English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

An Open Source Project That Rejects Code Contributions Is Treating AI Agents as Employees

Forum topic · QianXun · 2026-08-09

Summary

qm, a YC-backed open source project (MIT-licensed, 37,000+ lines of TypeScript, 377 test files), reimagines AI agents as digital coworkers rather than personal assistants. Its headless core runs TypeScript on Node with Fastify and Postgres, while a pluggable harness layer supports Pi, OpenCode, Codex, and Claude Code. Each agent gets an isolated workspace with its own memory, files, credentials, permissions, cron jobs, and sandbox. Unusually, the project's contributing guide rejects code PRs: contributors submit plain-language descriptions instead, and agents handle implementation. Strict engineering rules include zero code comments and mandatory fresh-context review by an independent agent before merging. A tiered security model (Strict/Auto/Dangerous) gates tool calls, with hard command policies enforced in all modes. Deployment is a single portable, committable directory generated by `qm init`, targetable at Docker, Fly, or AWS ECS Fargate with Lambda MicroVM sandboxes. The article argues this employee-model architecture may define how organizations adopt AI over the next decade.

An open source repository with a blunt contributing guide: don't send us code. To add a feature, write a plain-language description of the change you want — the team will burn tokens to implement it themselves.

The project is qm (from "queuing machines"), YC-backed, tagged a multiplayer agent harness for work. MIT license, 37,000+ lines of TypeScript, 377 test files, with commits landing as of yesterday. The author read the whole repo and concluded: it's not just another agent framework.

What It Actually Does

Most AI tools assume a "personal assistant" model: one agent serving one person (or a few session windows). qm changes the model — it provisions agents like new employees:

  • Each agent gets its own isolated workspace: memory, files, credentials, permissions, scheduled jobs, and sandbox, all independent
  • Every room and project has its own scope
  • People collaborate with agents in Slack channels, groups, and projects
  • In the authors' words: *Most agents are designed like personal assistants. You can make one work for a whole company, but it quickly gets complex. QM is designed for startups.* So everyone gets a digital coworker instead.

    Architecture: A Headless Core, Four Swappable Brains

    The core is headless: TypeScript on Node, Fastify for HTTP, Postgres for sessions, memory, and queues.

    The key differentiator is the harness layer — the engine that drives the agent. qm supports Pi, OpenCode, Codex, and Claude Code, all driving the same core. You pick one at deployment; no vendor lock-in.

    Every turn flows through the central core, which exposes a small, fixed tool surface. One tool, execute, runs commands in the scope's own isolated sandbox — a persistent "computer" for the agent, where installed tools stay installed. Scheduler, cron, and monitor keep background work running; web UI, admin console, and external portals are optional plugins over the core HTTP API. Slack runs as an in-process plugin supervised by the core.

    Architecture philosophy in one line: the core stays generic; everything company-specific goes into the deployment directory.

    Three Counterintuitive Design Choices

    1. Zero Comments Allowed

    AGENTS.md mandates a zero-comment standard: no explanatory comments, no TODOs, no lint suppressions, no commented-out code. Intent is expressed through naming, structure, and tests; rationale goes into commit messages and PR descriptions.

    2. Contributions in Plain Language Only

    Since the underlying code is mostly written by coding agents, the team prefers PRs in the form of human-written text — casual, like suggesting an idea in Slack. Once aligned, they implement it. They even add: don't use AI to inflate your idea into a formal proposal.

    This signals their stance on AI-written code: not resistance, but full acceptance with a redivision of labor — humans decide what to build; agents write it.

    3. Never Review Your Own Code

    A hard rule in AGENTS.md: before merging to main, changes must pass a fresh-context review — an independent review agent that hasn't seen the code being written, tasked specifically with finding flaws. Green CI doesn't count; self-review doesn't count.

    Post-merge habit: fix all instances of a bug class across the repo, not just the reported one.

    Security: Posture, Not Promises

    Organizations pick a security posture; smaller scopes can only tighten it:

  • Strict: every harness tool call pauses for human approval, except two side-effect-free turn-ending tools
  • Auto (default): a classifier screens inputs before they reach the model, detecting injection attempts (agent redirection, credential theft, data exfiltration); can point to your own screening agent
  • Dangerous: no content screening, no pauses between tools
  • Notably honest: pre-declared command policies (recursive deletes, destructive SQL) are hard-rejected in every posture, including Dangerous. Review records support post-hoc investigation but don't block actions.

    SECURITY.md openly admits this is early experimental software: isolation is the design goal, not a guarantee that data won't leak. That kind of honesty is rare in engineering.

    Deployment: The Whole Company Is One Directory

    Deployment isn't a docker-compose file — one deployment = one committable, portable directory. qm init generates it: config, sandbox Dockerfiles, tools, skills, Slack manifest, deployment docs. The qm CLI is the sole legitimate interpreter of the directory.

    Targets: Docker locally, Fly apps, AWS ECS Fargate ARM64 tasks with pinned digests, and Lambda MicroVMs for agent computers.

    Deep customization uses a private fork: a separate private repo, history starting from a clone, with all organization-specific content in deploy/layers/<org>/. Two skills maintain boundaries — update-qm merges upstream; upstream-pr pushes org-agnostic fixes upstream without leaking deploy/layers/ content.

    Is It Cargo Culting?

    The author's test — can you restate what it actually does?

  • It accepts agents as coworkers, so each gets a full working environment
  • It accepts that model vendors change, so the engine is pluggable
  • It accepts that AI code needs human judgment, so contributions were redefined
  • It accepts that security can't rest on promises, so the threat model is printed in the docs
It's early experimental software, and 37,000 lines surely hide pitfalls. But the direction is real: the hard part of organizational AI adoption isn't how smart a single agent is — it's whether it can have its own desk, memory, and permissions, and collaborate with others like a person.

Treating agents as employees may be the organizational shift most worth watching over the next decade.

Tags

#ai-agents#open-source#multi-agent-systems#ai-infrastructure#software-engineering#security#developer-workflow#typescript

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178603084