by Playa-Cyrene
An open-source desktop AI agent built around Cyrene’s persona and powered by the self-developed Cyrene_Harness framework. It combines immersive character chat with practical Agent capabilities for daily tasks, coding assistance, learning, and tools like music and weather.
# Add to your Claude Code skills
git clone https://github.com/Playa-Cyrene/Cyrene-AgentLast scanned: 9/20/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@hono/node-server: Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jimp/core: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@jimp/custom: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@larksuiteoapi/node-sdk: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@nut-tree-fork/nut-js: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@nut-tree-fork/provider-interfaces: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@nut-tree-fork/shared: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xenova/transformers: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: XML fragment injection via invalid EntityReference.nodeName during requireWellFormed serialization",
"severity": "high"
},
{
"type": "npm-audit",
"message": "axios: Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF",
"severity": "high"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "builder-util-runtime: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`",
"severity": "high"
},
{
"type": "npm-audit",
"message": "concurrently: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "electron-updater: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "exceljs: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "extract-zip: extract-zip unvalidated symlink path traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-uri: fast-uri vulnerable to host confusion via literal backslash authority delimiter",
"severity": "high"
},
{
"type": "npm-audit",
"message": "file-type: file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "hono: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
"severity": "high"
},
{
"type": "npm-audit",
"message": "jimp: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Mermaid configuration APIs allow prototype pollution",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "nanoid: nanoid: non-secure generators can loop indefinitely with negative size",
"severity": "high"
},
{
"type": "npm-audit",
"message": "nodemailer: Nodemailer: resolveContent() on a MailMessage bypasses disableFileAccess/disableUrlAccess when called with the legacy signature",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnx-proto: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "onnxruntime-web: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset",
"severity": "high"
},
{
"type": "npm-audit",
"message": "protobufjs: Arbitrary code execution in protobufjs",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "qs: qs array-limit bypass via bracket-key comma parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "sharp: sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591",
"severity": "high"
},
{
"type": "npm-audit",
"message": "shell-quote: shell-quote quote() does not escape newlines in object .op values",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to downstream response desynchronization via retry interceptor",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
}
],
"status": "FAILED",
"scannedAt": "2026-09-20T09:06:15.781Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how Cyrene-Agent compares with popular alternatives.
Cyrene-Agent is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Playa-Cyrene. An open-source desktop AI agent built around Cyrene’s persona and powered by the self-developed Cyrene_Harness framework. It combines immersive character chat with practical Agent capabilities for daily tasks, coding assistance, learning, and tools like music and weather. It has 608 GitHub stars.
Cyrene-Agent failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/Playa-Cyrene/Cyrene-Agent" and add it to your Claude Code skills directory (see the Installation section above).
Cyrene-Agent is primarily written in TypeScript. It is open-source under Playa-Cyrene on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh Cyrene-Agent against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
See comparison
Cyrene-Agent 是一个以《崩坏:星穹铁道》昔涟为核心角色的 Windows Live2D AI 桌面伴侣。
基于 Electron + TypeScript 开发的桌面端 Live2D 智能对话 Agent。
项目围绕昔涟(Cyrene)的角色设定,结合自研Cyrene_Harness+DMAE 记忆引擎,
将角色化聊天、个性化记忆、语音交互、工具调用与多平台接入整合在同一个桌面 Agent 中,
支持日常聊天(Chat)、辅助工作(Work)、代码协作(Code)、学习陪伴(Learn)四种对话模式。
Work / Code / Learn等需要工具调用的会话模式,全部跑在 CyreneHarness 之上。 源码:src/main/orchestrator/harness/cyrene-harness.ts
CyreneHarness 是 Cyrene Agent 的核心 Agent Loop,负责把模型决策、工具执行、副作用记账与状态恢复串成一个可中断、可恢复、可回放的连续循环。
关键设计:
toolCalls 进入工具派发,无 toolCalls 时由模型主动结束当前 turn。push 进 messages,否则下一轮模型会看不到自己上一步的回复,loop 立即崩。ask_user / confirm_uncertain_effect 是用户等待类内置工具,必须独占本轮:其余同轮工具全部以 not_executed 协议结果写回,并 discardProgressBuffer() 丢弃进度文本。success / failure / unknown / not_executed。当 unknown 且 sideEffect === non_idempotent 时,副作用会被记入 state.uncertainEffects,并 halted = true 暂停本轮后续同类调用,防止自动重放危险副作用。classifyToolResultError + resolveSideEffect 决定是否重试;sleepWithJitter 退避可被 AbortSignal 中断。ask_user 等待用户期间暂停执行计时,用户思考多久都不消耗任务超时预算。cacheEpoch 缓存周期跨压缩 / 恢复推进;Kimi prompt_cache_key 等厂商缓存 hints 在请求层统一注入。ToolOutputRef),模型消息只保留 preview;需要完整内容时由模型调用内置 read_tool_result 按需回读,大幅降低上下文占用。context_usage 快照事件,驱动 UI 上下文环实时显示。finishReason = length)时在回复尾部追加提示,不静默截断。await 都用 raceWithSignal 包裹,signal.aborted 时返回 cancelled()(finalAnswer = '',不发 final_answer 事件)。onCheckpoint 把 messages + state + rounds 持久化,跨进程崩溃后可恢复。4 种终止状态:
| 状态 | terminated |
terminateReason |
触发条件 |
|---|---|---|---|
| ✅ success | false |
undefined |
模型不再调用工具,主动结束当前 turn |
| ⚪ cancelled | true |
cancelled |
AbortSignal 触发(finalAnswer = '') |
| 🟥 error | true |
error |
LLM 抛错或 checkpoint 失败 |
| 🟨 timeout | true |
timeout |
超过 config.totalTimeoutMs |
主流程示意:

(示意图:① 初始化 → ② 主循环 → ③ LLM → ④ 工具调度 → ⑤ 状态账本 → ⑥ 终态结算)
安装 Visual Studio Build Tools 时,请勾选:
安装 Rust 后,建议确认使用 MSVC 工具链:
rustup default stable-x86_64-pc-windows-msvc
飞书、微信 iLink、
nut-js键鼠自动化及原生截图功能依赖 Windows 环境。如果直接安装 Releases 中的打包版本,无需另外安装 Rust 和 Visual Studio Build Tools。
git clone https://github.com/Playa-Cyrene/Cyrene-Agent.git
cd Cyrene-Agent
推荐使用锁定版本安装:
npm ci
也可以使用:
npm install
首次安装会下载 Electron、Pixi.js、Live2D 等相关依赖,具体耗时取决于网络环境。
项目附带 cyrene 命令行入口,可用于首次欢迎语、查看版本或启动桌面端。在项目根目录执行:
npm run build:cli
npm link
之后即可在任意目录使用 cyrene:
cyrene # 首次运行会显示欢迎 Banner,之后只输出简洁状态
cyrene hello # 重新查看完整欢迎 Banner
cyrene about # 查看 Banner 与项目元信息
cyrene version # 查看版本
cyrene --help # 查看全部子命令
cyrene run # 在项目根目录启动桌面端(开发模式)
首次欢迎语仅在第一次执行
cyrene时出现,状态记录在~/.cyrene/state.json;之后默认只输出Cyrene Agent <version>与Ready.。cyrene run目前为开发模式,需要当前目录存在package.json;正式安装版的cyrene desktop入口将在 1.x 提供。
npm run build已经包含npm run build:cli,因此构建项目后无需再单独执行build:cli。但npm link仍需单独运行,才能在任意目录使用cyrene命令。
Cyrene 无需本地大语言模型即可正常聊天,但建议安装 BGE-M3 Embedding 模型,以获得更完整的语义增强体验:
[!IMPORTANT]
未安装 BGE-M3 不会影响基础聊天,依赖 Embedding 的增强功能会自动关闭或降级。
音乐功能由主进程内置的 NeteaseOpenapiProvider + MpvController 组成:
NeteaseOpenapiProvider 通过网易云音乐 OpenAPI 拉取搜索结果、推荐、歌单、收藏等内容;需要在设置中配置 OpenAPI 凭据(Cookie / Token 等)。MpvController 启动打包在 resources/bin/mpv/mpv.exe 的 mpv 子进程,通过命名管道(Windows)或 Unix socket 发送 JSON IPC 命令,不需要安装网易云桌面客户端或注册 orpheus:// 协议。npm run prepare:mpv 在打包阶段拷贝 mpv 二进制到 resources/bin/mpv/;本地未检测到 mpv 时,音乐工具会返回 client_unavailable 并在 UI 中提示,但不影响其他功能。[!NOTE]
音乐功能为可选组件,不影响聊天及其他核心功能。未配置 OpenAPI 凭据或未检测到 mpv 时,音乐工具会自动跳过并在界面中提示。
首次从源码运行时,需要先构建 Rust 原生截图助手:
npm run build:screenshot-helper
npm run build
npm start
[!IMPORTANT]
原生截图助手不会以
.exe形式提交到 Git 仓库,因此首次克隆后必须执行一次npm run build:screenshot-helper。Windows 用户也可以直接双击项目根目录的
setup.bat完成依赖安装、构建和npm link,之后双击start.bat即可启动。
开发模式:
npm run build:screenshot-helper
npm run dev
修改 Rust 截图助手代码后,需要重新执行:
npm run build:screenshot-helper
构建 Windows 可分发版本:
npm run package:win:dir
打包命令会自动构建 Electron 应用和 Rust 截图助手。
应用启动后,点击系统托盘图标 → 打开设置,完成以下基础配置:
🔑 模型设置:选择 LLM 厂商预设,填写 API Key、Base URL 与模型名称。
这是 Cyrene 正常聊天和运行 Agent 的必要配置。
🎙️ TTS 设置(可选):选择 Mossland、MiniMax、MiMo、GPT-SoVITS 或自定义云端语音合成服务。
🎧 ASR 设置(可选):如需使用语音通话,可配置阿里云实时 ASR 的 AppKey 与 AccessKey,或填写与 Mossland TTS 共用的 API Key。
📱 外部渠道(可选):根据需要连接飞书或微信 iLink,在手机端与 Cyrene 对话。
相关配置会保存在应用的 <userData>/ 目录中,修改后通常无需重启应用。
pixi-live2d-display 与 Cubism Core 渲染,支持桌面置顶、鼠标交互、自然待机与嘴型同步。下面各会话模式是 Harness 的"消费者":

prompts/cyrene_harness.md,只约束表达风格、不污染工具参数,冲突时按「任务正确性 > 信息清晰 > 昔涟风格」取舍);完整人设层(Soul)在 Harness 出口后生成回复文本。state.uncertainEffects 并停止本轮同类自动重放,避免危险操作被无声重复。AbortSignal 取消;取消时不会发出"最终回复",避免误导用户。messages + state + rounds 序列化到本地,跨进程崩溃后可在原状态续跑,不丢上下文。
[!WARNING]
Code 模式目前尚未内置改动 review / diff 预览功能,Agent 改完文件会直接落盘。建议在改动发生前使用你顺手的 IDE 或 diff 工具(如 VS Code、Cursor、JetBrains 系列、SourceGit 等)打开绑定目录以便随时查看 / 回滚。
启用 Git 是最稳妥的兜底:
git init && git add -A后任何改动都可git diff/git checkout -- .还原。
.. 与符号链接逃逸)会被直接拒绝。node_modules/.bin 中查找,最后回退到系统 PATH 逐目录遍历(Windows 还会按 PATHEXT 追加 .exe / .cmd 等扩展名)。typescript-language-server、pyright-langserver、gopls、rust-analyzer、clangd、jdtls、OmniSharp、intelephense、ruby-lsp、kotlin-language-server、lua-language-server、vue-language-server、yaml-language-server;Windows 可用 where pyright-langserver,macOS/Linux 可用 which pyright-langserver 检查是否可发现。用户也可以明确要求昔涟通过现有、受权限控制的工具协助安装。stdio: "pipe" 启动,shell: false,cwd 强制为绑定工作目录;模型不能指定命令、服务 ID 或工作目录;lspServerOverrides 只覆盖 builtin 服务的命令名 / 参数 / 扩展名,不接受模型在对话中传入的任意命令。