Features

The complete CoderFriend system

One workspace for every part of the coding loop.

Bring your models, project knowledge, tools, and safety controls into one VS Code workflow—then move from a question to a verified change without losing context.

117feature systems 533documented capabilities 12model sources
01 / LIVING CONTEXTYour project.In every answer.

01 / LIVING CONTEXT

Your project.
In every answer.

Bring selected code, workspace search, and repository instructions into the conversation. Give each task the context it needs before the first edit.

Explore context tools
Four connected layers

Not a chat box. A complete coding system.

Every layer is useful on its own. Together, they keep the model informed, the work visible, and you in control.

01

AI workspace

Three working modes, editor-native actions, and a live Agent cockpit built around the way you already code.

Chat · Plan · Agent · Inline Explore workspace features
02

Living context

Files, ranked search, repository rules, docs, skills, images, and MCP sources assembled for the task.

Repository · Docs · Skills · MCP Explore context features
03

Safe execution

Approvals, sandboxes, atomic edits, code review, runtime proof, and recovery tools for deliberate autonomy.

Approve · Review · Verify · Restore Explore safety features
04

Models & orchestration

Local, subscription, and API routes coordinated through profiles, worktrees, background runs, and subagents.

12 sources · Worktrees · Subagents Explore orchestration features
Full feature catalog

Find the capability your workflow needs.

Search the complete CoderFriend AI system or filter by the layer you want to explore.

Showing 117 feature systems 533 capabilities

001 AI workspace · Chat, Plan & Agent modes Chat for focused questions and explanations

What it helps with. Use Chat when you need an explanation, diagnosis, comparison, or focused answer without asking the assistant to run a multi-step implementation. It keeps the request inside the same conversation and model controls, so you can add project context, clarify the result, or move deliberately into Plan or Agent mode when the task grows.

002 AI workspace · Chat, Plan & Agent modes Plan for structured, reviewable implementation strategy

What it helps with. Use Plan to turn an ambiguous change into an ordered implementation strategy before files are modified. The model can inspect the supplied context, identify dependencies and verification work, and return a plan you can challenge or refine before authorizing an Agent run.

003 AI workspace · Chat, Plan & Agent modes Agent for multi-step coding work with tools

What it helps with. Agent mode can inspect the repository, edit files, run approved commands, review diagnostics, and verify the resulting behavior across multiple bounded iterations. Every tool remains subject to the selected capability, approval, sandbox, cancellation, and request-budget controls rather than receiving silent unrestricted access.

004 AI workspace · Chat, Plan & Agent modes Switch modes from the same conversation composer

What it helps with. Change between Chat, Plan, and Agent without opening another panel or abandoning the current thread. The retained provider-neutral conversation and attached project context move with the next request, while the newly selected mode determines whether the model answers, plans, or receives coding tools.

005 AI workspace · Integrated composer cockpit Choose mode, provider, model, and speed

What it helps with. Set the working mode, model source, exact model, and supported processing tier beside the prompt that will use them. The selectors change the next request only, so exploring another route never sends an accidental message or rewrites the conversation already on screen.

006 AI workspace · Integrated composer cockpit Set reasoning effort and response detail

What it helps with. Tune model reasoning effort independently from the amount of detail you want in the visible answer. CoderFriend sends only controls the selected provider and model support, preventing a decorative selector from becoming an invalid API option or a misleading promise.

007 AI workspace · Integrated composer cockpit Select context, profile, trust, and approval behavior

What it helps with. Choose how much retained context is sent, which working persona applies, what capability profile the model receives, and when actions need approval. Keeping those decisions in the composer makes the effective request policy visible at the moment authority is granted.

008 AI workspace · Integrated composer cockpit Keep advanced controls close to the prompt

What it helps with. Advanced controls remain available in the composer instead of being buried several settings pages away from the request they affect. You can hide controls you rarely use, but their saved values continue to apply and can be restored without rebuilding the workspace.

009 AI workspace · Live progress & activity Concise progress commentary during long-running work

What it helps with. During a longer Agent task, the Working panel reports short findings, current actions, and the next useful step while execution continues. Updates are written for the user rather than dumping raw protocol traffic, so you can follow the work without waiting for the final response.

010 AI workspace · Live progress & activity Visible tool activity and completion state

What it helps with. Reads, searches, edits, commands, verification, and delegated work appear as bounded activity with a clear running, completed, failed, or cancelled state. Persistent status makes it possible to see whether the Agent is investigating, changing code, or proving the result instead of guessing from a spinner.

011 AI workspace · Live progress & activity Clear status without exposing private reasoning

What it helps with. CoderFriend shows observable actions and concise provider-authored progress, but it does not publish hidden chain-of-thought as if it were an audit log. This preserves useful transparency—the files inspected, tools used, checks run, and outcomes found—without exposing private internal reasoning.

012 AI workspace · Queue, steer, delete & stop Queue follow-up instructions while work continues

What it helps with. Enter during an active sidebar Agent run adds a follow-up to a visible queue. After successful completion, waiting items can start in order as new accountable turns. Cancellation, errors, and safety limits keep them queued for an explicit Send instead of automatically starting more model work.

013 AI workspace · Queue, steer, delete & stop Steer the active run with new direction

What it helps with. Steer applies a waiting instruction to the current Agent request at a safe boundary. A superseded model response is discarded before its unstarted tools execute; an active tool or approval finishes before the next instruction is consumed. The applied direction remains visible with the conversation and activity.

014 AI workspace · Queue, steer, delete & stop Remove queued messages before they run

What it helps with. Queued follow-ups remain visible and removable until they are submitted, so a stale idea does not become a paid model request merely because it was typed early. Deleting one affects only that waiting item and does not discard the active work or the rest of the queue.

015 AI workspace · Queue, steer, delete & stop Stop an active request immediately

What it helps with. Stop requests cancellation across the model call, tool execution, managed commands, runtime browser, SSH leases, and other request-owned work. The control stays in a stopping state until cleanup completes, preventing a visually finished request from leaving hidden child processes behind.

016 AI workspace · Inline Chat Start from a selected editor range

What it helps with. Open Inline Chat from a highlighted range to make the selected code and surrounding file context the deliberate target of the request. This keeps a focused repair or transformation close to the source instead of requiring you to paste code into a detached conversation.

017 AI workspace · Inline Chat Preview the proposed replacement inline

What it helps with. The model’s suggested replacement is shown against the selected range before it becomes the file’s accepted content. You can inspect the exact proposed change in editor context, including the code immediately around it, rather than trusting a prose summary.

018 AI workspace · Inline Chat Accept or reject before changing the file

What it helps with. Inline Chat leaves the final mutation behind an explicit accept or reject decision. Accept applies the reviewed replacement to the editor, while reject dismisses it without forcing you to reconstruct the original selection or undo an unwanted speculative change.

019 AI workspace · Inline completion Editor-native ghost-text suggestions

What it helps with. Inline completion presents a context-aware suggestion as native ghost text at the cursor instead of opening a separate response panel. You can read it in the flow of the file, accept it with the normal editor gesture, or keep typing to replace it.

020 AI workspace · Inline completion Suggestions grounded in nearby code

What it helps with. Inline completion reads bounded code before and after the cursor together with available imports, recent edits, diagnostics, open-file context, document symbols, and repository instructions. The completion model remains a separate selection for each provider, and unsupported prompt formats fall back to an explicit cursor-context request.

021 AI workspace · Inline completion Accept completions without leaving the editor

What it helps with. A useful suggestion can be accepted directly into the current document, while ignored suggestions disappear as ordinary editor state. Backoff protection limits repeated provider calls when a route is failing or the user is typing quickly, keeping the feature responsive rather than noisy.

022 AI workspace · Inline completion Read code before and after the cursor

What it helps with. Completion uses a bounded prefix and suffix so suggestions fit into the surrounding implementation. Models with a supported fill-in-the-middle format receive that format; other routes receive an explicit cursor context.

023 AI workspace · Inline completion Include recent edits, imports, diagnostics, and open-file context

What it helps with. The completion provider gathers bounded recent edits, imported names, visible file context, current diagnostics, document symbols, and repository instructions when available. These inputs help suggestions follow the work already happening in the editor.

024 AI workspace · Inline completion Keep suggestions responsive and discard stale results

What it helps with. Adaptive debounce, local caching, request deduplication, and document-version checks reduce redundant requests and reject results made obsolete by new typing. Failure backoff protects a provider that is repeatedly unavailable.

025 AI workspace · One-click editor actions Fix selected code

What it helps with. Run Fix from the lightbulb, context menu, command palette, or slash palette to ask for a focused correction around the active selection. The action carries the selected source and file context into CoderFriend so the result can address the concrete defect instead of guessing which code you meant.

026 AI workspace · One-click editor actions Explain unfamiliar code

What it helps with. Run Explain on a selection to receive a contextual walkthrough of what the code does, how its pieces interact, and where important assumptions live. The explanation stays connected to the actual editor range, making follow-up questions easier than moving a copied snippet into a separate tool.

027 AI workspace · One-click editor actions Generate tests

What it helps with. Run Test to ask for behavior-focused tests around the selected implementation and its visible dependencies. The generated request identifies the source range and current file, giving the model a concrete unit under test while leaving final application and verification under your control.

028 AI workspace · One-click editor actions Refactor an implementation

What it helps with. Run Refactor when the selected code should become clearer or easier to maintain without intentionally changing its behavior. CoderFriend grounds the request in the highlighted implementation so proposed structure, naming, and duplication changes remain reviewable rather than becoming a repository-wide rewrite by surprise.

029 AI workspace · One-click editor actions Write documentation

What it helps with. Run Doc to generate documentation for the selected function, class, module, or block in the language and style of the surrounding file. The action starts from real source context, so the result can describe parameters, behavior, and constraints instead of producing generic boilerplate.

030 AI workspace · Actionable code blocks Copy a complete code block

What it helps with. Every rendered code block offers a direct copy action that preserves the complete block rather than requiring a fragile drag selection. This is useful when the answer belongs in another file, review, terminal, or external discussion and should move without markdown fences or missing lines.

031 AI workspace · Actionable code blocks Send commands to the integrated terminal

What it helps with. A shell-shaped code block can be inserted into VS Code’s integrated terminal so you can inspect and run it in your own terminal context. CoderFriend does not present insertion as successful execution; the terminal remains visible and the command remains under your control.

032 AI workspace · Actionable code blocks Apply eligible changes to the workspace

What it helps with. Eligible generated code can be applied to the active editor through the code-block action instead of copied by hand. The action is limited to content CoderFriend can map safely to an editor target, and the resulting file remains available for normal diff review and undo.

033 AI workspace · Native VS Code entry points Dedicated activity-bar and secondary-sidebar experience

What it helps with. Open CoderFriend from its Activity Bar container or move the chat view into VS Code’s Secondary Side Bar when you want Explorer and AI visible together. The preserve setting leaves the primary sidebar untouched by default, while explicit left or right choices remain available.

034 AI workspace · Native VS Code entry points Discoverable slash-command menu

What it helps with. Type a forward slash in the composer to open a filterable menu of supported actions instead of memorizing command names. Choosing a row inserts or runs the appropriate request, and each item remains reachable from the same keyboard-first surface.

035 AI workspace · Native VS Code entry points Native @coderfriend chat participant

What it helps with. Use @coderfriend inside VS Code’s native Chat view when that surface fits the rest of your editor workflow. Requests still pass through CoderFriend’s provider selection, accounting, context, and guarded Agent infrastructure rather than becoming a separate untracked integration.

036 AI workspace · Native VS Code entry points Commands for chat, plan, Agent, explain, fix, tests, and review

What it helps with. Open the major CoderFriend workflows from VS Code’s Command Palette even when the sidebar composer is not focused. These commands provide predictable editor-native entry points for questions, planning, implementation, code actions, and high-signal review across keyboard and menu workflows.

037 AI workspace · A workspace that fits you Choose which composer controls stay visible

What it helps with. Toggle usage, context, mode, model, speed, reasoning, compaction, detail, profile, trust, provider, approval, and steering hints independently. Hiding a control only reduces visual density; its saved value still governs requests and the essential input, Send, and Stop controls remain available.

038 AI workspace · A workspace that fits you Separate typography for conversation and activity

What it helps with. Set independent font families and sizes for message content and the Working activity stream. This lets you enlarge the text you read most often without inflating status rows, controls, code, or every surrounding interface element at the same time.

039 AI workspace · A workspace that fits you Independent composer and code typography

What it helps with. Configure the prompt composer separately from code blocks, inline code, diffs, commands, and raw tool output. Each surface can follow the VS Code interface or editor font by default, or use a deliberate stack and size that improves readability for your setup.

040 AI workspace · A workspace that fits you Searchable Settings Center

What it helps with. Browse General, User Interface, Models and Providers, Context and Knowledge, Agent and Safety, Profiles and Guardrails, and Advanced settings in one searchable editor. Results take you to the real manifest-backed control, so changing a friendly setting updates the same configuration used by requests.

041 AI workspace · 25-command slash palette Explain selected code with /explain

What it helps with. Type /explain to turn the current selection and nearby file context into a focused explanation request. It is the keyboard-first equivalent of the editor action, useful when your attention is already in the composer and you want to ask follow-up questions in the same thread.

042 AI workspace · 25-command slash palette Repair selected code with /fix

What it helps with. Type /fix to request a concrete correction for the selected source while keeping the affected file and range explicit. The command starts the repair conversation but does not bypass normal review, write, approval, or sandbox controls when implementation work follows.

043 AI workspace · 25-command slash palette Generate focused tests with /test

What it helps with. Type /test to ask for tests around the active selection or file context without drafting a long prompt from scratch. The generated request focuses on observable behavior and gives you a clear starting point for reviewing, applying, and running the proposed coverage.

044 AI workspace · 25-command slash palette Refactor an implementation with /refactor

What it helps with. Type /refactor to ask for a behavior-preserving improvement around the code currently in focus. Because the command carries editor context, the model can discuss or implement a specific restructuring instead of returning broad refactoring advice detached from the repository.

045 AI workspace · 25-command slash palette Write code documentation with /doc

What it helps with. Type /doc to produce documentation for the selected implementation using the surrounding source as evidence. The command is designed for concrete comments and reference text, while you remain free to refine the wording or ask the Agent to update related documentation files.

046 AI workspace · 25-command slash palette Start a high-signal review with /review

What it helps with. Type /review to open the review workflow for a selection, file, working tree, branch, or pull request. Findings must identify concrete evidence and locations, and local results can be handed to a foreground Agent or an isolated repair worktree.

047 AI workspace · 25-command slash palette Switch directly to Chat with /chat

What it helps with. Type /chat to select answer-oriented Chat mode without reaching for the mode control. The next message uses the retained conversation and chosen provider but receives no autonomous coding loop, making it suitable for diagnosis, explanation, and focused decisions.

048 AI workspace · 25-command slash palette Switch directly to Plan with /plan

What it helps with. Type /plan to select planning mode before the next request. The model can inspect supplied context and return an ordered strategy, risks, and verification approach, while workspace mutation waits until you deliberately move into an execution workflow.

049 AI workspace · 25-command slash palette Switch directly to Agent with /agent

What it helps with. Type /agent to select the multi-step tool-using mode for the next message. The command changes the working mode but does not silently widen authority; the selected profile, approvals, sandbox, budgets, and available tool capability still define what the Agent may do.

050 AI workspace · 25-command slash palette Choose a model with /model

What it helps with. Type /model to open the active provider’s model picker from the keyboard. The list comes from that provider’s isolated catalog and respects favorites and aliases, so selecting a route updates the next request without mixing in models from another source.

051 AI workspace · 25-command slash palette Set reasoning effort with /reasoning

What it helps with. Type /reasoning to choose the supported reasoning effort for the current provider and model. CoderFriend remembers the provider-specific choice and omits it when a route does not support the control, avoiding an API error disguised as a preference.

052 AI workspace · 25-command slash palette Change processing speed with /fast

What it helps with. Type /fast to adjust the real processing or service tier exposed by a compatible provider. Speed remains independent from reasoning effort and visible response detail, and unsupported tiers are not sent merely because another provider offered them.

053 AI workspace · 25-command slash palette Inspect approval behavior with /permissions

What it helps with. Type /permissions to see the active approval behavior that governs file, command, MCP, browser, and live-server actions. This makes Ask, Workspace, and Always Allow semantics inspectable from the conversation instead of leaving authority implicit in a distant configuration value.

054 AI workspace · 25-command slash palette Inspect the command sandbox with /sandbox

What it helps with. Type /sandbox to see whether Agent commands are running in workspace-write, read-only, or off mode. The result distinguishes OS-level command isolation from approval policy, which matters because approving an action does not automatically remove its filesystem or network boundary.

055 AI workspace · 25-command slash palette Review the latest checkpoint with /changes

What it helps with. Type /changes to reopen the most recent Agent checkpoint and inspect its changed-file summary and bounded patch. From there you can open native before-and-after diffs, copy or reveal the raw patch, and decide whether the completed work should stay.

056 AI workspace · 25-command slash palette Restore the latest checkpoint with /undo

What it helps with. Type /undo to start guarded restoration of the latest Agent checkpoint. CoderFriend verifies that current files still match the checkpoint’s after-state, asks before forcing over newer work, and creates a reverse checkpoint when restoration succeeds.

057 AI workspace · 25-command slash palette Compact retained context with /compact

What it helps with. Type /compact to shrink the retained middle of a long conversation while preserving the opening task, newest work, and intact tool exchanges. The saved conversation is not rewritten merely because a smaller model-bound representation is prepared for the next request.

058 AI workspace · 25-command slash palette Back up conversation history with /backup

What it helps with. Type /backup to write a project backup of conversation history using readable Markdown alongside structured JSON and retained attachments. The files can be inspected or versioned like ordinary project artifacts and later selected through the restore workflow.

059 AI workspace · 25-command slash palette Inspect the active setup with /status

What it helps with. Type /status to summarize the active provider, model, working mode, policy, sandbox, context behavior, and connected capabilities relevant to the next request. It gives troubleshooting and handoff conversations a concrete configuration snapshot instead of relying on memory.

060 AI workspace · 25-command slash palette Open provider accounts with /account

What it helps with. Type /account to open one account-and-usage row for every configured provider. Each row can show a fetched balance where the provider exposes one, locally recorded spend for the active budget period, and direct usage or billing links when the provider remains the source of truth.

061 AI workspace · 25-command slash palette Refresh model prices with /priceupdate

What it helps with. Type /priceupdate to refresh the editable exact-model rate registry used for local cost estimates. Updating rates never fabricates missing usage or retroactively treats an unknown model as a related priced alias; uncertain requests continue to show N/A.

062 AI workspace · 25-command slash palette Discover and invoke skills with /skills

What it helps with. Type /skills to open a filterable catalog of project, user, provider, plugin, and extension skills. Selecting an entry inserts its $skill-name invocation into the composer, where it can guide any compatible selected model without changing providers.

063 AI workspace · 25-command slash palette Inspect connected MCP tools with /mcp

What it helps with. Type /mcp to inspect configured Model Context Protocol servers and the tools currently available from their live connections. The view helps distinguish an unavailable server from an unsupported task before an Agent attempts an external call.

064 AI workspace · 25-command slash palette Start a clean thread with /new

What it helps with. Type /new to begin a conversation without sending the current retained transcript to the next provider request. The previous thread remains in history according to the configured retention policy, while the new thread starts with fresh messages and usage accounting.

065 AI workspace · 25-command slash palette Open searchable guidance with /help

What it helps with. Type /help to open the in-app operating guide beside the current workspace. Search covers setup, providers, composer controls, tools, safety, code review, runtime verification, SSH, worktrees, background Agents, subagents, and troubleshooting without requiring a browser detour.

066 AI workspace · Model Debug workspace Resizable model-communication pane

What it helps with. Open the Model Debug pane beneath the conversation and drag its resizer to give protocol details as much or as little room as the investigation needs. The normal chat remains visible above it, so a transport problem can be compared with the user-facing result in the same surface.

067 AI workspace · Model Debug workspace Timestamped request, response, reasoning, status, and error entries

What it helps with. Each debug entry records its kind, title, time, bounded body size, and expandable content in arrival order. This separates outgoing requests, streamed chunks, reported reasoning metadata, status changes, final responses, and failures instead of flattening them into one ambiguous log.

068 AI workspace · Model Debug workspace Copy the complete bounded trace

What it helps with. Copy the retained debug trace when you need to paste a reproducible provider exchange into an issue or internal investigation. Entry and total-size limits prevent the convenience action from turning a pathological response into an unbounded clipboard or conversation-history payload.

069 AI workspace · Model Debug workspace Export structured JSON or readable text logs

What it helps with. Download the current trace as structured JSON for tooling or as readable text and log formats for people. Both exports preserve event order and useful metadata, while shared redaction removes credential-shaped values before retained diagnostic content leaves the extension surface.

070 AI workspace · Model Debug workspace Open the current extension-host instance log

What it helps with. Open the log file for the running extension-host instance directly in a normal VS Code editor tab after pending writes are flushed. This connects the visible model trace with lower-level operational messages without asking the user to locate a temporary log path manually.

071 AI workspace · Generated visual artifacts Generate raster images through the imagegen workflow

What it helps with. When a task needs a bitmap rather than code-native SVG or HTML, the Agent can follow the image-generation skill and invoke the imagegen CLI through optional uv support. The prompt, output path, and resulting asset remain part of the repository task instead of an unrelated external download.

072 AI workspace · Generated visual artifacts Save generated images under a configurable repository folder

What it helps with. Generated raster assets default to assets/generated and can be redirected with coderfriend-ai.generatedImageDirectory. Absolute paths and traversal outside the workspace fall back safely, keeping generated deliverables inside a deliberate project-owned location that normal source control and review can see.

073 AI workspace · Generated visual artifacts Open images, PDFs, and notebooks in their native VS Code editors

What it helps with. The open_file tool asks VS Code to display a produced image, PDF, or notebook using the editor that already understands that format. It returns no hidden file content to the model and avoids starting an unnecessary web server merely to show the user a finished artifact.

074 AI workspace · Generated visual artifacts Keep image credentials scoped to the generation command

What it helps with. If the image workflow needs the stored OpenAI key, CoderFriend injects it only into the approved image-generation command that consumes it. The credential is not added to ordinary sandboxed command environments, debug output, or the model conversation simply because image generation is available.

075 AI workspace · Resumable bounded requests Continue after an iteration, call, token, cost, or time ceiling

What it helps with. When a root Agent reaches a configured safety ceiling, the Working card explains which limit paused progress and offers a deliberate Continue path where appropriate. Continuing creates a fresh bounded accounting round while retaining the concrete task state and completed changes needed to proceed.

076 AI workspace · Resumable bounded requests Preserve the completed work and working-time history between continuations

What it helps with. A continued task keeps the edits, checkpoint context, plan state, and active-work duration accumulated before the pause. Idle time spent waiting for the user is excluded from the Working duration, so the displayed effort reflects execution rather than how long the tab remained open.

077 AI workspace · Resumable bounded requests Start each continuation as a separately accountable request

What it helps with. Every Continue action becomes its own Recent Requests row with independent provider calls, token usage, cost status, iteration count, and duration. The broader conversation still aggregates those rounds, letting one user objective remain coherent without concealing how many paid requests it required.

078 AI workspace · Resumable bounded requests Mark interrupted work clearly after an editor reload

What it helps with. Durable background and conversation state can be inspected after VS Code reloads, but in-flight paid work is not silently replayed. CoderFriend marks an active request as interrupted so the user can review what completed and choose the next action without duplicate model calls or hidden process assumptions.

079 AI workspace · Searchable in-app Help Search help without leaving the extension

What it helps with. The Help surface is built into CoderFriend and can be searched for the workflow, setting, command, or tool name you are using. Results stay beside the active workspace, making it practical to confirm a safety boundary or provider behavior before continuing a request.

080 AI workspace · Searchable in-app Help Open guidance from /help and the Settings Center

What it helps with. Open the same in-app guidance from the /help command or through the Settings Center’s Help page. Multiple entry points reduce hunting while keeping one maintained source of operational truth rather than separate short tips that drift apart.

081 AI workspace · Searchable in-app Help Cover providers, controls, tools, SSH, reviews, runtime, and delegation

What it helps with. Help documents the complete path from provider authentication and composer controls through local tools, approvals, sandboxing, code review, runtime browser verification, SSH Live Server work, worktrees, background Agents, task plans, subagents, and resource budgets. Search can therefore answer both setup and advanced-operation questions.

082 AI workspace · Searchable in-app Help Keep operational guidance available beside the active conversation

What it helps with. Because Help lives inside the extension, you can compare its documented behavior with the current conversation, settings, and activity state without losing your place. This is especially useful when a prompt, sandbox, remote capability, or budget behaves differently from an assumed default.

083 AI workspace · Smart conversation organization Create an automatic first-message title

What it helps with. A new conversation receives a bounded title derived from the first meaningful user request so history becomes recognizable without manual cleanup. The title is metadata for navigation, not a rewrite of the message itself, and it remains editable at any time.

084 AI workspace · Smart conversation organization Review an automatic title after the conversation develops

What it helps with. After enough real conversation exists, the selected model can review the initial generated title against what the thread actually became. The bounded review updates only an automatic title when a clearer description is justified, avoiding endless renaming or a separate unaccounted background workflow.

085 AI workspace · Smart conversation organization Preserve every title the user edits manually

What it helps with. Renaming a conversation marks its title as user-owned, which permanently removes that thread from automatic title review. CoderFriend treats a deliberate human label as authoritative even if later messages shift topic, so organization never changes behind the user’s back.

086 AI workspace · Smart conversation organization Restore saved usage totals when a conversation is reopened

What it helps with. Conversation usage is persisted with the thread and restored when history is reopened or the editor reloads. Prompt, output, thinking, tool-result, cache, turn, surface, and measurable-cost totals therefore remain attached to the work that produced them instead of resetting merely because the UI was closed.

087 AI workspace · Share remote Agent updates Copy any transcript row

What it helps with. Press and hold a remote update to copy its text without needing to select from a scrolling list.

088 AI workspace · Share remote Agent updates Share updates through the phone system sheet

What it helps with. Send a selected row to the installed sharing destinations on iPhone or Android.

089 AI workspace · Share remote Agent updates Keep desktop sharing useful

What it helps with. Copy the selected update and confirm the result when a desktop build has no mobile share sheet.

090 AI workspace · Open editors as per-request context Include open editors only when useful

What it helps with. Add the currently open documents to an individual request instead of sending every open tab automatically.

091 AI workspace · Open editors as per-request context Review the exact files before sending

What it helps with. Surface the selected editor context with the other request attachments so stale or sensitive tabs can be removed.

092 AI workspace · Open editors as per-request context Keep later requests lean

What it helps with. Treat open-editor context as request-scoped evidence rather than silently carrying it into the rest of the conversation.

093 AI workspace · External conversation storage Choose a dedicated conversation folder

What it helps with. Store chats outside the active repository when project-local history is not the right fit.

094 AI workspace · External conversation storage Create storage only when it is needed

What it helps with. Avoid leaving an empty CoderFriend history folder behind before the first conversation is actually saved.

095 AI workspace · External conversation storage Keep repositories free of personal chat data

What it helps with. Separate reusable or private conversation history from files intended for source control.

096 AI workspace · External conversation storage Continue using normal history controls

What it helps with. Browse, reopen, rename, and search stored conversations through the same CoderFriend interface.

097 AI workspace · Import Claude Code and Codex chats Discover supported local chat histories

What it helps with. Find conversations written by the installed Claude Code and Codex tools without requiring a cloud export.

098 AI workspace · Import Claude Code and Codex chats Name imports after their source

What it helps with. Label migrated conversations with the tool they came from so imported and native chats remain distinguishable.

099 AI workspace · Import Claude Code and Codex chats Review before continuing

What it helps with. Open imported messages in CoderFriend history and decide which context is still relevant before asking for more work.

100 AI workspace · Import Claude Code and Codex chats Keep the original records intact

What it helps with. Copy supported history into CoderFriend storage rather than rewriting the source tool’s own conversation files.

101 AI workspace · Built-in image viewer Inspect images without leaving VS Code

What it helps with. Open supported image files in the editor instead of translating visual output into an unreadable text payload.

102 AI workspace · Built-in image viewer Review generated visual artifacts

What it helps with. Display an image result at its workspace path so you can inspect what a tool produced before accepting the work.

103 AI workspace · Built-in image viewer Use the visible result in follow-up requests

What it helps with. Keep the image available for comparison while asking the Agent to refine the surrounding code or asset.

104 AI workspace · Agent debugger controls Inspect the active debug state

What it helps with. Read threads, stack frames, scopes, and bounded variables from the paused session before choosing an action.

105 AI workspace · Agent debugger controls Continue, pause, step, or stop deliberately

What it helps with. Use dedicated debugger operations instead of trying to drive the adapter through shell commands.

106 AI workspace · Agent debugger controls Evaluate a focused expression

What it helps with. Query the current paused frame when an exact runtime value is needed to test a diagnosis.

107 AI workspace · Agent debugger controls Keep debugger activity visible

What it helps with. Record the requested operation in the Agent run so runtime control is not hidden from review.

108 AI workspace · Draft-safe conversations Protect an unfinished prompt while navigating

What it helps with. Arrow keys move the caret inside a non-empty draft instead of replacing it with prompt history. History recall begins only when the composer is empty.

109 AI workspace · Draft-safe conversations Keep drafts across conversation changes

What it helps with. Starting a new chat leaves the current draft available so you can return to it instead of reconstructing the prompt.

110 AI workspace · Draft-safe conversations Restore text used by follow-up actions

What it helps with. Retry, Continue, and Resume Agent can submit their generated line without permanently overwriting what you were already composing.

111 AI workspace · Draft-safe conversations Remove text only through deliberate editing

What it helps with. Backspace, Delete, replacing a selection, sending, and running a slash command remain the explicit ways to clear composer content.

112 AI workspace · Terminal troubleshooting Capture terminal output when you enable it

What it helps with. Turn on terminal capture to retain bounded command output from VS Code terminals with shell integration. Capture is off by default, applies redaction, and clears its retained records when disabled.

113 AI workspace · Terminal troubleshooting Ask about the last captured command

What it helps with. Open an explanation request with the command, working directory, available exit code, and retained output together. This keeps the question attached to the actual terminal operation instead of an isolated error sentence.

114 AI workspace · Terminal troubleshooting Start a repair from a captured failure

What it helps with. Fix Terminal Failure opens a repair request for the latest captured command with a reported nonzero exit code. It requires terminal capture and shell integration; when no failure was captured, the command explains what is missing.

115 AI workspace · Paused debugger explanations Inspect a paused debug session

What it helps with. Explain Paused Debug Session reads the active debug adapter’s threads, stack frames, scopes, and top-frame variables. A running session without a paused stack is reported explicitly.

116 AI workspace · Paused debugger explanations Keep debugging inspection read-only

What it helps with. The snapshot workflow does not step, resume, evaluate expressions, or change the debugged program. It prepares context for a repair explanation while the developer keeps control of the debugger.

117 AI workspace · Paused debugger explanations Bound and redact captured variables

What it helps with. The snapshot limits frames, variables, and value length, skips expensive scopes, and withholds credential-shaped variable names. The resulting request includes useful failure context without deliberately collecting the whole process state.

118 AI workspace · Jupyter notebook cells Read numbered code and Markdown cells

What it helps with. The notebook tool presents .ipynb files as numbered cells with bounded source and text outputs. Non-text outputs are identified rather than embedded as large payloads.

119 AI workspace · Jupyter notebook cells Replace, insert, or delete a selected cell

What it helps with. Agent notebook edits target an explicit cell index and operation, preserving the surrounding document and metadata. The normal file-write policy and path checks still apply.

120 AI workspace · Jupyter notebook cells Clear outdated results when code changes

What it helps with. Replacing a code cell clears its stored outputs and execution count so old results are not presented as proof of the new source. Editing a cell does not execute the notebook kernel.

121 AI workspace · Jupyter notebook cells Review and restore notebook changes

What it helps with. Notebook mutations use the same change session and checkpoint path as other Agent edits. Open the result in VS Code’s notebook editor and inspect or restore the changed file through the usual review workflow.

122 AI workspace · Follow a run from your phone Watch the run as it happens

What it helps with. The phone shows the same run the sidebar does: what the model is doing now, each tool call with the command it actually ran, and the assistant’s own text. Connecting shows the session as it already stands, including the last completed run, rather than an empty screen that waits for the next event.

123 AI workspace · Follow a run from your phone Steer, stop, or start work

What it helps with. Type to steer a run in progress, or to start one when nothing is running, through the same path the sidebar composer uses. Stopping asks first, because a run stopped from a phone cannot be resumed from one.

124 AI workspace · Follow a run from your phone Trusted Agent only, and no approvals on the phone

What it helps with. Remote control is refused for any approval mode that can pause and ask, because there is no way to answer an approval from a phone: judging a command means reading it beside the workspace it will change. The setting is off until you turn it on.

125 AI workspace · Follow a run from your phone Pair once, then reconnect until you revoke it

What it helps with. Pair a phone with a desktop by reading an eight-character code off the sidebar, comparing a fingerprint at both ends, and confirming. After that it reconnects on its own with nothing to type. The paired-phones list shows what is trusted and revoking is the only way a pairing ends.

126 AI workspace · Follow a run from your phone Pick which editor window to watch

What it helps with. Every window with remote control on offers itself by its project name, so a phone lists the work you have open and you choose. A window turns remote control on for itself when it opens, and the composer shows a Remote Control switch for turning it off and on.

127 AI workspace · Follow a run from your phone Encrypted so the relay cannot read it

What it helps with. The two ends agree keys directly through a key exchange the relay only forwards, so the service that carries the traffic holds nothing that can decrypt it. Identity keys authenticate the pair and never derive session keys, so a phone lost later cannot decrypt anything recorded before.

128 Living context · Files, folders & image context Attach individual files and folders

What it helps with. Use the composer’s context picker to attach one file or a bounded folder tree before sending a request. CoderFriend shows the selected material as removable context chips, so you can verify what will accompany the prompt instead of relying on an invisible workspace sweep.

129 Living context · Files, folders & image context Include the active selection and open editor

What it helps with. Bring the highlighted range and active document into a request when the task starts from code already on screen. File identity, language, and nearby source keep the question grounded, while the explicit selection prevents a focused request from automatically expanding to the whole repository.

130 Living context · Files, folders & image context Attach up to five images to a request

What it helps with. Paste, drag, or choose as many as five images for a model route that supports vision input. Preview thumbnails remain visible before submission and can be removed individually, making screenshots, mockups, errors, and visual references deliberate parts of the request.

131 Living context · Files, folders & image context Review attached context before sending

What it helps with. Every selected file, folder, image, and context attachment is surfaced in the composer before the provider call begins. You can discard stale or sensitive material there, reducing accidental disclosure and helping the model receive the smallest useful evidence set.

132 Living context · Ranked local codebase search Local BM25-ranked repository retrieval

What it helps with. CoderFriend builds a local text index and uses BM25 ranking to find files and snippets relevant to a conceptual query. The search_codebase tool and automatic-context flow use that index without sending a vector database or repository copy to a hosted retrieval service.

133 Living context · Ranked local codebase search Bounded results that respect context limits

What it helps with. Repository retrieval limits the number and size of snippets returned, then fits them within the active context budget before provider submission. A broad query therefore yields ranked evidence instead of an unlimited dump that crowds out the task, recent conversation, or instructions.

134 Living context · Ranked local codebase search Relevant snippets pulled from across the workspace

What it helps with. A question can discover matching implementation, configuration, tests, and documentation beyond the open tab, including multi-root workspaces. Results retain file paths and useful source windows so the model can follow evidence into exact reads rather than treating search text as anonymous fragments.

135 Living context · Ranked local codebase search No external vector database required

What it helps with. Index construction, scoring, exclusions, and cached retrieval state remain on the extension host. This removes a separate embedding account and remote index from the normal workflow while still giving the Agent a conceptual search capability over the active project.

136 Living context · Repository instructions AGENTS.md and nested repository rules

What it helps with. CoderFriend discovers AGENTS.md guidance at the workspace root and in deeper folders, then applies the closest relevant rules to files an Agent reads or changes. Nested instructions can narrow broad repository guidance, so a frontend, package, or deployment area keeps its own conventions.

137 Living context · Repository instructions Claude and Gemini instruction files

What it helps with. Existing CLAUDE.md and GEMINI.md project or user instructions can guide any selected model route, not only their namesake provider. This lets teams reuse established repository knowledge while switching between local models, APIs, ChatGPT-authenticated Codex, or Claude subscription transport.

138 Living context · Repository instructions GitHub Copilot and Cursor rules

What it helps with. CoderFriend reads supported .github/copilot-instructions.md, matching .github/instructions files, and .cursor/rules entries as repository guidance. Their location and matching scope are respected so an instruction written for one technology or subtree does not silently become a universal rule.

139 Living context · Repository instructions Closest applicable instructions win by location

What it helps with. Instruction resolution follows the target path and combines broad guidance with the nearest deeper rules that apply. Agent tools also discover new nested instructions when work moves into another folder, preventing an early root-only snapshot from overriding local project conventions.

140 Living context · Repository instructions Apply user-level coding instructions

What it helps with. User-level Claude, Codex, and Gemini instruction files can join applicable repository rules. More specific project guidance remains visible in the instruction context used for the request.

141 Living context · Portable skills Discover project and user-level skills

What it helps with. The skills catalog scans supported project and user registries and presents them in a filterable list with their source. Project workflows can travel with the repository, while personal skills remain available across workspaces without being copied into every codebase.

142 Living context · Portable skills Load task-specific instructions only when needed

What it helps with. Invoking a $skill-name loads its complete SKILL.md workflow for that request rather than adding every installed skill to every prompt. This keeps routine context smaller while still making specialized procedures, references, scripts, and templates available for the task that needs them.

143 Living context · Portable skills Share compatible skills across providers and plugins

What it helps with. Portable .agents skills, Codex skills, Claude skills, Gemini skills, and compatible plugin or extension registries can appear in one catalog. Once selected, the workflow guides the active model provider through CoderFriend’s normal tool and policy layer instead of locking expertise to one transport.

144 Living context · Current web search Invoke current search with @web

What it helps with. Put @web and a query on its own composer line to retrieve current public information before the model answers. The resulting sources are attached as bounded context for that request, making time-sensitive facts explicit rather than allowing a model to imply it searched when it did not.

145 Living context · Current web search Review source-backed results in the conversation

What it helps with. Web results retain titles, links, and readable snippets so the answer can distinguish fetched evidence from model memory. You can open the cited pages, refine the query, or remove the mention before sending when the retrieved sources do not match the intended question.

146 Living context · Current web search Combine fresh web context with local code

What it helps with. A request can use current public sources alongside selected files, repository search, documentation, and conversation history. This is useful for changing APIs, release notes, standards, and dependency behavior where the repository shows what you use and the web shows what changed.

147 Living context · Local documentation library Search local indexed documentation with @docs

What it helps with. Use @docs with a question, or a site prefix and question, to retrieve matching passages from the local documentation library. The model receives bounded source text and origin details, allowing an answer to rely on the documentation you indexed instead of an unrelated generic web result.

148 Living context · Local documentation library Crawl documentation sites into the library

What it helps with. Add an approved documentation site and let CoderFriend follow same-site pages within configured page and depth ceilings. Fetched text is normalized into a local index for later searches, avoiding a fresh network crawl every time the same API question returns.

149 Living context · Local documentation library Keep docs close to the codebase workflow

What it helps with. Documentation search lives in the same composer and Agent tool registry as files and codebase retrieval. The assistant can compare an official contract with the actual implementation, then follow normal editing and verification controls without moving the task into a separate research application.

151 Living context · MCP servers & tools Configure multiple MCP servers

What it helps with. Declare more than one Model Context Protocol server with its name, command, arguments, and deliberately supplied environment in CoderFriend settings. Connections are initialized and disposed independently, so one unavailable integration does not need to redefine the built-in workspace tool system.

152 Living context · MCP servers & tools Discover available server tools

What it helps with. After an MCP server connects, CoderFriend reads its advertised tool definitions and converts them into the same provider-neutral shape used by built-in Agent tools. The /mcp view exposes what is actually connected, helping users confirm names and availability before asking for external work.

153 Living context · MCP servers & tools Use MCP capabilities during Agent work

What it helps with. An Agent can call a connected MCP tool when the selected policy allows external tool use and the request needs it. Calls retain timeout, cancellation, approval, result-history, and error handling instead of becoming an invisible side channel around the normal request lifecycle.

154 Living context · MCP servers & tools Combine external data with workspace context

What it helps with. MCP results can inform the same task that is reading source files, following repository instructions, editing code, and running verification. This lets an external system supply relevant records or actions while CoderFriend keeps the local repository and approval boundary explicit.

155 Living context · Adaptive context compaction Auto, Shrink, and Full bookend compaction modes

What it helps with. Choose Auto to compact only after a threshold, Shrink to compact proactively, or Full to send all retained context that fits the provider route. The selector changes the model-bound representation for the next request without deleting the saved conversation users can reopen later.

156 Living context · Adaptive context compaction Summarized history that preserves task direction

What it helps with. When compaction is needed, CoderFriend keeps the opening task and newest work while replacing the long middle with a bounded summary. Important decisions, constraints, completed actions, and unresolved work remain available, preventing the latest turn from losing why the task began.

157 Living context · Adaptive context compaction Context-aware image memory lifecycle

What it helps with. Recent screenshots and image attachments remain available while they are useful, but middle images can be released when long conversations are compacted. Their relevant findings can remain in the summary without repeatedly paying to resend the same large visual payload across many Agent iterations.

158 Living context · Adaptive context compaction Continue work after provider context limits

What it helps with. Compaction gives a long-running conversation a smaller coherent history when the selected provider cannot accept every retained message. If a provider still rejects the context, the failure remains visible and the user can shrink further, change routes, or start a clean thread deliberately.

159 Living context · Conversation history Browse and reopen previous conversations

What it helps with. Conversation History lists retained threads with titles and timestamps and lets you reopen one as the active workspace discussion. Its saved messages, debug trace, attachments, and usage state return together, so reviewing old work is more than loading a transcript excerpt.

160 Living context · Conversation history Rename and organize threads

What it helps with. Give a conversation a deliberate name when its automatic title no longer describes the work or when a project naming convention matters. A manual rename becomes authoritative and is not later overwritten by automatic title generation or review.

161 Living context · Conversation history Import and export conversation data

What it helps with. Export the active thread or all retained conversations into a portable structured format, and import compatible data back into CoderFriend. This supports troubleshooting, migration, and controlled archival without requiring access to a proprietary remote conversation account.

162 Living context · Conversation history Delete individual threads or clear history

What it helps with. Remove the current conversation, select a specific historical thread, or clear all retained history through explicit commands and confirmation where appropriate. Deletion is separate from starting a new conversation, so opening a clean thread does not silently erase the project record.

163 Living context · Project backup & restore Back up conversations as Markdown and JSON

What it helps with. Project backup writes human-readable Markdown alongside structured JSON so a conversation can be reviewed in ordinary tools and reconstructed by CoderFriend. The two formats serve different needs without forcing an opaque database export into the repository.

164 Living context · Project backup & restore Include conversation attachments

What it helps with. A backup can carry the attachment records and supporting material associated with the selected conversations, preserving more than visible message text. Bounded project-relative storage keeps the archive inspectable and avoids turning remote provider state into an unreviewable dependency.

165 Living context · Project backup & restore Restore a saved conversation project

What it helps with. Choose a compatible project backup and restore its retained conversation records through the dedicated command. The workflow validates the archive and reports the result, letting a moved or recovered workspace regain useful discussion history without manually recreating each thread.

166 Living context · Project backup & restore Keep a human-readable archive alongside structured data

What it helps with. Markdown gives maintainers a durable narrative they can search, diff, and review, while JSON preserves fields needed for machine restoration. Keeping both makes the backup useful to people, repository search, and future tools instead of optimizing only for one importer.

167 Living context · Project backup & restore Schedule optional conversation backups

What it helps with. Choose manual or automatic workspace backups, a destination directory, and an interval. Backups retain readable Markdown alongside structured history and attachments so an archive remains inspectable outside the extension.

168 Living context · Automatic codebase context Detect when a request would benefit from broader repository context

What it helps with. When automaticCodebaseContext is enabled, CoderFriend evaluates whether the user’s question depends on code beyond the explicit selection or active file. Straightforward conversational requests remain small, while repository-oriented questions can receive ranked project evidence without requiring a manual @ mention.

169 Living context · Automatic codebase context Rank local snippets against the active question

What it helps with. The automatic-context path searches the local BM25 index using the actual request and returns the strongest matching source windows. Paths and snippets remain linked, giving the model enough evidence to request exact files or symbols when deeper inspection is necessary.

170 Living context · Automatic codebase context Respect a dedicated automatic-context token budget

What it helps with. coderfriend-ai.automaticCodebaseContextTokenBudget caps how much retrieved repository text can join one request. The budget protects the user’s task, instructions, and recent conversation from being displaced by search results while still allowing a larger allowance for complex codebase questions.

171 Living context · Automatic codebase context Honor workspace index exclusions during retrieval

What it helps with. Configured workspaceIndexExcludePatterns remove generated, vendor, private, or otherwise irrelevant paths from indexing and search. Built-in secret screening remains independent, so widening a normal exclusion pattern does not make likely credentials eligible for automatic retrieval.

172 Living context · Automatic codebase context Rebuild the local index on demand

What it helps with. Run Rebuild Local Codebase Index when generated content, large branch changes, or updated exclusions make the cached search state stale. Rebuilding happens on the extension host and replaces the local retrieval index without uploading repository content to a separate service.

173 Living context · Skill authoring & cross-provider invocation Search skills by typing $ in the composer

What it helps with. Type a dollar sign to open a compact skill picker filtered as you continue typing. Rows identify the skill and its registry source, helping you choose a project workflow, personal workflow, or imported provider skill before inserting the invocation into the prompt.

174 Living context · Skill authoring & cross-provider invocation Invoke a selected skill with any compatible provider

What it helps with. A $skill-name invocation loads the selected skill instructions before the request is sent to the currently chosen model route. The workflow is not permanently bound to the provider that originally created it, so teams can compare models without duplicating their operating procedure.

175 Living context · Skill authoring & cross-provider invocation Read portable .agents skills alongside Codex, Claude, and Gemini registries

What it helps with. CoderFriend scans the shared .agents/skills convention together with .codex/skills, .claude/skills, and .gemini/skills at supported project and user locations. Portable project entries take precedence on name collisions, keeping repository-owned guidance predictable across different model ecosystems.

176 Living context · Skill authoring & cross-provider invocation Import skills exposed by installed provider plugins and extensions

What it helps with. Compatible Codex and Claude plugin skills and Gemini extension skills can join the same discoverable catalog when their local registries are installed. Source labels preserve provenance, so an imported workflow does not masquerade as a repository-authored skill.

177 Living context · Skill authoring & cross-provider invocation Read administrator-shared skill directories

What it helps with. Organization settings can add absolute shared skill directories to the existing skill registry. Shared skills remain bounded, discoverable workflows that users can inspect and invoke alongside their own skills.

178 Living context · Skill authoring & cross-provider invocation Create or update reusable SKILL.md workflows

What it helps with. A skill-authoring task can create or refine a SKILL.md package with scoped instructions, references, scripts, and reusable assets. Storing the result in a supported registry turns one successful process into a repeatable workflow that future requests can invoke explicitly.

179 Living context · Safe public page fetching Fetch an explicit HTTP or HTTPS page during Agent work

What it helps with. The fetch_web_page tool retrieves a public page only when the request supplies an explicit HTTP or HTTPS URL and web capability is enabled. It complements search by reading a chosen source in more depth while remaining subject to approval, cancellation, timeout, and output bounds.

180 Living context · Safe public page fetching Follow the final safe redirect instead of losing the requested source

What it helps with. Documentation and public pages often redirect to a canonical URL, locale, or version. CoderFriend validates each navigation step and returns the final readable destination, allowing the model to work from the page the user would actually see instead of an empty redirect response.

181 Living context · Safe public page fetching Return bounded readable text rather than an unbounded page payload

What it helps with. Fetched HTML is converted into a bounded text observation suitable for model context rather than copied as an unlimited document with every script and asset. Source URL and useful content remain visible, while size limits protect the request from a pathological or unexpectedly large page.

182 Living context · Safe public page fetching Reject unsafe protocols and credential-bearing requests

What it helps with. The fetch path accepts public HTTP and HTTPS destinations rather than local files or arbitrary protocols, and it does not solicit or type credentials. URLs and output pass through safety checks and redaction so web capability cannot quietly become a secret-exfiltration shortcut.

183 Living context · Bounded documentation crawler Add a documentation site from the Command Palette

What it helps with. Run Add Documentation Site, provide the approved starting URL, and let CoderFriend register it as a named local source. The deliberate setup step prevents an Agent from silently crawling an unrelated site merely because a documentation answer would be convenient.

184 Living context · Bounded documentation crawler Limit crawl depth and maximum indexed pages

What it helps with. documentationIndexMaxDepth and documentationIndexMaxPages bound how far a source crawl can follow links and how many pages it may retain. These limits keep a small product manual from unexpectedly turning into a domain-wide scrape or an unbounded local index.

185 Living context · Bounded documentation crawler Keep fetched documentation in a local cache

What it helps with. Normalized documentation pages are stored on the extension host for later @docs and docs_search requests. Reusing the local cache reduces repeated network work and gives a project a stable reference set until the user chooses to refresh or replace it.

186 Living context · Bounded documentation crawler Search indexed sources by site prefix and question

What it helps with. Prefix an @docs query with a registered source name to narrow retrieval when several libraries discuss similar concepts. CoderFriend ranks matching passages within that source and returns origin details, making version-specific or vendor-specific answers easier to verify.

187 Living context · Bounded documentation crawler Bound external documentation context before model submission

What it helps with. externalContextTokenBudget limits the combined material added from documentation and other external references. The selected excerpts remain useful, but they cannot consume the entire provider context window or silently displace repository instructions and the user’s actual task.

188 Living context · Secret-aware retrieval Skip likely secret files during workspace search and local retrieval

What it helps with. search_workspace, search_codebase, and local retrieval omit paths likely to contain environment secrets, credentials, private keys, or similar material even under permissive approval. This prevents broad search terms from sweeping sensitive files into model context as an incidental match.

189 Living context · Secret-aware retrieval Report excluded-file counts without exposing sensitive filenames

What it helps with. When workspace search skips likely secrets, its result states how many files were excluded without naming those paths. The count explains why a search may be incomplete while avoiding the paradox of revealing sensitive filenames in the warning intended to protect them.

190 Living context · Secret-aware retrieval Redact credential-shaped values before logs and history are retained

What it helps with. A shared redactor removes common credential assignments, bearer tokens, and private-key blocks before Agent logs, debug traces, or conversation history are stored. Redaction is a last safety layer rather than permission to read secrets unnecessarily, so path and approval controls still apply first.

191 Living context · Secret-aware retrieval Block secret access for background and subagent tools without an approval channel

What it helps with. Background Agents and read-only subagents cannot pause for an interactive secret-file approval, so their file, listing, search, and semantic tools omit or reject sensitive paths. The parent can handle a deliberate user-authorized exception in the foreground instead of granting silent delegated access.

192 Living context · Durable conversation memory Persist provider-neutral conversation messages

What it helps with. Messages are retained in a provider-neutral form so the same thread can continue after switching from one supported model source to another. Provider-specific transport details stay outside the durable transcript, reducing lock-in and keeping the user-visible conversation consistent across routes.

193 Living context · Durable conversation memory Restore the debug trace with the selected conversation

What it helps with. Opening a saved thread restores its bounded Model Debug entries alongside the visible messages. A provider or tool problem can therefore be investigated after navigation or reload without pretending the current extension-host log alone represents the historical request.

194 Living context · Durable conversation memory Reconnect retained attachments and project backup records

What it helps with. Conversation records preserve the attachment metadata and backup relationships needed to understand the original project context. Missing or moved material can be reported explicitly, while available files and exported artifacts remain connected to the thread that referenced them.

195 Living context · Durable conversation memory Resume with previously measured conversation usage visible

What it helps with. Reopening a saved conversation restores its accumulated token categories, turn count, request and surface breakdowns, and measurable cost status. The accounting follows the work across UI sessions, while starting or deliberately clearing a thread creates the expected fresh totals.

196 Living context · Approved project memory Save facts through an explicit memory command

What it helps with. Remember for This Project saves text you deliberately enter, with its scope and provenance. Project memory is optional and redacts sensitive-looking values before retaining bounded records locally.

197 Living context · Approved project memory Inspect, edit, disable, or delete saved memories

What it helps with. Manage Project Memories provides a searchable list with edit, enable or disable, mark verified, and delete actions. A remembered fact remains visible and removable instead of becoming an invisible permanent instruction.

198 Living context · Approved project memory Add active memories within a context budget

What it helps with. Enabled sidebar requests can include active applicable memories inside a bounded context allowance. The model receives them as user-approved context, while disabled, expired, or stale records are excluded.

199 Living context · Approved project memory Export or clear the memory collection

What it helps with. Export Project Memories writes a portable JSON record for inspection and archiving. Delete All Project Memories removes the saved collection after an explicit confirmation.

201 Living context · Shared tools for VS Code AI Keep exported tools read-only

What it helps with. The exported tool set provides reads and search; file writes and shell execution remain outside this integration. External calls have a session call ceiling and do not create provider token charges themselves.

202 Living context · Shared tools for VS Code AI Control tool availability from settings

What it helps with. The exportLanguageModelTools setting enables or disables registrations. Sharing requires a VS Code host with the Language Model tool API; an older host leaves these exports unavailable.

203 Safe execution · Approval profiles Default approval behavior

What it helps with. Ask mode keeps sensitive Agent actions behind a visible approval unless an exact saved rule already authorizes them. The prompt names the requested file, command, MCP call, browser action, or remote operation so the user can approve once, remember a narrow rule, or refuse it.

204 Safe execution · Approval profiles Workspace-specific approval choices

What it helps with. Workspace mode automatically permits ordinary operations inside the active project boundary while continuing to ask for external paths, commands, likely secrets, and other elevated actions. This reduces routine prompts without treating the entire host or every opened repository as trusted.

205 Safe execution · Approval profiles Always Allow profile for trusted workflows

What it helps with. Always Allow is literal: every Agent approval callback authorizes immediately and no approval dialog is created. Capability and sandbox rules remain separate, so a tool that was not offered or a mutation blocked by the selected sandbox must still fail visibly instead of pretending permission was granted.

206 Safe execution · Approval profiles Approval controls available from the composer

What it helps with. The active approval mode is visible and changeable beside the prompt that will use it, subject to any selected profile policy. Keeping authority in the request surface helps prevent a permissive setting chosen for one task from becoming an invisible assumption during another.

207 Safe execution · Workspace sandbox boundaries Workspace-write sandbox

What it helps with. Workspace-write confines built-in mutations to current workspace roots and runs ordinary shell commands with host files readable but only the workspace and bounded temporary storage writable. Network access is denied inside supported command sandboxes, and provider credentials are removed from the child environment.

208 Safe execution · Workspace sandbox boundaries Read-only sandbox

What it helps with. Read-only blocks built-in file mutations and mounts workspace content without writable roots for supported sandboxed commands. It is designed for investigation, explanation, and review tasks where executing a check may be useful but changing project or host files is not acceptable.

209 Safe execution · Workspace sandbox boundaries Sandbox-off option for explicitly trusted work

What it helps with. Turning the command sandbox off removes OS-level filesystem and network isolation and returns mutation scope to the approval and capability layers. The setting is intended for a workspace you explicitly trust or tools that cannot run in confinement, not as a hidden fallback when sandbox setup fails.

210 Safe execution · Atomic file editing Patch-based multi-file changes

What it helps with. apply_patch accepts bounded standard unified diffs across as many as 100 workspace files and computes every after-state before writing. If a later file fails validation or mutation, earlier writes are restored, so a multi-file patch behaves as one transaction rather than a half-applied edit.

211 Safe execution · Atomic file editing Exact text replacements for surgical edits

What it helps with. edit_file replaces one expected literal with a deliberate new value when the source text is unique and current. It is suited to a focused change where a full-file rewrite would risk unrelated formatting, and it fails clearly when the old text is absent or ambiguous.

212 Safe execution · Atomic file editing Safer writes with conflict awareness

What it helps with. Write tools resolve and authorize the target path, capture its first before-state, and coordinate with request-scoped locks before committing content. Stale expected text, an overlapping Agent run, a symlink boundary, or an invalid workspace path produces a visible error instead of a best-effort overwrite.

213 Safe execution · Atomic file editing Clear failure when the expected source has changed

What it helps with. Exact edits and unified patches verify their context against the file that exists at execution time. If another edit changed the relevant source, the tool reports the mismatch and lets the Agent reread or stop rather than applying the change at a guessed location.

214 Safe execution · Checkpoints, diffs & undo Automatic task checkpoints

What it helps with. Built-in mutations during one foreground Agent request share a change session that retains each file’s first before-state and final after-state. At completion, CoderFriend creates one bounded checkpoint outside the repository and keeps a rolling history of recent change sets for review and recovery.

215 Safe execution · Checkpoints, diffs & undo Visual diff review before moving on

What it helps with. The checkpoint card lists changed, added, and deleted files and opens any row as native before-and-after VS Code documents in the diff editor. Review Changes spans the complete checkpoint, while a bounded raw patch can also be copied or revealed for external inspection.

216 Safe execution · Checkpoints, diffs & undo Undo and restore support

What it helps with. Restore first verifies that current content still matches the checkpoint’s recorded after-state, protecting newer manual or Agent edits from silent loss. A conflict requires explicit force confirmation, and a successful restore creates a reverse checkpoint so the undo operation itself remains recoverable.

217 Safe execution · Checkpoints, diffs & undo Change summaries tied to the Agent run

What it helps with. The compact Changes card belongs to the request that produced the mutations and summarizes its complete captured file set. That connection lets users compare the Agent’s claims, verification output, and actual diff without searching the entire working tree for unrelated pre-existing changes.

218 Safe execution · Semantic code intelligence Definition and reference navigation

What it helps with. find_definitions and find_references ask VS Code’s language services where a symbol is declared and used across the open workspace. Results retain exact files and locations, giving the Agent compiler-aware evidence that plain text search cannot provide for overloaded names, imports, and cross-file behavior.

219 Safe execution · Semantic code intelligence Workspace symbol discovery

What it helps with. get_workspace_symbols searches the language-service index for classes, functions, types, and other semantic symbols by name. The Agent can use the bounded result to locate an unfamiliar subsystem before opening files, reducing broad repository scans and false matches in comments or generated content.

220 Safe execution · Semantic code intelligence Hover and signature information

What it helps with. get_hover_info retrieves the type, signature, and documentation the active VS Code language provider exposes at a source location. This helps an Agent confirm API contracts and inferred types in the same environment the developer sees, rather than relying only on text surrounding the symbol.

221 Safe execution · Semantic code intelligence Automatic diagnostics after changes

What it helps with. After relevant mutations, get_diagnostics collects bounded language-service errors and warnings from affected workspace files. New evidence can drive a repair iteration before completion, while unresolved findings remain visible so the final answer cannot quietly label a broken edit as verified.

222 Safe execution · Semantic code intelligence Identify failing tests from command output

What it helps with. Supported Node, Jest-style, pytest, Go, PHPUnit, and Mocha output is summarized into recognizable test results before it returns to the Agent. Named failures and available locations help the next repair target the failing behavior; an unknown runner stays as command output.

223 Safe execution · High-signal code review Review a selection, file, tree, or branch

What it helps with. The review target picker can scope analysis to an editor selection, complete file, staged and unstaged working tree, or current branch against a chosen merge base. Each scope is collected deliberately, allowing a small change to avoid unrelated repository noise and a branch review to include its actual diff.

224 Safe execution · High-signal code review Review GitHub pull-request changes

What it helps with. An authenticated GitHub CLI can provide the patch for a chosen pull request without checking out its head. Pull-request review is read-only because the reviewed source may not exist in the current worktree, and findings link back to exact paths and lines present in the supplied patch.

225 Safe execution · High-signal code review Prioritized findings with file locations

What it helps with. The review model must return structured correctness, security, race, performance, or missing-test findings with severity, confidence, concrete evidence, impact, recommendation, file, and positive line number. Malformed, duplicate, out-of-scope, or unsupported claims are removed before the result card appears.

226 Safe execution · High-signal code review Suppress findings that are not relevant

What it helps with. Each retained finding has a stable rule identifier that can be suppressed when it repeatedly does not apply to the project. The configured suppression list removes that rule from future review output without lowering the global evidence, category, or confidence requirements for every other finding.

227 Safe execution · High-signal code review Review an individual Git commit

What it helps with. The review commands include a single-commit scope as well as working-tree, branch, file, and pull-request workflows. Findings remain tied to the exact reviewed change.

228 Safe execution · High-signal code review Review before generating a commit message

What it helps with. Optionally run a working-tree review before CoderFriend fills the Source Control message field. Findings can be opened for inspection or explicitly overridden; this check does not create or block Git commits itself.

229 Safe execution · Review-to-repair workflow Send selected findings to an Agent

What it helps with. A local review finding can become a focused foreground Agent request carrying the evidence, location, impact, and recommendation already collected. The repair still follows the current provider, policy, sandbox, budget, checkpoint, and verification flow rather than receiving special hidden write authority.

230 Safe execution · Review-to-repair workflow Repair in an isolated worktree

What it helps with. Choose isolated repair to create a managed Git worktree where a background Agent can address selected findings without modifying the primary checkout. The run produces inspectable changes and status, letting ongoing foreground work continue while the repair is evaluated separately.

231 Safe execution · Review-to-repair workflow Run an automatic follow-up review

What it helps with. Background repair workflows can invoke a bounded reviewer after implementation and repeat for the configured number of repair rounds. Reviewer findings stay evidence-based and request-accounted, preventing an endless self-review loop or an unmeasured second model workflow.

232 Safe execution · Review-to-repair workflow Inspect the resulting diff before integration

What it helps with. A completed repair exposes the managed worktree’s diff and report before anything is integrated into the main checkout. Users can inspect changed files, verification evidence, remaining findings, and failure states, then choose their normal Git integration path with full context.

233 Safe execution · Runtime verification Launch request-owned development servers and watchers

What it helps with. start_process runs a local server, watcher, or interactive development process that remains available across later runtime tool calls in the same request. Output can be read incrementally and input can be written deliberately, while process ownership ensures finalization can stop the complete tree.

234 Safe execution · Runtime verification Use an isolated browser session

What it helps with. open_preview launches a fresh Chrome, Chromium, or Edge profile instead of reusing the developer’s personal browser state. The session contains no existing cookies, logins, history, or extensions, which keeps verification reproducible and prevents an Agent from inheriting personal credentials.

235 Safe execution · Runtime verification Inspect the DOM, console, network, and crashes

What it helps with. inspect_preview returns semantic page structure together with bounded console errors, failed network requests, blocked origins, and renderer-crash evidence. The Agent receives text observations it can reason about, while the local verification card retains visual proof and clear pass or failure state.

236 Safe execution · Runtime verification Exercise real interactions and responsive states

What it helps with. click_preview, type_preview, and select_preview_element let the Agent exercise visible controls and inspect a user-chosen element inside the isolated page. Combined with deliberate viewport changes and repeated inspection, this can verify behavior that a successful build or static source review cannot prove.

237 Safe execution · Runtime verification Capture screenshots as verification evidence

What it helps with. capture_preview_screenshot records the rendered interface in the local Runtime Verification card after meaningful states are reached. Screenshots support human review of layout, responsive behavior, and visible outcomes, while the model also receives bounded observations rather than relying on an unsupported claim that the page looked correct.

238 Safe execution · Live Server Agent Safe remote tools or an explicitly enabled full shell

What it helps with. Every Live Server connection chooses either root-bounded Safe Tools or separately warned Full Shell capability. Safe Tools never offers ssh_exec, while Full Shell can reach the complete SSH account and must remain visibly labeled so remote command authority cannot be mistaken for file-root access.

239 Safe execution · Live Server Agent Configured remote filesystem roots

What it helps with. Structured SSH file tools resolve POSIX paths beneath the canonical root chosen during connection. Traversal, target symlinks, likely secrets, and files too large for exact mutation are rejected, making the displayed remote root an enforced boundary rather than a suggested working directory.

240 Safe execution · Live Server Agent Health, log, process, and port inspection

What it helps with. Fixed SSH tools can inspect service status, bounded journal output, process lists, listening ports, and endpoint health without granting an arbitrary shell. These operations cover common deployment diagnosis while preserving recognizable inputs, outputs, time limits, and approval decisions.

241 Safe execution · Live Server Agent Atomic remote edits

What it helps with. Remote edit, write, and patch tools calculate the intended result, create recovery state, write through a same-directory temporary file, and rename into place. Multi-file patches roll back earlier targets if a later operation fails, reducing the chance of leaving a live deployment half-updated.

242 Safe execution · Live Server Agent Backups and rollback support

What it helps with. Each structured remote mutation creates a per-file backup under the SSH account’s CoderFriend state directory and retains only bounded metadata locally. Users and Agents can list recovery points and restore one explicitly, and transaction rollback continues even if the originating request is cancelled.

243 Safe execution · Request budgets & recovery Token and cost budgets

What it helps with. Root Agent requests can stop before another provider call when measured non-cache token usage or exact provider cost reaches the configured ceiling. Unknown cost is never counted as zero; token, call, iteration, and time safeguards continue while the interface reports that cost enforcement is unavailable.

244 Safe execution · Request budgets & recovery Time, tool-call, and iteration budgets

What it helps with. Separate limits bound total wall-clock duration, provider model calls, and Agent-loop iterations for one root request. Each ceiling has a distinct pause reason, helping users decide whether to continue intentionally instead of receiving a generic failure after an uncontrolled autonomous run.

245 Safe execution · Request budgets & recovery Budgets that include delegated subagent work

What it helps with. Planner, summary, reviewer, retry, and subagent calls inherit the root request’s accounting context rather than running as free hidden work. Delegated specialists also have per-child and shared token, exact-cost, concurrency, and time limits that can cancel the whole child pool when reached.

246 Safe execution · Request budgets & recovery Cancellation and continuation controls

What it helps with. Stop threads cancellation through provider calls, built-in transactions, MCP tools, sandboxed commands, runtime processes, browsers, and managed SSH work. A bounded pause can offer Continue as a fresh accountable request, preserving completed state without replaying paid calls or bypassing the limit that stopped them.

247 Safe execution · Request budgets & recovery Reload handoff for interrupted work

What it helps with. Saved background and conversation state survives for inspection after VS Code reloads, but active work is marked interrupted rather than automatically resumed. This makes the handoff honest: users can see what completed, inspect changes, and choose a next step without duplicate requests or assumed live processes.

248 Safe execution · Agent evaluations & scorecards A 72-task Agent evaluation suite

What it helps with. CoderFriend includes 72 reproducible coding tasks designed to exercise investigation, editing, verification, safety, and completion behavior across provider and model routes. Each task runs in an isolated evaluation workspace so benchmark changes do not contaminate the developer’s active repository.

249 Safe execution · Agent evaluations & scorecards Provider and model scorecards

What it helps with. Evaluation results are aggregated into scorecards keyed to the exact provider and model that performed the work. Users can compare completion quality, evidence, and failure patterns without treating every route from one model family as interchangeable.

250 Safe execution · Agent evaluations & scorecards Repeatable quality comparisons

What it helps with. The same corpus, harness, and scoring expectations can be rerun after a model, provider, prompt, or Agent implementation changes. Repeatability turns a subjective impression into comparable evidence while still exposing individual task output for deeper review.

251 Safe execution · Agent evaluations & scorecards Evidence for choosing the right route for a task

What it helps with. Scorecards help identify whether a route is strong at the kinds of repository work, safety constraints, and verification steps that matter to the team. They complement live price, speed, and context limits, giving model selection more substance than a provider name or leaderboard claim.

252 Safe execution · Exact approval memory Approve a sensitive action once

What it helps with. A one-time approval authorizes only the concrete action shown in the current prompt and creates no reusable rule. It is the safest way to allow an unusual external file, command, MCP call, browser interaction, Docker boundary, or live-server operation whose future variants should still be reviewed.

253 Safe execution · Exact approval memory Remember an exact command for the session, workspace, or globally

What it helps with. Save a complete shell command line after reviewing it, then choose whether that exact text applies only to the current session, the active workspace, or all workspaces. CoderFriend does not use executable-prefix approvals, because extra flags or shell chaining can turn a familiar prefix into different behavior.

254 Safe execution · Exact approval memory Remember an exact path or deliberate folder boundary

What it helps with. Authorize one resolved file path or a consciously selected containing folder at session, workspace, or global scope. Canonical path checks still run when the rule is used, preventing traversal or a misleading textual path from turning a narrow approval into access to another location.

255 Safe execution · Exact approval memory Keep likely secret files behind a dedicated approval decision

What it helps with. Workspace mode does not treat .env files, private keys, credential stores, and similarly shaped paths as ordinary project reads. A foreground request must surface the sensitive target for explicit authorization, while searches and approval-less delegated tools continue to omit it rather than asking indirectly.

256 Safe execution · Exact approval memory Inspect and edit saved approval rules from settings

What it helps with. The Settings Center exposes saved exact commands, exact paths, and path prefixes so remembered authority can be audited and removed without waiting for another prompt. Deprecated command-prefix settings are identified as ignored rather than silently providing broader execution than the interface describes.

257 Safe execution · Destructive-command intelligence Detect destructive filesystem and Git operations

What it helps with. Static command analysis recognizes deletion, shredding, truncation, raw disk writes, recursive ownership or permission changes, hard resets, cleaning, forced or delete pushes, history rewrites, dropped stashes, and forced branch deletion. The check scans the prepared command before approval or execution.

258 Safe execution · Destructive-command intelligence Detect database, container, infrastructure, and package-publish risks

What it helps with. The risk gate also identifies destructive database statements, container image or volume deletion, kubectl delete, Terraform destroy or apply, registry publishing, and related high-impact operations. These categories receive a concrete explanation so a prompt communicates consequences instead of showing only an opaque command string.

259 Safe execution · Destructive-command intelligence Scan chained shell commands instead of trusting the first executable

What it helps with. CoderFriend evaluates the complete shell line, including operations after pipes, semicolons, logical operators, and command substitutions. A harmless build step cannot launder a later rm, destructive Git command, or downloaded script past the approval classifier simply because it appears first.

260 Safe execution · Destructive-command intelligence Explain the concrete risk inside Ask and Workspace prompts

What it helps with. When a destructive pattern appears under a prompting policy, the approval dialog states the identified risk alongside the exact command and working boundary. Users can decide with relevant context rather than inferring impact from syntax, while Always Allow remains honest about bypassing the prompt entirely.

261 Safe execution · Destructive-command intelligence Keep risk classification deterministic and outside model influence

What it helps with. Risk rules are implemented as static command analysis, not a second model judgment that can be persuaded by untrusted repository text. The Agent cannot redefine a destructive operation as safe through its own prompt, and unsupported patterns still remain subject to the ordinary approval and sandbox layers.

262 Safe execution · Process-isolated command execution Use macOS sandbox-exec or Linux Bubblewrap when available

What it helps with. On macOS, supported command isolation uses sandbox-exec profiles; on Linux it uses Bubblewrap namespaces and mounts. CoderFriend verifies the required backend before execution and reports an actionable failure when isolation cannot be established instead of quietly launching the command unrestricted.

263 Safe execution · Process-isolated command execution Deny network access inside sandboxed project commands

What it helps with. Linux commands run in an unshared network namespace with no interfaces, while macOS commands receive a deny-network sandbox profile. The UI and documentation distinguish those enforcement models honestly, because macOS service-mediated escapes make its boundary a strong default rather than an equivalent hard namespace.

264 Safe execution · Process-isolated command execution Sanitize provider credentials from command environments

What it helps with. Sandboxed commands receive a reduced environment that excludes provider API keys and unrelated secrets, plus variables describing the active command boundary and sandbox. A toolchain can see whether it is confined without inheriting the credentials CoderFriend uses to contact model providers.

265 Safe execution · Process-isolated command execution Apply separate routine and recognized project-check timeouts

What it helps with. Routine shell commands receive a shorter process-tree timeout, while recognized repository verification such as builds, tests, Codeception, and Playwright can receive a larger bounded window. Long-running image generation and dependency setup are classified deliberately so legitimate work is not killed at the routine ceiling.

266 Safe execution · Process-isolated command execution Terminate the complete process group on timeout, overflow, or cancellation

What it helps with. Each sandboxed command owns a process group rather than only one child PID. Timeout, excessive output, or request cancellation escalates from TERM to KILL across the tree, preventing a wrapper script from ending while its compiler, test runner, watcher, or spawned shell keeps running.

267 Safe execution · Process-isolated command execution Fail closed when the required sandbox backend is unavailable

What it helps with. If the selected workspace-write or read-only policy cannot be enforced on the current platform, run_command returns an explicit error and does not fall back to unrestricted host execution. Users can repair the backend or consciously select sandbox off instead of receiving a hidden change in authority.

268 Safe execution · Docker-aware host verification Request a dedicated host-runtime approval when policy requires it

What it helps with. Direct Docker commands and Docker-backed repository targets can reach the host daemon beyond an ordinary command sandbox, so Ask and Workspace modes surface a one-shot host-runtime approval. Always Allow proceeds without a prompt, but the execution path still records that Docker is a distinct boundary.

269 Safe execution · Docker-aware host verification Run with a disposable home that omits personal Docker credentials

What it helps with. Approved host Docker execution receives a temporary home containing only the system Compose integration needed for the command. Personal Docker configuration, registry logins, and unrelated home-directory state are not copied into that environment merely because a repository test uses containers.

270 Safe execution · Docker-aware host verification Follow repository-declared Make and Compose targets

What it helps with. The Agent is directed to run the project’s documented Make or Compose entry points instead of reconstructing internal container commands from fragments. This preserves the same build topology maintainers use and makes verification output easier to compare with CI and developer instructions.

271 Safe execution · Docker-aware host verification Reject guessed Make targets when a static target list is available

What it helps with. When a Makefile can be read statically, CoderFriend detects a requested target that does not exist and returns the declared alternatives before spawning Make. The Agent can recover to a real project command without spending time inside Docker or inventing an e2e target from another repository.

272 Safe execution · Docker-aware host verification Recognize bounded Docker-backed Codeception and Playwright checks

What it helps with. Direct Codeception and Playwright invocations remain recognized project checks even when wrapped by Docker Compose. They receive the longer bounded verification window and full process-tree handling, allowing realistic application checks without turning container execution into an unlimited background task.

273 Safe execution · Atomic workspace-wide replacement Replace an exact literal across as many as 100 named files

What it helps with. replace_workspace_text takes an explicit list of workspace files plus one old and new literal, then replaces every exact occurrence in those named targets. It is optimized for bounded mechanical changes such as terminology, labels, imports, or configuration keys after one repository search identifies the scope.

274 Safe execution · Atomic workspace-wide replacement Skip files that do not contain the expected source text

What it helps with. A listed file with no exact old-string match is reported as skipped rather than rewritten or treated as an automatic failure. This lets one deliberate target set include nearby candidates while preserving clear counts of changed, skipped, and invalid files.

275 Safe execution · Atomic workspace-wide replacement Validate every target before any write begins

What it helps with. The replacement tool resolves policy, path, content, file-lock, and mutation constraints for the complete explicit list before committing changes. An invalid or unauthorized target cannot leave earlier files modified merely because it appeared later in the request.

276 Safe execution · Atomic workspace-wide replacement Roll back earlier files if a later mutation fails

What it helps with. All calculated after-states are written as one transaction, and a write failure restores targets already changed during that call. The tool reports the failure and rollback outcome, allowing the Agent to reassess the file set instead of continuing from an unknown half-replaced state.

277 Safe execution · Atomic workspace-wide replacement Record all successful replacements in the Agent checkpoint

What it helps with. Every changed file contributes its original and final content to the active AgentChangeSession just like patch, edit, write, and delete tools. The resulting checkpoint, diff, and guarded undo therefore represent the whole mechanical rewrite rather than only the last file touched.

278 Safe execution · Shell-edit checkpoint recovery Recognize explicit file targets in common shell-edit commands

What it helps with. Under maximum-trust execution, CoderFriend analyzes recognized shell mutation forms and extracts only direct, unambiguous file operands. Redirected, globbed, computed, or compound forms that cannot be mapped reliably remain ordinary shell side effects rather than being falsely advertised as checkpointed.

279 Safe execution · Shell-edit checkpoint recovery Capture a best-effort baseline before the command starts

What it helps with. For each explicit named target it can safely resolve, CoderFriend reads the pre-command content before launching the shell edit. Baseline capture is best effort and does not block an otherwise authorized maximum-trust command when a target cannot be identified or read.

280 Safe execution · Shell-edit checkpoint recovery Include detected shell-edited files in the request checkpoint

What it helps with. After the command finishes, files with captured baselines and real content changes join the same request checkpoint as built-in mutations. Their diffs become visible in Review Changes and eligible for guarded restore, extending recoverability to common direct shell edits without claiming universal command tracing.

281 Safe execution · Shell-edit checkpoint recovery Keep unidentified command side effects outside restore claims

What it helps with. Generic shell commands may change files, services, databases, containers, or remote state that CoderFriend cannot enumerate safely. Those unidentified side effects are not added to a checkpoint, and the interface and documentation state that limitation instead of implying Undo can reverse arbitrary host behavior.

282 Safe execution · Concurrent edit protection Acquire request-scoped file locks before mutation

What it helps with. Foreground, background, and delegated mutation tools claim canonical target paths through a request-scoped lock manager before writing. The lock belongs to the active run and is released during normal completion, failure, cancellation, or final cleanup rather than persisting as an unexplained project artifact.

283 Safe execution · Concurrent edit protection Detect path conflicts across concurrent Agent runs

What it helps with. A second Agent attempting to mutate a path already owned by another active request receives a conflict before the write begins. Canonical resolution catches equivalent path spellings, reducing the risk that two worktrees or automation surfaces silently interleave edits to the same underlying file.

284 Safe execution · Concurrent edit protection Release owned locks when work completes or is cancelled

What it helps with. Request finalization releases every lock acquired by that run whether it completed successfully, failed, timed out, or was stopped. Cleanup prevents an interrupted Agent from leaving a stale in-memory claim that blocks legitimate future edits after no process is working on the file.

285 Safe execution · Concurrent edit protection Report the conflicting run instead of racing the write

What it helps with. A lock conflict identifies the active ownership context and stops the mutation rather than retrying invisibly until one write wins. Users and coordinating Agents can wait, choose another task, or inspect the competing run with enough information to avoid accidental overwrite.

286 Safe execution · Diagnostics-guided repair Collect diagnostics after relevant workspace mutations

What it helps with. CoderFriend requests current language-service diagnostics for files affected by Agent edits and includes bounded results in the workflow. Compiler and editor evidence appears after the actual mutation, helping distinguish a plausible-looking patch from one that introduced a syntax, type, or import failure.

287 Safe execution · Diagnostics-guided repair Open exact diagnostic locations in VS Code

What it helps with. Diagnostic rows retain the workspace file, line, column, severity, source, and message needed to open the problem directly in the editor. The user can inspect surrounding code and language-service context instead of searching manually for an error summarized without a location.

288 Safe execution · Diagnostics-guided repair Give the Agent a bounded self-repair opportunity

What it helps with. New diagnostics can be returned to the same Agent for a limited correction pass while request budgets, iteration ceilings, cancellation, and tool policy remain active. Self-repair is not an endless loop and does not erase the original verification evidence if the fix fails.

289 Safe execution · Diagnostics-guided repair Distinguish pre-existing diagnostics from newly introduced failures

What it helps with. The workflow considers the diagnostic state around changed files so long-standing project warnings are not automatically blamed on the latest patch. Newly introduced or materially affected errors remain high priority, while pre-existing findings can be reported as context without inventing regression responsibility.

290 Safe execution · Diagnostics-guided repair Keep unresolved verification failures visible in the final result

What it helps with. If diagnostics remain after repair attempts, the Agent must state that verification did not pass and preserve the relevant evidence. CoderFriend does not convert an exhausted budget, cancelled check, or unresolved compiler error into a green completion state for presentation.

291 Safe execution · Evidence-backed completion Track understanding, editing, verification, and completion phases

What it helps with. The Agent activity model distinguishes investigation, mutation, project checks, runtime observation, and final reporting. This makes a request’s current phase visible and supports completion checks that can ask whether claimed implementation actually included edits and whether claimed verification produced evidence.

292 Safe execution · Evidence-backed completion Recognize repository-declared verification commands

What it helps with. CoderFriend reads relevant repository instructions and declared scripts before choosing build, test, lint, or application checks. Using project-owned commands reduces guessed verification, and a missing target can return available alternatives instead of being misreported as a failing codebase.

293 Safe execution · Evidence-backed completion Treat skipped host-only checks separately from failed checks

What it helps with. Extension-host, Electron, and similar checks can be declared skipped when an outer Agent command boundary cannot safely provide their required native GUI or nested isolation behavior. A suite containing only intentional documented skips is not labeled a test failure, but the missing coverage remains explicit.

294 Safe execution · Evidence-backed completion Report unverified work honestly instead of inventing success

What it helps with. Completion claims must match observable edits, diagnostics, command results, runtime evidence, review output, or a clearly stated inability to verify. When a check cannot run, times out, or fails, the final response reports that limitation rather than extrapolating success from source inspection alone.

295 Safe execution · Isolated browser interaction Open localhost previews in a fresh Chrome, Chromium, or Edge profile

What it helps with. open_preview detects a supported browser and launches a new request-owned profile for the local application URL. The profile starts without personal cookies, authentication, extensions, or history, making test results independent from the developer’s everyday browser session.

296 Safe execution · Isolated browser interaction Inspect semantic DOM content and selected elements

What it helps with. inspect_preview returns a bounded semantic view of visible structure, controls, text, accessibility state, and a user-selected element when requested. The Agent can reason about the rendered application and target a real interface component without receiving an unlimited raw DOM dump.

297 Safe execution · Isolated browser interaction Capture console errors, failed network requests, and renderer crashes

What it helps with. Runtime observations collect console errors, failed requests, blocked origins, and renderer-crash state alongside normal page content. Warning-only console output stays visible without automatically failing verification, while errors and crashes produce a clear failure signal for repair.

298 Safe execution · Isolated browser interaction Click controls, enter non-secret text, and exercise user flows

What it helps with. click_preview and type_preview can exercise ordinary visible interactions inside the isolated profile, while select_preview_element lets the user identify a target directly. The Agent is instructed never to request, read, or type credentials; authenticated flows require the user to sign in themselves.

299 Safe execution · Isolated browser interaction Approve external navigation and newly requested page origins explicitly

What it helps with. Localhost preview is available for project verification, but a public top-level URL and page-requested CDN or API origins follow the selected approval policy. Ask and Workspace modes surface the new external boundary, while Always Allow proceeds consistently rather than creating a hidden refusal.

300 Safe execution · Isolated browser interaction Capture screenshots as local verification evidence

What it helps with. Runtime screenshots record the visible state reached after opening, resizing, or interacting with the page and appear in the local verification card. They help users judge layout and visual behavior while DOM, console, network, and crash observations provide complementary machine-readable evidence.

301 Safe execution · Isolated browser interaction Remove request-owned browser profiles and processes at finalization

What it helps with. The runtime controller tracks the browser profile and process tree created for the request and closes them during completion, cancellation, timeout, or cleanup. Temporary verification state does not become a persistent browser installation or an abandoned background process after the Agent stops.

302 Safe execution · SSH connection identity & trust Reuse OpenSSH configuration and the user’s existing ssh-agent

What it helps with. Live Server connections use the system OpenSSH client with normal host-key verification, BatchMode, existing ~/.ssh/config aliases, and keys already available through ssh-agent. CoderFriend does not collect or persist SSH passwords, private keys, agent material, or a long-lived control socket.

303 Safe execution · SSH connection identity & trust Choose from recent targets, SSH aliases, or deliberate manual entry

What it helps with. The connection picker lists as many as ten validated successful targets in newest-first order, followed by concrete aliases discovered from SSH configuration and a manual user@host path. Failed attempts are not remembered, and history can be cleared without changing the user’s OpenSSH files.

304 Safe execution · SSH connection identity & trust Label the target as Production, Staging, or Development

What it helps with. Every connection receives an explicit environment identity before Agent access begins. The Production, Staging, or Development label remains visible beside the target so prompts, approvals, progress, and final reports carry the operational context of the machine being changed.

305 Safe execution · SSH connection identity & trust Keep host, structured root, capability, and trust visible in the UI

What it helps with. The sidebar and status bar continuously show the selected host, canonical Safe Tools root, Safe Tools or Full Shell capability, and current trust mode. This prevents a remembered remote session from looking like a local workspace or a restricted root from being confused with account-wide shell access.

306 Safe execution · SSH connection identity & trust Expire connection state and trusted-session authority on reload

What it helps with. Active connection metadata and trusted-session approval live only in memory and expire when the extension host reloads. Selecting a remembered target re-enters the normal connection flow, so recent history cannot silently restore remote trust or Full Shell capability in a new session.

307 Safe execution · SSH Safe Tools sandbox Read remote files with ssh_read_file

What it helps with. ssh_read_file resolves a root-relative POSIX path on the remote host, rejects traversal and target symlinks, and returns bounded text with line information. It can read a normal whole file within the mutation-size boundary or transfer only a requested range or tail for larger inspection work.

308 Safe execution · SSH Safe Tools sandbox Search one remote file with ssh_search_file

What it helps with. ssh_search_file runs bounded grep-style matching on the remote host and transfers only matching lines plus the total count. A multi-megabyte or rotating log can therefore be searched without downloading the complete file into local memory or consuming the model context window.

309 Safe execution · SSH Safe Tools sandbox List remote folders with ssh_list_directory

What it helps with. ssh_list_directory returns structured bounded entries beneath the configured canonical root rather than parsing an arbitrary ls shell transcript. Paths are checked physically against the root and likely secret names are filtered, giving the Agent a safe way to discover remote deployment structure.

311 Safe execution · SSH Safe Tools sandbox Edit exact remote text with ssh_edit_file

What it helps with. ssh_edit_file replaces one expected literal in a root-bounded remote file after validating the current content and creating a recovery point. Ambiguous or stale source fails clearly, so an Agent cannot apply a surgical production change at a guessed location after the file has changed.

312 Safe execution · SSH Safe Tools sandbox Write a remote file atomically with ssh_write_file

What it helps with. ssh_write_file validates the complete intended content, sends it through stdin to a same-directory temporary file, and renames that file into place. Existing targets receive a remote backup first, and cancellation or transport failure cannot present a partial streamed file as a successful write.

313 Safe execution · SSH Safe Tools sandbox Apply transactional remote diffs with ssh_apply_patch

What it helps with. ssh_apply_patch reuses the bounded unified-diff parser and calculates every target after-state locally before remote mutation starts. It creates recovery points for the file set and restores earlier targets when a later step fails, preserving all-or-rollback behavior across a multi-file live-server change.

315 Safe execution · SSH Safe Tools sandbox Omit ssh_exec from the model toolset in Safe Tools mode

What it helps with. When Safe Tools is selected, ssh_exec is not advertised to the model and runtime dispatch rejects an attempted call if one is fabricated. The Agent can still inspect files and operations through structured SSH tools, but it cannot escape the remote root by inventing an arbitrary shell command.

316 Safe execution · SSH Full Shell authority Show a dedicated Full Shell warning before connection

What it helps with. Choosing Full Shell opens a separate warning that explains ssh_exec is not confined to the structured file-tools root and may use everything the SSH account can access, including sudo. The connection proceeds only after that broader capability decision is made deliberately.

317 Safe execution · SSH Full Shell authority Keep the FULL SHELL state visible for the connection lifetime

What it helps with. A connected Full Shell target retains an unmistakable FULL SHELL label in the remote identity surface instead of reverting to a generic connected state. The persistent warning helps users notice that a later request has account-wide command capability even if the original modal is no longer on screen.

318 Safe execution · SSH Full Shell authority Allow ssh_exec to reach everything available to the SSH account

What it helps with. ssh_exec runs a foreground remote command through the selected OpenSSH account and is intentionally not restricted by the Safe Tools root. Its reach includes paths, services, network access, and executables allowed to that account, so approval and visible capability state—not a misleading cwd—define the risk.

319 Safe execution · SSH Full Shell authority Treat sudo and remote shell side effects as outside the file-tools root

What it helps with. Full Shell can invoke sudo when the remote account permits it and can change state that structured backup tools do not track, including databases, services, containers, and files elsewhere. CoderFriend does not claim its file-root backups can undo those arbitrary command effects.

320 Safe execution · SSH Full Shell authority Keep command approval policy separate from shell capability

What it helps with. Full Shell determines which remote command tool exists, while Ask, Workspace, trusted-session, and Always Allow determine whether a permitted call needs a prompt. Enabling one does not silently enable the other, and local saved approval rules never transfer automatically to the remote connection.

321 Safe execution · SSH large-file inspection Read a selected remote line range on the host

What it helps with. Pass startLine and endLine to ssh_read_file to run bounded sed-style extraction on the remote host and transfer only that window. This makes a known section of a large configuration or log available for diagnosis without pretending the entire oversized file was read.

322 Safe execution · SSH large-file inspection Tail the newest remote lines without whole-file transfer

What it helps with. Pass tailLines to ssh_read_file to execute the tail operation remotely and receive only the latest bounded records. The workflow is suited to active application logs where downloading the complete historical file would be slow, stale, and unnecessarily expensive in model context.

323 Safe execution · SSH large-file inspection Run remote grep and return bounded matching lines

What it helps with. ssh_search_file performs matching where the file lives and returns a bounded set of line-numbered hits together with a total match count. The Agent can refine a query or request a surrounding range while keeping nonmatching log content off the wire.

324 Safe execution · SSH large-file inspection Preserve strict whole-file size limits for mutation tools

What it helps with. Windowed reading does not weaken the exact-content requirement for ssh_edit_file, ssh_write_file, or ssh_apply_patch. A file too large for safe whole-file validation remains ineligible for structured mutation, because a partial view cannot support trustworthy after-state calculation and rollback.

325 Safe execution · SSH operational diagnostics Inspect a service state with ssh_service_status

What it helps with. ssh_service_status accepts a bounded service identifier and returns fixed status information rather than an arbitrary shell expression. It gives the Agent enough evidence to distinguish stopped, failed, and running deployment services while keeping Safe Tools mode free of general command execution.

326 Safe execution · SSH operational diagnostics Read bounded journal output with ssh_read_logs

What it helps with. ssh_read_logs retrieves a limited slice of remote journal output for an approved service using a structured request. Time and line bounds prevent an Agent from streaming an endless system log, while stderr remains separate so transport warnings cannot be mistaken for application log content.

327 Safe execution · SSH operational diagnostics List remote processes with ssh_list_processes

What it helps with. ssh_list_processes returns a bounded process snapshot suitable for identifying duplicate servers, unexpected workers, or the owner of a port. It is an inspection tool rather than a kill interface, so Safe Tools diagnosis does not quietly become arbitrary remote process control.

328 Safe execution · SSH operational diagnostics Check a listening port with ssh_check_port

What it helps with. ssh_check_port asks the host whether a specific validated port is listening and returns the bounded observation. This separates a process that exists from a service that is actually accepting connections, helping the Agent choose the next diagnostic step without constructing a shell pipeline.

329 Safe execution · SSH operational diagnostics Run a bounded endpoint health check with ssh_health_check

What it helps with. ssh_health_check probes a deliberate remote endpoint with fixed limits and reports its status, response timing, and bounded result. The tool can verify that a deployment responds after an edit or restart while preventing open-ended browsing or credential entry through the SSH diagnostic surface.

330 Safe execution · SSH operational diagnostics Keep stdout protocol data separate from remote stderr diagnostics

What it helps with. The SSH transport preserves an interleaved diagnostic view but also maintains a clean stdout channel for base64 files, host identity, directory records, and managed-process markers. Login banners, rc-file warnings, ioctl messages, and command errors therefore cannot be decoded as trusted protocol payloads.

331 Safe execution · SSH managed process lifecycle Start a request-owned remote process with ssh_start_process

What it helps with. ssh_start_process launches a temporary remote server or watcher in its own managed session for later tool calls in the same foreground request. The command cannot elevate or detach, and the remote host must provide the lifecycle utilities needed to enforce a hard maximum lifetime.

332 Safe execution · SSH managed process lifecycle Read status and bounded output with ssh_process_status

What it helps with. ssh_process_status checks whether the managed job is still active and returns only the bounded output recorded for that request-owned process. The Agent can wait for readiness, inspect a failure, or verify ongoing behavior without starting a second untracked SSH command.

333 Safe execution · SSH managed process lifecycle Stop a managed process with ssh_stop_process

What it helps with. ssh_stop_process terminates the selected request-owned job through its recorded process-group identity and verifies the cleanup outcome. A model cannot use it as a generic remote kill command, because handles are scoped to processes CoderFriend created for the active request.

334 Safe execution · SSH managed process lifecycle Terminate ordinary ssh_exec process groups on finish, timeout, or cancellation

What it helps with. Foreground ssh_exec work runs under a private remote lease that records a dedicated process group. Normal completion, timeout, cancellation, and output limits trigger independent TERM and KILL cleanup with verification, preventing a child server from surviving merely because the SSH parent exited.

335 Safe execution · SSH managed process lifecycle Clean registered leases when a request ends or the target changes

What it helps with. Before successful foreground completion, disconnect, or target switching, CoderFriend walks every registered remote lease and verifies its request-owned process tree is gone. Cleanup runs independently from the cancelled request token so stopping the Agent cannot also cancel the cleanup responsible for making Stop true.

336 Safe execution · SSH managed process lifecycle Require explicit approval for persistent process escapes

What it helps with. Detected background operators, detached containers, and external supervisors are blocked unless allowPersistentProcesses is supplied intentionally. Ask and Workspace modes require a separate approval even in a trusted SSH session, and the resulting persistent process is clearly documented as outside CoderFriend’s automatic ownership and cleanup.

337 Safe execution · SSH atomic backup & recovery Create a remote backup before each structured mutation

What it helps with. Before ssh_edit_file, ssh_write_file, or ssh_apply_patch changes an existing target, CoderFriend copies its current content into the remote recovery directory. Backup creation is part of the guarded mutation path, so a write is not reported successful when the required recovery point could not be established.

338 Safe execution · SSH atomic backup & recovery Store backup payloads on the remote host instead of in local history

What it helps with. Recovery content lives under ~/.local/state/coderfriend-ai/backups on the SSH host, close to the files and permissions it may need to restore. Local workspace state keeps only bounded metadata, avoiding silent replication of production source or configuration into conversation history.

339 Safe execution · SSH atomic backup & recovery List bounded recovery metadata with ssh_list_backups

What it helps with. ssh_list_backups returns the available recovery identifiers, target paths, timestamps, and bounded details needed to choose a restore point. It does not stream every backup payload to the model, keeping historical remote content private until a deliberate restoration is requested.

340 Safe execution · SSH atomic backup & recovery Restore a selected recovery point with ssh_restore_backup

What it helps with. ssh_restore_backup validates the chosen metadata, target boundary, current state, and approval before replacing the remote file from its stored recovery payload. Restore is an explicit mutation with a visible outcome, not an automatic rollback triggered by an unrelated later request.

341 Safe execution · SSH atomic backup & recovery Roll back earlier files when a multi-file remote patch partially fails

What it helps with. A remote unified patch calculates all after-states before writing and retains a recovery point for every target. If one later file cannot be committed, the transaction restores files already changed and reports both the primary failure and any rollback problem rather than leaving silent partial deployment.

342 Safe execution · SSH atomic backup & recovery Allow rollback to finish even when the originating request is cancelled

What it helps with. Transaction recovery deliberately does not reuse the cancelled Agent token that interrupted the original work. Cleanup gets its own bounded execution path, ensuring a Stop request cannot strand the remote server between several files simply by cancelling the rollback operation too.

343 Safe execution · Resilient Agent execution Explain a missing executable the first time it fails

What it helps with. When a command returns the shell’s executable-not-found failure on its first attempt, CoderFriend reports the missing tool and keeps platform-appropriate installation guidance readable. The Agent can install, choose a repository alternative, or stop without wasting another turn misreading empty stdout as a different problem.

344 Safe execution · Resilient Agent execution Distinguish shell parse failure from a command that actually ran

What it helps with. Command handling preserves stderr and exit context so malformed shell syntax is not summarized as successful execution or as the output of the first token. The Agent receives an actionable parse failure and can correct quoting or command construction before claiming any verification occurred.

345 Safe execution · Resilient Agent execution Guide absolute-path work back to the correct workspace boundary

What it helps with. When a command names a project through an absolute path rather than cd, boundary analysis still identifies that it leaves the current workspace. The resulting approval or error explains the actual target, helping the user open the intended repository or grant deliberate external access instead of seeing a generic denial.

346 Safe execution · Resilient Agent execution Bound each provider call with a configurable timeout

What it helps with. coderfriend-ai.providerCallTimeoutSeconds limits one HTTP or subscription-provider model call independently from the complete Agent request wall clock. A silent provider is abandoned with an explicit message and no invented content or token usage, while slower healthy routes can receive a deliberate larger bound.

347 Safe execution · Resilient Agent execution Retry unsupported provider-native tools once through guarded CoderFriend tools

What it helps with. If a provider such as Codex attempts its own shell, file, web, MCP, or collaboration tool outside CoderFriend’s boundary, the turn is interrupted and retried once with the guarded dynamic tools it was given. A repeated attempt stops visibly, preventing an unlimited loop or hidden provider-side execution.

348 Safe execution · Time-sensitive remote steering Send steering only to the active run

What it helps with. Direct a clarification to the session currently being watched.

349 Safe execution · Time-sensitive remote steering Refuse stale delivery instead of queuing it

What it helps with. Show that an unsent correction was not deferred to a later point in the run.

350 Safe execution · Time-sensitive remote steering Preserve deliberate human control

What it helps with. Let you review and resend a correction when the current run can receive it.

351 Safe execution · End-to-end encrypted remote sessions Verify pairing on both devices

What it helps with. Compare the same fingerprint on the phone and desktop before trusting the connection.

352 Safe execution · End-to-end encrypted remote sessions Seal remote session traffic

What it helps with. Protect transcript, steering, and stop messages between the paired desktop and phone.

353 Safe execution · End-to-end encrypted remote sessions Keep the relay blind to content

What it helps with. Route ciphertext through infrastructure that cannot read the remote session.

354 Safe execution · End-to-end encrypted remote sessions Reject incompatible protocol versions

What it helps with. Refuse a mismatched wire contract during the WebSocket handshake instead of misreading later frames.

355 Safe execution · Excluded-folder context protection Excluded folders stay out of model context

What it helps with. Apply workspace exclusions before attached folders, automatic context, and repository-search evidence are assembled for a provider request.

356 Safe execution · Excluded-folder context protection Use project-specific exclusion rules

What it helps with. Respect the workspace’s configured ignore and exclusion patterns instead of relying on one hard-coded directory list.

357 Safe execution · Excluded-folder context protection Filter nested files before transmission

What it helps with. Remove matching descendants while walking folder trees so selecting a parent folder does not bypass its protected children.

358 Safe execution · Excluded-folder context protection Keep local-only material on disk

What it helps with. Avoid silently including dependencies, build artifacts, private working directories, and other intentionally excluded files in hosted-model prompts.

359 Safe execution · Profile-controlled secret-file access Deny likely secret files without an approval loophole

What it helps with. When Secret files is off, file-reading tools refuse recognized credential and private-key paths instead of presenting a prompt that could be accepted accidentally.

360 Safe execution · Profile-controlled secret-file access Resolve real paths before applying the rule

What it helps with. Canonical-path checks prevent a symbolic link from disguising a protected file under a harmless-looking name.

361 Safe execution · Profile-controlled secret-file access Extend the boundary to Claude subscription mode

What it helps with. Equivalent Claude Code read deny rules cover its Read, Grep, and Glob operations when secret-file access is disabled.

362 Safe execution · Profile-controlled secret-file access Let policy and team roles enforce the restriction

What it helps with. Managed policy and viewer or developer roles can deny secret-file reads even when a local preset would otherwise permit them.

363 Safe execution · Profile-aware Agent step limits Name the active limit when a run stops

What it helps with. A cut-off Agent run reports whether its ceiling came from the selected guardrail profile or the legacy Agent iteration setting.

364 Safe execution · Profile-aware Agent step limits Point to the control that can change the outcome

What it helps with. When a profile maximum replaces the legacy setting, the notice directs you to that profile rather than suggesting an ineffective setting change.

365 Safe execution · Profile-aware Agent step limits Keep completed work available for continuation

What it helps with. Reaching the step ceiling preserves the work already produced and leaves the run ready to continue.

366 Safe execution · Organization policies & roles Restrict providers, tools, and request resources

What it helps with. A managed policy can withdraw capabilities, restrict provider sources, and lower request token, cost, time, call, or iteration ceilings. It is applied after user, provider, and exact-model policy resolution.

367 Safe execution · Organization policies & roles Tighten approvals and sandbox boundaries

What it helps with. Managed approvals and sandbox choices can make an existing policy more restrictive. A machine policy cannot silently grant a tool, remove a stricter user restriction, or widen the workspace boundary.

368 Safe execution · Organization policies & roles Choose Viewer, Developer, Maintainer, or Admin roles

What it helps with. Organization roles provide named starting restrictions: Viewer withdraws Agent tools, Developer requires per-action approvals and disables subagents, and Maintainer retains the workspace sandbox. Admin adds no role restriction; explicit managed policy still applies.

369 Safe execution · Organization policies & roles Use administrator-declared credential sources

What it helps with. An administrator can name the environment variable that supplies a provider key. When that declared source is empty, the connection explains the missing managed credential and does not fall back to a personally stored key.

370 Safe execution · Organization policies & roles Set retention periods for local records

What it helps with. Managed retention can prune old conversations, memories, completed run reports, and audit entries according to separate day limits. This controls the extension’s local records; exported copies and provider-side data remain separate.

371 Safe execution · Project checks before tools Enable repository hooks deliberately

What it helps with. Lifecycle hooks are optional and repository hooks require their own trust setting. Hook definitions live in .coderfriend/hooks.json, so accepting a repository does not silently authorize its command checks.

372 Safe execution · Project checks before tools Apply pre-tool checks that can narrow a request

What it helps with. Connected preToolUse hooks can deny a tool call, request the existing approval flow, or attach a reason. A hook cannot grant authority that the resolved request policy already withholds.

373 Safe execution · Project checks before tools Bound hook execution and report failures

What it helps with. Hook execution limits time, output, environment, and the number of checks. A failed deciding hook asks for a decision through the current approval policy instead of being treated as a successful check.

374 Safe execution · Local audit log & verification Record activity only after audit logging is enabled

What it helps with. Audit logging is off by default. Enabling it records connected activity from that point onward in the extension’s local storage, with redacted and bounded detail rather than a retroactive history claim.

375 Safe execution · Local audit log & verification Verify the retained audit chain

What it helps with. Verify Audit Log checks the sequence and linked entry hashes and reports where verification first fails. This helps reveal an altered or missing retained entry; a local file is not an independently authenticated or tamper-proof service.

376 Safe execution · Local audit log & verification Export the log with its verification result

What it helps with. Export Audit Log writes the retained JSON chain and reports whether it verifies. This gives support or internal review a concrete local artifact without uploading it automatically.

377 Safe execution · Local audit log & verification Bound retention without blocking coding work

What it helps with. The recorder limits retained entries and honors the managed audit-retention period. Disk writes are best effort, so recording does not become a guarantee that every action is durably logged or a reason to stop a coding request.

378 Models & orchestration · 12 model sources Ollama Local and Ollama Cloud

What it helps with. Run models from a local Ollama endpoint without an API key, or connect to Ollama Cloud with its own secure credential and endpoint. Both routes use the same CoderFriend conversation, mode, tool, policy, and accounting surfaces while preserving their distinct model catalogs and authentication.

379 Models & orchestration · 12 model sources LM Studio on your own machine

What it helps with. Connect a running loopback LM Studio server, choose an available chat model, and use optional authentication only when the server requires it. Local inference stays outside spending-budget accounting.

380 Models & orchestration · 12 model sources OpenAI Codex with ChatGPT and OpenAI API

What it helps with. Choose ChatGPT-authenticated Codex through the shared app-server login or direct OpenAI API access through a separately stored key. CoderFriend keeps the routes distinct because their catalogs, billing visibility, authentication, and available request controls are not interchangeable.

381 Models & orchestration · 12 model sources Google Gemini

What it helps with. Connect directly to the native Gemini API with GOOGLE_API_KEY or GEMINI_API_KEY support and a provider-specific endpoint. Gemini models appear only in their own catalog, retain their own mode and reasoning selections, and use CoderFriend’s normal guarded Agent tools rather than a separate workspace integration.

382 Models & orchestration · 12 model sources Anthropic Claude API and Claude subscription

What it helps with. Use Claude through the native Anthropic Messages API with an API key, or through the installed Claude Code CLI and its existing subscription login. The two choices share the Claude model source while retaining their own tool, image, authentication, and billing behavior.

383 Models & orchestration · 12 model sources OpenRouter and DeepSeek

What it helps with. Connect OpenRouter for routed multi-vendor models or use DeepSeek’s direct API as an independent provider source. Each route has its own secure key, endpoint, model catalog, usage semantics, exact pricing identity, and account links so one cannot silently borrow configuration from the other.

384 Models & orchestration · 12 model sources xAI, Groq, and Mistral

What it helps with. Enable xAI, Groq, and Mistral as first-class API providers with separate credentials, endpoints, live catalogs, and remembered model choices. Their requests still pass through CoderFriend’s shared context, tool, approval, sandbox, retry, budget, and conversation-accounting infrastructure.

385 Models & orchestration · Cross-provider continuity Provider-neutral conversation history

What it helps with. CoderFriend stores user and assistant messages in a neutral transcript instead of persisting one provider’s private request envelope as the conversation. That representation can be sent through another selected route on a later turn while provider-specific transport and tool formatting are rebuilt safely.

386 Models & orchestration · Cross-provider continuity Switch models without starting over

What it helps with. Choose another exact model or provider in the composer and send the next message with the retained thread; changing the selector alone sends nothing. This supports deliberate handoffs—for example, a fast diagnosis followed by a stronger implementation model—without copying the conversation between applications.

387 Models & orchestration · Cross-provider continuity Reuse attached project context across turns

What it helps with. Retained files, folders, selected source, images, instructions, documentation, and relevant conversation state remain associated with the thread when the provider changes. CoderFriend rebuilds the next route’s input from that shared context rather than requiring the user to attach the same project evidence again.

388 Models & orchestration · Cross-provider continuity Choose the right cost, speed, or reasoning profile per request

What it helps with. A single thread can route one turn to a low-latency model, another to a deep-reasoning model, and another to a local model according to the task. Visible provider, model, speed, reasoning, cost status, and policy controls make each handoff explicit instead of claiming all routes behave identically.

389 Models & orchestration · Codex with ChatGPT Sign in through the Codex authentication flow

What it helps with. Selecting the Codex route checks the shared Codex account and opens the official ChatGPT browser authorization flow only when no valid session exists. CoderFriend waits for completion, refreshes the authenticated catalog, and retries one interrupted operation instead of asking for an OpenAI API key.

390 Models & orchestration · Codex with ChatGPT Use supported Codex models from CoderFriend

What it helps with. The model picker uses the authenticated Codex app-server model/list response as its authoritative catalog. Codex remains a model transport: file, command, web, MCP, browser, approval, sandbox, cancellation, and checkpoint work returns to CoderFriend’s guarded dynamic tool loop.

391 Models & orchestration · Codex with ChatGPT Keep Codex alongside every other configured provider

What it helps with. ChatGPT-authenticated Codex appears in the same provider selector as local Ollama, subscription Claude, and API-backed routes. Its token usage can join the conversation HUD, while exact per-request USD cost remains N/A because a ChatGPT plan does not expose that charge.

392 Models & orchestration · Claude subscription support Claude Code subscription transport

What it helps with. Subscription mode launches the locally installed Claude Code CLI through the user’s existing official sign-in rather than sending ANTHROPIC_API_KEY. CoderFriend discovers the executable on PATH, in a home install, or inside the Anthropic VS Code extension, and bounds silent output with the provider-call timeout.

393 Models & orchestration · Claude subscription support Support for Claude Pro and Max workflows

What it helps with. Users with a valid Claude Code Pro or Max login can run CoderFriend conversations through that subscription transport while retaining CoderFriend modes, context, guarded tools, activity, and usage counts the CLI reports. Exact billed USD remains unavailable when the subscription transport does not expose it.

394 Models & orchestration · Claude subscription support Claude API remains available as a separate route

What it helps with. Choose Claude API for the native Anthropic Messages endpoint and secure API key, or Claude subscription for the existing Claude Code sign-in. API image parts and signed thinking follow the native transport; subscription image attachments require its Read tool. Choosing one transport does not overwrite the other’s credentials.

395 Models & orchestration · Claude subscription support Inspect attached images through Claude subscription

What it helps with. When the Claude subscription request permits its Read tool, supported attached image data is made available as temporary files for the model to inspect, then removed after the request. A request without Read, an unavailable file, or a remote image URL is identified as unavailable rather than silently treated as seen.

396 Models & orchestration · Secure API connections Keys stored with VS Code SecretStorage

What it helps with. Provider and web-search API keys are written to VS Code SecretStorage rather than ordinary JSON settings or repository files. Legacy plaintext configuration values are migrated and cleared, while supported environment variables remain an intentional alternative for users who manage credentials outside the extension.

397 Models & orchestration · Secure API connections Guided provider setup

What it helps with. Set Provider API Key opens a provider-specific picker that can add, replace, or remove the credential for one route. Selecting an API-backed provider with no available key explains what is missing and opens the secure setup path, while local and subscription routes avoid irrelevant key prompts.

398 Models & orchestration · Secure API connections Remove a saved key at any time

What it helps with. The removal command can delete one or every stored provider credential after explicit confirmation, and individual setup flows can clear their selected key. Because VS Code cannot guarantee an extension receives a pre-uninstall event, the dedicated command is the reliable cleanup path before uninstalling.

399 Models & orchestration · Secure API connections Independent credentials for each provider

What it helps with. Ollama Cloud, OpenAI, Gemini, Anthropic, OpenRouter, DeepSeek, xAI, Groq, Mistral, optional authenticated LM Studio, and web-search services keep separate secret entries. The active route resolves its own credential, with an administrator-declared source taking precedence where configured.

400 Models & orchestration · Portable provider setup Export provider setup

What it helps with. Export API Keys and Settings writes an editable setup template with explicit overrides and placeholders for every supported provider key; a populated export can also serve as a migration backup. Extension defaults are omitted so an old file cannot freeze obsolete defaults on a fresh install.

401 Models & orchestration · Portable provider setup Import a saved setup

What it helps with. Import validates the portable JSON, applies supported setting overrides, and writes real keys back into VS Code SecretStorage. Unchanged placeholders do not delete existing credentials, allowing the same template to configure only selected providers without erasing routes already present on the machine.

402 Models & orchestration · Portable provider setup Keep provider choices consistent across machines

What it helps with. The portable format can carry provider enablement, endpoints, exact per-mode model selections, favorites, aliases, and other explicit CoderFriend overrides to another installation. Because populated exports contain plaintext secrets, the workflow warns users to keep them private and never commit them.

403 Models & orchestration · Model favorites & aliases Favorite frequently used models

What it helps with. Star models in the picker to keep preferred routes easy to find inside a large live provider catalog. Favorites are stored per provider, survive catalog refreshes, and do not rewrite the underlying model identifier needed for requests, pricing, evaluation, or attribution.

404 Models & orchestration · Model favorites & aliases Give model identifiers readable aliases

What it helps with. Map a memorable local alias to an exact provider model ID when the official identifier is long or operationally awkward. The UI can display and accept the alias while requests, rate lookup, scorecards, and debug output retain the real model identity rather than pricing a nickname.

405 Models & orchestration · Model favorites & aliases Choose models by provider and working mode

What it helps with. Chat, Plan, Agent, and inline completion each remember their own model selection for every enabled provider. A route optimized for completion therefore does not need to replace the model chosen for autonomous repository work, and switching providers restores that source’s prior mode-specific choices.

406 Models & orchestration · Model favorites & aliases Control speed and reasoning where supported

What it helps with. Processing speed and reasoning effort are independent selectors backed by provider capabilities rather than generic decorative values. CoderFriend remembers each choice per provider and omits unsupported options from the API request, avoiding silent fallback claims or invalid cross-provider parameters.

407 Models & orchestration · Profiles & guardrails Default, Architect, Reviewer, and Explainer profiles

What it helps with. Built-in profiles provide distinct working instructions for general assistance, architecture, evidence-focused review, and clear explanation. Selecting one changes the behavior guidance for the next request while leaving provider, model, permission, sandbox, and resource decisions visible as separate controls.

408 Models & orchestration · Profiles & guardrails Custom profile instructions

What it helps with. Edit the behavioral instructions for Default, Architect, Reviewer, or Explainer conversation profiles. These instructions shape the assistant’s stance and response style; the separate Trust policy controls tool authority, approvals, sandboxing, and budgets.

409 Models & orchestration · Profiles & guardrails Provider and model exceptions

What it helps with. Start with one general policy, then define an exception for a provider or an exact provider/model pair whose tools, writes, sandbox, approvals, or budgets need different treatment. Resolution applies the most specific layer at request time so a narrow model cannot inherit broader authority accidentally.

410 Models & orchestration · Profiles & guardrails Guardrails that travel with the selected profile

What it helps with. The Trust selector resolves a general policy with narrower provider and exact-model exceptions, then applies any machine-level restrictions. Its effective tool, approval, sandbox, and resource limits remain separate from the Profile persona that changes how the assistant explains and approaches a task.

411 Models & orchestration · Prompt caching Provider-aware cache support

What it helps with. CoderFriend formats stable system and repository instruction segments for prompt caching on supported Anthropic, OpenAI, and DeepSeek routes while respecting each provider’s API semantics. Unsupported providers receive normal context without a fake cache claim or incompatible metadata copied from another transport.

412 Models & orchestration · Prompt caching Cached-token visibility in usage reporting

What it helps with. The Conversation Usage card records cache reads and writes when a provider reports them and shows cache-hit activity separately from prompt, output, thinking, and tool-result input. Provider-specific cache pricing is used only when the exact rate and complete billable categories are known.

413 Models & orchestration · Prompt caching Useful for recurring repository context

What it helps with. Stable system guidance, repository instructions, and repeated conversation prefixes can be reused by a provider instead of processed as entirely new input on every Agent step. Cache reads remain visible and priced, but they are excluded from request token ceilings so repetition does not consume the work budget quadratically.

414 Models & orchestration · Usage & cost visibility Conversation HUD for input, output, and thinking tokens

What it helps with. The sidebar usage card aggregates provider-reported prompt, visible output, separately billed thinking, and total token categories for the current conversation. Counts come from provider boundaries rather than text-length guesses, and unsupported categories remain absent instead of being fabricated for visual consistency.

415 Models & orchestration · Usage & cost visibility Tool and cache usage visibility

What it helps with. Where providers expose them, the HUD separates tool-result input, cache reads, cache writes, and cache-hit percentage from ordinary prompt traffic. This helps explain why a long Agent run consumed tokens even when the final visible answer was short, without treating cached input as free or invisible.

416 Models & orchestration · Usage & cost visibility Estimated cost and turn count

What it helps with. Each completed request contributes a turn and a cost only when the provider reports a charge or an exact provider/model rate can price every billable usage category. Unknown models, mutable unidentified tiers, incomplete usage, and unpriced cache activity make the affected request and aggregate cost N/A.

417 Models & orchestration · Usage & cost visibility Status-bar usage summary

What it helps with. A compact VS Code status-bar item mirrors the conversation total and exposes the longer provider, model, request, and surface breakdown on hover or click. Users can inspect or reset accounting without expanding the sidebar card, while both controls operate on the same underlying session state.

418 Models & orchestration · Usage & cost visibility Editable pricing rate table with fail-closed N/A handling

What it helps with. The bundled exact-model registry can represent provider-specific input, output, cache, request-tier, long-context, and scheduled rate changes and can be updated independently. CoderFriend never substitutes a related family, rolling latest alias, default provider, or invented cache discount when the exact price cannot be established.

419 Models & orchestration · Provider accounts & spending budgets Provider account and balance views

What it helps with. Account and Usage opens one row per configured provider with locally measured spend for the active period and direct links to authoritative usage and billing consoles. A fetched balance appears only where the provider publishes a supported endpoint; otherwise the console link is presented as the real source.

420 Models & orchestration · Provider accounts & spending budgets Fetched balance support for DeepSeek and OpenRouter

What it helps with. DeepSeek can report an account balance through its supported endpoint. OpenRouter reports the remaining cap of the current API key; an uncapped key has no numeric remainder. These fetched values remain separate from extension-recorded spend and the provider’s full account invoice.

421 Models & orchestration · Provider accounts & spending budgets Local spending-budget controls

What it helps with. Set an advisory USD ceiling for the current session, day, or month of extension-recorded provider spend. The usage card warns at 80% and at the ceiling; separate root-request and delegation budgets enforce execution limits. Unknown charges remain visible as incomplete accounting, and local inference is excluded from the spend ledger.

422 Models & orchestration · Provider accounts & spending budgets Budget context beside provider usage

What it helps with. The account surface shows recorded spend in the context of the configured period and ceiling, helping users distinguish conversation cost, extension-tracked provider spend, fetched account balance, and the provider’s authoritative invoice. Those numbers are labeled separately because they answer different questions.

423 Models & orchestration · Managed Git worktrees Create and manage Git worktrees

What it helps with. Create a managed Git worktree from a selected repository and branch so isolated Agent work has its own filesystem and index. CoderFriend records the session, path, branch, status, and cleanup state, making concurrent work discoverable instead of leaving anonymous folders beside the main checkout.

424 Models & orchestration · Managed Git worktrees Run isolated implementation tasks

What it helps with. A background Agent can implement a focused assignment inside the managed worktree while the foreground conversation and primary checkout remain available. The run uses its own bounded provider snapshot, policy, iterations, verification, review rounds, and cancellation state rather than sharing mutable foreground execution.

425 Models & orchestration · Managed Git worktrees Inspect worktree diffs before integration

What it helps with. Completed sessions expose their changed files, Git diff, report, verification outcome, and remaining review findings before any merge or cherry-pick decision. CoderFriend does not silently integrate isolated changes into the main branch merely because the background Agent reached a completed state.

426 Models & orchestration · Managed Git worktrees Keep the primary workspace available

What it helps with. Because implementation happens in another Git worktree, developers can continue reading, editing, testing, or discussing the main checkout without switching branches underneath active editor tabs. File-lock and run identity still make conflicting targets visible when foreground and background work could overlap.

427 Models & orchestration · Background Agent runs Launch Agent work in the background

What it helps with. Run Agent in Background creates a durable run for a concrete task and executes it outside the foreground chat turn in a managed worktree. Configured concurrency limits prevent every queued idea from starting at once, while the user remains free to continue another conversation.

428 Models & orchestration · Background Agent runs Review progress and completion reports

What it helps with. The Background Agent Runs view shows queued, running, completed, failed, cancelled, and interrupted state together with bounded progress and a final report. Users can inspect what the run understood, changed, checked, and could not finish without reopening the original launch prompt from memory.

429 Models & orchestration · Background Agent runs Inspect resulting diffs

What it helps with. Every background implementation retains an inspectable worktree diff and changed-file set connected to its report and review output. This lets maintainers verify the actual patch, not merely trust a completion sentence, before choosing how or whether to integrate the branch.

430 Models & orchestration · Background Agent runs Cancel a background run

What it helps with. A queued or running background Agent can be cancelled from its management surface, threading cancellation into provider calls, tools, commands, review rounds, and cleanup. The run records the cancellation rather than disappearing, preserving enough evidence to inspect partial work and remove its worktree deliberately.

431 Models & orchestration · Bounded specialist subagents Researcher, Architect, Reviewer, and Tester roles

What it helps with. The coordinating Agent can spawn bounded specialists with explicit Researcher, Architect, Reviewer, or Tester roles when a task benefits from parallel expertise. Each role receives a concrete assignment and relevant shared context rather than a vague instruction to solve the whole request independently.

432 Models & orchestration · Bounded specialist subagents Read-only specialist execution

What it helps with. Subagents investigate with bounded file, search, semantic, documentation, and approved information tools but do not mutate the workspace or run unrestricted implementation work. Sensitive paths remain blocked because delegated workers have no interactive secret-approval channel, keeping authority with the foreground coordinator.

433 Models & orchestration · Bounded specialist subagents Explicit task and resource bounds

What it helps with. Every child has configurable iteration, token, exact-cost, and wall-clock limits plus a parent-wide concurrency and resource pool. The spawn request identifies the assignment and expected output, so a specialist cannot silently turn one narrow question into an unlimited second Agent project.

434 Models & orchestration · Bounded specialist subagents Results returned to the coordinating Agent

What it helps with. A completed child returns bounded findings, evidence, and status to the parent, which remains responsible for synthesis and any workspace mutation. list_subagents and get_subagent_result also let the coordinator inspect asynchronous progress without duplicating the specialist’s paid investigation.

435 Models & orchestration · Shared plans & delegated review Shared task plans and progress state

What it helps with. set_task_plan creates a dependency-aware task graph with explicit pending, in-progress, completed, and blocked state that the parent and supported collaborators can inspect. Updates remain tied to named tasks, making parallel progress and unfinished dependencies visible rather than inferred from scattered chat messages.

436 Models & orchestration · Shared plans & delegated review Artifacts that survive across delegated steps

What it helps with. write_artifact, read_artifact, and list_artifacts provide a request-scoped channel for bounded research notes, decisions, and task results that are not workspace files. Parent and child Agents can exchange evidence without creating temporary repository documents or confusing an artifact name with a filesystem path.

437 Models & orchestration · Shared plans & delegated review Automatic specialist dispatch where appropriate

What it helps with. dispatch_ready_tasks finds graph nodes whose dependencies are complete and launches suitable specialist assignments within the configured concurrency and budget. It writes child findings back into task-result artifacts and task state, allowing the coordinator to continue when parallel work becomes ready instead of polling manually.

438 Models & orchestration · Shared plans & delegated review Reviewer-to-repair handoff

What it helps with. A reviewer can produce structured findings that a foreground Agent or isolated background worktree receives as a concrete repair assignment. Follow-up review can confirm the fix within bounded rounds, preserving evidence and avoiding an unstructured cycle where the same model repeatedly critiques its own prose.

439 Models & orchestration · Provider-attributed commit messages Generate a commit message from repository changes

What it helps with. Generate Commit Message reads the intended Git diff and writes a concise summary into the Source Control input box rather than committing automatically. Users can inspect and edit the message with the exact change set still visible, keeping the final commit operation under normal Git control.

440 Models & orchestration · Provider-attributed commit messages Prefix output with the active provider and model

What it helps with. By default, generated and Agent-created commit messages begin with the provider and exact model captured for the active run, such as OpenAI gpt-5.6-sol:. Attribution is resolved immediately before execution so it cannot drift to a later setting or claim a model that did not produce the work.

441 Models & orchestration · Provider-attributed commit messages Respect configured file exclusions

What it helps with. commitMessagePrefixExcludedFolders can omit model attribution for selected absolute paths, workspace-relative folders, folder names, and descendant repositories. This supports projects whose contribution policy forbids prefixes without disabling transparent attribution everywhere else.

442 Models & orchestration · Provider-attributed commit messages Keep the final commit under your control

What it helps with. Message generation fills the SCM input and normal Agent Git commands remain subject to command policy, risk classification, sandbox boundaries, and repository instructions. CoderFriend does not treat a suggested message as authorization to commit, rewrite history, or push changes to a remote.

443 Models & orchestration · Live provider model catalogs Discover current models from supported provider catalog APIs

What it helps with. When a provider exposes a model-list API, CoderFriend fetches and normalizes the current catalog for that source instead of relying only on a frozen dropdown. Enablement settings can hide routes, while favorite, alias, and mode selections layer onto the live exact identifiers returned.

444 Models & orchestration · Live provider model catalogs Use authenticated Codex app-server model listings for ChatGPT routes

What it helps with. Codex model choices come from account/read followed by the authenticated app-server model/list response associated with the user’s ChatGPT session. Cached or configured models from OpenAI API and other providers are never mixed into that picker, preserving the subscription route’s actual availability.

445 Models & orchestration · Live provider model catalogs Discover models from local and cloud Ollama endpoints

What it helps with. CoderFriend queries the selected local or cloud Ollama endpoint for the models it currently serves and keeps each catalog attached to its route. A local model can appear without an API key, while cloud discovery uses only the Ollama Cloud credential and configured compatible endpoint.

446 Models & orchestration · Live provider model catalogs Cache a provider catalog without mixing it into another provider

What it helps with. Provider catalogs and selections remain associated with their source so models from another API, local server, or subscription account cannot enter the wrong picker. Codex availability is checked against its authenticated catalog rather than treating an old cached list as permission to start a request.

447 Models & orchestration · Live provider model catalogs Retain a usable configured fallback when a live catalog is unavailable

What it helps with. Where a provider supports a configured fallback, a failed catalog refresh can keep that provider’s exact selection available for recovery. Codex is stricter: authenticated model listings are authoritative, failed refreshes clear stale choices, and every request must use a currently listed model. LM Studio has no invented default model.

448 Models & orchestration · Provider-specific model memory Remember separate Chat, Plan, Agent, and completion models per provider

What it helps with. Each provider stores four distinct model choices for answer-oriented chat, planning, tool-using Agent work, and inline completion. Returning to a provider restores its prior selections, letting a fast completion model and stronger planning model coexist without repeated picker cleanup.

449 Models & orchestration · Provider-specific model memory Remember reasoning effort separately for each provider

What it helps with. Reasoning selection is stored with the provider because supported values and semantics differ across model APIs. Switching sources restores the relevant choice, and the resolved client omits reasoning metadata when the active route does not advertise or implement it.

450 Models & orchestration · Provider-specific model memory Remember processing speed separately for each provider

What it helps with. A supported service-tier or processing-speed choice belongs to the provider that offers it rather than a global fast-mode flag. CoderFriend restores that route’s setting and avoids sending a tier copied from another API whose names, costs, or availability differ.

451 Models & orchestration · Provider-specific model memory Omit unsupported controls from provider requests

What it helps with. Provider configuration resolves model capabilities before serializing speed, reasoning, image, caching, or other optional fields. A visible value saved for one route is not blindly injected into every request, reducing hard API failures and misleading claims that a provider honored an unsupported control.

452 Models & orchestration · Provider-specific model memory Switch selectors without sending a message

What it helps with. Changing provider, model, mode, speed, reasoning, context, detail, profile, or policy updates the prepared next-request state only. No token usage, remote call, or conversation turn is created until the user submits a message, making exploration and comparison safe.

453 Models & orchestration · Provider authentication recovery Reuse an existing Codex CLI or OpenAI extension ChatGPT session

What it helps with. CoderFriend discovers the Codex executable on PATH or inside the supported OpenAI VS Code extension and asks its app server for the current account. A valid shared ChatGPT login is reused directly, avoiding a second credential store or redundant browser authorization flow.

454 Models & orchestration · Provider authentication recovery Start browser authentication automatically when Codex needs it

What it helps with. If account lookup, catalog discovery, or a later Codex request reveals no valid ChatGPT session, CoderFriend starts the official login flow and opens its HTTPS authorization URL. The UI waits for completion and reports failure clearly if the link cannot be opened or authentication is cancelled.

455 Models & orchestration · Provider authentication recovery Retry one interrupted Codex catalog or request after sign-in

What it helps with. After successful authentication, the exact catalog lookup or model request that discovered expiration is retried once using the refreshed account. A second authentication failure stops rather than looping browser flows, and the user can invoke Connect Codex manually when a deliberate retry is needed.

456 Models & orchestration · Provider authentication recovery Discover Claude Code from PATH, a home install, or its VS Code extension

What it helps with. Subscription transport searches the extension-host PATH, common Claude Code home installation, and the installed Anthropic VS Code extension before requiring a custom binary setting. The error names the missing executable and setup path on the first failure so users can repair the real environment.

457 Models & orchestration · Provider authentication recovery Surface empty-account and billing refusals with provider-specific actions

What it helps with. When a provider refuses a request because an account has no funds or a billing condition needs attention, CoderFriend preserves the provider’s useful sentence and links to the relevant console action. Billing refusals are not retried as transient network failures, avoiding repeated paid attempts with no chance of success.

458 Models & orchestration · Durable usage accounting Track prompt, visible output, thinking, tool-result, and cache tokens

What it helps with. Usage normalization keeps the token categories each provider actually reports: prompt input, visible output, separately billed thinking, tool-result input, cache reads, and cache writes. Aggregates retain those distinctions so a total does not hide whether cost came from reasoning, repeated context, tool data, or the answer itself.

459 Models & orchestration · Durable usage accounting Attribute usage to sidebar, native chat, inline, evaluation, reviewer, retry, and delegated surfaces

What it helps with. Every provider call includes a call-kind and request context covering sidebar and native chat, inline chat and completion, generated actions, evaluations, background Agents, planners, summaries, reviewers, retries, and subagents. The By Surface view exposes those categories under one consistent accounting rule.

460 Models & orchestration · Durable usage accounting Show each root request separately from aggregate surface totals

What it helps with. Recent Requests keeps every foreground or continued root Agent round as its own row with calls, iterations, duration, usage, model, and cost status. By Surface then aggregates comparable work, letting users inspect one surprising request without losing the broader conversation picture.

461 Models & orchestration · Durable usage accounting Restore saved conversation totals after reload or reopening

What it helps with. Normalized usage state is saved with the conversation and loaded when that thread becomes active again, including after an extension-host reload. Reopening history therefore restores the work’s measured totals, while starting, clearing, or deleting a conversation produces the appropriate fresh state.

462 Models & orchestration · Durable usage accounting Preserve token counts when exact provider cost is unavailable

What it helps with. A ChatGPT or Claude subscription response, unknown exact model, incomplete usage payload, or unreported mutable tier may prevent reliable USD pricing without invalidating reported tokens. CoderFriend continues to show those categories and explains why only the monetary total is unavailable.

463 Models & orchestration · Durable usage accounting Show N/A instead of inventing an uncertain charge

What it helps with. If any contributing paid request cannot be priced exactly, its request, surface, and complete conversation cost become N/A with a reason instead of treating uncertainty as zero. The calculator never borrows another provider’s rate, guesses a family default, or prices a rolling alias as a fixed release.

464 Models & orchestration · Live pricing & account budgets Refresh supported model prices on demand

What it helps with. Update Model Prices and /priceupdate fetch or rebuild the supported exact-model rate registry when current published pricing is needed. The update path validates the resulting data and leaves existing rates intact on failure rather than replacing the calculator with a partial or malformed table.

465 Models & orchestration · Live pricing & account budgets Schedule bounded model-price updates

What it helps with. Enable automatic price updates and choose the interval used to refresh supported rate data in the background. Scheduling is bounded and optional, and it does not make a model priceable unless its exact provider identity and required usage categories are present in the registry.

466 Models & orchestration · Live pricing & account budgets Use provider-reported request charges when available

What it helps with. A provider’s explicit per-request cost takes precedence over local estimation because it can reflect the actual tier and billing rules served. CoderFriend retains that charge with its request and aggregates it normally, while still showing the underlying reported token categories for audit.

467 Models & orchestration · Live pricing & account budgets Show fetched balances where a provider exposes them

What it helps with. The Account view fetches DeepSeek account balances and OpenRouter API-key cap remainders through their supported endpoints. A key cap is labeled separately from a provider account balance, and an uncapped or unsupported account links to its authoritative console instead of displaying a fabricated number.

468 Models & orchestration · Live pricing & account budgets Compare locally recorded spend with a configured budget period

What it helps with. Compare extension-recorded charges across session, day, or month windows without restarting accounting when you change the displayed period. Budget warnings describe the observed spend, not an account balance or billing stop; separate request limits control autonomous execution.

469 Models & orchestration · Dependency-aware task engine Create a shared plan with set_task_plan

What it helps with. set_task_plan records a bounded list of concrete tasks, dependency relationships, and initial state for the current coordinated request. The plan is visible as operational state rather than hidden model reasoning, and it can be updated as evidence changes without rewriting completed task results.

470 Models & orchestration · Dependency-aware task engine Inspect all tasks and dependency state with list_tasks

What it helps with. list_tasks returns every shared task with its status, dependencies, assignment, and bounded result references. The coordinator can see which work is pending, active, complete, or blocked before spawning more help, reducing duplicated investigation and impossible out-of-order execution.

471 Models & orchestration · Dependency-aware task engine Find unblocked work with get_ready_tasks

What it helps with. get_ready_tasks filters the shared graph to tasks whose dependencies are satisfied and that are not already running or complete. This gives the Agent a deterministic set of safe next assignments rather than relying on a language model to remember the entire dependency graph from prose.

472 Models & orchestration · Dependency-aware task engine Update one task explicitly with task_status

What it helps with. task_status changes a named task to the appropriate lifecycle state and can attach a bounded outcome or blocker. Explicit updates let the UI and dispatch logic distinguish genuine completion from an Agent merely mentioning that a task appears finished in its conversational answer.

473 Models & orchestration · Dependency-aware task engine Dispatch ready specialist work with dispatch_ready_tasks

What it helps with. dispatch_ready_tasks launches eligible tasks as bounded subagents up to the configured concurrency, role, and parent resource limits. Completed findings are connected back to their task and artifact automatically, while launch failures and cancellations remain visible to the coordinating Agent.

474 Models & orchestration · Dependency-aware task engine Exchange bounded findings through named task artifacts

What it helps with. Named artifacts carry plans, research, test observations, review findings, and task-result text between collaborators without writing them into the codebase. Size, scope, and tool separation keep the channel inspectable, and an Agent must use artifact tools rather than pretending the names are ordinary file paths.

475 Models & orchestration · Live subagent console Show each child role, assignment, status, and elapsed time

What it helps with. The Working card presents a collapsible row for every delegated child with its specialist role, concrete assignment, queued or running state, and elapsed active time. Users can see why each subagent exists and whether parallelism is making progress before the parent produces its final synthesis.

476 Models & orchestration · Live subagent console Show child iteration and recent safe tool summaries

What it helps with. Each expanded child row reports its bounded iteration count and recent sanitized operation summaries such as files read, searches run, or documentation inspected. Raw private reasoning, sensitive paths, and oversized protocol payloads are excluded, preserving useful operational transparency without turning activity into a secret leak.

477 Models & orchestration · Live subagent console Preview bounded findings without exposing private reasoning

What it helps with. A completed specialist can show a short preview of its final evidence and recommendation directly in the activity panel. The preview is redacted and size-limited and represents the child’s reported result, not hidden chain-of-thought or an unlimited transcript of its internal model exchange.

478 Models & orchestration · Live subagent console Explain child failure and cancellation states

What it helps with. Failed, timed-out, budget-stopped, parent-cancelled, and otherwise interrupted children retain a concise reason instead of collapsing into a generic missing result. The parent can decide whether to proceed with other evidence, retry deliberately, or report the unresolved assignment honestly.

479 Models & orchestration · Live subagent console Include delegated usage in the parent conversation HUD

What it helps with. Provider calls made by subagents inherit the root accounting context and appear in recent-request and per-surface usage alongside the parent. Their token categories and exact measurable cost count toward the conversation and shared budgets rather than being hidden as free parallel work.

480 Models & orchestration · Hierarchical delegation budgets Set per-child token, exact-cost, iteration, and wall-clock limits

What it helps with. Each spawned specialist receives independent ceilings for non-cache token usage, exact measurable USD cost, model iterations, and elapsed execution time. Reaching one stops that child and records the reason without automatically erasing useful findings already returned by other specialists.

481 Models & orchestration · Hierarchical delegation budgets Set parent-wide token, exact-cost, concurrency, and time limits

What it helps with. The coordinating request also owns a shared pool across every queued and running child, plus maximum child count and concurrency. These limits prevent many individually acceptable specialists from collectively exceeding the user’s intended resource envelope.

482 Models & orchestration · Hierarchical delegation budgets Charge measured provider usage before another delegated step

What it helps with. After every child model response, reported tokens and exact provider or exact-rate cost are added to both child and shared usage before the loop can call another model or tool. Enforcement therefore acts on completed paid work immediately instead of checking only after the specialist finishes its whole assignment.

483 Models & orchestration · Hierarchical delegation budgets Cancel queued and running children when the shared ceiling is reached

What it helps with. When the parent-wide token, exact-cost, or time budget is exhausted, CoderFriend prevents later spawns and cancels every queued or active child in that coordination scope. The activity panel records the shared-budget stop so simultaneous cancellations have one understandable cause.

484 Models & orchestration · Hierarchical delegation budgets Continue token and time safeguards when exact cost is unavailable

What it helps with. A provider or subscription transport that cannot expose exact USD cost shows N/A and makes cost enforcement unavailable rather than treating the call as free. Token, iteration, child-count, concurrency, and wall-clock limits continue to bound delegated work using the measurements that remain trustworthy.

485 Models & orchestration · Desktop Agent Dashboard Watch four runs in one view

What it helps with. Keep up to four independent editor sessions visible as separate panes on one desktop screen.

486 Models & orchestration · Desktop Agent Dashboard Search and assign a session to a pane

What it helps with. Find an armed editor window and place it deliberately on the board.

487 Models & orchestration · Desktop Agent Dashboard Use the board as a paired device

What it helps with. Pair the desktop board with the same verified-code and fingerprint flow used by a phone.

488 Models & orchestration · Desktop Agent Dashboard Keep a window focused on one viewer

What it helps with. Prevent simultaneous viewing conflicts by reserving each watched window for a single remote device.

489 Models & orchestration · Readable live Agent transcript Fold streaming assistant output into readable updates

What it helps with. Grow consecutive assistant text in place instead of flooding the transcript with token-sized rows.

490 Models & orchestration · Readable live Agent transcript Keep progress compact

What it helps with. Update one live status line rather than adding a new transcript entry for every progress change.

491 Models & orchestration · Readable live Agent transcript Respect your reading position

What it helps with. Pause automatic following when you scroll back through an active run.

492 Models & orchestration · Readable live Agent transcript Jump back to the live run when ready

What it helps with. Return to the newest Agent activity with a dedicated live-position action.

493 Models & orchestration · Readable live Agent transcript Restore a coherent session after reconnecting

What it helps with. Reconcile snapshots and completed runs without duplicating stale status entries.

494 Models & orchestration · Readable live Agent transcript Resume the encrypted remote transport

What it helps with. Reconnect the remote viewer and continue from the correct sealed frame sequence after a network interruption.

495 Models & orchestration · Phone-based Trusted Agent control Watch the agent transcript as it happens

What it helps with. Follow live progress away from the editor while the desktop remains the source of workspace context.

496 Models & orchestration · Phone-based Trusted Agent control Send steering messages to an active run

What it helps with. Redirect or clarify the current task from the paired phone without opening a separate conversation.

497 Models & orchestration · Phone-based Trusted Agent control Stop a run remotely when needed

What it helps with. End the active agent run from the phone when its direction or timing no longer fits.

498 Models & orchestration · Phone-based Trusted Agent control Discover armed editor windows

What it helps with. Search for available Remote Control sessions and choose the intended repository, computer, and VS Code window.

499 Models & orchestration · Phone-based Trusted Agent control Limit remote control to Trusted Agent

What it helps with. Keep the feature unavailable in modes that can pause for approvals the remote viewer cannot safely judge.

500 Models & orchestration · One phone, multiple desktops Control multiple desktops from one phone

What it helps with. Pair once for each CoderFriend installation, then use the phone’s desktop board to move among the computers and workspaces available to you.

501 Models & orchestration · One phone, multiple desktops See each VS Code window as its own session

What it helps with. Keep simultaneous projects distinguishable instead of collapsing every open editor on a computer into one ambiguous destination.

502 Models & orchestration · One phone, multiple desktops Watch a session from another VS Code window

What it helps with. Open the shared board on a second desktop window to follow an active remote conversation without taking over its editor.

503 Models & orchestration · One phone, multiple desktops Keep pairing changes synchronized

What it helps with. Phones paired or revoked in one window are reflected across the other participating windows, so the board stays current.

504 Models & orchestration · One phone, multiple desktops Open a focused desktop board

What it helps with. Use a dedicated board with recognizable window identity, built-in help, and a maximized view for monitoring several sessions.

505 Models & orchestration · Visible provider and model attribution See which model handled the request

What it helps with. Show the resolved model with the conversation response or run details rather than making you infer it from the answer.

506 Models & orchestration · Visible provider and model attribution Identify the provider route

What it helps with. Distinguish API, local, Codex, Claude subscription, and other configured transports when comparing results.

507 Models & orchestration · Visible provider and model attribution Confirm profile-selected models

What it helps with. Make the effective choice visible when a guardrail or runtime profile supplies provider and model settings.

508 Models & orchestration · Visible provider and model attribution Trace fallbacks without guesswork

What it helps with. Preserve the actual route used when availability or configuration causes execution to differ from the composer’s initial choice.

509 Models & orchestration · SSH uploads to live servers Upload one named local file deliberately

What it helps with. Use the dedicated SSH upload tool rather than hiding a transfer inside a generic shell command.

510 Models & orchestration · SSH uploads to live servers Validate both ends of the transfer

What it helps with. Apply workspace path policy to the local source and live-server safety rules to the remote destination.

511 Models & orchestration · SSH uploads to live servers Keep server identity visible

What it helps with. Tie the upload to the active live-server connection so the destination host is not inferred from an arbitrary command.

512 Models & orchestration · SSH uploads to live servers Respect the current approval mode

What it helps with. Route file transfer through the same resolved authority and confirmation controls as other live-server changes.

513 Models & orchestration · Live-server reconnect and resume Keep a disconnected server visible

What it helps with. Preserve the live-server row and its last known state when the connection ends instead of making the target disappear.

514 Models & orchestration · Live-server reconnect and resume Offer reconnection where work can continue

What it helps with. Surface a reconnect action in the composer and status banner when an interrupted task still has a usable server target.

515 Models & orchestration · Live-server reconnect and resume Refuse unsafe blind resumes

What it helps with. Do not resume remote work when no live-server connection exists to establish where later commands would run.

516 Models & orchestration · Live-server reconnect and resume Report the failed remote stage

What it helps with. Identify the SSH or remote execution step that interrupted the run so recovery starts from concrete evidence.

517 Models & orchestration · Web research with Claude subscription Research the web from Claude subscription runs

What it helps with. Claude Code WebSearch and WebFetch are available alongside its normal tool loop when web tools are enabled.

518 Models & orchestration · Web research with Claude subscription Use the same web-tools preference across providers

What it helps with. The existing web-tool setting governs Claude subscription access as well as other provider transports, keeping the control in one place.

519 Models & orchestration · Web research with Claude subscription Keep web access opt-in

What it helps with. Turning web tools off removes those Claude Code tools, so a local or restricted workflow stays restricted.

520 Models & orchestration · LM Studio local models Connect to a local LM Studio server

What it helps with. Start the LM Studio server and select LM Studio (Local). The default endpoint is http://localhost:1234/v1; configure the matching loopback port when your server uses another one. Plain HTTP on a non-loopback LAN address is not supported.

521 Models & orchestration · LM Studio local models Choose from the models your server provides

What it helps with. The picker reads the running server’s model list and filters embedding and reranking names from chat choices. No model is assumed to be installed: select one you have downloaded and made available in LM Studio.

522 Models & orchestration · LM Studio local models Use no key unless local authentication is enabled

What it helps with. LM Studio works without an API key by default. If its optional Require Authentication setting is enabled, supply the token through secure provider setup or LM_API_TOKEN; an unsecured local server needs neither.

523 Models & orchestration · LM Studio local models Use model-dependent Agent tools and completion

What it helps with. LM Studio can serve Chat, Plan, Agent, and completion requests. Tool calling and image understanding depend on the selected model; CoderFriend does not offer an LM Studio reasoning-effort control or native web-search capability that the server cannot honor.

524 Models & orchestration · LM Studio local models Track local tokens without charging a spending budget

What it helps with. Supported LM Studio versions report streamed usage, allowing token totals and context controls to work. Local inference is excluded from the spending ledger; monetary cost remains N/A rather than an invented provider charge.

525 Models & orchestration · Agent work beyond the editor window Continue compatible runs after closing VS Code

What it helps with. Enable detachedBackgroundRuns to launch supported background Agent tasks independently of the editor window. API-backed routes, Ollama Local, and LM Studio can use this workflow; Codex and Claude subscription sessions stay in the editor because their login belongs to the desktop session.

526 Models & orchestration · Agent work beyond the editor window Inspect recorded progress from another window

What it helps with. A detached run writes a bounded progress journal and final outcome that another CoderFriend window can inspect. The UI distinguishes completed, failed, cancelled, and interrupted work instead of silently replaying an abandoned task.

527 Models & orchestration · Agent work beyond the editor window Stop or steer a run from another window

What it helps with. Background run controls can address the current owner to request cancellation or send steering. Directions are applied at safe work boundaries, preserving the task’s isolated worktree and its resource limits.

528 Models & orchestration · Agent work beyond the editor window Review the worktree before integration

What it helps with. Detached execution belongs to the existing background-worktree workflow. Its result and diff remain reviewable before integration, so closing the foreground editor does not implicitly approve changes to the primary workspace.

529 Models & orchestration · GitHub issue-to-review workflow Start a task from a GitHub issue

What it helps with. Provide an issue number or GitHub issue URL to load its context and create or reuse a task branch. A signed-in GitHub CLI and an open workspace are required; an existing related pull request can be reused deliberately.

530 Models & orchestration · GitHub issue-to-review workflow Inspect the connected account and task status

What it helps with. GitHub connection and status commands show the authenticated account and scopes, repository, branch, available pull request, checks, and current authority summary. These views keep external work tied to a visible account and repository.

531 Models & orchestration · GitHub issue-to-review workflow Turn pull-request feedback into a repair request

What it helps with. Load review comments and failed checks from the current branch’s pull request into an Agent repair request. The prompt keeps push, commenting, and check reruns as separate external actions.

532 Models & orchestration · GitHub issue-to-review workflow Re-run failed checks with explicit confirmation

What it helps with. The failed-check command asks before starting GitHub workflow runs. It then reports the actual rerun result rather than treating a local repair as proof that remote checks passed.

533 Models & orchestration · GitHub issue-to-review workflow Push and open a draft pull request deliberately

What it helps with. On a non-default branch, the draft command checks for an existing pull request, then asks before pushing the branch and opening a draft against the repository default. The draft can be reviewed before later merge decisions.

From prompt to proof

Keep the whole coding loop in one place.

Start with the project—not an empty prompt. CoderFriend carries the context, control, and evidence from your first question through the final review.

Your providers. Your workspace. Your approval rules.
01

Context

Assemble the right project knowledge.

02

Reason

Choose the model and working mode.

03

Act

Make bounded, reviewable changes.

04

Verify

Test behavior and inspect the result.

One interface across
Ollama LocalOllama CloudLM StudioOpenAI APICodex (ChatGPT)ClaudeGeminiOpenRouterDeepSeekxAIGroqMistral