- Inside JARs, without unpacking.
ototo outline lib/core.jarlists a JAR, WAR, wheel or any other ZIP by directory, with what its manifest says, andototo read lib/core.jar!org.demo.Shelfgives a class as its declarations: generics,throws, parameter names and constants, read from the class file itself, with nounzip, nojavapand no JDK. Any other entry reads like a file (lib/core.jar!META-INF/MANIFEST.MF, with:10-40or#name), a library inside a WAR is one more!, and a class says where its source is when a-sources.jarsits beside the JAR. Nothing is unpacked to disk, and a secrets file in an archive is neither listed nor read. Claude is told: the CLAUDE.md block gains a line, and the Bash hook now sendsunzip -l,unzip -p,jar tfandjavapon such a file toototo read. - It is a plugin,
archive, of a new kind. It comes with this package like the others. A plugin of this kind is lent the bytes of the files its own globs name (.jar,.zip,.class…), read-only, and nothing else: no other file, no network.ototo pluginsshows it as "opens …". - Your dependencies' JARs, if you say so. A dependency's JAR is usually outside the repository, where Otōto reads nothing.
dependency_caches = trueinconfig.tomlletsreadandoutlinelook into the archives in~/.m2/repositoryand~/.gradle/caches(or the directories you list), by absolute path: archives only, nothing else there, never a write, and off unless you set it./add-dir ~/.m2/repositoryin Claude Code is the other way, for one session. An organisation can enforce the setting, off included, andototo doctorsays which directories are read. - Plugins are published on their own. A new or fixed plugin no longer waits for a release of Otōto: each has its own version, and the download channel has a signed index of them.
ototo plugins availablesays how each stands to the one you have (the same, newer, or in need of a later Otōto), andototo plugins updatebrings yours up to the channel's. It only goes forward a version, and nothing updates by itself. The index must be signed by Otōto's release key, and each plugin still needs its own signature by a key in yourallowed_signers. - A plugin you can rebuild. The index names the commit each plugin was built from:
sh dist/reproduce.sh --plugin archivein the source rebuilds it and compares it with the channel's file, assh dist/reproduce.shdoes for a release. - Upgrading from 2.10:
ototo update, as before. It installs thearchiveplugin with the rest; restart open Claude Code or OpenCode sessions to load it.
Otōto 2.11
Otōto released version 2.11, which adds an `archive` plugin that lets `ototo outline` and `ototo read` inspect JAR, WAR, wheel and other ZIP files without unpacking them to disk, reading class declarations directly from the class file with no `unzip`, `javap` or JDK required. The release also introduces independently versioned plugins published through a signed index, a `dependency_caches = true` setting in `config.toml` that lets reads look into archives in `~/.m2/repository` and `~/.gradle/caches` by absolute path, and a `sh dist/reproduce.sh --plugin archive` command that rebuilds a plugin from its named commit and compares it with the channel's file. Upgrading from 2.10 uses `ototo update`, and open Claude Code or OpenCode sessions must be restarted to load the new plugin.
Run your AI side-project on zahid.host
EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.