BigHugger
GH Repository · onecli

onecli

Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.

stars
3,490
30-day movement
+134/day
Related entries
60
Connections
1
secret-managementrustagent-appnodejsnode/pnpmpostgresai-agentssecurityclimcpnodesecurity-toolsvaultTypeScript

OneCLI is an open-source sandboxed agent harness designed for teams, giving each employee a secured personal agent. It is built with Rust, TypeScript, and Node.js, with Postgres and vault-based secret management, and exposes a CLI and MCP integration.

Use it when you want to give team members personal AI agents that run in a sandbox with managed secrets and security controls.

Use it to

  • Deploy sandboxed personal agents for employees
  • Manage agent secrets via vault-backed storage
  • Expose agent capabilities through MCP
  • Run and control agents from a CLI
  • Store agent state in Postgres

For Teams deploying secured personal AI agents

Role
agent-app
Language
TypeScript
Licence
Apache-2.0
Forks
228
Open issues
95
Last push
2026-09-14
Latest release
v1.0.0 · 2026-03-11
topicsai-agentssandboxingsecuritysecret-managementclimcp