THE MANUAL
FOR THE MACHINE.
From the first install to your first authorized CTF analysis. Every essential command, without the guesswork.
Build faster from your terminal.
WROSECODE is a Rust terminal coding agent with a responsive TUI, tool execution, AI provider integration, saved sessions, headless automation and an authorized CTF workflow. You can install a packaged native binary or build the CLI from source.
Install WROSECODE CLI.
Option A — npm: The easiest global installation method if the wrosecode package is published and its native release assets can be downloaded. Install Node.js 18+ first.
node --version
npm --version
npm install -g wrosecode
wrosecode --version
wrosecode --helpOr run once using npx wrosecode. To upgrade or remove the CLI:
npm install -g wrosecode@latest
# To uninstall:
npm uninstall -g wrosecodeUse the download selector on the homepage for a platform-specific installation command, or choose a release binary below. Always verify checksum files from the release.
Native downloads by platform.
v1.0.0 binaries and matching .sha256 assets are listed on GitHub Releases. The direct URLs below use those listed filenames.
Linux example (x86_64)
curl -fL https://github.com/whiterose717/WROSECODE-CLI/releases/download/v1.0.0/wrosecode-linux-x86_64 -o wrosecode-linux-x86_64
curl -fL https://github.com/whiterose717/WROSECODE-CLI/releases/download/v1.0.0/wrosecode-linux-x86_64.sha256 -o wrosecode-linux-x86_64.sha256
sha256sum -c wrosecode-linux-x86_64.sha256
chmod +x wrosecode-linux-x86_64
mkdir -p "$HOME/.local/bin"
install -m 755 wrosecode-linux-x86_64 "$HOME/.local/bin/wrosecode"
export PATH="$HOME/.local/bin:$PATH"
wrosecode --versionmacOS example (Apple Silicon)
curl -fL https://github.com/whiterose717/WROSECODE-CLI/releases/download/v1.0.0/wrosecode-darwin-aarch64 -o wrosecode-darwin-aarch64
curl -fL https://github.com/whiterose717/WROSECODE-CLI/releases/download/v1.0.0/wrosecode-darwin-aarch64.sha256 -o wrosecode-darwin-aarch64.sha256
shasum -a 256 wrosecode-darwin-aarch64
# Compare the hash with the official .sha256 file
chmod +x wrosecode-darwin-aarch64
./wrosecode-darwin-aarch64 --versionWindows (PowerShell)
Download wrosecode-windows-x86_64.exe (for most Windows PCs), verify the SHA-256 hash, then rename it to wrosecode.exe. The example assumes the file is in Downloads.
$file = "$HOME\Downloads\wrosecode-windows-x86_64.exe"
Get-FileHash $file -Algorithm SHA256
# Compare hash with the official release checksum
New-Item -ItemType Directory -Force -Path "$HOME\bin" | Out-Null
Copy-Item $file "$HOME\bin\wrosecode.exe"
& "$HOME\bin\wrosecode.exe" --versionBuild and install from Rust source.
For Kali Linux, Debian or Ubuntu, install build prerequisites and Rust, then clone the repository (requires access to the source).
sudo apt update
sudo apt install -y git curl build-essential pkg-config libssl-dev
# Install Rust via the official rustup script after reviewing it:
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source "$HOME/.cargo/env"
git clone https://github.com/whiterose717/WROSECODE-CLI.git
cd WROSECODE-CLI
cargo install --path .
wrosecode --versionAlternatively, use cargo build --release to create target/release/wrosecode. This method does not require npm.
Connect your AI provider.
The terminal agent needs a configured AI model to perform model-driven tasks. Use its provider manager to add a provider, save the key and verify the connection.
wrosecode providers list
wrosecode providers add
wrosecode providers set-key
wrosecode providers testFor a compatible local endpoint (such as a local OpenAI-compatible server):
export WROSECODE_OPENAI_URL="http://127.0.0.1:11434/v1"
wrosecode --provider openai-compat --model MODEL_NAMEYour first terminal session.
Open your project folder
Navigate to an existing code repository or create a new working directory.
Launch WROSECODE
Start the interactive TUI, select a model and the desired permission policy.
Give the agent a task
Ask it to inspect code, run tests, propose a change, or analyze an authorized CTF.
cd /path/to/your/project
wrosecode --permission auto-safe --think autoInside the terminal, try:
Inspect this project, explain its architecture, and list the failing tests.For one-shot headless execution:
wrosecode exec "review this repository"
wrosecode exec --json "inspect this codebase"Choose permissions & thinking.
Pick a permission policy based on your trust in the workspace. For ordinary development, auto-safe allows less risky operations automatically and prompts for sensitive actions.
wrosecode --permission ask
wrosecode --permission auto-safe
# CAUTION: skips prompts; disposable VM / trusted repo only
wrosecode --permission yoloThinking level
Choose from off, low, medium, high, max, and auto. The supported model and provider determine available performance.
wrosecode --think auto
wrosecode --think high
# Inside the TUI use: /think highUse the /ctf agent.
Start CTF investigations in the terminal against authorized challenge artifacts or challenge endpoints. The agent can use its configured tools and provider; actual solve performance is not measured by this website.
wrosecode ctf ./challenge-files/
wrosecode ctf ./capture.pcapng --category forensics
wrosecode ctf ./challenge --category crypto
wrosecode ctf ./binary --category pwnConfigure budgets and independent workers:
wrosecode ctf ./challenge --budget "steps=50,tokens=100000,seconds=1800" --parallel 4Inside interactive mode:
/ctf ./challenge-files/
/writeupFor a remote target, supply only a host and port explicitly authorized in your challenge:
wrosecode ctf ./binary --category pwn --remote challenge.example:31337CTFd commands & submission.
For competitions using an authorized CTFd instance, use the CLI's CTFd commands to inspect challenges, check the scoreboard and verify or submit flags as permitted.
wrosecode ctfd list
wrosecode ctfd scoreboard
wrosecode ctfd download
wrosecode ctfd submit
wrosecode ctfd verifyConfigure credentials privately in your local shell:
export CTFD_URL="https://ctf.example"
export CTFD_TOKEN="your-private-token"Essential CLI slash commands.
Type these inside the WROSECODE terminal interface (not as external shell commands). The installed version's /help is authoritative.
| COMMAND | PURPOSE |
|---|---|
/help | Show commands and keybindings |
/providers | Configure AI connections |
/models | Inspect or select models |
/think high | Set higher reasoning effort |
/plan | Switch to planning mode |
/build | Switch to implementation mode |
/ctf TARGET | Start a CTF investigation |
/sessions | List previous sessions |
/resume | Resume a session |
/add PATH | Pin a file to context |
/diff | Inspect changed files |
/review | Review changes |
/stats | Usage and performance |
/compact | Reduce context size |
/skills | Manage installed skills |
/writeup | Generate CTF notes/write-up |
Work at terminal speed.
| KEY | ACTION |
|---|---|
| Ctrl+P | Command palette |
| Tab | Toggle build/plan when input is empty |
| Ctrl+T | Cycle thinking |
| Ctrl+R | History picker |
| Ctrl+F | Flag picker |
| PageUp / PageDown | Scroll transcript |
| Shift+Enter | New line in prompt |
| Ctrl+C | Cancel running step; twice when idle exits |
| @ | Mention a file from picker |
Sessions, automation and more.
Resume & fork existing sessions
wrosecode --session SESSION_ID
wrosecode --session SESSION_ID --fork
wrosecode --session SESSION_ID --export-session session.jsonAutomatic test repairs
wrosecode --check-command "cargo test" --repair-retries 5 "fix the tests"Structured automation & events
wrosecode exec --json "analyze the repository"
wrosecode --events events.ndjson --headless "run the tests"
wrosecode --trace "investigate slow tests"Dashboard and local server
wrosecode dashboard
wrosecode --listen 127.0.0.1:7878Skills, agents & recipes.
Extend WROSECODE with reusable workflows and project-specific skills. Review any installed skill code before granting it permission to run commands.
wrosecode recipe list
wrosecode recipe run NAME
wrosecode recipe run NAME --set PROJECT=my-app
wrosecode --install-skill /path/to/skillInteractive commands and folders:
/skills list
/skills install SOURCE
/skills uninstall PACKAGE
# Project-specific recipes: .wrosecode/recipes/
# Project-specific agents: .wrosecode/agents/Run a project agent by name:
wrosecode --agent AGENT_NAMEWhere WROSECODE keeps data.
Useful local configuration and session locations. Keep provider secrets and exported session data out of public Git repositories.
| LOCATION | DESCRIPTION |
|---|---|
~/.wrosecode/providers.toml | Provider profiles and credentials |
~/.wrosecode/sessions/ | Saved sessions |
~/.wrosecode/state.db | Persistent application state |
~/.wrosecode/skills/ | Installed skills |
~/.wrosecode/trace.log | Performance traces |
.wrosecode/project.toml | Per-project settings |
Fix common setup problems.
"wrosecode: command not found"
Verify that installation completed and the global executable folder is in PATH. Open a new terminal after updating your shell environment.
npm prefix -g
export PATH="$(npm prefix -g)/bin:$PATH"
wrosecode --versionnpm reports 404 or installer cannot fetch a release
Confirm the npm package is published and the GitHub release assets are accessible. Install a native binary or compile from source when you have repo access.
CHECK GITHUB RELEASES ↗Model authentication fails
Re-enter your provider credential, confirm model access and test it directly.
wrosecode providers list
wrosecode providers set-key
wrosecode providers testNeed exact commands for your build?
Use the help output provided by the installed binary; commands and options may change after v1.0.0.
wrosecode --help
wrosecode providers --help
wrosecode ctfd --helpDocumentation reflects the project CLI command guide supplied for this site. Independent validation of each command against a live install was not performed here.
Grab the CLI, configure your provider, and put the terminal agent to work.
DOWNLOAD WROSECODE ↗