Zum Inhalt springen

External harnesses (optional)

Dieser Inhalt ist noch nicht in deiner Sprache verfügbar.

Next release (0.2) Claude Code runs as an external harness behind the policy gate (oax run --harness claude-code), verified with real runs. OpenCode is planned for 0.2, Hermes and OpenClaw for 0.3; today they are typed stubs.

Some teams already use an agent harness they like. openagentix can hand an agent to such a harness without giving up any guardrail: an adapter translates agents.md into the harness configuration, runs the harness in a sandboxed runner, and routes every tool call through the openagentix policy gate.

HarnessAdapterStatus
Claude Codeclaude-codeNext release (0.2)
OpenCodeopencodePlanned 0.2
HermeshermesRoadmap 0.3
OpenClawopenclawRoadmap 0.3
  1. The harness gets an MCP configuration with one server: the openagentix-gate proxy, authenticated with the run’s signed token.
  2. The proxy offers only the agent’s granted tools. Each call goes through the audit gate, is recorded in the audit trail, counts against the budgets and is watched by the control agent.
  3. The harness’s own tools are switched off; it can act only through the proxy.

For Claude Code this means a headless invocation along these lines:

Terminal window
claude -p "<prompt>" --output-format stream-json --verbose --model <model> \
--append-system-prompt "<instructions>" \
--mcp-config .openagentix/mcp.json --strict-mcp-config \
--permission-mode dontAsk \
--allowedTools "mcp__openagentix-gate__tickets__get_ticket,…"

with CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 set.