# CoderFriend AI complete capability reference
> Full, implementation-grounded descriptions of the capabilities available in the CoderFriend AI extension for Visual Studio Code.

This reference contains 533 capabilities across 117 feature systems. The canonical visual catalog is [https://coderfriendai.com/features/](https://coderfriendai.com/features/).

## AI workspace
27 feature systems and 127 capabilities.

### 01. Chat, Plan & Agent modes
Move from a quick answer to an implementation plan or an autonomous coding run without changing workspaces.

- [Chat for focused questions and explanations](https://coderfriendai.com/features/#capability-1-chat-for-focused-questions-and-explanations): Use Chat when you need an explanation, diagnosis, comparison, or focused answer without asking the assistant to run a multi-step implementation. It keeps the request inside the same conversation and model controls, so you can add project context, clarify the result, or move deliberately into Plan or Agent mode when the task grows.
- [Plan for structured, reviewable implementation strategy](https://coderfriendai.com/features/#capability-1-plan-for-structured-reviewable-implementation-strategy): Use Plan to turn an ambiguous change into an ordered implementation strategy before files are modified. The model can inspect the supplied context, identify dependencies and verification work, and return a plan you can challenge or refine before authorizing an Agent run.
- [Agent for multi-step coding work with tools](https://coderfriendai.com/features/#capability-1-agent-for-multi-step-coding-work-with-tools): Agent mode can inspect the repository, edit files, run approved commands, review diagnostics, and verify the resulting behavior across multiple bounded iterations. Every tool remains subject to the selected capability, approval, sandbox, cancellation, and request-budget controls rather than receiving silent unrestricted access.
- [Switch modes from the same conversation composer](https://coderfriendai.com/features/#capability-1-switch-modes-from-the-same-conversation-composer): Change between Chat, Plan, and Agent without opening another panel or abandoning the current thread. The retained provider-neutral conversation and attached project context move with the next request, while the newly selected mode determines whether the model answers, plans, or receives coding tools.

### 02. Integrated composer cockpit
Shape every request from one compact control surface instead of bouncing between settings screens.

- [Choose mode, provider, model, and speed](https://coderfriendai.com/features/#capability-2-choose-mode-provider-model-and-speed): Set the working mode, model source, exact model, and supported processing tier beside the prompt that will use them. The selectors change the next request only, so exploring another route never sends an accidental message or rewrites the conversation already on screen.
- [Set reasoning effort and response detail](https://coderfriendai.com/features/#capability-2-set-reasoning-effort-and-response-detail): Tune model reasoning effort independently from the amount of detail you want in the visible answer. CoderFriend sends only controls the selected provider and model support, preventing a decorative selector from becoming an invalid API option or a misleading promise.
- [Select context, profile, trust, and approval behavior](https://coderfriendai.com/features/#capability-2-select-context-profile-trust-and-approval-behavior): Choose how much retained context is sent, which working persona applies, what capability profile the model receives, and when actions need approval. Keeping those decisions in the composer makes the effective request policy visible at the moment authority is granted.
- [Keep advanced controls close to the prompt](https://coderfriendai.com/features/#capability-2-keep-advanced-controls-close-to-the-prompt): Advanced controls remain available in the composer instead of being buried several settings pages away from the request they affect. You can hide controls you rarely use, but their saved values continue to apply and can be restored without rebuilding the workspace.

### 03. Live progress & activity
See what the Agent is doing as it searches, reads, edits, and verifies the task.

- [Concise progress commentary during long-running work](https://coderfriendai.com/features/#capability-3-concise-progress-commentary-during-long-running-work): During a longer Agent task, the Working panel reports short findings, current actions, and the next useful step while execution continues. Updates are written for the user rather than dumping raw protocol traffic, so you can follow the work without waiting for the final response.
- [Visible tool activity and completion state](https://coderfriendai.com/features/#capability-3-visible-tool-activity-and-completion-state): Reads, searches, edits, commands, verification, and delegated work appear as bounded activity with a clear running, completed, failed, or cancelled state. Persistent status makes it possible to see whether the Agent is investigating, changing code, or proving the result instead of guessing from a spinner.
- [Clear status without exposing private reasoning](https://coderfriendai.com/features/#capability-3-clear-status-without-exposing-private-reasoning): CoderFriend shows observable actions and concise provider-authored progress, but it does not publish hidden chain-of-thought as if it were an audit log. This preserves useful transparency—the files inspected, tools used, checks run, and outcomes found—without exposing private internal reasoning.

### 04. Queue, steer, delete & stop
Stay in control while an Agent run is active, even when your priorities change mid-task.

- [Queue follow-up instructions while work continues](https://coderfriendai.com/features/#capability-4-queue-follow-up-instructions-while-work-continues): Enter during an active sidebar Agent run adds a follow-up to a visible queue. After successful completion, waiting items can start in order as new accountable turns. Cancellation, errors, and safety limits keep them queued for an explicit Send instead of automatically starting more model work.
- [Steer the active run with new direction](https://coderfriendai.com/features/#capability-4-steer-the-active-run-with-new-direction): Steer applies a waiting instruction to the current Agent request at a safe boundary. A superseded model response is discarded before its unstarted tools execute; an active tool or approval finishes before the next instruction is consumed. The applied direction remains visible with the conversation and activity.
- [Remove queued messages before they run](https://coderfriendai.com/features/#capability-4-remove-queued-messages-before-they-run): Queued follow-ups remain visible and removable until they are submitted, so a stale idea does not become a paid model request merely because it was typed early. Deleting one affects only that waiting item and does not discard the active work or the rest of the queue.
- [Stop an active request immediately](https://coderfriendai.com/features/#capability-4-stop-an-active-request-immediately): Stop requests cancellation across the model call, tool execution, managed commands, runtime browser, SSH leases, and other request-owned work. The control stays in a stopping state until cleanup completes, preventing a visually finished request from leaving hidden child processes behind.

### 05. Inline Chat
Ask for a targeted change directly beside the code and review the proposed result in place.

- [Start from a selected editor range](https://coderfriendai.com/features/#capability-5-start-from-a-selected-editor-range): Open Inline Chat from a highlighted range to make the selected code and surrounding file context the deliberate target of the request. This keeps a focused repair or transformation close to the source instead of requiring you to paste code into a detached conversation.
- [Preview the proposed replacement inline](https://coderfriendai.com/features/#capability-5-preview-the-proposed-replacement-inline): The model’s suggested replacement is shown against the selected range before it becomes the file’s accepted content. You can inspect the exact proposed change in editor context, including the code immediately around it, rather than trusting a prose summary.
- [Accept or reject before changing the file](https://coderfriendai.com/features/#capability-5-accept-or-reject-before-changing-the-file): Inline Chat leaves the final mutation behind an explicit accept or reject decision. Accept applies the reviewed replacement to the editor, while reject dismisses it without forcing you to reconstruct the original selection or undo an unwanted speculative change.

### 06. Inline completion
Complete code with both sides of the cursor, recent edits, repository guidance, and bounded editor context.

- [Editor-native ghost-text suggestions](https://coderfriendai.com/features/#capability-6-editor-native-ghost-text-suggestions): Inline completion presents a context-aware suggestion as native ghost text at the cursor instead of opening a separate response panel. You can read it in the flow of the file, accept it with the normal editor gesture, or keep typing to replace it.
- [Suggestions grounded in nearby code](https://coderfriendai.com/features/#capability-6-suggestions-grounded-in-nearby-code): Inline completion reads bounded code before and after the cursor together with available imports, recent edits, diagnostics, open-file context, document symbols, and repository instructions. The completion model remains a separate selection for each provider, and unsupported prompt formats fall back to an explicit cursor-context request.
- [Accept completions without leaving the editor](https://coderfriendai.com/features/#capability-6-accept-completions-without-leaving-the-editor): A useful suggestion can be accepted directly into the current document, while ignored suggestions disappear as ordinary editor state. Backoff protection limits repeated provider calls when a route is failing or the user is typing quickly, keeping the feature responsive rather than noisy.
- [Read code before and after the cursor](https://coderfriendai.com/features/#capability-6-read-code-before-and-after-the-cursor): Completion uses a bounded prefix and suffix so suggestions fit into the surrounding implementation. Models with a supported fill-in-the-middle format receive that format; other routes receive an explicit cursor context.
- [Include recent edits, imports, diagnostics, and open-file context](https://coderfriendai.com/features/#capability-6-include-recent-edits-imports-diagnostics-and-open-file-context): The completion provider gathers bounded recent edits, imported names, visible file context, current diagnostics, document symbols, and repository instructions when available. These inputs help suggestions follow the work already happening in the editor.
- [Keep suggestions responsive and discard stale results](https://coderfriendai.com/features/#capability-6-keep-suggestions-responsive-and-discard-stale-results): Adaptive debounce, local caching, request deduplication, and document-version checks reduce redundant requests and reject results made obsolete by new typing. Failure backoff protects a provider that is repeatedly unavailable.

### 07. One-click editor actions
Turn common code tasks into focused prompts from the lightbulb or editor context menu.

- [Fix selected code](https://coderfriendai.com/features/#capability-7-fix-selected-code): Run Fix from the lightbulb, context menu, command palette, or slash palette to ask for a focused correction around the active selection. The action carries the selected source and file context into CoderFriend so the result can address the concrete defect instead of guessing which code you meant.
- [Explain unfamiliar code](https://coderfriendai.com/features/#capability-7-explain-unfamiliar-code): Run Explain on a selection to receive a contextual walkthrough of what the code does, how its pieces interact, and where important assumptions live. The explanation stays connected to the actual editor range, making follow-up questions easier than moving a copied snippet into a separate tool.
- [Generate tests](https://coderfriendai.com/features/#capability-7-generate-tests): Run Test to ask for behavior-focused tests around the selected implementation and its visible dependencies. The generated request identifies the source range and current file, giving the model a concrete unit under test while leaving final application and verification under your control.
- [Refactor an implementation](https://coderfriendai.com/features/#capability-7-refactor-an-implementation): Run Refactor when the selected code should become clearer or easier to maintain without intentionally changing its behavior. CoderFriend grounds the request in the highlighted implementation so proposed structure, naming, and duplication changes remain reviewable rather than becoming a repository-wide rewrite by surprise.
- [Write documentation](https://coderfriendai.com/features/#capability-7-write-documentation): Run Doc to generate documentation for the selected function, class, module, or block in the language and style of the surrounding file. The action starts from real source context, so the result can describe parameters, behavior, and constraints instead of producing generic boilerplate.

### 08. Actionable code blocks
Use generated code immediately from the conversation instead of manually moving it between surfaces.

- [Copy a complete code block](https://coderfriendai.com/features/#capability-8-copy-a-complete-code-block): Every rendered code block offers a direct copy action that preserves the complete block rather than requiring a fragile drag selection. This is useful when the answer belongs in another file, review, terminal, or external discussion and should move without markdown fences or missing lines.
- [Send commands to the integrated terminal](https://coderfriendai.com/features/#capability-8-send-commands-to-the-integrated-terminal): A shell-shaped code block can be inserted into VS Code’s integrated terminal so you can inspect and run it in your own terminal context. CoderFriend does not present insertion as successful execution; the terminal remains visible and the command remains under your control.
- [Apply eligible changes to the workspace](https://coderfriendai.com/features/#capability-8-apply-eligible-changes-to-the-workspace): Eligible generated code can be applied to the active editor through the code-block action instead of copied by hand. The action is limited to content CoderFriend can map safely to an editor target, and the resulting file remains available for normal diff review and undo.

### 09. Native VS Code entry points
Reach CoderFriend from the sidebar, command palette, slash menu, or VS Code Chat.

- [Dedicated activity-bar and secondary-sidebar experience](https://coderfriendai.com/features/#capability-9-dedicated-activity-bar-and-secondary-sidebar-experience): Open CoderFriend from its Activity Bar container or move the chat view into VS Code’s Secondary Side Bar when you want Explorer and AI visible together. The preserve setting leaves the primary sidebar untouched by default, while explicit left or right choices remain available.
- [Discoverable slash-command menu](https://coderfriendai.com/features/#capability-9-discoverable-slash-command-menu): Type a forward slash in the composer to open a filterable menu of supported actions instead of memorizing command names. Choosing a row inserts or runs the appropriate request, and each item remains reachable from the same keyboard-first surface.
- [Native @coderfriend chat participant](https://coderfriendai.com/features/#capability-9-native-coderfriend-chat-participant): Use @coderfriend inside VS Code’s native Chat view when that surface fits the rest of your editor workflow. Requests still pass through CoderFriend’s provider selection, accounting, context, and guarded Agent infrastructure rather than becoming a separate untracked integration.
- [Commands for chat, plan, Agent, explain, fix, tests, and review](https://coderfriendai.com/features/#capability-9-commands-for-chat-plan-agent-explain-fix-tests-and-review): Open the major CoderFriend workflows from VS Code’s Command Palette even when the sidebar composer is not focused. These commands provide predictable editor-native entry points for questions, planning, implementation, code actions, and high-signal review across keyboard and menu workflows.

### 10. A workspace that fits you
Tune the density and typography of the interface without giving up access to advanced controls.

- [Choose which composer controls stay visible](https://coderfriendai.com/features/#capability-10-choose-which-composer-controls-stay-visible): Toggle usage, context, mode, model, speed, reasoning, compaction, detail, profile, trust, provider, approval, and steering hints independently. Hiding a control only reduces visual density; its saved value still governs requests and the essential input, Send, and Stop controls remain available.
- [Separate typography for conversation and activity](https://coderfriendai.com/features/#capability-10-separate-typography-for-conversation-and-activity): Set independent font families and sizes for message content and the Working activity stream. This lets you enlarge the text you read most often without inflating status rows, controls, code, or every surrounding interface element at the same time.
- [Independent composer and code typography](https://coderfriendai.com/features/#capability-10-independent-composer-and-code-typography): Configure the prompt composer separately from code blocks, inline code, diffs, commands, and raw tool output. Each surface can follow the VS Code interface or editor font by default, or use a deliberate stack and size that improves readability for your setup.
- [Searchable Settings Center](https://coderfriendai.com/features/#capability-10-searchable-settings-center): Browse General, User Interface, Models and Providers, Context and Knowledge, Agent and Safety, Profiles and Guardrails, and Advanced settings in one searchable editor. Results take you to the real manifest-backed control, so changing a friendly setting updates the same configuration used by requests.

### 11. 25-command slash palette
Control coding actions, modes, models, safety, history, usage, skills, and MCP from a discoverable keyboard-first menu.

- [Explain selected code with /explain](https://coderfriendai.com/features/#capability-11-explain-selected-code-with-explain): Type /explain to turn the current selection and nearby file context into a focused explanation request. It is the keyboard-first equivalent of the editor action, useful when your attention is already in the composer and you want to ask follow-up questions in the same thread.
- [Repair selected code with /fix](https://coderfriendai.com/features/#capability-11-repair-selected-code-with-fix): Type /fix to request a concrete correction for the selected source while keeping the affected file and range explicit. The command starts the repair conversation but does not bypass normal review, write, approval, or sandbox controls when implementation work follows.
- [Generate focused tests with /test](https://coderfriendai.com/features/#capability-11-generate-focused-tests-with-test): Type /test to ask for tests around the active selection or file context without drafting a long prompt from scratch. The generated request focuses on observable behavior and gives you a clear starting point for reviewing, applying, and running the proposed coverage.
- [Refactor an implementation with /refactor](https://coderfriendai.com/features/#capability-11-refactor-an-implementation-with-refactor): Type /refactor to ask for a behavior-preserving improvement around the code currently in focus. Because the command carries editor context, the model can discuss or implement a specific restructuring instead of returning broad refactoring advice detached from the repository.
- [Write code documentation with /doc](https://coderfriendai.com/features/#capability-11-write-code-documentation-with-doc): Type /doc to produce documentation for the selected implementation using the surrounding source as evidence. The command is designed for concrete comments and reference text, while you remain free to refine the wording or ask the Agent to update related documentation files.
- [Start a high-signal review with /review](https://coderfriendai.com/features/#capability-11-start-a-high-signal-review-with-review): Type /review to open the review workflow for a selection, file, working tree, branch, or pull request. Findings must identify concrete evidence and locations, and local results can be handed to a foreground Agent or an isolated repair worktree.
- [Switch directly to Chat with /chat](https://coderfriendai.com/features/#capability-11-switch-directly-to-chat-with-chat): Type /chat to select answer-oriented Chat mode without reaching for the mode control. The next message uses the retained conversation and chosen provider but receives no autonomous coding loop, making it suitable for diagnosis, explanation, and focused decisions.
- [Switch directly to Plan with /plan](https://coderfriendai.com/features/#capability-11-switch-directly-to-plan-with-plan): Type /plan to select planning mode before the next request. The model can inspect supplied context and return an ordered strategy, risks, and verification approach, while workspace mutation waits until you deliberately move into an execution workflow.
- [Switch directly to Agent with /agent](https://coderfriendai.com/features/#capability-11-switch-directly-to-agent-with-agent): Type /agent to select the multi-step tool-using mode for the next message. The command changes the working mode but does not silently widen authority; the selected profile, approvals, sandbox, budgets, and available tool capability still define what the Agent may do.
- [Choose a model with /model](https://coderfriendai.com/features/#capability-11-choose-a-model-with-model): Type /model to open the active provider’s model picker from the keyboard. The list comes from that provider’s isolated catalog and respects favorites and aliases, so selecting a route updates the next request without mixing in models from another source.
- [Set reasoning effort with /reasoning](https://coderfriendai.com/features/#capability-11-set-reasoning-effort-with-reasoning): Type /reasoning to choose the supported reasoning effort for the current provider and model. CoderFriend remembers the provider-specific choice and omits it when a route does not support the control, avoiding an API error disguised as a preference.
- [Change processing speed with /fast](https://coderfriendai.com/features/#capability-11-change-processing-speed-with-fast): Type /fast to adjust the real processing or service tier exposed by a compatible provider. Speed remains independent from reasoning effort and visible response detail, and unsupported tiers are not sent merely because another provider offered them.
- [Inspect approval behavior with /permissions](https://coderfriendai.com/features/#capability-11-inspect-approval-behavior-with-permissions): Type /permissions to see the active approval behavior that governs file, command, MCP, browser, and live-server actions. This makes Ask, Workspace, and Always Allow semantics inspectable from the conversation instead of leaving authority implicit in a distant configuration value.
- [Inspect the command sandbox with /sandbox](https://coderfriendai.com/features/#capability-11-inspect-the-command-sandbox-with-sandbox): Type /sandbox to see whether Agent commands are running in workspace-write, read-only, or off mode. The result distinguishes OS-level command isolation from approval policy, which matters because approving an action does not automatically remove its filesystem or network boundary.
- [Review the latest checkpoint with /changes](https://coderfriendai.com/features/#capability-11-review-the-latest-checkpoint-with-changes): Type /changes to reopen the most recent Agent checkpoint and inspect its changed-file summary and bounded patch. From there you can open native before-and-after diffs, copy or reveal the raw patch, and decide whether the completed work should stay.
- [Restore the latest checkpoint with /undo](https://coderfriendai.com/features/#capability-11-restore-the-latest-checkpoint-with-undo): Type /undo to start guarded restoration of the latest Agent checkpoint. CoderFriend verifies that current files still match the checkpoint’s after-state, asks before forcing over newer work, and creates a reverse checkpoint when restoration succeeds.
- [Compact retained context with /compact](https://coderfriendai.com/features/#capability-11-compact-retained-context-with-compact): Type /compact to shrink the retained middle of a long conversation while preserving the opening task, newest work, and intact tool exchanges. The saved conversation is not rewritten merely because a smaller model-bound representation is prepared for the next request.
- [Back up conversation history with /backup](https://coderfriendai.com/features/#capability-11-back-up-conversation-history-with-backup): Type /backup to write a project backup of conversation history using readable Markdown alongside structured JSON and retained attachments. The files can be inspected or versioned like ordinary project artifacts and later selected through the restore workflow.
- [Inspect the active setup with /status](https://coderfriendai.com/features/#capability-11-inspect-the-active-setup-with-status): Type /status to summarize the active provider, model, working mode, policy, sandbox, context behavior, and connected capabilities relevant to the next request. It gives troubleshooting and handoff conversations a concrete configuration snapshot instead of relying on memory.
- [Open provider accounts with /account](https://coderfriendai.com/features/#capability-11-open-provider-accounts-with-account): Type /account to open one account-and-usage row for every configured provider. Each row can show a fetched balance where the provider exposes one, locally recorded spend for the active budget period, and direct usage or billing links when the provider remains the source of truth.
- [Refresh model prices with /priceupdate](https://coderfriendai.com/features/#capability-11-refresh-model-prices-with-priceupdate): Type /priceupdate to refresh the editable exact-model rate registry used for local cost estimates. Updating rates never fabricates missing usage or retroactively treats an unknown model as a related priced alias; uncertain requests continue to show N/A.
- [Discover and invoke skills with /skills](https://coderfriendai.com/features/#capability-11-discover-and-invoke-skills-with-skills): Type /skills to open a filterable catalog of project, user, provider, plugin, and extension skills. Selecting an entry inserts its $skill-name invocation into the composer, where it can guide any compatible selected model without changing providers.
- [Inspect connected MCP tools with /mcp](https://coderfriendai.com/features/#capability-11-inspect-connected-mcp-tools-with-mcp): Type /mcp to inspect configured Model Context Protocol servers and the tools currently available from their live connections. The view helps distinguish an unavailable server from an unsupported task before an Agent attempts an external call.
- [Start a clean thread with /new](https://coderfriendai.com/features/#capability-11-start-a-clean-thread-with-new): Type /new to begin a conversation without sending the current retained transcript to the next provider request. The previous thread remains in history according to the configured retention policy, while the new thread starts with fresh messages and usage accounting.
- [Open searchable guidance with /help](https://coderfriendai.com/features/#capability-11-open-searchable-guidance-with-help): Type /help to open the in-app operating guide beside the current workspace. Search covers setup, providers, composer controls, tools, safety, code review, runtime verification, SSH, worktrees, background Agents, subagents, and troubleshooting without requiring a browser detour.

### 12. Model Debug workspace
Inspect the bounded request and response trace when a provider, tool call, or streamed result needs a closer look.

- [Resizable model-communication pane](https://coderfriendai.com/features/#capability-12-resizable-model-communication-pane): Open the Model Debug pane beneath the conversation and drag its resizer to give protocol details as much or as little room as the investigation needs. The normal chat remains visible above it, so a transport problem can be compared with the user-facing result in the same surface.
- [Timestamped request, response, reasoning, status, and error entries](https://coderfriendai.com/features/#capability-12-timestamped-request-response-reasoning-status-and-error-entries): Each debug entry records its kind, title, time, bounded body size, and expandable content in arrival order. This separates outgoing requests, streamed chunks, reported reasoning metadata, status changes, final responses, and failures instead of flattening them into one ambiguous log.
- [Copy the complete bounded trace](https://coderfriendai.com/features/#capability-12-copy-the-complete-bounded-trace): Copy the retained debug trace when you need to paste a reproducible provider exchange into an issue or internal investigation. Entry and total-size limits prevent the convenience action from turning a pathological response into an unbounded clipboard or conversation-history payload.
- [Export structured JSON or readable text logs](https://coderfriendai.com/features/#capability-12-export-structured-json-or-readable-text-logs): Download the current trace as structured JSON for tooling or as readable text and log formats for people. Both exports preserve event order and useful metadata, while shared redaction removes credential-shaped values before retained diagnostic content leaves the extension surface.
- [Open the current extension-host instance log](https://coderfriendai.com/features/#capability-12-open-the-current-extension-host-instance-log): Open the log file for the running extension-host instance directly in a normal VS Code editor tab after pending writes are flushed. This connects the visible model trace with lower-level operational messages without asking the user to locate a temporary log path manually.

### 13. Generated visual artifacts
Create raster assets inside the repository and open visual deliverables directly in VS Code for immediate inspection.

- [Generate raster images through the imagegen workflow](https://coderfriendai.com/features/#capability-13-generate-raster-images-through-the-imagegen-workflow): When a task needs a bitmap rather than code-native SVG or HTML, the Agent can follow the image-generation skill and invoke the imagegen CLI through optional uv support. The prompt, output path, and resulting asset remain part of the repository task instead of an unrelated external download.
- [Save generated images under a configurable repository folder](https://coderfriendai.com/features/#capability-13-save-generated-images-under-a-configurable-repository-folder): Generated raster assets default to assets/generated and can be redirected with coderfriend-ai.generatedImageDirectory. Absolute paths and traversal outside the workspace fall back safely, keeping generated deliverables inside a deliberate project-owned location that normal source control and review can see.
- [Open images, PDFs, and notebooks in their native VS Code editors](https://coderfriendai.com/features/#capability-13-open-images-pdfs-and-notebooks-in-their-native-vs-code-editors): The open_file tool asks VS Code to display a produced image, PDF, or notebook using the editor that already understands that format. It returns no hidden file content to the model and avoids starting an unnecessary web server merely to show the user a finished artifact.
- [Keep image credentials scoped to the generation command](https://coderfriendai.com/features/#capability-13-keep-image-credentials-scoped-to-the-generation-command): If the image workflow needs the stored OpenAI key, CoderFriend injects it only into the approved image-generation command that consumes it. The credential is not added to ordinary sandboxed command environments, debug output, or the model conversation simply because image generation is available.

### 14. Resumable bounded requests
Continue useful work after a deliberate safety limit without replaying completed steps or losing the accumulated task state.

- [Continue after an iteration, call, token, cost, or time ceiling](https://coderfriendai.com/features/#capability-14-continue-after-an-iteration-call-token-cost-or-time-ceiling): When a root Agent reaches a configured safety ceiling, the Working card explains which limit paused progress and offers a deliberate Continue path where appropriate. Continuing creates a fresh bounded accounting round while retaining the concrete task state and completed changes needed to proceed.
- [Preserve the completed work and working-time history between continuations](https://coderfriendai.com/features/#capability-14-preserve-the-completed-work-and-working-time-history-between-continuations): A continued task keeps the edits, checkpoint context, plan state, and active-work duration accumulated before the pause. Idle time spent waiting for the user is excluded from the Working duration, so the displayed effort reflects execution rather than how long the tab remained open.
- [Start each continuation as a separately accountable request](https://coderfriendai.com/features/#capability-14-start-each-continuation-as-a-separately-accountable-request): Every Continue action becomes its own Recent Requests row with independent provider calls, token usage, cost status, iteration count, and duration. The broader conversation still aggregates those rounds, letting one user objective remain coherent without concealing how many paid requests it required.
- [Mark interrupted work clearly after an editor reload](https://coderfriendai.com/features/#capability-14-mark-interrupted-work-clearly-after-an-editor-reload): Durable background and conversation state can be inspected after VS Code reloads, but in-flight paid work is not silently replayed. CoderFriend marks an active request as interrupted so the user can review what completed and choose the next action without duplicate model calls or hidden process assumptions.

### 15. Searchable in-app Help
Keep the complete operating guide inside CoderFriend so setup, safety, tools, and advanced workflows are searchable while you work.

- [Search help without leaving the extension](https://coderfriendai.com/features/#capability-15-search-help-without-leaving-the-extension): The Help surface is built into CoderFriend and can be searched for the workflow, setting, command, or tool name you are using. Results stay beside the active workspace, making it practical to confirm a safety boundary or provider behavior before continuing a request.
- [Open guidance from /help and the Settings Center](https://coderfriendai.com/features/#capability-15-open-guidance-from-help-and-the-settings-center): Open the same in-app guidance from the /help command or through the Settings Center’s Help page. Multiple entry points reduce hunting while keeping one maintained source of operational truth rather than separate short tips that drift apart.
- [Cover providers, controls, tools, SSH, reviews, runtime, and delegation](https://coderfriendai.com/features/#capability-15-cover-providers-controls-tools-ssh-reviews-runtime-and-delegation): Help documents the complete path from provider authentication and composer controls through local tools, approvals, sandboxing, code review, runtime browser verification, SSH Live Server work, worktrees, background Agents, task plans, subagents, and resource budgets. Search can therefore answer both setup and advanced-operation questions.
- [Keep operational guidance available beside the active conversation](https://coderfriendai.com/features/#capability-15-keep-operational-guidance-available-beside-the-active-conversation): Because Help lives inside the extension, you can compare its documented behavior with the current conversation, settings, and activity state without losing your place. This is especially useful when a prompt, sandbox, remote capability, or budget behaves differently from an assumed default.

### 16. Smart conversation organization
Turn long-running threads into durable project records with meaningful titles, retained usage, and portable exports.

- [Create an automatic first-message title](https://coderfriendai.com/features/#capability-16-create-an-automatic-first-message-title): A new conversation receives a bounded title derived from the first meaningful user request so history becomes recognizable without manual cleanup. The title is metadata for navigation, not a rewrite of the message itself, and it remains editable at any time.
- [Review an automatic title after the conversation develops](https://coderfriendai.com/features/#capability-16-review-an-automatic-title-after-the-conversation-develops): After enough real conversation exists, the selected model can review the initial generated title against what the thread actually became. The bounded review updates only an automatic title when a clearer description is justified, avoiding endless renaming or a separate unaccounted background workflow.
- [Preserve every title the user edits manually](https://coderfriendai.com/features/#capability-16-preserve-every-title-the-user-edits-manually): Renaming a conversation marks its title as user-owned, which permanently removes that thread from automatic title review. CoderFriend treats a deliberate human label as authoritative even if later messages shift topic, so organization never changes behind the user’s back.
- [Restore saved usage totals when a conversation is reopened](https://coderfriendai.com/features/#capability-16-restore-saved-usage-totals-when-a-conversation-is-reopened): Conversation usage is persisted with the thread and restored when history is reopened or the editor reloads. Prompt, output, thinking, tool-result, cache, turn, surface, and measurable-cost totals therefore remain attached to the work that produced them instead of resetting merely because the UI was closed.

### 17. Share remote Agent updates
Copy or share the exact command, tool result, or Agent response you are viewing from a Remote Control session.

- [Copy any transcript row](https://coderfriendai.com/features/#capability-17-copy-any-transcript-row): Press and hold a remote update to copy its text without needing to select from a scrolling list.
- [Share updates through the phone system sheet](https://coderfriendai.com/features/#capability-17-share-updates-through-the-phone-system-sheet): Send a selected row to the installed sharing destinations on iPhone or Android.
- [Keep desktop sharing useful](https://coderfriendai.com/features/#capability-17-keep-desktop-sharing-useful): Copy the selected update and confirm the result when a desktop build has no mobile share sheet.

### 18. Open editors as per-request context
Choose the files already open in your editor for one request without turning them into permanent conversation context.

- [Include open editors only when useful](https://coderfriendai.com/features/#capability-18-include-open-editors-only-when-useful): Add the currently open documents to an individual request instead of sending every open tab automatically.
- [Review the exact files before sending](https://coderfriendai.com/features/#capability-18-review-the-exact-files-before-sending): Surface the selected editor context with the other request attachments so stale or sensitive tabs can be removed.
- [Keep later requests lean](https://coderfriendai.com/features/#capability-18-keep-later-requests-lean): Treat open-editor context as request-scoped evidence rather than silently carrying it into the rest of the conversation.

### 19. External conversation storage
Keep chat history in a location you choose outside the project while retaining normal conversation browsing and search.

- [Choose a dedicated conversation folder](https://coderfriendai.com/features/#capability-19-choose-a-dedicated-conversation-folder): Store chats outside the active repository when project-local history is not the right fit.
- [Create storage only when it is needed](https://coderfriendai.com/features/#capability-19-create-storage-only-when-it-is-needed): Avoid leaving an empty CoderFriend history folder behind before the first conversation is actually saved.
- [Keep repositories free of personal chat data](https://coderfriendai.com/features/#capability-19-keep-repositories-free-of-personal-chat-data): Separate reusable or private conversation history from files intended for source control.
- [Continue using normal history controls](https://coderfriendai.com/features/#capability-19-continue-using-normal-history-controls): Browse, reopen, rename, and search stored conversations through the same CoderFriend interface.

### 20. Import Claude Code and Codex chats
Bring existing Claude Code and Codex CLI conversations into CoderFriend history for continued work in the editor.

- [Discover supported local chat histories](https://coderfriendai.com/features/#capability-20-discover-supported-local-chat-histories): Find conversations written by the installed Claude Code and Codex tools without requiring a cloud export.
- [Name imports after their source](https://coderfriendai.com/features/#capability-20-name-imports-after-their-source): Label migrated conversations with the tool they came from so imported and native chats remain distinguishable.
- [Review before continuing](https://coderfriendai.com/features/#capability-20-review-before-continuing): Open imported messages in CoderFriend history and decide which context is still relevant before asking for more work.
- [Keep the original records intact](https://coderfriendai.com/features/#capability-20-keep-the-original-records-intact): Copy supported history into CoderFriend storage rather than rewriting the source tool’s own conversation files.

### 21. Built-in image viewer
Open image assets and generated visual results directly in the editor for inspection and follow-up work.

- [Inspect images without leaving VS Code](https://coderfriendai.com/features/#capability-21-inspect-images-without-leaving-vs-code): Open supported image files in the editor instead of translating visual output into an unreadable text payload.
- [Review generated visual artifacts](https://coderfriendai.com/features/#capability-21-review-generated-visual-artifacts): Display an image result at its workspace path so you can inspect what a tool produced before accepting the work.
- [Use the visible result in follow-up requests](https://coderfriendai.com/features/#capability-21-use-the-visible-result-in-follow-up-requests): Keep the image available for comparison while asking the Agent to refine the surrounding code or asset.

### 22. Agent debugger controls
Let the Agent inspect and control a VS Code debug session while keeping each debugging action explicit and reviewable.

- [Inspect the active debug state](https://coderfriendai.com/features/#capability-22-inspect-the-active-debug-state): Read threads, stack frames, scopes, and bounded variables from the paused session before choosing an action.
- [Continue, pause, step, or stop deliberately](https://coderfriendai.com/features/#capability-22-continue-pause-step-or-stop-deliberately): Use dedicated debugger operations instead of trying to drive the adapter through shell commands.
- [Evaluate a focused expression](https://coderfriendai.com/features/#capability-22-evaluate-a-focused-expression): Query the current paused frame when an exact runtime value is needed to test a diagnosis.
- [Keep debugger activity visible](https://coderfriendai.com/features/#capability-22-keep-debugger-activity-visible): Record the requested operation in the Agent run so runtime control is not hidden from review.

### 23. Draft-safe conversations
Keep the text you are composing intact while you navigate history, switch chats, or launch a follow-up action.

- [Protect an unfinished prompt while navigating](https://coderfriendai.com/features/#capability-23-protect-an-unfinished-prompt-while-navigating): Arrow keys move the caret inside a non-empty draft instead of replacing it with prompt history. History recall begins only when the composer is empty.
- [Keep drafts across conversation changes](https://coderfriendai.com/features/#capability-23-keep-drafts-across-conversation-changes): Starting a new chat leaves the current draft available so you can return to it instead of reconstructing the prompt.
- [Restore text used by follow-up actions](https://coderfriendai.com/features/#capability-23-restore-text-used-by-follow-up-actions): Retry, Continue, and Resume Agent can submit their generated line without permanently overwriting what you were already composing.
- [Remove text only through deliberate editing](https://coderfriendai.com/features/#capability-23-remove-text-only-through-deliberate-editing): Backspace, Delete, replacing a selection, sending, and running a slash command remain the explicit ways to clear composer content.

### 24. Terminal troubleshooting
Bring a captured terminal command into a focused explanation or repair workflow.

- [Capture terminal output when you enable it](https://coderfriendai.com/features/#capability-24-capture-terminal-output-when-you-enable-it): Turn on terminal capture to retain bounded command output from VS Code terminals with shell integration. Capture is off by default, applies redaction, and clears its retained records when disabled.
- [Ask about the last captured command](https://coderfriendai.com/features/#capability-24-ask-about-the-last-captured-command): Open an explanation request with the command, working directory, available exit code, and retained output together. This keeps the question attached to the actual terminal operation instead of an isolated error sentence.
- [Start a repair from a captured failure](https://coderfriendai.com/features/#capability-24-start-a-repair-from-a-captured-failure): Fix Terminal Failure opens a repair request for the latest captured command with a reported nonzero exit code. It requires terminal capture and shell integration; when no failure was captured, the command explains what is missing.

### 25. Paused debugger explanations
Carry an actual paused stack and bounded variables into an explanation request.

- [Inspect a paused debug session](https://coderfriendai.com/features/#capability-25-inspect-a-paused-debug-session): Explain Paused Debug Session reads the active debug adapter’s threads, stack frames, scopes, and top-frame variables. A running session without a paused stack is reported explicitly.
- [Keep debugging inspection read-only](https://coderfriendai.com/features/#capability-25-keep-debugging-inspection-read-only): The snapshot workflow does not step, resume, evaluate expressions, or change the debugged program. It prepares context for a repair explanation while the developer keeps control of the debugger.
- [Bound and redact captured variables](https://coderfriendai.com/features/#capability-25-bound-and-redact-captured-variables): The snapshot limits frames, variables, and value length, skips expensive scopes, and withholds credential-shaped variable names. The resulting request includes useful failure context without deliberately collecting the whole process state.

### 26. Jupyter notebook cells
Read and edit notebooks as cells while keeping changes reviewable.

- [Read numbered code and Markdown cells](https://coderfriendai.com/features/#capability-26-read-numbered-code-and-markdown-cells): The notebook tool presents .ipynb files as numbered cells with bounded source and text outputs. Non-text outputs are identified rather than embedded as large payloads.
- [Replace, insert, or delete a selected cell](https://coderfriendai.com/features/#capability-26-replace-insert-or-delete-a-selected-cell): Agent notebook edits target an explicit cell index and operation, preserving the surrounding document and metadata. The normal file-write policy and path checks still apply.
- [Clear outdated results when code changes](https://coderfriendai.com/features/#capability-26-clear-outdated-results-when-code-changes): Replacing a code cell clears its stored outputs and execution count so old results are not presented as proof of the new source. Editing a cell does not execute the notebook kernel.
- [Review and restore notebook changes](https://coderfriendai.com/features/#capability-26-review-and-restore-notebook-changes): Notebook mutations use the same change session and checkpoint path as other Agent edits. Open the result in VS Code’s notebook editor and inspect or restore the changed file through the usual review workflow.

### 27. Follow a run from your phone
Watch a Trusted Agent run on iPhone or Android, steer it, stop it, or start one, with the content encrypted end to end.

- [Watch the run as it happens](https://coderfriendai.com/features/#capability-27-watch-the-run-as-it-happens): The phone shows the same run the sidebar does: what the model is doing now, each tool call with the command it actually ran, and the assistant’s own text. Connecting shows the session as it already stands, including the last completed run, rather than an empty screen that waits for the next event.
- [Steer, stop, or start work](https://coderfriendai.com/features/#capability-27-steer-stop-or-start-work): Type to steer a run in progress, or to start one when nothing is running, through the same path the sidebar composer uses. Stopping asks first, because a run stopped from a phone cannot be resumed from one.
- [Trusted Agent only, and no approvals on the phone](https://coderfriendai.com/features/#capability-27-trusted-agent-only-and-no-approvals-on-the-phone): Remote control is refused for any approval mode that can pause and ask, because there is no way to answer an approval from a phone: judging a command means reading it beside the workspace it will change. The setting is off until you turn it on.
- [Pair once, then reconnect until you revoke it](https://coderfriendai.com/features/#capability-27-pair-once-then-reconnect-until-you-revoke-it): Pair a phone with a desktop by reading an eight-character code off the sidebar, comparing a fingerprint at both ends, and confirming. After that it reconnects on its own with nothing to type. The paired-phones list shows what is trusted and revoking is the only way a pairing ends.
- [Pick which editor window to watch](https://coderfriendai.com/features/#capability-27-pick-which-editor-window-to-watch): Every window with remote control on offers itself by its project name, so a phone lists the work you have open and you choose. A window turns remote control on for itself when it opens, and the composer shows a Remote Control switch for turning it off and on.
- [Encrypted so the relay cannot read it](https://coderfriendai.com/features/#capability-27-encrypted-so-the-relay-cannot-read-it): The two ends agree keys directly through a key exchange the relay only forwards, so the service that carries the traffic holds nothing that can decrypt it. Identity keys authenticate the pair and never derive session keys, so a phone lost later cannot decrypt anything recorded before.

## Living context
18 feature systems and 75 capabilities.

### 28. Files, folders & image context
Give a request the exact source material it needs, from one selection to an entire project area.

- [Attach individual files and folders](https://coderfriendai.com/features/#capability-28-attach-individual-files-and-folders): Use the composer’s context picker to attach one file or a bounded folder tree before sending a request. CoderFriend shows the selected material as removable context chips, so you can verify what will accompany the prompt instead of relying on an invisible workspace sweep.
- [Include the active selection and open editor](https://coderfriendai.com/features/#capability-28-include-the-active-selection-and-open-editor): Bring the highlighted range and active document into a request when the task starts from code already on screen. File identity, language, and nearby source keep the question grounded, while the explicit selection prevents a focused request from automatically expanding to the whole repository.
- [Attach up to five images to a request](https://coderfriendai.com/features/#capability-28-attach-up-to-five-images-to-a-request): Paste, drag, or choose as many as five images for a model route that supports vision input. Preview thumbnails remain visible before submission and can be removed individually, making screenshots, mockups, errors, and visual references deliberate parts of the request.
- [Review attached context before sending](https://coderfriendai.com/features/#capability-28-review-attached-context-before-sending): Every selected file, folder, image, and context attachment is surfaced in the composer before the provider call begins. You can discard stale or sensitive material there, reducing accidental disclosure and helping the model receive the smallest useful evidence set.

### 29. Ranked local codebase search
Find relevant project code locally with bounded retrieval designed for useful signal, not indiscriminate context.

- [Local BM25-ranked repository retrieval](https://coderfriendai.com/features/#capability-29-local-bm25-ranked-repository-retrieval): CoderFriend builds a local text index and uses BM25 ranking to find files and snippets relevant to a conceptual query. The search_codebase tool and automatic-context flow use that index without sending a vector database or repository copy to a hosted retrieval service.
- [Bounded results that respect context limits](https://coderfriendai.com/features/#capability-29-bounded-results-that-respect-context-limits): Repository retrieval limits the number and size of snippets returned, then fits them within the active context budget before provider submission. A broad query therefore yields ranked evidence instead of an unlimited dump that crowds out the task, recent conversation, or instructions.
- [Relevant snippets pulled from across the workspace](https://coderfriendai.com/features/#capability-29-relevant-snippets-pulled-from-across-the-workspace): A question can discover matching implementation, configuration, tests, and documentation beyond the open tab, including multi-root workspaces. Results retain file paths and useful source windows so the model can follow evidence into exact reads rather than treating search text as anonymous fragments.
- [No external vector database required](https://coderfriendai.com/features/#capability-29-no-external-vector-database-required): Index construction, scoring, exclusions, and cached retrieval state remain on the extension host. This removes a separate embedding account and remote index from the normal workflow while still giving the Agent a conceptual search capability over the active project.

### 30. Repository instructions
Carry project conventions into every answer with instruction files discovered from the repository tree.

- [AGENTS.md and nested repository rules](https://coderfriendai.com/features/#capability-30-agents-md-and-nested-repository-rules): CoderFriend discovers AGENTS.md guidance at the workspace root and in deeper folders, then applies the closest relevant rules to files an Agent reads or changes. Nested instructions can narrow broad repository guidance, so a frontend, package, or deployment area keeps its own conventions.
- [Claude and Gemini instruction files](https://coderfriendai.com/features/#capability-30-claude-and-gemini-instruction-files): Existing CLAUDE.md and GEMINI.md project or user instructions can guide any selected model route, not only their namesake provider. This lets teams reuse established repository knowledge while switching between local models, APIs, ChatGPT-authenticated Codex, or Claude subscription transport.
- [GitHub Copilot and Cursor rules](https://coderfriendai.com/features/#capability-30-github-copilot-and-cursor-rules): CoderFriend reads supported .github/copilot-instructions.md, matching .github/instructions files, and .cursor/rules entries as repository guidance. Their location and matching scope are respected so an instruction written for one technology or subtree does not silently become a universal rule.
- [Closest applicable instructions win by location](https://coderfriendai.com/features/#capability-30-closest-applicable-instructions-win-by-location): Instruction resolution follows the target path and combines broad guidance with the nearest deeper rules that apply. Agent tools also discover new nested instructions when work moves into another folder, preventing an early root-only snapshot from overriding local project conventions.
- [Apply user-level coding instructions](https://coderfriendai.com/features/#capability-30-apply-user-level-coding-instructions): User-level Claude, Codex, and Gemini instruction files can join applicable repository rules. More specific project guidance remains visible in the instruction context used for the request.

### 31. Portable skills
Reuse durable workflows and domain guidance through SKILL.md registries that travel with your setup.

- [Discover project and user-level skills](https://coderfriendai.com/features/#capability-31-discover-project-and-user-level-skills): The skills catalog scans supported project and user registries and presents them in a filterable list with their source. Project workflows can travel with the repository, while personal skills remain available across workspaces without being copied into every codebase.
- [Load task-specific instructions only when needed](https://coderfriendai.com/features/#capability-31-load-task-specific-instructions-only-when-needed): Invoking a $skill-name loads its complete SKILL.md workflow for that request rather than adding every installed skill to every prompt. This keeps routine context smaller while still making specialized procedures, references, scripts, and templates available for the task that needs them.
- [Share compatible skills across providers and plugins](https://coderfriendai.com/features/#capability-31-share-compatible-skills-across-providers-and-plugins): Portable .agents skills, Codex skills, Claude skills, Gemini skills, and compatible plugin or extension registries can appear in one catalog. Once selected, the workflow guides the active model provider through CoderFriend’s normal tool and policy layer instead of locking expertise to one transport.

### 32. Current web search
Bring current public information into a request when repository context alone is not enough.

- [Invoke current search with @web](https://coderfriendai.com/features/#capability-32-invoke-current-search-with-web): Put @web and a query on its own composer line to retrieve current public information before the model answers. The resulting sources are attached as bounded context for that request, making time-sensitive facts explicit rather than allowing a model to imply it searched when it did not.
- [Review source-backed results in the conversation](https://coderfriendai.com/features/#capability-32-review-source-backed-results-in-the-conversation): Web results retain titles, links, and readable snippets so the answer can distinguish fetched evidence from model memory. You can open the cited pages, refine the query, or remove the mention before sending when the retrieved sources do not match the intended question.
- [Combine fresh web context with local code](https://coderfriendai.com/features/#capability-32-combine-fresh-web-context-with-local-code): A request can use current public sources alongside selected files, repository search, documentation, and conversation history. This is useful for changing APIs, release notes, standards, and dependency behavior where the repository shows what you use and the web shows what changed.

### 33. Local documentation library
Index the documentation you trust and call it into a coding conversation with @docs.

- [Search local indexed documentation with @docs](https://coderfriendai.com/features/#capability-33-search-local-indexed-documentation-with-docs): Use @docs with a question, or a site prefix and question, to retrieve matching passages from the local documentation library. The model receives bounded source text and origin details, allowing an answer to rely on the documentation you indexed instead of an unrelated generic web result.
- [Crawl documentation sites into the library](https://coderfriendai.com/features/#capability-33-crawl-documentation-sites-into-the-library): Add an approved documentation site and let CoderFriend follow same-site pages within configured page and depth ceilings. Fetched text is normalized into a local index for later searches, avoiding a fresh network crawl every time the same API question returns.
- [Keep docs close to the codebase workflow](https://coderfriendai.com/features/#capability-33-keep-docs-close-to-the-codebase-workflow): Documentation search lives in the same composer and Agent tool registry as files and codebase retrieval. The assistant can compare an official contract with the actual implementation, then follow normal editing and verification controls without moving the task into a separate research application.
- [Use documentation context alongside files and search](https://coderfriendai.com/features/#capability-33-use-documentation-context-alongside-files-and-search): @docs results can be combined with explicit files, selected source, automatic repository snippets, and current @web evidence in one request. Separate context budgets and source labels keep those materials useful without blurring local implementation, cached documentation, and live public information.

### 34. MCP servers & tools
Connect approved external tools and data sources through Model Context Protocol servers.

- [Configure multiple MCP servers](https://coderfriendai.com/features/#capability-34-configure-multiple-mcp-servers): Declare more than one Model Context Protocol server with its name, command, arguments, and deliberately supplied environment in CoderFriend settings. Connections are initialized and disposed independently, so one unavailable integration does not need to redefine the built-in workspace tool system.
- [Discover available server tools](https://coderfriendai.com/features/#capability-34-discover-available-server-tools): After an MCP server connects, CoderFriend reads its advertised tool definitions and converts them into the same provider-neutral shape used by built-in Agent tools. The /mcp view exposes what is actually connected, helping users confirm names and availability before asking for external work.
- [Use MCP capabilities during Agent work](https://coderfriendai.com/features/#capability-34-use-mcp-capabilities-during-agent-work): An Agent can call a connected MCP tool when the selected policy allows external tool use and the request needs it. Calls retain timeout, cancellation, approval, result-history, and error handling instead of becoming an invisible side channel around the normal request lifecycle.
- [Combine external data with workspace context](https://coderfriendai.com/features/#capability-34-combine-external-data-with-workspace-context): MCP results can inform the same task that is reading source files, following repository instructions, editing code, and running verification. This lets an external system supply relevant records or actions while CoderFriend keeps the local repository and approval boundary explicit.

### 35. Adaptive context compaction
Keep long conversations useful by preserving what matters as the context window fills.

- [Auto, Shrink, and Full bookend compaction modes](https://coderfriendai.com/features/#capability-35-auto-shrink-and-full-bookend-compaction-modes): Choose Auto to compact only after a threshold, Shrink to compact proactively, or Full to send all retained context that fits the provider route. The selector changes the model-bound representation for the next request without deleting the saved conversation users can reopen later.
- [Summarized history that preserves task direction](https://coderfriendai.com/features/#capability-35-summarized-history-that-preserves-task-direction): When compaction is needed, CoderFriend keeps the opening task and newest work while replacing the long middle with a bounded summary. Important decisions, constraints, completed actions, and unresolved work remain available, preventing the latest turn from losing why the task began.
- [Context-aware image memory lifecycle](https://coderfriendai.com/features/#capability-35-context-aware-image-memory-lifecycle): Recent screenshots and image attachments remain available while they are useful, but middle images can be released when long conversations are compacted. Their relevant findings can remain in the summary without repeatedly paying to resend the same large visual payload across many Agent iterations.
- [Continue work after provider context limits](https://coderfriendai.com/features/#capability-35-continue-work-after-provider-context-limits): Compaction gives a long-running conversation a smaller coherent history when the selected provider cannot accept every retained message. If a provider still rejects the context, the failure remains visible and the user can shrink further, change routes, or start a clean thread deliberately.

### 36. Conversation history
Treat conversations as durable project work instead of disposable chat tabs.

- [Browse and reopen previous conversations](https://coderfriendai.com/features/#capability-36-browse-and-reopen-previous-conversations): Conversation History lists retained threads with titles and timestamps and lets you reopen one as the active workspace discussion. Its saved messages, debug trace, attachments, and usage state return together, so reviewing old work is more than loading a transcript excerpt.
- [Rename and organize threads](https://coderfriendai.com/features/#capability-36-rename-and-organize-threads): Give a conversation a deliberate name when its automatic title no longer describes the work or when a project naming convention matters. A manual rename becomes authoritative and is not later overwritten by automatic title generation or review.
- [Import and export conversation data](https://coderfriendai.com/features/#capability-36-import-and-export-conversation-data): Export the active thread or all retained conversations into a portable structured format, and import compatible data back into CoderFriend. This supports troubleshooting, migration, and controlled archival without requiring access to a proprietary remote conversation account.
- [Delete individual threads or clear history](https://coderfriendai.com/features/#capability-36-delete-individual-threads-or-clear-history): Remove the current conversation, select a specific historical thread, or clear all retained history through explicit commands and confirmation where appropriate. Deletion is separate from starting a new conversation, so opening a clean thread does not silently erase the project record.

### 37. Project backup & restore
Package important conversations with their supporting material so work can be archived or moved safely.

- [Back up conversations as Markdown and JSON](https://coderfriendai.com/features/#capability-37-back-up-conversations-as-markdown-and-json): Project backup writes human-readable Markdown alongside structured JSON so a conversation can be reviewed in ordinary tools and reconstructed by CoderFriend. The two formats serve different needs without forcing an opaque database export into the repository.
- [Include conversation attachments](https://coderfriendai.com/features/#capability-37-include-conversation-attachments): A backup can carry the attachment records and supporting material associated with the selected conversations, preserving more than visible message text. Bounded project-relative storage keeps the archive inspectable and avoids turning remote provider state into an unreviewable dependency.
- [Restore a saved conversation project](https://coderfriendai.com/features/#capability-37-restore-a-saved-conversation-project): Choose a compatible project backup and restore its retained conversation records through the dedicated command. The workflow validates the archive and reports the result, letting a moved or recovered workspace regain useful discussion history without manually recreating each thread.
- [Keep a human-readable archive alongside structured data](https://coderfriendai.com/features/#capability-37-keep-a-human-readable-archive-alongside-structured-data): Markdown gives maintainers a durable narrative they can search, diff, and review, while JSON preserves fields needed for machine restoration. Keeping both makes the backup useful to people, repository search, and future tools instead of optimizing only for one importer.
- [Schedule optional conversation backups](https://coderfriendai.com/features/#capability-37-schedule-optional-conversation-backups): Choose manual or automatic workspace backups, a destination directory, and an interval. Backups retain readable Markdown alongside structured history and attachments so an archive remains inspectable outside the extension.

### 38. Automatic codebase context
Supply relevant repository snippets automatically when a request needs more than the open editor, without uploading an external vector index.

- [Detect when a request would benefit from broader repository context](https://coderfriendai.com/features/#capability-38-detect-when-a-request-would-benefit-from-broader-repository-context): When automaticCodebaseContext is enabled, CoderFriend evaluates whether the user’s question depends on code beyond the explicit selection or active file. Straightforward conversational requests remain small, while repository-oriented questions can receive ranked project evidence without requiring a manual @ mention.
- [Rank local snippets against the active question](https://coderfriendai.com/features/#capability-38-rank-local-snippets-against-the-active-question): The automatic-context path searches the local BM25 index using the actual request and returns the strongest matching source windows. Paths and snippets remain linked, giving the model enough evidence to request exact files or symbols when deeper inspection is necessary.
- [Respect a dedicated automatic-context token budget](https://coderfriendai.com/features/#capability-38-respect-a-dedicated-automatic-context-token-budget): coderfriend-ai.automaticCodebaseContextTokenBudget caps how much retrieved repository text can join one request. The budget protects the user’s task, instructions, and recent conversation from being displaced by search results while still allowing a larger allowance for complex codebase questions.
- [Honor workspace index exclusions during retrieval](https://coderfriendai.com/features/#capability-38-honor-workspace-index-exclusions-during-retrieval): Configured workspaceIndexExcludePatterns remove generated, vendor, private, or otherwise irrelevant paths from indexing and search. Built-in secret screening remains independent, so widening a normal exclusion pattern does not make likely credentials eligible for automatic retrieval.
- [Rebuild the local index on demand](https://coderfriendai.com/features/#capability-38-rebuild-the-local-index-on-demand): Run Rebuild Local Codebase Index when generated content, large branch changes, or updated exclusions make the cached search state stale. Rebuilding happens on the extension host and replaces the local retrieval index without uploading repository content to a separate service.

### 39. Skill authoring & cross-provider invocation
Use one task-specific skill system across model providers while preserving each ecosystem’s existing project and user registries.

- [Search skills by typing $ in the composer](https://coderfriendai.com/features/#capability-39-search-skills-by-typing-in-the-composer): Type a dollar sign to open a compact skill picker filtered as you continue typing. Rows identify the skill and its registry source, helping you choose a project workflow, personal workflow, or imported provider skill before inserting the invocation into the prompt.
- [Invoke a selected skill with any compatible provider](https://coderfriendai.com/features/#capability-39-invoke-a-selected-skill-with-any-compatible-provider): A $skill-name invocation loads the selected skill instructions before the request is sent to the currently chosen model route. The workflow is not permanently bound to the provider that originally created it, so teams can compare models without duplicating their operating procedure.
- [Read portable .agents skills alongside Codex, Claude, and Gemini registries](https://coderfriendai.com/features/#capability-39-read-portable-agents-skills-alongside-codex-claude-and-gemini-registries): CoderFriend scans the shared .agents/skills convention together with .codex/skills, .claude/skills, and .gemini/skills at supported project and user locations. Portable project entries take precedence on name collisions, keeping repository-owned guidance predictable across different model ecosystems.
- [Import skills exposed by installed provider plugins and extensions](https://coderfriendai.com/features/#capability-39-import-skills-exposed-by-installed-provider-plugins-and-extensions): Compatible Codex and Claude plugin skills and Gemini extension skills can join the same discoverable catalog when their local registries are installed. Source labels preserve provenance, so an imported workflow does not masquerade as a repository-authored skill.
- [Read administrator-shared skill directories](https://coderfriendai.com/features/#capability-39-read-administrator-shared-skill-directories): Organization settings can add absolute shared skill directories to the existing skill registry. Shared skills remain bounded, discoverable workflows that users can inspect and invoke alongside their own skills.
- [Create or update reusable SKILL.md workflows](https://coderfriendai.com/features/#capability-39-create-or-update-reusable-skill-md-workflows): A skill-authoring task can create or refine a SKILL.md package with scoped instructions, references, scripts, and reusable assets. Storing the result in a supported registry turns one successful process into a repeatable workflow that future requests can invoke explicitly.

### 40. Safe public page fetching
Retrieve the readable content behind an explicit public URL with bounded redirects, output limits, and credential-aware safeguards.

- [Fetch an explicit HTTP or HTTPS page during Agent work](https://coderfriendai.com/features/#capability-40-fetch-an-explicit-http-or-https-page-during-agent-work): The fetch_web_page tool retrieves a public page only when the request supplies an explicit HTTP or HTTPS URL and web capability is enabled. It complements search by reading a chosen source in more depth while remaining subject to approval, cancellation, timeout, and output bounds.
- [Follow the final safe redirect instead of losing the requested source](https://coderfriendai.com/features/#capability-40-follow-the-final-safe-redirect-instead-of-losing-the-requested-source): Documentation and public pages often redirect to a canonical URL, locale, or version. CoderFriend validates each navigation step and returns the final readable destination, allowing the model to work from the page the user would actually see instead of an empty redirect response.
- [Return bounded readable text rather than an unbounded page payload](https://coderfriendai.com/features/#capability-40-return-bounded-readable-text-rather-than-an-unbounded-page-payload): Fetched HTML is converted into a bounded text observation suitable for model context rather than copied as an unlimited document with every script and asset. Source URL and useful content remain visible, while size limits protect the request from a pathological or unexpectedly large page.
- [Reject unsafe protocols and credential-bearing requests](https://coderfriendai.com/features/#capability-40-reject-unsafe-protocols-and-credential-bearing-requests): The fetch path accepts public HTTP and HTTPS destinations rather than local files or arbitrary protocols, and it does not solicit or type credentials. URLs and output pass through safety checks and redaction so web capability cannot quietly become a secret-exfiltration shortcut.

### 41. Bounded documentation crawler
Turn official documentation sites into a local, searchable reference library with explicit depth, page, and token limits.

- [Add a documentation site from the Command Palette](https://coderfriendai.com/features/#capability-41-add-a-documentation-site-from-the-command-palette): Run Add Documentation Site, provide the approved starting URL, and let CoderFriend register it as a named local source. The deliberate setup step prevents an Agent from silently crawling an unrelated site merely because a documentation answer would be convenient.
- [Limit crawl depth and maximum indexed pages](https://coderfriendai.com/features/#capability-41-limit-crawl-depth-and-maximum-indexed-pages): documentationIndexMaxDepth and documentationIndexMaxPages bound how far a source crawl can follow links and how many pages it may retain. These limits keep a small product manual from unexpectedly turning into a domain-wide scrape or an unbounded local index.
- [Keep fetched documentation in a local cache](https://coderfriendai.com/features/#capability-41-keep-fetched-documentation-in-a-local-cache): Normalized documentation pages are stored on the extension host for later @docs and docs_search requests. Reusing the local cache reduces repeated network work and gives a project a stable reference set until the user chooses to refresh or replace it.
- [Search indexed sources by site prefix and question](https://coderfriendai.com/features/#capability-41-search-indexed-sources-by-site-prefix-and-question): Prefix an @docs query with a registered source name to narrow retrieval when several libraries discuss similar concepts. CoderFriend ranks matching passages within that source and returns origin details, making version-specific or vendor-specific answers easier to verify.
- [Bound external documentation context before model submission](https://coderfriendai.com/features/#capability-41-bound-external-documentation-context-before-model-submission): externalContextTokenBudget limits the combined material added from documentation and other external references. The selected excerpts remain useful, but they cannot consume the entire provider context window or silently displace repository instructions and the user’s actual task.

### 42. Secret-aware retrieval
Search useful project context without silently sweeping credentials, private keys, or likely secret files into model-visible results.

- [Skip likely secret files during workspace search and local retrieval](https://coderfriendai.com/features/#capability-42-skip-likely-secret-files-during-workspace-search-and-local-retrieval): search_workspace, search_codebase, and local retrieval omit paths likely to contain environment secrets, credentials, private keys, or similar material even under permissive approval. This prevents broad search terms from sweeping sensitive files into model context as an incidental match.
- [Report excluded-file counts without exposing sensitive filenames](https://coderfriendai.com/features/#capability-42-report-excluded-file-counts-without-exposing-sensitive-filenames): When workspace search skips likely secrets, its result states how many files were excluded without naming those paths. The count explains why a search may be incomplete while avoiding the paradox of revealing sensitive filenames in the warning intended to protect them.
- [Redact credential-shaped values before logs and history are retained](https://coderfriendai.com/features/#capability-42-redact-credential-shaped-values-before-logs-and-history-are-retained): A shared redactor removes common credential assignments, bearer tokens, and private-key blocks before Agent logs, debug traces, or conversation history are stored. Redaction is a last safety layer rather than permission to read secrets unnecessarily, so path and approval controls still apply first.
- [Block secret access for background and subagent tools without an approval channel](https://coderfriendai.com/features/#capability-42-block-secret-access-for-background-and-subagent-tools-without-an-approval-channel): Background Agents and read-only subagents cannot pause for an interactive secret-file approval, so their file, listing, search, and semantic tools omit or reject sensitive paths. The parent can handle a deliberate user-authorized exception in the foreground instead of granting silent delegated access.

### 43. Durable conversation memory
Reopen project conversations with their messages, debug trace, attachments, title, and measured usage ready for continued work.

- [Persist provider-neutral conversation messages](https://coderfriendai.com/features/#capability-43-persist-provider-neutral-conversation-messages): Messages are retained in a provider-neutral form so the same thread can continue after switching from one supported model source to another. Provider-specific transport details stay outside the durable transcript, reducing lock-in and keeping the user-visible conversation consistent across routes.
- [Restore the debug trace with the selected conversation](https://coderfriendai.com/features/#capability-43-restore-the-debug-trace-with-the-selected-conversation): Opening a saved thread restores its bounded Model Debug entries alongside the visible messages. A provider or tool problem can therefore be investigated after navigation or reload without pretending the current extension-host log alone represents the historical request.
- [Reconnect retained attachments and project backup records](https://coderfriendai.com/features/#capability-43-reconnect-retained-attachments-and-project-backup-records): Conversation records preserve the attachment metadata and backup relationships needed to understand the original project context. Missing or moved material can be reported explicitly, while available files and exported artifacts remain connected to the thread that referenced them.
- [Resume with previously measured conversation usage visible](https://coderfriendai.com/features/#capability-43-resume-with-previously-measured-conversation-usage-visible): Reopening a saved conversation restores its accumulated token categories, turn count, request and surface breakdowns, and measurable cost status. The accounting follows the work across UI sessions, while starting or deliberately clearing a thread creates the expected fresh totals.

### 44. Approved project memory
Keep useful project facts locally and decide which remembered context remains active.

- [Save facts through an explicit memory command](https://coderfriendai.com/features/#capability-44-save-facts-through-an-explicit-memory-command): Remember for This Project saves text you deliberately enter, with its scope and provenance. Project memory is optional and redacts sensitive-looking values before retaining bounded records locally.
- [Inspect, edit, disable, or delete saved memories](https://coderfriendai.com/features/#capability-44-inspect-edit-disable-or-delete-saved-memories): Manage Project Memories provides a searchable list with edit, enable or disable, mark verified, and delete actions. A remembered fact remains visible and removable instead of becoming an invisible permanent instruction.
- [Add active memories within a context budget](https://coderfriendai.com/features/#capability-44-add-active-memories-within-a-context-budget): Enabled sidebar requests can include active applicable memories inside a bounded context allowance. The model receives them as user-approved context, while disabled, expired, or stale records are excluded.
- [Export or clear the memory collection](https://coderfriendai.com/features/#capability-44-export-or-clear-the-memory-collection): Export Project Memories writes a portable JSON record for inspection and archiving. Delete All Project Memories removes the saved collection after an explicit confirmation.

### 45. Shared tools for VS Code AI
Make CoderFriend workspace-reading tools available to compatible VS Code Language Model API callers.

- [Share file reading, directory listing, and workspace search](https://coderfriendai.com/features/#capability-45-share-file-reading-directory-listing-and-workspace-search): Compatible VS Code AI integrations can call the exported readFile, listDirectory, and searchWorkspace tools. They use CoderFriend file boundaries and bounded workspace results without selecting a separate CoderFriend model.
- [Keep exported tools read-only](https://coderfriendai.com/features/#capability-45-keep-exported-tools-read-only): The exported tool set provides reads and search; file writes and shell execution remain outside this integration. External calls have a session call ceiling and do not create provider token charges themselves.
- [Control tool availability from settings](https://coderfriendai.com/features/#capability-45-control-tool-availability-from-settings): The exportLanguageModelTools setting enables or disables registrations. Sharing requires a VS Code host with the Language Model tool API; an older host leaves these exports unavailable.

## Safe execution
37 feature systems and 175 capabilities.

### 46. Approval profiles
Choose how much authority the Agent has for each workspace and each kind of task.

- [Default approval behavior](https://coderfriendai.com/features/#capability-46-default-approval-behavior): Ask mode keeps sensitive Agent actions behind a visible approval unless an exact saved rule already authorizes them. The prompt names the requested file, command, MCP call, browser action, or remote operation so the user can approve once, remember a narrow rule, or refuse it.
- [Workspace-specific approval choices](https://coderfriendai.com/features/#capability-46-workspace-specific-approval-choices): Workspace mode automatically permits ordinary operations inside the active project boundary while continuing to ask for external paths, commands, likely secrets, and other elevated actions. This reduces routine prompts without treating the entire host or every opened repository as trusted.
- [Always Allow profile for trusted workflows](https://coderfriendai.com/features/#capability-46-always-allow-profile-for-trusted-workflows): Always Allow is literal: every Agent approval callback authorizes immediately and no approval dialog is created. Capability and sandbox rules remain separate, so a tool that was not offered or a mutation blocked by the selected sandbox must still fail visibly instead of pretending permission was granted.
- [Approval controls available from the composer](https://coderfriendai.com/features/#capability-46-approval-controls-available-from-the-composer): The active approval mode is visible and changeable beside the prompt that will use it, subject to any selected profile policy. Keeping authority in the request surface helps prevent a permissive setting chosen for one task from becoming an invisible assumption during another.

### 47. Workspace sandbox boundaries
Match execution freedom to the risk of the task with explicit filesystem and command boundaries.

- [Workspace-write sandbox](https://coderfriendai.com/features/#capability-47-workspace-write-sandbox): Workspace-write confines built-in mutations to current workspace roots and runs ordinary shell commands with host files readable but only the workspace and bounded temporary storage writable. Network access is denied inside supported command sandboxes, and provider credentials are removed from the child environment.
- [Read-only sandbox](https://coderfriendai.com/features/#capability-47-read-only-sandbox): Read-only blocks built-in file mutations and mounts workspace content without writable roots for supported sandboxed commands. It is designed for investigation, explanation, and review tasks where executing a check may be useful but changing project or host files is not acceptable.
- [Sandbox-off option for explicitly trusted work](https://coderfriendai.com/features/#capability-47-sandbox-off-option-for-explicitly-trusted-work): Turning the command sandbox off removes OS-level filesystem and network isolation and returns mutation scope to the approval and capability layers. The setting is intended for a workspace you explicitly trust or tools that cannot run in confinement, not as a hidden fallback when sandbox setup fails.

### 48. Atomic file editing
Apply focused changes with tools designed to protect surrounding code and reduce accidental rewrites.

- [Patch-based multi-file changes](https://coderfriendai.com/features/#capability-48-patch-based-multi-file-changes): apply_patch accepts bounded standard unified diffs across as many as 100 workspace files and computes every after-state before writing. If a later file fails validation or mutation, earlier writes are restored, so a multi-file patch behaves as one transaction rather than a half-applied edit.
- [Exact text replacements for surgical edits](https://coderfriendai.com/features/#capability-48-exact-text-replacements-for-surgical-edits): edit_file replaces one expected literal with a deliberate new value when the source text is unique and current. It is suited to a focused change where a full-file rewrite would risk unrelated formatting, and it fails clearly when the old text is absent or ambiguous.
- [Safer writes with conflict awareness](https://coderfriendai.com/features/#capability-48-safer-writes-with-conflict-awareness): Write tools resolve and authorize the target path, capture its first before-state, and coordinate with request-scoped locks before committing content. Stale expected text, an overlapping Agent run, a symlink boundary, or an invalid workspace path produces a visible error instead of a best-effort overwrite.
- [Clear failure when the expected source has changed](https://coderfriendai.com/features/#capability-48-clear-failure-when-the-expected-source-has-changed): Exact edits and unified patches verify their context against the file that exists at execution time. If another edit changed the relevant source, the tool reports the mismatch and lets the Agent reread or stop rather than applying the change at a guessed location.

### 49. Checkpoints, diffs & undo
Review the real workspace impact and recover from an unwanted change without guesswork.

- [Automatic task checkpoints](https://coderfriendai.com/features/#capability-49-automatic-task-checkpoints): Built-in mutations during one foreground Agent request share a change session that retains each file’s first before-state and final after-state. At completion, CoderFriend creates one bounded checkpoint outside the repository and keeps a rolling history of recent change sets for review and recovery.
- [Visual diff review before moving on](https://coderfriendai.com/features/#capability-49-visual-diff-review-before-moving-on): The checkpoint card lists changed, added, and deleted files and opens any row as native before-and-after VS Code documents in the diff editor. Review Changes spans the complete checkpoint, while a bounded raw patch can also be copied or revealed for external inspection.
- [Undo and restore support](https://coderfriendai.com/features/#capability-49-undo-and-restore-support): Restore first verifies that current content still matches the checkpoint’s recorded after-state, protecting newer manual or Agent edits from silent loss. A conflict requires explicit force confirmation, and a successful restore creates a reverse checkpoint so the undo operation itself remains recoverable.
- [Change summaries tied to the Agent run](https://coderfriendai.com/features/#capability-49-change-summaries-tied-to-the-agent-run): The compact Changes card belongs to the request that produced the mutations and summarizes its complete captured file set. That connection lets users compare the Agent’s claims, verification output, and actual diff without searching the entire working tree for unrelated pre-existing changes.

### 50. Semantic code intelligence
Use the language server to understand symbols and surface compiler-quality feedback during a task.

- [Definition and reference navigation](https://coderfriendai.com/features/#capability-50-definition-and-reference-navigation): find_definitions and find_references ask VS Code’s language services where a symbol is declared and used across the open workspace. Results retain exact files and locations, giving the Agent compiler-aware evidence that plain text search cannot provide for overloaded names, imports, and cross-file behavior.
- [Workspace symbol discovery](https://coderfriendai.com/features/#capability-50-workspace-symbol-discovery): get_workspace_symbols searches the language-service index for classes, functions, types, and other semantic symbols by name. The Agent can use the bounded result to locate an unfamiliar subsystem before opening files, reducing broad repository scans and false matches in comments or generated content.
- [Hover and signature information](https://coderfriendai.com/features/#capability-50-hover-and-signature-information): get_hover_info retrieves the type, signature, and documentation the active VS Code language provider exposes at a source location. This helps an Agent confirm API contracts and inferred types in the same environment the developer sees, rather than relying only on text surrounding the symbol.
- [Automatic diagnostics after changes](https://coderfriendai.com/features/#capability-50-automatic-diagnostics-after-changes): After relevant mutations, get_diagnostics collects bounded language-service errors and warnings from affected workspace files. New evidence can drive a repair iteration before completion, while unresolved findings remain visible so the final answer cannot quietly label a broken edit as verified.
- [Identify failing tests from command output](https://coderfriendai.com/features/#capability-50-identify-failing-tests-from-command-output): Supported Node, Jest-style, pytest, Go, PHPUnit, and Mocha output is summarized into recognizable test results before it returns to the Agent. Named failures and available locations help the next repair target the failing behavior; an unknown runner stays as command output.

### 51. High-signal code review
Review exactly the scope that matters, from a selection to a GitHub pull request.

- [Review a selection, file, tree, or branch](https://coderfriendai.com/features/#capability-51-review-a-selection-file-tree-or-branch): The review target picker can scope analysis to an editor selection, complete file, staged and unstaged working tree, or current branch against a chosen merge base. Each scope is collected deliberately, allowing a small change to avoid unrelated repository noise and a branch review to include its actual diff.
- [Review GitHub pull-request changes](https://coderfriendai.com/features/#capability-51-review-github-pull-request-changes): An authenticated GitHub CLI can provide the patch for a chosen pull request without checking out its head. Pull-request review is read-only because the reviewed source may not exist in the current worktree, and findings link back to exact paths and lines present in the supplied patch.
- [Prioritized findings with file locations](https://coderfriendai.com/features/#capability-51-prioritized-findings-with-file-locations): The review model must return structured correctness, security, race, performance, or missing-test findings with severity, confidence, concrete evidence, impact, recommendation, file, and positive line number. Malformed, duplicate, out-of-scope, or unsupported claims are removed before the result card appears.
- [Suppress findings that are not relevant](https://coderfriendai.com/features/#capability-51-suppress-findings-that-are-not-relevant): Each retained finding has a stable rule identifier that can be suppressed when it repeatedly does not apply to the project. The configured suppression list removes that rule from future review output without lowering the global evidence, category, or confidence requirements for every other finding.
- [Review an individual Git commit](https://coderfriendai.com/features/#capability-51-review-an-individual-git-commit): The review commands include a single-commit scope as well as working-tree, branch, file, and pull-request workflows. Findings remain tied to the exact reviewed change.
- [Review before generating a commit message](https://coderfriendai.com/features/#capability-51-review-before-generating-a-commit-message): Optionally run a working-tree review before CoderFriend fills the Source Control message field. Findings can be opened for inspection or explicitly overridden; this check does not create or block Git commits itself.

### 52. Review-to-repair workflow
Turn a finding into an isolated repair task and verify the fix before it reaches your main worktree.

- [Send selected findings to an Agent](https://coderfriendai.com/features/#capability-52-send-selected-findings-to-an-agent): A local review finding can become a focused foreground Agent request carrying the evidence, location, impact, and recommendation already collected. The repair still follows the current provider, policy, sandbox, budget, checkpoint, and verification flow rather than receiving special hidden write authority.
- [Repair in an isolated worktree](https://coderfriendai.com/features/#capability-52-repair-in-an-isolated-worktree): Choose isolated repair to create a managed Git worktree where a background Agent can address selected findings without modifying the primary checkout. The run produces inspectable changes and status, letting ongoing foreground work continue while the repair is evaluated separately.
- [Run an automatic follow-up review](https://coderfriendai.com/features/#capability-52-run-an-automatic-follow-up-review): Background repair workflows can invoke a bounded reviewer after implementation and repeat for the configured number of repair rounds. Reviewer findings stay evidence-based and request-accounted, preventing an endless self-review loop or an unmeasured second model workflow.
- [Inspect the resulting diff before integration](https://coderfriendai.com/features/#capability-52-inspect-the-resulting-diff-before-integration): A completed repair exposes the managed worktree’s diff and report before anything is integrated into the main checkout. Users can inspect changed files, verification evidence, remaining findings, and failure states, then choose their normal Git integration path with full context.

### 53. Runtime verification
Let the Agent prove that an interface works, not merely that the code looks plausible.

- [Launch request-owned development servers and watchers](https://coderfriendai.com/features/#capability-53-launch-request-owned-development-servers-and-watchers): start_process runs a local server, watcher, or interactive development process that remains available across later runtime tool calls in the same request. Output can be read incrementally and input can be written deliberately, while process ownership ensures finalization can stop the complete tree.
- [Use an isolated browser session](https://coderfriendai.com/features/#capability-53-use-an-isolated-browser-session): open_preview launches a fresh Chrome, Chromium, or Edge profile instead of reusing the developer’s personal browser state. The session contains no existing cookies, logins, history, or extensions, which keeps verification reproducible and prevents an Agent from inheriting personal credentials.
- [Inspect the DOM, console, network, and crashes](https://coderfriendai.com/features/#capability-53-inspect-the-dom-console-network-and-crashes): inspect_preview returns semantic page structure together with bounded console errors, failed network requests, blocked origins, and renderer-crash evidence. The Agent receives text observations it can reason about, while the local verification card retains visual proof and clear pass or failure state.
- [Exercise real interactions and responsive states](https://coderfriendai.com/features/#capability-53-exercise-real-interactions-and-responsive-states): click_preview, type_preview, and select_preview_element let the Agent exercise visible controls and inspect a user-chosen element inside the isolated page. Combined with deliberate viewport changes and repeated inspection, this can verify behavior that a successful build or static source review cannot prove.
- [Capture screenshots as verification evidence](https://coderfriendai.com/features/#capability-53-capture-screenshots-as-verification-evidence): capture_preview_screenshot records the rendered interface in the local Runtime Verification card after meaningful states are reached. Screenshots support human review of layout, responsive behavior, and visible outcomes, while the model also receives bounded observations rather than relying on an unsupported claim that the page looked correct.

### 54. Live Server Agent
Diagnose and repair remote environments over OpenSSH with explicit roots and rollback-aware tools.

- [Safe remote tools or an explicitly enabled full shell](https://coderfriendai.com/features/#capability-54-safe-remote-tools-or-an-explicitly-enabled-full-shell): Every Live Server connection chooses either root-bounded Safe Tools or separately warned Full Shell capability. Safe Tools never offers ssh_exec, while Full Shell can reach the complete SSH account and must remain visibly labeled so remote command authority cannot be mistaken for file-root access.
- [Configured remote filesystem roots](https://coderfriendai.com/features/#capability-54-configured-remote-filesystem-roots): Structured SSH file tools resolve POSIX paths beneath the canonical root chosen during connection. Traversal, target symlinks, likely secrets, and files too large for exact mutation are rejected, making the displayed remote root an enforced boundary rather than a suggested working directory.
- [Health, log, process, and port inspection](https://coderfriendai.com/features/#capability-54-health-log-process-and-port-inspection): Fixed SSH tools can inspect service status, bounded journal output, process lists, listening ports, and endpoint health without granting an arbitrary shell. These operations cover common deployment diagnosis while preserving recognizable inputs, outputs, time limits, and approval decisions.
- [Atomic remote edits](https://coderfriendai.com/features/#capability-54-atomic-remote-edits): Remote edit, write, and patch tools calculate the intended result, create recovery state, write through a same-directory temporary file, and rename into place. Multi-file patches roll back earlier targets if a later operation fails, reducing the chance of leaving a live deployment half-updated.
- [Backups and rollback support](https://coderfriendai.com/features/#capability-54-backups-and-rollback-support): Each structured remote mutation creates a per-file backup under the SSH account’s CoderFriend state directory and retains only bounded metadata locally. Users and Agents can list recovery points and restore one explicitly, and transaction rollback continues even if the originating request is cancelled.

### 55. Request budgets & recovery
Bound autonomous work by the resources you choose, then continue cleanly after an interruption.

- [Token and cost budgets](https://coderfriendai.com/features/#capability-55-token-and-cost-budgets): Root Agent requests can stop before another provider call when measured non-cache token usage or exact provider cost reaches the configured ceiling. Unknown cost is never counted as zero; token, call, iteration, and time safeguards continue while the interface reports that cost enforcement is unavailable.
- [Time, tool-call, and iteration budgets](https://coderfriendai.com/features/#capability-55-time-tool-call-and-iteration-budgets): Separate limits bound total wall-clock duration, provider model calls, and Agent-loop iterations for one root request. Each ceiling has a distinct pause reason, helping users decide whether to continue intentionally instead of receiving a generic failure after an uncontrolled autonomous run.
- [Budgets that include delegated subagent work](https://coderfriendai.com/features/#capability-55-budgets-that-include-delegated-subagent-work): Planner, summary, reviewer, retry, and subagent calls inherit the root request’s accounting context rather than running as free hidden work. Delegated specialists also have per-child and shared token, exact-cost, concurrency, and time limits that can cancel the whole child pool when reached.
- [Cancellation and continuation controls](https://coderfriendai.com/features/#capability-55-cancellation-and-continuation-controls): Stop threads cancellation through provider calls, built-in transactions, MCP tools, sandboxed commands, runtime processes, browsers, and managed SSH work. A bounded pause can offer Continue as a fresh accountable request, preserving completed state without replaying paid calls or bypassing the limit that stopped them.
- [Reload handoff for interrupted work](https://coderfriendai.com/features/#capability-55-reload-handoff-for-interrupted-work): Saved background and conversation state survives for inspection after VS Code reloads, but active work is marked interrupted rather than automatically resumed. This makes the handoff honest: users can see what completed, inspect changes, and choose a next step without duplicate requests or assumed live processes.

### 56. Agent evaluations & scorecards
Compare how provider and model combinations perform against a repeatable coding-agent benchmark.

- [A 72-task Agent evaluation suite](https://coderfriendai.com/features/#capability-56-a-72-task-agent-evaluation-suite): CoderFriend includes 72 reproducible coding tasks designed to exercise investigation, editing, verification, safety, and completion behavior across provider and model routes. Each task runs in an isolated evaluation workspace so benchmark changes do not contaminate the developer’s active repository.
- [Provider and model scorecards](https://coderfriendai.com/features/#capability-56-provider-and-model-scorecards): Evaluation results are aggregated into scorecards keyed to the exact provider and model that performed the work. Users can compare completion quality, evidence, and failure patterns without treating every route from one model family as interchangeable.
- [Repeatable quality comparisons](https://coderfriendai.com/features/#capability-56-repeatable-quality-comparisons): The same corpus, harness, and scoring expectations can be rerun after a model, provider, prompt, or Agent implementation changes. Repeatability turns a subjective impression into comparable evidence while still exposing individual task output for deeper review.
- [Evidence for choosing the right route for a task](https://coderfriendai.com/features/#capability-56-evidence-for-choosing-the-right-route-for-a-task): Scorecards help identify whether a route is strong at the kinds of repository work, safety constraints, and verification steps that matter to the team. They complement live price, speed, and context limits, giving model selection more substance than a provider name or leaderboard claim.

### 57. Exact approval memory
Turn repeated safe actions into explicit reusable rules without granting a model vague command-prefix authority.

- [Approve a sensitive action once](https://coderfriendai.com/features/#capability-57-approve-a-sensitive-action-once): A one-time approval authorizes only the concrete action shown in the current prompt and creates no reusable rule. It is the safest way to allow an unusual external file, command, MCP call, browser interaction, Docker boundary, or live-server operation whose future variants should still be reviewed.
- [Remember an exact command for the session, workspace, or globally](https://coderfriendai.com/features/#capability-57-remember-an-exact-command-for-the-session-workspace-or-globally): Save a complete shell command line after reviewing it, then choose whether that exact text applies only to the current session, the active workspace, or all workspaces. CoderFriend does not use executable-prefix approvals, because extra flags or shell chaining can turn a familiar prefix into different behavior.
- [Remember an exact path or deliberate folder boundary](https://coderfriendai.com/features/#capability-57-remember-an-exact-path-or-deliberate-folder-boundary): Authorize one resolved file path or a consciously selected containing folder at session, workspace, or global scope. Canonical path checks still run when the rule is used, preventing traversal or a misleading textual path from turning a narrow approval into access to another location.
- [Keep likely secret files behind a dedicated approval decision](https://coderfriendai.com/features/#capability-57-keep-likely-secret-files-behind-a-dedicated-approval-decision): Workspace mode does not treat .env files, private keys, credential stores, and similarly shaped paths as ordinary project reads. A foreground request must surface the sensitive target for explicit authorization, while searches and approval-less delegated tools continue to omit it rather than asking indirectly.
- [Inspect and edit saved approval rules from settings](https://coderfriendai.com/features/#capability-57-inspect-and-edit-saved-approval-rules-from-settings): The Settings Center exposes saved exact commands, exact paths, and path prefixes so remembered authority can be audited and removed without waiting for another prompt. Deprecated command-prefix settings are identified as ignored rather than silently providing broader execution than the interface describes.

### 58. Destructive-command intelligence
Classify dangerous shell behavior before execution so approval prompts explain the actual irreversible risk in a complete command line.

- [Detect destructive filesystem and Git operations](https://coderfriendai.com/features/#capability-58-detect-destructive-filesystem-and-git-operations): Static command analysis recognizes deletion, shredding, truncation, raw disk writes, recursive ownership or permission changes, hard resets, cleaning, forced or delete pushes, history rewrites, dropped stashes, and forced branch deletion. The check scans the prepared command before approval or execution.
- [Detect database, container, infrastructure, and package-publish risks](https://coderfriendai.com/features/#capability-58-detect-database-container-infrastructure-and-package-publish-risks): The risk gate also identifies destructive database statements, container image or volume deletion, kubectl delete, Terraform destroy or apply, registry publishing, and related high-impact operations. These categories receive a concrete explanation so a prompt communicates consequences instead of showing only an opaque command string.
- [Scan chained shell commands instead of trusting the first executable](https://coderfriendai.com/features/#capability-58-scan-chained-shell-commands-instead-of-trusting-the-first-executable): CoderFriend evaluates the complete shell line, including operations after pipes, semicolons, logical operators, and command substitutions. A harmless build step cannot launder a later rm, destructive Git command, or downloaded script past the approval classifier simply because it appears first.
- [Explain the concrete risk inside Ask and Workspace prompts](https://coderfriendai.com/features/#capability-58-explain-the-concrete-risk-inside-ask-and-workspace-prompts): When a destructive pattern appears under a prompting policy, the approval dialog states the identified risk alongside the exact command and working boundary. Users can decide with relevant context rather than inferring impact from syntax, while Always Allow remains honest about bypassing the prompt entirely.
- [Keep risk classification deterministic and outside model influence](https://coderfriendai.com/features/#capability-58-keep-risk-classification-deterministic-and-outside-model-influence): Risk rules are implemented as static command analysis, not a second model judgment that can be persuaded by untrusted repository text. The Agent cannot redefine a destructive operation as safe through its own prompt, and unsupported patterns still remain subject to the ordinary approval and sandbox layers.

### 59. Process-isolated command execution
Run project commands inside an explicit filesystem and network boundary with bounded output, time, cancellation, and complete process-tree cleanup.

- [Use macOS sandbox-exec or Linux Bubblewrap when available](https://coderfriendai.com/features/#capability-59-use-macos-sandbox-exec-or-linux-bubblewrap-when-available): On macOS, supported command isolation uses sandbox-exec profiles; on Linux it uses Bubblewrap namespaces and mounts. CoderFriend verifies the required backend before execution and reports an actionable failure when isolation cannot be established instead of quietly launching the command unrestricted.
- [Deny network access inside sandboxed project commands](https://coderfriendai.com/features/#capability-59-deny-network-access-inside-sandboxed-project-commands): Linux commands run in an unshared network namespace with no interfaces, while macOS commands receive a deny-network sandbox profile. The UI and documentation distinguish those enforcement models honestly, because macOS service-mediated escapes make its boundary a strong default rather than an equivalent hard namespace.
- [Sanitize provider credentials from command environments](https://coderfriendai.com/features/#capability-59-sanitize-provider-credentials-from-command-environments): Sandboxed commands receive a reduced environment that excludes provider API keys and unrelated secrets, plus variables describing the active command boundary and sandbox. A toolchain can see whether it is confined without inheriting the credentials CoderFriend uses to contact model providers.
- [Apply separate routine and recognized project-check timeouts](https://coderfriendai.com/features/#capability-59-apply-separate-routine-and-recognized-project-check-timeouts): Routine shell commands receive a shorter process-tree timeout, while recognized repository verification such as builds, tests, Codeception, and Playwright can receive a larger bounded window. Long-running image generation and dependency setup are classified deliberately so legitimate work is not killed at the routine ceiling.
- [Terminate the complete process group on timeout, overflow, or cancellation](https://coderfriendai.com/features/#capability-59-terminate-the-complete-process-group-on-timeout-overflow-or-cancellation): Each sandboxed command owns a process group rather than only one child PID. Timeout, excessive output, or request cancellation escalates from TERM to KILL across the tree, preventing a wrapper script from ending while its compiler, test runner, watcher, or spawned shell keeps running.
- [Fail closed when the required sandbox backend is unavailable](https://coderfriendai.com/features/#capability-59-fail-closed-when-the-required-sandbox-backend-is-unavailable): If the selected workspace-write or read-only policy cannot be enforced on the current platform, run_command returns an explicit error and does not fall back to unrestricted host execution. Users can repair the backend or consciously select sandbox off instead of receiving a hidden change in authority.

### 60. Docker-aware host verification
Handle Docker-backed repository checks as a distinct host boundary instead of pretending daemon access fits inside an ordinary workspace sandbox.

- [Request a dedicated host-runtime approval when policy requires it](https://coderfriendai.com/features/#capability-60-request-a-dedicated-host-runtime-approval-when-policy-requires-it): Direct Docker commands and Docker-backed repository targets can reach the host daemon beyond an ordinary command sandbox, so Ask and Workspace modes surface a one-shot host-runtime approval. Always Allow proceeds without a prompt, but the execution path still records that Docker is a distinct boundary.
- [Run with a disposable home that omits personal Docker credentials](https://coderfriendai.com/features/#capability-60-run-with-a-disposable-home-that-omits-personal-docker-credentials): Approved host Docker execution receives a temporary home containing only the system Compose integration needed for the command. Personal Docker configuration, registry logins, and unrelated home-directory state are not copied into that environment merely because a repository test uses containers.
- [Follow repository-declared Make and Compose targets](https://coderfriendai.com/features/#capability-60-follow-repository-declared-make-and-compose-targets): The Agent is directed to run the project’s documented Make or Compose entry points instead of reconstructing internal container commands from fragments. This preserves the same build topology maintainers use and makes verification output easier to compare with CI and developer instructions.
- [Reject guessed Make targets when a static target list is available](https://coderfriendai.com/features/#capability-60-reject-guessed-make-targets-when-a-static-target-list-is-available): When a Makefile can be read statically, CoderFriend detects a requested target that does not exist and returns the declared alternatives before spawning Make. The Agent can recover to a real project command without spending time inside Docker or inventing an e2e target from another repository.
- [Recognize bounded Docker-backed Codeception and Playwright checks](https://coderfriendai.com/features/#capability-60-recognize-bounded-docker-backed-codeception-and-playwright-checks): Direct Codeception and Playwright invocations remain recognized project checks even when wrapped by Docker Compose. They receive the longer bounded verification window and full process-tree handling, allowing realistic application checks without turning container execution into an unlimited background task.

### 61. Atomic workspace-wide replacement
Apply one exact mechanical wording, label, or import-path change across an explicit file set as a single recoverable transaction.

- [Replace an exact literal across as many as 100 named files](https://coderfriendai.com/features/#capability-61-replace-an-exact-literal-across-as-many-as-100-named-files): replace_workspace_text takes an explicit list of workspace files plus one old and new literal, then replaces every exact occurrence in those named targets. It is optimized for bounded mechanical changes such as terminology, labels, imports, or configuration keys after one repository search identifies the scope.
- [Skip files that do not contain the expected source text](https://coderfriendai.com/features/#capability-61-skip-files-that-do-not-contain-the-expected-source-text): A listed file with no exact old-string match is reported as skipped rather than rewritten or treated as an automatic failure. This lets one deliberate target set include nearby candidates while preserving clear counts of changed, skipped, and invalid files.
- [Validate every target before any write begins](https://coderfriendai.com/features/#capability-61-validate-every-target-before-any-write-begins): The replacement tool resolves policy, path, content, file-lock, and mutation constraints for the complete explicit list before committing changes. An invalid or unauthorized target cannot leave earlier files modified merely because it appeared later in the request.
- [Roll back earlier files if a later mutation fails](https://coderfriendai.com/features/#capability-61-roll-back-earlier-files-if-a-later-mutation-fails): All calculated after-states are written as one transaction, and a write failure restores targets already changed during that call. The tool reports the failure and rollback outcome, allowing the Agent to reassess the file set instead of continuing from an unknown half-replaced state.
- [Record all successful replacements in the Agent checkpoint](https://coderfriendai.com/features/#capability-61-record-all-successful-replacements-in-the-agent-checkpoint): Every changed file contributes its original and final content to the active AgentChangeSession just like patch, edit, write, and delete tools. The resulting checkpoint, diff, and guarded undo therefore represent the whole mechanical rewrite rather than only the last file touched.

### 62. Shell-edit checkpoint recovery
Capture recoverable before-states for files explicitly named by recognized shell-edit commands, even during maximum-trust work.

- [Recognize explicit file targets in common shell-edit commands](https://coderfriendai.com/features/#capability-62-recognize-explicit-file-targets-in-common-shell-edit-commands): Under maximum-trust execution, CoderFriend analyzes recognized shell mutation forms and extracts only direct, unambiguous file operands. Redirected, globbed, computed, or compound forms that cannot be mapped reliably remain ordinary shell side effects rather than being falsely advertised as checkpointed.
- [Capture a best-effort baseline before the command starts](https://coderfriendai.com/features/#capability-62-capture-a-best-effort-baseline-before-the-command-starts): For each explicit named target it can safely resolve, CoderFriend reads the pre-command content before launching the shell edit. Baseline capture is best effort and does not block an otherwise authorized maximum-trust command when a target cannot be identified or read.
- [Include detected shell-edited files in the request checkpoint](https://coderfriendai.com/features/#capability-62-include-detected-shell-edited-files-in-the-request-checkpoint): After the command finishes, files with captured baselines and real content changes join the same request checkpoint as built-in mutations. Their diffs become visible in Review Changes and eligible for guarded restore, extending recoverability to common direct shell edits without claiming universal command tracing.
- [Keep unidentified command side effects outside restore claims](https://coderfriendai.com/features/#capability-62-keep-unidentified-command-side-effects-outside-restore-claims): Generic shell commands may change files, services, databases, containers, or remote state that CoderFriend cannot enumerate safely. Those unidentified side effects are not added to a checkpoint, and the interface and documentation state that limitation instead of implying Undo can reverse arbitrary host behavior.

### 63. Concurrent edit protection
Prevent foreground, background, and delegated Agents from silently writing the same path at the same time.

- [Acquire request-scoped file locks before mutation](https://coderfriendai.com/features/#capability-63-acquire-request-scoped-file-locks-before-mutation): Foreground, background, and delegated mutation tools claim canonical target paths through a request-scoped lock manager before writing. The lock belongs to the active run and is released during normal completion, failure, cancellation, or final cleanup rather than persisting as an unexplained project artifact.
- [Detect path conflicts across concurrent Agent runs](https://coderfriendai.com/features/#capability-63-detect-path-conflicts-across-concurrent-agent-runs): A second Agent attempting to mutate a path already owned by another active request receives a conflict before the write begins. Canonical resolution catches equivalent path spellings, reducing the risk that two worktrees or automation surfaces silently interleave edits to the same underlying file.
- [Release owned locks when work completes or is cancelled](https://coderfriendai.com/features/#capability-63-release-owned-locks-when-work-completes-or-is-cancelled): Request finalization releases every lock acquired by that run whether it completed successfully, failed, timed out, or was stopped. Cleanup prevents an interrupted Agent from leaving a stale in-memory claim that blocks legitimate future edits after no process is working on the file.
- [Report the conflicting run instead of racing the write](https://coderfriendai.com/features/#capability-63-report-the-conflicting-run-instead-of-racing-the-write): A lock conflict identifies the active ownership context and stops the mutation rather than retrying invisibly until one write wins. Users and coordinating Agents can wait, choose another task, or inspect the competing run with enough information to avoid accidental overwrite.

### 64. Diagnostics-guided repair
Feed compiler and language-service evidence back into the Agent loop so edits can be corrected before completion is claimed.

- [Collect diagnostics after relevant workspace mutations](https://coderfriendai.com/features/#capability-64-collect-diagnostics-after-relevant-workspace-mutations): CoderFriend requests current language-service diagnostics for files affected by Agent edits and includes bounded results in the workflow. Compiler and editor evidence appears after the actual mutation, helping distinguish a plausible-looking patch from one that introduced a syntax, type, or import failure.
- [Open exact diagnostic locations in VS Code](https://coderfriendai.com/features/#capability-64-open-exact-diagnostic-locations-in-vs-code): Diagnostic rows retain the workspace file, line, column, severity, source, and message needed to open the problem directly in the editor. The user can inspect surrounding code and language-service context instead of searching manually for an error summarized without a location.
- [Give the Agent a bounded self-repair opportunity](https://coderfriendai.com/features/#capability-64-give-the-agent-a-bounded-self-repair-opportunity): New diagnostics can be returned to the same Agent for a limited correction pass while request budgets, iteration ceilings, cancellation, and tool policy remain active. Self-repair is not an endless loop and does not erase the original verification evidence if the fix fails.
- [Distinguish pre-existing diagnostics from newly introduced failures](https://coderfriendai.com/features/#capability-64-distinguish-pre-existing-diagnostics-from-newly-introduced-failures): The workflow considers the diagnostic state around changed files so long-standing project warnings are not automatically blamed on the latest patch. Newly introduced or materially affected errors remain high priority, while pre-existing findings can be reported as context without inventing regression responsibility.
- [Keep unresolved verification failures visible in the final result](https://coderfriendai.com/features/#capability-64-keep-unresolved-verification-failures-visible-in-the-final-result): If diagnostics remain after repair attempts, the Agent must state that verification did not pass and preserve the relevant evidence. CoderFriend does not convert an exhausted budget, cancelled check, or unresolved compiler error into a green completion state for presentation.

### 65. Evidence-backed completion
Require the Agent to connect completion claims to edits, diagnostics, tests, runtime observations, or an explicit limitation.

- [Track understanding, editing, verification, and completion phases](https://coderfriendai.com/features/#capability-65-track-understanding-editing-verification-and-completion-phases): The Agent activity model distinguishes investigation, mutation, project checks, runtime observation, and final reporting. This makes a request’s current phase visible and supports completion checks that can ask whether claimed implementation actually included edits and whether claimed verification produced evidence.
- [Recognize repository-declared verification commands](https://coderfriendai.com/features/#capability-65-recognize-repository-declared-verification-commands): CoderFriend reads relevant repository instructions and declared scripts before choosing build, test, lint, or application checks. Using project-owned commands reduces guessed verification, and a missing target can return available alternatives instead of being misreported as a failing codebase.
- [Treat skipped host-only checks separately from failed checks](https://coderfriendai.com/features/#capability-65-treat-skipped-host-only-checks-separately-from-failed-checks): Extension-host, Electron, and similar checks can be declared skipped when an outer Agent command boundary cannot safely provide their required native GUI or nested isolation behavior. A suite containing only intentional documented skips is not labeled a test failure, but the missing coverage remains explicit.
- [Report unverified work honestly instead of inventing success](https://coderfriendai.com/features/#capability-65-report-unverified-work-honestly-instead-of-inventing-success): Completion claims must match observable edits, diagnostics, command results, runtime evidence, review output, or a clearly stated inability to verify. When a check cannot run, times out, or fails, the final response reports that limitation rather than extrapolating success from source inspection alone.

### 66. Isolated browser interaction
Test local interfaces and explicitly requested public pages in a fresh browser profile that never borrows personal cookies or credentials.

- [Open localhost previews in a fresh Chrome, Chromium, or Edge profile](https://coderfriendai.com/features/#capability-66-open-localhost-previews-in-a-fresh-chrome-chromium-or-edge-profile): open_preview detects a supported browser and launches a new request-owned profile for the local application URL. The profile starts without personal cookies, authentication, extensions, or history, making test results independent from the developer’s everyday browser session.
- [Inspect semantic DOM content and selected elements](https://coderfriendai.com/features/#capability-66-inspect-semantic-dom-content-and-selected-elements): inspect_preview returns a bounded semantic view of visible structure, controls, text, accessibility state, and a user-selected element when requested. The Agent can reason about the rendered application and target a real interface component without receiving an unlimited raw DOM dump.
- [Capture console errors, failed network requests, and renderer crashes](https://coderfriendai.com/features/#capability-66-capture-console-errors-failed-network-requests-and-renderer-crashes): Runtime observations collect console errors, failed requests, blocked origins, and renderer-crash state alongside normal page content. Warning-only console output stays visible without automatically failing verification, while errors and crashes produce a clear failure signal for repair.
- [Click controls, enter non-secret text, and exercise user flows](https://coderfriendai.com/features/#capability-66-click-controls-enter-non-secret-text-and-exercise-user-flows): click_preview and type_preview can exercise ordinary visible interactions inside the isolated profile, while select_preview_element lets the user identify a target directly. The Agent is instructed never to request, read, or type credentials; authenticated flows require the user to sign in themselves.
- [Approve external navigation and newly requested page origins explicitly](https://coderfriendai.com/features/#capability-66-approve-external-navigation-and-newly-requested-page-origins-explicitly): Localhost preview is available for project verification, but a public top-level URL and page-requested CDN or API origins follow the selected approval policy. Ask and Workspace modes surface the new external boundary, while Always Allow proceeds consistently rather than creating a hidden refusal.
- [Capture screenshots as local verification evidence](https://coderfriendai.com/features/#capability-66-capture-screenshots-as-local-verification-evidence): Runtime screenshots record the visible state reached after opening, resizing, or interacting with the page and appear in the local verification card. They help users judge layout and visual behavior while DOM, console, network, and crash observations provide complementary machine-readable evidence.
- [Remove request-owned browser profiles and processes at finalization](https://coderfriendai.com/features/#capability-66-remove-request-owned-browser-profiles-and-processes-at-finalization): The runtime controller tracks the browser profile and process tree created for the request and closes them during completion, cancellation, timeout, or cleanup. Temporary verification state does not become a persistent browser installation or an abandoned background process after the Agent stops.

### 67. SSH connection identity & trust
Connect to a deliberate OpenSSH target while keeping environment, host, root, capability, and temporary trust visible throughout the session.

- [Reuse OpenSSH configuration and the user’s existing ssh-agent](https://coderfriendai.com/features/#capability-67-reuse-openssh-configuration-and-the-users-existing-ssh-agent): Live Server connections use the system OpenSSH client with normal host-key verification, BatchMode, existing ~/.ssh/config aliases, and keys already available through ssh-agent. CoderFriend does not collect or persist SSH passwords, private keys, agent material, or a long-lived control socket.
- [Choose from recent targets, SSH aliases, or deliberate manual entry](https://coderfriendai.com/features/#capability-67-choose-from-recent-targets-ssh-aliases-or-deliberate-manual-entry): The connection picker lists as many as ten validated successful targets in newest-first order, followed by concrete aliases discovered from SSH configuration and a manual user@host path. Failed attempts are not remembered, and history can be cleared without changing the user’s OpenSSH files.
- [Label the target as Production, Staging, or Development](https://coderfriendai.com/features/#capability-67-label-the-target-as-production-staging-or-development): Every connection receives an explicit environment identity before Agent access begins. The Production, Staging, or Development label remains visible beside the target so prompts, approvals, progress, and final reports carry the operational context of the machine being changed.
- [Keep host, structured root, capability, and trust visible in the UI](https://coderfriendai.com/features/#capability-67-keep-host-structured-root-capability-and-trust-visible-in-the-ui): The sidebar and status bar continuously show the selected host, canonical Safe Tools root, Safe Tools or Full Shell capability, and current trust mode. This prevents a remembered remote session from looking like a local workspace or a restricted root from being confused with account-wide shell access.
- [Expire connection state and trusted-session authority on reload](https://coderfriendai.com/features/#capability-67-expire-connection-state-and-trusted-session-authority-on-reload): Active connection metadata and trusted-session approval live only in memory and expire when the extension host reloads. Selecting a remembered target re-enters the normal connection flow, so recent history cannot silently restore remote trust or Full Shell capability in a new session.

### 68. SSH Safe Tools sandbox
Operate on a remote deployment through structured, root-bounded tools while unrestricted shell execution remains unavailable.

- [Read remote files with ssh_read_file](https://coderfriendai.com/features/#capability-68-read-remote-files-with-ssh_read_file): ssh_read_file resolves a root-relative POSIX path on the remote host, rejects traversal and target symlinks, and returns bounded text with line information. It can read a normal whole file within the mutation-size boundary or transfer only a requested range or tail for larger inspection work.
- [Search one remote file with ssh_search_file](https://coderfriendai.com/features/#capability-68-search-one-remote-file-with-ssh_search_file): ssh_search_file runs bounded grep-style matching on the remote host and transfers only matching lines plus the total count. A multi-megabyte or rotating log can therefore be searched without downloading the complete file into local memory or consuming the model context window.
- [List remote folders with ssh_list_directory](https://coderfriendai.com/features/#capability-68-list-remote-folders-with-ssh_list_directory): ssh_list_directory returns structured bounded entries beneath the configured canonical root rather than parsing an arbitrary ls shell transcript. Paths are checked physically against the root and likely secret names are filtered, giving the Agent a safe way to discover remote deployment structure.
- [Search the remote tree with ssh_search](https://coderfriendai.com/features/#capability-68-search-the-remote-tree-with-ssh_search): ssh_search looks for matching names or content across the permitted remote tree while respecting result, output, path, and secret limits. The tool supports diagnosis and code discovery in Safe Tools mode without exposing an unrestricted command parser or silently following paths outside the selected root.
- [Edit exact remote text with ssh_edit_file](https://coderfriendai.com/features/#capability-68-edit-exact-remote-text-with-ssh_edit_file): ssh_edit_file replaces one expected literal in a root-bounded remote file after validating the current content and creating a recovery point. Ambiguous or stale source fails clearly, so an Agent cannot apply a surgical production change at a guessed location after the file has changed.
- [Write a remote file atomically with ssh_write_file](https://coderfriendai.com/features/#capability-68-write-a-remote-file-atomically-with-ssh_write_file): ssh_write_file validates the complete intended content, sends it through stdin to a same-directory temporary file, and renames that file into place. Existing targets receive a remote backup first, and cancellation or transport failure cannot present a partial streamed file as a successful write.
- [Apply transactional remote diffs with ssh_apply_patch](https://coderfriendai.com/features/#capability-68-apply-transactional-remote-diffs-with-ssh_apply_patch): ssh_apply_patch reuses the bounded unified-diff parser and calculates every target after-state locally before remote mutation starts. It creates recovery points for the file set and restores earlier targets when a later step fails, preserving all-or-rollback behavior across a multi-file live-server change.
- [Block traversal, target symlinks, likely secrets, and oversized mutations](https://coderfriendai.com/features/#capability-68-block-traversal-target-symlinks-likely-secrets-and-oversized-mutations): Structured remote paths must remain root-relative, resolve physically beneath the canonical root, avoid target-file symlinks, and pass secret screening. Exact mutation tools also enforce a 512 KB whole-file ceiling, because safe patching and rollback require complete known content rather than a truncated approximation.
- [Omit ssh_exec from the model toolset in Safe Tools mode](https://coderfriendai.com/features/#capability-68-omit-ssh_exec-from-the-model-toolset-in-safe-tools-mode): When Safe Tools is selected, ssh_exec is not advertised to the model and runtime dispatch rejects an attempted call if one is fabricated. The Agent can still inspect files and operations through structured SSH tools, but it cannot escape the remote root by inventing an arbitrary shell command.

### 69. SSH Full Shell authority
Enable unrestricted remote commands only through a separate, explicit capability decision that clearly names its reach beyond the structured file root.

- [Show a dedicated Full Shell warning before connection](https://coderfriendai.com/features/#capability-69-show-a-dedicated-full-shell-warning-before-connection): Choosing Full Shell opens a separate warning that explains ssh_exec is not confined to the structured file-tools root and may use everything the SSH account can access, including sudo. The connection proceeds only after that broader capability decision is made deliberately.
- [Keep the FULL SHELL state visible for the connection lifetime](https://coderfriendai.com/features/#capability-69-keep-the-full-shell-state-visible-for-the-connection-lifetime): A connected Full Shell target retains an unmistakable FULL SHELL label in the remote identity surface instead of reverting to a generic connected state. The persistent warning helps users notice that a later request has account-wide command capability even if the original modal is no longer on screen.
- [Allow ssh_exec to reach everything available to the SSH account](https://coderfriendai.com/features/#capability-69-allow-ssh_exec-to-reach-everything-available-to-the-ssh-account): ssh_exec runs a foreground remote command through the selected OpenSSH account and is intentionally not restricted by the Safe Tools root. Its reach includes paths, services, network access, and executables allowed to that account, so approval and visible capability state—not a misleading cwd—define the risk.
- [Treat sudo and remote shell side effects as outside the file-tools root](https://coderfriendai.com/features/#capability-69-treat-sudo-and-remote-shell-side-effects-as-outside-the-file-tools-root): Full Shell can invoke sudo when the remote account permits it and can change state that structured backup tools do not track, including databases, services, containers, and files elsewhere. CoderFriend does not claim its file-root backups can undo those arbitrary command effects.
- [Keep command approval policy separate from shell capability](https://coderfriendai.com/features/#capability-69-keep-command-approval-policy-separate-from-shell-capability): Full Shell determines which remote command tool exists, while Ask, Workspace, trusted-session, and Always Allow determine whether a permitted call needs a prompt. Enabling one does not silently enable the other, and local saved approval rules never transfer automatically to the remote connection.

### 70. SSH large-file inspection
Inspect large or rotating remote logs in place instead of downloading an entire multi-megabyte file into the Agent context.

- [Read a selected remote line range on the host](https://coderfriendai.com/features/#capability-70-read-a-selected-remote-line-range-on-the-host): Pass startLine and endLine to ssh_read_file to run bounded sed-style extraction on the remote host and transfer only that window. This makes a known section of a large configuration or log available for diagnosis without pretending the entire oversized file was read.
- [Tail the newest remote lines without whole-file transfer](https://coderfriendai.com/features/#capability-70-tail-the-newest-remote-lines-without-whole-file-transfer): Pass tailLines to ssh_read_file to execute the tail operation remotely and receive only the latest bounded records. The workflow is suited to active application logs where downloading the complete historical file would be slow, stale, and unnecessarily expensive in model context.
- [Run remote grep and return bounded matching lines](https://coderfriendai.com/features/#capability-70-run-remote-grep-and-return-bounded-matching-lines): ssh_search_file performs matching where the file lives and returns a bounded set of line-numbered hits together with a total match count. The Agent can refine a query or request a surrounding range while keeping nonmatching log content off the wire.
- [Preserve strict whole-file size limits for mutation tools](https://coderfriendai.com/features/#capability-70-preserve-strict-whole-file-size-limits-for-mutation-tools): Windowed reading does not weaken the exact-content requirement for ssh_edit_file, ssh_write_file, or ssh_apply_patch. A file too large for safe whole-file validation remains ineligible for structured mutation, because a partial view cannot support trustworthy after-state calculation and rollback.

### 71. SSH operational diagnostics
Investigate a live environment through fixed, inspectable operational tools before considering broader remote shell access.

- [Inspect a service state with ssh_service_status](https://coderfriendai.com/features/#capability-71-inspect-a-service-state-with-ssh_service_status): ssh_service_status accepts a bounded service identifier and returns fixed status information rather than an arbitrary shell expression. It gives the Agent enough evidence to distinguish stopped, failed, and running deployment services while keeping Safe Tools mode free of general command execution.
- [Read bounded journal output with ssh_read_logs](https://coderfriendai.com/features/#capability-71-read-bounded-journal-output-with-ssh_read_logs): ssh_read_logs retrieves a limited slice of remote journal output for an approved service using a structured request. Time and line bounds prevent an Agent from streaming an endless system log, while stderr remains separate so transport warnings cannot be mistaken for application log content.
- [List remote processes with ssh_list_processes](https://coderfriendai.com/features/#capability-71-list-remote-processes-with-ssh_list_processes): ssh_list_processes returns a bounded process snapshot suitable for identifying duplicate servers, unexpected workers, or the owner of a port. It is an inspection tool rather than a kill interface, so Safe Tools diagnosis does not quietly become arbitrary remote process control.
- [Check a listening port with ssh_check_port](https://coderfriendai.com/features/#capability-71-check-a-listening-port-with-ssh_check_port): ssh_check_port asks the host whether a specific validated port is listening and returns the bounded observation. This separates a process that exists from a service that is actually accepting connections, helping the Agent choose the next diagnostic step without constructing a shell pipeline.
- [Run a bounded endpoint health check with ssh_health_check](https://coderfriendai.com/features/#capability-71-run-a-bounded-endpoint-health-check-with-ssh_health_check): ssh_health_check probes a deliberate remote endpoint with fixed limits and reports its status, response timing, and bounded result. The tool can verify that a deployment responds after an edit or restart while preventing open-ended browsing or credential entry through the SSH diagnostic surface.
- [Keep stdout protocol data separate from remote stderr diagnostics](https://coderfriendai.com/features/#capability-71-keep-stdout-protocol-data-separate-from-remote-stderr-diagnostics): The SSH transport preserves an interleaved diagnostic view but also maintains a clean stdout channel for base64 files, host identity, directory records, and managed-process markers. Login banners, rc-file warnings, ioctl messages, and command errors therefore cannot be decoded as trusted protocol payloads.

### 72. SSH managed process lifecycle
Start temporary remote servers across tool calls while preserving request ownership, bounded lifetime, observable output, and verified cleanup.

- [Start a request-owned remote process with ssh_start_process](https://coderfriendai.com/features/#capability-72-start-a-request-owned-remote-process-with-ssh_start_process): ssh_start_process launches a temporary remote server or watcher in its own managed session for later tool calls in the same foreground request. The command cannot elevate or detach, and the remote host must provide the lifecycle utilities needed to enforce a hard maximum lifetime.
- [Read status and bounded output with ssh_process_status](https://coderfriendai.com/features/#capability-72-read-status-and-bounded-output-with-ssh_process_status): ssh_process_status checks whether the managed job is still active and returns only the bounded output recorded for that request-owned process. The Agent can wait for readiness, inspect a failure, or verify ongoing behavior without starting a second untracked SSH command.
- [Stop a managed process with ssh_stop_process](https://coderfriendai.com/features/#capability-72-stop-a-managed-process-with-ssh_stop_process): ssh_stop_process terminates the selected request-owned job through its recorded process-group identity and verifies the cleanup outcome. A model cannot use it as a generic remote kill command, because handles are scoped to processes CoderFriend created for the active request.
- [Terminate ordinary ssh_exec process groups on finish, timeout, or cancellation](https://coderfriendai.com/features/#capability-72-terminate-ordinary-ssh_exec-process-groups-on-finish-timeout-or-cancellation): Foreground ssh_exec work runs under a private remote lease that records a dedicated process group. Normal completion, timeout, cancellation, and output limits trigger independent TERM and KILL cleanup with verification, preventing a child server from surviving merely because the SSH parent exited.
- [Clean registered leases when a request ends or the target changes](https://coderfriendai.com/features/#capability-72-clean-registered-leases-when-a-request-ends-or-the-target-changes): Before successful foreground completion, disconnect, or target switching, CoderFriend walks every registered remote lease and verifies its request-owned process tree is gone. Cleanup runs independently from the cancelled request token so stopping the Agent cannot also cancel the cleanup responsible for making Stop true.
- [Require explicit approval for persistent process escapes](https://coderfriendai.com/features/#capability-72-require-explicit-approval-for-persistent-process-escapes): Detected background operators, detached containers, and external supervisors are blocked unless allowPersistentProcesses is supplied intentionally. Ask and Workspace modes require a separate approval even in a trusted SSH session, and the resulting persistent process is clearly documented as outside CoderFriend’s automatic ownership and cleanup.

### 73. SSH atomic backup & recovery
Make remote production changes with per-file recovery points, transactional rollback, and an explicit restore path.

- [Create a remote backup before each structured mutation](https://coderfriendai.com/features/#capability-73-create-a-remote-backup-before-each-structured-mutation): Before ssh_edit_file, ssh_write_file, or ssh_apply_patch changes an existing target, CoderFriend copies its current content into the remote recovery directory. Backup creation is part of the guarded mutation path, so a write is not reported successful when the required recovery point could not be established.
- [Store backup payloads on the remote host instead of in local history](https://coderfriendai.com/features/#capability-73-store-backup-payloads-on-the-remote-host-instead-of-in-local-history): Recovery content lives under ~/.local/state/coderfriend-ai/backups on the SSH host, close to the files and permissions it may need to restore. Local workspace state keeps only bounded metadata, avoiding silent replication of production source or configuration into conversation history.
- [List bounded recovery metadata with ssh_list_backups](https://coderfriendai.com/features/#capability-73-list-bounded-recovery-metadata-with-ssh_list_backups): ssh_list_backups returns the available recovery identifiers, target paths, timestamps, and bounded details needed to choose a restore point. It does not stream every backup payload to the model, keeping historical remote content private until a deliberate restoration is requested.
- [Restore a selected recovery point with ssh_restore_backup](https://coderfriendai.com/features/#capability-73-restore-a-selected-recovery-point-with-ssh_restore_backup): ssh_restore_backup validates the chosen metadata, target boundary, current state, and approval before replacing the remote file from its stored recovery payload. Restore is an explicit mutation with a visible outcome, not an automatic rollback triggered by an unrelated later request.
- [Roll back earlier files when a multi-file remote patch partially fails](https://coderfriendai.com/features/#capability-73-roll-back-earlier-files-when-a-multi-file-remote-patch-partially-fails): A remote unified patch calculates all after-states before writing and retains a recovery point for every target. If one later file cannot be committed, the transaction restores files already changed and reports both the primary failure and any rollback problem rather than leaving silent partial deployment.
- [Allow rollback to finish even when the originating request is cancelled](https://coderfriendai.com/features/#capability-73-allow-rollback-to-finish-even-when-the-originating-request-is-cancelled): Transaction recovery deliberately does not reuse the cancelled Agent token that interrupted the original work. Cleanup gets its own bounded execution path, ensuring a Stop request cannot strand the remote server between several files simply by cancelling the rollback operation too.

### 74. Resilient Agent execution
Recover from common model, command, and tool misunderstandings without hiding errors or spending unlimited retries.

- [Explain a missing executable the first time it fails](https://coderfriendai.com/features/#capability-74-explain-a-missing-executable-the-first-time-it-fails): When a command returns the shell’s executable-not-found failure on its first attempt, CoderFriend reports the missing tool and keeps platform-appropriate installation guidance readable. The Agent can install, choose a repository alternative, or stop without wasting another turn misreading empty stdout as a different problem.
- [Distinguish shell parse failure from a command that actually ran](https://coderfriendai.com/features/#capability-74-distinguish-shell-parse-failure-from-a-command-that-actually-ran): Command handling preserves stderr and exit context so malformed shell syntax is not summarized as successful execution or as the output of the first token. The Agent receives an actionable parse failure and can correct quoting or command construction before claiming any verification occurred.
- [Guide absolute-path work back to the correct workspace boundary](https://coderfriendai.com/features/#capability-74-guide-absolute-path-work-back-to-the-correct-workspace-boundary): When a command names a project through an absolute path rather than cd, boundary analysis still identifies that it leaves the current workspace. The resulting approval or error explains the actual target, helping the user open the intended repository or grant deliberate external access instead of seeing a generic denial.
- [Bound each provider call with a configurable timeout](https://coderfriendai.com/features/#capability-74-bound-each-provider-call-with-a-configurable-timeout): coderfriend-ai.providerCallTimeoutSeconds limits one HTTP or subscription-provider model call independently from the complete Agent request wall clock. A silent provider is abandoned with an explicit message and no invented content or token usage, while slower healthy routes can receive a deliberate larger bound.
- [Retry unsupported provider-native tools once through guarded CoderFriend tools](https://coderfriendai.com/features/#capability-74-retry-unsupported-provider-native-tools-once-through-guarded-coderfriend-tools): If a provider such as Codex attempts its own shell, file, web, MCP, or collaboration tool outside CoderFriend’s boundary, the turn is interrupted and retried once with the guarded dynamic tools it was given. A repeated attempt stops visibly, preventing an unlimited loop or hidden provider-side execution.

### 75. Time-sensitive remote steering
Make it clear when a remote correction cannot reach the active Agent run instead of silently applying it after the moment has passed.

- [Send steering only to the active run](https://coderfriendai.com/features/#capability-75-send-steering-only-to-the-active-run): Direct a clarification to the session currently being watched.
- [Refuse stale delivery instead of queuing it](https://coderfriendai.com/features/#capability-75-refuse-stale-delivery-instead-of-queuing-it): Show that an unsent correction was not deferred to a later point in the run.
- [Preserve deliberate human control](https://coderfriendai.com/features/#capability-75-preserve-deliberate-human-control): Let you review and resend a correction when the current run can receive it.

### 76. End-to-end encrypted remote sessions
Pairing and sealed session transport keep remote run content private from the routing relay.

- [Verify pairing on both devices](https://coderfriendai.com/features/#capability-76-verify-pairing-on-both-devices): Compare the same fingerprint on the phone and desktop before trusting the connection.
- [Seal remote session traffic](https://coderfriendai.com/features/#capability-76-seal-remote-session-traffic): Protect transcript, steering, and stop messages between the paired desktop and phone.
- [Keep the relay blind to content](https://coderfriendai.com/features/#capability-76-keep-the-relay-blind-to-content): Route ciphertext through infrastructure that cannot read the remote session.
- [Reject incompatible protocol versions](https://coderfriendai.com/features/#capability-76-reject-incompatible-protocol-versions): Refuse a mismatched wire contract during the WebSocket handshake instead of misreading later frames.

### 77. Excluded-folder context protection
Keep dependency trees, generated output, private work areas, and other excluded paths out of every model-bound context route.

- [Excluded folders stay out of model context](https://coderfriendai.com/features/#capability-77-excluded-folders-stay-out-of-model-context): Apply workspace exclusions before attached folders, automatic context, and repository-search evidence are assembled for a provider request.
- [Use project-specific exclusion rules](https://coderfriendai.com/features/#capability-77-use-project-specific-exclusion-rules): Respect the workspace’s configured ignore and exclusion patterns instead of relying on one hard-coded directory list.
- [Filter nested files before transmission](https://coderfriendai.com/features/#capability-77-filter-nested-files-before-transmission): Remove matching descendants while walking folder trees so selecting a parent folder does not bypass its protected children.
- [Keep local-only material on disk](https://coderfriendai.com/features/#capability-77-keep-local-only-material-on-disk): Avoid silently including dependencies, build artifacts, private working directories, and other intentionally excluded files in hosted-model prompts.

### 78. Profile-controlled secret-file access
Decide at the guardrail-profile level whether an Agent may read files that are likely to contain credentials.

- [Deny likely secret files without an approval loophole](https://coderfriendai.com/features/#capability-78-deny-likely-secret-files-without-an-approval-loophole): When Secret files is off, file-reading tools refuse recognized credential and private-key paths instead of presenting a prompt that could be accepted accidentally.
- [Resolve real paths before applying the rule](https://coderfriendai.com/features/#capability-78-resolve-real-paths-before-applying-the-rule): Canonical-path checks prevent a symbolic link from disguising a protected file under a harmless-looking name.
- [Extend the boundary to Claude subscription mode](https://coderfriendai.com/features/#capability-78-extend-the-boundary-to-claude-subscription-mode): Equivalent Claude Code read deny rules cover its Read, Grep, and Glob operations when secret-file access is disabled.
- [Let policy and team roles enforce the restriction](https://coderfriendai.com/features/#capability-78-let-policy-and-team-roles-enforce-the-restriction): Managed policy and viewer or developer roles can deny secret-file reads even when a local preset would otherwise permit them.

### 79. Profile-aware Agent step limits
See which Agent limit actually stopped a long run and where to adjust it.

- [Name the active limit when a run stops](https://coderfriendai.com/features/#capability-79-name-the-active-limit-when-a-run-stops): A cut-off Agent run reports whether its ceiling came from the selected guardrail profile or the legacy Agent iteration setting.
- [Point to the control that can change the outcome](https://coderfriendai.com/features/#capability-79-point-to-the-control-that-can-change-the-outcome): When a profile maximum replaces the legacy setting, the notice directs you to that profile rather than suggesting an ineffective setting change.
- [Keep completed work available for continuation](https://coderfriendai.com/features/#capability-79-keep-completed-work-available-for-continuation): Reaching the step ceiling preserves the work already produced and leaves the run ready to continue.

### 80. Organization policies & roles
Apply machine-level guardrails that narrow the authority already allowed by the user.

- [Restrict providers, tools, and request resources](https://coderfriendai.com/features/#capability-80-restrict-providers-tools-and-request-resources): A managed policy can withdraw capabilities, restrict provider sources, and lower request token, cost, time, call, or iteration ceilings. It is applied after user, provider, and exact-model policy resolution.
- [Tighten approvals and sandbox boundaries](https://coderfriendai.com/features/#capability-80-tighten-approvals-and-sandbox-boundaries): Managed approvals and sandbox choices can make an existing policy more restrictive. A machine policy cannot silently grant a tool, remove a stricter user restriction, or widen the workspace boundary.
- [Choose Viewer, Developer, Maintainer, or Admin roles](https://coderfriendai.com/features/#capability-80-choose-viewer-developer-maintainer-or-admin-roles): Organization roles provide named starting restrictions: Viewer withdraws Agent tools, Developer requires per-action approvals and disables subagents, and Maintainer retains the workspace sandbox. Admin adds no role restriction; explicit managed policy still applies.
- [Use administrator-declared credential sources](https://coderfriendai.com/features/#capability-80-use-administrator-declared-credential-sources): An administrator can name the environment variable that supplies a provider key. When that declared source is empty, the connection explains the missing managed credential and does not fall back to a personally stored key.
- [Set retention periods for local records](https://coderfriendai.com/features/#capability-80-set-retention-periods-for-local-records): Managed retention can prune old conversations, memories, completed run reports, and audit entries according to separate day limits. This controls the extension’s local records; exported copies and provider-side data remain separate.

### 81. Project checks before tools
Run explicitly trusted repository checks before supported Agent tool calls.

- [Enable repository hooks deliberately](https://coderfriendai.com/features/#capability-81-enable-repository-hooks-deliberately): Lifecycle hooks are optional and repository hooks require their own trust setting. Hook definitions live in .coderfriend/hooks.json, so accepting a repository does not silently authorize its command checks.
- [Apply pre-tool checks that can narrow a request](https://coderfriendai.com/features/#capability-81-apply-pre-tool-checks-that-can-narrow-a-request): Connected preToolUse hooks can deny a tool call, request the existing approval flow, or attach a reason. A hook cannot grant authority that the resolved request policy already withholds.
- [Bound hook execution and report failures](https://coderfriendai.com/features/#capability-81-bound-hook-execution-and-report-failures): Hook execution limits time, output, environment, and the number of checks. A failed deciding hook asks for a decision through the current approval policy instead of being treated as a successful check.

### 82. Local audit log & verification
Keep an optional, inspectable record of tool, approval, command, and hook activity on your machine.

- [Record activity only after audit logging is enabled](https://coderfriendai.com/features/#capability-82-record-activity-only-after-audit-logging-is-enabled): Audit logging is off by default. Enabling it records connected activity from that point onward in the extension’s local storage, with redacted and bounded detail rather than a retroactive history claim.
- [Verify the retained audit chain](https://coderfriendai.com/features/#capability-82-verify-the-retained-audit-chain): Verify Audit Log checks the sequence and linked entry hashes and reports where verification first fails. This helps reveal an altered or missing retained entry; a local file is not an independently authenticated or tamper-proof service.
- [Export the log with its verification result](https://coderfriendai.com/features/#capability-82-export-the-log-with-its-verification-result): Export Audit Log writes the retained JSON chain and reports whether it verifies. This gives support or internal review a concrete local artifact without uploading it automatically.
- [Bound retention without blocking coding work](https://coderfriendai.com/features/#capability-82-bound-retention-without-blocking-coding-work): The recorder limits retained entries and honors the managed audit-retention period. Disk writes are best effort, so recording does not become a guarantee that every action is durably logged or a reason to stop a coding request.

## Models & orchestration
35 feature systems and 156 capabilities.

### 83. 12 model sources
Choose local, subscription, or API-backed intelligence from one consistent coding workspace.

- [Ollama Local and Ollama Cloud](https://coderfriendai.com/features/#capability-83-ollama-local-and-ollama-cloud): Run models from a local Ollama endpoint without an API key, or connect to Ollama Cloud with its own secure credential and endpoint. Both routes use the same CoderFriend conversation, mode, tool, policy, and accounting surfaces while preserving their distinct model catalogs and authentication.
- [LM Studio on your own machine](https://coderfriendai.com/features/#capability-83-lm-studio-on-your-own-machine): Connect a running loopback LM Studio server, choose an available chat model, and use optional authentication only when the server requires it. Local inference stays outside spending-budget accounting.
- [OpenAI Codex with ChatGPT and OpenAI API](https://coderfriendai.com/features/#capability-83-openai-codex-with-chatgpt-and-openai-api): Choose ChatGPT-authenticated Codex through the shared app-server login or direct OpenAI API access through a separately stored key. CoderFriend keeps the routes distinct because their catalogs, billing visibility, authentication, and available request controls are not interchangeable.
- [Google Gemini](https://coderfriendai.com/features/#capability-83-google-gemini): Connect directly to the native Gemini API with GOOGLE_API_KEY or GEMINI_API_KEY support and a provider-specific endpoint. Gemini models appear only in their own catalog, retain their own mode and reasoning selections, and use CoderFriend’s normal guarded Agent tools rather than a separate workspace integration.
- [Anthropic Claude API and Claude subscription](https://coderfriendai.com/features/#capability-83-anthropic-claude-api-and-claude-subscription): Use Claude through the native Anthropic Messages API with an API key, or through the installed Claude Code CLI and its existing subscription login. The two choices share the Claude model source while retaining their own tool, image, authentication, and billing behavior.
- [OpenRouter and DeepSeek](https://coderfriendai.com/features/#capability-83-openrouter-and-deepseek): Connect OpenRouter for routed multi-vendor models or use DeepSeek’s direct API as an independent provider source. Each route has its own secure key, endpoint, model catalog, usage semantics, exact pricing identity, and account links so one cannot silently borrow configuration from the other.
- [xAI, Groq, and Mistral](https://coderfriendai.com/features/#capability-83-xai-groq-and-mistral): Enable xAI, Groq, and Mistral as first-class API providers with separate credentials, endpoints, live catalogs, and remembered model choices. Their requests still pass through CoderFriend’s shared context, tool, approval, sandbox, retry, budget, and conversation-accounting infrastructure.

### 84. Cross-provider continuity
Keep the same conversation and project context when a different model is better for the next step.

- [Provider-neutral conversation history](https://coderfriendai.com/features/#capability-84-provider-neutral-conversation-history): CoderFriend stores user and assistant messages in a neutral transcript instead of persisting one provider’s private request envelope as the conversation. That representation can be sent through another selected route on a later turn while provider-specific transport and tool formatting are rebuilt safely.
- [Switch models without starting over](https://coderfriendai.com/features/#capability-84-switch-models-without-starting-over): Choose another exact model or provider in the composer and send the next message with the retained thread; changing the selector alone sends nothing. This supports deliberate handoffs—for example, a fast diagnosis followed by a stronger implementation model—without copying the conversation between applications.
- [Reuse attached project context across turns](https://coderfriendai.com/features/#capability-84-reuse-attached-project-context-across-turns): Retained files, folders, selected source, images, instructions, documentation, and relevant conversation state remain associated with the thread when the provider changes. CoderFriend rebuilds the next route’s input from that shared context rather than requiring the user to attach the same project evidence again.
- [Choose the right cost, speed, or reasoning profile per request](https://coderfriendai.com/features/#capability-84-choose-the-right-cost-speed-or-reasoning-profile-per-request): A single thread can route one turn to a low-latency model, another to a deep-reasoning model, and another to a local model according to the task. Visible provider, model, speed, reasoning, cost status, and policy controls make each handoff explicit instead of claiming all routes behave identically.

### 85. Codex with ChatGPT
Use the shared Codex login flow for access backed by your ChatGPT account.

- [Sign in through the Codex authentication flow](https://coderfriendai.com/features/#capability-85-sign-in-through-the-codex-authentication-flow): Selecting the Codex route checks the shared Codex account and opens the official ChatGPT browser authorization flow only when no valid session exists. CoderFriend waits for completion, refreshes the authenticated catalog, and retries one interrupted operation instead of asking for an OpenAI API key.
- [Use supported Codex models from CoderFriend](https://coderfriendai.com/features/#capability-85-use-supported-codex-models-from-coderfriend): The model picker uses the authenticated Codex app-server model/list response as its authoritative catalog. Codex remains a model transport: file, command, web, MCP, browser, approval, sandbox, cancellation, and checkpoint work returns to CoderFriend’s guarded dynamic tool loop.
- [Keep Codex alongside every other configured provider](https://coderfriendai.com/features/#capability-85-keep-codex-alongside-every-other-configured-provider): ChatGPT-authenticated Codex appears in the same provider selector as local Ollama, subscription Claude, and API-backed routes. Its token usage can join the conversation HUD, while exact per-request USD cost remains N/A because a ChatGPT plan does not expose that charge.

### 86. Claude subscription support
Connect Claude Pro or Max through Claude Code as an alternative to API-key billing.

- [Claude Code subscription transport](https://coderfriendai.com/features/#capability-86-claude-code-subscription-transport): Subscription mode launches the locally installed Claude Code CLI through the user’s existing official sign-in rather than sending ANTHROPIC_API_KEY. CoderFriend discovers the executable on PATH, in a home install, or inside the Anthropic VS Code extension, and bounds silent output with the provider-call timeout.
- [Support for Claude Pro and Max workflows](https://coderfriendai.com/features/#capability-86-support-for-claude-pro-and-max-workflows): Users with a valid Claude Code Pro or Max login can run CoderFriend conversations through that subscription transport while retaining CoderFriend modes, context, guarded tools, activity, and usage counts the CLI reports. Exact billed USD remains unavailable when the subscription transport does not expose it.
- [Claude API remains available as a separate route](https://coderfriendai.com/features/#capability-86-claude-api-remains-available-as-a-separate-route): Choose Claude API for the native Anthropic Messages endpoint and secure API key, or Claude subscription for the existing Claude Code sign-in. API image parts and signed thinking follow the native transport; subscription image attachments require its Read tool. Choosing one transport does not overwrite the other’s credentials.
- [Inspect attached images through Claude subscription](https://coderfriendai.com/features/#capability-86-inspect-attached-images-through-claude-subscription): When the Claude subscription request permits its Read tool, supported attached image data is made available as temporary files for the model to inspect, then removed after the request. A request without Read, an unavailable file, or a remote image URL is identified as unavailable rather than silently treated as seen.

### 87. Secure API connections
Connect provider APIs without placing secrets in ordinary workspace settings or source files.

- [Keys stored with VS Code SecretStorage](https://coderfriendai.com/features/#capability-87-keys-stored-with-vs-code-secretstorage): Provider and web-search API keys are written to VS Code SecretStorage rather than ordinary JSON settings or repository files. Legacy plaintext configuration values are migrated and cleared, while supported environment variables remain an intentional alternative for users who manage credentials outside the extension.
- [Guided provider setup](https://coderfriendai.com/features/#capability-87-guided-provider-setup): Set Provider API Key opens a provider-specific picker that can add, replace, or remove the credential for one route. Selecting an API-backed provider with no available key explains what is missing and opens the secure setup path, while local and subscription routes avoid irrelevant key prompts.
- [Remove a saved key at any time](https://coderfriendai.com/features/#capability-87-remove-a-saved-key-at-any-time): The removal command can delete one or every stored provider credential after explicit confirmation, and individual setup flows can clear their selected key. Because VS Code cannot guarantee an extension receives a pre-uninstall event, the dedicated command is the reliable cleanup path before uninstalling.
- [Independent credentials for each provider](https://coderfriendai.com/features/#capability-87-independent-credentials-for-each-provider): Ollama Cloud, OpenAI, Gemini, Anthropic, OpenRouter, DeepSeek, xAI, Groq, Mistral, optional authenticated LM Studio, and web-search services keep separate secret entries. The active route resolves its own credential, with an administrator-declared source taking precedence where configured.

### 88. Portable provider setup
Move provider configuration between environments without rebuilding every preference by hand.

- [Export provider setup](https://coderfriendai.com/features/#capability-88-export-provider-setup): Export API Keys and Settings writes an editable setup template with explicit overrides and placeholders for every supported provider key; a populated export can also serve as a migration backup. Extension defaults are omitted so an old file cannot freeze obsolete defaults on a fresh install.
- [Import a saved setup](https://coderfriendai.com/features/#capability-88-import-a-saved-setup): Import validates the portable JSON, applies supported setting overrides, and writes real keys back into VS Code SecretStorage. Unchanged placeholders do not delete existing credentials, allowing the same template to configure only selected providers without erasing routes already present on the machine.
- [Keep provider choices consistent across machines](https://coderfriendai.com/features/#capability-88-keep-provider-choices-consistent-across-machines): The portable format can carry provider enablement, endpoints, exact per-mode model selections, favorites, aliases, and other explicit CoderFriend overrides to another installation. Because populated exports contain plaintext secrets, the workflow warns users to keep them private and never commit them.

### 89. Model favorites & aliases
Make a large model catalog feel personal, fast, and task-specific.

- [Favorite frequently used models](https://coderfriendai.com/features/#capability-89-favorite-frequently-used-models): Star models in the picker to keep preferred routes easy to find inside a large live provider catalog. Favorites are stored per provider, survive catalog refreshes, and do not rewrite the underlying model identifier needed for requests, pricing, evaluation, or attribution.
- [Give model identifiers readable aliases](https://coderfriendai.com/features/#capability-89-give-model-identifiers-readable-aliases): Map a memorable local alias to an exact provider model ID when the official identifier is long or operationally awkward. The UI can display and accept the alias while requests, rate lookup, scorecards, and debug output retain the real model identity rather than pricing a nickname.
- [Choose models by provider and working mode](https://coderfriendai.com/features/#capability-89-choose-models-by-provider-and-working-mode): Chat, Plan, Agent, and inline completion each remember their own model selection for every enabled provider. A route optimized for completion therefore does not need to replace the model chosen for autonomous repository work, and switching providers restores that source’s prior mode-specific choices.
- [Control speed and reasoning where supported](https://coderfriendai.com/features/#capability-89-control-speed-and-reasoning-where-supported): Processing speed and reasoning effort are independent selectors backed by provider capabilities rather than generic decorative values. CoderFriend remembers each choice per provider and omits unsupported options from the API request, avoiding silent fallback claims or invalid cross-provider parameters.

### 90. Profiles & guardrails
Save a working style once, then apply it consistently across tasks and providers.

- [Default, Architect, Reviewer, and Explainer profiles](https://coderfriendai.com/features/#capability-90-default-architect-reviewer-and-explainer-profiles): Built-in profiles provide distinct working instructions for general assistance, architecture, evidence-focused review, and clear explanation. Selecting one changes the behavior guidance for the next request while leaving provider, model, permission, sandbox, and resource decisions visible as separate controls.
- [Custom profile instructions](https://coderfriendai.com/features/#capability-90-custom-profile-instructions): Edit the behavioral instructions for Default, Architect, Reviewer, or Explainer conversation profiles. These instructions shape the assistant’s stance and response style; the separate Trust policy controls tool authority, approvals, sandboxing, and budgets.
- [Provider and model exceptions](https://coderfriendai.com/features/#capability-90-provider-and-model-exceptions): Start with one general policy, then define an exception for a provider or an exact provider/model pair whose tools, writes, sandbox, approvals, or budgets need different treatment. Resolution applies the most specific layer at request time so a narrow model cannot inherit broader authority accidentally.
- [Guardrails that travel with the selected profile](https://coderfriendai.com/features/#capability-90-guardrails-that-travel-with-the-selected-profile): The Trust selector resolves a general policy with narrower provider and exact-model exceptions, then applies any machine-level restrictions. Its effective tool, approval, sandbox, and resource limits remain separate from the Profile persona that changes how the assistant explains and approaches a task.

### 91. Prompt caching
Reuse eligible prompt context with supported providers to reduce repeated processing.

- [Provider-aware cache support](https://coderfriendai.com/features/#capability-91-provider-aware-cache-support): CoderFriend formats stable system and repository instruction segments for prompt caching on supported Anthropic, OpenAI, and DeepSeek routes while respecting each provider’s API semantics. Unsupported providers receive normal context without a fake cache claim or incompatible metadata copied from another transport.
- [Cached-token visibility in usage reporting](https://coderfriendai.com/features/#capability-91-cached-token-visibility-in-usage-reporting): The Conversation Usage card records cache reads and writes when a provider reports them and shows cache-hit activity separately from prompt, output, thinking, and tool-result input. Provider-specific cache pricing is used only when the exact rate and complete billable categories are known.
- [Useful for recurring repository context](https://coderfriendai.com/features/#capability-91-useful-for-recurring-repository-context): Stable system guidance, repository instructions, and repeated conversation prefixes can be reused by a provider instead of processed as entirely new input on every Agent step. Cache reads remain visible and priced, but they are excluded from request token ceilings so repetition does not consume the work budget quadratically.

### 92. Usage & cost visibility
Understand what each conversation consumes without leaving the coding flow.

- [Conversation HUD for input, output, and thinking tokens](https://coderfriendai.com/features/#capability-92-conversation-hud-for-input-output-and-thinking-tokens): The sidebar usage card aggregates provider-reported prompt, visible output, separately billed thinking, and total token categories for the current conversation. Counts come from provider boundaries rather than text-length guesses, and unsupported categories remain absent instead of being fabricated for visual consistency.
- [Tool and cache usage visibility](https://coderfriendai.com/features/#capability-92-tool-and-cache-usage-visibility): Where providers expose them, the HUD separates tool-result input, cache reads, cache writes, and cache-hit percentage from ordinary prompt traffic. This helps explain why a long Agent run consumed tokens even when the final visible answer was short, without treating cached input as free or invisible.
- [Estimated cost and turn count](https://coderfriendai.com/features/#capability-92-estimated-cost-and-turn-count): Each completed request contributes a turn and a cost only when the provider reports a charge or an exact provider/model rate can price every billable usage category. Unknown models, mutable unidentified tiers, incomplete usage, and unpriced cache activity make the affected request and aggregate cost N/A.
- [Status-bar usage summary](https://coderfriendai.com/features/#capability-92-status-bar-usage-summary): A compact VS Code status-bar item mirrors the conversation total and exposes the longer provider, model, request, and surface breakdown on hover or click. Users can inspect or reset accounting without expanding the sidebar card, while both controls operate on the same underlying session state.
- [Editable pricing rate table with fail-closed N/A handling](https://coderfriendai.com/features/#capability-92-editable-pricing-rate-table-with-fail-closed-n-a-handling): The bundled exact-model registry can represent provider-specific input, output, cache, request-tier, long-context, and scheduled rate changes and can be updated independently. CoderFriend never substitutes a related family, rolling latest alias, default provider, or invented cache discount when the exact price cannot be established.

### 93. Provider accounts & spending budgets
Pair usage data with account-level limits so cost remains an explicit engineering choice.

- [Provider account and balance views](https://coderfriendai.com/features/#capability-93-provider-account-and-balance-views): Account and Usage opens one row per configured provider with locally measured spend for the active period and direct links to authoritative usage and billing consoles. A fetched balance appears only where the provider publishes a supported endpoint; otherwise the console link is presented as the real source.
- [Fetched balance support for DeepSeek and OpenRouter](https://coderfriendai.com/features/#capability-93-fetched-balance-support-for-deepseek-and-openrouter): DeepSeek can report an account balance through its supported endpoint. OpenRouter reports the remaining cap of the current API key; an uncapped key has no numeric remainder. These fetched values remain separate from extension-recorded spend and the provider’s full account invoice.
- [Local spending-budget controls](https://coderfriendai.com/features/#capability-93-local-spending-budget-controls): Set an advisory USD ceiling for the current session, day, or month of extension-recorded provider spend. The usage card warns at 80% and at the ceiling; separate root-request and delegation budgets enforce execution limits. Unknown charges remain visible as incomplete accounting, and local inference is excluded from the spend ledger.
- [Budget context beside provider usage](https://coderfriendai.com/features/#capability-93-budget-context-beside-provider-usage): The account surface shows recorded spend in the context of the configured period and ceiling, helping users distinguish conversation cost, extension-tracked provider spend, fetched account balance, and the provider’s authoritative invoice. Those numbers are labeled separately because they answer different questions.

### 94. Managed Git worktrees
Give concurrent or risky work an isolated branch and filesystem without leaving CoderFriend.

- [Create and manage Git worktrees](https://coderfriendai.com/features/#capability-94-create-and-manage-git-worktrees): Create a managed Git worktree from a selected repository and branch so isolated Agent work has its own filesystem and index. CoderFriend records the session, path, branch, status, and cleanup state, making concurrent work discoverable instead of leaving anonymous folders beside the main checkout.
- [Run isolated implementation tasks](https://coderfriendai.com/features/#capability-94-run-isolated-implementation-tasks): A background Agent can implement a focused assignment inside the managed worktree while the foreground conversation and primary checkout remain available. The run uses its own bounded provider snapshot, policy, iterations, verification, review rounds, and cancellation state rather than sharing mutable foreground execution.
- [Inspect worktree diffs before integration](https://coderfriendai.com/features/#capability-94-inspect-worktree-diffs-before-integration): Completed sessions expose their changed files, Git diff, report, verification outcome, and remaining review findings before any merge or cherry-pick decision. CoderFriend does not silently integrate isolated changes into the main branch merely because the background Agent reached a completed state.
- [Keep the primary workspace available](https://coderfriendai.com/features/#capability-94-keep-the-primary-workspace-available): Because implementation happens in another Git worktree, developers can continue reading, editing, testing, or discussing the main checkout without switching branches underneath active editor tabs. File-lock and run identity still make conflicting targets visible when foreground and background work could overlap.

### 95. Background Agent runs
Let longer tasks continue outside the foreground conversation while you keep working.

- [Launch Agent work in the background](https://coderfriendai.com/features/#capability-95-launch-agent-work-in-the-background): Run Agent in Background creates a durable run for a concrete task and executes it outside the foreground chat turn in a managed worktree. Configured concurrency limits prevent every queued idea from starting at once, while the user remains free to continue another conversation.
- [Review progress and completion reports](https://coderfriendai.com/features/#capability-95-review-progress-and-completion-reports): The Background Agent Runs view shows queued, running, completed, failed, cancelled, and interrupted state together with bounded progress and a final report. Users can inspect what the run understood, changed, checked, and could not finish without reopening the original launch prompt from memory.
- [Inspect resulting diffs](https://coderfriendai.com/features/#capability-95-inspect-resulting-diffs): Every background implementation retains an inspectable worktree diff and changed-file set connected to its report and review output. This lets maintainers verify the actual patch, not merely trust a completion sentence, before choosing how or whether to integrate the branch.
- [Cancel a background run](https://coderfriendai.com/features/#capability-95-cancel-a-background-run): A queued or running background Agent can be cancelled from its management surface, threading cancellation into provider calls, tools, commands, review rounds, and cleanup. The run records the cancellation rather than disappearing, preserving enough evidence to inspect partial work and remove its worktree deliberately.

### 96. Bounded specialist subagents
Delegate focused investigation without handing every helper unrestricted control of the workspace.

- [Researcher, Architect, Reviewer, and Tester roles](https://coderfriendai.com/features/#capability-96-researcher-architect-reviewer-and-tester-roles): The coordinating Agent can spawn bounded specialists with explicit Researcher, Architect, Reviewer, or Tester roles when a task benefits from parallel expertise. Each role receives a concrete assignment and relevant shared context rather than a vague instruction to solve the whole request independently.
- [Read-only specialist execution](https://coderfriendai.com/features/#capability-96-read-only-specialist-execution): Subagents investigate with bounded file, search, semantic, documentation, and approved information tools but do not mutate the workspace or run unrestricted implementation work. Sensitive paths remain blocked because delegated workers have no interactive secret-approval channel, keeping authority with the foreground coordinator.
- [Explicit task and resource bounds](https://coderfriendai.com/features/#capability-96-explicit-task-and-resource-bounds): Every child has configurable iteration, token, exact-cost, and wall-clock limits plus a parent-wide concurrency and resource pool. The spawn request identifies the assignment and expected output, so a specialist cannot silently turn one narrow question into an unlimited second Agent project.
- [Results returned to the coordinating Agent](https://coderfriendai.com/features/#capability-96-results-returned-to-the-coordinating-agent): A completed child returns bounded findings, evidence, and status to the parent, which remains responsible for synthesis and any workspace mutation. list_subagents and get_subagent_result also let the coordinator inspect asynchronous progress without duplicating the specialist’s paid investigation.

### 97. Shared plans & delegated review
Coordinate larger tasks through visible plans, reusable artifacts, and deliberate specialist handoffs.

- [Shared task plans and progress state](https://coderfriendai.com/features/#capability-97-shared-task-plans-and-progress-state): set_task_plan creates a dependency-aware task graph with explicit pending, in-progress, completed, and blocked state that the parent and supported collaborators can inspect. Updates remain tied to named tasks, making parallel progress and unfinished dependencies visible rather than inferred from scattered chat messages.
- [Artifacts that survive across delegated steps](https://coderfriendai.com/features/#capability-97-artifacts-that-survive-across-delegated-steps): write_artifact, read_artifact, and list_artifacts provide a request-scoped channel for bounded research notes, decisions, and task results that are not workspace files. Parent and child Agents can exchange evidence without creating temporary repository documents or confusing an artifact name with a filesystem path.
- [Automatic specialist dispatch where appropriate](https://coderfriendai.com/features/#capability-97-automatic-specialist-dispatch-where-appropriate): dispatch_ready_tasks finds graph nodes whose dependencies are complete and launches suitable specialist assignments within the configured concurrency and budget. It writes child findings back into task-result artifacts and task state, allowing the coordinator to continue when parallel work becomes ready instead of polling manually.
- [Reviewer-to-repair handoff](https://coderfriendai.com/features/#capability-97-reviewer-to-repair-handoff): A reviewer can produce structured findings that a foreground Agent or isolated background worktree receives as a concrete repair assignment. Follow-up review can confirm the fix within bounded rounds, preserving evidence and avoiding an unstructured cycle where the same model repeatedly critiques its own prose.

### 98. Provider-attributed commit messages
Generate a concise commit message from the intended diff with clear model attribution.

- [Generate a commit message from repository changes](https://coderfriendai.com/features/#capability-98-generate-a-commit-message-from-repository-changes): Generate Commit Message reads the intended Git diff and writes a concise summary into the Source Control input box rather than committing automatically. Users can inspect and edit the message with the exact change set still visible, keeping the final commit operation under normal Git control.
- [Prefix output with the active provider and model](https://coderfriendai.com/features/#capability-98-prefix-output-with-the-active-provider-and-model): By default, generated and Agent-created commit messages begin with the provider and exact model captured for the active run, such as OpenAI gpt-5.6-sol:. Attribution is resolved immediately before execution so it cannot drift to a later setting or claim a model that did not produce the work.
- [Respect configured file exclusions](https://coderfriendai.com/features/#capability-98-respect-configured-file-exclusions): commitMessagePrefixExcludedFolders can omit model attribution for selected absolute paths, workspace-relative folders, folder names, and descendant repositories. This supports projects whose contribution policy forbids prefixes without disabling transparent attribution everywhere else.
- [Keep the final commit under your control](https://coderfriendai.com/features/#capability-98-keep-the-final-commit-under-your-control): Message generation fills the SCM input and normal Agent Git commands remain subject to command policy, risk classification, sandbox boundaries, and repository instructions. CoderFriend does not treat a suggested message as authorization to commit, rewrite history, or push changes to a remote.

### 99. Live provider model catalogs
Build each picker from the models the selected provider actually exposes, while keeping provider catalogs isolated from one another.

- [Discover current models from supported provider catalog APIs](https://coderfriendai.com/features/#capability-99-discover-current-models-from-supported-provider-catalog-apis): When a provider exposes a model-list API, CoderFriend fetches and normalizes the current catalog for that source instead of relying only on a frozen dropdown. Enablement settings can hide routes, while favorite, alias, and mode selections layer onto the live exact identifiers returned.
- [Use authenticated Codex app-server model listings for ChatGPT routes](https://coderfriendai.com/features/#capability-99-use-authenticated-codex-app-server-model-listings-for-chatgpt-routes): Codex model choices come from account/read followed by the authenticated app-server model/list response associated with the user’s ChatGPT session. Cached or configured models from OpenAI API and other providers are never mixed into that picker, preserving the subscription route’s actual availability.
- [Discover models from local and cloud Ollama endpoints](https://coderfriendai.com/features/#capability-99-discover-models-from-local-and-cloud-ollama-endpoints): CoderFriend queries the selected local or cloud Ollama endpoint for the models it currently serves and keeps each catalog attached to its route. A local model can appear without an API key, while cloud discovery uses only the Ollama Cloud credential and configured compatible endpoint.
- [Cache a provider catalog without mixing it into another provider](https://coderfriendai.com/features/#capability-99-cache-a-provider-catalog-without-mixing-it-into-another-provider): Provider catalogs and selections remain associated with their source so models from another API, local server, or subscription account cannot enter the wrong picker. Codex availability is checked against its authenticated catalog rather than treating an old cached list as permission to start a request.
- [Retain a usable configured fallback when a live catalog is unavailable](https://coderfriendai.com/features/#capability-99-retain-a-usable-configured-fallback-when-a-live-catalog-is-unavailable): Where a provider supports a configured fallback, a failed catalog refresh can keep that provider’s exact selection available for recovery. Codex is stricter: authenticated model listings are authoritative, failed refreshes clear stale choices, and every request must use a currently listed model. LM Studio has no invented default model.

### 100. Provider-specific model memory
Remember the right model and generation controls for each provider and working mode instead of forcing one global compromise.

- [Remember separate Chat, Plan, Agent, and completion models per provider](https://coderfriendai.com/features/#capability-100-remember-separate-chat-plan-agent-and-completion-models-per-provider): Each provider stores four distinct model choices for answer-oriented chat, planning, tool-using Agent work, and inline completion. Returning to a provider restores its prior selections, letting a fast completion model and stronger planning model coexist without repeated picker cleanup.
- [Remember reasoning effort separately for each provider](https://coderfriendai.com/features/#capability-100-remember-reasoning-effort-separately-for-each-provider): Reasoning selection is stored with the provider because supported values and semantics differ across model APIs. Switching sources restores the relevant choice, and the resolved client omits reasoning metadata when the active route does not advertise or implement it.
- [Remember processing speed separately for each provider](https://coderfriendai.com/features/#capability-100-remember-processing-speed-separately-for-each-provider): A supported service-tier or processing-speed choice belongs to the provider that offers it rather than a global fast-mode flag. CoderFriend restores that route’s setting and avoids sending a tier copied from another API whose names, costs, or availability differ.
- [Omit unsupported controls from provider requests](https://coderfriendai.com/features/#capability-100-omit-unsupported-controls-from-provider-requests): Provider configuration resolves model capabilities before serializing speed, reasoning, image, caching, or other optional fields. A visible value saved for one route is not blindly injected into every request, reducing hard API failures and misleading claims that a provider honored an unsupported control.
- [Switch selectors without sending a message](https://coderfriendai.com/features/#capability-100-switch-selectors-without-sending-a-message): Changing provider, model, mode, speed, reasoning, context, detail, profile, or policy updates the prepared next-request state only. No token usage, remote call, or conversation turn is created until the user submits a message, making exploration and comparison safe.

### 101. Provider authentication recovery
Recognize expired or missing provider authentication and guide the user back to a valid connection without losing the active workflow.

- [Reuse an existing Codex CLI or OpenAI extension ChatGPT session](https://coderfriendai.com/features/#capability-101-reuse-an-existing-codex-cli-or-openai-extension-chatgpt-session): CoderFriend discovers the Codex executable on PATH or inside the supported OpenAI VS Code extension and asks its app server for the current account. A valid shared ChatGPT login is reused directly, avoiding a second credential store or redundant browser authorization flow.
- [Start browser authentication automatically when Codex needs it](https://coderfriendai.com/features/#capability-101-start-browser-authentication-automatically-when-codex-needs-it): If account lookup, catalog discovery, or a later Codex request reveals no valid ChatGPT session, CoderFriend starts the official login flow and opens its HTTPS authorization URL. The UI waits for completion and reports failure clearly if the link cannot be opened or authentication is cancelled.
- [Retry one interrupted Codex catalog or request after sign-in](https://coderfriendai.com/features/#capability-101-retry-one-interrupted-codex-catalog-or-request-after-sign-in): After successful authentication, the exact catalog lookup or model request that discovered expiration is retried once using the refreshed account. A second authentication failure stops rather than looping browser flows, and the user can invoke Connect Codex manually when a deliberate retry is needed.
- [Discover Claude Code from PATH, a home install, or its VS Code extension](https://coderfriendai.com/features/#capability-101-discover-claude-code-from-path-a-home-install-or-its-vs-code-extension): Subscription transport searches the extension-host PATH, common Claude Code home installation, and the installed Anthropic VS Code extension before requiring a custom binary setting. The error names the missing executable and setup path on the first failure so users can repair the real environment.
- [Surface empty-account and billing refusals with provider-specific actions](https://coderfriendai.com/features/#capability-101-surface-empty-account-and-billing-refusals-with-provider-specific-actions): When a provider refuses a request because an account has no funds or a billing condition needs attention, CoderFriend preserves the provider’s useful sentence and links to the relevant console action. Billing refusals are not retried as transient network failures, avoiding repeated paid attempts with no chance of success.

### 102. Durable usage accounting
Account for model work at the provider boundary and preserve measured totals with the conversation that produced them.

- [Track prompt, visible output, thinking, tool-result, and cache tokens](https://coderfriendai.com/features/#capability-102-track-prompt-visible-output-thinking-tool-result-and-cache-tokens): Usage normalization keeps the token categories each provider actually reports: prompt input, visible output, separately billed thinking, tool-result input, cache reads, and cache writes. Aggregates retain those distinctions so a total does not hide whether cost came from reasoning, repeated context, tool data, or the answer itself.
- [Attribute usage to sidebar, native chat, inline, evaluation, reviewer, retry, and delegated surfaces](https://coderfriendai.com/features/#capability-102-attribute-usage-to-sidebar-native-chat-inline-evaluation-reviewer-retry-and-delegated-surfaces): Every provider call includes a call-kind and request context covering sidebar and native chat, inline chat and completion, generated actions, evaluations, background Agents, planners, summaries, reviewers, retries, and subagents. The By Surface view exposes those categories under one consistent accounting rule.
- [Show each root request separately from aggregate surface totals](https://coderfriendai.com/features/#capability-102-show-each-root-request-separately-from-aggregate-surface-totals): Recent Requests keeps every foreground or continued root Agent round as its own row with calls, iterations, duration, usage, model, and cost status. By Surface then aggregates comparable work, letting users inspect one surprising request without losing the broader conversation picture.
- [Restore saved conversation totals after reload or reopening](https://coderfriendai.com/features/#capability-102-restore-saved-conversation-totals-after-reload-or-reopening): Normalized usage state is saved with the conversation and loaded when that thread becomes active again, including after an extension-host reload. Reopening history therefore restores the work’s measured totals, while starting, clearing, or deleting a conversation produces the appropriate fresh state.
- [Preserve token counts when exact provider cost is unavailable](https://coderfriendai.com/features/#capability-102-preserve-token-counts-when-exact-provider-cost-is-unavailable): A ChatGPT or Claude subscription response, unknown exact model, incomplete usage payload, or unreported mutable tier may prevent reliable USD pricing without invalidating reported tokens. CoderFriend continues to show those categories and explains why only the monetary total is unavailable.
- [Show N/A instead of inventing an uncertain charge](https://coderfriendai.com/features/#capability-102-show-n-a-instead-of-inventing-an-uncertain-charge): If any contributing paid request cannot be priced exactly, its request, surface, and complete conversation cost become N/A with a reason instead of treating uncertainty as zero. The calculator never borrows another provider’s rate, guesses a family default, or prices a rolling alias as a fixed release.

### 103. Live pricing & account budgets
Combine an editable exact-model rate registry with provider account links, measured spend, and configurable budget periods.

- [Refresh supported model prices on demand](https://coderfriendai.com/features/#capability-103-refresh-supported-model-prices-on-demand): Update Model Prices and /priceupdate fetch or rebuild the supported exact-model rate registry when current published pricing is needed. The update path validates the resulting data and leaves existing rates intact on failure rather than replacing the calculator with a partial or malformed table.
- [Schedule bounded model-price updates](https://coderfriendai.com/features/#capability-103-schedule-bounded-model-price-updates): Enable automatic price updates and choose the interval used to refresh supported rate data in the background. Scheduling is bounded and optional, and it does not make a model priceable unless its exact provider identity and required usage categories are present in the registry.
- [Use provider-reported request charges when available](https://coderfriendai.com/features/#capability-103-use-provider-reported-request-charges-when-available): A provider’s explicit per-request cost takes precedence over local estimation because it can reflect the actual tier and billing rules served. CoderFriend retains that charge with its request and aggregates it normally, while still showing the underlying reported token categories for audit.
- [Show fetched balances where a provider exposes them](https://coderfriendai.com/features/#capability-103-show-fetched-balances-where-a-provider-exposes-them): The Account view fetches DeepSeek account balances and OpenRouter API-key cap remainders through their supported endpoints. A key cap is labeled separately from a provider account balance, and an uncapped or unsupported account links to its authoritative console instead of displaying a fabricated number.
- [Compare locally recorded spend with a configured budget period](https://coderfriendai.com/features/#capability-103-compare-locally-recorded-spend-with-a-configured-budget-period): Compare extension-recorded charges across session, day, or month windows without restarting accounting when you change the displayed period. Budget warnings describe the observed spend, not an account balance or billing stop; separate request limits control autonomous execution.

### 104. Dependency-aware task engine
Represent larger work as a shared task graph so ready work, blocked dependencies, artifacts, and completion state remain inspectable.

- [Create a shared plan with set_task_plan](https://coderfriendai.com/features/#capability-104-create-a-shared-plan-with-set_task_plan): set_task_plan records a bounded list of concrete tasks, dependency relationships, and initial state for the current coordinated request. The plan is visible as operational state rather than hidden model reasoning, and it can be updated as evidence changes without rewriting completed task results.
- [Inspect all tasks and dependency state with list_tasks](https://coderfriendai.com/features/#capability-104-inspect-all-tasks-and-dependency-state-with-list_tasks): list_tasks returns every shared task with its status, dependencies, assignment, and bounded result references. The coordinator can see which work is pending, active, complete, or blocked before spawning more help, reducing duplicated investigation and impossible out-of-order execution.
- [Find unblocked work with get_ready_tasks](https://coderfriendai.com/features/#capability-104-find-unblocked-work-with-get_ready_tasks): get_ready_tasks filters the shared graph to tasks whose dependencies are satisfied and that are not already running or complete. This gives the Agent a deterministic set of safe next assignments rather than relying on a language model to remember the entire dependency graph from prose.
- [Update one task explicitly with task_status](https://coderfriendai.com/features/#capability-104-update-one-task-explicitly-with-task_status): task_status changes a named task to the appropriate lifecycle state and can attach a bounded outcome or blocker. Explicit updates let the UI and dispatch logic distinguish genuine completion from an Agent merely mentioning that a task appears finished in its conversational answer.
- [Dispatch ready specialist work with dispatch_ready_tasks](https://coderfriendai.com/features/#capability-104-dispatch-ready-specialist-work-with-dispatch_ready_tasks): dispatch_ready_tasks launches eligible tasks as bounded subagents up to the configured concurrency, role, and parent resource limits. Completed findings are connected back to their task and artifact automatically, while launch failures and cancellations remain visible to the coordinating Agent.
- [Exchange bounded findings through named task artifacts](https://coderfriendai.com/features/#capability-104-exchange-bounded-findings-through-named-task-artifacts): Named artifacts carry plans, research, test observations, review findings, and task-result text between collaborators without writing them into the codebase. Size, scope, and tool separation keep the channel inspectable, and an Agent must use artifact tools rather than pretending the names are ordinary file paths.

### 105. Live subagent console
See delegated specialists as active parts of the request instead of receiving an unexplained combined answer at the end.

- [Show each child role, assignment, status, and elapsed time](https://coderfriendai.com/features/#capability-105-show-each-child-role-assignment-status-and-elapsed-time): The Working card presents a collapsible row for every delegated child with its specialist role, concrete assignment, queued or running state, and elapsed active time. Users can see why each subagent exists and whether parallelism is making progress before the parent produces its final synthesis.
- [Show child iteration and recent safe tool summaries](https://coderfriendai.com/features/#capability-105-show-child-iteration-and-recent-safe-tool-summaries): Each expanded child row reports its bounded iteration count and recent sanitized operation summaries such as files read, searches run, or documentation inspected. Raw private reasoning, sensitive paths, and oversized protocol payloads are excluded, preserving useful operational transparency without turning activity into a secret leak.
- [Preview bounded findings without exposing private reasoning](https://coderfriendai.com/features/#capability-105-preview-bounded-findings-without-exposing-private-reasoning): A completed specialist can show a short preview of its final evidence and recommendation directly in the activity panel. The preview is redacted and size-limited and represents the child’s reported result, not hidden chain-of-thought or an unlimited transcript of its internal model exchange.
- [Explain child failure and cancellation states](https://coderfriendai.com/features/#capability-105-explain-child-failure-and-cancellation-states): Failed, timed-out, budget-stopped, parent-cancelled, and otherwise interrupted children retain a concise reason instead of collapsing into a generic missing result. The parent can decide whether to proceed with other evidence, retry deliberately, or report the unresolved assignment honestly.
- [Include delegated usage in the parent conversation HUD](https://coderfriendai.com/features/#capability-105-include-delegated-usage-in-the-parent-conversation-hud): Provider calls made by subagents inherit the root accounting context and appear in recent-request and per-surface usage alongside the parent. Their token categories and exact measurable cost count toward the conversation and shared budgets rather than being hidden as free parallel work.

### 106. Hierarchical delegation budgets
Bound each specialist and the parent-wide pool so parallel investigation cannot silently exceed the request’s intended cost or time.

- [Set per-child token, exact-cost, iteration, and wall-clock limits](https://coderfriendai.com/features/#capability-106-set-per-child-token-exact-cost-iteration-and-wall-clock-limits): Each spawned specialist receives independent ceilings for non-cache token usage, exact measurable USD cost, model iterations, and elapsed execution time. Reaching one stops that child and records the reason without automatically erasing useful findings already returned by other specialists.
- [Set parent-wide token, exact-cost, concurrency, and time limits](https://coderfriendai.com/features/#capability-106-set-parent-wide-token-exact-cost-concurrency-and-time-limits): The coordinating request also owns a shared pool across every queued and running child, plus maximum child count and concurrency. These limits prevent many individually acceptable specialists from collectively exceeding the user’s intended resource envelope.
- [Charge measured provider usage before another delegated step](https://coderfriendai.com/features/#capability-106-charge-measured-provider-usage-before-another-delegated-step): After every child model response, reported tokens and exact provider or exact-rate cost are added to both child and shared usage before the loop can call another model or tool. Enforcement therefore acts on completed paid work immediately instead of checking only after the specialist finishes its whole assignment.
- [Cancel queued and running children when the shared ceiling is reached](https://coderfriendai.com/features/#capability-106-cancel-queued-and-running-children-when-the-shared-ceiling-is-reached): When the parent-wide token, exact-cost, or time budget is exhausted, CoderFriend prevents later spawns and cancels every queued or active child in that coordination scope. The activity panel records the shared-budget stop so simultaneous cancellations have one understandable cause.
- [Continue token and time safeguards when exact cost is unavailable](https://coderfriendai.com/features/#capability-106-continue-token-and-time-safeguards-when-exact-cost-is-unavailable): A provider or subscription transport that cannot expose exact USD cost shows N/A and makes cost enforcement unavailable rather than treating the call as free. Token, iteration, child-count, concurrency, and wall-clock limits continue to bound delegated work using the measurements that remain trustworthy.

### 107. Desktop Agent Dashboard
Follow several Trusted Agent sessions at once from a dedicated desktop board, without giving up the focused mobile Remote Control experience.

- [Watch four runs in one view](https://coderfriendai.com/features/#capability-107-watch-four-runs-in-one-view): Keep up to four independent editor sessions visible as separate panes on one desktop screen.
- [Search and assign a session to a pane](https://coderfriendai.com/features/#capability-107-search-and-assign-a-session-to-a-pane): Find an armed editor window and place it deliberately on the board.
- [Use the board as a paired device](https://coderfriendai.com/features/#capability-107-use-the-board-as-a-paired-device): Pair the desktop board with the same verified-code and fingerprint flow used by a phone.
- [Keep a window focused on one viewer](https://coderfriendai.com/features/#capability-107-keep-a-window-focused-on-one-viewer): Prevent simultaneous viewing conflicts by reserving each watched window for a single remote device.

### 108. Readable live Agent transcript
Keep a fast-moving remote Agent run readable on a phone or desktop while it continues in the editor.

- [Fold streaming assistant output into readable updates](https://coderfriendai.com/features/#capability-108-fold-streaming-assistant-output-into-readable-updates): Grow consecutive assistant text in place instead of flooding the transcript with token-sized rows.
- [Keep progress compact](https://coderfriendai.com/features/#capability-108-keep-progress-compact): Update one live status line rather than adding a new transcript entry for every progress change.
- [Respect your reading position](https://coderfriendai.com/features/#capability-108-respect-your-reading-position): Pause automatic following when you scroll back through an active run.
- [Jump back to the live run when ready](https://coderfriendai.com/features/#capability-108-jump-back-to-the-live-run-when-ready): Return to the newest Agent activity with a dedicated live-position action.
- [Restore a coherent session after reconnecting](https://coderfriendai.com/features/#capability-108-restore-a-coherent-session-after-reconnecting): Reconcile snapshots and completed runs without duplicating stale status entries.
- [Resume the encrypted remote transport](https://coderfriendai.com/features/#capability-108-resume-the-encrypted-remote-transport): Reconnect the remote viewer and continue from the correct sealed frame sequence after a network interruption.

### 109. Phone-based Trusted Agent control
Follow a live Trusted Agent run from a paired iPhone or Android phone without exposing workspace-wide controls.

- [Watch the agent transcript as it happens](https://coderfriendai.com/features/#capability-109-watch-the-agent-transcript-as-it-happens): Follow live progress away from the editor while the desktop remains the source of workspace context.
- [Send steering messages to an active run](https://coderfriendai.com/features/#capability-109-send-steering-messages-to-an-active-run): Redirect or clarify the current task from the paired phone without opening a separate conversation.
- [Stop a run remotely when needed](https://coderfriendai.com/features/#capability-109-stop-a-run-remotely-when-needed): End the active agent run from the phone when its direction or timing no longer fits.
- [Discover armed editor windows](https://coderfriendai.com/features/#capability-109-discover-armed-editor-windows): Search for available Remote Control sessions and choose the intended repository, computer, and VS Code window.
- [Limit remote control to Trusted Agent](https://coderfriendai.com/features/#capability-109-limit-remote-control-to-trusted-agent): Keep the feature unavailable in modes that can pause for approvals the remote viewer cannot safely judge.

### 110. One phone, multiple desktops
Use one paired phone to find, open, and follow Remote Control sessions across multiple computers and VS Code windows from a shared desktop board.

- [Control multiple desktops from one phone](https://coderfriendai.com/features/#capability-110-control-multiple-desktops-from-one-phone): Pair once for each CoderFriend installation, then use the phone’s desktop board to move among the computers and workspaces available to you.
- [See each VS Code window as its own session](https://coderfriendai.com/features/#capability-110-see-each-vs-code-window-as-its-own-session): Keep simultaneous projects distinguishable instead of collapsing every open editor on a computer into one ambiguous destination.
- [Watch a session from another VS Code window](https://coderfriendai.com/features/#capability-110-watch-a-session-from-another-vs-code-window): Open the shared board on a second desktop window to follow an active remote conversation without taking over its editor.
- [Keep pairing changes synchronized](https://coderfriendai.com/features/#capability-110-keep-pairing-changes-synchronized): Phones paired or revoked in one window are reflected across the other participating windows, so the board stays current.
- [Open a focused desktop board](https://coderfriendai.com/features/#capability-110-open-a-focused-desktop-board): Use a dedicated board with recognizable window identity, built-in help, and a maximized view for monitoring several sessions.

### 111. Visible provider and model attribution
See which provider route and model produced a response, including runs selected through profiles or subscription transports.

- [See which model handled the request](https://coderfriendai.com/features/#capability-111-see-which-model-handled-the-request): Show the resolved model with the conversation response or run details rather than making you infer it from the answer.
- [Identify the provider route](https://coderfriendai.com/features/#capability-111-identify-the-provider-route): Distinguish API, local, Codex, Claude subscription, and other configured transports when comparing results.
- [Confirm profile-selected models](https://coderfriendai.com/features/#capability-111-confirm-profile-selected-models): Make the effective choice visible when a guardrail or runtime profile supplies provider and model settings.
- [Trace fallbacks without guesswork](https://coderfriendai.com/features/#capability-111-trace-fallbacks-without-guesswork): Preserve the actual route used when availability or configuration causes execution to differ from the composer’s initial choice.

### 112. SSH uploads to live servers
Move an explicitly selected local file to a connected live server through the guarded SSH workflow.

- [Upload one named local file deliberately](https://coderfriendai.com/features/#capability-112-upload-one-named-local-file-deliberately): Use the dedicated SSH upload tool rather than hiding a transfer inside a generic shell command.
- [Validate both ends of the transfer](https://coderfriendai.com/features/#capability-112-validate-both-ends-of-the-transfer): Apply workspace path policy to the local source and live-server safety rules to the remote destination.
- [Keep server identity visible](https://coderfriendai.com/features/#capability-112-keep-server-identity-visible): Tie the upload to the active live-server connection so the destination host is not inferred from an arbitrary command.
- [Respect the current approval mode](https://coderfriendai.com/features/#capability-112-respect-the-current-approval-mode): Route file transfer through the same resolved authority and confirmation controls as other live-server changes.

### 113. Live-server reconnect and resume
Recover interrupted remote work by reconnecting to the intended server before a resumable Agent task continues.

- [Keep a disconnected server visible](https://coderfriendai.com/features/#capability-113-keep-a-disconnected-server-visible): Preserve the live-server row and its last known state when the connection ends instead of making the target disappear.
- [Offer reconnection where work can continue](https://coderfriendai.com/features/#capability-113-offer-reconnection-where-work-can-continue): Surface a reconnect action in the composer and status banner when an interrupted task still has a usable server target.
- [Refuse unsafe blind resumes](https://coderfriendai.com/features/#capability-113-refuse-unsafe-blind-resumes): Do not resume remote work when no live-server connection exists to establish where later commands would run.
- [Report the failed remote stage](https://coderfriendai.com/features/#capability-113-report-the-failed-remote-stage): Identify the SSH or remote execution step that interrupted the run so recovery starts from concrete evidence.

### 114. Web research with Claude subscription
Use Claude Code web search and page retrieval in Chat and Agent without switching away from subscription mode.

- [Research the web from Claude subscription runs](https://coderfriendai.com/features/#capability-114-research-the-web-from-claude-subscription-runs): Claude Code WebSearch and WebFetch are available alongside its normal tool loop when web tools are enabled.
- [Use the same web-tools preference across providers](https://coderfriendai.com/features/#capability-114-use-the-same-web-tools-preference-across-providers): The existing web-tool setting governs Claude subscription access as well as other provider transports, keeping the control in one place.
- [Keep web access opt-in](https://coderfriendai.com/features/#capability-114-keep-web-access-opt-in): Turning web tools off removes those Claude Code tools, so a local or restricted workflow stays restricted.

### 115. LM Studio local models
Use models served by LM Studio on your own machine in the same CoderFriend workspace.

- [Connect to a local LM Studio server](https://coderfriendai.com/features/#capability-115-connect-to-a-local-lm-studio-server): Start the LM Studio server and select LM Studio (Local). The default endpoint is http://localhost:1234/v1; configure the matching loopback port when your server uses another one. Plain HTTP on a non-loopback LAN address is not supported.
- [Choose from the models your server provides](https://coderfriendai.com/features/#capability-115-choose-from-the-models-your-server-provides): The picker reads the running server’s model list and filters embedding and reranking names from chat choices. No model is assumed to be installed: select one you have downloaded and made available in LM Studio.
- [Use no key unless local authentication is enabled](https://coderfriendai.com/features/#capability-115-use-no-key-unless-local-authentication-is-enabled): LM Studio works without an API key by default. If its optional Require Authentication setting is enabled, supply the token through secure provider setup or LM_API_TOKEN; an unsecured local server needs neither.
- [Use model-dependent Agent tools and completion](https://coderfriendai.com/features/#capability-115-use-model-dependent-agent-tools-and-completion): LM Studio can serve Chat, Plan, Agent, and completion requests. Tool calling and image understanding depend on the selected model; CoderFriend does not offer an LM Studio reasoning-effort control or native web-search capability that the server cannot honor.
- [Track local tokens without charging a spending budget](https://coderfriendai.com/features/#capability-115-track-local-tokens-without-charging-a-spending-budget): Supported LM Studio versions report streamed usage, allowing token totals and context controls to work. Local inference is excluded from the spending ledger; monetary cost remains N/A rather than an invented provider charge.

### 116. Agent work beyond the editor window
Optionally continue compatible background work in a detached process and review its recorded outcome later.

- [Continue compatible runs after closing VS Code](https://coderfriendai.com/features/#capability-116-continue-compatible-runs-after-closing-vs-code): Enable detachedBackgroundRuns to launch supported background Agent tasks independently of the editor window. API-backed routes, Ollama Local, and LM Studio can use this workflow; Codex and Claude subscription sessions stay in the editor because their login belongs to the desktop session.
- [Inspect recorded progress from another window](https://coderfriendai.com/features/#capability-116-inspect-recorded-progress-from-another-window): A detached run writes a bounded progress journal and final outcome that another CoderFriend window can inspect. The UI distinguishes completed, failed, cancelled, and interrupted work instead of silently replaying an abandoned task.
- [Stop or steer a run from another window](https://coderfriendai.com/features/#capability-116-stop-or-steer-a-run-from-another-window): Background run controls can address the current owner to request cancellation or send steering. Directions are applied at safe work boundaries, preserving the task’s isolated worktree and its resource limits.
- [Review the worktree before integration](https://coderfriendai.com/features/#capability-116-review-the-worktree-before-integration): Detached execution belongs to the existing background-worktree workflow. Its result and diff remain reviewable before integration, so closing the foreground editor does not implicitly approve changes to the primary workspace.

### 117. GitHub issue-to-review workflow
Connect issue context, local branch work, pull-request feedback, and explicit publishing actions through the GitHub CLI.

- [Start a task from a GitHub issue](https://coderfriendai.com/features/#capability-117-start-a-task-from-a-github-issue): Provide an issue number or GitHub issue URL to load its context and create or reuse a task branch. A signed-in GitHub CLI and an open workspace are required; an existing related pull request can be reused deliberately.
- [Inspect the connected account and task status](https://coderfriendai.com/features/#capability-117-inspect-the-connected-account-and-task-status): GitHub connection and status commands show the authenticated account and scopes, repository, branch, available pull request, checks, and current authority summary. These views keep external work tied to a visible account and repository.
- [Turn pull-request feedback into a repair request](https://coderfriendai.com/features/#capability-117-turn-pull-request-feedback-into-a-repair-request): Load review comments and failed checks from the current branch’s pull request into an Agent repair request. The prompt keeps push, commenting, and check reruns as separate external actions.
- [Re-run failed checks with explicit confirmation](https://coderfriendai.com/features/#capability-117-re-run-failed-checks-with-explicit-confirmation): The failed-check command asks before starting GitHub workflow runs. It then reports the actual rerun result rather than treating a local repair as proof that remote checks passed.
- [Push and open a draft pull request deliberately](https://coderfriendai.com/features/#capability-117-push-and-open-a-draft-pull-request-deliberately): On a non-default branch, the draft command checks for an existing pull request, then asks before pushing the branch and opening a draft against the repository default. The draft can be reviewed before later merge decisions.
