# Oh My Pi 17.1.7: beforeToolCall hook timing, 403 credential rotation, Kimi-K3 support, tool_call argument revision

> Oh My Pi 17.1.7 ships changes across all packages. @oh-my-pi/pi-agent-core moves beforeToolCall to a pre-dispatch prepare phase where it can replace tool arguments. @oh-my-pi/pi-ai rotates through sibling credentials on 403 responses instead of failing. @oh-my-pi/pi-catalog adds Kimi-K3 and kimi-k3-fast model support. @oh-my-pi/pi-coding-agent adds a TTSR rule for local isRecord definitions, lets tool_call handlers return input to revise arguments, adds macOS sample(1) and V8 .cpuprofile parsers to the read tool, unifies xd:// and direct dispatch under one tool map, and adds a /vision slash command.

| | |
|---|---|
| **Tool** | Oh My Pi |
| **Version** | v17.1.7 |
| **Kind** | release |
| **Published** | 2026-07-28 |
| **Observed** | 2026-08-21 |
| **Significance** | 4/5 |
| **Breaking** | no |
| **Categories** | feature, model-support, capability |

## What changed


### @oh-my-pi/pi-agent-core
- `beforeToolCall` now runs during arg-prep in a pre-dispatch prepare phase (before message_start/message_end, concurrency resolution, tool_execution_start, telemetry, and tool.execute) instead of inside the scheduled execution slot. Receives the resolved tool; may return `args` to replace call arguments (revalidated against schema, written back to the assistant message).
- Argument validation moved into the same prepare phase, so concurrency resolvers see validated (and possibly revised) arguments.
- The hook receives the run's request abort signal rather than the per-tool signal.

### @oh-my-pi/pi-ai
- Upstream 403 Forbidden responses (Anthropic permission_error, Copilot model-policy rejections) now rotate through sibling credentials like usage limits do, instead of failing the session on the first denied account. The denied credential is soft-blocked for 60s and re-validated.
- Usage report filtering in the auth-broker remote store is memoized per (reports, snapshot) with a precomputed per-provider OAuth credential map.
- Cursor and Devin Connect-frame readers no longer copy every stream chunk through Buffer.concat when the pending buffer is empty.

### @oh-my-pi/pi-catalog
- Added moonshotai/Kimi-K3 and kimi-k3-fast models.
- Added umans-kimi-k3 prerelease model configuration.
- Updated pricing and token limits for selected models.

### @oh-my-pi/pi-coding-agent
- Added `ts-no-local-is-record` TTSR rule that catches local `isRecord` function/lambda definitions.
- `tool_call` handlers (extension or hook) can now return `input` to revise tool arguments (not just block). Revalidated against schema; concurrency scheduling, transcripts, and approval gates observe the revised version.
- Added macOS `sample`(1) parser: reads return a compact bottleneck summary with per-thread hot paths, demangled symbols, recursion flattening, and a top-functions-by-self-samples table.
- Added V8 `.cpuprofile` parser: reads return a compact bottleneck summary with hot-path call tree, collapsed pass-through chains, and top-functions-by-self-time table.
- Direct and `xd://` dispatch now share one canonical tool map: `write xd://<tool>` and `read xd://<tool>` work for any enabled tool.
- Session listing caches parsed headers keyed on file stat identity (mtime + size).
- Reduced per-keystroke editor dispatch overhead.
- `xd://` device docs now render parameters as comment-annotated TypeScript types instead of raw JSON Schema.
- Added `/vision [on|off|auto|status]` slash command for session-scoped control of the `inspect_image` vision-delegation tool.
- Replaced `inspect_image.enabled` boolean with tri-state `inspect_image.mode` (auto|on|off, default auto).


## Sources

- [github_release](https://github.com/can1357/oh-my-pi/releases/tag/v17.1.7) — retrieved 2026-08-21


## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/oh-my-pi/v17-1-7
Entity: https://changelogs.info/oh-my-pi
Event ID: `evt_2026-07-28_oh-my-pi_v17-1-7`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
