by nrslib
TAKT Agent Koordination Topology - Define how AI agents coordinate, where humans intervene, and what gets recorded — in YAML
# Add to your Claude Code skills
git clone https://github.com/nrslib/taktLast scanned: 5/2/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@anthropic-ai/claude-agent-sdk: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@anthropic-ai/sdk: Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "rollup: Rollup 4 has Arbitrary File Write via Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite-node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-02T06:10:37.012Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how takt compares with popular alternatives.
takt is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by nrslib. TAKT Agent Koordination Topology - Define how AI agents coordinate, where humans intervene, and what gets recorded — in YAML. It has 1,402 GitHub stars.
takt returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/nrslib/takt" and add it to your Claude Code skills directory (see the Installation section above).
takt is primarily written in TypeScript. It is open-source under nrslib on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh takt against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Stop babysitting AI coding agents.
TAKT is an open-source CLI that turns AI coding agents into repeatable development workflows. Define planning, implementation, review, fix loops, human checkpoints, permissions, and output contracts in YAML, then run tasks with isolated worktrees and traceable logs.
Instead of asking one agent to remember the whole process, TAKT gives each step its own role, context, and transition rules. Agents can code, but the workflow decides what happens next.

TAKT Agent Koordination Topology orchestrates multiple AI agents with review loops, managed prompts, and per-step permissions.
Talk to AI to define what you want, queue it as a task, and run it with takt run. Planning, implementation, review, and fix loops are defined in YAML workflow files, so the process is not left to the agent's discretion. TAKT coordinates Claude Code, Codex, OpenCode, Pi, the official DeepSeek Harness SDK, Cursor, GitHub Copilot CLI, and Kiro CLI as agents with different roles, permissions, and context.
TAKT is built primarily for AI coding workflows, but the same model applies beyond coding: any task where multiple AI agents need to coordinate, or where review, judgment, and feedback loops can improve task quality.
TAKT is built with TAKT itself (dogfooding).
AI coding agents do not automatically create a stable development process. In long-running work, they forget instructions, accumulate polluted context, blur implementation and review responsibilities, and often force humans to repeat the same feedback again and again.
Adding more rules to prompts, CLAUDE.md, or skills can help, but it cannot enforce the process. Whether the rules are followed is still left to the agent's behavior.
TAKT treats AI agents as something to be controlled from the outside, not simply trusted.
Workflows define the phases, and each step receives its own persona, policy, knowledge, instruction, and output contract. TAKT manages implementation, review, fix, and re-review flows declaratively. By separating responsibilities, knowledge, and constraints, then giving each agent only what it needs for the current step, TAKT improves task quality without bloating context.
Reviews cannot be silently skipped. Findings route work back to fix steps, and human judgment can be requested when needed. Tasks run in isolated worktrees, and each step leaves logs and reports so the path from task to PR remains traceable.
TAKT runs all of this as a reusable agent process built from roles, phases, judgments, and feedback loops, so the development process stays reviewable and reproducible without constant human intervention.
From a Git repository with at least one commit:
npm install -g takt
# Talk to AI, describe a task, use /go, then choose "Queue as task"
takt
# Execute queued tasks in isolated worktrees
takt run
# Review diffs, merge, retry, requeue, or delete task branches
takt list
If this is your first run, configure a provider in ~/.takt/config.yaml or use the API key environment variables listed in Configuration. SDK-based providers such as claude-sdk, codex, pi, and deepseek-harness run with Node.js. Run takt install deepseek-harness before using DeepSeek Harness. CLI-based providers require their external CLIs.
On GitHub, run takt caccia <PR-number> to wait for CodeRabbit reviews, handle unresolved bot threads in isolated clones, and keep a decision report for each iteration. The same loop can run after TAKT creates or updates a PR when caccia.enabled is enabled; linked execution is disabled by default. See the CLI reference and configuration guide.
Follow the written tutorial with these hands-on walkthroughs:
| Chapter 1 | Chapter 2 |
|---|---|
![]() |
![]() |
| Plain AI coding agents | TAKT |
|---|---|
| The prompt asks the agent to follow a process | The YAML workflow owns the process |
| Review steps can be forgotten or skipped | Review and fix loops are explicit transitions |
| One long context keeps growing | Each step receives only the context it needs |
| Implementation and review responsibilities blur | Personas, permissions, and output contracts separate responsibilities |
| Work often lands directly in the current tree | Queued tasks run in isolated worktrees by default |
| The path from task to result is hard to audit | Logs and reports preserve the path from task to PR |
| The same process must be recreated by memory | Workflows are reusable, reviewable, and versionable |
TAKT requires Node.js >=22.22.0.
The provider you choose determines whether you need to install an external CLI or can run on Node.js alone via a TypeScript SDK.
The default provider is claude-sdk (Claude Agent SDK). claude is an alias for claude-sdk.
To keep using the previous headless Claude Code CLI provider, change provider: claude to provider: claude-headless in runtime.yaml profiles or legacy config.yaml settings, and use --provider claude-headless for CLI overrides. Move provider-specific permission settings to provider_profiles.claude-headless. To use the new SDK default or explicit claude-sdk, move those settings to provider_profiles.claude-sdk; an explicit claude alias still uses the provider_profiles.claude key. For example, with the provider omitted, an old provider_profiles.claude.default_permission_mode: readonly no longer applies and the new default can fall back to builtin edit unless the profile is moved. The shared provider_options.claude key stays the same. Existing sessions labeled claude start fresh after this change. claude-terminal is unchanged.
These providers run via SDK (no CLI required, Node.js only):
claude-sdk — @anthropic-ai/claude-agent-sdkcodex — @openai/codex-sdkpi — @earendil-works/pi-coding-agentThe deepseek-harness provider runs on Node.js through the official TypeScript SDK and the matching DeepSeek Harness runtime. Run takt install deepseek-harness once before using it; the pinned SDK and runtime are installed in TAKT's managed directory, separate from TAKT's npm dependencies. Repeat the command to repair damage detected by TAKT. If the provider still malfunctions, run takt install deepseek-harness --force to reinstall it even when integrity checks pass. The supported platforms are Linux x64/arm64 with glibc >= 2.28 and macOS arm64 >= 14.0. No Python or uv setup is required.
A session supports multiple FIFO-serialized turns while its runtime stays alive with the same supported configuration. The SDK cannot restore persisted history after runtime restart/teardown or replace runtime settings while keeping that history. In those cases TAKT refuses the old session with a fixed diagnostic; start a new TAKT session or run with a new session identity to use new settings. This is a deliberate breaking reduction, and cross-runtime history preservation is deferred. TAKT does not automatically remove files from an earlier Python/uv installation; review and remove that old managed environment manually if desired. Existing credential files remain user-owned and are not migrated or deleted.
TAKT disables the runtime's JSONL session-persistence plugin so newly written session logs cannot retain provider errors that echo credentials. Multiple turns still work in the live runtime; TAKT leaves existing DeepSeek session files untouched.
The standard SDK file/search, shell, and delegated-exec