mrkeyoor.com_
Tue 06 Oct 15:52 UTC
AI Toolsevaluationupdated 06 Oct 2026

agency-agents-app review

Agency Agents is a desktop app for browsing specialist AI-agent personas and installing their files into coding tools such as Claude Code, Codex, Cursor, and Gemini CLI. It keeps a local ledger of what it wrote, detects changed files, and can update or remove managed installs, but it does not run the agents.

Verdict

Our Agency Agents App run installed 69 npm packages and built in 23 seconds, but it exposed no test target and npm audit reported 4 high-severity vulnerabilities. Use it if persona files have multiplied across several coding tools and you value a local ledger with drift detection. Hold off if unsigned Windows software, WSLg rendering, or renderer correctness without your own file review is a deal-breaker.

We ran it

Lab card: what happened when we ran agency-agents-appScreenshot of agency-agents-app (agencyagents.app)
Install✓ · 13s69 packages · 108 MB
Build✓ · 23s
Testsn/ano test script
Known vulns70 critical · 4 high · 0 moderate · 3 low (npm audit)
Repo598 files~39,432 lines of source · 15.9 MB · 2 CI workflows

Answers from our run

Does agency-agents-app build from source?

Dependencies installed in 13 seconds (69 packages), and the build succeeded in 23 seconds. We cloned commit 2d6bbfe into a clean Debian container with 3 CPUs and no project-specific setup.

Does agency-agents-app have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does agency-agents-app have known vulnerabilities in its dependencies?

npm audit flagged 7 known advisories in the dependency tree at the time of our run.

Who should not use agency-agents-app?

Anyone looking for an agent runtime or orchestration system: the README says the app only installs personas into other tools.

What are the alternatives to agency-agents-app?

Agency Agents catalog, Skill Mix, CC Switch. Our Agency Agents App run installed 69 npm packages and built in 23 seconds, but it exposed no test target and npm audit reported 4 high-severity vulnerabilities.

Setup4/513-second install and 23-second build, with Rust needed for dev
Docs4/5Clear install targets, boundaries, build steps, and network posture
Community3/5657 stars and 17 issues and PRs, with an October 4 push
Maturity3/5v0.3.2 fixed renderer drift; our run found no test target

Who it’s for

Developers who use several coding assistants and want one visual place to install the same persona catalog.
Teams that need user-level and project-level agent files tracked by source and rendered hashes.
People who want to inspect a persona before adding it to Claude Code, Codex, Cursor, Gemini CLI, or another supported target.
Desktop users who prefer a local Tauri app over running catalog conversion scripts by hand.

Who it’s NOT for

Anyone looking for an agent runtime or orchestration system: the README says the app only installs personas into other tools.
Security-sensitive Windows shops that require signed installers: the v0.3.2 Windows build is not code-signed and triggers SmartScreen.
Teams that assume generated files cannot drift: v0.3.2 says built-in renderers had diverged from the catalog and some tools received broken files.
WSL2 users expecting a proven desktop path: issue 89 reports a live but blank v0.3.0 window because CSS and images did not render.
Release gates that require a discoverable default test target: our sandbox found no tests script or target and skipped that step.
Users whose required tool is only recognized, not installable: the README names Aider, Windsurf, OpenClaw, Antigravity, and Kimi in that state.

Setup reality

Our Node 22 sandbox installed commit 2d6bbfe in 13 seconds, adding 69 packages and using 108 MB. The build passed in 23 seconds. No tests script or target was available, so tests were skipped. npm audit found 7 vulnerabilities: 4 high and 3 low.

Running a packaged build needs no account for the local catalog and install ledger. Optional catalog refresh, updates, and GitHub features use network access, while GitHub sign-in uses OAuth Device Flow and stores its token in the platform keychain. Building from source also needs stable Rust and platform Tauri dependencies.

macOS builds are signed and require macOS 13 or newer. Linux ships as deb, rpm, and AppImage packages. Windows supports x64 and ARM64, but the installer is not code-signed. The open WSL2 issue shows that a supported Linux package does not guarantee correct rendering through WSLg.

It installs persona files; it does not run agents

The README's supported-target table names 8 coding tools, but Agency Agents App executes none of them. It is a native control panel for the separate agency-agents catalog. You browse roles, inspect their source text, and render a chosen persona for Claude Code, Codex, Gemini CLI, GitHub Copilot, Qwen Code, Cursor, opencode, or Osaurus. The destination may be user-wide or tied to one project. Execution stays with those coding tools.

The Rust backend records 2 hashes for each managed entry: one for the source and one for the rendered file. It also stores the tool, destination, scope, and project path. The backend owns the catalog, per-tool renderer, file writes, backups, and local install ledger. Reconciliation can then call a file current, outdated, modified, removed, or foreign. This remains useful when the same persona lands in several configuration directories.

Five ledger states make outside edits visible

Agency Agents classifies installed files into 5 states by re-rendering the canonical source and comparing bytes with the installed copy. The dashboard surfaces items that need attention, while a diff view shows what changed. Modified files are backed up before destructive work, and uninstall is limited to app-managed destinations rather than an arbitrary shell command supplied by the frontend.

The workflow still has a discoverability snag. Issue 93 describes a dashboard reporting 60 outdated agents, then sending the user to a filtered workspace with no obvious update button. The update action existed under the Tools view or a bulk-selection menu, but the reporter found it only by reading source code. Drift detection is valuable only when its repair path is visible.

What happened when we ran it

We measured a 13-second install for commit 2d6bbfe in our fresh Debian sandbox. npm added 69 packages and used 108 MB on disk. The checkout contained 598 files, about 39,432 lines of source, and occupied 15.9 MB. The build completed successfully in 23 seconds under Node 22 with 3 CPUs, 8 GB of RAM, no secrets, and no elevated privileges.

There was no tests script or target for the lab runner, so the test step was skipped. Our scan also found no tests directory and no Dockerfile, though it did find 2 CI workflow files. The README documents separate Rust and frontend checks for contributors, but our measured result is narrower: the automated sandbox could build the project and could not discover a test command to run.

npm audit reported 7 known vulnerabilities, split between 4 high-severity and 3 low-severity findings. There were no critical or moderate findings in the supplied measurement. That does not prove the desktop application is exploitable. It does mean a team should inspect the affected packages and paths before granting the app write access to several agent configuration directories.

Version 0.3.2 shows why renderer parity matters

The October 3 release notes describe a correctness failure with direct user impact. Built-in renderers had drifted from the upstream catalog since mid-August, and some tools received broken files. Qwen definitions used Claude tool names, leaving 17 agents unable to read or create files or use a shell. Three descriptions produced invalid YAML, and horizontal rules disappeared from 137 agent bodies. Version 0.3.2 corrected those conversions and marked older installs outdated.

The project repaired specific output defects, and the release explains them unusually well. Those fixes also prove that a green desktop build says little about whether every generated persona works in every target. If these files control tool access, review a sample after each app update and keep the v0.3.2-or-later source catalog revision with any team-wide rollout record.

Version 0.3.2 leaves the Windows installer unsigned

The v0.3.2 release ships signed and notarized macOS packages for Apple Silicon and Intel, with macOS 13 as the floor. Linux users get deb, rpm, and AppImage downloads. Windows receives x64 and ARM64 installers, although that build is not code-signed and requires a SmartScreen bypass. For managed fleets, that difference can decide the purchase before the interface does.

Linux packaging also has an edge case worth testing. Issue 89 reports that v0.3.0 stayed alive under WSL2 and executed JavaScript, yet displayed an unstyled gray window because CSS and image assets failed to render. That report is specific to WSLg rather than ordinary Linux desktops. Still, it is enough reason to test the exact display stack before deploying the app to a Windows team through WSL.

Four outbound paths are optional and settings-gated

The README names 4 outbound paths: catalog refresh, GitHub OAuth, optional GitHub features, and signed app updates. Core browsing and install tracking are local, and the project says it includes no telemetry, crash reporter, advertising pixel, or product analytics. Tokens stay in the platform keychain and are not returned to the frontend.

GitHub showed 657 stars and 17 combined open issues and pull requests when checked on October 6, 2026. The last push was October 4, and v0.3.2 arrived the day before. That is current maintenance for a pre-1.0 desktop app. Our 23-second build says the source is approachable. The missing lab test target, 4 high-severity audit findings, and recent renderer drift say you should verify generated files before making it the only path into every developer's agent setup.

Alternatives

ProjectWhat it isPick it when
Agency Agents catalog gh↗The upstream persona catalog with its own conversion and install scripts.pick this instead when you are comfortable in a terminal and do not need a desktop ledger or drift view.
Skill MixA management layer for discovering and scoping skills across Claude Code, Codex, and Cursor.pick this instead when reusable skills, rather than role personas, are the files you need to manage.
CC Switch gh↗A desktop manager for providers and configuration across several coding-agent clients.pick this instead when switching model providers and client settings matters more than installing personas.

What people are saying

  1. [github-trending] msitarzewski/agency-agents-app

Sources

  1. Agency Agents App repository
  2. Agency Agents App README
  3. Agency Agents App v0.3.2 release
  4. Outdated-agent update issue
  5. WSL2 blank-window issue
  6. Agency Agents App security policy

More ai tools reviews

DeepGEMM · guizang-product-video-skill · nimble · localjev · jev-visual · jev-review · the whole board →