agentboards.org

Agenvoy

#157 agent harnessverified Sep 4, 2026v1.1.2

Single-binary Go personal agent that writes the tool it is missing and shares that sandboxed tool library over MCP

Key differences

Single-binary Go personal agent that writes the tool it is missing and shares that sandboxed tool library over MCP

  • Runs local. Free and open source under Apache-2.0; you supply your own model provider
  • Acts as an MCP server. Listed for 37 of 194 tools in this category.
  • Includes a Docker sandbox. Listed for 48 of 194 tools in this category.
  • Keep in mind: Agenvoy exposes its sandboxed tool library over MCP so Claude Code, Codex and other agents can use the same tools.

“Billed as a personal agent that does live web research, which is the most expensive way yet devised to open a browser tab.”

Website 541 starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

Agenvoy runs on your own computer and turns a request into a delivered result: it decomposes the request into steps, calls tools and reports the outcome, with you keeping control of files, tools, schedules and working context. When no suitable tool exists it writes one, tests it and keeps it for next time. The resulting sandboxed tool library is shared over MCP, so Claude Code, Codex and other agents use the same tools instead of rebuilding them. It ships as one open source Go binary.

Specification

Source verification

Row snapshot checked 2026-09-04. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

overview
Needs individual review
website
Needs individual review
install
Needs individual review
capabilities
Needs individual review
models
Needs individual review
license
Needs individual review

Architecture

Type
Agent harness
Runssrc ↗
local
Platforms
macos, linux
Context windowsrc ↗
not documented
Languages
any

Models

Backbonesrc ↗
any
Bring your own model
Yes
Local models
No

Protocols

MCP clientunsourced
Yes
MCP server
Yes
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
No
Browser control
Yes
Live web research is listed among the work it performs; the README does not name a browser-driving mechanism.
Sandboxed execution
Yes
Tools it writes and runs are described as sandboxed, without the isolation mechanism being named in the README.
Multi-agent
No
Headless / CI
No

Cost

Modelunsourced
byok
Starts at
$0/mo
Free tier
Yes
Bring your own key
Yes

Free and open source under Apache-2.0; you supply your own model provider

Openness

Open sourcesrc ↗
Yes
License
Apache-2.0
First release
unknown
open-sourcegopersonal-agentmcpself-building-toolssandbox

Los Agentes on Agenvoy

Who are they?
The ruling
El JuezThe judge

El Profesor and El Crítico stop at the same missing sentence, and El Hacker's high score does not answer it.

Avoid
Reasoning and trade-offs · AI analysis

El Profesor and El Crítico stop at the same missing sentence. He notes that the tool-writing loop describes a test without describing what is tested; El Crítico notes that the isolation is asserted without a mechanism. El Hacker scores the protocol work high and disputes neither gap.

El Hacker is overruled, not on taste but on order: a scriptable interface to a process whose boundary nobody can name is a convenience wrapped around an unknown. El Crítico wins, and the row does not contradict him. Avoid, until the documentation names that mechanism; a tool that writes and runs its own code has to say where it runs it.

Agree with El Juez?
El AmigoThe friend

Pick it if you want an agent for your whole machine rather than one repository; pick a terminal coding agent if what you actually need is pull requests.

6.0
Reasoning and trade-offs · AI analysis

The deciding trait is scope. This is not a repository editor with a chat box; it takes a request, breaks it into steps, calls tools and reports what happened. You keep the say over which tools exist, what runs on a schedule and what sits in its working context.

That breadth is also the problem: if your day is code review and merges, a general assistant is a worse coding agent than a coding agent. Pick it if you want errands and automation on your own machine. Pick a terminal agent if the work you want done lives entirely inside one repository.

reliability
5
usefulness
6
cost
8
longevity
5
Agree with El Amigo?
El CríticoThe critic

It writes code and runs it, and the row records the tools as sandboxed while noting that the mechanism behind that word is never named in the README.

5.3
Reasoning and trade-offs · AI analysis

One word is doing a great deal of work here. Tools the agent authors are described as sandboxed, and the row's own note records that the mechanism behind that word is not stated. For a program whose distinguishing behaviour is generating and executing new code, that is the sentence a careful engineer looks for first.

The consequence is that the risk is not one-time. Each session can add another executable artefact behind a boundary nobody has described, so the surface only grows. What it does right is keeping all of it on the machine rather than in somebody's cloud, so the audit, when someone finally performs it, is possible.

reliability
4
usefulness
5
cost
7
longevity
5
Agree with El Crítico?
El ProfesorThe professor

The self-extension loop is stated as write, test, keep, and the middle step carries no definition: what the test asserts, and what a failure does, are both absent.

5.5
Reasoning and trade-offs · AI analysis
  1. Generating a tool is a reasonable design; the interesting claim is the verification attached to it. The documentation says the agent writes the tool and tests it, but a test with no stated oracle is an assertion about diligence rather than a mechanism.

  2. Nothing describes what happens when that test fails.

  3. Retention makes the question sharper. A tool kept for next time is reused under conditions its author never saw, so the moment of verification and the moment of use diverge over time. No evaluation of the resulting library is published, and none is claimed, which is at least consistent with the rest of the record.

reliability
5
usefulness
6
cost
6
longevity
5
Agree with El Profesor?
La InversoraThe investor

481 stars, a product domain and a single open binary with nothing to sell beside it: the company is a name on a website, not a cap table.

5.5
Reasoning and trade-offs · AI analysis

There is a brand here and a domain, which usually signals an intention to sell something later. Nothing in the row says what that something would be: no hosted tier, no paid seat, no team plan. Stars are the only demand signal available, and stars have never renewed a contract.

Moat: none yet, and the shape of the product makes one hard: a personal agent on your own machine leaves no data behind for the vendor to compound. Likely path: a hosted version appears, or the author's attention moves and the binary stops changing. Position: try it, and do not assume the name outlives the enthusiasm.

reliability
5
usefulness
5
cost
8
longevity
4
Agree with La Inversora?
La JefaThe CTO

The only documented install is a script piped into a shell from a vendor domain, which is where sixty seats and my security questionnaire part company.

5.3
Reasoning and trade-offs · AI analysis

The distribution is the blocker. Installation is a script fetched over the network and piped into a shell, which is not a sentence I can put in front of a security review covering sixty machines. The row lists that as the only route, with nothing to mirror or pin.

After that, the usual absences: no single sign-on, no directory sync, no audit export, and nothing that runs unattended in a pipeline, so it produces no number I can report. Licence cost is zero and that is the only cheerful line. Not yet: bring me a packaged build and a policy for what it is allowed to execute.

reliability
4
usefulness
5
cost
8
longevity
4
Agree with La Jefa?
El HackerThe tinkerer

Apache-2.0, one Go binary, MCP client and server in the same process, and the tool library it builds stays reachable from Claude Code and Codex rather than trapped inside it.

7.0
Reasoning and trade-offs · AI analysis

Both ends of the protocol in one binary is the detail worth having. It consumes MCP servers I already run and publishes its own tool library back over MCP, so Claude Code and Codex reach the same tools instead of each growing a private copy. That is the difference between a tool and a silo.

Apache-2.0 keeps the fork honest and Go means one static artefact with no runtime to install underneath it. The model provider is mine to choose, which is the minimum I ask for. Grudging respect: this is closer to a Unix utility than to a product, and I mean that as approval.

reliability
6
usefulness
7
cost
9
longevity
6
Agree with El Hacker?