agent-harness
An agent fleet that runs on free inference, with tool access gated per agent.
2critical holes found by the final review, both fixed with regression tests
An OpenAI-compatible router fails over across 7 free inference providers. A scheduler runs the agents, an MCP gateway gives each agent its own tool allowlist, and a "Rule of Two" splits capabilities between them.
The final review found two critical holes: read_file could escape its root through a symlink, and the Rule of Two could be bypassed through Set.prototype.add. Both were fixed with regression tests.