A coding agent that holdsthe whole working set.
Code Studio is a VS Code-style environment with a dedicated coding agent. It reads across files, plans the change in the open, and works inside the folder you opened, with a checkpoint before every turn so any of it can be undone.
Ask for a change. Read the diff. Decide.
The demo below runs the Code Studio scenario: file tree, staged diff, and the agent's own plan with its budget.
Move auth off server sessions
src/auth/middleware.ts
Staged. Review it before it touches the working tree.
The plan it wrote for itself
And this is Code Studio as it ships.
A full editor with a file tree, a tab strip, and the agent in a rail beside it, asking before it touches three files, not after.
Explorer
- src
- components
- lib
- auth.ts
- session.ts
- tokens.ts
- README.md
1
import { sign, verify } from 'jsonwebtoken'
2
3
export async function issueSession(userId: string) {
4
const token = sign({ sub: userId }, SECRET, {
5
expiresIn: '15m',
6
});
7
8
// Refresh token rotates on every use.
9
const refresh = await rotate(userId);
10
return { token, refresh };
11
}
Interface, rebuilt in the page · v0.1.10
Refactors that span files, not snippets that span lines.
Most coding assistants operate on the buffer in front of you. The Code Studio agent operates on the working set: it opens what it needs, tracks what it has changed, and keeps the change coherent across every file it touches.
- Reads and edits across the whole working set in one plan
- Tracks which files are read, edited, and added, and shows you
- Runs the test suite in the workspace before declaring itself done
- Every step is visible as it runs, and stoppable if it is going wrong
- 01Resolve the working setWhich files does this change actually touch?
- 02Checkpoint the workspaceA restore point, before anything is written
- 03Make the changeEvery edit shown as a reviewable diff
- 04Verify itTests run in the workspace before it reports done
- 05Yours to keep or undoOne click rewinds files and chat together
An agent that writes code is a security question.
Treating it as one is the difference between a demo and something you can run on a work machine.
Everything happens inside the workspace
File reads, writes and deletes are scoped to the folder you opened, and paths that try to climb out of it are rejected. Commands run with the workspace as their working directory.
Destructive commands are refused outright
Privilege escalation, anything that powers the machine down or reformats a disk, and deletes aimed at absolute or home-relative paths do not run. There is no phrasing that gets them through.
Risky commands stop and ask
Recursive deletes, history rewrites, anything that publishes to a remote, and piping the network into a shell are held for an approval card in the IDE. You see the exact command before it runs.
Every message is a restore point
The workspace is checkpointed into a shadow history, separate from your own version control, before each turn. Undo rewinds the files and the conversation together, so a bad refactor is one click rather than an archaeology session.
Point it at a real repository.
Free to download. The code never leaves your machine, which is the only reason it is safe to give an agent this much access.