
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@fuzzyos/fuzzy-code
Advanced tools
Fuzzy is a minimal terminal coding harness. Adapt fuzzy to your workflows, not the other way around, without having to fork and modify fuzzy internals. Extend it with TypeScript Extensions, Skills, Prompt Templates, and Themes. Put your extensions, skills, prompt templates, and themes in Fuzzy Packages and share them with others via npm or git.
Fuzzy ships with powerful defaults but skips features like sub agents and plan mode. Instead, you can ask fuzzy to build what you want or install a third party fuzzy package that matches your workflow.
Fuzzy runs in four modes: interactive, print or JSON, RPC for process integration, and an SDK for embedding in your own apps. See openclaw/openclaw for a real-world SDK integration.
npm install -g @fuzzyos/fuzzy-code
Authenticate with an API key:
export ANTHROPIC_API_KEY=sk-ant-...
fuzzy
Or use your existing subscription:
fuzzy
/login # Then select provider
Then just talk to fuzzy. By default, fuzzy gives the model four tools: read, write, edit, and bash. The model uses these to fulfill your requests. Add capabilities via skills, prompt templates, extensions, or fuzzy packages.
Platform notes: Windows | Termux (Android) | tmux | Terminal setup | Shell aliases
For each built-in provider, fuzzy maintains a list of tool-capable models, updated with every release. Authenticate via subscription (/login) or API key, then select any model from that provider via /model (or Ctrl+L).
Subscriptions:
API keys:
See docs/providers.md for detailed setup instructions.
Custom providers & models: Add providers via ~/.fuzzy/agent/models.json if they speak a supported API (OpenAI, Anthropic, Google). For custom APIs or OAuth, use extensions. See docs/models.md and docs/custom-provider.md.
The interface from top to bottom:
/hotkeys for all), loaded AGENTS.md files, prompt templates, skills, and extensionsThe editor can be temporarily replaced by other UI, like built-in /settings or custom UI from extensions (e.g., a Q&A tool that lets the user answer model questions in a structured format). Extensions can also replace the editor, add widgets above/below it, a status line, custom footer, or overlays.
| Feature | How |
|---|---|
| File reference | Type @ to fuzzy-search project files |
| Path completion | Tab to complete paths |
| Multi-line | Shift+Enter (or Ctrl+Enter on Windows Terminal) |
| Images | Ctrl+V to paste (Alt+V on Windows), or drag onto terminal |
| Bash commands | !command runs and sends output to LLM, !!command runs without sending |
Standard editing keybindings for delete word, undo, etc. See docs/keybindings.md.
Type / in the editor to trigger commands. Extensions can register custom commands, skills are available as /skill:name, and prompt templates expand via /templatename.
| Command | Description |
|---|---|
/login, /logout | OAuth authentication |
/model | Switch models |
/scoped-models | Enable/disable models for Ctrl+P cycling |
/settings | Thinking level, theme, message delivery, transport |
/resume | Pick from previous sessions |
/new | Start a new session |
/name <name> | Set session display name |
/session | Show session info (path, tokens, cost) |
/tree | Jump to any point in the session and continue from there |
/fork | Create a new session from the current branch |
/compact [prompt] | Manually compact context, optional custom instructions |
/copy | Copy last assistant message to clipboard |
/export [file] | Export session to HTML file |
/share | Upload as private GitHub gist with shareable HTML link |
/reload | Reload keybindings, extensions, skills, prompts, and context files (themes hot-reload automatically) |
/hotkeys | Show all keyboard shortcuts |
/changelog | Display version history |
/quit, /exit | Quit fuzzy |
See /hotkeys for the full list. Customize via ~/.fuzzy/agent/keybindings.json. See docs/keybindings.md.
Commonly used:
| Key | Action |
|---|---|
| Ctrl+C | Clear editor |
| Ctrl+C twice | Quit |
| Escape | Cancel/abort |
| Escape twice | Open /tree |
| Ctrl+L | Open model selector |
| Ctrl+P / Shift+Ctrl+P | Cycle scoped models forward/backward |
| Shift+Tab | Cycle thinking level |
| Ctrl+O | Collapse/expand tool output |
| Ctrl+T | Collapse/expand thinking blocks |
Submit messages while the agent is working:
On Windows Terminal, Alt+Enter is fullscreen by default. Remap it in docs/terminal-setup.md so fuzzy can receive the follow-up shortcut.
Configure delivery in settings: steeringMode and followUpMode can be "one-at-a-time" (default, waits for response) or "all" (delivers all queued at once). transport selects provider transport preference ("sse", "websocket", or "auto") for providers that support multiple transports.
Sessions are stored as JSONL files with a tree structure. Each entry has an id and parentId, enabling in-place branching without creating new files. See docs/session.md for file format.
Sessions auto-save to ~/.fuzzy/agent/sessions/ organized by working directory.
fuzzy -c # Continue most recent session
fuzzy -r # Browse and select from past sessions
fuzzy --no-session # Ephemeral mode (don't save)
fuzzy --session <path> # Use specific session file or ID
fuzzy --fork <path> # Fork specific session file or ID into a new session
/tree - Navigate the session tree in-place. Select any previous point, continue from there, and switch between branches. All history preserved in a single file.

/fork - Create a new session file from the current branch. Opens a selector, copies history up to the selected point, and places that message in the editor for modification.
--fork <path|id> - Fork an existing session file or partial session UUID directly from the CLI. This copies the full source session into a new session file in the current project.
Long sessions can exhaust context windows. Compaction summarizes older messages while keeping recent ones.
Manual: /compact or /compact <custom instructions>
Automatic: Enabled by default. Triggers on context overflow (recovers and retries) or when approaching the limit (proactive). Configure via /settings or settings.json.
Compaction is lossy. The full history remains in the JSONL file; use /tree to revisit. Customize compaction behavior via extensions. See docs/compaction.md for internals.
Use /settings to modify common options, or edit JSON files directly:
| Location | Scope |
|---|---|
~/.fuzzy/agent/settings.json | Global (all projects) |
.fuzzy/settings.json | Project (overrides global) |
See docs/settings.md for all options.
Fuzzy loads AGENTS.md (or CLAUDE.md) at startup from:
~/.fuzzy/agent/AGENTS.md (global)Use for project instructions, conventions, common commands. All matching files are concatenated.
Replace the default system prompt with .fuzzy/SYSTEM.md (project) or ~/.fuzzy/agent/SYSTEM.md (global). Append without replacing via APPEND_SYSTEM.md.
Reusable prompts as Markdown files. Type /name to expand.
<!-- ~/.fuzzy/agent/prompts/review.md -->
Review this code for bugs, security issues, and performance problems.
Focus on: {{focus}}
Place in ~/.fuzzy/agent/prompts/, .fuzzy/prompts/, or a fuzzy package to share with others. See docs/prompt-templates.md.
On-demand capability packages following the Agent Skills standard. Invoke via /skill:name or let the agent load them automatically.
<!-- ~/.fuzzy/agent/skills/my-skill/SKILL.md -->
# My Skill
Use this skill when the user asks about X.
## Steps
1. Do this
2. Then that
Place in ~/.fuzzy/agent/skills/, ~/.agents/skills/, .fuzzy/skills/, or .agents/skills/ (from cwd up through parent directories) or a fuzzy package to share with others. See docs/skills.md.

TypeScript modules that extend fuzzy with custom tools, commands, keyboard shortcuts, event handlers, and UI components.
export default function (fuzzy: ExtensionAPI) {
fuzzy.registerTool({ name: "deploy", ... });
fuzzy.registerCommand("stats", { ... });
fuzzy.on("tool_call", async (event, ctx) => { ... });
}
What's possible:
Place in ~/.fuzzy/agent/extensions/, .fuzzy/extensions/, or a fuzzy package to share with others. See docs/extensions.md and examples/extensions/.
Built-in: dark, light. Themes hot-reload: modify the active theme file and fuzzy immediately applies changes.
Place in ~/.fuzzy/agent/themes/, .fuzzy/themes/, or a fuzzy package to share with others. See docs/themes.md.
Bundle and share extensions, skills, prompts, and themes via npm or git. Find packages on npmjs.com or Discord.
Security: Fuzzy packages run with full system access. Extensions execute arbitrary code, and skills can instruct the model to perform any action including running executables. Review source code before installing third-party packages.
fuzzy install npm:@foo/fuzzy-tools
fuzzy install npm:@foo/fuzzy-tools@1.2.3 # pinned version
fuzzy install git:github.com/user/repo
fuzzy install git:github.com/user/repo@v1 # tag or commit
fuzzy install git:git@github.com:user/repo
fuzzy install git:git@github.com:user/repo@v1 # tag or commit
fuzzy install https://github.com/user/repo
fuzzy install https://github.com/user/repo@v1 # tag or commit
fuzzy install ssh://git@github.com/user/repo
fuzzy install ssh://git@github.com/user/repo@v1 # tag or commit
fuzzy remove npm:@foo/fuzzy-tools
fuzzy uninstall npm:@foo/fuzzy-tools # alias for remove
fuzzy list
fuzzy update # skips pinned packages
fuzzy config # enable/disable extensions, skills, prompts, themes
Packages install to ~/.fuzzy/agent/git/ (git) or global npm. Use -l for project-local installs (.fuzzy/git/, .fuzzy/npm/). If you use a Node version manager and want package installs to reuse a stable npm context, set npmCommand in settings.json, for example ["mise", "exec", "node@20", "--", "npm"].
Create a package by adding a fuzzy key to package.json:
{
"name": "my-fuzzy-package",
"keywords": ["fuzzy-package"],
"fuzzy": {
"extensions": ["./extensions"],
"skills": ["./skills"],
"prompts": ["./prompts"],
"themes": ["./themes"]
}
}
Without a fuzzy manifest, fuzzy auto-discovers from conventional directories (extensions/, skills/, prompts/, themes/).
See docs/packages.md.
import { AuthStorage, createAgentSession, ModelRegistry, SessionManager } from "@fuzzyos/fuzzy-code";
const authStorage = AuthStorage.create();
const modelRegistry = ModelRegistry.create(authStorage);
const { session } = await createAgentSession({
sessionManager: SessionManager.inMemory(),
authStorage,
modelRegistry,
});
await session.prompt("What files are in the current directory?");
For advanced multi-session runtime replacement, use createAgentSessionRuntime() and AgentSessionRuntimeHost.
See docs/sdk.md and examples/sdk/.
For non-Node.js integrations, use RPC mode over stdin/stdout:
fuzzy --mode rpc
RPC mode uses strict LF-delimited JSONL framing. Clients must split records on \n only. Do not use generic line readers like Node readline, which also split on Unicode separators inside JSON payloads.
See docs/rpc.md for the protocol.
Fuzzy is aggressively extensible so it doesn't have to dictate your workflow. Features that other tools bake in can be built with extensions, skills, or installed from third-party fuzzy packages. This keeps the core minimal while letting you shape fuzzy to fit how you work.
No MCP. Build CLI tools with READMEs (see Skills), or build an extension that adds MCP support.
No sub-agents. There's many ways to do this. Spawn fuzzy instances via tmux, or build your own with extensions, or install a package that does it your way.
No permission popups. Run in a container, or build your own confirmation flow with extensions inline with your environment and security requirements.
No plan mode. Write plans to files, or build it with extensions, or install a package.
No built-in to-dos. They confuse models. Use a TODO.md file, or build your own with extensions.
No background bash. Use tmux. Full observability, direct interaction.
fuzzy [options] [@files...] [messages...]
fuzzy install <source> [-l] # Install package, -l for project-local
fuzzy remove <source> [-l] # Remove package
fuzzy uninstall <source> [-l] # Alias for remove
fuzzy update [source] # Update packages (skips pinned)
fuzzy list # List installed packages
fuzzy config # Enable/disable package resources
| Flag | Description |
|---|---|
| (default) | Interactive mode |
-p, --print | Print response and exit |
--mode json | Output all events as JSON lines (see docs/json.md) |
--mode rpc | RPC mode for process integration (see docs/rpc.md) |
--export <in> [out] | Export session to HTML |
In print mode, fuzzy also reads piped stdin and merges it into the initial prompt:
cat README.md | fuzzy -p "Summarize this text"
| Option | Description |
|---|---|
--provider <name> | Provider (anthropic, openai, google, etc.) |
--model <pattern> | Model pattern or ID (supports provider/id and optional :<thinking>) |
--api-key <key> | API key (overrides env vars) |
--thinking <level> | off, minimal, low, medium, high, xhigh |
--models <patterns> | Comma-separated patterns for Ctrl+P cycling |
--list-models [search] | List available models |
| Option | Description |
|---|---|
-c, --continue | Continue most recent session |
-r, --resume | Browse and select session |
--session <path> | Use specific session file or partial UUID |
--fork <path> | Fork specific session file or partial UUID into a new session |
--session-dir <dir> | Custom session storage directory |
--no-session | Ephemeral mode (don't save) |
| Option | Description |
|---|---|
--tools <list> | Enable specific built-in tools (default: read,bash,edit,write) |
--no-tools | Disable all built-in tools (extension tools still work) |
Available built-in tools: read, bash, edit, write, grep, find, ls
| Option | Description |
|---|---|
-e, --extension <source> | Load extension from path, npm, or git (repeatable) |
--no-extensions | Disable extension discovery |
--skill <path> | Load skill (repeatable) |
--no-skills | Disable skill discovery |
--prompt-template <path> | Load prompt template (repeatable) |
--no-prompt-templates | Disable prompt template discovery |
--theme <path> | Load theme (repeatable) |
--no-themes | Disable theme discovery |
Combine --no-* with explicit flags to load exactly what you need, ignoring settings.json (e.g., --no-extensions -e ./my-ext.ts).
| Option | Description |
|---|---|
--system-prompt <text> | Replace default prompt (context files and skills still appended) |
--append-system-prompt <text> | Append to system prompt |
--verbose | Force verbose startup |
-h, --help | Show help |
-v, --version | Show version |
Prefix files with @ to include in the message:
fuzzy @prompt.md "Answer this"
fuzzy -p @screenshot.png "What's in this image?"
fuzzy @code.ts @test.ts "Review these files"
# Interactive with initial prompt
fuzzy "List all .ts files in src/"
# Non-interactive
fuzzy -p "Summarize this codebase"
# Non-interactive with piped stdin
cat README.md | fuzzy -p "Summarize this text"
# Different model
fuzzy --provider openai --model gpt-4o "Help me refactor"
# Model with provider prefix (no --provider needed)
fuzzy --model openai/gpt-4o "Help me refactor"
# Model with thinking level shorthand
fuzzy --model sonnet:high "Solve this complex problem"
# Limit model cycling
fuzzy --models "claude-*,gpt-4o"
# Read-only mode
fuzzy --tools read,grep,find,ls -p "Review the code"
# High thinking level
fuzzy --thinking high "Solve this complex problem"
| Variable | Description |
|---|---|
FUZZY_CODING_AGENT_DIR | Override config directory (default: ~/.fuzzy/agent) |
FUZZY_PACKAGE_DIR | Override package directory (useful for Nix/Guix where store paths tokenize poorly) |
FUZZY_SKIP_VERSION_CHECK | Skip version check at startup |
FUZZY_CACHE_RETENTION | Set to long for extended prompt cache (Anthropic: 1h, OpenAI: 24h) |
VISUAL, EDITOR | External editor for Ctrl+G |
See CONTRIBUTING.md for guidelines and docs/development.md for setup, forking, and debugging.
MIT
FAQs
Coding agent CLI with read, bash, edit, write tools and session management
The npm package @fuzzyos/fuzzy-code receives a total of 8 weekly downloads. As such, @fuzzyos/fuzzy-code popularity was classified as not popular.
We found that @fuzzyos/fuzzy-code demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.