Pick up where the other left off.
Tasks, checkpoints, and a ledger both clients can read and write. Every entry records which client filed it.
- task.submit
- task.list
- task.complete
ToolsEnabled Fleet for OpenShell Work in progress · Beta
ToolsEnabled Fleet is an MCP server for the Codex and Claude Code CLIs. Run them as one team inside NVIDIA OpenShell, with a shared work record, memory and coordinated edits, in a sandbox you control.
MIT licensed engine/Linux and Windows 10 (WSL 2)/No website account
Built around the tools
you already use
01A shared way to work
Different clients shouldn’t mean starting over. Give your agents a shared record of the work, while each keeps its own provider conversation.
Tasks, checkpoints, and a ledger both clients can read and write. Every entry records which client filed it.
Shared notes that last across sessions, plus local search over files you index. Search doesn’t need a model.
Claude Code and Codex workers can delegate and report back through a bounded tree, in the same sandbox. Up to four workers per agent, three levels deep, never wider than their parent.
02Terminal first
See your agent tree. Answer an ask. Check the work record and settings. Fleet lives alongside your coding clients, in the terminal where you already work.
$ toolsenabled status sandbox te / OpenShell workspace /sandbox/work clients Claude Code + Codex work record /sandbox/.toolsenabled policy enforced by OpenShell
$ toolsenabled tree You ├── Claude worker / manager │ ├── Codex worker / implementation │ └── Claude worker / review └── Codex worker / research Bounded delegation. Reports return to parents.
$ toolsenabled ledger TASKS T4 Review the API change Claude Code T5 Add the regression test Codex OPEN ASKS A3 Which API behavior should we preserve? $ toolsenabled ledger answer A3 Keep v1 behavior
$ toolsenabled settings See each setting, its value and its source. Use settings set <id> <value> to change one. These are cooperative runtime controls. OpenShell’s policy remains the boundary.
Illustrative output · Product controls inside a shared sandbox
03Enforced by OpenShell
OpenShell enforces filesystem and network access around every agent in the sandbox. Fleet explains observed denials and submits scoped access proposals for your review.
Read-only system paths. A writable workspace inside your sandbox.
Access follows your OpenShell policy: listed programs, listed endpoints.
Agents can propose new access. OpenShell keeps approval outside the sandbox.
OpenShell is the security boundary. Fleet coordinates cooperating agents inside it; workers in one sandbox are not isolated from each other.
04Build it in your environment
The OpenShell integration is in beta. Install it with two commands into an OpenShell sandbox you already have, or build the development image from the beta source. Each official client signs in through its own flow. Fleet installs the toolsenabled command.
Beta 3 runs on Windows 10 through WSL 2 with Docker Desktop’s Linux engine; its two-hour Windows soak passed (32 rounds, 0 failures). There is no native Windows runtime. Real Codex and Claude Code sessions on Windows, and Windows 11, are not yet tested. Windows (WSL 2) setup guide; see the release notes for current results.
build.shopenshell provider profile importopenshell provider createopenshell sandbox createtoolsenabled setup --add