I kept copying one agent’s report into another chat, then carrying the response back. One agent was reviewing and directing the work. The other was doing it. Each could handle its part, but I had become the connection between them. I wanted to keep deciding what mattered without relaying every message.
The exchange needs state: Agent Talks gives those two sessions a named local channel. An orchestrator sends a task, a worker reports a result or blocker, and the orchestrator reviews it. The channel records whose turn it is. Several pairs can run at once by choosing different names.
The public version is a small Python tool built around SQLite and MCP, the Model Context Protocol used to expose tools to an agent. Both Codex sessions run on the same machine and under the same operating-system user. Each tool process reads the same database. No network broker or separate model is involved.
One owner at a time: The channel starts with the orchestrator. Sending a task transfers control to the worker; sending a report transfers it back. Revisions reject a reply based on an old state. A request ID makes an identical retry return the stored message instead of sending it twice. This gives an interrupted exchange a definite place to resume.
While the other agent owns the turn, the waiting agent keeps a tool call open. That call checks local state without asking a model to reason about whether anything happened. Model use resumes when the surrounding agent handles a result. A timeout is only a timeout, and never permission to start work. A chat that has ended still needs to be resumed by its user.
Review belongs to the orchestrator: A worker report should bring the orchestrator back to a decision. It may inspect the result, discuss it with the user, or assign another task. Ending that discussion reply does not need to close the channel. If a worker waits past a received task without reporting, the tool returns control with a recovery notice. It does not pretend the task finished.
A lost session is recoverable: The same session can register again and recover its token. A new session cannot silently take someone else’s role. The user confirms the replacement; the old token is revoked, history stays in place, and an open channel returns to the orchestrator. Either role or both can be replaced. Closing also requires confirmation, and reopening preserves the conversation.
This still requires care with unfinished commands. Replacing a session does not stop a shell process or background job it started. The orchestrator needs to inspect that partial work before assigning it again. Recovery restores the conversation’s control state; it does not establish what happened in the workspace.
The guard has limits: The included Codex hooks check session identity and block covered work tools when the caller does not own the turn. They do not verify task meaning, produce a sandbox, or prevent an unrestricted agent from changing local files. Agents sharing a user account remain able to access that user’s files. Message history is plaintext locally, and messages entering the agent’s context may reach its model provider.
Installation stays small and visible: The repository includes an INSTALL-PROMPT.md for a coding agent to follow. It creates a virtual environment, runs tests, and merges the MCP and hook settings while preserving unrelated configuration. The user reviews the hooks in Codex. The release is source-only, with no Debian package, remote service, or bundled messaging bridge.
The tests exercise turn order, concurrent changes, retries, confirmation, and recovery through real MCP subprocesses. They do not prove an agent’s judgment or every host’s hook behavior. For me, the useful result is concrete: the agents exchange their own tasks and reports, and I can spend my attention reviewing what they actually did.
