A community-driven registry for Claude, Cursor, Windsurf, Cline & more. Not affiliated with Anthropic.
Are you the author? Sign in to claim
Local-first personal agentic OS and everything app for coding, knowledge work, web design, automations, and artifacts.
CoWork OS is the GUI-first, CLI-capable local AI super app and everything app for getting real work done.
Code, email, research, design web pages, create documents, work with spreadsheets and decks, spawn and manage agents, run automations, and ask for changes from the desktop app or the cowork CLI without jumping between separate coding, mail, browser, Word, Excel, or PowerPoint apps.
Getting Started · Composer Mentions · Message Box Shortcuts · Side Chat · Ask Inbox · Everything Workbench · CoWork CLI · Terminal Tabs · Browser Workbench · Use Cases · Release Notes 0.5.49 · Platform Updates · Documentation · Changelog · Security · Contributing
| Signal | Current |
|---|---|
| GitHub stars | 359 |
| GitHub forks | 53 |
| Installer/server downloads | 981 |
| Download delta | +7 |
| npm downloads, last week | 259 |
| GitHub views, last 14-ish days | 1,326 total / 489 unique |
| GitHub clones, last 14-ish days | 3,997 total / 956 unique |
Generated 2026-06-15T09:33:31.992Z. These are public GitHub/npm adoption signals, not active-user or in-app telemetry numbers. Full report.
cowork CLI gives terminal users the same local runtime for quick prompts and one-shot tasks.cowork CLI — Type cowork for an interactive terminal UI or cowork run "task" for a local one-shot run. Normal local CLI use shares desktop provider/settings state and does not require a Control Plane token; --remote is the explicit token-gated path. CoWork CLI/multitask, structured input cards, Side Chat, adaptive recovery, and visible routing/fallback state make agent work inspectable while it is running. Chat mode · Side Chat · Multitask@Inbox routing, while the gateway supports 17 messaging channels with specialization by workspace, agent role, guidance, and tool policy. Inbox Agent · Channels@ mentions, message-box / shortcuts, Plugin Store, Skill Store, and external skill directories make the app extensible without giving up local control. Providers · Plugin PacksRecent high-impact additions change the day-to-day product shape: the cowork CLI, Browser Use Cloud routing, Codex Security workflows, automation outcome reporting, real terminal tabs, visible Browser Workbench, Side Chat, message-box shortcuts, Everything Workbench artifacts, and Secure MCP Tunnels. Detailed feature inventory remains below for deeper evaluation.
Stable workflow entry points for the newest high-impact capabilities.
llm-wiki) — first-class workspace-local knowledge bases inspired by Andrej Karpathy's LLM Wiki concept, with deterministic raw-source capture, Obsidian-friendly notes, filed-back outputs, vault search, and vault-health analysis. Learn more.docx opens directly in an editable right-sidebar document surface with Google Docs-style controls, save, copy, external-open, fullscreen mode, and the same functional follow-up composer used by spreadsheet artifacts. .doc, .rtf, .odt, .ott, .pages, and related Word-style formats are recognized with best-effort preview or external-app/folder actions. Learn morekami skill for resumes, one-pagers, white papers, letters, portfolios, diagrams, and slide decks with workspace-local source scaffolding and PDF/PPTX export helpers. Learn morehighlight.js syntax colors), JSON / JSONL / GeoJSON (collapsible tree + raw toggle), CSV / TSV (RFC-4180 table), XLSX, DOCX, PDF (with page/OCR summary), images (fit / actual-size toggle, dimensions, alpha checkerboard), video, audio (with duration), LaTeX, and PPTX. Each format gets its own width profile, a header subtitle showing format-specific metadata, and a unified action bar with Copy path, Show in Finder, Open externally, and Close.read_pdf_visual remains reserved for layout, formatting, and page-appearance questions..mp4, .mov, and .webm files are sampled into representative frames for image-capable models. CoWork extracts a contact sheet and full frame, stores them under .cowork/video-frames/..., and shows those screenshots inline in the task timeline. Learn more.pptx decks render as compact artifact cards and open by default in the resizable right-sidebar presentation viewer. The viewer shows thumbnails, slide navigation, zoom, a white slide canvas, speaker notes, text-first fast loading, cached rendered slide images, fullscreen follow-up context, and background refresh after requested deck edits. Legacy PowerPoint formats are recognized with external-app/folder actions. Learn more.html / .htm pages and built React output such as dist/index.html, build/index.html, or out/index.html render as compact artifact cards and open by default in a resizable right-sidebar sandboxed iframe preview. Fullscreen mode keeps the functional follow-up composer and refreshes after the relevant file or build output changes. React-style source projects without build output show a clear build-output-needed state instead of auto-starting a dev server. Learn morebrowser_provider: "browser-use-cloud" for public HTTP(S) targets. Learn moremanim-video skill for Manim CE explainers, equation walkthroughs, algorithm visualizations, and animated architecture/data stories. Learn morearchitecture-design skill and local Rhino, Blender, and ComfyUI MCP connectors for concept house/building workflows with project-contained artifacts and connector evidence. Learn morereact-best-practices skill for React workspace changes, Next.js feature work, reviews, refactors, data-fetching improvements, bundle-size checks, and rendering-performance fixes. Learn moretaste-skill for stricter anti-slop frontend work with stronger layout variance, typography, motion, and implementation rules.See Everyday Agent, Workflow Intelligence, Dreaming, Core Automation, I Gave CoWork OS Workflow Intelligence, And Now It Learns From Reviewable Work | Full Guide, Features, Heartbeat v3, Providers, and Plugin Packs for current runtime details.
0.5.49 is the current package version. It adds the cowork CLI, Browser Use Cloud routing, bundled Codex Security workflows, automation outcome reporting, Mission Control automation visibility, Usage Insights token heatmaps, prompt composer link chips, public adoption stats, and a broad security/reliability hardening pass. Start with Release Notes 0.5.49, then Features, Getting Started, and the Changelog.
The larger recent feature expansion landed in 0.5.45: Agent Builder, finance/legal packs, channel specialization, Google Workspace Tasks/Slides, mailbox compose/send upgrades, runtime network/sandbox policy controls, Dreaming memory curation, and /multitask lane fan-out. See Release Notes 0.5.45, Managed Agents, Claude-for-Legal Workflows, Multitask Command, and Dreaming.
Download the latest release from GitHub Releases:
| Platform | Download | Install |
|---|---|---|
| macOS | .dmg | Drag CoWork OS into Applications |
| Windows | .exe (NSIS installer) | Run the installer and follow the prompts |
CoWork OS macOS DMGs are currently unsigned, so the first launch needs a one-time Gatekeeper override:
Open the downloaded .dmg and drag CoWork OS into Applications.
Open CoWork OS from Applications. If macOS says "CoWork OS" Not Opened, click Done.
Open System Settings > Privacy & Security, scroll to Security, and click Open Anyway next to "CoWork OS" was blocked to protect your Mac.
In the confirmation dialog, click Open Anyway.
On first startup, macOS may ask for access to the cowork-os Safe Storage keychain item. Enter your Mac login password and click Always Allow so CoWork OS can store local credentials securely.
Release maintainers can create this unsigned DMG/ZIP with npm run package:mac:unsigned.
Windows first launch: Windows SmartScreen may show a warning for unrecognized apps. Click More info > Run anyway to proceed.
First launch asks how you want to power AI: sign in with an existing ChatGPT subscription, use a local Ollama model if one is installed, or add an API key for Claude, OpenAI API, Gemini, OpenRouter, Groq, and other providers. OpenRouter, Gemini through Google AI Studio, and Groq are marked when a free option is available. You can explore the app without AI, but tasks require one working model route.
npm install -g cowork-os
cowork-os
cowork
cowork run "who are you?"
cowork-os launches the desktop GUI. cowork launches the terminal UI, cowork run starts a local one-shot task, and commands like cowork status, cowork sessions list, cowork tools list, cowork mcp list, cowork backup create, and cowork security audit manage the same local profile, provider settings, workspaces, skills, and MCP configuration. Use --remote only when intentionally calling a remote Control Plane endpoint.
Windows npm install notes:
- Run
npm install -g cowork-os/npm uninstall -g cowork-osfrom%USERPROFILE%(or another neutral directory), not from%APPDATA%\npm\node_modules\cowork-os, to avoidEBUSYlock errors.- On Windows ARM64, first launch may take longer while native modules are rebuilt; this can run multiple fallback steps before the app opens.
- If native rebuild fails, install Visual Studio Build Tools 2022 (C++) and Python 3, then retry.
- If startup logs show
ERR_FILE_NOT_FOUND ... dist/renderer/index.html, reinstall the latest package and check Troubleshooting.
git clone https://github.com/CoWork-OS/CoWork-OS.git
cd CoWork-OS
npm install && npm run setup
npm run build && npm run package
Windows prerequisites: Native module setup may require Visual Studio Build Tools 2022 (C++) and Python 3. On Windows ARM64, setup automatically falls back to x64 Electron emulation when ARM64 native prebuilds are unavailable.
npm run setupalso installs local git hooks (.githooks/) including a pre-commit secret scan. If needed, reinstall hooks withnpm run hooks:install.
See the Development Guide for prerequisites and details.
cowork run "...". No workspace needed — a private starter workspace is used automatically if you don't select one./multitask [N] <task>./side to open Side Chat for read-only questions about the selected running session, or use the title-bar terminal and browser buttons when you need direct CLI or web inspection beside the task.
Task execution stays visible with live progress, grouped work, and reviewable outputs.
Task-based execution with dynamic re-planning, five runtime modes (Chat, Execute, Plan, Analyze, Verified) plus orchestration toggles (Autonomous, Collaborative, Multi-LLM, Think With Me), /multitask lane fan-out, a shared turn kernel, metadata-driven tool scheduling, graph-backed delegation, typed worker roles, optional workflow-pipeline execution with per-phase model routing, agent teams with persistence, agent comparison, git worktree isolation, AI playbook, and performance reviews. Learn more
Skills now follow an additive runtime model: CoWork can proactively shortlist or apply a relevant skill, but the original task remains canonical. Skills add context and scoped execution modifiers instead of replacing the task prompt. Learn more
Real terminal tabs now sit beside the task runtime: xterm.js renders the terminal, node-pty owns the OS pseudoterminal, macOS uses the user's login shell, and Windows uses cmd.exe through ConPTY/winpty. This makes CoWork a stronger everyday developer workbench because repository work, agent execution, approvals, browser testing, and direct CLI sessions no longer require switching to a separate terminal app. Learn more
Side Chat gives active sessions a read-only inspection lane. /side [question] opens a right-side conversation about the selected running task with hidden inherited parent context, a fresh parent-status snapshot for progress questions, a side-only visible transcript, and mutating tools denied. Learn more
Agents Hub collects reusable managed agents, templates, and starter prompts.
Chronicle is an opt-in desktop-only recent-screen context lane for vague on-screen references such as this, that, the failing one, latest draft, or why is this failing. Configure it from Settings > Memory Hub > Chronicle: passive capture is consent-gated, can be paused from Settings or the tray, resolves through screen_context_resolve, and promotes only task-used observations into existing recall, evidence, and optional linked screen_context memory entries instead of creating a second memory system. Learn more
llm-wiki)CoWork OS includes llm-wiki as a bundled, first-class research-vault workflow inspired by Andrej Karpathy's LLM Wiki idea: keep a /raw corpus, build durable linked notes on top, and make the result easy for agents to traverse later.
You can launch it from the GUI with a normal prompt such as Build a persistent Obsidian-friendly research vault for GRPO papers, from the welcome/onboarding starter cards, or with /llm-wiki when you want explicit slash syntax.
The welcome-screen Research vault browser is optional and disabled by default. Enable it from Settings > Appearance > Home widgets > Show research vault when you want the research/wiki vault card visible near the composer.
llm-wiki creates and maintains a workspace-local markdown wiki with:
raw/ source capturesoutputs/SCHEMA.md, index.md, log.md, and inbox.mdIt works in desktop and gateway channels, supports inline chaining, and writes inspectable run artifacts alongside the persistent vault. GUI-first prompts can start the flow even before you supply a topic, in which case CoWork asks one short scoping question first. Learn more
Operator Runtime Visibility makes the runtime's learning and routing visible: task detail surfaces now show the learning progression, unified recall spans tasks/messages/files/workspace notes/memory/KG, shell sessions preserve operator state, and live routing/fallback events are surfaced in Mission Control and the task UI. Learn more
Workflow Intelligence reflections now use the same runtime with stricter safeguards: they start only after memory services are initialized, write durable target-scoped artifacts under .cowork/subconscious/ for compatibility, default to reviewable suggestions, learn from act/edit/snooze/dismiss/ignore feedback, and hand memory-specific drift/correction evidence to Dreaming for reviewable memory curation. Trusted code-change auto-create paths still require isolated git worktrees and skip non-git workspaces when isolation is required. See Workflow Intelligence, Dreaming, and Troubleshooting.
Completion state and file availability are now explicit:
Task complete with filename/count and actions for Open file, Show in Finder, and View in Files.xlsx, .xls, .xlsm, .csv, and .tsv open into a resizable editable sidebar by default; .numbers, .gsheet, .ods, and .xlsb are recognized as spreadsheet artifacts with external-app/folder actions. Editable sheets can expand into fullscreen spreadsheet mode with copy/save controls, zoom, attachments, voice input, and model selection for follow-up prompts.docx opens into a resizable editable sidebar by default and can expand into fullscreen document mode with a Google Docs-style toolbar, save, copy, attachments, voice input, model selection, follow-up context, and automatic preview refresh after follow-up edits. .doc, .rtf, .odt, .ott, .pages, and related formats are recognized with preview/external actions according to local parser support.tex, compile it with a system TeX engine, and show the source plus rendered PDF together with Summary, source, and PDF tabsparse_document on demand instead of stuffing the whole PDF into every turn; visual PDF inspection stays on read_pdf_visual.pptx outputs show inline deck cards in task events and assistant summaries, then open into a resizable sidebar or fullscreen viewer with thumbnails, previous/next navigation, zoom, speaker notes, fast text-first loading, cached rendered slide images, external actions, and follow-up prompt context. .ppt, .pptm, .potx, .potm, .ppsx, and .ppsm are recognized with external-app/folder actions.html / .htm files and built React output entrypoints show compact web page cards, then open into a resizable sidebar or fullscreen sandboxed iframe preview with browser/folder/copy actions, persisted sidebar width, and follow-up prompt context. React-style projects without dist, build, or out HTML output show a build-output-needed preview state rather than auto-running a dev serverLong-running tasks now have clearer operator handoffs and stronger recovery defaults:
30/30 style windows; explicit maxTurns / windowTurnCap still opt tasks into capped behavior/workspace/... aliases and drifted relative paths can be normalized back into the active workspace or pinned task root, with strict-fail policies available when you want hard enforcementThe top of this README is intentionally opinionated about what matters first. The broader surface area is still part of CoWork OS:
| Area | Current coverage |
|---|---|
| Agent runtime | Chat, Execute, Plan, Analyze, Verified, Think With Me, Autonomous, Collaborative, Multi-LLM, /multitask, structured input cards, Side Chat, dynamic re-planning, workflow pipelines, agent comparison, performance reviews, shell-session continuity, completion/resume coherence, and runtime recovery |
| Agent operations | Agents Hub, reusable managed agents, managed sessions, agent teams, Mission Control, visual boards, global queue visibility, task pinning, task wrap-up, sub-task navigation, external ACP/A2A delegation, restart-safe ACP tasks, remote cancel, and graph-backed orchestration |
| Developer workbench | Repository work, real PTY terminal tabs, title-bar terminal/browser toggles, shell tools, git worktree isolation, Browser Workbench, Browser V2 automation, responsive viewport QA, diagnostics, screenshots, annotation, web page previews, Live Canvas, Build Mode, React/Next.js guidance, and high-agency frontend design |
| Knowledge work artifacts | Editable document artifacts, spreadsheet artifacts, presentation artifacts, web page artifacts, paired LaTeX/PDF outputs, smart PDF attachments, format-aware file preview, designed editorial documents, generated images, generated videos, and programmatic Manim technical videos |
| Inbox and communications | Inbox Agent, Classic and Today inbox modes, Ask Inbox, hybrid mailbox search, editable AI drafts, manual reply/reply-all/forward, sender cleanup, commitments, Gmail forwarding automations, @Inbox routing, voice mode, outbound calls, and 17 messaging channels |
| Automation and memory | Routines, scheduled tasks, webhooks, event triggers, Workflow Intelligence, Heartbeat, Reflection, Dreaming, Suggestions, AI Playbook, adaptive style learning, Usage Insights, persistent memory, Knowledge Graph, ChatGPT history import, durable runtime context, context compaction, Supermemory, and Chronicle |
| Integrations and extensibility | 35 LLM provider options, ordered LLM/search fallback chains, provider-aware prompt caching, 47 MCP connectors, native and MCP-backed Google Workspace coverage, 36 bundled plugin packs, 338 pack skills, 263 pack shortcuts, 42 pack agent roles, 150 built-in skills, Plugin Store, Skill Store, external skill directories, and MCP client/host/registry support |
| Operations and deployment | Profiles, profile import/export, Devices, remote workspaces, remote task dispatch, remote file picking, Control Plane, Linux server package, self-hosting, Tailscale/SSH remote access, Zero-Human Company Ops, Digital Twin personas, company-linked operator agents, and best-fit Support/IT/Sales workflow packs |
| Safety and reliability | Approval workflows, sandboxed execution, workspace/profile permission rules, network/sandbox policy controls, private-memory filtering, session-scoped location approvals, command/path containment, import scanning and quarantine, encrypted storage, local-first data handling, renderer event caps, off-main-thread memory recall, and long-session cleanup |
Centralized orchestration and monitoring cockpit with clear separation between Heartbeat-enabled agents, the global runtime queue, workspace-scoped Mission Board work, the real-time activity feed, core automation profile visibility, and a Core Harness view for traces, failure clusters, evals, experiments, and learnings. Learn more | Core Automation
Mission Control shows global runtime queue state, scoped board work, agent status, and operational review without mixing the concepts.
The Devices tab turns CoWork OS into a multi-machine control surface. Save and reconnect remote CoWork nodes, inspect device summaries (activity, apps, storage, alerts, resource signals), launch tasks against a selected machine, browse that machine's remote workspaces, and attach files directly from the remote filesystem before dispatching a task. Learn more
Automations are now organized around a hard boundary: Workflow Intelligence is the always-on cognitive loop, while Routines are the main saved-automation product layered on top of lower-level execution surfaces. Scheduled Tasks, Webhooks, and Event Triggers still exist, but they now also serve as advanced or compiled backends for routines rather than competing first-class automation concepts. Task view can turn the current task into a routine from the three-dot menu with Add automation..., preserving the source task title, ID, and cowork://tasks/<taskId> deeplink while continuing the same thread by default. The home dashboard and routines panel surface recent automation suggestions/runs, while the optional welcome-screen Next actions widget is disabled by default and can be enabled from Settings > Appearance > Home widgets > Show next actions. Scheduled Tasks shows run health, latest results, delivery status, and links for generated sessions or continued threads so you can monitor background systems without hunting through tabs. Learn more | Task Automations
Automations separate scheduled work, triggered runs, and recurring background systems.
Everyday Agent turns personal priorities into a reviewable operating plan: goals, live plan items, priority queues, enabled capabilities, and focused settings stay visible instead of hiding inside a generic chat thread. Learn more
Everyday Agent keeps active goals, plans, and priority queues visible.
Capability settings make each Everyday Agent lane explicit and adjustable.
CoWork OS can be configured as a founder-operated autonomous company shell: venture workspace kit context, a dedicated Settings > Companies control surface, company-linked operator agents, automation profiles, strategic planner issue generation, and Mission Control ops monitoring. Create the company in Companies, activate operator personas such as Company Planner and Founder Office Operator, then attach automation where needed and monitor the company loop from Mission Control. Learn more | Core Automation
Company workspaces can track goals, operators, and autonomous company loops.
Role-specific AI twins that handle cognitive overhead as optional persona presets. Pick a template (Software Engineer, Engineering Manager, Product Manager, VP, Founder Office Operator, Company Planner, and more), customize it, and activate it as a role preset with recommended skills and prompt/personality defaults. Twins can be linked to a company for company-aware operations, but they no longer own heartbeat or Workflow Intelligence policy directly. Learn more
Persona presets give managed agents role-specific defaults and tools.
Agent-driven visual workspace for interactive HTML/CSS/JS content, data visualization, and iterative image annotation. Build Mode adds a phased idea-to-prototype workflow with named checkpoints and revert support. Learn more
Unified AI gateway across 17 channels with security modes, rate limiting, ambient mode, scheduled tasks, channel/chat/thread specialization, and a shared message lifecycle for commands, active-task follow-ups, cancellations, progress delivery, skill slashes, and scheduled outputs. WhatsApp supports /new, /new temp, /stop, editable progress updates, and hidden temporary scratch workspaces; Slack supports multiple workspaces and channel specialization, Telegram supports group/topic specialization plus group-routing policies and allowlists, Discord can be limited to specific guilds and specialized per channel/thread, and Feishu/Lark plus WeCom are first-class channels. Learn more | Per-channel guides | User guide | Message lifecycle
Channel settings specialize routing, security, and workspace behavior per messaging surface.
Local-first inbox workspace that turns email into an action queue while preserving normal email-client controls. It keeps cached mail visible on restart, syncs in the background, supports manual reply/reply-all/forward, and surfaces the right next step for each thread: triage, draft, cleanup, commitment tracking, and scheduling. Learn more
@Inbox composer routing: type @Inbox or @inbox ... in the main composer to open Inbox Agent, switch to Ask Inbox, and run the query there
Inbox Agent combines mailbox triage, thread evidence, drafts, and next actions.
Location-aware work is available when explicitly approved for the current session. CoWork can use native desktop location helpers on macOS, Windows, and Linux, fall back to IP-based location when configured, and pass coordinates into Maps MCP tools for geocoding, reverse geocoding, route estimates, and nearby-place search. Location permission cannot be auto-approved or persisted, so local errands, travel planning, route comparisons, and nearby search remain deliberate user-approved actions. Learn more
Built-in cloud infrastructure tools — no external processes or MCP servers needed. The agent can spin up sandboxes, register domains, and make payments natively.
All infrastructure operations that involve spending (domain registration, x402 payments) require explicit user approval. Configure in Settings > Infrastructure. Learn more
Advanced web scraping powered by Scrapling with anti-bot bypass, stealth browsing, and structured data extraction. Three fetcher modes — fast HTTP with TLS fingerprinting, stealth with Cloudflare bypass, and full Playwright browser. Includes batch scraping, persistent sessions, proxy support, and five built-in skills (web scraper, price tracker, site mapper, lead scraper, content monitor). Configure in Settings > Web Scraping. Learn more
@ in the message box to choose configured integrations. Google Workspace appears as service-specific options: Gmail, Google Drive, Google Calendar, Google Docs, Google Sheets, Google Slides, Google Tasks, and Google Chat when native or MCP-backed tools are available. The Google Calendar chip can include both calendar_action and google-workspace.calendar_* tools for scheduling, availability, and event CRUD. Mentions render as icon+name chips and are passed as soft routing hints, not permission grants. Learn moreglob/grep/edit_file, Playwright browser automation, MCP client/host/registry
Connector setup covers productivity, CRM, support, analytics, and payment tools.
Real-time overview of your active integrations, always visible in the right panel. Shows connected MCP connectors (47 available) and native integrations with branded Lucide icons (HubSpot, Salesforce, Google Workspace, Discord, GitHub, Postgres, and more) and green status dots, plus enabled skills from active packs. Each section shows 4 items with internal scrolling for more. Auto-refreshes every 30 seconds. Learn more
Dashboard with task metrics, cost/token tracking by model, prompt-cache read telemetry (cachedTokens and cache-read rate where available), activity heatmaps (day-of-week and hourly), top skills usage, per-pack analytics, persona-level success/retry/cost breakdowns, and task-result thumbs up/down quality signals with 7/14/30-day period selection. Access from Settings > Usage Insights. Learn more
Health pulls personal signals into a private, action-oriented view for readiness, notes, and workflow state.
Health keeps personal signals organized for review and action.
35 provider options, with 14 built-in providers and 21 compatible/gateway providers. Use cloud APIs, supported subscription logins, or fully offline Ollama, configure an ordered fallback chain for runtime failover, and get default-on prompt caching on supported Claude and GPT-style routes. Claude supports both direct API keys and Claude subscription tokens from claude setup-token; Grok supports both xAI API keys and SuperGrok browser OAuth with grok-4.3 as the default subscription model. Learn more
Model settings centralize providers, fallback routing, authentication, and model choices.
Unified plugin platform with 36 bundled packs (Engineering, DevOps, Product, Sales, QA, Finance, Claude-for-Legal practice packs, CoWork Shortcuts, and more), each bundling skills, agent roles, connectors, slash command aliases, and "Try asking" prompts. Packs can link to Digital Twin personas as optional role presets.
SKILL.md bundles, with managed scan reports and quarantine for unsafe importsAccess from Settings > Customize. Learn more
CoWork OS ships purpose-built packs and Tier-1 connectors for three operational lanes where governed AI delivery has the clearest ROI:
| Lane | Pack | Connectors |
|---|---|---|
| Support Ops | Customer Support Pack | Zendesk, ServiceNow |
| IT Ops | DevOps Pack | ServiceNow, Jira, Linear |
| Sales Ops | Sales CRM Pack | HubSpot, Salesforce |
These are the workflows where approval gates, local data control, and measurable outcome delivery pay off most — and where CoWork OS is a vendor-swap-friendly alternative to point solutions or BPO tooling. Learn more
~/Library/Application Support/cowork-os/skills/ (macOS) or %APPDATA%\cowork-os\skills\ (Windows)SKILL.md, and review quarantine/report state for imported skillsText-to-speech (ElevenLabs, OpenAI, Web Speech API), speech-to-text (Whisper), and outbound phone calls. Learn more
Built-in structured entity and relationship memory backed by SQLite. The agent builds a knowledge graph of your workspace — people, projects, technologies, services, and their relationships — with 10 dedicated tools, FTS5 search, multi-hop graph traversal, temporal validity on edges (valid_from / valid_to), historical as_of queries, auto-extraction from task results, and confidence scoring with decay. Learn more
Persistent memory with privacy protection, FTS5 search, LLM compression, and a contract-driven workspace kit (.cowork/) for durable human-edited context. The runtime now makes memory explicit as a four-layer wake-up model: L0 Identity and L1 Essential Story are prompt-visible by default, while L2 Topic Packs and L3 Deep Recall stay tool-driven through memory_topics_load, search_sessions, search_memories, and exact-span search_quotes. Durable writes can also pass through Memory Write Governance, which stages archive, curated, background, or external-provider writes for explicit approval depending on Memory Hub settings. Opt-in Durable Runtime Context adds task-scoped context_grep / context_describe recall for compacted active-task facts without broadening into cross-task memory. Runtime-native checkpoints capture both compact structured summaries and verbatim evidence packets before compaction, on meaningful task completion, and periodically during long runs.
The workspace kit separates workspace-wide files such as AGENTS.md, USER.md, MEMORY.md, TOOLS.md, SOUL.md, IDENTITY.md, RULES.md, VIBES.md, and LORE.md from project-scoped files such as .cowork/projects/<projectId>/CONTEXT.md and .cowork/projects/<projectId>/ACCESS.md. Special files get dedicated lifecycle handling: BOOTSTRAP.md is a one-time onboarding checklist tracked through .cowork/workspace-state.json, while HEARTBEAT.md is reserved for recurring Heartbeat v3 checklist work instead of general task context.
Every tracked file follows a shared parser/linter model with freshness windows, secret detection, missing-file status, and revision snapshots stored under .cowork/**/.history/. Workspace kit health is surfaced in the app and can be checked locally with npm run kit:lint for human-readable output or JSON export. Import your ChatGPT history to eliminate the cold-start problem — CoWork OS knows you from day one. Imported history stays local in SQLite and uses privacy filtering; selected sensitive settings/fields use OS keychain/AES-backed encryption, but the main SQLite file is not whole-file encrypted. Structured memory observations add inspectable local metadata, progressive recall tools, Memory Hub privacy controls, deterministic rebuild/backfill, and soft-delete suppression on top of archive memory. Memory Write Governance can stage durable memory writes in pending_memory_writes, atomically claim approvals as applying, and block sensitive external-memory payloads before they are stored in the approval queue. Durable Runtime Context stores sanitized active-task messages and source-linked summary DAG nodes when enabled, is erased by Clear memory, and keeps context_grep active-task scoped unless the user explicitly asks for another task. Optional Supermemory integration adds an external provider lane with supermemory_profile, supermemory_search, supermemory_remember, and supermemory_forget, plus optional prompt-time profile injection and background mirroring of non-private local memory captures. Proactive session compaction automatically generates comprehensive structured summaries when context reaches 90% capacity, and checkpoint capture preserves exact supporting spans so recall quality survives compaction. Learn more | Structured Memory | Durable Runtime Context | Supermemory | Context Compaction
┌─────────────────────────────────────────────────────────────────┐
│ Security Layers │
│ Channel Access Control │ Guardrails & Limits │ Approval Flows │
└─────────────────────────────────────────────────────────────────┘
↕
┌─────────────────────────────────────────────────────────────────┐
│ React UI (Renderer) │
│ Task List │ Timeline │ Approval Dialogs │ Live Canvas │
└─────────────────────────────────────────────────────────────────┘
↕ IPC
┌─────────────────────────────────────────────────────────────────┐
│ Agent Daemon (Main Process) │
│ Task Queue │ Agent Executor │ Tool Registry │ Cron Service │
└─────────────────────────────────────────────────────────────────┘
↕
┌─────────────────────────────────────────────────────────────────┐
│ Execution Layer │
│ File Ops │ Skills │ Browser │ LLM Providers (35) │ MCP │
│ Infrastructure (E2B Sandboxes │ Domains │ Wallet │ x402) │
└─────────────────────────────────────────────────────────────────┘
↕
┌─────────────────────────────────────────────────────────────────┐
│ SQLite DB │ Knowledge Graph │ MCP Host │ WebSocket │ Remote Access │
└─────────────────────────────────────────────────────────────────┘
See Architecture for the full technical deep-dive.
Top security score on ZeroLeaks — outperforming many commercial solutions
View Full Report
sandbox-exec (native), Docker containers, or process-level isolation on Windowstests/security/ and 405 control-plane/WebSocket-related casesSee Security Guide and Security Architecture for details.
| Mode | Platform | Guide |
|---|---|---|
| Desktop App | macOS, Windows | Getting Started |
| Packaged Server | Linux x64 VPS | VPS Guide |
| Self-Hosted | GitHub release tarball / Docker / systemd | Self-Hosting |
| Remote Access | Tailscale / SSH | Remote Access |
See CHANGELOG.md for the full history of completed features.
| Guide | Description |
|---|---|
| Getting Started | First-time setup and usage |
| Beginner's Guide | Practical guide to what CoWork OS is for and which workflows to try first |
| Release Notes 0.5.49 | What is new in the latest release |
| Composer Mentions | @ autocomplete for agents, configured integrations, files, rich integration chips, and @Inbox routing |
| Message Box Shortcuts | / picker for deterministic app commands and skill-backed workflow shortcuts |
| Side Chat | Right-side read-only questions about an active running session without steering or stopping the parent task |
| Claude-for-Legal Workflows | Bundled legal practice slash commands, editable picker selection, and main-view matter intake cards |
| Multitask Command | /multitask [N] <task> lane fan-out through collaborative team runs |
| Use Case Showcase | Comprehensive guide to what you can build and automate |
| Features | Complete feature reference |
| Desktop Location & Maps | Explicitly approved desktop location, geocoding, routes, and nearby-place workflows |
| Everything Workbench | Unified in-app artifact model for docs, sheets, decks, web pages, PDFs, and live browser sessions |
| Video Attachments | Uploaded video analysis through extracted contact sheets, representative frames, and inline task timeline screenshots |
| Browser Workbench | Visible in-app browser for website testing, responsive viewport QA, screenshots, annotation, diagnostics, and Browser V2 automation |
| Browser V2 Architecture | Unified browser session manager, adapters, snapshot refs, diagnostics, safety, and verification contract |
| Chat Mode | Direct chat mode, same-session follow-ups, and the narrow PDF-attachment read-only analysis exception |
| Platform Updates | Detailed implementation notes for integration setup, skill proposals, workspace-kit contracts, and bootstrap lifecycle |
| Channels | Messaging channel setup (17 channels) |
| Channel User Guides | End-user features and best practices across all messaging channels |
| Dedicated Channel Guides | Separate user guide pages for WhatsApp, Telegram, Discord, Slack, Teams, Google Chat, Signal, Email, and more |
| Gateway User Guide | End-user guide and best practices for using CoWork from WhatsApp and other channels |
| Gateway Message Lifecycle | Remote command routing, active-task policy, skill slashes, delivery, and scheduled channel outputs |
| X Mention Triggers | Configure do: mention-triggered task ingress on desktop and headless |
| Providers | LLM and search provider configuration, costs, and fallback chains |
| Development | Build from source, project structure |
| Architecture | Technical architecture deep-dive |
| Skills Runtime Model | Canonical prompt invariant, additive skill application, routing shortlist model, and use_skill contract |
| LLM Wiki | First-class research vault workflow, slash syntax, vault layout, analyzer outputs, and Obsidian-friendly knowledge-base behavior |
| Kami Skill | Bundled editorial document workflow for resumes, one-pagers, white papers, diagrams, and slide decks |
| manim-video Skill | Bundled Manim CE workflow for technical animation, project scaffolding, and draft-to-production render flow |
| Architecture Design Skill | Bundled Rhino, Blender, and ComfyUI orchestration workflow for concept architecture artifacts |
| React Best Practices Skill | Bundled React and Next.js guidance for feature work, refactors, reviews, data fetching, bundle size, and rendering performance |
| Workflow Intelligence | Memory + Heartbeat + Reflection + Dreaming + Suggestions model, reviewable outputs, and feedback learning |
| Dreaming | Background memory curation, Dreaming runs/candidates, trigger sources, and review-first memory maintenance |
| Core Automation | Runtime boundary for Workflow Intelligence, automation profiles, and the core harness |
| Task Automations | Create task-sourced routines and scheduled thread follow-ups from a task's overflow menu |
| Heartbeat v3 | Default two-lane heartbeat architecture, signals, Pulse, Dispatch, and automation-profile-backed operator semantics |
| Security Guide | Security model and best practices |
| Enterprise Connectors | MCP connector development |
| Secure MCP Tunnels | Self-hosted outbound-only private MCP access, relay setup, policy controls, and audit logs |
| Self-Hosting | Docker and systemd deployment |
| VPS/Linux | Headless server deployment |
| Remote Access | Tailscale, SSH tunnels, WebSocket API |
| Knowledge Graph | Structured entity/relationship memory |
| Durable Runtime Context | Opt-in active-task durable recall, context_grep, context_describe, summary DAGs, and testing prompts |
| Context Compaction | Proactive session compaction with structured summaries and chat-history summarization |
| Mission Control | Agent orchestration dashboard |
| Subconscious Loop | Compatibility redirect for the former name of Workflow Intelligence |
| Zero-Human Company Ops | Founder-directed company planning, operators, and Mission Control ops workflows |
| Plugin Packs | Plugin platform, Customize panel, and Plugin Store |
| Skill Store & External Skills | ClawHub support, external skill imports, and managed-skill install flows |
| Best-Fit Workflows | Support Ops, IT Ops, and Sales Ops — where CoWork OS delivers the strongest ROI |
| Admin Policies | Enterprise admin policies and organization pack management |
| Digital Twins | Optional role-based persona presets and cognitive offload without core-runtime ownership |
| Digital Twins Guide | Comprehensive guide with scenarios and expanded job areas |
| Windows npm Smoke Test | Clean Windows install/launch validation checklist for npm releases |
| Troubleshooting | Common issues and fixes |
| Uninstall | Uninstall instructions |
Users must comply with their model provider's terms: Anthropic · AWS Bedrock
See CONTRIBUTING.md for guidelines.
MIT License. See LICENSE.
"Cowork" is an Anthropic product name. CoWork OS is an independent open-source project and is not affiliated with, endorsed by, or sponsored by Anthropic. If requested by the rights holder, we will update naming/branding.
Run Claude Code as an MCP server so any agent can delegate coding tasks to it
Browser automation using accessibility snapshots instead of screenshots
MCP server integration for DaVinci Resolve Studio
A Jetbrains IDE IntelliJ plugin aimed to provide coding agents the ability to leverage intelliJ's indexing of the codeba