A coding agent that shows what it verified.

Kite is an open source terminal coding agent that records the checks behind a change and blocks submission until there is evidence. Bring the model you already pay for.

curl -fsSL https://raw.githubusercontent.com/KhanUzeb/kite/main/scripts/download.sh | bash

v1.0.6 · MIT · python 3.11+ · 16 providers · 19 tools

Read the docs Browse the source

Evidence, not a claim that the work is done.

Most agents will tell you a task is finished. Kite records what actually ran and holds the submission until there is a result behind it.

The collector watches tool results rather than the model's own summary, and derives verification from what ran rather than from what the model claims. A change moves between five states, and only verified and partial let a submit through.

The plan is discovered from your workspace: Python, JavaScript, Rust, and Go are detected from their markers, and a .kite/verification.toml overrides it. A check is a test runner, a linter, a build, or any command whose output looks like a terminal status.

application/verification.py

Two modes, and one of them cannot edit.

Plan is a read-only checklist. Build is the same loop with write access.

Plan mode is enforced where the tools are dispatched, not by asking the model to be careful. A mutating call in plan mode returns blocked in plan mode and nothing is written.

Both modes default to a different approval level, so switching to plan also tightens what the agent can do without a decision.

agent/mode.py
ModeDefault
plan readonly
build auto

Some things always ask. Nothing assumes.

Autonomy is a dial, and some effect classes sit past the far end of it.

Every tool call has its side effects derived before it runs, and those effects decide whether a human is asked. In auto, trust, and yolo the agent runs on its own and only risky classes prompt; supervised prompts on every mutation.

The consequence of an action is graded, and outside-workspace writes, sudo, and sandbox denials are the critical tier: they prompt even in yolo, and they are denied outright when there is nobody to ask.

SECURITY.md
Effect classWhy it asks
destructive deletes or overwrites outside an edit
network reaches the network
durable memory writes to memory that outlives the session
package or skill install runs code from a new source
nested agent spawns another agent

Shell commands are refused outright, including rm -rf /, disk writes, fork bombs, and piping a download into a shell.

Delegation with the edges spelled out.

A crew splits work across personas that cannot escalate, and reports back in a fixed shape.

The personas that ship are coder, context, reviewer, scout, shell. Each returns a result, the files it touched, and the tests it ran, so the parent verifies the work rather than trusting the summary.

Sibling subagent calls are coalesced into a single crew dispatch instead of running one after another, and a subagent gets its own step and cost budget with a 300 second timeout.

agent/orchestrator.py
BoundValue
Concurrent workers3
Hard cap12
Depth1
Max spawns64

The ceilings are in the config, not in a promise.

These are the shipped defaults, read from the config the tool loads.

When a run hits a ceiling it says which one and how to continue, rather than stopping quietly. Every value here is overridable in ~/.kite/configs/default.toml.

LimitDefault
Steps per task40
Cost per task$5.00
Steps interactive80
Cost interactive$10.00
Shell timeout120s
Provider retries4
Output kept16,384 chars

Execution mode is host and the working directory is sandboxed unless you change it.

The decisions, and what each one costs.

Each one is enforced in code rather than left to the model's judgement, and the link points at the file that does it.

  • It refuses to submit work it cannot back up

    Kite builds a verification plan from your workspace and records the result of every check. Submit stays blocked while a change is not verified.

    The gate is on by default, and turning it off is one config line.

    application/verification.py
  • Plan mode is read-only, not a suggestion

    Plan mode allows 21 read, search, and fetch tools and blocks write, edit, bash outright, in the loop rather than in the prompt.

    You cannot try a change in plan mode. Switch to build when you want edits.

    agent/mode.py
  • Some tool actions fail closed

    destructive, network, durable memory, package or skill install, nested agent. With no approver available the call is refused rather than run.

    A crew inherits its parent's policy, so a restricted parent cannot be escaped by delegating. You approve more than you might expect.

    application/tools.py
  • A crew is a bounded fan-out, not a swarm

    Personas ship for it (coder, context, reviewer, scout, shell), and subagents return a fixed contract of result, files touched, and tests run.

    Depth is 1 and a worker cannot spawn agents or write memory, so the shape is fixed.

    agent/orchestrator.py
  • It has no model allowlist

    Kite maintains no list of approved model names, so a new provider release works without waiting on a Kite update.

    You can pick a model that cannot tool call well, and find out mid-task instead of at selection time.

    CONTEXT.md
  • Secrets are scrubbed, but the scrubber is a pattern

    Output is filtered for known credential shapes before it is stored, and web tools are guarded against SSRF to private address ranges.

    Redaction is pattern-based, and approval decisions and tool events persist in your home directory until you delete them.

    SECURITY.md

Providers, grouped by how you connect.

The catalog stores auth metadata and no model names, so nothing goes stale when a provider ships something new.

Coding tools ship by default with Context7 documentation lookup on, and the GitHub tools off until you enable them. Credentials are read from your user config or the environment, never from the repository you are working in.

Two subscription entries carry a caveat worth knowing. Linking Claude Code reports status but model calls still need an API key, and Antigravity chat runs through a signed-in CLI.

Providers, with environment variables

Subscription. ChatGPT (subscription) · Claude (subscription) · Grok (subscription) · Antigravity (subscription) · OpenCode Go

API key. OpenAI · Anthropic · xAI · OpenRouter · Hugging Face · Google Gemini · Groq · OpenCode Zen · NVIDIA NIM

Local. Ollama (local)

Teach it the way you work.

Skills, commands, and plugins, all readable before you run them.

A skill is a markdown file with name and description frontmatter. Kite reads the description to decide relevance and loads the body when a task matches.

Bundled skills are trusted; installed and project-provided ones are labelled with their source and treated as untrusted instructions, because a skill is a prompt you are about to hand a model with shell access.

How skills and plugins resolve
/skills
/skills add <package-or-path>
/commands new <name>
/plugins init <name>

Bundled: /commit, /debug, /init, /orchestrate, /pr, /research, /review

What Kite does not do.

The gaps are worth as much as the features, so they are listed rather than left to be discovered.

Not builtWhat that costs
MCP stdio serversRemoved. Legacy [[mcp]] keys in runtime TOML are ignored rather than silently half-working. Context7 is the only bundled documentation integration.
A model allowlistKite will try a model name it has never seen. The cost is that nothing stops you picking one that cannot tool-call.
Recursive agent treesSubagent depth is 1 and a worker cannot spawn further agents. A crew is a fan-out you bound, not a swarm.
Live model quota reportingNo provider exposes a quota API to the harness, so cost and context figures come from local counters and can drift.
Exhaustive secret redactionFiltering is pattern-based. The security notes say so rather than implying credentials are guaranteed clean.

Don't like it? Fork it.

Kite is MIT licensed, by Uzeb Khan. It installs from a script in a public repository rather than a package registry, so you can read what you are about to run.