AgentScope

Windows desktop console

AgentScope

Trace local Codex and Claude Code processes, explain session relationships with evidence and confidence, and keep risky operations behind plans, backups, quarantine records, and journals.

Asset
AgentScope-0.1.0-Portable-x64.exe
SHA256
078BE46458B4...67C6A6DB3E
Not a chat UI AgentScope observes and controls local coding agent state. It does not replace Codex or Claude Code.
Not a Kanban board The primary objects are processes, sessions, transcripts, relations, config surfaces, and operation journals.
Not a file manager Privileged local paths stay behind explicit open/reveal allowlists and safety roles.

Product tour

The desktop UI is the product signal.

The public page should feel like AgentScope itself: dense, controlled, evidence-heavy, and clear about what is known, what is inferred, and what stays blocked.

Processes Separate real matches from weak candidates.

Process rows expose agent kind, PID, process tree context, candidate score parts, path evidence, and confidence labels without hiding the heuristic parts.

Relations Map local agent relationships.

Parent-child sessions and process-to-session candidates stay filterable by confidence.

Sessions Operate with records, not guesses.

Backup, delete, import, restore, resume, and fork actions stay anchored to a selected session.

Evidence model

Associations stay explainable.

AgentScope never turns a weak timing hint into certainty. Each link between a process and a session carries evidence, confidence, and the reason it was scored that way.

PID Exact when the local map says so

PID maps, child processes, and indexed session metadata can raise confidence.

cwd Path evidence, not identity by itself

Working directories and encoded project paths are scored alongside other signals.

JSONL / SQLite Safe metadata indexing

Codex versioned SQLite stores and rollout JSONL roots are discovered without reading hidden reasoning.

Time Time-only remains unknown

Temporal proximity can be shown as weak evidence, not promoted to an exact match.

exact indexed heuristic unknown

Local sources

Index the local state that actually exists.

Windows processes Win32_Process rows, command summaries, runtime fields, process trees, window titles.
Codex stores Versioned `state_*.sqlite`, `logs_*.sqlite`, rollout roots, archives, goals, memories.
Claude maps Session PID files, project transcript paths, daemon/job sidecars, stale PID handling.
AgentScope records Backups, quarantine journals, restore manifests, redacted exports, operation evidence.

Core views

A control console, not a chat surface.

Processes Windows `Win32_Process`, runtime fields, process trees, MCP helpers.
Sessions Codex and Claude session rows with transcript path evidence and safe actions.
Relations Parent-child sessions, process-to-session candidates, confidence filters.
Doctor Diagnostics for local stores, indexes, permissions, and runtime constraints.
Codex Control Structured config mutations with backups, journals, and read-back verification.
Settings Safe/read-only mode, motion preference, density, language, search boundaries.

Safety boundaries

Destructive operations are planned, backed up, and evidenced.

AgentScope treats local agent state as sensitive. Session delete, import, restore, and config mutation flows are blocked or confirmed before they touch files or SQLite rows.

  1. PlanResolve target session, blockers, protected roles.
  2. BackupWrite AgentScope backup manifest and file hashes.
  3. QuarantineMove allowed session files, never global credentials.
  4. JournalRecord every file and row-level SQLite step.
  5. RestoreRecover only from validated AgentScope manifests.
Reveal-only paths

Transcript, history, log, executable, DB, auth, config, plugin, skill, and rule paths are not opened as body text.

No hidden reasoning

AgentScope parses local metadata and safe fields. It does not read hidden vendor reasoning or MCP payload bodies.

Active sessions block delete

Exact PID matches, high-confidence active candidates, and child sessions keep destructive actions from proceeding.

Config mutation is structured

Raw config edits stay blocked unless a controlled surface can verify backup, journal, atomic write, and read-back state.

Codex Control

Structured config changes with read-back verification.

Raw `config.toml` editing stays behind structured controls. AgentScope classifies official keys, known local keys, unverified advanced keys, reserved provider IDs, sensitive values, and unsafe TOML before it writes anything.

  • sha256 check before write
  • backup and mutation journal
  • atomic temp write, fsync, rename
  • read-back verification of changed keys
  • clear warning that changes usually affect new Codex sessions
Applying structured patch config.toml current snapshot loaded
writing
...
1model = "gpt-5.4"
2model_reasoning_effort = "high" # advanced
*atomic write, fsync, rename, journal
*read-back verified 2 changed keys
*running Codex processes may not hot-reload config

Control surfaces

Known, unknown, sensitive, and reserved are different states.

Official key model

Allowlisted scalar config with read-back verification.

Unverified advanced experimental_flag

Editable only when scalar/string-array and not sensitive.

Sensitive key api_key

Blocked from structured editing and display summaries.

Reserved provider model_providers.openai.*

Built-in providers are not directly edited as custom tables.

MCP identity

Identify tools from evidence, not payloads.

AgentScope labels Codex-launched MCP helpers by safe config metadata, process markers, and parent-tree evidence. Generic `node` or `python` commands are never enough on their own.

process.mcp.config server table + safe summary
command/path marker known local tool evidence
parent tree Codex-launched helper context
redaction tokens and API keys excluded
Not read or displayed as body content MCP stdio/HTTP payloads browser pages and screenshots Playwright traces hidden vendor reasoning credentials and auth tokens memory body text

Docs paths

Document what the tool actually guarantees.

Release

Download the Windows portable build.

v0.1.0 is the current stable release. The portable artifact is built for Windows x64 and published through GitHub Releases.

078BE46458B4DABC33B6DD192EEEB7AE8E1D2408F91F6AAB55B2EA67C6A6DB3E