Installation¶
From PyPI¶
Both put the agent6 entry point in ~/.local/bin.
If that directory is not on your PATH:
Restart the shell afterwards.
Shell completion¶
One command installs tab-completion.
- detects your shell, or takes the name of one
- rerunning is safe and refreshes it
- bash/zsh: a marker-guarded source line in the rc file, pointing at a script under the config dir
- fish/xonsh: a file in the auto-loaded native location (
fish/completions,xonsh/rc.d), no rc edit --print bashemits the script instead, forevalor a dotfiles repo
Check the install¶
agent6 check sandbox runs the jail through live probes and reports the isolation level a run will use on your kernel.
Requirements¶
- Python 3.12 or newer
- git 2.40 or newer (
merge-tree --merge-base) - One provider: Anthropic, any OpenAI-compatible endpoint (a local one needs no key), a ChatGPT subscription, or a Claude Code login (
agent6 connect claude) - Linux on x86_64 or aarch64 for the sandbox
- Unprivileged user namespaces for
strictisolation - A Rust toolchain to build from source (the PyPI wheels bundle
agent6-jail)
The jail uses Landlock, seccomp, and user namespaces, and its seccomp filter exists for x86_64 and aarch64.
- On other architectures and on macOS,
isolation = "auto"resolves tonone: commands run as ordinary subprocesses behind a startup warning, and an explicitstrictorhardenedrefuses. - On Windows, use WSL.
- Unprivileged user namespaces are on by default on Ubuntu, Debian, and most cloud images
- Ubuntu 24.04+ blocks them (
kernel.apparmor_restrict_unprivileged_userns = 1): set it to 0, oragent6 system apparmor install(remove reverts)
- Ubuntu 24.04+ blocks them (
- Without user namespaces
autofalls back tohardened(Landlock, seccomp,NO_NEW_PRIVS), and tononeon a kernel with no Landlock.
The security model describes what each isolation level enforces.
From source¶
AGENT6_JAIL_BIN=/path/to/agent6-jail overrides the bundled jail binary.