New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

astra-tandem

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
Package was removed
Sorry, it seems this package was removed from the registry

astra-tandem

Luna builds. GPT-6 Astra reviews. One Codex login, two bounded passes, an isolated Git worktree.

latest
Source
npmnpm
Version
0.1.0
Version published
Weekly downloads
0
Maintainers
1
Weekly downloads
 
Created
Source

Astra Tandem — Luna builds. Astra reviews. One Codex login. Two bounded passes.

npm version CI MIT license

Give the task to Luna. Give the patch a fresh Astra review.

Astra Tandem is a small CLI that runs GPT-5.6 Luna → GPT-6 Astra through your existing Codex CLI login. The build happens in a separate Git worktree. You get an inspectable patch, a structured review, and reported token usage for each pass.

Interactive example · 한국어 · How it works · Market research

Install in one command

npm install -g astra-tandem

Then, from a clean, committed Git repository:

astra-tandem "Fix the failing date parser test"

Or try it without a global installation:

npx --yes astra-tandem "Fix the failing date parser test"

Requires Node 20+, Git, Codex CLI 0.153+, and a Codex login with access to both selected models. If you already use Codex, there is no additional key to configure. Otherwise install @openai/codex and run codex login first. Model runs consume your existing Codex allowance or API billing; this is not free inference.

The handoff

Your clean checkout
       │
       └─ separate Git worktree
             │
             ├─ 1. Luna implements + runs relevant checks
             │
             ├─ 2. Astra independently inspects the changed code
             │      read-only command sandbox · structured findings
             │
             └─ patch + review + per-pass token receipt
                    │
                    └─ you inspect → astra-tandem apply <run-id>
  • Two bounded passes. One build process, then one review process. No automatic repair loop. No review call when the build fails or produces no Git changes. Each process can make multiple model requests; two passes does not mean two API requests or a spending cap.
  • A fresh review context. Astra gets the task and base commit, then reads the diff and relevant code. It does not receive the builder's conversation or self-assessment. Applicable Codex and repository instructions still load.
  • Recoverable work. Failures and timeouts leave the worktree and receipt available. An invalid or missing review is never treated as approval.
  • Deliberate application. apply requires an approved result, the original repository and HEAD, a clean checkout, and the same patch that was reviewed. It uses git apply --check before application. It does not create a commit or push.
  • Visible usage. Receipts record token counts exposed by Codex's JSONL events. Missing counts remain unknown. No invented savings percentages or subscription-dollar estimates.

The tool sets the build command sandbox to workspace-write and the review command sandbox to read-only. It disables native multi-agent delegation and goals for these two runs. It does not rewrite your global Codex configuration or disable your execpolicy rules. Your existing custom providers, skills, hooks, MCP tools, and administrative policies can still affect a run. A worktree is a Git isolation mechanism, not a security boundary for arbitrary configured integrations.

Commands

astra-tandem doctor                         # installation + sign-in, no inference
astra-tandem "Add pagination" --dry-run     # inspect plan, no writes or model calls
astra-tandem "Fix the parser" --builder sol # Luna / Terra / Sol implementation
astra-tandem "Fix the parser" --timeout 300 # seconds per pass
astra-tandem runs
astra-tandem show latest
astra-tandem apply <run-id>                  # explicit local patch application

--cwd <dir>, --build-effort, --review-effort, and --json are also supported. Both efforts default to medium; choices are low, medium, high, xhigh, and max. A model or effort your account/provider does not support fails visibly; there is no silent substitution.

Exit codes: 0 approved/dry run; 2 changes requested; 1 blocked, failure, timeout, or no changes; 130 interrupted. Informational commands and successful apply also exit 0.

What approval means

Approval is Astra's review judgment, not a correctness guarantee. The receipt separates findings and checks marked pass, fail, or not_run. A read-only review may be unable to run tests that write caches or build artifacts. Check the build's final report too; Tandem does not independently certify an agent's test claims.

If the review requests changes, inspect the findings and continue in the saved worktree. There is no silent retry. To start a new Tandem run, commit the revised work in that worktree first. A new run receives a new review; an old approval never covers later edits.

New, non-ignored files are included. Ignored files, dependency folders, environment secrets, and uninitialized submodules are not copied from your checkout. Repositories with tracked submodules are rejected in v0.1. Dependencies may need installation in the worktree; respect your repository's setup instructions. The tool does not run an automatic dependency installation command.

Local data and cleanup

Runs live in ~/.astra-tandem/runs/<id>/ (override with ASTRA_TANDEM_HOME): worktree/, report.json, build.txt, review.txt, and changes.patch. Failed runs also attempt to preserve partial.patch; this never carries an approval. These can contain private task text and code. Nothing is uploaded by Tandem's Node code. Codex sends model context using its configured provider and may persist its own session records.

Run worktrees and branches are retained until you remove them. Once you have preserved the work you need, use git worktree remove <worktree-path>; Git refuses dirty worktrees by default. No automated deletion or forced cleanup is performed. Uninstall the CLI with npm uninstall -g astra-tandem; saved runs remain available.

Why another orchestrator?

Tools such as Astra Advisor offer dynamic native delegation. Tandem is for people who want a visible, fixed two-pass CLI pipeline: a configurable implementation model, an independent Astra review, a saved patch, and an explicit apply command. It does not plan arbitrary agent graphs or run workers in parallel.

The hypothesis is that keeping implementation on a smaller model and giving Astra a fresh review context is useful. We have not measured net cost savings, task success rates, or review quality against an all-Astra baseline. Compare completed tasks, not nominal per-token prices. Research and validation plan →

Development

npm ci
npm run check
npm test

No runtime dependencies. Tests use real temporary Git repositories and child processes with synthetic model responses. They verify the pipeline and failure handling, not model intelligence. See validation for the exact live-testing status.

Built with Codex. Independent project; not affiliated with OpenAI. MIT licensed.

If this workflow fits how you code, star the repository to follow its development. A small reproducible issue is especially useful.

Keywords

codex

FAQs

Package last updated on 05 Sep 2026

Related posts