Model or dataset
shareAI-lab/Kode-CLI avatar
shareAI-lab/Kode-CLI

Kode CLI: a terminal coding agent that runs in YOLO mode by default

Kode CLI — Design for post-human workflows. One unit agent for every human & computer task.

5,228 stars777 forksTypeScriptApache-2.0

At a glance

What is it?
Kode CLI is a TypeScript terminal assistant from shareAI-lab that reads AGENTS.md instructions, delegates to subagents, and ships with permission checks disabled unless you pass --safe.
Who is it for?
Adopt Kode CLI if you work in a disposable checkout or container and want AGENTS.md-driven instructions plus @run-agent-name delegation in the terminal. Do not adopt it on a machine holding credentials or uncommitted work you cannot restore, because the README states it bypasses all permission checks by default.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 33 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem Kode CLI targets, and who it is actually for

Most terminal coding assistants assume a single conversation with a single model. Kode CLI takes the position that a task should be split: one model writes, another reviews, a subagent handles the part that needs a different context window. The README describes this as a "post-human workflow" and lists two syntaxes for it, @ask-model-name to consult a specific model and @run-agent-name to delegate to a specialized subagent. If your work involves long refactors where you want a second opinion without leaving the shell, that is the gap it fills.

The audience is narrower than the tagline suggests. Kode is a terminal program, not an IDE plugin, and it expects the user to be comfortable with npm global installs, environment variables, and shell commands. The README also warns against older question-answering models such as GPT-4o or Gemini 2.5 Pro, arguing they are tuned for answering rather than sustained autonomous execution. That framing tells you the intended user runs long, multi-step tasks and picks models accordingly.

Instruction discovery: how Kode CLI reads AGENTS.md and CLAUDE.md

The mechanism the README documents in most detail is instruction discovery, which it describes as Codex-compatible. Kode walks from the Git repository root down to the current working directory. In each directory it prefers AGENTS.override.md over AGENTS.md, and reads at most one file per directory. The discovered files are concatenated root to leaf, and the combined size is capped at 32 KiB by default. That cap is configurable through the KODE_PROJECT_DOC_MAX_BYTES environment variable.

There is a legacy path as well. If a CLAUDE.md exists in the current directory, Kode reads it as an instruction file, and it reads .claude directories when present. The repository points to docs/compatibility.md for the details. This matters for teams migrating from Claude-oriented tooling: the instructions you already wrote are not discarded, but the override precedence means an AGENTS.override.md can silently shadow the AGENTS.md sitting next to it.

The 32 KiB default is the constraint worth watching. In a monorepo with several nested instruction files, concatenation is root to leaf, so the leaf files are the ones that get truncated once the cap is hit. The README does not describe how truncation is reported to the user.

Installing Kode CLI and running a first delegated task

The README gives a single npm command for installation. It requires Node.js 20.18.1 or newer according to the engines field in package.json.

bash
npm install -g @shareai-lab/kode

After that the kode binary is on your PATH. The package also declares kwa, kd, mcp-cli and kode-acp as binaries, so a global install puts all five there.

If you are behind a slow or blocked registry, the README offers a mirror:

bash
npm install -g @shareai-lab/kode --registry=https://registry.npmmirror.com

Kode uses ripgrep for search. Per the README it is pulled in through per-platform optionalDependencies named @shareai-lab/kode-ripgrep-<platform>-<arch>. If you installed with --no-optional, you need a system rg or a KODE_RIPGREP_PATH pointing at one. The same pattern applies to an optional native binary package, @shareai-lab/kode-bin-<platform>-<arch>; without it, Kode falls back to the Node.js entry at dist/index.js.

Before your first real task, the README's security notice recommends enabling permission checks:

bash
kode --safe

Inside the prompt, the documented delegation syntax is @run-agent-name for a subagent and @ask-model-name to consult a specific model. The prompt completes slash commands, file paths, agents, configured models and shell commands, and accepting an agent or model result inserts the required @ prefix for you. If you want Kode to draft its own instruction file, the README says to use # Your documentation request, which generates and maintains AGENTS.md while preserving existing .claude workflows.

YOLO mode is the default, and that is the main limitation

The README states plainly that Kode runs in YOLO mode by default, equivalent to the --dangerously-skip-permissions flag, bypassing all permission checks. It recommends YOLO only for trusted, secure environments and non-critical projects, and it recommends kode --safe when working with important files or models of questionable capability.

This is a design choice, and it is a defensible one for a tool whose value comes from running multi-step tasks unattended. It is also the single fact that should decide whether you install it. A coding agent that edits files and runs shell commands without approval, pointed at a directory with production credentials in a .env file, has the same reach as your shell account. The README does not document a rollback mechanism for edits the agent makes, and no recent releases were retrieved to check whether one exists elsewhere.

The privacy section is more reassuring. Kode sends no product telemetry or analytics by default. Network requests happen only for features you invoke: model provider requests to endpoints you configure, the WebFetch and WebSearch tools, plugin marketplace downloads and OAuth flows, and an optional update check that is opt-in through autoUpdaterStatus: enabled. The .env.example in the repository is for production API tests and carries a warning not to commit .env files. It defines PRODUCTION_TEST_MODE plus TEST_GPT5_API_KEY, TEST_GPT5_BASE_URL, TEST_MINIMAX_API_KEY and TEST_MINIMAX_BASE_URL, which shows the provider surface is OpenAI-compatible endpoints rather than a fixed vendor.

How Kode CLI's approach differs from a single-model assistant

The obvious alternative is a single-model terminal agent that keeps one conversation and one context. The difference is structural rather than cosmetic. A single-conversation agent spends its context on everything: the task, the tool output, the mistakes. Kode's @ask-model-name and @run-agent-name split that work, so a review pass can run in a separate context from the implementation pass, and the subagent system is described in the README as handling delegation and task orchestration.

The cost of that structure is configuration. You are choosing models, wiring provider endpoints, and deciding which agent handles what. The README's own advice to avoid Q&A-focused models means the model choice is not neutral either. A user who wants to type a request and get an answer without thinking about routing will find the multi-model framing to be overhead rather than a feature.

Kode also carries the AGENTS.md badge and states the format is used by 60k+ open-source projects, with an explicit legacy path for .claude and CLAUDE.md. For a team already standardised on AGENTS.md, that is a compatibility argument. For a team with no instruction files at all, the discovery walk has nothing to read and the feature is inert until someone writes one.

Packaging, licence and what an upgrade actually costs

The package is published as @shareai-lab/kode under Apache-2.0, with publishConfig set to public access and provenance enabled. Apache-2.0 permits commercial use and modification; it also carries a patent grant and requires that notices be preserved. That is a general description of the licence text, not legal advice for your situation.

The distribution model is the part that affects upgrades. The README's update log for 2025-12-22 describes npm plus optionalDependencies for all platforms, with the per-platform native binary package preferred and Node.js as a fallback, and standalone binaries also published on GitHub Releases. The README states Kode does not download anything from GitHub during install, and that the standalone binaries are separate from npm. So an upgrade is an npm install, not a self-update from a release page.

Upgrade cost is mostly the optionalDependencies story. If you install with --no-optional or --omit=optional, you lose both the bundled ripgrep and the native CLI binary and fall back to Node.js plus a system rg. The repository's Dockerfile does exactly this: it installs ripgrep via apk, then installs the packed tarball with --omit=optional --ignore-scripts, and sets ENTRYPOINT to kode. That is a working recipe for a reproducible image, and it is also a reminder that the fast path and the portable path are different installs. The repository lists no release notes beyond the update log, so version-to-version migration guidance is not documented.

Editorial conclusion

Adopt Kode CLI if you work in a disposable checkout or container and want AGENTS.md-driven instructions plus @run-agent-name delegation in the terminal. Do not adopt it on a machine holding credentials or uncommitted work you cannot restore, because the README states it bypasses all permission checks by default. Before trusting it, run kode --safe once and confirm the approval prompts appear, then check that your provider endpoint is one you configured rather than a default.

Frequently asked questions

What is Kode CLI?

Kode CLI is a terminal AI assistant from shareAI-lab that understands a codebase, edits files, runs commands and automates workflows. It is published on npm as @shareai-lab/kode and is written in TypeScript.

What Kode CLI commands and flags does the README document?

The README documents kode --safe for enabling permission checks, @run-agent-name for delegating to a subagent, @ask-model-name for consulting a specific model, and # Your documentation request for generating an AGENTS.md file. The package also ships kwa, kd, mcp-cli and kode-acp binaries.

How do I install Kode CLI?

Run npm install -g @shareai-lab/kode. Node.js 20.18.1 or newer is required. Users in China can add --registry=https://registry.npmmirror.com if the default registry is unreachable.

Does Kode CLI run commands without asking for permission?

Yes by default. The README states Kode runs in YOLO mode, equivalent to --dangerously-skip-permissions, and recommends kode --safe for important files or models of questionable capability.

Official sources

  1. Issues
  2. License: Apache-2.0
  3. README
  4. shareAI-lab/Kode-CLI on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/shareai-lab-kode-cli.svg)](https://hysenlabs.com/projects/shareai-lab-kode-cli)