Commit Graph

117 Commits

Author SHA1 Message Date
can1357 2ad61c7b92 feat(discovery): added Agent Plugins 1.0.0 standard support
- New agent-plugins provider discovers packages with a root plugin.json
  targeting the canonical schema (agent-plugins.org) from marketplace
  installs, --plugin-dir, and configured extension roots; skills/ and
  mcp.json load per spec with closed-schema validation,
  ${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
  environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
  read via the new contained-path helpers, including skill:// resource
  access from the read tool and bash; plugin skill files must
  realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
  surfaces of standard-targeting roots to the new provider and skip
  fatally invalid packages.
2026-08-07 05:59:52 +02:00
can1357 7a77771571 test(coding-agent): require multiline flag for anchored rules 2026-08-05 21:50:23 +02:00
zhang17-24 9e62597387 fix(coding-agent): enabled multiline matching in ts-no-tiny-functions condition 2026-08-06 01:59:47 +08:00
roboomp 9f92d36425 fix(mcp): ordered project entries before user in translated importers
The Claude/Cursor/Gemini/Windsurf importers appended user entries before
project entries, so a project `enabled: false` could not claim its dedupe key
ahead of a same-named user server and the disable was silently ignored. Load
project entries first, matching the native/Codex loaders, so a project disable
suppresses a same-named user server.

Updated docs/mcp-config.md to reflect the project-first precedence and added
compound regression coverage.

Fixes #7652
2026-08-04 21:14:11 +00:00
roboomp 73d3076d14 test(mcp): isolated translated importer home configs
Set HOME and os.homedir() to a dedicated temporary directory for each translated-provider fixture, then restore both after every test. This prevents real user MCP configs from shadowing the project fixture through capability deduplication.
2026-08-04 21:03:19 +00:00
roboomp b872e51e6f fix(mcp): propagate enabled flag from translated tool configs
The Claude Code, Cursor, Gemini CLI, Windsurf, and VS Code importers built
their canonical MCPServer object without mapping serverConfig.enabled, so a
server declared with "enabled": false stayed undefined and the central
suppressServer filter never fired. Only disabledServers masked the gap.

Map the field in each importer, mirroring opencode.ts and codex.ts, and add
a table-driven regression test across all five importers.

Fixes #7652
2026-08-04 20:57:47 +00:00
roboomp 6f7600cd89 fix(discovery): prioritized project codex mcp entries
Load project Codex MCP entries before user entries so a disabled project server claims its dedupe key before a same-named user server can survive.

Added regression coverage for project-over-user disable precedence.

Fixes #7538
2026-08-03 16:52:54 +00:00
roboomp 012836d99e fix(discovery): tag disabled codex mcp servers instead of dropping
Carry enabled = false through discovery so loadAllMCPConfigs' suppress
path can claim the dedupe key (keeping a same-named lower-priority
source disabled) and honor the user force-enable allowlist. Dropping the
entry outright defeated both.

Fixes #7538
2026-08-03 16:45:31 +00:00
roboomp 8b854598f1 fix(discovery): honored disabled codex mcp servers
- Skipped Codex config.toml MCP entries explicitly marked enabled = false.
- Added discovery regression coverage for disabled and enabled entries.

Fixes #7538
2026-08-03 16:38:20 +00:00
Sunil Srivatsa f22c0edbfa fix(coding-agent): scope SDK extension packages 2026-08-01 13:50:53 -04:00
Sunil Srivatsa df38e5b48e fix(coding-agent): rebind relative extension roots 2026-08-01 13:24:11 -04:00
Sunil Srivatsa 8a7edb3f3d fix(coding-agent): preserve explicit extensions in isolation 2026-08-01 12:32:19 -04:00
can1357 d1de4658aa fix(discovery): warn when a plugin mcpServers pointer names a missing file 2026-07-28 10:59:35 +02:00
roboomp 4f63e4e521 fix(discovery): honored inline plugin MCP manifest maps
Treated an object-valued mcpServers manifest field as the server map, rooting relative stdio paths at the plugin root, so plugins declaring servers inline no longer fell through to .mcp.json.

Fixes #6871
2026-07-28 07:24:49 +00:00
roboomp 8f31a123d6 fix(discovery): honored plugin MCP manifest pointers
Resolved mcpServers file pointers from OMP and Claude plugin manifests before the conventional root config fallback.

Updated marketplace installer documentation for runtime symlink and lockfile registration.

Fixes #6871
2026-07-28 07:12:46 +00:00
can1357 d0d6ab6237 feat(coding-agent/discovery): added ts-no-local-is-record builtin discovery rule
- Add the `ts-no-local-is-record` built-in rule to detect local `isRecord` definitions and direct agents to shared guards.
- Add unit tests validating detection of local function and lambda definitions for the new rule.
2026-07-28 04:06:18 +02:00
roboomp ab8fb13eea fix(mcp): deduplicated aliased server connections
Deduplicated semantically identical MCP endpoints across provider-specific names while preserving provider priority and canonical direct names.

Kept the first registration on sanitized tool-name collisions and logged both origins.

Fixes #6786
2026-07-27 10:22:39 +00:00
can1357 b6e68fd243 fix(coding-agent): updated mentions of explore -> scout 2026-07-23 00:12:07 +02:00
roboomp c74e9d324f fix(extensions): disambiguated .agent dirs provider tab label
The /extensions dashboard built one tab per provider from its displayName.
The .agent/.agents config-standard provider used "Agents (standard)", which
collided with the first-class /agents subagents feature even though the tab
only surfaces skills, rules, prompts, commands, and context/system files.
Renamed DISPLAY_NAME to "Agent Dirs (.agent/.agents)".

Fixes #5821
2026-07-17 09:04:40 +00:00
roboomp 64e6ffc454 fix(discovery): isolated Claude local plugins
Filtered Claude Code local marketplace entries against the canonical active project before exposing plugin roots.

Fixes #5750
2026-07-16 20:29:36 +00:00
can1357 61cb9cb4e3 merged PR #5562: fix(discovery): root Codex config.toml MCP command/cwd at config dir 2026-07-16 03:31:55 +02:00
can1357 5ff277349c refactor(coding-agent): consolidated tool surface onto xd:// devices and hub
- Added the `xd://` virtual device protocol (`internal-urls/xd-protocol.ts`, `tools/xdev.ts`): tools declaring `loadMode: "discoverable"` are unmounted from the request tools array and driven via `read xd://` (list/docs+schema) and `write xd://<tool>` (execute), gated by the `tools.xdev` setting (default on) and inlined into the system prompt.
- Merged the `irc`, `job`, and `launch` tools into a single `hub` tool (`tools/hub/`, `async/job-manager.ts`): messaging keeps `send`/`inbox`/`list`, job control maps to `wait`/`cancel`/`jobs`, process supervision keeps `start`/`logs`/`stop`/`restart`/`describe` with `ps`, and the unified `wait` races background jobs against peer messages; SDK `IrcTool`/`JobTool`/`LaunchTool` are replaced by `HubTool`.
- Removed the hidden `resolve` tool in favor of the `xd://resolve`/`xd://reject`/`xd://propose` resolution devices, auto-including `write` whenever a deferrable tool or plan mode is present.
- Removed the BM25 tool-discovery system: the `search_tool_bm25` tool, the `tool-discovery` module, the `tools.discoveryMode`/`mcp.discoveryMode`/`mcp.discoveryDefaultServers`/`tools.essentialOverride` settings, per-tool MCP selection, and the `mcp_tool_selection` message type.
- Unified tool presentation on `ToolLoadMode` (`essential`|`discoverable`), replacing the custom-tool `xdev?: boolean` opt-out; custom, extension, MCP, RPC host, image-generation, and TTS tools now default to `discoverable`, and added a `satisfies` predicate to `SoftToolRequirement`.
- Removed the standalone `ssh` command tool and `ssh/ssh-executor` (the `ssh://` read/write/search protocol stays), and made `--tools` address hidden built-ins.
- Updated collab-web to render `xd://` dispatches and `hub` op families, dropped the `search_tool_bm25`/`ssh`/`report-finding` renderers, refreshed tool docs and prompts, and migrated the affected tests and changelogs.
2026-07-15 15:16:29 +02:00
roboomp 0d0df064e0 fix(discovery): gated cwd-based command rooting to codex importer
The previous follow-up rooted path-like commands at the resolved cwd in
the shared resolvePluginStdioPaths helper, which regressed plugin
.mcp.json semantics: plugin commands are relative to the plugin package
root, so a plugin shipping ./bin/server with cwd="work" would resolve to
<pkg>/work/bin/server and ENOENT. Add a commandBase parameter defaulting
to "config-dir" (the plugin contract) and pass "cwd" only from the Codex
importer, where the OS resolves the relative command against the spawned
process cwd.

Fixes #5561
2026-07-15 10:05:08 +00:00
roboomp e88c45f063 fix(discovery): resolved plugin stdio command against rooted cwd
resolvePluginStdioPaths resolved a path-like command against the config
directory unconditionally, but the stdio transport spawns the subprocess
with the rooted cwd as its process cwd, so the OS resolves a relative
command from there. For cwd="server", command="./bin/mcp" that meant OMP
looked for <configDir>/bin/mcp instead of <configDir>/server/bin/mcp.
Root cwd first, then resolve path-like commands from that rooted cwd,
falling back to configDir only when no cwd is set.

Fixes #5561
2026-07-15 09:56:18 +00:00
roboomp d6683c351a fix(discovery): rooted codex toml mcp command/cwd at config dir
The Codex config.toml importer copied only command/args/url into the
returned MCPServer, dropping cwd and leaving relative command values
verbatim. MCP stdio spawning resolved those against the session cwd, so
the bundled Codex Computer Use server (relative command, cwd = ".") failed
with ENOENT. Route command/cwd through resolvePluginStdioPaths against the
config directory, matching the claude-plugins/omp-plugins fix in #5481.

Fixes #5561
2026-07-15 09:43:46 +00:00
can1357 425e583ae0 feat(coding-agent): added support for task-agent field and model resolution
- Added schema and type updates for task-agent fields and model resolver settings.
- Extended discovery helper logic to carry resolved task-agent metadata through execution setup.
- Updated task/agent registration and execution paths to use the new capability/field data.
- Expanded test coverage for agent-field parsing, model resolution, and executor prewalk behavior.
2026-07-15 00:50:55 +02:00
can1357 52f0d3f9e6 fix(discovery): tolerate malformed plugin cwd 2026-07-14 22:58:46 +02:00
roboomp 6467a3119e fix(discovery): rooted relative plugin mcp command and cwd at config dir
Discovered plugin .mcp.json stdio servers launched relative command/cwd
values against the session cwd instead of the plugin's config directory,
breaking bundled ChatGPT/Codex plugins (e.g. Computer Use) with ENOENT
when spawning ./... from an unrelated cwd.

The claude-plugins and omp-plugins providers now resolve relative cwd and
path-like command (./ or ../) against the .mcp.json directory via a shared
resolvePluginStdioPaths helper; bare executables such as npx are left
untouched so PATH lookup still works.

Fixes #5330
2026-07-14 18:36:21 +00:00
can1357 441037025a feat(coding-agent): updated thinking-level configuration and precedence
- Configured the default `task` subagent to use `auto` thinking.
- Enabled `auto` as a valid thinking-level value in agent frontmatter.
- Adjusted thinking-level precedence to ensure that explicit `:level` suffixes in resolved model patterns override agent-defined defaults.
2026-07-11 13:35:05 +02:00
can1357 7e4360d317 fix(discovery): preserve marketplace-root skill selection 2026-07-08 15:19:38 +02:00
can1357 5d20a739b7 merge PR #4610: fix(discovery): accept array-form Claude plugin manifest paths 2026-07-08 15:19:37 +02:00
roboomp 071f199a1d fix(agent): kept project sticky rules active
Synthesized project .omp/RULES.md as a distinct sticky rule name so capability dedup no longer shadows it behind the user sticky rule.

Added a public rules capability regression test covering user and project sticky RULES.md files loading together.

Fixes #4739
2026-07-06 19:43:46 +00:00
roboomp c92cf0a905 fix(discovery): load Claude plugin skill paths that point at a SKILL.md directory
Claude plugin manifests may declare a `skills` path that resolves directly to a
directory whose `SKILL.md` IS the skill (e.g. `"skills": ["./"]` or a
subdirectory containing only `SKILL.md`). `scanSkillsFromDir` only scanned
`<dir>/<name>/SKILL.md` children, so the single-skill directory layout — the
common shape the Claude plugins reference documents for plugins shipping one
skill — silently dropped every array-form manifest entry that pointed at it.

Add an opt-in `includeSelf` flag to `ScanSkillsFromDirOptions`: when set,
`<dir>/SKILL.md` (if present) is loaded as a skill in addition to the existing
child scan. The Claude plugin skills loader opts in; every other provider
(agents, builtin, claude.ts, codex, github, omp-plugins, opencode) keeps the
strict child-scan semantic they rely on. Frontmatter `name` still wins over
the directory basename fallback.

Regression test: `skills: ["./single"]` where `./single/SKILL.md` is the only
skill file loads the skill under its frontmatter name.
2026-07-05 12:23:18 +00:00
roboomp c42d2b2907 fix(discovery): load file-form Claude plugin commands
Claude plugin manifests allow command path entries to name either directories
or flat `.md` command files. The array resolver was now preserving those file
paths, but `loadSlashCommands` still sent every resolved entry through
`loadFilesFromDir`, which only globs inside directories. A manifest such as
`{"commands":["./custom/deploy.md"]}` therefore replaced the default scan
and then loaded nothing.

Teach the command loader to stat each resolved entry: `.md` files are read as
single slash commands with the same plugin namespace and source metadata as
directory-loaded files; directories continue through `loadFilesFromDir`.
Missing entries keep the existing silent-empty behavior.

Add a regression test covering a mixed array of a direct command file and a
command directory while proving default `commands/` remains replaced unless
listed explicitly.
2026-07-05 12:16:02 +00:00
roboomp f276d80fc4 fix(discovery): honour per-field Claude plugin path merge semantics
Review feedback on #4610: array-form skills was silently replacing the
default `skills/` scan when the manifest declared any explicit entries.
Per the Claude plugins reference "Path behavior rules"
(https://code.claude.com/docs/en/plugins-reference#path-behavior-rules):

- `skills` ADDS to the default `skills/` scan
- `commands` / `slash-commands` REPLACE the default `commands/` scan

`resolvePluginDir` now takes an explicit `includeFallback` flag. `loadSkills`
passes `true` (fallback + declared entries, deduped by resolved absolute
path so a manifest may still list `./skills` alongside extras without
double-load); `loadSlashCommands` passes `false` (replace semantic
preserved). Deduplication keeps the fallback first and declared entries
in manifest order.

Regression tests cover both semantics: skills-array merges with default
`skills/`; commands-array replaces default `commands/` so a stray
`commands/default.md` no longer loads once the manifest declares an
alternative — matching Claude's documented behavior.
2026-07-05 12:09:22 +00:00
roboomp d9ef874e2b fix(discovery): accept array-form Claude plugin manifest paths
The Claude plugin manifest allows `commands`, `slash-commands`, and `skills`
to be either a single string or an array of strings — documented under
https://code.claude.com/docs/en/plugins-reference#path-behavior-rules and
used by real marketplace plugins such as addyosmani/agent-skills whose
plugin.json declares `"commands": ["./.claude/commands", "./commands"]`.

`resolvePluginDir` in `packages/coding-agent/src/discovery/claude-plugins.ts`
typed those manifest fields as `string` only, so array-shaped values were
silently dropped: no items loaded, no warning surfaced. Slash commands
(`spec`, `plan`, `build`, `test`, `review`) never appeared in the picker.

Normalize `string | string[]` at the resolver, load every in-root entry,
and emit one out-of-plugin-root warning per bad entry so misconfigured
paths remain observable. Skills and slash-command loaders now fan out over
the resolved directory list and merge warnings from all sources.

Fixes #4609
2026-07-05 12:02:47 +00:00
ben 47a02929db test(coding-agent): preserve agent-dir env restore 2026-07-01 22:25:59 +02:00
ben 510ed57712 fix(coding-agent): harden local ci isolation review fixes 2026-07-01 22:25:04 +02:00
ben 34a4777497 test(coding-agent): harden local ci isolation 2026-07-01 22:25:04 +02:00
can1357 dcc7a1ce2c feat(coding-agent/discovery): added Go syntax and API discovery rules
- Added eight new Go-specific rules to the discovery package.
- Registered the new Go rules in the default rule source index.
- Covered the new Go AST matching conditions with test cases in `builtin-defaults.test.ts`.
2026-06-30 09:49:59 +02:00
roboomp 500c39aa2e fix(extensions): isolate codex hook scripts so process.exit cannot kill OMP startup
Codex discovery surfaced every `~/.codex/hooks/*.{ts,js}` file as an OMP
hook (silently defaulting untyped names to `pre:<basename>`), and
`discoverExtensionPaths` then handed those paths to `loadExtension` for
dynamic import. A standalone Codex hook script with a top-level
`process.exit(0)` terminated the host CLI cleanly — `try/catch` around
`await import()` cannot intercept a synchronous exit, so OMP died at the
`loadExtensions:start` startup marker with no error surface.

Two-layer fix:

- `packages/coding-agent/src/extensibility/utils.ts`: new
  `withExitGuard` helper patches `process.exit` for the duration of a
  guarded callback so an exit raises `ExtensionExitError` instead of
  terminating the process; nested and concurrent guards restore correctly
  via depth counter.
- `extensibility/extensions/loader.ts`, `extensibility/hooks/loader.ts`,
  and `extensibility/plugins/manager.ts` wrap their dynamic-import sites
  in `withExitGuard` so the existing per-module `try/catch` records the
  intercepted exit as a load error and OMP keeps starting.
- `discovery/codex.ts:loadHooks` no longer treats arbitrary files as
  OMP hooks: only `pre-<tool>.{ts,js}` and `post-<tool>.{ts,js}` are
  registered. Files like `memory-bank-reminder.ts` are silently skipped
  rather than imported as extension factories.

Adds regression coverage:

- `test/extension-loader-process-exit.test.ts` — `loadExtensions` /
  `loadHooks` return errors and leave `process.exit` restored when a
  module exits at import time; sibling modules still load.
- `test/discovery/codex-hooks-discovery.test.ts` — codex provider
  registers `pre-*` / `post-*` files and drops everything else.

Fixes #3680
2026-06-27 20:38:53 +00:00
roboomp 7289cd4baf fix(mcp): expanded plugin env headers
Expanded environment variable placeholders in Claude marketplace plugin MCP url and headers before registration. Added a regression test covering context7-style HTTP server headers.\n\nFixes #3621
2026-06-27 03:16:45 +00:00
can1357 74d7dfd2fa Merge PR #3354: fix: migrate coding-agent tests to removeWithRetries (@oldschoola) 2026-06-27 02:06:38 +02:00
can1357 ae1650d689 refactor: renamed search and find tools to grep and glob
- Renamed the `find` and `search` tools to `glob` and `grep` respectively across the codebase to improve command clarity.
- Implemented full-stack support for the renamed tools, including CLI arguments, system prompts, SDK exports, and tool registration.
- Added automated migration logic in `settings` to transform legacy `find` and `search` configuration keys to their new equivalents.
- Updated the `collab-web` renderer registry to ensure backwards compatibility with legacy tool outputs.
2026-06-27 00:57:55 +02:00
Dr Kennedy Umege 5ea467aa3c fix: address gc review edge cases 2026-06-26 12:58:30 +01:00
oldschoola a2854ba768 fix: migrate coding-agent tests from fs.rm to removeWithRetries
Migrate 203 test files (356 call sites) from fs.rm/fs.rmSync to
removeWithRetries/removeSyncWithRetries to reduce EBUSY test failures
on Windows. removeWithRetries is now exported from @oh-my-pi/pi-utils.

The migration uses a regex-based approach that:
- Replaces fs.rm(path, { recursive, force }) → removeWithRetries(path)
- Replaces fs.rmSync(path, { recursive, force }) → removeSyncWithRetries(path)
- Replaces fs.rm(path) → removeWithRetries(path) (no options)
- Skips fs.rm/fs.rmSync inside template literals (bun --eval scripts)
- Adds imports to existing @oh-my-pi/pi-utils import or creates new one
- Removes unused fs imports where fs.rm was the only fs usage (4 files)
2026-06-23 15:28:05 -07:00
roboomp bcfb5b5d8b fix(marketplace): preserved plugin root scope
Carried user/project root scope through enabled plugin enumeration so project marketplace installs keep project-level discovery metadata.
2026-06-22 08:59:24 +00:00
roboomp c531117869 fix(mcp): normalized opencode command arrays
Mapped OpenCode MCP array commands to stdio command plus args and accepted environment as the provider-native env key.\n\nAdded regression coverage for array command normalization, environment mapping, env fallback, and empty args omission.\n\nFixes #3180
2026-06-21 09:23:54 +00:00
can1357 d4317d3d20 feat(ai): consolidated OpenAI-family streaming and add OpenRouter API support
This change introduces a new `openrouter` API type and extensively refactors OpenAI-family streaming providers, centralizing shared logic and improving robustness.

Key changes include:
- **Unified OpenAI-family Logic:** Consolidated core utilities, compat resolution, request shaping, and stream processing into `openai-shared.ts`, reducing duplication across `openai-completions`, `openai-responses`, and `openai-codex-responses`.
- **OpenRouter API Type:** Introduced a dedicated `openrouter` API type with dual-surface compatibility, allowing it to dispatch requests as either OpenAI Chat Completions or Responses.
- **Enhanced Provider Integration:**
    - Improved Perplexity search to leverage shared OpenAI streaming transports, including API-key fallback to OpenRouter and support for Perplexity's Responses API.
    - Integrated xAI-specific logic directly into the shared `stream.ts` dispatch, removing the dedicated `xai-responses` provider.
    - Refined credential parsing for Google Gemini CLI and handling of Azure deployment names.
- **Robustness & Consistency:** Improved error handling for Codex, standardized output token parameter resolution, and ensured consistent application of reasoning suppression across all Chat Completions dialects.
- **New Documentation:** Added `provider-endpoint-constraints.md` to detail endpoint-specific behaviors and quirks for various providers.
- **Telemetry & Debugging:** Extended telemetry propagation to advisor calls and overflow compaction tasks. Improved debugging for Codex WebSocket failures and stream error messages.
- **Tooling & Security:** Updated browser stealth scripts to prevent detection and added a new `ts-no-inline-cast-access` TTSR rule.
2026-06-17 21:36:48 +02:00
can1357 c509a5d59c fix(coding-agent): honor comma-separated and **/* Copilot applyTo globs
GitHub documents applyTo as a single comma-separated string (e.g.
"**/*.ts,**/*.tsx") and treats both ** and **/* as all-files. The rule
loader kept the whole CSV value as one glob and missed **/* for
always-apply. Split applyTo via parseCSV and include **/* as all-files.

Addresses review feedback on #2734.
2026-06-16 14:23:50 +02:00