agent6
A coding agent that jails model commands and uses editable state machines for long-running tasks.
The model can write code and ask to run commands, but those commands go through a jail with restricted filesystem and network access. Long-running workflows can be written, reviewed, edited, resumed, and replayed as declarative state machines instead of being left to an open-ended agent loop.
Full documentation: agent6.dev
|
the TUI the full agent, as a live dashboard |
the CLI the full agent, in any terminal |
the web UI the full agent, desktop or phone |
Features
- Sandboxed execution for every LLM-chosen child process, jailed individually
with Landlock + seccomp; the default
strictisolation adds namespaces +pivot_root, rebinds.gitread-only, and gives jailed commands no network - Works with Anthropic and any OpenAI-compatible endpoint (OpenAI, OpenRouter, Ollama, vLLM, llama.cpp, LM Studio)
- Per-step git commits, snapshot-resumable runs, per-turn forkable checkpoints, a hard metered USD budget with a token fallback for calls the meter cannot price
- Plan, run, review, and ask modes; a live terminal dashboard, a zero-dependency
browser UI (
agent6 web, phone-friendly), and an editor-driven ACP agent (agent6 acp); persistent transcripts and a searchable run history - Sessions build on each other:
--from <session-id>seeds a new run or ask with another session's context (the source is untouched -- keeping a session's mode isfork), a session can read this project's other sessions, and/btw <question>asks a one-off question beside a live run without interrupting it -- the answer prints whole at the next turn boundary and stays resumable as the ask it is - Long jobs do not hold a turn open:
run_commandwithbackground: truestarts a slow build or a watcher,read_backgroundpolls it,/shellslists what a run started and how each one ended, and nothing a run started outlives it - Transparent, steerable context compaction: every surface shows what left the
model's context, and the conversation view shows the summary a restart
continued from;
/compact [focus]compacts on demand,/pin <text>makes an instruction survive compaction verbatim, andagent6 memory pinkeeps a load-bearing memory in every run's prompt (trimmed last, under the block's cap) - State machines (
agent6 machine) for long-running automated tasks: LLM-drafted, operator-reviewed, journaled, and replayable; they can pause for operator input, accept events, be steered from any front-end, and notify you when they need attention - Skills: install standard SKILL.md packs (superpowers, caveman, any
agentskills.io repo) with
agent6 skills install <url>; they index into the system prompt, load on demand via a read-only tool, and fire as/namepause-menu commands orrun --skill; nothing in a skill is ever executed. The format is shared with Claude Code and Pi, and[skills].extra_dirsloads an existing~/.claude/skills-style collection in place. Repo instructions are read fromAGENTS.md(a repo usingCLAUDE.mdcan symlink it) - Small, fixed LLM tool surface; the only extension point is operator-configured MCP servers, off by default
- Eight runtime dependencies, no telemetry, no auto-update
- Parallel fan-out (
agent6 run --parallel N|model-a,model-b): N isolated clone-based lanes run independently, each an ordinary sandboxed run; results auto-compare (reviewer-model judge, else verify+cost) into a ranked report. Nothing auto-merges;agent6 sessions merge <id>picks a winner.agent6 sessions compare <id> <id> ...runs the same ranked comparison over any past runs. The web/TUI composer and a live-run steer share one grammar,/parallel [N|models] <task>(repeat the token to queue more tasks), to dispatch and join a sibling group mid-conversation
Install
uv tool install agent6 # or: pipx install agent6
agent6 needs Linux for the sandbox, Python 3.12+, and an API key for at least one provider. macOS runs unsandboxed behind a warning; on Windows use WSL. See installation for the full requirements and building from source.
Quick start
# Connect a provider once (stored in ~/.config/agent6/, key in a 0600 secrets file).
# Already connected on this machine? Skip both; `agent6 check` verifies it.
agent6 connect # interactive: pick provider, paste API key
agent6 model worker anthropic claude-sonnet-4-6
# Run the agent on a task. agent6 infers a verify command if you haven't set one.
cd your-repo
agent6 run "add a --json output mode to the CLI"
# Watch and drive runs from a terminal, a full-screen TUI, a browser, or an editor.
agent6 attach <session-id> # follow + answer a run live (default: conversation view; --raw for the event stream)
agent6 tui # full-screen dashboard hub
agent6 web # browser UI on http://127.0.0.1:7658 (phone-friendly)
agent6 acp # speak ACP on stdio; an editor spawns this
# Audit the effective config, pre-flight the sandbox, resume or fork a run.
agent6 config show
agent6 check
agent6 resume <session-id>
agent6 fork <session-id> --at-turn 7
That is the whole loop. See getting started for the full command tour, the web UI for driving runs from a phone, configuration for every field, and the security model for what the sandbox enforces.
Config is layered: built-in secure defaults, then the global ~/.config/agent6/config.toml,
then the per-repo config (out of the workspace, per-machine, not committed), then an
explicit --config FILE. Every field has a default; security-sensitive fields default to
the safe value (network = "auto",
run_commands = "ask", protect_git = true), and git_ops.py
refuses push, --force, and history rewrites unconditionally.
Benchmarks
Reproducible harnesses live under bench/. The headline one is the
cross-model sweep (bench/sweep): replicated runs on real-world
tasks, scored out-of-band by each project's own test suite, reported with
confidence intervals for success rate and cost plus a latency comparison.
Also there: real-world
SWE-bench-Lite-style tasks, head-to-head runs against Claude Code / opencode /
aider, machine create validation, and a perf-optimization harness. The
recorded numbers in those are mostly small-n exploratory runs; re-run before
quoting.
Contributing
Read AGENTS.md first. The repo's verify command decides whether a change is landable:
uv run ruff check && uv run ruff format --check && \
uv run pyright && uv run tach check && uv run pytest
Adding a tool, loosening a security default, dialling a new network destination, or
changing the jail (src/agent6/jail/) requires a Security review note: paragraph in
the commit message.
License
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file agent6-0.0.22.tar.gz.
File metadata
- Download URL: agent6-0.0.22.tar.gz
- Upload date:
- Size: 1.1 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
132ca714319adba4b6faf3e8a3b54751f031fdade3a25647d910b03c8992eff6
|
|
| MD5 |
bdf79f1d5cb43edb9f1791a4502212ff
|
|
| BLAKE2b-256 |
9514305564c5380c0eaab00d6611405de2e1ab149b45b3c7bf9da9a0eb872dc0
|
Provenance
The following attestation bundles were made for agent6-0.0.22.tar.gz:
Publisher:
pypi.yml on agent6-dev/agent6
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agent6-0.0.22.tar.gz -
Subject digest:
132ca714319adba4b6faf3e8a3b54751f031fdade3a25647d910b03c8992eff6 - Sigstore transparency entry: 2405386155
- Sigstore integration time:
-
Permalink:
agent6-dev/agent6@4bccc1ab0e55bea6a74f3e500d2a8777820d04f5 -
Branch / Tag:
refs/tags/v0.0.22 - Owner: https://github.com/agent6-dev
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
pypi.yml@4bccc1ab0e55bea6a74f3e500d2a8777820d04f5 -
Trigger Event:
release
-
Statement type:
File details
Details for the file agent6-0.0.22-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl.
File metadata
- Download URL: agent6-0.0.22-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl
- Upload date:
- Size: 1.6 MB
- Tags: Python 3, manylinux: glibc 2.17+ x86-64, musllinux: musl 1.2+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a5c9678095c56afec5d15f3f9bb0c14f887a3720052733b288d2f715f283d98b
|
|
| MD5 |
c8c113a1b2078e9ee357f8acf9241e0c
|
|
| BLAKE2b-256 |
6f2ddcc44e3acb4a213863f39e7b621a387ef1abb42eba40307a670e008ef1e8
|
Provenance
The following attestation bundles were made for agent6-0.0.22-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl:
Publisher:
pypi.yml on agent6-dev/agent6
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agent6-0.0.22-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl -
Subject digest:
a5c9678095c56afec5d15f3f9bb0c14f887a3720052733b288d2f715f283d98b - Sigstore transparency entry: 2405386180
- Sigstore integration time:
-
Permalink:
agent6-dev/agent6@4bccc1ab0e55bea6a74f3e500d2a8777820d04f5 -
Branch / Tag:
refs/tags/v0.0.22 - Owner: https://github.com/agent6-dev
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
pypi.yml@4bccc1ab0e55bea6a74f3e500d2a8777820d04f5 -
Trigger Event:
release
-
Statement type:
File details
Details for the file agent6-0.0.22-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl.
File metadata
- Download URL: agent6-0.0.22-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl
- Upload date:
- Size: 1.6 MB
- Tags: Python 3, manylinux: glibc 2.17+ ARM64, musllinux: musl 1.2+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
aed33ad18cdda81f9b28afb15133ffc6367fd54a621e71731e6bca0b26e85317
|
|
| MD5 |
26aca12b09963730116a81a4c3d81a3d
|
|
| BLAKE2b-256 |
b0984ec1e1e3f6b8d65632d4ed4d1ea0e73ca0a9bb03f482579bc8dcc2d87f04
|
Provenance
The following attestation bundles were made for agent6-0.0.22-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl:
Publisher:
pypi.yml on agent6-dev/agent6
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
agent6-0.0.22-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl -
Subject digest:
aed33ad18cdda81f9b28afb15133ffc6367fd54a621e71731e6bca0b26e85317 - Sigstore transparency entry: 2405386206
- Sigstore integration time:
-
Permalink:
agent6-dev/agent6@4bccc1ab0e55bea6a74f3e500d2a8777820d04f5 -
Branch / Tag:
refs/tags/v0.0.22 - Owner: https://github.com/agent6-dev
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
pypi.yml@4bccc1ab0e55bea6a74f3e500d2a8777820d04f5 -
Trigger Event:
release
-
Statement type: