by off-grid-ai
Your private, on-device personal AI assistant for macOS and Windows. Chat, create, search files, and connect tools with local models. Includes an OpenAI-compatible API. Opt-in Pro sees, remembers, reflects, and acts with your approval. No cloud or account.
# Add to your Claude Code skills
git clone https://github.com/off-grid-ai/OGADLast scanned: 9/26/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@babel/core: @babel/core: Arbitrary File Read via sourceMappingURL Comment",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@humanfs/node: humanfs: Recursive copy follows symlinked files and copies data from outside the source tree",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jimp/core: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jimp/custom: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@mapbox/node-pre-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nut-tree-fork/nut-js: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@nut-tree-fork/provider-interfaces: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@nut-tree-fork/shared: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/coverage-v8: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xenova/transformers: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "baseline-browser-mapping: baseline-browser-mapping process termination on invalid input causes denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "browserslist: Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM",
"severity": "high"
},
{
"type": "npm-audit",
"message": "cacache: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "electron: Electron: AppleScript injection in app.moveToApplicationsFolder on macOS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "extract-zip: extract-zip unvalidated symlink path traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiter",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fflate: fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "file-type: file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "get-windows: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
"severity": "high"
},
{
"type": "npm-audit",
"message": "jimp: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
"severity": "high"
},
{
"type": "npm-audit",
"message": "kdbxweb: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "make-fetch-happen: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nanoid: nanoid: non-secure generators can loop indefinitely with negative size",
"severity": "high"
},
{
"type": "npm-audit",
"message": "node-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnx-proto: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnxruntime-web: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "high"
},
{
"type": "npm-audit",
"message": "protobufjs: Arbitrary code execution in protobufjs",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "qs: qs array-limit bypass via bracket-key comma parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "rollup: Rollup 4 has Arbitrary File Write via Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "sharp: sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545",
"severity": "high"
},
{
"type": "npm-audit",
"message": "smol-toml: smol-toml: Denial of Service via malformed TOML documents",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to downstream response desynchronization via retry interceptor",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "high"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-09-26T09:10:17.081Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how OGAD compares with popular alternatives.
OGAD is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by off-grid-ai. Your private, on-device personal AI assistant for macOS and Windows. Chat, create, search files, and connect tools with local models. Includes an OpenAI-compatible API. Opt-in Pro sees, remembers, reflects, and acts with your approval. No cloud or account. It has 114 GitHub stars.
OGAD failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/off-grid-ai/OGAD" and add it to your Claude Code skills directory (see the Installation section above).
OGAD is primarily written in TypeScript. It is open-source under off-grid-ai on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh OGAD against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Off Grid AI is a local-first AI runtime for your desktop. Download open models from the
built-in catalog (or any GGUF from Hugging Face) and use them across every modality — all
inference runs on your hardware via bundled llama.cpp, stable-diffusion.cpp,
whisper.cpp, and Kokoro. Nothing routes through a server we own; your conversations,
files, and models never leave your device.
Three things in one app:
http://127.0.0.1:7878/v1, no key)
for chat, vision, image, audio, and embeddings. Run it headless as just the gateway.The free, open app is a complete on-device AI studio:
stable-diffusion.cpp (Metal).
Ships SDXL-Lightning (few-step, fast), SDXL, SD 1.5/2.1, and Z-Image-Turbo
(2026 flagship, ~8-step). Live per-step preview, progress + ETA, cancel, lightbox, and
an artifacts gallery of everything you've generated.A full breakdown is in docs/FEATURES.md.
One local server (http://127.0.0.1:7878) speaks the OpenAI API:
| Capability | Endpoint |
|---|---|
| Chat (text + vision) | POST /v1/chat/completions |
| Text → Image | POST /v1/images (/generations, /edits) |
| Speech → Text | POST /v1/audio/transcriptions |
| Text → Speech | POST /v1/audio/speech |
| Embeddings | POST /v1/embeddings |
| Models | GET /v1/models |
curl http://127.0.0.1:7878/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{"model":"local","messages":[{"role":"user","content":"Hello!"}]}'
from openai import OpenAI
client = OpenAI(base_url="http://127.0.0.1:7878/v1", api_key="not-needed")
print(client.chat.completions.create(model="local",
messages=[{"role":"user","content":"Hello!"}]).choices[0].message.content)
Interactive API reference + an OpenAPI spec are served at /docs and /openapi.json.
You don't need the desktop UI to serve models — run only the gateway (no UI, no capture) and point any OpenAI client at it. Ideal for a server, a homelab box, or wiring local models into your own apps:
# from a built app
/Applications/Off\ Grid\ AI.app/Contents/MacOS/Off\ Grid\ AI --server-only
# or from source
OFFGRID_SERVER_ONLY=1 npm run gateway
It's self-sufficient — manage models over HTTP, no UI required:
| Action | Endpoint |
|---|---|
| List the catalog | GET /v1/models/catalog |
| List installed | GET /v1/models/installed |
| Active model per modality | GET /v1/models/active |
| Pull a model | POST /v1/models/pull { "id": "…" } → poll GET /v1/models/pull/status?id=… |
| Activate a model | POST /v1/models/activate { "id": "…", "kind"?: "image|speech|transcription" } |
| Delete a model | POST /v1/models/delete { "id": "…" } |
# pull a model into a headless gateway, then chat
curl -X POST http://127.0.0.1:7878/v1/models/pull \
-H 'Content-Type: application/json' -d '{"id":"unsloth/gemma-4-E4B-it-GGUF"}'
curl -X POST http://127.0.0.1:7878/v1/models/activate \
-H 'Content-Type: application/json' -d '{"id":"unsloth/gemma-4-E4B-it-GGUF"}'
The free app runs models. Pro adds the always-on layer that turns your own work into private, on-device memory — and an assistant that helps you act on it. Everything is explicit opt-in, with a visible recording indicator, and nothing leaves the device.