--- name: omega-android-termux-runtime description: Use when OMEGA engineering work is executed from ChatGPT on Android through a Termux-hosted MCP control plane, including Secure MCP Tunnel setup, host detection, repository/build routing, Android tooling, health verification, and mobile-safe security gates. --- # OMEGA Android / Termux Runtime ## Activation Use this skill when the user wants OMEGA to operate from Android/Termux or when `omega_host_info` reports `termux: true`. Do not infer that Termux is connected merely because this skill is installed. The execution path is live only when the OMEGA tools are exposed and `omega_capabilities` reports real capabilities. ## Required topology Prefer OpenAI Secure MCP Tunnel for ChatGPT Android: ```text ChatGPT Android -> Tunnel connector -> OpenAI Secure MCP Tunnel -> tunnel-client in Termux -> OMEGA MCP stdio server ``` This is outbound-only from the device. Do not replace it with a public unauthenticated Termux listener. ## First observations When tools are reachable: 1. call `omega_host_info`; 2. call `omega_capabilities`; 3. inspect the exact repository before mutation; 4. keep operations within the configured workspace roots; 5. route only to capabilities reported available. ## Termux capability expectations Typical available capabilities may include Node.js, Git, GitHub CLI, Java/Gradle, Python, Rust/Go, and ADB. Docker/Podman and the Android emulator are not assumed on Android. Their absence is a normal capability result, not a failure to fabricate around. ## Security gates The packaged Termux wrapper enables project execution but leaves unrestricted terminal, external mutation, high-impact actions and shell interpreters disabled by default. Do not weaken a gate globally to solve one command. Prefer a dedicated OMEGA tool first. If a task truly requires an external or high-impact operation, require the corresponding authorization and preserve evidence. ## Secure tunnel lifecycle Use the native tunnel runtime lifecycle where operator execution is available: ```text omega-termux configure omega-termux knowledge-setup omega-termux doctor omega-termux connect omega-termux status ``` The runtime key must stay local to the device. Never ask the user to paste the key into chat. `omega-termux doctor` must refresh the official `sample_mcp_stdio_local` profile and run `tunnel-client doctor --profile omega-termux --explain` before managed-runtime startup. Treat the runtime as connected only when the managed-runtime status proves the process is running and health/readiness are surfaced. A successful `doctor --explain` is a preflight result, not proof that the long-lived runtime is still running. If the runtime is offline, report the tunnel as unavailable rather than claiming tool execution. ## Android routing For code changes and builds, use the Termux filesystem/repository as the execution authority when that is where the user's project lives. For remote repository metadata, CI, releases or deployments, prefer the provider-native connector when it offers stronger permissions, provenance or rollback semantics. Use ADB only when `device.android` is available. Any mutating device operation must target an explicit serial. ## Completion A mobile session is complete only when the requested code/build/artifact result has direct evidence. Tunnel health proves connectivity only; it does not prove the software task succeeded. ## Phone knowledge root When the user binds a phone folder through `omega-termux knowledge-setup`, treat `knowledge.phone-folder` as a read-only local knowledge source. Required sequence: 1. call `omega_knowledge_info`; 2. inventory with `omega_knowledge_list`; 3. inspect exact files with `omega_knowledge_metadata` and `omega_knowledge_read`; 4. use `omega_knowledge_search` for bounded cross-document retrieval; 5. never claim access to a file that was not returned by the live MCP tools. The default Android target is the user's shared-storage folder `Download/BAZA WIEDZY`, auto-detected through either the Termux storage symlink or `/storage/emulated/0/Download/BAZA WIEDZY`. The knowledge surface intentionally has no create, update, move, rename or delete operations. Storage permission remains an Android user-consent boundary and must not be bypassed or represented as already granted without live evidence.