agy-staff
A plugin that hires Google’s Antigravity CLI as a member of staff: the host agent — Claude Code, Codex or Pi — keeps the decisions and hands the surveys, reviews and scoped edits to a Gemini 3.8 Flash worker that runs in the background and answers through a job id.

What it is
Google’s own coding agent is the Antigravity CLI, and this project hires it: a companion script wraps agy and hands it to Claude Code, Codex or Pi as a colleague worth delegating to. Five personas divide the work — ask for a tool-free one-shot answer, staffer for general delegation, researcher, reviewer for code and for plans, and implementer for scoped edits — each pinned to a Gemini 3.8 Flash effort tier, with a lead skill telling the host agent what to hand over and what to keep. Only ask answers in the same call; the other four return a job id and a wait command, run in a detached worker process, and leave their spec, log, result and final status under .agy-staff/ in the repository. It appeared on 2026-08-18 and shipped twelve releases in the following month, MIT-licensed, and finished September with 696 stars and two open issues.
Who built itThe GitHub profile behind the repository puts the account at 2022-04-18 with 31 public repositories, 147 followers, a bio of “think twice”, a company field filled in as Google and a personal site at lastwhisper.dev. Its 50 of the repository’s 52 commits arrive under two author names — pkuwkl with 39 and LastWhisper with 11 — both linked to the same account. Two other people, Shen-18 and solitudealma, have one commit each.
How it is put together
The parts · 6One companion script is the whole runtime and the skills around it are documentation, which decides most of the design. Because the delegating side is an ordinary shell user, everything the worker does has to be expressible as a command with an exit code, a file on disk and a bounded amount of text; and because the agent loop belongs to the host harness, the plugin never tries to schedule, wake or notify, handing back a job id and letting the host decide when to wait. State is per repository rather than global — .agy-staff/ beside the code holds conversations, job specs, logs, results, raw event streams and snapshots — so a job can be inspected, continued or restarted from the same checkout, and that directory appends itself to .git/info/exclude rather than to the tracked .gitignore, because it is local scratch and a committed file would change the repository for everybody else. Two permission profiles, unrestricted by default, keep the common path free of setup while leaving hardening available. What results is a thin launcher: prepare a prompt, dispatch a process, report the workspace state, collect a result — deliberately not parsing delivery contracts or doing the commit, push or pull-request work itself.
- companion/
- The runtime, four modules and nothing beyond Node’s standard library: an 88 KB entrypoint holding modes, job management and setup; a 17 KB streaming executor with process cleanup and deadlines; a 7.7 KB observation module for event parsing, progress snapshots and output budgets; and a 4.5 KB lock for state writes and stale-lock recovery.
- skills/ and pi-skills/
- Seven canonical skills — ask, staffer, researcher, reviewer, implementer, lead and jobs — with the reviewer and jobs skills carrying a references directory for on-demand detail. The Pi directory is generated mechanically from the canonical one with an
agy-prefix and rewritten sibling references; the contributing guide says to edit the canonical files and never the generated ones, with a generator and a consistency check as the gate between them. - templates/
- Five shared prompt templates for the delegating modes, from a 254-byte ask to a 3 KB implement, plus a harness-compatibility note that generated Pi skills append, directing a host that lacks one of the tools to adapt rather than drop the requirement.
- Plugin manifests
- A Claude Code plugin manifest with its own self-hosting marketplace file, a Codex plugin manifest, a Codex marketplace file, and a
package.jsonthat doubles as the Pi manifest, the npm file allowlist and the place where the verification commands live — one script shipped to three hosts through their own installation rituals. - tests/
- Twenty-five files, 219 KB. The standard suite runs offline against temporary repositories and HOME directories with a fake
agy; the largest files cover mode behavior, recovery regressions, Windows process handling and developer experience, and validation against the realagyis a separate opt-in suite. - docs/ and scripts/
- A 38 KB reference with a Chinese counterpart, a 13 KB guide written to be read by another coding agent, eleven release-notes files, and the scripts that generate the Pi skills, the badges, the logo and the diagrams. The documentation is kept in pairs by rule: change one, change its counterpart.
Choices, and what they beat
A delegation interface rather than harness-native scheduling over behaving like a native tool with the host’s notification or scheduling privileges
The stated goal was agent-native async subagent tools that disclose context progressively and hand back control with enough information for the orchestrator to decide what to do next, and the same issue says explicitly that this does not imply a plugin has the notification or scheduling privileges of a harness-native tool. The implementation matches: there is no additional daemon and no scheduler.
Unrestricted by default, with hardening as an opt-in flag over the earlier fail-closed default that made setup a prerequisite
The migration table says it plainly: 0.1 made research and review restricted unless setup had run first, and 0.2 works out of the box with
--restrictedas the flag you actually reach for. The README writes the price of that choice next to it — these prompt instructions do not provide permission isolation, and a restricted run without an allowlist returns a success with an empty response.Stop tokenizing the command line over a smarter rule for where the flags end and the task begins
The shell had already split argv, and splitting it a second time meant a task that mentioned
git diff --checkdied with an unknown-flag error. The fix was not a better boundary rule but to stop tokenizing: one task source per call, and the task text opaque down to the byte.Review described in words rather than handed a diff over
--diff-file,--prand--targetflagsThe reviewer gathers its own evidence with
gh pr view,git diffand file reads and reports ambiguity instead of guessing. Removing the flags keeps the template a neutral skeleton and moves the code-review and plan-review axes into two reference files that the reviewer skill composes into the task string.No automatic retry after a timeout or a crash over relaunching the work with a larger budget
Hard expiry and AGY timeouts produce a terminal state with recovery metadata — the previous timeout doubled, capped at 120 minutes, an exact continuation command, and
requires_user_confirmation— and the calling agent must ask the user first. A ten-minute implementation run that had made real edits and then hit its limit used to be reported as a complete failure even thoughagyhad returned a conversation id the caller could have resumed, which is why timeouts became a state to inspect rather than an end.
Read fromREADME.md (10,272 bytes) and docs/REFERENCE.md (38 KB) — the modes and defaults table, the two-profile permission model, the flags table, the task-text rules, the jobs and state section, the migration tables from 0.1 through 0.4.5, and the Windows notes — plus file sizes under companion/, templates/, skills/ and tests/, the 109-entry file tree, and the bodies of issues and pull requests 1, 2, 3, 5, 6, 8, 9, 10, 11, 13, 16, 17, 19, 20, 21, 22, 23 and 24.
Build log
5 stages- 01
One month, twelve releases, and a list that actually got done
The repository was created on 2026-08-18 and
v0.3.0, marked as the first public release, landed the same afternoon; byv0.7.3on 2026-09-15 there were twelve releases, with av0.3.1tag that never became one and release notes for only eleven of them. Fifty-two commits carry the month — 40 in August, 12 in September — and the release titles read like a plan that was finished rather than a changelog: personas, implementer continuation, opaque task text, a new default model, a false-crash guard, streaming observation and recovery, recovery follow-ups with workspace attachment, task orchestration with AGY, and three releases of Windows work at the end. The oldest commit predates the repository’s creation date and is the one that started it: a single-brainagywrapper with modes, jobs and setup. The project is JavaScript with no runtime dependency beyond Node’s standard library, MIT-licensed, and it ended September with 696 stars, 46 forks, a single watcher and two open issues — a request for a second host CLI, and a proposal for a channel where the staffer could post findings after a session ends. Forty-two commits carry a co-author trailer and 40 of those name Claude, 37 of them Fable 5 and three Fable 5.1; of the three accounts that have committed, two contributed a single commit each. - 02
What actually crosses between the two agents
No shared memory, no request-response API and no daemon: what crosses between the agents is a shell command, a file and an id. The persona skills are instructions for the host agent, which composes the call itself and runs
node companion/agy-companion.mjs <mode> --prompt …. The companion parses the shell’s argv exactly once, interprets no quotes and inspects no byte of the task, so a task mentioninggit diff --checkreachesagybyte for byte instead of being read as a companion flag — which is whyv0.4.5deleted positional task text and accepts exactly one of--prompt,--prompt-fileor--stdin. For the background modes the companion writes a job spec and spawns a detached copy of itself as_worker <job-id>, which spawns theagychild and drains itsstream-jsonoutput continuously into a bounded progress snapshot. It attaches the workspace with--add-dir <repoRoot>, which used to be missing from the restricted path: before the fix, every restricted run ended as a success with an empty response. Results and workspace warnings go to stdout, while the telemetry line — mode, profile, model, duration, tokens, conversation id — goes to stderr and into the job log. Continuity between turns rides onagy’s own conversation id, recorded in the repository’s.agy-staff/state.json, which is whatcontinueandrestartreuse later. - 03
Where the staffer’s authority stops
Each persona is fixed rather than tunable:
askis synchronous and tool-free, the other four hand back a job id, and no flag changes that. Effort is pinned too — low forask, medium forstafferandreviewer, high forresearcherandimplementer— so delegating means picking a colleague, not tuning a model. The boundary lives in theleadskill, and the month’s last release exists because it was not sharp enough: hosts could delegate a search while continuing local investigation, leaving users to steer the handover and the wait themselves.v0.7.3replaced that with a general default — frame the assignment, delegate coherent substantive work, wait, assess the result, then follow up, take over or deliver — with acceptance that asks for task-appropriate artifacts and evidence, and exceptions kept for small work, useful host work during a wait and later verification. What a worker may do is governed by prompts rather than permissions: four templates default-deny irreversible or costly actions, and the same prompt opens what a task authorizes. Three git guards sit above it —implementmay start in a dirty workspace with a capped summary of paths already touched, whileresearchandreviewsnapshotgit status --porcelainbefore and after — and the README states the limit in one line: these prompt instructions do not provide permission isolation. - 04
Failure is a state to inspect, not a retry
Nothing in the runtime retries on its own: the companion never retries automatically. A job that runs out of time ends in a terminal state carrying recovery metadata —
requires_user_confirmation, asuggested_timeoutset to twice the previous timeout and capped at 120 minutes, and an exact continuation command — and the calling agent must ask the user whether to continue or stop. Hard expiry and a timeout reported by AGY are separated intoreason=hard_timeoutandreason=response_timeout; a known conversation turns either intoattentionand exit 5, and without one the job stays anerror. Recovery is an explicit new job linked to the old one, andcontinuerefuses when the job it would continue is still running — the follow-up is not queued, so the caller waits or cancels first. Intermediates follow the same instinct: after a warning-free success the raw event stream and snapshot are deleted, while failures, cancellation and hard timeouts keep them, so partial work can be inspected before anyone decides to continue. The same instinct produced a fix for a report that was never true: a job started in one sandbox context and collected from another looked crashed because the worker’s PID was not visible from where it was read, and a job misclassified that way now heals back to running when inspected from the context that started it. - 05
Two weeks of Windows, and a contribution kept whole
The repository had never been run on Windows: there was no
windowsHideand nowin32branch anywhere, and continuous integration only ran on Ubuntu. A user reported that dispatching a background job made console windows appear continuously, that neithercancelnor closing the terminal stopped them, and that the machine was unusable until thenode.exetree was killed from the task manager. A contributor started the fix on the state lock, where Windows reportsEPERMandEBUSYinstead; the maintainer completed it, and when a follow-up pull request grew out of that work he pushed his commits onto the contributor’s branch so the original author kept it. Continuous integration was split into three jobs, with the Windows tests behind a manual approval gate because a Windows run is slow. The best bug came last: a detached worker keeps its exited dispatcher’s PID as its parent on Windows, PIDs are reused quickly, and once reused an unrelated orphan looked like a descendant and was killed — a vanished job, no status file, and a log of exactly 178 bytes that no internal error path could produce. The fix only follows a parent link when the child was created after the parent, and has the leader fall totaskkill /PID <pid> /Frather than/T. Windows support is still described as best-effort and unvalidated against a real Windowsagyinstallation.
Adjacent records
All records →No. 073
Engram
A learning engine that installs into a coding agent: a curriculum architect breaks a topic into a first-principles concept map, a tutor makes you predict, attempt and explain before it explains, a blind assessor grades your verbatim free recall and writes a receipt for every verdict, and a deterministic FSRS-4.5 core in one Python file decides when each concept comes back — with explorable HTML built only for the concepts whose content rewards manipulation.
No. 066
makerskills
Twenty-one agent skills for running a one-person business — decide, unstuck, maker-council, deep-research, second-brain, company-brain, domain, jab-hook, pm, personal-cfo and the rest — each one a Markdown workflow document rather than a program, installed into Claude Code, Codex, Cursor or any host that reads the Agent Skill format, with every piece of personal state kept in a config directory the repository never touches.
No. 129
Agents Universe
An open-source agent platform that keeps one project context shared by everyone working in it. Agents read the whole knowledge base when a project is opened and write what they learn back into the same files while they work; knowledge is Markdown on disk with a database index behind it, and there is no embedding model or vector search.