<- all tokdocs

Agent Room really does put Codex and Claude Code in one local room, and the server it ships has an unfixed lost-update race and no Origin check

Watch on TikTok

View on TikTok ->

The artifact is a 40.27 second clip (0:40) at 720x1280, HEVC Main video at 30 fps and roughly 120 kbps, HE-AACv2 audio at 44.1 kHz stereo and roughly 64 kbps, 960,899 bytes on disk (938 KiB), posted 2026-08-31 at 14:42:01 UTC by @github.signals, channel nickname "Github Signals". At capture on 2026-10-06 it showed 14,800 views, 580 likes, 9 comments and 166 reposts. The audio is listed as "original sound - Github Signals" with no licensed music. I read 14 of the 20 extracted frames and the full 109-word transcript. Every frame is the same shot: a Chrome-style browser window, tab titled "GitHub - steviebuilds/agen…", address bar reading github.com/steviebuilds/agent-room, scrolling slowly down the repository landing page. The sticky commit row at the top of frame_001 reads "install.sh | Initial public release of Agent Room | last month". Below it sit two tabs, "README" and "MIT license". The README opens with the H1 "Agent Room" and the line "Run private, local meeting rooms where Codex, Claude Code, and other terminal agents can talk to one another while you watch—or join—the conversation in a browser." The second paragraph reads "Everything runs on your computer. There are no accounts, hosted services, API keys, or model charges beyond the agents you already use." The embedded product screenshot shows a dark chat UI headed "Agent meeting", with header buttons "Only when addressed" and "Copy invite", a left rail showing "OBJECTIVE / Open collaboration meeting" and "IN THIS ROOM" listing three participants named Codex (Agent), Fable (Agent) and Steve (Human). The visible transcript has Steve asking "What is the meaning to life, codex?", a long Codex reply about meaning being "made through attention and commitment", Steve typing "claude?", and Fable answering "I'd add a footnote to Codex's answer: Douglas Adams already settled this at 42". The composer placeholder reads "Add to the conversation…". Further down the page the video exposes "Install with an agent" with the repo URL in a copy box, the prompt "Install this Agent Room skill into both my Codex and Claude skill …", then "Install manually" with git clone https://github.com/steviebuilds/agent-room.git, cd agent-room, ./install.sh, and the installer bullet list: "installs the skill at ~/.codex/skills/agent-room", "links ~/.claude/skills/agent-room to the Codex installation", "preserves an existing installation as a timestamped backup", "requires Bun or Node.js 20 or newer at runtime". Burned-in captions in yellow and white run across the whole clip: "AGENTROOM LETS", "CODECS AND CLOUD", "LIVE MEETINGS ON", "BEGIN DEBATING", "A CHAT INTERFACE", "NO CLOUD SERVERS", "TALKING DIRECTLY TO", "COMMAND LINE", "WORK SPOT BUGS", "THAT YOU STAY FULLY", "AS A SILENT", "ACTIVE PARTICIPANT". The caption generator misheard both product names at frame_002, rendering "Codex and Claude" as "CODECS AND CLOUD", and the Whisper transcript of the voiceover repeats the second error as "Cloud Code".

The project is real, and it is smaller and older than the video implies

The repository is steviebuilds/agent-room, owned by Steve Richardson. The GitHub API reports it as MIT licensed, JavaScript, created 2026-07-11T01:02:16Z, last pushed 2026-07-12T10:44:16Z, with 107 stars, 19 forks and 3 open issues as of 2026-10-06. Its topics are ai-agents, claude-code, codex, local-first and multi-agent. The description reads "Private local meeting rooms where Codex, Claude Code, and other agents collaborate live."

The commit history is two commits: "Initial public release of Agent Room" on 2026-07-11 and "docs: add Agent Room screenshot" on 2026-07-12. There are no tags and no releases. The whole project is four blobs and two directories: README.md, SKILL.md, install.sh, LICENSE, agents/openai.yaml, and scripts/agent_room.mjs at 41,441 bytes.

The video was posted 2026-08-31, seven weeks after the last push. At the time of writing the repo has gone roughly three months without a commit.

The local-only claim checks out at the code level, which is more than the video bothers to show

I have the skill installed on this machine, so I read the shipped server rather than trusting the README. scripts/agent_room.mjs is 591 lines. Its only imports are Node builtins: node:http, node:crypto, node:fs, node:os, node:path, node:process, node:child_process and node:url. There is no package.json and no third-party dependency, which matches the README bullet "Localhost-only Bun/Node server with no package dependencies".

The binding is explicit:

const HOST = process.env.AGENT_ROOM_HOST || "127.0.0.1";
const PORT = Number(process.env.AGENT_ROOM_PORT || 7331);

State lives in ~/.agent-room/. The installed version string is 0.5.1. Nothing in the file opens an outbound connection to a model provider, so the narration line "There are no cloud servers, accounts, or extra API bills" describes the server accurately.

The server accepts requests from any web page you have open

The README's safety argument is binding address: "The server binds to 127.0.0.1 and is not exposed to your network." Binding to loopback stops other machines. It does not stop the browser already running on the same machine.

Grepping the shipped script for headers.origin, headers.host and access-control returns zero matches. The server validates neither the Origin header nor the Host header. Issue #1, filed 2026-07-16 by an outside contributor, states the consequence directly: "The server accepted any Host and any Origin. A page you visit while a room is running can POST to 127.0.0.1:7331 — text/plain is a CORS-simple request, so no preflight blocks it."

The video's closing claim is "you stay fully in control, acting as a silent observer or an active participant". That is true of the UI. It is not true of the HTTP surface while a room is open.

The lost-update race described in the issue tracker is present in the code the installer puts on disk

Issue #1 also reports that concurrent agent messages are silently dropped. The reporter's reproduction output is quoted in the issue: "A -> HTTP/1.1 201 Created | B -> HTTP/1.1 201 Created / stored agent messages: ["message-from-A"] / participants: ["Host","AgentA"] / RESULT: LOST UPDATE — only 1/2 stored". Both agents receive a 201. One message vanishes and that agent is not even recorded as a participant.

The pattern is visible in agent_room.mjs as installed. Line 217 loads the entire state file into memory:

let state = loadState();

Line 288 then yields to the event loop before any mutation happens:

const body = await readBody(request);

Every mutating branch after that (join, message send, mode change, close) writes the whole snapshot back with saveState(state). Two overlapping requests each hold a stale copy, and the second save overwrites the first. Issue #3, filed 2026-09-02, describes the same class of bug and notes that it crosses rooms, "even across different rooms, since all rooms share one file". Neither issue has been merged. The repo's last push predates both.

This matters for the specific use case the video sells. The pitch is agents that "review work, spot bugs, and reach consensus together". A room whose message log can silently drop a participant's contribution is a poor substrate for consensus, because an agent will believe it spoke and the room will wait on a message that was never stored.

The Codex half of the install path no longer matches OpenAI's documentation

The installer writes the skill to ~/.codex/skills/agent-room and symlinks ~/.claude/skills/agent-room to it. I confirmed that on this machine: readlink ~/.claude/skills/agent-room returns /Users/matthewcullerton/.codex/skills/agent-room.

The Claude Code side is current. Anthropic's Agent Skills documentation states that custom Skills in Claude Code "are filesystem-based and don't require API uploads: place them in ~/.claude/skills/ (personal) or .claude/skills/ (project)." The symlink resolves and the skill loads.

The Codex side has drifted. OpenAI's current skills documentation at learn.chatgpt.com/docs/build-skills lists the discovery paths as $CWD/.agents/skills, $CWD/../.agents/skills, $REPO_ROOT/.agents/skills, $HOME/.agents/skills and /etc/codex/skills. It does not list ~/.codex/skills. That path was the original experimental location when OpenAI first added skills support to Codex CLI in late 2025, as Simon Willison documented on 2025-12-12. Anyone running ./install.sh today should expect the Claude Code half to work and should verify the Codex half against the current docs, or copy the directory into ~/.agents/skills/ as well.

The interop on display is a file-format convention, not a protocol between Anthropic and OpenAI

Nothing in Agent Room negotiates between vendors. It writes one SKILL.md and relies on two separate CLIs independently reading the same Markdown-with-YAML-frontmatter format from their own directories.

The order of events is worth stating, because the video presents the interop as a property of the project. Anthropic shipped Agent Skills and the SKILL.md format in October 2025. OpenAI added skills support to Codex CLI roughly two months later. Agent Room arrived in July 2026 and uses both. Willison's write-up makes the derivation explicit: OpenAI's skills "look very similar to Anthropic's implementation of the same kind of idea".

The actual coordination mechanism is more mundane than "agents talking directly to each other". The shipped SKILL.md instructs each agent to sit in a foreground long-poll:

After sending any message, immediately wait again. Prefer send --wait 45, which does both in one command.

Each agent runs a blocking CLI command against localhost, gets woken by HTTP, and re-enters its own model loop. The transport is a 591-line Node HTTP server. The intelligence is still two unmodified coding agents.

"No extra API bills" is the README's claim with its qualifier removed

The README says "There are no accounts, hosted services, API keys, or model charges beyond the agents you already use." The voiceover compresses this to "no cloud servers, accounts, or extra API bills, just your existing agents talking directly to each other". The on-screen caption shortens it further to "NO CLOUD SERVERS".

Agent Room itself charges nothing and calls no model API. The agents in the room do. A debate between two agents is a sequence of model turns, each of which re-ingests the room transcript on wake, and the SKILL.md loop instructs both agents to keep waking until a stop condition is met. Every wake costs tokens against whatever plan or API key already funds Claude Code and Codex. The honest reading of the README qualifier is that Agent Room adds no new vendor, not that it is free to run.

A footnote on the name in the screenshot

The README's demo screenshot labels the Claude Code participant "Fable", and the README's example prompt is "Call yourself Fable". That was a persona name chosen by the author in July 2026. Anthropic now ships a model called Claude Fable 5.1, listed on Anthropic's models overview alongside Claude Opus 5.5, Claude Sonnet 5.5 and Claude Haiku 4.5. The collision is coincidental and the README predates the model name, but a reader landing on the repo today should not take the screenshot as evidence that Agent Room selects models.

Key Takeaways

  • Verified: The project shown is steviebuilds/agent-room, MIT licensed, JavaScript, 107 stars and 19 forks as of 2026-10-06, created 2026-07-11 and last pushed 2026-07-12 across exactly two commits.
  • Verified: The local-only claim holds in the shipped code. scripts/agent_room.mjs imports only Node builtins, binds to 127.0.0.1:7331, stores state in ~/.agent-room/, and opens no outbound model connection.
  • Correction: The video says you "stay fully in control". The server validates neither Origin nor Host, so any web page open in your browser while a room is running can POST to 127.0.0.1:7331. This was reported in issue #1 on 2026-07-16 and is still open.
  • Correction: The video sells the room as a place where agents "review work, spot bugs, and reach consensus". Open issues #1 and #3 document a lost-update race in which two overlapping agent messages both return HTTP 201 and only one is stored. I confirmed the pattern in the installed v0.5.1: state is loaded at line 217, await readBody(request) runs at line 288, and the full snapshot is written back afterward.
  • Partial correction: "No extra API bills" drops the README's qualifier "beyond the agents you already use". Agent Room adds no vendor and no API key. The multi-turn debate it enables consumes tokens on whichever plan already pays for Claude Code and Codex.
  • Correction: The installer's Codex target is stale. It writes ~/.codex/skills/agent-room, while OpenAI's current documentation lists $HOME/.agents/skills, $CWD/.agents/skills, $REPO_ROOT/.agents/skills and /etc/codex/skills, and does not list ~/.codex/skills. The Claude Code target ~/.claude/skills/ remains correct per Anthropic's docs.
  • Context: The cross-vendor interop is a shared file format, not a vendor agreement. Anthropic introduced SKILL.md in October 2025, OpenAI adopted it in Codex CLI about two months later, and Agent Room was published in July 2026 on top of both.
  • Context: The video presents the idea as original. The repo's own README credits prior art: "Inspired by AgentMeet. Agent Room is an independent local-first project and is not affiliated with AgentMeet." AgentMeet is a hosted service that describes itself as "Google Meet, but for AI agents".
  • Context: The burned-in captions render the two product names as "CODECS AND CLOUD", and the speech-to-text transcript renders Claude Code as "Cloud Code". Both are automated transcription errors, not the author's spelling.
  • Unverified: Whether Codex CLI still reads ~/.codex/skills as a legacy fallback. I checked OpenAI's current skills documentation and the Codex repo's docs/skills.md redirect target, and neither mentions the path. The installer's behaviour on a current Codex build was not tested here.

Resources

Published August 31, 2026. Writeup generated from a favorited TikTok.