Coding agent

Kilo Code

One open agent across IDE, terminal, cloud, and CI.

Status
Active
License
MIT
Evidence
Documented + code-verifiable, 27 sources
Product record checked
2026-07-27

At a glance

An MIT-licensed, multi-provider coding agent for VS Code, JetBrains, terminal, browser-hosted cloud, and CI, with delegated subagents, MCP, browser automation, Git snapshots, and an opt-in macOS or Linux sandbox.

Good choice if

  • Vibe coders who want an IDE-first agent, subscription or local models, and a practical undo path
  • Developers who want the same sessions and provider choices across editor, terminal, cloud, and CI
  • Parallel work that combines delegated subagents with isolated Git worktrees

Check before choosing

  • The local OS sandbox is disabled by default, unavailable on Windows, and limits writes and network access rather than filesystem reads; Kilo explicitly says it is not a privacy boundary or a complete firewall
  • `kilo run --auto` disables permission prompts; unattended work still needs a trusted or separately isolated environment
  • Git snapshots are recovery aids rather than backups: ignored files are excluded and old unreachable snapshots can be pruned after seven days
See 1 more considerations
  • Cloud Agent runs in a separate managed Cloudflare sandbox architecture with its own repository credentials, persistence, and observability boundaries; this does not make the local CLI sandbox-first

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced
  • Adaptive agent loop

    Documented

    The system repeatedly observes results and chooses the next action instead of following a fixed one-pass graph.

  • Repository tool execution

    Documented

    The system can use tools to inspect and change a repository or its execution environment.

  • Task-aware context management

    Documented

    The runtime assembles, updates, compacts, retrieves, or persists task-relevant context while work proceeds.

  • Model-independent runtime control

    Documented

    Permissions, budgets, interruption, policy, or stop controls operate outside the model's own text generation.

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationSandbox availableDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible + browserDocumented mechanism, not a performance score.
  • Context & stateManaged contextDocumented mechanism, not a performance score.
  • Lifecycle & recoveryCheckpoint/rewindDocumented mechanism, not a performance score.
  • ObservabilityStructured tracesDocumented mechanism, not a performance score.
  • VerificationTool-assistedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.

Public code audit

5/5public artifacts present
Security policy
Present at inspected commit
CI workflow
Present at inspected commit
Automated tests
Present at inspected commit
Evaluation assets
Present at inspected commit
Contributor documentation
Present at inspected commit

The Harbor smoke workflow depends on private KiloBench code and covers two vendor-operated smoke tasks, so it is an auditable evaluation asset rather than independent benchmark evidence. SECURITY.md still says no sandbox even though the same commit ships and documents an opt-in OS sandbox.

Inspect commit a19d44c3ef9f, checked 2026-07-27

Measured configurations

No benchmark run passes the full metadata admission policy for this harness yet. Missing data is not scored as zero.

Benchmark policy and all runs

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Local models
DocumentedLocal or self-hosted model pathSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Browser control
DocumentedBuilt-in or product-supported browser controlSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Isolated execution
Depends on surfaceOpt-in locally; managed isolation on cloud surfacesSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Undo file changes
DocumentedProduct-supported file or session rollbackSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.

Primary evidence

Each capability claim is tied to a first-party record and a verification date.

Product record checked 2026-07-27
View 19 additional sources
Product and interfaces3 sources
Execution and control7 sources
Agents, state and recovery5 sources
Automation and extensions1 sources
Releases and public code audit3 sources

Ecosystem discovery

OpenRouter coding apps Discovery signal only; usage rank is not used as a quality or capability score. Observed 2026-07-27.