Documentation
¶
Overview ¶
Package agents is the jevkit hook framework and per-agent adapters.
`jevkit hook <agent> <event>` reads a JSON payload on stdin, dispatches to an Agent adapter, and prints a JSON response. Hooks must never break the calling agent: the runner recovers panics, enforces a hard timeout, fails open on garbage input or protocol-version mismatch, and exits 0 with a valid empty/allow response unless the adapter deliberately denies.
Index ¶
- Constants
- Variables
- func BuildShellWrapperCommand(binary, workspace, command, runtime string) string
- func DetectLookPath(name string, look func(string) (string, error)) (path string, ok bool)
- func FormatPreviews(previews []FilePreview) string
- func HookConfigPath(name string, opts InstallOptions) (string, error)
- func InstallMCP(name string, opts InstallOptions) error
- func IsShellWrapperCommand(command string) bool
- func MCPConfigPath(name string, opts InstallOptions) (string, error)
- func Names() []string
- func Register(a Agent)
- func ResolveScope(opts InstallOptions) string
- func Run(ctx context.Context, agent Agent, event Event, in io.Reader, out io.Writer, ...) int
- func SortedNames() []string
- func UnifiedDiff(fromName, toName string, before, after []byte) string
- func UninstallMCP(name string, opts InstallOptions) error
- type Agent
- type Antigravity
- func (a *Antigravity) Capabilities() Capabilities
- func (a *Antigravity) HandlePostTool(ctx context.Context, req Request) (Response, error)
- func (a *Antigravity) HandlePreTool(ctx context.Context, req Request) (Response, error)
- func (a *Antigravity) HandleStop(ctx context.Context, req Request) (Response, error)
- func (a *Antigravity) Install(opts InstallOptions) error
- func (a *Antigravity) Name() string
- func (a *Antigravity) Passthrough(event Event) []byte
- func (a *Antigravity) Uninstall(opts InstallOptions) error
- type ApplyReport
- func InstallAgent(a Agent, opts InstallOptions) (ApplyReport, error)
- func InstallAgentComponents(a Agent, opts InstallOptions, components Components) (ApplyReport, error)
- func UninstallAgent(a Agent, opts InstallOptions) (ApplyReport, error)
- func UninstallAgentComponents(a Agent, opts InstallOptions, components Components) (ApplyReport, error)
- type Capabilities
- type Claude
- func (c *Claude) Capabilities() Capabilities
- func (c *Claude) HandlePostTool(ctx context.Context, req Request) (Response, error)
- func (c *Claude) HandlePreTool(ctx context.Context, req Request) (Response, error)
- func (c *Claude) HandleStop(ctx context.Context, req Request) (Response, error)
- func (c *Claude) Install(opts InstallOptions) error
- func (c *Claude) Name() string
- func (c *Claude) Passthrough(event Event) []byte
- func (c *Claude) Uninstall(opts InstallOptions) error
- type Codex
- func (c *Codex) Capabilities() Capabilities
- func (c *Codex) HandlePostTool(ctx context.Context, req Request) (Response, error)
- func (c *Codex) HandlePreTool(ctx context.Context, req Request) (Response, error)
- func (c *Codex) HandleStop(ctx context.Context, req Request) (Response, error)
- func (c *Codex) Install(opts InstallOptions) error
- func (c *Codex) Name() string
- func (c *Codex) Passthrough(event Event) []byte
- func (c *Codex) Uninstall(opts InstallOptions) error
- type Components
- type Cursor
- func (c *Cursor) Capabilities() Capabilities
- func (c *Cursor) HandlePostTool(ctx context.Context, req Request) (Response, error)
- func (c *Cursor) HandlePreTool(ctx context.Context, req Request) (Response, error)
- func (c *Cursor) HandleStop(ctx context.Context, req Request) (Response, error)
- func (c *Cursor) Install(opts InstallOptions) error
- func (c *Cursor) Name() string
- func (c *Cursor) Passthrough(event Event) []byte
- func (c *Cursor) Uninstall(opts InstallOptions) error
- type Event
- type FilePreview
- type InstallOptions
- type InstallState
- type OpenCode
- func (o *OpenCode) Capabilities() Capabilities
- func (o *OpenCode) HandlePostTool(ctx context.Context, req Request) (Response, error)
- func (o *OpenCode) HandlePreTool(ctx context.Context, req Request) (Response, error)
- func (o *OpenCode) HandleStop(ctx context.Context, req Request) (Response, error)
- func (o *OpenCode) Install(opts InstallOptions) error
- func (o *OpenCode) Name() string
- func (o *OpenCode) Passthrough(event Event) []byte
- func (o *OpenCode) Uninstall(opts InstallOptions) error
- type Options
- type ReplacementScope
- type Request
- type Response
- type RuntimeCapability
Constants ¶
const ( CodexPreToolMarker = "_runtime dispatch --protocol 1 codex pre-tool" CodexPostToolMarker = "_runtime dispatch --protocol 1 codex post-tool" )
CodexPreToolMarker / CodexPostToolMarker are the full event tokens.
const ( CursorPreToolMarker = "_runtime dispatch --protocol 1 cursor pre-tool" CursorPostToolMarker = "_runtime dispatch --protocol 1 cursor post-tool" )
CursorPreToolMarker / CursorPostToolMarker are the full event tokens.
const ( OutcomeOK = "ok" OutcomeDeny = "deny" OutcomePassthrough = "passthrough" OutcomePanic = "panic" OutcomeTimeout = "timeout" OutcomeVersionMismatch = "version_mismatch" OutcomeGarbage = "garbage" OutcomeUnknownAgent = "unknown_agent" OutcomeHalt = "halt" OutcomeLatched = "latched" )
Outcome codes recorded in hook telemetry.
const AntigravityHookMarker = "_runtime dispatch --protocol 1 antigravity"
AntigravityHookMarker is the idempotency substring for managed entries in .agents/hooks.json. Installer matching is substring-based so a binary-path change still replaces the prior entry instead of duplicating.
const AntigravityHooksGroup = "jevkit"
AntigravityHooksGroup is the top-level group key written into .agents/hooks.json (ralph uses "ralph-native"; jevkit owns its own group).
const AntigravityName = "antigravity"
Antigravity adapter name used by installed runtime integrations.
const AntigravityPostToolMarker = "_runtime dispatch --protocol 1 antigravity post-tool"
AntigravityPostToolMarker is retained for removal of old telemetry hooks.
const AntigravityPreToolMarker = "_runtime dispatch --protocol 1 antigravity pre-tool"
const ClaudeHookMarker = "_runtime dispatch --protocol 1 claude post-tool"
Managed hook command token used as an idempotency marker inside Claude settings files. Installer matching is substring-based on this token so a binary-path change still replaces the prior entry instead of duplicating. Full command is `<binary> _runtime dispatch --protocol 1 claude post-tool`.
const ClaudeName = "claude"
Claude adapter name used by installed runtime integrations.
const ClaudePreHookMarker = "_runtime dispatch --protocol 1 claude pre-tool"
const CodexHookMarker = "_runtime dispatch --protocol 1 codex"
CodexHookMarker is the idempotency substring for managed entries in .codex/hooks.json. Installer matching is substring-based so a binary-path change still replaces the prior entry instead of duplicating.
const CodexName = "codex"
Codex adapter name used by installed runtime integrations.
const CursorHookMarker = "_runtime dispatch --protocol 1 cursor"
CursorHookMarker is the idempotency substring for managed entries in .cursor/hooks.json. Installer matching is substring-based so a binary-path change still replaces the prior entry instead of duplicating.
const CursorName = "cursor"
Cursor adapter name used by installed runtime integrations.
const DefaultTimeout = 5 * time.Second
DefaultTimeout is the hard upper bound for one hook dispatch. Hooks fire on every tool call, so adapters must stay well under this.
const OpenCodeHookMarker = "_runtime dispatch --protocol 1 opencode"
OpenCodeHookMarker identifies the plugin's private runtime dispatcher call.
const OpenCodeName = "opencode"
OpenCode adapter name used by the installed plugin.
const OpenCodePluginFile = "jevkit-runtime-hooks.ts"
OpenCodePluginFile is the staged plugin basename under .opencode/plugins/.
const OpenCodePluginMarker = "JEVKIT_OPENCODE_PLUGIN"
OpenCodePluginMarker is the idempotency / ownership token embedded in the staged TypeScript plugin. Installer matching is substring-based.
const ProtocolVersion = 1
ProtocolVersion is the stdin JSON protocol this build speaks. A payload that declares a different version fails open (passthrough, exit 0).
Variables ¶
var DetectBins = map[string][]string{
ClaudeName: {"claude"},
CursorName: {"cursor-agent", "cursor"},
CodexName: {"codex"},
OpenCodeName: {"opencode"},
AntigravityName: {"agy", "gemini"},
}
DetectBins maps adapter Name() -> PATH binaries that mean the agent is installed. First hit wins for doctor display.
var HookMarker = map[string]string{ ClaudeName: ClaudeHookMarker, CursorName: CursorHookMarker, CodexName: CodexHookMarker, OpenCodeName: OpenCodePluginMarker, AntigravityName: AntigravityHookMarker, }
HookMarker is the idempotency substring for each adapter's managed hooks.
Functions ¶
func BuildShellWrapperCommand ¶
BuildShellWrapperCommand returns a shell-safe invocation of the private wrapper. The wrapper is invoked by the agent, rather than the hook, so its stdout is the tool result the agent sees.
func DetectLookPath ¶
DetectLookPath finds the first PATH hit for name's detect binaries.
func FormatPreviews ¶
func FormatPreviews(previews []FilePreview) string
FormatPreviews renders unified diffs for changed previews.
func HookConfigPath ¶
func HookConfigPath(name string, opts InstallOptions) (string, error)
HookConfigPath is the primary hooks/settings/plugin path for name.
func InstallMCP ¶
func InstallMCP(name string, opts InstallOptions) error
InstallMCP merges the jevkit MCP server entry into the agent-specific client config. Idempotent; DryRun only reports a preview.
func IsShellWrapperCommand ¶
func MCPConfigPath ¶
func MCPConfigPath(name string, opts InstallOptions) (string, error)
MCPConfigPath is where jevkit registers its MCP server for name.
func Register ¶
func Register(a Agent)
Register adds an adapter under its Name(). Later registrations replace earlier ones for the same name.
func ResolveScope ¶
func ResolveScope(opts InstallOptions) string
ResolveScope returns "project" or "user" given opts.
func Run ¶
func Run(ctx context.Context, agent Agent, event Event, in io.Reader, out io.Writer, opts Options) int
Run reads a JSON hook payload from in, dispatches to agent for event, writes the response JSON to out, and returns the process exit code. It always fails open: panics, timeouts, garbage stdin, version mismatches, and unknown agents/events yield a safe passthrough body and exit 0.
func SortedNames ¶
func SortedNames() []string
SortedNames returns registered adapter names in stable order.
func UnifiedDiff ¶
UnifiedDiff renders a unified diff of two texts. Empty when equal.
func UninstallMCP ¶
func UninstallMCP(name string, opts InstallOptions) error
UninstallMCP restores the MCP config from its first-install backup, or strips the jevkit entry when no backup exists.
Types ¶
type Agent ¶
type Agent interface {
Name() string
Capabilities() Capabilities
HandlePreTool(ctx context.Context, req Request) (Response, error)
HandlePostTool(ctx context.Context, req Request) (Response, error)
HandleStop(ctx context.Context, req Request) (Response, error)
// Passthrough is the fail-open JSON body for event (empty/allow). It must
// always be valid JSON the agent accepts as "do nothing".
Passthrough(event Event) []byte
Install(opts InstallOptions) error
Uninstall(opts InstallOptions) error
}
Agent is one coding-agent adapter.
func SelectAgents ¶
func SelectAgents(target string, look func(string) (string, error), detectedOnly bool) ([]Agent, error)
SelectAgents resolves "all" or a single name against the registry. When all is true and detectedOnly is set, only agents found on PATH are returned (explicit names always resolve regardless of detection).
func SupportedInstallAgents ¶
SupportedInstallAgents is the set of adapters available for new installs.
type Antigravity ¶
type Antigravity struct {
// Binary is the jevkit executable name/path used in rewrites and install
// commands. Empty means "jevkit".
Binary string
Security *config.Config
SecurityDecider *registry.Decider
StateDir string
}
Antigravity is the Antigravity (agy) adapter.
Spike (docs/AGENT-CAPABILITIES.md): PreToolUse run_command rewrite via overwrite.CommandLine is the compaction path. PostToolUse carries only stepIdx/error — no output replacement. A decision must always be printed.
func NewAntigravity ¶
func NewAntigravity() *Antigravity
NewAntigravity returns an Antigravity adapter.
func (*Antigravity) Capabilities ¶
func (a *Antigravity) Capabilities() Capabilities
func (*Antigravity) HandlePostTool ¶
func (*Antigravity) HandlePreTool ¶
func (*Antigravity) HandleStop ¶
func (*Antigravity) Install ¶
func (a *Antigravity) Install(opts InstallOptions) error
Install merges Antigravity hooks into .agents/hooks.json (project) or <ConfigDir>/.agents/hooks.json (user). It is idempotent: a second apply leaves a single managed group. DryRun computes the merge without writing.
func (*Antigravity) Name ¶
func (a *Antigravity) Name() string
func (*Antigravity) Passthrough ¶
func (a *Antigravity) Passthrough(event Event) []byte
func (*Antigravity) Uninstall ¶
func (a *Antigravity) Uninstall(opts InstallOptions) error
Uninstall removes jevkit-managed Antigravity hooks and restores the hooks file to the byte-exact original captured on first install.
type ApplyReport ¶
type ApplyReport struct {
Agent string
Previews []FilePreview
}
ApplyReport is the outcome of InstallAgent / UninstallAgent.
func InstallAgent ¶
func InstallAgent(a Agent, opts InstallOptions) (ApplyReport, error)
InstallAgent runs hook Install then MCP registration for one adapter.
func InstallAgentComponents ¶
func InstallAgentComponents(a Agent, opts InstallOptions, components Components) (ApplyReport, error)
InstallAgentComponents installs only the selected, independently reversible integration components.
func UninstallAgent ¶
func UninstallAgent(a Agent, opts InstallOptions) (ApplyReport, error)
UninstallAgent removes MCP registration then restores hook config.
func UninstallAgentComponents ¶
func UninstallAgentComponents(a Agent, opts InstallOptions, components Components) (ApplyReport, error)
UninstallAgentComponents removes only components selected by the caller.
type Capabilities ¶
type Capabilities struct {
// PreTool is true when HandlePreTool may rewrite or decide on a tool call.
PreTool bool
// PostTool is true when HandlePostTool may replace or observe tool output.
PostTool bool
// Stop is true when HandleStop may block or continue a stop event.
Stop bool
// OutputReplace is true when PostTool can replace model-visible output.
OutputReplace bool
// PreToolRewrite is true when PreTool can rewrite the shell command into
// `jevkit exec -- ...`.
PreToolRewrite bool
}
Capabilities describes what an adapter supports.
type Claude ¶
type Claude struct {
// Getenv reads process env; nil means os.Getenv. Gates:
// JEVKIT_COMPACT=1 enables compaction; JEVKIT_COMPACT_SHADOW=1 passes through.
Getenv func(string) string
// ThresholdBytes overrides the compact threshold; zero uses the default.
ThresholdBytes int
// Asker is the optional jev ranked-line tier; nil is deterministic-only.
Asker compact.Asker
// StateDir is forwarded to compact shadow logging (unused when shadow
// passthrough skips compaction).
StateDir string
Policy *compact.Policy
Security *config.Config
SecurityDecider *registry.Decider
}
Claude is the Claude Code adapter.
Spike (docs/AGENT-CAPABILITIES.md, testdata/hooks/claude/): PostToolUse:Bash payloads carry tool_response.{stdout,stderr,...} but no real exit code. Non-zero exits fire PostToolUseFailure without tool_response, so this adapter only replaces successful Bash output. Compaction assumes exit 0.
func NewClaude ¶
func NewClaude() *Claude
NewClaude returns a Claude adapter wired to the process environment.
func (*Claude) Capabilities ¶
func (c *Claude) Capabilities() Capabilities
func (*Claude) HandlePostTool ¶
HandlePostTool compacts PostToolUse:Bash tool_response when jev compaction is enabled, the combined output is above the size threshold, and shadow mode is off. Everything else fails open with `{}`.
func (*Claude) HandlePreTool ¶
func (*Claude) HandleStop ¶
func (*Claude) Install ¶
func (c *Claude) Install(opts InstallOptions) error
Install merges the Claude PostToolUse:Bash hook into .claude/settings.local.json (project) or <ConfigDir>/.claude/settings.json (user). It is idempotent: a second apply leaves a single managed entry. DryRun computes the merge without writing.
func (*Claude) Passthrough ¶
func (*Claude) Uninstall ¶
func (c *Claude) Uninstall(opts InstallOptions) error
Uninstall removes jevkit-managed Claude hooks and restores the settings file to the byte-exact original captured on first install.
type Codex ¶
type Codex struct {
// Binary is the jevkit executable name/path used in rewrites and install
// commands. Empty means "jevkit".
Binary string
// Getenv reads process env; nil means os.Getenv. JEVKIT_COMPACT enables
// result replacement, while JEVKIT_COMPACT_SHADOW preserves original output.
Getenv func(string) string
// ThresholdBytes overrides the compaction threshold; zero uses the default.
ThresholdBytes int
// Asker is the optional Jev ranked-line tier. A nil or unavailable client
// fails open and preserves Codex's original tool result.
Asker compact.Asker
StateDir string
Policy *compact.Policy
Security *config.Config
SecurityDecider *registry.Decider
}
Codex is the OpenAI Codex CLI adapter.
PostToolUse can replace Codex's model-visible result with hook feedback via continue:false. It cannot mutate Bash output in place, so this adapter emits an already-compacted local result as its stop reason. Any untrusted decision leaves the original result alone.
func (*Codex) Capabilities ¶
func (c *Codex) Capabilities() Capabilities
func (*Codex) HandlePostTool ¶
HandlePostTool is telemetry-only. Shell output is replaced by the pre-tool wrapper, which preserves the real exit status and raw original.
func (*Codex) HandlePreTool ¶
func (*Codex) HandleStop ¶
func (*Codex) Install ¶
func (c *Codex) Install(opts InstallOptions) error
Install merges Codex hooks into .codex/hooks.json (project) or <ConfigDir>/.codex/hooks.json (user). It is idempotent: a second apply leaves a single managed set. DryRun computes the merge without writing.
func (*Codex) Passthrough ¶
func (*Codex) Uninstall ¶
func (c *Codex) Uninstall(opts InstallOptions) error
Uninstall removes jevkit-managed Codex hooks and restores the hooks file to the byte-exact original captured on first install.
type Components ¶
Components selects independently installable integration pieces. Plugin is a user-facing bundle alias that resolves to hooks plus MCP; it is not passed to individual adapters.
func DefaultComponents ¶
func DefaultComponents() Components
type Cursor ¶
type Cursor struct {
// Binary is the jevkit executable name/path used in rewrites and install
// commands. Empty means "jevkit".
Binary string
// Getenv reads process env; nil means os.Getenv. Gates:
// JEVKIT_COMPACT=1 enables post-tool compaction; JEVKIT_COMPACT_SHADOW=1
// passes through post-tool replacements (pre-tool rewrite still applies).
Getenv func(string) string
// ThresholdBytes overrides the compact threshold; zero uses the default.
ThresholdBytes int
// Asker is the optional jev ranked-line tier; nil is deterministic-only.
Asker compact.Asker
// StateDir is forwarded to compact shadow logging.
StateDir string
Policy *compact.Policy
Security *config.Config
SecurityDecider *registry.Decider
}
Cursor is the Cursor IDE / cursor-agent adapter.
Spike (docs/AGENT-CAPABILITIES.md): preToolUse Shell rewrite via updated_input.command is agent-visible. Shell postToolUse updated_tool_output is NOT agent-visible (telemetry only). Native Read/Grep/Glob and MCP:* results may be replaced via updated_tool_output / updated_mcp_tool_output.
func NewCursor ¶
func NewCursor() *Cursor
NewCursor returns a Cursor adapter wired to the process environment.
func (*Cursor) Capabilities ¶
func (c *Cursor) Capabilities() Capabilities
func (*Cursor) HandlePostTool ¶
HandlePostTool handles Shell and native tools as telemetry only. Cursor's documented replacement field is updated_mcp_tool_output, so only MCP tool results may be compacted here.
Everything else fails open with `{}`.
func (*Cursor) HandlePreTool ¶
func (*Cursor) HandleStop ¶
func (*Cursor) Install ¶
func (c *Cursor) Install(opts InstallOptions) error
Install merges Cursor hooks into .cursor/hooks.json (project) or <ConfigDir>/.cursor/hooks.json (user). It is idempotent: a second apply leaves a single managed set. DryRun computes the merge without writing.
func (*Cursor) Passthrough ¶
func (*Cursor) Uninstall ¶
func (c *Cursor) Uninstall(opts InstallOptions) error
Uninstall removes jevkit-managed Cursor hooks and restores the hooks file to the byte-exact original captured on first install.
type FilePreview ¶
FilePreview is one planned or applied file edit for dry-run diffs and install reporting.
type InstallOptions ¶
type InstallOptions struct {
// WorkDir is the project root (project-scoped config).
WorkDir string
// ConfigDir is the user config home (user-scoped config).
ConfigDir string
// Scope is "project" or "user"; empty means project when WorkDir is set.
Scope string
// Binary is the absolute path to the jevkit binary to register.
Binary string
// DryRun reports the planned edit without writing.
DryRun bool
InjectionGuard bool
// Preview receives each planned file edit (hooks and, when used by the
// installer, MCP configs). Called on dry-run and on write.
Preview func(FilePreview)
}
InstallOptions configures Install/Uninstall of an agent's hook config.
type InstallState ¶
type InstallState struct {
Name string
Detected bool
Binary string // first PATH hit; empty when not detected
Hooks string // "not installed" | "project" | "user" | "project+user"
MCP string // same vocabulary
}
InstallState is per-agent install reporting for doctor.
type OpenCode ¶
type OpenCode struct {
// Binary is the jevkit executable name/path used in rewrites and the
// staged plugin default. Empty means "jevkit".
Binary string
Getenv func(string) string
ThresholdBytes int
Asker compact.Asker
StateDir string
Policy *compact.Policy
}
OpenCode is the OpenCode adapter.
Not a settings-file stdin hook: Install stages a TypeScript plugin under .opencode/plugins/ that shells out to `jevkit hook opencode ...`. The Go handlers below are what that plugin invokes.
func (*OpenCode) Capabilities ¶
func (o *OpenCode) Capabilities() Capabilities
func (*OpenCode) HandlePostTool ¶
func (*OpenCode) HandlePreTool ¶
HandlePreTool deliberately leaves input untouched.
func (*OpenCode) HandleStop ¶
func (*OpenCode) Install ¶
func (o *OpenCode) Install(opts InstallOptions) error
Install stages the OpenCode TypeScript plugin under .opencode/plugins/jevkit-runtime-hooks.ts (project) or <ConfigDir>/.opencode/plugins/jevkit-runtime-hooks.ts (user). It is idempotent: a second apply leaves a single managed file. DryRun computes the rendered plugin without writing.
func (*OpenCode) Passthrough ¶
func (*OpenCode) Uninstall ¶
func (o *OpenCode) Uninstall(opts InstallOptions) error
Uninstall removes the staged OpenCode plugin and restores any pre-install file captured on first install (or deletes the file when it was absent).
type Options ¶
type Options struct {
// Timeout is the hard upper bound; zero means DefaultTimeout.
Timeout time.Duration
// StateDir is the usage/telemetry state home (see usage.Path). Empty
// disables telemetry unless AppendHook is set.
StateDir string
// LoadError is a policy-load failure recorded with this invocation.
LoadError string
// Now is the clock; nil means time.Now.
Now func() time.Time
// AppendHook records one invocation; nil uses usage.AppendHook when
// StateDir is set. Tests inject a recorder here.
AppendHook func(stateDir string, rec usage.HookInvocation) error
}
Options configures a single hook dispatch.
type ReplacementScope ¶
type ReplacementScope string
ReplacementScope describes the narrowest model-visible result replacement contract supported by a runtime's documented post-tool API. It deliberately does not infer replacement from a pre-tool input rewrite.
const ( ReplacementNone ReplacementScope = "none" ReplacementMCPOnly ReplacementScope = "mcp-only" ReplacementToolShapes ReplacementScope = "validated-tool-shapes" )
type Request ¶
type Request struct {
// Raw is the original stdin bytes (valid JSON when the runner reached the
// adapter; garbage never reaches adapters).
Raw json.RawMessage
// Event is the normalized CLI event.
Event Event
// ProtocolVersion is the version declared by the payload, or
// ProtocolVersion when the field is absent.
ProtocolVersion int
}
Request is one stdin payload delivered to an adapter.
type Response ¶
type Response struct {
Body []byte
Outcome string
// Deny marks a deliberate policy denial (as opposed to a fail-open
// passthrough). When true and ExitCode is 0, the process still exits 0
// and the body carries the deny for agents that encode it in JSON.
Deny bool
// ExitCode overrides the process exit code for a deliberate deny. Zero
// keeps the fail-open default of exit 0.
ExitCode int
}
Response is the adapter's answer. Body is written to stdout as JSON. ExitCode is used only for a deliberate deny; fail-open paths always force 0.
type RuntimeCapability ¶
type RuntimeCapability struct {
Name string
PreToolDecision bool
Evidence string
PostToolOutput bool
AuthoritativeState string
Replacement ReplacementScope
ContextInjection bool
Telemetry bool
Installation string
// ShellPolicyCoverage is true when the installed pre-tool hook actually
// inspects and can rewrite an eligible shell call before it runs (see
// IsShellWrapperCommand / buildSecurityShellWrapperCommand call sites).
// OpenCode's plugin never receives a pre-tool event (HandlePreTool is a
// documented no-op; see opencode.go and docs/AGENT-INTEGRATIONS.md), so its
// shell calls are never policy-checked in this version. This must stay in
// sync with PreToolDecision for every runtime that claims shell coverage;
// see TestRuntimeCapabilityAuditMatchesAdapterClaims.
ShellPolicyCoverage bool
InjectionGuard bool
}
RuntimeCapability is the evidence-backed contract used to decide what an adapter may do. Evidence dates identify when the vendor documentation was reviewed; they are not a claim that an unpinned runtime API is immutable.
func RuntimeCapabilities ¶
func RuntimeCapabilities(name string) (RuntimeCapability, bool)
RuntimeCapabilities is intentionally separate from an adapter's legacy Capabilities flags. The latter describe implemented dispatch events; this table limits what those events may do as the integrations are revised.
Source Files
¶
- agent.go
- antigravity.go
- antigravity_install.go
- apply.go
- capability_audit.go
- claude.go
- claude_install.go
- codex.go
- codex_install.go
- compact_env.go
- cursor.go
- cursor_install.go
- diff.go
- doc.go
- errors.go
- hook.go
- injection.go
- mcp_install.go
- meta.go
- opencode.go
- opencode_install.go
- raw_store.go
- registry.go
- security.go
- shell_wrapper.go