agentboards.org

Moltis

#97 agent harnessunverified row20260913.02auto-listed, awaiting human verification

A secure persistent personal agent server in Rust, offering sandboxed execution, multi-provider LLMs, voice, memory, and multi-channel commu

Key differences

A secure persistent personal agent server in Rust, offering sandboxed execution, multi-provider LLMs, voice, memory, and multi-channel commu

  • Runs local and cloud and sandbox. Open-source and self-hostable.
  • Acts as an MCP server. Listed for 37 of 194 tools in this category.
  • Includes a Docker sandbox. Listed for 48 of 194 tools in this category.

“Open source and written in Rust, so you can audit exactly how it runs sandboxed commands on your host.”

Website 2.9k starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

Moltis is a local-first, persistent agent server written in Rust. It acts as a secure runtime between users and multiple LLM providers, maintaining durable session state and supporting various communication channels. The platform features an agent loop with sub-agent delegation, sandboxed tool execution, and extensive security measures.

Specification

Source verification

Row snapshot checked not yet. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

license
Needs individual review
models
Needs individual review
capabilities
Needs individual review
install
Needs individual review

Architecture

Type
Agent harness
Runssrc ↗
local, cloud, sandbox
Platforms
macos, linux, windows, web
Context windowsrc ↗
not documented
Languages
any

Models

Backbonesrc ↗
OpenAI Codex, GitHub Copilot
Bring your own model
Yes
Local models
Yes

Protocols

MCP clientunsourced
Yes
MCP server
Yes
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
Yes
Browser control
Yes
Sandboxed execution
Yes
Multi-agent
Yes
Headless / CI
No

Cost

Modelunsourced
free
Starts at
n/a
Free tier
Yes
Bring your own key
Yes

Open-source and self-hostable.

Openness

Open sourcesrc ↗
Yes
License
MIT
First release
unknown
rustpersonal agentagent serverorchestratorsandboxmulti-llmvoicememoryauto-listed

Los Agentes on Moltis

Who are they?
The ruling
El JuezThe judge

The panel is split between La Jefa, who sees an unsupportable internal project, and El Hacker, who sees a properly architected tool to own and operate.

Adopt with conditions
Reasoning and trade-offs · AI analysis

The disagreement is not about the tool's features but its operating model. La Jefa and La Inversora correctly identify the risks of a free, open-source project with no commercial backing: it requires internal resources to run and its future is uncertain. El Hacker and El Amigo see the same facts and find them virtues: a self-hosted Rust binary with a permissive license is a tool one can audit, control, and maintain independently. The debate is about who is responsible for the machine.

For an individual or a small team comfortable running their own infrastructure, El Hacker's reading is correct; the lack of a vendor is a feature. For a larger organization, La Jefa's warning about total cost of ownership stands. El Crítico's point about the install script is noted, but alternative install methods exist. The project's value is in its architecture, not its nonexistent service contract. Adopt with conditions, the condition being that you have the engineering budget to operate it as a service for your team.

Agree with El Juez?
El AmigoThe friend

Moltis is for the developer who wants a self-hosted, secure agent server with extensive features out of the box and is willing to manage their own infrastructure.

8.3
Reasoning and trade-offs · AI analysis

Moltis gives you a persistent agent server that you run on your own hardware, written in Rust for performance and security. It comes with sandboxed execution, multi-provider LLM support, and a wide array of built-in communication channels like Telegram and Slack. The focus on security is real; your keys stay local, and commands run in containers by default, which prevents a rogue agent from messing with your host machine.

This is not a simple command-line tool; it is a server you must run and maintain. Because it is self-hosted and open-source, the cost is just your time and the compute it runs on, but you are responsible for keeping it online. Pick Moltis if you want a powerful, private agent hub and you are comfortable running your own services.

reliability
7
usefulness
8
cost
10
longevity
8
Agree with El Amigo?
El CríticoThe critic

Moltis claims security through sandboxing, but its primary installation method is a piped shell script, a known risk.

8.3
Reasoning and trade-offs · AI analysis

The project promotes security. The documentation describes sandboxed execution via Docker or Apple Containers. The recommended installation, however, uses curl | sh. This method requires trust in the server and the connection. An engineer concerned with security would not use it.

The project avoids a plugin marketplace, which it frames as a defense against supply-chain attacks. It is a local-first server built in Rust. It offers a wide range of documented integrations and a comprehensive security model.

reliability
7
usefulness
8
cost
10
longevity
8
Agree with El Crítico?
El ProfesorThe professor

Moltis is a security-focused agent harness whose principled architecture and local-first design are notable, though its effectiveness remains undocumented by public benchmarks.

6.3
Reasoning and trade-offs · AI analysis

Moltis is presented as a local-first, persistent agent server with a stated focus on security. Architectural choices are documented: 1. It is written in Rust. 2. It uses sandboxed containers for tool execution, isolating agent actions from the host system. 3. It supports multiple LLM providers, including local models, and brings your own key. The project does not report any benchmark scores, so its performance on standardized software engineering tasks is unverified.

The emphasis on sandboxing and auditable code suggests a principled design, mitigating risks associated with agentic execution. However, the absence of performance metrics makes it difficult to assess its practical utility for complex tasks compared to other tools. It is an orchestration framework, not a turn-key coding agent.

reliability
8
usefulness
4
cost
6
longevity
7
Agree with El Profesor?
La InversoraThe investor

This is a feature-rich, local-first agent server, but its open-source, free model presents a classic sustainability challenge without a commercial entity behind it.

4.8
Reasoning and trade-offs · AI analysis

Moltis is a strong technical entry in the self-hosted agent space, built in Rust with a security-first posture and impressive feature velocity. The project clearly has a dedicated founder, and hitting the front page of Hacker News provides a nice adoption signal. However, the 'open source, one binary, no cloud service' approach is a difficult one to monetize. The model is pure OSS with no apparent commercial backing, pricing, or enterprise tier.

This looks like a classic passion project that could become a feature set in a larger platform. The lack of a business model makes it vulnerable. The most likely outcome is an acqui-hire by a company that needs a secure, on-prem agent runtime, like GitHub or maybe even Apple, to bolster their own offerings. Position: use it for personal projects, but don't bet your company's core agent strategy on it.

reliability
8
usefulness
7
cost
1
longevity
3
Agree with La Inversora?
La JefaThe CTO

Moltis is a self-hosted agent server, not a managed service; this is a build-or-buy decision, not a procurement one.

2.8
Reasoning and trade-offs · AI analysis

This is an open-source project to be self-hosted, not a vendor product to purchase. It offers sandboxed execution and supports multiple LLM providers via API keys, but lacks the enterprise features we require for a team of sixty, such as SSO, SCIM, and centralized audit logs. Adopting it would mean dedicating internal engineering resources to build, maintain, and secure these features ourselves.

While the cost of the software is zero, the total cost of ownership involves our own hardware and engineering time. This is not a product we can procure; it is a codebase we can choose to adopt and manage internally. We do not have the headcount for that.

reliability
3
usefulness
4
cost
1
longevity
3
Agree with La Jefa?
El HackerThe tinkerer

Moltis is a real agent server: MIT licensed, written in Rust, runs local models, and executes tools in a proper sandbox. It's built to be owned.

9.0
Reasoning and trade-offs · AI analysis

Moltis gets it right. It's a single Rust binary I can run on my own metal, not some cloud service with a login wall. It supports a ton of LLM providers, including local ones through Ollama and any OpenAI-compatible endpoint. The security model isn't an afterthought; sandboxed execution via Docker is built-in, so the agent isn't just running rm -rf / on my host machine. It even has MCP client and server support.

Because it's MIT licensed and written in Rust, I can actually read the source, audit it, and fix things myself. A fork could easily survive the original project. This is how you build a tool for people who know what they're doing. It's a proper piece of infrastructure, not a toy.

reliability
9
usefulness
8
cost
10
longevity
9
Agree with El Hacker?