shepherd-agents/shepherdPublic

A runtime substrate that turns an agent's execution into a reversible, Git-like trace, so meta-agents can observe, fork, replay, and revert any run. Couples agent and environments in a copy-on-write fork ~5x faster than docker commit, with ~95% KV-cache reuse on replay. Framework built for meta-agents to supervise, optimize, and train other agents

AI summary: A runtime framework that records agent execution as reversible, Git-like traces for robust supervision and meta-optimization.

Stars
2.5K
+1 today
Forks
217
Watchers
9
Open issues
8
Open PRs
4
Contributors
~5
Commits
126
Branches
7

PythonMITCreated Jun 24, 2026Last push 25d agoLatest release v0.3.1+31 stars this week+79 this month

Quick answers

What is shepherd?
A runtime framework that records agent execution as reversible, Git-like traces for robust supervision and meta-optimization.
What does shepherd do?
Shepherd is a powerful runtime substrate designed to securely orchestrate, observe, and evaluate autonomous AI agents. It transforms an agent's execution lifecycle into a durable, inspectable trace, allowing developers or meta-agents to observe, fork, replay, and revert any specific run. By tightly coupling the agent and its environment within a highly efficient copy-on-write fork, it enables rapid state restoration and sandboxes agent outputs into a reviewable proposal space before they affect production systems. This infrastructure provides the crucial safety, auditability, and rollback mechanisms needed to train supervisor models or deploy agents into complex, high-stakes workflows.
Who is shepherd for?
AI developers, researchers, and platform engineers building complex, autonomous multi-agent systems that demand extreme safety, inspectability, and robust orchestration capabilities.
How do I get started with shepherd?
pip install shepherd-ai
How popular is shepherd on GitHub?
shepherd-agents/shepherd has 2,473 stars and 217 forks on GitHub, and gained 31 stars in the last 7 days.
What license does shepherd use?
shepherd-agents/shepherd is released under the MIT license.

Star history

since Jul 29, 2026
01K2KJul 2026Aug 2026Sep 2026Oct 2026
2.5K stars as of Oct 3, 2026. Measured daily since Jul 29, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
OctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-08: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 0 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 0 commits2026-03-03: 0 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 0 commits2026-03-09: 0 commits2026-03-10: 0 commits2026-03-11: 0 commits2026-03-12: 0 commits2026-03-13: 0 commits2026-03-14: 0 commits2026-03-15: 0 commits2026-03-16: 0 commits2026-03-17: 0 commits2026-03-18: 0 commits2026-03-19: 0 commits2026-03-20: 0 commits2026-03-21: 0 commits2026-03-22: 0 commits2026-03-23: 0 commits2026-03-24: 0 commits2026-03-25: 0 commits2026-03-26: 0 commits2026-03-27: 0 commits2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 0 commits2026-03-31: 0 commits2026-04-01: 0 commits2026-04-02: 0 commits2026-04-03: 0 commits2026-04-04: 0 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 0 commits2026-04-08: 0 commits2026-04-09: 0 commits2026-04-10: 0 commits2026-04-11: 0 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 0 commits2026-04-15: 0 commits2026-04-16: 0 commits2026-04-17: 0 commits2026-04-18: 0 commits2026-04-19: 0 commits2026-04-20: 0 commits2026-04-21: 0 commits2026-04-22: 0 commits2026-04-23: 0 commits2026-04-24: 0 commits2026-04-25: 0 commits2026-04-26: 0 commits2026-04-27: 0 commits2026-04-28: 0 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 0 commits2026-05-02: 0 commits2026-05-03: 0 commits2026-05-04: 0 commits2026-05-05: 0 commits2026-05-06: 0 commits2026-05-07: 0 commits2026-05-08: 0 commits2026-05-09: 0 commits2026-05-10: 0 commits2026-05-11: 0 commits2026-05-12: 0 commits2026-05-13: 0 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 0 commits2026-05-18: 0 commits2026-05-19: 0 commits2026-05-20: 0 commits2026-05-21: 0 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 0 commits2026-05-26: 0 commits2026-05-27: 0 commits2026-05-28: 0 commits2026-05-29: 0 commits2026-05-30: 0 commits2026-05-31: 0 commits2026-06-01: 0 commits2026-06-02: 0 commits2026-06-03: 0 commits2026-06-04: 0 commits2026-06-05: 0 commits2026-06-06: 0 commits2026-06-07: 0 commits2026-06-08: 0 commits2026-06-09: 0 commits2026-06-10: 0 commits2026-06-11: 0 commits2026-06-12: 0 commits2026-06-13: 0 commits2026-06-14: 0 commits2026-06-15: 0 commits2026-06-16: 0 commits2026-06-17: 0 commits2026-06-18: 0 commits2026-06-19: 0 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 0 commits2026-06-23: 0 commits2026-06-24: 0 commits2026-06-25: 2 commits2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 1 commit2026-06-30: 0 commits2026-07-01: 16 commits2026-07-02: 0 commits2026-07-03: 0 commits2026-07-04: 11 commits2026-07-05: 17 commits2026-07-06: 27 commits2026-07-07: 6 commits2026-07-08: 4 commits2026-07-09: 1 commit2026-07-10: 0 commits2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 0 commits2026-07-14: 0 commits2026-07-15: 0 commits2026-07-16: 0 commits2026-07-17: 0 commits2026-07-18: 0 commits2026-07-19: 0 commits2026-07-20: 2 commits2026-07-21: 3 commits2026-07-22: 0 commits2026-07-23: 0 commits2026-07-24: 0 commits2026-07-25: 0 commits2026-07-26: 0 commits2026-07-27: 0 commits2026-07-28: 0 commits2026-07-29: 0 commits2026-07-30: 0 commits2026-07-31: 0 commits2026-08-01: 0 commits2026-08-02: 0 commits2026-08-03: 0 commits2026-08-04: 0 commits2026-08-05: 0 commits2026-08-06: 0 commits2026-08-07: 0 commits2026-08-08: 0 commits2026-08-09: 5 commits2026-08-10: 0 commits2026-08-11: 0 commits2026-08-12: 0 commits2026-08-13: 0 commits2026-08-14: 0 commits2026-08-15: 0 commits2026-08-16: 0 commits2026-08-17: 0 commits2026-08-18: 0 commits2026-08-19: 0 commits2026-08-20: 0 commits2026-08-21: 0 commits2026-08-22: 0 commits2026-08-23: 0 commits2026-08-24: 0 commits2026-08-25: 0 commits2026-08-26: 0 commits2026-08-27: 0 commits2026-08-28: 0 commits2026-08-29: 0 commits2026-08-30: 0 commits2026-08-31: 0 commits2026-09-01: 0 commits2026-09-02: 0 commits2026-09-03: 0 commits2026-09-04: 0 commits2026-09-05: 0 commits2026-09-06: 0 commits2026-09-07: 0 commits2026-09-08: 0 commits2026-09-09: 1 commit2026-09-10: 0 commits2026-09-11: 0 commits2026-09-12: 0 commits2026-09-13: 0 commits2026-09-14: 0 commits2026-09-15: 0 commits2026-09-16: 0 commits2026-09-17: 0 commits2026-09-18: 0 commits2026-09-19: 0 commits2026-09-20: 0 commits2026-09-21: 0 commits2026-09-22: 0 commits2026-09-23: 0 commits2026-09-24: 0 commits2026-09-25: 0 commits2026-09-26: 0 commits2026-09-27: 0 commits2026-09-28: 0 commits2026-09-29: 0 commits2026-09-30: 0 commits2026-10-01: 0 commits2026-10-02: 0 commits2026-10-03: 0 commits
96 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Well documented

    High community health score

  • Permissive license

    MIT

  • Continuous integration

    Automated checks passing

What shepherd does

Shepherd is a powerful runtime substrate designed to securely orchestrate, observe, and evaluate autonomous AI agents. It transforms an agent's execution lifecycle into a durable, inspectable trace, allowing developers or meta-agents to observe, fork, replay, and revert any specific run. By tightly coupling the agent and its environment within a highly efficient copy-on-write fork, it enables rapid state restoration and sandboxes agent outputs into a reviewable proposal space before they affect production systems. This infrastructure provides the crucial safety, auditability, and rollback mechanisms needed to train supervisor models or deploy agents into complex, high-stakes workflows.

AI developers, researchers, and platform engineers building complex, autonomous multi-agent systems that demand extreme safety, inspectability, and robust orchestration capabilities.

  • Reversible Execution Traces: Automatically record every agent action into a durable, Git-like log that can be instantly observed, forked, or reverted.
  • Sandboxed Workspace Proposals: Isolate agent outputs into a safe review space, ensuring modifications are explicitly accepted before touching production files.
  • Copy-On-Write Environment Pairing: Couple agents to environments using lightning-fast copy-on-write forks, maximizing KV-cache reuse during replays.
  • Strict OS-Level Permissions: Define explicit permission signatures that are rigidly enforced at the operating system level via Seatbelt (macOS) or Landlock (Linux).
  • Meta-Agent Infrastructure: Provide the foundational architecture required for supervisor agents to monitor, optimize, and train subordinate agents dynamically.

Where teams use it

Auditable Workflow Automation

Deploying teams of specialized agents to handle multi-stage business processes where every action must be strictly logged and reviewable.

Safe Agentic Code Reviews

Utilizing agents to automatically analyze code and propose fixes within a sandboxed environment, requiring human approval before applying changes.

Meta-Optimization Research

Training advanced supervisor models to iteratively optimize the prompt execution and decision-making pathways of subordinate agents through rapid replay.

Secure AI Task Delegation

Executing untrusted or highly experimental AI agents within a rigidly permissioned sandbox that strictly prevents unauthorized network or file access.

Getting started: pip install shepherd-ai

README

main branch
Shepherd

Shepherd: Programmable Meta-Agents via Reversible Execution Traces

Status: Alpha PyPI Python Homepage Docs Paper Blog


Important

Shepherd is in early alpha and under active development. APIs may still change between releases. Feedback and issues are very welcome!

Install | Quickstart | Permissions | Examples | Docs | Citation

Shepherd is a runtime substrate for agent work that needs inspection, reversibility, and supervision. It records agent runs as durable, inspectable execution traces, with retained workspace outputs that can be reviewed before they are selected, applied, released, or discarded.

Platforms. Shepherd requires Python 3.11+. OS-level grant enforcement is executed on both macOS (Seatbelt) and Linux (Landlock, in a privileged container). Windows is unsupported (enforcement would be advisory-only at best) — use WSL.

Installation

pip install shepherd-ai

Working on Shepherd itself? Install the local editable closure instead: python -m venv .venv && . .venv/bin/activate && pip install -r requirements-dev.txt (see CONTRIBUTING.md).

Quickstart

Shepherd is an agent framework: a task's implementation can be a sandboxed agent, and its work comes back as a reviewable proposal — nothing touches your files until you accept it. Here the whole body of a task is a Claude agent.

Needs the claude CLI — signed in (a Claude subscription works) or with an ANTHROPIC_API_KEY. Neither? Jump to the Offline Quickstart — it runs anywhere, keyless.

On a subscription, a sandboxed run is most reliable with a long-lived token: export CLAUDE_CODE_OAUTH_TOKEN=$(claude setup-token). A short-lived signed-in session can't be refreshed from inside the sandbox, so it may work interactively yet fail here — shepherd doctor claude (add --probe for a real auth round-trip under Shepherd's config, in the parent — not a jailed run) tells you which credential you have before you run. If Claude returns an org-policy error (HTTP 403), that's an account/organization limit, not a login problem — a different key or your org admin is the fix. And an outright claude CLI hang (e.g. a stale version) surfaces as a budget timeout, not an auth error.

A task is a plain Python function with no body; the signature and docstring are the contract the agent fulfils at runtime — including its permissions: repo: sp.GitRepo is the explicit writable workspace-handle grant that lets the agent write the repository (see Permissions):

def write_program(
    repo: sp.GitRepo,
    prompt: str,
    output_path: str = "program.py",
) -> None:
    """Write a small, self-contained Python program that does what `prompt` asks.

    Save it to output_path. It must run with plain `python3`, read no input,
    and finish on its own within about ten seconds.
    """

Set up a scratch workspace and check the agent lane is ready:

mkdir /tmp/agent-task && cd /tmp/agent-task
shepherd init             # turn this directory into a Shepherd workspace
shepherd doctor claude    # confirm claude CLI, sign-in/key, and sandbox are ready

Fetch the demo and let the agent work (about a minute):

shepherd demo write agent-task > agent_task.py
python agent_task.py

The agent writes donut.py — but not into your directory. It lands as a retained output: a proposal held safely to one side, which you can run without applying anything:

shepherd run changeset --latest --read donut.py | python3 -

Ten seconds of spinning ASCII donut, straight out of the retained output. If you like it, keep it; if not, throw it away — the trace remembers either way (the demo prints both commands with the real run id):

shepherd run select <run-ref>     # keep it
shepherd run apply  <run-ref>     # ...or merge it onto a workspace that moved on
shepherd run discard <run-ref>    # ...or not

Edit PROMPT in agent_task.py and re-run to ask for anything else — the contract stays the same. For an agent that edits existing files, see shepherd demo write claude-readme.

Offline Quickstart

No API key required. This runs the same retained-output machinery through Shepherd's deterministic provider — the agent lane above, minus the agent:

mkdir /tmp/shepherd-quickstart && cd /tmp/shepherd-quickstart

shepherd init                                  # turn this directory into a workspace
shepherd demo write quickstart > quickstart_demo.py
python quickstart_demo.py                      # register + run a task, retaining its result

shepherd run list                              # the run and its status
shepherd run changeset --latest                # what it wrote, kept as a retained output

Inspect the full record with shepherd run show --latest (add --json to any read command for the durable machine payload); see the docs for backend selection and the complete run surface.

Permissions: the signature is the permission surface

For the common single-workspace writer, repo: sp.GitRepo is the clean spelling: an explicit read-write handle grant. Use May[GitRepo, ReadOnly] when a task must inspect without mutating; an unannotated repo parameter is just an ordinary value parameter, not a handle.

A task can also declare a read-only or read-write grant per bound repository, in its signature:

from shepherd import task, May, GitRepo, ReadOnly, ReadWrite

@task
def apply_documented_fix(
    docs:    May[GitRepo, ReadOnly],   # read-only: writes refused at the OS
    backend: May[GitRepo, ReadWrite],  # writable root
    issue:   str,
) -> None: ...

On a jailed device the grant is compiled to that run's writable roots and enforced at the native syscall jail (macOS Seatbelt; Linux Landlock): a write to a ReadOnly-granted repository, or to any managed path not covered by a ReadWrite grant, is refused at the syscall — before the last undo point, not advised and not caught only at a merge gate. Reading the signature is reading the permission surface, and shepherd task show renders it expanded. Grants are whole-profile per binding (a bound repository is entirely writable or entirely read-only). Bindings are named with ws.bind(root="backend/", name="backend") and passed to a run with workspace.run(task, bindings={...}); each run's world output is inspected per binding with run.changeset(name="backend") and settled once with select / apply / release / discard (apply three-way-merges a candidate onto a workspace that already moved on, when their changes are path-disjoint).

Scope (P-030 v0.2). Per-binding whole-profile ReadOnly/ReadWrite over disjoint named bindings, on a jailed device, filesystem / Git substrate, same-process value-children. Enforcement is executed on both macOS Seatbelt and Linux Landlock (the latter in a privileged container). Sub-root / where(path=…) grants are not part of this cut.

Examples

Audit a paper's bibliography with the Shepherd citation-checker package: shepherd-check-citations paper /path/to/paper.pdf --output citation-report. It uses pdfplumber and Claude Code subscription login with headless Opus. See the package for installation, reports, evaluation results and extraction limitations.

The demo scripts above are the Python surface in miniature — checked-in copies live in examples/quickstart/. The visual-artifact notebooks live in examples/notebooks/visual_artifact/notebooks/ — launch them with make notebooks.

Development

Useful local gates:

make dev-install
uv run pytest integration-tests/test_quickstart_core.py -q
make baseline

Documentation

Full documentation lives at docs.shepherd-agents.ai. In this repository the docs are authored under docs/shepherd/, starting with the Quickstart guide and Concepts — tasks, effects, scopes, permissions, and the trace.

Reproducing Paper Results

The full experiment code — the meta-agent applications and the framework-performance microbenchmarks — lives in a companion repository: shepherd-agents/shepherd-experiments. It bundles the frozen substrate snapshot used for the paper, so the numbers stay reproducible against the exact version that produced them.

Acknowledgments

We thank E2B, Tinker, and Modal for their generous compute support during this project.

SPONSORED BY E2B FOR RESEARCH

Citation

@misc{yu2026shepherdenablingprogrammablemetaagents,
      title={Shepherd: Enabling Programmable Meta-Agents via Reversible Agentic Execution Traces},
      author={Simon Yu and Derek Chong and Ananjan Nandi and Dilara Soylu and Jiuding Sun and Christopher D Manning and Weiyan Shi},
      year={2026},
      eprint={2605.10913},
      archivePrefix={arXiv},
      primaryClass={cs.AI},
      url={https://arxiv.org/abs/2605.10913},
}

License

This project is licensed under the MIT License — see the LICENSE file for details.

View on GitHub

Recent activity

commits and pull requests

Releases and announcements

5 total
  1. Shepherd now includes a citation checker that verifies bibliographic references, explains confirmed errors, and proposes evidence-backed corrections. ```bash pip install --upgrade "shepherd-ai[citation-checker]==0.3.1" claude auth login shepherd-check-citations paper paper.pdf --output citation-report ``` The workflow extracts references from PDFs, collects evidence, verifies complete matches deterministically, and sends difficult cases to Opus in batches. Reports include source links, field-level findings, and BibTeX corrections. Runs preserve evidence and execution traces, support resuming, and retain completed citations when a batch fails. Live reviews require Claude Code subscription authentication and a supported native jail on Linux or macOS. The repository includes the original task, the final workflow, and reproducible evaluation artifacts. The frozen development selection scores **116/140 citations (82.9%)** across Manual, HALLMARK, and DeLTA. Ten ambiguous labels are excluded; abstentions and unfinished citations count as errors. This screened development selection is not a held-out benchmark. This release also: - Selects workspace execution backends appropriate for

  2. Shepherd 0.3.0 completes the retained-output settlement vocabulary: **`apply`** joins `select` / `release` / `discard` as the fourth verb. Where `select` is fast-forward-only, **`apply` three-way-merges a run's whole delta onto a workspace that has moved on** when the two change sets are path-disjoint, and fails closed on any overlap — no content synthesis at the settlement boundary. N candidates, reviewed as changesets, settled explicitly — now including `apply` onto a workspace that moved on. ### Also in this release - **Cleaner task syntax** — `@sp.task` with `ws.tasks.register(fn)` and `ws.run(fn, ...)`, task arguments passed as keywords; `repo: GitRepo` as the writable workspace-handle grant; `with sp.open(".") as ws:`. - **Grant enforcement executed on both macOS (Seatbelt) and Linux (Landlock)** — the 0.2.0 container-gated caveat is retired. - **Beat-0 safety bar** — the fabrication fence and the ambient-world-access refusal. See the CHANGELOG for the full list, including the 0.2.x migration notes. ``` pip install shepherd-ai==0.3.0 ```

  3. v0.2.1v0.2.1Jul 6, 2026

    Shepherd 0.2.1 — Claude CLI lane diagnostics, interrupted-run recovery, and hardening. This release packages PRs #24–#29. Highlights: ## Fixed — the Claude CLI agent lane (#23) The `claude` CLI (headless) lane is the supported public agent provider, and this release makes its failures diagnosable and its preflight honest (PRs #27, #28): - **Actionable failures.** A nonzero `claude` exit now surfaces the CLI's own reason plus a remedy — not a blind 300-char tail-slice. Not-logged-in, org-policy `access_denied` (HTTP 403), and rootful `root_permission` are classified, with the safe envelope scalars kept in the trace. A `budget_seconds` alarm kill (`rc=-14`) maps to a trace-preserving `BudgetExhausted`, with a hung-body hint when the CLI produced no output at all (e.g. a stale `claude` version). - **Fail-fast preflight.** A jailed run with no usable credential (or an expired seeded subscription login) is refused **before** launch (`auth_missing` / `auth_expired`, `launch_attempted: false`) instead of spending a confined launch that fails not-logged-in. Wrappers that authenticate out-of-band can opt back in with `SHEPHERD_ALLOW_KEYLESS_CLAUDE=1`. - *

  4. v0.2.0v0.2.0Jul 5, 2026

    ## What's Changed * Fix CI lint: burn down ruff debt, correct stale excludes by @ananjan-nandi-9 in https://github.com/shepherd-agents/shepherd/pull/8 * Fix docs drift gate: regenerate public-symbols.json after #8 by @ananjan-nandi-9 in https://github.com/shepherd-agents/shepherd/pull/9 * chore: ruff format under the shared config by @dcx in https://github.com/shepherd-agents/shepherd/pull/10 * fix: upstream repairs + minimal CI gates by @dcx in https://github.com/shepherd-agents/shepherd/pull/12 * release: Shepherd 0.2.0 — per-binding signature grants at the syscall jail by @dcx in https://github.com/shepherd-agents/shepherd/pull/14 ## New Contributors * @ananjan-nandi-9 made their first contribution in https://github.com/shepherd-agents/shepherd/pull/8 **Full Changelog**: https://github.com/shepherd-agents/shepherd/compare/v0.1.3...v0.2.0

  5. v0.1.3v0.1.3Jul 1, 2026

    ## What's Changed * docs: early-alpha notice + "a Shepherd" grammar fixes by @dcx in https://github.com/shepherd-agents/shepherd/pull/2 * Add shepherd-ai PyPI packaging tooling by @dcx in https://github.com/shepherd-agents/shepherd/pull/1 * ci: add release + CI workflows and a RELEASING guide by @dcx in https://github.com/shepherd-agents/shepherd/pull/3 * feat(carrier): portable copy carrier + cross-platform auto backend by @dcx in https://github.com/shepherd-agents/shepherd/pull/4 * Fix Claude turn-exhaustion detection; default the headless lane uncapped by @dcx in https://github.com/shepherd-agents/shepherd/pull/5 * Lead the quickstart with a real agent task (donut demo) + offline fallback by @dcx in https://github.com/shepherd-agents/shepherd/pull/6 * Support signed-in claude CLI (subscription) auth; simplify README; prep 0.1.3 by @dcx in https://github.com/shepherd-agents/shepherd/pull/7 ## New Contributors * @dcx made their first contribution in https://github.com/shepherd-agents/shepherd/pull/2 **Full Changelog**: https://github.com/shepherd-agents/shepherd/commits/v0.1.3

Code frequency

additions and deletions
+546.1K-546.1KWeek of 2026-06-21: +67 linesWeek of 2026-06-21: -0 linesWeek of 2026-06-28: +546,076 linesWeek of 2026-06-28: -7,108 linesWeek of 2026-07-05: +24,068 linesWeek of 2026-07-05: -10,544 linesWeek of 2026-07-12: +0 linesWeek of 2026-07-12: -0 linesWeek of 2026-07-19: +9 linesWeek of 2026-07-19: -3 linesWeek of 2026-07-26: +0 linesWeek of 2026-07-26: -0 linesJun 21, 2026Jul 26, 2026
+570.2K lines added, -17.7K removed over the last year.

Commits per week

last 52 weeks
550Week of 2025-10-05: 0 commitsWeek of 2025-10-12: 0 commitsWeek of 2025-10-19: 0 commitsWeek of 2025-10-26: 0 commitsWeek of 2025-11-02: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 0 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 0 commitsWeek of 2026-03-01: 0 commitsWeek of 2026-03-08: 0 commitsWeek of 2026-03-15: 0 commitsWeek of 2026-03-22: 0 commitsWeek of 2026-03-29: 0 commitsWeek of 2026-04-05: 0 commitsWeek of 2026-04-12: 0 commitsWeek of 2026-04-19: 0 commitsWeek of 2026-04-26: 0 commitsWeek of 2026-05-03: 0 commitsWeek of 2026-05-10: 0 commitsWeek of 2026-05-17: 0 commitsWeek of 2026-05-24: 0 commitsWeek of 2026-05-31: 0 commitsWeek of 2026-06-07: 0 commitsWeek of 2026-06-14: 0 commitsWeek of 2026-06-21: 2 commitsWeek of 2026-06-28: 28 commitsWeek of 2026-07-05: 55 commitsWeek of 2026-07-12: 0 commitsWeek of 2026-07-19: 5 commitsWeek of 2026-07-26: 0 commitsWeek of 2026-08-02: 0 commitsWeek of 2026-08-09: 5 commitsWeek of 2026-08-16: 0 commitsWeek of 2026-08-23: 0 commitsWeek of 2026-08-30: 0 commitsWeek of 2026-09-06: 1 commitsWeek of 2026-09-13: 0 commitsWeek of 2026-09-20: 0 commitsWeek of 2026-09-27: 0 commitsOct 5, 2025Sep 27, 2026
96 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 0 commitsSun 1:00 — 0 commitsSun 2:00 — 0 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 0 commitsSun 7:00 — 0 commitsSun 8:00 — 0 commitsSun 9:00 — 3 commitsSun 10:00 — 2 commitsSun 11:00 — 4 commitsSun 12:00 — 4 commitsSun 13:00 — 9 commitsSun 14:00 — 0 commitsSun 15:00 — 0 commitsSun 16:00 — 0 commitsSun 17:00 — 0 commitsSun 18:00 — 0 commitsSun 19:00 — 0 commitsSun 20:00 — 0 commitsSun 21:00 — 0 commitsSun 22:00 — 0 commitsSun 23:00 — 0 commitsMon 0:00 — 1 commitsMon 1:00 — 0 commitsMon 2:00 — 0 commitsMon 3:00 — 0 commitsMon 4:00 — 0 commitsMon 5:00 — 1 commitsMon 6:00 — 5 commitsMon 7:00 — 2 commitsMon 8:00 — 5 commitsMon 9:00 — 0 commitsMon 10:00 — 0 commitsMon 11:00 — 0 commitsMon 12:00 — 1 commitsMon 13:00 — 7 commitsMon 14:00 — 6 commitsMon 15:00 — 0 commitsMon 16:00 — 1 commitsMon 17:00 — 0 commitsMon 18:00 — 0 commitsMon 19:00 — 0 commitsMon 20:00 — 1 commitsMon 21:00 — 0 commitsMon 22:00 — 0 commitsMon 23:00 — 0 commitsTue 0:00 — 0 commitsTue 1:00 — 0 commitsTue 2:00 — 0 commitsTue 3:00 — 0 commitsTue 4:00 — 0 commitsTue 5:00 — 0 commitsTue 6:00 — 0 commitsTue 7:00 — 0 commitsTue 8:00 — 0 commitsTue 9:00 — 3 commitsTue 10:00 — 2 commitsTue 11:00 — 0 commitsTue 12:00 — 2 commitsTue 13:00 — 0 commitsTue 14:00 — 1 commitsTue 15:00 — 0 commitsTue 16:00 — 0 commitsTue 17:00 — 0 commitsTue 18:00 — 1 commitsTue 19:00 — 0 commitsTue 20:00 — 0 commitsTue 21:00 — 0 commitsTue 22:00 — 0 commitsTue 23:00 — 0 commitsWed 0:00 — 0 commitsWed 1:00 — 0 commitsWed 2:00 — 0 commitsWed 3:00 — 1 commitsWed 4:00 — 0 commitsWed 5:00 — 0 commitsWed 6:00 — 0 commitsWed 7:00 — 1 commitsWed 8:00 — 1 commitsWed 9:00 — 0 commitsWed 10:00 — 4 commitsWed 11:00 — 5 commitsWed 12:00 — 2 commitsWed 13:00 — 1 commitsWed 14:00 — 2 commitsWed 15:00 — 0 commitsWed 16:00 — 0 commitsWed 17:00 — 0 commitsWed 18:00 — 0 commitsWed 19:00 — 0 commitsWed 20:00 — 0 commitsWed 21:00 — 0 commitsWed 22:00 — 4 commitsWed 23:00 — 1 commitsThu 0:00 — 0 commitsThu 1:00 — 0 commitsThu 2:00 — 0 commitsThu 3:00 — 0 commitsThu 4:00 — 0 commitsThu 5:00 — 0 commitsThu 6:00 — 1 commitsThu 7:00 — 0 commitsThu 8:00 — 0 commitsThu 9:00 — 0 commitsThu 10:00 — 1 commitsThu 11:00 — 0 commitsThu 12:00 — 0 commitsThu 13:00 — 0 commitsThu 14:00 — 0 commitsThu 15:00 — 0 commitsThu 16:00 — 0 commitsThu 17:00 — 0 commitsThu 18:00 — 0 commitsThu 19:00 — 0 commitsThu 20:00 — 0 commitsThu 21:00 — 1 commitsThu 22:00 — 0 commitsThu 23:00 — 0 commitsFri 0:00 — 0 commitsFri 1:00 — 0 commitsFri 2:00 — 0 commitsFri 3:00 — 0 commitsFri 4:00 — 0 commitsFri 5:00 — 0 commitsFri 6:00 — 0 commitsFri 7:00 — 0 commitsFri 8:00 — 0 commitsFri 9:00 — 0 commitsFri 10:00 — 0 commitsFri 11:00 — 0 commitsFri 12:00 — 0 commitsFri 13:00 — 0 commitsFri 14:00 — 0 commitsFri 15:00 — 0 commitsFri 16:00 — 0 commitsFri 17:00 — 0 commitsFri 18:00 — 0 commitsFri 19:00 — 0 commitsFri 20:00 — 0 commitsFri 21:00 — 0 commitsFri 22:00 — 0 commitsFri 23:00 — 0 commitsSat 0:00 — 0 commitsSat 1:00 — 0 commitsSat 2:00 — 0 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 7 commitsSat 7:00 — 4 commitsSat 8:00 — 0 commitsSat 9:00 — 0 commitsSat 10:00 — 0 commitsSat 11:00 — 0 commitsSat 12:00 — 0 commitsSat 13:00 — 0 commitsSat 14:00 — 0 commitsSat 15:00 — 0 commitsSat 16:00 — 0 commitsSat 17:00 — 0 commitsSat 18:00 — 0 commitsSat 19:00 — 0 commitsSat 20:00 — 0 commitsSat 21:00 — 0 commitsSat 22:00 — 0 commitsSat 23:00 — 0 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Jul 6, 2026daily#22+5