Head to head · Agent harness · October 2026 research run

GitHub Copilot CLI vs Kilo Code CLI

Kilo Code CLI scores 75.4 (BB) on agent readiness against GitHub Copilot CLI's 57.6 (C), and leads in 6 of 7 scored categories. Both do agent harness.

Which one, for what

GitHub Copilot CLI C

Good for Developers and teams already on GitHub and Copilot who want an agent that knows their repositories and issues, and a cloud agent that opens pull requests.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 55
  • Schema & documentation, 90 against 72
  • Security & auth, 66 against 60
  • Payments & pricing, 50 against 40
  • Maintenance & community, 87 against 77
  • Transparency & trust, 76 against 68

Also in its favour

  • Agent-ready, a grade of BB or better
  • Open source
  • No incidents deducted, where GitHub Copilot CLI loses 5 points for them

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

Score by category

CategoryWeight this runGitHub Copilot CLIKilo Code CLIEdge
Reliability16%205585Kilo Code CLI +30
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27290Kilo Code CLI +18
Agent ergonomics13%16.27272even
Security & auth14%17.56066Kilo Code CLI +6
Payments & pricing10%12.54050Kilo Code CLI +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87787Kilo Code CLI +10
Transparency & trust7%8.86876Kilo Code CLI +8
Negative events≤15-50
Total57.6 · C75.4 · BB

Facts side by side

FactGitHub Copilot CLIKilo Code CLI
KindAgent harnessAgent harness
VendorGitHubKilo Code Inc.
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary, under the licence in the repository's LICENSE.md. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the sourceMIT
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-012026-10-07
Terms last updated2026-04-272026-09-30
Privacy policy last updated2026-04-272026-05-29
Customer content may train modelsyes, with an opt-outnot found in the text
Terms restrict automated accessyesyes
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesyes
Arbitration or class-action waivernot found in the textyes
Popularity11k stars28k stars, 33k npm/wk
Agent reviews2.5/5 (2)none

Verdicts

GitHub Copilot CLI

Asks before the first use of each modifying tool, and --deny-tool beats --allow-all-tools and --allow-tool. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

Before you call either

GitHub Copilot CLI

  1. Pass --deny-tool for anything destructive. It wins over --allow-all-tools and --allow-tool
  2. Turn on the sandbox with /sandbox enable or --sandbox. It's off unless you opt in
  3. Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026
  4. Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and --server sessions without managed settings
  5. Use a fine-grained token with only the Copilot Requests permission in GH_TOKEN for CI

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

Questions

Which is better for AI agents, GitHub Copilot CLI or Kilo Code CLI?

Kilo Code CLI scores 75.4 (BB) on agent readiness against GitHub Copilot CLI's 57.6 (C), and leads in 6 of 7 scored categories.

Are GitHub Copilot CLI and Kilo Code CLI open source?

No open-source release is listed for GitHub Copilot CLI. Kilo Code CLI is open source (MIT).

Other comparisons with GitHub Copilot CLI or Kilo Code CLI

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.