Agent Workspace · Open Source · Apache 2.0 · ★ Star on GitHub GitHub stars · Releases

Your Agent
Gets Its Own
Computer.

Auto-approve everything. The agent works inside a cell — a container or VM with its own home, tools, and desktop. Your SSH keys, other repos, and credentials aren't hidden from it; they're absent.

And inside, it has more than your machine ever gave it: real tools behind its MCP servers, a browser with your sessions, a screen it can see.

~/myproject $ cell claude
Opening Cell myproject …
✔ mounted /home/alex/myproject
✔ ~/.ssh, ~/.aws: not mounted
───────────────────────────────────────
  Claude Code
· Sonnet 4.6 · Claude Max
  /myproject
   
───────────────────────────────────────
❯ implement login form
───────────────────────────────────────
⏵⏵ auto-approve · [*.] Cell Active

The payoff

What the agent gains inside.

Built-in sandboxes subtract tools to make agents safe. devcell adds tools and stays safe.

Tools behind the MCP servers

Marketplaces install the config. devcell installs the app underneath. OpenTofu actually runs tofu plan, Inkscape actually edits the SVG — display server included. 12 servers today, each with its backing software in the image.

A desktop it can see

VNC and RDP built in. The agent opens GUI apps, clicks through what it built, and you watch live — or take over at a login screen. Linux by default; VM engines for macOS.

Your sessions, not your browser

Run cell login <site> on your host: a real browser opens, you log in, it closes. Only that site's session crosses into the cell. The agent never sees your password — and never touches your real browser's history, cache, or other logins.

The boundary

What it can't touch.

"Run this in a container, not your actual machine."

— Anthropic, Claude Code documentation

Absent, not hidden

SSH keys, other repos, host credentials — the agent can't reach them because they aren't there. It can trash its whole machine and lose nothing but the cell: rebuild in minutes. Your project is the one live mount, same as any agent setup.

Secrets in RAM only

1Password secrets resolve on the host and land on a RAM-only tmpfs at /run/secrets/. Container stops, they're gone. The LLM never sees credential values — MCP tools resolve placeholder names server-side.

One cell per client

Named cells keep engagements apart: Acme's cell has Acme's keys, shell history, and agent memory; BigCorp's has BigCorp's. Same toolchain everywhere — add a project, inherit the setup, duplicate nothing.

Project The agent sees the project dir it was launched in — the sole mount. Other repos aren't hidden, they're absent.
Cell Its own home: dotfiles, shell history, agent memory. Shared across that cell's projects, invisible to other cells.
Host Nothing outside the mount and the cell home. ~/.ssh, ~/.aws, your real home: unreachable.

Docker by default. When your threat model demands a real kernel boundary, --engine=vagrant runs the same cell in a VM.

Quickstart

  1. 1

    Install

    brew install DimmKirr/tap/devcell. Requires docker.
    Platforms: macOS, Linux, Windows(not verified yet)

  2. 2

    Run from any project

    cd my-project && cell claude. First run picks a stack, scaffolds config, and builds. Works with cell codex and cell opencode too. Claude Max, Pro, and API keys all work — it's the client you already use, inside the cell.

# macOS & Linux brew install DimmKirr/tap/devcell # run from any project directory cd ~/dev/my-project cell claude

Focused stacks, not a kitchen sink.

Every cell anchors to one devcell.toml. Each stack ships only what its MCP servers need — Playwright cells have Chromium, IaC cells have OpenTofu, GUI cells have a display server. Start with base (~1.3 GB), adopt more when the work needs it.

First run asks one question — which stack. Enter takes the default; change it anytime in devcell.toml, and the agent can install whatever else the project needs.

Everything in the image is defined in nixhome — read it, fork it, or reuse the modules standalone. Drop a .tool-versions for runtime versions, extend a stack with nix overlays. Upstream updates still merge cleanly.

Compare the six stacks →
basegonodepythonfullstackultimate
Dev essentials ✓ ✓ ✓ ✓ ✓ ✓
Go environment — ✓ — — ✓ ✓
Node.js environment — — ✓ — ✓ ✓
Python environment — — — ✓ ✓ ✓
Infra tools — ✓ — — ✓ ✓
Browser + sessions — — ✓* ✓* ✓* ✓
GUI desktop — — — — — ✓
12+ MCP servers with backing tools — — — — — ✓

* Headless only. GUI desktop (VNC/RDP) ships in the ultimate stack; other stacks add it via modules.

Need a different mix? Set stack and modules in devcell.toml. Multi-arch (amd64/arm64), published to public.ecr.aws/w1l3v2k8/devcell.

Common questions

FAQ

Ready to try it?

One command. One question on first run. Enter takes the default.

Install now ↑Read the docs