Floe — a native iOS/iPadOS AI agent workspace for iPhone and iPad, built for private bring-your-own-key workflows.
# Add to your Claude Code skills
git clone https://github.com/JiangNanGenius/floe-agentLast scanned: 9/24/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-09-24T09:01:40.319Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how floe-agent compares with popular alternatives.
floe-agent is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by JiangNanGenius. Floe — a native iOS/iPadOS AI agent workspace for iPhone and iPad, built for private bring-your-own-key workflows. It has 128 GitHub stars.
Yes. floe-agent passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/JiangNanGenius/floe-agent" and add it to your Claude Code skills directory (see the Installation section above).
floe-agent is primarily written in Swift. It is open-source under JiangNanGenius on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh floe-agent against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.

Floe Agent turns a model conversation into a durable task. Each message continues the same task, while every model execution becomes a separate run with its own progress, tool evidence, approvals, checkpoints, and recovery state. A task can use an app-managed private workspace or an explicitly selected project workspace.
Current internal TestFlight: 1.7.0 (225). Apple VALID, unexpired and IN_BETA_TESTING in the sole private internal Floe QA group, verified September 22 at 20:17 UTC. The accepted-SDK release run preserved the unsigned IPA before signing and upload; the matching GitHub prerelease is public. Device behavior still belongs to user acceptance. Build 225 release notes · Delivery record · GitHub prerelease.
Build 225 is the current internal delivery. It carries the Build 224 candidate slice — Build 223 Runtime v2 startup/migration repairs (fresh registries and older Linux installs open again, verified content is never mistaken for uninstalled, environments needing repair fail closed), MLX residency across retained-task idle gaps, the PPT/PPTX edit-entry first render, and GitHub-first sharded Gitee fallback with a one-way GitHub→Gitee repository mirror — and fixes the single Swift 6 typed-throws error in the Linux image downloader that stopped the Build 224 accepted-SDK App build, without changing fail-closed mirror switching or cancellation. Focused Linux image tests (23), a Swift 6 iOS-SDK object compile, the cloud accepted-SDK build and distribution gates passed. Physical-device Linux, local-model, PPT and PiP behavior remains user acceptance. Release notes.
Build 224 never compiled. Its immutable tag v1.7.0-beta.81 (c36b7b24) and failed accepted-SDK run 35767875337 (exit 65, no artifact or upload) are retained as the failure record; see the Build 224 notes and the Build 225 failure table.
Source status — Build 226 candidate (unreleased). The source since delivered Build 225 adds a native iPad IDE workbench, compressed-archive operations, reusable Linux templates, Runtime v2 resource management, background and notification repairs, local-model tool continuation, a multiline composer with per-conversation drafts, one third-party license entry, native-first media routing, and the pinned Office host. Component and cloud checks are recorded in the candidate notes; the final App build, TestFlight availability and physical-device behavior are separate pending gates.
Floe 1.7 upgrades the iPad-first Notes workspace with illustrated mind maps, native Office editing, image and creative tools, on-device speech, and task-owned environments running TinyEMU/Linux. TinyEMU provides the main local Linux path; guest package managers own Linux language/tool installation, while WASM remains a separate compatibility route. See the implementation status, migration guide, build boundaries and version archive.
Notes (手记) is a separate workspace above Creative mode, with its own durable content and undo history while sharing Floe models, tools and permissions. PDF/image annotation, illustrated mind maps with document windows, native Office editing, selection questions and editable archives are available; full Office layout fidelity and physical-device acceptance remain tracked in the implementation status. The whole app prioritizes iPadOS 27, also validates iPhone, and keeps version 26 compatible.
Mind maps reflow as topics, images and branches change, preserve zoom during editing, and fit independent PDF windows. Notes supports Trash recovery and confirmed permanent deletion with deferred collection that protects shared files and undo history.
Voice input, video automatic captions and Agent file transcription now share on-demand multilingual Whisper Small with Apple recognition fallback. Timed exports support SRT, VTT and JSON. Home, conversations and Canvas can explicitly select Notes material and revoke access. Installing speech resources does not establish bilingual recognition quality. See the implementation and evidence record for remaining work; full package/model delivery and physical-device acceptance remain incomplete.