Apply the same recursive placeholder expansion used by native MCP configs before extension-package servers are validated and surfaced. This prevents stdio credentials and remote headers from reaching servers as literal placeholders.\n\nSolves: Extension-package MCP environment expansion\nTests: bun test packages/coding-agent/test/discovery/omp-plugins.test.ts
Keep host-specific secret injection in the maintained plugin layer instead
of carrying a behavioral divergence in the OMP fork.
Solves: Unwanted fork maintenance for MCP injection
Tests: Reverts only drycode/oh-my-pi PR #1
Claude marketplace plugins may reference runtime secrets in stdio
server environment values. Resolve those placeholders after plugin-root
substitution so child processes receive credentials instead of literal
template strings.
Solves: Stdio MCP credentials remain unexpanded
Tests: Claude plugin discovery tests; coding-agent check; live CH auth
The claude-plugins provider read installed_plugins.json but never the
`enabledPlugins` map Claude Code keeps in ~/.claude/settings.json and
<project>/.claude/settings(.local).json. Two consequences: a plugin the
user switched off for a project still loaded there, and a local-scope
install enabled for a project never loaded unless the project directory
matched the install's recorded projectPath exactly.
Merge enabledPlugins across the same layers Claude Code consults (user
settings, then the active project root's and cwd's .claude/settings.json
and settings.local.json; later wins) and apply it in
listClaudePluginRoots: `false` hides the plugin, `true` opts a
local-scope install in regardless of projectPath. Untouched ids keep the
existing behavior. Contributing settings files join the cache key.
Solves: Claude marketplace plugins loading in the wrong projects
Tests: claude-plugins.test.ts — per-project off switch (local wins over
settings.json, other projects unaffected) and enabledPlugins:true
opt-in for a local install recorded under a parent directory
OpenCode substitutes {env:VAR} and {file:path} in config text at load
time, but OMP's OpenCode discovery ran the generic ${VAR}-only
expandEnvVarsDeep, leaving those tokens literal. An MCP header like
`Bearer {env:MCP_KEY}` reached the server verbatim and returned 401.
The OpenCode loader now applies OpenCode's own substitution to raw
config text before parsing: {env:VAR} -> env value or empty string,
{file:path} -> trimmed, JSON-escaped file contents resolved relative to
the config dir / ~ / absolute, skipping tokens on // comment lines.
Fixes#8778
loadFilesFromDir built a top-level-only pattern (`*.{ts,js}`) for its
documented `recursive: false` default but never forwarded the flag to the
native glob, which defaults recursive=true and rewrites the pattern to
`**/*.{ts,js}`. Every non-recursive discovery scan therefore walked the whole
subtree: `~/.codex/tools` descended into a Python venv's `site-packages` and
imported browser-only frontend assets as custom tools, crashing OMP startup on
an unhandled `window` rejection.
Thread the caller's `recursive` flag through to the native glob call so the
non-recursive default is honored. Providers that need recursion already pass
`recursive: true` explicitly and are unaffected.
Fixes#8552
- Replaced time-based sleeps and polling loops with event-driven promise resolvers and fake timers across agent and tool tests.
- Migrated test suites to share in-memory auth storage and fixtures using lifecycle hooks.
- Updated catalog model definitions, metadata, and configurations.
- Deduplicated the re-imported changelog bullets from the PR #8403 merge,
keeping the condensed register with only the new #8402 entry.
- getUserHomeCandidates memoizes the WSL home candidate keyed by
platform + WSL markers + USERPROFILE, so a wedged interop pipe costs
one bounded probe per process instead of one 500ms stall per
discovery loader, while env changes (tests, SDK embeddings) still
recompute.
resolveWindowsUserProfile() ran Bun.spawnSync(cmd.exe echo %USERPROFILE%)
with no timeout during startup discovery. When the WSL->Windows interop
pipe is wedged, cmd.exe never returns and the synchronous spawn blocks
the JS thread forever, so the TUI never paints and no log is written.
Route both best-effort probes (cmd.exe and wslpath) through a shared
runHostProbe() helper that spawns under a 500ms hard timeout with SIGKILL
and reports a killed/non-zero exit as "host home unavailable", so
discovery falls back to the Linux $HOME/~/.omp candidates instead of
hanging.
Fixes#8402
- Replaced blanket subagent advisor global settings with fine-grained per-agent configuration and frontmatter support.
- Added dashboard keybindings and inline override editors for managing agent advisor patterns.
- Implemented settings migration logic to convert legacy global options into per-agent settings.
- Updated session persistence and execution layers to restore and enforce per-agent advisor behaviors.
- Refactored and condensed numerous system prompts, agent instructions, and tool documentation files across packages.
- Streamlined workflow rules, formatting constraints, and execution guidelines for improved clarity and brevity.
- Updated discovery rules, recommendation criteria, and syntax standards in prompt templates.
Deep-merged each MCP server across config layers in ascending precedence, matching OpenCode config merge, so a partial higher-precedence override inherits command/url and env from lower layers instead of shadowing and invalidating the complete definition.
Added a regression test asserting a project override of a single field keeps the user command, transport, and merged env.
Emitted OpenCode MCP servers highest precedence first so the name-keyed first-wins dedupe keeps the project/opencode.jsonc entry OpenCode would use instead of a shadowing user or opencode.json definition.
Added a regression test asserting same-named servers resolve to the highest-precedence source, including a project enabled:false override.
Discovered opencode.jsonc at user and project scopes and parsed both supported extensions with Bun JSONC semantics.
Added coverage for JSONC settings, MCP servers, and comments in opencode.json.
Fixes#8104
- 28 symbols across discovery, mcp header policy, agent-hub projection and
rendering, the agent registry, shell tokenizing and changelog comparison
were exported but referenced only inside their own module; they are now
module-private, shrinking the deep-import surface.
- Kept AGENT_PLUGIN_MANIFEST_SCHEMA, AGENT_PLUGIN_MCP_SCHEMA,
parseAgentPluginManifest, clearAgentPluginRootCache and mergeMCPHeaders
exported: each is a seam for tests that defend real parsing or header
precedence behavior.
- Nothing reachable from an explicit exports entry or public barrel changed.
- New agent-plugins provider discovers packages with a root plugin.json
targeting the canonical schema (agent-plugins.org) from marketplace
installs, --plugin-dir, and configured extension roots; skills/ and
mcp.json load per spec with closed-schema validation,
${PLUGIN_ROOT}/${PLUGIN_DATA} expansion, reserved subprocess
environment, instance-keyed data dirs, and per-component isolation.
- Package-boundary containment (spec §4.1) is enforced before every
read via the new contained-path helpers, including skill:// resource
access from the read tool and bash; plugin skill files must
realpath-resolve inside the plugin root (skills carry containRoot).
- Legacy claude-plugins/omp-plugins providers yield skills and MCP
surfaces of standard-targeting roots to the new provider and skip
fatally invalid packages.
- Implemented in-house, zero-dependency utility modules in `pi-utils` covering DOM manipulation, markdown parsing, templating, browser automation helpers, and terminal buffers.
- Migrated packages across the repository to consume the new internal utilities and `omptype` schema validators instead of external dependencies.
- Removed multiple external runtime and development dependencies including Zod, Marked, LRU cache, Turndown, and Puppeteer browser packages.
- 🛠️ Keep home-level context when no repository root exists.\n- ✅ Exclude home context only for nested repositories.\n- 🧪 Cover repositories whose root is above home.
Scanned the Windows host USERPROFILE .agents directory when running under WSL so globally installed Agent Skills are available alongside Linux-home skills.
Fixes#3779
(cherry picked from commit c3468dae4f9b91646bf50f2cf4ded9075572290e)
The Claude/Cursor/Gemini/Windsurf importers appended user entries before
project entries, so a project `enabled: false` could not claim its dedupe key
ahead of a same-named user server and the disable was silently ignored. Load
project entries first, matching the native/Codex loaders, so a project disable
suppresses a same-named user server.
Updated docs/mcp-config.md to reflect the project-first precedence and added
compound regression coverage.
Fixes#7652
The Claude Code, Cursor, Gemini CLI, Windsurf, and VS Code importers built
their canonical MCPServer object without mapping serverConfig.enabled, so a
server declared with "enabled": false stayed undefined and the central
suppressServer filter never fired. Only disabledServers masked the gap.
Map the field in each importer, mirroring opencode.ts and codex.ts, and add
a table-driven regression test across all five importers.
Fixes#7652
Load project Codex MCP entries before user entries so a disabled project server claims its dedupe key before a same-named user server can survive.
Added regression coverage for project-over-user disable precedence.
Fixes#7538
Carry enabled = false through discovery so loadAllMCPConfigs' suppress
path can claim the dedupe key (keeping a same-named lower-priority
source disabled) and honor the user force-enable allowlist. Dropping the
entry outright defeated both.
Fixes#7538
- Change the default MCP JSON-RPC request ID format from snowflake strings to sequential integers.
- Update server configuration schema, connection equivalence checks, and tests to reflect the new integer default.
OMP plugins ship their own .mcp.json, and that provider whitelists fields into
the canonical MCPServer shape the same way the other loaders do, so a plugin
bundling an integer-only server could set requestIdFormat and still have it
dropped before it reached a transport.
Extract the value parsing into parseRequestIdFormat() next to parseBoolean() in
discovery/helpers.ts and use it from all three OMP-owned loaders (native,
standalone mcp.json, omp-plugins), replacing the two hand-rolled copies.
Vendor providers (claude, claude-plugins, cursor, vscode, gemini, opencode,
windsurf) are deliberately untouched: they translate another tool's own server
list, where an OMP-specific key has no meaning.
The option was only present on the transport-facing `MCPServerConfig`, so a
value written in `.omp/mcp.json` or a standalone `.mcp.json` never reached the
transports: discovery normalizes config into the canonical `MCPServer` shape and
`convertToLegacyConfig()` rebuilds the transport config from it, and neither step
knew about the field. Setting `"number"` in the documented config path silently
kept the snowflake-string default, which is the hang the option exists to avoid.
Wire it through the same four places `timeout` already uses: the canonical
`MCPServer` shape, the two OMP-native loaders (with validate-and-warn on an
unrecognized value), and the legacy conversion. Foreign-format providers are
untouched, since the key is OMP-specific.
Also point the `MCPServerConfigBase` doc comment at `RequestIdAllocator` rather
than a helper name that never existed.