Skip to main content

agent6

A coding agent that jails model commands and uses editable state machines for long-running tasks.

The model can write code and ask to run commands, but those commands go through a jail with restricted filesystem and network access. Long-running workflows can be written, reviewed, edited, resumed, and replayed as declarative state machines instead of being left to an open-ended agent loop.

Full documentation: agent6.dev

the run TUI: conversation streaming, an approval modal, verify + auto-commit, the hub receipt
the TUI
the full agent, as a live dashboard
the CLI: a failing suite, one command, the run streams to a green verify and a diff
the CLI
the full agent, in any terminal
the web UI: the hub, a session view with expanded tool detail, the sandbox config
the web UI
the full agent, desktop or phone

Features

  • Jailed commands: Landlock + seccomp, and under strict (what the default auto picks when the host allows it) user namespaces, pivot_root, read-only .git, no route off the box (Security)
  • Providers: Anthropic, any OpenAI-compatible endpoint (OpenAI, OpenRouter, Ollama, vLLM, llama.cpp, LM Studio), or a ChatGPT subscription (agent6 connect chatgpt); model + reasoning effort per role (Config)
  • Clean checkout: per-step commits on a detached ref, sessions merge to land them, snapshot resume, fork at any turn
  • Verify gate: inferred when unset, pinned for the run, green/red on every surface; a worker can propose a replacement gate instead of reverting
  • Budget: hard max_usd cap, token cap for calls the provider does not price
  • Sessions: run, plan, ask (plan and ask never edit); --from <id> seeds from another, cross-session reads, /btw asks beside a live run
  • Four front-ends, one engine: CLI, TUI, browser (stdlib server, no JS deps, phone), and editor over ACP; attach, exec, forward, history
  • Background commands: background: true hands back a handle, read_background polls, /shells lists them; none outlive the run
  • Context control: compaction visible on every surface, /compact [focus], /pin, repo memory injected per run
  • State machines: LLM-drafted, operator-reviewed, journaled, replayable; they pause for input, take events, steer from any front-end (State machines)
  • Task graph: the worker keeps its plan in a persistent DAG (dependencies, acceptance criteria, statuses) journaled with the run; it survives crash and compaction restarts, shows live on every surface, and decompose = "auto" front-loads it for models measured to need it
  • Code review: agent6 review on any diff, plus an in-loop panel of adversarial reviewers where only blocking-category findings gate
  • Parallel fan-out: --parallel N|model-a,model-b clone-based lanes, auto-compared into a ranked report; sessions compare for past runs, /parallel mid-run (Architecture)
  • Skills: SKILL.md packs (the format Claude Code and most agents share) index into the prompt, load on demand, fire as /name or --skill; repo instructions from AGENTS.md
  • Fixed tool surface: extended only by operator-configured MCP servers, off by default, jailed by default
  • Eight runtime dependencies, no telemetry, no auto-update

Install

From PyPI with uv or pipx:

uv tool install agent6        # or: pipx install agent6

If agent6 is not found, you can add the uv or pipx bin dir (~/.local/bin) to your PATH with uv tool update-shell or pipx ensurepath.

Enable shell completion with agent6 completions (supports bash, zsh, fish, and xonsh).

agent6 requires Python 3.12+ and the sandbox only supports Linux (x86_64/aarch64). Other platforms run without the sandbox behind a warning. See installation for the full requirements and building from source.

Usage

# Connect a provider (stored in ~/.config/agent6/, key in a 0600 secrets file).
# If already connected, skip both; `agent6 check` verifies it.
agent6 connect                # interactive: pick provider, paste API key
# (or `agent6 connect chatgpt` to sign in with a ChatGPT subscription)
agent6 model worker anthropic claude-sonnet-5

# Run the agent on a task, create a plan, or ask a question.
cd your-repo
agent6 run "add a --json output mode to the CLI"
agent6 plan "how to add a --json output mode to the CLI"
agent6 ask "how to add a --json output mode to the CLI"

# Watch and drive runs from a terminal, a TUI, a browser, or an editor.
agent6 attach <session-id>    # follow + answer a run live (--raw for events)
agent6 tui                    # full-screen dashboard hub
agent6 web                    # browser UI on http://127.0.0.1:7658
agent6 acp                    # speak ACP on stdio; an editor spawns this

# Audit the effective config, check the sandbox, resume or fork a run.
agent6 config show
agent6 check
agent6 resume <session-id>
agent6 fork <session-id> --at-turn 7

# See all commands with `agent6 --help` or `agent6 <command> --help`.

See usage for the full command tour, the web UI for driving runs from a phone, configuration for every field, and the security model for what the sandbox enforces.

Config is layered, lowest precedence first: built-in defaults, the global ~/.config/agent6/config.toml, the per-repo config (in the state dir, out of the workspace, per-machine, never committed), then --config FILE. agent6 config show prints every effective value with the layer that set it. Every field has a default, and security-sensitive fields default to the safe value: isolation = "auto", network = "auto", run_commands = "ask", protect_git = true. Under "auto" the sandbox picks the most secure option available on the host and warns if it cannot enforce the full policy; an explicitly set value it cannot enforce refuses to run. protect_git = true re-binds .git read-only, which needs strict; on hardened the default warns and an explicitly set true refuses to run. agent6 itself does not push, rewrite history, or reset --hard, and no config key can enable them.

Metadata

Release files for agent6 0.0.27

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agent6 0.0.27
File Size Uploaded
agent6-0.0.27.tar.gz 1.2 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for agent6 0.0.27
File Interpreter ABI Platform
agent6-0.0.27-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl Python 3 none Linux musl 1.2+ x86-64, Linux glibc 2.17+ x86-64 Details
agent6-0.0.27-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl Python 3 none Linux musl 1.2+ ARM64, Linux glibc 2.17+ ARM64 Details

Total release size: 4.6 MB

Release files / agent6-0.0.27.tar.gz

Download URL agent6-0.0.27.tar.gz
Size 1.2 MB
Tags Source
SHA-256 checksum
How to use checksums
0fb97001a6e9342d7f4d9f7a6e30b9ee743fddb5a1a0eb653bc53a23a324a98f
BLAKE2b-256 checksum
How to use checksums
38fad7367af3069a3e5feba1804d545566f5475993f3344c5e30255bc56f0c95
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / agent6-0.0.27-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl

Download URL agent6-0.0.27-py3-none-manylinux_2_17_x86_64.musllinux_1_2_x86_64.whl
Size 1.7 MB
Tags Linux glibc 2.17+ x86-64 Linux musl 1.2+ x86-64 Python 3
SHA-256 checksum
How to use checksums
4c11a7ef33a5e7c28a857d7463f8d5d9bb32614daa5d7a8c91c6681d33915db1
BLAKE2b-256 checksum
How to use checksums
414c03fd6dc4472fdadcbb2fa05e04998aa3aeea06ca935680d0a994063ecf75
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release files / agent6-0.0.27-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl

Download URL agent6-0.0.27-py3-none-manylinux_2_17_aarch64.musllinux_1_2_aarch64.whl
Size 1.7 MB
Tags Linux glibc 2.17+ ARM64 Linux musl 1.2+ ARM64 Python 3
SHA-256 checksum
How to use checksums
6d9b4ee9df2239affb82596b4be317cc022e0d8663a58079f8f5f559dd916049
BLAKE2b-256 checksum
How to use checksums
8ca8e453c4f5208d8bda540635b05b0ee87c03c6a3788c3c6d0bdcf04df89ba1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 21, 2026.

Transparency log

Release history Release notifications | RSS feed

0.0.35

3 release files

0.0.34

3 release files

0.0.33

3 release files

0.0.29

3 release files

0.0.28

3 release files

This release

0.0.27 This release

3 release files

0.0.26

3 release files

0.0.25

3 release files

0.0.24

3 release files

0.0.22

3 release files

0.0.21

3 release files

0.0.20

3 release files

0.0.19

3 release files

0.0.18

3 release files

0.0.15

3 release files

0.0.14

3 release files

0.0.13

3 release files

0.0.12

3 release files

0.0.11

3 release files

0.0.10

2 release files

0.0.9

2 release files

0.0.8

2 release files

0.0.7

2 release files

0.0.6

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page