You trust your AI agent with your repo. Do you trust it with your SSH keys, your ~/.aws, your dotfiles? Most people running Claude Code, Codex, or OpenCode don’t think about it until it’s too late — and by then the agent has already read everything it could reach.
Greywall (Apache 2.0, Go) is a container-free, deny-by-default sandbox built specifically for AI coding agents on Linux and macOS. No Docker, no VMs — kernel-enforced isolation via Bubblewrap namespaces, Landlock, Seccomp BPF, eBPF monitoring, and a TUN-based network capture.
Two open-source projects are fighting for the same job — “make my AI agents work together instead of in parallel silos” — but they come at it from opposite poles. hcom is a peer-to-peer messaging bus: a chatroom where every agent is an equal. ORCH is a hierarchical orchestration engine: a company where every agent has a role, a manager, and a mandatory review gate. Same problem, opposite philosophies.
Full disclosure up front: I’ve contributed to hcom’s ACP integration (so Hermes can join the bus), so I’m not neutral on that one. All numbers below were fetched from GitHub at publish time.