Ship/code → a reviewed pull request
Type a task in any channel. A thread opens, an isolated container does the work, and a PR lands with Merge / Iterate buttons. Your default branch is never touched.
ANYWARECODE — SHIPPING MANIFEST
One AI engineer, shared by the whole server. Type /code in any channel — it works alone in a sealed container and comes back with a pull request.
* every PR carries a named human sponsor and a provenance receipt.
BYO LLM key · isolated containers · never pushes to main
ANYWARECODE — PROVENANCE RECEIPT
PR #128 OPENED — awaiting human merge
¶ THE PREMISE
Four entries carry the story. The annexes carry the rest.
Type a task in any channel. A thread opens, an isolated container does the work, and a PR lands with Merge / Iterate buttons. Your default branch is never touched.
Questions grounded in the connected repo, answered in the channel. Unlimited on every plan, because it never writes a thing.
Any reply in the thread forwards straight into the live run as a new turn. @mention the bot anywhere and it routes itself — a reply, an /ask, a /code run, or a proposal with Run buttons.
Repro Gate verifies inbound bug reports in the sandbox before a human reads them. Quarantine strips hidden instructions from issues. Every PR carries its provenance receipt.
ANNEX — ALSO IN THE LEDGER
BYO LLM — Anthropic key, Claude Pro/Max token, or compatible endpoint — encrypted per server
Squad Mode — N parallel attempts in separate sandboxes, the server votes
MCP extensions — your Sentry, database, or tracker — role-gated per connection
Provenance receipts — sponsor, approver, steerers, evidence — on every PR
Hardened runtime — non-root containers, cap-drop ALL, allowlisted egress
Server Memory — conventions accumulate; /memory commit flows them into AGENTS.md
04 ENTRIES · 06 ANNEXES — NOTHING OFF THE BOOKS
¶ THE WALKTHROUGH
From prompt to pull request in four hand-offs — each one visible in the thread, none of them touching your default branch.
01
Invite the bot with one click. It registers its slash commands automatically on boot.
Add to Discord →
02
Link a GitHub repo and bring your own LLM credential. Both are scoped per server.
/connect github /connect llm
03
Describe the change in any channel. A thread opens and the agent streams its progress live.
/code add dark-mode toggle to settings
04
It pushes a branch and opens a pull request. Merge, or hit Iterate to keep going — never touches main.
✓ PR #128 opened
¶ THE OBJECTION
Repo content, inbound issues, and chat history are all untrusted by default. The sandbox is the trust boundary — not the model's judgment.
Injection defense is in the system prompt — instructions embedded in repo files are ignored.
Tokens travel over stdin and are stripped from every error path before text reaches Discord.
Keys are encrypted per server; one guild's blob can't decrypt for another.
Non-root, every Linux capability dropped, CPU/mem/PID caps, removed on exit.
All git lands on anywarecode/<taskId>. A human merges, or nothing does.
Admins only by default; grant exactly one role with /config role.
In production the container can reach exactly two hosts: Anthropic and GitHub.
Designed after Comment & ControlOne subscription, the whole server — no per-seat math. Every plan ships every feature; the only meter is monthly /code. You bring your own AI — we never bill for it.
PLAN / Free
A real plan, not a demo. Connect your own AI and go.
PLAN / Pro
One shared engineer for the whole server — no per-seat math.
PLAN / Studio
For studios living in voice channels and shipping daily.
PLAN / OSS Community
For verified public open-source servers. Your runs are the demo.
STUB / Job Pack — $8 / ₹700
50 extra code tasks for the server, buyable by ANY member — Discord-boost style, with public credit. Never expires while subscribed.
No. Each task clones into an ephemeral container that's removed when it exits. We keep only task history and usage counters — removing the bot deletes your server's data.
Yours, always. We don't supply AI or bill for it. Every server connects its own credential — an Anthropic API key, a Claude Pro/Max token, or any compatible endpoint — encrypted per server. The Free plan is the trial: connect your key and go.
Never. All git lands on anywarecode/<taskId> and arrives as a pull request. Nothing merges without a human.
Everything external is untrusted: quarantine strips hidden instructions from inbound issues, verification runs hold read-only tokens, and the container is sealed. Designed after the Comment and Control disclosures, not before them.
Admins only by default. Grant exactly one role with /config role. @everyone and @here never trigger it.
The opposite, by construction: every run has a named human sponsor, every PR carries a provenance receipt, and Repro Gate filters bug reports before they cost a human minute.
06 / SIGN-OFF
Install the bot, connect a repo, type /code. Free to start — your key, your rules, every feature included.
AUTHORIZED SIGNATURE — YOUR SERVER