@phnx-labs/agents-cli

finance MCP Server

The missing toolchain for CLI coding agents. Run any agent on your subscription. Parallel teams, browser driving, Touch ID secrets, routines.

VerifiedInstall Ready
financefinance
2 views7 stars2 forksv1.20.5MIT

Why This Matters

Discovered via github-topic:mcp and last synced 3mo ago.

VerifiedInstall Ready
Source
github-topic:mcp
Stars
7
Last synced
3mo ago
Install
Instructions detected

Install

1. Install the package

npx @phnx-labs/agents-cli

2. Add to claude_desktop_config.json

{
  "mcpServers": {
    "-phnx-labs-agents-cli": {
      "command": "npx",
      "args": [
        "@phnx-labs/agents-cli"
      ]
    }
  }
}

Config file location: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) / %APPDATA%\Claude\claude_desktop_config.json (Windows)

22
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (22)

Preset

Model

Config

`~/.agents/`

Capability

Agent

kimi

Kimi K2.5

Agent

Versions

Hooks

Gemini

minimax

MiniMax M2.5

MCP

Permissions

Repo

Role

You

**Version pinning:** `agents.yaml` at project root pins which agent version to use (like `.nvmrc` for Node). **Resource resolution:** When syncing resources (commands, skills, rules, hooks, MCP, permissions), the order is **project > user > system**. A `.agents/` directory at project root wins, then `~/.agents/`, then `~/.agents-system/`. Same-named resources higher in the chain override lower ones; everything else unions in. See [docs/00-concepts.md](docs/00-concepts.md) for the full mental model: DotAgents repos, resource kinds, and how resolution works end-to-end. Other useful commands: `agents doctor` checks CLI availability and resource sync drift, `agents usage` shows available quota/rate-limit data for installed agents, `agents import` adopts an existing unmanaged install, `agents trash` lists and restores soft-deleted version directories, and `agents subagents` installs reusable subagent definitions for parent-agent workflows. --- ## Private skills Keep work or personal skills in a separate repo — public ones in `~/.agents/`, private ones in an extra repo that merges in at sync time. ```bash # Add a private repo for work-only skills agents repo add gh:yourname/.agents-work # Add with a custom alias agents repo add [email protected]:acme/team-skills.git --as acme agents repo list # Primary + every registered extra agents repo pull # Pull updates for all enabled extras agents repo disable acme # Stop merging without deleting agents repo remove acme # Unregister and delete the clone ``` Extras clone into `~/.agents-system/.repos/<alias>/` and ship the same layout as the primary (`skills/`, `commands/`, `hooks/`, `rules/`). Their contents merge into agent version homes after the primary's — so `~/.agents/` always wins on name collisions. `agents skills list` shows which repo each skill came from. --- ## Security & Privacy **The CLI binary has no built-in telemetry or phone-home path.** Routine commands run locally; explicit features such as cloud dispatch and iCloud Keychain sync send only the data needed for the action you invoke. Here's exactly what `agents-cli` stores locally and why. ### Event log Every agent run, version install, browser launch, and secrets access is logged to `~/.agents/.cache/logs/events-YYYY-MM-DD.jsonl`. This gives you a complete record of what agents did on your machine. ```bash # What gets logged (example event): { "ts": "2026-05-09T10:23:45Z", "event": "agent.run.end", "agent": "claude", "version": "2.1.121", "prompt": "Fix the auth bug in...", # truncated to 200 chars "durationMs": 45230, "exitCode": 0, "hostname": "your-mac", "platform": "darwin" } ``` **What's logged:** Operation type, agent, version, timing, prompt length + SHA-256 hash (raw text never stored), exit codes, errors, and secret bundle/key names with caller context. Argv entries that look like tokens or secret paths are redacted. **What's NOT logged:** Raw prompts, outputs, file contents, or secret values. **Permissions:** Logs directory is `0700` (owner-only), files are `0600`. Only you can read them. **Retention:** 7 days by default, then auto-pruned. **Opt out:** Set `AGENTS_DISABLE_EVENT_LOG=1` in your shell to disable completely. ### Session search Conversations with Claude, Codex, Gemini, and other agents scatter across their native storage. Session search indexes them locally so you can find any conversation: ```bash agents sessions "auth middleware" # Full-text search across all agents agents sessions --agent claude --since 7d ``` The index lives at `~/.agents/.history/sessions/sessions.db` (SQLite + FTS5). Nothing leaves your machine. See [Sessions](#sessions-across-agents) for full usage. ### Secrets API keys and credentials are stored in macOS Keychain, never in plaintext files. Bundle definitions also live in Keychain. ```bash agents secrets create my-keys agents secrets add my-keys API_KEY # Prompts for value, stores in Keychain ``` By default, secrets sync via iCloud Keychain to your other Macs. With `--no-icloud-sync`, they stay device-local. See [Secrets](#secrets) for full usage. ### Summary

Location

Who can read

qwen

Qwen3 Coder Next

Rules

Workflows

deepseek

DeepSeek Chat V3

yes

yes

Routines

Teams

glm

GLM 5

Commands

Plugins

Codex

< 0.117.0 (0.117+ uses command-as-skill)

Secrets

macOS Keychain

no

**Legend:** `yes` / `no` = synced or skipped at install time. `skills ($name)` = no file-based slash-command dir; behavior ships as a generated skill invoked with `$command`. `gateway` = OpenClaw resolves slash commands at runtime, not from synced files. Version suffixes are enforced at sync time — out-of-range versions are skipped with a clear message. **Host CLIs** (`agents cli`) are separate: YAML manifests under `~/.agents/cli/` install binaries onto your PATH (`gh`, `higgsfield`, etc.). They are not copied into per-agent version homes. ### agents-cli features (not agent-native resources)

Plugins

Codex