Portable agent handoffs, honest run outcomes, and a hardened Nano
Continue agent work across models and machines, trust that stopped or failed runs never look finished, keep ATS honest about what it cannot source, and build on a stronger Nano with enforced risk limits and deterministic receipts.
- ▸ Cross-model, cross-machine session handoffs — no repasting the conversation
- ▸ Stopped, failed or incomplete Aether Code runs can never appear finished
- ▸ ATS stops asserting health, prices and balances it cannot source
- ▸ Nano: enforced risk limits, deterministic receipts, 55 strategies, 40 kernels
- ▸ Vault, billing and capacity failures now fail closed instead of reading as empty
What changed
· noteThis release covers code merged to the product repositories through the 1.0.98 desktop build. A few foundations remain behind flags, require deployment, or need a separate package-release step — each is called out below.
Aether Agent
+ addedCross-model and cross-machine handoffs. Aether Agent exports a compact session handoff and continues the same task on another model, computer, operating system, or repository checkout without restating the work. The handoff carries the task, prior model, verification result, changed files, repository identity, branch, commit and test command — never file contents, shell history, or credential-shaped values.
+ addedSkills and capability foundation: the trusted skill runtime, instruction resolver, capability matrix, provenance-aware AGENTS.md handling, and a redacted support-bundle foundation. Skill trust is content-bound, so modifying a trusted skill invalidates that trust rather than silently preserving authority for changed code.
+ addedA shell-free pull-request primitive that uses your existing GitHub CLI session. It can open a pull request and nothing more — no authority to merge, force-push, push to the default branch, or smuggle model-authored text through a shell.
+ addedAll seven release canaries now run automatically: denied filesystem mutations, process-tree cancellation, reconnect replay, remote-base freshness, UVT-cap continuity, pull-request safety, and parity between the Python and Ollama brain paths.
× fixedRepository mirrors are validated against the requested remote and fetched before work begins. New worktrees pin to the exact fetched revision, and Aether refuses to start when it cannot prove the remote base instead of quietly branching from a stale checkout.
× fixedCtrl+C stops local model turns correctly. Shell and test commands run asynchronously, keep the interface responsive, and terminate the full child-process tree on timeout or cancellation instead of leaving orphaned test runners behind.
× fixed/limit is a real local stop boundary based on server-reported UVT usage. Replayed completion frames no longer double-count spend, and a session with no authoritative usage signal reports unknown rather than pretending it consumed zero.
× fixed/rollback and /revert now state whether files return to their staged state or their last committed state. Arguments that were previously accepted but ignored are refused, instead of creating a false impression of step-based rollback.
× fixedOllama tool results are correlated to the exact tool-call ID that requested them, schemas are generated from the same definitions the host validates, and unsupported pause, resume or steering requests are reported rather than silently discarded.
× fixedStartup no longer blocks on an unbounded git status. A very large or slow repository can no longer hold the command line hostage before you get a prompt.
× fixedOllama's own OLLAMA_HOST format is accepted as written, and the request timeout stays armed through the response-body read instead of expiring at the headers — so a stalled local model surfaces as a timeout rather than an indefinite hang.
× fixedThe dev-session client checks the protocol version the Cloud server actually answers with, rather than assuming the version it asked for was honoured.
· noteAether Agent 0.2.0 — package, release notes, install verification and positioning — is prepared, and the install documentation now describes only what installs today. Publishing the GitHub and npm release remains a separate release action.
Aether Code and Desktop
+ addedA visible Stop control while an agent is working, and unified project search in the command palette across files, changed files (with a change badge) and other projects on your account. Changed files are not duplicated, and project entries open the project directly.
+ addedThe Coder IDE editor moves to Monaco 0.56, bringing the current editor engine, its language services and its accessibility fixes to Aether Code.
× fixedHonest agent-run outcomes. Stopped, failed, aborted, stale or incompletely closed runs stay visibly stopped or failed, and success requires a real terminal completion frame. Queued prompts clear when a run is stopped, stale callbacks cannot overwrite a newer run, and voice-run failures settle exactly once.
× fixedA terminal process that exits while its panel is closed returns as a dismissible record with its final output and exit state, instead of disappearing silently or reappearing as a fake live terminal backed by a dead process.
× fixedCoder IDE production hardening: safer navigation for preload-enabled windows, full descendant-process cleanup, SSH-session pruning, consistent path handling across Windows and Linux, blocked Windows device-name edge cases, safer downloaded-skill temporary storage, correct trashed-project behaviour, and a project registry that survives restart. Corrupted desktop state is quarantined for recovery rather than crashing startup or silently replacing your project history with an empty registry. The known-failure allowlist is now empty.
ATS
+ addedThe options chain renders the greeks it was already receiving — delta, gamma, theta, vega and rho — and where a provider publishes none, the surface names that provider instead of showing a blank column that reads as zero.
+ addedPlans are editable in place. The proposal builder previously did no more than append and remove a leg; an operator can now adjust a plan without rebuilding it from scratch.
+ addedQuote snapshots carry the top of book. Bid, ask, volume and previous close were already validated by the sanitizer and then dropped before reaching the renderer; the market surfaces and the scanner now receive them.
+ addedBounded strategy evaluation state is observable end to end — exposed by the brain and rendered on the proposal board — so an evaluation that is still bounded is visibly bounded rather than silently pending.
+ addedFlow observability you can act on: a per-family Discord funnel report that separates transport from generation, so a quiet alert family can never collapse into "Discord isn't working"; a signal-quality against delivery-quality disposition for the alert pipeline; a sector baseline warmer with an honest cold-state report; and BaselinePhaseCoverageV1 with bounded backfill error evidence.
× fixedThe terminal stops asserting health, performance and price movement it cannot source. On a first launch with nothing connected, unreached fields previously rendered the design artifact's sample data as real market claims, real results, and real execution safety.
× fixedAn unreadable trading account is no longer drawn as a zeroed one. A failed broker read reported a calm, complete, fully-zeroed ledger — $0.00 headline, $0.00 realized, zero trades — which is indistinguishable from a real empty account.
× fixedEvery SIM and LIVE word on the account surface derives from the account's actual execution_environment field, rather than five separate places guessing or trusting a server-supplied string.
× fixedThe Chart window has no engine behind it, so it stops rendering as a healthy chart. The default Trading desk opened with a blank white rectangle under a header confidently reading SPY · 15m · TradingView; that was the window's entire ready state.
× fixedThe integrity banner stops burying the window it describes. A terminal starting with nothing connected reported four unavailable surfaces within a second and stacked a full card for each over the Watchlist, covering it completely.
× fixedThe FOCUS cockpit has somewhere to go: the NEXT ACTIONS footer controls are wired instead of gated on props the terminal never passed.
× fixedAn all-zero session is not a distribution. A warmed baseline held keys whose stored sessions were entirely zero, which produced a false p100 — a window pointing the other way, or carrying no resolved aggressor side, wrote a zero that then read as a maximum.
× fixedOne bad sector roster no longer unresolves all 27 universes, and a missing universe now says why it is missing instead of appearing merely unfinished.
× fixedA baseline whose sessions were all excluded is reported as what it is, not as healthy coverage.
× fixedUS equity sessions follow the actual America/New_York timezone instead of a frozen winter UTC offset, so regular and extended-hours windows stay correct through both EST and EDT.
× fixedA crossed indicative book received while the venue is known to be closed is rejected as a venue-state record instead of latching the entire market feed. Crossed books during an open market, or when market state is unknown, remain fatal integrity failures.
× fixedStartup grace ends only after the feed produces a genuinely current quote — an empty internal queue no longer implies the external provider has caught up to live time. A single delayed quote revokes its own evidence without killing the runtime; the feed still fails closed when staleness becomes sustained, and a stale quote can never authorize an order or produce valid execution evidence.
× fixedJournal retention reclaims disk space: the production path now securely shreds expired journal keys and disposes of permanently unrecoverable ciphertext, so expired sealed partitions can be removed while custody receipts and auditor-readable evidence are preserved. Large purges stream — multi-gigabyte partitions are verified and rewritten incrementally rather than loading a full trading day into memory.
Aether Online and Cloud platform
× fixedA storage failure is not an empty vault. Four separate failure paths reported an outage as a successful empty answer, so an object-storage incident was indistinguishable from a vault with nothing in it.
× fixedFork ciphertext gets a durable bucket. Every fork's encrypted vault snapshot and every staged edit had been living in a process-local dictionary intended for tests, and a merge is now all-or-nothing rather than partially applied.
× fixedYour memory graph is keyed on the vault storage id rather than your claimed social handle, so ownership of a memory graph no longer follows ownership of a username.
× fixedA charge's idempotency key identifies the charge instead of the second it happened in. Two charges landing in the same second collided, and the collision returned a balance rather than an error — which silently stopped billing instead of failing loudly.
× fixedA gate that reserves a concurrency slot now hands it back. The shared model gate acquired a task slot that counted against your concurrency cap and then discarded the handle needed to release it.
× fixedDev accounts show an explicit unlimited UVT entitlement, and their model catalog is built from the same tier already enforced for their requests, across Design, Chat, Code, Creator, Presets and the shared workbench rail.
× fixedModel routing tells the truth: the DeepSeek V4 Flash mapping points at the current model and pins its non-thinking transport mode explicitly, and plan tier is preserved through every orchestrator fallback path so entitlement filtering cannot be bypassed by a fallback.
+ addedFaster online surfaces. Vault links are fetched in one batch instead of one call per project, opening a single project reads that project instead of the entire repository list, responses support conditional GET, and the account-link call stops rewriting an unchanged link and re-preflighting on every route transition.
Predator
+ addedThe deterministic autopilot core — targets, policy, triage and a scan ledger — plus exact-SHA checkout and a deterministic replay adapter, so a scan result is bound to the precise revision it was produced from and can be replayed rather than re-argued.
MCP and platform
× fixedMCP OAuth startup repair: the server resolves its Supabase client when the client is actually accessed, instead of permanently capturing an unavailable value during early startup. This removes a mount-order failure that made healthy OAuth infrastructure answer 503 temporarily_unavailable. The MCP feature remains deployment-gated and should be re-enabled after the repaired build is deployed.
× fixedThe MCP broker's credential deny-list is actually installed on the logging path it was written for, and the summary handed back to callers is redacted through the same control.
× fixedRepeated authenticated requests to closed developer or feature-gated routes are now bounded before they repeatedly trigger expensive dependency and identity resolution. Accepted traffic keeps its existing limits, unauthenticated webhooks and health paths are unaffected, and no authorization gate is bypassed or weakened.
Nano
+ addedDeterministic Watchdogs: a dedicated profile with declared input contracts, bounded PAUSE and OBSERVE intents, input-availability handling, content-addressed artifacts, reproducible receipts and receipt-driven replay. Watchdogs cannot reach the network, perform external actions, or bypass a host-owned decision gate.
+ addedCanonical run receipts through one versioned, byte-stable serializer. Replay verification compares canonical bytes, detects type-level drift that ordinary Python equality misses, and reports the exact path where a result changed.
+ addedAn expanded library: a deterministic SuperTrend implementation and SuperTrend-flip strategy, 12 native Nano IR 1.0 strategies across trend, momentum, mean reversion, volatility and volume, and a curated G3 pack adding a volume-confirmed prior-channel breakout and a volatility-percentile Bollinger reclaim. Each ships a firing case, a no-fire case, deterministic replay coverage, regime assumptions, invalidation conditions, and explicit boundaries on what it cannot claim.
+ addedA deterministic strategy and Watchdog catalog, with CLI commands to list, show, search, filter and check library entries against the same generated catalog hosted consumers use. New temporal indicators — BARS_SINCE, COUNT_TRUE, RISING, FALLING, PERCENTRANK — bring the deterministic indicator registry to 40 kernels.
+ addedDifferential fuzz testing across compiler, IR, runtime, receipt, catalog and risk-gate campaigns over the full library, checking valid programs, single-mutation invalid programs, semantic-equivalence groups, multiple hash seeds, multiple references and parallel execution.
+ addedThe language reference is executable. It is written against landed parser, checker, codegen, dual-loader, VM, risk, receipt, provider, route and indicator behaviour, carries end-to-end specification fences that run, documents all 40 shipped indicators, and explicitly excludes anything unshipped.
× fixedThe risk block now actually enforces behaviour: actuating intents are suppressed when declared daily-loss, drawdown, order-count, consecutive-loss or confidence limits are breached. Missing or invalid risk measurements fail closed, while PAUSE and OBSERVE are never suppressed, so a breaker cannot silence itself.
× fixedThe compiler rejects source that would produce unloadable IR, repeated role bodies, invalid scalar parameters, oversized integer literals or non-finite numbers. Canonical receipts gained deterministic complexity limits for integer size, nesting depth, Unicode keys and failure reporting.
· noteNano package metadata advanced through the series to 1.0.12.
Aether Actions
+ addedA design-partner onboarding page for repositories that require an assurance profile before using Aether Actions. It states what Aether needs, what the product does today, what is not yet self-service, and that customers must never provide repository credentials or secrets.
Agentic Loops
+ addedLOOP-22, a website growth and simplification loop covering technical SEO, crawlability, content quality, information architecture, accessibility, performance, reliability, conversion paths and generative-retrieval readiness. It requires current evidence, reversible changes, explicit approval gates, and real post-deployment observation before any traffic or ranking claim.
+ addedMachine-checked loop contracts: a validator and CI workflow enforcing loop metadata, required sections, safety boundaries, portable paths, composition references, documentation coverage and valid internal links. The contributor guide, issue forms and pull-request template now give a clear path for proposing, testing and reviewing loops.
Web and documentation
+ addedThe company site now presents a five-layer product architecture — Work, Orchestrate, Secure, Trade and Verify — with product roles and maturity aligned to the current surfaces, and explicit evidence boundaries around deterministic execution, verification and early research.
× fixedThe Aether Agent card describes the agent that exists today: superseded model names corrected and shipped commands, including MCP connect and diagnose, no longer listed as forthcoming.
× fixedPublic repositories, package metadata, badges, security links, issue links, CODEOWNERS and documentation moved from the retired DBarr3 namespace to the canonical AetherAI3 organization. Installation commands for packages not yet on PyPI were replaced with repository install paths that work today, and the public terminal package name was corrected to aether-agents so it is not confused with an unrelated npm package.
× fixedThe ATS-DB GitHub Pages link is reachable again, AntiFlock's CI and container toolchain moved to Go 1.26.6 clearing six standard-library vulnerability findings, and the August 13 Members and Voice entry was restored to the release-notes archive.