# Flock

> A desktop multi-agent harness built with Rust, Tauri, and React, powered by langgraph-rust.

- **Type:** MCP server
- **Install:** `agentstack add mcp-onelevenvy-flock`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Onelevenvy](https://agentstack.voostack.com/s/onelevenvy)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [Onelevenvy](https://github.com/Onelevenvy)
- **Source:** https://github.com/Onelevenvy/flock

## Install

```sh
agentstack add mcp-onelevenvy-flock
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Flock

A desktop multi-agent harness built with Rust, Tauri, and React, powered by langgraph-rust.

**Visual Workflow | Multi-Agent Harness | Built-in Agent | Safe Sandbox & VNC | Cross-Platform | Any API Key**

English | [简体中文](docs/README_zh.md)

> **Note**: This project is built on top of [langgraph-rust](https://github.com/Onelevenvy/langgraph-rust), which is my personal Rust implementation of the LangGraph framework.
>
> **Refactoring History**: Flock has been completely rewritten from the ground up. The original version was a Python-based application using LangGraph, LangChain, and FastAPI as the backend. The current version is a native desktop application with a Rust backend, powered by Tauri for the desktop shell. This rewrite brings significant improvements in performance, reliability, and user experience.
> 
> **Legacy Code**: The original Python codebase is preserved in the `legacy/python` branch for reference.

---

## 📋 Quick Navigation

[Multi-Agent Harness & Workflow](#-multi-agent-harness--workflow) · [Core Features](#-core-features) · [Architecture](#-architecture) · [Quick Start](#-quick-start)

---

## 🤝 Multi-Agent Harness & Workflow — Visual Orchestration for AI Agents

Flock is more than just a chat client. It's a comprehensive **multi-agent harness** combined with a powerful **Visual Workflow Editor**. It orchestrates and runs AI agents locally or inside sandbox containers to read/write files, execute bash commands, browse the web, and run complex pipelines. You see everything the agent does, and you're always in control.

| Capability / Feature | Traditional Chat Clients | Flock (Multi-Agent Harness) |
| :--- | :---: | :---: |
| **Visual Workflow Builder** | No | **Yes** — ReactFlow editor with 10+ node types & streaming execution |
| **AI Operating on Files** | Limited or No | **Yes** — Built-in agent with full filesystem, grep, and glob access |
| **Multi-Step Autonomy** | No | **Yes** — Autonomous LangGraph-rust execution loop with approval prompts |
| **Scheduled Task Automation** | No | **Yes** — Native Cron scheduler for 24/7 unattended workflows |
| **Multi-Agent Collaboration** | No | **Yes** — Auto-detects & orchestrates multiple agents in team networks |
| **Open Source & Extensible** | Rarely | **Yes** — Free, built with Rust & Tauri, fully extensible |

---

## 🌟 Core Features

### 🕸️ Visual Workflow Editor (ReactFlow Engine)
* **Drag-and-Drop Canvas**: Design complex pipelines visually by connecting custom agent and logic nodes.
* **10 Node Types Shipped**:
  * `start` & `answer`: Define workflow inputs and final delivery parameters.
  * `llm` & `agent`: Pure inference nodes and tool-enabled LangGraph agents.
  * `classifier` & `ifelse`: Semantic routing routers and conditional branch checkers.
  * `code`: Custom JS/Python code runners to execute arbitrary transformations.
  * `human`: Interactive interrupts asking for manual feedback or input.
  * `plugin` & `parameter_extractor`: Expose custom tools/plugins and extract structured data.
* **Version Control & Execution History**: Easily manage multiple versions of your visual workflows, track historical execution paths, and debug states incrementally.

### 👥 Human-in-the-Loop (HITL) & Safe Interaction
* **Interactive Tool Approvals**: Crucial actions (like writing files, running bash scripts, or modifying configurations) require explicit user approval before execution. You can inspect the plan, approve, or deny on the fly.
* **VNC Screen Takeover**: Directly interact with sandboxed browser and OS interfaces. When the agent gets stuck on captchas, you can take over mouse/keyboard controls seamlessly.
* **Workflow Breakpoints (`human` node)**: Place manual intervention checkpoints in the visual flow to request human decisions, form submissions, or variable modifications before proceeding.

### 🌐 Browser Automation & Computer Use
* **Playwright Browser**: Scrape web data, click links, and bypass forms using an isolated browser execution engine.
* **Computer Use**: Command virtual desktops using OS-level commands (`xdotool`). The agent monitors framebuffer screen feeds and handles mouse/keyboard events.

### 🤖 Built-in Agent — Zero Configuration
* **Out of the box**: No external CLI tools to download or configure. Paste any API Key (OpenAI, Gemini, Anthropic Claude, AWS Bedrock, or Ollama/local) and start immediately.
* **Skill Extensions**: Extensible via YAML-frontmatter prompts that support Hot-Reloading on file changes.

### 🔒 Safe Sandbox Environment
* **Isolated Environment**: Executes risky shell scripts and code execution safely inside isolated environment containers.
* **VNC Streaming**: Stream sandbox desktops directly into the UI via WebSockets for full visual inspection of the running environment.

### 🔌 MCP & Scheduled Tasks
* **MCP (Model Context Protocol)**: Connect to third-party MCP servers once; all assistants and workflows automatically inherit the newly exposed schemas and tools.
* **Scheduled Cron Tasks**: Set it once, the agent executes scheduled tasks on autopilot. Supports standard cron syntax for automated system maintenance, daily file aggregation, or report generation.

---

## 🏗️ Architecture

```mermaid
graph TD
    UI[Tauri Desktop UI - React + Mantine] |IPC / Tauri Command| TauriHost[src-tauri Core]
    TauriHost |IPC Interface / JSON Protocol| AgentEngine[flock-agent - LangGraph Core]
    AgentEngine -->|Graph State Machine| StateGraph[langgraph-rust]
    AgentEngine |SQLite Checkpointer| DB[(SQLite Database)]
    AgentEngine |Discovery / Frontmatter| Skills[flock-skills]
    
    AgentEngine |Tool Execution| Registry[flock-tools - Tool Registry]
    Registry |Local Host| Builtin[Built-in Tools: Bash, Files, Grep]
    Registry |Model Context Protocol| MCP[MCP Server Registry]
    Registry |Isolated Container| Sandbox[Sandbox Client]
    
    Sandbox |X11 / VNC Server| VNC[x11vnc + websockify] |Websocket Stream| UI
    Sandbox |Playwright / xdotool| Browser[Browser & OS Controls]
```

### Module Breakdown

| Crate | Directory | Purpose |
|-------|-----------|---------|
| `flock-core` | `crates/flock-core` | Shared configuration schemas, SQLite DB models, encryption utilities, and IPC channels. |
| `flock-agent` | `crates/flock-agent` | The core agent executor loop, LangGraph state engine, checkpointer, and memory system. |
| `flock-workflow`| `crates/flock-workflow` | Workflow node logic and JSON-to-LangGraph AST compiler. |
| `flock-tools` | `crates/flock-tools` | Built-in and sandboxed tools, VNC web socket proxies, and sandbox managers. |
| `flock-skills` | `crates/flock-skills` | System prompts loader supporting variable injection and watcher-based hot-reload. |
| `flock-ui` | `flock-ui` | React application featuring Zustand, i18next, and ReactFlow editor. |

---

## 🚀 Quick Start

### Prerequisites
* **Rust**: `1.77.2` or later
* **Node.js**: `18.x` or later

### Install & Run

1. **Clone the Repository**
   ```bash
   git clone https://github.com/Onelevenvy/flock.git
   cd flock
   ```

2. **Install Frontend Dependencies**
   ```bash
   cd flock-ui
   npm install
   ```

3. **Start Development App**
   ```bash
   npm run tauri dev
   ```

4. **Run Backend Tests**
   ```bash
   cargo test --workspace
   ```

---

## 📄 License

Licensed under the Apache License, Version 2.0. See [LICENSE](LICENSE) for details.

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Onelevenvy](https://github.com/Onelevenvy)
- **Source:** [Onelevenvy/flock](https://github.com/Onelevenvy/flock)
- **License:** Apache-2.0

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-onelevenvy-flock
- Seller: https://agentstack.voostack.com/s/onelevenvy
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
