Dev & Engineering coding-agent-monitoringhook-managementmcp-managementskill-managementdesktop-consolessh-remote-agentsapi-provider-switchinglocal-first

AgentBro

Monitor, respond to, and manage local coding agents from a floating desktop console.

FollowAgents review · FARS-2.1
Recommended
78/ 100 5-point scale 3.9 / 5
1 2 3 4 5 6
Per-dimension scores and reasoning
1Trust18 / 29 · 3.1/5

The material clearly describes local Unix-socket or TCP transport, feature-triggered update checks, downloads, SSH and webhooks, and network monitoring that is off by default; CI also grants only contents: read. Approval shortcuts are disabled by default, and MCP calls expose arguments with a risk confirmation. Deductions apply because the application can install or remove CLIs, rewrite configuration, install hooks, distribute skills, and access remote hosts, while the supplied source does not establish the permission boundary and confirmation path for every operation. The default auto-approval list is mostly low-risk but includes state-changing task operations. Sensitive-data evidence includes local-first operation, redaction guidance, and a statement that Doubao conversations are not read, but credential storage, encryption, log retention, and access controls are not shown. Frozen dependency installation and restricted CI permissions help, but no vulnerability scan, dependency-update policy, or lockfile evidence is supplied. Skill revocation and hook repair provide limited recovery, with no general backup, transactional rollback, or failure-recovery design. Repository attribution, licensing, and contact paths are clear, although the publisher is unverified and no legal publishing entity is established.

2Reliability11 / 14 · 3.9/5

The README, package metadata, tests, and CI consistently describe the React/Tauri architecture, Node 20 requirement, dual-platform builds, and validation commands. Platform-path and interaction-default tests corroborate part of the implementation, justifying full self-consistency credit. Dependencies and system prerequisites are documented with build matrices, but the product also relies on external agents, marketplaces, SSH, webhooks, and platform components without a complete degradation policy. Hook Doctor, connection diagnostics, logs, configuration validation, and artifact checks indicate failure reporting, but the supplied files do not show enough concrete user-facing errors, recovery guidance, or error classification for full credit.

3Adaptability16 / 18 · 4.4/5

The intended audience and scenarios—parallel sessions, approvals, configuration management, remote development, and multiple agent ecosystems—are explicit. The material carefully separates hook integration, management scanning, and project scanning, and discloses varying interaction depth, Doubao inference limitations, the Windows MVP state, and lack of Linux support; capability boundaries are therefore thorough. Activation is generally explicit through hook installation, manually enabled monitoring, and on-demand external features, but the evidence does not show the complete event-matching, deduplication, false-trigger suppression, or webhook-trigger implementation. macOS and Windows requirements, path differences, toolchains, and limitations are documented thoroughly.

4Convention15 / 18 · 4.2/5

The documentation is well structured across installation, use cases, capabilities, support matrices, roadmap, platforms, development, contribution, release, and licensing. Homebrew, DMG, EXE, MSI, and source-development instructions are concrete. Naming is mostly consistent, but numerous aliases, two support levels, and a rapidly expanding integration surface create stability risk without a compatibility policy. Demos, procedures, and command examples are useful, though there is no consolidated FAQ or deep troubleshooting section. Windows, Linux, Doubao, and Codex Desktop limitations are specifically disclosed. Apache-2.0 is present in full and aligned with package metadata, with a clear brand-asset exception. Version 3.1.0 and release channels are identified, but no actual changelog is included. Security reporting, the dev branch, and community channels show maintenance pathways, while the responsible team, response targets, formal support entity, and long-term update commitment remain unclear.

5Effectiveness12 / 13 · 4.6/5

Floating approvals, session status, tool timelines, diffs, token information, and unified management of hooks, skills, MCP servers, plugins, and remote sessions form actionable workflows. Screenshots, usage steps, and multi-session design support strong output usability. Consolidating attention requests and configuration scattered across agents and terminals provides clear marginal value. Cost-benefit is reduced because users must install a resident desktop application and hooks, may need Node and Rust tooling for development, and must accept operational and security exposure from broad local configuration and remote-host access; Windows is also still an early MVP.

6Verifiability6 / 8 · 3.8/5

Version, dependency, build, CI, platform-path, and default interaction claims are traceable to package metadata, workflows, and tests. Many broader integration and feature claims, however, appear only in the README without corresponding implementation files or focused tests in the supplied evidence, preventing full traceability. README statements are cross-checked by tests, CI, and license metadata for several facts, but remote access, marketplaces, updates, MCP, plugins, and sensitive-data behavior lack multi-source corroboration. The material clearly distinguishes current behavior, variable coverage, best-effort inference, opt-in functionality, early-MVP limitations, unsupported platforms, and roadmap items, earning full credit for separating facts from plans and inference.

Evidence confidence: Low Reviewed Sep 22, 2026 Reviewed revision 06fe149fdfa2
Before you use it
  • The application can install or remove agents, modify configuration, install hooks, distribute skills, and connect to remote hosts; verify authorization prompts, target paths, and backups for each write operation before use.
  • Network monitoring can expose system prompts, messages, tool responses, and token data. Although disabled by default, its local storage, log retention, access control, and deletion behavior should be checked before enabling it.
  • The supplied evidence does not show dependency vulnerability scanning, lockfile contents, or a known-vulnerability response process; release artifacts and third-party dependencies still require independent review.
  • The Windows build is an unsigned early MVP that may trigger SmartScreen, lacks automatic updates, and omits some interactions; Linux has no official build.
  • Remote SSH, marketplace downloads, update checks, and webhooks create external connections; verify destinations, transmitted data, credential handling, and disable controls separately.
Review evidence [1][2][3][4][5][6][7][8][9]
See the full review method →

What does this agent do, and when should you use it?

AgentBro is a local-first desktop console for macOS and Windows that collects coding-agent sessions, tool activity, approvals, questions, and completion alerts in a Dynamic Island-style overlay. It connects to Claude Code, Codex, Gemini CLI, Cursor, GitHub Copilot, Kimi, OpenCode, and other tools through runtime hooks, while Agent Monitor exposes current and historical events. Its Agent Management workspace discovers local CLIs, desktop apps, versions, paths, and configuration, then centralizes Hooks, Skills, Skill Packs, MCP servers, and plugins. Agent Switch manages and tests API-provider configurations for Claude, Codex, Gemini, OpenCode, and Hermes, while SSH support brings remote hook events back to the desktop. The React, Rust, and Tauri application does not require cloud relaying for session events or local configuration; production downloads are available for macOS and Windows x64, although Windows remains an early MVP.

The workflow begins with Hook Doctor, which checks installed agents, executable paths, and hook status; Install All Hooks or the per-agent controls then install the required adapters. While an agent runs, Hook Server listens on a per-user local Unix socket on macOS or a local TCP endpoint on Windows, forwarding permission requests, questions, plans, tool calls, file diffs, Subagent activity, Token and Rate Limit data, results, and errors to the island and Agent Monitor. Users can approve permissions, answer questions, confirm plans, and send quick replies where the connected agent supports them. Agent Management scans CLIs, desktop apps, Skills, MCP definitions, plugins, configuration files, and project settings; it can repair hooks, distribute centrally managed Skills, apply reversible Skill Packs, inspect MCP tools, resources, prompts, and connection logs, and validate supported configuration before editing it. Agent Switch stores provider configurations, measures connectivity and latency, and changes the active provider, while the SSH module imports hosts from ~/.ssh/config and tunnels remote hook events. Optional paths include DingTalk or Feishu webhook forwarding, a local Claude Code network Inspector, and a desktop pet marketplace driven by the abpets CLI.

  1. A developer running several Claude Code, Codex, or Gemini CLI sessions can monitor progress, approval requests, and completion alerts from one desktop overlay.
  2. A terminal-heavy user whose agents frequently pause for permissions, questions, or plan approval can respond from the floating interface when the integration supports it.
  3. An individual maintaining Skills, MCP servers, plugins, and Hooks across several coding agents can distribute and diagnose them from a central library.
  4. A user switching among Claude, Codex, Gemini, OpenCode, or Hermes API-provider configurations can test connectivity and latency before activating a provider.
  5. A remote developer running coding agents on one or more servers can tunnel their hook events into the same local interface and retain host identity.
  6. An advanced Claude Code user can manually enable network monitoring and inspect prompts, messages, tools, responses, Token usage, and KV cache data locally.

What are this agent's strengths and limitations?

Pros
  • One floating interface aggregates sessions, approvals, questions, tool calls, Subagents, Token data, and completion state across multiple agents, with direct handling for supported interactions.
  • The management scope extends beyond monitoring to agent discovery, executable paths, Hooks, centralized Skills, reversible Skill Packs, MCP services, plugins, and configuration files.
  • Session events and local configuration do not need cloud relaying; network access is associated with explicitly used functions such as updates, marketplace downloads, SSH, and webhooks.
  • Local and SSH-hosted sessions share one interface while retaining host labels, which helps distinguish work across several machines.
  • The documented integrations span many coding agents and multiple API-provider configurations rather than tying the workflow to one model vendor.
Limitations
  • The Windows release is still an early MVP, with code signing, SmartScreen handling, automatic updates, and some deeper integrations still incomplete.
  • There is no official Linux release, and Linux is not in the current release plan.
  • Hook capabilities differ by agent, so event coverage and interaction depth are inconsistent; free-text replies for Codex Desktop are among the features unavailable on Windows.
  • Claude Code network monitoring is disabled by default and is the only explicitly documented deep request inspector.
  • The pet marketplace adds a Node.js 18+ and abpets CLI dependency, while source builds require the broader Node, pnpm, Rust, Cargo, and platform-specific toolchain.

How do you install or deploy this agent?

On macOS, the recommended command is: brew tap shirenchuang/tap && brew install --cask agentbro. A universal DMG is also available from GitHub Releases. Windows x64 users can install AgentBro_latest_x64-setup.exe or AgentBro_latest_x64.msi; the currently unsigned installer may trigger SmartScreen. No account or API credential is documented as a requirement for ordinary local desktop use, while SSH, webhooks, and external API providers require the relevant user-supplied connection settings. Building from source requires macOS or Windows, Node.js 20+, pnpm, the Rust toolchain, Cargo, and Tauri CLI. Run: git clone https://github.com/shirenchuang/agentbro.git; cd agentbro; pnpm install; pnpm tauri:dev.

How do you use this agent?

Open AgentBro and go to Island -> Integration. Run Hook Doctor first, then choose Install All Hooks or install only the hook for the agent you use. Restart that CLI session and launch Claude Code, Codex, Gemini CLI, or another supported agent; the island will begin showing session state, tool calls, permissions, questions, plans, and completion alerts. For centralized configuration, open Agent Management, select an agent, and use its Hooks, Skills, MCP, or plugin pages; MCP invocations display arguments and a risk confirmation before execution. For remote work, import a host from ~/.ssh/config and establish the SSH tunnel. To debug only the browser UI, run pnpm dev and open http://localhost:1423; the settings view is at http://localhost:1423/#settings.

FAQ

Must normal sessions be uploaded to a cloud service?
No. Session events and local configuration do not require cloud relaying. Hook Server uses a local Unix socket or a Windows local TCP endpoint; update checks, marketplace downloads, SSH, and webhooks contact their corresponding services only when used.
Does AgentBro replace Claude Code, Codex, or another coding agent?
No. It is a monitoring, interaction, and configuration console; the installed coding agent still performs the development work.
Does every supported agent expose the same controls?
No. Available events and interactions depend on each agent's published hook and client interfaces, so some integrations provide only partial visibility or response controls.
Is the Windows edition ready to be the primary deployment?
Its floating window, TCP hooks, path detection, Agent Management, Skills support, and installers are usable, but it remains an early MVP and its unsigned installer may trigger SmartScreen.
What safeguards are shown before an MCP tool runs?
AgentBro can inspect MCP tools, resources, prompts, and connection logs, and it displays the tool arguments and a risk confirmation before invocation.

Compare agents like this one

The same FARS review applied across the shortlist this agent qualifies for.

Related agents