Agents work best in YOLO mode!
So like any sane person I isolate them in sandboxes to get the most juice out of them, while averting possible catastrophes (like losing files, modifying system configuration / installing new software, blatant unsafe "browser use" or "computer use", actively being attacked by prompt injection, etc)
In my journey to agent isolation I tried dev containers, standalone podman containers, remote SSH hosts (rented servers or VMs), github codespaces, and local or remote micro VMs (docker sandboxes). All have pros and cons, it's nuanced.
Special mention for docker sandboxes (external link, opens in a new tab). Even though they:
- require your to login,
- are not open source,
- have unclear licensing terms,
- push you to use (and even pre-install) unrelated docker/docker engine everywhere,
- have telemetry on by default,
- have a TUI that consumes quite a large amount of CPU while doing nothing,
- and have SSH agent forwarding on by default (how can that be for such product?),
I still like it because the network proxy they bundle it with for traffic control and secret injection is nice.
The next logical step for me was to try Agent Development Environments (ADEs), because it's true that once you work with agents you have a need for parallelization of tasks, and the experience is much less centered on editing text.
Orca
I started using Orca (external link, opens in a new tab), SSH'ed into my agent sandboxes. It looks cool, however I quickly noticed that the orca CLI is available to agents. The CLI let's any agent list any shell you have open in the IDE and send arbitrary commands to it
I asked for confirmation (external link, opens in a new tab) and the CTO quickly replied that it's the intended behavior.
What Orca does is simultaneously:
- enable YOLO mode for the agents you start in it,
- and give them a CLI that lets them run arbitrary commands on any shell you have open in Orca (across all projects and hosts, local to the IDE & remote)
So I uninstalled Orca
I saw someone publishing what I assume is a vibe coded repo (external link, opens in a new tab), providing docker sandbox configs for use with Orca. The tagline is "your host stays safe" in bold. Their approach doesn't work because of the orca CLI, so I made an issue (external link, opens in a new tab) to tell them. I received an AI generated reply from an AI agent of an unrelated/competing product. It's advertisement through GitHub issues. Sign of the times?
VSCode Agents window
The Agents window (external link, opens in a new tab) is a new UI by Microsoft, it's basically an ADE within VSCode.
VSCode (including Agents window) suffers from the same problem as Orca. When you SSH into an agent sandbox, agents can climb back to your VSCode instance and do things like install extensions and open arbitrary links. I wrote an article on my attempts to disable this.
All sorts of things (external link, opens in a new tab) happen behind the scenes, including a large transfer to the sandbox ("VSCode remote" resulting in gigabytes of disk usage), and automatic forwarding of your SSH agent by default (meaning, your sandboxed AI agents can then SSH as you into any other machine you have access to, with the same access rights)
Also at the time of writing, the model picker is bugged and doesn't let the user select models that are present on the agents in the sandbox. There is an open issue (external link, opens in a new tab) (it's already receiving replies in the form of large AI-generated bodies of text... sigh)
I haven't uninstalled VSCode. I still use it sometimes as a repo browser
What about Herdr?
I haven't tried Herdr yet.
I asked GPT-6: "What are the fundamental differences between herdr and tmux, considering my tmux config already supports terminal bell notifications from agent harnesses?"
It answered that I should stay with tmux, that there are no fundamental differences, and that some of Herdr's features are unreliable because it bases its agent state detection on literal terminal output as best as it can, which is flaky.
I should try anyway though. One day I will, I'm probably missing something.
Back to tmux
tmux and neovim over SSH (or mosh) is so good. These tools are old. They work very well, are versatile and stable. Add tailscale in the mix for handling ports, hostnames, DNS etc and you're golden
And they're customizable, which is becoming extremely easy with AI agents helping. Surely you can remake a light version of Herdr that you like in a few hours (minutes?), at least the part that you need. That'll come with the bonus of you understanding the tool you're using.
I'm surprised that my setup (external link, opens in a new tab) from literally 11 years ago (external link, opens in a new tab) is the best setup. Pleasantly surprised because I'm fully proficient in it, down to the muscle memory. I feel lucky even. Which is of course making me doubt myself, surely there are better ways in 2026? No? I'll keep looking just to be sure
What does it mean?
Maybe there is no interesting lesson here. It might just be that, because AIs are strong and efficient in text generation, AIs are super well suited for coding and CLI tool use, kinda by coincidence. And so, by coincidence, two things are happening at once:
- The need for a strong code editing experience disappears (what made me use VSCode in the first place) because agents do it for you,
- and tmux+neovim+ssh (this category of tools) become significantly more powerful and adapted to the era,
so it's the end of the IDE. Do we even need ADEs?
However I feel like this post tells another story. It tells the story of people burning tokens to quickly generate software that isn't that great, or not needed even, or maybe just not thought through. At minimum it's unfinished. Maybe it'll all be fine in a few months... 🤔