Skip to content

Agent tools: multiplexers, desktop environments, sandboxes, gateways and more

Agent tools are third-party software around Claude Code, Codex and Cursor: terminal multiplexers, desktop agent environments, remote clients, sandboxes, review bots and model gateways. The agents now ship worktrees, agent views and remote control themselves, so a third-party tool earns its place only with cross-agent state, a review GUI, or isolation beyond files.

Use this page when someone proposes a fourth app to manage your three agents: check the built-ins, place the tool on a shelf, and decide within a week.

What the agents already do before you install anything

Section titled “What the agents already do before you install anything”

Checked against Claude Code 2.1.283 and codex-cli 0.157.1 on 2026-09-26; the Cursor column comes from Cursor’s documentation as read on 2026-08-28.

JobClaude CodeCodexCursor
A git worktree per taskclaude --worktree NAME; .worktreeinclude copies gitignored filescodex --worktree or /worktreeWorktrees in Agent
A terminal session per worktree--tmux (--tmux=classic for plain tmux)——
One screen for all agentsclaude agents (agent view, research preview)codex agents—
Agents cooperatingAgent teams (experimental, off by default)SubagentsSubagents
Steering from another deviceclaude --remote-controlcodex remote-control (experimental)—
Diff review/code-reviewcodex reviewBugbot (on pull requests)

Cursor: agent view and remote control not documented as of 2026-08-28 (host blocked since).

Start two agents on two tasks, each in its own checkout.

In two terminals, from the repository root:

Terminal window
claude --worktree feature-auth --tmux
claude --worktree fix-invoice-rounding --tmux

Each session gets its own worktree and branch; --tmux opens it in its own tmux session (iTerm2 native panes when available), so it survives a closed terminal. List .env in .worktreeinclude to copy it into new worktrees; watch both with claude agents.

Then prove the isolation:

Terminal window
git worktree list

Expect the main checkout plus one line per agent, each on its own branch. A single line means an agent is editing your main checkout: stop it.

The agent hands back evidence, not a claim: a red-then-green test, three gate results and a scope you confirm with git diff --stat main.

ShelfWhat it adds over the built-insGo deeper
Agent-aware multiplexersWorking, blocked or idle state across different agents; sessions that survive SSH drops; worktree managers such as Worktrunkherdr, tmux for agent fleets
Desktop agent environmentsA GUI diff and review board over a worktree per taskdesktop environments compared
Remote and mobile clientsApprovals and steering from a phone, for mixed agentsagents from your phone
Isolation runtimesA container, VM or cloud sandbox per agent: ports, databases and credentials isolated, not only filessandboxes compared
Review botsA second model on every pull requestAI code review bots
Gateways and local modelsProvider switching or local inference; you lose Remote Control and /voicegateways and local models

Which agent tools are worth knowing in September 2026?

Section titled “Which agent tools are worth knowing in September 2026?”

One or two picks per shelf; the shelf pages hold the rest and the install lines. Stars are GitHub stars read on 2026-09-26: attention, not use.

ToolShelfPick it whenLicense★
herdrMultiplexerMixed agents in one terminalApache-2.040.8k
tmuxMultiplexerNo new dependency allowedISC49.5k
OrcaDesktopFree, cross-platform, best-of-NMIT78.4k
ConductorDesktopMac team, review board (secondary sources)closed—
HappyRemoteEnd-to-end-encrypted phone clientMIT23.9k
container-useIsolationContainer plus branch per agent over MCP (experimental)Apache-2.04.0k
CC SwitchGatewaySwitch providers across agents (site: ccswitch.io)MIT136.9k
OllamaGatewayCode must stay on the machineMIT181.7k

Clear the license with legal before a tool becomes a team standard: AGPL-3.0 (Claude Squad, Coder) and GPL-3.0 (cmux) bite when you embed, host or distribute; ELv2 (Superset) forbids hosting as a service; closed-source Conductor needs a SaaS review.

Which agent tools should you not recommend?

Section titled “Which agent tools should you not recommend?”

As of 2026-09-26, keep these out of a team standard: Vibe Kanban (sunsetting), Uzi (dormant since 2025-06-04), Crystal (continues as Nimbalyst), Roo Code and coder/agentapi (archived), Continue (read-only), and subscription-resale proxies such as CLIProxyAPI and sub2api (terms compliance unverified).

When should you add a third-party agent tool?

Section titled “When should you add a third-party agent tool?”

A tech lead runs this before a tool enters the team setup.

  1. Name the gap in one sentence, such as “we cannot see which agent waits for approval.” If a built-in covers it, configure that instead.

  2. Place it on a shelf. A multiplexer does not isolate ports; a sandbox has no review board.

  3. Install from the vendor’s README only. On npm, herdr is a placeholder, claude-squad, conductor and oh-my-claudecode belong to unrelated authors, and coderabbit is a security holding package. Compare npm view TOOL repository with the README.

  4. Check health and license: last release, archive flag, LICENSE. Pin and hash Python gateways: LiteLLM 1.82.7 and 1.82.8 on PyPI were malicious (2026-03-24).

  5. List what you lose. A gateway (ANTHROPIC_BASE_URL other than api.anthropic.com) or an API key removes Claude Code’s Remote Control, so phone steering needs a third-party client; /voice needs a claude.ai login.

  6. Pilot for one week: two people, one backlog slice, unchanged CI gates. Record agent wait time, first-push CI result and review time per task.

  7. Keep it only if the gap closes and the gates stay green. Native worktrees stay the fallback: this category churns fast.

How do you verify work that agent tools multiply?

Section titled “How do you verify work that agent tools multiply?”

An agent tool multiplies code; it checks none of it. CI gates decide merges, a review bot reads first and a named human owns the merge (agent pull request review). git worktree list proves file isolation only, so run --dangerously-skip-permissions only in a disposable sandbox (permissions and sandboxing).

What goes wrong with agent tools, and how to recover

Section titled “What goes wrong with agent tools, and how to recover”
SymptomCauseRecovery
Two agents test against one dev serverWorktrees isolate files, not portsA port block per worktree, or a sandbox
An agent in a new worktree lacks secrets.env is gitignoredList it in .worktreeinclude
The standard tool stops shippingCategory churnFall back to native worktrees

For skills, MCP servers and plugins, see the ecosystem overview; for built-in supervisors, Claude Code agent view and Codex worktrees.