Small local-first agent kernel: bounded tools, reversible edits, auditable runs. CLI + Web, Ollama + compatible APIs.
# Add to your Claude Code skills
git clone https://github.com/MuzeAnisichael/minimal-local-agentGuides for using ai agents skills like minimal-local-agent.
Last scanned: 9/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-09-30T10:18:45.840Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how minimal-local-agent compares with popular alternatives.
minimal-local-agent is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by MuzeAnisichael. Small local-first agent kernel: bounded tools, reversible edits, auditable runs. CLI + Web, Ollama + compatible APIs. It has 129 GitHub stars.
Yes. minimal-local-agent passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/MuzeAnisichael/minimal-local-agent" and add it to your Claude Code skills directory (see the Installation section above).
minimal-local-agent is primarily written in Python. It is open-source under MuzeAnisichael on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh minimal-local-agent against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
A small local-first agent kernel. Bounded tools. Reversible edits. Auditable runs.
简体中文 · Documentation · Quick start · Customize · Releases · Contribute
One model/tool loop, one bounded workspace, and a local SQLite record of what happened. Use Ollama or an explicitly configured Chat Completions-compatible API from the CLI, local Web console, or your own Python host.
Built for developers who want to understand, embed, and customize an agent—not a universal assistant with a growing collection of default tools.

The real v1.0 interface with disposable sample files and a live model. The Web UI is currently Chinese. Screenshot provenance and reproduction.

The model called the real edit tool; the sample file stayed unchanged. Web tasks can read or preview. Approving an actual write requires interactive CLI.
See the scope comparison for trade-offs. This is neither a Python sandbox nor a general autonomous assistant.
Requires Python 3.11+ and a model supporting tool calling. The example uses Ollama; other local servers and compatible APIs use local configuration.
git clone https://github.com/MuzeAnisichael/minimal-local-agent.git
cd minimal-local-agent
python3.11 -m venv .venv
source .venv/bin/activate
python -m pip install -e .
ollama pull qwen3.5:9b
cp agent.example.toml agent.toml
minimal-agent doctor
minimal-agent web
git clone https://github.com/MuzeAnisichael/minimal-local-agent.git
Set-Location minimal-local-agent
py -3.11 -m venv .venv
.\.venv\Scripts\Activate.ps1
python -m pip install -e .
ollama pull qwen3.5:9b
Copy-Item agent.example.toml agent.toml
minimal-agent doctor
minimal-agent web
Open http://127.0.0.1:8765. Put only files the agent may access under
workspace/. Prefer the terminal? Run minimal-agent chat or
minimal-agent run --read-only "List the workspace files".
To try the Web interface with disposable sample files, run this from the source
checkout instead of minimal-agent web:
python examples/web_demo.py
Use the URL printed by the demo. It uses your configured real model but never loads your personal workspace or saved sessions; model calls may incur charges.
For a fixed install, download the wheel from the v1.0.0 release and install it in a virtual environment:
python -m pip install minimal_local_agent-1.0.0-py3-none-any.whl
No PyPI publication is assumed. The v1.0.0 tag pins the original release;
the screenshot demo and refreshed documentation live on main.
More commands and configuration: user guide.
| Area | Included |
|---|---|
| Tools | list_files, read_file, search_text, write_file, edit_files |
| Write control | Confirm / preview / deny; bounded diffs, multi-file transactions, rollback, undo |
| Runtime | Stable AgentRuntime API, model/tool/output limits, per-request message-byte guard |
| Interfaces | CLI and loopback Web; Web is read-only or preview-only |
| Local state | SQLite sessions, history, audit, change snapshots, chained execution receipts |
| Extensions | Explicit Python read tools, optional allowlisted loopback MCP, model/reducer seams |
| Evaluation | Isolated fixtures; deterministic answer, tool, and file assertions; task-family reports |
from dataclasses import replace
from minimal_local_agent import AgentRuntime, Settings
runtime = AgentRuntime(replace(Settings.load("agent.toml"), write_policy="deny"))
outcome = runtime.run("List the workspace files")
print(outcome.response)
print(outcome.receipt_hash)
ReadTool; start with the
runnable example.ModelFactory.context_reducer; automatic
compression is off, and the original history remains stored.Read the embedding guide and v1 compatibility contract before building an integration.
flowchart LR
Host["CLI / local Web / Python"] --> Runtime["AgentRuntime: policy + budgets"]
Runtime <--> Model["Ollama / compatible API"]
Runtime --> Tools["Bounded tools + reviewable edits"]
Tools --> Files["One workspace"]
Runtime --> State["SQLite: history + audit + receipts"]
PydanticAI handles model/tool iteration; project code handles boundaries, transactions, and local state. The Web UI uses standard-library HTTP and plain HTML/CSS/JavaScript—no frontend build stack. See the architecture and source map.
The v1.0 validation record documents 91 passing automated tests and six passing CI jobs, including Linux/Windows fresh installs, minimum supported dependencies, and optional MCP.
| Real-model smoke checks | Read tasks | Safety tasks |
|---|---|---|
Ollama · qwen3:8b |
3/3 | 2/2 |
Compatible API · openai/gpt-4o-mini |
3/3 | 2/2 |
These ten fixed-budget cases are regression evidence, not a model ranking or a statistical reliability guarantee. Missing usage stays unknown; token counts are not monetary costs. Reviewed release results.
Security policy · Troubleshooting · Maintenance roadmap
Small fixes, tests, examples, and documentation are welcome. Report a bug or suggest an improvement, then follow the contribution guide. Keep independently verifiable changes in small commits and preserve the kernel's narrow scope.