Agent Pipeline DesignerDesign, trace, and improve agent workflows. Agent Pipeline Designer turns privacy-safe VS Code agent-hook events into a live workflow graph. It is a standalone, domain-neutral developer tool with no application-specific runtime dependency. InstallInstall Agent Pipeline Designer from the Visual Studio Marketplace, or run:
The stable VSIX is also published on the project release page for manual installation and checksum verification. What it shows
The graph updates whenever a matching JSONL event log changes. Raw prompts, terminal commands, tool responses, and transcript contents are intentionally excluded from the event schema. Select any agent node in the pipeline to filter Activity to only the actions attributed to that agent. The selected node uses the primary accent, its direct callers, targets, and connecting routes use the connected accent, and unrelated branches recede without becoming unavailable. Selecting a route highlights both endpoint agents and dims the rest of the graph. The Activity header shows the selected agent or route and action count; select the same item again or choose Show all to return to the complete run. Search applies inside the current agent or connection scope. Node and connection clicks remain distinct from graph panning: pointer capture starts only after the pointer crosses a small drag threshold. A stationary click selects the bubble, while a drag pans without accidentally changing the Activity filter. Relationship lines use fixed-size open-chevron markers so repeated calls can increase line weight without inflating the arrowhead. Every edge shows its call count above the path with a background halo, and selected relationships switch both the line and arrow to the accent color. Repeated instances of the same custom-agent role are collapsed into one node. Handoff lines become thicker as one role calls another more often, while self-calls and mutual calls remain stable loops and cycles. Select a line to inspect the timestamped, privacy-safe delegation summaries and outcomes that produced that relationship. The extension view includes the same Pipeline / Agents / Gallery navigation as the standalone app. Those navigation buttons keep identical dimensions and placement while switching views. In Agents, create a template or edit an existing file through separate Metadata, Opening Instructions, and Markdown section editors. Change heading levels and names, reorder or remove sections, add new sections, switch to raw source when needed, or open the file in the normal VS Code editor. Unsaved source survives live pipeline refreshes; an external file edit is surfaced before an overwrite. Choose Open Agent Studio from the Agents toolbar to open the canonical full-width Agents workspace as a native VS Code editor. It uses the extension's workspace filesystem and Language Model APIs directly; it does not start localhost or Simple Browser, and it does not require pipeline capture to be installed. Agent Studio provides the complete agent-file workflow available on the standalone web surface: creation, Copilot-assisted drafts, structured metadata, workflow routing, tools, models, Form/Source editing, Auto Revise, save, delete, and post-create routing. Open Source remains available when direct Markdown editing is preferable. While VS Code activates the extension and scans workspace files, APD displays a dedicated loading screen instead of an empty editor. Longer scans show a progress explanation and Retry action; the workspace UI appears only after the webview and extension have completed their readiness handshake. Selecting a Workspace agent updates the editor immediately at every width, including while extension-host state is being persisted. At narrow sidebar widths, the view uses an in-place list/editor flow: select an agent to replace the list with its editor, then choose Agents to return to the workspace list. The editor is never placed below the visible sidebar area. The Workspace agents list keeps connected agents together in caller-to-target order. Solid dots identify agents connected to other files in the current workspace, with an accessible tooltip reporting the number of neighboring agents; a hollow warning dot identifies a loose custom agent. Small gaps separate connected groups from Main Agent Instructions and unconnected agents without making each row taller. Choose New Agent in Agent Studio or run Agent Pipeline Designer: New Agent... from the Command Palette. Both entry points open the same native review dialog for workspace, filename, invocation policy, tools, models, discovery description, and full instructions. Copilot can populate that form from a plain-language description, but no file is written until Create Agent is selected. The new agent then opens in the structured editor and offers routing. Open Web Version remains an optional standalone browser surface, not an agent-editing requirement. Choose Open Full Pipeline from the Live Pipeline view title or Command Palette to open the pipeline workspace as a native VS Code webview editor. VS Code's optional When several VS Code project windows are open, each window identifies its attached local workspace before reusing a standalone server. A different codebase automatically starts on the next available localhost port, while another window for the same codebase reuses its existing server. New servers run in a hidden transient terminal owned by that window instead of the shared VS Code task queue, and a simultaneous port race is retried on the next available port. Multi-root folders in one window are treated as one workspace, and the health check exposes only a fingerprint rather than filesystem paths. Graph connections use an invisible wide hit path for easier pointer and keyboard selection, but browser focus never draws its rectangular SVG bounds. Keyboard focus follows the route with a translucent accent halo, while the selected route and arrow use the same orange accent in VS Code and the web version. Event sourceThe default source is:
On first use, the extension shows a setup screen instead of loading the graph. Select Install Setup to install the privacy-safe recorder, lifecycle hook configuration, and Each line is one JSON object produced by documented VS Code agent hooks. The core fields are:
For exact tool attribution during parallel custom-agent work, agent-scoped hooks may add An agent-scoped tool hook can stamp that field without recording prompt content:
Commands
Clearing a workspace log requires Workspace Trust. Open Web Version opens an existing Agent Pipeline Designer server when one is detected. From desktop VS Code, it otherwise starts the standalone project on the first available port from Custom agentsOpen the Agents tab in the standalone application to browse Select New Agent to create a workspace agent. The form writes validated YAML frontmatter and instructions to Saving an existing agent uses the same validated document model in VS Code and localhost. The standalone endpoint accepts only same-origin writes to regular files directly inside When agent edits are unsaved, switching between Pipeline, Agents, and Gallery or selecting another agent opens a Save Changes / Discard / Keep Editing prompt. Save waits for the backend acknowledgment before navigating; failures keep the editor open. Closing or reloading the page also triggers the browser's native unsaved-changes warning. The VS Code view retains its context when merely hidden or collapsed. Inline file contextWhen the extension is active in VS Code, hover over content in
Unknown Markdown headings receive a scope-aware explanation, while unrelated Markdown files are left untouched. The provider supports VS Code's native Main Agent InstructionsMain Agent Instructions represents If no attached workspace has an instructions file, each available creation target appears as Not created. Opening the Agents view does not create anything: enter instructions and select Save Changes to create the file explicitly. Once it exists, Open Source and review-only Auto Revise become available. Auto Revise uses a dedicated project-instructions contract and cannot add custom-agent YAML frontmatter, tool access, or agent workflow routes. Routing, Tool Access, and Delete are intentionally hidden for the main entry. Use custom agents for isolated roles and tool restrictions; use Main Agent Instructions for project-wide coding standards, architecture notes, build/test commands, and conventions that apply everywhere. MetadataThe Metadata Form edits the agent name and discovery description without requiring YAML. Invocation offers four explicit policies: agent picker plus automatic calls, picker only, subagent-only automatic calls, or explicit routes only. Unknown frontmatter keys are preserved when the structured fields are saved. Use Source mode for metadata outside the supported Form. Direct source remains validated through the same YAML parser before writing. Tool access and custom toolsThe Tool Access section shows the seven built-in aliases and any tools already selected for the agent. Up to 1,000 tools currently registered through Choose Add Custom Tool to document a manual tool ID. Each definition includes the exact ID, purpose, and usage instructions. The ID is selected automatically and remains selected until its definition is removed. Saving writes selected IDs to YAML frontmatter and creates a managed Custom Tools section containing reviewable Auto Revise receives the available tool IDs and may propose tool-access improvements. Any changes remain part of the normal unsaved revision draft and require Save Changes. Model accessThe Model Access section controls the optional Selected models are pinned above unselected choices so current restrictions remain visible without scrolling. Remaining model choices stay alphabetized. Select multiple models to write list metadata such as:
Legacy scalar Delete agentsSelect Delete on an existing agent and confirm the modal warning. Delete is disabled while edits are unsaved or Auto Revise is running. The extension requests trash-backed deletion when supported and falls back to the workspace filesystem after confirmation. The standalone app accepts only same-origin deletion of regular Auto ReviseSelect an existing agent and choose Auto Revise. Copilot receives that selected agent file plus the names of available workspace agents and prepares a conservative modernization using current custom-agent conventions. It is instructed to preserve the agent's identity, purpose, custom metadata, and valid The result is validated as a complete Auto Revise is user initiated. Only the selected agent definition and available agent names are sent through the consent-aware VS Code Language Model API; workflow event logs, transcripts, terminal output, and hidden model reasoning are not included. The standalone app requires its authenticated VS Code Copilot bridge, while the extension invokes the same validated revision flow directly. RoutingThe Routing Form is the single place to understand and edit agent-to-agent traffic. Its live Routing flow reads left to right as Incoming → Current agent → Outgoing. Work and call rails move toward a target; result rails point back toward the caller. On narrow editors, the same stages stack top to bottom with downward work paths and upward result paths. The current agent appears once as the active routing hub. Incoming cards identify whether the relationship is an explicit workflow call, instruction mention, handoff, or allowlist-only availability. Numbered outgoing cards are configured calls in execution order; cards marked A are allowed through Outgoing calls opens in Builder mode. Select one or more available subagents and choose Auto Route Selected to create validated optional routes using each agent's discovery description. Selected targets are also added to the parent's
Routes are ordered. Route policy selects flexible routing or a strict listed sequence. Builder mode keeps common triggers and expected outcomes in menus and provides required/optional and reorder controls without exposing delegation text. The Routing flow does not imply that outgoing subagents call one another. Every numbered target is called directly by the current agent, which receives that result before continuing. Required calls use the success accent, optional calls remain muted, and each target includes its condition and expected outcome. Select a numbered target to jump to that route's editor. The flow updates immediately when route policy, target, condition, required state, expected outcome, or allowlist changes. Choose Advanced to directly edit custom trigger text, the task, required output, and delegation template. The template must contain Select a runtime node in Pipeline to compare that contract with observed delegation metadata. Each route is marked The contract is instruction-level enforcement, while compliance reporting is evidence-based. It does not expose or infer private model reasoning, and it does not claim that a language model is mechanically prevented from deviating. Evaluation uses only agent names, lifecycle events, privacy-safe delegation summaries, and structured outcomes already captured by the recorder. Incoming-call diagnostics. Agent Pipeline Designer detects incoming calls from Main Agent Instructions, managed Agent Workflow routes, exact The diagnostic keeps invocation concepts separate:
VS Code does not provide a custom-agent field that automatically schedules an agent at the true end of every chat. For a finalizer such as Select Auto Route on an agent with no explicit call route, then choose who should call it. A Main Agent target receives an inferred project instruction; its text stays collapsed unless Customize Main Agent instruction is opened. A selected custom parent receives a validated optional step in its Agent Workflow with no direct typing required. Existing parent metadata, tools, models, custom tools, and workflow steps are preserved. New agents open this chooser automatically after creation. Main-agent routes are stored in a managed Agent Routing section of For stronger enforcement, a workspace Draft with CopilotNew Agent is the single place to create custom agents. Describe the desired behavior in Draft with Copilot at the top of that form, or fill the same fields manually. The draft description requires at least 3 words and 10 characters and shows an inline error when that requirement is not met. Copilot can populate the name, filename, discovery description, minimal tool set, invocation visibility, and complete instructions. All values remain editable, and no file is written until Create Agent is selected. The browser never receives Copilot credentials. An authenticated localhost queue sends the one-shot draft request to the extension, which uses the consent-aware VS Code Language Model API. The first request may display a Copilot access prompt in VS Code. Jobs remain in server memory for at most 15 minutes and are not written to disk. A manually started web server can browse and create agents, but Copilot drafting is enabled only when the extension starts or reconnects to that server. If access has not yet been granted, the pending draft remains open and shows Grant Access in VS Code. That link focuses VS Code, opens the Copilot authentication flow, and resumes the same request after approval. Open Web Version also requests access while VS Code is already focused, before launching the browser. Use the Copilot model selector in New Agent to choose any model currently exposed by your Copilot account, or leave it on Auto (recommended). The selection is remembered in the browser. While a request runs, Process shows timestamped operational stages such as queued, received by VS Code, selected model, generating, validating, waiting for permission, and ready for review. This is execution status for transparency, not private model chain-of-thought or hidden reasoning. Pipeline GalleryThe Gallery reads a static versioned catalog from GitHub. The default public catalog currently contains no packages; its repository publishes only protocol schemas, declaration files, non-runnable examples, and documentation. Package download, verification, preview, conflict handling, receipts, and workspace writes remain part of the private Agent Pipeline Designer product. Browse the public catalog and publishing entry point at pipeline-designer.github.io. The public site uses black product branding, an animated pipeline scene, and a dedicated Actions workspace. Prepare in VS Code opens package preparation, while a valid GitHub manifest URL enables Open installer and passes that exact URL into Agent Pipeline Designer's verified review flow. The website itself never reads or writes workspace files. Version 1 packages may create only these declarative customization files:
Scripts, hooks, binaries, dependencies, arbitrary paths, traversal segments, percent escapes, cross-origin payloads, and symlinked path components are rejected. Registry, manifest, and file downloads must use HTTPS GitHub URLs. Every file declares an exact byte length and lowercase SHA-256 digest; all package files are fetched and verified before review. The VS Code extension uses a modal confirmation listing every destination. The standalone app uses a short-lived, one-time preview token and shows the exact verified text for every file before enabling installation. Installation refuses existing destinations, writes the receipt last, and removes files already written if a later write fails. Receipts are stored under Use Install from URL for a GitHub-hosted manifest that is not listed in the catalog. This does not bypass path, size, origin, content, integrity, preview, or conflict validation. Save and switch pipelinesEach workspace can contain multiple installed and local-only pipelines. The Pipeline tab groups them under Saved pipeline, shows the saved count, and keeps Activity and Run selection separate. Use + to add another package from Gallery, choose any saved pipeline, then select Set Active. Agent Pipeline Designer derives package membership from the verified installation receipt, identifies its coordinator, and generates one managed Saved pipelines coexist, but one pipeline per workspace is active at a time. The generated APD Active Pipeline agent preserves that coordinator's instructions while replacing its After activation, select Open Active and choose APD Active Pipeline from Copilot's agent picker. Inside that selected agent, the Select Delete to remove an old saved pipeline after reviewing the file-count confirmation. Deleting the active pipeline also removes the APD-managed active coordinator and state. Installed package files are checked against their receipt hashes before deletion; if an existing file was edited, deletion stops so those changes are not lost. Missing stale files do not prevent the remaining receipt and owned files from being cleaned up. Local-only pipelines remove their edited copies after explicit confirmation. Local-only pipeline copiesChoose an installed pipeline in the Pipeline tab and select Copy for Editing to create a private workspace copy. Enter a unique custom ID such as Agent Pipeline Designer creates namespaced Local manifests live under Publish a project pipelineRun Agent Pipeline Designer: Prepare Pipeline Package... or choose Publish Pipeline in Gallery. Select the agents, instructions, prompts, and main Copilot instructions that form the reusable pipeline, then enter the package metadata, public GitHub project repository, and immutable tag or commit. Agent Pipeline Designer writes an atomic, versioned folder at:
The folder contains copied declarative payloads, Commit the generated folder, push the declared tag or commit, and use Copy Manifest URL or Open Submission Page. The public website passes the manifest URL to an owner-reviewed GitHub issue. Package payloads remain in the project repository and are not copied into the registry repository. Settings
Release channels
Run See RELEASE_CHANNELS.md for promotion rules. Development
Press Source is grouped by ownership under
The UI runner targets VS Code
Privacy and limitationsVS Code exposes subagent and tool lifecycle metadata through preview hooks, not a public extension API for directly inspecting Copilot sessions. This extension therefore reads workspace-owned event logs. Hook APIs may evolve, and tool attribution is intentionally conservative when events are missing agent-scoped metadata. |