
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
loki-mode
Advanced tools
Loki Mode by Autonomi - Multi-agent autonomous startup system for Claude Code, Codex CLI, and Gemini CLI
Describe what you want. Get production-ready code.
Website | Documentation | Installation | Changelog | Purple Lab Web UI
How it works: You provide a PRD. Loki Mode classifies complexity, assembles an agent team from 41 specialized types across 8 swarms, and runs autonomous RARV cycles (Reason - Act - Reflect - Verify) with 9 quality gates. Code is not "done" until it passes automated verification. Output is a Git repo with source, tests, configs, and audit logs.
npm install -g loki-mode
loki doctor # verify environment
loki init my-app --template simple-todo-app
cd my-app
loki start prd.md # autonomous build starts
Or skip scaffolding and go straight to a quick task:
loki quick "build a landing page with a signup form"
| Method | Command |
|---|---|
| Homebrew | brew tap asklokesh/tap && brew install loki-mode |
| Docker | docker pull asklokesh/loki-mode |
| Inside Claude Code | claude --dangerously-skip-permissions then type "Loki Mode" |
| Git clone | git clone https://github.com/asklokesh/loki-mode.git |
See the full Installation Guide.
| Project | Build Time | Complexity |
|---|---|---|
| Landing page with signup form | ~10 min | Simple |
| REST API with JWT auth | ~20 min | Simple |
| Portfolio with animations | ~15 min | Simple |
| SaaS dashboard with analytics | ~25 min | Standard |
| E-commerce store with Stripe | ~45 min | Standard |
| Task manager with kanban board | ~25 min | Standard |
| Chat app with WebSocket | ~30 min | Standard |
| Blog platform with MDX | ~30 min | Standard |
| Microservice architecture | ~2 hours | Complex |
| ML pipeline with monitoring | ~3 hours | Complex |
+------------------------------------------------------------------+
| Purple Lab |
| Powered by Loki |
+------------------------------------------------------------------+
| | |
| Home | Describe it. Build it. Ship it. |
| Projects| |
|Templates| +----------------------------------------------------+ |
| Teams | | Build a SaaS dashboard with user analytics... | |
|Showcase | +----------------------------------------------------+ |
| Compare | |
| | [ Start Building ] |
| | |
|---------| +------+ +------+ +------+ +------+ |
| | |Phase | |Agent | |Termi-| |Quali-| |
| Settings| |Viewer| |Dash | | nal | | ty | |
| Docs | +------+ +------+ +------+ +------+ |
| | |
| v6.71.1 | +------------------+ +------------------+ |
| | | File Browser | | Memory Viewer | |
| | +------------------+ +------------------+ |
+------------------------------------------------------------------+
+------------------------------------------------------------------+
| PROJECT WORKSPACE |
+------------------------------------------------------------------+
| File Tree | Monaco Editor | AI Chat Panel |
| | | |
| > src/ | import { useState } | You: Add a search bar |
| App.tsx | from 'react'; | |
| index.ts | | AI: I will add a search |
| > public/ | export default | component with filtering |
| > tests/ | function App() { | and debounced input... |
| | return ( | |
| package.json <div>...</div> | [Send message] |
| | ); | |
| | } | Activity | Quality Gates |
| | | [Build Log] |
| | +--Live Preview------+ | [Agent Status] |
| | | localhost:3000 | | [Phase: Development] |
| | | | | |
| | +--------------------+ | |
+------------------------------------------------------------------+
| Simple | Standard | Complex | |
|---|---|---|---|
| Examples | Landing page, todo app, single API | CRUD + auth, REST API + React | Microservices, real-time, ML pipelines |
| Duration | 5-30 min | 30-90 min | 2+ hours |
| Autonomy | Completes independently | May need guidance on complex parts | Use as accelerator with human review |
RARV CycleEvery iteration: Reason (read state) - Act (execute, commit) - Reflect (update context) - Verify (run tests, check spec). Failures trigger self-correction. |
41 Agent Types8 swarms: engineering, operations, business, data, product, growth, review, orchestration. Auto-composed by PRD complexity. |
9 Quality GatesBlind review, anti-sycophancy, severity blocking, mock/mutation detection. Code does not ship until all gates pass. |
Memory System3-tier architecture: episodic (interaction traces), semantic (generalized patterns), procedural (learned skills). Vector search optional. |
DashboardReal-time monitoring, agent status, task queue, WebSocket streaming. Auto-starts at |
Enterprise LayerTLS, OIDC/SSO, RBAC, OTEL tracing, policy engine, audit trails. Activated via env vars. |
The hosted development platform. A Replit-like web UI for visual PRD-to-code workflow with AI chat for iterative development.
loki web # launches at http://localhost:57375
|
Platform Pages
|
IDE Workspace
|
| Feature | Loki Mode | bolt.new | Replit | Lovable |
|---|---|---|---|---|
| Self-hosted / your keys | Yes | No | No | No |
| 5 AI provider failover | Yes | No | No | No |
| 9 quality gates | Yes | No | No | No |
| Blind code review | Yes | No | No | No |
| Enterprise auth (SSO/RBAC) | Yes | No | Yes | No |
| Air-gapped deployment | Yes | No | No | No |
| Docker + CI/CD generation | Yes | No | Yes | No |
| Open source | Yes | No | No | No |
| Free tier | Open source | Yes | Yes | Yes |
Loki Mode is the only platform that is fully self-hosted, open source, and includes automated quality verification. Your code, your keys, your infrastructure.
| Provider | Autonomous Flag | Parallel Agents | Install |
|---|---|---|---|
| Claude Code | --dangerously-skip-permissions | Yes (10+) | npm i -g @anthropic-ai/claude-code |
| Codex CLI | --full-auto | Sequential | npm i -g @openai/codex |
| Gemini CLI | --approval-mode=yolo | Sequential | npm i -g @google/gemini-cli |
| Cline CLI | --auto-approve | Sequential | npm i -g @anthropic-ai/cline |
| Aider | --yes-always | Sequential | pip install aider-chat |
Claude gets full features (subagents, parallelization, MCP, Task tool). Other providers run sequentially. Auto-failover switches providers when rate-limited. See Provider Guide.
| Command | Description |
|---|---|
loki start [PRD] | Start with optional PRD file |
loki stop | Stop execution |
loki pause / resume | Pause/resume after current session |
loki status | Show current status |
loki dashboard | Open web dashboard |
loki web | Launch Purple Lab web UI |
loki doctor | Check environment and dependencies |
loki plan [PRD] | Pre-execution analysis: complexity, cost, iterations |
loki review [--staged|--diff] | AI-powered code review with severity filtering |
loki test [--file|--dir|--changed] | AI test generation (8 languages, 9 frameworks) |
loki onboard [path] | Project analysis and CLAUDE.md generation |
loki import | Import GitHub issues as tasks |
loki ci | CI/CD quality gate integration |
loki failover | Cross-provider auto-failover management |
loki memory <cmd> | Memory system: index, timeline, search, consolidate |
loki enterprise | Enterprise feature management |
loki version | Show version |
Run loki --help for all options. Full reference: CLI Reference | Config: config.example.yaml
Loki Mode integrates with the BMAD Method, a structured AI-driven agile methodology. If your project uses BMAD for requirements elicitation, Loki Mode can consume those artifacts directly:
loki start --bmad-project ./my-project
The adapter handles BMAD's frontmatter conventions, FR-format functional requirements, Given/When/Then acceptance criteria, and artifact chain validation. Non-BMAD projects are unaffected -- the integration is opt-in via --bmad-project.
Enterprise features are included but require env var activation. Self-audit: 35/45 capabilities working, 0 broken, 1,314 tests passing.
export LOKI_TLS_ENABLED=true
export LOKI_OIDC_PROVIDER=google
export LOKI_AUDIT_ENABLED=true
loki enterprise status
Enterprise Architecture | Security | Authentication | Authorization | Metrics | Audit Logging
Self-reported results from the included test harness. Verification scripts included for reproduction.
| Benchmark | Result | Notes |
|---|---|---|
| HumanEval | 162/164 (98.78%) | Max 3 retries, RARV self-verification |
| SWE-bench | 299/300 patches | Patch generation -- evaluator not yet run |
See benchmarks/ for methodology.

9 slides: Problem, Solution, 41 Agents, RARV Cycle, Benchmarks, Multi-Provider, Full Lifecycle
| Area | What Works | What Doesn't (Yet) |
|---|---|---|
| Code Gen | Full-stack apps from PRDs | Complex domain logic may need human review |
| Deploy | Generates configs, Dockerfiles, CI/CD | Does not deploy -- human runs deploy commands |
| Testing | 9 automated quality gates | Test quality depends on AI assertions |
| Providers | 5 providers with auto-failover | Non-Claude providers lack parallel agents |
| Dashboard | Real-time single-machine monitoring | No multi-node clustering |
What "autonomous" means: The system runs RARV cycles without prompting. It does NOT access your cloud accounts, payment systems, or external services unless you provide credentials. Human oversight is expected for deployment, API keys, and critical decisions.
| Source | What We Use |
|---|---|
| Anthropic: Building Effective Agents | Evaluator-optimizer, parallelization |
| Anthropic: Constitutional AI | Self-critique against quality principles |
| DeepMind: Scalable Oversight via Debate | Debate-based verification in council review |
| DeepMind: SIMA 2 | Self-improvement loop design |
| OpenAI: Agents SDK | Guardrails, tripwires, tracing |
| NVIDIA ToolOrchestra | Efficiency metrics, reward signals |
| CONSENSAGENT (ACL 2025) | Anti-sycophancy in blind review |
| GoalAct | Hierarchical planning for complex PRDs |
Practitioner insights: Boris Cherny, Simon Willison, HN Community
Full Acknowledgements -- 50+ papers and resources
git clone https://github.com/asklokesh/loki-mode.git && cd loki-mode
npm install && npm test # 683 tests
python3 -m pytest # 631 tests
See CONTRIBUTING.md for guidelines.
Business Source License 1.1 -- Free for personal, internal, academic, and non-commercial use. Converts to Apache 2.0 on March 19, 2030. Contact founder@autonomi.dev for commercial licensing.
FAQs
Loki Mode by Autonomi - Multi-agent autonomous startup system for Claude Code, Codex CLI, and Gemini CLI
The npm package loki-mode receives a total of 554 weekly downloads. As such, loki-mode popularity was classified as not popular.
We found that loki-mode demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.