Safe by default
Writes, most shell commands and reads outside the directory ask first, and a write shows you
the diff. Secret files and dangerous commands are always denied, even with --yolo.
Safe by default
Writes, most shell commands and reads outside the directory ask first, and a write shows you
the diff. Secret files and dangerous commands are always denied, even with --yolo.
Done means done
/until dotnet test keeps the agent working until your own check command passes. A command
decides when the work is finished, never a model.
Full-screen terminal UI
Replies are styled Markdown as they stream, with syntax-highlighted code. Keep typing while
anchor works, attach files with @path, open any tool’s whole output, search the
conversation, and /copy a reply. The bell rings when anchor needs you.
Long sessions
Context stays under the model’s window by summarizing, trimming and, as a last resort,
dropping old steps. Sessions resume, and /undo reverts the last turn’s file changes.
Extensible
Background sub-agents, Agent Skills and MCP servers with OAuth all go through the same approval checkpoint.
Scriptable
-p runs one prompt and prints the answer. --json streams events for scripts, CI and
editors.
Your model
Claude through the native API with prompt caching, or any OpenAI-compatible API: OpenAI, xAI, or a server on your own machine.