AgentloopSAFE
MIT-licensed, backend-agnostic AI agent orchestration loop in Python: orchestrator→worker→reviewer as a deterministic harness. Drive coding-agent backends through an MCP server + CLI.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE)
agentloop is a lightweight Python framework for multi-agent orchestration. It implements the orchestrator → worker → reviewer pattern (the AI agent orchestration loop) as a deterministic harness with a closed feedback loop: a goal is decomposed into subtasks, fanned out to worker subagents, aggregated, and run through a review gate that loops until the work meets its success criteria. One loop drives any LLM backend — Anthropic Claude, Claude Code, Codex, opencode, or aider — through a single Agent interface, and it ships as both an MCP server and a plain CLI so any coding agent can call it.
The design principle: the loop is a harness (deterministic code), not a skill. A prompt can describe "decompose, review, loop until done" but can't guarantee it. So the control flow lives in code, and the model-facing judgement (how to decompose, the review rubric) lives in swappable prompts. One harness drives any backend through a single Agent interface.
The tweet that started it all — Peter Steinberger (@steipete): "You shouldn't be prompting coding agents anymore. You should be designing loops that prompt your agents." agentloop is that idea as a reusable harness.
┌──────────── harness (this package) ────────────┐ goal ─▶ decompose ─▶ fan-out to subagents ─▶ aggregate ─▶ review gate ─▶ done? ▲ │ no └──────────────── feedback: refine plan ◀──────────────────┘
Quick start
python3 -m examples.run_demo # zero-dependency MockAgent python3 -m pytest # full test suite, no deps
from agentloop import Orchestr
945001dc2adeOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add agentloop --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env XAI_API_KEY=${XAI_API_KEY} -- uvx agentloop{
"mcpServers": {
"agentloop": {
"command": "uvx",
"args": [
"agentloop"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"XAI_API_KEY": "${XAI_API_KEY}"
}
}
}
}Exposed tools (8)
3 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
doctor | read | Diagnose this MCP server and worker backend availability without running agents. |
list_backends | read | List worker backends this server can drive. |
orchestrate | write | Run an orchestrator -> worker -> reviewer loop until the success |
orchestrate_list | write | List every detached run this server has started, with its status. |
orchestrate_result | write | Fetch the final result of a detached run. |
orchestrate_resume | write | Resume a run whose intake paused with stop_reason |
orchestrate_status | write | Light status of a detached run: phase, current iteration, whether it is |
orchestrate_tail | read | Read what the loop has done since `cursor` — the live window into a |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
print(f"\ntoken: {result['token']}")curl -fsSL https://x.ai/cli/install.sh | bash
Gates applied: no_behavioural_pass.
945001dc2adefull audit observations/trust-audit/mcp-server/luckeyfaraday__agentloop.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 945001dc2ade | SAFE | B | 89 | first audit |
Questions
What is the Agentloop MCP server?
MIT-licensed, backend-agnostic AI agent orchestration loop in Python: orchestrator→worker→reviewer as a deterministic harness. Drive coding-agent backends through an MCP server + CLI.
What tools does Agentloop expose?
8 in total: 3 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Agentloop safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Agentloop need?
It reads ANTHROPIC_API_KEY and XAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (945001dc2ade), read on 2026-10-08. The repository is watched and re-audited when it changes.