RepoDaily · 2026-08-20 · Security tool

Munder Difflin review: a local hive that runs Claude Code, Codex and eight other CLIs as one team

#5 Security tool TypeScript +797 chaitanyagiri/munder-difflin Open repository

A free, MIT-licensed desktop harness that turns ten terminal coding CLIs into a self-coordinating hive — local-only networking, sandboxed IPC, and a security policy you can actually read.

Repo typeSecurity tool
Best forDevelopers already paying for Claude Code, Codex or Copilot CLI who want several agents coordinated on one machine, locally
Risk levelMedium — working prototype, no test suite, bundled pixel art is non-commercial licensed
Time to evaluate1–2 hours: clone, npm install, npm run dev, hand Michael one task

Primary question: Does routing your existing CLI agents through one local hive — with a Unix-socket-only hook server — beat juggling them in separate terminals?

92/100

RepoDaily adoption score

RepoDaily rates this as 92/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.

Directional score from RepoDaily sources and adoption notes, not a benchmark.Risk: Medium
100Evidence quality

6 source(s) across 2 source category/categories, plus a RepoDaily-specific evidence module when available.

100Installability

6 workflow step(s), 5 next-action step(s), and 3 command/install signal(s) were detected.

66Maintenance confidence

Trending momentum is +797 stars, with maintenance/release/issue signals counted when present.

96Production readiness

Risk is marked medium, with 6 security note(s) and 4 explicit skip condition(s).

100Differentiation

3 opportunity lens item(s), 4 alternative(s), and 4 type-specific section(s) support differentiation.

68License clarity

License source or license wording is present.

90Agent / AI fit

8 AI/agent-related signal(s) were detected in the article text and metadata.

Project overview

Munder Difflin is a free, MIT-licensed desktop application that wraps ten terminal coding CLIs — Claude Code, Antigravity (Gemini), OpenAI Codex, xAI Grok, Kimi Code, Qwen, OpenCode, Crush, pi.dev and GitHub Copilot CLI — into what its README calls a hive mind. Each CLI (invoked as claude, agy, codex, grok, kimi, qwen, opencode, crush, pi or copilot) runs as a real process inside a pseudo-terminal. The stack is Electron, React, TypeScript, Pixi.js, xterm.js and node-pty, and the whole thing runs on the subscriptions you already pay for, within their hourly limits, with bring-your-own keys and local LLMs supported.

The pitch is your clone. One agent, named Michael, is the boss of the floor and the only one you talk to; he routes work between the others. Every agent gets long-term memory, a mailbox with inbox/ and outbox/ directories, and a desk on a 2D office floor where avatars are rendered doing their jobs. The README calls its memory layer the fastest in the world — a claim we cannot verify, but the memory, routing and mailbox primitives are all named files in the source tree (src/main/memory.ts, src/main/hive.ts, src/main/hooks.ts).

Read as a security tool, which is how RepoDaily is treating it, the picture is unusually clear for a prototype. SECURITY.md states the app spawns local processes in PTYs, reads and writes only under directories you register, opens no network listeners beyond a local Unix domain socket for the in-app hook server, and has no auth or remote surface by design. The renderer has no direct Node access (nodeIntegration: false, contextIsolation: true); all fs:* and git:* IPC calls are sandboxed and path-validated in the main process, rooted at an agent's working directory; and the hive commits to a local git repo from a single committer — the main process — while agents themselves only write plain files.

The timing explains the traction: 797 stars in the period and rank 5 on 2026-08-20, two days after v0.4.4 (2026-08-18). That release fixed agent-to-agent messaging on Windows, which had never worked — cmd.exe truncates the hive's multi-line, roughly 6.1k-character prompt argument at its first newline, so agents booted, looked healthy, and could not message anyone — and the changelog notes Windows accounts for roughly half of all downloads. It also fixed a bootstrapHiveServices() early-return that left a brand-new install's message router, hook server, telemetry collector and mission scheduler dead for the entire first session.

Problem it solves

  • Running several terminal coding CLIs at once means manual tab-switching with no shared memory and no routing between them
  • Subscriptions carry hourly limits: one agent idles while another burns quota, and nothing balances the two
  • Whatever an agent learns in a session is lost when it exits
  • Checking what agents actually did means scrolling terminal buffers
  • On Windows, cmd.exe argument truncation silently killed agent-to-agent messaging until v0.4.4 decoded the npm shim and spawned an argv array instead

How it works

  1. Each CLI is spawned by node-pty as a real process in a pseudo-terminal inside the Electron main process (src/main/pty.ts)
  2. Every agent gets long-term memory (src/main/memory.ts), a mailbox built on inbox/ and outbox/ directories, and a desk on the 2D office floor
  3. Messages route through the hive layer (src/main/hive.ts), with an in-app hook server listening only on a local Unix domain socket (src/main/hooks.ts)
  4. Michael, your clone, is the boss of the floor and assigns work; you talk only to him
  5. The main process is the single committer to a local git repo; agents themselves write plain files only
  6. Pixi.js renders the office scene (src/renderer/src/scene/office/) and xterm.js renders each terminal

Architecture read: one process, one floor, one committer

CONTRIBUTING.md publishes the layout. src/main/ holds the Electron main process: PTYs (pty.ts), the fs/git bridges, and the hive itself (hive.ts, hooks.ts, memory.ts) plus config. src/preload/ is the context-bridge IPC surface that exposes the typed window.cth API to the renderer, which is why the React UI in src/renderer/ has no direct Node access. The Pixi.js office scene lives in src/renderer/src/scene/office/, and tools/mapgen/ contains Python helpers for building and rendering a Tiled office map.

The most instructive design detail is how a prompt reaches an agent: the hive protocol delivers it as a single multi-line, paren-heavy command-line argument of roughly 6.1k characters. That is precisely what broke Windows — cmd.exe treats CR/LF as a statement separator before quoting is considered, has no backslash escape and no escape for a newline, so the argument was cut at its first line break, dropping the block that names inbox/ and outbox/. The 0.4.4 fix decodes the npm shim to its interpreter and script and spawns them with an argv array, letting node-pty's MSDN/CRT escaping hand the full prompt to CreateProcess, whose ceiling is 32767 characters rather than cmd.exe's 8191. A second fix handled opencode-ai, whose bin is a compiled binary and therefore gets an interpreter-less npm shim that previously returned null on every Windows install.

Try-it path

  • Prerequisites: Node.js 18+ with npm, a C/C++ toolchain to build node-pty's native addon (xcode-select --install on macOS), and Claude Code on PATH for the default command — any other CLI works
  • git clone the repo, then npm install; the postinstall script runs electron-rebuild so node-pty matches Electron's ABI
  • If launch fails with a wrong ELF/Mach-O or NODE_MODULE_VERSION error, re-run npm install after confirming the C/C++ toolchain — CONTRIBUTING calls this the most common setup failure
  • npm run dev starts the live-reloading Electron build; the setup wizard then asks for an agents folder (0.4.4 fixed the ~/HarnessAgents path that died on ENOENT: mkdir)
  • Before any PR: npm run typecheck (the de-facto CI gate, since there is no test suite) and npm run build

Command surface

  • Ten CLIs are wrapped: claude, agy, codex, grok, kimi, qwen, opencode, crush, pi and copilot, plus custom sessions
  • Bring-your-own keys and local LLMs are supported; 0.4.4 fixed OpenCode preselecting a BYOK slug and silently falling back when the key was absent while still reporting the requested model
  • Grok 4.6 is selectable as of 0.4.4
  • A Skills browser shows installed skills across Claude Code, OpenCode and Codex with scope precedence, and browses 227 more for one-click install or removal
  • A Prerequisites page in Settings lists which supporting tools you have, which you lack, and what each is for, with a button that asks Michael to set up the missing ones
  • The hook server — the app's only listener — binds a local Unix domain socket

Maintenance risk

  • The README badge says working prototype; SECURITY.md supports fixes on the main branch only, and older tags get none
  • There is no test suite — CONTRIBUTING states npm run typecheck is the de-facto CI gate
  • Avatar behavior is driven by a mock event loop at src/renderer/src/store/mockEvents.ts; wiring real Claude Code hook events is named as the headline next milestone
  • CONTRIBUTING calls the app macOS-first with Windows/Linux untested, even as the changelog reports Windows at roughly half of downloads — 0.4.4 closed the biggest Windows gaps but cross-platform smoke-testing is still listed as a good first area
  • The bundled pixel art ships under the LimeZu FREE VERSION license, which is non-commercial only — a hard limit on any packaged redistribution
  • Dark mode contrast was rebuilt in 0.4.4 after ink-300 measured 1.73–2.09:1 against surfaces (187 uses, 93 as 1px borders); it now measures 3.4–4.0:1, with a new --cth-on-accent token at 7.0–8.5:1 — evidence the UI was being checked by measurement, not by eye

Who should pay attention?

Good fit if

  • Developers with existing Claude Code, Codex or Copilot subscriptions and spare hourly quota
  • macOS users with Node 18+ and a C/C++ toolchain who are comfortable building from source (npm run dev)
  • Anyone who wants to audit a local-only harness: no network listeners beyond one local Unix domain socket, and IPC path-validated in the main process
  • Windows users burned by earlier versions — 0.4.4 specifically fixed agent-to-agent messaging and the silent first-run failure

Skip for now if

  • Anyone needing supported software: the badge says working prototype, there is no test suite, and security fixes target main only
  • Commercial redistribution of the bundled build — the LimeZu FREE VERSION pixel art is non-commercial only
  • Machines that cannot compile native modules, since node-pty requires a C/C++ toolchain
  • Environments where agents must not write inside your registered directories — the CLIs run with your privileges under the folders you hand over

Risks and cautions

Medium

The security design is documented and sane for a local tool, but the project is an early prototype with no tests and a mock event loop driving its signature visualization.

  • No test suite; npm run typecheck is the stated de-facto CI gate
  • Avatar behavior currently comes from src/renderer/src/store/mockEvents.ts, not real hook events
  • Bundled art is non-commercial licensed, limiting redistribution
  • Security fixes target the main branch only; older tags are unsupported
  • 0.4.4 had to fix core paths — Windows messaging and first-run bootstrapping — that had been silently broken
  • Local-first by design: spawns processes in PTYs, reads and writes only under registered directories, opens no network listeners beyond a local Unix domain socket for the in-app hook server, and has no auth or remote surface
  • Renderer↔main IPC goes through a typed contextBridge (window.cth) with nodeIntegration: false and contextIsolation: true
  • All fs:* and git:* IPC calls are sandboxed and path-validated in the main process, rooted at an agent's working directory
  • The hive commits to a local git repo from a single committer — the main process; agents only write plain files
  • The real blast radius is your own machine and API quota: wrapped CLIs run as real processes with your credentials
  • Vulnerability reporting runs through GitHub private vulnerability reporting or email; public issues are explicitly discouraged

Alternatives to compare

ApproachWhen to useTrade-off
AutoGen
You want programmatic multi-agent orchestration you call from Python code, not a desktop shell around CLIs you run by handFree, MIT-licensed; you pay model and API costs
CrewAI
You want role-based agent crews defined in code with a fast Python startOpen source; you supply model keys
OpenHands
You want an open-source autonomous software agent rather than a coordinator for the CLIs you already runOpen source; you supply model keys
Plain terminals or tmux
You want zero new software and do not need shared memory or message routing between agentsFree; your existing CLI subscriptions stay as they are

What this trend reveals

Replace the mock event loop with real hook events

Avatar behavior today comes from src/renderer/src/store/mockEvents.ts, and CONTRIBUTING names wiring real Claude Code hook events as the headline next milestone. The main process already runs a hook server on a local Unix domain socket, so the plumbing half-exists.

Run one claude session on the office floor and check whether avatars react to actual tool calls or only to the mock loop.

Cross-platform smoke tests

CONTRIBUTING calls Windows and Linux untested while the changelog says Windows is roughly half of downloads. Version 0.4.4 alone fixed PTY spawn decoding, the interpreter-less opencode-ai shim that returned null, and the bootstrapHiveServices() early-return that left a fresh install's services dead all session.

On a clean Windows machine, install 0.4.4, finish the setup wizard without restarting, and confirm messages move between two agents.

First tests around the spawn path

There is no test suite; typecheck is the de-facto gate. The Windows bugs — newline truncation in cmd.exe and the undecodable compiled-binary shim — are exactly the regressions a small suite around shim decoding and hive-prompt argv construction would catch.

Contribute a vitest suite covering npm-shim decode and argv building, and add it to the PR checklist in CONTRIBUTING.md.

Best next action

Spend one evening running two of your CLIs on the floor

The fastest way to judge Munder Difflin is to build it locally and give Michael one real task that requires a handoff between two agents.

  1. Install Node.js 18+, a C/C++ toolchain (xcode-select --install on macOS) and at least one CLI such as Claude Code on PATH
  2. git clone the repository, run npm install (postinstall rebuilds node-pty against Electron's ABI), then npm run dev
  3. Finish the setup wizard, register a working folder, and add a second agent such as codex or grok
  4. Give Michael one task that needs a handoff, watch the office floor, and inspect each agent's inbox/ and outbox/ directories
  5. Read the reviewer notes in SECURITY.md and inspect the local git repo the hive commits to before registering any sensitive folder

RepoDaily verdict

A genuinely local answer to multi-agent chaos: the ten-CLI wrap, the Unix-socket-only hook server, sandboxed fs/git IPC and the single-committer git design are real and documented. But it is a prototype — no tests, a mock event loop behind its signature visualization, and non-commercial bundled art. Run it on a machine you control, over folders you would already let a CLI touch.

Sources