Save tokens. Sharpen agents.
Smart token savings for coding agents and shell commands.
Sponsored by JFrog
English · Español · Français · Deutsch · 日本語 · हिन्दी · עברית
Dependencies, source, secrets, and IaC — scanned on every push to main. What that covers.
Frogi, our mascot, appears when you run just boost.
Boost wraps the commands your agents already run, turning noisy logs into compact, structured context that keeps the signal — errors, timings, changed counts, cache hits — while cutting the noise.
Boost never trades quality for savings. It trims only what's safe to drop, so agent output stays just as sharp. Our Terminal-Bench 2.0 benchmark shows it: identical task pass rate, ~12% lower cost — Boost keeps agents optimized without ever breaking their stride.
Install Boost
macOS / Linux / Windows WSL:
curl -fsSL https://boost.jfrog.com/install.sh | bashWindows PowerShell:
irm https://boost.jfrog.com/install.ps1 | iexWire it into Cursor, Claude Code, GitHub Copilot, and Codex CLI:
boost initFor AI coding agents installing Boost on a user's machine, follow AGENT-INSTALL.md.
- Long coding-agent sessions — Keep context lean across dozens of shell commands so agents spend tokens on the task, not scrollback.
- Noisy test, build, and debug loops — Compress
npm test,pytest,go test,docker build, linters, and logs while keeping failures and summaries. - CI pipelines — Shorter, easier-to-scan job logs with timing and cache signal for GitHub Actions and other runners.
- Custom or internal tools — Add TOML filters for your own CLIs so the same compression loop covers the tools your agents actually run.
Boost does not just truncate output. It applies command-aware filters that preserve what agents need to reason about the result.
# Without Boost: ~9,800 tokens of install noise
$ npm ci
npm warn deprecated [email protected] / [email protected] / [email protected] …
added 1285 packages, audited 1286 in 45s
found 0 vulnerabilities
# With Boost: ~640 tokens, same outcome, cache-backed
$ boost npm ci
[OK] npm ci · 1,285 packages restored from boost cache in 2.4s · 0 vulnerabilitiesThe agent sees the useful summary, not the scrollback. On failures, Boost keeps the failing test, compiler error, or stack frame that matters.
| Capability | Boost | RTK | Headroom | Caveman |
|---|---|---|---|---|
| Command output compression | ✓ | ✓ | ✓ | × |
| Full-context and RAG compression | × | × | ✓ | × |
| Assistant reply compression | × | × | × | ✓ |
| Command output recovery | ✓ | ✓ | ✓ | × |
| Native approval sees original executable | ✓ | × | — | — |
| Versioned retrieval feedback | ✓ | × | × | × |
| Auto-disable repeatedly retrieved filters | ✓ | × | × | × |
| End-to-end agent task + cost A/B | ✓ | × | × | × |
After wrapping commands, open the interactive web report:
boost reportFor a terminal narrative summary:
boost report -t
# or: boost report --tui- Agents: Cursor, Claude Code, GitHub Copilot, Codex CLI.
- Commands: Docker, npm, pytest, Git, GitHub CLI, and other shell commands pass through the same wrapper.
boost docker build ...— compressed build log and layer-cache summaryboost npm ci— dependency summary, local package cache, retry-safe outputboost pytest— quiet output on green runs, useful failures when tests break
boost updateSee the full documentation for commands, configuration, and OpenTelemetry export.
Boost's source repository is scanned on every push to main — the same commits every release is built from — by Frogbot, running JFrog Xray with JFrog Advanced Security.
| What gets scanned | |
|---|---|
| ✓ | Dependencies (SCA) — Go modules and npm trees across every module in the repo, matched against JFrog's vulnerability database |
| ✓ | Contextual Analysis — checks whether a reported CVE is actually reachable from Boost's code, so real risk is not buried in noise |
| ✓ | Malicious packages — dependencies flagged as malicious are caught before they reach a build |
| ✓ | Secrets — every tracked file is scanned for leaked credentials and tokens |
| ✓ | Source code (SAST) — Boost's own Go and TypeScript sources |
| ✓ | Infrastructure as Code — CI workflows and deployment definitions |
| ✓ | SBOM — a component inventory is generated per build target on every scan |
Findings land as code-scanning alerts and automated fix pull requests on the source repository. See SECURITY.md for the full scanning and disclosure policy.
- Local-first. Command history and raw logs stay on your machine.
- Only metadata leaves. When Boost sends usage data, it goes only to JFrog to help improve the product. Exported metadata includes timing, exit code, and cache stats, never raw logs, file contents, or env values. Secrets matching patterns like
*_TOKEN,*_SECRET,AWS_*,DATABASE_URLare redacted before write or export. - Open protocol, signed binaries. OpenTelemetry-native. Binaries ship signed via GitHub Releases.
Full policy, supported versions, and how to report a vulnerability: see SECURITY.md.
Copyright © 2026 JFrog Ltd. All rights reserved. See LICENSE and BETA_AGREEMENT.md.
Dedicated to the memory of Dima Gershovich — a brilliant engineer, a talented musician, and a dear friend. Read Dima's story