agend-sh
io.github.agend-shv1.2.14更新於 Oct 9, 2026
Persistent Linux environments for AI agents, with interactive terminals and HTTPS previews.
概覽
為 AI 助理提供持久的遠端 Linux 工作區,可執行指令、操作互動式終端機、編輯檔案並發布 HTTPS 預覽。
- 功能
- 此伺服器透過 stdio 提供 23 個工具來管理 Agend 雲端環境:列出、建立、更新、喚醒、檢視狀態與冷重置工作區。在環境內可執行前景、背景或互動式 shell 指令,對 REPL 與 TUI 傳送原始輸入,調整或中斷 PTY,並讀取或停止背景工作。它也支援寫入、上傳、下載與搬移檔案,並透過公開 HTTPS 通道暴露服務連接埠,可選用自訂網域。診斷工具可檢視磁碟、記憶體、CPU 與處理程序。
- 適用情境
- 當助理需要一台真實、長期存在的 Linux 機器,而非一次性的程式碼沙箱時適用:建置與執行專案、在工作階段之間保留狀態、操作互動式 Python REPL 或終端機應用程式,或啟動服務並分享瀏覽器預覽連結。
- 執行需求
- 需要本機 Agend CLI 執行檔(透過安裝指令碼、Homebrew 或 Docker 映像安裝)並設定為 stdio MCP 伺服器,以及具有可用環境配額的 Agend 帳號。驗證使用 AGEND_API_TOKEN 密鑰,透過 agend login 取得。需要連線至 Agend 後端的網路;企業代理可能需要設定 HTTPS_PROXY 或 HTTP_PROXY。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 agend-sh,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
A real computer for your AI agent.
Persistent Linux workspaces. Interactive terminals. Shareable previews.
Bring your favorite MCP agent. Let it get to work.
[Latest release] [CI] [MCP over stdio] [Linux, macOS, and Windows]
Quick start · Interactive terminals · Connect your agent · MCP tools · agend.sh
agend gives your agent a persistent, isolated Linux environment it can drive through MCP. It can run code, edit files, use Python REPLs and Vim, start services, and expose a preview URL. You can open a shell yourself or watch the agent's interactive terminal as it works.
Quick start
1. Install
Linux / macOS
Windows · PowerShell
Homebrew · Linux / macOS
The script installers verify the release signature and archive SHA-256 checksum. The Unix installer writes to /usr/local/bin and may ask for sudo. The Windows installer writes to %LOCALAPPDATA%\agend\bin and adds it to your user PATH. Releases support amd64 and arm64 on all three platforms.
2. Sign in
Complete authentication in the browser. Creating an account with email and a password instead:
signup prompts for a password and signs you in on success. You do not need to run login again.
3. Create your workspace
Creation selects the new environment for CLI commands. Its size follows your account's default profile. Use agend profiles to see available sizes, quotas, and sleep policies; pass a returned profile ID with agend env create --profile <profile-id> to choose another size.
4. Connect your agent
Or configure a different client:
Restart or reload your client's MCP integration, then try this prompt:
Use agend's
list_environmentsto findmy-workspace. Start an interactive Python REPL there, calculate 6 × 7, then exit the REPL.
Your agent discovers the environment and drives it with MCP tools. An Agend account and available environment quota are required; the CLI alone does not provision a free local machine.
agend-sh is listed in the official MCP Registry
as io.github.agend-sh/agend-sh. For Docker-based installation, see the
container package and connection guide.
Also available on Smithery.
For clients that support MCPB extensions, see the bundle guide.
Interactive terminals
The terminal can report that it entered an input wait. That gives the agent process feedback while it drives a REPL or terminal app.
For example, call shell_exec with:
A response can look like this:
Continue through shell_send_raw:
Then send exit()\n through shell_send_raw to close Python.
Reading the response
The input-wait signal is an event, not a persistent state query or a guarantee that an application or service is ready. It depends on support in the environment's guest stack.
For REPLs and TUIs, set interactive: true and use shell_send_raw for subsequent input. Include \n when you want Enter. Use shell_resize when the viewport changes. Quit through the app's own command, or use shell_interrupt to close the session. One interactive session can be active per environment; finish it before starting another shell_exec.
An interactive process stays alive between tool calls and is not killed when its response collection times out. After a completed tool response, disconnecting the MCP client does not itself stop the process: reconnect to the same environment to continue. Environment sleep, a crash, or a cold reset can affect its lifetime.
Watch your agent work
Watch mirrors the selected environment's interactive session, replays retained output, and follows new updates. It sends no input to the remote process. Press q or Ctrl+C to stop watching; the agent's session continues.
For a screen recording:
Match your terminal's size to the remote session for an accurate display. Watch follows output collected by the agent's tool calls; it does not poll the guest for output between those calls. It shows interactive sessions, not ordinary command output or background-task logs.
Want to work in the environment yourself?
This opens a live terminal with keyboard input and terminal resizing. Run exit to close the shell. It requires a terminal on stdin and uses the same single interactive-session slot as MCP, so close the agent's interactive app first.
Share a browser preview
Have your agent start a service using shell_exec:
Create /home/agend-user/readme-demo and put your demo files there first. Bind the service to 0.0.0.0 so the tunnel can reach it.
Then call port_expose:
The response contains a public HTTPS URL. Allow time for the tunnel and DNS to become reachable. port_list shows active exposures; port_unexpose removes one. Exposing a port makes that service reachable from the internet.
For your own Cloudflare-managed domain, register its zone with agend domain add example.com, then pass domain: "app.example.com" to port_expose. Registration prompts for a Cloudflare API token with Zone:DNS:Edit, Zone:Zone:Read, and Account:Cloudflare Tunnel:Edit permissions; scripts can supply it through AGEND_CF_TOKEN. agend domain list returns the domain IDs used by agend domain remove <domain-id>.
Connect your agent
agend config detects supported clients installed on your machine. Preview its choices before writing:
You can also select clients explicitly:
Configuration registers agend mcp as a local stdio server. The client must be able to find the installed binary; on Windows, the config writer uses its absolute path. Client-specific config paths and formats are handled by agend config.
Configure another MCP client manually
For clients that use the mcpServers JSON format:
Use the absolute binary path if the client does not inherit your shell's PATH. This is a generic example; some clients use a different schema. agend mcp reads JSON-RPC from stdin and writes protocol responses to stdout; logs go to stderr. Tool results are MCP text content, including fields such as status and input_wait.
MCP tools
The CLI exposes 23 tools. Call list_environments to discover IDs and names. Environment-specific tools require an environment argument and accept either an ID or a name. env_create, list_environments, profiles_list, and reload_config do not need one.
interactive and run_in_background are mutually exclusive. Background execution returns a task_id for the task tools.
Local paths in file_upload and file_download are confined to the MCP server's working directory, or to AGEND_LOCAL_ROOT if you set it in the server's environment. Downloads return transfer metadata; read text with shell_exec or open the downloaded local file. For large files, downloading directly inside the remote environment with curl or wget is usually faster.
CLI reference
CLI commands operate on the selected environment. Use environment IDs with agend env use and other CLI environment commands; MCP tools also resolve names.
Environments and accounts
Cold reset preserves the persistent data disk but discards guest memory, processes, sessions, and snapshots. It is a recovery operation. Creating, selecting, or executing in an environment can boot or wake it; env status is the read-only inspection path.
Shell, files, and tasks
exec supports --timeout in milliseconds (default: 30000), --head, --tail, --background, and --interactive. For a live terminal, use connect; for an agent driving a REPL or TUI, use MCP's interactive tool workflow.
For example:
file-get writes file metadata to stderr. file-put takes content, not a local filename; use MCP's file_upload for local file transfer. Both CLI file commands support --encoding text or --encoding base64; file-put also supports --create-dirs, --overwrite, and --mode.
Teams and shared environments
A team owns shared environments. A lease gives a member exclusive access until it is released or expires.
When the selected environment belongs to a team, agend mcp attempts to acquire its lease, heartbeats while connected, and releases it on normal shutdown. A lease held by another member blocks access. A hard-killed client can leave a lease until its expiry.
Updates and troubleshooting
The updater verifies the signed checksum manifest and archive before replacing the binary. An already running MCP process continues using its current version until restarted. Release builds also check automatically for updates at most once per 24 hours; set AGEND_NO_AUTOUPDATE=1 to disable those automatic checks. For a Homebrew-managed install, use brew upgrade agend.
Credentials and per-account environment selection live in ~/.config/agend/credentials.json, with owner-only file permissions on Unix. On Windows, ~ is your user profile and access is governed by Windows filesystem permissions. For scripted email/password authentication, use AGEND_PASSWORD; the CLI prompts otherwise.
Development
Requires Go 1.26.9+. From a source checkout:
make install builds and copies the binary to /usr/local/bin; that directory must be writable. On Windows, build directly with go build -o agend.exe ./cmd/agend.
CI builds, tests, and vets on Linux and Windows, with additional cross-compilation checks. Version tags trigger GoReleaser to publish Linux/macOS tarballs and Windows zip archives for amd64 and arm64, a checksum manifest, and its Sigstore signature bundle. The Homebrew tap updates through its own workflow. make release is a local Unix cross-build target, not the publishing workflow.
See the README verification report for the tested release, live checks, current issues, and coverage limits.
How it fits together
The MCP bridge resolves each environment's endpoint on demand, keeps a connection pool, and handles connection recovery. Direct CLI shell access uses the same backend. You do not need to install a separate tunnel client.
License
MIT.
來源:README.md,提交 ae7649e
工具
0版本歷史
1- v1.2.14最新Oct 9, 2026


