Coding agent

Gemini CLI

Google's open terminal agent with sandboxing, subagents, and rollback.

Status
Active
License
Apache-2.0
Evidence
Documented + code-verifiable + independently measured configuration, 20 sources
Product record checked
2026-08-20

At a glance

An Apache-2.0 terminal agent for Gemini with interactive and non-interactive modes, MCP, Agent Skills, policy controls, optional OS or container sandboxing, specialized subagents, worktrees, and file-aware rewind and restore.

Good choice if

  • Organizations retaining Gemini CLI through Gemini Code Assist Standard or Enterprise, Google Cloud, or paid enterprise API access
  • Headless automation with structured output and explicit policy controls
  • Tasks that benefit from subagents, worktrees, sandbox profiles, and file rollback

Check before choosing

  • Since June 18, 2026, Google AI free, Pro, and Ultra consumer accounts are served by Antigravity CLI instead; Gemini CLI remains supported for enterprise and paid API access
  • Model access remains centered on Gemini rather than a multi-provider model catalog
  • OS and container sandboxing is optional; the macOS default profile allows broad reads and network while constraining writes, so profiles must match the task
See 5 more considerations
  • Checkpointing and experimental Auto Memory are off by default; memory candidates require review and may send selected local transcript content to the configured model
  • The browser agent is disabled by default, uses a persistent Chrome profile by default, and changes behavior or availability under Seatbelt and container sandboxes
  • Worktrees isolate checkouts rather than processes, credentials, or network access
  • The policy engine's project-level Workspace tier is currently non-functional, so repository policy files do not enforce tool decisions; use User or Admin policies until that tier is restored
  • The repository contains extensive project-owned eval assets, but no complete independent harness benchmark result is imported

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Reusable skills
DocumentedProduct-supported reusable skill packagesSource · checked 2026-08-01Support does not establish portability, package quality, safety, or adoption.
Local models
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Browser control
DocumentedBuilt-in or product-supported browser controlSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Isolated execution
OptionalOptional OS or container sandbox profilesSource · checked 2026-07-27Profiles and platform support change the effective filesystem and network boundary.
Undo file changes
DocumentedProduct-supported file or session rollbackSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.

Getting started

For supported enterprise or paid API access, install `@google/gemini-cli`, authenticate through Google Cloud or an eligible API key, then configure sandbox and checkpointing policy.

Open official documentation

Classification and operating model

Category fit and technical mechanisms are evidence records, not product-quality scores.

Category fit
Qualifies, 4/4 criteria
Operating model
7/7 layers documented
Inspect category criteria and operating mechanismsFirst-party records

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced
  • Adaptive agent loop

    Documented

    The system repeatedly observes results and chooses the next action instead of following a fixed one-pass graph.

  • Repository tool execution

    Documented

    The system can use tools to inspect and change a repository or its execution environment.

  • Task-aware context management

    Documented

    The runtime assembles, updates, compacts, retrieves, or persists task-relevant context while work proceeds.

  • Model-independent runtime control

    Documented

    Permissions, budgets, interruption, policy, or stop controls operate outside the model's own text generation.

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationSandbox availableDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible + browserDocumented mechanism, not a performance score.
  • Context & statePersistent stateDocumented mechanism, not a performance score.
  • Lifecycle & recoveryCheckpoint/rewindDocumented mechanism, not a performance score.
  • ObservabilityStructured tracesDocumented mechanism, not a performance score.
  • VerificationTool-assistedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.

Measured and public context

Configuration-specific measurements and source-native activity stay separate from general product capability.

Inspect code audit, measured configurations, and ecosystem signalsContext, not a product score

Public code audit

5/5public artifacts present
Security policy
Present at inspected commit
CI workflow
Present at inspected commit
Automated tests
Present at inspected commit
Evaluation assets
Present at inspected commit
Contributor documentation
Present at inspected commit

The v0.52.0 tree contains 963 test-like files, 47 workflows, and 47 eval-like assets spanning behavior, memory, safety, integration, and performance. They are project-owned development evidence without a complete independent model × harness × environment × budget × attempts result, so no product score is imported; hosted Gemini services remain outside the source audit.

Inspect commit d14583b926769bd98f807cdc6b1ca50e91ae26ec, checked 2026-07-27
Context, not quality

Public ecosystem signals

Source-native observations for exact mapped artifacts and reviewed stable release trains. Different units and populations stay separate, and missing coverage is never treated as zero.

View this harness in Usage
  • Latest stable releasev0.58.0Released 2026-09-01; 13 stable releases in 90 daysOpen release
  • Homebrew 30d events7.17KFormula: gemini-cliOpen artifact
  • npm last-month downloads1.45MPackage: @google/gemini-cliOpen artifact
  • Release asset downloads21.97K35 stable releases; 69 matched assetsOpen artifact
  • VS Code installs1.07MExtension: Google.gemini-cli-vscode-ide-companionOpen artifact
  • Open VSX downloads1.57MExtension: Google/gemini-cli-vscode-ide-companion; latest 0.20.0Open artifact
  • GitHub stars106.86KFull-source repository; 14.54K forksOpen artifact

Routing, package retrievals, release downloads, editor installs, and repository interest observe different populations. They are never added together and never affect capability evidence, classification, or measured results.

Interpretation rulesSignals checked

First-party evidence

Each capability claim links to the first-party record that supports it.

20 first-party sourcesProduct record checked

Execution and control

1 source

Agents, state and recovery

1 source

Additional first-party sources

18 sources
View 17 more sources