Skip to content PULSAR
Docs Install
DocsThemesReleases Install Source on GitHub
Docs Coding agents

Coding agents

Pulsar ships no agent. Add one and it gets a briefing on this machine, health tools, and an optional sandbox that shows it one project.

Install one

The welcome window offers them at first login. Or:

add creates an agents toolbox, installs the agent with its vendor’s npm or uv method into ~/.local/share/pulsar/agents, and adds a command to ~/.local/bin. No root, nothing layered. An agent you installed yourself is left in place (listed as native) and still gets the setup below.

It keeps Node, Python and the agent off the host (toolbox rm -f agents removes it all), but shares your home folder and session. For isolation, use the sandbox.

What it knows about the machine

/usr/share/pulsar/AGENTS.md briefs agents on this system: read-only /usr, toolboxes, Flatpaks, what rollback covers, and what never to do. pulsar agent guide prints it; any agent can start there.

add also links it into the agent’s own instructions if none exist (Claude Code: ~/.claude/rules/pulsar.md), links the image’s skills (including one that makes themes), and for MCP agents registers pulsar mcp:

ToolWhat it answers
doctorthe health checks, all or one
statusdeployments, pins and layered packages
manifestthe image, the variant, the kernel and the hardware
reportthe redacted diagnosis report, with a crash if asked
crashesyour crashes this boot
update_checkwhether a newer image is out
agent_statusthe guide, the agents, guard, the pin and the sandbox setting
theme_list, theme_currentthe desktop themes
theme_setthe one tool that changes anything: your desktop theme, undone by pulsar theme revert

No tool needs root, and no root command is exposed: update, rollback, checkpoint, guard and pin stay yours. pulsar agent shows the setup:

Ask it to fix something

ask writes a redacted pulsar report (plus the crash, if named) to a private file in $XDG_RUNTIME_DIR (deleted at logout), then starts your agent with a prompt pointing at it, your question, and “Do not change the system without asking me first.” opencode: press Enter to send. aider: the report is a read-only file; paste the printed prompt.

A crash notification’s Ask button runs pulsar agent ask --crash in a new terminal. The report has the stack trace and logs, never the core file (Troubleshooting). What the agent reads goes to its provider; clicking is consent.

A model on your own GPU

opencode and aider can use a local OpenAI-compatible server, no account needed:

  • Runs llama.cpp’s server image as a rootless user service: CUDA on the NVIDIA image, Vulkan with a GPU at /dev/dri, else CPU.
  • First start downloads the model into ~/.local/share/pulsar/models.
  • Serves http://127.0.0.1:8080/v1 (local only); requests need the key in ~/.config/pulsar/model-key.
  • opencode: pick “Local (Pulsar)” with /models. aider: pulsar agent model prints the command.
  • Stops at logout unless started with --at-login (a loaded model holds gigabytes of video memory).

The sandbox

The agent runs in a rootless container that sees only the project you started it in: no SSH keys, browser profiles or other projects. Pushes go through a host-side gate that uses your credentials without exposing them and refuses force-pushes, deletions and tags.

  • The agent can commit, but git config and hooks (the repo’s, its submodules’, and any in-project hooks path or include) are read-only, and .git can’t be moved.
  • A new commondir or .git in the tree is renamed to <name>.from-sandbox when the session ends. Until then, an editor running git in the background could follow it: close the editor on the project while an untrusted agent works.
  • Linked worktrees and submodule checkouts are refused.

Type the agent’s name as usual:

Start it inside a project; it refuses your whole home folder. In interactive bash, claude, codex, gemini, opencode and aider go through the sandbox. Scripts, other shells and command claude don’t; pulsar agent run claude always follows your settings.

A repository can require the sandbox (this file can only tighten settings):

What goes in, what comes out, and what it doesn’t protect (the network): Agents and safety.

Guard, and checkpoints

On stock Fedora, an admin’s session (and anything it starts) can layer packages, roll back, and install or remove system Flatpaks without a password:

sudo pulsar agent guard on makes all five ask for the admin password. Updates stay ungated. sudo pulsar agent guard off restores Fedora’s default.

Before a long session: sudo pulsar checkpoint "before the agent"; afterwards diff and restore. Checkpoints.

Written with help from AI and reviewed by a person before publishing. Spotted a mistake? Let us know.

PULSAR

Your lighthouse in the sky.

Site

Machine

Arclight

Theme

Dark only Light only

Recolors the whole site, like pulsar theme set does your desktop.

Light and dark

One look picks light or dark for you

Saved in this browser Back to Pulsar