Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for developers and ops teams who need real browser or desktop automation with a clearer safety boundary than pointing an agent at their live machine.
Where this stands now
agent-sh/agent-workspace-linux ranks #17 of 1270 tracked Developer Tools items by composite score (8.5 against a section median of 4.9). The section currently carries 1032 Bronze, 134 Silver, 103 Gold, 1 Low Signal. RepoRadar has retained observations for this record since 2026-06-26 (99 days in the current window). Signal extremes versus the section: momentum at the 93th percentile; novelty at the 95th percentile.
Who should use it
Who should skip it
Pass on agent-sh/agent-workspace-linux if its scope or audience does not match what your team is building right now.
About this signal
agent-sh/agent-workspace-linux is tracked by RepoRadar as an MCP server in the Developer Tools section. First seen 2026-06-26; the source record was last checked on 2026-06-26. The current verdict is 'try now' with a Gold tier and moderate setup difficulty. Across RepoRadar's eight signals, agent-sh/agent-workspace-linux is strongest on workflow potential (10.0) and practical usefulness (9.0) and weakest on setup ease (6.4) — a profile worth weighing against your own priorities. This page summarizes the public evidence on the linked source page and states where additional review is still needed.
How this item is evaluated
The agent-sh/agent-workspace-linux record combines a 8.5/10 composite score with separate popularity (88.0), risk (conditional), and setup (moderate) signals. See the scoring methodology for the current weights and evidence definitions.
Questions worth asking before you adopt this
Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.
Risk explanation
The runtime can still browse, type, click, and handle files inside its hidden workspace, so start with disposable profiles and non-sensitive accounts; The hard isolation boundary depends on Linux dependencies and the permission ceiling you actually configure, so verify the enforcement path before production use; The control socket is same-user by design, which means shared or multi-user machines need a dedicated account or stronger host isolation.