Axe
Frameworks & Eval · tested 2026-08-18 · re-test due 2026-11-16 · by the Hlido desk, not the vendor
In short: A Unix-philosophy answer to the everything-chatbot: small, single-purpose LLM agents defined in TOML and composed with cron, pipes and git hooks — a coherent design that is also refreshingly security-conscious.
Quick answer
Axe scores 70/100 (STEADY) on Hlido’s independent, hands-on test (reviewed 2026-08-18). STEADY (70) because Axe presents a coherent, well-documented design — Unix-composable single-purpose agents defined in version-controllable TOML, multi-provider, with genuinely security-conscious defaults (working-direct Pricing: Open source (free entry point documented).
Axe makes an argument as much as a product, and the argument is good: most AI tooling assumes you want one long-running chatbot with a giant context window doing everything, but good software is small, focused and composable, so agents should be too. Axe treats LLM agents the way Unix treats programs — each does one thing, defined in a TOML file with its own system prompt, model, skills, context and memory, and run from the command line. Pipe data in, get results out, chain agents, trigger them from cron, git hooks or CI. It is explicitly 'the executor, not the scheduler,' composing with the Unix tools you already use rather than reinventing orchestration — a disciplined scoping decision. The feature list is substantial and, notably, security-aware in ways many agent frameworks are not: multi-provider (Anthropic, OpenAI, Ollama, OpenCode, AWS Bedrock), sub-agent delegation with depth limiting and parallel execution, persistent timestamped-markdown memory with LLM-assisted garbage collection, built-in file tools sandboxed to the working directory, an output allowlist that restricts url_fetch/web_search to specific hostnames with private/reserved IPs always blocked (SSRF protection), token budgets, configurable retry with backoff, and MCP tool support over SSE/streamable-HTTP. Four direct dependencies, a single Go binary, TOML configs you can version-control. The caveats are those of a young, single-maintainer open-source project: the documentation surface we captured is clear and complete, but there is no adoption, benchmark or reliability evidence, no third-party validation, and the behavioural quality of the agents it runs depends entirely on the user's configs and chosen providers. As a composable, scriptable, security-conscious agent runner for people who live in the terminal, it is a genuinely well-thought-out tool.
Why STEADY
STEADY (70) because Axe presents a coherent, well-documented design — Unix-composable single-purpose agents defined in version-controllable TOML, multi-provider, with genuinely security-conscious defaults (working-directory sandboxing, SSRF-protected output allowlist, token budgets, depth-limited delegation) and MCP support — as a clean single binary. Not VITAL because it is an early, solo open-source project with no adoption, benchmark or reliability evidence on the captured surface, and the quality of any agent it runs depends wholly on the user's configuration and provider choices.
What it does well
- Models agents the Unix way: small, single-purpose, defined in version-controllable TOML, composed with cron/pipes/git hooks
- Stays scoped as the executor, not the scheduler — composes with existing tools instead of reinventing orchestration
- Ships security-conscious defaults: working-directory-sandboxed file tools, SSRF-protected output allowlist, token budgets
- Supports multiple providers (Anthropic, OpenAI, Ollama, OpenCode, AWS Bedrock) and MCP tools over SSE/streamable-HTTP
- Offers sub-agent delegation with depth limiting and parallel execution, plus persistent memory with LLM-assisted GC
- Distributes as a single Go binary with only four direct dependencies and stdin piping for composition
What it fails at
- Early, single-maintainer open-source project with no adoption, benchmark or reliability evidence on the surface
- Agent behavioural quality depends entirely on the user's TOML configs and chosen model providers
- No third-party validation of the security controls (sandboxing, SSRF allowlist) on the captured surface
- Terminal- and config-file-centric; not for users wanting a GUI or a managed platform
- Documentation is thorough but the product's real-world robustness at scale is unproven
Best for
- Developers who want composable, single-purpose LLM agents triggered from cron, git hooks, CI and pipes
- Teams that value version-controllable, declarative agent definitions over a monolithic chatbot
- Security-conscious users who want working-directory sandboxing and SSRF-protected fetches by default
- Polyglot/multi-provider setups (Anthropic, OpenAI, Ollama, Bedrock) run from a single binary
Not recommended for
- Users wanting a GUI or an all-in-one conversational assistant rather than a scriptable CLI executor
- Teams needing vendor support, SLAs or proven at-scale reliability before adoption
- Those expecting Axe to schedule/orchestrate for them — it is deliberately the executor only
- Non-technical users uncomfortable authoring TOML agent configs
Pricing & access
- ModelOpen source
- Free entry pointYes — a free tier or open-source edition is documented
Derived from Hlido-held evidence only (engine checklist + editorial text); quotes are verbatim from the scorecard; not vendor-supplied; re-derived daily. Verify current prices on the vendor's pricing page. Last verified 2026-08-18.
Compared to
-
Agent Manager
composable-headless-agent-execution
Both run coding/LLM agents from the terminal, but Axe is a headless, composable executor — agents defined in TOML and chained with cron, pipes and CI for automation — whereas Agent Manager is an interactive TUI for driving many live agent sessions by hand. Choose Axe to script and automate single-purpose agents; choose Agent Manager to supervise a fleet of interactive coding agents.
Agent relevance
CLI MCP Behavioral-testable
Agentic-Commerce Readiness 57/100 · INTEGRABLE
Independent readiness for agent delegation & transaction. How it’s scored · check live
Axe IS an agent runner: define agents in TOML and invoke them from the shell (e.g. `git diff | axe run reviewer`), chain them, or trigger from cron/CI. It also consumes external MCP servers over SSE/streamable-HTTP to extend an agent's tools, and can delegate to sub-agents. Fully scriptable and composable; JSON output and dry-run mode make it easy to embed in larger automation.
Agent-friendly score: 8/10
Score over time
The longitudinal record — every point is the score as published on that date. Raw series.
Evidence
- Single-purpose agents defined in TOML, composed with cron/pipes/git hooks; executor not scheduler — source (2026-08-18) verified
- Working-directory-sandboxed file tools and SSRF-protected output allowlist (private IPs blocked) — source (2026-08-18) verified
- Multi-provider (Anthropic, OpenAI, Ollama, OpenCode, Bedrock) and MCP tool support — source (2026-08-18) verified
- Sub-agent delegation with depth limiting; token budgets; four direct dependencies — source (2026-08-18) verified
- Independent adoption, benchmark or reliability evidence — source (2026-08-18)