Antigravity CLI
by Google Agent harness in Agent harnesses
Google LLC · antigravity.google · who's behind it
Google's terminal agent for coding tasks, distributed as a closed-source binary and installed as agy. It replaces Gemini CLI for consumer accounts.
Best for Developers on Google AI plans or Gemini Enterprise who want a terminal agent with a sandbox on by default and access to several model families, depending on plan.
Is this your product? Claim this listing or verify it
Assessment. Google's terminal agent, shipped as a closed-source binary with a terminal sandbox on by default on macOS and Linux and documented headless JSON output. Interactions are used to improve Google products unless users opt out, and a headless run exits 0 when a tool is denied.
Facts
- Auth
- OAuth or key
- Pricing
- Freemium · Freemium
- x402
- No
- Licence
- Proprietary. The repository holds the README, changelog and examples, with no source and no licence file. Use is under the Google Antigravity Additional Terms of Service, the Google Terms of Service and the Privacy Policy
- llms.txt
- published
- Last release
- Interfaces
- Terminal user interface, with headless runs through
agy -p, a remote control daemon and an SSH login flow. macOS, Linux, Windows and Android through Termux - Install
install.shon macOS and Linux, PowerShell and CMD scripts on Windows. The binary is namedantigravityin the tarball and installed asagyin ~/.local/bin- Models
- Gemini 3.8, 3.7 and 3.6 Flash and Gemini 3.1 Pro on every plan. Claude Sonnet 5.5 and Opus 5.5 (thinking) on paid plans. Claude Sonnet 4.6, Opus 4.6 and GPT-OSS 120B are marked for removal on 2 November 2026
- Permission presets
- Default runs commands in the sandbox and asks outside it. Request Review turns the sandbox off and always asks. Turbo turns it off and allows everything
- Sandbox
- sandbox-exec profiles on macOS and Linux namespaces. Project folders are writable, ~/.ssh and .env are hidden, and network access is limited to approved domains
- MCP
- stdio, Streamable HTTP, SSE and WebSocket servers in mcp_config.json, managed with
/mcp. Allow rules use mcp(server/tool), mcp(server/*) or mcp(*) - Extensions
- Skills as folders with a SKILL.md file, custom subagents, hooks in hooks.json (PreToolUse, PostToolUse and Stop), and plugins installed with
/pluginoragy plugin install - Headless
agy -por--print, with--output-formatset to text, json or stream-json. Exit 0 for success and soft-denied tools, 1 for an error envelope such as an unknown model, 2 for an ERROR result on malformed stream-json input, and 3 for a model or agent error during a streamed run- Telemetry
- Enable Telemetry in the Account settings controls sharing of Interactions. The settings page also describes the same key as anonymous usage statistics and crash reports
- Implementation
- Built in Go, according to Google's announcement of 19 May 2026. Source isn't published
- Releases in 90 days
- 47 numbered releases from 1.1.2 (13 July) to 1.3.2 (8 October 2026)
- Capabilities
- agent.harness agent.mcp-client agent.multi-agent
Facts verified 10 October 2026 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- The sandbox is on under the Default preset on macOS and Linux, hides ~/.ssh and .env, and limits network access to approved domains
- Headless
agy -pruns with--output-format jsonorstream-json, a status field with SUCCESS, ERROR and other terminal states, and token usage in the result event - MCP clients for stdio, Streamable HTTP, SSE and WebSocket servers, with unconfigured MCP tools set to ask first and allow rules by server and tool
- Skills, subagents, PreToolUse and PostToolUse hooks, and plugins from an official marketplace that
/pluginmanages - The installer verifies a SHA-512 checksum against a manifest on Google's release server before it installs
Weaknesses
- Closed source. The repository holds the README, changelog and examples, with no source and no licence file
- Interactions are used to improve Google and Alphabet products and models, and Google staff and contractors may review them, unless the user opts out
- The sandbox is labelled preview in the permissions docs, and Windows still uses the older permission model that the docs describe separately
- A headless run exits 0 when a tool that needs approval is refused, and the only sign is a notice on stderr
- The plans page gives no request counts for the weekly quota, which Google sets by available capacity
Before you call it notes for agents
- Read the
statusfield from--output-format jsonand read stderr too. A tool refused for lack of approval still exits 0 - Pre-approve each shell command and tool a headless run needs with
action(target)rules underpermissions.allowin ~/.gemini/antigravity-cli/settings.json, because headless runs cannot ask - Export
GEMINI_API_KEYafter setting modelProvider to gemini. The CLI won't start when the key is missing, and setting the variable alone has no effect - Turn off Enable Telemetry in the Account settings before running on private repositories if Interactions should not be used for product improvement
- Set
--print-timeoutexplicitly. The docs give a five-minute default, whileagy --helpshows 0s
Who's behind it provenance 56/100
- Legal entity namedGoogle LLC20/20
- Domain ageantigravity.google, no registry record we could read0/15
- Endpoint on the vendor's domainno hosted endpointn/a
- Terms of servicepublished10/10
- Privacy policyread, states 7 of the 8 things a reader expects, and has 1 clause that costs points7.3/10
- Status pagenot found0/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Privacy policy dated 2026-10-01, states 7 of 8, 1 to know
TL;DR Dated 2026-10-01. States 7 of the 8 things a reader expects, and we didn't find where data goes. To know before relying on it, model training with no opt-out found.
Says it may use customer content to train or improve models, and no opt-out was foundcosts points
We use your interactions with AI models and technologies like Gemini Apps to develop, train, fine-tune, and improve these models to better handle your requests, and update their classifiers and filters including for safety, language understanding, and factuality.
Content an agent sends could end up in a model. An opt-out, where the document gives one, is shown instead.
Gives the date it was last updated Last updated 2026-10-01
Effective October 1, 2026 | Archived versions | Download PDF
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information.
The basic statement a privacy policy exists to make.
Says how long data is kept
The types of location data we collect and how long we store it depend in part on your device and account settings.
Says when data sent to the service is deleted.
Says who else receives the data
For example, we use service providers to help operate our data centers, deliver our products and services, improve our internal business processes, and offer additional support to customers and users.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
If Google is involved in a merger, acquisition, or sale of assets, we’ll continue to ensure the confidentiality of your personal information and give affected users notice before personal information is transferred or becomes subject to a different privacy policy.
A plain statement either way.
Says what rights people have over their data
If European Union or United Kingdom data protection law applies to the processing of your information, you can review the European requirements section below to learn more about your rights and Google’s compliance with these laws.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact
And if you have any questions about this Privacy Policy, you can contact us.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
Members of organisations using Google Workspace or Google Cloud Platform are referred to the separate Google Cloud Privacy Notice for how those services collect and use personal information.
If you’re a member of an organization that uses Google Workspace or Google Cloud Platform, learn how these services collect and use your personal information in the Google Cloud Privacy Notice.
Noted by a second reader on 2026-10-08.
Google says it uses publicly available information from the web and other public sources to help train machine learning models behind products such as Google Translate, Gemini Apps and Cloud AI.
We use publicly available information online or from other public sources to help train new machine learning models and build foundational technologies that power various Google products such as Google Translate, Gemini Apps, and Cloud AI capabilities.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 14,332 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The legal entity is taken from the google.com check on the Gemini CLI listing. The Antigravity terms name Google without an entity.
antigravity.google serves no security.txt (both /.well-known/security.txt and /security.txt answered 404 on 10 October 2026). google.com has a valid one, with reports to g.co/vulnz.
No status page for the CLI was found in the docs, and the domain's registration date was not read.
Checked 2026-10-10 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Notable
- Successor to Gemini CLI for consumer accounts. Google sign-in for Google AI Pro, Ultra and the free Code Assist for individuals tier stopped working with Gemini CLI on 18 June 2026 source
- Interactions are used to evaluate, develop and improve Google and Alphabet products and machine learning, and Google employees and contractors may review them. The user can opt out in settings source source 2
- The Default permission preset runs terminal commands in a sandbox on macOS and Linux, with network access limited to approved domains. The docs label the sandbox as preview source source 2
- Version 1.3.2 was released on 8 October 2026. The changelog has 47 numbered releases from 1.1.2 (13 July) to 1.3.2 source
- The installer checks a SHA-512 checksum against a manifest on Google's release server before it installs, and the CLI updates itself in the background during normal runs source
- A headless run soft-denies any tool that needs approval it cannot get. The run continues, exits 0 and prints a notice to stderr source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 10 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 8.6 | |
| Local-package reading. An official installer for macOS, Linux and Windows, with an Android build for Termux, that checks a SHA-512 checksum against Google's release manifest before it installs (20). No public CI or test suite, since the repository holds no source and no workflows, only issue templates (0). Open issues and pull requests could not be read from this session, so the crash and regression line is unchecked (0). Version 1.3.2 is the latest, and version 1.2.10 changed headless exit codes for streamed model errors from 0 to 3 under a Fixed heading, with no breaking-change heading (8). Version 1.x, so stable under the rule (15). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 12.7 | |
| Framework reading. No published JSON Schema for settings.json, mcp_config.json or hooks.json was found, although the docs type each key (10). llms.txt at antigravity.google/llms.txt, and every docs page has a Markdown copy (10). Pages say when to use each permission preset, what each allows and when the sandbox applies (15). Presets, output formats, modes and effort levels are enumerated (13). The headless page documents the output envelope, the status values and exit codes, with a jq example (15). A dated changelog on the docs site and versioned release notes in the repository (15). | |||
| Agent ergonomics | 13%16.2 | 12.7 | |
Framework reading, adapted to a harness driven by a pipeline. MCP tools can be allowed or refused by server and tool, and a 20,000-token budget for user rules stops large rule sets from crowding out skills and MCP tools (16). No turn or spend cap appears in the flag reference, and --print-timeout sets a wall-clock limit only (10). The JSON envelope carries a status field and token usage, and the stream-json result event carries token counts (16). Exit codes 0, 1, 2 and 3 are documented, but a tool soft-denied in headless mode still exits 0 (14). --continue and --conversation resume earlier runs (14). A Python SDK on PyPI, which is a separate package, and no second SDK language for the CLI (8). | |||
| Security & auth | 14%17.5 | 9.3 | |
| Framework reading (credentials and telemetry defaults, approvals and sandboxing, guardrails, audit, security programme), five lines. Credentials are a Google account sign-in kept in the operating system keyring, or a Gemini API key in settings.json. Interactions are collected until the user opts out, and the settings page does not state the default (10). The Default preset sandboxes terminal commands on macOS and Linux, hides ~/.ssh and .env, limits network access to approved domains and asks before MCP tools run, with allow rules by server and tool. The sandbox is labelled preview, the Turbo preset turns it off, and Windows uses the older model (18). Hooks run before and after tool calls and can block one, and the CLI shows a Reason line when a hook flags an action. No documented defence against prompt injection in fetched content was found (7). The CLI log records model resolution, and approvals show in the conversation, but no exportable audit log was found (10). google.com has a valid security.txt with reports to g.co/vulnz, antigravity.google serves none, and no CLI advisory appears in the changelog. The advisory page was not reachable, so that part is unchecked (8). | |||
| Payments & pricing | 10%12.5 | 3.8 | |
| Harness reading of the published rubric. No payment protocol in the docs, the pricing page or the plans page (0). Plan prices are public without a login, at $20 a month for Google AI Pro, $100 and $200 for Ultra and $30 a seat for Enterprise Standard. Consumption is priced at Gemini Enterprise rates, and those rates were not read, so this is plan-level pricing (10). The pricing page lists a $0 individual plan that needs no subscription. None of the pages read asks for a payment method, but the account flow was not tested, so the point is taken from the page (20). Sign-in is a browser flow with a Google account, or a Gemini API key set by hand, and the CLI won't start unauthenticated (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.0 | |
| 1.3.2 on 8 October 2026 (30). 47 numbered releases in the changelog from 1.1.2 (13 July) to 1.3.2 (20). Responsiveness rests on a public changelog, a community forum linked from the terms and the GitHub repository, but no replies could be read (8). The google-antigravity Python SDK, version 0.1.21 released on 7 October 2026 under Apache-2.0, is a separate package and no SDK for the CLI itself was found (10). No public CI or dependency list for the CLI, since the source is not published (0). | |||
| Transparency & trusteditorial 52, provenance 56 | 7%8.8 | 4.7 | |
| Closed source, with clear terms. The binary is under the Google Antigravity Additional Terms, the Universal Terms and the Privacy Policy (15). The terms say Interactions are used to evaluate, develop and improve Google and Alphabet products and machine learning, that Google employees and contractors may review them, and that the user can ask for deletion by email. The README and settings page agree with that, but no retention period appears in the pages read (15). Dated notices exist for the Gemini CLI transition and for the removal of Claude Sonnet 4.6, Claude Opus 4.6 and GPT-OSS 120B on 2 November 2026, but there is no written deprecation policy for the CLI (10). Enable Telemetry in the Account settings controls sharing of Interactions and can be turned off. The settings page describes the same key as anonymous usage statistics and crash reports, and its default is not stated (12). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 57.7 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Antigravity CLI, or have the agent fetch /fixes/antigravity-cli.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Antigravity CLI From Anchor Terminal's listing at https://www.anchorterminal.com/tools/antigravity-cli, the October 2026 research run, assessed 10 October 2026. Grade C, 57.7 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Antigravity CLI: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Reliability, 43 out of 100, up to 11.4 more on the total Why it scored 43: Local-package reading. An official installer for macOS, Linux and Windows, with an Android build for Termux, that checks a SHA-512 checksum against Google's release manifest before it installs (20). No public CI or test suite, since the repository holds no source and no workflows, only issue templates (0). Open issues and pull requests could not be read from this session, so the crash and regression line is unchecked (0). Version 1.3.2 is the latest, and version 1.2.10 changed headless exit codes for streamed model errors from 0 to 3 under a Fixed heading, with no breaking-change heading (8). Version 1.x, so stable under the rule (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: Harness reading of the published rubric. No payment protocol in the docs, the pricing page or the plans page (0). Plan prices are public without a login, at $20 a month for Google AI Pro, $100 and $200 for Ultra and $30 a seat for Enterprise Standard. Consumption is priced at Gemini Enterprise rates, and those rates were not read, so this is plan-level pricing (10). The pricing page lists a $0 individual plan that needs no subscription. None of the pages read asks for a payment method, but the account flow was not tested, so the point is taken from the page (20). Sign-in is a browser flow with a Google account, or a Gemini API key set by hand, and the CLI won't start unauthenticated (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Security & auth, 53 out of 100, up to 8.2 more on the total Why it scored 53: Framework reading (credentials and telemetry defaults, approvals and sandboxing, guardrails, audit, security programme), five lines. Credentials are a Google account sign-in kept in the operating system keyring, or a Gemini API key in settings.json. Interactions are collected until the user opts out, and the settings page does not state the default (10). The Default preset sandboxes terminal commands on macOS and Linux, hides ~/.ssh and .env, limits network access to approved domains and asks before MCP tools run, with allow rules by server and tool. The sandbox is labelled preview, the Turbo preset turns it off, and Windows uses the older model (18). Hooks run before and after tool calls and can block one, and the CLI shows a Reason line when a hook flags an action. No documented defence against prompt injection in fetched content was found (7). The CLI log records model resolution, and approvals show in the conversation, but no exportable audit log was found (10). google.com has a valid security.txt with reports to g.co/vulnz, antigravity.google serves none, and no CLI advisory appears in the changelog. The advisory page was not reachable, so that part is unchecked (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Transparency & trust, 54 out of 100, up to 4 more on the total Made of editorial 52, provenance 56. Why it scored 54: Closed source, with clear terms. The binary is under the Google Antigravity Additional Terms, the Universal Terms and the Privacy Policy (15). The terms say Interactions are used to evaluate, develop and improve Google and Alphabet products and machine learning, that Google employees and contractors may review them, and that the user can ask for deletion by email. The README and settings page agree with that, but no retention period appears in the pages read (15). Dated notices exist for the Gemini CLI transition and for the removal of Claude Sonnet 4.6, Claude Opus 4.6 and GPT-OSS 120B on 2 November 2026, but there is no written deprecation policy for the CLI (10). Enable Telemetry in the Account settings controls sharing of Interactions and can be turned off. The settings page describes the same key as anonymous usage statistics and crash reports, and its default is not stated (12). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: antigravity.google, no registry record we could read (0 of 15) - Privacy policy: read, states 7 of the 8 things a reader expects, and has 1 clause that costs points (7.3 of 10) - Status page: not found (0 of 10) - security.txt: not found (0 of 10) ## 5. Schema & documentation, 78 out of 100, up to 3.6 more on the total Why it scored 78: Framework reading. No published JSON Schema for settings.json, mcp_config.json or hooks.json was found, although the docs type each key (10). llms.txt at antigravity.google/llms.txt, and every docs page has a Markdown copy (10). Pages say when to use each permission preset, what each allows and when the sandbox applies (15). Presets, output formats, modes and effort levels are enumerated (13). The headless page documents the output envelope, the status values and exit codes, with a jq example (15). A dated changelog on the docs site and versioned release notes in the repository (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Agent ergonomics, 78 out of 100, up to 3.6 more on the total Why it scored 78: Framework reading, adapted to a harness driven by a pipeline. MCP tools can be allowed or refused by server and tool, and a 20,000-token budget for user rules stops large rule sets from crowding out skills and MCP tools (16). No turn or spend cap appears in the flag reference, and `--print-timeout` sets a wall-clock limit only (10). The JSON envelope carries a status field and token usage, and the stream-json result event carries token counts (16). Exit codes 0, 1, 2 and 3 are documented, but a tool soft-denied in headless mode still exits 0 (14). `--continue` and `--conversation` resume earlier runs (14). A Python SDK on PyPI, which is a separate package, and no second SDK language for the CLI (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 7. Maintenance & community, 68 out of 100, up to 2.8 more on the total Why it scored 68: 1.3.2 on 8 October 2026 (30). 47 numbered releases in the changelog from 1.1.2 (13 July) to 1.3.2 (20). Responsiveness rests on a public changelog, a community forum linked from the terms and the GitHub repository, but no replies could be read (8). The google-antigravity Python SDK, version 0.1.21 released on 7 October 2026 under Apache-2.0, is a separate package and no SDK for the CLI itself was found (10). No public CI or dependency list for the CLI, since the source is not published (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: GitHub issues, pull requests and security advisories for google-antigravity/antigravity-cli (github.com answered 403 for the issues page and the GitHub API is closed to this session) - unchecked: whether the $0 individual plan asks for a payment method, since the account flow was not tested - unchecked: the default of Enable Telemetry, which the settings page does not state, and the retention period for Interactions - unchecked: an incident history for the CLI or its quota service, since no status page was found - unchecked: GitHub stars, so popularity has no count - The docs say --print-timeout defaults to five minutes, while agy --help says 0s - The settings page describes Enable Telemetry twice, as sharing Interactions and as anonymous usage statistics and crash reports - The docs changelog marks v1.3.1 as the latest release on 10 October 2026, while the repository changelog and the release manifest show 1.3.2 from 8 October - The Windows sandbox default is not stated in the pages read ## Weaknesses - Closed source. The repository holds the README, changelog and examples, with no source and no licence file - Interactions are used to improve Google and Alphabet products and models, and Google staff and contractors may review them, unless the user opts out - The sandbox is labelled preview in the permissions docs, and Windows still uses the older permission model that the docs describe separately - A headless run exits 0 when a tool that needs approval is refused, and the only sign is a notice on stderr - The plans page gives no request counts for the weekly quota, which Google sets by available capacity ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Read the `status` field from `--output-format json` and read stderr too. A tool refused for lack of approval still exits 0 - Pre-approve each shell command and tool a headless run needs with `action(target)` rules under `permissions.allow` in ~/.gemini/antigravity-cli/settings.json, because headless runs cannot ask - Export `GEMINI_API_KEY` after setting modelProvider to gemini. The CLI won't start when the key is missing, and setting the variable alone has no effect - Turn off Enable Telemetry in the Account settings before running on private repositories if Interactions should not be used for product improvement - Set `--print-timeout` explicitly. The docs give a five-minute default, while `agy --help` shows 0s ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: GitHub issues, pull requests and security advisories for google-antigravity/antigravity-cli (github.com answered 403 for the issues page and the GitHub API is closed to this session)
- unchecked: whether the $0 individual plan asks for a payment method, since the account flow was not tested
- unchecked: the default of Enable Telemetry, which the settings page does not state, and the retention period for Interactions
- unchecked: an incident history for the CLI or its quota service, since no status page was found
- unchecked: GitHub stars, so popularity has no count
- The docs say --print-timeout defaults to five minutes, while agy --help says 0s
- The settings page describes Enable Telemetry twice, as sharing Interactions and as anonymous usage statistics and crash reports
- The docs changelog marks v1.3.1 as the latest release on 10 October 2026, while the repository changelog and the release manifest show 1.3.2 from 8 October
- The Windows sandbox default is not stated in the pages read
Sources 21
- repository README, changelog and examples (git clone at commit 8c1310b) github.com · seen 2026-10-10
- changelog, 1.1.2 to 1.3.2 github.com · seen 2026-10-10
- installer script with checksum check antigravity.google · seen 2026-10-10
- release manifest for linux_amd64 (version 1.3.2, sha512) antigravity-cli-auto-updater-974169037036.us-central1.run.app · seen 2026-10-10
- installation and authentication antigravity.google · seen 2026-10-10
- headless mode, output formats and exit codes antigravity.google · seen 2026-10-10
- terminal sandbox antigravity.google · seen 2026-10-10
- permissions and presets antigravity.google · seen 2026-10-10
- MCP configuration and permissions antigravity.google · seen 2026-10-10
- hooks antigravity.google · seen 2026-10-10
- settings and Enable Telemetry antigravity.google · seen 2026-10-10
- models and removal dates antigravity.google · seen 2026-10-10
- plans and AI credits antigravity.google · seen 2026-10-10
- pricing page antigravity.google · seen 2026-10-10
- plan changes and prices (Google blog, 19 May 2026) antigravity.google · seen 2026-10-10
- Google Developers blog on the Gemini CLI transition (19 May 2026) developers.googleblog.com · seen 2026-10-10
- terms of service, Interactions and third-party use antigravity.google · seen 2026-10-10
- docs changelog antigravity.google · seen 2026-10-10
- llms.txt index antigravity.google · seen 2026-10-10
- google-antigravity SDK on PyPI pypi.org · seen 2026-10-10
- google.com security.txt google.com · seen 2026-10-10
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The pollers record uptime for hosted endpoints as they run, and that doesn't change the score either.
Pricing & changes
Freemium Freemium Free to install. A $0 individual plan needs no subscription and has a weekly quota, with Gemini Flash and other models. Google AI Pro costs $20 a month and Ultra $100 or $200 a month (announced 19 May 2026). Enterprise Standard or Plus seats start at $30 a seat a month, or pay-as-you-go with no seat fee at consumption rates. Checked 10 October 2026.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/antigravity-cli.xml, or this listing's score history at history.json.
Connect
Install
curl -fsSL https://antigravity.google/cli/install.sh | bash
Headless / CI
{
"run": "agy -p \"fix the failing test\" --output-format json"
}
Alternatives to Antigravity CLI
#15 of 20 in Best agent harnesses and coding agents · All 186 harnesses comparisons
Kilo Code CLI BBgoose BBQwen Code BBOpenHands BBOpenCode BGemini CLI B
Head to head Aider vs Antigravity CLI · Amp vs Antigravity CLI · Antigravity CLI vs Claude Code · Antigravity CLI vs Cline · Antigravity CLI vs Cursor CLI · Antigravity CLI vs Devin · Antigravity CLI vs Droid CLI · Antigravity CLI vs Pi · Antigravity CLI vs Gemini CLI · Antigravity CLI vs GitHub Copilot CLI · Antigravity CLI vs goose · Antigravity CLI vs Kilo Code CLI · Antigravity CLI vs Kiro CLI · Antigravity CLI vs OpenAI Codex · Antigravity CLI vs OpenCode · Antigravity CLI vs OpenHands · Antigravity CLI vs Prime Agent · Antigravity CLI vs Qwen Code · Antigravity CLI vs Paperclip
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Kilo Code CLI Kilo Code Inc. | BB | 75.4 | agent.harness agent.mcp-client agent.multi-agent | no |
| goose Agentic AI Foundation (originally Block) | BB | 73.9 | agent.harness agent.mcp-client agent.multi-agent | no |
| Qwen Code Alibaba (Qwen team) | BB | 72.4 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenHands All Hands AI | BB | 70.8 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenCode Anomaly | B | 67.7 | agent.harness agent.mcp-client agent.multi-agent | no |
| Gemini CLI Google | B | 66.7 | agent.harness agent.mcp-client agent.multi-agent | no |
Machine-readable
- JSON
/api/v1/tools/antigravity-cli.json· historyhistory.json· badge/badges/antigravity-cli.svg· changes feed/feeds/tools/antigravity-cli.xml - Markdown
/tools/antigravity-cli.md· slim/tools/antigravity-cli.min.md(or sendAccept: text/markdown) - Fix list
/fixes/antigravity-cli.md·/fixes/antigravity-cli.json - From a terminal
anchor tool antigravity-cli --md(the CLI) · over MCPget_tool {"slug": "antigravity-cli"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/antigravity-cli"><img src="https://www.anchorterminal.com/badges/antigravity-cli.svg" alt="Antigravity CLI on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/antigravity-cli)<a href="https://www.anchorterminal.com/tools/antigravity-cli">Antigravity CLI on Anchor Terminal</a>It counts on a page on antigravity.google or one of its subdomains, or the README of github.com/google-antigravity/antigravity-cli.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "antigravity-cli", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


