Agent tools: multiplexers, desktop environments, sandboxes, gateways and more
Agent tools are third-party software around Claude Code, Codex and Cursor: terminal multiplexers, desktop agent environments, remote clients, sandboxes, review bots and model gateways. The agents now ship worktrees, agent views and remote control themselves, so a third-party tool earns its place only with cross-agent state, a review GUI, or isolation beyond files.
Use this page when someone proposes a fourth app to manage your three agents: check the built-ins, place the tool on a shelf, and decide within a week.
What the agents already do before you install anything
Section titled “What the agents already do before you install anything”Checked against Claude Code 2.1.283 and codex-cli 0.157.1 on 2026-09-26; the Cursor column comes from Cursor’s documentation as read on 2026-08-28.
| Job | Claude Code | Codex | Cursor |
|---|---|---|---|
| A git worktree per task | claude --worktree NAME; .worktreeinclude copies gitignored files | codex --worktree or /worktree | Worktrees in Agent |
| A terminal session per worktree | --tmux (--tmux=classic for plain tmux) | — | — |
| One screen for all agents | claude agents (agent view, research preview) | codex agents | — |
| Agents cooperating | Agent teams (experimental, off by default) | Subagents | Subagents |
| Steering from another device | claude --remote-control | codex remote-control (experimental) | — |
| Diff review | /code-review | codex review | Bugbot (on pull requests) |
Cursor: agent view and remote control not documented as of 2026-08-28 (host blocked since).
Try the native worktree workflow first
Section titled “Try the native worktree workflow first”Start two agents on two tasks, each in its own checkout.
In two terminals, from the repository root:
claude --worktree feature-auth --tmuxclaude --worktree fix-invoice-rounding --tmuxEach session gets its own worktree and branch; --tmux opens it in its own tmux session (iTerm2 native panes when available), so it survives a closed terminal. List .env in .worktreeinclude to copy it into new worktrees; watch both with claude agents.
In each terminal, from the repository root:
codex --worktreeCodex starts the session in a new managed worktree; /worktree does the same inside a session. codex agents lists the sessions on the local app-server daemon.
Start each agent in a worktree from the Agent interface; the control moves between releases, so follow Cursor’s worktrees documentation.
Then prove the isolation:
git worktree listExpect the main checkout plus one line per agent, each on its own branch. A single line means an agent is editing your main checkout: stop it.
The agent hands back evidence, not a claim: a red-then-green test, three gate results and a scope you confirm with git diff --stat main.
The six shelves of agent tools
Section titled “The six shelves of agent tools”| Shelf | What it adds over the built-ins | Go deeper |
|---|---|---|
| Agent-aware multiplexers | Working, blocked or idle state across different agents; sessions that survive SSH drops; worktree managers such as Worktrunk | herdr, tmux for agent fleets |
| Desktop agent environments | A GUI diff and review board over a worktree per task | desktop environments compared |
| Remote and mobile clients | Approvals and steering from a phone, for mixed agents | agents from your phone |
| Isolation runtimes | A container, VM or cloud sandbox per agent: ports, databases and credentials isolated, not only files | sandboxes compared |
| Review bots | A second model on every pull request | AI code review bots |
| Gateways and local models | Provider switching or local inference; you lose Remote Control and /voice | gateways and local models |
Which agent tools are worth knowing in September 2026?
Section titled “Which agent tools are worth knowing in September 2026?”One or two picks per shelf; the shelf pages hold the rest and the install lines. Stars are GitHub stars read on 2026-09-26: attention, not use.
| Tool | Shelf | Pick it when | License | ★ |
|---|---|---|---|---|
| herdr | Multiplexer | Mixed agents in one terminal | Apache-2.0 | 40.8k |
| tmux | Multiplexer | No new dependency allowed | ISC | 49.5k |
| Orca | Desktop | Free, cross-platform, best-of-N | MIT | 78.4k |
| Conductor | Desktop | Mac team, review board (secondary sources) | closed | — |
| Happy | Remote | End-to-end-encrypted phone client | MIT | 23.9k |
| container-use | Isolation | Container plus branch per agent over MCP (experimental) | Apache-2.0 | 4.0k |
| CC Switch | Gateway | Switch providers across agents (site: ccswitch.io) | MIT | 136.9k |
| Ollama | Gateway | Code must stay on the machine | MIT | 181.7k |
Clear the license with legal before a tool becomes a team standard: AGPL-3.0 (Claude Squad, Coder) and GPL-3.0 (cmux) bite when you embed, host or distribute; ELv2 (Superset) forbids hosting as a service; closed-source Conductor needs a SaaS review.
Which agent tools should you not recommend?
Section titled “Which agent tools should you not recommend?”As of 2026-09-26, keep these out of a team standard: Vibe Kanban (sunsetting), Uzi (dormant since 2025-06-04), Crystal (continues as Nimbalyst), Roo Code and coder/agentapi (archived), Continue (read-only), and subscription-resale proxies such as CLIProxyAPI and sub2api (terms compliance unverified).
When should you add a third-party agent tool?
Section titled “When should you add a third-party agent tool?”A tech lead runs this before a tool enters the team setup.
-
Name the gap in one sentence, such as “we cannot see which agent waits for approval.” If a built-in covers it, configure that instead.
-
Place it on a shelf. A multiplexer does not isolate ports; a sandbox has no review board.
-
Install from the vendor’s README only. On npm,
herdris a placeholder,claude-squad,conductorandoh-my-claudecodebelong to unrelated authors, andcoderabbitis a security holding package. Comparenpm view TOOL repositorywith the README. -
Check health and license: last release, archive flag,
LICENSE. Pin and hash Python gateways: LiteLLM 1.82.7 and 1.82.8 on PyPI were malicious (2026-03-24). -
List what you lose. A gateway (
ANTHROPIC_BASE_URLother thanapi.anthropic.com) or an API key removes Claude Code’s Remote Control, so phone steering needs a third-party client;/voiceneeds a claude.ai login. -
Pilot for one week: two people, one backlog slice, unchanged CI gates. Record agent wait time, first-push CI result and review time per task.
-
Keep it only if the gap closes and the gates stay green. Native worktrees stay the fallback: this category churns fast.
How do you verify work that agent tools multiply?
Section titled “How do you verify work that agent tools multiply?”An agent tool multiplies code; it checks none of it. CI gates decide merges, a review bot reads first and a named human owns the merge (agent pull request review). git worktree list proves file isolation only, so run --dangerously-skip-permissions only in a disposable sandbox (permissions and sandboxing).
What goes wrong with agent tools, and how to recover
Section titled “What goes wrong with agent tools, and how to recover”| Symptom | Cause | Recovery |
|---|---|---|
| Two agents test against one dev server | Worktrees isolate files, not ports | A port block per worktree, or a sandbox |
| An agent in a new worktree lacks secrets | .env is gitignored | List it in .worktreeinclude |
| The standard tool stops shipping | Category churn | Fall back to native worktrees |
Where to go next with agent tools
Section titled “Where to go next with agent tools”For skills, MCP servers and plugins, see the ecosystem overview; for built-in supervisors, Claude Code agent view and Codex worktrees.