I tried Orca and VSCode Agents window: I went back to tmux shortly after A developer abandoned Orca and the VSCode Agents window after finding that Orca's CLI lets any agent list every open shell in the IDE and send arbitrary commands to it, a behavior Orca's CTO confirmed as intended in GitHub issue #23835. The developer also reported that VSCode's Agents window lets sandboxed agents climb back to the host VSCode instance to install extensions and open arbitrary links, and that VSCode automatically forwards the SSH agent by default, giving sandboxed agents the user's access rights to other machines. The developer returned to tmux and documented the VSCode isolation attempts in a separate article. Agents work best in YOLO mode So like any sane person I isolate them in sandboxes to get the most juice out of them, while averting possible catastrophes like losing files, modifying system configuration / installing new software, blatant unsafe "browser use" or "computer use", actively being attacked by prompt injection, etc In my journey to agent isolation I tried dev containers, standalone podman containers, remote SSH hosts rented servers or VMs , github codespaces, and local or remote micro VMs docker sandboxes . All have pros and cons, it's nuanced. Special mention for docker sandboxes external link, opens in a new tab https://docs.docker.com/ai/sandboxes/ . Even though they: 1. require your to login, 2. are not open source, 3. have unclear licensing terms, 4. push you to use and even pre-install unrelated docker/docker engine everywhere, 5. have telemetry on by default, 6. have a TUI that consumes quite a large amount of CPU while doing nothing, 7. and have SSH agent forwarding on by default how can that be for such product? , I still like it because the network proxy they bundle it with for traffic control and secret injection is nice. The next logical step for me was to try Agent Development Environments ADEs , because it's true that once you work with agents you have a need for parallelization of tasks, and the experience is much less centered on editing text. Orca I started using Orca external link, opens in a new tab https://www.onorca.dev/ , SSH'ed into my agent sandboxes. It looks cool, however I quickly noticed that the orca CLI is available to agents. The CLI let's any agent list any shell you have open in the IDE and send arbitrary commands to it I asked for confirmation external link, opens in a new tab https://github.com/stablyai/orca/issues/23835 and the CTO quickly replied that it's the intended behavior. What Orca does is simultaneously: 1. enable YOLO mode for the agents you start in it, 2. and give them a CLI that lets them run arbitrary commands on any shell you have open in Orca across all projects and hosts, local to the IDE & remote So I uninstalled Orca I saw someone publishing what I assume is a vibe coded repo external link, opens in a new tab https://github.com/mattjohnson/orca-sbx-recipes , providing docker sandbox configs for use with Orca. The tagline is "your host stays safe" in bold. Their approach doesn't work because of the orca CLI, so I made an issue external link, opens in a new tab https://github.com/mattjohnson/orca-sbx-recipes/issues/26 to tell them. I received an AI generated reply from an AI agent of an unrelated/competing product. It's advertisement through GitHub issues. Sign of the times? VSCode Agents window The Agents window external link, opens in a new tab https://code.visualstudio.com/docs/agents/run/agents-window is a new UI by Microsoft, it's basically an ADE within VSCode. VSCode including Agents window suffers from the same problem as Orca. When you SSH into an agent sandbox, agents can climb back to your VSCode instance and do things like install extensions and open arbitrary links. I wrote an article on my attempts to disable this. https://martintapia.com/blog/2026/isolation-of-agents-in-devcontainers-for-vscode All sorts of things external link, opens in a new tab https://fly.io/blog/vscode-ssh-wtf/ happen behind the scenes, including a large transfer to the sandbox "VSCode remote" resulting in gigabytes of disk usage , and automatic forwarding of your SSH agent by default meaning, your sandboxed AI agents can then SSH as you into any other machine you have access to, with the same access rights Also at the time of writing, the model picker is bugged and doesn't let the user select models that are present on the agents in the sandbox. There is an open issue external link, opens in a new tab https://github.com/microsoft/vscode/issues/336904 it's already receiving replies in the form of large AI-generated bodies of text... sigh I haven't uninstalled VSCode. I still use it sometimes as a repo browser What about Herdr? I haven't tried Herdr yet. I asked GPT-6: "What are the fundamental differences between herdr and tmux, considering my tmux config already supports terminal bell notifications from agent harnesses?" It answered that I should stay with tmux, that there are no fundamental differences, and that some of Herdr's features are unreliable because it bases its agent state detection on literal terminal output as best as it can, which is flaky. I should try anyway though. One day I will, I'm probably missing something. Back to tmux tmux and neovim over SSH or mosh is so good. These tools are old. They work very well, are versatile and stable. Add tailscale in the mix for handling ports, hostnames, DNS etc and you're golden And they're customizable, which is becoming extremely easy with AI agents helping. Surely you can remake a light version of Herdr that you like in a few hours minutes? , at least the part that you need. That'll come with the bonus of you understanding the tool you're using. I'm surprised that my setup external link, opens in a new tab https://github.com/paps/dotfiles/ from literally 11 years ago external link, opens in a new tab https://github.com/paps/dotfiles/commit/fc08212951074d12a82ea768803e03b967744faf is the best setup. Pleasantly surprised because I'm fully proficient in it, down to the muscle memory. I feel lucky even. Which is of course making me doubt myself, surely there are better ways in 2026? No? I'll keep looking just to be sure What does it mean? Maybe there is no interesting lesson here. It might just be that, because AIs are strong and efficient in text generation, AIs are super well suited for coding and CLI tool use, kinda by coincidence. And so, by coincidence, two things are happening at once: 1. The need for a strong code editing experience disappears what made me use VSCode in the first place because agents do it for you, 2. and tmux+neovim+ssh this category of tools become significantly more powerful and adapted to the era, so it's the end of the IDE. Do we even need ADEs? However I feel like this post tells another story. It tells the story of people burning tokens to quickly generate software that isn't that great, or not needed even, or maybe just not thought through. At minimum it's unfinished. Maybe it'll all be fine in a few months... 🤔