rho is a fast, clean, local, private, and secure coding agent CLI built in Rust on Rig.
cargo install rho# Start interactive REPL
rho
# Run one-shot prompt
rho -p "summarize this repository"
# Select model in <provider>/<model> format
rho --model anthropic/claude-3-7-sonnet
rho --model gemini/gemini-2.5-flash
# Resume a previous session
rho --resume <SESSION_ID>
# Or browse recent sessions interactively
rho --resume-pickerrho includes 8 fast, native tools designed for coding agents:
read: Read file contents with line numbering, offset, and limit safeguards. Supports image sniffing and downscaling.write: Create or overwrite files, automatically creating missing parent directories.edit: Apply targeted, exact text replacements to files.bash: Execute shell commands with process group cleanup, timeout protection, and binary sanitization.fd: Fast, gitignore-aware workspace file discovery with smart-case regex matching.rg: Fast, line-oriented content searching; gitignore-aware, skips binary files, and bounds output.web_search: Search the web and retrieve structured summaries and URLs. Supports selectable search engines (Brave, DuckDuckGo Lite, Yahoo, Firecrawl).web_fetch: Fetch and extract clean markdown, text, HTML, CSV, or feeds from web URLs. Includes specialized extractors for GitHub (issues, PRs with diffs, commits, raw code, directory trees) and YouTube (metadata and timed dialogue transcripts).
Web tools, search providers, MCP, and permissions can be configured in config.toml or interactively toggled via /settings under Tools & Permissions.
Comprehensive guides are organized in docs/:
-
Providers, Configuration & Skills
- Authentication for 14+ providers (ChatGPT, Claude, Copilot, Antigravity, Anthropic, Gemini, DeepSeek, Local Ollama, and more).
- Custom OpenAI-compatible endpoints with private network protection.
- Hierarchical instruction loading (
AGENTS.md,CLAUDE.md,.cursorrules). - Declarative parameter-guided skills (
SKILL.md).
-
Interactive UI & Terminal Styling
- Dynamic upward-expanding multiline editor with stable screen scrollback.
- Live two-line footer metrics: token count, context percentage, speed, cost, and active model.
- In-memory FIFO message queueing (
Alt+Enter) and non-blocking background turns. - Universal native theme that adopts your terminal's 16-color palette, with SGR-dim secondary text, terminal-detected card fills, or configurable outline borders.
- Fenced Mermaid diagram rendering (Flowcharts with subgraphs, Sequence, State, Class, ER).
-
- Comprehensive keybinding reference organized by session flow, queueing, model controls, and editor navigation.
- Custom keybinding configuration (
~/.config/rho/keybindings.toml).
-
- Strict zero-telemetry policy: rho collects nothing, no analytics, no phone-home pings.
- In-process safety layer separating baseline safe inspection from mutating commands.
- Delegated Guard Model classification: automatically classifies shell commands using a fast local model (
qwen2.5-coder:7bvia Ollama) to execute safe commands without friction while intercepting hazardous operations. - Interactive approval modals: Allow, Edit (with multiline arrow navigation), Always (with pattern matching), and Deny (with feedback).
- Fail-closed execution in headless automation and on guard model errors or timeouts.
-
- Full Model Context Protocol (MCP) support:
stdioandstreamable-httptransports with OAuth 2.1 PKCE authorization. - Ecosystem interoperability with
~/.agents/mcp.json, project.agents/mcp.json, and.mcp.json. - Context budget tool gating (
directvsgatewayvsauto),/mcpTUI modal, andrho mcpmanagement suite. - One-shot lifecycle hooks in
.agents/hooks/for deterministic policy enforcement, tool gating, argument rewriting, and turn control without background daemons.
- Full Model Context Protocol (MCP) support:
-
Collab (Peer-to-Peer Live Pairing)
- Share active sessions terminal-to-terminal over end-to-end encrypted QUIC powered by Iroh.
- Capability-based cryptographic isolation: full interactive co-pilot vs. read-only spectator.
- REPL slash commands:
/collab start,/collab peers,/collab kick <id>,/collab rotate,/collab stop. - Collaborators join instantly with zero server setup via
rho join <ticket>. - Full interactive TUI for guests: alternate-screen rendering, markdown token streaming, styled tool cards, and snapshot transcript hydration.
- Shared interactive tool approval synchronization across terminals via in-TUI confirmation modals.
rho is built from the ground up with a strict privacy-first architecture:
- Zero Telemetry:
rhocollects nothing. There are no analytics, no telemetry, no tracking pixels, no crash reporters, and no phone-home pings. - Direct-to-Provider: Network requests travel strictly and directly between your machine and your configured model provider (e.g. Anthropic, OpenAI, Gemini, local Ollama). No prompts, source code, or completions are ever routed through intermediary proxies or secondary servers.
- 100% Local Storage: All authentication credentials, session histories, transcripts, and context caches reside exclusively on your local filesystem (in
~/.config/rho,~/.local/share/rho, and project.rho/). - Open Source & Auditable: The entire codebase is open source under MIT / Apache-2.0 and contains zero analytics SDKs or tracking dependencies.
Run the test suite, linter, and format checks:
cargo test --workspace
make clippy
cargo fmt --all -- --check