agents

package
v0.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: MIT Imports: 23 Imported by: 0

Documentation

Overview

Package agents is the jevkit hook framework and per-agent adapters.

`jevkit hook <agent> <event>` reads a JSON payload on stdin, dispatches to an Agent adapter, and prints a JSON response. Hooks must never break the calling agent: the runner recovers panics, enforces a hard timeout, fails open on garbage input or protocol-version mismatch, and exits 0 with a valid empty/allow response unless the adapter deliberately denies.

Index

Constants

View Source
const (
	CodexPreToolMarker  = "_runtime dispatch --protocol 1 codex pre-tool"
	CodexPostToolMarker = "_runtime dispatch --protocol 1 codex post-tool"
)

CodexPreToolMarker / CodexPostToolMarker are the full event tokens.

View Source
const (
	CursorPreToolMarker  = "_runtime dispatch --protocol 1 cursor pre-tool"
	CursorPostToolMarker = "_runtime dispatch --protocol 1 cursor post-tool"
)

CursorPreToolMarker / CursorPostToolMarker are the full event tokens.

View Source
const (
	OutcomeOK              = "ok"
	OutcomeDeny            = "deny"
	OutcomePassthrough     = "passthrough"
	OutcomePanic           = "panic"
	OutcomeTimeout         = "timeout"
	OutcomeVersionMismatch = "version_mismatch"
	OutcomeGarbage         = "garbage"
	OutcomeUnknownAgent    = "unknown_agent"
	OutcomeHalt            = "halt"
	OutcomeLatched         = "latched"
)

Outcome codes recorded in hook telemetry.

View Source
const AntigravityHookMarker = "_runtime dispatch --protocol 1 antigravity"

AntigravityHookMarker is the idempotency substring for managed entries in .agents/hooks.json. Installer matching is substring-based so a binary-path change still replaces the prior entry instead of duplicating.

View Source
const AntigravityHooksGroup = "jevkit"

AntigravityHooksGroup is the top-level group key written into .agents/hooks.json (ralph uses "ralph-native"; jevkit owns its own group).

View Source
const AntigravityName = "antigravity"

Antigravity adapter name used by installed runtime integrations.

View Source
const AntigravityPostToolMarker = "_runtime dispatch --protocol 1 antigravity post-tool"

AntigravityPostToolMarker is retained for removal of old telemetry hooks.

View Source
const AntigravityPreToolMarker = "_runtime dispatch --protocol 1 antigravity pre-tool"
View Source
const ClaudeHookMarker = "_runtime dispatch --protocol 1 claude post-tool"

Managed hook command token used as an idempotency marker inside Claude settings files. Installer matching is substring-based on this token so a binary-path change still replaces the prior entry instead of duplicating. Full command is `<binary> _runtime dispatch --protocol 1 claude post-tool`.

View Source
const ClaudeName = "claude"

Claude adapter name used by installed runtime integrations.

View Source
const ClaudePreHookMarker = "_runtime dispatch --protocol 1 claude pre-tool"
View Source
const CodexHookMarker = "_runtime dispatch --protocol 1 codex"

CodexHookMarker is the idempotency substring for managed entries in .codex/hooks.json. Installer matching is substring-based so a binary-path change still replaces the prior entry instead of duplicating.

View Source
const CodexName = "codex"

Codex adapter name used by installed runtime integrations.

View Source
const CursorHookMarker = "_runtime dispatch --protocol 1 cursor"

CursorHookMarker is the idempotency substring for managed entries in .cursor/hooks.json. Installer matching is substring-based so a binary-path change still replaces the prior entry instead of duplicating.

View Source
const CursorName = "cursor"

Cursor adapter name used by installed runtime integrations.

View Source
const DefaultTimeout = 5 * time.Second

DefaultTimeout is the hard upper bound for one hook dispatch. Hooks fire on every tool call, so adapters must stay well under this.

View Source
const OpenCodeHookMarker = "_runtime dispatch --protocol 1 opencode"

OpenCodeHookMarker identifies the plugin's private runtime dispatcher call.

View Source
const OpenCodeName = "opencode"

OpenCode adapter name used by the installed plugin.

View Source
const OpenCodePluginFile = "jevkit-runtime-hooks.ts"

OpenCodePluginFile is the staged plugin basename under .opencode/plugins/.

View Source
const OpenCodePluginMarker = "JEVKIT_OPENCODE_PLUGIN"

OpenCodePluginMarker is the idempotency / ownership token embedded in the staged TypeScript plugin. Installer matching is substring-based.

View Source
const ProtocolVersion = 1

ProtocolVersion is the stdin JSON protocol this build speaks. A payload that declares a different version fails open (passthrough, exit 0).

Variables

View Source
var DetectBins = map[string][]string{
	ClaudeName:      {"claude"},
	CursorName:      {"cursor-agent", "cursor"},
	CodexName:       {"codex"},
	OpenCodeName:    {"opencode"},
	AntigravityName: {"agy", "gemini"},
}

DetectBins maps adapter Name() -> PATH binaries that mean the agent is installed. First hit wins for doctor display.

View Source
var HookMarker = map[string]string{
	ClaudeName:      ClaudeHookMarker,
	CursorName:      CursorHookMarker,
	CodexName:       CodexHookMarker,
	OpenCodeName:    OpenCodePluginMarker,
	AntigravityName: AntigravityHookMarker,
}

HookMarker is the idempotency substring for each adapter's managed hooks.

Functions

func BuildShellWrapperCommand

func BuildShellWrapperCommand(binary, workspace, command, runtime string) string

BuildShellWrapperCommand returns a shell-safe invocation of the private wrapper. The wrapper is invoked by the agent, rather than the hook, so its stdout is the tool result the agent sees.

func DetectLookPath

func DetectLookPath(name string, look func(string) (string, error)) (path string, ok bool)

DetectLookPath finds the first PATH hit for name's detect binaries.

func FormatPreviews

func FormatPreviews(previews []FilePreview) string

FormatPreviews renders unified diffs for changed previews.

func HookConfigPath

func HookConfigPath(name string, opts InstallOptions) (string, error)

HookConfigPath is the primary hooks/settings/plugin path for name.

func InstallMCP

func InstallMCP(name string, opts InstallOptions) error

InstallMCP merges the jevkit MCP server entry into the agent-specific client config. Idempotent; DryRun only reports a preview.

func IsShellWrapperCommand

func IsShellWrapperCommand(command string) bool

func MCPConfigPath

func MCPConfigPath(name string, opts InstallOptions) (string, error)

MCPConfigPath is where jevkit registers its MCP server for name.

func Names

func Names() []string

Names returns registered adapter names in unspecified order.

func Register

func Register(a Agent)

Register adds an adapter under its Name(). Later registrations replace earlier ones for the same name.

func ResolveScope

func ResolveScope(opts InstallOptions) string

ResolveScope returns "project" or "user" given opts.

func Run

func Run(ctx context.Context, agent Agent, event Event, in io.Reader, out io.Writer, opts Options) int

Run reads a JSON hook payload from in, dispatches to agent for event, writes the response JSON to out, and returns the process exit code. It always fails open: panics, timeouts, garbage stdin, version mismatches, and unknown agents/events yield a safe passthrough body and exit 0.

func SortedNames

func SortedNames() []string

SortedNames returns registered adapter names in stable order.

func UnifiedDiff

func UnifiedDiff(fromName, toName string, before, after []byte) string

UnifiedDiff renders a unified diff of two texts. Empty when equal.

func UninstallMCP

func UninstallMCP(name string, opts InstallOptions) error

UninstallMCP restores the MCP config from its first-install backup, or strips the jevkit entry when no backup exists.

Types

type Agent

type Agent interface {
	Name() string
	Capabilities() Capabilities
	HandlePreTool(ctx context.Context, req Request) (Response, error)
	HandlePostTool(ctx context.Context, req Request) (Response, error)
	HandleStop(ctx context.Context, req Request) (Response, error)
	// Passthrough is the fail-open JSON body for event (empty/allow). It must
	// always be valid JSON the agent accepts as "do nothing".
	Passthrough(event Event) []byte
	Install(opts InstallOptions) error
	Uninstall(opts InstallOptions) error
}

Agent is one coding-agent adapter.

func Lookup

func Lookup(name string) Agent

Lookup returns the adapter registered as name, or nil.

func SelectAgents

func SelectAgents(target string, look func(string) (string, error), detectedOnly bool) ([]Agent, error)

SelectAgents resolves "all" or a single name against the registry. When all is true and detectedOnly is set, only agents found on PATH are returned (explicit names always resolve regardless of detection).

func SupportedInstallAgents

func SupportedInstallAgents(in []Agent) []Agent

SupportedInstallAgents is the set of adapters available for new installs.

type Antigravity

type Antigravity struct {
	// Binary is the jevkit executable name/path used in rewrites and install
	// commands. Empty means "jevkit".
	Binary          string
	Security        *config.Config
	SecurityDecider *registry.Decider
	StateDir        string
}

Antigravity is the Antigravity (agy) adapter.

Spike (docs/AGENT-CAPABILITIES.md): PreToolUse run_command rewrite via overwrite.CommandLine is the compaction path. PostToolUse carries only stepIdx/error — no output replacement. A decision must always be printed.

func NewAntigravity

func NewAntigravity() *Antigravity

NewAntigravity returns an Antigravity adapter.

func (*Antigravity) Capabilities

func (a *Antigravity) Capabilities() Capabilities

func (*Antigravity) HandlePostTool

func (a *Antigravity) HandlePostTool(ctx context.Context, req Request) (Response, error)

func (*Antigravity) HandlePreTool

func (a *Antigravity) HandlePreTool(ctx context.Context, req Request) (Response, error)

func (*Antigravity) HandleStop

func (a *Antigravity) HandleStop(ctx context.Context, req Request) (Response, error)

func (*Antigravity) Install

func (a *Antigravity) Install(opts InstallOptions) error

Install merges Antigravity hooks into .agents/hooks.json (project) or <ConfigDir>/.agents/hooks.json (user). It is idempotent: a second apply leaves a single managed group. DryRun computes the merge without writing.

func (*Antigravity) Name

func (a *Antigravity) Name() string

func (*Antigravity) Passthrough

func (a *Antigravity) Passthrough(event Event) []byte

func (*Antigravity) Uninstall

func (a *Antigravity) Uninstall(opts InstallOptions) error

Uninstall removes jevkit-managed Antigravity hooks and restores the hooks file to the byte-exact original captured on first install.

type ApplyReport

type ApplyReport struct {
	Agent    string
	Previews []FilePreview
}

ApplyReport is the outcome of InstallAgent / UninstallAgent.

func InstallAgent

func InstallAgent(a Agent, opts InstallOptions) (ApplyReport, error)

InstallAgent runs hook Install then MCP registration for one adapter.

func InstallAgentComponents

func InstallAgentComponents(a Agent, opts InstallOptions, components Components) (ApplyReport, error)

InstallAgentComponents installs only the selected, independently reversible integration components.

func UninstallAgent

func UninstallAgent(a Agent, opts InstallOptions) (ApplyReport, error)

UninstallAgent removes MCP registration then restores hook config.

func UninstallAgentComponents

func UninstallAgentComponents(a Agent, opts InstallOptions, components Components) (ApplyReport, error)

UninstallAgentComponents removes only components selected by the caller.

type Capabilities

type Capabilities struct {
	// PreTool is true when HandlePreTool may rewrite or decide on a tool call.
	PreTool bool
	// PostTool is true when HandlePostTool may replace or observe tool output.
	PostTool bool
	// Stop is true when HandleStop may block or continue a stop event.
	Stop bool
	// OutputReplace is true when PostTool can replace model-visible output.
	OutputReplace bool
	// PreToolRewrite is true when PreTool can rewrite the shell command into
	// `jevkit exec -- ...`.
	PreToolRewrite bool
}

Capabilities describes what an adapter supports.

type Claude

type Claude struct {
	// Getenv reads process env; nil means os.Getenv. Gates:
	// JEVKIT_COMPACT=1 enables compaction; JEVKIT_COMPACT_SHADOW=1 passes through.
	Getenv func(string) string
	// ThresholdBytes overrides the compact threshold; zero uses the default.
	ThresholdBytes int
	// Asker is the optional jev ranked-line tier; nil is deterministic-only.
	Asker compact.Asker
	// StateDir is forwarded to compact shadow logging (unused when shadow
	// passthrough skips compaction).
	StateDir        string
	Policy          *compact.Policy
	Security        *config.Config
	SecurityDecider *registry.Decider
}

Claude is the Claude Code adapter.

Spike (docs/AGENT-CAPABILITIES.md, testdata/hooks/claude/): PostToolUse:Bash payloads carry tool_response.{stdout,stderr,...} but no real exit code. Non-zero exits fire PostToolUseFailure without tool_response, so this adapter only replaces successful Bash output. Compaction assumes exit 0.

func NewClaude

func NewClaude() *Claude

NewClaude returns a Claude adapter wired to the process environment.

func (*Claude) Capabilities

func (c *Claude) Capabilities() Capabilities

func (*Claude) HandlePostTool

func (c *Claude) HandlePostTool(ctx context.Context, req Request) (Response, error)

HandlePostTool compacts PostToolUse:Bash tool_response when jev compaction is enabled, the combined output is above the size threshold, and shadow mode is off. Everything else fails open with `{}`.

func (*Claude) HandlePreTool

func (c *Claude) HandlePreTool(ctx context.Context, req Request) (Response, error)

func (*Claude) HandleStop

func (c *Claude) HandleStop(ctx context.Context, req Request) (Response, error)

func (*Claude) Install

func (c *Claude) Install(opts InstallOptions) error

Install merges the Claude PostToolUse:Bash hook into .claude/settings.local.json (project) or <ConfigDir>/.claude/settings.json (user). It is idempotent: a second apply leaves a single managed entry. DryRun computes the merge without writing.

func (*Claude) Name

func (c *Claude) Name() string

func (*Claude) Passthrough

func (c *Claude) Passthrough(event Event) []byte

func (*Claude) Uninstall

func (c *Claude) Uninstall(opts InstallOptions) error

Uninstall removes jevkit-managed Claude hooks and restores the settings file to the byte-exact original captured on first install.

type Codex

type Codex struct {
	// Binary is the jevkit executable name/path used in rewrites and install
	// commands. Empty means "jevkit".
	Binary string
	// Getenv reads process env; nil means os.Getenv. JEVKIT_COMPACT enables
	// result replacement, while JEVKIT_COMPACT_SHADOW preserves original output.
	Getenv func(string) string
	// ThresholdBytes overrides the compaction threshold; zero uses the default.
	ThresholdBytes int
	// Asker is the optional Jev ranked-line tier. A nil or unavailable client
	// fails open and preserves Codex's original tool result.
	Asker           compact.Asker
	StateDir        string
	Policy          *compact.Policy
	Security        *config.Config
	SecurityDecider *registry.Decider
}

Codex is the OpenAI Codex CLI adapter.

PostToolUse can replace Codex's model-visible result with hook feedback via continue:false. It cannot mutate Bash output in place, so this adapter emits an already-compacted local result as its stop reason. Any untrusted decision leaves the original result alone.

func NewCodex

func NewCodex() *Codex

NewCodex returns a Codex adapter.

func (*Codex) Capabilities

func (c *Codex) Capabilities() Capabilities

func (*Codex) HandlePostTool

func (c *Codex) HandlePostTool(ctx context.Context, req Request) (Response, error)

HandlePostTool is telemetry-only. Shell output is replaced by the pre-tool wrapper, which preserves the real exit status and raw original.

func (*Codex) HandlePreTool

func (c *Codex) HandlePreTool(ctx context.Context, req Request) (Response, error)

func (*Codex) HandleStop

func (c *Codex) HandleStop(ctx context.Context, req Request) (Response, error)

func (*Codex) Install

func (c *Codex) Install(opts InstallOptions) error

Install merges Codex hooks into .codex/hooks.json (project) or <ConfigDir>/.codex/hooks.json (user). It is idempotent: a second apply leaves a single managed set. DryRun computes the merge without writing.

func (*Codex) Name

func (c *Codex) Name() string

func (*Codex) Passthrough

func (c *Codex) Passthrough(event Event) []byte

func (*Codex) Uninstall

func (c *Codex) Uninstall(opts InstallOptions) error

Uninstall removes jevkit-managed Codex hooks and restores the hooks file to the byte-exact original captured on first install.

type Components

type Components struct {
	Hooks bool
	MCP   bool
}

Components selects independently installable integration pieces. Plugin is a user-facing bundle alias that resolves to hooks plus MCP; it is not passed to individual adapters.

func DefaultComponents

func DefaultComponents() Components

type Cursor

type Cursor struct {
	// Binary is the jevkit executable name/path used in rewrites and install
	// commands. Empty means "jevkit".
	Binary string
	// Getenv reads process env; nil means os.Getenv. Gates:
	// JEVKIT_COMPACT=1 enables post-tool compaction; JEVKIT_COMPACT_SHADOW=1
	// passes through post-tool replacements (pre-tool rewrite still applies).
	Getenv func(string) string
	// ThresholdBytes overrides the compact threshold; zero uses the default.
	ThresholdBytes int
	// Asker is the optional jev ranked-line tier; nil is deterministic-only.
	Asker compact.Asker
	// StateDir is forwarded to compact shadow logging.
	StateDir        string
	Policy          *compact.Policy
	Security        *config.Config
	SecurityDecider *registry.Decider
}

Cursor is the Cursor IDE / cursor-agent adapter.

Spike (docs/AGENT-CAPABILITIES.md): preToolUse Shell rewrite via updated_input.command is agent-visible. Shell postToolUse updated_tool_output is NOT agent-visible (telemetry only). Native Read/Grep/Glob and MCP:* results may be replaced via updated_tool_output / updated_mcp_tool_output.

func NewCursor

func NewCursor() *Cursor

NewCursor returns a Cursor adapter wired to the process environment.

func (*Cursor) Capabilities

func (c *Cursor) Capabilities() Capabilities

func (*Cursor) HandlePostTool

func (c *Cursor) HandlePostTool(ctx context.Context, req Request) (Response, error)

HandlePostTool handles Shell and native tools as telemetry only. Cursor's documented replacement field is updated_mcp_tool_output, so only MCP tool results may be compacted here.

Everything else fails open with `{}`.

func (*Cursor) HandlePreTool

func (c *Cursor) HandlePreTool(ctx context.Context, req Request) (Response, error)

func (*Cursor) HandleStop

func (c *Cursor) HandleStop(ctx context.Context, req Request) (Response, error)

func (*Cursor) Install

func (c *Cursor) Install(opts InstallOptions) error

Install merges Cursor hooks into .cursor/hooks.json (project) or <ConfigDir>/.cursor/hooks.json (user). It is idempotent: a second apply leaves a single managed set. DryRun computes the merge without writing.

func (*Cursor) Name

func (c *Cursor) Name() string

func (*Cursor) Passthrough

func (c *Cursor) Passthrough(event Event) []byte

func (*Cursor) Uninstall

func (c *Cursor) Uninstall(opts InstallOptions) error

Uninstall removes jevkit-managed Cursor hooks and restores the hooks file to the byte-exact original captured on first install.

type Event

type Event string

Event is a normalized runtime event used by installed integrations.

const (
	EventPreTool  Event = "pre-tool"
	EventPostTool Event = "post-tool"
	EventStop     Event = "stop"
)

type FilePreview

type FilePreview struct {
	Path   string
	Before []byte
	After  []byte
}

FilePreview is one planned or applied file edit for dry-run diffs and install reporting.

type InstallOptions

type InstallOptions struct {
	// WorkDir is the project root (project-scoped config).
	WorkDir string
	// ConfigDir is the user config home (user-scoped config).
	ConfigDir string
	// Scope is "project" or "user"; empty means project when WorkDir is set.
	Scope string
	// Binary is the absolute path to the jevkit binary to register.
	Binary string
	// DryRun reports the planned edit without writing.
	DryRun         bool
	InjectionGuard bool
	// Preview receives each planned file edit (hooks and, when used by the
	// installer, MCP configs). Called on dry-run and on write.
	Preview func(FilePreview)
}

InstallOptions configures Install/Uninstall of an agent's hook config.

type InstallState

type InstallState struct {
	Name     string
	Detected bool
	Binary   string // first PATH hit; empty when not detected
	Hooks    string // "not installed" | "project" | "user" | "project+user"
	MCP      string // same vocabulary
}

InstallState is per-agent install reporting for doctor.

func AllStates

func AllStates(workDir, homeDir string, look func(string) (string, error)) []InstallState

AllStates returns InstallState for every registered adapter in sorted order.

func StateOf

func StateOf(name string, workDir, homeDir string, look func(string) (string, error)) InstallState

StateOf reports detection and whether jevkit hooks/MCP are present.

type OpenCode

type OpenCode struct {
	// Binary is the jevkit executable name/path used in rewrites and the
	// staged plugin default. Empty means "jevkit".
	Binary         string
	Getenv         func(string) string
	ThresholdBytes int
	Asker          compact.Asker
	StateDir       string
	Policy         *compact.Policy
}

OpenCode is the OpenCode adapter.

Not a settings-file stdin hook: Install stages a TypeScript plugin under .opencode/plugins/ that shells out to `jevkit hook opencode ...`. The Go handlers below are what that plugin invokes.

func NewOpenCode

func NewOpenCode() *OpenCode

NewOpenCode returns an OpenCode adapter.

func (*OpenCode) Capabilities

func (o *OpenCode) Capabilities() Capabilities

func (*OpenCode) HandlePostTool

func (o *OpenCode) HandlePostTool(ctx context.Context, req Request) (Response, error)

func (*OpenCode) HandlePreTool

func (o *OpenCode) HandlePreTool(ctx context.Context, req Request) (Response, error)

HandlePreTool deliberately leaves input untouched.

func (*OpenCode) HandleStop

func (o *OpenCode) HandleStop(ctx context.Context, req Request) (Response, error)

func (*OpenCode) Install

func (o *OpenCode) Install(opts InstallOptions) error

Install stages the OpenCode TypeScript plugin under .opencode/plugins/jevkit-runtime-hooks.ts (project) or <ConfigDir>/.opencode/plugins/jevkit-runtime-hooks.ts (user). It is idempotent: a second apply leaves a single managed file. DryRun computes the rendered plugin without writing.

func (*OpenCode) Name

func (o *OpenCode) Name() string

func (*OpenCode) Passthrough

func (o *OpenCode) Passthrough(event Event) []byte

func (*OpenCode) Uninstall

func (o *OpenCode) Uninstall(opts InstallOptions) error

Uninstall removes the staged OpenCode plugin and restores any pre-install file captured on first install (or deletes the file when it was absent).

type Options

type Options struct {
	// Timeout is the hard upper bound; zero means DefaultTimeout.
	Timeout time.Duration
	// StateDir is the usage/telemetry state home (see usage.Path). Empty
	// disables telemetry unless AppendHook is set.
	StateDir string
	// LoadError is a policy-load failure recorded with this invocation.
	LoadError string
	// Now is the clock; nil means time.Now.
	Now func() time.Time
	// AppendHook records one invocation; nil uses usage.AppendHook when
	// StateDir is set. Tests inject a recorder here.
	AppendHook func(stateDir string, rec usage.HookInvocation) error
}

Options configures a single hook dispatch.

type ReplacementScope

type ReplacementScope string

ReplacementScope describes the narrowest model-visible result replacement contract supported by a runtime's documented post-tool API. It deliberately does not infer replacement from a pre-tool input rewrite.

const (
	ReplacementNone       ReplacementScope = "none"
	ReplacementMCPOnly    ReplacementScope = "mcp-only"
	ReplacementToolShapes ReplacementScope = "validated-tool-shapes"
)

type Request

type Request struct {
	// Raw is the original stdin bytes (valid JSON when the runner reached the
	// adapter; garbage never reaches adapters).
	Raw json.RawMessage
	// Event is the normalized CLI event.
	Event Event
	// ProtocolVersion is the version declared by the payload, or
	// ProtocolVersion when the field is absent.
	ProtocolVersion int
}

Request is one stdin payload delivered to an adapter.

type Response

type Response struct {
	Body    []byte
	Outcome string
	// Deny marks a deliberate policy denial (as opposed to a fail-open
	// passthrough). When true and ExitCode is 0, the process still exits 0
	// and the body carries the deny for agents that encode it in JSON.
	Deny bool
	// ExitCode overrides the process exit code for a deliberate deny. Zero
	// keeps the fail-open default of exit 0.
	ExitCode int
}

Response is the adapter's answer. Body is written to stdout as JSON. ExitCode is used only for a deliberate deny; fail-open paths always force 0.

type RuntimeCapability

type RuntimeCapability struct {
	Name               string
	PreToolDecision    bool
	Evidence           string
	PostToolOutput     bool
	AuthoritativeState string
	Replacement        ReplacementScope
	ContextInjection   bool
	Telemetry          bool
	Installation       string
	// ShellPolicyCoverage is true when the installed pre-tool hook actually
	// inspects and can rewrite an eligible shell call before it runs (see
	// IsShellWrapperCommand / buildSecurityShellWrapperCommand call sites).
	// OpenCode's plugin never receives a pre-tool event (HandlePreTool is a
	// documented no-op; see opencode.go and docs/AGENT-INTEGRATIONS.md), so its
	// shell calls are never policy-checked in this version. This must stay in
	// sync with PreToolDecision for every runtime that claims shell coverage;
	// see TestRuntimeCapabilityAuditMatchesAdapterClaims.
	ShellPolicyCoverage bool
	InjectionGuard      bool
}

RuntimeCapability is the evidence-backed contract used to decide what an adapter may do. Evidence dates identify when the vendor documentation was reviewed; they are not a claim that an unpinned runtime API is immutable.

func RuntimeCapabilities

func RuntimeCapabilities(name string) (RuntimeCapability, bool)

RuntimeCapabilities is intentionally separate from an adapter's legacy Capabilities flags. The latter describe implemented dispatch events; this table limits what those events may do as the integrations are revised.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL