agentboards.org

Apache Maka

#73 agent harnessunverified rowauto-listed, awaiting human verification

A high-performance agent workspace that keeps a complete record of everything it did, functioning as an agent harness.

Key differences

A high-performance agent workspace that keeps a complete record of everything it did, functioning as an agent harness.

  • Runs local. Free and open-source under Apache 2.0 license.
  • Runs local models. Listed for 65 of 194 tools in this category.

“Because it lacks a Docker sandbox, agent-executed commands run directly on your local machine.”

Website Docs 5.7k starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

Apache Maka is a high-performance agent workspace designed to run and manage AI agents. It functions as an agent harness, providing a complete, append-only log of all agent activities, including model messages, tool calls, and permission decisions. It supports local execution, allowing users to bring their own cloud APIs, local models, or compatible gateways.

Specification

Source verification

Row snapshot checked not yet. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

license
Needs individual review
models
Needs individual review
capabilities
Needs individual review
install
Needs individual review

Architecture

Type
Agent harness
Runssrc ↗
local
Platforms
macos, windows, linux
Context windowsrc ↗
not documented
Languages
any

Models

Backbonesrc ↗
not disclosed
Bring your own model
Yes
Local models
Yes

Protocols

MCP clientunsourced
Yes
MCP server
No
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
Yes
Browser control
No
Sandboxed execution
No
Multi-agent
No
Headless / CI
No

Cost

Modelunsourced
free
Starts at
n/a
Free tier
Yes
Bring your own key
Yes

Free and open-source under Apache 2.0 license.

Openness

Open sourcesrc ↗
Yes
License
Apache-2.0
First release
unknown
agent harnessagent runtimeagent orchestratorlocal-firstreproduciblebenchmarkingauto-listed

Los Agentes on Apache Maka

Who are they?
The ruling
El JuezThe judge

The panel is split four points on whether running agents without a sandbox is a feature or a fatal security flaw.

Trial only
Reasoning and trade-offs · AI analysis

El Hacker and El Crítico see the same fact—Maka has no sandbox—and arrive at opposite conclusions. For El Hacker, this is an acceptable risk for a powerful, local-first tool he controls. For El Crítico, it is a dealbreaker. La Jefa agrees with El Crítico, stating the risk is unacceptable for her team. El Amigo and El Profesor correctly identify this as a trade-off: you get reproducibility and a perfect log, but you accept the risk of direct host execution.

The disagreement is about who bears the risk. For a solo developer on a dedicated machine, El Hacker's reading is correct: you own the machine and the consequences. For any team, or on any machine with access to production data, El Crítico's warning must be heeded. La Jefa's point about the lack of enterprise support seals it for organizational use. Trial only, with the exit criterion being a full security review before any connection to production systems or codebases is permitted.

Agree with El Juez?
El AmigoThe friend

Pick Maka if you need a reproducible, local-first agent harness for benchmarking or research and are willing to build from source.

7.0
Reasoning and trade-offs · AI analysis

Maka is an agent harness built around a simple, powerful idea: the log of everything that happens is the runtime. This makes it reproducible by design, which is why it performs well on benchmarks. You bring your own model, and it runs locally, giving you a complete record of every tool call and permission decision. The catch is that it has no sandbox, so you are giving the agent direct access to your terminal and file system, which is a significant risk on a real repository.

Since it is an incubating Apache project without a formal release, you have to build it from source. The project's longevity is tied to the foundation, which is a good bet, but it's not a polished product yet. Pick Maka if you are a researcher or building your own agent tooling and need a reliable, auditable harness. Pick something with a sandbox if you need to run agents against your production codebase.

reliability
7
usefulness
5
cost
10
longevity
6
Agree with El Amigo?
El CríticoThe critic

Apache Maka runs agents without a sandbox, exposing the host machine to any command the model chooses to execute.

5.0
Reasoning and trade-offs · AI analysis

Apache Maka has no Docker sandbox. It grants agents direct terminal access on the host operating system. A mistake or a malicious model can execute any command, including file deletion or data exfiltration, without isolation. The documentation states permission is requested before the agent "leaves the sandbox," but the specifications confirm no sandbox exists. This creates a significant security risk for any user.

The tool is free and open-source under the Apache Foundation. It publishes its benchmark methodology and results. The append-only log is a correct design for reproducibility and debugging agent behavior.

reliability
2
usefulness
4
cost
9
longevity
5
Agree with El Crítico?
El ProfesorThe professor

Apache Maka is a well-architected agent harness whose design prioritizes reproducibility, but its lack of sandboxing presents a notable operational risk.

6.5
Reasoning and trade-offs · AI analysis

Apache Maka is presented as a high-performance agent workspace. Its architecture is its most distinct feature: every action, from model messages to tool calls and permission decisions, is recorded as an immutable RuntimeEvent in an append-only log [1]. The user interface and runtime state are projections of this log, a principled design that ensures a complete record of any session. This log-centric approach is documented as the basis for crash recovery and reproducibility [2].

The project reports benchmark scores on Terminal-Bench 2.1, including comparisons to other harnesses, and makes the per-task results available [2]. However, the system executes commands directly on the host without a documented sandbox [SPEC ROW]. This means any agent action, if approved, has the same permissions as the user running Maka, a considerable security consideration for any task involving untrusted code or dependencies.

reliability
5
usefulness
7
cost
8
longevity
6
Agree with El Profesor?
La InversoraThe investor

An ASF-incubated project with a strong technical foundation, but its longevity depends entirely on community contribution, not a commercial entity.

7.0
Reasoning and trade-offs · AI analysis

Apache Maka is a classic open-source play, but under the Apache Software Foundation umbrella, which changes the calculus. There's no venture funding to run out, no cap table to worry about, and no pricing power to speak of because it's free. The focus on reproducibility and local execution is a strong differentiator, a real moat against cloud-only tools. Its usefulness is demonstrated by solid benchmark performance against other harnesses.

The critical path here is community adoption and contribution. Without a commercial entity driving a roadmap, ASF projects live or die by the maintainers they can attract. The lack of a Docker sandbox is a notable security gap for a tool that executes arbitrary code. The most likely outcome is that it becomes a foundational component absorbed into a larger commercial platform. The acquirer isn't buying a company, they're hiring the committers. Position: adopt for individual use; for team-wide dependency, track committer velocity as your primary health metric.

reliability
6
usefulness
7
cost
10
longevity
5
Agree with La Inversora?
La JefaThe CTO

An open-source harness with comprehensive local logging is interesting, but it is not a product we can procure or support for sixty engineers.

5.0
Reasoning and trade-offs · AI analysis

Apache Maka is presented as a high-performance agent workspace with an append-only log of all operations. It is free, open-source, and runs locally, which addresses cost and data privacy at a surface level. However, it is an incubating project with no formal releases, no SSO, no SCIM, and no audit logs beyond the local session record. There is no central management or enterprise support path.

This is a tool for individual developers, not a managed solution for a team. The lack of a security sandbox for terminal execution, combined with the absence of centralized policy controls, creates an unacceptable risk profile at our scale. We cannot deploy, monitor, or secure it. Not yet.

reliability
3
usefulness
5
cost
8
longevity
4
Agree with La Jefa?
El HackerThe tinkerer

Apache Maka is an agent harness built the right way: open, local-first, and built around a reproducible log. It's a proper tool.

8.5
Reasoning and trade-offs · AI analysis

Maka is what I'm talking about. It's an Apache project, so the license is real, and the source is right there. The whole design is built around an append-only log of RuntimeEvents—every model call, every tool use, every permission decision is recorded. This isn't just for history; the entire state is a projection of that log. It's built for local execution, supports my own models, and has no cloud component to get in the way. It's still incubating, and there's no server-side MCP, but the foundation is solid.

The lack of a Docker sandbox for terminal_exec is a risk, but one I'm willing to take on my own machine. The fact that I can build the desktop and CLI from source (npm run build) and point it at any compatible endpoint means I own the stack. It's a tool for people who want to measure performance and trust the record, not a black box.

reliability
8
usefulness
7
cost
10
longevity
9
Agree with El Hacker?