Skip to main content

agent6

A coding agent that jails model commands and uses editable state machines for long-running tasks.

The model can write code and ask to run commands, but those commands go through a jail with restricted filesystem and network access. Long-running workflows can be written, reviewed, edited, resumed, and replayed as declarative state machines instead of being left to an open-ended agent loop.

Full documentation: agent6.dev

agent6: one sandboxed coding agent across the CLI, the TUI, and the web

Features

  • Sandboxed execution for every LLM-chosen child process, jailed individually with Landlock + seccomp; the default strict profile adds namespaces + pivot_root, rebinds .git read-only, and confines egress to your provider
  • Works with Anthropic and any OpenAI-compatible endpoint (OpenAI, OpenRouter, Ollama, vLLM, llama.cpp, LM Studio)
  • Per-step git commits, snapshot-resumable runs, per-turn forkable checkpoints, token budgets with hard stops and a best-effort USD ceiling
  • Plan, run, review, and ask modes; a live terminal dashboard and a zero-dependency browser UI (agent6 web, phone-friendly); persistent transcripts and a searchable run history
  • State machines (agent6 machine) for long-running automated tasks: LLM-drafted, operator-reviewed, journaled, and replayable; they can pause for operator input, accept events, be steered from any front-end, and notify you when they need attention
  • Skills: install standard SKILL.md packs (superpowers, caveman, any agentskills.io repo) with agent6 skills install <url>; they index into the system prompt, load on demand via a read-only tool, and fire as /name pause-menu commands or run --skill; nothing in a skill is ever executed
  • Small, fixed LLM tool surface; the only extension point is operator-configured MCP servers, off by default
  • Eight runtime dependencies, no telemetry, no auto-update
  • Parallel fan-out (agent6 run --parallel N|model-a,model-b): N isolated clone-based lanes run independently, each an ordinary sandboxed run; results auto-compare (reviewer-model judge, else verify+cost) into a ranked report. Nothing auto-merges; agent6 runs merge <id> picks a winner. agent6 runs compare <id> <id> ... runs the same ranked comparison over any past runs. The web/TUI composer and a live-run steer share one grammar, /parallel [N|models] <task> (repeat the token to queue more tasks), to dispatch and join a sibling group mid-conversation

Install

From PyPI with uv or pipx:

uv tool install agent6        # or: pipx install agent6

agent6 needs Linux for the sandbox (kernel 6.7+ for TCP rules), Python 3.12+, and an API key for at least one provider. macOS runs unsandboxed behind a warning; on Windows use WSL. See installation for the full requirements and building from source.

Quick start

# Connect a provider once (stored in ~/.config/agent6/, key in a 0600 secrets file).
# Already connected on this machine? Skip both; `agent6 check` verifies it.
agent6 connect                # interactive: pick provider, paste API key
agent6 model worker anthropic claude-sonnet-4-6

# Run the agent on a task. agent6 infers a verify command if you haven't set one.
cd your-repo
agent6 run "add a --json output mode to the CLI"

# Watch and drive runs from a terminal, a full-screen TUI, or a browser.
agent6 attach <run-id>        # follow + answer a run live (default: conversation view; --raw for the event stream)
agent6 tui                    # full-screen dashboard hub
agent6 web                    # browser UI on http://127.0.0.1:7658 (phone-friendly)

# Audit the effective config, pre-flight the sandbox, resume or fork a run.
agent6 config show
agent6 check
agent6 resume <run-id>
agent6 fork <run-id> --at-turn 7

That is the whole loop. See getting started for the full command tour, the web UI for driving runs from a phone, configuration for every field, and the security model for what the sandbox enforces.

Config is layered: built-in secure defaults, then the global ~/.config/agent6/config.toml, then the per-repo config (out of the workspace, per-machine, not committed), then an explicit --config FILE. Every field has a default; security-sensitive fields default to the safe value (agent_network = "providers", tool_network = "block", run_commands = "ask", protect_git = true, git.allow_* = false), and git_ops.py refuses push, --force, and history rewrites unconditionally.

Benchmarks

Reproducible harnesses live under bench/: real-world SWE-bench-Lite-style tasks, head-to-head runs against Claude Code / opencode / aider, machine create validation, and a perf-optimization harness. See each directory's README for recorded numbers (single runs, no variance measured; re-run before quoting).

Contributing

Read AGENTS.md first. The repo's verify command decides whether a change is landable:

uv run ruff check && uv run ruff format --check && \
  uv run pyright && uv run tach check && uv run pytest

Adding a tool, loosening a security default, dialling a new network destination, or changing the jail (src/agent6/jail/) requires a Security review note: paragraph in the commit message.

License

Apache-2.0.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent6-0.0.20.tar.gz (893.8 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

agent6-0.0.20-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl (1.3 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64musllinux: musl 1.2+ x86-64

agent6-0.0.20-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl (1.3 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64musllinux: musl 1.2+ ARM64

File details

Details for the file agent6-0.0.20.tar.gz.

File metadata

  • Download URL: agent6-0.0.20.tar.gz
  • Upload date:
  • Size: 893.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for agent6-0.0.20.tar.gz
Algorithm Hash digest
SHA256 b1e74f1323ffca4efba42dd8629672610a58e3e66a3f5ee75d4ae424be25f069
MD5 d8d7ba64ef0138409bded8547490d786
BLAKE2b-256 c822313d6f1746a9bef43fd5658b0e4c3e89f7de5ab3f51d645e1a859feef4ef

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.20.tar.gz:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent6-0.0.20-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for agent6-0.0.20-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 1b83a569c66b7052ce25f1f8b1a6b1e70803a610c3c99594534006a9f247d54a
MD5 6a60c64f13406aaff757476c37169cfa
BLAKE2b-256 88b925c13268db3b4e192c53c191ae6666c603676b93f1654aa600f0df6c6bb0

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.20-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent6-0.0.20-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for agent6-0.0.20-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 04f4758e6453a3107b06dc6cd6ad5fc2aebdf33f6bb02add35edb8feb65908f5
MD5 2a0ad0cf4237466c8f71bfd23a194e31
BLAKE2b-256 cd46513ec4b7a2cc371136e18fbc4a21012260be06088bf3b3ef43117f115ad3

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.20-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page