Dispatch bounded tasks to isolated LLM workers (GLM, Kimi, and more)
Project description
pilot-workers
Dispatch bounded tasks to isolated LLM workers. Your main AI agent (Claude, Codex, or any planner) stays in control of requirements, planning, and verification — the worker only executes what it's told.
What it does
- Provider isolation: each model (GLM, Kimi, DeepSeek, or your own) gets its own credentials, XDG directories, logs, and session storage. No cross-contamination.
- Fixed routing: provider, model, and endpoint are locked per YAML config. Tasks cannot override them.
- Security by default: API keys never appear in CLI args, environment variables, task contracts, or logs. Output is auto-redacted.
- Five modes:
code(edit),explore(read-only),test(run tests),review(read-only audit),resume(continue a prior code session). - Pluggable runners: the runner adapter layer (
RunnerABC) abstracts engine-specific details. Currently ships with OpenCode; designed for future alternatives. - Observable: two-line JSON contract (
started+ structuredverdictcarryingparse_state, a per-moderesult, andfinal_text_path) for AI planners; human-readablelatest.logfortail -f. - Per-run sandboxes: every dispatch runs inside its own isolated XDG tree (
providers/<key>/runs/<run_id>/) with a zero-copy symlink to the canonical credential and a shared per-provider cache; resume (--session+--run-id) reuses the original sandbox. - Host-level playbook: one
pilot-workersplaybook skill per host (Claude Code or Codex). A host's skill exists only where at least one provider is configured for it, and its worker table is generated from that host's own configuration — a host never learns about a provider you did not give it.
Install
pip install pilot-workers
Quick start
# 1. Install the worker runtime
pilot-workers install runner opencode
# 2. Make a provider available to a host, and set its API key while you are
# there (interactive, key never displayed). The key belongs to the PROVIDER,
# so it is configured once and every host uses it.
pilot-workers install glm on claude --global-key
pilot-workers install kimi-k3 on claude for code --global-key # ...and route code -> kimi-k3
pilot-workers install ds on codex for explore --global-key
# 3. (optional) Refresh a host's deployed skill in place
pilot-workers install claude # idempotent sync; deploys nothing if no provider is configured
pilot-workers install codex
pilot-workers install all # both hosts
# 4. Check everything is ready
pilot-workers status
# 5. Verify with a dry-run
pilot-workers run --provider glm --mode explore --workdir . --task "hello" --dry-run
# 6. Run a real task
pilot-workers template code > /tmp/task.md # generate a structured task template
# fill in the template, then:
pilot-workers dispatch --provider glm --mode code --workdir /path/to/project --task-file /tmp/task.md
# dispatch stdout = exactly two JSON lines: worker_runner.started + worker_runner.verdict
CLI reference
pilot-workers <subcommand> [args]
run Dispatch a task (streaming output).
dispatch Deterministic wrapper around run (two-line JSON: started + verdict).
fanout Dispatch several jobs concurrently; stdout = one JSON array of verdicts.
template Print the task template for a mode (code|explore|test|review).
install Configure a worker for a host, or deploy/refresh a host's skill.
install <provider> on <host> [for <mode>] [--global-key]
install <host|all> [--target <dir>]
install runner <name>
uninstall Remove a worker from a host, an assignment, a key, or a whole host.
uninstall <provider> on <host>
uninstall for <mode> on <host>
uninstall key <provider>
uninstall <host|all>
uninstall runner <name>
status Show provider credentials, host installs, and runner state.
status [--json]
status <host>
maintain Worker log, run-sandbox, and worktree lifecycle tools.
maintain logs --older-than-days N
maintain runs --older-than-days N [--keep M]
maintain worktrees list|remove <path>
Adding a new provider
Drop a YAML file in data/providers/ (inside the package):
key: my-model
provider_id: my-worker
model_id: my-model-v1
base_url: https://api.example.com/v1
display_name: My Model Worker
context_tokens: 128000
output_tokens: 8192
# runner: opencode # optional, default opencode
# permissions: relaxed # optional, reference a permission profile
# asset_prefix: my-model # optional, default = key (legacy; no longer used for file naming)
# strengths: ... # optional, surfaced by `pilot-workers status`
# suitable_modes: ... # optional, surfaced by `pilot-workers status`
# notes: ... # optional, surfaced by `pilot-workers status`
Then pilot-workers install my-model on claude --global-key (or codex) to set its API key and deploy/refresh that host's playbook skill.
Reserved keys (cannot be used as provider key): runner, all, on, for, key, claude, codex.
Host integration
The host is whatever AI agent acts as the planner. Each host ships ONE pilot-workers playbook skill (a doctrine playbook, not provider-specific syntax) — a core SKILL.md plus five on-demand modes/<mode>.md playbooks, so triggering loads the core only and mode craft is read per dispatch:
claude-host/skills/pilot-workers/: playbook skill for Claude Code (installed to~/.claude/skills/pilot-workers/)codex-host/skills/pilot-workers/: the same playbook skill for Codex (installed to$CODEX_HOME/skills/pilot-workers/)
pilot-workers install <provider> on <host> copies the skill into the host's skill directory and regenerates its worker table from that host's configuration; the doctrine itself carries no engine-specific knowledge. The deployed tree is a build artifact — every install re-renders it from the packaged template, so upgrading is pip upgrade + pilot-workers install <host|all> (hosts with nothing configured are untouched). Removing the last provider deletes the skill, so a host with nothing configured has none and the planner does the work itself. (The v0.4.0 12-agents + 8-commands matrix is gone.)
Adding a new host: create integrations/<name>-host/skills/pilot-workers/, put whatever config your host needs, point it at pilot-workers dispatch. See integrations/README.md.
Architecture
See CLAUDE.md for the current architecture, module reference, and conventions. See docs/architecture.md for the detailed contract and security model.
Development
python3 -m venv .venv && .venv/bin/pip install -e ".[dev]"
.venv/bin/pytest # the whole suite, offline
License
MIT
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file pilot_workers-0.5.5.tar.gz.
File metadata
- Download URL: pilot_workers-0.5.5.tar.gz
- Upload date:
- Size: 232.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f376e4b0d95016ed5f6815977f41185a132119e8833dfdf0208c0316dc1b1492
|
|
| MD5 |
58393ce675ea82a103ad72495e8c3a39
|
|
| BLAKE2b-256 |
de23a6b0554927e41e87280c7cbf44efd126d88328eebf5846a2f6c9255e2a53
|
Provenance
The following attestation bundles were made for pilot_workers-0.5.5.tar.gz:
Publisher:
publish.yml on gWcyWoo/pilot-workers
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pilot_workers-0.5.5.tar.gz -
Subject digest:
f376e4b0d95016ed5f6815977f41185a132119e8833dfdf0208c0316dc1b1492 - Sigstore transparency entry: 2256334482
- Sigstore integration time:
-
Permalink:
gWcyWoo/pilot-workers@d476268d0fcad2ae032ead290f30f5e4efe67fac -
Branch / Tag:
refs/tags/v0.5.5 - Owner: https://github.com/gWcyWoo
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@d476268d0fcad2ae032ead290f30f5e4efe67fac -
Trigger Event:
push
-
Statement type:
File details
Details for the file pilot_workers-0.5.5-py3-none-any.whl.
File metadata
- Download URL: pilot_workers-0.5.5-py3-none-any.whl
- Upload date:
- Size: 143.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ca1e233b4cc21cce47041e4e65190657a564d02c8ace5fde752f24f60e67e111
|
|
| MD5 |
90985471fe6fb1cf92f539fd6c242094
|
|
| BLAKE2b-256 |
e9ac2760d3da019a402b9aa4e46561b71cbd6338667149231d34bde0f08a6091
|
Provenance
The following attestation bundles were made for pilot_workers-0.5.5-py3-none-any.whl:
Publisher:
publish.yml on gWcyWoo/pilot-workers
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
pilot_workers-0.5.5-py3-none-any.whl -
Subject digest:
ca1e233b4cc21cce47041e4e65190657a564d02c8ace5fde752f24f60e67e111 - Sigstore transparency entry: 2256334490
- Sigstore integration time:
-
Permalink:
gWcyWoo/pilot-workers@d476268d0fcad2ae032ead290f30f5e4efe67fac -
Branch / Tag:
refs/tags/v0.5.5 - Owner: https://github.com/gWcyWoo
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@d476268d0fcad2ae032ead290f30f5e4efe67fac -
Trigger Event:
push
-
Statement type: