Ross ROSS = Recommend OSS · open-source software intelligence for agents

onecli/onecli

Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent. observed · 2026-08-28

github.com/onecli/onecli · homepage · TypeScript · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

77/100

  • Activity 99
  • Release rhythm 87
  • Longevity 12

Flags: young

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 0
  • age_days: 178
  • days_rel: 7
  • days_push: 7
  • n_releases_24m: 96

Full methodology

Adoption not part of the score

3415 stars · 206 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

OneCLI is an open-source platform that gives every employee a personal, sandboxed AI agent, with all tool calls routed through a gateway that injects scoped credentials and enforces team policy. Agents never see raw secrets, and human-in-the-loop approvals, IdP provisioning, and Slack access are built in.

Use cases

  • give every employee a secure personal AI agent
  • run AI agents without exposing API keys to the model
  • enforce a single security policy across all team agents
  • provision agents from a company identity provider
  • require human approval for sensitive agent actions
  • self-host a multi-user agent platform
  • route agent tool calls through a credential-injecting gateway

When to choose

  • you want to deploy agents across a team or company with per-person isolation
  • your compliance posture requires that agents and LLMs never hold real credentials
  • you need deterministic, network-level policy enforcement rather than prompt-based guardrails
  • you want IdP integration, audit logs, and Slack access out of the box

When to avoid

  • you are a solo user who just wants a personal agent with full machine access
  • you need a lightweight agent framework library rather than a hosted/self-hosted platform
  • you cannot run a gateway in front of your agents' network traffic

Facets

service · maturity active

agent-framework secrets-management security mcp api-gateway security developer-tools self-hosted self-hosted rust cli credential-vault sandboxed-agents human-in-the-loop team-agents policy-enforcement identity-provider slack-integration gateway-proxy sandboxing ai-agents docker nodejs web-server

5 sources

Member repositories

RepositoryRoleHealth v2
onecli/oneclimain77

For agents

markdown · JSON · MCP: product_card(name="onecli/onecli")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem