by ConardLi
Production-ready open source terminal coding agent with readable, layered code: permission rules, OS sandboxing, MCP, skills, sub-agents, and Anthropic, OpenAI-compatible, Gemini, or local models.
# Add to your Claude Code skills
git clone https://github.com/ConardLi/easy-agentLast scanned: 10/4/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@anthropic-ai/sandbox-runtime: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
"severity": "low"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild allows arbitrary file read when running the development server on Windows",
"severity": "low"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiter",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
"severity": "high"
},
{
"type": "npm-audit",
"message": "node-forge: node-forge RSA PKCS#1 v1.5 signature verification accepts extra nested DigestAlgorithm elements",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs array-limit bypass via bracket-key comma parsing",
"severity": "medium"
},
{
"file": "README.md",
"line": 40,
"type": "remote-install",
"message": "Install command (remote install script piped to a shell — review the source before running): \"curl -fsSL https://raw.githubusercontent.com/ConardLi/easy-agent/main/install.sh\"",
"severity": "low"
},
{
"file": "README.md",
"line": 85,
"type": "dangerous-command",
"message": "Dangerous command (disables permission prompts): \"--dangerously-skip-permissions\"",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-10-04T10:26:28.639Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how easy-agent compares with popular alternatives.
easy-agent is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by ConardLi. Production-ready open source terminal coding agent with readable, layered code: permission rules, OS sandboxing, MCP, skills, sub-agents, and Anthropic, OpenAI-compatible, Gemini, or local models. It has 1,007 GitHub stars.
easy-agent returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/ConardLi/easy-agent" and add it to your Claude Code skills directory (see the Installation section above).
easy-agent is primarily written in TypeScript. It is open-source under ConardLi on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh easy-agent against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A terminal coding agent that reads your code, edits files, and runs commands under permission rules you control.

Easy Agent (eagent) runs in your terminal next to your repository. Describe a task and it plans the work, reads and changes files, runs tests or shell commands, and reports back. Every action that can change your machine goes through permission rules, workspace trust, and an optional OS-level sandbox. It works with Anthropic, OpenAI-compatible, Gemini, and local models.
The code is written to be read as well as run. Model communication, the agentic loop, tools, permissions, context management, and each extension system live in separate layers. The documents linked below explain how the security-relevant parts behave and why, and the learning path walks through the layers in order with code snapshots, which helps if you want to build or customize an agent of your own.
中文文档:README.zh-CN.md
/rewind if they are wrong.eagent -p and read text, JSON, or NDJSON output in CI or shell scripts.Requirements: Node.js 22 or newer, npm, and credentials for at least one supported model provider.
npm install -g --ignore-scripts eagent
eagent --version
Or try it without installing:
npx --yes eagent@latest
On macOS and Linux an installer is also available. It checks Node.js, installs the same npm package with --ignore-scripts, and verifies that eagent is on PATH. It does not install Node.js or run package lifecycle scripts.
curl -fsSL https://raw.githubusercontent.com/ConardLi/easy-agent/main/install.sh | sh
The package installs two commands, eagent and the long alias easy-agent.
export ANTHROPIC_AUTH_TOKEN="your-token"
cd your-project
eagent
On first use in a folder, Easy Agent asks whether you trust it. Then type a request, for example explain how requests are authenticated in this repo. Type /help for commands; press Ctrl+D to exit.
AGENTS.md / AGENT.md), file checkpoints, and rewindeagent/sdk), images and screenshots, and multiple model protocols| Platform | Status | Shell tool | Shell sandbox |
|---|---|---|---|
| macOS | Supported | Bash | Seatbelt; needs rg |
| Linux, WSL2 | Supported | Bash | bubblewrap; needs bubblewrap, socat, rg, and unprivileged user namespaces |
| Windows | Supported without sandbox | PowerShell | Not available; an enabled fail-closed sandbox blocks PowerShell |
install.sh installer supports macOS and Linux. On Windows, install with npm.0600/0700 modes. /doctor reports this.pngpaste or osascript on macOS and xclip or xsel on Linux.See Sandbox security for per-platform setup, including the Ubuntu AppArmor restriction on user namespaces.
Easy Agent assumes the model can make mistakes and that a repository you open may be hostile. Several independent layers limit what a session can do:
default asks before risky actions. plan (--plan) allows only read-only tools. auto (--auto) lets a classifier approve safe calls, block risky ones, and fall back to a prompt when unsure. Headless runs (-p) deny calls that would prompt unless you pass --dangerously-skip-permissions; deny rules still apply..env, project MCP servers, hooks, plugins, and model profiles are ignored until you trust the folder. Trust is stored in your home directory, so a repository cannot mark itself trusted, and project files cannot replace credentials inherited from your shell (details).sandbox.enabled is set, Bash runs inside an OS sandbox with an allow-only write policy and proxy-filtered network. If the sandbox cannot start, the command is blocked rather than run unsandboxed (details).Easy Agent sends no analytics or telemetry. Network requests go to the model provider you configure, to MCP servers and plugin sources you add, and to WebFetch/WebSearch targets when those tools are allowed. /doctor probes the configured provider endpoint for reachability.
Settings are JSON files merged in this order, from lowest to highest priority:
~/.easy-agent/settings.json<project>/.easy-agent/settings.json (shared, applied once the folder is trusted)<project>/.easy-agent/settings.local.json (personal, applied once the folder is trusted)--settings <file>, --model, --permission-mode, and similar flags/Library/Application Support/EasyAgent/managed-settings.json on macOS, /etc/easy-agent/managed-settings.json on Linux, %PROGRAMDATA%\EasyAgent\managed-settings.json on WindowsA project .env is applied after project and local settings, only for a trusted folder. Feature switches are described in Configuration and feature controls.
For a raw Anthropic model name, environment variables are enough:
export ANTHROPIC_AUTH_TOKEN="your-token"
export ANTHROPIC_MODEL="claude-sonnet-4-20250514" # optional
eagent
Named Anthropic, OpenAI-compatible, Gemini, and local profiles go in settings.json:
{
"defaultModel": "gpt",
"models": {
"gpt": {
"protocol": "openai-chat",
"model": "gpt-5.1",
"baseURL": "https://api.openai.com/v1",
"apiKey": "${OPENAI_API_KEY}"
},
"gemini": {
"protocol": "gemini",
"model": "gemini-2.5-pro",
"apiKey": "${GEMINI_API_KEY}"
},
"ollama": {
"protocol": "openai-chat",
"model": "qwen2.5-coder",
"baseURL": "http://localhost:11434/v1"
}
}
}
Select a profile with eagent --model gpt or /model gpt inside the REPL.
| Environment variable | Purpose |
|---|---|
ANTHROPIC_AUTH_TOKEN |
Anthropic API token or compatible gateway token |
ANTHROPIC_BASE_URL |
Optional Anthropic-compatible endpoint |
ANTHROPIC_MODEL |
Default raw Anthropic model name |
OPENAI_API_KEY |
Referenced by OpenAI-compatible profiles |
GEMINI_API_KEY |
Referenced by Gemini profiles |
WEB_SEARCH_API_KEY |
Optional WebSearch provider key |
Run /config list, /model list, or /doctor to inspect the effective setup. Credential values are always redacted.
| Location | Contents |
|---|---|
~/.easy-agent/settings.json |
User settings |
~/.easy-agent/state.json |
Workspace trust decisions and machine-level state |
~/.easy-agent/AGENT.md |
User-wide memory loaded into every session |
~/.easy-agent/projects/ |
Session transcripts (JSONL) and per-project memory |
~/.easy-agent/file-history/ |
File checkpoints used by /rewind |
~/.easy-agent/tasks/, plans/, teams/ |
Task graphs, Plan Mode plans, Agent Team state |
~/.easy-agent/skills/, agents/, commands/, output-styles/ |
User extensions |
~/.easy-agent/plugins/, mcp/ |
Installed plugins, MCP OAuth tokens and artifacts |
~/.easy-agent/stream-debug.log |
Only when EASY_AGENT_DEBUG_STREAM=1 is set |
<project>/.easy-agent/ |
Project settings, local settings, and project extensions |
<project>/AGENTS.md, <project>/AGENT.md |
Project memory you write or create with /init; both load when present, `A |