Head to head · Agent harness · October 2026 research run

Kilo Code CLI vs Qwen Code

Kilo Code CLI scores 75.4 (BB) on agent readiness against Qwen Code's 72.4 (BB), and leads in 3 of 7 scored categories. Qwen Code leads on agent ergonomics and payments & pricing. Both do agent harness.

Which one, for what

Kilo Code CLI BB

Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.

Ahead on

  • Reliability, 85 against 69
  • Security & auth, 66 against 53
  • Transparency & trust, 76 against 63

Watch for

Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it

Qwen Code BB

Good for Developers and CI jobs that want an open-source harness tied to no single model vendor, with run budgets and SDKs.

Ahead on

  • Agent ergonomics, 85 against 72
  • Payments & pricing, 60 against 50

Watch for

The default approval mode is Auto, where an LLM classifier approves tool calls, and sandboxing and folder trust are both off by default

Score by category

CategoryWeight this runKilo Code CLIQwen CodeEdge
Reliability16%208569Kilo Code CLI +16
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29091Qwen Code +1
Agent ergonomics13%16.27285Qwen Code +13
Security & auth14%17.56653Kilo Code CLI +13
Payments & pricing10%12.55060Qwen Code +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88788Qwen Code +1
Transparency & trust7%8.87663Kilo Code CLI +13
Negative events≤1500
Total75.4 · BB72.4 · BB

Facts side by side

FactKilo Code CLIQwen Code
KindAgent harnessAgent harness
VendorKilo Code Inc.Alibaba (Qwen team)
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyAPI key
PricingFreemiumFree
x402nono
LicenceMITApache-2.0
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-072026-10-05
Terms last updated2026-09-302026-10-01
Privacy policy last updated2026-05-292026-10-01
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessyesnot found in the text
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticeyesnot found in the text
Arbitration or class-action waiveryesnot found in the text
Popularity28k stars, 33k npm/wk28k stars, 105k npm/wk

Verdicts

Kilo Code CLI

Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.

Qwen Code

Apache-2.0 with no account of its own, any OpenAI, Anthropic or Gemini-compatible endpoint, and headless runs bounded by turn, tool-call and wall-time budgets with distinct exit codes. Out of the box, Auto mode lets an LLM classifier approve tool calls, with the sandbox and folder trust both off. Usage statistics are on by default.

Before you call either

Kilo Code CLI

  1. Set sandbox.enabled to true in the global kilo.jsonc before kilo run --auto. --auto approves every permission request not explicitly denied
  2. Set experimental.openTelemetry to false, or KILO_TELEMETRY_LEVEL to a value other than all, to stop telemetry
  3. Add needed hosts to sandbox.allowed_hosts in global config. MCP tool calls are unavailable while network restriction is on
  4. Without --auto a non-interactive run rejects every permission prompt and exits 1
  5. Put provider keys in global config or the environment. {env:VAR} in a project kilo.json is ignored

Qwen Code

  1. Pass --approval-mode on every run. The settings default is auto, and one docs page says headless runs default to asking, so don't rely on either
  2. Add --max-session-turns, --max-wall-time and --max-tool-calls. All three are unlimited by default. Exit 53 is the turn limit and 55 a budget
  3. --yolo doesn't turn on a sandbox. Add --sandbox, or on Linux set tools.executionSandbox with network set to closed
  4. Set QWEN_USAGE_STATISTICS_ENABLED=false to stop usage statistics
  5. Authenticate with OPENAI_API_KEY, OPENAI_BASE_URL and OPENAI_MODEL in CI. The browser sign-in is discontinued

Questions

Which is better for AI agents, Kilo Code CLI or Qwen Code?

Kilo Code CLI scores 75.4 (BB) on agent readiness against Qwen Code's 72.4 (BB), and leads in 3 of 7 scored categories. Qwen Code leads on agent ergonomics and payments & pricing.

Are Kilo Code CLI and Qwen Code open source?

Yes. Kilo Code CLI is open source (MIT). Qwen Code is open source (Apache-2.0).

Other comparisons with Kilo Code CLI or Qwen Code

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.