A permission engine sits between the agent and your machine — allow / ask / deny per tool. When a rule says ask, it stops.
In plan mode it can only read. It investigates, writes the plan, and hands the decision back to you:
A terminal coding harness with a headless agent core, where every capability — including the interface — is a plugin. One compiled binary: no runtime, no node_modules.
Permissions per tool, plan mode, secret redaction, undo across files and conversation, sub-agents, background jobs, MCP and LSP. Configuration layers a user file with a project file.
This page is an emulation of the real terminal interface and needs JavaScript to run.