{"slug": "i-tried-orca-and-vscode-agents-window-i-went-back-to-tmux-shortly-after", "title": "I tried Orca and VSCode Agents window: I went back to tmux shortly after", "summary": "A developer abandoned Orca and the VSCode Agents window after finding that Orca's CLI lets any agent list every open shell in the IDE and send arbitrary commands to it, a behavior Orca's CTO confirmed as intended in GitHub issue #23835. The developer also reported that VSCode's Agents window lets sandboxed agents climb back to the host VSCode instance to install extensions and open arbitrary links, and that VSCode automatically forwards the SSH agent by default, giving sandboxed agents the user's access rights to other machines. The developer returned to tmux and documented the VSCode isolation attempts in a separate article.", "body_md": "Agents work best in YOLO mode!\n\nSo like any sane person I isolate them in sandboxes to get the most juice out of them, while averting possible catastrophes (like losing files, modifying system configuration / installing new software, blatant unsafe \"browser use\" or \"computer use\", actively being attacked by prompt injection, etc)\n\nIn my journey to agent isolation I tried dev containers, standalone podman containers, remote SSH hosts (rented servers or VMs), github codespaces, and local or remote micro VMs (docker sandboxes). All have pros and cons, it's nuanced.\n\nSpecial mention for [docker sandboxes (external link, opens in a new tab)](https://docs.docker.com/ai/sandboxes/). Even though they:\n\n1. require your to login,\n2. are not open source,\n3. have unclear licensing terms,\n4. push you to use (and even pre-install) unrelated docker/docker engine everywhere,\n5. have telemetry on by default,\n6. have a TUI that consumes quite a large amount of CPU while doing nothing,\n7. and have SSH agent forwarding on by default (how can that be for such product?),\n\nI still like it because the network proxy they bundle it with for traffic control and secret injection is nice.\n\nThe next logical step for me was to try Agent Development Environments (ADEs), because it's true that once you work with agents you have a need for parallelization of tasks, and the experience is much less centered on editing text.\n\n### Orca\n\nI started using [Orca (external link, opens in a new tab)](https://www.onorca.dev/), SSH'ed into my agent sandboxes. It looks cool, however I quickly noticed that the `orca` CLI is available to agents. The CLI let's any agent list any shell you have open in the IDE and send arbitrary commands to it\n\nI [asked for confirmation (external link, opens in a new tab)](https://github.com/stablyai/orca/issues/23835) and the CTO quickly replied that it's the intended behavior.\n\nWhat Orca does is simultaneously:\n\n1. enable YOLO mode for the agents you start in it,\n2. and give them a CLI that lets them run arbitrary commands on any shell you have open in Orca (across all projects and hosts, local to the IDE & remote)\n\nSo I uninstalled Orca\n\nI saw someone publishing what I assume is a [vibe coded repo (external link, opens in a new tab)](https://github.com/mattjohnson/orca-sbx-recipes), providing docker sandbox configs for use with Orca. The tagline is \"your host stays safe\" in bold. Their approach doesn't work because of the `orca` CLI, so [I made an issue (external link, opens in a new tab)](https://github.com/mattjohnson/orca-sbx-recipes/issues/26) to tell them. I received an AI generated reply from an AI agent of an unrelated/competing product. It's advertisement through GitHub issues. Sign of the times?\n\n### VSCode Agents window\n\nThe [Agents window (external link, opens in a new tab)](https://code.visualstudio.com/docs/agents/run/agents-window) is a new UI by Microsoft, it's basically an ADE within VSCode.\n\nVSCode (including Agents window) suffers from the same problem as Orca. When you SSH into an agent sandbox, agents can climb back to your VSCode instance and do things like install extensions and open arbitrary links. [I wrote an article on my attempts to disable this.](https://martintapia.com/blog/2026/isolation-of-agents-in-devcontainers-for-vscode)\n\n[All sorts of things (external link, opens in a new tab)](https://fly.io/blog/vscode-ssh-wtf/) happen behind the scenes, including a large transfer to the sandbox (\"VSCode remote\" resulting in gigabytes of disk usage), and automatic forwarding of your SSH agent by default (meaning, your sandboxed AI agents can then SSH as you into any other machine you have access to, with the same access rights)\n\nAlso at the time of writing, the model picker is bugged and doesn't let the user select models that are present on the agents in the sandbox. [There is an open issue (external link, opens in a new tab)](https://github.com/microsoft/vscode/issues/336904) (it's already receiving replies in the form of large AI-generated bodies of text... sigh)\n\nI haven't uninstalled VSCode. I still use it sometimes as a repo browser\n\n### What about Herdr?\n\nI haven't tried Herdr yet.\n\nI asked GPT-6: *\"What are the fundamental differences between herdr and tmux, considering my tmux config already supports terminal bell notifications from agent harnesses?\"*\n\nIt answered that I should stay with tmux, that there are no fundamental differences, and that some of Herdr's features are unreliable because it bases its agent state detection on literal terminal output as best as it can, which is flaky.\n\nI should try anyway though. One day I will, I'm probably missing something.\n\n### Back to tmux\n\ntmux and neovim over SSH (or mosh) is so good. These tools are old. They work very well, are versatile and stable. Add tailscale in the mix for handling ports, hostnames, DNS etc and you're golden\n\nAnd they're customizable, which is becoming extremely easy with AI agents helping. Surely you can remake a light version of Herdr that you like in a few hours (minutes?), at least the part that you need. That'll come with the bonus of you understanding the tool you're using.\n\nI'm surprised that [my setup (external link, opens in a new tab)](https://github.com/paps/dotfiles/) from [literally 11 years ago (external link, opens in a new tab)](https://github.com/paps/dotfiles/commit/fc08212951074d12a82ea768803e03b967744faf) is the best setup. Pleasantly surprised because I'm fully proficient in it, down to the muscle memory. I feel lucky even. Which is of course making me doubt myself, surely there are better ways in 2026? No? I'll keep looking just to be sure\n\n### What does it mean?\n\nMaybe there is no interesting lesson here. It might just be that, because AIs are strong and efficient in text generation, AIs are super well suited for coding and CLI tool use, kinda by coincidence. And so, by coincidence, two things are happening at once:\n\n1. The need for a strong code editing experience disappears (what made me use VSCode in the first place) because agents do it for you,\n2. and tmux+neovim+ssh (this category of tools) become significantly more powerful and adapted to the era,\n\nso it's the end of the IDE. Do we even need ADEs?\n\nHowever I feel like this post tells another story. It tells the story of people burning tokens to quickly generate software that isn't that great, or not needed even, or maybe just not thought through. At minimum it's unfinished. Maybe it'll all be fine in a few months... 🤔", "url": "https://wpnews.pro/news/i-tried-orca-and-vscode-agents-window-i-went-back-to-tmux-shortly-after", "canonical_source": "https://martintapia.com/blog/2026/i-tried-orca-and-vscode-agents-window-i-went-back-to-tmux-shortly-after", "published_at": "2026-09-30 05:37:06+00:00", "updated_at": "2026-09-30 05:47:59.713309+00:00", "lang": "en", "topics": ["ai-agents", "ai-tools", "developer-tools", "ai-safety"], "entities": ["Orca", "VSCode Agents window", "Microsoft", "Visual Studio Code", "tmux", "Docker", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/i-tried-orca-and-vscode-agents-window-i-went-back-to-tmux-shortly-after", "markdown": "https://wpnews.pro/news/i-tried-orca-and-vscode-agents-window-i-went-back-to-tmux-shortly-after.md", "text": "https://wpnews.pro/news/i-tried-orca-and-vscode-agents-window-i-went-back-to-tmux-shortly-after.txt", "jsonld": "https://wpnews.pro/news/i-tried-orca-and-vscode-agents-window-i-went-back-to-tmux-shortly-after.jsonld"}}