CopilotAtelier.psd1

@{
    RootModule        = 'CopilotAtelier.psm1'

    # Replaced at build time by GitVersion.
    ModuleVersion     = '6.1.0'

    GUID              = '67bbef0b-f4de-4c1b-bb5a-b34104beb5b7'

    Author            = 'raandree'

    CompanyName       = 'raandree'

    Copyright         = '(c) raandree. All rights reserved.'

    Description       = 'Portable GitHub Copilot customization library. Ships custom agents, auto-applied instructions, on-demand skills, prompt templates, and lifecycle hooks, and installs them into the well-known ~/.copilot discovery folders that VS Code, the GitHub Copilot CLI, and Claude Code read.'

    PowerShellVersion = '5.1'

    FunctionsToExport = @('Get-CopilotAtelierClientAdapter','Get-CopilotAtelierFootprint','Get-CopilotAtelierProfile','Get-CopilotAtelierSkillHealth','Get-CopilotAtelierVersion','Install-CopilotAtelier','Test-CopilotAtelier','Uninstall-CopilotAtelier','Update-CopilotAtelier')

    CmdletsToExport   = @()

    VariablesToExport = @()

    AliasesToExport   = @()

    PrivateData       = @{
        PSData = @{
            Tags         = @(
                'Copilot'
                'GitHubCopilot'
                'VSCode'
                'Agents'
                'Skills'
                'Prompts'
                'Instructions'
                'Hooks'
                'AI'
                'Windows'
                'Linux'
                'MacOS'
            )

            LicenseUri   = 'https://github.com/raandree/CopilotAtelier/blob/main/LICENSE'

            ProjectUri   = 'https://github.com/raandree/CopilotAtelier'

            IconUri      = 'https://raw.githubusercontent.com/raandree/CopilotAtelier/main/assets/CA-glyph-on-light.png'

            Prerelease   = 'preview0003'

            ReleaseNotes = '## [6.1.0-preview0003] - 2026-10-05

### Added

- Add contributor calibration: every agent pitches answers and questions at your familiarity with each knowledge area (`new`, `familiar`, or `expert`; `familiar` until you say otherwise), and in `new` and `familiar` areas illustrates an abstract finding with a concrete example; every calculated or reconstructed result names its sources and method. Every technical question offers a recommended answer and a `not sure, you pick` option; a delegated answer becomes an assumption flagged for expert review, counts only when you write it yourself, and never authorizes an irreversible, destructive, or security-relevant action; a question that authorizes such an action comes without the option. A level changes wording and depth, never warnings, tests, or reviews, and is never written to a repository. See [How Much Explanation You Want](README.md#how-much-explanation-you-want).
- Add [`docs/SECURITY-REVIEW.md`](docs/SECURITY-REVIEW.md), the independent security review of contributor calibration with every finding, its severity, and its resolution.
- Add the `/simpler` and `/deeper` Prompts, which re-explain the last answer one familiarity level simpler or deeper and keep that level for its knowledge area for the rest of the session.

### Changed

- Let `grill-me`, `software-architect`, and `gilb-requirements-engineering` accept `not sure, you pick`: the recommended answer, or for a numeric target a level derived from `Past`, `Record`, or a verified benchmark, is recorded as an assumption flagged for expert review instead of blocking the interview.
- Document in `agent-evals` that the Copilot backend''s content filter blocks some harmless eval prompts, why an embedded chat transcript makes it worse, and how to keep a comparison fair: situation as system context, `FinishReason` logged per call, retries, and arms compared only on cases complete in both. See [harness prerequisites](skills/agent-evals/SKILL.md#harness-prerequisites).
- Document in `agent-evals` that compared arms must run at the same time, because backend behavior drifts within hours, and that an LLM judge''s disagreement can expose a mislabelled reply, which justifies a label correction only for an objective error. See [micro-tests](skills/agent-evals/SKILL.md#micro-test-the-wording-first).

### Fixed

- Deliver the SessionStart context to Copilot SDK (agent host) and Copilot CLI sessions. `Add-SessionContext` wrote it only under `hookSpecificOutput`, which those hosts ignore; it now also writes the top-level `additionalContext` they read.
- Keep the session clock when a Copilot SDK chat resumes. The runtime reruns the `SessionStart` hook with `source: resume` when it reloads a chat, and `Add-SessionContext` restarted the clock there, so the closing elapsed line and the turn count started over and the injected start time moved; it now keeps a readable clock of the same session.
- Keep the `long-running-job-monitor` heartbeat state readable while it is rewritten. `Start-JobHeartbeat.ps1` wrote the state file in place, so `-Stop`, `-TouchStatus`, or a wake read at the same moment could find it empty or cut off and fail; it now renames a complete file over it, also on Windows PowerShell 5.1.
- Stop the wording of a commit message from choosing the release version. `GitVersion.yml` raised it on words such as "major", "breaking", or "add" anywhere in a message, which is how review text made 6.0.0 a major release; now only the Conventional Commit type in the subject line (`feat:`, `fix:`, `perf:`, `!`), a line that starts with `BREAKING CHANGE:`, or a literal `+semver:` override raises it above the branch''s default increment.
- Send an authorized push to the user''s own terminal. The `PreToolUse` block message, `AGENTS.md`, and the hooks README told the agent to set `COPILOT_ATELIER_ALLOW_REMOTE=1` for the command, but each host starts the hook with its own environment, so a variable set in an agent terminal never reaches the guard. They now also warn never to persist the variable, for example with `setx`: every host started afterwards would run without the guard.
- Show the `PreToolUse` guard''s reason to the model in Copilot SDK chats on Windows. That host ran the cross-platform `command` launcher inside an outer PowerShell that reported the block as 1, so the model saw only "hook errored". A new `powershell` launcher, which the SDK host prefers on Windows, passes exit 2 on, and the guard prints the reason as one JSON object on standard output, which that host merges into the deny on exit 2. The object now carries only the top-level `permissionDecision` and `permissionDecisionReason`: the SDK runtime in VS Code 1.140.0 drops a `PreToolUse` object that also carries `hookSpecificOutput`, so the model read only "hook exited with code 2". VS Code still reads the reason from standard error.

### Security

- Block a push in VS Code Local chats on Windows. VS Code runs a hook''s `windows` launcher as the `-Command` text of an outer Windows PowerShell, which reported the guard''s exit code 2 as 1, and VS Code treats every exit other than 2 as a warning, so the `PreToolUse` guard only warned there. The launcher now ends with a statement that passes the inner exit code on. Found by the post-release review of the v6.0.0 hook launcher fix.
- Look for the hook scripts under `USERPROFILE` before `HOME`. Since v6.0.0 the launchers tried `HOME` first, so a `HOME` that a tool such as Git for Windows pointed at a writable tree could run a planted script instead of the deployed guard, and a `HOME` on an unreachable network share delayed the guard past its 20-second timeout, which the Copilot SDK host treats as allow.
- Scan the raw payload text whenever the `PreToolUse` guard cannot walk the payload field by field. A payload that was not valid JSON has been allowed since v6.0.0, and the walk stopped four levels deep, so a push nested more than four levels, or more than the 100 levels Windows PowerShell parses (1,024 in PowerShell 7), went through. The walk now reaches 64 levels, and whatever it cannot reach is scanned as raw text, with JSON escapes decoded and without JSON punctuation, so an argument array such as `["git","push"]` is caught as well, before the call is allowed. The raw text scan also joins the command-bearing fields the way the walk does, so a command split across fields, such as `{"command":"git","args":["push"]}`, is caught there too.
- Block a push whose arguments come before the command, such as `{"args":["push"],"command":"git"}`, the order a serializer that sorts its keys writes. Since v6.0.0 the `PreToolUse` guard joined the command-bearing fields only in the order they appear, which read `push git`; it now also joins each object''s executable fields before its argument fields, and for a payload it cannot walk, the whole payload''s fields in that order and in reverse.
- Block a tool call the `PreToolUse` guard cannot inspect within five seconds. Some of its patterns slow down quadratically on one long line of `git` words: 64 KB of them took 21.5 seconds, past the 20-second hook timeout, which the Copilot SDK host treats as allow. Parsing and walking a payload cannot be interrupted either, and 300,000 small objects kept the guard busy past the timeout too. The whole decision now has a time limit: a payload is parsed only up to 1 MB and walked only up to 20,000 fields and nested objects, the rest is scanned as raw text, a payload over 4 MB is blocked unscanned, and a payload not inspected within the limit is blocked. Ordinary commands still take well under a second.

'

        }
    }
}