omk
Health Gecti
- License — License: MIT
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Community trust — 122 GitHub stars
Code Basarisiz
- fs module — File system access in .github/workflows/approve-contributor.yml
- exec() — Shell command execution in .omk/extensions/prompt-url-widget.ts
Permissions Gecti
- Permissions — No dangerous permissions requested
This tool is a multi-agent orchestration harness designed for the Kimi Code CLI. It manages parallel coding teams in isolated Git worktrees, utilizing DAG planning and enforcing quality gates to turn a single prompt into a complete, reviewable project.
Security Assessment
Risk Rating: Low to Medium
The core application does not request dangerous permissions. However, the repository contains several code execution flags. The automated rule-based scan failed because internal maintenance scripts (`package-audit.mjs`, `run-tests.mjs`, `smoke-test.mjs`) use synchronous shell execution (`execSync`, `spawnSync`) and access environment variables. Additionally, file system access is used in the GitHub workflows and `package.json`. These flagged operations are standard for a Node.js development environment running automated tests and packaging, rather than indicators of malicious behavior. There is no evidence of hardcoded secrets or unauthorized network requests.
Quality Assessment
Overall, the project demonstrates strong health and active maintenance. It is licensed under the permissive MIT license, making it highly accessible for most projects. The repository is actively maintained, with the most recent push occurring today. It has garnered 47 GitHub stars, indicating a fair level of early community trust and visibility. Furthermore, the project is tagged as a stable release (v1.1.0) and is fully compatible with a wide array of popular AI developer CLIs like Cursor and Claude Code.
Verdict
Use with caution. While the tool itself is actively maintained, MIT-licensed, and safe for use, users should be aware that the underlying developer scripts rely on direct shell execution and environment variable access.
Evidence-gated runner for Codex, Claude Code, OpenCode, and local coding agents. Routes tasks into scoped DAG lanes with replayable artifacts.
OMK
OMK//CONTROL — provider-neutral multi-agent control plane for coding workflows.
Models execute. OMK routes, verifies, measures, and controls.
New issues and PRs from new contributors are auto-closed by default. Maintainers review auto-closed issues daily. See CONTRIBUTING.md.
OMK Agent Harness Mono Repo
This is the home of the omk agent harness project including our self extensible coding agent.
- open-multi-agent-kit: Interactive coding agent CLI
- omk-agent-core: Agent runtime with tool calling and state management
- omk-ai: Unified multi-provider LLM API (OpenAI, Anthropic, Google, …)
To learn more about omk:
- Visit omk.dev, the project website with demos
- Read the documentation, but you can also ask the agent to explain itself
OMK//CONTROL TUI
The OMK//CONTROL startup surface is the default operator view. The header reads omk v<package.version> · OMK//CONTROL, using the published open-multi-agent-kit package version as the single source of truth.
The default dark TUI theme uses the omk-control-grid-dark Night City palette and keeps the control sidebar focused on route, evidence, loop, MCP, runtime, skills, and context budget state.
Slash commands, packages, and skills (load them hard)
OMK is most useful when packages and skills are installed up front, then invoked with / slash commands and bang skills (!skill:name, !omk-loop).
Browse community packages at pi.dev/packages. Install into the user agent (~/.omk/agent/settings.json) with pinned versions for stability:
# Context + web + code intelligence
omk install npm:@hypabolic/[email protected]
omk install npm:[email protected]
omk install npm:[email protected]
omk install npm:[email protected]
omk install npm:@ff-labs/[email protected]
omk install npm:@mrclrchtr/[email protected]
omk install npm:@mrclrchtr/[email protected]
# Plan / goal / task loops
omk install npm:@mjasnikovs/[email protected]
omk install npm:@narumitw/[email protected]
omk install npm:@narumitw/[email protected]
omk install npm:@plannotator/[email protected]
# Operator UX + quality
omk install npm:@ayulab/[email protected]
omk install npm:@juicesharp/[email protected]
omk install npm:@juicesharp/[email protected]
omk install npm:[email protected]
omk install npm:[email protected]
# Optional: refresh git/npm package checkouts
omk update --extensions
omk list
After install, open a fresh omk session and hammer the slash surface:
| Slash | Package | What it does |
|---|---|---|
/plan |
@narumitw/pi-plan-mode |
Read-only plan collaboration mode |
/goal |
@narumitw/pi-goal |
Keep working a goal until marked complete |
/task, /task-list, /task-resume |
@mjasnikovs/pi-task |
Crash-safe task pipeline with verify gates |
/plannotator, /plannotator-review |
@plannotator/pi-extension |
Interactive plan / PR annotation review |
/rewind, /checkpoint, /tree |
@ayulab/pi-rewind |
Checkpoint navigation |
/todos |
@juicesharp/rpiv-todo |
Live todo overlay |
/hypa |
@hypabolic/pi-hypa |
Hypa context compression diagnostics |
/simplify |
pi-simplify |
Review recent edits for clarity |
/supi-context |
@mrclrchtr/supi-context |
Context usage report |
/fff-health, /fff-rescan |
@ff-labs/pi-fff |
Fuzzy file/content search health |
/shazam-doctor |
pi-shazam |
Structural codebase awareness doctor |
/powerline |
pi-powerline-footer |
Status bar controls |
/think auto |
built-in | Automatic reasoning-effort routing (v4) |
Skills ecosystem (in addition to OMK-native packs):
# Discover
npx skills find "plan review"
npx skills find "react performance"
# Install globally (user-level), skip prompts
npx skills add vercel-labs/agent-skills --skill vercel-optimize -g -y -a '*'
npx skills add vercel-labs/agent-skills --skill vercel-react-view-transitions -g -y -a '*'
npx skills add vercel-labs/agent-skills --skill writing-guidelines -g -y -a '*'
# Enable / disable package resources in the TUI
omk config
Inside OMK, prefer minimum necessary skills per turn (usually 1–3). Load heavy packs on demand with bang syntax, for example !omk-loop, !skill:programming, !skill:debugging. Do not bulk-load the entire catalog into every session — that burns context without improving routing.
Hypa (optional, pairs with @hypabolic/pi-hypa):
hypa init --global --agent pi
hypa doctor
Release v0.90.6
This release documents the operator package/slash loadout (with the omkgirl hero asset), lands the experimental B2C Correctness Wall and Grok OAuth harness wiring, and continues the v4 reasoning-router generalization track.
| Area | What changed |
|---|---|
| Docs / loadout | Root README now documents pinned pi.dev package installs, slash-command map, and skills.sh install flow; added readmeasset/omkgirl.png. |
| Correctness Wall | Experimental B2C Correctness Wall extension with soft/hard/shadow modes; evidence-gated advisory evaluation only. |
| Grok harness | Grok OAuth domain profile, playbook auto-apply, grok-4.5 compaction preference, Imagine chat-model rejection on completion paths. |
| Extension host | callMcpTool bind path for extensions at load time. |
| Reasoning router | Table-driven intent clusters + normalize module and governed held-out generalization gate. |
GitHub-focused release notes live in .github/RELEASE_NOTES_v0.90.6.md. The GitHub release workflow also extracts the canonical release body from packages/coding-agent/CHANGELOG.md.
Share your OSS coding agent sessions
If you use OMK or other coding agents for open source work, publish sanitized sessions from .omk/agent/sessions.
Public OSS session data helps improve coding agents with real-world tasks, tool use, failures, and fixes instead of toy benchmarks.
All Packages
| Package | Description |
|---|---|
| omk-ai | Unified multi-provider LLM API (OpenAI, Anthropic, Google, etc.) |
| omk-agent-core | Agent runtime with tool calling and state management |
| open-multi-agent-kit | Interactive coding agent CLI |
| omk-tui | Terminal UI library with differential rendering |
For Slack/chat automation and workflow integrations, use OMK extensions and MCP servers.
Adaptorch MCP integration
AdaptOrch MCP is a separate, proprietary reliability-kernel service (not part of
this monorepo) that OMK can route orchestration tasks through: topology-aware DAG routing, multi-model
synthesis, and consistency verification. It is versioned 0.1.0 — an MVP stage — with a public-ready free
Starter tier and paid Pro/Team tiers, and is backed by a published paper
(arXiv:2602.16873).
The adaptorch and adaptorch-prod MCP servers plus the adaptorch-route and adaptorch-synthesize skills
ship in OMK's default omk-core-verified execution preset, so they are available from the first prompt of a
default session without extra setup. Actually invoking AdaptOrch (e.g. adaptorch_run) still requires anADAPTORCH_CONTROL_PLANE_TOKEN (a dev token is auto-set for a local control plane at 127.0.0.1:8000) and
follows normal task-routing rules rather than firing on every message.
This is distinct from packages/adaptorch-wpl in this monorepo, an experimental, design-stage Work Packet
Loop package that is not yet wired into the open-multi-agent-kit CLI — see that package's own README for its
current status.
Permissions & Containerization
OMK does not include a built-in permission system for restricting filesystem, process, network, or credential access. By default, it runs with the permissions of the user and process that launched it.
If you need stronger boundaries, containerize or sandbox OMK. See packages/coding-agent/docs/containerization.md for three patterns:
- OpenShell: run the whole
omkprocess in a policy-controlled sandbox. - Gondolin extension: keep
omkand provider auth on the host while routing built-in tools and!commands into a local Linux micro-VM. - Plain Docker: run the whole
omkprocess in a local container for simple isolation.
Contributing
See CONTRIBUTING.md for contribution guidelines and AGENTS.md for project-specific rules (for both humans and agents).
Development
npm install --ignore-scripts # Install all dependencies without running lifecycle scripts
npm run build # Build all packages
npm run check # Lint, format, and type check
./test.sh # Run tests (skips LLM-dependent tests without API keys)
./omk-test.sh # Run OMK from sources (can be run from any directory)
Supply-chain hardening
We treat npm dependency changes as reviewed code changes.
- Direct external dependencies are pinned to exact versions. Internal workspace packages remain version-ranged.
.npmrcsetssave-exact=trueandmin-release-age=2to avoid same-day dependency releases during npm resolution.package-lock.jsonis the dependency ground truth. Pre-commit blocks accidental lockfile commits unlessOMK_ALLOW_LOCKFILE_CHANGE=1is set.npm run checkverifies pinned direct deps, native TypeScript import compatibility, and the generated coding-agent shrinkwrap.- The published CLI package includes
packages/coding-agent/npm-shrinkwrap.json, generated from the root lockfile, to pin transitive deps for npm users. - Release smoke tests use
npm run release:localto build, pack, and create isolated npm and Bun installs outside the repo before tagging a release. - Local release installs, documented npm installs, and
omk update --selfuse--ignore-scriptswhere supported. - CI installs with
npm ci --ignore-scripts, and a scheduled GitHub workflow runsnpm audit --omit=devplusnpm audit signatures --omit=dev. - Shrinkwrap generation has an explicit allowlist for dependency lifecycle scripts; new lifecycle-script deps fail checks until reviewed.
License
MIT
Yorumlar (0)
Yorum birakmak icin giris yap.
Yorum birakSonuc bulunamadi