aidevops

作者 marcusquinn已验证

Vibe-Coding is easy. DevOps is hard. OpenCode & Git token-efficient AI agent automation for your app, business, and personal development. Opinionated tools, services, CLI & API stack for speed, security, and 24/7 results. Open-source first. SOTA everything. Try on your repos for money-making magic.

381
Stars
63
Forks
Shell
语言
2026/8/23
添加时间

⚠️ 第三方软件声明

本 Skill 为第三方开源软件,独立托管于 GitHub。SkillTip 仅为信息目录,不控制或维护底层仓库。所显示的安全检查为自动化且范围有限,安装前请自行审查源码。

阅读服务条款

安装

添加到你的 Claude Code skills 目录:

# Add to your Claude Code skills
git clone https://github.com/marcusquinn/aidevops

快速入门

使用 aidevops 等 Skills 的指南。

安全报告

已验证

上次扫描:—

{
  "status": "PASSED",
  "issues": []
}

README.md

AI DevOps social graph preview

AI DevOps Framework

aidevops.sh is an OpenCode plugin and AI DevOps framework for people who want AI to do useful work across code, infrastructure, business, marketing, content, and creative projects without turning every job into another long, fragile chat.

Most AI tools still leave you doing the hard coordination yourself: finding the right context, choosing a model, protecting secrets, managing branches, watching CI, spotting stuck work, and remembering what went wrong last time. aidevops puts structure around that work so agents can share context, work safely in parallel, spend model budget where it matters, and leave the system better than they found it.

Recommended setup: OpenCode + OpenAI models. GPT-5.5 is the preferred high-capability model for complex agent work; GPT-5.4 mini is the preferred fast, lower-cost model for triage and routine implementation. Claude models (Anthropic) remain fully supported, and other model providers are evaluated from time to time as their quality, latency, and cost profiles change.

"Scope a mission to redesign the landing pages — break it into milestones, dispatch workers in parallel, validate each milestone, and track budget across the whole project."

One conversation, autonomous project delivery, with security, teamwork, token efficiency, and quality control built in.

Founded by Marcus Quinn on 9th November 2025 to help anyone level-up their AI & Open-Source game.

The Aim

Maximum value for your time and money. aidevops is built for the gap between “the model can probably do this” and “the work is actually done, verified, safe, and worth the cost.”

  • Load the right context when it is needed, instead of stuffing every agent, skill, and tool into the prompt.
  • Spend tokens and model budget deliberately. Cheap and fast models should handle routine work; stronger models should handle judgement, architecture, review, and risk.
  • Keep secrets out of chat. Credentials, tenants, scans, confirmations, and audit logs are part of the workflow, not an afterthought.
  • Let people and agents work across machines without trampling each other. Worktrees, branches, PRs, task IDs, mailbox state, and memory keep the work separated and traceable.
  • Notice when the system is struggling. Stuck workers, orphaned PRs, stale assignments, CI failures, review-bot traps, and repeated mistakes should become visible signals.
  • Improve the framework from real use. Imported skills, session learnings, quality findings, and better patterns should become better agents, hooks, scripts, and docs.
  • Optimise for profitable outcomes: useful work shipped, lower supervision cost, safer operations, and decisions that make sense beyond the next prompt.

The result: an AI operations platform that manages projects across every business domain — absorbing everything automatable so you can focus on what matters.

Built on proven patterns: aidevops implements industry-standard agent design patterns - including multi-layer action spaces, context isolation, and iterative execution loops.

Why This Framework?

Beyond single-task AI. A normal AI harness can be brilliant for one job and still weak at the work around the job. aidevops is for the surrounding discipline: context, routing, safety, git hygiene, collaboration, verification, memory, and follow-through.

What makes it different:

  • Pulse supervision - scheduled checks can dispatch workers, merge ready PRs, close loops, and surface stuck work.
  • Domain agents - code, automation, product, business, marketing, legal, content, research, SEO, health, reports, and framework work each get their own guidance.
  • Cross-model checks - risky operations can be reviewed by a second provider to reduce shared failure modes.
  • Service coverage - hosting, Git platforms, DNS, security, monitoring, deployment, payments, communications, and more are handled through repeatable helpers.
  • Mission work - larger goals can be split into milestones with validation, budget tracking, and automatic advancement.

GitHub Actions Quality Gate Status CodeFactor Maintainability Codacy Badge CodeRabbit

License: MIT Copyright

Version npm version Homebrew GitHub repository

Services Supported AGENTS.md AI Optimized MCP Servers API Integrations

Lines of code Dependencies

Languages by lines of code

Attribution

aidevops is MIT licensed. Reuse is welcome, including commercial use, provided the copyright and license notices are retained. If you build a derivative framework, automation bot, workflow library, or commercial product from aidevops code or distinctive operating patterns, see ATTRIBUTION.md for the required notices and preferred credit text.

Quick Reference

  • Purpose: AI-assisted DevOps automation framework
  • Install: npm install -g aidevops && aidevops update
  • Recommended runtime/models: OpenCode + OpenAI GPT-5.5 / GPT-5.4 mini
  • Entry: aidevops CLI, ~/.aidevops/agents/AGENTS.md
  • Stack: Bash scripts, TypeScript (Bun), MCP servers
  • Recent focus: OpenCode control-plane safety, local repo metrics, mobile simulator testing, self-hosted runner operations, and pulse/worker diagnostics

Key Commands

  • aidevops init - Initialize in any project
  • aidevops update - Update framework
  • aidevops auto-update - Automatic update polling (enable/disable/status)
  • aidevops runtime-bundle list - List retained validated runtime bundles; use rollback --bundle-id <id> --reason <text> for an explicit audited rollback
  • aidevops gpt56-context [enable|disable|status] - Keep GPT-5.6 at a 300K advertised context window in OpenCode (enabled by default), so 80% auto-compaction runs near 240K before long-context pricing; status verifies plugin discovery, initialization, hook registration, and effective limits
  • aidevops buzz [status|apply|rollback] - Inspect or manage Buzz Desktop OpenCode ACP compatibility
  • ~/.aidevops/agents/scripts/team-interface-helper.sh [providers|detect|status|doctor|plan] - Inspect registered collaboration providers, persist read-only observations, or emit deterministic dry-run plans; no provider-write command is exposed
  • aidevops opencode conversation --overlay FILE --dir PATH - Launch fixed-argv OpenCode ACP with a schema-validated ephemeral team-interface overlay and a final read-only capability guard; see .agents/reference/team-interface-opencode-overlays.md
  • aidevops secret - Manage secrets (gopass encrypted, AI-safe)
  • aidevops source-access - Manage exact-path, session-bound source-read approvals signed via sudo
  • aidevops security - Full security assessment (posture, secrets, supply chain)
  • aidevops lint audit - Audit native lint/format/typecheck commands and repo-verify hooks
  • aidevops lint configure --dry-run - Preview safe evidence-based lint provisioning
  • aidevops metrics generate - Generate local LOC, language, and dependency data for README badges or app about pages
  • /onboarding - Interactive setup wizard (in AI assistant)
  • /design-artifact - Route artifact-first UI, deck, email, poster, and mobile mockup work
  • /open-design - Manage the optional Open Design companion studio
  • /auto-browse - Learn, optimize, and graduate repeatable browser operations and web data-mining workflows
  • /report-render - Render report-ready Markdown or JSON to HTML with sticky TOC, print CSS, evidence badges, and source cards for PDF export
  • /report-token-use - Generate a local per-session token, model, compaction, and MCP-use report
  • /pulse - Run the autonomous supervisor loop for dispatch, merge, diagnostics, and stuck-work recovery
  • /serve-sim / serve-sim-helper.sh - Exercise mobile web flows in simulator-backed local previews

Agent Structure

  • 14 primary agents (Build+, Automate, Product, SEO, Marketing-Sales, etc.) with specialist @subagents on demand
  • 2,150+ agent and subagent markdown files organized by domain
  • 1,630+ helper scripts in .agents/scripts/
  • 185+ slash commands and workflow guides for common operations

What You Can Ask aidevops To Do

  • Build, fix, review, release, and maintain software with worktrees, PRs, tests, and quality gates.
  • Run infrastructure, hosting, DNS, monitoring, security, and deployment workflows.
  • Plan products, PRDs, onboarding, monetisation, growth, analytics, and UI direction.
  • Operate business, finance, receipts, invoices, marketing, outreach, SEO, content, video, and personal-productivity routines.
  • Discover the right capability with /skills recommend "TASK", /onboarding, or the OpenCode agent picker.

Recent framework upgrades

Since the last README feature refresh, aidevops has added or expanded:

  • OpenCode GUI/control-plane planning: ADRs, threat model, trust-boundary guidance, and containment rules for a future GUI that stays local-first, auditable, and explicitly separated from secret-bearing helpers (docs/gui/).
  • Mobile and simulator workflows: app-development guidance, App Store Connect support, Expo/Xcode/Swift workflows, Maestro/minisim/iOS Simulator MCP references, and serve-sim mobile web testing support (.agents/tools/mobile/).
  • Self-hosted runner operations: lifecycle and storage runbooks, Docker foreground-mode guidance, systemd timer freshness triage, and ExecStop race-guard documentation (.agents/reference/github-self-hosted-runners.md).
  • Pulse diagnostics and reliability: compact API-budget diagnostics, pulse cadence/API diagnostics, GitHub read ramp pacing, configurable worker floors, Renovate dashboard skipping, and more defensive duplicate/blocked-by/rate-limit handling.
  • Worker and PR observability: worker diagnostic failure families, runtime observability signals, review-thread response scanning, required-check validation, orphan-recovery base handling, and safer automated GitHub write guards.
  • Runtime-neutral safety and evidence contracts: shared command decisions across supported runtimes, commit-pinned plugin provenance with explicit hook authorization, recognized-client network checks, causal worker lineage, and redacted state snapshots/deltas in the existing observability database.
  • OpenCode runtime polish: versioned session title suffixes, session archive retention, OAuth pool hardening, debug-error preservation, and reusable shell-env version lookup in the OpenCode plugin.

Enterprise-Grade Quality & Security

Comprehensive DevOps framework with tried & tested services integrations, popular and trusted MCP servers, and enterprise-grade infrastructure quality assurance code monitoring and recommendations.

Vault security model: aidevops defines protected data classes, provider routing labels, trust boundaries, and phased encrypted sync architecture in .agents/reference/vault.md. Vault guidance is local-first: third-party AI providers can only reason over data that has been decrypted into their prompt or tool context, so provider-side logs/retention remain outside Vault's technical control. Future local LLM mode reduces provider exposure but not local host compromise risk.

Vault passphrase warning: aidevops cannot recover a lost Vault passphrase. Save it in a trusted password manager with backups; never paste it into AI chat, CLI arguments, environment variables, logs, issue comments, or test fixtures.

Report creation, previews, and PDF exports

Use aidevops to turn evidence bundles into decision-ready reports while keeping Markdown or JSON as the canonical source. Report agents can produce AI-search audits, SEO/GEO scorecards, delivery reviews, campaign reports, board packs, incident summaries, recurring client handoffs, and before/after remediation evidence.

New report capabilities include:

  • Markdown-first report anatomy with cover pages, executive summaries, evidence ledgers, source cards, action prompts, appendix links, charts, Mermaid/LaTeX fallbacks, and verified, partial, inferred, or missing evidence badges.
  • DESIGN.md-backed visual templates plus basic no-CSS output for lightweight handoff.
  • Browser preview HTML with sticky contents, source-card links, copy buttons, and light/dark theme variants where a style supports them.
  • PDF-ready profiles for A4, US Letter, and 16:9 slides. Generated PDF links use *-a4.pdf, *-usletter.pdf, and *-slides.pdf names.
  • Versioned examples under _reports/examples/; open _reports/examples/index.html locally to browse the example reports, rendered styles, and PDF exports.

Create a report:

  1. Load reports/general.md for structure, then the matching domain report doc such as reports/seo-geo.md, reports/development.md, reports/marketing.md, or reports/business.md.
  2. Gather source evidence first. Use deterministic run: steps or service helpers for collection, then ask the domain agent plus agent:Reports to interpret and prioritise.
  3. Save canonical source as report.md or report.json in _reports/drafts/<report-name>/ while working, or in _reports/examples/<example-name>/ only after privacy review.
  4. Render with /report-render report.md or .agents/scripts/report-render-helper.sh render report.md --template <style> --theme auto --pdf-profile a4 --output report.html.
  5. Export PDFs from Chrome/Chromium using the generated HTML and the A4, US Letter, or slides profiles. Regenerate derived HTML/PDF files instead of hand-editing them.

Create a repeatable report agent:

  1. Read reports/routine-handoff.md and tools/build-agent/build-agent.md.
  2. Define the report cadence, evidence collection commands, source IDs, privacy rules, target template/style, and verification gates.
  3. Put deterministic collection in run: steps and reserve agent:Reports for narrative, evidence interpretation, recommendations, and handoff tasks.
  4. Store reusable agent instructions in the appropriate agent tier (custom/ for local/client-specific agents; shared .agents/ only for broadly reusable framework agents).

Security Notice

This framework provides agentic AI assistants with powerful infrastructure access. Use responsibly.

Capabilities: Execute commands, access credentials, modify infrastructure, interact with APIs Your responsibility: Use trusted AI providers, rotate credentials regularly, monitor activity

Security Commands

aidevops security              # Run ALL checks (posture + hygiene + supply chain)
aidevops security posture      # Interactive security posture setup (gopass, gh auth, SSH)
aidevops security status       # Combined posture + hygiene summary
aidevops security scan         # Secret hygiene & supply chain scan only
aidevops security scan-pth     # Python .pth file audit (supply chain attack vector)
aidevops security scan-secrets # Plaintext credential locations only
aidevops security scan-deps    # Unpinned dependency check
aidevops security check        # Per-repo security posture assessment
aidevops security dismiss <id> # Dismiss a security advisory after taking action
aidevops source-access status  # List temporary source-read approvals
sudo -k /usr/bin/python3 -I -B /etc/aidevops/source-access/source-access-helper.py revoke <approval-id>

Running aidevops security with no arguments is the single command that covers everything — user security posture, plaintext secret detection, supply chain IoC scanning, and active advisories.

When a read guard identifies only a low-confidence source-code basename match, it emits a scoped request. A maintainer can run the displayed root-broker approval command. Approvals are bound to the exact runtime session, user, Git-tracked regular source path, approved content digest, and guard reason; they expire within 12 hours and never override private-key, environment-file, credential-store, hard-link, symlink, changed-content, cross-worktree, or untracked-file denials. Repeating --path while creating a request produces one exact, repository-bound manifest that a human can approve once. The plugin redirects each approved read to its root-controlled immutable snapshot; revocation removes the receipt and every snapshot.

Routine aidevops update never requests sudo or launches an editor. When the root-owned broker differs from the active release, update prints a machine-readable deferred action; a human runs aidevops setup --scope source-access in an attached terminal. Scoped setup verifies the published signed tag, invalidates inherited sudo, asks for one confirmation, has root fetch the exact reviewed broker bytes directly over TLS, compares those downloads byte-for-byte with the signed Git objects, creates a dedicated root-only signing key under /etc/aidevops/source-access, and invalidates sudo again. It never executes or copies the user-writable aidevops deployment as root. The plugin rejects approvals whenever installed broker bytes differ from the active release.

Security advisories are delivered via aidevops update and shown in the session greeting until dismissed. The scanner never exposes secret values — only file locations and key names. All remediation commands should be run in a separate terminal, not inside AI chat sessions.

Supply chain hardening: All Python dependencies are pinned to exact versions (==) to prevent malicious package upgrades. The .pth file auditor detects known supply chain attack indicators (e.g., the LiteLLM March 2026 PyPI compromise).

Quick Start

Installation Options

npm (recommended - verified provenance):

npm install -g aidevops && aidevops update

Note: npm suppresses postinstall output. The && aidevops update deploys agents to ~/.aidevops/agents/. The CLI will remind you if agents need updating.

Bun (fast alternative):

bun install -g aidevops && aidevops update

Homebrew (macOS/Linux):

brew install marcusquinn/tap/aidevops && aidevops update

Direct from source (aidevops.sh):

bash <(curl -fsSL https://aidevops.sh/install)

Updater recovery for v3.32.213: If aidevops update stops because the official framework source checkout is not in the project registry, run the direct installer above once, then rerun aidevops update. Do not add the framework checkout to the downstream project registry or bypass canonical remote validation.

Manual (git clone):

git clone https://github.com/marcusquinn/aidevops.git ~/Git/aidevops
~/Git/aidevops/setup.sh

That's it! The setup script will:

  • Clone/update the repo to ~/Git/aidevops
  • Deploy agents to ~/.aidevops/agents/
  • Install the aidevops CLI command
  • Configure your AI assistants automatically
  • Offer to install Oh My Zsh (optional, opt-in) for enhanced shell experience
  • Install recommended token-efficiency tooling by default, including RTK for compact git/gh/test/lint command summaries before output reaches AI context
  • Guide you through recommended tools (Tabby, Zed, Git CLIs)
  • Ensure all PATH and alias changes work in both bash, zsh, and fish
  • When Claude Code is installed, add a claude alias that runs claude --dangerously-skip-permissions (skips per-tool permission prompts). Re-running setup updates the alias automatically. To grant permissions per-session instead, press Shift-Tab inside Claude Code to cycle through permission modes (default → skip permissions → auto-approve).

New users: Start OpenCode and type /onboarding to configure your services interactively. OpenCode is the recommended tool for aidevops; pair it with OpenAI GPT-5.5 and GPT-5.4 mini for the best current results across agent tiers. The onboarding wizard will:

  • Explain what aidevops can do
  • Ask about your work to give personalized recommendations
  • Show which services are configured vs need setup
  • Guide you through setting up each service with links and commands

After installation, use the CLI:

aidevops status           # Check what's installed
aidevops doctor           # Detect duplicate installs and PATH conflicts
aidevops update           # Update framework + check registered projects
aidevops auto-update      # Manage automatic update polling (every 10 min)
aidevops runtime-bundle list # Inspect retained validated runtime bundles
aidevops init             # Initialize aidevops in any project
aidevops features         # List available features
aidevops repos            # List/add/remove registered projects
aidevops design           # DESIGN.md detection + brand guideline HTML/PDF exports
aidevops detect           # Scan for unregistered aidevops projects
aidevops upgrade-planning # Upgrade TODO.md/PLANS.md to latest templates
aidevops update-tools     # Check and update installed tools
aidevops uninstall        # Remove aidevops

Optional Design Artifact Studio

aidevops now treats design as a self-contained stack with optional peripherals:

  • Google DESIGN.md standard: AI-readable design systems with YAML tokens, linting, previews, and brand/style libraries (.agents/tools/design/design-md.md).
  • Init-aware design files: aidevops init records has_interface and seeds root DESIGN.md for standard repos plus minimal-scope repos with detected GUI/interface markers.
  • Brand guideline exports: aidevops design guidelines . --pdf generates _reports/brand-guidelines/brand-guidelines.md, HTML, and A4/US Letter/slides PDFs from DESIGN.md.
  • Repo rollout: aidevops design survey --json audits owned initialized GUI repos; aidevops design issues --apply files worker-ready auto-dispatch issues for missing DESIGN.md/brand-guideline artifacts.
  • Design agents and skills: brand identity, palettes, UI inspiration, product UI rules, shadcn/Tailwind/UI skills, Nothing-style design, email rendering, Remotion/video, and browser-based UI verification.
  • Artifact routing commands: /design-artifact decides whether to use aidevops-native implementation or a companion artifact studio; /open-design manages optional Open Design workflows.
  • Verification gates: Playwright screenshots, accessibility/contrast checks, email rendering, deck export/fidelity checks, and media smoke tests before generated artifacts are accepted.

Optional companion: Open Design by nexu-io (Apache-2.0) is supported as a peripheral for live sandboxed previews, design-skill pickers, .od/ artifact workspaces, and HTML/PDF/PPTX/ZIP-style exports. aidevops remains canonical for agents, skill ingestion, Google DESIGN.md, local hosting, and verification.

# Inspect optional companion status
open-design-helper.sh status

# Print safe install plan only
open-design-helper.sh install

# Install alongside aidevops only after opting in
open-design-helper.sh install --execute

# Start through aidevops local HTTPS if Open Design only prints localhost
open-design-helper.sh start --https-local open-design
# → https://open-design.local when localdev is configured

Imported Open Design skills are not copied verbatim. They are evaluated through aidevops build-agent methodology, deduplicated against existing agents, flattened into aidevops *-skill.md structure, attributed to upstream, and given verification commands. See .agents/tools/design/open-design-ingestion.md for the full skill-value matrix.

Project tracking: When you run aidevops init, the project is automatically registered in ~/.config/aidevops/repos.json. Running aidevops update checks all registered projects for version updates.

Use aidevops in Any Project

Initialize aidevops features in any git repository:

cd ~/your-project
aidevops init                         # Enable the default feature set
aidevops init planning                # Enable only planning
aidevops init planning,time-tracking  # Enable specific features
aidevops init deployment-context   # Scaffold a deployment manifest
aidevops init wordpress-context    # Scaffold WordPress + deployment manifests

This creates:

  • .aidevops.json - Configuration with enabled features
  • .agents/AGENTS.md - Project-specific agent context
  • TODO.md - Quick task tracking with time estimates
  • todo/PLANS.md - Complex execution plans
  • .beads/ - Task graph database (if beads enabled)
  • .aidevops/deployments.yaml - Deployment instance inventory (opt-in)
  • .aidevops/wordpress.yaml - WordPress and LocalWP context (opt-in)

Available features: planning, git-workflow, code-quality, time-tracking, database, beads, sops, security, deployment-context, wordpress-context. hosting-context is an alias for deployment-context; wordpress-context implies deployment context. The default all set intentionally excludes both project-instance context features.

Per-repo platform setup

After aidevops init registers a new repo, run /setup-git in your AI assistant to apply per-repo platform secrets. Most notably, this sets SYNC_PAT — a GitHub Actions secret that lets issue-sync.yml push TODO.md auto-completion past branch protection.

This is distinct from /onboarding (per-account credentials like gh auth login): GitHub Actions secrets are scoped per-repo, so each repo needs its own. You need gh auth login to succeed before any per-repo helper can run, so /onboarding comes first, /setup-git second.

Run /setup-git again whenever you register a new repo with aidevops repos add or when a SYNC_PAT advisory appears in the session greeting toast. If you skip this step, issue-sync.yml will post a remediation comment when it hits branch protection — /setup-git walks through the fix.

Upgrade Planning Files

When aidevops templates evolve, upgrade existing projects to the latest format:

aidevops upgrade-planning           # Interactive upgrade with backup
aidevops upgrade-planning --dry-run # Preview changes without modifying
aidevops upgrade-planning --force   # Skip confirmation prompt

This preserves your existing tasks while adding TOON-enhanced parsing, dependency tracking, and better structure.

Automatic detection: aidevops update now scans all registered projects for outdated planning templates (comparing TOON meta version numbers) and offers to upgrade them in-place with backups.

Task Graph Visualization with Beads

Beads provides task dependency tracking and graph visualization:

aidevops init beads              # Enable beads (includes planning)

Task Dependencies:

- [ ] t001 First task
- [ ] t002 Second task blocked-by:t001
- [ ] t001.1 Subtask of t001
SyntaxMeaning
blocked-by:t001Task waits for t001 to complete
blocks:t002This task blocks t002
t001.1Subtask of t001 (hierarchical)

Commands:

CommandPurpose
/readyShow tasks with no open blockers
/list-verifyList verification queue (pending, passed, failed)
/sync-beadsSync TODO.md/PLANS.md with Beads graph
bd listList all tasks in Beads
bd readyShow ready tasks (Beads CLI)
bd graph <id>Show dependency graph for an issue

Architecture: aidevops markdown files (TODO.md, PLANS.md) are the source of truth. Beads syncs from them for visualization.

Optional Viewers: Beyond the bd CLI, there are community viewers for richer visualization:

  • beads_viewer (Python TUI) - PageRank, critical path analysis
  • beads-ui (Web) - Live updates in browser
  • bdui (React/Ink TUI) - Modern terminal UI
  • perles (Rust TUI) - BQL query language

See .agents/tools/task-management/beads.md for complete documentation and installation commands.

Your AI assistant now has agentic access to 30+ service integrations.

OpenAI Models in OpenCode (Recommended)

OpenCode with OpenAI is the current recommended aidevops setup. Use GPT-5.5 for complex reasoning, architecture, security-sensitive review, and hard agent tiers; use GPT-5.4 mini for fast triage, routine implementation, retries, and lower-cost worker throughput.

Authenticate via the pool:

aidevops model-accounts-pool add openai
# Restart OpenCode after adding

Why this is the default:

  • Best current cross-tier results — strongest observed balance across interactive Build+, workers, review, and dispatch tiers
  • Good cost/latency split — GPT-5.5 for depth, GPT-5.4 mini for high-volume routine work
  • Provider isolation — OpenAI accounts rotate independently from Anthropic, Google, Cursor, and local providers
  • Fallback-friendly — Claude, Gemini, Cursor, and local models remain available when a task or rate-limit profile calls for them

OpenCode Anthropic OAuth (Supported)

OpenCode includes Anthropic OAuth authentication natively — no API key needed. OAuth is covered by your Claude Pro/Max subscription at zero additional cost.

Authenticate via the pool (recommended):

aidevops model-accounts-pool add anthropic
# Opens browser OAuth flow — no API key required
# Restart OpenCode after adding

Or via the OpenCode TUI:

Open OpenCode → Ctrl+A → Select AnthropicLogin with Claude.ai → follow browser OAuth flow.

Note: opencode auth login prompts for an API key, not OAuth. Use the commands above for subscription-based OAuth access.

Benefits:

  • Still fully supported for users who prefer Claude models or already have Claude Pro/Max
  • Zero marginal cost for Claude Pro/Max subscribers (covered by subscription)
  • Automatic token refresh — no manual re-authentication needed
  • Multiple accounts — add more accounts to the pool for automatic rotation when one hits rate limits
  • Beta features enabled — extended thinking modes and latest features

Cursor Models via Pool Proxy

Access Cursor Pro models (Composer 2, Claude 4.6 Opus/Sonnet, GPT-5.x, Gemini 3.1 Pro) in OpenCode through a local gRPC proxy that translates OpenAI-compatible requests to Cursor's protobuf/HTTP2 protocol.

Setup:

# Add your Cursor account to the pool (reads from local Cursor IDE)
oauth-pool-helper.sh add cursor

# Restart OpenCode — Cursor models appear in Ctrl+T model picker

How it works:

  • Reads Cursor credentials from the local IDE state database
  • Starts a gRPC proxy that speaks Cursor's native protocol (not the cursor-agent CLI)
  • Discovers available models via gRPC and registers them as an OpenCode provider
  • Supports true streaming, tool calling, and automatic token refresh
  • Falls back gracefully if no Cursor accounts are in the pool

Benefits:

  • Zero additional cost for Cursor Pro subscribers
  • True streaming — responses stream as they arrive (not buffered)
  • Tool calling — Cursor's native MCP tool protocol works through the proxy
  • Model discovery — automatically detects all models available to your account
  • Pool rotation — multiple accounts with LRU rotation and 429 failover

Google AI Pool (Gemini CLI / Vertex AI)

Use your Google AI Pro, AI Ultra, or Workspace subscription for Gemini models. Tokens are injected as ADC bearer tokens that Gemini CLI, Vertex AI SDK, and the Gemini API pick up automatically.

Setup:

# Add your Google account to the pool (browser OAuth flow)
aidevops model-accounts-pool add google

# Restart OpenCode — token is injected as GOOGLE_OAUTH_ACCESS_TOKEN

Supported plans:

  • Google AI Pro (~$25/mo) — daily Gemini CLI limits
  • Google AI Ultra (~$65/mo) — higher daily limits
  • Google Workspace with Gemini add-on — enterprise daily limits

Isolation guarantee: Google auth failures never affect Anthropic/OpenAI/Cursor providers. A Google 429 or auth error only puts the Google pool into cooldown.

GitHub AI Agent Integration

Enable AI-powered issue resolution directly from GitHub. Comment /oc fix this on any issue and the AI creates a branch, implements the fix, and opens a PR.

Security-first design - The workflow includes:

  • Trusted users only (OWNER/MEMBER/COLLABORATOR)
  • ai-approved label required on issues before AI processing
  • Prompt injection pattern detection
  • Audit logging of all invocations
  • 15-minute timeout and rate limiting

Quick setup:

# 1. Install the OpenCode GitHub App
# Visit: https://github.com/apps/opencode-agent

# 2. Add API key secret for your chosen provider
# Repository → Settings → Secrets → OPENAI_API_KEY or ANTHROPIC_API_KEY

# 3. Create required labels
gh label create "ai-approved" --color "0E8A16" --description "Issue approved for AI agent"
gh label create "security-review" --color "D93F0B" --description "Requires security review"

The secure workflow is included at .github/workflows/opencode-agent.yml.

Usage:

ContextCommandResult
Issue (with ai-approved label)/oc fix thisCreates branch + PR
Issue/oc explain thisAI analyzes and replies
PR/oc review this PRCode review feedback
PR Files tab/oc add error handling hereLine-specific fix

See .agents/tools/git/opencode-github-security.md for the full security documentation.

Supported AI tool: OpenCode is the recommended and tested AI coding tool for aidevops. All features, agents, and workflows are designed and tested for OpenCode first. We recommend OpenAI models for the best current results across all agent tiers: GPT-5.4 mini for fast triage/routine work and GPT-5.5 for complex implementation, review, and reasoning. Claude models (Anthropic) remain fully supported, and other providers are tested as their capabilities change.

The native ai_research tool uses OpenCode's configured providers and canonical simple, standard, and thinking workload tiers; it does not require a specific provider credential.

Recommended stack:

  • OpenCode - The recommended AI coding agent. Powerful agentic TUI/CLI with native MCP support, Tab-based agent switching, LSP integration, plugin ecosystem, and excellent DX. All aidevops features are designed and tested for OpenCode first.
  • OpenCode Zen - Free tier of OpenCode with included models. Start working with AI straight away at no cost -- no API keys or subscriptions required.
  • OpenAI GPT-5.5 / GPT-5.4 mini - Recommended model pair for aidevops today. Use GPT-5.5 for complex reasoning and high-impact agent tiers; use GPT-5.4 mini for triage, routine implementation, and cost-efficient parallel workers.
  • Claude (Anthropic) - Fully supported alternative provider. Claude models remain useful for fallback, cross-provider verification, and users with Claude Pro/Max OAuth access.
  • Tabby - Recommended terminal. Colour-coded Profiles per project/repo, auto-syncs tab titles with git/session context and marks OpenCode turns from the first submitted message as ⚪, 🔴, 🟡, or 🟢.
  • Zed - Recommended editor. High-performance with AI integration (use with the OpenCode Agent Extension).

Buzz Desktop OpenCode ACP compatibility

Buzz Desktop 0.5.4 can save an OpenCode managed agent without the required acp runtime argument, causing ACP initialization to time out. On macOS, aidevops init and aidevops update automatically reconcile affected records after deploying the current helper. Close Buzz first; if it is running, setup defers the change and reports the manual command.

aidevops buzz status    # Inspect compatibility state without changing it
aidevops buzz apply     # Add "acp" only to eligible empty argument lists
aidevops buzz rollback  # Restore only fields changed by aidevops

The migration preserves custom runtime arguments and unknown record fields, uses private backups and rollback state, and fails closed for unsupported Buzz versions or unsafe store paths. It never prints the managed-agent store, which can contain fallback credentials.

Troubleshooting Auth

If you see "Anthropic Key Missing", "OpenAI Key Missing", or the model stops responding, run these commands from any terminal — no working model session required.

Step 1 — Check pool health

aidevops model-accounts-pool status       # counts: available / rate-limited / auth-error
aidevops model-accounts-pool check        # live token validity test per account

Step 2 — Fix based on what you see

SymptomCommand
OpenAI account shows rate-limitedaidevops model-accounts-pool rotate openai
Anthropic account shows rate-limitedaidevops model-accounts-pool rotate anthropic
All accounts in cooldownaidevops model-accounts-pool reset-cooldowns
OpenAI account shows auth-erroraidevops model-accounts-pool add openai (re-auth)
Anthropic account shows auth-erroraidevops model-accounts-pool add anthropic (re-auth)
Pool is empty (no accounts)aidevops model-accounts-pool add openai
Recently re-authenticated, still brokenaidevops model-accounts-pool assign-pending openai
Google Gemini CLI rate-limitedaidevops model-accounts-pool rotate google
Google token expiredaidevops model-accounts-pool add google (re-auth)

Step 3 — If still broken, re-add the account

aidevops model-accounts-pool add openai        # ChatGPT Plus/Pro
aidevops model-accounts-pool add anthropic     # Claude Pro/Max — opens browser OAuth
aidevops model-accounts-pool add cursor        # Cursor Pro (reads from local IDE)
aidevops model-accounts-pool add google        # Google AI Pro/Ultra/Workspace — browser OAuth
aidevops model-accounts-pool import claude-cli # Import from existing Claude CLI auth

Restart OpenCode after any add, rotate, or reset-cooldowns to pick up the new credentials.

Full command reference

aidevops model-accounts-pool status            # Pool health at a glance
aidevops model-accounts-pool list              # Per-account detail + expiry
aidevops model-accounts-pool check             # Live API validity test
aidevops model-accounts-pool rotate [provider] # Switch to next available account NOW
aidevops model-accounts-pool reset-cooldowns   # Clear all rate-limit cooldowns
aidevops model-accounts-pool assign-pending <p># Assign stranded pending token
aidevops model-accounts-pool remove <p> <email># Remove an account

Note: reset-cooldowns clears cooldowns in the pool file. If OpenCode is already running, the in-memory token endpoint cooldown is only cleared when OpenCode restarts or when you use the /model-accounts-pool reset-cooldowns slash command inside an active session.

If you prefer guided help: Open OpenCode with a free model (OpenCode Zen includes free models that don't require any API key or subscription) and run the auth troubleshooting agent by typing:

@auth-troubleshooting

The agent contains the full recovery flow and symptom table. Free models work fine for this — no paid subscription needed.

Terminal Tab Title Sync

Your terminal tab/window title automatically shows repo/branch context when working in git repositories. Interactive OpenCode tabs add ⚪ as soon as the first root-session message is submitted and keep it when the initial title becomes descriptive, 🔴 while retrying after an error, 🟡 while awaiting permission, and 🟢 when finished and awaiting input. This helps identify both the work context and session state across multiple terminal sessions.

Supported terminals: Tabby, cmux, iTerm2, Kitty, Alacritty, WezTerm, Hyper, and most xterm-compatible terminals.

How it works: The pre-edit-check.sh script's primary role is enforcing git workflow protection (blocking edits on main/master branches). As a secondary, non-blocking action, it updates the terminal title via escape sequences. The OpenCode plugin listens for root-session user-message, status, and permission events and updates the same title without changing the stored OpenCode session name. No configuration is needed when dynamic terminal titles are enabled.

Example format: {repo}/{branch-type}/{description}

See .agents/tools/terminal/terminal-title.md for customization options.

Companion tool:

  • claude-code CLI - Called from within OpenCode for sub-tasks and headless dispatch

Collaborator compatibility: Projects initialized with aidevops init include pointer files (.cursorrules, .windsurfrules, etc.) that reference AGENTS.md, helping collaborators using other editors find project context. aidevops does not install into or configure those tools.

Repo courtesy files: aidevops init scaffolds standard repo files if they don't exist: DESIGN.md for GUI/interface repos, README.md, LICENCE (MIT), CHANGELOG.md, CONTRIBUTING.md, SECURITY.md, CODE_OF_CONDUCT.md. Author name and email are auto-detected from git config. Existing files are never overwritten.

Core Capabilities

AI-First Infrastructure Management:

  • SSH server access, remote command execution, API integrations
  • DNS management, application deployment, email monitoring
  • Git platform management, domain purchasing, setup automation
  • WordPress management, credential security, code auditing

Autonomous Orchestration:

  • Pulse supervisor - Autonomous AI supervisor runs every 2 minutes via launchd — merges ready PRs, dispatches workers, kills stuck processes, detects orphaned PRs, syncs TODO state with GitHub, triages quality findings, and advances missions. No human in the loop
  • Missions - Multi-day autonomous projects: /mission scopes a high-level goal into milestones and features. The pulse dispatches workers, validates milestones, tracks budget, and advances through the project automatically (mission-dashboard-helper.sh)
  • Multi-model verification - Destructive operations (force push, production deploy, data migration) are verified by a second AI model from a different provider before execution. Different providers have different failure modes, so correlated hallucinations are rare
  • Supervisor - SQLite state machine dispatches tasks to parallel AI agents with retry cycles, batch management, and cron scheduling
  • Runners - Named headless agent instances with persistent identity, instructions, and memory namespaces
  • /runners command - Batch dispatch from task IDs, PR URLs, or descriptions with concurrency control and progress monitoring
  • Self-hosted runner operations - GitHub runner lifecycle, storage, Docker foreground mode, systemd timers, and cleanup race guidance for reliable local/hosted worker capacity
  • Mailbox - SQLite-backed inter-agent messaging for coordination across parallel sessions
  • Worktree isolation - Each agent works on its own branch in a separate directory, no merge conflicts
  • Budget tracking - Append-only cost log (budget-tracker-helper.sh) with burn-rate analysis and /budget-analysis command for model routing decisions
  • Observability - LLM request/tool capture plus append-only, redacted runtime lifecycle/state evidence with worker correlation and causal lineage in the existing local SQLite database
  • Rate limits and API budget diagnostics - Per-provider rate-limit configuration, secondary cooldown capture, reset-aware pacing, and compact API budget summaries for pulse and worker decisions

Project Intelligence:

  • Bundles - Project-type presets that auto-configure model tiers, quality gates, and agent routing per repo. 7 built-in bundles (web-app, library, cli-tool, content-site, infrastructure, agent, schema) with auto-detection from marker files (bundle-helper.sh)
  • TTSR rules - Soft rule engine (ttsr-rule-loader.sh) with .agents/rules/ directory for AI output correction (e.g., no-edit-on-main, no-glob-for-discovery)
  • Unified review - /review applies one evidence and finding contract to issues, PRs, local patches, branches, and commits. Workflow-owned findings are verified and repaired autonomously; ad-hoc human reviews can remain report-only
  • Cross-review - /cross-review dispatches the same prompt to multiple AI models in parallel, diffs results, and optionally auto-scores via a judge model
  • Local models - Run AI models locally via llama.cpp for free, private, offline inference (local-model-helper.sh) with HuggingFace GGUF model management
  • Tech stack lookup - /tech-stack detects technology stacks of URLs or finds sites using specific technologies (Wappalyzer, httpx, nuclei, BuiltWith)
  • IP reputation - ip-reputation-helper.sh checks IP addresses against multiple reputation databases (Spamhaus, ProxyCheck, AbuseIPDB) before VPS purchase or deployment
  • Mobile app guidance - Expo, Swift/Xcode, App Store Connect, simulator automation, push/onboarding/monetisation/testing, and mobile web previews through serve-sim
  • GUI control plane planning - Local-first product scope, stack and repo-layout ADRs, GUI trust boundaries, and threat model for future aidevops UI surfaces

Conversational Memory & Entity System:

  • Entity memory - Cross-channel relationship continuity (entity-helper.sh): people, agents, and services tracked across Matrix, SimpleX, email, and CLI with versioned profiles
  • Conversational memory - Per-conversation context management (conversation-helper.sh): idle detection, immutable summaries, tone profile extraction
  • Three-layer architecture - Layer 0 (immutable raw log), Layer 1 (tactical summaries), Layer 2 (strategic entity profiles) in shared SQLite

Communications:

  • SimpleX bot - Channel-agnostic gateway with SimpleX Chat as first adapter for AI agent dispatch (simplex-bot/)
  • Matterbridge - Multi-platform chat bridge connecting 20+ platforms including Matrix, Discord, Telegram, Slack, IRC, WhatsApp, XMPP (matterbridge-helper.sh)
  • Account knowledge and approval-bound social operations - Bounded account collection uses guarded X, named PRAW Reddit, and youtube.readonly user-OAuth YouTube adapters with stable identity, independent checkpoints, and explicit unsupported coverage. Owner-only immediate/scheduled posts, replies, likes/upvotes, bookmarks/saves, receipts, reconciliation, and mention/reply workflow state remain a separate fixed-provider subsystem. Model-provider auth such as OpenCode xAI/Grok remains separate from social API OAuth (content/social-xurl.md, content/social-reddit.md, content/social-youtube.md, knowledge-social-helper.sh)
  • Localdev - Local development environment manager with dnsmasq, Traefik, mkcert for production-like .local domains with HTTPS (localdev-helper.sh)

MCP Toolkit:

  • MCPorter - Discover, call, compose, and generate CLIs/typed clients for MCP servers (mcporter npm package)
  • OpenAPI Search - Search and explore any OpenAPI specification via MCP (zero install, Cloudflare Worker)
  • Cloudflare Code Mode - Full Cloudflare API (2,500+ endpoints) via 2 tools in ~1,000 tokens

Unified Interface:

  • Standardized commands across all providers
  • Automated SSH configuration and multi-account support for all services
  • Security-first design with comprehensive logging, code quality reviews, and continual feedback-based improvement

Quality Control & Monitoring:

  • Multi-Platform Analysis: SonarCloud, CodeFactor, Codacy, CodeRabbit, Qlty, Snyk
  • Review gate preferences: choose whether true review-bot rate limits block merges (aidevops review-gate owner/repo wait) or allow merge with follow-up quality coverage (aidevops review-gate owner/repo pass, the default). Per-tool overrides are supported, for example aidevops review-gate owner/repo --tool coderabbitai wait. Failed, skipped, or placeholder bot states are not treated as rate limits and continue to block until a real review/status appears or a human resolves them.
  • Performance Auditing: PageSpeed Insights, Lighthouse, WebPageTest, Core Web Vitals (/performance command)
  • SEO Toolchain: 40+ SEO subagents including Semrush, Ahrefs, ContentKing, Screaming Frog, Bing Webmaster Tools, Rich Results Test, programmatic SEO, analytics tracking, schema validation, content analysis, keyword mapping, and AI readiness
  • SEO Debugging: Open Graph validation, favicon checker, social preview testing
  • Email Deliverability: SPF/DKIM/DMARC/MX validation, blacklist checking
  • Uptime Monitoring: Updown.io integration for website and SSL monitoring

Imported Skills

aidevops includes curated skills imported from external sources. Skills support automatic update tracking:

SkillSourceDescription
cloudflare-platformdmmulroy/cloudflare-skill60 Cloudflare products: Workers, Pages, D1, R2, KV, Durable Objects, AI, networking, security
heygenheygen-com/skillsAI avatar video creation API: avatars, voices, video generation, streaming, webhooks
remotionremotion-dev/skillsProgrammatic video creation with React, animations, rendering
video-prompt-designsnubroot/Veo-3-Meta-FrameworkAI video prompt engineering - 7-component meta prompt framework for Veo 3
animejsanimejs.comJavaScript animation library patterns and API (via Context7)
caldav-calendarClawdHubCalDAV calendar sync via vdirsyncer + khal (iCloud, Google, Fastmail, Nextcloud)
proxmox-fullClawdHubComplete Proxmox VE hypervisor management via REST API

CLI Commands:

aidevops skill add <owner/repo>    # Import a skill from GitHub
aidevops skill add clawdhub:<slug> # Import a skill from ClawdHub
aidevops skill list                # List imported skills
aidevops skill check               # Check for upstream updates
aidevops skill update [name]       # Update specific or all skills
aidevops skill scan [name]         # Security scan skills (Cisco Skill Scanner)
aidevops skill remove <name>       # Remove an imported skill

Skills are registered in ~/.aidevops/agents/configs/skill-sources.json with upstream tracking for update detection.

Security Scanning:

Imported skills are automatically security-scanned using Cisco Skill Scanner when installed. Scanning runs on both initial import and updates -- pulling a new version of a skill triggers the same security checks as the first import. CRITICAL/HIGH findings block the operation; MEDIUM/LOW findings warn but allow. Telemetry is disabled - no data is sent to third parties.

When a VirusTotal API key is configured (aidevops secret set VIRUSTOTAL_MARCUSQUINN), an advisory second layer scans file hashes against 70+ AV engines and checks domains/URLs referenced in skill content. VT scans are non-blocking -- the Cisco scanner remains the security gate.

ScenarioSecurity scan runs?CRITICAL/HIGH blocks?
aidevops skill add <source>YesYes
aidevops skill update [name]YesYes
aidevops skill add <source> --forceYesYes
aidevops skill add <source> --skip-securityYes (reports only)No (warns)
aidevops skill scan [name]Yes (standalone)Report only

The --force flag only controls file overwrite behavior (replacing an existing skill without prompting). To bypass security blocking, use --skip-security explicitly -- this separation ensures that routine updates and re-imports never silently skip security checks.

Scan results are logged to .agents/SKILL-SCAN-RESULTS.md automatically on each batch scan and skill import, providing a transparent audit trail of security posture over time.

Browse community skills: skills.sh | ClawdHub | Specification: agentskills.io

Reference:

Agent Sources (Private Repos)

Sync agents from private Git repositories into the framework. Private repos keep their own agents, helper scripts, and slash commands — aidevops sources sync deploys them alongside the core agents.

aidevops sources add ~/Git/my-private-agents     # Register a local repo
aidevops sources add-remote git@github.com:u/r.git  # Clone and register a remote repo
aidevops sources list                             # List configured sources
aidevops sources sync                             # Sync all sources
aidevops sources remove my-private-agents         # Remove a source

How it works: Private repos contain a .agents/ directory with agent subdirectories. Agents with mode: primary in their frontmatter are symlinked to the agents root for auto-discovery as primary agent tabs. Markdown files with agent: frontmatter are deployed as /slash commands. All sources sync automatically during aidevops update.

Reference: .agents/aidevops/agent-sources.md

Agent Design Patterns

aidevops implements proven agent design patterns identified by Lance Martin (LangChain).

PatternDescriptionaidevops Implementation
Give Agents a ComputerFilesystem + shell for persistent context~/.aidevops/.agent-workspace/, 1,630+ helper scripts
Multi-Layer Action SpaceFew tools, push actions to computerPer-agent MCP filtering (~12-20 tools each)
Knowledge Graph RoutingIndexed, cross-referenced agents instead of isolated skillssubagent-index.toon maps 2,150+ agents by domain, purpose, and dependency — agents discover related context through the graph, not just their own file
Progressive DisclosureLoad context on-demandSubagent routing with content summaries, YAML frontmatter, read-on-demand
Offload ContextWrite results to filesystem.agent-workspace/work/[project]/ for persistence
Cache ContextPrompt caching for costStable instruction prefixes
Isolate ContextSub-agents with separate windowsSubagent files with specific tool permissions
Multi-Agent OrchestrationCoordinate parallel agentsTOON mailbox, agent registry, supervisor dispatch
Compaction ResiliencePreserve context across compactionOpenCode plugin injects dynamic state at compaction time
Ralph LoopIterative execution until complete/full-loop, full-loop-helper.sh
Evolve ContextLearn from sessions/remember, /recall with SQLite FTS5 + opt-in semantic search
Pattern TrackingLearn what works/fails/patterns command, memory-helper.sh
Token-Efficient SerialisationMinimise context overhead for structured dataTOON format — 20-60% token reduction vs JSON/YAML for agent indexes, registries, and data exchange
Token-Efficient Tool OutputSummarise noisy terminal output without hiding evidenceRTK is installed by default during setup; start with rtk-helper.sh for compact supported summaries, then rerun raw/direct commands when filtered output is insufficient; bypass compression for file reads, JSON assertions, exact diffs, security scans, and other verbatim evidence
Cost-Aware RoutingMatch model to task complexitymodel-routing.md with provider-aware tier guidance, /route command
Model ComparisonCompare models side-by-side/compare-models (live data), /compare-models-free (offline)
Response ScoringEvaluate actual model outputs/score-responses with structured criteria

Key insight: Context is a finite resource with diminishing returns. aidevops treats every token as precious - loading only what's needed, when it's needed.

See .agents/aidevops/architecture.md for detailed implementation notes and references.

Multi-Agent Orchestration

Run multiple AI agents in parallel on separate branches, coordinated through a lightweight mailbox system. Each agent works independently in its own git worktree while the supervisor manages task distribution and status reporting.

Architecture:

Supervisor (pulse loop)
├── Agent Registry (TOON format - who's active, what branch, idle/busy)
├── Mailbox System (SQLite WAL-mode, indexed queries)
│   ├── task_assignment → worker inbox
│   ├── status_report → coordinator outbox
│   └── broadcast → all agents
└── Model Routing (tier-based: GPT-5.4 mini / GPT-5.5 / provider fallbacks)

Key components:

ComponentScriptPurpose
Mailboxmail-helper.shSQLite-backed inter-agent messaging (send, check, broadcast, archive)
Supervisorsupervisor-helper.shAutonomous multi-task orchestration with SQLite state machine, batches, retry cycles, cron scheduling, auto-pickup from TODO.md
Registrymail-helper.sh registerAgent registration with role, branch, worktree, heartbeat
Model routingmodel-routing.md, /routeCost-aware routing across OpenAI, Anthropic, Gemini, Cursor, Grok, and local providers
Budget trackingbudget-tracker-helper.shAppend-only cost log for model routing decisions
Observabilityobservability.mjs, runtime-events.mjsLLM/tool metrics plus redacted lifecycle, lineage, and state evidence in one local SQLite database

How it works:

  1. Each agent registers on startup (mail-helper.sh register --role worker)
  2. Supervisor runs periodic pulses (supervisor-helper.sh pulse)
  3. Pulse collects status reports, dispatches queued tasks to idle workers
  4. Agents send completion reports back via mailbox
  5. SQLite WAL mode + busy_timeout handles concurrent access (79x faster than previous file-based system)

Compaction plugin (.agents/plugins/opencode-aidevops/): When OpenCode compacts context (at ~200K tokens), the plugin injects current session state - agent registry, pending mailbox messages, git context, and relevant memories - ensuring continuity across compaction boundaries.

Custom system prompt (.agents/prompts/build.txt): Based on upstream OpenCode with aidevops-specific overrides for tool preferences, professional objectivity, and per-model reinforcements for weaker models.

Subagent index (.agents/subagent-index.toon): Compressed TOON routing table listing all agents, subagents, workflows, and scripts with model tier assignments - enables fast agent discovery without loading full markdown files.

Autonomous Orchestration & Parallel Agents

Why this matters: Long-running tasks -- batch PR reviews, multi-site audits, large refactors, multi-day feature projects -- are where AI agents deliver the most value. Instead of babysitting one task at a time, the supervisor dispatches work to parallel agents, each in its own git worktree, with automatic retry, progress tracking, and batch completion reporting.

Pulse Supervisor: Autonomous AI Operations

The pulse is the heartbeat of aidevops — an autonomous AI supervisor that runs every 2 minutes via launchd. There is no human at the terminal. It manages the entire development pipeline across all repos registered with pulse: true.

What it does each cycle:

PhaseAction
Capacity checkCircuit breaker, dynamic worker slots calculated from available RAM
Merge ready PRsGreen CI + no blocking reviews → squash merge (free — no worker slot needed)
Fix failing PRsDispatch a worker to fix CI failures or address review feedback
Detect stuck workPRs open 6+ hours with no activity → flag or close and re-file
Dispatch workersRoute open issues to available worker slots, respecting priority and blocked-by: dependencies
Advance missionsCheck active multi-day missions, dispatch features, validate milestones, track budget
Triage qualityRead daily quality sweep findings (ShellCheck, SonarCloud, Codacy, CodeRabbit), create issues for actionable findings
Sync TODOsCreate GitHub issues for unsynced TODO entries, commit ref changes
Respect API budgetUse cached/prefetched GitHub metadata, cooldown headers, and ramp pacing before spending more API calls
Kill stuck workersWorkers running 3+ hours with no PR are killed to free slots
Detect orphaned PRsOpen PRs with no active worker and no activity for 6+ hours are flagged for re-dispatch

Operational intelligence:

  • Struggle-ratio — computes messages / max(1, commits) for each active worker. High ratio (>30) with >30 min elapsed and zero commits flags the worker as "struggling". Ratio >50 after 1 hour flags "thrashing". Informational signal — the supervisor LLM decides the action (kill, wait, re-dispatch with more context)
  • Circuit breaker — prevents cascading failures by tracking success/failure rates and tripping when error rate exceeds threshold
  • Dynamic concurrency — worker slot count adapts to available RAM, not a hardcoded constant
  • API budget diagnostics — compact reports show GitHub core/search usage, cooldown provenance, cached PR metadata freshness, and pacing decisions before pulse burns through API quota
  • Worker failure families — headless runtime errors, local runtime diagnostics, blocked-by lookup gaps, provider quota/credit exhaustion, and review-thread remediation issues are classified for targeted redispatch
  • Stale assignment recovery — tasks assigned to workers that died (no active process, no PR, 3+ hours stale) are automatically unassigned and made available for re-dispatch
  • Priority ordering — green PRs (free merge) > failing PRs (closer to done) > high-priority/bug issues > active mission features > product repos > smaller tasks > oldest
  • Repository campaign shadow — an opt-in, default-off projection preserves an oldest-ready frontier, semantic work state, and device-aware runner lanes without changing legacy dispatch or GitHub authority. See .agents/reference/repository-campaigns.md

The pulse is an LLM, not a script. It reads issue bodies, assesses context, and uses judgment. When it encounters something unexpected — an issue body that says "completed", a task with no clear description, a label that doesn't match reality — it handles it the way a competent human manager would.

# Pulse runs automatically via launchd (every 2 minutes)
# Manual trigger:
opencode run "/pulse"

See: .agents/scripts/commands/pulse.md for the full supervisor specification.

Missions: Multi-Day Autonomous Projects

Missions are the highest-level orchestration primitive — autonomous multi-day projects that break a high-level goal into milestones, features, and validation criteria. The pulse supervisor advances them automatically.

# Scope a mission interactively
/mission "Redesign the landing pages for mobile-first with A/B testing"

How missions work:

  1. /mission scopes the goal into milestones with features and acceptance criteria
  2. Each feature becomes a TODO entry tagged mission:mNNN with a GitHub issue
  3. The pulse dispatches features as regular workers (respecting MAX_WORKERS)
  4. When all features in a milestone complete, the pulse dispatches a validation worker to verify integration
  5. Passed milestones advance automatically — the next milestone's features are dispatched
  6. Budget tracking pauses the mission if any category exceeds the alert threshold (default 80%)

Two execution modes:

ModeWorkflowBest for
FullWorktree + PR per feature, standard review flowProduction code, collaborative projects
POCDirect commits, skip ceremonyPrototypes, experiments, proof-of-concept

Mission state is tracked in a JSON file committed to the repo. Each pulse cycle reads the state, acts on it, and commits updates — so any session (or the next pulse) can pick up where the last one left off.

See: .agents/workflows/mission-orchestrator.md for the full orchestrator specification, .agents/scripts/commands/dashboard.md for the mission progress dashboard.

Multi-Model Verification: Cross-Provider Safety

High-stakes operations are verified by a second AI model from a different provider before execution. This catches single-model hallucinations before destructive operations cause irreversible damage.

When verification triggers:

Risk LevelExamplesAction
Criticalgit push --force to main, DROP DATABASE, production deployBlocked unless second model agrees
HighForce push to task ref, data migration, secret exposureWarned, verification recommended
MediumBulk file deletion, config changesLogged
LowNormal edits, test runsNo verification

How it works:

  1. pre-edit-check.sh screens operations against the high-stakes taxonomy
  2. For critical/high operations, verify-operation-helper.sh sends the operation context to a second model (different provider than the primary)
  3. The verifier independently assesses whether the operation is safe
  4. On disagreement, the operation is blocked (critical) or warned (high)
  5. All verification decisions are logged for audit

Why cross-provider? Same-provider models share training data and failure modes. A GPT hallucination is unlikely to be reproduced by Claude or Gemini, and vice versa. The verifier uses the cheapest suitable model tier, so cost is minimal per check.

Configuration: Per-repo via .agents/reference/high-stakes-operations.md. Opt-out with VERIFY_ENABLED=false (not recommended).

See: .agents/tools/verification/parallel-verify.md for the verification agent specification.

Project Bundles: Auto-Configuration

Bundles are project-type presets that auto-configure model tiers, quality gates, and agent routing per repo. Instead of manually configuring each project, bundles detect what kind of project you're working on and apply sensible defaults.

Built-in bundles:

BundleAuto-detected byModel defaultQuality gatesAgent routing
web-apppackage.json + framework markersstandardFull (lint, test, build, a11y)Build+ default
librarypackage.json with main/exportsstandardFull + API docs checkBuild+ default
cli-toolbin field in package.jsonstandardShellCheck, testBuild+ default
content-siteCMS markers, wp-config.phpfastLighthouse, SEOMarketing for content tasks
infrastructureDockerfile, terraform/, ansible/standardShellCheck, security scanBuild+ default
agentAGENTS.md, .agents/thinkingAgent review, prompt qualityBuild+ default

Resolution priority: Explicit bundle field in repos.json > .aidevops.json project config > auto-detection from marker files.

CLI:

bundle-helper.sh detect <repo-path>    # Auto-detect bundle type
bundle-helper.sh resolve <repo-path>   # Show resolved config (with overrides)
bundle-helper.sh show <bundle-name>    # Show bundle defaults
bundle-helper.sh list                  # List all available bundles

See: .agents/bundles/ for bundle definitions, .agents/scripts/bundle-helper.sh for the CLI.

Parallel Agents & Headless Dispatch

Run multiple AI sessions concurrently with isolated contexts. Named runners provide persistent agent identities with their own instructions and memory.

FeatureDescription
Headless dispatchheadless-runtime-helper.sh run provides canonical model routing, retries, and session isolation
Durable one-shot schedulingaidevops schedule once queues private, restart-safe delayed work without fake recurring jobs or sleeper processes
RunnersNamed agent instances with per-runner AGENTS.md, config, and run logs (runner-helper.sh)
Self-hosted runner runbooksGitHub runner storage, lifecycle, Docker foreground mode, timer freshness, and cleanup-race guidance (.agents/reference/github-self-hosted-runners.md)
Session managementResume sessions with -s <id> or -c, fork with SDK
Memory namespacesPer-runner memory isolation with shared access when needed
SDK orchestration@opencode-ai/sdk for TypeScript parallel dispatch via Promise.all
Matrix integrationChat-triggered dispatch via self-hosted Matrix (optional)
# Create a named runner
runner-helper.sh create code-reviewer --description "Reviews code for security and quality"

# Dispatch a task (one-shot)
runner-helper.sh run code-reviewer "Review src/auth/ for vulnerabilities"

# Queue one delayed execution and inspect its lifecycle
aidevops schedule once --after 2h --name "Review authentication" \
  --dir ~/Git/example --prompt-file ~/.config/aidevops/prompts/auth-review.md
aidevops schedule status

# Dispatch against warm server (faster, no MCP cold boot)
opencode serve --port 4096 &
runner-helper.sh run code-reviewer "Review src/auth/" --attach http://localhost:4096

# Parallel dispatch via CLI
opencode run --attach http://localhost:4096 --title "Review" "Review src/auth/" &
opencode run --attach http://localhost:4096 --title "Tests" "Generate tests for src/utils/" &
wait

# List runners and status
runner-helper.sh list
runner-helper.sh status code-reviewer

Architecture:

OpenCode Server (opencode serve)
├── Session 1 (runner/code-reviewer)
├── Session 2 (runner/seo-analyst)
└── Session 3 (scheduled-task)
         ↑
    HTTP API / SSE Events
         ↑
┌────────┴────────┐
│  Dispatch Layer │ ← runner-helper.sh, cron, Matrix bot, SDK
└─────────────────┘

Example runner templates: code-reviewer, seo-analyst - copy and customize for your own runners.

Matrix bot dispatch (optional): Bridge Matrix chat rooms to runners for chat-triggered AI. Accepted text events normalize through the provider-neutral contract and are durably claimed before dispatch. SQLite context is isolated by room and actor; idle sessions compact to summaries without deleting immutable interaction history.

# Setup Matrix bot (interactive wizard)
matrix-dispatch-helper.sh setup

# Map rooms to runners (mutable context is isolated by room and actor)
matrix-dispatch-helper.sh map '!dev-room:server' code-reviewer
matrix-dispatch-helper.sh map '!seo-room:server' seo-analyst

# Start bot (daemon mode)
matrix-dispatch-helper.sh start --daemon

# In Matrix room: "!ai Review src/auth.ts for security issues"

# Manage sessions
matrix-dispatch-helper.sh sessions list
matrix-dispatch-helper.sh sessions stats

See: headless-dispatch.md for full documentation including parallel vs sequential decision guide, SDK examples, CI/CD integration, and custom agent configuration. matrix-bot.md for Matrix bot setup including Cloudron Synapse guide and session persistence.

Self-Improving Agent System

Agents that learn from experience and contribute improvements:

PhaseDescription
ReviewAnalyze memory for success/failure patterns (memory-helper.sh)
RefineGenerate and apply improvements to agents
TestValidate in isolated OpenCode sessions
PRContribute to community with privacy filtering

Safety guardrails:

  • Worktree isolation for all changes
  • Human approval required for PRs
  • Mandatory privacy filter (secretlint + pattern redaction)
  • Dry-run default, explicit opt-in for PR creation
  • Audit log to memory

Agent Testing Framework

Test agent behavior through isolated AI sessions with automated validation:

# Create a test suite
agent-test-helper.sh create my-tests

# Run tests (auto-detects claude or opencode CLI)
agent-test-helper.sh run my-tests

# Quick single-prompt test
agent-test-helper.sh run-one "What tools do you have?" --expect "bash"

# Before/after comparison for agent changes
agent-test-helper.sh baseline my-tests   # Save current behavior
# ... modify agents ...
agent-test-helper.sh compare my-tests    # Detect regressions

Test suites are JSON files with prompts and validation rules (expect_contains, expect_not_contains, expect_regex, min_length, max_length). Results are saved for historical tracking.

See: agent-testing.md subagent for full documentation and example test suites.

Voice Bridge - Talk to Your AI Agent

Speak naturally to your AI coding agent and hear it respond. The voice bridge connects your microphone to OpenCode via a fast local pipeline -- ask questions, give instructions, execute tasks, all by voice.

Mic → Silero VAD → Whisper MLX (1.4s) → OpenCode (4-6s) → Edge TTS (0.4s) → Speaker

Round-trip: ~6-8 seconds on Apple Silicon. The agent can edit files, run commands, create PRs, and confirm what it did -- all via voice.

Quick start:

# Start a voice conversation (installs deps automatically)
voice-helper.sh talk

# Choose engines and voice
voice-helper.sh talk whisper-mlx edge-tts en-GB-SoniaNeural
voice-helper.sh talk whisper-mlx macos-say    # Offline mode

# Utilities
voice-helper.sh devices      # List audio input/output devices
voice-helper.sh voices       # List available TTS voices
voice-helper.sh benchmark    # Test STT/TTS/LLM speeds
voice-helper.sh status       # Check component availability

Features:

FeatureDetails
Swappable STTwhisper-mlx (fastest on Apple Silicon), faster-whisper (CPU)
Swappable TTSedge-tts (best quality), macos-say (offline), facebookMMS (local)
Voice exitSay "that's all", "goodbye", "all for now" to end naturally
STT correctionLLM sanity-checks transcription errors before acting (e.g. "test.txte" → "test.txt")
Task executionFull tool access -- edit files, git operations, run commands
Session handbackConversation transcript output on exit for calling agent context
TUI compatibleGraceful degradation when launched from AI tool's Bash (no tty)

How it works: The bridge uses opencode run --attach to connect to a running OpenCode server for low-latency responses (~4-6s vs ~30s cold start). It automatically starts opencode serve if not already running.

Requirements: Apple Silicon Mac (for whisper-mlx), Python 3.10+, internet (for edge-tts). The voice helper installs Python dependencies automatically into the S2S venv.

Speech-to-Speech Pipeline (Advanced)

For advanced use cases (custom LLMs, server/client deployment, multi-language, phone integration), the full huggingface/speech-to-speech pipeline is also available:

speech-to-speech-helper.sh setup              # Install pipeline
speech-to-speech-helper.sh start --local-mac  # Run on Apple Silicon
speech-to-speech-helper.sh start --cuda       # Run on NVIDIA GPU
speech-to-speech-helper.sh start --server     # Server mode (remote clients)

Supported languages: English, French, Spanish, Chinese, Japanese, Korean (auto-detect or fixed).

Additional voice methods:

MethodDescription
VoiceInk + ShortcutmacOS: transcription → OpenCode API → response
iPhone ShortcutiOS: dictate → HTTP → speak response
Pipecat STSFull voice pipeline: Soniox STT → AI → Cartesia TTS

See: speech-to-speech.md for full component options, CLI parameters, and integration patterns (Twilio phone, video narration, voice-driven DevOps).

Scheduled Agent Tasks

Cron-based agent dispatch for automated workflows:

# Example: Daily SEO report at 9am
0 9 * * * ~/.aidevops/agents/scripts/runner-helper.sh run "seo-analyst" "Generate daily SEO report"

See: TODO.md tasks t109-t118 for implementation status.

Requirements

Recommended Hardware

aidevops itself is lightweight (shell scripts + markdown), but AI model workloads benefit from capable hardware:

TierMachineCPURAMGPUBest For
MinimumAny modern laptop4+ cores8GBNoneFramework only, cloud AI APIs
RecommendedMac Studio / desktopApple M1+ or 8+ cores16GB+MPS (Apple) or NVIDIA 8GB+Local voice, browser automation, dev servers
Power UserWorkstation8+ cores32GB+NVIDIA 24GB+ VRAMFull voice pipeline, local LLMs, parallel agents
ServerCloud GPUAny16GB+A100 / H100Production voice, multi-user, batch processing

Cloud GPU providers for on-demand GPU access: NVIDIA Cloud, Vast.ai, RunPod, Lambda. See .agents/tools/infrastructure/cloud-gpu.md for the full deployment guide (SSH setup, Docker, model caching, cost optimization).

Note: Most aidevops features (infrastructure management, SEO, code quality, Git workflows) require no GPU. GPU is only needed for local AI model inference (voice pipeline, vision models, local LLMs).

Software Dependencies

# Install dependencies (auto-detected by setup.sh)
brew install sshpass jq curl mkcert dnsmasq fd ripgrep  # macOS
sudo apt-get install sshpass jq curl dnsmasq fd-find ripgrep  # Ubuntu/Debian

# Generate SSH key
ssh-keygen -t ed25519 -C "your-email@domain.com"

File Discovery Tools

AI agents use fast file discovery tools for efficient codebase navigation:

ToolPurposeSpeed
fdFast file finder (replaces find)~10x faster
ripgrepFast content search (replaces grep)~10x faster

Both tools respect .gitignore by default and are written in Rust for maximum performance.

Preference order for file discovery:

  1. git ls-files '*.md' - Instant, git-tracked files only
  2. fd -e md - Fast, respects .gitignore
  3. rg --files -g '*.md' - Fast, respects .gitignore
  4. Built-in glob tools - Fallback when bash unavailable

The setup script offers to install these tools automatically.

Comprehensive Service Coverage

Infrastructure & Hosting

  • Hostinger: Shared hosting, domains, email
  • Hetzner Cloud: VPS servers, networking, load balancers
  • Closte: Managed hosting, application deployment
  • Coolify Enhanced with CLI: Self-hosted PaaS with CLI integration
  • Cloudron Enhanced with packaging guide: Server and app management platform with custom app packaging support
  • Vercel Enhanced with CLI: Modern web deployment platform with CLI integration
  • AWS: Cloud infrastructure support via standard protocols
  • DigitalOcean: Cloud infrastructure support via standard protocols

Domain & DNS

Development & Git Platforms with CLI Integration

  • GitHub Enhanced with CLI: Repository management, actions, API, GitHub CLI (gh) integration
  • GitLab Enhanced with CLI: Self-hosted and cloud Git platform with GitLab CLI (glab) integration
  • Gitea Enhanced with CLI: Lightweight Git service with Gitea CLI (tea) integration
  • Agno: Local AI agent operating system for DevOps automation
  • Pandoc: Document conversion to markdown for AI processing

AI Orchestration Frameworks

  • Langflow: Visual drag-and-drop builder for AI workflows (MIT, localhost:7860)
  • CrewAI: Multi-agent teams with role-based orchestration (MIT, localhost:8501)
  • AutoGen: Microsoft's agentic AI framework with MCP support (MIT, localhost:8081)

Design, UI & Artifact Creation

  • Google DESIGN.md standard: Canonical AI-readable design systems with YAML tokens, Markdown rationale, linting, Tailwind/DTCG export, and preview generation. aidevops keeps DESIGN.md as the source of truth for UI agents.
  • Design library: 54 brand examples and 12 original style archetypes for agent-ready visual direction, plus palette, brand identity, and UI inspiration workflows.
  • Artifact commands: /design-artifact routes prototype, deck, email, poster, social carousel, and mobile mockup requests; /open-design manages optional Open Design companion workflows.
  • Open Design Optional peripheral: Local-first design artifact studio by nexu-io (Apache-2.0) for sandboxed previews, design-skill pickers, .od/ workspaces, and exports. It installs alongside aidevops only when requested; selected skills are ingested via aidevops build-agent optimisation, not imported verbatim.
  • Local HTTPS previews: localdev-helper.sh can wrap Open Design or other dev servers with mkcert-backed .local routes when tools only expose localhost.
  • Verification: workflows/ui-verification.md, email-design-test-helper.sh, design preview screenshots, and deck/media smoke tests provide evidence before generated artifacts ship.

Mobile App & Simulator Testing

  • Mobile app stack guidance: Expo, Swift/Xcode, backend, analytics, monetisation, onboarding, notification, publishing, and test strategy references for mobile delivery (.agents/tools/mobile/).
  • Simulator-backed web testing: serve-sim guidance and helpers cover local/mobile preview flows, prompt failure handling, and simulator smoke tests before mobile UI changes ship.
  • Device and automation options: agent-device, App Store Connect, Maestro, minisim, iOS Simulator MCP, Xcodebuild MCP, and accessibility tooling references help agents choose the right mobile verification path.
  • Mobile-first artifact routing: /design-artifact can route mobile mockups and app screens through the design stack, then hand implementation to mobile/testing specialists.

Video Creation

  • Remotion: Programmatic video creation with React - animations, compositions, media handling, captions
  • Video Prompt Design: AI video prompt engineering using the 7-component meta prompt framework for Veo 3 and similar models
  • Kie.ai: Unified asynchronous Market API and kie-helper.sh workflow for image, video, audio, uploads, callbacks, and credit checks with model-specific JSON pass-through
  • MuAPI: Multimodal AI API for image/video/audio/VFX generation, workflows, agents, music (Suno), and lip-sync - unified creative orchestration platform
  • yt-dlp: YouTube video/audio/playlist/channel downloads, transcript extraction, and local file audio conversion via ffmpeg

WordPress Development

  • LocalWP: WordPress development environment with MCP database access
  • MainWP: WordPress site management dashboard

Git CLI Enhancement Features:

  • .agents/scripts/github-cli-helper.sh: Advanced GitHub repository, issue, PR, and branch management
  • .agents/scripts/gitlab-cli-helper.sh: Complete GitLab project, issue, MR, and branch management
  • .agents/scripts/gitea-cli-helper.sh: Full Gitea repository, issue, PR, and branch management

Security & Code Quality

  • gopass: GPG-encrypted secret management with AI-native wrapper (aidevops secret) - subprocess injection + output redaction keeps secrets out of AI context
  • Vaultwarden: Password and secrets management
  • SonarCloud: Security and quality analysis (A-grade ratings)
  • CodeFactor: Code quality metrics (A+ score)
  • Codacy: Multi-tool analysis (0 findings)
  • CodeRabbit: AI-powered code reviews
  • Snyk: Security vulnerability scanning
  • Socket: Dependency security and supply chain protection
  • Sentry: Error monitoring and performance tracking
  • Cisco Skill Scanner: Security scanner for AI agent skills (prompt injection, exfiltration, malicious code)
  • VirusTotal: Advisory threat intelligence via VT API v3 -- file hash scanning (70+ AV engines), domain/URL reputation checks for imported skills
  • Secretlint: Detect exposed secrets in code
  • OSV Scanner: Google's vulnerability database scanner
  • Qlty: Universal code quality platform (70+ linters, auto-fixes)
  • Retired review compatibility: Historical Gemini Code Assist GitHub reviews remain readable, but the sunset integration is no longer advertised or configurable

AI Prompt Optimization

  • Augment Context Engine: Semantic codebase retrieval with deep code understanding
  • Repomix: Pack codebases into AI-friendly context (80% token reduction with compress mode)
  • DSPy: Framework for programming with language models
  • DSPyGround: Interactive playground for prompt optimization
  • TOON Format: Token-Oriented Object Notation - 20-60% token reduction for LLM prompts

Document Processing & OCR

  • Document Creation Agent (document-creation-helper.sh): Unified document format conversion, template-based creation, and OCR for scanned PDFs/images. Routes to the best available tool (pandoc, odfpy, LibreOffice, Tesseract, EasyOCR, GLM-OCR) based on format pair and availability. Supports 13+ formats (ODT, DOCX, PDF, MD, HTML, EPUB, PPTX, ODP, XLSX, ODS, RTF, CSV, TSV).
  • LibPDF: PDF form filling, digital signatures (PAdES B-B/T/LT/LTA), encryption, merge/split, text extraction
  • MinerU: Layout-aware PDF-to-markdown/JSON conversion with OCR (109 languages), formula-to-LaTeX, and table extraction (53k+ stars, AGPL-3.0)
  • Unstract: LLM-powered structured data extraction from unstructured documents (PDF, images, DOCX)
  • GLM-OCR: Local OCR via Ollama - purpose-built for document text extraction (tables, forms, complex layouts) with zero cloud dependency

PDF/OCR Tool Selection:

NeedToolWhy
Format conversionDocument Creation AgentAuto-selects best tool, 13+ formats
Complex PDF to markdownMinerULayout-aware, formulas, tables, 109-language OCR
Quick text extractionGLM-OCRLocal, fast, no API keys, privacy-first
Structured JSON outputUnstractSchema-based extraction, complex documents
Screen/window OCRPeekaboo + GLM-OCRpeekaboo image --analyze --model ollama/glm-ocr
PDF text extractionLibPDFNative PDF parsing, no AI needed
Simple format conversionPandocLightweight, broad format support
Scanned PDF OCRDocument Creation AgentAuto-detects, routes to Tesseract/EasyOCR/GLM-OCR

Quick start:

# Document creation agent
document-creation-helper.sh status                          # Check available tools
document-creation-helper.sh install --standard              # Install core tools
document-creation-helper.sh convert report.pdf --to odt     # Convert formats
document-creation-helper.sh convert scan.pdf --to md --ocr  # OCR scanned PDF
document-creation-helper.sh template draft --type letter     # Generate template

# GLM-OCR direct
ollama pull glm-ocr
ollama run glm-ocr "Extract all text" --images /path/to/document.png

See .agents/tools/ocr/glm-ocr.md for batch processing, PDF workflows, and Peekaboo integration.

Communications

  • Twilio: SMS, voice calls, WhatsApp, phone verification (Verify API), call recording & transcription
  • Telfon: Twilio-powered cloud phone system with iOS/Android/Chrome apps for end-user calling interface
  • Matrix: Self-hosted chat with bot integration for AI runner dispatch (matrix-dispatch-helper.sh)
  • SimpleX Chat: Privacy-first messaging with AI bot gateway for agent dispatch (simplex-bot/)
  • Matterbridge: Multi-platform chat bridge connecting 20+ platforms (Matrix, Discord, Telegram, Slack, IRC, WhatsApp, XMPP) with SimpleX adapter (matterbridge-helper.sh)

Animation & Video

  • Anime.js: Lightweight JavaScript animation library for CSS, SVG, DOM attributes, and JS objects
  • Remotion: Programmatic video creation with React - create videos using code with 29 specialized rule files
  • Video Prompt Design: Structured prompt engineering for AI video generation (Veo 3, 7-component framework, character consistency, audio design)

Voice AI

  • Voice Bridge: Talk to your AI coding agent via speech -- Silero VAD → Whisper MLX → OpenCode → Edge TTS (~6-8s round-trip)
  • Speech-to-Speech: Open-source modular voice pipeline (VAD → STT → LLM → TTS) with local GPU and cloud GPU deployment
  • Pipecat: Real-time voice agent framework with Soniox STT, Cartesia TTS, and multi-LLM support

Performance & Monitoring

  • PageSpeed Insights: Website performance auditing
  • Lighthouse: Comprehensive web app analysis
  • WebPageTest: Real-world performance testing from 40+ global locations with filmstrip, waterfall, and Core Web Vitals
  • Updown.io: Website uptime and SSL monitoring

AI & Documentation

  • Context7: Real-time documentation access for libraries and frameworks
  • Context7 CLI mode: npx ctx7 setup --opencode --cli for docs lookup without MCP transport (useful fallback in shell-first workflows)
  • Local Models: Run AI models locally via llama.cpp for free, private, offline inference with HuggingFace GGUF model management (local-model-helper.sh)

Local Development

  • Localdev: Local development environment manager with dnsmasq, Traefik, and mkcert for production-like .local domains with HTTPS on port 443 (localdev-helper.sh)

MCP Integrations

Model Context Protocol servers for real-time AI assistant integration. The framework configures these MCPs for OpenCode (TUI, Desktop, and Extension for Zed/VSCode).

All Supported MCPs (20 available)

MCP packages are installed globally via bun install -g for instant startup (no npx registry lookups). Run setup.sh or aidevops update-tools to update to latest versions.

MCPPurposeTierAPI Key Required
Augment Context EngineSemantic codebase retrievalGlobalYes (Augment account)
Claude Code MCPClaude as sub-agentGlobalNo
Amazon Order HistoryOrder data extractionPer-agentNo
Chrome DevToolsBrowser debugging & automationPer-agentNo
Context7Library documentation lookupPer-agentNo
Docker MCPContainer managementPer-agentNo
Google AnalyticsAnalytics dataPer-agentYes (Google API)
Google Search ConsoleSearch performance dataPer-agentYes (Google API)
Grep by VercelGitHub code searchPer-agentNo
LocalWPWordPress database accessPer-agentNo (local)
macOS AutomatormacOS automationPer-agentNo
PlaywriterBrowser with extensionsPer-agentNo
QuickFileAccounting APIPer-agentYes
RepomixCodebase packing for AI contextPer-agentNo
SentryError trackingPer-agentYes
shadcnUI component libraryPer-agentNo
SocketDependency securityPer-agentNo
UnstractDocument data extractionPer-agentYes
OpenAPI SearchSearch and explore any OpenAPI specPer-agentNo
Cloudflare Code ModeFull Cloudflare API (2,500+ endpoints via 2 tools)Per-agentYes (Cloudflare)

Tier explanation:

  • Global - Tools always available (loaded into every session)
  • Per-agent - Tools disabled globally, enabled per-agent via config (zero context overhead when unused)

Performance optimization: MCP packages are installed globally via bun install -g for instant startup (~0.1s vs 2-3s with npx). The framework uses a three-tier loading strategy: MCPs load eagerly at startup or on-demand when their subagent is invoked. This reduces OpenCode startup time significantly.

SEO Integrations (curl subagents - no MCP overhead)

These use direct API calls via curl, avoiding MCP server startup entirely:

IntegrationPurposeAPI Key Required
[Ahrefs](https:

常见问题

What is aidevops?

aidevops is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by marcusquinn. Vibe-Coding is easy. DevOps is hard. OpenCode & Git token-efficient AI agent automation for your app, business, and personal development. Opinionated tools, services, CLI & API stack for speed, security, and 24/7 results. Open-source first. SOTA everything. Try on your repos for money-making magic. It has 381 GitHub stars.

Is aidevops safe to use?

Yes. aidevops passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.

How do I install aidevops?

Clone the repository with "git clone https://github.com/marcusquinn/aidevops" and add it to your Claude Code skills directory (see the Installation section above).

What programming language is aidevops written in?

aidevops is primarily written in Shell. It is open-source under marcusquinn on GitHub, so you can review or fork the full source.

Are there alternatives to aidevops?

Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh aidevops against similar tools.

评论 (0)

暂无评论,成为第一个分享想法的人!

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI 智能体ai-agentsbrainstorming
查看详情

hermes-agent

by NousResearch

10

The agent that grows with you

234,43747,175Python
AI 智能体ai-agentsagent-orchestration
查看详情

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI 智能体claude-codeai-tools
查看详情

claude-code

by anthropics

Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.

120,03119,897Shell
AI 智能体
查看详情

开发者还喜欢

基于喜欢此 Skill 的开发者投票和收藏

ECC

by affaan-m

10

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

242,21936,702JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情
15

An agentic skills framework & software development methodology that works.

234,96620,863Shell
AI 智能体ai-agentsbrainstorming
查看详情

hermes-agent

by NousResearch

10

The agent that grows with you

234,43747,175Python
AI 智能体ai-agentsagent-orchestration
查看详情

n8n

by n8n-io

12

Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.

201,88160,308TypeScript
MCP 服务器apisai-tools
查看详情

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

185,94028,768JavaScript
AI 智能体ai-agentsanthropicclaude-code
查看详情

cc-switch

by farion1231

3

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io

128,8688,826Rust
AI 智能体claude-codeai-tools
查看详情