AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified MIT Self-run

CoWork OS

mcp-cowork-os-cowork-os · by CoWork-OS

Local-first personal agentic OS and everything app for coding, knowledge work, web design, automations, and artifacts.

No reviews yet
0 installs
34 views
0.0% view→install

Install

$ agentstack add mcp-cowork-os-cowork-os

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-cowork-os-cowork-os)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of CoWork OS? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

CoWork OS is the GUI-first, CLI-capable local AI super app and everything app for getting real work done. Code, email, research, design web pages, create documents, work with spreadsheets and decks, spawn and manage agents, run automations, and ask for changes from the desktop app or the cowork CLI without jumping between separate coding, mail, browser, Word, Excel, or PowerPoint apps.

Getting Started · Composer Mentions · Message Box Shortcuts · Side Chat · Ask Inbox · Everything Workbench · CoWork CLI · Terminal Tabs · Browser Workbench · Use Cases · Release Notes 0.5.49 · Platform Updates · Documentation · Changelog · Security · Contributing

Public Adoption Signals

| Signal | Current | |---|---:| | GitHub stars | 367 | | GitHub forks | 56 | | Installer/server downloads | 1,133 | | Download delta | +6 | | npm downloads, last week | 42 | | GitHub views, last 14-ish days | 1,226 total / 489 unique | | GitHub clones, last 14-ish days | 3,382 total / 953 unique |

Generated 2026-06-29T08:24:38.821Z. These are public GitHub/npm adoption signals, not active-user or in-app telemetry numbers. [Full report](docs/public-adoption-stats.md).

Why CoWork OS?

  • Local AI super app — CoWork OS keeps coding, email, research, browser testing, documents, spreadsheets, presentations, PDFs, channels, devices, automations, memory, providers, and approvals in one governed local workspace.
  • GUI-first, CLI-capable agent operations — Agents Hub, Mission Control, task timelines, visual boards, teams, devices, and automations remain the main operator console, while the cowork CLI gives terminal users the same local runtime for quick prompts and one-shot tasks.
  • First-class cowork CLI — Type cowork for an interactive terminal UI or cowork run "task" for a local one-shot run. Normal local CLI use shares desktop provider/settings state and does not require a Control Plane token; --remote is the explicit token-gated path. [CoWork CLI](docs/cli.md)
  • Long-running agent runtime — Chat, Execute, Plan, Analyze, Verified, Think With Me, Collaborative, Multi-LLM, /multitask, structured input cards, Side Chat, adaptive recovery, and visible routing/fallback state make agent work inspectable while it is running. [Chat mode](docs/chat-mode.md) · [Side Chat](docs/side-chat.md) · [Multitask](docs/multitask.md)
  • Everything Workbench — Generated documents, spreadsheets, decks, web pages, PDFs, previews, and file outputs open beside the agent with follow-up context, so everyday knowledge work can be created and revised inside CoWork. [Learn more](docs/everything-workbench.md)
  • Developer workbench — Real xterm.js + node-pty terminal tabs, title-bar terminal/browser toggles, Browser Workbench, responsive Browser V2 automation, screenshots, diagnostics, and visible web testing keep repo work, CLI work, and live app QA in the same workspace. [Terminal Tabs](docs/terminal-tabs.md) · [Browser Workbench](docs/browser-workbench.md)
  • Inbox and channels — Inbox Agent handles local-first mail triage, Ask Inbox evidence search, drafts, send/reply/forward, commitments, and @Inbox routing, while the gateway supports 17 messaging channels with specialization by workspace, agent role, guidance, and tool policy. [Inbox Agent](docs/inbox-agent.md) · [Channels](docs/channels.md)
  • Automation and memory loop — Workflow Intelligence, Heartbeat, Reflection, Dreaming, Suggestions, AI Playbook, Chronicle, Knowledge Graph, durable runtime context, and Usage Insights form a reviewable learning loop instead of an invisible background process. [Workflow Intelligence](docs/workflow-intelligence.md) · [Chronicle](docs/chronicle.md)
  • Integrations, providers, and skills — 35 LLM provider options, configurable fallback chains, provider-aware prompt caching, 47 MCP connectors, 36 bundled packs, 150 built-in skills, Composer @ mentions, message-box / shortcuts, Plugin Store, Skill Store, and external skill directories make the app extensible without giving up local control. [Providers](docs/providers.md) · [Plugin Packs](docs/plugin-packs.md)
  • Ops and portability — Zero-Human Company Ops, Digital Twin personas, managed devices, remote access, profiles, profile import/export, and best-fit workflow packs support both personal work and founder/operator-style autonomous company loops.
  • Local-first security — Your data and API keys stay on your machine. Approval workflows, sandboxed execution, configurable guardrails, encrypted storage, session-scoped location prompts, private-memory filtering, and a verified automated test suite keep high-agency work bounded and reviewable.

Recent high-impact additions change the day-to-day product shape: the cowork CLI, Browser Use Cloud routing, Codex Security workflows, automation outcome reporting, real terminal tabs, visible Browser Workbench, Side Chat, message-box shortcuts, Everything Workbench artifacts, and Secure MCP Tunnels. Detailed feature inventory remains below for deeper evaluation.

Ideas & Media

Stable workflow entry points for the newest high-impact capabilities.

  • Ideas panel — curated launchpad of pre-written workflow prompts and capability-aware starting points, with deep links into common tasks.
  • Research vaults (llm-wiki) — first-class workspace-local knowledge bases inspired by Andrej Karpathy's LLM Wiki concept, with deterministic raw-source capture, Obsidian-friendly notes, filed-back outputs, vault search, and vault-health analysis. [Learn more](docs/llm-wiki.md)
  • Everything Workbench — generated documents, spreadsheets, decks, web pages, PDFs, and previews share the same artifact model: task-feed card, sidebar open, fullscreen workspace, follow-up composer, and refresh after the agent finishes the requested edit. It makes CoWork the default place to create, inspect, and revise everyday Word/Excel/PowerPoint-style work. [Learn more](docs/everything-workbench.md)
  • Terminal Tabs — real PTY-backed terminal tabs live inside the task workspace, so coding and CLI work can stay beside agent tasks, artifacts, browser previews, and approvals. [Learn more](docs/terminal-tabs.md)
  • Document artifacts — task-created Word-style files render as compact artifact cards. .docx opens directly in an editable right-sidebar document surface with Google Docs-style controls, save, copy, external-open, fullscreen mode, and the same functional follow-up composer used by spreadsheet artifacts. .doc, .rtf, .odt, .ott, .pages, and related Word-style formats are recognized with best-effort preview or external-app/folder actions. [Learn more](docs/document-artifacts.md)
  • Designed editorial documents — bundled kami skill for resumes, one-pagers, white papers, letters, portfolios, diagrams, and slide decks with workspace-local source scaffolding and PDF/PPTX export helpers. [Learn more](docs/skills/kami.md)
  • Format-aware file preview popup — clicking any file link in chat opens a unified preview modal that adapts to the format. Built-in support for HTML, Markdown, code (with highlight.js syntax colors), JSON / JSONL / GeoJSON (collapsible tree + raw toggle), CSV / TSV (RFC-4180 table), XLSX, DOCX, PDF (with page/OCR summary), images (fit / actual-size toggle, dimensions, alpha checkerboard), video, audio (with duration), LaTeX, and PPTX. Each format gets its own width profile, a header subtitle showing format-specific metadata, and a unified action bar with Copy path, Show in Finder, Open externally, and Close.
  • Smart PDF attachments — uploaded PDFs are copied into the workspace, summarized into a compact prompt excerpt with page/extraction metadata, and read on demand with the document parser when the user asks for summaries, Q&A, extraction, comparison, or transformation. Scanned/image-heavy PDFs keep OCR/scan status visible, PDF excerpts are marked as untrusted document data, and read_pdf_visual remains reserved for layout, formatting, and page-appearance questions.
  • Video attachments — uploaded .mp4, .mov, and .webm files are sampled into representative frames for image-capable models. CoWork extracts a contact sheet and full frame, stores them under .cowork/video-frames/..., and shows those screenshots inline in the task timeline. [Learn more](docs/video-attachments.md)
  • Spreadsheet artifacts — task-created spreadsheet files render as compact artifact cards. Excel workbooks and CSV/TSV files open in the editable right-sidebar viewer; native Numbers, Google Sheets shortcut, ODS, XLSB, and other recognized spreadsheet outputs still get the same card and external-app/folder actions. Fullscreen mode expands editable sheets across the app with cell/range/row/column selection, copy, zoom, add row/column, save, model picker, voice input, attachments, and follow-up task context. [Learn more](docs/spreadsheet-artifacts.md)
  • Presentation artifacts — generated .pptx decks render as compact artifact cards and open by default in the resizable right-sidebar presentation viewer. The viewer shows thumbnails, slide navigation, zoom, a white slide canvas, speaker notes, text-first fast loading, cached rendered slide images, fullscreen follow-up context, and background refresh after requested deck edits. Legacy PowerPoint formats are recognized with external-app/folder actions. [Learn more](docs/pptx-generation-and-preview.md)
  • Web page artifacts — generated .html / .htm pages and built React output such as dist/index.html, build/index.html, or out/index.html render as compact artifact cards and open by default in a resizable right-sidebar sandboxed iframe preview. Fullscreen mode keeps the functional follow-up composer and refreshes after the relevant file or build output changes. React-style source projects without build output show a clear build-output-needed state instead of auto-starting a dev server. [Learn more](docs/web-page-artifacts.md)
  • Browser Workbench / Browser V2 — live website testing opens a visible in-app browser in the right sidebar by default. Browser-use tools target that shared webview through Browser V2, show cursor movement during actions, can resize the page to desktop/tablet/mobile breakpoints for responsive QA, prefer accessibility snapshot refs over selectors, expose console/network/download/storage diagnostics, support screenshots and annotation, and can expand to fullscreen with the normal follow-up composer. Explicit fallback routes include local Playwright, external Chrome/Edge CDP attach with consent, and Browser Use Cloud stealth browsers through browser_provider: "browser-use-cloud" for public HTTP(S) targets. [Learn more](docs/browser-workbench.md)
  • Image generation — configurable provider ordering across Gemini, OpenAI, Azure OpenAI, and OpenRouter.
  • Video generation — text-to-video and image-to-video routing with polling tools and inline preview.
  • Programmatic technical video — bundled manim-video skill for Manim CE explainers, equation walkthroughs, algorithm visualizations, and animated architecture/data stories. [Learn more](docs/skills/manim-video.md)
  • Architecture design orchestration — bundled architecture-design skill and local Rhino, Blender, and ComfyUI MCP connectors for concept house/building workflows with project-contained artifacts and connector evidence. [Learn more](docs/skills/architecture-design.md)
  • React/Next.js implementation guidance — bundled react-best-practices skill for React workspace changes, Next.js feature work, reviews, refactors, data-fetching improvements, bundle-size checks, and rendering-performance fixes. [Learn more](docs/skills/react-best-practices.md)
  • High-agency frontend design — bundled taste-skill for stricter anti-slop frontend work with stronger layout variance, typography, motion, and implementation rules.

See [Everyday Agent](docs/everyday-agent.md), [Workflow Intelligence](docs/workflow-intelligence.md), [Dreaming](docs/dreaming.md), [Core Automation](docs/core-automation.md), [I Gave CoWork OS Workflow Intelligence, And Now It Learns From Reviewable Work | Full Guide](docs/continual-learning-in-cowork.md), [Features](docs/features.md), [Heartbeat v3](docs/heartbeat-v3.md), [Providers](docs/providers.md), and [Plugin Packs](docs/plugin-packs.md) for current runtime details.

Latest Release

0.5.49 is the current package version. It adds the cowork CLI, Browser Use Cloud routing, bundled Codex Security workflows, automation outcome reporting, Mission Control automation visibility, Usage Insights token heatmaps, prompt composer link chips, public adoption stats, and a broad security/reliability hardening pass. Start with [Release Notes 0.5.49](docs/release-notes-0.5.49.md), then [Features](docs/features.md), [Getting Started](docs/getting-started.md), and the [Changelog](CHANGELOG.md).

The larger recent feature expansion landed in 0.5.45: Agent Builder, finance/legal packs, channel specialization, Google Workspace Tasks/Slides, mailbox compose/send upgrades, runtime network/sandbox policy controls, Dreaming memory curation, and /multitask lane fan-out. See [Release Notes 0.5.45](docs/release-notes-0.5.45.md), [Managed Agents](docs/managed-agents.md), [Claude-for-Legal Workflows](docs/claude-for-legal.md), [Multitask Command](docs/multitask.md), and [Dreaming](docs/dreaming.md).

Quick Start

Download the App

Download the latest release from GitHub Releases:

| Platform | Download | Install | |----------|----------|---------| | macOS | .dmg | Drag CoWork OS into Applications | | Windows | .exe (NSIS installer) | Run the installer and follow the prompts |

macOS unsigned app workaround

CoWork OS macOS DMGs are currently unsigned, so the first launch needs a one-time Gatekeeper override:

  1. Open the downloaded .dmg and drag CoWork OS into Applications.
  1. Open CoWork OS from Applications. If macOS says "CoWork OS" Not Opened, click Done.
  1. Open System Settings > Privacy & Security, scroll to Security, and click Open Anyway next to "CoWork OS" was blocked to protect your Mac.
  1. In the confirmation dialog, click Open Anyway.
  1. On first startup, macOS may ask for access to the cowork-os Safe Storage keychain item. Enter your Mac login password and click Always Allow so CoWork OS can store local credentials securely.

Release maintainers can create this unsigned DMG/ZIP with npm run package:mac:unsigned.

> Windows first launch: Windows SmartScreen may show a warning for unrecognized apps. Click More info > Run anyway to proceed.

> First launch asks how you want to power AI: sign in with an existing ChatGPT subscription, use a local Ollama model if one is installed, or add an API key for Claude, OpenAI API, Gemini, OpenRouter, Groq, and other providers. OpenRouter, Gemini through Google AI Studio, and Groq are marked when a free option is available. You can explore the app without AI, but tasks require one working model route.

Or Install via npm

npm install -g cowork-os
cowork-os
cowork
cowork run "who are you?"

cowork-os launches the desktop GUI. cowork launches the terminal UI, cowork run starts a local one-shot task, and commands like cowork status, cowork sessions list, cowork tools list, cowork mcp list, cowork backup create, and cowork security audit manage the same local profile, provider settings, workspaces, skills, and MCP configuration. Use --remote only when intentionally calling a remote Control Plane endpoint.

> Windows npm install notes: > - Run npm install -g cowork-os / npm uninstall -g cowork-os from %USERPROFILE% (or another neutral dire

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.