Udemy, Hotmart and YouTube downloader with a yt-dlp GUI for 1,800+ sites, and a desktop app to run AI agents (Claude Code, Codex, Gemini CLI, Ollama) with permissions, undo, jobs, loops and an MCP server
omniget provides 9 file/shell operation tools with complete schemas and clear descriptions. Naming follows verb_noun convention (fs_read, fs_list, fs_edit, shell_exec). Descriptions are functional and average ~100-150 chars, above the minimum but not LLM-optimized. Input schemas are fully defined with types and descriptions. However, output schemas are undocumented (no return type descriptions for any tool), limiting agent understanding of result structure. Error handling is basic, no guidance on retryability, user-fixable errors, or recovery actions. No tool annotations (readOnlyHint/destructiveHint/idempotentHint) despite having clear risk classes (READ_ONLY, WRITE, IRREVERSIBLE). Security-critical, shell_exec and file write tools accept arbitrary untrusted input; no evidence of sanitization or input validation. Descriptions lack dependency hints (e.g., 'use fs_glob first to discover files'). No pagination for fs_list/fs_grep despite accepting recursive traversal and result caps.
Apply unified diff patch with context-based fuzzy matching using aider's V4A envelope format.
Edit file contents by finding and replacing text with context-based fuzzy matching (exact, rstrip, strip).
Find files matching glob patterns within workspace. Maximum 500 results returned.
Search file contents for regex patterns. Maximum 100 matches returned.
List directory contents with optional recursive traversal and pattern filtering. Skips .git, node_modules, target, build, dist, .svelte-kit directories.
Read file contents with line/character limits and offset support. Returns binary file error if null bytes detected in first 8KB.
No output schema documentation. All 9 tools lack documented return types, field names, and structures. LLMs cannot plan downstream calls or extract required data (e.g., file content type, directory entry structure, grep match context).
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Tools are marked with Risk classes (READ_ONLY, WRITE, IRREVERSIBLE) in metadata but not exposed via MCP tool annotations. Agents cannot infer side effects or retry safety.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 68 | 2026-07-28+ | v2 |
Create or overwrite file with contents. Creates parent directories as needed.
Execute shell commands within workspace with 120-second timeout. Environment inherits from parent process.
Update the execution plan (equivalent to Codex update_plan). Accepts JSON plan structure.
No input validation or error recovery guidance. shell_exec and file write tools accept arbitrary untrusted input (command strings, file paths, content). No evidence of path traversal sanitization, command injection guards, or actionable error messages. Descriptions lack validation constraints.
Insufficient error handling. Descriptions do not indicate error conditions, recovery steps, or retryability. E.g., fs_read mentions 'binary file error' but offers no guidance on how the agent should react or what to do next.
Missing dependency hints and discovery guidance. Descriptions do not explain when to call fs_glob vs fs_list, or suggest calling fs_glob first to discover patterns before fs_grep. Agents must discover this through trial.
No pagination or result limit guidance for potentially large operations. fs_list with recursive=true and fs_grep could return thousands of results. Descriptions mention caps (fs_glob max 500, fs_grep max 100) but no offset/limit params, token costs, or guidance on chunking large directories.
fs_apply_patch description is vague about the patch format. Mentions 'aider's V4A envelope format' but does not explain what that is or provide examples. Agents cannot know if their patch will be accepted.
shell_exec timeout is documented (120 seconds) but no error message guidance for timeout scenarios. Agents cannot distinguish between a slow command that eventually succeeds, a hung process, and a true timeout error.