
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
agent-mailbox
Advanced tools
Local-first AI agent team workbench: project-scoped MCP mailboxes for existing apps and CLIs, shared context, task handoffs and human review.
Local-first team workbench for your existing AI agent apps and CLIs.
Turn the AI agents you already use into a project team. Give them shared context, let them hand off work through a project mailbox, and review their delivery before applying changes. Your project records stay on your computer; the workbench needs no additional management LLM account.
中文 · Quick start · Release channels · Product baseline
v0.8.0 connects existing agent sessions through project mailbox MCP. Download availability and checksums are determined by the actual release page.
Keep each employee's project connection with its main session. Subagents report to their responsible agent; sharing that connection with subagents would attribute their calls to the same registered session. The system does not independently verify the internal author.
Managed CLI execution remains optional. Codex and Claude Code CLI adapters can run workbench-started tasks with project tools supplied by the runner. Local editing tasks use isolated Git worktrees and captured diffs; applying a patch to the original repository requires separate confirmation. agent-mailbox never commits or pushes automatically. This managed path is separate from connecting an existing App or CLI mailbox.
Existing-session mailbox connections currently require employees registered on the local device. Optional remote execution nodes use their existing protocol; they do not provide the new remote App mailbox connection.
Version: 0.8.0. Check the GitHub release for available files and checksums. A release is available only after its checks pass and its files are uploaded. Channel status and release gates distinguish release preparation from publication.
| Your computer | Native download |
|---|---|
| Apple Silicon Mac | Agent-Mailbox-0.8.0-darwin-arm64.zip |
| Windows x64 | Agent-Mailbox-0.8.0-win32-x64.zip |
| Linux x64 | Agent-Mailbox-0.8.0-linux-x64.tar.gz |
Extract the entire archive, then start Agent Mailbox. Native downloads include Python, Node and the locked task runtime. Keep their folders intact. macOS builds have no Developer ID signature or notarization; Windows downloads may show a reputation warning. See installation and upgrade steps. Intel Mac and Windows ARM native packages are not provided by this release.
Prefer Python? Use Python 3.10+ and a dedicated virtual environment. Use the exact version below; availability is determined by the registry:
python3 -m venv .venv
. .venv/bin/activate
python -m pip install 'agent-mailbox==0.8.0'
agent-mailbox --home ~/.agent-mailbox-v08
On Windows use py -m venv .venv and .venv\Scripts\Activate.ps1. Package availability is determined by the registry; use the exact version pin to verify installation. Python/source task execution needs Node.js 22.13+ and Prepare runtime in the UI. Our existing package is PyPI agent-mailbox. There is no TestPyPI or Homebrew distribution. The existing dsh-agent-mailbox npm package is a separate DeepSeek Harness plugin, not a workbench installer. The matching plugin release target is dsh-agent-mailbox@0.8.0; its registry publication must be checked separately; the unscoped npm name agent-mailbox belongs to another project.
Sign into Codex or Claude Code using its native login. Viewing connection checks does not run a model; starting a connection test uses native model quota. If a default model is unavailable, explicitly select a model advertised by the execution service. See the quick start for source installation and your first collaboration.
Several employee names of the same tool share that device's native login by default. Discovering a desktop app does not make it automatically controllable. v0.8 replaces the software distribution, but does not automatically migrate a v0.7 database, background service, or configuration; old MCP configuration is not compatible with the new project-tool entry points. Keep the old data backed up; do not point v0.8 at a v0.7 data home.
Detailed quick start · Beta acceptance and platform boundaries · Beta 3 verification evidence · Optional device setup · Security
Updates currently offer explicit checks, maintenance pause, and private backups; program replacement and recovery remain manual. Keep project repositories and retained task worktrees backed up separately from the database backup. Cross-device editing isolation, automatic updates, universal app control, a drag-and-drop workflow editor, and AI ERP are outside this version's implemented scope.
© 2026 NoFox and contributors · Apache-2.0 · NOTICE · Legacy MIT notices
FAQs
Local-first AI agent team workbench: project-scoped MCP mailboxes for existing apps and CLIs, shared context, task handoffs and human review.
We found that agent-mailbox demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.