A coding agent that jails every command and leaves your branch untouched. Each command the model runs goes through a sandbox, each step commits to the run's own hidden ref, and a verify gate certifies the tree before a run may finish.
Documentation: agent6.dev
the TUI the full agent, as a live dashboard |
the CLI the full agent, in any terminal |
the web UI the full agent, desktop or phone |
uv tool install agent6 # or: pipx install agent6
agent6 connect # pick a provider, paste a key; or `connect chatgpt` / `connect claude` for a subscription
cd your-repo
agent6 run "add a --json output mode to the CLI"Linux (x86_64/aarch64) with Python 3.12+; other platforms run without the sandbox behind a warning. Installation covers shell completion, PATH and building from source.
- Jailed commands. Every command the model asks to run goes through a jail that bounds what it reads, writes and reaches on the network;
autopicks the strongest level the host allows (Security). - Your branch stays yours. Each step commits to the run's own ref, so HEAD, the index and your branch are untouched until
sessions mergelands the work;resumecontinues a run andforkbranches it at any turn. - A verify gate. The repo's test command, inferred when unset, certifies the tree before a run may finish, and every surface shows the same green or red.
- One run, four front-ends. The CLI, the TUI, a browser on a desktop or phone, and an editor over ACP all drive the same runs;
attachfollows one live andsteerqueues an instruction from a script or a cron job. - State machines for long work.
.asm.tomlfiles you review, edit, run, watch and replay, with waits, operator input and steering built in (State machines). - Secure by default.
network = "auto",run_commands = "ask",protect_git = true; a fixed tool surface, eight runtime dependencies, no telemetry, no auto-update.
Providers: Anthropic, any OpenAI-compatible endpoint (OpenAI, OpenRouter, Ollama, vLLM, llama.cpp, LM Studio), a ChatGPT subscription, or the signed-in Claude Code binary, with model and reasoning effort set per role (Configuration).
Usage walks through a first run, inspecting it and recovering one that went wrong; Architecture explains the loop, the task graph, compaction, memory and --parallel lanes.


