A coding agent that shows what it verified.
Kite is an open source terminal coding agent that records the checks behind a change and blocks submission until there is evidence. Bring the model you already pay for.
curl -fsSL https://raw.githubusercontent.com/KhanUzeb/kite/main/scripts/download.sh | bash irm https://raw.githubusercontent.com/KhanUzeb/kite/main/scripts/download.ps1 | iex v1.0.6 · MIT · python 3.11+ · 16 providers · 19 tools
PowerShell blocks this?
powershell -NoProfile -ExecutionPolicy Bypass -Command "irm https://raw.githubusercontent.com/KhanUzeb/kite/main/scripts/download.ps1 | iex" Evidence, not a claim that the work is done.
Most agents will tell you a task is finished. Kite records what actually ran and holds the submission until there is a result behind it.
The collector watches tool results rather than the model's own summary, and derives
verification from what ran rather than from what the model claims. A change moves between
five states, and only verified and partial let a submit through.
The plan is discovered from your workspace: Python, JavaScript, Rust, and Go are detected
from their markers, and a .kite/verification.toml overrides it. A check is a test
runner, a linter, a build, or any command whose output looks like a terminal status.
Two modes, and one of them cannot edit.
Plan is a read-only checklist. Build is the same loop with write access.
Plan mode is enforced where the tools are dispatched, not by asking the model to be
careful. A mutating call in plan mode returns
blocked in plan mode and nothing is written.
Both modes default to a different approval level, so switching to plan also tightens what the agent can do without a decision.
agent/mode.py| Mode | Default |
|---|---|
| plan | readonly |
| build | auto |
Some things always ask. Nothing assumes.
Autonomy is a dial, and some effect classes sit past the far end of it.
Every tool call has its side effects derived before it runs, and those effects decide
whether a human is asked. In auto, trust, and yolo the
agent runs on its own and only risky classes prompt; supervised prompts on every
mutation.
The consequence of an action is graded, and outside-workspace writes, sudo, and sandbox denials are the critical tier: they prompt even in yolo, and they are denied outright when there is nobody to ask.
SECURITY.md| Effect class | Why it asks |
|---|---|
| destructive | deletes or overwrites outside an edit |
| network | reaches the network |
| durable memory | writes to memory that outlives the session |
| package or skill install | runs code from a new source |
| nested agent | spawns another agent |
Shell commands are refused outright, including rm -rf /, disk writes, fork
bombs, and piping a download into a shell.
Delegation with the edges spelled out.
A crew splits work across personas that cannot escalate, and reports back in a fixed shape.
The personas that ship are coder, context, reviewer, scout, shell. Each returns a result, the files it touched, and the tests it ran, so the parent verifies the work rather than trusting the summary.
Sibling subagent calls are coalesced into a single crew dispatch instead of running one after another, and a subagent gets its own step and cost budget with a 300 second timeout.
agent/orchestrator.py| Bound | Value |
|---|---|
| Concurrent workers | 3 |
| Hard cap | 12 |
| Depth | 1 |
| Max spawns | 64 |
The ceilings are in the config, not in a promise.
These are the shipped defaults, read from the config the tool loads.
When a run hits a ceiling it says which one and how to continue, rather than stopping
quietly. Every value here is overridable in
~/.kite/configs/default.toml.
| Limit | Default |
|---|---|
| Steps per task | 40 |
| Cost per task | $5.00 |
| Steps interactive | 80 |
| Cost interactive | $10.00 |
| Shell timeout | 120s |
| Provider retries | 4 |
| Output kept | 16,384 chars |
Execution mode is host and the working directory is sandboxed
unless you change it.
The decisions, and what each one costs.
Each one is enforced in code rather than left to the model's judgement, and the link points at the file that does it.
-
It refuses to submit work it cannot back up
Kite builds a verification plan from your workspace and records the result of every check. Submit stays blocked while a change is not verified.
The gate is on by default, and turning it off is one config line.
application/verification.py -
Plan mode is read-only, not a suggestion
Plan mode allows 21 read, search, and fetch tools and blocks write, edit, bash outright, in the loop rather than in the prompt.
You cannot try a change in plan mode. Switch to build when you want edits.
agent/mode.py -
Some tool actions fail closed
destructive, network, durable memory, package or skill install, nested agent. With no approver available the call is refused rather than run.
A crew inherits its parent's policy, so a restricted parent cannot be escaped by delegating. You approve more than you might expect.
application/tools.py -
A crew is a bounded fan-out, not a swarm
Personas ship for it (coder, context, reviewer, scout, shell), and subagents return a fixed contract of result, files touched, and tests run.
Depth is 1 and a worker cannot spawn agents or write memory, so the shape is fixed.
agent/orchestrator.py -
It has no model allowlist
Kite maintains no list of approved model names, so a new provider release works without waiting on a Kite update.
You can pick a model that cannot tool call well, and find out mid-task instead of at selection time.
CONTEXT.md -
Secrets are scrubbed, but the scrubber is a pattern
Output is filtered for known credential shapes before it is stored, and web tools are guarded against SSRF to private address ranges.
Redaction is pattern-based, and approval decisions and tool events persist in your home directory until you delete them.
SECURITY.md
Providers, grouped by how you connect.
The catalog stores auth metadata and no model names, so nothing goes stale when a provider ships something new.
Coding tools ship by default with Context7 documentation lookup on, and the GitHub tools off until you enable them. Credentials are read from your user config or the environment, never from the repository you are working in.
Two subscription entries carry a caveat worth knowing. Linking Claude Code reports status but model calls still need an API key, and Antigravity chat runs through a signed-in CLI.
Providers, with environment variablesSubscription. ChatGPT (subscription) · Claude (subscription) · Grok (subscription) · Antigravity (subscription) · OpenCode Go
API key. OpenAI · Anthropic · xAI · OpenRouter · Hugging Face · Google Gemini · Groq · OpenCode Zen · NVIDIA NIM
Local. Ollama (local)
Teach it the way you work.
Skills, commands, and plugins, all readable before you run them.
A skill is a markdown file with name and description
frontmatter. Kite reads the description to decide relevance and loads the body when a task
matches.
Bundled skills are trusted; installed and project-provided ones are labelled with their source and treated as untrusted instructions, because a skill is a prompt you are about to hand a model with shell access.
How skills and plugins resolve/skills
/skills add <package-or-path>
/commands new <name>
/plugins init <name> Bundled: /commit, /debug, /init, /orchestrate, /pr, /research, /review
What Kite does not do.
The gaps are worth as much as the features, so they are listed rather than left to be discovered.
| Not built | What that costs |
|---|---|
| MCP stdio servers | Removed. Legacy [[mcp]] keys in runtime TOML are ignored rather than silently half-working. Context7 is the only bundled documentation integration. |
| A model allowlist | Kite will try a model name it has never seen. The cost is that nothing stops you picking one that cannot tool-call. |
| Recursive agent trees | Subagent depth is 1 and a worker cannot spawn further agents. A crew is a fan-out you bound, not a swarm. |
| Live model quota reporting | No provider exposes a quota API to the harness, so cost and context figures come from local counters and can drift. |
| Exhaustive secret redaction | Filtering is pattern-based. The security notes say so rather than implying credentials are guaranteed clean. |
Don't like it? Fork it.
Kite is MIT licensed, by Uzeb Khan. It installs from a script in a public repository rather than a package registry, so you can read what you are about to run.