Command reference

Every CLI operation available through the Amaleh runtime, grouped by purpose. Each entry states what the operation does and the input shape it expects, drawn from the shipped runtime reference files.

plandelegateexecutereviewdecideoperateplanfeedback · shape · plan · amendinvalidate · record-decisionbuilddelegate · delegate-batch · wait · claimroute · worker · check · resultreviewreviewer · review-packet · review-checkreview · repair · accept · integratedfinish · healthdecidedecide · decide-batch · host-decision · poolscatalog · host-exceptionoperatestart · list · status · next · diagnose · resumeconfigure · block · requeue · unlock · preflightsave · artifact · fingerprint · host-actiondiagnostic-export · doctor · install · htmleffort-configure … effort-reconcile (5)uninstall
The operation map: every CLI operation grouped by the stage of the run it serves — planning, delegation and execution, review and repair, decisions, and the operations that inspect, configure and close a run.

Invocation shape

Run the CLI with Bun (preferred) or Node 24+ (fallback):

sh
bun <skill>/scripts/cli.ts <operation> <workspace> <run-id> [input.json]
node <skill>/scripts/run.ts <operation> <workspace> <run-id> [input.json]

Paths are arguments, not interpolated shell commands. There are no npm runtime dependencies.

The doctor operation takes no run id. The list and worktrees operations take only a workspace; clean-worktrees takes a workspace and an input, and worktree takes a workspace, a run id and an input. All other operations require a workspace and a run id.

Run lifecycle

references/runtime.md

These operations create, inspect and close runs. A closed session is not a background scheduler; invoking the skill again lists the workspace's runs and resumes the one matching your request.

start

Creates a new run with a host, model, intent, acceptance criteria and constraints. Refuses if an existing run substantially repeats the same intent unless continues or unrelated is supplied. Pass the intent's shape; without it, planning waits until the intent is shaped. In a Git checkout with a remote, it fetches the remote, resolves its default branch from the remote HEAD, and refuses unless HEAD contains the fetched tip, naming the branch and the Git commands that fix it; base.userInstruction, quoting the user, is the only override. A workspace outside Git, or with no remote, records base-unverified and proceeds.

input.json
{
  "host": { "kind": "codex", "model": "actual model from session" },
  "intent": "requested outcome",
  "criteria": ["observable success"],
  "constraints": ["accepted restriction"],
  "continues": "<optional prior run id>",
  "unrelated": "<optional reason when word overlap is coincidental>",
  "base": { "userInstruction": "<optional quote from the user naming another base>" },
  "shape": { "understanding": "what is asked and what it is for", "clearCut": "why there is only one sensible reading" }
}

In a Git checkout that does not already ignore the worktree folder, start appends /.amaleh/ to the workspace's .gitignore and commits only that file as the run's first commit, with the message Ignore Amaleh run state and task worktrees; a workspace that already ignores it commits nothing. It refuses on the remote default branch and on a detached HEAD, naming git switch -c <branch> <remote>/<default branch>, and refuses while .gitignore has uncommitted changes. The setup is recorded as a worktree-folder event with status committed, ignored or unverified.

worktree

Creates one task's checkout at .amaleh/worktrees/<run-id>/<task-id> on branch amaleh/<run-id>/<task-id>, from the run workspace's HEAD or the task's base, and records it as the task's workspace. It installs no dependencies, so install the project's dependencies in the new checkout when the task's checks need them.

sh
bun <skill>/scripts/cli.ts worktree <workspace> <run-id> <input.json>
input.json
{
  "id": "charge",
  "base": "<optional commit-ish; defaults to the run workspace HEAD>"
}
output.json
{ "id": "charge", "workspace": "C:/code/my-project/.amaleh/worktrees/<run-id>/charge", "branch": "amaleh/<run-id>/charge", "base": "...", "created": true }

worktrees

Lists every worktree of the project with its absolute path, branch, head, whether it is the main working tree, whether it has uncommitted changes, whether its branch still adds anything to the freshly fetched default branch, whether its path is missing, and the run and task using it. A squash-merged branch reads adds: false. A task branch whose head sits on another branch that adds nothing, such as a run branch that was squash-merged later, reads adds: false too, and mergedVia names that branch. branch is null on a detached HEAD, adds is null when the default branch cannot be fetched or compared, and task is null when no run task uses the worktree; a reason says why a check did not run.

sh
bun <skill>/scripts/cli.ts worktrees <workspace>
output.json
{
  "defaultBranch": "origin/main",
  "worktrees": [
    {
      "path": "C:/code/my-project/.amaleh/worktrees/<run-id>/charge",
      "branch": "amaleh/<run-id>/charge",
      "head": "<commit>",
      "main": false,
      "dirty": false,
      "adds": true,
      "missing": false,
      "task": {
        "run": "<run-id>",
        "id": "charge",
        "status": "running",
        "integrated": false
      }
    },
    {
      "path": "C:/code/my-project/.amaleh/worktrees/<run-id>/docs",
      "branch": "amaleh/<run-id>/docs",
      "head": "<commit>",
      "main": false,
      "dirty": false,
      "adds": false,
      "missing": false,
      "task": null
    },
    {
      "path": "C:/code/my-project/.amaleh/worktrees/<run-id>/hero",
      "branch": "amaleh/<run-id>/hero",
      "head": "<commit>",
      "main": false,
      "dirty": false,
      "adds": false,
      "mergedVia": "origin/feat/landing-page",
      "missing": false,
      "task": null
    }
  ]
}

clean-worktrees

Takes the absolute paths of the worktrees to remove and removes only those, with git worktree remove and never --force. It refuses, removing nothing, without userInstruction, for a dirty worktree, for the main working tree, and for the workspace of a task an open run has not integrated. With deleteBranches it deletes a branch only when it adds nothing.

Before starting new work, run worktrees, offer the user to remove the worktrees whose branch adds nothing while naming the ones that still add work, and call clean-worktrees only with the user's quoted answer.

input.json
{
  "paths": ["C:/code/my-project/.amaleh/worktrees/<run-id>/charge"],
  "userInstruction": "the user's actual words",
  "deleteBranches": true
}
output.json
{
  "removed": [
    {
      "path": "C:/code/my-project/.amaleh/worktrees/<run-id>/charge",
      "branch": "amaleh/<run-id>/charge",
      "branchDeleted": true
    }
  ]
}

feedback

Records the user's feedback as a new request. Planning, amending, reopening and delegating wait until it is shaped. Chunks that are already running finish; nothing new starts on the old understanding.

input.json
{ "text": "the user's actual words" }

shape

Shapes the latest request before any plan: the understanding, what is missing, pushback, additions, a reusable principle when one is warranted, and two to four real options with a recommendation. Pass clearCut instead of options when the request has only one sensible reading. Options without chosen, or open questions, make next return ask-user. The chosen option becomes a requirement decision.

input.json
{
  "understanding": "the hero must sell the product in one glance",
  "gaps": ["no headline copy was supplied"],
  "pushback": ["three paragraphs bury the animation"],
  "additions": ["show every model's logo"],
  "mentor": ["a hero earns attention with one promise, not a feature list"],
  "options": [
    { "id": "headline", "summary": "one headline and one line", "gains": "scene stays visible", "costs": "less detail" },
    { "id": "split", "summary": "copy left, scene right", "gains": "both readable", "costs": "scene shrinks on phones" }
  ],
  "recommendation": "headline",
  "affects": ["hero"],
  "chosen": { "option": "headline", "quote": "the user's words" }
}

list

Returns one summary per run in a workspace — id, status, intent, acceptance criteria, task count, revision, the run it continues and its acceptance record — newest revision first. Read it before starting anything.

sh
bun amaleh/scripts/cli.ts list ./my-project

status

Returns the run's current state including durable references and phase status. No input required beyond the workspace and run id.

next

Returns the next recommended action for the run. No input required. Exposes parallel.ready candidates and parallel.available worker capacity.

diagnose

Returns current state, pending work, operation timelines, failures, unfinished operations and usage totals. Includes host-action ledger, telemetry diagnostics, and process health. Also works when initialization failed before a valid snapshot existed.

resume

Resumes a closed run. On a new host or model, pass the actual current coordinator so the handoff retains prior identity and allows escalation.

input.json
{ "host": { "kind": "claude", "model": "actual current coordinator" } }

html

Returns a local HTML progress artifact. No input required.

doctor

Local check only. Reports runtime engine and version, platform, pi executable, whether OpenRouter credentials are configured, and the Jev endpoint. Does not prove network connectivity. Takes no workspace or run id.

install

Links the canonical skill into the default Codex and Claude skill directories. Refuses conflicting targets. Windows uses directory junctions; Unix uses symlinks. Takes no workspace or run id.

uninstall

The inverse of install, with the same optional home argument. Removes only the two skill links when they resolve to the canonical skill directory and reports each target as removed or not installed. It never removes the checkout, and a real directory, a file or a link that resolves elsewhere is refused with Conflicting skill target: <target>, leaving both targets untouched. Rerunning it reports every target as not installed. Takes no workspace or run id.

Planning and task contracts

These operations define and modify the work graph. Plans add tasks, not discard history. A task may carry skills and references which the runtime reads at launch.

plan

Defines the task graph. Each task needs its own independently deliverable outcome — one task carrying three or more outcomes, or four or more criteria, is refused because nothing in it can run in parallel.

input.json
{
  "tasks": [
    {
      "id": "charge",
      "title": "Correct charge",
      "goal": "Apply the agreed amount rule",
      "phase": "checkout",
      "deps": [],
      "resources": ["checkout"],
      "criteria": ["expected totals hold"],
      "kind": "code",
      "checks": [
        { "id": "test", "command": "bun", "args": ["test", "test/charge.test.js"] }
      ],
      "skills": ["optional-skill-name"],
      "references": ["path/to/design-contract.md"]
    }
  ],
  "integrationChecks": [
    { "id": "all", "command": "bun", "args": ["test"] }
  ]
}

Commands use executable plus argument arrays. Register actual project checks, not invented test commands. singleChunk overrides division when work genuinely cannot be split.

amend

Changes an existing task contract while retaining identity and escalation ancestry. Sends affected descendants back as invalidate does. Do not create a replacement ID merely to reset repair history. An amendment spends a repair cycle only when the task is in review with a failing check other than scope, or an open blocking finding, or when it asks an accepted task for more, and never when it answers a worker's contract question. An amendment that changes only resources on a task holding a finished output with no open blocking finding keeps that output, so the next delegate verifies it again with no new worker run; when it answers a contract question, a change to checks keeps the output too. Add "feedback": true when the change delivers shaped user feedback naming this task; that reopen spends no repair cycle. An amendment without feedback that asks an accepted task for more — a new goal, changed criteria or a check id the task did not have — reopens work its checks already passed, so it is a defect reopen like invalidate: every new probe must fail on the task's checkout first, or pass noProbe with a reason, once per task. Any other amendment is recorded as a contract reopen. Only defect reopens count in the reopen health warning and metrics.reopenedChunks.

input.json
{
  "id": "charge",
  "reason": "actual changed requirement or diagnosis",
  "task": { ...complete updated task contract... }
}

invalidate

Invalidates a task and its dependents when an accepted assumption or piece of evidence changes. Repair ancestry remains, and the reopen spends a repair cycle on the named task only. Its dependents carry no defect of their own and spend nothing: an accepted one keeps its output and, once the named task is integrated again and merged into its checkout, delegate checks and reviews it with no worker run. A dependent whose own last attempt had already failed returns for a repair and spends a cycle. Reopening a delivered task needs the probe that found the defect as check; it joins the task's checks and runs on every later repair. Pass noProbe with a reason when no executable can show the defect; it is accepted once per task. "feedback": true reopens a task named by settled user feedback, with no probe and no repair cycle.

input.json
{
  "id": "charge",
  "reason": "which accepted assumption/evidence changed",
  "check": { "id": "totals", "command": "bun", "args": ["test", "test/charge.test.js"] }
}

record-decision

Records a settled intent decision without a Jev call. Use source host only for delegated technical decisions. Never invent a user answer.

input.json
{
  "id": "intent-answer",
  "question": "What outcome?",
  "answer": "The user's actual answer",
  "source": "user",
  "reason": "Reference to the actual instruction"
}

block accepts an optional task id to block only that task and its dependents while unrelated work proceeds.

Delegation

One coordinator invocation per chunk routes, launches the worker, assembles the brief, runs checks, obtains review, applies Jev course-correction, and drives repair cycles. Do not call worker, check, reviewer, or repair manually for a delegated chunk.

delegate

Delegates a whole chunk to the runtime. Outcomes: accepted (chunk done, integrate next), escalated (repair-exhausted / host-takeover / host-checks-failed / scope-question / contract-question / refresh-checkout / review-evidence — your turn), route-pending (resolve the named prerequisite), failed (infrastructure error; task state preserved). Host work is final: work the host wrote under host-exception is accepted once its checks and scope pass, with no model review. A failing scope check spends no repair cycle; it returns scope-question so the coordinator can widen the resources or delegate again to revert the paths. A worker that finds its contract wrong, such as a check that cannot pass for a reason outside the task, raises a contract question instead of working around it; delegate returns contract-question before any check runs, with no repair cycle spent, and the coordinator amends the contract or delegates again with a brief saying why the contract stands; without a brief that call is refused. A dependent kept after its upstream was reopened returns refresh-checkout until its checkout contains the new upstream. The brief also reaches every repair worker the call starts. A reviewer call that fails for any reason other than a workspace escape or a settled funding or authorization failure is replaced by a fresh review on another model, bounded by providerFailovers; when that budget runs out the chunk fails and the task stays in review with its worker output. A worker call stopped by a time, idle or debugger limit that left the task's tracked content unchanged is routed to another family from the same budget, with no repair cycle; one that changed content fails the chunk for the host to inspect. A registered check that fails is run once more alone before the failure counts. When the lone run passes, the chunk goes on to review with no repair cycle, the reviewer judges whether the change causes the failure, and an accepted outcome lists that check in unstableChecks.

input.json
{
  "id": "charge",
  "workspace": "absolute task workspace",
  "brief": "optional extra guidance",
  "lenses": ["optional review lenses"],
  "skills": ["optional override skill"],
  "references": ["optional override reference"]
}

delegate-batch

Delegates every ready chunk in one invocation, bounded by maxWorkers. Each task needs its own isolated checkout, and briefs carries extra guidance for single chunks. The batch runs in a detached process, so the call returns within seconds with { launched, pid, ids, cursor, log }. Follow it with wait. The final outcomes land in log; one chunk failing never stops the others. Two chunks whose resources overlap, globs included, never run at once: the batch holds the later one and starts it the moment the earlier one finishes.

input.json
{
  "ids": ["hero", "docs", "pricing"],
  "briefs": { "hero": "optional guidance for this chunk only" },
  "lenses": ["optional review lenses"],
  "skills": ["optional shared skill"],
  "references": ["optional shared contract"]
}

wait

Follows a running batch. Returns as soon as a chunk finishes, a batch process is gone, nothing is running, or the timeout passes. The outcome is finished, interrupted, idle or still-running, with the finished chunks, a new cursor and the next action. Pass the cursor back on the next call and keep going until it reports idle.

input.json
{ "after": 812, "timeoutMs": 100000 }

Execution

These operations handle the low-level execution of individual tasks, checks and model routing. They are called internally by delegate and are listed here for completeness.

claim

Claims a fresh matching worker route for a task. A fresh route is required and consumed atomically; an arbitrary model name is insufficient. For direct host exceptions, first call host-exception.

input.json
{
  "id": "charge",
  "workspace": "absolute task workspace",
  "model": "actual selected model",
  "routeDecisionId": "decisionId returned by route",
  "hostAuthorization": "returned by host-exception (alternative)"
}

worker

Invokes a worker. Selects a model automatically, invokes pi, records real model and session output, and checkpoints the result. Never concurrently run workers in the same checkout.

input.json
{ "id": "charge", "workspace": "C:/code/my-project/.amaleh/worktrees/<run-id>/charge", "brief": "...", "routing": { ... } }

Result: { "id": "charge", "output": { "changes": ["..."], "remaining": [] } }.

check

Runs a registered executable check, saves output and fingerprints. Checks share a lock under .amaleh/check-lock: normal runs hold it together, and the lone rerun of a failed check inside delegate holds it alone. If a check changes files, rerun checks invalidated by those changes before acceptance. Omit id for a feature integration check.

input.json
{ "id": "charge", "checkId": "test" }

route

Selects a worker or reviewer model. Selection is deterministic round-robin across eligible models, seeded by the run's session hash. A model that exhausted retries is skipped for five minutes, and a model whose average call takes at least twice the median of its configured peers for a role is skipped for that role until its slow calls age out of slowModelWindowMs. routing.excludeFamilies is a hard filter for a reviewer and a soft one for a worker: a worker route skips those families unless no eligible model would remain. Finding no eligible candidates returns route-blocked.

input.json
{
  "id": "charge",
  "purpose": "worker",
  "workspace": "absolute checkout",
  "routing": {
    "role": "configured optional role",
    "requiredInputs": ["text"],
    "contextTokens": 8000,
    "evidence": "Observed requirements and model suitability evidence"
  }
}

result

Records the output of a completed worker execution.

input.json
{ "id": "charge", "output": { "changes": ["..."], "remaining": [] } }

Review and repair

Independent review verifies each chunk with structured coverage. Findings route back into the worker's repair loop, not to the coordinator.

reviewer

Invokes a fresh read-only pi review. Uses the review coverage contract with entries for id, status and evidence. The prompt asks for every blocking defect the reviewer can find in one pass, grouping lenses that share a root defect into one finding. Vendor code or setup for a third-party service that the task added with no source in the workspace or the task's references is a blocking finding. A reply that is not a valid report is asked for once more in the reviewer's own session, so its inspection is kept.

input.json
{
  "id": "charge",
  "lenses": ["Spec", "Standards", "Correctness", "Omissions"],
  "routing": { "evidence": "Relevant suitability evidence" }
}

review

Records a review obtained through a supported native agent. Never fabricate a reviewer identity or report. Findings require id, lens, location, scenario, evidence, consequence and a boolean blocking field.

input.json
{
  "id": "charge",
  "model": "actual reviewer model",
  "fingerprint": "from fingerprint operation",
  "report": "coverage and findings evidence",
  "findings": []
}

review-packet

Returns factual review context and exact required coverage IDs. Both the pi reviewer and the standalone review operation use these coverage entries.

input.json
{ "id": "charge", "lenses": ["optional specific lenses"] }

review-check

Registers an additional unique task check while review is idle, invalidates the old review, and retains repair counters.

input.json
{ "id": "charge", "check": { "id": "test", "command": "bun", "args": ["test"] } }

repair

Triggers a repair cycle. Updates the persistent escalation counter.

input.json
{ "id": "charge" }

accept

Accepts a completed task after review passes and all checks are satisfied.

input.json
{ "id": "charge" }

integrated

Records integration after the host integrates changes and checks compatibility. The evidence must be actual interaction inspection. It compares the task's checkout with the accepted output, so record it before removing the task's worktree; once the checkout is gone it refuses and names the missing path.

input.json
{ "id": "charge", "evidence": "actual integration and interaction inspection evidence" }

finish

Closes a run after all tasks are integrated, required checks pass and Jev claim-support decisions are resolved. While a task is not accepted and integrated it refuses, naming each such task and its state. A finished run cannot change; later work starts a new run with continues. Claims are host attestations, not cryptographic proof. Refuses while health reports delegation warnings; acknowledgeWarnings overrides and records a durable event. It also fetches the remote default branch and refuses while merging it into HEAD would conflict, naming the conflicting files.

input.json
{
  "claims": ["evidence explanation corresponding to each run criterion"],
  "acknowledgeWarnings": "reason for overriding warnings (optional)"
}

Decisions and routing

These operations handle model selection, Jev-based decisions, and model pool configuration.

decide

Settles a bounded either/or question. Uses actual evidence, not empty routing ceremony. Response chooses an option or yields host-decision. OpenRouter Jev uses the decisions endpoint, not chat completions.

input.json
{
  "id": "unique-decision",
  "question": "Which route is justified?",
  "criteria": { "source": "Read relevant code", "execute": "Evidence is sufficient" },
  "state": { "task": "...", "facts": ["..."] }
}

decide-batch

Settles up to sixteen independent questions in one gateway call. Always prefer it over repeated decide calls. Each answer is recorded individually.

input.json
{
  "decisions": [
    { "id": "...", "question": "...", "criteria": { ... }, "state": { ... } }
  ]
}

host-decision

Records a decision made directly by the host coordinator. The host is the source of truth for its own reasoning.

input.json
{ "id": "unique-decision", "choice": "source", "reason": "evidence and reasoning" }

pools

Persists purpose-specific routing preferences. Filter against the current catalog capability facts before dispatch; configuring a model does not prove eligibility.

input.json
{
  "pools": [
    {
      "role": "frontend",
      "models": ["verified exact model IDs"],
      "requiredInputs": ["text", "image"],
      "requiresTools": true,
      "notes": "User preference and relevant evidence"
    }
  ]
}

catalog

Fetches dated candidate cards including capability, price and source. Select stable eligible models and record exact IDs. No input required.

Configuration

Operations that modify runtime settings and task state.

configure

Sets positive integer values for operational limits. maxWorkers changes freely. The repair budget is the user's policy, so changing flashRepairCycles or deepRepairCycles needs userInstruction quoting the user's request.

input.json
{ "maxWorkers": 4, "flashRepairCycles": 3, "userInstruction": "Give Flash three tries before Kimi" }

block

Pauses a task or the entire run pending external intervention. When a task id is provided, only that task and its dependents are blocked.

input.json
{ "id": "charge (optional)", "reason": "external failure and intervention needed" }

requeue

Returns a blocked task to ready state. Only for blocked tasks; the evidence must document that interrupted effects have been inspected and reconciled.

input.json
{ "id": "charge", "evidence": "interrupted effects inspected and reconciled" }

unlock

Verifies a dead same-host lock owner before removing a stale lock. Never delete a live or unverifiable lock.

host-exception

Grants a one-use authorization for a direct host exception when the worker model must differ from the routed model. Requires explicit evidence of user instruction or repair escalation after the persistent allowance is exhausted. Host work is final: after result, delegate runs the task checks and accepts with no model review, so re-read your own diff before recording the result.

input.json
{ "id": "charge", "reason": "user-request", "evidence": "actual explicit user instruction" }

Artifacts and fingerprints

Evidence storage, retrieval and content fingerprinting.

save

Archives any JSON evidence and returns a content ID.

artifact

Retrieves the original evidence for a saved content ID.

input.json
{ "id": "artifact hash" }

fingerprint

Returns the exact current content fingerprint for a workspace. Optional — defaults to the command workspace.

input.json
{ "workspace": "absolute task workspace (optional)" }

Effort path

These five operations implement the conditional same-model effort path. A host/model switch must first reconcile any active effort pass. See the effort reference for validated input shapes and host execution requirements.

effort-configure

Configures the effort path parameters for a run. Must be called before requesting or starting an effort pass.

effort-request

Requests an effort pass. The host must supply valid configuration first.

effort-start

Records that an effort pass has started execution.

effort-finish

Records that an effort pass has completed.

effort-reconcile

Reconciles an effort pass, resolving execution state. A host/model switch must first reconcile any active effort pass before resuming.

Host actions and diagnostics

Operations for recording host observations, exporting diagnostic data, and reconciling execution.

host-action

Records an immutable local host observation. Works before run initialization or after an API failure. Kinds: decision, worker, review, edit, check, integration, permission, other. Phases: planned, permission-granted, permission-denied, started, completed, failed, skipped.

input.json
{
  "actionId": "review-attempt-1",
  "sessionId": "host-session-1",
  "kind": "review",
  "phase": "planned",
  "summary": "Request fresh review of the current task",
  "taskId": "layout",
  "next": "Request host network permission"
}

taskId and next are optional. Summaries should contain concise reasons and local evidence references, never credentials.

diagnostic-export

Writes a local JSON file under the run's exports directory and returns its path. Works without valid run state. The structural allowlist excludes free text, prompts, code, model names, paths and raw tool output. No input required beyond the workspace and run id.

reconcile-execution

For legacy running claims only. Accepts a trusted host attestation that task execution has stopped. Archives the prior task and releases ownership into blocked state. Inspect preserved artifacts, then use requeue and route again.

input.json
{
  "id": "charge",
  "operation": "exact current owner operation",
  "confirmedStopped": true,
  "evidence": "evidence of stopped execution"
}

health

Standalone health check. Measures delegation quality — coordinator-authored decisions per task, worker-side Jev calls, delegate versus manual dispatches, host takeovers per task, host-action ceremony, model-family distribution, contract questions, checks that failed only beside other checks and the coordinator's own state-changing operations — and emits warnings. State revisions are shown as a plain count: the runtime saves most of them inside delegate, so they measure the work, not the coordinator. finish reads the same warnings and refuses on them. It also reports each model's speed per role — calls, failures, average and longest minutes, with failed and timed-out calls' elapsed time counted — and names any model whose average call takes at least twice the median of the other flash models in that role; a slow model never blocks finish. Spend is priced per model, role and task from the OpenRouter catalog card that routing recorded, next to pi's own estimate, and the deep models warn when they take more than 30% of an estimated spend of at least 0.10 US dollars. No input required.

Network and preflight

preflight

Validates credentials and a fixed synthetic Jev choice with one request and a ten-second timeout. Run it before the first network operation in a session.

input.json
{ "network": "restricted|allowed|unknown", "channel": "actual host execution channel" }

Known restricted networking performs zero requests. No project content is included, no permission is granted, and no global setting is changed. doctor remains a local check; it does not prove network connectivity.

Environment variables

The runtime reads these environment variables. None are written by the CLI.

VariablePurpose
OPENROUTER_API_KEYOpenRouter credential. The runtime never prints or writes it into artifacts.
AMALEH_PI_ENTRYNames the installed pi JavaScript entry if the default resolution is wrong.
AMALEH_RUNTIMEOverride the runtime executable. Checked before AMALEH_NODE.
AMALEH_NODEFallback executable path for pi. Checked after AMALEH_RUNTIME.
AMALEH_HOST_PIDOptional process ID to record as the host process for claim operations.
AMALEH_JEV_MODELVerified current OpenRouter Jev model ID, used when the installed default becomes stale.

Worker-side Jev helper

Workers consult Jev mid-task without the coordinator through the bundled helper. Worker briefs include the invocation automatically; calls are recorded as worker-jev events.

sh
node <skill>/scripts/jev.ts <workspace> <run-id> <task-id> "<question>" "<optionA>|<optionB>|..."

The helper accepts a workspace path, a run id, a task id, a question string, and pipe-separated option strings. It returns Jev's chosen option. This keeps worker-side decisions inside the chunk loop without escalating to the coordinator.

Jev chooses between options inside the task contract; it cannot repair the contract. A worker that finds the contract itself wrong raises a contract question through the second bundled helper, then finishes its run without working around it. delegate returns contract-question to the coordinator.

sh
node <skill>/scripts/question.ts <run workspace> <run-id> <task-id> "<what is wrong, with the evidence>" [check-id]