Agenvoy

A self-hosted harness that executes work, creates sandboxed tools, and shares them with MCP-compatible agents.

Source repo
agenvoy/Agenvoy
Stars
★ 536
Last updated
3d ago
License
AGPL-3.0
Primary language
Go

At a glance

How it runs
CLISelf-hosted serviceMCP server
Works with
Universal · cross-platformCodex · Claude Code
Cost
Free, no paid service needed
Setup effort
Low · running in minutes
You'll need
macOS or Linux; Windows via WSLA configured model providerShell / CLINetwork accessLocal filesystemMCP Server
Typical use
Developers who want an agent to search and organize local files while keeping execution under local control.
Not a fit if
  • Teams unable to meet AGPL network-source obligations or obtain a commercial license
  • Windows users who require a native installation and will not use WSL
  • Organizations unwilling to let a local agent execute commands or access files
Source review
70/100 · Some gaps

What does this agent do, and when should you use it?

Agenvoy is a Taiwan-developed AI agent harness distributed as a single Go binary that runs on the user's computer. It combines model routing, context, long-term memory, tools, schedules, sub-agents, and execution into workflows that produce file work, research, automation, and reports. Users can operate it through a TUI, an embedded web dashboard, Telegram, or Discord while watching command output in real time. It acts as both an MCP client and server, connecting to external MCP services while exposing a shared sandboxed tool library to Claude Code, Codex, and other compatible clients. The local daemon retains control of files and services, with confirmation required for sensitive paths, access outside the home directory, and restricted actions. The project is dual-licensed under AGPL-3.0 and a commercial option, so network deployments must account for source-disclosure and attribution obligations.

After receiving a request, Agenvoy breaks it into steps, selects models or sub-agents, calls tools, and combines their results. It searches local files, retrieves live information, executes commands through run_command, streams progress to the TUI and web dashboard, and creates cron schedules from natural-language requests. When no suitable tool exists, it can generate, sandbox-test, save, and later repair that tool; its built-in MCP Server then makes the resulting library available to Agenvoy, Claude Code, Codex, and other MCP clients. Its MCP Client uses the official Go SDK and supports stdio/HTTP servers, live tool refresh, and OAuth for HTTP MCP servers, with tokens stored in the operating-system keychain. The web interface also manages sessions, tools, schedules, and memory, and provides wake-word voice interaction with interruptible spoken replies. Image generation, transcription, and text-to-speech require configured providers.

  1. Developers who want an agent to search and organize local files while keeping execution under local control.
  2. Operators who need recurring stock, repository, or progress reports created from a natural-language schedule.
  3. Teams using Claude Code, Codex, and other MCP clients that want one reusable library of sandbox-tested tools.
  4. Users whose workflows lack an existing integration and want the agent to build, test, retain, and repair a tool.
  5. People who need remote access to a local agent through Telegram or Discord without exposing inbound ports.
  6. Teams routing different tasks across model tiers and delegating work to logged sub-agent sessions.

How do you install or deploy this agent?

On macOS or a Linux distribution, run the documented one-line installer:

curl -fsSL https://agenvoy.com/scripts/install.sh | bash

On Windows, open PowerShell as an administrator, list available WSL distributions, and install one:

wsl --online --list
wsl --install <distribution-name>

Restart the computer, open a WSL terminal, and run the same installer:

curl -fsSL https://agenvoy.com/scripts/install.sh | bash

For schedules on a MacBook, the documentation also recommends preventing sleep while connected to power:

sudo pmset -c sleep 0

A model provider must then be selected and configured. One documented no-subscription route is to create a free Ollama Cloud API key, choose Ollama Cloud in /model add, and add gemma4:31b; its free plan has a usage cap. The supplied material does not state the exact command used to start the daemon or perform the first launch.

How do you use this agent?

After configuring a model, start the local daemon; the exact CLI command is not included in the supplied material. Once it is running, open http://127.0.0.1:17989 to manage sessions, tools, schedules, and memory. Users can ask direct file questions such as finding last year's invoices, or request a multi-step job such as summarizing the day's GitHub commits and producing a progress report. To automate recurring work, describe the desired schedule in natural language; the agent asks where to send the result, which format to use, and when to run. Telegram and Discord access requires the corresponding bot token, after which the daemon initiates outbound connections without an inbound port or reverse proxy. Claude Code, Codex, and other clients can connect to the MCP Server for shared tools, although no copyable client configuration is included in the source material.

What are this agent's strengths and limitations?

Pros
  • One Go binary combines a local daemon, TUI, embedded web dashboard, MCP client, and MCP server.
  • It can generate, sandbox-test, retain, and repair missing tools instead of being limited to bundled integrations.
  • Claude Code, Codex, and other MCP clients can reuse the same sandboxed tool library.
  • Sensitive paths and restricted actions require confirmation, while command output remains visible in the TUI and dashboard.
  • Telegram and Discord use outbound daemon connections, avoiding inbound ports and public host exposure.
Limitations
  • The documented Windows path requires WSL; no native Windows installation is provided.
  • Capability and operating cost depend on the configured model, image, STT, TTS, and external MCP providers; the documented free Ollama Cloud plan has a cap.
  • AGPL-3.0 imposes source-disclosure requirements on network-accessible derivatives and requires visible License and Source entries unless a commercial license is obtained.
  • The source provides an installer but omits the exact daemon startup command and a complete MCP client configuration example.
  • Since v0.34.4, Telegram and Discord no longer respond to voice input with voice output by default; users must generate and send audio through STT/TTS tools.

How does this agent compare with similar options?

A conventional chat system primarily returns an answer; Agenvoy is positioned to decompose requests, call tools, work with local files, execute commands, and deliver an artifact or completed operation. Compared with independently rebuilding integrations inside Claude Code or Codex, its MCP Server offers a shared sandboxed tool library and can generate a new reusable tool when a capability is missing.

Key facts side by side with the most closely related agents.

Agent Source review Form / cost Stars Updated Language Full support on
Agenvoy This agent 70 · Some gaps CLIFree ★ 536 3d ago Go Codex · Claude Code
Echo Agent 60 · Some gaps CLIFree + model costs ★ 1.1k 1d ago Python —
Agent Swarm 47 · Major gaps Agent plugin / skillFree + model costs ★ 851 today TypeScript Codex · Claude Code
OpenAkita — Open-Source Multi-Agent AI Assistant 45 · Major gaps Desktop appFree + model costs ★ 2k 9d ago Python OpenAI API · Claude API

How does FollowAgents rate this agent?

FollowAgents source review · FARS-2.1
Some gaps
70/ 100 5-point scale 3.5 / 5
Trust 17/29
Reliability 9/14
Adaptability 14/18
Convention 14/18
Effectiveness 10/13
Verifiability 6/8
Why each dimension lost points
Trust17 / 29 · 2.9/5

The README expressly claims bubblewrap sandboxing, sensitive-path restrictions, confirmation before out-of-home access, streamed command output, and OS-keychain storage for MCP OAuth tokens. This supports ordinary handling of least privilege, confirmation, sensitive data, and visible external effects, but full marks are withheld because no corresponding implementation, complete permission matrix, network-destination inventory, or per-action approval policy is supplied. Checkpoint resumption is not evidence that file changes, installed tools, or schedules can be rolled back, so rollback is weak. Dependencies are versioned and release archives receive SHA-256 files, but no dependency audit, SBOM, vulnerability scan, artifact signature, or provenance verification is shown. Author, contributor, license, and commit attribution are visible, although the publisher is unverified and the agenvoy/Agenvoy versus pardnchiu/agenvoy namespaces leave the ownership chain less than fully clear.

Reliability9 / 14 · 3.2/5

The README, go.mod, and release workflow consistently describe a single Go binary, supported build targets, and versioned releases. The workflow also documents and guards against a prior version-stamping failure. Dependencies are pinned and Linux amd64/arm64 and macOS arm64 are built natively, but availability and degradation behavior for numerous libraries, model providers, and external services are not comprehensively documented. CI errors, live command output, and claimed repair after execution failures aid diagnosis, but runtime source and an error catalogue are absent, so comprehensive failure quality cannot be established.

Adaptability14 / 18 · 3.9/5

Intended users and scenarios—research, file work, recurring reports, shared tools, and technical operations—are concrete and comprehensive, justifying full marks for audience and scenarios. The README enumerates capabilities, platforms, MCP modes, chatbot channels, and some restrictions, but does not fully define prohibited operations, permission boundaries, or provider-specific constraints. The scheduling example asks for destination, format, and time, showing useful trigger precision; however, activation rules and false-trigger controls for tool generation, self-repair, and automatic routing remain unclear. Environment coverage includes macOS, Linux, WSL, a local port, and a Mac sleep setting, but omits native Windows, detailed Linux prerequisites, bubblewrap availability requirements, and hardware guidance.

Convention14 / 18 · 3.9/5

The README has clear sections for audiences, capabilities, examples, installation, documentation, licensing, and authorship, with strong documentation navigation and examples. Installation covers macOS, Linux, and WSL, but relies chiefly on piping a remote script into a shell; the supplied material does not expose that script or provide verification, uninstall, upgrade, or complete prerequisite instructions. Naming is recognizable but Agenvoy, agen, agenvoy/Agenvoy, and pardnchiu/agenvoy coexist. A paused voice-response flow, platform coverage, and sleep caveat are disclosed, yet there is no consolidated account of broader limitations. The complete AGPL-3.0 text, dual-licensing explanation, and section 7(b) condition justify full license marks. Release badges, dated milestones, and generated release notes provide an update path, but no complete changelog sample or compatibility policy is shown. The author and issue channel are clear, while maintenance commitments, response expectations, and verified organizational responsibility are absent.

Effectiveness10 / 13 · 3.8/5

The product is designed to return actionable results through chat, TUI, Web, files, schedules, and shared tools, supporting ordinary output usability. Most evidence is descriptive or linked demonstrations, however, with few concrete output schemas, quality criteria, or complex result samples. Sandboxed tools that can be generated once and shared across Agenvoy, Claude Code, Codex, and MCP clients offer clear marginal value over a conventional chat agent. A self-hosted single binary, tiered model selection, subscription examples, and a free option support a plausible cost benefit, but token, storage, maintenance, security-review, and service costs are not quantified.

Verifiability6 / 8 · 3.8/5

The “Validated designs” table maps many capabilities to dated commits or releases, while the release workflow concretely shows builds, version-stamp validation, packaging, and checksum creation, providing strong claim traceability. The single-binary and Go claims receive some corroboration across the README, go.mod, and workflow, and LICENSE supports the licensing claim. Most runtime safety, generation, memory, scheduling, and self-repair claims lack a second supplied source such as implementation or tests. Facts, examples, and promotional material are generally organized separately, but the statement that later adoption by others confirms the designs solve real problems is an inference presented too strongly, preventing full fact/inference separation.

Risks and how to mitigate them
  • Do not interpret local execution or the absence of inbound ports as zero data egress. Model providers, Telegram, Discord, MCP services, OAuth, and live research can all create outbound flows; review each destination, retention policy, and credential scope before enabling it.
  • The installation command pipes a remote script directly into a shell. Download and inspect it first, verify the release archive's SHA-256, and confirm that the tag, source revision, and binary version agree; the supplied evidence shows neither signatures nor reproducible-build attestations.
  • Automatic generation, self-repair, and shared tools expand the executable-code surface. Treat generated tools as untrusted, verify that bubblewrap is actually active, and restrict network, filesystem, credential, and scheduler access.
  • Checkpoint and task recovery do not imply reversible side effects. Maintain separate backups, audit records, and explicit removal procedures for file changes, installed tools, marketplace extensions, and schedules.
  • AGPL-3.0 and the README's stated section 7(b) condition may affect modified or network-service deployments. Organizations unable to satisfy source-disclosure duties should separately evaluate the commercial license.
Evidence confidence: Low Reviewed Oct 03, 2026 Reviewed revision 8fcab0a88c73
See the full review method →

FAQ

Can Agenvoy be used without paying?
Yes. It is available under AGPL-3.0, and the documentation describes a free, usage-capped Ollama Cloud option. Paid model subscriptions, APIs, external services, or a commercial license may still add costs.
Does it upload local files to a hosted service?
The dashboard is served by the user's machine and local control is emphasized. Data handling by models or external services depends on the providers configured by the user; the source does not claim that every model workflow is fully offline.
What limits risky execution?
Agenvoy can execute commands and manipulate files, but sensitive paths, access outside the home directory, and restricted actions require confirmation. The documented design also includes bubblewrap sandboxing and visible command output.
Can Claude Code and Codex share tools through it?
Yes. Its MCP Server exposes sandboxed tools to Claude Code, Codex, and other MCP-compatible clients, allowing clients to reuse existing tools or create additions to the shared library.
What licensing issue matters for a network deployment?
Under AGPL-3.0, derivatives and network-accessible services built on the software must provide corresponding source. The web interface's License and Source entries must remain prominently visible; the commercial license removes that requirement.
View on GitHub ↗ Install ↓

Compare agents like this one

The same FARS review applied across the shortlist this agent qualifies for.

Related agents