Wukong Code v0.0.19 is available now. Every new Loop first shows the Goal, optional Done when, Must not constraints, real project checks, warnings, and this run's iteration limit.
Headless users can inspect the same proposal with wukong loop "<goal>" --dry-run. Starting requires exact Gate, warning, and workspace trust confirmation; Auto, YOLO, and --yes cannot silently grant it.
Check commands, source locators, definitions, order, and policy are frozen locally. Definition drift, missing evidence, or damaged replay fails closed. Continuing a terminal run creates a new traceable run; changing the finish line creates a revised Goal and contract.
Trusted project checks still run with your current operating-system permissions. Wukong rejects known inline secrets and recognizable destructive or upload commands, but this release does not claim a complete shell sandbox.