Firmware that gets verified on hardware,
not just written.
Firment is an AI engineering agent for embedded development. It takes a natural-language requirement and drives the whole loop from one conversation — write code, build with the real toolchain, flash over the probe, watch serial, analyze the ELF, and prove the physical behavior. The model doesn't get to declare "done"; the hardware does.
curl -fsSL https://raw.githubusercontent.com/MoRiv447/Firment/main/install.sh | sh
iex (irm https://raw.githubusercontent.com/MoRiv447/Firment/main/install.ps1)

Embedded context is scattered across six tools.
You edit in the IDE, compile from the CLI, flash with CubeProgrammer or probe-rs, watch logs in a serial terminal, and dig through .map files to find what blew the stack. A coding assistant that only "writes the code" leaves the hardest, most error-prone part — does it build, flash, run, and behave — entirely on you. Firment is built around that last mile.
A five-rung evidence ladder the model can't fake.
"The model wrote firmware" is not the finish line. Firment enforces what counts as done with mechanical gates — and a higher rung never implies a lower one. A clean compile does not prove the physical task.
An embedded-first toolchain, plus the safety rails.
On top of a general Rust coding agent (multi-provider LLM, streaming tool calls, plan mode, subagents), Firment ships the hardware loop and the guardrails embedded engineers care about.
Peripheral skeletons + KB
UART/GPIO/I2C/SPI/TIM/ADC HAL skeletons for STM32 & ESP32, with a knowledge base of real traps (G4 DMAMUX, H7 D-Cache coherency).
Compile ≠ correct
Reads flash/RAM, function sizes and real stack depth from -fstack-usage. Auto re-analyzes each edited turn; regressions above threshold block completion.
Real toolchain loop
CMake/Make/Keil builds, probe-rs flashing with chip auto-detect — all wired into the agent loop.
On-chip debugging
Halt, registers, memory, breakpoints, backtrace over probe-rs (no OpenOCD/GDB). One-command hard-fault post-mortem before the watchdog destroys the scene.
Physical evidence
Deterministic CV on photos (LED lit? motion? blink frequency as a range?) and logic-analyzer captures via sigrok — every verdict carries a confidence; low confidence can't pass.
Guarded by default
Write/edit/shell need approval; dangerous commands blocked; SHA-256 content-addressed edits; path sandbox; SSRF protection; transactional undo.
Terminal, desktop, browser — same Rust core.
The CLI is the source of truth. The GUI shares the exact agent kernel through a unified Tool trait and session format; the web surface is a TypeScript reimplementation kept in sync via a committed tool-spec snapshot.

CLI / TUI
A full terminal agent built on ratatui: streaming tool calls, an ask_user dialog, a live tool-call stack, plan mode, sessions and undo. This is where Firment lives day-to-day.

Desktop GUI
A Tauri client with a workbench — session tree, pin registry, ADR decisions, device bindings, flash history — driving the same kernel over IPC and an event bus.

Web
A browser surface you can try instantly — no install. A TypeScript reimplementation of the agent loop, synced to the Rust registry through a committed spec snapshot.
One command, then point it at a board.
Install with the one-liner above, run firm config to pick a provider, then open a project and go. Or build from source with cargo install firment-cli · requires Rust 1.85+.