Yeachan-Heo/oh-my-claudecode
55.4
Adequate · 28 September 2026
466.9k
lines of production code
TypeScript
with JavaScript
3
measurements over time
What this system is
Oh-My-ClaudeCode is a multi-agent orchestration layer for Claude Code that manages complex software development workflows through a modular system of specialized agents and automated pipelines. It provides intelligent model routing, background task concurrency, and secure graph-based execution to coordinate autonomous coding, verification, and review tasks. The system also includes comprehensive tooling for workspace checkpointing, session history analysis, and integration with external providers and issue trackers.
Features
Add Beads and Beads-Rust task tool context injection
The beads-context hook now supports injecting persistent task-management instructions for the 'beads' (bd) and 'beads-rust' (br) CLI tools. Users can configure their preferred task tool via the \taskTool\ setting in \omc-config.json\ (values: \builtin\, \beads\, \beads-rust\) and control instruction injection with \taskToolConfig.injectInstructions\. When enabled, the hook registers the appropriate tool-specific instructions with the context collector on session init and clears them on session end, allowing the AI to use \bd\ or \br\ commands for task tracking instead of built-in tools.
src/hooks/beads-context · high confidence
Add OMC\_DISABLE\_TOOLS environment variable to filter MCP tools
Users can now selectively disable groups of MCP tools (such as LSP, Python REPL, or Skills) by setting the OMC\_DISABLE\_TOOLS environment variable. The system parses a comma-separated list of group names (e.g., 'lsp,python-repl') and automatically excludes those tools from the available toolset at startup.
dist/mcp · high confidence
Add multi-provider git hosting abstraction for GitHub, GitLab, Bitbucket, Azure DevOps, and Gitea
Users can now interact with pull requests and issues across five major git hosting platforms using a unified interface. The new provider layer in src/providers auto-detects the hosting service from the git remote URL and delegates to the appropriate adapter: GitHub (via gh CLI), GitLab (via glab CLI), Bitbucket (via REST API with token or basic auth), Azure DevOps (via az CLI), and Gitea/Forgejo (via tea CLI or REST API with optional auth token). Self-hosted GitLab and Gitea instances are detected by hostname patterns, and Gitea URLs are validated against SSRF risks. The implementation includes a central registry and URL parser in src/providers/index.ts, shared type definitions in src/providers/types.ts, and individual provider files (github.ts, gitlab.ts, bitbucket.ts, azure-devops.ts, gitea.ts) that handle PR/issue viewing, authentication checks, and CLI requirements.
src/providers · high confidence
Add multi-provider support for Azure DevOps, Bitbucket, Gitea, and GitLab
The Project Session Manager now supports Azure DevOps, Bitbucket, Gitea, and GitLab in addition to the existing GitHub and Jira integrations. New provider scripts in \skills/project-session-manager/lib/providers\ implement detection, pull request/issue fetching, and status checking for these platforms, allowing users to manage sessions across a wider range of hosting services.
skills/project-session-manager/lib/providers · high confidence
Add oh-my-claudecode CLI entry point
A new executable script, bin/oh-my-claudecode.js, has been added to the project. This script serves as a CLI entry point that delegates execution to the existing bridge/cli.cjs module, enabling users to run the tool via this specific binary path.
bin · high confidence
Add vendor reference MCP server for company context
Added a minimal, runnable reference implementation of the company-context MCP contract in the examples/vendor-mcp-server directory. This server exposes a single tool, get\_company\_context, which accepts a natural-language query and returns informational markdown covering security guidelines, review checklists, and domain glossary terms. It serves as a portable example for vendors to integrate with the company-context interface documented in the project.
examples/vendor-mcp-server · high confidence
Added Claude goal snapshot parsing and reconciliation logic
The goal-workflows module now includes a new \claude-goal-snapshot\ component that parses JSON payloads from the Claude agent's \/goal\ command, normalizing various status and objective field names (such as \condition\ for \objective\ or \cleared\ for \cancelled\). It provides a reconciliation function to verify that the agent's reported state matches the expected ultragoal plan, flagging mismatches in objectives or statuses as errors or warnings. This logic is supported by a comprehensive test suite covering input parsing, status normalization, and error handling for malformed or missing snapshots.
dist/goal-workflows, src/goal-workflows · high confidence
Added verification tier selection logic and tests
Introduced a new verification tier system in \src/verification\ that automatically scales review effort based on change complexity. The \tier-selector\ module analyzes changed files to detect architectural or security implications and selects a verification tier (LIGHT, STANDARD, or THOROUGH), which determines the specific agent and model (e.g., haiku, sonnet, opus) used for the review. Comprehensive tests were added to validate the tier selection logic, agent mapping, and file pattern detection for architectural and security changes.
src/verification · high confidence
Agent Usage Reminder Hook Encourages Agent Delegation
A new hook in src/hooks/agent-usage-reminder monitors tool usage and appends a reminder message to the output when users call search or fetch tools (such as grep, glob, webfetch, or websearch) directly without first using an agent. The system tracks whether an agent has been used in the current session; if not, it suggests delegating tasks to specialized agents like 'explore' or 'document-specialist' via the Task tool to improve efficiency and reduce context window usage. State is persisted per session to track usage history and reminder counts.
src/hooks/agent-usage-reminder · high confidence
Agent architecture restructured with modular definitions and tiered model routing
The agent system has been reorganized from a monolithic registry into a modular structure where each agent (e.g., architect, executor, qa-tester) is defined in its own file with dedicated metadata for cost, category, and delegation triggers. This change introduces a 3-tier model routing system (LOW/MEDIUM/HIGH) that automatically assigns models like Haiku, Sonnet, or Opus based on task complexity, allowing users to benefit from optimized cost-performance trade-offs. Additionally, the registry now includes new specialized agents such as tracer for causal analysis and verifier for completion evidence, while consolidating previous overlapping roles into a streamlined set of 18 base agents.
src/agents · high confidence
Alias retirement verifier and closure inventory
The \src/alias-retirement\ module now provides the executable verifier and closure inventory for retiring deprecated skill aliases. It enforces a strict retirement policy requiring a major-version boundary, or alternatively, a combination of temporal thresholds (2 minor releases and 90 days), a 95% canonical usage share over two consecutive releases, and zero critical integrations. The verifier produces machine-readable receipts that determine whether an alias is eligible for removal, while the closure inventory tracks generated artifacts to ensure they are only deleted after their owning alias is proven eligible, preventing premature cleanup.
src/alias-retirement · high confidence
Automatic injection of README and AGENTS context files
The new directory-readme-injector hook automatically detects and injects the content of README.md and AGENTS.md files from the current directory and its ancestors into the AI's context when using read, write, edit, or multiedit tools. This provides immediate project context without manual file inclusion, with content truncated to 5000 tokens if necessary and cached per session to avoid redundant injections.
src/hooks/directory-readme-injector · high confidence
Autopilot now uses a configurable pipeline orchestrator with named workflow support
The Autopilot hook has been refactored to use a new configurable pipeline orchestrator that unifies the workflow into a sequenced pipeline (RALPLAN → EXECUTION → RALPH → QA). This introduces support for named workflow profiles, allowing users to define and resume specific stage sequences. The change includes new cancellation and enforcement logic to handle these named workflows, ensuring state consistency and proper cleanup of linked lifecycle states (like Ralph and UltraQA) during cancellation or clearing. Additionally, the system now supports team execution backends with configurable agent types (e.g., Claude, Codex, Gemini, Grok, Cursor, Antigravity) and provides runtime insights to surface dependency stalls and worker issues.
src/hooks/autopilot · high confidence
Autoresearch introduces structured mission contracts and setup handoffs
The autoresearch feature now enforces strict contracts for mission definitions and setup data. New \contracts.ts\ and \setup-contract.ts\ files define how sandbox evaluations are parsed (requiring YAML frontmatter with specific evaluator commands and JSON output) and how setup handoffs are validated (including confidence thresholds and keep policies). This ensures that autoresearch missions are consistently structured and that the system can reliably parse and execute evaluation scripts defined in mission sandboxes.
src/autoresearch · high confidence
Background agent concurrency and task management
The background-agent feature now includes a ConcurrencyManager that enforces configurable concurrency limits for background tasks, supporting per-model, per-provider, and default limits with automatic queueing when capacity is reached. The BackgroundManager persists task state to disk, prunes stale tasks based on configurable timeouts, and detects inactive sessions to mark them as errored, ensuring reliable background task lifecycle management.
dist/features/background-agent · high confidence
Dynamic orchestrator prompt generation for multi-agent systems
The \dist/agents/prompt-sections\ module now provides a set of functions to dynamically build sections of the orchestrator prompt based on agent metadata. This includes generating the header, agent registry (with tiered variants), trigger tables, tool selection guidance, delegation matrix, orchestration principles, workflow steps, critical rules, and a completion checklist. Adding a new agent automatically updates the orchestrator prompt via these builders.
dist/agents/prompt-sections · high confidence
Graph Core descriptor validation and deterministic scheduler implementation
The \dist/graph\ module now includes the compiled JavaScript and TypeScript declaration files for the Graph Core surface. This adds strict descriptor sealing and structure-before-hash validation (via \descriptor.js\), ensuring that graph definitions are parsed, validated, and hashed with deterministic canonical JSON serialization before being passed to the scheduler. It also introduces the pure deterministic scheduler (\scheduler.js\), which manages graph execution state through hash-fenced projections, replay-fenced mutations, and specific transitions for node results, human approvals, and join resolution, all bound to the sealed descriptor hash to prevent tampering or drift.
dist/graph · high confidence
Graph runtime v2 introduces secure execution with approval gates and containment
The graph runtime has been upgraded to version 2, introducing a hardened execution model that enforces strict directory containment to prevent path traversal and symlink attacks across Linux and macOS. This release adds human approval gates for both interactive (stdin) and remote (file-backed) workflows, ensuring fail-closed behavior on unrecognized input or timeouts. It also implements an epoch-based ownership fence to prevent concurrent writer races, an append-only journal with cryptographic fingerprinting for integrity verification, and a crash-recovery runner that replays committed records to restore state. Additionally, a new ASCII progress reporter provides real-time status updates for runs and node executions.
src/graph/runtime · high confidence
Graph runtime v2 introduces secure execution, ownership fencing, and human approval gates
The graph runtime has been updated to version 2, introducing several new core capabilities and security controls. A new human approval gate allows interactive y/n prompts for critical actions, failing closed on unrecognized input or stream closure. Execution is now bounded by a contained file-system API that restricts operations to specific directory file descriptors, preventing path traversal and ensuring safe file access on Linux and macOS. An epoch-based ownership fence manages run-level concurrency using atomic file locks and tombstones to prevent race conditions. Additionally, an append-only journal with SHA-256 fingerprinting ensures data integrity, while new executors for commands and agents provide structured execution with strict environment allowlisting and read-only tool constraints for AI agents.
dist/graph/runtime · high confidence
HUD introduces agent classification and background task management
The HUD now classifies incoming agent messages and spawns (subagent, teammate, peer-session) to provide accurate ownership metadata while discarding payload bytes for security. It also manages background tasks by tracking their lifecycle, remapping IDs, and cleaning up stale or orphaned tasks that persist from previous sessions. Additionally, the HUD status line now uses color-coded indicators for model tiers (Opus, Sonnet, Haiku) and context window usage to improve visual clarity.
dist/hud · high confidence
HUD now displays API key source and agent activity details
The HUD now includes new elements to provide greater transparency into the session environment and agent activity. The API Key Source element detects and displays whether the active ANTHROPIC\_API\_KEY is configured at the project level, global level, or via an environment variable, without exposing the key itself. Additionally, the Agents element has been expanded to support multiple display formats, including single-character type codes color-coded by model tier (Opus vs Sonnet/Haiku), duration indicators, and detailed descriptions of what each agent is doing. The Autopilot element now renders workflow-specific progress, including stage names and iteration counts, while the Call Counts element provides real-time metrics on tool calls, agent invocations, and skill usages with emoji or ASCII fallbacks for cross-platform compatibility.
dist/hud/elements · high confidence
Initial repository scaffolding for oh-my-claudecode v5.5.0
The repository has been initialized with the core configuration and documentation files for the v5.5.0 release. This includes \.gitattributes\ to enforce line-ending consistency across platforms, \.mcp.json\ to register the OMC bridge MCP server, and \AGENTS.md\ which defines the multi-agent orchestration protocol, delegation rules, and agent catalog. The release is further documented via \CHANGELOG.md\, \CLAUDE.md\ for session guidance, \CONTEXT.md\ for glossary terms, and \CONTRIBUTING.md\ for developer setup instructions.
(repo-wide) · high confidence
Installer adds robust CLAUDE.md analysis and transaction engine
The installer now includes a new analysis module that parses CLAUDE.md files to detect OMC markers and legacy guide patterns while preserving exact byte content and line endings, alongside a transaction engine that manages safe, atomic updates to these files with automatic backups, strict path validation, and rollback capabilities to prevent data loss during configuration changes.
dist/installer · high confidence
Intelligent model routing based on task complexity
The system now automatically selects the appropriate model tier (Haiku, Sonnet, or Opus) for sub-agent tasks by analyzing prompt complexity. It extracts lexical, structural, and context signals—such as keyword presence, subtask count, and cross-file dependencies—to score tasks and assign them to the most cost-effective tier. The router also supports agent-specific overrides, explicit model selection, and automatic escalation to higher tiers if previous attempts fail.
src/features/model-routing · high confidence
Intelligent model routing for sub-agent tasks
The system now automatically routes sub-agent tasks to the most appropriate model tier (Haiku, Sonnet, or Opus) based on task complexity. This feature analyzes lexical, structural, and contextual signals—such as keyword usage, estimated subtasks, and impact scope—to assign a complexity score and select the optimal model. It includes a rules engine for specific agent behaviors (e.g., architects for debugging, planners for strategic tasks) and a scoring system that weighs factors like word count, risk keywords, and reversibility. Users benefit from more efficient resource usage and better performance on complex tasks, as the system proactively selects the right model tier rather than using a default.
dist/features/model-routing · high confidence
Intelligent model routing with tier-specific prompt adaptations
The system now automatically adapts prompts based on the selected model tier (Opus, Sonnet, or Haiku) to optimize performance. High-tier (Opus) prompts enforce deep reasoning, edge-case analysis, and strategic planning. Medium-tier (Sonnet) prompts focus on efficient, structured task execution. Low-tier (Haiku) prompts strip verbosity to maximize speed and conciseness. This change introduces the prompt adaptation logic and templates in the model-routing feature, ensuring users get behavior tailored to the model's capabilities without manual prompt engineering.
src/features/model-routing/prompts · high confidence
Introduce Graph Core contract with deterministic scheduler and descriptor validation
This change adds the foundational Graph Core module in \src/graph\, establishing the data contract, validation, and execution logic for graph-based workflows. It introduces strict Zod-based schema validation for graph descriptors, nodes, and edges, alongside a deterministic scheduler that manages activation, branching, and joining. The module enforces descriptor integrity through SHA-256 hashing and canonical JSON serialization, ensuring that graph structures are sealed and verified before execution. This provides the core infrastructure for defining, validating, and running complex, multi-node workflows with support for agent, command, human-approval, and join node types.
src/graph · high confidence
Introduce LLM Wiki knowledge layer
Adds a persistent, self-maintained markdown knowledge base that compounds project and session knowledge across sessions. The new \src/hooks/wiki\ module provides a public API for ingesting knowledge (with append-only merge strategy), querying pages via keyword and tag search (including CJK bi-gram tokenization), and running health checks (linting for orphans, stale content, broken cross-references, and structural contradictions). It includes session hooks that inject wiki context at session start and auto-capture session metadata at session end, all backed by a file-locked storage layer with a defined schema version and configurable defaults.
src/hooks/wiki · high confidence
Introduce Notepad Wisdom module for capturing plan learnings and decisions
A new 'Notepad Wisdom' feature has been added to automatically capture and persist agent learnings, decisions, issues, and problems. The module parses agent completion responses using regex patterns to extract content from \<wisdom\>, \<learning\>, \<decision\>, \<issue\>, and \<problem\> tags, and writes timestamped entries to markdown files within a plan-scoped directory (.omc/notepads/{plan-name}/). This provides a structured way to track plan progress and insights.
src/features/notepad-wisdom · high confidence
Introduce Project Memory Hook for auto-detecting and injecting project context
A new Project Memory hook has been added to automatically detect and inject project environment details into the AI context. The hook scans for languages, frameworks, package managers, and build/test commands by analyzing configuration files (e.g., package.json, Cargo.toml, pyproject.toml) and directory structures. It tracks frequently accessed files and directories ('hot paths') to prioritize relevant code, and detects user directives (e.g., 'always use...', 'never modify...') from messages to enforce constraints. The detected memory is persisted in \.omc/project-memory.json\ with atomic writes and cross-process file locking to prevent data loss. Context is injected via a session cache to avoid duplication, and a pre-compaction handler ensures critical directives and environment details survive context window compaction.
src/hooks/project-memory · high confidence
Introduce Project Session Manager (PSM) skill for isolated worktree-based development
Adds the Project Session Manager skill, enabling users to create isolated development environments using git worktrees and optional tmux sessions for PR reviews, issue fixes, and feature development. The skill supports multiple issue-tracking providers (GitHub and Jira), allows configuration of project aliases via \\~/.psm/projects.json\, and includes commands for managing session lifecycles (list, attach, kill, cleanup). It also integrates with the \omc teleport\ command for worktree creation and ensures session names are tmux-safe to prevent silent rewriting issues.
skills/project-session-manager · high confidence
Introduce Project Session Manager (PSM) skill for multi-provider issue and PR workflows
The new Project Session Manager skill adds a suite of Bash utilities in skills/project-session-manager/lib to manage project aliases, Git worktrees, and tmux-based AI sessions. It supports GitHub and Jira providers, allowing users to reference issues and pull requests via aliases (e.g., omc\#123) or direct URLs. The skill handles creating isolated worktrees for PR reviews and issue fixes, managing session lifecycles with file locking, and launching Claude Code in tmux with safe session naming and automatic context injection.
skills/project-session-manager/lib · high confidence
Introduce Ralphthon autonomous hackathon lifecycle mode
Ralphthon adds an autonomous workflow that guides a project from a deep-interview intake through PRD generation, task execution, and an automatic hardening phase, terminating only after a configured number of consecutive clean waves. The mode introduces a new PRD schema with support for hardening tasks, a brownfield planning context for existing codebases, and an orchestrator that manages tmux-based execution, idle detection, and phase transitions.
src/ralphthon · high confidence
Introduce agent and command node executors for graph runtime
Added new executors for the graph runtime: the AgentNodeExecutor runs nodes via the @anthropic-ai/claude-agent SDK with read-only tool access, timeout handling, and idempotency support, while the CommandNodeExecutor spawns shell commands with environment allowlisting, output tailing, and cross-platform process-tree termination (including hiding spawned windows on Windows).
src/graph/runtime/executors · high confidence
Introduce bundled builtin skills feature with runtime provider detection
The application now includes a new \builtin-skills\ feature that loads and manages bundled skills (such as \deep-interview\, \ralplan\, and \ralph\) from the \skills\ directory. This feature introduces runtime detection for available AI providers (Claude, Codex, Gemini, Grok, and Antigravity) to dynamically inject provider-specific execution guidance into skill templates. It also enforces a denylist of Claude Code native commands (e.g., \/review\, \/plan\, \/compact\) to prevent skill short names from overriding built-in functionality, and resolves the \deep-interview\ ambiguity threshold from user settings files at runtime rather than using hardcoded values.
src/features/builtin-skills · high confidence
Introduce centralized mode registry for execution state detection
Added a new \src/hooks/mode-registry\ module that centralizes the detection and configuration of execution modes (Autopilot, Autoresearch, Team, Ralph, Deep Interview, Merge Readiness, Self Improve). This registry defines the state file locations, marker files, and mutual exclusivity rules (e.g., Autopilot and Autoresearch cannot run concurrently) using file-based detection under the \.omc/state/\ directory, replacing scattered or global state logic with a unified, session-local approach.
src/hooks/mode-registry · high confidence
Introduce deterministic prompt SSOT composer and projection system
A new single-source-of-truth (SSOT) system for agent prompts has been added to the \dist/agents/prompt-ssot\ module. This system replaces legacy, manually maintained prompt files (such as \CLAUDE.md\ and \agents/\*.md\) with a deterministic composer that generates projections from a central manifest and a set of canonical sections. The composer ensures byte-identical output for the same inputs by sorting sections by kind rank and ID, normalizing whitespace, and computing SHA-256 digests. It supports role-based projections (planner, executor, reviewer, verifier) and allows provider/model-specific overlays (e.g., Codex high-tier vs. Gemini low-tier) to inject data-select deltas without duplicating normative policy text. The module includes a manifest defining required sections and projection catalogs, a digest module for integrity verification, and a metrics module for measuring token duplication and projection drift.
dist/agents/prompt-ssot · high confidence
Introduce native contained filesystem for directory-relative operations
Added a new native C module (contained-fs.c) that exposes Node-API functions for filesystem operations relative to a directory file descriptor (openat, mkdirat, fstatat). This implementation avoids libuv linkage to keep the ABI stable and provides directory-relative operations specifically for the graph store, addressing filesystem path handling on Darwin.
native · high confidence
Introduce notepad memory system for compaction resilience
Added a new notepad support hook that implements a three-tier memory persistence system (Priority Context, Working Memory, and Manual sections) to improve resilience during compaction. This feature introduces a structured markdown-based storage format with automatic pruning for session notes, size limits for priority context, and safeguards for user content, ensuring critical discoveries are preserved while managing file size and memory usage.
src/hooks/notepad · high confidence
Introduce plan-scoped notepad wisdom and rate-limit wait daemon
This release adds a new Notepad Wisdom module that automatically extracts structured learnings, decisions, issues, and problems from agent completion responses and saves them as timestamped markdown files in a plan-specific directory. It also introduces a Rate Limit Wait daemon that monitors API rate limits and automatically resumes blocked tmux panes when limits reset, while preventing stale notifications by tracking per-pane scrollback history.
dist/features/rate-limit-wait · high confidence
Introduce prompt SSOT composer and projection digests
Added a new single-source-of-truth (SSOT) system for agent prompts in \src/agents/prompt-ssot\. This introduces a manifest-driven architecture where normative prompt clauses are authored exactly once in \sections.ts\ and composed into deterministic, versioned projections (e.g., \coordinator\, \role-planner\) via \compose.ts\. The system supports provider and model-tier overlays (e.g., \provider/codex\) as data selects rather than copied prose, ensuring policy text remains consistent across variants. It includes a \digest.ts\ module for SHA-256 hashing of normalized prompt bodies to detect drift, and a \metrics.ts\ module for analyzing token duplication and projection drift. The \manifest.ts\ file defines the projection catalog, required sections, and rollback history, while \types.ts\ establishes the schema for sections, overlays, and composed outputs. Comprehensive tests in \prompt-ssot.test.ts\ verify deterministic composition, manifest integrity, overlay behavior, and normalization invariance.
src/agents/prompt-ssot · high confidence
Introduce prompt prerequisite enforcement for Ralph-family execution
A new hook at src/hooks/prompt-prerequisites/index.ts enforces declared prerequisites before proceeding with Ralph-family execution. It parses prompt sections (memory, skills, verify-first, context) to identify required tool calls (e.g., notepad\_read, project\_memory\_read, supermemory.search) and file paths, using strict path validation (requiring ./, ../, / prefixes or file extensions) to avoid false positives. The hook tracks state via mode-state-io and blocks execution until all required tools and files are satisfied, configurable via plugin config for enabled status, section names, blocking tools, and execution keywords.
src/hooks/prompt-prerequisites · high confidence
Introduce rate-limit auto-resume daemon and tmux pane detection
A new background daemon monitors usage API rate limits and automatically resumes blocked Claude Code sessions in tmux panes when limits reset. The feature includes a daemon process with secure file permissions, a rate-limit monitor that checks 5-hour, weekly, and monthly usage quotas, and a tmux detector that identifies blocked panes using specific UI patterns while filtering out stale history and false positives from git output or saved transcripts.
src/features/rate-limit-wait · high confidence
Introduce self-improve autonomous code improvement skill
Adds a new 'self-improve' skill that runs an autonomous evolutionary loop to improve code in a target repository. The skill orchestrates a multi-agent workflow (research, planning, architecture/critic review, execution, and tournament selection) to iteratively propose and merge changes based on benchmark scores. It introduces topic-scoped artifact storage (under \.omc/self-improve/topics/{slug}/\) with session isolation for concurrent runs, while preserving legacy flat layouts for backward compatibility. Users configure improvement goals, benchmarks, and guardrail harness rules (H001–H003) via interactive setup, after which the loop runs autonomously until a stop condition is met. Supporting scripts handle path resolution, progress visualization, and sealed-file enforcement to prevent self-modification of evaluation code.
skills/self-improve · high confidence
Introduce task decomposition engine for parallelizable subtask generation
Added a new task decomposition feature that analyzes user tasks to identify parallelizable components and generates structured subtasks with non-overlapping file ownership. This engine determines execution order, assigns file patterns to specific subtasks to prevent conflicts, and provides detailed prompts and acceptance criteria for each component, enabling more efficient parallel processing of complex development tasks.
src/features/task-decomposer · high confidence
Introduce team pipeline state machine and transition guards
This change adds the core state management and validation logic for the team pipeline. It defines the \TeamPipelineState\ schema (version 1) and enforces a strict phase progression (plan → prd → exec → verify → fix/complete/failed). The new \transitions.ts\ module validates that transitions are legal, ensures required artifacts exist (e.g., plan/prd paths before execution), and applies numeric guards to execution metrics (ensuring \tasks\_total\ and \tasks\_completed\ are valid non-negative integers, that \tasks\_total \> 0\, and that all tasks are completed before verifying). It also handles fix-loop retry limits, cancellation with resume preservation, and idempotent phase marking.
src/hooks/team-pipeline · high confidence
Introduce unified delegation router with configurable role-based routing
A new delegation routing system has been added to determine which provider and tool to use for a given agent role. The router supports explicit tool invocations, configurable role-based routing (currently disabled by default), and a default heuristic that maps roles to Claude subagents. It also handles deprecated MCP providers (Codex/Gemini) by warning users and falling back to Claude Task, and normalizes legacy role aliases to canonical names.
src/features/delegation-routing · high confidence
Introduce unified state manager with XDG support and TOCTOU protection
A new state management module has been added to standardize how state files are stored and accessed. It introduces a dual-location model: local state is now stored in \.omc/state/\ relative to the project root, while global state uses XDG-compliant paths with a fallback to the legacy \\~/.omc/state\ directory for backward compatibility. The implementation includes a read cache with a 5-second TTL and a 200-entry size limit to improve performance. Crucially, the read operation now captures the file modification time before reading the content to prevent Time-of-Check to Time-of-Use (TOCTOU) race conditions that could lead to caching stale or corrupted data. Legacy state paths for various features (e.g., boulder, autopilot, ralph) are preserved and checked during reads to ensure smooth migration.
src/features/state-manager · high confidence
Introduce v2 mixed-schema skill-active-state ledger with workflow slots
The \src/hooks/skill-state\ module now manages skill state using a dual-copy ledger (\skill-active-state.json\) that supports both legacy support-skill protection and new workflow-slot tracking. This change introduces a \version: 2\ schema where canonical workflow skills (such as \autopilot\, \ralph\, \team\, \deep-interview\, \ralplan\, and \self-improve\) are tracked in an \active\_skills\ branch with lineage and session data, while non-workflow skills continue to use the legacy \support\_skill\ branch with configurable protection levels (light, medium, heavy). The implementation enforces atomic writes to both root and session-specific state files to prevent state collisions and orphaning, and includes logic to handle stale agent cleanup and reinforcement counters for active skills.
src/hooks/skill-state · high confidence
Introduces modular pipeline stage adapters for planning, execution, verification, and QA
The autopilot system now uses a standardized adapter interface to manage its four core pipeline stages: Planning (RALPLAN), Execution, Verification (RALPH), and Quality Assurance (QA). This change replaces previous ad-hoc implementations with distinct, configurable modules that handle specific workflows—such as consensus-driven planning, team-based or solo execution, iterative code review, and build/lint/test cycling—while exposing completion signals and skip conditions for the pipeline orchestrator.
src/hooks/autopilot/adapters · high confidence
Jev judgment-point integration with shadow-mode evaluation and degradation
The \src/hooks/jev\ module introduces a judgment-point system that evaluates developer actions against a TypeSafe AI service (System One). The implementation includes a zero-dependency HTTP client, a configuration layer governed by environment variables (e.g., \OMC\_JEV\ for opt-in points, \OMC\_JEV\_TIMEOUT\_MS\), and a resolver that supports a tri-state execution model: 'off' (twin decides), 'shadow' (twin decides, Jev runs in background for comparison), and 'active' (Jev decides). The system features automatic degradation to the local heuristic twin on timeouts, HTTP errors, or invalid responses, and includes a circuit breaker that opens after three consecutive failures. It supports both blocking (gate-type) and non-blocking (detector-type) judgment points, with all Jev interactions logged to a shadow log for later analysis.
src/hooks/jev · high confidence
Lightweight execution path for small tasks via task-size detection
The task-size-detector hook now classifies user prompts as small, medium, or large to prevent over-orchestration. Small tasks—identified by word count, specific keywords (e.g., 'typo', 'single file'), or escape-hatch prefixes like 'quick:'—are routed to a lightweight execution path, while large tasks (e.g., 'refactor', 'entire codebase') continue through standard orchestration. A shadow judgment point also records heuristic classifications alongside external Jev model choices for future comparison without impacting latency.
src/hooks/task-size-detector · high confidence
MCP tool surface hardening and observability
The MCP server surface now includes a configurable tool-disabling mechanism via the OMC\_DISABLE\_TOOLS environment variable, allowing users to filter entire tool families (such as LSP, AST, or Python REPL) at startup. To prevent prompt injection and path traversal when passing context files to external agents, the server validates file paths against the working directory and rejects control characters. Background job management tools now support structured output path policies and persistence, while a mandatory subagent header prevents recursive agent spawning. Additionally, the standalone server exposes a comprehensive audit trail for prompts and responses, and includes robust shutdown and team-cleanup handlers to prevent orphaned processes.
src/mcp · high confidence
Major API surface expansion and rebranding of the core library
The \src\ module has been rebranded from 'Oh-My-Claude-Sisyphus' to 'Oh-My-ClaudeCode' and significantly expanded its public API. The main entry point (\src/index.ts\) now exports a comprehensive suite of new capabilities, including a background task management system (\createBackgroundTaskManager\), an auto-update system (with version checking and update functions), and a 'Lookout' pre-flight danger scanning API. Additionally, it exposes team worker recovery utilities (\recoverDeadWorkerV2\), an MCP tools server (\omcToolsServer\), and a broader set of agent definitions and features (such as boulder state management and context injection). This reflects a shift from a simple orchestration library to a full-featured plugin runtime with extensive internal tooling and state management exposed to consumers.
src · high confidence
Merge Readiness gate: MCQ explainability, audit trails, and cross-platform support
The merge-readiness hook now enforces a human explainability gate using objective multiple-choice questions (MCQs) scored against configurable depth profiles (quick, standard, deep) with specific thresholds and dimension coverage. The runtime manages a full session lifecycle (start, content, questioning, pass/pause/cancel) and persists state to a session-scoped \.omc\ directory, ensuring path resolution and git execution work correctly on Windows. To prevent information leakage, the gate redacts answer keys and scoring details from public status surfaces until the gate completes, while preserving a complete, immutable audit trail of prior attempts. The tool flow also enforces strict ordering (preventing content submission without a start) and ensures cancellation and state-clear operations are durable and audit-preserving.
src/hooks/merge-readiness · high confidence
New AST-aware code search and incremental deepinit manifest tools
The dist/tools directory now includes two new capabilities. First, ast-tools provides AST-aware code search and transformation using ast-grep, supporting over 25 programming languages with pattern matching and code replacement while preserving structure; it includes path restriction validation to ensure operations stay within the project root boundary when OMC\_RESTRICT\_TOOL\_PATHS is enabled. Second, deepinit-manifest introduces a deterministic manifest system for incremental /deepinit operations, tracking directory file lists to regenerate AGENTS.md only for directories whose structure has actually changed, with actions to diff, save, and check manifest validity. Both tool sets are registered in the tool index and available via the MCP server.
dist/tools · high confidence
New CLI commands for alias retirement verification and capability locking
The CLI now includes two new diagnostic commands: \omc alias-retirement\ and \omc capabilities\. The alias retirement command acts as a read-only verifier that checks aliases against a strict retirement contract (requiring 2 minor releases, 90 days, 95% canonical share, and zero critical integrations) and generates machine-readable receipts and closure reports without deleting any files. The capabilities command introduces a deterministic local runner that collects the current tool, agent, and skill surface, runs a suite of default fixtures (such as tool selection and argument validity), and generates a lockfile (\omc-capabilities.lock.json\) to ensure the runtime surface remains stable across versions.
dist/cli/commands · high confidence
New CLI commands for multi-provider queries, guided autoresearch, graph execution, and workspace checkpoints
The CLI now exposes several new subcommands to expand autonomous and interactive capabilities. The \omc ask\ command allows querying multiple AI providers (Claude, Codex, Gemini, Antigravity, Grok, and Cursor) with support for role-based agent prompts. A guided autoresearch setup flow has been introduced via \autoresearch-guided.ts\ and \autoresearch-intake.ts\, enabling users to define research missions and evaluators through an interactive interview process, while the legacy \omc autoresearch\ command is now deprecated. The \omc graph\ command enables the execution of sealed graph descriptors with remote approval gates and safety checks. Additionally, the \omc checkpoint\ command provides workspace snapshot and rollback functionality for autonomous runs, and the \omc interop\ command facilitates split-pane tmux sessions for interacting with both Claude Code and Codex CLI simultaneously.
src/cli · high confidence
New CLI utility functions for colored output and token count formatting
A new formatting utility module has been added to the CLI, providing a set of ANSI color helpers (red, green, yellow, blue, magenta, cyan, gray, bold) and a function to format token counts into human-readable strings (e.g., '1.5k', '2.00M'). This enables consistent styling and clearer display of token usage metrics in command-line output.
src/cli/utils · high confidence
New OMC orchestration session API for direct SDK integration
The \dist\ directory now includes the compiled entry point (\index.js\ and \index.d.ts\) for the Oh-My-ClaudeCode library, exposing a new \createOmcSession\ function. This API allows developers to programmatically configure and run multi-agent orchestration sessions using the \@anthropic-ai/claude-agent-sdk\ without relying on the interactive Claude Code plugin UI. The session object provides query options (including system prompts, agent definitions, MCP servers, and allowed tools), a state manager, and helpers for processing prompts with magic keywords and managing background tasks.
dist · high confidence
New SWE-bench benchmark suite for comparing vanilla and OMC-enhanced Claude Code
Added a complete benchmarking infrastructure in the \benchmark/\ directory to evaluate and compare standard Claude Code against the oh-my-claudecode (OMC) orchestration layer using the SWE-bench Verified dataset. This includes a Dockerized evaluation environment (\Dockerfile\, \docker-compose.yml\) that supports both vanilla and OMC modes, along with shell scripts (\setup.sh\, \quick\_test.sh\, \run\_vanilla.sh\, \run\_omc.sh\, \run\_full\_comparison.sh\) for executing runs. The suite provides Python tools (\run\_benchmark.py\, \evaluate.py\, \compare\_results.py\, \analyze\_failures.py\) to generate predictions, run official SWE-bench evaluations, and produce detailed comparison reports on pass rates, token usage, and failure patterns. Configuration is managed via \.env.example\, and results are stored in structured directories for vanilla and OMC predictions, logs, and analysis.
benchmark · high confidence
New Setup Hook for OMC initialization and maintenance
A new setup hook has been added to handle OMC initialization and maintenance tasks. On initialization, it creates the required directory structure (\.omc/state\, \.omc/logs\, etc.), validates config files, and sets environment variables. For maintenance, it prunes old state files, cleans up orphaned sessions, and vacuums the swarm SQLite database. It also includes Windows-specific logic to patch \hooks.json\ to avoid shell invocation issues and ensure portable hook paths.
src/hooks/setup · high confidence
New Think Mode hook for extended reasoning
A new 'think-mode' hook has been added to automatically activate extended reasoning capabilities when prompts contain specific keywords. The system detects terms like 'think', 'ultrathink', and their equivalents in over 20 languages (excluding code blocks) to trigger the mode. When activated, the hook can automatically switch the model to a high-reasoning variant (e.g., Sonnet to Opus, or GPT-4 to GPT-4-high) and inject provider-specific thinking configurations, such as enabling Claude's extended thinking with a 64k token budget or setting OpenAI's reasoning effort to high.
src/hooks/think-mode · high confidence
New artifact handoff system and expanded routing configuration
The shared module now includes a new artifact-handoff mechanism that allows components to pass data either inline (for small payloads under 2048 bytes) or via file descriptors (for larger content), complete with content hashing and retention policies. Additionally, the shared type definitions have been expanded to support a \forceInherit\ routing option, which allows agents to bypass model routing and inherit the parent model setting, alongside a broader set of supported team agent types including 'antigravity' and 'cursor'.
dist/shared · high confidence
New atomic file writing and cross-process locking utilities
The distribution now includes new \atomic-write\ and \file-lock\ modules. The atomic-write module provides durable, crash-safe file writes using a temp-file-and-rename pattern with optional fsync and hooks, while the file-lock module implements cross-process advisory locking using exclusive file creation (O\_CREAT\|O\_EXCL) with PID-based stale lock detection and retry/timeout support. These utilities are self-contained and have no external dependencies, ensuring reliable state management and coordination in concurrent environments.
dist/lib · high confidence
New auto-invoke and auto-learner capabilities for learned skills
The learner hook now includes an auto-invoke system that can automatically execute detected skills when confidence exceeds a configurable threshold, subject to per-session limits and cooldowns. Additionally, an auto-learner module has been added to automatically detect problem-solution patterns during work sessions and suggest new skills for extraction. These features are supported by a new shadow judgment point (Jev) for recording extraction decisions and a comprehensive test suite for the shadow logging mechanism.
src/hooks/learner · high confidence
New auto-slash-command hook for detecting and expanding slash commands
A new auto-slash-command hook has been added to automatically detect and expand slash commands in user prompts. The hook scans input for slash commands (e.g., /command), excluding specific built-in commands like 'help', 'clear', 'compact', 'history', 'exit', and 'quit' as well as certain oh-my-claudecode prefixed commands. It discovers commands from multiple sources including Claude Code native commands, user skills, project-level commands, and bundled skills, while preventing user skills from overriding Claude Code's native commands by prefixing them with 'omc-'. The hook also supports live data injection with ! prefix for executing commands and injecting their output, with security measures including control character rejection, command substitution blocking, and allowlist-based command execution.
src/hooks/auto-slash-command · high confidence
New auto-update and background task management capabilities
The distribution now includes the \auto-update\ and \background-tasks\ feature modules. The auto-update system provides version checking against GitHub releases, automatic download and installation, and configurable notification profiles for Discord, Telegram, Slack, and file logging, with an opt-in prompt for upgrades at session start. The background task module introduces heuristics to decide when commands should run in the background versus foreground, manages task lifecycles, and enforces concurrency limits to improve agent efficiency.
dist/features · high confidence
New background agent feature with concurrency control and task persistence
The background-agent module has been introduced to manage long-running, autonomous tasks (Autopilot) outside the main interaction loop. This feature allows users to launch background tasks that persist across sessions via disk storage, track their progress, and resume them later. It includes a concurrency manager that enforces configurable limits on parallel execution per model or provider, preventing resource exhaustion, and automatically prunes stale or timed-out tasks.
src/features/background-agent · high confidence
New boulder-state module for tracking active work plans
The \dist/features/boulder-state\ directory now contains the compiled distribution files for the boulder-state module, which manages the active work plan state for the OMC orchestrator. This module introduces constants for state directories (\.omc\), plan storage (\.omc/plans\), and notepads, alongside storage operations to read, write, and clear the \boulder.json\ state file. It provides functionality to track session IDs, find planner plan files, calculate checkbox progress for markdown plans, and determine the active plan path, effectively porting the boulder-state capability from oh-my-opencode to this codebase.
dist/features/boulder-state · high confidence
New bridge runtime components and protocol handlers
The bridge directory now includes several new runtime files that establish the core communication and execution infrastructure. The \claude-md-coordinator.cjs\ file introduces a coordinator with a handshake mechanism and handles legacy \CLAUDE.md\ corpus migrations. The \gyoshu\_bridge.py\ file adds a Python bridge that executes code via a JSON-RPC 2.0 protocol over Unix sockets (or TCP on Windows), featuring structured output parsing for scientific markers. Additionally, \mcp-server.cjs\, \team-bridge.cjs\, and \team-mcp.cjs\ provide the Node.js runtime for the Model Context Protocol (MCP) and team orchestration, while \run-mcp-server.sh\ serves as a wrapper to ensure global npm modules are resolvable for native dependencies.
bridge · high confidence
New build and verification scripts for plugin distribution and CI integrity
The scripts directory now includes a suite of new build and verification tools to support the plugin distribution model and CI release workflows. Build scripts (build-bridge-entry, build-cli, build-mcp-server, build-team-server, build-runtime-cli, build-skill-bridge) bundle TypeScript sources into standalone CJS/ESM bundles in the bridge/ and dist/ directories, handling native module externalization and import.meta.url polyfills. A new build-generated-artifact-authorization script automates the creation of GitHub artifact authorization records for release PRs by diffing dist/ and bridge/ paths. Additionally, build-prompt-ssot.ts generates and verifies deterministic prompt projections, and audit-multirepo-e2e.mjs provides an end-to-end test fixture for multi-repo workspace functionality.
scripts · high confidence
New code-simplifier stop hook with XDG config support and Jev advisory logging
A new code-simplifier stop hook has been added to automatically delegate recently modified source files to a simplification agent when the feature is explicitly enabled in the global OMC config (opt-in only). The hook respects XDG-style global configuration paths on Unix systems while maintaining backward compatibility with the legacy \~/.omc fallback. It uses a fire-once marker to prevent re-triggering within the same turn cycle and integrates with the Jev advisory system by recording shadow-mode judgment logs for the 'simplifier-trigger' point, ensuring that Jev's input is observed without blocking the simplification delegation.
src/hooks/code-simplifier · high confidence
New comment-checker hook flags unnecessary comments and docstrings
A new comment-checker hook has been added to the codebase that detects comments and docstrings in code changes and prompts the user to justify or remove them. The hook identifies comments across a wide range of languages (including JavaScript, TypeScript, Python, Go, Rust, and more) and applies filters to skip acceptable comments such as BDD keywords (given/when/then), linter/type-checker directives (eslint, pyright, clippy, etc.), shebangs, copyright headers, and TODO/FIXME markers. When unnecessary comments are detected, the hook generates a detailed message listing the flagged comments and requires the user to either explain why they are necessary (e.g., complex algorithms, security-related code) or remove them in favor of self-documenting code.
src/hooks/comment-checker · high confidence
New context injection and tiered prompt adaptation features
This update introduces a context injection system that allows multiple sources to register context entries which are then merged and injected into user prompts with priority ordering and deduplication. It also adds tiered prompt adaptations for Opus, Sonnet, and Haiku models, providing model-specific prompt templates and strategies to optimize instructions based on the model's capability tier.
dist/features/context-injector, dist/features/model-routing/prompts · high confidence
New context injection system for merging and injecting session context
A new context-injector module has been added to manage and inject context from multiple sources into user prompts. This system allows different components (such as project memory, rules, or directory agents) to register context entries with specific priorities and sources. The collector merges these entries, sorts them by priority and timestamp, and injects the combined content into messages using configurable strategies (prepend, append, or wrap), ensuring that critical context is prioritized and deduplicated within a session.
src/features/context-injector · high confidence
New diagnostic, session, and workflow CLI commands
The CLI now includes several new commands to improve diagnostics, session management, and workflow automation. The \omc doctor conflicts\ command scans for plugin coexistence issues, legacy CLAUDE.md markers, and Windows-unsafe hook configurations. The \omc doctor team-routing\ command probes the PATH for configured team role-routing providers (Claude, Codex, Gemini, Grok, Cursor, Antigravity) and reports availability. Session management is enhanced with \omc session-friction-report\ to analyze local session artifacts for friction signals and \omc session-search\ to search session history. Workflow capabilities are expanded with \omc alias-retirement\ to verify alias retirement eligibility, \omc capabilities\ to generate deterministic capability lockfiles, \omc ralphthon\ for an autonomous hackathon lifecycle mode, and \omc ultragoal\ for durable multi-goal workflows with Claude Code integration.
src/cli/commands · high confidence
New feature modules for agent addressability, background tasks, and delegation categories
This release introduces several new feature modules in src/features. The agent-addressability module (\#3665) makes unnamed background agents discoverable and addressable by description, with stable short IDs for listings and notifications. A new background-tasks module provides heuristics to decide when commands should run in the background, enforcing concurrency limits and identifying long-running vs. blocking operations. Delegation categories add a semantic layer over model routing, allowing tasks to be categorized (e.g., visual-engineering, ultrabrain, artistry) with automatic tier, temperature, and thinking budget configuration. An auto-update module implements silent version checking and background updates. A delegation-enforcer middleware ensures model parameters are always present in Task/Agent calls, with support for forceInherit to bypass model routing for non-Claude providers. Documentation (AGENTS.md) provides integration guides and API references for these new capabilities.
src/features · high confidence
New hooks directory with documentation, bridge, and background notification system
This change introduces the \src/hooks\ directory, establishing the core infrastructure for the event-driven hook system. It includes \AGENTS.md\ documentation outlining the 31 hooks and their categories (execution modes, validation, recovery, etc.), a TypeScript bridge (\bridge.ts\, \bridge-normalize.ts\) to handle shell-to-TypeScript communication and input normalization, and a new background notification system (\background-notifications.ts\, \background-notification/\) that dispatches task completion alerts via isolated child processes to prevent stream pollution. Additionally, it adds a startup codebase map injection hook (\agents-overlay.ts\, \codebase-map.ts\) to provide project structure context to agents, and a non-interactive environment detector (\non-interactive-env/\) to prevent hangs in CI by blocking interactive commands and injecting safe environment variables.
src/hooks · high confidence
New interop layer with gated MCP bridge and artifact-based handoffs
A new interop subsystem has been added to enable communication between OMC and OMX. This includes an MCP bridge (mcp-bridge.ts) that exposes tools for sending tasks and messages, gated by environment variables (OMX\_OMC\_INTEROP\_ENABLED, OMC\_INTEROP\_TOOLS\_ENABLED, OMX\_OMC\_INTEROP\_MODE) to restrict direct-write capabilities to 'active' mode. The shared-state layer (shared-state.ts) now supports artifact handoffs for large task descriptions, results, and message content, storing them as files when they exceed a size threshold while keeping small data inline. An OMX team state layer (omx-team-state.ts) provides read/write access to native OMX team directories. The implementation also fixes workspace-root resolution for multi-repo setups, ensuring interop state is written to the workspace root's .omc/ directory rather than a sub-repo's .omc/ directory. Comprehensive tests cover the gating logic, artifact surfacing, and workspace path resolution.
src/interop · high confidence
New keyword detection hook with multi-language support and shadow judgment points
The \src/hooks/keyword-detector\ module introduces a new hook that detects magic keywords in user prompts to trigger specific modes (e.g., ralph, autopilot, codex, antigravity) and supports multi-language patterns including Korean and Japanese. It includes logic to parse explicit slash invocations, suppress false positives from code blocks and CLI prefixes, and integrates with the Jev shadow judgment system to record heuristic decisions for skill triggers and intent without adding latency.
src/hooks/keyword-detector · high confidence
New notification configuration and dispatcher system
The dist/notifications directory now includes a comprehensive configuration reader and dispatcher for sending notifications to Discord, Telegram, Slack, and custom webhooks. The config module (config.js/config.d.ts) introduces named notification profiles, environment variable overrides (e.g., OMC\_DISCORD\_NOTIFIER\_BOT\_TOKEN, OMC\_TELEGRAM\_BOT\_TOKEN), and backward compatibility migration from the legacy stopHookCallbacks format. It also adds strict input validation for Discord mentions, Slack channels/usernames/mentions, and reply injection settings. The dispatcher module (dispatcher.js/dispatcher.d.ts) implements non-blocking, parallel notification sending with per-platform timeouts (10s send, 15s overall), proxy support for Telegram, and IPv4 enforcement to avoid connectivity issues. Custom integrations are supported via webhook or CLI execution.
dist/notifications · high confidence
New per-agent benchmark suites for code-reviewer and debugger agents
Added dedicated benchmark suites for the consolidated code-reviewer and debugger agents, including runner scripts, test fixtures, ground-truth definitions, and agent prompts. The code-reviewer suite evaluates the merged agent against the previous quality-reviewer prompt using fixtures covering payment logic, retry handlers, and SQL injection vulnerabilities. The debugger suite evaluates the merged agent against the previous build-fixer prompt using fixtures for TypeScript build errors, undefined state crashes, and intermittent Redis connection issues. Baseline results are stored in JSON files to track performance over time.
benchmarks · high confidence
New pre-flight danger scan for autonomous runs
The Lookout feature is now available to scan task briefings and workspace state before unattended efforts (such as graph runs or multi-agent teams) begin. It emits a machine-readable report of high-risk findings—such as dangerous SQL operations, force pushes to protected branches, or risky file deletions—based on strict, zero-config rules that prioritize high confidence and minimize false positives. Lookout is advisory only and does not block or mutate the workspace, but its findings are designed to pair with approval gates and checkpoints.
dist/features/lookout, src/features/lookout · high confidence
New scripts/lib utilities for hooks and HUD
The scripts/lib directory now includes a suite of new modules to support hook execution, HUD performance, and configuration resolution. These include agent-model-config.mjs for per-agent model overrides, atomic-write.mjs for durable file operations, bounded-git-timeout.mjs for nested git call limits, cache-occupancy.mjs for tracking plugin roots, config-dir modules (CJS, MJS, shell) for consistent path resolution, context-usage.mjs for HUD cache integration, encode-project-path.mjs for path sanitization, force-agent-delegation-preflight.mjs for routing rules, hook-command-normalizer.mjs for cross-platform command handling, hud-cache-wrapper.sh and hud-wrapper-template.mjs/txt for HUD statusline caching and loading, and model-routing-override-message.mjs for provider-specific model hints.
scripts/lib · high confidence
New subagent lifecycle tracking and session replay infrastructure
The subagent-tracker hook now provides comprehensive monitoring for spawned agents, including detection of stuck or stale agents (over 5 minutes without progress), automatic cleanup of orphaned state, and integration with the HUD for real-time status display. It records detailed lifecycle events—such as agent starts/stops, hook firings, keyword detections, skill activations, and mode changes—to a session-scoped JSONL replay file for post-session bottleneck analysis and timeline visualization. Additionally, on abnormal agent termination, the system collects bounded, read-only evidence of dirty git worktrees to alert coordinators before destructive cleanup, and it now supports explicit user-chosen names and descriptions for unnamed background agents to make them addressable and discoverable.
src/hooks/subagent-tracker · high confidence
New team activity logging and task allocation policies
The team runtime now includes structured activity logging and role-aware task allocation. A new activity log module reads audit events and transforms them into categorized, human-readable entries (task, file, message, lifecycle, error) with a timeline formatter for reports. Additionally, a new allocation policy distributes tasks to workers using load balancing: uniform role pools use round-robin by load, while mixed-role pools score workers by role match and load penalty to prevent overloading.
dist/team · high confidence
New template hooks and deliverables schema for team workflows
The templates directory now includes a new deliverables schema (templates/deliverables.json) that defines file requirements and validation rules for team pipeline stages (plan, prd, exec, verify, fix). Additionally, several new hook templates have been added: code-simplifier.mjs (an opt-in stop hook for automatic code simplification), keyword-detector.mjs (detects magic keywords to invoke skills), persistent-mode.mjs (continuation enforcer for modes like ralph and autopilot), post-tool-use-failure.mjs (tracks tool failures for retry guidance), post-tool-use.mjs (processes \<remember\> tags for memory), pre-tool-use.mjs (enforces delegation and manages skill state), session-start.mjs (restores persistent modes and checks for updates), stop-continuation.mjs (simplified stop handler), and workflow-drift-guard.mjs (prevents workflow drift at stop boundaries).
templates · high confidence
New todo-continuation hook with robust stop-reason detection
Added a new todo-continuation hook that enforces completion of pending tasks and introduces precise detection for authentication errors, rate limits, and user aborts. The hook now correctly distinguishes between user-initiated cancellations and system-level interruptions (such as rate limits or OAuth expiry loops), preventing false positives that previously caused infinite retry or cancellation loops. It also supports both legacy todo files and the new Claude Code Task system, ensuring tasks are tracked and completed across session boundaries.
src/hooks/todo-continuation · high confidence
New unified recovery system for context limits, edit errors, and session state
A new recovery module in src/hooks/recovery consolidates handling for context window limit errors, Edit tool mistakes, and session structural issues into a single coordinated system. It detects token limit and edit errors to inject corrective messages, manages session state with garbage collection, and fixes a regression (issue \#1386) where recovery would incorrectly reuse stale assistant thinking by injecting a synthetic placeholder instead. This ensures conversations recover gracefully from common failure points without losing context or repeating errors.
src/hooks/recovery · high confidence
New utility modules and comprehensive test coverage for core path, config, and parsing logic
This change introduces a suite of new utility modules in src/utils alongside their corresponding test suites. Key additions include cache-occupancy.ts for atomic, privacy-bounded plugin cache tracking with Windows process identity resolution; config-dir.ts to resolve the CLAUDE\_CONFIG\_DIR environment variable; encode-project-path.ts to sanitize project paths for transcript storage; frontmatter.ts for robust YAML-like parsing with flow-collection depth tracking; jsonc.ts to parse JSON with comments and trailing commas; paths.ts for cross-platform directory resolution (XDG/Windows); resolve-node.ts for Node binary detection; string-width.ts for CJK-aware string truncation; and omc-cli-rendering.ts for CLI command rewriting. The accompanying tests validate these utilities across platforms and edge cases.
src/utils · high confidence
New verification module for standardized workflow checks
A new reusable verification module has been introduced to provide a single source of truth for verification requirements across the Ralph, Ultrawork, and Autopilot workflows. This module standardizes the verification process by offering pre-defined checks (such as build, test, lint, and functionality) and allowing teams to define custom protocols with specific evidence collection and validation rules. Users can now create verification checklists, run checks in parallel or sequentially, and generate human-readable reports in multiple formats, ensuring consistent evidence collection and approval gates across all major OMC workflows.
src/features/verification · high confidence
OpenClaw integration adds gateway configuration, event deduplication, and shell-escape security
The dist/openclaw distribution now includes the core OpenClaw integration modules. The config module reads and caches settings from \~/.claude/omc\_config.openclaw.json, gating activation on the OMC\_OPENCLAW environment variable and supporting both HTTP and command-type gateways. A new deduplication layer suppresses stale lifecycle events (such as session-starts arriving after a stop) within a 60-second window to prevent redundant alerts. The dispatcher module handles gateway communication with a 10-second timeout, enforces HTTPS for remote URLs, and uses shell-escaping for command gateways to prevent injection. The main entry point enriches hook context with reply channel details and captures fresh tmux pane content for stop/session-end events.
dist/openclaw · high confidence
OpenClaw webhook gateway integration with deduplication and tmux pane capture
The OpenClaw integration now supports configurable webhook and command gateways, allowing lifecycle events (session-start, stop, session-end) to trigger external HTTP endpoints or local shell commands via a new config file (omc\_config.openclaw.json). To prevent notification noise, the system includes a deduplication layer that suppresses late-arriving lifecycle events within a 60-second window after a terminal state, and uses delta-only tmux pane capture to forward only fresh output to gateways, avoiding stale scrollback alerts.
src/openclaw · high confidence
Orchestrator delegation enforcement with audit logging
The new omc-orchestrator hook enforces a delegation-first workflow by preventing the orchestrator from directly editing source files outside the .omc/ and .claude/ directories. When a Write or Edit tool is used on source code, the hook injects a critical system directive requiring the orchestrator to delegate implementation to subagents via the Task tool instead. The enforcement level (off, warn, or strict) is configurable via .omc/config.json or a global config file, with a 30-second cache to avoid repeated config reads. All delegation decisions are recorded in a JSONL audit log at .omc/logs/delegation-audit.jsonl, which can be queried for summary statistics to help analyze enforcement patterns.
src/hooks/omc-orchestrator · high confidence
Portable factcheck guard and sentinel health analyzer
The factcheck guard in src/hooks/factcheck has been ported to TypeScript, introducing a portable validation engine that checks claims payloads against configurable policies. It supports four modes (strict, declared, manual, quick) to enforce required fields, gate states, path prefixes, and command restrictions, while the new sentinel health analyzer parses JSONL logs to compute readiness stats (pass rate, timeout rate, etc.) and determine if upstream signals are healthy. Configuration is loaded from the OMC config system with token expansion and deep merge, and the sentinel readiness gate is wired into the team pipeline to block on degraded signals.
src/hooks/factcheck · high confidence
Pre-compact hook preserves session state via durable checkpoints
The new PreCompact hook in src/hooks/pre-compact creates durable checkpoints before context compaction to preserve critical session state, including active mode states (autopilot, ralph), TODO summaries, and notepad wisdom. It implements a compaction mutex to prevent concurrent race conditions and uses a robust restore mechanism with canonical directory validation, hard-link CAS for marker publication, and strict session ID allowlisting to ensure portable, safe state recovery across platforms.
src/hooks/pre-compact · high confidence
Preemptive context-usage monitoring with shadow Jev evaluation
A new preemptive compaction hook monitors session context usage and warns users before hitting the context limit, encouraging proactive compaction to prevent overflow. The hook tracks token usage per session, applies configurable warning and critical thresholds (defaulting to 85% and 95% of the model's context window), and enforces a cooldown period and maximum warning count to avoid spam. It also debounces rapid-fire tool completions to prevent concurrent compaction errors. Additionally, when the Jev shadow-evaluation feature is enabled, the hook asynchronously records a shadow comparison of the heuristic's pruning decision against a Jev staleness score, logging the result for later analysis without blocking the user experience.
src/hooks/preemptive-compaction · high confidence
Prevent API errors from empty messages with automatic sanitization
A new empty-message-sanitizer hook has been added to ensure all messages sent to the API contain valid content, preventing errors like 'all messages must have non-empty content'. The hook detects messages with empty text or no parts and injects a placeholder text (defaulting to '\[user interrupted\]') marked as synthetic. It correctly handles tool parts as valid content and skips the final assistant message, which is allowed to be empty by the API specification. Comprehensive tests cover text validation, tool part detection, and sanitization logic.
src/hooks/empty-message-sanitizer · high confidence
Ralph hook consolidated into modular components with Jev shadow-verification
The Ralph hook has been restructured into distinct modules (loop, PRD, progress, verifier, stale-prd) to improve maintainability and isolation. A new Jev shadow-verification point has been added to the Ralph completion verdict, allowing the system to record a 'Noul' judgment for comparison without altering the actual approval flow. Additionally, the PRD module now supports evidence-preserving criterion amendments and stale-state detection with reconciliation, ensuring that unfinished stories are correctly identified and verified against observable evidence.
src/hooks/ralph · high confidence
SDK-compatible command expansion utilities
The src/commands/index.ts module now provides programmatic access to slash commands for SDK integration. Users can discover available commands via listCommands or getAllCommands, retrieve specific command details with getCommand, and expand command templates with arguments using expandCommand or expandCommandPrompt. The system respects the CLAUDE\_CONFIG\_DIR environment variable for locating user-defined commands while falling back to packaged defaults, enabling seamless integration with the Claude Agent SDK.
src/commands · high confidence
Session history search feature added
A new session history search capability has been introduced, allowing users to query past session transcripts. The implementation in \src/features/session-history-search\ provides the core logic and type definitions for searching across project transcripts, legacy transcripts, and OMC session summaries/replays. It supports filtering by query string, time range (since), session ID, project, and case sensitivity, and returns matches with context excerpts.
src/features/session-history-search · high confidence
Ship complete session friction report plugin runtime
The \dist/features/session-friction-report\ module is now included in the distribution, providing the \generateSessionFrictionReport\ function and its associated TypeScript types (\SessionFrictionReport\, \SessionFrictionSession\, \SessionFrictionSignal\). This runtime implementation enables the analysis of session data by scanning for project transcripts, legacy transcripts, and OMC session summaries/replays to calculate friction scores and signals based on metrics like error rates, idle gaps, and tool usage.
dist/features/session-friction-report · high confidence
Unified delegation router with configurable external models
The delegation-routing module now provides a unified router that determines which provider or tool to use for a given agent role based on configuration. It introduces a precedence system: explicit tool invocations take priority, followed by configured routing (if enabled), a default heuristic mapping role categories to Claude subagents, and finally a default provider. The router now supports configurable fallback chains (e.g., \["claude:explore", "codex:gpt-5"\]) and includes logic to handle deprecated MCP providers (Codex/Gemini) by issuing warnings and falling back to Claude Task. It also normalizes legacy role aliases to canonical names and exposes constants for default delegation configuration and role category defaults.
dist/features/delegation-routing · high confidence
Workspace checkpointing for snapshot and rollback
Added a new checkpoint feature that allows users to snapshot the entire working tree (including untracked files) as a git shadow commit and restore it later. This enables safe rollback of autonomous runs by capturing the state under refs/omc/checkpoints/ without modifying HEAD or the real index. The implementation provides functions to create checkpoints with labels, list existing checkpoints, check if the worktree is dirty, and rollback to a specific checkpoint (with a force option to discard uncommitted changes).
dist/features/checkpoint · high confidence
Workspace snapshot and rollback for autonomous runs
A new checkpoint system allows the application to capture the entire working tree (including untracked files) as a lightweight git shadow commit without altering the user's HEAD or index. This enables safe rollback capabilities for autonomous runs: users can restore the workspace to a previous state, with the system automatically cleaning up new files and refusing to discard uncommitted local changes unless the --force flag is explicitly provided.
src/features/checkpoint · high confidence
Security
Python REPL bridge now enforces strict security validations and sandbox boundaries
The Python REPL tool now includes a new bridge-manager that enforces security validations when spawning and managing the underlying Python process. This includes anti-poisoning checks to verify session IDs, anti-hijack protections for socket paths, and process identity verification to guard against PID reuse. Additionally, the tool now explicitly documents and enforces sandbox boundaries, blocking imports, file I/O, and dynamic code execution to ensure safe in-memory data analysis.
dist/tools/python-repl · high confidence
Secure plugin patterns with cross-platform path validation
The plugin-patterns hook now includes robust security validation for file paths, blocking shell metacharacter injection (such as semicolons, pipes, and backticks) and path traversal attempts (like ../). It also adds full support for Windows file paths, correctly handling backslashes and absolute drive letters (e.g., C:\\) in validation logic. Comprehensive test coverage ensures these security constraints and cross-platform path formats are enforced for auto-formatting and linting operations.
src/hooks/plugin-patterns · high confidence
Behavioural changes
Agent addressability contract and projection fixtures added to dist
The build now tracks generated distribution modules in git. This change adds the compiled JavaScript and TypeScript declaration files for the new agent addressability contract (dist/features/agent-addressability), which implements stable discoverability and exact addressing for background agents, alongside the corresponding contract tests. It also adds the compiled projection fixture tests (dist/projection/\_\tests\\_/fixtures.test.js), which verify the integrity of prompt projection golden files and normalized body fixtures.
dist/features/agent-addressability, dist/projection · high confidence
Bundled skills now adapt to available AI providers and respect user-defined ambiguity thresholds
The built-in skills feature now detects which AI providers (Claude, Codex, Gemini, Grok, and Antigravity) are available on the user's system and dynamically adjusts its guidance—such as recommending Codex-specific commands for the deep-interview, plan, and Ralph skills when Codex is installed. Additionally, the deep-interview skill now reads the \ambiguityThreshold\ from the user's \.claude/settings.json\ (project-level) or \\~/.claude/settings.json\ (profile-level), replacing previously hardcoded 20% / 0.2 values so that execution behavior aligns with the user's configured preferences.
dist/features/builtin-skills · high confidence
CI gates added to enforce multi-repo path resolution and prevent committed build artifacts
New CI scripts in \scripts/ci\ now enforce stricter rules for multi-repo workspaces and build hygiene. The \check-multirepo-paths.mjs\ gate uses AST-grep to detect raw \.omc\ path constructions in source code, requiring developers to use canonical resolvers like \resolveSessionStatePaths()\ or \getOmcRoot()\ instead of hardcoded paths. Additionally, \check-no-committed-build-artifacts.mjs\ prevents generated files in \dist\ and \bridge\ directories from being committed to the repository, ensuring a cleaner source history.
scripts/ci · high confidence
Centralized constants for modes, tool categories, and hook events
The application now uses a unified constants registry to define mode names (such as autopilot, ralph, and ultrawork), tool categories (including lsp, ast, python, and new additions like antigravity, shared-memory, deepinit, and wiki), and hook events (such as PreToolUse and SessionStart). This change replaces scattered string literals with a single source of truth, ensuring consistent naming across the codebase and providing strongly-typed identifiers for these core configuration elements.
src/constants · high confidence
Centralized model routing and configurable plan output paths
The configuration system has been refactored to centralize model ID management and introduce configurable plan output paths. Model defaults are now resolved dynamically via environment variables (OMC\_MODEL\_HIGH/MEDIUM/LOW) with built-in fallbacks, replacing hardcoded agent-specific model IDs in the default configuration. A new intelligent routing system is enabled by default, allowing per-agent tier overrides (e.g., architect/planner to HIGH, explore/writer to LOW) and supporting forceInherit for non-Claude providers. Additionally, users can now customize where autopilot and open-questions plan files are saved via the planOutput configuration, with safe path sanitization and template support.
src/config · high confidence
Directory diagnostics now use a dual strategy with LSP fallback
The diagnostics tool in dist/tools/diagnostics now supports a dual strategy for checking TypeScript/JavaScript projects. It primarily uses the TypeScript compiler (tsc --noEmit) for fast, comprehensive checks, but falls back to an LSP-based aggregation when tsc is unavailable or unsuitable. This change introduces new entry points (runDirectoryDiagnostics, runLspAggregatedDiagnostics, runTscDiagnostics) and result types (DirectoryDiagnosticResult, LspAggregationResult, TscResult) that standardize output across both strategies, including error/warning counts, file-level diagnostics, and installation hints for missing language servers.
dist/tools/diagnostics · high confidence
Durable, worker-managed session-end cleanup with deferred actions
The session-end hook now uses a durable manifest and a detached background worker to manage cleanup tasks, ensuring they complete reliably even if the main process exits unexpectedly. Cleanup actions (such as foreground cleanup, team cleanup, Python bridge cleanup, and notifications) are now defined in a manifest, claimed by a worker, and executed in detached child processes with strict deadlines and idempotency keys. This replaces the previous synchronous cleanup path with a robust, retryable, and observable system that prevents state leaks and ensures critical cleanup steps are not skipped.
src/hooks/session-end · high confidence
Introduce artifact handoff system and expand configuration schema
This change introduces a new artifact-handoff mechanism in src/shared/artifact-descriptor.ts, allowing the system to pass content to agents either inline (for small payloads) or via file descriptors (for larger artifacts) based on a configurable byte threshold. It also significantly expands the shared configuration types in src/shared/types.ts: the ModelType enum now includes 'fable', AgentConfig supports optional/disallowed tools and default models, and a new AutopilotConfigBlock defines structured profiles for planning, execution backends, and QA cycles. Additionally, the PluginConfig gains sections for intelligent model routing (with tier-based selection, escalation, and alias overrides), external model support, company-context MCP contracts, and keyword-detector opt-outs, while renaming several legacy agent keys to reflect the current product identity.
src/shared · high confidence
LSP client now supports configurable request timeouts and Windows shell execution
The LSP client implementation in dist/tools/lsp now allows users to override the default 15-second request timeout via the OMC\_LSP\_TIMEOUT\_MS environment variable, providing better control over server responsiveness. Additionally, the client now correctly spawns language server processes on Windows using shell execution (shell: true) to resolve ENOENT errors with npm-installed .cmd scripts, ensuring reliable server startup on that platform.
dist/tools/lsp · high confidence
New planning artifact parsing and execution hint extraction
The dist/planning module now includes new artifact-names and artifacts utilities that standardize how planning files (PRDs and test specs) are identified and validated. These changes introduce structured parsing for artifact filenames (supporting kinds like 'prd', 'test-spec', 'deep-interview', and 'deep-interview-autoresearch') and implement logic to verify planning completeness by checking for required sections in the latest PRD and its matching test spec. Additionally, the system can now extract embedded launch hints from PRD files to determine approved execution commands for team or ralph modes, handling complex flag parsing and worker count extraction.
dist/planning · high confidence
New shared constants registry and expanded hook lifecycle tests
The dist/hooks package now includes a centralized constants registry (dist/constants) that defines canonical string values for modes (e.g., autopilot, team), tool categories (e.g., lsp, codex), and hook events (e.g., SessionStart, PreToolUse), replacing scattered literals. Additionally, the package ships new regression tests for the hook bridge: one ensures AskUserQuestion notifications fire at PreToolUse rather than PostToolUse, and another validates the background process guard logic, including enforcing max background task limits and permission checks for executor tasks.
dist/hooks · high confidence
Rebrand to Oh-My-ClaudeCode and add delegation and hook examples
The examples directory has been updated to reflect the product rebrand from 'Oh-My-Claude-Sisyphus' to 'Oh-My-ClaudeCode', updating all import paths (e.g., \oh-my-claudecode\), session creation functions (\createOmcSession\), and system prompt helpers (\getOmcSystemPrompt\). The default agent configuration has shifted from 'sisyphus' to 'omc', and specific agent models have been updated (e.g., \claude-sonnet-5\, \claude-opus-4-6\). Additionally, two new example files have been introduced: \delegation-enforcer-demo.ts\ demonstrates the automatic injection of model parameters for agent tasks and integration with pre-tool-use hooks, while \hooks.json\ provides a schema-compliant configuration for common automation patterns like auto-formatting, linting, and secret detection.
examples · high confidence
Rebuilt agent definitions with modular structure and expanded roles
The agent system in dist/agents has been rebuilt to use a modular file structure, with individual definitions for agents like analyst, architect, critic, designer, document-specialist, executor, explore, qa-tester, scientist, and tracer, alongside a consolidated definitions.js that registers all agents (including debugger, verifier, test-engineer, security-reviewer, code-reviewer, git-master, and code-simplifier) and provides the main orchestrator prompt. This change introduces new agent roles, standardizes metadata and prompt loading, and updates the orchestrator's available subagent list to 19 agents with explicit role disambiguation and deprecated alias mappings.
dist/agents · high confidence
Timestamped planning artifacts and canonical handoff matching
Planning outputs (PRDs and test specs) are now canonicalized with ISO timestamps in their filenames (e.g., prd-20260502T090000Z-alpha.md). The system reads artifacts from both .omc/plans and .omx/plans directories, preferring the lexicographically latest artifact across both roots. Timestamped PRDs strictly match only their corresponding timestamped test specs, while legacy un-timestamped files continue to match by slug. Planning completion gates now require both the latest PRD and its matched test spec to contain required sections (Acceptance criteria, Requirement coverage map, Unit coverage, Verification mapping).
src/planning · high confidence
Unified state management with legacy migration and stale-state cleanup
The state-manager module now standardizes state file locations to \.omc/state/{name}.json\ for local state and an XDG-aware global path for user state, while maintaining backward compatibility by reading from legacy locations (e.g., \\~/.omc/state\) when enabled. Users benefit from automatic migration of existing state files to the new standard locations, ensuring a clean transition. Additionally, the module introduces utilities to detect and deactivate stale states based on activity heartbeats and modification times, and provides cleanup functions to remove orphaned state files, improving disk hygiene and preventing issues with abandoned states.
dist/features/state-manager · high confidence
Updated default model versions and added forceInherit routing option
The built-in default for the HIGH model tier has been updated from Claude Opus 4.7 to Claude Opus 4.8, and the default Sonnet model has been upgraded from 4.5 to 4.6. Additionally, a new \forceInherit\ option has been added to the routing configuration, allowing users to bypass model routing and force sub-agents to inherit the parent session's model.
dist/config · high confidence
Workflow registry, alias resolution, and prompt projection parity
The workflow module now enforces a canonical registry and alias resolution system: legacy aliases (e.g., \release\, \psm\) route to Tier-0 targets (\omc-release\, \project-session-manager\) with session-scoped warnings, while retired aliases (e.g., \ultrawork\, \swarm\) no longer resolve. The registry defines six Tier-0 workflows (\plan\, \deep-interview\, \ralplan\, \execute\, \review\, \verify\) and four Tier-0 roles, applying risk-based gate policies (hard risks fail closed, others fail open) and a structured retirement policy. Deterministic registry projections and drift checks ensure installed skills/commands match the registry. Additionally, prompt projection parity tests verify that \docs/CLAUDE.md\ generates deterministic, digest-verified projections for \CLAUDE.md\ and \.github/CLAUDE.md\, ensuring build consistency and manifest validation.
src/workflow · high confidence
Fixes
Add TypeScript type definitions for safe-regex
Added TypeScript declaration file for the safe-regex library to enable type-safe usage of its validation function within the codebase.
src/types · high confidence
Cross-platform process management and identity verification
The platform module now provides robust, cross-platform utilities for managing and verifying process lifecycles. It introduces precise process start-time identity checks to detect PID reuse, including high-precision DMTF timestamp parsing for Windows and locale-safe probes for macOS. Process termination is now safer and more reliable: owned process groups on Unix are terminated by group ID with strict identity verification (preventing accidental termination of unrelated processes), while Windows uses a fallback strategy beyond WMIC. The module also consolidates process existence checks with proper EPERM handling and adds a centralized platform detection utility.
src/platform · high confidence
Harden permission-handler security and reliability
The permission handler now enforces stricter security by removing file-reading commands (cat, head, tail) from auto-allowed safe patterns and expanding the regex for dangerous shell metacharacters to prevent command injection. It also improves reliability by adding support for swarm markers, allowing read-only GitHub issue/PR commands, and hardening subagent-tracker logic to prevent state isolation issues.
src/hooks/permission-handler · high confidence
New standalone hook library with robust state, I/O, and platform-specific fixes
The templates/hooks/lib directory now includes a comprehensive set of self-contained JavaScript modules that power the hook runtime. These changes introduce atomic file writes with emergency journaling to prevent data corruption, bounded Git timeouts to prevent indefinite hangs, and platform-specific stdin reading with strict timeouts to resolve Linux and Windows freeze issues. The library also adds a new config-dir module that respects the CLAUDE\_CONFIG\_DIR environment variable, a model-routing-override message for non-standard providers, and hardened precompact restore/publisher logic with canonical path verification and integer mtime normalization. Additionally, it includes a state-lock template that fails closed if unprovisioned, a skill-entitlements visibility check, and a workflow-profile-runtime that validates autopilot stage sequences and hashes. These modules collectively fix session state isolation, restore provenance, and improve reliability across Windows, Linux, and macOS.
templates/hooks · high confidence
Port rules-injector hook with fixes for unbounded directory walks and CRLF parsing
The rules-injector hook, ported from oh-my-opencode, is now available to automatically inject project and user-level rule files (from .github, .cursor, .claude, and CLAUDE\_CONFIG\_DIR) when you use read, write, edit, or multiedit tools. This release includes two key fixes: it prevents the rule finder from walking up to the filesystem root when no project root is detected, ensuring only rules in the current file's directory are considered; and it correctly parses multi-line rule arrays in YAML frontmatter authored on Windows with CRLF line endings, preventing rules from silently applying to no files.
src/hooks/rules-injector · high confidence
Prevents API errors from missing thinking blocks in assistant messages
A new proactive hook validates message structure before sending requests to the Anthropic API, specifically for models supporting extended thinking (e.g., Claude Sonnet 4, Opus 4). It detects assistant messages that contain content parts but lack a required thinking block and automatically inserts a synthetic thinking block to prevent the 'Expected thinking/redacted\_thinking but found tool\_use' error. This fix also addresses issue \#1386 by ensuring that stale reasoning from prior turns is not incorrectly carried forward into subsequent messages.
src/hooks/thinking-block-validator · high confidence
Test coverage
Added comprehensive test coverage for session-end hooks; Added comprehensive test coverage for state management, path resolution, and safety guards; Added comprehensive test coverage for the Project Memory Hook; Added comprehensive test coverage for the Wiki hook subsystem; Added comprehensive test suite for the rate-limit-wait feature; Added comprehensive tests for skill-state management logic; Added contract-authored tests for Graph Core descriptor validation and scheduler logic; Added integration tests for custom webhook and CLI dispatch; Added integration tests for state cancellation and deepinit manifest scanning; Added prompt validation test helpers; Added regression tests for Jira provider CLI flags and prompt injection context; Added regression tests for Windows compatibility and config directory portability in skills; Added regression tests for skill markdown portability and correctness; Added test coverage for AST tools, skills tools, and trace tools; Added test coverage for CLI commands; Added test coverage for HUD elements and utilities; Added test coverage for agent contracts, registry, and handoffs; Added test coverage for autoresearch contracts, runtime, and setup validation; Added test coverage for graph runtime v2 components; Added test coverage for notification system components; Added test coverage for team activity logging, task allocation, and API interop; Added test coverage for the Mnemosyne skill-learning subsystem; Added test coverage for the learner hook bridge, parser, and transliteration logic; Added test coverage for the multi-provider git hosting abstraction; Added test fixtures for hook lifecycle and transcript validation; Added tests for CLI ask and autoresearch-guided modules; Added tests for CLI capabilities locking, doctor team routing, and team role shorthand; Added tests for Graph Core descriptor validation and scheduler execution; Added tests for HUD agent kind classification and background task management; Added tests for LSP client devcontainer support, eviction logic, and byte-length handling; Added tests for LSP diagnostics aggregation; Added tests for MCP prompt injection guards, tool-list drift, shutdown, and team cleanup; Added tests for Ralphthon CLI, Orchestrator, and PRD modules; Added tests for agent registry, advisory output contracts, and artifact descriptor handoffs; Added tests for atomic write and mode state I/O; Added tests for autoresearch contract parsing and runtime outcome decisions; Added tests for checkpoint, Jev shadow routing, and magic keywords; Added tests for config loader and model detection logic; Added tests for config loader, model detection, and plan output paths; Added tests for config resolution, deduplication, and dead-pane guard; Added tests for delegation routing fallback and deprecation handling; Added tests for delegation routing resolver fallback logic; Added tests for interop bridge gating, artifact handling, and workspace path resolution; Added tests for magic keywords feature; Added tests for model routing and prompt adaptation; Added tests for multi-repo ultragoal artifact anchoring; Added tests for notification config merging and validation; Added tests for permission-handler command safety and injection prevention; Added tests for planning artifact reading and completeness validation; Added tests for plugin-patterns validation and session-end cleanup; Added tests for process identity and termination utilities; Added tests for python\_repl bridge cleanup, sandbox enforcement, and documentation parity; Added tests for rate-limit-wait daemon and integration flows; Added tests for self-improve session isolation; Added tests for session-scoped state isolation in mode registry; Added tests for setup hook state pruning, stdin symlink healing, and Windows hook patching; Added tests for state-manager cache behavior; Added tests for team activity logging, task allocation, and API cleanup behavior; Added tests for the alias-retirement closure and policy logic; Added tests for the auto-learner and skill matcher modules; Added tests for the learner hook bridge, parser, and transliteration map; Added tests for the think-mode hook logic; Added tests for ultragoal multi-repo workspace artifact handling; Added tests for utility functions in dist/utils; Added unit tests for agent and command node executors; Expanded test coverage for CLI, launch, and autoresearch subsystems; Expanded test coverage for HUD agent kind, background tasks, and usage elements; Expanded test coverage for hook bridge and orchestration logic; Expanded test coverage for new orchestration and workspace features; HUD test coverage for new status elements and state management; Installer CLAUDE.md handling tests added; Installer CLAUDE.md merge and transaction logic gains comprehensive regression tests; New test suite for tools directory state, memory, and wiki behavior; Session-scoped idle notifications and new persistent-mode test coverage; Test coverage for persistent-mode hook edge cases and regressions.
Dependencies
Major version upgrade to 5.5.0 with expanded runtime and dependency support
The product has been upgraded to version 5.5.0, introducing support for Node.js versions 20 through 26. This release adds several new runtime dependencies, including the Model Context Protocol SDK, Better-SQLite3 for local storage, AJV for JSON validation, and safe-regex. It also introduces new CLI entry points (omc, omc-cli) and expands the build system with scripts for team server, bridge, and prompt generation. Test and benchmarking capabilities are enhanced with the addition of a Python benchmark environment and updated TypeScript testing tools.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 40 → 55 (+15.3)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 45 → 61 (+15.9)
- Architecture 56 → 51 (-5.2)
- Maturity 69 → 80 (+10.7)
- Readiness 27 → 53 (+26.6)
- Security 60 → 76 (+16.6)
- Performance 60 (new)
Resolved (398)
- (anonymous) (cognitive 17) (bridge/team-mcp.cjs)
- (anonymous) (cognitive 18) (bridge/team-mcp.cjs)
- (anonymous) (cognitive 19) (bridge/runtime-cli.cjs)
- (anonymous) (cognitive 24) (bridge/runtime-cli.cjs)
- (anonymous) (cognitive 25) (bridge/team-mcp.cjs)
- (anonymous) (cognitive 25) (templates/hooks/keyword-detector.mjs)
- (anonymous) (cognitive 33) (bridge/runtime-cli.cjs)
- (anonymous) (cognitive 33) (templates/hooks/keyword-detector.mjs)
- (anonymous) (cyclomatic 16) (templates/hooks/keyword-detector.mjs)
- (anonymous) (cyclomatic 17) (bridge/runtime-cli.cjs)
- (anonymous) (cyclomatic 19) (templates/hooks/keyword-detector.mjs)
- (anonymous) (cyclomatic 22) (bridge/runtime-cli.cjs)
- (anonymous) (cyclomatic 25) (bridge/team-mcp.cjs)
- (anonymous) (cyclomatic 30) (bridge/runtime-cli.cjs)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Critical CVE: [GHSA redacted] (package-lock.json)
- Dimension evaluation failed
- FileTooLong: tests/post-tool-verifier.test.mjs (src/tests/post-tool-verifier.test.mjs)
- FileTooLong: bridge/claude-md-coordinator.cjs (bridge/claude-md-coordinator.cjs)
- FileTooLong: bridge/runtime-cli.cjs (bridge/runtime-cli.cjs)
- …and 378 more
New (397)
- Coverage not measured — JavaScript/TypeScript suite
- Decision is a thin one-line statement with no context (why replace heuristics with Jev) and no consequences/trade-offs (docs/adr/03665-jev-degradation-contract.md)
- Decision is real but consequences/trade-offs are unstated: why one-shot child-process over stdin JSON rather than in-process TS imports or a local daemon; what happens if the resolver ever blocks tool execution (docs/adr/03671-script-side-judgment-channel.md)
- Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
- Documentation: no project overview (docs/AGENTS.md)
- Further orphaned files (smaller)
- Further sole-owners (lower concentration)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 377 more
Changes since last survey
- 300 commits — 135 feature/other, 165 fixes
By area
- inventory/inventory-graph.json — 94 commits
- src/features — 59 commits
- (repo) — 39 commits
- src/tests — 16 commits
- .github/generated-artifact-authorizations.json — 9 commits
- dist/lib — 7 commits
- src/team — 7 commits
- src/workflow — 7 commits
- src/cli — 6 commits
- src/hooks — 6 commits
- src/lib — 4 commits
- src/utils — 4 commits
- (root) — 3 commits
- dist/hooks — 3 commits
- dist/team — 3 commits
- docs/shipyard.md — 3 commits
- src/graph — 3 commits
- src/notifications — 3 commits
- src/tools — 3 commits
- .github/release-body.md — 2 commits
Notable commits
- fix: Merge PR #3994 round-ten fixes and review fixes
- fix: Merge contributor round-eleven fixes without duplicate logic
- fix: Merge pull request #3921 from Yeachan-Heo/fix/issue-3920-windows-supervisor-stdio
- fix: Merge pull request #3927 from Yeachan-Heo/fix/issue-3926-notepad-tag-regex
- fix: Merge pull request #3928 from Yeachan-Heo/fix/issue-3923-hooks-pertool-cost
- fix: Merge pull request #3929 from Yeachan-Heo/fix/issue-3924-lsp-diagnostics-directory
- fix: Merge pull request #3930 from Yeachan-Heo/fix/issue-3925-session-search-buffering
- fix: Merge pull request #3932 from Yeachan-Heo/fix/issue-3922-hud-toplevel-memoization
- fix: Merge pull request #3974 from Yeachan-Heo/fix-3972-windows-tick-precision
- fix: Merge pull request #3983 from iyoda/fix/cursor-codex-startup-grace
- fix: Merge pull request #3997 from iyoda/fix/team-leader-terminal-pid-safety
- fix: Merge pull request #3999 from Iams4kura/bugfix/hud-model-date-suffix-20260909t040218z
- fix: Merge remote-tracking branch 'origin/dev' into fix/issue-3923-hooks-pertool-cost
- fix: chore(inventory): refresh graph after SQL regression
- fix: chore(inventory): refresh graph after lookout review fixes
- fix: chore(inventory): refresh inventory graph after lookout review fixes
- fix: chore(inventory): refresh inventory graph after lookout round-10 fixes
- fix: chore(inventory): refresh inventory graph after lookout round-11 fixes
- fix: chore(inventory): refresh inventory graph after lookout round-3 fixes
- fix: chore(inventory): refresh inventory graph after lookout round-4 fixes
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Yeachan-Heo/oh-my-claudecode was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9fd35ece5d6de65b511bf43b55e42c499e4fc194 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.