Agent Swarm, an open-source "company operating system" for AI agents from Desplega Labs, resurfaced on Hacker News on October 9, 2026 with a new batch of features. The pitch: a lead agent takes in work from Slack, GitHub, email or an API, and delegates it to worker agents, such as Claude Code or Codex, each running in an isolated Docker container with shared memory and review gates. It is MIT licensed and self-hosted.
This post covers what the project says it does, how to start it, the new features its maintainer highlighted, and the questions to ask before you hand it real credentials. We have not run it ourselves, so everything below is drawn from the repository, its release notes and the maintainer's Hacker News post.
TL;DR: Agent Swarm at a glance
| Question | Answer |
|---|---|
| What is it? | A self-hosted system where a lead agent delegates to worker agents |
| License | MIT |
| Who builds it? | Desplega Labs |
| Workers | Claude Code, Codex, pi, opencode, Cursor, Amp, Grok, Devin, ACP agents |
| Where do workers run? | Isolated Docker containers |
| Inputs | Slack, GitHub, GitLab, email, issue trackers, API and CLI |
| Latest release seen | v1.167.0, October 9, 2026 |
| Scale signals | About 874 stars, 116 forks, 2,600+ commits, repo created December 2025 |
| Not to be confused with | OpenAI Swarm, per the README |
What does Agent Swarm do?
The README describes an architecture in four parts. Work arrives from Slack, GitHub or GitLab, email or the API. A lead agent plans and delegates. Workers in Docker containers do the tasks, reading from and writing to a persistent "brain" of memory with vector search and an identity layer such as SOUL and CLAUDE.md files. Output ships as pull requests, Slack replies or email replies.
Feature highlights from the README include schema-validated task results for callers that need structured JSON, deferred tasks that wake when watched tasks finish or a deadline arrives, workflows and schedules for recurring work, inline tool-result images in task logs, dashboard file attachments, and real-time rooms for shared page state. Memory persists across sessions with citation ratings and self-rating hints on by default.
A notable design choice is harness agnosticism: instead of tying you to one agent runtime, the lead hands work to whichever harness you configure. That makes it a layer above tools like Claude Code rather than a replacement for them.
Conductor illustration for Agent Swarm lead agent orchestrating a group of worker agents
What did the maintainer say on Hacker News?
The post on Hacker News was shared by tarasyarema, who says the team has been building the swarm for almost a year and is making it open source (MIT) and harness agnostic. In their comment they list recent additions, which they describe as: scripts that give a safe, code-mode-like experience; an integration with agent-fs, described as something like a Google Drive rebuilt for agents and also MIT; pages and apps, which they describe as artifacts; and extensions, which the README says are trusted TypeScript hooks installed as inert drafts that a trusted lead, operator or dashboard user must activate. The maintainer also says they have seen a company build a "lovable inside an app," their phrase.
The thread had only a few comments at the time we looked, one of which simply called it potentially revolutionary. That is not evidence about quality, so there is no independent hands-on report to cite yet. Treat the maintainer's list as claims.
What orchestration patterns does it document?
The README links an orchestration-patterns document that describes five patterns for multi-step agent work: delegating a task to a worker, fanning out several tasks in parallel, gating on humans, retrying, and persisting state across steps. These map onto the features above in a fairly direct way.
Delegating and fanning out are the lead agent's core job. Deferred tasks are how a lead waits: instead of blocking, it registers interest in the outcome of all or any of a set of watched tasks, or in a deadline, and wakes when one of those conditions is met. Gating on humans is the review step, where a person approves before a pull request is merged or a reply is sent. Retrying and persisting lean on the shared memory and the task log, so a worker that fails midway can be restarted without losing what earlier workers learned.
The practical takeaway for builders is that the hard part of a swarm is rarely the model call. It is deciding when work is finished, who reviews it, and where the intermediate state lives. A project that makes those choices explicit, and open to inspection in files you control, is easier to trust than one that hides them inside a hosted service.
Structured, schema-validated task results are worth singling out. If a caller such as a script or another service needs JSON back, validating the worker's output against a schema turns a free-form agent answer into something a pipeline can safely consume, and failed validation can trigger a retry rather than silently passing bad data downstream.
How do you run it?
The README offers three routes.
- Let your coding agent install it. Run
npx skills add desplega-ai/agent-swarmto give an agent the operator skill for Docker Compose or Kubernetes, or install the plugin: in Claude Code,/plugin marketplace add desplega-ai/agent-swarmthen/plugin install agent-swarm@agent-swarm. Similar commands are listed for Codex, Cursor, Gemini CLI and Factory Droid. - Docker Compose. Clone the repo, copy
.env.docker.exampleto.env, setAPI_KEY, a harness credential and all eight agent UUIDs, generate an encryption key, restrict file permissions, then bring updocker-compose.example.yml. The API listens on port 3013 with/docsand/openapi.json. - Kubernetes. An OCI Helm chart is provided.
Releases also ship as npm and bun packages (npx @desplega.ai/agent-swarm), Docker images for server, worker and dashboard, and E2B templates, according to the v1.167.0 release notes.
Sandbox box playground illustration for Agent Swarm workers isolated in Docker containers
How active and mature is it?
By the numbers from the GitHub API at the time of writing: about 874 stars, 116 forks, 15 open issues and 7 open pull requests, TypeScript, created December 19, 2025, with more than 2,600 commits. The README itself says "this repo evolves every single day," and release notes bear that out: v1.165.0 and v1.166.0 landed on October 8 and v1.167.0 on October 9.
One caution. Many of the listed pull requests in recent releases are authored by a bot account named desplega-bot. That fits a project that dogfoods its own swarm, and the maintainers seem to treat that as a feature, but it means commit counts overstate the human review the code has had. High velocity also means breaking changes are likely, so pin versions.
Where does it fit in the agent-orchestration landscape?
Multi-agent orchestration is crowded. If you want a local control plane to run several coding agents side by side, see our guide to AgentPlane. If you want persistent hosted agents inside an editor, compare Cursor Projects. For the conceptual background on why swarms behave the way they do, our swarm AGI emergence explainer is a good read.
Agent Swarm's distinguishing choice is that it is company-shaped: Slack and email in, pull requests and replies out, memory and schedules in the middle. That suits a small team that wants an always-on agent teammate, and it raises more operational questions than a single-session tool does.
What should you question before adopting it?
- Blast radius. A system wired to Slack, email, repositories and issue trackers can do real damage if a worker is manipulated by a malicious email or issue. Scope tokens to the minimum and keep production credentials out of workers.
- Review gates. The README mentions review gates; check which actions require human approval by default and which do not.
- Persistent memory. Memory that carries across sessions is useful and also a place for bad instructions to persist. Decide who can write to it and how it gets pruned.
- Cost. Each worker runs a model harness; a busy swarm multiplies token bills. Set budgets per harness.
- Data retention. The README notes, for example, that its AgentMail integration archives verified inbound deliveries and retains the archive for 30 days, including mail excluded from task routing. Read the retention notes for each integration.
- Support model. There is a cloud service and a self-hosted option; the plugin's privacy and terms links cover the website and Cloud service, while self-hosted software falls under the MIT license.
For teams that put agents in front of live systems, AgentBeam, the agent security platform from the explainx.ai team, stops AI agents before they take dangerous actions. Our agent reverse-engineering MCP server write-up shows the kind of tool access that makes this question concrete.
Agent long-term memory illustration showing persistent memory for Agent Swarm workers across sessions
A cautious first trial
If you want to evaluate it, a sensible plan is: run the Docker Compose example on a throwaway machine, connect only a test Slack workspace and a scratch repository, use a cheap model for workers, give the lead one small recurring task, and read the task logs for every action. Only after a week of boring behavior would we widen access. Pin the image tags to a specific release such as 1.167.0 rather than tracking latest.
What to watch next
Watch for independent reviews from teams that run it in production, how the maintainers handle security reports given the number of integrations, whether the harness list stays maintained as Claude Code, Codex and Cursor change, and whether the Cloud and self-hosted offerings diverge. We will update this post if notable hands-on reports appear.
Related reading
- AgentPlane: local control plane for Claude Code, Codex and Cursor
- Cursor Projects and persistent agents
- Swarm AGI and multi-agent emergence explained
- Claude Code commands complete reference
- REA reverse-engineering MCP server and agent security
- What are agent skills: complete guide
Sources: desplega-ai/agent-swarm on GitHub, v1.167.0 release notes, Agent Swarm docs, Hacker News thread.
Version numbers and star counts are accurate as of October 9, 2026 and change daily.
