Native pet runtime and controlled AI connections
- Added
- A first-run guide explains what Pipipong can do, how AI execution is connected, and when macOS permissions are requested.
- The desktop Pet Library can locally import complete PPAS 0.9.5 .pppet packages and run their declared actions, clips, triggers, effects, sounds and permission review.
- AI Connections adds destination-bound setup for Codex and configured API providers, plus a controlled connector framework for browser and desktop AI targets without reading browser cookies or account tokens. No specific third-party browser or desktop AI client has been verified in this release.
- Changed
- Configured API providers continue to use the bounded Pip Agent Runtime, attachment consent, permission checks, file transactions, Diff, optional Snapshot and Undo controls; the browser and desktop connector framework implements the same local authority boundary.
- Connector capability evidence and authorization are bound to the exact AI destination. Unverified or unsupported browser and desktop targets remain disabled instead of receiving local tool authority.
- The app keeps its compact desktop-pet surface while moving setup, appearance, AI connections and advanced controls into Settings.
- Fixed
- Packaged-app verification now checks the shipped bridge components, permission boundaries, PPAS runtime lifecycle and isolated virtual-input smoke paths against the release build.
- Known limitations
- This build remains a controlled technical preview rather than a production-stable release, and the installed app is still named Voice Router Pet.
- Native .pppet import is included, but community pet-package downloads remain closed until package compatibility and publisher-trust controls complete their rollout; public previews do not expose package URLs.
- No specific third-party browser or desktop AI client has been verified for this release. Those paths require explicit in-app authorization and a verified destination profile, and unverified targets remain disabled. An AI client never receives direct filesystem authority.
- Windows remains in development, with no public test or release date announced.