gate4agent
A Rust workbench for running, watching and orchestrating CLI coding agents across machines — wrapping Claude Code, Codex, Kimi and Grok behind one transport, one relay and one operator protocol.

What it is
A Rust stack that wraps the vendor CLIs people already use — Claude Code, Codex, Kimi Code, Grok — and turns them into sessions that can be spawned, streamed, resumed and observed from anywhere. It is layered: a transport core that owns one subprocess, a node that wraps every provider on one machine, a relay that connects any number of nodes to their clients, a stateful harness that adds task tracking and session continuation, and a terminal client that speaks only to the harness. Everything is loopback-only by default and credentials are read from the environment, never from the command line.
Who built itThe author of all 465 commits, under a single Gmail address. The repository itself is owned by a different account, ZENG3LD, so the owner and the committer are not the same identity and the contributor list shows one person. He also maintains the uzor-tui crate on crates.io, which this project’s terminal client depends on, and the README notes with some care that a fresh clone builds every crate including the TUI with no sibling checkouts.
Build log
8 stages- 01
Seventy-one per cent of the commits name their co-author
Of 465 commits, 328 carry a co-author trailer naming a model — the highest proportion this archive has recorded, against 56 per cent on AI Comic Builder and 23 per cent on DeepSeek Harness. The spread is also unusually wide: Claude Opus 5 on 131, Fable 5.1 on 79, Fable 5 on 63, Opus 4.6 on 49, Sonnet 4.6 on four, one Opus 5.5 with a million-token context, and a single Grok 4.6. Every one of the 465 commits is attached to the same account, and the repository is owned by a different one, so the attribution question here is not who wrote it — it is which of two identities counts as the author.
- 02
A workbench in layers, wrapping CLIs rather than replacing them
The design decision underneath everything is that the vendor tools stay the vendor tools. gate4agent does not reimplement an agent; it owns the processes. Providers are wrapped by a transport core, a node wraps every provider on one machine along with the file browser, local git and worktrees, a relay connects any number of nodes to their clients, and a harness sits behind a single application-facing protocol adding a task kanban over SQLite, session extraction and continuation, and delivery of skills, plugins and MCP configuration. A terminal client talks only to the harness and never to the relay directly. The layers run in one direction — providers, node, relay, harness, client — and the README states that direction as a rule rather than a diagram. One layer deserves singling out: observation is read-only by construction, projecting monitoring facts out of provider sessions and never prompts, transcripts or credentials.
- 03
The README publishes which of its own paths are broken
Most projects describe what works. This one carries two tables of what does not. The provider matrix says Kimi Code’s current PTY canary exits before readiness because the local provider reported a permission error, and that no current PTY lifecycle is claimed for it; that Grok has a resume gap which is tracked; that qwen-code is wired but unverified; and that Gemini and OpenCode were last live-verified two minor versions ago and are outside the product target. The testing table repeats it per mode and pins versions — Claude Code 2.1.224, Codex 0.144.6, Kimi Code 0.31.1 — including the entry that Claude Code’s current resume canary failed. It also states the boundary of the claim: vendor tests are opt-in, need an installed and authenticated CLI, and plain
cargo testis hermetic and never touches a provider account. A support matrix that names its own failing canary is worth more than one that does not. - 04
Four processes, and two of the ports are not in the source
Bringing up the whole stack means four processes: a node, two relays and a harness. The harness deliberately does not share the primary relay — it connects out through a second relay instance of its own — and the README warns that skipping that second instance makes the harness fail at startup with a bare connect error. The endpoint table then admits something unusual: only the node’s port and the relay’s port are compiled-in defaults, while the harness’s two ports are conventions passed on the command line, so searching the source for them finds nothing. That is the kind of sentence that saves a reader an hour, and it is the sort of thing documentation usually leaves out because it makes the design look accidental.
- 05
Prompts are argv, never a shell string
The transport core has a security posture worth copying. Its launch planning always produces an executable plus an argument vector and never concatenates a prompt into a shell command. Input preparation produces bounded, UTF-8-safe writes and neutralises bracketed-paste sequences embedded in the text, which is the terminal equivalent of escaping a quote. On Windows, the reviewed npm installations of Claude, Codex and Kimi are resolved to their direct executable or JavaScript entrypoint so prompts stay real argv and stdin data instead of being reparsed by a command shim; unknown wrappers fall back to a shell knowingly. And the terminal layer, which owns an interactive process with a VT100 screen model and bounded replay, never auto-accepts a workspace-trust or update prompt — those stay on screen for the operator to answer. Four separate decisions, all of them about not letting generated text become something that gets executed.
- 06
One CLAUDE.md per crate
The repository root has an 8,719-byte
CLAUDE.md, and seven of the crates carry one of their own — 385 to 875 bytes each, in the catalog, engine, handle, kernel, node-protocol, PTY and types crates. Instructions live next to the code they describe rather than in one file at the top, which is the opposite of how this archive’s other agent-configured projects arrange it; DeepSeek Harness keeps one 17-kilobyte guide and a single link, and PocketPilot keeps one document that outside contributors cite by clause. A per-crate file is a smaller commitment made more often, and it matches a repository where the interesting constraints are local: what a node protocol may assume, what the PTY layer is allowed to do on Windows. - 07
A test supervisor because plain cargo test cannot
Windows terminal tests need something the standard test runner will not provide, so this project ships its own: a headless supervisor binary that suppresses Windows fault dialogs and enforces a hard per-test timeout, because a process that hangs on a dialog never returns and a suite that waits forever is indistinguishable from a suite that is working. Tests gated on it reject themselves outright when run any other way. The README also records the reasoning behind a build detail — that builds share one target directory because a per-run directory copies the whole dependency graph and they accumulate, and that overlapping builds simply wait on Cargo’s lock rather than failing. Most projects would have left both of those as tribal knowledge.
- 08
Nine stars, no releases, no issues
Nothing outside the repository has touched it. Nine stars, one fork, no watchers, and in five and a half months nobody has opened a single issue or pull request — the tracker is empty, which is why this record has nothing to quote from one. There are no releases and no tags either: the newest commit is a release commit for version 0.4.0, described as the first wave without the SQLite binding and with tokio macros for a standalone build, so versions advance by commit rather than by published release. Eight hundred and twenty files and 465 commits, 425 of them since July, with essentially no audience. Two things complicate the picture in the project’s favour: a third of the reference metadata is drawn from another project’s public tool descriptions and credited and pinned by revision, with the README calling those entries transitional debt rather than support claims; and the author maintains the terminal framework this depends on and says plainly that a fresh clone needs no sibling checkout. It is a large, disciplined project that has not yet found anyone to be disciplined for.
Adjacent records
All records →No. 061
DeepSeek Harness
DeepSeek’s agent harness, built so that the model adapter, the tool registry, the session log and the agent loop itself are plugins — swapped from a configuration file rather than a fork.
No. 060
VibeGame
Describe a game in one sentence and a team of agents divides the work — an architect plans it, a programmer builds it, an auditor checks the code against the plan, and a player has to actually play it before the task is accepted.
No. 051
AI Job Search
A job-application framework that runs on your own machine: it scores postings against a profile you fill in, drafts a tailored CV and cover letter in LaTeX, compiles them, reads the rendered PDF back — and stops one step short of sending anything.