Skip to main content

Newt-Agent

Newt-Agent logo

Free, friendly, local agentic coder. vi to Hermes-Agent's emacs.

A single Rust binary with a sharp, minimal tool set. It runs against your local hardware by default — no cloud bytes leave your machine unless you deliberately install a provider plugin. Opinionated, not extensible.

Why — the bridle, not just the harness

An agent harness helps the model do work; a bridle lets the operator steer — and prove, after the fact, exactly where the horse went. Newt is an experiment in making Object Capability (OCAP) security — long considered theoretically correct but practically unimplementable — pragmatic inside an agent loop, as a reusable concept (agent-bridle) intended to be pluggable into other harnesses, not just this one.

OCAP's algebraic construction means some questions are answered structurally, not by audit-log archaeology:

  • Who acted on what, and when?
  • Who granted the authority for this to do that?
  • Did what they permitted actually happen — and did only what they permitted happen?

For anyone whose work lives on provenance, authority, integrity, and data sovereignty — lawyers, clinicians, data scientists — those answers have to be properties of the system, not promises in a policy document.

If it doesn't find its day in the sun, it was fun anyway.

Quick start

git clone https://github.com/Gilamonster-Foundation/newt-agent
cd newt-agent
just install          # release binaries → ~/bin/newt, ~/bin/newt-mcp-server
newt setup dgx1.home.lab  # probe configured ports and select detected inference
newt code             # TUI coder in the current directory

Bare setup hosts are probed anonymously across the configured discovery ports (including 8000 and 8080 by default). For an authenticated endpoint, use its exact HTTPS URL and store only a secret reference:

newt setup https://inference.example.net:8000 --token-env INFERENCE_TOKEN
newt setup https://inference.example.net:8080 --token-file ~/.config/newt/token

Detected endpoints are stored as ~/.newt/backends/*.toml; the main ~/.newt/config.toml only records the selected default_backend.

Tool output scrollback

Completed tool results use a bounded, tail-biased spill ([tui] spill_lines = 3 by default). On Unix, the default interactive build also streams an active shell tool into that bounded frame when both stdin and stdout are terminals and TERM is not dumb. Up/Down scroll retained lines; Space or Enter toggles ⧉ expand and ▣ collapse. Expansion never exceeds safe terminal capacity, and each tool still commits one canonical completed block to normal terminal scrollback.

Use /spill <N> for a session-only row count, /spill reset to restore configuration, or /spill 0 for unbounded completed output with live display disabled. The default newt binary enables live-spill; a --no-default-features build strips it. See the TUI README and decision record.

Operating modes and permission postures

Inside the TUI, /mode lists and selects a working style: chat, dev, admin, plan, diagnose, auto, or full-auto. Bare /mode includes a description of each. plan is workspace-read-only with access to Newt's plan ledger, and diagnose is bounded read-only research. In auto, the model can select a bounded style for a later action-shaped turn, but protected intake still wins and only the human can select full-auto. Every mode still honors all permission and safety boundaries. dev and full-auto both carry TDD, worktree-safe Git, targeted-test, and full-preflight guidance; full-auto changes persistence and interruption policy, not authority.

/posture is the separate authority control. It lists or applies a configured skill/framing binding and its optional permission floor; /posture off clears it. A configured floor can only narrow authority, while a posture without one leaves authority unchanged. Existing posture bindings remain under [modes.<name>] in TOML for compatibility. See the mode/posture decision.

Run newt --help for every mode (worker, MCP server, doctor, config, …) — the binary is the authority on its own surface, this file is not. Python bindings live in newt-agent-py/ (pip install newt-agent-py, import path newt_agent).

Terminal-Bench scoreboard

newt is measured on Terminal-Bench via newt solve (headless) + the Harbor adapter. The release gate is a per-model monotonic ratchet — a model's score never goes down across releases; we establish a starting number and keep beating it. The table below is published from scripts/eval/bench-results.jsonl every release (scripts/eval/bench_scoreboard.py render).

Per-model champion scores — the release gate is a monotonic ratchet: a model's score never goes down. Auto-generated; do not edit by hand.

Model Family Score Passed Suite Window Version Date
qwen3.6_35b qwen 20.0% 6/30 tb-30 65536 0.7.5 2026-07-28
qwen3-coder_30b qwen 10.0% 3/30 tb-30 65536 0.7.5 2026-07-28

Design laws

The invariants. Each links to the decision record that argues it.

  • Local-first inference. The default binary speaks only to local backends. Cloud providers are opt-in subprocess plugins speaking the JSON-RPC schema in plugins-protocol/ — the opt-in is enforced at the build level, not a runtime flag.
  • Fail-closed OCAP. Authority is a caveat lattice, not a denylist; a fixed safety floor no mode or grant can unlock. See docs/decisions/agentic_object_capability_security.md and docs/decisions/ocap_confinement_model.md.
  • Small crates, zero warnings, coverage-gated. just check mirrors CI; the pre-push hook runs it. One operator's leverage is this discipline.
  • Patch, not prose. Delegated work is verified by the harness (real diffs, real test runs — newt-eval/), never by trusting a model's summary of itself.
  • Skills are on-demand context. The prompt carries an index; bodies load when used. See docs/decisions/agent-skills.md and the bundled skills in .newt/bundled-skills/.
  • Issues are ground truth. ROADMAP.md sequences delivery, but GitHub issue state is authoritative — the document is only the map.
  • Causal ordering, not wall-clock. Timestamps are display claims; the conversation store orders on signed per-writer ticks + content hashes. See docs/decisions/conversation_context_architecture.md.

Field notes

The durable output of this experiment is what building it teaches about how LLMs behave inside a harness:

  • Summarization-induced hallucination — context compression that summarizes a session can make the model hallucinate APIs it had already read. A confident summary is worse than a labelled absence: absence routes the model to re-read; a summary suppresses recovery.
  • Truncation honesty — silent context truncation yields silently wrong answers; every fix moves the failure, it doesn't always remove it.
  • Coder-driving sweet spots — where small local models are and aren't reliable at agentic coding.
  • Hermes learnings — take the algorithms, refuse the architecture.

Where things live

What Where
Forward plan ROADMAP.md (issue numbers are the live state)
Release history CHANGELOG.md
Design docs & studies docs/design/
Decision records docs/decisions/
Evaluation harness newt-eval/README.md
Local gate just check (see justfile)

License

Apache-2.0. See LICENSE.

Metadata

Release files for newt-agent-py 0.7.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for newt-agent-py 0.7.5
File Size Uploaded
newt_agent_py-0.7.5.tar.gz 1.8 MB Details

Built distributions (wheels)

Table of built distributions (wheels) for newt-agent-py 0.7.5
File
newt_agent_py-0.7.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.12 CPython 3.12 Linux glibc 2.17+ x86-64 Details
newt_agent_py-0.7.5-cp312-cp312-macosx_11_0_arm64.whl CPython 3.12 CPython 3.12 macOS 11.0+ ARM64 Details
newt_agent_py-0.7.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.17+ x86-64 Details
newt_agent_py-0.7.5-cp311-cp311-macosx_11_0_arm64.whl CPython 3.11 CPython 3.11 macOS 11.0+ ARM64 Details
newt_agent_py-0.7.5-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.10 CPython 3.10 Linux glibc 2.17+ x86-64 Details
newt_agent_py-0.7.5-cp310-cp310-macosx_11_0_arm64.whl CPython 3.10 CPython 3.10 macOS 11.0+ ARM64 Details
newt_agent_py-0.7.5-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.9 CPython 3.9 Linux glibc 2.17+ x86-64 Details
newt_agent_py-0.7.5-cp39-cp39-macosx_11_0_arm64.whl CPython 3.9 CPython 3.9 macOS 11.0+ ARM64 Details

Total release size: 38.4 MB

Release files / newt_agent_py-0.7.5.tar.gz

Download URL newt_agent_py-0.7.5.tar.gz
Size 1.8 MB
Tags Source
SHA-256 checksum
How to use checksums
13906abab31e53bee03bb6f2ac8f639d33442aa0cb735592e738665ea6b29883
BLAKE2b-256 checksum
How to use checksums
69e454dfeec694d767d7eea1abcef0b1ea4a136c84a62472ad3eb8361109400a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL newt_agent_py-0.7.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 4.8 MB
Tags CPython 3.12 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
1d33de874081d11318cbaf4e01648a8db2ba784b34911392ca072ce259070160
BLAKE2b-256 checksum
How to use checksums
37f615f2ecdc5b5c50bd089e73007aabd1b1270f4a80b137b9125d10275a9b14
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp312-cp312-macosx_11_0_arm64.whl

Download URL newt_agent_py-0.7.5-cp312-cp312-macosx_11_0_arm64.whl
Size 4.3 MB
Tags CPython 3.12 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
d6f5e358860c18af0234fe054d5699f35364ec6c4293c91ee64fafb512d2385d
BLAKE2b-256 checksum
How to use checksums
9e111cfb8b02f443ec9a1f89a1f030cc94a86bdddb8bcf5312c86c69296e50cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL newt_agent_py-0.7.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 4.8 MB
Tags CPython 3.11 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
8f5742b547a5f85fa6d9c3aa32158f730087e96d0825be6d959e58ae1c34e8fd
BLAKE2b-256 checksum
How to use checksums
776ba1a922a25ca72967ed474c6da0e808345c1f4482eb20c578c290d1a3f513
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp311-cp311-macosx_11_0_arm64.whl

Download URL newt_agent_py-0.7.5-cp311-cp311-macosx_11_0_arm64.whl
Size 4.3 MB
Tags CPython 3.11 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
3101682cf7afed186660fe7b2d1434ae8c3eb7666d0de57d7e66bfaacaf98716
BLAKE2b-256 checksum
How to use checksums
20a10f493576dcba98811785c879d88efd334dafe5aa0e08794d94d199751a78
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL newt_agent_py-0.7.5-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 4.8 MB
Tags CPython 3.10 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
f8fca03a891557e8fc552e56bc89958b4f83124c4f13b5249b06dd83c554ab2b
BLAKE2b-256 checksum
How to use checksums
8f5e4af4d1a180d53f8396d82fa944baca2f63b6afe2a1b86511dd2611cdf648
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp310-cp310-macosx_11_0_arm64.whl

Download URL newt_agent_py-0.7.5-cp310-cp310-macosx_11_0_arm64.whl
Size 4.3 MB
Tags CPython 3.10 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
d12fb224b6e56a84c751fffa7f0ef35b84f13d10e97887018b341cc628542ae7
BLAKE2b-256 checksum
How to use checksums
c9699f32eedfcd90c349f7649f6fe98c594c25381d759e3e5c255ad5d58f3c85
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL newt_agent_py-0.7.5-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 4.8 MB
Tags CPython 3.9 Linux glibc 2.17+ x86-64
SHA-256 checksum
How to use checksums
1a809ac5f679ddaa3ee966f9f815f601772d9e69dd9a9d9b6cade742b09e7996
BLAKE2b-256 checksum
How to use checksums
7b6e2febedaa0a4aec6111392288f6db4ef5d402c7be14879ab73d0f9ef7f308
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / newt_agent_py-0.7.5-cp39-cp39-macosx_11_0_arm64.whl

Download URL newt_agent_py-0.7.5-cp39-cp39-macosx_11_0_arm64.whl
Size 4.4 MB
Tags CPython 3.9 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
c8c6bd0fa14b6366721d0b47be3aac8877d39030168740fa86a84414705bd590
BLAKE2b-256 checksum
How to use checksums
4a6f8cb125366de3900a349279548472df2f78c8750c6f47f14e136a76cc897f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

0.7.5 This release

9 release files

0.7.3

9 release files

0.7.2

9 release files

0.7.1

9 release files

0.6.8

9 release files

0.6.7

9 release files

0.6.6

9 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page