/src/widgets/home_surface_copy.rs)
  • Duplicated block (11 lines × 2) (crates/op-editor-ui/src/widgets/home_surface_paint_art_screens.rs)
  • Duplicated block (11 lines × 2) (crates/op-host-native/src/widget_host/mode_transition_host.rs)
  • Duplicated block (11 lines × 2) (crates/op-orchestrator/src/card_inner_padding.rs)
  • …and 400 more

Changes since last survey

  • 26 commits — 14 feature/other, 12 fixes

By area

  • crates/op-editor-ui — 8 commits
  • crates/op-editor-host-core — 3 commits
  • crates/op-host-services — 3 commits
  • (root) — 2 commits
  • crates/op-ai-skills — 1 commit
  • crates/op-chat-agent — 1 commit
  • crates/op-cli — 1 commit
  • crates/op-design-lint — 1 commit
  • crates/op-git — 1 commit
  • crates/op-host-native — 1 commit
  • crates/op-html — 1 commit
  • crates/op-i18n — 1 commit
  • crates/op-smoke — 1 commit
  • screenshot/fluxion-ai-sponsor-banner.png — 1 commit

Notable commits

  • fix: fix(agent): keep the natively-cased Windows vars for guarded CLIs (#233)
  • fix: fix(agent): match the Codex env allowlist case-insensitively (#232)
  • fix: fix(agent): route every Studio task family to the design pipeline
  • fix: fix(ai): keep the radius context cut on a char boundary (#241)
  • fix: fix(ai): ride out provider 429s in the headless smoke client
  • fix: fix(cli): decode a percent-encoded resource name before the disk lookup (#242)
  • fix: fix(desktop): never overwrite a settings file the startup load rejected
  • fix: fix(desktop): persist the chosen chat model row, not just the provider
  • fix: fix(editor): address restored blobs with git's path separator (#235)
  • fix: fix(editor): make Home's avatar and model picker actually usable
  • fix: fix(html): stop a non-ascii css prelude from panicking the import (#240)
  • fix: fix(i18n): carry the catalog size into the exporter, and split the settings tests
  • change: docs(readme): add Fluxion AI sponsor block alongside Infistar in all locales
  • change: docs(readme): arrange sponsor ads in two columns
  • change: docs(readme): update Fluxion AI sponsor banner
  • change: feat(ai): add Atlas Cloud image provider (#227)
  • change: feat(editor): Studio entry surface — task home, generation workspace, Agent rail
  • change: feat(editor): home entrance choreography and result-view short-viewport fit
  • change: feat(editor): home model chip, connect card, persisted agent and orchestrator route
  • change: feat(editor): home surface — match the prototype's composition and finish
  • …and 6 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

ZSeven-W/openpencil was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 3e55570d20bd4be891700789146e7c43c9c1c3b1 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5ff527f25b99.