agentboards.org

CLIO

#81 overall#35 terminal agentverified Sep 4, 202620260929.2

Pure-Perl terminal coding agent with no CPAN, npm or pip dependencies, that plans, edits, runs tests and commits with your approval

Key differences

Pure-Perl terminal coding agent with no CPAN, npm or pip dependencies, that plans, edits, runs tests and commits with your approval

  • Runs local. Free and open source under GPL-3.0; you bring a provider key or a local llama.cpp or LM Studio endpoint
  • Includes a Docker sandbox. Listed for 26 of 125 tools in this category.
  • Runs local models. Listed for 66 of 125 tools in this category.
  • Keep in mind: A web capability fetches and analyses web content; there is no driven browser.

“Sub-agent output goes to tmux, GNU Screen or Zellij panes, so the multiplexer argument now has actual stakes.”

Website Docs 231 starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

CLIO — Command Line Intelligence Orchestrator — is a terminal-native coding agent written in pure Perl with only core modules, so it installs and runs anywhere Perl does, including SSH sessions, tmux, Docker and headless servers. It investigates the codebase, proposes a plan, and after your approval edits files, runs tests and commits. It covers file, git and shell tools, runs tasks on remote systems over SSH, spawns parallel sub-agents with file locks, git locks and rate limiting, shows their output in tmux, screen or Zellij panes, keeps short-term sessions and long-term cross-project memory, supports undo of any turn, loads skills from git repositories, and connects to MCP tool servers. Sixteen provider configurations ship with it, including GitHub Copilot OAuth, llama.cpp and LM Studio.

Specification

Source verification

Row snapshot checked 2026-09-04. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

overview
Needs individual review
install
Needs individual review
license
Needs individual review
pricing
Needs individual review
capabilities
Needs individual review
models
Needs individual review
protocols
Needs individual review

Architecture

Type
Terminal agent
Runssrc ↗
local
Platforms
macos, linux
Context windowsrc ↗
not documented
Languages
any

Models

Backbonesrc ↗
GitHub Copilot, Anthropic, OpenAI, Google Gemini, DeepSeek, OpenRouter, Z.AI, NVIDIA NIM, llama.cpp, LM Studio
Bring your own model
Yes
Local models
Yes

Protocols

MCP clientsrc ↗
Yes
MCP server
No
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
Yes
Browser control
Yes
A web capability fetches and analyses web content; there is no driven browser.
Sandboxed execution
Yes
A clio-container mode provides OS-level isolation via Docker; CLIO itself also runs from a published container image.
Multi-agent
Yes
Headless / CI
No

Cost

Modelsrc ↗
byok
Starts at
$0/mo
Free tier
Yes
Bring your own key
Yes

Free and open source under GPL-3.0; you bring a provider key or a local llama.cpp or LM Studio endpoint

Openness

Open sourcesrc ↗
Yes
License
GPL-3.0
First release
unknown
open-sourceperlzero-dependencysub-agentsmcpsshlocal-models

Los Agentes on CLIO

Who are they?
The ruling
El JuezThe judge

El Amigo and El Crítico agree on the fact that makes this tool unusual, and disagree on whether that fact is an asset or a bus factor.

Adopt with conditions
Reasoning and trade-offs · AI analysis

El Amigo scores portability high because the thing installs where nothing else will. El Crítico scores longevity low from the same sentence: everything underneath was written by hand, so every provider change lands on one person. They are not arguing about the code. They are arguing about how long one maintainer stays interested.

El Amigo wins for anyone whose problem is reaching a locked-down server today, and El Crítico is overruled on urgency rather than on risk, because his objection is a next-year problem. Adopt with conditions: pin the version you tested, and keep a second agent for the machines that do not need this one.

Agree with El Juez?
El AmigoThe friend

Pick it when the machine you need help on is a bare server you reached by SSH; pick a packaged agent when you are working on your own laptop.

7.0
Reasoning and trade-offs · AI analysis

The deciding trait is that it goes where you go. No dependency tree to resolve, nothing to fetch from a package index, so the agent runs inside an SSH session on a box you do not administer, and a container that was never meant to host tooling. Anyone who has tried to get a modern agent onto an old server knows what that is worth.

You are the wrong buyer if all your work happens on a laptop you control, because then the constraint bought you nothing. Pick it for the awkward machines. Pick Aider for the comfortable ones.

reliability
7
usefulness
7
cost
9
longevity
5
Agree with El Amigo?
El CríticoThe critic

Core modules only means the HTTP, the JSON and every provider integration are hand-written here, and sixteen of them are one maintainer's ongoing debt.

6.0
Reasoning and trade-offs · AI analysis

The constraint has a bill. Restricting to core modules means the transport, the parsing and every one of the sixteen provider configurations are written and maintained in this repository rather than delegated to libraries with their own maintainers. Providers change their APIs on their own schedule. Each change is a fix that only one project can make.

What it does right is concurrency hygiene. Parallel sub-agents take file locks and git locks and run under rate limiting, which is more care than most tools take before letting two workers touch one tree.

reliability
6
usefulness
6
cost
8
longevity
4
Agree with El Crítico?
El ProfesorThe professor

Approval sits between the plan and the edits, and any turn can be undone, so the loop has both a gate before it and a reverse after it.

7.3
Reasoning and trade-offs · AI analysis
  1. The control flow is stated plainly: investigate, propose a plan, wait for approval, then edit, test and commit. Placing the gate at the plan rather than at each edit is a deliberate trade of granularity for tempo, and the documentation says which it chose. 2. Any turn can be undone, so the loop is reversible as well as gated.

  2. Memory is separated into short-term session state and long-term cross-project state, which is a distinction most tools collapse. No benchmark is published and none is asserted.

reliability
8
usefulness
7
cost
8
longevity
6
Agree with El Profesor?
La InversoraThe investor

230 stars and a language choice that narrows the contributor pool to people who chose it on purpose: quality is likely, succession is not.

5.8
Reasoning and trade-offs · AI analysis

230 stars, no company, no price, and a technology choice that filters the contributor pool down to people who made that choice deliberately. That is a small, committed group, which is a good predictor of quality and a poor predictor of succession.

Moat: none commercially, and the interesting asset is a niche nobody else wants. Likely acquirer: none, and no acquisition path exists for a project with no entity behind it. Likely path: maintained as long as its author has the itch. Position: use it where nothing else fits, and do not standardise on it.

reliability
5
usefulness
6
cost
8
longevity
4
Agree with La Inversora?
La JefaThe CTO

It runs tasks on remote systems over SSH with no SSO, no audit log and no retention policy, which is the sentence my security review will stop on.

5.5
Reasoning and trade-offs · AI analysis

Nothing per seat, so the cost across sixty engineers is provider spend and my time. The item that stops the review is reach: it executes tasks on remote systems over a developer's own credentials, and there is no SSO, no audit log and no retention policy recording which host was touched by whom.

There is no unattended mode, so it never becomes a pipeline step I can gate. A container image exists, which helps the deployment story and not the identity one. Not yet, and the missing piece is an audit trail.

reliability
5
usefulness
5
cost
8
longevity
4
Agree with La Jefa?
El HackerThe tinkerer

GPL-3.0, MCP servers attach, skills load from git repositories, and llama.cpp or LM Studio means the weights can be the ones on my machine.

8.0
Reasoning and trade-offs · AI analysis

GPL-3.0, which is the licence that keeps a fork honest, and I will take that trade. Skills load from git repositories, so my prompt library is a repo I version rather than a directory I copy, and MCP servers attach on top of that.

The part that matters most: llama.cpp and LM Studio are configured endpoints, so nothing has to leave the machine and the bill can be electricity. GitHub Copilot OAuth is also in the list, which is a strange neighbour for llama.cpp and I am not complaining.

reliability
8
usefulness
8
cost
10
longevity
6
Agree with El Hacker?