How it works

A small loop you can read end to end.

No hidden orchestration. The agent streams a reply, calls tools when it needs to, folds the results back in, and repeats until it's done.

  1. 01

    Point it at a model

    Drop endpoints into .lambai/models.json or use the built-in defaults. Keys come from the environment and are never written to disk.

    /model deepseek-flash
  2. 02

    Ask in plain language

    The agent plans, calls tools, reads results, and loops until the job is done — up to 10 tool rounds per user turn.

    > list the files in this directory
  3. 03

    Review and ship

    Every write is confirmed before it lands. Approve once, all turn, always, or lean on the read-only profile.

    [y]es / [n]o / [a]ll / [A]lways
The loop

Messages in, tool calls out.

Each user turn can chain up to ten rounds of tool calls. Tool results come back as messages, the model decides what's next, and the transcript is saved as plain JSONL after every step.

  • ✓ Streaming replies, token by token
  • ✓ Structured tool_calls the model can chain
  • ✓ Byte-capped results, so context stays healthy
  • ✓ JSONL transcripts you can resume or export
lambai · main
assistant

I'll take a look at the project first.

↳ fs_ls .

↳ search_glob "*.v"

tool

Listed 9 entries · 4 V files

assistant

Found it — I'll add the flag in main.v.

↳ fs_edit main.v

tool

Wrote main.v · snapshot #7

Trust model

Three rings of safety, on by default.

Ring 1

Confinement

The sandbox resolves every path against the project root. A request to escape is refused outright.

Ring 2

Write policy

Switch between none, confirm, and allow. Under confirm, each write waits for a y / n / all / always.

Ring 3

Protected paths

.lambai and .kilo are off-limits, and shell commands run with a cleared environment.