Skip to content

PocketHarness: a tiny coding-agent harness in one C++ binary for Linux

Open-source software · 2 min read · updated

PocketHarness is a deliberately tiny, Linux-native coding-agent harness: one C++20 binary with a chat terminal UI, slash commands and autonomous goals, and no SDKs, plugins, MCP layer or other languages. The whole design is one loop: the terminal feeds an agent, the agent calls a model provider, the model may call tools, and Linux executes them. It is MIT-licensed.

Platform
Linux x86_64
Language
C++20
Licence
MIT
Requires
  • g++ (C++20), make and curl
  • Optional: Chrome, FFmpeg, llama.cpp for screenshots, video and the local judge
Run
See the README for the install steps
The PocketHarness mascot, a pocket-sized toolbox robot, above the loop terminal, agent loop, model, tool, Linux, result.

How do I install PocketHarness?

git clone https://github.com/yunusemrejr/pocketharness
cd pocketharness
./install.sh        # builds, tests, installs to ~/.local/bin/pocket

Or manually: make && make test && make install. Then verify with command -v pocket, pocket --version and pocket --help. The requirements are g++ (C++20), make and curl, with no bundled third-party code. Chrome or Chromium, FFmpeg with H.264 encoding, and a llama.cpp llama-server with a GGUF file are optional, for screenshots, video export and the free local judge.

What is the loop at the centre of it?

terminal → agent loop → model provider → optional tool call → Linux/filesystem → result → agent loop

Everything else is a small native function hung on that loop. General-purpose work is delegated to Linux rather than wrapped: curl for HTTPS, Chrome for screenshots, FFmpeg for video and llama.cpp for the local judge.

Which tools does the model get?

Exactly five: read, write, edit, bash and skill. There are intentionally no tools for git, grep, find, curl, npm, python, compilers, test runners, todos, memory or background jobs; the model uses normal programs through bash. The README's reason is that every wrapper would add another schema, authority boundary, test surface and context cost.

How does it limit what the agent can do?

Safety is enforced by the harness and the Linux kernel, not by asking the model to behave. The README lists openat2 path containment, Landlock confinement of every model command, NO_NEW_PRIVS so there is no sudo or setuid gain, and a refusal to run as root unless --allow-root is given. By default the workspace is readable and writable, while $HOME, ~/.ssh and other repositories are not accessible. Model bash has network access by default; --offline denies it.

What does it deliberately leave out?

The README's "anti-goals" rule out an extension or plugin API, event bus, MCP, dependency graph, swarms, a subagent or workflow framework, an embedded browser runtime, a vector database, telemetry, capability registries, wrappers for Linux commands and dependency-injection frameworks. It links no libcurl, Boost, ncurses or OpenSSL, uses no SQLite, and contains no second language.

Quick answers

What do I need to build PocketHarness?
g++ with C++20 support, make and curl. There is no bundled third-party code. Chrome or Chromium, FFmpeg with H.264 and llama.cpp are optional.
Does it use MCP or plugins?
No. The README lists MCP, plugins and an extension API among its anti-goals. The model-facing tools are read, write, edit, bash and skill.
Where is it installed?
./install.sh builds, tests and installs the pocket binary to ~/.local/bin/pocket. You can also run make, make test and make install by hand.

More on Downloads