@okelo0121/oei-cli
v0.1.0
Published
Open Execution Intelligence (OEI) CLI - Developer safety & execution gate protocol
Maintainers
Readme
OEI CLI (@oei/cli)
Open Execution Intelligence (OEI) is an execution-aware developer safety protocol that parses, analyzes, scores risk, and enforces safety gates before developer commands execute.
Installation
npm install -g @oei/cliSystem Diagnostic Verification
Verify installation health, local system environment, and developer tools:
oei doctorUsage & Commands
1. oei analyze "<command>"
Analyze a developer command against the OEI Knowledge & Risk Engine without executing it.
Safety Guarantee:
oei analyzeis strictly analysis-only and NEVER executes any requested process.
oei analyze "npm install express"
oei analyze "git push origin main --force"
oei analyze "solana program deploy target/deploy/app.so"2. oei exec "<command>"
Evaluate a command through the OEI Execution Gate and conditionally execute it.
oei exec "node --version"
oei exec "npm install express"
oei exec "solana program deploy app.so" --dry-run3. oei context
Inspect workspace runtime environment, operating system, and Git repository state safely.
oei context4. oei config
Manage OEI system and AI provider configuration settings persisted at ~/.oei/config.json.
oei config list
oei config get AI_PROVIDER
oei config set AI_PROVIDER mock5. oei knowledge
Inspect registered knowledge sources and query official advisories.
oei knowledge sources
oei knowledge search "Solana"Safety & Execution Security Model
- Analysis Non-Execution:
oei analyzenever spawns child processes. - Strict Gate Policy:
ALLOW/SUGGESTION: Executes automatically (with suggestion banner).WARN: Requires developer confirmation[y/N](defaultNin non-interactive environments).BLOCK: Exits with code2and NEVER executes.
- No BLOCK Bypasses: Passing
--yes/-yon aBLOCKdecision will NEVER bypass policy. - Shell Injection Protection: Complex shell operators (
&&,||,;,>,>>,|,<,$(),`) are safely intercepted and rejected with exit code5. - Zero Secret Exposure: Passwords, tokens, API keys, and environment variables are protected via
SafetyGuardand strictly excluded from logs, outputs, and AI reasoning boundaries. - Offline AI Boundary: Operates 100% offline by default using
AI_PROVIDER=mock. AI only provides explanation summaries and never alters deterministic risk scores or execution permissions.
Exit Codes
0: Success (executed process exited 0, or dry-run complete)1: Executed process exited non-zero / missing argument / invalid config2: Command blocked by OEI Security Policy (BLOCK)3: User declined confirmation prompt (WARN->n)4: Internal gate or analysis error5: Unsupported / unsafe shell expression
