Skip to content

agent6

A coding agent that jails every command and leaves your branch untouched.

The run dashboard: task graph, budget, tool calls, reasoning, log, and diff

uv tool install agent6                 # or: pipx install agent6
agent6 connect                         # pick a provider, paste a key (once)
cd your-repo
agent6 run "add a --json output mode to the CLI"

Jailed commands

Every command the model runs goes through a sandbox that bounds what it reads, writes and reaches on the network. auto picks the strongest level the host allows. Security

Your branch stays yours

Each step commits to the run's own hidden ref; HEAD, the index and your branch are untouched until sessions merge lands the work. resume continues a run, fork branches it at any turn.

A verify gate

The repo's test command, inferred when unset, certifies the tree before a run may finish. Every surface shows the same green or red.

One run, four front-ends

The CLI, the terminal UI, a browser on a desktop or phone, and an editor over ACP drive the same runs. attach follows a live run; steer queues an instruction from a script or a cron job.

State machines for long work

.asm.toml files you review, edit, run, watch and replay, with waits, operator input and steering built in. State machines

Secure by default

network = "auto", run_commands = "ask", protect_git = true, a fixed tool surface, eight runtime dependencies, no telemetry. Configuration

The terminal UI

agent6 run streams the run in your terminal; agent6 tui opens the hub, every run for the repository with its mode, status and cost, and from there the live conversation and the dashboard (Ctrl+D). The terminal UI page has a still of each screen.

The web UI

agent6 web serves the same views in a browser, from a desktop or a phone: start a run, watch it stream, steer it, approve prompts, answer questions, read the transcript, browse and run state machines. It binds 127.0.0.1; put tailscale serve in front for encrypted remote access. See the web UI.

Installation covers requirements, shell completion and building from source. Usage covers the first run, inspecting it and recovering one that went wrong.