Inside an AI shell assistant: the Angela CLI blueprint
How a Gemini-powered terminal assistant is designed to fit together: shell hooks, a context engine, a request pipeline, a five-level risk classifier, adaptive confirmation and a rollback log. The design is worth borrowing; the project behind it is an unfinished prototype, and the checks say exactly where. Checked against the project’s own code
Angela is an AI assistant that lives in your shell. You type what you want in plain English; it works out the command, scores how sure it is, rates how risky it is, previews it, asks before anything destructive, runs it, and can roll it back. That loop is a clean blueprint for any AI that acts on a real machine, built from textbook parts: shell hooks that watch what you do, a context engine, a dispatcher, a five-level risk ladder, confirmation in proportion to risk, and a transaction log for undo. This is the blueprint, with each part checked against the code. The honest finding: the architecture is worth borrowing, the project is not something to rely on. It is an alpha prototype, untouched since May 2025, pinned to a Gemini model Google has since shut down, and several of the pieces the design describes are missing or broken.
A design reference, not an install guide. Angela CLI is an open-source Python tool that sits inside Bash or Zsh and turns plain-English requests into shell commands through Google’s Gemini API, wrapped in context gathering, risk checks, confirmation and undo. The architecture it describes is a good map for building any agent that executes commands on a real machine. The code is a useful place to see that map partly built, and to learn from where it isn’t.
The project bills itself as the world’s first command-line AGI. Its own README says “(will be)” and “ANGELA IS NOT COMPLETE YET”, and its package metadata says Alpha, version 0.1.0. Technically it is a Typer command-line app that calls Gemini. One developer, three stars, last commit 25 May 2025, and no licence file despite the MIT badge.
What held up, on 2 October 2026
Checked against the angela-cli repository at its latest commit (aafda64, 25 May 2025), by reading the code and running it, plus Google’s Gemini deprecation notices.
Ambient intelligence in the shell
Traditional command lines make you memorise syntax and flags. Chat assistants understand plain language but can’t see your machine. Angela’s design puts the model inside the shell, where it can see your project, the commands you just ran and the files you are working on, and act right there. The ambition is an assistant you can talk to at any level, from “show disk usage” to “set this project up for Docker”, that adapts to how you work over time.
The five design principles
Six subsystems
As designed, with what the code actually contains.
Shell integration
Zsh preexec and precmd hooks (a DEBUG trap in Bash) report every command, its exit code, its duration and any change of directory to Angela in the background, so the terminal never waits. A tmux file adds a status indicator and key bindings.
Context management
Project-type inference, recent-file tracking, command history and session state, gathered lazily so only what a request needs is computed. In practice, ordinary requests get fixed-size slices of it, not a relevance-ranked selection.
Request handling
An orchestrator classifies each request into one of 16 types (command, multi-step, file content, workflow, code generation, toolchain and so on) and hands it to that type’s handler.
Gemini integration
A GeminiClient wrapper, prompt-building functions with few-shot examples, a parser that pulls JSON out of the reply, a nine-factor confidence scorer, and an error analyser that suggests fixes when a command fails.
Safety layer
A five-level risk classifier, regex checks for dangerous patterns, per-command impact previews, confirmation that adapts to risk and to your history, and a rollback manager that records changes as undoable transactions.
Toolchain adapters
Git, Docker, package managers and a universal translator for arbitrary command-line tools, each behind its own adapter class, plus CI/CD and test-framework integrations.
The hook that makes it ambient
From angela_enhanced.zsh. Every notification runs in a background subshell, which is the trick that keeps a context-gathering assistant from slowing the prompt down.
The single-command path
What the orchestrator actually does with “find all Python files in this project”.
Gather context
Refresh what it knows about the working directory and project, and resolve any file the request mentions by name.
Classify the request
Pattern-match the text into one of the 16 request types. A plain command request takes this path; multi-step goals take another.
Ask Gemini for a command
Send system instructions, the context, few-shot examples and a strict JSON response format, then parse the reply into intent, command and explanation.
Score confidence
Rate the suggestion on history, similarity, syntax, flags and context. Below 0.6, ask a clarifying question instead of guessing.
Rate the risk and preview it
Place the command on the five-level ladder and generate a preview of what it would touch.
Confirm in proportion
SAFE and LOW run without asking. Above that, skip the question for a command you’ve trusted, or one with a long record of succeeding at a level you allow; otherwise ask simply at MEDIUM and show a detailed confirmation at HIGH and CRITICAL.
Run, log, learn
Execute, record the outcome in history, and offer to trust a command you keep approving. On failure, analyse the error and suggest a fix.
Structured output, every time
The last thing every command prompt contains before the user’s request. Forcing JSON is what lets the rest of the pipeline treat the model’s answer as data rather than prose.
The risk ladder
The ladder, as code
Undo, as transactions
The part most worth copying is the rollback manager. Each logical action, say a five-step plan, opens a transaction; every file change and command inside it is recorded with what is needed to reverse it, either a backup or a compensating command; and rollback replays those in reverse order, newest first. Transactions are saved as JSON, so they survive the session. It isn’t atomic in the database sense, but it turns “the AI broke my project” into one command.
When a step fails, an error-recovery manager chooses between retrying, modifying the command, trying an alternative, preparing the environment, reverting, skipping or aborting.
The patterns it is built on
What to fix before you borrow it
The roadmap, and where things stand
The design’s roadmap lists deeper multi-tool orchestration, local models for privacy, customisable learning, multi-agent collaboration, visual feedback and team features. None of it has landed: the code has one model client, Gemini’s, and no commit since 25 May 2025.
Explore the code safely
For study, not daily use. Use --suggest-only (or --dry-run) so nothing executes, and remember its safety layer has the gaps above.
The shape is right: watch the shell, gather context lazily, turn language into a structured suggestion, score it, rate its risk, preview it, confirm in proportion to the risk, run it inside something you can undo, and learn from what happens. Build that loop with real validation, the provider’s filters left on and nothing hard-coded, and it is a solid blueprint for any agent that touches a real machine.