Skip to main content

packet-ask

Korean

A local CLI that sends only a scrubbed packet to a SUB agent. The MAIN agent is whichever session you are in now.

It copies the files or diff you choose, scrubs them, then either runs an official CLI against that packet or prints packet.md to paste elsewhere.

This tool shrinks what you send on purpose. It does not guarantee no leakage and does not stop vendor training. Vendor terms still apply. See SECURITY.md (Korean).

MIT licensed. See LICENSE.

Requirements

  • Python 3.11+
  • uv 0.10.9+ (same lower bound as uv_build in pyproject.toml)
  • GLM / Claude SUB runs: a claude CLI on the allowlist path (origin signatures are not verified)
  • Kimi runs: a kimi CLI on the allowlist path
  • paste / grok / agy print a packet and do not launch a vendor

Keys are environment variables only. This tool does not read .env files. Do not put key values on the command line; they land in shell history. .env is gitignored. Variable names are in .env.example. The executable allowlist is in SECURITY.md. doctor only checks that help text mentions required flags. It does not prove a no-tools sandbox. Launch probes only the selected binary. doctor still lists the catalog and caches --help by executable path, mtime, and size for the process lifetime.

Install

uv tool install packet-ask
packet-ask install-skills
packet-ask doctor

If it is already installed, run uv tool upgrade packet-ask. pipx install packet-ask and pip install packet-ask in a venv also work.

From the GitHub default branch:

uv tool install git+https://github.com/ictechgy/packet-ask

Local checkout:

uv sync
uv run packet-ask doctor

install-skills writes SKILL.md to ~/.claude/skills/packet-ask, ~/.grok/skills/packet-ask, ~/.codex/skills/packet-ask, and ~/.agents/skills/packet-ask. After that, /packet-ask or a phrase like "review with kimi" should make MAIN call this CLI.

Scope

review requires one of the flags below. It does not send the whole working tree by default.

Flag What is sent
--files the listed files
--diff the given git range
--staged staged diff
--unstaged uncommitted working-tree diff

research does not attach local files or diffs by default. The only exception is --include-files. --diff and --staged are rejected.

--max-files applies to explicit files and diff paths. --max-bytes applies to the final UTF-8 packet.md, including framing and path labels. Reads stop at the configured bound, and explicit binary or non-UTF-8 files are rejected.

Usage

packet-ask providers

# Packet only; do not launch a vendor
packet-ask review --provider paste --files src/app.py --question "Find race conditions in this code"
packet-ask review --provider paste --files src/app.py --json --question "Find race conditions in this code"

# GLM. Key: PACKET_ASK_GLM_KEY
packet-ask review --provider glm --diff HEAD --question "Review this change"

# Uncommitted working-tree diff. review without a scope flag is rejected
packet-ask review --provider paste --unstaged --question "Review this change"

# Anthropic Claude SUB. Key: PACKET_ASK_CLAUDE_KEY. Parent BASE_URL is unchanged
packet-ask review --provider claude --files src/app.py --question "Review this code"

# Kimi. Key: PACKET_ASK_KIMI_KEY
packet-ask review --provider kimi --files src/app.py --question "Review this code"

# grok/agy still paste; they do not run a no-tools one-shot yet
packet-ask review --provider grok --files src/app.py --question "Review this code"

# Research. Local files are off by default
packet-ask research --provider paste --question "What usually breaks in a Tailwind v4 migration?"

packet-ask doctor

Kimi is official kimi --quiet one-shot. It does not open an interactive session. It refuses to run without PACKET_ASK_KIMI_KEY. Tools are disabled with a tools: [] agent file and a non-matching [tools] enabled list. KIMI_CODE_HOME is only the isolated profile ~/.config/packet-ask/providers/kimi/kimi-code. Do not run kimi in the real repo.

GLM uses the official claude binary. It does not change the parent shell ANTHROPIC_BASE_URL. Only the child environment gets the Z.ai Claude Code endpoint and PACKET_ASK_GLM_KEY. GLM and Claude child environments also set CLAUDE_CODE_DISABLE_AUTO_MEMORY, CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC, and DISABLE_ERROR_REPORTING. That reduces local session residue. It does not prove the vendor stores nothing.

On success, stderr prints a receipt before launch (packet-ask receipt …) and millisecond phase times after (packet-ask timing …). --json adds a timing object. Neither line contains keys. Receipt paths are JSON escaped, and terminal control sequences are removed from untrusted provider output before it is printed.

Packet temp dirs live in the OS cache, not the git worktree. cwd is not a sandbox. A PACKET_ASK_CACHE_DIR inside the worktree is rejected. .gitignore entries for .packet-ask-tmp/ and packet.md only stop leftover files from being committed.

User config ~/.config/packet-ask/providers.toml adds paste aliases only. It does not accept executables, argv, or env.

The implementation/incident question gate is a conservative lexical check, not a proof of intent. Launch adapters still disable tools and confine the child to the packet even if wording is novel.

version = 1
[providers.gemini]
label = "Gemini CLI"

Skills

packet-ask install-skills installs into harness homes. The skill only tells MAIN to call packet-ask. Isolation is enforced by the CLI.

Exit codes

1014 mean the vendor process was never started.

Code Meaning
0 success
1 internal error
2 usage error
10 policy reject (implementation, incidents, ...)
11 scope reject
12 redaction / re-check failed
13 could not confirm launch conditions
14 over budget
20 provider or key missing
21 provider failed
22 output guard failed (dedicated key leak or oversized output)

Development

uv sync --group dev
uv run pytest

The current confinement hardening rationale is in docs/hardening.md.

See CONTRIBUTING.md.

License

MIT Copyright (c) 2026 Coden

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

packet_ask-0.1.6.tar.gz (33.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

packet_ask-0.1.6-py3-none-any.whl (43.1 kB view details)

Uploaded Python 3

File details

Details for the file packet_ask-0.1.6.tar.gz.

File metadata

  • Download URL: packet_ask-0.1.6.tar.gz
  • Upload date:
  • Size: 33.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for packet_ask-0.1.6.tar.gz
Algorithm Hash digest
SHA256 f72b2e2f7480c66330ee4b66e2a812b5e1eee0a2361455c9eedf6e37104008ae
MD5 4834f1979e578ff5ddc821f049147061
BLAKE2b-256 37ed5c126691dc4eaa8c78141ac7e62980a586e1500c12fdba0cae24b4698c3b

See more details on using hashes here.

Provenance

The following attestation bundles were made for packet_ask-0.1.6.tar.gz:

Publisher: release.yml on ictechgy/packet-ask

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file packet_ask-0.1.6-py3-none-any.whl.

File metadata

  • Download URL: packet_ask-0.1.6-py3-none-any.whl
  • Upload date:
  • Size: 43.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: uv/0.12.7 {"installer":{"name":"uv","version":"0.12.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for packet_ask-0.1.6-py3-none-any.whl
Algorithm Hash digest
SHA256 968089295c9b1e433ea7e34d7e168440556fc3090f83ec5676aad47e98429d2e
MD5 2d38e6affe8158c545fdd516ab3f4b82
BLAKE2b-256 af13e71cdab91fbc1ecc3a3c3ef84e875857c90970ef53387fd9878b9e5ebdf2

See more details on using hashes here.

Provenance

The following attestation bundles were made for packet_ask-0.1.6-py3-none-any.whl:

Publisher: release.yml on ictechgy/packet-ask

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.7.1

2 files

0.7.0

2 files

0.6.0

2 files

0.5.1

2 files

0.5.0

2 files

0.4.0

2 files

0.3.0

2 files

0.2.0

2 files

0.1.9

2 files

0.1.8

2 files

0.1.7

2 files

This release

0.1.6 This release

2 files

0.1.5

2 files

0.1.4

2 files

0.1.3

2 files

0.1.2

2 files

0.1.1

2 files

0.1.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page