Skip to main content

Brave Bot

Brave Bot is a general-purpose coding agent for your terminal. It reads a repository, edits files, runs programs and answers questions about the code in front of it, and it is meant as a drop-in replacement for the agents you already use.

Its defining property is structural resistance to indirect prompt injection. Most agents ask a model to be careful with the web pages, dependency READMEs and command output it reads. Brave Bot does not ask: content that nobody vouched for never reaches the part of the system that decides what to do next. That is a property of the plumbing rather than of the prompt, so it holds whatever the content says.

npm install -g @brave/bravebot
cd your-project
bravebot

What it can do

  • Answer questions about a codebase. Read files, list directories and search for literal text, with paging so a large file does not swallow the conversation. See Tools.
  • Write and edit code. Every write and every edit is approved by you first, as a body or as a diff. See Approvals and permissions.
  • Run programs. run takes an argv pipeline rather than a command line, so nothing is ever handed to a shell on the model's behalf. See the run tool.
  • Run your own shell commands. Type ! on an empty prompt and the line goes to $SHELL, with globs and redirection intact, and its output reaches the model in full so you can follow it with "fix the first failure". See Shell mode.
  • Work on content it is not allowed to read. Quarantined files are handed to an isolated processor that rewrites them, and the result is written back without either the planner or the driver ever seeing the bytes. See How Brave Bot works.
  • Take standing instructions. AGENTS.md and skills apply to every task in a directory. See Instructions and Skills.
  • Show its work. Every gate decision — what was checked, what label a value carried, what was released — is recorded and can be read live with Ctrl-T or after the fact with --trace. See The audit trail.

What makes it different

Labels, not vibesEvery value carries a label on two axes: trusted or untrusted, public or private. Labels only ever degrade, and no code path can hand a value a better one than its inputs had.
Quarantine, not warningsUntrusted content is never placed in a message to the model. The planner gets a reference — origin, line count, byte count, label — and acts on content it cannot read.
Approval bound to what you sawAn approval is single-use and bound to the exact value it was given for. Approving a write is not approving a run, and no approval survives into a later session unless it was explicitly a standing one.
No shell for the plannerThe model never gets a shell tool. Not behind a capability, not behind a prompt. It composes argv stages instead.
Specified clause by clauseBehaviour is written down as numbered clauses, each naming the tests that pin it, and the code is reviewed against them.

Start here

Status

Brave Bot is experimental. It is developed in the open at brave-experiments/brave-bot, where the mini-specs are the source of truth for how it behaves. Where this site and a spec disagree, believe the spec and please file an issue.