From a5d134bc7e36f392feba079dadc4c5b648fb7ba5 Mon Sep 17 00:00:00 2001 From: code-crusher Date: Sat, 3 Oct 2026 19:06:52 +0530 Subject: [PATCH 1/2] fix(models): identify as first-party agent in /v1/models catalog fetch fetchDynamicModels built its own headers and never sent the orbcode-cli/ User-Agent, so the backend's isFirstPartyAgent check failed and appended the API-only System One models (e.g. fastino/gliner2.5-decide) to the response; they were registered into the model picker like regular chat models. The fetch now sends the standard DEFAULT_HEADERS, matching every other backend call. --- CHANGELOG.md | 4 ++++ src/api/models.ts | 6 ++++++ 2 files changed, 10 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 70c900a..f6a11a4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +### Fixed + +- **API-only models no longer leak into the model picker.** The `/v1/models` catalog fetch in `fetchDynamicModels` sent no `User-Agent`, so the backend's first-party check failed and appended the System One models (e.g. `fastino/gliner2.5-decide`) to the response; they were registered into the picker like regular chat models. The fetch now sends the standard `DEFAULT_HEADERS` (`orbcode-cli/` User-Agent), matching every other backend call, and the backend hides System One models from first-party agents again. + ### Changed - **Shell-first exploration.** The `list_files` and `search_files` tools are no longer offered to the model; it now searches and lists with `rg`, `find`, `ls` and `git` through `execute_command`, the way Claude Code does, and the system prompt teaches the common patterns. To keep this from becoming a prompt on every search, read-only commands (`rg`, `grep`, `find` without `-exec`/`-delete`, `ls`, `cat`, `head`, `wc`, `git status/diff/log/show/grep`, and pipes or `&&` chains of these, with no redirects or command substitution) skip the approval prompt and run in parallel. Anything unrecognised still asks. Old sessions that called the removed tools still resume. diff --git a/src/api/models.ts b/src/api/models.ts index ab26f16..c93cd4c 100644 --- a/src/api/models.ts +++ b/src/api/models.ts @@ -4,6 +4,8 @@ import * as fs from "node:fs" import * as os from "node:os" import * as path from "node:path" +import { DEFAULT_HEADERS } from "./headers.js" + /** * Read the currently selected model id from disk without triggering the full * settings-load side effects (env application, custom-model registration). @@ -447,7 +449,11 @@ export async function fetchDynamicModels( ? getUrlFromToken("https://api.matterai.so/v1/models", token) : "https://api.matterai.so/v1/models"; + // DEFAULT_HEADERS carries the `orbcode-cli/` User-Agent the + // backend's isFirstPartyAgent check requires; without it /v1/models + // appends the API-only System One models to the picker list. const headers: Record = { + ...DEFAULT_HEADERS, Accept: "application/json", }; if (token) { From 6bc1d9728240b3cabcbb011e7ab12863cd676667 Mon Sep 17 00:00:00 2001 From: code-crusher Date: Sat, 3 Oct 2026 19:07:36 +0530 Subject: [PATCH 2/2] release: v6.9.2 --- CHANGELOG.md | 2 +- package-lock.json | 4 ++-- package.json | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index f6a11a4..50f13ce 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,7 +5,7 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). -## [Unreleased] +## [6.9.2] - 2026-10-03 ### Fixed diff --git a/package-lock.json b/package-lock.json index bed5eb3..fde4dbf 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "@matterailab/orbcode", - "version": "6.9.1", + "version": "6.9.2", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "@matterailab/orbcode", - "version": "6.9.1", + "version": "6.9.2", "license": "MIT", "dependencies": { "@ai-sdk/anthropic": "^3.0.85", diff --git a/package.json b/package.json index 3b9652c..d67138a 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "@matterailab/orbcode", - "version": "6.9.1", + "version": "6.9.2", "description": "OrbCode CLI — agentic coding in your terminal, by MatterAI", "type": "module", "bin": {