Skip to main content

agent6

A coding agent that jails model commands and uses editable state machines for long-running tasks.

The model can write code and ask to run commands, but those commands go through a jail with restricted filesystem and network access. Long-running workflows can be written, reviewed, edited, resumed, and replayed as declarative state machines instead of being left to an open-ended agent loop.

Full documentation: agent6.dev

agent6: one sandboxed coding agent across the CLI, the TUI, and the web

Features

  • Sandboxed execution for every LLM-chosen child process, jailed individually with Landlock + seccomp; the default strict profile adds namespaces + pivot_root, rebinds .git read-only, and confines egress to your provider
  • Works with Anthropic and any OpenAI-compatible endpoint (OpenAI, OpenRouter, Ollama, vLLM, llama.cpp, LM Studio)
  • Per-step git commits, snapshot-resumable runs, per-turn forkable checkpoints, token budgets with hard stops and a best-effort USD ceiling
  • Plan, run, review, and ask modes; a live terminal dashboard and a zero-dependency browser UI (agent6 web, phone-friendly); persistent transcripts and a searchable run history
  • Transparent, steerable context compaction: every surface shows what left the model's context, and the conversation view shows the summary a restart continued from; /compact [focus] compacts on demand, /pin <text> makes an instruction survive compaction verbatim, and agent6 memory pin keeps a load-bearing memory in every run's prompt (trimmed last, under the block's cap)
  • State machines (agent6 machine) for long-running automated tasks: LLM-drafted, operator-reviewed, journaled, and replayable; they can pause for operator input, accept events, be steered from any front-end, and notify you when they need attention
  • Skills: install standard SKILL.md packs (superpowers, caveman, any agentskills.io repo) with agent6 skills install <url>; they index into the system prompt, load on demand via a read-only tool, and fire as /name pause-menu commands or run --skill; nothing in a skill is ever executed. The format is shared with Claude Code and Pi, and [skills].extra_dirs loads an existing ~/.claude/skills-style collection in place. Repo instructions are read from AGENTS.md (a repo using CLAUDE.md can symlink it)
  • Small, fixed LLM tool surface; the only extension point is operator-configured MCP servers, off by default
  • Eight runtime dependencies, no telemetry, no auto-update
  • Parallel fan-out (agent6 run --parallel N|model-a,model-b): N isolated clone-based lanes run independently, each an ordinary sandboxed run; results auto-compare (reviewer-model judge, else verify+cost) into a ranked report. Nothing auto-merges; agent6 runs merge <id> picks a winner. agent6 runs compare <id> <id> ... runs the same ranked comparison over any past runs. The web/TUI composer and a live-run steer share one grammar, /parallel [N|models] <task> (repeat the token to queue more tasks), to dispatch and join a sibling group mid-conversation

Install

From PyPI with uv or pipx:

uv tool install agent6        # or: pipx install agent6

agent6 needs Linux for the sandbox (kernel 6.7+ for TCP rules), Python 3.12+, and an API key for at least one provider. macOS runs unsandboxed behind a warning; on Windows use WSL. See installation for the full requirements and building from source.

Quick start

# Connect a provider once (stored in ~/.config/agent6/, key in a 0600 secrets file).
# Already connected on this machine? Skip both; `agent6 check` verifies it.
agent6 connect                # interactive: pick provider, paste API key
agent6 model worker anthropic claude-sonnet-4-6

# Run the agent on a task. agent6 infers a verify command if you haven't set one.
cd your-repo
agent6 run "add a --json output mode to the CLI"

# Watch and drive runs from a terminal, a full-screen TUI, or a browser.
agent6 attach <run-id>        # follow + answer a run live (default: conversation view; --raw for the event stream)
agent6 tui                    # full-screen dashboard hub
agent6 web                    # browser UI on http://127.0.0.1:7658 (phone-friendly)

# Audit the effective config, pre-flight the sandbox, resume or fork a run.
agent6 config show
agent6 check
agent6 resume <run-id>
agent6 fork <run-id> --at-turn 7

That is the whole loop. See getting started for the full command tour, the web UI for driving runs from a phone, configuration for every field, and the security model for what the sandbox enforces.

Config is layered: built-in secure defaults, then the global ~/.config/agent6/config.toml, then the per-repo config (out of the workspace, per-machine, not committed), then an explicit --config FILE. Every field has a default; security-sensitive fields default to the safe value (agent_network = "providers", tool_network = "block", run_commands = "ask", protect_git = true, git.allow_* = false), and git_ops.py refuses push, --force, and history rewrites unconditionally.

Benchmarks

Reproducible harnesses live under bench/. The headline one is the cross-model sweep (bench/sweep): replicated runs on real-world tasks, scored out-of-band by each project's own test suite, reported with confidence intervals for success rate and cost plus a latency comparison. Also there: real-world SWE-bench-Lite-style tasks, head-to-head runs against Claude Code / opencode / aider, machine create validation, and a perf-optimization harness. The recorded numbers in those are mostly small-n exploratory runs; re-run before quoting.

Contributing

Read AGENTS.md first. The repo's verify command decides whether a change is landable:

uv run ruff check && uv run ruff format --check && \
  uv run pyright && uv run tach check && uv run pytest

Adding a tool, loosening a security default, dialling a new network destination, or changing the jail (src/agent6/jail/) requires a Security review note: paragraph in the commit message.

License

Apache-2.0.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent6-0.0.21.tar.gz (951.7 kB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

agent6-0.0.21-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl (1.4 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64musllinux: musl 1.2+ x86-64

agent6-0.0.21-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl (1.4 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64musllinux: musl 1.2+ ARM64

File details

Details for the file agent6-0.0.21.tar.gz.

File metadata

  • Download URL: agent6-0.0.21.tar.gz
  • Upload date:
  • Size: 951.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.13

File hashes

Hashes for agent6-0.0.21.tar.gz
Algorithm Hash digest
SHA256 10cfada26fb19a67862c55f2edba88ad0f668b1081416284605e948df9d3f79c
MD5 96a751263a2d78f12f83753d4c8ddc28
BLAKE2b-256 49498af36d87c491792659e48687905aa43faab0631f2ac47f0a75543ad2d4ec

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.21.tar.gz:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent6-0.0.21-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for agent6-0.0.21-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 aa6f98afc6c85f31e63d446e9a12cc65deec64e6e70865433546fe0c9735fa6c
MD5 5192049390828625fa302946952b114f
BLAKE2b-256 c8e150a34f1c07d533ac75a20b46235343d45d4157364b7f6ccd53e22b5f3152

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.21-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent6-0.0.21-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for agent6-0.0.21-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 2db4d5249778c4881c517614239f4d629cd8d10877713b459236973c388ae874
MD5 f3be67feac32ee9bbc1f374a7401de42
BLAKE2b-256 8092c14b60f5c63aa921ae355e4f34f45d4a970d0cbe6102e9bf748faeb4bcf1

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.21-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page