Install
$ agentstack add mcp-can1357-oh-my-pi Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged1 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Pipes remote content directly into a shell (remote code execution).
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
A coding agent with the IDE wired in. omp.sh
Fork of Pi by @mariozechner
The most capable agent surface that ships. Continuously tuned by real-world use — complete out of the box, open all the way down.
40+ providers · 32 built-in tools · 14 lsp ops · 28 dap ops · ~55k lines of Rust core.
Install
macOS · Linux
curl -fsSL https://omp.sh/install | sh
Homebrew
brew install can1357/tap/omp
Bun (recommended)
bun install -g @oh-my-pi/pi-coding-agent
Windows (PowerShell)
irm https://omp.sh/install.ps1 | iex
Pinned versions (mise)
mise use -g github:can1357/oh-my-pi
macOS · Linux · Windows · bun ≥ 1.3.14
Shell completions
omp generates its own completion scripts for bash, zsh, and fish from the live command/flag metadata, so they never drift from the actual CLI. Subcommands, flags, and enum values complete statically; model names (--model, --smol, --slow, --plan) resolve against the bundled model catalog and --resume against your on-disk sessions.
# zsh — add to ~/.zshrc (or write the output into a file on your $fpath)
eval "$(omp completions zsh)"
# bash — add to ~/.bashrc
eval "$(omp completions bash)"
# fish
omp completions fish > ~/.config/fish/completions/omp.fish
Every tool, benchmaxxed.
Edits that land on the first attempt. Reads that summarize files instead of dumping their content. Searches that return instantly. Pick any model — omp will get it right.
| model | metric | what | | ---------------- | ------------ | --------------------------------------------------------------------- | | Grok Code Fast 1 | 6.7% → 68.3% | Tenfold lift the moment the edit format stops eating the model alive. | | Gemini 3 Flash | +5 pp | Over str_replace — beats Google's own best attempt at the format. | | Grok 4 Fast | −61% tokens | Output collapses once the retry loop on bad diffs disappears. | | MiniMax | 2.1× | Pass rate more than doubles. Same weights, same prompt. |
read: summarized snippets · ideal defaults · selector hit ratesearch: fastest in the westlsp: everything your IDE knows, the agent knowsprompts: adjusted relentlessly for each model
The Pi you love, with batteries included.
Originally built on Mario Zechner's wonderful Pi, omp adds everything you're missing.
01 · Code execution w/ tool-calling
Most harnesses give the agent a Python sandbox and call it done. Ours runs persistent Python and a Bun worker, and either kernel can call back into the agent's own tools — read, search, task — over a loopback bridge. The agent loads a CSV with tool.read from inside Python, charts it from JavaScript, and never leaves the cell.
02 · LSP wired into every write
Ask for a rename and you get a rename. The call goes through workspace/willRenameFiles, so re-exports, barrel files, and aliased imports update before the file moves. Everything your IDE knows, the agent knows.
03 · Drives a real debugger
A C binary segfaults: the agent attaches lldb, steps to the bad pointer, reads the frame. A Go service hangs: it attaches dlv and walks the goroutines. A Python process is wedged: debugpy, pause, inspect, evaluate. Most agents are still sprinkling print statements.
04 · Time-traveling stream rules
Your rules sit dormant until the model goes off-script. A regex match aborts the stream mid-token, injects the rule as a system reminder, and retries from the same point. You get course-correction without paying context tax on every turn. Injections survive compaction, so the fix sticks.
05 · First-class subagents
Split a job across workers and get typed results back. task fans out into isolated worktrees, each worker runs its own tool surface, and the final yield is a schema-validated object the parent reads directly. No prose to parse, no merge conflicts between siblings, no orphaned edits.
06 · A second model, watching every turn.
Pair a reviewer model to the 'advisor' role and it reads every turn the main agent takes, injecting notes inline — a quiet aside, a concern, or a hard blocker. It runs on its own context and its own model, so it catches what the doer rushed past. The main agent sees the note and course-corrects, or tells you why it won't.
07 · Hand someone the link, they're in.
/collab puts your live session on a relay and hands back a link — and a QR. A teammate joins from another terminal with omp join, or just opens it in a browser. Share read-write to pair on the same agent, or /collab view for a read-only link anyone can watch but no one can steer. Frames are sealed client-side; the relay never sees your keys.
08 · Read a pdf on arxiv, why not?
web_search chains eighteen ranked providers and hands whatever URLs it finds straight to read. Arxiv PDFs, GitHub pages, Stack Overflow threads come back as structured markdown with anchors intact — the same tool surface you use on local files. Cite, follow, quote, never lose where you came from.
09 · Unapologetically native. Even on Windows.
Other agents shell out to rg, grep, find, and bash. On many machines those binaries don't exist, and on the ones where they do, every call costs a fork-exec round-trip. omp links the real implementations into the process. ripgrep, glob, find: in-process. brush is the bash, with sessions that survive across calls. The same omp binary runs on macOS, Linux, and Windows — no WSL bridge.
10 · Code review with priorities and a verdict
Get a clear verdict on whether the change ships, with every issue ranked P0 through P3 and scored for confidence. /review spawns dedicated reviewer subagents that sweep branches, single commits, or uncommitted work in parallel. You tackle what blocks release first; nothing important hides in a wall of prose.
11 · Hashline: edit by content hash
Perfect edits, fewer tokens. The model points at anchors instead of retyping the lines it wants to change, so whitespace battles and string-not-found loops just stop happening. Edit a stale file and the anchors diverge — we reject the patch before it corrupts anything. Grok 4 Fast spends 61% fewer output tokens on the same work.
12 · GitHub is just another filesystem
Other harnesses bolt on ghissueview, ghprview, gh_search — each with its own parameters the agent has to learn and you have to debug. We skipped that. read already handles paths; PRs are paths. One interface to teach the model, one surface to keep correct.
13 · Hindsight: memory the agent curates
The agent remembers your codebase between sessions. It writes facts mid-run with retain, pulls them back with recall, and compresses each session into a mental model that loads on the first turn of the next one. Project-scoped by default, so what it learns about this repo stays with this repo.
14 · ACP: editor-drivable agent
Run omp inside Zed and you get the same agent you drive from the terminal — reading the buffer you're actually looking at, writing through the editor's save path, spawning shells in the editor's terminal. Destructive tools pause for a permission prompt you can answer once and forget. No bridge, no plugin, no second brain to keep in sync.
15 · Inherits what your other tools already wrote
Every other agent ships an importer and expects you to convert. omp reads the eight formats already on disk in their native shape — Cursor MDC, Cline .clinerules, Codex AGENTS.md, Copilot applyTo, and the rest. No migration script, no YAML-to-TOML port, no "supported subset" footnotes. The config your team wrote last quarter still works tonight.
16 · omp commit: atomic splits, validated messages
omp reads the working tree through gitoverview, gitfilediff, and githunk, then splits unrelated changes into atomic commits ordered by their dependencies. Cycles are rejected before anything is written. Source files score above tests, docs, and configs, so the headline commit is the one that matters. Lock files are excluded from analysis entirely.
17 · Read PRs. Walk skills. Pull JSON out of subagents.
Twelve internal schemes — pr://, issue://, agent://, skill://, rule://, and the rest — resolve transparently inside every FS-shaped tool the agent already calls. read pr://1428 returns the same shape as read src/foo.ts. search walks a diff like a directory. agent:///findings.0.path pulls a field out of a subagent's output by path.
![omp TUI reading pr://can1357/oh-my-pi/1063 and then /diff/1, showing hunk headers, added lines, and a [MODIFIED] (+12 -0) summary.](https://omp.sh/captures/pr.webp)
18 · Conflict resolution, made easy.
Each merge conflict becomes one URL. The agent writes @theirs, @ours, or @base to conflict://N and the file resolves cleanly. Bulk form: conflict://*.
19 · Preview, then accept.
ast_edit returns a (proposed) card with the replacement count. The change is staged. The agent calls resolve with a reason; the TUI turns it into an Accept card and the disk move happens — atomic, all or nothing.
20 · Drives a real browser. Or your Slack?
Stealth's on by default, so pages see a normal user instead of a headless bot. The same API drives any Electron app in place — point it at Slack and the agent reads your DMs the way it reads the web.
Whatever the task needs, it's already in the box.
32 tools live in the same namespace as read and bash. Pin the active set with --tools read,edit,bash,… and the rest stay hidden but indexed — search_tool_bm25 pulls them back in mid-session when tools.discoveryMode says so.
Files & search
read— files, dirs, archives, SQLite, PDFs, notebooks, URLs, and internal://schemes through one path.write— create or overwrite a file, archive entry, or SQLite row.edit— hashline patches with content-hash anchors and stale-anchor recovery.ast_edit— structural rewrites previewed before apply, via ast-grep.ast_grep— structural code queries over 50+ tree-sitter grammars.search— regex over files, globs, and internal URLs.find— glob-based path lookup; reach forsearchwhen you need content matches.
Runtime
bash— workspace shell, with optional PTY or background-job dispatch.eval— persistent Python and JavaScript cells with shared prelude and tool re-entry.ssh— one remote command against a configured host.
Code intelligence
lsp— diagnostics, navigation, symbols, renames, code actions, raw requests.debug— drive a DAP session — breakpoints, stepping, threads, stack, variables.
Coordination
task— fan out subagents in parallel, optionally workspace-isolated.irc— short prose between live agents in this process.todo— ordered mutations over the session todo list with phase tracking.job— wait on or cancel background jobs.ask— structured follow-up questions for interactive runs.
Outside the box
browser— Puppeteer tabs over headless Chromium or CDP-attached apps.web_search— one query across configured providers, returning answer plus citations.github— GitHub CLI ops — repo, PR, issues, code search, Actions run-watch.generate_image— generate or edit raster images via Gemini, GPT, or xAI Grok image models.inspect_image— vision-model analysis of a local image file.tts— text-to-speech via xAI Grok Voice — five built-in voices, WAV or MP3.
Memory & state
checkpoint— mark conversation state for a later collapse-and-report.rewind— prune exploratory context, keep a concise report.retain— queue durable facts into the active Hindsight bank.recall— search the Hindsight bank for raw memories.reflect— ask Hindsight to synthesize an answer over the bank.
Misc
resolve— apply or discard a queued preview action.search_tool_bm25— BM25 over the hidden tool index; activates top matches mid-session.
Setting-gated, off by default: github, inspect_image, tts, checkpoint, rewind, search_tool_bm25, retain, recall, reflect. Flip them on once, scoped per project.
Forty-plus providers, hundreds of models, one /model away.
Roles route work by intent. default for normal turns. smol for cheap subagent fan-out. slow for deep reasoning. plan for plan mode. commit for changelogs. Override at launch with --smol, --slow, or --plan; cycle through the configured models for the active role with Ctrl+P. Swap the active model mid-session with the /model slash command.
Auth tags below: oauth signs in with your provider account, plan routes through a coding-plan subscription, local runs against a local server with the key optional.
Frontier APIs
Direct APIs and gateways. Mix providers per role.
Anthropic oauth · OpenAI · OpenAI Codex oauth · Google Gemini · Google Antigravity oauth · xAI · Mistral · Groq · Cerebras · Fireworks · Together · Hugging Face · NVIDIA · OpenRouter · Synthetic · Vercel AI Gateway · Cloudflare AI Gateway · Wafer Serverless · Perplexity oauth
Coding plans
Subscription-routed. /login attaches the session.
Cursor oauth · GitHub Copilot oauth · GitLab Duo · Kimi Code plan · Moonshot · MiniMax Coding Plan plan · MiniMax Coding Plan CN plan · Alibaba Coding Plan plan · Qwen Portal · Z.AI / GLM Coding Plan plan · Xiaomi MiMo · Qianfan · NanoGPT · Venice · Kilo · ZenMux · OpenCode Go · OpenCode Zen
Run it yourself
OpenAI-compatible /v1/models. Local instances skip the key.
Ollama local · Ollama Cloud · LM Studio local · llama.cpp local · vLLM local · LiteLLM
Four knobs that make routing useful
- Custom providers — Declare anything that speaks
openai-completions,openai-responses,openai-codex-responses,azure-openai-responses,anthropic-messages,google-generative-ai, orgoogle-vertexin~/.omp/agent/models.yml. - Fallback chains — Per-role chains under
retry.fallbackChains. When the primary throws 429s or hits a quota wall, the next entry takes the rest of the turn — restored on cooldown. - Path-scoped models — Scope
enabledModelsanddisabledProvidersentries to apath:prefix to pin a different model set on one repo without touching the global config. Scoped entries cover the path and everything under it. - Round-robin credentials — Stack API keys per provider and the runtime rotates with session affinity and per-credential backoff. Useful when one key would burn its quota by lunch.
Full provider & routing reference at omp.sh/docs/providers.
Eighteen backends. One tool the agent already knows.
web_search is built in, not bolted on. auto walks an eighteen-provider chain; pin one by name if you already pay for it. Behind every hit, site-aware extraction turns GitHub, reg
…
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: can1357
- Source: can1357/oh-my-pi
- License: MIT
- Homepage: https://omp.sh
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.