Frameworks
Agent Zero: giving an agent a whole Linux computer
Agent Zero's pitch is not a better tool list but a whole desktop in a container: a browser, an office suite, a terminal and isolated projects. What that makes possible, and the risks that come with it.
- Published
- 3 Sep 2026
- Reading
- 9 min
- Class
- frameworks
half-life 120dfrom 3 Sep 2026
Most agent frameworks give a model a list of functions. Agent Zero gives it a computer. The agent runs inside a Docker container that holds a full Linux desktop, and it works the way a person would: opening a browser, editing a document, running commands and writing code to fill any gap it finds.
That is a different bet from the typed, testable frameworks elsewhere on our framework board, and it is worth being clear about what it is good for before deciding whether it is for you.
What is in the box
- A real desktop. An XFCE session in the container, so the agent can drive GUI software, not just command-line tools.
- A browser you can annotate. Built in, with DOM inspection: you can point at an element on a page, comment on it or lift it out and hand it to the agent.
- Live document work. Markdown and LibreOffice (Writer, Calc, Impress) can be edited alongside the agent rather than passed back and forth.
- Projects. Isolated workspaces with their own files, instructions, secrets, memory and Git repositories, so one client's context does not leak into another's.
- Skills, plugins and subordinates. Skills load on demand or can be pinned from chat; a plugin hub lists more than a hundred community extensions; and the agent can create subordinate agents to split up work.
- Time travel. Snapshot history with diffs and revert for its own workspace — useful, though the project itself says it is not a replacement for Git or backups.
Getting it running
Docker is the requirement. The quickest route is a single command that publishes the web interface and keeps your data in a named volume:
docker run -p 80:80 -v a0_usr:/a0/usr agent0ai/agent-zero
There is also a terminal installer and a desktop launcher for macOS, Linux and Windows. A separate CLI connector lets the agent work on real repositories on your host, which is the point where the safety story changes.
The safety story
The container is the boundary. Inside it the agent can install packages, run code and break things freely, which is what makes it capable and also why the project's own guidance is blunt: keep it in Docker, do not mount your whole home directory, keep credentials in project secrets rather than prompts, and review anything that touches accounts, money or production systems.
Where the risk moves
Inside the container, the worst case is a mess you delete. The moment you connect a host bridge or mount real folders, the agent's mistakes become yours. Decide the smallest set of folders it needs and grant read-write only to those.
When it earns its place
Choose Agent Zero when the job does not fit a fixed tool list: exploratory research that ends in a document, browser-heavy tasks, or projects where you want the agent to build its own tooling as it goes. It is also a good way to learn what agent instructions do under load, because the persona and prompts are plain, editable text.
It is a poor fit for a production service that needs predictable, testable behaviour; a self-writing agent is hard to pin down. If that is your need, look at typed frameworks instead. Our Agent Zero spec sheet has the standing comparison, and the project's README is the authority on its current state, since it moves quickly.
Sources
- agent0ai/agent-zero — README: features, install commands and security guidance.