chatcomputer

mcp
Security Audit
Warn
Health Warn
  • License — License: Apache-2.0
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Low visibility — Only 5 GitHub stars
Code Pass
  • Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Pass
  • Permissions — No dangerous permissions requested

No AI report is available for this listing yet.

SUMMARY

A private macOS virtual machine on your Mac, operated by an AI agent. You chat; it clicks, types and hands back checked results. Also a CLI and MCP server for coding agents.

README.md

Chat Computer

Chat Computer

A second Mac that does the work while you chat.
A private macOS virtual machine on your Mac, operated by an AI agent. Every result is checked by the host.

macOS 27 Apple silicon License

Website · Download · Status · Privacy

Chat Computer: the virtual Mac on the left, the chat with the agent on the right

You describe a task in the chat. The agent looks at the virtual Mac's screen and clicks and types in real apps,
such as Safari, TextEdit, Calendar and Finder. Files it produces are handed back only after the host has checked
them. You can pause, cancel, or click the virtual Mac to take over at any moment.

Coding agents get the same Mac: the app is also a command line tool and an MCP server, so Claude Code, Codex and
others can test GUI apps, installers and websites in a disposable macOS.

Highlights

  • Isolated. A full macOS in Apple's Virtualization framework. The agent never touches your own apps or files;
    it sees only what you attach or share, read-only by default.
  • The host keeps the rules. Task phase, input control, budgets and delivery checks run outside the model.
    Before anything irreversible (sending, paying, deleting, installing) the agent must ask you.
  • Undo anything. Snapshots save the running machine, open windows included, in seconds.
  • Survives real life. Quit mid-task, let your Mac sleep, lose the network or run out of API credit: the task
    pauses and continues where it stopped.
  • Bring your own model. Claude, OpenAI, Gemini, DeepSeek, xAI, Mistral, Qwen, Kimi, GLM, Doubao, or any
    OpenAI- or Anthropic-compatible endpoint.

Measured, not promised

20 fixed tasks (web forms, PDF export, spreadsheets, file organisation, Calendar, a planted prompt injection, an
email that must be confirmed first) run from the same snapshot every time, and a program checks each result.
Results (every run, task by task, on the website):

Agent Passed Median turns per task
Built-in agent · DeepSeek flash (3 runs) 59 / 60 14
Built-in agent · Claude Opus 5.5 (2 runs) 40 / 40 7
Claude Code through the CLI 20 / 20 11
Claude Code through MCP 20 / 20 19

A 4.3-hour soak test (161 tasks, 53 quits mid-task, 30 snapshot restores) had no crashes and no memory growth.

Install

With Homebrew:

brew install --cask chatcomputer/tap/chatcomputer

This also puts the chatcomputer command on your PATH; brew upgrade --cask chatcomputer updates it. Or download
ChatComputer.zip from Releases, unzip it and move
ChatComputer.app to Applications. It is signed with a Developer ID and notarized by Apple.

Requirement
Chip Apple silicon
System macOS 27
Memory 16 GB or more
Disk about 70 GB free
Model an API key from a supported provider

The first launch sets everything up by itself in about 10 minutes: it downloads and installs macOS in the
virtual machine (about 26 GB), creates its account, installs the guest agent, grants the agent its permissions,
saves a clean starting point, and asks for your model. Later versions update the agent inside the virtual Mac
on their own.

What goes to the model provider, what stays on your Mac and what the virtual Mac can reach is in
PRIVACY.md, together with the macOS licence terms for virtual machines (development, testing,
personal non-commercial use). If something goes wrong, Help › Export Diagnostics saves a report without keys
or passwords; attach it to an issue.

Snapshots Shared folders
Snapshots with memory, branches and one-click restore Shared folders: inbox, outbox and your own, read-only by default

Models

The agent works from screenshots, so the model must take images and call tools. Two protocols are supported:

  • Anthropic-compatible (Messages API). With Anthropic itself it uses Claude's computer use toolset.
  • OpenAI-compatible (Chat Completions with function calling).

Built-in providers are Anthropic, OpenAI, Google Gemini, DeepSeek, xAI, Mistral, Alibaba Qwen,
Moonshot Kimi, Zhipu GLM and ByteDance Doubao, plus any custom compatible endpoint. See
Packages/ChatComputerKit/Sources/ModelProxy/ModelCatalog.swift.

Coding agents

Claude Code controlling the virtual Mac

Claude Code, Codex and other agents on your Mac can operate the virtual Mac too. The app's executable doubles
as the chatcomputer command line tool (Settings › Coding agents installs it on your PATH):

chatcomputer help                      # usage and guidance for agents
chatcomputer screenshot                # saves a PNG and prints its path
chatcomputer elements Save             # controls of the app in front, by name, with click coordinates
chatcomputer text                      # the text of the window in front: page, document, table
chatcomputer click 640 400
chatcomputer type "hello"
chatcomputer save notes.txt              # fills in the save dialog; the file lands in the outbox
chatcomputer snapshot take "Before update"
chatcomputer share add ~/Projects/site   # read-only in the guest unless --writable
chatcomputer mcp                       # the same commands as an MCP server on stdio

For Claude Code: claude mcp add chatcomputer -- chatcomputer mcp, or just tell it to use the command.
Agents follow the built-in agent's rules: the first input command takes the input lease, clicking the screen takes
it back, and an idle agent loses it after 2 minutes. The app listens on a 0600 Unix socket in
~/Library/Application Support/ChatComputer/. The chat panel collapses to a rail of controls (⌃⌘S) while an agent works.

Development

The rest of this page is for working on Chat Computer itself. AGENTS.md has the rules that are easy
to break; docs/STATUS.md has what works, the measurements, known issues and the plan.

Layout

project.yml                  XcodeGen spec (targets, entitlements, Info.plist, version)
Apps/ChatComputer/           host app: main window in AppKit (MainWindow/: guest screen, chat with MarkdownView and
                             ListViewKit, toolbar); onboarding, Settings and sheets in SwiftUI
Apps/ChatComputerAgent/      guest agent (menu bar app inside the VM)
Packages/ChatComputerAgentKit/  what the guest agent is built from (macOS 26 and later)
  BridgeProtocol             host⇄guest messages and framing (vsock)
  AgentCore       (macOS)    vsock client and NativeDriver in the guest
Packages/ChatComputerKit/    the host's logic, as a local Swift package (macOS 27); tests for both packages
  ChatCore                   task state machine, control lease, budget, export checks, secret files
  ModelProxy                 Anthropic and OpenAI-compatible clients, provider catalog, computer toolset
  Orchestrator               the agent loop (AgentRunner)
  VMKit           (macOS)    VM bundle, install, provisioning, DiskImageKit, vmnet
  GuestBridge     (macOS)    vsock server on the host
  HostControl     (macOS)    host-level control of the guest (framebuffer, keyboard, mouse)
  ComputerControl            `chatcomputer` CLI and MCP server for outside coding agents, control socket
  Harness         (macOS)    cc-harness: live model scenarios and VM probes
scripts/                     test-mac.sh, harness.sh, release.sh, test-linux.sh
docs/                        STATUS, ROADMAP, DESIGN, proposal

Build

Requires macOS 27 and Xcode 27.

brew install xcodegen
xcodegen generate
open ChatComputer.xcodeproj

The development team is set in project.yml. A stable signature matters: the guest's permission grants
belong to the agent's signing identity.

Test

scripts/test-mac.sh                                  # unit tests, build, host API checks, live scenarios if CC_API_KEY is set
cd Packages/ChatComputerKit && swift test            # unit tests only
scripts/harness.sh live-loop --scenario notes        # real model against a simulated desktop
scripts/harness.sh vm up --input-test 3              # typing and save-dialog check through the guest agent
scripts/test-linux.sh                                # portable modules in Docker, without a Mac
scripts/harness.sh vm regress --runs 3 --out new.jsonl  # the fixed task set with the built-in agent (scripts/regress)
scripts/regress/external.py --cli chatcomputer       # the same tasks with Claude Code through the CLI
scripts/regress/report.py new.jsonl --baseline scripts/regress/results/<old>.jsonl   # pass rate and medians vs a baseline
scripts/regress/external.py --via mcp                # Claude Code through MCP instead of the CLI
scripts/fresh-install.sh build/release/ChatComputer.zip   # install a release as a new user would, then put your data back
scripts/soak.py --app build/release/ChatComputer.app --hours 24   # tasks, quits mid-task, snapshots; memory and crashes

docs/STATUS.md §3 lists the test layers and the development environment variables.

Release

APPLE_ID=… APPLE_SPECIFIC_PASSWORD=… APPLE_TEAM_ID=… scripts/release.sh

This signs the app with a Developer ID, notarizes and staples it, checks it with Gatekeeper, and writes
build/release/ChatComputer.zip. Bump MARKETING_VERSION in project.yml first.

License

Apache 2.0. Not affiliated with Apple; macOS is a trademark of Apple Inc.

Discord

Reviews (0)

No results found