v2026.10.0

open max

Open Max is a self-extending agent harness for coding in the terminal: one native Rust binary with seven built-in tools and a 770-token prompt core. Every other capability is a plain file the agent can write and you can read.

Binary
7.5 MB
First frame
3 ms
Prompt core
770 tokens
Tests
968 passing
Telemetry
None
$curl -fsSL https://useopenmax.dev/install.sh | sh
Sources and methods
  • Binary7.5 MB7,513,472 bytes: the v2026.10.0 binary for Apple silicon. It links only libSystem and libiconv.
  • First frame3 msProcess spawn to the first painted frame of an idle, trusted session, under a pseudo-terminal that answers the startup capability queries: median 2.88 ms over 21 runs after one warm-up, the v2026.10.0 binary for Apple silicon.
  • Prompt core770 tokensBase rules and the extension pointer (279) plus the seven tool schemas (491), as sent on the wire, counted with o200k; 752 with cl100k. Project context is added on top, within byte caps.
  • Tests968 passingcargo test --workspace --locked on v2026.10.0: 968 passed, 0 failed, 11 ignored.
  • TelemetryNoneOpen Max connects only to the model endpoint you configure, and never checks for updates. Tools, hooks, and shell commands are child processes with your own network access.

01Session

my-project · openmax · needs approval
~/my-project

❯ add a tool that searches our docs index                                                           

• execution policy: ask for this trusted project; mutating calls and unapproved tool content
  require confirmation unless the applicable gate permits them. Hooks and project permission allows
  require content approval.

✓ Write .openmax/tools/docs.toml  +12 −0  739ms                                                     

• extension refreeze: .openmax/tools/docs.toml added (initial). New tools registered; the FIRST
  call of each stops for human approval of its exact bytes: docs (openmax --approve
  '.openmax/tools/docs.toml'). Prove one first with bash: openmax --check --run-examples
  (unapproved tools probe in a sandbox).

• toolbox changed: re-frozen with 8 tools, 0 skills - .openmax/tools/docs.toml added (initial)

⚙ Docs approvals
⠏ 2.9s · esc to cancel
 y allow once · a auto for project · n deny                       your-model  ctx 11%  out 114  ask
╭ Approval ────────────────────────────────────────────────────────────────────────────────────────╮
│Docs  approvals                                                                                   │
│unapproved tool content (its .toml or the code it runs) · .openmax/tools/docs.toml (45441fdde1d3)…│
│▸ [y] Allow once [a] Auto for project [n] Deny                                                    │
╰──────────────────────────────────────────────────────────────────────────────────────────────────╯

A frame from the v2026.10.0 binary in a 100 by 40 terminal, run against a scripted model server. Only blank rows are removed.

02What developers ask for

  1. 2.1

    Approval before action, and no false sandbox

    Trust is a human act, granted per project. In ask mode, write_file, edit_file, and bash need your approval or an approved allow rule, and deny rules apply at once. These gates decide dispatch; they are not OS isolation, so run untrusted code in a container.

    60% of respondents block agents from making unapproved system changes. Stack Overflow pulse survey, May 2026

  2. 2.2

    No hidden traffic

    Open Max connects only to the model endpoint you configure. No telemetry, no update check, and the source is MIT-licensed.

    81% of respondents have concerns about the security and privacy of data with AI agents. Stack Overflow Developer Survey 2025

  3. 2.3

    A small prompt that stays cached

    The fixed core is 770 tokens: rules, an extension pointer, and seven tool schemas. The prefix stays byte-identical until a tool, skill, or memory file changes, and history only appends between compactions, so a server's prompt cache keeps hitting.

  4. 2.4

    Any model, local or hosted

    Any chat/completions endpoint that returns native tool_calls: Ollama, vLLM, llama.cpp, or a hosted API. Name several in providers.json and switch with /model.

  5. 2.5

    Context and spend you can see

    /context itemizes the prefix and its cache hits, and max_agent_tokens caps what a turn may spend. Past the context budget, compaction prunes to 70% and archives what it drops, searchable with openmax --recall. There is no built-in sub-agent scheduler.

  6. 2.6

    Extensions as plain files

    TOML tools, SKILL.md skills, hooks, prompt templates, and AGENTS.md. A skill costs one index line until opened, and openmax --check names why any file fails to load.

  7. 2.7

    Native and scriptable

    One 7.5 MB Rust binary; the curl and Homebrew installs need no runtime. -p prints the answer and exits 4 on an iteration cap or a spent budget, --json streams every event, and --stdio speaks a versioned JSONL protocol.

03Thesis

Every harness feature is a fossil of a model limitation.

Plan modes and task lists compensate for what models once did badly; Open Max leaves them out of the core. A scaffold your model still needs is a file you can add, measure, and delete.

04Quickstart

# ~/.openmax/settings.json · any chat/completions server that returns tool_calls { "base_url": "http://localhost:8080/v1", "model": "your-model", "context_tokens": 128000 } # a hosted endpoint also needs a key: "api_key": "$ENV_VAR", or export OPENMAX_API_KEY # run in the project directory, then accept the trust prompt openmax

No defaults: until the endpoint, model, and window are set, Open Max names what is missing. On a local server, enable the model's tool-call parser and chat template.

In CI, OPENMAX_HUMAN_ATTEST=1 openmax --trust-project -p "…" grants trust as the human running the job; later runs in that directory need only -p. Headless runs decline approvals in ask mode, so jobs that edit files set "approval_mode": "auto".