Limits
What this version of Bishop doesn't do.
- One agent per process. One Bishop directory runs one agent, and there's no agent registry. Run a second Bishop from a second directory for a second agent.
- Threads share a working directory unless worktree mode is on. Worktree mode keeps concurrent threads out of each other's files by convention, and needs a git repository. The sandbox keeps the agent out of Bishop's own state and other threads' shared files, but not out of other threads' checkouts.
- No approval flow. Permission decisions are the harness's, and a conversation has no way to ask a person for one.
- No way to turn Bishop's own tools off. Bishop serves them on
127.0.0.1, on an ephemeral port, authenticated with a credential minted per turn and destroyed when the turn ends. Nothing is reachable from off the machine, but anything running on it can reach the port and will be refused. - No health signal for a dead Slack connection. Bishop notices neither a revoked Slack app nor a dead socket, so a supervised process can look healthy while receiving nothing. Restart it if the agent goes quiet.
- Group chat files in Teams are untested. A direct chat and a channel are the two that are known to work.
- No sandbox in the container image, since it doesn't include nono.