Husk
БесплатноНе проверенHusk gives your AI chat a real computer of its own: files, a browser, and somewhere to run code. It can build things, look stuff up online and keep your work be
Описание
Husk gives your AI chat a real computer of its own: files, a browser, and somewhere to run code. It can build things, look stuff up online and keep your work between chats. Turn a chat you already had into a bot that does the job again tomorrow. Free and open source; there is no paid tier.
README
Your AI chat can write a script. It cannot run it.
Ask for a scraper and you get code to paste somewhere yourself. Ask again tomorrow and the files from today are gone. It cannot install a package, keep a login, or check whether the thing it just wrote actually works.
Husk hands it a Linux computer instead. A shell, a filesystem at /work that outlives
the conversation, and a browser whose login survives from one page to the next. One line
to set up. Runs on hardware you already have, with no account and no API key.
[!NOTE] Husk is in early alpha — everything works, things are moving fast, and your feedback shapes what comes next. Jump in.
Open interactively — pan, zoom, trace relationships · SVG · all 16 diagrams
Install
claude mcp add husk -- npx -y @husk-ai/mcp
That is the whole setup. Nothing is created until the first tool call, so an installed husk that nobody uses costs nothing. Works with Cursor, Zed, or anything else that speaks MCP.
Your agent gets 21 tools. Eight for the machine — shell, read_file, write_file,
edit_file, list_dir, expose_port, browse, computer_info — and thirteen
browser_* tools that drive a real Chromium inside that same machine, addressed by
accessibility ref rather than pixel coordinates.
The first tool result says what kind of machine it got. A model that thinks it is sandboxed when it is not makes worse decisions than one that knows.
The CLI
npx @husk-ai/cli doctor # what this machine can offer
npx @husk-ai/cli up dev # bring up a Linux computer
npx @husk-ai/cli exec dev -- 'uname -sr && python3 -V'
npx @husk-ai/cli rm dev # tear it down
On a laptop with Docker stopped and WSL2 installed, exec prints
Linux 6.18.33.2-microsoft-standard-WSL2 and Python 3.14.4. doctor reports every
provider it probed, which one it would pick, and why the others were skipped.
Turn a chat into a bot
A conversation that worked once becomes a file you can run again.
husk import # lists transcripts it found
husk import --pick 1 # imports one, prints its id
husk distill <id> --out triage.yaml # conversation → agent spec
husk run triage.yaml "check the build"
Importers read Claude Code JSONL, ChatGPT, Cursor, Gemini and markdown into one
Transcript. Branched threads are rebuilt by walking parentUuid back from the last
leaf. The distiller runs with no API key at all, and the model-backed mode falls back to
that free path rather than failing. Secrets are stripped before the file is written,
not after.
What comes out is YAML you can read and diff:
name: triage
model: sonnet
persona: |
You triage CI failures for a TypeScript monorepo.
Always read the failing job log before guessing.
tools: [computer, files]
computer:
flavor: node
network: { mode: egress, allow: ['*.github.com'] }
limits: { maxSteps: 24, maxCostUsd: 0.25 }
husk distill prints its confidence and everything it could not work out, so a thin
transcript announces itself instead of producing a plausible-looking persona nobody
checks. Five worked examples live in examples/.
What is in it
- A machine, not an interpreter. Files, a shell, ports, a browser.
/worksurvives the whole session, andpersistkeeps it past that. - Five computer providers.
docker,podman,ssh,fly,local. One interface;autotakes the highest available. - Eleven model providers. Ollama, Anthropic, OpenAI, Google, Groq, DeepSeek,
Cerebras, OpenRouter, Mistral, Together, LM Studio. Aliases resolve across all of
them, so one
husk.yamlruns on Opus or on a local Gemma. - Four adapters. Discord, Slack, Telegram, webhook.
- No telemetry. Not off by default. Absent. There is no analytics call, no crash reporter, no version ping.
- No native modules.
npm installfinishes on Windows with no C++ toolchain. Node 20.10 or newer. - 1,570 tests across 81 files, all passing with no Docker, no API key and no network.
How it works
Eleven packages and three apps. Dependencies run downhill: the other ten packages
import @husk-ai/core, core imports nothing from the workspace, and nothing imports
@husk-ai/cli.
packages/
core contracts, husk.yaml schema, primitives
runtime computer providers: docker, podman, local, ssh, fly
models one surface over eleven model providers
sessions transcript importers + the distiller
browser Chromium lifecycle and CDP automation
agent tool-calling loop and built-in tools
adapters Discord, Slack, Telegram, webhook
mcp MCP server (stdio)
server control-plane API + bot host
sdk typed client for the control plane
cli the husk command
apps/
console dashboard: live terminal, files, browser
docs documentation site (Next.js + MDX)
web marketing site (Next.js + Three.js)
server reaches @husk-ai/agent through a dynamic import and never declares it as a
dependency, so the control plane starts on a tree where the agent was never built.
Four flavours choose the image: base, python, node, full. Husk publishes none of
its own. base is debian:bookworm-slim, python is python:3.12-slim, node is
node:22-slim, and full is Playwright's image, which already carries the twenty-odd
shared libraries Chromium links against. An image you publish is an operating system you
have promised to keep patched, and Debian and the Playwright team already do that better.
Set HUSK_REGISTRY to point the lot at your own mirror.
Providers
auto walks the ladder and takes the highest rung that answers. Every rung is free
except fly, which is metered. An explicit --provider that turns out to be
unavailable is an error, never a quiet downgrade to weaker isolation.
| Provider | Priority | Isolation | Cost | Notes |
|---|---|---|---|---|
docker |
20 | Kernel namespaces, cgroups, seccomp, read-only root | Free | Default when the daemon is up |
podman |
18 | Kernel, rootless | Free | Linux without Docker |
ssh |
16 | Whatever the remote gives you | Free if you own the box | An Oracle Always Free instance, a Pi, a VPS |
fly |
14 | microVM | Metered | Bursty parallel work |
local |
10 | Guardrails only | Free | WSL2 gives real Linux; POSIX runs your own shell with guardrails |
The
localprovider is not a sandbox. It stops accidents, not adversaries.husk doctorreportsisolated: falsefor it, and the first MCP tool result says so again.
Security model
These hold in every mode, local included: the path jail, the command deny list, the
environment scrub, output caps, process-tree kill, redact() on every result and
audited() on every MCP call. What local does not give you is a kernel boundary. It
shares your kernel, your network and your user account.
169.254.169.254 stays blocked even under network.mode: full, because full means
the internet and not the cloud metadata service that hands IAM credentials to whatever
asks. Loopback and the RFC1918 ranges are the same problem one hop out. An operator who
wants one of them names it in allow, where a reviewer reading the husk.yaml can see
the decision.
Address spellings are normalised first. 127.1, 2130706433 and 0x7f000001 are all
127.0.0.1 to curl, to Chromium and to Python's urllib, so a rule that only understands
four dotted octets is not a rule.
Documentation
- Architecture — why it is shaped this way
- API reference — the control-plane HTTP contract
- Build contract — conventions every package obeys
- Security model — what is isolated and what is not
- Examples — five
husk.yamlrecipes and an MCP session demo - Diagrams — 16 interactive architecture, dataflow and design diagrams
Status
Alpha, pre-1.0. The husk.yaml schema and the HTTP contract can still change between
releases. What is known not to work today:
- The rendered browser is only confirmed on
local. The thirteenbrowser_*tools drive Chromium there today. On the container providers the root filesystem is mounted read-only, so Chromium's shared libraries have to arrive in the image rather than through a package manager, and that path is still being worked out.browse, which fetches a page and strips the tags, works everywhere. flyis the least exercised provider. It has tests. It has far fewer real hours thandockerandlocal.
Development
git clone https://github.com/Hotragn/husk.git && cd husk
npm install
npm run build
npm test
Contributing
Contributions are welcome. CONTRIBUTING.md covers the build contract, the test requirements, and how to add a provider or a model.
Contributors
Everyone who has shipped something here is on the contributors graph, which counts commits rather than asking anyone to remember to add a name.
License
Установка Husk
У этого сервера нет опубликованного пакета — он собирается из исходников. Открой репозиторий и следуй инструкции в README.
▸ github.com/Hotragn/huskFAQ
Husk MCP бесплатный?
Да, Husk MCP бесплатный — установка в пару кликов через Unyly без оплаты.
Нужен ли API-ключ для Husk?
Нет, Husk работает без API-ключей и переменных окружения.
Husk — hosted или self-hosted?
Self-hosted: сервер запускается локально на твоей машине командой из раздела установки.
Как установить Husk в Claude Desktop, Claude Code или Cursor?
Открой Husk на unyly.org, выбери вкладку своего клиента (Claude Desktop, Claude Code, Cursor) и нажми Install — конфиг сгенерируется автоматически, без правки JSON.
Похожие MCP
Gmail
Read, send and search emails from Claude
автор: GoogleSlack
Send, search and summarize Slack messages
автор: SlackRunbear
No-code MCP client for team chat platforms, such as Slack, Microsoft Teams, and Discord.
Discord Server
A community discord server dedicated to MCP by [Frank Fiegel](https://github.com/punkpeye)
Klavis AI
Open Source MCP Infra. Hosted MCP servers and MCP clients on Slack and Discord.
Work90210/APIFold
Turn any REST API into a hosted MCP server. 18 free public servers (GitHub, Stripe, Slack, OpenAI, Notion, and more) — no setup required, bring your own API key
автор: Work90210arikusi/deepseek-mcp-server
MCP server for DeepSeek AI with chat, reasoning, multi-turn sessions, function calling, thinking mode, and cost tracking.
автор: arikusihashgraph-online/hashnet-mcp-js
MCP server for the Registry Broker. Discover, register, and chat with AI agents on the Hashgraph network.
автор: hashgraph-onlineprofullstack/mcp-server
A comprehensive MCP server aggregating 20+ tools including SEO optimization, document conversion, domain lookup, email validation, QR generation, weather data,
автор: profullstackWayStation-ai/mcp
Seamlessly and securely connect Claude Desktop and other MCP hosts to your favorite apps (Notion, Slack, Monday, Airtable, etc.). Takes less than 90 secs.
автор: waystation-aiCompare Husk with
Не уверен что выбрать?
Найди свой стек за 60 секунд
Автор?
Embed-бейдж для README
Похожее
Все в категории communication
