Milestone v2.0: omp-native swarm (extension package, hooks, headless runtime, workspace install) - #2
SomeRandmGuyy wants to merge 141 commits into
Conversation
…contract failures
… and scripts over
…ent verdicts migration
…derived-prefix docs
…ed real key - envelope._dev_key_forbidden(): SWARM_ED25519_KEY set (loadable or not) or SWARM_REQUIRE_KEY=1 - verify_envelope hmac branch never falls back to dev-insecure-key when forbidden (CR-01, T-01-14/15) - envelope.signing_config_error(); make_verdict raises E-POLICY on missing/unloadable key before signing - tests/test_signing.py: forgery under Ed25519(+REQUIRE_KEY), unloadable seed, real HMAC/Ed25519 controls, gate-script key-config errors
…ashing reconcile - validate_envelope: E-CONTRACT for non-object envelope or non-string type/schema/priority/risk_class - verify_envelope: non-string sig -> False; strict base64 (validate=True), undecodable -> False - TaskStore._check_row: any exception while validating a row -> bad-sig (WR-07, T-01-28) - tests: int sig / null schema / bad base64 / non-object rows; record_verdict raises SwarmError only
…te dir - sign_envelope(env, *, root=None) -> _warn_dev_key(env, root) -> runlog.emit(root=root) - make_verdict(root=None); record_gate_verdicts(root=None); issue_gate passes root=ctx.root to both - maint_deps.cve_match(..., root) forwards ctx.root to sign_envelope - test: rev_gate --root app from cwd=other (no SWARM_DIR) writes the event to app/.swarm, no other/.swarm (IN-02, D-10)
…policy - dev-key signing emits security.dev_key into the resolved state dir - missing_gates verifies signed envelopes; malformed/forged rows read bad-sig - dev-key hmac refused under SWARM_ED25519_KEY or SWARM_REQUIRE_KEY=1; explicit key-config errors
…correlation with no tasks - orch_plan.py and orch_status.py accept --repo as an alias of --root, so plan, run and status resolve the same <repo>/.swarm from any cwd (D-09/D-10) - swarm_run.py exits 2 E-INPUT when the correlation has no tasks in the resolved tasks.db instead of reporting complete:true with empty counts - tests/test_operator_flow.py: documented plan→run→status flow from a foreign cwd uses one state dir; unknown correlation exits 2 (WR-01, verifier gap 3)
- CLAUDE.md / README.md: orch_plan, swarm_run (incl. --dry-run) and orch_status all take the same --repo, since state lives in <repo>/.swarm (D-09) - AGENTS.md: exported SWARM_DIR variant noted as what keeps the store shared, plus a no-SWARM_DIR --repo variant; orch_plan key-file line documents the derived T<4 hex> prefix (D-06); plan re-run gotcha now describes D-05 reuse / E-CONTRACT instead of a UNIQUE-constraint failure
…-repo, lease-before-delegate - prompts/A01-orchestrator.md: orch_plan example drops --prefix T (D-06); tools, in-session loop and workflow pass --repo <app> to orch_plan/orch_status/ swarm_run; ready tasks are leased (CLAIMED → IN_PROGRESS) before delegating; gate agents' scripts record verdicts, A01 never records them (D-12) - scripts/_write_skills.py: orchestrate plan command and A01 ingest/lease steps take --repo <app>; plan JSON checked under <app>/.swarm/plans/ - regenerated .claude/.grok A01 agents and the two affected skills
…R-09) - orch_plan without --prefix keeps T<4hex> when those tasks belong to this correlation, so re-runs reuse (reused: true) or exit 2 E-CONTRACT - 6-hex fallback only when the 4-hex tasks belong to another correlation - E-CONTRACT hint names --correlation-id or --prefix for derived prefixes - regression tests: three same-correlation runs keep 13 tasks; other brief exits 2
- new tasks record plan_sha256 (sha256 of the normalized plan rows) - reuse requires a matching plan_sha256; legacy rows fall back to brief+pattern for pattern plans and fail closed for custom plans - --plan always records pattern custom - regression tests: edited plan.json exits 2 with no writes; notes carry pattern custom and a 64-hex plan_sha256
…ssing (WR-11) - swarmDir catches the Bun.spawnSync error for an absent git and uses <root>/.swarm, matching swarm/paths.py's OSError fallback - regression test: req_lint.ts with PATH=/nonexistent prints its JSON result and exits 0/1
…rrent claimers wins (WR-02) - transition() reads, checks caps and writes under one BEGIN IMMEDIATE transaction - _apply UPDATE is conditional on the expected from-state (rowcount != 1 -> E-CONTRACT) - state change and transitions row commit together; rework-cap path is one unit - sqlite3.connect(timeout=30) so contenders wait for the write lock - tests/test_store_concurrency.py: 4-process claim race, crash-between-writes rollback
…ng gate rows (WR-03) - set_notes re-reads and writes notes inside store.transaction() - new TaskStore.append_feedback(task_id, entry) appends under one write lock - record_gate_verdicts records every gate_for row and fail feedback in one transaction (D-13) - results._agent_verdict_feedback uses append_feedback - tests: 4x25 feedback race keeps 100 entries, concurrent set_notes keeps both keys, unknown gate_for target leaves no rows
…encies (CR-03) - apply_result ingest auto-claim only for PLANNED/RETRY with deps_satisfied (checked with the claim in one transaction) - BLOCKED task in ingest -> E-CONTRACT; A01 releases it with orch_status --transition after approval - test_ingest_gate_result_no_rows leases X-qa before ingesting - tests: BLOCKED and unmet-dependency ingests exit 2 with history unchanged and task.result.rejected - AGENTS.md State writes: atomic transitions, transactional notes, ingest claim rules
…re-rework PASS reads stale (WR-04) - _check_row(self, task, gate, row, now): envelope correlation_id != task correlation -> mismatch; signed issued_at < notes.verdicts_since -> stale (outside _VERIFIED, reconcile ignores it) - latest_verdicts/missing_gate_reasons read the task once (_latest_rows, _gates_of) - resolve_targets(correlation_id=): a foreign --correlation-id / stale SWARM_CORRELATION_ID export -> E-POLICY before any write - record_gate_verdicts signs each target with the target's own correlation; issue_gate's file envelope uses ctx correlation, else the gate task's, else a minted one - tests: replay/cross-correlation/target-correlation/foreign-correlation regressions; make_verdict callers that must count pass correlation_id="c"
… scripts record only for leased gate tasks (CR-02) - resolve_targets: a gate task with targets must be IN_PROGRESS, else E-POLICY 'not a running gate task' - issue_gate(simulate): signed dry_run: true on the file envelope and every target verdict; rows only when the gate task's notes.dry_run is set (else gate.verdict.unrecorded 'dry-run outside a runner dry-run'); per-target findings = simulated + caller findings - _check_row: signed dry_run on a target without notes.dry_run -> 'dry-run' (outside _VERIFIED) - swarm_run execute_one sets notes dry_run=bool(args.dry_run) with running at dispatch (only writer) - rel_plan --dry-run reads release.freeze (never writes it) and fails every target with the freeze finding - tests: leased/flagged dry-run regressions, release dry-run freeze; existing gate tests lease G-q/G-r/X-qa
…a runner dry-run (CR-02) - A08/A09/A10/A12 acceptance: the gate script ran for real with the agent's own gate task --task-id; dry-run verdicts only count inside a runner --dry-run - graceful_degradation: never pass --dry-run unless task.assign says the plan is a runner dry-run - regenerated .claude/.grok agents (build_agents.py); Trae output unchanged (--check up-to-date)
…ation reasons - gate scripts record only for leased (IN_PROGRESS) gate tasks, target-correlation signed; foreign correlation → E-POLICY - dry-run verdicts signed dry_run: true, recorded/counted only inside swarm_run --dry-run - missing_gate_reasons vocabulary incl. stale and dry-run
There was a problem hiding this comment.
Stale comment
Agentic security review of this head found one high-severity control-plane gap: D-08 does not cover the runtime root\u2019s
omp/andscripts/trees that yolo specialist sessions can rewrite before the runner re-executes gate scripts with signing keys. Prior comments on nestedxd://ast_editpaths andcd/env -Cdirectory tracking were already addressed on this head.Sent by Cursor Security Agent: Security Reviewer
- quality/security: a target the agent omits gets only the script's findings; overall status fails when any recorded target verdict fails - guard: scope-accurate directory tracking (env -C per command, subshell and pipeline restore, pushd/popd stack); strip shell keywords and split on lone & Refs SPE-3798
- qa_gate derives its risk class from the gate task and its targets (runner and swarm_gate alike); unknown targets are skipped - guard protects the agent-swarm runtime root from sessions outside it; mv/rsync --remove-source-files sources count as mutations Refs SPE-3798
Gate scripts refuse per-target findings under ids that are not targets of the gate task (E-INPUT), so a stale or mistyped id cannot drop a blocker. Refs SPE-3798
There was a problem hiding this comment.
Stale comment
Agentic security review of this head found two D-08 containment bypasses in
omp/src/guard.ts: bash>|redirects are split as pipes (high), and BusyBox applet forms oftee/cpskip write-target detection (medium). Both are net-new versus prior review threads.Sent by Cursor Security Agent: Security Reviewer
Guard reads >|, 2>| and &>| as redirections, not pipes, and strips busybox/toybox before an applet name. Refs SPE-3798
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
There was a problem hiding this comment.
Stale comment
Agentic security review of the current head found one high-severity D-08 fail-open: command-substitution (and related lexical) write destinations are stripped from the parent shell line before
protected-path-shellruns. Direct literal redirects to.swarm/and the runtime root are already blocked.Sent by Cursor Security Agent: Security Reviewer
Guard fails closed on write targets it cannot judge lexically (substitutions, variables, protected-matching globs/braces), checks find -exec and other nested commands, dequotes argv0, and reads only unescaped >| as a redirection. Refs SPE-3798
Guard: only --dry-run[=client|server|true] exempts kubectl/helm; output-file flags are per command (grep -o writes nothing); command substitutions run as subshells of their holder instead of widening every relative write to an unknown directory. Refs SPE-3798
HOOK-02 rules parse attached/joined flag values, global options before subcommands, clustered short flags and verb synonyms; kubectl covers every mutating verb and destination flag. Refs SPE-3798
Guard re-parses eval/watch/parallel/sudo -i/env -S with all arguments joined; HOME/TMPDIR/CDPATH count as reassigned only on real assignments. Refs SPE-3798
Guard exemptions (dry-run, helm plugin, publish --dry-run, read-only subcommands, compressor stdout) count only in their syntactic slot, never after -- or as a flag value; interpreter flag values are never taken as the executed script. Refs SPE-3798
glob-dotfiles matches only commands that enable dotfile globbing, not mentions; /proc/self/fd/N and friends count as descriptor sinks. Refs SPE-3798
Dismissed because a newer commit was pushed; Greptile will re-review the current head.
| if (cmd === "unsetopt") return args.some((w) => dynamicWord(w) || /^no_?glob_?dots$/i.test(w.replace(/_/g, ""))); | ||
| const optionAfter = (flag: RegExp) => args.some((w, i) => flag.test(w) && args[i + 1] !== undefined && named(args[i + 1])); | ||
| if (cmd === "set" && optionAfter(/^-o$/)) return true; | ||
| if (/^[a-z]*sh$/.test(cmd) && (optionAfter(/^-[A-Za-z]*[Oo]$/) || args.some((w) => w.startsWith("--") && isDotglobOption(w.slice(2))))) return true; |
There was a problem hiding this comment.
Attached dotglob option bypasses guard
In a swarm session, bash -Odotglob -c 'rm -r *' enables Bash’s dotfile matching, but this check recognizes -O only when dotglob is a separate word. The guard then treats * as unable to match .swarm or .omp, allowing the command to remove protected state.
How this was verified: The shell-option check rejects the attached -Odotglob form, while protected-path glob matching assumes dotfile matching remains off.
Prompt To Fix With AI
This is a comment left during a code review.
Path: omp/src/guard.ts
Line: 942
Comment:
**Attached dotglob option bypasses guard**
In a swarm session, `bash -Odotglob -c 'rm -r *'` enables Bash’s dotfile matching, but this check recognizes `-O` only when `dotglob` is a separate word. The guard then treats `*` as unable to match `.swarm` or `.omp`, allowing the command to remove protected state.
**How this was verified:** The shell-option check rejects the attached `-Odotglob` form, while protected-path glob matching assumes dotfile matching remains off.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| if (assignment !== null) { | ||
| if (assignment[1] === "GLOBIGNORE" || assignment[1] === "BASHOPTS") return true; | ||
| } else if (!/^(?:export|declare|typeset|local|readonly|env|-\w+)$/.test(w)) break; | ||
| } |
There was a problem hiding this comment.
Dotglob assignment forms go undetected
High Severity
enablesDotglob only treats leading GLOBIGNORE=/BASHOPTS= words (after export/declare/env) as enablement. Real bash assignments that assignsVariable already models — printf -v GLOBIGNORE, read GLOBIGNORE, for GLOBIGNORE, and namerefs — are ignored. A later rm * then treats * as non-dot, so .swarm can be mutated in the same tool call.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit b3108d2. Configure here.
| if (cmd === "unsetopt") return args.some((w) => dynamicWord(w) || /^no_?glob_?dots$/i.test(w.replace(/_/g, ""))); | ||
| const optionAfter = (flag: RegExp) => args.some((w, i) => flag.test(w) && args[i + 1] !== undefined && named(args[i + 1])); | ||
| if (cmd === "set" && optionAfter(/^-o$/)) return true; | ||
| if (/^[a-z]*sh$/.test(cmd) && (optionAfter(/^-[A-Za-z]*[Oo]$/) || args.some((w) => w.startsWith("--") && isDotglobOption(w.slice(2))))) return true; |
There was a problem hiding this comment.
Dotglob option spellings are missed
High Severity
enablesDotglob only accepts a standalone -o/-O followed by the next word, and never treats +o noglobdots as enablement. Clustered or attached flags (set -eo globdots, set -oglobdots, bash -Odotglob) and the inverse set/zsh +o noglobdots (the set twin of the handled unsetopt noglobdots) turn dotglob on without a block, so a following * no longer excludes .swarm.
Reviewed by Cursor Bugbot for commit b3108d2. Configure here.
Guard extracts attached shell -c payloads and recognizes pathed or wrapped echo/printf feeding a shell; a test literal no longer carries a host-looking path. Refs SPE-3798
| const args = words.slice(1); | ||
| if (args[0] === "-v") args.splice(0, 2); | ||
| if (args[0] === "--") args.shift(); | ||
| return args.map((a) => a.replace(/\\n/g, "\n").replace(/\\t/g, " ")).join("\n"); |
There was a problem hiding this comment.
Formatted commands evade the guard
In a swarm session, printf 'touch %s' '.swarm/tasks.db' | sh prints and executes touch .swarm/tasks.db. The guard instead checks the format and argument as separate shell lines, so it misses the write to protected Task Store state. The same split can miss printf 'git push %s' --force | sh.
How this was verified: The guard constructs separate lines from printf’s format and arguments, while the shell executes their formatted output as one command.
Prompt To Fix With AI
This is a comment left during a code review.
Path: omp/src/guard.ts
Line: 800
Comment:
**Formatted commands evade the guard**
In a swarm session, `printf 'touch %s' '.swarm/tasks.db' | sh` prints and executes `touch .swarm/tasks.db`. The guard instead checks the format and argument as separate shell lines, so it misses the write to protected Task Store state. The same split can miss `printf 'git push %s' --force | sh`.
**How this was verified:** The guard constructs separate lines from printf’s format and arguments, while the shell executes their formatted output as one command.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.| if (attached !== "") out.push(attached); | ||
| } else if (w === "--" || /^[-+]/.test(w)) continue; | ||
| else { | ||
| if (c) out.push(w); |
There was a problem hiding this comment.
Positional argument gets checked
For bash -c'echo ok' 'git push -f', the attached -c value is the command and the following word is only $0. The parser checks both as commands, so this harmless invocation requires approval for a force push that will not run.
Prompt To Fix With AI
This is a comment left during a code review.
Path: omp/src/guard.ts
Line: 473-476
Comment:
**Positional argument gets checked**
For `bash -c'echo ok' 'git push -f'`, the attached `-c` value is the command and the following word is only `$0`. The parser checks both as commands, so this harmless invocation requires approval for a force push that will not run.
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
There are 3 total unresolved issues (including 2 from previous reviews).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 640172a. Configure here.
| const args = words.slice(1); | ||
| if (args[0] === "-v") args.splice(0, 2); | ||
| if (args[0] === "--") args.shift(); | ||
| return args.map((a) => a.replace(/\\n/g, "\n").replace(/\\t/g, " ")).join("\n"); |
There was a problem hiding this comment.
Printf split misses formatted shell scripts
High Severity
printedText now emits each printf argument as its own script line instead of joining them the way the previous helper did. A command assembled from the format string and later arguments is never reconstructed, so a printf pipeline into a shell can change .swarm or .omp without matching the write rules.
Reviewed by Cursor Bugbot for commit 640172a. Configure here.
There was a problem hiding this comment.
Agentic security review of this head found two remaining D-08/HOOK-02 bypasses in the new omp tool_call guard: attached archive/copy destination flags, and bash BASH_ENV startup sourcing. Other review modules did not report additional qualifying issues.
Sent by Cursor Security Agent: Security Reviewer
| if (cmd === "yq") return has(/^(?:-[A-Za-z]*i[A-Za-z]*|--inplace)$/) ? args : []; | ||
| if (cmd === "dd") return words.flatMap((w) => (w.startsWith("of=") ? [w.slice(3)] : [])); | ||
| if (cmd === "tar") { | ||
| const out = optionValues(words, ["-C", "--directory"], "--directory"); |
There was a problem hiding this comment.
🔒 Agentic Security Review
Severity: HIGH
D-08 treats tar/unzip -C/-d and cp/mv/install -t destinations as protected-path mutate/write targets, but those parsers only match a standalone flag word (and --directory= / --target-directory=). GNU tar accepts tar -C.swarm -xf a.tar and clustered tar xfC a.tar .swarm; unzip accepts unzip -d.swarm a.zip; GNU cp/mv/install accept cp -t.swarm file. Those words are not -C/-d/-t, so shellMutateTargets / shellWriteTargets record no destination and the guard allows the write.
Impact: A swarm-session bash call can extract or copy files into .swarm (Task Store, signed verdicts) or .omp without the human-approval path this guard is meant to enforce.
Reviewed by Cursor Security Reviewer for commit 640172a. Configure here.
| if (typeof command !== "string" || command.trim() === "") return undefined; | ||
| // the bash tool's own `env` reaches the shell: GLOBIGNORE/BASHOPTS turn dotglob on, HOME and CDPATH move paths | ||
| const env = new Map<string, unknown>("env" in input && typeof input.env === "object" && input.env !== null ? Object.entries(input.env) : []); | ||
| if (env.has("GLOBIGNORE") || env.has("BASHOPTS")) return { block: true, reason: reason("protected_path", "glob-dotfiles") }; |
There was a problem hiding this comment.
🔒 Agentic Security Review
Severity: MEDIUM
The bash-tool env map and command-word assignment scan treat GLOBIGNORE/BASHOPTS as enabling dotglob, but they do not treat BASH_ENV. For non-interactive bash, BASH_ENV is sourced before -c runs. A swarm agent can write a script under /tmp and then call bash with env.BASH_ENV (or a BASH_ENV=... prefix). The sourced file is not in event.input.command, so HOOK-02 never sees protected writes, shopt -s dotglob, git destructive rows, or gate/orch scripts.
Impact: Swarm sessions can run unconstrained shell at bash startup, bypassing D-08 protected-path rules and the rest of the command-string guard. Blast radius is the operator workspace, including .swarm / .omp control-plane state.
Reviewed by Cursor Security Reviewer for commit 640172a. Configure here.




Summary
Milestone v2.0 "Omp-Native Swarm": the 15-agent swarm now runs natively in omp, alongside the Claude Code and Grok renders. All 7 phases passed verification. The milestone audit covers requirements 38/38, phases 7/7, integration 23/23 and flows 8/8, with status
tech_debt(non-blocking residuals recorded).omp/,.omp/config.yml): five typed tools (swarm_status|plan|ingest|transitionfor A01,swarm_gatefor the four gate agents) behind a single Python bridge; the/swarm <brief>command; the HOOK-01 context hook and runtime root; and thetool_callguard (HOOK-02 autonomy ceiling, HOOK-03 swarm state, HOOK-04 depth cap, D-08 hardening).prompts/+agents.json(build_agents.pyrendersomp/agents,omp/skillsandswarm-orchestrate). The gate agents record their gate only throughswarm_gate.swarm_run.py --runtime omp(headlessomp -p, yield-payload results, E-CONTRACT/E-DEP failure modes, session-group kill on timeout and signals). Gate parity: per-target review findings, fail-closed normalization, and ingest refusing a contradicting review.build_agents.py --install-workspace <ws> [--omp-mode link|copy]with a safe config merge, a shadow scan, and symlink and$HOMErefusals.AGENTS.md/CLAUDE.mdcarry the full contract.Local gates at the head commit: pytest 413 passed;
build_agents.py --checkandbuild_trae_agents.py --checkup to date;bun test tests/tspass; ompbun run test5 + 801 pass; ruff shows only 2 pre-existing E401 errors.This PR was opened by the ultrathink ship flow and merges only at Greptile 5/5 with no open threads and green CI. The advisory judge notes below concern the separate ship-gate task, which merged as swcstudiospace/claude-ultrathink#11.
Linked issues
Fixes SPE-3795 — [n1] Understand blocker and orchestration state
https://linear.app/swcstudio/issue/SPE-3795/n1-understand-blocker-and-orchestration-state
Fixes SPE-3796 — [n2] Inventory available access and credentials
https://linear.app/swcstudio/issue/SPE-3796/n2-inventory-available-access-and-credentials
Fixes SPE-3794 — [n3] Locate all Greptile/automerge enforcement mechanisms in repo files
https://linear.app/swcstudio/issue/SPE-3794/n3-locate-all-greptileautomerge-enforcement-mechanisms-in-repo-files
Fixes SPE-3797 — [n4] Query live GitHub branch protection / rulesets via API
https://linear.app/swcstudio/issue/SPE-3797/n4-query-live-github-branch-protection-rulesets-via-api
Fixes SPE-3798 — [n5] Determine correct least-privilege fix option
https://linear.app/swcstudio/issue/SPE-3798/n5-determine-correct-least-privilege-fix-option
Fixes SPE-3799 — [n6] Critique missing information and ambiguities before applying any change
https://linear.app/swcstudio/issue/SPE-3799/n6-critique-missing-information-and-ambiguities-before-applying-any
Fixes SPE-3800 — [n7] Define verification and audit-trail plan
https://linear.app/swcstudio/issue/SPE-3800/n7-define-verification-and-audit-trail-plan
Fixes SPE-3801 — [n8] Synthesize ordered execution plan to resolve blocker and resume orchestration
https://linear.app/swcstudio/issue/SPE-3801/n8-synthesize-ordered-execution-plan-to-resolve-blocker-and-resume
Notion task: https://app.notion.com/p/3e7bc1a0c7ae81c782d2d47dd4e07979?pvs=204
Assessment
ultrathink graph ut-mui5nw82-522018c8
Note
Medium Risk
Changes orchestration leasing, ingest payload, and gate recording contracts that affect fail-closed approval paths; mostly prompt/docs/CI with runtime behavior carried by existing scripts.
Overview
This milestone aligns orchestration and gate agent prompts (Claude + Grok) with a repo-scoped Task Store: plan/status/run examples and workflows now require
--repo <app>, persist plans under<app>/.swarm, lease ready tasks (CLAIMED→IN_PROGRESS) before delegation, ingesttask.result, and forbid A01 from hand-writing gate verdicts—gate scripts record signed verdicts ongate_fortargets when invoked with the gate task’s--task-id.Gate agents (A08/A09/A10/A12) switch from per-target script runs to a single gate invocation; acceptance criteria and graceful degradation reject
--dry-runon gate scripts unless the runner is in dry-run mode. A09 standardizes JSONpass|fail(legacy approve/request_changes/block aliased).Adds a Trae SOLO registration kit (
.trae/: 15 generated prompts,registration.json,/swarmcommand, README), GitHub Actions CI (pytest, agent build checks, Bun TS tests),.omp/config.ymlplus generated omp skill stub, and expands README/CLAUDE.md for omp workspace install,--runtime omp, and Trae usage. Hooks:user_prompt_submit.pyandautonomous_run.pyuse a shared SDLC classifier shape (regex-based, dispatch-marker skip), resolve swarm dir viaswarm.paths, support--runtime omp, and skip swarm run when planning fails (passing--correlation-idon success). Grok hook path is relative (hooks/user_prompt_submit.py).Reviewed by Cursor Bugbot for commit 640172a. Bugbot is set up for automated code reviews on this repo. Configure here.
The PR is not safe to merge while the new printf bypass and the outstanding dotglob guard bypass remain.
Fix with agent prompt
Summary
The PR adds omp-native swarm execution, generated agent and skill assets, workspace installation, gate handling, and CI coverage. Since the previous review, it has also changed shell-command and stdin-script parsing in the omp guard; those parsing changes need correction.
Reviews (8) · Last reviewed commit: "address greptile review feedback"