by EKKOLearnAI
Ekko Studio is a local-first AI workspace for multi-agent chat, coding, and visual workflows, available on desktop and the web.
# Add to your Claude Code skills
git clone https://github.com/EKKOLearnAI/ekko-studioLast scanned: 9/23/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@tsoa/cli: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/coverage-v8: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization",
"severity": "high"
},
{
"type": "npm-audit",
"message": "adm-zip: adm-zip extraction follows destination symlinks, allowing arbitrary file overwrite",
"severity": "high"
},
{
"type": "npm-audit",
"message": "axios: Axios: Prototype pollution auth subfields can inject Basic auth",
"severity": "high"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "concurrently: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify contains a Cross-site Scripting vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild allows arbitrary file read when running the development server on Windows",
"severity": "low"
},
{
"type": "npm-audit",
"message": "express: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "form-data: form-data: CRLF injection in form-data via unescaped multipart field names and filenames",
"severity": "high"
},
{
"type": "npm-audit",
"message": "immutable: Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "high"
},
{
"type": "npm-audit",
"message": "linkify-it: linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Mermaid configuration APIs allow prototype pollution",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "monaco-editor: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "nanoid: nanoid: custom generators can loop indefinitely when size is zero",
"severity": "high"
},
{
"type": "npm-audit",
"message": "pdfjs-dist: PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF ",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs array-limit bypass via bracket-key comma parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "sharp: sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545",
"severity": "high"
},
{
"type": "npm-audit",
"message": "shell-quote: shell-quote quote() does not escape newlines in object .op values",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "tar: node-tar: Process crash via PAX numeric path type confusion",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "ts-deepmerge: ts-deepmerge: Prototype Method Override leads to DoS",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tsoa: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "critical"
}
],
"status": "FAILED",
"scannedAt": "2026-09-23T09:06:32.409Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how ekko-studio compares with popular alternatives.
ekko-studio is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by EKKOLearnAI. Ekko Studio is a local-first AI workspace for multi-agent chat, coding, and visual workflows, available on desktop and the web. It has 11,184 GitHub stars.
ekko-studio failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/EKKOLearnAI/ekko-studio" and add it to your Claude Code skills directory (see the Installation section above).
ekko-studio is primarily written in TypeScript. It is open-source under EKKOLearnAI on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh ekko-studio against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Ekko Studio was previously named Hermes Studio / Hermes Web UI. The GitHub
repository is EKKOLearnAI/ekko-studio. The primary npm package is
ekko-studio, with the ekko-studio-web command. The legacy hermes-web-ui
package and command remain supported and receive the same releases.
Captured in Ekko Studio v0.7.18 on 2026-09-10. Chat and workflow screens use demo data.
| Visual workflows | Agent Manager |
|---|---|
![]() |
![]() |
| Connect agent steps and add a human approval gate. | Manage agent installations, settings, and updates in one place. |
Browse installed skills, read their instructions, and enable them as needed.

| Area | What Ekko Studio does |
|---|---|
| Multi-agent runtime | Runs Hermes, Ekko, Claude Code, Codex, Pi, Grok, OpenCode, and DeepSeek Harness (DSH) with streaming responses, tool traces, generated-file previews, persistent sessions, and standalone desktop chat windows. |
| Studio workspace | Provides shared chats, group chat, global-agent runs, workflows, files, voice, media, devices, themes, logs, usage, and App connectivity across agent runtimes. |
| Agent control planes | Keeps Hermes profiles, providers, models, memory, skills, plugins, jobs, Kanban, channels, and runtime management in their owning agent module. |
| Automation | Builds executable visual workflows and connects the supported runtimes through schedules, approval gates, group-chat rooms, platform channels, and MCP servers. |
| Workspace tools | Provides a file browser, web terminal, Desktop Agent Browser, voice input/output, coding-agent runners, device discovery, Journey graph, and performance views. |
| Distribution | Ships as a desktop app for Windows/macOS/Linux, an npm CLI package, and a Docker image. |
Ekko Studio provides a shared workspace for its supported agent runtimes, grouped into three agent families:
| Agent family | Runtime | Owned behavior |
|---|---|---|
| Hermes | Hermes | Profiles, providers, models, skills, plugins, memory, jobs, Kanban, channels, MCP, terminal, and Hermes runtime integration. |
| Ekko | Ekko | Ekko execution, approvals, clarifications, memory, MCP, and provider runtime behavior. |
| Coding | Claude Code, Codex, Pi, Grok, OpenCode, DSH | Coding-agent installation, configuration, proxies, sessions, and process execution. |
Studio owns capabilities shared by those families: single chat, group chat,
global-agent orchestration, workflows, webhooks, sessions, files and uploads,
TTS/STT, media, pets, themes, devices, networking, logs, usage, authentication,
and App connectivity. Studio-owned HTTP APIs use /api/studio/*; Hermes-owned
control-plane APIs use /api/hermes/*. Already-released mobile App paths are
handled by one centralized compatibility layer instead of duplicate legacy
controllers.
/chat-run; Studio dispatches each run to Hermes, Ekko, Claude Code, Codex, Pi, Grok, OpenCode, or DSH through runtime adaptersUnified configuration for 10 platforms in one page:
| Platform | Features |
|---|---|
| Telegram | Bot token, mention control, reactions, free-response chats |
| Discord | Bot token, mention, auto-thread, reactions, channel allow/ignore lists |
| Slack | Bot token, mention control, bot message handling |
| Enable/disable, mention control, mention patterns | |
| Matrix | Access token, homeserver, auto-thread, DM mention threads |
| Feishu (Lark) | App ID / Secret, mention control |
| DingTalk | Client ID / Secret, mention control |
| QQBot | App ID / Secret, mention control |
| QR code login (scan in browser, auto-save credentials) | |
| WeCom | Bot ID / Secret |
~/.hermes/.env~/.hermes/config.yaml~/.hermes/auth.json)/v1/models)/v4).tar.gz)