# Core Features of the Open-SWE Project: A Complete Technical Guide

> Discover the core features of Open-SWE, an open-source framework for deploying internal coding agents. Explore sandboxed execution, toolsets, and automated PRs powered by LangGraph and Deep Agents.

- Repository: [LangChain/open-swe](https://github.com/langchain-ai/open-swe)
- Tags: deep-dive
- Published: 2026-03-19

---

**Open-SWE is an open-source framework that enables organizations to deploy internal coding agents via Slack, CLI, or web apps, featuring sandboxed execution, curated toolsets, and automatic PR creation powered by LangGraph and Deep Agents.**

The core features of the open-swe project center on providing a production-ready architecture for autonomous coding agents. Built by LangChain and used by engineering teams at Stripe, Ramp, and Coinbase, this framework combines deterministic orchestration with flexible sandbox environments to handle real-world software engineering workflows.

## Architectural Overview of Open-SWE

The project implements a layered architecture that separates agent logic from execution environments. Each layer serves a specific function in the autonomous coding pipeline.

### Agent Harness and Deep Agents Integration

At the core of the system lies the **Agent Harness**, which composes agents using the Deep Agents library. The `create_deep_agent` function in [`agent/utils/__init__.py`](https://github.com/langchain-ai/open-swe/blob/main/agent/utils/__init__.py) wires together the model, system prompt, curated tools, and middleware.

```python
from deepagents import create_deep_agent
from agent.utils import (
    http_request,
    fetch_url,
    commit_and_open_pr,
    linear_comment,
    slack_thread_reply,
)

agent = create_deep_agent(
    model="anthropic:claude-opus-4-6",
    system_prompt=construct_system_prompt(repo_dir, ...),
    tools=[
        http_request,
        fetch_url,
        commit_and_open_pr,
        linear_comment,
        slack_thread_reply,
    ],
    backend=sandbox_backend,
    middleware=[
        ToolErrorMiddleware(),
        check_message_queue_before_model,
    ],
)

```

### Sandboxed Execution Environments

Each agent run executes inside an isolated **Linux sandbox** created on-demand. The framework supports multiple backend providers including Modal, Daytona, Runloop, and LangSmith. As implemented in [`agent/webapp.py`](https://github.com/langchain-ai/open-swe/blob/main/agent/webapp.py), sandboxes are reused across follow-up messages but auto-recreated if unreachable, ensuring stateful yet resilient execution.

### Curated Toolset for Common Operations

Rather than exposing unlimited function calling, Open-SWE provides approximately **15 first-party tools** covering the most common software engineering actions:

- **`execute`** – Shell command execution within the sandbox
- **`read_file`** and **`write_file`** – File system operations via Deep Agents
- **`fetch_url`** – Web page retrieval and markdown conversion
- **`http_request`** – Generic HTTP requests for API interactions
- **`commit_and_open_pr`** – Git operations and automatic draft PR creation
- **`linear_comment`** – Issue tracking integration
- **`slack_thread_reply`** – In-thread communication during long-running tasks

## Key Capabilities and Core Features

Beyond the base architecture, Open-SWE distinguishes itself through specific production capabilities designed for enterprise use.

### Multi-Channel Invocation

The FastAPI server in [`agent/webapp.py`](https://github.com/langchain-ai/open-swe/blob/main/agent/webapp.py) exposes webhook endpoints for **Slack mentions**, **Linear comments**, and **GitHub events**. Each endpoint validates signatures using [`agent/utils/github.py`](https://github.com/langchain-ai/open-swe/blob/main/agent/utils/github.py) for GitHub and [`agent/utils/slack.py`](https://github.com/langchain-ai/open-swe/blob/main/agent/utils/slack.py) for Slack, resolves repository configuration, and enqueues a LangGraph thread for processing.

```python
from agent.webapp import process_slack_mention

async def handle_mention():
    event = {
        "channel_id": "C123456",
        "thread_ts": "1690000000.000200",
        "user_id": "U789012",
        "text": "@openswe add unit tests for the new API",
    }
    repo_cfg = {"owner": "langchain-ai", "name": "open-swe"}
    await process_slack_mention(event, repo_cfg)

```

### Context Engineering with AGENTS.md

Open-SWE implements **repository-specific context injection** through the [`AGENTS.md`](https://github.com/langchain-ai/open-swe/blob/main/AGENTS.md) file. If present in the repository root, this file is read from the sandbox and injected into the system prompt, providing the agent with coding conventions, testing policies, and architectural guidelines specific to that codebase.

Additionally, issue payloads from Linear, Slack thread context, and GitHub event data are automatically appended to the prompt, ensuring the agent begins execution with full situational awareness.

### Deterministic Middleware Orchestration

The framework uses **LangGraph** for deterministic state management. Middleware hooks execute predictably around each model call:

- **`check_message_queue_before_model`** – Intercepts incoming user messages during long runs
- **`open_pr_if_needed`** – Automatically creates draft PRs if the agent finishes without manual submission
- **`ToolErrorMiddleware`** – Handles tool execution failures and retry logic

This architecture allows the main agent to spawn **sub-agents** using the `task` tool for parallel workstreams while maintaining parent-child state isolation.

### Automatic PR Creation and Validation

The `commit_and_open_pr` tool in [`agent/tools/commit_and_open_pr.py`](https://github.com/langchain-ai/open-swe/blob/main/agent/tools/commit_and_open_pr.py) handles the complete Git workflow: staging changes, committing with descriptive messages, and opening draft pull requests. If the agent completes its task without explicitly creating a PR, the `open_pr_if_needed` middleware automatically generates a draft PR to ensure no work is lost.

The agent is instructed via system prompts to run linters, formatters, and tests before committing, creating a self-validating workflow that maintains code quality standards.

## Summary

The core features of the open-swe project provide a complete production framework for autonomous coding agents:

- **Modular Architecture** – Layered design separating agent logic, sandbox execution, and tool orchestration via LangGraph and Deep Agents
- **Multi-Channel Integration** – Native webhook endpoints for Slack, Linear, and GitHub with signature validation and thread management
- **Sandboxed Execution** – Isolated Linux environments with support for Modal, Daytona, Runloop, and LangSmith backends
- **Curated Toolset** – Approximately 15 first-party tools covering shell execution, file operations, HTTP requests, and PR creation
- **Context Engineering** – Automatic injection of repository-specific conventions via [`AGENTS.md`](https://github.com/langchain-ai/open-swe/blob/main/AGENTS.md) and full payload context from triggering events
- **Deterministic Orchestration** – Middleware-driven execution with sub-agent support, message queue checking, and automatic PR creation

## Frequently Asked Questions

### What is Open-SWE and how does it differ from other coding agents?

Open-SWE is an open-source framework for running internal coding agents built on LangGraph and Deep Agents. Unlike general-purpose coding assistants, it provides a production-ready architecture with deterministic middleware, sandboxed execution, and native integrations for Slack, Linear, and GitHub that large engineering teams at Stripe, Ramp, and Coinbase use for autonomous PR creation.

### How does the sandboxed execution work in Open-SWE?

Each agent run executes inside an isolated Linux sandbox created on-demand through backends like Modal, Daytona, Runloop, or LangSmith. As implemented in [`agent/webapp.py`](https://github.com/langchain-ai/open-swe/blob/main/agent/webapp.py), these sandboxes persist across follow-up messages in the same thread but automatically recreate if they become unreachable, ensuring both stateful continuity and execution resilience.

### What tools are available to agents in the Open-SWE framework?

The framework provides approximately 15 first-party tools including `execute` for shell commands, `read_file` and `write_file` for filesystem operations, `fetch_url` and `http_request` for web interactions, `commit_and_open_pr` for Git workflows, and integration tools like `linear_comment` and `slack_thread_reply` for platform-specific actions.

### How does Open-SWE handle repository-specific coding conventions?

Open-SWE implements context engineering through an optional [`AGENTS.md`](https://github.com/langchain-ai/open-swe/blob/main/AGENTS.md) file in the repository root. When present, the framework reads this file from the sandbox and injects its contents into the system prompt, providing the agent with specific coding conventions, testing policies, and architectural guidelines unique to that codebase.