Skip to content
Weiß CODEby Niflheim

Weiß CODE · 002 / Free · out now

Free · lightweight · yours to keep

Bring your AI. Keep your rules.

A small, free assistant that lives in your project instead of a browser tab. It reads the code, writes a plan you can check, and asks before it changes anything. You pick the AI behind it, and you pick how far it can go.

npm install --global @najihh/weiss-code

Install the signed release with npm, or use Homebrew, Scoop, or a release archive.

weiss — ~/code/payments
>_ WEIß CODE (v0.1.0)
model: auto · anthropic/claude-sonnet /model to change
directory: ~/code/payments
sandbox: filesystem · read-only
session: da30de40-7c7e-489a-b0c8-f407916826e0
mode: PLAN
Use /help for commands, /mcp and /hooks to inspect integrations.
Approval mode: plan — reads and the plan/validation tools; everything else is refused
› find the cause of the checkout timeout, make the smallest fix, then run the relevant tests
• fs.read AGENTS.md repository instructions resolved
• git.status clean · fix/checkout-timeout
• hook session.start scripts/guard.sh · exit 0
✻ Thinking
The gateway call has no deadline of its own, so it inherits the outer request timeout and the retry never gets a turn.
⌕ code.references chargeGateway 240ms
src/checkout/request.ts:118 await chargeGateway(order) src/checkout/retry.ts:41 retry(() => chargeGateway(order))
⌘ mcp.call observability · p99 checkout latency 612ms
p99 30.0s · timeout ceiling reached on 4.1% of orders
2 of 4 TODO(s) done
[x] reproduce the timeout under the sandbox [x] inspect the checkout request path
> [~] give the gateway call its own deadline
[ ] run the tests that cover checkout
mode plan → acceptEdits — reads and file writes/creates/edits/moves; everything else asks
✎ fs.edit src/checkout/request.ts 88ms
- await chargeGateway(order)
+ await chargeGateway(order, { deadlineMs: GATEWAY_DEADLINE_MS })
• process.exec pnpm test checkout running…

APPROVAL REQUIRED

Effect:
process.exec · outbound network
Scope:
~/code/payments · integration suite
Reversibility:
reversible
Reason:
the integration tests reach the gateway sandbox over the network

[d] deny [o] approve operation [r] approve displayed rule

• rule allowed · process.exec + net.fetch (this session) recorded in the event log
$ process.exec pnpm test checkout 8410ms
PASS src/checkout/request.test.ts (7) PASS src/checkout/retry.test.ts (3) 10 passed · p99 1.9s
✦ Response
The gateway call inherited the outer request deadline, so the retry never ran. It now carries its own 4s deadline; 10 checkout tests pass.
session da30de40 · 1 file changed · 1 rule granted · 23 events · resume with /resume
› ask for the next change
✦ auto◑ medium⚙ acceptEdits📁 ~/code/payments⎇ fix/checkout-timeout

One real job, start to finish: find the bug, plan the fix, make the change, ask before running the tests, and leave a record.

Nothing up its sleeve.

Every line in that window is a choice you could have stopped. That is the difference between an assistant you have to babysit and one you can hand a job to — and it is why a teammate who missed the whole thing can still read back exactly what happened.

  1. 01

    It learns your rules

    Your project's own AGENTS.md is read before anything else.

  2. 02

    It shows its work

    A plan you can read, correct, or throw out.

  3. 03

    It uses your tools

    The things you already rely on — MCP, skills, hooks — not a walled garden.

  4. 04

    You set the leash

    Change how far it can go, and it says so out loud.

  5. 05

    It stops at the line

    Anything that reaches outside waits for your yes.

  6. 06

    It keeps the receipt

    Every step is on record as evidence, not summarised afterwards.

You set the leash

It never owns your machine.

One setting decides what it may do on its own, what it has to ask about, and what it simply is not allowed to try. Tighten it for a stranger's code, loosen it on a branch you can throw away. It is one keystroke to change, and it is always written on screen so you never have to remember which mode you are in.

Whichever mode you pick, anything that cannot be undone always stops and asks first. There is no setting that turns that off by accident.

  • default

    reads only; everything else asks

    Shift+Tab
  • acceptEdits

    reads and file writes/creates/edits/moves; everything else asks

    Shift+Tab
  • plan

    reads and the plan/validation tools; everything else is refused

    Shift+Tab
  • auto

    everything runs without asking

    Shift+Tab
  • dontAsk

    reads only; everything else is refused instead of asked

    /approval
  • bypassPermissions

    everything runs without asking (same as auto)

    /approval

Your AI, your bill

Swap the brain. Keep the tool.

Use a cheap one for the boring parts and a clever one for the hard parts — one keystroke apart, mid-job if you like. Your keys stay locked on your machine, and the name of whatever is answering is always on screen, so you are never guessing who did the work.

One keystroke to switch · nothing locked in

  • Claude

    Anthropic

  • GPT

    OpenAI

  • Gemini

    Google

  • Anything else

    Point it at your own provider

  • Nothing at all

    Replay a saved session with no calls out

It fits how you already work.

  • Your house rules

    Drop an AGENTS.md in the project and it follows it.

  • Your tools

    Connect MCP servers over stdio or Streamable HTTP in a couple of lines.

  • Your scripts

    Hooks run your own checks automatically before and after each tool.

  • Your old setup

    weiss compat explain brings settings over from Claude, Codex or OMP.

Ask it anything

Nothing is hidden behind a menu.

Want to know what it is allowed to do, what it did last Tuesday, or whether your setup is healthy? Ask it directly. If you can't check something yourself, you can't really trust it.

  • weissOpen it and start talking
  • weiss run <TASK>Give it one job and get the answer back
  • weiss resume <SESSION_ID>Pick up exactly where you left off
  • weiss reviewHave it look over what you just changed
  • weiss policy explain fs.writeAsk what it is and isn't allowed to do
  • weiss session show <ID> --evidenceRead back everything it actually did
  • weiss compat explain codexBring over the setup from a tool you use
  • weiss mcp add docs --transport stdioPlug in one of your own tools
  • weiss auth set anthropicStore a provider credential as a handle
  • weiss doctorCheck everything is set up properly

Security principles

Untrusted by default.

  • Model and operation output is always untrusted.
  • Read and write are separate capabilities.
  • Network, filesystem, process, and credentials have separate policies.
  • Destructive commands cannot rely on generic approval.
  • Secrets never enter prompts or event logs.
  • Every external effect has an operation ID, status, and result evidence.

There is a bigger one coming.

Weiß · next up

For everything that isn't code

The same promise — plans you can read, nothing risky without a yes — pointed at research, errands and the long jobs nobody enjoys.

↑ same rules, wider job

Weiß CODE · here now

For the project in front of you

Free to download today, and it stands on its own. You never have to wait for the other one to get value out of this.

Get it

Three lines and you're in.

It's free, it's small, and it lives entirely on your machine — no account, no upload, no meter running. Install the signed release in one line, or build from source when you want the latest code.

Recommended · npm

npm install --global @najihh/weiss-code
weiss --version
weiss doctor

The package downloads the signed release for your platform and verifies its SHA-256 checksum. Then point it at a project and say hello.

Other options

Homebrew

brew install Najihh/tap/weiss-code

Scoop

scoop bucket add Najihh https://github.com/Najihh/scoop-bucket
scoop install weiss-code

macOS / Linux

curl -fsSL https://github.com/Najihh/Weiss/releases/latest/download/install.sh | sh

Windows PowerShell

irm https://github.com/Najihh/Weiss/releases/latest/download/install.ps1 | iex

The shell scripts verify the downloaded archive's SHA-256 checksum before installing. Source builds remain available in the repository.

  • Use it on real workReady
  • Free and open to copy (MIT)Ready
  • You decide what it may touchReady
  • Sharper edges, more polishIn progress
  • One-line installReady
  • Signed, numbered releasesReady

FAQ

Questions, answered plainly.

Is it really free?

Yes. Weiß CODE is MIT-licensed and free to use, copy and change. You pay only your own AI provider, if you use one.

Does my code leave my machine?

Only to the model provider you choose, and only what a task needs. Credentials are stored as handles under ~/.weiss/secrets and never enter prompts or event logs.

Which platforms are supported?

macOS, glibc Linux and Windows on x86-64 and ARM64 — six Tier 1 targets, each shipped as a signed release.

How do I verify a release?

The npm package and install scripts verify the archive's SHA-256. Every release also publishes a SHA256SUMS signed through keyless Sigstore for stronger verification.

Where does it keep files?

Your own settings live in ~/.weiss/, a project's in <workspace>/.weiss/. Anything under state/ or cache/ is safe to delete — Weiß rebuilds what it needs.

Try it tonight

Free, and it stays that way. If you end up liking it, the best thank-you is a star — and if something annoys you, tell us now, while the rules are still easy to change.

Issues and pull requests welcome · small ones are the best kind