Windows desktop console
AgentScope
Trace local Codex and Claude Code processes, explain session relationships with evidence and confidence, and keep risky operations behind plans, backups, quarantine records, and journals.
- Asset
- AgentScope-0.1.0-Portable-x64.exe
- SHA256
- 078BE46458B4...67C6A6DB3E
Product tour
The desktop UI is the product signal.
The public page should feel like AgentScope itself: dense, controlled, evidence-heavy, and clear about what is known, what is inferred, and what stays blocked.
Process rows expose agent kind, PID, process tree context, candidate score parts, path evidence, and confidence labels without hiding the heuristic parts.
Parent-child sessions and process-to-session candidates stay filterable by confidence.
Backup, delete, import, restore, resume, and fork actions stay anchored to a selected session.
Evidence model
Associations stay explainable.
AgentScope never turns a weak timing hint into certainty. Each link between a process and a session carries evidence, confidence, and the reason it was scored that way.
PID maps, child processes, and indexed session metadata can raise confidence.
Working directories and encoded project paths are scored alongside other signals.
Codex versioned SQLite stores and rollout JSONL roots are discovered without reading hidden reasoning.
Temporal proximity can be shown as weak evidence, not promoted to an exact match.
Local sources
Index the local state that actually exists.
Core views
A control console, not a chat surface.
Safety boundaries
Destructive operations are planned, backed up, and evidenced.
AgentScope treats local agent state as sensitive. Session delete, import, restore, and config mutation flows are blocked or confirmed before they touch files or SQLite rows.
- PlanResolve target session, blockers, protected roles.
- BackupWrite AgentScope backup manifest and file hashes.
- QuarantineMove allowed session files, never global credentials.
- JournalRecord every file and row-level SQLite step.
- RestoreRecover only from validated AgentScope manifests.
Transcript, history, log, executable, DB, auth, config, plugin, skill, and rule paths are not opened as body text.
AgentScope parses local metadata and safe fields. It does not read hidden vendor reasoning or MCP payload bodies.
Exact PID matches, high-confidence active candidates, and child sessions keep destructive actions from proceeding.
Raw config edits stay blocked unless a controlled surface can verify backup, journal, atomic write, and read-back state.
Codex Control
Structured config changes with read-back verification.
Raw `config.toml` editing stays behind structured controls. AgentScope classifies official keys, known local keys, unverified advanced keys, reserved provider IDs, sensitive values, and unsafe TOML before it writes anything.
- sha256 check before write
- backup and mutation journal
- atomic temp write, fsync, rename
- read-back verification of changed keys
- clear warning that changes usually affect new Codex sessions
model = "gpt-5.4"model_reasoning_effort = "high" # advancedatomic write, fsync, rename, journalread-back verified 2 changed keysrunning Codex processes may not hot-reload configControl surfaces
Known, unknown, sensitive, and reserved are different states.
Allowlisted scalar config with read-back verification.
Editable only when scalar/string-array and not sensitive.
Blocked from structured editing and display summaries.
Built-in providers are not directly edited as custom tables.
MCP identity
Identify tools from evidence, not payloads.
AgentScope labels Codex-launched MCP helpers by safe config metadata, process markers, and parent-tree evidence. Generic `node` or `python` commands are never enough on their own.
Docs paths
Document what the tool actually guarantees.
Release
Download the Windows portable build.
v0.1.0 is the current stable release. The portable artifact is built for Windows x64 and published through GitHub Releases.
078BE46458B4DABC33B6DD192EEEB7AE8E1D2408F91F6AAB55B2EA67C6A6DB3E