Type to search the docs and updates.

Browse documentation

Agents

agents/ defines subagents: specialists the main agent hands a task to, each with its own instructions, tools, and model. A reviewer that only reads, an architect on the strongest model, a test writer on a cheaper one.

Why a subagent instead of more instructions in the main session:

  • Clean context. A subagent works in its own context and hands back a result, so its exploration stays out of the main conversation.
  • Least privilege. tools, readonly, and mcpServers narrow what it may touch.
  • The right model per role. model and effort set cost and depth per agent, and per tool.
  • One definition. Every target with an agent surface gets its native file from the same spec; the rest get a coverage note.

Write one

agnostic-ai new agent code-reviewer creates agents/code-reviewer.md. The frontmatter configures the agent. The body is its system prompt.

---
name: code-reviewer
description: Reviews diffs for bugs, style, and architectural issues. Use after a change set is complete.
tools: [Read, Grep, Bash]
model: sonnet
---

You are a code reviewer. Report concise findings with `file:line` references.

Write description for the main agent: it reads it to decide when to delegate, so say what the agent does and when to use it.

A read-only auditor on a stronger model for Claude Code, with a fallback everywhere else and one MCP server:

---
name: security-auditor
description: Checks a diff for injection, leaked secrets, and unsafe input handling. Use before merging auth or payment changes.
readonly: true
model: {claude: opus, default: gpt-5.5}
mcpServers: [github]
---

List each finding with its `file:line`, the attack it enables, and the smallest fix.

Fields

FieldRequiredDefaultDescription
namenofilename without .mdAgent identifier and output filename.
descriptionnoemptyWhen to delegate to the agent. Tools show it in listings and use it to pick an agent.
toolsnounsetTools the agent may invoke. See tools support by target.
modelnounsetA string for every target, or a map per target. See per-target model and effort.
effortnounsetA string or integer for every target, or a map per target. See per-target model and effort.
colornounsetBadge color. See color support by target.
readonlynounsettrue restricts the agent to reading. Cursor: restricted. Claude: disallowedTools: Write, Edit, NotebookEdit (Bash stays allowed). Codex: sandbox_mode = "read-only". Factory: tools: read-only with mcpServers: [] unless servers are listed (wins over a portable tools list). An explicit x-claude.disallowedTools, x-codex.sandbox_mode, or x-factory.tools wins. Other targets report a coverage note. false is a no-op.
memorynounsetPersistent memory scope: user, project, or local.
mcpServersnounsetMCP servers this agent may reach. See mcpServers support by target.
permissionModenounsetApproval boundary for this agent. See permissionMode and agent hooks.
hooksnounsetLifecycle hooks scoped to this agent. See permissionMode and agent hooks.

Any other frontmatter field passes through unchanged.

memory gives the agent a directory that survives across sessions. Only Claude Code is confirmed to act on it; Qoder gets the key unconfirmed, Junie passes it through, and every other adapter drops it.

Per-target model and effort

model: and effort: each take a scalar or a map keyed by target name, with an optional default. Precedence: x-<target>.<key>, then <key>.<target>, then <key>.default, then the key is not written and the tool uses its own default. x-<target>.<key>: null deletes it. A non-scalar value under a target key falls through to default.

WantWrite
Same model everywheremodel: sonnet
Per target, with a fallbackmodel: {claude: sonnet, default: gpt-4o}
Per target, tool default elsewheremodel: {claude: sonnet}
Different effort per targeteffort: {claude: xhigh, default: high}
---
name: architect
description: Designs the change before anyone codes it.
model:
  claude: opus
  cursor: "claude-opus-5[effort=high]"
  default: gpt-5.5
effort:
  claude: xhigh
  qoder: 8000
  factory: max
  default: high
x-codex:
  model_reasoning_effort: xhigh
---

Result: Claude gets opus and xhigh; Qoder gpt-5.5 and 8000; Junie gpt-5.5 and high; Cursor claude-opus-5[effort=high] (resolved effort discarded); Codex gpt-5.5 with x-codex overriding effort to xhigh; Factory gpt-5.5 with no reasoningEffort (max is outside its enum, coverage note); Trae drops both with notes.

effort values by target. Only the targets listed were checked. Omitting effort inherits the session's level.

TargetValuesHow it lands
Claude Codelow, medium, high, xhigh, max, model dependentVerbatim effort, not validated
QoderSame five names, or a positive integerVerbatim effort
JunieAlias of reasoningLevelVerbatim effort
Factorylow, medium, highreasoningEffort. Other values and integers raise a coverage note
CodexAny stringmodel_reasoning_effort; x-codex.model_reasoning_effort wins. An integer raises a note
CursornoneCoverage note. Put it in the model id: model: {cursor: "claude-opus-5[effort=high]"}
CopilotnoneCoverage note. x-copilot.effort still passes through
Every other targetnoneCoverage note

Cursor encodes effort in the model string, so it rides on the model map. Factory ignores reasoningEffort when model resolves to inherit.

tools support by target

Only the targets listed were checked. A target that cannot honor tools prints a coverage note at sync time, so tools: [Read] never silently becomes an unrestricted agent.

TargetBehavior
Claude Code, Copilot, JuniePassed through as a YAML list
Qoder, TraePassed through as a comma-separated string (tools: Read, Bash)
Windsurf, Kiro, Factory, GeminiTranslated to native names
Antigravity, OpenHands, Goose, Codex, Cursor, Augment, Kilo CodeDropped with a note

Translation can widen access: on Kiro, Edit alone also permits delete_file. Most targets accept native names through x-<target>.tools, which bypasses translation.

mcpServers support by target

Only the targets listed were checked. A top-level mcpServers list narrows which MCP servers one agent may reach. Omitting it inherits the session's full set.

TargetBehavior
Claude Code, Junie, FactoryServer names, written to the agent file
QoderServer names or inline objects, written to the agent file
OpenHandsInline definitions only. Set x-openhands.mcp_servers
AntigravityInline objects only. Set x-antigravity.mcpServers
KiroInline definitions only. Set x-kiro.mcpServers

Every other target drops the list with a coverage note; the three inline targets' notes name the x-<target> key to set.

An empty list is not portable. Junie treats mcpServers: [] as keeping every configured server. Factory treats it as excluding every server. List the servers you want instead.

permissionMode and agent hooks support by target

Only the targets listed were checked. permissionMode sets one delegated agent's approval boundary; hooks scopes lifecycle hooks to it. Omitting either inherits the parent session.

TargetpermissionModeAgent hooks
Claude CodeSeven values, manual aliases defaultWritten to the agent file
QoderSix values, another one is reportedSeven events, a wider one is reported
OpenHandsDifferent names (always_confirm, never_confirm, confirm_risky). Set x-openhandsSix snake_case events, command handlers only. Set x-openhands

On Qoder, bypassPermissions is demoted to acceptEdits when security policy disables it, and agent scope runs fewer hook events than project scope.

color support by target

Only the targets listed were checked. color is written verbatim and not validated. An unrecognized value is cosmetic: the agent still runs.

TargetValues
AugmentFree text, an ANSI color name
Kilo CodeHex or a theme token
QoderOne of eight names
OpenHandsDropped with a note. Set x-openhands.color to a Rich color name

color: blue is valid on Augment and Qoder but is neither hex nor a Kilo Code theme token. OpenHands shares its .agents/agents/ tree with Goose, whose frontmatter has no color, so a portable color prints a coverage note there.