ff61b5f81da272ac0a3d1087740823386ca4dcc6
GoodBuddy could share Skills across runtimes, but custom MCP remained limited and DeepSeek Harness could not manage third-party extensions. The app now provides a default-off DSH npm marketplace with managed installation, configuration, failure isolation, and packaged npm support, while assigned custom MCP is available to managed OpenCode, Continue Agent, and DeepSeek Harness in Execute. Third-party DSH install scripts, initialization, and tools run with the current user's permissions. Ask remains read-only at dispatch, and turning off the marketplace hides management without disabling installed plugins. Release note: 新增默认关闭的 DSH 插件市场,并让自定义 MCP 可分配给 OpenCode、Continue 和 DeepSeek Harness;安装第三方插件前会明确提示当前用户权限边界。
GoodBuddy
English | 简体中文
A secure, cross-platform, local-first desktop AI assistant and Agent workspace.
Highlights
- Controlled execution:
Askstays read-only;Executeruns only enabled tools within defined boundaries and records their activity. - Local-first data: Conversations, tasks, artifacts, memory, knowledge bases, and graphs are stored in local SQLite. API keys are encrypted by the operating system.
- Multiple runtimes: Connect directly to models or use OpenCode, Continue, and the preview DeepSeek Harness, with cancellation, timeouts, output limits, and process cleanup.
- Open integrations: Supports OpenAI Responses, OpenAI-compatible Chat Completions, Anthropic Messages, OpenAI Images, Embeddings, cross-runtime Skills and custom MCP, plus a default-off DeepSeek Harness npm plugin marketplace that users enable explicitly.
- Knowledge workspace: Import files, folders, and web pages, then search them with full-text, phrase, vector, and graph retrieval.
- Work management: Organize projects, conversations, tasks, activity, artifacts, memory, Magic Notes, and Smart Heartbeat.
- Remote channels: Connect WeChat ClawBot, WeCom, and DingTalk with separate remote sessions for each sender.
- Desktop context: Add selected files, screenshots, application windows, clipboard content, and voice.
- Offline speech: Use local SenseVoice, Paraformer, and Whisper models.
- Rich responses: Render Markdown, LaTeX, and controlled Mermaid diagrams.
See FEATURES.md for the detailed feature matrix and roadmap.
Install
Download a build from GitHub Releases:
| Platform | Architectures | Formats |
|---|---|---|
| Windows | x64, arm64 |
NSIS, portable ZIP |
| macOS | x64, arm64 |
DMG, ZIP |
| Linux | x64, arm64 |
AppImage, DEB |
Code signing and macOS notarization are not configured yet, so your operating system may display a security warning.
Run from source
Requires Node.js 24 and npm:
git clone https://github.com/mesalogo/goodbuddy.git
cd goodbuddy
npm ci
npm run dev
See BUILD.md for build and packaging instructions.
Privacy and security
- Model requests are sent only to services selected by the user.
- Local data stays in the operating system's application data directory by default.
- The Renderer has no access to raw Electron APIs or model credentials.
- The DeepSeek Harness plugin marketplace is off by default. After it is enabled and a third-party plugin is installed, its install scripts, initialization, and Execute tools run with the current user's permissions. Turning off the marketplace only hides its catalog and management interface; it does not disable or uninstall existing plugins. Installation requires explicit confirmation, and Ask limits only model tool calls.
- Remote delegation is disabled until the user configures an endpoint and token.
- Private-network compatibility permits in-app HTTP and non-standard HTTPS certificates. WeChat credential and media endpoints remain strictly validated.
Contributing
Issues and pull requests are welcome. Read AGENTS.md first, then run:
npm test
npm run typecheck
npm run lint
License
Original GoodBuddy code is released under the 0BSD License. You may use, modify, distribute, and commercialize it freely. Third-party components and resources retain their respective licenses.
Languages
TypeScript
92.1%
CSS
4%
Python
1.9%
JavaScript
1.7%
HTML
0.3%




