omnara (deprecated)
Disable date: 2027-02-05
Install command:
brew install omnaraTalk to Your AI Agents from Anywhere
License: Apache-2.0
Development: Pull requests
Formula JSON API: /api/formula/omnara.json
Formula code: omnara.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
tahoe | ✅ |
|---|---|---|
| sequoia | ✅ | |
| sonoma | ✅ | |
| macOS on Intel |
sonoma | ✅ |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ | |
Current versions:
| stable | ✅ | 1.7.0 |
Depends on:
| certifi | 2026.7.22 | Mozilla CA bundle for Python |
| cryptography | 50.0.0 | Cryptographic recipes and primitives for Python |
| libyaml | 0.2.5 | YAML Parser |
| pydantic | 2.13.4 | Data validation using Python type hints |
| python@3.14 | 3.14.7 | Interpreted, interactive, object-oriented programming language |
| ripgrep | 15.2.0 | Search tool like grep and The Silver Searcher |
| rpds-py | 2026.6.3 | Python bindings to Rust's persistent data structures |
Depends on when building from source:
| rust | 1.98.0 | Safe, concurrent, practical language |
Known vulnerabilities in the current version:
| PYSEC-2025-183 (high) | |
| GHSA-m8x7-r2rg-vh5g (medium) | FastMCP has a Command Injection vulnerability - Gemini CLI |
| GHSA-5h2m-4q8j-pqpj | FastMCP OAuth Proxy token reuse across MCP servers |
| GHSA-6mq8-rvhq-8wgg (high) | AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb |
| GHSA-69f9-5gxw-wvc2 | AIOHTTP's unicode processing of header values could cause parsing discrepancies |
| GHSA-mqqc-3gqh-h2x8 | AIOHTTP has unicode match groups in regexes for ASCII protocol elements |
| GHSA-54jq-c3m8-4m76 | AIOHTTP vulnerable to brute-force leak of internal static file path components |
| GHSA-jj3x-wxrx-4x23 | AIOHTTP vulnerable to DoS when bypassing asserts |
| GHSA-6jhg-hg63-jvvf | AIOHTTP vulnerable to denial of service through large payloads |
| GHSA-g84x-mcqj-x9qq | AIOHTTP vulnerable to DoS through chunked messages |
| GHSA-fh55-r93g-j68g | AIOHTTP Vulnerable to Cookie Parser Warning Storm |
| GHSA-w8v5-vhqr-4h9v | DiskCache has unsafe pickle deserialization |
| GHSA-38jv-5279-wg99 (high) | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) |
| GHSA-w2fm-2cpv-w7v5 | aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage |
| GHSA-58pv-8j8x-9vj2 (high) | jaraco.context Has a Path Traversal Vulnerability |
| GHSA-wp53-j4wj-2cfg (high) | Python-Multipart has Arbitrary File Write via Non-Default Configuration |
| GHSA-gc5v-m9x4-r6x2 (medium) | Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function |
| GHSA-rww4-4w9c-7733 | FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnera... |
| GHSA-wvwj-cvrp-7pv5 (critical) | Authlib JWS JWK Header Injection: Signature Verification Bypass |
| GHSA-7432-952r-cw78 | Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle |
| GHSA-m344-f55w-2m6j | Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding |
| GHSA-mf9w-mj56-hr94 (medium) | python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rena... |
| GHSA-7wc2-qxgw-g8gg | Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification |
| GHSA-752w-5fwx-jx9f (high) | PyJWT accepts unknown `crit` header extensions |
| GHSA-vv7q-7jx5-f767 (critical) | FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability |
| GHSA-69v7-xpr6-6gjm (critical) | Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / set... |
| GHSA-hcc4-c3v8-rx92 | AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector |
| GHSA-2vrm-gr82-f7m5 | AIOHTTP has CRLF injection through multipart part content type header construction |
| GHSA-p998-jp59-783m | AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler o... |
| GHSA-m5qp-6w8w-w647 (high) | AIOHTTP has a Multipart Header Size Bypass |
| GHSA-3wq7-rqq7-wx6j | AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS |
| GHSA-966j-vmvw-g2g9 (medium) | AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect |
| GHSA-mwh4-6h8g-pg8w | AIOHTTP has HTTP response splitting via \r in reason phrase |
| GHSA-63hf-3vf5-4wqf (critical) | AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values -... |
| GHSA-c427-h43c-vf67 | AIOHTTP accepts duplicate Host headers |
| GHSA-jg22-mg44-37j8 (medium) | AIOHTTP is Vulnerable to Deserialization of Untrusted Data |
| GHSA-mj87-hwqh-73pj (medium) | python-multipart affected by Denial of Service via large multipart preamble or epilogue data |
| GHSA-jj8c-mmj3-mmgv (medium) | Authlib: Cross-site request forging when using cache |
| GHSA-w8p2-r796-3vmq (medium) | Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect... |
| GHSA-pp6c-gr5w-3c5g (high) | python-multipart has Denial of Service via unbounded multipart part headers |
| GHSA-qccp-gfcp-xxvc (medium) | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects |
| GHSA-mf9v-mfxr-j63j (high) | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API |
| GHSA-r95x-qfjj-fjj2 (medium) | Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect |
| GHSA-5239-wwwm-4pmq (low) | Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching |
| GHSA-65pc-fj4g-8rjx (medium) | Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() ... |
| GHSA-hg6j-4rv6-33pg | AIOHTTP is vulnerable to cross-origin redirect with per-request cookies |
| GHSA-993g-76c3-p5m4 (medium) | PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file:... |
| GHSA-jq35-7prp-9v3f (medium) | PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys |
| GHSA-fhv5-28vv-h8m8 (low) | PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) |
| GHSA-w7vc-732c-9m39 (medium) | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=fals... |
| GHSA-xgmm-8j9v-c9wx (high) | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are... |
| GHSA-86qp-5c8j-p5mr (medium) | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based ... |
| GHSA-x746-7m8f-x49c (medium) | Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr` |
| GHSA-wqp7-x3pw-xc5r (high) | Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows |
| GHSA-m6qw-4cw2-hm4m | aiohttp: CRLF injection in multipart headers |
| GHSA-jpw9-pfvf-9f58 (high) | MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal |
| GHSA-hvrp-rf83-w775 (high) | MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' t... |
| GHSA-vffw-93wf-4j4q (low) | python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters |
| GHSA-6jv3-5f52-599m (low) | python-multipart: Semicolon treated as querystring field separator enables parameter smuggling |
| GHSA-5rvq-cxj2-64vf (high) | python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial ... |
| GHSA-v9pg-7xvm-68hf (low) | python-multipart: Negative Content-Length in parse_form buffers the entire body in memory |
| GHSA-4fvr-rgm6-gqmc | aiohttp: HTTP/1 Pipelined Requests Queue Without Limit |
| GHSA-xcgm-r5h9-7989 | aiohttp: Incomplete websocket frame payloads bypass memory limits |
| GHSA-4m7w-qmgq-4wj5 | aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections |
| GHSA-hpj7-wq8m-9hgp | aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges |
| GHSA-63hw-fmq6-xxg2 | aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines |
| GHSA-g3cq-j2xw-wf74 | aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup |
| GHSA-2fqr-mr3j-6wp8 | aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence |
| GHSA-9x8q-7h8h-wcw9 | aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect |
| GHSA-jp82-jpqv-5vv3 (low) | Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname |
| GHSA-82w8-qh3p-5jfq (high) | Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS |
| GHSA-4xgf-cpjx-pc3j (medium) | pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling loc... |
| GHSA-mq44-7p77-q5h7 | AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate |
| GHSA-vj7q-gjh5-988w | MCP Python SDK: WebSocket server transport does not support Host/Origin validation |
| GHSA-mfx4-hv73-q22v | AIOHTTP: HTTP request smuggling via WebSocket upgrade |
| GHSA-cq5v-8q36-5273 | AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) |
| PYSEC-2026-2132 (high) |
Data from Homebrew/advisory-database. Run brew vulns omnara for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 2 | 5 | 830 |
Installs (--HEAD) | 0 | 0 | 1 |
| Installs on Request | 2 | 5 | 830 |
Installs on Request (--HEAD) | 0 | 0 | 1 |
| Build Errors | 0 |