agentboards.org

FuXi

#90 overall#41 terminal agentverified Sep 4, 2026v0.1.8

Terminal coding agent shipped as a single Go binary with 50+ built-in tools, cost-aware provider routing and MCP in both directions

Key differences

Terminal coding agent shipped as a single Go binary with 50+ built-in tools, cost-aware provider routing and MCP in both directions

  • Runs local. Binary is free with no licence cost; you pay your own model provider, or sign in for FuXi-managed models
  • Acts as an MCP server. Listed for 10 of 125 tools in this category.
  • Supports headless CI workflows. Listed for 55 of 125 tools in this category.
  • Keep in mind: The LICENSE reads "Proprietary. All rights reserved." and the repository contains only docs, installers and issues, so no field here can be checked against source.

“More than fifty built-in tools in one binary, which is either thoroughness or the longest permission prompt in this category.”

Website Docs 3.4k starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

FuXi is a TUI coding agent that reads and edits files, runs shell commands and drives tools in a think, act and verify loop, distributed as one static Go binary. It is provider-agnostic: point it at any OpenAI-compatible endpoint, Anthropic, Gemini, Bedrock or Vertex with your own key, or sign in for FuXi-managed models. It adds AST-based shell command safety classification, fine-grained permissions, durable sessions with checkpoints and fork, hooks, skills and plugins. The GitHub repository hosts only docs, installers and the issue tracker; the product source is not published.

Specification

Source verification

Row snapshot checked 2026-09-04. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

install
Needs individual review
license
Needs individual review
models
Needs individual review
protocols
Needs individual review
capabilities
Needs individual review
pricing
Needs individual review

Architecture

Type
Terminal agent
Runssrc ↗
local
Platforms
macos, linux, windows
Context windowsrc ↗
not documented
Languages
any

Models

Backbonesrc ↗
any OpenAI-compatible provider, Anthropic, Gemini, Amazon Bedrock, Google Vertex
Bring your own model
Yes
Local models
Yes
A custom base_url is documented through config, the FUXI_BASE_URL environment variable and the -b/--base-url flag, which covers a locally hosted OpenAI-compatible server.

Protocols

MCP clientsrc ↗
Yes
MCP server
Yes
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
Yes
Browser control
Yes
Sandboxed execution
No
Multi-agent
Yes
Headless / CI
Yes

Cost

Modelsrc ↗
byok
Starts at
$0/mo
Free tier
Yes
Bring your own key
Yes

Binary is free with no licence cost; you pay your own model provider, or sign in for FuXi-managed models

Openness

Open sourcesrc ↗
No
License
proprietary
First release
2026-08
previewterminalgobyokmcpsubagentssource-unavailable

Los Agentes on FuXi

Who are they?
The ruling
El JuezThe judge

El Crítico says none of the safety claims can be checked; El Profesor says the one that matters is at least the right design. They are both looking at a repository with no code in it.

Trial only
Reasoning and trade-offs · AI analysis

El Crítico's objection is that the repository publishes documentation, installers and an issue tracker, so every assurance is a promise rather than an artefact. El Profesor agrees on the epistemics and separates the question: parsing a command before judging it is the correct approach whether or not he can read the parser.

El Crítico wins on trust and El Profesor is overruled on comfort, not on design, because a good architecture you cannot inspect is still an architecture you cannot inspect. El Hacker's escape hatch keeps this from being a refusal. Trial only: your own key, your own endpoint, and nothing sensitive until the source appears.

Agree with El Juez?
El AmigoThe friend

Pick it if you want one downloaded binary and no runtime to install; pick OpenCode when you would rather your terminal agent be something you can read.

6.5
Reasoning and trade-offs · AI analysis

You will appreciate the packaging on day one: a single static binary, no runtime, no dependency tree to keep alive on three machines. The trait that decides it in daily use is session durability, because checkpoints and forking a session mean a long task survives your mistakes, and you can branch an approach rather than starting the conversation again from the beginning.

Pick it if you want a terminal agent that installs in one command and answers to your own provider. Pick OpenCode when transparency matters more to you than packaging, or Aider if you want the edit loop under your thumb.

reliability
6
usefulness
7
cost
8
longevity
5
Agree with El Amigo?
El CríticoThe critic

The LICENSE reads proprietary and the repository holds only documentation, installers and issues, so no safety claim in this product can be checked against anything.

5.3
Reasoning and trade-offs · AI analysis

Everything here is testimony. Command classification, permission granularity and the safety model are described in a usage document published by the same party that ships the binary, and there is no source to compare it against. The product is one month old and carries a preview label. A tool asking for shell access should be the easiest thing on this board to audit, and this is the hardest.

What it does right: permissions are described at fine granularity rather than as a single trust toggle, which at least means the vendor has thought about the question it will not let you verify.

reliability
4
usefulness
6
cost
7
longevity
4
Agree with El Crítico?
El ProfesorThe professor

Classifying shell commands by parsing them into a syntax tree is the correct method; pattern matching on command strings is what everyone else does and it is defeated by quoting.

6.3
Reasoning and trade-offs · AI analysis

One design choice is worth isolating. 1. Deciding whether a command is dangerous by analysing its parsed structure is categorically stronger than matching text, because shells offer unlimited ways to spell the same instruction and a string comparison loses to every one of them. 2. That approach also degrades predictably: an unparseable command is an unknown, not a false negative.

The claim is documented and not demonstrated, no evaluation accompanies it, and the documentation is a single usage page. The method is right. Whether the implementation is right is not a question the published material can answer.

reliability
6
usefulness
6
cost
7
longevity
6
Agree with El Profesor?
La InversoraThe investor

A free binary with an optional managed model service is a funnel, and three thousand stars on a repository that ships no code is a marketing result.

5.3
Reasoning and trade-offs · AI analysis

The shape is familiar: give away the client, monetise the inference. Sign-in for vendor-hosted models sits beside the option to use your own provider, which means the revenue depends entirely on convenience beating configuration, and that is a thin advantage against competitors doing the same thing with published source.

Distribution is real and strange. Over three thousand stars accrued to a repository containing documentation and installers, which measures attention rather than adoption. No entity detail, no funding signal, no pricing page. Likely outcome is a paid tier within two quarters or silence. Position: pass on the managed service, treat the client as disposable.

reliability
5
usefulness
6
cost
6
longevity
4
Agree with La Inversora?
La JefaThe CTO

Zero licence cost for sixty and a documented token command for headless runs, but a one-month-old preview from a vendor with no company details is not a supplier.

5.0
Reasoning and trade-offs · AI analysis

The cost line is easy and irrelevant. What I need is a counterparty, and the row gives me a preview product first released last month, no published entity, no support terms and no retention statement. Nothing describes SSO, SCIM or an audit trail. It does provide a documented token flow for unattended runs, so the pipeline story is real, which makes the absence of everything else more frustrating rather than less.

Onboarding would be an hour. Not yet. Revisit when there is a company to sign a contract with and a security page to send to my auditors.

reliability
4
usefulness
6
cost
7
longevity
3
Agree with La Jefa?
El HackerThe tinkerer

Closed source, but FUXI_BASE_URL or the -b flag points it at any OpenAI-compatible endpoint, which includes the server running on my own machine.

6.5
Reasoning and trade-offs · AI analysis

The licence is a single proprietary line, so a fork is not on the table and I hate that. What keeps it in my toolbox is the escape hatch: a base URL from config, an environment variable or a command flag, which means the model can be anything speaking the common API, including one served locally, and my keys never touch the vendor. MCP works in both directions, so my servers attach and its tools are exposed back.

Model freedom without source freedom is half of what I want. I will run it, and I will not depend on it.

reliability
5
usefulness
8
cost
9
longevity
4
Agree with El Hacker?