External harnesses (optional)
Roadmap 0.3 Harness execution is planned for 0.3. The adapter interface exists today; the Claude Code invocation is already built and tested, the others are stubs.
Some teams already use an agent harness they like. openagentix can hand an agent to such a harness
without giving up any guardrail: an adapter translates agents.md into the harness
configuration, runs the harness in a sandboxed runner, and routes every
tool call through the openagentix policy gate.
| Harness | Adapter | Status |
|---|---|---|
| Claude Code | claude-code | Invocation built Roadmap 0.3 |
| OpenCode | opencode | Roadmap 0.3 |
| Hermes | hermes | Roadmap 0.3 |
| OpenClaw | openclaw | Roadmap 0.3 |
How the gate stays in charge
Section titled “How the gate stays in charge”- The harness gets an MCP configuration with one server: the
openagentix-gateproxy, authenticated with the run’s signed token. - The proxy offers only the agent’s granted tools. Each call goes through the audit gate, is recorded in the audit trail, counts against the budgets and is watched by the control agent.
- The harness’s own tools are switched off; it can act only through the proxy.
For Claude Code this means a headless invocation along these lines:
claude -p "<prompt>" --output-format stream-json --verbose --model <model> \ --append-system-prompt "<instructions>" \ --mcp-config .openagentix/mcp.json --strict-mcp-config \ --permission-mode dontAsk \ --allowedTools "mcp__openagentix-gate__tickets__get_ticket,…"with CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 set.