# Changelog — adia-ui-kit-factory

## [0.8.66] — 2026-09-14

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.66 work shipped in chat-shell send()-failure cleanup + Retry button, structured-surface width fix, SSE error-frame JSON escaping. See `packages/llm/core/CHANGELOG.md#0866--2026-09-14` for details.
- **`.claude-plugin/plugin.json` version bump**: moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`): no substantive entries recorded in this section, describe what shipped, or confirm this is meta-only, before cutting.
- **`references/` touched in this release window** (1 file(s), e.g. `references/component-behavior-index.md`): no substantive entries recorded in this section, describe what shipped, or confirm this is meta-only, before cutting.

## [0.8.65] — 2026-09-14

### Changed

- chore: `.codex-plugin/plugin.json` version bump only, mirroring `.claude-plugin/plugin.json`'s lockstep bump; no skill or command content change.

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.65 work shipped in A2UI renderer tree-build cycle guard now checks real DOM ancestry (ticket 10054). See `packages/gen-ui/a2ui/CHANGELOG.md#0865--2026-09-14` for details.
- **`.claude-plugin/plugin.json` version bump**: moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`): carried by the entry above.

## [0.8.64] — 2026-09-13

### Changed

- chore: allowlist 7 verified real script/prose G8 names, per-plugin `.release-gate-g8-allow.json` (ticket 10036) (#4407)
- chore: de-reference the phantom `component-token-audit` citations in theme-audit's description and body (ticket 10036) (#4409)

### Docs

- docs: host-wiring gains an A2UI-rendering-hosts paragraph, stating an `<a2ui-root>`-embedding host needs no manual per-component JS/CSS import for LLM-composed content, and must not add one (adr-0115, lld-0037, ticket 10041) (local ticket 10041)
- docs: clarify tools/delegate_tool.py is a path inside the external Hermes Agent install, not this repo (#4411)

### Maintenance
- **`.claude-plugin/plugin.json` version bump**: moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`): carried by the entries above.
- **`skills/` touched in this release window** (4 file(s), e.g. `host-wiring/SKILL.md`): carried by the entries above.

## [0.8.63] — 2026-09-12

### Changed

- chore: accept release_gate G15 (harness overlay convention mismatch) per conductor ruling, file ticket 10035 (ticket 10026) (#4403)

### Maintenance
- **`.claude-plugin/plugin.json` version bump**: moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`): carried by the entries above.

## [0.8.62] — 2026-09-10

### Changed
- chore: .mcp.json generation-MCP pin moved to @adia-ai/mcp@0.8.62 (invariant 8); .claude-plugin, .codex-plugin, plugin.yaml, hermes-mcp.yaml manifests and the README pin stamped 0.8.62

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.62 work shipped in the icon-ui premature settle-notify drain-loop fix (ticket 10015, PR #4361), the regression that blocked v0.8.61's site deploy. See `packages/web-components/CHANGELOG.md#0862--2026-09-10` for details.
- **`.claude-plugin/plugin.json` version bump**: moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`): carried by the entries above.

## [0.8.61] — 2026-09-10

### Changed

- chore: swap `<admin-scroll>` for `<page-scroll>` in shell-authoring guidance (gh#3745) (#3826)
    `references/shell-admin.md` and the Figma Make `components.md` guideline taught agents to
    author `<admin-scroll>` directly; both now point at `<page-scroll>`, the module's sole
    successor now that `admin-scroll` is deleted.
- chore: re-derive lint-rule bank and component-behavior-index after shader-texture-ui's `noise` variant (gh#3777) (#4235)
- chore: suppress RAW-COLOR on the theme-audit-fixtures' own seeded literal-fallback fixture, RAW-COLOR now sees it and would otherwise fail the fixture bank as a real violation (gh#3839) (#4038)

### Fixed

- fix: vendored lint-rule bank mirror regenerated after MISSING-SCOPE's substring-loophole fix (gh#3888) (#3917)

### Maintenance
- **`.claude-plugin/plugin.json` version bump**: moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`): carried by the entries above.
- **`scripts/` touched in this release window** (2 file(s), e.g. `scripts/lint-rules.generated.mjs`): carried by the entries above.
- **`skills/` touched in this release window** (2 file(s), e.g. `references/pattern-index.md`): carried by the entries above.

## [0.8.60] — 2026-09-06

### Added

- feature: screen-composition's "Validate anything generated" step also calls classify_archetype alongside validate_schema (ADR-0112 Decision 2, gh#3373) (#3419)
- feature: new `references/component-behavior-index.md` (generated) plus `screen-composition`/`surface-qa` consumption of it, and the new typed `fulfills`/`disambiguation` yaml fields once gh#3368's build landed (gh#3360, LLD-0022) (#3433)

### Changed

- chore: resync vendored lint-rules.generated.mjs against the shared lint-rule bank (gh#3359) (#3365)

### Fixed

- fix: wire REQUIRED-ATTR into lab-posture-guard.mjs's write-time hook, never blocking (gh#3221 follow-up, gh#3236) (#3311)
  The write-time `PreToolUse` lab-posture hook now surfaces REQUIRED-ATTR findings
  (a missing manifest-declared required attribute) as a non-blocking advisory —
  `permissionDecision: "allow"` carrying `hookSpecificOutput.additionalContext` —
  kept structurally separate from the four rules that still deny on any finding, per
  the conductor ruling on gh#3221 that a false-positive rule must never block
  authoring at the keystroke. Also fixes `adia-manifest-lite.mjs`, which never
  forwarded a sidecar's `required` array onto its attr descriptors — without that
  fix REQUIRED-ATTR would have wired in as a silent no-op at write time even though
  it already fires correctly at check time (`npm run lint`, CI).
- fix: adia-manifest-cache.mjs's cache key always includes repoRoot, not just session_id — two runs sharing a literal session id no longer read back each other's cached manifest (gh#3316) (#3320)
- fix: vendored lint-rule bank mirror no longer emits an em dash (gh#3834) (#3878)

### Docs

- docs: update `a2ui-mcp-surface.md`'s `plan_app_state` row for the ontology-context -> app-state-context rename (gh#3385) (#3415)
- docs: update the component-authoring reference's token example off the retired --a-ui-px alias, onto --a-ui-inset (gh#3054) (#3669)
- docs: retarget the pattern-catalog annotation for the renamed page-header route (#3759)
    `annotations.yaml`'s key for `site/pages/patterns/admin-page-header.html` follows the site
    page's rename to `site/pages/patterns/page-header.html` (gh#3750, ADR-0098 drain); the derived
    `pattern-index.md`/`site/patterns-index.json` regenerate from it via `npm run build:patterns-index`.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.
- **`scripts/` touched in this release window** (5 file(s), e.g. `scripts/adia-manifest-cache.mjs`) — carried by the entries above.
- **`skills/` touched in this release window** (4 file(s), e.g. `references/annotations.yaml`) — carried by the entries above.

## [0.8.59] — 2026-09-04

### Added
- **`scripts/adia-posture.d.mts`: ambient TypeScript types for `scripts/adia-posture.mjs` (gh#2875).** Lets `@adia-ai/mcp`'s factory server's new `scaffold_prototype` tool import `readPosture()` directly (the SAME reader `lab-posture-guard.mjs` uses) once vendored, without pulling the plain-JS module into that package's TypeScript build as a compiled input. No behavior change to `adia-posture.mjs` itself; see `@adia-ai/mcp`'s own CHANGELOG for the tool this enables.

### Fixed
- **`skills/pattern-catalog/references/pattern-index.md` regenerated after gh#2916's `dashboard-page-header` corpus-chunk rebuild reordered `dashboard-admin-page`'s components list.** Derived-only (`npm run build:factory-mcp-assets`), no source change in this package.

### Changed
- **`scripts/lint-rules.generated.mjs` (vendored lab-posture bank) regenerated after gh#2939's EXAMPLE-PROP-CONTRACT `data-*` exemption and GENUI-DOC-CONFLICT self-scope fix landed in the shared rule sources.** Derived-only, no source change in this package; the vendored bank picks up both predicate narrowings — full-corpus warn count 1413 → 1410 (see repo-root CHANGELOG.md for the gate's own detail).
- **`scripts/lint-rules.generated.mjs` (vendored lab-posture bank) regenerated after gh#2937's `tagTree()` memoization landed in `scripts/lint/engine/primitives.mjs` (root).** Derived-only, no source change in this package; the vendored bank picks up the shared engine's single-slot memo, so the 48 generated `COMPOSITION-*` rules now share one tag-tree parse per file instead of each re-parsing it — full golden-corpus `check:lint-efficacy`: 110.9s → 9.45s. Byte-identical rule semantics (38/38 seeded-fixture catch rate, 0 error-severity across 438 files, unchanged).
- **`scripts/lint-rules.generated.mjs` (vendored lab-posture bank) regenerated to carry `enum_meta` tier data for gh#2831 batch 2's 9 components** (feed-item-ui, inline-message-ui, link-ui, loading-overlay-ui, mark-ui, menu-item-ui, nav-group-ui, nav-item-ui, nav-ui). Derived-only, no source change in this package; the vendored bank follows the yaml `enum_meta` authored in `@adia-ai/web-components`.
- **`scripts/lint-rules.generated.mjs` (vendored lab-posture bank) regenerated to carry `enum_meta` tier data for gh#2831 batch 3's 13 components (FINAL batch)** (pagination-ui, preview-ui, rating-ui, select-ui, shader-texture-ui, spinner-ui, table-toolbar-ui, tabs-ui, tag-ui, text-ui, timeline-item-ui, toast-ui, toggle-scheme-ui). Derived-only, no source change in this package; the vendored bank follows the yaml `enum_meta` authored in `@adia-ai/web-components`. Closes the 31-component sweep (gh#2831).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.

## [0.8.58] — 2026-09-02

### Added
- **Lab posture: `.adia` marker, manifest-derived lint rules, and a blocking `PreToolUse` write-time hook (ADR-0108 D1/D5, LLD-0019 C3-C5, gh#2856).** New `Posture` README section documents the `.adia` marker schema (`{ "posture": "lab" | "bare-repo", "kit"?: { "web-components": "<version>" } }`) and `scripts/adia-posture.mjs`'s `readPosture(repoRoot)` reader, posture is explicit, never inferred from `package.json`/`node_modules`. New `lab-posture-guard` hook (`PreToolUse`, `Write|Edit`): in lab posture, denies a write containing an unknown tag/attribute/enum value or an `internal`-tier value (the same four rules, `UNKNOWN-TAG`/`UNKNOWN-ATTR`/`ENUM-VALUE`/`INTERNAL-TIER`, imported straight from this plugin's own vendored `lint-rules.generated.mjs`, never a second matcher implementation), with the violating tag/attr/value and the manifest's allowed set in the deny reason; a no-op in bare-repo/absent posture, `adia-lint`'s existing advisory `PostToolUse` contract is completely unchanged. New `SessionStart` hook warms the manifest cache once per session. Reads a lab consumer's LIVE installed manifest via a new dependency-free `adia-manifest-lite.mjs` (JSON-only: none of the four rules needs `a2ui.rules`, so no vendored yaml parser required for this path), cached per-session by `adia-manifest-cache.mjs` under the OS temp dir (never a tracked repo artifact). Hook integration selftest (`npm run check:lab-posture-guard-selftest`) builds two tmp-dir fixture consumer repos (lab / bare-repo, mirroring `get-manifest.test.js`'s own fixture-building pattern rather than committing a real `.a2ui.json` fixture, which would trip `adia-ui-forge`'s `sidecar-prewrite-guard`) and asserts an unknown-tag write is denied in lab and allowed bare-repo, plus clean/enum/internal-tier/unknown-attr/non-markup cases. Non-Claude harnesses (Codex/Hermes/Pi) get no hook runtime, see the README's "Non-Claude harnesses" section for the `npm run lint`-at-`warn` degradation. Hooks roster: 1 → 2 (site's `factory-plugin.html` roster page updated, `check:plugin-count-claims` guards it).

### Changed
- **`adia-scaffold spa`'s `_SPA_JS`/`_SPA_HTML` templates register only the tags the placeholder markup uses (page-ui, text-ui) via per-component JS + CSS imports, instead of the full `@adia-ai/web-components` / `@adia-ai/web-components/css` barrel (ADR-0107, gh#2765).** The generated app's `dist/` shrinks from ~39MB / 9,092 files (barrel JS + the full Phosphor icon glob) to ~272KB / 3 files, JS gzip 430KB→7.7KB, CSS gzip drops similarly, measured against this checkout's own `packages/web-components`. The barrel stays fully supported: the template's own header comment documents the two-line kitchen-sink opt-in (`import '@adia-ai/web-components'` + `/css`) for consumers who want zero-config registration of every primitive. Scaffolded SPAs now also get a `README.md` with a "Bundle cost" section stating this trade-off, the icon-subsetting `installIconLoaders()` path, and the kitchen-sink opt-in.
- **`selftest`'s `_resolve_export` wildcard-match tie-break fixed to match Node's own exports-resolution specificity rule** (prefix+suffix length, not prefix length alone), the old tie-break could resolve a `.css`-suffixed subpath against the wrong same-prefix wildcard key (e.g. `./components/*` instead of the more specific `./components/*.css`), which the previous templates never exercised but the new per-component CSS imports do.

### Fixed
- **Pi `ui-architect` self-test now re-execs with Node's explicit TypeScript-stripping flag on early Node 22 patch releases (gh#2803).** Direct and npm-script invocations can import `ui-architect.extension.ts` across the supported Node 22 major instead of depending on the later patch that enabled type stripping by default.
- **ATTR-TYPO/LLM-KEY-IN-CLIENT/NATIVE-PRIMITIVE matcher hardening (gh#2708)**, propagated to this plugin's vendored `scripts/lint-rules.generated.mjs` via `npm run build:lint-rules`, byte-identical to the shared lint-rule bank, no change to `adia-lint.mjs`'s own CLI contract.

### Docs
- **`scripts/lint-rules.generated.mjs` (vendored lab-posture bank) regenerated to carry `enum_meta` tier data for gh#2831 batch 3's 13 components** (pagination-ui, preview-ui, rating-ui, select-ui, shader-texture-ui, spinner-ui, table-toolbar-ui, tabs-ui, tag-ui, text-ui, timeline-item-ui, toast-ui, toggle-scheme-ui). Derived-only, no source change in this package; the vendored bank follows the yaml `enum_meta` authored in `@adia-ai/web-components`. Closes the 31-component sweep (gh#2831).
- **generated lint-rule bank refreshed (gh#2821, gh#2824)**: a full `npm run build:lint-rules` regen pass, run while rebasing the heatmap/noodles a11y fixes onto main, picked up `enum_meta` `tier`/`when` data already landed upstream (gh#2864) that this vendored copy hadn't caught up to yet; vendored copy byte-identical to the shared bank, no behavior change.
- **generated lint-rule bank refreshed (gh#2845)**: `gen-composition-rules.mjs`'s scan widened from `<dirname>.yaml` only to every `*.yaml` in a component directory, discovering 14 previously-missed child/sub-item yamls; composition-rule count 34 → 48 (mechanics: repo-root CHANGELOG.md); vendored copy byte-identical to the shared bank, no behavior change.
- **generated lint-rule bank refreshed (gh#2801)**: `gen-composition-rules.mjs`'s eligibility widened from 1 to 34 generated composition rules, decoupled from component.md pilot status (mechanics: repo-root CHANGELOG.md); vendored copy byte-identical to the shared bank, no behavior change.
- **generated lint-rule bank refreshed** by wave-5A component.md eligibility regen (lld-0018).
- **generated lint-rule bank refreshed** by wave-5B component.md eligibility regen (lld-0018).
- **generated lint-rule bank refreshed**: wave-1A component.md eligibility added 3 composition rules (accordion/action-list/choice-card, lld-0018).
- **pattern-catalog `pattern-index.md` regenerated** for the header-ui→header sweep (gh#2793).
- **pattern-catalog `pattern-index.md` regenerated** for the admin-page-header pattern entry's admin-scroll→page-scroll wrapper swap (gh#2734).
- **`pattern-catalog/SKILL.md`'s ADR-0084 forward note gains a build-status update (gh#2736).** The generated `templates/` npm mirror generator has landed (`@adia-ai/web-components`'s CHANGELOG carries the mechanics); this note records that the `ships:`/resolution-table flip is a separate, not-yet-built wave.
- **ADR-0098 drain: remaining admin-page prose in `references/shell-admin.md`, `skills/app-audit/references/gap-classes.md`, and `skills/screen-composition/assets/figma-make/guidelines/components.md` rewritten to `<page-ui band>`.** These three still described the retired `<admin-page>`/`<admin-page-header>`/`<admin-page-body>` triad as the current admin-shell chrome pattern, the canonical skeleton example, the chrome-tier allocation table, a gotcha row on the "without inner column-owner" failure mode, and the Figma-Make shells vocabulary/skeleton all now show `<page-ui band>` with `<header-ui>`/`<section-ui>` children. `demo-audit/references/admin-shell-anatomy.md`, `demo-audit/references/app-shell-pitfalls.md`, and `primitive-authoring/references/shell-patterns.md` were checked and already carry correct dated ADR-0098 deprecation notes from an earlier harvest, no change needed there.
- **`pattern-catalog/references/pattern-index.md` + `annotations.yaml` updated for `admin-page-header.html`'s ADR-0098 rewrite (gh#2748).** The docs-site pattern page itself moved off the deprecated `<admin-page-header>`/`<admin-page>`/`<admin-page-body>` triad onto `<page-ui band>`'s direct `<header-ui>` child (root `CHANGELOG.md` carries the page-rewrite detail); `annotations.yaml`'s `admin-page-header.html` entry intent/keywords updated to name `page-ui band` instead of `admin-page`, and `pattern-index.md` regenerated (`npm run build:patterns-index`) picks up the entry's `components:` list dropping `admin-page`/`admin-page-body`/`admin-page-header`/`alert-ui` for `page-ui`.
- **`pattern-catalog/references/pattern-index.md` regenerated (`npm run build:patterns-index`, gh#2730).** `patterns-form-drawer`'s `components:` list re-sorts after gh#2730's label-variant sweep collapsed `form-drawer.examples.html`'s `field-ui[inline]`-wrapping-`switch-ui` anti-pattern to the switch's own `[label]` attribute, shifting the extracted tag order.
- **ADR-0098 knowledge-harvest applied to `shell-selection/SKILL.md`.** The "Canonical nesting" verify-target row gains a dated deprecation note (2026-09-01) pointing the `admin-page`/`admin-scroll` nesting example at its successor, `page-ui[band]` nested inside `page-scroll`.
- **`pattern-catalog/references/pattern-index.md` regenerated (`npm run build:patterns-index`, gh#2706).** The "Admin Shell" and "Admin Content Aside" pattern entries' `components:` lists still named `admin-page`/`admin-page-header`/`admin-page-body`/`admin-scroll`, their source demo (`packages/web-components/patterns/admin-shell/admin-shell.examples.html`) had been missed by the earlier ADR-0098 sweep; now byte-resynced to `page-scroll`/`page-ui[band]` after the source migration.
- **ADR-0084 knowledge-harvest applied to `pattern-catalog/SKILL.md`.** The "Reach the source" section's "none of them a template screen" `ships:` claim gains a dated forward-note (2026-09-01) recording ADR-0084's ruled `templates/` npm-mirror plan for all 121 template screens (Class R, build-at-publish); the 6 `/site/pages/patterns/` docs-hub pages stay `monorepo-only` permanently either way.
- **ADR-0102 harvest: `surface-qa/references/verification.md:62`'s superseded heading-role workaround corrected.** The Accessibility checklist row recommending `role="heading"` + `aria-level` or an `<h*>` wrapper for a `text-ui variant="heading"` node now points at `text-ui[level]` (1-6, promotes to a real native `<h1>`-`<h6>`) as the current fix, citing ADR-0102 (2026-09-01); `variant` stays presentational-only, `level` is the tag-promoting prop.

### Chore
- **Author email in `package.json` updated to `kim.granlund@adia.ai`** (was a stale personal address).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.
- **`adapters/` touched in this release window** (1 file(s), e.g. `claude/hooks.json`) — carried by the entries above.

## [0.8.57] — 2026-09-01

### Fixed
- **Plugin passes `author-cross-harness-plugins`'s cross-harness validator, modulo one documented, permanent, irreconcilable exception (gh#2668).** `${CLAUDE_PLUGIN_ROOT}`/`$ARGUMENTS`/the `` !`command` `` auto-injection syntax removed from shared `app-migration`, `theme-audit`, `screen-composition`, `project-scaffolding`, `app-planning`, `surface-qa`, and `find-unused` SKILL.md bodies, all eight `commands/*.md` bodies, and their linked reference docs (`surface-qa/references/verification.md`, `find-unused/references/recon-and-audits.md`) — portable `<plugin-root>` prose / "named in the current request" phrasing throughout; `screen-composition`/`app-planning`'s Claude-only auto-injected context block became an explicit "run this yourself" instruction, since Codex has no equivalent auto-injection surface. `hooks/hooks.json` moved to `adapters/claude/hooks.json` (unchanged, `${CLAUDE_PLUGIN_ROOT}`-based); new root `hooks.json` mirrors the same event/matcher/action signature with a monorepo-root-relative command path for Codex's convention-discovered hook surface — an unverified-but-honest fallback documented in `HARNESS-NOTES.md`. **The one exception:** every skill's `disable-model-invocation:`/`user-invocable:` frontmatter — required, explicitly, by this repo's own blocking `check:skills` gate (`plugin-estate-v2.md`'s species-pinning charter) — collides head-on with the validator's opposite requirement on the exact same file, and Codex is hard-pinned to read root `skills/` directly (no adapter escape). The repo's own charter is not weakened; `npm run check:cross-harness-plugins` (`scripts/verify/check-cross-harness-plugins.mjs`, wrapping the vendored `scripts/verify/vendor/validate_cross_harness.py`) treats only this one exact finding shape as accepted (logged as INFO) and still fails on every other portability class. Full reasoning in `HARNESS-NOTES.md`.

### Docs
- **`skills/pattern-catalog/references/pattern-index.md` regenerated for `page-scroll`'s addition (gh#2639, ADR-0098 Fork 4).** `build:patterns-index`'s re-extraction picked up `admin-dashboard.contents.html`/`admin-shell.contents.html`'s tag-list changes under the page-chrome consolidation (`admin-page*` → `page-ui[band]`, `admin-scroll` → `page-scroll`).

### Changed
- **`adia-lint` rewritten as a thin Node CLI (`adia-lint.mjs`) consuming a shared generated lint-rule bank, retiring the Python script (gh#2638, LLD-0016, ADR-0099).** The consumer-app structural checks (the forge-shared rules plus SSR-DOUBLE-ROUTER, SSR-TOPLEVEL-IMPORT, HARDCODED-OPEN, SHELL-NESTING, SHELL-RESIZE, LLM-KEY-IN-CLIENT, GENUI-UNVALIDATED, GENUI-DOC-CONFLICT) now live as individually-fixtured rule modules under `scripts/lint/rules/` in the repo root, built into `scripts/lint/generated/rule-bank.mjs` and vendored byte-identically into this plugin, `adia-ui-forge`, and the gen-ui MCP's factory vendor tree (`npm run build:lint-rules`, freshness gated by `npm run check:lint-rules-fresh`). `hooks/hooks.json`'s PostToolUse command changes from `python3 ".../adia-lint" --hook` to `node ".../adia-lint.mjs" --hook`; the CLI contract (including `-h`/`--help`), exit codes, and PostToolUse never-block invariant are unchanged. `npm run check:lint-rules-selftest` proves finding-parity against the retired script's own `selftest()` fixtures. The gen-ui MCP factory server's `lint` tool (`audit_structure`) now spawns the Node CLI directly instead of shelling through `python3`.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.
- **`agents/` touched in this release window** (1 file(s), e.g. `agents/surface-qa-agent.md`) — carried by the entries above.
- **`prompts/` touched in this release window** (8 file(s), e.g. `prompts/app-audit.md`) — carried by the entries above.

## [0.8.56] — 2026-08-31

### Added
- **`theme-audit` skill, `/theme-audit` command, and `scripts/adia-theme-audit.mjs` runner (lld-0012 B1–B3, gh#2257).** Audits a consumer app's `theme.css` for the four redundancy classes (restated defaults, token re-derivations, dead selectors, hand-built components) across every sitemap route, with a Playwright class-1 toggle and route discovery (#2308, #2312, #2413). Fixtures under `scripts/theme-audit-fixtures/`; report shape in `skills/theme-audit/references/report-shape.md`; Codex/Pi/Hermes manifests derived (`skills/theme-audit/agents/openai.yaml`, `prompts/theme-audit.md`).
- **`HARNESS-NOTES.md`** pointer for non-Claude harnesses (gh#2449) — points at `AGENTS.md`/README rather than duplicating install prose.

### Changed
- **`scripts/adia-probe.mjs`** gains the route-discovery + class-1 toggle hooks the theme-audit runner drives (#2413); `agents/surface-qa-agent.md` cites the extended probe.
- **`skills/token-selection/references/a-alias-layer.md`** documents the 15 new `--a-*` aliases from tokens batch C0 and the advisory reroute gate (gh#2240, #2243).
- **`skills/pattern-catalog/references/{pattern-index.md,annotations.yaml}`** pick up the sidebar-modal pattern (#2226) and the registration/NPI-search and errors surfaces (#2242, #2270); `skills/table-composition/references/base-table.md` follows `table-toolbar-ui`'s count-cluster redesign (#2190); `skills/find-unused/SKILL.md` wording tightened.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.
- **`commands/` touched in this release window** (1 file(s), e.g. `commands/theme-audit.md`) — carried by the entries above.

## [0.8.55] — 2026-08-28

### Changed
- **`.codex-plugin/` regenerated for the release window** — `.codex-plugin/plugin.json`'s embedded `version` moves with the lockstep bump (derived from `.claude-plugin/plugin.json`, not an independent edit).

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.55 work shipped in button-ui flex-shrink:0 default fix (gh#2180/gh#2181). See `packages/web-components/CHANGELOG.md#0855--2026-08-28` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.54] — 2026-08-27

### Added
- **`references/overlays.md`** — new decision reference grounding the modal-ui/drawer-ui/popover-ui/tooltip-ui/menu-ui/context-menu-ui choice in the primitives' own yaml sidecars, closing a coverage gap in `references/` (tables had table-composition, charts had chart-selection, overlays only had scattered mentions). Carries the mobile-nav-drawer always-in-DOM scoping gotcha (gh#2031) and is wired into `skills/screen-composition/SKILL.md`'s load-when routing table. Closes gh#2031.
- **`scripts/verify/check-adia-ui-factory-references.mjs`** (repo-root, wired as `check:adia-ui-factory-references`, 93 → 94 gates) — mechanizes the checkable subset of a `references/` drift audit going forward: every `required-for:` skill name resolves to a real `skills/` directory, and every backtick-quoted repo path citation resolves under the repo root or the plugin root.

### Fixed
- **`references/annotations.yaml`** — flagged the `responsive-shell-sidebar` pattern's own documented state-loss defect (components with local DOM state lose it when the viewport crosses the breakpoint, since the inline copy unmounts while the drawer copy mounts) and points shell leading-nav collapse work at the drawer-relocation approach instead (ADR-0090 supersedes this recipe in practice; the dual-mount recipe stays lawful only for non-shell/non-nav cases). Derived `skills/pattern-catalog/references/pattern-index.md` regenerated to match.
- **`references/component-model.md`** — still cited the pre-v0.2.0 `AdiaToast`/`AdiaFeed` class names, renamed to `UIToast`/`UIFeed` at v0.2.0 (~80 releases stale).
- **`references/genui-a2ui.md`** — pointed maintainer-territory edits at `packages/gen-ui/a2ui/compose`; the real path is `packages/gen-ui/engine/compose`. Also fixed a stale `registerResolver` import citing the ancient pre-consolidation `@adia-ai/a2ui-runtime` package name — now `@adia-ai/a2ui`.
- **`references/mcp-substrate.md`** — package naming two renames behind (gh#1240): the generation MCP is `@adia-ai/mcp`'s `gen-ui` subcommand, not the retired `@adia-ai/gen-ui-mcp`.
- **`references/llm.md`** — version snapshot stale (v0.7.26 → lockstep current); API surface itself re-verified accurate.
- **`references/shell-simple.md`** — stylesheet line-count citation wrong (33 → 40).
- **`references/spa-architecture.md`** — cross-referenced "five" data-flow patterns in `data-and-hydration.md`; it documents six (`createStore()` added later).
- **`references/agentic-ux-patterns.md`** — `confirm-dialog` → `confirm-dialog-ui` (tag-suffix convention).

### Docs
- **`references/shell-admin.md`, `shell-chat.md`, `shell-editor.md`** — none mentioned the mobile-nav-drawer persistent-DOM contract (gh#2031); `shell-admin.md` also gained a Subnav-rail pages section (the gh#2143 fix).
- **`references/ssr-integration.md`** — re-verified all `[D]` claims against live source, refreshed the staleness self-check date stamp; applied the same re-verification date-stamp convention to the other 18 reference files in this tree (`agentic-ux-patterns.md`, `authoring-components.md`, `composed-surface-rubric.md`, `contracts/a2ui-mcp-surface.md`, `contracts/migration-guide-format.md`, `data-and-hydration.md`, `genui-a2ui.md`, `llm.md`, `mcp-substrate.md`, `migration.md`, `overlays.md`, `project-shapes.md`, `shell-embed.md`, `spa-architecture.md`, plus the three shell-* files and `shell-simple.md` above) — following the operator ruling on the coverage-gap review: "if it was identified as a gap, it needs to be addressed" (PR #2157's manual audit had covered all 19 files once already; nothing mechanized re-verification afterward until this cut's new gate).
- **`references/authoring-components.md`, `data-and-hydration.md`, `project-shapes.md`, `migration.md`, `contracts/*.md`, `composed-surface-rubric.md`** — checked against current `main`, already accurate, date-stamp applied, no content changes.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.

## [0.8.53] — 2026-08-26

### Changed
- **`skills/pattern-catalog/references/pattern-index.md` regenerated** (`npm run build:patterns-index`) — mechanical reindex, no skill/agent behavior change this cut.

### Maintenance
- **Lockstep version bump only.** No other source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.53 work shipped in Framework-wide docs+catalog audit (177 primitives/modules), nav collapsible click-handler bug fix, corpus-wide Related-link sweep (181 fixes), SegmentedControl catalog-rename cascade fix, mobile-nav-drawer consumer contract docs (gh#2032, gh#2031, gh#2068, gh#2076, gh#2116, gh#2133). See `packages/web-components/CHANGELOG.md#0853--2026-08-26` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the `pattern-index.md` regen above; no separate content change.

## [0.8.52] — 2026-08-25

### Added
- **`ui-architect` portable skill + `BuildResult`/`VerifyProof` linters + repo-root Codex git-sourced marketplace (ADR-0091 C1/C2/C3/C4/C7, PR #1998).** `skills/ui-architect/SKILL.md` (with `agents/openai.yaml`, auto-derived via `codex-manifests.mjs`) authors one contract-grammar skill body every harness consumes as a thin adapter, backed by new `scripts/build-result-lint` and `scripts/verify-proof-lint` (record-lint family) plus `check:ui-architect-skill-portable` (85 → 88 gates in `npm run check`). `.agents/plugins/marketplace.json` (repo root) is the new git-install Codex channel — verified against OpenAI's own merged `codex-rs` marketplace-resolution source rather than assuming the Claude-side schema. `agents/ui-architect.md` slimmed to identity/tool-wall/dispatch-mechanics/failure-branches/stopping-predicate; the app-planning/screen-composition/surface-qa agent files already met the target shape.
- **`ui-architect` Pi extension (`pi/ui-architect.extension.ts`) + Hermes `delegate_task` `/ui-architect` command (ADR-0091 C5/C6, PR #2000).** Both harnesses verified live against their actual installed runtimes before building: Pi via the installed `@earendil-works/pi-coding-agent` v0.84.3's own subprocess-based subagent-dispatch pattern (live end-to-end run: dispatched all three isolated planning/composition/QA passes as real child `pi` processes, wrote a real file, took a real screenshot, returned a clean `VerifyProof`); Hermes via the installed Hermes Agent's own `PluginContext.register_command`/`delegate_tool.py` source, gated by the same portable-contract linters and live-verified via `hermes plugins doctor --ci`. Pi/Hermes native adapters framed as in-progress in the README rather than claiming unverified parity.

### Changed
- **All agent seats pinned to `sonnet` + `xhigh` reasoning effort, replacing the prior fable/opus ceiling-ladder pins (PR #1999).** Operator's direct standing instruction, applied across `app-planning-agent`, `screen-composition-agent`, `surface-qa-agent`, `ui-architect`. See root `CHANGELOG.md` for the cross-plugin note.

### Fixed
- **The new repo-root Codex marketplace manifest collided on `"name": "adia-plugins"` with the npm-sourced sibling, so `codex plugin marketplace add`/`codex plugin add` resolved ambiguously (PR #2002).** Renamed to `adia-ui-kit`, matching the existing Claude-side `adia-ui-kit`/`adia-plugins` split exactly; README + getting-started site page install references updated.

### Docs
- **README's install section hand-typed a stale "published v0.1.0" for `@adia-ai/adia-plugins`, now at v0.2.0 (PR #1996).** Dropped the hardcoded version number (it would only go stale again on the next Class-B cut) in favor of a pointer to the `adia-plugins` README, which carries its own current version and Non-Claude-harness detail.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.

## [0.8.51] — 2026-08-24

### Added
- Hermes + Pi external-distribution manifests (gh#1954) — `plugin.yaml` +
  `__init__.py` + `hermes-mcp.yaml` (Hermes) and `prompts/*.md` + a `"pi"`
  field in `package.json` (Pi), derived from `.claude-plugin/plugin.json` +
  `skills/` + `commands/` + `.mcp.json` via `npm run
  build:harness-manifests` (`check:harness-manifests-fresh` gates
  freshness). Additive: the Claude Code plugin surface is unchanged.
  **MCP caveat, not parity:** Hermes MCP is user-level config — merge the
  generated `hermes-mcp.yaml` into `~/.hermes/config.yaml` by hand. Pi core
  has no native MCP — the `adia-gen-ui` server only reaches Pi through the
  third-party `pi-mcp-adapter` reading this plugin's `.mcp.json` unmodified.
  See the README's "Non-Claude harnesses" section before promising Pi/Hermes
  parity for this plugin's headline MCP-wiring feature.

### Maintenance
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.
- **`scripts/` touched in this release window** (2 file(s), e.g. `scripts/adia-contract-check.mjs`) — carried by the entries above.

## [0.8.50] — 2026-08-23

### Maintenance
- **Lockstep bump riding the v0.8.50 cut** (`scripts/release/check-lockstep.mjs`); the headline v0.8.50 work ships in @adia-ai/web-components (prose/verse sheet removal gh#1885 / PR #1918, input/search fill-default posture gh#1856 — see `packages/web-components/CHANGELOG.md#0850--2026-08-23`). Package-local changes are listed below.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`.codex-plugin/` touched in this release window** (1 file(s), e.g. `.codex-plugin/plugin.json`) — carried by the entries above.

### Docs
- **`references/` + `skills/` docs refreshed for the release window** — `component-model.md` and `spa-architecture.md` plus the `find-unused` (`recon-and-audits.md`), `host-wiring` (`SKILL.md`, `mode-wiring-detail.md`), and `table-composition` (`base-table.md`) skill references updated to current framework contracts (incl. the gh#1918 `[prose]`/`[verse]` removal and gh#1856 fill-default posture).

## [0.8.48] — 2026-08-23

### Added
- OpenAI Codex plugin manifest (gh#1888) — `.codex-plugin/plugin.json`
  (including `mcpServers: "./.mcp.json"`) + a per-skill
  `skills/<name>/agents/openai.yaml`, derived from
  `.claude-plugin/plugin.json` via `npm run
  build:codex-manifests` (`check:codex-manifests-fresh` gates freshness).
  Additive: the Claude Code plugin surface is unchanged.

## [0.8.47] — 2026-08-22

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.47 work shipped in table-toolbar size/chrome fixes, anchor popover reuse guard, token-layer light-dark cleanup (gh#1852), side-by-side docs demos. See `packages/web-components/CHANGELOG.md#0847--2026-08-22` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.46] — 2026-08-22


### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (3 file(s), e.g. `references/annotations.yaml`) — carried by the entries above.

## [0.8.45] — 2026-08-20

### Changed
- **Plugin description tuning from the 2026-08-19 check-routing findings (gh#1731).** Narrowed
  `app-audit`'s symptom vocabulary — dropped the "what's wrong with X" catch-all and tightened
  "renders unstyled/broken/off" to "looks unstyled/off-brand" — so it stops gravitationally
  stealing sibling trigger cases from `chart-selection`, `data-wiring`, `surface-qa`,
  `project-scaffolding`, and `app-planning`. Added the "harvest chunks / point retrieval at our
  own corpus" trigger phrase to `gen-ui-wiring` (was routing DEAD in the blind-judge sim). Scoped
  `surface-qa` to a CONSUMER app's surfaces and named the framework repo's own dogfood/demo-page
  sweep (forge's `demo-audit`) in a NOT-line — fixes a routing leak on that wording. Closes #1731.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`references/` touched in this release window** (2 file(s), e.g. `references/component-model.md`) — carried by the entries above.
- **`skills/` touched in this release window** (7 file(s), e.g. `app-audit/SKILL.md`) — carried by the entries above.

## [0.8.44] — 2026-08-20

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.44 work shipped in charts y-domain pins, table-toolbar compaction ladder, text mono roles, pagination SSR adoption. See `packages/web-components/CHANGELOG.md#0844--2026-08-20` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`references/` touched in this release window** (3 file(s), e.g. `references/data-and-hydration.md`) — carried by the entries above.
- **`skills/` touched in this release window** (22 file(s), e.g. `app-audit/SKILL.md`) — carried by the entries above.

## [0.8.43] — 2026-08-18

### Breaking
- adia-lint SHELL-RESIZE accepts only `data-sidebar-resize`; the W1 dual-name window and `DEPRECATED-LAYOUT-NAME` advisory are retired with the W3 cut (gh#1562, #1622).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`scripts/` touched in this release window** (1 file(s), e.g. `scripts/adia-lint`) — carried by the entries above.
- **`skills/` touched in this release window** (1 file(s), e.g. `references/a-alias-layer.md`) — carried by the entries above.

## [0.8.42] — 2026-08-17

### Maintenance
- Vendored contract/catalog references updated for the ADR-0063 compat shims and rename-wave W1/W2 names (PRs #1565/#1567/#1569).
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`scripts/` touched in this release window** (1 file(s), e.g. `scripts/adia-lint`) — carried by the entries above.
- **`skills/` touched in this release window** (1 file(s), e.g. `references/pattern-index.md`) — carried by the entries above.

## [0.8.41] — 2026-08-17

### Changed
- **`pattern-catalog`'s `references/pattern-index.md` lists every component tag a pattern composes (gh#1498)** — the silent top-12 cap per pattern is removed, and the index is regenerated for the 0.8.41 catalog wave (`progress-row-ui` absorbed into `progress-ui`, `input-ui[type]` enum trim). Consumers picking patterns by component tag now see the full list.
- **`gen-ui-wiring` + `wave-coordination` skills harvest ADR-0046/ADR-0047 into references (#1409)** — `gen-ui-wiring/references/persona-floor.md` and `wave-coordination/references/seat-roster-names.md` carry the ratified decisions the SKILL.md files previously restated informally.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.40] — 2026-08-15

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.40 work shipped in the ADR-0052/0053/0054/0056 attribute-grammar and token-convention breaking wave. See `packages/web-components/CHANGELOG.md#0840--2026-08-15` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.39] — 2026-08-15

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.39 work shipped in overnight board-clear: tiered catalogs complete, modal close root fix, ADR-0025 input conformance, [selected] convergence, nav collapse-on-select, caret family sizing. See `packages/web-components/CHANGELOG.md#0839--2026-08-15` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`references/` touched in this release window** (1 file(s), e.g. `contracts/a2ui-mcp-surface.md`) — carried by the entries above.

## [0.8.38] — 2026-08-15

### Added
- **This plugin's gated scripts now also ship as MCP tools — `adia-mcp factory`, the third `@adia-ai/mcp` server (ADR-0051, gh#1241).** `adia-info`, `record-lint`, `adia-lint`, `adia-scaffold`, `adia-contract-check.mjs`, and `adia-probe.mjs` are vendored VERBATIM into `packages/gen-ui/mcp/factory/vendor/` (sha256 manifest; `npm run build:factory-mcp-assets` regenerates), and four skill files (`shell-selection/SKILL.md`, `data-wiring/SKILL.md`, `token-selection/references/pairing-laws.md`, `pattern-catalog/references/pattern-index.md`) derive the server's doctrine resources. The plugin's files stay the single source — editing any of them now requires re-running the asset build, and `mcp:factory:smoke` (in `npm run check`) fails on drift. Nothing in the plugin's own runtime changes; `.mcp.json` deliberately does NOT gain the factory server here (consumer wiring — the plugin ships in consumer repos).
- **`scripts/adia-probe.mjs` gains an instrumented AA-contrast gate (gh#1259)** —
  the one VerifyProof row QA seats carried as UNMEASURED or hand-computed (the
  #1246 wave's probes 4/5). The probe samples rendered foreground/background
  pairs for visible text nodes (computed sRGB, alpha-composited up to the first
  opaque ancestor background), scores each against WCAG AA (4.5:1 normal /
  3.0:1 large text ≥18pt or ≥14pt bold), and reports pass/fail per pair with
  the sampled values in the existing VerifyProof shape (`gates.contrast`).
  Measured contrast is a blocking gate — a failing pair fails the verdict;
  no-samples degrades to UNMEASURED, and background-image-backed pairs are
  skipped and counted (indeterminate from computed styles — the image-reader's
  judgment). Dependency-free like the rest of the script; selftest extended
  with positive, negative-control, and large-text-threshold fixtures.
  `surface-qa`'s VerifyProof a11y row notes the slice is now probe-measured.

### Fixed
- **`scripts/adia-probe.mjs` hardening (PR #1289 review).** (1) Entry guard: the module exports pure contrast helpers (`srgbChannel` … `buildProof`), yet ran `main()` unconditionally at module scope — any importer launched the CLI and its `process.exit(2)` paths. Now guarded by the repo's canonical-path compare (`realpathSync` both sides, matching `adia-contract-check.mjs`). (2) Playwright resolution: a bare `import('playwright')` searches the PROBE's own ancestors — correct in-app, wrong for a relocated copy (e.g. @adia-ai/mcp's vendored one under an npx cache); on failure it now retries with a resolver rooted at `process.cwd()` (the consumer app) before emitting the install message.
- **`scripts/adia-contract-check.mjs` no longer flags the global HTML `role` attribute as CLASS-5-UNKNOWN (gh#1256).** `role` joins the exact allowlist alongside the existing `aria-*` prefix — host-language globals are never component contract members, and `text.yaml` itself documents `role="heading"` + `aria-level` as the sanctioned semantic-heading path. Selftest gains a text-ui `role="heading" aria-level="1"` regression fixture (now 11 fixtures).
- **`scripts/adia-lint` SHELL-NESTING no longer false-positives on the canonical admin skeleton (gh#1258).** The check counted the literal prefix `<admin-page`, which also matched `<admin-page-header>`/`<admin-page-body>`/`<admin-page-footer>` — so any file with those plus `<admin-scroll>` tripped it. The tag match is now boundary-anchored (`<admin-page[\s/>]`). Selftest gains the canonical skeleton (must stay clean) and a genuinely nested `<admin-page>` negative control (must still fire).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (4 file(s), e.g. `app-planning/SKILL.md`) — carried by the entries above.

## [0.8.37] — 2026-08-14

### Changed
- **ADR-0048 P5 — MCP references re-keyed to `@adia-ai/gen-ui-mcp`** (`README.md`
  tool-SoT path → `packages/gen-ui-mcp/TOOLS.md`, `skills/app-planning` +
  `skills/screen-composition` tool-roster pointers → the new package name and the
  generated TOOLS.md). The `.mcp.json` pin itself is deliberately UNCHANGED and
  still names the retired `@adia-ai/a2ui-mcp`: release invariant 8 pins it to the
  current lockstep version, and `@adia-ai/gen-ui-mcp` has no `0.8.x` on npm, so
  flipping the name before the 0.8.37 cut would pin consumers to a registry 404.
  The name flips in the P7 release commit (`adia-release`'s `cut-procedure.md`
  §The 0.8.37 estate-split cut).

### Fixed
- **`references/contracts/a2ui-mcp-surface.md` gains a `plan_app_state` row (REQ-03, gh#1208).** Companion to `@adia-ai/gen-ui-mcp@[Unreleased]`'s `plan_app_state`/`generate_ui` contract repair (re-landed on `packages/gen-ui-mcp/` after ADR-0048 P2's move) — the consumer-load-bearing subset table now names `plan_app_state`, and notes the `experience.shell` enum's breaking reconciliation with the Orientation Record's own Shell axis. Twin copy in `adia-ui-forge` updated identically. No `.mcp.json` pin bump in this PR — the pinned server version is unchanged; the pin moves at the lockstep cut that publishes this package's `[Unreleased]` work.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`agents/` touched in this release window** (7 file(s), e.g. `agents/app-planner.md`) — carried by the entries above.
- **`commands/` touched in this release window** (7 file(s), e.g. `commands/app-audit.md`) — carried by the entries above.
- **`scripts/` touched in this release window** (5 file(s), e.g. `scripts/adia-info`) — carried by the entries above.

## [0.8.36] — 2026-08-13

Ships in the **next cut**, not 0.8.35 (0.8.35 was already tagged when this landed).

### Added
- **`ui-architect` (gh#1183): the factory's missing foreman/coordinator agent.** Takes a
  whole-deliverable ask — a novice one-line brief through a PRD file expected to be "figured out"
  — and runs it across the existing three seats without duplicating their charters: GEAR 1 (novice/
  vague ask) runs one clarify round (or `adia-orient`'s cited-signal defaults when unattended), a
  single app-planner → screen-builder → consumer-reviewer pass, and hands back the VerifyProof;
  GEAR 2 (PRD/elaborate ask) decomposes the PRD into surfaces/flows and a wave build plan,
  dispatches app-planner per ambiguous surface and screen-builder per screen, and gates every wave
  with consumer-reviewer, iterating on findings until the plan's acceptance holds (generator ≠
  critic maintained throughout). Holds no Write/Edit tool — every deliverable is a sealed dispatch,
  never an inline edit (the team-lead coordination discipline). `model: fable` + `effort: high`
  (Planning ceiling-ladder row).
- Agent roster: `README.md`'s `## Agents` section now lists 4 (was 3) — `check:plugin-count-claims`-
  guarded where applicable.
- `agents/routing-corpus.json` gained 6 trigger cases + 3 explicit no-trigger cases for
  `ui-architect`, scoped to WHOLE-DELIVERABLE asks so it never steals `app-planner`'s lone
  classify/plan territory (measured clean via `eval:agent-routing:factory`, fp=0 against
  app-planner).
- **`adia-probe.mjs` gains an ADVISORY perf row (REQ-06, gh#1200/gh#1211) — realizes ADR-0040's
  ui-verifier "perf" clause at its floor.** The probe now records navigation timing
  (`performance.getEntriesByType('navigation')`) alongside the existing console/box/screenshot
  gates and reports it in every `VerifyProof` against a `--perf-budget-ms` budget (default
  3000ms). Advisory means exactly that: an over-budget page still reports `pass-pending-read` —
  the row never participates in `verdict`. Promoting it to a blocking gate is a later ruling made
  with real budget data, not a guess made here. `skills/surface-qa/references/verification.md`
  and `skills/surface-qa/SKILL.md`'s VerifyProof deliverable document the new `perf` row; the
  selftest gained fixtures proving an over-budget page still ships and a missing-timing page
  degrades to `UNMEASURED` rather than failing.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`references/` touched in this release window** (1 file(s), e.g. `references/a2ui-mcp-tools.md`) — carried by the entries above.
- **`skills/` touched in this release window** (3 file(s), e.g. `adia-compose/SKILL.md`) — carried by the entries above.

## [0.8.35] — 2026-08-13

### Added
- **The consumer-side CI recipe (OUT-05, gh#1136): a documented 4-step verify pipeline that runs headless in a consumer repo with no `gen-ui-kit` access.** `scripts/adia-preflight.mjs` (Node floor, Playwright + browser binary, preview-server reachability — each failure named with its remedy, exit 2 on any gap) and `scripts/adia-contract-check.mjs` (the class-5 gate: authored markup attributes vs. the shipped `custom-elements.json`/`*.a2ui.json` contracts, plus the `table-ui` raw `<thead>`/`<tbody>` rule, gh#924 — the defect class with no gate anywhere until now, gh#1024/gh#982). The full recipe (GitHub Actions + bare `npm run` forms), the minimum plugin version note, and the CI-honesty disclaimer: `skills/surface-qa/references/ci-recipe.md`.
- Validating `adia-contract-check.mjs` against this repo's own shipped demos surfaced that `custom-elements.json` itself is missing real reflected properties for 14+ tags (e.g. `icon-ui`'s `tone`) — filed as gh#1154 (separate, upstream generator defect) and documented as a known limitation rather than fixed here.

### Fixed
- **`adia-scaffold`'s spa/component templates emitted `.js`-suffixed core imports that the published exports map double-resolves (gh#1120/gh#1132)** — `@adia-ai/web-components/core/register.js` resolved to `core/register.js.js` (missing), so a freshly scaffolded app could not boot via its own documented path. Suffix dropped; a real before/after scaffold+install+build proof recorded on the ticket; the selftest now `npm pack`s BOTH published packages and resolves every emitted specifier against the real extracted exports maps (release pre-flight gate 25).
- **Scaffolded SPA CSS never loaded: raw `/node_modules/...` `<link>` hrefs 404'd silently under Vite's SPA fallback (gh#1149)** — the scaffold's `vite.config.js` sets `root: 'src'`, so static-file links miss; templates now import the stylesheet as a bare specifier (`import '@adia-ai/web-components/css'`) from the JS entry that already registers components. `spa-architecture.md`'s inverted "CSS via `<link>`, never via JS import" claim corrected.
- **`adia-scaffold`'s command doc `argument-hint` listed a nonexistent `app` mode and omitted `ssr`/`selftest` (gh#1121)** — now derived-checked against argparse's own choices.
- **`adia-info` swallowed a bare `-h` as a positional path (gh#1122)** — probed a directory literally named `-h` at exit 0; explicit help branch added (and `adia-probe.mjs` gained the same).
- **`adia-lint`'s `_hook()` linted generated/vendored trees (gh#1041)** — `node_modules`/`dist`/`build`/`.next`/`coverage` segment exclusion added, extending its existing segment-check pattern.

- **`adia-lint`'s and `record-lint`'s `-h`/`--help` violated the exit-code contract (gh#1136, REQ-05).** `adia-lint -h` fell through to the no-args branch (docstring fragment, exit 2); `record-lint -h` fell through further into the positional-file branch and crashed with an uncaught `FileNotFoundError` (exit 1, traceback to stderr). Both now exit 0 with a one-line usage string, matching `adia-probe.mjs`/`adia-info`'s existing contract; each selftest gained the corresponding assertion.
- **`skills/token-selection/references/a-alias-layer.md` was missing ~a third of the `--a-*` alias vocabulary it claims to fully map (gh#1068).** The generator (`scripts/release/check-token-semantics-sync.mjs`, framework-side) read only `core.css`; regenerated now that it unions the whole `colors/semantics/` barrel — 305 declarations (was 207), including `--a-data-0..9` and `--a-chrome-light` that the skill's own law 6 and eval `t07` already treated as answerable. Root-cause + fix live in the root `CHANGELOG.md`'s matching entry.

### Changed
- All 7 commands now declare `disable-model-invocation` and `user-invocable` explicitly (gh#1046, house rule: both dials always); `adia-project`'s description gained its routing-corpus-prescribed "WHEN mode/shape are already decided" qualifier (gh#1040).
- Agents: `<example>` blocks moved out of always-resident `description:` scalars into `## Dispatch examples` body headings (gh#1044, ADR/#80); `app-planner` and `consumer-reviewer` pinned `model: fable` + `effort: high` per the ceiling ladder's Planning/Review rows (gh#1045 — the prior sonnet pins borrowed a Coding-row precedent).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.34] — 2026-08-11

### Fixed
- **Top-level `bin/` directory renamed to `scripts/` — claude.ai-hosted plugin validation was rejecting this plugin outright (gh#934).** claude.ai auto-adds any plugin's top-level `bin/` to PATH on the CLI, which isn't shown on the admin approval surface, so hosted validation refused to approve the plugin at all ("2 plugins found, 2 failed validation" alongside `adia-ui-kit-forge`, same defect). `bin/adia-info`, `bin/adia-lint`, `bin/adia-probe.mjs`, `bin/adia-scaffold`, `bin/record-lint` moved to `scripts/` with executable bits preserved; every `${CLAUDE_PLUGIN_ROOT}/bin/...` reference across `hooks/hooks.json`, `commands/*.md`, `agents/*.md`, `skills/*/SKILL.md`, `references/*.md`, and `skills/project-scaffolding/evals/routing-corpus.json` updated to `scripts/...`; `package.json`'s `files` array updated so the published tarball ships the renamed directory. Hooks/commands still fire the same scripts, just from a non-PATH-reserved location.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.33] — 2026-08-11

### Fixed
- **`adia-patterns`' pattern index no longer names components that don't exist (gh#848).** `Agent Memory`'s entry listed `form-container-ui` (no such tag — native `<form>` is the real contract per `registry.js` §45) and `Diff & Review`'s listed `description-detail-ui`/`description-term-ui` (native `<dt>`/`<dd>` per `description-list.yaml`'s own documented contract) — both invented tags the corresponding demo pages had already stopped authoring. `Agent Memory`'s entry also gained `row-ui`, which its demo genuinely composes and the index had missed.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (1 file(s), e.g. `references/pattern-index.md`) — carried by the entries above.

## [0.8.32] — 2026-08-09

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.32 work shipped in component fixes (nav selected states, avatar centering, stat Phosphor arrows, tag solid default, card-table chrome, breadcrumb ellipsis, input min-width) + a2ui eval overhaul (render probe navigates, refine passthrough, Tier-1 plans). See `packages/web-components/CHANGELOG.md#0832--2026-08-09` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (2 file(s), e.g. `references/annotations.yaml`) — carried by the entries above.

## [0.8.31] — 2026-08-07

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.31 work shipped in post-0.8.30 fix wave: double-submit boundaries, list-item render gate, segmented allow-empty + adapter kebab-case booleans, MCP multi-session + idle TTL, feedback signal:none, swatch auto-contrast, tabs strip-gap spacing + vertical clearance. See `packages/web-components/CHANGELOG.md#0831--2026-08-07` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (2 file(s), e.g. `adia-compose/SKILL.md`) — carried by the entries above.

## [0.8.30] — 2026-08-07

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.30 work shipped in agent-harness v1 wave: MCP-client mode, guardrails/tracing/memory hardening, auto engine, chat agent-event rendering, human feedback loop. See `packages/agent/CHANGELOG.md#0830--2026-08-07` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.29] — 2026-08-06

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.29 work shipped in web-components (icon-ui tone prop gh#652) + web-modules (plan-envelope chrome gh#648) + a2ui-runtime (registry drift fix gh#645) + a2ui-compose (plan-turn executor gh#648) + a2ui-corpus (chunk re-harvest). See `0829--2026-08-06` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.28] — 2026-08-05

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.28 work shipped in sideEffects tree-shaking fix + CSS barrel regen (gh#625/632). See `0828--2026-08-05` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.27] — 2026-08-05

### Changed
- **Agent seats pin explicit models** — no seat rides the caller's tier (gh#618, PR #620).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`agents/` touched in this release window** (2 file(s), e.g. `agents/app-planner.md`) — carried by the entries above.

## [0.8.26] — 2026-08-05

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the lockstep version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.26 work shipped in WCH chat-harness wave + genui conformance train; first publish of @adia-ai/agent + @adia-ai/persona. See `packages/web-modules/CHANGELOG.md#0826--2026-08-05` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.25] — 2026-07-31

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.25 work shipped in theme-panel scoped-target [parametric] density/radius fix (gh#570) + System scheme option; anchor-bar-ui; stat-ui band chart layout; chart-ui dots/series-emphasis. See `packages/web-components/CHANGELOG.md#0825--2026-07-31` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (2 file(s), e.g. `references/annotations.yaml`) — carried by the entries above.

## [0.8.24] — 2026-07-30

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.24 work shipped in requiredIcons drift cleared across 16 components + checker comment handling (gh#550), worktree bootstrap workspace-link hardening + retrieval corpus-pin fix (gh#554), list-item two-line icon centering (gh#558), card footer bottom-pinning (gh#559). See `packages/web-components/CHANGELOG.md#0824--2026-07-30` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (2 file(s), e.g. `references/annotations.yaml`) — carried by the entries above.

## [0.8.23] — 2026-07-30

### Changed
- **Plugin renamed: `adia-factory` → `adia-ui-kit-factory`** (gh#520, operator ruling 2026-07-30). The in-repo marketplace renames `adia` → `adia-ui-kit`; the install pattern becomes `adia-ui-kit-factory@adia-ui-kit`. Directory and npm package identity (`@adia-ai/…`) unchanged. A new manifest name means a FRESH install — consumers re-add the marketplace under the new key and re-enable `adia-ui-kit-factory@adia-ui-kit`; old `adia-factory@adia` refs no longer resolve.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (1 file(s), e.g. `references/pattern-index.md`) — carried by the entries above.

## [0.8.22] — 2026-07-29

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.22 work shipped in select-ui aria-selected action-row fix, combobox radio indicator, form-popover summary hardening, resumable release Step 10. See `packages/web-components/CHANGELOG.md#0822--2026-07-29` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.21] — 2026-07-28

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.21 work shipped in card/table/select/form-popover fixes from adia-v2 adoption + three drift gates (gh#473, gh#425, gh#435). See `packages/web-components/CHANGELOG.md#0821--2026-07-28` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (1 file(s), e.g. `references/pattern-index.md`) — carried by the entries above.

## [0.8.20] — 2026-07-28

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.20 work shipped in form/ subpath exports (gh#457) + tarball test-file hygiene, 7 packages (gh#462). See `packages/web-modules/CHANGELOG.md#0820--2026-07-28` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.19] — 2026-07-27

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.19 work shipped in form/ cluster publishes (form-popover-ui installable, gh#448) + select-ui summary-label (gh#442) + row-hover container-ladder token fix. See `packages/web-modules/CHANGELOG.md#0819--2026-07-27` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (1 file(s), e.g. `references/a-alias-layer.md`) — carried by the entries above.

## [0.8.18] — 2026-07-27

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.18 work shipped in form-popover-ui rename + 9-test surface + first passing rendered-dom probe (harness repaired for all composites). See `packages/web-modules/CHANGELOG.md#0818--2026-07-27` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.17] — 2026-07-27

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.17 work shipped in one selection language (radios + tonal + container tier) · form-popover module · check:demo-routes sweep. See `packages/web-components/CHANGELOG.md#0817--2026-07-27` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`skills/` touched in this release window** (4 file(s), e.g. `references/annotations.yaml`) — carried by the entries above.

## [0.8.16] — 2026-07-26

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.16 work shipped in text-on-fill AA (90/90 pairs) + release-gate roster 18→22 + the theming guide. See `packages/web-components/CHANGELOG.md#0816--2026-07-26` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.15] — 2026-07-26

### Added
- **`find-unused` skill + `/find-unused` command** — the consumer-side counterpart to `adia-migrate`, for the span where nothing broke. `adia-migrate` is guide-driven, and the shipped MIGRATION GUIDE documents *breaking* changes only, so a lockstep PATCH span had no procedure beyond "drop-in". Four defect classes live in that blind spot, each with a real instance behind it: an **inert opt-in layer** (`styles/scale.css` shipped v0.8.11 as opt-in — an app can set `[scale]` for two releases with nothing importing the layer, failing silently), a **redundant workaround** (local CSS patching a bug since fixed upstream, now fighting the framework), a **changelog-invisible change** (v0.8.13's collapsed-rail work — PR #407's icon sizes, square hit-boxes and filled selected icons — reached the changelog only as an auto-generated "`components/` touched in this release window" stub, so the skill teaches resolving those stubs against `git log` or the PR), and a **shipped-advice hazard** (`styles/theme-fonts-url.txt` instructs one `<head>` link covering all 23 theme font families — right for a docs site, wasteful where theming is optional, a policy question under a CSP). Fonts, third-party requests, and anything touching persisted user state are classified judgment items that never auto-sweep. Each verification is specified as what *failure* looks like, not "confirm it works".

### Changed
- **`adia-migrate`'s Step 0 no longer dead-ends a PATCH span.** The classification row read "**additive** — drop-in; no code change"; it now reads "drop-in for the API" and hands off to `find-unused`, with a paragraph stating why — "drop-in" describes the API, never the app. Derived from the v0.8.10→0.8.14 span: zero API breaks, three real omissions in a consumer that had upgraded cleanly twice.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).
- **`commands/` touched in this release window** (1 file(s), e.g. `commands/find-unused.md`) — carried by the entries above.
- **`skills/` touched in this release window** (4 file(s), e.g. `adia-migrate/SKILL.md`) — carried by the entries above.

## [0.8.14] — 2026-07-25

### Fixed
- **The documented install command works** (`README.md`; PR #412) — it read `adia-factory@gen-ui-kit`, but the marketplace manifest's own `name` field is `adia`; corrected to `adia-factory@adia`. The same PR relocated that manifest to the repo root, without which `claude plugin marketplace add` could not find it at all (see `adia-forge`'s entry for the mechanism).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.13] — 2026-07-25

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.13 work shipped in 12 named theme identities + select-menu Theme row in theme-panel; fixes scale.css wiring, Preset/Reset UX, and a Theme-select XSS finding. See `packages/web-modules/CHANGELOG.md#0813--2026-07-25` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.12] — 2026-07-24

### Fixed
- **`adia-compose`, `adia-host`, and `references/spa-architecture.md` learn the v0.8.11 size model** — three skills still taught the removed `xs`/`xl` size vocabulary and the deprecated `[verse]`-only density register; following them verbatim would have authored invalid attribute values or wired a host to the wrong opt-in CSS layer. Figma Make guidelines (`adia-compose/assets/figma-make/guidelines/{components,tokens,styles}.md`) now teach `size` as sm/md/lg and introduce the ancestor `[scale]` register (six tiers) alongside `--a-density`; `adia-host`'s SKILL.md cascade order + Host Record template and its `evals/routing-corpus.json` rationale now cite `scale.css` (verse/prose as deprecated aliases); `spa-architecture.md`'s host-document snippet links `scale.css` and demonstrates `scale="ui-sm"`. Stale "127 primitives" counts corrected to 125 in the same pass.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.11] — 2026-07-23

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.11 work shipped in sm/md/lg size model + ancestor [scale] context; adia-wordmark-ui; forge release-cycle hardening. See `packages/web-components/CHANGELOG.md#0811--2026-07-23` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.10] — 2026-07-20

### Added
- **`adia-charts` knowledge skill** (`skills/chart-selection/`; gh#381) — which component to use for which chart/graph/sparkline/gauge/heatmap need, data binding, legend wiring, and theming, grounded in `chart-ui`/`chart-legend-ui`/`heatmap-ui`'s real prop surface. Sibling to `adia-patterns`/`adia-tokens`/`adia-shells`. `chart-legend-ui[for]` auto-mirrors `chart-ui` only (verified `heatmap-ui` never populates `.legendData`/dispatches `legend-update`, despite a stale docstring elsewhere claiming otherwise); `heatmap-ui` is included as a genuine chart-family member (`chart.yaml` itself routes density-grid asks there).
- **`adia-tables` knowledge skill** (`skills/table-composition/`; gh#382) — contained vs. uncontained/bleed chrome, `[raw]` (a separate axis from data-driven rendering — see the `@adia-ai/web-components` gh#385 fix), striped rows (opt-in, not default — corrects a stale assumption in the original ticket), column resize/sort (opt-out for JS `.columns`, opt-in for declarative `<col-def>` — the two forms have opposite defaults), and the inline-edit-grid + tree/hierarchical-row patterns. `list-window-ui` named as the escape hatch for 1,000+-row collections.
- **`evals/evals.json` behavioral test-case files for 15 skills** (gh#369) — the file `release_gate.py`'s G7 coverage check actually reads (a schema distinct from `evals/routing-corpus.json`). Derived from each skill's already-vetted `routing-corpus.json` phrases where genuinely good behavioral tests, with real judgment applied rather than a mechanical paste (independently reviewed, sampled across both plugins).

### Fixed
- **`evals/routing-corpus.json` unified onto one schema across all skills** (gh#355) — converged the two mutually-incompatible per-skill corpus shapes (forge's `{positives,negatives}` vs. factory's `{phrases}`) onto the `{phrases:[{id,phrase,expected,expected_shape?,rationale?}]}` shape `scripts/skills/run-skill-evals.mjs` already reads, since that's the one in-repo runner that actually exercises these corpora. Fixed 4 missing `.agents/skills/` symlinks that blocked discovery entirely, independent of schema (`adia-site-docs`, `adia-ssr`, `adia-audit`, `adia-patterns`). Coverage: 97 reachable phrases (8 skills invisible) → 572 phrases across all 22 skills existing at the time.
- **`adia-patterns`: routes are a client-rendered SPA — never plain-fetch** (`skills/pattern-catalog/SKILL.md`; PR #362) — a non-browser fetch of any `ui-kit.exe.xyz` route returns the identical loading shell whether the path is valid or not, so `WebFetch`/`curl` can't distinguish a live route from a dead one. Documents the file-resolution alternative (`node_modules` install, or a monorepo checkout).

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.9] — 2026-07-19

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.9 work shipped in select-ui mark visual (gh#339); release-tooling hardened (branch creation, settle-wait poll, pr-bridge draft guard). See `packages/web-components/CHANGELOG.md#unreleased` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.8] — 2026-07-19

### Maintenance
- **Lockstep version bump only.** No source changes in this package; bumped to maintain the 11-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.8 work shipped in Type scale tightened one step (body 14px / ui 13px base); release machinery hardened (pr-bridge, mechanized pins, single-sourced roster). See `packages/web-components/CHANGELOG.md#088--2026-07-19` for details.
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.7] — 2026-07-19

### Added
- **`adia-audit` skill** (`skills/app-audit/`: `SKILL.md`, `references/{correction-loop,gap-classes,rubric,triage-model,defensible-feedback}.md`, `evals/routing-corpus.json`; PR #323) — brownfield consumer-repo diagnosis the factory lacked: the 60-second recon, the four-layer triage (skill/codebase/substrate/spec) with the Light-DOM zeroth question, the five-phase Correction Loop, the four gap/drift classes, and the seven-section diagnostic report + rubric. Fenced against `adia-migrate` (mechanical sweep only) and `adia-orient` (greenfield classification only) — neither root-causes a wrong-output symptom in an existing repo. Routes handoffs to `adia-migrate`/`adia-compose`/`adia-shells`/`adia-verify`; the a2ui MCP is the live source of truth, not a vendored catalog map.
- **`references/agentic-ux-patterns.md`** (new, wired into `adia-genui`; PR #323) — the six agentic UX patterns (intent preview, autonomy dial, explainable rationale, confidence signals, action audit/undo, escalation) mapped onto concrete AdiaUI primitives, plus the mental-model-first rule.
- **`references/composed-surface-rubric.md`** (new, wired into `agents/consumer-reviewer.md`; PR #323) — the two-axis COMPOSE/REALIZE defect-quadrant rubric scoring whether a surface was composed *right* (intent fidelity, primitive correctness, pattern/shell fidelity, state wiring) and realized *right* (token discipline, verify closure, content-trust), with a no-cross-axis-compensation rule and three `[gate]` dimensions hard-required. `consumer-reviewer` now runs this as its composition-quality lens, distinct from its existing VerifyProof render gate.
- **`adia-patterns` skill** (`skills/pattern-catalog/`: `SKILL.md`, `references/{annotations,pattern-index}`, `evals/routing-corpus.json`; PR #325) — a 107-entry index (45 patterns + 62 template screens) over `site/sitemap.json`, drift-gated by `scripts/build/patterns-index.mjs` against a hand-authored category/intent/keyword layer. `adia-compose` gained a reuse-before-compose precondition gate; `adia-orient`'s task table routes here first. `@adia-ai/web-components` now ships `patterns/` in its published `files` so a consumer install resolves pattern source from `node_modules`.

### Changed
- **Agents renamed to registered role suffixes** (`agents/{app-planner,screen-builder,consumer-reviewer}.md`, `agents/routing-corpus.json`; `app-architect`→`app-planner`, `screen-composer`→`screen-builder`, `consumer-verifier`→`consumer-reviewer`) — the `-architect`/`-composer`/`-verifier` suffixes aren't in the third-party forge harness's registered role set (D9 gate), same rename class as the forge-plugin agents in gh#268. Added "Use when/to" trigger phrasing (D1). Every live cross-reference re-keyed (both plugins' routing corpora + `a2ui-mcp-surface.md` contracts, README, the `commands/adia-verify.md` command doc, `adia-orient` SKILL.md). All 3 agents pass `harness_checks` 5/5.
- **`skills/screen-composition/references/spec-to-ui-reasoning.md`** (PR #323) — a "requirements traceability" section: the QA-engineer test for what counts as a requirement, stable-ID/never-renumber discipline, and a pre-proceed validation checklist, so a wireframe region traces to a `REQ-NN`, not a paraphrase. Plus a mental-model-first rule at rung 1 for agentic surfaces, cross-linked to `agentic-ux-patterns.md`.
- **`adia-host`** (PR #323) — icon-loader wiring (entry-relative glob + bold weight; the gh#287 silent-blank failure), the per-cluster-vs-per-component module barrel trap (AdminSidebar toggle dies on the wrong subpath) with the single-segment shell-CSS path (gh#296), and the CDN/HTML-first consumption path (single bundle, no dup-define) — the skill previously had zero icon or CDN content.
- **`skills/shell-selection/references/shell-admin.md`** (PR #323) — a chrome-tier vs content-tier allocation table + four allocation anti-patterns (e.g. a page CTA in the topbar sticking across every route) — the skill previously taught pick/nest/register but not what lives in which region.
- **`README.md`** (PR #323) — skills 10→13, agents 2→3, a new plugin-root references section, the MCP pin refreshed 0.7.26→0.8.6, version footer.
- **`skills/screen-composition/references/spec-to-ui-reasoning.md`, `composition-traps.md`** (PR #326) — restored the INCORRECT worked wireframe example (tag vocabulary leaking = premature component collapse); added five composition gotchas (stat-ui-vs-input-readonly semantic trap, divergent control default heights, per-section `bleed` split for toolbar+table, display-toggle clobbering `:scope` flex, `minmax()`-vs-container-query overflow).
- **`skills/screen-composition/references/meta-surfaces.md`** (new; PR #326) — the operator-facing inspection-surface pattern class (galleries, eval browsers, audit dashboards): six rules, stated by token role.
- **`skills/data-wiring/SKILL.md`** (PR #326) — shared-drawer per-row `hydrate` CustomEvent pattern; four-state (default/loading/empty/error) region-coverage discipline.
- **`skills/app-audit/references/defensible-feedback.md`** (new; PR #326) — four-bucket framework-bug/gap/consumer-miss/third-party classification, verified-exclusions discipline, per-finding structure, sniff tests for filing upstream `gh issue`s.
- **`bin/adia-info`** (PR #326) — offline split-lockstep detection (`installedAdiaVersions`, `splitLockstep`, always on) and an opt-in `--staleness` npm-latest compare (never default — the probe feeds skill-load context injection and must stay offline-fast).
- **A2UI/GenUI terminology detangle** (`skills/{adia-verify,adia-patterns,adia-genui}/SKILL.md`; PR #329): adia-verify's routing line now distinguishes live/runtime-generated markup validation (`adia-genui`) from build-time compose output (validates inside `adia-compose`'s own loop); adia-patterns' Gen-UI Feed exclusion is attributed to `adia-genui`'s runtime pattern instead of "the a2ui pipeline"; adia-genui's `<gen-root>` chat-mode table row notes the chat half is wired by `adia-llm` (canvas half only), matching the skill's own NOT-for carve-out.

### Fixed
- **`skills/screen-composition/references/composition-traps.md`** (PR #326) — corrected two false claims from the initial harvest: `<search-ui>` DOES forward its `size` attribute to the inner input (verified against `search.class.js`); `tag-ui`'s default size is `md`, not `sm` (verified against `tag.yaml`).
- **`skills/data-wiring/SKILL.md`** (PR #326) — `<empty-state-ui heading action>` corrected; `action` is a slot, not an attribute (`empty-state.yaml`) — a literal attribute would silently no-op.
- **`references/shell-editor.md`** (PR #326) — the `<editor-canvas>` zoom row corrected: shell CSS already scales every direct child (`editor-canvas > * { transform: scale(...) }`); the real gotcha is a host adding its own `scale()` and double-scaling nested content.

### Maintenance
- **`.claude-plugin/plugin.json` version bump** — moves in lockstep with package.json (the `/plugin update` cache key).

## [0.8.6] — 2026-07-18

### Changed
- **`agents/routing-corpus.json` re-keyed to the renamed forge seats** (gh#268 W0, PR #312): prose notes referencing `a2ui-engineer`/`release-engineer` updated to `a2ui-builder`/`release-builder` after the forge plugin's registered-role rename.
- **`skills/token-selection/references/a-alias-layer.md` re-synced** (PR #316): the `--a-ui-bg-selected` token repoint (gh#307) had drifted this generated reference from its source; regenerated via `check:token-semantics-sync`, no hand edits.

### Maintenance
- **Lockstep version bump only** (`.claude-plugin/plugin.json` version field). No source changes in this package; bumped to maintain the 9-package version coherence enforced by `scripts/release/check-lockstep.mjs`. Substantive v0.8.5 work shipped in gemini production passthrough + hardening (@adia-ai/llm), SSR browser-API guards + gh issue 276 wave-4 button-ui/option-card-ui migrations (@adia-ai/web-components), admin-sidebar SSR collapse fix (@adia-ai/web-modules), kbd-ui A2UI-render fix (@adia-ai/a2ui-runtime), full chunk/embeddings regen (@adia-ai/a2ui-corpus). See `packages/llm/CHANGELOG.md#085--2026-07-17` for details.

## [0.8.4] — 2026-07-16

### Fixed
- **Agent-eval records reconciled** (`agents/consumer-verifier.md`, `agents/routing-corpus.json`, `skills/surface-qa/SKILL.md`; PR #273, landed after the 0.8.3 tag): the routing corpus's `expected_baseline` re-measured at 60.6% with the floor marked ADVISORY and attribution recorded; consumer-verifier's VerifyProof record language aligned with the measured state.

### Maintenance
- **Exact `.mcp.json` pin** — `@adia-ai/a2ui-mcp@0.8.4` (invariant 8: the consumer never floats). Substantive framework v0.8.4 work shipped in @adia-ai/llm, @adia-ai/web-components, @adia-ai/web-modules — see `packages/llm/CHANGELOG.md#084--2026-07-16`.

## [0.8.3] — 2026-07-16

### Added
- **`adia-tokens` knowledge pack** (`skills/token-selection/`, gh#265): the consumer-facing "which color token/role" answerer — role grammar + the six pairing laws (incl. the fill-contrast operator ruling), the `--a-*`-vs-Material layer choice, and two cut-time-GENERATED references (the 8×53 role roster and the full 206-row `--a-*` → Material bridge table), regenerated + CI-gated from the framework token sources so the corpus cannot drift. Routing evals included; `adia-compose` routes token questions here.
- **`skills/llm-wiring` verify-gates table + debugging catalog**: the key-in-client gate now cites the `adia-lint` rule that mechanizes it; a source-grounded symptom→cause table headlines the two runtime traps whose docs Wave 0 corrected (`Unknown provider "google"` throw; `GEMINI_API_KEY` vs `GOOGLE_API_KEY`).

### Changed
- **`commands/` refreshed to the post-campaign estate**: `/adia-verify` dispatches the read-only consumer-verifier seat (generator ≠ critic); NEW `/adia-info`; `/adia-migrate` carries the shipped-guide path + consent options; `/adia-scaffold` surfaces inventory mode; `/adia-genui` closes with the Generation Record.

### Maintenance
- `.mcp.json` a2ui-mcp pin → 0.8.3 (invariant 8); `packages/plugins/adia-ui-factory/.claude-plugin/plugin.json` moves in lockstep (the `/plugin update` cache key).
## [0.8.2] — 2026-07-16

### The modernization campaign (gh#259, Waves 0–3 + the command refresh)

An operator-directed, 10-auditor-baselined overhaul of the whole plugin. By area:

- **`skills/` — factual corrections (Wave 0):** the documented `GOOGLE_API_KEY`/provider-`google` forms (which throw at runtime) corrected to `GEMINI_API_KEY`/`gemini`; `shell-admin.md`'s four fabricated host methods replaced with the real delegation contract; the chat barrel's missing `<chat-input-ui>` registration documented with the real-usage citation; the raw-`<header>` gotcha retracted (source CSS treats both forms identically); adia-orient's drift-prone MCP-pin literal replaced with a live probe-field citation; adia-data's phantom "adia-verify gates these" claim corrected.
- **`skills/*/evals/` — eval coverage (Wave 1):** 10 per-skill routing corpora (214 phrases, both-direction boundary coverage, undecidable phrasings excluded-with-reason); genui/llm fence fixes.
- **`skills/` + `bin/` — typed contracts + mechanization (Wave 2):** every skill now names its deliverable (Wiring Record · Migration Report with per-cluster consent slots · ShellComposition · Generation Record · Host Record · VerifyProof with a mandatory imageRead slot); NEW `bin/record-lint` (Orientation Record gate) and `bin/adia-probe.mjs` (the shipped browser gate); `bin/adia-scaffold inventory` mode scores the structure rubric; `bin/adia-lint` +5 rules (shell nesting/resize, LLM key-in-client, genui validate/feed-path); all bin selftests CI-cast.
- **`agents/` — the reviewer seat (Wave 3):** NEW `consumer-verifier` card — the QA seat un-folded from screen-composer (generator ≠ critic), read-only, returns the VerifyProof; agent routing corpus +5 phrases.
- **`commands/` — refreshed to the post-campaign estate:** `/adia-verify` dispatches the consumer-verifier seat (inline skill = mid-build self-check only); NEW `/adia-info`; `/adia-migrate` carries the shipped-guide path + consent options; `/adia-scaffold` surfaces inventory; `/adia-genui` closes with the Generation Record.
- **`references/` — provenance:** shipped-guide acquisition path, v0.8.0 judgment classes, [D]-claim date stamps, divergent verification.md copies deduped.

### Maintenance
- **`.mcp.json` a2ui-mcp pin → 0.8.2** (release invariant 8) and `packages/plugins/adia-ui-factory/.claude-plugin/plugin.json` version → 0.8.2 in lockstep (the `/plugin update` cache key).
## [0.8.1] — 2026-07-15

### Added
- **`bin/adia-info`** — consumer-repo context probe (python3 stdlib, 3-fixture selftest): declared vs installed `@adia-ai/*` versions, rendering-mode/framework signals (the same signals adia-orient's classifiers cite), shells in use, registration files, theming knobs, a2ui MCP pin, and a framework-monorepo misroute flag. Injected at skill load in `skills/screen-composition` + `skills/app-planning` via dynamic context (validated empirically in the live harness — plugin-skill execution, project cwd, `${CLAUDE_PLUGIN_ROOT}` substitution all confirmed).
- **adia-compose:** field → decision map for the injected context; six inline correct/wrong pattern pairs (every prop verified against the component yaml); need → primitive selection table for the routinely ambiguous picks.
- **adia-migrate:** enumerated per-cluster sweep consent (sweep / show-diff / skip / manual); blanket approval never covers judgment items; locally-deviated files get a diff, never a blind regex.

### Fixed
- **adia-orient:** the embed row claimed no embed module ships — `<embed-shell>` ships in web-modules/shell (defined + tested); a2ui-mcp version mention updated to track the plugin's `.mcp.json` pin.

### Maintenance
- **`.mcp.json` a2ui-mcp pin → 0.8.1** (release invariant 8 — the consumer never floats).
- **`packages/plugins/adia-ui-factory/.claude-plugin/plugin.json` version → 0.8.1** in lockstep with package.json (the `/plugin update` cache key).

## [0.8.0] — 2026-07-15

### Changed — joins the @adia-ai lockstep (policy change, operator ruling 2026-07-15)
- **Version jumps 0.1.0 → 0.8.0 to adopt the lockstep version line** (same policy change as adia-forge — see that CHANGELOG; npm previously served the pre-harness-reset `adia-ui-factory@0.2.4` content).
- **`.mcp.json` pins `@adia-ai/a2ui-mcp@0.8.0`** (release invariant 8 — with the plugins in lockstep this pin now bumps mechanically every cut).
- **Token teachings updated for the v0.8.0 Material color-token adoption** — `component-model`, `composition-traps`, and the Figma-make token guidelines no longer teach the removed `--a-accent-*` vocabulary; the stale "accent-fg resolves near-black" rationale corrected.
- **npm consumers jumping from `adia-ui-factory@0.2.4`:** this version also delivers the full harness-reset estate rewrite documented under `[0.1.0]` below — the `skills/`, `agents/`, `commands/`, `hooks/`, and `references/` trees plus `.mcp.json` were all replaced wholesale (design: `.claude/docs/specs/plugin-estate-v2.md`). Read `[0.1.0]` for that scope; `[0.8.0]` adds only the items above.

## 0.1.0 — 2026-07-10

Initial cut, replacing `adia-ui-factory@0.2.4` (harness reset Phase 2;
design: `.claude/docs/specs/plugin-estate-v2.md`).

- 13 skills → 10: the 442-line `adia-ui-kit` monolith dissolved into the
  sibling family (its §SpecToUi gate → `adia-compose`; knowledge → plugin
  references; figma-make + feedback templates → assets; team-scaffold assets
  retired); `adia-ui-migration` deleted (superseded by `adia-migrate`);
  `spa`+`ssr` merged into `adia-host`; `adia-data`/`adia-llm` re-specied as
  model-only knowledge.
- The ~4,900-char `trigger:` keyword dump deleted (it gamed the local TF-IDF
  eval, not the real router); descriptions ≤350 chars; both dials explicit.
- Agents thinned to shells with `skills:` preloads; the Orientation Record
  schema moved into `adia-orient` (single source).
- MCP pin bumped 0.7.21 → 0.7.26; `references/contracts/` added (consumer
  side of the MIGRATION GUIDE + MCP-surface contracts).
