OMP 遠端 Coding Agent(4/5):設定、權限與安全¶
摘要¶
遠端操作時,權限要先收緊再放寬。本篇整理 Approval Mode、推薦設定檔、專案規則,以及 API Key 的保管方式。
資料基準:2026-09。執行前請以
omp --help、omp config list與omp models核對目前版本支援的選項。
1. Approval Mode¶
安全設定
遠端使用尤其重要。請先確認工具核准模式,再開放遠端控制。
常見模式:
概念:
| Mode | Read | Write | Shell / Exec |
|---|---|---|---|
always-ask |
自動 | 問 | 問 |
write |
自動 | 自動 | 問 |
yolo |
自動 | 自動 | 自動 |
遠端操作推薦先使用:
再視需要調整。
更細設定¶
這樣:
2. 推薦 config.yml¶
modelRoles:
default: YOUR_MAIN_MODEL
smol: YOUR_FAST_CHEAP_MODEL
slow: YOUR_REASONING_MODEL
plan: YOUR_PLANNING_MODEL
cycleOrder:
- smol
- default
- slow
tools:
approvalMode: write
approval:
bash: prompt
collab:
autoStart: control
relayUrl: wss://my.omp.sh
displayName: Shane-Laptop
位置:
模型名稱請先:
再填入。
3. AGENTS.md:讓 OMP 記住專案規則¶
Repository:
範例:
# Project Instructions
- Python 使用 uv
- 修改完成後執行 pytest
- 不要直接修改 production database
- 不要直接 push main
- Migration 必須先取得使用者確認
- TypeScript 使用 strict mode
- Commit message 使用 Conventional Commits
這樣就不需要每次重新提醒。
4. 推薦的 AGENTS.md¶
# Project Agent Rules
## General
- Before modifying code, inspect the relevant implementation first.
- For large changes, present a plan before editing.
- Do not push code unless explicitly requested.
- Do not deploy production unless explicitly requested.
## Testing
- Run relevant unit tests after code changes.
- Run lint/typecheck when applicable.
- If tests fail, report the failure before making unrelated changes.
## Database
- Never modify production database.
- Ask before generating or applying migrations.
- Never run destructive SQL without explicit approval.
## Git
- Never force-push.
- Never push directly to main.
- Show git diff summary before commit.
## Security
- Never print secrets.
- Never commit .env files.
- Never expose API keys or tokens.
5. Project-specific Config¶
例如工作專案:
可以比較保守:
私人專案:
可以:
6. 自訂 OpenAI-compatible Provider¶
檔案:
範例:
providers:
my-provider:
baseUrl: https://api.example.com/v1
api: openai-completions
apiKey: MY_API_KEY
models:
- id: my-model
name: My Model
contextWindow: 128000
maxTokens: 8192
API Key 不要直接硬編碼。
例如:
然後:
7. API Key 安全¶
API Key 安全
API Key 請透過環境變數或 Provider 登入管理,不要提交至 Git。
不要:
然後 commit 進 Git。
推薦:
再設定:
或者使用:
8. 安全 Checklist¶
在正式長期使用前確認:
- [ ] Full-control URL 沒有放到公開位置
- [ ] API Key 沒有 Commit
- [ ]
.env已加入.gitignore - [ ]
approvalMode不是在不了解風險時直接使用完全自動模式 - [ ]
bash高風險命令需要確認 - [ ] Production DB 有額外保護
- [ ] 不允許 Agent 自動 Push
main - [ ] 不允許 Agent 自動 Deploy Production
- [ ] 其他電腦與網路的使用符合當地 IT Policy
- [ ] Host 筆電啟用磁碟加密
- [ ] Host 系統有登入密碼
- [ ] 不共用 Full-control Collab URL
上一篇:Collab 遠端控制 · 下一篇:手機通知與日常流程