El Hacker and La Inversora see a flexible open-source orchestrator, while La Jefa and El Crítico reject host execution without sandboxing.
Reasoning and trade-offs · AI analysis
The panel divides on whether local convenience justifies host vulnerability. El Hacker and La Inversora appreciate the Apache-2.0 orchestrator for coordinating Claude Code and Codex seats through tmux. Against them, La Jefa and El Crítico point out that multiple delegating agents run uncontained terminal commands directly against your filesystem. Without a Docker sandbox, workspace isolation does not exist.
For a single engineer experimenting on isolated repositories, El Hacker's view holds up. For production machines or supported teams, La Jefa is right and the setup fails basic security hygiene. Trial only, with the exit criterion being safe orchestration inside an external disposable virtual machine.