Agent platform

Mux

Parallel agent workspaces with persistent memory and selectable runtimes.

Status
Active
License
AGPL-3.0
Evidence
Documented + code-verifiable, 26 sources
Product record checked
2026-07-27

At a glance

An open-source agent workspace for parallel coding tasks with custom agents, nested subagents, persistent scoped memory, compaction, MCP, local or container runtimes, policy files, editor integrations, and budgeted CLI goal runs.

Good choice if

  • Parallel feature work in isolated child workspaces
  • Teams that want agent definitions and tool policy committed with the repository
  • Workflows spanning desktop, CLI, editors, Docker, and remote runtimes

Check before choosing

  • The platform has more operational concepts than a single-session coding CLI
  • The default local runtime has no filesystem or process isolation; worktrees separate files but still execute on the host
  • Docker and dev-container runtimes provide optional container isolation, while SSH security depends on the remote machine and credentials
See 3 more considerations
  • Tool hooks can block commands and run validation but are experimental; they are configurable policy rather than an OS isolation boundary
  • Browser and remote server access uses a bearer token by default, but --no-auth deliberately removes that boundary and must be limited to trusted networks
  • Browser automation is only an MCP example, not a built-in browser-control capability; anonymous usage telemetry is enabled unless disabled

Why it qualifies as a coding harness

This confirms category fit, not product quality. Every required criterion links back to first-party evidence.

Qualifies4 of 4 required criteria evidenced
  • Adaptive agent loop

    Documented

    The system repeatedly observes results and chooses the next action instead of following a fixed one-pass graph.

  • Repository tool execution

    Documented

    The system can use tools to inspect and change a repository or its execution environment.

  • Task-aware context management

    Documented

    The runtime assembles, updates, compacts, retrieves, or persists task-relevant context while work proceeds.

  • Model-independent runtime control

    Documented

    Permissions, budgets, interruption, policy, or stop controls operate outside the model's own text generation.

Membership establishes category fit only. It does not score quality, safety, autonomy, model capability, or benchmark performance. · Read the membership rule.

How it works under the hood

Seven mechanisms mapped from first-party records. These labels describe what the harness provides, not how intelligent its model is.

7/7layers documented
  • Execution & isolationSandbox availableDocumented mechanism, not a performance score.
  • Tooling & integrationsExtensible toolsDocumented mechanism, not a performance score.
  • Context & statePersistent stateDocumented mechanism, not a performance score.
  • Lifecycle & recoverySession resumeDocumented mechanism, not a performance score.
  • ObservabilityLogs/transcriptsDocumented mechanism, not a performance score.
  • VerificationTool-assistedDocumented mechanism, not a performance score.
  • Governance & permissionsPolicy controlsDocumented mechanism, not a performance score.

Public code audit

3/5public artifacts present
Security policy
Not found
CI workflow
Present at inspected commit
Automated tests
Present at inspected commit
Evaluation assets
Present at inspected commit
Contributor documentation
Not found

The v0.28.1 tree contains 879 test-like files, thirteen workflows, and fourteen Terminal-Bench adapter or analysis assets, but no root security policy or contributor guide. The benchmark tooling is project-owned and does not include a complete independently replicated model × harness × environment × budget × attempts result, so no product score is imported.

Inspect commit 8ec0e299022677a22c53f994c8d8d5ee0fe4ef22, checked 2026-07-27

Measured configurations

No benchmark run passes the full metadata admission policy for this harness yet. Missing data is not scored as zero.

Benchmark policy and all runs

Capability support

Documented first-class product support, checked against the sources below.

External tools (MCP)
DocumentedProduct-supported MCP integrationSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Local models
DocumentedLocal or self-hosted model pathSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Agent parallelism
DocumentedDelegated or parallel agent workflowSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Runs without an open UI
DocumentedNon-interactive or automation surfaceSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Browser control
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.
Isolated execution
Depends on surfaceContainer or devcontainer modes; host execution remains availableSource · checked 2026-07-27The source establishes the mechanism, not its quality or availability in every mode.
Undo file changes
Not documentedNo first-class support established by the current recordAbsence of current documentation is not proof that the capability is impossible.

Primary evidence

Each capability claim is tied to a first-party record and a verification date.

Product record checked 2026-07-27
View 18 additional sources
Product and interfaces3 sources
Execution and control6 sources
Agents, state and recovery2 sources
Automation and extensions4 sources
Enterprise and operations2 sources
Releases and public code audit1 sources

Ecosystem discovery

OpenRouter apps Discovery signal only; usage rank is not used as a quality or capability score. Observed 2026-07-27.