Capability-bounded JSON transformation for the openOODA era.
v0.1.0 100% openOODA 98% jq Parity 1,036 Tests Passing CI 100% Green MCP Native
curl -fsSL https://openooda-tools.github.io/oojq/install.sh | bash
Installs native standalone binary to /usr/local/bin (or ~/.local/bin) with strict SHA-256 seal verification.
Signed release packages are attached to every GitHub release:
# Debian, Ubuntu (APT)
sudo apt install ./oojq_0.1.0-1_amd64.deb
# Fedora, RHEL, Rocky, Alma (DNF)
sudo dnf install ./oojq-0.1.0-1.*.rpm
| Capability | jq | oojq |
|---|---|---|
| Everyday filters & builtins (2,433 side-by-side cases) | reference | byte-identical, 98% parity |
Exit codes (0 success, 2 error) | yes | POSIX exit code contract strictly held |
Compact & raw modes (-c, -r) | yes | byte-for-byte identical |
| Stack exhaustion defense (deep nesting) | SIGSEGV / crash on 20k brackets | depth capped at 512, clean error |
| AST explosion defense (chained expressions) | SIGSEGV stack overflow | iterative DP AST depth check |
| Combinatorial stream explosions | unbounded RAM / freeze | bounded stream budget ceiling |
| Daemon / slowloris protection | no daemon | 16MB frame ceiling + JSON-RPC error frame |
| Agent surface (MCP stdio) | no | JSON-RPC 2.0 stdio server |
| Pure capability confinement | ambient auth | zero ambient authority |
oojq . data.json # Pretty-print
oojq -c '.items[] | {id, name}' data.json # Compact streaming
oojq -r '.users[].email' data.json # Raw text output
oojq --mcp # Model Context Protocol stdio server