{
  "data": {
    "category": {
      "area": "frameworks",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "description": "Finished programs that run the agent loop for a person or a pipeline, in a terminal, an editor or the vendor's cloud. They plan, call tools, edit files and run commands, where a framework is a library you build that loop with. Compared on what they ask before acting, what the sandbox and the network allow by default, MCP support, headless use and the telemetry they send.",
      "json": "https://www.anchorterminal.com/categories/agent-harnesses.json",
      "name": "Agent harnesses",
      "slug": "agent-harnesses",
      "test": "The same small repository task run headless in each harness with one MCP server attached, first fixing a failing test, then a task that needs the network. We check what it asks before acting, what the sandbox blocks, whether the run stops on its own, what it costs and what leaves the machine.",
      "title": "Agent harnesses and coding agents",
      "toolCount": 10,
      "tools": [
        "goose",
        "openai-codex",
        "gemini-cli",
        "openhands",
        "opencode",
        "claude-code",
        "cline",
        "github-copilot-cli",
        "aider",
        "cursor-cli"
      ],
      "url": "https://www.anchorterminal.com/categories/agent-harnesses"
    },
    "tools": [
      {
        "slug": "goose",
        "name": "goose",
        "vendor": "Agentic AI Foundation (originally Block)",
        "vendorUrl": "https://goose-docs.ai",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Open-source general-purpose agent written in Rust, with a desktop app, a CLI and an embeddable server.",
        "url": "https://www.anchorterminal.com/tools/goose",
        "markdownUrl": "https://www.anchorterminal.com/tools/goose.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/goose.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/goose.json",
        "repo": "https://github.com/aaif-goose/goose",
        "license": "Apache-2.0",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "@aaif/goose-acp"
          },
          {
            "registry": "oci",
            "name": "ghcr.io/aaif-goose/goose"
          }
        ],
        "auth": "none",
        "authNotes": "No account of its own. Model keys go in the system keyring through `goose configure`, in provider environment variables, or come from an existing Claude, ChatGPT or Gemini subscription through ACP providers.",
        "pricing": "free",
        "pricingNotes": "Free and Apache-2.0, with nothing to buy. You pay your model provider, or nothing with a local model.",
        "priceSummary": "Free · OSS",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 54800,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-01"
        },
        "docsUrl": "https://goose-docs.ai/docs/quickstart",
        "llmsTxt": "https://goose-docs.ai/llms.txt",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "tags": [
          "open-source",
          "local",
          "free",
          "no-card",
          "foundation",
          "llms-txt",
          "docker"
        ],
        "lastRelease": "2026-09-23",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 73.9,
          "grade": "BB",
          "agentReady": true,
          "rank": 52,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 1,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 82,
            "maintenance": 86,
            "payments": 60,
            "reliability": 77,
            "schema": 81,
            "security": 77,
            "transparency": 63
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -2,
          "negativeNotes": [
            "2026-07-24. GHSA-r5pp-p5r8-466r (CVE-2026-72718, 7.0 at NVD), a repository's git `core.fsmonitor` setting ran arbitrary commands during `goose review` without approval or a sandbox. Fixed in 1.44.0 and published, inside six months, -2. https://github.com/aaif-goose/goose/security/advisories/GHSA-r5pp-p5r8-466r"
          ],
          "verdict": "Telemetry off until the user opts in, with the collected fields listed. Autonomous mode, which approves every tool call, is the default.",
          "strengths": [
            "Telemetry off until the user opts in, with the collected fields listed",
            "Four permission modes, per-tool always, ask or never rules, and an extension allowlist an administrator can host",
            "Headless `goose run` with `--output-format json` or `stream-json`, `--max-turns` and recipes with typed parameters, retries and success checks",
            "15+ providers, built-in local inference, and existing Claude, ChatGPT or Gemini subscriptions through ACP",
            "Weekly releases with dated notes, 12 in the 90 days to 1 October 2026"
          ],
          "weaknesses": [
            "Autonomous mode, which approves every tool call, is the default",
            "No sandbox, and prompt-injection detection and adversary mode are off by default",
            "No privacy policy for goose, and the usage-data page doesn't say where data goes or how long it's kept",
            "No breaking-change section in any of the last ten release notes",
            "About 270 open issues, many recent ones unanswered"
          ],
          "agentNotes": [
            "Set `GOOSE_MODE=smart_approve` or `approve` before a run. The default approves everything",
            "Pass `--max-turns` with a real limit. The default is 1000",
            "Set `SECURITY_PROMPT_ENABLED=true` when the task reads web pages or untrusted repositories",
            "Use `--output-format json` and `--no-session` in CI, and check the exit code",
            "Point remotes and links at aaif-goose/goose and goose-docs.ai. The block/goose paths redirect"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 73.9
            }
          ],
          "editorialScores": {
            "ergonomics": 82,
            "maintenance": 86,
            "payments": 60,
            "reliability": 77,
            "schema": 81,
            "security": 77,
            "transparency": 73
          },
          "provenanceScore": 53
        },
        "connect": {
          "install": "curl -fsSL https://github.com/aaif-goose/goose/releases/download/stable/download_cli.sh | bash   # or: brew install block-goose-cli",
          "headless": {
            "command": "goose run --no-session --max-turns 30 --output-format json -t \"$TASK\"",
            "env": {
              "GOOSE_MODE": "smart_approve",
              "GOOSE_MODEL": "\u003cmodel\u003e",
              "GOOSE_PROVIDER": "\u003cprovider\u003e",
              "SECURITY_PROMPT_ENABLED": "true"
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/goose"
        },
        "area": "frameworks",
        "provenance": {
          "legalEntity": "Agentic AI Foundation (Linux Foundation)",
          "domain": "goose-docs.ai",
          "domainRegistered": "",
          "endpointOnVendorDomain": null,
          "terms": "",
          "privacy": "",
          "statusPage": "",
          "changelog": "https://github.com/aaif-goose/goose/releases",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "notes": [
            "The docs footer reads Copyright AAIF (Agentic AI Foundation). Block donated goose, and the escalation contact in SECURITY.md is still a block.xyz address.",
            "We found no terms or privacy page on goose-docs.ai and no security.txt among the docs site's static files.",
            "The repository moved from block/goose to aaif-goose/goose, announced on the goose blog on 7 April 2026."
          ],
          "score": 53
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/goose.json",
        "live": {
          "slug": "goose",
          "versions": [
            {
              "registry": "github",
              "name": "aaif-goose/goose",
              "version": "v1.53.0",
              "released": "2026-10-02",
              "seenAt": "2026-10-04T16:29:00.933626606Z"
            },
            {
              "registry": "npm",
              "name": "@aaif/goose-acp",
              "version": "1.53.0",
              "seenAt": "2026-10-04T16:29:00.469168357Z"
            }
          ],
          "githubStars": 54938,
          "npmWeekly": 228,
          "securityTxt": {
            "url": "https://goose-docs.ai/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:16:04.830171027Z"
          },
          "llmsTxt": {
            "url": "https://goose-docs.ai/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:50.350800204Z"
          },
          "domain": {
            "domain": "goose-docs.ai",
            "registered": "2026-03-30",
            "source": "https://rdap.identitydigital.services/rdap/domain/goose-docs.ai",
            "checkedAt": "2026-10-04T13:06:07.115541766Z"
          },
          "updatedAt": "2026-10-04T16:29:00.933626606Z"
        }
      },
      {
        "slug": "openai-codex",
        "name": "OpenAI Codex",
        "vendor": "OpenAI",
        "vendorUrl": "https://openai.com",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "OpenAI's coding agent for software development tasks.",
        "url": "https://www.anchorterminal.com/tools/openai-codex",
        "markdownUrl": "https://www.anchorterminal.com/tools/openai-codex.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openai-codex.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openai-codex.json",
        "repo": "https://github.com/openai/codex",
        "license": "Apache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "@openai/codex"
          }
        ],
        "auth": "mixed",
        "authNotes": "Sign in with a ChatGPT account (Free, Go, Plus, Pro, Business, Edu or Enterprise) or use an OpenAI API key. Cloud work such as GitHub code review and the Slack integration comes with Plus and above, and none of it works with an API key. `--oss` talks to a local Ollama or LM Studio server and needs no account.",
        "pricing": "freemium",
        "pricingNotes": "Included in every ChatGPT plan. Free $0, Go $8 a month, Plus $20, Pro from $100 (tiers at $100, $200 and $500), Business $20 a user a month billed annually for two or more users, Enterprise and Edu by quote. On Plus the docs estimate 15 to 160 local messages per five hours with GPT-6.1 Sol, and Pro has no five-hour limit. Cloud tasks use more of the allowance. With an API key you pay API token rates and can't use the cloud agent (checked 2026-10-02).",
        "priceSummary": "$20 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-02).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 126000,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-02"
        },
        "docsUrl": "https://developers.openai.com/codex",
        "llmsTxt": "https://learn.chatgpt.com/llms.txt",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "tags": [
          "official",
          "harness",
          "coding-agent",
          "cli",
          "open-source",
          "rust",
          "typescript",
          "python",
          "mcp",
          "llms-txt",
          "telemetry-default-on",
          "pre-1.0",
          "free-tier",
          "no-card",
          "hosted",
          "status-page"
        ],
        "lastRelease": "2026-10-01",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 73.4,
          "grade": "BB",
          "agentReady": true,
          "rank": 58,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 2,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 80,
            "maintenance": 87,
            "payments": 60,
            "reliability": 55,
            "schema": 90,
            "security": 82,
            "transparency": 83
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -2,
          "negativeNotes": [
            "2026-04-14. CVE-2025-61260 (GHSA-xrxf-jgv3-qmrm), critical (CVSS 9.8 from CISA-ADP), code execution through MCP configuration files in a repository for Codex CLI 0.23.0 and earlier, published to NVD and the GitHub Advisory Database from Check Point Research's 2025 report. Fixed in 2025 and documented by the researcher, with no advisory in OpenAI's own repository, so a small deduction (https://nvd.nist.gov/vuln/detail/CVE-2025-61260; https://research.checkpoint.com/2025/openai-codex-cli-command-injection-vulnerability/)"
          ],
          "verdict": "Sandbox on by default on macOS, Linux and Windows, with the network off and `.git` and `.codex` read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes.",
          "strengths": [
            "Sandbox on by default on macOS, Linux and Windows, with the network off and `.git` and `.codex` read-only",
            "Apache-2.0, with public CI and a JSON Schema for config.toml",
            "`codex exec --json`, `--output-schema` and `exec resume` for pipelines, plus TypeScript and Python SDKs",
            "Codex cloud keeps the agent phase offline by default and can limit requests to GET, HEAD and OPTIONS",
            "Included in ChatGPT Free, and `--oss` runs local models through Ollama or LM Studio with no account"
          ],
          "weaknesses": [
            "Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes",
            "Anonymous usage metrics and feedback collection on by default",
            "Over 5,000 open issues",
            "CVE-2025-61260 (critical) has no advisory in OpenAI's own repository",
            "Cloud tasks and code review need a ChatGPT plan, not an API key"
          ],
          "agentNotes": [
            "Run `codex exec --json` in pipelines, with `--output-schema` when the final message has to parse",
            "Keep the default sandbox. `--yolo` removes both the sandbox and approvals",
            "Set `network_access = true` under `[sandbox_workspace_write]` only for tasks that need it. Network is off by default",
            "Set `[analytics] enabled = false` and `[feedback] enabled = false` in config.toml to keep usage data local",
            "Pin the npm version. A 0.x minor lands every few days"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 73.4
            }
          ],
          "editorialScores": {
            "ergonomics": 80,
            "maintenance": 87,
            "payments": 60,
            "reliability": 55,
            "schema": 90,
            "security": 82,
            "transparency": 65
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "npm i -g @openai/codex   # or: brew install --cask codex",
          "headless": {
            "run": "codex exec --json \"fix the failing test\""
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/openai-codex"
        },
        "sameCompany": [
          "openai-api",
          "openai-embeddings",
          "openai-moderation",
          "openai-image-api",
          "openai-sora",
          "openai-agents-sdk"
        ],
        "area": "frameworks",
        "unitPrices": [
          {
            "item": "ChatGPT Plus",
            "unit": "month",
            "usd": 20,
            "note": "includes Codex local and cloud"
          },
          {
            "item": "ChatGPT Pro",
            "unit": "month",
            "usd": 100,
            "note": "lowest Pro tier, no five-hour limit"
          }
        ],
        "provenance": {
          "legalEntity": "OpenAI OpCo, LLC",
          "domain": "openai.com",
          "domainRegistered": "2007-01-19",
          "endpointOnVendorDomain": null,
          "terms": "https://openai.com/policies/services-agreement/",
          "privacy": "https://openai.com/policies/privacy-policy/",
          "statusPage": "https://status.openai.com",
          "changelog": "https://github.com/openai/codex/releases",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "notes": [
            "The Codex docs moved from developers.openai.com/codex to learn.chatgpt.com (302 redirects on 2 October 2026), and the installer is served from chatgpt.com.",
            "Legal entity, domain date and security.txt are from the openai-api listing's check of 26 September 2026."
          ],
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/openai-codex.json",
        "live": {
          "slug": "openai-codex",
          "vendorStatus": {
            "page": "https://status.openai.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T23:27:54.547965456Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "openai/codex",
              "version": "rust-v0.160.0",
              "released": "2026-10-01",
              "seenAt": "2026-10-04T16:35:27.33031869Z"
            },
            {
              "registry": "npm",
              "name": "@openai/codex",
              "version": "0.160.0",
              "seenAt": "2026-10-04T16:35:27.077650904Z"
            }
          ],
          "githubStars": 127838,
          "npmWeekly": 25521694,
          "securityTxt": {
            "url": "https://openai.com/.well-known/security.txt",
            "state": "valid",
            "checkedAt": "2026-10-04T15:15:58.86463118Z"
          },
          "llmsTxt": {
            "url": "https://learn.chatgpt.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:04.216898809Z"
          },
          "domain": {
            "domain": "openai.com",
            "registered": "2007-01-19",
            "source": "https://rdap.verisign.com/com/v1/domain/openai.com",
            "checkedAt": "2026-10-04T13:05:02.32020521Z"
          },
          "updatedAt": "2026-10-04T23:27:54.547965456Z"
        }
      },
      {
        "slug": "gemini-cli",
        "name": "Gemini CLI",
        "vendor": "Google",
        "vendorUrl": "https://geminicli.com",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Google's open-source coding agent for the terminal, in TypeScript on Node 20 or newer.",
        "url": "https://www.anchorterminal.com/tools/gemini-cli",
        "markdownUrl": "https://www.anchorterminal.com/tools/gemini-cli.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/gemini-cli.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gemini-cli.json",
        "repo": "https://github.com/google-gemini/gemini-cli",
        "license": "Apache-2.0",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "@google/gemini-cli"
          }
        ],
        "auth": "mixed",
        "authNotes": "Sign in with a Google account (Gemini Code Assist for individuals, Google AI Pro or Ultra, Code Assist Standard or Enterprise), or use a Gemini API key from AI Studio or Vertex AI credentials. Google's terms forbid using the Gemini CLI sign-in from third-party software.",
        "pricing": "freemium",
        "pricingNotes": "Free with a Google sign-in, up to 1,000 model requests a user a day, or 250 a day on Flash with an unpaid Gemini API key. Google AI Pro raises the daily limit to 1,500 and Ultra to 2,000, Code Assist Standard to 1,500 and Enterprise to 2,000. Pay as you go through a paid Gemini API key or Vertex AI at token rates. Requests are also limited per minute (checked 2026-10-02).",
        "priceSummary": "Freemium",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-02).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 107000,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-02"
        },
        "docsUrl": "https://geminicli.com/docs/",
        "llmsTxt": "https://geminicli.com/llms.txt",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "tags": [
          "official",
          "harness",
          "coding-agent",
          "cli",
          "open-source",
          "typescript",
          "mcp",
          "llms-txt",
          "telemetry-default-on",
          "pre-1.0",
          "free-tier",
          "no-card",
          "gemini-only"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 72.3,
          "grade": "BB",
          "agentReady": true,
          "rank": 72,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 3,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 78,
            "maintenance": 88,
            "payments": 40,
            "reliability": 71,
            "schema": 93,
            "security": 67,
            "transparency": 90
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -2,
          "negativeNotes": [
            "2026-04-24. GHSA-wpqr-6v78-jr5g, critical (CVSS 10). In CI, headless Gemini CLI trusted the workspace folder automatically and loaded its configuration, and `--yolo` ignored fine-grained tool allowlists, so a workflow fed untrusted pull requests or issues could run an attacker's code. Fixed in @google/gemini-cli 0.39.1 and run-gemini-cli 0.1.22 and published, so the deduction is small (https://github.com/advisories/GHSA-wpqr-6v78-jr5g)"
          ],
          "verdict": "Apache-2.0, CI passing on main, and 583 open issues with priority labels. Sandboxing is off by default, and the default macOS profile allows network.",
          "strengths": [
            "Apache-2.0, CI passing on main, and 583 open issues with priority labels",
            "A weekly stable release after a week in preview, under a written release policy",
            "Headless JSON and stream-json output with documented exit codes, including 53 for the turn limit",
            "A TOML policy engine with admin policy paths, folder trust on by default and a setting that blocks yolo mode",
            "1,000 free requests a day with a Google sign-in and no card"
          ],
          "weaknesses": [
            "Sandboxing is off by default, and the default macOS profile allows network",
            "Usage statistics on by default, and the free tier may train on data unless the user opts out",
            "A critical advisory in April 2026 (CVSS 10) for CI runs that trusted untrusted repositories",
            "Pre-1.0 at 0.62.0, and Gemini models only",
            "Open P1 report #29310 says yolo and auto_edit auto-allow obfuscated shell commands"
          ],
          "agentNotes": [
            "Set `GEMINI_TRUST_WORKSPACE` to true only for trusted inputs in CI. Since 0.39.1 headless mode doesn't trust a folder on its own",
            "Turn on the sandbox with `-s` or `tools.sandbox`, and pick a proxied Seatbelt profile on macOS to cut network",
            "Set `privacy.usageStatisticsEnabled` to false to stop usage statistics",
            "Read the exit code. 42 is bad input and 53 is the turn limit",
            "Use `--output-format stream-json` to get tool calls and results as JSONL events"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 72.3
            }
          ],
          "editorialScores": {
            "ergonomics": 78,
            "maintenance": 88,
            "payments": 40,
            "reliability": 71,
            "schema": 93,
            "security": 67,
            "transparency": 80
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "npm i -g @google/gemini-cli   # or: brew install gemini-cli",
          "headless": {
            "run": "gemini -p \"fix the failing test\" --output-format json --approval-mode auto_edit"
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/gemini-cli"
        },
        "sameCompany": [
          "gemini-api",
          "gemini-embedding",
          "vertex-ai-tuning",
          "google-model-armor",
          "google-imagen",
          "google-veo",
          "google-lyria",
          "google-speech-to-text",
          "google-adk",
          "google-secret-manager",
          "google-weather-api",
          "chrome-devtools-mcp",
          "google-maps-platform",
          "google-cloud-translation",
          "google-calendar-api",
          "google-drive-api"
        ],
        "area": "frameworks",
        "provenance": {
          "legalEntity": "Google LLC",
          "domain": "google.com",
          "domainRegistered": "1997-09-15",
          "endpointOnVendorDomain": null,
          "terms": "https://geminicli.com/docs/resources/tos-privacy",
          "privacy": "https://policies.google.com/privacy",
          "statusPage": "https://aistudio.google.com/status",
          "changelog": "https://geminicli.com/docs/changelogs",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "notes": [
            "The docs are on geminicli.com. The terms page there maps each sign-in method to its own terms and privacy notice (Gemini Code Assist, the Gemini API unpaid and paid services, Google Cloud).",
            "The status page is the Gemini API's. We found no status page for Gemini Code Assist sign-ins.",
            "Legal entity, domain date and security.txt for google.com are from the gemini-api listing's check of 26 September 2026."
          ],
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/gemini-cli.json",
        "live": {
          "slug": "gemini-cli",
          "vendorStatus": {
            "page": "https://aistudio.google.com/status",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:40:04.477079675Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "google-gemini/gemini-cli",
              "version": "v0.62.0",
              "released": "2026-09-29",
              "seenAt": "2026-10-04T16:27:48.184399075Z"
            },
            {
              "registry": "npm",
              "name": "@google/gemini-cli",
              "version": "0.62.0",
              "seenAt": "2026-10-04T16:27:47.915925343Z"
            }
          ],
          "githubStars": 107231,
          "npmWeekly": 459071,
          "securityTxt": {
            "url": "https://google.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2030-04-01T00:00:00z",
            "checkedAt": "2026-10-04T15:15:53.387118101Z"
          },
          "llmsTxt": {
            "url": "https://geminicli.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:48.20670565Z"
          },
          "domain": {
            "domain": "google.com",
            "registered": "1997-09-15",
            "source": "https://rdap.verisign.com/com/v1/domain/google.com",
            "checkedAt": "2026-10-04T13:05:50.737985829Z"
          },
          "pages": [
            {
              "url": "https://geminicli.com/docs/changelogs",
              "kind": "changelog",
              "status": 304,
              "checkedAt": "2026-10-04T15:44:53.591365058Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "1a4924fbe02a"
            },
            {
              "url": "https://geminicli.com/docs/resources/tos-privacy",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:44:55.657597873Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "f7d55fbc670d"
            }
          ],
          "updatedAt": "2026-10-04T21:40:04.477079675Z"
        }
      },
      {
        "slug": "openhands",
        "name": "OpenHands",
        "vendor": "All Hands AI",
        "vendorUrl": "https://openhands.dev",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Open-source coding agent with a self-hosted web interface, local and remote execution, and scheduled or webhook-driven automation.",
        "url": "https://www.anchorterminal.com/tools/openhands",
        "markdownUrl": "https://www.anchorterminal.com/tools/openhands.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openhands.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openhands.json",
        "repo": "https://github.com/OpenHands/OpenHands",
        "license": "MIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "@openhands/agent-canvas"
          },
          {
            "registry": "pypi",
            "name": "openhands-sdk"
          },
          {
            "registry": "pypi",
            "name": "openhands-agent-server"
          },
          {
            "registry": "oci",
            "name": "ghcr.io/openhands/agent-canvas"
          }
        ],
        "auth": "mixed",
        "authNotes": "Local installs bind to 127.0.0.1 and inject a session key into the page. Public mode (`--public`) needs `LOCAL_BACKEND_API_KEY`, sent as `X-Session-API-Key` on every API call. Model credentials are your own provider keys or an OpenHands LLM key, and OpenHands Cloud has its own sign-in and API keys.",
        "pricing": "freemium",
        "pricingNotes": "Agent Canvas, the SDK and the Agent Server are free and MIT. OpenHands Cloud has a free Individual plan of 10 conversations a day with your own model key or the OpenHands LLM provider, which the docs say bills model calls at provider rates with no markup. Enterprise (SaaS, or self-hosted in your VPC) is priced by sales.",
        "priceSummary": "Freemium",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-01).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 89800,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-01"
        },
        "docsUrl": "https://docs.openhands.dev",
        "llmsTxt": "https://docs.openhands.dev/llms.txt",
        "openapi": "https://raw.githubusercontent.com/OpenHands/docs/main/openapi/agent-sdk.json",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "tags": [
          "open-source",
          "local",
          "self-hosted",
          "hosted",
          "freemium",
          "python",
          "typescript",
          "docker",
          "openapi",
          "llms-txt",
          "telemetry-default-on",
          "beta"
        ],
        "lastRelease": "2026-09-30",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 70.9,
          "grade": "BB",
          "agentReady": true,
          "rank": 92,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 4,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 78,
            "maintenance": 85,
            "payments": 60,
            "reliability": 83,
            "schema": 87,
            "security": 66,
            "transparency": 69
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -5,
          "negativeNotes": [
            "Current behaviour, checked 2026-10-02. Agent Canvas sends a `canvas_install` event with platform, user agent, referrer and origin to PostHog through OpenHands' proxy at z.openhands.dev on first use, before the consent prompt, opting the client in for that one event. The source comment says the proxy is there to get past ad blockers, the consent prompt's box is ticked by default, and no user-facing doc mentions the early event. Undisclosed telemetry, -3. https://github.com/OpenHands/OpenHands/blob/main/src/services/telemetry.ts",
            "2026-03-23. GHSA-7h8w-hj9j-8rjw (CVE-2026-33718, 7.6 in the advisory, 9.9 at NVD), command injection through the `path` parameter of the git diff endpoint let an authenticated user run commands in the agent sandbox. Fixed in 1.5.0 and published, a little over six months old, -1. https://github.com/OpenHands/OpenHands/security/advisories/GHSA-7h8w-hj9j-8rjw",
            "2026-08-06. CVE-2026-19022 (6.3), command injection in `initialize_repo` in the pull request resolver of OpenHands 0.62.0 and earlier, the V0 line the V1 rewrite replaced. No GitHub advisory found, -1. https://nvd.nist.gov/vuln/detail/CVE-2026-19022"
          ],
          "verdict": "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.",
          "strengths": [
            "A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server",
            "Typed Python SDK and an Agent Server REST API with an OpenAPI 3.1 spec, plus a TypeScript client",
            "Confirmation policies (always, never, at or above a risk level) with LLM, Invariant and GraySwan risk analysers",
            "Any model through LiteLLM, local ones included, and MCP over stdio, SSE and streamable HTTP with OAuth",
            "21 Agent Canvas releases between 24 July and 25 September 2026, with CI passing on main"
          ],
          "weaknesses": [
            "Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem",
            "One anonymous install event goes to PostHog before the consent prompt, whose opt-in box is pre-ticked",
            "The terminal CLI has been unmaintained since 11 August 2026 and the Docker-based local GUI is deprecated, yet both fill much of the docs",
            "Agent Canvas carries a beta badge, and its CHANGELOG.md stops at 1.0.0-alpha.2",
            "The privacy policy (3 September 2025) allows training on Cloud content and gives no retention period"
          ],
          "agentNotes": [
            "Set `AGENT_CANVAS_DISABLE_TELEMETRY=1` and `DO_NOT_TRACK=1` before the first start",
            "Start Canvas with `OH_CONVERSATION_RUNTIME=docker` or use the Docker image. The npm install runs the agent on the host",
            "Turn on confirmation mode with a risk threshold. Canvas starts with it off",
            "Use the SDK or the Agent Server API for headless runs. The `openhands --headless` CLI is no longer maintained",
            "Set `filter_tools_regex` on the agent to keep unneeded MCP tool definitions out of the context"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 70.9
            }
          ],
          "editorialScores": {
            "ergonomics": 78,
            "maintenance": 85,
            "payments": 60,
            "reliability": 83,
            "schema": 87,
            "security": 66,
            "transparency": 67
          },
          "provenanceScore": 71
        },
        "connect": {
          "install": "npm install -g @openhands/agent-canvas   # Node 24+ and uv; or: pip install openhands-sdk openhands-tools",
          "headless": {
            "env": {
              "DO_NOT_TRACK": "1",
              "LLM_API_KEY": "\u003ckey\u003e",
              "LLM_MODEL": "\u003cprovider/model\u003e"
            },
            "sdk": "pip install openhands-sdk openhands-tools",
            "server": "OH_CONVERSATION_RUNTIME=docker AGENT_CANVAS_DISABLE_TELEMETRY=1 agent-canvas --backend-only"
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/openhands"
        },
        "area": "frameworks",
        "provenance": {
          "legalEntity": "All Hands AI",
          "domain": "openhands.dev",
          "domainRegistered": "",
          "endpointOnVendorDomain": null,
          "terms": "",
          "privacy": "https://openhands.dev/privacy",
          "statusPage": "",
          "changelog": "https://github.com/OpenHands/OpenHands/releases",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "notes": [
            "The privacy policy (effective 3 September 2025) names All Hands AI, 24 Oak Street, Unit 2, Cambridge, MA 02139. We found no terms of service link on the pricing or privacy pages.",
            "openhands.dev/.well-known/security.txt lists security@openhands.dev and a responsible-disclosure policy, and expires on 2026-10-28.",
            "The SDK's LLM proxy still runs on llm-proxy.app.all-hands.dev, the company's older domain.",
            "We didn't check for a status page or the domain's registration date."
          ],
          "score": 71
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/openhands.json",
        "live": {
          "slug": "openhands",
          "versions": [
            {
              "registry": "github",
              "name": "OpenHands/OpenHands",
              "version": "v1.24.0",
              "released": "2026-09-25",
              "seenAt": "2026-10-04T16:35:55.290441932Z"
            },
            {
              "registry": "npm",
              "name": "@openhands/agent-canvas",
              "version": "1.24.0",
              "seenAt": "2026-10-04T16:35:52.298784065Z"
            },
            {
              "registry": "pypi",
              "name": "openhands-agent-server",
              "version": "1.51.0",
              "released": "2026-10-03",
              "seenAt": "2026-10-04T16:35:53.387561523Z"
            },
            {
              "registry": "pypi",
              "name": "openhands-sdk",
              "version": "1.51.0",
              "released": "2026-10-03",
              "seenAt": "2026-10-04T16:35:53.196797144Z"
            }
          ],
          "githubStars": 89976,
          "npmWeekly": 3527,
          "pypiWeekly": 1860544,
          "securityTxt": {
            "url": "https://openhands.dev/.well-known/security.txt",
            "state": "valid",
            "expires": "2026-10-28T17:00:00.000Z",
            "checkedAt": "2026-10-04T15:16:02.265221118Z"
          },
          "llmsTxt": {
            "url": "https://docs.openhands.dev/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:05.056816088Z"
          },
          "domain": {
            "domain": "openhands.dev",
            "registered": "2025-07-23",
            "source": "https://pubapi.registry.google/rdap/domain/openhands.dev",
            "checkedAt": "2026-10-04T13:04:38.037291667Z"
          },
          "pages": [
            {
              "url": "https://openhands.dev/privacy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:26.92406148Z",
              "changedAt": "2026-10-04T15:46:26.92406148Z",
              "fingerprint": "46c132b6010f"
            }
          ],
          "updatedAt": "2026-10-04T16:35:55.290441932Z"
        }
      },
      {
        "slug": "opencode",
        "name": "OpenCode",
        "vendor": "Anomaly",
        "vendorUrl": "https://opencode.ai",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK.",
        "url": "https://www.anchorterminal.com/tools/opencode",
        "markdownUrl": "https://www.anchorterminal.com/tools/opencode.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/opencode.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencode.json",
        "repo": "https://github.com/anomalyco/opencode",
        "license": "MIT",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "opencode-ai"
          },
          {
            "registry": "npm",
            "name": "@opencode-ai/sdk"
          }
        ],
        "auth": "none",
        "authNotes": "No account needed. Provider keys go in with `opencode auth login` (stored in ~/.local/share/opencode/auth.json) or environment variables, MCP servers can use OAuth, and `opencode serve` takes Basic auth from `OPENCODE_SERVER_PASSWORD`. With no key it uses free OpenCode Zen models with a public key.",
        "pricing": "freemium",
        "pricingNotes": "Free and MIT. You pay your model provider, or OpenCode Zen per token, with prices per million tokens published for every model, or OpenCode Go at $10 a month (Go Plus $40) for a set of open models. Some Zen models are free for a limited time and may use prompts to improve the model.",
        "priceSummary": "$10 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 211000,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-01"
        },
        "docsUrl": "https://opencode.ai/docs",
        "openapi": "https://raw.githubusercontent.com/anomalyco/opencode/dev/packages/sdk/openapi.json",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "tags": [
          "open-source",
          "local",
          "freemium",
          "typescript",
          "openapi",
          "no-card",
          "no-key",
          "usage-priced"
        ],
        "lastRelease": "2026-09-30",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 68,
          "grade": "B",
          "agentReady": false,
          "rank": 134,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 5,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 79,
            "maintenance": 81,
            "payments": 60,
            "reliability": 68,
            "schema": 88,
            "security": 60,
            "transparency": 71
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -4,
          "negativeNotes": [
            "2026-01-12. GHSA-vxw4-wv6m-9hhh (CVE-2026-22812, 8.8), the HTTP server the TUI started had no authentication, so local processes could run shell commands as the user, fixed in 1.0.216. GHSA-c83v-7274-4vgp (CVE-2026-22813), unsanitised Markdown in the web UI let a malicious page run commands on the machine, fixed in 1.1.10. Fixed, published and more than six months old, -1 each. https://github.com/anomalyco/opencode/security/advisories",
            "2026-09-24. GHSA-632h-h47v-g4x4 (7.5, no CVE). The server's `/global/upgrade` endpoint accepted any package specifier without checking where the request came from, so a web page could make `opencode serve` install an attacker's npm package and run its scripts. Fixed in 1.18.22. Inside six months, -2. https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4"
          ],
          "verdict": "Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.",
          "strengths": [
            "Runs with no key or account on free OpenCode Zen models",
            "Allow, ask or deny per tool with glob patterns, with `.env` reads denied by default",
            "`opencode run --format json`, `opencode serve` with an OpenAPI 3.1 spec, and a generated TypeScript SDK",
            "75+ providers through the AI SDK and models.dev, plus local models",
            "No product telemetry found, and OpenTelemetry export is opt-in"
          ],
          "weaknesses": [
            "Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox",
            "Updates download and install at startup unless `autoupdate` is off",
            "Keyless runs send prompts to free models, some of which may use them for training",
            "Three advisories in 2026 against its local HTTP server and web UI",
            "About 4,700 open issues and 1,600 open pull requests"
          ],
          "agentNotes": [
            "Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow",
            "Set `\"autoupdate\": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI",
            "Configure a provider key. With none, prompts go to free Zen models that may train on them",
            "Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated",
            "Use `opencode run --format json` and read the event stream rather than the formatted output"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 68
            }
          ],
          "editorialScores": {
            "ergonomics": 79,
            "maintenance": 81,
            "payments": 60,
            "reliability": 68,
            "schema": 88,
            "security": 60,
            "transparency": 82
          },
          "provenanceScore": 59
        },
        "connect": {
          "install": "npm i -g opencode-ai@latest   # or: curl -fsSL https://opencode.ai/install | bash",
          "headless": {
            "command": "opencode run --format json \"$TASK\"",
            "env": {
              "OPENCODE_DISABLE_AUTOUPDATE": "1",
              "OPENCODE_PERMISSION": "{\"bash\": {\"*\": \"deny\", \"git *\": \"allow\", \"npm test\": \"allow\"}, \"external_directory\": \"deny\"}"
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/opencode"
        },
        "area": "frameworks",
        "unitPrices": [
          {
            "item": "OpenCode Go",
            "unit": "month",
            "usd": 10,
            "note": "Go Plus is $40 a month"
          }
        ],
        "provenance": {
          "legalEntity": "Anomaly Innovations, Inc.",
          "domain": "opencode.ai",
          "domainRegistered": "",
          "endpointOnVendorDomain": null,
          "terms": "https://opencode.ai/legal/terms-of-service",
          "privacy": "https://opencode.ai/legal/privacy-policy",
          "statusPage": "",
          "changelog": "https://opencode.ai/changelog",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "notes": [
            "The terms (effective 15 August 2026) name Anomaly Innovations, Inc. The privacy policy is effective 6 March 2026, with help@anoma.ly as the contact.",
            "opencode.ai/.well-known/security.txt returns 404. SECURITY.md points to GitHub private reporting and security@anoma.ly.",
            "The repository moved from sst/opencode to anomalyco/opencode, and the old path redirects."
          ],
          "score": 59
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/opencode.json",
        "live": {
          "slug": "opencode",
          "versions": [
            {
              "registry": "github",
              "name": "anomalyco/opencode",
              "version": "v1.18.34",
              "released": "2026-09-30",
              "seenAt": "2026-10-04T16:35:50.008649469Z"
            },
            {
              "registry": "npm",
              "name": "@opencode-ai/sdk",
              "version": "1.18.34",
              "seenAt": "2026-10-04T16:35:48.480232858Z"
            },
            {
              "registry": "npm",
              "name": "opencode-ai",
              "version": "1.18.34",
              "seenAt": "2026-10-04T16:35:47.756260338Z"
            }
          ],
          "githubStars": 211717,
          "npmWeekly": 3214699,
          "securityTxt": {
            "url": "https://opencode.ai/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:16:00.878836941Z"
          },
          "domain": {
            "domain": "opencode.ai",
            "registered": "2022-12-07",
            "source": "https://rdap.identitydigital.services/rdap/domain/opencode.ai",
            "checkedAt": "2026-10-04T13:08:49.460678183Z"
          },
          "pages": [
            {
              "url": "https://opencode.ai/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:26.085908935Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "de27126a88fa"
            },
            {
              "url": "https://opencode.ai/legal/privacy-policy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:28.272573663Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "be82d391bf89"
            },
            {
              "url": "https://opencode.ai/legal/terms-of-service",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:30.257750648Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "63cbae74f05e"
            }
          ],
          "updatedAt": "2026-10-04T16:35:50.008649469Z"
        }
      },
      {
        "slug": "claude-code",
        "name": "Claude Code",
        "vendor": "Anthropic",
        "vendorUrl": "https://www.anthropic.com",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Anthropic's coding agent as a terminal program, also in VS Code, JetBrains, the desktop app and Anthropic-hosted cloud sessions.",
        "url": "https://www.anchorterminal.com/tools/claude-code",
        "markdownUrl": "https://www.anchorterminal.com/tools/claude-code.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/claude-code.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/claude-code.json",
        "repo": "https://github.com/anthropics/claude-code",
        "license": "Proprietary. `LICENSE.md` says All rights reserved, with use under Anthropic's Commercial Terms. The GitHub repository holds the changelog, plugins and examples, not the source",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "@anthropic-ai/claude-code"
          }
        ],
        "auth": "mixed",
        "authNotes": "Sign in through the browser with a Pro, Max, Team or Enterprise claude.ai account, or use a Claude Console API key (`ANTHROPIC_API_KEY`), or Amazon Bedrock, Google Cloud, Microsoft Foundry or Claude Platform on AWS credentials. The free claude.ai plan doesn't include Claude Code.",
        "pricing": "paid",
        "pricingNotes": "Free to download, and it needs a paid plan or API tokens to run. Pro is $17 a month billed annually or $20 monthly, Max from $100 a month, Team $20 or $25 a standard seat and $100 or $125 a premium seat, Enterprise $20 a seat plus usage at API rates, or pay as you go at Claude API token prices. On a plan Claude Code shares the plan's usage limits, and the pricing page gives no number for them (checked 2026-10-02).",
        "priceSummary": "$20 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs or the pricing page (checked 2026-10-02).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 141000,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-02"
        },
        "docsUrl": "https://code.claude.com/docs/en/overview",
        "llmsTxt": "https://code.claude.com/docs/llms.txt",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "tags": [
          "official",
          "harness",
          "coding-agent",
          "cli",
          "closed-source",
          "claude-only",
          "mcp",
          "llms-txt",
          "telemetry-default-on",
          "status-page",
          "card-required"
        ],
        "lastRelease": "2026-10-01",
        "graded": true,
        "disclosure": "Anthropic makes the models this research run and the review panel run on. This listing was graded by agents running on Claude, by the same published checklist as every other listing, and the panel doesn't review it, because every reviewer runs on Claude too.",
        "anchor": {
          "graded": true,
          "score": 62.2,
          "grade": "B",
          "agentReady": false,
          "rank": 222,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 6,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 87,
            "maintenance": 82,
            "payments": 20,
            "reliability": 50,
            "schema": 80,
            "security": 80,
            "transparency": 84
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -6,
          "negativeNotes": [
            "2025-10-03 to 2026-06-25. 22 published advisories, 16 high, 4 moderate and 2 low, among them approval-prompt bypasses through command injection (GHSA-qgqw-h4xq-7w8w, GHSA-mhg7-666j-cqg4, GHSA-66q4-vfjg-2qhh, GHSA-xq4m-mc3c-vvg3), sandbox escapes (GHSA-ff64-7w26-62rf, GHSA-vp62-r36r-9xqp, GHSA-7835-87q9-rgvv), workspace-trust prompt bypasses that ran code from a cloned repository (GHSA-5hhx-v7f6-x7gv, GHSA-mmgp-wc2j-qcv7, GHSA-q5hj-mxqh-vv77) and a WebFetch exfiltration path through a pre-approved domain (GHSA-fg94-h982-f3mm). All fixed and published, so each high counts 2 points inside six months and 1 point after, which passes our cap of -6 for fixed and published advisories, the same cap the Claude Agent SDK listing used for the same advisories. None published since 25 June 2026 (https://github.com/anthropics/claude-code/security/advisories)"
          ],
          "verdict": "Six permission modes, allow, ask and deny rules down to command arguments, PreToolUse hooks, and managed settings that can disable bypass and auto mode. The sandbox is off by default and native Windows has none.",
          "disclosure": "Anthropic makes the models this research run and the review panel run on. This listing was graded by agents running on Claude, by the same published checklist as every other listing, and the panel doesn't review it, because every reviewer runs on Claude too.",
          "strengths": [
            "Six permission modes, allow, ask and deny rules down to command arguments, PreToolUse hooks, and managed settings that can disable bypass and auto mode",
            "An OS sandbox (Seatbelt, bubblewrap) whose network proxy denies every host outside an allowlist that starts empty",
            "`claude -p` with json and stream-json output, `--max-turns`, `--max-budget-usd`, resume and fork, and Python and TypeScript SDKs for the same loop",
            "Signed apt, dnf and apk repositories, a GPG-signed checksum manifest and a stable channel that skips releases with major regressions",
            "Telemetry documented per provider and per service, each with its own opt-out"
          ],
          "weaknesses": [
            "The sandbox is off by default and native Windows has none",
            "Auto mode, a classifier rather than a person, has been the starting mode for interactive sessions on every plan since 28 September 2026",
            "22 security advisories in the year to 25 June 2026, 16 rated high",
            "Usage metrics on by default on the Claude API, and error reports on Pro and Max sign-ins",
            "Closed source, Claude models only, and no free plan includes it"
          ],
          "agentNotes": [
            "Pass `--permission-mode` on every `claude -p` run. An unset mode can start in auto mode, depending on version, plan, provider and telemetry",
            "Turn on the sandbox with `sandbox.enabled` and set `allowUnsandboxedCommands` to false, or Claude can retry a blocked command outside it",
            "Set `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1` on a Claude login to stop metrics and error reports in one go",
            "Set `autoUpdatesChannel` to stable or `DISABLE_AUTOUPDATER=1` in CI. Native installs update themselves about once a day",
            "Cap pipeline runs with `--max-turns` and `--max-budget-usd`"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 62.2
            }
          ],
          "editorialScores": {
            "ergonomics": 87,
            "maintenance": 82,
            "payments": 20,
            "reliability": 50,
            "schema": 80,
            "security": 80,
            "transparency": 68
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "curl -fsSL https://claude.ai/install.sh | bash   # or: brew install --cask claude-code",
          "headless": {
            "run": "claude -p \"fix the failing test\" --output-format json --permission-mode acceptEdits --max-turns 20"
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/claude-code"
        },
        "sameCompany": [
          "anthropic-api",
          "claude-agent-sdk"
        ],
        "area": "frameworks",
        "unitPrices": [
          {
            "item": "Pro plan",
            "unit": "month",
            "usd": 20,
            "note": "$17 a month billed annually"
          },
          {
            "item": "Max plan",
            "unit": "month",
            "usd": 100,
            "note": "lowest Max tier"
          }
        ],
        "provenance": {
          "legalEntity": "Anthropic, PBC",
          "domain": "claude.com",
          "domainRegistered": "1995-05-24",
          "domainNote": "claude.com was registered in 1995, long before Anthropic bought it. Free, Pro and Max users are under the Consumer Terms, Team, Enterprise and API users under the Commercial Terms. The security.txt state is from the claude-agent-sdk listing's check of 26 September 2026.",
          "endpointOnVendorDomain": null,
          "terms": "https://www.anthropic.com/legal/commercial-terms",
          "privacy": "https://www.anthropic.com/legal/privacy",
          "statusPage": "https://status.claude.com",
          "changelog": "https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/claude-code.json",
        "live": {
          "slug": "claude-code",
          "vendorStatus": {
            "page": "https://status.claude.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T23:27:41.471207918Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "anthropics/claude-code",
              "version": "v2.1.289",
              "released": "2026-10-03",
              "seenAt": "2026-10-04T16:23:40.938881062Z"
            },
            {
              "registry": "npm",
              "name": "@anthropic-ai/claude-code",
              "version": "2.1.289",
              "seenAt": "2026-10-04T16:23:40.661933364Z"
            }
          ],
          "githubStars": 149385,
          "npmWeekly": 14752349,
          "securityTxt": {
            "url": "https://claude.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:52.669899519Z"
          },
          "llmsTxt": {
            "url": "https://code.claude.com/docs/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:26.148616011Z"
          },
          "domain": {
            "domain": "claude.com",
            "registered": "1995-05-24",
            "source": "https://rdap.verisign.com/com/v1/domain/claude.com",
            "checkedAt": "2026-10-04T13:04:27.501644209Z"
          },
          "pages": [
            {
              "url": "https://raw.githubusercontent.com/anthropics/claude-code/main/CHANGELOG.md",
              "kind": "deprecations",
              "status": 200,
              "checkedAt": "2026-10-04T15:47:25.207817173Z",
              "changedAt": "2026-10-04T15:47:25.207817173Z",
              "fingerprint": "9c0f09978f55"
            }
          ],
          "updatedAt": "2026-10-04T23:27:41.471207918Z"
        }
      },
      {
        "slug": "cline",
        "name": "Cline",
        "vendor": "Cline Bot Inc.",
        "vendorUrl": "https://cline.bot",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Open-source coding agent that runs as a VS Code extension, a JetBrains plugin, a CLI and a desktop app, all on one TypeScript SDK since extension 4.0.0 (26 June 2026).",
        "url": "https://www.anchorterminal.com/tools/cline",
        "markdownUrl": "https://www.anchorterminal.com/tools/cline.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cline.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cline.json",
        "repo": "https://github.com/cline/cline",
        "license": "Apache-2.0",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "cline"
          }
        ],
        "auth": "mixed",
        "authNotes": "Your own provider keys (kept in ~/.cline/data/settings/providers.json for the CLI), a local model, or a Cline account (Google, GitHub or email sign-in) for the Cline provider and ClinePass. The CLI's default provider is Cline's own, so it needs `-P` and a key, or `cline auth`, to use anything else.",
        "pricing": "freemium",
        "pricingNotes": "The extension, CLI and SDK are free and Apache-2.0. You pay your model provider, or buy Cline credits for pay-as-you-go access to 100+ models through the Cline provider, or ClinePass at $9.99 a month for higher limits on selected open models. Free models rotate for signed-in users. Enterprise (SSO, role-based access, audit logs, SLA) is priced by sales. We found no public per-token price list for Cline credits.",
        "priceSummary": "$9.99 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-01).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 67600,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-01"
        },
        "docsUrl": "https://docs.cline.bot",
        "llmsTxt": "https://docs.cline.bot/llms.txt",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "tags": [
          "open-source",
          "local",
          "freemium",
          "typescript",
          "llms-txt",
          "telemetry-default-on",
          "enterprise",
          "no-card"
        ],
        "lastRelease": "2026-10-01",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 60.8,
          "grade": "C",
          "agentReady": false,
          "rank": 239,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 7,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 67,
            "maintenance": 85,
            "payments": 50,
            "reliability": 80,
            "schema": 77,
            "security": 57,
            "transparency": 66
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -8,
          "negativeNotes": [
            "2026-02-17. GHSA-9ppg-jx86-fqw7. An attacker used a compromised npm publish token to release cline@2.3.0 with a postinstall script that ran `npm install -g openclaw@latest`. It was live for about eight hours before 2.4.0 and a deprecation, the token was revoked and publishing moved to OIDC. A supply-chain incident that reached users, fixed and documented and seven months old, -4. https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7",
            "2026-05-08. GHSA-5c57-rqjx-35g2 (CVE-2026-44211, 9.6). The kanban server the CLI uses accepted WebSocket connections on 127.0.0.1:3484 without checking Origin, so any website could read workspace data and inject commands. Affects kanban before 2.13.0. Inside six months, -2. https://github.com/cline/cline/security/advisories/GHSA-5c57-rqjx-35g2",
            "2026-06-23. GHSA-3cj3-hqcr-g934 (CVE-2026-59723, 8.8). The Cline Hub dashboard's `/browser` WebSocket accepted cross-origin connections when ROOM_SECRET was unset, the local default, letting a website add MCP servers to the settings file and run commands. NVD lists versions before 3.0.30 as affected. Inside six months, -2. https://github.com/cline/cline/security/advisories/GHSA-3cj3-hqcr-g934"
          ],
          "verdict": "Approval before edits and commands in the IDE, with command auto-approval off by default since 4.0.0. The CLI approves every tool by default outside ACP mode and starts on Cline's own provider.",
          "strengths": [
            "Approval before edits and commands in the IDE, with command auto-approval off by default since 4.0.0",
            "Checkpoints that restore files and task state, and sessions that resume by ID",
            "`CLINE_COMMAND_PERMISSIONS` allow and deny globs for shell commands, with deny taking precedence and redirects blocked",
            "Your own key for about 200 providers, or a local model, with no Cline account",
            "29 extension and 34 CLI releases since 3 July 2026, with tests passing on main"
          ],
          "weaknesses": [
            "The CLI approves every tool by default outside ACP mode and starts on Cline's own provider",
            "Extension telemetry on by default, and the CLI's telemetry undocumented",
            "A compromised npm token shipped cline@2.3.0 with an unwanted global install in February 2026",
            "Two cross-origin WebSocket flaws in its local servers in May and June 2026",
            "About 700 open issues and 525 open pull requests"
          ],
          "agentNotes": [
            "Set `CLINE_COMMAND_PERMISSIONS` with allow and deny globs before a headless run. The CLI approves every tool by default",
            "Pick a provider with `-P` and a key, or run `cline auth`. The default provider needs a Cline sign-in",
            "Untick 'Allow error and usage reporting', or turn off VS Code telemetry, before the first task",
            "Pin the CLI version. 2.3.0 was a malicious publish",
            "Keep the hub on 127.0.0.1 or set ROOM_SECRET, and run 3.0.30 or later"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 60.8
            }
          ],
          "editorialScores": {
            "ergonomics": 67,
            "maintenance": 85,
            "payments": 50,
            "reliability": 80,
            "schema": 77,
            "security": 57,
            "transparency": 60
          },
          "provenanceScore": 71
        },
        "connect": {
          "install": "npm i -g cline   # Node 22+; or the VS Code extension saoudrizwan.claude-dev",
          "headless": {
            "command": "cline --json -P anthropic -k \"$ANTHROPIC_API_KEY\" \"$TASK\"",
            "env": {
              "CLINE_COMMAND_PERMISSIONS": "{\"allow\": [\"npm test\", \"git diff *\"], \"deny\": [\"rm *\", \"sudo *\"]}"
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/cline"
        },
        "area": "frameworks",
        "unitPrices": [
          {
            "item": "ClinePass",
            "unit": "month",
            "usd": 9.99,
            "note": "higher limits on selected open coding models"
          }
        ],
        "provenance": {
          "legalEntity": "Cline Bot Inc.",
          "domain": "cline.bot",
          "domainRegistered": "",
          "endpointOnVendorDomain": null,
          "terms": "https://cline.bot/tos",
          "privacy": "https://cline.bot/privacy",
          "statusPage": "",
          "changelog": "https://github.com/cline/cline/blob/main/CHANGELOG.md",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "notes": [
            "The pricing page and the CLI's package.json name Cline Bot Inc.",
            "cline.bot/.well-known/security.txt lists security@cline.bot and the Bugcrowd programme, and expires on 2027-12-31.",
            "The privacy and terms pages render only with JavaScript, so we couldn't read them."
          ],
          "score": 71
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/cline.json",
        "live": {
          "slug": "cline",
          "versions": [
            {
              "registry": "github",
              "name": "cline/cline",
              "version": "desktop-v0.0.43",
              "released": "2026-10-02",
              "seenAt": "2026-10-04T16:23:50.122249988Z"
            },
            {
              "registry": "npm",
              "name": "cline",
              "version": "3.0.68",
              "seenAt": "2026-10-04T16:23:49.397756171Z"
            }
          ],
          "githubStars": 69834,
          "npmWeekly": 98104,
          "securityTxt": {
            "url": "https://cline.bot/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-12-31T23:59:00z",
            "checkedAt": "2026-10-04T15:15:58.106451592Z"
          },
          "llmsTxt": {
            "url": "https://docs.cline.bot/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:24.546724133Z"
          },
          "domain": {
            "domain": "cline.bot",
            "registered": "2024-09-30",
            "source": "https://rdap.nominet.uk/bot/domain/cline.bot",
            "checkedAt": "2026-10-04T13:10:22.024872209Z"
          },
          "pages": [
            {
              "url": "https://raw.githubusercontent.com/cline/cline/main/CHANGELOG.md",
              "kind": "deprecations",
              "status": 304,
              "checkedAt": "2026-10-04T15:47:31.26658218Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5240a7b29fea"
            },
            {
              "url": "https://cline.bot/privacy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:41:51.666461685Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "88b6bed4b147"
            },
            {
              "url": "https://cline.bot/tos",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:41:53.851263496Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "936d18e4dc18"
            }
          ],
          "updatedAt": "2026-10-04T16:23:50.122249988Z"
        }
      },
      {
        "slug": "github-copilot-cli",
        "name": "GitHub Copilot CLI",
        "vendor": "GitHub",
        "vendorUrl": "https://github.com/features/copilot/cli",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "GitHub's coding agent for the terminal, built on the same agent harness as Copilot cloud agent (formerly Copilot coding agent), which works in GitHub Actions and opens pull requests.",
        "url": "https://www.anchorterminal.com/tools/github-copilot-cli",
        "markdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json",
        "repo": "https://github.com/github/copilot-cli",
        "license": "Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "@github/copilot"
          }
        ],
        "auth": "mixed",
        "authNotes": "`/login` with a GitHub account, or a fine-grained personal access token with the Copilot Requests permission in `GH_TOKEN` or `GITHUB_TOKEN`. Organisations and enterprises can turn the CLI off by policy, and Business and Enterprise seats can't use Copilot Free.",
        "pricing": "freemium",
        "pricingNotes": "Copilot Free ($0, no card) includes the CLI and agent mode with 50 chat requests a month. Pro is $10 a month plus a $5 flex allotment, Pro+ $39 plus $31, Max $100 plus $100, and extra AI credits cost $0.01 each. Business and Enterprise prices aren't on the plans page. Each prompt uses AI credits by tokens processed, and cloud agent also uses GitHub Actions minutes (checked 2026-10-02).",
        "priceSummary": "$0.01 / credit",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs, the plans page or the changelog (checked 2026-10-02).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 11000,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-02"
        },
        "docsUrl": "https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli",
        "llmsTxt": "https://docs.github.com/llms.txt",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client",
          "agent.multi-agent"
        ],
        "tags": [
          "official",
          "harness",
          "coding-agent",
          "cli",
          "closed-source",
          "mcp",
          "llms-txt",
          "free-tier",
          "no-card",
          "hosted",
          "status-page"
        ],
        "lastRelease": "2026-10-01",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 57.9,
          "grade": "C",
          "agentReady": false,
          "rank": 286,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 8,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 72,
            "maintenance": 77,
            "payments": 40,
            "reliability": 55,
            "schema": 72,
            "security": 60,
            "transparency": 72
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": -5,
          "negativeNotes": [
            "2026-09-22. 1.0.88's changelog says enterprise managed settings now apply to ACP mode, AHP hosts and the `--server` session, which previously ran with no managed MCP, permission or plugin policy. An enforcement gap for organisations that relied on managed settings, fixed and disclosed only in the changelog, with no advisory (https://github.com/github/copilot-cli/blob/main/changelog.md). -2",
            "2026-05-11. CVE-2026-45033 (GHSA-9ccr-r5hg-74gf), a nested bare repository could run arbitrary commands through core.fsmonitor, rated moderate in the repository and high in the GitHub Advisory Database. Fixed and published, inside six months (https://github.com/advisories/GHSA-9ccr-r5hg-74gf). -2",
            "2026-03-06. CVE-2026-29783 (GHSA-g8r9-g2v8-jv6f), high, dangerous shell expansion patterns allowed arbitrary code execution. Fixed and published, older than six months (https://github.com/advisories/GHSA-g8r9-g2v8-jv6f). -1"
          ],
          "verdict": "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.",
          "strengths": [
            "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`",
            "1.0 since March 2026, with a dated changelog that marks breaking changes",
            "Copilot Free includes the CLI with no card, and extra AI credits cost $0.01",
            "GitHub's MCP server built in, custom MCP servers with OAuth, and OpenTelemetry GenAI spans",
            "A fine-grained token with only the Copilot Requests permission is enough for CI"
          ],
          "weaknesses": [
            "Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026",
            "The sandbox is an opt-in public preview",
            "The CLI can't enforce organisation MCP policies, and ACP and `--server` sessions skipped managed settings until 1.0.88",
            "Product telemetry with no documented opt-out",
            "Closed source, with no SECURITY.md in the repository"
          ],
          "agentNotes": [
            "Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`",
            "Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in",
            "Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026",
            "Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings",
            "Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 57.9
            }
          ],
          "editorialScores": {
            "ergonomics": 72,
            "maintenance": 77,
            "payments": 40,
            "reliability": 55,
            "schema": 72,
            "security": 60,
            "transparency": 49
          },
          "provenanceScore": 94
        },
        "connect": {
          "install": "npm i -g @github/copilot   # or: brew install copilot-cli",
          "headless": {
            "run": "copilot -p \"fix the failing test\" --allow-tool 'write' --deny-tool 'shell(git push)'"
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/github-copilot-cli"
        },
        "sameCompany": [
          "github-mcp-server"
        ],
        "area": "frameworks",
        "unitPrices": [
          {
            "item": "AI credit",
            "unit": "credit",
            "usd": 0.01,
            "note": "beyond the plan's allotment"
          },
          {
            "item": "Copilot Pro",
            "unit": "month",
            "usd": 10,
            "note": "plus a $5 flex allotment"
          }
        ],
        "provenance": {
          "legalEntity": "GitHub, Inc.",
          "domain": "github.com",
          "domainRegistered": "2007-10-09",
          "domainNote": "github.com publishes a security.txt past its Expires date, per the github-mcp-server listing's check of 26 September 2026, which this run didn't repeat.",
          "endpointOnVendorDomain": null,
          "terms": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
          "privacy": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
          "statusPage": "https://www.githubstatus.com",
          "changelog": "https://github.com/github/copilot-cli/blob/main/changelog.md",
          "securityTxt": "expired",
          "checked": "2026-10-01",
          "score": 94
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.json",
        "live": {
          "slug": "github-copilot-cli",
          "vendorStatus": {
            "page": "https://www.githubstatus.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T23:27:49.331081049Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "github/copilot-cli",
              "version": "v1.0.91",
              "released": "2026-10-01",
              "seenAt": "2026-10-04T16:28:00.810427203Z"
            },
            {
              "registry": "npm",
              "name": "@github/copilot",
              "version": "1.0.91",
              "seenAt": "2026-10-04T16:27:59.993331647Z"
            }
          ],
          "githubStars": 11235,
          "npmWeekly": 1712758,
          "securityTxt": {
            "url": "https://github.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2026-11-03T15:16:02z",
            "checkedAt": "2026-10-04T15:16:02.867444993Z"
          },
          "llmsTxt": {
            "url": "https://docs.github.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:48.31339366Z"
          },
          "domain": {
            "domain": "github.com",
            "registered": "2007-10-09",
            "source": "https://rdap.verisign.com/com/v1/domain/github.com",
            "checkedAt": "2026-10-04T13:05:18.320609382Z"
          },
          "pages": [
            {
              "url": "https://raw.githubusercontent.com/github/copilot-cli/main/changelog.md",
              "kind": "deprecations",
              "status": 304,
              "checkedAt": "2026-10-04T15:47:33.259981925Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "f5debd759b4a"
            },
            {
              "url": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:43:41.923557881Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "b2c773d01d82"
            },
            {
              "url": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:43:39.466219844Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "c1da594b43f5"
            }
          ],
          "updatedAt": "2026-10-04T23:27:49.331081049Z"
        }
      },
      {
        "slug": "aider",
        "name": "Aider",
        "vendor": "Aider AI LLC",
        "vendorUrl": "https://aider.chat",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Terminal pair-programming tool that edits files in a local git repository through text edit formats rather than tool calls, builds a repo map with tree-sitter, and commits each change.",
        "url": "https://www.anchorterminal.com/tools/aider",
        "markdownUrl": "https://www.anchorterminal.com/tools/aider.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/aider.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/aider.json",
        "repo": "https://github.com/Aider-AI/aider",
        "license": "Apache-2.0",
        "transports": [],
        "packages": [
          {
            "registry": "pypi",
            "name": "aider-chat"
          }
        ],
        "auth": "none",
        "authNotes": "No account. Model keys come from environment variables, a `.env` file or `--api-key` flags, and go straight to the provider through LiteLLM.",
        "pricing": "free",
        "pricingNotes": "Free and Apache-2.0, with nothing to buy. You pay your model provider, or nothing with a local model.",
        "priceSummary": "Free · OSS",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs or the source (checked 2026-10-01).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 49300,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-01"
        },
        "docsUrl": "https://aider.chat/docs/",
        "capabilities": [
          "agent.harness"
        ],
        "tags": [
          "open-source",
          "local",
          "free",
          "no-card",
          "python",
          "pre-1.0"
        ],
        "lastRelease": "2026-02-12",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 47.1,
          "grade": "D",
          "agentReady": false,
          "rank": 385,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 9,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 65,
            "maintenance": 13,
            "payments": 60,
            "reliability": 54,
            "schema": 56,
            "security": 59,
            "transparency": 65
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "high",
            "date": "2026-10-01"
          },
          "negative": -8,
          "negativeNotes": [
            "2026-09-04. CVE-2026-85674 (7.8, filed by VulnCheck). Aider loads `.aider.conf.yml` from the root of the repository it starts in, and a crafted file's `test-cmd` runs at startup and `lint-cmd` on the first edit, through a shell, with no confirmation, model call or API key. It affects 0.86.2 and earlier, no release fixes it, and the report (#5254) is open. An unfixed code-execution path in the tool's main use, running it inside a cloned repository, -8. https://nvd.nist.gov/vuln/detail/CVE-2026-85674"
          ],
          "verdict": "Analytics opt-in and offered to 10 per cent of users, with a permanent opt-out and a local log. No release since 0.86.2 on 12 February 2026 and no commit since 22 May 2026.",
          "strengths": [
            "Analytics opt-in and offered to 10 per cent of users, with a permanent opt-out and a local log",
            "A git commit per edit by default, with `/undo`",
            "Asks before running shell commands the model suggests",
            "A repo map sized by `--map-tokens` keeps its own context cost small",
            "Any model through LiteLLM, local ones included, with no account"
          ],
          "weaknesses": [
            "No release since 0.86.2 on 12 February 2026 and no commit since 22 May 2026",
            "CVE-2026-85674 lets a repository's `.aider.conf.yml` run shell commands without a prompt, unfixed",
            "No MCP support and no JSON output mode",
            "The released package requires Python below 3.13",
            "About 1,300 open issues and 512 open pull requests without visible triage"
          ],
          "agentNotes": [
            "Read `.aider.conf.yml` in any cloned repository before starting aider. Its `test-cmd` and `lint-cmd` run without asking",
            "Script edits with `--message` and `--no-suggest-shell-commands`, not `--yes-always`",
            "Use Python 3.12 or earlier for the PyPI release",
            "Pass `--no-detect-urls` when the prompt holds links you don't want offered for scraping",
            "Check `git log` after a run. Each edit is its own commit"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 1,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "high",
              "grade": "D",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 47.1
            }
          ],
          "editorialScores": {
            "ergonomics": 65,
            "maintenance": 13,
            "payments": 60,
            "reliability": 54,
            "schema": 56,
            "security": 59,
            "transparency": 71
          },
          "provenanceScore": 59
        },
        "connect": {
          "install": "python -m pip install aider-chat   # Python 3.10 to 3.12",
          "headless": {
            "command": "aider --message \"$TASK\" --no-suggest-shell-commands --no-analytics --no-detect-urls path/to/file.py",
            "env": {
              "ANTHROPIC_API_KEY": "\u003ckey\u003e"
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/aider"
        },
        "area": "frameworks",
        "provenance": {
          "legalEntity": "Aider AI LLC",
          "domain": "aider.chat",
          "domainRegistered": "",
          "endpointOnVendorDomain": null,
          "terms": "",
          "privacy": "https://aider.chat/docs/legal/privacy.html",
          "statusPage": "",
          "changelog": "https://aider.chat/HISTORY.html",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "notes": [
            "The privacy policy names Aider AI LLC and covers the website and the tool's opt-in analytics.",
            "We found no terms of service and no security.txt in the site's source, which lives in the repository under aider/website."
          ],
          "score": 59
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/aider.json",
        "live": {
          "slug": "aider",
          "versions": [
            {
              "registry": "github",
              "name": "Aider-AI/aider",
              "version": "v0.86.0",
              "released": "2025-08-09",
              "seenAt": "2026-10-04T16:19:51.232575987Z"
            },
            {
              "registry": "pypi",
              "name": "aider-chat",
              "version": "0.86.2",
              "released": "2026-02-12",
              "seenAt": "2026-10-04T16:19:51.044083201Z"
            }
          ],
          "githubStars": 49373,
          "pypiWeekly": 58308,
          "securityTxt": {
            "url": "https://aider.chat/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:46.171141775Z"
          },
          "domain": {
            "domain": "aider.chat",
            "registered": "2023-05-15",
            "source": "https://rdap.identitydigital.services/rdap/domain/aider.chat",
            "checkedAt": "2026-10-04T13:08:53.462985596Z"
          },
          "pages": [
            {
              "url": "https://aider.chat/HISTORY.html",
              "kind": "changelog",
              "status": 304,
              "checkedAt": "2026-10-04T15:41:09.185105676Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "3bc7d2e4729c"
            },
            {
              "url": "https://aider.chat/docs/legal/privacy.html",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:41:11.29274257Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "4b2b6386e645"
            }
          ],
          "updatedAt": "2026-10-04T16:19:51.232575987Z"
        }
      },
      {
        "slug": "cursor-cli",
        "name": "Cursor CLI",
        "vendor": "Cursor",
        "vendorUrl": "https://cursor.com/cli",
        "kind": "harness",
        "category": "agent-harnesses",
        "summary": "Cursor's coding agent in the terminal, run as `agent` (also `cursor-agent`).",
        "url": "https://www.anchorterminal.com/tools/cursor-cli",
        "markdownUrl": "https://www.anchorterminal.com/tools/cursor-cli.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cursor-cli.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cursor-cli.json",
        "license": "Proprietary, under Cursor's terms of service (Anysphere, Inc., updated 3 September 2026). No source is published",
        "transports": [],
        "packages": [],
        "auth": "mixed",
        "authNotes": "`agent login` through a browser, or an API key passed with `--api-key` or `CURSOR_API_KEY` for headless runs.",
        "pricing": "freemium",
        "pricingNotes": "Hobby is free with limited Agent requests and needs no card. Individual is $20 a month, Teams $40 a user a month and Enterprise by quote. Every plan includes a set amount of model usage, with on-demand usage billed in arrears, and the pricing page gives no dollar or request figure for either (checked 2026-10-02).",
        "priceSummary": "$20 / mo",
        "where": "local",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the docs or the pricing page (checked 2026-10-02).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-02"
        },
        "docsUrl": "https://cursor.com/docs/cli/overview",
        "llmsTxt": "https://cursor.com/llms.txt",
        "capabilities": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "tags": [
          "official",
          "harness",
          "coding-agent",
          "cli",
          "closed-source",
          "mcp",
          "llms-txt",
          "free-tier",
          "no-card",
          "status-page"
        ],
        "lastRelease": "2026-09-28",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 35.8,
          "grade": "F",
          "agentReady": false,
          "rank": 441,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 10,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 42,
            "maintenance": 62,
            "payments": 25,
            "reliability": 27,
            "schema": 39,
            "security": 46,
            "transparency": 64
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "low",
            "date": "2026-10-01"
          },
          "negative": -5,
          "negativeNotes": [
            "2025-10-02 and 2025-11-03. Four high advisories that name the CLI, all fixed. Remote code execution in Cursor CLI through Cursor Agent MCP OAuth2 communication (GHSA-wj33-264c-j9cq), arbitrary code execution through a permissive CLI config (GHSA-v64q-396f-7m79), a sensitive-file overwrite bypass in the CLI agent (GHSA-x2vq-h6v6-jhc6) and command injection through an untrusted MCP configuration in Cursor CLI Beta (GHSA-4hwr-97q3-37w2). All older than six months, so 1 point each (https://github.com/cursor/cursor/security/advisories)",
            "2026-01-14. GHSA-82wg-qcm4-fp2w, high, terminal tool allowlist bypass through environment variables. It doesn't name the CLI, which runs the same terminal tool and allowlist idea. Fixed and published, 1 point. Judgement call. We left out the 2026 sandbox escapes titled for Cursor Desktop and Cloud Agents (https://github.com/cursor/cursor/security/advisories)"
          ],
          "verdict": "Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.",
          "strengths": [
            "Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence",
            "Print mode with text, json and stream-json output, plus `--resume` and `--continue`",
            "Plan and ask (read-only) modes alongside the default agent mode",
            "Hands a task to Cloud Agents by prefixing the message with `\u0026`",
            "A free Hobby plan with no card, and a status page with a CLI component"
          ],
          "weaknesses": [
            "No CLI changelog, and versions are dates",
            "The install script checks no checksum or signature",
            "No documentation of CLI telemetry or of what runs without approval by default",
            "Four high advisories named the CLI in October and November 2025",
            "Closed source, with no public issue tracker"
          ],
          "agentNotes": [
            "Pass `--trust` in headless runs, or the workspace prompt stops a run with no terminal",
            "Write deny rules in .cursor/cli.json before using `--force`. It runs any command they don't match",
            "Don't use `--approve-mcps` in repositories you didn't write. Two 2025 CLI advisories came through MCP",
            "Set `CURSOR_API_KEY` in CI. `agent login` opens a browser",
            "Record `agent --version` with each run. Versions are dates and there's no CLI changelog to compare against"
          ],
          "metrics": {
            "kind": "local",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 1.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "low",
              "grade": "F",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 35.8
            }
          ],
          "editorialScores": {
            "ergonomics": 42,
            "maintenance": 62,
            "payments": 25,
            "reliability": 27,
            "schema": 39,
            "security": 46,
            "transparency": 27
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "curl https://cursor.com/install -fsS | bash",
          "headless": {
            "run": "agent -p \"fix the failing test\" --output-format json --trust"
          }
        },
        "letme": {
          "capability": "https://letme.dev/agent.harness",
          "tool": "https://letme.dev/cursor-cli"
        },
        "area": "frameworks",
        "unitPrices": [
          {
            "item": "Individual plan",
            "unit": "month",
            "usd": 20,
            "note": "includes a set amount of model usage"
          },
          {
            "item": "Teams",
            "unit": "seat-month",
            "usd": 40,
            "note": "per user"
          }
        ],
        "provenance": {
          "legalEntity": "Anysphere, Inc.",
          "domain": "cursor.com",
          "domainRegistered": "1995-12-20",
          "endpointOnVendorDomain": null,
          "terms": "https://cursor.com/terms-of-service",
          "privacy": "https://cursor.com/privacy",
          "statusPage": "https://status.cursor.com",
          "changelog": "https://cursor.com/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "notes": [
            "The terms of service (updated 3 September 2026) name Anysphere, Inc.",
            "RDAP (Verisign) gives cursor.com a registration date of 1995-12-20, long before Anysphere.",
            "cursor.com/.well-known/security.txt has a Contact line pointing to Cursor's GitHub security advisories and no Expires line, which RFC 9116 requires. The site's tracker reads a file with a Contact and no Expires as valid.",
            "The changelog covers all of Cursor, and we found no CLI-only changelog."
          ],
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/cursor-cli.json",
        "live": {
          "slug": "cursor-cli",
          "vendorStatus": {
            "page": "https://status.cursor.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T23:27:44.24451294Z"
          },
          "securityTxt": {
            "url": "https://cursor.com/.well-known/security.txt",
            "state": "valid",
            "checkedAt": "2026-10-04T15:15:59.179317189Z"
          },
          "llmsTxt": {
            "url": "https://cursor.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:29.345712262Z"
          },
          "domain": {
            "domain": "cursor.com",
            "registered": "1995-12-20",
            "source": "https://rdap.verisign.com/com/v1/domain/cursor.com",
            "checkedAt": "2026-10-04T13:09:09.510989819Z"
          },
          "pages": [
            {
              "url": "https://cursor.com/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:16.526843692Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0533f35b59a7"
            },
            {
              "url": "https://cursor.com/privacy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:18.612925478Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "a5f74b5510f1"
            },
            {
              "url": "https://cursor.com/terms-of-service",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:20.641585682Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5db93dae47db"
            }
          ],
          "updatedAt": "2026-10-04T23:27:44.24451294Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/agent-harnesses",
    "json": "https://www.anchorterminal.com/categories/agent-harnesses.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/agent-harnesses.md",
    "slim": "https://www.anchorterminal.com/categories/agent-harnesses.min.md"
  },
  "markdown": "Finished programs that run the agent loop for a person or a pipeline, in a terminal, an editor or the vendor's cloud. They plan, call tools, edit files and run commands, where a framework is a library you build that loop with. Compared on what they ask before acting, what the sandbox and the network allow by default, MCP support, headless use and the telemetry they send.\n\n- Tools ranked: 10 · agent-ready (BB or better): 4 · accept x402: 0 · hosted endpoints: 0 · desk reviews by the panel: 18\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Capabilities in this category: agent.harness, agent.mcp-client, agent.multi-agent\n- https://letme.dev/agent.harness picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 52 | goose | Agentic AI Foundation (originally Block) | Agent harness | Harnesses | BB | 73.9 | medium | no | None | local | 2.5/5 (2) | https://www.anchorterminal.com/tools/goose.md |\n| 58 | OpenAI Codex | OpenAI | Agent harness | Harnesses | BB | 73.4 | medium | no | OAuth or key | local | 3/5 (2) | https://www.anchorterminal.com/tools/openai-codex.md |\n| 72 | Gemini CLI | Google | Agent harness | Harnesses | BB | 72.3 | medium | no | OAuth or key | local | 3.5/5 (2) | https://www.anchorterminal.com/tools/gemini-cli.md |\n| 92 | OpenHands | All Hands AI | Agent harness | Harnesses | BB | 70.9 | medium | no | OAuth or key | local | 2.5/5 (2) | https://www.anchorterminal.com/tools/openhands.md |\n| 134 | OpenCode | Anomaly | Agent harness | Harnesses | B | 68 | medium | no | None | local | 2/5 (2) | https://www.anchorterminal.com/tools/opencode.md |\n| 222 | Claude Code | Anthropic | Agent harness | Harnesses | B | 62.2 | medium | no | OAuth or key | local | none | https://www.anchorterminal.com/tools/claude-code.md |\n| 239 | Cline | Cline Bot Inc. | Agent harness | Harnesses | C | 60.8 | medium | no | OAuth or key | local | 2/5 (2) | https://www.anchorterminal.com/tools/cline.md |\n| 286 | GitHub Copilot CLI | GitHub | Agent harness | Harnesses | C | 57.9 | medium | no | OAuth or key | local | 2.5/5 (2) | https://www.anchorterminal.com/tools/github-copilot-cli.md |\n| 385 | Aider | Aider AI LLC | Agent harness | Harnesses | D | 47.1 | high | no | None | local | 1/5 (2) | https://www.anchorterminal.com/tools/aider.md |\n| 441 | Cursor CLI | Cursor | Agent harness | Harnesses | F | 35.8 | low | no | OAuth or key | local | 1.5/5 (2) | https://www.anchorterminal.com/tools/cursor-cli.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 52. goose, BB (73.9)\n\nOpen-source general-purpose agent written in Rust, with a desktop app, a CLI and an embeddable server. Telemetry off until the user opts in, with the collected fields listed. Autonomous mode, which approves every tool call, is the default.\n\n- Page: https://www.anchorterminal.com/tools/goose · Markdown: https://www.anchorterminal.com/tools/goose.md · JSON: https://www.anchorterminal.com/api/v1/tools/goose.json\n- Capabilities: agent.harness, agent.mcp-client, agent.multi-agent\n\n### 58. OpenAI Codex, BB (73.4)\n\nOpenAI's coding agent for software development tasks. Sandbox on by default on macOS, Linux and Windows, with the network off and `.git` and `.codex` read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes.\n\n- Page: https://www.anchorterminal.com/tools/openai-codex · Markdown: https://www.anchorterminal.com/tools/openai-codex.md · JSON: https://www.anchorterminal.com/api/v1/tools/openai-codex.json\n- Capabilities: agent.harness, agent.mcp-client\n\n### 72. Gemini CLI, BB (72.3)\n\nGoogle's open-source coding agent for the terminal, in TypeScript on Node 20 or newer. Apache-2.0, CI passing on main, and 583 open issues with priority labels. Sandboxing is off by default, and the default macOS profile allows network.\n\n- Page: https://www.anchorterminal.com/tools/gemini-cli · Markdown: https://www.anchorterminal.com/tools/gemini-cli.md · JSON: https://www.anchorterminal.com/api/v1/tools/gemini-cli.json\n- Capabilities: agent.harness, agent.mcp-client, agent.multi-agent\n\n### 92. OpenHands, BB (70.9)\n\nOpen-source coding agent with a self-hosted web interface, local and remote execution, and scheduled or webhook-driven automation. A Docker container per conversation with `OH_CONVERSATION_RUNTIME=docker`, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.\n\n- Page: https://www.anchorterminal.com/tools/openhands · Markdown: https://www.anchorterminal.com/tools/openhands.md · JSON: https://www.anchorterminal.com/api/v1/tools/openhands.json\n- Capabilities: agent.harness, agent.mcp-client, agent.multi-agent\n\n### 134. OpenCode, B (68)\n\nOpen-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK. Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox.\n\n- Page: https://www.anchorterminal.com/tools/opencode · Markdown: https://www.anchorterminal.com/tools/opencode.md · JSON: https://www.anchorterminal.com/api/v1/tools/opencode.json\n- Capabilities: agent.harness, agent.mcp-client, agent.multi-agent\n\n### 222. Claude Code, B (62.2)\n\nAnthropic's coding agent as a terminal program, also in VS Code, JetBrains, the desktop app and Anthropic-hosted cloud sessions. Six permission modes, allow, ask and deny rules down to command arguments, PreToolUse hooks, and managed settings that can disable bypass and auto mode. The sandbox is off by default and native Windows has none.\n\n- Page: https://www.anchorterminal.com/tools/claude-code · Markdown: https://www.anchorterminal.com/tools/claude-code.md · JSON: https://www.anchorterminal.com/api/v1/tools/claude-code.json\n- Capabilities: agent.harness, agent.mcp-client, agent.multi-agent\n\n### 239. Cline, C (60.8)\n\nOpen-source coding agent that runs as a VS Code extension, a JetBrains plugin, a CLI and a desktop app, all on one TypeScript SDK since extension 4.0.0 (26 June 2026). Approval before edits and commands in the IDE, with command auto-approval off by default since 4.0.0. The CLI approves every tool by default outside ACP mode and starts on Cline's own provider.\n\n- Page: https://www.anchorterminal.com/tools/cline · Markdown: https://www.anchorterminal.com/tools/cline.md · JSON: https://www.anchorterminal.com/api/v1/tools/cline.json\n- Capabilities: agent.harness, agent.mcp-client, agent.multi-agent\n\n### 286. GitHub Copilot CLI, C (57.9)\n\nGitHub's coding agent for the terminal, built on the same agent harness as Copilot cloud agent (formerly Copilot coding agent), which works in GitHub Actions and opens pull requests. Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.\n\n- Page: https://www.anchorterminal.com/tools/github-copilot-cli · Markdown: https://www.anchorterminal.com/tools/github-copilot-cli.md · JSON: https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json\n- Capabilities: agent.harness, agent.mcp-client, agent.multi-agent\n\n### 385. Aider, D (47.1)\n\nTerminal pair-programming tool that edits files in a local git repository through text edit formats rather than tool calls, builds a repo map with tree-sitter, and commits each change. Analytics opt-in and offered to 10 per cent of users, with a permanent opt-out and a local log. No release since 0.86.2 on 12 February 2026 and no commit since 22 May 2026.\n\n- Page: https://www.anchorterminal.com/tools/aider · Markdown: https://www.anchorterminal.com/tools/aider.md · JSON: https://www.anchorterminal.com/api/v1/tools/aider.json\n- Capabilities: agent.harness\n\n### 441. Cursor CLI, F (35.8)\n\nCursor's coding agent in the terminal, run as `agent` (also `cursor-agent`). Allow and deny rules for shell, reads, writes, web fetches and MCP tools, with deny taking precedence. No CLI changelog, and versions are dates.\n\n- Page: https://www.anchorterminal.com/tools/cursor-cli · Markdown: https://www.anchorterminal.com/tools/cursor-cli.md · JSON: https://www.anchorterminal.com/api/v1/tools/cursor-cli.json\n- Capabilities: agent.harness, agent.mcp-client\n\n## How we test this category\n\nThe same small repository task run headless in each harness with one MCP server attached, first fixing a failing test, then a task that needs the network. We check what it asks before acting, what the sandbox blocks, whether the run stops on its own, what it costs and what leaves the machine. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent harnesses",
        "url": ""
      }
    ],
    "description": "10 agent harnesses ranked by the Anchor benchmark. Leader goose (BB). Finished programs that run the agent loop for a person or a pipeline, in a terminal, an editor or the vendor's cloud. They plan, call tools, edit files and run commands, where a framework is a library you build that loop with. Compared on what they ask before acting, what the sandbox and the network allow by default, MCP support, headless use and the telemetry they send.",
    "facts": [
      "goose BB",
      "OpenAI Codex BB",
      "Gemini CLI BB"
    ],
    "h1": "Agent harnesses and coding agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-agent-harnesses.png",
    "path": "/categories/agent-harnesses",
    "published": "",
    "section": "tools",
    "title": "Agent harnesses and coding agents, ranked | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/categories/agent-harnesses"
  },
  "tokens": {
    "markdown": 2600,
    "slim": 480
  },
  "version": 1
}
