Peon
Peon is a small, fast, extensible agent runtime for the terminal. It keeps the agent loop simple, puts model and tool authority in a separate server process, and provides a responsive Rust TUI for coding work.
Project status: Peon is an early v0.1 implementation. Its protocol and configuration may change before 1.0. Run it in version-controlled workspaces and review every approval.
What works
- Streaming OpenAI-compatible model calls and function tools
- Built-in workspace-scoped
read, atomicwrite, andbashtools - Native tool adapters for installed
claude,codex, andpiagents - Progressive-disclosure Markdown skills from user and project directories
- Configurable, bounded context selection and deterministic compaction
- Server-enforced approvals, timeouts, output caps, and cancellation
- Separate stdio server and Ratatui client processes
- Interactive TUI plus a headless
scv execmode - Linux and macOS support on ARM64 and x86-64
Install
Peon requires Rust 1.88 or newer and /bin/bash.
Until release archives are published, build from source:
The package installs two binaries: scv and the standalone protocol entry
point scv-server.
To publish from a clean checkout, authenticate with cargo login and publish
the workspace in dependency order (Cargo will refuse a package whose local
dependencies are not already on crates.io):
The server is a long-running JSONL backend. Keep it attached to a supervisor
such as systemd; the checked-in scv-server.service
unit is a starting point:
The stdio protocol is intentionally local and one-session-per-connection. A remote client should use SSH or a small authenticated stdio proxy rather than exposing the raw server socket.
ClawBot / WeChat iLink
ClawBot uses WeChat's iLink HTTP API: QR login, then POST /ilink/bot/getupdates
long-polling and POST /ilink/bot/sendmessage. Incoming messages include a
context_token; replies must echo that token. The Peon integration boundary is
therefore an adapter that maps each inbound text message to session.start and
turn.start, forwards the final assistant response to sendmessage, and
resolves approvals through a trusted local operator channel. The scv clawbot
command provides the polling and reply adapter. Credentials are the
bot_token, ilink_bot_id, ilink_user_id, and returned baseurl from the
official QR status API; do not put them in project configuration or logs.
Quick start
Peon's first provider speaks the OpenAI-compatible Chat Completions API.
Use another compatible model or endpoint:
Run one non-interactive prompt. Risky tools are denied unless --yes is
present:
In the TUI, Enter sends, Ctrl+J inserts a newline, Esc cancels, Ctrl+O
toggles the latest tool result, and /help lists the compact command set.
Configuration
User configuration lives at ~/.config/peon/config.toml. A workspace may add
.peon/config.toml, but project configuration cannot redirect provider
credentials or replace native-agent executables.
[]
= "gpt-4.1-mini"
= "https://api.openai.com/v1"
= "OPENAI_API_KEY"
[]
= 128000
= 8192
[]
= "on-risk"
= 120
[]
= "codex"
= ["exec"]
Precedence is CLI, environment, explicit PEON_CONFIG, project configuration,
user configuration, then defaults. Unknown keys fail startup. See
docs/configuration.md for the complete schema and
trust rules.
Extending Peon
The core exposes small Rust traits for providers, tools, context policies,
approval gates, and event sinks. Registering a new Tool does not require a
change to the agent loop or TUI.
Skills use .peon/skills/<name>/SKILL.md in a project or
~/.config/peon/skills/<name>/SKILL.md for the user. Only skill metadata enters
the initial prompt; the model loads full instructions through the contained
read_skill tool when needed.
The built-in agent_claude, agent_codex, and agent_pi tools launch those
installed CLIs directly, without shell interpolation. They are optional,
approval-gated, cancellable subprocess adapters and share the same output and
timeout limits as other process tools.
Architecture
Peon is a Cargo workspace with deliberately narrow packages:
scv-core: loop and extension traits;scv-protocol: versioned wire types with no runtime policy;scv-provider-openai: streaming provider transport;scv-tools: filesystem, process, skill, and nested-agent tools;scv-server: configuration, sessions, permissions, and protocol dispatch;scv-tui: terminal client and headless protocol client.
The TUI spawns peon server --stdio; scv-server --stdio exposes the same
server library to other local clients. Start with the final v0.1
architecture, then see the
protocol, context,
tools, TUI, and
security model.
Security
Peon is not an OS sandbox. bash and nested agents run with your user
permissions and inherited environment after approval. File tools reject
absolute paths, parent traversal, and symlink escapes, but an approved process
can access anything your account can access. Use a container or operating-system
sandbox for untrusted repositories. See SECURITY.md and the
full security model.
Development
Read AGENTS.md before using a coding agent in this repository.
Use a sibling git worktree for parallel or unrelated work. For cross-cutting
agent-loop, protocol, security, or architecture changes, update the final-state
design in docs/ and pass an independent design review before implementation.
Keep one coherent requested outcome in one commit by default, and commit or
push only at an explicit delivery boundary.
Tests use scripted providers and fake executables; they do not require a live
API key. The test and performance contract is in
docs/quality.md, with measured results and an honest
feature comparison in the v0.1 evaluation.
Contributions are welcome—read
CONTRIBUTING.md first.
License
Licensed under the Apache License 2.0.