Skip to content

Repository files navigation

agent6

A coding agent that jails every command and leaves your branch untouched. Each command the model runs goes through a sandbox, each step commits to the run's own hidden ref, and a verify gate certifies the tree before a run may finish.

Documentation: agent6.dev

the run TUI: conversation streaming, an approval answered inline, verify + auto-commit, the hub receipt
the TUI
the full agent, as a live dashboard
the CLI: a failing suite, one command, the run streams to a green verify and a diff
the CLI
the full agent, in any terminal
the web UI: the hub, a session view with expanded tool detail, the sandbox config
the web UI
the full agent, desktop or phone

Install

uv tool install agent6        # or: pipx install agent6
agent6 connect                # pick a provider, paste a key; or `connect chatgpt` / `connect claude` for a subscription
cd your-repo
agent6 run "add a --json output mode to the CLI"

Linux (x86_64/aarch64) with Python 3.12+; other platforms run without the sandbox behind a warning. Installation covers shell completion, PATH and building from source.

Why agent6

  • Jailed commands. Every command the model asks to run goes through a jail that bounds what it reads, writes and reaches on the network; auto picks the strongest level the host allows (Security).
  • Your branch stays yours. Each step commits to the run's own ref, so HEAD, the index and your branch are untouched until sessions merge lands the work; resume continues a run and fork branches it at any turn.
  • A verify gate. The repo's test command, inferred when unset, certifies the tree before a run may finish, and every surface shows the same green or red.
  • One run, four front-ends. The CLI, the TUI, a browser on a desktop or phone, and an editor over ACP all drive the same runs; attach follows one live and steer queues an instruction from a script or a cron job.
  • State machines for long work. .asm.toml files you review, edit, run, watch and replay, with waits, operator input and steering built in (State machines).
  • Secure by default. network = "auto", run_commands = "ask", protect_git = true; a fixed tool surface, eight runtime dependencies, no telemetry, no auto-update.

Providers: Anthropic, any OpenAI-compatible endpoint (OpenAI, OpenRouter, Ollama, vLLM, llama.cpp, LM Studio), a ChatGPT subscription, or the signed-in Claude Code binary, with model and reasoning effort set per role (Configuration).

Learn more

Usage walks through a first run, inspecting it and recovering one that went wrong; Architecture explains the loop, the task graph, compaction, memory and --parallel lanes.

About

A coding agent that jails model commands and uses editable state machines for long-running tasks

Topics

Resources

Security policy

Stars

6 stars

Watchers

0 watching

Forks

Releases

Used by

Contributors

Languages