sOMP

Your subagents leave the machine. Yours stays yours.

sOMP wraps omp so every subagent the model spawns runs in a disposable AIec microVM — srt-wrapped, Guard-egress-controlled — then returns a git diff and is destroyed. Your session, skills, and MCP servers stay exactly as upstream ships them.

git clone https://github.com/fedoragobrowse-design/somp.git ~/code/somp && ~/code/somp/install.sh

One line. Idempotent. Never touches your omp setup.

SANDBOX PROTECTION SOMP · REV A
level strict · runtime firecracker
dispatched work: GOVERNED
placement refused without KVM — fail closed

The relay, wired

You talk to omp. The model spawns subagents. The extension throws a breaker: local spawn blocked, work re-dispatched into a box that cannot reach your host.

you terminal somp (governed TUI) omp + 1 extension skills · MCP intact task → BLOCKED ⏚ somp_task → dispatch disposable microVM srt wrap · files+task in Guard: model-endpoint only no keys in guest git diff out → destroy model endpoint diff lands in your session; the box is gone
  1. Model calls task. The extension blocks local spawn — no subprocess, no host filesystem.
  2. somp_task dispatches. Files + task text staged into a fresh AIec box; secrets scrubbed at the print boundary.
  3. Work runs wrapped. srt confines filesystem/network inside the guest; Guard brokers model-only egress outside it.
  4. Diff returns, box destroyed. Server-side git diff collected; destroy runs even on task failure.

Install

  1. Paste the line. Clones the operator repo, builds the CLI, links somp + somp-omp, seeds config, verifies.

  2. Point at your plane. Edit ~/.config/somp/config.yaml: aiec.base_url, key file, and guard.model_host (no default — inventing one would aim boxes at the wrong provider).

  3. Run somp. Governed TUI, your normal omp. Check the status bar: sandbox 🛡️ STRICT.

Three positions. One open breaker refuses.

STRICT default

Firecracker microVM + Guard model-only egress + srt. Demands KVM; refuses governed work without it.

somp level strict

STANDARD

Docker worker + Guard + srt. Development only — there is no microVM boundary here, and the page says so.

somp level standard

OFF

No sandboxing. dispatch and session up refuse fail-closed until you re-engage.

somp level off

SOMP_LEVEL in the environment wins over config — and says so when it does.

Honest limits

Numbers below are measured on the host or single-sampled — proxies, not guest evidence. The repo keeps docs/UNPROVEN.md as a standing list; this page will not claim what it hasn't measured.

ClaimStatusEvidence
srt wrap median ≈ 330 msmeasured · host proxysomp bench, 16 samples, 0 failures
Warm subagent start < 1 sunprovenneeds Firecracker E2E
Per-subagent RSS smallunprovenneeds Firecracker E2E
JEV bash gate livenot implementedpolicy pure-function only, 15/15 unit tests
Fail-closed on unenforceableproven liveOFF refusal before any VM created

Asked, answered

Does updating omp break sOMP?
No. The wrapper execs omp from PATH with an explicit -e flag — upstream changes flow through. If a future omp ever breaks the extension seam, the installer's bun build check fails loudly instead of running ungoverned.
Where do my skills and MCP servers go?
Nowhere — they stay. somp-omp is omp plus one extension flag. Guests receive staged files + task text only; MCP credentials are never forwarded into VMs.
What does somp update pull?
Only fedoragobrowse-design/somp, exact-origin match. Upstream omp, npm, and lookalike origins are refused. omp update stays upstream's business.
Resume a governed session how?
somp-omp --resume <id> — plain omp --resume reloads ungoverned. The extension rewrites the hint in history and reminds on shutdown.
Which keys can leak?
None by design: guests get proxy posture, never real keys. The CLI scrubs OPENAI / OPENROUTER / ANTHROPIC_API_KEY and TYPESAFE_API_KEY from diffs and exec output.

Throw the breaker.

One line, reversible, your omp untouched.

git clone https://github.com/fedoragobrowse-design/somp.git ~/code/somp && ~/code/somp/install.sh