Reply in the same language as the user.
This is a TypeScript monorepo built for agent-assisted development. Keep the root AGENTS.md limited to hot-path rules: the project map, hard constraints, and workflow requirements — things every task needs to know.
- Think from first principles. Start from real requirements, code facts, and verification results; if the goal is unclear, discuss it with the user first.
- Treat code, not documentation, as the source of truth. Unless the user explicitly says otherwise, do not read ordinary Markdown just to understand the implementation.
- Before making code changes, read the relevant code and the most recent constraints, and follow the nearest
AGENTS.mdin the directory tree. - Keep changes focused. Do not slip in unrelated refactors along the way.
- When committing, do not add any co-author attribution, and do not reveal the identity of the agent in commit messages, PR descriptions, or any explanatory text.
apps/kimi-code: the CLI / TUI application. It consumes core capabilities through@moonshot-ai/kimi-code-sdkand must not depend directly on@moonshot-ai/agent-core. When writing or modifying its terminal UI, use thewrite-tuiskill (.agents/skills/write-tui/SKILL.md).apps/kimi-web: the browser web UI, a peer to the TUI. Vue 3 + Vite + vue-i18n; talks to the server over REST + WebSocket under/api/v1. It must not depend on@moonshot-ai/agent-core(wire types are re-implemented locally). Debug against the two engines via the rootpnpm dev:v1/pnpm dev:v2backend scripts — the dev Sidebar shows the active backend and switches it at runtime. Seeapps/kimi-web/AGENTS.md.apps/vis,apps/vis/server,apps/vis/web: visual debugging tools for sessions and replays.apps/kimi-inspect: web inspector for the kap-server/api/v1/debugRPC surface — workspace/session browser, per-session chat, and Service panels (data + trigger buttons) for the Session and Agent scopes. A left icon rail (src/components/NavRail.tsx) switches top-level views: the Chat workspace, the Model Catalog (src/components/ModelCatalogView.tsx— every Provider with its Models and the default marker, viaIModelCatalog/IModelServicechannel proxies), and App Services (src/components/AppServicesView.tsx— the app-scope Service reflection, full width; the Agent scope stays in the Chat view's right dock (src/components/RightPanel.tsx) across two tabs: theAgenttab (Inspector: agent switcher + a Plan lookup card —PlanCardinsrc/components/Inspector.tsx— queryingGET /sessions/{id}/transcript/plan(one tool_call_id, or every plan of the agent) viasrc/transcript/api.ts'sfetchTranscriptPlan— plus the agent Service panels) and theStatetab (every key an Agent Service registered into the agent-state container, polled live viaIAgentStateService.snapshot()— the same live diff-tree view as the session State tab, sharingStateCardfromsrc/components/StateCard.tsx), while the Session scope has its own column right next to the session-list sidebar (src/components/SessionPane.tsx) with two tabs: Services (the pending-interactions card —src/components/InteractionsCard.tsx— plus the session Service panels) and State (every key a Session Service registered into the session-state container, read on demand viaISessionStateService.snapshot())). Expanding a Model opens the model inspector inside that view: provider/model config layers plus the resolved runtime view with per-value provenance (config / override / builtin / env / synthesized), served on demand byIModelCatalog.inspect— the same resolution pass the runtime'sgetserves, traced viaResolutionTraceCollectorand assembled bykosong/model/inspection.ts. Built on its own old-klient-style channel layer (src/channel/: the VS CodeProxyChannelmodel — service-boundIChannel, HTTPProxyChannelfor calls routed to/api/v1/debug), typed byagent-core-v2Service interfaces;GET /api/v1/debug/channelsloads the whole wire protocol 1:1 (every scoped Service, no whitelist). There is no Service-event push channel: panels fetch/refresh on demand (Sidebarpolls react-query on a 15 s interval), and a connection failure shows a blocking "Debug surface unavailable" screen instead of falling back anywhere. Session-level coarse status is the one exception:src/activity/holds a second/api/v1/wsclient (GlobalEventsWs) that subscribes to nothing and consumes the server-pushed global facts —event.session.work_changedupdates a per-session activity map (SessionActivityHub+ subscribe/version store, seeded on connect/reconnect fromGET /api/v1/sessions), whileevent.session.created/session.meta.updatedinvalidate the['sessions']query; theSidebarsession rows renderrunning/approval/question/failedbadges from it viauseSessionActivities. The Vite dev server proxies/apito a running kap-server (KIMI_SERVER_URL, defaulthttp://127.0.0.1:58627) and exposesGET /__inspect/servers(vite/serverDiscovery.ts), which scans the local kap-server instance registry (~/.kimi-code/server/instances+ legacylock) and the home token so the app can zero-config auto-connect and switch servers from the header dropdown at runtime. The per-session chat (src/components/ChatView.tsx) renders turn-granularly from the transcript surface instead of context memory: full state is read fromGET /api/v1/sessions/{id}/transcript(initial load = newest page, refreshes re-read from the tail backwards), older history auto-pages withbefore_turnvia an IntersectionObserver sentinel at the top of the scroll view, and each timeline item is wrapped incontent-visibility: auto+contain-intrinsic-sizeso the browser virtualizes off-screen rendering natively (no windowing library);/api/v1/wsis an incremental channel (transcript.ops, gradeblock— the cheapest grade that still carries whole-state frame upserts, dropping per-tokenappendframes;transcript.resetis ignored by the store, surfaced only to the audit recorder via the optionalonResethandler). The channel tracks the op-batch watermark: a dedicatedsubscribe_v2control frame carries the per-agent grades and thetranscript_sincecursor, a seq gap / reconnect /resync_required/ append gap triggers a point-to-point catch-up (fetchTranscriptOps→GET .../transcript/ops?since_seq=), and any legacy/incomplete answer falls back to the full REST refresh. Convergence reuses@moonshot-ai/transcript's L2 reducer (src/transcript/: REST/WS clients + store; the data model and reducer come from the package, nothing is re-implemented locally). The Transcript audit panel (src/components/audit/, theAudittab of the chat view's right dock —src/components/RightPanel.tsx, fed the trail byChatView'sonTrailChange) replays how the visible store was built: anAuditTrail(src/audit/) records every step — each REST page (request + replace/prepend), every WS frame (transcript.opslive/buffered/flushed/catchup,transcript.reset), loss signals, and prompt/cancel actions — with the resulting immutableAgentStateper entry; the panel offers a draggable timeline plus a Diff tab (structural diff vs the previous entry: added/modified/removed colored, long strings tail-truncated, all fields kept), a full State view, and the raw Event payload.packages/agent-core: the unified agent engine, including Agent, Session, profile, skills, tools, plan, permission, background, records, the in-process DI service layer (src/services/), and other core capabilities.packages/node-sdk: the public TypeScript SDK and harness.packages/kosong: the LLM / provider abstraction layer.packages/kaos: the execution environment and file/process abstractions.packages/oauth: Kimi OAuth and managed auth utilities.packages/telemetry: shared client-side telemetry infrastructure.packages/transcript: the isomorphic transcript rendering data layer — agent-granular L1 store, idempotent L2 operations,off/turn/block/deltaL3 subscription granularity, framework-free L4 view registry, and turn-cursor pagination. Pure TypeScript (browser-safe, no engine imports) and the sole owner of all transcript contract types (src/contract/); consumed bypackages/kap-server(engine events → transcript, REST + WS surface; live stores backfill history from the persisted per-agent wire records — main on first attach, any agent on demand, cold sessions rebuild any agent — with 0-based turn ordinals matching the engine's). The cold rebuild is a two-level fold overwire.jsonlas the single source of truth:history/groupTurns.ts(context messages → turn tree) plushistory/foldFacts.ts(non-context records → tasks, interactions, todos, goal/plan/swarm meta, and end-appended markers/taskrefs; interactions left pending at shutdown fold tocancelled). Plan content is a recorded fact too: each ExitPlanMode review submission offloads the document toagents/<agentId>/plan/<planId>/v<N>.mdand persists a reference-onlyplan.revisionrecord ({id, version, path, sha256, bytes}), which projects — live and cold — to aplan.revisionmarker and themodes.planbadge ({reviewPath, version}). It also owns the op-batch sequencing contract (transcriptSeqSchemaincontract/schema.ts): a per-(session, agent) monotonic batchseqontranscript.ops/transcript.reset/ the REST transcript response, thetranscript_sincesubscription cursor, and theGET .../transcript/opscatch-up response shape — every field optional so pre-seq peers fall back to loss-signal-driven refreshes. Beyond the timeline, the model carries wire-equivalent detail: steps carryusage/finishReason/timing(LLM latencies) /retry/ interrupt reason, turns carrydurationMs/error/usage, tool frames carry the streamedinputTextand the latestprogress, tasks carry subagentresultSummary/error/stateReason/usage,meta.agentmirrors the agent status slices (model / usage / context / permission / phase), a globalpromptsentity (opprompt.upsert) tracks the prompt queue, andhook.resultlands as a'hook'marker. These live-projected fields are NOT backfilled by the cold rebuild (known limitation).packages/kap-server: the Kimi Code server, backed by the DI × Scope agent engine (@moonshot-ai/agent-core-v2). Exposes sessions over REST + WebSocket (/api/v1+/api/v1/ws); bootstrapped fromsrc/start.tsand consumed byapps/kimi-code. The RPC surface is/api/v1/debug/*— a reflection dispatcher over the ENTIRE scoped DI registry (every Service callable, no whitelist;src/transport/registerDebugRoutes.ts+serviceDispatcherRoutes.ts), mounted only with--debug-endpointson a loopback bind and gated by the global bearer auth; repo dev scripts pass the flag. Its transcript surface implements the op-batch sequencing contract:TranscriptService.dispatchOpsassigns every dispatched batch a per-agent consecutiveseqand retains it in a bounded in-memory journal (TRANSCRIPT_OPS_JOURNAL_CAPACITY, dies with the live store); WStranscript.ops/transcript.resetpayloads carry the seq/watermark, atranscript_sincesubscription cursor (carried, with the per-agent grades, by thesubscribe_v2control frame — the only transcript subscription channel; its agent-grained counterpartunsubscribe_v2detaches listed agents' streams, or the whole session's whenagent_idsis absent, letting the detached agents' legacy events flow again) replays journaled batches instead of a baseline reset when the journal covers it, andGET /sessions/{id}/transcript/ops?since_seq=serves point-to-point catch-up (complete: false= journal can't cover or session cold → caller falls back to a full refresh). Beside the paged route,GET /sessions/{id}/transcript/plan?agent_id=[&tool_call_id=]projects an agent's ExitPlanMode plan info (content / path / options / review outcome;tool_call_idnarrows to one call, omitted lists every recoverable plan) from the first available fact — the linked approval interaction's persisted request display, the live tool frame's display, or the tool result output text. The baselinetranscript.resetitself is items-empty (TRANSCRIPT_RESET_TAIL_TURNS = 0): it carries only global state + the watermark +has_more_older, because history always pages in over REST. When a WS connection subscribes to the transcript protocol (grade ≠offfor an agent), the broadcaster suppresses the transcript-projectedsession_eventtypes for that connection × agent (TRANSCRIPT_PROJECTED_EVENT_TYPES+suppressedByTranscriptinsessionEventBroadcaster.ts; cursor replay viagetBufferedSinceapplies the same filter). Suppression is only a per-connection send view — the journal still records everything, and connections without transcript grades are unaffected. The session's work aggregate behindevent.session.work_changed(busy/main_turn_active/pending_interaction/last_turn_reason) is owned by the core'sISessionActivityView(sessionActivitydomain, Session scope): the broadcaster only schedules the wire emission around turn frames (busy:falselands afterturn.ended), andresolveSessionFacts(src/routes/sessions.ts) reads the same view — never fold per-agent activity at the edge. Delivery split on/api/v1/ws: global events (session.meta.updatedand theevent.session.*/event.workspace.*/event.config.*families, including every activated session'sevent.session.work_changed) fan out to EVERY established connection —WsConnectionV1registers itself viabroadcaster.addGlobalTargeton construction and unregisters on close — while session/agent-grained events only reach connections subscribed to that session (subject toagent_filterand the transcript suppression above); transcript frames are a separate channel governed by the per-agent grades alone and bypassagent_filterentirely.packages/klient: the client SDK — a contract-driven facade over agent-core-v2 with aggregatedglobal.*/session(id).*/agent(id).*methods, zod validation on every call, and klient-level typed event forwarding. Transport is chosen once at creation via subpath entry (@moonshot-ai/klient/ipc|memory); both return the sameKlient. The package also hosts the e2e suites: the legacy/api/v1live suites (test/e2e/legacy/) and the docker e2e runner (pnpm --filter @moonshot-ai/klient docker:e2e). Seepackages/klient/AGENTS.md.packages/server-e2e: live e2e tests and scenarios against a running server (KIMI_SERVER_URL, defaulthttp://127.0.0.1:58627). Seepackages/server-e2e/AGENTS.md.
- Node.js:
>=24.15.0(from the rootpackage.jsonengines;.nvmrcis24.15.0, used by nvm / fnm / mise to pick the minimum recommended version). - pnpm:
10.33.0(from the rootpackage.jsonpackageManager). pnpm installwill fail when the Node version is not satisfied, because.npmrcsetsengine-strict=true.
pnpm-workspace.yamlis the source of truth for workspace membership, butflake.nixalso contains hardcodedworkspacePathsandworkspaceNameslists.- Whenever you add or remove a workspace package, you MUST update both
pnpm-workspace.yamlandflake.nix— for every package, including leaf / test / e2e packages that nothing depends on.pnpm-workspace.yamluses globs (packages/*,apps/*), so most packages land there automatically;flake.nixis fully manual and is where omissions happen.- Missing a path in
flake.nix'sworkspacePathswill silently drop files from the Nix build'ssrcfileset. - Missing a name in
flake.nix'sworkspaceNameswill breakpnpmConfigHookbecause dependencies for that workspace will not be fetched.
- The automated "Check flake.nix workspace sync" (
scripts/check-nix-workspace.mjs) only validates the transitive dependency closure of@moonshot-ai/kimi-code. A leaf package outside that closure (e.g. an e2e package nobody imports) slips through even when it is missing fromflake.nix. A green check is therefore NOT proof thatflake.nixis fully in sync — keep it updated by hand on every add/remove, do not rely on the check to catch omissions.
- For optional object properties, pass
undefineddirectly instead of using conditional spread.- YES:
{ user } - NO:
{ ...(user ? { user } : undefined) }
- YES:
- Optional object properties do not need to additionally allow
undefinedin the type.- YES:
interface Options { user?: User } - NO:
interface Options { user?: User | undefined }
- YES:
- Internal methods with only a single parameter should not be turned into options objects just for stylistic uniformity.
- Except for a package's
index.ts, otherindex.tsfiles should preferexport * from './module';. - The
Agentclass inpackages/agent-core/src/agentmust be usable on its own. The constructor must not force the caller to create aSessioninstance, nor require anagentIdorsession. It may accept an optionalsessionIdas a request-config hint — for example mapped to the provider'sprompt_cache_key— but the instance must not holdsessionId, and must not depend on the Session lifecycle, metadata, or parent/child relationship logic. - Do not add too many new test files. Prefer adding tests to the existing test file of the corresponding component or module.
- When a test fails because of a user modification, default to fixing the test first; do not change the implementation to satisfy an old test unless the implementation truly has a bug.
- Do not sacrifice code quality for external compatibility unless the user explicitly asks for it. Breaking changes go through changesets and a
majorbump, gated by the rule below.
- Gate a not-yet-public feature behind an experimental flag. Add the flag to the registry at
packages/agent-core/src/flags/registry.ts, then check it withflags.enabled('my-feature'). Flags are env-driven and default off:KIMI_CODE_EXPERIMENTAL_<NAME>toggles one,KIMI_CODE_EXPERIMENTAL_FLAGenables all. Release by flipping the entry'sdefaulttotrue.
- Hard rules that affect almost every task: update the root
AGENTS.md. - Rules that only affect a specific directory: update the nearest sub-directory
AGENTS.md. - Keep instruction updates focused and supported by code facts.
- Prefer
rg/rg --fileswhen reading code. - When designing changes, follow existing boundaries and local patterns first.
- In public text and test data, replace real internal identifiers with neutral placeholders such as
example.com,example.test, andYOUR_API_KEY. Before opening a PR, ask a read-only agent to audit the diff for context-specific internal identifiers. - When creating a PR, the PR title must follow Conventional Commit style, e.g.
chore: remove legacy format commands. - When an AI agent opens or updates a PR, fill in
.github/pull_request_template.md— link the related issue or explain the problem, then describe what changed. Do not leave placeholder text or submit a generic summary of the diff. - Do not submit vague AI-generated PR text. The human author must understand the change well enough to explain the code, edge cases, and why the approach fits this repository.
- After finishing a task and before submitting a PR, you must run the
gen-changesetsskill (see.agents/skills/gen-changesets/SKILL.md) and generate a changeset under.changeset/according to its rules. - When generating a changeset, never decide on a
majorbump on your own. When you judge a change to meet the major criteria (breaking changes, incompatible user configuration, renamed or removed commands/arguments, changed behavior semantics, etc.), you must stop and explain it to the user and ask for confirmation. Only writemajorafter the user has explicitly agreed. Otherwise default tominor(and fall back topatchifminoris unclear). See the "Hard rule: confirm with the user before writingmajor" section in.agents/skills/gen-changesets/SKILL.mdfor details. - Prefer importing via
import ... from '#/...', which serves the same purpose asimport ... from '@/...'. - Do not commit throwaway scratch or exploratory files. Never stage:
- Agent working notes or handoff/summary documents (e.g.
HANDOVER-*.md,HANDOFF-*.md,handoff.md). - Throwaway UI/UX prototypes or design mockups (e.g.
*-designs.html,*-mockup.html,*-demo(s).html) at the repo root or under adesign/folder. The only tracked.htmlfiles should be Viteindex.htmlentrypoints. Before committing or opening a PR, rungit statusandgit diff --staged --statand remove anything matching these patterns. Put scratch work under.tmp/(gitignored) instead of the repo root or the source tree.
- Agent working notes or handoff/summary documents (e.g.