Repository navigation
Releases: HKUDS/OpenHarness
Release list
v0.1.9 — Skill Workflows and Provider Key Updates
v0.1.9 — Skill Workflows and Provider Key Updates
OpenHarness v0.1.9 is a small follow-up release after v0.1.8 focused on making skills easier to create and invoke, plus fixing provider API key updates.
Highlights
-
Bundled skill creator
- Added a bundled
skill-creatorskill for creating, improving, and verifying OpenHarness/ohmo skills. - This makes repeatable workflows easier to capture as first-class skills.
- Added a bundled
-
User-invocable skill slash commands
- Skills marked as user-invocable can now be triggered directly with slash commands.
- Slash-invoked skills support user arguments and can request a model override through skill metadata.
-
Provider API key update fix
oh setupnow lets users update the API key for an already-configured API-key provider profile.oh provider edit <profile> --api-key <key>can replace a saved profile key directly.oh provider add ... --api-key <key>can store a key while creating a provider profile.
Fixes
- Fixed issue #238, where users could change a configured provider model but had no supported path to update the saved API key.
Install
pip install --upgrade openharness-ai==0.1.9Contributors
This release is primarily a maintainer follow-up release. Thanks to the users and contributors who reported and validated the provider key update workflow, especially the reporter of #238.
v0.1.8 — Providers, ohmo Feishu Groups, and Safer Remotes
v0.1.8 — Providers, ohmo Feishu Groups, and Safer Remotes
OpenHarness v0.1.8 is a stabilization and provider-expansion release. It adds more first-class provider workflows, improves ohmo's Feishu group experience, hardens remote-channel security, and fixes several Windows/MCP reliability issues.
Highlights
-
New provider workflows
- Added NVIDIA NIM as a built-in OpenAI-compatible provider using
NVIDIA_API_KEY. - Added ModelScope Inference API support.
- Added Qwen (DashScope), MiniMax, and Gemini provider profiles.
- Improved OpenAI-compatible API behavior, including explicit bearer authorization headers and
<think>block filtering for compatible streaming responses.
- Added NVIDIA NIM as a built-in OpenAI-compatible provider using
-
ohmo Feishu group support
- Added Feishu managed group creation flow for ohmo.
- Added gateway-scoped provider/model commands for chat-based operation.
- Improved group routing and mention policy so ohmo responds in shared Feishu groups only when explicitly addressed.
- Hardened Feishu attachment filename handling.
-
Security and remote-channel hardening
- Kept sensitive config/auth/provider/model/ship commands local-only by default in remote channels.
- Kept bridge commands local-only by default.
- Added coverage for bridge spawn blocking and remote gateway security behavior.
- Rejected path traversal names during plugin uninstall.
-
Windows and shell reliability
- Fixed Windows agent/subagent spawning by direct-executing teammate argv instead of shell-wrapping Python paths.
- Windows shell resolution now skips discovered
bash.exebinaries that cannot actually run commands, falling back to PowerShell/cmd. - Improved Windows gateway process lifecycle handling.
- Avoided shell execution when opening browsers on Windows.
-
MCP, tools, and stability
- MCP startup now isolates failed servers instead of aborting the whole OpenHarness startup.
- Fixed subprocess stderr pipe deadlocks in grep/glob/bash/session runner paths.
- Bounded large tool results in conversation history and improved compaction under large/vision contexts.
- Improved skill frontmatter parsing with YAML
safe_loadfor bundled and user skills.
-
TUI and UX fixes
- Restored raw
DELbackspace handling for macOS Terminal-style environments. - Added better slash-command completion, markdown table rendering, spinner behavior, and escape interruption.
- Added image-to-text fallback support for text-only models and
--vision-modeloverride.
- Restored raw
External contributors
Thanks to the external contributors whose PRs are included in this release:
- @Litianhui888 — MCP startup isolation (#237)
- @Hinotoi-agent — remote command security hardening (#232, #209, #208, #198, #197)
- @nsxdavid — Windows agent spawn fix (#231)
- @voidborne-d — bundled skill frontmatter parsing (#229)
- @Mcy0618 — image-to-text fallback and ModelScope support (#227, #224)
- @WANG-Guangxin — invalid regex fallback fix (#219)
- @glitch-ux — Windows browser auth safety, async coordinator draining, autopilot shell safety, hook events (#217, #200, #188, #170)
- @Escapingbug — Windows gateway lifecycle and Telegram proxy config fixes (#193, #192)
- @ZevGit — Qwen provider profile (#207)
- @yl-jiang — subprocess stderr deadlock fixes and OpenAI-compatible think-block filtering (#205, #174)
- @he-yufeng — TUI slash-command completion polish (#185)
- @powAu3 — raw DEL backspace fix (#182)
- @flobo3 — shell subprocess stdin default fix (#179)
Install
pip install --upgrade openharness-ai==0.1.8Or run the installer from the repository docs.
v0.1.7 — TUI Polish & Safer Install
Highlights for 0.1.7
- Safer install flow:
scripts/install.shnow linksoh,ohmo, andopenharnessinto~/.local/bininstead of prepending the virtualenvbindirectory toPATH, which avoids clobbering Conda-managed shells. - Better React TUI input:
Shift+Enternow inserts a newline while plainEnterstill submits. - Quieter busy-state animation: the extra pseudo-animation line was removed, and Windows terminals now use conservative ASCII spinner frames to reduce flashing.
- PyPI package published:
openharness-ai==0.1.7.
What's Changed
- feat(tui): pair tool-call and tool-result rows for cleaner transcript by @yl-jiang in #111
- fix(auth): cache keyring probe and rename misleading encrypt/decrypt by @glitch-ux in #106
- feat(providers): add built-in Google Gemini provider profile by @glitch-ux in #105
- fix: regenerate system prompt on checkpoint restore by @JiangweiYe76 in #104
- fix(tui): keep busy spinner active throughout agent turn by @yl-jiang in #116
- fix(config): strip ANSI escape sequences from model names by @jiakeboge in #114
- fix(ui): show effective runtime model in header by @siaochuan in #95
- fix(grep): handle long rg lines without crashing by @tjb-tech in #112
- feat(personalization): auto-extract local environment rules from session history by @siaochuan in #65
- fix(grep): raise asyncio stream limit and catch ValueError on long lines by @yl-jiang in #110
- fix(skills): use yaml.safe_load for SKILL.md frontmatter parsing by @fengjie926 in #96
- [security] Harden path rules and web fetch network guards by @13ernkastel in #92
- bugfix: fix Claude subscription auth lookup on macOS by @hackereee in #123
- feat(sandbox): add Docker as an alternative sandbox backend by @glitch-ux in #121
- fix(persistence): atomic writes and locks for shared state by @glitch-ux in #128
- fix: harden gateway slash command security by @Hinotoi-agent in #127
- fix(feishu): reply in group threads instead of creating new topics by @hehe1111 in #125
- fix(tui): write trailing newline on exit so shell prompt starts on a fresh line by @yl-jiang in #133
- [Windows] Add PowerShell installer for native Windows support - Add … by @benben951 in #118
- fix(tools): todo_write updates existing items in-place instead of duplicating by @yl-jiang in #135
- fix(engine): keep parallel tool turns alive when one tool raises by @glitch-ux in #138
- feat(tui): add codex output style to mitigate streaming flicker by @siaochuan in #141
- fix(installer): detect installed launcher instead of hard-coding openh by @glitch-ux in #145
- [security] fix(ohmo): secure default remote channel allowlists by @Hinotoi-agent in #147
- fix(runtime): resolve profile base_url and support openai_compat format by @yay2008 in #146
- [codex] fix agent spawn overrides and task cleanup by @yu2001-s in #148
- fix(settings): Add Ollama Support and prevent env overrides from clobbering provider profile… by @forrestzhang in #139
- feat: add MiniMax as a first-class provider by @octo-patch in #140
- fix(agent): Explore and claude-code-guide no longer hard-code model=haiku by @yl-jiang in #154
- [security] fix(ohmo): isolate shared-chat sessions by sender by @Hinotoi-agent in #159
- [security] fix(plugin): address code execution via untrusted plugin activation by @Hinotoi-agent in #156
- [security] fix(personalization): stop replaying exported env var values by @shaun0927 in #151
- [security] fix(sandbox): fail closed for unsupported Docker domain policies by @shaun0927 in #152
New Contributors
- @JiangweiYe76 made their first contribution in #104
- @jiakeboge made their first contribution in #114
- @fengjie926 made their first contribution in #96
- @hackereee made their first contribution in #123
- @Hinotoi-agent made their first contribution in #127
- @hehe1111 made their first contribution in #125
- @benben951 made their first contribution in #118
- @yay2008 made their first contribution in #146
- @yu2001-s made their first contribution in #148
- @octo-patch made their first contribution in #140
- @shaun0927 made their first contribution in #151
Full Changelog: v0.1.6...v0.1.7
v0.1.6 — ohmo Personal Agent & Auto-Compaction
Highlights
ohmo — a personal AI agent built on OpenHarness. Chat with ohmo in Feishu / Slack / Telegram / Discord, and it forks branches, writes code, runs tests, and opens PRs on its own. ohmo runs on your existing Claude Code or Codex subscription — no extra API key needed.
pip install openharness-ai
oh setup
ohohmo init && ohmo config && ohmo gateway startWhat's New since v0.1.0
🤖 Swarm & Multi-Agent
- Full coordinator orchestration system with agent definition loading
- InProcessBackend with contextvars isolation, subprocess backend for pollable agents
- WorktreeManager with git worktree isolation per teammate
- TeamLifecycleManager with persistent team file management
- Mailbox communication system with file-lock layer extracted to standalone module
- Permission sync protocol for leader-worker bridging
- Subprocess teammates run in headless worker mode
🧠 Auto-Compaction
- Context auto-compression for long-running sessions
- Task state and channel logs preserved across compaction
- Tested: ohmo ran 4 days straight without manual compact or clear
📡 ohmo Personal Agent
ohmo init/ohmo config/ohmo gateway start— 3 commands to go live- 10 IM channels: Telegram, Slack, Discord, Feishu, DingTalk, WeChat, QQ, Matrix, WhatsApp, Email
- Channel slash commands, file attachments, multimodal gateway messages
- Runs on Claude Code subscription or Codex subscription
🔌 MCP
- HTTP transport support
- Auto-reconnect on disconnected servers
- JSON Schema type inference for tool inputs
- Tool-only server compatibility
🌙 Multi-Provider
- Native Moonshot / Kimi support with thinking model
reasoning_contenthandling - GitHub Copilot provider with OAuth device flow
- OpenAI-compatible API client (
--api-format openai) - Unified
oh setupwizard for all providers - Profile-scoped credentials — different endpoints no longer share one global key
🎨 TUI
- 5 switchable themes (
oh --theme cyberpunk) - TodoPanel, SwarmPanel, PlanMode indicator, enhanced AskUser modal
- Assistant messages render full Markdown in React TUI
- Permission modals serialized to prevent input swallowing
- Rendering throttle for smoother streaming
🛡️ Security & Stability
- Built-in sensitive path protection in PermissionChecker
- Shell injection fix in command hook
$ARGUMENTSsubstitution web_fetchURL validation hardened- EIO crash recovery in Ink TUI
- Windows: UTF-8 protocol, cmd flash fix, git prompt deadlock fix, WSL dialog fix
- Network error notification with real error messages
- glob/grep backed by ripgrep (10x faster)
📦 Release
pip install openharness-aion PyPI- Frontend bundled in wheel
- One-click installer:
curl -fsSL .../install.sh | bash oh --version/--resume/--continueflags- Cron scheduler daemon
182 commits · 242 files changed · 41,000+ lines added