by apache
Apache Maka (Incubating) is a high-performance agent workspace that keeps a complete record of everything it did.
# Add to your Claude Code skills
git clone https://github.com/apache/makaLast scanned: 8/21/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@babel/core: @babel/core: Arbitrary File Read via sourceMappingURL Comment",
"severity": "low"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to downstream response desynchronization via retry interceptor",
"severity": "high"
}
],
"status": "WARNING",
"scannedAt": "2026-08-21T04:36:42.220Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}maka is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by apache. Apache Maka (Incubating) is a high-performance agent workspace that keeps a complete record of everything it did. It has 4,995 GitHub stars.
maka returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/apache/maka" and add it to your Claude Code skills directory (see the Installation section above).
maka is primarily written in TypeScript. It is open-source under apache on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh maka against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
An agent harness exists to finish tasks. We hold it to one measure: how many it completes and at what cost. We publish every run: same model, same official verifier, full per-task record.
docs/eval/.The website walks through one turn of the log and links the published runs. ARCHITECTURE.md has the system map.
Apache Releases: Maka has not made an Apache release yet. When one exists, the signed source archive will be the official release; packages distributed elsewhere are convenience artifacts. See the downloads page and .github/ASF_SOURCE_RELEASE.md for candidate criteria, signing procedures, and verification steps.
Desktop Nightly: Built daily from main for developers and testers, for macOS on Apple Silicon and Intel, Windows x64 and Linux x64 and arm64; the Windows and Linux builds are unsigned previews. It is not an ASF release and is not intended for production use. The downloads page has the installers and the platform status.
Build from source: To compile and run Desktop, the TUI, or the CLI directly from a source checkout, see the Build from source section below.
packageManager is npm 11);ripgrep, used by Runtime's Grep tool.git clone https://github.com/apache/maka.git
cd maka
npm ci
npm run dev
npm run dev starts the Desktop development environment with HMR. To build every workspace before starting Electron, use:
npm run dev:full
Direct Peer and Peer Mesh development additionally requires Rust stable 1.98 or newer and the platform linker (Xcode Command Line Tools on macOS, MSVC Build Tools on Windows). Use the peer-enabled entry point so the native addon is built before Desktop starts:
npm run dev:peer # HMR
npm run dev:full:peer # full build
If dependencies were installed with ELECTRON_SKIP_BINARY_DOWNLOAD=1, install the Electron platform binary before starting:
node node_modules/electron/install.js
Maka does not bundle a shared model account. On first launch:
Settings → Models;The app distinguishes configured, send-ready, and experimental connection states. An account flow that is not wired into Runtime is not presented as a usable model.
For the public npm package, see the CLI installation and usage guide. The commands below run the development CLI from a source checkout.
Build the workspaces first:
npm run build
Then start the TUI or run one Turn:
npm run cli:dev
npm run cli:dev -- run "Summarize this repository and identify its most important risk"
npm run cli:dev -- run --graph "Implement two independent slices, integrate them, then review the result"
npm run cli:dev -- --help
The TUI also accepts /graph on, /graph off, and /graph <task>. Non-interactive
--graph runs wait for the durable Graph to finish before printing the final
supervisor output. Graph implementation operators use isolated Git worktrees, so
the source project must be a clean Git worktree.
The repository CLI uses the same Maka Dev profile as a development Desktop build. The
released maka binary continues to use the Maka profile; the two profiles are not copied or
synchronized automatically. Evaluation specs and adapters live in packages/eval.
The backend spine is:
Desktop / TUI / CLI → Runtime Host → SessionManager → AgentRun
↓
Model + Tool Runtime → Runtime Event Log
↓
Context / Session / UI projections
Experiment → Cells → Attempts → Results
↓
Runtime Host executes Maka subjects
Start with ARCHITECTURE.md. It provides the system map, code boundaries, problem-oriented reading paths, and links to the deep dives under docs/architecture/.
apps/desktop/ Electron main / preload / React renderer
packages/core/ Pure contracts for Sessions, Events, Permissions, and Connections
packages/storage/ SQLite operational state, configuration, and payload stores
packages/mcp/ Provider-neutral Model Context Protocol client integration
packages/runtime/ AgentRun, model adapters, tools, context, and recovery
packages/runtime-host/ Single-owner Runtime Host lifecycle, protocol, and client bootstrap
packages/eval/ Experiment cells, attempts, results, and executor/subject adapters
packages/computer-use/ Computer-use backend selection, host lifecycle, and protocol adapters
packages/cli/ TUI and non-interactive CLI
packages/ui/ Shared conversation, Markdown, Artifact, and UI primitives
native/ Rust: the direct-peer addon for Runtime Host and the gitoxide helper
website/ Astro source for maka.apache.org
docs/ Architecture, product, security, privacy, and test contracts
scripts/ Build hygiene, visual checks, smoke tests, and release helpers
skills/ Agent skills shipped with the repository
patches/ Patches applied to npm dependencies at install
experiments/ Platform experiments, currently the Windows sandbox smoke scripts
Workspace data lives under Electron userData by default:
<Electron userData>/workspaces/default/
runtime.sqlite
connection-catalog.json
credential-vault.json
settings.json
artifacts/
credential-vault.json), readable only by your OS account. The renderer never sees them.runtime.sqlite is the live record. Older JSONL transcripts and Electron safeStorage credential files are not imported; an upgraded workspace can show empty threads, and those credentials must be entered again.MAKA_RUNTIME_SAFE_BOUNDARY_RESUME=1 only if you want Desktop Safe resume, CLI /resume, and startup auto-resume — those calls hit the model and use tokens.Details: SECURITY.md, privacy, resume.
Before sending a change, read CONTRIBUTING.md.
Common repository-level commands:
npm run bu