by PM-Shawn
Open-source alternative to Claude Cowork — a local-first AI agent desktop app · multi-model · self-evolving skills · privacy-first
# Add to your Claude Code skills
git clone https://github.com/PM-Shawn/Abu-CoworkLast scanned: 7/5/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@babel/core: @babel/core: Arbitrary File Read via sourceMappingURL Comment",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware",
"severity": "high"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Large numeric range defeats documented `max` DoS protection",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "echarts: Apache ECharts has a cross-site scripting (XSS) vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild allows arbitrary file read when running the development server on Windows",
"severity": "low"
},
{
"type": "npm-audit",
"message": "express-rate-limit: express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network",
"severity": "high"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash: lodash vulnerable to Code Injection via `_.template` imports key names",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "pptx-preview: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "xlsx: Prototype Pollution in sheetJS",
"severity": "high"
}
],
"status": "WARNING",
"scannedAt": "2026-07-05T07:24:53.587Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}Abu-Cowork is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by PM-Shawn. Open-source alternative to Claude Cowork — a local-first AI agent desktop app · multi-model · self-evolving skills · privacy-first. It has 199 GitHub stars.
Abu-Cowork returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/PM-Shawn/Abu-Cowork" and add it to your Claude Code skills directory (see the Installation section above).
Abu-Cowork is primarily written in TypeScript. It is open-source under PM-Shawn on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh Abu-Cowork against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
English | 中文
Your AI Desktop Office Assistant — Just Leave It to Abu
A locally-run AI desktop assistant inspired by Claude Code's Cowork mode. Tell Abu what you need — it reads files, runs commands, writes docs, and builds reports, all on your machine.
Download · Quick Start · Features · User Guide · Build from Source
| Feature | Abu | Regular AI Chat | Traditional Automation |
|---|---|---|---|
| Autonomous planning & task execution | :white_check_mark: | :x: | :x: |
| Read/write local files, run commands | :white_check_mark: | :x: | :white_check_mark: |
| Natural language interaction | :white_check_mark: | :white_check_mark: | :x: |
| 28 built-in skills + self-evolving (Abu grows its own) | :white_check_mark: | :x: | :x: |
| Multi-conversation Project aggregation | :white_check_mark: | :x: | :x: |
| Scheduled tasks & event triggers | :white_check_mark: | :x: | :white_check_mark: |
| IM bot (Lark/DingTalk/WeCom/Slack) | :white_check_mark: | :x: | Partial |
| Multi-agent parallel execution | :white_check_mark: | :x: | :x: |
| Browser & computer control | :white_check_mark: | :x: | Partial |
| 100% local data, privacy-safe | :white_check_mark: | :x: | :white_check_mark: |
Latest release v0.29.0 — workspace file tree + code canvas · declarative progress panel · multi-endpoint provider presets.
Recent highlights: Workspace file tree + code canvas (browse / preview / edit files in the side panel, CodeMirror source editing with auto-save, preview auto-refresh, version snapshots with rollback), declarative progress panel (the model declares its own plan steps and status via report_plan), inline visualization widgets (charts / HTML / Mermaid rendered inline in chat), multi-endpoint provider presets (Volcengine / Bailian / Zhipu access plans as curated presets + a unified add/edit modal), per-model capabilities (vision / tools / reasoning / token limits declared per model), plus doc comment-to-chat, full internationalization, and signed + notarized macOS builds.
Full changelog per release: see Releases.
Clean interface, powerful capabilities
SOUL.md