* Treat literal 'null'/'none' strings as absent for optional tool args
Models routinely pass the literal string "null" or "none" instead of
omitting an optional argument. Taken at face value it becomes a filter
that matches nothing, so tools like list_notes / list_reports /
list_requests silently return no results.
Coerce such values to None in the central argument-coercion layer, but
only for parameters the schema allows to be null (or that are absent from
a declared "required" list), so required strings keep the literal value.
The list/filter helpers normalize the same values too, so a direct call
can't regress.
* Limit nullish coercion to query tools and keep literal tags
A literal "null"/"none" is only a mistake where the argument is a filter, so
gate the coercion on read-only query tools; a tool that writes keeps the value,
which stops update_note(content="none") from being read as "leave unchanged".
Stop dropping nullish entries from a notes tag filter too: tags are free-form,
so a literal "none" tag stays filterable and mixed tag queries keep every
branch.
* add a generic MCP client and a config for connecting MCP servers
* Add MCP docs and CLI polish: docs page, startup connect summary, --mcp-config flag, compact tool output
* Add MCP connection notes and per-run selection; clean up on cancel and dedupe names
* Show errored MCP tool calls as failed in the TUI
* Sanitize namespaced tool names so model APIs accept them
* Show MCP tool calls distinctly in the terminal and the run viewer
* Say what MCP servers are worth connecting for
* Correct the notes docstring to match how notes reach the agent
* keep the mcp tests from reading your shell's STRIX_MCP_* vars
When the dedupe model uses llmtr/ but the main model is a different
provider, the global litellm.api_base (derived from the main model) is
not the LLMTR gateway, so the dedupe request would resolve to LiteLLM's
default openai/ endpoint and fail. Mirror the existing per-call dedupe
credential pattern: inject the LLMTR gateway base URL into the dedupe
request's extra_args when no explicit DEDUPE_LLM_API_BASE is set. An
explicit DEDUPE_LLM_API_BASE still wins.
Addresses Greptile review feedback on the mixed main/dedupe routing case.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ag2XdAsvrR7XKMmQsAjqSN
Make LLMTR (https://llmtr.com) a first-class option alongside OpenRouter:
users set STRIX_LLM="llmtr/<model>" + LLM_API_KEY (llmtr-...) and nothing
else. LLMTR is a Turkey-hosted OpenAI-compatible gateway, so StrixProvider
resolves llmtr/<model> to LiteLLM's openai/<model> route, and
_configure_llmtr_routing supplies the gateway base URL (an explicit
LLM_API_BASE still wins) plus Strix attribution headers. Attribution is
also sent per-request via _request_headers, mirroring OpenRouter.
Adds unit tests for prefix detection, routing resolution, base-URL/header
configuration, explicit-base override, the non-LLMTR no-op path, and
frontier-model detection through the llmtr/ prefix.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ag2XdAsvrR7XKMmQsAjqSN
- Remove --mount from two skills: the flag does not exist in the CLI. Local
paths are mounted writable when passed with -t.
- Document --target-list, --scope-mode, --diff-base, and OpenAPI/Postman
targets, so agents stop putting spec URLs in --instruction prose.
- Add the application-security-testing skill as the entry point for
whole-product AppSec requests, routing each asset to the right workflow.
- Drop contractions and Latin abbreviations across the skill prose.
* add extra-files plumbing so orchestrators can drop single files into the sandbox workspace
* reject extra-file paths that collide with a local source tree
* add --workspace-file so CLI users can place files in the sandbox workspace
* reject repeated and control-character workspace paths
* revalidate persisted workspace files when resuming a run
* drop the workspace-file size limit