Skip to content

feat(engines): omp — install omp from omp.sh - #536

Merged
ralyodio merged 1 commit into
mainfrom
feat/engines-omp
Sep 25, 2026
Merged

ralyodio merged 1 commit into
mainfrom
feat/engines-omp

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Adds omp (Stencil Labs' coding agent, oh-my-pi upstream) as an engine:
moshcode install omp runs curl -fsSL https://omp.sh/install | sh. The
installer bun install -gs when a native-arch bun is present (~/.bun/bin)
and otherwise downloads a prebuilt binary to ~/.local/bin; it edits no
shell rc, so both are bridged via binDirs. Aliases: oh-my-pi, ohmypi,
omp.sh.

Agent mode is --auto-approve (skips tool approvals; the agent can still
ask). No agentsView: omp agents manages bundled agent files and exits.
Headless ai() is omp -p <prompt>, resume is --continue, and upgrade is
omp's own omp update.

Verified with omp 18.3.1: a moshcode install into a throwaway HOME with
neither dir on PATH lands the binary in ~/.local/bin and resolves it via
binDirs; omp --auto-approve under a pty in a fresh directory opens
straight to the composer — no trust or bypass dialog, so no boot
answers. Uncosted: its session logs are not read by cost yet.

Adds omp (Stencil Labs' coding agent, oh-my-pi upstream) as an engine:
`moshcode install omp` runs `curl -fsSL https://omp.sh/install | sh`. The
installer `bun install -g`s when a native-arch bun is present (~/.bun/bin)
and otherwise downloads a prebuilt binary to ~/.local/bin; it edits no
shell rc, so both are bridged via binDirs. Aliases: oh-my-pi, ohmypi,
omp.sh.

Agent mode is `--auto-approve` (skips tool approvals; the agent can still
ask). No agentsView: `omp agents` manages bundled agent files and exits.
Headless ai() is `omp -p <prompt>`, resume is `--continue`, and upgrade is
omp's own `omp update`.

Verified with omp 18.3.1: a moshcode install into a throwaway HOME with
neither dir on PATH lands the binary in ~/.local/bin and resolves it via
binDirs; `omp --auto-approve` under a pty in a fresh directory opens
straight to the composer — no trust or bypass dialog, so no `boot`
answers. Uncosted: its session logs are not read by `cost` yet.
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

8 finding(s) in the 5 file(s) this pull request changes.

MEDIUM: 8

Severity Rule Location
MEDIUM sql-string-concatenation src/cli-schema.mjs:180
MEDIUM sql-string-concatenation src/cli-schema.mjs:239
MEDIUM sql-string-concatenation src/cli-schema.mjs:643
MEDIUM sql-string-concatenation src/cli-schema.mjs:676
MEDIUM sql-string-concatenation src/cli-schema.mjs:783
MEDIUM sql-string-concatenation src/cli-schema.mjs:1536
MEDIUM sql-string-concatenation src/cli-schema.mjs:1554
MEDIUM insecure-temp-file test/engines.test.mjs:166
93 pre-existing finding(s) elsewhere in the repository — **HIGH/CRITICAL**: 8 | **MEDIUM**: 74 | **LOW**: 11

Not introduced by this pull request. The full set is in the Security tab.

Severity Rule Location
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
HIGH tls-verification-disabled apps/pwa/src/lib/moshpit-gateway.mjs:299
HIGH sh-remote-script-execution install.sh:86
HIGH sh-remote-script-execution install.sh:90
HIGH sh-remote-script-execution install.sh:258
HIGH sh-remote-script-execution install.sh:269
HIGH sh-remote-script-execution install.sh:275
HIGH tls-verification-disabled src/dns.mjs:766
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:44
MEDIUM sql-template-interpolation apps/pwa/src/lib/moshpit-certs.mjs:82
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:139
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:153
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:179
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:373
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:377
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:422
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:671
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:867
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:869
MEDIUM sql-template-interpolation apps/pwa/src/moshpit.mjs:928

…and 73 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 4813301 into main Sep 25, 2026
6 checks passed
@ralyodio
ralyodio deleted the feat/engines-omp branch September 25, 2026 06:57
ralyodio added a commit that referenced this pull request Sep 25, 2026
Cross-engine session handoff, stream rules at the PTY layer, and provider
limits folded into `moshcode cost`, drawn from omp (oh-my-pi) after #536
added it as an engine.

Grounded in three things already in the tree: cost.mjs already parses every
engine's transcript format, pty.mjs already sits below every engine's output
stream, and cost.mjs already reports spend but not headroom. Records two
non-starters so they are not re-proposed: completion.mjs already generates
no-drift completions from cli-schema.mjs, and advisor.mjs is advis0r.com
equity research rather than an advisor model, so that name is taken.

Conforms to profullstack.com/stack: MCP bridge on every verb, hqtui rather
than a localhost web dashboard, node --test, and no em dashes.

Regenerating the index with prd.mjs also corrected a stale row: 0017 has
said Accepted on disk while README said Draft.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant