Kilo Code
kilo.ai- Category
- AI Agents
- Rank
- No. 716Tools index
- Listed in
- #15 Code with an agent · #10 Interface with your agents
- Pricing
- Freemium
- Type
- AGENT
- Use case
- Coding
- Interfaces
- CLI · Editor Extension
- Builder
- Kilo-Org
- GitHub
- 27.5k stars
- Latest release
- jetbrains/v7.1.9-rc.1
- Date
About
Kilo Code is an open-source AI coding agent that runs across VS Code, JetBrains IDEs, CLI, and cloud, giving access to 500+ models with no markup on inference and support for bring-your-own-keys or local models. It includes specialized agent modes (Code, Architect, Debug) and an Auto Model router that picks between free, efficient, and frontier models based on task and budget.
What it does
This is an assistant that lives inside your development environment and does real work: it writes and edits code across multiple files, runs terminal commands, and can drive a browser to complete a task, then reviews its own changes before handing control back to you. You choose which underlying language model powers it, and can swap models mid-task to trade off speed, cost, and reasoning depth. It reaches you through several different surfaces, from an editor add-on to a command-line program to a hosted, browser-based session, all sharing the same session history.
Why it's ranked here
This one earns attention for reach and openness, not polish alone: it is MIT licensed, installable a half-dozen ways, and built as a genuine multi-client platform rather than a single editor plugin with a marketing page. The catalogue's claim of specialized task modes and wide model choice is borne out in the source. What tempers the verdict is candor cutting the other way: the project's own security documentation states plainly that the agent runs with no isolation, and a fully autonomous mode exists that turns off every confirmation prompt. That combination is worth knowing before adoption, not after.
What's good
The multi-client story is real: the same engine backs an editor extension, a JetBrains plugin, a terminal program, and a hosted agent, plus automated review of pull requests. Install paths are unusually generous for a developer tool, covering package managers on every major platform down to prebuilt binaries. It connects to external tools through a standard protocol with support for local, remote, and OAuth-authenticated servers, and ships with authentication wired up for a long list of model and infrastructure providers already, rather than leaving every integration to the user.
Tradeoffs
The project is unusually blunt about a real limitation: there is no sandbox around the agent's actions, and its own documentation says the permission prompts are a convenience, not a security boundary. An autonomous mode can disable every one of those prompts outright, with a direct warning to use it only in trusted environments. The optional server mode runs without authentication unless you set a password yourself. None of this is unusual for the category, but it does mean the isolation burden sits entirely with whoever deploys it.
How to use it well
Run it interactively inside your editor or terminal for day-to-day coding, where the permission prompts give you a chance to catch bad actions before they happen. Save the fully autonomous mode for pipelines running inside a container or disposable virtual machine, never on a machine with anything you care about, since nothing else stands between the agent and your filesystem. Reach for the plugin marketplace before writing custom integration code, since a wide set of providers are already wired in. It is not the right choice if you need built-in execution isolation without adding your own containment layer.
Technical notes+
SECURITY.md states directly that the CLI does not sandbox the agent and that the permission system is a UX feature rather than isolation, recommending Docker or a VM for real isolation, and it notes that server mode is unauthenticated unless KILO_SERVER_PASSWORD is set. package.json shows the root test script is deliberately broken (it prints a message and exits 1) to force tests to run from individual packages, and its dependency catalog lists dozens of pinned and patched packages under an Effect-based, Bun and Turborepo driven workspace. packages/opencode/src/mcp/index.ts implements the MCP client, handling stdio, StreamableHTTP, and SSE transports plus OAuth flows for remote servers. packages/opencode/src/plugin/index.ts registers built-in auth plugins for providers including GitHub Copilot, Codex, Cloudflare, Azure, DigitalOcean, xAI, Snowflake Cortex, GitLab, and Poe. CONTRIBUTING.md documents the kilocode_change marker convention used to track this fork's edits against the upstream OpenCode source it is built on.
Observed
- License
- MIT
- Language
- TypeScript monorepo built with Bun and Turborepo
- Install surface
- npm global install, curl install script, Homebrew tap, Arch Linux AUR package, and prebuilt binaries for Windows, macOS, and Linux (x64 and arm64)
- Interfaces
- CLI with terminal UI, VS Code extension, JetBrains plugin, cloud agent, and an HTTP server mode with SSE
- MCP support
- MCP client with stdio, StreamableHTTP, and SSE transport support, including OAuth-authenticated remote servers
- Security posture
- Documented as running with no sandbox by design; permission prompts are described as a UX feature, not isolation
- Server auth
- HTTP server mode runs unauthenticated unless a password environment variable is set
- Test structure
- Root-level test command is intentionally disabled; tests are run per package instead
- Provenance
- CLI core is a fork of the OpenCode project, with fork-specific changes tracked via inline markers
Read from README.md, package.json, AGENTS.md, packages/opencode/src/auth/index.ts, packages/opencode/src/permission/index.ts, packages/opencode/src/mcp/index.ts, packages/opencode/src/plugin/index.ts, packages/llm/src/providers/index.ts, packages/llm/src/route/index.ts, packages/kilo-indexing/src/indexing/index.ts, packages/kilo-sandbox/src/index.ts, packages/kilo-docs/pages/getting-started/index.md, SECURITY.md, CONTRIBUTING.md, LICENSE.
What it can do
Route tasks automatically between free, efficient, and frontier models based on task and budget
Coding task and budget constraints → Selected AI model
Operate specialized agent modes for coding, architecture, and debugging
User request or codebase → Code, architectural plan, or debugging output
Intel on Kilo Code
Tags
Tech Stack
Media

Comments (0)
No comments yet
Editorially curated, with community endorsements as a secondary signal. Corrections welcome.