- Added shared Python call and literal serialization utilities with multiline verbatim support.
- Standardized tool inventories to format as an OpenAI-Harmony functions namespace using TypeScript declarations.
- Updated tool normalization and rendering functions to accept options objects and default to Python-syntax examples.
- Refactored Gemini dialect rendering to leverage shared serialization functions directly.
Hard-coded 'scout' references reached the model even when the scout
agent was disabled via task.disabledAgents or absent from the session
spawn list. Gate every such reference on scout actually being spawnable:
the task tool description, the delegation gates, the plan-mode and
workflowz notices, the glob/grep/ast-grep guidance, and the task
specialization advisory. Prompt shape is otherwise unchanged; only
erroneous references to the unavailable subagent are dropped.
Closes#7313
Threaded the session's disabledExtensions into context-file rediscovery so a concurrently-created session's global settings cannot toggle another session's context entries.
Fixes#7258
On a fresh session with deferred MCP discovery the post-discovery prompt
rebuild renders the full mounted xd:// device catalog, yet the pre-user
xdev-mount-notice re-listed the same names because announcement tracking was
never updated by the rebuild. This double-billed the entire mounted MCP
inventory into the first model request.
rebuildSystemPrompt now reports the catalog it rendered via
BuildSystemPromptResult.xdevCatalogNames, and applyActiveToolsByName folds
those devices into the announced-mount baseline (marking them announced and
dropping them from the pending delta). Notices for mount changes the rebuild
did not expose, and all unmount notices, remain intact.
Fixes#7139
Catalog summaries of mounted xd:// devices are inlined verbatim into the
system prompt. External devices (MCP servers, plugins) supply that text, and
it was bounded only by character count: a summary of multi-byte script passed
roughly three times the intended budget, and control characters survived into
the prompt where they can forge structure.
Summaries now go through a single sanitize-and-bound step that strips C0/C1
control characters and bounds the result in UTF-8 bytes via the central
truncateHeadBytes helper, so a cut lands on a code point boundary and never
renders a partial code point. The built-in/external distinction is derived
once per entry, and that same boolean both selects the description cap and is
exposed as `dynamic`, so the cap and the flag cannot disagree. The prompt uses
the flag to state that dynamic summaries are untrusted metadata, and the mount
notice says the same for newly appeared devices.
(cherry picked from commit 5989da6235d820bc687779a791e655e6f1b2df0f)
Fixes a crash: createAgentSession passes workspaceTreePromise (a
Promise) as providedWorkspaceTree. The merge path accessed
primary.agentsMdFiles without awaiting, rejecting the system-prompt
prep and falling back to an empty tree.
Co-authored-by: oh-my-pi <https://omp.sh>
- Filter #additionalDirectories when moveTo changes cwd so the new cwd
is never also listed as an additional root (session-manager.ts)
- Build workspace tree for each additional root to discover nested
AGENTS.md files under added roots, merging agentsMdFiles into the
primary set (system-prompt.ts)
Co-authored-by: oh-my-pi <https://omp.sh>
- Always augment context files with additional root context, even when
createAgentSession passes preloaded contextFiles (system-prompt.ts)
- Merge configured dirs with existing restored roots on resume instead
of replacing them (sdk.ts)
- Copy additionalDirectories from source header in forkFrom so forks
preserve the multi-root set (session-manager.ts)
- Add test for forkFrom preserving additionalDirectories
Co-authored-by: oh-my-pi <https://omp.sh>
When additional workspace directories have their own AGENTS.md/rules,
the agent now discovers and injects those context files alongside the
primary cwd's context. This prevents the agent from editing under a
root without seeing the rules that apply there.
Co-authored-by: oh-my-pi <https://omp.sh>
A session now carries an ordered list of workspace directories beyond cwd,
managed live from the terminal. New /add-dir, /remove-dir, and /dirs slash
commands let you add and remove folders mid-session; the repeatable --add-dir
CLI flag seeds them at launch, and the workspace.additionalDirectories
setting persists defaults per project. Additional roots are persisted in the
session header, survive reopen/fork/move, and are surfaced to the agent in the
system prompt so it knows they exist and can read/grep/glob them by absolute
path. Design aligns with the endorsed community implementation on
feature/session-workspace.
Co-authored-by: oh-my-pi <https://omp.sh>
Removed display-only home shortening from the provider-facing project prompt and covered home-relative project paths with a regression test.
Fixes#6100
Kept top-level custom tool descriptors when a retained xd device uses the same name. Added compact and inline inventory coverage for mounted-only and dual-presentation tools.
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
- Centralized task concurrency and delegation logic by moving instructions from individual tool descriptions to the system prompt.
- Introduced conditional system prompt logic to handle model-specific task policies, including support for GPT-5.6.
- Added infrastructure for task concurrency normalization and IRC steering state within the system prompt configuration.
- Refactored prompt inputs and session logic to enable dynamic system prompt updates based on model-specific policy cohorts.
Read the Linux CPU model from /proc/cpuinfo during system prompt construction instead of calling os.cpus(), which can synchronously probe every logical CPU frequency file on many-core hosts.
Fixes#4712
Stop advertising eval in the default prompt and workflow notice when no eval
backend is enabled. Gate bash guidance on live eval backend availability and
cover the disabled-backend rendering contract.
Agent-Milestone: tooling: hide eval prompt guidance when eval backends are disabled
Signed-off-by: Christian Stewart <christian@aperture.us>
Bun on macOS 15+ (Darwin 24/25) returns the literal string "unknown" from
os.version() when uv_os_uname() cannot populate the version field. That
value was piped straight into the <workstation> block as `Kernel:
unknown`, and the model then guessed the OS glyph from the ambiguous
signal — displaying a Windows logo on Macs.
Fall back to `${os.type()} ${os.release()}` (uname -s + uname -r, e.g.
`Darwin 25.5.0`) whenever os.version() is empty or the literal
"unknown". Linux keeps its build string when Bun returns one.
Fixes#4141
On a probe that exits 0 with valid output but leaves a descendant holding stdout open, the bounded drain previously discarded the captured bytes and cached { gpu: null }. Use the already-captured stdout when the probe itself succeeded; only treat a non-zero/timeout exit as a failure.
Even on exit 0 the GPU probe can leave a descendant holding stdout open. Race the EOF wait against a 250ms grace window so the success path cancels the reader instead of blocking until the descendant exits, and unref the prep deadline timer so a one-shot CLI is not held alive by it once all prep work returns.
Stopped the GPU probe from awaiting stdout EOF after the probe process exits non-zero, which can hang when a wrapper leaves descendants holding stdout open. The regression now covers a killed wrapper with an inherited stdout holder and verifies the scenario process exits before the deadline.
Bun.spawn defaults killSignal to SIGTERM, which a wedged lspci/wmic (or its PATH wrapper) can ignore, leaving the probe alive past the prep deadline and blocking the null-cache write. Force SIGKILL so proc.exited always resolves at the deadline and the next startup hits the cache.
Replaced the Bun Shell call with Bun.spawn + timeout, so a hanging lspci/wmic now receives SIGTERM at the prep deadline instead of keeping the Bun process alive after withDeadline returned. Tightened the regression test to also assert the spawned scenario process exits within the deadline.
Cached empty GPU probe results and routed GPU detection through the system prompt prep deadline so slow WMI/lspci probes cannot block startup indefinitely.\n\nFixes #3835
- Added `includeWorkspaceTree` configuration setting to optionally render the workspace directory tree.
- Configured the system prompt template and SDK to respect this toggle, allowing users to disable the tree to prevent prompt cache invalidation.
- Updated the system schema and prompt options to disable inline tool descriptors by default.
- Modified the build system prompt logic to reflect the new default fallback value.
Skip the secondary loadSystemPromptFiles capability walk when the caller already controls block 0 via customPrompt/resolvedCustomPrompt, so project/user SYSTEM.md cannot silently augment a CLI --system-prompt override.
Fixes#3014
- Renamed `repeatToolDescriptions` to `inlineToolDescriptors` throughout configuration, SDK, and internal session management.
- Set the default value to `true` and updated descriptions to clarify the descriptor inlining behavior.
- Fixed the `/dump` command to prevent duplicate tool inventory output when inlining is enabled.
Added GitHub Copilot instruction-file discovery to the github rule provider path, mapping applyTo frontmatter into always-apply or glob-scoped rules and avoiding duplicate always-apply prompt content when context imports the same file.\n\nFixes #2731