Citadel 🤖 Agent Open source
Routing, repo-local memory, guarded workflows and handoffs around Claude Code and Codex
- GitHub stars
- 922
- Stars this week
- +-1
- Forks
- 82
- Licence
- MIT
- Last push
- 2026-10-01
- Maintainer
- SethGammon
claude plugin marketplace add SethGammon/[email protected] --scope localThird-party subagents & agents run with your permissions. Read the source before installing, and prefer pinned versions.
Works with
About Citadel
What it does
Citadel is an operating layer that sits around Claude Code or OpenAI Codex inside a single git repository. Instead of choosing between dozens of commands, you describe the outcome through one /do entry point, and Citadel routes the request to a matching workflow, keeps repository-local state between sessions, and records what happened so a fresh session knows the next step. It is aimed at work that spans more than one prompt: multi-step changes, parallel branches, and tasks that get interrupted.
What is inside
The release ships a catalogue of skills and hook scripts wired to the agent's lifecycle events. Work moves through five named states: request, run, evidence, needs you, and resume. Checks report passed, failed, blocked or unknown, and missing evidence is never promoted to success. Parallel work runs in isolated worktrees with ownership rules and shared discoveries. Operational state lives in a .planning/ folder and a few .claude/ and .citadel/ paths, separate from application code. A /unharness command produces a reviewable removal plan.
Works with
Claude Code and OpenAI Codex, both through their native plugin marketplaces. Node.js 22 or newer and a git repository are required.
How to install
For Claude Code, run these from the repository you want Citadel to manage:
claude plugin marketplace add SethGammon/[email protected] --scope local
claude plugin install citadel@citadel-local --scope local
For Codex:
codex plugin marketplace add SethGammon/Citadel --ref v1.4.3
codex plugin add citadel@citadel-local
Maintenance and safety
The project is MIT licensed, actively developed, and pins installs to tagged releases with checksum-verified archives for offline setups. The README is unusually candid: it states that its own experiments do not support a cost-savings claim and that it is not a sandbox, so it runs with the agent's normal permissions. Telemetry and state stay local by default. Read the security and privacy notes before using it on a sensitive repository.
Who should use it
Developers who run long or multi-session tasks with Claude Code or Codex and want durable handoffs, guarded workflows and a clear audit trail. For quick one-off edits it adds more structure than you need.
Pros
- Single /do entry point with durable repo-local state and resume actions
- Pinned, checksum-verified releases and a reviewable removal path
- Unusually candid about what its benchmarks do and do not prove
Cons
- Heavy process for short one-off edits
- Not a sandbox; runs with the agent's full permissions
Similar subagents & agents
All agent workflows & frameworks →Spec Kit 🤖 AgentFree
GitHub's toolkit for spec-driven development with AI coding agents
Task Master 🤖 AgentFree
AI task management that turns a PRD into tasks your coding agent works through
Fast Agent 🤖 AgentOpen source
Python framework for building, orchestrating and evaluating MCP-native AI agents
OpenSpec 🤖 AgentFree
Lightweight spec-driven development: agree on changes before the agent codes
CC Safety Net 🤖 AgentOpen source
Pre-execution guard that blocks destructive commands and secret access for coding agents
BMAD Method 🤖 AgentFree
Agile AI-driven development with analyst, PM, architect, developer and UX agents