ToolsEnabled Fleet for OpenShell Work in progress · Beta

Many agents.
One team.
Your rules.

ToolsEnabled Fleet is an MCP server for the Codex and Claude Code CLIs. Run them as one team inside NVIDIA OpenShell, with a shared work record, memory and coordinated edits, in a sandbox you control.

MIT licensed engine/Linux and Windows 10 (WSL 2)/No website account

01A shared way to work

Switch agents.
Keep the thread.

Different clients shouldn’t mean starting over. Give your agents a shared record of the work, while each keeps its own provider conversation.

01 — Shared work

Pick up where the other left off.

Tasks, checkpoints, and a ledger both clients can read and write. Every entry records which client filed it.

  • task.submit
  • task.list
  • task.complete
02 — Persistent context

Both agents remember.

Shared notes that last across sessions, plus local search over files you index. Search doesn’t need a model.

  • memory.set
  • memory.get
  • search.query
03 — Agent teams

Your agent gets a team.

Claude Code and Codex workers can delegate and report back through a bounded tree, in the same sandbox. Up to four workers per agent, three levels deep, never wider than their parent.

  • agent.spawn
  • agent.resume
  • agent.stop
  • Claude Code worker
  • Codex worker
  • Refused: wider than its parent

02Terminal first

Stay in charge.
From the shell.

See your agent tree. Answer an ask. Check the work record and settings. Fleet lives alongside your coding clients, in the terminal where you already work.

Explore the commands
YOUR TERMINAL / YOUR WORKSPACE
$ toolsenabled status

sandbox       te / OpenShell
workspace     /sandbox/work
clients       Claude Code + Codex
work record   /sandbox/.toolsenabled
policy        enforced by OpenShell
$ toolsenabled tree

You
├── Claude worker / manager
│   ├── Codex worker / implementation
│   └── Claude worker / review
└── Codex worker / research

Bounded delegation. Reports return to parents.
$ toolsenabled ledger

TASKS
T4   Review the API change       Claude Code
T5   Add the regression test     Codex

OPEN ASKS
A3   Which API behavior should we preserve?

$ toolsenabled ledger answer A3 Keep v1 behavior
$ toolsenabled settings

See each setting, its value and its source.
Use settings set <id> <value> to change one.

These are cooperative runtime controls.
OpenShell’s policy remains the boundary.

Illustrative output · Product controls inside a shared sandbox

03Enforced by OpenShell

Let them work.
Within your limits.

OpenShell enforces filesystem and network access around every agent in the sandbox. Fleet explains observed denials and submits scoped access proposals for your review.

  • FILES

    Read-only system paths. A writable workspace inside your sandbox.

  • NETWORK

    Access follows your OpenShell policy: listed programs, listed endpoints.

  • APPROVALS

    Agents can propose new access. OpenShell keeps approval outside the sandbox.

  • Denied at the wall
  • A listed program to a listed host
  • A rule you approved

OpenShell is the security boundary. Fleet coordinates cooperating agents inside it; workers in one sandbox are not isolated from each other.

See who enforces what

04Build it in your environment

Your machine.
Your workspace.

The OpenShell integration is in beta. Install it with two commands into an OpenShell sandbox you already have, or build the development image from the beta source. Each official client signs in through its own flow. Fleet installs the toolsenabled command.

Beta 3 runs on Windows 10 through WSL 2 with Docker Desktop’s Linux engine; its two-hour Windows soak passed (32 rounds, 0 failures). There is no native Windows runtime. Real Codex and Claude Code sessions on Windows, and Windows 11, are not yet tested. Windows (WSL 2) setup guide; see the release notes for current results.

  1. Build the imagebuild.sh
  2. Import the Codex profileopenshell provider profile import
  3. Create the provideropenshell provider create
  4. Create your sandboxopenshell sandbox create
  5. Sign in and add Fleettoolsenabled setup --add

One shared workspace.
On your terms.