Install
Kite installs from a script in a public repository. It is not on PyPI, which means the repository has to stay public for the raw file URLs to resolve.
Then run kite inside a repository; it needs
>=3.11 or newer. Manual install, update, and uninstall
are in the README.
macOS, Linux, WSL
curl -fsSL https://raw.githubusercontent.com/KhanUzeb/kite/main/scripts/download.sh | bash Windows PowerShell
irm https://raw.githubusercontent.com/KhanUzeb/kite/main/scripts/download.ps1 | iex If execution policy blocks it
powershell -NoProfile -ExecutionPolicy Bypass -Command "irm https://raw.githubusercontent.com/KhanUzeb/kite/main/scripts/download.ps1 | iex" Modes
Two modes. Plan blocks write, edit, bash at the dispatch layer, so nothing is written even if the model tries, and it adds back the read, search, and fetch tools on top. Build restores write access.
Switch with /plan and /build inside a session, or start with
kite run --mode plan "…".
| Mode | Approval | Use it for |
|---|---|---|
| plan | readonly | a checklist before committing to an approach |
| build | auto | the actual edit |
Model providers
kite setup configures a provider and a default model. The catalog hardcodes
no model ids, so kite models fetches the live list from whichever provider
you point it at.
Subscription providers use a plan you already pay for rather than API credits. Link one
with kite login <provider>. Keys are read from your user config or the
environment, never from the project repository.
ANTHROPIC_API_KEY. Antigravity chat runs through the signed-in
agy CLI, and GEMINI_API_KEY upgrades it to direct
tool-supporting calls.
Subscription
ChatGPT (subscription) Claude (subscription) Grok (subscription) Antigravity (subscription) OpenCode Go
API key
| Provider | Environment variable |
|---|
Local and custom
| Provider | Base URL |
|---|---|
| Ollama (local) | http://localhost:11434 |
| Custom OpenAI-compatible | http://localhost:8000/v1 |
Approval
Each tool call has its side effects derived before it runs, and those effects decide
whether a human is asked. Autonomy is one of auto, trust,
supervised, yolo, or readonly.
In auto, trust, and yolo the agent runs on its own
and only risky classes prompt. supervised prompts on every mutation.
With no approver available, calls in a mandatory class are refused rather than run, and a crew inherits its parent's policy so a restricted parent cannot be escaped by delegating.
Always needs a decision
destructive network durable memory package or skill install nested agent
Consequence tiers
routine serious critical
Refused outright
46 shell patterns, including rm -rf /, disk writes,
fork bombs, and piping a download into a shell. Web fetches are checked against private
address ranges.
Skills, commands, and plugins
A skill is a markdown file with name and description
frontmatter in a SKILL.md. Kite reads the description to decide relevance and
loads the body when a task matches. Lookup order is bundled,
~/.kite/skills, ~/.agents/skills, plugins, then
.kite/skills in the project.
A workspace plugin lives in .kite/plugins/<name>/ and can bundle
commands and skills for one project. Python extensions can register tools through the
extension API, documented in
architecture.md.
.kite-provenance.json next to the skill.
/skills
/skills add <package-or-path>
/commands new <name>
/plugins init <name> Bundled skills
/commit /debug /init /orchestrate /pr /research /review
Bundled commands
/explain /fix /pr /unslop
Tools
Parallelism is explicit rather than inferred. read, grep,
glob, and ls are concurrency-safe. bash,
task, subagent, and submit are serial, and
sibling subagent calls are coalesced into one crew dispatch.
Web search, fetch, and crawl work with no extra setup through DuckDuckGo. Context7 library documentation lookup is on by default. The GitHub tools are off until you enable them.
Coding tools
read write edit bash grep glob ls set_cwd skill todo_write todo_read task webfetch websearch webcrawl subagent memory submit question
Optional web keys
TAVILY_API_KEY, EXA_API_KEY, FIRECRAWL_API_KEY,
and CONTEXT7_API_KEY turn on more.
Crews
subagent delegates. A worker cannot spawn further agents or write to memory,
and every subagent returns a fixed contract of result, files touched, and tests run, so
the parent verifies rather than trusts.
Each subagent gets its own step and cost budget with a 300 second timeout.
| Bound | Value |
|---|---|
| Concurrent workers | 3 |
| Hard cap | 12 |
| Depth | 1 |
| Max spawns | 64 |
Personas
coder context reviewer scout shell
Verification
The collector derives verification from tool results and explicitly not from what the model claims. When the gate blocks a submit, the refusal names a command to run.
The plan is discovered from your workspace: Python, JavaScript, Rust, and Go are
detected from their markers, and a .kite/verification.toml overrides the
whole thing. The gate is on by default and is one config flag to turn off.
Change states
idle changed_unverified failed verified partial
Only verified and partial let a submit through.
Memory and sessions
Sessions are JSONL. Continue one with kite resume --last or browse with
kite sessions. Context is discovered from the project, and memory injection
is opt-in rather than on by default.
Session policy
full redacted disabled
Default is redacted.
Context files
CONTEXT.md AGENTS.md KITE.md
Stores
MEMORY.md MEMORY.md (project) episodes.sqlite
Limits
These are the shipped defaults, read from
src/kite/data/configs/default.toml. Override them in
~/.kite/configs/default.toml.
When a run hits a ceiling it reports which one and how to continue, rather than stopping quietly. A task that spends 7 loops without progress is stopped as stuck.
| Limit | Default |
|---|---|
| Steps per task | 40 |
| Cost per task | $5.00 |
| Steps interactive | 80 |
| Cost interactive | $10.00 |
| Shell timeout | 120s |
| Provider retries | 4 |
| Output kept | 16,384 chars |
| Execution mode | host |
Architecture
The terminal interface drives an agent loop. The loop asks the model for a tool call, derives that call's side effects, asks the policy engine whether it is allowed, runs it through the execution layer, and feeds the result back. A separate verification collector watches the results.
What is not built in
MCP stdio support was removed and legacy [[mcp]] keys are ignored rather
than silently half-working. Context7 is the only bundled documentation integration and
no other MCP servers are included. Secret redaction is pattern-based, not exhaustive.
Kite runs no telemetry and operates no shared provider account or credential proxy.
Found an error here? Open an issue.
Shape
A test suite that is not an integration suite against live model APIs.
Interface
prompt_toolkit + rich