Rust · MIT · v0.8.0 · Windows / Linux / macOS

Firmware that gets verified on hardware,
not just written.

Firment is an AI engineering agent for embedded development. It takes a natural-language requirement and drives the whole loop from one conversation — write code, build with the real toolchain, flash over the probe, watch serial, analyze the ELF, and prove the physical behavior. The model doesn't get to declare "done"; the hardware does.

Linux / macOS
$ curl -fsSL https://raw.githubusercontent.com/MoRiv447/Firment/main/install.sh | sh
Windows · PowerShell
> iex (irm https://raw.githubusercontent.com/MoRiv447/Firment/main/install.ps1)
Firment TUI showing an ask_user dialog, a tool-call stack and a status bar
0
Built-in tools
0
Evidence rungs
0
Surfaces, one kernel
0
Vision models (deterministic CV)
RustSTM32ESP32probe-rssigrokFreeRTOSPlatformIOCortex-MSWO / ITMTauriNext.jsratatuitokioMQTTAnthropicOpenAI-compatible
The last mile

Embedded context is scattered across six tools.

You edit in the IDE, compile from the CLI, flash with CubeProgrammer or probe-rs, watch logs in a serial terminal, and dig through .map files to find what blew the stack. A coding assistant that only "writes the code" leaves the hardest, most error-prone part — does it build, flash, run, and behave — entirely on you. Firment is built around that last mile.

Verification, enforced

A five-rung evidence ladder the model can't fake.

"The model wrote firmware" is not the finish line. Firment enforces what counts as done with mechanical gates — and a higher rung never implies a lower one. A clean compile does not prove the physical task.

1
CodeFiles were generated or modified as intended.
2
BuildThe real toolchain accepted the project.
3
DeployFirmware was written to the target over the probe.
4
RuntimeSerial output and registers match expectations (HIL assertions).
5
PhysicalA real external effect was measured — a photo shows the LED lit, a logic-analyzer capture measures the waveform. Never the model's say-so.
What's inside

An embedded-first toolchain, plus the safety rails.

On top of a general Rust coding agent (multi-provider LLM, streaming tool calls, plan mode, subagents), Firment ships the hardware loop and the guardrails embedded engineers care about.

🧩
periph_init

Peripheral skeletons + KB

UART/GPIO/I2C/SPI/TIM/ADC HAL skeletons for STM32 & ESP32, with a knowledge base of real traps (G4 DMAMUX, H7 D-Cache coherency).

📦
elf_analyze

Compile ≠ correct

Reads flash/RAM, function sizes and real stack depth from -fstack-usage. Auto re-analyzes each edited turn; regressions above threshold block completion.

🔌
build · flash · run

Real toolchain loop

CMake/Make/Keil builds, probe-rs flashing with chip auto-detect — all wired into the agent loop.

🐞
debug · forensic

On-chip debugging

Halt, registers, memory, breakpoints, backtrace over probe-rs (no OpenOCD/GDB). One-command hard-fault post-mortem before the watchdog destroys the scene.

📷
observe · la

Physical evidence

Deterministic CV on photos (LED lit? motion? blink frequency as a range?) and logic-analyzer captures via sigrok — every verdict carries a confidence; low confidence can't pass.

🛡️
safety

Guarded by default

Write/edit/shell need approval; dangerous commands blocked; SHA-256 content-addressed edits; path sandbox; SSRF protection; transactional undo.

One kernel, three surfaces

Terminal, desktop, browser — same Rust core.

The CLI is the source of truth. The GUI shares the exact agent kernel through a unified Tool trait and session format; the web surface is a TypeScript reimplementation kept in sync via a committed tool-spec snapshot.

Firment terminal UI

CLI / TUI

A full terminal agent built on ratatui: streaming tool calls, an ask_user dialog, a live tool-call stack, plan mode, sessions and undo. This is where Firment lives day-to-day.

Rustratatuitokio
Firment desktop GUI

Desktop GUI

A Tauri client with a workbench — session tree, pin registry, ADR decisions, device bindings, flash history — driving the same kernel over IPC and an event bus.

Tauri 2ReactVite
Firment web app

Web

A browser surface you can try instantly — no install. A TypeScript reimplementation of the agent loop, synced to the Rust registry through a committed spec snapshot.

Next.jsTailwindVercel
Get started

One command, then point it at a board.

Install with the one-liner above, run firm config to pick a provider, then open a project and go. Or build from source with cargo install firment-cli · requires Rust 1.85+.