Head to head · Agent harnesses · October 2026 research run

Droid CLI vs Kilo Code CLI

Kilo Code CLI scores 75.4 (BB) on agent readiness against Droid CLI's 59.1 (C), and leads in 6 of 7 scored categories. Both do agent harnesses.

Best agent harnesses and coding agents · All 167 harnesses comparisons

Which one, for what

Droid CLI C

Good for Teams that want a terminal coding agent with tiered autonomy, command rules and an optional sandbox, and that will pay for a Factory plan.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

No free tier or trial was found. Plans start at $20 a month and included usage is stated only as rolling rate limits without numbers

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 49
  • Schema & documentation, 90 against 79
  • Payments & pricing, 50 against 10
  • Maintenance & community, 87 against 79
  • Transparency & trust, 76 against 64

Also in its favour

  • Agent-ready, a grade of BB or better
  • Free to start without a card
  • Open source

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

Score by category

CategoryWeight this runDroid CLIKilo Code CLIEdge
Reliability16%204985Kilo Code CLI +36
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27990Kilo Code CLI +11
Agent ergonomics13%16.27272even
Security & auth14%17.56366Kilo Code CLI +3
Payments & pricing10%12.51050Kilo Code CLI +40
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87987Kilo Code CLI +8
Transparency & trust7%8.86476Kilo Code CLI +12
Negative events≤1500
Total59.1 · C75.4 · BB

Facts side by side

FactDroid CLIKilo Code CLI
KindAgent harnessAgent harness
VendorFactoryKilo Code Inc.
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingPaidFreemium
x402nono
LicenceProprietary, under Factory's Terms and Conditions. The droid npm package is marked UNLICENSED and the public repository holds documentation only. The Python SDK is Apache-2.0MIT
Read-only variant documentedyesno
llms.txtyesyes
Last release2026-10-082026-10-07
Terms last updated2026-07-142026-09-30
Privacy policy last updated2026-08-202026-05-29
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingyesnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waiveryesyes
Popularity49 stars, 7.8k npm/wk28k stars, 33k npm/wk

Verdicts

Droid CLI

droid exec is read-only unless --auto raises the autonomy level, with command rules, an optional kernel-enforced sandbox, JSON output and documented exit codes. No free tier, status page or security.txt was found, the source is closed, and usage metrics go to Factory by default.

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

Before you call either

Droid CLI

  1. Set FACTORY_API_KEY (starts fk-) from the API keys page in Factory settings for headless runs. Interactive use signs in through a browser
  2. Start with droid exec and no flags for analysis. Add --auto low for edits and --auto medium for installs, tests and local commits
  3. Use --output-format json and read is_error, num_turns and session_id. Treat a non-zero exit code as failure
  4. Set sandbox.enabled to true before running on untrusted code. In droid exec a sandbox violation is denied without a prompt
  5. Pin the version in CI with npm install -g droid@<version>, or set FACTORY_DROID_AUTO_UPDATE_ENABLED=false on standalone installs, which update themselves

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

Questions

Which is better for AI agents, Droid CLI or Kilo Code CLI?

Kilo Code CLI scores 75.4 (BB) on agent readiness against Droid CLI's 59.1 (C), and leads in 6 of 7 scored categories.

Are Droid CLI and Kilo Code CLI open source?

No open-source release is listed for Droid CLI. Kilo Code CLI is open source (MIT).

Other comparisons with Droid CLI or Kilo Code CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.