A Python-native, provider-agnostic AI coding agent for your terminal
Project description
CodeGopher
A Python-native, provider-agnostic AI coding agent for your terminal.
CodeGopher includes both the original headless command and an interactive Textual TUI for iterative project work. It can stream through OpenAI Chat Completions or Responses API, connect configured MCP stdio/SSE servers as approval-gated tools, expand file mentions, manage context, compact long sessions, save memory, load Markdown skills, track session TODOs, and resume local terminal sessions. The current 0.2.1 release also includes repository documentation skills, static security audit skills, chained-vulnerability reporting, and mission contracts that help long-running skill tasks finish with explicit artifacts instead of silent partial results.
Release Status
Version 0.2.1 is an alpha release. The CLI, TUI, VS Code chat bridge, MCP integration, documentation skills, static security skills, and chained-vulnerability audit path are implemented and locally verified. The development benchmark tooling used to measure audit quality is internal and is not exposed as a public cgopher subcommand.
Usage
cgopher
cgopher -p "What does this project do?"
cgopher --no-project-init -p "What does this project do?"
cgopher -p "read this test log and summarize it" < test.log
cgopher --events -p "What does this project do?"
cgopher init
cgopher init --skill-pack repo-docs
cgopher init --skill-pack security
cgopher init --skill-pack chained-vulns
cgopher -p "Use @skill:chained-vulnerability-static-audit to review this repository"
Run plain cgopher in an interactive terminal to open the TUI. Use -p/--prompt for the headless one-shot path.
Use cgopher --events for the newline-delimited JSON protocol used by IDE integrations, including the VS Code extension.
On first use in a project, CodeGopher creates default local project guidance under .codegopher/skills/project/SKILL.md; pass --no-project-init to disable that for a run.
Run cgopher init [PATH] to create default project-local Markdown skill guidance under .codegopher/skills.
Use cgopher init [PATH] --skill-pack repo-docs|security|chained-vulns|all to materialize built-in repository documentation and static security review skills into a project.
Useful flags:
--model,--provider, and--base-urloverride model/provider settings.--api-family chat_completions|responsesselects the OpenAI-compatible Chat Completions path or OpenAI Responses API path for the run.--approval-mode review|auto|yolocontrols tool approval behavior.--max-iterations Nsets the per-turn agent loop limit; the default is64.--no-project-initdisables first-use project guidance creation for the current run.--jsonemits machine-readable headless results.--debugshows provider reasoning content in headless text output when available.--eventsemits JSONL protocol events for IDE and automation clients.
Interactive TUI
The Textual TUI keeps chat history, streams assistant answers, renders tool calls/results, and shows inline approval prompts. Local session history is saved under CodeGopher's user data directory and automatically resumes for the same project directory.
Slash commands:
/help: show commands./clear: clear visible chat history without deleting saved session data./compact [instructions]: summarize older provider context while preserving recent turns./forget ID --yes: delete a saved memory after confirmation./memory: list session and project memories./model [NAME]: show or update the active model./mode [review|auto|yolo]: show or update approval mode./stats: show session counters./shell COMMAND: run a shell command after approval unlessyolois active./skills [load ID]: list or explicitly load Markdown skills./todo,/todo add TEXT,/todo done ID: manage session TODO state.
Prompt helpers:
@path, glob-style mentions such as@src/**/*.py, and@glob:patternexpand readable text files into the submitted prompt.@skill:IDexplicitly loads a discovered Markdown skill into provider context.- Mention expansion respects project boundaries and
.codegopherignore. - Models that emit
reasoning_contentshow thinking separately from final answer text; TUI reasoning is collapsed by default.
Context, memory, skills, and TODOs:
/statsreports context token usage when a providercontext_windowis configured.- Automatic compaction runs before a turn would exceed the configured threshold; manual
/compactis always visible in chat. save_memorystores approved session or project memories under CodeGopher's user data directory, with secret-like values redacted.- Project skills live in
.codegopher/skills/*/SKILL.md, user skills live in~/.codegopher/skills/*/SKILL.md, and built-in skills ship with the package. - Built-in skill packs include
repo-domain-docs,repo-tech-docs,crud-owasp-static-audit, andchained-vulnerability-static-audit; the security skills are static-only and do not perform live probing, fuzzing, credential attacks, dynamic scanners, exploit payloads, or network tests. - Active TODOs are included in provider context and can also be updated by the model through the
update_todotool.
MCP tools:
- Configure MCP servers in settings under
[mcp.servers.NAME]. transport = "stdio"starts a local MCP server process withcommand,args, optionalenv,cwd, andstartup_timeout_seconds.transport = "sse"connects to an SSE MCP endpoint withurl, optionalheaders,headers_env,timeout_seconds, andsse_read_timeout_seconds.- MCP tools are exposed as
mcp__SERVER__TOOL, always require approval, and are cleaned up after headless runs or TUI exit. - SSE header values and values resolved from
headers_envare not printed or persisted.
VS Code Extension
The v0.6 VS Code extension lives in extensions/vscode and exposes CodeGopher through native VS Code Chat as @codegopher. The extension launches the local Python CLI with cgopher --events, so provider setup, config loading, MCP validation, approvals, tool execution, redaction, and filesystem safety remain owned by Python.
Local setup:
cd extensions/vscode
npm install
npm run compile
npm run lint
npm test
For manual development, open the extension package in VS Code, press F5 to launch an Extension Development Host, open a disposable workspace, and use VS Code Chat with @codegopher.
To build a local .vsix package for VS Code smoke testing, run npm run package from extensions/vscode; see the extension README.
Useful VS Code surfaces:
@codegopher /help: show chat commands.@codegopher /status: show CLI path, workspace root, provider/model overrides, approval mode, and subprocess state.@codegopher /restart: restart the localcgopher --eventssubprocess.CodeGopher: Open Chat: focus VS Code Chat with@codegopher.CodeGopher: View LLM Endpoint: display the effective configured provider, model, API family, base URL, and source metadata without secrets.CodeGopher: Manage MCP Servers: list, add, edit, enable, disable, and remove configured stdio/SSE MCP servers through Python-side validation.CodeGopher: Show Protocol Trace: open redacted protocol trace output whencodegopher.traceProtocolis enabled.
If cgopher is not on the VS Code process PATH, set codegopher.cliPath to the absolute CLI executable path. See VS Code Extension Testing for Stable vs Insiders, Windows/macOS/Linux, headless Linux, and manual smoke-test guidance.
Implemented Features
- Headless Click CLI via
codegopher,cgopher, andpython -m codegopher. - Interactive Textual TUI for repeated terminal sessions.
- VS Code extension package with
@codegopherChat integration overcgopher --events. - Pydantic settings with CLI, environment, project, user, and default precedence.
- OpenAI-compatible Chat Completions streaming provider with streamed tool-call and reasoning parsing.
- OpenAI Responses API streaming provider with stateless local replay of required response output items.
- MCP stdio/SSE tool discovery and approval-gated execution through the official Python MCP SDK.
- Approval-aware file and shell tools with prior-read and parent-inspection gates.
- Static security report tooling for CRUD OWASP and chained-vulnerability audits, including a dedicated chained report writer.
- Mission contracts and task ledgers for selected complex skills so required TODOs, evidence, tool calls, and report artifacts survive retries and compaction.
- Context-window accounting, manual/automatic compaction, memory, Markdown skills, session TODOs, slash commands, file mentions, shell passthrough, and local session save/resume.
- JSON and JSONL events output for automation, IDE clients, and focused unit/integration test coverage.
Example Outcomes
These examples were run on sanitized source-only copies of two benchmark-style sample apps. Evaluator files and hint documents were removed before CodeGopher ran, and the detailed reports use only app names and relative file references.
| Task | Sample app | Outcome |
|---|---|---|
| Documentation skills | Banking Transaction Service | Produced architecture, domain, workflow, API, data-store, setup/test, and open-question notes with relative source citations after an explicit file-context retry. |
| Source-grounded question | Charity Donation Platform | Correctly traced refund state changes and the missing refund audit log; the evaluator noted one unsupported comment citation in the answer. |
| Chained vulnerability audit | Banking Transaction Service and Charity Donation Platform | Generated chained audit reports for both apps and matched evaluator ground truth for 4/4 chains and 12/12 components after retrying the larger Banking audit with a higher iteration budget. |
| Code change | Charity Donation Platform | Added a refund audit log call in the sanitized copy and verified Python syntax; no focused test was added because the sanitized app copy did not contain a test suite. |
Detailed release example reports are kept in docs/release/examples/0.2.1/.
Development
Install the package with development tools:
pip install -e ".[dev]"
Useful Hatch scripts:
hatch run test
hatch run lint
hatch run typecheck
Planned Direction
- Improve reliability around empty final responses and environment-sensitive verification commands.
- Continue strengthening source evidence quality for chained vulnerability reports.
- Expand provider capability checks, sandboxing, Git/worktree helpers, and richer coding workflows in later releases.
Docs
- Product Intro
- Product Roadmap
- Initial v0.1 Plan
- llama.cpp OpenAI-Compatible Test Endpoint
- VS Code Extension Testing
Configuration
CodeGopher uses ~/.codegopher/settings.toml for user-wide settings and .codegopher/settings.toml for per-project settings. CLI flags and environment variables take precedence.
[model]
provider = "openai"
name = "gpt-4o"
[[providers.openai]]
id = "gpt-4o"
name = "GPT-4o"
api_key_env = "OPENAI_API_KEY"
api_family = "chat_completions"
replay_reasoning_content = false
[agent]
max_iterations = 64
For OpenAI Responses API, set api_family = "responses" or pass --api-family responses. Responses calls use store = false; CodeGopher keeps the required replay metadata locally.
For OpenAI-compatible local endpoints, set base_url on the provider entry and export a key through the configured api_key_env. If an upstream requires streamed assistant reasoning_content to be sent back in later Chat Completions tool-loop requests, set replay_reasoning_content = true or pass --replay-reasoning-content for that run.
[mcp.servers.playwright]
enabled = true
transport = "stdio"
command = "npx"
args = ["@playwright/mcp@latest", "--headless", "--isolated"]
[mcp.servers.remote_docs]
enabled = true
transport = "sse"
url = "https://example.test/sse"
headers_env = { Authorization = "MCP_REMOTE_DOCS_AUTHORIZATION" }
timeout_seconds = 5
sse_read_timeout_seconds = 300
License
Apache-2.0
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file codegopher-0.2.1.tar.gz.
File metadata
- Download URL: codegopher-0.2.1.tar.gz
- Upload date:
- Size: 282.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.11
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2cb8412430f041eeb07722c8307f9b3d50519d7709538a695e6941e056bf494a
|
|
| MD5 |
1b4d3db938900643353bd1b96d258c79
|
|
| BLAKE2b-256 |
65679231d8029f2b6c25417913e9898ea0d01148c4d9db1facf5ec635cf03988
|
File details
Details for the file codegopher-0.2.1-py3-none-any.whl.
File metadata
- Download URL: codegopher-0.2.1-py3-none-any.whl
- Upload date:
- Size: 134.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.13.11
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
34ff4a166cc1d3c8ba46e2d908b6f63535ff4025465e3dac0c06790d63d8e427
|
|
| MD5 |
8517792861328d6e9d9470eb51342bd2
|
|
| BLAKE2b-256 |
f054d981680a831152e4ddd4a568e406a2cbff54436147ee036668f50a2811b3
|