Prime Agent
by Prime Intellect Agent harness in Agent harnesses
Prime Intellect, Inc. · primeintellect.ai · status page · who's behind it
Prime Agent is an open-source coding and research agent from Prime Intellect, run from a terminal. The model works through a persistent Python REPL, spawns subagents as function calls and keeps sessions running in a background daemon.
Good for Long-running research and coding work where one model drives subagents, schedules and goals from code, and where the owner can isolate the machine.
Is this your product? Claim this listing or verify it
Assessment. Budgets for turns, tokens and time bound an autonomous run, and sessions survive a closed terminal through a supervising daemon. Model-written Python and shell commands run with the user's rights, with no approval step and no sandbox, and the Rust build on the main branch ships only as nightly betas.
Facts
- Auth
- None
- Pricing
- Free · Free · OSS
- x402
- No
- Licence
- MIT
- llms.txt
- not found
- Last release
- GitHub stars
- 22k
- Interfaces
- Terminal UI,
-pprint mode, and--mode text|json|rpc|acp|daemonper the argument parser. Daemon commandsagents,attach,status,doctor,schedule,shutdown - Built-in tools
bash,editandipython. Subagents, compaction, goals, skills and MCP calls are Python functions in the persistent REPL- Approvals
- None found. Commands and edits run with the user's rights. MCP tools can be limited with
enabledToolsanddisabledTools - Sandbox
- None. The README recommends an external sandbox or restricted environment for untrusted code or instructions
- Network
- No egress controls found.
--offlineexists as a flag - MCP client
- stdio and HTTP servers through
prime-agent mcp add|list|get|remove, OAuth through/mcp login, and a built-in service catalogue - Models
/loginfor a subscription or an API-key provider. Provider code for Anthropic, OpenAI, Google, OpenRouter, Mistral, Bedrock, Azure OpenAI and Prime Inference- Self-improvement
/refineapplies small updates to supplemental prompts, memories, skill descriptions and subagent specifications, with snapshots for rollback. The base system prompt is not rewritten- Telemetry
- On by default, pseudonymous installation id, primitive values only, sent to api.primeintellect.ai and forwarded to PostHog. Off with
/telemetry off,PRIME_AGENT_TELEMETRY=0,DO_NOT_TRACK=1or offline mode - Release channels
- Stable v0.9.8 of 29 September 2026 (TypeScript build). Nightly v0.9.9-beta.55 of 7 October 2026 (Rust build). Windows on the beta channel only
- Platforms
- macOS and Linux on x64 and arm64 as checksummed binaries, with an npm install needing Node.js 20.6 or later as the fallback
- First public release
- Announced on 5 August 2026 (https://www.primeintellect.ai/blog/prime-agent)
- Capabilities
- agent.harness agent.mcp-client agent.multi-agent
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- MIT licence, with CI on main passing on 8 October 2026 (fmt, clippy with warnings as errors, sharded tests, cargo-deny)
- Three model tools (bash, edit, ipython). MCP tools are found and called from Python, so their definitions stay out of the prompt
- Autonomous mode takes limits on turns, tokens, time and continuations, plus user-defined quality gates with retries
- A daemon supervises one worker per session, restarts it with backoff and restores from append-only JSONL session files
- Telemetry is disclosed on first run, carries primitive values only and has four documented ways to turn it off
Weaknesses
- No approval prompts and no sandbox. The README says the worker and kernel processes are not a security sandbox
- The stable channel (v0.9.8, 29 September 2026) is the TypeScript build. The Rust code on main ships only as nightly betas
- No documentation site for Prime Agent. Headless, JSON, RPC and ACP modes are described only in source and crate READMEs
- Usage telemetry is on by default, and the vendor privacy policy (updated 23 February 2024) does not describe it
- No SECURITY.md in the repository, and public issues and unsolicited pull requests are closed automatically
Before you call it notes for agents
- Run it in a disposable clone, container or VM. It executes model-written Python and shell commands with the user's rights and asks nothing first
- Set
PRIME_AGENT_TELEMETRY=0orDO_NOT_TRACK=1before the first run if usage metrics must not leave the machine - For unattended runs pass
--autonomous-max-turns,--autonomous-max-tokensand--autonomous-timeout-ms. Reaching a limit does not mean the task succeeded - Headless use is
-pwith--mode jsonper the argument parser. A provider key must already be configured, because/loginis interactive - The
-t/--tools,-nt/--no-toolsand-nbt/--no-builtin-toolsflags were removed and now fail as unknown options
Who's behind it provenance 61/100
- Legal entity namedPrime Intellect, Inc.20/20
- Domain ageprimeintellect.ai, no registry record we could read0/15
- Endpoint on the vendor's domainno hosted endpointn/a
- Terms of serviceread, states 5 of the 7 things a reader expects, and has 3 clauses that cost points2.3/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagestatus.primeintellect.ai10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service gives no date, states 5 of 7, 5 to know
TL;DR Gives no date. States 5 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access, limits on benchmarking, changes without notice, cut-off without notice or for any reason and arbitration or a class action waiver.
Restricts automated accesscosts points
You will not access the Site or the Marketplace Offerings through automated or non-human means, whether through a bot, script or otherwise
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Restricts benchmarking or competitive usecosts points
You are prohibited from using the Marketplace Offerings in any manner that competes with our services
A clause against publishing test results or using the service to build something that competes.
Says the terms or the service can change without noticecosts points
We also reserve the right to modify or discontinue all or part of the Marketplace Offerings without notice at any time.
A customer may not hear about a change before it applies.
Says access can be ended without notice or for any reason
We may terminate your use or participation in the Site and the Marketplace Offerings or delete your account and any content or information that you posted at any time, without warning, at our sole discretion.
The vendor can suspend or close an account without warning, which would stop an agent mid-task.
Requires arbitration or waives class actions
…are unable to resolve a Dispute through informal negotiations, the Dispute will be resolved through binding arbitration under the Commercial Arbitration Rules of the American Arbitration Association ("AAA") and, where appropriate, the AAA's Supplementary Procedures for Consumer Related Disputes ("AAA Consumer Rules"),…
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of Delaware
These Terms of Use and your use of the Site and the Marketplace Offerings are governed by and construed in accordance with the laws of the State of Delaware applicable to agreements made and to be entirely performed within the State of Delaware, without regard to its conflict of law principles.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the lesser of $500.00 and the fees paid in the 6 months before the claim
Notwithstanding anything to the contrary contained herein, our liability to you for any cause whatsoever and regardless of the form of the action, will at all times be limited to the lesser of the amount paid, if any, by you to us during the six (6) month period prior to any cause of action arising or $500.00 USD.
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
We may terminate your use or participation in the Site and the Marketplace Offerings or delete your account and any content or information that you posted at any time, without warning, at our sole discretion.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
We will alert you about any changes by updating the "Last updated" date of these Terms of Use, and you waive any right to receive specific notice of each such change.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Therefore, if your interactions are subject to such laws, you may not use this Site.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
The list of prohibited activities includes using a buying agent or purchasing agent to make purchases on the site.
Use a buying agent or purchasing agent to make purchases on the Site
Noted by a second reader on 2026-10-08.
Liability is limited to the lesser of the amount paid in the six months before the claim or 500 US dollars.
our liability to you for any cause whatsoever and regardless of the form of the action, will at all times be limited to the lesser of the amount paid, if any, by you to us during the six (6) month period prior to any cause of action arising or $500.00 USD.
Noted by a second reader on 2026-10-08.
Accepting the terms also means accepting the terms of any cloud service provider Prime Intellect uses to supply computing resources.
By agreeing to these Terms and Conditions, you explicitly agree to the terms and conditions of any cloud service providers we may utilize to provide computing resources.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 6,984 words
Privacy policy gives no date, states 7 of 8, 1 to know
TL;DR Gives no date. States 7 of the 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
Subject to applicable law, we may share your personal information with our marketing partners for permitted marketing purposes.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Policy ("Policy") is designed to help you understand how we collect, use, safeguard, share, and disclose your personal information in connection with our products and services.
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We will retain your personal information only for as long as is necessary for the purposes set out in this Policy.
Says when data sent to the service is deleted.
Says who else receives the data
We, or service providers that assist us in providing, maintaining, and operating our Services, may collect the following types of personal information from you:
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
To the extent we sell your personal information to third parties, you have the right to request that we disclose to you:
A plain statement either way.
Says what rights people have over their data
Depending on the applicable law where you reside, you may exercise the right to access, or correct your personal information that we have collected or has been previously provided to us.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@primeintellect.ai
If you have any questions about this Privacy Policy, want to exercise a privacy right with respect to your personal information, or have a privacy-related complaint, please contact us by email at privacy@primeintellect.ai or by writing us at - Prime Intellect, Inc.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
We rely primarily on the European Commission's Standard Contractual Clauses to facilitate the international and onward transfer of personal information collected in the European Economic Area ("EEA"), the United Kingdom and Switzerland (collectively "European Personal Information"), to the extent the recipients of the…
The countries data goes to and the safeguard used.
Prime Intellect reserves the right to publish a request sent to it by support email or a feedback mechanism.
If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users.
Noted by a second reader on 2026-10-08.
The policy does not cover personal information that Prime Intellect processes as a data processor for its cloud, colocation and hardware clients.
This Policy does not apply to Prime's processing when we are a data processor.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,671 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The site footer, terms and privacy policy name Prime Intellect, Inc. of Dover, Delaware. The repository LICENSE names Prime Intellect Ltd. as copyright holder.
www.primeintellect.ai/.well-known/security.txt returned 404 on 8 October 2026. A security policy with a reporting address is at https://www.primeintellect.ai/security.
The status page covers Prime Intellect's hosted platform (API, inference, sandboxes), not the locally run agent.
The LICENSE adds that the software is a port of the Prime Agent TypeScript product, originally copyright 2025 Mario Zechner, used under the MIT licence. GitHub's licence detector reports the file as unrecognised.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:26 UTC
- Vendor status page unknown, no machine-readable status found · 1 hour ago
- github
PrimeIntellect-ai/prime-agentv0.9.8, released 2026-09-29 - GitHub stars 22k
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/prime-agent.json
Notable
- The README warns that Prime Agent executes model-generated Python and project commands with the user's permissions, and that its worker and kernel processes are not a security sandbox source
- The stable channel pointer is v0.9.8, the TypeScript build. The installer source says no Rust stable release exists yet, so the Rust code on main ships as nightly betas source
- Usage telemetry is on by default and disclosed on first run, with
/telemetry off,PRIME_AGENT_TELEMETRY=0andDO_NOT_TRACK=1as opt-outs source - Public issues from unapproved contributors and pull requests from unvouched contributors are closed automatically, and intake is through GitHub Discussions source
- Prime Intellect announced Prime Agent on 5 August 2026 source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.0 | |
Read with the local-software lines. The vendor's installer fetches checksummed binaries for macOS and Linux on x64 and arm64, with an npm install needing Node.js 20.6 or later as the fallback, but the stable pointer is the TypeScript build while the Rust code on main ships only on the nightly channel, and Windows builds are beta only (17). A public CI workflow runs fmt, clippy with warnings as errors, sharded workspace tests and cargo-deny, and its badge read passing on 8 October 2026 (25). 20 open issues and 91 open pull requests on 8 October. Issues hold only work the maintainers accepted, and the Discussions bug category lists reports from the past two weeks of session-worker crashes, truncated RPC output and provider hangs, whose reply state we did not read (15). Stable releases carry written notes and changes are recorded as fragments in .changes, including the removal of the --tools flags, but there is no changelog file, the nightly notes are boilerplate and the project is at 0.x (8). Version 0.9.8, and the Rust build is a beta (0). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 6.8 | |
Harness reading of the framework line. --mode json emits a session event stream and rpc and acp modes exist, but we found no published schema or reference for them outside the source (10). docs.primeintellect.ai serves an llms.txt that has no Prime Agent page (0). The README states what the agent does, how it differs and that it is not a sandbox, and the bundled skills say when to use each function (10). CLI values are validated with messages that list the valid choices, and MCP tool schemas are read live from the server (7). The README gives the install line and seven commands, and the MCP skill documents its error types, but there is no headless or configuration guide (5). Versioned releases with notes for stable versions, none of substance for nightlies (10). | |||
| Agent ergonomics | 13%16.2 | 11.9 | |
Harness reading, scored on what a person or pipeline driving it has to supply. The model sees three tools (bash, edit, ipython), and MCP tools are searched, described and called from Python instead of being loaded into the prompt (23). Autonomous mode has limits for turns, tokens, time and continuations, a goal token budget and automatic compaction (17). A JSON event stream and exit codes for headless runs, described in the crate README and source only (10). Sessions resume, the daemon restarts workers and restores from JSONL files, refinements can be rolled back and quality gates retry (15). One command starts it and no SDK was found. A provider must be chosen through an interactive /login or supplied as a key first (8). | |||
| Security & auth | 14%17.5 | 8.8 | |
Harness reading of the framework checklist, as used for the other harnesses. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Usage telemetry is on by default. It is pseudonymous, limited to primitive values with no prompts, tool content or file paths per the source, disclosed on first run and mirrored to a local telemetry.jsonl (18). No approval prompts were found and there is no sandbox, which the README states. MCP tools can be limited with enabledTools and disabledTools, and the agent is told to recommend a connection, not make one (4). The README tells users to work only with trusted repositories, instructions and skills. No detection or mitigation found (5). Append-only JSONL session files, a prime-agent incident timeline command and the local telemetry mirror (12). The vendor's security policy has a reporting address, safe harbour, response times and discretionary rewards, scoped to its website and API. The repository has no SECURITY.md and no published advisories, CONTRIBUTING.md says to report privately without naming an address, and security.txt returned 404. cargo-deny runs in CI (11). | |||
| Payments & pricing | 10%12.5 | 7.5 | |
| Self-hosted rule. No payment protocol (0). Free and MIT-licensed with nothing to buy, so 20, 20 and 20 on the last three lines. The model provider is paid separately. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.9 | |
| Nightly v0.9.9-beta.55 on 7 October 2026 and stable v0.9.8 on 29 September 2026 (30). At least 12 stable tags since 20 August 2026 and 55 nightly betas since 30 September (20). The main branch had at least 200 commits between 22 September and 8 October, and Discussions had new threads daily in October, but issues from unapproved contributors and unsolicited pull requests are closed automatically and we could not read reply times (14). Binaries for five targets from one release workflow and Homebrew definitions in the repository. No SDK and no registry package found (8). A pinned toolchain, a committed lockfile, cargo-deny with two triaged advisory exceptions reviewed on 17 September 2026, and CI passing. An open issue (#3292) reports npm audit findings for the 0.9.8 install, which we did not verify (7). | |||
| Transparency & trusteditorial 67, provenance 61 | 7%8.8 | 5.6 | |
| MIT in the LICENSE file and Cargo.toml, with a notice that the code is a port of a TypeScript product originally copyright Mario Zechner (30). The first-run notice and the telemetry crate README say what is sent and what is excluded, and name the endpoint and PostHog, but the vendor privacy policy is dated 23 February 2024, does not describe agent telemetry and gives no retention period for it (12). No deprecation policy found. Removed flags are recorded in change fragments (5). Telemetry is disclosed with a setting, a command and two environment variables to turn it off (20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 60.5 · C | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 20 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Prime Agent, or have the agent fetch /fixes/prime-agent.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Prime Agent From Anchor Terminal's listing at https://www.anchorterminal.com/tools/prime-agent, the October 2026 research run, assessed 8 October 2026. Grade C, 60.5 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Prime Agent: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Schema & documentation, 42 out of 100, up to 9.4 more on the total Why it scored 42: Harness reading of the framework line. `--mode json` emits a session event stream and `rpc` and `acp` modes exist, but we found no published schema or reference for them outside the source (10). docs.primeintellect.ai serves an llms.txt that has no Prime Agent page (0). The README states what the agent does, how it differs and that it is not a sandbox, and the bundled skills say when to use each function (10). CLI values are validated with messages that list the valid choices, and MCP tool schemas are read live from the server (7). The README gives the install line and seven commands, and the MCP skill documents its error types, but there is no headless or configuration guide (5). Versioned releases with notes for stable versions, none of substance for nightlies (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 2. Security & auth, 50 out of 100, up to 8.8 more on the total Why it scored 50: Harness reading of the framework checklist, as used for the other harnesses. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. Usage telemetry is on by default. It is pseudonymous, limited to primitive values with no prompts, tool content or file paths per the source, disclosed on first run and mirrored to a local `telemetry.jsonl` (18). No approval prompts were found and there is no sandbox, which the README states. MCP tools can be limited with `enabledTools` and `disabledTools`, and the agent is told to recommend a connection, not make one (4). The README tells users to work only with trusted repositories, instructions and skills. No detection or mitigation found (5). Append-only JSONL session files, a `prime-agent incident` timeline command and the local telemetry mirror (12). The vendor's security policy has a reporting address, safe harbour, response times and discretionary rewards, scoped to its website and API. The repository has no SECURITY.md and no published advisories, CONTRIBUTING.md says to report privately without naming an address, and security.txt returned 404. cargo-deny runs in CI (11). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 3. Reliability, 65 out of 100, up to 7 more on the total Why it scored 65: Read with the local-software lines. The vendor's installer fetches checksummed binaries for macOS and Linux on x64 and arm64, with an npm install needing Node.js 20.6 or later as the fallback, but the stable pointer is the TypeScript build while the Rust code on main ships only on the nightly channel, and Windows builds are beta only (17). A public CI workflow runs fmt, clippy with warnings as errors, sharded workspace tests and cargo-deny, and its badge read passing on 8 October 2026 (25). 20 open issues and 91 open pull requests on 8 October. Issues hold only work the maintainers accepted, and the Discussions bug category lists reports from the past two weeks of session-worker crashes, truncated RPC output and provider hangs, whose reply state we did not read (15). Stable releases carry written notes and changes are recorded as fragments in `.changes`, including the removal of the `--tools` flags, but there is no changelog file, the nightly notes are boilerplate and the project is at 0.x (8). Version 0.9.8, and the Rust build is a beta (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Payments & pricing, 60 out of 100, up to 5 more on the total Why it scored 60: Self-hosted rule. No payment protocol (0). Free and MIT-licensed with nothing to buy, so 20, 20 and 20 on the last three lines. The model provider is paid separately. The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 5. Agent ergonomics, 73 out of 100, up to 4.4 more on the total Why it scored 73: Harness reading, scored on what a person or pipeline driving it has to supply. The model sees three tools (bash, edit, ipython), and MCP tools are searched, described and called from Python instead of being loaded into the prompt (23). Autonomous mode has limits for turns, tokens, time and continuations, a goal token budget and automatic compaction (17). A JSON event stream and exit codes for headless runs, described in the crate README and source only (10). Sessions resume, the daemon restarts workers and restores from JSONL files, refinements can be rolled back and quality gates retry (15). One command starts it and no SDK was found. A provider must be chosen through an interactive `/login` or supplied as a key first (8). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Transparency & trust, 64 out of 100, up to 3.2 more on the total Made of editorial 67, provenance 61. Why it scored 64: MIT in the LICENSE file and Cargo.toml, with a notice that the code is a port of a TypeScript product originally copyright Mario Zechner (30). The first-run notice and the telemetry crate README say what is sent and what is excluded, and name the endpoint and PostHog, but the vendor privacy policy is dated 23 February 2024, does not describe agent telemetry and gives no retention period for it (12). No deprecation policy found. Removed flags are recorded in change fragments (5). Telemetry is disclosed with a setting, a command and two environment variables to turn it off (20). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: primeintellect.ai, no registry record we could read (0 of 15) - Terms of service: read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points (2.3 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10) - security.txt: not found (0 of 10) ## 7. Maintenance & community, 79 out of 100, up to 1.8 more on the total Why it scored 79: Nightly v0.9.9-beta.55 on 7 October 2026 and stable v0.9.8 on 29 September 2026 (30). At least 12 stable tags since 20 August 2026 and 55 nightly betas since 30 September (20). The main branch had at least 200 commits between 22 September and 8 October, and Discussions had new threads daily in October, but issues from unapproved contributors and unsolicited pull requests are closed automatically and we could not read reply times (14). Binaries for five targets from one release workflow and Homebrew definitions in the repository. No SDK and no registry package found (8). A pinned toolchain, a committed lockfile, cargo-deny with two triaged advisory exceptions reviewed on 17 September 2026, and CI passing. An open issue (#3292) reports npm audit findings for the 0.9.8 install, which we did not verify (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - Unchecked: reply times and maintainer answers in Discussions and on the 20 open issues (the GitHub API was rate-limited for our address on 8 October, and the HTML lists do not show replies) - Unchecked: the full release list beyond the first page, so the count of stable releases in 90 days comes from git tags in a shallow clone (12 from v0.7.4 on 20 August 2026) - Unchecked: whether trace sharing through `/traces` is off until the user turns it on. The source describes a settings flag and we did not trace its default - Unchecked: the npm audit findings reported in issue #3292 for the 0.9.8 install - Unchecked: whether the Homebrew cask and formula in the repository are published to a tap - The scout wrote that every GitHub release is a pre-release. v0.9.8 of 29 September 2026 is marked Latest and is a stable release, of the TypeScript build. The Rust build on main is nightly only - The scout wrote that the README does not mention MCP or a headless mode. That is right for the README, but the source has an MCP client, `-p` print mode and `--mode json|rpc|acp`, none documented for users - The LICENSE names Prime Intellect Ltd. while the website and terms name Prime Intellect, Inc. Which entity publishes the agent is not stated - No documentation was found for the JSON event stream, the RPC protocol or the settings file ## Weaknesses - No approval prompts and no sandbox. The README says the worker and kernel processes are not a security sandbox - The stable channel (v0.9.8, 29 September 2026) is the TypeScript build. The Rust code on main ships only as nightly betas - No documentation site for Prime Agent. Headless, JSON, RPC and ACP modes are described only in source and crate READMEs - Usage telemetry is on by default, and the vendor privacy policy (updated 23 February 2024) does not describe it - No SECURITY.md in the repository, and public issues and unsolicited pull requests are closed automatically ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Run it in a disposable clone, container or VM. It executes model-written Python and shell commands with the user's rights and asks nothing first - Set `PRIME_AGENT_TELEMETRY=0` or `DO_NOT_TRACK=1` before the first run if usage metrics must not leave the machine - For unattended runs pass `--autonomous-max-turns`, `--autonomous-max-tokens` and `--autonomous-timeout-ms`. Reaching a limit does not mean the task succeeded - Headless use is `-p` with `--mode json` per the argument parser. A provider key must already be configured, because `/login` is interactive - The `-t/--tools`, `-nt/--no-tools` and `-nbt/--no-builtin-tools` flags were removed and now fail as unknown options ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- Unchecked: reply times and maintainer answers in Discussions and on the 20 open issues (the GitHub API was rate-limited for our address on 8 October, and the HTML lists do not show replies)
- Unchecked: the full release list beyond the first page, so the count of stable releases in 90 days comes from git tags in a shallow clone (12 from v0.7.4 on 20 August 2026)
- Unchecked: whether trace sharing through
/tracesis off until the user turns it on. The source describes a settings flag and we did not trace its default - Unchecked: the npm audit findings reported in issue #3292 for the 0.9.8 install
- Unchecked: whether the Homebrew cask and formula in the repository are published to a tap
- The scout wrote that every GitHub release is a pre-release. v0.9.8 of 29 September 2026 is marked Latest and is a stable release, of the TypeScript build. The Rust build on main is nightly only
- The scout wrote that the README does not mention MCP or a headless mode. That is right for the README, but the source has an MCP client,
-pprint mode and--mode json|rpc|acp, none documented for users - The LICENSE names Prime Intellect Ltd. while the website and terms name Prime Intellect, Inc. Which entity publishes the agent is not stated
- No documentation was found for the JSON event stream, the RPC protocol or the settings file
Sources 28
- repository main branch (cloned at 967eb13) github.com · seen 2026-10-08
- README github.com · seen 2026-10-08
- LICENSE github.com · seen 2026-10-08
- contribution policy github.com · seen 2026-10-08
- development rules, surface contract and telemetry rule github.com · seen 2026-10-08
- telemetry crate README github.com · seen 2026-10-08
- first-run telemetry notice (source) github.com · seen 2026-10-08
- CLI argument parser github.com · seen 2026-10-08
- CLI crate README, print and JSON modes github.com · seen 2026-10-08
- MCP skill github.com · seen 2026-10-08
- CI workflow github.com · seen 2026-10-08
- CI badge (passing) github.com · seen 2026-10-08
- releases github.com · seen 2026-10-08
- latest release, v0.9.8 github.com · seen 2026-10-08
- security tab (no policy, no advisories) github.com · seen 2026-10-08
- open issues github.com · seen 2026-10-08
- discussions github.com · seen 2026-10-08
- repository metadata (stars, licence detection) api.github.com · seen 2026-10-08
- installer script app.primeintellect.ai · seen 2026-10-08
- stable channel pointer pub-728493de92a943e2a9b2d17b4719f318.r2.dev · seen 2026-10-08
- nightly channel pointer pub-728493de92a943e2a9b2d17b4719f318.r2.dev · seen 2026-10-08
- launch announcement, 5 August 2026 primeintellect.ai · seen 2026-10-08
- vendor security policy primeintellect.ai · seen 2026-10-08
- privacy policy primeintellect.ai · seen 2026-10-08
- terms of service primeintellect.ai · seen 2026-10-08
- security.txt (404) primeintellect.ai · seen 2026-10-08
- vendor docs index (no Prime Agent page) docs.primeintellect.ai · seen 2026-10-08
- status page status.primeintellect.ai · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Free Free · OSS Free and MIT-licensed, with nothing to buy for the agent itself. The model provider is paid separately, and Prime Intellect's own inference service is one of the providers.
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/prime-agent.xml, or this listing's score history at history.json.
Connect
Install
curl -fsSL https://app.primeintellect.ai/prime-agent/install.sh | sh
Compare with
goose BBGemini CLI BBOpenHands BBOpenCode BClaude Code CCline C
Head to head Aider vs Prime Agent · Claude Code vs Prime Agent · Cline vs Prime Agent · Cursor CLI vs Prime Agent · Pi vs Prime Agent · Gemini CLI vs Prime Agent · GitHub Copilot CLI vs Prime Agent · goose vs Prime Agent · OpenAI Codex vs Prime Agent · OpenCode vs Prime Agent · OpenHands vs Prime Agent · Paperclip vs Prime Agent
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| goose Agentic AI Foundation (originally Block) | BB | 73.9 | agent.harness agent.mcp-client agent.multi-agent | no |
| Gemini CLI Google | BB | 72 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenHands All Hands AI | BB | 70.8 | agent.harness agent.mcp-client agent.multi-agent | no |
| OpenCode Anomaly | B | 67.7 | agent.harness agent.mcp-client agent.multi-agent | no |
| Claude Code Anthropic | C | 61.9 | agent.harness agent.mcp-client agent.multi-agent | no |
| Cline Cline Bot Inc. | C | 60.4 | agent.harness agent.mcp-client agent.multi-agent | no |
Machine-readable
- JSON
/api/v1/tools/prime-agent.json· historyhistory.json· badge/badges/prime-agent.svg· changes feed/feeds/tools/prime-agent.xml - Markdown
/tools/prime-agent.md· slim/tools/prime-agent.min.md(or sendAccept: text/markdown) - Fix list
/fixes/prime-agent.md·/fixes/prime-agent.json - From a terminal
anchor tool prime-agent --md(the CLI) · over MCPget_tool {"slug": "prime-agent"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/prime-agent"><img src="https://www.anchorterminal.com/badges/prime-agent.svg" alt="Prime Agent on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/prime-agent)<a href="https://www.anchorterminal.com/tools/prime-agent">Prime Agent on Anchor Terminal</a>It counts on a page on primeintellect.ai or one of its subdomains, or the README of github.com/PrimeIntellect-ai/prime-agent.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "prime-agent", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
