Automatically accept agent steps, terminal commands, file edits, and permission prompts in Antigravity — Google's AI coding assistant.
Run unlimited background agents completely hands-free.
Antigravity's Agent Manager can only interact with the active conversation. Background agents sit idle until you manually click through each one. Swarm Mode solves this — it automatically navigates between all your pending Agent Manager conversations via CDP, clicking Accept/Run/Allow across every agent.
Start 5 agents. Minimize the window. Walk away. Swarm handles everything.
| 💰 Price | $9/mo (with free trial) |
| 🔗 Get Pro | Start Free Trial → |
📖 Full Swarm Mode Guide → — Setup, activation, usage, and FAQ.
Control your agents from your phone.
Pair your IDE with Telegram to send prompts, receive responses with screenshots, and manage all your agent windows remotely.
| Command | Description |
|---|---|
/list |
Show & select active agents |
/peek |
Screenshot your live IDE |
/pause |
Pause AutoAccept + Swarm |
/resume |
Resume everything |
/stop |
Emergency stop all agents |
/status |
Check IDE connection |
/help |
Show all commands |
/disconnect |
Unpair from this IDE |
📖 Telegram Setup Guide → — Pairing, commands, and architecture.
When the Antigravity agent proposes file edits, terminal commands, or asks for tool permissions, this extension auto-accepts them so you don't have to click every button manually.
Two strategies, zero interference:
| Strategy | What it handles | How |
|---|---|---|
| VS Code Commands (500ms) | Agent steps, terminal commands | Calls Antigravity's native accept commands |
| CDP + MutationObserver (event-driven) | Run, Accept, Always Allow, Continue | One-shot script injected once, reacts instantly to DOM changes |
The extension needs Chrome DevTools Protocol to click permission buttons. Launch Antigravity with:
--remote-debugging-port=9333
Why port 9333? Antigravity's built-in Browser Control (Chrome button in the toolbar) uses port 9222 by default. Using the same port causes an
EADDRINUSEconflict on macOS/Linux. Port 9333 avoids this entirely. (Thanks to u/unlike_a_boss for discovering this!)
🪟 Windows
Automatic: On first launch, the extension detects if the port is closed and shows "Auto-Fix Shortcut" — click it to automatically patch your .lnk shortcut.
Manual: Right-click your Antigravity shortcut → Properties → append to Target:
--remote-debugging-port=9333
🍎 macOS
Option 1 — Automator App (recommended):
- Open Automator → New Document → Application
- Search for "Run Shell Script" in the library
- Paste:
open -a "Antigravity" --args --remote-debugging-port=9333 - Save as "AntiGravity Launcher" to Desktop or Applications
Option 2 — Terminal alias (add to ~/.zshrc):
alias antigravity='open -a "Antigravity" --args --remote-debugging-port=9333'Note: The app name must match exactly. Check with
ls /Applications/ | grep -i anti
Option 3 — Direct Electron binary (if open -a doesn't pass args correctly):
alias antigravity='/Applications/Antigravity.app/Contents/MacOS/Electron --remote-debugging-port=9333 & disown'(Thanks to @aangelinsf)
🐧 Linux
Option 1 — Edit the .desktop file:
# Find it:
find /usr/share/applications ~/.local/share/applications -name "*ntigravity*" 2>/dev/null
# Edit the Exec line:
Exec=/path/to/antigravity --remote-debugging-port=9333 %FOption 2 — Shell alias (add to ~/.bashrc or ~/.zshrc):
alias antigravity='antigravity --remote-debugging-port=9333'Option 3 — Wrapper script:
#!/bin/bash
/opt/Antigravity/antigravity --remote-debugging-port=9333 "$@"From VSIX (recommended):
- Download the latest
.vsixfrom Releases - In Antigravity:
Ctrl+Shift+P→Extensions: Install from VSIX - Select the downloaded file
- Reload Window
Manual:
- Copy the
src/directory,package.json, andpackage-lock.jsonto:~/.antigravity/extensions/YazanBaker.antigravity-autoaccept-3.27.29/ - Run
npm installin that directory (installswsdependency) - Reload Window
- Toggle: Click
⚡ Auto: ON/✕ Auto: OFFin the status bar - Or:
Ctrl+Shift+P→AntiGravity AutoAccept: Toggle ON/OFF - Dashboard: Click
📊in the status bar to see CDP status, active sessions, and activity log - Logs: Output panel →
AntiGravity AutoAccept
Antigravity's Agent Manager uses a single shared webview — only the active conversation's DOM is rendered. Background conversations are completely unmounted. Both the VS Code Commands API and CDP can only reach the currently visible conversation.
We verified this by decompiling Antigravity's source code: their accept command handlers are hardcoded to vscode.window.activeTerminal with zero arguments — there is no way to target a specific conversation.
This is an Antigravity architectural limitation, not an extension bug. It would require Antigravity to implement a cross-conversation accept command (e.g.
antigravity.agent.acceptAll).
To run multiple agents with auto-accept on all of them:
- Click File → Duplicate Workspace
- This opens a second Antigravity window connected to the same project
- Start a chat in Window 1 and another chat in Window 2
- Each window has its own webview — the extension auto-clicks buttons in both windows simultaneously
| Setting | Default | Scope | Description |
|---|---|---|---|
autoAcceptV2.pollInterval |
500 |
window | Polling interval in ms |
autoAcceptV2.customButtonTexts |
[] |
application | Extra button texts for i18n or custom prompts |
autoAcceptV2.cdpPort |
9333 |
machine | CDP port (default avoids conflict with AG Browser Control on 9222) |
autoAcceptV2.autoAcceptFileEdits |
true |
window | Auto-accept file edit changes (disable to review diffs manually) |
autoAcceptV2.blockedCommands |
[] |
application | Commands to NEVER auto-run (e.g. rm, git push, npm publish) |
autoAcceptV2.allowedCommands |
[] |
application | If set, ONLY these commands will auto-run (whitelist mode) |
Tip: Settings are hot-reloaded — changes take effect immediately without restarting.
The extension maintains a persistent browser-level WebSocket connection to Chromium's DevTools Protocol. Instead of polling every 1.5s, it injects a MutationObserver payload once per target. The observer reacts instantly when React mounts new button elements, with 100ms leading-edge throttle to prevent CPU spikes during streaming output. The extension uses a whitelist-only target filter — it only attaches to vscode-webview:// targets and automatically yields the CDP port when the AG browser sub-agent is detected, preventing ArrayBuffer conflicts.
The button scanner walks the DOM tree exactly once per cycle, checking all keywords simultaneously against each node. This is O(D) instead of the previous O(N×D) which could cause UI freezes with many keywords. Priority-aware matching ensures Run always beats Accept, which always beats Allow, regardless of DOM order.
Antigravity's agent panel runs in an isolated Chromium process (OOPIF). The injected script uses a deferred isAgentPanel() check inside scanAndClick() — verifying .react-app-container existence dynamically on each scan rather than at injection time. This avoids a race condition where the DOM is unhydrated on targetCreated.
The CDP connection validates existing sessions every heartbeat cycle (10s). If a session's MutationObserver is dead (execution context cleared by webview navigation or React hot-reload), it automatically re-injects the observer — no reconnection needed. Sessions unreachable 3 times consecutively are cleanly detached and pruned. The heartbeat also handles target discovery (replacing the removed Target.setDiscoverTargets subscription to avoid CDP conflicts with the AG browser sub-agent). (Fixes the "stops clicking after ~1 hour" bug and the "Cannot freeze array buffer views" crash.)
Expand-type buttons (e.g. browser preview "Expand") use a click-once-per-session rule: once clicked, they are permanently suppressed for that CDP session via an expandedOnce Set. This prevents the infinite overlay re-open loop where closing the expanded panel triggers a re-click. The state resets naturally when a new agent conversation starts.
Inside the agent panel, a TreeWalker searches for buttons by text content using startsWith matching with word-boundary checks to prevent false positives (e.g. accept-test.js won't match accept):
| Priority | Text | Matches |
|---|---|---|
| 1 | run |
"Run Alt+d" button ✅ (not "Always run ^" dropdown) |
| 2 | accept |
Accept button |
| 3 | always allow |
Permission prompts |
| 4 | allow this conversation |
Conversation-scoped permissions |
| 5 | allow |
Permission prompts |
| 6 | retry |
Retry prompts |
| 7 | continue |
Agent invocation limit resume |
Blocked and allowed command lists use word-boundary matching against the code block above a Run button. For example, blocking rm will block rm -rf /tmp but NOT yarn format or npm run build.
The dashboard includes a 🛡 Load Safety Presets button that bulk-imports 50+ destructive command patterns covering filesystem wipers, disk formatters, database drops, force-pushes, and fork bombs.
One-click: Open the Dashboard (📊 in status bar) → click 🛡 Load Recommended Safety Presets.
Bulk paste: The blocked/allowed inputs now support comma-separated values — paste a list and hit Enter.
📋 Manual: Copy to settings.json
Add this to your settings.json (Ctrl+Shift+P → Preferences: Open User Settings (JSON)):
"autoAcceptV2.blockedCommands": [
"rm -rf /",
"rm -rf /*",
"rm -rf ~",
"rm -rf .*",
"rm -rf .git",
"rmdir /s /q c:\\",
"rmdir /s /q d:\\",
"rd /s /q c:\\",
"rd /s /q d:\\",
"del /f /s /q c:\\",
"del /f /s /q d:\\",
"remove-item -recurse -force c:\\",
"remove-item -recurse -force d:\\",
"format c:",
"format d:",
"diskpart",
"clear-disk",
"format-volume",
"remove-partition",
"initialize-disk",
"dd if=/dev/zero",
"dd if=/dev/urandom",
"dd if=/dev/random",
"mkfs.",
"wipefs",
"shred ",
"vssadmin delete shadows",
"reg delete hk",
"chmod -r 777 /",
"chown -r root /",
"sudo su",
"su -",
"| bash",
"| sh",
"| zsh",
"| pwsh",
"invoke-expression",
"iex (",
"set-executionpolicy bypass",
"drop database",
"drop table",
"truncate table",
"db.dropdatabase()",
"docker system prune -a --volumes",
"docker volume prune",
"docker volume rm",
"git push --force",
"git push -f",
"git clean -fdx",
":(){ :|:& };:",
"shutdown ",
"stop-computer"
]On activation, the extension checks if port 9333 is open (with 9222 fallback). If not, it shows a notification with:
- Auto-Fix Shortcut (Windows) — patches
.lnkshortcuts on Desktop, Start Menu, and Taskbar - Manual Guide — links to this README
Cause: Either (a) Antigravity silently restarts its Electron process (auto-updates, memory pressure, or extension host crash) and the new process doesn't have --remote-debugging-port=9333, or (b) the webview's execution context was cleared by a navigation/hot-reload (fixed in v3.2.0 with heartbeat self-healing).
Fix: Update to v3.2.0+ — the heartbeat now auto-detects and re-injects dead observers. If it still doesn't work, close all Antigravity windows completely, then reopen from your patched shortcut.
- Toggle OFF → ON — click the status bar icon twice to restart polling
- Check the debug port — visit
http://127.0.0.1:9333/json/listin a browser. If it refuses, the debug port is dead (see above) - Check Output logs —
Ctrl+Shift+U→ dropdown →AntiGravity AutoAccept. Look for[CDP] ✓ Threadlines. If there are none, CDP can't find the agent panel
Cause: The script is matching a static text element instead of the real Run button. Short terms like run require an exact text match to limit false positives. If you still see spam, the 5-second per-element cooldown (data-aa-t) should suppress it after the first click.
Fix: Update to the latest version — this was fixed in v2.0.0.
- Run
Ctrl+Shift+P→Reload Window - Check that the VSIX was built with dependencies (the
wspackage must be included)
Commands deliberately excluded to prevent harm:
notification.acceptPrimaryAction— would auto-click destructive dialogschatEditing.acceptAllFiles— causes sidebar Outline toggling- All merge/git conflict commands — could silently pick wrong side
- All autocomplete/suggestion commands — would corrupt typing
Why does this need --remote-debugging-port?
Antigravity's agent panel runs in an isolated Chromium process. The VS Code Extension API cannot see or interact with the Run/Accept/Allow buttons inside it — they're React UI elements with no registered commands. Chrome DevTools Protocol (CDP) on a localhost port (default 9333) is the only way to reach them.
Is it safe?
- Localhost only — the port binds to
127.0.0.1, not0.0.0.0. No external machine can connect. - Fully open source — the extension finds buttons by text and clicks them. No data is read, no network requests, no telemetry.
- Standard dev workflow —
--remote-debugging-portis the same flag used by VS Code extension developers and Electron app debugging. - Shortcut patcher is scoped — the auto-fix only modifies
.lnkfiles whose target path contains "Antigravity".
MIT
