Skip to main content

agent6

A coding agent that jails model commands and uses editable state machines for long-running tasks.

The model can write code and ask to run commands, but those commands go through a jail with restricted filesystem and network access. Long-running workflows can be written, reviewed, edited, resumed, and replayed as declarative state machines instead of being left to an open-ended agent loop.

Full documentation: agent6.dev

the run TUI: conversation streaming, an approval modal, verify + auto-commit, the hub receipt
the TUI
the full agent, as a live dashboard
the CLI: a failing suite, one command, the run streams to a green verify and a diff
the CLI
the full agent, in any terminal
the web UI: the hub, a session view with expanded tool detail, the sandbox config
the web UI
the full agent, desktop or phone

Features

  • Jailed commands: Landlock + seccomp, and under the default strict policy user namespaces, pivot_root, read-only .git, no route off the box (Security)
  • Providers: Anthropic and any OpenAI-compatible endpoint (OpenAI, OpenRouter, Ollama, vLLM, llama.cpp, LM Studio); model + thinking level per role (Config)
  • Clean checkout: per-step commits on a detached ref, sessions merge to land them, snapshot resume, fork at any turn
  • Verify gate: inferred when unset, pinned for the run, green/red on every surface; a worker can propose a replacement gate instead of reverting
  • Budget: hard max_usd cap, token cap for calls the provider does not price
  • Sessions: run, plan, ask (plan and ask never edit); --from <id> seeds from another, cross-session reads, /btw asks beside a live run
  • Four front-ends, one engine: CLI, TUI, browser (stdlib server, no JS deps, phone), and editor over ACP; attach, exec, forward, history
  • Background commands: background: true hands back a handle, read_background polls, /shells lists them; none outlive the run
  • Context control: compaction visible on every surface, /compact [focus], /pin, repo memory injected per run
  • State machines: LLM-drafted, operator-reviewed, journaled, replayable; they pause for input, take events, steer from any front-end (State machines)
  • Code review: agent6 review on any diff, plus an in-loop panel of adversarial reviewers where only blocking-category findings gate
  • Parallel fan-out: --parallel N|model-a,model-b clone-based lanes, auto-compared into a ranked report; sessions compare for past runs, /parallel mid-run (Architecture)
  • Skills: SKILL.md packs (Claude Code / Pi format) index into the prompt, load on demand, fire as /name or --skill; repo instructions from AGENTS.md
  • Fixed tool surface: extended only by operator-configured MCP servers, off by default, jailed by default
  • Eight runtime dependencies, no telemetry, no auto-update

Install

From PyPI with uv or pipx:

uv tool install agent6        # or: pipx install agent6

If agent6 is not found, you can add the uv or pipx bin dir (~/.local/bin) to your PATH with uv tool update-shell or pipx ensurepath.

Enable shell completion with agent6 completions (supports bash, zsh, fish, and xonsh).

agent6 requires Python 3.12+ and the sandbox only supports Linux (x86_64/aarch64). Other platforms run without the sandbox behind a warning. See installation for the full requirements and building from source.

Usage

# Connect a provider (stored in ~/.config/agent6/, key in a 0600 secrets file).
# If already connected, skip both; `agent6 check` verifies it.
agent6 connect                # interactive: pick provider, paste API key
agent6 model worker anthropic claude-sonnet-5

# Run the agent on a task, create a plan, or ask a question.
cd your-repo
agent6 run "add a --json output mode to the CLI"
agent6 plan "how to add a --json output mode to the CLI"
agent6 ask "how to add a --json output mode to the CLI"

# Watch and drive runs from a terminal, a TUI, a browser, or an editor.
agent6 attach <session-id>    # follow + answer a run live (--raw for events)
agent6 tui                    # full-screen dashboard hub
agent6 web                    # browser UI on http://127.0.0.1:7658
agent6 acp                    # speak ACP on stdio; an editor spawns this

# Audit the effective config, check the sandbox, resume or fork a run.
agent6 config show
agent6 check
agent6 resume <session-id>
agent6 fork <session-id> --at-turn 7

# See all commands with `agent6 --help` or `agent6 <command> --help`.

See usage for the full command tour, the web UI for driving runs from a phone, configuration for every field, and the security model for what the sandbox enforces.

Config is layered, lowest precedence first: built-in defaults, the global ~/.config/agent6/config.toml, the per-repo config (in the state dir, out of the workspace, per-machine, never committed), then --config FILE. agent6 config show prints every effective value with the layer that set it. Every field has a default, and security-sensitive fields default to the safe value: isolation = "auto", network = "auto", run_commands = "ask", protect_git = true. Under "auto" the sandbox picks the most secure option available on the host and warns if it cannot enforce the full policy; an explicitly set value it cannot enforce refuses to run. protect_git = true re-binds .git read-only, which needs strict; on hardened the default warns and an explicitly set true refuses to run. agent6 itself does not push, rewrite history, or reset --hard, and no config key can enable them.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agent6-0.0.24.tar.gz (1.2 MB view details)

Uploaded Source

Built Distributions

If you're not sure about the file name format, learn more about wheel file names.

agent6-0.0.24-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl (1.7 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ x86-64musllinux: musl 1.2+ x86-64

agent6-0.0.24-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl (1.6 MB view details)

Uploaded Python 3manylinux: glibc 2.17+ ARM64musllinux: musl 1.2+ ARM64

File details

Details for the file agent6-0.0.24.tar.gz.

File metadata

  • Download URL: agent6-0.0.24.tar.gz
  • Upload date:
  • Size: 1.2 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for agent6-0.0.24.tar.gz
Algorithm Hash digest
SHA256 ef78748247c0cb0808f1b04501a58f99fb983d0a4c6c1528e8e53bb161e633ea
MD5 318ac8402341ef271385016902be5b35
BLAKE2b-256 9561150c2ec15111414c83bdd4420cac7d9efc3935360eb9c1fe3f29283f1ad1

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.24.tar.gz:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent6-0.0.24-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl.

File metadata

File hashes

Hashes for agent6-0.0.24-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl
Algorithm Hash digest
SHA256 ec6148d62eedbb0d0aeba9e89cd664c987be2d59d36b935a35c6654777501010
MD5 fee1059424224fd9bd9abb838e431124
BLAKE2b-256 9ced9296cd930769f26a0314f394452d593b7d9c56cbbbf7774cf17d26da7ee6

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.24-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agent6-0.0.24-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl.

File metadata

File hashes

Hashes for agent6-0.0.24-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl
Algorithm Hash digest
SHA256 d856a3dc6cedd103addb70c6e7a30d573d6bee7364e5675c5c003cdd9ff61434
MD5 6d6f93960b56cf796eb5e89914271a48
BLAKE2b-256 9e93dc0b0898ad86eb6f2ba16003eeeb673edd6b30ea397b5bee9bb2c6ce8a51

See more details on using hashes here.

Provenance

The following attestation bundles were made for agent6-0.0.24-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl:

Publisher: pypi.yml on agent6-dev/agent6

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page