This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+8 more
ReleasePort's take
Moderate signalThe release replaces the worktree‑stack skill with a general‑purpose create‑worktree workflow and removes private project names, local paths, and network traces from public evidence surface.
Why it matters: Security fact (severity 70) eliminates exposure of private project details in public repositories; developers and SREs should verify no sensitive data leaks post‑upgrade.
Summary
AI summaryThe old worktree-stack skill is replaced by a general-purpose create-worktree workflow.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Removes private project names, local paths, and network traces from public evidence surface. Removes private project names, local paths, and network traces from public evidence surface. Source: llm_adapter@2026-05-29 Confidence: high |
— |
| Refactor | Low |
Replaces old worktree-stack skill with general-purpose create-worktree workflow. Replaces old worktree-stack skill with general-purpose create-worktree workflow. Source: llm_adapter@2026-05-29 Confidence: high |
— |
| Refactor | Low |
Folds imported security auditor into canonical Klimkit security skill. Folds imported security auditor into canonical Klimkit security skill. Source: llm_adapter@2026-05-29 Confidence: high |
— |
Full changelog
Klimkit v0.2.8 sharpens the public skills package: the imported security auditor is folded into the canonical Klimkit security skill, the old worktree-stack skill is replaced by a general-purpose create-worktree workflow with deterministic bundled scripts for simple and dev-synced worktrees, and the tracked public evidence surface is scrubbed of private project names, local machine paths, and private network traces so the repository is safer to publish, install, and inspect.
Breaking Changes
- Removed the worktree-stack skill; replaced with a general-purpose create-worktree workflow.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Klimkit
All releases →Related context
Related tools
Earlier breaking changes
- v0.2.1 Moves old Switchboard/runtime/plugin machinery to deprecated paths.
Beta — feedback welcome: [email protected]