built by osiris · v0.9.0 · stdlib only

mule

a minimal coding agent that runs against any openai-compatible chat completions api. give it a task, it reads and writes files and runs shell commands until the job is done. no dependencies, stdlib only.

54
flags & modes
520
tests passing
15
tools
0
dependencies

01 · quick start

running in ten seconds

set a key, point it at a folder, give it a task. that's the whole install.

terminal
# point it at openai, or anything else with a /v1/chat/completions
export OPENAI_API_KEY=sk-...
python main.py "add a hello world function to app.py" --root ./myproject

# or ollama, or agentrouter, whatever
python main.py "summarize the repo layout" \
  --base-url http://localhost:11434/v1 --api-key ollama \
  --model qwen2.5-coder --root ./myproject

02 · features

small binary, big toolbox

everything a coding agent needs, nothing it doesn't. one folder, runs anywhere python does.

🔌

any openai-compatible api

openai, ollama, agentrouter, deepseek, local models. if it speaks /v1/chat/completions, mule talks to it.

📦

stdlib only, zero deps

no pip install, no venv dance. clone it and run. works on machines that have never seen a package manager.

🛠️

15 tools, sandboxed

read, write, edit, shell, grep, find, web search, fetch, images, todos, subagents, background jobs. all locked to your project root.

💾

sessions that stick around

every run auto-saves. resume with --resume, keep going with --continue, fork with --fork.

🖥️

mule serve

a local web chat ui in one self-contained page. no build step, no cdn, listens on 127.0.0.1 only.

💸

cost tracking

token counts and rough cost every step. --max-cost 1.50 kills the run before your wallet notices.

📋

plan mode

--plan makes the model write a plan first. you approve it, reject it, or ask for one revision before anything runs.

🧩

skills & plugins

drop a SKILL.md in .mule/skills/ or python tools in ~/.mule/plugins/. they just show up.

⏪

checkpoints & undo

--checkpoint tars your project before a run. every file write is backed up, --undo brings the last one back.

03 · safety

it runs shell commands. be smart.

only point --root at directories you don't mind being changed, and read the task output. then turn the guardrails up as high as you want.

  • --ask · approve every shell command and file write, diffs shown first
  • --readonly · kills every writing tool. looking, not touching
  • denylist · the truly awful stuff is refused outright, no prompt
  • secret warnings · loud warning before api keys reach the model