DeskPilot.psd1

@{
    RootModule        = 'DeskPilot.psm1'
    ModuleVersion     = '0.5.0'
    GUID              = 'b8f3a2d1-7c4e-4a9b-9f1d-2e6c5a0b3d77'
    Author            = 'Raimund Andree'
    CompanyName       = 'Raimund Andree'
    Copyright         = '(c) Raimund Andree. MIT licensed.'
    Description       = 'DeskPilot is a local, desktop-style web UI that fronts the ShellPilot engine to give non-technical users the full GitHub Copilot agent toolset (browse, read/write files, run commands, skills, instructions) with visible permissions and honest cost - no terminal or IDE required. The web UI is bundled in the module and served on loopback; ShellPilot and a Copilot-enabled GitHub account are required.'
    PowerShellVersion = '7.0'
    FunctionsToExport = 'Start-DeskPilot'
    CmdletsToExport   = @()
    VariablesToExport = @()
    AliasesToExport   = @()
    PrivateData       = @{
        PSData = @{
            Tags         = @('Copilot', 'GitHubCopilot', 'ShellPilot', 'Agent', 'AI', 'GUI', 'AgenticOperatingModel', 'PSEdition_Core', 'Windows', 'Linux', 'macOS')
            LicenseUri   = 'https://github.com/raandree/DeskPilot/blob/main/LICENSE'
            ProjectUri   = 'https://github.com/raandree/DeskPilot'
            IconUri      = 'https://raw.githubusercontent.com/raandree/DeskPilot/main/source/web/assets/logo-mark.png'
            ReleaseNotes = '## [0.5.0-preview0019] - 2026-09-01

### Added

- **A full-screen file viewer.** The viewer opens at a comfortable reading width,
  but a wide table, a long diff or a large screenshot wants the whole window. The
  new ⛶ button in its header takes the viewer edge to edge — no border, no rounded
  corners, no margin — and back again. The choice is remembered, so once you have
  said you want files full screen, every file opens that way until you say
  otherwise. Escape and ✕ still close it.

- **Open a file with your own program.** A spreadsheet, a Word document, a PDF —
  DeskPilot cannot draw any of them, and until now clicking one in the file panel
  said so and stopped. Trying to open a file it can''t show now asks whether to
  hand it to the program your computer already uses for that file type, with a
  **Always open .xlsx files this way** box on the question. Tick it and that type
  opens straight away from then on; leave it and DeskPilot asks again next time.
  Every file also has an **↗** button in the viewer, so a Markdown file or an
  image can be opened in your own editor whenever you want it there. The types
  you chose to keep are listed under **Settings › General**, each with a ✕ that
  makes DeskPilot ask again, plus **Forget all**.

  **A program or a script is never opened this way, and there is no way to allow
  one.** The agent writes into the same folder the file panel lists, so a
  `.exe`, `.bat`, `.ps1`, `.sh`, `.lnk` — or a `budget.xlsx.exe` — is refused
  outright rather than confirmed, and cannot be remembered either; opening it
  would be running it. Those files are still readable in DeskPilot''s own viewer.
  Backed by a new `POST /api/fs/open`, confined to the selected Project exactly
  like the file tree, which chooses no program and passes no arguments of its
  own.

- **Image previews instead of "there is no text to compare."** A screenshot the
  agent saved, a logo you dropped into the Project, an icon that changed — the
  Diff viewer and the file viewer now *show the picture* for the formats a
  browser can draw (PNG, JPEG, GIF, WebP, BMP, ICO, AVIF), captioned with what
  happened to the file, on a checkerboard so a transparent image reads on either
  theme. Anything else still says plainly that it has no text to compare. There
  is no before-and-after for a picture: the preview is the file as it stands
  now.

  Backed by a new `GET /api/fs/image`, confined to the selected Project exactly
  like the file tree. It is the file''s **own signature bytes** that decide the
  media type it is served under, never its extension, so a file named `.png`
  that is really a web page is refused rather than handed to the browser. SVG is
  deliberately not previewed — it is script-capable markup, and being text it
  is already readable as text. Every response now also carries
  `X-Content-Type-Options: nosniff`.

- **Automatic response retries.** A Turn no longer stops at the first transient
  Engine failure or successful-but-empty response before work has begun. The new
  **Response retries** Setting controls how many extra attempts DeskPilot makes
  after the first (`0–100`, default `2`), with each wait capped at five seconds;
  `0` turns the behavior off, and Stop remains responsive during the wait.
  Retries stop as soon as any answer or Tool Activity has appeared, so DeskPilot
  never repeats a command or write behind the user''s back. The Setting also says
  plainly that failed attempts can still consume time and Copilot credits, and
  the final token and cost Usage includes every attempt the Engine recorded
  rather than only the successful one.

- **MCP servers.** DeskPilot can now attach Model Context Protocol servers, so
  the agent gains tools from programs you choose — an issue tracker, a database,
  a document store — beside its own. A new **MCP servers** tab in Settings takes
  either a command DeskPilot runs or the path to an `mcp.json` you already keep
  for another editor (both the VS Code `servers` and the Claude `mcpServers`
  shapes are read). Each server reports what it is actually doing: whether it is
  running, which protocol version it negotiated, and exactly which tools it
  contributes. Nothing is ever discovered on its own — a file that can start a
  program has to be named by you — and a server''s tools appear in the Activity
  panel as they are called, marked apart from DeskPilot''s own so you can always
  tell whose code just ran.

  Three deliberate limits, because an MCP server is somebody else''s program
  running with your privileges. **Secrets are never stored:** a server that needs
  a token names the environment variable, and DeskPilot reads the value from its
  own environment when it starts the server, so a settings backup cannot leak a
  key. **Reach can be narrowed:** *Only offer these tools* attaches a server for
  the two tools you want and keeps the rest away from the agent entirely. And a
  new **MCP servers** permission withholds every attached server''s tools for a
  job without stopping the servers — while the panel states plainly that the
  other permissions limit DeskPilot''s own tools and do not limit an attached
  server, which can bring file and shell tools of its own.

  Requires ShellPilot 0.4.0-preview0007 or later; on an older engine the panel
  says so and everything else works as before.

- **You can now watch the agent work.** The Activity panel only ever appeared
  once a job had finished, as an unordered list of what it had touched — so while
  the agent was working, the window said nothing beyond a spinner unless *Show
  the model''s thinking* was on, and the only files it named live were the ones it
  wrote. Every tool the agent uses now appears in the panel the moment it is used,
  in order: the files it reads and writes, the folders it lists, the commands it
  runs, the **pages it fetches**, the searches it makes. A run of the same kind of
  action folds into one line — *Read 6 files*, *Fetched 2 pages* — which is open
  while the job runs and closed when it ends, leaving the whole panel as a single
  line the reader can open again. The account is kept with the message, so it
  survives a reload, and a job that was stopped or ran out of its step budget now
  keeps it too — those never receive a result, so until now they showed no
  activity at all. A fetched page is also finally named by its address rather than
  by the raw instruction that requested it.

- **One way to throw away a whole review.** Reviewing a set of changed files
  offered exactly one decision — *Undo this file* — so putting a whole change set
  back meant walking every file and undoing each one. The review footer now
  carries **Discard all changes**, which puts every file listed in the review
  back the way it was at the last save and deletes the files that were never
  saved. It appears only when there is more than one file to discard, sits at the
  opposite end of the footer from **Close** so a mis-click cannot reach it, and
  always asks first — naming how many files it is about to take, listing them,
  and saying plainly that it cannot be undone.

### Changed

- **Attachments are shown as chips on your message, not typed into it.**
  Attaching files used to write a sentence into the prompt on your behalf — "I
  attached 2 file(s) in the Workspace Folder: …" — which you then read back in
  your own bubble, saw again in the conversation title, and carried along every
  time you edited or regenerated the Turn. The files now travel beside the
  message the way GitHub Copilot Chat shows them: a chip per file above the
  bubble, hover for the full path, and your text stays exactly what you typed.
  The agent is still told what is attached and where to find it; DeskPilot says
  it rather than putting the words in your mouth, naming a file inside the
  Project relative to it and anything else by its absolute path. Attachments now
  survive a reload, an edit and a regenerate, a message can be nothing but
  attachments, and every attached path goes through the same upload check that
  already guarded images — so a crafted request still cannot point the agent at
  an arbitrary local file.

- **A Turn is now laid out in the order it happened, with the answer last.** The
  reasoning trace used to be printed as one block above the reply, so the answer
  you were waiting for was buried under thousands of lines explaining it, and the
  box stayed open forever once the job was done. DeskPilot now shows the Turn the
  way GitHub Copilot Chat does: each run of thinking gets its own box, placed at
  the point it happened, and whatever the model said before that run stays above
  it rather than being collected somewhere else — so neither the reasoning nor
  the reply piles up on one side of the other. Each box folds to a single line
  the moment its run ends, labelled with how long it took, and any of them can be
  opened again afterwards. A run streams open while it is happening, so nothing
  is hidden while you wait for it, and a box you opened yourself stays open
  rather than being shut under you when the run finishes. The complete answer is
  always rendered in full at the end, below everything else.

### Fixed

- **The end of a long answer is reachable again.** The thread could stop scrolling
  with a bar apparently already at the end while more of the answer was still
  below — reachable only by dragging a text selection downwards. The bar at the
  end belonged to the *thinking box*, not the conversation: while a run of
  thinking streams, that box sat in the middle of the message with the answer and
  the Activity panel below it, and it scrolled on its own — so a mouse wheel over
  it moved the box and never reached the conversation behind it. A run that is
  still streaming no longer scrolls separately; it shows its newest lines and
  passes the wheel straight through, and it is shorter, so it no longer fills the
  window on its own. A finished run still scrolls when you ope'

            Prerelease   = 'preview0019'
        }
    }
}