Agent Mode and approvals
Agent Mode lets the model read and search files, create documents, run code, and work through several steps. Each action appears in the chat, with approval cards for actions that need your review.
Turn on Agent Mode
Click the robot button for the current chat. To enable it for new chats, check Settings → Behavior → Start new chats with agent mode enabled.
Agent Mode works best with models trained for tool calling. A small model can chat well and still struggle with tools. If a provider model is marked Allow agent tools off, it stays chat-only even with Agent Mode enabled.
What the agent can do
List folders, read text or selected line ranges, grep with surrounding lines, and open supported files in Windows.
Create files and folders, edit unique text matches, replace whole files, and delete individual files or empty folders.
Inspect CSV, XLSX, PDF, DOCX and ZIP files, extract text, fill compatible PDF forms, and create reports or workbooks.
Run finite PowerShell commands, keep a Python session across steps, create reusable scripts, and install one named Python package at a time.
Read or append personal and Project notes, and create reminders that appear while LlamaBoss is running.
Fetch a public web page or inspect images on disk with a vision-capable model, including images extracted from a ZIP.
Ask for tools in plain language. The old typed tool shortcuts, such as read, grep and Python commands, were removed; Commands & shortcuts lists the commands that remain.
Independent tools can be requested together and are executed one after another. Calls that depend on earlier output, file changes or code execution are handled one step at a time.
Where the agent works
Each conversation gets a workspace under its chat folder:
%USERPROFILE%\LlamaBoss\Chats\<date>_<title>_<id>\WorkspaceA new or untitled folder may use only the date and id. Folder names stay stable after creation, even if you rename the chat. Older installations may still have chat folders under LlamaBoss\Workflows; LlamaBoss migrates eligible folders on startup and keeps using ones it could not move.
Native file-changing tools are limited to the working directory, an attached Project, Skills, and folders you explicitly grant. Read-only tools can inspect other local paths that your Windows account can read. To change or display this chat's working directory, type:
/cd D:\MyProject
/cdThe model cannot change the chat's working directory itself. A cd within a PowerShell command lasts only for that command.
A native write outside the allowed folders shows Folder Access Required. Grant Folder for Chat allows that location for this app session, including when you reopen the chat. Grants are not saved across an app restart. Granting a folder does not also approve a destructive action.
These folder limits apply to the native file tools. PowerShell and Python code run with your Windows account's file and network permissions, so review what the code does before approving it. Existing scripts in the supported script folders can run without a separate approval card.
What asks first
Read-only tools and ordinary file writes inside allowed folders run without an approval card. With normal approval settings, these actions ask first:
- Deleting a file or empty folder.
- PowerShell commands outside the automatic read-only profile.
- Running arbitrary code in the persistent Python session.
- Creating a Python script or creating/replacing a PowerShell script.
- Installing a Python package.
| Choice | What happens |
|---|---|
| Allow Once | Approves this action. |
| Allow Always | Trusts later tool actions in this conversation for the current app session. Separate folder grants and package-install approvals still apply. |
| Deny | Skips the action and tells the model. A denied call also skips the remaining calls in that batch. |
You can type approve once, approve or deny while a card is showing. Each package install still asks separately and shows the exact package name after Allow Always.
Creating a script and running it are separate operations. python_run_script runs existing scripts from the conversation's Scripts folder, the attached Project's Workflows folder, or Skills. Imported Skill scripts should be reviewed before you ask the agent to use them.
Python session
Each chat can keep a Python process running so variables and loaded data survive across tool calls. Ask the agent to use Python for calculations or incremental data exploration. Direct /py and /py reset shortcuts are no longer handled by the app.
A session closes after 30 minutes idle and has a 2 GiB process memory limit. Cancelling it, a timeout, or a crash ends the session and loses its variables; the next call starts fresh and reports the restart.
Local chat does not require Python. Document helpers and Python tools do. Ask the agent to check Python health if a helper fails; missing packages can be installed after your approval.
Waiting and reminders
PowerShell runs in the foreground, with a five-minute default timeout. For a finite build or installation, the agent can request 15–1800 seconds for one call. Local child processes left running after the command exits are terminated; ask for foreground commands that wait for completion.
The Wait tool pauses 15–600 seconds between status checks for work managed elsewhere, such as a remote job or a process you started manually. The default total wait budget is 30 minutes per reply. Waiting does not keep a detached PowerShell job alive.
Ask for a reminder in plain language, or use the reminder commands. Reminders appear while LlamaBoss is running; overdue reminders appear after the next launch. You can snooze for 10 minutes or dismiss them.
Limits and loop guards
The default limit is 12 tool steps per reply. Check or change the saved limit:
/agent_steps
/agent_steps 20The range is 4–60. Waiting does not count toward it. LlamaBoss checks for repeated calls with no progress, malformed calls, and repetitive generated output. Tool-call arguments have a 4 MiB per-call limit.
Older large tool results are shortened when context fills. Their full contents can be stored in the workspace's Vars folder for later search or selected reads; the model should verify completed work rather than repeat a file-changing action to recover old output.
Stopping
Click Stop to cancel generation, a running tool sequence, or a pending approval. Partial answer text and completed changes are kept. Stop does not undo a file change that already completed. If a persistent Python session was cancelled, its variables are lost.