Agent
Hand the work over
Agent reads files, writes patches, and uses shell and git with permission. For a concrete implementation.
Agents
Four modes for different jobs. Tools follow your permission level. Nothing is written to disk in silence.
41 def charge(order, wallet): 42 tax = order.subtotal * 0.09 43 total = order.subtotal + tax 44 if wallet.balance < total: 45 raise InsufficientFunds(total) 46 wallet.debit(total) 47 return Receipt(order.id, total)
Split regional tax from the hardcoded rate, and check coverage before debit.
Read 6 files · 2 searches · 1 test
charge still hard-codes 0.09. tax_for(region) exists. I will wire can_cover to the wallet.
12-line patch across two files. Review the diff.
Before touching checkout, write the approach for multi-region tax.
Plan · product shell and edits are limited
Freeze the tax_for contract, then change charge, then update test_charge.
Plan is ready. I switch to Agent after you confirm.
Where does charge take tax from, and which test pins it?
Ask · read only
The rate is checkout.py:42. test_charge asserts the same 0.09.
Nothing was written.
InsufficientFunds also fires for tax-exempt orders. Evidence first.
Debug · reproduce before the fix
It fails when the region is exempt and wallet.can_cover still sees the flat rate.
Failure trail is ready. The fix waits for your OK.
- tax = order.subtotal * 0.09 + tax = order.tax_for(region) - if wallet.balance < total: + if not wallet.can_cover(total, region): wallet.debit(total)
Agent
Agent reads files, writes patches, and uses shell and git with permission. For a concrete implementation.
Plan
Plan writes the approach. Product-code edits and shell are limited in this mode until you agree.
Ask
Ask reads the repository and explains. It writes nothing to disk.
Debug
Debug gathers reproduction and a failure trail first; the fix waits for your OK.
Tools, MCP, skills, local subagents, Computer Use, checkpoints, and a real terminal — the surfaces a professional workbench needs, on your machine.
Files · shell · git · search
The agent does not only talk. It reads, searches, patches, and — when you allow it — runs shell and git.
stdio · SSE
Plug in Model Context Protocol servers — browsers, issue trackers, internal APIs — without a marketplace.
SKILL.md · rules · AGENTS.md
Teach the agent your procedures once. It follows them on the next run.
Local · parallel
Split a job. Explore, shell, debug, or computer-use in a focused worker — on this machine.
Windows
When the job leaves files and the terminal, the agent can see a graphical interface.
Diff · undo · accept
Every write is a snapshot you can restore. You accept or reject the patch — the agent does not silently own the tree.
PTY · agent shell
A real terminal in the workbench, and a stateful shell the agent can drive — with sandbox and permission prompts.
SSH
Open a folder on a remote host; the helper installs on the host itself.
Every patch is readable. Apply happens when you say so. Switch modes mid-run; context is kept.
Ask, Allow safe, or Allow all. Shell sandbox is Off / Soft / Restricted. Computer Use follows the same levels.
Concrete implementation with Agent. Design with Plan. Questions with Ask. A muddy failure with Debug.
No. You see the diff. Nothing ships without you.
Tools run with less friction — review is not removed. Keep Ask or Allow safe on a sensitive tree.