Kilo Code CLI
by Kilo Code Inc. Agent harness in Agent harnesses
Agent-ready
Kilo Code Inc. · kilo.ai since 2017 · status page · who's behind it
Open-source coding agent for the terminal, forked from opencode and built from the same repository as Kilo's VS Code and JetBrains extensions. It runs with your own provider key, a local model or the Kilo Gateway.
Good for Developers who want an open-source terminal agent with per-tool permission rules, an optional sandbox and a choice of provider, and the same engine in VS Code and JetBrains.
Is this your product? Claim this listing or verify it
Assessment. Shell commands ask before running by default, and an optional operating-system sandbox blocks writes outside the workspace and outbound network. Telemetry to PostHog is on by default and the sandbox is off, so an unattended kilo run --auto approves everything not denied unless both are configured first.
Facts
- Auth
- OAuth or key
- Pricing
- Freemium · $19 / mo
- x402
- No
- Licence
- MIT
- Packages
npm@kilocode/clinpm@kilocode/sdk- llms.txt
- published
- Last release
- GitHub stars
- 28k
- npm / week
- 33k
- Interfaces
- Terminal CLI and TUI,
kilo serveHTTP server, ACP server (kilo acp), TypeScript SDK. The same repository ships the VS Code extension and JetBrains plugin - Install
- npm, pnpm, bun, an install script, a Homebrew tap, AUR, and release binaries for Linux, macOS and Windows
- Models
- Your own provider keys, local models, or the Kilo Gateway, which the vendor says carries 500+ models
- Approvals
allow,askordenyper tool with glob rules. Shell commands ask outside a built-in allow list, edits in the project run without asking,.envreads and outside paths ask- Sandbox
- Off by default. Seatbelt on macOS and Bubblewrap on Linux, write limits plus
sandbox.networkdeny withsandbox.allowed_hosts. None on Windows - MCP client
- Local (stdio) and remote (HTTP) servers under
mcpinkilo.json, OAuth throughkilo mcp auth, permission globs over tool names - Headless
kilo runwith--auto,--format json,--continue,--sessionand--fork. Exit codes 0, 1 and 124- Agents
- Code, Plan, Ask and Debug, custom agents, and subagents
- Telemetry
- PostHog, on by default. Off with
experimental.openTelemetryfalse orKILO_TELEMETRY_LEVEL. Optional OTLP export whenOTEL_EXPORTER_OTLP_ENDPOINTis set - Releases in 90 days
- 37 stable (10 July to 8 October 2026)
- Capabilities
- agent.harness agent.mcp-client agent.multi-agent
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Permission rules of
allow,askordenyper tool with glob patterns, and shell commands asking by default outside a built-in allow list - A sandbox on macOS and Linux that limits writes, blocks network by default and refuses to run when it can't be enforced
- Project config can't weaken the sandbox or read environment variables through
{env:VAR} - Your own provider key or a local model works with no Kilo account
- 37 stable releases since 10 July 2026, with the last 40 workflow runs on main passing on 8 October 2026
Weaknesses
- Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it
- The sandbox is off by default and unavailable on Windows
kilo runlists no flag for a turn, time or cost limit- The terms grant a perpetual licence to use uploaded Customer Data to improve Kilo's services
- SECURITY.md still says the CLI has no sandbox, and the changelog has no dates or breaking-change headings
Before you call it notes for agents
- Set
sandbox.enabledto true in the globalkilo.jsoncbeforekilo run --auto.--autoapproves every permission request not explicitly denied - Set
experimental.openTelemetryto false, orKILO_TELEMETRY_LEVELto a value other thanall, to stop telemetry - Add needed hosts to
sandbox.allowed_hostsin global config. MCP tool calls are unavailable while network restriction is on - Without
--autoa non-interactive run rejects every permission prompt and exits 1 - Put provider keys in global config or the environment.
{env:VAR}in a projectkilo.jsonis ignored
Who's behind it provenance 90/100
- Legal entity namedKilo Code Inc. (the terms are a contract with Anaconda, Inc. on behalf of itself and its affiliates, including Kilo Code Inc.)20/20
- Domain agekilo.ai, registered 2017-12-16 (8 years)11/15
- Endpoint on the vendor's domainno hosted endpointn/a
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 8 of the 8 things a reader expects10/10
- Status pagestatus.kilo.ai10/10
- Changelogpublished10/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service dated 2026-09-30, states 6 of 7, 4 to know
TL;DR Dated 2026-09-30. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts automated accesscosts points
(vi) use any spider, crawler, scraper or other automatic device, process or software that intercepts, mines, scrapes, extracts or otherwise accesses the Services to monitor, extract, copy or collect information or data from or through the Services
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Says the terms or the service can change without noticecosts points
Kilo reserves the right to modify or discontinue all or any portion of the Services at any time (including by limiting or discontinuing certain features of the Services), temporarily or permanently, without notice to you.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
In addition, Kilo may, at its sole discretion, terminate these Terms or your Account on the Services, or suspend or terminate your access to the Services, at any time for any reason or no reason, with or without notice, and without any liability to you arising from such termination.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
You agree that, by entering into these Terms, you and Kilo are each waiving the right to a trial by jury or to participate in any class action or other representative proceeding.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated Last updated 2026-09-30
Last updated September 30, 2026.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Delaware
These Terms are governed by the laws of the State of Delaware without regard to conflict of law principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the greater of USD 100 and the fees paid in the 6 months before the claim
…ANY PORTION OF THE SERVICE OR OTHERWISE UNDER THESE TERMS, WHETHER IN CONTRACT, TORT, OR OTHERWISE, IS LIMITED TO THE GREATER OF: (a) THE AMOUNT YOU HAVE PAID TO KILO FOR ACCESS TO AND USE OF THE SERVICE IN THE 6 MONTHS PRIOR TO THE EVENT OR CIRCUMSTANCE GIVING RISE TO THE CLAIM OR, IF GREATER, (b) USD 100.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Kilo may suspend or terminate access to the Services, including Fee-based portions of the Services, for any Account for which any amount is due but unpaid.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives thirty calendar days of notice before a change
Notwithstanding any provision in these Terms to the contrary, Kilo agrees that if it makes any future change to this Arbitration Agreement (other than a change to the Notice Address) while you are a user of the Services, you may reject any such change by sending Kilo written notice within thirty (30) calendar days of…
Says whether a customer hears about a change before it binds them.
Lists what users may not do
During a skipped Subscription Period, you will not be charged the Subscription Fee and will not receive Monthly Credits (defined in Section 4(F)).
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Uploading Customer Data, including source code, grants Kilo a perpetual, irrevocable, sublicensable and transferable licence to use it to run and improve the Services and Kilo's other products.
you grant Kilo a perpetual, irrevocable, fully-paid, royalty-free, worldwide, sublicensable, transferable right and license to use such Customer Data to provide and improve the Services and Kilo’s other products and services, including for development, diagnostic and corrective purposes
Noted by a second reader on 2026-10-08.
Customer Data sent to an AI model through the Services is used by that model under the model provider's own terms, which the customer is responsible for reviewing.
You agree that any Customer Data provided to any AI Model through the Services will be used by the applicable AI Model in accordance with the applicable AI Model Terms.
Noted by a second reader on 2026-10-08.
Purchased Credits expire one year after purchase or when the account is deleted, whichever comes first, and the terms say Credits are non-refundable.
All Credits must be used before the sooner of (i) one (1) year after the date of purchase or (ii) the deletion of your Account or other access to the Services.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 10,676 words
Privacy policy dated 2026-05-29, states 8 of 8
TL;DR Dated 2026-05-29. States all 8 things a reader expects. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-05-29
Last Updated: May 29, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
and/or any of its affiliates ("Kilo Code" or "we" or "us") and describes how we process your personal information in connection with the Services, and how we collect information through the use of cookies and related technologies.
The basic statement a privacy policy exists to make.
Says how long data is kept Names a period of 90 days
errors, session replays, uptime data, and attachments are generally retained for 30 to 90 days, logs, profiles, crons, application metrics, and most spans are generally retained for 30 days, and some sampled span data may be retained for up to 13 months on Business or Enterprise plans.
Says when data sent to the service is deleted.
Says who else receives the data
If you are a customer of Kilo Code, this Privacy Policy does not apply to personal information or other data and information that we process on your behalf (if any) as your service provider (collectively, “Customer Data”).
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Kilo Code may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business transaction (or potential business transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the even…
A plain statement either way.
Says what rights people have over their data
Right to withdraw consent at any time (if processing is based on consent).
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact support@kilo.ai
If you have any questions about this Privacy Policy or our privacy and security practices or you wish to make a complaint about our compliance with applicable privacy laws, contact us at support@kilo.ai.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
…we will take steps to ensure your personal information is adequately protected by safeguards such as Standard Contractual Clauses (“SCCs”) approved by the EU Commission or by the UK Government.
The countries data goes to and the safeguard used.
The policy does not cover data Kilo processes on a customer's behalf as a service provider, which the separate terms of service govern.
If you are a customer of Kilo Code, this Privacy Policy does not apply to personal information or other data and information that we process on your behalf (if any) as your service provider (collectively, “Customer Data”).
Noted by a second reader on 2026-10-08.
Kilo reserves the right to publish a support or feedback request sent to it, and says it will not publish personal information with the request.
If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish your request in order to help us clarify or respond to your request or to help us support other users.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 4,169 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms (last updated 30 September 2026) name the CLI among the services they cover and are made with Anaconda, Inc. The privacy policy (29 May 2026) names Kilo Code Inc. as data controller.
kilo.ai/.well-known/security.txt lists security@kilo.ai and the policy at kilo.ai/security, names the CLI in scope and expires on 2026-12-31.
trust.kilo.ai redirects to trust.anaconda.com, which has a Kilo Code section.
status.kilo.ai is a Statuspage site for the website, gateway and cloud platform. The CLI runs on the owner's machine.
PRIVACY.md in the repository is a separate short policy for the CLI dated March 2025.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-09 09:03 UTC
- Vendor status page maintenance, Service Under Maintenance · 1 minute ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/kilo-code-cli.json
Notable
kilo run --autoapproves every permission request that no rule explicitly denies, and without--autoa non-interactive run rejects each request and exits 1 source- The sandbox is off by default, limits writes to the workspace and blocks outbound network when on, and has no Windows backend source
- Telemetry is on by default and is turned off with
experimental.openTelemetryset to false source - The telemetry client posts to PostHog at us.i.posthog.com and links the machine identifier to the account email after sign-in source
- The terms are a contract with Anaconda, Inc. on behalf of itself and affiliates including Kilo Code Inc. source
- The CLI is a fork of opencode, and the licence file keeps opencode's 2025 copyright beside Kilo Code's source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 17.0 | |
Local-package reading. @kilocode/cli on npm, a Homebrew tap, an AUR package, an install script and release binaries for Linux, macOS and Windows on x64 and arm64, with baseline and musl builds named (20). Public CI, and the 40 most recent completed workflow runs on main on 8 October 2026 all succeeded, the test, typecheck and VS Code test workflows among them (25). 448 open issues and 147 open pull requests, a workflow that closes issues after 60 quiet days and pull requests after 30, and open reports from 7 October of a turn that hangs after the loop exits (#14876) and of exhausted 503 retries ending a run with no visible error (#14877) (15). The CLI changelog is generated by Changesets with Minor and Patch headings and no dates or breaking-change headings, and the end of the fallback to .opencode configuration is recorded in the docs, not under a version (10). 7.8.8, past 1.0 (15). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 14.6 | |
Framework reading. A JSON Schema for kilo.jsonc at https://app.kilo.ai/config.json, an OpenAPI file for the kilo serve API at packages/sdk/openapi.json and a CLI reference generated from the command definitions (25). llms.txt on kilo.ai and on the docs, the second listing a raw Markdown address for every page (10). The sandboxing page says when to use the sandbox, what it does not protect and how it differs from permissions (16). Permissions are allow, ask or deny with glob rules, sandbox.network and --format are enums, though the schema served on 8 October had no sandbox key (13). Config and CI samples and exit codes 0, 1 and 124, but we found no reference for the records --format json writes (11). A versioned changelog and dated GitHub releases (15). | |||
| Agent ergonomics | 13%16.2 | 11.7 | |
Framework reading, adapted to a harness driven by a pipeline. Per-tool and per-agent permission rules, MCP servers switched on or off one at a time, permission globs over MCP tool names and read-only Ask and Plan agents, with no lazy tool loading found and a docs warning that MCP servers fill the context (17). Exit code 124 is documented for a timeout and a doom_loop check stops repeated failures, but kilo run lists no flag for a turn, time or cost limit (11). Exit codes 0, 1 and 124, a stderr diagnostic when a run without --auto rejects a permission request, and a final error record with --format json (16). --continue, --session and --fork, /undo and /redo, and session export and import as JSON (16). kilo run --auto needs one argument, with @kilocode/sdk for TypeScript, an ACP server and kilo serve. We found no second-language SDK on a registry (12). | |||
| Security & auth | 14%17.5 | 11.6 | |
Harness reading of the framework checklist. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Telemetry is on by default and goes to PostHog in the United States, the source links the machine identifier to the account email after a Kilo sign-in, and it is turned off with experimental.openTelemetry or KILO_TELEMETRY_LEVEL. Provider keys stay on the machine (14). Shell commands ask by default outside a built-in allow list, reads of .env files and paths outside the project ask, and edits inside the project run without asking. An operating-system sandbox (Seatbelt on macOS, Bubblewrap on Linux, none on Windows) limits writes and blocks the network, refuses to run when it can't be enforced, and is off by default. --auto approves everything not explicitly denied (15). The sandboxing page covers prompt injection and its limits, project config can't weaken the sandbox, and {env:VAR} is resolved only in trusted config (11). Session export, kilo stats and OTLP export of traces and logs, with audit logs on the Enterprise plan (12). A valid security.txt (expires 2026-12-31), a disclosure policy that cites HackerOne's standards and safe harbour, CodeQL in CI and no published repository advisories, while SECURITY.md still says the CLI has no sandbox (14). | |||
| Payments & pricing | 10%12.5 | 6.2 | |
| No payment protocol (0). Scored on Kilo's paid options, as with Cline. Plan prices are public (Kilo Pass from $19 a month, Teams $15 a user a month, Enterprise by quote) and the gateway bills provider rates plus a 5 per cent fee on credit purchases, but the pricing page carries no per-token list (10). The CLI is MIT-licensed and free, and the pricing page says the free tier needs no card (20). Your own provider key or a local model works with no Kilo account, so an agent can install and run it without a sign-up (20). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 7.6 | |
7.8.8 on 7 October 2026 (30). 37 stable releases since 10 July 2026, JetBrains tags aside (20). The newest issues carry area and triage labels from automation, but the 15 newest open issues had no or one comment each on 8 October, against 448 open issues and 147 open pull requests (15). @kilocode/sdk and @kilocode/plugin are at 7.8.8 with the CLI, and the VS Code extension ships from the same release workflow (13). CI, CodeQL and Dependabot security updates run, with version updates switched off because most dependencies arrive through merges from opencode (9). | |||
| Transparency & trusteditorial 61, provenance 90 | 7%8.8 | 6.7 | |
MIT, with opencode's copyright kept in the licence file (30). The privacy policy (29 May 2026) names Kilo Code Inc. as controller, says data is stored in the United States and lists Stripe, OpenRouter, model providers, AppsFlyer and Sentry, but it doesn't mention the CLI's PostHog telemetry. PRIVACY.md in the repository is dated March 2025 and is silent on telemetry too. The terms (30 September 2026) are a contract with Anaconda, Inc. and grant a perpetual licence to use uploaded Customer Data to improve the services (13). kilo console is marked deprecated with no removal date, and updated terms apply after 30 days. No written deprecation policy found (8). The docs say telemetry is on by default and name the opt-out key in two places, without listing what is collected or where it goes (10). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 75.4 · BB | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 17 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Kilo Code CLI, or have the agent fetch /fixes/kilo-code-cli.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Kilo Code CLI
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/kilo-code-cli, the October 2026 research run, assessed 8 October 2026. Grade BB, 75.4 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Kilo Code CLI: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Payments & pricing, 50 out of 100, up to 6.3 more on the total
Why it scored 50: No payment protocol (0). Scored on Kilo's paid options, as with Cline. Plan prices are public (Kilo Pass from $19 a month, Teams $15 a user a month, Enterprise by quote) and the gateway bills provider rates plus a 5 per cent fee on credit purchases, but the pricing page carries no per-token list (10). The CLI is MIT-licensed and free, and the pricing page says the free tier needs no card (20). Your own provider key or a local model works with no Kilo account, so an agent can install and run it without a sign-up (20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 2. Security & auth, 66 out of 100, up to 6 more on the total
Why it scored 66: Harness reading of the framework checklist. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Telemetry is on by default and goes to PostHog in the United States, the source links the machine identifier to the account email after a Kilo sign-in, and it is turned off with `experimental.openTelemetry` or `KILO_TELEMETRY_LEVEL`. Provider keys stay on the machine (14). Shell commands ask by default outside a built-in allow list, reads of `.env` files and paths outside the project ask, and edits inside the project run without asking. An operating-system sandbox (Seatbelt on macOS, Bubblewrap on Linux, none on Windows) limits writes and blocks the network, refuses to run when it can't be enforced, and is off by default. `--auto` approves everything not explicitly denied (15). The sandboxing page covers prompt injection and its limits, project config can't weaken the sandbox, and `{env:VAR}` is resolved only in trusted config (11). Session export, `kilo stats` and OTLP export of traces and logs, with audit logs on the Enterprise plan (12). A valid security.txt (expires 2026-12-31), a disclosure policy that cites HackerOne's standards and safe harbour, CodeQL in CI and no published repository advisories, while SECURITY.md still says the CLI has no sandbox (14).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 3. Agent ergonomics, 72 out of 100, up to 4.6 more on the total
Why it scored 72: Framework reading, adapted to a harness driven by a pipeline. Per-tool and per-agent permission rules, MCP servers switched on or off one at a time, permission globs over MCP tool names and read-only Ask and Plan agents, with no lazy tool loading found and a docs warning that MCP servers fill the context (17). Exit code 124 is documented for a timeout and a `doom_loop` check stops repeated failures, but `kilo run` lists no flag for a turn, time or cost limit (11). Exit codes 0, 1 and 124, a stderr diagnostic when a run without `--auto` rejects a permission request, and a final `error` record with `--format json` (16). `--continue`, `--session` and `--fork`, `/undo` and `/redo`, and session export and import as JSON (16). `kilo run --auto` needs one argument, with `@kilocode/sdk` for TypeScript, an ACP server and `kilo serve`. We found no second-language SDK on a registry (12).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 4. Reliability, 85 out of 100, up to 3 more on the total
Why it scored 85: Local-package reading. `@kilocode/cli` on npm, a Homebrew tap, an AUR package, an install script and release binaries for Linux, macOS and Windows on x64 and arm64, with baseline and musl builds named (20). Public CI, and the 40 most recent completed workflow runs on main on 8 October 2026 all succeeded, the test, typecheck and VS Code test workflows among them (25). 448 open issues and 147 open pull requests, a workflow that closes issues after 60 quiet days and pull requests after 30, and open reports from 7 October of a turn that hangs after the loop exits (#14876) and of exhausted 503 retries ending a run with no visible error (#14877) (15). The CLI changelog is generated by Changesets with Minor and Patch headings and no dates or breaking-change headings, and the end of the fallback to `.opencode` configuration is recorded in the docs, not under a version (10). 7.8.8, past 1.0 (15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 5. Transparency & trust, 76 out of 100, up to 2.1 more on the total
Made of editorial 61, provenance 90.
Why it scored 76: MIT, with opencode's copyright kept in the licence file (30). The privacy policy (29 May 2026) names Kilo Code Inc. as controller, says data is stored in the United States and lists Stripe, OpenRouter, model providers, AppsFlyer and Sentry, but it doesn't mention the CLI's PostHog telemetry. PRIVACY.md in the repository is dated March 2025 and is silent on telemetry too. The terms (30 September 2026) are a contract with Anaconda, Inc. and grant a perpetual licence to use uploaded Customer Data to improve the services (13). `kilo console` is marked deprecated with no removal date, and updated terms apply after 30 days. No written deprecation policy found (8). The docs say telemetry is on by default and name the opt-out key in two places, without listing what is collected or where it goes (10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Domain age: kilo.ai, registered 2017-12-16 (8 years) (11 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
## 6. Schema & documentation, 90 out of 100, up to 1.6 more on the total
Why it scored 90: Framework reading. A JSON Schema for `kilo.jsonc` at `https://app.kilo.ai/config.json`, an OpenAPI file for the `kilo serve` API at `packages/sdk/openapi.json` and a CLI reference generated from the command definitions (25). `llms.txt` on kilo.ai and on the docs, the second listing a raw Markdown address for every page (10). The sandboxing page says when to use the sandbox, what it does not protect and how it differs from permissions (16). Permissions are `allow`, `ask` or `deny` with glob rules, `sandbox.network` and `--format` are enums, though the schema served on 8 October had no `sandbox` key (13). Config and CI samples and exit codes 0, 1 and 124, but we found no reference for the records `--format json` writes (11). A versioned changelog and dated GitHub releases (15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 7. Maintenance & community, 87 out of 100, up to 1.1 more on the total
Why it scored 87: 7.8.8 on 7 October 2026 (30). 37 stable releases since 10 July 2026, JetBrains tags aside (20). The newest issues carry area and triage labels from automation, but the 15 newest open issues had no or one comment each on 8 October, against 448 open issues and 147 open pull requests (15). `@kilocode/sdk` and `@kilocode/plugin` are at 7.8.8 with the CLI, and the VS Code extension ships from the same release workflow (13). CI, CodeQL and Dependabot security updates run, with version updates switched off because most dependencies arrive through merges from opencode (9).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- The terms of 30 September 2026 are a contract with Anaconda, Inc. on behalf of itself and affiliates including Kilo Code Inc., and trust.kilo.ai redirects to trust.anaconda.com. We didn't read an announcement of the relationship, and the lead named only Kilo Code as vendor
- Whether the SOC 2 Type 2 report listed on Anaconda's trust centre covers Kilo's services. The page has a Kilo Code section we couldn't read in full
- Which properties the PostHog events carry. We read the event names and the client, not every call site
- Whether Kilo runs a paid bug bounty. The security page cites HackerOne's standards and names no rewards
- Unchecked: the Kilo Pass Pro and Expert prices, which the pricing page draws by script. Only the $19 entry price was in the page text
- Unchecked: where exit code 124 is set. The docs list it and `kilo run` shows no timeout flag
- Unchecked: the first release date of `@kilocode/cli` on npm, and whether a Python SDK is published (the repository has a publish workflow for one)
- The repository is a fork of opencode. How quickly upstream security fixes reach Kilo releases wasn't measured
## Weaknesses
- Telemetry to PostHog is on by default, and the privacy policy and PRIVACY.md don't mention it
- The sandbox is off by default and unavailable on Windows
- `kilo run` lists no flag for a turn, time or cost limit
- The terms grant a perpetual licence to use uploaded Customer Data to improve Kilo's services
- SECURITY.md still says the CLI has no sandbox, and the changelog has no dates or breaking-change headings
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Set `sandbox.enabled` to true in the global `kilo.jsonc` before `kilo run --auto`. `--auto` approves every permission request not explicitly denied
- Set `experimental.openTelemetry` to false, or `KILO_TELEMETRY_LEVEL` to a value other than `all`, to stop telemetry
- Add needed hosts to `sandbox.allowed_hosts` in global config. MCP tool calls are unavailable while network restriction is on
- Without `--auto` a non-interactive run rejects every permission prompt and exits 1
- Put provider keys in global config or the environment. `{env:VAR}` in a project `kilo.json` is ignored
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- The terms of 30 September 2026 are a contract with Anaconda, Inc. on behalf of itself and affiliates including Kilo Code Inc., and trust.kilo.ai redirects to trust.anaconda.com. We didn't read an announcement of the relationship, and the lead named only Kilo Code as vendor
- Whether the SOC 2 Type 2 report listed on Anaconda's trust centre covers Kilo's services. The page has a Kilo Code section we couldn't read in full
- Which properties the PostHog events carry. We read the event names and the client, not every call site
- Whether Kilo runs a paid bug bounty. The security page cites HackerOne's standards and names no rewards
- Unchecked: the Kilo Pass Pro and Expert prices, which the pricing page draws by script. Only the $19 entry price was in the page text
- Unchecked: where exit code 124 is set. The docs list it and
kilo runshows no timeout flag - Unchecked: the first release date of
@kilocode/clion npm, and whether a Python SDK is published (the repository has a publish workflow for one) - The repository is a fork of opencode. How quickly upstream security fixes reach Kilo releases wasn't measured
Sources 28
- repository README (install, autonomous mode) github.com · seen 2026-10-08
- CLI docs (permissions, autonomous mode, exit codes, telemetry) kilo.ai · seen 2026-10-08
- CLI command reference (docs source) github.com · seen 2026-10-08
- sandboxing (docs source) github.com · seen 2026-10-08
- auto-approving actions and defaults (docs source) github.com · seen 2026-10-08
- settings page, telemetry default (docs source) github.com · seen 2026-10-08
- MCP in the CLI (docs source) github.com · seen 2026-10-08
- telemetry client source github.com · seen 2026-10-08
- default permission rules in source github.com · seen 2026-10-08
- CLI changelog github.com · seen 2026-10-08
- releases (GitHub API) api.github.com · seen 2026-10-08
- workflow runs on main (GitHub API) api.github.com · seen 2026-10-08
- open issues github.com · seen 2026-10-08
- repository security advisories (none published) github.com · seen 2026-10-08
- SECURITY.md github.com · seen 2026-10-08
- PRIVACY.md github.com · seen 2026-10-08
- auto-close workflow github.com · seen 2026-10-08
- npm package registry.npmjs.org · seen 2026-10-08
- pricing kilo.ai · seen 2026-10-08
- terms of service kilo.ai · seen 2026-10-08
- privacy policy kilo.ai · seen 2026-10-08
- security disclosure page kilo.ai · seen 2026-10-08
- security.txt kilo.ai · seen 2026-10-08
- llms.txt for the docs kilo.ai · seen 2026-10-08
- config JSON Schema app.kilo.ai · seen 2026-10-08
- status page incidents status.kilo.ai · seen 2026-10-08
- trust centre (trust.kilo.ai redirects here) trust.anaconda.com · seen 2026-10-08
- domain registration (RDAP) rdap.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Freemium $19 / mo The CLI is free and MIT-licensed, and needs no Kilo account with your own key or a local model. Kilo Gateway credits are billed at provider rates with a 5 per cent fee on credit purchases. Kilo Pass starts at $19 a month, Teams is $15 a user a month and Enterprise is quoted. The pricing page says the free tier needs no card.
Prices
| Item | Price | Unit | Note |
|---|---|---|---|
| Kilo Pass, entry tier | $19 | per month (plan) | monthly model credits with bonus credits, optional |
| Teams plan | $15 | per seat per month | model use billed separately at provider rates |
Compared across listings on the price index.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/kilo-code-cli.xml, or this listing's score history at history.json.
Connect
Install
npm install -g @kilocode/cli # or: brew install Kilo-Org/tap/kilo
Headless / CI
{
"command": "kilo run --auto --format json \"$TASK\""
}
Compare with
goose BBQwen Code BBGemini CLI BBOpenHands BBOpenCode BClaude Code C
Head to head Aider vs Kilo Code CLI · Amp vs Kilo Code CLI · Claude Code vs Kilo Code CLI · Cline vs Kilo Code CLI · Cursor CLI vs Kilo Code CLI · Devin vs Kilo Code CLI · Pi vs Kilo Code CLI · Gemini CLI vs Kilo Code CLI · GitHub Copilot CLI vs Kilo Code CLI · goose vs Kilo Code CLI · Kilo Code CLI vs Kiro CLI · Kilo Code CLI vs OpenAI Codex · Kilo Code CLI vs OpenCode · Kilo Code CLI vs OpenHands · Kilo Code CLI vs Prime Agent · Kilo Code CLI vs Qwen Code · Kilo Code CLI vs Paperclip
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| goose Agentic AI Foundation (originally Block) | BB | 73.9 | agent.harness agent.mcp-client agent.multi-agent | no |
| Qwen Code Alibaba (Qwen team) | BB | 72.4 | agent.harness agent.mcp-client agent.multi-agent | no |
| Gemini CLI Google | BB | 72 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenHands All Hands AI | BB | 70.8 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenCode Anomaly | B | 67.7 | agent.harness agent.mcp-client agent.multi-agent | no |
| Claude Code Anthropic | C | 61.9 | agent.harness agent.mcp-client agent.multi-agent | no |
Machine-readable
- JSON
/api/v1/tools/kilo-code-cli.json· historyhistory.json· badge/badges/kilo-code-cli.svg· changes feed/feeds/tools/kilo-code-cli.xml - Markdown
/tools/kilo-code-cli.md· slim/tools/kilo-code-cli.min.md(or sendAccept: text/markdown) - Fix list
/fixes/kilo-code-cli.md·/fixes/kilo-code-cli.json - From a terminal
anchor tool kilo-code-cli --md(the CLI) · over MCPget_tool {"slug": "kilo-code-cli"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/kilo-code-cli"><img src="https://www.anchorterminal.com/badges/kilo-code-cli.svg" alt="Kilo Code CLI on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/kilo-code-cli)<a href="https://www.anchorterminal.com/tools/kilo-code-cli">Kilo Code CLI on Anchor Terminal</a>It counts on a page on kilo.ai or one of its subdomains, or the README of github.com/Kilo-Org/kilocode.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "kilo-code-cli", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


