Where it comes from

Built on Amazon's open-source Kiro agent workspace, published under Apache-2.0 in 2026. Most of the code is theirs; the attribution notice is in NOTICE. Not affiliated with Amazon.

The attribution notice, verbatim, is NOTICE, served verbatim on this site. The upstream project is not named on this site beyond that link; its authors are credited there, in the form the licence asks for.

The carry-set

What is ours is a thin, named set of changes carried on top of the upstream tree. Everything not on this list is upstream's, and we do not fork it.

  1. The harness registry, with kiro-cli optional and last

    One dock, 11 runtimes, chosen by preference order or by one setting: cursor, claude, codex, kimi, dsh, goose, grok, opencode, pi, droid, then kiro-cli. Ten are non-Kiro; five of them the upstream project does not dock, and both of us dock OpenCode. First run never asks for a vendor account with us. The registry, with what is verified on each.

  2. The harness router, for subagents

    Chat runs the one harness you choose. The harness router (warding route) sends a spawned subagent to another installed harness: flat-rate plan quota before metered spend, the kind of task, and a cooldown after a usage limit or a failed login. It picks a harness and never forwards provider traffic. Registered · unverified.

  3. Endpoint removal

    The upstream project's update feed, app catalog and telemetry are off in the default build, and nothing contacts a server of ours. One inherited address remains: the embedding model is fetched on first embedding use from a CDN the upstream codebase shipped with, checked against a pinned hash; point memory.embed_model_url at your own mirror to avoid it. The run that lists every outbound connection is on the verification log as planned.

  4. The brand

    The name, the seal, the site and the CLI name warding. Package identifiers stay as their systems spelled them.

  5. The proof pages

    /verified/ and /registry/: a checkmark on this site links to a dated row, and a capability without one is written as unverified.

  6. Dawn-expiring approval grants In development

    A grant that lets a class of command run until a clock time, then asks again.

  7. The Morning Report In development

    What was done, what was asked, what was refused and what was redacted, counted from the audit log.

  8. warding switch In development

    Change the docked harness in one command; schedules, memory and channels stay.

The fork strategy

Track upstream
Not a hard fork. Upstream releases are merged, not re-implemented; every one of them is free work for the people running Warding.
Rebase quarterly
The carry-set is rebased onto the upstream tree once a quarter, and we refuse to widen it.
Offer the registry upstream
The harness registry, kiro-cli optional and last, is offered to the upstream project as a change of theirs to accept or decline. Planned; not offered yet.
Harden downstream
The proof artefacts and the two mechanisms above are where the work goes.

What upstream has that we lack

If you use kiro-cli, the upstream project is ahead and we say so. The comparison puts its strengths first.

  • No signed installers yet; upstream ships them for macOS, Windows and Linux.
  • No Docker image yet; upstream publishes one.
  • No desktop app yet; upstream ships one.
  • No KAS yet; upstream docks it. Both of us dock OpenCode.
  • On a non-Kiro harness, upstream gives the agent its own MCP tools; Warding passes them only to kiro-cli today, so on other harnesses the agent cannot create jobs, spawn subagents or ask you a question from chat.
  • Install polish, generally. The upstream project is at a later version with more hands on it.

Not affiliated

Myrmitis is not affiliated with, endorsed by, or connected to Amazon or the upstream project. The upstream name and marks belong to their owners and appear nowhere in this product's name, logo, domain or tagline. Releases of this tree are listed on the changelog, which reproduces only what we shipped.

Review the local beta.

Apache-2.0 source publication is pending. Read the setup notes and verification limits.

Source publication pending

Public source, install commands and downloads are not available yet. A clean install and live workflow are not yet verified.

Source status Read beta notes