A small loop you can read end to end.
No hidden orchestration. The agent streams a reply, calls tools when it needs to, folds the results back in, and repeats until it's done.
- 01
Point it at a model
Drop endpoints into .lambai/models.json or use the built-in defaults. Keys come from the environment and are never written to disk.
/model deepseek-flash - 02
Ask in plain language
The agent plans, calls tools, reads results, and loops until the job is done — up to 10 tool rounds per user turn.
> list the files in this directory - 03
Review and ship
Every write is confirmed before it lands. Approve once, all turn, always, or lean on the read-only profile.
[y]es / [n]o / [a]ll / [A]lways
Messages in, tool calls out.
Each user turn can chain up to ten rounds of tool calls. Tool results come back as messages, the model decides what's next, and the transcript is saved as plain JSONL after every step.
- ✓ Streaming replies, token by token
- ✓ Structured tool_calls the model can chain
- ✓ Byte-capped results, so context stays healthy
- ✓ JSONL transcripts you can resume or export
I'll take a look at the project first.
↳ fs_ls .
↳ search_glob "*.v"
Listed 9 entries · 4 V files
Found it — I'll add the flag in main.v.
↳ fs_edit main.v
Wrote main.v · snapshot #7
Three rings of safety, on by default.
Confinement
The sandbox resolves every path against the project root. A request to escape is refused outright.
Write policy
Switch between none, confirm, and allow. Under confirm, each write waits for a y / n / all / always.
Protected paths
.lambai and .kilo are off-limits, and shell commands run with a cleared environment.