open max
Open Max is a self-extending agent harness for coding in the terminal: one native Rust binary with seven built-in tools and a 770-token prompt core. Every other capability is a plain file the agent can write and you can read.
$curl -fsSL https://useopenmax.dev/install.sh | shSources and methods
- Binary7.5 MB7,513,472 bytes: the v2026.10.0 binary for Apple silicon. It links only libSystem and libiconv.
- First frame3 msProcess spawn to the first painted frame of an idle, trusted session, under a pseudo-terminal that answers the startup capability queries: median 2.88 ms over 21 runs after one warm-up, the v2026.10.0 binary for Apple silicon.
- Prompt core770 tokensBase rules and the extension pointer (279) plus the seven tool schemas (491), as sent on the wire, counted with o200k; 752 with cl100k. Project context is added on top, within byte caps.
- Tests968 passing
cargo test --workspace --lockedon v2026.10.0: 968 passed, 0 failed, 11 ignored. - TelemetryNoneOpen Max connects only to the model endpoint you configure, and never checks for updates. Tools, hooks, and shell commands are child processes with your own network access.
01Session
~/my-project ❯ add a tool that searches our docs index • execution policy: ask for this trusted project; mutating calls and unapproved tool content require confirmation unless the applicable gate permits them. Hooks and project permission allows require content approval. ✓ Write .openmax/tools/docs.toml +12 −0 739ms • extension refreeze: .openmax/tools/docs.toml added (initial). New tools registered; the FIRST call of each stops for human approval of its exact bytes: docs (openmax --approve '.openmax/tools/docs.toml'). Prove one first with bash: openmax --check --run-examples (unapproved tools probe in a sandbox). • toolbox changed: re-frozen with 8 tools, 0 skills - .openmax/tools/docs.toml added (initial) ⚙ Docs approvals ⠏ 2.9s · esc to cancel y allow once · a auto for project · n deny your-model ctx 11% out 114 ask ╭ Approval ────────────────────────────────────────────────────────────────────────────────────────╮ │Docs approvals │ │unapproved tool content (its .toml or the code it runs) · .openmax/tools/docs.toml (45441fdde1d3)…│ │▸ [y] Allow once [a] Auto for project [n] Deny │ ╰──────────────────────────────────────────────────────────────────────────────────────────────────╯
A frame from the v2026.10.0 binary in a 100 by 40 terminal, run against a scripted model server. Only blank rows are removed.
02What developers ask for
- 2.1
Approval before action, and no false sandbox
Trust is a human act, granted per project. In
askmode,write_file,edit_file, andbashneed your approval or an approved allow rule, and deny rules apply at once. These gates decide dispatch; they are not OS isolation, so run untrusted code in a container.60% of respondents block agents from making unapproved system changes. Stack Overflow pulse survey, May 2026
- 2.2
No hidden traffic
Open Max connects only to the model endpoint you configure. No telemetry, no update check, and the source is MIT-licensed.
81% of respondents have concerns about the security and privacy of data with AI agents. Stack Overflow Developer Survey 2025
- 2.3
A small prompt that stays cached
The fixed core is 770 tokens: rules, an extension pointer, and seven tool schemas. The prefix stays byte-identical until a tool, skill, or memory file changes, and history only appends between compactions, so a server's prompt cache keeps hitting.
- 2.4
Any model, local or hosted
Any
chat/completionsendpoint that returns nativetool_calls: Ollama, vLLM, llama.cpp, or a hosted API. Name several inproviders.jsonand switch with/model. - 2.5
Context and spend you can see
/contextitemizes the prefix and its cache hits, andmax_agent_tokenscaps what a turn may spend. Past the context budget, compaction prunes to 70% and archives what it drops, searchable withopenmax --recall. There is no built-in sub-agent scheduler. - 2.6
Extensions as plain files
TOML tools,
SKILL.mdskills, hooks, prompt templates, andAGENTS.md. A skill costs one index line until opened, andopenmax --checknames why any file fails to load. - 2.7
Native and scriptable
One 7.5 MB Rust binary; the curl and Homebrew installs need no runtime.
-pprints the answer and exits 4 on an iteration cap or a spent budget,--jsonstreams every event, and--stdiospeaks a versioned JSONL protocol.
03Thesis
Every harness feature is a fossil of a model limitation.
Plan modes and task lists compensate for what models once did badly; Open Max leaves them out of the core. A scaffold your model still needs is a file you can add, measure, and delete.
04Quickstart
No defaults: until the endpoint, model, and window are set, Open Max names what is missing. On a local server, enable the model's tool-call parser and chat template.
In CI, OPENMAX_HUMAN_ATTEST=1 openmax --trust-project -p "…" grants trust as the human running the job; later runs in that directory need only -p. Headless runs decline approvals in ask mode, so jobs that edit files set "approval_mode": "auto".