THE AI AGENT FIELD GUIDESOURCES FIRST. CLEARER CHOICES.
OPEN-SOURCE SELECTION · CHECKED 2026-10-11

Inspect permissions before connecting your files.

Five source reviews explain what to check before a pilot. Each one links to an exact commit, identifies the observed controls, and keeps source analysis separate from recorded execution tests.

MIT · SOURCE INSPECTED

nanobot

Consider it for a configurable Python assistant when you can review its file, command, and provider configuration.

Key finding: The tool configuration declares restrict_to_workspace as false. File-tool creation uses the configured workspace restriction or exec sandbox setting to decide its allowed directory.

Inspect permissions & evidence →

MIT · SOURCE INSPECTED

PicoClaw

Consider it for a Go-based assistant when a controlled workspace and explicit isolation setup suit the deployment.

Key finding: Default configuration enables RestrictToWorkspace but leaves Isolation.Enabled false. Workspace policy and subprocess isolation are separate settings.

Inspect permissions & evidence →

Apache-2.0 · SOURCE INSPECTED

Goose

Consider it for developer workflows when you can control the active mode and enabled extensions.

Key finding: GooseMode defines Auto, Approve, SmartApprove, and Chat. Auto is the enum default; the other modes describe approval before every call, sensitive calls only, or no tool calls.

Inspect permissions & evidence →

MIT · SOURCE INSPECTED

OpenCode

Consider it for coding workflows where you can inspect the active agent, session rules, and saved approvals.

Key finding: The evaluator uses the last matching rule and falls back to ask when no rule matches. The service also combines agent/session rules and saved project approvals.

Inspect permissions & evidence →

GPL-3.0 · SOURCE INSPECTED

Chatblade

Consider it for terminal text workflows when you understand the configured API endpoint and session retention.

Key finding: The client builder selects Azure OpenAI when its environment setting is present; otherwise it uses OpenAI with a configurable base URL. The request sends the message list to chat.completions.create.

Inspect permissions & evidence →

What we used REA for

REA 6.4.0 generated a historical source inventory for each pinned repository using import-reference-source. We then read selected configuration, permissions, storage, and execution code. Every profile provides file hashes and source links so another reader can inspect the same revision.

All five inventories report partial coverage. REA’s deeper JavaScript-analysis probe could not complete the environment’s process-ownership check. We did not bypass that check or claim the deeper analysis ran.

Use the reviews to prepare a small pilot

  1. Check the deployed version against the pinned commit. Defaults and integrations can change.
  2. Review file access, command execution, provider endpoints, and saved approvals separately.
  3. Use a disposable workspace and synthetic inputs, then inspect outputs and actual logs.
  4. Include model usage, hosting, retries, and review time when comparing cost. Open-source licensing does not make those costs zero.

These reviews do not establish the absence of malware or vulnerabilities. Existing recorded tests remain separate evidence with their own versions and limits.

Applying this to ecommerce work

Our sister site EcomAgentHub provides shared evaluation briefs for listing copy, support handoff, and product images. Both sites are operated by the same team. Its hosted-product comparisons are based on documentation and explicitly scoped retained outputs, not REA reverse engineering.