This release fixes issues for SREs watching stability and regressions.
Published 6d
Developer Productivity
✓ No known CVEs patched
✓ No known CVEs patched in this version
Topics
ai-coding-assistant
archetype
ast-analysis
claude-code
claude-plugin
code-conventions
+12 more
code-review
code-style
developer-tools
javascript
linter
mcp
mcp-server
prompt-engineering
python
ruby
rails
typescript
Affected surfaces
auth
Summary
AI summaryFixed /chameleon-journey to require confirmation before starting a billed run.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
/chameleon-journey now asks before starting a billed run. /chameleon-journey now asks before starting a billed run. Source: llm_adapter@2026-07-20 Confidence: medium |
— |
Full changelog
Fixed
/chameleon-journeyasks before spending. The skill documented the cost (~$38, ~65 min, $40
cap) but its Run section went straight to the spawning command, with no step that puts the
decision to the user -- so a bare/chameleon-journeycould start an hour-long billed run
unprompted. That contradicts the project's own testing policy, which says of this exact harness:
"Run before a release, not on every/qa. Ask before spending." The skill now requires a free
--dry-runpreflight, a stated projection, and an affirmative confirmation before the first
Claude-spawning command;--dry-runand--liststay ungated, and an explicit authorization in
the user's own message still skips the prompt. Found by driving all 14 slash commands as real
headless sessions.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Chameleon
All releases →Beta — feedback welcome: [email protected]