Skip to main content

中文 · English

CI PyPI Downloads License codecov

agent-runner

A restart-on-exit supervisor for autonomous coding CLIs. Ships presets for Claude Code, aider, gemini, codewhale, kimi and pi; any prompt-arg CLI via custom config. Spawn the agent round-after-round under defenses that prevent the failure modes that bite in production: stuck rounds, orphan commits, OAuth burn loops, full disks, runaway memory.

┌──────────────────────────────────────────┐
│ Layer 3: The Witness (monitor)           │  13 detectors + auto-stop
├──────────────────────────────────────────┤
│ Layer 2: The Loop (serve)                │  signal-trapping restart loop
├──────────────────────────────────────────┤
│ Layer 1: The Round (round)               │  one agent invocation
└──────────────────────────────────────────┘

Install

pip install cli-agent-runner

The installed CLI command is agent-runner (the PyPI distribution name is prefixed for namespace disambiguation; the import name and command are not).

Quick start

cd your-project
agent-runner init                 # scaffold agent-runner.toml + prompts/main.md
$EDITOR agent-runner.toml         # point agent.command at your CLI
agent-runner install --monitor    # systemd user units for serve + monitor
agent-runner status               # confirm running
agent-runner peek                 # snapshot of project state
agent-runner monitor              # live anomaly detection

Full walkthrough: docs/quickstart.md.

17 verbs

Lifecycle Observation
init / install / uninstall peek — state snapshot
start / stop / kill watch — peek in a refresh loop
restart / status monitor — 13 detectors, alerts, auto-stop
round / serve events — query / stream events.jsonl
upgrade / migrate

Verb reference: docs/commands.md.

Defenses (built in)

15 named defenses, structured as data — see agent-runner peek --select defenses. Each carries the historical incident it codifies and the invariant test that guards it. Highlights:

  • round_budget_s — hard wall, never the agent's word on when to stop
  • process_group_isolation — kill the round, not just the parent
  • orphan_stash_idempotency_s — no 3-stashes-per-second pile-ups
  • sha_locked_stash — stash@{N} indices drift; SHAs don't
  • set_diff_classification — line-set comparison, not unified-diff +/- scan
  • startup_smoke_check — refuse to run with a clearly-truncated prompt

Full list and rationale: docs/architecture.md.

Optionally pause the loop during off-hours: [schedule] run/pause windows gate serve (override with serve --ignore-schedule) — see the [schedule] section of docs/configuration.md.

Monitor: 13 detectors

Notify only: timeout_rate, hung, orphan_chain, disk_warning, mem_pressure, mem_pressure_gate_inert, mem_signal_unavailable, network_fail, rate_limit_active, anomaly_repetitive_active, supervisor_stale. mem_pressure also drives a separate serve-loop admission gate that defers or terminates rounds under real memory pressure — see docs/architecture.md.

Auto-stop the service (continuing is harmful):

  • oauth_fail — burning API quota on auth-rejected rounds
  • disk_critical — writing to a near-full disk risks corruption

Runs against the supervised project's local logs:

agent-runner monitor                  # 30s poll
agent-runner monitor --json | jq -c   # pipe to downstream consumers

Watch a remote host's event stream from your laptop with a managed ssh relay — one command instead of a hand-rolled ssh … ; sleep loop:

agent-runner monitor --host pi --mode events   # managed ssh relay, JSONL stdout

Detection stays on the host: --host with --mode anomaly | narrate | http exits with an error, since the detectors and auto-stop must keep working with your laptop closed. Full relay + SSH-trust mechanics: docs/runbook.md § "Remote event relay & SSH trust".

Documentation

Development

git clone https://github.com/wan9yu/cli-agent-runner.git
cd cli-agent-runner
python3 -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]"

./build.sh check                          # full local-CI sweep
./build.sh test                           # unit + integration only
AGENT_RUNNER_E2E_PI=1 ./build.sh e2e      # opt-in pi e2e (needs ssh alias `pi`)

Some docs/*.md blocks are generated from code — ./build.sh docs rewrites the <!-- gen:* --> regions, and ./build.sh check verifies they are fresh.

POSIX-only (Linux, macOS). Tested under Python 3.11+ on x86_64 and aarch64.

License

Apache License 2.0.

Metadata

Release files for cli-agent-runner 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cli-agent-runner 0.3.0
File Size Uploaded
cli_agent_runner-0.3.0.tar.gz 728.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cli-agent-runner 0.3.0
File Interpreter ABI Platform
cli_agent_runner-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.0 MB

Release files / cli_agent_runner-0.3.0.tar.gz

Download URL cli_agent_runner-0.3.0.tar.gz
Size 728.0 kB
Tags Source
SHA-256 checksum
How to use checksums
e61009a3baa771b1124880a1dd8fa6cadf7c5b7118fdc520f0c8b9a7a161baf7
BLAKE2b-256 checksum
How to use checksums
ff257fad5af9cd21cc89397f14dc6c34da0be3da32ffc2111c4ac1c40ccb923b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 13, 2026.

Transparency log

Release files / cli_agent_runner-0.3.0-py3-none-any.whl

Download URL cli_agent_runner-0.3.0-py3-none-any.whl
Size 298.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
244825de5453c6ad675550d769a7b246e7c2ab276ee73f3016fde06ff706c16c
BLAKE2b-256 checksum
How to use checksums
a321c8168196b89910381b709e5eb1414e3275c04d01f79b284a5ee8b30e7ce3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 13, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.14

2 release files

0.3.13

2 release files

0.3.12

2 release files

0.3.11

2 release files

0.3.10

2 release files

0.3.9

2 release files

0.3.8

2 release files

0.3.7

2 release files

0.3.6

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

This release

0.3.0 This release

2 release files

0.2.24

2 release files

0.2.23

2 release files

0.2.22

2 release files

0.2.21

2 release files

0.2.20

2 release files

0.2.11

2 release files

0.2.10

2 release files

0.2.9

2 release files

0.2.8

2 release files

0.2.7

2 release files

0.2.6

2 release files

0.2.5

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.42

2 release files

0.1.40

2 release files

0.1.39

2 release files

0.1.38

2 release files

0.1.37

2 release files

0.1.36

2 release files

0.1.35

2 release files

0.1.34

2 release files

0.1.33

2 release files

0.1.32

2 release files

0.1.31

2 release files

0.1.30

2 release files

0.1.29

2 release files

0.1.28

2 release files

0.1.27

2 release files

0.1.26

2 release files

0.1.25

2 release files

0.1.24

2 release files

0.1.23

2 release files

0.1.22

2 release files

0.1.21

2 release files

0.1.20

2 release files

0.1.19

2 release files

0.1.18

2 release files

0.1.17

2 release files

0.1.16

2 release files

0.1.15

2 release files

0.1.14

2 release files

0.1.13

2 release files

0.1.12

2 release files

0.1.11

2 release files

0.1.10

2 release files

0.1.9

2 release files

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page