by Sayhi-bzb
A Unicode canvas for humans and AI. Draw diagrams, interfaces, and slides as editable text.
# Add to your Claude Code skills
git clone https://github.com/Sayhi-bzb/CharDeskLast scanned: 10/6/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@humanfs/node: humanfs: Recursive copy follows symlinked files and copies data from outside the source tree",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/coverage-v8: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "braces: braces vulnerable to stack-exhaustion denial of service through deeply nested patterns",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-glob: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-cookie: JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "high"
},
{
"type": "npm-audit",
"message": "knip: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "micromatch: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "smol-toml: smol-toml: Denial of Service via TOML documents containing thousands of consecutive commented lines",
"severity": "high"
},
{
"type": "npm-audit",
"message": "source-map-js: source-map-js allows event-loop denial of service through indexed source-map section offsets",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to downstream response desynchronization via retry interceptor",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-10-06T11:01:53.811Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how CharDesk compares with popular alternatives.
CharDesk is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Sayhi-bzb. A Unicode canvas for humans and AI. Draw diagrams, interfaces, and slides as editable text. It has 547 GitHub stars.
CharDesk returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/Sayhi-bzb/CharDesk" and add it to your Claude Code skills directory (see the Installation section above).
CharDesk is primarily written in TypeScript. It is open-source under Sayhi-bzb on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh CharDesk against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
[English] | 简体中文
A shared visual medium for people and agents.
CharDesk gives people and LLM-powered agents a common artifact: visual Unicode text. Its infinite Canvas lets people draw diagrams and interfaces while agents inspect the source, revise it, and verify the result. Cell UI applies the same medium to interactive interfaces.
Product home · CharGraph · CLI reference
Requires Node.js 20 or later.
npx skills add https://github.com/sayhi-bzb/chardesk --skill chardesk
Register the MCP server with your agent:
# Codex
codex mcp add chardesk -- npx -y @chardesk/mcp
# Claude Code
claude mcp add chardesk -- npx -y @chardesk/mcp
# Pi
pi mcp add chardesk -- npx -y @chardesk/mcp
After that, no manual server or pair command is needed. The first Canvas tool call opens Canvas when necessary, and the page connects to the local bridge automatically.
The CLI is optional for local file workflows:
npm install -g @chardesk/cli
Then tell your agent what you want to see:
$chardesk Explain how a GPU works as a visual Canvas.
The agent creates the source, checks it, and opens the canvas. You do not need to learn a file format or configure an AI provider first.
Shared medium · Source
Visual explanation · Source
Scientific figure · Source
Character slides · Source
Interface design · Source
Agent Canvas · Source
Context Control Room · Source
Idea Signal Player · Source
Pocket Canvas · Source
People scan a two-dimensional surface. Language models generate and edit token sequences. Screenshots preserve layout, but add pixel noise and are awkward to revise precisely across turns; plain text is easy to edit, but normally gives up space and style.
CharDesk keeps both. A fixed Unicode grid carries position, box drawing carries structure, and ANSI carries emphasis. The result remains selectable, searchable, diffable, and directly editable by an agent.
Person reads and uses
⇅
Shared Unicode scene
⇅
Agent reads and edits
Unicode, box drawing, CJK, technical symbols, monochrome emoji, and Nerd Font glyphs share one grid. ESC-less ANSI adds foreground and background colors, bold, italic, underline, strike, and inverse styles without turning the work into an image.
Write Markdown, Mermaid, math, GFM tables, fenced code, JSON, YAML, Vega-Lite, and XY or line charts. CharGraph compiles structured source into portable character graphics while preserving the source that produced it.
Arrange content on Freeform canvases, start from reusable Cell templates, compose multiline fields with ||| and ---, or tell a story with Slides. Every form resolves to the same character-grid rendering pipeline.
@chardesk/mcp once with your agent (Codex, Claude Code, or Pi). The agent starts it automatically; Canvas discovers the local bridge and the first canvas_* call opens Canvas if needed. See the MCP package reference.chardesk checks, previews, opens, and renders the result. See the CLI reference.chrome://flags/#enable-webmcp-testing, relaunch Chrome, and use the browser path only when needed.Browser agents can call chardesk_read_materials to enter the same visual language and worked examples as the skill. Canvas tools read, search, and write the active two-dimensional Cell surface.
Use @chardesk/protocol for interchange, @chardesk/viewer for framework-independent rendering, and @chardesk/fonts for the compatible glyph set. Each package owns its installation and API documentation.
Thanks to LINUX DO.
CharDesk is open source under the MIT License.