Skip to content

fix(code): require AGENTS.md marker for /agent discovery - #5076

Merged
Mason Daugherty (mdrxy) merged 3 commits into
mainfrom
fix-agent-picker-issue
Jul 27, 2026
Merged

fix(code): require AGENTS.md marker for /agent discovery#5076
Mason Daugherty (mdrxy) merged 3 commits into
mainfrom
fix-agent-picker-issue

Conversation

@mdrxy

Copy link
Copy Markdown
Member

Makes /agent listing fail-closed: only ~/.deepagents/<name>/ directories that contain a real AGENTS.md file are shown as switchable agents.


#4991 stopped the leak of plugins/ and conversation_history/ by expanding a reserved-name denylist. That still defaulted to "every subdirectory is an agent unless named." Any new app-owned dir under ~/.deepagents/ would leak again unless the denylist was updated.

Discovery now requires the agent marker the product already stamps — AGENTS.md (created empty on first use when memory is enabled). Bare folders, app state (bin/, plugins/, conversation_history/, .state/, and future siblings), directory symlinks, and symlink markers are excluded without maintaining a name denylist.

Related #4991

Fail-closed agent listing so only dirs with a real AGENTS.md appear in
the picker, instead of denylisting app-owned names under ~/.deepagents/.
@github-actions github-actions Bot added dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization size: M 200-499 LOC labels Jul 27, 2026

@open-swe open-swe Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Open SWE Review found 1 potential issue.

Open in WebView Open SWE trace

Comment thread libs/code/deepagents_code/agent.py
Belt-and-suspenders: still denylist bin/plugins/conversation_history so
dcode -a plugins stamping AGENTS.md cannot surface app state in /agent.
@github-actions github-actions Bot added size: S 50-199 LOC and removed size: M 200-499 LOC labels Jul 27, 2026
@mdrxy
Mason Daugherty (mdrxy) merged commit aff1435 into main Jul 27, 2026
54 checks passed
@mdrxy
Mason Daugherty (mdrxy) deleted the fix-agent-picker-issue branch July 27, 2026 14:53
Mason Daugherty (mdrxy) pushed a commit that referenced this pull request Jul 27, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Release notes preview: keep this section in sync with the package
`CHANGELOG.md`. Publish reads the merged CHANGELOG via `release.yml`,
not this PR description — keep them aligned anyway so the PR stays an
accurate historical record for reviewers and anyone returning later._

---


##
[0.1.48](deepagents-code==0.1.47...deepagents-code==0.1.48)
(2026-07-27)

### Features

- Added Fireworks `kimi-k3`, GLM-5.2-Fast, and Kimi-K3 to model
selection and recommended models.
([#5082](#5082),
[#5072](#5072))
- Migrated legacy hooks to v2 events.
([#4971](#4971))

### Bug Fixes

- Require an `AGENTS.md` marker for `/agent` discovery, resolving
unintended discovery behavior.
([#5076](#5076), closes
[#4991](#4991))
- Removed the redundant `/restart` hint from the restart prompt.
([#5083](#5083))
- Removed the caret flash in plugin type-to-search.
([#5078](#5078))

_End release notes preview._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
…in-ai#5076)

Makes `/agent` listing fail-closed: only `~/.deepagents/<name>/`
directories that contain a real `AGENTS.md` file are shown as switchable
agents.

---

langchain-ai#4991 stopped the leak of `plugins/` and `conversation_history/` by
expanding a reserved-name denylist. That still defaulted to "every
subdirectory is an agent unless named." Any new app-owned dir under
`~/.deepagents/` would leak again unless the denylist was updated.

Discovery now requires the agent marker the product already stamps —
`AGENTS.md` (created empty on first use when memory is enabled). Bare
folders, app state (`bin/`, `plugins/`, `conversation_history/`,
`.state/`, and future siblings), directory symlinks, and symlink markers
are excluded without maintaining a name denylist.

Related langchain-ai#4991
Marcelo5444 pushed a commit to Marcelo5444/deepagents that referenced this pull request Jul 30, 2026
> [!CAUTION]
> Merging this PR will automatically publish to **PyPI** and create a
**GitHub release**.

For the full release process, see
[`.github/RELEASING.md`](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md).

---

_Release notes preview: keep this section in sync with the package
`CHANGELOG.md`. Publish reads the merged CHANGELOG via `release.yml`,
not this PR description — keep them aligned anyway so the PR stays an
accurate historical record for reviewers and anyone returning later._

---


##
[0.1.48](langchain-ai/deepagents@deepagents-code==0.1.47...deepagents-code==0.1.48)
(2026-07-27)

### Features

- Added Fireworks `kimi-k3`, GLM-5.2-Fast, and Kimi-K3 to model
selection and recommended models.
([langchain-ai#5082](langchain-ai#5082),
[langchain-ai#5072](langchain-ai#5072))
- Migrated legacy hooks to v2 events.
([langchain-ai#4971](langchain-ai#4971))

### Bug Fixes

- Require an `AGENTS.md` marker for `/agent` discovery, resolving
unintended discovery behavior.
([langchain-ai#5076](langchain-ai#5076), closes
[langchain-ai#4991](langchain-ai#4991))
- Removed the redundant `/restart` hint from the restart prompt.
([langchain-ai#5083](langchain-ai#5083))
- Removed the caret flash in plugin type-to-search.
([langchain-ai#5078](langchain-ai#5078))

_End release notes preview._

---

> [!NOTE]
> A **New Contributors** section is appended to the GitHub release notes
automatically at publish time (see [Release
Pipeline](https://github.com/langchain-ai/deepagents/blob/main/.github/RELEASING.md#release-pipeline),
step 2).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: langchain-oss-automated-triage[bot] <248757908+langchain-oss-automated-triage[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dcode Related to `deepagents-code` fix A bug fix (PATCH) internal User is a member of the `langchain-ai` GitHub organization size: S 50-199 LOC

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant