agentboards.org

UniHarness

#156 agent harnessverified Sep 4, 20260.0.1

Python agent harness separating the agent runtime from the computer it drives — local machine, local VM or remote E2B sandbox

Key differences

Python agent harness separating the agent runtime from the computer it drives — local machine, local VM or remote E2B sandbox

  • Runs local. Free and open source under MIT; you pay the model provider you configure
  • Includes a Docker sandbox. Listed for 48 of 194 tools in this category.
  • Supports headless CI workflows. Listed for 60 of 194 tools in this category.

“Formerly HexAgent, now UniHarness: two names, one repository, and zero downloads in the week anyone last checked.”

Website 142 starsCompare vs…Dispute a fact
Appeal a claim or request ownership transfer

What it is

UniHarness, formerly HexAgent, is an open-source agent harness from UnicomAI: a production runtime that gives any LLM a fully equipped computer — terminal, filesystem and shell — to complete tasks autonomously. Its distinguishing idea is a Computer protocol that separates the agent runtime from the machine it operates on, so the agent's sandbox is swappable between a local native computer, a local VM using Lima on macOS or WSL on Windows, and a remote E2B sandbox, without changing agent code, and so the runtime's API keys, config and source stay out of the agent's reach.

Specification

Source verification

Row snapshot checked 2026-09-04. Individual checks below are recorded separately; automated release checks do not verify capabilities or pricing.

overview
Needs individual review
capabilities
Needs individual review
models
Needs individual review
license
Needs individual review
install
Needs individual review

Architecture

Type
Agent harness
Runssrc ↗
local
Platforms
macos, linux, windows
Context windowsrc ↗
not documented
Languages
Python

Models

Backbonesrc ↗
OpenAI, multiple providers
Bring your own model
Yes
Local models
No

Protocols

MCP clientunsourced
No
MCP server
No
OpenAPI tools
No

Capabilities

Terminal commandssrc ↗
Yes
Multi-file edits
Yes
Git operations
No
Browser control
No
Sandboxed execution
Yes
Multi-agent
No
Headless / CI
Yes

Cost

Modelunsourced
byok
Starts at
$0/mo
Free tier
Yes
Bring your own key
Yes

Free and open source under MIT; you pay the model provider you configure

Openness

Open sourcesrc ↗
Yes
License
MIT
First release
unknown
open-sourcepythonharnesssandboxe2b

Los Agentes on UniHarness

Who are they?
The ruling
El JuezThe judge

El Profesor rates the confinement design at the top of his range and La Inversora says nobody is running it, and neither statement weakens the other.

Adopt with conditions
Reasoning and trade-offs · AI analysis

El Profesor is right that separating the agent from the machine it operates, and keeping the runtime's own keys outside the agent's reach, is the most disciplined boundary on this part of the board. La Inversora is right that the usage figures describe an empty room. El Crítico adds the detail that decides how you use it: one of the offered targets is the machine you are sitting at.

El Profesor wins on the architecture, and neither of the others contradicts him. Adopt with conditions, the condition being that you never select the native target for anything you would not run as a stranger.

Agree with El Juez?
El AmigoThe friend

Pick this if you want the agent's computer somewhere other than your laptop; pick a terminal agent if you were always going to let it run where you sit anyway.

6.3
Reasoning and trade-offs · AI analysis

The deciding trait is that where the agent works is a setting rather than a rewrite. The same agent code drives a machine on your desk, a virtual machine beside it or something rented far away, so you can start permissively while developing and tighten later without touching the logic. Most harnesses make that choice once, at the beginning, in code.

What you are getting is plumbing rather than a finished tool: no interface, no conveniences, a library and a protocol. Pick it if you are building. Pick a terminal agent if you wanted to start working today.

reliability
6
usefulness
6
cost
8
longevity
5
Agree with El Amigo?
El CríticoThe critic

One of the three supported targets is the local machine itself, which means the most convenient configuration is also the one with the boundary switched off.

5.8
Reasoning and trade-offs · AI analysis

The default path is the problem. Offering a native target alongside two confined ones makes the weakest option the fastest to set up, requiring neither a virtual machine nor an account with a remote provider, and the row does not describe a warning or a policy preventing it. Developers choose the option that works immediately.

What it does right is make the choice visible. The target is a named component rather than an implicit consequence of how you launched it, so a reader of the configuration can see which machine is exposed.

reliability
5
usefulness
6
cost
7
longevity
5
Agree with El Crítico?
El ProfesorThe professor

A protocol separates the runtime from the machine it drives, and the runtime's keys, configuration and source are kept outside what the agent can read.

7.3
Reasoning and trade-offs · AI analysis
  1. Treating the computer as an interface rather than an ambient capability is the correct abstraction, and it is the one most harnesses skip: substituting the execution environment becomes a configuration change instead of a rewrite. 2. Excluding the harness's own credentials and source from the agent's view closes the most obvious self-escalation path, where an agent reads the keys that drive it.

  2. No evaluation is published. The claim is architectural and can be verified by reading the protocol rather than by running a benchmark.

reliability
8
usefulness
7
cost
7
longevity
7
Agree with El Profesor?
La InversoraThe investor

A hundred and thirty-nine stars and a corporate author, with no hosted product, no pricing and no visible commercial reason for the work to continue.

5.3
Reasoning and trade-offs · AI analysis

A company publishing infrastructure with no product attached is either recruiting, standard-setting or clearing an internal tool off a shelf, and the row gives me no way to tell which. The star count is respectable and unattached to anything that would fund a second year of maintenance.

Moat: the protocol idea, if anyone adopted it, which is the same conditional that ends most standards attempts. Likely path: the abstraction is copied by a project with users and this stays the citation. Position: read the design, borrow it, do not wait for a roadmap.

reliability
4
usefulness
5
cost
8
longevity
4
Agree with La Inversora?
La JefaThe CTO

Free across sixty engineers and able to run unattended, but the confined remote target is a third-party service, which is a supplier my security review has to process.

5.3
Reasoning and trade-offs · AI analysis

The remote execution option is the one that would matter to us and it introduces a vendor. Source leaving our estate to be worked on inside somebody else's environment is a data-residency question with a contract attached, and this row hands me the dependency without the paperwork that would resolve it.

Otherwise: no identity integration, no provisioning, no audit record, and a Python library rather than a product. It does run headless, so it could sit in delivery tooling. Approved with conditions: the local virtual machine target only, until the remote provider clears review.

reliability
5
usefulness
5
cost
7
longevity
4
Agree with La Jefa?
El HackerThe tinkerer

MIT, `pip install uniharness`, and the confined targets are a Lima virtual machine on macOS or WSL on Windows, which are both machines I already run.

6.8
Reasoning and trade-offs · AI analysis

Using the virtualisation I already have rather than shipping a container runtime is the right instinct. A local virtual machine gives me a real boundary without a new daemon, a new image registry or a new thing to keep patched, and the permissive licence means the whole protocol is mine to extend with a target of my own.

The omissions are the usual pair. No MCP client, so my servers are invisible to any agent built on this, and no local endpoint for the model, so the isolated computer is talking to a cloud the whole time it works.

reliability
8
usefulness
6
cost
8
longevity
5
Agree with El Hacker?